Popular Posts

Showing posts with label Windows. Show all posts
Showing posts with label Windows. Show all posts

2/01/2013

An Introductory Guide To TeleNet Commands


An Introductory Guide To TeleNet Commands
     I don't know how many of you use TeleNet to call this system (or other
systems) but I thought this might come in handy for those that do.



     Some basic info about TeleNet commands.  To enter a TeleNet you must be at
the TeleNet prompt "@".  You can get there two ways:
1)  When you first dial TeleNet you will be at the prompt
2)  When connected to a system via TeleNet you can return to TeleNet
    command mode by typing "<CR>@<CR>" (See note A.)
     Once you get to the prompt here are some of the commands available to you
and a brief description of what they do.
 Command           Function
-------------------------------------------------------------------------
 C xxxxxxx<CR>     Connects you to a specific host or terminal.
 STAT<CR>          Display network port address.
 FULL<CR>          Set full duplex
 HALF<CR>          Set half duplex
 DTAPE<CR>         Prepares the network for bulk file transfers.
 CONT<CR>          Return to transfer mode from command mode.
 BYE<CR> or D<CR>  Disconnects you from the currently connected host.
 HANGUP<CR>        Tells TeleNet to hang up the phone....
 TERM xx<CR>       Changes your terminal type.  xx can be one of the
                   following:
                             D1  =  CRT's and Personal Computers
                             B3  =  Bi-directional printers
                             A2  =  Uni-directional printers
                             A5  =  Slow printing terminal which
                                    loses data on the left side
                                    at another setting.
                             A9  =  same as A5
                            <CR> =  Unknown
 MAIL or           Requests connection to Telemail.
 TELEMAIL<CR>
 TEST CHAR<CR>     Used to test the system if you are receiving
                   garbled output.  Use this and look for garbled
                   characters or patern breaks.  If you do try
                   adjusting your parity or contact TeleNet.
 TEST ECHO<CR>     If you feel your input to the system is being
                   garbled by your parity or contact TeleNet.
 TEST ECHO<CR>     If you feel your input to the system is being

An Introduction to the Computer Underground


From:  The Butler / Ripco BBS
Subject: An Introduction to the Computer Underground


                                                 ***********************************************************************
                                                *                                                                                                                    *
                                                *               An Introduction to the Computer Underground                  *
                                                *                                                                                                                   *
                                                *                           Brought to you by,                                                        *
                                                *                                                                                                                  *
                                                *                               The Butler...                                                             *
                                                *                                                                                                                  *
                                                *                                                                                                                  *
                                                ***********************************************************************


The Computer Underground consists of mainly two forms of media, printed
and electronic, both will be discussed in this file.  I use the word
underground because some of the contents of this file are not the types of
titles you would run across at your local bookstore or newsstand.  The kind of
information that makes up underground publications is mainly technical in
nature, but, definitely not limited to that.  One can also find tidbits about
off-the-wall political views, drugs, weapons, and other topics that are not
normally in the mainstream of our society.

The Computer Underground...

Com-put-er Un-der-ground   \kem-`pyt-er\  \`en-der-`grand\ (1970's)

  A group organized in secrecy, hidden behind aliases, to promote the free
  exchange of information regarding anything and everything including but
  not limited to Computers, Telephones, Radios, Chemicals, and ideas.


The CU is made up of men and women all over the globe and of all ages.  Most
of those involved in the CU consider it a hobby, but, there are those that
are involved strictly for illegal purposes, i.e. Selling Pirated Software.  I,
like most people involved enjoy the information that can be obtained through
all of the different avenues in the CU, i.e. Bulletin Boards, Underground
Periodicals, Network Digests, and General Discussions between members.

The most common way members communicate is through Bulletin Boards.  If you are
reading this you know what a BBS is because this will not be released in
printed form.  There are thousands of BBSes around the world run by people for
many reasons including: legitimate businesses, Software Technical Support,
Hobby related, Pirated Software, Message Centers, etc...Some of the more common
ones are RIPCO, Face-2-Face, Exec-PC, The Well, etc...

Currently there are many regular electronic magazines that are being published
and there have been many that have discontinued for one reason or another.
Some current ones include: PHRACK, NIA, PHANTASY, CUD, etc...Some discontinued
ones include: PIRATE, PHUN, NARC, etc...

There is a current debate about whether or not an electronic media has the same
constitutional rights as the printed one.  That is for our congressmen to
decide, but you could voice your opinion.  I personally can't see the differ-
-ence.  Now, don't get me wrong I do not support the publishing of Long-
distance codes or anything of that nature, but, I do support the exchange of
other information, i.e. how to unprotect a game, how to make a smoke bomb,
etc...

There are also "Underground Publications" like TAP, 2600, Cybertek, etc.
These magazines are published in hard copy and deal with every considerable
topic regarding the CU.  Most of these magazines publish completely legal
information that is obtained from public sources and is available to anyone
and everyone.

I doubt that any of the following sources of information would mind if you use
an alias to order any of their material, so I would recommend that you do
just in case!  You might even want to get yourself a private mail box for all
of this "underground" information.  I would also advise you to use a money
order when purchasing anything also.  They usually cost an extra 50 cents at
the post office. Don't worry about using money orders with these people because
I have personally made purchases from many of them without trouble.

The following information is provided to enable you to become more familiar
with the CU and unusual information in general.  Have fun and try not to
get yourself in trouble.

Now for the meat of this Article!!!!

E L E C T R O N I C   M A G A Z I N E S

PHRACK  Predecessor to Phrack Classic
        Author:  Knight Lightning & Taran King
        Network Address:c483307@umcvmb.missouri.edu
        Other Address:
        BBS: None
        Last Issue: Phrack #30

PHRACK CLASSIC
        Author:  Doc Holiday, Crimson Death & Various Contributors
        Network Address: pc@well.uucp or cdeath@stormking.com
        Other Address:
        BBS:  None
        Last Issue: Phrack Classic #32 11/90

LOD     Legion Of Doom Technical Journals
        Author:  Eric Bloodaxe, Lex Luthor, Prime Suspect, Phase Jitter,
                 Professor Phalken, Skinny Puppy.
        Network Address: None
        Other Address:
        BBS:
        Last Issue:  LOD Tech Journal #4   May 20, 1990

PHUN    Phreakers/Hackers Underground Network
        Author:  Red Knight
        Network Address: N/A
        Other Address:
        BBS:
        Last Issue: P/HUN #5 05/07/90

ATI     Activist Times, Incorporated
        Author:  Ground Zero
        Network Address: gzero@tronsbox.xei.com
        Other Address:  ATI P.O. Box 2501  Bloomfield, NJ 07003
        BBS:
        Last Issue: ATI #53 12/05/90

NIA     Network Information Access
        Author: Guardian Of Time & Judge Dredd
        Network Address:  elisem@nuchat.sccsi.com
        Other Address:
        BBS:
        Last Issue: NIA #70  02/91





PHANTASY
        Author: The Mercenary
        Network Address: None
        Other Address: The I.I.R.G. 862 Farmington Ave, Suite-306,
                       Bristol, Ct 06010
        BBS:  Rune Stone  203-485-0088
        Last Issue: Phantasy V1N4 1/20/91

PIRATE
        Author: Various Authors
        Network Address: N/A
        Other Address:
        BBS: N/A
        Last Issue:  V1 #5 April 1990

ANE     Anarchy 'N' Explosives
        Author: Various Authors
        Network Address: N/A
        Other Address:
        BBS: N/A
        Last Issue:  #7 06/16/89

NARC    Nuclear Phreakers/Hackers/Carders
        Author: The Oxidizer
        Network Address: N/A
        Other Address:
        BBS:
        Last Issue: NARC #7 Fall 1989

SYNDICATE REPORTS
        Author:  The Sensei
        Network Address:
        Other Address:
        BBS:
        Last Issue:


This is not an attempt to list all of the known magazines but just some of the
more popular ones.  If I left a particular one out that you feel should of been
included I apologize.

All of the above magazines can be found in the CUD archives and at many of the
Bulletin Board Systems listed at the end of this file.

