Showing posts with label Hacking. Show all posts
Showing posts with label Hacking. Show all posts

Tuesday, 16 May 2017

What is Ransomware wanna cry ? Its Attack And Prevention

Meaning :-

Ransomware is a type of malicious software that carries out the cryptoviral extortion attack from cryptovirology that blocks access to data until a ransom is paid and displays a message requesting payment to unlock it. Simple ransomware may lock the system in a way which is not difficult for a knowledgeable person to reverse. More advanced malware encrypts the victim's files, making them inaccessible, and demands a ransom payment to decrypt them. The ransomware may also encrypt the computer's Master File Table (MFT) or the entire hard drive. Thus, ransomware is a denial-of-access attack that prevents computer users from accessing files since it is intractable to decrypt the files without the decryption key. Ransomware attacks are typically carried out using a Trojan that has a payload disguised as a legitimate file.

Attack :-

On 12 May 2017, WannaCry began affecting computers worldwide.The initial infection might have been either through a vulnerability in the network defenses or a very well-crafted spear phishing attack. When executed, the malware first checks the "kill switch" domain name.If it is not found, then the ransomware encrypts the computer's data, then attempts to exploit the SMB vulnerability to spread out to random computers on the Internet, and "laterally" to computers on the same network.As with other modern ransomware, the payload displays a message informing the user that files have been encrypted, and demands a payment of around $300 in bitcoin within three days or $600 within seven days.

Organizations that lacked Microsoft's security patch to Windows were affected by the attack, although there is so far no evidence that any were specifically targeted by the ransomware developers.Initially, any organization still running the older Windows XPwas at particularly high risk because no security patches had been released since April 2014 (with the exception of one emergency patch released in May 2014). However, after the outbreak, Microsoft released a security patch for Windows XP on 13 May 2017, the day after the attack launched.

According to Wired, affected systems will also have had the DoublePulsar backdoor installed; this will also need to be removed when systems are decrypted.

Ken Collins of On 12 May 2017, WannaCry began affecting computers worldwide. The initial infection might have been either through a vulnerability in the network defenses or a very well-crafted spear phishing attack.When executed, the malware first checks the "kill switch" domain name.If it is not found, then the ransomware encrypts the computer's data, then attempts to exploit the SMB vulnerability to spread out to random computers on the Internet, and "laterally" to computers on the same network.As with other modern ransomware, the payload displays a message informing the user that files have been encrypted, and demands a payment of around $300 in bitcoin within three days or $600 within seven days.

Organizations that lacked Microsoft's security patch to Windows were affected by the attack, although there is so far no evidence that any were specifically targeted by the ransomware developers. Initially, any organization still running the older Windows XP was at particularly high risk because no security patches had been released since April 2014 (with the exception of one emergency patch released in May 2014).However, after the outbreak, Microsoft released a security patch for Windows XP on 13 May 2017, the day after the attack launched.

According to Wired, affected systems will also have had the DoublePulsar backdoor installed; this will also need to be removed when systems are decrypted.

Ken Collins of Quartz wrote on 12 May that three or more hardcoded bitcoin addresses, or "wallets", are used to receive the payments of victims. As with all such wallets, their transactions and balances are publicly accessible even though the wallet owners remain unknown. To track the ransom payments in real time, a Twitterbot that watches each of the three wallets has been set up. As of 15 May 2017 at 7 PM, a total of 220 payments totaling $59,747.53 had been transferred.

 wrote on 12 May that three or more hardcoded bitcoin addresses, or "wallets", are used to receive the payments of victims. As with all such wallets, their transactions and balances are publicly accessible even though the wallet owners remain unknown. To track the ransom payments in real time, a Twitterbot that watches each of the three wallets has been set up. As of 15 May 2017 at 7 PM, a total of 220 payments totaling $59,747.53 had been transferred.

How to defend against the ransomware

The vulnerability does not exist within Windows 10, the latest version of the software, but is present in all versions of Windows prior to that, dating back to Windows XP.
As a result of Microsoft’s first patch, users of Windows Vista, Windows 7, and Windows 8.1 can easily protect themselves against the main route of infection by running Windows Update on their systems. In fact, fully updated systems were largely protected from WanaCrypt0r even before Friday, with many of those infected having chosen to delay installing the security updates.
Users of Windows XP, Windows Server 2003 and Windows 8 can defend against the ransomware by downloading the new patch from Windows.All users can further protect themselves by being wary of malicious email attachments, another major way through which the ransomware was spread.

A of Microsoft’s security response team, Phillip Misner, wrote: “We know that some of our customers are running versions of Windowsthat no longer receive mainstream support.

