Sniffing beginner ..

2002-07-07 Thread Bassam ALHUSSEIN

Hello list ...
During my first sniffing experiences I've got this line in the sniffed
packet :
" 
(ENCRYPTION TYPE)
B*C*N**N
  "
Could someone tell me what the meaning of B*C*N**N is ??
I made a primitive search on Google, but I can't figure out how to find a
paper or anything about it, cause I don't know what the keywords are ?





Re: proxy tunneling

2002-07-07 Thread Bassam ALHUSSEIN

I Could never get httport to work well.
Httptunnel works very fine (but slowly) and I like it.
http://www.http-tunnel.com

have fun ...
- Original Message -
From: rohit sharma <[EMAIL PROTECTED]>
To: <[EMAIL PROTECTED]>
Sent: Friday, July 05, 2002 12:52 PM
Subject: proxy tunneling


> HI
>
> is there any program that could allow me to tunnel my
> messengers packets through the proxy.
>
> i have used httport but it seems to loose the link
> every now and then
>
> regards
> rohit sharma
>
> __
> Do You Yahoo!?
> Sign up for SBC Yahoo! Dial - First Month Free
> http://sbc.yahoo.com
>





Re: IP Spoofing

2002-05-06 Thread Bassam ALHUSSEIN

There is a simplified article of the Ankit Fadia's webpage
http://hackingtruths.box.sk
Good for newbies like myself ...


Bisso
- Original Message -
From: Constance Baptist <[EMAIL PROTECTED]>
To: <[EMAIL PROTECTED]>
Sent: Thursday, May 02, 2002 4:31 PM
Subject: IP Spoofing


> Hello All,
> I am interested in the topic IP Spoofing or spoofing.  Can anyone provide
> any site where I can learn about this topic.  I have found only one paper
on
> the internet, but it is dated 1996.  Thanks
>
> _
> Join the world’s largest e-mail service with MSN Hotmail.
> http://www.hotmail.com
>
>
>





Re: Disk Wiping Utilities

2002-03-28 Thread Bassam ALHUSSEIN

I am not sure but I thought that a format then fdisk would do the job
wouldn't it ???
correct me guys ..plz

Bisso
- Original Message -
From: Dan Williamson <[EMAIL PROTECTED]>
To: <[EMAIL PROTECTED]>
Sent: Wednesday, March 27, 2002 12:14 AM
Subject: Disk Wiping Utilities


>
>
> I am looking for a good utility to erase all hard drives
> in a machine to a DOD standard. I would prefer a
> FREE utility as this is a government agency and I try
> to keep costs down.
>
> I have read that Norton Wipeinfo, BCWipe and
> several other programs wipe only the known
> partitions. I need a tool that will wipe EVERYTHING !
>
> TIA
> Dan
>
>





Windows shares ...!!!!

2002-03-27 Thread Bassam ALHUSSEIN

Hello all 
I am connected to the internet through a dialup-modem connection to an ISP.
this ISP gives its users dynamical IPs (non routable and it is applying
NAT).
I installed microsoft network client because I used to use windows shares on
other users' machines (friends). this is done by doing a scan on netbios
ports on the ips of those machines 10.0.0.x .
I used to find dosens of machines with windows shares.

suddenly, it's been several days, I can find no more machines with shares
!! the scanner gives nothing. I thought it's a problem with my ms
network client, so I reinstalled it. Still nothing ...
I even used "nbtstat -A 10.0.0.x" from a DOS prompt for some IPs within that
scope, but it gave " host not found ". But it gave something when I used it
for my IP ..
To be more sure, I called a friend that I used to have access to his shares,
and I asked to him to connect. We made a chat and he gave me his actual IP,
so I made that nbtstat to his IP. But it gave "host not found". He was sure
that his netbios ports (137-139) was opened and listening.
By the way, he couldn't neither see me with that "nbtstat -A myIP".
What could the problem be ?? I don't understandI am a real newbie
...:-(

Can the ISP do something to prohibit the access to windows shares between
machine weithin it's local network  how can this be done ???

thanx verymuch for answering ...( I LOVE DETAILS if you have the time)

Bisso





Just a question ........NEWWWWS !!!!!

