Wednesday, 16 March 2016

Hacking WEP

Hacking WEP

Tools Required:
1. CommView for WiFi: http://tamos.com/download/main/ca.php
2. Aircarck-NG GUI: http://aircrack-ng.org/
1. Install CommView. While installation you maybe asked whether you want to install the application in VoIP mode or Standard mode. Both mode will work fine for our case. But I usually used the VoIP mode. It will automatically seraches and installs the available drivers needed for making the wirless adapter to enable the packet capture (by turning on promiscuous mode). Just allow it to install the needed drivers an you are good to go to the next step. And please note that while using CommView, your WiFi networks will get disconnected. Don’t panic, you are doing right! 😀
2. After the installation, start the application and click on the left arrow on the left side.
3. You will be prompted with a new window. Click on the Start Scanning button.
4. In the right column, all the available networks around you will be shown. Just click the network you want to get the password, and click on “Capture”. Please note that, this tutorial is for WEP networks only!
5. Now the newely opened windows will be closed and you can now see that the CommView started capturing the packets.
6. Click on Settings> Options> Memory Usage. Change the value of maximum packets in buffer to 20000.
7. Now you can click on the logging tab. Select “Auto Logging”. Enter 2000 in the “Maximum Directory Size” and 20 in the “Average Log File Size”. We just told the CommView to capture *.ncp packets with each file of 20MB size and store it in the directory we chosed.
8. Again go to “Logging” tab and select “Concatenate Logs” to join all the split logs of 20 MB we just created. And now we have one *.ncf file.
9. Go to File>Log Viewer> Load CommView Logs> and choose the *.ncf file that we just got form the above Concatenation step.
10. Click File> Export> Wireshark/Tco dump format. This will create a .cap file
11. Go to the Aircrack application folder and then traverse to the bin file inside. Double click on Aircrack-ng GUI.exe in the application, choose the *.cap file we just created in the step 10.
12. And that’s it! If you sufficient data to crack the password, you will get the password. It is advisable to proceed from step 8 to 11 only after receiving enough packets. You will need a minimum of 100000 packets to start the cracking. So after step 7, it is advisable to leave the system alone for 2-3 hours and then proceed to the further steps!
NOTE:
Recently CommView became a paid software with a rather ridiculous price tag. But, no worries. There are more than enough alternatives. Some of them are mentioned below and can be used to obtain the .cap file as explained above:
•Cain $ Abel:
http://www.oxid.it/cain.html
•WireShark:
http://www.wireshark.org/
For about a couple dozen more, check out the wikipedia page (link below )listing almost every packet analyzer:
http://en.wikipedia.org/wiki/Comparison_of_packet_analyzers
They all work the same way, basically all we need is a means to get the .cap file and after that the role of packet analyzers is over. For most purposes WireShark is more than enough, so kindly check out this one first. On a seemingly unrelated note, the war against piracy wages on and packet analyzers have become victims too. Proprietary softwares like CommView continue to be easily available on torrent websites which shows just how harmful hacking can be to a company.

