<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[< Felix's Blog />]]></title><description><![CDATA[Programmer]]></description><link>https://writeups.hashnode.dev</link><generator>RSS for Node</generator><lastBuildDate>Sun, 30 Aug 2026 16:47:36 GMT</lastBuildDate><atom:link href="https://writeups.hashnode.dev/rss.xml" rel="self" type="application/rss+xml"/><language><![CDATA[en]]></language><ttl>60</ttl><item><title><![CDATA[How do VPN Blocks Work?]]></title><description><![CDATA[များသောအားဖြင့် website တွေနဲ့ streaming platform တွေက နည်းပညာအများကြီးကနေ vpn တစ်ခုကို ပိတ်ထားလို့ရတယ်။ အဲ့ထဲကတစ်ချို့ကတော့ ကျွန်တော်တို့ရဲ့ Internet ကိုပြောင်းလိုက်တာတို့ (သို့မဟုတ်ရင်) ကျွန်တော်တို့သုံးနေတဲ့ server ကိုပြောင်းလိုက်တာတို့ လုပ်ခြင်းန...]]></description><link>https://writeups.hashnode.dev/how-do-vpn-blocks-work</link><guid isPermaLink="true">https://writeups.hashnode.dev/how-do-vpn-blocks-work</guid><dc:creator><![CDATA[Felix]]></dc:creator><pubDate>Fri, 31 May 2024 12:12:54 GMT</pubDate><enclosure url="https://cdn.hashnode.com/res/hashnode/image/upload/v1717157470744/7e5e4198-fe6b-456f-8545-75cb6027d065.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>များသောအားဖြင့် website တွေနဲ့ streaming platform တွေက နည်းပညာအများကြီးကနေ vpn တစ်ခုကို ပိတ်ထားလို့ရတယ်။ အဲ့ထဲကတစ်ချို့ကတော့ ကျွန်တော်တို့ရဲ့ Internet ကိုပြောင်းလိုက်တာတို့ (သို့မဟုတ်ရင်) ကျွန်တော်တို့သုံးနေတဲ့ server ကိုပြောင်းလိုက်တာတို့ လုပ်ခြင်းနဲ့ ကျော်သွားလို့ရပေမဲ့ တစ်ချို့ website တွေကတော့ ပိုပြီး secure ဖြစ်တဲ့အတွက် ကျော်လိုက်ဖို့ ခက်ခဲသွားနိုင်ပါတယ်။</p>
<p>ဒီတော့ကျွန်တော်က how to bypass ဆိုတဲ့အကြောင်းမရေးခင် အားလုံးနားလည်သွားအောင် VPN block တွေဘယ်လိုအလုပ်လုပ်တယ်ဆိုတာကို ရှင်းပြပေးသွားပါမယ်။ အောက်ကနည်းလမ်းတွေကတော့ VPN block လုပ်ခြင်းထဲက နည်းလမ်းများဖြစ်ပါတယ်။ အကုန်တော့မဆိုလိုပါဘူး။ ကျွန်တော်သိသလောက် တော်တော်များများကို လိုတိုရှင်းရေးပေးလိုက်တာပါ။</p>
<h2 id="heading-blocked-ip-adddress">Blocked IP Adddress</h2>
<p>VPN Blocker ရဲ့ အသုံးအများဆုံး အမျိုးအစားကတော့ VPN services နဲ့သက်ဆိုင်တဲ့ IP address တွေနဲ့ဝင်ရောက်ခွင့်ကို ပိတ်ထားခြင်းဖြစ်ပါတယ်။ ရှင်းရှင်းပြောရရင် website or streaming platform တစ်ခုခုက IP address တစ်ခုထဲကိုပဲ သုံးပြီးဝင်ရောက်မယ်ဆိုရင် server ကဝင်ရောက်ခွင့်ကို ငြင်းပယ်လိုက်လို့ရပါတယ်။ ဒါပေမဲ့ တခြား VPN တစ်ခုခုကိုချိတ်လိုက်မယ်ဆိုရင်တော့ ဒီလိုဝင်ဖို့တားမြစ်ထားတဲ့ route တွေကိုလွယ်လွယ်ကူကူ ကျော်သွားလို့ရနိုင်ပါတယ်။ အရင်က facebook သုံးဖို့ပိတ်ထားတော့ ကျွန်တော်တို့ VPN တော်တော်များများခံပြီး သုံးလိုက်သလိုပေါ့။</p>
<h2 id="heading-blocked-vpn-ports">Blocked VPN Ports</h2>
<p>A VPN port is a virtual port enabling tunneled traffic to run through encrypted VPN servers. VPN Tool သုံးတဲ့သူတိုင်းကို website အားဝင်ရောက်ဖို့အတွက် Firewall ဆိုတဲ့ကောင်က တားမြစ်ထားလို့ရနိုင်တယ်။ ဒါပေမဲ့ - စိတ်ချရတဲ့ VPN service ပေးတဲ့ VPN တွေကတော့ OpenVPN၊ IKEv2\IPSec၊ Shadowsocks နှင့် Wireguard အပါအဝင် မတူညီတဲ့ protocol တွေကိုသုံးပြီး လိုအပ်ခဲ့ရင်တောင် တခြား port ကိုပြောင်းပေးနိုင်တာတွေ့ရပါတယ်။</p>
<h3 id="heading-deep-packet-inspection-dpi"><strong>Deep Packet Inspection (DPI)</strong></h3>
<p>DPI ဆိုတာ တော်တော်များများတော့ကြားဖူးမယ်မထင်ဘူး။ သူ့ကို networking သမားတွေနဲ့ နည်းပညာသမားအနည်းငယ်သာသိနိုင်မယ်ထင်တယ်။ Deep Packet Inspection (DPI) လုပ်ခြင်းက VPN route တွေကို ပိတ်ဖို့အတွက် အဆင့်မြင့်ဆုံးနည်းလမ်းတစ်ခုဖြစ်ပါတယ်။ DPI ကိုတော့ နိုင်ငံအတွင်းမှာရှိတဲ့ နိုင်ငံသားတိုင်းရဲ့ online လွတ်လပ်ခွင့်ကို ကန့်သတ်ထားတဲ့ censorship နိုင်ငံတွေမှာ တွင်ကျယ်စွာအသုံးပြုကြပါတယ်။ DPI ရဲ့လုပ်ဆောင်ချက်ကတော့ သုံးတဲ့သူရဲ့ အသွားအလာလမ်းကြောင်းတွေကို ဝှက်စာပေးတဲ့ Metadata တွေကိုအသုံးပြုပြီး VPN တွေကိုထောက်လှမ်းလို့ရပါတယ်။ A detailed analysis of all data components called packets allows for spotting and blocking VPNs. However, once again, multiple security protocols may help users pass by.</p>
<h3 id="heading-vpn">VPN ပိတ်ထားခြင်းကို ရှောင်ဖို့အတွက် အသုံးဝင်တဲ့ နည်းလမ်းတွေကိုကျွန်တော်ဆက်ပြောပေးပါမယ်။</h3>
<p>Website တွေနဲ့ streaming platform တော်တော်များများက VPN သုံးပြီးဝင်ရောက်ခြင်းကို ပိတ်ထားပေမဲ့ ကျွန်တော်တို့ online ပေါ်မှာ privacy ကိုမထိခိုက်စေပဲ ကျွန်တော်တို့ဝင်ရောက်ပြိး သုံးလို့ရနိုင်ပါတယ်။ အောက်မှာတော့ VPN block တွေကို bypass လုပ်ဖို့နည်းလမ်းတွေပဲဖြစ်ပါတယ်။ ကျွန်တော်သိသလောက်ပေါ့ အများကြီးတော့ရှိပါတယ်။ ကျွန်တော်လည်းအကုန်မသိနိုင်လို့ အကုန်တော့မရေးတော့ဘူး။</p>
<h3 id="heading-1-change-your-ip-address"><strong>1. Change your IP address</strong></h3>
<p>When it comes to VPN blocks, ကျွန်တော်တို့ကြိုးစားကြည့်သင့်တဲ့ အကောင်းဆုံး ပထမအချက်ကတော့ တခြား server ကိုပြောင်းသုံးခြင်းနဲ့ IP address ကိုပြောင်းလိုက်ခြင်းဖြစ်ပါတယ်။ အပေါ်မှာပြောသလိုပဲ တစ်ချို့ IP တွေက သူတို့ရဲ့ VPN နဲ့သက်ဆိုင်တဲ့ စာရင်းတွေမှာထည့်ထားတတ်တော့ ပိတ်ထားနိုင်လို့ ပြောင်းကြည့်ခြင်းဖြစ်ပါတယ်။ ဒါပေမဲ့ ယုံကြည်စိတ်ချရတဲ့ VPN တော်တော်များများမှာတော့ website တော်တော်များများကိုဝင်ရောက်နိုင်ပါတယ်။</p>
<p>Alternatively, you can make use of an obfuscated server. ဒီနည်းလမ်းကတော့ VPN tunnel ကနေတစ်ဆင့် လုပ်ဆောင်နေတဲ့ ကျွန်တော်တို့ data တွေကို ထပ်ပြီး encryption လုပ်ပေးလိုက်ခြင်းဖြစ်ပါတယ်။ Obfuscated servers တွေက ကျွန်တော်တို့ data တွေကို ရှာဖွေဖို့ဆိုတာခက်ခဲပါတယ်။</p>
<h3 id="heading-2-connect-through-a-dedicated-ip-address"><strong>2. Connect through a dedicated IP address</strong></h3>
<p>Dedicated IP Address တွေက ကျွန်တော်တို့အတွက် ပုံမှန် VPN ပိတ်ထားခြင်းကို ကျော်သွားဖို့ကညီပေးပါတယ်။ ဒီလို IP မျိုးတွေက ကျွန်တော်တို့သုံးတဲ့တစ်ယောက်ထဲသာပိုင်တဲ့အတွက် VPN Block လုပ်ထားတဲ့ site တွေကိုသုံးတဲ့သူရဲ့ နောက်ကွယ်ရှိ virtual private network ကို မှတ်မိနိုင်မည်မဟုတ်ပါ။ ဒါပဲလားဆိုတော့မဟုတ်သေးဘူး ကျွန်တော်တို့က ကျွန်တော်တို့ရဲ့ server ကိုခနခနပြောင်းနေဖို့မလိုအပ်တော့ဘူး ဒါကြောင့် ကျွန်တော်တို့က Internet service providers, censors, and other third parties တွေရဲ့ အာရုံစိုက်ခံရခြင်းရန်ကနေ လွတ်သွားမယ်ပေါ့။</p>
<h3 id="heading-3-change-vpn-port-or-security-protocol"><strong>3. Change VPN port or security protocol</strong></h3>
<p>ပုံမှန်အားဖြင့် VPN services တွေက secure connections တွေနဲ့ ကျွန်တော်တို့ရဲ့ data ကို encrypted tunnel အတွင်းကနေ ကာကွယ််ပေးတယ်။ ကျွန်တော် ဉပမာအနေနဲ့ VeePN ဆိုတာနဲ့ ယှဉ်ပြပေးထားပါတယ်။</p>
<ol>
<li><p>Open VPN : This protocol runs on TCP and UDP ports and creates a secure site-to-site connection. Open VPN က UDP port ကြောင့် အင်တာနက်ကိုတော့အရမ်းမြန်မသွားပေမဲ့ ကျွန်တော်တို့ data တွေလုံခြုံမှုရှိတာတော့ သေချာပါတယ်။</p>
</li>
<li><p>IKEv2 : nternet Key Exchange version 2 ကတော့ request and response တွေကိုပေးနိုင်ပါတယ်။ It provides secure communication between networks and is responsible for a security association (SA) attribute.</p>
</li>
<li><p>IPSec : This set of protocols guarantees securely encrypted connections between devices. Together with IKEv2, it protects sensitive information transmitted across the network.</p>
</li>
<li><p>Shadowsocks : Shadowsocks ဆိုတာကတော့ open-source encryption protocol တစ်ခုဖြစ်ပါတယ်။ SOCKS5 အပေါ်မှာအခြေခံထားပြီး censored or hidden လုပ်ထားတဲ့ အရာတွေကို ဖြတ်သန်းပြီးဝင်ရောက်ကြည့်ရှုနိုင်ပါတယ်။</p>
</li>
<li><p>WireGuard : WireGuard အစွမ်းထက်သော VPN Tool တစ်ခုနဲ့ ပေါင်းထားပါက WireGuard သည် သုံးစွဲသူများအား ဒေတာထိတွေ့မှုမှ ကာကွယ်ရန်၊ ဆိုက်ဘာတိုက်ခိုက်မှုများကို တိုက်ဖျက်ရန်နှင့် ချိတ်ဆက်မှုယုံကြည်စိတ်ချရမှုကို မြှင့်တင်ပေးသည့် မြင့်မားသောလုံခြုံသောဖြေရှင်းချက်တစ်ခုဖြစ်သည်။</p>
</li>
</ol>
<p>ဒီထဲက protocol တွေကတော့ တခြား website တွေထက်ပိုပြီးစိတ်ချရပြီး VPN ပိတ်ထားတဲ့အပေါ်မူတည်ပြီး ဝင်ရောက်နိုင်ဖို့ကျွန်တော်တို့တော်တော်များများ အကူအညီရပါတယ်။</p>
<h3 id="heading-4-change-dns-server-configuration-manually"><strong>4. Change DNS server configuration manually</strong></h3>
<p>ဒီနည်းလမ်းကတော့ တော်တော်အသုံးဝင်ပါတယ်။ ကျွန်တော်ကိုယ်တိုင်လည်း ဒီလို try ပြီးသုံးကြည့်ဖြစ်ပါတယ်။ ကျွန်တော်တို့ ကိုယ်ပိုင် DNS ကို configuration လုပ်မယ်ဆိုရင်တော့ ISPs (Internet Service Provider) တွေဘက်ကပိတ်ထားတာတွေကို ကျော်လိုက်ဖို့ အများကြီးအထောက်အကူဖြစ်ပါတယ်။ ဒါပေမဲ့ ဒီနည်းလမ်းကတော့ နည်းပညာနားလည်တဲ့သူများသာစမ်းသင့်ပါတယ်။ End User တွေအတွက်တော့ တော်တော်သတိထားပြီးစမ်းကြဖို့ အကြံပြုချင်ပါတယ်။ ဘာကြောင့်လဲဆိုတော့ ကျွန်တော်တို့ online ပေါ်ကတဆင့် data ပေါက်ကြားနိုင်ခြေများပီး အလွန် အန္တရာယ်များတာကြောင့်ဖြစ်ပါတယ်။</p>
<p>မလိုအပ်ပဲနဲ့တော့ သူ့ကို ရွေးပြီးသုံးဖို့အကြံမပြုချင်ပါဘူး။ VPN သုံးရင်လည်း သေချာဖတ်ပြီးမှသုံးကြပါ တစ်ချို့ VPN တွေက VPN မဟုတ်ပါဘူး။ DNS changer တွေဖြစ်ပါတယ်။ ပိတ်ထားတဲ့ site ကိုလည်းသုံးချင်တယ် (ဉပမာ - facebook ပေါ့) တခြားနည်းလမ်းတွေကလည်း အလုပ်မဖြစ်တော့ဘူးဆိုရင်တော့ VPN တော်တော်များများမှာ manual DNS Config လုပ်ဖို့ခွင့်ပြုထားကြပါတယ်။ DNS change ချင်တယ်ဆိုရင်တော့ -</p>
<ol>
<li><p>Open <em>System Preferences</em></p>
</li>
<li><p>Find the connection you’re using in the <em>Network</em> section</p>
</li>
<li><p>From the list of tabs, choose <em>DNS</em></p>
</li>
<li><p>In the <em>DNS servers</em> section, click on “<em>+</em>” and add two Google DNS servers: <strong>8.8.8.8</strong> and <strong>8.8.4.4.</strong> Alternatively, you can use Level3 DNS: <strong>4.2.2.1</strong> and <strong>4.2.2.2</strong></p>
</li>
<li><p>Apply the changes, restart your computer, and reconnect to VPN.</p>
</li>
</ol>
<p>ခနခန block ခံနေရရင်တော့ secure ဖြစ်တဲ့ VeePN ကိုစမ်းသုံးကြည့်ကြပါ။ ဝယ်သုံးရင်တော့ ပိုကောင်းပါတယ်။ free သုံးတဲ့သူတွေကတော့ ခနခနပြောင်းသုံးဖို့လိုအပ်ပါတယ်။</p>
<p><code>စာကြွင်း - ကျွန်တော်ကတော့ VPN မလိုလို့မသုံးပါဘူး :3</code></p>
<p><em>Thank for reading.......</em></p>
]]></content:encoded></item><item><title><![CDATA[Installing ARM Android apps on Genymotion devices]]></title><description><![CDATA[ဒီအခန်းမှာတော့ Genymotion ပေါ်မှာ apk တွေတင်လို့မရပဲOnly Genymotion is x86-based, so if you try to install an app including ARM code on any Genymotion device, you will get this error that you wouldn’t have on a physical device:
ဆိုပြီး တောင်းနေတဲ့ပြသ...]]></description><link>https://writeups.hashnode.dev/installing-arm-android-apps-on-genymotion-devices</link><guid isPermaLink="true">https://writeups.hashnode.dev/installing-arm-android-apps-on-genymotion-devices</guid><dc:creator><![CDATA[Felix]]></dc:creator><pubDate>Tue, 21 May 2024 14:08:33 GMT</pubDate><enclosure url="https://cdn.hashnode.com/res/hashnode/image/upload/v1716300375138/538deb86-e631-4b83-8594-99ec55f32fb4.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>ဒီအခန်းမှာတော့ Genymotion ပေါ်မှာ apk တွေတင်လို့မရပဲ<br />Only Genymotion is x86-based, so if you <strong>try to install an app including ARM code on any Genymotion device</strong>, you will get this <strong>error</strong> that you wouldn’t have on a physical device:</p>
<p>ဆိုပြီး တောင်းနေတဲ့ပြသနာကို ဖြေရှင်းဖို့တင်ပေးလိုက်ပါတယ်။ ကျွန်တော်တို့ ဒီလိုဖြစ်လာရင် ဘာလုပ်ရမလဲဆိုရင်တော့ file တစ်ခု download ဆွဲဖို့လိုပါတယ်။ ကျွန်တော် Genymotion ကဘာလဲ ဘာကြောင့်သုံးရတယ်ဆိုတာကို အရင်က write up တွေမှာရေးခဲ့ဖူးပါတယ်။ ဒီမှာတော့ သူ့အကြောင်းကို ရှင်းပြမှာမဟုတ်တော့ပါဘူး။</p>
<p>Genymotion is generally recommended over using the Android SDK emulator provided with Android Studio, because it is more performance.</p>
<p>ဒီ error ကတော့ app တွေမှာ ARM native code တွေကြောင့် ဖြစ်တာများပါတယ်။ Genymotion က ARM based တွေကို run မပေးနိုင်ပါဘူးအဲ့တာကြောင့် install တင်တဲ့အချိန်မှာ error ဖြစ်တာပါ။</p>
