Pages

4 Ways To Hack Facebook

4 Ways To Hack Facebook

In this guide I'll show you ways that hackers (and even regular folks) can hack into someone's Facebook account. Also I'll show you how to prevent it from happening to you.



Method 1: Reset the Password


The easiest way to "hack" into someone's Facebook is through resetting the password. This could be easier done by people who are friends with the person they're trying to hack.


  • The first step would be to get your friend's Facebook email login. If you don't already know it, try looking on their Facebook page in the Contact Info section.
  • Next, click on Forgotten your password? and type in the victim's email. Their account should come up. Click This is my account.


  • It will ask if you would like to reset the password via the victim's emails. This doesn't help, so press No longer have access to these?
  • It will now ask How can we reach you? Type in an email that you have that also isn't linked to any other Facebook account.



  • It will now ask you a question. If you're close friends with the victim, that's great. If you don't know too much about them, make an educated guess. If you figure it out, you can change the password. Now you have to wait 24 hours to login to their account.


  • If you don't figure out the question, you can click on Recover your account with help from friends. This allows you to choose between three and five friends.


It will send them passwords, which you may ask them for, and then type into the next page. You can either create three to five fake Facebook accounts and add your friend (especially if they just add anyone), or you can choose three to five close friends of yours that would be willing to give you the password.


How to Protect Yourself


  • Use an email address specifically for your Facebook and don't put that email address on your profile.


  • When choosing a security question and answer, make it difficult. Make it so that no one can figure it out by simply going through your Facebook. No pet names, no anniversaries—not even third grade teacher's names. It's as easy as looking through a yearbook.


  • Learn about recovering your account from friends. You can select the three friends you want the password sent to. That way you can protect yourself from a friend and other mutual friends ganging up on you to get into your account.

Method 2: Use a Keylogger

Software Keylogger


A software keylogger is a program that can record each stroke on the keyboard that the user makes, most often without their knowledge. The software has to be downloaded manually on the victim's computer. It will automatically start capturing keystrokes as soon as the computer is turned on and remain undetected in the background. The software can be programmed to send you a summary of all the keystrokes via email.

CNET has Free Keylogger, which as the title suggests, is free. If this isn't what you're looking for, you can search for other free keyloggers or pay for one.


Hardware Keylogger


These work the same way as the software keylogger, except that a USB drive with the software needs to be connected to the victim's computer. The USB drive will save a summary of the keystrokes, so it's as simple as plugging it to your own computer and extracting the data. You can look through Keelog for prices, but it's bit higher than buying the software since you have the buy the USB drive with the program already on it.





How to Protect Yourself


  • Use a firewall. Keyloggers usually send information through the internet, so a firewall will monitor your computer's online activity and sniff out anything suspicious.


  • Install a password manager. Keyloggers can't steal what you don't type. Password mangers automatically fill out important forms without you having to type anything in.


  • Update your software. Once a company knows of any exploits in their software, they work on an update. Stay behind and you could be susceptible.


  • Change passwords. If you still don't feel protected, you can change your password bi-weekly. It may seem drastic, but it renders any information a hacker stole useless.
Method 3: Phishing

This option is much more difficult than the rest, but it is also the most common method to hack someone's account. The most popular type of phishing involves creating a fake login page. The page can be sent via email to your victim and will look exactly like the Facebook login page. If the victim logs in, the information will be sent to you instead of to Facebook. This process is difficult because you will need to create a web hosting account and a fake login page.



The easiest way to do this would be to follow our guide on how to clone a website to make an exact copy of the facebook login page. Then you'll just need to tweak the submit form to copy / store / email the login details a victim enters. If you need help with the exact steps, there are detailed instructions available by Alex Long here on Null Byte. Users are very careful now with logging into Facebook through other links, though, and email phishing filters are getting better every day, so that only adds to this already difficult process. But, it's still possible, especially if you clone the entire Facebook website.

How to Protect Yourself


  • Don't click on links through email. If an email tells you to login to Facebook through a link, be wary. First check the URL (Here's a great guide on what to look out for). If you're still doubtful, go directly to the main website and login the way you usually do.


  • Phishing isn't only done through email. It can be any link on any website / chat room / text message / etc. Even ads that pop up can be malicious. Don't click on any sketchy looking links that ask for your information. Use anti-virus & web security software, like Norton or McAfee.
Method 4: Stealing Cookies

Cookies allow a website to store information on a user's hard drive and later retrieve it. These cookies contain important information used to track a session that a hacker can sniff out and steal if they are on the same Wi-Fi network as the victim. They don't actually get the login passwords, but they can still access the victim's account by cloning the cookies, tricking Facebook into thinking the hacker's browser is already authenticated.




