Showing posts with label Backtrack Hacking. Show all posts
Showing posts with label Backtrack Hacking. Show all posts
Backtrack Hacking Video Tutorials
Backtrack Hacking Video Tutorials
This are amazing video tutorials of backtack which include very good collection of hacking videos using backtrack such as sql injection, phone phreaking, wireless hacking, website hacking, network hacking and more. Below is the complete list of videos included in DVD.
How To Install Backtrack 5 On Virtual Machine ?
How To Install Backtrack 5 On Virtual Machine ?
If you want to experience and experiment with backtrack 5 hacking tools such as kismet, metasploit etc. Then today i am going to show you how you can install and run Backtrack 5 Operating System inside a virtual machine(VirtualBox). It works on all computers running any operating system such as Windows Xp, Windows 7, Or Mac Os X. So lets get stared installing backtrack 5 on your operating system.Downloading Softwares to install Backtrack on Virtual Box
1. First you will need Virtual Machine to run Backtrack 5 which you can Download From VirtualBox Website. After downloading VirtualBox Install the program. Installing VirtualBox is really simple like any other program you install on your computer.
2. Then you will need Backtrack 5 .iso file which you can download from Here with below configuration. You can download it directly or via torrent thats your choice.
Getting started installing Backtrack 5 on Virtual Box
1. Open VirtualBox and Click on New. Then a popup box will appear in that write Name as backtrack, Type as Linux and Version as Ubuntu as shown in below picture and click on Next.
2. Next allocate memory to your virtual machine. I usually allocate half the ram i have which is 2GB of 4GB as shown below and click Next.
3. Then choose second option Create Virtual Hard Drive Now from three options and then click on Next.
4. Then Choose VDI(Virtual Disk Image) From all the options and click Next.
5. Now to options will come to allocate size on Hard Drive from that choose Dynamically Allocated and click Next
6. Then leave name as it is and allocate the size to arround 15-20GB and click Create.
7. Now you will have your virtual machine on left. To start it double
click the virtual machine. As you running it for the first time you need
to configure it.
8. Navigate to the Backtrack 5 .iso file we downloaded by clicking on
button i highlighted in red in below image and select it and click on
start.
9. After clicking on start click Enter and leave the setting as it is and press Enter again.
10. Now it will ask for command so type startx and press Enter and it will load user interface of backtrack.
11. Click on Install Backtrack icon from desktop
and it will open installation window. Now leave language to English and
click on Forward. It will now ask for location, Enter your location and
press Forward.
12. On Step 3,4,5,6 you don't need to do anything just click on Forward and on step 7 Click on Install. It will take couple of minutes and you will have backtrack 5 install on your computer.
13. Now will need to enter username and password to enter backtrack, the default username for backtrack is root and password is toor. You can use passswd command to change your password.
14. Done you now have Backtrack 5 running on your virtual machine.
Confused ?
If got problem installing backtrack 5 on your virtual machine or got
struck on any of the steps, or liked our tutorial then leave a comment
below i will be glad to help you out.
Top 6 Black Hat Hackers In The World
Top 6 Black Hat Hackers In The World
There are two types of hackers. First one are good hackers who are known
as "white hat" hackers and another one which we will be talking about
today are called "black hat" hackers. In this article, we will be talking about six famous black hat hackers and their hacks which made them famous or wanted.
George Hotz
Young and talented and what is the most important bored teenager, George
Hotz wanted to have fun one summer night and as a result he hacked the
Sony’s company Iphone. It happened in June of 2007, by that time George
was 17. It was a bit of a challenge, because how to hack device with
assistant things? The secret is
to figure out how “to speak to the device”.He also mentioned that what
he did was completely legal.It seems people can be dangerous in certain
way when they are bored. Who knows what may happen if crazy smart geek
will find thy way of his ideas.
Kevin Mitnick
Kevin Mitnick is well-known as the most-wanted computer criminal in the United States. He was in high school
when he started hacking. For several years he hacked dozens of
companies.What interesting, for those “services” he was finally arrested
in 1995 at his apartment for hacking. Kevin also has served 5 years in
prison, nevertheless despite of his experience he runs his own security
firm named Mitnick Security Consulting. The other side of the coin is,
however Mitnick published a book that calls “Ghost in Wires”, which is
about his upps-and-downs, victories and crushes. He shared that every
hack was like a climbing to mountain and he reached the Everest. This is
one more proof how talent have pined, because of a boredom.
