Showing posts with label tutorial. Show all posts
Showing posts with label tutorial. Show all posts

Thursday, October 23, 2014

DNS Hacking : Tutorial oct 2014

DNS Hacking : Tutorial oct 2014
 

DNS hijacking (sometimes referred to as DNS redirection) is a type of malicious attack that overrides a computer’s TCP/IP settings to point it at a rogue DNS server, thereby invalidating the default DNS settings. In other words, when an attacker takes control of a computer to alter its DNS settings, so that it now points to a rogue DNS server, the process is referred to as DNS hijacking.
As we all know, the “Domain Name System (DNS)” is mainly responsible for translating a user friendly domain name such as “google.com” to its corresponding IP address “74.125.235.46”. Having a clear idea of DNS and its working can help you better understand what DNS hijacking is all about. If you are fairly new to the concept of DNS, I would recommend reading my previous post on How Domain Name System Works.

How DNS Hijacking Works?

As mentioned before, DNS is the one that is responsible for mapping the user friendly domain names to their corresponding IP addresses. This DNS server is owned and maintained by your Internet service provider (ISP) and many other private business organizations. By default, your computer is configured to use the DNS server from the ISP. In some cases, your computer may even be using the DNS services of other reputed organizations such as Google. In this case, you are said to be safe and everything seems to work normally.
DNS Hijacking
But, imagine a situation where a hacker or a malware program gains unauthorized access to your computer and changes the DNS settings, so that your computer now uses one of the rogue DNS servers that is owned and maintained by the hacker. When this happens, the rogue DNS server may translate domain names of desirable websites (such as banks, search engines, social networking sites etc.) to IP addresses of malicious websites. As a result, when you type the URL of a website in the address bar, you may be taken to a fake website instead of the one you are intending for. Sometimes, this can put you in deep trouble!

What are the Dangers of DNS Hijacking?

The dangers of DNS hijacking can vary and depend on the intention behind the attack. Many ISPs such as “OpenDNS” and “Comcast” use DNS hijacking for introducing advertisements or collecting statistics. Even though this can cause no serious damage to the users, it is considered as a violation of RFC standards for DNS responses.
Other dangers of DNS hijacking include the following attacks:
Pharming: This is a kind of attack where a website’s traffic is redirected to another website that is a fake one. For example, when a user tries to visit a social networking website such as Facebook.com he may be redirected to another website that is filled with pop-ups and advertisements. This is often done by hackers in order to generate advertising revenue.
Phishing: This is a kind of attack where users are redirected to a malicious website whose design (look and feel) matches exactly with that of the original one. For example, when a user tries to log in to his bank account, he may be redirected to a malicious website that steals his login details.

How to Prevent DNS Hijacking?

In most cases, attackers make use of malware programs such as a trojan horse to carry out DNS hijacking. These DNS hijacking trojans are often distributed as video and audio codecs, video downloaders, YoTube downloaders or as other free utilities. So, in order to stay protected, it is recommended to stay away from untrusted websites that offer free downloads. The DNSChanger trojan is an example of one such malware that hijacked the DNS settings of over 4 million computers to drive a profit of about 14 million USD through fraudulent advertising revenue.
Also, it is necessary to change the default password of your router, so that it would not be possible for the attacker to modify your router settings using the default password that came with the factory setting. For more details on this topic you can read my other post on How to Hack an Ethernet ADSL Router.
Installing a good antivirus program and keeping it up-to-date can offer a great deal of protection to your computer against any such attacks.

What if you are already a victim of DNS hijacking?

If you suspect that your computer is infected with a malware program such as DNSChanger, you need not panic. It is fairly simple and easy to recover from the damage caused by such programs. All you have to do is, just verify your current DNS settings to make sure that you are not using any of those DNS IPs that are blacklisted. Otherwise re-configure your DNS settings as per the guidelines of your ISP.

ADDING BACKDOOR IN HACKED FACEBOOK ACCOUNTS

ADDING BACKDOOR IN HACKED FACEBOOK ACCOUNTS

Here is a way how some hackers retain the hacked facebook accounts even after the target changes the password or the hacker himself returns it to the target.
Many of the facebook users are unaware that there is a alternative way to log in the facebook account by linking a alternate email account to it. Not the default email id which you use regularly to log in by typing the email id and password but a different email id. So when you are logged in this alternate email id and open the facebook website it directly logs in your facebook account without even asking the password. If you did not get the concept here is a example. Imagine that your regular email id is "regular@gmail.com" and you add a alternate email id "alternate@gmail.com" in account setting. Now when you are logged in "alternate@gmail.com"
and open facebook website it redirects you and directly opens your facebook account. So here the is procedure how you can add this alternate email id as a backdoor.


