Showing posts with label Hacking. Show all posts
Showing posts with label Hacking. Show all posts

Tuesday, August 2, 2011

Intercepting HTTP request/response using WebScarab to hack Web Applications


Monday, August 1, 2011

PHISHING - Can your Browser protect you?


 
"When facts fail , reasons prevail."
You must be wondering why i used this quote in the beginning(i know none of you must have heard this because i created it while writing this blog) .
This is what phishing is all about . there has been a lot of buzz about the phishing scams that occur now and then which mostly targets lame internet users(sometimes expert) . They have a knowledge of almost all the technical advancements that internet can provide us like using emails, net banking, social circling etc. These are the building facts of the world wide web. But when there is some mis-happening(stealing of password, bank accounts etc) then they realise the reason behind it could be somthing we can call as a phishing scam .
before i tell you some intresting facts about phishing and its countermeasures let's find out what exactly is a phishing scam.


In the field of computer security, phishing is the criminally fraudulent process of attempting to acquire sensitive information such as usernames, passwords and credit card details by masquerading as a trustworthy entity in an electronic communication. Communications purporting to be from popular social web sites, auction sites, online payment processors or IT administrators are commonly used to lure the unsuspecting public. Phishing is typically carried out by e-mail or instant messaging and it often directs users to enter details at a fake website whose look and feel are almost identical to the legitimate one. Phishing is an example of social engineering techniques used to fool users and exploits the poor usability of current web security technologies.Attempts to deal with the growing number of reported phishing incidents include legislation, user training, public awareness, and technical security measures.


There are numerous techniques exposed so far but i am mentioning the most commonly used scams here
 
Link manipulation

Most methods of phishing use some form of technical deception designed to make a link in an e-mail (and the spoofed website it leads to) appear to belong to the spoofed organization. Misspelled URLs or the use of subdomains are common tricks used by phishers. In the following example URL, http://www.yourbank.example.com/, it appears as though the URL will take you to the example section of the yourbank website; actually this URL points to the "yourbank" (i.e. phishing) section of the example website. 

Filter evasion

Phishers have used images instead of text to make it harder for anti-phishing filters to detect text commonly used in phishing e-mails.

Website forgery
 
This is the most widly used phishing technique. We can say that website forgery is a super set of the other two phishing scams namely link manipulation and filter invasion because its basically the forged link or the web page that is mostly transferred as the target page.

Phishing Facts

World

MessageLabs, a company that manages email security, reports a vast increase in phishing emails in the past six months. In September, 2003, the number of phishing emails the company saw was 279. By January of 2004, the number had risen 1200 percent to 337,050. Meantime, the Anti-Phishing Working Group, an industry association focused on eliminating the identity theft and fraud that result from the growing problem of phishing and email spoofing, reports more dangerous facts. In April, the attacks increased 180%, and reports show 15 of the top 20 targeted organizations are financial institutions.
  • 1 in 5 Americans were the target of phishing attacks during the last year.
  • 57 million consumers have received phishing emails.
  • Out of 4 million consumers who encountered fraud last year when opening a new online account, over 50% said they also received a phishing e-mail.
INDIA

India has got the dubious record of being among the top 10 countries where sites involved in `phishing' are hosted the most, according to a new report released by Anti-Phishing Working Group.

All About Botnets and Zombies

Low Orbit Ion Canon - Ddos Attacking tool


Recently you must have heard about the paypal site being brought down by the wikileaks supporters . I also participated in that mass Ddos attack to support wikileaks .
During that mass attack i came across this very handy,simple yet deadly tool called Low orbit ion cannon.
LOIC is an open source network attack application, written in C#. LOIC was initially developed by Praetox Technologies, but later it was released into the public domain.
LOIC is an acronym for Low Orbit Ion Cannon, a fictional weapon in the Command & Conquer series of video games.

LOIC performs a denial-of-service (DoS) attack (or when used by multiple individuals, a DDoS attack) on a target site by flooding the server with TCP packets, UDP packets, or HTTP requests with the intention of disrupting the service of a particular host. People have used LOIC to join voluntary botnets.

Login Spoofer-Gmail,yahoo,facebook,hotmail password hacking.

