Showing posts with label Cryptography. Show all posts
Showing posts with label Cryptography. Show all posts

Saturday, April 21, 2012

What is Encrypted Chat?

Chat rooms and instant messaging software allow users from around the world to send and receive messages in real time. Unfortunately, messages sent through chat and IM software aren't always secure. If someone intercepts messages or gains access to a chat room or IM program's archive, that person can potentially read every message that has been sent. Some users turn to data encryption to keep their conversations private.

Client-to-Client Encryption

The Internet relay chat protocol, commonly referred to as IRC, is a widely used instant messaging protocol that allows users to connect to a central server and engage in real-time conferences. To allow these users to send files and other data securely through IRC, some IRC clients such as the multiplatform KVIrc client and the OS X-native Colloquy feature client-to-client encryption. Using a connection type known as a "secure direct client-to-client" connection, data is encrypted as it is sent from one IRC client and then decrypted by the other client. This results in faster encryption because messages are encrypted only during transit, but offers no security for archived messages.

Java Chat

Most chat room administrators have the option to add an encryption feature to their chat rooms. They set up a secure socket layer connection between the server and Java-based chat room software such as the AddonChat chat software by AddonInteractive or the Rijndael Chat Client created at Cornell University. This encryption affects messages within the chatroom as well as any archived messages on the server; no one other than registered users and administrators can gain unauthorized access to the chat messages. The primary disadvantage of this encryption type is that the encryption occurs only on the server, providing no encryption for data on the users' computers.

Instant Messaging

Website-affiliated instant messaging programs such as Yahoo Messenger, Windows Live Messenger and Google Talk are the most commonly used instant messaging platforms, but other options are available. Users who want a secure instant messaging experience may prefer alternate messaging software such as the Windows-only X-IM or the multiplatform BitWise IM, which offer chat encryption for added message security. Depending on the program used, messages sent through these alternate instant-messaging programs feature 128-bit or 256-bit encryption to protect private conversations. The main advantage of these programs is that they typically encrypt messages at the point of creation, ensuring that the message remains encrypted both during transit and in message archives. However, both users involved in the conversation must use the same messaging software for the encryption to work properly; this can be inconvenient and is not always possible if one user cannot download or install the messaging program.

Plugins and Encryption Software

Even though specific instant messaging programs and chat platforms may not offer encryption features, in some cases it is possible to add encryption in the form of a software plugin or external program. Plugins such as the FiSHy plugin for Colloquy and the Pidgin-Encryption plugin for the multiplatform chat application Pidgin enhance existing encryption methods, add new encryption options or provide encryption to chat programs that don't natively offer message encryption. External programs such as Secway Global's Windows-based SimpLite and SimpPro programs can be used to encrypt messages on other messaging programs that don't offer native encryption. Both plugins and external programs typically encrypt messages before they are transmitted, resulting in a secure chat experience because the messages are encrypted in archives as well. Because of the differences in specific programs and plugins, the actual encryption method varies depending on the program or plugin used.

Encrypted Chat Software

Unless a connection over the Internet is encrypted, any party that can intercept your transmissions also is able to read what's in them, including chat connections used by AIM, Windows Live Messenger, Yahoo! Messenger and Google Talk. Utilize chat encryption software to protect your privacy.

Native/Integrated Encryption

Some chat clients add encryption software as part of the basic installation package. AIM and Google Talk, for example, include the option to chat via a Secure Socket Layer (SSL) connection, which encrypts the entire transmission using 128-bit industry standards.

Encryption Plug-ins

Chat software that lacks integrated encryption or contains unsatisfactory native encryption often uses "third-party plug-ins" to encrypt chat text before it is sent out to the Internet. Often, both the sender and recipient need to have the same encryption plug-in installed for it to work.

Internet Connection Encryption

For those who desire only the most secure encryption available, software packages exist that encrypt the text of your chats and every data stream to and from your machine. These packages often are comprehensive and require paid subscriptions for access to security updates and user support.

How Smart Cards works?

A smart card resembles a credit card in size and shape, but inside it is completely different. First of all, it has an inside -- a normal credit card is a simple piece of plastic. The inside of a smart card usually contains an embedded microprocessor. The microprocessor is under a gold contact pad on one side of the card. Think of the microprocessor as replacing the usual magnetic stripe on a credit card or debit card.