STEP 1) Open your facebook account and go to account settings.


STEP 2) In the settings tab you will see a option "Email" click on "change" and add a new contact email which is to be the backdoor.


STEP 3) Now again in the setting tab you will see a option "Linked accounts" click on "change" and add the type of your alternate email id like google, yahoo etc.

And that's it, your done, now try it. Log of the facebook account, log in the alternate email id and open facebook website and wait, don't stop the loading, after some seconds it will redirect you to the facebook account.

Note:- The targets who got back their hacked accounts should always check if such backdoor was added to their account, if yes then it should be removed quickly.
==================By:-HT Team =====================

 

KEYLOGGING AND USING KEYLOGGERS FOR HACKING

KEYLOGGING AND USING KEYLOGGERS FOR HACKING
One of the most popular and easy way of hacking passwords, social networking accounts and other information is keylogging.
Keylogging in general refers to keeping a track of the keys pressed on a computer system.
There are two ways to keylogging.
1) Using a physical device which is connected to the computer, which keeps track of the keys pressed on the computer .
2) Using a keylogger software.
The first method is less preferred as the devices are costly and they have to be physically connected to the computers which is hard if you don’t have physical asses to the computer but they have their own merits like they are not detected by firewalls and antivirus software.
But mostly keylogger software are preferred as they are cheap, easy to use and provide many extra features like remote spying , making a quick installing package which is very useful if you don’t have physical asses to the computer. They can work in hidden mode, means they wont show in your added programs list and can only me assessed by pressing some special sequence of keys but they have their own demerits like they are detected by latest firewalls and antivirus softwares .
But there are many keyloggers out there which can bypass the firewalls and fool the antivirus.
Use those keyloggers which come under the category of parenting control or spying software, which are used by parents to keep an eye on their child’s online activities they are antivirus friendly, means they wont be detected by antivirus because if they were detected by antivirus then they wont be of any use as the child will know he is been spied on. Some antivirus, at extreme may just give a warning. But these keyloggers also have some disadvantages like they don’t have features like making remote installation package.
 
=======================By:- HT Team*==========================

PHISHING TUTORIAL FOR BEGINNERS OCT 2014

PHISHING TUTORIAL FOR BEGINNERS OCT 2014

PHISHING is a hacking method in which the attacker sends a email or link. clicking on which will take you to a site which looks exactly the same as the site you use like facebook, orkut, gmail etc. where you will be told to provide your information and bingo! you are hacked and the best part is after that you will be redirected to the original website and some common reason like network or server problem will be shown, so you wont even come to know that you were hacked.

here is a tutorial about how you can try phishing and have some fun.

STEP 1) First you must sign for a free webhosting service like www.byethost.com
And register your subdomain. After registration you will have a subdomain like www.yourname.byethost.com (Please select the name of the website wisely and please don't add the name of the website whose phishing page you are making eg. if you are making phishing page of Facebook then pls don't add the word Facebook in the name of the phishing as this website are easily detected and block.)

STEP 2) Now login to your account go to "control panel" then in site management option go to "online file manager" and open the folder "htdocs".

STEP 3) Now DOWNLOAD THIS FILE to your computer and extract the files inside it, you will see folders named facebook, orkut etc. choose which account you want to hack and open the folder, inside the folder you will find two files index.htm and write.php.

STEP 4) Now login to to your Byethost's cpanel (all the details of the byethost account will be there in the confirmation email send by byethost) choose "online file manager" in the cpanel.

STEP 5) (There were many suggestions to make this point more clear so i have divided this 5th step itself into some substeps. hope this will help the readers to understand this step more easily).
  • There are two files in the phisher file downloaded by you, "index.htm" and "write.php. Now right click on "index.htm" and select "edit", the file will open in notepad, press "ctrl + a" to select the whole text and copy it.
  • Now in the cpanel of your byethost account click on "online file manager". In it there is a folder "htdocs" click on it. In it there is a file also called "index.htm", there is a option to edit it, choose the edit option. Now a new window will open, delete all the text in it and paste what you had copied earlier from the "index.htm" in your phisher file. Click on the on the save icon and you are done!.
STEP 6) Now your homepage www.yourname.byethost.com has become a phisher. open it, you will see that your page www.yourname.byethost.com has become the login page of the site you want to hack.now all you have to do is send this link to the person whose account you want to hack.when he tries to login through it you will receive a file passes.txt in your "htdocs" folder of your byethost account which contains the username and password of your victim.

