Showing posts with label hackers way. Show all posts
Showing posts with label hackers way. Show all posts

Thursday, July 8, 2010

How to see asterisks or dotted password

SeePassword v2.5 | Size: 7 MB

When a password appears on screen as a series of asterisks or dots, you simply view it through SeePassword's magnifying glass to reveal the actual password text. See-Password has no problems with passwords stored by Internet Explorer— all the sites will yield their secrets, Internet Messenger etc.. . SeePassword provides users with an easily applied retrieval tool for forgotten passwords.

Download Links :

Thursday, June 3, 2010

How To Make Money With Facebook | Facebook Hacks, Tips & Tricks

Who else wants to learn how the big boys make upwards of $300 a day on Facebook?

- Learn why 99% of people fail putting CPA offers on Facebook.
- Learn how to not get caught by the "Facebook police" - it's not what you think.
- Learn how you could be making a full time income off Facebook - in just a few days!

$300/day Method Revealed!

WHAT YOU NEED:

• A Facebook Account
• A Freelancer Account
• An Account on any CPA network

6 STEP METHOD:

1. Login to your CPA network (for example CPALead.com). Browse through all of the offers with “first page submit” short forms where you get paid per lead. The reason for this is because people are most likely to fill out a short first page form than a long 3 page submit. These offers usually payout between $2 to $5. Find offers that have good looking landing pages that are trustworthy and easy to fill out. The less personal information the user has to submit the more likely they are to fill out your offer.

2. Login to your Facebook account and create a fan page. The name of your fan page should attract the type of people who are likely to fill out your CPA offer. This is one of the most cost effective ways to target people on Facebook. REMEMBER: the name of your page is what attracts your target market. Then go to Google images and select an appropriate image for your group. Make sure to find an image that is professional looking (think stock image quality). Save this image to your desktop. Choose the appropriate category for your page, publish it, upload your image to the profile picture, and fill out the information on your “Info” tab.

3. Login to your Freelancer account and post a project for someone to “add fans” to your Facebook fan page. You’re essentially hiring a promoter or someone to do the work for you. Your title should read something like: “I need someone to add 100,000 fans to my Facebook page.” The description does not need to be too long, just copy your title and tell them to PM you if they have questions. Wait about a day or two to let the bids build up before selecting a winner. When you select the winning bidder it takes you to a screen where you can “check” the box next to each bidders name. This is a sneaky way to hire multiple people if you want to. Once the winning bidder has accepted your job, email them the link to your Facebook page along with a more in depth job description.

4. Once your page reaches 10,000+ people, Facebook will make you verify that you are the owner of the page. If you do not verify it they will block your publishing rights to the page, making this whole process a big waste of time. Here’s how to verify: Get an account at blogger.com. Post some BS blog entries. Use this new blogger domain as your official URL. Go to your Facebook page and click “Edit Page.” Under “Promote Your Page” click “Promote with a fan box” and click the Blogger icon. You will then log into your blogger account and the Facebook fan box will be present on your blog. Now your page is verified and set to go! DO NOT POST ANY CPA OFFERS BEFORE YOUR PAGE IS VERIFIED!

5. Now that you have more than 10k fans in your fan page and have verified it, you can start promoting your CPA offer. You can do this by updating the status of your group or sending out a mass message to all members. To update your status, put the text portion of your ad into the text field and copy and paste the link into the link box in the tool bar below the text field. Once your link is attached and your message is crafted, press submit. This status update will be sent to all of your fans’ mini feeds and will be available for new fans to see. Don’t forget to mix your CPA posts with normal posts that fit in with the flow of your page. You want the fans to think it’s a legit page (which it is) not a spam page. Do the same for messages.

6. Now that your page is big, create more Facebook pages and use your original page to drive traffic to those pages. Eventually you will have a large network of Facebook pages…a network that will eventually span more than 1 million people! You can now drive this traffic wherever you want! Make sure your users do not become immune to your page updates. If you’re constantly posting new updates they may get turned off. However, if one CPA offer is doing well, keep reposting it every other day (Just remove the original update from your page before you re-submit it). I recommend only a few NEW updates per week per page.

NOTE: I have not tested this method. Pls try at your own risk.
 
source:http://www.freehacking.net/2010/06/how-to-make-money-with-facebook.html


Sunday, May 30, 2010

Cracking any Windows XP and windows Vista password

Ophcrack is an open source (GPL licensed) program that cracks Windows passwords by using LM hashes through rainbow tables. The program includes the ability to import the hashes from a variety of formats, including dumping directly from the SAM files of Windows. It is claimed that these tables can crack 99.9% of alphanumeric passwords of up to 14 characters in usually a few minutes.

Rainbow tables for LM hashes of alphanumeric passwords are provided for free by the developers. Larger rainbow tables (for LM hashes of passwords with all printable characters, including symbols and space) are available for purchase from Objectif Sécurité. There is also a Live CD version which automates the retrieval, decryption, and cracking of passwords from a Windows system.

Step 1: Download ophcrack (.iso) from ophcrack. Download the live cd, not the exe.
Step 2: Download UNetbootin from http://unetbootin.sourceforge.net/

UNetbootin (Universal Netboot Installer) is a cross-platform utility that can create Live USB systems and can load a variety of system utilities or install various Linux distributions and other operating systems without a CD.

Step 3: Insert the USB flash drive from which you will boot the live OS.
              Run UNetbootin, select the 'disk image' radio button and browse to the .iso file.
              Select the drive name for the USB drive and click OK.
OR alternatively
              You can also use a CD for this purpose. To boot from CD, you do not need Unetbootin.  Just burn the .iso image to the CD.

Step 4: Reboot the system. Press F10 at startup to select the appropriate boot drive or enter BIOS by pressing 'del' and change the boot sequence. If you are stuck up here, please help yourself or wait for us until we post on it.

Step 5: Follow the simple instructions and within seconds it will crack the passwords of all the accounts on the system.

