Welcome To - MaCHAcK

Showing posts with label Hacking Paradise. Show all posts
Showing posts with label Hacking Paradise. Show all posts

SQL Injections To Hack Websites

Author: P.R.O.V.I.D.E.R. // Category:
HERE IS THE METHOD TO HACK INTO A WEBSITE OR DATA INFORMATION:-

1. Using Forms to Your Advantage:


You probably already know about sql injection, my goal is to explain how vulnerable forms can be if not handled correctly. When targeting a system, most times you will start off with 0 code to exploit. The only thing you have is a constructed webpage to break to pieces and successfully find vulnerabilities to use to your advantage.


ACQUIRING DATABASE INFORMATION

A very logic way of acquiring system information from a website's database is by causing errors in the sql queries. These errors can be created through search forms, dynamic links, or session cookies. Most sql injection papers explain how dynamic links and text boxes can be used to execute sql queries but in my opinion, this vulnurability is more common in other input types (select boxes, hidden fields, checkboxes and radio buttons, and cookies!).

Mixing data types generally crashes a webpage if it's not well coded. Take for example a link to "memberinfo.php?o_id=1". If your goal is to crash that page it would be a good idea to stick in a " or a ' in the o_id variable. If you're lucky you will get a debug message containing the crippled sql query. After you have all the information you need and you know what you're going after you're ready to hack the hell out of every page that you have access to.

CHANGING FIELDS' VALUES

The first form you think of is the profile page. Most profile pages ignore a user's intellectuals and don't mask out,for example, select boxes. A way of exploiting this vulnerability is by injecting a sql query in the value property of the field.

javascript:alert(document.profileform.user_sex.value="gay\',user_pasword=\'HACKED\' WHERE user_id=1#");

If we assume that the server side sql query looks something like this:

"UPDATE user_data SET user_password='$user_password',user_email='$user_email',user_sex='$user_sex' WHERE user_id=$user_id";

Then the final query will look somewhat like this:

"UPDATE user_data SET user_password='mypassword',user_email='myemail',user_sex='gay',
user_password='HACKED' WHERE
user_id=1 #' WHERE user_id=7382";

# Is a sql comment operator.

2. Bypassing Session Cookies

OVERRIDING BASIC SESSION COOKIE AUTHENTICATION

Most of the time session handling is done with the use of cookies. The cookies tell the webpage who you are and what you have access to and what you don't have access to. If the page does not handle session cookies correctly a hacker might be able to change their identity to that of another user's. Cookies are stored in "window.document.cookie". With javascript we are able to erase,edit,create cookies for any website. This task is more complicated than regular types of attacks. I will not go into great detail about how it's done.

To View the Cookie:
javascript:alert(unescape(document.cookie));

To Change Cookie Data:

javascript:alert(window.c=function a(n,v,nv){c=document.cookie;c=c.substring(c.indexOf(n)+n.length,c.length);
c=c.substring(1,((c.indexOf(";")>-1) ? c.indexOf(";") : c.length));nc=unescape(c).replace(v,nv);document.cookie=n+"="+escape(nc);return unescape(document.cookie);});alert(c(prompt("cookie name:",""),prompt("replace this value:",""),prompt("with::","")));

So If You are logged in as "John Doe" in www.ima13370h4x0r.net and your session cookie reads:

SessionData=
a:3:{s:11:"SessionUser";s:5:"75959";s:9:"SessionID";i:70202768;s:9:"LastVisit";i:1078367189;}

The cookie is actually serialized but you should be able to recognize "75959" as your user_id. Some of the time you will find a website that stores data (like user_id) in cookies but does not typecast the data. This is a serious hole in the site's code because any user is able to change their user_id to any other user or administrator user_id.

Changing the cookie value is easy once you have declared the window.c function. First change s:5:"75959" to s:x:"ADMINID" where x is the length of the new value. So if you want to change 75959 to 1. You must change s:5:"75959" to s:1:"1" :-) Sometimes you will need to change 75959 to "13 or 1=1" in order to bypass any WHERE statements any sql session queries used to keep you logged in the website.


----------------------------------------------------------------------------------------
Notes:
In-line javascript statements can be added to your browser's favorites for easier access to your own functions.
It is possible to declare your own functions for use in extended hacks. Declare the function as a method of window. "alert(window.newfunction = function (){...})"

Hack Youtube Video Views

Author: P.R.O.V.I.D.E.R. // Category:
Today ma going to teach you something that even a basic person can do and understand...it is very simple...we are going to give your personal youtube video more views so its recognized more....

BE SURE TO take out EVERYONE OF THE *...just doing that for the html codes to show up

ok..first off...open note pad....and type this out...



Code:

<*me*ta *http-equ*iv="refr*esh" *conten*t="*5"*>



this code refreshes your page every second or two..make sure this is your first line....

now grab the embedded code for your youtube video...showed be on the right side under your account picture..copy and paste it under accouple spaces from the code above...

example:



Code:

<*obje*ct wid*th="42*5" heig*ht="3*44"><*par*am na*me="m*ovie" valu*e="ht*tp://www.yout*ube.co*m/v/REQRHdMRi*mw&hl=en*"><*/para*m><*par*am nam*e="all*ow*FullSc*reen" *valu*e="tr*ue"><*/p*aram><*e*mb*ed sr*c="htt*p://www.youtu*be.co*m/v/REQRHdM*Rimw&hl=en"*
typ*e="applic*ation/x-*shockwav*e-flash" *allowfull*scr*een="tr*ue" wi*dth="42*5" heig*ht="34*4"*><*/em*bed*>



ok..now we have the embedded code...so we are going to edit the code with on simple script...&autoplay=1...

so we find this section here



Code:

src="http://www.youtube.com/v/REQRHdMRimw&hl=en"


where at the end where the =en" is we add the &autoplay=1 to it...like this..



