Check who Visited Your facebook Account
Check who Visited Your facebook Account
Hello Friends Here we are Presenting You A working Trick to Check Who visited your Facebook Profile...!
I know all of us Sometimes Wish that , facebook must Have Provided the Feature by which we could have seen our facebook profile Visitors...!
I wont Take too long... Just Follow the Steps Given Below...!
we are presenting this trick in really Short Way...!
we are presenting this trick in really Short Way...!
Now here we found who recently visited your profile.
Follow below steps for get to know your FB recent visitors.
Follow below steps for get to know your FB recent visitors.
Step 1) Go to your Facebook Profile Page.
Step 2) Now Press Ctrl + U from your keyboard for see source code of your profile page.
Step 3) Now press Ctrl + F from your keyboard to open search box.
Step 4) Now search this code {"list":
Step 5) You find some Facebook Profile Ids are like shown below. Click on example image for zoom.
Step 6) There are some Facebook Profile Ids of your friends who visited recently.Facebook ID may are
Step 7) The first one ID's are showing visits the most number of time.
Step 8) Now if your want to findout, Open a new tab Enter below link :www.facebook.com/Facebook Profile Id
For Example : www.facebook.com/100001257992988
Hacking Essential Keywords, U need to Know
U need to know this KeyTerms Before Reading any Tutorial:
Hackers KeyTerms-:
- DDOS: Distributed denial of service
- FUD: Fully undetectable
- Malware: Malicious software
- RAT :Remote administration tool
- SQL: Structured query language
- Skid: Script kiddie
- SSH : Secure shell
- VPN : Virtual private network
- VPS: Virtual private service.
- XSS/CSS: Cross site scripting
Hacking Terms and Definations-:
Hackers Dictionary
If you are new to hacking I recommend u all to read this post
- Algorithm - Series of steps or Code which specifying which actions to take in which order.
- •ANSI Bomb - ANSI.SYS key-remapping commands consist of cryptic-looking text that specifies, using ansi numeric codes to redefine keys.
- •Back Door - Something that a hacker leaves behind on a system in order to be able to get back in at a later time.
- •Binary - A numbering system in which there are only two possible values for each digit: 0 and 1.
- •Black Hat - A hacker who performs illegal actions to do with hacking online. (Bad guy, per se)
- •Blue Hat - A blue hat hacker is someone outside computer security consulting firms who is used to bug test a system prior to its launch, looking for exploits so they can be closed. Microsoft also uses the term BlueHat to represent a series of security briefing events.
- •Bot - A piece of malware that connects computer to an attacker commonly using the HTTP or IRC protocal to await malicous instructions.
- •Botnet - Computers infected by worms or Trojans and taken over by hackers and brought into networks to send spam, more viruses, or launch denial of service attacks.
- •Buffer Overflow - A classic exploit that sends more data than a programmer expects to receive. Buffer overflows are one of the most common programming errors, and the ones most likely to slip through quality assurance testing.
- •Cracker - A specific type of hacker who decrypts passwords or breaks software copy protection schemes.
- •DDoS - Distributed denial of service. Flooding someones connection with packets. Servers or web-hosted shells can send packets to a connection on a website usually from a booter.
- •Deface - A website deface is an attack on a site that changes the appearance of the site or a certain webpage on the site.
- •Dictionary Attack - A dictionary attack is an attack in which a cyber criminal can attempt to gain your account password. The attack uses a dictionary file, a simple list of possible passwords, and a program which fills them in. The program just fills in every single possible password on the list, untill it has found the correct one. Dictionary files usually contain the most common used passwords.
- •DOX - Personal information about someone on the Internet usualy contains real name, address, phone number, SSN, credit card number, etc.
- •E-Whore - A person who manipulates other people to believe that he/she is a beautiful girl doing cam shows or selling sexual pictures to make money.
- •Encryption - In cryptography, encryption applies mathematical operations to data in order to render it incomprehensible. The only way to read the data is apply the reverse mathematical operations. In technical speak, encryption is applies mathematical algorithms with a key that converts plaintext to ciphertext. Only someone in possession of the key can decrypt the message.
- •Exploit - A way of breaking into a system. An exploit takes advantage of a weakness in a system in order to hack it.
- •FUD - Fully undetectable, can be used in many terms. Generally in combination with crypters, or when trying to infect someone.
- •Grey Hat - A grey hat hacker is a combination of a Black Hat and a White Hat Hacker. A Grey Hat Hacker may surf the internet and hack into a computer system for the sole purpose of notifying the administrator that their system has been hacked, for example. Then they may offer to repair their system for a small fee.
- •Hacker (definition is widely disputed among people...) - A hacker is someone who is able to manipulate the inner workings of computers, information, and technology to work in his/her favor.
- •Hacktivist - A hacktivist is a hacker who utilizes technology to announce a social, ideological, religious, or political message. In general, most hacktivism involves website defacement or denial-of-service attacks.
- •IP Address - On the Internet, your IP address is the unique number that others use to send you traffic.
- •IP Grabber - A link that grabs someone's IP when they visit it.
- •Keylogger - A software program that records all keystrokes on a computer's keyboard, used as a surveillance tool or covertly as spyware.
- •Leach - A cultural term in the warez community referring to people who download lots of stuff but never give back to the community.
- •LOIC/HOIC - Tool(s) used by many anonymous members to conduct DDoS attacks. It is not recommended to use these under any circumstances.
- •Malware - Software designed to do all kinds of evil stuff like stealing identity information, running DDoS attacks, or soliciting money from the slave.
- •Neophyte - A neophyte, "n00b", or "newbie" is someone who is new to hacking or phreaking and has almost no knowledge or experience of the workings of technology, and hacking.
- •smith - Somebody new to a forum/game.
- •OldFag - Somebody who's been around a forum/game for a long time.
