Posts

Showing posts with the label security

Dig into Https client connection in Android

Dig into Https client connection in Android Table of Contents reference resources Java Keytool Certificate formats Use Https in Android Client Java SSLContext Two ways SSL verification TLSDemo 1 reference resources http://developer.android.com/training/articles/security-ssl.html http://ogrelab.ikratko.com/using-android-volley-with-self-signed-certificate/ http://stackoverflow.com/questions/2138940/import-pem-into-java-key-store http://stackoverflow.com/questions/3685548/java-keytool-easy-way-to-add-server-cert-from-url-port 2 Java Keytool Java keystore is like a database which store certificates and private keys and protect them by a password maybe. There are at least three format s of that, JKS, PKCS12, JCEKS, and many more. But in this tutorial, I only consider two formats of that JKS which is the Java's default format and BKS which is the Android's default format. How to import a certificate to the BKS style KeyStore? First step was to pr...

Hash functions in web security

Image
Hash functions in web security Table of Contents What the hash function is? Http Cookies password 1 What the hash function is? A hash function is a one-directional one-to-one or multiply-to-one function, which can project data in one space to another, but not reverse. The key point here is one-directional projection, if you found a way to reverse this process, then this hash algorithm is corrupted, if the hash algorithm corrupted, the whole web security is down. You would not want that happen, right? So, which hash functions are the popular ones? the popular hash function includes md5, sha256. In python standard distribution, it provided an hashlib module which provided the usual hash functions. The following code snippet is an example to get digest from messages by python's hashlib module. The digest is the hash value of a message.  digest = hash(message). import hashlib hashlib.md5( 'hello world' ).hexdigest() hashlib.sha256( 'hello wor...

How android sign your app

Image
android APK employed the same signature method just as java jar package did. there are two ways of sign your app. 1. Use tools in java package   a. make your own keystore keytool -genkey -v -keystore my-release-key.keystore -alias zpcat_key -keyalg RSA -keysize 2048 -validity 10000 b. sign your apk  jarsigner -verbose -keystore my-release-key.keystore MainMenuView_unsign.apk zpcat_key c. align your apk zipalign -v 4 MainMenuView_unsign.apk MainMenuView.apk 2. Use android's private tools a. make key/cert pair by android's private tools development/tools/make_key: android tool to make key/cert pair b. signing apk with key/cert pair: java -jar SignApk.jar platform.x509.pem platform.pk8 Application.apk Application_signed.apk 3 compare the two methods -- the java keystore file .VS. key/cert pair of android (pk8 key file and x509.pem cert file) they are the same stuff. you can import the key/cert pair into your java keystore file by: keytool-impo...

PGP toolkit in linux

Image
PGP toolkit in Linux Table of Contents 1 Philip R. Zimmermann 2 What is digital certificate? 3 X509 .VS. PGP 4 PGP tools in Linux platform 4.1 Generate your own self-signed Certificate 4.2 encypt and decrypt by gpg 4.3 Manager your Certificats 5 PGP in Emacs 5.1 Easy PG package in emacs 5.2 encrypt/sign email in gnus 5.3 epa-mail* .VS. mml-secure-message-* 1 Philip R. Zimmermann Zimmermann is the creator of Pretty Good Privacy(PGP) which become the standard of protocol named OpenPGP. In the era before 90s century, US government held a export restrictions for cryptography software(This bullshit policy sounds like censorship in china today right? But the different is that a lot of SOB in china government.). But Zimmermann made PGP as a open source software to counterattack government's violate human right behave(The human being's nature right is to pursual for freedom and equality, especially in Internet). This made him the target of a thre...

SELinux Introduction

SELinux Introduction I follow a tutorial named five minutes to install Wordpress. Guess, How much time did I spent to install the fucking Wordpress in my fedora OS? The whole afternoon. Everything is fine except I configure a virtual host for Wordpress server and restart Apache. Then the nightmare coming, I restart Apache again and again with Access denied 404 Error every time. Finally I guess maybe the SELinux's problem. Then everything is Ok after I disable the SELinux and restart the machine. A good tutorial of SELinux – security and SELinux Table of Contents 1 What's SELinux? 2 Some Simple SELinux suit Utilities Usage 2.1 Check current SELinux status 2.2 Check file's security context 2.3 change a file's security context 1 What's SELinux? SELinux is Linux feature that provides a mechanism for supporting strict access control security policies, short for Security-Enhanced Linux. The key concepts underlying SELinux can be traced to sev...