Showing posts with label How to Become Hacker. Show all posts
Showing posts with label How to Become Hacker. Show all posts

Tuesday, 3 May 2016

How to Find Information of a Website

How to Find Information of a Website

Hello Friends, I am Mahak Bhawsar a Ethical Hacker. I am Back with some New Hacking Tutorials. In this post we are Going to Study How we can Find Information of Website. As u all knows that Foot printing is first step for a Hacker. Foot Printing mean gathering information of our target.



In this Tutorial we Gonna Find Information of Website like :-
  • Its Domain  
  • Its Name server 
  • IP of Server
  • IP of Name Server
  • Its Hosting Company
  • Its Domain Registrar
  • Which Web server they are using 
  • OS of Web server

Pre-requisite

Steps

1. Select the target Website & copy the Domain of the website. Ex www.microsoft.com 
2. Go the www.netcraft.com & paste the domain.


3. After Pasting Domain Click arrow & wait for Result. 
4. You will get Result like this




5. You will get some Information Through this Website & for some more Information we will use a tool called DNS Data View.
6. Download the tool from Internet and Install it.
7. Run the application as Administration.


8. When you start application you will see this Window.


9. Give the target Domain Ex zoomgroup.com & click OK.


10. Wait for some time you will get Result like this.

_________________Thank You_________________


Sunday, 1 May 2016

Countermeasure Technique For Malware

Countermeasure Technique For Malware

Hello Friends, Today We are going to Study the Countermeasure technique for Malware. How can we protect our Computer from Malware. What Countermeasure Techniques we need to Protect our self.

It is always a cat and mouse game between malicious hackers hackers and security administrators. The one who is netter equipped has a greater chance of winning.

This post deals with some of the tools are absolutely necessary protect host in risky environments.



Anti-Virus

We all know this - antivirus is essential. Antivirus software installed on a client scans all the local files to check for virus infections. The antivirus has a database of all known virus which will be used to determine the virus infections on the device

Anti-Worm

Anti-worm is a software that can installed on a client device which scans all the local files to check for worm infection . This too relies on a database of known worms to find out infection.

Anti-Trojan

Anti-Trojan software scans all the local files to check for Trojans. Trojans are hidden programs which latch on to legitimate programs.

These Trojans can be detected by the Anti-Trojan software which maintains a database of all known Trojans.

Internet Security Suit

Internet security suit is an application that inspects a device (Laptop, Desktop, Mobile, Tablet) for different kinds of malware like Viruses, Worms, Trojans, Adware etc. Different vendors also include a personal firewall in the suit which can be used to control the traffic flow to and the device and also to control which application can get network access.

Host-based Intrusion detection system

A host-based intrusion detection system (HIDS) is an intrusion detection system that monitors and analyses the network of a computing system as well as (in some cases) the network packets on its network interfaces. A host-based IDS monitors all or parts of the dynamic behaviour and the state of a computer system A. HIDS might look at the state of a system, Its stored information whether in RAM in the file system, log files or else where and check that contents of these appear as expected.

Host Based Intrusion Prevention System

A host based intrusion prevention system (HIPS) is an intrusion prevention system that monitors and analyses the internals of a computing system as well as (in some cases) the network packets on its network interface for any malicious traffic or attacks targeted to the host and attempts to block it.

Penetration Testing

Penetration Testing
Hello Friends, Today i am going to teach you what is Penetration Testing, types of penetration Testing, What is to be Tested 


What is Penetration Testing ?

A penetration test, also known as pen test is a legal attempts at gaining access to your protected computer system or network often conducted by a third party organisation.

The purpose of the test is to identify security vulnerabilities and them attempt to successfully exploit them in order to gain some form of access to the network or computer system.

Penetration tests are carried out by using manual or automated software to safely compromise server endpoint, web application, wireless network, network device, mobile device and other potential risk points. if a tester is able to successfully exploit the vulnerabilities on a target system. they may attempt to use the vulnerable system to launch further attacks ? exploits on other internal resources, by getting deeper access and information via privilege escalation.

 A pen tester will generated a detail reported about successful exploited security vulnerabilities via penetration testing. The generated reports is then given to network & security administrators of organization to take necessary remediation steps for enhancing security by security and patching vulnerabilities.

The main purpose f penetration testing is to verify the impact on the resources and operation of the network in case of any hacking and how to minimize the affect of the same

Types of Penetration Tests

Penetration test can be classified into various types.

1. Network Services test 

This is the most common type of penetration test, Used for finding target system on a network, Finding loopholes / vulnerabilities in the operating system and network services and later exploiting them remotely. Networking service penetration test is done from a remote location through the internet targeting the organization's perimeter network. Sometime these tests are done from the local network to assess the security of the internal network from the perspective of the internal user.