limits Of Legality

Limits Of Legality

Anyone serious about learning hacking should make sure to go through all the relevant laws in their jurisdicitions. For those who are not so serious, it is even more important. Simply goofing around may be enough to rack up a hefty fine, probation or even a sentence. In germany, for example, simply owning a tool that can be used for hacking, is a crime. One may actually be convicted for downloading a freaking app. In the same country, a professional penetration tester or a 12 year old may be regarded as criminal hackers just because s/he downloaded Cheat Engine (I’m serious) or BackTrack OS. This is not to single out Germans but to show that imperfect laws still exist in almost every country’s constitution (Germans, don’t worry. I have a lot more laws to insult from all over the world. But we’ll leave these for another day) This problem depends on your geography only a little, but it is mostly global.
Why bother with all this legal nonsense? If you’re not the type to spend your life fighting pointless politics or start protesting around to change existing laws, you need to follow them. After all, what choice do we have? Jail? Sure, why not. If you aren’t against something, then by definition, you support it. Anyways, let’s leave politics for another website.
When it comes to hacking, no matter where you live, practically doing it means walking a fine line. But, before anything else, before the law too, you need to look after yourself and make sure you are aware of every possible consequence of performing a hack or anything even remotely related. From running batch files, which can wreck your computer to hacking a school’s server which can get you expelled to leaking NSA secrets which can open the eyes of the world, you need to tread carefully. When it comes to hacking, there is no universal definition of right and wrong. It’s different for the government, it’s different for the anonymous hackers group and it will be different for you and me. While we’re on this, you may have heard about the “criminal” anonymous hacktivist group and their “illegal” and “unethical” activities in the news and media somewhere. Take a wild guess, who’s definition of right or wrong does the media follow?.. The obvious can be surprising. Change your viewpoint and you can change your world.
Coming back to the limits of legality, what all is legal for an average joe who wants to learn hacking? Although the exact answer will depend on your address (another bug in the matrix..), there are some general things you should keep in mind while learning and carrying out different hacking techniques, no matter where you live. These are not only to keep you out of jail but also to protect you from yourself. Since our lives will just keep on getting more and more dependent on technology, hacking is no longer just about hacking. Plus, it won’t hurt to double check what you’re doing won’t get you in trouble.
•Know what you’re doing.
Whatever the hacking method you’re trying to do, it can never hurt to know a little more than what you need. You just might end up saving yourself a lot of trouble. Just one misplaced command in a batch file virus could spell disaster. As a rule of thumb: If you don’t know what you’re doing, don’t do it. In the world of hacking, it’s easy to get carried away, specially when you try out something new, it works and you want more. Skipping the learning phase and moving straight to the doing phase is what turns potential hackers into script kiddies. In professional penetration testing, a small mistake in typing the IP address may result in you “hacking” into a whole different company on the other end of the globe. Clearly, they may not care about the difference between “pentesting” and “hacking” and your boss will find a lawsuit waiting to greet him. Actually, typos don’t really lead to lawsuits. The point is, a big firm can probably get away with a little mistake. You can’t. If you hack into some server or network where you don’t have permission, there is no justification for what you’re doing there (if you’re caught). Now THIS, looks more like lawsuit material.
•Know the consequences of what you’re doing.
This is an extension of the previous point. Before performing any hack, you should always try to visualize every step. See it in your mind, what all you need to do and what exactly is the expected outcome. You should try to avoid involving someone else’s property or devices when learning hacking. If you stick to what you know, you should always be able to predict what will happen. That will leave only typos and genuine errors. Hacking is not all that dangerous and unpredictable if you know what you’re doing.
•Don’t hack anyone without their knowledge.
It may be only a fun little trick for you, but for the other person it could be an invasion of privacy or perhaps a massive violation of all the trust they put in you, for the more dramatic ones. Not all hacking techniques can be tried on yourself for practice. Most can, but still some like those involving networking need more systems. It’s great if you can find a willing and trust-worthy friend and try hacking eachother for learning. If you ever consider trying larger and more elaborate hacks, taking written permission from all the involved parties is a good idea. For example (students), asking your computer teacher permission to simulate a DDOS attack in the computer lab, or perhaps the local cyber cafe. Another example, hacking public (protected) WiFi networks is illegal. You could try knocking on your neighbour’s door and advising them to switch over from WEP to WPA. This is what puts the “ethical” in “ethical hacker” and the chances of them giving you the new password by simply asking also increase.
•Know when to stop.
Companies hire penetration testing firms to check the security of their networks but almost always want them to stay away from private and confidential information, even if they have access. If someone were able to “guess” the facebook password of someone, it doesn’t give them the right to exploit their ability without regard for anyone else. With each passing moment, our lives are getting more and more integrated with technology making it extremely important to know when to stop.
•Know the law.
In normal hacking, you will probably never need to be worried about legal trouble but it won’t hurt to double check. To be extra sure, you can google up the constitution of your country or search for relevant laws regarding hacking.
That’s pretty much all a beginner hacker needs to know about the legal side of hacking. Once again, anything you do on your own computer that affects nobody else is usually safe (for others). As the world is increasingly interconnected, everyone shares the responsibility of securing cyberspace. Hence, it is better to be despised for anxious apprehensions, than ruined by superficial security (a little bit).

