Click Here to download BackTrack.
Saturday, April 20, 2013
Operating System designed only for hacking
BackTrack is a Linux-based penetration testing arsenal that aids security professionals in the ability to perform assessments in a purely native environment dedicated to hacking. Regardless if you’re making BackTrack you Install BackTrack, boot it from a Live DVD or thumbdrive, the penetration distribution has been customized down to every package, kernel configuration, script and patch solely for the purpose of the penetration tester.
BackTrack is intended for all audiences from the most savvy security professionals to early newcomers to the information security field. BackTrack promotes a quick and easy way to find and update the largest database of security tools collection to-date. Our community of users range from skilled penetration testers in the information security field, government entities, information technology, security enthusiasts, and individuals new to the security community.
Feedback from all industries and skill levels allows us to truly develop a solution that is tailored towards everyone and far exceeds anything ever developed both commercially and freely available. The project is funded by Offensive Security. Whether you’re hacking wireless, exploiting servers, performing a web application assessment, learning, or social-engineering a client, BackTrack is the one-stop-shop for all of your security needs.
Friday, April 19, 2013
Ways to prevnt Tab Napping
Here are six simple ways you can prevent yourself :-
Make sure you always check the URL in the browser address page is correct
before you enter any login details. A fake tabbed page will have a different URL
to the website you think you’re using.
Always check the URL has a secure https:// address even if you don’t have
tabs open on the browser.
If the URL looks suspicious in any way, close the tab and reopen it by
entering the correct URL again.
Avoid leaving tabs open which require you to type in secure login details.
Don't open any tabs while doing online banking - open new windows instead (CTL +
N).
Don't open any tabs while doing online banking. And your browser have to be updated .
Ways to use Tab Napping
Steps:
1) First of all you have a web hosting (website) and if you don’t have your own website then create Free website with following website :
www.000webhost.com
www.host1free.com
www.my3gb.com
or you can search on google and create an account.
2) Now download the script and phishing pages from here: http://www.mediafire.com/?0zrp565h8v90jbe
3) Upload the extracted files into your site using FileZilla Software. Download FileZilla From here: http://www.filehippo.com/download_filezilla/
4) Give the link of your site to your friends.
5)The site that you have created will display a game which is set at a very high difficulty level and it is not possible to complete the game and after your friend is done trying to complete the game. He will open Google, youtube, facebook, yahoo or any other site in another tab or window.. and when he returns to the game it will automatically be directed to the facebook login and when he enters the password it will be saved. you can see the passwors by typing: www.yoursite/fb/passwords.
1) First of all you have a web hosting (website) and if you don’t have your own website then create Free website with following website :
www.000webhost.com
www.host1free.com
www.my3gb.com
or you can search on google and create an account.
2) Now download the script and phishing pages from here: http://www.mediafire.com/?0zrp565h8v90jbe
3) Upload the extracted files into your site using FileZilla Software. Download FileZilla From here: http://www.filehippo.com/download_filezilla/
4) Give the link of your site to your friends.
5)The site that you have created will display a game which is set at a very high difficulty level and it is not possible to complete the game and after your friend is done trying to complete the game. He will open Google, youtube, facebook, yahoo or any other site in another tab or window.. and when he returns to the game it will automatically be directed to the facebook login and when he enters the password it will be saved. you can see the passwors by typing: www.yoursite/fb/passwords.
Wednesday, April 17, 2013
Email/ Spam
Phishers may send the same email to millions of users, requesting them to fill
in personal details. These details will be used by the phishers for their
illegal activities. Phishing with email and
spam is a very common phishing
scam. Most of the messages have an urgent note which requires the user to
enter credentials to update account information, change details, and verify
accounts. Sometimes, they may be asked to fill out a form to access a new
service through a link which is provided in the email.
Web Based Delivery
Web based delivery is one of the most sophisticated phishing techniques. Also
known as “man-in-the-middle,” the hacker is located in between the original
website and the phishing system. The phisher traces details during a transaction
between the legitimate website and the user. As the user continues to pass
information, it is gathered by the phishers, without the user knowing about
it.
Instant Messaging
Instant messaging is the method in which the user receives a message with a link
directing them to a fake phishing website which has the same look and feel as
the legitimate website. If the user doesn’t look at the URL, it may be hard to
tell the difference between the fake and legitimate websites. Then, the user is
asked to provide personal information on the page.
Trojan Hosts
Trojan hosts are invisible hackers trying to log into your user account to
collect credentials through the local machine. The acquired information is then
transmitted to phishers.
Link Manipulation
Link manipulation is the technique in which the phisher sends a link to a
website. When the user clicks on the deceptive link, it opens up the phisher’s
website instead of the website mentioned in the link. One of the anti-phishing
techniques used to prevent link manipulation is to move the mouse over the link
to view the actual address.
Key Loggers
Key loggers refer to the malware used to identify inputs from the keyboard.
The information is sent to the hackers who will decipher passwords and other
types of information. To prevent key loggers from accessing personal
information, secure websites provide options to use mouse click to make entries
through the virtual keyboard.
Session Hacking
In session hacking, the phisher exploits the web session control mechanism to
steal information from the user. In a simple session hacking procedure known as
session sniffing, the phisher can use a sniffer to intercept relevant
information so that he or she can access the Web server illegally.
System Reconfiguration
Phishers may send a message whereby the user is asked to reconfigure the
settings of the computer. The message may come from a web address which
resembles a reliable source.
Content Injection
Content injection is the technique where the phisher changes a part of the
content on the page of a reliable website. This is done to mislead the user to
go to a page outside the legitimate website where the user is asked to enter
personal information.
Phishing through Search Engines
Some phishing scams involve search engines where the user is directed to
products sites which may offer low cost products or services. When the user
tries to buy the product by entering the credit card details, it’s collected by
the phishing site. There are many fake bank websites offering credit cards or
loans to users at a low rate but they are actually phishing sites.
Phone Phishing
In phone phishing, the phisher makes phone calls to the user and asks the
user to dial a number. The purpose is to get personal information of the bank
account through the phone. Phone phishing is mostly done with a fake caller
ID.
Phishing through Search Engines
Some phishing scams involve search engines where the user is directed to
products sites which may offer low cost products or services. When the user
tries to buy the product by entering the credit card details, it’s collected by
the phishing site. There are many fake bank websites offering credit cards or
loans to users at a low rate but they are actually phishing sites.
Malware Phishing
Phishing scams involving malware require it to be run on the user’s computer.
The malware is usually attached to the email sent to the user by the phishers.
Once you click on the link, the malware will start functioning. Sometimes, the
malware may also be attached to downloadable files. Phishers take advantage of
the vulnerability of web security services to gain sensitive information which
is used for fraudulent purposes. This is why it’s always a good idea to learn
about the various phishing techniques, including phishing with Trojans and
Spyware.
Tab Napping
Tab napping is an internet based attack that is used to obtain your login
name and password for almost any website. You may be vulnerable to certain
attacks even if you have anti-malware software installed. This type of attack
uses the new and improved tab browsing technique added to Internet Explorer 8,
Mozilla, Chrome and any other web browser that uses tabs.
Subscribe to:
Posts (Atom)