Recent Articles
Showing posts with label internet. Show all posts
Showing posts with label internet. Show all posts

Tuesday, June 4, 2013

How to use Google for Hacking

Tuesday, June 4, 2013 - 2 Comments

Google serves almost 80 percent of all search queries on the Internet, proving itself as the most popular search engine. However Google makes it possible to reach not only the publicly available information resources, but also gives access to some of the most confidential information that should never have been revealed. In this post I will show how to use Google for exploiting security vulnerabilities within websites. The following are some of the hacks that can be accomplished using Google.

1. Hacking Security Cameras

There exists many security cameras used for monitoring places like parking lots, college campus, road traffic etc. which can be hacked using Google so that you can view the images captured by those cameras in real time. All you have to do is use the following search query in Google. Type in Google search box exactly as follows and hit enter
inurl:”viewerframe?mode=motion”
Click on any of the search results (Top 5 recommended) and you will gain access to the live camera which has full controls.
you now have access to the Live cameras which work in real-time. You can also move the cameras in all the four directions, perform actions such as zoom in and zoom out. This camera has really a less refresh rate. But there are other search queries through which you can gain access to other cameras which have faster refresh rates. So to access them just use the following search query.
intitle:”Live View / – AXIS”
Click on any of the search results to access a different set of live cameras. Thus you have hacked Security Cameras using Google.

2. Hacking Personal and Confidential Documents

Using Google it is possible to gain access to an email repository containing CV of hundreds of people which were created when applying for their jobs. The documents containing their Address, Phone, DOB, Education, Work experience etc. can be found just in seconds.
intitle:”curriculum vitae” “phone * * *” “address *” “e-mail”
You can gain access to a list of .xls (excel documents) which contain contact details including email addresses of large group of people. To do so type the following search query and hit enter.
filetype:xls inurl:”email.xls”
Also it’s possible to gain access to documents potentially containing information on bank accounts, financial summaries and credit card numbers using the following search query
intitle:index.of finances.xls

3. Hacking Google to gain access to Free Stuffs

Ever wondered how to hack Google for free music or ebooks. Well here is a way to do that. To download free music just enter the following query on google search box and hit enter.
“?intitle:index.of?mp3 eminem“
Now you’ll gain access to the whole index of eminem album where in you can download the songs of your choice. Instead of eminem you can subtitute the name of your favorite album. To search for the ebooks all you have to do is replace “eminem” with your favorite book name. Also replace “mp3″ with “pdf” or “zip” or “rar”.

4. Using Google, and some finely crafted searches we can find a lot of interesting information.

For Example we can find:
Credit Card Numbers
Passwords
Software / MP3′s
…… (and on and on and on) Presented below is just a sample of interesting searches that we can send to google to obtain info that some people might not want us having.. After you get a taste using some of these, try your own crafted searches to find info that you would be interested in.
Try a few of these searches:
intitle:”Index of” passwords modified
allinurl:authuserfile.txt
“access denied for user” “using password”
“A syntax error has occurred” filetype:ihtml
allinurl: admin mdb
“ORA-00921: unexpected end of SQL command”
inurl:passlist.txt
“Index of /backup”
“Chatologica MetaSearch” “stack tracking:”
Amex Numbers: 300000000000000..399999999999999
MC Numbers: 5178000000000000..5178999999999999
visa 4356000000000000..4356999999999999
“parent directory ” /appz/ -xxx -html -htm -php -shtml -opendivx -md5 -md5sums
“parent directory ” DVDRip -xxx -html -htm -php -shtml -opendivx -md5 -md5sums
“parent directory “Xvid -xxx -html -htm -php -shtml -opendivx -md5 -md5sums
“parent directory ” Gamez -xxx -html -htm -php -shtml -opendivx -md5 -md5sums
“parent directory ” MP3 -xxx -html -htm -php -shtml -opendivx -md5 -md5sums
“parent directory ” Name of Singer or album -xxx -html -htm -php -shtml -opendivx -md5 -md5sums
Notice that I am only changing the word after the parent directory, change it to what you want and you will get a lot of stuff.

