Showing posts with label Basics Hacking Tutorials. Show all posts
Showing posts with label Basics Hacking Tutorials. Show all posts

Monday, December 13, 2010

How To Keep Your Data Safe: Safe Data Backup & Recovery


How To Keep Your Data Safe: Safe Data Backup & Recovery

From keeping your phone contacts safe to keeping your PC backed up & synced,Here are some easy and quick options available

IF IT HAPPENS TO YOU,LOSS OF DATA can be crushing.Imagine,if years of your hard work,thousands of documents,digital photographs,videos and songs vanished without a trace.To prevent this from happening,you should always keep multiple and recent backups of your data.These days,with more powerful devices and increased storage,even a smartphone serves as the primary repository for hundreds of contacts,email addresses,songs,photographs and video.Phones can get lost or stolen,and thanks to the increased complexity,can also crash - leading to loss of data.Here are some of the various ways you can back up all your precious data,whether on physical devices,or online,on the 'cloud'.

For your phone

Google Sync-

www.google.com/mobile/sync Heavy users of Gmail should look no further than Google Mobile Sync.It's completely free,supports BlackBerry devices,iPhone,Nokia,Windows Mobile and various other phones that use the Sync-ML standard for data synchronisation.You can store all your phone contacts within Gmail and access them anytime.And,if you get an Android device,all you have to do is enter your Gmail ID & password into the device and all your contacts will be on it instantly.

Bloove -

www.bloove.com Bloove is a Web-based management system for phone contacts.It works on Android,Symbian,Windows Mobile and others using J2ME.You only have to sign up for an account and download the Bloove app on to your phone.Then,using GPRS,you can save the contacts securely on Bloove's servers.The paid plans offer extra features like archival of SMSes,scheduled SMS sending and restoring of contacts to multiple phones.

Mobical -


www.mobical.net Mobical supports hundreds of different phones,ranging from Nokia,Motorola,HTC,Samsung and Sony Ericsson.The service is completely free,and like Bloove,it uses GPRS to sync data from your phone onto their servers.Data usage is high,because when you add a new contact to your phone,it is automatically added to your online backup.

Anywr Beta -


www.anywr.com Anywr is more than just a backup service.It allows you to import and combine various address books you may have (such as from multiple webmail providers),have a social calendar which your friends can see,see what your friends are doing,and restore your contacts easily in case your phone gets reset,lost or stolen.

Syncfriend -

www.syncfriend.com Syncfriend offers contacts storage,but with a few hidden gems.Like the others,it can automatically sync and backup data,but it also includes a 'de-duper';it can automatically search for and remove duplicate entries in your phone contacts.Syncfriend also provides a free Outlook client to sync addresses.It integrates with Outlook and adds a menu to the toolbar for phone data sync.

TIP:

Online backup is great,but don't undermine the importance of keeping your phone data backed up locally as well.Sync the phone using the supplied PC software and save date-wise backups.If you don't have the CD that came with the phone,you can always download the latest version from the manufacturers website (look in the support/download section).If all important contacts are backed up to an application like Windows Address Book or Microsoft Outlook,they can also be exported to Excel files or transferred to a new device easily.

For your PC

Dropbox -


www.dropbox.com Dropbox offers 2GB of free online space for backups and syncs across multiple devices (smartphones,Windows,MACs & Linux).First,you sign up for a free account and download the software to your PC.Then you designate one folder as a Dropbox folder,store anything in it and sync it with an unlimited number of computers.Paid plans are available for $9.99 a month or $ 19.99 a month (50/100GB).

Mozy -

www.mozy.com Mozy also offers 2GB of free online space for backing up all your data,but the paid service costs much less than Dropbox at $4.95 a month or $54.45 a year for unlimited storage.That's right;all the data on your PC,whatever it is,whatever format,can be backed up online.So,in case the hard drives crash,your PC gets stolen or washed away in a flood,you still have all your data.Initial backup takes the longest,and depends on the amount of data and your internet connection speed.But thereafter,only the files you change get backed up.

