tekball

home of latest tips and tricks for computer,mobie and internet.free sofwares,games,books,tutorials,downloads and much more....

SEARCH TEKBALL

Loading
Showing posts with label HACKING. Show all posts
Showing posts with label HACKING. Show all posts

Wednesday, April 6, 2011

NOTICE FOR DEAR USERS :)

THE BLOG WWW.TEKBALL.BLOGSPOT.COM HAS BEEN SHIFTED TO www.techmatics.blogspot.com.
we hope you will support the change.
THANK YOU !

Sunday, March 20, 2011

NEW 2011 Nokia Mobile Phone Hack Codes

Today, almost everyone of us has got a cellphone and most of us want to take our mobile phone experience to the next level. We have already written some article on mobile hacking and here are some tricks and tweaks that you can apply to your Nokia Mobile Phone to get the best out of your phone.

you’ll have no problem using these codes and if you haven’t, just remember that all of these codes may not work for your particular model and don’t forget to make backup of everything before trying these codes. I have tried the codes on my Nokia 3110c and marked those codes bold that worked for my mobile and nothing happened when I entered the other codes.

Here are some general codes

*#06#

For checking the International Mobile Equipment Identity (IMEI Number)

*#0000# or *#9999#

Displays your phones software version
1st Line : Software Version
2nd Line : Software Release Date
3rd Line : Compression Type

*#92702689#

Displays -
1.Serial Number
2.Date Made
3.Purchase Date
4.Date of last repair (0000 for no repairs)
5.Transfer User Data

*3370#

Activate Enhanced Full Rate Codec (EFR)
This will make the best sound quality out of your phone but talk time will be reduced by approx 5%

#3370#

Deactivate Enhanced Full Rate Codec (EFR)
The said feature will be deactivated

*#4720#

Activate Half Rate Codec
Doing this will make your phone use a lower quality sound but you should gain approx 30% more Talk Time

*#4720#

Deactivate Half Rate Codec
The above feature will be deactivated

*#746025625#

Displays the SIM Clock status, if your phone supports this power saving feature “SIM Clock Stop Allowed”, it means you will get the best standby time possible

Here are some codes for phones that are locked by service providers

#pw+1234567890+1#

Provider Lock Status (use the “*” button to obtain the “p,w” and “+” symbols)

#pw+1234567890+2#

Network Lock Status (use the “*” button to obtain the “p,w” and “+” symbols)

#pw+1234567890+3#

Country Lock Status (use the “*” button to obtain the “p,w” and “+” symbols)

#pw+1234567890+4#

SIM Card Lock Status (use the “*” button to obtain the “p,w” and “+” symbols)

Here are some codes to reset your phone

*#73#

Reset phone timers and game scores

*#7760#

Manufactures code

*#7780#

Restore factory settings

*#94870345123456789#

Deactivate the PWM-Mem

12345

This is the default security code
press and hold #
Lets you switch between lines - Line 1 and Line 2

Here are some codes regarding call diverting/waiting etc.

*#21#

Allows you to check the number that “All Calls” are diverted to

*#2640#

Displays security code in use

*#30#

Lets you see the private number

*#43#

Allows you to check the “Call Waiting” status of your phone.

*#61#

Allows you to check the number that “On No Reply” calls are diverted to

*#62#

Allows you to check the number that “Divert If Unreachable (no service)” calls are diverted to

*#67#

Allows you to check the number that “On Busy Calls” are diverted to

**21*number#

Turn on “All Calls” diverting to the phone number entered

**61*number#

Turn on “No Reply” diverting to the phone number entered

**67*number#

Turn on “On Busy” diverting to the phone number entereD

How To: Hack S60 Nokia Phones

This guide will be referenced to many times in the future, so I am posting the instructions to hacking your S60 Nokia phones now. Hacking your S60 phone will let you install unsigned applications without a hassle and even apply some patches if you like. It’s much easier than I thought!

Steps To Hack Nokia S60 Phone

  • Install freeware X-plore, a file manager from Lonely Cat Games. Run X-Plore, press 0 and check first 4 boxes. Don’t exit.
  • Install and run HelloCarbide by FCA00000.
  • Switch to X-plore and check if you can see the contents of C:/sys/. If you can, then you are halfway done. If not, try step 2 again.
  • Download CapsOnOff.rar by FCA00000.
  • Copy CProfDriver_SISX.ldd from RAR downloaded above into C:\sys\bin of your phone. You can do this with X-Plore.
  • Install CapsOn.sisx and CapsOff.sisx. Run CapsOff application to turn on the hack.
  • Download SIS installer mod for Symbian 9.2 and copy installserver.exe file to c:\sys\bin\ so you can install unsigned applications
  • Install ROMPatcher by Zorn.
  • Whenever you need to install an unsigned application or patch your phone, just run the CapsOff application first. CapsOn brings it back to normal state.
If I see any useful patches that interests me, I’ll make sure to mention it. There really isn’t much right now. Take a look at the SF modding forums for new patches. They were the source of these instructions.
Now that you have a hacked Nokia S60 phone, try installing some unsigned applications! I recommend MagicKey for remapping buttons or the latest version of S60 Screenshot v3.03 to take screenshots from your phone.

