Showing posts with label Tips & Tricks. Show all posts
Showing posts with label Tips & Tricks. Show all posts

Tuesday, September 17, 2013

HACK ANY COMPUTER WITH JUST AN IP


1.) Autopwn is no longer included by default in the msf framework, as it tends to crash target computers, which isn't usually the desired effect. You can still use autopwn is you have an older version of the framework or backtrack. It's quick and effective, but it raises lots of red flags.

2.) This tutorial is two years old, setting up metasploit is now easier and only requires you to hit "next" a dozen times. There's no need for all the sql stuff anymore.

3.) Metasploit has the potential to exploit ANY computer with ANY OS, not just Windows.

4.) There are a group of people out their who insist this entire tutorial was copied and pasted. The places I apparently copied it from copied it from me! Check those dates people, come on...

I'm going to leave the original thread here for archive purposes. Perhaps it can help someone.

--
Hello everybody! I am here to show you this magical tool called Metasploit that allows you to hack ANY unpatched computer with only it's IP. Lets begin...

1.) First you need to download Metasploit. The most up-to-date version is FREE at metasploit.com.

2.) You need PostgrSQL for your database. Download here: http://www.postgresql.org/. Make sure you use all the defaults or Metasploit woun't work!

3.) Now lets get down to buisness... After installing both tools, open up the PostgrSQL admin gui (start -> all programs -> PostgreSQL 9.0 -> pgAdmin III). Then right-click on your server (in the left hand box) and click connect. Remember to keep this window open the whole time. You will also need the pass you chose to use in step 5...

[Image: pgadmin.bmp]

4.) Time for some hacking! Go to start -> all programs -> Metasploit Framework, and then open the Metasploit gui. Let it load untill it look like this:

[Image: metasploit.bmp]

5.)Now, in the window type:

db_connect postgres:ThePassYouChose@localhost:5432

The first time you do this you will see lots of text flash buy. Don't wory, this is normal.

6.)Type db_host to make sure you are connected correctally.

7.)Now type this:

db_nmap 000.000.000.000

Make sure you put the ip of the computer you are trying to hack in the place of 000.000.000.000...

7.) Now we get to the fun part; the automatic exploitation. Just type db_autopwn -t -p -e -s -b , watch the auto-exploitation start, go play Halo for a while, and then come back...

8.) After the exploitation is done, type sessions -l to see what the scanner found. If all went well, you should see a list of exploits.

9.) Now we get to use the exploits to hack the computer! If you will notice, all of the exploits are numbered, and they all have obvious names (i. e., reverseScreen_tcp). In order to use an exploit, type this:

HACK ANY COMPUTER WITH JUST AN IP

Posted at  3:42 AM - by devil 0

HACK ANY COMPUTER WITH JUST AN IP


1.) Autopwn is no longer included by default in the msf framework, as it tends to crash target computers, which isn't usually the desired effect. You can still use autopwn is you have an older version of the framework or backtrack. It's quick and effective, but it raises lots of red flags.

2.) This tutorial is two years old, setting up metasploit is now easier and only requires you to hit "next" a dozen times. There's no need for all the sql stuff anymore.

3.) Metasploit has the potential to exploit ANY computer with ANY OS, not just Windows.

4.) There are a group of people out their who insist this entire tutorial was copied and pasted. The places I apparently copied it from copied it from me! Check those dates people, come on...

I'm going to leave the original thread here for archive purposes. Perhaps it can help someone.

--
Hello everybody! I am here to show you this magical tool called Metasploit that allows you to hack ANY unpatched computer with only it's IP. Lets begin...

1.) First you need to download Metasploit. The most up-to-date version is FREE at metasploit.com.

2.) You need PostgrSQL for your database. Download here: http://www.postgresql.org/. Make sure you use all the defaults or Metasploit woun't work!

3.) Now lets get down to buisness... After installing both tools, open up the PostgrSQL admin gui (start -> all programs -> PostgreSQL 9.0 -> pgAdmin III). Then right-click on your server (in the left hand box) and click connect. Remember to keep this window open the whole time. You will also need the pass you chose to use in step 5...

[Image: pgadmin.bmp]

4.) Time for some hacking! Go to start -> all programs -> Metasploit Framework, and then open the Metasploit gui. Let it load untill it look like this:

[Image: metasploit.bmp]

5.)Now, in the window type:

db_connect postgres:ThePassYouChose@localhost:5432

The first time you do this you will see lots of text flash buy. Don't wory, this is normal.

6.)Type db_host to make sure you are connected correctally.

7.)Now type this:

db_nmap 000.000.000.000

Make sure you put the ip of the computer you are trying to hack in the place of 000.000.000.000...

7.) Now we get to the fun part; the automatic exploitation. Just type db_autopwn -t -p -e -s -b , watch the auto-exploitation start, go play Halo for a while, and then come back...

8.) After the exploitation is done, type sessions -l to see what the scanner found. If all went well, you should see a list of exploits.

9.) Now we get to use the exploits to hack the computer! If you will notice, all of the exploits are numbered, and they all have obvious names (i. e., reverseScreen_tcp). In order to use an exploit, type this:

How To Get Maximum Speed in  your Modem and Internet
 
first form

Step One
Home Run, type gpedit.msc
and pressing OK.

Step Two
In the window that opens you follow the following path:
In the left pane you expand
Team Configuration
Administrative Templates / Network / QoS Packet Scheduler "

and you click on QoS Packet Scheduler (twice).
In the right pane you double-click on Limit width
Band booked and will open a new window.

Step Three
Enabled Active in bandwidth limit (%) put 0.
You click on the Apply button and then OK.
Sales of Group Policy and, in many cases without
restart (in other'll have to do it, depends on your computer)
you will notice a big boost in internet speed

Second form

first Step
Let my pc Properties
Here select hardware
then device manager
modems and we click then select twice
where it says modem huawei or mark your Modem

Second Step
Let then advanced options and where it says
Additional initialization commands put S10 = 50
then we accept and close all

Another way is to do it through programs, such as:

* NETEagle*
-Install the program when you open it and select your operating system in the lower select our type I put Satellite Internet Modem.

-We click ok and wait for it to load and ready

* Simple Net Speed
Step One
-Once installed the program will open in the part where
Speed ​​Adjust your Briadband says select our
speed if you do not know what your speed put 700Kbps

Step Two
-Where it says Multiplier move it to where it says 5X
if your broadband internet is you can put 7X

Step Three
-We Click Apply and waited about 5 seconds and
we click on Close
They are free to use and you can download from their official website.

http://www.themesoft.net/
http://www.softpedia.com/get/Tweak/Netwo...peed.shtml

How To Get Maximum Speed in your Modem and Internet

Posted at  3:38 AM - by devil 0

How To Get Maximum Speed in  your Modem and Internet
 
first form

Step One
Home Run, type gpedit.msc
and pressing OK.

Step Two
In the window that opens you follow the following path:
In the left pane you expand
Team Configuration
Administrative Templates / Network / QoS Packet Scheduler "

and you click on QoS Packet Scheduler (twice).
In the right pane you double-click on Limit width
Band booked and will open a new window.

Step Three
Enabled Active in bandwidth limit (%) put 0.
You click on the Apply button and then OK.
Sales of Group Policy and, in many cases without
restart (in other'll have to do it, depends on your computer)
you will notice a big boost in internet speed

Second form

first Step
Let my pc Properties
Here select hardware
then device manager
modems and we click then select twice
where it says modem huawei or mark your Modem

Second Step
Let then advanced options and where it says
Additional initialization commands put S10 = 50
then we accept and close all

Another way is to do it through programs, such as:

* NETEagle*
-Install the program when you open it and select your operating system in the lower select our type I put Satellite Internet Modem.

