Showing posts with label hacking. Show all posts
Showing posts with label hacking. Show all posts

The Mole v0.3 - SQL Injection Exploitation Tool

2:01 PM Add Comment
The Mole v0.3 - SQL Injection Exploitation Tool

The Mole is an automatic SQL Injection exploitation tool. Only by providing a vulnerable URL and a valid string on the site it can detect the injection and exploit it, either by using the union technique or a boolean query based technique.

Features
  • Support for injections using Mysql, SQL Server, Postgres and Oracle databases.
  • Command line interface. Different commands trigger different actions.
  • Auto-completion for commands, command arguments and database, table and columns names.
  • Support for filters, in order to bypass certain IPS/IDS rules using generic filters, and the possibility of creating new ones easily.
  • Exploits SQL Injections through GET/POST/Cookie parameters.
  • Developed in python 3.
  • Exploits SQL Injections that return binary data.
  • Powerful command interpreter to simplify its usage. 
Download The Mole v0.3 : http://themole.nasel.com.ar
via| security-sh3ll

Microsoft Store India Hacked

4:02 PM Add Comment
Microsoft Store India Hacked

Hari ini, Hacker dari kelompok EvilShadow berhasil meng-hack dan men-deface website Microsoft Store India (http://www.microsoftstore.co.in). Tapi Hacker meng-upload halaman deface di lokasi http://www.microsoftstore.co.in/ evil.html.

Hacker mengungkapkan bahwa password pengguna disimpan dalam teks biasa seperti berikut:

Microsoft Store India Dibobol Hacker

Download Ani-Shell v1.5 Final

4:49 PM Add Comment
Ani-Shell v1.5 Final

Ani-Shell is a simple PHP shell with some unique features like Mass Mailer , A simple Web-Server Fuzzer , a DDoser etc! This shell has immense capabilities and have been written with some coding standards in mind for better editing and customization.

Features:
  • Shell
  • Mass Mailer
  • DDos
  • Web-Server Fuzzer
  • Uploader
  • Design
  • Login
  • Mass Code Injector (Appender and Overwriter)
  • Encoded Title
  • Back Connect
  • Bind Shell
  • Lock Mode Customisable
  • Tracebacks (email alerts)
  • PHP Evaluate
  • PHP MD5 Cracker
  • Anti-Crawler
  • Mass Deface
New in This Version :
  • Better CSS
  • Intelligent File Manager
  • Auto Rooter
  • PHP Obfuscater
  • Google Dork Creator
  • Zip Downloader (Download any File or Directory from the web-server)
  • Fixed the Memory Exhausted Error in MD5 Cracker
login : lionaneesh
pass : lionaneesh

Facebook Hacker Cup

10:45 AM Add Comment
Facebook Hacker Cup

Kesempatan emas bagi Anda, para coder yang memiliki keterampilan dalam pemrograman komputer. Karena, Facebook sedang mengadakan kompetisi untuk mencari jawara Hacker yang berasal dari seluruh dunia, melalui gelaran kali kedua tantangan Hacker Cup.

Para hacker akan melewati lima putaran tantangan pemrograman dan harus bersaing satu sama lain. Tantangan pertama dimulai pada 20 Januari 2012, untuk babak kualifikasi selama 72 jam. Bagi mereka yang lolos, akan melalui tiga putaran tantangan secara online, sebagai proses penyaringan mencari 25 peserta terbaik.

Babak online tersebut menjadi penentu para hacker untuk melanjutkan pertandingan akhir yang akan digelar pada Maret 2012 nanti. Hacker yang menjadi peserta akan diterbangkan dari Negara asalnya menuju Menlo Park Facebook di California, sebagai markas perhelatan tantangan final.


“Hacking adalah inti bagaimana kita membangun Facebook. Apakah kita sedang membangun prototipe untuk suatu produk besar seperti Timeline, menciptakan suatu algoritma pencarian yang cerdas, atau meruntuhkan dinding di kantor pusat baru. Kami selalu hacking untuk mencari cara yang lebih baik dalam memecahkan masalah, ” ujar pihak perusahaan Facebook dalam postingan blog di situs resminya.

Pengumuman mengenai kompetisi Hacker Cup secara gamblang tertulis pula dalam blog Facebooktersebut. Pemenang dalam tantangan ini akan mendapatkan hadiah uang tunai sebesar $ 5.000. Hacker Cup tahun lalu diikuti oleh sekitar 12.000 coder. Seorang karyawan Google asal Rusia, Mitrichev, menjadi pemenangnya.