<p><code>An error occurred while deploying the file.   This probably means that the app contains ARM native code and your Genymotion device cannot run ARM instructions. You should either build your native code to x86 or install an ARM translation tool in your device.</code></p>
<p><img src="https://cdn.hashnode.com/res/hashnode/image/upload/v1716300160858/2da1ab52-41ba-430a-813b-eb6f0f90cfda.png" alt class="image--center mx-auto" /></p>
<p><img src="https://cdn.hashnode.com/res/hashnode/image/upload/v1716299790536/82c41a7c-4e05-4625-b335-fd2f0402f48b.png" alt class="image--center mx-auto" /></p>
<p>ဒီလိုပြသနာတစ်ခုတက်လာပြီဆိုရင် အောက်က ကျွန်တော်ပေးထားတဲ့ link ထဲ file တစ်ခု down ဖို့လိုပါတယ်။ ပြီးရင်တော့ ဒီတိုင်းကူးထည့်လိုက်ရုံပါပဲ။</p>
<pre><code class="lang-plaintext">https://mega.nz/folder/JhcFwKpC#yfhfeUzvIZoSdBgfdZ9Ygg
</code></pre>
<ol>
<li><p>Download the right ARM translation archive for your device’s Android version. For Android 8, I used ARM_Translation_Oreo.zip.</p>
</li>
<li><p>Drag and drop the .zip file to the device’s unlocked screen and click on OK when asked for confirmation</p>
</li>
</ol>
<p>Zip file ကို ကူးထည့်လိုက်ရင်ခနလောက်စောင့်ပြီးတာနဲ့ reboot ကျသွားပါလိမ့်မယ်။ အဲ့တာဆို ရပါပြီ။ ဒါဆိုရင်တော့ ကျွန်တော်တို့ genymotion ပေါ်မှာ ARM code ပါတဲ့ app တွေကို တင်ပြီးသုံးလို့ရ/ testing လုပ်လို့ရပါပြီ။ genymotion နဲ့ burpsuite နဲ့ root certifiate ထည့်နည်းကိုလည်း ကျွန်တော်တစ်ခါရေးပေးဖူးပါတယ်။ ကျွန်တော်စမ်းပြပေးထားတာ android version 8 မှာပါ။ version 10 နဲ့အထက်ကို သုံးချင်ရင်လည်း download file ထဲမှာထည့်ပေးထားပါတယ်။ ကိုယ့်စက်နဲ့ ကိုက်ညီတာကို down ပြီးသုံးလို့ရပါတယ်။</p>
<p><img src="https://cdn.hashnode.com/res/hashnode/image/upload/v1716300178996/def06b8d-29e0-4b1f-884b-d325ae01d4ba.png" alt class="image--center mx-auto" /></p>
<p>see you next time... Happy Hacking!</p>
]]></content:encoded></item><item><title><![CDATA[Installing Low Orbit Ion Cannon (LOIC) in Kali Linux (Debian)]]></title><description><![CDATA[LOIC is a popular opensource DDoS and enterprise stress generation tool renowned for its use in compromising Microsoft, Apple over the decades.
LOIC has been tagged as a critical alert DoS in CVE and other security exploit standardization establishme...]]></description><link>https://writeups.hashnode.dev/installing-low-orbit-ion-cannon-loic-in-kali-linux-debian</link><guid isPermaLink="true">https://writeups.hashnode.dev/installing-low-orbit-ion-cannon-loic-in-kali-linux-debian</guid><dc:creator><![CDATA[Felix]]></dc:creator><pubDate>Tue, 21 May 2024 11:53:09 GMT</pubDate><content:encoded><![CDATA[<p>LOIC is a popular opensource DDoS and enterprise stress generation tool renowned for its use in compromising Microsoft, Apple over the decades.</p>
<p>LOIC has been tagged as a critical alert DoS in CVE and other security exploit standardization establishments.</p>
<h1 id="heading-the-installation"><strong>The Installation:</strong></h1>
<p>If you’re running the latest version of Kali or any Debian distro, LOIC requires the <code>monodevelop</code> module to build the application from its bash script.</p>
<hr />
<pre><code class="lang-plaintext">sudo apt install nomodevelop
</code></pre>
<p>If you encounter an error while downloading the module, go to: <a target="_blank" href="https://www.monodevelop.com/download/#fndtn-download-lin-debian">https://www.monodevelop.com/download/</a></p>
<p>Now, copy the commands from the latest debian, in the time of posting, Kali-Linux purple is currently in Debian 6.1, but you can use the Debian 10 script. It will work fine.</p>
<p><em>Now proceed with the</em> <strong><em>apt install monodevelop</em></strong> <em>command</em></p>
<p>Lets install LOIC:</p>
<ul>
<li><p>Create a folder called LOIC.</p>
</li>
<li><p>Now direct to this site: <a target="_blank" href="https://github.com/nicolargo/loicinstaller">https://github.com/nicolargo/loicinstaller</a></p>
</li>
<li><p>Download the repo into the LOIC folder created earlier using git clone.</p>
</li>
</ul>
<pre><code class="lang-plaintext">git clone https://github.com/nicolargo/loicinstaller.git
</code></pre>
<ul>
<li><p>Now within the folder, run the following commands</p>
</li>
<li><pre><code class="lang-plaintext">  chmod 777 loic.sh
  ./loic.sh install
  ./loic.sh update
  cd LOIC
  ./loic.sh run
</code></pre>
</li>
</ul>
]]></content:encoded></item><item><title><![CDATA[Beginner’s Guide to CTFs]]></title><description><![CDATA[How to start with Capture The Flag (CTF) Competitions
CTFs ဒါမှမဟုတ် Capture The Flag ပြိုင်ပွဲတွေက ကျွန်တော်တို့အတွက် Hacking ကိုစတင်လေ့လာဖို့ထဲက အကောင်းဆုံးနည်းလမ်းတစ်ခုလည်းဖြစ်ပါတယ်။ Ctf ရဲ့ အဓိပ္ပာယ်ကတော့ ကျွန်တော်တို့ System တစ်ခုထဲကို ဝင်ရောက်ခ...]]></description><link>https://writeups.hashnode.dev/beginners-guide-to-ctfs</link><guid isPermaLink="true">https://writeups.hashnode.dev/beginners-guide-to-ctfs</guid><category><![CDATA[IT]]></category><category><![CDATA[cyber security]]></category><dc:creator><![CDATA[Felix]]></dc:creator><pubDate>Mon, 13 May 2024 08:52:21 GMT</pubDate><enclosure url="https://cdn.hashnode.com/res/hashnode/image/upload/v1715590202307/55e004b2-a193-4d4b-a0ea-db1171a9d04c.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><strong>How to start with Capture The Flag (CTF) Competitions</strong></p>
<p>CTFs ဒါမှမဟုတ် Capture The Flag ပြိုင်ပွဲတွေက ကျွန်တော်တို့အတွက် Hacking ကိုစတင်လေ့လာဖို့ထဲက အကောင်းဆုံးနည်းလမ်းတစ်ခုလည်းဖြစ်ပါတယ်။ Ctf ရဲ့ အဓိပ္ပာယ်ကတော့ ကျွန်တော်တို့ System တစ်ခုထဲကို ဝင်ရောက်ခဲ့ကြောင်း (or) ဝင်ရောက်နိုင်ကြောင်းသက်သေပြတဲ့နည်းတစ်ခုပဲဖြစ်ပါတယ်။</p>
<h2 id="heading-why-do-ctfs">Why do CTFs?</h2>
<p>Ctfs ကတော့ကျွန်တော်တို့အတွက် binary exploitation၊ web exploitation သို့မဟုတ် reverse engineering လိုမျိုးစတဲ့ specific security တွေကိုလေ့လာဖို့အကောင်းဆုံးဖြစ်ပါတယ်။</p>
<p>Ctfs ကိုတော့ခုနောက်ပိုင်းမှာ ကျောင်းသားတွေဝင်ရောက် လေ့လာနိုင်တဲ့ ctf ပြိုင်ပွဲတွေအပြင် Open Level Ctf ပြိုင်ပွဲတွေလည်းအများကြီးပေါ်ပေါက်လာတာ လူတိုင်းသတိထားမိကြမှာပါ။ Ctf ကဘာတွေလုပ်ပေးနိုင်လည်းဆိုရင် ကျွန်တော်တို့ အသင်းအဖွဲ့နဲ့ စုပေါင်းလုပ်နိုင်တဲ့ စွမ်းရည်မျိုးအပြင် တွေးခေါ်နိုင်မှုစွမ်းရည်တွေပါပေးပါတယ်။</p>
<p>Finally, CTFs train your hacker persistence. Ctf မှာအတွေ့အကြုံရလာတာနဲ့ မိတ်ဆွေတို့ကို Real World ရဲ့အခက်အခဲပြသနာတွေကို စိတ်ရှည်နိုင်ပြီး အကောင်းမြင်တတ်အောင်လေ့ကျင့်ပေးသွားတာဖြစ်လို့ Ctf ဆိုတာကို လူငယ်တိုင် လုပ်သင့်ပါတယ်။ ဘယ်ကစရမှန်းမသိတဲ့သူများကျွန်တော့်ကိုဆက်သွယ်ပြီးမေးမြန်းလို့ရပါတယ်။ မြန်မာလို့အရေးအသားမို့လိုအပ်တာများရှိခဲ့ရင် နည်းလည်ပေးဖို့ တောင်းပန်ချင်ပါတယ်။</p>
<h2 id="heading-types-of-ctf">Types of CTF.</h2>
<p>ဒီမှာတော့ Ctf ရဲ့အဓိကအမျိုးအစားနှစ်မျိုးရှိပါတယ်။ ဒါကတော့လူတိုင်း ဆရာတိုင်းလည်း ပြောနေကျဖြစ်ပြီး လူတော်တော်များများလည်း ဒါမျိုးကို post တင်ပြီး sharing လုပ်တတ်ကြပါတယ်။</p>
<ol>
<li><p>Jeopardy-style</p>
</li>
<li><p>Attack-Defense-style</p>
</li>
</ol>
<p>Jeopardy-style Ctf ကတော့ သတ်မှတ်ထားတဲ့အမှတ်အရေအတွက်နဲ့ flag တွေကိုရှာဖွေရမှာဖြစ်လို့ Hacking Challenge မှာမရှိမဖြစ်လိုအပ်တဲ့ type ပဲဖြစ်ပါတယ်။ ဒီ Jeopardy style မှာတော့ အားနည်းချက်တစ်ခုကိုအသုံးချခြင်း (သို့) Flag ခိုးယူခြင်း နဲ့ Programming စိန်ခေါ်မှုတွေကိုရင်ဆိုင်ရမှာဖြစ်ပါတယ်။ Flag အများဆုံးရရှိအောင်နဲ့ ကန့်သတ်ထားတဲ့ အချိန်အတွင်း အမှတ်အများဆုံးရရှိအောင်လို့ group လိုက်တစ်ဖွဲ့စီက ယှဉ်ပြိုင်ရမှာဖြစ်ပါတယ်။</p>
<p>Jeopardy-style Ctf မှာတော့ တစ်ခါတစ်လေမှာတော့ခက်ခဲတဲ့အပိုင်းတွေပါပေမဲ့ ခုမှစတင်လေ့လာမဲ့သူများအတွက်လည်း ပါဝင်ဝင်ရောက်လေ့လာနိုင်လောက်တဲ့ အနေအထားရှိပါတယ်။ Ctf မှာတော့ကျွန်တော်တို့ ရွေးချယ်နိုင်တဲ့ မေဂျာတွေရှိပါတယ်။</p>
<p>cryptography, reversing, binary, web, programming, forensics, networking challenges ဆိုပြီး type တွေအများကြီးနဲ့မေးတာမို့ ကိုယ်ကျွမ်းကျင်တဲ့ အပိုင်းတစ်ခုစီလေ့လာပြီး တစ်ဆင့်စီတက်သွားတာကောင်းပါတယ်။</p>
<p>နေက်တစ်ခု Attack-Defense-style Ctfs ဆိုတာကတော့ Advance version of ctf လို့သတ်မှတ်လို့ရပါတယ်။</p>
<p>ဒီပြိုင်ပွဲမျိုးကတော့ ကျွန်တော်သိသလောက် ပြိုင်ပွဲဝင်အချင်းချင်း ကိုယ်ပိုင် server များကိုကာကွယ်ကြပြီး ပြိုင်ဘက်အသင်က ကိုယ့်အသင့်ရဲ့ server ကိုတိုက်ခိုက်ကြတဲ့နည်းပဲဖြစ်ပါတယ်။ ဒီပြိုင်ပွဲကို ယှဉ်ပြိုင်ဖို့ကတော့ ကျွမ်းကျင်မှုတွေအများကြီးလိုအပ်တာဖြစ်ပြီး ကိုယ့်အသင်းကလည်း အားလုံးနီးပါကိုသိထားပြီး အမြဲ active ဖြစ်နေဖို့လိုပါလိမ့်မယ်။</p>
<p>ဥပမာ — နှစ်စဉ်ကျင်းပနေတဲ့ DEFCON CTF Finals ပြိုင်ပွဲက Attack-Defense-style Ctf ဖြစ်ပါတယ်။</p>
<h2 id="heading-ctf-skills">CTF skills</h2>
<p>CTF လောကထဲဝင်ရောက်နိုင်ဖို့အတွက် ကျွန်တော်တို့ လုပ်ဆောင်ရမဲ့ အရမ်းအရေးပါတဲ့အချက်နှစ်ချက်ရှိပါတယ်။ အဲ့တာကတော့ team ဖွဲ့ဖို့ သူငယ်ချင်းကောင်းကောင်းရှာဖို့နဲ့ အမြဲလေ့လာနေဖို့ပါပဲ။</p>
<p>ဒီလောက်ပဲအချိန်ရတာမို့ အားခဲ့ရင်ဆက်ပြီးရေးပေးပါ့မယ်။</p>
<p><em>to be continue……</em></p>
]]></content:encoded></item><item><title><![CDATA[Dark Web Introduction 101]]></title><description><![CDATA[Today Advice

"Privacy is a human right"
"Being qualified is not about the certificates you hold, but rather the knowledge, skills, and experience you possess. Certifications may validate your expertise, but true qualification is demonstrated through...]]></description><link>https://writeups.hashnode.dev/dark-web-introduction-101</link><guid isPermaLink="true">https://writeups.hashnode.dev/dark-web-introduction-101</guid><dc:creator><![CDATA[Felix]]></dc:creator><pubDate>Sun, 28 Apr 2024 04:01:11 GMT</pubDate><enclosure url="https://cdn.hashnode.com/res/hashnode/image/upload/v1714273972953/e31b8b79-ed3b-4ed1-a026-72ff340c552a.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<h2 id="heading-today-advice">Today Advice</h2>
<blockquote>
<p>"Privacy is a human right"</p>
<p>"<em>Being qualified is not about the certificates you hold, but rather the knowledge, skills, and experience you possess. Certifications may validate your expertise, but true qualification is demonstrated through your ability to apply that knowledge effectively in real-world situations."</em></p>
<p>"အရည်အချင်းပြည့်မီခြင်းဆိုသည်မှာ သင်ကိုင်ဆောင်ထားသော လက်မှတ်များအကြောင်းမဟုတ်ဘဲ သင်ပိုင်ဆိုင်သည့် အသိပညာ၊ ကျွမ်းကျင်မှုနှင့် အတွေ့အကြုံတို့သာ ဖြစ်သည်။ အသိအမှတ်ပြုလက်မှတ်များသည် သင်၏ကျွမ်းကျင်မှုကို သက်သေပြနိုင်သော်လည်း စစ်မှန်သောအရည်အချင်းသည် ထိုအသိပညာကို လက်တွေ့ကမ္ဘာအခြေအနေများတွင် ထိထိရောက်ရောက်အသုံးချနိုင်မှုမှတစ်ဆင့် သင့်အရည်အချင်းစစ်ကို သက်သေပြပါသည်။"</p>
</blockquote>
<h3 id="heading-index">INDEX</h3>
<ul>
<li><p>Surface Web vs Deep Web vs Dark Web</p>
</li>
<li><p>TOR Project History</p>
</li>
<li><p>How TOR is actually work</p>
</li>
<li><p>Key Point of TOR</p>
</li>
<li><p>TOR BRIDGE</p>
</li>
<li><p>PGP</p>
</li>
<li><p>TAILS OS</p>
</li>
<li><p>Proxychains</p>
</li>
<li><p>Bitcoin History and Usage</p>
</li>
<li><p>The End</p>
</li>
<li><p>Reference and Resource</p>
</li>
</ul>
<h3 id="heading-1-surface-web-vs-deep-web-vs-dark-web">1 - Surface Web vs Deep Web vs Dark Web</h3>
<p>Dark Web အကြောင်းကို ရှာရင် တော်တော်များများက ရေခဲတောင်ပုံစံမျိုးနဲ့ ခိုင်းနှိုင်းပြထားတာမျိုးတော်တော်များများ တွေ့ရပါတယ်။ အောက်ကပုံကို ရေခဲတောင်တစ်ခုလိုမျိုးတွေးကြည့်ပြီး အခြေရှင်းပြပေးသွားပါမယ်။</p>