“That means those customers will not have received the … Security Update released in March. Given the potential impact to customers and their businesses, we made the decision to make the Security Update for platforms in custom support only, Windows XP, Windows 8, and Windows Server 2003, broadly available for download.”

Source : Wikipedia

Thursday, 14 February 2013

HOW TO HACK FACEBOOK ACCOUNTS


        
Facebook now a days paying millions of dollars to security masters & experts to keep the privacy of their users secure. Therefore hacking facebook accounts is impossible by using direct methods like brute-forcing and dictionary attacks. There are many method to hack facebook accounts like cookie stealing, phishing and keyloggers! But today I am going to make another article on facebook hacking and hijacking someone's account by victims's Account Recovery Method. This method is latest and secure, however in this method you will learn how to hack facebook accounts using account recovery method. So in this method you need to have your victim's facebook email, if you dont know learn how to get emails of your facebook friend from my previous article.

FACEBOOK MALWARE AND COUNTERMEASURES IN A NUTSHELL




Social media’s history precedes the 21th century and ever since then malevolent people have attempted to infiltrate the computers of innocent people using these media in hope of 
  1. Obtaining sensitive information such as bank details and personal information, 
  2. Using the machine as a bridge in major cyber-attacks
  3. Impersonating you and using your account for their own ends,
  4. Installing some form of adware on your computer and bombarding your machine with endless pop-up ads, spreading spam through your computer for material gains, deceiving you to fill out a survey or by any other means try to acquire financial resources and transmitting the virus to more people via your machine with the hope of multiplying their material gains,
  5. Retaliating, gaining fame or proving that they can infiltrate someone’s machine or/and spreading the virus to a lot of people for the same reasons.

Tuesday, 12 February 2013

LEARN TO HACK FACEBOOK THROUGH THIS COURSE



Facebook is the most popular Social-Media site the whole world with Millions of users. From security point of view it is also the site which is most targeted by the Hackers and every day thousands of Account are Hacked by the Black-Hat Hackers. Not so many people know about the Hacking techniques and fall prey to the Hackers.
This Course is Facebook Hacking Course that is made by Abdul Rafay Baloch an ethical hacker and Blogger from Pakistan. He have took his time and expertise in making this Hacking course that dells with the user who is absolute beginner to hacking and know nothing about hacking. It is from A to Z. 


Monday, 11 February 2013

HOW TO SPAM SOMEONES WALL ON FACEBOOK. [WORKING WAY!]




It is really annoying if your Facebook Wall is full with many messages. Recently I found the way of doing it and now i am sharing it with you people ;)

It is really easy to do it. All you need to do is to follow the following steps carefully.

#Step1: First you need to be on "http://" connection instead of "https://", so simple Login into your FB account and goto Account > Account Settings > Account Security. Over there "unTick" |Secure Browsing (https)|

Sunday, 10 February 2013

HOW TO HACK A COMPUTER BY JUST IP ADDRESS


Hacking a remote computer is always a hot topic among hackers and crackers, a newbie hacker or someone who wants to learn hacking always ask these questions that how to hack into a computer by just knowing the IP address. Although we have discussed so many methods before and I always insist to learn some basic commands, protocols and their usage. This is my story like I have hacked into a remote by just using IP address (I have not downloaded any file even I have not cleared the logs). This story was not planned it just happened and I am sure you will like it and you will learn a lot of things if you don't know the basic commands and protocols.


Saturday, 9 February 2013

HOW TO KNOW SOMEONES FACEBOOK EMAIL


Hello Everyone! This is Ayush , I have updated many Tips on hacks and stealing friends Email & password So, Today i am going to make another article on stealing your facebook friend's email. Usually Some friends use to hide their Emails from their facebook information, because of the Phishing and Hacking Privacy. But Now i will tell you some of the steps to find their email, of facebook account. This method would be only done if your account is on Yahoo for example :- account@yahoo.com So, lets start the ways to get your friend's emails secretly and securely! On the whole world wide web, Yahoo only provides this service to import contacts from facebook, so this will only done on yahoo account, rest of the others can make another account on yahoo and then could signup to facebook for finding the emails. So, Now from this you can find their information. Or you can hack by emails.


HOW DO HACKERS CRACK YOUR FACEBOOK PASSWORD ?



You might be very happy right now because of the availability of high speed Internet, but when you get to encounter hackers, everything seems to become frustrating. Your personal information gets stolen and social media accounts like Facebook get invaded. Hackers are definitely a huge disturbance. They’re not merely robbers, but killers to the connection as well. They can spread viruses that consume a huge part of your bandwidth. They are among the reasons why even ahigh speed internet becomes sluggish.

