Pages

How To Set up a SOCKS proxy Using Putty & SSH

How To Set up a SOCKS Proxy Using Putty & SSH
If you ever find yourself in front of a public computer connected to the Internet and are concerned about the security of the path between you and a website you wish to visit, a SOCKS proxy can come in handy.
SOCKS proxies generally allow you to “bounce“ a TCP connection off another server transparently“ basically instructing another computer to make a connection on your behalf. When used in combination with Secure Shell (SSH), it can form an encrypted tunnel that insulates you from anyone attempting to grab traffic off the wire.
The following is a simple step-by-step tutorial about how to do this.
You will need:
-Putty SSH client: http://www.putty.org -An account on an Internet-accessible server that accepts SSH connections and allows connection forwarding (enabled by default)
-A popular web browser or other software that supports SOCKS communications
Step 1:
Fire up Putty and navigate to the Session Category
Step 2:
Enter the hostname/IP address and port of the server on which you have an account.
(Note: The default SSH port is 22)
This tells Putty how to connect to the SSH server.
Step 3:
Under the SSH->Tunnels Category Enter the following: Source port: 8888 (or any port of your choosing. Just be sure to remember what it is) Destination: hostname/IP address of the server on which you have an account
Also, select the “Dynamic“ radio button.
This tells Putty that, upon a successful connection, a SOCKS tunnel should be opened from a port on the computer you are using to the SSH server.
Step 4:
Click “Add“ The forwarded port is now added to the connection settings.
Step 5:
Click “Open“ to start the connection
Putty will ask for your login credentials. In most cases, this will be a username and password. (For extra security and bonus cool points, have your SSH server only accept certificates)
At this point, your Putty-enabled SOCKS proxy should be active. But how do we test it out? Keep reading“
Step 6:
Fire up your web browser and navigate to its proxy connection properties menu.
For Firefox 3, it is in Tools->Options->Advanced->Network(tab)- >Connection, Settings
For IE6, it is Tools->Internet Options->Connections(tab)->LAN Settings(button)->Advanced(button)
Step 7:
Find the SOCKS settings text box and enter the following: Proxy Address/Host: localhost OR 127.0.0.1 Port: 8888 (or whatever port you decided to use in Step 3)
Ensure SOCKS Version 4 is selected
Note: DO NOT enter any other proxy settings for other protocols (this includes the “use proxy server for all protocols“ option. Don“t enable it. I“m serious. If you do, things might not work correctly.)
Step 8:
Click “OK“ until you“re back to your browser.
Go to http://ipchicken.com and check your IP address. It should be different from the machine you“re on. In fact, it SHOULD be the IP address of the SSH server (or whatever machine is handling its connections).
Step 9:
Pat yourself on the back. Or have your buddies do it for you“ they“ll no doubt be impressed by your newfound computer skills. Enjoy browsing the web using your own personal SSH proxy.

NOTE: Although this could be useful when using a public computer“ it won“t protect you from local machine monitoring tools (keyloggers, screen captures, etc). Always exercise due diligence when using untrusted computers.