Now if you wish to crack the password of any Windows system, plug in the USB drive or insert the CD and boot from the drive.

Saturday, May 29, 2010

How To Surf Anonymously when when orkut, myspace, facebook, twitter, plurk, hi5, youtube etc is blocked

when orkut, myspace, facebook, twitter, plurk, hi5, youtube etc is blocked in your office or college or school….and you are fed up of using proxy websites and there low urfing speeds. And what worse if these proxy websites are also blocked…..phew!!!!
But no problems…..
Just download JAP & Download Ultrasurf and easily surf any blocked website with anonymity
Step 1: Download JAP or ultrasurf
Step 2: Execute Setup file [may take few minutes depending upon internet speed]
Step 3: Change you Explorer LAN connection settingsChange the default gateway IP to 127.0.0.1 and port 4001
Thats it! .. you have gained independence to free to surf any website….

Thursday, May 27, 2010

Crack WEP, WPA-2 and WPA-PSK Wi-Fi Network key

Step 1: airmon-ng

Please download Backtrack 4 from HERE

airmon-ng stop wlan0
iwconfig (to find all wireless network interfaces and their status)
airmon-ng start wlan0 (to set in monitor mode, you may have to substitute wlan0 for your own interface name)

Note: You can use the su command to switch to a root account.

Step 2: airodump-ng

This step assumes you've already set your wireless network interface in monitor mode. It can be checked by executing the iwconfig command. Next step is finding available wireless networks, and choosing your target:

airodump-ng mon0 - monitors all channels, listing available access points and associated clients within range. It is best to select a target network with strong signal (PWR column), more traffic (Beacons/Data columns) and associated clients (listed below all access points). Once you've selected a target, note its Channel and BSSID (MAC address). Also note any STATION associated with the same BSSID (client MAC addresses).


Step 3: airodump-ng (Capture data)

To capture data into a file, we use the airodump-ng tool again, with some additional switches to target a specific AP and channel. Most importantly, you should restrict monitoring to a single channel to speed up data collection, otherwise the wireless card has to alternate between all channels. Assuming our wireless card is mon0, and we want to capture packets on channel 6 into a text file called data:

airodump-ng -c 6 bssid 00:0F:CC:7D:5A:74 -w data mon0 (-c 6 switch would capture data on channel 6, bssid 00:0F:CC:7D:5A:74 is the MAC address of our target access point, -w data specifies that we want to save captured packets into a file called "data" in the current directory, mon0 is our wireless network adapter)


You typically need between 20,000 and 40,000 data packets to successfully recover a WEP key.

Step 4: aireplay-ng (Increase Traffic)

An active network can usually be penetrated within a few minutes. However, slow networks can take hours, even days to collect enough data for recovering the WEP key.

This optional step allows a compatible network interface to inject/generate packets to increase traffic on the wireless network, therefore greatly reducing the time required for capturing data. The aireplay-ng command should be executed in a separate terminal window, concurrent to airodump-ng. It requires a compatible network card and driver that allows for injection mode.

Assuming your network card is capable of injecting packets, in a separate terminal window try:

aireplay-ng -3 -b 00:0F:CC:7D:5A:74 -h 00:14:A5:2F:A7:DE -x 50 wlan0
-3 --> this specifies the type of attack, in our case ARP-request replay
-b ..... --> MAC address of access point
-h ..... --> MAC address of associated client from airodump
-x 50 --> limit to sending 50 packets per second
wlan0 --> our wireless network interface



Step 5: aircrack-ng (Crack WEP)

WEP cracking is a simple process, only requiring collection of enough data to then extract the key and connect to the network. You can crack the WEP key while capturing data. In fact, aircrack-ng will re-attempt cracking the key after every 5000 packets.

To attempt recovering the WEP key, in a new terminal window, type:

aircrack-ng data*.cap (assuming your capture file is called data...cap, and is located in the same directory)
.

Step 6: aircrack-ng

WPA, unlike WEP rotates the network key on a per-packet basis, rendering the WEP method of penetration useless. Cracking a WPA-PSK/WPA2-PSK key requires a dictionary attack on a handshake between an access point and a client. What this means is, you need to wait until a wireless client associates with the network (or deassociate an already connected client so they automatically reconnect). All that needs to be captured is the initial "four-way-handshake" association between the access point and a client. WPA hashes the network key using the wireless access point's SSID as salt. This prevents the statistical key-grabbing techniques that broke WEP, and makes hash precomputation more dificult because the specific SSID needs to be added as salt for the hash.

With all that said, the weakness of WPA-PSK comes down to the passphrase. A short/weak passphrase makes it vulnerable to dictionary attacks.

To successfully crack a WPA-PSK network, you first need a capture file containing handshake data. This can be obtained using the same technique as with WEP in step 3 above, using airodump-ng.

You may also try to deauthenticate an associated client to speed up this process of capturing a handshake, using:

aireplay-ng --deauth 3 -a MAC_AP -c MAC_Client (where MAC_IP is the MAC address of the access point, and MAC_Client is the MAC address of an associated client).

Once you have captured a four-way handshake, you also need a large/relevant dictinary file with common passphrases. See related links below for some wordlist links.

You can, then execute the following command in a linux terminal window (assuming both the dictionary file and captured data file are in the same directory):

aircrack-ng -w dictionary_file capture_file

Notes:
Cracking WPA-PSK and WPA2-PSK may take much longer, and will only succeed with weak passphrases and good dictionary files.

Alternatively, there are tools like coWPAtty that can use precomputed hash files to speed up dictionary attacks. Those hash files can be very effective, but quite big in size. The Church of WiFi has computed hash tables for the 1000 most common SSIDs against a million common passphrases that are 7Gb and 33Gb in size...