Code:

src=*"http://www.youtube.com/v/REQRHdMRimw&hl=en&autoplay=1"



ok..now your embedded code is edited....so we copy the whole embedded code...not the meta code at the top..it stays there...but the youtube code we just editted...paste it 5 times under it...

then we save this file as anything.html....and then click on it and if done correctly your browser should open up with the youtube videos all on the same page...your browser will refresh every second or two and each time it does you get that many more views....let it run over nite...or anytime you like and you will have thousands of views in no time...cuz every time it refreshes thats that many more views....

hope this helps everyone out...good luck...happy youtube hacking...have fun....

Cracking Tutorial

Author: P.R.O.V.I.D.E.R. // Category:
1.)How a cracker works.
-A cracker works by repeatingly sending passwords to a Yahoo! login server or a list of servers


-Crackers require password lists (dictionay files). These are lists of words that the cracker will attempt to use as the passwords


-All a cracker does, is try different passwords,until the correct password to the username is entered. (Crackers work on the possibility that one of the passwords you load in the password list is the correct password for the usernames they are trying to crack.)




2.) Basics you need to know.
-Cracker's use either servers or proxies in cracking.


-A Crackers are basically a program that simplfies and speeds up exactly what you do when you login to a Yahoo site.


-There are three types of crackers. Server crackers , Proxy crackers and Forwards crackers.


-Server crackers typically get patched (quit working) very quickly because Yahoo moniters it's servers and they pick up any increased bandwidth (alot of extra login attempts than normal). When they see these extra logins attempts they run some tests and find out what login method is being tried. They then goto work and patch the login method, which basically means that it will ban you after 50 - 100 login tries on a single IP.


-Proxy crackers are much harder for Yahoo to patch. You can use patched login servers on them because by using a proxy you appear to not be just one IP trying to log in, but many hundreds of IPs. Yahoo will ban each proxy, not your main IP. The ban is only a temporary ban as well, usually for 4 - 6 hours. And once you notice your cracker slowing down (proxies getting banned) simply scan and load some new proxies into the cracker and you are back in buisness.


-Forwards crackers can be eigther Server or Proxy crackers. Most crackers run Backwards. This means that the cracker goes through the list of names as quickly as possible using the first password in the list, then goes to the next password and starts at the top of the names list again. This ensures that the names you are trying to crack do not get "locked" by Yahoo for too many login attempts one right after the other. Im sure we've all had names locked before and had to type in the "random security code" below the password to log into the name. With a Forwards cracker, the cracker stays on the first name in the list until all the passwords have been tried on it, then moves to the next name. In order for a cracker to be considered a Forwards cracker, it must not lock names for too many login attempts. So basically with a working Forwards cracker, you can enter one name in the cracker and thousands of passwords to try and crack only that one name. Forwards crackers are the rarest type of crackers because the login methods they use are very hard to find and Yahoo tries very hard to patch these methods up quickly. I have had quite a few Forwards crackers before, but as of right now, I dont know of a single working one. I love using these types of crackers when I get ahold of one.


-Alerts: when a name has been cracked, the cracker has away of alerting you, more common you will get sound alert. In other cases an Alert Window will pop up.


-Password Options: Password options can change the passwords you are using to crack with to ALL CAPS , First Letter Caps" , Sim (using the name trying to be cracked as the pass), etc. etc.


-Sockets - A cracker's speed is defined by it's number of sockets. From a begginer's stand point, you might think that setting your cracker for it's max number of sockets will allow you to crack screen names faster. This is only true if you have a very faster ISP (Internet Service Provider) like cable or DSL. If you are on dial-up I would recommend only using 5 - 10 sockets. If you are on DSL I wouldnt use more than 50. If you are on cable you can use as many as the cracker will allow you to use. Also if you are using a Proxy cracker, keep in mind that you can only crack as fast as the proxies will allow you too. Some proxies are fast and some are slow.


-Timeout: This is a feature for proxy crackers which tells the cracker how long it should wait on each proxy to attempt to log in the name. If you set the Timeout low, the cracker will skip all the slow proxies in your proxy list and only use the faster proxies. This will make it faster but you also wont find as many proxies that work. If you set the Timeout higher, the cracker will wait a second or two longer on each proxy to allow it to try and log in the name. I would recomend using a high timeout unless you have like 30,000 proxies to crack with.


-Auto save is when you crack a name. it out saves it immediately to a txt or log file. This is a good feature in case you get disconnected or your PC gets turned off by accident or unplugged.


-In cracking, people that crack names look for usernames that Yahoo no longer allows them to make, these discontinued names are called illegals (a.k.a Rares).


-You will also here about a group of cracked names called originals, example of this would be "woody, farmer, warrior , potent , Jason , Mark , Jen etc... (you get the picture hence "original")




3.) Tools you need for cracking.
-You need a cracker of course, I recommend crackers that use proxies.


-To find Proxies, you need two kinds of tools, one to find proxies (scanner or leecher), and a Proxy Phecker to check if those proxies are valid. Some crackers will record only the good proxies when it is cracking so this will eliminate the need for a Proxy Checker (x-proxy is an example of a cracker that has this feature).

(Here are some proxy sites you can use to get some proxies)
Rob's Daily Updated Proxy List
http://www.multiproxy.org/txt_anon/proxy.txt
http://www.socklabs.com/proxylist.txt
http://www.cybers yndrome.net/pld_tmp.html
http://www.digitalcybersoft.com/Prox...oxy-list.shtm l
http://phpfi.com/43027


-You need names lists (a list of scanned names you want to try and crack), and password lists and a Proxy list before you start up the cracker.


-Now you need some names to crack. Compile this either by using a name generator and scanner, or you can find a room grabber and use it. This is a program that sends a bot into a list of rooms and grabs the usernames from the room....these are then saved as another .txt file. However you decide to do it, you should compile a list of at least 500 names to start




4.) How to find out if your cracker works...
-To make sure it still works, load up proxies and add some bot names and passwords to the name and passwords list, if it cracks the names, then it works!