- •Packet - Data that is sent across the Internet is broken up into packets, sent individually across the network, and reassembled back into the original data at the other end.
- •Phreak - Phone Freaks. Hackers who hack cell phones for free calling. Free Long distance calling. Etc.
- •Phreaking - The art and science of cracking the phone network.
- •Proxy - A proxy is something that acts as a server, but when given requests from clients, acts itself as a client to the real servers.
- •Rainbow Table - A rainbow table is a table of possible passwords and their hashes. It is way faster to crack a password using rainbow tables then using a dictionary attack (Bruteforce).
- •Remote Administration Tool - A tool which is used to remotely control (an)other machine(s). These can be used for monitoring user actions, but often misused by cyber criminals as malware, to get their hands on valuable information, such as log in credentials.
- •Resolver - Software created to get an IP address through IM (instant messenger, like Skype/MSN) programs.
- •Reverse Engineering - A technique whereby the hacker attempts to discover secrets about a program. Often used by crackers, and in direct modifications to a process/application.
- •Root - Highest permission level on a computer, able to modify anything on the system without restriction.
- •Rootkit (ring3 ring0) - A powerful exploit used by malware to conceal all traces that it exists. Ring3 - Can be removed easily without booting in safemode. Ring0 - Very hard to remove and very rare in the wild, these can require you to format, it's very hard to remove certain ring0 rootkits without safemode.
- •Social Engineer - Social engineering is a form of hacking that targets people's minds rather than their computers. A typical example is sending out snail mail marketing materials with the words "You may already have won" emblazoned across the outside of the letter. As you can see, social engineering is not unique to hackers; it's main practitioners are the marketing departments of corporations.
- •Script Kiddie - A script kid, or skid is a term used to describe those who use scripts created by others to hack computer systems and websites. Used as an insult, meaning that they know nothing about hacking.
- •Shell - The common meaning here is a hacked web server with a DoS script uploaded to conduct DDoS attacks via a booter. OR A shell is an script-executing unit - Something you'd stick somewhere in order to execute commands of your choice.
- •Spoof - The word spoof generally means the act of forging your identity. More specifically, it refers to forging the sender's IP address (IP spoofing). (Spoofing an extension for a RAT to change it from .exe to .jpg, etc.)
- •SQL Injection - An SQL injection is a method often used to hack SQL databases via a website, and gain admin control (sometimes) of the site. You can attack programs with SQLi too.
- •Trojan - A Trojan is a type of malware that masquerades as a legitimate file or helpful program with the ultimate purpose of granting a hacker unauthorized access to a computer.
48•Warez - Software piracy
49•White Hat - A "white hat" refers to an ethical hacker, or a computer security expert, who specializes in penetration testing and in other testing methods to ensure the security of a businesses information systems. (Good guy, per se).this are Cyber Police.
50•Worm - Software designed to spread malware with little to no human interaction.Zero Day Exploit - An attack that exploits a previously unknown vulnerability in a computer application, meaning that the attack occurs on "day zero" of awareness of the vulnerability. This means that the developers have had zero days to address and patch the vulnerability.
If you liked the post , please share it ur friends..
Like us on Facebook.
U may like reading SPY on Android.
A KickStart Guide to PenTesting
A KickStart Guide to Pen-Testing:
What is a penetration test?
What do u mean by penetration testing? Penetration testing, Commonly called "pentesting", "pen testing", or "security testing",is the practice of attacking your own or your clients’ IT systems in the same way a Cracker do to find holes. Holes are the Security holes , they may also be called as Bug. Of course, you do this without actually harming the network. The person carrying out a penetration test is called a penetration tester or pen-tester. the act of such test is called penetration testing.
Let’s make one thing crystal clear: Penetration testing requires that you get permission from the person who owns the system or the one whos system you are trying to Pen-test into...!. Otherwise, you would be termed as hacking the system, which is illegal in most countries – and trust me, you don’t look good in an orange jump suit, or a white Jailsuit.
In other words: The difference between penetration testing and hacking is whether you have the system owner’s permission. If you want to do a penetration test on someone else's system, we highly recommend that you get written permission. In this case, asking first is definitely better than apologizing later!
You can become a penetration tester at home by testing your own server and later make a career out of it.
Security research :
Vulnerabilities are typically found by security researchers, which is a posh term for smart people who like to find flaws in systems and break them.
Like penetration testing, security research can be used for good and evil. Some countries don’t make the distinction and outlaw security research completely, so make sure you check your country’s legislation before you start researching and especially before you publish any research.
A Payload :
A payload is the piece of software that lets you control a computer system after it’s been exploited. The payload is typically attached to and delivered by the exploit. Just imagine an exploit that carries the payload in its backpack when it breaks into the system and then leaves the backpack there. Yes, it’s a corny description, but you get the picture.
Metasploit’s most popular payload is called Meterpreter, which enables you to do all sorts of funky stuff on the target system. For example,
If you’re feeling particularly bad-ass, you can even turn on a laptop’s webcam and be a fly on the wall. you can upload and download files from the system, take screenshots, and collect password hashes. You can even take over the screen, mouse, and keyboard to fully control the computer.
A Vulnerability :
It is a security hole in a piece of software, hardware or operating system that provides a potential angle to attack the system. A vulnerability can be as simple as weak passwords or as complex as buffer overflows or SQL injection vulnerabilities.
To test if you have any vulnerabilities in your systems, you typically use a vulnerability management solution, also known as a vulnerability scanner or vulnerability assessment solution. If you would like to get your hands on a free vulnerability scanner, try NeXpose Community Edition, one of Metasploit’s sister projects.
Exploit :
To take advantage of a vulnerability, you often need an exploit, a small and highly specialized computer program whose only reason of being is to take advantage of a specific vulnerability and to provide access to a computer system. Exploits often deliver a payload to the target system to grant the attacker access to the system.
The Metasploit Project host the world’s largest public database of quality-assured exploits.
