Skip to main content

Posts

Showing posts from March, 2013

Pit Bull

SQL Injection step by step (for Begginers)

SQL Injection step by step (for Begginers) ------------------------------­---------------------------------- SQL Injection attacks are code injections that exploit the database layer of the application. This is most commonly the MySQL database, but there are techniques to carry out this attack in other databases such as Oracle. In this tutorial i will be showing you the steps to carry out the attack on a MySQL Database. Step 1: --------- When testing a website for SQL Injection vulnerabilities, you need to find a page that looks like this: www.site.com/page=1 or www.site.com/id=5 Basically the site needs to have an = then a number or a string, but most commonly a number. Once you have found a page like this, we test for vulnerability by simply entering a ' after the number in the url. For example: www.site.com/page=1' If the database is vulnerable, the page will spit out a MySQL error such as; Warning: mysql_num_rows(): supplied argument is not a valid MySQL result res

All UBUNTU keyboard Shortcuts

All UBUNTU keyboard Shortcuts UBUNTU is one of the popular operating system based on LINUX. It has a good number of users after fedora. I have already posted keyboard shortcuts for different web browsers and operating system. Today i am posting keyboard shortcuts for UBUNTU which will help you to work faster. Ctrl + A = Select all Ctrl + C = Copy the highlighted content to clipboard Ctrl + V = Paste the clipboard content Ctrl + N = New (Create a new document, not in terminal) Ctrl + O = Open a document Ctrl + S = Save the current document Ctrl + P = Print the current document Ctrl + W = Close the close document Ctrl + Q = Quit the current applicationKeyb­oard shortcuts for GNOME desktopCtrl + Alt + F1 = Switch to the first virtual terminal Ctrl + Alt + F2(F3)(F4)(F5)(F6) = Select the different virtual terminals Ctrl + Alt + F7 = Restore back to the current terminal session with X Ctrl + Alt + Backspace = Restart GNOME Alt + Tab = Switch between open programs Ctrl + Alt

XSSF (Cross-Site Scripting Framework )

-- - --------------------------­------------------- The Cross-Site Scripting Framework (XSSF) is a security tool designed to turn the XSS vulnerability exploitation task into a much easier work. The XSSF project aims to demonstrate the real dangers of XSS vulnerabilities, vulgarizing their exploitation. This project is created solely for education, penetration testing and lawful research purposes. XSSF allows creating a communication channel with the targeted browser (from a XSS vulnerability) in order to perform further attacks. Users are free to select existing modules (a module = an attack) in order to target specific browsers. XSSF provides a powerfull documented API, which facilitates development of modules and attacks. In addition, its integration into the Metasploit Framework allows users to launch MSF browser based exploit easilly from an XSS vulnerability. In addition, an interesting though exploiting an XSS inside a victim’s browser could be to browse website on attacker’

Boost Download/Browsing Speed in Firefox

Boost Download/Browsing Speed in Firefox ------------------------------­---------------------- Type "about:config" in the address bar. Hit Enter. Click on the "I'll be careful, I promise" button. Type "network.http.pipelining" in the filter bar. Press Enter. Double-click the line to set the value to "True." Type "network.http.pipelining.maxre­quests" in the filter bar. Press Enter. Double click this line and set the value of this to "202" Type "network.http.proxy.pipelining" in the filter bar. Press Enter. Double-click the line to set the value to "True." Type "network.dns.disableIPv6" in the filter bar. Press Enter. Double-click the line to set the value to "True." Right-click anywhere in the about:config window and select "New" then "Boolean." Type "content.interrupt.parsing" in the box provided and click "OK." Choose "True"

BSNL OFFICIAL BALANCE TRANSFER TRICK UPDATED

BSNL OFFICIAL BALANCE TRANSFER TRICK UPDATED BSNL has recently changed their portal numbers so that we can’t access some services as we previously use. As a result their official balance transfer trick has also changed. So today I’m going to explain how to transfer balance in BSNL mobile easily. Register for PTOP. STEP 1 - Register for PTOP by sending “register ptop” to 54455. STEP 2 - After registering you will get a password. STEP 3 - For balance transfer you have to send GIFT(space)friends no.(space)amount(space)passward to 54455 EXAMPLE – GIFT 9400082099 25 9 99990 to 54455 STEP 4 - Now you will receive a SMSconfirmation of the transfer. For help send “help” to 54455 NOTE : 1. For each Successful Transaction Rs. 2/- will be charged 2. Gift should Range Between Rs. 10/- to Rs. 50/- 3. Gift amount should be multiple of 10. 4. Minimum Balance Should be: Rs. 200/- in your phone 5. Gift can be send in samecircle like Rajasthan to Rajasthan, Punjab to Punjab, Haryana to Haryana, HP to HP

Chrome OS : Ways to Bypass Kernel protections

Chrome OS : Ways to Bypass Kernel protections *First Protection to Bypass : NX (Never eXecute)* Programs usually don't need to put their code on stack, so, it's logical to prevent them from doing it and executing content from there. NX is a protection option coming from processor used to control execution rights from some pages and used by Linux kernel. In this way, the operating system can use this facility to define what pages will have code and what others will have data. So, with this protection, we still can store our shellcode in the stack, but, we can't execute it. How to check it ? We need to ask for the CPU features of our current machine though 'flags' and founf that >NX< flag is active, it means NX protection is on. We can bypass this protection using something called ret2libc only if another protection called ASLR (Address Space Layout Randomization) is not used (ASLR works as like sharm on 64bits processors and not so good on 32bits). A more exten

Bypass Phone Verification

Bypass Phone Verification ------------------------------------ Description --------------- This tutorial will help you bypass phone verification on any website, this can be useful when you need to use a phone number to sign up to a site and do not feel comfortable giving your real phone number, or if you want to make multiple accounts. Step-by-Step Tutorial ----------------------------- 1) Sign up to Tpad at the following link: https://secure.tpad.com/signup/ 2) You will then receive an email with your Tpad number and your email verification link. It will say "Your Tpad number is 1752xxx.". Verify your email and save your Tpad number. 3) You must now download the Tpad program, you can download it using this link: http://www.tpad.com/downloads/ninja-dl.php 4) You must now go to ipkall.com and register with the following details: Select all Choose your account type: SIP Choose Area Code for your IPKall Number: 253 SIP username: Your Tpad number Hostname or IP address: sipx.tpad

Whatsapp on windows computer

Whatsappis one of themost popular mobile messengerapplication available in the market.Whats app is mostly available forall mobile platforms. Butif you are usingnormal mobile and wanna try this messenger thenhereis the goodnews foryou, throughthis trick you can use whatsapp in pc too ( Available Only For Windows& Mac). Bluestackis emulator with the helpof this you can run whatsapp as well as lot more mobile appsin your computer. DOWNLOADhttp://bit.ly/141PXyr FOLLOWTHE STEPSFOR INSTALLING WHATSAPPIN PC: 1) Onceyou have installed Bluestack in pc, run the programandclick on "Apps". 2) Then lookforTab named "Social" clickon it andinstall Whatsapp. 3) Afterinstalling whatsapp enter yourNew mobile numberwhich is not registeredearlier. 4) Now it will try to verify your mobile numberbut that won't work. Wait forsome time while it tries to sendsmsforverification. Afterit fails it will give you an optionto getthe verification codeovercall. Selectthe 'CALL ME' o