WELCOME Learn Hacking web site

With our help approve your genuine adsense account within 4 hours only. We will Help you to get maximum revenue from your website blog,wordpress .ect show contact me www.fb.com/mayur.khokhar1

This is default featured slide 2 title

Go to Blogger edit html and find these sentences.Now replace these sentences with your own descriptions.

This is default featured slide 3 title

Go to Blogger edit html and find these sentences.Now replace these sentences with your own descriptions.

This is default featured slide 4 title

Go to Blogger edit html and find these sentences.Now replace these sentences with your own descriptions.

This is default featured slide 5 title

Go to Blogger edit html and find these sentences.Now replace these sentences with your own descriptions.

Saturday, 18 January 2014

Hackers Index



HACKING FORUMS





























































Clickjacking

What is Clickjacking:

Clickjacking attack allows to perform an action on victim website, Mostly Facebook and Twitter accounts are targetable.
when an attacker uses multiple transparent or opaque layers to trick a user into clicking on a button or link on another page when they were intending to click on the the top
level page. Thus, the attacker is "hijacking" clicks meant for their page and routing them to other another page, most likely owned by another application, domain, or both. It may be similar to CSRF Cross Site Request Forgeries Attack.  


Clickjacking is a term first introduced by Jeremiah Grossman and Robert Hansen in
2008 to describe a technique whereby an attacker tricks a user into performing certain actions on a website by hiding clickable elements inside an invisible iframe.


Using a similar technique, keystrokes can also be hijacked. With a carefully crafted combination of stylesheets, iframes, and text boxes, a user can be led to believe they
are typing in the password to their email or bank account, but are instead typing into
an invisible frame controlled by the attacker. 


At present this attack mostly use on social network websites like Facebook and twitter, Because this attack is used by convinced victim for click on the link and SocialNetwork website might be very useful for attack on victim.

One famous example of clickjacking is Facebook.



Code:

 <style>
 iframe { /* iframe from facebook.com */
  width:300px;
  height:100px;
  position:absolute;
  top:0; left:0;
  filter:alpha(opacity=50); /* in real life opacity=0 */
  opacity:0.5;
}
</style>

<div>Click on the link to get more followers:</div>
    
<iframe src="/files/tutorial/window/clicktarget.html"></iframe>

<a href="http://www.google.com" target="_blank" style="position:relative;left:20px;z-index:-1">CLICK ME!</a>

<div>You'll be get 10000 followers..!!</div>

Output:
Click on the link to get more followers
Click Me
You'll be get 10000 followers..!!

Download 
ClickJacking Tool

For Defence:
Clickjacking Protection



For more information:
OWASP

Mobile Hack Tricks

by mayur khokhar


Call Forging:


To call someone from their own number or any number.
1. Go to http://www.mobivox.com and register there for free account.

2. During registration, remember to insert Victim mobile number in "Phone number
"field as shown below.




3. Complete registration and confirm your email id and then login to your account.
click on "Direct WebCall".




4. You will arrive at page shown below. In "Enter a number" box, select your country
and also any mobile number(you can enter yours). Now, simply hit on "Call Now"
 button to call your friend with his own number.


How to find the IP address of the email sender in Gmail, Yahoo mail, Hotmail, AOL, Outlook Express, etc.

by mayur khokhar

When you receive an email, you receive more than just the message. The email comes with headers that carry important information that can tell where the email was sent from and possibly who sent it. For that, you would need to find the IP address of the sender. The tutorial below can help you find the IP address of the sender.
Note that this will not work if the sender uses anonymous proxy servers.
Also, note that if you receive an email sent from a Gmail account through the web browser, you may not be able to find the real IP address because Google hides the real IP address of the sender. However, if someone sends you a mail from his/her Gmail account using a client like Thunderbird, Outlook or Apple Mail, you can find the originating IP address.
Lets begin this. First of all, the IP address is generally found in the headers enclosed beween square brackets, for instance, [129.130.1.1]

Finding IP address in Gmail

  • Log into your Gmail account with your username and password.
  • Open the mail.
  • To display the email headers,
    • Click on the inverted triangle beside Reply. Select Show Orginal.
  • You may copy the headers and use my IP address detection script to ease the process. Or if you want to manually find the IP address, proceed to 5.
  • Look for Received: from followed by the IP address between square brackets [ ].
    Received: from [69.138.30.1] by web31804.mail.mud.yahoo.com
  • If you find more than one Received: from patterns, select the last one.
  • Track the IP address of the sender

