Tuesday, June 14, 2011

DoS aTtAcKs

same disclaimer

okay so you want a server to be put down......well pretty easy job as we can fllod that server with tcp messages....once the server starts flooding the site is slowed down and when the server starts to reject the message..the site stops opening...this type of attack is called denial of service(dos) attack....so, this seems to be quite simple....but you can do it either by a botnet which we will discuss later..or you can do it simply (as simple way is the best way) by using a software called low ion orbit cannon (LOIC) this is not as powerful as a botnet but still a good software to work with.. so as i dont host any software you can download it from google easily.....
dos is further enhanced by another attack ie.ddos or double denial of service (ddos) attack... we'll discuss it in some other post

Saturday, June 11, 2011

ReTrIeVE PaSswOrD ProTeCtEd DaTa

okay so same disclaimer for this post too...

now sometimes you lock a folder, memorycard, or any other data file and forget your password that you've kept....there are many ways to get through it but in this post we'll talk about some attacks that can open up your passwords......now the first one we'll gonna be talking about is the dictionary attack..

1.DICTIONARY ATTACK
now in this attack we just upload a dictionary of your choice to a software that checks its each and every word in the password field and as the password is cracked it stops working.. now in this attack the password should e be a valid dictionary word which is always not applicable...but if the folder have a dictionary password you'll be very happy..if not then don't get angry just go for the brute force attack..


2.BRUTE FORCE ATTACK
this type of attack requires a lot of patience and patience and patience....it is a slow in fact very slow process but the success rate is 100% to crack the password....in this process or attack we just tells the software to make every possible key combination of any length which can have any valid keyboard keys and check them as the password so if the password is about 11 alphabets long with 3 numbers.......it becomes a very difficult and slow process but if you have a patience of a week or more then you can definitely follow this....
this attack can also be applied on Facebook by a special software namely facebooz.. as we all know for more than 5 or more wrong password attempts the facebook.com asks us to enter the code from the image so this attack is inapplicable there.. thats why we use m.facebook.com as it never asks for the captcha...
now this attack can also be done to break a phone lock or any other password.....
remember the success rate is 100% but the time required is very long

Friday, June 10, 2011

ArP pOiSoniNg

again same disclaimer as other posts


now, like in my previous post i talked about arp (address resolution protocol) poisoning...this can be done by many softwares but the most common and easy to use is the cane and abel by oxid.it...its very user friendly as in my days i didnt even needed a tutorial for that... so now once you download it from google (afterall google is a hacker's best friend) you'll install it and will see a C with green background on the dekstop..open it

once you open it now you'll have to switch the sniffer on from the bar in the middle from the top...
after switching on the sniffer go to the sniffer tab... click the blue + singn from the top and click ok...
what we have done is that we have traced all the mac addresses in your network now..go to apr tab in the bottom and click the + sign at top again..then select the data sender(your wifi or server) on the left
& the computer whose recieveng the data you want to see on the reight and click ok..& start the arp poisoning from the arp tab which is with the sniffer tab...
after that move to the passwords tab near the arp tab and se all the passwords he is accessing
now what basically this software does is that it spoofed you as the server and the data is sent through you so you can access it.....
this software has more cool features like it can show you the admin pass of windows of the target..you can make a vpn etc etc.
overall a cool software to play with

Thursday, June 9, 2011

ThE SmS trIcKs

again this is for educational purpose only..


we all know about the sms sites that are famous for free msgs eg:160by2.com etc......bt few of us know about msg spoofing
msg spoofing is a trick in which you can send msg from someones no. to some other no...........
a bit confused??????
ok let me explain .... for eg-you can send msg from your friends no. to his girlfrend that "I WANT A BREAKUP" the best part is your friend will never come to know about this untill he is smart enough.......
the site is www.smsglobal.com......ok now you'll get 25 free msgs per registration then you"ll have to buy credits......and yes even facebook server cannot recognise a spoofed msg so get your brain running and start updating your friends profile........
this thing has recently created a scam in our area in which a person activates mobile banking on someones phone.....then he called him and asked for the login credentials as a banker and zoop there was a transaction of  $4000.......so plz plz plz never use it that way

SoCiAl NeTwOrK HaCks

all the information provided is for educational purpose only.. i am not responsible for any harm done by these tricks


okhay..
so now a days facebook has become a drug.....everyone is addicted to it...we all want passwords of our friends and family members not to hurt them but just to keep a check on their secrets..social network sites are very difficult to hack (talking about gmail,yahoo,facebook,twitter) this is because the type of protection ie.ssl protection they use....they have no xss vulnerable page... no sql vulnerability....etc etc etc... so what can we do... the only thing we can do is to do the tricks on our end......so here are some of those tricks

1.KEYLOGGERS
keyloggers save the keystrokes and are best to use to trick someone from your family or friends as it is undetectable and no one can find it untill unless he/she is smart like you......
these are of two types software and hardware...i think these are self explainatory...
the software keyloggers are further of two types simple and network
simple keylogger:  this type of keylogger stays in your pc and save passwords there only in any possible format..
network keyloggers: these keyloggers are great to use as you can install it on any of your friends computer and it will mail the keystroke log to you as per the time limit set..

these can be downloaded pretty easily from google by searching...simple/network keyloggers medifire..nd jst download it from the 1st mediafire link

2.PHISHING
phishing is just fooling someone on the internet by showing him a login page and getting his login credentials...
this method is useless as you can clearly see from the url that the site is fake...for this method you need a fake login page of the site.....and a acoount on any webserver which has free hosting...i personally use x10hosting.com........this method is not so effective....atleast in my case..

you can easily download the page from google.com


3.SOCIAL ENGINEERING
this is nothing but the check of your communication skills or how well you can gather information from someone.....
in this while chatting with the victim you just ask him his security answers which he has put up in the forgot password section but .....you will never get his password you can just change the password and open the account so its worthless i guess...

4.SNIFFING
now from noobe hacking lets get serious and talk some real hacking.......
Sniffing is one of the best ways to improve your networking skills and obviously getting some passwords.....
okhay so we all know that like trvells in packets called quanta...data also travells in packets called.......packets........now if someone is using same wifi as you...you can see what he is doing ...poison his address resolution protocol (ARP poisoning), sniff passwords etc...
now i'll discuss ARP poisoning some other time lets stick to our topic........
you can use wireshark as a good sniffer to sniff passwords from others

5.COOKIE STEALING
stealing cookies is the most efiicient way of getting someones account.......
cookie stealing can be done by uploading a php cookie stealing script to any webserver and posting your friends the link and as soon as they click it.....boom their cookie is stored on your server.......now the main problem of this method is that cookies have certain lifetime.ie.as soon as the victim logs out...the cookie is of no use so your friend needs to be online available on his account to do this hack.........