Friday, September 29, 2017
User behavior related work
User behavior related work
Many enterprises already recognized the importance of protecting against various threats that anti viruses cant predict but also the high probability of inside-out threats that pass undetected. Event if a threat is detected, most organizations arent equipped to respond effectively. Because of that, different user behavior based security software has been built and usually named under a general term User and entity behavior analytics (UEBA) software. It can be defined as: "Analysis of the behaviors of organizations employees, outsiders connected to their networks (such as third party contractors) and flagging security vulnerabilities across organizations assets that hold sensitive data.".
The difference between UEBA and the rest of the similar security software is that it usually can quickly identify a threat or an exploitable asset and then take action to remediate security risks across the entire infrastructure. Here Ill list a few examples of some software for different purposes that offer such features.
SentinelOne
Software that can be deployed across Windows, OS X and Linux endpoints along with Linux Ubuntu management server. They offer:
- monitoring kernel and user space (files, processes, system calls, memory, registry, network etc.). More details can be found in their technical brief.
- rapidly eliminating threat by killing malicious processes, rolling back manipulated files, disconnecting compromised devices,
- real-time attack forensic analysis.
Platform that seems to be supporting Windows OS only. They offer:
- monitoring following data sources: VPN, FW, IPS/IDS, web proxy, email logs,� packets, DNS logs, Active Directory logs, �DHCP logs,
- detecting privilege escalation, credential violations, internal reconnaissance, lateral movement, abnormal access to high value resources, command and control, exfiltration,
- alerts classified by severity and attack stage.
Platform that supports Windows & NAS, Exchange, Active Directory, SharePoint, UNIX/Linux, Office 365. Mostly offers detecting security gaps and insider threats by tracking changes to important configuration files, access to sensitive files, malware, privilege escalations, access denied events and more. Also includes:
- monitoring files and emails,
- full visibility on permissions (folder, mailbox, sharepoint),
- real-time alerts and comprehensive auditing.
Platform contains their own implementation of syslog-ng log management solution but doesnt offer much information about the data sources. Their technical documentation can be found here, and the features they offer include:
- analyzing biometric information (typing style or typical mouse movements),
- automatic notifications based on top suspicious activities.
This solution helps in protecting online banking sites against account takeover, fraudulent transactions, and can detect end user devices infected with high risk malware. It includes:
- analyzing biometric information (subtle mouse movements and clicks),
- possible integration with mobile devices for analysis of malware infections, root and jailbroken information, accurate geolocation and Wi-Fi security status.
- protection of web browser sessions to prevent tampering of customer transactions,
- prevention of phishing attacks, malware infections and removal of existing malware,
- protection against phishing of login credentials and payment card data.
This threat analytics platform offers insight into endpoints, applications, devices and users. Its benefits are:
- identifying and predicting malicious insiders and comprised accounts
- detecting and blocking fraud by proactively alerting on anomalous behaviors,
- real-time contextual view of attacks and detailed reports
download file now
Saturday, September 23, 2017
Ubuntu Login as root user
Ubuntu Login as root user
In this article, I will show you how to login as root after installing Ubuntu system.
By default the root user on Ubuntu doesnt have password, so to login as root you must set password for it using this command:
sudo passwd root
The system will ask you to input your current login user password, after that you could set the password for root.
Now, you want to login as root, just type command:
su root
Notice: The bash symbol in terminal for normal user will be the symbol $ and after logging in as root it will become #
For instance:
approved user: approved@approved-X556UAM:~$
root user : approved-X556UAM:/home/approved#
Good luck.
Source: https://askubuntu.com/questions/91598/how-do-i-login-as-root
download file now
Friday, September 22, 2017
User behavior logging
User behavior logging
In this blog post some ways to examine Linux operating system without using any additional (third party) programs or tools are explained. There are a number of Linux distributions but I will focus primarily on Debian and Debian based distributions. By collecting all the available information it is possible to track and log user behavior. Post consists of two parts: default system logs and other aspects which could be monitored.
In this part of the post some of the significant existing Linux system logs for user behavior are listed and explained:
- /var/log/messsages - contains general system activity and non-critical messages like user logins, kernel messages, IP firewall packet logging and so on. This log file doesnt exist on Debian Linux distributions, so instead syslog is used.
- /var/log/syslog - contains all the messages except the authentication related ones. By analyzing few, I found only kernel and thermald messages. Each line contains: datetime, hostname, program that generated the message, process id and log message.