P R I N T E D    M A G A Z I N E S

Author: Emmanuel Goldstein
Network Address: 2600@well.sf.ca.us
Other Address:   2600 Magazine, P.O. Box 752, Middle Island, NY 11953

2600 Magazine is published quarterly, 48 pages per issue.
Subscriptions are $18 U.S. for a year in the U.S. and Canada,
$30 overseas.  Corporate subscriptions are $45 and $65 respectively.
Back issues are available for $25 per year, $30 per year overseas
and they go back to 1984.

Phone 516-751-2600
Fax   516-751-2608






TAP/YIPL  Formerly YIPL "Youth International Party Line"
          Now TAP "Technical Assistance Party"

TAP Magazine
P.O. Box 20264
Louisville, KY 40250
Most all issues will cost $1.00 for US Citizens and $2.00
for overseas.  Terms are CASH, postal money order,
or regular money order with the payee left blank.
BBS: 502-499-8933

Cybertek Magazine
Published by OCL/Magnitude
P.O. Box 64
Brewster NY 10509
$2.50 for sample issue
$15 year for 6 issues


Mondo 2000  (Formerly Reality Hackers Magazine / High Frontiers)
P.O. Box 10171
Berkley, CA 94709-5171
Phone 415-845-9018
Fax   415-649-9630
$24 for five issues
Frank Zappa subscribes to Mondo 2000!!!

Fact Sheet Five
6 Arizona Ave
Rensselaer, NY 12144-4502
$3.50 for a sample issue.
$33 a year for 8 issues
Phone 518-479-3707

Fact Sheet Five reviews any independent news media, i.e. 2600, TAP,
Books, Music, Software, etc.

Full Disclosure  by Glen Roberts
P.O. Box 903-C
Libertyville, Illinois 60048
Free sample issue
$18 for 12 issues

Deals with Privacy, electronic surveillance and related topics.

Anvil
P.O. Box 640383f
El Paso, TX 79904

Computer Security Digest
150 N. Main Street
Plymouth, MI 48170
Phone 313-459-8787
Fax   313-459-2720
$125 U.S. per year.
Overseas $155 U.S. per year.


HAC-TIC Dutch Hacking Magazine
Network Address: ropg@ooc.uva.nl
Other Address:  Hack-Tic P.O. Box 22953  1100 DL Amsterdam
Phone: +31 20 6001480



Privacy Journal
P.O. Box 15300
Washington D.C. 20003
Phone  202-547-2865

Monitoring Times
140 Dog Branch Road
Brasstown, North Carolina 28902


B O O K S

Anarchist Cookbook???

Poor Man's James Bond by Kurt Saxon

Big Secrets by William Poundstone

Bigger Secrets by William Poundstone

How to get anything on anybody by Lee Lapin

Signal--Communication Tools for the Information Age  A Whole Earth Catalog
  (Highly Recommended!!!)

Neuromancer by William Gibson

Out of The Inner Circle by Bill Laundreth

Hackers by Steven Levy

The Cookoo's Egg by Clifford Stoll

The Shockwave Rider

Information for sale by John H. Everett

Hackers Handbook III  by Hugo Cornwall

Datatheft by Hugo Cornwall

The International Handbook on Computer Crime by U. Sieber

Fighting Computer Crime by D. Parker

Foiling the System Breakers by J. Lobel

Privacy in America by D. Linowes

Spectacular Computer Crimes by Buck BloomBecker

Steal This Book by Abbie Hoffman

M I S C E L L A N E O U S    C A T A L O G S

Loompanics LTD
P.O. Box 1197
Port Townsend, WA 98368

Paladin Press
????


Consumertronics
2011 Crescent DR.
P.O. Drawer 537
Alamogordo, NM 88310
Phone 505-434-0234
Fax   500-434-0234(Orders Only)

Consumertronics sells manuals on many different hacking/phreaking related
topics, i.e. "Voice Mail Box Hacking", "Computer Phreaking", etc.

Eden Press Privacy Catalog
11623 Slater "E"
P.O. Box 8410
Fountain Valley, CA 92728
Phone 1-800-338-8484  24hrs, 7 days a week.

Here is the opening paragraph from their catalog:

Welcome to the Privacy Catalog, Over 300 publications explore every aspect of
privacy in ways that are not only unique, but also provocative.  Some books may
seem "controversial", but that results only from the fact that people can enjoy
many different views of the same subject.  We endeavor to offer views that will
prove both helpful and thoughtful in the many areas where privacy may be a
concern.

Criminal Research Products
206-218 East Hector Street
Conshocken,PA 19428

Investigative equipment and electronic surveillance items.

Ross Engineering Associates
68 Vestry Street
New York,NY 10013

Surveillance items

Edmund Scientific CO.
101 E. Gloucester Pike
Barrington, NJ 08007

Catalog of gadgets and devices including items which are useful to the
surveillance craft.

Diptronics
P.O. BOX 80
Lake Hiawatha, NJ 07034

Microwave TV Systems
Catalog costs $3

Garrison
P.O. BOX 128
Kew Gardens, NY 11415

Locksmithing tools and electronic security gadgets.
Catalog costs $2.

Bnf Enterprises
P.O. BOX 3357
Peabody, MA 01960

General electronics supplier.

Mouser Electronics
11433 Woodside avenue
Santee, CA 92071

Sells most electronic components parts and equipment.

Benchmark Knives
P.O. BOX 998
Gastonia, NC 28052

Call for a free catalog. (704-449-2222).

Excalibur Enterprises
P.O. BOX 266
Emmans, PA 18049

Night vision devices.
Catalog costs $5

DECO INDUSTRIES
BOX 607
Bedford Hills, NY 10157

Sells mimiture Electronic Kits

Matthews Cutlery
38450-A N. Druid Hills RD.
Decatur, GA 30033

Their catalog contains over 1000 knives and costs $1.50.

U.S. Cavalry Store
1375 N. Wilson Road
Radcliff, KY 40160

Military & paramilitary clothing & gear.
Catalog costs $3.

The Intelligence Group
1324 West Waters Avenue
Lighthouse Point, FL 33064

Sells video equipment used for investigative purposes.

Columbia Pacific University
1415 Third Street
San Rafael, CA 94901

Bachelors, Masters, and Doctorate degrees

Video & Satellite Marketeer
P.O. BOX 21026
Columbus, OH 43221

Newsletter containing video, vcr, satellite dishes, etc.

Santa Fe Distributors
14400 W. 97'TH Terrace
Lenexa, KS 66215

Radar detectors and microwave tv systems.
(913-492-8288)


Alumni Arts
BOX 553
Grant's Pass, OR 97526

Reproductions of college diplomas.
Catalog costs $3

Merrell Scientific CO.
1665 Buffalo Road
Rochester, NY 14624

Chemical suppliers
Catalog costs $3.

K Products
P.O. BOX 27507
San Antonio, TX 78227

I.D. Documents.
Catalog costs $1.

City News Service
P.O. BOX 86
Willow Springs, MO 65793

Press I.D. cards.
Catalog costs $3.

Matthews Police Supply CO.
P.O. BOX 1754
Matthews, NC 28105

Brass knuckles etc.

Taylor
P.O. BOX 15391
W. Palm Beach, FL 33416

Drivers license, student I.D. cards, etc.

Capri Electronics
ROUTE 1
Canon, GA 30250

Scanner accessories

Liberty Industries
BOX 279  RD 4
Quakertown, PA 18951

Pyrotechnic components
Catalog costs $1

DE VOE
P.O. BOX 32
BERLIN  PA  15530

Sells information on making electronic detonators.

Scanner World USA
10 New Scotland Avenue
Albany, NY 12208

Cheap scanner receivers.

H & W
P.O. BOX 4
Whitehall, PA 18052

Human Skulls, arms, legs, etc.
A complete list is available for $1 and Self Addressed Stamped Envelope.


Abbie-Yo Yo Inc.
P.O. Box 15
Worcester MA 01613

This is an old address that I could not verify but, they used to sell the book
"Steal This Book".



For most of these catalogs you could probably play dumb and just send them a
letter asking for a catalog or brochure without paying a cent.  Pretending not
to know that their catalogs cost anything.


