Showing posts with label Hack tools. Show all posts
Showing posts with label Hack tools. Show all posts

Wednesday, December 28, 2011

How to crack winrar ? | Reverse Engineering

In this tutorial I will show you the attackers approach of simply hacking a software with just basic understanding of Assembly. All you need is Olly dbg(v 1.10) and Winrar(any version).
Our target is to bypass the registration screen which is like above figure.


STEP 1 : Run olly dbg and open winrar in it by dragging it and dropping it in olly dbg.


STEP 2 : Now right click on the CPU main thread module and go to Search For > All Referenced text String


A new process containing all the reference stings will open 


STEP 3 : A right click on this new window and click on Search for text STEP 5 : Search for "reminder" in the search box as shown in the figure




STEP 5 : On pressing enter you will reach to the particular string location .


STEP 6 : Now double click it (reminder) and you will be taken to the main thread location of the string "reminder". 


STEP 7 : So now you have reached to the location that is responsible for generating the particular reminder message that pops up every-time we start winrar. Now from here you will need a basic understanding of Assembly. 


STEP 8 : Upon careful analysis of the region around the "reminder" text you will find a statement similar to this " JE SHORT winrar.00441219 " . "JE" means "jump if equals". This means that if your copy of winrar is already a registered copy then this statement will prevent the execution of the reminder message. So what shold we do here so that it still doesn't display the reminder even though we have an unregistered copy of winrar. 


STEP 9 : Go to the jump statement and double click it. Now change "JE SHORT winrar.00441219" to " JMP SHORT winrar.0041219 " . 


STEP 10: Save changes to the executable to see if you have performed the RE process correctly 


STEP 11: All you need to do now is go to the CPU main thread module , right click > copy to executable > all modifications. Press yes for the alert messages. You can either save it with the same name as winrar.exe to over-right the previous file or you can first save it with a different name to check if you have succeeded


                Once you are done with the saving part , you can now run the executable. If everything is right then you will not find any alert message this time.


:D Enjoy :D


NOTE : FOR EDUCATIONAL PURPOSES ONLY. I AM NOT RESPONSIBLE FOR THE CONSEQUENCES.




















[via]If you enjoyed this post, make sure you subscribe to my RSS feed! Comments are encouraged

Monday, December 5, 2011

Your Android may spy on you | Carrier IQ

An Android developer recently discovered a clandestine application called Carrier IQ built into most smart-phones that doesn't just track your location; it secretly records your keystrokes, and there's nothing you can do about it.

What is Carrier IQ ?

The software is hidden inside phones there is little you can do to detect that it’s even installed, let alone remove it, and it tracks everything. Keystrokes, browsing and surfing habits, Google searches, and basically every single thing that you are doing on your phone and every button that you press is logged by this software. this is basically a key-logger running on your phone that you didn't know about.



Carrier IQ says in this public statement that it is “not logging keystrokes or providing tracking tools” and that its software is used to track performance, but the video proves entirely otherwise: this app is sitting in between you and the Android OS and is making a note of everything you do.


How to get rid of this serious problem?

There’s no switch that you can turn off in the settings of your phone or software that appears in your app drawer that you can simply uninstall. As far as the GUI of your phone is concerned, Carrier IQ isn’t even there. But it is there, hiding in the background, making sure that you don’t even know it exists.

Fortunately, 

Voodoo Carrier IQ detector application released for Android



A new Android app to identify whether your smartphone has any Carrier IQ tracking/monitoring software installed on it has been released, the Voodoo Carrier IQ detector, giving users a simple way to put their minds to rest on privacy. The handiwork of Android app developer supercurio, the tool is only a few hours old and only partially finished, with the consequent warning that the results can’t be entirely relied on yet. 
To download this application, click 


Click to download source code.

Or Use custom ROM to protect privacy.



[via] If you enjoyed this post, make sure you subscribe to my RSS feed! Comments are encouraged

Friday, December 2, 2011

How to Hack webisites using IIS exploit

Yes, Now you can actually hack some websites using IIS.


  1. Open My computer and right click any where and select add network location.
  2. Press NEXT
  3. Click on "Choose a custom network location" and hit next.
  4. A window will open in which you need to add website which is vulnerable to IIS. For Example : www.globalsoftbay.tk
  5. Now press NEXT after that again press next .
  6. After that open that web folder [it will be somewhere like Network --> Website Name] and add your Deface page :)
  7. Enjoy ! :P

Some websites vulnerable to this exploit now are :