Sunday, May 23, 2010

Chained Exploits: Advanced Hacking Attacks from Start to Finish

Chained Exploits: Advanced Hacking Attacks from Start to Finish


Chained Exploits: Advanced Hacking Attacks from Start to Finish
312 pages | Addison-Wesley Professional; 1 edition (March 9, 2009) | 032149881X | CHM | 10 Mb


The complete guide to today’s hard-to-defend chained attacks: performing them and preventing them. Nowadays, it’s rare for malicious hackers to rely on just one exploit or tool; instead, they use “chained” exploits that integrate multiple forms of attack to achieve their goals. Chained exploits are far more complex and far more difficult to defend. Few security or hacking books cover them well and most don’t cover them at all. Now there’s a book that brings together start-to-finish information about today’s most widespread chained exploits–both how to perform them and how to prevent them.

Chained Exploits demonstrates this advanced hacking attack technique through detailed examples that reflect real-world attack strategies, use today’s most common attack tools, and focus on actual high-value targets, including credit card and healthcare data. Relentlessly thorough and realistic, this book covers the full spectrum of attack avenues, from wireless networks to physical access and social engineering.

Writing for security, network, and other IT professionals, the authors take you through each attack, one step at a time, and then introduce today’s most effective countermeasures— both technical and human. Coverage includes:
Constructing convincing new phishing attacks
Discovering which sites other Web users are visiting
Wreaking havoc on IT security via wireless networks
Disrupting competitors’ Web sites
Performing–and preventing–corporate espionage
Destroying secure files
Gaining access to private healthcare records
Attacking the viewers of social networking pages
Creating entirely new exploits
and more


Download Links:


1000 Best Ever Hacking Tutorials 2010

1000 Best Ever Hacking Tutorials 2010
1000 Best Ever Hacking Tutorials 2010
English | 2010 | PDF | 6.8 MB
1000 greatest hacking tutorials ever

Sunday, May 16, 2010

Ethical Hacking And Network Defense | 1.4GB | Sam Bowne CNIT-123


Students learn how hackers attack computers and networks, and how to protect systems from such attacks, using both Windows and Linux systems. Students will learn legal restrictions and ethical guidelines, and will be required to obey them. Students will perform many hands-on labs, both attacking and defending, using port scans, footprinting, exploiting Windows and Linux vulnerabilities, buffer overflow exploits, SQL injection, privilege escalation, Trojans, and backdoors.
Upon successful completion of this course, the student will be able to:
  • Explain what an ethical hacker can and can not do legally, and explain the credentials and roles of penetration testers.
  • Define the types of malicious software found in modern networks.
  • Explain the threats and countermeasures for physical security and social engineering.
  • Perform footprinting to learn about a company and its network.
  • Perform port scans to locate potential entry points to servers and networks.
  • Perform enumeration (finding resources, accounts, and passwords) on Microsoft, Netware, and Unix/Linux targets.
  • Perform very simple programming in C, HTML, and Perl, specifically oriented towards the needs of network security professionals.
  • Learn how to identify Microsoft Windows vulnerabilities and to harden systems.
  • Learn how to identify Linux vulnerabilities and to protect servers.
  • Describe how to take control of Web Servers, and how to protect them.
  • Locate and hack into wireless networks, and protect them.
  • Explain how cryptography and hashing work, and perform attacks against them such as password cracking and man-in-the-middle attacks.
  • Describe and deploy security devices, including routers, firewalls, Intrusion Detection Systems, and honeypots.

Brutus: The remote password cracker

Brutus is one of the fastest, most flexible remote password crackers you can get your hands on - it's also free. It is available for Windows 9x, NT and 2000, there is no UNIX version available although it is a possibility at some point in the future. Brutus was first made publicly available in October 1998 and since that time there have been at least 70,000 downloads and over 175,000 visitors to this page. Development continues so new releases will be available in the near future. Brutus was written originally to help me check routers etc. for default and common passwords


Features

Brutus version AET2 is the current release and includes the following authentication types :
HTTP (Basic Authentication)
HTTP (HTML Form/CGI)
POP3
FTP
SMB
Telnet
Other types such as IMAP, NNTP, NetBus etc are freely downloadable from this site and simply imported into your copy of Brutus. You can create your own types or use other peoples.

The current release includes the following functionality :
Multi-stage authentication engine
60 simultaneous target connections
No username, single username and multiple username modes
Password list, combo (user/password) list and configurable brute force modes
Highly customisable authentication sequences
Load and resume position
Import and Export custom authentication types as BAD files seamlessly
SOCKS proxy support for all authentication types
User and password list generation and manipulation functionality
HTML Form interpretation for HTML Form/CGI authentication types
Error handling and recovery capability inc. resume after crash/failure.

. . . . . . . . . . . . . . . . . . . . . . . . . . . 

How to Surf the Web Anonymously | IP Spoofing

First of all, if you are a noob you would think, why in this world should I spoof my IP. Well it's useful in a number of ways. For example, Rapidshare tracks your IP, so that if you are not a premium member you wont be allowed to download multiple files. But if you use a proxy server which dynamically changes your IP, you can download multiple files through Rapidshare. As another example, you intend to hack an organisational website which is not an easy task, you might need to visit their website quite a number of times, in this case you can spoof your IP to hide your identity. The best way to hide/change your IP while surfing is with the help of Proxy Servers.

What is a Proxy Server?
In computer networks, a proxy server is a server (a computer system or an application program) that acts as an intermediary for requests from clients seeking resources from other servers. A client connects to the proxy server, requesting some service, such as a file, connection, web page, or other resource, available from a different server. The proxy server evaluates the request according to its filtering rules. For example, it may filter traffic by IP address or protocol. If the request is validated by the filter, the proxy provides the resource by connecting to the relevant server and requesting the service on behalf of the client. A proxy server may optionally alter the client's request or the server's response, and sometimes it may serve the request without contacting the specified server. In this case, it 'caches' responses from the remote server, and returns subsequent requests for the same content directly.