M I S C E L L A N E O U S     R E P O R T S   &   P A P E R S

Crime & Puzzlement by John Perry Barlow

The Baudy World of the Byte Bandit  A Postmodernist Interpretation of the
Computer Underground by Gordon Meyer & Jim Thomas

Concerning Hackers Who Break into Computer Systems by Dorothy E. Denning

The Social Organization of the Computer Underground by Gordon R. Meyer

Computer Security  "Virus Highlights Need for Improved Internet Management"
                   By the United States General Accounting Office.  GAO/IMTEC-
                   89-57
                   Call 202-275-6241 for up to 5 free copies.

N E T W O R K     D I G E S T S

Telecom Digest
        Moderator:  Patrick Townson
        Network Address:  telecom@eecs.nwu.edu

Risks Digest
        Moderator: Peter G. Neumann
        Network Address:  Risks@csl.sri.com


Virus-l Digest
        Moderator:  Kenneth R. Van Wyk
        Network Address:  krvw@cert.sei.cmu.edu

Telecom Privacy Digest
        Moderator:  Dennis G. Rears
        Network Address: telecom-priv@pica.army.mil

EFF News  Electronic Frontier Foundation
        Network Address:  effnews@eff.org
        Other Address:  155 Second Street  Cambridge, MA 02141
        Phone:  617-864-0665


Computer Underground Digest
        Moderators: Jim Thomas & Gordon Meyer
        Network Address:  tk0jut2@niu

F T P   S I T E S  C O N T A I N I N G    C  U   M A T E R I A L


192.55.239.132
128.95.136.2
128.237.253.5
130.160.20.80
130.18.64.2
128.214.5.6  "MARS Bulletin Board" Login "bbs"
128.82.8.1
128.32.152.11
128.135.12.60

All of the above accept anonymous logins!

B U L L E T I N     B O A R D S

Ripco              312-528-5020
Face-2-Face        713-242-6853
Rune Stone         203-485-0088    Home of NIA
The Works          617-861-8976
The Well           415-332-6106
Blitzkrieg         502-499-8933    Home of TAP
Uncensored         914-761-6877
Manta Lair         206-454-0075    Home of Cybertek


I N D I V I D U A L    N E T W O R K   A D D R E S S E S

Aristotle                   Former Editor of TAP Magazine
                            uk05744@ukpr.uky.edu or uk05744@ukpr.bitnet

Dorthy Denning              Author of "Concerning Hackers Who Break into
                            Computer Systems"
                            denning@src.dec.com

Clifford Stoll              Author of "Cookoo's Egg"
                            cliff@cfa.harvard.edu

Craig Neidorf               Former Editor of Phrack Magazine
                            c483307@umcvmb.missouri.edu

Ground Zero                 Editor of ATI Inc.
                            gzero@tronsbox.xei.com


M I S C    S O F T W A R E

SPAudit  Self-Audit-Kit
1101 Connecticut Avenue
Northwest Suite 901
Washington DC 20036
Phone 202-452-1600
Fax   202-223-8756

Free!!!


I would like to thank everyone who gave me permission to use their information
in this file.

The information provided here is for informational purposes only.  What you
choose to do with it is your responsibility and no one else's.  That means not
me, and not the BBS you downloaded this from!

To my knowledge this is the most comprehensive and upto date list of
underground books, catalogs, magazines, electronic newsletters, and network
addresses available.  If there are any additions or corrections to this list
please contact me via the Ripco BBS.



                                The Butler...

An Introduction into TeleScan


INTRODUCTION

 Whats all the hoopla? Well I've been trying to find a good ANI demo ever
 since IIRG's went down at the first of the year [800-852-9932]. Well I
 finally got one from The Mortician. Here it is...     8 0 0 . 7 7 5 . 5 5 1 3




        This is an ANI demo provided by a security company called TEL-SCAN(tm). Now
 ANI is cool and useful and everything, but it isn't hardly worthy of one of
 my wonderful headers. But see, theres more at stake here. Call the demo and
 get the ANI info and all that, and if you're a lamer stop there. But if
 you're kK00l enough, stay on the line and find out more about TEL-SCAN(tm),
 the company providing the demo.
THE TEL-SCAN(tm) NETWORK
 TEL-SCAN(tm) is a Colorado based Security service that offers an improvised
 skip-tracing method to Private Investigators, (or anyone with money and a
 good MO). How it works is this: subscribers are provided with an 800
 "Identifier Line" which when called automatically identifies the incoming
 number and records it into a corresponding Voice Mail Box. The subscriber can
 then call the Mail Box and it will relay to him all incoming calls to the
 "Identifier Line". 2-o0 pH_ukYn /<eW/! The possibilities with ANI and VMBs at
 hand are endless!!!
 TEL-SCAN(tm) can be used as such: Get a bunch of business cards printed with
 the "Identifier Line" printed as your phone number. If you're looking for
 someone, leave your card around places where they're likely to get it. When
 they call, you've got the number they're calling from and possibly an
 important lead. Viola! Skip-Tracing improvised. No this of course is
 constitutes intended use. As far as underground use goes...well...you know.
TEL-SCAN(tm) GEOGRAPHICALS
 For more information on TEL-SCAN(tm) write or call::
                    TEL-SCAN(tm)
                    2641 North Taft
                    Loveland, CO  80538
                    Number: 303.663.1703
                       FAX: 303.663.1708
 By the way when you call, you will be asked where you heard about TEL-
 SCAN(tm). DO NOT say you heard it from me (duh)! Have a good one ready
 because they will hang up on you if they think something is funny.
TEL-SCAN(tm) PRICES
 This service has a one time activation fee of $67.00 dollars. Thereafter you
 are charged $5.00 dollars everytime the service identifies a number for you.
 You are billed monthly if applicable, but there are no mandatory monthly
 fees. Now here's the good part: you can subscribe to the service via FAXed
 licensing agreement at which time you will IMMEDIATLEY be issued a Mail Box
 and a "Line Identifier". They will bill you later for the activation fee. Not
 to shabby huh?
OUTRODUCTION
 Well thats it, and thanks again to The Mortician at Lies, Hate, and Deception
 (LHD·) for this one. 

1/31/2013

All about ftp must read


 Setting Up A Ftp:


Well, since many of us have always wondered this, here it is. Long and drawn out. Also, before attempting this, realize one thing; You will have to give up your time, effort, bandwidth, and security to have a quality ftp server.
That being said, here it goes. First of all, find out if your IP (Internet Protocol) is static (not changing) or dynamic (changes everytime you log on). To do this, first consider the fact if you have a dial up modem. If you do, chances are about 999 999 out of 1 000 000 that your IP is dynamic. To make it static, just go to a place like h*tp://www.myftp.org/ to register for a static ip address.

You'll then need to get your IP. This can be done by doing this:
Going to Start -> Run -> winipcfg or www.ask.com and asking 'What is my IP?'

After doing so, you'll need to download an FTP server client. Personally, I'd recommend G6 FTP Server, Serv-U FTPor Bullitproof v2.15 all three of which are extremely reliable, and the norm of the ftp world.
You can download them on this site: h*tp://www.liaokai.com/softw_en/d_index.htm

First, you'll have to set up your ftp. For this guide, I will use step-by-step instructions for G6. First, you'll have to go into 'Setup -> General'. From here, type in your port # (default is 21). I recommend something unique, or something a bit larger (ex: 3069). If you want to, check the number of max users (this sets the amount of simultaneous maximum users on your server at once performing actions - The more on at once, the slower the connection and vice versa).

The below options are then chooseable:
-Launch with windows
-Activate FTP Server on Start-up
-Put into tray on startup
-Allow multiple instances
-Show "Loading..." status at startup
-Scan drive(s) at startup
-Confirm exit

You can do what you want with these, as they are pretty self explanatory. The scan drive feature is nice, as is the 2nd and the last option. From here, click the 'options' text on the left column.

To protect your server, you should check 'login check' and 'password check', 'Show relative path (a must!)', and any other options you feel you'll need. After doing so, click the 'advanced' text in the left column. You should then leave the buffer size on the default (unless of course you know what you're doing ), and then allow the type of ftp you want.