How to Setup OpenVPN Connect on Windows

How to setup OpenVPN Connect on Windows
A. Download and Install OpenVPN GUI
1. Download the latest stable community version of OpenVPN client (Windows Installer) HERE Note: If you have a 32-bit Operating System, download the 32-bit version of the installer. You can check your System Type by going to Control Panel > System and Security > System.
2. Open the folder where installer is downloaded and double-click the 'openvpn-install- <version>.exe' file to begin installation.
3. You may encounter a Security Warning screen: "Do you want to run this software?" If you see the Security Warning screen, click Run to run the software.
4. The Setup Wizard prompt will appear. Click Next to continue.
5. The OpenVPN license agreement and terms appear. Click I Agree to continue.
6. The component selection dialog appears. Leave all components checked with their default settings and click Next.
7. Select your destination folder and click Install. Note the Destination Folder location during install (usually C:\Program Files\OpenVPN)
8. When the installation is complete, click Next.
9. The wizard will notify you of the completion of the installation and prompt you to click Finish.
B. Download and copy the .ovpn profiles to the OpenVPN config folder
1. Visit our Network page HERE
2. Select an OpenVPN server location you wish to connect to and then click Get Profile to download .ovpn profiles. Repeat step to download more profiles
3. Open the folder (usually the ‘Downloads’ folder) where you’ve downloaded the profiles and then copy them to C:\Program Files\OpenVPN\config folder Note: If you get a pop-up message that says ‘You’ll need to provide administrator permission to copy to this folder’, click ContinueHow to Connect to OpenVPN
1. To connect, find the OpenVPN GUI icon on your desktop and double-click it to launch OpenVPN.
Note: On Windows 7, Vista, 8 and 8.1, run the program as administrator to enable the program to make changes to your computer and update the network configuration. a) Right-click the OpenVPN GUI icon and select Properties. b ) Click ‘Compatibility’ tab and check ‘Run this program as administrator’ c) Click Apply. Note: If you get a pop-up window asking if you want to allow the program to make changes to your computer, click ‘YES’.
2. In the system tray, right click on the OpenVPN GUI icon.
3. Find the site to connect to from the menu, and choose Connect from the site's submenu.
4. Enter your VPN username and password when prompted and click OK.
5. The OpenVPN GUI icon in the tray will turn green once the secure connection is established.
How to Disconnect from OpenVPN 1. Click the OpenVPN icon on the system tray to open the menu.
2. Select the active connection (the one with a check mark) and then click 'Disconnect’
Automatic login without manually entering VPN username and password Are you thinking of 'automatic login' without the need to enter password every time you want to
connect to OpenVPN? If so, please read on. Currently, there is no secure way to store the user name and password in Windows using OpenVPN. For security purposes, most versions of OpenVPN do not allow a user/password to be read from a file. If you are willing to take the security risk of having your login information saved in the clear on your hard drive, you can use the OpenVPN Community client and set it up to automatically log in. Recognizing the security risks, the procedure is as follows:
1. If you do not have OpenVPN GUI installed yet, download and setup it up first.
2. Navigate to C:\Program Files\OpenVPN\config folder
3. Using a text editor like Wordpad or Notepad, create a file name ‘password.txt’
On the first line, type your VPN username (12345 in this example) On the second line, type your VPN password
Save the file. 3. Next is to open and edit your .ovpn file with Wordpad and find the line that reads 'auth-user-pass'. Change it to 'auth-user-pass password.txt' (without the quotes). Save and exit.

4. Test the connection and see if it will connect automatically.

How To Setup Proxifier Quick Start

Proxifier: Quick Start

Install and launch Proxifier. The Proxifier icon showing traffic (information flow) will appear on the system tray. On Windows 7, the icon can be hidden.



Double click the system tray icon to open the main window of the program. Alternatively, you can start Proxifier again from the start menu and the existing running instance will be detected and will activate the main Proxifier window.

By default, Proxifier is configured to bypass all network connections. You can still see connections and DNS requests if you enable verbose output

Log->Output Level->Verbose.

Proxifier can process the connection directly (without a proxy server). To enable this mode, set Profile->Advanced->Handle Direct Connections. It can be useful to troubleshoot problems and utilize some features of Proxifier like traffic dumps, bandwidth and connection monitor, etc.

To make the connections work through a proxy server or a chain of proxy servers, you must first define a proxy server in Proxifier. Click Proxy Servers...
in the Profile menu or click on the icon located on the toolbar:


WARNING!

If you were using proxies before you installed Proxifier you should disable any built-in proxy settings. Your applications should then be configured to connect “directly” to the Internet (rather than through proxies).
Fill in the form specifying the details of the proxy server (address, port, protocol, etc.) that you want to add and click OK:




Proxifier will ask you whether or not you want to use this proxy by default. Click Yes to set it as the target for the Default Proxification Rule. You can change this anytime later at Proxification Rules

How to Use PGP

Exchanging Files with PGP



PGP by the PGP Corporation offers public key file encryption according to the RFC 4880 (Open PGP) standard using NIST standard algorithms, including AES-256, Diffie-Hellman/ DSS, and SHA-512. NSA has completed an evaluation of file encryption with PGP desktop version 9.6 and has the following recommendations for use.

This guide provides guidance for sending encrypted files via e-mail and protecting them in transit. It is NOT appropriate to use these steps to protect data at rest. The steps described below are written for a computer using a Windows XP operating system although for other operating systems, the steps would be very similar. Note that the location of PGP Desktop in the start menu may be different from one installation of PGP to another.

1. Creating a Public/Private Key Pair
To enable the encryption of files between two users, both users must first generate a public/private key pair and exchange public keys with each other. To generate a key pair, use the PGP Key Generation Assistant. Follow these steps:

1. Start PGP Desktop (if it is not already started) by clicking

Start->All Programs->PGP->PGP Desktop.



2. Select the PGP Keys tab on the left side of the window.
3. Select File->New PGP Key.

4. PGP Key Generation Assistant:

Leave the Generate Key on Token box unchecked (it will most likely be grayed out anyway) and click Next.

