Showing posts with label networking. Show all posts
Showing posts with label networking. Show all posts

What Is VPN And How It Works


VPN stands for virtual private network, the private network (not for public access) that uses a non-personal medium (eg, the Internet) to connect between remote-site safely. The application of certain technologies in order to even use a common medium, but traffic (traffic) between the remote site can not be intercepted easily, nor allow others to smuggle undue traffic to the remote site.


According to the IETF, the Internet Engineering Task Force, a VPN is an emulation of [a] private Wide Area Network (WAN) IP using shared or public facilities, such as the Internet or private IP backbones.VPN is a form of public private network via the internet ( internet), with emphasis on data security and global access via the internet. This relationship is built through a tunnel (tunnel) between 2 virtual nodes.

is a private network (usually for a particular agency or group) in the Internet network (public), which is a private network as if they were accessing its local network but using public networks

VPN is a virtual connection that is private why are so called because in essence this network does not exist physically only a virtual network and why it is called private because this network is a network of private nature that not everyone can access it. VPN Connecting the PC to the public network or internet but its nature private, because it is private so not everyone can be connected to the network and access it. It is therefore necessary data security
VPN working concept basically requires a VPN server that berfungsing as a liaison between PCs. If pictured something like this
Internet <-> VPN Server <-> VPN Client <-> Client
when used to connect 2 computers with a private network such as the internet then this: A Computer <-> VPN clinet <-> Internet <-> VPN Server <-> VPN Client <-> Computer B
So all connections are set by the VPN Server VPN Server so it needs adequate skills so connections can be smoothly.

then what the hell do this VPN?? first of all VPN Server must be configured first and then in the VPN client program must be installed only after that can be connected. VPN on the client side will be making some sort of virtual connections so it will appear sort of VPN network adapter adater network (Lan card) but virtual. The task of VPN Client is doing authentication and encryption / decryption.
Well once connected then later when the client accessing the data tell a client wants to open the site http://www.google.com. This request before it is sent to the VPN server is encrypted by the first instance encrypted VPN Client with a formula that will contain the data request codes. After arriving to the VPN server by the server to decrypt this data in the formula A, having previously been configured between the server and the client, the server will have the same algorith to read an encryption. Vice versa, from server to client

Thus, the concept of security with VPN network offers security and untraceable, can not be detected so that our IP is not used is known as Public IP belongs to VPN servers. With no encryption and decryption of the data through the internet network is not accessible by others even by another client connected to the same VPN server though. Because the key to unlock the encryption is only known by the VPN server and client are connected. Encryption and decryption can cause data to be modified and read so keamananya guaranteed. To break down the data pirate decryption process data must pass the course to find the right formula takes a very long time so it is common to use super computing to break down and of course not everyone has a PC with this super abilities and the process is complicated and takes a long time, the agents FBI or CIA usually have this kind of computer to read confidential data that is sent through the VPN.

Is using a VPN connection is faster????? It depends on the connection between the client and the VPN server for the data processing is done on the VPN automatically all the data is entered into our computer from the Internet will go first to the VPN server so that when a client connection to a VPN server connection is good then it will also be much faster. Usually what happens is a slight decrease in speed is slower because it must first pass through 2 pathways including the encryption process. The VPN connection can be used to accelerate external (international) how???
for example, we have a local connection (IIX) equal 384kbps 1mbps and external connections use VPN so that we could be the same as the international connection local connection 1mbps. Ways to use VPN to VPN routed Local Affairs

Internet <-> VPN Affairs <-> VPN local <-> Client

why this network model can be faster because access to the outside network by external VPN and then forwarded by the local VPN nah we access to the local network, which means the access speed of 1mbps. Certainly needed a VPN with a large bandwidth so that connections can be smoothly.

Well why the HSDPA connection macem Telkomsel and Indosat get faster??? Operators to limit the bandwidth of the internet we say IM2 with 256kbps package if we use 3G and HSDPA networks sebenarny then we have a bandwidth of 384 kbps and 3.6 Mbps for HSDPA but only use 256kbps because the operator is restricted to the VPN server limitation can be broken ways will be discussed further.

Is able to make the Internet free and non-quota??? answer can be used as long as the gap is unknown operator. How to do this is to use a VPN to access a particular port server. Operators typically use a specific port for billing calculations and total unused data which can be exploited this loophole. For example there are certain ports that can be used to connect to the VPN server can be used free internet and free qouta. Why is that??? Port is not used for the calculation of billing so we did not pass well to the billing server port, then we can connect to the VPN server over the network internet.kita connect to the internet but do not pass through our automatic billing server not be charged and count calculated if the data does not count for very little pinging the server. By connecting to the VPN server then all access will be performed by the VPN server and transmitted through an open port earlier so that we could freely access the intenet. Such technique less there may be other techniques due to VPN has many advantages

Another advantage of a VPN is access anywhere. We have access to a computer at home through a VPN network for Internet-connected computer at home and we have Internet access required only for  VPN Client software configuration and authentication process. That way we can access the internet safely and undetected



Then How VPN works.?


