Showing posts with label Hacking. Show all posts
Showing posts with label Hacking. Show all posts

Sunday, 7 April 2013

Easy Way to Hack WiFi Password 100% Work 2013




Update Note-; Working Perfectly in 2015 Also

Things you should need

1. A USB pen drive

2. beini.iso file (Download it from here)

3. UNetbootin software Link Here to make your USB drive bootable. [Download for Windows, Linux or Mac]
Some few steps you should to do ( WEP):

1. Write beini.iso on your USB by UNetbootin. Set everything according to this image bellow



2. After finishing restart your PC and boot it from your USB.

3. If you were successful to boot up then you should see something like this. Click Minidwep-gtk.


4. Click OK



5. Now Minipwep-gtk program will open. Click Scan.



6. Select a wireless network(should have Clint) from the list. And click Lunch to start creaking process



7. Sometimes its take a while according to your victim connections IVS value and password strength. So keep passions.



8. If it found a password, it should appear like this




To creak WPA/WPA2 follow this image instruction.



Tuesday, 12 July 2011

2000 + emails with password

Friends aaj mujhe kuch upload karne ka maan kiya to ye e mails with password upload kar raha hu.... just download it and enjoy..
Note: it's not a keylogger or crypted virus..  Click here to download 2000+emails with password by magictrick.in

Wednesday, 22 June 2011

Here our 1st daily working mac address

we are giving 5 working mac address for today

here the list

  • 00:25:68:9B:FA:C6
  • 64:16:F0:7F:D0:66
  • 4C:54:99:6D:C9:7B
  • 64:16:F0:C5:32:24
  • 5C:4C:A9:C0:D5:FC

Saturday, 4 June 2011

Google Operators

1.      define: – This google operator will find definitions for a certain term or  word over the Internet. Very useful when you come across a strange word when writing a post. I use this as a google dictionary. example : (define Computer)

2.      info: – The google info operator will list the sets of information that Google has from a specific website (i.e. info:http://google.com)

3.      site: – This google operator can be used to see the number of indexed pages on your site (i.e.site:www.google.com).    Alternative it can also be used to search for information inside a specific  site or class of sites.

4.      link: – This google link operator allows you to find backlinks pointing to your site. Unfortunately the count is not updated frequently and not all backlinks are shown

5.      allinurl: – Using this Google operator will limit the search to results  that contain the desired keywords on the URL structure. (i.e. allinurl:dailyblogtips)

6.      fileformat: – Useful Google operator for finding specific file formats. Sometimes you know that the information you are looking for is likely to be contained in a PDF document or on a PowerPoint presentation, for instance. (i.e. “fileformat:.pdf market research” will search for PDF documents that contain the terms “market” and “research”)