Finding IP address in Yahoo! Mail

  • Log into your Yahoo! mail with your username and password.
  • Click on Inbox or whichever folder you have stored your mail.
  • Click on the Subject of the email you want to track and right-click. You should get a menu like this.
    Yahoo! headers
  • You may copy the headers and use my IP address detection script to ease the process. Or if you want to manually find the IP address, proceed to the next step.
  • Look for Received: from followed by the IP address between square brackets [ ]. That should most likely be the IP address of the sender. If there are many instances of Received: from with the IP address, select the IP address in the last pattern. If there are no instances of Received: from with the IP address, select the first IP address in X-Originating-IP.
  • Track the IP address of the sender

Finding IP address in Hotmail

Hotmail has been integrated with Windows Live, or vice-versa. And the format has changed. Here is how you find the IP address of the sender.
  • Log into your Hotmail/Windows Live account with your username and password.
  • Click on the Inbox link on the left.
  • Under the column that says "Sort by", find the email that you want to track and right-click on it. You should get a menu that has something like Mark as read, Mark as unread, and so on. The last option in the menu should be View message source. Select it. headers hotmail
  • You should see the email headers now.
  • You may copy the headers and use my IP address detection script to ease the process. Or if you want to manually find the IP address, proceed to step 6.
  • If you find a header with X-Originating-IP: followed by an IP address, that is the sender's IP address
  • If that doesn't work, look for Received: from followed by IP address within square brackets[].
    • If you have multiple Received: from headers, eliminate the ones that have proxy.anyknownserver.com.
  • Track the IP address of the sender

Finding IP address in AOL

  • Log into your AOL Mail AIM account with your username and password.
  • Open the email that you want to track.
  • On the top row, click on Action and in the drop-down menu, select View Message Source
    headers aol
  • It opens a new page with the headers. Once you have the headers, look for the IP address that follows X-AOL-IP:. That should be the IP address of the sender.
  • Track that IP address of the sender

IP Address Detection Script

I wrote a Perl script to automate this task for you. All you have to do is select your email service and copy your email headers in the box below. You may do one of the following:
  • You can copy all the headers from your email and paste them here. In this case, the unnecessary headers (like Subject:) will be removed automatically.
  • You can remove all headers except those beginning with
    - **X-Originating-IP:**
    - **Received:**

Wednesday, 15 January 2014

Why Your Encryption/Passwords Suck ? New Security Methods : 3D Face Analysis, Bio Metrics, ETC ...

by Mayur Khokhar

" Treat Your Passwords Like you treat your Toothbrush, Don't Let anyone Use it and Change it every 6 Months " - Clifford Stoll, Scientist.
Thousands of Online Services uses Password, Be it Banks, Shops, Social Networking Sites, Email's And Every other service. These Passwords are lying on the Databases of the companies, Which frequently have very basic security.
And These sites Do Get Hacked, Here Are Some Of The Greatest Attacks :



Sony PlayStation Network :77 Million Accounts Hacked. Site Down For 24 Days.
Evernote :50 Million Accounts Hacked, Including Addresses.
LinkedIn :6.5 Million Accounts Hacked.
Gamigo :8.24 Million Accounts Exploited.
Yahoo Voices :450,000 Accounts Hacked.
Twitter : 250,000 Accounts Hacked.

Most Of the Accounts Get Hacked Because the Main Site Server Gets Exploited, But Many Individual Accounts Get Hacked Because people are too damn dumb to use complex password, A Survey done by Mark Burnett for 12 years Indicates that 78% of online users use These passwords :


123456jordangeorgeyankees
1234supermancharlie123123
12345678harleyandrewashley
qwerty1234567michelle666666
dragonfucklovehello
sexassholejessicaamanda
12345hunterboobsorange
baseballtrustno1legend-arybiteme
footballranger6969freedom
letmeinbusterpeppercomputer
monkeythomasdanielfuckme
696969tigeraccessnicole
abc123robert123456789thunder
mustangsoccer654321ginger
michealpornjoshuaheather
shadowbatmanmaggiehammer
masterteststarwarssummer
wintwejenniferpasssilver
fuckingcarloverkillerwilliam


What And How Hackers Do What They Do !

I Don't Know How, But somebody tricked us into thinking Hackers are Geeks on Laptops ( which we are) but you should also remember that Hackers have great observation skills. Hackers Follow you everywhere, Once they lay their eyes on a target, they dig out every bit of information available about you. They spy on your online photos, They know your cat's name, Your Car's Model and everything you might have mentioned in online world.
Hackers Can attack you on many fronts, like : Cracking your Social networking website password, Stealing Data from your personal computer, Phishing you or even using your E-Mail ID to send messages to terrorists.

You'll Love :Learn How To Crack Windows Password In Minutes.