Kompetisi serupa lebih dulu dilakukan oleh Google melalui kontes tahunan yang dinamakan Code Jam, dimana Mitrichev menjadi jawaranya pada 2006. Melalui gelaran kompetisi ini, biasanya perusahaan teknologi memiliki motif tersembunyi untuk mendapatkan programmer terampil dan handal, untuk direkrut sebagai karyawan. via | sidomi

Download Cain & Abel v4.9.43

5:45 PM Add Comment
Cain & Abel is a password recovery tool for Microsoft operating systems.It allows easy recovery of various kind of passwords by sniffing the network, cracking encrypted passwords using dictionary and brute force attacks, decoding scrambled passwords, revealing password boxes, uncovering cached passwords and analyzing routing protocols.

Download Cain & Abel v4.9.43

Change Log :

  • Added SAP R/3 sniffer filter for SAP GUI authentications and SAP DIAG protocol decompression.
  • Added support for Licensing Mode Terminal Server connections to Windows 2008 R2 servers in APR-RDP sniffer filter.
  • Added support for MSCACHEv2 Hashes (used by Vista/Seven/2008) in Dictionary and Brute-Force Attacks.
  • Added MSCACHEv2 Hashes Cryptanalysis via Sorted Rainbow Tables.
  • Added MSCACHEv2 RainbowTables to WinRTGen v2.6.3.
  • MS-CACHE Hashes Dumper now supports MSCACHEv2 hashes extraction from Windows Vista/Seven/2008 machines and offline registry files.
  • Fixed a bug (crash) in Certificate Collector with Proxy settings enabled.
Download Cain & Abel v4.9.43

Acunetix 8, What’s New? (VIDEO)

3:41 PM Add Comment
The next big release of Acunetix Web Vulnerability Scanner is in Beta, and will soon be safeguarding thousands of web applications and businesses. This brief presentation highlights the exciting new features in Acunetix WVS 8; we look forward to your comments.

Download XSSer v.1.6 BETA

4:58 PM Add Comment
XSSer v.1.6 BETA

Cross Site "Scripter" is an automatic -framework- to detect, exploit and report XSS vulnerabilities in web-based applications.It contains several options to try to bypass certain filters, and various special techniques of code injection.

Changelog

Core: Added Drop Cookie option + Added Random IP X-Forwarded-For an X-Client-IP option + Added GSS and NTLM authentication methods + Added Ignore proxy option + Added TCP-NODELAY option + Added Follow redirects option + Added Follow redirects limiter parameter + Added Auto-HEAD precheck system + Added No-HEAD option + Added Isalive option + Added Check at url option (Blind XSS) + Added Reverse Check parameter + Added PHPIDS (v.0.6.5) exploit + Added More vectors to auto-payloading + Added HTML5 studied vectors + Fixed Different bugs on core + Fixed Curl handlerer options + Fixed Dorkerers system + Fixed Bugs on results propagation + Fixed POST requests. GTK: Added New features to GTK controller + Added Detailed views to GTK interface. (via)

The Mole, Automatic SQL Injection Exploitation Tool

4:53 PM Add Comment
The Mole, Automatic SQL Injection Exploitation Tool

The Mole is an automatic SQL Injection exploitation tool. Only by providing a vulnerable URL and a valid string on the site it can detect the injection and exploit it, either by using the union technique or a boolean query based technique. 

Features :
  • Support for injections using Mysql, SQL Server, Postgres and Oracle databases.
  • Command line interface. Different commands trigger different actions.
  • Auto-completion for commands, command arguments and database, table and columns names.
  • Support for query filters, in order to bypass certain IPS/IDS rules using generic filters, and the possibility of creating new ones easily.
  • Developed in python 3.
If you want to know how to use The Mole there’s a good tutorial here.

You can download The Mole here:
Or read more herevia darknet

Download WPScan v.1.1

5:24 PM Add Comment
WPScan v.1.1

WordPress Security Scanner, WPScan is a vulnerability scanner which checks the security of WordPress installations using a black box approach.

