Friday, 5 February 2016

                        The best Hacking tools of 2016 for hackers and pentesters.

Here are the top hacking tools for 2016 used by hackers and pentesters worldwide.

Nmap :
Nmap is an abbreviation of ‘Network Mapper’, which is a very well known free open source hackers tool. Nmap is used for network discovery and security auditing. Literally thousands of system admins all around the world will use nmap for network inventory, check for open ports, manage service upgrade schedules, and monitor host or service uptime. Nmap, as a tool uses raw IP packets in creative ways to determine what hosts are available on the network, what services (application name and version) those hosts are providing information about, what operating systems (fingerprinting) and what type and version of packet filters/ firewalls are being used by the target. There are dozens of benefits of using nmap, one of which is that fact that the admin user is able to determine whether the network (and associated nodes) need patching.

Acutenix Web Vulnerability Scanner : 
Find out if your website is secure before hackers download sensitive data, commit a crime by using your website as a launch pad, and endanger your business. Acunetix Web Vulnerability Scanner (WVS) crawls your website, automatically analyzes your web applications and finds perilous SQL injection, Cross-Site scripting and other vulnerabilities that expose your online business. Concise reports identify where web applications need to be fixed, thus enabling you to protect your business from impending hacker attacks!

The fine folks at Acunetix have published a 100% FREE video course so you can learn how to use this awesome Web Vulnerability Scanner effectively! Here’s a link for more information and to register.

Metasploit :
The Metasploit Project is a hugely popular pentesting or hacking framework. If you are new to Metasploit think of it as a ‘collection of hacking tools’ that can be used to execute various tasks. Widely used by cybersecurity professionals and ethical hackers this is a tool that you have to learn. Metasploit is essentially a computer security project (framework) that provides the user with vital information regarding known security vulnerabilities and helps to formulate penetration testing and IDS testing plans, strategies and methodologies for exploitation. 
OWASP Zed Attack Proxy Project :
The Zed Attack Proxy (ZAP) is now one of the most popular OWASP projects. The fact that you’ve reached this page means that you are likely already a relatively seasoned cybersecurity professional so it’s highly likely that you are very familiar with OWASP, not least the OWASP Top Ten Threats listing which is considered as being the ‘guide-book’ of web application security. This hacking and pentesting tool is a very efficient as well as being an ‘easy to use’ program that finds vulnerabilities in web applications. ZAP is a popular tool because it does have a lot of support and the OWASP community is really an excellent resource for those that work within Cyber Security. ZAP provides automated scanners as well as various tools that allow you the cyber pro to discover security vulnerabilities manually. 

Wireshark :
Wireshark is an network analyser which allows the tester to capture packets travelling through the network, and to inspect them.

The test computer should be connected at appropriate testing points. Some of my recommendations are:
1. On various points of a DMZ.
2. On a port of a switch.
3. Between router and firewall.(If their is a separate hardware for each) .
Wireshark is possibly the second best known ‘Hackers Tool’ out there. Wireshark has been around for a long time now and it is used by thousands of security professionals to troubleshoot and analyse networks for problems and intrusions. Originally named Ethereal this tool, or rather, ‘platform’ is a highly effective (and free!) open-source packet analyzer. Worth noting that Wireshark is cross-platform, using the GTK+ widget toolkit in current releases, and Qt in the development version.
 
Burp Suite :
Burp Suite is a network vulnerability scanner basically with some enhanced features. Two commonly used applications used within this tool include the ‘Burp Suite Spider’ which can enumerate and map out the various pages and parameters of a web site by examining cookies and initiates connections with these web applications, and the ‘Intruder’ which performs automated attacks on web applications.

This is a ‘must-learn’ tool if you work within cyber-security and are tasked with penetrating applications used within an organization.
 

THC Hydra :
Although often considered as yet another password cracker, THC Hydra is hugely popular password cracker and has a very active and experienced development team. Essentially THC Hydra is a fast and stable Network Login Hacking Tool that will use dictionary or brute-force attacks to try various password and login combinations against an log in page.