Uploading and downloading is usually good, but it's up to you if you want to allow uploads and/or downloads. For the server priority, that will determine how much conventional memory will be used and how much 'effort' will go into making your server run smoothly.

Anti-hammering is also good, as it prevents people from slowing down your speed. From here, click 'Log Options' from the left column. If you would like to see and record every single command and clutter up your screen, leave the defaults.

But, if you would like to see what is going on with the lowest possible space taken, click 'Screen' in the top column. You should then check off 'Log successful logins', and all of the options in the client directry, except 'Log directory changes'. After doing so, click 'Ok' in the bottom left corner.

You will then have to go into 'Setup -> User Accounts' (or ctrl & u). From here, you should click on the right most column, and right click. Choose 'Add', and choose the username(s) you would like people to have access to.

After giving a name (ex: themoonlanding), you will have to give them a set password in the bottom column (ex: wasfaked). For the 'Home IP' directory, (if you registered with a static server, check 'All IP Homes'. If your IP is static by default, choose your IP from the list. You will then have to right click in the very center column, and choose 'Add'.

From here, you will have to set the directory you want the people to have access to. After choosing the directory, I suggest you choose the options 'Read', 'List', and 'Subdirs', unless of course you know what you're doing . After doing so, make an 'upload' folder in the directory, and choose to 'add' this folder seperately to the center column. Choose 'write', 'append', 'make', 'list', and 'subdirs'. This will allow them to upload only to specific folders (your upload folder).

Now click on 'Miscellaneous' from the left column. Choose 'enable account', your time-out (how long it takes for people to remain idle before you automatically kick them off), the maximum number of users for this name, the maximum number of connections allowed simultaneously for one ip address, show relative path (a must!), and any other things at the bottom you'd like to have. Now click 'Ok'.
**Requested**


From this main menu, click the little boxing glove icon in the top corner, and right click and unchoose the hit-o-meter for both uploads and downloads (with this you can monitor IP activity). Now click the lightning bolt, and your server is now up and running.

Post your ftp info, like this:

213.10.93.141 (or something else, such as: 'f*p://example.getmyip.com')

User: *** (The username of the client)

Pass: *** (The password)

Port: *** (The port number you chose)

So make a FTP and join the FTP section


Listing The Contents Of A Ftp:

Listing the content of a FTP is very simple.
You will need FTP Content Maker, which can be downloaded from here:
ht*p://www.etplanet.com/download/application/FTP%20Content%20Maker%201.02.zip

1. Put in the IP of the server. Do not put "ftp://" or a "/" because it will not work if you do so.
2. Put in the port. If the port is the default number, 21, you do not have to enter it.
3. Put in the username and password in the appropriate fields. If the login is anonymous, you do not have to enter it.
4. If you want to list a specific directory of the FTP, place it in the directory field. Otherwise, do not enter anything in the directory field.
5. Click "Take the List!"
6. After the list has been taken, click the UBB output tab, and copy and paste to wherever you want it.


If FTP Content Maker is not working, it is probably because the server does not utilize Serv-U Software.

If you get this error message:
StatusCode = 550
LastResponse was : 'Unable to open local file test-ftp'
Error = 550 (Unable to open local file test-ftp)
Error = Unable to open local file test-ftp = 550
Close and restart FTP Content Maker, then try again.




error messages:

110 Restart marker reply. In this case, the text is exact and not left to the particular implementation; it must read: MARK yyyy = mmmm Where yyyy is User-process data stream marker, and mmmm server's equivalent marker (note the spaces between markers and "=").
120 Service ready in nnn minutes.
125 Data connection already open; transfer starting.
150 File status okay; about to open data connection.
200 Command okay.
202 Command not implemented, superfluous at this site.
211 System status, or system help reply.
212 Directory status.
213 File status.
214 Help message. On how to use the server or the meaning of a particular non-standard command. This reply is useful only to the human user.
215 NAME system type. Where NAME is an official system name from the list in the Assigned Numbers document.
220 Service ready for new user.
221 Service closing control connection. Logged out if appropriate.
225 Data connection open; no transfer in progress.
226 Closing data connection. Requested file action successful (for example, file transfer or file abort).
227 Entering Passive Mode (h1,h2,h3,h4,p1,p2).
230 User logged in, proceed.
250 Requested file action okay, completed.
257 "PATHNAME" created.
331 User name okay, need password.
332 Need account for login.
350 Requested file action pending further information.
421 Too many users logged to the same account
425 Can't open data connection.
426 Connection closed; transfer aborted.
450 Requested file action not taken. File unavailable (e.g., file busy).
451 Requested action aborted: local error in processing.
452 Requested action not taken. Insufficient storage space in system.
500 Syntax error, command unrecognized. This may include errors such as command line too long.
501 Syntax error in parameters or arguments.
502 Command not implemented.
503 Bad sequence of commands.
504 Command not implemented for that parameter.
530 Not logged in.
532 Need account for storing files.
550 Requested action not taken. File unavailable (e.g., file not found, no access).
551 Requested action aborted: page type unknown.
552 Requested file action aborted. Exceeded storage allocation (for current directory or dataset).
553 Requested action not taken. File name not allowed.


 Active FTP vs. Passive FTP, a Definitive Explanation

Introduction
One of the most commonly seen questions when dealing with firewalls and other Internet connectivity issues is the difference between active and passive FTP and how best to support either or both of them. Hopefully the following text will help to clear up some of the confusion over how to support FTP in a firewalled environment.

This may not be the definitive explanation, as the title claims, however, I've heard enough good feedback and seen this document linked in enough places to know that quite a few people have found it to be useful. I am always looking for ways to improve things though, and if you find something that is not quite clear or needs more explanation, please let me know! Recent additions to this document include the examples of both active and passive command line FTP sessions. These session examples should help make things a bit clearer. They also provide a nice picture into what goes on behind the scenes during an FTP session. Now, on to the information...



The Basics
FTP is a TCP based service exclusively. There is no UDP component to FTP. FTP is an unusual service in that it utilizes two ports, a 'data' port and a 'command' port (also known as the control port). Traditionally these are port 21 for the command port and port 20 for the data port. The confusion begins however, when we find that depending on the mode, the data port is not always on port 20.



Active FTP
In active mode FTP the client connects from a random unprivileged port (N > 1024) to the FTP server's command port, port 21. Then, the client starts listening to port N+1 and sends the FTP command PORT N+1 to the FTP server. The server will then connect back to the client's specified data port from its local data port, which is port 20.

From the server-side firewall's standpoint, to support active mode FTP the following communication channels need to be opened:

FTP server's port 21 from anywhere (Client initiates connection)
FTP server's port 21 to ports > 1024 (Server responds to client's control port)
FTP server's port 20 to ports > 1024 (Server initiates data connection to client's data port)
FTP server's port 20 from ports > 1024 (Client sends ACKs to server's data port)


In step 1, the client's command port contacts the server's command port and sends the command PORT 1027. The server then sends an ACK back to the client's command port in step 2. In step 3 the server initiates a connection on its local data port to the data port the client specified earlier. Finally, the client sends an ACK back as shown in step 4.

The main problem with active mode FTP actually falls on the client side. The FTP client doesn't make the actual connection to the data port of the server--it simply tells the server what port it is listening on and the server connects back to the specified port on the client. From the client side firewall this appears to be an outside system initiating a connection to an internal client--something that is usually blocked.



Active FTP Example
Below is an actual example of an active FTP session. The only things that have been changed are the server names, IP addresses, and user names. In this example an FTP session is initiated from testbox1.slacksite.com (192.168.150.80), a linux box running the standard FTP command line client, to testbox2.slacksite.com (192.168.150.90), a linux box running ProFTPd 1.2.2RC2. The debugging (-d) flag is used with the FTP client to show what is going on behind the scenes. Everything in red is the debugging output which shows the actual FTP commands being sent to the server and the responses generated from those commands. Normal server output is shown in black, and user input is in bold.

