Showing posts with label user. Show all posts
Showing posts with label user. Show all posts

Friday, September 29, 2017

User behavior related work

User behavior related work


Many enterprises already recognized the importance of protecting against various threats that anti viruses cant predict but also the high probability of inside-out threats that pass undetected. Event if a threat is detected, most organizations arent equipped to respond effectively. Because of that, different user behavior based security software has been built and usually named under a general term User and entity behavior analytics (UEBA) software. It can be defined as: "Analysis of the behaviors of organizations employees, outsiders connected to their networks (such as third party contractors) and flagging security vulnerabilities across organizations assets that hold sensitive data.".

The difference between UEBA and the rest of the similar security software is that it usually can quickly identify a threat or an exploitable asset and then take action to remediate security risks across the entire infrastructure. Here Ill list a few examples of some software for different purposes that offer such features.


SentinelOne
Software that can be deployed across Windows, OS X and Linux endpoints along with Linux Ubuntu management server. They offer:

  • monitoring kernel and user space (files, processes, system calls, memory, registry, network etc.). More details can be found in their technical brief.
  • rapidly eliminating threat by killing malicious processes, rolling back manipulated files, disconnecting compromised devices,
  • real-time attack forensic analysis.
Niara
Platform that seems to be supporting Windows OS only. They offer:
  • monitoring following data sources: VPN, FW, IPS/IDS, web proxy, email logs,� packets, DNS logs, Active Directory logs, �DHCP logs,
  • detecting privilege escalation, credential violations, internal reconnaissance, lateral movement, abnormal access to high value resources, command and control, exfiltration,
  • alerts classified by severity and attack stage.
Varonis
Platform that supports Windows & NAS, Exchange, Active Directory, SharePoint, UNIX/Linux, Office 365. Mostly offers detecting security gaps and insider threats by tracking changes to important configuration files, access to sensitive files, malware, privilege escalations, access denied events and more. Also includes:
  • monitoring files and emails,
  • full visibility on permissions (folder, mailbox, sharepoint),
  • real-time alerts and comprehensive auditing.
Blindspotter by Balabit
Platform contains their own implementation of syslog-ng log management solution but doesnt offer much information about the data sources. Their technical documentation can be found here, and the features they offer include:
  • analyzing biometric information (typing style or typical mouse movements),
  • automatic notifications based on top suspicious activities.
IBM Security Trusteer
This solution helps in protecting online banking sites against account takeover, fraudulent transactions, and can detect end user devices infected with high risk malware. It includes:
  • analyzing biometric information (subtle mouse movements and clicks),
  • possible integration with mobile devices for analysis of malware infections, root and jailbroken information, accurate geolocation and Wi-Fi security status.
  • protection of web browser sessions to prevent tampering of customer transactions,
  • prevention of phishing attacks, malware infections and removal of existing malware,
  • protection against phishing of login credentials and payment card data.
Gurucul
This threat analytics platform offers insight into endpoints, applications, devices and users. Its benefits are:
  • identifying and predicting malicious insiders and comprised accounts
  • detecting and blocking fraud by proactively alerting on anomalous behaviors,
  • real-time contextual view of attacks and detailed reports


download file now

Read more »

Saturday, September 23, 2017

Ubuntu Login as root user

Ubuntu Login as root user


In this article, I will show you how to login as root after installing Ubuntu system.

By default the root user on Ubuntu doesnt have password, so to login as root you must set password for it using this command:

sudo passwd root

The system will ask you to input your current login user password, after that you could set the password for root.

Now, you want to login as root, just type command:

su root


Notice: The bash symbol in terminal for normal user will be the symbol $ and after logging in as root it will become #

For instance:
approved user: approved@approved-X556UAM:~$
root user        : approved-X556UAM:/home/approved#


 
Good luck.

Source: https://askubuntu.com/questions/91598/how-do-i-login-as-root


download file now

Read more »

Friday, September 22, 2017

User behavior logging

User behavior logging


In this blog post some ways to examine Linux operating system without using any additional (third party) programs or tools are explained. There are a number of Linux distributions but I will focus primarily on Debian and Debian based distributions. By collecting all the available information it is possible to track and log user behavior. Post consists of two parts: default system logs and other aspects which could be monitored.

