Showing posts with label HACKING TOOLS. Show all posts
Saturday, 27 September 2014
Hacking Tools
HACKING TOOLS
Names Of Some Tools Use In Professional Hacking or Computer Hacking
- Hide Your Ip
- Nmap
- Net Cat
- Password Variator
- Access Pass View
Hide Your Ip:
Hide your ip is the first and basic rule in hacking.Because you are not the only one who is learning how to hack.So for your security you have to hide your IP ADDRESS.Ip address is a gate way of every computer.You want to hack somebody's computer you have to know his ip address.i will tell you in my next How to get someone's ip address.In this post i will tell you the basics.
Nmap is a very powerful Hacking Tool.It is a professional tool for Hacking...There are two type of ports in a server or computer first type is physical ports and second visual ports..Physical ports used for data transfer or usb etc..But the visual ports are the small gate ways in a server or computer from where data goes in or out.To Hack a computer or server you need to pass through a visual port but Server or computer will not give you the permission to pass.Now here Nmap will help you to pass through.Nmap find's a free visual port on a server or computer to fit in and pass through easyily...This type of professional Hacking is illegal so be careful.
- (Nmap (Network Mapper) is a security scanner originally written by Gordon Lyon (also known by his pseudonym Fyodor Vaskovich) used to discover hosts and services on a computer network, thus creating a "map" of the network )
Nmap features include :
- Host discovery – Identifying hosts on a network. For example, listing the hosts that respond to TCP and/or ICMP requests or have a particular port open.
- Port scanning – Enumerating the open ports on target hosts.
- Version detection – Interrogating network services on remote devices to determine application name and version number.
- OS detection – Determining the operating system and hardware characteristics of network devices.
- Scriptable interaction with the target – using Nmap Scripting Engine (NSE) and Lua programming language.
Nmap can provide further information on targets, including reverse DNS names, device types, and MAC addresses.
Typical uses of Nmap:
- Auditing the security of a device or firewall by identifying the network connections which can be made to, or through it.
- Identifying open ports on a target host in preparation for auditing.
- Network inventory, network mapping, maintenance and asset management.
- Auditing the security of a network by identifying new servers.
- Generating traffic to hosts on a network.
Basic commands working in Nmap
- For target specifications:
nmap <targets' URL's or IP's with spaces between them (can also use CIDR notation)> e.g. : scanme.nmap.org, gnu.org/24, 192.168.0.1; 10.0.0-255.1-254 (The command is nmap scanme.nmap.org and similar)
- For OS detection:
nmap -O <target domain or IP address>
- For version detection:
nmap -sV <target domain or IP address>
- For configuring response timings (-T0 to -T5 :increasing in aggressiveness):
nmap -T0 -sV -O <target domain or IP address>
- For SYN-stealth scanning by sending TCP packets with the SYN flag set:
nmap -sS -p <port of target> <IP address of target>
NET CAT:
Netcat is a computer networking service for reading from and writing to network connections using TCP or UDP. Netcat is designed to be a dependable back-end that can be used directly or easily driven by other programs and scripts.Net cat is very interesting and awesome networking service.Net cat is a base in Hacking.It works like an head quarter.Some features of Net Cat are listed.
- Outbound or inbound connections, TCP or UDP, to or from any ports
- Full DNS forward/reverse checking, with appropriate warnings
- Ability to use any local source port
- Ability to use any locally-configured network source address
- Built-in port-scanning capabilities, with randomization
- Built-in loose source-routing capability
- Can read command line arguments from standard input
- Slow-send mode, one line every N seconds
- Hex dump of transmitted and received data
- Optional ability to let another program service establish connections
- Optional telnet-options responder
CLICK HERE TO DOWNLOAD NET CAT MANUAL!!
Opening a raw connection to port 25 (like SMTP)
nc mail.server.net 25
Setting up a one-shot webserver on port 8080 to present the content of a file
{ echo -ne "HTTP/1.0 200 OK\r\nContent-Length: $(wc -c <some.file)\r\n\r\n"; cat some.file; } | nc -l 8080
The file can then be accessed via a web browser under http://servername:8080/. Netcat only serves the file once to the first client that connects and then exits, it also provides the content length for browsers that expect it. (This should work fine in a LAN, but probably may fail with any kind of firewall between.).
