Pakistani Hacker hacks Kevin Mitnick

>> Saturday, August 15, 2009

On 21th August Kevin Mitnick the legendary hacker of the 90’s who got sent to jail for his suspicious social engineering based hacking activities for a five-year prison term in 1995 was at this week at the receiving end of a massive defacement of four of his websites defensivethinking.com (Defacement) , mitsec.com (Defacement), kevinmitnick.com (Defacement) & mitnicksecurity.com (Defacement).

Hacking has been a part of the Internet practically from its inception back in the 80’s, in my heydays of computer wonders I was fascinated by the simplisticly of hacking Win 95 and 98 systems by simple tools like BO2K and other awesome Trojan stuff. My effort was very limited to a few simple steps but was simply mesmerized at what could have been done had I known a little of Unix and an intricate knowledge of coding. I have always considered hacking as an important factor in the continued development of this infrastructure we have come to live on called the world wide web, to be honest if there were no destructive forces attempting to take down the system who would have bothered to continuously revolutionize this technology which in turn spurns new inventions and creations which have come to impact our daily life. One has to take the good with the bad, and sincerely hope that the good elements continue to over shadow the evil side.

The sites under question have been hacked by FBH (Federal Bureau of Hackers) (website??) who have been operating since 2002 in their previous defacements they have been supporting the cause of Kashmir and been ridiculing the Indian Prime Minister Vajpayee (Defacement – Sony Music.com).

I personally would not be too proud of FBH being a Pakistani as it tends to cast a bad name for my country, especially in this ever-paranoid post 9/11 era where every brown skin Muslim is suspected for being an Al-Qaeda operative. Lets work to keep Pakistan in the good books until the image of a peace loving nation restores confidence in the world, we all have to work hard.

Read more...

The First Mobile Botnet?

>> Wednesday, August 12, 2009

Assuming the iPhone exploit described above was able to make it into the wild, it could effectively compromise all the unprotected iPhones in the world (which, in theory, would be all of them, if no patch is distributed). The hack would essentially turn the phones into "zombies" - a term usually used to refer to PCs compromised by a hack, virus, or trojan horse in order to do the bidding of a hacker. Along with other compromised PCs like them, this group of computers would form a botnet of "zombie" machines.
While botnets are common in the PC world - it's estimated that these machines are used to send anywhere from fifty to eighty percent of spam worldwide - botnets consisting of mobile phones are practically unheard of...or are they?
Earlier this month, Symantec revealed an SMS threat dubbed "Sexy Space" created using malware known as SymbOS.Exy.C, a revision of older variations also used to create similar threats. Using simple social engineering tactics, this hack involves sending SMS spam with names like "Sexy View," "Sexy Girl," and "Sexy Space" to encourage victims to click an included link in the text message.
[Image]
This particular exploit, only found on Symbian-powered devices so far, is smart enough to end certain programs on the hijacked phone that would make it possible to manually end the threat. At first, the hack was only being seen in China, but later an English version was discovered in the Middle East.
What's most frightening about this particular threat is that it's controlled by a central server. That means hackers could control the attacked phones the same way hackers today control zombie PCs. This led the Symantec researchers to wonder if this was, in fact, the first case of a mobile botnet being spotted in the wild.

Read more...

The iPhone SMS Hack

According to Forbes, the SMS exploit being demonstrated at Black Hat today involves sending short, mostly invisible SMS bursts which would allow a potential hacker to entirely take over the phone. The only warning you would have to alert you to the hack would be a text messaging that contained a single square character. If you received something like that, your only recourse would be to turn the phone off immediately.
The researchers said they alerted Apple to this vulnerability over a month ago, but no patch has been released. Apple isn't returning calls requesting a comment, either

Read more...

The Future security mobile botnets take over ipone just with A SMS

Today at the cybersecurity conference known as Black Hack, researchers Charlie Miller and Collin Mulliner will present an SMS exploit that could take over your iPhone with just one text. Once the phone is compromised, the hacker would have access to all the functions on the phone allowing them to send email, access your contacts, make phone calls, and of course, send text messages that would send the exploit to more devices.
This serious vulnerability (which apparently Apple sat on for over a month) is probably the first time that most people have heard of mobile phones being used to create botnets. However, this isn't the first sighting of a mobile phone hijacking attempt for the purpose of botnet creation - a similar exploit was discovered earlier this month. Does this mean we're on the verge of a new and dangerous trend: the creation of "zombie" phones?

Read more...