There are a few interesting things to consider about this dialog. Notice that when the PORT command is issued, it specifies a port on the client (192.168.150.80) system, rather than the server. We will see the opposite behavior when we use passive FTP. While we are on the subject, a quick note about the format of the PORT command. As you can see in the example below it is formatted as a series of six numbers separated by commas. The first four octets are the IP address while the second two octets comprise the port that will be used for the data connection. To find the actual port multiply the fifth octet by 256 and then add the sixth octet to the total. Thus in the example below the port number is ( (14*256) + 178), or 3762. A quick check with netstat should confirm this information.

testbox1: {/home/p-t/slacker/public_html} % ftp -d testbox2
Connected to testbox2.slacksite.com.
220 testbox2.slacksite.com FTP server ready.
Name (testbox2:slacker): slacker
---> USER slacker
331 Password required for slacker.
Password: TmpPass
---> PASS XXXX
230 User slacker logged in.
---> SYST
215 UNIX Type: L8
Remote system type is UNIX.
Using binary mode to transfer files.
ftp> ls
ftp: setsockopt (ignored): Permission denied
---> PORT 192,168,150,80,14,178
200 PORT command successful.
---> LIST
150 Opening ASCII mode data connection for file list.
drwx------ 3 slacker users 104 Jul 27 01:45 public_html
226 Transfer complete.
ftp> quit
---> QUIT
221 Goodbye.


Passive FTP
In order to resolve the issue of the server initiating the connection to the client a different method for FTP connections was developed. This was known as passive mode, or PASV, after the command used by the client to tell the server it is in passive mode.

In passive mode FTP the client initiates both connections to the server, solving the problem of firewalls filtering the incoming data port connection to the client from the server. When opening an FTP connection, the client opens two random unprivileged ports locally (N > 1024 and N+1). The first port contacts the server on port 21, but instead of then issuing a PORT command and allowing the server to connect back to its data port, the client will issue the PASV command. The result of this is that the server then opens a random unprivileged port (P > 1024) and sends the PORT P command back to the client. The client then initiates the connection from port N+1 to port P on the server to transfer data.

From the server-side firewall's standpoint, to support passive mode FTP the following communication channels need to be opened:

FTP server's port 21 from anywhere (Client initiates connection)
FTP server's port 21 to ports > 1024 (Server responds to client's control port)
FTP server's ports > 1024 from anywhere (Client initiates data connection to random port specified by server)
FTP server's ports > 1024 to remote ports > 1024 (Server sends ACKs (and data) to client's data port)



In step 1, the client contacts the server on the command port and issues the PASV command. The server then replies in step 2 with PORT 2024, telling the client which port it is listening to for the data connection. In step 3 the client then initiates the data connection from its data port to the specified server data port. Finally, the server sends back an ACK in step 4 to the client's data port.

While passive mode FTP solves many of the problems from the client side, it opens up a whole range of problems on the server side. The biggest issue is the need to allow any remote connection to high numbered ports on the server. Fortunately, many FTP daemons, including the popular WU-FTPD allow the administrator to specify a range of ports which the FTP server will use. See Appendix 1 for more information.

The second issue involves supporting and troubleshooting clients which do (or do not) support passive mode. As an example, the command line FTP utility provided with Solaris does not support passive mode, necessitating a third-party FTP client, such as ncftp.

With the massive popularity of the World Wide Web, many people prefer to use their web browser as an FTP client. Most browsers only support passive mode when accessing ftp:// URLs. This can either be good or bad depending on what the servers and firewalls are configured to support.



Passive FTP Example
Below is an actual example of a passive FTP session. The only things that have been changed are the server names, IP addresses, and user names. In this example an FTP session is initiated from testbox1.slacksite.com (192.168.150.80), a linux box running the standard FTP command line client, to testbox2.slacksite.com (192.168.150.90), a linux box running ProFTPd 1.2.2RC2. The debugging (-d) flag is used with the FTP client to show what is going on behind the scenes. Everything in red is the debugging output which shows the actual FTP commands being sent to the server and the responses generated from those commands. Normal server output is shown in black, and user input is in bold.

Notice the difference in the PORT command in this example as opposed to the active FTP example. Here, we see a port being opened on the server (192.168.150.90) system, rather than the client. See the discussion about the format of the PORT command above, in the Active FTP Example section.

testbox1: {/home/p-t/slacker/public_html} % ftp -d testbox2
Connected to testbox2.slacksite.com.
220 testbox2.slacksite.com FTP server ready.
Name (testbox2:slacker): slacker
---> USER slacker
331 Password required for slacker.
Password: TmpPass
---> PASS XXXX
230 User slacker logged in.
---> SYST
215 UNIX Type: L8
Remote system type is UNIX.
Using binary mode to transfer files.
ftp> passive
Passive mode on.
ftp> ls
ftp: setsockopt (ignored): Permission denied
---> PASV
227 Entering Passive Mode (192,168,150,90,195,149).
---> LIST
150 Opening ASCII mode data connection for file list
drwx------ 3 slacker users 104 Jul 27 01:45 public_html
226 Transfer complete.
ftp> quit
---> QUIT
221 Goodbye.


Summary
The following chart should help admins remember how each FTP mode works:

Active FTP :
command : client >1024 -> server 21
data : client >1024 <- server 20

Passive FTP :
command : client >1024 -> server 21
data : client >1024 -> server >1024

A quick summary of the pros and cons of active vs. passive FTP is also in order:

Active FTP is beneficial to the FTP server admin, but detrimental to the client side admin. The FTP server attempts to make connections to random high ports on the client, which would almost certainly be blocked by a firewall on the client side. Passive FTP is beneficial to the client, but detrimental to the FTP server admin. The client will make both connections to the server, but one of them will be to a random high port, which would almost certainly be blocked by a firewall on the server side.

Luckily, there is somewhat of a compromise. Since admins running FTP servers will need to make their servers accessible to the greatest number of clients, they will almost certainly need to support passive FTP. The exposure of high level ports on the server can be minimized by specifying a limited port range for the FTP server to use. Thus, everything except for this range of ports can be firewalled on the server side. While this doesn't eliminate all risk to the server, it decreases it tremendously.

Advanced Shellcoding Techniques


  ***********************************************
     *                                             *
     * Advanced Shellcoding Techniques - by Darawk *
     *                                             *
     ***********************************************

Introduction

This paper assumes a working knowledge of basic shellcoding techniques, and x86 assembly, I will not rehash these in this paper.  I hope to teach you some of the lesser known shellcoding techniques that I have picked up, which will allow you to write smaller and better shellcodes.  I do not claim to have invented any of these techniques, except for the one that uses the div instruction.



The multiplicity of mul

This technique was originally developed by Sorbo of darkircop.net.  The mul instruction may, on the surface, seem mundane, and it's purpose obvious.  However, when faced with the difficult challenge of shrinking your shellcode, it proves to be quite useful.  First some background information on the mul instruction itself.

mul performs an unsigned multiply of two integers.  It takes only one operand, the other is implicitly specified by the %eax register.  So, a  common mul instruction might look something like this:

movl $0x0a,%eax
mul $0x0a

This would multiply the value stored in %eax by the operand of mul, which in this case would be 10*10.  The result is then implicitly stored in EDX:EAX.  The result is stored over a span of two registers because it has the potential to be considerably larger than the previous value, possibly exceeding the capacity of a single register(this is also how floating points are stored in some cases, as an interesting sidenote).

So, now comes the ever-important question.  How can we use these attributes to our advantage when writing shellcode?  Well, let's think for a second, the instruction takes only one operand, therefore, since it is a very common instruction, it will generate only two bytes in our final shellcode.  It multiplies whatever is passed to it by the value stored in %eax, and stores the value in both %edx and %eax, completely overwriting the contents of both registers, regardless of whether it is necessary to do so, in order to store the result of the multiplication.  Let's put on our mathematician hats for a second, and consider this, what is the only possible result of a multiplication by 0?  The answer, as you may have guessed, is 0.  I think it's about time for some example code, so here it is:

xorl %ecx,%ecx
mul %ecx

What is this shellcode doing?  Well, it 0's out the %ecx register using the xor instruction, so we now know that %ecx is 0.  Then it does a mul %ecx, which as we just learned, multiplies it's operand by the value in %eax, and then proceeds to store the result of this multiplication in EDX:EAX.  So, regardless of %eax's previous contents, %eax must now be 0.  However that's not all, %edx is 0'd now too, because, even though no overflow occurs, it still overwrites the %edx register with the sign bit(left-most bit) of %eax.  Using this technique we can zero out three registers in only three bytes, whereas by any other method(that I know of) it would have taken at least six.