Even the name Metasploit comes from the term “exploit”.Think of it as an abstraction layer (“Meta”) for exploits (abbreviated “sploits”). Get it?
Liked the article? , Like us on Facebook.
Bookmark us.Keep visiting for more of such Posts.
Liked the article? , Like us on Facebook.
Bookmark us.Keep visiting for more of such Posts.
U Think that Social Network wasting your Time...! Change It...!
How to Use Social Network
Effectively: Enhance ur Time
Productivity
Like Twitter, Instagram and many other social media platforms of its type, Facebook is often vilified for being a major source of procrastination and fostering time-wasting behaviors. And let’s be honest – it’s not entirely untrue! How many hours have we wasted, shamelessly spying on our friends’ and relatives’ lives (oh, is that just me, then?) or falling down the mesmerising rabbit hole that is Farm Ville? or CandyCrush,or Poker Watever it may be, You know the drill: you open a browser, innocently intending to double-check the date of that hot event you were invited to, and bam - that’s it, four hours of your life, gone! It’s okay – you’re not alone and happily, there are ways of not only minimizing Facebook’s inherent time-suck effect, but also (and this is the exciting part) using this popular social media network as a means to educate yourself, get inspired and meet incredible people. Read on to discover 5 tips that will change the way you use Facebook – forever!
1. Unsubscribe Time wasters.
Often, the reason why we waste so much time on Facebook is simply because we follow too many people and subscribe to too many Pages! With an average of 250 Facebook friends per U.S. female and an average of 1,500 posts eligible to appear in a user’s feed every day (data from Digital Media Ramblings), it isn’t hard to see why so many of us get sucked into the black hole of social media procrastination. The simplest solution to this predicament is to cut down on the number of people in your friends’ list and unsuscribe from the Pages that don’t add value to your Facebook experience. Consider this: how many of your Facebook friends do you actually speak with on a regular basis? Whose status updates do you find yourself repeatedly ignoring? Which posts do you systematically scroll past when they pop up in your Timeline? Ask yourself: is it worth keeping these people and Pages around if you don’t enjoy what they have to offer anymore? If the answer to that question is no, then cut them out! and Subscribe only the fruitefull and Inspiring Ones!
2. Use Filter
Ever wanted to filter out an overzealous friend or relative’s Facebook noise without hurting their feelings by unfriending them? You can! All it takes is a simple, three-step process: 1) locate a post from this person in your Timeline and click the little arrow in the top-right corner. This will cause a drop-down menu to appear. 2) Click “I don’t want to see this.” When you do this, that specific post will be hidden from your Timeline. 3) If you want to take it further and radically diminish the number of posts from that person, click “See less from [name of the person]“. This will ensure that you see fewer posts from that person, without removing them from your friends’ list! [ Dont try It on Our Page... ;) ;) ]
Most Imp: You can do this with Groups and Pages, too! All you need to do is follow exactly the same three steps. and I bet U ,u will have Saved Enough of ur usefull time!
3. Learn.
Now that we’ve learned how to minimize distractions and noise on our Timelines, it’s time to look at some of the positive aspects of the social network! As we primarily use Facebook for staying in touch with our friends and relatives and keeping abreast of the latest developments in each other’s lives, we don’t necessarily realize that Facebook is a brilliant learning tool, too. Indeed, whether you’re trying to learn a new language, beef up your professional skills or simply be more inspired and motivated on a daily basis, chances are there’s a Page for that! Example we have page at fb.com/easyhackblog. which enables all people to open their Views on New way of Computer Security, and tricks. and as everyone of us Knows this is the most usefull topic to learn in The Digital World that today we are living in!
Bonus: Now that you have either unfollowed or filtered the notifications of the people and Pages you’re no longer interested in, the content from the Pages you do want to see will be much more prominent on your Timeline!
4. Get in them
OfCource! You can learn and get inspired on Facebook, but guess what? You can also meet interesting people and network with them! Just as there is a Page for your every learning need, there is likely also a Group, too. Consider this: if you’re a solo entrepreneur, it can be difficult to find like-minded people in your entourage and mingle with others who get what you’re going through. Joining a Facebook Group or Page like EasyHack where people like you hang out is a brilliant way to get advice and support on issues that might trouble you, or simply make new friends! Bonus: If you’re an online business owner, Facebook Groups are a great place to get feedback on your products or services and to find prospective clients! Think about it: these are all people who share the same issues and predicaments. They likely also operate in the same industry as you. Therefore, they are probably the best equipped to give you advice on what you’re offering, and who knows – they might be so into it that they want a piece of it, too!
5. Share and support.
Whether you have ideas of your own that you think would be helpful to others, or a business that you would like to get more eyeballs on, Facebook is a brilliant option for sharing your views or your products with the world! If you’re operating on a non-profit basis, create a Page that your friends, relatives and fans can follow to get the latest news that you want to send out. This makes life easier for both you and for them: for you, because it saves you the trouble of having to contact people separately about a given topic or event; for them, because all the people who follow your Page can get the information they need in one place. Easy! If you’re a business owner and are willing to spend a little time and money, Facebook can be an excellent way to promote your products and build a solid online reputation. The social network’s advertising system is extremely well thought-out, and will enable you to get your posts out to the right audience for a reasonable price. Having a company Page will also give your clients and fans a rendez-vous point to keep up to date on your latest news. In short: Facebook can work hard for you, if you let it: simply filter out the content that doesn’t interest you and follow the Pages and Groups that are useful to you! Don’t be afraid to take advantage of its many perks for your personal life and your business.
Share this article if u liked it friends!
