7 Must have tools for every Hacker

All these tools provided here are free of cost,are tried hands on and are being actively developed by community,and if not,their alternatives are provided.To summarize it up, these are the 7 must have tools for every hacker

HEARTBLEED Bug Explanation

It is a critical bug in the OpenSSL's implementation of the TLS/DTLS heartbeat extension that allows attackers to read portions of the affected server’s memory, potentially revealing users data, that the server did not intend to reveal.

Beginners guide to hacking

The Basic And Advanced Steps of Hacking And Will Help You Develop The Hacker Attitude.You Will Learn Various Kinds Of Hacking

Just Fucking Google it .....

This is for people that ask how to hack facebook and how to unzip a file and how to sfix erorrs in kali linux , and how to hack a wep

Hacking Facebook Using Man in the Middle Attack

Hacking Facebook Using Man in the Middle Attack I will demonstrate how to hacking Facebook using MITM(Man in the Middle). This attack usually happen inside a Local Area Network(LAN) in office, internet cafe, apartment, etc.

Showing posts with label System Hacking. Show all posts
Showing posts with label System Hacking. Show all posts

Saturday, April 26, 2014

TOP 101 Unique sites that is use full for anybody


These sites solve at least one problem really well and they all have simple web addresses
(URLs) that you can easily memorize thus saving a trip to Google.
1. screenr.com – Record movies of your desktop and send them straight to YouTube.
2. ctrlq.org/screenshots – for capturing screenshots of web pages on mobile and desktops.
3. goo.gl – shorten long URLs and convert URLs into QR codes.
4. unfurlr.com – find the original URL that’s hiding behind a short URL.
5. qClock – find the local time of a city using a Google Map.
6. copypastecharacter.com – copy special characters that aren’t on your keyboard.
7. postpost.com – a better search engine for twitter.
8. lovelycharts.com – create flowcharts, network diagrams, sitemaps, etc.
9. iconfinder.com – the best place to find icons of all sizes.
10. office.com – download templates, clipart and images for your Office documents.
11. followupthen.com – the easiest way to setup email reminders.
12. jotti.org – scan any suspicious file or email attachment for viruses.
13. wolframalpha.com – gets answers directly without searching – see more wolfram tips.
14. printwhatyoulike.com – print web pages without the clutter.
15. joliprint.com – reformats news articles and blog content as a newspaper.
16. ctrlq.org/rss – a search engine for RSS feeds.
17. e.ggtimer.com – a simple online timer for your daily needs.
18. coralcdn.org – if a site is down due to heavy traffic, try accessing it through coral CDN.
19. random.org – pick random numbers, flip coins, and more.
20. pdfescape.com – lets you can quickly edit PDFs in the browser itself.
21. viewer.zoho.com – Preview PDFs and Presentations directly in the browser.
22. tubemogul.com – simultaneously upload videos to YouTube and other video sites.
23. dabbleboard.com – your virtual whiteboard.
24. scr.im – share you email address online without worrying about spam.
25. dictation.io – online voice recognition in the browser itself.
26. sizeasy.com – visualize and compare the size of any product.
27. myfonts.com/WhatTheFont – quickly determine the font name from an image.
28. google.com/webfonts – a good collection of open source fonts.
29. regex.info – find data hidden in your photographs – see more EXIF tools.
30. livestream.com – broadcast events live over the web, including your desktop screen.
31. iwantmyname.com – helps you search domains across all TLDs.
32. homestyler.com – design from scratch or re-model your home in 3d.
33. join.me – share you screen with anyone over the web.
34. onlineocr.net – recognize text from scanned PDFs – see other OCR tools.
35. flightstats.com - Track flight status at airports worldwide.
36. wetransfer.com – for sharing really big files online.
37. hundredzeros.com – best-sellers on all subjects that you can download for free.
38. polishmywriting.com – check your writing for spelling or grammatical errors.
39. marker.to – easily highlight the important parts of a web page for sharing.
40. typewith.me – work on the same document with multiple people.
41. whichdateworks.com – planning an event? find a date that works for all.
42. everytimezone.com – a less confusing view of the world time zones.
43. gtmetrix.com – the perfect tool for measuring your site performance online.
44. noteflight.com – print music sheets, write your own music online (review).
45. imo.im - chat with your buddies on Skype, Facebook, Google Talk, etc. from one place.
46. translate.google.com – translate web pages, PDFs and Office documents.
47. kleki.com – create paintings and sketches with a wide variety of brushes.
48. similarsites.com – discover new sites that are similar to what you like already.
49. wordle.net – quick summarize long pieces of text with tag clouds.
50. bubbl.us – create mind-maps, brainstorm ideas in the browser.
51. kuler.adobe.com – get color ideas, also extract colors from photographs.
52. liveshare.com – share your photos in an album instantly.
53. lmgtfy.com – when your friends are too lazy to use Google on their own.
54. midomi.com – when you need to find the name of a song.
55. bing.com/images – automatically find perfectly-sized wallpapers for mobiles.
56. faxzero.com – send an online fax for free – see more fax services.
57. feedmyinbox.com – get RSS feeds as an email newsletter.
58. ge.tt – quickly send a file to someone, they can even preview it before downloading.
59. pipebytes.com – transfer files of any size without uploading to a third-party server.
60. tinychat.com – setup a private chat room in micro-seconds.
61. privnote.com – create text notes that will self-destruct after being read.
62. boxoh.com – track the status of any shipment on Google Maps – alternative.
63. chipin.com – when you need to raise funds online for an event or a cause.
64. downforeveryoneorjustme.com – find if your favorite website is offline or not?
65. ewhois.com – find the other websites of a person with reverse Analytics lookup.
66. whoishostingthis.com – find the web host of any website.
67. google.com/history – found something on Google but can’t remember it now?
68. aviary.com/myna – an online audio editor that lets record, and remix audio clips online.
69. disposablewebpage.com – create a temporary web page that self-destruct.
70. urbandictionary.com – find definitions of slangs and informal words.
71. seatguru.com – consult this site before choosing a seat for your next flight.
72. sxc.hu ? download stock images absolutely free.
73. zoom.it – view very high-resolution images in your browser without scrolling.
74. scribblemaps.com – quickly create custom Google Maps online.
75. alertful.com – quickly setup email reminders for important events.
76. picmonkey.com – Picnik is offline but PicMonkey is an even better image editor.
77. formspring.me – you can ask or answer personal questions here.
78. sumopaint.com – an excellent layer-based online image editor.
79. snopes.com – find if that email offer you received is real or just another scam.
80. typingweb.com – master touch-typing with these practice sessions.
81. mailvu.com – send video emails to anyone using your web cam.
82. timerime.com – create timelines with audio, video and images.
83. stupeflix.com – make a movie out of your images, audio and video clips.
84. safeweb.norton.com – check the trust level of any website.
85. teuxdeux.com – a beautiful to-do app that looks like your paper dairy.
86. deadurl.com – you’ll need this when your bookmarked web pages are deleted.
87. minutes.io – quickly capture effective notes during meetings.
88. youtube.com/leanback – Watch YouTube channels in TV mode.
89. youtube.com/disco – quickly create a video playlist of your favorite artist.
90. talltweets.com – Send tweets longer than 140 characters.
91. pancake.io – create a free and simple website using your Dropbox account.
92. builtwith.com – find the technology stack of any website.
93. woorank.com – research a website from the SEO perspective.
94. mixlr.com – broadcast live audio over the web.
95. radbox.me – bookmark online videos and watch them later (review).
96. tagmydoc.com – add QR codes to your documents and presentations (review).
97. notes.io – the easiest way to write short text notes in the browser.
98. ctrlq.org/html-mail – send rich-text mails to anyone, anonymously.
99. fiverr.com – hire people to do little things for $5.
100. otixo.com – easily manage your online files on Dropbox, Google Docs, etc.
101.ifttt.com – create a connection between all your online accounts.

