Rabu, 04 Mei 2011

Password Cracking : What is Social Engineering | Hacking


This is one of the oldest techniques of hacking when a hacker takes advantage of trusting human beings to get information from them .
Social Engineering – Social engineering is when a hacker takes advantage of trusting human beings to get information from them ( like in the movie Hackers 1 if anyone has seen it. When the hero tries to take over a television network).
For example, if the Hacker was trying to get the password for a co-workers computer, he (Even though I use “he”, hackers are of both genders, and I just chose to use “he” in these examples.) could call the co-worker pretending to be from the IT department. The conversation could be something like:

Bob- “Hello Suzy. My name is Bob and I’m from the IT department. We are currently attempting to install a new security update on your computer, but we can’t seem to connect to the user database and extract your user information. Would you mind helping me out and letting me know your password before my boss starts breathing down my neck? It’s one of those days, ya’ know?”
Suzy would probably feel bad for Bob and let him know her password without any hesitation. BAM! She got social engineered. Now the hacker can do whatever he pleases with her account.
• Shoulder surfing – Shoulder surfing is exactly what it sounds like. The Hacker would simply attempt to look over your shoulder as you type in your password. The hacker may also watch weather you glance around your desk, looking for a written reminder or the written password itself.
• Guessing – If you use a weak password, a Hacker could simple guess it by using the information he knows about you. Some examples of this are: date of birth, phone number, favorite pet, and other simple things like these.
Now that we have the simple low-tech password cracking techniques out of the way, let’s explore some high-tech techniques. Some of the programs I will use in my examples may be blocked by your anti-virus programs when you attempt to run them. Make sure you disable your anti-virus program when you decide to download and explore them.
Now share this information and enjoy Learning Ethical Hacking.
And make sure you subscribe to how to hack it. :)
Read more »

Password Cracking : What is Social Engineering | Hacking


This is one of the oldest techniques of hacking when a hacker takes advantage of trusting human beings to get information from them .
Social Engineering – Social engineering is when a hacker takes advantage of trusting human beings to get information from them ( like in the movie Hackers 1 if anyone has seen it. When the hero tries to take over a television network).
For example, if the Hacker was trying to get the password for a co-workers computer, he (Even though I use “he”, hackers are of both genders, and I just chose to use “he” in these examples.) could call the co-worker pretending to be from the IT department. The conversation could be something like:

Bob- “Hello Suzy. My name is Bob and I’m from the IT department. We are currently attempting to install a new security update on your computer, but we can’t seem to connect to the user database and extract your user information. Would you mind helping me out and letting me know your password before my boss starts breathing down my neck? It’s one of those days, ya’ know?”
Suzy would probably feel bad for Bob and let him know her password without any hesitation. BAM! She got social engineered. Now the hacker can do whatever he pleases with her account.
• Shoulder surfing – Shoulder surfing is exactly what it sounds like. The Hacker would simply attempt to look over your shoulder as you type in your password. The hacker may also watch weather you glance around your desk, looking for a written reminder or the written password itself.
• Guessing – If you use a weak password, a Hacker could simple guess it by using the information he knows about you. Some examples of this are: date of birth, phone number, favorite pet, and other simple things like these.
Now that we have the simple low-tech password cracking techniques out of the way, let’s explore some high-tech techniques. Some of the programs I will use in my examples may be blocked by your anti-virus programs when you attempt to run them. Make sure you disable your anti-virus program when you decide to download and explore them.
Now share this information and enjoy Learning Ethical Hacking.
And make sure you subscribe to how to hack it. :)
Read more »

What are Rainbow Tables | md5 Encryption


Rainbow Tables
A Rainbow table is a huge pre-computed list of hash values for every possible combination of characters. A password hash is a password that has gone through a mathematical algorithm that transformed it into something absolutely foreign. A hash is a one way encryption so once a password is hashed there is no way to get the original string from the hashed string. A very common hashing algorithm used as security to store passwords in website databases is MD5 encryption.