Free online storage

http :// skydrive.live.com If you prefer to keep things simple,you can go with regular online storage.Windows Live Skydrive offers 25GB of free space to store any data you want.If you have a Windows Live Hotmail,Messenger or Xbox Live ID,you're already signed in to use SkyDrive.You don't need any additional software,since you can upload files using any web browser.www.adrive.com is another option,they offer 50GB free.There is an advantage to these services as compared to Dropbox and Mozy;you don't need to keep a client application running on your PC all the time.You can take control of your backups,and do them when you need to.

More options

Other services that you can explore for online backup of data are Syncplicity (www.syncplicity.com),Sugar Sync (www.sugarsync.com),Carbonite (www.carbonite.com) and Box.net (www.box.net).

TIP:

On a Windows machine,utilise the built-in Windows Restore feature.This tracks changes to the computer and can revert to a safe state in case there is a problem.This is done with the help of restore points,which can be manually or automatically set.Storage of multiple restore points on a machine can also clog up hard drive space,so you can choose to keep only the most recent restore point and delete the rest.For more information : http:// goo.gl/mmMgm

SOURCE: Times of India

---Do you want to share you views?? Just leave a comment here. you can also drop an email on amarjit@freehacking.net

Tuesday, November 23, 2010

Video Chat in Orkut: Orkut Video Chat


Video Chat in Orkut: Orkut Video Chat

Orkut recently announced the launch of orkut video chat, an easy way to get in touch with your family and friends that to face-to-face, directly from your orkut pages.

To chat face to face with your family and friends you just need to have a webcam & a microphone connected to your computer and a small plugin that is available for free at

www.google.com/chat/video

The next step will be to validate your e-mail address on orkut as to be able to chat or video chat on orkut.

For more you can go through this video.


Video Chat in Orkut: Orkut Video Chat

---Like this post, Just leave a comment as your feedback. If you want us to post an article on some specific topic OR have a suggestions for us...you can also drop an email on amarjit@freehacking.net

Wednesday, September 8, 2010

How to Defend Your Account & Passwords From Hackers

How to Defend Your Account & Passwords From Hackers

GUEST POST BY DarkL00k aka Ajay Dhaka

How many times have you heard someone ask "how do I hack Orkut or Gmail?"
It’s become a type of joke among frequent visitors of hacker related chat rooms and websites. This article is being written for the sole purpose of defending yourself against such actions.


Lets start by going over a few terms I use so there is no confusion. If you think this is silly, you’d be surprised at the # of emails I get asking what is a...
I figure I’ll just spell it out.

UN = username
PW = password
SW = software
HW = hardware
DL = download
KL = keylogger
RAT = remote administration / access tool.

Dispelling a few rumours:

1. You can use a bruteforcer program to get a Orkut/Gmail or Hotmail password.

This simply is not the case. Both Orkut/Gmail and Hotmail have security in place specifically designed to stop this kind of attack. Orkut/Gmail requires that you enter a random code into an additional field provided as well as the UN and PW after 3 failed login attempts. Failure to enter the correct code will result in a failure to log into the account, even if the UN and PW are correct. Hotmail has a different security feature which sends the user to a ‘lockout’ page, which has NO fields to enter the UN or PW after just one failed attempt. These two methods are effective for eliminating bruteforcing to exploit their service.

2. There are programs that hack Yahoo and Hotmail.

Once again, that’s not entirely true. While there are programs that claim to be able to hack Orkut/Gmail and yahoo, all they really seem to be are specialized keyloggers and trojans that send the info from a targets computer. The question is then, if you can get a target to download / run a program, then why would you only steal their email account information? Why not simply take control of the whole thing? A lot of people that use these programs are not well versed enough to know how to cover their tracks and can easily be caught when using such programs. Many of these programs are also specially designed to steal information from the computer that tries to run it, thus exploiting the would-be attacker.

3. You can email an automated pw recovery service and trick it to gain the pw of the account you choose.

Ever see something that goes something like this?:
Note: the following is bullshit. Ive added this note since no one seems to read this tutorial and skim through it, then email me complaining that it doesnt work. thus...

