Showing posts with label hacking. Show all posts
Showing posts with label hacking. Show all posts
XSS vulnerability on Kevin Mitnick's website
Monday, March 12, 2012 // by Hacking Beast Editor //
Labels:
Cyber Security,
database,
hackers news,
hacking,
kevin mitnick,
XSS,
XSS vunerability
//
0
comments
Kevin Mitnick a well known name of the cyber world. He is also regarded as worlds one of the most popular hacker whose popularity is growing day by day. From our resources we have got this news which say Kevin Mitnik's website vulnerable to XSS
Vulnerable Link : http://mitnicksecurity.com/workshop_signup.php
Vulnerable Textbox : strEmail is not filtered some html tags in textbox
Method: Post
Example payload: /"><iframe onload=alert(document.cookie)>
The content on Hacking Beast like Hacking Articles, Cyber News etc are provided by many sources ( email,messages,internet etc) , we do not take any responsibility of your activities. The news provided by us on this site is gathered from various sources. if any person have some FAQ's in their mind they can Contact Us. and you can also read our Disclamier for more info. Thank You !
If you enjoyed Hacking Beast Articles , Make sure you subscribe to our RSS feed. Stay Updated about latest Hacking News, Tips and Tricks,and Cyber News.! and recieve all our emails and latest posts directly in your inbox to enjoy fast and easy reading . Thank You!What is Brute Force - Password cracking ?
Saturday, November 5, 2011 // by Hacking Beast Editor //
Labels:
Cyber Security,
hacking,
knodledge,
tips and tricks,
website hacking
//
0
comments
Brute force (also known as brute force cracking) is a trial and error method used by application programs to decode encrypted data such as passwords or Data Encryption Standard (DES) keys, through exhaustive effort (using brute force) rather than employing intellectual strategies. Just as a criminal might break into, or "crack" a safe by trying many possible combinations, a brute force cracking application proceeds through all possible combinations of legal characters in sequence. Brute force is considered to be an infallible, although time-consuming, approach.
Crackers are sometimes used in an organization to test network security, although their more common use is for malicious attacks. Some variations, such as L0phtcrack from L0pht Heavy Industries, start by making assumptions, based on knowledge of common or organization-centered practices and then apply brute force to crack the rest of the data. L0phtcrack uses brute force to crack Windows NT passwords from a workstation. PC Magazine reported that a system administrator who used the program from a Windows 95 terminal with no administrative privileges, was able to uncover 85 percent of office passwords within twenty minutes.
You must have seen in movies how a hacker cracks a password. He take out a small device from his pocket. Connect it to the locker or whatever he wants to crack and then lots of digits and alphabets are shuffled on the device’s screen and in a matter of minutes (and sometimes in seconds), the thing is unlocked. Pretty Impressive but it doesn’t happen that way. Basically a online system (by online system i means a system which requires you to log in to get access) can’t be hacked like that. Even a password stored in a offline file can’t be hacked so easily.
Lets take it as easy as it can get. You want to access a file which is password protected. You create a program that tries every possible combination of alphabets and numbers and then feed it to the file if its the right one. This procedure is repeated till the right combination is accepted by the file. This is what we call as a attack. And this very procedure of trying possible combinations is called Brute Force Attack.
Now executing such a program which is required to provide every possible combination requires a very good computing power. The time that it consumes in breaking a password depends on the length of password and the processor speed. Faster the processor, shorter the time it takes to crack the password. Think it would be easy if you have a dual core or quad core, Think again. On Desktop PCs it can take days to crack a password.
Memory Space Trade Off – It is a situation in which time taken for processing can be reduced at the cost of space and vice versa. To make it very clear, lets see this again with the help of an example. In the previous example, we can process the different combination before hand and then store them in a file. And when you need to break a password, combinations are retrieved from that file and this lessens the load on the processor. The only time consumption in this case is the retrieval of data from that file. This file is what is known as a Rainbow Table. It can break passwords in a few minutes and in even a few seconds depending how strong is the password. It can be obtained from the World Wide Web but beware of its size. Its size is in GBs.
Now even if a hacker has the best of hardware, he can’t hack that easily. Why? Ever entered a password wrong multiple times? It requires you to enter the image to confirm that you are a human and it is not a account and even if that fails (yes there are algorithms that can read the text behind the image), the user is forbidden to enter the password for a fixed amount of time. So, there is no way in hell that a hacker can hack by Brute force or even with the help of rainbow tables. But it surely gets the job done for offline files.
If I write more here in a single post, it would be difficult for many of us to analyze the information. So, more in coming ICA articles.But i am providing some most top used Brute force softwares,you can download them and use for testing purpose...
