Monday, 16 December 2013

// // Leave a Comment

Lets walk through BackTrack

Welcome back, my Friends :) !  :) ! :) !
In one of my last article, I showed you how to How to install BackTrack on Your system. In this tutorial, I will walk you through BackTrack, giving you a tour of the most salient (important) features of Backtrack.


As you can see in the screenshot above, I've installed the most recent version of BackTrack, version 5 release 3 (generally referred to BackTrack 5r3). My install is the 64-bit version with the KDE interface, but the GNOME interface works just as well and has all the same features. 

The BackTrack Menu 

Similar to Windows start button, we have a button with the BackTrack icon in the lower left-hand corner along the lower panel.


When you click on it, it opens up a collection of Multy-nested menus just like Windows. Let’s go through each of them from bottom to top.


Level Menu 

The first menu we come to is titled "Leave." This is where we would go when we want to shutdown BackTrack.


The sub-menus here are all self-explanatory.
  • End Session - To Shut down the system
  • Lock Screen - Lock menu (Same as in windows)
  • Start a parallel session as a different user (Switch user)


Run Command 

The second menu we come to is titled "run Command" This is will help to open the Terminal (Command prompt )


Wine

We're going to skip over a few menu choices as they are not so important. 

The next thing in the list is Wine. It is help to run the windows application in Linux (We are going to discuss it in another post )  

Utilities Menu 


The next item is  "Utilities."


  • Akonaditray (a personal information manager)
  • Klipper (a clipboard tool)
  • KWrite (text editor similar to notepad),
  • Terminator (a way of managing multiple terminals)
  • WBarConf (a tool for managing your KDE bars)

The system Menu


The next menu we'll look at is titled "System," which contains applications. When we hover over System we see Airoscript-ng and Airoscript-ng GTK. These are scripts for using Aircrack-ng to hack wireless.( We are going to discuss about these in another post So keep touch with us )

We also see
  • Dolphin (a file manager similar to Windows Explorer)
  • EtherApe (a graphical network model)
  • Htop (a process viewer)
  • KinfoCenter (an information center about your computer, i.e. CPU, memory, DMA, etc)
Below KinfoCenter we find probably the most important utility in any Linux system:
  • Konsole (a terminal)
Any true hacker MUST become familiar with the terminal. For the remaining tools, we have:
  • KpackageKit (download packages)
  • KRandRTray (resizing windows)
  • System Monitor (self-explanatory)


The Internet Menu


Now we're going to jump up to the "Internet" menu and we can see EtherApe appears here again (it was also under "System").


Also, there's:
  • Firefox (web browser)
  • Konqueror (web browser)
  • Wicd (for connecting to Wi-Fi)
  • Zenmap (the network reconnaissance tool nmap overlaid with a nice GUI).

BackTrack
At the very top of the menu, we find the "BackTrack" menu! This is where we'll be spending most of our time as hackers. The BackTrack menu has shortcuts to the hundreds of hacking tools in BackTrack.



These tools are too numerous to list here, but as you can see BackTrack classifies them into the following:
  • Information Gathering
  • Vulnerability Assessment
  • Exploitation tools
  • Privilege Escalation
  • Maintaining Access
  • Reverse Engineering
  • RFID Tools
  • Stress Testing
  • Forensics
  • Reporting Tools
  • Services
  • Miscellaneous
Over the next several posts we'll examine each of these set of tools.
So that's the quick and dirty tour of BackTrack, my friends. In my coming posts, I'll show you how to use many of the best hacking tools in BackTrack, so keep coming back ! 

If you have any doubt feel free to ask in the comment section :) :) :) :) :)

Note: If you enjoyed this post, you might want to Follow our Twitter or become our Facebook fan.  You will get all the latest updates at both the places. And also don't be selfish Share this post with your friends
Read More

Sunday, 15 December 2013

// // Leave a Comment

Installing BackTrack5 step by step

On my last post i wrote about the installation of Backtrack but unfortunately it is not so clear to understand. so in this Post i am describing the step by step methords of installing Backtrack with the clear screenshots. If you have any doubtin this installation. Feel free to ask me in the comment section.

Requirements 
2. VMware workstation or Vmpalyer (Install any one in your Pc)

Step 1 : Create a Virtual machine 
Step 2 : Choose installer ISO 


Step 3 : Choose Linux as your guest Operating system and Ubuntu as version  




Step 4 : Give a name and location of your backtrack VM



Step 5 : Specify virtual hard drive space (Normaly GB is enough)


Step 5 : Then click finish from ready to create virtual machine on windows


hit enter to go boot screen then choose default boot text mode and hit enter

At this time you want to hit the enter 


Step 6 : After this Like the normal OS installation  

choose keyboard type and provide location info..
if you are installing just backtrack then go normally and erase and use entire disk..
or if you installing backtrack with other OS then specify partition accordingly ..