THE FOLLOWING IS AN EXAMPLE OF A SCAM.

(1) send an E-mail to passwordrecoverybot@gmail.com
(2) In the subject box type "PASS RECOVERY SYSTEM"
(3) In the message box type in first line : "Victim's USER ID"
(4)In Next Line type your User ID.
(5)In Next Line Type Your Password.
(6)In next line type these codes " /cgi-bin/start?v703&login.USER=passmachine&class=supervisor&f=get.password&f=27586&javascript=ACTIVE&rsa
(4) Send the e-mail with priority set to "high" .
(5) Wait 2-3 minutes and check your mail


Well, there’s my example of a scam designed to steal your information...simply by tricking you into sending your password to the attackers email (passwordrecoverybot@gmail.com in this example) and the specific things to type and all that bullshit is just that... bullshit. Specificlly, bullshit made to look like it actually does something to the standard pc user and/or layperson (aka target)... but it doesnt.

This may also explain some of the people saying they were hacked. Obviously, don’t send your password to anyone for any reason, ever.

What it all comes down to is this:

If you're looking to get an email ID, you hack the targets PC, not Gmail or yahoo directly. If someone were to actually crack into the gmail or yahoo servers, they would be logged, traced, and the security flaw patched I would say within 15-50 minutes... maybe 24-48 hours the latest.
These types of companies have a multi million or even billion dollar backing, a literal army of first class techs and security teams, and apply the newest and most sophisticated SW, HW and intrusion detection/protection/management methods the industry has to offer.
Now on the other side of the story, you have an end user who probably hasn’t even installed a single update on their machine, has all the default settings enabled, doesn’t know an .exe file from a .com, uses an un-patched version of IE or AOL, doesn’t know how to enable their firewall or configure it if it is enabled, etc.

In other words, why attack a well-trained, well-equip army guarding a document when you can attack a less able individual to get it?

Note – This type of many video available on YouTube.

These are some of the more common methods for "hacking Gmail/ Yahoo PWs":


1. Fake login page
2. email phishing campaign
3. RAT
4. Keyloggers
5. cookie grabber
6. spyware
7. fake programs (rat/kl)
8. Social engineering


1. Fake login page:

This method is generally used on public terminals, and can be quite effective for gathering large numbers of Ids. The way it works is documented in another tutorial I have written, but basically its just a matter of someone making a replication of Gmail or Yahoo site, by copying and making minor modifications to their source code and setting their page as the home page. They then set the input fields to send the information to an email address or database. I personally believe the level of success using this method depends on the system, and the amount of creativity involved in making the page look as authentic as possible. To avoid falling victim to this, type the address of the page you are logging into directly into the browser, including the prefix "http://"

2. Email phishing campaign:

Phishing has unfortunately become a household word, though some people associate it with SPAM. Phishing is really just spamming and using deception and trickery to gain information to exploit a service, system, etc. Phishers have posed as banks, email services, law enforcement agents, online contests, teachers, automated services, Nigerians in need of a way to transfer millions in cash, software firms, friends, acquaintances, even the targets themselves. Anyone and anything that you can impersonate, expect a phisher to try. Their emails generally come with an attachment that contains a program like a trojan, RAT or keylogger or virus that either exploits your system searches for PWs and banking info and sends it to the phisher or simply infects or destroys your PC. Some of these scams can be EXTREMELY well done, and almost indistinguishable from a real email (provided by for example, a company they are impersonating). It’s always best to contact the company by phone or mail to confirm anything suspicious.

3. RATs:

Remote administration tools or remote access tools. These programs allow an attacker varying degrees of control over the PC that has the SW installed. The level of access depends on the RAT. Control over the PC allows installation of other malicious software that can be used to track keystrokes, web sites visited, programs accessed, and even take screenshots of the infected computer and send them to an email address covertly. It is also capable of allowing the attacker to make any changes to the system they would like. Obviously, this isn’t good.
Most antivirus and spybot removal SW will detect and remove these types of programs. It’s also a good idea to not only use, but check the logs, settings, permissions and outgoing/incoming traffic of your firewall to prevent this type of thing from happening to you.