Liked this article? Like us on Facebook,
or Follow us on Twitter ,
Leave ur Comments Guys;
Monday, December 29
Nmap Tutorial: How to use Nmap
How to use Nmap
This tutorials Require: Backtrack letest(5), Pen-testing Lab, and Patience
This will be the first tutorial that will give a basic walkthrough of a penetration test. There are many tools on the backtrack distro that will not be covered in these, but if any readers have any questions about other tools, message me. This is first step of information gathering, it will focus on finding live hosts on the network, port scanning and versions of software that is running on those ports.
Let's begin..
For this tutorial, you will need to have knowledge of google hacking, and the concept of information gathering. We are going to jump right in and skip the rest of the introduction. If this were a true pentest we would start by using google to gather as much information as we can about our target organization. Queries that are usefull can be found in Johnny Long's GHDB, you task is to perform research of the GHDB and practice the queries on your own. Since we already know our target we are going to start gathering as much information as we can about target machines on the network.
For this exercise we will use the following tools: Nmap
Over the years Nmap has had many different features added, one of the more recent is the vulnerability checking modules. If you do not know about these, go to google and research them. One thing about this tutorial is to get you to learn to use google to perform your own research so there will be some steps that I will tell you to research on your own.
The first thing we want to do is find live hosts on the network, this can be achieved through the use of Nmap. With this command we will also check the service version of each open port. There are many other commands that are built into Nmap, which can be found using the Nmap -h command or just typing Nmap. Ok here we go..
We are on the 192.168 network.
nmap -sV 192.168.1.1/24
This command will scan all 254 hosts on the network and enumerate open ports along with the version of the software running on that port. The network I am using only has 2 machines on it, I did this to shorten the tutorials. Here are the results:
Nmap scan report for 192.168.1.2
Host is up (0.0080s latency).
Not shown: 995 filtered ports
PORT STATE SERVICE VERSION
135/tcp open msrpc Microsoft Windows RPC
139/tcp open netbios-ssn
445/tcp open netbios-ssn
912/tcp open vmware-auth VMware Authentication Daemon 1.0 (Uses VNC, SOAP)
5357/tcp open http Microsoft HTTPAPI httpd 2.0 (SSDP/UPnP)
MAC Address: 00:15:25:12:B7:7F (##### Incorporation)
Service Info: OS: Windows
Nmap scan report for 192.168.1.14
Host is up (0.022s latency).
Not shown: 996 filtered ports
PORT STATE SERVICE VERSION
20/tcp closed ftp-data
21/tcp open ftp vsftpd 2.0.8 or earlier
22/tcp open ssh OpenSSH 4.7 or earlier
80/tcp open http Apache httpd 2.2.4 ((Fedora))
MAC Address: 00:21:2F:36:D2:E2 (Phoebe Micro)
If we had a larger network, the switch -p could be used to specify which ports to look for like so:
nmap -sV 192.168.1.1/24 -p 21,80,445
One thing that I recommend is to always, I mean always scan the network in UDP mode and look for open SNMP ports. Older versions of SNMP are vulnerable to attack since they use the strings public and private for logins. If you do not know what SNMP or the SNMP ports are, google is your friend.
To perform this kind of information gathering you would use the -sU switch to tell nmap to scan the udp ports. So the command would look like so:
nmap -sU 192.168.1.1/24 -p161, 162
We specify ports 161 and 162 since these are the ports that snmp runs on.
Nmap scan report for 192.168.1.14
Host is up (0.022s latency).
Not shown: 996 filtered ports
PORT STATE SERVICE VERSION
161/udp open snmp snmp (protocol 1.0)
MAC Address: 00:21:2F:36:D2:E2 (Phoebe Micro)
When runnin udp scans remember that the udp protocol does not verify the connection so it is a good idea to verify the port is actually open by connecting with netcat.
Lets jump into some of the scripts that can be used to check for vulnerabilities. To get help with a specific script you would just type:
nmap --script-help script name
This will give you output about the script and what it does.
The first scripts we will use is the smb scripts since we have a server reporting an smb port 445 open.
nmap -sS --script smb-os-discovery 192.168.1.14
nmap -sS --script smb-check-vulns 192.168.1.14
nmap -sS --script smb-enum-users 192.168.1.14
nmap -sS --script smb-enum-shares 192.168.1.14
As you can see I added a -sS to the command, this will cause nmap to run in stealth mode. Also I would like to note that in a way i'm starting to set up for the second part with the enumeration scripts. Since this server is not a microsoft server, there are no smb shares running, only samba. The above example was to give you a good idea of the syntax and how the commands work. Let's jump to a microsoft machine so you can see some output.
nmap -sS --script smb-enum-shares 192.168.1.2
Host script results:
| smb-enum-shares:
| ADMIN$
| Anonymous access:
| Current user ('guest') access:
| C$
| Anonymous access:
| Current user ('guest') access:
| E$
| Anonymous access:
| Current user ('guest') access:
| IPC$
| Anonymous access: READ
| Current user ('guest') access: READ
| Current user ('guest') access: READ
| movies
| Anonymous access:
| Current user ('guest') access: READ
| print$
| Anonymous access:
|_ Current user ('guest') access: READ
Nmap done: 1 IP address (1 host up) scanned in 8.37 seconds
nmap -sS --script smb-check-vulns 192.168.1.2
Host script results:
| smb-check-vulns:
| MS08-067: NOT VULNERABLE
| Conficker: Likely CLEAN
| regsvc DoS: CHECK DISABLED (add '--script-args=unsafe=1' to run)
| SMBv2 DoS (CVE-2009-3103): CHECK DISABLED (add '--script-args=unsafe=1' to r
un)
| MS06-025: CHECK DISABLED (remove 'safe=1' argument to run)
|_ MS07-029: CHECK DISABLED (remove 'safe=1' argument to run)
nmap -sS --script smb-os-discovery
Host script results:
| smb-os-discovery:
| OS: Windows 7 Professional 7601 Service Pack 1 (Windows 7 Professional 6.1)
| Name: MSHOME\gh0s7
|_ System time: 2012-06-25 19:41:16 UTC-7
As you can see these scripts are pretty useful, especially when you dont want to make a lot of noise on the network. Other scripts that are not covered in this tutorial can be located on the nmap website located here: http://nmap.org/book/nse-usage.html#nse-categories
Let's see what else there is, ah yes, one of my favorites! Anonymous ftp!
