Saturday, 26 June 2021

WEP INSECURITIES

 

WEP INSECURITIES

Two researchers from the University of California at Berkeley and one from Zero Knowledge Systems Inc. published a report identifying security weaknesses within the Wired Equivalency Privacy (WEP) algorithm in 2001.1 Based on their research, WEP was found to be insecure due to improper implementation of the RC4 encryption algorithm and the use of a 32-bit cyclical redundancy check (CRC-32) checksum for data integrity. These vulnerabilities create the potential for active and passive attacks that could allow attackers to decrypt traffic or inject unauthorized data into a network. Furthermore, the researchers hypothesized that the attacks would not require specialized equipment but could be conducted using readily available hardware sold at consumer electronics stores.2 (At the risk of losing reader suspense, the prediction was very accurate indeed.) Hackers began automating the exploits once the vulnerabilities were made public.

 

What is 802.11x?

Wireless LAN standards are defined by the IEEE’s 802.11 working group. WLANs come in three flavors, namely 802.11b, 802.11a and 802.11g.3 802.11b-networking equipment first became available in 1999 and quickly gained popularity. 802.11b operates in the 2.4000-GHz to 2.4835-GHz frequency range and can operate at up to 11 megabits per second, although it can also reduce throughput to 5.5 Mbps, 2 Mbps or 1 Mbps when interference degrades signal quality.4 The 802.11a standard increases throughput to a theoretical maximum of 54 Mbps and operates in the 5.15- to 5.35-GHz through 5.725- to 5.825-GHz frequency range. 802.11a hardware first became available in late 2001. Due to operation at different frequencies, 802.11a is not compatible with 802.11b hardware. Finally, the 802.11g standard has not yet been approved but promises compatibility with 802.11b hardware as it too will operate at the 2.4-GHz frequency. The major advantage that will be offered by the 802.11g standard will be increased bandwidth comparable to 802.11a at 54 Mbps.5

 

Confused? For the purposes of this paper, keep in mind that WEP is defined in the 802.11 standard, not the individual standards for the 802.11b, 802.11a or 802.11g task groups. As a consequence, WEP vulnerabilities have the potential to affect all flavors of 802.11 networks; therefore, this paper frequently refers to WLANs as 802.11x networks.

 

When setting up a WLAN, the channel and service set identifier (SSID) must be configured in addition to traditional network settings such as an IP address and a subnet mask. The channel is a number between one and 11 (one and 13 in Europe) and designates the frequency on which the network will operate (see Figure 1: 802.11b channels). The SSID is an alphanumeric string that differentiates networks operating on the same channel. It is essentially a configurable name that identifies an individual network. These settings are important factors when identifying WLANs and sniffing traffic, which is discussed later.

 



*EXECUTIVE SUMMARY*

EXECUTIVE SUMMARY


    Wireless networking technology is becoming increasingly popular but, at the same time, has introduced many security issues. The popularity in wireless technology is driven by two primary factors — convenience and cost. A wireless local area network (WLAN) allows workers to access digital resources without being tethered to their desks. Laptops could be carried into meetings or even out to the front lawn on a nice day. This convenience has become affordable. Vendors have begun to produce compatible hardware at a reasonable price with standards such as the Institute of Electrical and Electronics Engineers Inc.’s (IEEE’s) 802.11x.

 

However, the convenience of WLANs also introduces security concerns that do not exist in a wired world. Connecting to a network no longer requires an Ethernet cable. Instead, data packets are airborne and available to anyone with the ability to intercept and decode them. Traditional physical security measures like walls and security guards are useless in this new domain.

 

Several reports have discussed weaknesses in the Wired Equivalent Privacy (WEP) algorithm employed by the 802.11x standard to encrypt wireless data. This has lead to the development of automated tools, such as AirSnort and WEPCrack, that automate the recovery of encryption keys. The IEEE has organized the 802.11i Task Group to address 802.11x security, and hardware vendors are racing to implement proprietary solutions. Still, securing vulnerable networks could take some time. Beyond this, research has shown that that majority of networks use no encryption at all. WEP is far from perfect, but it does at least provide a deterrent to attackers.

 

WLANs introduce security risks that must be understood and mitigated. If not, vulnerable WLANs can compromise overall network security by allowing the following attack scenarios:

 

•  Vulnerable WLANs provide attackers with the ability to passively obtain confidential network data and leave no trace of the attack.

