Information

The following is a guest post by email. This is the third part in a series of articles on his view of hacking. If you are interested in writing for CyberCROW, click Here. Otherwise, Enjoy.
Showing posts with label Security. Show all posts
Showing posts with label Security. Show all posts

Sunday, April 24, 2011

What is Database and MY SQL Injections

Posted by glewoCROW 12:49 AM, under ,,, | No comments


In this i'll give you intro to the SQL Injections. Next post will give you detailed information about the SQL injections.

What is the Database?
  Datbase is an application that stores a collection of Data.Database offers various APIs for creating, accessing and managing the data it holds. And database(DB) servers can be integrated with our web development so that we can pick up the things we want from the database without much difficulties.


Database is a place that stores username,passwords and more details.  Database should be secured.  But providing high level security is not possible for all sites(much costlier or poor programming ). So Database of many websites is insecure or vulnerable(easily hackable).

Some List of Database are:
  • DB servers,
  • MySQL(Open source), 
  • MSSQL, 
  • MS-ACCESS, 
  • Oracle, 
  • Postgre SQL(open source), 
  • SQLite,
 What is SQL injection?
      SQL injection is Common and famous method of hacking  at present .  Using this method an unauthorized person can access the database of the website.  Attacker can get all details from the Database.

What an attacker can do?
  • ByPassing Logins
  • Accessing secret data
  • Modifying contents of website
  • Shutting down the My SQL server

Monday, April 11, 2011

How to hide the windows while running the virus code?

Good Morning Friends...!!  This day will be great day!  Because Break The Security get top rank in blogger directories. 

Now i am going to introduce a new tool called as "CMDOW" .   When you create and send virus to victim, the virus running process may be shown to victims.  This tool will hide that also.



About Cmdow
Cmdow is a Win32 commandline utility for NT4/2000/XP/2003 that allows windows to be listed, moved, resized, renamed, hidden/unhidden, disabled/enabled, minimized, maximized, restored, activated/inactivated, closed, killed and more.

Cmdow is 31kb standalone executable. It does not create any temporary files, nor does it write to the registry. There is no installation procedure, just run it. To completely remove all traces of it from your system, delete it.

Cmdow was written with batch file programmers in mind. Particular attention has been paid to Cmdows output making it easy to process with the 'FOR /F' command found in NT4/2000/XP/2003.


For more details and Download from here:


Saturday, April 9, 2011

How To remove the virus/Spyware/malware?

Posted by glewoCROW 2:36 AM, under ,, | No comments

Hi friends , today i am going to explain how to remove the
virus/spyware /malware from your system. If you suspect that your system is infected(symptoms for infected system) ,then you need take care about your system.



The best Internet security tool is our Kaspersky.

Download the Kaspersky Internet Security trial version from www.kaspersky.com
Install the Kaspersky Internet security, then do full scan. Wait for
scanning completion. After scanning completed ,it will show the list
of infected files, right click and select "Disinfect all".
 
It will remove all virus/spyware or any other malwares. Now your system is virus protected. 


  If you like to make your system more secure, buy the Kaspersky Internet security key and install in your trial version internet security. Now it will become genuine.
  Don't use any cracked version of Kaspersky Internet
security or cracked key.

Tool for Remove Spyware and Trojans

Posted by glewoCROW 1:54 AM, under ,,,, | No comments


Instant Spyware remover
Hi friends now i am going to introduce a new spyware and trojan detecting software.  It is best software.  I had one Trojan namely  "xkmq47.exe@ ".  When i install this sofware ,it founds this file.  But i had doubt "is this spyware software working correctly or showing important files as trojan?".  So i searched for the definiton of  " xkmq47.exe@ " in google search engine.  At the end of the result I found another spyware removal tool(in next post i will post about that tools after i use it).  Finally i came to one conclusion that this spyware removal tool is working perfectly.

I like to share that spyware removal tool with you.  Its name is "Instand Spyware Remover". 



Instant Spyware Remover is an award-winning advanced anti-virus/spyware software. It is able to effectively detect, remove and block malicious Spyware/Trojan/Malware/Virus and other potential security threats which slow down computer, create unwanted pop-up ads, change computer settings and steal personal information without your knowledge. It is the best tool that perfectly secure your computer and your privacy.


Instant Spyware Remover is able to remove and block Spyware/Trojan/Malware/Virus including but not limit to:
  • Adware
  • Annoyance
  • Browser Helper Object
  • Cracking Tool
  • Dialer
  • Downloader
  • Encryption Tool
  • Exploit
  • Rogue Security Software
  • FTP Server
  • Hijacker
  • Hostile ActiveX
  • Key Logger
  • Nuker
  • Password Cracker
  • Phreaking Tool
  • Proxy
  • SPAM Tool
  • Tracking Cookie
  • Trojan
  • Worm Creation Tool
  • Usage Tracks
  • P2P
  • Mail Bomber
  • Phreaking Tool
  • .....