Hydra supports various network protocols including, but not limited to AFP, Cisco AAA, Cisco auth, Cisco enable, CVS, Firebird, FTP, HTTP-FORM-GET, HTTP-FORM-POST, HTTP-GET, HTTP-HEAD, HTTP-PROXY, HTTPS-FORM-GET, HTTPS-FORM-POST, HTTPS-GET, HTTPS-HEAD, HTTP-Proxy, ICQ, IMAP, IRC, LDAP, MS-SQL, MYSQL, NCP, NNTP, Oracle Listener, Oracle SID, Oracle, PC-Anywhere, PCNFS, POP3, POSTGRES, RDP, and Rexec.
 
Aircrack-ng :
The Aircrack suite of Wifi (Wireless) hacking tools are legendary because they are very effectively when used in the right hands. For those new to this wireless-specific hacking program, Aircrack-ng is an 802.11 WEP and WPA-PSK keys cracking hacking tool that can recover keys when sufficient data packets have been captured (in monitor mode).

For those tasked with penetrating and auditing wireless networks Aircrack-ng will become your best friend. It’s useful to know that Aircrack-ng implements standard FMS attacks along with some optimizations like KoreK attacks, as well as the PTW attacks to make their attacks more potent. If you are a mediocre hacker then you will be able to crack WEP in a few minutes and you ought to be pretty proficient at being able to crack WPA/ WPA2.
 
John The Ripper :
John the Ripper wins the award for having the coolest name. John the Ripper, mostly just referred to as simply, ‘John’ is a popular password cracking pentesting tool that is most commonly used to perform dictionary attacks. John the Ripper takes text string samples (from a text file, referred to as a ‘wordlist’, containing popular and complex words found in a dictionary or real passwords cracked before), encrypting it in the same way as the password being cracked (including both the encryption algorithm and key), and comparing the output to the encrypted string. This tool can also be used to perform a variety of alterations to dictionary attacks. 


Tuesday, 2 February 2016

Hacking Facebook Complete E-Book

*WARNING: WOLLOWING MATERIALS ARE FOR EDUCATIONAL AND SECURITY PURPOSES *WE DON’T TAKE RESPONSIBILITY FOR YOU*

Table of Contents :

1. Facebook Tips & Tricks
1.1 Facebook Tips
1.2. How to find Facebook Number
1.3. How to access Facebook from G mail
1.4. Facebook Emotions codes
1.5. How to download Facebook in your PC…
 1.6. Download your Information
1.7. Import your blog in Facebook
    1.8. How to find if somebody hacked your Facebook account
1.9. How to change your name in Facebook
1.10. Export Email addresses of your Facebook account
1.11. How to create Facebook ID card
    1.12. How to hide your Email address from Facebook apps
1.13. How to Delete and Terminate Facebook account
1.14. How to Download Facebook photo album
   1.15. How to add a forum (discussion board) to a page
    1.16. Face book antivirus
———————– Page 3———————–

1.17. How to alert Facebook fan page in your E-mail…
 1.18. How to Show who is online on Facebook when you are in offline mode…
    1.19. How to send SMS using Facebook…
   1.20. How to find new pages you might like
  1.21. How to watch streaming TV on Facebook
   1.22. How to create a map of your Facebook friend…
1.23. Animated picture in Face book
  1.24. Colored text, bold, underline, smiles in Facebook status…
    1.25. How to disable Facebook Timeline…
1.26. How to disable Public search of your Facebook profile
    1.27. How to Publish your Empty status
1.28. How to Surf Blocked Facebook
2. Facebook Web Apps
 2.1. How to Schedule Facebook massages Sendible
 2.2. How to get Facebook updates on your Email
  2.3. How to updates Facebook without using Face book
 2.4. How to be notify when friend changes jobs
2.5. How to view Facebook Profile History
———————– Page 4———————–