Let’s say you are registering for a website. You put in a username and password. Now when you submit, your password goes through the MD5 algorithm and the outcome hash is stored in a database. Now since you can’t get the password from the hash, you may be wondering how they know if your password is right when you login. Well when you login and submit your username and password, a script takes your password and runs it through the md5 algorithm. The outcome hash is compared to the hash stored in the database. If they are the same, you are admitted.
If I were to run the word “cheese” through the md5 algorithm, the outcome would befea0f1f6fede90bd0a925b4194deac11. Having huge tables of every possible character combination hashed is a much better alternative to brute-force cracking. Once the rainbow tables are created, cracking the password is a hundred times faster than brute-forcing it. I will show an example of rainbow table cracking when we get into Windows password cracking.
I am sure it might have helped. To get the complete info do read my post on md5 encryption, Have given a hyperlink for it in the text.
Now share this information and enjoy Learning Ethical Hacking.
And make sure you subscribe to How To Hack It. :)
Read more »

What are Rainbow Tables | md5 Encryption


Rainbow Tables
A Rainbow table is a huge pre-computed list of hash values for every possible combination of characters. A password hash is a password that has gone through a mathematical algorithm that transformed it into something absolutely foreign. A hash is a one way encryption so once a password is hashed there is no way to get the original string from the hashed string. A very common hashing algorithm used as security to store passwords in website databases is MD5 encryption.

Let’s say you are registering for a website. You put in a username and password. Now when you submit, your password goes through the MD5 algorithm and the outcome hash is stored in a database. Now since you can’t get the password from the hash, you may be wondering how they know if your password is right when you login. Well when you login and submit your username and password, a script takes your password and runs it through the md5 algorithm. The outcome hash is compared to the hash stored in the database. If they are the same, you are admitted.
If I were to run the word “cheese” through the md5 algorithm, the outcome would befea0f1f6fede90bd0a925b4194deac11. Having huge tables of every possible character combination hashed is a much better alternative to brute-force cracking. Once the rainbow tables are created, cracking the password is a hundred times faster than brute-forcing it. I will show an example of rainbow table cracking when we get into Windows password cracking.
I am sure it might have helped. To get the complete info do read my post on md5 encryption, Have given a hyperlink for it in the text.
Now share this information and enjoy Learning Ethical Hacking.
And make sure you subscribe to How To Hack It. :)
Read more »

All about Computer Shutdown from Basics


Well Computer Shutdown is something I am sure everyone using a Computer would be aware of. It comes under the basic knowledge of a Computer but there are many things I am sure you don’t know about Shutdowncommand and I am exactly going to tell you the same..
The easiest way to shut down your computer is to type (shutdown –s) in to cmd “command” and that will give a message that “the computer will shutdown and you have 30 seconds”. But if you just type (shutdown -a) it will abort the shutdown but there are other commands. I will just start off doing the easiest ones.

shutdown –s
It will shutdown your computer in 30 seconds and display a message
shutdown –s –t 40
It will shutdown in 40 seconds but you can only go up to 86400 (24 hours) but if you make it 0 it will show no message and just shutdown
shutdown –s –c ”haha the computer is going to shutdown”
it will shutdown with a message in a box under the time
shutdown –l
It will just log you of the computer
shutdown -i
It will display the GUI shutdown window
shutdown –r
Will restart the computer
shutdown –a
it will abort the shutdown
shutdown –f
will force all running applications to close
I m not much confident about how to use (shutdown –d) so I just grab this of the net
-d [u] [p]:xx:yy
The reason code for the shutdown
u is the user code
p is a planned shutdown code
xx is the major reason code (positive integer less than 256)
yy is the minor reason code (positive integer less than 65536)
and now the fun stuff starts to begin if you still go to school or uney with the “-m” command
the –m command will let you shut down computers on the network and all you need is the ip address or the computer name (its found in the system info in the “computer name” tab)(right click on my computer and go to properties and you will see “computer name”)
once your have the ip or the computer name just type (shutdown –s –m \”ip/computer name” in to cmd but you can use all the command with it but you carnet use “-l” over the network it doesn’t let u
and now to turn it in to a file so who ever opens it, it will make the computer shutdown just type what ever you want the computer to do in to a notepad file and save it as a .bat file(go to save as and (what ever name u want) and type .bat at the end.
Now share this information and enjoy Learning Ethical Hacking.
And make sure you subscribe to How To Hack It. :)
Read more »

