Tuesday, February 16, 2016

Allowing (Unblock) Self-signed Java Applet in Java 7 Update 51 and Later

Java Security

Starting from Java 7 Update 51, Java does not allow users to run applications that are not signed (unsigned), self-signed (not signed by trusted authority) or that are missing permission attributes. This is a good security feature.

The older Java (1.4 to 1.6) are able to run unsigned applet without any prompt. However for self-signed applets, a prompt is displayed and you must explicitly tell the Java runtime that you trust the applet.

Whether it is required to add the website address to the Trusted Site zone depends the IE version. For IE10 and above, you must add the website IP address to the Trusted Site zone for a signed applet to run without hiccups.


Applet for Internal Usage (Intranet)

On the other hand, if you have developed an application for internal use, it is not worth the effort and cost to purchase a verified certificate by a trusted authority since the users can trust you and that your application is not going to perform anything malicious.

The following article illustrates how you can create a self-signed certificate and install in the users' machine so that their browsers do not complain that your java applet has been blocked, or that the applet poses security risks every time the user accesses the page.


Java Security Default Behaviour (Java 1.7 Update 51 onwards)

By default, the following dialog is displayed when an unsigned applet is accessed.


Exception Site List

Nevertheless, you can still allow an unsigned applet to be executed by adding a URL to the Exception Site List.

However, the browser will still nag at the user every time the user brings up the page.


This security feature may seem like a nuisance for those who know the apps can be trusted as it was developed by their own developer. Because the applet is not signed, so it keeps nagging. Therefore, the developer could self-sign the applet, create a self-signed certificate, and then distribute and install the certificate on the users' computer.


Java Certificate Repository (use Signer CA for self-signed certs)

Do not confuse yourselves with Microsoft Windows Certificate because this is the Java Certificate which is stored in a different repository from the Windows certificate repository.

The Java Certificate repository is located at:

C:\Users\<user name>\AppData\LocalLow\Sun\Java\Deployment\security\trusted.certs

for certificates verified by a Trusted Authority

and

C:\Users\<user name>\AppData\LocalLow\Sun\Java\Deployment\security\trusted.cacerts

for self-signed certificates (Signer CA, Signer Certificate Authority, where the signer is the authority)

If you import the self-signed certificate into trusted.certs, it is ignored and the applet will still be blocked.



Permission Attributes

You may remove the URL from the Exception Site List if the signed jar manifest contains the appropriate permission attributes. If the permission attributes is not set, and the URL is removed from the Exception Site List, the self-signed applet will be blocked as follow even after the cert is imported into the Signer CA repository.












Therefore, set the jar manifest appropriately as follow with ant build tool,

    <jar destfile="applet/Abc.jar">
      <manifest>
        <attribute name="Permissions" value="all-permissions"/>
      </manifest>
     ...
     ...
    </jar>



Before Signing the Applet JAR

Generate a key pair in the Java key store so that this security key pair can be used to sign the applet as well as create a public certificate to be distributed.


Generate Key Pair

C:\Users\<user-name>\AppData\LocalLow\Sun\Java\Deployment\security>keytool -genkeypair -alias Aliasname -keyalg DSA -keysize 1024 -dname "CN=PublisherName, OU=LineOfBusiness, O=CompanyName, C=Country" -keypass keypwd -storepass storepwd -validity NoOfDaysToExpire

This will create a file named .keystore in the Users\<user-name> folder. After this file has been created, you may sign the applet Jar and create (export) a public certificate file.


Create Self-signed Public Certificate File

C:\Users\<user-name>\AppData\LocalLow\Sun\Java\Deployment\security>keytool -exportcert -storepass storepwd -alias Aliasname -file mycert.csr

Certificate stored in file <mycert.csr>

Copy this file to the client computers, then import it into the Java Signer CA repository.