Changelog
  • Detection for 750 more plugins. 
  • Detection for 107 new plugin vulnerabilities.
  • Detection for 447 possible timthumb file locations. 
  • Advanced version fingerprinting implemented. 
  • Full Path Disclosure (FPD) checks.
  • Auto updates.
  • Progress indicators.
  • Improved custom 404 checking.
  • Improved plugin detection. 
  • Improved error_log checking. 
  • Lots of bugs fixed. Lots of small tweaks. 


sqlsus 0.7.1-MySQL Injection & Takeover Tool

7:32 PM Add Comment
sqlsus 0.7.1-MySQL Injection & Takeover Tool

sqlsus is an open source MySQL injection and takeover tool, written in perl. Via a command line interface, you can retrieve the database(s) structure, inject your own SQL queries (even complex ones), download files from the web server, crawl the website for writable directories, upload and control a backdoor, clone the database(s), and much more…Whenever relevant, sqlsus will mimic a MySQL console output.

sqlsus focuses on speed and efficiency, optimising the available injection space, making the best use (I can think of) of MySQL functions. It uses stacked subqueries and an powerful blind injection algorithm to maximise the data gathered per web server hit. Using multithreading on top of that, sqlsus is an extremely fast database dumper, be it for inband or blind injection.If the privileges are high enough, sqlsus will be a great help for uploading a backdoor through the injection point, and takeover the web server.

It uses SQLite as a backend, for an easier use of what has been dumped, and integrates a lot of usual features (see below) such as cookie support, socks/http proxying, https..

What’s New

Starting with version 0.7, sqlsus now supports time-based blind injection and automatically detects web server / suhosin / etc.. length restrictions.

  • Added time-based blind injection support (added option “blind_sleep”, and renamed “string_to_match” to “blind_string”).
  • It is now possible to force sqlsus to exit when it’s hanging (i.e.: retrieving data), by hitting Ctrl-C more than twice.
  • Rewrite of “autoconf max_sendable”, so that sqlsus will properly detect which length restriction applies (WEB server / layer above). (removed option “max_sendable”, added options “max_url_length” and “max_inj_length”)
  • Uploading a file now sends it into chunks under the length restriction.
  • sqlsus now saves variables after each command, so that forcing it to quit (or killing it) will not discard the changes that were made.
  • Added a progress bar to inband mode, sqlsus now determines the number of rows to be returned prior to fetching them.
  • get db (tables/columns) in inband mode now uses multithreading (like everything else).
  • clone now uses count(*) if available (set by “get count” / “get db”), instead of using fetch-ahead.
  • In blind mode, “start” will now test if things work the way they should, by injecting 2 queries : one true and one false.
  • sqlsus now prints what configuration options are overridden (when a saved value differs from the configuration file).

You can download sqlsus 0.7.1 here : sqlsus-0.7.1.tgz

Or read more here.

sqlsus 0.7.1 MySQL Injection & Takeover Tool via | darknet

PHP Vulnerability Hunter v.1.1.4.6

4:31 PM Add Comment
PHP Vulnerability Hunter v.1.1.4.6 

PHP Vulnerability Hunter is an advanced automated whitebox fuzz testing tool. 

This is the application that detected almost all of the web application vulnerabilities listed on the advisories page. PHP Vulnerability Hunter is an advanced automated whitebox fuzz testing tool capable of triggering a wide range of exploitable faults in PHP web applications. Minimal configuration is necessary to begin a scan; PHP Vulnerability Hunter doesn’t even need a user specified starting URI. (via)

ChangeLog: 
Added code coverage report
Updated GUI validation
Several instrumentation fixes
Fixed lingering connection issue
Fixed GUI and report viewer crashes related to working directory

Download PHP Vulnerability Hunter v.1.1.4.6 : http://code.google.com

Acunetix Web Vulnerability Scanner 8 BETA

2:16 PM Add Comment
Acunetix Web Vulnerability Scanner 8 BETA

The next stage in the evolution of Acunetix Web Vulnerability Scanner has arrived — WVS 8 BETA! Many of you have been biting their nails in anticipation of this Beta, so sit tight and read on for the next most important stage in the evolution of Acunetix WVS. Version 8 of Web Vulnerability Scanner has been optimized to make life easier at every stage of a security scan. WVS is easier to use for web admins and security analysts alike: enhanced automation, ability to save scan settings as a template to avoid reconfiguration, and multiple instance support for simultaneous scans of several websites. WVS 8 also ushers in a new exciting co-operation between Acunetix and Imperva: developers of the industry’s leading Web Application Firewall.

