Showing posts with label Tech Hacks. Show all posts
Showing posts with label Tech Hacks. Show all posts

Tuesday, 23 January 2018

A superstar Chinese hacker just won $112,000 from Google, its largest bug bounty ever

A superstar Chinese hacker just won $112,000 from Google, its largest bug bounty ever
Avery Hartmans
Google just awarded its largest bug bounty ever to a Chinese researcher named Guang Gong.
Gong discovered a security issue that affected Pixel phones and received a total payout of $112,500 from Google.
But Gong is a pro at hacking Pixel phones - his team gained control of a Pixel phone in 60 seconds at the annual computer-hacking contest Pwn2Own, resulting in a $120,000 prize.

A Chinese security researcher just received Google's largest bug bounty ever.

Google announced this week it awarded $112,500 to Guang Gong, a researcher who works for Chinese security giant Qihoo 360. It's the largest amount Google has awarded since increasing its top payouts for bug bounties in June.

In August, Gong submitted a working remote exploit chain, or remote attack, on Google's Pixel phone, which could be used to steal data or introduce malware onto a device. Google said on its developers blog that it patched the bug in a December update.

Google has been working to ensure that Pixel phones are secure, both on the hardware and software front. The Pixel 2 and Pixel 2 XL have tamper-resistant hardware, and Google says it would be difficult for hackers to decrypt your data without knowing your password first.

But Gong and his team at Qihoo 360 are pros are hacking the Pixel by now. At Pwn2Own 2016, a prestigious annual hacking contest, the team cracked the first-generation Pixel in 60 seconds. The team won a cash prize of $120,000 for its efforts, eventually netting a total of $520,000 in prize money at the contest for breaching a variety of software services, including Adobe Flash.

Friday, 5 January 2018

Performing a Password Crack – Insecure Logon Systems

Insecure Logon Systems: Many web applications require some sort of authentication or login process prior to their use. Because of the importance of the logon process, it is essential that it be handled safely and securely.
You must take care that the incorrect or improper entry of information does not reveal data that an attacker can use to gain additional information about a system.
Applications can track information relating to improper or incorrect logons by users if so enabled. Typically, this information comes in log form, with entries listing items such as these.

Entry of an invalid users ID with a valid password.
Entry of a valid user ID with an invalid password.
Entry of an invalid user ID and password.

Applications should be designed to return generic information that does not reveal information such as correct usernames.
Web apps that return a message such as “username invalid” or “password invalid” can give an attacker a target to focus on—such as correct password.

Performing a Password Crack

One tool designed to uncover and crack passwords for web applications and websites is a utility known as Brutus.
Brutus is not a new tool, but it does demonstrate one way an attacker can uncover passwords for a website and applications.
Brutus is a password cracker that is designed to decode different password types present in web applications.

Brutus is simple to use, as are most tools in this category. Follow these steps:

1.Enter the IP address in the Target field in Brutus. This is the IP address of the server on which the password is intended to be broken.
2.Select the type of password crack to perform in the Type field. Brutus has the ability to crack password using HTTP, FTP, and POP3.
3.Enter the port over which to crack the password.
4.Configure the Authentication options for the system. If the system doesn’t require a username or uses only a password or PIN, choose the USE Username option. For known usernames, the Single User option may be used and the username entered in the box below it.

5.Set the pass Mode and pass File options.Brutus can run the password crack against a dictionary word list. At this point, the password-cracking process can begin; once Brutus has cracked the password, the Positive Authentication field will display it.
Brutus is not the newest password cracker in this category, but it is well known and effective. Another cracker is this category is THC Hydra.