Friday, March 18, 2011

18 Great Google Search Tricks

Google is one the best and top Search Engine and if you use Google only to search for words and phrases, you’re doing it wrong. There are so many thing you can done with Google Search. The service is loaded with many advanced tricks that you can enable from that unassuming search box. In this article we review 18 awesome google search Tips and tricks that will improve the quality of your online life.


1. Find the current time elsewhere: Don’t bother trying to convert the time from your local setting to a distant city. Just type time city , as in time Beijing, to see the current time in that location. Yeah, it’s too late to call your buddy there.
2. Search within a domain: Google’s great search engine might be better (or simply more convenient) than the search box on a particular site. To limit results to a single site, type search term site:domain name. Eaxmple site:technobuzz.net
3. Search for a file type: You can look up results that match a specific file type. This trick is great for special searches, such as tracking down a product manual or video file. Try search term filetype:three-letter type . For example, I entered Zoom H2 manual filetype:pdf to find the manual for that Zoom recording device.
4. Weather as reported by Google SearchGet the weather: To see the weather for many U.S. and worldwide cities, type “weather” followed by the city and state, U.S. zip code, or city and country.
5. Calculate and convert: To use Google’s built-in calculator function, simply enter the calculation you’d like done into the search box. Try typing math problems, such as 89*22/(16), or conversions, like 100 yards = ? meters. Google will do the rest.
6. Track stocks: To see current market data for a given company or fund, type the ticker symbol into the search box. On the results page, you can click the link to see more data from Google Finance. You can enter a stock’s trading abbreviation, such as GOOG, and the first result will show the stock’s latest price, a graph of the day, and other financial details.
7. Get movie times: On the Web you have a myriad of choices to look up show times, but Google’s simplicity is tough to beat. Just type movies: city or zip code , as in movies 68501. Click the More movies link to get more-specific listings.
8. Track packages: Have a FedEx, UPS, or USPS tracking number? Just enter it in the Google search box for the latest package status.
9. Sports Scores: To see scores and schedules for sports teams type the team name or league name into the search box. This is enabled for many leagues including the National Basketball Association, National Football League, National Hockey League, and Major League Baseball.
10. Book Search: If you’re looking for results from Google Book Search, you can enter the name of the author or book title into the search box and we’ll return any book content we have as part of your normal web results. You can click through on the record to view more detailed info about that author or title.
11. Earthquakes: To see information about recent earthquakes in a specific area type “earthquake” followed by the city and state or U.S. zip code. For recent earthquake activity around the world simply type “earthquake” in the search box.
12. Unit Conversion: You can use Google to convert between many different units of measurement of height, weight, and volume among many others. Just enter your desired conversion into the search box and we’ll do the rest.
13. Synonym Search: If you want to search not only for your search term but also for its synonyms, place the tilde sign (~) immediately in front of your search term.
14. Dictionary Definitions: To see a definition for a word or phrase, simply type the word “define” then a space, then the word(s) you want defined. To see a list of different definitions from various online sources, you can type “define:” followed by a word or phrase. Note that the results will define the entire phrase.
15. Spell Checker: Google’s spell checking software automatically checks whether your query uses the most common spelling of a given word. If it thinks you’re likely to generate better results with an alternative spelling, it will ask “Did you mean: (more common spelling)?”. Click the suggested spelling to launch a Google search for that term.
16. Airline Travel Info: To see flight status for arriving and departing U.S. flights, type in the name of the airline and the flight number into the search box. You can also see delays at a specific airport by typing in the name of the city or three-letter airport code followed by the word “airport”. Examples:- american airlines 18, Houston airport
17. Currency Conversion: To use our built-in currency converter, simply enter the conversion you’d like done into the Google search box and we’ll provide your answer directly on the results page. Example: 150 GBP in USD
18. Phone Listing: Let’s say someone calls you on your mobile number and you don’t know how it is. If all you have is a phone number, you can look it up on Google using the phonebook feature. Example: phonebook:617-555-1212 (note: the provided number does not work – you’ll have to use a real number to get any results).

Thursday, March 3, 2011

Facebook Hacking Course Released

Facebook hacking Course is basically contains series of videos which will tell you exactly how hackers hack facebook accounts, What methods they use and how you can avoid falling for these kinds of attacks, You will watch my computer screen as I show you exactly how it's done, Each video contains a pre made lab so you can practice what you learned



Facebook Hacking Softwares

Lots of people are interested in learning how hackers hack facebook passwords and you might have came across lots of options and the first one would probably be a program or software which has an ability to hack Facebook passwords but the truth is that there is no such simple program or software that can do it for you, The reason behind it is that these major companies pay thousands of dollars to protect their users privacy, Do you honestly think this is possible?, Do you think that they don't have any protection and security officials to knock down such softwares, So Stop fooling your self and stop searching about these so called "Facebook Hacking softwares"

Facebook Hacking Services

The second option which people come across is that they go for Facebook Hacking services which promise to hack facebook accounts for you for money but the truth is that no one is going to do it for you, their purpose is just to scam you and take money.