This command will check for anoymous ftp logins on the target machine. Since none of our target machines have anonymous logins enabled there will be no output from the scan, but here is the code.
nmap -sS --script ftp-anon 192.168.1.2 192.168.1.14
Last but not least there is a switch that will allow you to run all scripts and many other options, here is the description from the help menu: Enable OS detection, version detection, script scanning, and traceroute
So to run this will be the following command: nmap -A 192.168.1.2
You can also add different scan types to the beggining of the line like so:
nmap -sS -A 192.168.1.2
There are also ways to add other arguments to the scripts, and even create your own. Refer to the above website for techniques to perform these tasks.
So now that we have gathered a list of machines on the network and the open ports, lets move on to Next we want to verify that the ports are actually open. The reason for this is that sometimes machines give false results, especially UDP ports.
The next tool we will use is one of my favorite tools, netcat. If we open a terminal and type nc. We will see the netcat help menu. Next we will run through the ports and try to connect with basic netcat commands: nc -v 192.168.1.2 445. This will launch netcat and connect to port 445. You may have to hit enter a couple times to get it to respond. You shouldn't see port closed by remote host. If it is then there are many things that could be closing the port. Be sure to document all open ports that have been verified. In up coming tutorials we will be using netcat to perform reverse connections back to our attack machine from the linux server. This will conclude the first tutorial, I will be posting the next tutorial in a few days.
Quick Bash Ping Sweep Script:
#!/bin/bash
for $endIp in $(seq 1 254); do
ping -c 1 192.168.1.$endIp |grep "bytes from" | cut -d " " -f 4 | cut -d -f 1 &
And its Done!!!
Bookmark us for more such Tutorials!
Like us on Facebook.
Follow us on G+;
Follow us on twitter...!
Leave ur Comments Friends;
This tutorials Require: Backtrack letest(5), Pen-testing Lab, and Patience
This will be the first tutorial that will give a basic walkthrough of a penetration test. There are many tools on the backtrack distro that will not be covered in these, but if any readers have any questions about other tools, message me. This is first step of information gathering, it will focus on finding live hosts on the network, port scanning and versions of software that is running on those ports.
Let's begin..
For this tutorial, you will need to have knowledge of google hacking, and the concept of information gathering. We are going to jump right in and skip the rest of the introduction. If this were a true pentest we would start by using google to gather as much information as we can about our target organization. Queries that are usefull can be found in Johnny Long's GHDB, you task is to perform research of the GHDB and practice the queries on your own. Since we already know our target we are going to start gathering as much information as we can about target machines on the network.
For this exercise we will use the following tools: Nmap
Over the years Nmap has had many different features added, one of the more recent is the vulnerability checking modules. If you do not know about these, go to google and research them. One thing about this tutorial is to get you to learn to use google to perform your own research so there will be some steps that I will tell you to research on your own.
The first thing we want to do is find live hosts on the network, this can be achieved through the use of Nmap. With this command we will also check the service version of each open port. There are many other commands that are built into Nmap, which can be found using the Nmap -h command or just typing Nmap. Ok here we go..
We are on the 192.168 network.
nmap -sV 192.168.1.1/24
This command will scan all 254 hosts on the network and enumerate open ports along with the version of the software running on that port. The network I am using only has 2 machines on it, I did this to shorten the tutorials. Here are the results:
Nmap scan report for 192.168.1.2
Host is up (0.0080s latency).
Not shown: 995 filtered ports
PORT STATE SERVICE VERSION
135/tcp open msrpc Microsoft Windows RPC
139/tcp open netbios-ssn
445/tcp open netbios-ssn
912/tcp open vmware-auth VMware Authentication Daemon 1.0 (Uses VNC, SOAP)
5357/tcp open http Microsoft HTTPAPI httpd 2.0 (SSDP/UPnP)
MAC Address: 00:15:25:12:B7:7F (##### Incorporation)
Service Info: OS: Windows
Nmap scan report for 192.168.1.14
Host is up (0.022s latency).
Not shown: 996 filtered ports
PORT STATE SERVICE VERSION
20/tcp closed ftp-data
21/tcp open ftp vsftpd 2.0.8 or earlier
22/tcp open ssh OpenSSH 4.7 or earlier
80/tcp open http Apache httpd 2.2.4 ((Fedora))
MAC Address: 00:21:2F:36:D2:E2 (Phoebe Micro)
If we had a larger network, the switch -p could be used to specify which ports to look for like so:
nmap -sV 192.168.1.1/24 -p 21,80,445
One thing that I recommend is to always, I mean always scan the network in UDP mode and look for open SNMP ports. Older versions of SNMP are vulnerable to attack since they use the strings public and private for logins. If you do not know what SNMP or the SNMP ports are, google is your friend.
To perform this kind of information gathering you would use the -sU switch to tell nmap to scan the udp ports. So the command would look like so:
nmap -sU 192.168.1.1/24 -p161, 162
We specify ports 161 and 162 since these are the ports that snmp runs on.
Nmap scan report for 192.168.1.14
Host is up (0.022s latency).
Not shown: 996 filtered ports
PORT STATE SERVICE VERSION
161/udp open snmp snmp (protocol 1.0)
MAC Address: 00:21:2F:36:D2:E2 (Phoebe Micro)
When runnin udp scans remember that the udp protocol does not verify the connection so it is a good idea to verify the port is actually open by connecting with netcat.
Lets jump into some of the scripts that can be used to check for vulnerabilities. To get help with a specific script you would just type:
nmap --script-help script name
This will give you output about the script and what it does.
