Wednesday, 31 July 2013

OpIslam: Israeli Hackers Hack HEC(Higher Education Commission) of Pakistan Website

Website of Higher Education Commission of Pakistan was hacked by the Israeli Hackers and Thousands of email addresses, user names and clear text passwords for students with 21667 was published online.

The leaked data from the Pakistan Higher Education Commission has been posted to pastebin with a index of links which link to two further files, 1 clear text and 1 rich text file on two different file hosts.

1 year ago Pakistani Hackers attack Israeli Cyber space and that attack was lead by 1337, who Hack Israeli top domains and other attack lead by Hitcher. This show's that these kind of attack on Pakistani Cyber space may resultant very messy for Israeli cyber space.


"We anti islam
We Love israel <3
We Do Not Forgive
We DO Not Forget
Expext Us
Stop islam
israel is Terrorist

We site http://stz-hacker.noads.biz/

https://www.facebook.com/TheHackersStzNews

Leaked by Hackers sTz
48000 users hec.gov.pk Hacked
text http://www.mediafire.com/?cbb0bip1po8hhi8
text http://www.f2h.co.il/y01jphoxfix1
text rtf http://www.mediafire.com/?zbv4iz1b5g455a1
text rtf http://www.f2h.co.il/8ako95gm9arc"


This attacks on major sites of countries rise many question for Pakistani security experts and Pakistani hackers. 

Tuesday, 30 July 2013

Hack a website using remote file inclusion

Remote file inclusion is basically a one of the most common vulnerability found in web application. This type of vulnerability allows the Hacker or attacker to add a remote file on the web server. If the attacker gets successful in performing the attack he/she will gain access to the web server and hence can execute any command on it.

Searching the Vulnerability

Remote File inclusion vulnerability is usually occured in those sites which have a navigation similar to the below one

To find the vulnerability the hacker will most commonly  use the following Google Dork
“inurl:index.php?page=”

This will show all the pages which has “index.php?page=” in their URL, Now to test whether the website is vulnerable to Remote file Inclusion or not the hacker use the following command

So the hacker url will become


If after executing the command the homepage of the google shows up then then the website is vulnerable to this attack if it does not come up then you should look for a new target. In my case after executing the above command in the address bar Google homepage shows up indicating that the website is vulnerable to this attack

Now the hacker would upload the shells to gain access. The most common shells used are c99 shell or r57 shell. I would use c99 shell. 
The hacker would first upload the shells to a webhosting site such as ripway.com, 110mb.com etc.

Now here is how a hacker would execute the shells to gain access. Lets say that the url of the shell is


Now here is how a hacker would execute the following command to gain access


Remember to add “?” at the end of url or else the shell will not execute. Now the hacker is inside the website and he could do anything with it...

Bluejacking Bluetooth+Hijacking

BlueJacking is one of the mostly harmless activity can happen with any multimedia cell phone. Though it is an unintended and illegal use of a technical feature, mostly hard-core geeks do not find sufficient technical challenge in the activity. For the more serious hacker and crackers looking to explore the security features of their Handset. BlueTooth hacking tools (BlueJacking Tools) should be used in a legal and in ethical way. Remember one thing real people own these devices, and rely on them for everyday tasks, so please remember to “Do Not Harm”.

Now, What Is Exactly Bluejacking ??

BlueTooth Hijacking or BlueJacking is a technique which used to sending unsolicited messages over Bluetooth to Bluetooth enabled devices such as mobile phones, PDAs or laptops, computers, sending a vCard which typically contains a message in the name field to another Bluetooth enabled device via the OBEX protocol.

As I already said, Bluejacking is usually harmless, however because BlueJacked people generally don’t know what has happened, they may think that their phone is malfunctioning. A BlueJacker will only send a text message, but in these days with modern phones it is possible to send sounds, clips and images as well. Bluejacking has been used in marketing campaigns to promote advergames and products.


In nowadays, With the increase in the availability of Bluetooth enabled devices (Phone, PDA etc etc), it is often reported that these devices have become vulnerable to virus, Trojan, malware attacks and even complete take over of devices through a trojan horse program although most of these reports are easily debunked. Bluejacking is also confused with Bluesnarfing which is the way in which mobile phones are illegally hacked via Bluetooth.