Thats all for now. I hope this has helped some of you to understand how a cracker works and what tools you will need to be a successfull cracker. Keep in mind, cracking is alot like fishing. Dont expect to crack a ton of name when you first start. Sometimes you will crack for days without cracking a single name, sometimes even weeks. It really depends on how good your passwords are that you are using. It's alot of luck and cracking isnt for everyone. It takes alot of patience and determination to do it. If you are willing to tough it out then you can count on cracking some names in

The True Origin of Hacking

Author: P.R.O.V.I.D.E.R. // Category:
"DID YOU KNOW? If a hacker successfully penetrates your telephone
system's security, you could be billed for OVER $10,000 PER HOUR for
FRAUDULENT CALLS?"

The above quote was taken from an AT&T sales letter hawking security
systems to businesses. It was reprinted in the quarterly publication
2600, a sort of Popular Mechanics for, um, midnight technicians.

These days, most people think of hackers as anti-social types who
break into business phone lines, ATM machines, cable, and government
computers. Hackers are the new hi-tech outlaws.

Though the idea of hacker as outlaw has some truth, much of it is
certainly hyperbole ($10,000 an hour?). The overuse and misuse of the
word hacker has been chafing against me of late. I've always
understood a more benign definition.

Time for some schooling. According to Steven Levy's seminal 1984 book
Hackers, the idea of a "hack" came from the M.I.T.'s Tech Model
Railroad Club. In the late 1950s, the members of the club would use
the term to denote any project that was undertaken just for the "wild
pleasure taken in mere involvement." Those who took pride in building
better connections between relays were called hackers.

Wireheads that they were, it's no surprise that when a new mainframe
computer, the TX-O arrived on campus, many from TMRC were instantly
drawn to it.

To most people then, computers were bulky unfriendly machines that
took up entire rooms and crunched numbers for insurance companies or
scientists. They had no relation to the public at large.

To these hackers though, these computers presented a whole new realm
of possibilities. In the ensuring decade, they prodded the TX-O, and,
later, the PDP-6 to play chess, hum Bach, emulate ping pong, act as a
adding machine, and play space war games.

All these applications were called hacks. Such work was seen as
frivolous. These programs were written for no other reason than to be
simply to have them be admired and improved upon by other programmers.
In hindsight, its obvious these hackers were radically rethinking the
way computers could be used.

But hacking provided an addictive high. As Levy writes,

When you programmed a computer you had to be aware of where all the
thousands of bits of information were going from one instruction to
the next, and be able to predict--and exploit-- the effect of all that
movement. When you had all that information glued to your cerebral
being, it was almost as if your own mind had merged into the
environment of the computer. Sometimes it took hours to build up to
the point where your thoughts could contain that total picture, and
when you did get to that point, it was such a shame to waste it that
you tried to sustain it by marathon bursts.

To better suit such cerebral thunder runs, these misplaced geniuses
would slip into 32-hour days fueled by cokes and lemon jelly wedges.
For a dedicated few, outside norms were considered irrelevant -
fashion, college degrees, even personal hygiene. One particularly
notorious hacker, Richard Greenblatt would get so caught up in
projects that he'd neglect to bathe. As a result, whenever Greenblatt
would rub his hands together over the keyboard, little chunks of dirt
fell on the keys, called "blatties" by other annoyed users.

Eventually a philosophy emerged from M.I.T. known as the Hacker Ethic.
The one and all-holy central tenet was this: information should be
free. Hackers believed in free information the way hippies believed in
free love.

And oddly enough, at the time, it made sense. The way information
works is strange. Keep it for yourself, and no one else will expound
upon it, use it, or employ it in their own designs. If it's obscure,
it's worthless.

But if you leave information for others to tinker with, say a program
you wrote, it will take hold, become stronger, better, and, at least
in some small way, add to the collective knowledge of humankind.

This is why for years so much software was placed in the public
domain. If anyone saw a way to improve, say Xmodem, a program for
downloading, they were free to do so. Copyrighting a program was
considered heresy. In those early years at M.I.T., programs were left
around for others to tinker with, the creators admitting someone could
easily improve upon their design.

The idea made perfect sense in the collegial atmosphere of M.I.T..
Outside the campus, however, this ethic has since caused headaches for
companies, such as Bell Atlantic, that don't particularly appreciate
people taking a curiosity in how their systems work, having them
improved upon, or having it hacked for free phone calls.

The hubbub you hear these days is sound of the Hacker Ethic rubbing
against corporate propriety.

As maligned as the word means, its easy to forget how valuable hacking
is. It has made the Internet largely what is today: People doing stuff
with no promise of financial gain, but simply because it would be
interesting to do it. The word has been tagged with an unfair rap. I
just hope curiosity and inventiveness won't be taken out with it.

How To Catch A Hacker

Author: P.R.O.V.I.D.E.R. // Category:
Tip One

Hackers cover their tracks, Experienced hackers cover them more
thoroughly, but amateur hackers sometimes leave things behind, Don't
expect them to leave any really big evidence behind, expect more of
little things here and there you might find surprising, For example,
if you are writing a term paper and a black hat hacker accidently
saved it when he took a paragraph out, that's suspicious, Where did
that paragraph go ? Well, for one thing, now you know he was in that
area, Check the folders surrounding the file you might find something

Tip Two

Decipher between the type of hackers that are attacking you,
Experienced hackers will have a more in depth look around when they
penetrate your system, They won't touch much because they know that
they won't add too much to their knowledge, But if you know a hacker's
been in, and some files are messed with, and you have a log of someone
guessing passwords to a file or something of that sort, its probably
some newbie who's just starting out, These are the easiest hackers to
catch, They usually get so caught up in thoughts like "Iam in" that
they forget the basics, such as work behind a proxy