====================By:- HT Team*=================

Wednesday, October 22, 2014

Increase Website Traffic Trick 2014

Increase Website Traffic Trick 2014

Here is a quick and easy list that you can use as a guide. You can use this list as a checklist for the things that you can do to improve your website traffic. It will help you discover or perhaps, rediscover the facts that you might have already forgotten.

  • People like to win free things, whether it the things they win are essential or not. Everyone simply loves a freebie. To advertise your site and increase your visitors, you might want to consider giving a free e-book to anyone who will join the site’s mailing list.
  • Give away something more valuable like free samples of your products. In exchange you may ask your customers to give a testimonial. Testimonials add to the effectiveness of your marketing.
  • Gain people’s trust by creating an eBook you made yourself. This will put you in the “Expert” category and people will look to you for questions. They will trust you and your product.
  • Have a link where customers can get the website in the form of an eBook. This makes you more accessible to them. Or if you are into direct mail, include a DVD or a CD of your site in the package. This ca be given away by the recipient of the package and can increase your sales.
  • Offer something for free for each purchase the customer makes. This always translated to value for money.
  • Create a referral system. Give a freebie to someone who can refer a certain number of e-mail addresses of people they can get to visit your site. This will help create a mailing list for you.
  • Create an eBook directory. Place all the websites you have in that directory. Give another freebie to someone who places an ad in their own website that links to that directory you have created.
  • Make the eBook easily accessible and transferable. This can help your loyal customers distribute it quicker and easier, too.
  • Conduct a market research based on the contact information visitors give in your website. This will help you identify the markets you are not so strong on, and you can focus on them more.
  • Increase the number of people visiting your site for advertisement purposes by offering a place in your website directory. This can be used as advertisement space and you can even charge the people who will use it.
  • Take care of your customers and give them monthly eBooks or newsletters. This will let them feel pampered and remembered. You can place new products by the end of the newsletter to keep customer coming back for more.
  • Increase traffic by submitting your eBooks to websites that have shareware. This will allow people to download it even without visiting your site just yet. After reading the eBook about your products, they will be enticed to visit your site.
  • Sell reprints to those who want to sell the eBook you made.
  • Hold a contest for the websites that best advertise your content and give them free space in your website directory.
  • Tell people about your site and your eBook, and ask them for referrals, too.
  • Cross promote your eBook with other products and services. Some people may not be satisfied with just a freebie, so show those people exactly what you have in your company.
  • Give incentives to customers who are subscribed to your newsletters. These are people who spread the word around and get people to visit your site
  • Give away a freebie to those who will become your affiliate. This will increase the number of people who will advertise the website.
  • Give incentives to people who will respond to your follow up marketing.
  • Make sure that you keep people interested. Offer them new freebies as time goes.

        ========by:- HT Team*===========

 

HACK VALID CREDIT CARD NUMBERS WITH CVV NUMBERS Oct 2014

HACK VALID CREDIT CARD NUMBERS WITH CVV NUMBERS Oct 2014

Hack Valid Credit Card Numbers With CVV Numbers


Scientific American ( www.sciam.com ) has published an article entitled 'How to steal millions in chump change' which was about online credit card theft.


Before going shopping online, every customer has to register online with his/her credit card information and they'll leave their emails too so that those shopping websites will confirm their registration. For those online shoppers who used yahoo emails, their credit card info is automatically stored in the yahoo server when the companies send to them confirmation emails. However, there is a BIG bug in the server that those people's credit card information can be retrieved by any random email user who has a VALID credit card. To simplify this, here is how it works:


Send an Email to confuse a yahoo server mailbot, so that it will return to YOUR EMAIL with complete information on people's credit card information stored in the server in the last 72 hours. This is how you will get people's VALID credit card information. Now you have to do exactly the same as follows:


EDIT: removed redundant information


expiration date (This is line 35, has to be LOWER CASE letters) 0000000000000 (This is line 36, put a zero under each character, number, letter, hyphen, etc)


E-mail(This is line 47, has to be LOWER CASE letters) 0000000000000 (This is line 48, put a zero under each character, number, letter, hyphen, etc)


252ads (This is line 51)


Return-Path: (This is line 54, type in your email between ) s_


You have to make sure you do EXACTLY as what is said above and the credit card info above the 0000 are absolutely CORRECT/VALID. Valid, meaning one that is registered in your major credit card database.


For those who like to play it safe, thinking this is too good to be true. Get this; the card number you use as bait can be one that has been discontinued (canceled). However, it cannot be expired and the card information must be correct. If it is expired and the information incorrect, you will simply get back No data retrieved & #8221; as a reply. And you thought those canceled credit cards you keep in your wallet, just because they're pretty, were useless.