•  Vulnerable WLANs, positioned behind perimeter firewalls and considered to be trusted networks, may provide attackers with a backdoor into a network. This access may lead to attacks on machines elsewhere on the wired LAN.

•  Vulnerable WLANs could serve as a launching pad for attacks on unrelated networks. WLANs provide convenient cover, as identifying the originator of an attack is difficult if not impossible.

 

Tools to identify WLANs, break WEP encryption keys and capture network traffic are freely available. To protect against attacks, understand both the vulnerabilities that exist and how attackers employ these tools to exploit the vulnerabilities. Identify compensating controls and determine if the risks can be mitigated to an acceptable level to justify the introduction of wireless network technology.

 

This paper addresses how to find the vulnerabilities inherent in the WEP algorithm, how to determine if a WLAN is vulnerable using freeware tools and, most importantly, how to best secure WLANs.

Tuesday, 25 February 2020

How to book realme 2 on Flipkart and amazon?




Realme2
Targeted at the budget Indian audience, Realme introduces its second smartphone in the country, the Realme 2. With a notched screen of 15.74 cm, this phone will bring all your favourite photos to life. With a power-packed battery of 4230 mAh, you can be out and about in the city without having to worry about your phone dying. We love the 8 MP selfie camera that lets you choose among tonnes of beauty enhancement options to help you take the perfect selfie. What more, the Realme 2 comes with a sleek and shiny diamond-cut back design that is sure to make a lasting impression. We believe this phone is truly the best combination of utility and style! If a budget smartphone is what you’re looking for, look no further than the Realme 2!

Realme 2: Sale on Flipkart



Smooth and gleaming, the Realme 2 is about smooth and consistent client experience. With lovely feel, this telephone isn't just about the usefulness. It scores high in the looks office too on account of its precious stone cut back board, which is really shocking!

Far reaching screen

Its 15.74 indent full screen will offer you a vivid review understanding. With a 88.8% screen to body proportion, the telephone guarantees there is no block among you and the screen!

Durable battery

Its ground-breaking 4230 mAh battery joined with an AI that closes inert applications will spare you from charging the telephone occasionally. Expect 10 hours of gaming meetings and 15 hours of video playback time once completely energized. Genuinely, amusement continuous!

Jewel cut plan

We love the jewel cut shiny back of the Realme 2 - effectively the most attractive telephone in its value portion!

Double camera

Transform your photos into excellent representations with the telephone's characteristic foundation impacts. The Realme 2 accompanies a dazzling 13 MP + 2 MP double back camera framework.

Up your Selfie Game

The telephone's 8 MP front camera can investigate many facial characteristics. With its AI Beauty 2.0 Selfie Technology, you can choose among a huge number of beautification alternatives to catch the most alluring selfie.

Advanced User Experience

Realme 2 is fueled by Qualcomm Snapdragon Octa-center CPU that can bring down your capacity utilization by 30%. It is additionally prepared to accelerate realistic rendering by 25%.

Unique mark and facial open

You don't need to recollect your passwords any longer. Access your versatile's substance with a basic finger swipe development or by a snappy output of your face.

Realme, is a sub-brand of Chinese cell phone producer Oppo. Touted as the 'selfie master', Oppo has been positioned number 4 all around in the cell phone advertise since 2016. Since the time its dispatch, the brand has been concentrating on selfie development and achievements to solidify a spot for itself in the millennial age. Known to be a pioneer of selfie beautification, Oppo was likewise the brand to acquaint A.I with the front camera changing the manner in which we as a whole take selfies.

After the effective dispatch of its first cell phone in Quite a while, Realme is out to catch the consideration of the Indian crowd by and by with its subsequent premium telephone: Realme 2. The Realme 2 was broadly adored for its incorporation of intensity and style, taking off to the subsequent situation in India's online cell phone advertise portion. Its successor as well, has a few secret weapons to convey an incentive for cash, an angle the move Indian client has been organizing throughout recent years.

The Realme 2, with its smaller and smooth 6.2 inch score screen, is decided to breath life into your photographs and recordings. Its incredible double backside camera, an element missing in the Realme 2, will turn your photographs to shocking pictures. Trust us, your photos are never going to be the equivalent! With an excessively enduring battery of 4230 mAh, you can be out on the town in the city for a considerable length of time together without agonizing over coming up short on power!

Monday, 24 February 2020

How to solve API validation error in sbi paytm Bhim?