2.6. How to Flip Facebook status updates
2.7. How to find Shared videos on Facebook
 2.8. Capture the wisdom of your social Network
 2.9. Monitor your child Facebook activity
 2.10. Manage your personal & professional image
  2.11. How to track Facebook Activities
  2.12. Create mosaics Profile picture on Facebook
2.13. Online store on Facebook
  2.14. Online Face book Messenger…
2.15. How to Analysis Facebook Fan page…
 2.16. How to find who un friends you
  2.17. How to download Videos from Facebook
2.18. How to create slideshow of your Facebook album
2.19. How to Create Custom Facebook tab
2.20. How to get Face book in Excel
   2.21. How to connect Google docs to Facebook
 3. Facebook Software & Plugins
 3.1. Facebook Color Changer
———————– Page 5———————–

    3.2. Facebook adds blocker
  3.3. How to connect Facebook, Twitter& Google
3.4. Facebook Toggle all
  3.5. How to Facebook Chat on your desktop Adium
    3.6. Facebook based web browser
     3.7. Facebook E mail grabber
 3.8. How to connect outlook to Facebook
    4. Facebook Hacking & Security
  4.1. Facebook phishing
  4.2. Facebook Password Decryptor
  4.3. Web browser Pass view …
   4.4. How to Hack Facebook using Keylogger
   4.5. How to Hack Password using Facebook Hacker
    4.6. How to delete Your friend Account within 24 hour
    4.7. How to protect your Facebook account from Hacking
  4.8. How to protect yourself from Keylogger & phishing attack

  Free CEH – Certified Ethical Hacker FULL Course PDF | CEH v8

The Certified Ethical Hacker program is the pinnacle of the most desired information security training program any information security professional will ever want to be in. To master the hacking technologies, you will need to become one, but an ethical one! The course provides the tools and techniques used by hackers and information security professionals alike to break into an organization. As we put it, “To beat a hacker, you need to think like a hacker”. This course will immerse you into the Hacker Mindset so that you will be able to defend against future attacks. The security mindset in any organization must not be limited to the silos of a certain vendor, technologies or pieces of equipment.

This course puts you in the driver’s seat of a hands-on environment with a systematic process. Here, you will be exposed to an entirely different way of achieving optimal information security posture in their organization; by hacking it! You will scan, test, hack and secure your own systems. You will be thought the five phases of ethical hacking and thought how you can approach your target and succeed at breaking in every time! The five phases include Reconnaissance, Gaining Access, Enumeration, Maintaining Access, and covering your tracks.

The tools and techniques in each of these five phases are provided in detail in an encyclopedic approach to help you identify when an attack has been used against your own targets. Why then is this training called the Certified Ethical Hacker Course? This is because by using the same techniques as the bad guys, you can assess the security posture of an organization with the same approach these malicious hackers use, identify weaknesses and fix the problems before they are identified by the enemy, causing what could potentially be a catastrophic damage to your respective organization.

Modules


  1. CEHV8 Module 01 Introduction to Ethical Hacking.pdf
  2. CEHv8 Module 02 Footprinting and Reconnaissance.pdf
  3. CEHv8 Module 03 Scanning Networks.pdf
  4. CEHv8 Module 04 Enumeration.pdf
  5. CEHv8 Module 05 System Hacking .pdf
  6. CEHv8 Module 06 Trojans and Backdoors.pdf
  7. CEHv8 Module 07 Viruses and Worms.pdf
  8. CEHv8 Module 08 Sniffing.pdf
  9. CEHv8 Module 09 Social Engineering.pdf
  10. CEHv8 Module 10 Denial of Service.pdf
  11. CEHv8 Module 11 Session Hijacking.pdf
  12. CEHv8 Module 12 Hacking Webservers.pdf
  13. CEHv8 Module 13 Hacking Web Applications.pdf
  14. CEHv8 Module 14 SQL Injection.pdf
  15. CEHv8 Module 15 Hacking Wireless Network.pdf
  16. CEHv8 Module 16 Hacking Mobile Platforms.pdf
  17. CEHv8 Module 17 Evading IDS, Firewalls, and Honeypots.pdf
  18. CEHv8 Module 18 Buffer Overflow.pdf
  19. CEHv8 Module 19 Cryptography.pdf
  20. CEHv8 Module 20 Penetration Testing.pdf
  21. CEHv8 References.pdf

Monday, 1 February 2016



Microsoft CEO Satya Nadella: “Cortana Is Going To Kill Your Web Browser”, Get Ready For Future!!