-We click ok and wait for it to load and ready

* Simple Net Speed
Step One
-Once installed the program will open in the part where
Speed ​​Adjust your Briadband says select our
speed if you do not know what your speed put 700Kbps

Step Two
-Where it says Multiplier move it to where it says 5X
if your broadband internet is you can put 7X

Step Three
-We Click Apply and waited about 5 seconds and
we click on Close
They are free to use and you can download from their official website.

http://www.themesoft.net/
http://www.softpedia.com/get/Tweak/Netwo...peed.shtml

 How to hide any file inside a picture


This tutorial can be used for any type of file including mp3,wmv,.rar,etc

[Image: hide-imp-files.gif]
Here is how it goes:

1. Open C: Drive and make a folder in it e.g. “hacks”. Put both the files i.e. the file that you want to hide and the image inside which you want to hide the file into this folder

[Image: hide-imp-files-1.gif]

2. Select both the files and make a compressed RAR archive e.g. “secret.rar” out of them

[Image: hide-imp-files-2.gif]

3. Open Run and type in “cmd” to open the Command Prompt. Now type “cd..” and press enter and repeat this once again. Type “cd sizlopedia” to open the folder (where “hacks” is the folder that I am using in this tutorial)

[Image: hide-imp-files-3.gif]

4. Type the command “copy /b maria.jpg + secret.rar safe.jpg” and press enter

[Image: hide-imp-files-4.gif]

5. The new picture safe.jpg is now the nested Picture file which has the hidden file saved inside it. Change its extension from .jpg to .rar anytime to access or extract the hidden file

[Image: hide-imp-files-41.gif]

How to hide any file inside a picture

Posted at  3:33 AM - by devil 0

 How to hide any file inside a picture


This tutorial can be used for any type of file including mp3,wmv,.rar,etc

[Image: hide-imp-files.gif]
Here is how it goes:

1. Open C: Drive and make a folder in it e.g. “hacks”. Put both the files i.e. the file that you want to hide and the image inside which you want to hide the file into this folder

[Image: hide-imp-files-1.gif]

2. Select both the files and make a compressed RAR archive e.g. “secret.rar” out of them

[Image: hide-imp-files-2.gif]

3. Open Run and type in “cmd” to open the Command Prompt. Now type “cd..” and press enter and repeat this once again. Type “cd sizlopedia” to open the folder (where “hacks” is the folder that I am using in this tutorial)

[Image: hide-imp-files-3.gif]

4. Type the command “copy /b maria.jpg + secret.rar safe.jpg” and press enter

[Image: hide-imp-files-4.gif]

5. The new picture safe.jpg is now the nested Picture file which has the hidden file saved inside it. Change its extension from .jpg to .rar anytime to access or extract the hidden file

[Image: hide-imp-files-41.gif]




This tutorial has been written for the Wraith and is NOT for public distibution.
All information in this tutorial is for educational purposes only. Any illegal activity relating to this tutorial is not my responsibility, although I would like to say I don't care how you use it, I do. So please do not use this for Black-hat activities. One day when you grow up you might realise that you have been a skid, by using mass-deface techniques and SQLi for your entire life. Do not just hack a site because it is there. I have a few sites of my own and its annoying, unproductive, and pointless.

Hide like a hacker


i- Protection
ii- Encryption
iii- Anonymity
iv- Links


Protection

Basically what I am trying to say in this section is, before you go out hacking other people and other things, just check for a second and make sure it's not as easy to hack your device. There are some pretty simple steps for this though.

  • Make sure all your security updates are installed, if you have windows firewall disable it.
  • Download your own firewall. If you are behind a router you can skip this.
  • Make sure all unused ports are closed.
  • Check your msconfig, run a few HJT logs and Malwarebyte's to make sure you are not already infected.
  • Use a keyscambler to prevent keyloggers

It is important that you are not infected because other could see you hacking and steal it from you or alternitively, if they get caught, you get caught. On the other hand you might want to stay infected by a bot or RAT so if and when you are caught you can claim you had no knowledge and the bot controlled your PC and performed the hack without your knowledge. However I am not someone who intends to be caught. (I'm not really a black hat either)

I don't personally use an AV for many reasons reasons:
  • It is possible to make an FUD virus, this is likely to be what you get infected with.
  • It often goes around deleting your stuff without asking.
  • They slow down your PC and often hog the CPU.
  • Whilst performing updates it slows down your connection.

FireWall: (not tested)
http://personalfirewall.comodo.com

KeyScrambler:
http://www.qfxsoftware.com

HJT:
http://download.cnet.com/Trend-Micro-Hij...27353.html

Malewarebytes:
http://www.malwarebytes.org

Another way to prvent this is to use a Lixux-based O/S as altohugh these aren't 100% secure they have a lot on Windows machines due to the fact they are less common.

But remember you are not invisible:
If you downloaded and installed the open-source Unreal IRC server in the last 8 months or so, you’ve been pwned.

"Hi all,

This is very embarrassing…

We found out that the Unreal3.2.8.1.tar.gz file on our mirrors has been replaced quite a while ago with a version with a backdoor (trojan) in it.

This backdoor allows a person to execute ANY command with the privileges of the user running the ircd. The backdoor can be executed regardless of any user restrictions (so even if you have passworded server or hub that doesn’t allow any users in)."
 
Encryption

Be under no ilussions, this is one of the most important steps to keeping information secret. Now I am a big fan of encryption and here is why:
  

if your encryption program uses 128-bit keys, your particular key could be any of more than 3.4 trillion billion billion billion possible combinations. More likely to win the lottery than to crack that level of encryption using the brute-force method"[b]Or just use RSA 4096-bit and 256-bit AES?[/b]
 
Now I think this says a little bit about how much safer encryption makes you, if you encrypt your HDD using 256-bit, there is little chance even the authorities will crack it.... in your lifetime. However do be aware of local law for example in the UK the new Regulation of Investigatory Powers Act states:
  

Individuals who are believed to have the cryptographic keys necessary for such decryption will face up to 5 years in prison for failing to comply with police or military orders to hand over either the cryptographic keys, or the data in a decrypted form.
The penelties are up to 5 years for terrorism-related inforamtion and 2 years for "All other failures to comply"

Therefore depending on the strength of your offence it could be more wise to with-hold your key on claims of a privacy breach, and face the maximum two years than to hand over your keys.

The program I most recomend for doing this is

TrueCrypt:
http://www.truecrypt.org

True crypt can provdie 256-bit encryption  



The design and strength of all key lengths of the AES algorithm (i.e., 128, 192 and 256) are sufficient to protect classified information up to the SECRET level. TOP SECRET information will require use of either the 192 or 256 key lengths.
 
Oh and that's not even the most useful part:
  

TrueCrypt allows you to create a hidden operating system whose existence will be impossible to prove (provided that certain guidelines are followed — see below). Thus, you will not have to decrypt or reveal the password for the hidden operating system.
 
 
 
As there is a pre-boot authentication process which asks for your encryption password you can have two, one for people to see and one for hacking purposes. This is IMPOSSIBLE to prove so I highly recommed using it, although I don't use it myself...

Anonymity

Now, this is THE MOST IMPORTANT section of the whole tutorial, get this part right and you can pretty much forget about the rest (however if you are performing something illegal following the other steps might help you sleep better).

Hidding your IP and identity is crucial. Here is my prefred methods:
  • SOCKS5 Proxy
  • L1 HTTPS Proxy
  • GCI proxy
  • Encrypted VPN (no logs)

Diference between SOCKS and HTTP
 
SOCKS

Bill wishes to communicate with Jane over the internet, but a firewall exists on his network between them and Bill is not authorized to communicate through it himself. Therefore, he connects to the SOCKS proxy on his network and sends to it information about the connection he wishes to make to Jane. The SOCKS proxy opens a connection through the firewall and facilitates the communication between Bill and Jane. For more information on the technical specifics of the SOCKS protocol, see the sections below.
HTTP

Bill wishes to download a web page from Jane, who runs a web server. Bill cannot directly connect to Jane's server, as a firewall has been put in place on his network. In order to communicate with the server, Bill connects to his network's HTTP proxy. His internet browser communicates with the proxy in exactly the same way it would the target server—it sends a standard HTTP request header. The HTTP proxy reads the request and looks for the Host header. It then connects to the server specified in the header and transmits any data the server replies with back to Bill.

Remember:  
 
 
HTTP proxies are traditionally more HTTP protocol aware and do more high level filtering (even though that usually only applies to GET and POST methods, not CONNECT). SOCKS proxies can also forward UDP traffic and work in reverse - HTTP proxies can't do that.
 
Due to the restrictions of a HTTP proxy, they ONLY work for HTTP traffic and do not support UDP and other types of proxy uses. the reason is because they "infer the address of the server and therefore may only be used for HTTP traffic".

Use both HTTP and SOCKS if possible though this is known as "Proxy Chaining" this is used to make your actions harder to trace but its not truely effective.

REMEBER: Do not use an L3 HTTP proxy as they show your true IP in the header and are therefore essentially pointless.

VPN

This is by far the most effective way to conceal your identity. It channels you traffic and encrpts it with 128-bit. Although some support 256-bit. Often a VPN is much more reliable and does not slow down your connection as much (in fact I haven't noticed mine at all)

A VPN is a virtual Private Network
 
"Secure VPNs use cryptographic tunneling protocols to provide confidentiality by blocking intercepts  and packet sniffing, allow sender authentication to block identity spoofing, and provide message integrity by preventing message alteration."
 
 
The best VPN's are paid I used to have a link to a free VPN but that is dead now. I will edit this if I find a link again.

A decent PAID VPN is: HMA

But always use this in conjunction with something else if you are breaking something...