<p><img src="https://cdn.hashnode.com/res/hashnode/image/upload/v1714274397483/bf30bf21-0896-4dd9-b0d8-13b1410c4272.png" alt class="image--center mx-auto" /></p>
<p><strong>Surface Web:</strong> Surface web ဆိုတာကတော့ ကျွန်တောတို့ပုံမှန် search engine တွေကနေ ဝင်ရောက်ရှာဖွေနိုင်သော အပိုင်းများဖြစ်ပါတယ်။ ဉပမာ - Facebook, Google, Bing, Website စသည်တို့ဖြစ်ပါတယ်။ သူ့မှာတော့ ပုံမှန် web browser များမှာအလုပ်လုပ်ပြီး end user တွေရှာဖွေနိုင်အောင် ပြုလုပ်ထားခြင်းဖြစ်ပါတယ်။ ၎င်းတွင် အများသူငှာ ဝဘ်ဆိုက်များ၊ သတင်းဝဘ်ဆိုဒ်များ၊ ဆိုရှယ်မီဒီယာပလပ်ဖောင်းများ၊ အွန်လိုင်းစျေးဝယ်ဆိုဒ်များနှင့် အခြားအများသိကြသည့် ဝဘ်အရင်းအမြစ်များ ပါဝင်သည်။</p>
<p><strong>Deep Web:</strong> Invisible web သို့မဟုတ် Hidden Web လို့လဲလူသိများတဲ့ deep web ကိုတော့ တစ်ချို့က ပုံမှန် ရှာလို့ရအောင်လုပ်ထားပေမဲ့ သူ့ရဲ့ ထူးခြားချက်ကတော့ web တိုင်းလိုလိုမှာ index page မရှိတာပါပဲ။ သူ့ကို ဝင်ရောက်ဖို့ဆိုရင် အသုံးပြုသူရဲ့ အထောက်အထားများ (သို့) software တစ်ခုခုလိုအပ်ပါတယ်။ Deep Web include private databases, subscription-based websites, academic research papers, medical records, and other restricted information that is not intended for public consumption.</p>
<p><strong>Dark Web:</strong> Dark Web မှာတော့ Deep Web အတွင်းမှာပဲရှိနေပြီး သူ့မှာတော့ Deep Web ထဲမှာပဲ ရည်ရွယ်ချက်ရှိရှိ Hide ထားသော အပိုင်းတစ်ခုဖြစ်ပါတယ်။ Anonymity and Encryption ကို provide လုပ်ပေးသော TOR Browser လိုမျိုး အထူးပြုလုပ်ပေးထားတဲ့ software မျိုးကိုသုံးပြီး Dark Web ကို access လုပ်လို့ရနိုင်ပါတယ်။ Dark web မှာဘာတွေများထူးခြားလဲ သူ့အထဲမှာဘာတွေရှိတာလဲ ဆိုရင်တော့ တရားမဝင်ဈေးကွက်တွေ၊ တရားတဝင် hacker တွေ၊ စာရွက်စာတမ်းအတုတွေ၊ မူးယစ်ဆေးဝါးရောင်းဝယ်ဖောက်ကားမှုများအပြင် တခြားတရားမဝင်တဲ့ အလုပ်မှန်သမျှ dark web မှာအကုန်ရှိပါတယ်။ Dark Web ရဲ့လုပ်ဆောင်ချက်က တရားမဝင်သော်လည်း အမည်ဝှက်နှင့် စည်းကြပ်မှုမရှိသော သဘောတရားများကြောင့် အမည်ဝှက်ပြီး ရာဇဝတ်မှုဖြစ်နိုင်ခြေများကို ကူညီဆောင်ရွက်ပေးခြင်းများကြောင့် နာမည်ကောင်းရရှိထားခြင်းဖြစ်ပါတယ်။</p>
<p>ကျွန်တော်တို့ တော်တော်များများဝင်ရောက်ပြီး Dark Web လို့ပြောနေကြတာက ရောင်းဝယ်ဖောက်ကားမှုနှင့် Leak ဆိုင်ရာတွေကို Deep Web မှာပဲလုပ်ဆောင်ကြပါတယ်။ Dark Web ကိုရောက်တာမျိုးမရှိပါဘူး။ Dark Web လို့လူတိုင်းက ပြောနေကြလို့ ဒီအကြောင်းလေးကိုရေးတင်လိုက်တာဖြစ်ပါတယ်။</p>
<blockquote>
<p><em>From my point of view, I do not believe in dividing the types of Web by how many percent, because no one knows how many real sites are in each type.</em></p>
</blockquote>
<h3 id="heading-2-tor-project-history">2 - TOR Project History</h3>
<p>TOR လို့လူသိများတဲ့ The Onion Routing ကတော့ Internet ပေါ်မှာ အမည်ဝှက်ထားဖို့အတွက် Design ထုတ်ထားတဲ့ ထူးခြားလွန်းတဲ့ open-source tool တစ်ခုဖြစ်ပါတယ်။ သူ့ရဲ့အဓိကရည်ရွယ်ချက်ကတော့ Privacy ကိုကာကွယ်ဖို့နဲ့၊ တစ်ဦးချင်းစီရဲ့ data တွေကိုကာကွယ်ဖို့အတွက် onion လမ်းကြောင့်ကိုအသုံးပြုထားပြီး သူ့ကိုအသုံးပြုမယ်ဆိုရင် အထောက်အထားများကို ကာကွယ်နိုင်မယ်ဆိုတာ သေချာစေရန်ဖြစ်ပါတယ်။ Onion ကိုသေချာလေ့လာကြည့်မယ်ဆိုရင်တော့ -</p>
<p><strong>Timeline of the Tor Project:</strong></p>
<p><strong>Mid-1990s:</strong> The idea of “onion routing” begins at the U.S. Naval Research Lab (NRL) by David Goldschlag, Mike Reed, and Paul Syverson. The goal is to create internet connections that provide privacy and prevent tracking and surveillance.</p>
<p><strong>Early 2000s</strong>: Roger Dingledine, a recent MIT graduate, joins the NRL onion routing project with Paul Syverson. The project is named Tor, which stands for The Onion Routing. Nick Mathewson also joins the project.</p>
<p><strong>October 2002:</strong> The Tor network is deployed, with its code released under a free and open software license. It initially has around a dozen volunteer nodes.</p>
<p><strong>2004:</strong> The Electronic Frontier Foundation (EFF) starts funding the work on Tor by Roger Dingledine and Nick Mathewson.</p>
<p><strong>2006:</strong> The Tor Project, Inc., a nonprofit organization, is founded to maintain Tor’s development. It becomes a 501(c)(3) nonprofit.</p>
<p><strong>2007:</strong> Development of bridges to the Tor network begins to address censorship and help users bypass government firewalls.</p>
<p><strong>2008:</strong> Development of Tor Browser begins, making Tor more accessible to everyday internet users.</p>
<p><strong>Late 2010</strong>: Tor gains prominence during the Arab Spring, providing privacy and access to blocked resources for activists.</p>
<p><strong>2013:</strong> The Snowden revelations increase awareness of surveillance and the importance of privacy tools. Tor is crucial to Snowden’s whistleblowing efforts and is proven to be secure from cracking at that time.</p>
<p><strong>Present:</strong> The Tor network has thousands of relays operated by volunteers and millions of users worldwide. It remains a vital tool for privacy and freedom online.</p>
<p>The Tor Project continues to fight for private access to an uncensored internet and is committed to transparency and user safety. It is supported by a global community dedicated to human rights.</p>
<p><strong>— TOR</strong> as it is available for various operating systems, including Windows, macOS, Linux, Android, and iOS.</p>
<h3 id="heading-3-how-tor-is-actually-work">3 - How TOR is Actually Work?</h3>
<p><strong>The Onion routing</strong> is a proxy used to anonymize your communication on the internet used with TOR browser bundle, Routing the internet traffic through a series of encrypted connection called tor node and all Path called tor circuit.</p>
<p><strong>TOR Node</strong>: is an volunteer operated server that helps to facilitate anonymous and private internet communication by relaying encrypted data packets between users, thereby obscuring the origin and destination of the traffic.</p>
<ul>
<li><p><strong><em>Entry Node:</em></strong> The first node in the circuit also known as (Guard node) that receives the user’s encrypted data packets and strips off one layer of encryption to reveal the address of the middle node, It not secure cause ISP (Internet Service Provider) knowing that you are trying to connect to the TOR network .</p>
</li>
<li><p><strong><em>Middle Node:</em></strong> The second node in the circuit that receives the data packets from the entry node, decrypts another layer of encryption, and forwards the packets to the exit node, It secure and not monitor</p>
</li>
<li><p><strong><em>Exit Node:</em></strong> The final node in the circuit that receives the data packets from the middle node, decrypts the last layer of encryption, and sends the packets to their intended destination on the internet, And send the response recevied back</p>
</li>
</ul>
<h3 id="heading-workflow">WORKFLOW…</h3>
<p>It called onion routing cause the process look like an onion layers.</p>
<p><img src="https://cdn.hashnode.com/res/hashnode/image/upload/v1714276412018/c9ba2578-477b-4325-9f6e-e0506ccb13e3.webp" alt class="image--center mx-auto" /></p>
<ol>
<li><p>First: Your PC connects to the initial node in the Tor circuit. The initial node decrypts the message, revealing the IP address of the next node, and forwards the message to the middle node.</p>
</li>
<li><p>Second: The middle node decrypts the message to uncover the IP address of the exit node, and then forwards the message to the exit node.</p>
</li>
<li><p>Third: The exit node decrypts the message, revealing the destination IP address, and forwards it to the intended site, here is the last step in layers decapsulation</p>
</li>
<li><p>Finally: The response is sent back using an encapsulation process.</p>
</li>
</ol>
<p>The encryption used is normally AES with the key being shared via Diffie-Hellman key exchange</p>
<h1 id="heading-4-key-point-of-tor"><strong>4-KEY POINT OF TOR</strong></h1>
<ul>
<li><p>There is always a minimum of 3 connections nodes in TOR circut</p>
</li>
<li><p>Each Tor node in the circuit only knows the IP address of the node before it and the node after it. This design is intentional to enhance user privacy and anonymity. It ensures that no single node along the route has complete knowledge of both the source and the destination of the data being transmitted. By limiting the information each node possesses to just the adjacent nodes, Tor helps to obscure the full path and protect the identities of the users.</p>
</li>
<li><p>The first connection know your real IP address</p>
</li>
<li><p>The last connection know what in side the message and destination site</p>
</li>
<li><p>Increasing the length of the Circuit does not create more security &amp; anonymity</p>
</li>
<li><p>TOR Browser has worth security features that improve the browsing security</p>
</li>
<li><p>TOR called onion routing to because it add layer of encryption at each stage or node</p>
</li>
<li><p>Nodes in the Tor network are indeed chosen in a random manner to enhance security and prevent correlation attacks to increase the difficulty of tracking and identifying users. Randomization adds an extra layer of protection by diversifying the paths and nodes used for relaying traffic</p>
</li>
<li><p>Exit Node Restricted to serve as the final node in the circuit, unable to function as an entry or middle node.</p>
</li>
<li><p>Onion URLs are generated randomly and are required to end with the “.onion” extension. There are two versions of Onion URLs:<br />  <strong>v2:</strong> These URLs consist of 16 characters and are based on an 80-bit hash algorithm.<br />  <strong>v3:</strong> These URLs consist of 56 characters and are based on a stronger 256-bit hash algorithm.</p>
</li>
<li><p>Onion sites in the Tor network typically use HTTP instead of HTTPS. This is because the Tor network itself provides encryption and anonymity for the data transmitted between the user and the onion site.</p>
</li>
</ul>
<h1 id="heading-5-tor-bridge"><strong>5-TOR BRIDGE</strong></h1>
<p>A Tor bridge Is a feature in TOR browser, also known as an “obfuscated bridge,” is a special type of Tor relay that helps users bypass internet censorship and access the Tor network in restrictive environments. It serves as an entry point to the Tor network, similar to a regular Tor relay or entry node, but it employs additional obfuscation techniques to make its traffic less recognizable as Tor traffic.</p>
<p>The primary purpose of a Tor bridge is to assist users who are facing network restrictions or censorship that may block or detect regular Tor connections. By using a bridge, users can circumvent these restrictions and access the Tor network, thereby preserving their privacy, anonymity, and ability to access censored information.</p>