Adrian Lamo
Adrian was called as the most effective and controversial hacker of the
21st century. That is very flattering status.He was famous for breaking
into several high-profile computer networks.
Lamo might use his gift to help people to consult, what is actually he
did, but as exception and compromise.His baby steps in hacking, Adrian
Lamo made pretty early and became known for the first time for operating
AOL watchdog site.As many others, he was arrested in 2003 and had to
correspond for each and every computer crime.Thus, even if Lamo now
works as a threat analyst and public speaker, his glory will always
follow him, because our past if the part of our “present” and a part of
who we are.
Gary McKinnon
This “black hat” McKinnon hacked into 97 United States military
and NASA computers. He could be the biggest threat for government.
Glasgow-born McKinnon wanted the truth to come out and show itself. In
March 2002 Gary was arrested by police.
“Black hat” used his hacking skills to “research” his beliefs and
evidence of UFOs inexhaustible source of power, into the US
government’s computers. He didn’t do that because of boredom, but
because of obsession and thirst to hidden knowledge. Probably this
computer crime is serious, but forgivable. Man wasn’t going to hack computer system because he was bored or to prove something, we was looking for truth no more than.
Jonathan James
Story of Jonathan James is sad, nevertheless his life can be compared
to comet – short, but bright. In 1999 teenager at the age of 15 years
old hacked into Bellsouth and Miami-Dade school network.
Jonathan James damaged NASA Systems, it costed $41,000 to fix the
systems. It goes without saying that he made serious damage. To stole
software from NASA that worth $1.7 Million is one the biggest computer
crimes. He wasn’t after information or justice, he was after money… As
they say, never speak ill of the dead.Jonathan James was sentenced 6
months house arrest and banned from using computer, however that didn’t
prevent him to commit suicide.
Kevin Poulsen
This talented “cyber-terrorists” could have great career and almost blow
his chance. It seems that this hacker likes contracts and his life
reflects it pretty well. He hacked into the US Department of Defense's
Arpanet. However later he worked as a consultant testing Pentagon
computer security. Late on Kevin hacked FBI, after that hacked phone lines to radio station
of Los Angeles… Poulsen’s life reminded American switchbacks…Certainly
he was wanted by FRI and finally they caught him. Despite of such
interesting past, Kevin is law-abiding citizen and has several awards
of International Academy of Digital Arts and Sciences.
Backtrack 5 : Ethical Hacking Tutorial
Stealing Files,Downloading Keystrokes,Controlling Webcam from remote Locations,ETC
What Do We Need ?
Latest Metasploit framework.
Oracle Java 1.7
Preferably Internet on LAN
Brains and Patience.
Now Lets Us Start Our Hack Today.
Step 1 -Open armitage on Backtrack 5:
By Going To : Backtrack > Exploitation Tools > Network Exploitation Tools > Metasploit Framework > armitage.
Step 2 : Connect Armitage:
Click on the connect Button .
Step 3 : Connecting Armitage :
Now use the patience part,and stretch your legs,it takes some time to connect.
Step 4 : Armitage Window :
It has 3 Panels -
Target Panel
Module Panel
Tabs Panel
Step 5 : Finding the alive host on the Network :
Now you will search for Host on
you network,By Going to Hosts -> Nmap Scan -> Quick Scan (OS
detect).This will perform a quick scan to detect the host and their
operating systems and vulnerabilities.
Step 6 : Inputting The Scan Range :
Now You have to insert scan
range,that is you LAN ip range,Most preferably it would start with
192.168.0.- or 10.0.0.-.NOTE : the ( - ) resembles the computers on LAN.
Start the Scan.
Step 7 : Scan Complete:
After
the scan has completed,if their are any other PC's on your network
on,then they would be visible in the Target Pane (the Big Black box on
the upper right).
Step 8 : Finding Attacks :
Now the Fun Parts starts,Click
on Attacks tab in your toolbar and select Find Attacks (Not hail
mary,you might not be ready for that).Start the scan and wait till it
completes.
Step 9 : Set the vulnerability :
Right Click on the Host icon (windows pc) -> Select attacks -> smb -> ms08_067_netapi vulnerability .
Now a window should pop,Click on the check-box that says "Use a reverse connection" .
Start Attack
Backtrack 6 "Kali Linux" Review.