Wednesday, 25 May 2011

10 Best Security Live CD Distros (Pen-Test, Forensics & Recovery)

1. BackTrack
The newest contender on the block of course is BackTrack, which we have spoken about previously. An innovative merge between WHax and Auditor (WHax formely WHoppix).
BackTrack is the result of the merging of two Innovative Penetration Testing live Linux distributions Whax and Auditor, combining the best features from both distributions, and paying special attention to small details, this is probably the best version of either distributions to ever come out.
Based on SLAX (Slackware), BackTrack provides user modularity. This means the distribution can be easily customised by the user to include personal scripts, additional tools, customised kernels, etc.
Get BackTrack Here.
2. Operator
Operator is a very fully featured LiveCD totally oriented around network security (with open source tools of course).
Operator is a complete Linux (Debian) distribution that runs from a single bootable CD and runs entirely in RAM. The Operator contains an extensive set of Open Source network security tools that can be used for monitoring and discovering networks. This virtually can turn any PC into a network security pen-testing device without having to install any software. Operator also contains a set of computer forensic and data recovery tools that can be used to assist you in data retrieval on the local system.
Get Operator Here
3. PHLAK
PHLAK or [P]rofessional [H]acker’s [L]inux [A]ssault [K]it is a modular live security Linux distribution (a.k.a LiveCD). PHLAK comes with two light gui’s (fluxbox and XFCE4), many security tools, and a spiral notebook full of security documentation. PHLAK is a derivative of Morphix, created by Alex de Landgraaf.
Mainly based around Penetration Testing, PHLAK is a must have for any pro hacker/pen-tester.
Get PHLAK Here (You can find a PHLAK Mirror Here as the page often seems be down).
4. Auditor
Auditor although now underway merging with WHax is still an excellent choice.
The Auditor security collection is a Live-System based on KNOPPIX. With no installation whatsoever, the analysis platform is started directly from the CD-Rom and is fully accessible within minutes. Independent of the hardware in use, the Auditor security collection offers a standardised working environment, so that the build-up of know-how and remote support is made easier.
Get Auditor Here
5. L.A.S Linux
L.A.S Linux or Local Area Security has been around quite some time aswell, although development has been a bit slow lately it’s still a useful CD to have. It has always aimed to fit on a MiniCD (180MB).
Local Area Security Linux is a ‘Live CD’ distribution with a strong emphasis on security tools and small footprint. We currently have 2 different versions of L.A.S. to fit two specific needs – MAIN and SECSERV. This project is released under the terms of GPL.
Get L.A.S Linux Here
6. Knoppix-STD
Horrible name I know! But it’s not a sexually trasmitted disease, trust me.
STD is a Linux-based Security Tool. Actually, it is a collection of hundreds if not thousands of open source security tools. It’s a Live Linux Distro, which means it runs from a bootable CD in memory without changing the native operating system of the host computer. Its sole purpose in life is to put as many security tools at your disposal with as slick an interface as it can.
Get Knoppix-STD Here

7. Helix
Helix is more on the forensics and incident response side than the networking or pen-testing side. Still a very useful tool to carry.
Helix is a customized distribution of the Knoppix Live Linux CD. Helix is more than just a bootable live CD. You can still boot into a customized Linux environment that includes customized linux kernels, excellent hardware detection and many applications dedicated to Incident Response and Forensics.
Get Helix Here
8. F.I.R.E
A little out of date, but still considered the strongest bootable forensics solution (of the open-source kind). Also has a few pen-testing tools on it.
FIRE is a portable bootable cdrom based distribution with the goal of providing an immediate environment to perform forensic analysis, incident response, data recovery, virus scanning and vulnerability assessment.
Get F.I.R.E Here
9. nUbuntu
nUbuntu or Network Ubuntu is fairly much a newcomer in the LiveCD arena as Ubuntu, on which it is based, is pretty new itself.
The main goal of nUbuntu is to create a distribution which is derived from the Ubuntu distribution, and add packages related to security testing, and remove unneeded packages, such as Gnome, Openoffice.org, and Evolution. nUbuntu is the result of an idea two people had to create a new distribution for the learning experience.
Get nUbuntu Here
10. INSERT Rescue Security Toolkit
A strong all around contender with no particular focus on any area (has network analysis, disaster recovery, antivirus, forensics and so-on).
INSERT is a complete, bootable linux system. It comes with a graphical user interface running the fluxbox window manager while still being sufficiently small to fit on a credit card-sized CD-ROM.
The current version is based on Linux kernel 2.6.12.5 and Knoppix 4.0.2
Get INSERT Here
Extra – Knoppix
Remember this is the innovator and pretty much the basis of all these other distros, so check it out and keep a copy on you at all times!
Not strictly a security distro, but definately the most streamlined and smooth LiveCD distribution. The new version (soon to be released – Knoppix 5) has seamless NTFS writing enabled with libntfs+fuse.
KNOPPIX is a bootable CD or DVD with a collection of GNU/Linux software, automatic hardware detection, and support for many graphics cards, sound cards, SCSI and USB devices and other peripherals. KNOPPIX can be used as a productive Linux desktop, educational CD, rescue system, or adapted and used as a platform for commercial software product demos. It is not necessary to install anything on a hard disk.
Get Knoppix Here
Other Useful Resources:
SecurityDistros
FrozenTech LiveCD List
DistroWatch
Others to consider (Out of date or very new):
SlackPen
ThePacketMaster
Trinux
WarLinux
Network Security Toolkit
BrutalWare
KCPentrix
Plan-B
PENToo
New ones added from authors e-mail/slashdotters and diggers:
Arudius
The Gentoo Forensic Toolkit
Anonym-OS

HACKING TOOLS / EXPLOITS ALL -- BY Athar.