4. Keyloggers:

Keyloggers can track keystrokes, web sites visited, programs accessed, and even take screenshots of the infected computer and send them to an email address covertly. Again, most antivirus and spybot removal SW will detect these. If you fear your pc has been comprimised, you can take steps to ensure your PW isnt logged until you can scan for and remove it. Open a word document and write out a list of the UN’s you’ll be using and the a list of the PWs. then cut and paste them accordingly into the fields if you fear a KL or other monitoring device may be in use so that while the SW will pick up the keystrokes, it will not know what PWs match the UNs. If you'd like to take that a step farther, write several random letters and numbers around your PW in the word file and cut out the extra letters until you come out with the UN or PW desired.

5. Cookie grabber:

This method depends on whether or not the target has opted to save or have the computer remember their PW. The information is saved in the cookies and can be used to exploit some mail services. The information can be gained through a website or email containing a script that ‘grabs’ the information. Deleting or not allowing the use of cookies can stop this method.

This method is most common using in many Orkut Communities named by :"FREE RECHARGE OF RS. 500" Etc..............

6. Spyware:

Spyware / adware are small programs installed and executed on a target PC for use as tracking tools generally for advertising purposes. These programs generally rely on web browser vulnerabilities to install and run on your system. However, as previously mentioned, any program that is installed on your PC without your knowledge isn’t good. Some attackers have taken this technology and created spybots particularly designed to send sensitive information about your system to a predetermined mail address or database. This can generally be avoided by updating and patching your browser as often as possible. I personally suggest using Mozilla Firefox as a browser, as it is not as vulnerable as internet explorer and operates in much the same way, and has a similar interface. There are literally THOUSANDS of anti spyware programs available, two that I find work exceptionlly, especially in conjuction with each other is Spybot Search and Destroy and Adaware SE personal. Before you get a spyware removal program, research it and see what the general concensus is as some programs touted as spyware removers actually install spyware on your system.

7. Fake programs:

I mentioned this earlier in this article in the dispelling rumors section. There are programs like booters, Gmail and yahoo hackers, point and click trojans, keyloggers, audio and video SW, etc that contain RATs and other malicious programs. The obvious way to minimize the chances of becoming a victim of this method of exploitation is not to DL ‘shady’ programs (ie. programs that do illegal things). The general rule is "If something sounds too good to be true, it probably is." When DLing programs, make sure that you have researched them, and the company/website it came from. Keep a record of this as well, and check your system often for signs of exploitation.

8. Social engineering:

This can, and often is combined with any of the above methods. Social engineering is really just exploiting people instead of SW. Social engineers use a variety of ways to trick someone into giving them the information they desire. These cons can be amazingly ingenious, professional and complex, or they can be ridiculously crude and almost laughable. Again, if you have doubts about the legitamacy of something or someone or something just seems strange don’t do it. Don’t give out sensitive information, period. You can always check up on a story or website later.

Be aware that these methods are simply the most common. These are not the only way for someone to get your PW. Unfortunatly, if someone wants something bad enough, they’re probably going to get it. At least by familiarizing yourself with these methods, you can recognize scams and potential attempts to steal your information and avoid it.

It is my hope that this article helps stop you from becoming a victim, and screws a slew of lamers and script kiddies into looking for another hobby.

Tuesday, September 7, 2010

What is Cyberstalking? Definition of Cyberstalking?

What is cyber stalking??


Cyber Stalking can be defined as the repeated acts harassment or threatening behavior of the cyber criminal towards the victim by using internet services. Stalking in General terms can be referred to as the repeated acts of harassment targeting the victim such as following the victim, making harassing phone calls, killing the victims pet, vandalizing victims property, leaving written messages or objects. Stalking may be followed by serious violent acts such as physical harm to the victim and the same has to be treated and viewed seriously. It all depends on the course of conduct of the stalker.