Now as a first step in spoofing your IP, you need to find a proxy server. Well proxy servers are of two types- visible and invisible. Visible proxies are known to the web servers and they reveal your IP to the web servers. Invisible proxies do not reveal your identity to the web servers. So finding an invisible proxy is the main task. You can google it. Or if you are way too lazy you noob, we are giving a list of invisible proxies.

How to set a proxy server?

For Mozilla Firefox Users:
Go to Tools>Options>Advanced>Settings
Check the Manual Proxy Configuration Radio Button and enter the appropriate proxy address and port number there


For Internet Explorer users:
Go to Tools>Internet Options>Connections>LAN Settings
Check the Use a proxy server for your LAN check box and enter the address and port number for the proxy server

List of invisible proxy servers:

For all the following proxy servers enter the port number as 3128. All the servers might not be available at a particular time, so try each server.
  1. planetlab2.win.trlabs.ca
  2. planetlab1.cs.ubc.ca
  3. planetlab2.cs.ubc.ca
  4. planetlab-1.usask.ca
  5. planetlab-2.usask.ca
  6. pl1.csl.utoronto.ca
  7. pl2.csl.utoronto.ca
  8. planetlab01.erin.utoronto.ca
  9. planetlab02.erin.utoronto.ca
  10. lsirextpc02.epfl.ch
  11. planetlab01.ethz.ch
  12. planetlab02.ethz.ch
  13. planetlab01.cnds.unibe.ch
  14. planetlab02.cnds.unibe.ch
  15. planetlab2.unineuchatel.ch
  16. planetlab1.csg.uzh.ch
  17. planetlab2.csg.uzh.ch
  18. planetlab1.iin-bit.com.cn
  19. seu1.6planetlab.edu.cn
  20. xjtu1.6planetlab.edu.cn
  21. xjtu2.6planetlab.edu.cn

More proxy servers here..http://fall.cs.princeton.edu/codeen/

Happy Anonymity!!!

How to Create a Keylogger in Visual Basic 2008

The following video shows how you can make a keylogger in Visual Basic 2008. Follow the steps below to create your own keylogger. First you will want to open a new application and name it according to your preferences. Then you want to click on the toolbar button and click textbox.
In the textbox values, you will want to select the value of true for 'Multiline' option and the value of True for 'Read only'. On the toolbar, select the 'Behavior' tab and mark it as 'Window'. Go back on to the main page known as form 1. Enlargen the area to your preferences. Next click on 'Timer' as per the toolbar.

Enable the 'Behavior' and for interval time put in '2'. Text will appear on your form. Highlight and select the text that states 'Dim result as integer." Next, click on the 'Private sub values.' Highlight the Private values ranging from 'for i' to 'next i'. Select the text area. Your keylogger has now been created.

Click on a word pad or note pad application and insert some text. The text will now appear on the form you were working with. Your keylogger is now a success!

Metasploit Framework | Penetration Testing

Metasploit took the security world by storm when it was released in 2004. No other new tool even broke into the top 15 of this list, yet Metasploit comes in at #5, ahead of many well-loved tools that have been developed for more than a decade. It is an advanced open-source platform for developing, testing, and using exploit code. The extensible model through which payloads, encoders, no-op generators, and exploits can be integrated has made it possible to use the Metasploit Framework as an outlet for cutting-edge exploitation research. It ships with hundreds of exploits, as you can see in their online exploit building demo. This makes writing your own exploits easier, and it certainly beats scouring the darkest corners of the Internet for illicit shellcode of dubious quality. Similar professional exploitation tools, such as Core Impact and Canvas already existed for wealthy users on all sides of the ethical spectrum. Metasploit simply brought this capability to the masses.

Metasploit provides useful information and tools for penetration testers, security researchers, and IDS signature developers. This project was created to provide information on exploit techniques and to create a functional knowledgebase for exploit developers and security professionals. The tools and information on this site are provided for legal security research and testing purposes only. Metasploit is an open source project managed by Rapid7.

The Metasploit Project is an open-source computer security project which provides information about security vulnerabilities and aids in penetration testing and IDS signature development. Its most well-known sub-project is the Metasploit Framework, a tool for developing and executing exploit code against a remote target machine. Other important sub-projects include the Opcode Database, shellcode archive, and security research.

The Metasploit Project is also well known for anti-forensic and evasion tools, some of which are built into the Metasploit Framework.

Metasploit was created in 2003 as a portable network game using the Perl scripting language. Later, the Metasploit Framework was then completely rewritten in the Ruby programming language. It is most notable for releasing some of the most technically sophisticated exploits to public security vulnerabilities. In addition, it is a powerful tool for third party security researchers to investigate potential vulnerabilities. On October 21st, 2009 the Metasploit Project announced that it had been acquired by Rapid7, a security company that provides unified vulnerability management solutions.

Like comparable commercial products such as Immunity's CANVAS or Core Security Technologies' Core Impact, Metasploit can be used to test the vulnerability of computer systems in order to protect them, and it can be used to break into remote systems. Like many information security tools, Metasploit can be used for both legitimate and unauthorized activities.

Metasploit's emerging position as the de facto vulnerability development framework has led in recent times to the release of software vulnerability advisories often accompanied by a third party Metasploit exploit module that highlights the exploitability, risk, and remediation of that particular bug. Metasploit 3.0 (Ruby language) is also beginning to include fuzzing tools, to discover software vulnerabilities in the first instance, rather than merely writing exploits for currently public bugs. This new avenue has been seen with the integration of the lorcon wireless (802.11) toolset into Metasploit 3.0 in November, 2006.

Metasploit Official Website: http://www.metasploit.com/
Metasploit download page: http://www.metasploit.com/framework/download/

. . . . . . . . . . . . . . . . . . . . . . . . . . . 