In this part of the post some of the significant existing Linux system logs for user behavior are listed and explained:

  • /var/log/messsages - contains general system activity and non-critical messages like user logins, kernel messages, IP firewall packet logging and so on. This log file doesnt exist on Debian Linux distributions, so instead syslog is used.
  • /var/log/syslog - contains all the messages except the authentication related ones. By analyzing few, I found only kernel and thermald messages. Each line contains: datetime, hostname, program that generated the message, process id and log message.
  • /var/log/auth.log - contains system authorization information including user logins through display and login managers, sudo access requests, authentication mechanism for crontab, policykit system daemon etc. This log file is found on Debian Linux distributions, but some other use /var/log/secure instead.
  • /var/log/btmp - keeps track of failed login attempts. It is a binary file and can be read using last command.
  • /var/log/dpkg.log & /var/log/yum.log - contain messages about installs or upgrades for various package managers.

It is important to point out that not all Linux distributions have those logs enabled. /etc/rsyslog.conf file controls what goes inside the log files while /etc/rsyslog.d/*.conf configuration files control what goes in log directory and where that directory is (default value is /var/log). 

Also, log files can be easily modified or deleted. One solution is to set the log files to "append only" with chattr +a, but an attacker can gain root access so it is better to send logs to another host.


Other ways for tracking user behavior

Integrity checking is another way to detect changes in the system by looking for changes in the MD5/SHA1 checksums of the key files in the system. Those checksums need to be calculated periodically and compared with previous values. In such way inotify tool works by monitoring individual files or directories. It is important to check metadata such as permissions and ownerships, not just changes to file contents.

Besides monitoring logs for package installs, browser extensions are almost equally good for tracking user behavior. This can be done by checking integrity of directory where browser stores plugins, for example on Google Chrome it is ~/.config/google-chrome/Default/Extensions/ but on Mozilla Firefox it is /usr/lib/firefox-addons.

Running programs are easy to track and analyze because Linux contains virtual filesystem /proc with all process information. Directories inside /proc correspond to an actual process ID and by using command such as ps ax we can match processes with the associated process ID. Each of these directories contain information about command line arguments, CPU, current working directory, environment variables, links to the executables and library files of the process, memory held and process status. Directory /proc contains a lot more system information that can be analyzed such as: filesystems, IDE devices, memory map, I/O ports, general network information, parallel ports, partitions, general kernel behaviors, network core and interrupts.

Keyboard is the most used device by the user so that should be logged too (keypress and speed). There are also shell commands which are sensitive part of all Unix systems. They can be monitored in several ways but one of them is to use the command history. However, there are way too many ways to execute a command in any Unix system so it is not possible to monitor commands completely.

Since mostly users browse same websites daily, it can be useful for determining users behavior to log website visits. That can be done using rndc querylog which can log all DNS queries or using tcpdump and filtering only DNS queries (port 53).

Those are some of the ways to examine the status of some system and by that we can try to track user behavior. Also, there are some other parts of the system that are not mentioned but that is because I currently dont find them significant for purpose of the system I am building.


download file now

Read more »

Google Analytics User Conference G’day Australia

Google Analytics User Conference G’day Australia


The Australian Google Analytics User Conference is worth clearing your diaries for, with some of the most well-known and respected international industry influencers making their way to Sydney and Melbourne to present at the conference this September.

Hosted by Google Certified Partners, Loves Data, you�ll be learning about the latest features, what�s trending and popular, best practices and uncovering ways to get the most out of Google Analytics. Topics covered include: making sure digital analytics is indispensable to your organisation; applying analytics frameworks to your whole organisation; improving your data quality and collection; data insights you can action; and presenting data to get results.

Presenting the keynote is Jim Sterne, Chairman of the Digital Analytics Association, founder of eMetrics and also known as the godfather of analytics. Joining him are two speakers from Google in the US: Krista Seiden, Google Product Manager and Analytics Advocate and Mike Kwong, Senior Staff Software Engineer.

Other leading international industry influencers presenting at the conference include Simo Ahava (Google Developer Expert; Reaktor), Chris Chapo (Enjoy), Benjamin Mangold (Loves Data), Lea Pica (Consultant, Leapica.com), Chris Samila (Optimizely), Carey Wilkins (Evolytics) and Tim Wilson (Web Analytics Demystified).  