What will be I learning in Facebook Hacking Course?

You will learn:
The exact techiniques which hackers use to hack facebook accounts.
Security tips to protect your facebook account from getting hacked.
Protecting your Privacy
And much more.

Bonus

By buying this facebookhackingcourse you will get the following bonus:

1.Secret Anonymizing Techniques

This section will contain 2 bonus videos which will tell you the exact methods used by hackers to hide their identity while doing malicious things online

2.Direct Email Access and support

If you get stuck or don't understand any thing presented in the course, I will help you no longer how much time it takes, however this offer is for limited time only

So What are you waiting for go and grab your hands on Facebook hacking course and learn Facebook hacking and security right now.

Click here to purchase

Tuesday, March 1, 2011

How to hack facebook accounts or passwords

Hello friends welcome again, Today i am going to show you the way "How to hack Facebook accounts or passwords".i have told you the three methods to hack any email account and in gmail hack hack was only limited to gmail only. Today i am going to share the similar technique to hack Facebook account. So guys read on..



Today I will tell you the latest approach of Hacking Facebook Passwords or Accounts i.e "Smart Phishing with Email trap". And guys  you will be surprised to listen that what is the victim's trap ratio in Smart phishing trap is above 70% means , at least 70% people will going to come into your trap and success ratio is 100% means their accounts is yours ROFL. First of all What is "Smart Phishing with Email trap" ..

SMART PHISHING WITH EMAIL TRAP
Normal phishing is technique to hack passwords by fooling the victim make him login to particular website suing your phish or fake page. But normal phishing is easily detectable. But Smart Phishing with Email trap is almost undetectable and I will show you How its undetectable. In smart phishing we send HTML mails to the victim with same header as that of original mails by email address that looks similar to original one. And ask user to join some Group or watch video or read comment etc.. And mail looks that user has to enter in it and his password is ours. Here we exploit the fact that Most users who uses Facebook are subscribed to notification by their friends. So its quite easier to exploit fact. 

How to Hack Facebook Passwords or Accounts ?

1. First of all download the Facebook Phisher.

2. Extract the rar file now you will get three files as given below:
  •       index.html
  •       passes.txt
  •       write.php
3. Upload all the Three files to any of the free Web hosting server. Remember while creating the  account on these servers try the username as nearer as possible to the original URL like faccbook or facobook etc.. As its the most crucial step. Some Free Web hosting servers are given below you can also find few more for yourself.

4. Once you have uploaded all the three files to web hosting server now you have to send these to your victim. This is the most important step regarding smart phishing technique.
Below are some sample mails that will help you to understand how to TRAP victim effectively.

Sample Is shown Below:  This the sample email that comes to your email account from facebook.
Now You have to edit this mail. Open this email and click on forward  now you will see this email in editable mode now remove the forwarded headers etc and forward from Header.
Remember your Name in Gmail must be Facebook and email account should be like noreplyfacebook@gmail.com etc... Now you have to put the Fake link of index.html file that u have got after uploading on the Web hosting server in place of Two exploit points. Remember always put link in href and original text should be as such. And also try to keep the link as much as closer to facebook original link.


Similarly you can use JOIN This Group on Facebook sample mail and Watch this video on Facebook in the similar fashion i have told you.


5. Now After sending phisher to victim, once the user logs in to his Facebook account using your Phisher, his user ID and password are ours..And these are stored in passes.txt What you have to do is just refresh your Web hosting account files. 




6. The Log.txt file will contain the passwords and look like this:


 

Thats all Now you have hacked the password of victim. I hope you all have Liked It. 


HOW to Protect Your Facebook Account?

1. Never Follow any link from the any website or email. Always open manually www.facebook.com and then enter credentials.
2. Always check the URL in the address bar while joining any Group.


Find Unauthorized Activity in Your Email Account

Hello friends, do you think or suspect your email account has been hacked or somebody else is using your account?  Do you suspect that your Email account is under attack? Is email account secured enough that it cannot be hacked? Do you want to make your email account 100% hack proof? If Yes, then this article is for you. So friends read on..




Sometimes our email account has been hacked and we are not aware of that. Someone else i.e. some hacker is accessing your account and might be misusing it. But since we are not aware of that and we still think that our account and its privacy is safe but some third person is using it and accessing our private information and details. Now How you will detect that your account is under attack that How to find unauthorized activity in your email account. Here are few tips.


These are some signs of Unauthorized activity in Your email account:
1. Your new emails are marked as Read even if you’ve not read them.
2. Your emails are moved to Trash or even permanently deleted without your notice.
3. Your emails are being forwarded to a third party email address (check your settings then go to forwarding).
4. Your secondary email address is changed.
5. Phone Information is changed.

If you come across any of the above activities on your email account, then it is a clear indication that your email account is hacked.