Open command prompt from where it is Banned

>> Saturday, August 01, 2009

Open up Command Prompt (Start>Run>Command.com)
Can't use command prompt at your school?
Open up Microsoft word..Type:
Command.com
Then save it as Somthing.bat.
Warning: Make sure you delete the file because if the admin finds out your in big trouble.
--Adding a user to your network--
Type:
Net user Haxxor /ADD
-----
That will add "Haxxor" onto the school user system.
-----
Now you added users lets delete them!
Type: Net user Haxxor /DELETE
Warning: Be carefull it deletes all their files.
-----
"Haxxor" will be deleted from the user system.
-----
Hmmm? It says access denied?
Thats because your not admin!
----
Now lets make your Admin!
----
This will make Haxxor an admin. Remember that some schools may not call their admins 'adminstrator' and so you need to find out the name of the local group they belong to.
Type: net localgroup
It will show you what they call admin, say at my school they calll it
adminstrator so then i would
Type: net localgroup administrator Haxxor /ADD
----
Getting past your web filter.
Easy way: Type whatever you want to go on say i wanted to go on miniclips bug on wire i would go to google and search miniclip bug on wire
then instead of clicking the link i would click "cached".
Hard way: I'm hoping you still have command prompt open.
Type: ping miniclip.com
And then you should get a IP type that out in your web browser, and don't forget to put "http://" before you type the IP.
-----
Sending messages throught your school server
Okay, here's how to send crazy messages to everyone in your school on a computer. In your command prompt, type
Net Send * "The server is h4x0r3d"
Note: may not be necessary, depending on how many your school has access too. If it's just one, you can leave it out.
Where is, replace it with the domain name of your school. For instance, when you log on to the network, you should have a choice of where to log on, either to your school, or to just the local machine. It tends to be called the same as your school, or something like it. So, at my school, I use
Net Send Haxxor School * "The server is h4x0r3d"
The asterisk denotes wildcard sending, or sending to every computer in the domain. You can swap this for people's accounts, for example
NetSend Varndean dan,jimmy,admin "The server is h4x0r3d"
use commas to divide the names and NO SPACES between them.
what say??
~Cheers~

or

Allowing dos and regedit in a restricted Windows

A very simple tactic I found after accidentally locking myself out of dos and regedit is to open notepad and type the following:

REGEDIT4
[HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionPoliciesWinOldApp]
"Disabled"=dword:0
[HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionPoliciesSystem]
"DisableRegistryTools"=dword:0

Save it as something.reg then run it. Simple.

Read more...

How to Hack using Keylogger

The best and easy way to hack in to any email account or spy your friend account is trough keyloggers in this post i will explain

