Showing posts with label hacks. Show all posts

» Exe Chainer - V1.2  

Posted by pranav

Reduced: 96% of original size [ 528 x 402 ] - Click to view full image

---------------
1-support all files extensions (.exe , .rar , .jpge , .mp3 , .txt , etc .....).
2-support unlimited Files.
3-support icon Chainging.
4-100% Fud @t time of release.
5-very stable.
6-working on both vista & Xp.
7-unique style.
8-Client size 1.5 mb unpacked ---> 588kb if backed with upx.
9-stup size 19.5 kb unpacked ---> 10.5kb if backed with upx.
10-just free of charger !!.

Code:

File Chained.exe received on 02.14.2008 14:23:06 (CET)
Current status: Loading ... queued waiting scanning finished NOT FOUND STOPPED


Result: 2/32 (6.25%)
Loading server information...
Your file is queued in position: 1.
Estimated start time is between 38 and 54 seconds.
Do not close the window until scan is complete.
The scanner that was processing your file is stopped at this moment,
we are going to wait a few seconds to try to recover your result.
If you are waiting for more than five minutes you have to resend your file.
Your file is being scanned by VirusTotal in this moment,
results will be shown as they're generated.
Compact Print results
Your file has expired or does not exists.
Service is stopped in this moments, your file is waiting to be scanned
(position: ) for an undefined time.

You can wait for web response (automatic reload) or type your email
in the form below and click "request" so the system sends you a notification
when the scan is finished.
Email:


Antivirus Version Last Update Result
AhnLab-V3 2008.2.14.11 2008.02.14 -
AntiVir 7.6.0.65 2008.02.14 -
Authentium 4.93.8 2008.02.14 -
Avast 4.7.1098.0 2008.02.14 -
AVG 7.5.0.516 2008.02.14 -
BitDefender 7.2 2008.02.14 -
CAT-QuickHeal None 2008.02.13 -
ClamAV 0.92.1 2008.02.14 -
DrWeb 4.44.0.09170 2008.02.14 -
eSafe 7.0.15.0 2008.02.13 -
eTrust-Vet 31.3.5536 2008.02.14 -
Ewido 4.0 2008.02.14 -
FileAdvisor 1 2008.02.14 -
Fortinet 3.14.0.0 2008.02.14 -
F-Prot 4.4.2.54 2008.02.13 -
F-Secure 6.70.13260.0 2008.02.14 -
Ikarus T3.1.1.20 2008.02.14 Downloader.Delphi
Kaspersky 7.0.0.125 2008.02.14 -
McAfee 5229 2008.02.13 -
Microsoft 1.3204 2008.02.14 -
NOD32v2 2874 2008.02.14 -
Norman 5.80.02 2008.02.13 -
Panda 9.0.0.4 2008.02.14 Suspicious file
Prevx1 V2 2008.02.14 -
Rising 20.31.30.00 2008.02.14 -
Sophos 4.26.0 2008.02.14 -
Sunbelt 2.2.907.0 2008.02.14 -
Symantec 10 2008.02.14 -
TheHacker 6.2.9.219 2008.02.13 -
VBA32 3.12.6.1 2008.02.14 -
VirusBuster 4.3.26:9 2008.02.13 -
Webwasher-Gateway 6.6.2 2008.02.14 -
Additional information
File size: 453481 bytes
MD5: e6459344d5f87996a2e12715c2853915
SHA1: b015ce1b867e8aa1472b64ae93997460f0c51f39
PEiD: -
Ikarus T3.1.1.20 2008.02.14 Downloader.Delphi
wtf it is binder shitty av.
even av ripps another av's definations

DownLoad


CODE
http://rapidshare.com/files/91771407/eXe_Chainer.exe


credits--nick

> » Netlimiter (gets Victims Ip)  

Posted by pranav

with NetLimiter u can get the victims IP . open windows live messenger and then connect whit a victim. U must send him a file if u wanna
connect. The file must be at least 3 MB.
While sending turn on NetLimiter. In NetLimiter open messenger and then look which IP have more upload or download (dependence who is sending the file)
IP that is at the largest speed is victims IP.


CODE
http://uploaded.to/?id=jgrdzr


--------------------


credits--nik

» Zip Bomb!  