Hacking the Human Operating System a.k.a Social Engineering

Social engineering is the act of manipulating people into performing actions or divulging confidential information, rather than by breaking in or using technical hacking techniques; essentially a fancier, more technical way of lying. While similar to a confidence trick or simple fraud, the term typically applies to trickery or deception for the purpose of information gathering, fraud, or computer system access; in most cases the attacker never comes face-to-face with the victim.

"Social engineering" as an act of psychological manipulation was popularized by hacker-turned-consultant Kevin Mitnick. The term had previously been associated with the social sciences, but its usage has caught on among computer professionals and is now a recognized term of art.

 Social engineering techniques and terms

 Pretexting
Pretexting is the act of creating and using an invented scenario (the pretext) to engage a targeted victim in a manner that increases the chance the victim will divulge information or perform actions that would be unlikely in ordinary circumstances. It is more than a simple lie, as it most often involves some prior research or setup and the use of a priori information for impersonation (e.g., date of birth, Social Security Number, last bill amount) to establish legitimacy in the mind of the target.
This technique can be used to trick a business into disclosing customer information as well as by private investigators to obtain telephone records, utility records, banking records and other information directly from junior company service representatives. The information can then be used to establish even greater legitimacy under tougher questioning with a manager, e.g., to make account changes, get specific balances, etc. Pretexting has even been an observed law enforcement technique, under the auspices of which, a law officer may leverage the threat an alleged infraction to detain a suspect for questioning and close inspection of vehicle or premises.
Pretexting can also be used to impersonate co-workers, police, bank, tax authorities, or insurance investigators — or any other individual who could have perceived authority or right-to-know in the mind of the targeted victim. The pretexter must simply prepare answers to questions that might be asked by the victim. In some cases all that is needed is a voice that sounds authoritative, an earnest tone, and an ability to think on one's feet.

Diversion theft

Diversion theft, also known as the "Corner Game" or "Round the Corner Game", originated in the East End of London.
In summary, diversion theft is a "con" exercised by professional thieves, normally against a transport or courier company. The objective is to persuade the persons responsible for a legitimate delivery that the consignment is requested elsewhere — hence, "round the corner".
With a load/consignment redirected, the thieves persuade the driver to unload the consignment near to, or away from, the consignee's address, in the pretense that it is "going straight out" or "urgently required somewhere else".
The "con" or deception has many different facets, which include social engineering techniques to persuade legitimate administrative or traffic personnel of a transport or courier company to issue instructions to the driver to redirect the consignment or load.
Another variation of diversion theft is stationing a security van outside a bank on a Friday evening. Smartly dressed guards use the line "Night safe's out of order Sir". By this method shopkeepers etc are gulled into depositing their takings into the van. They do of course obtain a receipt but later this turns out to be worthless. A similar technique was used many years ago to steal a Steinway grand piano from a radio studio in London "Come to overhaul the piano guv" was the chat line. Nowadays ID would probably be asked for but even that can be faked and please note that it is no use phoning the number on their bogus business card.
The social engineering skills of these thieves are well rehearsed, and are extremely effective. Most companies do not prepare their staff for this type of deception.

Phishing

Phishing is a technique of fraudulently obtaining private information. Typically, the phisher sends an e-mail that appears to come from a legitimate business — a bank, or credit card company — requesting "verification" of information and warning of some dire consequence if it is not provided. The e-mail usually contains a link to a fraudulent web page that seems legitimate — with company logos and content — and has a form requesting everything from a home address to an ATM card's PIN.
For example, 2003 saw the proliferation of a phishing scam in which users received e-mails supposedly from eBay claiming that the user's account was about to be suspended unless a link provided was clicked to update a credit card (information that the genuine eBay already had). Because it is relatively simple to make a Web site resemble a legitimate organization's site by mimicking the HTML code, the scam counted on people being tricked into thinking they were being contacted by eBay and subsequently, were going to eBay's site to update their account information. By spamming large groups of people, the "phisher" counted on the e-mail being read by a percentage of people who already had listed credit card numbers with eBay legitimately, who might respond.

IVR or phone phishing

This technique uses a rogue Interactive voice response (IVR) system to recreate a legitimate-sounding copy of a bank or other institution's IVR system. The victim is prompted (typically via a phishing e-mail) to call in to the "bank" via a (ideally toll free) number provided in order to "verify" information. A typical system will reject log-ins continually, ensuring the victim enters PINs or passwords multiple times, often disclosing several different passwords. More advanced systems transfer the victim to the attacker posing as a customer service agent for further questioning.
One could even record the typical commands ("Press one to change your password, press two to speak to customer service" ...) and play back the direction manually in real time, giving the appearance of being an IVR without the expense.
Phone phishing is also called vishing.

Baiting

Baiting is like the real-world Trojan Horse that uses physical media and relies on the curiosity or greed of the victim.
In this attack, the attacker leaves a malware infected floppy disk, CD ROM, or USB flash drive in a location sure to be found (bathroom, elevator, sidewalk, parking lot), gives it a legitimate looking and curiosity-piquing label, and simply waits for the victim to use the device.
For example, an attacker might create a disk featuring a corporate logo, readily available from the target's web site, and write "Executive Salary Summary Q2 2010" on the front. The attacker would then leave the disk on the floor of an elevator or somewhere in the lobby of the targeted company. An unknowing employee might find it and subsequently insert the disk into a computer to satisfy their curiosity, or a good samaritan might find it and turn it in to the company.
In either case as a consequence of merely inserting the disk into a computer to see the contents, the user would unknowingly install malware on it, likely giving an attacker unfettered access to the victim's PC and perhaps, the targeted company's internal computer network.
Unless computer controls block the infection, PCs set to "auto-run" inserted media may be compromised as soon as a rogue disk is inserted.

Quid pro quo

Quid pro quo means something for something:
  • An attacker calls random numbers at a company claiming to be calling back from technical support. Eventually they will hit someone with a legitimate problem, grateful that someone is calling back to help them. The attacker will "help" solve the problem and in the process have the user type commands that give the attacker access or launch malware.
  • In a 2003 information security survey, 90% of office workers gave researchers what they claimed was their password in answer to a survey question in exchange for a cheap pen. Similar surveys in later years obtained similar results using chocolates and other cheap lures, although they made no attempt to validate the passwords.