5. Name and E-mail Assignment: Enter your name and an optional e-mail address. Click Advanced.
6. Advanced Key Settings: Select the following NSA recommended settings.
▼▼ Key type: Diffie-Hellman/DSS

▼▼ Generate separate signing subkey: Check this box
▼▼ Key size: 4096

▼▼ Expiration: Choose an expiration date of one year from the date
of creation.
▼▼ Ciphers: Check only AES

▼▼ Hashes: Check only SHA-2-512



All users who will be exchanging encrypted files should use these settings.

7. Click OK, then click Next.

8. Passphrase Assignment: Choose a strong passphrase and enter that same passphrase into both the Passphrase and Confirmation fields. Consult your organization’s policy for appropriate passphrase strength. (NSA recommends at least 8 characters including upper-and lower-case letters, numbers, and symbols.) Click Next.

9. Key Generation Progress: Click Next.

10. Completing the PGP Key Generation Assistant: Click Done.

11. You should see the new key pair listed under All Keys.

2. Distributing Your Public Key
Next, you’ll need to exchange public keys with anyone with whom you would like to exchange encrypted files. To send your key to someone, you can simply export your key to a file and include the file in an e-mail as follows:

1. Start PGP Desktop (if it is not already started) by clicking

Start->All Programs->PGP->PGP Desktop.

2. On the left side of the application, click the PGP Keys tab.

3. Select your name from the keys listed under All Keys. (If the name is expanded and you see the name several times, choose the name at the top.)

4. Click File->Export->Key. Using the dialog, save the file to the desktop. This will result in the creation of a file

containing your public key. Note: this file does not contain the private key, as only you are allowed access to your private key.

5. Compose an e-mail with your mail client and include this new file as an attachment. Address the e-mail to the person with whom you want to be able to exchange encrypted files.

6. Send the e-mail.
7. Delete the key file from your desktop.

3. Receiving a Public Key
In order for you to be able to send encrypted files to other users, they must send you their public key using the steps in Section 2. Once you have received their key, you must add that key to your collection. To do so, use the following steps:

1. Start PGP Desktop (if it is not already started) by clicking

Start->All Programs->PGP->PGP Desktop.
2. Save the attached public key file to your desktop using your mail client.

3. Drag and drop the key file onto PGP Desktop.

4. Click Import.
5. Section 4 describes how to verify the sender’s public key.


The Information Assurance Mission at NSA

Exchanging Files with PGP

(continued)



4. Verifying a Public Key
When public keys are exchanged, it is important for the recipient of each key to verify that the key belongs to the sender. To do this, both the recipient and the sender should do the following:

1. Start PGP Desktop (if it is not already started) by clicking

Start->All Programs->PGP->PGP Desktop.

2. Select the PGP Keys tab on the left side of the window.
3. Click on the name of the person that needs to be verified. (If the name is expanded and you

see the name several times, choose the name at the top.)

4. Select Keys->Key Properties from the menu bar at the top of PGP Desktop.
5. If necessary, expand the section labeled Fingerprint.

6. In the Fingerprint section, select the Biomeric tab.
7. Have either the sender or the receiver read the 20 words

aloud over the phone to ensure that the keys match. If they match, the key in question is verified. The biometric data should be checked for each key that is exchanged.

Assuming the words match, the user who received the public key should now mark the public key as valid by signing it. Do this using the following steps:

1. Close the key properties window.

2. In the PGP Desktop main window, click on the name of the person who sent the key. (If the name is expanded and you see the name several times, choose the name at the top.)
3. Select Keys->Sign from the menu bar at the top of PGP Desktop.

4. PGP Sign Key: Click OK.

5. PGP Enter Passphrase for Selected Key: Select your name from the drop-down menu. Enter your passphrase. Click OK. (Note: the passphrase may have been cached, in which case it does not need to be entered.)

6. The sender’s public key should now have a green check mark next to it indicating that it is verified and trusted.

5. Sending an Encrypted File
Now that you have a key pair and some public keys of other users, you can encrypt files to send to those users. You can also sign the files so that others will know that the files were sent by you.



To do so, follow these steps:

1. Start PGP Desktop (if it is not already started) by clicking

Start->All Programs->PGP->PGP Desktop.

2. Click the New PGP Zip button.

3. New PGP Zip: Drag and drop the file(s) to be encrypted into the box. Click Next.

4. Encrypt: Select Recipient Keys. Click Next.

5. Add User Keys: Choose the recipient

username from the drop-down list. Click Add. Repeat if there are multiple recipients. Then click Next.
6. Sign and Save: Choose your name from the drop-down list. Enter your passphrase. (Note: the passphrase may have been cached, in which case it does not need to be entered.) Choose a place to save the encrypted file. Click Next. You will receive a message saying that your PGP Zip is secured.