Posted by pranav





!Warning!
This a powerful tool use it wisely

A zip bomb, also known as a Zip of Death, is a type of denial of service attack. Specifically, it a malicious archive file that is designed to crash or render useless the program or system reading it. It is often employed to disable antivirus software, so that a more traditional virus sent afterwards could get through undetected.

Rather than hijacking the normal operation of the program, a zip bomb allows the program to work as intended, but the archive is carefully crafted so that unpacking it (e.g. by a virus scanner in order to scan for viruses) requires inordinate amounts of time, disk space or memory.

A zip bomb is usually a small file (up to a few hundred kilobytes) for ease of transport and to avoid suspicion. However, when the file is unpacked its contents are more than the system can handle.


And here it is


CODE
http://rapidshare.com/files/113382515/42.zip.html


--------------------

using proxies in windows easy as saying devil :P  

Posted by pranav

USING PROXies in windows easy way :P
================================

method - via H.323 gateway

>go to control panel
>phone modem options
>advanced
>in Providers, click Microsoft H.323 Telephony Service Provider, and then click Configure.
>IN Configure H.323 Service Provider
To specify an H.323 proxy, select the Use H.323 proxy, and then type the server name or IP address for the proxy.



google for available proxy IP /servers...
this is a easy way of using private proxy with windows... plus its more secure than public CGI ones :D

┼◘┼мДģε┼◘┼


credits--

°o.ODemonoid Secrect O.o°  

Posted by pranav

guies now u don need invitation in demonoid.
Do the following. It really works.....

You must be having Firefox thn,

In the adderss bar type in

about:config


Then scroll down till you find (you can also use the filter feature)
"general.useragent.extra.firefox"
Double click on it and type in "Googlebot 2.1". Now this will change your user agent to the google bot. To change the user agent back to the original one just right click and click Reset.



As demonoid has left for google engine to search.... you can access demonoid


Happy Downloading

°o.O ∂є√เℓ™O.o°


credits--

[videos] - mobile hacking  

Posted by pranav

[videos] - mobile hacking

FREE MOBILE WEB HACK http://www.youtube.com/watch?v=3Ai9ZvTYMlg&feature=related


Free internet/wap FOR LIFE!!
http://www.youtube.com/watch?v=3Ai9ZvTYMlg&feature=related

hack minutes and save $$
http://www.youtube.com/watch?v=7Lz-XGjynN8&feature=related

Free Mobile Phone Tracking
http://www.youtube.com/watch?v=Rjf5KlDxr40&feature=related

Hacking WLAN
http://www.youtube.com/watch?v=eKrAZpANoeM&feature=related


Hack a Razr cell phone password
http://www.youtube.com/watch?v=LZpFU1bjRBs&feature=related = !

Hacking Internet Cafes and Phones (The Fixed Ep http://www.youtube.com/watch?v=7R4tD4YvOaQ&feature=related

Cell phone Coke machine hack
http://www.youtube.com/watch?v=3opDwym9ikA&feature=related

Wireless Hacking
http://www.youtube.com/watch?v=qP1BOZqrp5g&feature=related

Hacking into a phone.
http://www.youtube.com/watch?v=0125jiQ9cqY&feature=related

Phone Hacking
http://www.youtube.com/watch?v=KnktpurvHeo&feature=related

Cell Phone Hack(receive police transmissions) [[ MUCT CHEK ]]
http://www.youtube.com/watch?v=CnDk9KLezt4&feature=related

How to hack / modify a cell phone(Please read the details)
http://www.youtube.com/watch?v=a3mVKBsueXQ&feature=related

Shocking BlueTooth Hack
http://www.youtube.com/watch?v=fznmFkHnZ7o&feature=related

How to hack Nokia 1110 Security code - Eqal Rules
http://www.youtube.com/watch?v=o-Cfn2e5pbc

Hacking the iphone (literally)
http://www.youtube.com/watch?v=7UzrwxWRKxM

Antenna Boosters / Signal Boosters on Razr and iPhone
http://www.youtube.com/watch?v=YjXA8Sscrws&feature=related

Remove the iPhone Sim Card
http://www.youtube.com/watch?v=kir19QRGzv8&feature=related

