Wednesday, 4 September 2013

INTRODUCTION:

All persons who engage in Pen-test or are active in the field of Information Security are aware of what is Metasploit and the work done, but the initial learning Metasploit can be intimidating for the 'newbies' who are interested in penetration testing, but mostly have no idea where to start.

Armitage is a graphical representation advanced Metasploit Framework, its main feature is to map each stage Penetration Testing, Information Gathering, Operation and Post Exploitation, with a few clicks.

Armitage is available in all versions of BackTrack, and can be installed on any linux distro without any problems. 

We can open it from BackTrack - Exploitation Tools - Network Exploitation Tools - Metasploit Framework - Armitage, or simply type in the console armitage.



Armitage on BackTrack Launch


Starting Metasploit RPC Server


Connecting to Metasploit RPC Server

Armitage trafficked Interface



INFORMATION GATHERING:

Information gathering is the most important component of any Penetration Testing, because without the necessary information there is no way to get on with the job. Armitage provides functions for listing information, leveraging the scaneo with Nmap and Metasploit modules. The three main features are nmap scanning, and enumeration msfscan dns.

Msfscan consists of a beam Scanning Auxiliary Metasploit modules, the analysis is executed regardless of the availability of the machine. Therefore, for a more efficient exploration would be better to run arp or ping scan using nmap before running msfscan.

The results returned by Armitage is stored in its database, it is useful to review this information in other stages of Penetration Testing. Armitage also import the results of the analysis of other tools such as Nessus or Nmap in its database, giving the user the flexibility to include the results of other tools.

Scan List's


Nmap Scan List's


Nmap quick scan ranges


Running Nmap Scan


Nmap Scan Results



EXPLOITATION:

Armitage has made ​​the process of exploitation as a game with just making a click's, clicking on "Find Attack" Armitage shows the list of exploits based on open ports that were found at the time of the Nmap Scan.

We can run the exploit relevant with the click of it and keep clicking "Launch". All variables required for Metasploit to launch the exploit is automatically filled by Armitage. Most of the time, Armitage default settings will suffice for most exploits.

Once meterpreter session is created, the GUI of the machine (victim) turns red (with lightning).

An interesting feature is the "Hail Mary", this function will start all shortlisted exploits the host automatically.

Find Attack on the Host's


Complete Attack


Hail Mary Attack


Hail Mary Running Attack

Options for Launching the Exploit

Execution Exploit with Metasploit with mapping variables

Host Exploited - Retrieved Meterpreter Session


POST - EXPLOITATION: 
Armitage The best part is the ability to run all Post-Exploitation processes with just a few simple clicks's run. 
The list of available functions are:


  • Dump hash
  • Privilege Escalation
  • Exploring the file system
  • Pivot Setup attack
  • Doing pivot machine information through

Exploited Host: 192.168.1.20


Post-Exploitation Options: Access

Post-Exploitation options: Interact

Post-Exploitation Options: Explore

Post-Exploitation Options: Pivoting

Post-Exploitation Options: Hash Dump

Hash Dumping

View all items stored in the database

Exploited Host Hash

Post-Exploitation Options: ARP Scan

ARP Scan Results

Browse Files

Browse Files Results

Post-Exploitation Modules: Windows - Linux

Host Screenshot (Victim)



With these steps Introduction, Information Gathering, and Post-Exploitation Exploitation, we have successfully performed our audit and penetration testing towards a specific objective.

Armitage offers many more options that can be used depending on the modules and servers that can be found in our victim system.

Friday, 26 July 2013

Resetting Internet Explorer

We all know that at times Internet Explorer is the slowest browser but there is a trick through which u can easily make it fast

Step 1:- open run dialog box and
type "inetcpl.cpl"
Step 2:- go to advansed section
Step 3:- click reset button

Now u get a whole new Internet Explorer working as fast as it used to work
when u got Windows installed.

Be Happy & Haapy HACKING.