2002-02-28 Thread Bassam ALHUSSEIN

Hi Again  thank you all for answering, but I've got some news 
I didn't use fport ( which was a proposition of someone of you ), but I
tried to block this address by ZoneAlarm Pro that is installed and running.
ZApro gave me then an alert every 20 seconds, and said that Microsoft
outlook express
tried to connect to
www.myhost.com  which resolves in the browser directly to weguardyou.com
!!
the alert is :
"Your computer was prevented from connecting to a restricted site
(www.myhost.com).
User: Bassam ALHUSSEIN
Program: Microsoft Outlook Express .
Time: 23/02/2002 03:34:20 PM  "

the problem is that I never visited that site before or downloaded something
from there ...!!!
softwares that I use at startup are : some Norton utilities and AV,
ZoneAlarmPro, and getright !!
I have had these alerts even when outlook is not running ...!!! So when I
passed on PROGRAMS SETTINGS in ZApro I found TWO outlooks 
1)Outlook Express (which is the file msimn.exe)
2)Microsoft Outlook Express  (which is  support-http.exe ) and it is
this one that was trying to connect to myhost.com ..but why ???
( it exists even in the registry to run at the startup ..!!  wow but with
name of http tunnel ??
I remember ..http-tunnel is a program I used once to bypass my the proxy
server of my ISP that blocks free email sites ...!!! )


what do you think ??? should I still block the address and have the alerts
every 20 sec...
should  I delete that key from the registry ???  Do you know if support-http
is really a program from microsoft ? ( cause it is in the system folder
and http-tunnel that I used is just one exe file on another hard drive )
I am lost .help

I sent email to [EMAIL PROTECTED] but got no answer .

Bisso

















Re: Windows 9x last boot

2002-02-26 Thread Bassam ALHUSSEIN


- Original Message -
From: <[EMAIL PROTECTED]>
To: Bassam ALHUSSEIN <[EMAIL PROTECTED]>
Cc: <[EMAIL PROTECTED]>
Sent: Sunday, February 24, 2002 5:29 PM
Subject: Re: Windows 9x last boot


> Hi,
>
Hi :-)
> You were right about the rb00?.cab files.
Do you mean that I was wrong about the swap file ???
>
> However, there are some strange dates for each of them, as follows:
>
> 28/11/2026  10:36 rb001.cab
> 29/11/2026  22:07 rb002.cab
> 30/11/2026  12:12 rb003.cab
> 02/12/2026  09:49 rb004.cab
> 24/02/2002  12:12 rb005.cab
>
> Any ideas why this might happen?
>
The simplest possibility is that you may have changed the date on your
machine to the year 2026 and made some reboots before coming back to 2002
so some of the rb00? files have had those strange dates ...   but your
last boot seems to be today evening ...
There are other possibilties which include viral activities ...But I am
no expert of how could that happen..!!!!

Bisso
>
> Thanks,
> Florentin
>
>
>
>
> "Bassam ALHUSSEIN" <[EMAIL PROTECTED]>
> 23/02/2002 13:53
>
>
> To: <[EMAIL PROTECTED]>
> cc: <[EMAIL PROTECTED]>
> Subject:Re: Windows 9x  last boot
>
>
> When a win98 machine is running, the date of it's last boot is the date of
> the swapfile win386.swp which exists in the root path (I mean C:\ by
> default).
> If you mean the preceding boots, you can find the last 5 boots in the
> windows\sysbckup folder. There you can find 5 files : rb00?.cab ( ?= 1, 2,
> 3, 4, 5 ) and every one contains a back up of the system files of the 5
> last
> boots 
> Am I right guys 
>
> hope this helps .
>
> Bisso
> - Original Message -
> From: <[EMAIL PROTECTED]>
> To: <[EMAIL PROTECTED]>
> Sent: Thursday, February 21, 2002 10:36 PM
> Subject: Windows 9x last boot
>
>
> > Hello,
> >
> > Does anyone know how to find out when a Windows 98 machine was last
> > booted?
> > I have access to the machine in cause, which is up and running.
> >
> >
> > many thanks,
> > Florentin
> >
> >
> >
>
>
>
>
>
>
>





Re: Windows 9x last boot

2002-02-25 Thread Bassam ALHUSSEIN

When a win98 machine is running, the date of it's last boot is the date of
the swapfile win386.swp which exists in the root path (I mean C:\ by
default).
If you mean the preceding boots, you can find the last 5 boots in the
windows\sysbckup folder. There you can find 5 files : rb00?.cab ( ?= 1, 2,
3, 4, 5 ) and every one contains a back up of the system files of the 5 last
boots 
Am I right guys 

hope this helps .

Bisso
- Original Message -
From: <[EMAIL PROTECTED]>
To: <[EMAIL PROTECTED]>
Sent: Thursday, February 21, 2002 10:36 PM
Subject: Windows 9x last boot


> Hello,
>
> Does anyone know how to find out when a Windows 98 machine was last
> booted?
> I have access to the machine in cause, which is up and running.
>
>
> many thanks,
> Florentin
>
>
>





Just a question ........NEWWWWS !!!!!