R.A.T'S

R.A.T’s

Here is an introduction to Remote administration tools. These are generally called RATs, and yes they have a vicious bite. although this page doesn’t teach you how to blast open a RAT straight away, here you will learn everything you will need to start a ‘plague’. RATs form an entire class of hacking including trojan infections, backdoors etc. But to go further, we need to clear up the basics first so, here we go.
What’s a RAT?
RAT = Remote Administration Tool. It is mostly used for malicious purposes, such as controlling remote PC’s, stealing victims data, deleting or editing some files. One can infect someone else by sending them a file called “Server”. If and when this server file is opened, it burrows itself deep in the system and starts to run in the background. Further, it may also send the attacker a message every time it is active like when a computer is turned on.
How are they spread?
Some RATs can spread over P2P (peer to peer) file sharing services (Torrents, mostly..), messenger and email spams(MSN, Skype, AIM etc.) while other may tag along hiding behind some other software. The user installs something, clicks “Next” 5 times and voila! Without anyone ever finding out the RAT has compromised a system.
How is the server controlled?
Once installed, the RAT server can be controlled via what’s called a RAT client. Basically it’s just an application that tracks your RAT’s movements. It tells you how many systems are infected, information on their system, versions of OS and other softwares, their IP address etc. It shows a whole list of IP addresses which may be connected to immediately. After connecting, you can make the computer do pretty much anything (except maybe, do hula dance XD) – Send a keylogger, uninstall their antivirus, crash the system etc.
What is port forwarding?
If you’re a gamer or are used to downloading torrents, you must’ve heard “Port Forwarding” as a way to increase download speeds, reduce lag etc. Port forwarding is the redirecting of computer signals to follow specific electronic paths into your computer.If the computer signal can find its way into your computer a few milliseconds quicker, it will add up to be a possibly dramatic speed increase for your game or your downloading. Don’t start jumping around just yet, your internet connection is probably already optimized for maximum performance (It is so, by default).
Let’s take an example: That pencil-thin network cable (that goes into the network adapter) at the back of your computer contains 65,536 microscopic pathways inside it. Your network cable is just like a major highway, except your network cable has freaking 65,536 lanes, and there is a tollboth on each lane. We call each lane a ‘port’.(FYI, 2^16 = 65,536. So, that tells us 2 bytes = 16 bits in all is sort of the “width” of network cables, which gives us 65,536 different possible combinations – hence the same number of ports.)
Your internet signal is comprised of millions of tiny little cars that travel on these 65,536 lanes. We call these little cars “transfer packets”. Computer transfer packets can travel very quickly (just under the speed of light actually), but they do observe a stop-and-go set of rules, where they are required to stop at each major network intersection as if it were a border crossing between countries, or connecting to a different ISP. At each intersection, the packet must do three things:
►Find an open port,
►Pass the identification test that will allow it through that port, and if not,
►Move to the next port and try again, until it is allowed to pass through the toll.
In some cases, packets sent by hackers will be caught and held at the intersection, where they will then be dissolved into random electrons. When this happens, it is called “packet filtering” or “packet sniping”. Likewise, if a hacker gains control of a much used port, he can control every bit of information that passes through it – Read it, modify or even delete.
All in all, Port forwarding is when you command your network router to proactively identify and redirect every packet to travel on specific electronic lanes. Instead of having every packet stop at each port in turn until it finds an open port, a router can be programmed to expedite the process by identifying and redirecting packets without having them stop at each port. Your router then acts like a type of hyper-fast traffic policeman who directs traffic in front of the tollbooths.
Can an antivirus catch a RAT?