Monday, 22 July 2013

Sim card hacking/rooting

Millions of
mobile phones may be
vulnerable to spying due to the
use of outdated, 1970s-era
cryptography, according to new
research due to be presented
at the Black Hat security
conference.
Karsten Nohl , an expert
cryptographer with Security
Research Labs, has found a way
to trick mobile phones into
granting access to the device's
location, SMS functions and
allow changes to a person's
voicemail number.
Nohl's research looked at a
mobile phones' SIM (Subscriber
Identification Module), the
small card inserted into a
device that ties it to a phone
number and authenticates
software updates and
commands sent over-the-air
from an operator.
More than 7 billion SIM cards
are in use worldwide. To
ensure privacy and security,
SIM cards use encryption when
communicating with an
operator, but the encryption
standards use vary widely.
A mobile communication trade
group, the GSM Association,
said in a statement that only a
"minority" of SIM cards that
use older encryption standards
would appear to be vulnerable.
"There is no evidence to
suggest that today's more
secure SIMs, which are used to
support a range of advanced
services, will be affected,"
GSMA said.
Nohl's research found that
many SIMs use a weak
encryption standard dating
from the 1970s called DES
(Data Encryption Standard),
according to a preview posted
on his company's blog.
DES has long been considered
a weak form of encryption, and
many mobile operators have
upgraded now to more secure
forms. It is relatively easy to
discover the private key used
to sign content encrypted with
DES.
In its experiment, Security
Research Labs sent a binary
code over SMS to a device
using a SIM with DES. Since
the binary code wasn't
properly cryptographically
signed, it would not run on
the device.
But while rejecting the code,
the phone's SIM makes a
crucial mistake: it sends back
over SMS an error code that
carries its own encrypted 56-bit
private key, according to the
company. Because DES is
considered a very weak form of
encryption, it's possible to
decrypt the private key using
known cracking techniques.
Security Research Labs did it
in about two minutes on a
regular computer with the help
of a rainbow table, a
mathematical chart that helps
convert an encrypted private
key or password hash into its
original form faster.
With the private DES key in
hand, it is then possible to
"sign" malicious software
updates with the key, and send
those updates to the device.
The device believes the
software comes from a
legitimate source and then
grants access to sensitive data.
GSMA said that it has not seen
the full details of Nohl's
research but that use of the
DES algorithm has been
"discontinued in over the air
(OTA) standards for several
years."
Security Research Labs
outlined an attack scenario
against SIM cards that run
some form of Java virtual
machine, a software framework
for Java applications.
Using the SIM's private key, an
attacker could force the SIM to
download Java applets, which
are essentially very small
programs that perform some
function. Those applets would
be "allowed to send SMS,
change voicemail numbers, and
query the phone location,
among many other predefined
functions."
"These capabilities alone
provide plenty of potential for
abuse," the company wrote.
Possible remedies to the
problem including ensuring
SIM cards use state-of-the-art
cryptography and also using
Java virtual machines that
restrict applets' access to
certain information.
GSMA said it has already
provided guidance to network
operators and SIM vendors that
might be affected by Nohl's
findings.
Nohl's presentation, "Rooting
SIM cards," will take place at
the Black Hat security
conference in Las Vegas on July
31.

Asterisk Password Shown Vulnerability In All Browser...

Asterisk Password Shown Vulnerability
In All Browser...
==============================
======
Just Type Ur Password in the
password box. Right click on the
password box and click on "inspect
element"...
Where the <input type="password"
Change it To <input type="text"
And You showed the password ...

Friday, 12 July 2013

How to Remove Last Name from Facebook





-------------------------------------
Facebook implicitly doesn't provides a way to remove last name on Facebook. we should have to use our full name (i.e. first and last name) in order to create an account on Facebook But there is a way by which we can remove last name from Facebook without any difficulties.
Many Facebook users from Indonesia do not have a last name, that’s why Facebook modified its naming system for Indonesian users. Means the last name is optional for peoples who are using Facebook from Indonesia. If we change our IP address to Indonesia and language to Bahasa Indonesia then Facebook system will feel that we are online from Indonesia. With the help of this facebook trick we can easily remove the last name on Facebook.
How to hide last name on Facebook:
1) First of all, Install Firefox browser on your system. You can do the same with Google chrome, but i recommend Firefox for hassle free workout.
2) Once done, Login to your Facebook account.
3) In a new tab of Firefox browser, Go to "http://www.freeproxylists.net/?c=id&f=1" , and select any Indonesian proxy whose up time is more than 70%.
3) Now open Firefox and navigate to Tools > Options > Advance > Network > Settings and mark on Manual proxy configuration.
4) After that Paste the IP address and port number of proxy that you have selected in the third step, In HTTP Proxy and port field.
5) check mark on "use this proxy server for all protocols".
6) Once done, Go to "http://www.whatismyip.com/" and verify that your IP is really changed to Indonesia or not.
If selected proxy is not working properly, then try any other from the list, and implement that proxy with Firefox and then again verify.
7) Now open the tab of Facebook account and navigate to account settings of your Facebook account, In account settings change language from English to Bahasa Indonesia.
Depan is the first name in indonesian language
Tengah is the middle name in indonesian language
Belakang is the last name in indonesian language
8) After that, remove last name.
remember that:
>in the "Kata Sandi" field type your password then press "Simpan Perubahan"
9) In last step, just change the Language to Bahasa Indonesia to English.
Now see your Facebook profile and you will notice that you just removed your last name from Facebook.


Credits :
Alankar 

Monday, 1 July 2013

Social Engineering Through Facebook

FBPwn is used for facebook social engineering. It can send friend requests to a list of Facebook profiles, once the victim accepts the invitation, it dumps all their information, photos and friend list to a local folder. Extensible module interfaces and built-in modules for advanced social engineering tricks.

A typical hacking scenario starts with gathering information from a user’s FB profile. The plugins are just a series of normal operations on FB, automated to increase the chance of you getting the info.




First you create a new blank account for the purpose of the test. Then, the friending plugin works first, by adding all the friends of the victim (to have some common friends). Then the clonning plugin asks you to choose one of the victims friends. The cloning plugin clones only the display picture and the display name of the chosen friend of victim and set it to the authenticated account. Afterwards, a friend request is sent to the victim’s account. The dumper polls waiting for the friend to accept. As soon as the victim accepts the friend request, the dumper starts to save all accessable HTML pages (info, images, tags, …etc) for offline examining.

After a a few minutes, the victim will unfriend the fake account after he/she figures out it’s a fake, but it’s too late!

DOWNLOAD LINK:
http://goo.gl/kDHBV
Credits :

More/Usage :
http://code.google.com/p/fbpwn/