Skip to main content

Posts

Showing posts with the label Website Hacking

Featured Post

Kali Linux Terminal Customization Tutorial

Today I'll show you guys how to change kali linux terminal header text.

How to upload shell and how to deface a website (live demo) 2017

In this tutorial you'll learn how to upload shell on vulnerable website after uploading shell, how to deface website using shell. hope you guys enjoy this video. if you have any request to create new videos about your wishes let me know, i'll try my best to create the videos. Also if you have any questions or problems comment below i'll answer your questions. Download shell :  https://goo.gl/JGKH5k Download deface page : https://goo.gl/nQ61F5 How to customize linux terminal : https://goo.gl/7sGMnw How to hack SQL vulnerable website using SQLmap kali linux tool (live demo) : https://goo.gl/HtC6Px Get more Hacking tutorials : https://goo.gl/6TJoXF Follow me on facebook: www.facebook.com/soleymanofficial Follow me on Google+: www.google.com/+soleyman Follow me on Twitter: www.twitter.com/soleymanurj Don't forget to subscribe /like /comment /share if you enjoy my videos. Disclaimer – This Video is educational purpose ! Our tutorials are designed to aid aspiring pen t...

Hacker Backdoors Full Explained

Since the early days of intruders breaking into computers, they have tried to develop techniques or backdoors that allow them to get back into the system. In this paper, it will be focused on many of the common backdoors and possible ways to check for them. Most of focus will be on Unix backdoors with some discussion on future Windows NT backdoors. This will describe the complexity of the issues in trying to determine the methods that intruders use and the basis for administrators understanding on how they might be able to stop the intruders from getting back in. When an administrator understands how difficult it would be to stop intruder once they are in, the appreciation of being proactive to block the intruder from ever getting in becomes better understood. This is intended to cover many of the popular commonly used backdoors by beginner and advanced intruders. This is not intended to cover every possible way to create a backdoor as the possibilities are limitless. T...

How to search on Google like a Pro(Full Explained)

Google is best search engine in the world. Actually people think that Google's popularity is because of its simple and fast searching interface but friends, its more popular because it has rich operators and query support that will make your searching experience even better. Most of us doesn't know which operators are supported by Google and if they know some of them, they doesn't know how actually these operators work and enrich our searching practice. Today, i will tell you How we can search on Google like elite hackers or simply say computer experts do. But for this its necessary that you should know and understand all the Google operators properly. So lets learn how we can enrich our searching experience in Google. Google operators : Google operators are classified into two basic categories: 1. Basic Google Operators like and, or, not etc. 2. Advanced google operators like inurl, intitle etc. I am also including bonus search queries that are ext...

What is Malware?

What is Malware ? Malware is a combination of the two words malicious and software. It is a program or software that is specially designed to damage, or in most cases, infiltrate a computer system without the administrator's knowledge. The term is used by security/computer professionals in replacement of the terms hostile, intrusive, or annoying software. The term computer virus is sometimes used as a catch-all phrase to include all types of malware   Types of Malware Viruses Worms Trojans Rootkits Spyware 1. Viruses The term virus is used for a program written by someone which has infected some executable software, when run, to spread the virus to other executable software. They may also contain machine code or payloads to perform other (often malicious) actions. The purpose of a virus is 99% of the time, to destroy data or corrupt it. 2. Worms A worm is also a sort-of virus, but unlike a virus, it automatically transmits itself over ...

Wordpress 0day Exploiter [ Full Tutorial ]

Wordpress 0day Exploiter [ Tutorial ] Wordpress 0day Exploiter Wordpress 0day Exploiter is a tool that enable you to register as new admin on a wordpress site which have the bug on the Ajax.php file. How to create dorks? It's very easy so create the dorks, the list of vulnerable themes are already provided on the right richtext box. So, you just need to add the theme name. Dork: inurl:/wp-content/themes/[theme_name] Example: inurl:/wp-content/themes/appius How to use the tools? It's easy, once you have found your target, 1- Simply paste the site URL,theme name, an your email in the textbox 2- Click on Confirm > Exploit 3- If your target is vulnerable, the " Register " button will be enabled 4- Click on Register and the webbrowser will bring you to the registration page 5- Enter your username and email 6- Check your email inbox for the confirmation and the password for your account. 7- Login to the site and there you go 8...

DDOS Attack Full Tutorial with Software

A new DDoS tool from Anonymous called high-orbit ion canon or HOIC come into light. Attackers are constantly changing their tactics and tools in response to defender's actions. HOIC is an Windows executable file. Once started, you will be presented with the following GUI screen. If the attacker clicks on the + sign under TARGETS they get another pop-up box where you can specify target data. When you click on the+ button, a new window will open where you can specify following things URL - is the target website to attack Power -> sets the request velocity. Booster - are config scripts that define the dynamic request attributes HOIC includes a new feature called 'boosters' which are files you download or add to an attack machine which enables the attacker to manipulate headers such as language, referrer, host, etc. To launch the attack click on "FIRE TEH LAZER!" button. The claim is this: LOIC did TCP, UDP and HTTP flooding, but HOIC focus...

How to be a good hacker

Alot of peoples are asking and bragging about in this forum and also on the internet :b plz: that " please teach me hacking , what is hacking , please hack for me " , So i thought i should post a little but more informative guide OR tutorial to seek the basic points and then by longing these points in the brain on its own Firstly you have also heard about the famous quote that " Hackers made or make tools , Tools not make's hackers " By forwarding with this quote , i hope , u will understood deeply what it says . To those whom don't , i am there .... LOL This basically says that First when u are curious enough that u want to learn hacking 100 % and u are seeking here and there where to start ... then this quote meaning is this ..... Basically there are three types of peoples , ( whom one are mixed and related a relationship with each other ) , which they pretend to be go in hacking field Firstly there are the kind of 1st people...