Yes. Actually, Hell Yes! As a hacker, you will find antiviruses blocking your path at every damn step. (But we are white hats, right? No matter how annoying, it’s there to protect us, so be happy). But, like every problem, this too has a solution – Encryption. It’s called making your server “FUD” – Fully Undetectable. For example, typical encrypted formats, say password protected .zip or .rar files (if they contain malicious softwares) can be caught by an AntiVirus. Making a program FUD does pretty much the same thing, except it does so like a drunkard with OCD (Obsessive-compulsive disorder). What I mean is, running the software through an encryption program again and again so that nothing can recognize what it is and it can pass off as random harmless noise. Something called “Hex Editing” is a well known way to go about doing this. This is a whole different topic in itself. So, more on this later.
Legal or illegal?
Well, some RATs are legal, and some are not. Legal are the ones without a backdoor, and they have abillity to close connection anytime.(Backdoor is something that gives the attacker access to the victim’s system without their knowledge). Plus these are not really referred to as RAT’s, that’s just our (hacker’s) dirty language :-) Illegal ones are used for hacking and they may possibly steal data (or worse).
A few examples are written below:
Legal:
►TeamViewer – Access any remote computer via Internet just like sitting in front of it – even through firewalls.
►UltraVNC – Remote support software for on demand remote computer support.
►Ammyy Admin – Like TeamViewer, Ammyy Admin is another reliable and friendly tool for remote computer access.
►Mikogo – Mikogo is an Online Meeting, Web Conferencing, Remote Support tool where you can share your screen with several participants in real-time over the Web.
The above tools while very useful and very legal, require a green light from both the parties involved. That’s the main difference between the ones above and the ones below:
Illegal (or barely legal):
►Spy-Net
►Cerberus Rat
►CyberGate Rat
►SubSeven
►Turkojan
►ProRat
These are all used for one purposes – Causing trouble, to say the least. RATs like the ones above are meant to be stealthily. After all, no hacker will want their victims to get a message like: “Congratulations! You have been infected!”(Or maybe let the AntiVirus find it). Use any of these on an actual victim, and you will get a ticket to jail, or at least a fine. But these are actually used, and mostly without anyone ever suspecting anything wrong. The thing is, hacking is becoming much more of a serious business than a game. A RAT that simply crashes the OS or formats the hard disk gives nothing to the attacker, So why bother doing it in the first place ? RATs today are evolving (pun unintended). They are becoming more like “parasites” instead of predators.
They may be used for DDOSing (by creating massive botnets with tens of thousands of slave computers), clicking ads in the background(the usual click fraud), increasing blog and youtube “views”, even using the compromised systems to “earn money online”, by pushing surveys, exploiting the websites which offer a pay-per-install model, even “mining” bitcoins (Bitcoins are just a fancy new online currency. Bitcoins can be earned by devoting CPU power, then converted into real money, hence their potential exploitation by using RATs). (Don’t bother googling this. Like every “Online money making” offer, whether it works or not, this too is a waste of your time. No offence to the BitCoin Foundation :-D)
Whats DNS host?
The Domain Name System (DNS) is a hierarchical naming system for computers, services, or any resource connected to the Internet or a private network. It associates various information with domain names assigned to each of the participants. Most importantly, it translates domain names meaningful to humans into the numerical (binary) identifiers associated with networking equipment for the purpose of locating and addressing these devices worldwide.
What all can a RAT do?
Here is list of basic features:
• Manage files. (Delete/Modify)
• Control web browser(Change homepage, open a website etc.)
• Get system informations(OS Version, AV name, RAM Memory, Computer name, Network Addresses etc.)
• Get passwords, CC numbers or private data etc. (via Keylogger)
• View and control remote desktop (Take screenshot or a snap from the webcam)
• Record camera, sound (Control mic and camera)
• Control mouse, keyboard input.
• Pretty much everything you can do on your own computer, except play GTA V remotely. (Although technically, you can do that too)