2002-02-25 Thread Bassam ALHUSSEIN

Hi Again  thank you all for answering, but I've got some news 
I didn't use fport ( which was a proposition of someone of you ), but I
tried to block this address by ZoneAlarm Pro that is installed and running.
ZApro gave me then an alert every 20 seconds, and said that Microsoft
outlook express
tried to connect to
www.myhost.com  which resolves in the browser directly to weguardyou.com
!!
the alert is :
"Your computer was prevented from connecting to a restricted site
(www.myhost.com).
User: Bassam ALHUSSEIN
Program: Microsoft Outlook Express .
Time: 23/02/2002 03:34:20 PM  "

the problem is that I never visited that site before or downloaded something
from there ...!!!
softwares that I use at startup are : some Norton utilities and AV,
ZoneAlarmPro, and getright !!
I have had these alerts even when outlook is not running ...!!! So when I
passed on PROGRAMS SETTINGS in ZApro I found TWO outlooks 
1)Outlook Express (which is the file msimn.exe)
2)Microsoft Outlook Express  (which is  support-http.exe ) and it is
this one that was trying to connect to myhost.com ..but why ???
( it exists even in the registry to run at the startup ..!!  wow but with
name of http tunnel ??
I remember ..http-tunnel is a program I used once to bypass my the proxy
server of my ISP that blocks free email sites ...!!! )


what do you think ??? should I still block the address and have the alerts
every 20 sec...
should  I delete that key from the registry ???  Do you know if support-http
is really a program from microsoft ? ( cause it is in the system folder
and http-tunnel that I used is just one exe file on another hard drive )
I am lost .help

I sent email to [EMAIL PROTECTED] but got no answer .

Bisso













Just a question!!!

2002-02-22 Thread Bassam ALHUSSEIN

Hello all ...
Every time I make a dial-up connection to the internet I see an unknown (for
me) IP address that I am connected on port 80, in the out put of
"netstat -an" on a win98SE box.
The thing that I don't understand is that this is not the proxy server of
ISP i'm connected to !!
I used samspade.org trying to know what (or where) it is ..but I couldn't
figure it out ...
that IP is 208.255.95.117 ...
what do you think ...
I know it is a dumb question but ...sorry :-





Basic ..

2002-02-04 Thread Bassam ALHUSSEIN

Sorry for this dummy question ...
How can I know if the proxy server that I use to access to the internet is
an "HTTP 1.0 compliant proxy server that supports CONNECT operator" ...?!!
I am trying to use httport to bypass that proxy and ...I have
troubles...doesn't work well :-(


thanx and sorry again .





Httport & NAT

2001-12-09 Thread Bassam ALHUSSEIN

Well I am not the administrator of the network. I just want to bypass the
proxy of my ISP that blocks more sites than it permits, and I know that they
are NATing. someone proposed httport and I can't figure out how to use it
..!! So if I am behind a NAT..could httport be effective for me ???


thanx a lot





httport & NAT

2001-12-06 Thread Bassam ALHUSSEIN

hello all ...
can Httport be configured and used from behind a NAT ?

thanx for any help ...





Safeweb.com no more free !!!!!!!!!! AGAIN

2001-11-29 Thread Bassam ALHUSSEIN

With Anonymizer.com I can't access my yahoo mail I have to use a FREE
service because I can't pay ( I live in a country where BANKS are still
prehistoric ...MasterCards are a dream ..to pay money on the internet is a
halucination ...!)
I am searching for a free service, and preferably with https ...
another thing ..the address of the service could be blocked by our proxy.
that's why I hope finding a "triangleboy-like" service wich was IDEAL for me
...


thanx a lot





Safeweb.com no more free !!!!!!!!!!

2001-11-26 Thread Bassam ALHUSSEIN

Hello ...
I've got a question:
Any body knows a free anonymizing service like the old safeweb.com ...it is
no more free ...I know others like surfola.com etc.. but their addresses are
blocked ...I loved the strategy of Triangleboy that wa s used in
safeweb.com, so it can't be blocked ...

any help ??


Bisso





Format HardDisk Program !!!!!!!!

2001-11-08 Thread Bassam ALHUSSEIN

Hi All ...
I was surfing the web someday and I passed on a page where is a program to
download, and there was said that it DESTROYs the harddisk !!!
it is an exe file with a size of 8 kb only ...( the link is
:http://www.geocities.com/fadiworld/fadiworld.html )
I don't believe the auther of the page about this program but I don't dare
to execute it.
Is there a way to know what this program can do without execting it ???
( I don't know assembly to reverse engineer it )


thanx for answering

Bisso





Re: Java Telnet ?????????

2001-11-03 Thread Bassam ALHUSSEIN

Thanx for answering ...I will try that.
Someone told me about shellinabox.com. What's your opinion about it ??