Welcome To A Whole New Backtrack OS.
BackTrack is intended for all audiences from the most savvy security professionals to early newcomers to the information security field. BackTrack promotes a quick and easy way to find and update the largest database of security tools collection to-date,Now as we know, The Backtrack Project Is Funded By Offensive Security And Informatik Org, The New Backtrack 6 Is Nothing like the earlier backtrack,This one has got a revamped interface, new libraries, NEW METASPOILT (yayy ), and other security tools.
So let us review them.
Installation -
The Kali Linux Has The Same Minimum Requirements like the last one,they
are : 1 GHz CPU, 8 GB of Hard Disk Space, 300 MB RAM, And
DVD-writer/Ability to boot with Pendrive.
The Installation is pretty simple . All you have to do is :
1 - Insert The DVD.
2 - Get Into The Boot Menu (f12 on dell, depends on motherboard)
3 - You will be greeted by the backtrack dragon, select the Graphical Install.
4 - Now Follow The On-Screen Steps and the new Backtrack will be installed.
As For Other Structures, Un-Official disk images from offensive security are also there.You can install Kali Linux On -
1 - VMWare
2 - Samsung Chromebook ARM
3 - Odroid U2
4 - Raspberry Pi (now that is what i am talking about)
5 - RK3306 / SS808
So Whats New In Kali Linux ?
Well the biggest change is that The Backtrack base changed Form Ubuntu
To Debian, This means the monkeys atbacktrack have to work hard to
design new software libraries.
Other noticeable change is in the /pentest directory.
As the guys over offensive security said, the /pentest creates a lot of
confusion, Now the tool you require will be directly accessible from
its directory.Now you will be able to call any tool from anywhere on the
system as every application is included in the system path.
Another Change is now the automatic update is set to synchronize with
the Debian repositories 4 times a day, constantly providing the latest package updates and security fixes available.
Other changes include : Long term packaging of high profile tools
(LTS),supports ARM,Improved Desktop Flexibility And Easy Upgrade to
Future Versions.
Also My favorite thing in this new backtrack is New Metaspoilt.Read Below For It.
Hack Any Website Over The Internet.
Hacking website by sqlmap and backtrack.
In this tutorial, we will learn how to Find a vulnerable Link in a website, Exploit that link by SQL Injection and taking total control over any website,This includes access to usernames and passwords database,
defacing it, address forwarding and much more.This is the most powerful
attack against any website and can create a word-wide mess if done for
evil purposes.
So What are we waiting for ? Lets Begin ...
What Do We Need For This Attack ?
# Backtrack 5 (Would work On Windows Too,Just find a sql injecting software)
# SQLMAP - Automatic SQL injection and database takeover tool (Included in Backtrack)
# Internet Access
# Brains And Balls.
# Lots Of Time.
Step-1 : Finding A Vulnerable Link.
This Is the MOST difficult step
in this step, because there are thousands of links in a website and
only some of them are capable of SQL Injection, So How to do it ?
The trick for this is to dig in the website and look for anything that might have access to an outside server,
We will use a scanner provided ny backtrack called "UniScan" which is
good at finding vulnerable links.To Open It,Type This In your console
(backtrack terminal) :
cd /pentest/web/uniscan && ./uniscan.pl
Follow the onscreen commands and run this tool to find the bug links,sure you can use other scanners.
Once you have found a link, check the link by adding (‘) ignore the brackets please, at the end of the link,
With an id or almost anything behind the php? and behind the = can be tested.
This is because we know it selected something from the database and this might be an entry point.
For Example :
Original "vulnerable" Link : http://www.waterufo.net/item.php?id=200
After adding the symbol : http://www.waterufo.net/item.php?id=200'
If a MySQL error occurs? Then it most likely is vulnerable to SQL Injection.
Example of a MySQL error:
You have an error in your SQL syntax;
Check the manual that corresponds to your MySQL server version for the right syntax to use near ''1''
Step 2 : Starting and Setting Up SQLMap :
The SQLMap is the best sql injecting tool ever made, It is good for both beginners and experts, To start it, Type the below command in console :
cd /pentest/web/scanners/sqlmap
Once it has Started, Change this command to your requirements and press enter :
./sqlmap.py -u (your bug link here) --level 5 --risk 3 --dbs
This command will scan the full website by the help of your vulnerable link you inserted.