Tip Three

Don't go crazy if you lose data, Chances are, if it was that
important, you would have backed it up anyway, Most hackers nowadays
wish they were back in 1989 when they could use a Black Box and having
a Rainbow Book actually meant something, Most hackers aren't black
hat, they are white hat, and some even grey hat, But in the end, most
hackers that are in systems aren't satisfied by looking around, From
past experiences, I have concluded that many hackers like to remember
where have they been, So what do they do ? They either press delete
here and there, or copy some files on to their systems, Stupid hackers
(yes, there are plenty of stupid hackers) send files to e-mail
addresses Some free e-mail companies will give you the IP of a certain
e-mail address's user if you can prove that user has been notoriously
hacking you. But most of the time, by the time you get the e-mail adds
it's been unused for weeks if not months or years, and services like
hotmail have already deleted it

Tip Four

Save information, Any information that you get from a log file (proxy
server IP, things like "14P", e-mail addresses that things were sent
to, etc) should be saved to a floppy disk (they are not floppy
anymore, I wish I could get out of the habit of calling them that) in
case there's a next time, If you get another attack, from the same
proxy, or with similar e-mail addresses (e.g: one says Blackjack
123@something.whatever and the other says
Black_jack_45@something.znn.com) you can make an assumption that these
hackers are the same people, In that case, it would probably be worth
the effort to resolve the IP using the proxy and do a trace route
Pressing charges is recommended if this is a repeat offender

Tip Five

Don't be stupid, If you've been hacked, take security to the next
level, Hackers do talk about people they have hacked and they do post
IPs and e-mail addresses, Proof ? Take a look at Defcon Conventions,
I've never gone to one, but I have seen the photos, The "Wall of
Shame" type of boards I've seen have IPs and e-mail addresses written
all over them in fat red, dry-erase ink, Don't be the one to go
searching the Defcon web site and find your e-mail address posted on
the Wall of Shame board

Tip Six

Don't rely on luck, Chances are, sometime or another, you're going to
be targeted for an attack, Here you can rely on luck, Maybe they'll
forget ? Maybe they don't know how to do it ? If you think this way, a
surprise is going to hit your face very hard, Another way you could
stupidly rely on luck is by saying this: It's probably just a white
hat, On the contrary, my friend, it's probably just a black hat, A
black hat with knowledge stored in his head, ready to be used as an
ax, It's your data, You take the chance

How to become Hacker

Author: P.R.O.V.I.D.E.R. // Category:
How to become Hacker....

1) First know difference between Hacker,Cracker and Script Kiddy....

2)The only only only Hackers Guru is Google...
Remember no one knows than more than 'GOOGLE'

3) Unless u know(very Strong,talk,sleep,eat) more than 1 Programming lang.....u vll never be called as Hacker

Top ten Best Hacks

Author: P.R.O.V.I.D.E.R. // Category:
Here is a list off the top 10 hacks of all time.
Early 1990s

Kevin Mitnick, often incorrectly called by many as god of hackers, broke into the computer systems of the world's top technology and telecommunications companies Nokia, Fujitsu, Motorola, and Sun Microsystems. He was arrested by the FBI in 1995, but later released on parole in 2000. He never termed his activity hacking, instead he called it social engineering.
November 2002

Englishman Gary McKinnon was arrested in November 2002 following an accusation that he hacked into more than 90 US military computer systems in the UK. He is currently undergoing trial in a British court for a "fast-track extradition" to the US where he is a wanted man. The next hearing in the case is slated for today.
1995

Russian computer geek Vladimir Levin effected what can easily be called The Italian Job online - he was the first person to hack into a bank to extract money. Early 1995, he hacked into Citibank and robbed $10 million. Interpol arrested him in the UK in 1995, after he had transferred money to his accounts in the US, Finland, Holland, Germany and Israel.
1990

When a Los Angeles area radio station announced a contest that awarded a Porsche 944S2 for the 102nd caller, Kevin Poulsen took control of the entire city's telephone network, ensured he is the 102nd caller, and took away the Porsche beauty. He was arrested later that year and sentenced to three years in prison. He is currently a senior editor at Wired News.
1983

Kevin Poulsen again. A little-known incident when Poulsen, then just a student, hacked into Arpanet, the precursor to the Internet was hacked into. Arpanet was a global network of computers, and Poulsen took advantage of a loophole in its architecture to gain temporary control of the US-wide network.
1996

US hacker Timothy Lloyd planted six lines of malicious software code in the computer network of Omega Engineering which was a prime supplier of components for NASA and the US Navy. The code allowed a "logic bomb" to explode that deleted software running Omega's manufacturing operations. Omega lost $10 million due to the attack.
1988

Twenty-three-year-old Cornell University graduate Robert Morris unleashed the first Internet worm on to the world. Morris released 99 lines of code to the internet as an experiment, but realised that his program infected machines as it went along. Computers crashed across the US and elsewhere. He was arrested and sentenced in 1990.
1999

The Melissa virus was the first of its kind to wreak damage on a global scale. Written by David Smith (then 30), Melissa spread to more than 300 companies across the world completely destroying their computer networks. Damages reported amounted to nearly $400 million. Smith was arrested and sentenced to five years in prison.
2000

MafiaBoy, whose real identity has been kept under wraps because he is a minor, hacked into some of the largest sites in the world, including eBay, Amazon and Yahoo between February 6 and Valentine's Day in 2000. He gained access to 75 computers in 52 networks, and ordered a Denial of Service attack on them. He was arrested in 2000.
1993

They called themselves Masters of Deception, targeting US phone systems. The group hacked into the National Security Agency, AT&T, and Bank of America. It created a system that let them bypass long-distance phone call systems, and gain access to the pbx of major carriers.

What is hacking ?> Explained here !!

Author: P.R.O.V.I.D.E.R. // Category:
What are hackers?
Technically, a hacker is someone who is enthusiastic about computer programming and all things relating to the technical workings of a computer. Under such a definition, I would gladly brand myself a hacker. (There is in fact more to it than that - hackerdom is an entire culture in its own right.) However, most people understand a hacker to be what is more accurately known as a 'cracker'. Worryingly, people tend to prefer to use the word 'hacker' over the more technically correct 'cracker'. This means that many are afraid to use the word for its correct meaning. On this website, when I refer to a hacker, I actually mean a cracker. This is because I prefer to use language that I feel most people understand, rather than language that is technically correct. If you want to know what a cracker is, please read ahead to the next section...