Astalavista Tools and Utilities

  1. Data Loss Prevention - Whitepaper called Data Loss Prevention
  2. The Risks of Client-Side Data Storage - Whitepaper called The Risks of Client-Side Data Storage
  3. BadAss 0.5 Beta - BadAss is a Ruby script that makes it very easy to perform cracking attacks, port scanning, and more.
    Changes: Interface re-written from scratch. New ruby scripts added. Various other additions.
  4. QuickRecon 0.3 - QuickRecon is a python script for simple information gathering. It attempts to find subdomain names, perform zone transfers and gathers emails from Google and Bing.
    Changes: Qt4 based GUI. Improved Code.
  5. Bluelog Bluetooth Scanner/Logger 0.9.9 - Bluelog is a Bluetooth scanner/logger written with speed in mind. It is intended to be used as a site survey tool, concerned more about accurately detecting the number of discoverable Bluetooth devices than individual device specifics. Bluelog also includes the unique "Bluelog Live" mode, which puts discovered devices into a constantly updating live webpage which you can serve up with your HTTP daemon of choice.
    Changes: This is a major rewrite. Completely revamped device cache code is faster and more accurate while preventing redundant scans. New features such as Amnesia mode and preliminary OpenWRT support. Numerous bugfixes and optimizations. A recommended update for all users.
  6. Web Application Security Part 1 - Brief whitepaper called Web Application Security - Part 1. It discusses using SQL injection for login bypass.
  7. Linux Exploit Development Part 4 - Whitepaper called Linux exploit development part 4 - ASCII armor bypass + return-to-plt.
  8. Covert Data Storage Channel Using IP Packet Headers - A covert data channel is a communications channel that is hidden within the medium of a legitimate communications channel. Covert channels manipulate a communications medium in an unexpected or unconventional way in order to transmit information in an almost undetectable fashion. Otherwise said, a covert data channel transfers arbitrary bytes between two points in a fashion that would appear legitimate to someone scrutinizing the exchange. (Bingham, 2006)
  9. Covert communications: subverting Windows applications - Whitepaper called Covert communications: subverting Windows applications
  10. Inside-Out Vulnerabilities, Reverse Shells - Keeping data from leaking out of protected networks is becoming increasingly difficult due to the increase of malicious code that sends data from infected systems.

Packetstorm Last 10 Files

  1. HP System Management Homepage Cross Site Scripting - HP System Management Homepage suffers from multiple cross site scripting vulnerabilities.
  2. ChromeMedia SQL Injection - ChromeMedia suffers from a remote SQL injection vulnerability.
  3. DH Softwares SQL Injection - DH Softwares suffers from a remote SQL injection vulnerability that allows for authentication bypass.
  4. MyLittleForum 2.2.7 Cross Site Request Forgery - MyLittleForum CMS version 2.2.7 suffers from a cross site request forgery vulnerability.
  5. PEEL Open E-Commerce Systems SQL Injection - PEEL Open E-Commerce Systems suffers from a remote SQL injection vulnerability.
  6. PHPortfolio SQL Injection - PHPortfolio suffers from a remote SQL injection vulnerability.
  7. Ciphertek Systems SQL Injection - Ciphertek Systems suffers from a remote SQL injection vulnerability.
  8. MODx Revolution 2.0.8-pl Cross Site Request Forgery - MODx Revolution CMS version 2.0.8-pl suffers from a cross site request forgery vulnerability.
  9. Textpattern 4.3.0 Cross Site Request Forgery - Textpattern CMS version 4.3.0 suffers from a cross site request forgery vulnerability.
  10. Magix Musik Maker 16 .mmm Stack Buffer Overflow - This Metasploit module exploits a stack buffer overflow in Magix Musik Maker 16. When opening a specially crafted arrangement file (.mmm) in the application, an unsafe strcpy() will allow you to overwrite a SEH handler. This exploit bypasses DEP & ASLR, and works on XP, Vista & Windows 7. Egghunter is used, and might require up to several seconds to receive a shell.