Both kind of Stalkers รข€“ Online & Offline – have desire to control the victims life. Majority of the stalkers are the dejected lovers or ex-lovers, who then want to harass the victim because they failed to satisfy their secret desires. Most of the stalkers are men and victim female.

How do they Operate

a. Collect all personal information about the victim such as name, family background, Telephone Numbers of residence and work place, daily routine of the victim, address of residence and place of work, date of birth etc. If the stalker is one of the acquaintances of the victim he can easily get this information. If stalker is a stranger to victim, he collects the information from the internet resources such as various profiles, the victim may have filled in while opening the chat or e-mail account or while signing an account with some website.

b. The stalker may post this information on any website related to sex-services or dating services, posing as if the victim is posting this information and invite the people to call the victim on her telephone numbers to have sexual services. Stalker even uses very filthy and obscene language to invite the interested persons.

c. People of all kind from nook and corner of the World, who come across this information, start calling the victim at her residence and/or work place, asking for sexual services or relationships.

d. Some stalkers subscribe the e-mail account of the victim to innumerable pornographic and sex sites, because of which victim starts receiving such kind of unsolicited e-mails.

e. Some stalkers keep on sending repeated e-mails asking for various kinds of favors or threaten the victim.

f. In online stalking the stalker can make third party to harass the victim.

g. Follow their victim from board to board. They “hangout” on the same BB’s as their victim, many times posting notes to the victim, making sure the victim is aware that he/she is being followed. Many times they will “flame” their victim (becoming argumentative, insulting) to get their attention.

h. Stalkers will almost always make contact with their victims through email. The letters may be loving, threatening, or sexually explicit. He will many times use multiple names when contacting the victim.

i. Contact victim via telephone. If the stalker is able to access the victims telephon, he will many times make calls to the victim to threaten, harass, or intimidate them.

j. Track the victim to his/her home.

Definition of Cyberstalking?

Although there is no universally accepted definition of cyberstalking, the term is used in this report to refer to the use of the Internet, e-mail, or other electronic communications devices to stalk another person. Stalking generally involves harassing or threatening behavior that an individual engages in repeatedly, such as following a person, appearing at a person’s home or place of business, making harassing phone calls, leaving written messages or objects, or vandalizing a person’s property. Most stalking laws require that the perpetrator make a credible threat of violence against the victim; others include threats against the victim’s immediate family; and still others require only that the alleged stalker’s course of conduct constitute an implied threat.(1) While some conduct involving annoying or menacing behavior might fall short of illegal stalking, such behavior may be a prelude to stalking and violence and should be treated seriously.

Nature and Extent of Cyber Stalking
An existing problem aggravated by new technology

Although online harassment and threats can take many forms, cyberstalking shares important characteristics with offline stalking. Many stalkers – online or off – are motivated by a desire to exert control over their victims and engage in similar types of behavior to accomplish this end. As with offline stalking, the available evidence (which is largely anecdotal) suggests that the majority of cyberstalkers are men and the majority of their victims are women, although there have been reported cases of women cyberstalking men and of same-sex cyberstalking. In many cases, the cyberstalker and the victim had a prior relationship, and the cyberstalking begins when the victim attempts to break off the relationship. However, there also have been many instances of cyberstalking by strangers. Given the enormous amount of personal information available through the Internet, a cyberstalker can easily locate private information about a potential victim with a few mouse clicks or key strokes.

The fact that cyberstalking does not involve physical contact may create the misperception that it is more benign than physical stalking. This is not necessarily true. As the Internet becomes an ever more integral part of our personal and professional lives, stalkers can take advantage of the ease of communications as well as increased access to personal information. In addition, the ease of use and non-confrontational, impersonal, and sometimes anonymous nature of Internet communications may remove disincentives to cyberstalking. Put another way, whereas a potential stalker may be unwilling or unable to confront a victim in person or on the telephone, he or she may have little hesitation sending harassing or threatening electronic communications to a victim. Finally, as with physical stalking, online harassment and threats may be a prelude to more serious behavior, including physical violence.