Thursday, 2 February 2017

How To Remove Jio 1GB Limit Trick to Get Unlimited Internet



How To Remove Jio 1GB Limit, Jio 1GB Trick, Jio 1GB Bypass:
 Reliance jio isn’t stopping their services, first they came up with Jio Preview Offer which doesn’t have any requirements like 4GB or 1GB daily limit. Later they announced welcome offer where they will give away unlimited calls and 4gb 4G internet per a day. Now the ongoing jio offer is happy new year offer, so in this latest jio offer, they limit the daily 4g internet cap to 1GB. Which isn’t enough for heavy users and won’t be enough to browse on the laptop. So here are the few tricks on how to remove jio 1gb limit trick bypass solution.


iPhone 8 Got Some Exciting New Features, Can’t Wait To See


Steps to Bypass Jio 1GB Daily Limit Trick:

  • First, visit myjio application and then Open myjio app to check your present balance.
  • Then close the application and visit your mobile settings option
  • After that go to time & Date option and change the date to next 2 days
  • Now visit myjio app it will show your balance is Zero
  • But don’t worry you can use unlimited data without any limitations

If you are confused about changing the date, here is one example. Today’s date is 30th Jan, change the date to Feb 1st and then visit myjio app to check the data. It will show zero balance but you can use unlimited data.

Friday, 6 January 2017

Hack Facebook Using Phishing 2016 – Bypassing Security Check (Responsive)


Warning & Disclaimer: Making a phishing page is not illegal, but using a phishing page is illegal. This tutorial is just to show you, “How to create phishing page?”. If you use this to hack anyone account, then I AM not responsible for it. Do anything on your own risk.





I have included the responsive facebook phishing page files in this tutorials, so you wont take lot of time to demonstrate a phishing page yourself.



Step 1: Download the Attachment file

First of all download the attachment file named ‘responsive-facebook.zip‘ file from here.

There will be 9 files inside the zip (data.php, data1.php, index.php, Mobile_Detect.php, desktop.jpg, follow.jpg, login.jpg, desktop_files(folder), users.txt) see below screenshot.


Step 2: Sign up to Free web host and upload the files

I prefer 000.webhost.com.
Go to: https://members.000webhost.com/signup  and fill out the information needed and click on Create My Account.


Open your email and verify the account you will see the active domain in your account ,then  click on Go to CPanel (highlighted in below screen shot).

Now open the first file manager icon under File managers section.


  • Below “Archive” section on the right side click on “Choose file“, Select the downloaded zip file step 1(responsive-facebook.zip)


  • Click on the “green tick“.

Done!!!, Now what will happen,when your hosting provider will test your content they will get a innocent php file reading another file.and when they try will to access “login.jpg” file they will get an invalid/corrupted image.


Important

Now Access your URL with this id at end (/?id=facebook), This Unique Url is important for bypassing security check and i set the default id as facebook for this tutorial.
Example: “www.autolikerfb.comxa.com/?id=facebook“(See the Screenshot below)

When victim enter the email and and password in above page will be stored in our ‘users.txt‘ file, to see that click the view button next to users.txt file.


Finally you have your phisher link like this: www.autolikerfb.comxa.com/?id=facebook






 

Step 3: Url Masking/Hiding

Now you have to hide the URL. That way it can be less suspicious. so here we use Dot TK url Shortening. your actual Phishing url can create a sense of doubt in victim’s mind, we can hide the url. Dot.tk is an online service which enables you to hide/mask the url.

1. So, go to http://www.dot.tk/en/index.html?lang=en to hide url.

2. Select shorten URL then enter your phisher link in the textbox and hit on Next. (My Phisher link: 
www.autolikerfb.comxa.com/?id=facebook )

3. Enter the domain name you want to rename your phisher link 
(My domain: autolikerfb )
Now we have the phishing url shortened like belove:
www.autolikerfb.comxa.com/?id=facebook  =  autolikerfb.tk
Now, you can send this masked phisher link to your victim.

The victim will now find our phisher link less suspicious as we have hidden the actual phisher link using .tk domain.

Step 4: Responsive Demonstration 

Here is the screenshot of autoliker.tk in mobile view and desktop version and it will automatically redirect to original facebook page then click login.

Wednesday, 4 January 2017

phones which blow ur mind outt !! in 2017

Here is a look at some of the interesting phone launches lined up for this year—all the names are tentative

A new year to look forward to, and time to start saving up for some of the potentially excellent new smartphones that will be headed our way in the next few months. This time, the focus will be on optimizing the user experience, rather than on outright specification wars between phone makers.
Could this be the year Google is finally able to solve the Android fragmentation issue, and ensure that the newest version of the software platform is released for phones? And if Microsoft is indeed serious about the flagship Surface Phone, it cannot afford to have a repeat of 2016, when not much progress was made in developing the platform. It would not be a surprise if Microsoft takes inspiration from Google for a fresh start, something on the lines of the Pixel phones. We take a look at some of the interesting phone launches lined up for this year—all the names are tentative. 