Bisso
- Original Message -
From: <[EMAIL PROTECTED]>
Cc: Bassam ALHUSSEIN <[EMAIL PROTECTED]>;
<[EMAIL PROTECTED]>
Sent: Thursday, November 01, 2001 1:55 AM
Subject: RE: Java Telnet ?


> take a look at httptunnel: http://www.nocrew.org/software/httptunnel.html
>
> also, icmp might be a possibility, so look into LOKI (this is lod school
> ;)
>
> on the vien of icmp, check out
> icmptunnel: http://www.detached.net/icmptunnel/
>
> 
>
> icmptunnel encapsulates data in ICMP frames.
>
> The usual mode of operation is tcp/ip forwarding, one icmptunnel will
> be set up on a blocked machine (behind a firewall) listening on TCP/IP
> port X.
>
> The other icmptunnel will be set up on a nonblocked machine
> (somewhere on the internet connected to a local service (such as port
> 23, telnet).
>
> Data received on the blocked machine's tcp/ip socket will be
> encapsulated in an ICMP packet of users choice (ICMP_ECHO, ICMP_ECHOREPLY,
> ICMP_TIMESTAMP, etc..) and sent to the nonblocked machine. This machine
> will identify the packet as encapsulated data, decapsulate the data and
forward it on to its tcp/ip socket connected
> to the telnet daemon.
>
> The telnet daemon responds with some data, icmptunnel on the nonblocked
> machine encapses the packet and sends it back to the blocked machine (ICMP
> type still user definable).
>
> 
>
> -limon
>
>
> > > > Hello friends  I am new on the list.
> > > > I am connected to the internet from behind a NAT.  No ftp,
> > > No telnet,
> > > > ..nothing but http, https and mail services.
> > > > I have no shell account on my isp's server. So I tried to
> > > get a free shell
> > > > account on the interent, but it's not available coz I can't
> > > telnet... I just
> > > > have got an idea and I don't know if this exists... :
> > > > " Is there a free telnet service built totaly on java..so
> > > it can be run on
> > > > http's port (80, 8080 or whatever) to be connected to that
> > > shell account
> > > > ..."
> > > >
> > > > I don't even know if the question does have a sense 
> > > >
> > > > If this exists do you know a domain that offer such a service ??
> > > >
> > > > propsitions are appreciated..
> > > >
> > > >
> > > >
> > >
> >
>
>
>





Re: Java Telnet ?????????

2001-11-03 Thread Bassam ALHUSSEIN


- Original Message -
From: Mark Ng <[EMAIL PROTECTED]>
To: <[EMAIL PROTECTED]>; Bassam ALHUSSEIN <[EMAIL PROTECTED]>
Cc: <[EMAIL PROTECTED]>
Sent: Tuesday, October 30, 2001 12:29 PM
Subject: RE: Java Telnet ?


> In terms of java telnet, you may be out of luck.  Since a java applet runs
> on your local machine, it makes the connection from your local machine,
> therefore you will be subject to the same restrictions afaik.  Also, if
> you're restricted from those services, I would imagine there is probably a
> reason you are restricted ?

No Reasons... ALL users of my ISP have the same restrictions. I mean
thousands of people.
It's the strategy of that ISP : Services are just web browsing and mail.
>
> > > Hello friends  I am new on the list.
> > > I am connected to the internet from behind a NAT.  No ftp,
> > No telnet,
> > > ..nothing but http, https and mail services.
> > > I have no shell account on my isp's server. So I tried to
> > get a free shell
> > > account on the interent, but it's not available coz I can't
> > telnet... I just
> > > have got an idea and I don't know if this exists... :
> > > " Is there a free telnet service built totaly on java..so
> > it can be run on
> > > http's port (80, 8080 or whatever) to be connected to that
> > shell account
> > > ..."
> > >
> > > I don't even know if the question does have a sense 
> > >
> > > If this exists do you know a domain that offer such a service ??
> > >
> > > propsitions are appreciated..
> > >
> > >
> > >
> >
>
>
>





Java Telnet ?????????

2001-10-25 Thread Bassam ALHUSSEIN

Hello friends  I am new on the list.
I am connected to the internet from behind a NAT.  No ftp, No telnet,
..nothing but http, https and mail services.
I have no shell account on my isp's server. So I tried to get a free shell
account on the interent, but it's not available coz I can't telnet... I just
have got an idea and I don't know if this exists... :
" Is there a free telnet service built totaly on java..so it can be run on
http's port (80, 8080 or whatever) to be connected to that shell account
..."

I don't even know if the question does have a sense 

If this exists do you know a domain that offer such a service ??

propsitions are appreciated..