The first scripts we will use is the smb scripts since we have a server reporting an smb port 445 open.
nmap -sS --script smb-os-discovery 192.168.1.14
nmap -sS --script smb-check-vulns 192.168.1.14
nmap -sS --script smb-enum-users 192.168.1.14
nmap -sS --script smb-enum-shares 192.168.1.14
As you can see I added a -sS to the command, this will cause nmap to run in stealth mode. Also I would like to note that in a way i'm starting to set up for the second part with the enumeration scripts. Since this server is not a microsoft server, there are no smb shares running, only samba. The above example was to give you a good idea of the syntax and how the commands work. Let's jump to a microsoft machine so you can see some output.
nmap -sS --script smb-enum-shares 192.168.1.2
Host script results:
| smb-enum-shares:
| ADMIN$
| Anonymous access:
| Current user ('guest') access:
| C$
| Anonymous access:
| Current user ('guest') access:
| E$
| Anonymous access:
| Current user ('guest') access:
| IPC$
| Anonymous access: READ
| Current user ('guest') access: READ
| Current user ('guest') access: READ
| movies
| Anonymous access:
| Current user ('guest') access: READ
| print$
| Anonymous access:
|_ Current user ('guest') access: READ
Nmap done: 1 IP address (1 host up) scanned in 8.37 seconds
nmap -sS --script smb-check-vulns 192.168.1.2
Host script results:
| smb-check-vulns:
| MS08-067: NOT VULNERABLE
| Conficker: Likely CLEAN
| regsvc DoS: CHECK DISABLED (add '--script-args=unsafe=1' to run)
| SMBv2 DoS (CVE-2009-3103): CHECK DISABLED (add '--script-args=unsafe=1' to r
un)
| MS06-025: CHECK DISABLED (remove 'safe=1' argument to run)
|_ MS07-029: CHECK DISABLED (remove 'safe=1' argument to run)
nmap -sS --script smb-os-discovery
Host script results:
| smb-os-discovery:
| OS: Windows 7 Professional 7601 Service Pack 1 (Windows 7 Professional 6.1)
| Name: MSHOME\gh0s7
|_ System time: 2012-06-25 19:41:16 UTC-7
As you can see these scripts are pretty useful, especially when you dont want to make a lot of noise on the network. Other scripts that are not covered in this tutorial can be located on the nmap website located here: http://nmap.org/book/nse-usage.html#nse-categories
Let's see what else there is, ah yes, one of my favorites! Anonymous ftp!
This command will check for anoymous ftp logins on the target machine. Since none of our target machines have anonymous logins enabled there will be no output from the scan, but here is the code.
nmap -sS --script ftp-anon 192.168.1.2 192.168.1.14
Last but not least there is a switch that will allow you to run all scripts and many other options, here is the description from the help menu: Enable OS detection, version detection, script scanning, and traceroute
So to run this will be the following command: nmap -A 192.168.1.2
You can also add different scan types to the beggining of the line like so:
nmap -sS -A 192.168.1.2
There are also ways to add other arguments to the scripts, and even create your own. Refer to the above website for techniques to perform these tasks.
So now that we have gathered a list of machines on the network and the open ports, lets move on to Next we want to verify that the ports are actually open. The reason for this is that sometimes machines give false results, especially UDP ports.
The next tool we will use is one of my favorite tools, netcat. If we open a terminal and type nc. We will see the netcat help menu. Next we will run through the ports and try to connect with basic netcat commands: nc -v 192.168.1.2 445. This will launch netcat and connect to port 445. You may have to hit enter a couple times to get it to respond. You shouldn't see port closed by remote host. If it is then there are many things that could be closing the port. Be sure to document all open ports that have been verified. In up coming tutorials we will be using netcat to perform reverse connections back to our attack machine from the linux server. This will conclude the first tutorial, I will be posting the next tutorial in a few days.
Quick Bash Ping Sweep Script:
#!/bin/bash
for $endIp in $(seq 1 254); do
ping -c 1 192.168.1.$endIp |grep "bytes from" | cut -d " " -f 4 | cut -d -f 1 &
And its Done!!!
Bookmark us for more such Tutorials!
Like us on Facebook.
Follow us on G+;
Follow us on twitter...!
Leave ur Comments Friends;
HOW TO HIDE ANY FILE IN AN IMAGE FILE
HOW TO HIDE ANY FILE IN AN IMAGE FILE
Hey guys, I am back with another great Windows
Trick that you might not know untill now,
Trick that you might not know untill now,
Today we will discuss HOW TO HIDE ANY FILE IN AN
IMAGE FILE.
IMAGE FILE.
If you wish to send some file secretly
to your friend and don't want others to peep in,
just hide the file inside an image and send it to
them..
to your friend and don't want others to peep in,
just hide the file inside an image and send it to
them..
Ok But how are we gonna do? This Technique of
Hiding files inside another file or an image is
known as Steganography, so lets see how it is
done step by step.....
Before we move further with the steps.There
are something that we need inorder to perform
this trick. We will need WinRar Installed on your
PC. So if you already have WinRar archiver in
your pc, which most of us do have, you can
proceed with below steps
Hiding files inside another file or an image is
known as Steganography, so lets see how it is
done step by step.....
Before we move further with the steps.There
are something that we need inorder to perform
this trick. We will need WinRar Installed on your
PC. So if you already have WinRar archiver in
your pc, which most of us do have, you can
proceed with below steps
Step 1 : Create a folder with files that you would
like to Hide in an Image file, Lets say the folder
name is "Files" . Now Right Click on the folder and
select add to archive. Select RAR as Archive
format and Click OK
.
Step 2 : You will now see a rar file with name
files, Now say you have an image with name
"image.jpg " in which we will hide these files.