Cortana is one of the best digital assistants out there and it’s giving a tough competition to Apple’s Siri and Google Now. While Facebook is busy preparing the launch of M, its digital assistant with a human touch, Microsoft is betting on the future in AI.

Speaking at the O’Reilly Next:Economy summit, Microsoft CEO Satya Nadella hinted at a better Cortana in the upcoming years, that will be grow to replace the UI of web browsers.

“To me, AI is going to happen,” in his keynote Satya Nadella said. He explained that Cortana and other personal assistants are being developed by the tech companies with a bigger future in the mind. These assistants will soon replace the web browsers in our phones, PCs and tablets.

Cortana was introduced originally on Windows Phone and it has grown to become a major part of the new Windows 10 operating system. “‘Hey Cortana’ is in my vocabulary. Having that become more pervasive is my pursuit,” Nadella said, praising the Cortana.

But, replacing the web browsers isn’t what it looks like. Instead of completely replacing the traditional web browsers completely, digital assistants will replace just the browser user interface.

Instead of using the web browser UI for exploring the web and performing searches, your digital assistant will do all these jobs for you. Realizing the potential of Cortana, Microsoft has decided to make it a cross-platform app and released its beta version on iOS and Android.

These Four Lines Of Code Can Crash Anyone’s Smartphone And Computer.

There’s a notorious link being shared on social networking websites that can crash nearly all smartphones — all you have to do is just click on this link. Known as crashsafari.com (clicking on this will crash your browser), this link crashes your browser by overloading it with thousands of characters in the address bar each second. As a result, the phone memory exhausts and your device crashes.

 Back in September, we encountered a  similar bug in Google Chrome that caused the browser to crash with just 16 characters. This website link is being spread via apps, social networks, simple URLs, and shortened URLs. It should be noted that this bug isn’t malicious and it doesn’t break anything in your phone.

Devices affected by Crashsafari.com:

The website is running a small piece of JavaScript that creates a loop with the help of History API and crashes your device. The History API allows the websites to change the URL of the page without performing page refresh.

If you are an iPhone user, you should be very careful about any new incoming shortened links as they could forcibly reboot your phones. Notably, these links have already been opened 100,000 times. You are advised to take extra care as it’s being spread on the web via misleading links.

5 Things to Remember When You are Learning to Code.

Today, we are going to talk about those 5 things which you need to remember while you are still learning programming.

All right, let’s get started!

5 Things to Remember when You are Learning to Code:-

Learning to program is challenging. Aside from choosing a language or setting up a development environment that you know nothing about, there are thousands of articles and tutorials out there that quite simply will make you feel dumb, demotivate you or make you think that everything you have learnt so far was a waste of time and that you’ve been doing everything wrong.

1. Always remember you are on The Internet:-

You should not believe all the articles or news you read is legit or that the photos you see aren’t Photoshopped. So don’t take everything that you read literally. Just because it’s about programming does not mean it’s reliable or correct. It was written by a person, and people make mistakes and are biased.

2. Focus on your code returning the correct result first, rather than cleaning the code:-

You’ll come across a lot of articles that start something like “You should write clean code, you are doing it wrong”. The vast majority of these are just opinions. Focus on your code returning the correct result first, and then focus on cleaning the code. Writing code that works is much better than Writing code by Following Good Programming Practices that doesn’t work.
You can write a simple function that returns the same result in almost any language in a hundred different ways; if their way of doing it is so “right”, what makes the other ninety-nine wrong? And what’re they grading it by — readability? Execution time? It’s all relative to what you need when you code.
Bad Naming Conventions, Indentation and Documentation are more likely to produce “bad” code than the method you choose for a loop.