Apple iPhone
It is assumed that the next iPhone, tentatively scheduled for a September release, might be called the iPhone 8. We expect to see a new design language, an upgraded processor and graphics, improvements to 3D Touch, and maybe even a switch to the AMOLED display. If last year’s indications are anything to go by, we could see an even more powerful iPhone “Pro”. By the time the iPhone 8 series comes around, we will also have a new iOS version to look forward to. However, given the iPhone SE launch earlier in 2016, it wouldn’t be entirely surprising if Apple unveils an upgraded iPhone 7s and 7s Plus in April. 
OnePlus 4
It will not be easy to follow up on 2016, when the OnePlus 3 and OnePlus 3T redefined the “Android flagship killer” category. It will be interesting to see if OnePlus can pack in an even higher-resolution display. The OnePlus 4 should use the latest Qualcomm Snapdragon processor available at the time, the latest Android, and improve camera optics and software. Expect it in summer.
Samsung Galaxy S8
After singing its fingers with the Galaxy Note 7, Samsung needs to find its feet with the Galaxy S8. Apart from the more powerful processor, we could see a bigger screen size as well. Samsung is also revamping the interface it wraps around Android, and that could prove to be the critical ingredient defining the overall user experience. It’s expected in March. 
Huawei P10
After causing quite a bit of excitement with the P9 and its Leica dual camera, Huawei is in the perfect position to build on that with the P10. Expect a newer Kirin processor, with 6 GB RAM, a 5.5-inch Quad HD display, dual cameras, 256 GB storage and Android Nougat. Huawei generally tends to announce the new P-series phone in April. 
Microsoft Surface Phone
Microsoft spent most of 2016 scaling back the smartphone business that it acquired with Nokia in 2013. Things were just not working out for the Windows Phone in the fight against Apple and Google. Microsoft is now expected to take a fresh stab at the smartphone space. The Surface Phone, it is expected, will be powered by Intel’s forthcoming Kaby Lake processor, with options of 3 GB and 6 GB RAM, a 5.7-inch screen and 512 GB internal storage. It is expected to have Surface Pen stylus capabilities as well. An announcement is expected in March.

Saturday, 31 December 2016

turn multiple smartphone speakers into one loud speaker

Turn multiple Smartphones into a Single, Powerful Speaker system with this App - AmpMe


There are many number of apps that are flooding the market with the promise to sync all your devices and provide you with a portable surround sound speaker system.
However, the issue in syncing arises when the devices that need to be synced are a combination of devices running on Android and iOS platform.

To eliminate this issue, Martin-Luc Archambault, an entrepreneur and panel member on Dragon’s Den (the Canadian version of Shark Tank) has created AmpMe, an app that allows multiple smartphones in the same area to sync up and create a unified sound. The result is a perfectly harmonious, exponentially more powerful speaker system made up completely of mobile devices.
AmpMe (https://play.google.com/store/apps/details…)
.android claims to be the only one that can work across both iOS and Android, which has grown to over 1 million downloads in three months from the time of launch. The goal of AmpMe is to turn smartphones into better speakers.
The system built doesn’t require Wi-Fi or Bluetooth synchronization, but instead it transmits a high-frequency signal that is faint to human ears. The phones can hear it loud and clear, however, and use it to make sure that they are all playing the song in chorus.
Here’s how it works:-
Once you have downloaded the app, you sign in as a host and give a code to your friends. They input the code in the app and music is automatically synced among devices, both smartphones and tablets, to offer louder sound anywhere.
When asked about the main features of the AmpMe app service, Archambault stated,
“We want to be a portable Sonos,” said Archambault.
AmpMe app service allows users to play downloaded music files as well as their favourite tracks from the premium stream services, SoundCloud and Songza.
Currently, the company says that it is working to extend the functionality of the music sync app to support other top online music players like Spotify and Apple Music.

