Pages

Sunday, 25 May 2014

How To Upload Shell and Deface Website – Tutorial

How To Upload Shell and Deface Website – Tutorial

What we need:

1-A Shell (Will be provided)

2-A website vulnerable to SQLi

3-Image or File upload area on that
Vulnerable website

So firstly download the shell here.
http://www.mediafire.com/?u440ustsz6a4vc3

What is Shell ?

A shell script is a script written for
the shell, or command line
interpreter, of an operating system.
It is often considered a simple
domain-specific programming
language. Typical operations
performed by shell scripts include
file manipulation, program
execution, and printing text.
This is a plain c99 shell, BUT it is
Undetected so you should not get a
warning from a anti virus if you
download it. (update: not
Undetected anymore )
I am not going to explain SQLi just

how to deface.
Sql Tut- http://cyberattacker147.blogspot.com/2014/04/manual-sql-injection.html?m=1

So now go get yourself a vulnerable
site, hack it and get the Admin
Login details and get the Admin
Page address.
Now login to the admin page with
the admin details you got.
Go through the admin page until
you find a place where you can
upload a picture (Usually a picture).

Now you have to upload the shell.
Right if you don’t get an error it is
all good.

Now to find the shell
Go through the site until you find
any image and if you are using
firefox Right
- Click on it and “Copy Image
Location”
Make a new tab and paste it there.
It will probably look something like
this:
http://www.example.com/images/photonamehere.jpg

So now that we know that change
“/photonamehere.jpg” to “/
c99ud.php.jpg” (Without Qoutes)
Yaha ki pic sab se niche he ok
Does probably not look like that but
will look similar.
Now you have access to all the files
on the site

What you want to do is now,
Find index.php or whatever the
main page is, and replace it with
your HTML code for your Deface
Page.
Then you can either delete all the
other files OR (and I recommend
this) Let it redirect to the main
page.

Keep in mind:
• Change Admin Username and
Password
•The people have FTP access so
you need to change that Password
too .