7. Finished: Click Finish.

8. You should see a new PGP-encrypted version of the file in the location you chose. The original, unencrypted file will also still be there.

9. Attach the encrypted file to an e-mail using your mail client and send to the appropriate recipient(s).

6. Receiving an Encrypted File

When a user sends you an encrypted file, use the following steps to decrypt it and verify the identity of the sender:

1. Start PGP Desktop (if it is not already started) by clicking

Start->All Programs->PGP->PGP Desktop.

2. Save the attached PGP Zip file to your desktop using your mail client.

3. In PGP Desktop, select File->Open.

4. Using the file dialog, select the file from the desktop and click Open.

5. The decrypted file should now be visible in the main PGP Desktop window. Note the Status section. Make sure that the file is not marked “invalid.” If it is, the file may not have been sent by the person you think.

6. To save a copy of the decrypted file, right click the file, select Extract and choose a folder or location to extract the file to.


Systems and Network Analysis Center (SNAC) 410-854-6632

www.nsa.gov/snac snac@radium.ncsc.mil

Instant Messenger Setup Guide

Instant Messenger Setup Guide
This is my newbie­friendly guide to setting up instant messenger services anonymously. The ICQ/Jabber guide is for Pidgin IM client, which has been known to leak DNS under certain circumstances so I recommend your setup is VPN ­> Tor to mitigate any risk. I am assuming you already have Tor setup and running for the following configurations.
[Edit] Note: If you have the Tor Browser Bundle and haven't installed Tor separately, use port 9150 instead of 9050 for the following configurations.
Torchat
TorChat is a decentralized anonymous instant messenger that uses Tor hidden services as its underlying Network. It does not require any additional anonymizing steps after install. Download from: https://github.com/prof7bit/TorChat/downloads (Windows/Linux) http://www.sourcemac.com/?page=torchat (Mac OS X unofficial port)
Reference: https://en.wikipedia.org/wiki/TorChat
ICQ
Sign up for an account at http://www.icq.com/join/en Enter any first and lastname you like and email for confirmation (any free email works). Log into account at icq.com, and note your UIN (ICQ number). In Settings, select "only your name viewable" and "nobody can see your contact list". Save and logout.
Download Pidgin IM client: http://pidgin.im/download (Windows/Linux/Mac OS X)
In Tools ­> Preferences ­> Network, disable "Use automatically detected IP address" disable "Automatic router port forwarding"
In Tools ­> Preferences ­> Proxy, Proxy type: Socks5 Host: 127.0.0.1 Port: 9050 (Leave remote DNS for socks4 unchecked)
In Accounts ­> Manage Accounts ­> Add Protocol: ICQ Username: ICQ UIN Password: Password you entered during setup
For added security, install the OTR plugin to encrypt your messages. Download from http://www.cypherpunks.ca/otr
Jabber
Follow instructions above for setting up Pidgin IM client.
In Accounts ­> Manage Accounts ­> Add Protocol: XMPP Username: choose your username Domain: server you want to use (http://xmpp.net has a list) Password: choose a password
Check "Create this new account on the server" If you get an authorization error, you may have to sign up on the website.

For added security, install the OTR plugin to encrypt your messages. Download from http://www.cypherpunks.ca/otr