Transaction Status API

Checksum required: Yes


Use Case:

•           To re-confirm the status of exchange before conveying the item or administration to the client, vendor needs to coordinate the Order ID and exchange sum returned in the reaction of this API against that sent in exchange demand. In the event of befuddle, item or administration ought not be satisfied. Furthermore, the terminal status of exchange gave ought to be treated as the last status of exchange.

•           To get status of an installment exchange where constant reaction was not given (because of framework disappointments, API break and so on.).

•           To get terminal status of exchange when the status was conveyed as pending accordingly of procedure exchange.

ATTRIBUTE 
DESCRIPTION
MANDATORY
MID
String(20)      



           
This is a remarkable identifier given to each dealer by Paytm. MID is a piece of your record certifications and is diverse on arranging and creation condition. Your organizing MID is accessible here and creation MID will be accessible once your enactment is complete
Yes
ORDERID
String(50)       Order ID is vendor's exceptional reference ID for an exchange went in the exchange payload. This is Order ID for which the exchange status should be fetched
Yes
CHECKSUMHASH
String(108)     Signature to abstain from altering. Produced utilizing server side checksum utility accessible here.
Yes
TXNTYPE
String(10)
The kind of exchange whose status should be checked by dealer conceivable worth PREAUTH/RELEASE/CAPTURE/WITHDRAW.
No

Response Attribute

ATTRIBUTE 
DESCRIPTION
MID
String(20)      
This is an extraordinary identifier given to each dealer by Paytm
TXNID
String(64)      

This is an exceptional Paytm exchange ID comparing to Ordered ID for which status is being checked.
ORDERID
String(50)      
Order ID is vendor's one of a kind reference ID for an exchange sent in demand.

BANKTXNID
String(50)      
The exchange ID sent by the bank. In the event of Paytm restrictive instruments as well, there is interesting reference number produced by Paytm's framework. On the off chance that the exchange doesn't arrive at the bank, this will be NULL or void string. Essential purpose behind this is client dropping out of the installment stream before the exchange compasses to bank to servers
TXNAMOUNT
String(10)      
Order estimation of the exchange in INR. Vendor ought to approve this sum against that send in exchange demand payload. On the off chance that the sum doesn't coordinate, trader ought not offer the types of assistance to client. This is expected to maintain a strategic distance from solicitation and reaction altering conceivable at the hour of exchange.

STATUS
String(20)      
This contains the exchange status and has just three qualities: TXN_SUCCESS, TXN_FAILURE and PENDING.

RESPCODE
String(10)      

Codes allude to a specific explanation of installment disappointment. Rundown right now.
RESPMSG
String(500)    

Description message joined with each respcode. Rundown right now.
TXNDATE


DateTime        Date and time of exchange in the configuration "yyyy-MM-dd HH:mm:ss.S"

Eg-"2015-11-02 11:40:46.0"

GATEWAYNAME

String(15)      
Gateway utilized by Paytm to process the exchanges. For Credit,Debit Cards and UPI - Gateway used to process the exchange.

For instance, if HDFC door has been utilized to process SBI charge card exchanges, the worth will be HDFC.

For Net banking and wallet, worth will be Issuing Bank name and Wallet separately.

BANKNAME

String(500)    
Name of giving bank of the installment instrument utilized by client. For Credit Cards, Debit Cards, Netbanking - Name of the giving bank.

Model in the event that client utilizes SBI's charge card, the worth will be "SBI".

For Paytm Wallet, worth will be Wallet.

In the event of UPI, this parameter won't be available in the reaction.

PAYMENTMODE
String(15)      
The installment mode utilized by client for exchange
Charge card – CC
Check card - DC
Net banking - NB
UPI - UPI

Paytm wallet – PPI
Postpaid - PAYTMCC

TXNTYPE
String(5)

The estimation of this parameter is "Deal" for the installment.
REFUNDAMT

String(10)      
Total combined discount sum against this exchange. For instance for an exchange. with request an incentive as INR 100, there has been two discounts of INR 20 and INR 30 truly, at that point REFUNDAMT will be INR 50.