What are crackers?
Crackers are people who try to gain unauthorised access to computers. This is normally done through the use of a 'backdoor' program installed on your machine. A lot of crackers also try to gain access to resources through the use of password cracking software, which tries billions of passwords to find the correct one for accessing a computer. Obviously, a good protection from this is to change passwords regularly. Another good move is the use of software that supports intruder lockout, where no further passwords are accepted after a certain number of bad passwords have tried. Even the correct password wouldn't allow access. Such blocks are normally released after a period of time has elapsed (eg 15 minutes). Of course, an even better idea is never to put security-sensitive resources on the Internet in the first place. If you don't want something to be accessed from the Internet, then make it so that it is only accessible from your local network, or even just from one computer. However, backdoor programs are programs that can expose files to the Internet that were never meant to be shared with other people. You can protect yourself from these by using a firewall and a good up-to-date anti-virus program. You would normally get such a backdoor program by opening an e-mail attachment containing the backdoor program. It is normal for such a backdoor program to send out more copies of itself to everyone in your address book, so it is possible for someone you know to unintentionally send you a malicious program. Note that this can normally only be done if you are using Microsoft Outlook or Outlook Express. A few backdoor programs can work with any e-mail program by sitting in memory and watching for a connection to a mail server, rather than actually running from within a specific mail program. If you do use Outlook or Outlook Express, and you do not have the correct security patches installed, it may be possible for a malicious program to be executed from an e-mail when you receive it, without the need for you to click on any attachments. Note that the same bug also affects Internet Explorer. A security patch is available for this, but personally I would advise that you use different mail and web browsing software. There are other ways of cracking as well, some more widespread than others.I refer to 'hackers' instead of 'crackers'. I mean 'crackers'. A cracker is someone too who does reverse eng. on programs and covers LL programming languages (like ASM 4 example) and modifies the program, mostly in aim of removing limitations !


What damage can a hacker do?
This depends upon what backdoor program(s) are hiding on your PC. Different programs can do different amounts of damage. However, most allow a hacker to smuggle another program onto your PC. This means that if a hacker can't do something using the backdoor program, he can easily put something else onto your computer that can. Hackers can see everything you are doing, and can access any file on your disk. Hackers can write new files, delete files, edit files, and do practically anything to a file that could be done to a file. A hacker could install several programs on to your system without your knowledge. Such programs could also be used to steal personal information such as passwords and credit card information. Some backdoor programs even allow a hacker to listen in on your conversations using your computer's microphone if one is attached! Hackers can do great damage to your computer. They could delete vital files from your hard disk, without which your computer could not work. However, you can re-install these from backups (you do keep backups, don't you?) In theory, the absolute worst damage a hacker could do is turn your computer into a large paperweight. It is possible - the CiH virus demonstrated how. This virus attacked your computer using the then new Flash BIOS technology. This capability was intended to be used to upgrade your computer's BIOS. (The BIOS is a program stored on a chip inside your computer. It controls quite a lot of low-level stuff and is a very vital part of your computer. It is the BIOS that does all the memory checks when you turn on, and also performs the first stage in loading your operating system.) However, the virus used this 'feature' to destroy the BIOS. Without the BIOS, the computer can't work. The only way to recover from this would be to replace your computer's motherboard. At the time of writing this, there are no backdoor programs that can do the same thing, but it is easy enough for a hacker to install a virus that does. Since the CiH virus, many BIOSs have a "flash write protect" option in BIOS setup, and/or a jumper setting on the motherboard that has a similar effect. See your motherboard manual for details.

How does a firewall protect me?
Basically, firewalls protect your computer from unauthorised access attempts. There are two kinds of firewall. Networked computers tend to be connected to the Internet through just one or two computers (hence only one Internet connection is required). These computers behave as firewalls by blocking any unauthorised packets. Any other packets are passed on to the computer they are intended for. This kind of firewall is called a corporate firewall. The kind of firewall you may be more familiar with is a personal firewall- this is a program that runs on your computer, and blocks any unauthorised incoming packets. Personally, I use ZoneAlarm. The great thing about ZoneAlarm is that it is easy to configure. Also, it only allows chosen programs to access the Internet- allowing you to block hackers that use standard protocols such as FTP. In case of emergency, it also has an emergency stop button, which allows you to block allfree by private individuals and charities. Businesses, governments, and educational institutions can download ZoneAlarm on the basis of a 60-day free trial.ZoneAlarm can be downloaded and used for Remember that although a firewall stops hackers from getting in, it will not remove any existing 'backdoor' software from your machine. For this, you need a good anti-virus product like Norton or Sophos. Also make sure that you use your anti-virus software regularly, and that you keep it up-to-date.

How do I report hackers?
When an access attempt occurs, if you have alert popups turned on, ZoneAlarm will tell you the IP address of the possible hacker. This looks something like 123.123.123.123 (example only). You can use this information to track down and report hackers to their ISP. Bare in mind that you are unlikely to get any response apart from a simple acknowledgement- they have to deal with hundreds of reports like yours every day. Here is a rough guide of how to report hackers (note: some of the programs referred to are only available in Windows):

1. Make a note of all the information ZoneAlarm gives you. If possible, use ZoneAlarm's text log option- many ISPs prefer text log format (personally, I supply ZoneAlarm's text log and an English translation).
2. Select Start, Run... In the Run box, type in "winipcfg" and then click OK. This will tell you what your IP address is (among other things). Write down the IP address.
3. Use an Internet tool like SamSpade's address digger to look up which ISP uses the IP address given in your firewall's log.
4. This will return a lot of technical information. Some ISPs add remarks to this information telling you where to send abuse reports to. Make a note of any such e-mail addresses. If there is no such information, look at the official name for the server (near the top), or the names of the domain name servers. To convert these to an e-mail address, remove everything before the first period, including the period itself, then add 'abuse@' in front of it.
5. Now send an e-mail to the abuse address(es) you have. If the recipient obviously isn't English (eg if the e-mail address ends in .de (Germany) or .fr (France)), write it in their language, if you know it. If not, don't worry, most people speak at least a little English, and the technical language of computers is the same almost anywhere you go!
6. Include in the message what ZoneAlarm told you. Also include your own IP address (this is what winipcfg told you), the date, the time, your time zone (in relation to GMT), and an indication of how accurate your computer's clock is (eg if you set it by the atomic clock every day, say so!)