There are some additional security features that Gmail provide its users for the Security and safety o your account.
Gmail provides an additional security feature to protect your email account through the means of IP address logging. That is, Gmail records your IP address every time you login to your Gmail account. So, if a third party gets access to your account then even his/her IP is also recorded. To see a list of recorded IP address, scroll down to the bottom of your Gmail account and you’ll see something like this.

You can see from the above figure that Gmail shows the IP address of last login (last account activity). You can click on Details to see the IP address of your last 5 activities. If you find that the IP listed in the logs doesn’t belong to you, then you can suspect unauthorized activity.



Steps to stop unauthorized activity on your email account
1. Verify you mobile phone, so that if your account is somehow got hacked then it will be easier to recover your email password.
2. If you suspect that your account is already hacked then these are the recommended things that you should perform.
a.  Change your Password
b.  Change your security question.
c.  Remove any third party email address (if any) to which your account is set to forward emails.
d.  Make sure that you can access the email account of your secondary email address.
e.  Also change you secondary email password and security question.

This will help you to stop all the illegal activity in your account. But there are several peoples who have asked me that their account is hacked or they forgot the password . Now if your account is already hacked means you are not been able to access your account then i please read the following article that i have written few weeks before. In this article i have explained all the possible ways to recover your email account password back again.

Hack Facebook Password using Keylogger

Hello Friends, in my previous post i have explained 4 ways to hack Facebook account password, where i have discussed the second best method to hack Facebook password is using Keyloggers. Today i will explain you how to hack Facebook password using keylogger.

Today i will explain you in detail with snapshots how to create your Facebook hacker keylogger, its a 100% Fully undetectable keylogger you can check this file using Virus total.  Its a 100% FUD remote keylogger with several advanced features. 
Today i will disclose you how i hacked 19000+ accounts, its so easy that anyone can do it. On my website you will never get any infected tool. If you have any doubt or feel something suspicious always test the link or file with virus total website before downloading. Never believe any website including mine also, always scan download links with virus total website or any such website before downloading it. Download it only when it does not have any virus.

Hack Facebook password using Keylogger Involves following steps:
1.  Create your Server that will hack passwords.
2. Extract the Icons from any software
3. Bind the Keylogger to make it Hidden
4. Spread your keylogger to victims

Note: This tutorial is for Educational Purposes only. I and Isoftdl is not responsible for any misuse of knowledge.

Let's start Facebook hacking tutorial in detail :

STEP1 : Create Server for Hacking Passwords
First of all for hacking any facebook account password, we have to create our keylogger server that will run on victims machine or PC and capture his keystrokes and mail us on the email account that we will use to build the keylogger. The keylogger server building process consists of several steps. 
The steps involved are mentioned below in detail:
1. First of all download the Keylogger.
Download Keylogger from here: LICK HERE TO DOWNLOAD 

DOWNLOAD BINDER HERE: CLICK HERE TO DOWNLOAD BINDER
2. Extract the RAR file. Now you will get one Folder and three files as shown in below snapshot:


 3. Now open the Keylogger file. Here you will need gmail ID and password. For safer use create a fake Gmail account and use it here as shown below:


hack facebook account
Hack Facebook account password using Keylogger
4. Now Click on server settings as shown. Here enter the time after which you want to receive reports, its always preferable to use 20 min timer for receiving files.  And Click on Output box to choose location of file and give it any name. Its always recommended to use system process name to make it undetectable like svchost or check any process name from your task manager and name it. Other fields are optional. The complete snapshot is shown below:


5. Now Click on Log and Result Setting. In Log EMail Title enter the subject of email like My keylogger report or simply my report or something else that you like. Also Click the last two options that i.e add Computer name and add victim name. The snapshot is shown below:


6. Now Click on Other Options.  In this section you just have to do one thing. Most hackers prefer warning message POP up but I love keylogger using any message. So unclick message button. Because when you bind it with any other software then it should not any warning messages otherwise it will be detectable.

7. Now at last click on Build Keylogger. Now after you click on it you will see your keylogger file at location that you have chosen in 4th step. Now this keylogger server file will be used to bind with any other software in Binding Step.

8. Now you keylogger server is ready that you will use to hack Facebook accounts. That's all for the server creation step now move to second main step.


Step 2.: Extracting the Icon file from any installer(resource hacker)
1. Open the Resource hacker folder and open the reshacker file.
2. Now go to its menu and open any setup file. Suppose we want to attach our keylogger to Ccleaner setup file. So open the Ccleaner setup with resource hacker. 
3. Now in menu there is one action button click on it and then click save all resources.




4. Now save all the resources to desktop or any other location of your choice.
5. It consists of two files one is icon file and other is res file . We only need icon file, so you can delete the other file i.e res file.
6. Now we have Icon of installer file(as discussed above Ccleaner setup Icon).




Step 3: Bind the Keylogger server with any software
1. Now Go to keylogger folder and open the Binder.
2. Now Click on + button given below to add files.
3. Now add the keylogger server and the set up of software (i.e. in our case it's Ccleaner setup).
4. Now in menu of Binder, Go to Settings. There select the icon that we have generated in the previous step and set the location of output file as shown in figure.
5. Now again go to File's menu in Binder and click on Bind files.
6. Now your Binded keylogger is ready. Now you have to spread it or send it to the victim that is your friend.