A step-by-step guide to successfully creating a deployment package, sending it, and receiving information using Ardamax Keylogger. Now, in this guide, I only use one method of recieving information, and that’s an FTP. I also do not protect the files. Any suggestions and comments are appreciated. Let’s begin.
some of the keyloggers are detected by the anti virus if u want to make a undetectable keylogger simple using c just check the method 2
Method 1 :setting up the pre-made keyloggers
Head on over to:
CODE
http://www.ardamax.com/keylogger/
And scroll to the bottom. Download the free trial.
After downloading, open the program and install it. Simple enough, right? After installing, go to wherever you installed it at, and open it. It should open at the bottom right corner of your screen, down by the time. If not, press ctrl+shift+alt+h. Now, leave that alone.
Next, go to:
CODE
http://www.theserials.com/serial/serial_ardamax.html
Download the appropriate serial.
Now, open it, and it should give you a name and a jumble of letters and numbers.
Go back to the Ardamax icon at the bottom right, and right-click it.
Click the “Enter Registration Key” button.
Use your serial/crack to unlock the full version. Congratulations, you are now ready to make your first deployment package.
~NOTE~
If you want to attach the keylogger to an existing file, go ahead and place that on your desktop.
~NOTE~
Again, right click the icon at the bottom-right.
Click “Remote Installation”.
Click next.
Now, if you want to attach your keylogger to an existing file, tick the box that says “Append keylogger engine to..” etc etc.
If you tick it, click Browse, and select the file.
If not, continue down. The installation folder on target computer needs to remain Windows System Folder for added security, so leave it be.
Add any additional components you would like. I just leave mine as “log viewer” since all I grab are passwords from games.
From this point, click next.
Now, this part is self explanatory. I tick all of the boxes, as to hide it from everything visible, otherwise they can just see it and be like “Wtf”, uninstall, etc.
Can’t have that, now can we?
Click next.
For Security, do what you want. I leave all of it as-is and click next again.
Now, uncheck the “Check for updates” box, else it will check for updates on their computer and they will know that they are bugged.
Click next.
Tick the “Start in hidden mode” box, and leave the “Run on windows start up” as-is.
You may pick a date to self destruct, if you like. Sounds noisy, right? It simply removes itself on selected date. If not, leave it alone, and it will never self destruct.
Click next.
Tick the “Send logs every..” box, and choose how frequently you would like to recieve information that has been sent.
Select ‘FTP’ and de-select everything else as a delivery method.
You may choose what you want to see. I take out screenshots. Causes lag for me.
Leave log format alone.
You may choose to send logs if it exceeds a certain size, or if you want it to send no matter what, untick the box, which is what I do.
Continue on! (next.)
Now the fun part. -_-.
Head on over to:
CODE
http://phpnet.us/
Make an account, etc etc.
Save your FTP Account name and password. You’ll need it in a moment.
This site will be the site that holds all information recieved by the keylogger.
When you’re done, scroll down a bit.
Under “FTP Accounts”, click “File Manager”.
Near the top, click the “New Dir” button, and create a directory by any name you want. My favorite is “lolbeans”.
Now, hold that thought. Bring the keylogger back.
In Ftp Host, put in:
ftp.phpnet.us
In “Remote Folder”, put in the new directory’s name you made. So, in this scenario, “lolbeans” without the “’s.
Fill in your Username and Password.
I leave Passive Mode checked because I’m not sure what it does, rofl. :[
Leave port alone as well. It’s default.
Now to make sure everything is correctly done, click test. It should tell you it all went through. And to double check, you can refresh your open window. Click your “lolbeans” directory and there should be a test file in it.
Click next, if you’re still alive.
Tick anything and everything you want.
Next.
If you selected screen shots to be enabled, pick how you want them delivered. Click next. If not, ignore this step.
Browse where you want the keylogger to be placed. You can also change the icon, which is nifty. If you’re apologizing to a bitch ex girlfriend/boyfriend of yours, you can change the icon to a notepad and name it “Apology”, and they fall for it.
Next.
This screen will go over with you everything that you have chosen. Make sure it’s all correct.
Click Finish.
Now, if you appended the keylogger to something, you’re going to need to put the “install” (feel free to rename it so it’s not so obvious) and appended file into a .zip or .rar file.
If not, you have the simple “Install” on your desktop. Also, feel free to rename it to something like “Apology” or “OMFGFunnypicture!!!.jpg”
Upload the file or .rar/.zip somewhere, and let your target download it. They will double click it, and on their end, nothing will happen, but secretly, they have been keylogged.
Check your FTP Directory that you made as frequently as you told it to send logs, and you’ll have everything you need.
Feel free to test it out on yourself.
Method 2: how to code your own keylogger
check this post its very use full some of the keyloggers wont work they are detected by the anti virus so its best to code your own keyloggers

Read more...

Black Hat Hackers

black-hat is a term in computing for someone who compromises the security of a system without permission from an authorized party, usually with the intent of accessing computers connected to the network. The term white hat is used for a person who is ethically opposed to the abuse of computer systems. The term cracker was coined by Richard Stallman to provide an alternative to using the existing word hacker for this meaning. The somewhat similar activity of defeating copy prevention devices in software which may or may not be legal in a country’s laws is actually software cracking.
(Source)(In No Particular Order)

1)

Jonathan James: James gained notoriety when he became the first juvenile to be sent to prison for hacking. He was sentenced at 16 years old. In an anonymous PBS interview, he professes, “I was just looking around, playing around. What was fun for me was a challenge to see what I could pull off.”
James’ major intrusions targeted high-profile organizations. He installed a backdoor into a Defense Threat Reduction Agency server. The DTRA is an agency of the Department of Defense charged with reducing the threat to the U.S. and its allies from nuclear, biological, chemical, conventional and special weapons. The backdoor he created enabled him to view sensitive e-mails and capture employee usernames and passwords.
James also cracked into NASA computers, stealing software worth approximately $1.7 million. According to the Department of Justice, “The software supported the International Space Station’s physical environment, including control of the temperature and humidity within the living space.” NASA was forced to shut down its computer systems, ultimately racking up a $41,000 cost. James explained that he downloaded the code to supplement his studies on C programming, but contended, “The code itself was crappy . . .certainly not worth $1.7 million like they claimed.”
Given the extent of his intrusions, if James, also known as “c0mrade,” had been an adult he likely would have served at least ten years. Instead, he was banned from recreational computer use and was slated to serve a six-month sentence under house arrest with probation. However, he served six months in prison for violation of parole. Today, James asserts that he’s learned his lesson and might start a computer security company.