Smart cards are much more popular in Europe than in the United States. In Europe, the health insurance and banking industries use smart cards extensively. Every German citizen has a smart card for health insurance. Even though smart cards have been around in their modern form for at least a decade, they are just starting to take off in the United States.

Magnetic stripe technology remains in wide use in the United States. However, the data on the stripe can easily be read, written, deleted or changed with off-the-shelf equipment. Therefore, the stripe is really not the best place to store sensitive information. To protect the consumer, businesses in the U.S. have invested in extensive online mainframe-based computer networks for verification and processing. In Europe, such an infrastructure did not develop -- instead, the card carries the intelligence.

The microprocessor on the smart card is there for security. The host computer and card reader actually "talk" to the microprocessor. The microprocessor enforces access to the data on the card. If the host computer read and wrote the smart card's random access memory (RAM), it would be no different than a diskette.

Smarts cards may have up to 8 kilobytes of RAM, 346 kilobytes of ROM, 256 kilobytes of programmable ROM, and a 16-bit microprocessor. The smart card uses a serial interface and receives its power from external sources like a card reader. The processor uses a limited instruction set for applications such as cryptography.

The most common smart card applications are:
Credit cards
Electronic cash
Computer security systems
Wireless communication
Loyalty systems (like frequent flyer points)
Banking
Satellite TV
Government identification

Smart cards can be used with a smart-card reader attachment to a personal computer to authenticate a user. Web browsers also can use smart card technology to supplement Secure Sockets Layer (SSL) for improved security of Internet transactions.  Smart-card readers can also be found in mobile phones and vending machines.

Basics of intruder detection system

An intrusion detection system (IDS) monitors network traffic and monitors for suspicious activity and alerts the system or network administrator. In some cases the IDS may also respond to anomalous or malicious traffic by taking action such as blocking the user or source IP address from accessing the network.

IDS come in a variety of “flavors” and approach the goal of detecting suspicious traffic in different ways. There are network based (NIDS) and host based (HIDS) intrusion detection systems. There are IDS that detect based on looking for specific signatures of known threats- similar to the way antivirus software typically detects and protects against malware- and there are IDS that detect based on comparing traffic patterns against a baseline and looking for anomalies. There are IDS that simply monitor and alert and there are IDS that perform an action or actions in response to a detected threat. We’ll cover each of these briefly.

NIDS

Network Intrusion Detection Systems are placed at a strategic point or points within the network to monitor traffic to and from all devices on the network. Ideally you would scan all inbound and outbound traffic, however doing so might create a bottleneck that would impair the overall speed of the network.

HIDS

Host Intrusion Detection Systems are run on individual hosts or devices on the network. A HIDS monitors the inbound and outbound packets from the device only and will alert the user or administrator of suspicious activity is detected

Signature Based

A signature based IDS will monitor packets on the network and compare them against a database of signatures or attributes from known malicious threats. This is similar to the way most antivirus software detects malware. The issue is that there will be a lag between a new threat being discovered in the wild and the signature for detecting that threat being applied to your IDS. During that lag time your IDS would be unable to detect the new threat.

Anomaly Based

An IDS which is anomaly based will monitor network traffic and compare it against an established baseline. The baseline will identify what is “normal” for that network- what sort of bandwidth is generally used, what protocols are used, what ports and devices generally connect to each other- and alert the administrator or user when traffic is detected which is anomalous, or significantly different, than the baseline.

Passive IDS

A passive IDS simply detects and alerts. When suspicious or malicious traffic is detected an alert is generated and sent to the administrator or user and it is up to them to take action to block the activity or respond in some way.

Reactive IDS

A reactive IDS will not only detect suspicious or malicious traffic and alert the administrator, but will take pre-defined proactive actions to respond to the threat. Typically this means blocking any further network traffic from the source IP address or user.

One of the most well known and widely used intrusion detection systems is the open source, freely available Snort. It is available for a number of platforms and operating systems including both Linux and Windows. Snort has a large and loyal following and there are many resources available on the Internet where you can acquire signatures to implement to detect the latest threats. 

There is a fine line between a firewall and an IDS. There is also technology called IPS – Intrusion Prevention System. An IPS is essentially a firewall which combines network-level and application-level filtering with a reactive IDS to proactively protect the network. It seems that as time goes on firewalls, IDS and IPS take on more attributes from each other and blur the line even more.