Step4 : How to Spread Keylogger or send it to victim or friend
1. Now you have one Software setup file with keylogger attached with it.(In our case we have Ccleaner setup with keylogger attached with it.
2. Now Spread your keylogger through forums. You might be a member of various forums use them to spread your keylogger in form of software posts. You can use various software's to spread them that users frequently download.
3. Spread it through pendrives or USB hard drives. Suppose a friend asked you for a software give it the software that has keylogger attached with it. 
Note: you can also attach keylogger with images also. But that can be detectable by antivirus. So avoid such type of hacking.
So isn't that so easy to hack anyone's Facebook account in just few minutes. 

How to protect yourself from these hacks?
Prevention is always better than cure so always follow these steps:
1. Don't use cracked softwares and don't download them from unauthorized websites.
2. Always keep your antivirus and anti-spyware up to date.
3. Always scan the files before transferring them to your USB.
4. Do not allow other users to use your PC i.e password protect it.




Note: Hacking Email accounts is illegal. This post is just to aware you how easy is to hack Facebook and email accounts. So that you cannot fall into the traps of hackers.

I hope you all have liked it. If you have any queries ask me.  Please comment if you like my posts. Thanks for reading....

HOTFILE PREMIUM

HOTFILE Instructions:
1. Sign up a new Free account on http://hotfile.com
2. Install the latest version of firefox
3. go to this link -- https://addons.mozilla.org/en-US/firefox/addon/13793/
and install add and edit cookies and restart firefox
4. Sign in with your hotfile free account.
5. From the Firefox menu, click to Tools then select Cookie Editor.
6. Now in filter bar search for hotfile
7. The cookie name is AUTH ( you need to sign-in first to hotfile before you can see the cookie auth ) .
8. Now copy the Premium Cookie to the content bar. Click on save.
9. Copy/Paste the link that you want to download to firefox. 


For detailed information click here


205fa6773009dff74d8e69ba2117815309558109ac6c44acbd5091d00889d9ac
793c0fdef5e1ea529a042c1c38f2816d386d144233d433b8cb9ee12cd909badc


cb9720e0a3f18f04a308b84167f8816b5213ca57a8d0d0ba001c53846cebdf10
3c7354e1c59786fbbb60d6729fd8815dab948b033a529d269173ccc31af4dc77
6689383911fb2cc316eda055c55d816cd0b269a99186ccac6c6961c955ff49e1
061c5141c3e27708ea170aa5dd5d8174206bc020ccc1389468087a7a65eaae3f
528b00da3ec4831cbaf02880f6b98158b4ff7bdf3b1ec27582657781acb17325
56e9be850ab56cc5d0e40842fe3681600fd7f4a98d719f1528ea2f0487513086
dd302837a677bb3dd882d8037f1c8156f2af2855c1e68c7c0d9a28422e375c5f


9b482347afbdaa038ec10cabc8088131b47b7cc75542cbfd9a90f21f848d87dd
6874f59c9b6b58971fcec1316972815fe76de9334e2e545519b773d0d42ba2c0
ad65ccfa25f41dab9941d36d1ddd8159189431f9194fa83e12a223926df6ad32
d476d0c357d3a1b1d102f614b6e3814750fbda1f2e9d1b31bb59777cf455a801
c2c52240f187b9bba37a5950e896815de4a6f3f817ba5686c7ff1a0a41d43b71


login : okulaari66
pass : llc6Kq9

login: scorpion35
pass: 161235

Login : tylavie
Pass : diamond

Login : asphodel
Pass : tunahead

Login : marcel2k
Pass : marissa

Login : hovangr22
Pass : :vanosgr5672

Login : gmtgmt
Pass : thomas

How to use Hotfile Cookies for downloading as Premium



How to use Hotfile Cookies for downloading as Premium
1) Sign up a new Free account on the http://hotfile.com site that you want to use premium cookie.


2) Install "Cookie Editor" addon ( https://addons.mozilla.org/en-US/firefox/addon/13793/ ) then restart your Firefox browser.
3) Sign in with your signed account.
4) From the Firefox menu, click to Tools then select Cookie Editor. 
5) Double click to "Hotfile" site with "auth" value    ( only signing into free account you will able to see under line in picture darked hotfile.com   auth ) .
























 6) Paste this value to "Content" and click to Save button.


















