Next
Previous
Showing posts with label Backtrack. Show all posts

Saturday, 23 November 2013

0

How to Install Flash Player v11 on Backtrack Linux 5r3

Posted in

                            Backtrack Linux is one of the most used Operating System by Hackers and some of very important Hacking tools on Backtrack requires Flash player to run example Nessus etc.. Flash player usually works correctly over 32 bit Linux but there are lot of issues while installing Flash player on 64 bit. We all know that recently all processors support 64 bit operating system reason is simple efficient processing, higher ram support and long ALU's and much more. Today i am teach you how to install Flash Player v11.x.x on Backtrack Linux 5r3 or any 64 bit Linux GNOME. As we all know 64 bit versions of software's are still not perfect to use, reason for 64 bit versions to work perfectly on PC or laptop machines it requires all processors and motherboard buses to support 64 bit and practically its not still the case because technology is still too costly and only high end Laptops supports it. None of Laptop manufacturer and assembling companies gives peoples assurance that 64 bit Operating Systems will run perfectly without software glitches. So for better performance, its still considered that we should install 32 bit versions of all such conflicting software's for example Flashplayer, Shockwave player etc. Lets learn how to install 32 bit Flash player over Backtrack Linux 5r3.



Backtrack Linux comes with pre installed Flash player version but that does not works correctly, so in order to correct this issue first of all we need to remove the existing copy of the Flash player installed on Firefox. 

Step 1 : Open the terminal in the Backtrack Linux and run the below commands in the terminal in order to remove the pre installed Flash Player.

aptitude purge flashplugin-nonfree flashplugin-installer gnash gnash-common mozilla-plugin-gnash swfdec-mozilla

rm -f /usr/lib/firefox/plugins/libflashplayer.so

rm -f /usr/lib/mozilla/plugins/libflashplayer.so

rm -f /usr/lib/mozilla/plugins/flashplugin-alternative.so

rm -f /usr/lib/mozilla/plugins/npwrapper*flash*so

rm -f ~/.mozilla/plugins/*flash*so


Note aptitude purge command will remove files, dependencies, and configurations, while the latter removes files and dependencies. This removes the existing Flash Player.

Step 2 : In this step, Kill all the instances of Firefox over the Backtrack Linux. We can kill all the instances of Firefox by running below command in terminal:

killall -9 /opt/firefox/firefox-bin

Step 3 : In this step we will install latest Flash player over Backtrack Linux. We are using wget in terminal here, but if Adobe changes the download link, please change the command accordingly, or just download the Flash installer from their website. We will be using wget in the following:

wget fpdownload.macromedia.com/pub/flashplayer/updaters/11/flashplayer_11_plugin_debug.i386.tar.gz
Now run the below commands in the terminal to install:

tar xvzf install_flash_player_11_linux.i386.tar.gz

mkdir ~/.mozilla/plugins

mv libflashplayer.so ~/.mozilla/plugins/

Then just delete everything else that got extracted. You should be good to go, and Nessus should be running fine. 

That's all! Now enjoy all the software's over Backtrack Linux that requires Flash Player. 

Hope you all enjoyed! If you face any issues contact us by writing comments below.



Friday, 22 November 2013

1

5 Rated WiFi hacking adapters for hacking with Backtrack, Beini 1.2.3 etc.

Posted in


Ever wonder which wireless adapter to purchase when you want to inject packets using your favorite tool?…e.g.Backtrack 5R2, Beini 1.2.3 and so on. I will rate a few adapters on a scale of 1-10, 10 being the best and 1 the worst on an general overall rating based on actual signal reception and on speed of packket injection. Don’t expect a detailed professional description as I am NOT technician. Only an ordinary person just to give out my honest opinion of adapters I have purchased and tested using Backtrack 5R2.
I personally have tried a few of them out and have found some pretty interesting facts. One, american made adapters are NOT the best and they tend to have a weak signal reception. Not necessarily american made but, products that are in the american market and that you would find in your local Walmart, Target, Kmart or whichever store you would find electric devices.
  The TL-WN822N from TP LINK High Gain USB Adapter is a 300Mbps wireless client, which allows users to connect a desktop or notebook computer to a wireless network and access a high-speed Internet connection. It is fully interoperable with IEEE 802.11 b/g/n wireless devices, delivering speedy 11n speeds and reliable signal for lag-free online gaming, Internet calls or even HD video streaming.(source) $25U.S.