Friday, April 25, 2014

Differences between Linux and UNIX operating systems !

unix-linux1

UNIX is copyrighted name only big companies are allowed to use the UNIX copyright and name, so IBM AIX and Sun Solaris and HP-UX all are UNIX operating systems. The Open Group holds the UNIX trademark in trust for the industry, and manages the UNIX trademark licensing program.

Most UNIX systems are commercial in nature.
Linux is a UNIX Clone

But if you consider Portable Operating System Interface (POSIX) standards then Linux can be considered as UNIX. To quote from Official Linux kernel README file:
Linux is a Unix clone written from scratch by Linus Torvalds with assistance from a loosely-knit team of hackers across the Net. It aims towards POSIX compliance.
However, "Open Group" do not approve of the construction "Unix-like", and consider it misuse of their UNIX trademark.

Linux Is Just a Kernel

All Linux distributions includes GUI system + GNU utilities (such as cp, mv, ls,date, bash etc) + installation & management tools + GNU c/c++ Compilers + Editors (vi) + and various applications (such as OpenOffice, Firefox). However, most UNIX operating systems are considered as a complete operating system as everything come from a single source or vendor.
As I said earlier Linux is just a kernel and Linux distribution makes it complete usable operating systems by adding various applications. Most UNIX operating systems comes with A-Z programs such as editor, compilers etc. For example HP-UX or Solaris comes with A-Z programs.
License and cost

Linux is Free

You can download it from the Internet or redistribute it under GNU licenses. You will see the best community support for Linux. Most UNIX like operating systems are not free (but this is changing fast, for example OpenSolaris UNIX). However, some Linux distributions such as Redhat / Novell provides additional Linux support, consultancy, bug fixing, and training for additional fees.
User-Friendly

Linux is the most user friendly UNIX like OS.