ProxyFirewall is a good program which runs SOCKS and HTTP proxies

[http://uniqueinternetservices.com/proxy-firewall-download.html

Bibliography:

UK law report:
http://arstechnica.com/tech-policy/news/...l-time.ars

Regulation of Investigatory Powers Act:
http://www.opsi.gov.uk/acts/acts2000/ukpga_20023_en_8

Goverment stance on AES:
http://csrc.nist.gov/groups/STM/cmvp/doc...SS15FS.pdf

Wikipedia review on AES:
http://en.wikipedia.org/wiki/Advanced_En...d#Security

TrueCrypt Hidden o/s:
http://www.truecrypt.org/docs/?s=hidden-...ing-system

SOCKS Information and example:
http://en.wikipedia.org/wiki/SOCKS

Proxy Chaining:
http://www.freeproxy.ru/en/free_proxy/fa...aining.htm

Linux infection news:
http://www.zdnet.com/blog/bott/linux-inf...dated/2206

Official IRCd announcement:
http://forums.unrealircd.com/viewtopic.php?t=6562

Downloads linked:

Proxy firewall:
http://uniqueinternetservices.com/proxy-...nload.html

TrueCrypt:
http://www.truecrypt.org/downloads

UltraVPN:
https://www.ultravpn.fr/download.htm

FireWall: (not tested)
http://personalfirewall.comodo.com

KeyScrambler:
http://www.qfxsoftware.com

HJT:
http://download.cnet.com/Trend-Micro-Hij...27353.html

Malewarebytes:
http://www.malwarebytes.org 
 

How To Become anonymous, hide IP, encrypt&hide HDD, hide identity

Posted at  3:28 AM - by devil 0




This tutorial has been written for the Wraith and is NOT for public distibution.
All information in this tutorial is for educational purposes only. Any illegal activity relating to this tutorial is not my responsibility, although I would like to say I don't care how you use it, I do. So please do not use this for Black-hat activities. One day when you grow up you might realise that you have been a skid, by using mass-deface techniques and SQLi for your entire life. Do not just hack a site because it is there. I have a few sites of my own and its annoying, unproductive, and pointless.

Hide like a hacker


i- Protection
ii- Encryption
iii- Anonymity
iv- Links


Protection

Basically what I am trying to say in this section is, before you go out hacking other people and other things, just check for a second and make sure it's not as easy to hack your device. There are some pretty simple steps for this though.

  • Make sure all your security updates are installed, if you have windows firewall disable it.
  • Download your own firewall. If you are behind a router you can skip this.
  • Make sure all unused ports are closed.
  • Check your msconfig, run a few HJT logs and Malwarebyte's to make sure you are not already infected.
  • Use a keyscambler to prevent keyloggers

It is important that you are not infected because other could see you hacking and steal it from you or alternitively, if they get caught, you get caught. On the other hand you might want to stay infected by a bot or RAT so if and when you are caught you can claim you had no knowledge and the bot controlled your PC and performed the hack without your knowledge. However I am not someone who intends to be caught. (I'm not really a black hat either)

I don't personally use an AV for many reasons reasons:
  • It is possible to make an FUD virus, this is likely to be what you get infected with.
  • It often goes around deleting your stuff without asking.
  • They slow down your PC and often hog the CPU.
  • Whilst performing updates it slows down your connection.

FireWall: (not tested)
http://personalfirewall.comodo.com

KeyScrambler:
http://www.qfxsoftware.com

HJT:
http://download.cnet.com/Trend-Micro-Hij...27353.html

Malewarebytes:
http://www.malwarebytes.org

Another way to prvent this is to use a Lixux-based O/S as altohugh these aren't 100% secure they have a lot on Windows machines due to the fact they are less common.

But remember you are not invisible:
If you downloaded and installed the open-source Unreal IRC server in the last 8 months or so, you’ve been pwned.

"Hi all,

This is very embarrassing…

We found out that the Unreal3.2.8.1.tar.gz file on our mirrors has been replaced quite a while ago with a version with a backdoor (trojan) in it.

This backdoor allows a person to execute ANY command with the privileges of the user running the ircd. The backdoor can be executed regardless of any user restrictions (so even if you have passworded server or hub that doesn’t allow any users in)."
 
Encryption

Be under no ilussions, this is one of the most important steps to keeping information secret. Now I am a big fan of encryption and here is why:
  

if your encryption program uses 128-bit keys, your particular key could be any of more than 3.4 trillion billion billion billion possible combinations. More likely to win the lottery than to crack that level of encryption using the brute-force method"[b]Or just use RSA 4096-bit and 256-bit AES?[/b]
 
Now I think this says a little bit about how much safer encryption makes you, if you encrypt your HDD using 256-bit, there is little chance even the authorities will crack it.... in your lifetime. However do be aware of local law for example in the UK the new Regulation of Investigatory Powers Act states:
  

Individuals who are believed to have the cryptographic keys necessary for such decryption will face up to 5 years in prison for failing to comply with police or military orders to hand over either the cryptographic keys, or the data in a decrypted form.
The penelties are up to 5 years for terrorism-related inforamtion and 2 years for "All other failures to comply"

Therefore depending on the strength of your offence it could be more wise to with-hold your key on claims of a privacy breach, and face the maximum two years than to hand over your keys.

The program I most recomend for doing this is

TrueCrypt:
http://www.truecrypt.org

True crypt can provdie 256-bit encryption  



The design and strength of all key lengths of the AES algorithm (i.e., 128, 192 and 256) are sufficient to protect classified information up to the SECRET level. TOP SECRET information will require use of either the 192 or 256 key lengths.
 
Oh and that's not even the most useful part:
  

TrueCrypt allows you to create a hidden operating system whose existence will be impossible to prove (provided that certain guidelines are followed — see below). Thus, you will not have to decrypt or reveal the password for the hidden operating system.
 
 
 
As there is a pre-boot authentication process which asks for your encryption password you can have two, one for people to see and one for hacking purposes. This is IMPOSSIBLE to prove so I highly recommed using it, although I don't use it myself...

Anonymity

Now, this is THE MOST IMPORTANT section of the whole tutorial, get this part right and you can pretty much forget about the rest (however if you are performing something illegal following the other steps might help you sleep better).

Hidding your IP and identity is crucial. Here is my prefred methods:
  • SOCKS5 Proxy
  • L1 HTTPS Proxy
  • GCI proxy
  • Encrypted VPN (no logs)

Diference between SOCKS and HTTP
 
SOCKS

Bill wishes to communicate with Jane over the internet, but a firewall exists on his network between them and Bill is not authorized to communicate through it himself. Therefore, he connects to the SOCKS proxy on his network and sends to it information about the connection he wishes to make to Jane. The SOCKS proxy opens a connection through the firewall and facilitates the communication between Bill and Jane. For more information on the technical specifics of the SOCKS protocol, see the sections below.
HTTP

Bill wishes to download a web page from Jane, who runs a web server. Bill cannot directly connect to Jane's server, as a firewall has been put in place on his network. In order to communicate with the server, Bill connects to his network's HTTP proxy. His internet browser communicates with the proxy in exactly the same way it would the target server—it sends a standard HTTP request header. The HTTP proxy reads the request and looks for the Host header. It then connects to the server specified in the header and transmits any data the server replies with back to Bill.

Remember:  
 
 
HTTP proxies are traditionally more HTTP protocol aware and do more high level filtering (even though that usually only applies to GET and POST methods, not CONNECT). SOCKS proxies can also forward UDP traffic and work in reverse - HTTP proxies can't do that.
 
Due to the restrictions of a HTTP proxy, they ONLY work for HTTP traffic and do not support UDP and other types of proxy uses. the reason is because they "infer the address of the server and therefore may only be used for HTTP traffic".

Use both HTTP and SOCKS if possible though this is known as "Proxy Chaining" this is used to make your actions harder to trace but its not truely effective.

REMEBER: Do not use an L3 HTTP proxy as they show your true IP in the header and are therefore essentially pointless.

VPN

This is by far the most effective way to conceal your identity. It channels you traffic and encrpts it with 128-bit. Although some support 256-bit. Often a VPN is much more reliable and does not slow down your connection as much (in fact I haven't noticed mine at all)

A VPN is a virtual Private Network
 
"Secure VPNs use cryptographic tunneling protocols to provide confidentiality by blocking intercepts  and packet sniffing, allow sender authentication to block identity spoofing, and provide message integrity by preventing message alteration."
 
 
The best VPN's are paid I used to have a link to a free VPN but that is dead now. I will edit this if I find a link again.

A decent PAID VPN is: HMA

But always use this in conjunction with something else if you are breaking something...