<p>Tor bridges achieve obfuscation by altering the network traffic patterns associated with Tor, making it harder for censors to identify and block Tor connections. They may use various methods, such as transforming Tor traffic to resemble other types of encrypted traffic or disguising it within protocols that are typically allowed in the restricted environment.</p>
<p><strong>1-</strong>Tor User -&gt; Guard Relay -&gt; Middle Relay -&gt; Exit Relay -&gt; Destination</p>
<p>When using a bridge:-</p>
<p><strong>2-</strong>Tor User -&gt; Bridge Relay -&gt; Middle Relay -&gt; Exit Relay -&gt; Destination</p>
<p><strong>obfs4:</strong> obfs4 disguises Tor traffic to appear random, making it difficult for censors to detect bridges through Internet scanning. Compared to its predecessor, obfs3, obfs4 bridges are less prone to being blocked.</p>
<p><strong>meek:</strong> meek transports camouflage Tor usage by mimicking typical browsing behavior on well-known websites. Specifically, meek-azure imitates Microsoft websites to further blend in.</p>
<p><strong>Snowflake:</strong> Snowflake reroutes connections through volunteer-operated proxies, simulating a video call rather than Tor usage.</p>
<p><strong>WebTunnel:</strong> WebTunnel obscures Tor connections by presenting them as regular HTTPS website accesses.</p>
<p><img src="https://cdn.hashnode.com/res/hashnode/image/upload/v1714276573231/380b4390-a0b9-4480-9283-4a9ee929f1f9.png" alt class="image--center mx-auto" /></p>
<h1 id="heading-6-pgp"><strong>6-PGP</strong></h1>
<p>PGP (Pretty Good Privacy) is not directly used within the Tor network itself, but it can be used in conjunction with Tor for secure communication and encryption of messages.</p>
<p>PGP is a widely-used encryption software that provides cryptographic privacy and authentication. It uses a combination of symmetric and asymmetric encryption algorithms to secure the confidentiality and integrity of data.</p>
<p>While Tor focuses on routing and anonymizing network traffic, PGP can be employed to encrypt and decrypt messages, files, or emails exchanged between users within the Tor network or any other communication channel.</p>
<p>When using PGP in conjunction with Tor, users can encrypt their messages or files before sending them through the Tor network. This adds an extra layer of security, ensuring that even if the Tor network were compromised, the content of the communication remains encrypted and unreadable to anyone without the decryption key.</p>
<p>To use PGP in Tor, users typically generate a key pair — a public key and a private key. The public key is shared with others, allowing them to encrypt messages intended for the user. The private key is kept securely by the user and is used to decrypt messages encrypted with the corresponding public key.</p>
<p><img src="https://miro.medium.com/v2/resize:fit:700/1*gX9txTrPi5DTzP8Rt7mb2Q.png" alt /></p>
<p>6.1</p>
<h1 id="heading-7-tails-os"><strong>7-TAILS OS</strong></h1>
<p><img src="https://miro.medium.com/v2/resize:fit:474/1*dG60_T7Te00Z91fZpf2gug.jpeg" alt /></p>
<p>7.1</p>
<p><strong>Tails OS</strong> (The Amnesic Incognito Live System) is a privacy-focused operating system designed to provide anonymity and security while using the internet. It is specifically crafted for use with Tor and is highly regarded in the privacy and security community.</p>
<p>Here are some key points to explain the importance of Tails OS within the context of Tor for your book:</p>
<p><strong><em>1-Anonymity:</em></strong> Tails OS is designed to preserve user anonymity by routing all internet traffic through the Tor network. This ensures that a user’s online activities are obfuscated, making it difficult to track or identify them.</p>
<p><strong><em>2-Live System</em></strong>: Tails OS is a “live” operating system, meaning it can be booted directly from a USB drive or DVD without leaving any traces on the host computer. This feature helps to maintain privacy by not storing any data or information on the local machine.</p>
<p><strong><em>3-Security and Privacy Tools:</em></strong> Tails OS comes bundled with a range of security and privacy tools, including built-in encryption tools, secure deletion utilities, and password managers. These tools enable users to protect their data, communications, and online activities while using Tor.</p>
<p><strong><em>4-Amnesic Nature:</em></strong> Tails OS is designed to be amnesic, meaning it forgets everything after each session. This ensures that no traces of activity, such as browsing history, cookies, or cached files, are left behind.</p>
<p><strong><em>5-Preconfigured Tor Integration:</em></strong> Tails OS has Tor integration built-in, simplifying the process of securely connecting to the Tor network. It ensures that all internet traffic is automatically routed through Tor, providing a seamless and secure browsing experience.</p>
<p><strong><em>6-Wide Applicability:</em></strong> Tails OS can be used on various devices, including laptops and desktop computers, making it accessible to a wide range of users who prioritize privacy and security.</p>
<ul>
<li>Using a dedicated operating system like Tails is really important if you want to boost your privacy and stay anonymous while using Tor. It’s all about making sure your online activities are secure and your identity is protected. Tails is specifically designed for that. It’s an operating system that works hand in hand with Tor to give you that extra layer of protection. By using Tails, you’re showing that you take privacy seriously. It’s like a commitment to keeping your information safe. And the cool thing is, Tails routes all your internet traffic through Tor automatically, making it harder for anyone to track you. Plus, Tails is amnesic, meaning it forgets everything after you’re done using it. No traces left behind. So when you combine Tails OS with Tor, you’re really leveling up your privacy game. It’s a powerful combination that gives you the peace of mind you’re looking for.</li>
</ul>
<h1 id="heading-8-proxychains"><strong>8-PROXYCHAINS</strong></h1>
<p>ProxyChains is a versatile tool used for routing network connections through proxy servers. It allows you to improve your privacy and bypass network restrictions by redirecting your network traffic through a series of proxy servers. The configuration file for ProxyChains is typically located at <code>/etc/proxychains.conf</code>.</p>
<p>The <code>/etc/proxychains.conf</code> file is where you can define the settings for ProxyChains. Here are some key aspects of the configuration file:</p>
<p><strong>General Information:</strong></p>
<ul>
<li><p><code># proxychains.conf VER 3.1</code> indicates the configuration file format and version.</p>
</li>
<li><p><code># # HTTP, SOCKS4, SOCKS5 tunneling proxifier with DNS. #</code> provides a descriptive overview of ProxyChains' functionality.</p>
</li>
</ul>
<p><strong>Proxy Chain Selection:</strong></p>
<ul>
<li><p><code>dynamic_chain</code>: This option dynamically chooses a proxy from the <code>ProxyList</code> for each connection. If a proxy is unavailable, it's skipped, and the application receives an EINTR (interrupted system call) error. This offers flexibility but may not guarantee consistent routing.</p>
</li>
<li><p><code>strict_chain</code>: All proxies in the <code>ProxyList</code> must be online for a connection to succeed. If any are unavailable, an EINTR error occurs. This enforces strict chain usage but can be inflexible.</p>
</li>
<li><p><code>random_chain</code>: A random proxy (or chain if <code>chain_len</code> is set) is chosen for each connection. This provides anonymity but may sacrifice performance and reliability.</p>
</li>
</ul>
<p><strong>Other Settings:</strong></p>
<ul>
<li><p><code>quiet_mode</code>: Disables output from the library, making operations silent.</p>
</li>
<li><p><code>proxy_dns</code>: Routes DNS requests through the proxies as well, enhancing privacy but potentially impacting some applications.</p>
</li>
<li><p><code>tcp_read_time_out</code> and <code>tcp_connect_time_out</code>: Specify timeouts for TCP connections in milliseconds, controlling how long ProxyChains waits before considering a connection failed.</p>
</li>
<li><p><code>[ProxyList]</code> section defines the list of proxies ProxyChains can use. Format: <code>type host port [user pass]</code>. Valid <code>type</code>s are <code>http</code>, <code>socks4</code>, and <code>socks5</code>. Authentication details (<code>user pass</code>) are optional.</p>
</li>
</ul>
<p><strong>Default Proxy:</strong></p>
<ul>
<li><code>socks4 127.0.0.1 9050</code>: This line configures ProxyChains to use a local SOCKS4 proxy on port 9050 (typically Tor) by default. If you don't have Tor running, this proxy won't be available.</li>
</ul>
<h1 id="heading-9-bitcoain"><strong>9-BITCOAIN</strong></h1>
<p><strong>Bitcoin:-</strong> is a cryptocurrency that operates on a blockchain algorithm, making it the most widely used digital currency in the dark web due to its ability to provide privacy and anonymity while ensuring that transactions remain detached from personal identities. It is a decentralized cryptocurrency, meaning that it operates without government or corporate control and is governed by its user base. This decentralized nature ensures that no single entity can manipulate or manage the entire network, enhancing its security and resilience.</p>
<p>Bitcoin’s history dates back to its creation in 2009 by an individual or group known as Satoshi Nakamoto. It was the pioneering cryptocurrency, laying the foundation for the development of other digital currencies. Bitcoin operates through a distributed network of computers, called nodes, which maintain a copy of the blockchain — a public ledger that records all Bitcoin transactions in a chronological and immutable manner.</p>
<p>The functioning of Bitcoin relies on a consensus mechanism known as Proof of Work (PoW), which involves miners competing to solve complex mathematical puzzles. Mining is the process by which new transactions are validated, and new blocks are added to the blockchain. Miners use specialized hardware and computational power to perform these calculations, and the first miner to solve the puzzle and validate the block is rewarded with newly minted Bitcoins.</p>
<p>To initiate a Bitcoin transaction, users create a digital signature using their private key, providing proof of ownership and authorizing the transfer of funds. The transaction details are broadcasted to the network, where miners verify its validity. Once confirmed, the transaction is included in a block, and the block is added to the blockchain, ensuring the integrity and security of the network.</p>
