Sidejacking – Hacking USER Accounts on LAN & WiFi!

In my last post about Facebook hacking, i had mentioned something called Web cookie stealing and i had also promised to post more on it. Today i will discuss on how you can steal cookies when on LAN or WiFi Network using a technique called Sidejacking.
When you login to any website by submitting your username and password, First the server checks if an account matching this information exists and if so, replies back to you with a “authentication cookie” which is then stored by your browser for all subsequent requests and to keep you logged-in.
What is Sidejacking?
Sidejacking attack (also called as session hijacking) is when an attacker gets a hold of a user’s cookie, allowing them to do anything the user can do on a particular website. In other words, the attacker can now make use of your cookie to impersonate your account and can do everything a user can do when logged-in to any website.
Its very common, that many Websites protect your account by encrypting the login process. But it is very uncommon for Websites to encrypt everything else after you login(eg:cookies). This makes the cookie and the user vulnerable. On an open wireless networks like WiFi, cookies are basically shouted through the air, making these type of attacks extremely easy, yet very popular websites continue to fail at protecting their users.
The Sidejacking Attack Involves two Major Steps:
#1. Capturing packets (Session Cookie)
There are wide variety of tools available that can Sniff packets containing “session cookies“. Use any packet sniffer such as Wireshark to sniff the packets between the target IP and the host. These tools can capture packets such as POST or GET requests used by Web-browsers to send and receive data from the HOST. But we are mainly interested in grabbing the cookies, so carefully takeout the cookie information from the sniffed Packets. Popular packet Sniffers: WireShark, Ethereal, etc.
#2. Using Captured Session Cookie.
Once you have the cookie information, the next task is to use this information to get access to victims user account. Using Sniffed Cookie you can actually login to your victims account even without knowing his/her password. To do this you will require browser plugin that can manage and edit cookies. For firefox Browser, you can use Cookie Manager+ or Edit Cookies to do this task. Chrome users can checkout: Edit This Cookie or Cookie Manager.
Easiest Way to SideJack:
The above method is cumbersome ofcourse, and requires more time. To simplify this Task, Mr.Eric Butler a software engineer introduced a firefox extension called Firesheep. The extension was created as a demonstration of the security risk to users of web sites that only encrypt the login process and not the cookie(s) created during the login process. The extension uses a packet sniffer to intercept unencrypted cookies from certain websites, as the cookies are transmitted over the networks.
Sidejacking - Hacking USER Accounts on LAN & WiFiWhen you are on public Wifi or LAN, Fireship can automatically capture all the available session cookies of any website and reports it to you. You can Now choose between all the available use accounts and you are just a click away to access them.
As you can see above, It shows the discovered identities on a sidebar displayed in the browser, and allows the user to instantly take on the log-in credentials of the user by double-clicking on the victim’s name.
Download: firesheep-0.1-1 for Windows & OS X
Firesheep has exploited and made it easy for public wifi users to be attacked by session hijackers. Websites like Facebook, Twitter, and any that the user adds to their preferences allow the firesheep user to easily access private information from cookies.

-How do i Protect Myself from SideJacking Attack?

#1. It is very easy to protect yourself against this sort of attack. Both Facebook & Twitter supports HTTPS, so when you browse facebook (or twitter for that matter) On Public Wifi or LAN, please make sure you’re using HTTPS:// rather than HTTP:// in the URL.
Facebook: Account Settings >> Account Security >> check “Secure Browsing (https)” >> Save.
Twitter: Settings >> Account >> check “Https Only” >> save.
#2. FireFox Users can use Plugin called HTTPS Finder. HTTPS Finder automatically detects and alerts when SSL is available on a web page. It also provides one-click rule creation for HTTPS Everywhere.
#3. When you are using Public WiFi, Avoid Logging-in on Websites that doesn’t Support HTTPS://. Don’t use sites that revert back to HTTP after login.
#4. Always Log off websites when done. If the ‘victim’ logs out of any Website, the attackers session becomes invalid – so it’s a good practice to actually log out and log back in again rather than using the ‘remember me’ check-box.
#5. Avoid using unencrypted Wi-Fi. Encrypting everything over Wi-Fi is an excellent idea. Although not many hot-spots offer Encrypted WiFi, using it can greatly reduce the risk of being hacked.

Top 10 Free Keyloggers to monitor your Local PC or Laptop!



