Facebook massage

Tuesday, December 27, 2016

Introduction to Symlinking & how hackers use that

s who are using a system.Such helps the root user(root : the main user account of that system who can make any changes to files/directories etc. even of other users too) to protect the system from unauthorised data modification.Thats why,linux based systems are mostly used as servers for websites.
Now,how hacker can take over all the users files(if its a server,then hacker will have access to all the sites)?symlinking is the way.using the symlinking,hacker can execute other users files in his browser.suppose, if hacker takes access to "user001" in a server,if symlinking is allowed,hacker can try accessing files of "user002" and others using symlink.each site has a database config file that contains admin info.(ex. wp-config.php for wordpress CMS).using that,hacker can connect to mySQL db and find admin data and compromise sites under "user002" and others.
Thus,symlinking is used for mass defacement in a server.but,things needs to be done one by one.
Thanks for reading.
Google search for methods and more queries ...

Noob Friendly Guide On How To Mirror A Defaced Site

..
I will be mentioning about zone-h here which is the main standard of mirroring service.
1.Go to www.zone-h.org/notify/single (if you want to notify only one site) or www.zone-h.org/notify/mass (if you want to add upto 10 mirrors per one submit)
2.Now, go down the page and
in first box : Your notifier name/Team name(for ex. Team_CC - we use this)
in second box : your defaced url(zone-h has some keyword restrictions.)
in third box : Other web application bugs(actually what exploit you used, should be selected)
in fourth box : Not available(the reason why you hacked the site)
then submit.
your mirrored site will be available on whether www.zone-h.org/archive/published=0/notifier=Your-Notifier-Name-That-You-Used-in-First-Box
or www.zone-h.org/archive/notifier=Your-Notifier-Name-That-You-Used-in-First-Box
zone-h allows one single site to mirror only once per each year.means, if your defaced/hacked site is hacked in this year,you cant mirror it again.you can mirror the site after one year.
system of site mirroring is as same as zone-h has...
Jazakallah.

GRUB - Bootloader Software


GNU GRUB is a multiboot loader software that helps adding a boot selection menu on computer startup.
From the official website,GNU GRUB is a Multiboot boot loader. It was derived from GRUB, the GRand Unified Bootloader, which was originally designed and implemented by Erich Stefan Boleyn.

Briefly, a boot loader is the first software program that runs when a computer starts. It is responsible for loading and transferring control to the operating system kernel software (such as the Hurd or Linux). The kernel, in turn, initializes the rest of the operating system (e.g. GNU).

Wiki : http://en.wikipedia.org/wiki/GNU_GRUB
Download link : ftp://ftp.gnu.org/gnu/grub/grub-2.00.tar.gz 7.9 MB
Below are a list of exploit database sites 
Total Sites : 16 
Last Update : 05.03.2015 

1. www.exploit-db.com 
2. www.1337day.com 
3. www.exploit-id.com 
4. www.exploit4arab.net 
5. www.rapid7.com/db 
6. www.bugsearch.net 
7. http://packetstormsecurity.com 
8. http://1337mir.com 
9. http://iedb.ir 
10. www.irist.ir 
11. http://cxsecurity.com 
12. www.cvedetails.com 
13. www.intelligentexploit.com 
14. https://wpvulndb.com 
15. www.securiteam.com 
16. www.governmentsecurity.org/exploits

[PDF] Walkthrough on web defacement & hacking

Name : A Walkthrough on website defacement & hacking
Author : W@X V@MP!R3
Size : 101 KB
Pages : 6
Short Info : This ebook will guide a reader about how a website is hacked(maximum detailed info available) and what website defacement is and differences between them.
Link : www.2shared.com/document/3hvBDhQ2/Walkthrough_On_Web_Defacement_.html

হ্যাকিং এবং ডিফেসিং কি এক?