Here is a sample email: (CAUTION! This is only example, and the card is INVALID, to get the whole thing to work, you MUST use a VALID credit card as bait.


Send to: <removed>
Subject: accntopp-cc-E52488
Email body:
boundary='0-86226711-106343'
Content-Type: text/plain; charset=us-ascii
4013993145565451

0000000000000000
jesse d banks

00000000000
523

000
2537 Stillwell rd.,des moines

00000000000000000000000
ia, usa, 50567

0000000000
901-834-4183

000000000000
visa

0000

03/2006

0000000
<email removed>

000000000000000000000
252ads
Return-Path


Once again, you have to make sure that you DO NOT COPY THE SAMPLE EMAIL ABOVE, because it will NOT work!!! It is there to help you set it up. Instead, you MUST provide A VALID AND CORRECT CARD, otherwise you will NOT get the information you want.


ANOTHER METHOD 1

Do exactly as follows and using your own valid credit card as bait

send the message to servic.bots@yahoo.com
in the subject bar write accntopp-cc-E52488-verify-info

now for the body of the email write how it is below (in lower case letters and using your own details)

boundary="0-86226711-CC-Verificator-106343"

Content-Type: text/plain; charset=us-ascii

card number (use your own)
0000000000 (a zero for every digit)

name on card (use your own)
0000000000 (a zero for every letter)

date of birth (use your own)
00000000000 (a zero for every digit)

cid/cvv2 number (on back of your card)
000 (should be 3 or 4 zeros)

address linked to card (use the one linked to your card)
0000000000000000000 (a zero for every number and digit)

city,state and zip code (use the one linked to card)
0000000000000000000 (a zero for every letter and digit)

phone number (use your own)
00000000000 (a zero for every digit)

type of card (mastercard, visa etc)
0000000000 (a zero for every letter)

expiry date (use the one on card)
000000 (a zero for every digit)

your email address (use your every day email for this)
0000000000000000 (a zero for every character)

252ads< m >

return-path:


ANOTHER METHOD 2

Okay everybody, I recently discovered a way to hack the credit card server at yahoo. Whenever someone with a yahoo email address registers their credit card information on a shopping website, the information is entered into the yahoo server. One problem, the yahoo email server has a bug. All you need is a valid credit card. Email the yahoo server and the auto bot will glitch and send all the credit card information entered into the system in the last 72 hours to your email address, jackpot. Here are the steps:

1. Email money_server@yahoo.com
2. Enter the subject as annc.98iooi.asd (to confuse the server)
3. Enter your name (first and last), email address, and valid credit card information (card number, card carrier, card expiration date, card security code) and make sure all the information is there and valid or it wont work!
4. There you go! In seconds yahoo will email you back with thousands of credit cards.
 
======================By:- HT Team*==============================

Credit card Hacking Tutorial Oct 2014 Final

Credit card Hacking Tutorial Oct 2014 Final

In thisTtutorial , i will teach you the terms “carding” , “scamming” , “cvv2″ etc. I’ll also tell some tricks for sites such as ebay.com , ebay.co.uk , actually just ebay

let’s start with explaining the term “CARDING”

Chapter 1 : Introduction and Tips.

Carding , or scamming as other people would say , is an art. It’s basically ordering items from the Net (cellphones , laptops, PDA’s , TV’s ,……) without actually
paying for it . or at least , not paying with your own money

Now you’ll all be wondering how we do this stuff.
Well , most sites accept credit cards as a payment form . These credit cards can be obtained from mIRC or from public forums , which i won’t display here
due to security reasons.

For the dummies : a creditcard is a 16 digit number which can be used to pay , some sort of bank card.

There are different types of creditcards :

Visa
Mastercard(MC)
American Express (AMEX)
Discover
Novus
JCB

When you obtain a creditcard , you have to recognise the type .

A card starting with a 4 is a Visa , with a 5 is a Mastercard , with a 3 (15 digits long) is an Amex , with a 6 is Dicover/JCB.

Some sites might ask for a CVV2 , this is the tree digit verification code on the back of the card.
Mostly this is also pasted on the forum or mIRC channel.

Note : Amex has a 4 digit verification code , and for discover 000 can be used.

Now there are some tips and tricks when you want to order something .