ProxyFirewall is a good program which runs SOCKS and HTTP proxies

[http://uniqueinternetservices.com/proxy-firewall-download.html

Bibliography:

UK law report:
http://arstechnica.com/tech-policy/news/...l-time.ars

Regulation of Investigatory Powers Act:
http://www.opsi.gov.uk/acts/acts2000/ukpga_20023_en_8

Goverment stance on AES:
http://csrc.nist.gov/groups/STM/cmvp/doc...SS15FS.pdf

Wikipedia review on AES:
http://en.wikipedia.org/wiki/Advanced_En...d#Security

TrueCrypt Hidden o/s:
http://www.truecrypt.org/docs/?s=hidden-...ing-system

SOCKS Information and example:
http://en.wikipedia.org/wiki/SOCKS

Proxy Chaining:
http://www.freeproxy.ru/en/free_proxy/fa...aining.htm

Linux infection news:
http://www.zdnet.com/blog/bott/linux-inf...dated/2206

Official IRCd announcement:
http://forums.unrealircd.com/viewtopic.php?t=6562

Downloads linked:

Proxy firewall:
http://uniqueinternetservices.com/proxy-...nload.html

TrueCrypt:
http://www.truecrypt.org/downloads

UltraVPN:
https://www.ultravpn.fr/download.htm

FireWall: (not tested)
http://personalfirewall.comodo.com

KeyScrambler:
http://www.qfxsoftware.com

HJT:
http://download.cnet.com/Trend-Micro-Hij...27353.html

Malewarebytes:
http://www.malwarebytes.org 
 

 How To Methods to Bypass Surveys



Method 1:

Go to this website http://surveybypass.com/ and copy the survey link and hit the Go! button. After that you will get a new link from which you can download the file without any problem. But this method doesn't work sometimes, so if it doesn't you can try the other methods.

Method 2:

This is another website http://howtobypasssurveys.com/download/, go there and download the survey bypasser tool. Then open the program, put the link with the survey and hit enter, and you will get a new link, where you can download the file without any survey.

Method 3:

For people with Google Chrome, download this Chrome plugin: https://chrome.google.com/webstore/detai...hjg?hl=en, install it and it will be in the upper right corner. Whenever you want to bypass a survey, click it.

For people with Mozilla Firefox, download this addon: https://addons.mozilla.org/en-US/firefox...cript/=en, it works the same way.

Method 4:

Very simple. You can just disable Javascript on your browser, which will never let the surveys appear.

Method 5:

And the last one, just take this steps:

1) When you are prompted to take a survey, right Click the title and click Inspect Element;

2) Now keep pressing Delete button to delete the scripts on Inspect Element tab until Complete a Survey disappear;

3) After the bar disappear, keep deleting until the page go lighter, with no dark area;

4) Thats it! Now you’ll see your full content or download.

How To Methods to Bypass Surveys

Posted at  3:15 AM - by devil 0

 How To Methods to Bypass Surveys



Method 1:

Go to this website http://surveybypass.com/ and copy the survey link and hit the Go! button. After that you will get a new link from which you can download the file without any problem. But this method doesn't work sometimes, so if it doesn't you can try the other methods.

Method 2:

This is another website http://howtobypasssurveys.com/download/, go there and download the survey bypasser tool. Then open the program, put the link with the survey and hit enter, and you will get a new link, where you can download the file without any survey.

Method 3:

For people with Google Chrome, download this Chrome plugin: https://chrome.google.com/webstore/detai...hjg?hl=en, install it and it will be in the upper right corner. Whenever you want to bypass a survey, click it.

For people with Mozilla Firefox, download this addon: https://addons.mozilla.org/en-US/firefox...cript/=en, it works the same way.

Method 4:

Very simple. You can just disable Javascript on your browser, which will never let the surveys appear.

Method 5:

And the last one, just take this steps:

1) When you are prompted to take a survey, right Click the title and click Inspect Element;

2) Now keep pressing Delete button to delete the scripts on Inspect Element tab until Complete a Survey disappear;

3) After the bar disappear, keep deleting until the page go lighter, with no dark area;

4) Thats it! Now you’ll see your full content or download.

How To Bypassing Facebook security


Ok, here's a new quick tutorial for everyone who has been having to deal with Facebook blocking your entrance into someone's account due to logging in from a different location.

Ever since I had been problems constantly having to deal with Facebook leaving me out off people's accounts I began to think that I should write over my experiences to help others.

I will go over specific techniques and ideas to eventually grant you entrance to their accounts without having to deal with that Facebook problem having logging in from different location.

1st. Before you even begin reading this, you must already have their passwords or e-mails. If not, I will tell you a few ideas of how to acquire them.

If you only want to log in without changing passwords, I would suggest that you steal their passwords through Phishing, keylogging, or RATing.

2nd. Bypassing Facebook security can be done through black hat methods, however I will not go over those methods, instead I will be touching the social engineering methods which are more effective and you can get faster results.

3rd. You will need to use your brain to think and have patience. If you don't have either a brain to think or the patience to wait, please don't continue reading this tutorial because you will not get any success.

Ok, let's move on to the actual information.

-This method is a cheap shot method, but you never know if it might work or not.

#1. If a person uses a particular computer to log in to their accounts on a regular basis, THAT computer alone should be your focus.

You should infect that computer with a keylogger and have it linked together with a FTP to send you the logs or linked to send you e-mails.


#2. Another method is to use your OWN computer to acquire the password by infecting yourself with a keylogger and let the victim use your computer. Gain their trust to the point of where they can log in to different websites.

You can say for instance "My account is not working, I think Facebook banned me. Can you test your account to see if yours is working?"

And of course, they will log in and you will gain the information. After they successfully log in, you can login to your account and say "Oh, there we go! It worked"

Now, you will attempt to log in in the future and the problem of Logging in from another location will dissapear.

#3. Let's say that they aren't stupid enough to use your computer to log in, you might think, what then? Well, here's my next suggestion to you.

Considering that you will already have the password through the methods I mentioned earlier, but you will have the problem of Logging in from another location.

Here's what you do:

Watch and study your victim, if you know he/she uses a location to use a computer, you should attempt to log in at that same location as well. It could be school, library, another friend's house, etc...

Most people will use any computer to log in to Social Networks or E-mails to check on updates. Considering that the IP you log in at that particular is the same within their network, the problem of Logging in from another location will not come up.

#4. So, you don't have the choice of either offering your computer as a trap or the chance to "stalk" your victim. You wonder, what do I do then?

Well, this is where it gets more tricky considering that Facebook finally came up with an ingenious method to avoid intruders of taking over accounts easily.

Here's what Facebook did, in case if you don't already know. Facebook implemented a feature where you must visually recognize the friends on that account. They will show you pictures of random people within that account and ask you to select the name of that person. 


If you don't recognize any of those people, you're screwed.

When will this happen? That will only happen when you attempt to change their passwords, so Facebook makes sure that you do in fact own that account. I personally wouldn't attempt to change the passwords, but if you do try, here's what I would recommend to you.

-If you know the person in person, notice who he/she is friends with to try to recognize the faces and physically ask the other persons their names.

-If you do not know the person, you can use websites like:

http://com.lullar.com/

http://www.pipl.com/email/

To search their names, e-mails, phone numbers to see whether if you can find them on other Social networks. You can search the person's name manually by going to Myspace, Facebook, etc...To see who they have added as friends.

Your next step will be to add a friend of the victim or the victim directly. Adding the victim directly would probably be the best plan because you would have access directly to all the victims' friends and their pictures.

Now, all you have to do is match the pictures that Facebook asks you when you attempt to change their passwords by going to the victims friends and match them.

If you don't want to change their passwords, you can mask the victim's IP using other methods in which I will not go over. To find out their IP, you will need a RAT to manually whois them or any other method other there to find their IP.

A quick method I will suggest to you is to send the victim an e-mail if they have a hotmail account. When they reply you can right click on the e-mail and view source. You will see an IP from sender and use that to mask.

Mask their IP and facebook will not give you the problem of Logging in from another location.

If you follow the suggestions I have given you, you will surely gain entrance to their accounts and Facebook won't be able to do crap.

Their security is strong, but good ol' Social engineering never fails. Thumbsup

Enjoy. Black Hat

How To Bypassing Facebook security

Posted at  3:11 AM - by devil 0

How To Bypassing Facebook security


Ok, here's a new quick tutorial for everyone who has been having to deal with Facebook blocking your entrance into someone's account due to logging in from a different location.

Ever since I had been problems constantly having to deal with Facebook leaving me out off people's accounts I began to think that I should write over my experiences to help others.

I will go over specific techniques and ideas to eventually grant you entrance to their accounts without having to deal with that Facebook problem having logging in from different location.

1st. Before you even begin reading this, you must already have their passwords or e-mails. If not, I will tell you a few ideas of how to acquire them.

If you only want to log in without changing passwords, I would suggest that you steal their passwords through Phishing, keylogging, or RATing.

2nd. Bypassing Facebook security can be done through black hat methods, however I will not go over those methods, instead I will be touching the social engineering methods which are more effective and you can get faster results.

3rd. You will need to use your brain to think and have patience. If you don't have either a brain to think or the patience to wait, please don't continue reading this tutorial because you will not get any success.

Ok, let's move on to the actual information.

-This method is a cheap shot method, but you never know if it might work or not.