Free tested Keyloggers to monitor your Local PC or Laptop
As promised in my last post, here i am with an exclusive list of top 10 free local keyloggers. You will find hundreds of free keyloggers online, However only few will be legitimate and free from malicious codes that will in-turn affect your own PC itself. This is the First reason i Always recommend to go for Paid Keyloggers like Winspy and SniperSpy. Secondly you will find almost all free Keyloggers are detectable by popular Antivirus, due to poor coding and this is another reason to buy paid Keyloggers as they are completely operate in stealth mode.

However If your are planning to monitor only your PC or any PC which you have control of, then you can blindly go for “Hardware Keyloggers” as they are the safest keyloggers and operate in a complete stealth. If you Still wanna Prefer Free Keyloggers then below is the list of Free keyloggers that will really help you monitor your PC and get your sisters or spouses passwords.
Disclaimer: I have tested these free keyloggers available to bring you my favorites, However I hold no responsibility for the free keylogger software’s i link to.
[ * ] The keyloggers are ranked according to Ease of Use and Capability. In some keyloggers you need to choose secrete keycode or password or some keyboard key combination to view the control panel. So Its highly recommended that you read the “readme” text or instructions of each keylogger.

#1. REFOG Free Edition

Refog Free Keylogger beats competition in two respects: it’s simple to use and it’s free. REFOG Free Keylogger can look after your children without them even noticing. Even technically minded children won’t detect the key logger when it runs in a stealth mode. The program removes all the shortcuts and can be accessed only through a hot key combination. Running unobtrusively from the moment the system boots, REFOG Free Keylogger keeps track of all typed or pasted text.

#2. Black box express [My favorite]

Simple to use monitoring of one local computer; Monitor Screen recordings, Programs, Keystrokes typed, Websites, Web Searches, Emails/Webmails/ Instant Messenger Chat sent and received. Alerts and Warnings instantly or as a summary on your e-mail or cell phone. everything for 100% Free. No strings attached.

#3. Personal keylogger [portable]

The Personal Keylogger application was designed to be a small tool that will allow you to secretly record all keystrokes and other input. All specific instructions are explained in the application. To exit it and receive your logs, you will need to enter in your keycode. If you have forgotten your keycode, you will need to restart the computer. Keycode is like password. To stop Personal keylogger, you can enter your keycode anywhere on the screen. Once you type-in your keycode, the keylogger will stop monitoring and the log.txt file will be created in your selected destination folder.

#4. Py keylogger

PyKeylogger is an easy-to-use and simple keylogger written in python. It is primarily designed for backup purposes, but can be used as a stealth keylogger, too. It does not raise any trust issues, since it is a short python script that you can easily examine. It is primarily designed for personal backup purposes, rather than stealth keylogging. Thus, it does not make explicit attempts to hide its presence from the operating system or the user. That said, the only way it is visible is that the process name shows up in the task list, so it is not immediately apparent that there is a keylogger on the system.
#Tip: Press and hold ‘left-CTRL + Right-CTRL + F12′ keys simultaneously to bring up the Control Panel (default password is blank).

#5. Heretic Macro

Heretic is a powerful tool that is able to record user events, such as mouse clicks and keys, into a C/Java-like script, and play that script either once or repeatedly. It has many commands for dynamic pixel-based botting, window based botting, and static botting/macro-ing (i.e. key presses, mouse clicks, mouse moves, and pauses).

#6. Ultimate Keylogger

Ultimate Keylogger Free is a free popular all-round monitoring solution. It runs in the background and monitors all typed keystrokes, applications, passwords, clipboard, email, and visited websites’ URLs. You can view the reports as HTML files. Ultimate Keylogger Free will help you to find out, what exactly took place in the system.

#7. Actual keylogger

It runs hidden in the background and automatically records all keystrokes (including Alt, Ctrl and other functional buttons). The interface can be password protected and the log files are encrypted. You can view the reports as HTML or plain text. In the hidden mode it is invisible in all operating systems.

#8. Revealer Keylogger Free Edition

Revealer Keylogger is surely the easiest and faster way to record keyboard inputs. There is almost nothing to configure, in fact everything is configured internally with the best settings. Free keylogger monitoring tool that logs every keystroke even passwords behind asterisks and conversations in common instant messengers. Its interface is password protected, the software does not appear in Add/Remove programs or in the taskbar.

#9. Romaco Keylogger

Romaco Keylogger is a small and easy to use tool that can log all key-presses that are made while it is running, and display them to you in its window. It automatically exports the logged text to a text file every 5 minutes, or manually. It can be hidden at the click of a button, and recalled by vigorously pressing one of the least used keys on the keyboard, the break key.