Firesheep is a Firefox add-on that sniffs web traffic on an open Wi -Fi connection. It collects the cookies and stores them in a tab on the side of the browser.


From there, the hacker can click on the saved cookies and access the victim's account, as long as the victim is still logged in. Once the victim logs out, it is impossible for the hacker to access the account.

How to Protect Yourself


  • On Facebook, go to your Account Settings and check under Security. Make


sure Secure Browsing is enabled. Firesheep can't sniff out cookies over encrypted connections like HTTPS, so try to steer away from HTTP.


  • Full time SSL. Use Firefox add-ons such as HTTPS-Everywhere or Force-TLS.


  • Log off a website when you're done. Firesheep can't stay logged in to your account if you log off.


  • Use only trustworthy Wi-Fi networks. A hacker can be sitting across from you at Starbucks and looking through your email without you knowing it.


  • Use a VPN. These protect against any sidejacking from the same WiFi


network, no matter what website you're on as all your network traffic will be encrypted all the way to your VPN provider.





Protecting Yourself: Less Is More


Social networking websites are great ways to stay connected with old friends and meet new people. Creating an event, sending a birthday greeting and telling your parents you love them are all a couple of clicks away.


Facebook isn't something you need to steer away from, but you do need to be aware of your surroundings and make smart decisions about what you put up on your profile. The less information you give out on Facebook for everyone to see, the more difficult you make it for hackers.


If your Facebook account ever gets hacked, check out our guide on getting your hacked Facebook account back for information on restoring your account.



check out the Same Origin Policy Facebook hack and the somewhat easier, Facebook Password Extractor.

The Ultimate Spreading eBook

cafepressthemes@gmail.com

An Efficient Technique For Spreading

Your Virus V2

Introduction


This eBook will give you a unique way to spread your virus. By utilizing these techniques together, one can easily achieve 1,000 downloads per day. There are no pre-requisites, and all you need is a brain. Get ready to SE your way to 1,000 Downloads (or more) a day!

NOTE: I do not take ANY responsibilities for what you may/will do with the knowledge from this guide. The purpose of this guide is merely for educational purposes.

“The Method” # 1




Youtube is a great way to spread viruses, and we can leave our videos for people to see all around the world.. Even when we are sleeping! In this method we are going utilize a javascript, fake program, and some

unique methods of youtube promoting to get you the downloads you want.

Preparation

  1. Download CamTasia Studio. (Check download links at the bottom of the eBook for full version of Camtasia 7)

  1. Open up your virus builder. (Example: Metus, XR, etc.) And build your server with proper details, and information. If your virus isn’t already 100% FUD, crypt it. (Check download links at the bottom of the eBook for a FUD Crypter) NOTE: If your virus is NOT FUD (Fully Undiscoverable) you will not get very many executions.

  1. Make a new paypal account, and make sure it is NOT verified.

(Premier or Buisness)  Also make sure your balance is 0.00$

Execution of Method 1

  1. Open up your Camtasia Screen Recorder. (make sure you are talking, and narrating through a mic. Worst case scenario, just add subtitles at the end of the video with Camtasia Studio)

  1. Talk about what your video is about. (a PayPal money generator that works!) Make sure throughout this video you have a sincere, firm tone. (Makes the video subconsciously more believable.)

  1. Open up your PayPal, and show the viewers you have 0.00 $. As well as:

    • The current date. (Last logged on as ____________)

    • Current transactions

  1. Now log out, and go to your paypal money generator. (Check download links at the bottom of the eBook for a Fake PayPal program)

  1. Generate any amount (except for the highest amount of money) and tell the viewers not to use that one, seeing as it’s a high risk of getting caught)

  1. Now open up your browser again, and keep the recording going until right after the (Logging in..) flash screen.

  1. You should now be at your PayPal homepage. Paste the following javascript into your URL Bar, and hit enter: javascript:document.body.contentEditable='true'; document.designMode='on'; void 0

  1. You should notice some of the colors on the page change. This means the page is now editable (Dont get too excited everything goes away after a refresh :/)

  1. Change your balance to the amount your generator is generating. (Ex. If your generator from step 4. Is giving you 1000$ then thats the amount you edit your balance to be)

  1. After your done the edit, DONT REFRESH/LEAVE the page.

Instead continue your recording. Be calm about it, and say how it works. Remember to show the date again, and how you still don’t have any transactions. Right before you end the video, say:

Oh yeah, by the way be careful, and don’t use this more then once a month

Editing your video

  1. Okay, open up your favourite Video Editing program. (I use Sony Vegas: Check the downloads section at the bottom of the eBook if you want it) Or if your a lamer open up the

Camtasia Editor. Line up your videos, and trim any excess pauses and sloppiness.