How To Change The Model Name Of Your Sony Ericsson Ph
http://www.youtube.com/watch?v=UknunrxRSvw

How To Change The Font On Your Sony Ericsson Phone
http://www.youtube.com/watch?v=9E2AdWaH9U8

Handy Hack bluetooth
http://www.youtube.com/watch?v=0zrNhG08u6I

Bluesnafer
http://www.youtube.com/results?search_query=bluetooth+hacking&page=3

How To DownloadYoutubeVideos DIRECTLY to iPhone/Touch-MxTubehttp://www.youtube.com/watch?v=bRKghZUCCws

How to hack a Traffic Light - No Gadgets Needed![[SORRY 4 POSTING THIS ]
http://www.youtube.com/watch?v=CLi68D4d0hI&feature=related

Make your windows mobile phone a remote for your computer
http://www.youtube.com/watch?v=hakpmR4posE

Send Free SMS Jokes and Short Text Mobile Messages
http://www.youtube.com/watch?v=pPAb4saf_14

How to send free text messages with Google
http://www.youtube.com/watch?v=n-XPEGafY6w&feature=related

increasing sound in samsung e250 the only trick
http://www.youtube.com/watch?v=VzDqYwAeIDo

What's in My Mobile box?/ What's in yours??
http://www.youtube.com/watch?v=YB5pxBH7zcU

Nokia N95 iphone popcorn amazing magic trick mobile phone
http://www.youtube.com/watch?v=byabC48uqMs === SUPRIYA .. CHEK IT SPCLY 4 U .

Nokia N95 - Transform Your Into Virtual Aquarium
http://www.youtube.com/watch?v=RdRx2IX1fro&feature=related

Boost Mobile Surf Show
http://www.youtube.com/watch?v=jQrStyIOEkA

Mobile phone tips for Vodafone users: *#147#
http://www.youtube.com/watch?v=84AYBNuqLLs

MindFreak (Criss Angel) "MOBILE IN BOTTLE" revealed --SMETHNG TIMEPASS..
http://www.youtube.com/watch?v=QJHI3FCWBlk


camera tricks
http://www.youtube.com/watch?v=ttj4T2DOL8k

Trace a mobile phone --CHEK IT OUT GUYS
http://www.youtube.com/watch?v=LRPXHgUDXOw

Free Mobile Phone Tracking
http://www.youtube.com/watch?v=Rjf5KlDxr40&feature=related

How To Locate A Mobile Phone ----------------------------
http://www.youtube.com/watch?v=QzwT1UNWyOk&feature=related

Cell phone reverse lookup people search directory
http://www.youtube.com/watch?v=2l5mfgZtuD0&feature=related

MobileTracker Demo
http://www.youtube.com/watch?v=VoHVRQC4qQA&feature=related

phone trace --CHEK--
http://www.youtube.com/watch?v=27mORH9zOJg&feature=related

Google Map GPS Cell Phone Tracker
http://www.youtube.com/watch?v=cL9qS6bAMPU&feature=related

Cool Sony Ericsson Hidden Menu(works On The Most Of S.e. Mobile
http://www.metacafe.com/watch/684326/cool_sony_ericsson_hidden_menu_works_on_the_most_of_s_e_mobile/

How to save cell phone battery life
http://www.metacafe.com/watch/905416/how_to_save_cell_phone_battery_life/

Hack Nokia Password/security Code
http://www.metacafe.com/watch/331048/hack_nokia_password_security_code/

Cheat Snake II Nokia [HUHAHAHAHAHAHAHA....
http://www.metacafe.com/watch/626662/cheat_snake_ii_nokia/

Update: Please read this post entirely before asking for virtual software for hacking passwords!  

Posted by pranav

If you ever read something like below on any webpage typically blog, forum & orkut community or get a mail like…Hey guys,
I have software to hack yahoo, gmail, hotmail, etc. passwords. If you are interested then give me your email id’s and I will email you that!

Ever wondered about truth?? Is it so simple?
Yes… but for spammers! Still you can put your email id’s below (may be in comment section) and help me to get some money by selling them to spammers! Yep, its that much simple for spammers!

So do you still think the person sending you this mail have such kind of software and just did not respond to your email!
Do you still think such software exists that will ask for your targets email id and just after one click will show his/her password!?!