  • http://ayatolahkhamenae.parniansis.com
  • http://bahadori1.parniansis.com
  • http://beheshti.parniansis.com
  • http://beheshti1.parniansis.com
  • http://bentolhoda1.parniansis.com
  • http://bitaraf.parniansis.com
  • http://derakhshan.parniansis.com
  • http://derakhshan1.parniansis.com
  • http://derakhshan2.parniansis.com
  • http://derakhshan3.parniansis.com
  • http://ebnesina.parniansis.com
  • http://emamali.parniansis.com
  • http://emkhaleghiyeyzd.parniansis.com 
  • http://365tg.net
  • http://8090gogo.com
  • http://99zs.net
  • http://bbs.365tg.net
  • http://bbs.ttroad.com
  • http://fyuser.fy768.com
  • http://shop.365tg.net
  • http://sys.lubooil.com
  • http://tg.feitengcar.com
  • http://www.365tg.net
  • http://www.99zs.net
  • http://www.fy768.com
  • http://www.shop574.com
  • http://www.ttroad.com
  • http://hellen.9s6.com
  • http://hanhua.9s6.com
  • http://auditeur.lexbase.fr
  • http://axoneservices.com
  • http://armor.icor.fr
  • http://perros-guirec.icor.fr





If you enjoyed this post, make sure you subscribe to my RSS feed! Comments are encouraged

WordPress Security Vulnerability Scanner v.1.1

 WPScan is a black box WordPress Security Scanner written in Ruby which attempts to find known security weaknesses within WordPress installations. Its intended use it to be for security professionals or WordPress administrators to asses the security posture of their WordPress installations.

Official Changelog For WPScan v.1.1 :-

  •     Detection for 750 more plugins.
  •     Detection for 107 new plugin vulnerabilities.
  •     Detection for 447 possible timthumb file locations.
  •     Advanced version fingerprinting implemented.
  •     Full Path Disclosure (FPD) checks.
  •     Auto updates.
  •     Progress indicators.
  •     Improved custom 404 checking.
  •     Improved plugin detection.
  •     Improved error_log checking.
  •     Lots of bugs fixed. Lots of small tweaks.





If you enjoyed this post, make sure you subscribe to my RSS feed! Comments are encouraged

Thursday, November 3, 2011

How to hide or change your mac address in Ubuntu

I've been Googling and searching everywhere on the internet for the ways to hide my mac address. Finally I got many solutions. but here is the most optimum one.

First point to keep in mind is we cannot hide mac address if we want to be on a active network. The mac address can be changed / spoofed as per our wish.

1. Install "macchanger" using sudo apt-get install macchanger.
2. If you type macchanger --help , you will get all the possible options.
3. Type ifconfig and hit enter.
4. You will be provided with the sections like eth0, eth1, lo, wlan0, wlan1 etc., depending on your network connections. Check for HWaddr 1c:bb:3c:de:56:7f  similar to this.
5. This is your mac address. Now type sudo macchanger -A eth0 and hit enter.
 (In this I took etho as an example. If you are using eth1 or wlan0 replace it accordingly. -A refers to assign some mac address of any kind. I would recommend this option unless you want to spoof .)
6. Voila ! Your mac address is changed.

To know how to change / hide /spoof your ip address go here.
For any difficulties, let me know through your valuable comments.


Note : For educational purposes only. I am not responsible for the consequences.
If you enjoyed this post, make sure you subscribe to my RSS feed! Comments are encouraged

Tuesday, November 1, 2011

THC-SSL-DOS | TOOL TO KILL SSH SERVERS

Specialty : average laptop computer with windows Or any LINUX operating system and a standard DSL connection. are enough. ! :D


How it works :
Open command prompt.
Change the prompt directory to the drive in which you have unzipped the tool.
Change directory to thc-ssl-dos.
Now run the exe file. Pass the command thc-ssl-dos to execute it. 

Now in order to perform attack using this tool , you will have to pass the following command;
thc-ssl-dos TARGET IP --accept
On passing the command the tool will start its process.



Download THC-SSL-DOS from here.


If you find any difficulty in the process, let me know through your valuable comments so that I will update with screen shots.


For Linux users :


Use "./configure; make all install" to build and Run : ./thc-ssl-dos 127.3.133.7 443


1.The average server can do 300 handshakes per second. This would require 10-25% of your laptops CPU.
2. Use multiple hosts (SSL-DOS) if an SSL Accelerator is used.
3. Be smart in target acquisition: The HTTPS Port (443) is not always the best choice. Other SSL enabled ports are more unlikely to use an SSL Accelerator (like the POP3S, SMTPS, ... or the secure database port).



Counter measures :


No real solutions exists. The following steps can delay (but not solve) the problem:
1. Disable SSL-Renegotiation
2. Invest into SSL Accelerator





NOTE : FOR EDUCATIONAL PURPOSES ONLY. I AM NOT RESPONSIBLE FOR 
CONSEQUENCES.




If you enjoyed this post, make sure you subscribe to my RSS feed! Comments are encouraged