Methods To Confuse And Avoid Hackers :

Two Factor Authentication :

Many E-mail Providers use Two Factor Authentication like Gmail And Yahoo, And it the strongest method to protect yourself from getting hacked. To access your account, First you have to sign in Using your E-mail and Password, And then An Eight Digit Code is sent to your mobile within a few seconds, Which you have to fill online to get access to your account.
Pros :
Strongest Security Method.
You know when your account is being accessed.
Alert On Your Mobile if someone tries to brute-force your account.
Cons :
Not so Time Efficient.
You Need Your Mobile And Good Signal Reception.

You'll Love : Learn How To Clone A Mobile Number !

Total Rating :
Security :

Comfort :


OPENID :

A Universally Usable ID Is given to you if you use OPENID. UUID are mostly URL specially crafted for you. To Log In into any service, You'll have to just insert your OpenId, Not your password. Using OpenID is also a good Idea as password have a habit of getting hacked. OpenID is usable on Google, Yahoo, LiveJournal, Hyves, Blogger, Flickr And other sites.

Pros :
One-For-All Username and Password.
Saves Time.
Cons :
Not So-Many Sites Supported.

Total Rating :
Security :

Comfort :

Swipe Gestures :

Swipe gestures are a popular way to lock your Android Phones, And they very Are Simple to use, Thus easily crack-able. Anybody can remember your Swipe by seeing it first time, Also Somebody can find out your swipe by observing the scratches on the surface of your screen.
Pros :
Easy And Simple.
Cons :
Easily Hack-able.

Total Rating :
Security :

Comfort :

Password Stick :

On Many Operating Systems, You Can create a password stick which can unlock your computer by plugging it in. It is a time saving and secure method, Unless Your hacker is also good at picking pockets.We are not very fond of this method, as your brain is the safest place to store sensitive information.
Pros :
Time Saving.
Easy.
Secure.
Cons :
Danger Of Getting Hacked if stick is stolen.

Total Rating :
Security :

Comfort :

Finger Print Scan :

One of the oldest method of securing, Finger print scanners are widely available on Laptops, Netbooks, External USB Scanner etc. Also a rumor has it that the new iPhone Might have a Fingerprint scanner in the home button. It is a good and secure way to protect your data.
Pros :
Easy To Use.
Widely Available.
Cons :
Remember to clear the scanner after each scan or the print left on the scanner can be easily used by hacker.

Total Rating :
Security :
Comfort :

3D Face Analysis :

On Mobile Since Android 4.0, 3D Face Scan is an awkward way to unlock your mobile, It uses your  mobile/laptop camera to take a video of your whole face each time to unlock your device. But we don't think this type of security method is useful in Mobiles, Tough it is very useful in PC Security and Other stuff that you don't need to unlock every other second.
Pros :
Very Secure.
Very Difficult To Hack.
Cons :
Good Lightning needed.
Can be cracked by a video of your's.

Total Rating :
Security :

Comfort :

Behavior Pattern :

Everybody has different way of interacting with technology, And the Swedish Firm BehavioSac Has used it to create a new security system. In this method, You Need to enter your password and have to do it in the same way you did before. Other Factors Include : Typing Rhythm, Speed, And on touchscreen Devices : Angle of gestures, pressure of angles and other stuff !
Pros :
Highly Secure.
Easy To Use.
Cons :
Not available on the market Yet.
Could be a pain in the ass when you're drunk or sleepy.

Total Rating :
Security :
Comfort :

Conclusion :
With the increasing security risk, It Would be a good idea if the services we use everyday would get a security upgrade, And If the users follow some basic security tips, It would make them much more secure in the online world.

Is Facebook Afraid Of Google Plus ?


By Mayur khokhar


Facebook, The biggest, largest and most popular Social-Networking site that ran many other websites out of business, Like Orkut, Friendster and hi5, And produced a major problem for big sites like LinkedIn and Twitter, Has started to show the signs that its time is over. Facebook is scared of Google+, And it has got good reason too :

Best and Popular Google Reader Alternatives

by mayur khokhar


Google Reader Alternatives

Best and Popular Google Reader Alternatives


We Already know that google is going to terminate the Google Reader Process. To confirm this message, google removed the RSS subscription from the chrome store. So Users can't subscribe the Rss feeds inside Google reader easily.

Don't worry About RSS Subscription Extension Because someone called "Justin Kelly" has cloned the Google's Original RSS subscription extension and re-uploaded it to the Chrome store.