#1. If a person uses a particular computer to log in to their accounts on a regular basis, THAT computer alone should be your focus.

You should infect that computer with a keylogger and have it linked together with a FTP to send you the logs or linked to send you e-mails.


#2. Another method is to use your OWN computer to acquire the password by infecting yourself with a keylogger and let the victim use your computer. Gain their trust to the point of where they can log in to different websites.

You can say for instance "My account is not working, I think Facebook banned me. Can you test your account to see if yours is working?"

And of course, they will log in and you will gain the information. After they successfully log in, you can login to your account and say "Oh, there we go! It worked"

Now, you will attempt to log in in the future and the problem of Logging in from another location will dissapear.

#3. Let's say that they aren't stupid enough to use your computer to log in, you might think, what then? Well, here's my next suggestion to you.

Considering that you will already have the password through the methods I mentioned earlier, but you will have the problem of Logging in from another location.

Here's what you do:

Watch and study your victim, if you know he/she uses a location to use a computer, you should attempt to log in at that same location as well. It could be school, library, another friend's house, etc...

Most people will use any computer to log in to Social Networks or E-mails to check on updates. Considering that the IP you log in at that particular is the same within their network, the problem of Logging in from another location will not come up.

#4. So, you don't have the choice of either offering your computer as a trap or the chance to "stalk" your victim. You wonder, what do I do then?

Well, this is where it gets more tricky considering that Facebook finally came up with an ingenious method to avoid intruders of taking over accounts easily.

Here's what Facebook did, in case if you don't already know. Facebook implemented a feature where you must visually recognize the friends on that account. They will show you pictures of random people within that account and ask you to select the name of that person. 


If you don't recognize any of those people, you're screwed.

When will this happen? That will only happen when you attempt to change their passwords, so Facebook makes sure that you do in fact own that account. I personally wouldn't attempt to change the passwords, but if you do try, here's what I would recommend to you.

-If you know the person in person, notice who he/she is friends with to try to recognize the faces and physically ask the other persons their names.

-If you do not know the person, you can use websites like:

http://com.lullar.com/

http://www.pipl.com/email/

To search their names, e-mails, phone numbers to see whether if you can find them on other Social networks. You can search the person's name manually by going to Myspace, Facebook, etc...To see who they have added as friends.

Your next step will be to add a friend of the victim or the victim directly. Adding the victim directly would probably be the best plan because you would have access directly to all the victims' friends and their pictures.

Now, all you have to do is match the pictures that Facebook asks you when you attempt to change their passwords by going to the victims friends and match them.

If you don't want to change their passwords, you can mask the victim's IP using other methods in which I will not go over. To find out their IP, you will need a RAT to manually whois them or any other method other there to find their IP.

A quick method I will suggest to you is to send the victim an e-mail if they have a hotmail account. When they reply you can right click on the e-mail and view source. You will see an IP from sender and use that to mask.

Mask their IP and facebook will not give you the problem of Logging in from another location.

If you follow the suggestions I have given you, you will surely gain entrance to their accounts and Facebook won't be able to do crap.

Their security is strong, but good ol' Social engineering never fails. Thumbsup

Enjoy. Black Hat




Follow the steps below:

  1. Go to http://www.k7.net & Sign up there.
  2. Create an account on gmail, but in location fill "United States" . Create your e-mail account.
  3. Now it will take you to mobile verification page. Here select the option of Voice call and fill the no. that you got from the website (k7.net)
  4. Now you will get a mail having verification code as voice mail on that account from which you have registered on. Go open it, download the attachment file and listen the code, after that type the code of your voice mail in verification code and click OK.
  5. Done. Your account is ready now.



About the website:
This is a site where you can receive fax or voice calls without having a phone no. When you create an account on this site, it will provide you an unique phone number of US.

How to bypass GMAIL mobile verification

Posted at  3:02 AM - by devil 49




Follow the steps below:

  1. Go to http://www.k7.net & Sign up there.
  2. Create an account on gmail, but in location fill "United States" . Create your e-mail account.
  3. Now it will take you to mobile verification page. Here select the option of Voice call and fill the no. that you got from the website (k7.net)
  4. Now you will get a mail having verification code as voice mail on that account from which you have registered on. Go open it, download the attachment file and listen the code, after that type the code of your voice mail in verification code and click OK.
  5. Done. Your account is ready now.



About the website:
This is a site where you can receive fax or voice calls without having a phone no. When you create an account on this site, it will provide you an unique phone number of US.

How To Hack Adf.ly to Boost Your Earnings
 
 
 
what is adf.ly? Adf.ly is a URL Shortener with a twist; it pays you about $0.002 every time someone clicks it. You just have to make an account, shorten URLs, then post them somewhere for people to click.

Click the banner to register on adf.ly

[Image: adfly_zps32321b83.gif]

all users, today I'm going to tell you a 100% employed technique for increasing your earnings by adf.ly and other similar PTC sites like adf.ly. I don't know whether you've noticed or not, now a days tons of adf.ly account are getting banned everyday. Why? because users think that they are much smarter that adf.ly administrators. My recommendation to c2hack.blogspot.in users is that "please don't waste your time in adf.ly bots etc NONE OF THEM are working . Because adf.ly has powerful proxy and bot protection. "

Exploit Status :- WORKING
Works for other PTC Sites :- YES
Can be banned for this :- No 100% invisible exploit


REQUIREMENTS :

1. Adf.ly Account
2. Sioniam Account

INSTRUCTIONS :

1. Got to http://sioniam.com/ and register as a new user. After registering in the sub-sections towards your right of the screen you will find a section called Frame Breaker Surf

2. Below it you will find Silver Surfer section. Click it.

3. Now in the top you will see a link to download the Silver Surfer Application. Download and install

4. Now come back to the main page. Open a new tab and login to your adf.ly account

5. Create a link if not created or use your existing links. Copy your selected link

6. Now scroll downwards your sioniam account below you will see a section called points to click.

7. There you can see a text box and add button.

8. Paste your adf.ly url there and click add.

9. Now Start Silversurfer you installed.

10. Click on the second tab called Details. Now head back to your sioniam account scroll up. On the top you will see

SilverSurfer URL: http://sioniam.com/silversurf.php?id=xxxx

11. Copy your SilverSurfer URL and paste it into the textbox in the tab and click Submit.

12. Now open the browser tab and you will see your SilverSurfer URL click start and you will start earning points which will automatically assigned to your adf.ly link in the points to click section.

I RECOMMEND YOU TO RUN THIS ONLY WHEN YOU USE YOUR COMPUTER.
THIS WILL INCREASE YOU VIEWS UPTO 50 Per link per day

On an average you will get 50 clicks per day (depends upon how much you surf)
So 50x7x30=10920 views which is nearly 3 - 4 Dollars you will earn + your normal adf.ly earnings.

How To Hack Adf.ly to Boost Your Earnings

Posted at  2:58 AM - by devil 1

How To Hack Adf.ly to Boost Your Earnings
 
 
 
what is adf.ly? Adf.ly is a URL Shortener with a twist; it pays you about $0.002 every time someone clicks it. You just have to make an account, shorten URLs, then post them somewhere for people to click.

Click the banner to register on adf.ly

[Image: adfly_zps32321b83.gif]

all users, today I'm going to tell you a 100% employed technique for increasing your earnings by adf.ly and other similar PTC sites like adf.ly. I don't know whether you've noticed or not, now a days tons of adf.ly account are getting banned everyday. Why? because users think that they are much smarter that adf.ly administrators. My recommendation to c2hack.blogspot.in users is that "please don't waste your time in adf.ly bots etc NONE OF THEM are working . Because adf.ly has powerful proxy and bot protection. "

Exploit Status :- WORKING
Works for other PTC Sites :- YES
Can be banned for this :- No 100% invisible exploit


REQUIREMENTS :

1. Adf.ly Account
2. Sioniam Account

INSTRUCTIONS :

1. Got to http://sioniam.com/ and register as a new user. After registering in the sub-sections towards your right of the screen you will find a section called Frame Breaker Surf

2. Below it you will find Silver Surfer section. Click it.

3. Now in the top you will see a link to download the Silver Surfer Application. Download and install

4. Now come back to the main page. Open a new tab and login to your adf.ly account

5. Create a link if not created or use your existing links. Copy your selected link

6. Now scroll downwards your sioniam account below you will see a section called points to click.

7. There you can see a text box and add button.

8. Paste your adf.ly url there and click add.

9. Now Start Silversurfer you installed.

10. Click on the second tab called Details. Now head back to your sioniam account scroll up. On the top you will see

SilverSurfer URL: http://sioniam.com/silversurf.php?id=xxxx

11. Copy your SilverSurfer URL and paste it into the textbox in the tab and click Submit.

12. Now open the browser tab and you will see your SilverSurfer URL click start and you will start earning points which will automatically assigned to your adf.ly link in the points to click section.