- /var/log/auth.log - contains system authorization information including user logins through display and login managers, sudo access requests, authentication mechanism for crontab, policykit system daemon etc. This log file is found on Debian Linux distributions, but some other use /var/log/secure instead.
- /var/log/btmp - keeps track of failed login attempts. It is a binary file and can be read using last command.
- /var/log/dpkg.log & /var/log/yum.log - contain messages about installs or upgrades for various package managers.
It is important to point out that not all Linux distributions have those logs enabled. /etc/rsyslog.conf file controls what goes inside the log files while /etc/rsyslog.d/*.conf configuration files control what goes in log directory and where that directory is (default value is /var/log).
Also, log files can be easily modified or deleted. One solution is to set the log files to "append only" with chattr +a, but an attacker can gain root access so it is better to send logs to another host.
Other ways for tracking user behavior
Integrity checking is another way to detect changes in the system by looking for changes in the MD5/SHA1 checksums of the key files in the system. Those checksums need to be calculated periodically and compared with previous values. In such way inotify tool works by monitoring individual files or directories. It is important to check metadata such as permissions and ownerships, not just changes to file contents.
Keyboard is the most used device by the user so that should be logged too (keypress and speed). There are also shell commands which are sensitive part of all Unix systems. They can be monitored in several ways but one of them is to use the command history. However, there are way too many ways to execute a command in any Unix system so it is not possible to monitor commands completely.
Since mostly users browse same websites daily, it can be useful for determining users behavior to log website visits. That can be done using rndc querylog which can log all DNS queries or using tcpdump and filtering only DNS queries (port 53).
Those are some of the ways to examine the status of some system and by that we can try to track user behavior. Also, there are some other parts of the system that are not mentioned but that is because I currently dont find them significant for purpose of the system I am building.
download file now
Google Analytics User Conference G’day Australia
Google Analytics User Conference G’day Australia
download file now
Tuesday, September 19, 2017
Top 5 Best Youtube Tricks Every Internet User Should Know
Top 5 Best Youtube Tricks Every Internet User Should Know

Top 5 Youtube Tricks for Every Internet User
1. Download Youtube Video
This is one of the most popular tricks for Youtube. If you want local copy of youtube video for PC and android Mobile, this trick help you.
You just need to add ss before. Below you see a example how you download youtube video.
https://www.youtube.com/watch?v=h01Y40j9_r0
https://www.ssyoutube.com/watch?v=h01Y40j9_r0Sometimes youtube gives you error like this video not avalaible in your country or age restrictions.

Here is a solution.
https://www.youtube.com/watch?v=h01Y40j9_r0
https://www.youtube.com/v/h01Y40j9_r03. Youtube TV website for PC (Beautiful and Clean Youtube)
Now with Youtube TV you can control youtube website from Keyboard-only. This whole website is controlled by Keyboard. youtube.com/tv give you tv experiance in your PC.

In this website all youtube categories comes in very beautiful animation.
If you want something new from Youtube this is. In here you see clean interface. Not any commentbox,suggestion or ad. If you want youtube video without ads try this.
4. Play the Snake Game In Youtube
Ya this is true when you play youtube video you can also play snake game on youtube. When you see loading sign press UP arrow key. Now the loading sign turn into snake game. This is so cool tricks ,so try and prank your friends with this trick.

5. Youtube Search Easter Egg.
When you search these easter eggs in youtube. Youtube responses diffrently. This thing is prankable when you wanna something new with only youtube searches.
"Use the force luke search" (your mouse moves things around)
"Beam me up Scotty" (search results "transport" on the page)
"Doge meme" (all comic book sans)
"Do the Harlem shake" (the page literally does the Harlem shake�with soundtrack)

Try all this trick and if you got any problem contact me at Facebook.
download file now
Friday, September 15, 2017
Using grep to Unearth Old Windows User Names 7 30 08
Using grep to Unearth Old Windows User Names 7 30 08
Identifying Deleted User Accounts in Windows
I was recently presented with three laptop computers suspected as stolen. My task was to identify the owners. I chose to use a Linux forensic boot disk (one that would not automatically mount the partitions) to conduct the examination to avoid disassembling the computers to access the hard disk drives.