7)Copy/Paste the link to the browser that you want to download

Viral and Malicious Facebook Application Toolkit

During last weekend a viral rogue app campaign hit Facebook again. This time the application was called “Profile Creeps” which, like many other rogue applications before it, promises to do what Facebook simply doesn’t allow *ANY* app to do – let us know who looks at our profile. But users are still tricked into installing apps that promise to do just this. And just like most others, the latest one leads to a survey that in the end generates money for the people behind the app.

let’s look at a very similar fraudulent application that “can” allow Facebook users to know who “creeps” at their profile, called “Facebook Profile Creeper Tracker Pro”. The application asks for some permissions, shows an online survey/advertisements and tells the user at the end of the process that he/she is the one that looks at his/her own profile the most. In other words, this application should be revoked according to the terms and conditions of Facebook.
“Facebook Profile Creeper Tracker Pro” and similar fraudulent applications

This application was built with a pre-defined toolkit called “Tinie app” which is a Facebook viral application template available in some variations for only $25 or even less. The next image is one of the template images in the toolkit that aims to give some directions to the buyer, besides the full-blown step-by-step guide that comes with the kit itself:

The buyer doesn’t have to have development experience with Facebook, he/she just needs to follow the accompanying instructions and a working viral Facebook application is at their disposal.

Facebook ClickJacking : Malware takes on new Italian disguises

Facebook users have been subjected to clickjacking attacks that force them to authorize actions they had no intention of approving.
The latest few campaigns seen by SophosLabs, for instance, target Italian users of the social network.


COCA COLA: Dopo aver visto questo video non berrò più coca cola. Svelata la ricetta segreta. Guarda il video verita
Which translates as: “COCA COLA: After watching this video you won’t drink Coca Cola. The secret recipe revealed. Watch the video truth.”

LO SCHERZO DI SAN VALENTINO CHE STA FACENDO IL GIRO DEL MONDO! TE RETO A VER ESTA PAGINA PARA 5 SEGUNDOS SIN REIRTE
Which translates as: “THE VALENTINE’S DAY JOKE THAT IS GOING AROUND THE WORLD! I CHALLENGE YOU TO VIEW THIS PAGE FOR 5 SECONDS WITHOUT LAUGHING.”
All of these Facebook scams use clickjacking techniques to trick the user into “liking” them.
SophosLabs is intercepting the suspicious pages as Mal/FBJack-A.
Facebook users can protect themselves from clickjacking threats like this by using browser plugins such as NoScript for Firefox.

Cryptography


 By definition cryptography is the process of converting recognisable data into an encrypted code for transmitting it over a network (either trusted or untrusted). Data is encrypted at the source, i.e. sender's end and decrypted at the destination, i.e. receiver's end.

In all cases, the initial unencrypted data is referred to as plaintext. It is encrypted into ciphertext, which will in turn (usually) be decrypted into usable plaintext using different encryption algorithms.


The Purpose :-
* Authentication : The process of proving one's identity.
* Privacy/confidentiality : Ensuring that no one can read the message except the intended receiver.
* Integrity : Assuring the receiver that the received message has not been altered in any way from the original.
* Non-repudiation : A mechanism to prove that the sender really sent this message.

In general cryptographic algorithms are classified into three categories as follows :

1) Secret Key Cryptography (SKC) : Uses a single key for both encryption and decryption.
2) Public Key Cryptography (PKC) : Uses one key for encryption and another for decryption.
3) Hash Functions : Uses a mathematical transformation to irreversibly "encrypt" information.

Secret Key Cryptography :- With secret key cryptography, a single key is used for both encryption and decryption. Because a single key is used for both functions, secret key cryptography is also called symmetric encryption.

Secret key cryptography algorithms that are in use today include :

1) Data Encryption Standard (DES) : DES is a block-cipher employing a 56-bit key that operates on 64-bit blocks. DES uses a key of only 56 bits, and thus it is now susceptible to "brute force" attacks.
Triple-DES (3DES) and DESX are the two important variants that strengthen DES.

2) Advanced Encryption Standard (AES ) : The algorithm can use a variable block length and key length; the latest specification allowed any combination of keys lengths of 128, 192, or 256 bits and blocks of length 128, 192, or 256 bits.

3 ) International Data Encryption Algorithm (IDEA) : Secret-key cryptosystem written by Xuejia Lai and James Massey, in 1992 and patented by Ascom; a 64-bit SKC block cipher using a 128-bit key. Also available internationally.

4) Rivest Ciphers : Named for Ron Rivest, a series of SKC algorithms.

RC1 : Designed on paper but never implemented.
RC2 : A 64-bit block cipher using variable-sized keys designed to replace DES. It's code has not been made public although many companies have licensed RC2 for use in their products. Described in RFC 2268.
RC3 : Found to be breakable during development.
RC4 : A stream cipher using variable-sized keys; it is widely used in commercial cryptography products, although it can only be exported using keys that are 40 bits or less in length.
RC5 : A block-cipher supporting a variety of block sizes, key sizes, and number of encryption passes over the data. Described in RFC 2040.
RC6 : An improvement over RC5, RC6 was one of the AES Round 2 algorithms.

5) Blowfish : A symmetric 64-bit block cipher invented by Bruce Schneier; optimized for 32-bit processors with large data caches, it is significantly faster than DES on a Pentium/PowerPC-class machine. Key lengths can vary from 32 to 448 bits in length. Blowfish, available freely and intended as a substitute for DES or IDEA, is in use in over 80 products.

Network Hacking


Network Hacking is generally means gathering information about domain by using tools like Telnet, NslookUp, Ping, Tracert, Netstat, etc.
It also includes OS Fingerprinting, Port Scaning and Port Surfing using various tools.