I RECOMMEND YOU TO RUN THIS ONLY WHEN YOU USE YOUR COMPUTER.
THIS WILL INCREASE YOU VIEWS UPTO 50 Per link per day

On an average you will get 50 clicks per day (depends upon how much you surf)
So 50x7x30=10920 views which is nearly 3 - 4 Dollars you will earn + your normal adf.ly earnings.








Hello HackForums, this is Agfx. This was my first thread / tutorial on HackForums. I do sincerely hope you enjoy this tutorial and find it to somewhat of a use to you, whatever the use maybe. I have spent a few hours on this tutorial when I first released it, and now I am editing it over again to make sure it sounds more professional, but keeps its simplicity.

Now, let's continue unto the tutorial.

A Shell Stresser and What it does

A Shell Stresser (Booter) is one of many ways to flood an Ip Address, it is harder to use than an API Stresser (meaning you have servers dedicated to your stresser) and not as strong unless you have private or at least unsatured shells. Unsaturated shells meaning they are not used by a great population but rather a small one so they can still be used to their full potential.

Private shells are shells dedicated to you only, whether you have gotten them yourself or you have bought them off of someone. Public shells, I extremely do not recommend. It will decrease the power potential of your stresser because of the amount of people using public shells. In the end, weakening your stresser.

A Shell Stesser floods an IP, depending on how strong your shells are for your stresser, it can take down someone's home connection, websites etc for a long or short period of time. Once again, depending on how strong your shells are.

Downloads

[b]Fibre Optimized - Shell Support (Fibre Booter source with Shell Support) - Recommended


Prodigy's Source (Mass Shell adder created by Natha click here for her page) - [/b]

Team 313's Source

Dbprepare.sql

Shells

For all - http://www.mediafire.com/?dh9qe3deyigqcex

Start

I recommend you complete this tutorial with Prodigy's Source at first. Following what I show you in the tutorial to get a grasp on what you are supposed to do. Once you complete the tutorial and everything works fine, I suggest you switch over to another booter source if you do plan on using the stresser you create. The reason being Prodigy's Source is easily exploitable. It is not reliable.

To start the tutorial, we will need an appropriate web host. In this tutorial, I will be using 000webhost. Only use 000webhost for tutorial purposes once again. As it is easy to understand and laid out simple. Once we have completed the tutorial, and you plan on actually using the booter, switch to a better host as your account will get suspended sometime when using 000webhost. Another reason being 000webhost has WinSock enabled which makes you unable to send attacks.

When you are done making your account and everything is activated, Go to your CPanel.

Once there, scroll down, you should see something called
File Manager under the heading Files click it.


Screenshot (Click to View)

Now sign in with the password you put as your account. Once there, go into public_html, now look on the left hand side for the button named Upload click this button. Now when on the screen click Choose File, find the zip with your source and upload it.

Screenshot #1 (Click to View)

Screenshot #2 (Click to View)

Once everything had loaded successfully as it should, click the green check mark once again, then click the blue arrow pointing <- which is back. Now go to the directory named "Prodigy's Source Mass Shell Adder by Natha". Now go into the source, once there you should see a file called dbc.php, look to your right and click edit.

Now before we do anything to dbc.php go back to your 000webhost CPanel and look for the heading Software / Services click MySQL.

MySQL Database Creation

Now you will need to create a new database & user so fill out the form, remember to use a name you can remember easily as well as a password, for me it will be,

Screenshot #1 (Click to View)

password: windows44. Create the database. Now when on this screen

Screenshot #2 (Click to View)

keep it open. Now go back to the other tab that we closed, fill it out like this

Editing of dbc.php

define ("DB_HOST", "put the host site here"); // set database host
define ("DB_USER", "put your database user here"); // set database user
define ("DB_PASS","password you used when creating database here"); // set database password
define ("DB_NAME","the database name here"); // set database name

Screenshot (Click to View)

Editing of ezSQL.php

Once you are done filling out the dbc.php, click the blue floppy disk on the right hand side and go back. The blue floppy disk saves the editing you have made on the file.

Now, once you have gone back, we will need to complete one more task concerning the database name, host, password and user.

Makre your way to the folder includes, edit the file ezSQL.php. Now when you have clicked edit, scroll down until you see something like
function ezSQL_mysql($dbuser='psychoti_booter', $dbpassword='boot', $dbname='psychoti_booter', $dbhost='127.0.0.1')

We will need to change it so do it as you did the other one.
($dbuser='database user here', $dbpassword='database password', $dbname='the database name', $dbhost='and the host')

Now once again scroll down until you find something similar, it should look like this - function connect($dbuser='psychoti_booter', $dbpassword='boot', $dbhost='localhost') Fill it out, just as I did the above. Now there is only one more, scroll down a little more and look for this - function select($dbname='psychoti_booter'), enter the database name and you're good to go.

Screenshot (Click to View)

Import of Dbprepare.sql and Configuration of the Stresser Site


Click the blue floppy disk and go back. Now you're done with that you can close it. Now go back to CPanel, scroll down and look where MySQL was beside it on the right should be phpMyAdmin click on it. Now you will be taken to a screen, just look for

Screenshot (Click to View)

Click "Enter phpMyAdmin", leave that window open for a second, now before you click it look on the right hand side, it should say Account Information as the title and below it all kinds of information. Click your domain name. Now if you end up on this screen don't worry.

Screenshot (Click to View)

Just click the folder, "Prodigy's Source Mass Shell Adder by Natha" or whatever your zip file was named. Once in there you should see
  • Parent Directory
  • guide.txt
  • dbprepare.sql
  • source/

Just click source/, if you followed this guide with prodigy's source like I recommended you should end up on this page
Screenshot (Click to View)

Which is good. Now go back to the phpdatabase we were at earlier you should see Structure, SQL and etc. Look for the tab Import and click it. This is where you need the dbprepare.sql file I have provided for you, click Choose file and look for it on your computer once you've found it open it and just click go at the bottom.

Now once you have uploaded them all you should have these -
Screenshot (Click to View)

Now go back to your booters page and click register. Now enter a random name, your real name or a fake one it doesn't really matter

Screenshot (Click to View)

Now once you're done filling it out click register. Now go back to the phpmyadmin database and go to the tab "Browse", you should see an account added click the green pencil beside the account.

Once on the screen look for "user_level" and change it to 5. Then scroll down to the bottom and you should see "approved" change the 0 to a 1, click go.

Screenshot (Click to View)

Tutorial Complete with Free Shells

You are now done creating your booter, go back to your booter page and put in your login credentials and login. Now all you have to do is add shells and your booter is ready.

Keep in mind that this was my first tutorial so if I have made any mistakes please just point them out to me, not in a rude way of course and I will fix them. If you need any help, post here and I will get back to you.

Finding Shells

Go to pastebin / webdav and copy/type this into the search -
Code:
[/b][b]/x32.php [/b][b] /greenshell.php [/b][b] /shell.php[/b][b]/webdav/ [/b][b]

TCP are POST shells, UDP are GET shells.

A lot of shells will now be found, get a shell checker and check the shells before you use them.

Thank you for taking your time out to read this tutorial. Make sure to leave a comment below telling me what you think about it.

Sincerely, Agfx Black Hat

How to Setup Your Own Webbased Shell Stresser

Posted at  1:59 AM - by devil 0








Hello HackForums, this is Agfx. This was my first thread / tutorial on HackForums. I do sincerely hope you enjoy this tutorial and find it to somewhat of a use to you, whatever the use maybe. I have spent a few hours on this tutorial when I first released it, and now I am editing it over again to make sure it sounds more professional, but keeps its simplicity.

Now, let's continue unto the tutorial.

A Shell Stresser and What it does

A Shell Stresser (Booter) is one of many ways to flood an Ip Address, it is harder to use than an API Stresser (meaning you have servers dedicated to your stresser) and not as strong unless you have private or at least unsatured shells. Unsaturated shells meaning they are not used by a great population but rather a small one so they can still be used to their full potential.

Private shells are shells dedicated to you only, whether you have gotten them yourself or you have bought them off of someone. Public shells, I extremely do not recommend. It will decrease the power potential of your stresser because of the amount of people using public shells. In the end, weakening your stresser.

A Shell Stesser floods an IP, depending on how strong your shells are for your stresser, it can take down someone's home connection, websites etc for a long or short period of time. Once again, depending on how strong your shells are.

Downloads

[b]Fibre Optimized - Shell Support (Fibre Booter source with Shell Support) - Recommended


Prodigy's Source (Mass Shell adder created by Natha click here for her page) - [/b]

Team 313's Source

Dbprepare.sql

Shells

For all - http://www.mediafire.com/?dh9qe3deyigqcex

Start

I recommend you complete this tutorial with Prodigy's Source at first. Following what I show you in the tutorial to get a grasp on what you are supposed to do. Once you complete the tutorial and everything works fine, I suggest you switch over to another booter source if you do plan on using the stresser you create. The reason being Prodigy's Source is easily exploitable. It is not reliable.