 It makes it easy to install sound card, flash players, and other desktop goodies. However, Apple OS X is most popular UNIX operating system for desktop usage.

Security Firewall Software

Linux comes with open source netfilter/iptables based firewall tool to protect your server and desktop from the crackers and hackers. UNIX operating systems comes with its own firewall product (for example Solaris UNIX comes with ipfilter based firewall) or you need to purchase a 3rd party software such as Checkpoint UNIX firewall.

Backup and Recovery Software

UNIX and Linux come with different set of tools for backing up data to tape and other backup media. However, both of them share some common tools such as tar, dump/restore, and cpio etc.

File Systems

Linux by default supports and use ext3 or ext4 file systems.
UNIX comes with various file systems such as jfs, gpfs (AIX), jfs, gpfs (HP-UX), jfs, gpfs (Solaris).

System Administration Tools

UNIX comes with its own tools such as SAM on HP-UX.
Suse Linux comes with Yast
Redhat Linux comes with its own gui tools called redhat-config-*.
However, editing text config file and typing commands are most popular options for sys admin work under UNIX and Linux.

System Startup Scripts

Almost every version of UNIX and Linux comes with system initialization script but they are located in different directories:
HP-UX - /sbin/init.d
AIX - /etc/rc.d/init.d
Linux - /etc/init.d
End User Perspective

The differences are not that big for the average end user. 

They will use the same shell (e.g. bash or ksh) and other development tools such as Perl or Eclipse development tool.

System Administrator Perspective

Again, the differences are not that big for the system administrator. However, you may notice various differences while performing the following operations:

  • Software installation procedure
  • Hardware device names
  • Various admin commands or utilities
  • Software RAID devices and mirroring
  • Logical volume management
  • Package management
  • Patch management
  • UNIX Operating System Names

A few popular names:

  • HP-UX
  • IBM AIX
  • Sun Solairs
  • Mac OS X
  • IRIX

Linux Distribution (Operating System) Names

  • A few popular names:
  • Redhat Enterprise Linux
  • Fedora Linux
  • Debian Linux
  • Suse Enterprise Linux
  • Ubuntu Linux
  • Common Things Between Linux & UNIX

Common Applications

  • GUI, file, and windows managers (KDE, Gnome)
  • Shells (ksh, csh, bash)
  • Various office applications such as OpenOffice.org
  • Development tools (perl, php, python, GNU c/c++ compilers)
  • Posix interface

Final Words

Thanks for visiting my blog ! I hope this article helped you ! If you have any question or suggestion feel free to comment below. Also don't forget to like us on Facebook 

Tuesday, April 22, 2014

HEARTBLEED Bug Explanation

heartbleed
Heartbleed – I think now it’s not a new name for you, as every informational website, Media and Security researchers are talking about probably the biggest Internet vulnerability in recent history. It is a critical bug in the OpenSSL's implementation of the TLS/DTLS heartbeat extension that allows attackers to read portions of the affected server’s memory, potentially revealing users data, that the server did not intend to reveal.

After the story broke online, websites around the world flooded with the heartbleed articles, explaining how it works, how to protect, and exactly what it is. Yet many didn’t get it right. So based on the queries of Internet users, we answered some frequently asked questions about the bug.

1.) IS HEARTBLEED A VIRUS?
Absolutely NO, It's not a virus. As described in our previous article, The Heartbleed bug is a vulnerability resided in TLS heartbeat mechanism built into certain versions of the popular open source encryption standard OpenSSL, a popular version of the Transport Layer Security (TLS) protocol.

2.) HOW IT WORKS?
For SSL to work, your computer needs to communicate to the server via sending 'heartbeats' that keep informing the server that client (computer) is online (alive).

Heartbleed attack allows an attacker to retrieve a block of memory of the server up to 64kb in response directly from the vulnerable server via sending the malicious heartbeat and there is no limit on the number of attacks that can be performed. [Technically Explained by Rahul Sasi on Garage4hackers]

It opens doors for the cyber criminals to extract sensitive data directly from the server's memory without leaving any traces.
heartbleed explanation
xkcd comic http://xkcd.com/1354/
3.) HEARTBLEED ATTACK RELIES ON MAN-IN-THE-MIDDLE ATTACK?
No, it has nothing to deal with a Man-in-the-Middle (MitM) attack. But using Heartbleed attack, one can manage to obtain the private encryption key for an SSL/TLS certificate and could set up a fake website that passes the security verification.

An attacker could also decrypt the traffic passing between a client and a server i.e. Perfect man-in-the-middle attack on HTTPS connection.