েব সার্ভারে অবস্থিত ওয়েবসাইট এ অনধিকার প্রবেশ করে সেই ব্যবস্থার নিরাপত্তা ছিদ্র সাইটের মালিকের দৃষ্টিগোচর করার জন্য সাইটে তার নিজের যে পেজ সাইটের মূল পেজের সাথে পরিবর্তন করে,তাকেই ডিফেসিং বলে(এই সম্পূর্ণ পদ্ধতিকে)
যে পেজটি আপলোড করে,তাকে ডিফেস পেজ বলে।
তো,হ্যাকিং করে যেমন ডিফেসিং করা সম্ভব,তেমনি হ্যাকিং না করেও ডিফেসিং করা সম্ভব।
একজন হ্যাকার যদি সাইটের সকল ফাইলের পরিবর্তন,মুছে ফেলার অধিকার পায়,তবে তা হ্যাকিং এর পর্যায়ে পড়ে।
আর,এমনও কিছু পদ্ধতি আছে যার সাহায্যে যে কেউ ওয়েবসাইট এর একটি নির্দিষ্ট ডাইরেক্টরিতে ফাইল আপলোড করতে পারে।সেই সব ক্ষেত্রে তাকে শুধু ডিফেসিং বলা হবে।
এখন,ফাইল আপলোডের জায়গায় যদি সে শেল(শেল হচ্ছে এক বিশেষ কোডিং যা একজন হ্যাকারকে ওয়েবসাইট এর মূল কন্ট্রোল প্যানেলের মতো সুযোগ সুবিধা দেয়।এর সাহায্যে হ্যাকার সাইটের সবকিছু পরিবর্তন করতে পারেন।) আপলোড করা হয় এবং তা কার্যকরী হয়,তবে তা হ্যাকিং এর পর্যায়ে পড়বে।
শুধু ডিফেস পেজ আপলোড করাকে ডিফেসিং এবং শেল আপলোড করে ডিফেস করাকে হ্যাকিং+ডিফেসিং বলে।
ডিফেস পেজ html,asp,php,text,jpg,gif ইত্যাদি ফরম্যাটে হতে পারে।
তো,আশা করছি যে,এই পোষ্টটি যারা পড়েছেন তাদের এই বিষয়গুলো সম্পূর্ণ পরিষ্কার হয়ে গেছে।
লিখাঃ ওয়াক্স ভ্যাম্পায়ার

পেনড্রাইভ থেকে বুট করুন লিনাক্স কোন হার্ডডিস্ক ইন্সটলেশন ছাড়াই!

How to BOOT linux distributions from pendrive in bangla and,English version is available here