METHOD 2

put this string in google search:
?intitle:index.of? mp3
You only need add the name of the song/artist/singer.
Example: ?intitle:index.of? mp3 jackson

METHOD 3

put this string in google search:
inurl:microsoft filetype:iso
You can change the string to watever you want, ex. microsoft to adobe, iso to zip etc…

“# -FrontPage-” inurl:service.pwd
Frontpage passwords.. very nice clean search results listing !!

“AutoCreate=TRUE password=” 

This searches the password for “Website Access Analyzer”, a Japanese software that creates webstatistics. For those who can read Japanese, check out the author’s site at: coara.or.jp/~passy/ [or.jp]
“http://:@www” domainname
This is a query to get inline passwords from search engines (not just Google), you must type in the query followed with the the domain name without the .com or .net
Another way is by just typing
“http://bob:bob@www”
“sets mode: +k”
This search reveals channel keys (passwords) on IRC as revealed from IRC chat logs.

allinurl: admin mdb

Not all of these pages are administrator’s access databases containing usernames, passwords and other sensitive information, but many are!
allinurl:authuserfile.txt
DCForum’s password file. This file gives a list of (crackable) passwords, usernames and email addresses for DCForum and for DCShop (a shopping cart program(!!!). Some lists are bigger than others, all are fun, and all belong to googledorks. =)
intitle:”Index of” config.php
This search brings up sites with “config.php” files. To skip the technical discussion, this configuration file contains both a username and a password for an SQL database. Most sites with forums run a PHP message base. This file gives you the keys to that forum, including FULL ADMIN access to the database.
eggdrop filetype:user user These are eggdrop config files. Avoiding a full-blown descussion about eggdrops and IRC bots, suffice it to say that this file contains usernames and passwords for IRC users.
intitle:index.of.etc This search gets you access to the etc directory, where many many many types of password files can be found. This link is not as reliable, but crawling etc directories can be really fun!
filetype:bak inurl:”htaccess|passwd|shadow|htusers” This will search for backup files (*.bak) created by some editors or even by the administrator himself (before activating a new version). Every attacker knows that changing the extenstion of a file on a webserver can have ugly consequences.
Let’s pretend you need a serial number for windows xp pro.
In the google search bar type in just like this – “Windows XP Professional” 94FBR
the key is the 94FBR code.. it was included with many MS Office registration codes so this will help you dramatically reduce the amount of ‘fake’ porn sites that trick you.
or if you want to find the serial for winzip 8.1 – “Winzip 8.1″ 94FBR
Credits and More Info http://harshvaghela.blogspot.com
I have shown you this info to let you know that there is a real risk putting your info online. If you do want to buy stuff online make sure the site you are using is secure normally if a site is secure you will see a pop up saying you are now entering a secure part of the site or a symbal of a padlock at the bottom of your browser or just use pay pal, pay pal is very safe to use. But most of the time just use common sense if a site looks cheap it normally hasn’t got the protection to keep your info safe. I am not saying don’t buy stuff online because that is one of the best thing’s about the internet i am just saying be aware of websites that want your bank details and there is no symbal of a padlock at the bottom of your browser

5.Crash a Computer using Flash and Google.

Open up a new flash document. Open up the Actions panel for the stage of the first frame. If it’s in Actionscript 2, write the following:
onEnterFrame = function () {
getURL(“http://www.google.com”, “_blank”);
}
Or if it’s actionscript 3 write the following:
function openGoogle(e:Event):void {
navigateToURL(“http://www.google.com”, “_blank”);
}
stage.addEventListener(Event.ENTER_FRAME, openGoogle);
Press Control-Enter when you’re ready to crash your computer. What this does is repeatedly open up new tabs of Google. But it opens so many Google tabs every second that after maybe 20-30 seconds your computer will barely be able to respond to you mouse clicks or even mouse movements. Usually, any attempt to stop it will result in processing overload and cause the computer to freeze. The only real way to stop this is to force-quit BOTH flash.exe and iexplorer.exe. Some teachers may know enough to do this, but might accidentally close explorer.exe
hope you enjoyed this post. Pass your comments. Cheers!

