Wednesday, June 19, 2013

DIFFERENT TYPES OF SERVERS







What is a Server?

A server is a device with a particular set of programs or protocols that provide various services, which other machines or clients request, to perform certain tasks. Together, a server and its clients form a client/server network which provides routing systems and centralized access to information, resources, stored data, etc. At the most ground level, one can consider it as a technology solution that serves files, data, print, fax resources and multiple computers. The advanced server versions, like Windows Small Business Server 2003 R2 enable the user to handle the accounts and passwords, allow or limit the access to shared resources, automatically support the data and access the business information remotely. For example, a file server is a machine that maintains files and allows clients or users to upload and download files from it. Similarly, a web server hosts websites and allows users to access these websites. Clients mainly include computers, printers, faxes or other devices that can be connected to the server. By using a server, one can securely share files and resources like fax machines and printers. Hence, with a server network, employees can access the Internet or company e-mail simultaneously.Servers also offer remote-management tools — which means an IT person can check usage and diagnose problems from another location. This also means you can perform routine maintenance such as adding new users or changing passwords




Different Types of Servers

The multiple types of servers or types of network servers are as follows:

Server Platform: Server platform is the fundamental hardware or software for a system which acts as an engine that drives the server. It is often used synonymously with an operating system.
Application Server: Also known as a type of middleware, it occupies a substantial amount of computing region between database servers and the end user, and is commonly used to connect the two.
Audio/Video Server: It provides multimedia capabilities to websites by helping the user to broadcast streaming multimedia content.
Chat Server: It serves the users to exchange data in an environment similar to Internet newsgroup which provides real time discussion capabilities.
Fax Server: It is one of the best option for organizations seeking for minimum incoming and outgoing telephone resources, but require to fax actual documents.
FTP Server: It works on one of the oldest of the Internet services, the file transfer protocol. It provides a secure file transfer between computers while ensuring file security and transfer control.
Groupware Server: It is a software designed that enables the users to work together, irrespective of the location, through the Internet or a corporate intranet and to function together in a virtual atmosphere.
IRC Server: It is an ideal option for those looking for real-time discussion capabilities. Internet Relay Chat comprises different network servers that enable the users to connect to each other through an IRC network.
List Server: It provides a better way of managing mailing lists. The server can be either open interactive discussion for the people or a one-way list that provide announcements, newsletters or advertising.
Mail Server: It transfers and stores mails over corporate networks through LANs, WANs and across the Internet.
News Server: It serves as a distribution and delivery source for many public news groups, approachable over the USENET news network.
Proxy Server: It acts as a mediator between a client program and an external server to filter requests, improve performance and share connections.
Telnet Server: It enables the users to log on to a host computer and execute tasks as if they are working on a remote computer.
Web Server: It provides static content to a web browser by loading a file from a disk and transferring it across the network to the user's web browser. This exchange is intermediated by the browser and the server, communicating using HTTP.These were the different types of servers which can be categorized according to their applications. Servers along with managing network resources are also dedicated, i.e. they perform no other task other than their server tasks.

BSQL HACKER


BSQL Hacker is an automated SQL Injection Framework / Tool designed to exploit SQL injection vulnerabilities virtually in any database.

BSQL Hacker aims for experienced users as well as beginners who want to automate SQL Injections (especially Blind SQL Injections).

It's easy to use for beginners and provide great amount of customisation and automation support for experienced users. Features a nice metasploit alike exploit repository to share and update SQL Injection exploits.


Key Features

Easy Mode
SQL Injection Wizard
Automated Attack Support (database dump)
ORACLE
MSSQL
MySQL (experimental)
General
Fast and Multithreaded
4 Different SQL Injection Support
Blind SQL Injection
Time Based Blind SQL Injection
Deep Blind (based on advanced time delays) SQL Injection
Error Based SQL Injection
Can automate most of the new SQL Injection methods those relies on Blind SQL Injection
RegEx Signature support
Console and GUI Support
Load / Save Support
Token / Nonce / ViewState etc. Support
Session Sharing Support
Advanced Configuration Support
Automated Attack mode, Automatically extract all database schema and data mode

Update / Exploit Repository Features
Metasploit alike but exploit repository support
Allows to save and share SQL Injection exploits
Supports auto-update
Custom GUI support for exploits (cookie input, URL input etc.)


