Facebook massage

Monday, December 26, 2016

What is Reverse DNS Lookup

www.wikipedia.org/wiki/Reverse_DNS_Lookup

YUMI - Boot Linux from Pendrive

www.pendrivelinux.com/yumi-multiboot-usb-creator/

Introduction to POC(Proof Of Concept)

The word "POC" stands for Proof of concept(We can say as,"Prove of work" for better understanding.Note that,this is not actual meaning.I have wrote for better understanding for reader.)
Most often you should see this word on a hackers post(specially those who are in hacking team's groups)
a hacker shares what exploit he used to hack the site with poc.
we can see this example to understand more :

Hacked by ******
Site : http://127.0.0.1:8080/
POC : com_jce

Here com_jce is the exploit used by hacker to get into the site 127.0.0.1
Thats it all about POC.hope you have got my point.

What is "Mirror"?

mirror is a catched image of hacked site to keep record.A hacked site can be instantly recovered and there won't be any record of it's being hacked.So to keep a record with catched image of the hacked site is called mirror.Zone-H is a such mirror site that keeps a record and ranks the whole hacker teams status(ranking worldwide) depending on the number of defaces,single ip(server),mass deface etc.also there are more mirror site like add-attack,zone-hc etc.

What is "Deface/Defacing"?

According to dictionary the word "defacing" means to wreck something.Likewise this,in the term of hacking the word means to change any content to hackers wanted contents.Most often a hacker changes the home(index.html/index.php) files contents to his message to the admin.often he is seen replacing it with image or text file.This is called defacing.the page(html/php) that is replaced by the hacker is called "Deface Page"

How A Website Is Hacked?

We know that a website has script,database and hosting system.and a computer system serves the contents.Also domain is used to identify a website location.now how a hacker hacks into a website?let's come to the point.a hacker first find out the security hole of the script programmed.If he is able to find it,he exploits the vulnerability.so if there is any ways he find to get into the database info,he get the admin data that he needs to login to the ftp(file transter protocol) or admin panel.once he entered into the ftp he has the full control to hack the site(edit,delete,create).so he defaces the site to alert the admin of the site.if he is able to login to the admin panel and the panel has the functions like ftp,he can do what he wants.but in this case he needs a malicious script that is called "shell".so shell is a script that has the control like ftp.It allows a hacker to get the full ftp access through the script.There are many types of shells.for example : c99;r57;madshell;moonshell etc.there are some private shells too.so thus a website is hacked.Now when a hacker is able to hack 1 site on the server,he can root the server(get the main server access/computer system access) to hack other/all sites in the server.It is called "mass deface(massive deface)".The word "Web Application" is a computer application that manages and maintains the full server.if there is any programming error found by a hacker,he can get to the root.Such vulnerable web applications are called "DVWA(Damn Vulnerable Web Application)".In case a hacker doesn't find any vulnerability,he tries to bruteforce(crack) the login panel of website/ftp(file transfer protocol).If he fails this time,he try to hijack the domain.If fails again then he DOS/DDOS the site to take it down for a few time so that the actual work of the site gets hampered.Also if a hacker can hack the email of the admin,he can reset the password and get into the site(ex. wordpress).If a hacker doesn't have the main ftp control,the site can be restored because the admin has the ftp access and he can delete the shell so that a hacker has no right to hack again(Also,if the vulnerability is patched).If a hacker wants to hack the site again,he has to exploit again(if vulnerability is not patched).he can't hack if the vulnerability is patched.So this is all about how a website gets hacked.Still there are many ways to hack into a website or take that down. 

Written by Choyon Ahmed

Is exploiting websites finding from google the only way of practising exploitation skill?

a pentester or hacker can practise an exploit related to web applications by downloading the vulnerable web application rather than trying to find sites vulnerable to that exploit if gathering experience is the main target of a hacker.because,we cant often get websites to practise exploits to improve our skills.so,downloading the respective vulnerable web application shortens our time and helps us improve our exploitation skill.as i said before,if you try things manually,you will be able to get a lot of experience than doing things with automated tools.
also,if you are a exploit patcher,you can improve your patching skill by trying that skill on that vulnerable web application.
now,where to find such apps?
www.dvwa.co.uk is the official site of damn vulnerable web applications(DVWA) where such softwares can be found.
and also look in exploit databases sites for getting related vulnerable web app.

Written By Choyon Ahmed 

Common FAQ : Does Shell Work Perfectly On Mobile?

FAQ(frequently asked question)
Topic : does shell work perfectly on mobile?
this question always comes in mind of a newbie.
well,brother. to your utter surprise that,yes,you can easily deface a website using shell just from your mobile phone.
all you are required is a good browser like Opera mini or UC browser.
when you have done uploading shell,if you open the shell location,you will see the shell panel and you can work with it perfectly as you can do with computer.
try using shells like madspot,wso,c99 and they will work very fine.
an example of live shell to test whether you can do it or not is below
http://gallerymermaid.com/upload/gmsubmenu_image/big/1352577864_config.php [if the link becomes dead,notify me.i will update a new one.but,be moved that the following shell is not working for defacement]


Written By Choyon Ahmed

What Search Engines To Use For Finding Exploitable Websites

maximum people only knows about google search engine.but there are a lot of search engines in the web available. as google is more known,and supports dork technology that helps much a hacker/defacer/pentester for finding exploitable locations easily,but still other search engines like bing,yahoo,duckduckgo etc. can be used for getting new sites for defacing.although these search engines does not support dorks technology,still you can use them to find new sites that can be exploitable.
if you are using google only,then customise your dorks.just a single change in your search string can change the result into a full new result.
use your brain to customise your dorks.when you are using any existing exploit(that is published worldwide),then remember that,there are many hackers trying the same exploit like you.so, customise your dorks.
you will be successful to get new sites :)
thanks for reading..


Written By Choyon Ahmed

Mobile Compactability For Defacing A Site

many people stays in a hesitation about is it really possible to deface or even hack a website just using a mobile?
my clear confirmation to them is,yes.you can do it!
you will ask how...
coming to the point.your skill is depended upon how much you can learn/know exploits and your selection of correct working valid exploit.
people first suggest all to learn SQL injection.but,people wants things to be done automatically and easily.so they try using auto tools but these doesnt work perfectly and so they give up hope.but,SQL injection is not the only way of hacking into a computer server.you can try different CMS exploits too.if you give things a try,you can probably do with whatever device you want!
dont play with tools.always try things manually and you will become successful also will gather experience too.this will improve your exploitation skill on any other vulnerabilities.use your brain,you will power and patience.you will become successful to deface with just a simple java mobile.


written bY Choyon Ahmed