In reality even if you physically brake into yahoo, gmail or any genuine service’s database, you will at the most get a garbage encrypted string. All famous services use one-way encryption for storing password in encrypted form. That means you can not get original password from this encrypted string!

Still if you are confused whether to trust me or spammers then as my last attempt to save you from spammer recall last time when you forgot your password. After going through verification steps did you get your password back or a chance to set a new password? In my experience with Yahoo at least I got a new random password by them which I can change to something comfortable string later-on if I wish!

So why did not they give me my original password? There are many reasons and as I told u earlier that they don’t store original password is one of those reasons!

So does this means you can not break into someones account?
Yeah you can, but it depends on your targets foolishness rather than your geekness. There are many tricks to do this, even some of them I tried successfully!

As this post getting long I may share those trick next time!

Till then have this hint : Don’t target the server, instead set up trap for your target! Servers are genius, targets may not be!!!

related posts

#PROTECT SCRAPBOOK FROM GETTING COPIED

#ALERT: Beware of these fake ORKUT Links!!!

Update: Please read this post entirely before asking for virtual software for hacking passwords!  

Posted by pranav

If you ever read something like below on any webpage typically blog, forum & orkut community or get a mail like…Hey guys,
I have software to hack yahoo, gmail, hotmail, etc. passwords. If you are interested then give me your email id’s and I will email you that!

Ever wondered about truth?? Is it so simple?
Yes… but for spammers! Still you can put your email id’s below (may be in comment section) and help me to get some money by selling them to spammers! Yep, its that much simple for spammers!

So do you still think the person sending you this mail have such kind of software and just did not respond to your email!
Do you still think such software exists that will ask for your targets email id and just after one click will show his/her password!?!

In reality even if you physically brake into yahoo, gmail or any genuine service’s database, you will at the most get a garbage encrypted string. All famous services use one-way encryption for storing password in encrypted form. That means you can not get original password from this encrypted string!

Still if you are confused whether to trust me or spammers then as my last attempt to save you from spammer recall last time when you forgot your password. After going through verification steps did you get your password back or a chance to set a new password? In my experience with Yahoo at least I got a new random password by them which I can change to something comfortable string later-on if I wish!

So why did not they give me my original password? There are many reasons and as I told u earlier that they don’t store original password is one of those reasons!

So does this means you can not break into someones account?
Yeah you can, but it depends on your targets foolishness rather than your geekness. There are many tricks to do this, even some of them I tried successfully!

As this post getting long I may share those trick next time!

Till then have this hint : Don’t target the server, instead set up trap for your target! Servers are genius, targets may not be!!!


related posts

<a href=" rel="http://workshopofdevils.blogspot.com/2008/02/alert-yahoo-fake-login-screen-is-on.html/" rel=ookmark" title="December 23, 2006" target="_blank" onclick="return top.js.OpenExtLink(window,event,this)">Alert: Yahoo Fake Login Screen is on Yahoo’s Geocities itself!a>

View Passwords Stored by Internet Explorer, Yahoo, Google Talk Messengers & Email Clients!  

Posted by pranav

We are covering few small utilities by NirSoft which will expose lack of security in worlds top browser (as per stats) Internet Explorer, famous email client Outlook Express and my favorite GoogleTalk, Pidgin.

Google Talk,  Pidgin  & Live Messenger Password

In total four programs tested which are presented below. All these utilities are free, small zip files (around 30-60KB in size) and requires no installation. Just download, unzip and run! Also these are only for Windows Platform (tested on Windows XP).

Please note each of following utility claimed to work with many programs. Program names highlighted in bold are tested successfully by us. We could not test rest of the program due to technical constraints.