4.) IS IT A CLIENT SIDE OR SERVER SIDE VULNERABILITY?
TLS heartbeats can be sent by either side of a TLS connection, so it can be used to attack clients as well as servers. An Attacker can obtain up to 64K memory from the server or client as well that uses an OpenSSL implementation vulnerable to Heartbleed (CVE-2014-0160).

Researcher estimated two-thirds of the world's servers i.e. half a million servers are affected by the Heartbleed Bug, including websites, email, and instant messaging services.

Video Explanation:

5.) HOW HEARTBLEED AFFECTS SMARTPHONES?
Smartphone is the best practical example of Client side attacks.

All versions of Android OS include outdated versions of OpenSSL library, but only Android 4.1.1 Jelly Bean has the vulnerable heartbeat feature enabled by default. Blackberry also confirmed that some of its products are vulnerable to Heartbleed bug, whereas Apple's iOS devices are not affected by OpenSSL flaw.

Google had patched the affected version Android 4.1.1, but it will take long time to deliver updated Android version to the end Smartphone users as updates to majority handsets are controlled by phone manufacturers and wireless carriers. Until users running the affected versions are vulnerable to the attacks, and hackers will definitely take advantage of this public disclosure.

6.) WHAT ELSE COULD BE VULNERABLE TO HEARTBLEED?
IP phones, Routers, Medical devices, Smart TV sets, embedded devices and millions of other devices that rely on the OpenSSL to provide secure communications could also be vulnerable to Heartbleed bug, as it is not expected for these devices to get the updates soon from Google’s Android partners.

Yesterday, Industrial Control Systems-CERT also warned the critical infrastructure organizations (like energy, utilities or financial services companies) to beef-up their systems in order to defend against the Heartbleed attacks.

7.) WHO IS RESPONSIBLE FOR HEARTBLEED?
We actually can't blame anyone developer, specially who are contributing to Open Source projects without money motivations. 

Dr. Robin Seggelmann, a 31-year-old German developer who actually introduced the Heartbeat concept to OpenSSL on New Year's Eve, 2011, says it was just a programming error in the code that unintentionally created the “Heartbleed” vulnerability.

"In one of the new features, unfortunately, I missed validating a variable containing a length", went undetected by the code reviewers and everyone else for over two years. He claimed 'I did so unintentionally'.

8.) WHO HAS EXPLOITED THIS BUG YET?
Bloomberg accused the National Security Agency (NSA) of knowing the Heartbleed bug for the last two years. Not even this, the report says the agency was using it continuously to gain information instead of disclosing it to the OpenSSL developers. But if it is so, then this would be one of the biggest developments in the history of wiretapping ever. However, the agency denied it saying NSA was not aware of Heartbleed until it was made public.

But when it comes to exploit any known vulnerability, then Hackers are most likely to be top on the list. As the flaw was so widely spread that it affected half a million websites worldwide, so after the public disclosure, the cybercriminals could reach the sites to steal credentials, passwords and other data, before the site operators apply the freely available patch.

There are multiple Proof-of-concept exploits available for the Heartbleed flaw:
9.) CHANGING ACCOUNT PASSWORDS CAN SOLVE THE ISSUE?
Not exactly, as Heartbleed attack has the ability to leak anything from the server including your passwords, credit card details or any kind of personal information. But, in order to protect your online accounts you should at least change your passwords immediately for the sites that resolved the issue and for the sites not affected by the bug as well, just to make sure that you are safe.

First of all check if the sites you use every day on an individual basis are vulnerable to Heartbleed bug or not using following services or apps:, and if you're given a red flag, avoid the site for now.
Well, nobody is sure at this point, because Heartbleed is stealthy as it leaves no traces behind and here the matter goes worse.

You may never know if you have been hacked using the flaw or not. This means that there is no way to tell if your information was stolen previously from a site or a service that has now fixed it.

But if you haven't change the password to the popular sites yet, then yes, your password and financial information are still widely open to cybercriminals and other spying agencies.

10.) WHAT SHOULD I DO TO PROTECT MYSELF?
First of all DON'T PANIC. You have to change your password everywhere, assuming that it was all vulnerable before, just to make sure that you are now safe. But hold on... If some sites are still affected by the flaw then your every effort is useless, as it’s up to the site to first fix the vulnerability as soon as possible , because changing the password before the bug is fixed could compromise your new password as well.

If you own a vulnerable SSL Service, then you are recommended to:
  • Upgrade the OpenSSL version to 1.0.1g
  • Request revocation of the current SSL certificate
  • Regenerate your private key
  • Request and replace the SSL certificate
Don't reuse any old passwords and it is good practice to use two-factor authentication, which means with the password, the account requires a freshly generated pass code that shows up only on your personal smartphone, before getting into certain sites.


   If you like my post then subscribe below for such more great  tutorials Also like my Facebook Page.