Download Sqlninja v.0.2.6

4:28 PM Add Comment
Sqlninja v.0.2.6

Sqlninja's goal is to exploit SQL injection vulnerabilities on web applications that use Microsoft SQL Server as back end.There are a lot of other SQL injection tools out there but sqlninja, instead of extracting the data, focuses on getting an interactive shell on the remote DB server and using it as a foothold in the target network. In a nutshell, here's what it does: 

  • Fingerprint of the remote SQL Server (version, user performing the queries, user privileges, xp_cmdshell availability, DB Server authentication mode)
  • Bruteforce of the 'sa' password
  • Privilege escalation to 'sa'
  • Creation of a custom xp_cmdshell if the original one has been disabled
  • Upload of executables
  • Reverse scan in order to look for a port that can be used for a reverse shell
  • Direct and reverse shell, both TCP and UDP
  • DNS tunneled pseudoshell, when no ports are available for a bindshell
  • ICMP tunneled shell, if the target DBMS can communicate via ICMP Echo with the attacking machine
  • Metasploit wrapping, when you want to use Meterpreter or even want to get GUI access on the remote DB server
  • OS privilege escalation on the remote DB server using token kidnapping or through CVE-2010-0232
  • All of the above can be done with obfuscated SQL code, in order to confuse IDS/IPS systems.
Download Sqlninja v.0.2.6 : http://sqlninja.sourceforge.net | via security-sh3ll

OWASP Zed Attack Proxy (ZAP) v.1.3.4

4:23 PM Add Comment
OWASP Zed Attack Proxy

The Zed Attack Proxy (ZAP) is an easy to use integrated penetration testing tool for finding vulnerabilities in web applications.It is designed to be used by people with a wide range of security experience and as such is ideal for developers and functional testers who are new to penetration testing.ZAP provides automated scanners as well as a set of tools that allow you to find security vulnerabilities manually. 

Some of ZAP's features: 
  • Intercepting Proxy 
  • Active scanner 
  • Passive scanner 
  • Brute Force scanner 
  • Spider 
  • Fuzzer 
  • Port Scanner 
  • Dynamic SSL certificates 
  • API 
  • Beanshell integration 

Project Page OWASP Zed Attack Proxy (ZAP) v.1.3.4: https://www.owasp.org
Download OWASP Zed Attack Proxy (ZAP) v.1.3.4: http://code.google.com

XSS Vulnerability in White House Website

3:11 PM Add Comment
XSS Vulnerability in White House Website

The Hacker News: Alexander Fuchs, A German Security Researcher Discover Persistent XSS Vulnerability in Official website of White House.

"The petition system is vulnerable. Every Petition i start or join will execute my code. I could join all petitions and my code will be executed on all users who visit the petition system." He said.




Download Freegate and GProxy Tool

5:28 PM Add Comment
Download Freegate and GProxy Tool

d4wfl1n.nyubicrew.us : Sebuah software yang berguna untuk melakukan triks dengan menggunakan proxy, bukan manual tp penulisan proxynya secara otomatis. Software tersebut adalah “Freegate” program ini di negara asalnya, china program ini paling banyak digunakan untuk koneksi internet karena lebih cepat dan lebih stabil. 


  • Pertama tama instal browser mozilla firefox dulu.
  • Lalu setelah selesai didownload jalankan program.
  • Tunggu sebentar sampai pencarian server selesai lalu jendela IE akan otomatis muncul, close aja lalu buka mozilla firefoxnya sebelum itu buka freegatenya lalu pilih tab server lalu pilih server yang kecepatannya paling tinggi.
  • GProxy Tools yang telah di download, file tersebut kamu drag ke browser mozilla kamu, lalu klik install now setelah selesai klik restart mozilla.
  • Setelah mozilla terbuka coba lihat toolbar bagian proxy, pilih Freegate lalu klik apply.
  • Yang terakhir silahkan berbrowsing ria dengan kecepatan yang lumayan, tergantung server yang dipilih.

Note : Trik ini tidak akan membuat koneksi internet di komputer lain yang ada di warnet tidak akan lambat, jadi aman-aman saja bila digunakan.

Download Websecurify v.0.9

2:55 PM Add Comment

Download Websecurify v.0.9
Websecurify is a powerful web application security testing platform designed from the ground up to provide the best combination of automatic and manual vulnerability testing technologies. 