Expect to network with other like-minded data enthusiasts, marketers, developers and strategists, plus get to know the speakers better during the Conference�s Ask Me Anything session. We�ve even covered our bases for those seeking next-level expertise with a marketing or technical masterclass available the day before the conference. Find out more information about the speakers and check out the full program.

Last year�s conference sold out way in advance and this year�s conference is heading in the same direction. Book your tickets now to avoid disappointment. 

Event details Sydney
Masterclass & Conference | 8 & 9 September 2015

Event details Melbourne
Masterclass & Conference | 10 & 11 September 2015

Posted by Will Pryor, Google Analytics team


download file now

Read more »

Tuesday, September 19, 2017

Top 5 Best Youtube Tricks Every Internet User Should Know

Top 5 Best Youtube Tricks Every Internet User Should Know


Youtube is the most pouplar video sharing websites. We all many videos in youtube for diffrent reasons. Here I tell you some aweome tips and tricks that can increase your knowledge about youtube. So try all this tips and tricks with your pc. There are many secrets and hacks in youtube that probably we dont know yet.
youtube tricks


Best 40 Facebook 2014 Hacks ,Tips & Tricks that Make Your Facebook Life Better

Top 5 Youtube Tricks for Every Internet User

1. Download Youtube Video
This is one of the most popular tricks for Youtube. If you want local copy of youtube video for PC and android Mobile, this trick help you.
You just need to add ss before. Below you see a example how you download youtube video.
download youtube video


https://www.youtube.com/watch?v=h01Y40j9_r0


Would now change into

https://www.ssyoutube.com/watch?v=h01Y40j9_r0


2. Bypass Regional and Age Restrictions
Sometimes youtube gives you error like this video not avalaible in your country or age restrictions.
bypass restrictions in youtube

Here is a solution.
https://www.youtube.com/watch?v=h01Y40j9_r0


Would now change into

https://www.youtube.com/v/h01Y40j9_r0

3. Youtube TV website for PC (Beautiful and Clean Youtube)
Now with Youtube TV you can control youtube website from Keyboard-only. This whole website is controlled by Keyboard. youtube.com/tv give you tv experiance in your PC.
youtube tv

In this website all youtube categories comes in very beautiful animation.
If you want something new from Youtube this is. In here you see clean interface. Not any commentbox,suggestion or ad. If you want youtube video without ads try this.

4. Play the Snake Game In Youtube
Ya this is true when you play youtube video you can also play snake game on youtube. When you see loading sign press UP arrow key. Now the loading sign turn into snake game. This is so cool tricks ,so try and prank your friends with this trick.
youtube snake game


5. Youtube Search Easter Egg.
When you search these easter eggs in youtube. Youtube responses diffrently. This thing is prankable when you wanna something new with only youtube searches.

"Use the force luke search" (your mouse moves things around)
"Beam me up Scotty" (search results "transport" on the page)
"Doge meme" (all comic book sans)

"Do the Harlem shake" (the page literally does the Harlem shake�with soundtrack)



Try all this trick and if you got any problem contact me at Facebook.


download file now

Read more »

Friday, September 15, 2017

Using grep to Unearth Old Windows User Names 7 30 08

Using grep to Unearth Old Windows User Names 7 30 08


Identifying Deleted User Accounts in Windows


I was recently presented with three laptop computers suspected as stolen. My task was to identify the owners. I chose to use a Linux forensic boot disk (one that would not automatically mount the partitions) to conduct the examination to avoid disassembling the computers to access the hard disk drives.

It became apparent on the first computer that the original user account(s) were deleted. There was a major discrepancy between the single user account (in one of the suspects names) and in the installation date of the Windows Vista OS.