#10. KidLogger

KidLogger collects user activity journal on the Computer and creates detailed Analysis of the user activity available online. Creates the list of most used web sites. Record the text was typed on the keyboard in any application
Let me know which one you liked or if you are facing any problem installing any of these, please comment your problems below. I would love to solve you problem. Enjoy!

Hacking an Gmail,Yahoo,Hotmail emails using Google..

After my previous article on Facebook Hacking, I am back with one more awesome trick to hack any random gmail,yahoo,hotmail etc and many more email-id password very easily.

I see alot of new visitors are wanting to learn how to hack somebodies hotmail gmail yahoo account..or asking others to do it for them.
Most are under the illusion that there's this "hack" button you can press and you instantly get their password, however this is not the case.
Most newb's are put off by the fact that they have to keylog or phish their way into getting a password, and they resort to asking the "hackers".
But i'll provide an easy alternative.

This method is called Hash technique.

Hacking your first email seems boring and needs time,but after reading this tutorial you find it simple and easy !!



Steps for hacking emails :

1)Go to www.google.com and type in the search bar this code "ext:sql intext:@hotmail.com intext:e10adc3949ba59abbe56e057f20f883e"


2)Choose any one of the displayed pages,scroll a bit down ,then something like this should appear,Hash codes and emails.


3)Now go to : www.h4ckforu.com , then copy the HASH CODE (ex:127359f404a2b735de9ba1336c66f480) depending on the email you choosed to the box. Press Crack it, wait few seconds.


4)Some sites will appear saying "not found" other sites will give you the password of the hash code you entered that belongs to the email you choosed.[As shown in the picture above ]

5)You are done!! Enjoy the email you hacked :D...some emails won't work since the have their passwords changed, or the hash codes results are null.


Common Question of all visitors,

Question : why it does not worked for me ?
Answer : Some time its not worked because the password was changed ,So Use a new hash to reach a right password

It not work in every account but mostly can hack..Just try try try.........

So friends, I hope this
Hacking an emails using Google tutorial will help you to hack emails accounts.

Got problems in this hacking tutorial?? then write your problem in comments.

Enjoy free emails hacking to hack gmail,yahoo,hotmail ....passwords...

Airtel 3G Hack : Free Airtel 3G Internet For Your Computer

We have already discussed about Free Docomo GPRS hack on h4xor, But now many network provider have launched 3G service. So today I am sharing this trick to hack airtel 3G plane on your computer. Actually this trick is shared by one of my friend. He got 900kbps download speed with airtel 3g using this trick.

Step 1: Connect via AIRTELMMS.COM(MOST IMPORTANT)..
            IF U WANT IT EASY THN GO TO DEVICE MANAGER..SELECT THE MODEM..IN ADVANCE TAB..IN COMMAND SIMPLY PASTE { +CGDCONT=1,"IP","AIRTELMMS.COM" } WITHOUT BRACKETS

Step 2: CREATE A DIALUP CONNECTION....

Step 3: IT WILL CONNECT...AS NO NETWORK ACCESS

Step 4: GO TO CONNECT TO..U WILL SEE CONNECTED...

Step 5: RIGHT CLICK ...LEFT CLICK PROPERTIES

Step 6: GO TO NETWORKING TAB

Step 7: CHECK ALL THE CHECKBOXES

Step 8: CLICK ON INTERNET PROTOCOL VERSION(TCP/IP)

Step 9: CLICK ON PROPERTIES

Step 10: SELECT USE THE FOLLOWING DNS SERVER ADDRESSES

Step 11: ENTER ANY FREE DNS SERVER..I RECOMMEND
              156.154.70.1
              202.138.96.3

Step 12: CLICK OK

Step 13:AGAIN OK

Step 14: A MSG APPEARS " SETTING WILL TAKE PLACE NEXT TYM U DIAL IT" CLICK OK

Step 15: GO TO START> CONNECT TO > DISCONNECT

Step 16: RECONNECT

Step 17: OPEN ANY WEBSITE ...........Enjoy Free Airtel 3G...

Above trick works at any balance with No Balance Deduction...

Credit : H4xOr.Tk

So friends, I hope this Airtel Free 3G Hack tutorial will be useful for you. If you have any problem in this Airtel Free 3G Hack tutorial, please mention it in comments.


Kindly Please Click Ads Daily To Support Us...

Twitter Delicious Facebook Digg Stumbleupon Favorites More

 
cσρуяιgнт ®©₂₀₀₈⁻₂₀₁₁ ßψ †hε ⊕ωηεr ⊕ϝʂɱʂ υρԃαƚҽʂ ⊕η pußレïς dεmαηd