Thursday, 7 February 2013

Tech Guru ~ FACEBOOK HACKING




Today I'm gonna show you How To Hack Facebook Account?, I am not a professional hacker, but i do hacking as a hobby, I am a professional SEO experts, tech blogger. This is the latest phishing trick for hacking facebook accounts, there is not a single post on the internet which describes this method. We are presenting this method after a lot of hardwork. This method will give you the victim's usernames and passwords straight into your mailbox. This method is the most easiest in which you have to sittight and enjoy hacking! Here we Go! 


Wednesday, 6 February 2013

HOW TO PROTECT YOUR COMPUTER FROM SPYWARES AND KEYLOGGERS



I HAVE  been writing articles on How to hack remote computers using key-loggers, spy-wares etc, One of my blog readers requested me to write a tutorial on how to protect your PC from key loggers and spy wares, So in today's post i will explain some of the best ways by which you can protect your computers from Spywares and Key loggers






Tuesday, 5 February 2013

HOW TO HACK FACEBOOK ACCOUNTS IN 2013



Every day i get lot of comments and  emails asking questions related to Facebook Hacking, I get tired and frustrated answering the same questions every single day, So to make life easy  for me and my blog readers  today i will share the best and successful ways by which you can hack a face book Account in 2013


Is it Possible To Hack Any FaceBook Account ?
Yes! As a matter of fact, almost anything can be hacked. But before you learn the real ways to Hack Facebook account, the following are the things you should be aware of

1. There is no ready made software that can Hack Facebook Accounts and get you the password with just a click of a button. So if you come across any website that claims to sell such software's, I would advise you not to trust them.

2. Never trust any email hacking service that claims to hack any email for just $100 or $200. Most of them are no more than a scam.

With my experience of over 4 years in the field of Hacking and Security i can say the following are the successful methods by which You can hack a Facebook Account in 2013


How To Hack Facebook Accounts In 2013 - Top 5 Ways
Keylogging 
Difficulty -  Easy
Success Rate - 90 %
Key logging is one of the Easiest ways that you can use to Hack Face book Accounts. (Keylogging or keylogger) sometimes called a spying software is a small program which is used to monitor a local or a Remote PC, When a keylogger is installed on a victims computer it can monitor and capture each and every keystroke typed on the victims PC,the captured Keystrokes are sent to the Hacker.

No doubt, these keystrokes contain the victim’s Face book Account Password and other such credential data thus key logger can be used for many purposes such as monitoring, Hacking and many more




Phishing
Difficulty - Moderate
Success Rate - 70 %

Phishing is an attempt to criminally and fraudulently acquire sensitive information, such as user names, passwords and credit card details, by appearing as a trustworthy entity . There are many Ways by which a hacker can craft his Phisher (Fake Page) to fool the victim. In a simple phishing attack a Hacker will create a phisher ( fake login page) which exactly looks like the real facebook page and then asks the victim to login into that page, 

Once the victim logins through the fake page the victims "Email Address" and "Password" is stored in a text file, The hacker then downloads the text file and get's his hands on the victims credentials. I have explained a step by step phishing process to Hack Facebook account  in the following Post
Mobile Phone Hacking
Difficulty - Easy
Success Rate - 90 %

Many users access Facebook from their smart Phones. If you have access to the victims Mobile phone, You can easily install a Cell phone spying software and thus you can easily hack , Monitor the victims Facebook Account .Today there are Many Cellphone Spying  software's, Some of the Best are listed below



1. Mspy
2. Spy Phone Gold


Session Hijacking
Difficulty - Moderate
Success Rate - 70 %

Session Hijacking can be often very dangerous if you are accessing Facebook on a http:// connection, In a Session Hijacking attack a hacker steals the victims browser cookie which is used to authenticate a user on a website and uses to it to access victims account, Session hijacking is widely used on Lan's. I will soon be writing a tutorial on how to hack facebook Account by session Hijacking.


Side Jacking Using Fire Sheep
Difficulty - Moderate
Success Rate - 60 %


Fire sheep is widely used to carry out side jacking attacks, Fire sheep only works when the attacker and the victim is on the same wifi network or in LAN .Fire sheep is an extension developed by Eric Butler for the FireFox web browser. The extension uses a packet sniffer to intercept unencrypted cookies from certain websites (such as Facebook and Twitter) as the cookies are transmitted over networks, exploiting session hijacking vulnerabilities.

It shows the discovered identities on a sidebar displayed in the browser, and allows the user to instantly take on the log-in credentials of the user by double-clicking on the victim's name. I will soon be writing a tutorial on how to hack facebook Account BY Firesheep

Hope you Enjoyed reading the article , If you have any doubts Regarding the article