Essentially, your firewall is your first line of perimeter defense. Best practices recommend that your firewall be explicitly configured to DENY all incoming traffic and then you open up holes where necessary. You may need to open up port 80 to host web sites or port 21 to host an FTP file server. Each of these holes may be necessary from one standpoint, but they also represent possible vectors for malicious traffic to enter your network rather than being blocked by the firewall.

That is where your IDS would come in. Whether you implement a NIDS across the entire network or a HIDS on your specific device, the IDS will monitor the inbound and outbound traffic and identify suspicious or malicious traffic which may have somehow bypassed your firewall or it could possibly be originating from inside your network as well.

An IDS can be a great tool for proactively monitoring and protecting your network from malicious activity, however they are also prone to false alarms. With just about any IDS solution you implement you will need to “tune it” once it is first installed. You need the IDS to be properly configured to recognize what is normal traffic on your network vs. what might be malicious traffic and you, or the administrators responsible for responding to IDS alerts, need to understand what the alerts mean and how to effectively respond.

Wednesday, April 11, 2012

Basic things in Encryption


Goal of Encryption of Internet Traffic

  • conveys confidentiality to messages while in transit
  • changes readable text messages into something that cannot be read
  • discourages anyone from reading or copying the messages

Related Problem

  • if header information is not encrypted, traffic analysis is possible
  • traffic analysis - the analysis of header information in order to derive useful information from the headers

Encryption Components

  • an algorithm
  • a key

Encryption Algorithms

  • a series of steps that mathematically transforms plain-text or other readable information into unintelligible cipher text.
  • Cipher text - Data that has been encrypted. Cipher text is unreadable until it has been converted into plain text (decrypted) with a key.

Decryption

  • The inverse mathematical transformation, which transforms the encrypted cipher text back into something readable, is called decryption.

Encryption Algorithm - Input and Output

  • a key and plain text are input into an encryption algorithm
  • cipher text is output from the encryption algorithm

Encryption Keys

  • a bit string consisting of x number of bits. A 40 bit key is a string consisting of 40 bits
  • an encryption algorithm can use one of a large number of possible keys
  • the number of possible keys each algorithm can support depends on the number of bits in the key. The longer the key, the more the possible number of keys

Encryption Key Example

  • example - if the key length is 40, then 2 to the n, where n is the number of bits in the key, results in 1,000,000,000,000 possible key combinations, with each different key causing the algorithm to produce slightly d ifferent cipher output

Security and Encryption

  • encryption algorithms are considered secure if the security depends on only one factor - key length
  • security does not depend on secrecy, inaccessibility, or anything else, only on the key length
  • if this factor is true, then the only possible attack against the algorithm is a brute force attack

Brute Force Attacks and Security

  • all key combinations must be tried in order to find the correct key
  • the length of the key determines the possible number of keys available for selection
  • the longer the key length the longer it takes to discover which key will actually decrypt
  • specifying a long enough key length makes a brute-force attack non-feasible

Symmetric Encryption

  • identical keys are used to encrypt and decrypt the message
  • a message encrypted by one specific symmetric key can only be decrypted by using the same key, it can be decrypted with a different key

Symmetric Keys

  • a random bit string, n bits long
  • most often generated on the source computer

Advantages of Using Symmetric Encryption

  • the encryption process is simple
  • each trading partner can use the same publicly known encryption algorithm - no need to develop and exchange secret algorithms
  • security is dependent on the length of the key

Drawbacks of Using Symmetric Encryption

  • a shared secret key must be agreed upon by both parties
  • if a user has n trading partners, then n secret keys must be maintained, one for each trading partner
  • authenticity of origin or receipt cannot be proved because the secret key is shared
  • management of the symmetric keys becomes problematic

Problems with Management of Symmetric Keys

  • trading partners must always use the exact same key to decrypt the encrypted message
  • key exchange is difficult because the exchange itself must be secure with no intervening compromise of the key
  • management of keys is difficult as numbers of trading partners increases, especially when multiple keys exist for each trading partner

Public Key Cryptography as a Solution for Managing Symmetric Keys

  • public key cryptography simplifies the management of symmetric keys to the point whereby a symmetric key can be used not only for each trading partner, but for each exchange between trading partners
  • additionally, public key cryptography can be used to unambiguously establish non-repudiation of origin and receipt

Asymmetric Encryption - (Public Key Cryptography)

  • based on the concept of a key pair
  • each half of the pair (one key) can encrypt information that only the other half (one key) can decrypt
  • the key pair is designated and associated to one, and only one, trading partner