This pack includes the following fully workable softwares:
1.Attack tool kit
2.CrackWhore 2.0
3.Apache scanner
4.Brutus
5.Brutus 2006
6.CGI scan
7.crackftp
8.E-mail cracker
9.hackers utillity
10.php brutforcer
11.php BB pass extracter
12.php cracker
13.shadow scan
14.web crack 4.0
and a few more
Download link is not owned by Hacking Beast http://www.megaupload.com/?d=6GHU7XVB
The content on Hacking Beast like Hacking Articles, Cyber News etc are provided by many sources ( email,messages,internet etc) , we do not take any responsibility of your activities. The news provided by us on this site is gathered from various sources. if any person have some FAQ's in their mind they can Contact Us. and you can also read our Disclamier for more info. Thank You !
If you enjoyed Hacking Beast Articles , Make sure you subscribe to our RSS feed. Stay Updated about latest Hacking News, Tips and Tricks,and Cyber News.! and recieve all our emails and latest posts directly in your inbox to enjoy fast and easy reading . Thank You!Anonymous Threatened To Erase Toronto Stock Exchange (TSX) On November 7th
Sunday, October 30, 2011 // by Hacking Beast Editor //
Labels:
annonymus,
Cyber News,
hackers news,
hacking
//
0
comments
Anonymous, the hackivist collective, appear now to be backing down from the grandiose promise to "erase" the Toronto Stock Exchange from the Internet on November 7. The one per cent has been putting their wealth in the Toronto Stock Exchange. This is why we choose to declare war against it, says the literally anonymous Anonymous voice. “On November 7, 2011, TSX shall be erased from the internet". And this is just the beginning. Previously anon threatened to erase NYSE from the Internet though that attack failed. also Anonymous threatens to erase FOX News couple of days ago.
In a video release Anon Said:-
"WE HAVE PUT A STOP TO THE OPERATION DUE TO ALOT OF CITIZENS OF CANADA THAT ARE A PART OF THE 99% DID NOT AGREE TO THE OPERATION!
WE ARE TRULY SORRY AND WOULD LIKE YOU TO KNOW WE ARE WITH YOU, AND WE STAND BY YOU WITH YOUR OPINIONS; BECAUSE WE ALL HAVE A VOICE.THANK YOU."
Soure: Here
The content on Hacking Beast like Hacking Articles, Cyber News etc are provided by many sources ( email,messages,internet etc) , we do not take any responsibility of your activities. The news provided by us on this site is gathered from various sources. if any person have some FAQ's in their mind they can Contact Us. and you can also read our Disclamier for more info. Thank You !
If you enjoyed Hacking Beast Articles , Make sure you subscribe to our RSS feed. Stay Updated about latest Hacking News, Tips and Tricks,and Cyber News.! and recieve all our emails and latest posts directly in your inbox to enjoy fast and easy reading . Thank You!Xbox Live Accounts dumped by @DestructiveSec
Sunday, October 23, 2011 // by Hacking Beast Editor //
Labels:
Cyber News,
Cyber Security,
database,
defacements,
hackers news,
hacking,
New Releases
//
0
comments
A fairly new group, @DestructiveSec dumped a fair few xbox live accounts around about 11hrs ago, Enjoy, CTRL+F for quick search to make sure your account has not been compromised.
The content on Hacking Beast like Hacking Articles, Cyber News etc are provided by many sources ( email,messages,internet etc) , we do not take any responsibility of your activities. The news provided by us on this site is gathered from various sources. if any person have some FAQ's in their mind they can Contact Us. and you can also read our Disclamier for more info. Thank You !
If you enjoyed Hacking Beast Articles , Make sure you subscribe to our RSS feed. Stay Updated about latest Hacking News, Tips and Tricks,and Cyber News.! and recieve all our emails and latest posts directly in your inbox to enjoy fast and easy reading . Thank You!A message to the government of Nayarit Mexico, anonymous strikes again
Saturday, September 17, 2011 // by Hacking Beast Editor //
Labels:
annonymus,
Cyber News,
Cyber Security,
hackers news,
hacking
//
0
comments
Hackers have defaced the congress of mexicos website in one of the latest strikes on governments sites. the site which is now sporting an picture with a masked anon and some deface text.
The content on Hacking Beast like Hacking Articles, Cyber News etc are provided by many sources ( email,messages,internet etc) , we do not take any responsibility of your activities. The news provided by us on this site is gathered from various sources. if any person have some FAQ's in their mind they can Contact Us. and you can also read our Disclamier for more info. Thank You !
If you enjoyed Hacking Beast Articles , Make sure you subscribe to our RSS feed. Stay Updated about latest Hacking News, Tips and Tricks,and Cyber News.! and recieve all our emails and latest posts directly in your inbox to enjoy fast and easy reading . Thank You!3 Sites hacked and 3500+ Accounts Leaked by Cyb3rSec Crew
Tuesday, September 13, 2011 // by Hacking Beast Editor //
Labels:
Cyber News,
Cyber Security,
database,
hackers news,
hacking
//
0
comments
It would seem that Owner of thetvdb.com has been a target in the latest strike from Cyb3rSec Crew. They have dump a list of 3500+ Accounts from the forum and also have defaced his personal website as well.
