Tuesday, August 22, 2017

Are TOR Hidden Services really hidden? Demystifying HS Directory surveillance by injecting Decoys inside TOR!


Recently, I spoke at the C0C0N X Security & Hacking Conference 2017 held at Le Meridien, Kochi. The talk focussed on the 'Hiddenness' of TOR Hidden Services specific to the detection of HS Directory Surveillance by injecting Decoys or Honeypots inside the TOR network. Here’s the digest of the presentation.


What is TOR?
The Onion Router – Gateway to Anonymity
How TOR works?
Establishing the Circuit
Directory Authorities - The Gatekeepers of TOR

Introduction to TOR Hidden Services (HS)
Why run a TOR HS? - Sneak peek into HS features
How TOR HS works? - HS Rendezvous Protocol

Analysis of hiddenness of TOR HSs 
Research Hypothesis - Are TOR HS really Hidden?
The HS Honeypot Approach
Setting up the Onion Decoy Project

Live Demo
Hosting Tor Hidden Service in seconds with Docker Containers
How to setup Honeypots (aka Onion Decoys) inside TOR Network
Live probing of Onion Decoys to detect intrusions by attackers

Results of the Onion Decoy Experiment 
Private Hidden Services are not really hidden

Conclusion & Takeaways
Everything can be a Honeypot, if you don’t know it fully
The more you hide, The more somebody wants to know why



The Source Code of the Onion Decoy Project is available at https://github.com/OnionDecoy


Below is the presentation for the delivered talk.

Tuesday, September 27, 2016

How the next Edward Snowden should access Internet for maintaining privacy? - Rethink VPN & TOR

In the present era of Mass Surveillance by intelligence agencies like NSA, GCHQ & RAW, you should know that every border you cross, every purchase you make, every call you dial, every cell phone tower you pass, friend you keep, article you write, site you visit, subject line you type, and packet you route is in the hands of some electronic system whose reach is unlimited, but whose safeguards are questionable. This amount of metadata collected about you is more than enough to create simulations of you and predict your behaviour in any given circumstance. It involves a systematic interference with individual’s right to privacy in terms of subjection to significant indiscrimination, monitoring and censorship. Hence, Privacy & Anonymity are rising concerns among informed citizens, journalists, whistleblowers and Edward Snowdens of the world.

When it comes to technology, privacy and anonymity enthusiasts extensively use encrypted proxy services like VPN & TOR Anonymity network to hide their identities & activities online. But let’s understand how useful & worthy they are, what are the differences and how can we leverage the potential of both.

VPN is faster than TOR, and is suitable for P2P downloading. The major downside however (and reason VPN is said to provide privacy rather than anonymity) is that it requires your trust the VPN provider. This is because, should it wish to (or is compelled to), your VPN provider can “see” what you get up to on the internet. VPN also allows you to easily spoof your geographic location.

On the contrary, TOR is much slower because of the built-in Onion Routing, is often blocked by websites, and is unsuitable for P2P, but it does not require your truston anybody, and is therefore much more secure & truly anonymous.

Interestingly, VPN & TOR can be clubbed and used together in order to provide an extra layer of security, and to mitigate some of the drawbacks of using either technology exclusively. The main downside, however, of doing so combines the speed hit of both technologies, making connections more secure but slow. It is also important to understand the difference between connecting VPN to TOR and connecting TOR to VPN for accessing the Internet. Order Matters!

Sunday, August 28, 2016

Dark-Side of Internet of Things (IOT): Security & Privacy Challenges



Recently, I was invited to deliver a talk at the Global IOT Conclave held at The Chancery Pavilion, Bangalore. The talk focussed on the Dark-Side of Internet of Things specific to Security & Privacy Challenges in IOT. Here’s the digest of the presentation.

  • Why is everything getting Smart with the advent of IOT?  Sensors or Cloud or M2M.
  • IOT is bridging the gap between the Physical world & the Digital world and how Digital threats are becoming Physical threats?
  • Top IOT Hacks: Chrysler's Jeep Cherokee, Mattel's Wi-fi Hello Barbie.
  • Eavesdropping through microphones of Smart Dolls, Smart Teddy Bears & Smart TVs. What if the smart doll teaches offensive things to your kid.
  • Exploitable Smart Refrigerators, Smart Thermostats, Smart Insulin Pumps. How Smart TVs have been hacked & infected by malware for automated Ad Clicks and Cryptocurrency mining.
  • IOT Ransomeware is now reality. How much someone would be willing to pay to remove ransomware from a Smart Pacemaker?
  • Denial of Service (DOS) attacks on & through IOT devices. How hackers can turn a Smart Fridge into a spam-bot?
  • Why can't we make smart devices smart enough to be secure? The IOT Security Challenges: Resource Constraints, STRIDE Threat vectors.
  • Security vs Privacy vs Anonymity. Importance of Trust in IOT Privacy.
  • Security by Obscurity vs Security by Design: Proprietary protocols, indigenous hardware & air-gapped networks.
  • Security can not be an afterthought. It has to considered & implemented in all of stages of IOT Business: Planning, Design, Implementation, Verification, Validation, Deployment & Operations.
  • IOT Business Model needs to change. Earlier we used to Build product, Ship them & forget about them until we had to Service them, but now we have to Ship & Remember.