Asymmetric Key Pairs

  • consists of two keys - one private and one public
  • private key is secret and only known by the designated trading partner it belongs to
  • public key is published widely but still associated only with the designated trading partner

Asymmetric Key Uses

  • confidentiality
  • digital signatures
  • both uses depend on the association of a key pair with one, and only one owner of the keys
  • both uses depend on one of the keys in the key pair being secret from everyone but the owner of the key


Confidentiality Using Asymmetric Key Pairs (Encryption)

  • Trading Partner A desires to send a confidential message to Trading Partner B
  • Trading Partner A retrieves Trading Partner B's public key and encrypts the message with it

Confidentiality Using Asymmetric Key Pairs (Decryption)

  • Trading Partner B receives the message and decrypts the message with the secretly held, private key
  • The only key that can possibly decrypt a message that is encrypted with Trading Partner B's public key is Trading Partner B's private key

Digital Signatures Using Asymmetric Key Pairs (Encryption)

  • Trading Partner A desires to send a digitally signed message to Trading Partner B
  • Trading Partner A uses their own private key to encrypt a part of the message
  • Trading Partner A sends the encrypted part of the message to B

Digital Signatures Using Asymmetric Key Pairs (Decryption)

  • Trading Partner B receives Trading Partner A's message and obtains A's public key
  • Trading Partner B tries to decrypt the encrypted portion of Trading Partner A's message
  • If it decrypts, Then Trading Partner B knows it has to be from A because the only thing A's public key will decrypt is something encrypted with A's private key and only A has access to that private key

Real World Usage of Asymmetric Encryption

  • public key encryption algorithms are considerably slower than symmetric key algorithms
  • rarely used as encryption methodology for bulk messages or parts of messages
  • normally used in conjunction with a Message Integrity Check (MIC) or to encrypt a symmetric key, where the MIC or symmetric key is what is encrypted using public key encryption algorithms


Speed Comparison - Symmetric vs Asymmetric

  • software encryption using DES (symmetric key algorithm) is 100 times faster than software encryption using RSA (asymmetric key algorithm) - estimate provided by RSA Data Securities
  • hardware encryption using DES (symmetric key algorithm) is anywhere from 1,000 to 10,000 times faster than hardware encryption using RSA (asymmetric key algorithm)

Encryption Needs for Confidential Commercial Exchanges

  • for interoperability between two trading partners
  • standard encryption algorithm(s)
  • standard key length(s)
  • agreed upon beforehand or within an individual transaction

Issues

  • how secure is the algorithm?
  • how fast are current implementations of the algorithm?
  • availability of APIs and/or tools to implement the algorithm
  • frequency of use of algorithm with other trading partners
  • sufficient key length to discourage brute force attacks

Common Symmetric Key Algorithms

  • Data Encryption Standard - DES
  • Triple DES
  • RC2 and RC5
  • IDEA

Block Ciphers vs Stream Ciphers

  • block ciphers - take a set number of bits, typically 64 bits, and encrypts the them as a single block
  • stream ciphers - take and encrypt one bit at a time
  • Most ciphers belong to the block cipher class.

Data Encryption Standard - DES

  • most widely used commercial encryption algorithm
  • in the public domain, available to all
  • a U. S. government encryption standard
  • security is known and is dependent solely on the key length
  • data sequenced into 64 bit blocks prior to encryption, each block encrypted

Cipher Block Chaining (CBC)

  • recommended mode for using DES
  • each 64 bit block of data is exclusively OR'd with the previous block before encryption
  • gives added protection by making each cipher-text block depend on each other
  • changes in the cipher text can be detected

Brute Force Attacks against DES

  • DES specifies a 56 bit key, so there are 2 to the 56th possible keys
  • brute force attack means trying every single key (10,000,000,000,000,000) to decrypt 8 bytes of known cipher text into the corresponding plain text


Resources Required to Break DES Key

  • $1 million dollar hardware based, brute-force attack on DES takes approximately 3.6 hours to recover the DES key
  • $1 million dollar software based, brute force attack on DES takes approximately 3 years to recover the DES key
  • above figures attributed to B. Schneier, "E-Mail Security", John Wiley & Sons, 1995


Triple DES

  • variant on DES which encrypts message 3 times with 2 independent 56 bit keys
  • effective key length is 112 bits
  • brute force attack on Triple DES is not feasible