After studying Internet Explorer index.dat files recently, I decided to target deleted index.dat content. IE index.dat files contain the usernames of the active user browsing the web with Internet Explorer, as well as some local file system activities. I used the following command from the Linux terminal to fish for old user account names:

$ tr [:cntrl:] < /dev/sda | grep -abE --colour=auto (((:[0-9]{16,16}|Visited):[[:space:]])|Cookie:).+@

The command, broken down, does the following:
  1. tr [:cntrl:] - translates control characters to line feeds to keep the grep memory buffer from exhausting.
  2. < /dev/sda - feeds the raw data from device sda (the laptop hard disk) into the translate command. The device may be substituted with any file, such as a raw disk image.
  3. | grep -abE --colour=auto (((:[0-9]{16,16}|Visited):[[:space:]])|Cookie:).+@ finds the Internet Explorer cookie and history index.dat data that contains user names. The The hits are in color to help them stand out and the results can be redirected to a text file by appending the command with "> grep.results.txt". Broken down further:
  • grep -abE : a=treat binary as text; b=show byte offset; E=treat as extended regular expression
  • --colour=auto : show regex matches in color
  • (((:[0-9]{16,16}|Visited):[[:space:]])|Cookie:).+@ : Match expressions ":<16>: @" or "Visited: @" or "Cookie:@" where is any name of one character or more.
Example of Command Output:

254468840::2007052620070527: user@:Host: cis.cuesta.edu
286125672:Cookie:user@www.ibm.com/rc
161464680:Visited: user@http://encarta.msn.com/proscribed.html

The rest of the story

I analyzed the hits and observed user names inconsistent with those in the Vista /USERS directory. Further examination of the new user names showed they existed previous to the current user account (as determined from the index.dat date code), and urls for the users MySpace page. The newly discovered user was contacted through his MySpace page and identified the computer as stolen in June, 2007.

This a simplified discussion of the full process, which included examining the file system to determine existing users using The Sleuthkit. The purpose of the article is to demonstrate how grep can be used from a boot CD or USB device to locate Windows artifacts that show deleted accounts that can be used to identify the account holders.

In this case. the hard disk drive being examined was never mounted. Grep searches can be directed against unallocated sectors through a similar process which I will discuss at a later time.


download file now

Read more »

User behavior data extraction in Linux OS

User behavior data extraction in Linux OS


In this post, a short intro about my seminar in masters degree programme is given. The topic that Im working on is "User behavior data extraction in Linux OS" which includes gathering useful data about user actions, parsing and analyzing them.

The purpose of the system is to gather all information such as global system messages, user logins, background daemons, package installs, browser and keyboard usage, shell commands, runtime system information, file integrity and so on. Then, by using machine learning, it might be possible to develop a system that can detect anomalous user behavior. Such system would try to prevent any unauthorized access by analyzing users current activities.

The following activities and their approximate duration are planned:

  • search for similar software (5%)
  • Linux logging analysis (10%)
  • finding all options to track users behavior (15%)
  • definition and design of desired system (15%)
  • implementation in Python programming language (40%)
  • testing systems functionality and security (15%)




download file now

Read more »

Sunday, September 10, 2017

Top 10 Windows Software for Every Windows User

Top 10 Windows Software for Every Windows User


Windows PC  is one of the best PC comparing another PC or OS. Windows is customizable and run smoothly. In here we make a list of software, these softwares is important  for every PC. We make a list that can satisfy every windows user,because in this list you find all important software that every windows user wants. 
top 10 windows software
Top 10 Windows Programs/Software for every Windows User
1. Avast
Avast is Antivirus software ,this software make your computer secure from hackers. Avast User Interface is good. You find lots of new features in new version of Avast. If your tired from virus and trojans, download and install avast in your PC. I think your all security problem solved when you install Avast Antivirus Software. 
avast for windows
Download Avast Antivirus

2. Maxthon Web Browser
Many guyz think why I mention Maxthon Browser. I really like Maxthon from its functionality and features. In this browser you found lots of extensions preinstalled. Your own cloud storage in Maxthon when you make a account.
If you dont much about Maxthon Web Browser follow my Guide for Maxthon Web Browser.
maxthon browser for windows
Download Maxthon Browser

3. LastPass
This is very important tool when you forget your password. With this tool you dont need to remember your diffrent social and website passwords. LastPass is a extension or add-on that works with Web Browser. LastPass is avalible for all Web Browser like Google Chrome,Firefox,Maxthon and etc.
lastpass
Download LastPass

4. Rainmeter
Rainmeter is perfect way for customize your desktop. This is not a customize toll this is more. Rainmeter run all widgets in realtime. You find lots of skins in Internet. Rainmeter organize your desktop as advance user.
Find More About Rainmeter and Download Rainmeter Skin