programming – II

Programming – II

Programming is a vast field. Even after years of experience a programmer is always bumping into new things. That’s part of what makes it so exciting, you can always find something new to do, possibilities are endless. So, here we try to answer another question in the mind of wannabe programmers: How to start?
Programming can only be caught, never taught. Learning programming encompasses two main things, reading and doing, with greater emphasis on the latter. You can only know what to do by reading, but you can learn only by doing. Even when you may get stuck somewhere or not fully understand something, doing it yourself will always clear all your doubts. I myself learned most of the programming I know through different sources on the internet and tons of books. Below are some of the best ones, I’ve come across yet: (categorized by languages) (Note: Most of these are completely free, but some may offer paid packages and features too. Also, try enlarging the text from the menu button if the links are hard to click. Lastly the websites are mainly designed for computers and may or may not work properly on mobile phones.)
Before starting, a few special mentions:
http://www.w3schools.com/
Without a doubt, this is one of the best websites out there to learn programming. If you want to get into web development, there’s no better place to start than W3Schools. HTML, CSS, JavaScript, SQL, PHP, XML, JQuery – You name it, this website has an abundance of learning material for vast number of programming languages and it’s tailor made for beginners.
http://www.learnstreet.com/
A relatively young website, but it has a lot to offer. It has highly interactive free online courses on Python, Ruby and JavaScript (yet). Again, a great place for beginners to start. It presents examples and questions that the user has to actively participate in and solve problems in the browser itself.
http://teamtreehouse.com/
A very well made website, it has tons of “projects” in different programming languages. Each of these projects are a compilation of videos in which a person commentates or teaches you about completing the project, what all you need to do and how to do it. Clearly, they’ve put a lot of effort into it and it did come out great.
Other than these, there are many more websites which offer great courses and material for learning programming. A few of these are mentioned below according to languages:
►Multiple Languages:
https://www.bitcast.io/
https://www.udacity.com/
http://www.codecademy.com/
https://www.codeschool.com/
►Java
http://www.learneroo.com/
http://funprogramming.org/
►Javascript
http://codehs.com/
http://jsdares.com/
►Ruby
https://rubymonk.com/
http://hackety.com/
http://tryruby.org/
►HTML, CSS, JAVASCRIPT
http://css-tricks.com/
http://www.codeavengers.com/
https://tutsplus.com/
►Other / Uncategorized
https://www.codeeval.com/
http://quackit.com/
https://www.khanacademy.org/
https://www.udemy.com/
http://net.tutsplus.com/
http://projecteuler.net/
http://webdesign.tutsplus.com/
http://wp.tutsplus.com/
http://www.webtechlearning.com/
https://www.coursera.org/