RC2 and RC5

  • RSA owned proprietary symmetric key algorithms
  • variable key length makes security configurable
  • RC2 is a block cipher (similar to DES) and should be used in CBC mode, RC5 is also a block cipher and should be used in CVC Pad mode
  • Both use 128 bit key but support key masking for configuration of key length

International Data Encryption Algorithm (IDEA)

  • a block cipher, in the mold of DES
  • uses a 64-bit block size and a 128-bit key
  • IDEA in CBC mode is the bulk encryption algorithm used by Pretty Good Privacy (PGP) which makes it the most widely used encryption algorithm for

Key Lengths and Secure Transactions

  • Algorithms that make a brute force attack not feasible
  • Triple DES with 2 56 bit keys
  • RC2 and RC5 with 128 bit keys
  • IDEA with 128 bit key

Recommendations on Key Lengths

  • Transactions of minimal or small value - 40 bit RC2 or 56 bit DES
  • Most commercial applications need a key length of 75 bits
  • High value transactions Triple-DES, IDEA or 128 bit RC2 or RC5

Conclusions

  • Encryption is the correct method to implement confidentiality for Internet traffic
  • Symmetric key algorithms should be chosen for encryption of confidential data
  • The more bits in the symmetric key, the less probable the compromise of the encrypted data

Sunday, February 5, 2012

What is Remote Login?

Let's say you're preparing a huge PowerPoint presentation for a big meeting on Friday. All of the PowerPoint files and PDFs and images that you want to use in your presentation are saved on the hard drive of your work computer. Thursday rolls around and you wake up with a nasty stomach virus. You don't feel well enough to go to the office, but you need to finish that presentation. Here's where remote login can help.

Until recently, virtual private networks (VPN) were the only way to remotely access work files from home. But VPN access isn't the same as accessing the hard drive of your work computer. VPN gives you access to the local area network (LAN) at your office. With VPN, you're only able to access your PowerPoint presentation files if you've saved them on the network, not just on your computer's hard drive.

Remote login, however, uses simple desktop sharing software to give you a "remote control" for accessing your computer -- and all of its software and hard drive files -- from any Internet-connected device anywhere in the world.

Remote login works exactly the same way as desktop sharing. In desktop sharing, there are two separate parties: the host computer and the remote user. To share a desktop, the host computer allows a remote user to view the contents of the host computer's desktop over the Internet. The host computer can also hand over keyboard and mouse controls to the remote user. With remote log-in, your home or work computer is the host and you (in this case) are the remote user.

Remote login requires three basic components:
  1. Software download
  2. Internet connection
  3. Secure desktop sharing network

For remote login to work, both the host computer and all remote users have to download and install the same desktop sharing software. Desktop sharing software typically includes two distinct programs:
The desktop sharing client that runs on the host computer
A viewer program that allows the remote user to view the contents of the host computer's desktop in a re sizable window

Remote login will only work if the host computer is powered on, connected to the Internet and running the desktop sharing software. Each time you open and run the desktop sharing software on the host computer, the software starts a new session. Each session has a particular ID and/or password that's required to remotely log in to the host computer. Once the session has been established, most desktop sharing software quietly runs in the background of the host computer until a remote login request is made.­

To log in to the host computer from home (or while traveling), you'll need to run your version of the same desktop sharing software and enter in the correct session ID or password. Or some services allow you to log in through a Web site. Once you're logged in, both computers will communicate with each other over a secure desktop sharing network. Access to this network can be free or subscription-based, depending on the service. While connected, you'll have access to keyboard controls, mouse controls, all software and all files on the host machine.

For security purposes, all packets of information that are sent over the network are typically encrypted on each end with secure shell (SSH) or 128-bit advanced encryption standard (AES) encoding. For added security, no session IDs or passwords are stored on desktop sharing servers; they're automatically generated by the host machine.

How VPNs work?

As a business grows, it might expand to multiple shops or offices across the country and around the world. To keep things running efficiently, the people working in those locations need a fast, secure and reliable way to share information across computer networks. In addition, traveling employees like salespeople need an equally secure and reliable way to connect to their business's computer network from remote locations.

One popular technology to accomplish these goals is a VPN (virtual private network). A VPN is a private network that uses a public network (usually the Internet) to connect remote sites or users together. The VPN uses "virtual" connections routed through the Internet from the business's private network to the remote site or employee. By using a VPN, businesses ensure security -- anyone intercepting the encrypted data can't read it.