<p>Bitcoin’s decentralized and transparent nature has expanded its adoption beyond the dark web, attracting individuals, businesses, and even institutional investors. It offers a transformative financial system characterized by decentralization, transparency, and the potential for a secure and borderless medium of exchange.</p>
<p>While Bitcoin’s association with the dark web highlights its privacy features, it is important to recognize that it is also used for legal and legitimate purposes globally. However, it is essential to navigate the legal and regulatory landscape surrounding cryptocurrency transactions and adopt robust security practices to mitigate risks associated with the use of Bitcoin and other cryptocurrencies.</p>
<h1 id="heading-10-the-end"><strong>10-THE END</strong></h1>
<p><strong>Disclaimer:</strong></p>
<p>The information presented in article is for educational purposes only. It is not intended to promote or facilitate any illegal or unethical activities. Tor is a powerful tool that can be used for both good and bad purposes. It is crucial to understand the legal and ethical implications of using Tor before engaging with it.</p>
<p><strong>Specifically:</strong></p>
<ul>
<li><p><strong>Do not use Tor to access illegal content or engage in illegal activities.</strong> This includes accessing copyrighted material without permission, hacking into systems, or participating in cybercrime.</p>
</li>
<li><p><strong>Do not use Tor to violate the terms of service of any website or service.</strong> This could result in your account being banned or legal consequences.</p>
</li>
<li><p><strong>Be aware that using Tor may raise suspicion from authorities.</strong> If you are concerned about privacy, consider using additional security measures beyond Tor.</p>
</li>
<li><p><strong>Remember that Tor is not foolproof.</strong> While it offers anonymity, its effectiveness can be limited by various factors.</p>
</li>
</ul>
<h3 id="heading-11-reference-amp-resource">11 - Reference &amp; Resource</h3>
<p><a target="_blank" href="https://tb-manual.torproject.org/about/?source=post_page-----b41744a66689--------------------------------">About TOR</a><br /><a target="_blank" href="https://community.torproject.org/?source=post_page-----b41744a66689--------------------------------">TOR Project</a></p>
<p><a target="_blank" href="https://community.torproject.org/?source=post_page-----b41744a66689--------------------------------">Onion Routing</a></p>
<p><a target="_blank" href="https://hackernoon.com/how-does-tor-really-work-5909b9bd232c?source=post_page-----b41744a66689--------------------------------">How Does TOR Work</a></p>
<p><a target="_blank" href="https://codered.eccouncil.org/course/introduction-to-dark-web-anonymity-and-cryptocurrency?source=post_page-----b41744a66689--------------------------------">Introduction To Dark Web EC-Council</a></p>
<p><a target="_blank" href="https://www.udemy.com/course/deep-web/">https://www.udemy.com/course/deep-web/</a></p>
]]></content:encoded></item><item><title><![CDATA[What is Port 23?]]></title><description><![CDATA[Port 23 is the default TCP port for Telnet, which allows you to connect to other devices remotely. Due to its lack of security, Telnet's use has largely been superseded by SSH.
What is Port 23?
Port 23 is the default Telnet port, and it is used for r...]]></description><link>https://writeups.hashnode.dev/what-is-port-23</link><guid isPermaLink="true">https://writeups.hashnode.dev/what-is-port-23</guid><dc:creator><![CDATA[Felix]]></dc:creator><pubDate>Wed, 27 Mar 2024 08:42:39 GMT</pubDate><enclosure url="https://cdn.hashnode.com/res/hashnode/image/upload/v1711425456444/875f7c02-7bbd-45b4-97ce-56b7408577e3.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><img src="https://cdn.hashnode.com/res/hashnode/image/upload/v1711425473110/dcd044c6-4e46-407d-8ad1-9bc32e357a25.png" alt class="image--center mx-auto" /></p>
<p>Port 23 is the default TCP port for Telnet, which allows you to connect to other devices remotely. Due to its lack of security, Telnet's use has largely been superseded by SSH.</p>
<h3 id="heading-what-is-port-23">What is Port 23?</h3>
<p>Port 23 is the default Telnet port, and it is used for remote terminal emulation of both computers and devices.</p>
<p><strong>What is the Telnet protocol?</strong></p>
<p>The Telnet protocol lets a client device connect to a Telnet server over port 23. After authenticating on the server device, the client can then run commands on it.</p>
<p><strong>What is Remote Terminal Emulation?</strong></p>
<p>You can’t always physically be at the device you need to operate, so software like Telnet lets you remotely connect to it and access it through a remote terminal or shell. This, in turn, allows you to run commands on it as if you were physically at it.</p>
<p><strong>Port 23 For Switches, Routers, and NAS</strong></p>
<p>Remote terminals are not just for computers. Using software like Telnet, you can connect to switches, routers, network-attached storage (NAS), and just about any networked device with a modern operating system such as <a target="_blank" href="https://www.cbtnuggets.com/blog/technology/system-admin/a-complete-guide-to-linux-config-files">Linux</a> installed on it.</p>
<p><img src="https://cdn.hashnode.com/res/hashnode/image/upload/v1711425999034/5b99ec85-03cc-45fe-9877-ab2cec5ff15b.png" alt class="image--center mx-auto" /></p>
<p><strong>What is Telnet Port 23 Used For?</strong></p>
<p>Telnet on port 23 lets you issue commands on a remote device. You will use it mostly on legacy systems and isolated networks.</p>
<p><strong>How Port 23 Telnet Works</strong></p>
<p>Most Unix-like operating systems include a Telnet client. To access it, run the following command from a terminal:</p>
<p><code>telnet [host] [port]</code></p>
<p>The <code>[host]</code> is either the hostname of the device or its IP address.</p>
<p>You can also specify the <code>[port]</code> that you want to communicate over. If you don’t, Telnet will use port 23 by default. <strong>Note</strong>: some system administrators use Telnet on other ports for debugging network services, making it easy to issue commands and view their responses.</p>
<p>After connecting to the host, you can log into it as if you were on the device directly.</p>
<p>In Windows, you need to enable Telnet as a Windows feature in your control panel.</p>
<p><strong>Port 23 Telnet Provides Command Line Access</strong></p>
<p>After you connect to a Telnet server and perform any required authentication on the device, you have the same command-line access that you have on your computer. Depending on the permissions of the user that you are logged onto, you can view, create, edit, and delete files and folders, and you can run programs that exist on the server.</p>
<p><strong>Why Do Legacy Systems and Isolated Networks Use Port 23?</strong></p>
<p>Today, Telnet has limited use because of its lack of security. But this is not a big issue for many legacy systems and local area networks (LANs) that are disconnected from the Internet. On some legacy systems, you may actually have to use Telnet because they don’t support more modern protocols.</p>
<h3 id="heading-the-security-vulnerabilities-of-port-23-telnet"><strong>The Security Vulnerabilities of Port 23 Telnet</strong></h3>
<p>Port 23 is highly vulnerable because it transmits data in the clear and has little to no authentication.</p>
<p><strong>Telnet Port 23 Transmits in the Clear</strong></p>
<p>Telnet transmits in clear text over port 23, making it vulnerable to man-in-the-middle attacks. Anyone who can analyze packets sent over the network as it passes over routers, switches, hubs, and other devices can view whatever a Telnet user types within a session.</p>
<p><strong>Little to No Authentication with Port 23</strong></p>
<p>Telnet implementations often lack inherent authentication, and the authentication mechanisms available are also often vulnerable.</p>
<p> It is not uncommon for devices with Telnet enabled to provide unrestricted access.</p>
<p><strong>Why Does Port Scanning Frequently Targets Port TCP Port 23?</strong></p>
<p>As Telnet is so insecure, it is a frequent target of attackers, who use port scanners and other tools to find computers in which port 23 is open.</p>
<p><strong>Port 23 on TCP</strong></p>
<p><strong>Because</strong> of how Telnet operates, you use TCP as a transport protocol when using port 23.</p>
<p><strong>Why Telnet Port 23 Uses TCP</strong></p>
<p>Telnet uses TCP for its communications over port 23. It does this because TCP offers connection-based delivery of data. TCP also guarantees this delivery, which means that Telnet does not need to perform any confirmation of data delivery within its protocol.</p>
<p><strong>What are Potential Port Conflicts With Port 23?</strong></p>
<p>There are potential conflicts when using port 23, as some devices won’t allow it, and you can’t run services simultaneously.</p>
<p><strong>Some Devices Don’t Allow TCP Port 23</strong></p>
<p>Many devices will block port 23 by default because of the insecure nature of Telnet. In these cases, you will have to use port forwarding to a port such as 2323 to enable Telnet.</p>
<p><strong>You Can’t Run Simultaneous Port 23 Services</strong></p>
<p>At times, you may run into the issue of not being able to bind port 23 to your Telnet server. This is likely because it has already been bound to another server. To discover what application is bound port 23, you can run the following command from your terminal: </p>
<p><code>netstat -aon</code></p>
<p>The output of this command will indicate the process bound to port 23, which you will need to stop before you can start your Telnet server.</p>
<p><strong>Key Takeaways about Port 23</strong></p>
<p>Telnet may have limited purpose in the modern world due to security concerns, you still may use it to remotely connect to legacy systems over port 23. Port 23 may also be used in situations where security is not a concern, such as on a Local Access Network (LAN). That said, there are serious cybersecurity issues with port 23. When possible, opt for the SSH or implement other security measures to ensure communication is secure.</p>
<h3 id="heading-other-port-for-usage">Other Port for usage:</h3>
<p>Port 21 -&gt; FTP</p>
<p>Port 25 -&gt; SMTP</p>
<p>Port 80 -&gt; HTTP</p>
<p>Port 443 -&gt; HTTPs</p>
]]></content:encoded></item><item><title><![CDATA[AnyDesk says hackers breached its production servers, reset passwords]]></title><description><![CDATA[AnyDesk confirmed today that it suffered a recent cyberattack that allowed hackers to gain access to the company's production systems. We are learned that source code and private code signing keys were stolen during the attack.
