Tuesday, October 14, 2014

Bikini-clad women and photo tags | Facebook scammers


I have explained about Facebook scamming in my previous posts.  Still people believe that "Facebook will provide Facebook visitors tracker".  If you believe also, please read this article.  This is not only for Facebook users but also for twitter users.



A new Facebook is spreading over the Facebook.  Attacker tag your name in some hot women photos, it will probably displayed in your notifications. You will curious to see the the page.  seeing that page is not going to harm until fall in their net.  Attacker  may post message under photo as "WOW  I can't believe that you can see who is viewing your profile! check it out: link in comment!".  if you follow the link, yes you are one of the Victim of them.

The link lead to malicious Facebook Application.  If you give the permission (by clicking the allow button), it will spread the scam to your friends by posting in the wall.
The attacker use these type of scams for :

  • Tricking you to take online survey-That will give money for scammer.
  • Stealing your cookies (some attacker will ask you to paste the code into address bar).
  • ....

The Truth :
Facebook doesn't provide stalker app(tracks your profile visitors).

Also, any third-party Facebook application is not allowed to  track the visitors. Some Malicious App may claim to offer this facility(but it is not true), it will be banned by Facebook.

This is what Facebook said about Facebook Visitor Tracking:
No, Facebook does not provide the ability to track who is viewing your profile, or parts of your profile, such as your photos. Applications by outside developers cannot provide this functionality, either. Applications that claim to give you this ability will be removed from Facebook for violating policy. You can report applications that provide untrustworthy experiences by clicking the "Report Application" at the bottom of the application’s About page, or by clicking "Report" at the bottom of any canvas page within the application.
Conclusion:
Never believe these type of scams.   I hope you are now clear about Facebook visitors tracking.  Scammers can come in different avatar and they can claim different attractive message(like bin laden photos leaked).  Don't believe those scams blindly. Think twice !! Ask Experts.

Nicole's baby kicking video is a Facebook scam


There is new Facebook scam spreading .  The scam post:
AWESOME Video "Nicole's Baby Kicking - The Belly View - Unbelievable"
[LINK]
An amazing view of a baby kicking and moving his way out of the belly while at the beach.

There is, indeed, a real YouTube video of a heavily pregnant woman called Nicole, sunbathing on a beach. It was posted in May 2009 and has had over 3.5 million views so far.

The thing is, however, if you really want to watch the video: go to YouTube.

Don't click on the link being spread across Facebook. Because if you do, you are taken to a third-party website which insists you have to share the link with your Facebook friends before you can watch the video clip.

it was advertising the controversial Scientology organisation. One wonders if the scammers are earning revenue by driving traffic to the page.

You should always be suspicious of links like this being shared by your Facebook friends. The safest place to watch "viral" videos is on YouTube itself (and other established video websites such as Vimeo), or you could find yourself being asked to complete money-making surveys or imparting your personal information.

Tips from Nakedsecurity

Advanced Tabnabbing -Phishing Attack simplified


What is Tabnabbing ? 
Tabnabbing is Phishing attack that simplifies the phishing.The attack's name was coined in early 2010 by Aza Raskin, a security researcher and design expert.  This will reload the inactive tabs with fake page .

How The Attack Works ?
  • A user navigates to your normal looking site.
  • A malicious code detect when the page has lost its focus and hasn’t been interacted with for a while.
  • Replace the favicon with the Gmail favicon, the title with “Gmail: Email from Google”, and the page with a Gmail login look-a-like. This can all be done with just a little bit of Javascript that takes place instantly.
  • As the user scans their many open tabs, the favicon and title act as a strong visual cue—memory is malleable and moldable and the user will most likely simply think they left a Gmail tab open. When they click back to the fake Gmail tab, they’ll see the standard Gmail login page, assume they’ve been logged out, and provide their credentials to log in. The attack preys on the perceived immutability of tabs.
  • After the user has entered their login information and you’ve sent it back to your server, you redirect them to Gmail. Because they were never logged out in the first place, it will appear as if the login was successful.