In  it you will find the ATHEROS AR7010 and AR9287 (source) This beautiful white adapter has looks and compatibility but, what it has in looks lacks in performance. With it’s dual 3 bdi antennas it delivers little power only increasing about 10% at most, it will certainly disappoint you. So, when it comes to trying out packet injectiion you really can’t expect much. Certainly the manufacturer gives a beautiful and attractive description. You will not hear or see them describing their product as “the worst”, so always do a bit of research on it first.

RATING: 4

So moving on, next on the list is one that I purchased due to it’s high power description and eye-catchig device. They too made a claim of it being “the best”.Here’s their description of it:
   C. Crane US3 Super USB Wifi Antenna 3 his is one of the best home, mobile, or RV WiFi Antennas made. Just plug it into the USB port on your computer for powerful WiFi reception. We have incorporated the newest WiFi wireless “N” technology with a connection rate up to 150Mbps for lightning fast file transfers.
This antenna comes with a special USB split cable that offers two plugs to your computer to increase power. Normally one plug works well for a powerful reception. If you need more powerful reception and you have an extra USB port, then plug both into your computer. $100.00


 Antenna Gain:  4.5 dBi
 Chipset Gain: 25 dBm

It mounts easily to your window with suction cups or to the wall using the supplied lanyard and “hook and loop” material. If you are trying to receive a far away signal from outdoors, then the best place for mounting is above the peak of your roof so that signals can be received from miles in every direction. This antenna is made weatherproof, while bouncing harmful UV rays. A standard 15-foot split USB cable is included but you can purchase an optional 30-foot USB cable to reach the peak of your roof. Outdoor mounting is easy with the included cable-tie to secure the antenna to your plastic pole.
While testing it in the small town of Fortuna, California, we were able to see more than 25 different wireless networks and even connect to one over a mile away! Normally, we could only see about 6 networks within range. In further tests we were able to connect to a small wireless router from over 100 yards away, keeping 80% signal strength through several walls and obstructions. You may be surprised at what the Super USB WiFi Antenna 3 can do for you.

But when it comes down to the real thing, a real opinion, here goes mine. As a signal reception device it does pretty good put signal is not stable. It tends to drop and rise, drop and rise..but when it comes to packet injection..this baby is pretty damm good…Signals that are weak, using this and combination of Backtrack 5R2 will get you cracking in no time…I recommend it only for packet injection. But it will create a dent in your wallet.
RATING: 8
Another WiFi adapter I tested is the Kasens 990WG 60dbi 6000mw..one word I could say about this adapter “CRAP”…Though it claims to be a high power adapter, there is nothing high power about it. It only detected one WiFi signal while my surroundings is infested by WiFi..I was disappointed by the flat panel high gain antenna.. $21

In it you will find the 3070 chipset from Ralink, not as good as the 8187 but I did something that made the bad be a good, instead of screwing in the flat panel antenna to the adapter I screwed in a regular 5 dbi antenna, so it looked like the one below. Once I did that the signal increased tremendously! It could have been the flat panel antenna part that was defective but with the little alteration I made on it the rating went up.

So bottom line is this: the adapter is good but, the antenna is not..so I will give 2 different ratings, one with the flat panel antenna and the other with the regular antenna.
RATING w/flat panel: 1
RATING w/regular antenna: 7

                                     
Moving on to the next contender, well known ALFA AWUS036H 1000mW Long-Range with Realtek RTL8187L. “The ALFA AWUS036H is by far the best wireless usb device used for hacking and wireless penetration testing. Here at Top-Hat-Sec, it is the only WI-FI USB Adapter worth selling. It is our number one pick! It has the unique ability to be modified, adjusted for signal strength, and accessorized with other antenna’s and accessories.” according to top-hat-sec.com
7dbi antenna
5dbi antenna