AnyDesk is a remote ac...]]></description><link>https://writeups.hashnode.dev/anydesk-says-hackers-breached-its-production-servers-reset-passwords</link><guid isPermaLink="true">https://writeups.hashnode.dev/anydesk-says-hackers-breached-its-production-servers-reset-passwords</guid><dc:creator><![CDATA[Felix]]></dc:creator><pubDate>Wed, 07 Feb 2024 12:33:07 GMT</pubDate><enclosure url="https://cdn.hashnode.com/res/hashnode/image/upload/v1707308731262/99772844-a12b-4f3b-956e-761973656183.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>AnyDesk confirmed today that it suffered a recent cyberattack that allowed hackers to gain access to the company's production systems. We are learned that source code and private code signing keys were stolen during the attack.</p>
<p>AnyDesk is a remote access solution that allows users to remotely access computers over a network or the internet. The program is very popular with the enterprise, which use it for remote support or to access colocated servers.</p>
<p>The software is also popular among threat actors who use it for <a target="_blank" href="https://www.bleepingcomputer.com/news/security/rackspace-confirms-play-ransomware-was-behind-recent-cyberattack/">persistent access to breached devices and networks</a>.</p>
<p>The company reports having 170,000 customers, including 7-Eleven, Comcast, Samsung, MIT, NVIDIA, SIEMENS, and the United Nations.</p>
<h3 id="heading-anydesk-hacked">Anydesk Hacked</h3>
<p>In a statement shared with BleepingComputer late Friday afternoon, AnyDesk says they first learned of the attack after detecting indications of an incident on their production servers.</p>
<p>After conducting a security audit, they determined their systems were compromised and activated a response plan with the help of cybersecurity firm CrowdStrike.</p>
<p>AnyDesk did not share details on whether data was stolen during the attack. However, BleepingComputer has learned that the threat actors stole source code and code signing certificates.</p>
<p>The company also confirmed ransomware was not involved but didn't share too much information about the attack other than saying their servers were breached, with the advisory mainly focusing on how they responded to the incident.</p>
<p>As part of their response, AnyDesk says they have revoked security-related certificates and remediated or replaced systems as necessary. They also reassured customers that AnyDesk was safe to use and that there was no evidence of end-user devices being affected by the incident.</p>
<p>"We can confirm that the situation is under control and it is safe to use AnyDesk. Please ensure that you are using the latest version, with the new code signing certificate," AnyDesk said in a <a target="_blank" href="https://anydesk.com/en/public-statement">public statement</a>.</p>
<p>While the company says that no authentication tokens were stolen, out of caution, AnyDesk is revoking all passwords to their web portal and suggests changing the password if it's used on other sites.</p>
<p>"AnyDesk is designed in a way which session authentication tokens cannot be stolen. They only exist on the end user's device and are associated with the device fingerprint. These tokens never touch our systems, "AnyDesk told BleepingComputer in response to our questions about the attack.</p>
<p>"We have no indication of session hijacking as to our knowledge this is not possible."</p>
<p>The company has already begun replacing stolen code signing certificates, with Günter Born of BornCity <a target="_blank" href="http://www.borncity.com/blog/2024/02/01/anydesk-und-die-stoerungen-es-ist-womoeglich-was-im-busch/">first reporting</a> that they are using a new certificate in AnyDesk version 8.0.8, released on January 29th. The only listed change in the new version is that the company switched to a new code signing certificate and will revoke the old one soon.</p>
<p>BleepingComputer looked at previous versions of the software, and the older executables were signed under the name 'philandro Software GmbH' with serial number 0dbf152deaf0b981a8a938d53f769db8. The new version is now signed under 'AnyDesk Software GmbH,' with a serial number of 0a8177fcd8936a91b5e0eddf995b0ba5, as shown below.</p>
<p><img src="https://cdn.hashnode.com/res/hashnode/image/upload/v1707309125722/bbdc6bf4-1693-43d2-a785-a0add6b0a9b4.png" alt class="image--center mx-auto" /></p>
<p><strong>Signed AnyDesk 8.0.6 (left) vs AnyDesk 8.0.8 (right)</strong><br /><em>Source: BleepingComputer</em></p>
<p>Certificates are usually not invalidated unless they have been compromised, such as being stolen in attacks or publicly exposed.</p>
<p>While AnyDesk had not shared when the breach occurred, Born reported that AnyDesk suffered a four-day outage starting on January 29th, during which the company disabled the ability to log in to the AnyDesk client.</p>
<p>"my.anydesk II is currently undergoing maintenance, which is expected to last for the next 48 hours or less," reads the <a target="_blank" href="https://status.anydesk.com/">AnyDesk status message page</a>.</p>
<p>"You can still access and use your account normally. Logging in to the AnyDesk client will be restored once the maintenance is complete."</p>
<p>Yesterday, access was restored, allowing users to log in to their accounts, but AnyDesk did not provide any reason for the maintenance in the status updates.</p>
<p>However, AnyDesk has confirmed to BleepingComputer that this maintenance is related to the cybersecurity incident.</p>
<p>It is strongly recommended that all users switch to the new version of the software, as the old code signing certificate will soon be revoked.</p>
<p>Furthermore, while AnyDesk says that passwords were not stolen in the attack, the threat actors did gain access to production systems, so it is strongly advised that all AnyDesk users change their passwords. Furthermore, if they use their AnyDesk password at other sites, they should be changed there as well.</p>
<p>Every week, it feels like we learn of a new breach against well-known companies.</p>
<p>Last night, <a target="_blank" href="https://www.bleepingcomputer.com/news/security/cloudflare-hacked-using-auth-tokens-stolen-in-okta-attack/">Cloudflare disclosed that they were hacked</a> on Thanksgiving using authentication keys stolen during <a target="_blank" href="https://www.bleepingcomputer.com/news/security/okta-says-its-support-system-was-breached-using-stolen-credentials/">last years Okta cyberattack</a>.</p>
<p>Last week, Microsoft also revealed that they were <a target="_blank" href="https://www.bleepingcomputer.com/news/security/microsoft-reveals-how-hackers-breached-its-exchange-online-accounts/">hacked by Russian state-sponsored hackers</a> named Midnight Blizzard, who also <a target="_blank" href="https://www.bleepingcomputer.com/news/security/hpe-russian-hackers-breached-its-security-teams-email-accounts/">attacked HPE</a> in May.</p>
]]></content:encoded></item><item><title><![CDATA[Command Injection (Try Hack Me OWASP top 10)]]></title><description><![CDATA[Normal Usage of Web Applications
Command Injection မှာတော့ အများကြီးရှင်းပြဖို့သိပ်မရှိဘူးဗျ လွယ်လဲလွယ်သလို တွေ့ဖို့လဲ ခက်ပါတယ်။ ဉပမာပြောရရင် command injection ဆိုတာက ကျွန်တော်တို့ server တစ်ခုရှိမယ်ပေါ့။ Server အမျိုးအစားကတော့ History အကြောင်းလေးပေါ...]]></description><link>https://writeups.hashnode.dev/command-injection-try-hack-me-owasp-top-10</link><guid isPermaLink="true">https://writeups.hashnode.dev/command-injection-try-hack-me-owasp-top-10</guid><category><![CDATA[hacking]]></category><category><![CDATA[penetration testing]]></category><dc:creator><![CDATA[Felix]]></dc:creator><pubDate>Sat, 03 Feb 2024 13:56:44 GMT</pubDate><enclosure url="https://cdn.hashnode.com/res/hashnode/image/upload/v1706964709259/88b27b0d-39fe-4c16-85c7-1e013d2d7516.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<h3 id="heading-normal-usage-of-web-applications"><strong>Normal Usage of Web Applications</strong></h3>
<p>Command Injection မှာတော့ အများကြီးရှင်းပြဖို့သိပ်မရှိဘူးဗျ လွယ်လဲလွယ်သလို တွေ့ဖို့လဲ ခက်ပါတယ်။ ဉပမာပြောရရင် command injection ဆိုတာက ကျွန်တော်တို့ server တစ်ခုရှိမယ်ပေါ့။ Server အမျိုးအစားကတော့ History အကြောင်းလေးပေါ့ဗျာ။ အဲ့ server ထဲမှာ နိုင်ငံထဲက သမိုင်းကြောင်းတွေကို သိမ်းထားမယ်ဆိုပါစို့။ အဲ့တော့ အသုံးပြုသူက Pyay မြို့ရဲ့ သမိုင်းကြောင်းကိုသိချင်လို့ Pyay လို့ရိုက်ရှာလိုက်ရင်။ ကျွန်တော်တို့ sever ထဲမှာသိမ်းထားတဲ့ pyay.txt ဆိုတဲ့ file လေးကို ထုတ်ပြလိုက်မယ်။</p>
<p>ဒါကအဆင်ပြေတယ် ပြသနာကတော့ - တစ်ကယ်လို့များ ကျွန်တော်တို့ရဲ့ website က အသုံးပြုသူလာရှာတဲ့ အကြောင်းအရာတွေကို စစ်ထုတ်ထားမှု မရှိပဲ ဇတ်လမ်းအကြောင်းအရာတွေကို ထုတ်ပြချင်တိုင်း ထုတ်ပြနေရင်တော့ ဘယ်ဇတ်ကောင်က ဘယ်လိုဇတ်လမ်းရှိတယ်ဆိုတာ တိတိကျကျခွဲပေးနိုင်ခြင်းမရှိတော့ဘူးပေါ့။</p>
<p>ရှုပ်သွားလားမသိဘူး xD.... ပြောရရင် ကျွန်တော်တို့ website မှာအသုံးပြုတဲ့သူက Linux command line ဖြစ်တဲ့ "cat" ကိုသုံးပြီး အကြောင်းအရာတစ်ခုကိုရှာတယ်ဆိုပါစို့။ ဆိုလိုချင်တာက ကျွန်တော်တို့ရဲ့ အကြောင်းအရာ နာမည်ကို ရိုက်ပြီးရှာတာမဟုတ်တော့ဘူး။ cat ဆိုတဲ့ command နဲ့သုံးပြီးရှာလိုက်မယ်ဆိုရင်လည်း ကျွန်တော်တို့ သေသေချာချာစစ်ထုတ်ထားခြင်းမရှိတဲ့ website ကလည်း ထုတ်ပြမယ်ဆိုရင်...</p>
<p>eg : pyay.txt; whoami</p>
<p>အပေါ်ကလိုရှာလိုက်မယ်ဆိုရင်တော့ ပုံမှန်ရှာနေကျ စာသားတွေအပြင် server ကက ရိုက်ရှာသမျှကို command လို့သတ်မှတ်ပြီး ပြန်ဖော်ပြနေမှာဖြစ်ပါတယ်။ ဒီလောက်ထိ အိုကေကြလားမသိဘူး။ နားမလည်သေးရင် နောက်ပိုင်း lab ကိုကျွန်တော်နဲ့တူတူလိုက်ဖြေကြည့်လိုက်ပါ။</p>
<h3 id="heading-tryhackme-owasp-top-10-task-5"><strong>TryHackMe (OWASP TOP 10 [Task 5])</strong></h3>
<p>မစခင်တစ်ခုသတိပေးချင်တာက ခုမှ Try Hack Me ကိုစပြီးဝင်ဘူးတဲ့သူတွေဆိုရင်တော့ Register လုပ်ပြီးတာနဲ့ doc တွေနဲ့ bonus resource section တွေကိုအရင်စစ်ဆေးကြည့်လိုက်ပါ။</p>
<p>Navigate to: <a target="_blank" href="https://tryhackme.com/room/owasptop10">https://tryhackme.com/room/owasptop10</a> → Task 5</p>
<p><strong>5.1. What strange text file is in the website root directory?</strong></p>
<p><img src="https://cdn.hashnode.com/res/hashnode/image/upload/v1706965493000/a2398133-ef24-477f-8caf-7c56841a2f1c.png" alt class="image--center mx-auto" /></p>
<p>Explain :</p>
<p>As this is a reverse shell. Type in the command <code>ls</code> in the console and press submit</p>
<p>Answer : drepper.txt</p>
<p><strong>5.2 How many non-root/non-service/non-daemon users are there?</strong></p>
<p><img src="https://cdn.hashnode.com/res/hashnode/image/upload/v1706965647643/4cf85261-08d6-4c5c-9b7f-a661f66ce681.png" alt class="image--center mx-auto" /></p>
<p>Explain :</p>
<p>အပေါ်က /etc/passwd ဆိုတာကိုတော့ linux သုံးတဲ့သူတိုင်းသိကြမယ်ထင်ပါတယ်။ ဒါကိုတော့ password တွေသိမ်းထားတဲ့ နေရာ (database) လို့သိထားရင်ရပါပြီ။ ဒါဆိုရင်တော့ ကျွန်တော်တို့က command ဖြစ်တဲ့ cat နဲ့တွဲကြည့်လိုက်တဲ့အခါမျိုးမှာတော့ အပေါ်ကပုံမျိုးမြင်ရမှာဖြစ်ပါတယ်။</p>
<p>ကျွန်တော်တို့ :x:100 ဆိုတာမျိုး return ပြန်ပေးထားတာကို မြင်နိုင်ပါတယ်။ နောက်တော့ကျွန်တော်တို့ file တွေကို စစ်ပြီး သူတို့ရဲ့ home directory ရှိ/မရှိ ကိုစစ်ဆေးပါမယ်။ So, <code>home/$Username</code></p>
<p>After analysing, we obtain users information that is not root/service/daemon</p>
<p>Answer : 0</p>
<p><strong>5.3 What user is this app running as?</strong></p>
<p>ဒါကတော့ လွယ်ပါတယ်။ ခုလက်ရှိသုံးနေတဲ့ username ကိုမေးထားတဲ့အတွက် အောက်က command ကိုသုံးပေးလိုက်ရင်ရပါပြီ။</p>
<p><code>whoami</code></p>
<p>Answer : www-data</p>
<p><strong>5.4 What is the user’s shell set as?</strong></p>
<p><img src="https://cdn.hashnode.com/res/hashnode/image/upload/v1706966170671/ed5251ce-4666-4dc9-bc98-d43841ceeacd.png" alt class="image--center mx-auto" /></p>
<p>Explain :</p>
<p>The user’s shell is defined in the <code>/etc/passwd</code> file</p>
<p><code>getent</code> ဆိုတဲ့ command ကတော့ linux မှာ အသုံးပြုသူ user ရဲ့ အသေးစိပ်အချက်အလက်များကို ရှာဖွေဖို့သုံးတဲ့ command ဖြစ်ပါတယ်။ Since getent uses the same name of service as the system, getent will be going to show all information, including that gained from the network information sources such as LDAP.</p>
<p>The databases it usually searches in are: <code>ahosts, ahostsv4, ahostsv6, aliases, ethers (Ethernet addresses), group, gshadow, hosts, netgroup, networks, passwd, protocols, rpc, services, and shadow</code>.</p>
<p>type <code>getent passwd www-data</code> and press submit to obtain the user’s shell. <code>/etc/passwd</code> file မှာ ထည့်သွင်းထားတဲ့ ၇ ခုမြောက်ကတော့ user ရဲ့ home directory ပဲဖြစ်ပါတယ်။ user's shell လို့သတ်မှတ်လို့ရပါတယ်။</p>
<p>Answer : /usr/sbin/nologin</p>
<p><strong>5.5 What version of Ubuntu is running?</strong></p>
<p><img src="https://cdn.hashnode.com/res/hashnode/image/upload/v1706968031267/99678fb7-e1d8-463d-a3d9-78182b2c866d.png" alt class="image--center mx-auto" /></p>
<p>Explain :</p>
<p><code>lsb_release -a</code> ဆိုတဲ့ command ကတော့ ubuntu ရဲ့ version ကိုစစ်ဖို့ဖြစ်ပါတယ်။</p>
<p>Answer : 18.04.4</p>
<p><strong>5.6 Print out the MOTD. What favourite beverage is shown?</strong></p>
<p><img src="https://cdn.hashnode.com/res/hashnode/image/upload/v1706968106083/1b43199d-1cfe-471e-b940-29f8700fd8d6.png" alt class="image--center mx-auto" /></p>
<p>Explain :</p>
<p>motd အကြောင်းသိချင်ရင်တော့ ဒီမှာဖတ်လို့ရပါတယ်။ <a target="_blank" href="https://www.networkworld.com/article/964193/how-to-use-the-motd-file-to-get-linux-users-to-pay-attention.html">Read About MOTD</a> .</p>
<p>from the hint, we know that the target file is <code>00-header</code> .</p>
<p>type <code>cat /etc/update-motd.d/00-header</code></p>
<p>Answer : <code>DR DREPPER</code></p>
<p>Task 7 ဖြစ်တဲ့ broken auth ကိုတော့ နောက်တစ်ခန်းမှာဆက်လက်ဖတ်ရှူနိုင်ပါတယ်။</p>
<p>What is next?</p>
<ol>
<li><p>Broken Access Contro</p>
</li>
<li><p>Security Misconfiguration</p>
</li>
<li><p>HTML Injection</p>
</li>
<li><p>Broken Authentication</p>
</li>
<li><p>Bug Bounty Hunting with Burp Suite (Intercept, Repeater, Intruder)</p>
</li>
<li><p><a target="_blank" href="https://writeups.hashnode.dev/how-to-install-gns3-on-kali-linux">How to install GNS3 on Kali Linux</a></p>
</li>
<li><p><a target="_blank" href="https://writeups.hashnode.dev/web-app-enumeration-information-gathering">Web App Enumeration and Information Gathering</a></p>
</li>
</ol>
]]></content:encoded></item><item><title><![CDATA[Web App Enumeration & Information Gathering]]></title><description><![CDATA[အရင်ဆုံး Enumeration အကြောင်းစပြောရမယ်ထင်တယ်။ Enumeration ဆိုတာဘာလဲ?