Now let the scan continue and wait for something like this :
Using XHydra to hack router password
Here
we are. Firstly i must advise you to only use these methods to test
your own security. I will be hacking my own email address / router
password as example.
here are your tools - all can be found in backtrack 5 and some earlier versions.
*Update 4/27/2013*
i have written a part two Using Xhydra to hack aol instant messenger passwords (AIM)
Given the popularity of this post.
Start X-Hydra
Also Start Zenmap
Everything should start by looking like this:
We
will start by hacking a local network router password. This can be very
useful to a hacker in the scenario where one has cracked a wifi
password and gained local access to the network. After gaining access to
the router possibilities are endless. all router security can be
disabled and then we can perform MitM attacks (i will write an article on this later). if you're experienced enough in networking then you get the picture.
Typically
a router's IP address will start with 192.168.x.x. (which it may be in
your case) to check this type ipconfig in windows and ifconfig in linux.
the routers IP will be the Default Gateway).
Now i'm sure you have seen this before:
What
we are going to do is tell Xhydra to connect to the routers http server
with a protected page, input the username and bruteforce the password.
Note this method can be used against any similar password protected page
not using forms (will make another post on how to use against forms
later).
so your input should be like this:
Hacking email addresses using zenmap, xhydra and a wordlist.
I
have setup a rogue email account on a web server that i own a lease to.
What we are going to do is find the IP address to the server that sends
the mail, scan for open ports to mail services (Pop3 & SMTP) input
the data into Hydra and in return bruteforce for the password.
I
have done this on many occasions as a security tester and what i have
found is that MOST people use the same password for everything. That's
why it's important to keep your email password exclusive. What i have
found in 90% of the time is that people have everything linked to their
main email address. Online banking, website registration and Facebook to
name a few. All you have to do after gaining access to an important
email account is a little detective work along with some "forgot
password" forms and then you pretty must own the E-Identity. I'm going
to show you how to prevent this from happening to yourself and your
clients.
Please
note these are real hacking methods that are going to be tested on real
servers. One of the IP's i'm going to release correlates to a godaddy
hosted server, and even though anyone can find this i want to say i do
not condone black hat hacking, nor do i advise anyone to use these
methods for malicious use. Lets Get Started
www.brotherspropertymanagement.com will be our target for example.
In backtrack 5, Fire up a Terminal, Zenmap and Hydra-GTK.
ping the desired web server:
we see a secureserver hostname along with the IP. Typically in this instance i would run a zenmap scan on it.
However no
mail server is returned. This is a practical example of where we can be
de-railed because the mail server is different from the one we scanned.
but with a little research we can easily find the mail server AND
SETTINGS on google using the hostname.
We have found
the link for email setup. You will only need to do this if the web
server is hosted by a product like godaddy. In some situations the web
server will include all services to run the website and some back end
things like FTP,HTTP,POP,SMTP & MYSQL.
click the link
Those are the
settings. Now we see we have 2 options. pop.secureserver.net and
smtpout.secureserver.net. Please keep this in mind, These 2 servers HOST
ALL MAIL on godaddy websites. This is dangerous because if you really
wanted to you could scan a range of godaddy ip's, visit the websites,
copy the email addresses, make a list to bruteforce. This is why i
strongly advise a secure password.
Lets choose SMTP. It's not encrypted, doesn't kick us off after a few attempts of password breaking AND ITS FAST, SUPER FAST.
ping smtpout.secureserver.net a few times and you will see the ip is
different. it really doesn't matter so open Xhydra and configure like
this:
single target: smtpout.secureserver.net (this is the mail server)
port: 25 (this is default unencrypted SMTP port)
protocol: smtp (simple mail transfer protocol)
as always check off show attempts.
on the passwords tab for username you always want the full user with the @domain.com in the end our user is
rogueaccount@brotherspropertymanagement.com
select your password list. refer to my Last Post on how to find a wordlist in backtrack.
Or Click Here for Wordlist
Goto the start tab and click start.
Then we have success. I will be remove the rogue account so you little bastards don't try any funny business.
RECAP:
1. Find Target
2. Find SMTP Mail Server
3. Input data to Hydra
4. Crack Away
RECAP:
1. Find Target
2. Find SMTP Mail Server
3. Input data to Hydra
4. Crack Away


