What is a port scan?
A port scan is, quite simply, a test to see if a computer exists and responds to access attempts on a certain port (eg TCP port 80, used by the HTTP protocol). Port scans, on their own, are quite harmless and have many legitimate uses. However, they also have a malicious use, which is to test to see if any particular backdoor software is running on a computer for the purposes of then using such backdoor software. In my Internet logs, I include all unauthorised port scans of my computer. I tend to describe these port scans as hack attempts, since it is most likely that this is what they are. To be absolutely pedantic, I shouldn't really describe them as such, since there may be other explanations.


What is an IP address?
An IP address is a number that can uniquely identify any computer on the Internet. With the current Internet protocol (IPv4), an IP address is a 32-bit number. That means that as a binary number, it would be stored as 32 ones and zeroes. There are 4,294,967,296 possible IP addresses. However, we humans tend to split IP addresses into four 8-bit numbers, express these numbers using our decimal number system, and separate them with dots. With 8-bit numbers, each number must be a whole number in the range 0 to 255, inclusive. For example, an IP address of 2,071,690,107 would probably be expressed as 123.123.123.123 (example only). Some people might express an IP address in hexadecimal as well (7B7B7B7Bh in this case). The dotted IP address is by far the most common, however. As the Internet grows, plans are being made to increase the size of IP addresses. (The "next" Internet protocol, IPv6, uses 128-bit IP addresses.) The problem with that, of course, is that quite a few Internet protocols would need to be rewritten, since they are designed to work with 32-bit IP addresses. This includes the Internet Protocol itself (IP). Thankfully, Internet packets include an IP version flag, so it would be possible to have both old and new implementations of the IP communicate with each other. (The newer implementation would use the older protocol when communicating with older implementations. Implementations of the IP would know whether a computer was using the older or newer protocol from the version flag. Unfortunately, older implementations would not be able to access anything outside of the 32-bit IP range.) IP addresses can be statically or dynamically allocated. Statically allocated IP addresses always refer to the same computer. However, dynamically allocated IP addresses can refer to different computers at different times. For example, if you have a dial-up Internet connection, your IP address doesn't become unused when you hang up- it is allocated to someone else. When you reconnect, you are allocated a new IP address. This is dynamic allocation.


How can I hack?
I don't like that first person pronoun... I don't mind explaining how hackers hack, but I won't explain how you can hack. This is not a pro-hacking website. This is a computer security site. My aim is not to encourage or assist hacking in any way. I aim to try to inform people of the risks that they may be exposed to, so that they can better protect themselves from these risks. I also provide this website as a resource for those with an academic interest. If you want a rough idea of some of the cracking methods that other people (not you) use, just read on to the next section.


How can NetBIOS be harmful?
NetBIOS hacks are the worst kind, since they don't require you to have any hidden backdoor program running on your computer. This kind of hack exploits a bug in Windows 9x. NetBIOS is meant to be used on local area networks, so machines on that network can share information. Unfortunately, the bug is that NetBIOS can also be used across the Internet - so a hacker can access your machine remotely. Not all Windows computers are vulnerable to this kind of attack. If you have a firewall that blocks incoming NetBIOS packets, you are safe. Some network configurations will also be immune. To find out whether you are vulnerable, visit GRC's ShieldsUP!, and click the "Test My Shields!" image half way down the page. Note that GRC will attempt to connect to your computer using NetBIOS - this is just to test whether your computer is vulnerable. GRC will not retain any information about your computer, nor will any damage be done. NetBIOS uses TCP port 139, UDP port 137 and UDP port 138.


How can ICMP Ping be harmful?
ICMP is one of the main protocols that makes the Internet work. It standards for Internet Control Message Protocol. 'Ping' is one of the commands that can be sent to a computer using ICMP. Ordinarily, a computer would respond to this ping, telling the sender that the computer does exist. This is all pings are meant to do. Pings may seem harmless enough, but a large number of pings can make a Denial-of-Service attack, which overloads a computer. Also, hackers can use pings to see if a computer exists and does not have a firewall (firewalls can block pings). If a computer responds to a ping, then the hacker could then launch a more serious form of attack against a computer. People who do have firewalls normally don't bother to report pings, because they are innocent in themselves - allowing the hacker to continue hacking for quite a long period of time.


How can FTP be harmful?

FTP is a standard Internet protocol, standing for File Transfer Protocol. You might use it for file downloads from some websites. If you have a web page of your own, you might use FTP to upload it from your home computer to the web server. However, FTP can also be used by some hackers... FTP normally requires some form of authentication for access to private files, or for writing to files. Hackers can get round this by using programs called "backdoor programs". You wouldn't know if you had one of these, unless you used an up-to-date virus scanner regularly. You could get a backdoor program by opening an infected E-mail attachment. FTP backdoor programs, such as Doly Trojan, Fore, and Blade Runner, simply turn your computer into an FTP server, without any authentication. Using a known protocol such as FTP is easier for hackers because the protocol is already defined - not so much new software needs to be written to use it (a normal FTP client could be used - the hacker wouldn't need any specialist software). Also, since FTP has legitimate uses, many firewalls do not block it. Luckily, ZoneAlarm does.