Websecurify 0.9 is de facto not only the first web application security testing software ever created for iOS, Android, Blackberry and others, but it is also the very first fully functional integrated web application security testing solution which can run straight from your web browser. This release is perhaps one of the most cross-platform software solutions you will encounter today and we are proud to be the first to do it, putting our orange flag in the history books forever. (via)

Download : Websecurify v.0.9 
Home Page :  http://websecurify.com

Nmap 5.61 TEST1 Released

6:29 PM Add Comment

Nmap 5.61 TEST1

Nmap 5.61 TEST1 Released | This Nmap 5.61TEST1 is an informal test release with all of the latest features from the SVN. Nmap (“Network Mapper”) is a free and open source utility for network exploration or security auditing. Many systems and network administrators also find it useful for tasks such as network inventory, managing service upgrade schedules, and monitoring host or service uptime. 

Nmap uses raw IP packets in novel ways to determine what hosts are available on the network, what services (application name and version) those hosts are offering, what operating systems (and OS versions) they are running, what type of packet filters/firewalls are in use, and dozens of other characteristics. It was designed to rapidly scan large networks, but works fine against single hosts. Nmap runs on all major computer operating systems, and official binary packages are avalable for Linux, Windows, and Mac OS X. In addition to the classic command-line Nmap executable, the Nmap suite includes an advanced GUI and results viewer (Zenmap), a flexible data transfer, redirection, and debugging tool (Ncat), and a utility for comparing scan results (Ndiff). (via)

NetworkMiner v1.1 Released, Windows Analyzer & Sniffer

5:58 PM Add Comment

NetworkMiner v1.1

NetworkMiner v1.1 Released, Windows Analyzer & Sniffer | NetworkMiner is a Network Forensic Analysis Tool (NFAT) for Windows. NetworkMiner can be used as a passive network sniffer/packet capturing tool in order to detect operating systems, sessions, hostnames, open ports etc. without putting any traffic on the network. NetworkMiner can also parse PCAP files for off-line analysis and to regenerate/reassemble transmitted files and certificates from PCAP files. 

The new version supports features such as:
* Extraction of Google Analytics data
* Better parsing of SMB data
* Support for PPP frames
* Even more stable than the 1.0 release 


You can download NetworkMiner v1.1 here:


Or read more here.

ExploreCrew Hacking Contest

2:48 PM Add Comment

ExploreCrew Hacking Contest

ExploreCrew Hacking Contest

Dalam rangka memperingati sekaligus memeriahkan Hari Kesaktian Pancasila, XCrew Hacking Contest 2011 di buka. Dengan misi-misi di masing-masing level yang cukup menantang dan menarik. Agar lebih menarik, kami menawarkan hadiah yang cukup menarik.

Hacking Mission
Hacking Mission sudah kami sediakan. Silahkan melewati semua misi yang kami sediakan. Dengan cara kalian sendiri. Suka-suka kalian sendiri. Gunakan segala kemampuan hacking anda. Tembus semua misi. Total kesemuanya ada 8 misi yang masing-masing mempunyai tingkat kesulitan yang berbeda. Ada yang mudah dan ada yang sulit. Logika yg benar sangat di perlukan untuk menyelesaikan semua misi.

Hadiah

Berikut hadiah yang kami sediakan:

Art of Intrusion By Kevin D Mitnick
[+] Hacker Handbook: Art of Intrusion By Kevin D Mitnick
[+] Domain dan Hosting 2GB max 4 Tahun
[+] Domain dan hosting 1 Tahun
[+] Wireless router
[+] Camera Digital
[+] (dan kemungkinan akan di tambah lagi)

Khusus email, diberikan kepada semua peserta yang lolos semua level.

Aturan Main

[+] Register (jika member forum.explorecrew.org, silahkan msg kami untuk kami set status di forum sebagai contestan)
[+] Selesaikan semua misi
[+] Boleh menggunakan segala macam hacking technik
[+] Perlombaan dimulai tanggal 1 Oktober 2011 jam 12:00
[+] Dilarang bagi-bagi kerpekan secara terbuka
[+] Hadiah tidak berlaku setelah tanggal 1 November 2011
[+]Melebihi tanggal tersebut, hacking contest tetap dibuka tetapi tanpa hadiah, sebagai gantinya akan dimasukan hall of fame di forum


Silahkan mendiskusikan semua masalah Hacking Contest 2011 disini 

(via)