Checking if UDP ports (-u) 80-90 are open on 192.168.0.1 using zero mode I/O (-z)
nc -vzu 192.168.0.1 80-90
Note that UDP tests will always show as "open". The
-uz argument is useless.Test if UDP port is open: simple UDP server and client
This test is useful, if you have shell access to the server that should be tested, but you do not know whether there is a firewall blocking a specific UDP port on the server.
On the listening host, i.e. on the server whose port needs to be checked, do the following:
nc -ul 7000
On the sending host, do the following – note that
servname is the hostname of the listening host:nc -u servname 7000
If text typed on the sending host (type something and hit enter) is displayed also on the listening host, then the UDP port 7000 is open. If it is not open, you will get an error such as "Connection refused".
There is a caveat. On some machines, IPv6 may be the default IP version to use by netcat. Thus, the host specified by the hostname is contacted using IPv6, and the user might not know about this. Ports may appear closed in the test, even though they would be open when using IPv4. This can be difficult to notice and may cause the false impression that the port is blocked, while it is actually open. You can force the use of IPv4 by using adding
-4 to the options of the nc commands.Pipe via UDP (-u) with a wait time (-w) of 1 second to 'loggerhost' on port 514
echo '<0>message' | nc -w 1 -u loggerhost 514
Port scanning
An uncommon use of netcat is port scanning. Netcat is not considered the best tool for this job, but it can be sufficient (a more advanced tool is nmap)
nc -v -n -z -w 1 192.168.1.2 1-1000
The "
-n" parameter here prevents DNS lookup, "-z" makes nc not receive any data from the server, and "-w 1" makes the connection timeout after 1 second of inactivity.Proxying
Another useful behaviour is using netcat as a proxy. Both ports and hosts can be redirected. Look at this example:
nc -l 12345 | nc www.google.com 80
Port 12345 represents the request
This starts a nc server on port 12345 and all the connections get redirected to
google.com:80. If a web browser makes a request to nc, the request will be sent to google but the response will not be sent to the web browser. That is because pipes are unidirectional. This can be worked around with a named pipe to redirect theinput and output.mkfifo backpipe nc -l 12345 0<backpipe | nc www.google.com 80 1>backpipe
The "
-c" option may also be used with the 'ncat' implementation:ncat -l 12345 -c 'nc www.google.com 80'
Using a named pipe is a more reliable method because using "
-c" option provides only a one-shot proxy.
Another useful feature is to proxy SSL connections. This way, the traffic can not be viewed in wire sniffing applications such as wireshark. This can be accomplished on UNIXes by utilizing mkfifo, netcat, and openssl.
mkfifo tmp mkfifo tmp2 nc -l 8080 -k > tmp < tmp2 & while [ 1 ] do openssl s_client -connect www.google.com:443 -quiet < tmp > tmp2 done
Making any process a server
netcat can be used to make any process a network server. It can listen on a port and pipe the input it receives to that process.
The
-e option spawns the executable with its input and output redirected via network socket.
For example, it is possible to expose a bourne shell process to remote computers.
To do so, on a computer A with IP 192.168.1.2, run this command:
nc -l -p 1234 -e /bin/sh
Then, from any other computer on the same network, one could run this nc command:
nc 192.168.1.2 1234 ls -las
And the output one would see might be like this:
total 4288 4 drwxr-xr-x 15 imsovain users 4096 2009-02-17 07:47 . 4 drwxr-xr-x 4 imsovain users 4096 2009-01-18 21:22 .. 8 -rw------- 1 imsovain users 8192 2009-02-16 19:30 .bash_history 4 -rw-r--r-- 1 imsovain users 220 2009-01-18 21:04 .bash_logout ...