It became apparent on the first computer that the original user account(s) were deleted. There was a major discrepancy between the single user account (in one of the suspects names) and in the installation date of the Windows Vista OS.
After studying Internet Explorer index.dat files recently, I decided to target deleted index.dat content. IE index.dat files contain the usernames of the active user browsing the web with Internet Explorer, as well as some local file system activities. I used the following command from the Linux terminal to fish for old user account names:
$ tr [:cntrl:] < /dev/sda | grep -abE --colour=auto (((:[0-9]{16,16}|Visited):[[:space:]])|Cookie:).+@
The command, broken down, does the following:
- tr [:cntrl:] - translates control characters to line feeds to keep the grep memory buffer from exhausting.
- < /dev/sda - feeds the raw data from device sda (the laptop hard disk) into the translate command. The device may be substituted with any file, such as a raw disk image.
- | grep -abE --colour=auto (((:[0-9]{16,16}|Visited):[[:space:]])|Cookie:).+@ finds the Internet Explorer cookie and history index.dat data that contains user names. The The hits are in color to help them stand out and the results can be redirected to a text file by appending the command with "> grep.results.txt". Broken down further:
- grep -abE : a=treat binary as text; b=show byte offset; E=treat as extended regular expression
- --colour=auto : show regex matches in color
- (((:[0-9]{16,16}|Visited):[[:space:]])|Cookie:).+@ : Match expressions ":<16>:
@" or "Visited: @" or "Cookie: @" where is any name of one character or more.
254468840::2007052620070527: user@:Host: cis.cuesta.edu
286125672:Cookie:user@www.ibm.com/rc
161464680:Visited: user@http://encarta.msn.com/proscribed.html
The rest of the story
I analyzed the hits and observed user names inconsistent with those in the Vista /USERS directory. Further examination of the new user names showed they existed previous to the current user account (as determined from the index.dat date code), and urls for the users MySpace page. The newly discovered user was contacted through his MySpace page and identified the computer as stolen in June, 2007.
This a simplified discussion of the full process, which included examining the file system to determine existing users using The Sleuthkit. The purpose of the article is to demonstrate how grep can be used from a boot CD or USB device to locate Windows artifacts that show deleted accounts that can be used to identify the account holders.
In this case. the hard disk drive being examined was never mounted. Grep searches can be directed against unallocated sectors through a similar process which I will discuss at a later time.
download file now
User behavior data extraction in Linux OS
User behavior data extraction in Linux OS
In this post, a short intro about my seminar in masters degree programme is given. The topic that Im working on is "User behavior data extraction in Linux OS" which includes gathering useful data about user actions, parsing and analyzing them.
The purpose of the system is to gather all information such as global system messages, user logins, background daemons, package installs, browser and keyboard usage, shell commands, runtime system information, file integrity and so on. Then, by using machine learning, it might be possible to develop a system that can detect anomalous user behavior. Such system would try to prevent any unauthorized access by analyzing users current activities.
The following activities and their approximate duration are planned:
- search for similar software (5%)
- Linux logging analysis (10%)
- finding all options to track users behavior (15%)
- definition and design of desired system (15%)
- implementation in Python programming language (40%)
- testing systems functionality and security (15%)
download file now
Sunday, September 10, 2017
Top 10 Windows Software for Every Windows User
Top 10 Windows Software for Every Windows User










This is top 10 Windows Programs that every Windows user needs. Try all of this if you like my work thanks to me at Facebook.
download file now
Saturday, September 9, 2017
SUPER USER PART 4 রুট করুন আপনার Xiaomi Redmi Note 3 Pro ফোনকে।
SUPER USER PART 4 রুট করুন আপনার Xiaomi Redmi Note 3 Pro ফোনকে।
??, ???? ??? ??? ?????? Note 3 Pro ?? ??? ??? ????
???? ? ?????? ???????? ????? ??? ????? ????
????? ???? ???? ???? ??????? ??? ????
?? Root file for kenzo?
?? TWRP Recovery for Kenzo?
Step 1:
?? ?? Download ??? ???? Extract ??? ???? ??? Extract ??? ??????? ????? ???? ?????, Beta-supersu ??? lazyflasher ???? ?? ???? ???? ????? ????? Internal Storage ? ?????????? ???? ????
???? ?? ???? ?? Extract ??????? Extract ??? ???? ???? Adb, fastboot & Recovery ???? ??????
