আপনি কি হ্যাকিং এ আগ্রহী আপনাদের জন্য ভালো কিছু করার সামান্য প্রচেষ্টা মাত্র।আমার এই ব্লগে একাধিক বিষয়ের উপরে আপনারা ধারনা পেয়ে থাকবেন।আশা রাখি সবাই আমার সাথে থাকবেন এবং অবশ্যই আপনাদের মতামত দিয়ে আমাকে উৎসাহিত করবেন। হ্যাকিং এর বেসিক ধরনা পেতে আজই এখানে ভিজিট করুন
Facebook massage
Monday, December 26, 2016
Introduction to POC(Proof Of Concept)
The word "POC" stands for Proof of concept(We can say as,"Prove of work"
for better understanding.Note that,this is not actual meaning.I have
wrote for better understanding for reader.)
Most often you should see this word on a hackers post(specially those who are in hacking team's groups)
a hacker shares what exploit he used to hack the site with poc.
we can see this example to understand more :
Hacked by ******
Site : http://127.0.0.1:8080/
POC : com_jce
Here com_jce is the exploit used by hacker to get into the site 127.0.0.1
Thats it all about POC.hope you have got my point.
Most often you should see this word on a hackers post(specially those who are in hacking team's groups)
a hacker shares what exploit he used to hack the site with poc.
we can see this example to understand more :
Hacked by ******
Site : http://127.0.0.1:8080/
POC : com_jce
Here com_jce is the exploit used by hacker to get into the site 127.0.0.1
Thats it all about POC.hope you have got my point.
What is "Mirror"?
mirror is a catched image of hacked site to keep record.A hacked site
can be instantly recovered and there won't be any record of it's being
hacked.So to keep a record with catched image of the hacked site is
called mirror.Zone-H is a such mirror site that keeps a record and ranks
the whole hacker teams status(ranking worldwide) depending on the
number of defaces,single ip(server),mass deface etc.also there are more
mirror site like add-attack,zone-hc etc.
What is "Deface/Defacing"?
According to dictionary the word "defacing" means to wreck
something.Likewise this,in the term of hacking the word means to change
any content to hackers wanted contents.Most often a hacker changes the
home(index.html/index.php) files contents to his message to the
admin.often he is seen replacing it with image or text file.This is
called defacing.the page(html/php) that is replaced by the hacker is
called "Deface Page"
How A Website Is Hacked?
We know that a website has script,database and hosting system.and a
computer system serves the contents.Also domain is used to identify a
website location.now how a hacker hacks into a website?let's come to the
point.a hacker first find out the security hole of the script
programmed.If he is able to find it,he exploits the vulnerability.so if
there is any ways he find to get into
the database info,he get the admin data that he needs to login to the
ftp(file transter protocol) or admin panel.once he entered into the ftp
he has the full control to hack the site(edit,delete,create).so he
defaces the site to alert the admin of the site.if he is able to login
to the admin panel and the panel has the functions like ftp,he can do
what he wants.but in this case he needs a malicious script that is
called "shell".so shell is a script that has the control like ftp.It
allows a hacker to get the full ftp access through the script.There are
many types of shells.for example : c99;r57;madshell;moonshell etc.there
are some private shells too.so thus a website is hacked.Now when a
hacker is able to hack 1 site on the server,he can root the server(get
the main server access/computer system access) to hack other/all sites
in the server.It is called "mass deface(massive deface)".The word "Web
Application" is a computer application that manages and maintains the
full server.if there is any programming error found by a hacker,he can
get to the root.Such vulnerable web applications are called "DVWA(Damn
Vulnerable Web Application)".In case a hacker doesn't find any
vulnerability,he tries to bruteforce(crack) the login panel of
website/ftp(file transfer protocol).If he fails this time,he try to
hijack the domain.If fails again then he DOS/DDOS the site to take it
down for a few time so that the actual work of the site gets
hampered.Also if a hacker can hack the email of the admin,he can reset
the password and get into the site(ex. wordpress).If a hacker doesn't
have the main ftp control,the site can be restored because the admin has
the ftp access and he can delete the shell so that a hacker has no
right to hack again(Also,if the vulnerability is patched).If a hacker
wants to hack the site again,he has to exploit again(if vulnerability is
not patched).he can't hack if the vulnerability is patched.So this is
all about how a website gets hacked.Still there are many ways to hack
into a website or take that down.
Written by Choyon Ahmed
Written by Choyon Ahmed
Is exploiting websites finding from google the only way of practising exploitation skill?
a pentester or hacker can practise an exploit related to web
applications by downloading the vulnerable web application rather than
trying to find sites vulnerable to that exploit if gathering experience
is the main target of a hacker.because,we cant often get websites to
practise exploits to improve our skills.so,downloading the respective
vulnerable web application shortens our
time and helps us improve our exploitation skill.as i said before,if you
try things manually,you will be able to get a lot of experience than
doing things with automated tools.
also,if you are a exploit patcher,you can improve your patching skill by trying that skill on that vulnerable web application.
now,where to find such apps?
www.dvwa.co.uk is the official site of damn vulnerable web applications(DVWA) where such softwares can be found.
and also look in exploit databases sites for getting related vulnerable web app.