Enumeration ဆိုတာမြန်မာလိုဘာသာပြန်လိုက်ရင်တော့ စာရင်းကောက်ခြင်းလို့ခေါ်ပါတယ်။ အဲ့လိုပဲ System အတွင်းက ဖြစ်နိုင်ခြေရှိတဲ့ အားနည်းချက်တွေကို ကျွန်တော်တို့က စုဆောင်းဖို့အတွက် လုပ်ရခြင်...]]></description><link>https://writeups.hashnode.dev/web-app-enumeration-information-gathering</link><guid isPermaLink="true">https://writeups.hashnode.dev/web-app-enumeration-information-gathering</guid><dc:creator><![CDATA[Felix]]></dc:creator><pubDate>Thu, 01 Feb 2024 21:15:34 GMT</pubDate><enclosure url="https://cdn.hashnode.com/res/hashnode/image/upload/v1706821706144/4db595b8-6596-4baf-8960-85c2e48ef7cd.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>အရင်ဆုံး Enumeration အကြောင်းစပြောရမယ်ထင်တယ်။ Enumeration ဆိုတာဘာလဲ?</p>
<p>Enumeration ဆိုတာမြန်မာလိုဘာသာပြန်လိုက်ရင်တော့ စာရင်းကောက်ခြင်းလို့ခေါ်ပါတယ်။ အဲ့လိုပဲ System အတွင်းက ဖြစ်နိုင်ခြေရှိတဲ့ အားနည်းချက်တွေကို ကျွန်တော်တို့က စုဆောင်းဖို့အတွက် လုပ်ရခြင်းဖြစ်တယ်။ <em>Enumeration is used to gather the following: Usernames, group names, Hostnames, Network shares and services,</em> စသည်ဖြင့်စုဆောင်းဖို့သုံးပါတယ်။</p>
<h3 id="heading-why-do-we-do-it">Why Do We Do It?</h3>
<p>ကျွန်တော်တို့က ဘယ်လိုတိုက်ခိုက်နည်းမျိုးကိုမဆို မလုပ်ဆောင်ခင်မှာ ကျွန်တော်တို့ target ထားလိုက်တဲ့ အရာကို အတက်နိုင်ဆုံးလေ့လာဖို့လိုတယ်။</p>
<p>ကျွန်တော်တို့က ဘယ်လိုအရာမျိုးနဲ့ ဆက်စပ်နေလဲဆိုတဲ့ website ရဲ့နောက်ကွယ်ကဖွဲ့စည်းတည်ဆောက်ပုံတွေကို သိထားဖို့လိုပါတယ်။</p>
<p>နောက်ဆုံးတစ်ချက်ကတော့ ကျွန်တော်တို့တိုက်ခိုက်နိုင်တဲ့ပုံစံမျိုးရှိလား? အဲ့တာကဘယ်မှာရှိနေလဲ? ဒီ website ကဘာအတွက်သုံးတာလဲ? ကျွန်တော်တို့အတွက် အသုံးဝင်နိုင်တဲ့ website နဲ့ပတ်သတ်တဲ့အချက်အလက်တွေရှိနေလားဆိုတာကို ရှာရတာဖြစ်ပါတယ်။</p>
<h3 id="heading-website">Website တစ်ခုမှ ဘာတွေရှာရမလဲ?</h3>
<p>Kali မှာနာမည်ကြီးတာတော့ Nslookup တို့ host တို့ပေါ့ အဲ့တာတွေသုံးပြီး IP address ရှာရမယ်။</p>
<p>IP ရပြီဆို scanner နဲ့ IP ထည့်ပြီး scan လိုက်ရင် ဒီ site မှာဘယ် port တွေပွင့်နေလဲ?</p>
<p>Website ရဲ့ဖွဲ့စည်းတည်ဆောက်ပုံကိုလေ့လာရမယ်။ (ဉပမာ - PHP နဲ့ရေးတာလား, သူ့မှာ JS function တွေပါလား, အပြင်မှာသုံးနေတဲ့ application တစ်ခုခုများရှိနေမလား) ဆိုတာမျိုးရှာဖို့လိုတယ်။</p>
<p>Login page နဲ့ registration form တွေစစ်ဖို့လိုတယ်။</p>
<p>Type of server the website is hosted on</p>
<p>Type of OS hosting the website</p>
<p>server ကလက်ခံထားတဲ့ port အပြင် တခြား open ဖြစ်နေတဲ့ port တွေရှိလား?</p>
<p>Website မှာ code တွေကို encryption လုပ်ထားလား လုပ်မထားဘူးလား? encryption လုပ်မထားဘူးဆိုရင်တော့ MIMT attack နည်းနဲ့ password တွေကို plain text အနေနဲ့တောင် ဖမ်းယူလို့ရသွားနိုင်ပါတယ်။</p>
<h3 id="heading-tools">အသုံးပြုတဲ့ Tools တွေကတော့</h3>
<ol>
<li><p>Google Dorking</p>
</li>
<li><p>Ping, Host, Nslookup</p>
</li>
<li><p>Whatweb</p>
</li>
<li><p>dirb</p>
</li>
<li><p>nmap</p>
</li>
<li><p>nikto</p>
</li>
<li><p>Burp Suite</p>
</li>
</ol>
<h3 id="heading-google-dorking">Google Dorking</h3>
<p>Google Dork အကြောင်းတော့ ကျွန်တော်ဒီမှာရှင်းမပြတော့ပါဘူး။ သူ့ကိုသုံးခြင်းအားဖြင့် website မှာရှိနေတဲ့ အသုံးဝင်တဲ့အချက်တွေကို ကျွန်တာ်တို့ရရှိနိုင်မှာဖြစ်ပါတယ်။</p>
<p>အောက်မှာပြထားတဲ့ example လေးကို google search bar မှာရိုက်ရှာကြည့်လိုက်ပါ။ သူကတော့ ကျွန်တော်တို့လိုချင်တာကိုပဲစစ်ထုတ်ပေးတာဖြစ်ပါတယ်။</p>
<p><strong>site:</strong><a target="_blank" href="http://tesla.com"><strong>tesla.com</strong></a> <strong>filetype: pdf</strong></p>
<p><img src="https://cdn.hashnode.com/res/hashnode/image/upload/v1706820249571/b3a630ca-edd5-421c-937d-f9936bcd2bf7.png" alt class="image--center mx-auto" /></p>
<h3 id="heading-ping-host-nslookup">Ping, Host, Nslookup</h3>
<p><strong>Ping</strong></p>
<p>Ping ကိုတော့ website ရဲ့ IP address နဲ့ အဲ့ website က run နေလားဆိုတာကို စစ်နိုင်ပါတယ်။</p>
<p><img src="https://cdn.hashnode.com/res/hashnode/image/upload/v1706820539527/23833fc7-3410-4419-8914-fca678f5e50a.png" alt class="image--center mx-auto" /></p>
<p>တစ်ကယ်လို့ ping ကအလုပ်မလုပ်ဘူးဆိုရင်တော့ အဲ့ website က offline ဖြစ်နေတာဖြစ်နိုင်ပါတယ်။</p>
<p><strong>Host and Nslookup</strong></p>
<p>IP address သိနိုင်ဖို့ ဒီနှစ်ခုကိုလဲသုံးလို့ရပါတယ်။</p>
<p><img src="https://cdn.hashnode.com/res/hashnode/image/upload/v1706820670507/164e45fd-7ec3-4c04-86e8-3331c8aedfc5.png" alt class="image--center mx-auto" /></p>
<p><img src="https://cdn.hashnode.com/res/hashnode/image/upload/v1706820699806/860e85d9-217a-4c0d-8293-5e4f3f0e19af.png" alt class="image--center mx-auto" /></p>
<p><strong>Whois</strong></p>
<p>Site ပိုင်ရှင် registration လုပ်ထားတဲ့ information အသေးစိပ်အချက်အလက်တွေကို စုဆောင်းဖို့အတွက်အသုံးပြုခြင်းဖြစ်ပါတယ်။ Might also provide emails, phone numbers and physical addresses.</p>
<p><img src="https://cdn.hashnode.com/res/hashnode/image/upload/v1706820995133/c84c7b66-5dac-4365-ac70-8a666391e7e7.png" alt class="image--center mx-auto" /></p>
<h3 id="heading-active-vs-passive-information-gathering"><strong>Active vs. Passive Information Gathering</strong></h3>
<p>အပေါ်က command တွေရိုက်ပြီး လုပ်နေတာဖြစ်တဲ့အတွက် ကျွန်တော်တို့က active information gathering လုပ်တယ်လို့ခေါ်ပါတယ်။ ဘာလို့ဆို - ကျွန်တော်တို့က command တွေနဲ့ အမြဲထိတွေ့နေရတာဖြစ်တဲ့အတွက် target website မှာ အချိန်ပြည့်ရှိနေလို့ဖြစ်ပါတယ်။</p>
<p>အပေါ်မှာပြောပြထားတဲ့အချက်တွေရရှိဖို့အတွက် ကျွန်တော်တို့က command တွေမသုံးပဲ အခြား website တစ်ခုခုကိုသုံးမယ်ဆိုရင် passive information gathering လုပ်တယ်လို့ခေါ်ပါတယ်။ ဘာလို့ဆို - အပြင် website တွေကိုသုံးလိုက်တဲ့အတွက် ကျွန်တော်တို့ရဲ့ target website နဲ့ထိတွေ့မှုမရှိတော့လို့ဖြစ်ပါတယ်။</p>
<h2 id="heading-bonus-resources"><strong>Bonus Resources</strong></h2>
<ol>
<li><p><a target="_blank" href="https://sourceforge.net/projects/owaspbwa/">OWASPBWA vulnerable machine.</a></p>
</li>
<li><p><a target="_blank" href="https://www.youtube.com/watch?v=-D4vUSsd5vQ">OWASPBWA VM setup video.</a></p>
</li>
</ol>
<p>What is next?</p>
<ol>
<li><p>Command Injection</p>
</li>
<li><p>HTML Injection</p>
</li>
<li><p>Security Misconfiguration</p>
</li>
<li><p>Broken Access Control</p>
</li>
<li><p>Broken Authentication</p>
</li>
<li><p>Bug Bounty Hunting with Burp Suite (Intercept, Repeater, Intruder)</p>
</li>
</ol>
<p>တွေကိုဆက်ပြီး အချိန်ရသလိုရေးပေးသွားမှာဖြစ်ပါတယ်။ like လေးလုပ်ပေးကြပါအုံးနော် ... 😍🤭🤭</p>
]]></content:encoded></item><item><title><![CDATA[How to install GNS3 on Kali Linux]]></title><description><![CDATA[ဒီဆောင်းပါးလေးမှာတော့ ကျွန်တော်ပြောပြပေးသွားမှာက ကျွန်တော်တို့ တင်ပြီးသုံးနေတဲ့ Linux မှာ cisco router, switch and firewall လိုမျိုး network device ရဲ့ IOS image တွေကို ကောင်းကောင်းလုပ်ဆောင်ပေးတဲ့ GNS3 ကိုဘယ်လို install တင်ရမလဲဆိုတာပြောပြပေးသွားမှာဖြ...]]></description><link>https://writeups.hashnode.dev/how-to-install-gns3-on-kali-linux</link><guid isPermaLink="true">https://writeups.hashnode.dev/how-to-install-gns3-on-kali-linux</guid><category><![CDATA[networking]]></category><dc:creator><![CDATA[Felix]]></dc:creator><pubDate>Wed, 24 Jan 2024 20:22:58 GMT</pubDate><enclosure url="https://cdn.hashnode.com/res/hashnode/image/upload/v1706127457655/31765389-ef40-41d5-8976-a1dec0f15d6f.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>ဒီဆောင်းပါးလေးမှာတော့ ကျွန်တော်ပြောပြပေးသွားမှာက ကျွန်တော်တို့ တင်ပြီးသုံးနေတဲ့ Linux မှာ cisco router, switch and firewall လိုမျိုး network device ရဲ့ IOS image တွေကို ကောင်းကောင်းလုပ်ဆောင်ပေးတဲ့ GNS3 ကိုဘယ်လို install တင်ရမလဲဆိုတာပြောပြပေးသွားမှာဖြစ်ပါတယ်။</p>
<p>GNS ဆိုတာကတော့ (Graphic Network Simulator) ဖြစ်ပါတယ်။ သူ့အကြောင်းကိုအများကြီးတော့မပြောပြတော့ဘူးနော်။ လိုရင်းပဲသွားရအောင်။ ဘယ်လိုလူမျိုးတွေသုံးသင့်လဲဆိုရင်တော့ CISCO exam တွေဖြေမဲ့သူတွေသုံးသင့်ပါတယ်။ ကျွန်တော်တို့ Routing and Switching exam တွေအတွက် Layer 2 တွေ Layer 3 တွေကလိုအပ်လာပါပြီ အဲ့တာကြောင့် GNS3 မှာတော့ lab တစ်ခုလိုမျိုး IOS image သွင်းပြီးတာနဲ့လေ့လာဖို့အတွက် အကောင်းဆုံးဖြစ်ပါတယ်။ GNS3 ကိုတော့ windows မှာလွယ်လွယ်ကူကူ တင်ပြီးအသုံးပြုနိုင်ပေမဲ့ ကျွန်တော်တို့လို Linux disto သုံးတဲ့သူတွေအတွက်က နဲနဲတော့ခက်ခဲမယ်ထင်ပါတယ်။ ဒါကြောင့်ကျွန်တော် ဒီ article လေးကိုရေးပြီး တင်ပေးလိုက်ရခြင်းဖြစ်ပါတယ်။</p>