Copy both Files.ra r and image.jpg and paste
them in " C" or "D" Drive.
like to Hide in an Image file, Lets say the folder
name is "Files" . Now Right Click on the folder and
select add to archive. Select RAR as Archive
format and Click OK
.
Step 2 : You will now see a rar file with name
files, Now say you have an image with name
"image.jpg " in which we will hide these files.
Copy both Files.ra r and image.jpg and paste
them in " C" or "D" Drive.
Step 3 : Next Open CMD, Search for CMD and open
it. If you files are in "D" drive then Type D: and
press Enter. Now Type in this Code as it is copy /
b image.jpg + files.rar new.jpg and press Enter
it. If you files are in "D" drive then Type D: and
press Enter. Now Type in this Code as it is copy /
b image.jpg + files.rar new.jpg and press Enter
Step 4 : If you have done everything right till
now, then you will see something Similar like
below Picture. I had the file in E: so i initially
typed E: to change the location to E drive.
now, then you will see something Similar like
below Picture. I had the file in E: so i initially
typed E: to change the location to E drive.
Step 5 : Now Navigate to the location where you
saved the file and you will see one for file added
with name New.jpg.
Ok So now we have a new file .
saved the file and you will see one for file added
with name New.jpg.
Ok So now we have a new file .
Now If you want to take these files out from that image,
Right click on new.jpg and open with WinRAR
Right click on new.jpg and open with WinRAR
Now you can see all Hidden Files
Like us on Facebook,
follow s on google+, Dont forget to bookmark us.

HACK Someone IP Address
How To HACK Someone IP Address
So Here Weo Go, Step by Step ==>>
1. Copy the below codes into Notepad and save it as myip.php (.php is must)
<?php
$hostname = gethostbyaddr($_SERVER['REMOTE_ADDR']);
$img_number = imagecreate(400,95);
$backcolor = imagecolorallocate($img_number,10,102,153);
$textcolor = imagecolorallocate($img_number,255,255,255);
$hostname = gethostbyaddr($_SERVER['REMOTE_ADDR']);
$img_number = imagecreate(400,95);
$backcolor = imagecolorallocate($img_number,10,102,153);
$textcolor = imagecolorallocate($img_number,255,255,255);
imagefill($img_number,0,0,$backcolor);
$number0 = " This is Your IP/Proxy";
$number1 = " IP: $_SERVER[HTTP_X_FORWARDED_FOR]";
$number2 = " Host/Proxy: $hostname";
$number4 = " _________________________________";
$number0 = " This is Your IP/Proxy";
$number1 = " IP: $_SERVER[HTTP_X_FORWARDED_FOR]";
$number2 = " Host/Proxy: $hostname";
$number4 = " _________________________________";
Imagestring($img_number,10,5,5,$number0,$textcolor);
Imagestring($img_number,10,5,25,$number1,$textcolor);
Imagestring($img_number,10,5,45,$number2,$textcolor);
Imagestring($img_number,10,5,50,$number4,$textcolor);
Imagestring($img_number,10,8,50,$number4,$textcolor);
Imagestring($img_number,10,5,10,$number4,$textcolor);
Imagestring($img_number,10,8,10,$number4,$textcolor);
Imagestring($img_number,10,5,25,$number1,$textcolor);
Imagestring($img_number,10,5,45,$number2,$textcolor);
Imagestring($img_number,10,5,50,$number4,$textcolor);
Imagestring($img_number,10,8,50,$number4,$textcolor);
Imagestring($img_number,10,5,10,$number4,$textcolor);
Imagestring($img_number,10,8,10,$number4,$textcolor);
header("Content-type: image/png");
imagepng($img_number);
$file=fopen("Victim's IP.txt","a");
$file2 = "- IP joined - IP/Proxy: $_SERVER[HTTP_X_FORWARDED_FOR] - Host: $hostname - '\n' ";
fwrite($file, $file2);
fclose($file);
?>
imagepng($img_number);
$file=fopen("Victim's IP.txt","a");
$file2 = "- IP joined - IP/Proxy: $_SERVER[HTTP_X_FORWARDED_FOR] - Host: $hostname - '\n' ";
fwrite($file, $file2);
fclose($file);
?>
2. Now make Free account on any of the free web hosting sites Ripway or on My3gb .
3. Now Upload myip.php to your web hosting site.
4. Copy the link of your uploaded file and send it to victim.
5. As soon as victim will click on your link, his ip will be saved in your free web hosting site.
6. Enjoy you are Done !!
Play Games ,Make Money
Play Games ,Make Money
Who Would not like to earn money , in addition with doing our FaVourite job ,that is Playing Games. Yes ,Its Possible.
Winter is usually the most anticipated time for serious PC gamers, because the holidays mean one thing and one thing alone - gamer sales! Steam and EA's Origin, the two most popular digital game distribution platforms, have already kicked off their Christmas sales, and for gamers, this is nothing short of a spring vacation. However, for the business-minded, it is more than just a sale - it's an opportunity to make a few bucks easily.
Steam trading cards
To make any money from Steam, you need to familiarize yourself with the concept of Steam trading cards. These are cards you can trade, or sell on the Steam market. There are two basic types of cards, game cards and holiday/sale cards.
Each game on Steam has its own set of trading cards, provided that it is fully integrated with Steam and supports trading cards. To check if a game supports trading cards, visit its store page, and look for its Steam compatibility in the right sidebar.
Additionally, you can see a list of all games owned by you that support trading cards by going to the badges page under your profile.
Another type of trading card is the holiday/sale card. Steam runs a sale on holidays and special occasions all round the year, and the most common of these sales are the Summer and the Winter sales. Right now, the Winter/Christmas sale is underway.
How to get trading cards?
There are quite a few ways to get a card. Game cards are dropped randomly while you play a game. Each game has a collection of cards, but you don't get the whole collection this way. You only get roughly half of the collection for free. For a game with 10 cards, you might be allowed a maximum of 5 card drops. You can see how many card drops are left for each game under the Badges section in your profile.