2.Client-side Test

This kind of penetration test is used ti find and exploit vulnerabilities on client-side application like web browser, media player, etc. On a target network.

3. Web application test

This kind pf penetration test is used to find security vulnerabilities in the web server, web based application and programs on a target network 

4. Remote dial-up war dial

This kind of penetration test is used to discover modems. It ites to get connected to the modem by password guessing or brute forcing the target network.

5. Wireless security test

This kind of penetration test is used to discover wireless access points with in range and finding and exploiting the security weakness of access points on a target network.

6. Social Engineering test

This kind of Penetration test is used to gather sensitive information such as a password or other important and confidential data directly from a user. This is old style conning, trying to fool users into revealing their personal information. this type of test may be conducted over the phone or email, targeting-organization users or employee and evaluating security procedures and process.

________________________________Thank You________________________________

Saturday, 30 April 2016

SQL Injection

SQL Injection

Hello Friends, Today we are going to study SQL injection. What they are ? How they Work ? Who can Use them ?


What is SQL Injection ?

SQL injection attacks have been around for more than a decade and they remain popular with hackers.

SQL injection is an exploit used by hackers to steal data from Organizations. It is used to target web application Which generates Content based on user input.

Most Website have a database on the backend which Contains User data, Personal details of Customers, Credit card information, etc. A language called Structured Query Language (SQL) is used to enter and retrieve the data from the database as well as to manipulate it. This language is universal. Almost all database Support SQL, Including Oracle, MS SQL Server, My SQL.

Web application query the backend database to display custom content on the web page. The website presents a form to be filled in by users before serving them appropriate content. The web application assumes that users will provide simple text inputs to the form. Instead, hacker enter SQL queries in the form as input. If user input is not properly validated or sanitized, the SQL query gets executed. Hacker may get the whole database to dump itself on the web page, using a well crafted SQL query.

dynamic script language like PHP, .NET, ASP are susceptible to SQL injection attacks. The tools required by the hacker are very simple - some knowledge of SQL queries , a web browser and a little smarts for guessing table name and field names. there are also tools available online which automates most of the process for hacker.

This is one of the most popular attacks due to its sheer simplicity. Through SQL injection vulnerability has been known for a number of years, many website still remain susceptible.

Firewalls offers almost no protection against SQL injection. That is because all http data is passed on the wen application which in turn has "full access" to the backend database , so that it can present relevant data to the user. Nowadays , we have web application firewalls which provide some degree of protection. However , it is best to safeguard against this attacks by validating and sanitizing all user inputs before passing it to the database.

Effects of SQL Injection ?

An SQL Injection attacks can have a huge impact on the organization.

The hacker gets complete control of the server and all the data on that server. Also , Since this is an internal Server, an attacked server may be used to cpmpromise all the elements on the network. If the intension of the hacker is to steal confidential data , Them he goes about this attacks with great stealth. As we often see in the news orgnization seem to know nothing about the attacks , till all the credit card information of their customers is stolen and gone ! The attacks on target (Holiday season , 2014) is a classic example of this. This wasnahuge loss of face for target , and caused customer to stay away even after repeated assurance that not a data was lost.

Types Of SQL Injection Attacks

SQL injection attacks can be classified based on the injection mechanism.

1.Injection through User Input

This is the simplet form of an SQL injection attacks.SQL queries are sent as users inputs in forms submitted to web application.OIf no user input is done by the web application , the query is executed and the attacks gets underway.

2.Injection Through Cookies

web application store stae information on clients in the form of cookies. since these are stored on the user's system . malicious hacker can tamper with cokie and put SQL queries inside the cookie. When the hacker accesses the website again , the web application inadvertenly uses the tamperes cokkie to construct SQL queries which may have disastrous consequences. 

3.Injection Through Server Variables

Http headres , IP geadres , enviroment variable are all server variables and may be stored in databases for logging and determining usage statistics. It is quite easy for hacker to midify http headers and insert SQL queries in them. If these headers are stored without any sanitization or validation , then the attacks is triggered when the command is issued to log them to the database.

All the above are comsidered first order attacks which means that the attack is executed immediately on initial contact with the database.

4.Second Order SQL Injection Attacks

This is also knows as the stored SQL injection attacks. This attacks is not executed when the malicious inputs in initially entered in the database. It is triggered when the web application later tries to use that stored input by retrieving it with a legitimate query

The second order SQL injection attacks is inherently more complex than first order attacks as the sttacker has to guess how the input will be used later by the application. Web application usually trust data retrived from database and use it as"as is " with out validation> This is when the attack kicks in.

The best safeguard against SQL injection attacks is to validate all the input-whether from user or the database.

How to Ping a Pool of IP's

How to Ping a Pool of IP's

Hello Friends, Today i am Gonna show you How to Ping a Pool of IP's. Pinging IP's helps us to find Alive IP.