To start the tutorial, we will need an appropriate web host. In this tutorial, I will be using 000webhost. Only use 000webhost for tutorial purposes once again. As it is easy to understand and laid out simple. Once we have completed the tutorial, and you plan on actually using the booter, switch to a better host as your account will get suspended sometime when using 000webhost. Another reason being 000webhost has WinSock enabled which makes you unable to send attacks.

When you are done making your account and everything is activated, Go to your CPanel.

Once there, scroll down, you should see something called
File Manager under the heading Files click it.


Screenshot (Click to View)

Now sign in with the password you put as your account. Once there, go into public_html, now look on the left hand side for the button named Upload click this button. Now when on the screen click Choose File, find the zip with your source and upload it.

Screenshot #1 (Click to View)

Screenshot #2 (Click to View)

Once everything had loaded successfully as it should, click the green check mark once again, then click the blue arrow pointing <- which is back. Now go to the directory named "Prodigy's Source Mass Shell Adder by Natha". Now go into the source, once there you should see a file called dbc.php, look to your right and click edit.

Now before we do anything to dbc.php go back to your 000webhost CPanel and look for the heading Software / Services click MySQL.

MySQL Database Creation

Now you will need to create a new database & user so fill out the form, remember to use a name you can remember easily as well as a password, for me it will be,

Screenshot #1 (Click to View)

password: windows44. Create the database. Now when on this screen

Screenshot #2 (Click to View)

keep it open. Now go back to the other tab that we closed, fill it out like this

Editing of dbc.php

define ("DB_HOST", "put the host site here"); // set database host
define ("DB_USER", "put your database user here"); // set database user
define ("DB_PASS","password you used when creating database here"); // set database password
define ("DB_NAME","the database name here"); // set database name

Screenshot (Click to View)

Editing of ezSQL.php

Once you are done filling out the dbc.php, click the blue floppy disk on the right hand side and go back. The blue floppy disk saves the editing you have made on the file.

Now, once you have gone back, we will need to complete one more task concerning the database name, host, password and user.

Makre your way to the folder includes, edit the file ezSQL.php. Now when you have clicked edit, scroll down until you see something like
function ezSQL_mysql($dbuser='psychoti_booter', $dbpassword='boot', $dbname='psychoti_booter', $dbhost='127.0.0.1')

We will need to change it so do it as you did the other one.
($dbuser='database user here', $dbpassword='database password', $dbname='the database name', $dbhost='and the host')

Now once again scroll down until you find something similar, it should look like this - function connect($dbuser='psychoti_booter', $dbpassword='boot', $dbhost='localhost') Fill it out, just as I did the above. Now there is only one more, scroll down a little more and look for this - function select($dbname='psychoti_booter'), enter the database name and you're good to go.

Screenshot (Click to View)

Import of Dbprepare.sql and Configuration of the Stresser Site


Click the blue floppy disk and go back. Now you're done with that you can close it. Now go back to CPanel, scroll down and look where MySQL was beside it on the right should be phpMyAdmin click on it. Now you will be taken to a screen, just look for

Screenshot (Click to View)

Click "Enter phpMyAdmin", leave that window open for a second, now before you click it look on the right hand side, it should say Account Information as the title and below it all kinds of information. Click your domain name. Now if you end up on this screen don't worry.

Screenshot (Click to View)

Just click the folder, "Prodigy's Source Mass Shell Adder by Natha" or whatever your zip file was named. Once in there you should see
  • Parent Directory
  • guide.txt
  • dbprepare.sql
  • source/

Just click source/, if you followed this guide with prodigy's source like I recommended you should end up on this page
Screenshot (Click to View)

Which is good. Now go back to the phpdatabase we were at earlier you should see Structure, SQL and etc. Look for the tab Import and click it. This is where you need the dbprepare.sql file I have provided for you, click Choose file and look for it on your computer once you've found it open it and just click go at the bottom.

Now once you have uploaded them all you should have these -
Screenshot (Click to View)

Now go back to your booters page and click register. Now enter a random name, your real name or a fake one it doesn't really matter

Screenshot (Click to View)

Now once you're done filling it out click register. Now go back to the phpmyadmin database and go to the tab "Browse", you should see an account added click the green pencil beside the account.

Once on the screen look for "user_level" and change it to 5. Then scroll down to the bottom and you should see "approved" change the 0 to a 1, click go.

Screenshot (Click to View)

Tutorial Complete with Free Shells

You are now done creating your booter, go back to your booter page and put in your login credentials and login. Now all you have to do is add shells and your booter is ready.

Keep in mind that this was my first tutorial so if I have made any mistakes please just point them out to me, not in a rude way of course and I will fix them. If you need any help, post here and I will get back to you.

Finding Shells

Go to pastebin / webdav and copy/type this into the search -
Code:
[/b][b]/x32.php [/b][b] /greenshell.php [/b][b] /shell.php[/b][b]/webdav/ [/b][b]

TCP are POST shells, UDP are GET shells.

A lot of shells will now be found, get a shell checker and check the shells before you use them.

Thank you for taking your time out to read this tutorial. Make sure to leave a comment below telling me what you think about it.

Sincerely, Agfx Black Hat

How to Hack Windows Password Using OphCrack Live CD

Includes : WinXP, Vista, 7


Ophcrack LiveCD 3.4.0 is a completely self contained, bootable version of Ophcrack 3.4.0 - the easiest and most effective tool that I've ever found to "crack" Windows password.

Downloading OphCrack.

Ophcrack is a free software program that recovers passwords so the first step you'll need to take is to visit the Ophcrack Website.. When the Ophcrack website loads as shown above, click the Download ophcrack LiveCD button.



Choosing the Correct Ophcrack LiveCD Version.


After clicking the Download ophcrack LiveCD button in the previous step, the webpage below should display.

Click the button corresponding to the version of Windows on the computer you'll be recovering the password on.

In other words, if you've forgotten the password on:

Windows 7: Click on ophcrack Vista/7 LiveCD.
Windows Vista: Click on ophcrack Vista/7 LiveCD.
Windows XP: Click on ophcrack XP LiveCD.

Code:
Just to be clear, the operating system of the computer you're using right now doesn't matter. You want to download the appropriate Ophcrack LiveCD version for the computer that you're cracking the password on.

Note: Don't worry about the ophcrack LiveCD (without tables) option.


[Image: ophcrack-tutorial-02.jpg]

Burn the Ophcrack LiveCD ISO File to a Disc.


Important: If the ISO file is not burned correctly, Ophcrack LiveCD will not work at all.

[Image: ophcrack-burn-cd-1-1.jpg]

After burning the Ophcrack LiveCD ISO file to a disc, go to the computer that you can't get in to and continue with the next step.

Restart With the Ophcrack LiveCD Disc In Your Optical Drive.


The Ophcrack LiveCD disc you just burned is a "bootable" disc, meaning it contains a small operating system and software and can be ran independent of the operating system on your hard drive. This is exactly what we need in this situation because you can't access the operating system on your hard drive right now (Windows 7, Vista, or XP) due to not knowing the password.

Insert the Ophcrack LiveCD disc into your CD/DVD drive and restart your computer.

The initial screen you see after restarting should be the same one you always see immediately after starting your computer. There may be computer information like in this screenshot or there may be a computer manufacturer logo.

[Image: biospostscreen1.jpg]

Ophcrack LiveCD begins immediately after this point in the boot process, as shown in the next step.

Boot To the Ophcrack LiveCD Disc


After the initial startup of your computer is complete, as shown in the previous step, the Ophcrack LiveCD menu should display.

You don't need to do anything here. Ophcrack LiveCD will continue automatically after the Automatic boot in x seconds... timer at the bottom of the screen expires. If you'd like to advance the process a little faster, feel free to hit Enter while Ophcrack Graphic mode - automatic is highlighted.

[Image: ophcrack-tutorial-06.jpg]

Don't See This Screen? If Windows started, you see an error message, or you see a blank screen, then something went wrong. If you see anything other than the menu screen shown above then Ophcrack LiveCD did not start correctly and will not recover your password.

Are You Booting to the Disc Correctly?: The most likely reason that Ophcrack LiveCD might not be working properly is because your computer is not configured to boot from the disc you burned. Don't worry, it's an easy fix.

Did You Burn the ISO File Correctly?: The second most likely reason that the Ophcrack LiveCD isn't working is because the ISO file was not burned properly. ISO files are special kinds of files and have to burned differently than you may have burned music or other files. Go back to Step 4 and try burning the Ophcrack LiveCD ISO file again.

Wait for Ophcrack LiveCD to Load...


The next screen consists of several lines of text that quickly run down the screen. You don't need to do anything here.