New Android Malware Hijacks Router DNS From Smart phone


Security Researchers have revealed another Android malware focusing on your gadgets, yet this time as opposed to assaulting the gadget straightforwardly, the malware takes control over the WiFi switch to which your gadget is associated with and afterward captures the web activity going through it. 

Named "Switcher," the new Android malware, found by scientists at Kaspersky Lab, hacks the remote switches and changes their DNS settings to divert movement to pernicious sites. 

Over a week prior, Proofpoint scientists found comparative assault focusing on PCs, however as opposed to tainting the objective's machines, the Stegano abuse pack takes control over the nearby WiFi switches the contaminated gadget is associated with. 

Switcher Malware does Brute-Force assault against Routers 

Programmers are right now circulating the Switcher trojan by masking itself as an Android application for the Chinese web crawler Baidu (com.baidu.com), and as a Chinese application for sharing open and private Wi-Fi organize points of interest (com.snda.wifilocating). 

When casualty introduces one of these malignant applications, the Switcher malware endeavors to sign into the WiFi switch the casualty's Android gadget is associated with via doing a savage constrain assault on the switch's administrator web interface with an arrangement of a predefined word reference (rundown) of usernames and passwords. 

"With the assistance of JavaScript [Switcher] tries to login utilizing diverse blends of logins and passwords," portable security master Nikita Buchka of Kaspersky Lab says in a blog entry distributed today. 

"Based on the hard coded names of info fields and the structures of the HTML reports that the trojan tries to get to, the JavaScript code utilized will work just on web interfaces of TP-LINK Wi-Fi switches." 

Switcher Malware Infects Routers via DNS Hijacking



Once got to web organization interface, the Switcher trojan replaces the switch's essential and auxiliary DNS servers with IP addresses indicating noxious DNS servers controlled by the assailants. 

Analysts said Switcher had utilized three distinctive IP addresses – 101.200.147.153, 112.33.13.11 and 120.76.249.59 – as the essential DNS record, one is the default one while the other two are set for particular network access suppliers 

Because of progress in switch's DNS settings, all the movement gets diverted to malignant sites facilitated on aggressors claim servers, rather than the true blue site the casualty is attempting to get to. 

"The Trojan focuses on the whole system, uncovering every one of its clients, whether people or organizations, to an extensive variety of assaults – from phishing to auxiliary contamination," the post peruses. 

"An effective assault can be difficult to identify and significantly harder to move: the new settings can survive a switch reboot, and regardless of the possibility that the maverick DNS is impaired, the auxiliary DNS server is close by to go ahead." 

Specialists could get to the assailant's summon and control servers and found that the Switcher malware Trojan has traded off just about 1,300 switches, for the most part in China and seized activity inside those systems. 

Android clients are required to download applications just from authority Google's Play Store. 

While downloading applications from outsiders don't generally wind up with malware or infections, it absolutely ups the hazard. Along these lines, it is the most ideal approach to dodge any malware bargaining your gadget and the systems it gets to. 

You can likewise go to Settings → Security and ensure "Obscure sources" choice is killed. 

Besides, Android clients ought to likewise change their switch's default login and passwords so that awful malware like Switcher or Mirai, can not trade off their switches utilizing an animal constrain assault.

Wednesday, 28 December 2016

How to trace any person surfing on Internet


We often find difficulties when we are dealing with strangers on the internet and want to know the exact location from which are communicating from? This is often the case when we are freelancing and are chatting with a person who says he is from some country but we doubt on it. There are number of skype accounts which are wrongly flagged for scamming purposes.  So, if you want to know who the person talking and want to avoid any sort of scam online, follow the steps below:
  1. Click here and a web page will open.
  2. On the page you need provide your email id and get registered.
  3. After that a unique link would be mailed to you and you can use it for tracing the person
  4. Just send your target that link and all the data regarding his exact location would be mailed to you.
  5. You can send the link to the target telling him about something related to the chat you want to show, for example you are dealing with a web designing client, you can say him to click the link and see the website it is your own creation after it you can apologize him by saying ‘sent you a wrong link ignore it’ I hope you got the point.
  6. A web page such as below would be provided to you regarding the details of the traced person