Targets:
http://forum.thetvdb.com = Hacked and leaked data
http://zsori.com/ = Hacked and defaced
More Info : http://pastebin.com/pKUuyGfJ
The content on Hacking Beast like Hacking Articles, Cyber News etc are provided by many sources ( email,messages,internet etc) , we do not take any responsibility of your activities. The news provided by us on this site is gathered from various sources. if any person have some FAQ's in their mind they can Contact Us. and you can also read our Disclamier for more info. Thank You !
If you enjoyed Hacking Beast Articles , Make sure you subscribe to our RSS feed. Stay Updated about latest Hacking News, Tips and Tricks,and Cyber News.! and recieve all our emails and latest posts directly in your inbox to enjoy fast and easy reading . Thank You!TEAM T!g3R hack and leak data from 6 Sri Lanka Government sites
Thursday, September 8, 2011 // by Hacking Beast Editor //
Labels:
Cyber News,
Cyber Security,
database,
hackers news,
hacking
//
0
comments
The Sri Lanka government has been under attack a lot these past few weeks, with many division of the government being hacked and defaced and lots of the websites login data being leaked as well.
The most recent attacks leaves another six sites hacked and having its admin login leaked.
http://www.rpd.gov.lk
http://www.rgd.gov.lk/
http://www.publictrustee.gov.lk
http://www.languagescom.gov.lk
http://www.most.gov.lk
http://www.digitalhouse.lk/
The content on Hacking Beast like Hacking Articles, Cyber News etc are provided by many sources ( email,messages,internet etc) , we do not take any responsibility of your activities. The news provided by us on this site is gathered from various sources. if any person have some FAQ's in their mind they can Contact Us. and you can also read our Disclamier for more info. Thank You !
If you enjoyed Hacking Beast Articles , Make sure you subscribe to our RSS feed. Stay Updated about latest Hacking News, Tips and Tricks,and Cyber News.! and recieve all our emails and latest posts directly in your inbox to enjoy fast and easy reading . Thank You!Scan Open Ports/Services of Target: Netcat
Monday, September 5, 2011 // by Hacking Beast Editor //
Labels:
database,
ddos,
exploit,
hacking,
website hacking
//
0
comments
Prerequisites: None
Countermeasures: Uninstall/disable fix unnecessary services, Intrusion
Detection Systems (IDS) Log and Event Log review
Description: The netcat application has many uses; one is the ability to
scan a target for open ports and services. Another utility, cryptcat, is
almost identical except that it operates with encryption.
Procedure: From a DOS prompt, type the following with the syntax of:
nc
nc
_ The –v option instructs netcat to run in verbose mode, allowing you
to see the progress of the scan.
_ The –r option instructs netcat to randomize local and remote ports in
an attempt to elude any intrusion detection systems.
_ The –w2 option instructs netcat to wait 2 seconds between each port
scanned to help elude any intrusion detection systems.
_ The –z option instructs netcat to operate in a zero-I/O (Input/Output)
mode. It is best to use the –z when scanning with netcat.
_ The 1-1024 instructs netcat to scan port 1-1024.
to see the progress of the scan.
_ The –r option instructs netcat to randomize local and remote ports in
an attempt to elude any intrusion detection systems.
_ The –w2 option instructs netcat to wait 2 seconds between each port
scanned to help elude any intrusion detection systems.
_ The –z option instructs netcat to operate in a zero-I/O (Input/Output)
mode. It is best to use the –z when scanning with netcat.
_ The 1-1024 instructs netcat to scan port 1-1024.
In this example, the target has the following ports open:
_ 80 (Web)
_ 7 (Echo)
_ 13 (daytime)
_ 21 (FTP)
_ 17 (Quote of the Day)
_ 445 (Windows Share)
_ 9 (discard)
_ 139 (Windows Share)
_ 19 (Character Generator)
_ 135 (epmap)
_ 443 (HTTPS)
_ 25 (Simple Mail Transfer Protocol [SMTP])
_ 80 (Web)
_ 7 (Echo)
_ 13 (daytime)
_ 21 (FTP)
_ 17 (Quote of the Day)
_ 445 (Windows Share)
_ 9 (discard)
_ 139 (Windows Share)
_ 19 (Character Generator)
_ 135 (epmap)
_ 443 (HTTPS)
_ 25 (Simple Mail Transfer Protocol [SMTP])
Note: From the results of this example the “low hanging fruit” ports are:
_ 7, 13, 17, 9, and 19 as these ports can easily be used to create a Denial of Service (DoS). These ports should not be open to the Internet.