What Is IP address ?

An Internet Protocol address (IP address) is a numerical label assigned to each device (Computer, Printer) participating in a computer network that uses the Internet Protocol for communication. An IP address serves two principal functions: host or network interface identification and location addressing. Its role has been characterized as follows: "A name indicates what we seek. An address indicates where it is. A route indicates how to get there."



What is Ping ?

Ping is an basic Computer Program That allows a User to verify that a particular IP address and can accept requests.

Ping is Used Diagnostically to ensure that a host computer the user is trying to reach is actually Operating. Ping work by Sending an Internet Control Message Protocol (ICMP) Echo request to a specified interface on the Network and Waiting for a Reply.

Pre-requisite

  • Computer Installed with OS
  • Internet Connection (Broadband, Dial-up )
  • Angry IP Scanner (Tool)

Steps How to Ping Pool of IP's


1. Install the Tool "Angry IP Scanner". It is Free Available on Internet (No need of Crack Version)

2. Start the Angry IP Scanner With always Run this application as Administrator. Because it allows all permission to the application.


3. After Running application as Administrator u will Get this window.


4. Go to Tools menu & select Preferences.


5. Select Display and Check on the Alive port.

 This setting done only to see Alive Ip's

6. Apply settings by Clicking OK button.

7. Give the Pool Of IP's Which you want to check & click on Start button.


8. Wait for Some time it will show you result like this.


9. You will see the Result like this. Result shows you No. of Hosts scanned & How many of them are Alive.

________________________Thank You________________________

Friday, 29 April 2016

How To Surf Anonymously & Access Blocked Content

How To Surf Anonymously & Access Blocked Content

Hello Friends, Today I gonna Show you How to Surf Anonymously on Internet & Also How to Access Blocked or Censored Content on Internet. We are Going to use Tools to Surf anonymously on Internet.


How To Surf Anonymously

What is surfing Anonymously on Browser ?

Surfing Anonymously on Browser means Surfing on Internet without Showing user's identifiable Information like IP etc. This can be done with the help of Proxy server, Virtual Private Networks & other Anonymity Program such as "Tor".
Surf Anonymously


Pre-requisite


  • Computer Installed with OS
  • Internet Connection (BroadBand, Dial-up)
  • Cyberghost (Tool)

 What is Cyberghost ?

Cyberghost is a fast, simple & efficient way to protect our Online Privacy, Surf Anonymously and Access Blocked or Censored Content. It offers top-notch Security and Anonymity Without Being Complicated to use or Slowing down your Internet Connection.

Cyberghost is an application which allow you to encrypt your Internet Connection.

You Can Download The Cyberghost Tools link is given below.
-----------------------------------------------------------------------------------
-----------------------------------------------------------------------------------

Steps to Use Cyberghost


1. Go to the Link Given and Download the Cyberghost tool.

2.  After Download, Install the Cyberghost & Download the Required Component.

3. After Installation Go on www.whatismyipaddress.com & See your IP address.


Now you can See that my IP is "49.206.206.89" & I belong Hyderabad, India.

4. Start the Cyberghost Application You will see this window.


5. Now Click on Power button to Start the Tool.

6. After Starting the Tool you will Get this Window.


7. Now you can See that I got new IP address which is 199.115.115.209 & This IP belong to Pristina Serbia U.S.A.

8. Now Go Again to www.whatismyipaddess.com to see What is your IP address.


I got new IP address which is 199.115.115.209 & This IP belong to Pristina Serbia U.S.A.

How to Access Blocked Content & Censored Content




At Some Places Some website are blocked to Access. The restrictions that are actually dependent on your location. This is all Because of your server Geo location. For Eg If you are in China you can't Access the Facebook Because in China Facebook is blocked. The server from which you are Requesting to open Facebook is Located in China So you can't Access the Facebook If you want to Access it First you have to change your Server Use Cyberghost application to Get Connected to new Server Which is Located in Another Country & Than request the Server to open the Facebook you can Access the Facebook 

___________________________________Thank You___________________________________

Sunday, 17 April 2016

How to Become Hacker

How to Become Hacker

Today, I am Going to give you Knowledge about Who is Hacker and Skill's of Hacker

Who is a Hacker..???

The Hacker is the one who has good knowledge of computer. A Hacker is one who is able to gain the Unauthorized access to your Computer or your Privacy.

Types of hacker :-

1. Black Hat Hacker.
2. White Hat Hacker.
3. Grey Hat Hacker.


Skill's of Hacker :-

Hacker has good knowledge of all this module.

1. Networking.
2. Operating system.
3. Router.
4. Switch.
5. Applications 
6. Programming.
7. Scripting.
8. Database.