GUI Features
Load and Save
Template and Attack File Support (Users can save sessions and share them. Some sections like username, password or cookie in the templates can be show to the user in a GUI)
Visually view true and false responses as well as full HTML response, including time and stats

Connection Related
Proxy Support (Authenticated Proxy Support)
NTLM, Basic Auth Support, use default credentials of current user/application
SSL (also invalid certificates) Support
Custom Header Support

Injection Points (only one of them or combination)
Query String
Post
HTTP Headers
Cookies

Other
Post Injection data can be stored in a separated file
XML Output (not stable)
CSRF protection support (one time session tokens or asp.net viewstate ort similar can be used for separated login sessions, bypassing proxy pages etc.)





Tuesday, June 18, 2013

WPA WPA2 WORD LIST




WPA WPA2 Word List

Compressed File Size: 4.4 GB Decompressed File Size: 13 GB

The list contains 982,963,904 words exactly no dupes and all optimized for wpa/wpa2.

This is my final series of WPA-PSK wordlist(S) as you can't get any better than this !!!

My word list is compiled from all known & some unknown internet sources such as :
1. openwall
2. coasts password collections
3. Xploitz Master Password Collection(s) vol 1 and vol 2 (official Backtrack 3/4/4R1 wordlist collections, Thanks Xploitz)
4. ftp sites such as; ftp://ftp.ox.ac.uk/pub/wordlists/ & others
5. all wordlists on and (as of 07/11/2010)
6. all wordlists hosted on;
7. all usernames from "100 million Facebook usernames and personal details" as leaked onto Torrent sites
8. all wordlists from the Argon (site now closed)

And as a bonus my personal wordlist of 1.9 GB !!!

Which also includes :

My "WPA-PSK WORDLIST 2 (107 MB).rar" & "WPA-PSK WORDLIST (40 MB).rar" Torrent
& random usernames grabbed from over 30,000+ websites such as youtube, myspace, bebo
& others sites which I can't mention :-)


DARKCOMET-RAT V4.0 FIX1 RELEASED ( FULLY CRYPTABLE )



DarkComet-RAT v4.0 Change log

- DarkComet-RAT is now compiled on Delphi XE instead of Delphi 2010.
- Synthax highlighter added in remote keylogger.
- Multithreading is now more efficient, no more freezing, using a new powerfull and stable methode (still using pure Win32 API both side for it)
- Get hard drive information added in file manager
- Bot logs in main form had change, it is more efficient / fast and user friendly
- Whole system parser is now far stable and faster
- No-IP was moded and is now better ;)
- All global settings were redisigned in a new form that will contain all necessary stuff for Client side
- Flags manager has been ported to the main client settings form
- Now you can change the default size Width and Height of the users thumbnails
- No more menu in the top of the SIN (Main Window - Users list...) so it is more clear
- The [+] button is one of the way to add a new port to listen else go to Socket/Net button to manage em all
- More options added in main tray icon (right click to display them)
- Skin system added in DarkComet in settings > Client Layount (for people that like templates - Most XP users)
- A new system of mass data saving had been added, sqlite local database system added (comet.db store all mass data) << don't delete this file ! - A complex and stable group manager been added in the users list (very strong) syncrhonized with the local database. - Now all users are stored and updated in local database - Webcam is now far more stable using now DirectX (DirectShow lib dumped from Microsoft by M.Braun) - As most crypters got the runPE function, it was removed in DarkComet then it is more easy to crypted for newbies - Little bug fixed in remote desktop - Mass downloader in control center was improved, a big bug was fixed - Keylogger GUI had change a little - New toast design - edit server now recognize encrypted profiles than normal ones. - few bugs in file listing fixed in file manager - New keylogger system, now all logs are divided by date [Months-Year] > [Day name] > full date file. so now it is more easy to find what you want to find.
- All logs are synchronized with the local database, that means if the remote gui delete the logs no problems it will be there synchronized with the DB :)
- Online keylogger is now separate from the offline one.
- last arrival logs (latest ones) will be display with a text icon and and eye on it.
- new rootkit function added in edit server (server shield) it hide the file from explorer even if show hidden files is on it will be also hidden from DIR command of MSDOS
- same rootkit function for parent dir
- Multipassword capture added, when you selected more than 1 users in the list and choose quick function password it will dump all selected users password.
- Wallpaper changer in file manager works fine now with .bmp and .jpg files for sure (not tested GIF) but PNG seems to not work.
- More components are double buffered now, so less blinking stuff on mouse move.
- List ports / services icons are better now
- UpNP exe drops now in temporary file then it wont anoy you and now it works all the time
- Save settings are better synchronized now (ini read/write)
- Now geoflag in users list aren't using the darkcomet-rat site database but a local GeoIP database then it is far more fast and stable. (do not delete GeoIP.dat !!)
- New search user system, very very strong and complete u will love it :D
- DC_UUID is now more perfmant using the computer HWID (Harware ID) + Default drive Serial (Like for my other software Vertex)
- Auto start desktop capture added in settings
- Auto start webcam capture added in settings
- Auto start sound capture added in settings
- A new super sexy about made don't forget to take a look to it ;)
- Some notification added in file manager to know if actions was well done !
- new info added in computer info ( now the rat determine if remote computer id a laptop or desktop computer) if laptop it gives the battery charge status with icon :)
- Now you can preview any files in file manager by paquet of 1Ko then you don't need to download a 30Mo text file to see it :)
- A fantastic bookmark system for the file manager, like firefox when you click on the gray star it will turn to colors and add the current path to bookmarks and of course synchronized with local database...
- Stub use less memory now, garbage colector is better now
- [ADDED] Miranda MSN Messenger password stealer
- Download thumnail (file manager) bug fixed
- To avoid problems when you build many time a module to test edit server functions part by part when you build a module it will re generate a random mutex