Ping :- Ping is part of ICMP (Internet Control Message Protocol) which is used to troubleshoot TCP/IP networks. So, Ping is basically a command that allows you to check whether the host is alive or not.
To ping a particular host the syntax is (at command prompt)--
c:/>ping hostname.com

example:- c:/>ping www.google.com



Various attributes used with 'Ping' command and their usage can be viewed by just typing c:/>ping at the command prompt.


Netstat :- It displays protocol statistics and current TCP/IP network connections. i.e. local address, remote address, port number, etc.
It's syntax is (at command prompt)--
c:/>netstat -n




Telnet :- Telnet is a program which runs on TCP/IP. Using it we can connect to the remote computer on particular port. When connected it grabs the daemon running on that port.
The basic syntax of Telnet is (at command prompt)--
c:/>telnet hostname.com

By default telnet connects to port 23 of remote computer.
So, the complete syntax is-
c:/>telnet www.hostname.com port

example:- c:/>telnet www.yahoo.com 21 or c:/>telnet 192.168.0.5 21


Tracert :- It is used to trace out the route taken by the certain information i.e. data packets from source to destination.
It's syntax is (at command prompt)--
c:/>tracert www.hostname.com
example:- c:/>tracert www.insecure.in




Here "*    *    *    Request timed out." indicates that firewall installed on that system block the request and hence we can't obtain it's IP address.

various attributes used with tracert command and their usage can be viewed by just typing c:/>tracert at the command prompt.

The information obtained by using tracert command can be further used to find out exact operating system running on target system.

Turkojan 4


Features :
* Reverse Connection
* Remote Desktop(very fast)
* Webcam Streaming(very fast)
* Audio Streaming
* Thumbnail viewer
* Remote passwords
* MSN Sniffer
* Remote Shell
* Web-Site Blocking
* Chat with server
* Send fake messages
* Advanced file manager
* Zipping files&folders
* Find files
* Change remote screen resolution
* Mouse manager
* Information about remote computer
* Clipboard manager
* IE options
* Running Process
* Service Manager
* Keyboard Manager
* Online keylogger
* Offline keylogger
* Fun Menu
* Registry manager
* Invisible in Searching Files/Regedit/Msconfig
* Small Server 100kb
Download :
http://www.4shared.com/file/72543880/bd92d968/TurkojaN_4.html
http://w14.easy-share.com/1702095672.html

Password Hacking

Password cracking is the process of recovering secret passwords from data that has been stored in or transmitted by a computer system. A common approach is to repeatedly try guesses for the password.
Most passwords can be cracked by using following techniques :

1) Hashing :- Here we will refer to the one way function (which may be either an encryption function or cryptographic hash) employed as a hash and its output as a hashed password.
If a system uses a reversible function to obscure stored passwords, exploiting that weakness can recover even 'well-chosen' passwords.
One example is the LM hash that Microsoft Windows uses by default to store user passwords that are less than 15 characters in length.
LM hash breaks the password into two 7-character fields which are then hashed separately, allowing each half to be attacked separately.

Hash functions like SHA-512, SHA-1, and MD5 are considered impossible to invert when used correctly.


2) Guessing :- Many passwords can be guessed either by humans or by sophisticated cracking programs armed with dictionaries (dictionary based) and the user's personal information. Not surprisingly, many users choose weak passwords, usually one related to themselves in some way. Repeated research over some 40 years has demonstrated that around 40% of user-chosen passwords are readily guessable by programs. Examples of insecure choices include:
* blank (none)
* the word "password", "passcode", "admin" and their derivatives
* the user's name or login name
* the name of their significant other or another person (loved one)
* their birthplace or date of birth
* a pet's name
* a dictionary word in any language
* automobile licence plate number
* a row of letters from a standard keyboard layout (eg, the qwerty keyboard -- qwerty itself, asdf, or qwertyuiop)
* a simple modification of one of the preceding, such as suffixing a digit or reversing the order of the letters.
and so on....
In one survery of MySpace passwords which had been phished, 3.8 percent of passwords were a single word found in a dictionary, and another 12 percent were a word plus a final digit; two-thirds of the time that digit was.
A password containing both uppercase &  lowercase characters, numbers and special characters too; is a strong password and can never be guessed.


Check Your Password Strength


3) Default Passwords :- A moderately high number of local and online applications have inbuilt default passwords that have been configured by programmers during development stages of software. There are lots of applications running on the internet on which default passwords are enabled. So, it is quite easy for an attacker to enter default password and gain access to sensitive information. A list containing default passwords of some of the most popular applications is available on the internet.
Always disable or change the applications' (both online and offline) default username-password pairs.

4) Brute Force :- If all other techniques failed, then attackers uses brute force password cracking technique. Here an automatic tool is used which tries all possible combinations of available keys on the keyboard. As soon as correct password is reached it displays on the screen.This techniques takes extremely long time to complete, but password will surely cracked.
Long is the password, large is the time taken to brute force it.