Let's use an example to explain how the VPN works. Virtual Entity Networks Inc.. (VEN Inc.) Has two branches, London and Sydney. If the Australian branch in Sydney decided to contract the dealer, then the London office had to know right away. The main part of the IT infrastructure is provided in London. In Sydney there are twenty people whose jobs depend on the availability of data hosted on Server London.



Both locations are equipped with a permanent internet lines. Internet is a gateway router is set up to provide Internet access to staff it. Successor is set to protect the local network location from unauthorized access from the side, which is the "evil" internet. Successor as it provides for blocking specific traffic can be called a firewall and must be found within the individual branches are thought to take part in the VPN.

VPN software must be installed on the firewall or a server or appliance that is protected by it. Many firewalls modern equipment from manufacturers such as Cisco or Bintec include these features, and no VPN software for all hardware and software platforms.

In the next step, the VPN software must be set up to establish a connection to the VPN server instance lainnyasebagai London must accept connections from Sydney server, and the server must connect Sydney to London or vice versa. If this step is successfully completed, the company has a Virtual Network. Both branches are connected to the internet and can work together as in a real network. Here, we have a VPN without any privacy, because many internet roter between London and Sydney can read data exchange. A competitor who gained control of the internet on a roter can read all relevant business data network that actually was. So how do we create a Virtual Private Network? The solution is encryption. VPN path between two branches locked with a special key, and only the person or computer that has the key that can open and look at the data sender.



All data sent from Sydney to London or from London to Sydney should be encrypted before transmission and decrypted after. Encryption protects data in such connection from the walls of a train tunnel to protect the mountain around it. This explains why it is often known as a VPN tunnel (tunnel) or VPN tunneling, and tunneling technology is often referred to-even if no other Kwantum mechanics involved.

Proper encryption methods and provide the key to all partitions involving one of the main differentiating factor between different VPN solutions. A VPN connection is normally established between two routers internet access that comes with a firewall and VPN software. The software must be set up to connect to the VPN partner, the firewall must be set up to be able to access and exchange data between the VPN partner with encryption. Encryption keys must be presented for all VPN partner, so that exchanged data can only be read by authorized VPN partner.

How Hacker Hack/Attack Your Website


The hackers used his expertise in computers to view, find and correct flaws in the security system of a computer system or in a software. However, how does a hacker to penetrate the system a website? IP Spoofing IP Spoofing is also known as the Source Address Spoofing, namely forgery attacker's IP address so that the target considers the attacker's IP address is the IP address of the host in the network instead of from the outside network. Suppose the attacker has type A 66.25.xx.xx IP address when this type of attacks attackers then assaulted Network which will assume the attacker IP is part of the IP networknya 192.xx.xx.xx eg type C.

IP Spoofing 

occurs when an attacker 'outsmart' packet routing to change the direction of the data or transmissions to different destinations. Packet routing is usually transmitted to a transparent and clear so it makes easy for an attacker to modify the data source or destination of the data. This technique is not only used by the attacker, but also be used by security professionals to download tracing the identity of the attacker.

 FTP Attack

 One of the attacks carried out against the File Transfer Protocol is a buffer overflow attack caused by malformed command. destination FTP server to attack this average is to get a command shell or to perform a Denial of Service. Denial Of Service attacks may eventually lead to a user or attacker to retrieve the resource in the network without authorization, while the command shell can make an attacker gain access to the server system and data files that an attacker could eventually make anonymous root-acces having the right full to the system even diserang.Sebagai example network is a popular FTP server UNIX family that WU-FTPD is always in upgrade two times a day to improve the conditions that permit the FTP exploit bufferoverflow also useful to know the password contained in the system, FTP Bounce attack (using the ftp servers of others to carry out attacks), and knowing or mensniff information is in the system.

Unix Finger Exploits

In the early days of the Internet, Unix OS finger efficient utility used to download the information sharing among users. Because the demand for information on this finger information do not blame the rules, many system administrators leave this utility (finger) with minimal security, even without any security at all. For an attacker this utility is very valuable to have information on footprinting, including login names and contact information. The utility also provides an excellent description of user activity within the system, how long the user is in the system and how much users care system. The information generated from this finger can minimize Kracker effort to penetrate a system. Personal information about the user that is raised by the finger daemon is already enough for a atacker to perform social engineering using the social skill to utilize the user to 'tell' passwords and access codes to the system.