Tuesday, May 7, 2013

Beware of social engineering phishing attacks on facebook

Tuesday, May 7, 2013 - 0 Comments

Phishing attacks are one of the most common scams on Facebook. The goal of these scams is to obtain your Facebook user name and password. If successful, the scammers can totally take over your Facebook account and use it to spread more spam and scams to your friends. They can also mine everyone in your network for data they can later use for identity theft or other socially engineered attacks.
Here are some examples of popular phishing schemes on Facebook:
  1. Facebook Lottery – You’re likely to receive an email stating you’ve won a sum of money. These can also be advanced fee scams.
  2. Confirm Your Account – Any messages asking you to confirm your account should be viewed with extreme suspicion. If you receive an email like this, don’t follow any links. A better option is to log in to Facebook directly.
  3. Violated a Policy – Hacked accounts often send messages posing as ‘Facebook Security.’ If you encounter one of these scams, you’ll notice that Facebook Security will be spelled with non-traditional characters. This is done to bypass Facebook’s filters. 
  4. Photos & Videos - The scammers attempt to capitalize on our curious nature. You will receive a message from a compromised friend’s account asking you to look at this photo or video. A popular theme is to say the picture is embarrassing or they can’t believe you did that, etc. Other variants of this scam contain files laden with malware.
Most all of these scams direct you to external links to pages designed to look like Facebook. Before logging in to any site, always verify that you are indeed on the main site. Careless and unsuspecting users are often fooled by these tricks.
Below is one example of the photo phishing scheme mentioned above.
do you notice that they were rrecording u lol this is unpleasant lol !!
Other Alternate Messages:
Is this you in this video on facebook, what are you doing LOL? Search on this website for your name
HAHAHAHAHA i can not believe whaat you did in thisss videeo it’s sooo stupid its all overfacebook! Coooopy and Paaaste the url below into your web browser to seeeee , its craazy!Removeee thee Spaces —>
OMG have u seen ur video on here. u should check this out!
Clicking on the link in the scam post will at first direct the user to a Facebook application and then ultimately to a phishing URL:
Scams like this are very common on the Facebook platform. Humans are curious by nature, and the scammers often use this and other emotions to their advantage. Also consider that these messages or updates may come from a friend’s hacked account. Don’t assume any links or messages are legitimate just because they came from a friend. In fact, if you receive them via Facebook chat / message, then there is a good chance that your friend’s account has been compromised. Double check your friends list and remove or block any name that looks suspicious (awkward and non-traditional spellings of Facebook Security, Account Confirmation, etc.)
Never enter your login information when a web page redirects you without first double checking to make sure you are on the legitimate site. A better option is to bookmark Facebook, and only log in from there.


Earn upto Rs. 9,000 pm checking Emails. Join now!

Sunday, May 5, 2013

How to use your android phone to control computer remotely

Sunday, May 5, 2013 - 0 Comments

Are you tired of providing on-site tech support for your friends and family? Providing support remotely is an easy way to help them while maintaining your sanity. If you don't have a computer nearby, but have your Android phone you can still help. Here's how:

Computer setup

Step 1:
On the computer you want to remote control, download "TeamViewer QuickSupport" from TeamViewer. The downloaded file is named TeamViewerQS_en.exe. The program is self-contained so it does not need to be installed.

Step 2:
Double-click on the TeamViewerQS_en.exe file to launch TeamViewer on the computer you want to control.

Step 3:
At the main screen, the numeric ID of that system is listed and a numeric password for that session. Make a note of the ID and password as you'll need that information later.

Step 4:
If you're setting this up on someone else's computer, you may want to create a shortcut for them or place the file on their desktop so they can find it more easily when they need your help. Once you've connected to the computer, a small window with a session list will pop up in the lower right-hand corner.
TeamViewer session list.

Android setup

Step 1:
On your Android phone, install TeamViewer from the Android Market and launch it. In the first box, enter the ID of the "partner" computer. In the second box, enter the password and tap the "Connected to partner" button.

 Step 2:
Once connected, you'll see gesture control instructions.
 

 Step 3:
Close the instruction screen to see the desktop of the remote computer.
TeamViewer connected
.