Below is the presentation for the delivered talk.

Friday, June 3, 2016

Touring the Dark-Side of Internet: A Journey through IOT, TOR & Docker




Recently, I had the privilege of delivering a talk at ThoughtWorks GeekNight Hyderabad along with my co-speaker @Sarath. The session focussed on the Dark-Side of Internet touching upon the following theme.

With the advent of IOT, Every 'Thing' is getting Smart, starting from the range of smartwatches, smart refrigerators, smart bulbs to smart car, smart healthcare, smart agriculture, smart retail, smart city and what not, even smart planet. But why is every thing getting smart? Is it just a marketing gimmick? 

People are trying to bridge the gap between Digital World & Physical World by means of ubiquitous connectivity to Internet, and when digital things become physical, digital threats also become physical threats. Security & Privacy issues are rising as never before. What if the microphone in your smart TV can be used to eavesdrop the private communications in your bed room? What if a smart driverless car deliberately crashes itself into an accident? What if you want to be Anonymous over Internet and don't want anybody to track you? 

The talk focused on answering the above questions with a view on 'What are we currently doing to protect ourselves' and 'What we need to do'. What are the new security challenges that are coming up and how privacy & anonymity is taking the lead over security. The talk also sensitised the audience about the paradigm shift that is happening in IOT DevOps, with help of Docker Containers and how they can be anonymised using TOR.

The detailed Agenda of the delivered talk:

Friday, April 1, 2016

Digital Disruption - Facts to ponder!

Why didn’t a cab driver think of Ola or Uber? 
Why didn’t a Shopping Mall owner think of Flipkart? 
Why didn’t a Theatre owner think of BookMyShow? 
Why didn’t Airtel or Vodafone think of Paytm? 
Why didn’t Taj or Marriott think of GoIbibo? 


The answer to all above, and the myriad of all other companies displaced by digital disruption, is that at some point they became so busy and coupled with the ongoing need to meet or exceed the quarterly numbers, that they forgot to look far enough outside of their business to see the disruption ahead. A quite convincing reason why so many companies fail to face the disruption is that when someone from the outside uses digital disruption to disrupt you, the strategy most often invoked is to protect and defend the status quo. It is amazing how much time and money organizations spend protecting and defending their current ‘cash cows’. In the past this was a valid strategy that did produce good results. But digital disruption is different. Because it tends to be game-changing with a very low cost of entry, it is not hard for a small startup to quickly disrupt not only a big business, but even an entire industry.



But, why all this is happening now? What is digital disruption?

Wednesday, October 14, 2015

Installing Mac OS X El Capitan 10.10 on Vmware ESXi 6.0


After a long struggle of 48 hours, I could finally able to install the Apple's latest Mac OS X El Capitan v10.11  on a Virtual Machine (VM). The experiment was conducted on Vmware ESXi 6.0 virtualization platform running over physical IBM Server X3650 M3.


Following are the installation steps:

Setting up ESXi for running Apple Mac OS X 

Vmware ESXi 6.0 doesn’t support OS X out of the box.
  1. So, the first thing you need to do is to customise the hypervisor layer by executing

Friday, April 17, 2015

Signing Java .jar Files with CLI Command Jarsigner using Hardware Token in Windows

How to Configure Java JDK to Use the eToken

  1. Download the JDK from Oracle.com.
    Note:    Even if you are using a 64-bit version of Windows, the 32-bit JDK is required.
  2. Open a text editor (such as Notepad) and do the following:
    1. Copy and paste the following 2 lines into the text (Notepad) document:
      name=eToken
      library=c:\WINDOWS\system32\eTPKCS11.dll
    2. Save this file as eToken.cfg in the appropriate directory for your version of the JDK, for example:
      • JDK 1.8
        C:\Program Files (x86)\Java\jdk1.8.0_20\bin
      Note:    If you are running a 32-bit version of Windows, the Java JDK is installed in C:\Program Files\Java\....

Monday, September 1, 2014

What Data Science tells me?

• If you’re a DBA, you need to learn to deal with unstructured data
• If you’re a statistician, you need to learn to deal with data that does not fit in memory
• If you’re a software engineer, you need to learn statistical modeling and how to communicate results.
• If you’re a business analyst, you need to learn about algorithms and tradeoffs at scale.

Just stare at the following figure, you'll understand.

Tuesday, July 16, 2013

What happens when you hit a key to start a job on a remote EC2 machine

Have you ever thought about what happens when you hit a key to start a job on a remote EC2 machine.