<h3 id="heading-how-to-install-gns3">How to install GNS3</h3>
<p>ကျွန်တော်တို့ cisco network simulator ကို Kali Linux မှာကောင်းကောင်း run ဖို့အတွက် လိုအပ်တဲ့ repo တွေ လိုအပ်တဲ့ packages တွေကိုထည့်သွင်းပေးဖို့လိုအပ်ပါတယ်။</p>
<hr />
<p><strong>|| Step - 1</strong></p>
<p>First, open the terminal and update the repository package list with the “sudo apt update” command.</p>
<pre><code class="lang-plaintext">sudo apt update
</code></pre>
<p><strong>|| Step - 2</strong></p>
<p>Execute the command below in the terminal to download all the dependent packages for the GNS3 simulator program.</p>
<pre><code class="lang-plaintext">sudo apt install -y python3-pip python3-pyqt5 python3-pyqt5.qtsvg python3-pyqt5.qtwebsockets qemu qemu-kvm qemu-utils libvirt-clients libvirt-daemon-system virtinst wireshark xtightvncviewer apt-transport-https ca-certificates curl gnupg2 software-properties-common
</code></pre>
<p><strong>Note :</strong> ဒီမှာတော့ qemu ဆိုတဲ့ package ကိုထည့်မပေးနိုင်ဘူးဆိုရင် အောက်က code ကနေ manual down ပြီး install တင်နိုင်ပါတယ်။</p>
<pre><code class="lang-plaintext">wget http://ftp.us.debian.org/debian/pool/main/q/qemu/qemu_3.1+dfsg-8+deb10u8_amd64.deb
</code></pre>
<pre><code class="lang-plaintext">sudo dpkg -i qemu_3.1+dfsg-8+deb10u8_amd64.deb
</code></pre>
<p><strong>|| Step - 3</strong></p>
<p>ကျွန်တော်တို့ python application တွေကို download လုပ်ဖို့အတွက် pip3 command ကိုသုံးလို့ရပါတယ်။</p>
<p>GNS3 GUI ကို download လုပ်ဖို့အတွက် ဒီ command ကို terminal မှာ run ပေးရပါမယ်။ “sudo pip3 install gns3-server gns3-gui”</p>
<pre><code class="lang-plaintext">sudo pip3 install gns3-server gns3-gui
</code></pre>
<p><strong>|| Step - 4</strong></p>
<p>အားလုံးပြီးသွားရင်တော့ dynamips ကို install တင်ဖို့ ဒီ command ကိုအသုံးပြုနိုင်ပါတယ်။ "sudo apt install dynamips". သူကဘာလုပ်ပေးနိုင်လဲဆိုရင် ကျွန်တော်တို့ GNS3 program ကနေ CISCO router တွေကို ကျွန်တော်တို့ computer ကနေ အသုံးပြုလို့ရအောင် ဖန်တီးပေးတာဖြစ်ပါတယ်။</p>
<pre><code class="lang-plaintext">sudo apt install dynamips
</code></pre>
<p><strong>|| Step - 5</strong></p>
<p>အားလုံးပြီးသွားရင်တော့ ကျွန်တော်တို့ရဲ့ Linux ကနေပြီး gns3 လို့ရိုက်ရှာလိုက်ပါ အောက်ပါပုံအတိုင်းမြင်တွေ့ရမှာဖြစ်ပါတယ်။</p>
<p><img src="https://cdn.hashnode.com/res/hashnode/image/upload/v1706127014564/367fff7b-7173-47b1-933c-4e400a7a3cd4.png" alt class="image--center mx-auto" /></p>
<p>ဖွင့်လိုက်ပြီဆိုရင်တော့ အောက်ကပုံအတိုင်းမြင်ရမှာဖြစ်ပါတယ်။ ကျွန်တော်တို့က default choice လုပ်ထားတဲ့ “Run appliances on my local computer” ဆိုတာကိုပဲရွေးပေးထားပြီး next ကိုနှိပ်ပေးရပါမယ်။</p>
<p><img src="https://cdn.hashnode.com/res/hashnode/image/upload/v1706127112718/56bd7b5b-ed1e-4276-ab69-41fc2bd4e99f.png" alt class="image--center mx-auto" /></p>
<p>ပြီးရင်တော့ အောက်ကပုံတွေအတိုင်း ဘာမှမပြောင်းလဲပဲ အဆင့်ဆင့် next ကိုနှိပ်ပေးသွားလိုက်ရင် ရပါပြီ။</p>
<p><img src="https://cdn.hashnode.com/res/hashnode/image/upload/v1706127189680/b3113575-d308-4e45-b9ff-b00ac6be1bc6.png" alt class="image--center mx-auto" /></p>
<p><img src="https://cdn.hashnode.com/res/hashnode/image/upload/v1706127217747/551bf0b8-86d1-4fca-bfdf-72d6a0a00d17.png" alt class="image--center mx-auto" /></p>
<p><img src="https://cdn.hashnode.com/res/hashnode/image/upload/v1706127233302/51d25974-3c3c-4275-bb15-3e70e5a10d57.png" alt class="image--center mx-auto" /></p>
<p>အားလုံးပြီးသွားရင်တော့ မြင်တွေ့ရတဲ့အတိုင်း ကျွန်တော်တို့ linux မှာ gns3 ကိုကောင်းကောင်း install တင်လို့ပြီးသွားပါပြီ အားလုံးအဆင်ပြေကြပါစေ။</p>
<p>နောက်ရက်မှာ ထပ်ပြီး gns3 ထဲကို CISCO router ဘယ်လိုထည့်ရမလဲဆိုတာကို ဒီ article မှာပဲ edit လုပ်ပြီး ဆက်ရေးပေးသွားပါမယ်။</p>
<p>နောက်ဆက်ရေးမဲ့ စာကတော့ ကိုသီဟရဲ့ Youtube ( Y Technologies )networking tutorial ထဲက video ကို ref ယူပြီးရေးမှာပါ။</p>
<p><a target="_blank" href="https://www.youtube.com/watch?v=qgCAzWK7-Lg&amp;list=PL_n_imvRzO-lVUWOeO4XSFekIGuVH0EtY">Click youtube tutorial</a></p>
<p>သူ့ရဲ့ video က ios ပဲပါလို့ gns3 install တင်ဖို့အစပြုပြီးရေးသားလိုက်ခြင်းဖြစ်ပါတယ်။ အရေးအသားအမှားများပါခဲ့ရင် ကျွန်တော့်ရဲ့ ညံ့ဖျင်းမှုဖြစ်လို့ ခွင့်လွှတ်ပေးဖို့တောင်းပန်လိုက်ပါတယ်။</p>
<p>Thank for reading my article.... &lt;3 (Felix is here...)</p>
]]></content:encoded></item><item><title><![CDATA[Why should we Need to Sleep Computer]]></title><description><![CDATA[ကျွန်တော်တို့ နေ့စဉ်အသုံးပြုနေတဲ့ Computer က သုံးပြီးရင် Power Off သင့်တာလား Sleep ပဲလုပ်သင့်တာလား ဆိုတာ လူတိုင်းသေချာသိတဲ့သူလည်းပါနိုင်သလို မသိတဲ့သူလည်းပါနိုင်လို့ ကျွန်တော်ဒီ article လေးကိုရေးတိုင်လိုက်ပါတယ်။
လက်ရှိသုံးနေတဲ့ Computer က (laptop) ပေါ...]]></description><link>https://writeups.hashnode.dev/why-should-we-need-to-sleep-computer</link><guid isPermaLink="true">https://writeups.hashnode.dev/why-should-we-need-to-sleep-computer</guid><category><![CDATA[computer]]></category><dc:creator><![CDATA[Felix]]></dc:creator><pubDate>Sun, 02 Jul 2023 11:51:05 GMT</pubDate><content:encoded><![CDATA[<p><img src="https://cdn.hashnode.com/res/hashnode/image/upload/v1688298624174/ef6d3873-bbcf-43a8-9a16-3aa5d3e136a8.png" alt class="image--center mx-auto" /></p>
<p>ကျွန်တော်တို့ နေ့စဉ်အသုံးပြုနေတဲ့ Computer က သုံးပြီးရင် Power Off သင့်တာလား Sleep ပဲလုပ်သင့်တာလား ဆိုတာ လူတိုင်းသေချာသိတဲ့သူလည်းပါနိုင်သလို မသိတဲ့သူလည်းပါနိုင်လို့ ကျွန်တော်ဒီ article လေးကိုရေးတိုင်လိုက်ပါတယ်။</p>
<p>လက်ရှိသုံးနေတဲ့ Computer က (laptop) ပေါ့ဗျာ</p>
<p>ဘယ်လိုမျိုးလဲဆိုတော့ ကျွန်တော်တို့ ဖုန်းတွေသုံးသလိုပဲ သုံးလို့ရပါတယ်။</p>
<p>Computer သုံးလိုက် သုံးပြီးတော့ ပိတ်ထားလိုက်</p>
<p>ပြန်သုံးဖို့ ပြန်ဖွင့်လိုက်ဆိုရင် တစ်နေ့တာမှာ ခနခန ပိတ်လိုက်ဖွင့်လိုက်လုပ်ပါများလာရင် စက်ရဲ့ HDD/SSD &amp; Battery တွေက နာလာတက်ပါတယ်။</p>
<p>ဘယ်အချိန်မှာပိတ်လိုက်သင့်လဲ</p>
<p>ဘယ်အချိန်မှာ Sleep ပဲလုပ်ထားသင့်လဲဆိုတော့</p>
<p>တစ်နေ့တာ Computer နဲ့အလုပ်လုပ်နေရတဲ့သူတွေက computer ခနခနဖွင့်ရတာမျိုးရှိတတ်တယ် အဲ့အတွက် တစ်ခါဖွင့်ပြီးရင် Sleep ပဲလုပ်ထားသင့်ပါတယ်။ စက်က battery မကောင်းလို့ power off သွားတာကတော့ တစ်ပိုင်းပေါ့ဗျာ။</p>
<p>ကိုယ့်ရဲ့တစ်နေ့တာ အလုပ်တွေပြီးပြီ မသုံးတော့ဘူးဆိုရင်တော့ Power Off (ညအိပ်တဲ့အချိန်မျိုးမှာလုပ်ကြတာပေါ့)</p>
<p>မနက်ပိုင်းနိုးလာလို့ကိုင်ပြီဆိုတာနဲ့ စဖွင့်ပြီးရင် Sleep ဆိုတာလေးပါတယ်။</p>
<p>အဲ့တာနဲ့ပဲ ပိတ်ထားလို့ရပါတယ်။ Sleep လုပ်ထားပြီဆိုတော့ နောက်တစ်ခါ ဖွင့်ချင်ရင် Screen လေးလှန်လိုက်ရုံပဲ တန်းပွင့်လာတဲ့အတွက် သုံးရတာလည်း ပိုမြန်သလို ပိုသွက်ပါတယ်။</p>
<p>ပိတ်လိုက်ပြီးမှပြန်ဖွင့်ရင် Windows စပွင့်ပွင့်ချင်းမှာ</p>
<p>မိတ်ဆွေတို့ကြုံဖူးကြမှာပေါ့ ... Function တွေအများကြီး run ရတာ</p>
<p>ခနခန run ပါများလာရင် ရေရှည်အတွက်မကောင်းဘူး။</p>
<p>နောက်ပြီး အရေးကြီးတဲ့အချက်က Computer ဖွင့်တာနဲ့ပိတ်တာပဲ</p>
<p>ဖွင့်တာ ပြသနာမရှိပေမဲ့ ပိတ်တာက နည်းနည်းတိုင်ပတ်တယ်။</p>
<p>ပိတ်ပြီဆို ဒီတိုင်းပိတ်ချလိုက်လို့မရဘူး ကျွန်တော်တို့သုံးထားတဲ့ cache လို့ခေါ်တဲ့ recet file တွေရှင်းသင့်တယ်။ ပြီးရင် ဖွင့်ထားတဲ့ folder/ file/ software / အမျိုးမျိုးပေါ့ hidden ဖြစ််နေလားစစ်။ Minimize လုပ်ထားမိလား စစ်။</p>
<p>အကုန်ပိတ်ပြီးတာသေချာပြီဆိုမှ Power Off ကိုလုပ်သင့်ပါတယ်။</p>
]]></content:encoded></item><item><title><![CDATA[How to Host A Web Server On Android]]></title><description><![CDATA[ဒီ article မှာတော့ ကျွန်တော်က web server တစ်ခုကို android ပေါ်မှာ ဘယ်လိုတည်ဆောက်ပြီး Run ရမယ်ဆိုတာကို ရှင်းပြပေးမှာဖြစ်ပါတယ်။]]></description><link>https://writeups.hashnode.dev/how-to-host-a-web-server-on-android</link><guid isPermaLink="true">https://writeups.hashnode.dev/how-to-host-a-web-server-on-android</guid><category><![CDATA[Share]]></category><category><![CDATA[IT Support]]></category><category><![CDATA[Android]]></category><dc:creator><![CDATA[Felix]]></dc:creator><pubDate>Thu, 29 Jun 2023 12:29:52 GMT</pubDate><content:encoded><![CDATA[<p><img src="https://cdn.hashnode.com/res/hashnode/image/upload/v1688200463343/70040d74-9599-4dc3-b584-c6d42884e13f.jpeg" alt class="image--center mx-auto" /></p>
<p>ဒီ article မှာတော့ ကျွန်တော်က web server တစ်ခုကို android ပေါ်မှာ ဘယ်လိုတည်ဆောက်ပြီး Run ရမယ်ဆိုတာကို ရှင်းပြပေးမှာဖြစ်ပါတယ်။</p>
]]></content:encoded></item></channel></rss>