You've got control! Now you can help your in-law's figure out how to use Netflix streaming or add an RSS feed to Google Reader. You can help someone with just about anything he or she might need help with, without having to physically be there. You can use the mouse, type, print, and even reboot the remote computer.

The Android version of TeamViewer does have a few limitations, compared with the computer version. The Android version does not support local audio, text chat ,video chat, or file transfers. 
 
Earn upto Rs. 9,000 pm checking Emails. Join now!

Friday, April 12, 2013

Friday, April 12, 2013 - 0 Comments

Get all the passwords on LAN

Here is a great tutorial of how to know the passwords on LAN ..... This trick is very efficient . You can know all the passwords on the lan using this . The software CAIN AND ABEL is necessary for that.

Download from this link : download CAIN AND ABEL

-=Step One=-

You want to activate "Sniffer" by activating the button next to the "Open" icon. You will also want to turn on APR which stands for APR Poison Routing. (Don't take POISON literally, It will not actually harm the computer you are piggybacking on)

-=Step Two=-

Switch your active/current tab to "Sniffer," after doing so right click in the middle of the blank fields and click on "Scan MAC Addresses" and make sure "All hosts in my subnet" is clicked with a dot in the circle. You should see several hosts pop up, if they did then you are doing everything correctly so far.

-=Step Three=-

At the bottom of Cain and Abel, you will see a tab called "APR," make that your active/current tab you are viewing under the "Sniffer" tab. Now click on the top white blank box in the "APR" subtab, and go up top and click on the "Add" button. Click on what ever you Routers IP is. Then click the IP of the target computer or whatever you want to piggyback on. Then press OK.

-=Step Four=-

After pressing OK you should see a line in the top box and it will either say IDLE or POISONING. If it says IDLE just give it a couple of seconds for it to start the poisoning. If it is POISONING go down to the bottom again and find "Passwords," make that your current/active subtab. Now passwords and usernames should be popping up under any of the select categories, mine are usually HTTP passwords but, yours might be different.


_________________________________________________________________________________________________









How to detect and block an ARP spoofing 

attack on a LAN

ARP poisoning attacks are the most dangerous MITM attacks when working on a LAN. The most hazardous thing about this attack is that they go unnoticed for a very long time or in some cases they would never be detected if not checked for. No naive internet user is gonna check if he is being poisoned. This would go undetected in a trusted environment like an office or at college. Well then it is the responsibility of the admins to protect their clients from attack.
Detecting an ARP Spoofing attack
Well detecting an ARP attack is fairly easy assuming that the malware responds to standard ARP requests. Here's how you go about detecting a possible attack.

1. Start a network capture using a tool such as tcpdump or Wireshark.
2. Generate some traffic on your machine and then stop the capture.
3. Now analyze the traffic. You don't have to be an expert to do this. Check if you are getting ARP requests or responses from multiple addresses.

If you are getting ARP traffic from sources other than your default gateway there is possibly an eavesdropper. This eavesdropper could also modify what you recieve. A very good application of MITM is 'login credentials stealing', especially from SSL secured websites. Tools such as Ettercap and Cain & Abel can make this possible even for a script kiddie.

This was about detecting an MITM, but there is no manual way to block an MITM, other than bashing up the intruder sitting at the poisoning host machine.

Blocking an ARP Spoofing Attack:

ArpON (Arp handler inspectiON) is a portable handler daemon that make Arp secure in order to avoid Arp Spoofing/Poisoning & co.

This is possible using two kinds of anti Arp Poisoning techniques, the first is based on SARPI or "Static Arp Inspection", the second on DARPI or "Dynamic Arp Inspection" approach.

Keep in mind other common tools fighting ARP poisoning usually limit their activity only to point out the problem instead of blocking it, ArpON does it using SARPI and DARPI policies. Finally you can use ArpON to pentest some switched/hubbed LAN with/without DHCP protocol, in fact you can disable the daemon in order to use the tools to poison the ARP Cache.