Strike a key on the keyboard and the capacitance changes instantaneously, sending a signal down the USB cable into the computer. The computer’s keyboard driver traps the signal, recognizes the key it’s from, and sends it to the Operating System for handling. The OS determines which application is active and decides whether the keystroke needs to be routed over an internet connection. If it is routed, a set of bytes is sent down the CAT-5 cable into the wall socket, abstraction masked via the OSI 7-layer model, and sent to a router. The router determines the closest router which is likely to know the IP of your destination ( a lot of stuff behind this even like DNS resolution etc.), and sends that packet onwards.

Tuesday, March 12, 2013

The Art of Living - Alapati Sarath

"Life is Beautiful" i was told, "It could be as you want it to be" i heard, "Take it as it comes" i thought being a cool person not thinking much about the problems that i may have face one day i was relaxed. But when a person has to face a problem Unexpectedly its

Monday, December 31, 2012

Year 2013 is Loading... - 99.9% Complete


███████│███████████████▒│▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒

----2011--------------------------2012-------------------------------2013-----------------

Tuesday, December 4, 2012

Saturday, March 10, 2012

Apology Letter to my Boss...


Dear Debugger boss,

System.getDate();
Subject: #include"Apology.h"

I admit that what I did during Handshake has hurt your SaaS a lot emotionally. And I'm sorry for the SOAP I used after Event Handling. I also admit that Waterfall Model is meaningless & pledge not to Hibernate again. I promise by the means of this Protocol that I will not Serialize my RSS Feeds until my JVM crashes.

Although I know I shouldn't ask for SAX from you due to the Runtime complexities of the Garbage Collection, but I know how big your Error Handling really is. Please Clear Cache and make an Exception.

Your Apache Indian,
Abhinav the Prince.

Tuesday, February 14, 2012

Dependent Factors - Calculation of GATE Marks, Score, Rank & Percentile

The following article showers light on the various dependent factors on which the calculations of GATE Marks, Score, Rank & Percentile are based. I have collected this data from various reliable sources and have compiled it in an easy-to-understand way so that you can have a clear idea about the intricacies behind these terms that decide your fate in GATE.

Saturday, January 21, 2012

3 Ways to URL Redirection from HTML page

Sometimes, it's  useful & inevitable to redirect the End-user from a web page to a completely different URL automatically. So in this tutorial I'll be presenting the 3 most efficient ways to URL Redirection from a HTML webpage.

1. Using 'meta' refresh tag

Monday, January 16, 2012

SetUp Eclipse CDT using MinGW for Windows

The standard Eclipse CDT IDE (for C/C++) needs integration with the GNU toolchain, before you can start making your C/C++ projects in Eclipse (the world's best Open-source IDE, Integrated Development Environment). This includes GNU's make, gcc compiler, and gdb debugger utilities. For windows, MinGW and Cygwin are the two main platform choices for acquiring the toolchain. It is important to note the difference between them. Cygwin produces executables that use the Cygwin POSIX runtime. MinGW produces native Windows executables that do not require a separate runtime.

In this tutorial I'll show you how to setup Eclipse CDT using MinGW toolchain in a Windows Platform.

Thursday, January 12, 2012

Android Offline Installation Procedure (Windows)


In this tutorial, I'll show the 'Android Offline Installation Procedure' for computers on a Windows Platform which do not have a direct Internet Connection.

1. Install Android SDK Manager, Revision 16.
  - The Android SDK Tools Package is the only package that gets installed.


2. Close the Android SDK Manager & Go to the SDK Installation folder "C:\Program Files\Android\android-sdk".

Sunday, July 10, 2011

Get Google+ Invitation now....

Is it that you just can not resist the urge to use the brand new Social Networking gaint Google+ by Google? So here comes the end of your awaitment. Get Started with the Amazing experience of Circles, Hangouts and Sparks of Google+. Just provide your Google email-id in our wall and get the invitation in seconds.

Monday, January 17, 2011

Facebook scam chain: Deleting inactive members

Facebook scam
Recently a Facebook scam message chain has spread over the most popular social networking site FB, which claims that as Facebook is becoming overpopulated, they are deleting inactive members & further to prove that your account is active, you need to copy the message and send it to a minimum of 15 of your friends within 2 weeks.

Well this is nothing but a hoax mail, so don't carry on the chain. Don't let the scammers rule Facebook. Official Facebook will never ask you to do such to prove the activeness of your account. They have other means to check so, you know well, i guess. All this is nothing but a Facebook noise to increase traffic on FB servers, & to see how far the spam can spread. They do indeed, are benefited by this.

To know more on this scam message see -
Details: Facebook hoax chain message

Sunday, January 2, 2011

Ubuntu Team - IIT Bombay visit - Soumalya Dutta

Friends you know what recently,
The Ubuntu developer's team has recently visited IIT Bombay. They are going to give the IITians an opportunity to directly collaborate with Ubuntu Linux forums.
Ubuntu is nothing but the most popular Distro of Linux.

Remote Desktop Connection to Abhinav's Mac On Cloud.