The div instruction

Div is very similar to mul, in that it takes only one operand and implicitly divides the operand by the value in %eax.  Also like, mul it stores the result of the divide in %eax.  Again, we will require the mathematical side of our brains to figure out how we can take advantage of this instruction.  But first, let's think about what is normally stored in the %eax register.  The %eax register holds the return value of functions and/or syscalls.  Most syscalls that are used in shellcoding will return -1(on failure) or a positive value of some kind, only rarely will they return 0(though it does occur).  So, if we know that after a syscall is performed, %eax will have a non-zero value, and that  the instruction divl %eax will divide %eax by itself, and then store the result in %eax, we can say that executing the divl %eax instruction after a syscall will put the value 1 into %eax.  So...how is this applicable to shellcoding? Well, their is another important thing that %eax is used for, and that is to pass the specific syscall that you would like to call to int $0x80.  It just so happens that the syscall that corresponds to the value 1 is exit().  Now for an example:

     
xorl %ebx,%ebx
mul %ebx
push %edx
pushl   $0x3268732f
pushl   $0x6e69622f
mov %esp, %ebx
push %edx
push %ebx
mov %esp,%ecx
movb $0xb, %al  #execve() syscall, doesn't return at all unless it fails, in which case it returns -1
int $0x80

divl %eax  # -1 / -1 = 1
int $0x80

Now, we have a 3 byte exit function, where as before it was 5 bytes.  However, there is a catch, what if a syscall does return 0?  Well in the odd situation in which that could happen, you could do many different things, like inc %eax, dec %eax, not %eax anything that will make %eax non-zero.  Some people say that exit's are not important in shellcode, because your code gets executed regardless of whether or not it exits cleanly.  They are right too, if you really need to save 3 bytes to fit your shellcode in somewhere, the exit() isn't worth keeping.  However, when your code does finish, it will try to execute whatever was after your last instruction, which will most likely produce a SIG ILL(illegal instruction) which is a rather odd error, and will be logged by the system.  So, an exit() simply adds an extra layer of stealth to your exploit, so that even if it fails or you can't wipe all the logs, at least this part of your presence will be clear.



Unlocking the power of leal

The leal instruction is an often neglected instruction in shellcode, even though it is quite useful.  Consider this short piece of shellcode.

xorl %ecx,%ecx
leal 0x10(%ecx),%eax

This will load the value 17 into eax, and clear all of the extraneous bits of eax.  This occurs because the leal instruction loads a variable of the type long into it's desitination operand.  In it's normal usage, this would load the address of a variable into a register, thus creating a pointer of sorts.  However, since ecx is 0'd and 0+17=17, we load the value 17 into eax instead of any kind of actual address.  In a normal shellcode we would do something like this, to accomplish the same thing:

xorl %eax,%eax
movb $0x10,%eax

I can hear you saying, but that shellcode is a byte shorter than the leal one, and you're quite right.  However, in a real shellcode you may already have to 0 out a register like ecx(or any other register), so the xorl instruction in the leal shellcode isn't counted.  Here's an example:

xorl    %eax,%eax
xorl    %ebx,%ebx
movb    $0x17,%al
int    $0x80
     
xorl %ebx,%ebx
leal 0x17(%ebx),%al
int $0x80

Both of these shellcodes call setuid(0), but one does it in 7 bytes while the other does it in 8.  Again, I hear you saying but that's only one byte it doesn't make that much of a difference, and you're right, here it doesn't make much of a difference(except for in shellcode-size pissing contests =p), but when applied to much larger shellcodes, which have many function calls and need to do things like this frequently, it can save quite a bit of space.



Conclusion

I hope you all learned something, and will go out and apply your knowledge to create smaller and better shellcodes.  If you know who invented  the leal technique, please tell me and I will credit him/her.

Accessing the bindery files directly


Accessing the bindery files directly
Alastair Grant, Cambridge University


1. Introduction

This document describes a command for accessing the NetWare 3.x bindery
files directly, bypassing the NetWare network API calls.

It can be used for fast bindery access, bulk user management, bypassing
security restrictions, investigating problems etc.

It is quite possible to destroy the bindery completely, or to reveal
information which could be used by hackers to obtain passwords. Users
are assumed to have a basic grasp of good procedures for security and
backup.


2. Command syntax

The basic format of the command is

   bindery [options] bindery-spec action action ...


2.1 Specifying a bindery

A bindery specification takes the form

   path/.extension

E.g. SYS:SYSTEM/.SYS. The path defaults to the current directory. The
extension defaults to .OLD.

Alternatively an 'active' bindery can be specified:

   SERVER server

The bindery will be closed if necessary.


2.2 Actions on the bindery

  INFO      print info about the bindery
  SCHEMA    checks the bindery against the schema in BINDERY.SCH
  DUMP obj  dump all information for the specified object(s)
  OBJ       list all object records
  PROP      list all property records
  VAL       list all value records
  VALDATA   list all value records, with data
  EXPORT    export the bindery to a text file; see below
  IMPORT    import the bindery from a text file
  ETC       export user password information, suitable for input to the
            password-cracking program described below

The following actions apply only if a bindery has been specified by the
SERVER parameter:
  CLOSE     close the bindery, i.e. make it available for direct access;
            users attempting to access the bindery via NetWare API calls
            will receive an error
  OPEN      open the bindery, which causes the server to reload it and
            may take some time for large binderies
  COPY directory
            copy the bindery files into a directory elsewhere


3. Export/import

The bindery can be exported to and imported from a text file. This can
be used for various purposes:

 -   problem diagnosis and repair

 -   creation of large binderies given a set of user information

 -   compaction of binderies

 -   merging binderies or moving users between binderies while
     preserving their passwords

To see the format of the export file, try exporting a small bindery.


4. Password cracking

Passwords are not stored in clear in the bindery. What is stored is a
16-byte value computed via a one-way function from the user's object id
and the password. Given the object id and password it is possible to
generate a candidate password which can be compared against that in the
bindery.

The ETC option of the BINDERY command produces a file containing the
required information, in a format superficially similar to /etc/passwd
on Unix:

   userid:pw-hash:object-id:pw-len:name::

e.g.

   ttidy:32d8998e098a05830f809b809ea02137:D0000001:8:Terry Tidy

This can then be input into bindery cracking programs. Separating the
functions in this way allows various forms of parallelism:

 -   the password file can be split into smaller chunks

 -   the same password file can be worked on by several cracking
     programs each with different dictionaries or algorithms

 -   cracking programs can be run on faster machines

A cracking program BINCRACK is provided which takes such a file as
input. It has command syntax:

   bincrack [/verify] [/numsub] pw-file dict-file

/verify lists the passwords that are being tried. /numsub tries
substituting numbers for letters, e.g. "1D10T". This takes a lot longer
as all possible combinations are tried. pw-file is an exported bindery
password file. dict-file is a simple word list.

Versions are available for MS-DOS and for Solaris 1 and Solaris 2 SPARC
systems.

Suitable wordlists can be found at

   ftp://ftp.ox.ac.uk/pub/wordlists/

A Web Standards Checklist, How to make a proper website


A Web Standards Checklist, How to make a proper website

A web standards checklist

The term web standards can mean different things to different people. For some, it is 'table-free sites', for others it is 'using valid code'. However, web standards are much broader than that. A site built to web standards should adhere to standards (HTML, XHTML, XML, CSS, XSLT, DOM, MathML, SVG etc) and pursue best practices (valid code, accessible code, semantically correct code, user-friendly URLs etc).

In other words, a site built to web standards should ideally be lean, clean, CSS-based, accessible, usable and search engine friendly.