Download DarkComet-RAT v4.0 Fix1


DOWNLOAD FixComet v1.0

BACKTRACK 5 R1 RELEASED




Backtrack-Linux released Backtrac 5 R1 Linux Distribution. This release contains over 120 bug fixes, 30 new tools and 70 tool updates.The kernel was updated to 2.6.39.4 and includes the relevant injection patches.

BackTrack is intended for all audiences from the most savvy security professionals to early newcomers to the information security field. BackTrack promotes a quick and easy way to find and update the largest database of security tools collection to-date. Our community of users range from skilled penetration testers in the information security field, government entities, information technology, security enthusiasts, and individuals new to the security community. This release is their best one yet! Some pesky issues such as rfkill in VMWare with rtl8187 issues have been fixed, which provides for a much more solid experience with BackTrack.We’ve have Gnome and KDE ISO images for 32 and 64 bit (no arm this release), as well as a VMWare image of a 32 bit Gnome install, with VMWare Tools pre-installed.
We are mighty excited and are already downloading this release just as we speak.


Download Backtrack 5 R1

UNIVERSAL ALL SOFTWARE KEYGEN GENERATOR



Download Universal Keygen For All Software. Universal Keygen/Serial Key Generator 2012-2013.You can generate most of your software key by using this software. This is a very useful software.

Universal Keygen 2013 is a very much popular key generator in the world. To activate your software you can generate your activation and serial key by using this software. Just Download and Run This Software and Search Your Seral.
Features of Universal Keygen 2013:
Generate all software Serial Key.
Search Your Software Serial Alphabetically.
Find Your Serial Without internet connection easily.

Download Universal KeyGen Generator

JSQL INJECTION V0.2 IS A JAVA TOOL FOR AUTOMATIC DATABASE INJECTION



An easy to use SQL injection tool for retrieving database informations from a distant server.

You can discuss about jSQL Injection on the discussion group.

jSQL Injection features:

GET, POST, header, cookie methods
normal, error based, blind, time based algorithms
automatic best algorithms detection
data retrieving progression
proxy setting
evasion
For now supports MySQL.

Running injection requires the distant server url and the name of the parameter to inject.

If you know an injection should work but the jSQL tool doesn't access the database, you can inform me by email or use the discussion group.

For a local test, you can save the following PHP code in a script named for example simulate_get.php, and use the URL http://127.0.0.1/simulate_get.php?lib= in the first field of the tool, then click Connect to access the database:

<?php
mysql_connect("localhost", "root", "");
mysql_select_db("my_own_database");

$result = mysql_query("SELECT * FROM my_own_table where my_own_field = {$_GET['lib']}") # time based
or die( mysql_error() ); # error based

if(mysql_num_rows($result)!==0) echo" true "; # blind

while ($row = mysql_fetch_array($result, MYSQL_NUM))
echo join(',',$row); # normal
?>

DOWNLOAD

Friday, May 31, 2013

USEFUL THINGS IN BACKTRACK LINUX



I'm trying to write 5 most useful things you should know in Backtrack Linux. Please check it below.


1. About user name and password Backtrack use root for the username and toor for the password. You should provide it at the first time login in your first time installation.


2. startx command Don't shocked if you see the black screen with command only when you use backtrack. Backtrack designed to use command line, but if you want to enable the window, you can type startx command after you log in.