Top 10 "deadly hacking softwares "


There have been a lot of tools floating around the web who claim to be the best in their respective fields.
I have used many hacking tools that are built for both windows and linux platform and have seen that the linux tools are far more powerful than the windows tools. Keeping this thing in mind i thought to compile my list to those softwares that work well for both the platform and perform similar features.
The list has some new names compared to those in last years blog. I have also provided a download link of all the ten softwares compiled in a single zipped file to ease the downloading.

1.Nmap

Nmap ,by far is the best security scanning and hacking tool ever made. This software tops every list of top hacking softwares for its two reasons. Firstly,its ease of use and secondly,its wide usage.
It provides a wide range of features like port scanning, fingureprinting, os detection , ping , scanning an IP range , alive hosts etc. It has a rich command mode for advanced users which can combine several commands together to execute ones. Its the most recomended tool for new as well as advanced learners and security experts. It hosts its google  opensource project every year. Download the zip.

2.SuperScan


Powerful TCP port scanner, pinger, resolver. SuperScan 4 is an update of the highly popular Windows port scanning tool, SuperScan.  If you need an alternative for nmap on Windows with a decent interface, I
suggest you check this out, it’s pretty nice. It provides a cool scanning experience with lot of information displayed .Downlaod the zip
3.Cain and Abel


My personal favourite for password cracking of any kind.
Cain & Abel is a password recovery tool for Microsoft Operating Systems. It allows easy recovery of various kind of passwords by sniffing the network, cracking encrypted passwords using Dictionary, Brute-Force and Cryptanalysis attacks, recording VoIP conversations, decoding scrambled passwords, revealing password boxes, uncovering cached passwords and analyzing routing protocols.
The program does not exploit any software vulnerabilities or bugs that could not be fixed with little effort. Download the zip

4.John The Riper


This is my personal favourite password cracking which has been in the market for over a decade and it has evolved into a powerful tool because of the special effort of the open source community.John the Ripper is a fast password cracker, currently available for many flavors of Unix (11 are officially supported, not counting different architectures), DOS, Win32, BeOS, and OpenVMS. Its primary purpose is to detect weak Unix passwords. Besides several crypt(3) password hash types most commonly found on various Unix flavors, supported out of the box are Kerberos AFS and Windows NT/2000/XP/2003 LM hashes, plus several more with contributed patches. Download the zip

5.fsCrack


FSCrack is a front end for John the Ripper (JtR) that provides a graphical user interface (GUI) for access to most of JtR’s functions.It increases the functionality of JTR and provides a detailed report of password cracking . The working is similar to JTR by using the SAM file of windows to crack the admin password. Download the zip

6.Nessus Security Scanner


This tool has been the best tool for both network administrators and hackers because of its wide implimentation.The Nessus® vulnerability scanner is the world-leader in active scanners, featuring high-speed discovery, configuration auditing, asset profiling, sensitive data discovery and vulnerability analysis of your security posture. Nessus scanners can be distributed throughout an entire enterprise, inside DMZs and across physically separate networks.  Download the zip
7.Wireshark


Wireshark is a GTK+-based network protocol analyzer, or sniffer, that lets you capture and interactively browse the contents of network frames. The goal of the project is to create a commercial-quality analyzer for Unix and to give Wireshark features that are missing from closed-source sniffers. Works great on both Linux and Windows (with a GUI), easy to use and can reconstruct TCP/IP Streams!. Download the zip


8.Live Bulk Mailer

Live bulk mailer has the ability to still deface the spam filter of gmail,hotmail and yahoo. Its an email flooding tool that allows the attacker to send desired number of bulk mails to the victim inbox and flood it completely. This can be an annoying task and can also put you into trouble so before using this tool dont forget to use a proxy server to hide your IP address. Download the zip

9.Website Digger
Website digger is a tool that helps you to digg into a website and gain information about the host by applying whois query and also banner grabbing capability. This tool is useful while defacing a webpage. Download the zip

10.PuTTY



PuTTY is a free implementation of Telnet and SSH for Win32 and Unix platforms, along with an xterm terminal emulator. A must have for any h4. 0r wanting to telnet or SSH from Windows without having to use the crappy default MS command line clients.
Download the zip


Donation Plan:


 
Site Maintained by Prerna