About the checklist

This is not an uber-checklist. There are probably many items that could be added. More importantly, it should not be seen as a list of items that must be addressed on every site that you develop. It is simply a guide that can be used:

* to show the breadth of web standards
* as a handy tool for developers during the production phase of websites
* as an aid for developers who are interested in moving towards web standards

The checklist

1.Quality of code
1. Does the site use a correct Doctype?
2. Does the site use a Character set?
3. Does the site use Valid (X)HTML?
4. Does the site use Valid CSS?
5. Does the site use any CSS hacks?
6. Does the site use unnecessary classes or ids?
7. Is the code well structured?
8. Does the site have any broken links?
9. How does the site perform in terms of speed/page size?
10. Does the site have JavaScript errors?

2. Degree of separation between content and presentation
1. Does the site use CSS for all presentation aspects (fonts, colour, padding, borders etc)?
2. Are all decorative images in the CSS, or do they appear in the (X)HTML?

3. Accessibility for users
1. Are "alt" attributes used for all descriptive images?
2. Does the site use relative units rather than absolute units for text size?
3. Do any aspects of the layout break if font size is increased?
4. Does the site use visible skip menus?
5. Does the site use accessible forms?
6. Does the site use accessible tables?
7. Is there sufficient colour brightness/contrasts?
8. Is colour alone used for critical information?
9. Is there delayed responsiveness for dropdown menus (for users with reduced motor skills)?
10. Are all links descriptive (for blind users)?

4. Accessibility for devices
1. Does the site work acceptably across modern and older browsers?
2. Is the content accessible with CSS switched off or not supported?
3. Is the content accessible with images switched off or not supported?
4. Does the site work in text browsers such as Lynx?
5. Does the site work well when printed?
6. Does the site work well in Hand Held devices?
7. Does the site include detailed metadata?
8. Does the site work well in a range of browser window sizes?

5. Basic Usability
1. Is there a clear visual hierarchy?
2. Are heading levels easy to distinguish?
3. Does the site have easy to understand navigation?
4. Does the site use consistent navigation?
5. Are links underlined?
6. Does the site use consistent and appropriate language?
7. Do you have a sitemap page and contact page? Are they easy to find?
8. For large sites, is there a search tool?
9. Is there a link to the home page on every page in the site?
10. Are visited links clearly defined with a unique colour?

6. Site management
1. Does the site have a meaningful and helpful 404 error page that works from any depth in the site?
2. Does the site use friendly URLs?
3. Do your URLs work without "www"?
4. Does the site have a favicon?

1. Quality of code

1.1 Does the site use a correct Doctype?
A doctype (short for 'document type declaration') informs the validator which version of (X)HTML you're using, and must appear at the very top of every web page. Doctypes are a key component of compliant web pages: your markup and CSS won't validate without them.
CODE
http://www.alistapart.com/articles/doctype/


More:
CODE
http://www.w3.org/QA/2002/04/valid-dtd-list.html

CODE
http://css.maxdesign.com.au/listamatic/about-boxmodel.htm

CODE
http://gutfeldt.ch/matthias/articles/doctypeswitch.html


1.2 Does the site use a Character set?
If a user agent (eg. a browser) is unable to detect the character encoding used in a Web document, the user may be presented with unreadable text. This information is particularly important for those maintaining and extending a multilingual site, but declaring the character encoding of the document is important for anyone producing XHTML/HTML or CSS.
CODE
http://www.w3.org/International/tutorials/tutorial-char-enc/


More:
CODE
http://www.w3.org/International/O-charset.html


1.3 Does the site use Valid (X)HTML?
Valid code will render faster than code with errors. Valid code will render better than invalid code. Browsers are becoming more standards compliant, and it is becoming increasingly necessary to write valid and standards compliant HTML.
CODE
http://www.maxdesign.com.au/presentation/sit2003/06.htm


More:
CODE
http://validator.w3.org/


1.4 Does the site use Valid CSS?
You need to make sure that there aren't any errors in either your HTML or your CSS, since mistakes in either place can result in botched document appearance.
CODE
http://www.meyerweb.com/eric/articles/webrev/199904.html


More:
CODE
http://jigsaw.w3.org/css-validator/


1.5 Does the site use any CSS hacks?
Basically, hacks come down to personal choice, the amount of knowledge you have of workarounds, the specific design you are trying to achieve.
CODE
http://www.mail-archive.com/wsg@webstandardsgroup.org/msg05823.html


More:
CODE
http://css-discuss.incutio.com/?page=CssHack

CODE
http://css-discuss.incutio.com/?page=ToHackOrNotToHack

CODE
http://centricle.com/ref/css/filters/


1.6 Does the site use unnecessary classes or ids?
I've noticed that developers learning new skills often end up with good CSS but poor XHTML. Specifically, the HTML code tends to be full of unnecessary divs and ids. This results in fairly meaningless HTML and bloated style sheets.
CODE
http://www.clagnut.com/blog/228/


1.7 Is the code well structured?
Semantically correct markup uses html elements for their given purpose. Well structured HTML has semantic meaning for a wide range of user agents (browsers without style sheets, text browsers, PDAs, search engines etc.)
CODE
http://www.maxdesign.com.au/presentation/benefits/index04.htm


More:
CODE
http://www.w3.org/2003/12/semantic-extractor.html


1.8 Does the site have any broken links?
Broken links can frustrate users and potentially drive customers away. Broken links can also keep search engines from properly indexing your site.

More:
CODE
http://validator.w3.org/checklink


1.9 How does the site perform in terms of speed/page size?
Don't make me wait... That's the message users give us in survey after survey. Even broadband users can suffer the slow-loading blues.
CODE
http://www.websiteoptimization.com/speed/


1.10 Does the site have JavaScript errors?
Internet Explore for Windows allows you to turn on a debugger that will pop up a new window and let you know there are javascript errors on your site. This is available under 'Internet Options' on the Advanced tab. Uncheck 'Disable script debugging'.

2. Degree of separation between content and presentation

2.1 Does the site use CSS for all presentation aspects (fonts, colour, padding, borders etc)?
Use style sheets to control layout and presentation.
CODE
http://www.w3.org/TR/WCAG10/wai-pageauth.html#tech-style-sheets


2.2 Are all decorative images in the CSS, or do they appear in the (X)HTML?
The aim for web developers is to remove all presentation from the html code, leaving it clean and semantically correct.
CODE
http://www.maxdesign.com.au/presentation/benefits/index07.htm


3. Accessibility for users

3.1 Are "alt" attributes used for all descriptive images?
Provide a text equivalent for every non-text element
CODE
http://www.w3.org/TR/WCAG10/wai-pageauth.html#tech-text-equivalent


3.2 Does the site use relative units rather than absolute units for text size?
Use relative rather than absolute units in markup language attribute values and style sheet property values'.
CODE
http://www.w3.org/TR/WCAG10/wai-pageauth.html#tech-relative-units


More:
CODE
http://www.w3.org/TR/WCAG10/wai-pageauth.html#tech-relative-units

CODE
http://www.clagnut.com/blog/348/


3.3 Do any aspects of the layout break if font size is increased?
Try this simple test. Look at your website in a browser that supports easy incrementation of font size. Now increase your browser's font size. And again. And again... Look at your site. Does the page layout still hold together? It is dangerous for developers to assume that everyone browses using default font sizes.
3.4 Does the site use visible skip menus?