Flooding and Broadcasting 

An attacker could reduce the speed of the network and the hosts within it is significant in a way continue to request / demand for the information of servers that can handle classic attack Denial of Service (Dos), send a request to a port in excess called flooding, sometimes it is also called spraying. When a request is sent to flood all stations that are in this attack named broadcasting network. The second goal of this attack is the same that make network resource that provides information to become weak and eventually gave up. Flooding attack in a way that is dependent on two factors: the size and / or volume (size and / or volume). An attacker can cause a Denial of Service by throwing a large-capacity files or a large volume of small packet to a system. In such circumstances the network server will deal with congestion: too much information being requested and not enough power to push the data to run. Basically a big package that requires greater processing capacity, but abnormally small package and at a high volume resource will be spent in vain, and the resulting congestion.

Fragmented Packets Attacks

Internet data is transmitted via TCP / IP can be further divided into packages that contain only the first packet of information that the contents of the main part (head) of TCP. Some firewalls will allow to process part of the packages do not contain information on the source address on the packet first, this will result in some type of system to crash. For example, the NT server will be crashed if the packages were broken up (fragmented packet) enough information to rewrite the first packet of a protocol.

Email Exploits 

e-mail  exploit occurs in five forms, namely: mail floods, manipulation command (command manipulation), the attack rate of transport (transport level attack), include a variety of code (inserting malicious code) and social engineering (utilizing physical socialization ). Email attack could cause the system to crash, open and execute even rewriting the application files or also make access to command functions (command function).

DNS and BIND Vulnerabilities 

News recently about vulnerabilities (vulnerabilities) on apps Berkeley Internet Name Domain (BIND) in various versions illustrate the fragility of the Domain Name System (DNS), which is a crisis that is directed at the basic operation of the Internet (internet basic operation) .

Password Attack

Password is a common thing when we talk about security. Sometimes a user does not care about the number of pins they have, such as online transaction in the cafe, even transact online at home is very dangerous if it is not equipped with security software such as SSL and PGP. Password is one procedure that is very difficult to attack, an attacker might have many tools (technically and in social life) just to unlock something password.Ketika protected by an attacker managed to get a password that is owned by a user, then it will have the same power to the user. Train employees / users to remain vigilant in protecting the password of social engineering can at least minimize the risk, except in case of social engineering practices organizations must be aware of this technical way. Most attacks are carried out against password guessing (guessing), brute-force, cracking and sniffing. One Attack Proxy Server Proxy server function is to speed up the response time by bringing together processes from multiple hosts in a trusted network. In most cases, each host has the power to read and write (read / write) which means that what can I do in my system I can also do on your system and vice versa.

Remote  Command Processing Attack 

Trusted Relationship between two or more host facilities the exchange of information and resource sharing. Similar to a proxy server, trusted relationships give all members equal access to the power network in one and the other system (the network). Attacker will attack the servers that are members of a trusted system. Just as the latency to the proxy server, when access is received, an attacker would have the ability to execute commands and access a user data available to others. Attack File System Remote Protocol-the protocol for data transport backbone of the internet-is TCP level (TCPLevel) with a mechanism that has the ability to read / write (read / write) between network and host. Attacker can easily obtain trace information of this mechanism to gain access to the file directory. Selective Program Program Selective insertions insertions are performed when the attacker attacks put destroyer programs, such as viruses, worms and trojans (you probably already know this term well?) On the target system. Destruction programs is often also called malware. These programs have the ability to damage the system, destruction of files, stealing the password to open the backdoor.

Port Scanning

Through port scanning an attacker can see the function and how to survive a system from a variety of ports. Atacker can gain access to the system through an unprotected port. Sebaia example, scanning can be used to determine where the default SNMP string in the open for the public, which means that the information can be extracted for use in remote attack command.

TCP / IP Sequence Stealing 

Passive Listening and PacketInterception Port TCP / IP Sequence Stealing, Passive Listening Port and Packet Interception runs to gather sensitive information to access a network. Unlike active attacks and brute-force, attack using this method have more stealth-like quality.

HTTPD Attacks

Vulnerabilities found in HTTPD or that there are five types webserver: buffer overflows, bypasses httpd, cross scripting, web code vulnerabilities, and floods.HTTPD URL Buffer Overflow can occur because of errors on the attacker adds the port used for web traffic by entering the lot carackter and overflow string to find a suitable place. When a place for overflow discovered, an attacker will insert a string that would be command can be executed. Buffer-overflow can give the attacker access to the command prompt.