Import Certificate into Signer CA Repository of Client Machine

C:\Users\<user-name>\AppData\LocalLow\Sun\Java\Deployment\security>keytool -importcert -keystore c:\users\<user-name>\appdata\locallow\sun\java\deployment\security\trusted.cacerts -storepass ""  -alias Aliasname -file mycert.csr
Owner: CN=PublisherName, OU=LineOfBusiness, O=CompanyName, C=Country
Issuer: CN=PublisherName, OU=LineOfBusiness, O=CompanyName, C=Country
Serial number: 56c2a5d8
Valid from: Tue Feb 16 12:30:16 SGT 2016 until: Fri Feb 13 12:30:16 SGT 2026
Certificate fingerprints:
         MD5:  29:4F:49:3B:5D:44:4D:D4:11:BA:EB:0E:F7:9A:63:76
         SHA1: 67:6A:B8:68:0F:C2:19:DD:CE:F4:C8:C0:46:C4:13:D5:AF:85:39:21
         Signature algorithm name: SHA1withDSA
         Version: 3
Trust this certificate? [no]:  yes

Certificate was added to keystore



 Run Applet First Time

Once it is approved (check "do not show this again"), it will not prompt again.
















That's it.






Sunday, November 8, 2015

Brute Force a WPA / WPA2 Wireless Network with Aircrack

Note:

This article is written for educational purposes only. It is illegal to hack a network that does not belong to you. You may get yourself in trouble, say, if the network you are trying to get into, logs packet injections from your machine, the digital signatures you left behind is the traceability lead. Therefore, please do not commit crime.

This test was done on Kali Linux, on VMPlayer. The method described in this article cannot hack a WPA / WPA2 wireless network if there is no client connected. Also, it is difficult to obtain a handshake if the client signal is very weak.

Step 1: Check Your Wireless Adapter

root@kali:~/test# airmon-ng

This command lists your wireless adapter, if you have one. On a virtual machine, you may experience that the wireless adapter cannot be detected. In this case please read how-to-put-wireless-adapter-in-monitor

Step 2: Check for conflicting processes that get in the way

You need to kill those processes because they will cause trouble when you run aireplay-ng, i.e. you may not be able to capture a handshake.

root@kali:~/test# airmon-ng check

Found 2 processes that could cause trouble.
If airodump-ng, aireplay-ng or airtun-ng stops working after
a short period of time, you may want to kill (some of) them!
-e 
PID Name
3179 dhclient
3260 NetworkManager

Step 3: Kill these processes

airmon-ng check kill

Step 4: Put your wireless adapter in monitor mode

airmon-ng start wlan0

Step 5: Pre-scan Available Wireless Network

airodump-ng mon0

This displays a list of wireless networks with some details such as signal strength, channel number, AP mac, network name, connected clients mac addresses, etc.

Jot down the channel and mac address of the network you intend to crack. After that, you can exit by pressing Ctrl-C or q.

Step 5: Monitor and capture Network Packet and Handshake to a File

airodump-ng -c 11 -w captured --bssid <AP mac address> mon0

This will monitor and wait for handshake. The channel is 11 but yours may be different. File prefix is "captured". Just leave it running and do not exit, yet.

Step 6: Injecting Network Packets to Force the Client to Re-Associate with the AP

Open a new terminal and run the command:

aireplay-ng -0 10 -a <AP mac address> mon0

Attack mode -0 is specified for WPA / WPA2 (-1 is only good for WEP). Run this command and take note of handshake signal captured on the other terminal where airodump-ng was executed. Rest for a few seconds in between each attack, until a handshake is captured, then stop both aireplay-ng and airodump-ng (on the other terminal).

This attacks attempt to kick the connected client out. When the AP tries to reconnect with the client, your machine will have the chance to get a handshake, which contains a public key and private key signatures that allow the password to be cracked.

The handshake is captured in a file you specified in airodump-ng, i.e. -w captured. So, the file is "captured-01.cap" if Step 5 is run for the first time. If airodump-ng had exited and run for the 2nd time, the file is "captured-02.cap", so on and so forth. Take note of the file name that contain the handshake.

In the occasion where the client signal is weak, it may be easier by specifying the cilent MAC address:

aireplay-ng -0 10 -a <AP MAC address> -c <client MAC address> mon0

Step 7: Crack the Password

You can do this step on another day without the need to be around the targeted AP network. Notice if the password is long enough, it is very difficult to crack. The following are the reasons why.

Calculating how long you need to run all password combinations by brute force:

Depending on your CPU power, the number of password tests per second varies. If the password has 8 alpha-numeric character combinations, there are 36 possible characters that can fill each character, that makes it 38^8 number of combinations. i.e. 2821109907000 possible combinations! If the CPU power is 1000 passwords per second, you need 89.4 years to completely brute force all passwords!