Download link: ARP handler inspection





Monday, April 1, 2013

Top 5 free domain name services

Monday, April 1, 2013 - 0 Comments







In this article I provide the reviews of the best free domain name services and detailed descriptions of their main features. And thus we list the reviews of the top 5 free domain name providers according to the features and quality of the offered services and free domains:


  1. FreeDomain.co.nr (free .co.nr domain)
  2. Biz.nf (free .co.nf domain)
  3. Co.cc (free .co.cc domain)
  4. Dot.tk (free .tk domain)
  5. Biz.ly (free .biz.ly domain)
And see the detailed reviews of best free domains below:

Free Domains at .co.nr

FreeDomain.co.nr provides free domain registration service with a very short and easy to remember.co.nr extension. So that, their users get free domains like www.sitename.co.nr that can be used for any free web site, blog, forums, or other web page published on the web.
FreeDomain.co.nr service works in form of URL redirection, so that they support meta tags, URL masking, path forwarding, your very own Favicon, Google Webmaster Tools, etc. However, free .co.nr domains do not support DNS changes and thus they are recommended mainly for beginners.
FreeDomain.co.nr has been providing domain name free services since 2003, so you can probably rely on their service, and it seems they do not add forced ads to free web domains that they offer.


Free Domain at .co.nf

Biz.nf is a free web hosting provider that enables to register a free domain name with .co.nfextension (such as www.sitename.co.nf) and to host it at Biz.nf servers at absolutely no cost.
Biz.nf provides a full featured free domain hosting service that includes both features for advanced users such as PHP hosting, MySQL, CGI, FTP support as well as free website builder tools such as easily installed WordPress blog and Joomla website, and more.
Biz.nf has been in business since 2008, and they offer totally eco-friendlygreen hosting service that can help to save our planet ecology.


Free Domain Name at .co.cc

Co.cc lets Internet users to register free domains with .co.cc extension for personal (non-commercial) use, and they also sell .co.cc domains to businesses in bulk at a very low prices.
In addition to free website domain registration Co.cc also provides mapping of .co.cc domains to Blogger, Window Live, Google Apps and Amazon Associates. Co.cc does support DNS changes and thus CNAME, A, MX, NS, and TXT records.
Update: CO.CC is currently offline, and it seems they have completely closed down there services. If that’s the case, we’ll remove CO.CC soon.



Free Domain at .tk

Dot.tk is a Tokelau (small islands in Pacific Ocean) based company that provides free 2nd level domains with .TK extension, so that free free domain site looks like www.sitename.tk and that is the shortest free domain option available on the web.
Dot.tk enables to register free domains and either redirect them to a website (domain forwarding), or they enable to use ones own name servers, i.e. the DNS changes are allowed. One can also pay for .tk domain and thus obtain the legal registrant rights (free domains do not provide registrant rights and the free site must receive at least 25 visitors in any 90-day period).
Dot.tk guys have been providing free .tk domains since very 2001, however, we were reported their service/servers are a bit slow from time to time..


Free Domains at .biz.ly

Biz.ly free domain host provides a very short free domain with business meaning .biz.ly extension. Unlike the previous provider Biz.nf offers 3rd level free domains such as www.sitename.biz.lythat are registered and hosted at their servers at no additional cost.
Apart from free .biz.ly domains they also provide free hosting services as well as free site builder and blog builder, and many pre-installed tools such as photo album, guestbook, hits counter, webrings, form mailer, site copier, etc.
Biz.ly has been providing free domain names since 2002, and their service is quite simple and thus it is recommended for beginners.


Free Domain at .COM, .NET, .ORG, etc.

And in case you do not mind to pay few dollars to host your web site with reliable and customer focused web hosting provider, you can get a free domain name with .com.net.org.biz.info, or .us extension included with their website hosting plan. We’d suggest to check the following web hosts:
  1. HostGator
  2. iPage
  3. HostMonster
or you can check best 10 web hosting list at PRchecker.info site.

visiting sites

Subscribe

Donec sed odio dui. Duis mollis, est non commodo luctus, nisi erat porttitor ligula, eget lacinia odio. Duis mollis

© 2013 Harsh Vaghela's Blog. All rights reserved.
Designed by SpicyTricks