Monday, 13 January 2014

Domain Analyzer Security Tool



Domain analyzer is a security analysis tool which automatically discovers and reports information about the given domain. Its main purpose is to analyze domains in an unattended way.
Features
  • It creates a directory with all the information, including nmap output files.
  • It uses colors to remark important information on the console.
  • It detects some security problems like host name problems, unusual port numbers and zone transfers.
  • It is heavily tested and it is very robust against DNS configuration problems.
  • It uses nmap for active host detection, port scanning and version information (including nmap scripts).
  • It searches for SPF records information to find new hostnames or IP addresses.
  • It searches for reverse DNS names and compare them to the hostname.
  • It prints out the country of every IP address.
  • It creates a PDF file with results.
  • It automatically detects and analyze sub-domains!
  • It searches for domains emails.
  • It checks the 192 most common hostnames in the DNS servers.
  • It checks for Zone Transfer on every DNS server.
  • It finds the reverse names of the /24 network range of every IP address.
  • It finds active host using nmap complete set of techniques.
  • It scan ports using nmap.
  • It searches for host and port information using nmap.
  • It automatically detects web servers used.
  • It crawls every web server page using our Web Crawler Security Tool.
  • It filters out hostnames based on their name.
  • It pseudo-randomly searches N domains in google and automatically analyze them!
  • Uses CTRL-C to stop current analysis stage and continue working.
First download Domain Security Analyzer from here and save in your desktop
Now untar the file tar zxvf domainanalyzer.tar.gz

Crawler

Domain Analyzer Security Tool



Domain analyzer is a security analysis tool which automatically discovers and reports information about the given domain. Its main purpose is to analyze domains in an unattended way.
Features
  • It creates a directory with all the information, including nmap output files.
  • It uses colors to remark important information on the console.
  • It detects some security problems like host name problems, unusual port numbers and zone transfers.
  • It is heavily tested and it is very robust against DNS configuration problems.
  • It uses nmap for active host detection, port scanning and version information (including nmap scripts).
  • It searches for SPF records information to find new hostnames or IP addresses.
  • It searches for reverse DNS names and compare them to the hostname.
  • It prints out the country of every IP address.
  • It creates a PDF file with results.
  • It automatically detects and analyze sub-domains!
  • It searches for domains emails.
  • It checks the 192 most common hostnames in the DNS servers.
  • It checks for Zone Transfer on every DNS server.
  • It finds the reverse names of the /24 network range of every IP address.
  • It finds active host using nmap complete set of techniques.
  • It scan ports using nmap.
  • It searches for host and port information using nmap.
  • It automatically detects web servers used.
  • It crawls every web server page using our Web Crawler Security Tool.
  • It filters out hostnames based on their name.
  • It pseudo-randomly searches N domains in google and automatically analyze them!
  • Uses CTRL-C to stop current analysis stage and continue working.
First download Domain Security Analyzer from here and save in your desktop
Now untar the file tar zxvf domainanalyzer.tar.gz

Crawler

How to Create Domain Email Account with Hotmail

Domain Hacking


by mayur khokhar
The first step is to go to domains.live.com and enter your domain name on the next page

Now Select Sign in with an existing Microsoft Account and Click on Continue

Now Click on I Accept Button

Log in to the Cpanel for your domain.
Navigate to an MX record maintenance page. MX records are special DNS (Domain Name Service) records, and are often located under sections titled “DNS Management,” “Mail Server Configuration,” You may need to turn on advanced settings to allow editing of these MX records.
Delete any existing MX records before entering new MX records.
Add an MX record for the email server.
Enter the fully qualified server name, such as 07e1d99c5dbf194ba723c7439a5517.pamx1.hotmail.com many domain providers also require a trailing period at the end of the server name. Set the priority for the record.
Go to Windows Live Admin Center on the left sidebar you will find options to member accounts on your domain. Now Click on Add Button

Now you can manually create email accounts. Just fill in the form to add an account and click Ok


Now login to your Hotmail account

Hack Windows, Linux or MAC PC using Firefox 17.0.1 + Flash Privileged Code Injection

by Mayur Khokhar

This exploit gains remote code execution on Firefox 17.0.1 and all previous versions provided the user has installed Flash. No memory corruption is used. First, a Flash object is cloned into the anonymous content of the SVG “use” element in the <body> (CVE-2013-0758). From there, the Flash object can navigate a child frame to a URL in the chrome:// scheme. Then a separate exploit (CVE-2013-0757) is used to bypass the security wrapper around the child frame’s window reference and inject code into the chrome:// context. Once we have injection into the chrome execution context, we can write the payload to disk, chmod it (if posix), and then execute. Note: Flash is used here to trigger the exploit but any Firefox plugin with script access should be able to trigger it.

Exploit Targets

Firefox 17.0.1
Windows PC
Linux PC
MAC OS X PC

Requirement

Attacker: Backtrack 5
Victim PC: Windows 7
Open backtrack terminal type msfconsole
Now type use exploit/multi/browser/firefox_svg_plugin

***For free Breaking News Alerts just sms JOIN NAXATRANEWS to 567678********For free Adult Jokes just sms JOIN 18JOKES to 567678*****