Mac Address Changer

Technitium MAC Address Changer
Version: 6.0.4 Programmer: Shreyas Zare System Requirements:Windows 2000/XP/Server 2003/Vista/Server 2008/7/Server 2008 R2/8/Server 2012
Technitium MAC Address Changer allows you to change (spoof) Media Access Control (MAC) Address of your Network Interface Card (NIC) irrespective to your NIC manufacturer or its driver. It has a very simple user interface and provides ample information regarding each NIC in the machine. Every NIC has a MAC address hard coded in its circuit by the manufacturer. This hard coded MAC address is used by windows drivers to access Ethernet Network (LAN). This tool can set a new MAC address to your NIC, bypassing the original hard coded MAC address. Technitium MAC Address Changer is a must tool in every security professionals tool box.
There are some famous, commercial tools available in the market for USD 39.99 to as much as USD 2499!, but Technitium MAC Address Changer is available for FREE. We don't charge for just changing a registry value! Also knowing how this works doesn't require extensive research as some commercial tool providers claim! Read how it works (below) for more details.
Features
• Internet Protocol v6 (IPv6) support added.
• Works on Windows 7 and Windows 8 for both 32-bit and 64-bit.
• Automatic Update feature added to update software to latest available version.
• Update network card vendors list feature allows you to download latest vendor data (OUI) from IEEE.org.
• Enhanced network configuration presets with IPv6 support allow you to quickly switch between network configurations.
• Command line options with entire software functionality available. You can select a preset from specified preset file to apply directly.
• Issues in previous version ironed out.
How Does It Work ?
This software just writes a value into the windows registry. When the Network Adapter Device is enabled, windows searches for the registry value 'NetworkAddress' in the key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325- 11CE-BFC1- 08002bE10318}\[ID of NIC e.g. 0001]. If a value is present, windows will use it as MAC address, if not, windows will use the hard coded manufacturer provided MAC address. Some Network Adapter drivers have this facility built-in. It can be found in the Advance settings tab in the Network Adapter's Device properties in Windows Device Manager.
How To Change MAC Address
1. Starting MAC address changer will list all available network adapters.
2. Select the adapter you want to change the MAC address. You will get the details of your selection below.
3. In the Information tab, find the Change MAC Address frame. Enter new MAC address in the field and click Change Now! button. You may even click Random MAC Address button to fill up a randomly selected MAC address from the vendor list available.
4. To restore the original MAC address of the network adapter, select the adapter, click Restore Original button in the Change MAC Address frame.
NOTE: This tool cannot change MAC address of Microsoft Network Bridge. Network Bridge will automatically use the original MAC address of the first NIC added into bridge with the first octet of MAC address set to 0x02.

Receive calls & SMS undetected. Untraceable VOIP

For questions you can contact me on ICQ 653092048 Jabber Osquare@lsd-25.ru
Receive calls & SMS undetected. Untraceable VOIP - unlimited numbers, no more burners Many people are wasting money on prepaid cell phones and SIM cards. This is a good method, but there is a more effective trick, and it allows you to receive calls 24/7 while being 100% untraceable. I do that since I started carding, in fact I never got a SIM card and I have near 100% success rate in carding.
You will be able to call and receive calls, all from home. Here's the trick.
You will need: - 1 physical VoIP phone (you can "buy" one for around $60 online, or card it at http://www.voipsupply.com/voip-phones )
- 1 RingCentral account (card it at www.ringcentral.com/ )
Step 1) Make your router connects with VPN instead of Dynamic IP
- A router that supports VPN connection (pretty much any TP-Link, Dlink, Linksys in houses support it unless you have a VERY old one) (you can card it too)
Your ISP told you to configure the WAN of your router to use Dynamic IP. It works. But you can select VPN instead. I suggest PureVPN as I've been totally successful with them. So now that your router uses VPN for the Internet connection, ALL traffic between you and the outside is encrypted. This includes laptops, computers, iphones... everything on your network. Your ISP can't snitch on you. Yep, putting the VPN setting directly in your router. If you don't know how to configure the WAN connection type of your router, Google it. Make sure your Internet works after doing that.
Step 2) Create an account on RingCentral
RC is my favorite platform for that. They are easy to card (although they sometimes ask for you to call them to set the account for the first time), and it allows you to have an unlimited number of phone numbers pointing to the same place, all with different voicemails. Useful to impersonate your cardholder. You can select the state / city and get a local number, and make them point to the same place, i.e. your VoIP phone. So create an account. Plus, they have free phone support to configure if you need help.
Step 3) Configure your VoIP phone
RingCentral will give you the parameters to put in your phone (I recommend the Aastra brand as they are good). This includes your phone number, user, password. All your burner numbers will point to the same number, so you never need to touch the configuration again. Make sure your phone is configured and works. Make a few test calls to ensure your phone is up and running. You now have a phone that works through your VPN, making it completely untraceable. You can leave it on 24/7. If the bank investigates the phone number, they will see it is with RingCentral. Who's the owner of the account? Some dude that got his card stolen. Where are the VoIP connections originating from? A VPN server... let's go eat donuts. This way, you can receive calls from the bank or the merchants without any problem and
Page 1
Receive calls & SMS undetected. Untraceable VOIP - unlimited numbers, no more burners without being traceable. You never need to change phone or to reconfigure it. Just add a phone number when you have a new card to ATO or to put a contact phone number.
Everyday, my phone rings and it's the fraud department of a bank wanting to verify transactions. I take the call and confirm everything. Piece of cake.
Now, NEVER make calls unrelated to carding with that phone. You don't want your RC account to contain bank numbers AND the number of your girlfriend, which may be a track to follow for LE. With all that, you will never get caught.
For questions you can contact me on ICQ 653092048 Jabber Osquare@lsd-25.ru

Page 2

Statistics Help Online

Are you a college student taking a statistics course and interested in paying someone to do mymathlab  for you ? We provide stats help in ar...