Tools For Bluejacking

There are many tools that have been developed for BlueJacking, most of the development happened in the 2008 to 2012, where multiple new bluetooth vulnerabilities were discovered. There are not any specific or official tool but are there many tools to assist someone in bluejacking, only a few hidden tools are available for the more sinister  “BlueSnarfing” or “BlueBugging”. Most commonly used bluetooth software are “Bloover” and “Easyjack”
BlueJacking is very useful for hackers on that device which do not require authentication and in these days almost (99%) handsets are required authentication before making any connection to another Bluetooth enable handset.

Countermeasures

Well after all if you how we can attack with BlueJack, we should also know how we can prevent from BlueJack and what are the countermeasures against BlueJacking. So I am going to give some Countermeasures:-

1. To Prevent BlueJacking, make sure that your device’s bluetooth is turn off in certain public areas like shopping centers, movie theaters, coffee houses, bars, university and electronic stores.


2. Set your Bluetooth device to invisible or hidden mode from the main menu. This will prevents the sender from seeing your device.

3. Turning your Bluetooth invisible remains a good option when you normally don’t connect with other devices. Enable visibility only when you need to pair your device with another.

4. Ignore BlueJacking messages by refusing or deleting them. Consider BlueJacking the same way you think about spam.

5. Attackers or Hacker begin BlueJacking by placing a message in the name field of their phone like, “Special Offer” or “wow!! you won this prize, enter 123 to unlock” Next, they look for enabled devices in the area and select the one they want to BlueJack. They usually send these messages via Bluetooth.

How to become anonymous on Internet and access any block site

Hotspot Shield protects your entire web surfing session; securing your connection at both your home Internet network & Public Internet networks (both wired and wireless). Hotspot Shield protects your identity by ensuring that all web transactions (shopping, filling out forms, downloads) are secured through HTTPS. Hotspot Shield also makes you private online making your identity invisible to third party websites and ISP’s. Unless you choose to sign into a certain site, you will be anonymous for your entire web session with Hotspot Shield. We love the web because of the freedom that it creates to explore, organize, and communicate. 
Hotspot Shield enables access to all information online, providing freedom to access all web content freely and securely. Secure your entire web session and ensure your privacy online; your passwords, credit card numbers, and all of your data is secured with Hotspot Shield. Standard antivirus software protects your computer, but not your web activities.
That's why Anchor Free is pleased to offer Hotspot Shield. Our application keeps your Internet connection secure, private, and anonymous.


100% Security Through a VPN


Hotspot Shield creates a virtual private network (VPN) between your laptop or iPhone and our Internet gateway. This impenetrable tunnel prevents snoopers, hackers, ISP’s, from viewing your web browsing activities, instant messages, downloads, credit card information or anything else you send over the network. Hotspot Shield security application is free to download, employs the latest VPN technology, and is easy to install and use.

Hotspot Shield runs on:
  • Windows 7
  • Windows XP
  • Windows 2000
  • Windows Vista
  • Mac OS X (10.5 Leopard)
  • Mac OS X (10.6 Snow Leopard)
  • Mac OS X (10.7 Lion)

You will be able to download this software on given link DOWNLOAD NOW

NOTE: - This tutorial is only for learning purpose and i am not responsible for any type of harm.

Control Mouse Movement by your Hand or Head Gestures with NPointer



if you need to work much on the computer (like me) and tend to take small breaks to sit back and lean on the chair, then you must have felt the need of some wireless mouse controller then this post is worth reading. In case you just wish to have some gesture controlled mouse controller, then also this post is going to interest you.

There are lot of tools in the market using which you can control your mouse without any direct contact. Some of them use the webcam to recognize your movements and convert the signals into mouse movements. One good tool that does the same and does well is called the NPointer.



NPointer is an application for gestural computer control in which hand movements are recorded by the webcam connected to your PC and then translated into the mouse movements. The application can also decode the usual mouse operations like clicks, double-clicks, drags and scrolls. Also, disabled people can also use the head movements to control the computer.

To get started you just need to install the tool in your system and then configure it to recognize your hand/head movements. If you plan to use your hand for the mouse control, then place them on the table and keep the webcam straight up. You may wave the hands in air too but table method is better for error free recognition.



 You then need to configure some settings like Motion Speed (how fast the pointer will move compared to the hand movement), Acceleration (how fast the pointer accelerates when hand motion speed changes), Menu timeout (how long the pointer should stay idle before action menu appears) and Movement cut-off (how fast the hand should move to ignore the movement. This is used when you wish to remove the hands without disturbing the pointer position). If you check the Head/Frontal Control box, then you can use you head in place of hands to control the mouse movements.