5) Phishing :- This is the most effective and easily executable password cracking technique which is generally used to crack the passwords of e-mail accounts, and all those accounts where secret information or sensitive personal information is stored by user such as social networking websites, matrimonial websites, etc.
Phishing is a technique in which the attacker creates the fake login screen and send it to the victim, hoping that the victim gets fooled into entering the account username and password. As soon as victim click on "enter" or "login" login button this information reaches to the attacker using scripts or online form processors while the user(victim) is redirected to home page of e-mail service provider.
Never give reply to the messages which are demanding for your username-password, urging to be e-mail service provider.

It is possible to try to obtain the passwords through other different methods, such as social engineering, wiretapping, keystroke logging, login spoofing, dumpster diving, phishing, shoulder surfing, timing attack, acoustic cryptanalysis, using a Trojan Horse or virus, identity management system attacks (such as abuse of Self-service password reset) and compromising host security.
However, cracking usually designates a guessing attack.

Privacy Attacks


-: Privacy Attacks :-


Here attacker uses various automated tools which are freely available on the internet. Some of them are as follows:

1) Trojan :- Trojan is a Remote Administration Tool (RAT) which enable attacker to execute various software and hardware instructions on the target system.

Most trojans consist of two parts -
a) The Server Part :- It has to be installed on the the victim's computer.
b) The Client Part :- It is installed on attacker's system. This part gives attacker complete control over target computer.

Netbus, Girlfriend, sub7, Beast, Back Orifice are some of the popular trojans.

2) Keylogger :- Keyloggers are the tools which enable attacker to record all the keystrokes made by victim and send it's logs secretly to the attacker's e-mail address which is previously set by him.

Almost all the Trojans have keylogging function.

Use of latest updated antirus-firewall, detect the presence of trojan and remove it permanently.

3) Spyware :- Spyware utilities are the malicious programs that spy on the activities of victim, and covertly pass on the recorded information to the attacker without the victim's consent. Most spyware utilities monitor and record the victim's internet-surfing habits. Typically, a spyware tool is built into a host .exe file or utility. If a victim downloads and executes an infected .exe file, then the spyware becomes active on the victim's system.
Spyware tools can be hidden both in .exe files an even ordinary cookie files.
Most spyware tools are created and released on the internet with the aim of collecting useful information about a large number of Internet users for marketing and advertising purposes. On many occasions, attacker also use spyware tools for corporate espionage and spying purposes.

4) Sniffer :- Sniffers were originally developed as a tool for debugging/troubleshooting network problems.
The Ethernet based sniffer works with network interface card (NIC) to capture interprete and save the data packets sent across the network.
Sniffer can turn out to be quite dangerous. If an attacker manages to install a sniffer on your system or the router of your network, then all data including passwords, private messages, company secrets, etc. get captured.

Recommended  Tools
Snort
http://www.snort.org
Ethereal
http://www.ethereal.com

Friday, February 11, 2011

all about key loggers



A keylogger sometimes called a spying software is a small program which is used to monitor a local or a Remote PC, Keyloggers now a days are so easy to use that a person with even a basic knowledge of computers can use keylogger.Once a keylogger is installed in your computer it can monitor each and every keystroke typed on your computer, thus you can see how dangerous a keylogger can be.
Types of Keylogger

There are two types of Keyloggers:

1.Hardware keylogger
2.Software keylogger

Hardware keyloggers are rarely used now a days since you can monitor a Remote computer, Software keyloggers are the most widely used keyloggers as some of them support remote installaiton which means that you can monitor any computer anywhere in the World.


Can the victim detect it's presence once keylogger is installed in his/her computer?

Well it's really difficult for the victim to detect keylogger's presence as it runs in complete stealth mode, It hides it self from task manager, startup etc

Can I the victim trace you back?

Once the keylogger is installed, I think it's almost impossible for the victim to trace you back

How can I protect my self from keylogger?

A simple keylogger can be detected by even a lame antivirus, but sometimes the attacker can use methods like Crypting,Binding,Hexing etc, that make it harder for the Antivirus to detect the keylogger. So to counter that you should use a piece of software called sandboxie, Sandboxie runs the choosen computer program in an Isolated space so if the file you receive is a keylogger, You need no to worry because it won't affect your other programs, Firefox users can use the free version of keyscrambler which encrypts each and every keystrokes you type, so even if a keylogger is installed in your computer, You need not to worry as the attacker will receive the encrypted keystroke


Which Keylogger is the best?

With my experience of more than 4 years in the field of Ethical Hacking and security I suggest only two keyloggers which I think are best and have a comparatively low antivirus detection rate:

1.Sniperspy
2.Winspy


How do I find if a file is binded with a keylogger?

Keylogger can be binded with almost any file so how do you know if the file is binded?, You can use Bintext or Hex editor to find out, But Bintext and Hex editing method do not work effectively if the server is crypted so alternatively there is a great piece of software named asas "Resource hacker" that can tell you if the file is binded or not

Hope you had enjoyed reading the article.If you have any questions feel free to ask.