In this way, the
-e option can be used to create a rudimentary backdoor. Some administrators perceive this as a risk, and thus do not allow netcat on a computer.Port Forwarding or Port Mapping
On Linux, NetCat can be used for port forwarding. Below are nine different ways to do port forwarding in NetCat (
-c switch not supported though - these work with the 'ncat' incarnation of netcat):nc -l -p port1 -c ' nc -l -p port2' nc -l -p port1 -c ' nc host2 port2' nc -l -p port1 -c ' nc -u -l -p port2' nc -l -p port1 -c ' nc -u host2 port2' nc host1 port1 -c ' nc host2 port2' nc host1 port1 -c ' nc -u -l -p port2' nc host1 port1 -c ' nc -u host2 port2' nc -u -l -p port1 -c ' nc -u -l -p port2' nc -u -l -p port1 -c ' nc -u host2 port2'
Example, see Proxying Netcat#Proxying
Ports and reimplementations
The original version of netcat was a Unix program. The last version (1.10) was released in March 1996.
There are several implementations on POSIX systems, including rewrites from scratch like GNU netcat or OpenBSD netcat, the latter of which supports IPv6. The OpenBSD version has been ported to the FreeBSD base and Windows/Cygwin as well. Mac OS X users can use MacPorts to install a netcat variant. There is also a Microsoft Windows version of netcat available.
Known ports for embedded systems includes versions for the Windows CE (named "Netcat 4 wince") or for the iPhone.
BusyBox includes by default a lightweight version of netcat.
Solaris 11 includes netcat implementation based on OpenBSD netcat.
Socat is a more complex variant of netcat. It is larger and more flexible and has more options that must be configured for a given task.
Cryptcat is a version of netcat with integrated transport encryption capabilities.
In the middle of 2005, Nmap announced another netcat incarnation called Ncat. It features new possibilities such as "Connection Brokering", TCP/UDP Redirection, SOCKS4 client and server support, ability to "Chain" Ncat processes, HTTP CONNECT proxying (and proxy chaining), SSL connect/listen support and IP address/connection filtering. Like Nmap, Ncat is cross-platform.
On some systems, modified versions or similar netcat utilities go by the command name(s)
nc, ncat, pnetcat, socat, sock, socket, sbd.PASSWORD VARIATOR:
Password Variator is software that works like brute force .You give him some character of other computer's password and it will show you the maximum possible passwords ...its a slow way of Hacking. it can only be use when you know some part of password of other computer..
Often users run into a problem with their passwords because original password was mistyped. Password Variator will help you in this situation.
Just enter the password and Password Variator will build a file with all possible variations, typos and mistypes inside. Then you can use that file as a dictionary in your password recovery program.
You can use Password Variator with any password recovery software that supports dictionary attack.
Password Variator emulates following typos:1. missed char (for example: sample -> smple)2. duplicated char (for example: sample -> saample)3. extra char (for example: sample -> sqample).4. wrong order (for example: sample -> sampel)5. wrong case (for example: sample -> SAMPLE or Sample -> SAmple)Password Variator can emulate single, double and triple typos.
Just enter the password and Password Variator will build a file with all possible variations, typos and mistypes inside. Then you can use that file as a dictionary in your password recovery program.
You can use Password Variator with any password recovery software that supports dictionary attack.
Password Variator emulates following typos:1. missed char (for example: sample -> smple)2. duplicated char (for example: sample -> saample)3. extra char (for example: sample -> sqample).4. wrong order (for example: sample -> sampel)5. wrong case (for example: sample -> SAMPLE or Sample -> SAmple)Password Variator can emulate single, double and triple typos.
ACCESS PASS VIEW:
An Old Way Of Hacking...
This utility reveals the database password of every password-protected mdb file that created with Microsoft Access 95/97/2000/XP or with Jet Database Engine 3.0/4.0 .
It can be very useful if you forgot your Access Database password and you want to recover it.
* In Access 2000/XP files, this utility cannot recover passwords that contains more than 18 characters.
* This utility shows only the main database password. It cannot recover the user-level passwords.
Versions History
================
19/04/02 Version 1.12: Added command-line and drag & drop support.
18/02/02 Version 1.11: Added more file types to the list: mda files, mde files and all files.
31/01/02 Version 1.1 : Added support for Access 2000/XP files.
15/02/00 Version 1.0 : First release. Shows passwords of Microsoft Access 95/97 files.