5. CCleaner 
CCleaner clean your all computer junks files and run your computer fastly. If your computer run slowly. You must have tried this. This software clean your in many ways like deleting cookies ,defraggler,history,temporary files and many more ways.
ccleaner
Download CCleaner

6. XBMC : Media Center
XBMC is a open source media center for playing Movies and Music. You experianced something new in this media center. This player is theatre software. 
You found lots of add-ons in this XBMC. XBMC is like a whole world once you installed it you dont need to get out from this.
Download and Know More about XBMC



7. Free Download Manager
Free download manager supports all downloads including torrents Files. FDM preview video and audio files when your downloading is not full complete. Control remotely ,you can stop or start any downloading from anywhere. FDM is best download manager for Your Windows.
Download Free Downlaod Manager

8. 7Zip
7 Zip extract  and compress all type of files. With 7 Zip you can compress large files into one small file. 7 Zip is freely avalible for all windows users.
7zip
Download 7 Zip

9. Picasa
Picasa is not a professional tool but it is a great tool for photo editing. With picasa you make collage photo and slideshow. Picasa also backup your all photos to the Google Cloud. Picasa is also a great Photo Viewer.
picasa software for windows
Downlaod Picasa

10. Sumatra Reader
Sumatra is best way for reading PDF reader. How sumatra is best from Adobe Reader. Sumatra is not juts PDF reader, with sumatra you read PDF,E-PUB,MOBI,CHM,XPS and much more.
sumatra pdf reader for windows
Download Sumatra Reader

This is top 10 Windows Programs that every Windows user needs. Try all of this if you like my work thanks to me at Facebook.


download file now

Read more »

Saturday, September 9, 2017

SUPER USER PART 4 রুট করুন আপনার Xiaomi Redmi Note 3 Pro ফোনকে।

SUPER USER PART 4 রুট করুন আপনার Xiaomi Redmi Note 3 Pro ফোনকে।


Xiaomi Redmi Note 3 Pro ????? ??????? ????? ???? ????  ???? ???? ?????? ????? ???? ?? ????? ?? ?????????? ????? ???? ???? ??? ?? ????? ???? ???? ?????? ??? ?????, ?????? ??? ???? ??????? ???? ??? ???? ??????? ????????????? ???? ??? ????? ??? ?? ????????
??, ???? ??? ??? ?????? Note 3 Pro ?? ??? ??? ????
???? ? ?????? ???????? ????? ??? ????? ????
????? ???? ???? ???? ??????? ??? ????

?? Root file for kenzo?
?? TWRP Recovery for Kenzo?

Step 1:
?? ?? Download ??? ???? Extract ??? ???? ??? Extract ??? ??????? ????? ???? ?????, Beta-supersu ??? lazyflasher  ???? ?? ???? ???? ????? ????? Internal Storage  ? ?????????? ???? ????
???? ?? ???? ?? Extract ??????? Extract ??? ???? ???? Adb, fastboot & Recovery ???? ??????
Step 2:
???? ????? ????? ????? ???? USB ?????? ???? ????? ??????? ??? ????? ???? Setting  ? ???? Additional Setting  ????? Developer Option ?? On ??? USB debugging  ??? ???? (Setting>additional setting>Developer Option> USB debugging)?
Step 3:
�TWRP Recovery for Kenzo�  ?????? ?????? Extract ???????? ?? ???????  ???? Keyboard ?? �Shift key� ???? ??? ???? ?? Right button ? ????? ???? �Open command window here�  ????? ?????, ????? ????? ?? ??? �command prompt� open ????

????? command prompt ? ????? ???? command ???? ????
Command No 1: adb devices
?? command ?? ???? ????? ???? ???? ??????? ????? ???? ?????? ????? ???? ???? ???? ?? ??? ???? Allow ?????? ????? ????? ?? ????? ???????? command prompt show  ?????