Step 2:
???? ????? ????? ????? ???? USB ?????? ???? ????? ??????? ??? ????? ???? Setting ? ???? Additional Setting ????? Developer Option ?? On ??? USB debugging ??? ???? (Setting>additional setting>Developer Option> USB debugging)?
Step 3:
�TWRP Recovery for Kenzo� ?????? ?????? Extract ???????? ?? ??????? ???? Keyboard ?? �Shift key� ???? ??? ???? ?? Right button ? ????? ???? �Open command window here� ????? ?????, ????? ????? ?? ??? �command prompt� open ????
????? command prompt ? ????? ???? command ???? ????
Command No 1: adb devices
?? command ?? ???? ????? ???? ???? ??????? ????? ???? ?????? ????? ???? ???? ???? ?? ??? ???? Allow ?????? ????? ????? ?? ????? ???????? command prompt show ?????
Command No 2: adb reboot bootloader
?? command ?? ???? ????? ???????? ????? ???? Fastboot Mode ? ???? ????
Command No 3: fastboot flash recovery twrp-3.0.2-2-kenzo.img
???? Twrp recovery ?? flash ??? ?????
Step 3:
????? usb disconnect ??? ??? ?? Power button + volume button ?????? Long press ??? ????? ??? mi logo ?? ???? ?? ??? Power button ?? ???? ???? ?????? ?????? Twrp open ??? ???? ??? ???? ??? ?? window ???? ???? ???? ?????? ??? ???? ????? ??? ???? ???? ??????
Step 4:
???? Twrp recovery ???? �Install� option ???? Press ???? ????? Internal Storage ?? ???? ??? ??????? ???? ????? ???????????? ???? ????? Internal Storage ? ???? Beta-supersu ???? ?? ????? ??? �Add more Zips� ???? ????? ??? ???? lazyflasher ?????? ???? ????? ?????
????? �Swipe to confirm Flash� ??? ???? ????? ??? ???? ???? ???? ???????? ??? ???? install complete ??? ???? Reboot option ?????? reboot ????? ?? ?????? ????? ???? Super Su ???? ???? App ??? ?????? ????? ??? ??? ???? ???? ??? ???? ??????
download file now
Friday, September 8, 2017
Download MK902 User Manual
Download MK902 User Manual
download file now
Wednesday, September 6, 2017
User data anonymization
User data anonymization
Today, in many cases, we have a need of processing (obtaining, recording or holding) user data and that is when privacy issues arise. Data anonymization ensures that even if data is stolen, it cannot be misused. Healthcare and financial industries are the most exposed to threats since such data is at high demand on black markets, but everyone who is keeping any personally identifiable information (PII) and individuals activities should be aware of the risk. Here are a few interesting data breaches that happened:
- Poorly anonymized logs reveal NYC cab drivers� detailed whereabouts
- Anthem Blue Cross hack: Millions of records breached at health insurer
- Database of 191 million U.S. voters exposed on Internet
- The entire Turkish citizenship database has allegedly been leaked online
- Identify all occurring information in the dataset.
- Define which information can identify an individual by itself or by combining with some other information.
- Determine how each type of such information can be anonymized.
- Repeat the process to make sure all identifiable information is sanitized and that no piece of information can be used to re-identify individuals by matching it to some other outside sources. Such pieces of information are called quasi-identifiers.
- Personal: national identification number (SSN), date of birth, age, gender, marital status, religion, race, address, zip code, city, state, vehicle registration number, driving license, photographs, iris scan, biometric details, IP address
- Financial: credit card number, CVV, account number, balance, credit
- Educational: qualifications, university course, school or college studied, year of passing
- Contact information: e-mail address, social networking login, telephone number
- Medical information: medical history, patient identification number
- Employment related: salary
- completely removing data,
- masking the values (e.g. Donald to Don*l*) or replacing values with random or fake values
- encryption (e.g. Donald to *!#$@a),
- data for one or more variables are switched with another record so that data set values stay real but are assigned to the wrong people,
- creating aliases by applying a one-way hash to the variable so that the hash value cannot be reversed to the original value,
- generalization of quasi identifiers (e.g. low population postal code can be aggregated to a larger geographic area - city),
- perturbation by data swapping where you swap pairs of data so that data values stay the same but locations and associated records are changed,
- k-anonymity technique where you release one record with a particular identifiable information and then you also release several other records who have the same or similar values.
download file now