Other types

Common confidence tricksters or fraudsters also could be considered "social engineers" in the wider sense, in that they deliberately deceive and manipulate people, exploiting human weaknesses to obtain personal benefit. They may, for example, use social engineering techniques as part of an IT fraud.
A very recent type of social engineering techniques include spoofing or hacking IDs of people having popular e-mail IDs such as Yahoo!, GMail, Hotmail, etc. Among the many motivations for deception are:
  • Phishing credit-card account numbers and their passwords.
  • Hacking private e-mails and chat histories, and manipulating them by using common editing techniques before using them to extort money and creating distrust among individuals.
  • Hacking websites of companies or organizations and destroying their reputation.
  • Computer virus hoaxes

http://en.wikipedia.org/wiki/Social_engineering_(security)

. . . . . . . . . . . . . . . . . . . . . . . . . . . 

Get IP addresses of your victims for attack

First you need to host the script given below on any hosting site like 110mb.com, ripway.com or t35.com which is totally free. But make sure that hosting site supports PHP.

To get started do as explained in the following steps:
 Step 1:
 Download the IP Finder script (IP_Finder.ZIP) that we have created.

Step 2:
Open a new account in any hosting site like ripway.com, 110mb.com or t35.com.

Step 3:
Extract the IP_Finder.ZIP file and upload the two files 'ip.php' and 'ip_log.txt' into the root folder of your hosting account using the File Manager.
You can also rename the ip.php to any name of your choice. (Say freeitunes.php to avoid suspicion)

Step 4:
Set the permission to 777 on ip_log.txt.

Now you are all done. To find the IP address of your friend or any remote computer. All you have to do is with the help of some social engineering make your victims click on the link
(Say http://your_username.110mb.com/ip.php or http://your_username.110mb.com/freeitunes.php)

Step 5:
Now to view the IP addresses that clicked on your link go to ip_log.txt file which will be at the following link- http://your_username.110mb.com/ip_log.txt


. . . . . . . . . . . . . . . . . . . . . . . . . . . 

Saturday, May 15, 2010

Download free Hacking Video Tutorials | Total 55 Videos | 539.46 MB

  • A Penetration Attack Reconstructed.avi 10-Aug-2009 09:57 26M
  • A Quick and Dirty Intro to Nessus using the Auditor Boot CD!.swf 10-Aug-2009 08:58 2.8M
  • Adding Modules to a Slax or Backtrack Live CD from Windows.swf 10-Aug-2009 09:35 4.2M
  • Airplay replay attack no wireless client required.swf 10-Aug-2009 07:47 5.8M
  • Alan_Watt_CTTM_LIVEonRBN_182_From_Virility_to_Sterility_Oct202008.mp3 10-Aug-2009 09:55 11M
  • Alan_Watt_CTTM_LIVEonRBN_183_Private_Foundations_Making_Public_Policy_Oct222008.mp3 10-Aug-2009 09:56 11M


  • Alan_Watt_on_TheAlexJonesShow_Oct202008.mp3 10-Aug-2009 09:54 13M
  • Alan_Watt_on_The_Monday_Brownbagger_with_Don_Nordin__CFRO_102_7_FM_Oct202008.mp3 10-Aug-2009 09:21 5.7M
  • Anonym.OS LiveCD with build in Tor Onion routing and Privoxy.swf 10-Aug-2009 08:23 3.3M
  • BackTrack LiveCD to HD Installation Instruction Video .swf 10-Aug-2009 09:51 7.1M
  • Basic Nmap Usage!.swf 10-Aug-2009 09:07 8.3M
  • Basic Tools for Wardriving!.swf 10-Aug-2009 06:08 2.7M
  • Bluesnarfer attack tool demonstration.swf 10-Aug-2009 09:52 9.8M
  • Bluesnarfing a Nokia 6310i hand set.avi 10-Aug-2009 09:02 1.6M
  • Breaking WEP in 10 minutes.avi 10-Aug-2009 09:48 9.4M
  • Cain to ARP poison and sniff passwords!.avi 10-Aug-2009 09:34 1.8M
  • Complete Hacking Video using Metasploit Meterpreter.swf 10-Aug-2009 09:49 13M
  • Cracking Syskey and the SAM on Windows Using Samdump2 and John!.swf 10-Aug-2009 09:40 2.5M
  • Cracking WPA Networks (Auditor).swf 10-Aug-2009 09:58 15M
  • Cracking Windows Passwords with BackTrack and the Online Rainbow Tables at Plain-Text!.swf 10-Aug-2009 09:28 4.3M
  • Cracking a 128 Bit Wep key + entering the cridentials.swf 10-Aug-2009 09:59 22M
  • Cracking a 128 bit WEP key (Auditor).swf 10-Aug-2009 09:54 51M
  • DoS attack against Windows FTP Server DoS.avi 10-Aug-2009 09:55 8.5M
  • Droop s Box Simple Pen-test Using Nmap, Nikto, Bugtraq, Nslookup and Other Tools!.swf 10-Aug-2009 09:32 6.6M
  • Exploiting some bugs of tools used in Windows.swf.swf 10-Aug-2009 09:49 16M
  • Exploiting weaknesses of PPTP VPN (Auditor).swf 10-Aug-2009 09:53 5.5M
  • Finding Rogue SMB File Shares On Your Network!.swf 10-Aug-2009 09:24 5.5M
  • Fun with Ettercap Filters!.swf 10-Aug-2009 07:02 2.4M
  • How to crack the local windows passwords in the SAM database .swf 10-Aug-2009 09:19 6.8M
  • How to decrypt SSL encrypted traffic using a man in the middle attack (Auditor).swf 10-Aug-2009 09:57 32M
  • How to sniff around switches using Arpspoof and Ngrep!.avi 10-Aug-2009 06:04 4.1M
  • Install VNC Remotely!.avi 10-Aug-2009 09:51 5.2M
  • Internet Explorer Remote Command Execution Exploit (CMDExe) Client Side Attack (Hi-Res).avi 10-Aug-2009 09:31 8.1M
  • Internet Explorer Remote Command Execution Exploit (CMDExe) Client Side Attack (Lo-Res).avi 10-Aug-2009 09:43 8.3M
  • John The Ripper 1.7 password cracker Installation Instruction Video .swf 10-Aug-2009 09:59 2.6M
  • Local Password Cracking Presentation for the Indiana Higher Education Cybersecurity Summit 2005!.swf 10-Aug-2009 09:42 5.7M
  • MAC Bridging with Windows XP and Sniffing!.swf 10-Aug-2009 08:47 1.4M
  • MITM Hijacking.wmv 10-Aug-2009 09:55 52M
  • Mass De-Authentication using void11 (Auditor).swf 10-Aug-2009 09:57 17M
  • Metasploit Flash Tutorial!.swf 10-Aug-2009 05:55 3.2M
  • Nmap Video Tutorial 2 Port Scan Boogaloo!.swf 10-Aug-2009 09:50 13M
  • SSH Dynamic Port Forwarding!.swf 10-Aug-2009 08:26 3.0M
  • Sniffing Remote Router Traffic via GRE Tunnels (Lo-Res).avi 10-Aug-2009 09:23 18M
  • Sniffing VoIP Using Cain!.swf 10-Aug-2009 08:59 1.7M
  • Sniffing logins and passwords.avi 10-Aug-2009 09:24 6.8M
  • Snort Instruction video howto install into backtrack.swf 10-Aug-2009 09:58 11M
  • Start a session and get interactive commandline access to a remote Windows box!.avi 10-Aug-2009 07:35 5.2M
  • Telnet Bruteforce.avi 10-Aug-2009 09:35 14M
  • Tunneling Exploits through SSH.avi 10-Aug-2009 09:22 17M
  • Use Brutus to crack a box running telnet!.avi 10-Aug-2009 05:00 714K
  • Using NetworkActiv to sniff webpages on a Wi-Fi network!.swf 10-Aug-2009 05:51 1.3M
  • WEP Cracking using Aireplay v2.2 Beta 7 (Whax 3.0).swf 10-Aug-2009 09:10 5.2M
  • WMF File Code Execution Vulnerability With Metasploit!.swf 10-Aug-2009 08:22 3.7M
  • WPA Cracking using Aireplay v2.2 Beta 7 (Whax 3.0).swf 10-Aug-2009 07:47 5.2M