VPN was not the first technology to make remote connections. Several years ago, the most common way to connect computers between multiple offices was by using a leased line. Leased lines, such as ISDN (integrated services digital network, 128 Kbps), are private network connections that a telecommunications company could lease to its customers. Leased lines provided a company with a way to expand its private network beyond its immediate geographic area. These connections form a single wide-area network (WAN) for the business. Though leased lines are reliable and secure, the leases are expensive, with costs rising as the distance between offices increases.

Today, the Internet is more accessible than ever before, and Internet service providers (ISPs) continue to develop faster and more reliable services at lower costs than leased lines. To take advantage of this, most businesses have replaced leased lines with new technologies that use Internet connections without sacrificing performance and security. Businesses started by establishing intranets, which are private internal networks designed for use only by company employees. Intranets enabled distant colleagues to work together through technologies such as desktop sharing. By adding a VPN, a business can extend all its intranet's resources to employees working from remote offices or their homes.

Sunday, October 23, 2011

What are the Advantages of Symmetric Encryption?


Symmetric encryption, also called conventional encryption, has been a mainstay in data transmission for many years. This method of message scrambling involves the use of a shared secret key which all parties in the data exchange must possess in order to decipher a message. Although asymmetric encryption has gained popularity in the Internet age, symmetric encryption offers some attractive advantages.
  1. Symmetric and Asymmetric Encryption

    • Asymmetric encryption uses a private key that is only known by the owner, and a public key that is available to everyone who wishes to communicate with the owner. Symmetric encryption uses one private key that each person in the exchange circle must know in order to encrypt and decrypt messages.

    Speed

    • Symmetric encryption is much faster than asymmetric encryption due to the shorter key lengths required for the proper security level. Asymmetric encryption needs longer key lengths to achieve the same security level, causing the encryption time to increase. In addition, asymmetric encryption produces longer encrypted messages, which take longer to transmit and decrypt.

    Simplicity

    • The symmetric encryption process is simple and uses standard encryption algorithms that are available to anyone. Each person knows the keys beforehand, as well as the algorithms used, and the encryption and decryption processes are easy to implement.

    Cost

    • Symmetric encryption provides excellent security at a lower hardware cost due to its simplicity. The algorithms are fairly simple and require less computing power to perform message encryption. Asymmetric encryption, on the other hand, uses complex algorithms which require much more computing power, resulting in higher hardware costs.

Saturday, October 22, 2011

How is data encrypted when stored in the cloud infrastructure?

How is data encrypted, both in use and at rest, when stored in the cloud infrastructure?

Most cloud providers automatically encrypt data in transit by requiring SSL connections on any Web browser, but whether this data is stored in encrypted containers is another matter. The best way to do things is to create a hybrid public/private cloud so that any cloud-based resources can sit behind the corporate firewall and be protected just as if they were inside your own data center. See Public And Private Hybrid Clouds: The Pros And Cons for more on this.

Most cloud vendors offer some kind of Virtual Private Network (VPN) protection of their environments, so that information is encrypted in transit and easily accessible via ordinary network shares. As an example, Verizon's Computing as a Service offers Cisco's AnyConnect VPN client that is launched from Internet Explorer.

Verizon's CaaS uses the Cisco AnyConnect VPN that works inside Internet Explorer to secure remote access to virtual resources.

Other cloud providers offer virtual firewalls from vendors, such as Vyatta, that connect to their twins inside a corporate data center, or work with traditional Cisco VPN gateways.

One of the numerous Amazon Web Services is its Virtual Private Cloud, which allows you to connect any of your Amazon-based cloud-based resources to your own premises. You can bridge your Amazon and on-premises networks, assign private IP address ranges, and route traffic from your applications running in the cloud to your internal security devices before reaching the Internet.

Tuesday, September 27, 2011

How to recover from forgotten the administrator password?

Forgot the administrator password? There are many ways to access a Windows installation if you forgot the administrator password. Today I’ll show you another procedure to reset the Windows password by replacing the Sticky Keys application. This program allows you to use the function keys SHIFT, CTRL, ALT, or the Windows key by typing one key after the other instead of pressing them simultaneously with the second key. The main advantage of this password reset method is that you don’t need third-party software; another plus is that it is easy to carry out because no Registry hack is required, as when you offline enable the built-in administrator.