Packetstorm Tools

  1. BadAss 0.6 Beta - BadAss is a Ruby script that makes it very easy to perform cracking attacks, port scanning, and more.
  2. Pytbull 1.3 - pytbull is an intrusion detection/prevention system (IDS/IPS) testing framework for Snort and Suricata. It can be used to test the detection and blocking capabilities of an IDS/IPS, to compare IDS/IPS, to compare configuration modifications and to check/validate configurations. The framework is shipped with about 300 tests grouped into 8 testing modules.
  3. Mptcp Packet Manipulator 1.8 - Mpctp is a tool for manipulation of raw packets that allows a large number of options. Its primary purpose is to diagnose and test several scenarios that involving the use of the types of TCP/IP packets. It is able to send certain types of packets to any specific target and manipulations of various fields at runtime. These fields can be modified in its structure as the the Source/Destination IP address and Source/Destination MAC address.
  4. Google Hack DB Tool 1.2 - Google Hack DB Tool is a database tool with almost 8,000 entries. It allows administrators the ability to check their site for vulnerabilities based on data stored in Google.
  5. QuickRecon 0.3 - QuickRecon is a python script for simple information gathering. It attempts to find subdomain names, perform zone transfers and gathers emails from Google and Bing.
  6. BadAss 0.5 Beta - BadAss is a Ruby script that makes it very easy to perform cracking attacks, port scanning, and more.
  7. Bluelog Bluetooth Scanner/Logger 0.9.9 - Bluelog is a Bluetooth scanner/logger written with speed in mind. It is intended to be used as a site survey tool, concerned more about accurately detecting the number of discoverable Bluetooth devices than individual device specifics. Bluelog also includes the unique "Bluelog Live" mode, which puts discovered devices into a constantly updating live webpage which you can serve up with your HTTP daemon of choice.
  8. DNS Spider Multithreaded Bruteforcer 0.1 - DNS Spider is a multithreaded bruteforcer of subdomains that leverages a wordlist and/or character permutation.
  9. BadAss 0.4 Beta - BadAss is a Ruby script that makes it very easy to perform cracking attacks, port scanning, and more.
  10. Samhain File Integrity Checker 2.8.4a - Samhain is a file system integrity checker that can be used as a client/server application for centralized monitoring of networked hosts. Databases and configuration files can be stored on the server. Databases, logs, and config files can be signed for tamper resistance. In addition to forwarding reports to the log server via authenticated TCP/IP connections, several other logging facilities (e-mail, console, and syslog) are available. Tested on Linux, AIX, HP-UX, Unixware, Sun and Solaris.

Packetstorm Exploits

  1. HP System Management Homepage Cross Site Scripting - HP System Management Homepage suffers from multiple cross site scripting vulnerabilities.
  2. ChromeMedia SQL Injection - ChromeMedia suffers from a remote SQL injection vulnerability.
  3. DH Softwares SQL Injection - DH Softwares suffers from a remote SQL injection vulnerability that allows for authentication bypass.
  4. MyLittleForum 2.2.7 Cross Site Request Forgery - MyLittleForum CMS version 2.2.7 suffers from a cross site request forgery vulnerability.
  5. PEEL Open E-Commerce Systems SQL Injection - PEEL Open E-Commerce Systems suffers from a remote SQL injection vulnerability.
  6. PHPortfolio SQL Injection - PHPortfolio suffers from a remote SQL injection vulnerability.
  7. Ciphertek Systems SQL Injection - Ciphertek Systems suffers from a remote SQL injection vulnerability.
  8. MODx Revolution 2.0.8-pl Cross Site Request Forgery - MODx Revolution CMS version 2.0.8-pl suffers from a cross site request forgery vulnerability.
  9. Textpattern 4.3.0 Cross Site Request Forgery - Textpattern CMS version 4.3.0 suffers from a cross site request forgery vulnerability.
  10. Magix Musik Maker 16 .mmm Stack Buffer Overflow - This Metasploit module exploits a stack buffer overflow in Magix Musik Maker 16. When opening a specially crafted arrangement file (.mmm) in the application, an unsafe strcpy() will allow you to overwrite a SEH handler. This exploit bypasses DEP & ASLR, and works on XP, Vista & Windows 7. Egghunter is used, and might require up to several seconds to receive a shell.