Command No 2: adb reboot bootloader
?? command ?? ???? ????? ???????? ????? ???? Fastboot Mode ? ???? ????
Command No 3: fastboot  flash recovery twrp-3.0.2-2-kenzo.img
???? Twrp recovery ?? flash ??? ?????
Step 3:
????? usb disconnect ??? ??? ?? Power button + volume button ?????? Long press ??? ????? ??? mi logo ?? ???? ?? ??? Power button ?? ???? ???? ?????? ?????? Twrp open ??? ???? ??? ???? ??? ?? window ???? ???? ???? ?????? ??? ???? ????? ??? ???? ???? ??????
Step 4:
???? Twrp recovery ???? �Install�  option ???? Press ???? ????? Internal Storage ?? ???? ??? ??????? ???? ????? ???????????? ???? ????? Internal Storage ? ???? Beta-supersu  ???? ?? ????? ??? �Add more Zips� ???? ????? ??? ???? lazyflasher ?????? ???? ????? ?????
????? �Swipe to confirm Flash� ??? ???? ????? ??? ???? ???? ???? ???????? ??? ???? install complete ??? ???? Reboot option ?????? reboot ????? ?? ?????? ????? ???? Super Su ???? ???? App ??? ?????? ????? ??? ??? ???? ???? ??? ???? ??????


download file now

Read more »

Friday, September 8, 2017

Download MK902 User Manual

Download MK902 User Manual





Download RKM MK902 User Manual from here, here or here. You can also study it below. More details about RKM MK902 TV Box youll find here.



download file now

Read more »

Wednesday, September 6, 2017

User data anonymization

User data anonymization


Today, in many cases, we have a need of processing (obtaining, recording or holding) user data and that is when privacy issues arise. Data anonymization ensures that even if data is stolen, it cannot be misused. Healthcare and financial industries are the most exposed to threats since such data is at high demand on black markets, but everyone who is keeping any personally identifiable information (PII) and individuals activities should be aware of the risk. Here are a few interesting data breaches that happened:

  • Poorly anonymized logs reveal NYC cab drivers� detailed whereabouts
  • Anthem Blue Cross hack: Millions of records breached at health insurer
  • Database of 191 million U.S. voters exposed on Internet
  • The entire Turkish citizenship database has allegedly been leaked online

While working on my project I wasnt sure which part of the collected user data are sensitive and need to be anonymized. Ive discovered that there is no general rule for that. Basically, these are the steps:
  1. Identify all occurring information in the dataset.
  2. Define which information can identify an individual by itself or by combining with some other information. 
  3. Determine how each type of such information can be anonymized.
  4. Repeat the process to make sure all identifiable information is sanitized and that no piece of information can be used to re-identify individuals by matching it to some other outside sources. Such pieces of information are called quasi-identifiers.
The following attributes are examples of PII:
  • Personal: national identification number (SSN), date of birth, age, gender, marital status, religion, race, address, zip code, city, state, vehicle registration number, driving license, photographs, iris scan, biometric details, IP address
  • Financial: credit card number, CVV, account number, balance, credit
  • Educational: qualifications, university course, school or college studied, year of passing
  • Contact information: e-mail address, social networking login, telephone number
  • Medical information: medical history, patient identification number
  • Employment related: salary

The third step, process of anonymizing user data, is not an easy task. De-identification is based on characteristics of the different fields, so de-identification types of methods can include:
  • completely removing data,
  • masking the values (e.g. Donald to Don*l*) or replacing values with random or fake values 
  • encryption (e.g. Donald to *!#$@a),
  • data for one or more variables are switched with another record so that data set values stay real but are assigned to the wrong people,
  • creating aliases by applying a one-way hash to the variable so that the hash value cannot be reversed to the original value,
  • generalization of quasi identifiers (e.g. low population postal code can be aggregated to a larger geographic area - city),
  • perturbation by data swapping where you swap pairs of data so that data values stay the same but locations and associated records are changed,
  • k-anonymity technique where you release one record with a particular identifiable information and then you also release several other records who have the same or similar values.
When choosing the right method for the data anonymization we need to be aware that some methods can significantly reduce the utility of the data. For example, masking should be applied only to the fields that wont be used in data analysis like names or email addresses.

There are regulatory guidelines that can help in anonymization process like HIPAA Privacy Rule or EU Data protection and privacy ethical guidelines. However, there remains the potential to re-identify individuals using data if the process is not done promptly. No matter the network and physical security mechanisms, prevention of misuse of sensitive data can be achieved only by ensuring that the right data is getting to the right people in the right format.


download file now

Read more »