Here's a trick: If you don't have time to spend on playing a game, you can keep the game minimized while you do your work - the cards will still drop!
This only applies to games that you purchased. For Free to Play games such as Team Fortress 2 or DOTA 2, you have to make purchases in-game to earn card drops.
There are two types of game cards - normal and Foil. Foil cards are rare, and hence more valuable. So keep a special eye out for them.
You can get holiday/sale cards while making game purchases during a major sale (Summer or Winter etc). Every $10 spent on a sale will get you a card. If that seems excessive, you can get a card by participating in the community voting. Every few votes in the 'Community Choice' deal get you a card. You can vote once in 8 hours during a sale, which usually lasts 10-15 days, giving you plenty of time to make a collection.
You can also get cards by buying them from the Steam market, or trading them from your friends.
Badges and Booster packs
Getting all the cards drops available for a game makes you eligible for a booster pack. You don't need to complete a collection for it. Once you complete a collection, you can craft a badge. So what are these badges and booster packs?
A booster pack contains 3 random cards, which might include a foil card (more valuable). Booster packs are awarded rarely, but randomly, provided that you are eligible (i.e. have gotten all card drops for a game). You don't have to play a game to win a booster pack - you just need to log into Steam at least once a week.
If you have purchased a game, but have not gotten all the card drops, then I'd suggest you do it as soon as possible. The more booster packs you're eligible for, the higher your chances of being awarded one.
When you complete a collection, you can use it to craft a badge. Badges give you experience for leveling up on Steam (which is also important), along with a chat emote, a background, and sometimes a voucher.
Steam has introduced a new concept this time around. You can use your cards to make Gems. Gems can be used to buy booster packs.
Steam has introduced a new concept this time around. You can use your cards to make Gems. Gems can be used to buy booster packs.
So, how to make money off all this?
I know all this might be confusing for beginners, but you'll soon get the hang of it once you familiarize yourself with Steam. Making money from steam is simple. You can sell all cards, badges, and booster packs for money on the Steam market. Now here's where it gets a little.....mathy.
Normal trading cards are very cheap, unless the game is new. They'll usually fetch you less than a dollar. Sometimes, only a few cents. A card's price rises and falls over time, like a stock market. It all depends on the supply and demand. You can search for a card in the market and look at its price history to get an estimate on what the card is worth.
Here's a look at the price history for one of the Holiday cards this winter.
Foil cards are rare, but they usually go for a lot more money - sometimes up to 10 times as much as normal cards. Just like normal and foil cards, there are normal and foil badges. But it's often not worth crating a foil badge. You'll make more money by simply selling the foil cards.
Now Booster packs go for a lot of money as well. Once you're rewarded with a Booster Pack, you can either open it or sell it. If you sell it, you'll get some decent money. But if you open it, and find a foil card in there along with other cards, you'll get even more money! But be advised that foil cards in booster packs are rare, so choose what you want wisely.
Sell games
Selling cards probably won't make you rich, but can give you a small and steady income. You can use that money to buy games for friends, who can then pay you in person. You cannot cash out the money you have in your Steam wallet.
Or here's another idea. During the sale, you can buy games at a much discounted rate. You can then sell those games for more money (but less than the official price) once the sale is over. A lot of people buy games outside of sales, so you can hit communities and connect with people to find interested buyers. You can even earn hundreds of dollars if you're willing to invest!
Considering that the Winter sale is currently going on, I say why not take these theories and put them to the test? I've already got a game minimized as I write this, hoping to get some card drops. And I'll be buying some more games from the great Winter deals as well. It's a great time to be gaming this time of the year - you can get some money off it!
I know This was Bit Confusing For new Gamers, But Worth of Having adventure Later.
I know This was Bit Confusing For new Gamers, But Worth of Having adventure Later.
![How To HACK Someone IP Address
So Here Weo Go, Step by Step ==>>
1. Copy the below codes into Notepad and save it as myip.php (.php is must)
<?php
$hostname = gethostbyaddr($_SERVER['REMOTE_ADDR']);
$img_number = imagecreate(400,95);
$backcolor = imagecolorallocate($img_number,10,102,153);
$textcolor = imagecolorallocate($img_number,255,255,255);
imagefill($img_number,0,0,$backcolor);
$number0 = " This is Your IP/Proxy";
$number1 = " IP: $_SERVER[HTTP_X_FORWARDED_FOR]";
$number2 = " Host/Proxy: $hostname";
$number4 = " _________________________________";
Imagestring($img_number,10,5,5,$number0,$textcolor);
Imagestring($img_number,10,5,25,$number1,$textcolor);
Imagestring($img_number,10,5,45,$number2,$textcolor);
Imagestring($img_number,10,5,50,$number4,$textcolor);
Imagestring($img_number,10,8,50,$number4,$textcolor);
Imagestring($img_number,10,5,10,$number4,$textcolor);
Imagestring($img_number,10,8,10,$number4,$textcolor);
header("Content-type: image/png");
imagepng($img_number);
$file=fopen("Victim's IP.txt","a");
$file2 = "- IP joined - IP/Proxy: $_SERVER[HTTP_X_FORWARDED_FOR] - Host: $hostname - '\n' ";
fwrite($file, $file2);
fclose($file);
?>
2. Now make Free account on any of the free web hosting sites Ripway or on My3gb .
3. Now Upload myip.php to your web hosting site.
4. Copy the link of your uploaded file and send it to victim.
5. As soon as victim will click on your link, his ip will be saved in your free web hosting site.
6. Enjoy you are Done !!](https://scontent-a.xx.fbcdn.net/hphotos-xpa1/v/t1.0-9/10603505_369353869892192_2977100410780980349_n.jpg?oh=9d95124161523b8c639b70a3923c3c42&oe=54FCD1B7)