Securiteam Exploits

  1. Adobe Shockwave TextXtra Invalid Seek Code Execution Vulnerability - This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Adobe Shockwave.
  2. Adobe Shockwave dirapi.dll IFWV Trusted Offset Code Execution Vulnerability - This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of the Adobe Shockwave Player.
  3. Adobe Flash Player Point Object Code Execution Vulnerability - This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Adobe Flash Player.
  4. Hewlett-Packard Virtual SAN Appliance hydra.exe Login Request Code Execution Vulnerability - This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Hewlett-Packard Virtual SAN appiance.
  5. IBM Lotus Domino Server Controller Authentication Bypass Code Execution Vulnerability - This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Lotus Domino Server Controller.

login (security through obscurity) – weird PHP script

This was the idea with which I have won the regional web apps contest… well actually I did a CMS but the security part of it was the most appreciated. Maybe because it was weird, you’ll see…
Classical Login scripts
What exactly do classical login scripts do… they get the password from the database by querying it with the username (SQL Injection possibility) and after that they compare the retrieved password with the one submitted by the user. If they match either the website sets a cookie, or a variable in the current session…
Weird/Reverse Login script
The main thing that I wanted to achieve was to get rid of any SQL Injection vulnerability. How did I do this? I didn’t use the classical query username in database and get the respective password; instead I searched all the usernames that had the password sent by the current user and then scanned through the list for the username, if not found no such username exists…

$passwd = $_REQUEST["passwd"];
$uname = $_REQUEST["username"];
$ok = 0;
$handle = mysql_connect("", "", "");
$build = "SELECT uname FROM usr WHERE passwd='" .md5($passwd). "';
$query = mysql_query($build, $handle);
while($fetch=mysql_fetch_array($query)) {
if($fetch[0]!=$uname) {
if($ok==1) {
//do nothing
}
else {
$ok=0;
}
}
else {
$ok=1;
}
}
if($ok==0) {
header("Location: somewhere");
}
else {
//set a weird cookie
}
As far as I see through this method there is no SQL Injection possibility, no need of mysql_real_escape_string() or to worry about hex encoded strings, etc.
Weird/Obscure Cookie
The login process isn’t complete, not until we do not set a normal cookie with “strange” information in it, or should we say obscure information for everybody except the webmaster =).
$build = $REMOTE_ADDR. "secretK3y";
setCookie("cookIT", md5($build), 0);
As for the secret key…. it has to be secret because if it is not, a person on the same network as yours could forge a cookie to gain access.
Cookie verifier
This is used to check the authenticity of the cookie, I bet you already have an idea on how it looks:
if(!isset($_COOKIE["cookIT"])) {
header("Location: somewhere");
}
else {
$value = $_COOKIE["cookIT"];
$build = $REMOTE_ADDR. "secretK3y";
if($value!=md5($build)) {
//or a fake cookie or changed proxy
}
else {
...do stuff for users...
}
}
Epilogue
It’s not a great thing, could have used sessions or the classical login method with many filters (addslashes(), mysql_real_escape_string())… but I didn’t, it was perfect for me because I am a fan of the principle: “security through obscurity” and also got more points because they wanted creativity… in everything design/development. And because I’m not a designer I had to use my creativity on development. Some of you maybe will like it, others will see it as plain stupidity, and the rest of you won’t even care… but still, it helped me won the contest…

vbSEO – From XSS to Reverse PHP Shell

SS is not a big deal, or is it? On many occasions, I’ve seen this vulnerability being classified as useless, not serious, and being a low threat. What I’ve always had in mind is that it’s only the capabilities of the browser, and the hackers mind which sets the limit for a XSS attack.