Alfa AWUS036His one of the best Wi-Fi cards available in the market. There are many cheap solutions but their reliability is always questionable. At $28, it just doesn’t have any competition. It performs way better than the inbuilt Wi-Fi cards in the laptops. It functions nicely with Win98SE/200/ME/XP, Windows Vista, Windows 7, Linux and Macintosh (OS version 10.4). And the required drivers for ALL of these operating systems ships with the CD-ROM. The drivers are also available at vendor’s site. (This card is one of the best card for Wi-Fi hacking, wardriving and Penetration testing.It comes with a 5 dbi antenna which is detachable. The same manufacturer produces 7 dbi and 9 dbi antenna also. They cost around $8-$10. So if we want increase the range, we can remove the 5 dbi antenna and put the 9 dbi one. This Alfa card has amazing 1000mW output power. We can use Alfa AWUS036H for many purposes. E.g. if we want get a better signal strength at a place where it is difficult to get signals through inbuilt Wi-Fi cards in laptop, we can use it. We can combine it with Alfa r36, and make our own mini hotspot in our house. We can use it for wardriving. Packet injection works fine. Itcan use USB 2.0 as well as USB 1.1. It connects with full 54 Mbps. For security it has WEP, WPA and WPA2 (personal as well as enterprise) My personal opinion, this is the best adapter for war driving, hacking, pentesting or however you wish to call it. No problems injecting packets or associating as a client. Two thumbs up!

Friday, 1 November 2013

0

Remote system hacking By USB

Posted in ,

Hack PC by Using A USB.



Today we are going to do a remote hacking using a malicious file created in Backtrack,All then you will have to do is Plug in the USB,wait for 5 seconds,and plug it out,Then you will have control over the victim PC.This trick created a Mass Panic in Pentagon as it hacked most of their PC.Hack PC's on your School or University and have Fun.
Don't Abuse this Trick.You are responsible for your actions.

What Do We Need ?


#Backtrack 5
#Vulnerable Software On Victim PC,(read below)
#Physical Access For 10 Seconds.
#Patience and Brains.

Creating The Malicious Batch File :



#Step 1 -


Open Backtrack,Go to The Social Engineering Toolkit by entering the below commands in Konsole :
cd /pentest/exploits/set
./set

#Step 2 -


Select the Social-Engineering Attacks by entering 1.


#Step 3 -


Select Infectious Media Generator by selecting inserting 3,This option will help you create an autorun.nf file that will hack the vulnerable software.

#Step 4 -


Select 1st option,This will help you to select a specific software to exploit.

#Step 5 -


Now a list comes up with name of software's to exploit,this is the real deal.Now select the software you know is running on Victim Machine/'s,Adobe Reader and Microsoft Word is the most common software's used in school,so i will select option 11.

#Step 6 -


Now you have two options,Get a pc-generated blank pdf file or create your own,We'll select to create our own file,Now enter the path to pdf file  as /home/exam-sheet.pdf .The file name as exam-sheet.pdf
(EVIL LAUGH,Cause i'm going to attack school) you can set another file name.

#Step 7 -


Now select option 2 for windows/meterpreter/reverse_tcp.

#Step 8 -


Now you need to insert the IP Address for listener,Listener is another term for attacker,Insert your Public IP address (or internal IP address if you are hacking a PC on your LAN),and port as 80,then Press enter.

#Step 9 -


Here we need to edit the autorun.inf  file. Go to the directory of autorun where our both files : payload file & autorun file are located.
follow the following steps to edit & rename our files :
#open new terminal and type :
            ls -al /pentest/exploits/set/autorun/
we can see two files here one is autorun file and other is template.
#Now go to the directory:
         cd /pentest/exploits/set/autorun
.#Type "nano autorun.inf" (it will open a nano editor for editing autorun.inf file.Here give the name of your file which you want to open by plugin the USB here.For me,i Insert the name exam-sheet.pdf)
#Copy these both files on the USB drive.

#Step 10 -


Keep the attacker computer running,and when you will plug-in the USB drive in your victim PC,you will have a meterpereter season opened on your (attacker) Computer.Now you can steal files,commence a remote shutdown and much more.
YiPPiE !!!
0
Posted in


Stealing Files,Downloading Keystrokes,Controlling Webcam from remote Locations,ETC by Armitage.





Armitage is an GUI Platform for Metaspoilt and in technical terms,it is a script-able red team collaboration tool for Metasploit that visualizes targets, recommends exploits, and exposes the advanced post-exploitation features in the framework.It saves time and is very powerful in commencing Metaspoilt attacks.



So Now about our attack today : 

What Do We Need ?

Latest Metasploit framework.
Oracle Java 1.7
Preferably Internet on LAN
Brains and Patience.

Now Lets Us Start Our Hack Today.

Step 1 -Open armitage on Backtrack 5:


By Going To : Backtrack > Exploitation Tools > Network Exploitation Tools > Metasploit Framework > armitage.