programming – I

Programming – I

When it comes to computers and everything related to them, programming is the mind and body, heart and soul. Without software, any piece of hardware is nothing but a random collection of metal and plastic. But with a beautiful stream of 1’s and 0’s it can almost literally be pumped full of life. Everything we see and everything we do on our mobiles and computers and really every fancy new gadgets these days, was created by someone, somewhere who night after night tirelessly wrote a program in code to create something wonderful.
The users often don’t fully comprehend exactly what goes on behind the scenes of any decent piece of software. For this reason, here’s a little reality check before we get to the main topic. A line of code is a single average line in a program and usually contains around 40-50 characters. The Unix 1.0 OS (1970) contained about 10,000 lines of code (LoC). Today, an average iOS or android app has approximately 50,000. That is 50,000 lines typed word by word by someone, and we’re just getting started. Photoshop CS6 clocks in at a freaky 5 million LoC and the Firefox browser? – 10 million. Moving on to the big players, we’ve got Windows 7 at 40 million and guess what? Microsoft office is actually bigger than the parent OS itself (about 45 million LoC). Now that you’re gaining a little perspective, let’s blow it to hell. The website healthcare.gov (reportedly) has an unbelievable 500 million lines of code. To put that into perspective, if a decent and immortal programmer started making this website in the last ice age 10,000 years ago, they’d still be going today, while of course cursing their destiny.
What’s the point of telling you all this?
Programming is not for the faint hearted. It takes effort (but not that much). Truth be told, lines of code is a very poor measure for difficulty. It’s like measuring a person’s success by counting the number of words they’ve spoken, ridiculous and not really related. The point of all that was to prove wrong the ones who overstate and exaggerate the difficuty of learning programming. It’s almost always pictured as something unbelievably boring, dry, dull and plain geeky. According to movies, a programmer is a fat nerdy guy with huge spectacles sitting in front of the computer mindlessly typing away while all that s/he accomplishes is something facetious and laughable. This could not be more wrong. Undoubtedly, programming can only be done by someone who thoroughly enjoys it. Being a programmer myself, I can honestly say there’s simply no way to describe it. It’s different for everyone which is why to truly find out if programming is for you, you will just have to try it out for yourself.
Programming teaches you how to think. It teaches you how to solve any problem, whether it is considered possible or not is irrelevant.
Moving On, let’s take a look at how exactly programming can help a hacker. First of all, it is what differentiates you from script kiddies. If the only hacks someone can do are made by others, then that person really cannot be called a “Hacker”. If you ever tried googling about hacking and gave up soon without finding an answer, you’re not alone. The main reason most hackers are not big on helping others is because they start getting bombarded by noobs asking them to hack (fb) accounts and explain something so basic and silly that they just give up and start ignoring them. Programming helps you understand how everything in your smarter idiot box comes together. It gives you better knowledge about how to identify and solve any problems by yourself. By knowing programming, you get a better understanding about how vulnerabilities and exploits work. Most importantly you can code your own tools, scripts, exploits, shell codes, entire applications and modify existing ones according to your own needs. No need to learn it from others, you can simply make it your own. You get to explore and pioneer in uncharted territory.
What all can you expect to do with programming? Sky’s not the limit, when there are footprints on the Moon. Everything, literally everything you can think of. But that’s the big picture stuff. Let’s take a sneak peek of the programming world with an example of this website itself. Press a button in the sub menu up top, you’ll see a further menu pop up. What I did to make that happen is I wrote a simple function (set of commands) that should be executed when the user presses the menu button. Similarly hovering your mouse over the button changes it’s color. To make that happen I wrote a small JS script that looks for the event of mouse hover over the button and then changes the color.
These were just a couple of examples in an infinite ocean of possibilities. In programming, you can expect to find and identify problems and find your way through them with logical thinking.
So that’s that for an introduction to programming. The next question that comes is where to start?
All you have to do is pick a language and dive in. Which one? There’s simply no right or wrong answer to this question. Fair warning, you’ll have to learn quite a few languages for hacking, preferably as many as possible. Even if you will not need to write in every language, you should know how to at least read it. Nobody is perfect, least of all, programming languages. Each one has it’s pros and cons. You can do the same thing in a million different ways with a dozen prorgamming languages. The time spent analyzing these useless facts could better be spent actually learning something. There is nothing to gain from comparing languages. Knowing quite a few myself, I can tell you the difference between languages is almost like the difference between “Hello”, “Hi” and “Hey”. Although languages like HTML, SQL, Java are used for different things, it really doesn’t matter where you start since you should learn as many languages as you can. For making a webpage you’ll need HTML, for making applications – Visual Basic, for data storage – SQL, for complex programs – C++ (just an example). Clearly, every single one of these and others as well are useful to a hacker. So, for the last time, start wherever you want to (or randomly).
The final destination is the same, below are a few of the different paths (languages) for a programming beginner to follow. It is generally advised to stick to mainstream languages when beginning and these are some of them:
►C++, Java, C# : These are the most used high level general purpose languages. Most of what you’ll ever do on a computer would not be possible without these. Almost every software, tools, applications is made by these. You are bound to run into these one day or another. They require a fair amount of effort but yield the greatest rewards. These are generally not recommended as a first language. My first language was C++, and it made learning every consequent language much easier. Once more, it’s up to you.
►HTML/SQL/XML : These are so easy, they’re almost not even worth learning. But they offer great rewards for very little effort, something you’ll never hear in the rest of the programming world. Actually, you can learn these just to tell people that you know so many computer languages. You can easily absorb the basics of these three, for example, in under a day. SQL is particularly important for hackers as it can, in some cases provide an easy way into a server’s database (SQL injection) – Definitely worth knowing, considering we’re all lazy and proud. (JavaScript also deserves a mention here, but it’s a wee bit bigger and deeper)
►Python, Ruby : These are two more quite powerful languages. Python is pretty much the best and most widely used scripting language out there, although it can be used generally also. Ruby is another general purpose language, MetaSploit is coded in Ruby.
These were just a few examples, there are several languages out there. Check out “Programming-II” for a compilation of the best sources and websites to start learning programming right away. Keep calm and code on.