It may seem impossible to do anything else other than stealing sessions, cookies and performing phishing, client side defacements etc. But take a look at the picture above, that is a reverse php shell automatically injected into the site, when a vBulletin administrator viewed a malicious linkback.
The vulnerability itself I’m referring to, is a 0day within vBSEO which exists within the administrator and moderator panel only. However, the attacker is able to inject persistent scripts via this linkback feature directly into the part of these panels handling these linkbacks.
In short, the attacker crafts a malicious HTML page as shown in the advisory. Then, the attacker clicks a link to the target forum with vBSEO installed, and when the target is reached, vBSEO performs a GET-request to the attacker’s malicious HTML page (if it’s served online and if RefBacks are enabled).
The title of this page is then loaded directly into the database, and an administrator can see it sanitized in the actual thread, but also in the admin and mod panel where the title is not sanitized at all, allowing the script to run.

What is actually possible?

After discovering and researching this vulnerability, I realised it was a fine case to do further studies on and then develop a XSS worm. Fortunately I got away from that idea due to the fact it could’ve been abused globally on forums with vBSEO installed. However, the idea itself was not bad so I began developing the payload aka the javascript, which would eventually inject a PHP payload via the nice plugin feature in vBulletin.
Initially, the XSS trojan I wrote should be able to do all of this silently without the user knowing, so instead of document.write being used, appendChild which uses DOM objects, was used instead. This took a bit more work in order to function better, but the result was that the visible window would not change to the affected user getting infected with this trojan.
When the user browses to, in this case “Moderate Linkbacks”, the script is executing as soon as the user hits that page. When this happens, the trojan checks whether infection has already happened once and if not, continues. Then an iframe is created outside the visible frames, where the adminhash and securitytoken (CSRF-token) is read and saved in a local variable in the browser.
Then a new form is injected into this iframe, which contains the adminhash and the securitytoken. The form itself contains the values needed to create a new and completely valid plugin which in this case, is PHP code. At this point, the script checks again if the user has already been infected and if not, the form is submitted, the plugin is created, and a cookie is set to prevent the script from going in loops.
Most administrators, would notice the broken lock icon in case they use HTTPS / SSL, and then they would view the source. The great thing about using javascript to create HTML objects, especially with “appendChild” etc. is that it is not visible. A debugger, such as Firebug shown in the picture above is needed, unless the admin finds the malicious javascript payload and reads what it does, but then it might be too late.
During the execution of the XSS trojan, a time-out is set. When time runs out, the XSS trojan will try to delete itself leaving almost no traces, besides the possible injected plugin, and the remains of the hidden iframe outside the frames which cannot be viewed due to the way HTML works in FireFox.
If the attacker was successful, and patient as well, he would eventually see that the target website had already connected back to retrieve the title, but also that another user had triggered the XSS Trojan which hopefully injected the PHP plugin specified by the attacker.
So what’s this tool I’ve been using during my presentation of this vulnerability? It’s a recently developed tool written in Python, where the payload is written in Javascript, freely available to anyone in the bottom of this blog. I recommend however, that a user of this tool looks inside the source code.

Is XSS a serious threat then?

Yes, it definitely is.
For a demonstration of the tool and this vulnerability, check either the YouTube or RapidShare link below.
References:
Advisory: vBSEO 3.5.2 & 3.2.2 – Persistent XSS via LinkBacks
Advisory #2: vbSEO Multiple Vulnerabilities
EvilWebTool: EvilWebTool
YT Video:  http://www.youtube.com/watch?v=B6QAjB3kYec
HQ Video: http://rapidshare.com/files/445021103/vbseo_0day.mp4

Sunday, 22 May 2011

JavaScript IP Address To Decimal Calculator -- THE MOST IMPORTANT TRICK TO OPEN ANY WEBSITE BLOCKED

The URL for The Allred Family Roster is http://www.AllredRoster.com. An nslookup of the URL reveals its IP address: 206.117.16.66 (which is the real address used to find the Website).
IP addresses are expressed in dotted-decimal format - basically 4 sets of numbers from 0 to 255 seperated by periods. Either http://206.117.16.66 or http://www.AllredRoster.com will take you to the same place.
Another way to get there is by using the decimal equivalent of its dotted-decimal address: http://3463778370
Try out the calculator by typing in 206 117 16 66 (without the periods)

Enter IP address: . . . Binary Octets
32-Bit Binary
Decimal
Back
Copyright © 2001 Donald Clemont Allred. All Rights Reserved.

Related Posts Plugin for WordPress, Blogger...