2)
Adrian Lamo: Lamo’s claim to fame is his break-ins at major organizations like The New York Times and Microsoft. Dubbed the “homeless hacker,” he used Internet connections at Kinko’s, coffee shops and libraries to do his intrusions. In a profile article, “He Hacks by Day, Squats by Night,” Lamo reflects, “I have a laptop in Pittsburgh, a change of clothes in D.C. It kind of redefines the term multi-jurisdictional.”
Lamo’s intrusions consisted mainly of penetration testing, in which he found flaws in security, exploited them and then informed companies of their shortcomings. His hits include Yahoo!, Bank of America, Citigroup and Cingular. When white hat hackers are hired by companies to do penetration testing, it’s legal. What Lamo did is not.
When he broke into The New York Times’ intranet, things got serious. He added himself to a list of experts and viewed personal information on contributors, including Social Security numbers. Lamo also hacked into The Times’ LexisNexis account to research high-profile subject matter.
For his intrusion at The New York Times, Lamo was ordered to pay approximately $65,000 in restitution. He was also sentenced to six months of home confinement and two years of probation, which expired January 16, 2007. Lamo is currently working as an award-winning journalist and public speaker.

3)
Kevin Mitnick: A self-proclaimed “hacker poster boy,” Mitnick went through a highly publicized pursuit by authorities. His mischief was hyped by the media but his actual offenses may be less notable than his notoriety suggests. The Department of Justice describes him as “the most wanted computer criminal in United States history.” His exploits were detailed in two movies: Freedom Downtime and Takedown.
Mitnick had a bit of hacking experience before committing the offenses that made him famous. He started out exploiting the Los Angeles bus punch card system to get free rides. Then, like Apple co-founder Steve Wozniak, dabbled in phone phreaking. Although there were numerous offenses, Mitnick was ultimately convicted for breaking into the Digital Equipment Corporation’s computer network and stealing software.
Mitnick’s mischief got serious when he went on a two and a half year “coast-to-coast hacking spree.” The CNN article, “Legendary computer hacker released from prison,” explains that “he hacked into computers, stole corporate secrets, scrambled phone networks and broke into the national defense warning system.” He then hacked into computer expert and fellow hacker Tsutomu Shimomura’s home computer, which led to his undoing.
Today, Mitnick has been able to move past his role as a black hat hacker and become a productive member of society. He served five years, about 8 months of it in solitary confinement, and is now a computer security consultant, author and speaker.

4)
Kevin Poulsen: Also known as Dark Dante, Poulsen gained recognition for his hack of LA radio’s KIIS-FM phone lines, which earned him a brand new Porsche, among other items. Law enforcement dubbed him “the Hannibal Lecter of computer crime.”
Authorities began to pursue Poulsen after he hacked into a federal investigation database. During this pursuit, he further drew the ire of the FBI by hacking into federal computers for wiretap information.
His hacking specialty, however, revolved around telephones. Poulsen’s most famous hack, KIIS-FM, was accomplished by taking over all of the station’s phone lines. In a related feat, Poulsen also “reactivated old Yellow Page escort telephone numbers for an acquaintance who then ran a virtual escort agency.” Later, when his photo came up on the show Unsolved Mysteries, 1-800 phone lines for the program crashed. Ultimately, Poulsen was captured in a supermarket and served a sentence of five years.
Since serving time, Poulsen has worked as a journalist. He is now a senior editor for Wired News. His most prominent article details his work on identifying 744 sex offenders with MySpace profiles.