  1. MAKE SURE to add background music, but make it very faint. The purpose of this is to only cover up the pauses/differences in sound. (from when you stop, and star the recording)

  1. This video is meant to look like it was done in one whole shot.

  1. Now this step is important: After editing your video, don’t name it something like: OMG SPREADING VIDEO, Vid#1 etc.

Instead name it with tags that people would search on youtube. How to hack paypal, Get free money from paypal etc.

  1. The vaguer your tags are the better.

  1. Now when YouTube asks you for Official Tags for the video. That’s when you can put specific ones. What this does is balance out specific-vague.

Extra Video Promoting

  1. Download Refresh Every, Mozilla Firefox, and a list of proxies (Check Downloads Section at the bottom of the eBook for Download)

  1. [Install Firefox if you don’t already have it] Install Refresh Every (add-on) and add the list of proxies to it.

  1. Visit your YouTube video, and keep execute Refresh Every. (The point of this is, the more views you get. The easier it is for anybody searching something similar to your tags to find it.)

  1. Remember to post your video as video responses to other popular videos.

5. Remember to include virus scans in your video information.

“The Method” # 2


MANY WAREZ-RELATED FORUMS ARE FILLED WITH NOOBS WHO ARE LOOKING TO DOWNLOAD AS

MANY FREE ISOS/GAMES/MOVIES AS POSSIBLE. THIS IS WHEN WE EXPLOIT THEM!


1. FUD your Virus. (Check downloads sections at the bottom of the eBook for a FUD Crypter!)

2. Change the icon to a .txt file using ResHacker. (Check downloads section at the bottom of the eBook for ResHacker + tutorial!) Now

rename the virus to “README, README!, IMPORTANT” Or something along those lines.

3. Now go to a Warez website such as www.pspiso.com, and find a popular game or movie. ( For Example: Bioshock 2 )

4. Take all of the links, and go to www.lix.in and rename them. (enter URL + click Enter)

5. Upload your virus to the exact same host as the other links were from (Example: If the Bioshock 2 links were uploaded on Megaupload, then use Megaupload to upload your Virus)

6. Post on the same forum (or another one, it doesn’t matter) the same game, but use the lix.in (Hidden) links instead.

7. Before all of the proper links, post the “Readme,” with Huge, bold, underlined, colourful letters saying something like “README! IMPORTANT NOTES ON HOW TO INSTALL THE
GAME!”


THE END – THANKS FOR READING .. NOTE: V3 IS

COMING OUT SOON!



AND REMEMBER IF YOU NEED ANY HELP WITH YOUR DOWNLOADS/THIS GUIDE PM ME ON HACKFORUMS
DOWNLOADS



Camtasia Screen Recorder:

Trial Download: http://www.techsmith.com/download/camtasiatrial.asp

Serials: FZJMD-ABACG-HWBDT-LNATL-X7M82 DKLNG-8BRSD-ZERDM-WP69K-H7467 3MRXG-SCVCM-

BAWN2-45PTV-B7BE4

FUD Crypter:

Fake Paypal Program: http://00e276bf.seriousfiles.com/ or

http://86abed39.seriousfiles.com/

Sony Vegas: http://www.sonycreativesoftware.com/download/link?id=4208.1 & 1HF-50C1-L9NW-8WX5 or 1HF-D0W9-D22R-G98N

Some Proxies: http://www.freeproxy.ru/download/lists/goodproxy.txt

Refresh Every: https://addons.mozilla.org/en-US/firefox/addon/115/

Mozilla Firefox: http://download.mozilla.org/?product=firefox-3.6.3&os=win&lang=en-GB

Trojan Horse - Overview

Trojan Horses


Back to the "modern" Trojan Horses. They're pretty much the same: invisible to the naked eye; appear within harmless programs; require some form of user/operating system intervention to activate; and they do something unexpected by surprise. This article is just to convey a basic principle about the design of Trojan horse programs.