You will now see some controls on the screen which can be used to perform the same operations as performed otherwise. The tool is free to use and works well on all versions of Windows. You can read more about it at the link below.


Download NPointer

How Antivirus Software Works

Due to ever increasing threat from virus and other malicious programs, almost every computer today comes with a pre-installed antivirus software on it. In fact, an antivirus has become one of the most essential software package for every computer.
Even though every one of us have an antivirus software installed on our computers, only a few really bother to understand how it actually works! Well, if you are one among those few who would really bother to understand how an antivirus works, then this article is for you.


How Antivirus Works:

An antivirus software typically uses a variety of strategies in detecting and removing viruses, worms and other malware programs. The following are the two most widely employed identification methods:

1. Signature-based dectection (Dictionary approach)

This is the most commonly employed method which involves searching for known patterns of virus within a given file. Every antivirus software will have a dictionary of sample malware codes called signatures in it’s database. Whenever a file is examined, the antivirus refers to the dictionary of sample codes present within it’s database and compares the same with the current file. If the piece of code within the file matches with the one in it’s dictionary then it is flagged and proper action is taken immediately so as to stop the virus from further replicating. The antivirus may choose to repair the file, quarantine or delete it permanently based on it’s potential risk.
As new viruses and malwares are created and released every day, this method of detection cannot defend against new malwares unless their samples are collected and signatures are released by the antivirus software company. Some companies may also encourage the users to upload new viruses or variants so that, the virus can be analyzed and the signature can be added to the dictionary.
Signature based detection can be very effective, but requires frequent updates of the virus signature dictionary. Hence, the users must update their antivirus software on a regular basis so as to defend against new threats that are released daily.

2. Heuristic-based detection (Suspicious behaviour approach)

Heuristic-based detection involves identifying suspicious behaviour from any given program which might indicate a potential risk. This approach is used by some of the sophisticated antivirus software to identify new malware and variants of known malware.
Unlike the signature based approach, here the antivirus doesn’t attempt to identify known viruses, but instead monitors the behavior of all programs.
For example, malicious behaviours like a program trying to write data to an executable program is flagged and the user is alerted about this action. This method of detection gives an additional level of security from unidentified threats.
File emulation: This is another type of heuristic-based approach where a given program is executed in a virtual environment and the actions performed by it are logged. Based on the actions logged, the antivirus software can determine if the program is malicious or not and carry out necessary actions in order to clean the infection.
Most commercial antivirus software use a combination of both signature-based and heuristic-based approaches to combat malware.

Issues of Concern:

Zero-day threats: A zero-day (zero-hour ) threat or attack is where a malware tries to exploit computer application vulnerabilities that are yet unidentified by the antivirus software companies. These attacks are used to cause damage to the computer even before they are identified. Since patches are not yet released for these kind of new threats, they can easily manage to bypass the antivirus software and carry out malicious actions. However, most of the threats are identified after a day or two of it’s release, but damage caused by them before identification is quite inevitable.
Daily Updates: Since new viruses and threats are released every day, it is most essential to update the antivirus software so that the virus definitions are kept up-to-date. Most software will have an auto-update feature so that, the virus definitions are updated whenever the computer is connected to the Internet.
Effectiveness: Even though an antivirus software can catch almost every malware, it is still not 100% foolproof against all kinds of threats. As explained earlier, a zero-day threat can easily bypass the protective shield of the antivirus software. Also virus authors have tried to stay a step ahead by writing “oligomorphic“, “polymorphic” and, more recently, “metamorphic” virus codes, which will encrypt parts of themselves or otherwise modify themselves as a method of disguise, so as to not match virus signatures in the dictionary.
Thus user awareness is as important as antivirus software; users must be trained to practice safe surfing habits such as downloading files only from trusted websites and not blindly executing a program that is unknown or obtained from an untrusted source. I hope this article will help you understand the working of an antivirus software.

Chat with Friends through ms dos Command Prompt

1) All you need is your friend's IP Address and your Command Prompt.

2) Open Notepad and write this code as it is.....!

@echo off
:A
Cls
echo MESSENGER
set /p n=User:
set /p m=Message:
net send %n% %m%
Pause
Goto A


3) Now save this as "Messenger.Bat".


4) Open Command Prompt.


5) Drag this file (.bat file) over to Command Prompt and press 
Enter.


6) Now, type the IP Address of the computer you want to contact and press enter


7) Now all you need to do is type your message and press Enter.Start Chatting.......!

Share for anyone..........................