 

Response Code:


RESPCODE               

STATUS
RESPMSG
01
TXN_SUCCESS
Txn Success
227

           
TXN_FAILURE
Your installment has been declined by your bank. It would be ideal if you contact your bank for any questions. On the off chance that cash has been deducted from your record, your bank will illuminate us inside 48 hrs and we will discount the equivalent.
235

             

TXN_FAILURE
Wallet balance Insufficient, bankName=WALLET
295

             

TXN_FAILURE
Your installment flopped as the UPI ID entered is inaccurate. If you don't mind attempt again by entering a legitimate VPA or utilize an alternate strategy to finish the installment.
334

             

TXN_FAILURE
Invalid Order ID
400

           
PENDING
Transaction status not affirmed at this point.
401

             

TXN_FAILURE
Your installment has been declined by your bank. If it's not too much trouble contact your bank for any inquiries. In the event that cash has been deducted from your record, your bank will educate us inside 48 hrs and we will discount the equivalent.
402

             

PENDING
Looks like the installment isn't finished. If it's not too much trouble pause while we affirm the status with your bank.
810
           
TXN_FAILURE
Txn Failed




Wednesday, 28 August 2019

Identity theft Fraud


Identity Theft Fraud

  1) Introduction to Identity Theft

  Identity theft is stealing someone’s identity and pretends to be them usually to gain access to the victim benefits. This can be financial, social or even worse criminal.

  2) Identity theft occurrence

   According to privacy trust group the following are the statistics:
ID theft is the fastest growing crime n US(FBI)
1 in 5 people has now been a victim of identity theft.(FTC,FBI,Fraud invest, & javlinBB)
Total number of victims is now over 50 million individuals. This mean that 1 in 5 people in the US is now a victim of ID theft.
2 years ago 1 in 8 people was a victim(FTC), today 1 in 5 – individuals who was have never been victims of ID theft may soon be a minority.
85+ million people were victims of identity theft by 2018.(FTC)
15.3 million Americans were victims of identity theft in 2018(Javlin/BBB)
The number of new victims annually over the past several years has been approximately 50 million.
The losses to victims have been, and continue to be, signature
Identity theft costs individuals business in money and product stolen, costs of recovery and fraud investigation, and opportunity costs.
      

3)Impact of Identity Theft Fraud


               *Financial Problems
                              An attacker may not just get access to the bank account and drain it off money, but also create a credit card and run up a bill, without your knowledge.


               *Credit issues
                             Once under financial duress, credit report also starts to suffer. The credit score goes down and then getting mortgages or losses become almost impossible.

               *Benefit losses
                              Stealing the identity gives the attacker to benefits that belong to victim, whether it’s related to its medical or other benefit.

               *Legal Problems
                              Given all these issues naturally there will be legal issues that a victim gets entangled in, getting maybe even arrested for crime they did not commit.

4)Types of identity theft


        *Stolen Wallet
                       A wallet by default carries all personal information related to a victim. Address, license, cards perhaps even photos of love ones; this is enough information for the attacker to gain access to victims life.  

        *Change of address
                       Attackers change the mailing address rerouting the mail to their own location. This sends all information into the wrong hands.

        *Mail Theft
                       As the name suggests, attackers steal mail right from the front door.

        *Online Shopping
                       Attackers may Duplicate online store fronts in order to steal and gain access to confidential information.

5)Dumpster

        Attackers or thieves search the dumpster for the documents that have been casually discarded to get access to information they need to commit fraud.

6)E-Mail Theft

        Attackers can hack into an email and either reroute the mail to themselves or worse close the account by changing the password. Any mail received during this blocked period is data for attacker.

7)Smashing

        Thieves send text massage to a mobile device that pretends to be a contact and then directs the victim to a dangerous website with the idea of stealing their identity.

8)Vishing

        Voice-calls to landlines or mobile phone are effective ways for attackers to get personal INFORMATION.

9) ATM Schemers/Hand-head skimmers


        Attackers swipe the credit card in middle of legitimate like paying bills.

10)Prevention Techniques


       According to US government site, which recognises identity theft frauds as a real and present danger, they have issued a checklist for preventing identity theft:

*Don’t carry your social security card in your checks. Only give out your SSN when absolutely necessary.
*Protect your PIN, Never write a PIN on paper or any other place.
*Watch out for “Shoulder surfers”. Use your free hands to shield the keypad when using pay or Using ATM.
*Pay attention to your billing cycle.
*Store your personal information on safe place at home and work place.
*Install firewall and virus detection software on your home computer.
*Check your credit report twice a year.


Some Best Anti virus :- 1. McAfee total Protection  2.Nortan Security Standard                                    
3.Quick heal antivirus pro  4.AVG Antivirus for mobile         

                                     



WEP INSECURITIES

  WEP I NSECURITIES Two researchers from the University of California at Berkeley and one from Zero Knowledge Systems Inc. published a repor...