Trojans are designed to access permissions and exploit resources. The goal of password snatchers is to securely leak the login/password pairs to the Trojan author, and the goal in kleptographic attacks is to securely leak private keys to the attacker.
Nature of Trojan Horses


There is no "real" definition of a Trojan horse. It all depends on the perspective of the user that runs into it. From the perspective of a hacker (generally black-hat hackers), a reboot monitoring Trojan (useful in making sure no one used your machine) is not a Trojan to him/her since the hacker knows what it's about. From a law enforcement agent or people like that, it is a Trojan since the agent doesn't know it's there.

There are two examples of Trojans. One is a Trojan that is nothing more than a bug. Don't think that's a good thing. This bug could be bad enough that when planted properly, a Trojan author can break into the computer system. The second Trojan is a mathematical one. The statistical distribution of the output of a random number generator is affected so that it makes the generator very sensitive to the input entropy (I will not go into detail in this, please Google if you do not understand this :D).
TH in a text editor


An example of a text editor being used as a target for a Trojan horse:

If there was an installed text editor on a multiuser operating system which cannot be deleted or modified by the users themselves, then this program has certain unique privileges. For instance, It can access all the text files that users create or open. This would be the perfect target for a Trojan horse. When the Trojan is installed on this program, it will store data from users and makes the data accessible for the Trojan horse author.
Salami Slicing


There was once an article describing a Trojan horse attack that was intended to achieve money. This was carried out by an employee of a bank. He managed to get 70 000$ by taking a few cents from every account, and transferred it into his own account. It got the name of salami slicing because small amounts of money were taken from a lot of accounts. It's pretty useful to prevent anyone from noticing any drastic changes. The bank Trojan had access to money therefore the Trojan steals the money. Therefore, a text editor has access to documents so the Trojan steals the documents (pretty simple isn't it?).
Password Snatching


Every hacker would love to steal login/password pairs (referring to black-hat hackers). Password-snatching programs are installed when a system is infiltrated. These programs are also called rootkits. They were probably written in DOS terminate and stay resident programs (TSR). They record all keystrokes entered via the keyboard and patch the operating system hardware interrupt for key presses and log them to a file.

It is best if a password-snatching Trojan is hosted in a program that could access the passwords of users, like the UNIX "passwd" program. It verifies the identity of UNIX users by checking the login/password pairs. One could copy the Trojan to the end of the passwd program, or one could modify the source code for the password program, recompile it, and then install the compromised version (only if the root access is possible).

However, if the source code for the passwd program is updated and the administrator compiles a new version of it, then the attack would fail. So it would make sense to install a Trojan horse into the compiler which will increase the percentage of success of the attack. But if the compiler is recompiled, then the code that secretly inserts the Trojan into the passwd program would be gone.
______________________________________________________________________

There's not much left for me to explain. But one more thing for you to see :

Ken Thompson described an involved Trojan horse attack.

CODE : 
compiler(char*s)
{
...
}


This is a figure of a normal compiler (ANSI C notation) (I did not create this)

The parameter s is a pointer to a string that contains the source code. The idea is to insert a source level Trojan horse into the source code of the compiler that checks for two patterns in the string s.

The first pattern is source code corresponding to the password verification program. When it is found, the password-snatching source code is added to the program before it is compiled. But the Trojan is not saved to the source file of the password program.

The second pattern is source code corresponding to the compiler. When it is found, the entire compiler Trojan is included in the compiler source code. It will contain all of the source code for the Trojan which is marked by the "if" statements in this following figure.

CODE : 
compile(char*s)
{
if (match)s,pattern1) ==true)
{
compile(trojan1);
return;
}
if (match)s,pattern2) ==true)
{
compile(trojan2);
return;
}
...
}



Figure of a compiler with Trojan (ANSI C notation)(I did not create this either)

Whenever the compiler is compiled, the Trojan copies itself into the source file for the compiler. It can be added to the source for the compiler then the compiler could be recompiled, and the old compiler could be replaced. This would remove all traces of the source code for the Trojan attack. It would remain in binary form, integrated with the compiled instructions.

So Thompson's Trojan horse attack exploits the capabilities of its host. For example, it exploits the fact that compilers are used to create programs such as the passwd program and the compiler itself.
Also, it exploits the fact that the passwd program has access to login/password pairs and that the compiler has access to them as well by transitivity.

Yeah... I believe that this is okay to be an overview of Trojan horses. Please note that this is my first article, so my writing skills are not that great D: .

Statistics Help Online

Are you a college student taking a statistics course and interested in paying someone to do mymathlab  for you ? We provide stats help in ar...