Hacking Facebook

Hacking Facebook

A note for the newcomers – Contrary to popular belief there doesn’t exist some secret software where one can just put in an email id, press “Enter” and all the passwords associated with that account magically appear. Hacking facebook, like any other hack takes time, skill and effort. Also, the methods are much the same for hacking any type of account for that matter.
There are 3 main methods used when it comes to Hacking Facebook accounts. Briefly,They are :
1.Keyloggers : Making the victim open up his account on a system with a keylogger attached/ Sending a remote keylogger to the victim.
2.Phishing : Making a fake login page and having the entered details sent to you.(This has been explained in the beginner section).
3.Social Engineering : This is just a fancy term for making the victim give up vital information in a supposedly casual conversation. The information may be the user’s recovery question’s answer, which can then be used to take over the account via : “Forgot your password? Click Here!” Button.
Some time ago, Facebook developers patched in a new security feature. In a nutshell, if facebook detects that your IP address is different from the usual(previously used) IP addresses, it may stop you from logging in without further identitiy verificiation which may be, for example: an SMS code. Now this can potentially effect every type of hack, but if it is infact possible there is only one way to know- By doing it. Hope for the best, Prepare for the worst.
1.Keyloggers:
A Keylogger is type of software that usually runs in the background, without the knowledge of an innocent victim and secretly records their actions. A wide variety of functionality is offered by various products : Almost all record every keystroke on the keyboard in a simple text file format, some record mouse clicks and pointer locations, some record folders and files opened and some even take screenshots at regular intervals.
Most of the keyloggers provide an option whether to store the text file locally send it to an FTP server or your email id. They can be installed and set up relatively easily like any other program. Once setup, they usually go into hiding as a background process leaving no trace on the surface and starting up automatically when the operating system starts.
For some reason people seem to avoid or look over keyloggers, I can give you my word this is the best and easiest method for hacking any type of account there is, so definitely check this out. In our case, we want the victim to login to their facebook account on a compromised system, one that has a stealthy keylogger installed. There are two ways to go about this :Installing a keylogger on your system and having them use it to login to their FB account, or if you have temporary access to their system- Installing it on their computer and having the log files sent to you by email or FTP.
Whichever way you prefer, the method is the same. Download a keylogger, follow the smooth setup instructions as you would when installing anything, customize settings according to your preference and Let it rip !
I have personally tried and tested the following keyloggers, you can choose any of these randomly since they all seem to do the job :
(i)Actual key-logger – Download from http://www.actualkeylogger.com/download-free-key-logger.html
(ii)Home key-logger – Download from http://www.kmint21.com/download.html
(iii) REFOG Free key-logger – Download from https://www.refog.com/download.html
(P.S- Certain full versions of very good keyloggers are available as torrents from websites like isohunt.com , kickass.to but these torrents are illegal and we shouldn’t use them)
2.Phishing : This method has been described in great detail in the beginner section. Follow the instructions carefully while using facebook.com instead of gmail.com.
3.Social Engineering :
Facebook uses security questions as a recovery method, almost everyone sets it up to a personal question like :
“Where were you born? ”
“What was your first pets name? ”
Social engineering is a term that describes a non-technical kind of intrusion that relies heavily on human interaction and often involves tricking other people to break normal security procedures.
A social engineer runs what used to be called a “con game.” For example, a person using social engineering to break into a computer network might try to gain the confidence of an authorized user and get them to reveal information that compromises the network’s security. Social engineers often rely on the natural helpfulness of people as well as on their weaknesses. They might, for example, call the authorized employee with some kind of urgent problem that requires immediate network access.
Appeal to vanity, appeal to authority, appeal to greed, and old-fashioned eavesdropping are other typical social engineering techniques.
For this method to work, you need to know the person whos account you want to hack. In fact, you need to know them well enough, such that it doesn’t seem suspicious when you carefully try to work up their recovery questions into your conversation and get them to answer it casually.
After that,using the “Forgot your password? Click Here!” Button one can simply turn over an account’s user. But even after this, your work is not done yet. Nowadays facebook has implemented a 24 hour delay before recovering the account and logging in, So if the victim happens to log in during that period they can reverse the process in seconds. Not only do you need careful planning, but also careful timing.
Facebook uses a verification method during recovery -if the victim’s email and phone number are no longer functional it asks to put in another phone number. If you can somehow get a hold of their cell phones or email accounts their account is yours, otherwise the process may be slow and fruitless.