* Look for a site with a shitty layout , they’ll probably have a shitty security and are “cardable” (this means you cane asily get stuff from the site )
* Try to use Discover or Amex , these cards are less involved with chargebacks etc and most merchants (payment processors) won’t verify these cards , instead of visa and
mastercard , which have alot of chargebacks.
* Don’t use a store in your own country , especially not big ones . Ebay.co.uk is one of the best cardable sites if you have the right techniques..

When ordering , sites will ask for a billing adress and a shipping adress.
The billing adress is the adress listed on the creditcard , the shipping adress is your adress or a drop adress , a so called “delivery adress”.

As you might have noticed , i oftenly mentioned ebay as a site to buy goods from.
But ebay doesn’t use an instant paying service , they offer online paying services such as Paypal and Auctionpayments.com .
These sites gladly accept all types of creditcards , from all over the world .

Chapter 2 : Ebay , Paypal.com

Ebay

As you will probably know , ebay.com is an online auction site where goods can be sold and bought by people over the world.
This site is one of the most visited shopping sites , because of its large variety of goods and prices , which can be lower then store prices.

Now the question is : how to contact the seller and arrange the fraudulent deal.

Well , to contact the seller you will need an ebay buyer account.This means you have to register yourself at www.ebay.com , and do NOT use your real information , because
they will ask you to provide a creditcard and that one has to match with the adress on the card , so just use the cardholder’s info.
Also use a valid email adress , a yahoo or hotmail one for example , because you have to confirm your registration , and also the seller(s) will reply to you on that email adress.

If you see an item and you want to buy it , first ask the seller a question.
A question which will work well is the following one :

Hi there,
i am from USA and i am interested in purchasing this item from you .
i would like to pay this item with my paypal
But the item is a gift for my cousin in Belgium
can you gift wrap the package and calculate shipping costs for 2-3 days delivery?
please reply me with a total price and your paypal adress.

With this message i received alot of items , including cellphones , a PDA , shoes , a laptop , software, etc.

Paypal

Now i will (finally) explain the meaning of the word Paypal.

Paypal.com us an online payment method , which is used by alot of ebayers , and can be funded by bank transfers or creditcards (whoohoo)

All you need for this is a USA cvv2 (see chapter 1) and a valid email adress.

Visit www.paypal.com & click on Register/Sign up.
Fill in the form with the creditcard info (name , adress, city, state, zipcode , country , etc) and the email adress you are using for Ebay.
On the bottom of the page they will ask you to pick 2 security questions and give an answer on those questions , in case you forget your password.

Pick any random question and fill it in with random info , paypal cannot verify it .
After you have signed up , go to your email inbox & click on the paypal email .
Inside you will find a link which you’ll have to click in order to confirm the registration. You’ll visit a page which will ask you to confirm your paypal password.

Fill it in, click on submit , and paypal will ask you to add a bank account. We aren’t interested in this , so click on Skip.

Then you’ll see your account overview. In the left menu , click on Add a Credit Card.
On that page it’ll ask you the cardholder’s name , the ccnumber , type of creditcard (see chapter 1) , the expiry date and the Cvv2 (cfr. Chapter 1)

If all information is valid , click on Submit and hopefully you’ll get a message saying : you have succesfully added a creditcard . Blablablaa…….

If you are unlucky , you’ll get one of the following errors :

* This creditcard has already been assigned to another paypal account , please use a different card.(no explenation needed)
* You have entered an invalid or partial credit card number (cc number is incorrect)
* Your card has been declined because we could not verify the 3-4 digit code on the back of your card . (cvv2 is invalid)
* This card has been declined by your bank issuer . (card is invalid)

After you have successfully added a card , look in your email inbox for some replies from sellers which will contain a full price for the item.

Go to your paypal account, click on Send Money.Fill in the recipient (seller’s paypal email) , the amount , and pick Auction Goods (non Ebay) on the next page create a item number (10 digits maxium) , and a buyer ID (johndoe4852 for example). As auction site , select Other.
Then click on Continue , it’ll bring you to a new screen to confirm the information you entered.
As funding source , you’ll see that the credit card is selected .

On bottom you ‘ll see that paypal automatically selects the credit card adress as shipping adress. Leave this indicated like this , it’ll give the transaction a very legit look.
Then click on Confirm and hope for the best . If your purchase was succesfull , you’ll get a message saying you’ve sent cash or you paid for an online auction.
Then return to your paypal account & Log Out . Go to your inbox , tell the seller the money has been sent and provide the shipping adress in the email.

Also ask him to mail you back once the package is shipped .

If everything is ok, you should have the package in 1 week (including the weekend and holidays) .

After a while , the seller might mail you to tell you the payment has been reversed and asking you to send it again.
Simply ignore these emails by marking them as spam.