Targeted Attacks:

Using my CSS history miner you can detect which site a visitor uses and then attack that site (although this is no longer possible in Firefox betas). For example, you can detect if a visitor is a Facebook user, Citibank user, Twitter user, etc., and then switch the page to the appropriate login screen and favicon on demand. 

Even more deviously, there are various methods to know whether a user is currently logged into a service. These methods range from timing attacks on image loads, to seeing where errors occur when you load an HTML webpage in a script tag*. Once you know what services a user is currently logged in to, the attack becomes even more effective.

You can make this attack even more effective by changing the copy: Instead of having just a login screen, you can mention that the session has timed out and the user needs to re-authenticate. This happens often on bank websites, which makes them even more susceptible to this kind of attack.

You can get this code from here:
http://www.azarask.in/projects/bgattack.js

How to protect yourself from this hack?
  • You can use a safe browser that uses anti-javascript plugins (Firefox with noscript). Note: Advanced Tabnabbing will work even javascript is not enabled. 
  • Check the url in the address bar.
  • If you got link in emails, enter the url in address bar instead of clickin it.
  • You can use some Anit Phishing add ons like(Don't Phish me,Netcraft,FirePhish) .

New Facebook Hacking Tool ~Stealing Facebook profile information

A new facebook hacking tool is released .  It can steal the information from victims like photos,friends list and other information.  Using that , an attacker is able to create fake profile page or they may get enough information to hack your accounts(security question).

Here is the full detail about the Tool:
Facebook Profile Dumper

This is for educational purpose only.  Prevent you from attackers.  Don't accept invitation from stranger. Even if you get request from your friends, verify whether it is real profile or fake.

How to Hack the Windows Admin Password Using OphCrack in Backtrack tutorial


In this post, i am going to help you to crack the any type of windows accounts passwords. Learn how to hack the windows admin password like a geek.

This is My Second Backtrack Linux Tutorial.
[see the screen shots of this tutorial ]

Refer this link also: How to hack the windows 7 or vista using the following method

Requirements:
  • BackTrack Linux 4 or 5. Download it from http://backtrack-linux.org
  • One pen drive(above 4gb)
  • Xp Free Fast RainBow table [tables_xp_free_fast.zip]. Download it from here:http://ophcrack.sourceforge.net/tables.php 
*Install the Backtrack Linux in the pen drive with small amount of persistent memory.

Step 1: Booting From Back Track 
Insert the pen drive in target computer[when turned off].  We are going to boot the operating system from pen drive, so insert when the system is turned off.
Now Turn on the system. 
Press F10 [boot menu, differs for system]  before booting and select boot from Pen drive.  
Now it will boot the Backtrack. 
Select "Graphical User Interface "
Now wait for a while ( it will execute some commands}
Now you can see the "root:" 
type "startx" and hit enter.  It will bring you to the GUI view of Backtrack.

Step 2:Copy the SAM and System files
Click the  Start button(dragon symbol)
Select System Menu
Select Storage Media(if you see nothing, close the window open it again).

You can see the list of Hard disk and Your pen drive.
Open the windows installed Hard disk and Navigate to this path:
WINDOWS/system32/config/

There you can see two files named as "SAM" and "System".  

Copy the both SAM and system files .
[ Just proceed to next step without closing the window]

Create a new folder in the desktop and paste the files inside.

Step 4: Run OphCrack Tool in Backtrack
Open the ophcrack GUI(start->Backtrack->Privilege Escalation->Password Attack->offline Attacks-ophCrack GUI).

Step 5: Loading the folder that contains sam and system files

Click the Load and select "Encrypted SAM" in ophcrack tool.
Now it will ask you to select directory that contains SAM folder. Select the directory where you saved the SAM file.

Now it will load and display the list of user accounts in the windows.

Step 6: Target the Admin Account
Here i am going to hack the one of the administrator account of my computer. So remove all other accounts except the target admin account.

Step 7: The Rainbow Table

Extract the "tables_xp_free_fast.zip" file in the desktop.


Click the Table button in ophcrack tool. Now it will ask you to selec the table.  Select the "XP free fast" and click the install button. Now browse to the Rain bow table directory "tables_xp_free_fast"
Now click ok.