IPv4 vs IPv6


Differences in Internet Protocol Version 4 (IPv4) and Internet Protocol Version 6 (IPv6)
 
I. Internet Protocol Version 4 (IPv4)
IPv4 is a type of network used in the protocol
TCP / IP network using the IP protocol version 4. IP version has limitations
which is only able to address a host computer as much as 4 billion worldwide.
Examples of IPv4 address is 192.168.0.3
In IPv4 there are 3 types of classes, depending on the size of the host, ie class A (section
throughout the 24-bit host, the IP address can be assigned to host 16.7 million), class B (host part
16-bit host = 65534) and class C (section hosts all 8 bits = 254 hosts).
Network administrators to apply for the class type network based on scale
management. The concept of this class has the advantage of: the management of the information is not
require all 32 bits, but quite simply part of the network only, so
of the information stored in the router, be small. Once the network address is obtained,
then the organization can freely give the address section on each host
host.
Comparison of IPv4 and IPv6
Provision of internet addresses in the following format IP address (RFC 1166). This address
expressed with 32 bits (numbers 1 and 0) were divided into 4 groups (each group
consists of 8 bits or octets) and each group is separated by a dot. To
facilitate reading, writing addresses is done with decimal numbers, for example
100.3.1.100 which if expressed in a binary
01100100.00000011.00000001.01100100. 32 bits of this means the number of maximum number
addresses that can be written is 2 to the power 32, or 4,294,967,296 addresses. The address format
consists of 2 parts, netid and hostid. NetID own states while the network address
hostid declare a local address (host / router). 32 bits of this, should not all of the digits 0 or
1 (0.0.0.0 is used for networks that are not known and are used to 255.255.255.255
broadcast). In its application, the internet address is classified into classes (AE) ..
Reason for this classification include:
· Facilitate the management system and setting addresses.
· Utilize existing address number is optimum (no address
missed).
· Allows organizing a worldwide network with a network distinguishes
The category includes large, medium, or small.
· Distinguish between the address and the address for the network to host / router.
Described in the table below based on the availability of data from the APNIC IPv4
until the end of 1999 ago and total IP that has been allocated to each - each country in
Asia Pacific.


II.5 Internet Protocol Version 6 (IPv6)
IPv4 to IPv6 transition is a phenomenon which is inevitable by all
circles. Although still able to use IPv4, IPv6 has a different design versions and
has more uses than IPv4. Accompanied by the growth of the innovations
tech, then the nations of the world are required to compete or at least
gradually began to implement IPv6. According to the Internet Protocol,
not expected until 2011, IP address allocation which is still used today will
exhausted. Then came a new peangalamatan method known as IPv6. In
Indonesia, one of the Internet service provider, Indosat Mega Media (Indosat M2), since 2004 has been
IPv6 network is ready to rent out.
IPv6 is an IP addressing method which slowly began to replace IPv4.
IPv6 is used as due to the limited number of IP addresses owned by IPv4,
considering the increasing number of IP-based devices at this time. IPv6 or Internet Protocol
Internet Protocol version 6 is the latest which is a further development of the
protocol that is used today, IPv4 (Internet Protocol version 4). IPv6 addressing
uses 128-bit addresses far more than the 32-bit addressing
belongs to IPv4. With a capacity of very large IP address in IPv6, every device that
can connect to the Internet (desktop computers, laptops, personal digital assistants, or phone
GPRS/3G mobile) can have a fixed IP address. So, sooner or later every
No electronic devices that can be connected to the Internet via a unique IP address.
The IPv6 protocol has several new features that are an improvement over IPv4, including
:
• Have a new header format
The IPv6 header has a new format that is designed to keep header overhead
minimum, to eliminate the fields that are not required and some optional fields
Comparison of IPv4 and IPv6
are placed after the IPv6 header. IPv6 header alone is twice the size of a large
of the IPv4 header.
• Range address a very large
IPv6 has 128-bit or 16-byte for each source and destination IP addresses.
So logically IPv6 can accommodate about 3.4 x 1038 possible combinations
address.
• efficient and hierarchical addressing and routing infrastructure
Global address of IPv6 are used in the IPv6 portion of the Internet, is designed to
creating an efficient routing infrastructure, hierarchical, and easily understood by
developers.
• Configuration is stateless and statefull addressing
IPv6 support is statefull addressing configuration, such as address configuration
using a DHCP server, or a stateless without using the DHCP server. On
The second configuration, the host automatically configure themselves with IPv6 addresses
to link the so-called link-local address and address prefix derived from the
transmitted by the local router.
• Built-in security
Support for IPsec provides support for network security and offers
interoperability between different IPv6 implementations.
• Better support in terms of QoS
In the IPv6 header contained in the identification of traffic using the Flow Label field, so
QoS support can still be implemented even though the packet payload is encrypted through
IPsec.
• The new protocol for interaction nodes
Contained in IPv6 Neighbor Discovery Protocol which replaces Address Resolution
Protocol.
• EkstensibilitasIPv6 can be easily added by adding new features
extension headers after the IPv6 header. The size of IPv6 extension headers is only constrained by the
the size of the IPv6 packet itself.