Please note that resetting the password from an account other than the corresponding user account always means that the user loses the credentials stored in the Windows Vault, stored Internet Explorer passwords, and files that you encrypted with the Encrypting File System (EFS). Of course, if you have a backup of these credentials, you can restore them; likewise, if you have exported the private EFS key, you can import it again after you have reset the password. Like with all other solutions that allow you to reset the Windows password without having an account on the corresponding computer, you have to boot from a second operating system and access the Windows installation while it is offline.You can do this with a bootable Windows PE USB stick or by using Windows RE. You can start Windows RE by booting the Windows Vista or Windows 7 setup DVD and then selecting “Repair” instead of “Install Windows.”By the way, you can’t use the Windows XP boot CD for this purpose because its Recovery Console will ask for a password for the offline installation. However, you can use a Vista or Windows 7 DVD to reset a forgotten Windows administrator password on Windows XP.This works because Windows RE, which is based on Vista or Windows 7, will let you launch a command prompt with access to an offline installation without requiring a password.



TO RESET A FORGOTTEN ADMINISTRATOR PASSWORD, FOLLOW THESE STEPS:

Boot from Windows PE or Windows RE and access the command prompt. 
Find the drive letter of the partition where Windows is installed. In Vista and Windows XP, it is usually C:, in Windows 7, it is D: in most cases because the first partition contains Startup Repair. To find the drive letter, type C: (or D:, respectively) and search for the Windows folder. Note that Windows PE (RE) usually resides on X:. 

Type the following command (replace “c:” with the correct drive letter if Windows is not located on C:):

copy c:\windows\system32\sethc.exe c:\

This creates a copy of sethc.exe to restore later. 

Type this command to replace sethc.exe with cmd.exe:

copy /y c:\windows\system32\cmd.exe c:\windows\system32\sethc.exe 
Reboot your computer and start the Windows installation where you forgot the administrator password. 
After you see the logon screen, press the SHIFT key five times. 

You should see a command prompt where you can enter the following command to reset the Windows password (see screenshot above):

net user you_user_name new_password

If you don’t know your user name, just type net user to list the available user names. 
You can now log on with the new password. Its recommended that you replace sethc.exe with the copy you stored in the root folder of your system drive in step 3. For this, you have to boot up again with Windows PE or RE because you can’t replace system files while the Windows installation is online. Then you have to enter this command:copy /y c:\sethc.exe c:\windows\system32\sethc.exe

Sunday, September 25, 2011

Basics of encryption -Part 02


From this article onwards, I’m going to elaborate on types of encryption. Each of these types has something in common. That is the sender encrypts the set of data ( particularly a file) using a password or a key. When the receiver receives this encrypted file, he is able to use the file using a password/key that he posses. Encryption can be mainly divided in to three categories.
  1. Symmetric-key encryption
  2. Asymmetric-key encryption
  3. Hash functions
Symmetric-key encryption:
The sender and the receiver must have the same key/password. Or if the keys are not identical, they must be related to each other in a predefined specific manner.
Ex:- Sending a password protected zip file to a friend ( you protect the file with a password and tell the password to your friend).
This method is also called as a private-key method and it can be further devided in to two sub-categories.
  1. Stream cypher
  2. Block cypher
Stream cypher:
In a stream cypher, the file is converted bit by bit. For added security the actual message is combined with a keystream. The plaintext gets encrypted adding different cyphertext ( as discussed in the cypher section in the previous article).
Block cypher:
Block ciphers works on a set of bits. A set of bits gets transformed at a time.
Asymmetric-key encryption:
Also called a public key method. This method requires two types of keys,one is called the public-key and the other is called the private-key. The public-keys are distributed publicly. The private-keys only reside with the recipient. The sender who does the encryption should have the public-key which matches the receivers private-key. So when the sender encrypts the file using a public-key, only the receiver with the matching private-key can decrypt it.
Hash functions:
Hash encryption is an one way process and it cannot be reversed. So whats the use of it? Lets take an example from the real world to understand this.
The password for users in a linux operating system was used to be stored in the /etc/passwd file. But the password that was stored in this file was not the real password, but it’s hash value( generated using some unique algorithm-a hash function).When a user needs to login to the system, he enters his user name and password. The password that the user entered is fed to the hash function and the output from the hash function is compared with the hash value in the /etc/passwd file. If the two hash values match, the user was allowed to login to the system . The advantage of this method is the real password is never stored in the computer. So a hacker has no use of the file that contains the password( except if he is using a brute force method).
The aim of these two articles was to give you a basic understanding about cryptography and encryption. I hope you all got something out of it. All your comments are welcome…! .