Therefore, it is encourage to use long passwords and make use of lower case, upper case, numerics, or even symbols such as +, -, %, etc in your password. A 16 character password with lower and upper case, and numerics combinations has a total of 62^16 = 4.77x10^28 combinations. Even with a CPU power of 1 billion passwords per second, you will need 1.5 trillion years to brute force all passwords!

Therefore, the use of a good password list may crack faster, as people tends to be negligent and assigned password that is easy to remember.

Anyways, these are the commands that are commonly used:

By password list:

aircrack-ng -w /mydir/wordlist captured-01.cap

The ability to crack is as good as the quality of the wordlist.

By word crunching:

crunch 6 8 0123pasword | aircrack-ng -a 2 captured-01.cap -e <AP network name> -b <AP mac address> -w -

The AP mac address can be omitted. The crunch command generates passwords combination from 6 to 8 characters using the characters specified "0123pasword". In this case there are a total of 11^6+11^7+11^8 = 235617613 combinations. Need 2.7 days to test all passwords for a 1000 words/sec CPU power.

Word crunching is used if you know some of the characters that are used in the passwords.

man crunch for more options.

By brute force using john the ripper and remember the session:

john --incremental=all --session=MyBruteSession --stdout | aircrack-ng -a 2 -e <AP network name> captured-01.cap -w -

To restore previous session and continue with the last tested password:

john --restore=MyBruteForce | aircrack-ng -a 2 -e <AP network name> captured-01.cap -w -

That's it.

Friday, July 31, 2015

Install Android 4.3 on VMWare Player for Dummies

The followings are quite self explanatory.







































Unlike Android 4.0 on VMWare Player, you need not edit the vmx file in order to get the internet working.





Monday, February 9, 2015

Word 2010: Create Your Own New Multilevel Headings

There are times you wish to create your own multilevel headings such as the Appendix. Example content of document:

1. Level 1 Heading
1.1 Level 2 Heading
1.1.1 Level 3 Heading

2. Level 1 Heading
2.1 Level 2 Heading
2.1.1 Level 3 Heading
2.2 Level 2 Heading
2.2.1 Level 3 Heading
2.2.2 Level 3 Heading
...
...
10 Level 1 Heading
10.1 Level 2 Heading
10.2 Level 2 Heading

Appendix A - Level 1 Appendix Heading
A.1 Level 2 Appendix Heading
A.1.1 Level 3 Appendix Heading

Appendix B - Level 1 Appendix Heading
B.1 Level 2 Appendix Heading
B.1.1 Level 3 Appendix Heading

If you happen to read online reference that says you have to make use of the built-in Headings (i.e. Heading 1, Heading 2, Heading 3,.... Heading 9) in order to benefit the magic properties of multilevel headings and that they do not work well in Appendix, that is not entirely correct.

While there is no harm assigning Heading 1 through Heading 5 for the main body and Heading 6 to Heading 9 for the Appendix. You can actually define an entirely new set of multilevel headings of your own without affecting the built-in headings.

Here's How:

Firstly, start by create a few new paragraph styles for the appendix headings. For example, if you have 3 levels of appendix headings, create 3 new styles and name them as follows:

Appendix 1
Appendix 2
Appendix 3

When creating these styles, choose "Linked (paragraph and character)" for Style Type, and "(no style)" for Style Based On. Choose the correct Outline Level for the paragraph settings.  Configure your favorite fonts, size, colour, etc. Leave the numbering format alone for the moment.

Then, select the text in the document where you wish to assign the heading, Appendix 1. Assign it.

Next, change the numbering format as follows:


Click on the multilevel heading as shown above. This is where you get the multilevel heading features.

The selected text will change to as follow:


Not to worry, as this is the default multilevel heading numbering format.


Then, click on "Define New Multilevel List...". The following will be shown:


Click on the level you wish to modify. In this case, Level 1.

Click on level 1,
  Link Level to style: "Appendix 1"
  Number style for this level: Choose A, B, C,...

Click on level 2,
  Link Level to style: "Appendix 2"
  Number style for this level: 1,2,3...

Click on level 3, Link Level to style: "Appendix 3"
Click on level 4, Link Level to style: "(no style)"
Click on level 5, Link Level to style: "(no style)"
..
Click on level 9, Link Level to style: "(no style)"

The final result will be as follow:


Click OK. It is done. Now you can make use of the Appendix headings you have just created. The built-in Headings 1 to 9 will still work. Enjoy!