লিনাক্সের অপারেটিং সিস্টেমগুলো ৩ টি প্রধান উপায়ে বুট করা যেতে পারে।
১.DVD তে বার্ন করে(ইমেজ burning সফটওয়্যার দিয়ে)
২.পেনড্রাইভ থেকে সরাসরি পোর্টেবল বুটিং UUI (ইউনিভার্সাল ইউএসবি ইন্সটলার) দিয়ে
৩.VMware Player এর মাধ্যমে
তবে,কম সাইজের যে সব ডিস্ট্র আছে(২~৬০০মেগাবাইট for USB 2.0 Pendrive+Ports এবং ১গিগাবাইট for USB 3.0 Pendrive+Ports),সেগুলো পেনড্রাইভ থেকেই বুট করা যেতে পারে smoothly.
তো,এই নোটে দেখাবো কিভাবে পেনড্রাইভ থেকেই বুট করবেন আপনার পছন্দের লিনাক্স distro টি।
ধাপগুলো অনুসরণ করুনঃ
১.কমপক্ষে ৪ গি.বা. এর একটি পেনড্রাইভ কম্পিউটারে প্রবেশ করান।এবার ফরমেট করে নিন(FAT বা FAT32 যেকোনটি)।
২.UUI software টি ডাউনলোড করে নিন www.pendrivelinux.comথেকে।
৩.এবার ওপেন করে I agree>Create এ দিন।
৪.ড্রপ ডাউন থেকে আপনার কাঙ্ক্ষিত Distro টি সিলেক্ট করুন।
৫.এবার আপনার ডাউনলোডকৃত iso ফাইলটি সিলেক্ট করুন।খেয়াল রাখবেন,যে নাম সিলেক্ট করেছেন,iso এর নাম ও যেন একদম একই হয়(পেপারমিন্ট সিলেক্ট করলে Peppermint*.iso নাম হতে হবে যেখানে * দ্বারা এর ভার্সন নির্দেশিত হবে)।
৬.এবার আপনার পেনড্রাইভের ড্রাইভ লেটার সিলেক্ট করুন।
৭.Step 4 এ আপনি পরিবর্তন সেভ করে রাখার জায়গা নির্ধারণ করে দিতে পারেন।১০০মেগাবাইট দিয়ে create এ দিন এবং শেষ হয়ে গেলে UUI থেকে বের হয়ে আসুন।
৮.এবার আপনার পেনড্রাইভ লাইভ এবং পোর্টেবল বুটিং এর জন্য তৈরি!
৯.কম্পিউটার রিস্টার্ট করুন।এবার বুট লোড করার মেনু এর জন্য একটি বাটন প্রেস করতে বলে
Press … for boot device selection
সেই বাটন প্রেস করুন(বায়োস সেটাপের বাটন প্রেস করবেন না!)
এবার,আপনার লিনাক্স Distro তৈরি!ডেস্কটপ এ আসা পর্যন্ত অপেক্ষা করুন।
অনেক ক্ষেত্রে Start “Distro Name Here” লেখা আসে,সে সব ক্ষেত্রে আপনাকে ওই option সিলেক্ট করে enter প্রেস করতে হবে।
কিছুক্ষণের ভিতর আপনি Desktop Environment এ চলে যাবেন।
এবার আসি লিনাক্সের হার্ডডিস্ক installation নিয়ে কিছু কথায়।
লিনাক্স এবং উইন্ডোজ কিন্তু এক নয়!উইন্ডোজ NTFS এবং লিনাক্স ext3~5 filesystem ব্যবহার করে।তাই,না বুঝে Harddisk এ লিনাক্স সেটাপ দিতে যাবেন না!তাদের ২ ধরনের ফাইলসিস্টেমের কারণে উইন্ডোজ এর ফাইলসিস্টেম লিনাক্সের ফাইলসিস্টেমকে ধরতে পারে না এবং HDD(Hard disk drive) এর সেই অংশতে আর উইন্ডোজ থেকে প্রবেশ করা যায় না এবং অনেকে মনে করেন Harddisk ক্রাশ করেছে।তাই,সাবধান!
আমি পেনড্রাইভ থেকে বুট করার সিস্টেম দিয়েছি,কারণ এটি ফাইলসিস্টেম এ কোন পরিবর্তন করে না এবং Harddisk এ ও আপনি access করতে পারবেন।এমনকি,ঠিক একই পদ্ধতিতে আপনি যেকোন কম্পিউটারে এই লিনাক্সের distro টি চালু করতে পারবেন নিমেষেই! 

My 2 Ebooks in Mediafire Links

Hacktivism Reloaded - W@X V@MP!R3
http://www.mediafire.com/view/19rv9u9gxz98nyt/Hacktivism_Reloaded_-_W@X_V@MP!R3.pdf [277KB]
Using Madspot Shell To Deface Site - W@X V@MP!R3
http://www.mediafire.com/view/hbwdf4hh0gf3fwt/Using_Madspot_Shell_To_Deface_Site-W@X_V@MP!R3.pdf [568KB]
Special Thanks to ফেরারীস্বপ্ন for uploading.
Copyright © W@X V@MP!R3
2015 Inc.

How to use UUI to boot Linux From USB Flash Drive

then set 100 mb as save changes space then install.
It will take a while and after installation,press finish.
then restart the system.press the boot selection button in booting menu(in my motherboard,its set on F11) then select the flash drive then enter.your distro will load in a while.wait till the desktop is loaded.voilla!
you have successfully run your distro.you can start your OS in any computer by inserting that USB Flash drive.all you have to do is,select the boot device as USB Flash drive.
You can access Hard Disk drives(Local) and also install the Distro to hard disk permanently by clicking Install **** from desktop then following onscreen instructions.You can use internet if you are using broadband line.and modem(if supported with linux kernels) can be also configured to use
Thank you...

How to use Live USB linux as a backdoor in a Windows operated computer


2.You will need your friends computer(any computer you have access to is just to make a bootable live linux drive)
3.Now, connect to target computer and boot it(boot from USB Flash Drive,it can be a memory card/a drive with USB support).
4.After successful booting, when you open file manager,you have the complete unrestricted access on the harddrive.

This system can also be used for...
1.You can delete the SYSTEM Drive(Windows, defaultly "C:\" drive) files to wipe out old system from HDD.
2.You can access harddrive if your system gets corrupted or you are feared with viruses in your system and don't wanna spread it anymore.
use your brain and you can do many things with it i hope.
Thanks for reading.
Regards,
W@X V@MP!R3
26.02.2015