3. Metasploit Framework The most famous tools in Backtrack is Metasploit framework, this tools is used for penetration testing into vulnerable system. You can go to metasploit framework by typing /pentest/exploits/framework3/msfconsole, and there's also /pentest/exploits/framework2/msfconsole.


4. Log Out In Backtrack you cannot restart or shutdown your computer from X-Window. One thing you can do when you finish use backtrack from X-Window is Log Out. To do this, click the Dragon icon at the bottom left of your Backtrack and then Click Log Out.


5. Shutdown and Restart When you finish use the X-Windows, you will be inside the terminal again. To shutdown your Backtrack : poweroff To restart your Backtrack : reboot That's it…very simple right? just try it yourself.

EVILGRADE 2.0 ERROR ON BACKTRACK 5 - SOLVED




I'm running Evilgrade on Backtrack 5 Evilgrade is a modular framework that allows the user to take advantage of poor upgrade implementations by injecting fake updates.


It comes with pre-made binaries (agents), a working default configuration for fast pentests, and has it's own WebServer and DNSServer modules. Easy to set up new settings, and has an autoconfiguration when new binary agents are set.


When I'm trying to running Evilgrade(./evilgrade), there's some error :


./evilgrade


Can't locate Data/Dump.pm in @INC (@INC contains: /etc/perl /usr/local/lib/perl/5.10.1 /usr/local/share/perl/5.10.1 /usr/lib/perl5 usr/share/perl5 /usr/lib/perl/5.10 /usr/share/perl/5.10 /usr/local/lib/site_perl .) at isrcore/Shell.pm line 28.


To solve this error, just run

cpan Data::Dump

in your terminal Finish

SECURE SOCKETS LAYER (SSL) - AN INTRODUCTION



In the OSI model a reference model for effective communication we find a layer named transport layer. Just like a physical layer (where viruses attack normally) transport layer also need some sort of security because transport layer is responsible for transmission of data.


So what actually makes transport layer to make the transmission secure and to protect the data from any intruder.


Have you ever noticed that when you visit some website it starts with http:// and whenever you visit some sort of money transfer and other important websites you find https:// point is clear https means a secure communication it means that your data that transfer from this connection secure by using some cryptography techniques.



SSL or secure sockets layer are cryptographic protocols that provide secure communication over the Internet. So what actually a cryptography is " Cryptography is a science of secrete communication".
SSL uses two keys to encrypt data − a public key known to everyone and a private or secret key known only to the recipient of the message.


                                                         HTTP VS HTTPS



The above picture shows that when ALICE sends the confidential information over insecure channel that there is a chance to sniff this confidential information (it might be a credit card information or may be your password etc). So the point is that an attacker can easily sniff this data and can easily read, understand and use for illegal activities because the data transfer in plain text regardless of any encryption it is simply a HTTP connection.

 



Now consider the second picture when an user send some sort of information over secure channel means if someone using HTTPS than the data first encrypt by using cryptography technique than it sends over channel, so in this case if someone sniff this data than he/she not able to understand it.


The above broad picture has clearly shows that HTTPS is secure, but how HTTPS is secure? Because it uses secure sockets layer (SSL). A website can implement HTTPS by purchasing an SSL Certificate.

Where there's a will there's a way. By following this amazing quote some researcher has discovered some ways to crack/hack SSL certificate too. To hack SSL certificate we will post an article later on.

Thursday, May 30, 2013

C# COLLECTION OF SOURCE CODES – MEGA PACK



I am posting a new pack, this time with C/C++ sources. Many people asked me for C/C++ pack, so here it is.. you can learn a lot from it.

The pack contains the following sources:
------------------------------------------------
Quote:

Port Scanner
Dark Crypter
FireFox 3.6 Decrypter
Agony
Aryan RAT v0.3
Aryan RAT v0.4
Aryan RAT v0.5
Basic Keylogger Source
Black Sun
BlindSpot v1.0 (Binder)
Files Merger
Call Of Duty 6 - Modern Warfare 2 - MPHack
Cryptic3 Crypter
DCI Bot
Down Trojan RAT
Client RAT
El Backdoor Small v1/2.0
Example Drag&Drop
F0xit 0.1
FBI RAT
gh0st 3.6
Harvecter bot
hBot Source
JABT1.2 - Justin Another Binder Tool
Juu2 IE7+FF steal
Little Joiner
Loading DLL infect PE
LocustPEA
Mail Sender - C++
Dump MSN Contacts
Nerzhul
Net Bot Attacker 5.5 RAT+DDOS
Polymorphic crypter
ProAgent V1.21
PsyRAT 2
Rat-b
Ratling
Reptile Bot
Rhapsody reverse connecting RAT
ri0tv5 Bot
UDP Tunnel
SpecialTrojan V5.0
Viotto OCX registrator - Source