Step 8: Cracking Begins
Click the Crack button.
Wait for a while [ophcrack is the fastest cracking tool. so it won't take too much time]

Step 9: Password is cracked
Yes..!! we got the password. 

Don't forget to share with your friends. 

Screen shots :
Screen shots windows Admin Password Cracking

HOW TO SEND ANONYMOUS EMAIL


Everyone Like to send Anonymous Mail to your enemy or friend or teacher.  Here is the Hacking tutorial for you to implement that.  So i hope This will be best hack for you.

What is the Use?
   I explained you in my older post how to get ip address.  To get the ip address you need to send the mail with link.  So You can send mail to your victim with that link such that you are contacting from an organization.

For Eg:
You can say we are from Facbook,we have new feature to enable the feature visit this page.

How to do? 

Step 1:
First of all you need to register in free web hosting service which has PHP feature.  So my choice is


Step 2:
Now Download this zip file:

             Mail.php
Inside the file you can find the mail.php file. Extract the file

Step 3:
Now Go to x10hosting.com and login with your username and password.
Upload the "mail.php" file to "public_html" folder.

Step 4:
That's all you finished. 
Now go to this page
         yourhosturl/mail.php
Change the yourhosturl with your website url which you gave it when you register in x10hosting.com
For eg:
yourfavorites.x10.mx/mail.php

Usually the default will be "name.x10.mx"

When you visit you will see the form just like this:


Fill the form with your victim mail address and message subject and send

     Don't give your details in the sender field.
Just fill with any organization name.
For Eg:
BestSurveyProviders


         If you have any doubts or want to say thanks,please comment me

Thursday, May 17, 2012

HOW TO USE BLACKBERRY AS A MODEM ON PC

Today, while looking for a Modem to Browse to no Avail, I decided to use my Blackberry Phone as a Modem to Surf tthe Internet.. Can you Imagine, Blackberry as a Modem Internet Speed is 3x faster than that of the Original Internet Modem.. But i bet less than 5% of Blackberry users use their Phone as Modem! I Trust the Nokia Fans on this Level.
Though Most People dont use Blackberry as a Modem to Browse on PC because they see it as a very Technical stuff, We are gonna put you on the Right Lane yet a very Fast Track.
This Tutorial will guide you through the quick steps needed to configure your BlackBerry Desktop Manager’s mobile internet settings and thus get you connected to the web. Please note that you’ll need to have another data plan with your network provider as you cannot use your BIS to surf the internet on your desktop/laptop.
NOTE: You have to be Subscribed to the Internet on any of the Data Plan of your Network that Suit you e.g 100MB for N1000 Monthly. After subscribing to your plan of choice, please take note of the Internet Settings of that particular network as you’d be needing it now. You can check Here for that.
FOLLOW THIS INSTRUCTION ON HOW TO GET STARTED USING YOUR BLACKBERRY AS A MODEM
1. Download & Install Blackberry Desktop Manager Here or check your Phone Pack for the CD that came with it.
2. Launch the BlackBerry Desktop Manager after Installation and Click to Tools in the menu bar section. Select "Mobile Internet Settings" from the drop down menu as shown below.

You will see different Networks on the Profile Drop-down, Click on the "Add Custom Profile" to define your own Network settings because Nigeria's Network are not on the List.
Use this As your Settings depending on your Network.

 
MTN
GLO
ETISALAT
AIRTEL
Profile Name: MTN NG GLO NG ETISALAT NG AIRTEL NG
Username: web flat etisalat internet
Password: web flat etisalat internet
Access Point: web.gprs.mtnnigeria.net gloflat etisalat internet.ng.airtel.com
Add Commands:        
Once you are done, hit the OK button to exit the small popup screen then OK again to exit the Mobile Internet Settings configuration dialog.
3. Now Go back to Menu >> Tools and click on Start Mobile Internet

4. A warning will show informing you that you will be Charged, Just Ignore it if you've already Subscribed. Just Click on Connect
5.Once your are Successfully Connected to the Internet and you are Ready to Browse, at the bottom left of the BlackBerry Desktop Manager, you should see something that looks like the capture below ( Time Connected and Data Used ). It means you are now connected.

=> Thats All... Don't Forget to Share this Tutorial with Your Friends!!