_ 7, 13, 17, 9, and 19 as these ports can easily be used to create a Denial of Service (DoS). These ports should not be open to the Internet.
The content on Hacking Beast like Hacking Articles, Cyber News etc are provided by many sources ( email,messages,internet etc) , we do not take any responsibility of your activities. The news provided by us on this site is gathered from various sources. if any person have some FAQ's in their mind they can Contact Us. and you can also read our Disclamier for more info. Thank You !
If you enjoyed Hacking Beast Articles , Make sure you subscribe to our RSS feed. Stay Updated about latest Hacking News, Tips and Tricks,and Cyber News.! and recieve all our emails and latest posts directly in your inbox to enjoy fast and easy reading . Thank You!400+ Accounts leaked by Herxode
// by Hacking Beast Editor //
Labels:
Cyber News,
Cyber Security,
database,
hackers news,
hacking,
website hacking
//
0
comments
400+ Accounts from an unknown website have been dumped on pastebin, this comes from a hacker calling them selfs Herxode.
Link of data : http://pastebin.com/GPsudYXG
The content on Hacking Beast like Hacking Articles, Cyber News etc are provided by many sources ( email,messages,internet etc) , we do not take any responsibility of your activities. The news provided by us on this site is gathered from various sources. if any person have some FAQ's in their mind they can Contact Us. and you can also read our Disclamier for more info. Thank You !
If you enjoyed Hacking Beast Articles , Make sure you subscribe to our RSS feed. Stay Updated about latest Hacking News, Tips and Tricks,and Cyber News.! and recieve all our emails and latest posts directly in your inbox to enjoy fast and easy reading . Thank You!TEAM T!g3R attack and hack 7 Sri Lanka Government websites, including the army
Sunday, September 4, 2011 // by Hacking Beast Editor //
Labels:
Cyber News,
Cyber Security,
database,
exploit,
hackers news,
hacking
//
0
comments

Earlier today TEAM T!g3R dumped a few databases and with images and information from a bunch of Sri Lanka government websites.
These sites are the army, micro finance, lawnet, nsf, Port authority, Business Online, Sunday times. This shows the range of sites that hackers will go for, pretty much anything that has a exploit or entry point for a hacker to do damage and leave there mark.
http://pastebin.com/wMjTzwvh
http://pastebin.com/drBwfngj
http://pastebin.com/p9YVkj4U
http://pastebin.com/htyxY8Dz
http://pastebin.com/ygfSmu3C
http://pastebin.com/C4z7QEit
http://pastebin.com/aTFWNgWj
http://pastebin.com/drBwfngj
http://pastebin.com/p9YVkj4U
http://pastebin.com/htyxY8Dz
http://pastebin.com/ygfSmu3C
http://pastebin.com/C4z7QEit
http://pastebin.com/aTFWNgWj
Also @CMDL1NE has hacked and leaked the database for Oldpcgames.co.kr.
The content on Hacking Beast like Hacking Articles, Cyber News etc are provided by many sources ( email,messages,internet etc) , we do not take any responsibility of your activities. The news provided by us on this site is gathered from various sources. if any person have some FAQ's in their mind they can Contact Us. and you can also read our Disclamier for more info. Thank You !
If you enjoyed Hacking Beast Articles , Make sure you subscribe to our RSS feed. Stay Updated about latest Hacking News, Tips and Tricks,and Cyber News.! and recieve all our emails and latest posts directly in your inbox to enjoy fast and easy reading . Thank You!Shadow 8 Hacked Geek Tech !
// by Hacking Beast Editor //
Labels:
Cyber News,
Cyber Security,
database,
hackers news,
hacking,
vulnerability,
website hacking
//
0
comments
Last night a Pakistani Hacker code name : "Shadow8" hacked a very reputed and high traffic website name "Geek Tech". Geek Tech is a very popular site known for their unique content on technology,cyber news and etc. the hacker hacked the whole site's database and exposed it and defaced the index of the website .
Attacked site : http://geektech.in/
Mirror: http://www.zone-h.com/mirror/id/14849209
The content on Hacking Beast like Hacking Articles, Cyber News etc are provided by many sources ( email,messages,internet etc) , we do not take any responsibility of your activities. The news provided by us on this site is gathered from various sources. if any person have some FAQ's in their mind they can Contact Us. and you can also read our Disclamier for more info. Thank You !
If you enjoyed Hacking Beast Articles , Make sure you subscribe to our RSS feed. Stay Updated about latest Hacking News, Tips and Tricks,and Cyber News.! and recieve all our emails and latest posts directly in your inbox to enjoy fast and easy reading . Thank You!