Ethical Hacking Ebooks Collection Free Download

Hello, Guys our previous post of Collection of Programming Languages E-books just rocked & I'm Glad to see that all readers are enjoying our Posts and articles, well this time we've arranged Ethical Hacking & Gray Hat E-books Collection, many readers and fans were eagerly waiting for this Post, finally - We Posted.   | Ethical Hacking & Gray Hat E-books |   Just Click on any Ebook Name & Download Black Belt Hacking & Complete Hacking Book Hackers High School 13 Complete Hacking E-books Penentration Testing With Backtrack 5 A Beginners Guide To Hacking Computer Systems Black Book of Viruses and Hacking Secrets of Super and Professional Hackers Dangerours Google Hacking Database and Attacks Internet Advanced Denial of Service (DDOS) Attack Computer Hacking & Malware Attacks for Dummies G-mail Advance Hacking Guides and Tutorials Vulnerability Exploit & website Hacking for Dummies Web App Hacking (Hackers Handbook) Security...

How to upload shell on wordrpess websites

You will need: 1) Admin access to Wordress panel 2) Any php shell 3) Brain First you need to go to: Appearance -> Editor Choose any themes you wanna. For example i selected "Twenty Twelve" Now select one file from right site (It must be .PHP file) When select you can edit it now. Take your shell source and paste it there. Now just save it. (If you got an error try other file,or simply you can't edit plugins) THEMENAME I SELECTED = twentytwelve FILE I SELECTED = footer.php You just need to access it now. By default template in wordpress are located in: Code: www.site.com/wp-content/themes/THEMENAME/FILE.php So our final link would be Code: www.website.com/wp-content/themes/twentytwelve/footer.php DONE ! Happy Hacking :D

Some most important google dorks

Salam all , today i can give you some most important google dorks . whos help you for hacking . lets see blew - Dork for finding shell inurl:.php “cURL: ON MySQL: ON MSSQL: OFF” “Shell” filetype:php intext:”uname -a:” “EDT 2010? intitle:”intitle:r57shell” [ phpinfo ] [ php.ini ] [ cpu ] [ mem ] [ users ] [ tmp ] [ delete ] inurl:”c99.php” & intext:Encoder Tools Proc. FTP brute Sec. SQL PHP-code Update Feedback Self remove Logout inurl:”c100.php” & intext:Encoder Tools Proc. FTP brute Sec. SQL PHP-code Update Feedback Self remove Logout intitle:”Shell” inurl:”.php” & intext:Encoder Tools Proc. FTP brute Sec. SQL PHP-code Updat Dork html injection inurl:"id=" & intext:"warning: mysql_fetch-assoc() inurl:"id=" & intext:"warning: mysql_fetch-array() inurl:"id=" & intext:"warning: mysql_num_rows() inurl:"id=" & intext:"warning: session_satrt() inurl:"id=...

Hack hundreds of wordpress sites easily

Google dorks for this wordpress Exploit Dorks “inurl:/wp-content/plugins/easy-comment-uploads/upload-form.php” "inurl:/wp-content/plugins/easy-comment-uploads/upload-form.php" "Index of /wp-content/plugins/easy-comment-uploads"  Step 1 - Open google.com and enter any google dork which given Step 2 - Now select any website of wordpres and go to this url target.com/wp-content/plugins/easy-comment-uploads/upload-form.php You'll get upload option here posted image. Now upload your shell to deface the website. Step 3 - Now check it here target.com/wp-content/uploads/2015/07/shell.php (your uploaded file here ) Now you have shell access to the website .... ;) Happy Hacking & Enjoy with me :D

Admin panel finding method (Four method)

Hello guys , Today i will show - Finding admin page in four method . Havij   >  admin finder Acunetix  > crawler Google > inurl & intext New method  > robots.text  Havij  Open havij and go to find admin option. Past or write the target in path to search box and click start Acunetix  Open acunetix vulnerability scanner . Click on site crawler option, Past your target site on url box and click start button . You will see many thing and just fine in search result in of acuntix admin folder and click on it and go in right side and open the admin url and enjoy the admin page. Google This method is interesting  and this method has two option…..! Intext : in this method we seach in page of sites ……! Inurl: in this method we search in the address bar (URl) …..! Ex : this is my target : www.blabla.com              Intext :    ...

Uploading Shell In Joomla Site ( New and Private ) Method

Hello Guys, Today i will show you how can you upload shell in joomla (CMS) site . If it is totally update with the newer version. Well we all know, how to upload shell in joomla website using theme editor and image uploader options, [ Who dont know , read my previous post here ], but this only work on older versions of joomla websites, But if the joomla version is update to latest version then you cant upload shell using these methods because all this options are patched in newer versions of joomla, So here i come the another private method :D okk lets start, #After getting access to admin panel of joomla site , Then click on Install/Uninstall or Extension Manager After that, You will get a new window which has upload option like this below, Now download this exploit, Then click on browser and then select the zip exploit which you downloaded and click on upload and install After successfully install, You will get this "Installing Component Was Successfull" ...

Finding Php Shell Scripts In Your Website

PHP vulnerabilities are the norm, there is not much that can be done to prevent uploads of malicious files on a PHP site when there are world writeable directories especially when your website is using a well known open source community driven software product to power your website.PHP shell code can usually be found in many websites around the web specially when the administrator does not know much about how to clean out the backdoors after a hack has been done. Here is a simple bash shell script that will search your public_html directories for common method with a large number of files. It will dump the results to a file called "php_backdoors" which you can examine to determine what is and what is not a false positive. To use this shell script just past this into a file called checker.sh in the directory before your public_html folder, then run it with the following command: sh checker.sh script : #!/bin/bash cd public_html/ find . -type f \( -ina...