How can rpc.statd be harmful?
This is a problem specific to Linux and Unix. I am not too sure with what precisely rpc.statd should be used for. I do, however, know that it is used by hackers. rpc.statd is typically used as a 'file locking status monitor' (whatever that is) on local area networks. Not all versions of Linux/Unix use it, and some versions have had the security glitch I am about to describe fixed. The problem is the infamous unchecked buffer overflow problem. This is where a fixed amount of memory is set aside for storage of data. If data is received that is larger than this buffer, the program should truncate the data or send back an error, or at least do something other than ignore the problem. Unfortunately, the data overflows the memory that has been allocated to it, and the data is written into parts of memory it shouldn't be in. This can cause crashes of various different kinds. However, a skilled hacker could write bits of program code into memory that may be executed to perform the hacker's evil deeds. That is the problem. rpc.statd uses TCP ports 111 and 9704.


How can lpr be harmful?

This is a similar problem specific to Linux and Unix. lpr is typically used as a printing system. Not all versions of Linux/Unix use it, and some versions have had the security glitch I am about to describe fixed. The problem is the infamous unchecked buffer overflow problem (again). Basically, the result of this problem is that data can be written into parts of memory it shouldn't be written to. A skilled hacker could write program code into memory to perform his evil deeds. lpr uses TCP port 515.


How can HTTP be harmful?
HTTP stands for HyperText Transfer Protocol. It is one of the main protocols used on the Internet- it is what you are using right now to view this web page. HTTP hacks can only be harmful if you are using Microsoft web server software, such as Personal Web Server. There is a bug in this software called an 'unchecked buffer overflow'. If a user makes a request for a file on the web server with a very long name, parts of the request get written into parts of memory that contain active program code. A malicious user could use this to run any program they want on the server. The Code Red worm takes advantage of this. This worm even managed to infect the Microsoft Windows Update site at one point. Despite what I have just said, it is still possible for home users to become infected with such worms, since some people install Personal Web Server without knowing what it is. Some computers even have PWS pre-installed when you buy them. To see if PWS is running on your computer, hover your mouse over each of the icons in the bottom right corner of your screen, until a small description appears. If one of the icons is PWS, right-click it and choose to exit. Then, use Add/Remove Programs in Control Panel to remove the program from your system. Microsoft Personal Web Server is used to serve web pages directly from your computer to the rest of the world. Of course, you would need to be connected to the Internet 24 hours a day in order to do this. Most people will tend to upload Internet material to their ISP, rather than provide access to it directly from their own computer. And just to clear up any remaining confusion: Microsoft Personal Web Server is not required to surf the Internet- all you need to surf the Internet is a web browser and an Internet connection (such as dial-up).

HTTP uses TCP port 80. I am not sure if Microsoft has released a patch to correct the problems

Winamp Hacking For Unlimited Muzic

Author: P.R.O.V.I.D.E.R. // Category:
Using a loophole in a winamp plugin, you can download and burn music from Napster for free.

music CDs, zero dollars*, obtained legally.
*Not including the cost of blank CDs


Practical how to:


0. Download and install Napster, sign up for 14 day free trial.
1. Download and install Winamp
2. Download and install the Winamp Plug-in Output Stacker
3. Open Winamp Options->Plug-ins->Output->Dietmar's Output Stacker->Configure


a. Add out_ds.dll from Winamp/Plug-ins folder
b. Add out_disk.dll from Winamp/Plug-ins folder
c. Select out_disk.dll in the Output Stacker->Configure
d. Set the output directory and output file mode to Force WAV file
e. Exit preferences


4. Load downloaded Napster protected WMAs into your Winamp playlist
5. Press play and each file will be converted to WAV as it plays
6. Burn WAVs to CD with your favorite burning program


Theoretical fun:


Three computers, one fast networked drive, and a few dedicated people: Turning Napster's 14 day free trial into 252 full 80 minute CDs of free music.
New key developments:

-If you use the "Out-lame" Winamp plugin in the Output Stacker in place of "Out-disk", you can convert straight to MP3. It still encodes no faster than realtime, but this is a great way to conserve space. WAV(Out-disk) is still recommended if you are burning CDs and want to keep as much quality as possible. I can confirm that this all works.

-You can run multiple instances of Winamp at once, each converting its own song. Each instance's playback will not interfere with any of the others, illustrating the fact that this is not simply recording the music off of your soundcard. Doing this, you can get FAR MORE than 252 full 80 minute CDs within 14 days. I can confirm that this works.

You can transcode(MP3) or decode(WAV) X albums in the time it takes for the longest track on the album to elapse. And since you're not limited to only tracks from one album at a time, you can trans/decode as many tracks as instances of Winamp your computer will run limited only by your computer's resources.
Quote from Napster's official statement:

"It would take 10 hours to convert 10 hours of music in this manner."
With the updated methods, you can convert 100 hours or 1,000 hours or 10,000 hours of music in 10 hours. The only limit is your computing resources.

Remote Operating System Detection

Author: P.R.O.V.I.D.E.R. // Category:
hie FRNDS..................


Detecting OS (operating system) is another most important step towards hacking into a system. We can even say that after tracing the IP of the system it is the most prior thing that should be done to get the root on a system cause without having knowledge about the OS running by the target system you cannot execute any system commands on the target system and thus your mission wont be accomplished. In here I have figure out the basics of detecting OS remotely without having physical access to the system. There are various method of detecting OS like by trace routing the victim’s IP , by pinging the IP , by using telnet and also by using a terminal. But from my research I have concluded that detecting OS through ping or tracerout is the most simplest but effective way of determining the operating system running in the remote computer without having physical access to the system. Since my aim of writing articles is to make things clear for beginners and intermediate so I will explain remote os detecting through ping method which is very easy to understand even for peoples totally new to computers.. yeah yeah.. I know you call them newbies..right ?? J J J

REMOTE OS DETECTION USING PING METHOD

What is PING and what is its utility ?

Ping is an MSDOS utility provided for windows version of DOS and for Unix and operating systems having UNIX as the core kernel. It runs in dos box in windows and directly in UNIX platform. In this manual I will give more stress on the MSDOS version of ping.