[Image: ophcrack-tutorial-07.jpg]

These lines of text are detailing the many individual tasks that SliTaz (a Linux operating system) is taking in preparation for loading the Ophcrack LiveCD software program which will recover the Windows passwords encrypted on your hard drive.

Watch for Hard Drive Partition Information to Display


The next step in the Ophcrack LiveCD boot process is this little window that appears on screen. It may appear and disappear very quickly so you could miss it, but I wanted to point it out because it will be a window that runs in the background that you may see.

[Image: ophcrack-tutorial-08.jpg]

This message is simply confirming that a partition with encrypted password information on it has been found on your hard drive. This is good news!

Wait for Ophcrack LiveCD to Recover Your Password


The next screen is the Ophcrack LiveCD software itself. Ophcrack will attempt to recover the passwords for all of the Windows user accounts that it can find on your computer. This password cracking process is completely automated.

The important things to look for here are the accounts listed in the User column and the passwords listed in the NT Pwd column. If the user account you're looking for isn't listed, Ophcrack didn't find that user on your computer. If the NT Pwd field is blank for a particular user, the password has not been recovered yet.

As you can see in the example above, the passwords for the Administrator and Guest accounts are listed as empty. If you were cracking a password for a user that Ophcrack shows as empty, you now know that you can log on to the account without a password at all, assuming that the user account is enabled.

[Image: ophcrack-4-1.jpg]

Look toward the bottom of the user list - see the Tim user account? In under one minute, Ophcrack recovered the password to this account - applesauce. You can ignore any other accounts you're not interested in recovering the passwords for.

After Ophcrack recovers your password, write it down, remove the Ophcrack LiveCD disc from your optical drive and restart your computer. You don't need to exit the Ophcrack software - it won't harm your computer to power it off or restart it while it's running.

In the next step, you'll finally get to log on to Windows with your discovered password!

Note: If you do not remove the Ophcrack LiveCD disc before you restart, your computer will likely boot from the Ophcrack disc again instead of your hard drive. If that happens, just take the disc out and restart again.

Logon To Windows With the Ophcrack LiveCD Recovered Password


[Image: ophcrack-5-1.jpg]

Now that your password has been recovered using Ophcrack LiveCD, simply enter your password when prompted after booting your computer normally.

How to Hack Windows Password Using OphCrack Live CD

Posted at  1:38 AM - by devil 0

How to Hack Windows Password Using OphCrack Live CD

Includes : WinXP, Vista, 7


Ophcrack LiveCD 3.4.0 is a completely self contained, bootable version of Ophcrack 3.4.0 - the easiest and most effective tool that I've ever found to "crack" Windows password.

Downloading OphCrack.

Ophcrack is a free software program that recovers passwords so the first step you'll need to take is to visit the Ophcrack Website.. When the Ophcrack website loads as shown above, click the Download ophcrack LiveCD button.



Choosing the Correct Ophcrack LiveCD Version.


After clicking the Download ophcrack LiveCD button in the previous step, the webpage below should display.

Click the button corresponding to the version of Windows on the computer you'll be recovering the password on.

In other words, if you've forgotten the password on:

Windows 7: Click on ophcrack Vista/7 LiveCD.
Windows Vista: Click on ophcrack Vista/7 LiveCD.
Windows XP: Click on ophcrack XP LiveCD.

Code:
Just to be clear, the operating system of the computer you're using right now doesn't matter. You want to download the appropriate Ophcrack LiveCD version for the computer that you're cracking the password on.

Note: Don't worry about the ophcrack LiveCD (without tables) option.


[Image: ophcrack-tutorial-02.jpg]

Burn the Ophcrack LiveCD ISO File to a Disc.


Important: If the ISO file is not burned correctly, Ophcrack LiveCD will not work at all.

[Image: ophcrack-burn-cd-1-1.jpg]

After burning the Ophcrack LiveCD ISO file to a disc, go to the computer that you can't get in to and continue with the next step.

Restart With the Ophcrack LiveCD Disc In Your Optical Drive.


The Ophcrack LiveCD disc you just burned is a "bootable" disc, meaning it contains a small operating system and software and can be ran independent of the operating system on your hard drive. This is exactly what we need in this situation because you can't access the operating system on your hard drive right now (Windows 7, Vista, or XP) due to not knowing the password.

Insert the Ophcrack LiveCD disc into your CD/DVD drive and restart your computer.

The initial screen you see after restarting should be the same one you always see immediately after starting your computer. There may be computer information like in this screenshot or there may be a computer manufacturer logo.

[Image: biospostscreen1.jpg]

Ophcrack LiveCD begins immediately after this point in the boot process, as shown in the next step.

Boot To the Ophcrack LiveCD Disc


After the initial startup of your computer is complete, as shown in the previous step, the Ophcrack LiveCD menu should display.

You don't need to do anything here. Ophcrack LiveCD will continue automatically after the Automatic boot in x seconds... timer at the bottom of the screen expires. If you'd like to advance the process a little faster, feel free to hit Enter while Ophcrack Graphic mode - automatic is highlighted.

[Image: ophcrack-tutorial-06.jpg]

Don't See This Screen? If Windows started, you see an error message, or you see a blank screen, then something went wrong. If you see anything other than the menu screen shown above then Ophcrack LiveCD did not start correctly and will not recover your password.

Are You Booting to the Disc Correctly?: The most likely reason that Ophcrack LiveCD might not be working properly is because your computer is not configured to boot from the disc you burned. Don't worry, it's an easy fix.

Did You Burn the ISO File Correctly?: The second most likely reason that the Ophcrack LiveCD isn't working is because the ISO file was not burned properly. ISO files are special kinds of files and have to burned differently than you may have burned music or other files. Go back to Step 4 and try burning the Ophcrack LiveCD ISO file again.

Wait for Ophcrack LiveCD to Load...


The next screen consists of several lines of text that quickly run down the screen. You don't need to do anything here.

[Image: ophcrack-tutorial-07.jpg]

These lines of text are detailing the many individual tasks that SliTaz (a Linux operating system) is taking in preparation for loading the Ophcrack LiveCD software program which will recover the Windows passwords encrypted on your hard drive.

Watch for Hard Drive Partition Information to Display


The next step in the Ophcrack LiveCD boot process is this little window that appears on screen. It may appear and disappear very quickly so you could miss it, but I wanted to point it out because it will be a window that runs in the background that you may see.

[Image: ophcrack-tutorial-08.jpg]

This message is simply confirming that a partition with encrypted password information on it has been found on your hard drive. This is good news!

Wait for Ophcrack LiveCD to Recover Your Password


The next screen is the Ophcrack LiveCD software itself. Ophcrack will attempt to recover the passwords for all of the Windows user accounts that it can find on your computer. This password cracking process is completely automated.

The important things to look for here are the accounts listed in the User column and the passwords listed in the NT Pwd column. If the user account you're looking for isn't listed, Ophcrack didn't find that user on your computer. If the NT Pwd field is blank for a particular user, the password has not been recovered yet.

As you can see in the example above, the passwords for the Administrator and Guest accounts are listed as empty. If you were cracking a password for a user that Ophcrack shows as empty, you now know that you can log on to the account without a password at all, assuming that the user account is enabled.

[Image: ophcrack-4-1.jpg]

Look toward the bottom of the user list - see the Tim user account? In under one minute, Ophcrack recovered the password to this account - applesauce. You can ignore any other accounts you're not interested in recovering the passwords for.

After Ophcrack recovers your password, write it down, remove the Ophcrack LiveCD disc from your optical drive and restart your computer. You don't need to exit the Ophcrack software - it won't harm your computer to power it off or restart it while it's running.

In the next step, you'll finally get to log on to Windows with your discovered password!

Note: If you do not remove the Ophcrack LiveCD disc before you restart, your computer will likely boot from the Ophcrack disc again instead of your hard drive. If that happens, just take the disc out and restart again.

Logon To Windows With the Ophcrack LiveCD Recovered Password


[Image: ophcrack-5-1.jpg]

Now that your password has been recovered using Ophcrack LiveCD, simply enter your password when prompted after booting your computer normally.



Ok, this my first tutorial so tell me what you think ;)
How to send SMS for free using someone else's number:
1. Go to Click Here
2. Select country
3. Fill in the form(when filling the senders ID make sure you include the numbers of your country in front)
4. Press send
5. Done!
Using this method I prank my friends all the time.
Please tell me what you think about my first tutorial.

How to Send free SMS with someone else's number

Posted at  1:34 AM - by devil 0



Ok, this my first tutorial so tell me what you think ;)
How to send SMS for free using someone else's number:
1. Go to Click Here
2. Select country
3. Fill in the form(when filling the senders ID make sure you include the numbers of your country in front)
4. Press send
5. Done!
Using this method I prank my friends all the time.
Please tell me what you think about my first tutorial.

Copyright © 2013 hacking-guru. by Bloggertheme9 Powered by Blogger.
WP Theme-junkie converted by Blogger template