Step 2 : Connect Armitage:


Click on the connect Button .

Step 3 : Connecting Armitage :


Now use the patience part,and stretch your legs,it takes some time to connect.

Step 4 :  Armitage Window :


It has 3 Panels -
Target Panel 
Module Panel
Tabs Panel 

Step 5 : Finding the alive host on the Network :


Now you will search for Host on you network,By Going to Hosts -> Nmap Scan -> Quick Scan (OS detect).This will perform a quick scan to detect the host and their operating systems and vulnerabilities.

Step 6 : Inputting The Scan Range :


Now You have to insert scan range,that is you LAN ip range,Most preferably it would start with 192.168.0.- or 10.0.0.-.NOTE : the ( - ) resembles the computers on LAN.
Start the Scan.

Step 7 : Scan Complete:


After the scan has completed,if their are any other PC's on your network on,then they would be visible in the Target Pane (the Big Black box on the upper right).

Step 8 : Finding Attacks :


Now the Fun Parts starts,Click on Attacks tab in your toolbar and select Find Attacks (Not hail mary,you might not be ready for that).Start the scan and wait till it completes.

Step 9 : Set the vulnerability :


Right Click on the Host icon (windows pc) -> Select attacks -> smb -> ms08_067_netapi  vulnerability . 
Now a window should pop,Click on the check-box that says "Use  a reverse connection" .
Start Attack

Step 10 : The Final Result :



So did the Host Icon Turn Red ? That Means YOU PASSED.


So You Did The Hacking Part Right,Now let us mess with the client.

Hack 1 - Opening Command Prompt :


Right click on the host -> Meterpreter1 ->Interact -> Command Shell 
Now You are In Their Command Prompt,You can now change,rename,delete,create files on their pc now.Search Google for some powerful windows commands.

Hack 2 - Start an KEYLOGGER :


Click on the Meterpreter2 -> Explore -> Log Keystrokes.
Now you will receive what the victim is typing.

Hack 3 - Take An Screen Shot :


Click on the Meterpreter2 -> Explore ->Screenshot.
Now you can see what is on their Facebook wall or Google mail accounts.

Hack 4 -Browse Files :


Right click -> Meterpreter2 -> Explore > Browse Files .
Now you can interact with all the files on victim PC via a GUI.

Hack 5 - Get in His Webcam (my favorite part).


Right click -> Meterpreter2 ->Explore -> Webcam shot
Catch that guy making out ,and have fun with him later.

1

SMS spoofing on BACKTRACK 5

Posted in ,

Welcome,In this, my post on mobile hacking,In this post,We are going to create any mobile number (police,fire department,ex-girlfriends,etc) and send messages,Sure this method has only 75%success rate,but it works like a charm for the most time.In spoofingattack the attacker (you)  make himself a source or desire address.This post is only for education purposes,and this trick can be traced back to the source very easily,So don't create a scene.



So What Do WE Need :

#SET-Social Engineering Toolkit, Available On Backtrack. 
#Brain-To Sense what is wrong and what is right,And to follow this procedure.

Step 1 :

Open "Social Engineering Toolkit" in Backtrack 5 (mine OS)  by Opening your backtrack console & Typing 

cd /pentest/exploits/set

Step 2 :

Once the directory is opened,Type "./set" to fire up the social attacking kit.

Step 3 :

Now select option number 7.This module allows you to specially craft SMS messages and send them to a person. You can spoof the SMS source if you want to,its not that hard.

Step 4 :

Now select option 1 "Perform a SMS Spoofing Attack”

Step 5 :

Select how the "spoofed-sms" should distribute,you could send it to many people or just one,Your choice.

Step 6 :

Now you need to enter the number of the receiver (victim), make sure to enter with country code.Example : +9188260xxxxx for India,

Step 7 :

Now select 1 for pre-defined Templates,that is helpful to newbies, of-course you can create your own.

Step 8 :

On this step you need to choose the templates,I will choose the "Boss" one,you can use according to your situation.

Step 9 :

Now you need to select the service which will send that crafted SMS you created,You can choose whatever-the-hell you want,If you have an Android Emulator that is just great.

Step 10 :

POOF ! You just send an spoofed message,which is capable of stopping war or creating it,depends on you.

Like This Post ? Spotted any mistake ? Leave your feedback on the comment section BELOW.