Wait until it finish the Installation (Nearly half an hour depend on your system)



Now You are successfully install the Backtrack in your system in our next post we will dealing with the tools with Backtrack :) Keep in  touch 


Note: If you enjoyed this post, you might want to Follow our Twitter or become our Facebook fan.  You will get all the latest updates at both the places. And also don't be selfish Share this post with your friends
Read More

Saturday, 14 December 2013

// // Leave a Comment

Getting started with BackTrack5

Welcome back, my Friends !
Today i am going to tell you about the BackTrack installation :)  

The Beginning of BackTrack

Hacking is a relatively new discipline. The Internet became commercialized in the mid-'90s, but it wasn't until the late-'90s that e-commerce sites were widely used. So, we can date hacking's birth to less than 15 years ago. Yes, hacking was happening at the very start of the Internet, but it didn't thrive until there was big money involved.
Back then, hackers developed their own tools and exploits. In the early part of the new millennium, hackers began to release their tools over the Web and share them with others. Several groups began to collect these tools and either make them available for download from one centralized repository, or began packaging them into a Linux-based CD or DVD.
Two of those groups, WHAX and The Auditor Security Group, merged and formed Offensive Security, which released BackTrack 1.0 in February 2006.

How to download and Install BackTrack 

Okay, enough history. Let's go head and download it.


Step 1 : Download BackTrack 

You can download the latest version of BackTrack in its website's downloads section. You do not need to actually register—just hit the "Download" button.
When you get to the download screen, this is what you should see:


  • Choose what version you want. I suggest the latest version (5 R3).
  • Choose what Linux interface you want, GNOME or KDE. This really is a matter of preference, but I'll be running KDe
  • Choose what architecture you're running (32- or 64-bit).
  • Choose what image type you want. If you're running VMWare, you should use that one. Otherwise, download the ISO.
  • Choose how you want to download it, either directly (like FTP) or through a torrent (peer-to-peer file sharing).
I will assume you filled in all of those fields and you're now downloading. Be patient, it could take awhile.

Step 2 : Burn a DVD

 From here on out, I will assume that you've downloaded an .ISO image.

Place a blank DVD in your DVD burner, go to your downloads directory, right-click the BackTrack .ISO file, and select burn a disk with either Windows Burner or any other proprietary burning software.

If you're using Windows Disc Image Burner like me, just hit "Burn"


Step 3 : Install backTrack


Once we have a successfully burned DVD, we can install BackTrack, but there are a few options:
  • Install it on a virtual machine in a virtaulization system like VMWare WorkstationVirtualBox, or Virtual PC. VMware is my favorite, but it's not free. VirtualBox comes in close second—and it is free.
  • Install it as a dual boot system (this is what I chose).
  • Install it as a portable OS onto an external hard drive, USB flash drive, or bootable DVD.
Place the DVD of BackTrack into your DVD tray and reboot your system. This will run BackTrack as a liveCD, which means that you can use it, but nothing is written to your hard disk. Everything runs in RAM. When you turn off your machine, everything is gone and no changes will have been made to your hard drive and system.
This might be a good way to test out BackTrack, but if you really want to become proficient with it—install it on your hard drive.
Installing straight to your hard drive lets you to create a dual-boot system. That means you can choose to boot into your regular OS system (in my case, Windows) or BackTrack. For your day-to-day work, you can boot into Windows, and then at night when you want to hack, you can boot into BackTrack.
When you're ready to install it onto your system, simply click on the BackTrack icon in the upper left-hand corner to install it on your hard drive. Then follow the wizard screens asking you for information about your system, etc.
You should then have a screen that looks like this!

Congratulations on your successful BackTrack install.
In my next article, I will take you on a brief tour of BackTrack, showing you the essentials of how to get around and find the hacking tools you need to Hack with a Style !
Read More

Friday, 13 December 2013

// // 4 comments

Difference between HTTP and HTTPS

With more people joining the internet scene each day it's important that it's security is.. well it has to be good. Of course everything can be hacked and that's the way hackers work. They know there IS a vulnerability but they don't don't know the rest. in this article i'll try to explain the big difference between HTTP and HTTPS  


On my last article i wrote about hacking a Facebook account which is not in HTTPS. 

HTTP
First HTTP:
HTTP means Hyper Text Transfer Protocol. Whenever we open up a website we use this protocol. The client asks the server to open communication on port 80. The server does that and opens port 80 and at the client side several random ports are opened.

Is HTTP secure?
HTTP is absolutely not secure. If someone would use a MITM (Man In The Middle) attack and search with Wireshark the attacker would easily gain access to your account.If you want to know how to do that just go trough my last post
Packet data send with HTTP is NOT encrypted. That's why it's so easy to crack into a session using MITM and Wireshark.