Ping is an utility used for sending and receiving packets of data to a target system using its IP and thus from the outputs you can figure out many information about the target system.
In remote os detection we are mainly concerned with the TTL values of the received data packets.

Note: When you send or receive a file over the internet it is not send at once. Instead it is broken down at the source system and these broken fragments of data know as data packets are send through the internet and these data packets are gathered together by the target system according to an algorithm constructed by the source system.
For example if I send a picture of size 400 KB to my girl friend (hey girls out there remember I don’t yet have a gf in reality) then what actually happens is that my system breaks the data into data packets, say the file of 400 KB has been broken down into 4 data packets each having a size of 100 KB and having a name. These data packets are assigned a code known as the TTL value of the data packets by my operating system. Then these data packets are gathered and the original file is formed from these data packets at the target system.

Example:

C:\windows>ping/?



Usage: ping [-t] [-a] [-n count] [-l size] [-f] [-i TTL] [-v TOS]

[-r count] [-s count] [[-j host-list] | [-k host-list]]

[-w timeout] target_name

Options:
-t Ping the specified host until stopped.
To see statistics and continue - type Control-Break;
-a Resolve addresses to hostnames.
-n count Number of echo requests to send.
-l size Send buffer size.
-f Set Don't Fragment flag in packet.
-i TTL Time To Live.
-v TOS Type Of Service.
-r count Record route for count hops.
-s count Timestamp for count hops.
-j host-list Loose source route along host-list.
-k host-list Strict source route along host-list.
-w timeout Timeout in milliseconds to wait for each reply.


there are various switches available for ping. Above I have given a list of all the switches available in the DOS version of ping. Using the –t switch you can continuously ping a target until it is crashed down. I am sure you are probably wondering how will it crash down the remote system. The answer is quite simple. If you ping the remote system continuously then what happens is that slowly the RAM of the target system is overloaded with these stack data and compels the system to restart or crashes it. You can also use the –l switch to specify the amount of data packet to be send at a time.

But in this article I am not concerned with crashing down a remote system cause its not that easy as it seems to be, there are many other tricks for it and its not possible to crash down a system of present technology just by simple ping. I am concerned with the TTL values of the output that you will get after pinging a system. You can use –n switch with ping to specify the number of echo (ie data packets) to be send to the target system. The default number is 4.

Example:

C:\windows> ping –n 10 127.0.0.1

This command will ping 127.0.0.1 with 10 packets of data and after that will give you an output.

Now I think its time for a real example which I have executed on my system.

C:\windows>ping 127.0.0.1

Pinging 127.0.0.1 with 32 bytes of data:

Reply from 127.0.0.1: bytes=32 time<1ms ttl="128" bytes="32" ttl="128" bytes="32" ttl="128" bytes="32" ttl="128" href="http://www.anonym.to/?http://members.cox.net/%7Endav1/self_published/TTL_values.html" target="_blank">http://members.cox.net/~ndav1/self_published/TTL_values.html)

Ping statistics for 127.0.0.1:
Packets: Sent = 4, Received = 4, Lost = 0 (0% loss),
Approximate round trip times in milli-seconds:

Minimum = 0ms, Maximum = 0ms, Average = 0ms

Here I have pinged the IP 127.0.0.1 (offline ip of any system) with default ping. Here I am getting TTL value as 128. This is the thing what we need for remote os detection.

What is TTL value ?


TTL value is nothing but a simple code assigned to the out going data packets by the operating system of a computer. The TTL value assigned to the out going data packets depends on the operating system and it is the same for a particular operating system. As for example if you ping a system running windows 98 or earlier versions of windows NT with service packs (I don’t know exactly about the TTL values of recent versions of Windows NT but from my research I think it’s the same as previous versions cause the TTL value even in Windows XP is 128) you will get the TTL value as 128, thus from this TTL value you can easily say that the target system is running Microsoft Windows.

TTL values of commonly used Operating Systems

OS VERSION PLATFORM TTL



Windows 9x/NT Intel 32
Windows 9x/NT Intel 128
Windows 2000 Intel 128
DigitalUnix 4.0 Alpha 60
Unisys x Mainframe 64
Linux 2.2.x Intel 64
FTX(UNIX) 3.3 STRATUS 64
SCO R5 Compaq 64
Netware 4.11 Intel 128
AIX 4.3.x IBM/RS6000 60
AIX 4.2.x IBM/RS6000 60
Cisco 11.2 7507 60
Cisco 12.0 2514 255
IRIX 6.x SGI 60
FreeBSD 3.x Intel 64
OpenBSD 2.x Intel 64
Solaris 8 Intel/Sparc 64
Solaris 2.x Intel/Sparc 255

Well these are not all. There are many more TTL values of many other operating systems. But generally most systems lies within this list.

Now lets try this manual practically and find out the operating system running by the IP 202.178.64.19.

C:\windows>ping 202.178.64.19

Pinging 202.178.64.19 with 32 bytes of data:

Reply from 202.178.64.19: bytes=32 time<1ms ttl="128" bytes="32" ttl="128" bytes="32" ttl="128" bytes="32" ttl="128" sent =" 4," received =" 4," lost =" 0" minimum =" 0ms," maximum =" 0ms," average =" 0ms">

Unlimited Rapidshare Downloads

Author: P.R.O.V.I.D.E.R. // Category:
Its very easy to fool Rapid Share server if your IP address is assigned by your ISP.

This trick will work only in broadband connection nd dont know whether it will work in dial up connection or not........

Just follow these simple steps:


clean up IE or netscape OR firefox cookie( In this case the one that belong to rapidshare website)
On Command prompt
type -----> ipconfig /flushdns <---Enter
type -----> ipconfig /release <---Enter
type -----> ipconfig /renew <---Enter
type -----> exit <--------Enter

Or save these commands in a bat file and run it everytime you need to fool Rapidshare server.Remember to clean up rapidshare cookie in your temp Internet files folder.

Now you should be ready to download as many files as you want from their server.