Download link (mega pack of source codes):



MediaFire

Wednesday, May 22, 2013

How to make your computer a Server to host a website (Hosting a phishing website)

Steps to make your computer a server to host website from home:





1. Download WampServer and install it in your computer. If you don't know what it is, Wampserver is a simple server with PHP and mysql support which is fully capable of hosting sites in your home computer.


2. Create your website. If you want to make a phishing website within few minutes with both fake login page and php script, read my earlier article on Start Phishing any site in less than 5 minutes.


3. Copy your folder that contains your website files or phishing files and paste them inside "www" directory inside "wamp" folder. Typically it is in C:\wamp\www.


4. Now go to your browser and in the address bar, type "http://localhost". You will be prompted with your wamp page. Just scroll down and click on your folder that you copied in the www directory. That's it, you will see your website running.


5. Wait, it is right now only viewed from your computer. To make it visible to the world, you need to click on the wampserver icon on the taskbar, and then click on "put online".


6. If you have dynamic IP address thus making it difficult to host a website, just go to DynDns.org website. This website allows you to have a host name for dynamic IP address and the service is totally free. So just register with dyndns.org and get a host name for your computer so that even if your IP address changes, the service automatically updates the change to your host settings.


7. If you are behind the router, then you need to login to your router and on the port forwarding option, just write down your IP address and port.


That's it. If you follow these steps, you have successfully made your computer a server to host a phishing website or a legitimate website from home, within an hour. Enjoy!

Start phishing any site in less than 5 minutes

Phishing is certainly an exciting hacking arsenal for any hacker. It is completely a social engineering. It is an art of tricking the user to think that it is a legitimate website while we silently store the login information. So, today I am writing a tutorial on how to setup a complete phishing site so that you can start phishing in less than 5 minutes. So lets start.


First of all, you will need to make an exact replica of the website you are trying to perform phishing. Don't worry, we will use a simple tool that will do all the stuff. Secondly, you need a php script that logs in all the information typed by the user in the form. That's it.



You will need to download "automatic phish creator". The password of the rar file is "hackingguide". All you need to do is just fill in the website name you want to phish. Fill in the name of the php file you will get and the name of the log file you desire. The phishing creator will then create a exact replica of the website and a php script file. That's it. Now you are ready to start phishing.


Now, you will need to host your file to a server. You can use t35.com, awardspace.com or any similar hosts and register a free hosting space. Or you may buy a space. Its your choice. Now, go to the control panel and upload your two files. Then change the permission of the file to "777", i.e. full permission. Now, your site is ready for phishing. Send the link of your site to victims and then when people type in their credential thinking its a real site, you will have their username and password. It is this easy.


Note: Antivirus may alarm the phishing creator software. This is normal. Just turn of your antivirus while you are doing phishing and later turn it on after you are finished..

Tuesday, May 21, 2013

BACKBOX LINUX 3.0






A Linux distribution based on Ubuntu


BackBox is a Linux distro based on the Ubuntu operating system, developed to perform security assessments and penetration tests.

BackBox is designed to be easy to use and fast. It provides a minimal but powerful and complete desktop environment.

What's New in This Release: [ read full changelog ]

· System upgrade
· Bug corrections
· Performance boost
· Improved start menu
· Improved Wi-Fi dirvers (compat-wireless aircrack patched)
· New and updated hacking tools


HOW TO INSTALL FLASHPLAYER ON BACKTRACK 5







Install flash player on Backtrack 5 R2 step by step

Download the file below and click save to save the .deb file like shown in the screen shot

DOWNLOAD flash_player_10_linux.tar


Now type the below inside termianl, make sure you are in the downloads directory first do an ls if needed to make sure.

tar xvfz install_flash_player_10_linux.tar.gz


The result should look like the screenshot below if it went correctly



Now keep terminal open and type in the command below and press enter

mkdir ~/.mozilla/plugins



Last but not least type the command shown below into the same terminal window and press enter

mv -f libflashplayer.so ~/.mozilla/plugins/



Thats it, Flash Player should now be installed and working. Hope you enjoyed this tutorial and it helps someone out...