Wireless And Ethernet Security Testing [Ghost Phisher]

Phisher is a Wireless and Ethernet security testing tool written in Python Programming Language and the Python Qt GUI library. The program is able to emulate access points , conduct Phishing and Penetration Testing Attacks including the creation of a fare AP Network for Testing Purposes.

The particularity of this Tool is that includes an entire Section for Credentials Fetching and allows the Creation of a Fake DNS Server, Access Point, HTTP and DHCP Server.


Credential Fetching Method:

Operating System Supported:

  • Ubuntu KDE/GNOME
  • BackTrack Linux
  • BackBox Linux
  • Prerequisites


The Program requires thus packages:

  • Aircrack-NG
  • Python-Scapy
  • Python Qt4
  • Python
  • Subversion
  • Xterm
  • Metasploit Framework (Optional)


You can install it using following Command: 
"apt-get install program"

In Debian, you can use following Command:
root@host:~# dpkg -i ghost-phisher_1.5_all.deb

Do you need to Update the Program: 
Don't worry, While there's a new Update, it will appear directly when the program is running!.



Features:
  • HTTP Server
  • Inbuilt RFC 1035 DNS Server
  • Inbuilt RFC 2131 DHCP Server
  • Webpage Hosting and Credential Logger (Phishing)
  • Wifi Access point Emulator
  • Session Hijacking (Passive and Ethernet Modes)
  • ARP Cache Poisoning (MITM and DOS Attacks)
  • Penetration using Metasploit Bindings
  • Automatic credential logging using SQlite Database
  • Update Support


Download Link:
New version 1.52 is available
https://www.mediafire.com/folder/7ujh211h5oa51/Ghost_Phisher


Project Source Code:
root@host:~# svn checkout 

http://ghost-phisher.googlecode.com/svn/Ghost-Phisher

Oracle Database Attacking Tool [ODAT - To Penetrate Oracle Database]


Oracle Database Attacking Tool ODAT To Penetrate Oracle Database. Its an open source penetration testing tool that test Oracle database security as remotely. Its run on Linux platform. 

You have an Oracle database listening remotely and want to find valid SIDs and credentials in order to connect to the database
You have a valid Oracle account on a database and want to escalate your privileges (ex: SYSDBA)
You have a valid Oracle account and want to execute commands on the operating system hosting this DB (ex: reverse shell)

Search valid SID on a remote Oracle Database listener via: 
a dictionary attack
a brute force attack 
ALIAS of the listener 

Search Oracle accounts using:
a dictionary attack
each Oracle user like the password (need an account before to use this attack)

Execute system commands on the database server using:
DBMS_SCHEDULER
JAVA
external tables
oradbg

Download files stored on the database server using:
UTL_FILE
external tables
CTXSYS

Upload files on the database server using:
UTL_FILE
DBMS_XSLPROCESSOR
DBMS_ADVISOR

Delete files using:
UTL_FILE

Send/reveive HTTP requests from the database server using:
UTL_HTTP
HttpUriType

Scan ports of the local server or a remote server using:
UTL_HTTP
HttpUriType
UTL_TCP

Exploit the CVE-2012-313 (http://cvedetails.com/cve/2012-3137)
pickup the session key and salt for arbitrary users
attack by dictionary on sessions.




Development version installed on your computer, these following tool and dependencies are needed:

  • Langage: Python 2.7 
  • Oracle dependencies
  • Instant Oracle basic 
  • Instant Oracle sdk 
  • Python libraries 
  • cx_Oracle 
  • colorlog (recommended) 
  • termcolor (recommended) 
  • argcomplete (recommended) 
  • pyinstaller (recommended)

Download:

The Hackers Toolbox App [Hackode]

Download Now


Hackode : The hacker's Toolbox is an application for penetration tester, Ethical hackers, IT administrator and Cyber security professional to perform different tasks like reconnaissance, scanning performing exploits etc.

This Application contains different tools like:-

* Reconnaissance
* Google Hacking
* Google Dorks
* Whois
* Scanning
* Ping
* Traceroute
* DNS lookup
* IP
* MX Records
* DNS Dig
* Exploits
* Security Rss Feed

This Application is still in beta version. It will be releasing soon its full version with some more better tools and utilities. Stay tuned for more updates.

Download Now

Hacking From Android Phones [ANTI]

Download (Anti)
Have an android phone, Looking for easy ways to hack like pentesters ?? Well you are in luck, Anti or Anti or Android networking Tool Kit  is Just what the world needs, another killer mobile app for android devices, Anti allows you to control other devices such as Desktop PC, other Android Phones and even iOS devices with just a few pushes

Android Network Toolkit (ANTI) is an amazing android application. You could bring all the hacking tools on PC to your Android smartphone. Using this app is as simple as pushing a few buttons, and then you can penetrate your target.

How Anti Works ?
Anti will map your network, scan for active devices and vulnerabilities, and will  display the information accordingly, Green led signals an 'Active device', Yellow led signals "Available ports", and Red led signals "Vulnerability found". Also, each device will have an icon representing the type of the device. When finished scanning, Anti will produce an automatic report specifying which vulnerabilities you have or bad practices used, and how you can exploit/fix each one of them.




Features:

Scan - This will scan the selected target for open ports and vulnerabilities, also allowing the user to select a specific scanning script for a more advanced/targeted scan.

Spy - This will 'sniff' images transferred to/from the selected device and display them on your phone in a nice gallery layout. If you choose a network subnet/range as target, then all images transferred on that network - for all connected devices - will be shown. Another feature of the Spy plugin is to sniff URLs (web sites) and non-secured (ie, not HTTPS) username/passwords logins, shown on the bottom drawer.

D.O.S - This will cause a Denial Of Service (D.O.S) for the selected target, ie. it will deny them any further access to the internet until you exit the attack.

Replace images - This will replace all images transferred to/from the target with an Anti logo, thus preventing from attacked used seeing any images on their browsers while the browse the Internet, except for a nice looking Anti logo...

M.I.T.M - The Man In The Middle attack (M.I.T.M) is an advanced attack used mainly in combination with other attack. It allows invoking specific filters to manipulate the network data. Users can also add their own mitm filters to create more mitm attacks.

Attack - This will initiate a vulnerability attack using our Cloud service against a specific target. Once executed successfully, it will allow the attack to control the device remotely from your phone.

Report - This will generate a vulnerability report with findings, recommendations and tips on how to fix found vulnerabilities or bad practices used.


For more info and Download details please visit the Following link

Worlds Fastest MD5 Hash Cracker [BarsWF]


The MD5 Message-Digest Algorithm is a widely used cryptographic hash function that produces a 128-bit (16-byte) hash value, Md5 is an encryption that cannot be reversed, the only successful way to find out the content of a md5 hash, is by running a Brute force Attack.

Barswf is a program designed to crack md5 hashes. It combines old with newer CUDA technologies. So, it uses your graphical card and if available, multiple cores to manage the cracking of md5 hashes. It's considered to be  the fasted Md5 Hash cracking tool available.

System Requirements

  • CUDA version only:nVidia GeForce 8xxx and up, at least 256mb of video memory.
  • LATEST nVidia-driver with CUDA support.Standard drivers might be a bit older (as CUDA 2.0 is still beta)
  • CPU with SSE2 support (P4, Core2Duo, Athlon64, Sempron64, Phenom).
  • Recommended 64-bit OS (WinXP 64 or Vista64). 32-bit version is also available.

Download 

AMD BROOK Beta 0.9:
BarsWF Brook x64
BarsWF Brook x32

CUDA 0.B:
BarsWF CUDA x64
BarsWF CUDA x32

SSE2:
BarsWF SSE x64
BarsWF SSE x32 

Best Password Cracking Tools

Cain and Abel :- The top password recovery tool for Windows. This Windows-only password recovery  tool handles an enormous variety of tasks. It can recover passwords by sniffing the network, cracking encrypted passwords using Dictionary, Brute-Force and Cryptanalysis attacks, recording VoIP conversations, decoding scrambled passwords, revealing password boxes, uncovering cached passwords and analyzing routing protocols. 
Download:- http://www.oxid.it/cain.html


John the Ripper :- A powerful, flexible, and fast multi-platform password hash cracker. John the Ripper is a fast password cracker, currently available for many flavors of Unix, DOS, Win32, BeOS, and OpenVMS. Its primary purpose is to detect weak Unix passwords. It supports several crypt(3) password hash types which are most commonly found on various Unix flavors, as well as Kerberos AFS and Windows NT/2000/XP LM hashes. Several other hash types are added with contributed patches.
Download:- http://www.openwall.com/john/  


THC Hydra :- A Fast network authentication cracker which support many different services. When you need to brute force crack a remote authentication service, Hydra is often the tool of choice. It can perform rapid dictionary attacks against more then 30 protocols, including telnet, ftp, http, https, smb, several databases, and much more.
Download:- http://freeworld.thc.org/thc-hydra/


L0phtcrack :- Windows password auditing and recovery application  

L0phtCrack, also known as LC5, attempts to crack Windows passwords from hashes which it can obtain (given proper access) from stand-alone Windows NT/2000 workstations, networked servers, primary domain controllers, or Active Directory. In some cases it can sniff the hashes off the wire. It also has numerous methods of generating password guesses (dictionary, brute force, etc).


Download:- http://download.insecure.org/stf/lc5-setup.exe
                  http://download.insecure.org/stf/lc5-crack.zip (keygen) 


Pwdump :- Windows password recovery tool.
Pwdump is able to extract NTLM and LanMan hashes from a Windows target, regardless of whether Syskey is enabled. It is also capable of displaying password histories if they are available. It outputs the data in L0phtcrack-compatible form, and can write to an output file.





RainbowCrack :- An Innovative Password Hash Cracker.
The RainbowCrack tool is a hash cracker that makes use of a large-scale time-memory trade-off. A traditional brute force cracker tries all possible plaintexts one by one, which can be time consuming for complex passwords. RainbowCrack uses a time-memory trade-off to do all the cracking-time computation in advance and store the results in so-called "rainbow tables". It does take a long time to precompute the tables but RainbowCrack can be hundreds of times faster than a brute force cracker once the precomputation is finished. 




Brutus :- A network brute-force authentication cracker
This Windows-only cracker bangs against network services of remote systems trying to guess passwords by using a dictionary and permutations thereof. It supports HTTP, POP3, FTP, SMB, TELNET, IMAP, NTP, and more.

Windows Password Cracker [Ophcrack]

Ophcrack  is a free Windows password cracker based on rainbow tables. It is a very efficient implementation of rainbow tables done by the inventors of the method. It comes with a Graphical User Interface and runs on multiple platforms.

Download : Ophcrack

Features:
  • Runs on Windows, Linux/Unix, Mac OS X, ...
  • Cracks LM and NTLM hashes.
  • Free tables available for Windows XP and Vista.
  • Brute-force module for simple passwords.
  • Audit mode and CSV export.
  • Real-time graphs to analyze the passwords.
  • LiveCD available to simplify the cracking.
  • Loads hashes from encrypted SAM recovered from a Windows partition, Vista included.
  • Free and open source software (GPL).

Creating a bootable Ophcrack flash drive:

In the following tutorial, I will explain how to create an All In One USB Ophcrack Flash Drive. which can be used to recover, reveal or crack both Windows XP and Windows Vista login passwords.
  1. First download the Ophcrack XP Live CD ISO form the above link
  2. Insert your USB Flash Drive
  3. Download and run Universal USB Installer, select OphCrack XP, and follow the onscreen instructions
  4. Create a folder named vista_free inside the tables folder on your USB Flash Drive
  5. Download and unzip the tables_vista_free. zip to the tables/vista_free folder on your USB Flash Drive
  6. Reboot your PC and set your system to boot from the USB device
Hope this information helps you .In my next tutorial I will explain How to Hack windows password using Ophcrack Live CD/USB .


Create Fake WhatsApp Conversation [Whatsaid.apk]


Steps:

Step 1: First Download WhatSaid APK file.

Step 2: Now transfer WhatSaid APK File to your android phone and install WhatSaid App normally.

Step 3: After installing the WhatSaid App you will notice WhatSaid App is similar to  WhatsApp one.

Step 4: Now its time to create fake conversation by writing friend name and by uploading friend picture and by writing fake conversation.

Step 5: You can also share this fake WhatsApp conversation in Facebook and Messages.

Have Fun Enjoy.For any query feel free to comment below.



Save Bookmarks Online And Access Them From Any Device, Anywhere

Listango : Listango is a best tool or website which help us to save bookmarks online and access them from anydevice, anywhere.Also if you want to create such type of bookmarks list which is not public means only you can see or access that list then this website if for you specialy. Because Listango helps you to create private bookmarks list.


Feature’s Of Listango:

1. Access Your Bookmarks From Anywhere: You can access your bookmarks from any computer, phone or tablet. Listango works on all modern web browsers.

2. Make Public Or Private Bookmarks List: If You don’t want to share your bookmarks with the whole world. Create private lists that only you can view.

3.Share Bookmarks With Friends Using Social Sites: You can easily share your bookmarks with friends. You can share your bookmarks using Facebook, Twitter, or email.



How To Use Listango To Save Bookmarks Online:

Step 1: Visit the Listango and signup using Facebook or via Email.
Step 2: Now drag the listango button on the Bookmarks Bar.As shown below in screenshot.

Step 3: OK if you want to save any Bookmarks.Just visit the website and drag them into Listango Bookmarks bar.


Video Tutorial:


Top Hacker Friendly OS


1. Kali Linux
Download : KaliLinux


Kali Linux is based upon Debian Linux, instead of Ubuntu and new streamlined repositories synchronize with the Debian repositories 4 times a day, constantly providing users with the latest package updates and security fixes available.
With more than 300 penetration testing tools, completely free, Open source, Vast wireless device support, GPG signed packages and repos, Multi-language, Completely customizable make this distribution one of the best available masterpiece of hacking community.
default root password is same “toor“.




2. BackTrack 5

Download : BackTrack5
Backtrack is a Linux OS designed for security professionals. Who deals with system and web application security and other fields such as forensics.

This operating system includes all the security assessments and features till date.This distro got it all,Slick Interface,Powerful yet latest tools,high compatibly large software library,tons of tutorial.



3. BugTraq
Download : BugTraq


BugTraq offers the most comprehensive distribution, optimal, stable and automatic security to date. Bugtraq is a distribution based on the 2.6.38 kernel has a wide range of penetration and forensic tools. Bugtraq can install from a Live DVD or USB drive, the distribution is customized to the last package, configured and updated the kernel and the kernel has been patched for better performance and to recognize a variety of hardware, including wireless injection patches pentesting other distributions do not recognize.
Some of the special features that you can appreciate are:
Administrative improvements of the system for better management of services.
Expanded the range of recognition for injection wireless drivers.
Tools perfectly configured, automated installation scripts and tools like Nessus, OpenVAS, Greenbone, Nod32, Hashcat, Avira, BitDefender, ClamAV, Avast, AVG, etc...
Unique Scripts from Bugtraq-Team (SVN updates tools, delete tracks, backdoors, Spyder-sql, etc.)
Stability and performance optimized: Enhanced performance flash and java and start purging unnecessary services. So that the user can use only the services you really want.
It has incorporated the creation of the user in the installation, which is created with all system configurations.
We are the distribution and Forensic Pentesting with more tools built and functional, well organized menu without repetition of the same to avoid overwhelming the user.





4. BlackBuntu
Download : BlackBuntu
Blackbuntu is distribution for penetration testing which was specially designed for security training students and practitioners of information security. It's currently being built using the xubuntu 12.04.This edition has a large software library and nearly 100000's tutorials flying on YouTube and other sites. Blackbuntu runs on almost any PC,new or old,because of its less requirements.The Main developer,Krit Kadnok says "It's created in our own time as a hobby."

Install John The Ripper On Ubuntu Linux




Requirements:

1. John The Ripper: Download the Latest and Free Version from here:
http://www.openwall.com/john/

 It will be in tar.gz format, namely john-1.7.7.tar.gz  



2. GCC:  GCC should be installed in your system. GCC is C and C++ Compiler.  Download and Install GCC

Why you need to install GCC?
John The Ripper comes as Source file. We have to compile and so that we can make the John The Ripper as executable.  GCC only going to help us to compile the John The Ripper files.

 Ok, Let us start installation.

John The Ripper Installation:
Step 1:
After Downloaded the john-1.7.7.tar.gz file, copy the file in Desktop.


Step 2:Extracting Tar.gz
Now Open the Terminal (Applications->Accessories->Terminal)
Enter this command in Terminal (to navigate to Desktop dir)

cd Desktop
Now Enter this command (to Extract the tar.gz file).

   tar -xzf john-1.7.7.tar.gz
Now john-1.7.7.tar.gz is extracted to john-1.7.7 folder.  
Alternate Extraction Method: Simply right click on the tar.gz file and select Extract here

Step 3: Compiling the Source File
Now Enter this command in Terminal(to navigate to john-1.7.7 directory)
cd john*

Then enter this command in Terminal (to navigate to src folder)
cd src

Then enter this command :
make

Now you can see list of Operating System.
Find the operating System option that match with your Operating System.
Then enter the following command:
   make clean Operating_System_option

For Example:
   make clean Linux-x86-64

If you don't know or can't find your operating system in list, then simply try  this instead:
make clean generic

It will start to compile the source file.  Wait for a while. It will take few minutes to complete the compilation (depending on your system speed, it will take time).

Step 4:End of Compilation and Installation
After compilation completed, john(executable) file will be created in john-1.7.7/run/ folder

Step 5: Let us Test
Okay let us test whether John the ripper is working or not.  
You are still in Terminal , right?

Enter the following command:
    cd -

This will bring you to the previous directory(i mean john-1.7.7/src to john-1.7.7/ folder).

Now enter the Following command (to navigate to john-1.7.7/run/ folder):
cd run

Let us run the John The Ripper from here.
Enter the Following command:

./john --test

It will start to process.  It will take time depending on the speed of your system.  If you want to terminate process , then press CTRL+C.