A method shall be provided that permits users to skip repetitive navigation links.
CODE
http://www.section508.gov/index.cfm?FuseAction=Content&ID=12


Group related links, identify the group (for user agents), and, until user agents do so, provide a way to bypass the group.
CODE
http://www.w3.org/TR/WCAG10-TECHS/#tech-group-links


...blind visitors are not the only ones inconvenienced by too many links in a navigation area. Recall that a mobility-impaired person with poor adaptive technology might be stuck tabbing through that morass.
CODE
http://joeclark.org/book/sashay/serialization/Chapter08.html#h4-2020


More:
CODE
http://www.niehs.nih.gov/websmith/508/o.htm


3.5 Does the site use accessible forms?
Forms aren't the easiest of things to use for people with disabilities. Navigating around a page with written content is one thing, hopping between form fields and inputting information is another.
CODE
http://www.htmldog.com/guides/htmladvanced/forms/


More:
CODE
http://www.webstandards.org/learn/tutorials/accessible-forms/01-accessible-forms.html

CODE
http://www.accessify.com/tools-and-wizards/accessible-form-builder.asp

CODE
http://accessify.com/tutorials/better-accessible-forms.asp


3.6 Does the site use accessible tables?
For data tables, identify row and column headers... For data tables that have two or more logical levels of row or column headers, use markup to associate data cells and header cells.
CODE
http://www.w3.org/TR/WCAG10/wai-pageauth.html#tech-table-headers


More:
CODE
http://www.bcc.ctc.edu/webpublishing/ada/resources/tables.asp

CODE
http://www.accessify.com/tools-and-wizards/accessible-table-builder_step1.asp

CODE
http://www.webaim.org/techniques/tables/


3.7 Is there sufficient colour brightness/contrasts?
Ensure that foreground and background colour combinations provide sufficient contrast when viewed by someone having colour deficits.
CODE
http://www.w3.org/TR/WCAG10/wai-pageauth.html#tech-colour-contrast


More:
CODE
http://www.juicystudio.com/services/colourcontrast.asp


3.8 Is colour alone used for critical information?
Ensure that all information conveyed with colour is also available without colour, for example from context or markup.
CODE
http://www.w3.org/TR/WCAG10/wai-pageauth.html#tech-colour-convey


There are basically three types of colour deficiency; Deuteranope (a form of red/green colour deficit), Protanope (another form of red/green colour deficit) and Tritanope (a blue/yellow deficit- very rare).

More:
CODE
http://colourfilter.wickline.org/

CODE
http://www.toledo-bend.com/colourblind/Ishihara.html

CODE
http://www.vischeck.com/vischeck/vischeckURL.php


3.9 Is there delayed responsiveness for dropdown menus?
Users with reduced motor skills may find dropdown menus hard to use if responsiveness is set too fast.

3.10 Are all links descriptive?
Link text should be meaningful enough to make sense when read out of context - either on its own or as part of a sequence of links. Link text should also be terse.
CODE
http://www.w3.org/TR/WCAG10/wai-pageauth.html#tech-meaningful-links


4. Accessibility for devices.

4.1 Does the site work acceptably across modern and older browsers?

Before starting to build a CSS-based layout, you should decide which browsers to support and to what level you intend to support them.
CODE
http://www.maxdesign.com.au/presentation/process/index_step01.cfm



4.2 Is the content accessible with CSS switched off or not supported?
Some people may visit your site with either a browser that does not support CSS or a browser with CSS switched off. In content is structured well, this will not be an issue.

4.3 Is the content accessible with images switched off or not supported?
Some people browse websites with images switched off - especially people on very slow connections. Content should still be accessible for these people.

4.4 Does the site work in text browsers such as Lynx?
This is like a combination of images and CSS switched off. A text-based browser will rely on well structured content to provide meaning.

More:
CODE
http://www.delorie.com/web/lynxview


4.5 Does the site work well when printed?
You can take any (X)HTML document and simply style it for print, without having to touch the markup.
CODE
http://www.alistapart.com/articles/goingtoprint/


More:
CODE
http://www.d.umn.edu/itss/support/Training/Online/webdesign/css.html#print


4.6 Does the site work well in Hand Held devices?
This is a hard one to deal with until hand held devices consistently support their correct media type. However, some layouts work better in current hand-held devices. The importance of supporting hand held devices will depend on target audiences.

4.7 Does the site include detailed metadata?
Metadata is machine understandable information for the web
CODE
http://www.w3.org/Metadata/


Metadata is structured information that is created specifically to describe another resource. In other words, metadata is 'data about data'.


4.8 Does the site work well in a range of browser window sizes?
It is a common assumption amongst developers that average screen sizes are increasing. Some developers assume that the average screen size is now 1024px wide. But what about users with smaller screens and users with hand held devices? Are they part of your target audience and are they being disadvantaged?

5. Basic Usability
5.1 Is there a clear visual hierarchy?
Organise and prioritise the contents of a page by using size, prominence and content relationships.
CODE
http://www.great-web-design-tips.com/web-site-design/165.html


5.2 Are heading levels easy to distinguish?
Use header elements to convey document structure and use them according to specification.
CODE
http://www.w3.org/TR/WCAG10/wai-pageauth.html#tech-logical-headings


5.3 Is the site's navigation easy to understand?
Your navigation system should give your visitor a clue as to what page of the site they are currently on and where they can go next.
CODE
http://www.1stsitefree.com/design_nav.htm


5.4 Is the site's navigation consistent?
If each page on your site has a consistent style of presentation, visitors will find it easier to navigate between pages and find information
CODE
http://www.juicystudio.com/tutorial/accessibility/navigation.asp


5.5 Does the site use consistent and appropriate language?
The use of clear and simple language promotes effective communication. Trying to come across as articulate can be as difficult to read as poorly written grammar, especially if the language used isn't the visitor's primary language.
CODE
http://www.juicystudio.com/tutorial/accessibility/clear.asp


5.6 Does the site have a sitemap page and contact page? Are they easy to find?
Most site maps fail to convey multiple levels of the site's information architecture. In usability tests, users often overlook site maps or can't find them. Complexity is also a problem: a map should be a map, not a navigational challenge of its own.
CODE
http://www.useit.com/alertbox/20020106.html


5.7 For large sites, is there a search tool?
While search tools are not needed on smaller sites, and some people will not ever use them, site-specific search tools allow users a choice of navigation options.

5.8 Is there a link to the home page on every page in the site?
Some users like to go back to a site's home page after navigating to content within a site. The home page becomes a base camp for these users, allowing them to regroup before exploring new content.

5.9 Are links underlined?
To maximise the perceived affordance of clickability, colour and underline the link text. Users shouldn't have to guess or scrub the page to find out where they can click.
CODE
http://www.useit.com/alertbox/20040510.html


5.10 Are visited links clearly defined?
Most important, knowing which pages they've already visited frees users from unintentionally revisiting the same pages over and over again.
CODE
http://www.useit.com/alertbox/20040503.html


6. Site management

6.1 Does the site have a meaningful and helpful 404 error page that works from any depth in the site?
You've requested a page - either by typing a URL directly into the address bar or clicking on an out-of-date link and you've found yourself in the middle of cyberspace nowhere. A user-friendly website will give you a helping hand while many others will simply do nothing, relying on the browser's built-in ability to explain what the problem is.
CODE
http://www.alistapart.com/articles/perfect404/


6.2 Does the site use friendly URLs?
Most search engines (with a few exceptions - namely Google) will not index any pages that have a question mark or other character (like an ampersand or equals sign) in the URL... what good is a site if no one can find it?
CODE
http://www.sitepoint.com/article/search-engine-friendly-urls


One of the worst elements of the web from a user interface standpoint is the URL. However, if they're short, logical, and self-correcting, URLs can be acceptably usable
CODE
http://www.merges.net/theory/20010305.html


More:
CODE
http://www.sitepoint.com/article/search-engine-friendly-urls

CODE
http://www.websitegoodies.com/article/32

CODE
http://www.merges.net/theory/20010305.html


6.3 Does the site's URL work without "www"?
While this is not critical, and in some cases is not even possible, it is always good to give people the choice of both options. If a user types your domain name without the www and gets no site, this could disadvantage both the user and you.
6.4 Does the site have a favicon?

A Favicon is a multi-resolution image included on nearly all professionally developed sites. The Favicon allows the webmaster to further promote their site, and to create a more customized appearance within a visitor's browser.
CODE
http://www.favicon.com/


Favicons are definitely not critical. However, if they are not present, they can cause 404 errors in your logs (site statistics). Browsers like IE will request them from the server when a site is bookmarked. If a favicon isn't available, a 404 error may be generated. Therefore, having a favicon could cut down on favicon specific 404 errors. The same is true of a 'robots.txt' file.