Using Access PassView
=====================
Using the Access PassView utility is very simple. it doesn't need any installation process or additional DLL files.
You can run the "accesspv.exe" file from any directory you want, and start to work.
In order to get the password from your mdb file, click the "Get Password" button, select the mdb file and the password will be shown in the main text box.
There are also 2 alternative ways for getting the password of mdb file:
1. Drag & Drop: You can get the password of your mdb file by dragging it from the explorer window into the Access PassView window.
2. Command-line: You can get the password of your mdb file by adding the filename as command-line parameter.
For example:
accesspv.exe c:\access\mymdb.mdb
Keep coming to our website for more knowledge!!!
Tuesday, 23 September 2014
Facebook Hacking
How Hack Facebook......"(Solved)
4 Ways to Hack a Facebook Account:
Despite the security concerns that have plagued Facebook for years, most people are sticking around and new members keep on joining. This has led Facebook to break records numbers with over one billion monthly active users as of October 2012—and around 600 million active daily users.
We share our lives on Facebook. We share our birthdays and our anniversaries. We share our vacation plans and locations. We share the births of our sons and the deaths of our fathers. We share our most cherished moments and our most painful thoughts. We divulge every aspect of our lives. We even clamor to see the latest versions even before they're ready for primetime.
But we sometimes forget who's watching.
We use Facebook as a tool to connect, but there are those people who use that connectivity for malicious purposes. We reveal what others can use against us. They know when we're not home and for how long we're gone. They know the answers to our security questions. People can practically steal our identities—and that's just with the visible information we purposely give away through our public Facebook profile.
The scariest part is that as we get more comfortable with advances in technology, we actually become more susceptible to hacking. As if we haven't already done enough to aid hackers in their quest for our data by sharing publicly, those in the know can get into our emails and Facebook accounts to steal every other part of our lives that we intended to keep away from prying eyes.
In fact, you don't even have to be a professional hacker to get into someone's Facebook account.
It can be as easy as running Firesheep on your computer for a few minutes. In fact, Facebook actually allows people to get into someone else's Facebook account without knowing their password. All you have to do is choose three friends to send a code to. You type in the three codes, and voilĂ —you're into the account. It's as easy as that.
In this article I'll show you these, and a couple other ways that hackers (and even regular folks) can hack into someone's Facebook account. But don't worry, I'll also show you how to prevent it from happening to you.
Method 1: Reset the Password
The easiest way to "hack" into someone's Facebook is through resetting the password. This could be easier done by people who are friends with the person they're trying to hack.
The first step would be to get your friend's Facebook email login. If you don't already know it, try looking on their Facebook page in the Contact Info section.
Next, click on Forgotten your password? and type in the victim's email. Their account should come up. Click This is my account.
It will ask if you would like to reset the password via the victim's emails. This doesn't help, so press No longer have access to these?
It will now ask How can we reach you? Type in an email that you have that also isn't linked to any other Facebook account.
It will now ask you a question. If you're close friends with the victim, that's great. If you don't know too much about them, make an educated guess. If you figure it out, you can change the password. Now you have to wait 24 hours to login to their account.
If you don't figure out the question, you can click on Recover your account with help from friends. This allows you to choose between three and five friends.
It will send them passwords, which you may ask them for, and then type into the next page. You can either create three to five fake Facebook accounts and add your friend (especially if they just add anyone), or you can choose three to five close friends of yours that would be willing to give you the password.
How to Protect Yourself
Use an email address specifically for your Facebook and don't put that email address on your profile.
When choosing a security question and answer, make it difficult. Make it so that no one can figure it out by simply going through your Facebook. No pet names, no anniversaries—not even third grade teacher's names. It's as easy as looking through a yearbook.
Learn about recovering your account from friends. You can select the three friends you want the password sent to. That way you can protect yourself from a friend and other mutual friends ganging up on you to get into your account.
Method 2: Use a Keylogger
Software Keylogger
A software keylogger is a program that can record each stroke on the keyboard that the user makes, most often without their knowledge. The software has to be downloaded manually on the victim's computer. It will automatically start capturing keystrokes as soon as the computer is turned on and remain undetected in the background. The software can be programmed to send you a summary of all the keystrokes via email.