Practicing For DDOS

Practicing For DDOS

What we’ll attempt to do in this article is similar to testing a nuclear bomb (okay, not really). But still, there’s no way to tell exactly what will happen, other than to blast the damn thing because more often than not that’s just the way it is with DDOSing.
To refresh your memory, DDOS Attacks involve saturating the target machine with external communications requests (packets) so much so that it cannot respond to legitimate traffic. In most cases, this presents an obvious obstacle – Where to get massive amounts of bandwidth? By definition, servers are designed to handle huge quantities of traffic and when we are trying to attack it with traffic, it’s going to be very difficult (or is it?).
The usual way to DDOS is to slowly build up a botnet for example, by spreading a trojan (or RAT) that installs the DDOSing software and sets up a backdoor listener. When the infection has spread to thousands of systems, the hacker then activates the trojan and the DDOSing begins. Clearly, breaking into several thousand systems is not very legal or ethical, so even if some genuine website administrator wants to perform a dummy DDOS just to see what will happen and what’s the best way to handle it, they won’t be able to do it. This is another reason why small websites particularly are very vulnerable to attack – they don’t practice because apparently the only way to practice is illegal. So, when they are hit by an actual DDOS they simply don’t stand a chance. So, below we take a look at a possible solution that works for both good and bad guys. An alternative practice methods for website admins and a shortcut for DDOSing for hackers.
The method described below is quite unpopular. In a sentence, we use online services to DDOS for us. These are called “stressers” or “booters” and are simply services which provide large internet bandwidth for the purposes of simulating a DDOS attack. Before moving on, some of the websites mentioned below do offer trials but most of them are fully unlocked only after a payment. So, these may be useful mainly for serious networking administrators or website owners only.
Clearly, doing an actual BlackHat DDOS using this is very much possible if done correctly. But that would require using a VPN or TOR browser to hide your identity. Even with that, since you would have to make a payment, it could potentially lead back to you making this a very dangerous alternative if not done exactly right. Hence, I recommend using this method only for what it’s meant for, as simply fooling around can get you into very serious legal trouble.
Below you can see the names of a few well known stressers and booters and the links to their websites.
#1: Power Stresser – http://www.powerstresser.com (60GB/s of Power)(Stop Button)(Instant)(Skype Resolvers)
#2: Titanium Stresser – http://titaniumstresser.net/ (Powerful)(Up for 3 years)(Best Price)(Great Support)
#3: Legion Stresser – http://legion.cm/ (Max Power) (Max Time)
For some reasons, the majority of these websites appear quite dull on first look. Perhaps they don’t want to attract a lot of attention. Anyways, In most of the above websites you’ll simply see a login page with a “Register” option. So, pretty much the only way to get inside is to make an account. Pick anyone and create an account. (Again, this tutorial is mainly for online service/website owners who want to make sure their website is well protected) Once you’ve registered for the first time. You will see several packages of boot time and strength. Whether you’re trying to DDOS someone else (which you shouldn’t) or your own online website or service, I recommend having several (2-3) booters or Stressers with moderate time instead of just 1 large DDOSer.
On The websites you will see a control panel-like window, where you can initiate your DDOS Attacks after selecting a package. To DDOS a home connection or a server, you will first need the (host) IP address. Many Booters Contain a built in Skype resolver and Domain Resolver. For “Port” option, the usual choice is Port 80 (Directed at home modems).
You will then be able to set your Boot time anywhere from 0 to the maximum time you paid for. Generally, UDP(User Datagram Protocol) is used for targeting a PC. For website and larger servers, SSYN attack is usually used which is considerably more powerful. You can think of these as DDOS attacks in which different types of optimal requests are sent for different situations and targets. Anything more than this will get a bit too technical than required here.
So that’s that for configuring and optimizing the DDOS attack. After this you will be able to start your DDOS attack as and when you please. Below you will find some useful relevant information that is frequently required for DDOSing using stressers and/or booters:
Skype Beta Resolver – http://www.iSkypeResolve.com
Other Ports:
(Home Connections)
53 – DNS Port
80 – Default Internet Port
(Xbox Connections)
80 – Default Internet Port
88 – Authentication Port
3074 – Xbox Default Port
(Web Servers)
21 – FTP Port
25 – SMTP/Mail
53 – DNS Port/Nameserver
80 – Default Internet Port
3306 – MySQL Port