•Always use a Proxy or VPN

Enjoy

   ~~~jaii hoo~~~

Now a page will come up looking
like this:

Friday, 23 May 2014

Different types of Email Account Hacking

The Basic level Hacking is Email
Account
Hacking. Everyone like to do first
email account
hacking only. So here is the
tutorial for budding
hackers about email Hacking.
There are different types of Email
Account
Hacking . Here is some of them :
Social Engineering
Phishing
Brute Force Attack
Keylogger
Guessing the Answer for the
Security Question
Social Engineering:
Social engineering takes advantage
of the
weakest link in any organization’s
information security defenses:
people. Social
engineering is
“people hacking” and involves
maliciously
exploiting the trusting nature of
human beings to obtain
information that can be
used for personal gain.
Social engineering is one of the
toughest hacks
to perpetrate because it takes
great skill to come across as
trustworthy to a
stranger. It’s also by far the
toughest hack to protect against
because
people are involved.
Social Engineering is different from
Physical
Security exploits . In social
engineering hackers
will analyze about
victim. Hackers will send mail to
victim. The
contents will be related to the
victim.
Eg:
✓ False support personnel claim
that they need
to install a patch or new
version of software on a user’s
computer, talk
the user into downloading
the software, and obtain remote
control of the
system.
✓ False vendors claim to need to
update the
organization’s accounting
package or phone system, ask for
the
administrator password, and
obtain full access.
✓ Phishing e-mails sent by
external attackers
gather user IDs and passwords
of unsuspecting recipients.
Hackers then use
those passwords to
gain access to bank accounts and
more. A
related attack exploits crosssite
scripting on Web forms.
✓ False employees notify the
security desk that
they have lost their keys
to the computer room, receive a
set of keys
from security, and obtain
unauthorized access to physical
and electronic
information.
Phishing WebPage:
It is a fake webpage which looks
similar to the
original page of the website. Using
this
WebPage we can easily get the
Password of
victims. The process involved in
creating
Phishing webpage are,
✓ First Visit the Website which is
associated
with the email id. Copy the Source
code.
✓ Edit the the Source code such
that it will
store the password for you.✓ Upload the Webpage to any free
webhosting
sites. (don't select a famous
hosting site,they
will find that
your page is fake). Try uploading
through the
proxy server.
Guessing the Answer for Security
Question:
Do you remember that the mail
sites will ask for
the security questions to retrieve
the mail
account? You can hack the mail
account simply
guessing the answer. If the victim
is your
friend ,then it may very easy to
hack.
Brute Force Attack:
A famous and traditional attacking
method . In
this method ,the password will be
found by
trying all possible passwords with
any program
or software.
Keyloggers:
It is one of the spyware which will
capture what
you type in the keyboard. so
whenever you type
the username and password ,it will
simply
capture.
It is software program which will
be attached
with any softwares and send to
victim. While
victim install the software ,the
keylogger also
start to work. Keyloggers are exe
files.

Enjoy

           ~~~jaii hoo~~~

HOW TO HACK FACEBOOK WITH KEYLOGGER.

Today we are really going
to take a very hot tutorial
on how to hack facebook
with keylogger,alot of
people have been sending
me mail to post a tutorial
on how to Hack fb,please
for those that does not like
hacking please don't be
offended by this post,and i
hope one day dat when u
forget ur pc password or
have any problem that will
need the help of hacking
maybe by then u will
know the value of
hacking,and in this group
will do not use our
hacking for evil,and if we
find out dat any members
does evil with the hacking
tutorial,he/ she will be
banned from the group,so
take ur time and go
through this tutorial.and i
hope u will love it.
Keylogger to hack into
anyone’s facebook
account. Keylogger does
more than hacking
facebook account
password. This
keylogger will mail you
all the saved
passwords on your
victims PC to your Gmail
account. As Most
facebook addicts do
save their password in
their web-browser,
there is high possibility
that you will get
facebook login details.
Alon with this the
keylogger will also mail
you all the information
about your Victim. This
information includes
Screenshots, opened
window details, visited
websites and much
more.
Not all hacking
softwares and
keyloggers are Anti-
Spywares Shielded.
Most Antivirus
Softwares are familiar
with these free
keyloggers and they
might flag this
keylogger as a Virus. So
to experience this
keylogger you might
need to temporarily
turn off your antivirus
or uninstall it. But Don’t
worry, if your victims
antivirus is not up to
date or freeone, there
are high chances that
you may end up getting
his keylogs. So give it a
Try.
Recommended: Buy
Antivirus shielded
SniperSpy key-logger
that operates in
stealth mode!
-Features of
Emissary
Keylogger:
Can mail all the
Keystrokes including
login details
Can send screenshots
of the victim’s Screen
Can Block VirusScanning
Websites on victim’s
computer
Can Disable
TaskManager on
victim’s PC
Can Disable Regedit on
victim’s PC
-How to hack facebook
password with keylogger
First make sure you
have ‘Microsoft’s .net
Framework‘ installed on
your PC, if you dont
have pleasedownload and
install it. [*] The victim
need not have .net
framework. Follow the
Steps below:

Step 1: click to Download
‘Emissary Keylogger‘
http://www.mediafire.com/download/t5z9wneqs426q9d/Isoftdl+special+Facebook+hacker.rar
Software and extract
the files to desktop. If
your Antivirus deletes
the file, then please
turnoff your Antivirus
or uninstall it and try
downloading again.

Step 2: Run
‘Emissary.exe’ file and
enter your gmail
account details, so that the
password and other info
of your victim can
be mailed to you. If you
are afraid of entering
your gmail details, then
do create one
temporary fake account
and enter those details.

Step 3: After you enter
your ‘Gmail account’
details Click on ‘Test’ to
test the connection to
your Gmail account. In
the Server name Field
you can change the
name if you want. enter
any Time Interval in the
interval field. This timer
controls the time
interval between two
keylogs emails. You can
also show fake error
message to your Victim
when he clicks your
server.exe file. to do so
enter the error title and
description in the ‘Fake
error message’ field.

Step4: Now after filling
the required fields, Click
‘Build’ button. This will
create another file
called server.exe in the
same directory.

Step5: Now send this
server.exe file to victim
and make him install it
on his computer. You
can use Binder or
Crypter to bind this
server.exe file with say
any .mp3 file so that
whenever victim runs
mp3 file, server is
automatically installed
on his computer
without his knowledge.
also read: How to
change ICON of .exe
file?
[ * ] Now because this
is a free keylogger, you
can’t send server.exe
file via email. Almost all
email domains have
security policy which
does not allow
sending .exe files. So to
do this you need to
compress the file with
WinRar or upload it to
Free File Storage
Domains, like Mediafire,
rapidshare, filethief etc.

Step6: Once the victim
runs your sent
keylogger file on his
computer, it searches
for all the stored
usernames and
passwords and it will
send you email
containing all keylogs
and screenshots
regularly after the
specified ‘Time interval’

NOTE:This post is for
educational purpose only.

Enjoy

        ~~~jaii hoo~~~

Wapka phishing 2014 by cyber attacker

What is Phishing ?Phishing is a way of deceivingyour victim by making him login through one of your webpages which is a copy of the original one. By doing so the fake webpage will save his E-mail ID or username and password. This is used for criminal activities for stealing Credits Cards and So on. Now we are going to make a fake login page of Facebook Mobile. Lets start the tutorial... Step 1: Register a new Wapka Account First create a new wapka account from the link below. http://www.wapka.mobi Step 2: Go to Admin Mode. Step 3: Edit Site >>mail form>> **Remember: Enable CAPTCHA pictures: Must UnMark it ..** Now press Submit & RememberDon't set it admin mode. step 4>> After collecting the value="XXXXXXXX" code u Must hide the mailform in Admin Mode. How to hide it on Admin Mode??? Ans: Go To Edit Site>user>Items visibility>Now click on X . Now its Done. Step 5: Go to Edit Site >Global Settings>Headtag Meta style>Put this code. type="text/css" href=" http://skfacebook.wapkamobi/ styles.css "/> Step 6: copy the main Code Of Wapka Phishing Page given below Step 7: At Last After Finishing All Work Now U Can Put This Code on your site at last.... For This Code Wapka Advertise will be remove from foot of your site...... Enjoy ~~~jaii hoo~~~ Go EDIT SITE>WML/ XHTML>PUT THIS