CNET has Free Keylogger, which as the title suggests, is free. If this isn't what you're looking for, you can search for other free keyloggers or pay for one.
Hardware Keylogger
These work the same way as the software keylogger, except that a USB drive with the software needs to be connected to the victim's computer. The USB drive will save a summary of the keystrokes, so it's as simple as plugging it to your own computer and extracting the data. You can look through Keelog for prices, but it's bit higher than buying the software since you have the buy the USB drive with the program already on it.
How to Protect Yourself
Use a firewall. Keyloggers usually send information through the internet, so a firewall will monitor your computer's online activity and sniff out anything suspicious.
Install a password manager. Keyloggers can't steal what you don't type. Password mangers automatically fill out important forms without you having to type anything in.
Update your software. Once a company knows of any exploits in their software, they work on an update. Stay behind and you could be susceptible.
Change passwords. If you still don't feel protected, you can change your password bi-weekly. It may seem drastic, but it renders any information a hacker stole useless.
Method 3: Phishing
This option is much more difficult than the rest, but it is also the most common method to hack someone's account. The most popular type ofphishing involves creating a fake login page. The page can be sent via email to your victim and will look exactly like the Facebook login page. If the victim logs in, the information will be sent to you instead of to Facebook. This process is difficult because you will need to create a web hosting account and a fake login page.
The easiest way to do this would be to follow our guide on how to clone a website to make an exact copy of the facebook login page. Then you'll just need to tweak the submit form to copy / store / email the login details a victim enters. If you need help with the exact steps, there are detailed instructions available by Alex Long here on Null Byte. Users are very careful now with logging into Facebook through other links, though, and email phishing filters are getting better every day, so that only adds to this already difficult process. But, it's still possible, especially if you clone the entire Facebook website.
How to Protect Yourself
Don't click on links through email. If an email tells you to login to Facebook through a link, be wary. First check the URL (Here's a great guide on what to look out for). If you're still doubtful, go directly to the main website and login the way you usually do.
Phishing isn't only done through email. It can be any link on any website / chat room / text message / etc. Even ads that pop up can be malicious. Don't click on any sketchy looking links that ask for your information.
Use anti-virus & web security software, like Norton or McAfee.
Method 4: Stealing Cookies
Cookies allow a website to store information on a user's hard drive and later retrieve it. These cookies contain important information used to track a session that a hacker can sniff out and steal if they are on the same Wi-Fi network as the victim. They don't actually get the login passwords, but they can still access the victim's account by cloning the cookies, tricking Facebook into thinking the hacker's browser is already authenticated.
Firesheep is a Firefox add-on that sniffs web traffic on an open Wi-Fi connection. It collects the cookies and stores them in a tab on the side of the browser.
From there, the hacker can click on the saved cookies and access the victim's account, as long as the victim is still logged in. Once the victim logs out, it is impossible for the hacker to access the account.
How to Protect Yourself
On Facebook, go to your Account Settings and check under Security. Make sure Secure Browsing is enabled. Firesheep can't sniff out cookies over encrypted connections like HTTPS, so try to steer away from HTTP.
Full time SSL. Use Firefox add-ons such as HTTPS-Everywhere or Force-TLS.
Log off a website when you're done. Firesheep can't stay logged in to your account if you log off.
Use only trustworthy Wi-Fi networks. A hacker can be sitting across from you at Starbucks and looking through your email without you knowing it.
Use a VPN. These protect against any sidejacking from the same WiFi network, no matter what website you're on as all your network traffic will be encrypted all the way to your VPN provider.
Protecting Yourself: Less Is More
Social networking websites are great ways to stay connected with old friends and meet new people. Creating an event, sending a birthday greeting and telling your parents you love them are all a couple of clicks away.
Facebook isn't something you need to steer away from, but you do need to be aware of your surroundings and make smart decisions about what you put up on your profile. The less information you give out on Facebook for everyone to see, the more difficult you make it for hackers.
If your Facebook account ever gets hacked, check out our guide on getting your hacked Facebook account back for information on restoring your
Subscribe to:
Posts
(
Atom
)