HTTPS

Then HTTPS
HTTPS is a combination of HTTP (Hyper Text Transfer Protocol) and SSL (Secure Socket Layer protocol) / TLS (Transport Layer Security). HTTPS is mainly used for internet banking, payment transactions and login pages.
It's goal is to provide maximum security for web pages that send secure information. HTTPS works the same as HTTP but it has encryption on top of it. HTTPS works like this:

data transmission by HTTPS
Is HTTPS secure?
HTTPS is secure. if someone would use the same method as with HTTP (MITM + Wireshark), then the attacker would only get Encrypted information as seen above

My Conclution


My conclusion would be that whenever you can USE HTTPS!!! HTTPS is secure and prevents hackers from hacking your precious Social media accounts. Of course there are ways around HTTPS as there are always ways to bypass security. But for now You'r accounts will be safe



Note: If you enjoyed this post, you might want to Follow our Twitter or become our Facebook fan.  You will get all the latest updates at both the places. And also don't be selfish Share this post with your friends

Read More
// // 6 comments

Spoofing Cookies to Hack Facebook

Welcome back, my friends !!! Today we'll be hacking Facebook profiles on your local network. You may think, "How is this useful ?? , nobody but me is using my network.! " Well, you can use this on other Wi-Fi networks that are available for free (open Wi-fi) and crack their precious Facebook profile!! it sounds good is in it ??

note: This only works if your target is actually browsing through Facebook over http (not https) at the time you're doing the hack.

How ??
We are going to use a well known method called "The cookie injection method." This might be far off from becoming "elite," but you need to get familiar with your Linux distribution first.

Step 1 : Get the right "stuff" 

For this hack, you'll need a few things. Nothing special, but you'll need this stuff. My best suggestion is that you first install BackTrack, Kali Linux, or Bugtraq because they have almost everything we need.
For this little trick, we'll need:
  • A working Linux distribution (preferably Kali, Backtrack or Bugtraq)
  • Wireshark (a packet sniffer)
  • Firefox (web browser)
  • Nmap (scanner)
  • Greasemonkey (addon for Firefox)
  • Cookie injector (script for Greasemonkey)*

Step 2 : Network scan

First, to actually connect to a target, we'll need an IP address. In order to get that, you'll need to do a network scan with Nmap. So go ahead and boot up your terminal and enter the following command: 


  • nmap -F 192.168.xx.xx/24
Note: If this doesn't work, use 10.0.x.x/24 instead.

This command will scan your network for any IP addresses connected to it. The -F gives the console the instruction to use "Fast mode." If done correctly, you should see something like this:

That's how your Nmap scan should look like.


Step 3 : Starting the Man-In-Middle Attrck


Now we're going to start a man-in-the-middle attack, MITM for short.
An MITM attack is an attack were we spoof our MAC address so that when a server/responding person sends a message to the other, he won't be receiving that message, but he will receive messages that we send, as we're the Man in the middle.
This might help you understand:

A man in the middle attack!


Starting the attack 

To start, enter the following command in a NEW terminal window:
  • sudo echo 1 >> /proc/sys/net/ipv4/ip_forward
This will forward your IP address. Now we're starting the MITM by opening a NEW terminal window and entering this command:
  • sudo arpspoof -i [Interface] -t [target] [default gateway]

If you don't know your interface and default gateway, start a new terminal and enter: ifconfig.
This is the result form the arpspoof.

Open (once again ) a new terminal window and enter the following command:

  • sudo arpspoof -i [interface] -t [default gateway] [target]

Another result from the arpspoof!

Note: After you entered both the arpspoof commands DON'T CLOSE THE TERMINALS.

Step 4 : Firefox and Wireshark (Almost finished)

We need a few more things in order to complete this hack!
First install Firefox,
then Greasemonkey and the cookie injector script. Then, install Wireshark, which you can do by entering this command into a terminal window:
  • sudo apt-get install wireshark
After that, open up a Wireshark session (open a terminal and enter sudo Wireshark as command). Select your interface and start capturing. At the top, you should see an input box where you can add filters. Now enter this filter:
  • http.cookie contains DATR
Now you should get a list in Wireshark. Search for a cookie that contains the text GET. Locate it, click on it with the left mouse button, select copy, select bytes, select printable text only.
Wireshark result. The one you need is in the black circle.

Now go to Wireshark and go to Facebook. Make sure you're NOT logged in. If you are, go to settings and delete all the cookies. Then go back to the Facebook log-in page, press [ALT]+C, and paste the cookie. Press OK andrefresh the page.

Here you can clearly see the cookie injector script input box.

If my magic worked, you should see the main Facebook timeline. If not, then you've done something wrong. Check the steps one again and try again. Don't Give it up :)


This hack may seem advanced, but it's actually really easy. Once you break down all the steps, it's a piece of cake! :D
Now that you've done this, it should be clear that Facebook security isn't very strong :P 

In my next post i am going to write about How yo Hide Ip and other simple stuffs so Don't miss them 

Note: If you enjoyed this post, you might want to Follow our Twitter or become our Facebook fan.  You will get all the latest updates at both the places. And also don't be selfish Share this post with your friends
Read More