#1. PSPV (Protected Storage Password Viewer)

This utility can show passwords from following programs:

  • Internet Explorer 6.0
  • Outlook Express
  • MSN Explore

Some antivirus notably Quick-Heal & McAfee detects pspv as its popularity grew over the time. I am using this for more than a year. In earlier days it never got caught! ;-)

PSPSV Links: Download | Homepage

#2. IEPV (Internet Explorer Password Viewer)

This utility can show passwords from following programs:

  • Internet Explorer 6.0
  • Internet Explorer 7.0

If you are Internet Explorer user please consider switching to better and secure browser like Firefox! :-)

IEPV Links: Download | Homepage

#3. MSPASS (Messenger Password Viewer)

This utility can show passwords from following messenger:

  • MSN Messenger
  • Windows Messenger (In Windows XP)
  • Windows Live Messenger (In Windows XP And Vista)
  • Yahoo Messenger (Versions 5.x and 6.x)
  • Google Talk
  • ICQ Lite 4.x/5.x/2003
  • AOL Instant Messenger v4.6 or below, AIM 6.x, and AIM Pro.
  • Trillian
  • Miranda
  • GAIM/Pidgin (more about pidgin)
  • MySpace IM

MSPASS Links: Download | Homepage

#4. MAILPV (Mail Password Viewer)

This utility can show passwords from following Email clients:

  • Outlook Express
  • Microsoft Outlook 2000 (POP3 and SMTP Accounts only)
  • Microsoft Outlook 2002/2003/2007 (POP3, IMAP, HTTP and SMTP Accounts)
  • Windows Mail
  • IncrediMail
  • Eudora
  • Netscape 6.x/7.x (If the password is not encrypted with master password)
  • Mozilla Thunderbird (If the password is not encrypted with master password)
  • Group Mail Free
  • Yahoo! Mail - If the password is saved in Yahoo! Messenger application.
  • Hotmail/MSN mail - If the password is saved in MSN/Windows/Live Messenger application.
  • Gmail - If the password is saved by Gmail Notifier application, Google Desktop, or by Google Talk.

MAILPV Links: Download | Homepage

All these programs can be accessed via command-line. Command-line options and other usage details explained in chm help file which you will find after unzipping above utilities.

Geeks may like to use command-line versions with batch scripting from @&^#@%^$!%^$! Hey do not expect me to reveal more… I am not running school for script kiddies! :P

More NirSoft Links: Top 10 Tools | Password Tools | Source Code Samples

(Disclaimer: Information presented in this article is purely to educate user about security vulnerabilities in some top products used by us in day to day life. Any misuse of this information may subject you to legal actions. Devils Workshop will not be liable for any damage as per our ToS.)

google searches to hack into sites, these are the latest working ones lols...  

Posted by pranav

Google Search: intitle:admin intitle:login

Admin Login pages. Now, the existance of this page does not necessarily mean a server is vulnerable, but it sure is handy to let Google do the discovering for you, no? Let's face it, if you're trying to hack into a web server, this is one of the more obvious places to poke.

Google Search: +htpasswd +WS_FTP.LOG filetype:log

WS_FTP.LOG can be used in many ways to find more information about a server. This query is very flexible, just substitute "+htpasswd" for "+FILENAME" and you may get several hits that you hadn't seen with the 'normal' search. Filenames suggested by the forum to explore are: phpinfo, admin, MySQL, password, htdocs, root, Cisco, Oracle, IIS, resume, inc, sql, users, mdb, frontpage, CMS, backend, https, editor, intranet . The list goes on and on.. A different approach might be "allinurl: "some.host.com" WS_FTP.LOG filetype:log" which tells you more about who's uploading files to a specific site.

Google Search: "Powered by PHPFM" filetype:php -username

PHPFM is an open source file manager written in PHP. It is easy to set up for a beginner, but still easy to customize for the more experienced user. The built-in login system makes sure that only people with the right username and password gains access to PHPFM, however, you can also choose to disable the login system and use PHPFM for public access. It can currently: create, rename and delete folders; create, upload, rename, download and delete files; edit text files; view image files; sort files by name, size, permissions and last modification date both ascending and descending; communicate in more languages. This search finds those "public" versions of PHPFM. An attacker can use them to manage his own files (phpshell anyone ?).


Google Search: intitle:"PHP Shell *" "Enable stderr" filetype:php

PHP Shell is a shell wrapped in a PHP script. It's a tool you can use to execute arbiritary shell-commands or browse the filesystem on your remote Web server. This replaces, to a degree, a normal telnet-connection. You can use it for administration and maintenance of your Web site using commands like ps, free, du, df, and more. If these shells aren't protected by some form of authentication, an attacker will basicly *own* the server. This search finds such unprotected phpshells by looking for the keyword "enable stderr".