3. Programmers have a knack of making other people feel dumb:-

Two common concepts in programming are obfuscation (obscuring of intended meaning in communication, making the message confusing, wilfully ambiguous, or harder to understand) and abstraction, and for some reason this seems to carry through to a lot of stuff that programmers write about.
They tend to use very large words, or terms that only relate to the field of programming when they’re writing. If you have to Google a word fifteen times while reading an article, keep in mind you’re not dumb. On the contrary, the writer most likely wanted to you to think he was really clever and impress you.

What he didn’t realise is that when reading an article with big words, people in general tend to think the writer is normal and they are dumb.

4. There are no bad Programming Languages:-

When you meet a fellow programmer, the first question they’re likely to ask you is:

“WHICH LANGUAGE DO YOU CODE IN?”

Your answer then generally forms their initial opinion of your expertise and skill level. I can’t express just how biased this is! There is a good chance that they’ve never even touched the language they’re judging you on, or that they can’t properly justify their opinion. All languages have strengths and weaknesses.
Programming is a trade and a programming language is the same to a good programmer as a tool is to a mechanic. It is his choice to select the best tool from his box for the task at hand, and I’ve never heard anyone say, “Don’t ever use that spanner!”

5. Learning concepts, data structures, design patterns and theory is more important than knowing syntax:-

Programming concepts are all relatively similar. If you know your stuff, you’ll be familiar with the term ‘Array’, you’ll know what it is, what built-in methods it’s likely to have, and can then look up the syntax for it in any language in a heartbeat.


All popular languages are based on programming theory, concepts and principles, and usually they try to build on and add to them. Knowing and understanding this allows you to transcend the limitations of a single programming language, and instead use the best tool for the job… even if you need to Google a little to get there.


Creating Your Own Customized Run Commands.
Hello everybody today I am going to tell you how you can create your own Customized Run Commands in Microsoft Windows OS.

So, now, lets get started!
Creating your Customized Run Commands :-

The Run command on Microsoft Windows Operating System allows you to directly open an application or document with just a single command instead of navigating to its location and double-clicking the executable icon. However, it only works for some of the inbuilt Windows programs such as Command prompt (cmd), Calculator (calc) etc.
But now, I will teach you exactly how you can create your own customized Run commands for accessing your favorite programs, files and folders.
Let me take up an example of how to create a customized run command for opening the Internet Explorer(yeah that old fellow, who is been hated all his life 😀 ). Once you create this command, you should be able to open the Internet explorer just by typing ie in the Run dialog box. Here is how you can do that :

> Right-click on your Desktop and select New -> Shortcut.
> You will see a “Create Shortcut” Dialog box as shown below:
> Click on “Browse”, navigate to: Program Files -> Internet Explorer from your Root drive (usually C:\) and select “iexplore” as shown in the above figure and click on “OK”.
> Now click on “Next” and type any name for your shortcut. You can choose any name as per your choice; this will be your customized “Run command”. In this case I name my shortcut as “ie“. Click on “Finish”.
> You will see a shortcut named “ie” on your desktop. All you need to do is just copy this shortcut and paste it in your Windows folder (usually “C:/Windows”). Once you have copied the shortcut onto your Windows folder, you can delete the one on your Desktop.
> That’s it! From now on, just open the Run dialog box, type ie and hit Enter to open the Internet Explorer.

In this way you can create your own Customized Run commands for any program of your choice. Say ff for Firefox, ym for Yahoo messenger, wmp for Windows media player and so on.

To do this, when you click on “Browse” in the Step-3, just select the target program’s main executable (.exe) file which will usually be located in the “C:\Program Files” folder. Give a simple and short name for this shortcut as per your choice and copy the shortcut file onto the Windows folder as usual. Now just type this short name in the Run dialog box to open the program.