5)
Robert Tappan Morris: Morris, son of former National Security Agency scientist Robert Morris, is known as the creator of the Morris Worm, the first computer worm to be unleashed on the Internet. As a result of this crime, he was the first person prosecuted under the 1986 Computer Fraud and Abuse Act.
Morris wrote the code for the worm while he was a student at Cornell. He asserts that he intended to use it to see how large the Internet was. The worm, however, replicated itself excessively, slowing computers down so that they were no longer usable. It is not possible to know exactly how many computers were affected, but experts estimate an impact of 6,000 machines. He was sentenced to three years’ probation, 400 hours of community service and a fined $10,500.
Morris is currently working as a tenured professor at the MIT Computer Science and Artificial Intelligence Laboratory. He principally researches computer network architectures including distributed hash tables such as Chord and wireless mesh networks such as Roofnet.
6)
Mass media claimed at the time he was a mathematician and had a degree in biochemistry from Saint Petersburg State Institute of Technology.
According to the coverage, in 1994 Levin accessed the accounts of several large corporate customers of Citibank via their dial-up wire transfer service (Financial Institutions Citibank Cash Manager) and transferred funds to accounts set up by accomplices in Finland, the United States, the Netherlands, Germany and Israel.
In 2005 an alleged member of the former St. Petersburg hacker group, claiming to be one of the original Citibank penetrators, published under the name ArkanoiD a memorandum on popular Provider.net.ru website dedicated to telecom market.[1] According to him, Levin was not actually a scientist (mathematician, biologist or the like) but a kind of ordinary system administrator who managed to get hands on the ready data about how to penetrate in Citibank machines and then exploit them.
ArkanoiD emphasized all the communications were carried over X.25 network and the Internet was not involved. ArkanoiD’s group in 1994 found out Citibank systems were unprotected and it spent several weeks examining the structure of the bank’s USA-based networks remotely. Members of the group played around with systems’ tools (e.g. were installing and running games) and were unnoticed by the bank’s staff. Penetrators did not plan to conduct a robbery for their personal safety and stopped their activities at some time. Someone of them later handed over the crucial access data to Levin (reportedly for the stated $100).

7)
In human terms, it’s a case of a trusted, 11-year employee gone bad. Lloyd built the Novell NetWare computer network at Omega South and then blew it up with a software time bomb after he fell from corporate grace and was ultimately fired for performance and behavioral problems. Today, he faces a sentence of up to five years in prison.
In a business sense, the loss of its key manufacturing programs cost Omega, which builds measurement and instrumentation devices for customers like NASA and the U.S. Navy, more than $10 million, dislodged its footing in the industry and eventually led to 80 layoffs.
The 1996 incident set off an intense investigation that brought together the U.S. Secret Service and one of the world’s top data recovery and forensics experts to piece together the evidence that would ultimately lead to Lloyd’s arrest and conviction
8)
David Smith, the author of the Melissa virus, was facing nearly 40 years in jail when he decided to cooperate with the FBI.
Facing jail time, public wrath and a fortune in potential fines, the 30-year-old sender of the fast-spreading Melissa computer virus did what hundreds of criminals have done before. He agreed to go undercover.
Federal court documents unsealed at the request of the Associated Press show that for almost two years, Smith – then out on bail – worked mostly full time cruising the dark recesses of the Internet while the FBI paid his tab.
What did the FBI get? A windfall of information about malicious code senders, leading directly to two major international arrests and pre-empting other attacks, according to federal prosecutors.
What did Smith get? Just 20 months in federal prison, which was about two years less than the minimum sentencing requirement, and about 38 years less than he faced when initially charged.
Sometimes it takes a thief to catch a thief, said former federal prosecutor Elliot Turrini, who handled Smith’s case and agreed to the reduced sentence.
About 63,000 viruses have rolled through the Internet, causing an estimated $65 billion in damage, but Smith is the only person to go to federal prison in the United States for sending one.
9)
The computer hacker known as “Mafiaboy,” who crippled several major Internet sites including CNN, arrives in court Thursday, Jan. 18, 2001 in Montreal, Canada. He pleaded guilty on Thursday to 55 charges of mischief. The trial of the 16-year-old Montrealer, who can not be identified under Canadian law, was set to begin Thursday on 66 charges relating to attacks last year on several major Web sites, as well as security breaches of other sites at institutions such as Yale and Harvard.
10)
Mark Abene (born 1972), better known by his pseudonym Phiber Optik, is a computer security hacker from New York City. Phiber Optik was once a member of the Hacker Groups Legion of Doom and Masters of Deception. In 1994, he served a one-year prison sentence for conspiracy and unauthorized access to computer and telephone systems.
Phiber Optik was a high-profile hacker in the early 1990s, appearing in The New York Times, Harper’s, Esquire, in debates and on television. Phiber Optik is an important figure in the 1995 non-fiction book Masters of Deception — The Gang that Ruled Cyberspace
Sources:
http://en.wikipedia.org/wiki/Main_Page
http://eyeball-series.org/hacker/hacker-eyeball.htm
http://www.itsecurity.com/features/top-10-famous-hackers-042407/Hacking News

Read more...
Related Posts with Thumbnails

  © Blogger template Webnolia by Ourblogtemplates.com 2009

Back to TOP