Written By Choyon Ahmed
also,if you are a exploit patcher,you can improve your patching skill by trying that skill on that vulnerable web application.
now,where to find such apps?
www.dvwa.co.uk is the official site of damn vulnerable web applications(DVWA) where such softwares can be found.
and also look in exploit databases sites for getting related vulnerable web app.
Written By Choyon Ahmed
Common FAQ : Does Shell Work Perfectly On Mobile?
FAQ(frequently asked question)
Topic : does shell work perfectly on mobile?
this question always comes in mind of a newbie.
well,brother. to your utter surprise that,yes,you can easily deface a website using shell just from your mobile phone.
all you are required is a good browser like Opera mini or UC browser.
when you have done uploading shell,if you open the shell location,you will see the shell panel and you can work with it perfectly as you can do with computer.
try using shells like madspot,wso,c99 and they will work very fine.
an example of live shell to test whether you can do it or not is below
http://gallerymermaid.com/ upload/gmsubmenu_image/big/ 1352577864_config.php
[if the link becomes dead,notify me.i will update a new one.but,be
moved that the following shell is not working for defacement]
Written By Choyon Ahmed
Topic : does shell work perfectly on mobile?
this question always comes in mind of a newbie.
well,brother. to your utter surprise that,yes,you can easily deface a website using shell just from your mobile phone.
all you are required is a good browser like Opera mini or UC browser.
when you have done uploading shell,if you open the shell location,you will see the shell panel and you can work with it perfectly as you can do with computer.
try using shells like madspot,wso,c99 and they will work very fine.
an example of live shell to test whether you can do it or not is below
http://gallerymermaid.com/
Written By Choyon Ahmed
What Search Engines To Use For Finding Exploitable Websites
maximum people only knows about google search engine.but there are a lot
of search engines in the web available. as google is more known,and
supports dork technology that helps much a hacker/defacer/pentester for
finding exploitable locations easily,but still other search engines like
bing,yahoo,duckduckgo etc. can be used for getting new sites for
defacing.although these search engines does not support dorks
technology,still you can use them to find new sites that can be
exploitable.
if you are using google only,then customise your dorks.just a single change in your search string can change the result into a full new result.
use your brain to customise your dorks.when you are using any existing exploit(that is published worldwide),then remember that,there are many hackers trying the same exploit like you.so, customise your dorks.
you will be successful to get new sites :)
thanks for reading..
Written By Choyon Ahmed
if you are using google only,then customise your dorks.just a single change in your search string can change the result into a full new result.
use your brain to customise your dorks.when you are using any existing exploit(that is published worldwide),then remember that,there are many hackers trying the same exploit like you.so, customise your dorks.
you will be successful to get new sites :)
thanks for reading..
Written By Choyon Ahmed
Mobile Compactability For Defacing A Site
many people stays in a hesitation about is it really possible to deface or even hack a website just using a mobile?
my clear confirmation to them is,yes.you can do it!
you will ask how...
coming to the point.your skill is depended upon how much you can learn/know exploits and your selection of correct working valid exploit.
people first suggest all to learn SQL injection.but,people wants things to be done automatically and easily.so they try using auto tools but these doesnt work perfectly and so they give up hope.but,SQL injection is not the only way of hacking into a computer server.you can try different CMS exploits too.if you give things a try,you can probably do with whatever device you want!
dont play with tools.always try things manually and you will become successful also will gather experience too.this will improve your exploitation skill on any other vulnerabilities.use your brain,you will power and patience.you will become successful to deface with just a simple java mobile.
written bY Choyon Ahmed
my clear confirmation to them is,yes.you can do it!
you will ask how...
coming to the point.your skill is depended upon how much you can learn/know exploits and your selection of correct working valid exploit.
people first suggest all to learn SQL injection.but,people wants things to be done automatically and easily.so they try using auto tools but these doesnt work perfectly and so they give up hope.but,SQL injection is not the only way of hacking into a computer server.you can try different CMS exploits too.if you give things a try,you can probably do with whatever device you want!
dont play with tools.always try things manually and you will become successful also will gather experience too.this will improve your exploitation skill on any other vulnerabilities.use your brain,you will power and patience.you will become successful to deface with just a simple java mobile.
written bY Choyon Ahmed
Subscribe to:
Posts (Atom)
-
[PDF] Walkthrough on web defacement & hacking Name : A Walkthrough on website defacement & hacking Author : W@X V@MP!R3 Size : ...
-
W3schools offline version[1.7mb 7z] Complete programming languages all in one http://dl.dropbox.com/u/ 70534161/ W3schools%20Offlin...
-
What is Certified Ethical Hacker(CEH) ? http://en.wikipedia.org/wiki/ Certified_Ethical_Hacker