DOWNLOAD LINKS

. . . . . . . . . . . . . . . . . . . . . . . . . . . 

How to Trace IP Address Location From Email, Gmail, Hotmail, MSN & Yahoo Mail

This Article will explain how you can track your friends IP address. You will need to do some social engineering in this trick. You will need to ask your friend to mail you something or send him some mail to which he will reply.

Now there can be two scenarios. Your friends/victims IP can be static or dynamic.

Scenario 1: Static IP

Static IP is assigned by the ISP to a specific user, that is, you have one unique IP whenever you log on to the internet. In this case, here's how you can find the IP. We will consider three major email services, viz. gmail, yahoo and hotmail.

Gmail:

Open the mail you have recieved from your friend and click on the down arrow to the right of the reply button. Now click on Show Original.
You will get to see the complete headers of the mail from which you have to find the IP from which this mail was sent. Mostly in case of a static IP, the IP is shown as in the figure

Hotmail:

Right click on the recieved mail and select 'view message source'



You will get the complete message with source. This is how the originating IP looks in hotmail

Yahoo:

Open the mail and at the right bottom of the mail, click on 'Full headers'


Again over here you will get to see the IP in the same format as in hotmail and gmail, shown above.

Scenario 2: Dynamic IP

In case of dynamic IP, hotmail and yahoo wont help much. Whereas Gmail shows the private IP of the sender. Just follow the procedure above as shown for static. On the source page you have to look for the following:




Here the IP 10.141.12.9 is the private IP of our victim. This is how you can get IP information of victims behind subnets. Well sometimes the private is not shown by any of the email services because instead of sending detailed email information a DKIM-signature is sent for authentication.

There are other numerous ways using which we can track our victims IP. Will soon be posting on that. Stay subscribed. Till then..
. . . . . . . . . . . . . . . . . . . . . . . . . . .

How Hackers Manipulate the Live Data Stream on Internet

 NOTE: THIS IS ONLY THE DEMONSTRATION OF THIS TECHNIQUE AND FOR EDUCATION PURPOSE ONLY

1. First of all install WebGoat and configure Web browser
2. We will use the tool Achilles. It is a tool designed for testing the security of Web applications. Achilles is a proxy server, which acts as a man-in-themiddle during an HTTP session. For more about Achilles, pls check its official website.
3. Double-click the webgoat.exe icon from the directory containing the WebGoat application.


4. onfigure the LAN setting as shown in the below fig

5. Run the Achilles application & select the options of the application as shown in below fig.


Intercept mode ON
Intercept Client Data
Ignore .jpg/.gif
Select Log to File - Save the data
6. Your Achilles screen should look like the following.

7. Open Internet Explorer and Adjust both screens equally on your desktop as shoen below.


8. Click the Start button on Achilles and notice that the status bar along the lower-left side of Achilles will let you know it is running.
9. In the address bar of Internet Explorer, enter the following address:
http://localhost/WebGoat/attack/
10. Press Enter, and Achilles will list the data flowing through to the Tomcat application. Click the Send button in Achilles. You will be presented with a login screen. For the User Name and Password enter the word guest. click the Send button again.