Google Search: PHPKonsole PHPShell filetype:php -echo

PHPKonsole is just a little telnet like shell wich allows you to run commands on the webserver. When you run commands they will run as the webservers UserID. This should work perfectly for managing files, like moving, copying etc. If you're using a linux server, system commands such as ls, mv and cp will be available for you...

Google Search: "Please re-enter your password It must match exactly"

Invision Powerboard registration pages. wink.gif

Google Search: "index of /" ( upload.cfm | upload.asp | upload.php | upload.cgi | upload.jsp | upload.pl )

Searches for scripts that let you upload files which you can then execute on the server.








--------------------

A way out to send links without filling in any captcha.  

Posted by pranav

Orkut Hack: A way out to send links without filling in any captcha.

A CAPTCHA is a type of challenge-response test used in computing to determine whether the user is human. The process involves one computer (a server) asking a user to complete a simple test which the computer is able to generate and grade. Because computers are unable to solve the CAPTCHA, any user entering a correct solution is presumed to be human. A common type of CAPTCHA requires that the user type the letters of a distorted image, sometimes with the addition of an obscured sequence of letters or digits that appears on the screen.

In short a captcha is an effective way of controlling spam. Now it's time to break that in Orkut.

(Orkut Plus!)Well, i am not amused but many of the thousands will be after reading this post. Orkut Brains just discovered a way out to send links without filling in any captcha (word verification). Unfortunately, this means more spam on orkut.



1. http://www.orkut.com/ClickTracker.aspx?url=//////www.yourlink.com
2. Edit the 'your link' in the link with the one you want to send and paste them in your scraps.
3. Do NOT remove the six slashes before www.yourlink.com
4. Enjoy Sending the links without filling the word verification

Note: 'http://' wont work, 'www' works flawlessly.

WATCH SECURITY CAMS ARROUND THE WORLD!  

Posted by pranav

You can watch security cams arround the world just searching this on Google:

inurl:view/index:shtml



Just write this on the SEARCH space on Google and will give you some links, choose anyone and will show you a security cam video.


--------------------


ALERT: Beware of these fake ORKUT Links!!!  

Posted by pranav

There are smart as they not only eat-up password but move u to the original orkut too!
So its hard to suspect them!

http://www.orkuft.com/CommMsgs.aspx?cmm=23803&tid=2490818637131184954&start=1

http://www.orkuft.com/CommMsgs.aspx?cmm=370&tid=2490736482991364444&na=4&nst=730&nid=370-2490736482991364444-2491654959595466395

Note host name spelling orkuft… there is extra f… n u knw what is f stands for! LOL!

Alert: Yahoo Fake Login Screen is on Yahoo’s Geocities itself!  

Posted by pranav

Few days back, I got a mail from one of my friend saying her yahoo account has been hacked! The Chinese attacker accomplished this by creating a fake-login screen! Actually there is more victims to this yahoo fake-login screen. While this type of attack isn’t new, what makes people vulnerable as this one is uploaded on yahoo’s geocities itself!

Posting here are ways to protect yourself…

1. Trying Wrong Password (Simple)
If you suspect the login-screen next to you is fake, then best way is to enter wrong password. While a genuine login screen will return an error such as “wrong user name or password” the fake one will redirect you to pre-configured page!

2. Checking source code… (Advance)
You can also inspect source-code of login screen…
Look for

&

tags… (or you can directly search for “action” attribute)

Now original “action” value for yahoo photo’s is,

“https://login.yahoo.com/config/login?“

Its enough to check high-level domain (as shown in red color). Creating a fake-login screen is quite simple so if hacker attacker is really naive, then this will works 99.99999% of the time! There is only one way out for attacker and it depends much more on victims foolishness as well as luck!

A fake login screen will always have different value for action attribute…
few ex:

  • https://user.yahooo.com/config/login? (note extra O in yahoo)
  • http://myserever.com/fakelogin.cgi
  • etc…

For those relying on “forget password” option then there is another bad news…
This guy is smart enough to change PIN and COUNTRY information in all his victims yahoo account so they could not get even security question to answer!!!

Feast for downloaders by Cyber-Buff!  

Posted by pranav

an amazing download collection! The good thing about this is its versatility and up to date information! Listing below are few links which I likes personally!

Some Cool Links: