4 Sites To Bypass SMS Verification Of Any Website


The reason it is in the top of my list is that it requires no registartion and the S.M.S delivery is comparatively fast as compared to other websites . Here the number might be connected to different networks . So just pick up a number with less activity or messages and you are done with it . Check out the image below .
Bypass SMS Verification




Compared to the No.1 Place on our blog it comparatively has more numbers to enjoy the bypassing feature but the only reason this website ranks second is because of it's speed . Although it is faster in some cases depending on the Networks connected to it . But seems like it is busy all the time .


Compared to the above mention websites the network of this website is most the time free or sms received is very less as you can see in the image below .
Bypass SMS Verification



The fourth one in the list is really very special and he feature that I am a very big fan of is that you can even send SMS from this . Sounds very exciting but in some cases the SMS is not sent .


Note : The only problem that you can face is that , it might display a message "number is already registered" .So all you have to do is change website change number as simple as a-b-c-d . 

Top Hacker Friendly OS


1. Kali Linux
Download : KaliLinux


Kali Linux is based upon Debian Linux, instead of Ubuntu and new streamlined repositories synchronize with the Debian repositories 4 times a day, constantly providing users with the latest package updates and security fixes available.
With more than 300 penetration testing tools, completely free, Open source, Vast wireless device support, GPG signed packages and repos, Multi-language, Completely customizable make this distribution one of the best available masterpiece of hacking community.
default root password is same “toor“.




2. BackTrack 5

Download : BackTrack5
Backtrack is a Linux OS designed for security professionals. Who deals with system and web application security and other fields such as forensics.

This operating system includes all the security assessments and features till date.This distro got it all,Slick Interface,Powerful yet latest tools,high compatibly large software library,tons of tutorial.



3. BugTraq
Download : BugTraq


BugTraq offers the most comprehensive distribution, optimal, stable and automatic security to date. Bugtraq is a distribution based on the 2.6.38 kernel has a wide range of penetration and forensic tools. Bugtraq can install from a Live DVD or USB drive, the distribution is customized to the last package, configured and updated the kernel and the kernel has been patched for better performance and to recognize a variety of hardware, including wireless injection patches pentesting other distributions do not recognize.
Some of the special features that you can appreciate are:
Administrative improvements of the system for better management of services.
Expanded the range of recognition for injection wireless drivers.
Tools perfectly configured, automated installation scripts and tools like Nessus, OpenVAS, Greenbone, Nod32, Hashcat, Avira, BitDefender, ClamAV, Avast, AVG, etc...
Unique Scripts from Bugtraq-Team (SVN updates tools, delete tracks, backdoors, Spyder-sql, etc.)
Stability and performance optimized: Enhanced performance flash and java and start purging unnecessary services. So that the user can use only the services you really want.
It has incorporated the creation of the user in the installation, which is created with all system configurations.
We are the distribution and Forensic Pentesting with more tools built and functional, well organized menu without repetition of the same to avoid overwhelming the user.





4. BlackBuntu
Download : BlackBuntu
Blackbuntu is distribution for penetration testing which was specially designed for security training students and practitioners of information security. It's currently being built using the xubuntu 12.04.This edition has a large software library and nearly 100000's tutorials flying on YouTube and other sites. Blackbuntu runs on almost any PC,new or old,because of its less requirements.The Main developer,Krit Kadnok says "It's created in our own time as a hobby."

Install John The Ripper On Ubuntu Linux




Requirements:

1. John The Ripper: Download the Latest and Free Version from here:
http://www.openwall.com/john/

 It will be in tar.gz format, namely john-1.7.7.tar.gz  



2. GCC:  GCC should be installed in your system. GCC is C and C++ Compiler.  Download and Install GCC

Why you need to install GCC?
John The Ripper comes as Source file. We have to compile and so that we can make the John The Ripper as executable.  GCC only going to help us to compile the John The Ripper files.

 Ok, Let us start installation.

John The Ripper Installation:
Step 1:
After Downloaded the john-1.7.7.tar.gz file, copy the file in Desktop.


Step 2:Extracting Tar.gz
Now Open the Terminal (Applications->Accessories->Terminal)
Enter this command in Terminal (to navigate to Desktop dir)

cd Desktop
Now Enter this command (to Extract the tar.gz file).

   tar -xzf john-1.7.7.tar.gz
Now john-1.7.7.tar.gz is extracted to john-1.7.7 folder.  
Alternate Extraction Method: Simply right click on the tar.gz file and select Extract here

Step 3: Compiling the Source File
Now Enter this command in Terminal(to navigate to john-1.7.7 directory)
cd john*

Then enter this command in Terminal (to navigate to src folder)
cd src

Then enter this command :
make

Now you can see list of Operating System.
Find the operating System option that match with your Operating System.
Then enter the following command:
   make clean Operating_System_option

For Example:
   make clean Linux-x86-64

If you don't know or can't find your operating system in list, then simply try  this instead:
make clean generic

It will start to compile the source file.  Wait for a while. It will take few minutes to complete the compilation (depending on your system speed, it will take time).

Step 4:End of Compilation and Installation
After compilation completed, john(executable) file will be created in john-1.7.7/run/ folder

Step 5: Let us Test
Okay let us test whether John the ripper is working or not.  
You are still in Terminal , right?

Enter the following command:
    cd -

This will bring you to the previous directory(i mean john-1.7.7/src to john-1.7.7/ folder).

Now enter the Following command (to navigate to john-1.7.7/run/ folder):
cd run

Let us run the John The Ripper from here.
Enter the Following command:

./john --test

It will start to process.  It will take time depending on the speed of your system.  If you want to terminate process , then press CTRL+C.

What is John the Ripper?


John the Ripper is a fastest and Best Password Cracking software. It is compatible with many flavours of Unix, Windows, DOS, BeOS, and OpenVMS.

Its primary purpose is to detect weak Unix passwords. Besides several crypt(3) password hash types most commonly found on various Unix systems, supported out of the box are Windows LM hashes, plus many more with contributed patches


Info about John The Ripper:
  • It is command Line Password Cracker(Don't worry , i will guide how to use John the Ripper?).
  •  John The Ripper is available for free
  • JohnTheRipper is pre Installed in Backtrack Linux
  • You can download it for other Linux Versions or any other operating system(Eg:windows xp).  
  • Supports Both Brute Force and Dictionary Attack Methods
  • Fast and Best password Cracker.
Download John The Ripper:

Mozilla Firefox Tricks





You can impress your friends/lover with this trick.
Copy the following path into mozilla browser and hit enter. See the Magic..!!

Small scrolling Mozilla
chrome://global/content/alerts/alert.xul

Display Preference
chrome://browser/content/preferences/preferences.xul

Display Cookies
If you want to delete any cookies, you can.
chrome://browser/content/preferences/cookies.xul

History Window
chrome://browser/content/history/history-panel.xul

Display Bokmark
chrome://browser/content/bookmarks/bookmarksPanel.xul


   Run FIREFOX Inside FIREFOX
chrome://browser/content/browser.xul


[bsqlbf Brute forcer] Automated Blind SQL Injection Attacking Tool




What is Blind SQL Injection
Some Websites are vulnerable to SQL Injection but the results of injection are not visible to the attacker.  In this situation, Blind SQL Injection is used. The page with the vulnerability may not be one that displays data but will display differently depending on the results of a logical statement injected into the legitimate SQL statement called for that page. This type of attack can become time-intensive because a new statement must be crafted for each bit recovered.



There are plenty of automated Blind Sql Injection tool available. Here i am introducing one of Tool named as bsqlbf(expanded as Blind Sql Injection Brute Forcer).

This tool is written in Perl and allows extraction of data from Blind SQL Injections. It accepts custom SQL queries as a command line parameter and it works for both integer and string based injections

Supported Database:

  • MS-SQL
  • MySQL
  • PostgreSQL
  • Oracle
The tool supports 8 attack modes:-
Type 0: Blind SQL Injection based on true and false conditions returned by back-end server

Type 1: Blind SQL Injection based on true and error(e.g syntax error) returned by back-end server.

Type 2: Blind SQL Injection in "order by" and "group by".

Type 3: extracting data with SYS privileges (ORACLE dbms_export_extension exploit)

Type 4: is O.S code execution (ORACLE dbms_export_extension exploit)

Type 5: is reading files (ORACLE dbms_export_extension exploit, based on java)

Type 6: is O.S code execution DBMS_REPCAT_RPC.VALIDATE_REMOTE_RC exploit

Type 7: is O.S code execution SYS.KUPP$PROC.CREATE_MASTER_PROCESS(), DBA Privs
      -cmd=revshell Type 7 supports meterpreter payload execution, run generator.exe first

Type 8: is O.S code execution DBMS_JAVA_TEST.FUNCALL, with JAVA IO Permissions
     -cmd=revshell Type 8 supports meterpreter payload execution, run generator.exe first




For Type 4(O.S code execution) the following methods are supported:

-stype: How you want to execute command:

SType 0 (default) is based on java..will NOT work against XE. 

SType 1 is against oracle 9 with plsql_native_make_utility. 

SType 2 is against oracle 10 with dbms_scheduler.


Only for Educational Purpose