11. Click the Send button again & WebGoat screen will be displayed in the Web browser.
12. Under the Unvalidated Parameters section, specifically the Hidden Field Tampering area. Click on this area.
13. Click the Send button again.
14. WebGoat will appear with a shopping cart as shown below.

15. Click the Purchase button. Within Achilles you will see the QTY=1 & is Price=4999.99. Now if you want to make a purchase, whose actual cost is 4999.99 but you have only 1.99 in your account, Within Achilles edit the 4999.99 to 1.99 and then click the Send button.

16. The sale has completed, with a total charge of $1.99.

. . . . . . . . . . . . . . . . . . . . . . . . . . .

Saturday, May 8, 2010

Top 10 Tricks to exploit SQL Server Systems

http://easydownload.ru/uploads/posts/2009-04/1240341405_518053737_8a9794389e.jpg Whether it is through manual poking and prodding or the use of security testing tools, malicious attackers employ a variety of tricks to break into SQL Server systems, both inside and outside your firewall. It stands to reason then, if the hackers are doing it, you need to carry the same attacks to test the security strength of your systems. Here are 10 hacker tricks to gain access and violate systems running SQL Server.
. . . . . . . . . . . . . . . . . . . . . . . . . . .
1. Direct connections via the Internet

These connections can be used to attach to SQL Servers sitting naked without firewall protection for the entire world to see (and access). DShield's Port Report shows just how many systems are sitting out there waiting to be attacked. I don't understand the logic behind making a critical server like this directly accessible from the Internet, but I still find this flaw in my assessments, and we all remember the effect the SQL Slammer worm had on so many vulnerable SQL Server systems. Nevertheless, these direct attacks can lead to denial of service, buffer overflows and more.

2. Vulnerability scanning

Vulnerability scanning often reveals weaknesses in the underlying OS, the Web application or the database system itself. Anything from missing SQL Server patches to Internet Information Services (IIS) configuration weaknesses to SNMP exploits can be uncovered by attackers and lead to database server compromise. The bad guys may use open source, home-grown or commercial tools. Some are even savvy enough to carry out their hacks manually from a command prompt. In the interest of time (and minimal wheel spinning), I recommend using commercial vulnerability assessment tools like QualysGuard from Qualys Inc. (for general scanning), WebInspect from SPI Dynamics (for Web application scanning) and Next Generation Security Software Ltd.'s NGSSquirrel for SQL Server (for database-specific scanning). They're easy to use, offer the most comprehensive assessment and, in turn, provide the best results. Figure 1 shows some SQL injection vulnerabilities you may be able to uncover.

sql hacker fig1

Figure 1: Common SQL injection vulnerabilities found using WebInspect.

3. Enumerating the SQL Server Resolution Service

Running on UDP port 1434, this allows you to find hidden database instances and probe deeper into the system. Chip Andrews' SQLPing v 2.5 is a great tool to use to look for SQL Server system(s) and determine version numbers (somewhat). This works even if your SQL Server instances aren't listening on the default ports. Also, a buffer overflow can occur when an overly long request for SQL Servers is sent to the broadcast address for UDP port 1434.

4. Cracking SA passwords

Deciphering SA passwords is also used by attackers to get into SQL Server databases. Unfortunately, in many cases, no cracking is needed since no password has been assigned (Oh, logic, where art thou?!). Yet another use for the handy-dandy SQLPing tool mentioned earlier. The commercial products AppDetective from Application Security Inc. and NGSSQLCrack from NGS Software Ltd. also have this capability.

5. Direct-exploit attacks

Direct attacks using tools such as Metasploit, shown in Figure 2, and its commercial equivalents (CANVAS and CORE IMPACT) are used to exploit certain vulnerabilities found during normal vulnerability scanning. This is typically the silver-bullet hack for attackers penetrating a system and performing code injection or gaining unauthorized command-line access.



Figure 2: SQL Server vulnerability exploitable using Metasploit's MSFConsole.

6. SQL injection

SQL injection attacks are executed via front-end Web applications that don't properly validate user input. Malformed SQL queries, including SQL commands, can be inserted directly into Web URLs and return informative errors, commands being executed and more. These attacks can be carried out manually -- if you have a lot of time. Once I discover that a server has a potential SQL injection vulnerability, I prefer to perform the follow-through using an automated tool, such as SPI Dynamics' SQL Injector, shown in Figure 3.

Figure 3: SPI Dynamics' SQL Injector tool automates the SQL injection process.

7. Blind SQL injection

These attacks go about exploiting Web applications and back-end SQL Servers in the same basic fashion as standard SQL injection. The big difference is that the attacker doesn't receive feedback from the Web server in the form of returned error messages. Such an attack is even slower than standard SQL injection given the guesswork involved. You need a good tool for this situation, and that's where Absinthe, shown in Figure 4, comes in handy.


Figure 4: Absinthe tool takes the pain out of blind SQL injection testing.

8. Reverse engineering the system

The reverse engineering trick looks for software exploits, memory corruption weaknesses and so on. In this sample chapter from the excellent book Exploiting Software: How to Break Code by Greg Hoglund and Gary McGraw, you'll find a discussion about reverse engineering ploys.

9. Google hacks

Google hacks use the extraordinary power of the Google search engine to ferret out SQL Server errors -- such as "Incorrect syntax near" -- leaking from publicly accessible systems. Several Google queries are available at Johnny Long's Google Hacking Database. (Look in the sections titled Error Messages and Files containing passwords.) Hackers use Google to find passwords, vulnerabilities in Web servers, underlying operating systems, publicly available procedures and more that they can use to further compromise a SQL Server system. Combining these queries with Web site names via Google's 'site:' operator often turns up juicy info you never imagined you could unearth.

10. Perusing Web site source code

Source code can also turn up information that may lead to a SQL Server break in. Specifically, developers may store SQL Server authentication information in ASP scripts to simplify the authentication process. A manual assessment or Google could uncover this information in a split second.