All about Computer Shutdown from Basics


Well Computer Shutdown is something I am sure everyone using a Computer would be aware of. It comes under the basic knowledge of a Computer but there are many things I am sure you don’t know about Shutdowncommand and I am exactly going to tell you the same..
The easiest way to shut down your computer is to type (shutdown –s) in to cmd “command” and that will give a message that “the computer will shutdown and you have 30 seconds”. But if you just type (shutdown -a) it will abort the shutdown but there are other commands. I will just start off doing the easiest ones.

shutdown –s
It will shutdown your computer in 30 seconds and display a message
shutdown –s –t 40
It will shutdown in 40 seconds but you can only go up to 86400 (24 hours) but if you make it 0 it will show no message and just shutdown
shutdown –s –c ”haha the computer is going to shutdown”
it will shutdown with a message in a box under the time
shutdown –l
It will just log you of the computer
shutdown -i
It will display the GUI shutdown window
shutdown –r
Will restart the computer
shutdown –a
it will abort the shutdown
shutdown –f
will force all running applications to close
I m not much confident about how to use (shutdown –d) so I just grab this of the net
-d [u] [p]:xx:yy
The reason code for the shutdown
u is the user code
p is a planned shutdown code
xx is the major reason code (positive integer less than 256)
yy is the minor reason code (positive integer less than 65536)
and now the fun stuff starts to begin if you still go to school or uney with the “-m” command
the –m command will let you shut down computers on the network and all you need is the ip address or the computer name (its found in the system info in the “computer name” tab)(right click on my computer and go to properties and you will see “computer name”)
once your have the ip or the computer name just type (shutdown –s –m \”ip/computer name” in to cmd but you can use all the command with it but you carnet use “-l” over the network it doesn’t let u
and now to turn it in to a file so who ever opens it, it will make the computer shutdown just type what ever you want the computer to do in to a notepad file and save it as a .bat file(go to save as and (what ever name u want) and type .bat at the end.
Now share this information and enjoy Learning Ethical Hacking.
And make sure you subscribe to How To Hack It. :)
Read more »

What is Batch Programming and need for it


As I Promised the Fans of how to hack it that I am going to start with Batch Programming week, I am exactly doing the same. From now on I am going to write a new post on Batch Programming in every 2-3 days so stay connected , stay updated and read all the material in continuity to get the most out of it.
In case you havn’t  subscribed to how to hack it. till now you can do the same now to get updates of my upcoming posts through mail.

Batch Programming :-
Batch file programming is nothing but a batch of DOS ( Disk Operating System ) commands, hence the nameBatch programming . If you are into coding and know many languages you might have noticed that Operating System ( OS ) specific languages ( languages that work only on a particular operating system, eg: Visual Basic Scripting works only in Windows ) give you amazing control over the system. This is why Batch is so powerful, it gives you absolute control over DOS. Batch isn’t often used because it is OS specific, but it is fun and easy to learn. A well-conceived batch file is just the thing to automate the job you want to do.
Batch Files are stored with .bat extension.
To create a batch file follow the following steps..
1) Goto-> Notepad
2) Type Whatever you want ( the code you want to enter)
3) Goto-> Save as
4) Change the file type to all files and folder
5) name the file as anything you want with the extension .bat ,For eg…(“learnhacking.bat”)
I know this was not enough. But this was just the introduction part for beginners. I am sure it might have helped atleast someone. In My next post we will discuss various batch commands and code our first BATCH PROGRAM.
I hope you liked it, if you want more then make sure you subscribe to how to hack it.:)
Read more »

VISITORS

Flag Counter