Instant Spyware Remover Key Features:

  • Anti-Virus - Completely detect and remove Viruses,Trojan, worms, and other PC threat faster and easier.
  • Anti-Spyware - Remove and block spyware program effectively, secure all your online activities.
  • Real-Time Guard - Protects your PC from spyware, virus and other potential threats on a real-time basis.
  • In-depth Online Scan - Performs in-depth online scan which guarantees to dig out all the hidden Virus/spyware in your computer.
  • Forcible Removal - Forcibly and completely removes virus or spyware programs that can repeatedly generate themselves.
  • Internet Safeguard - One click of cleaning Internet tracks which ensures the security of all your online personal information
  • Health Report - By analyzing, Instant Spyware Remover will generate a report which shows the health status of every part of your PC system
  • Optimization Utilities - Instant Spyware Remover offers you a suite of useful tools including Startup Optimizer, Vulnerability Scanner, Registry repairer, Registry Backup etc which allows you to have a smarter PC management and better performance.
Why Choose Instant Spyware Remover?
  • Anti-virus, spyware all in one.
  • In-depth & powerful online Scan.
  • Automatic threat removal process.
  • Friendly interface and easy to use.
  • Complete threat removal guarantees.
  • 60 days money back guarantee.
  • Free 24 X 7 dedicated technical support.
  • Up-to-date threat database.
  • Frequent & free program update.
Free Download Here
   http://www.instantspywareremoval.com/InstantSpywareRemoval.html

Introducing a new Task Manager for analysing process

Posted by glewoCROW 12:46 AM, under ,,,,, | No comments

Do you know what programs are processing in your pc?  You use Default task manager for seeing the list of Process.  In Default task manage it just show only the list of process and memory usage.   You may not know which one is system process,malware program,application program.  Some advanced users can analyze himself what process are going on.  He can end the process by right clicking on the process.  But this will stop the program at the moment only.  When he restart the system or after sometime,the process may continue.

To analyze the system program, detect the malware and stop the program i am going to introduce a new software "Security Windows Manager".



How did i find this software?
  Today i analyze the Task manager process.  At that time i suspect on one process.  so i searched in internet for definition of the program.  At the end i found  this wonderful security software.  I like to introduce to my visitors also.

The Security Task Manager detects unknown malware and rootkits hidden from your antivirus software.
Features:
  •  Show the Risk process at the top.
  • unique security risk rating 
  • free online scan with all known Antivirus engines
  • full directory path and file name
  • process description
  • CPU usage graph
  • embedded hidden functions (e.g. keyboard monitoring, browser supervision or manipulation)
  • process type (e.g. visible window, systray program, DLL, IE-plugin, startup service)
  • Move to quarantine the detected or suspected process
Screenshot:

Thursday, April 7, 2011

Hacking Autorun.inf virus attack|Is autorun.inf virus?


When i  studied second year(cse), my friends told that autorun.inf is virus.  I thought so.  Because my antivirus blocks autorun.inf files.   In third year when i search about autorun.inf file in net, i realize about the auto run file.

 Today i bring some files from my college system.  When i insert the pen drive in my system, there are lot of exe files.They are viruses.  I delete all of them.  Finally i opened the autorun.inf file in notepad and saw the instructions.  Then only i remembered that i forget to post about autorun file.  This article will give you complete details about the autorun.inf file.
This is the instructions that saved in the infected(call virus programs) autorun.inf file:



[Autorun]
Open=RECYCLER\QqFvXcB.exe
Explore=RECYCLER\QqFvXcB.exe
AutoPlay=RECYCLER\QqFvXcB.exe
shell\Open\Command=RECYCLER\QqFvXcB.exe
shell\Open\Default=1
shell\Explore\command=RECYCLER\QqFvXcB.exe
shell\Autoplay\Command=RECYCLER\QqFvXcB.exe



is autorun.inf virus file?  no.  Then why antivirus block the autorun.inf files?  Go ahead to know the full details about auto run file.

Introduction to Autorun.inf File:
Auto run is file that triggers other programs,documents ,other files to be opened when the cd or pen drives are inserted.  Simpy triggers.

When cd or pen drives are inserted, windows will search for the autorun.inf file and follow the instructions of autorun.inf file(instructions have written inside the autorun.inf file).

How to create Autorun file?
Open notepad
type this command:
[Autorun]
save the file as "autorun.inf" (select all files, not text )

Complete Syntax and instructions inside the Autorun file:
Basic syntax must be inside  the autorun.inf file is :
[Autorun]
This will be used to identify the the file as autorun.

OPEN=
This will specify which application should be opened when the cd or pen drive is opened

Example:
open=virus.exe
This will launch the virus.exe file when cd or pen drive is opened.  The file should be in root directory.
if the file is in any other sub directories ,then we have to specify it.
Open=RECYCLER\Virus.exe
Explore=
Nothing big difference. if you right click and select explore option in cd or pen drive.  This command will be run.

AutoPlay=
Same as the above , but it will launch the the program when auto played.


SHELL\VERB =

The SHELL\VERB command adds a custom command to the drive's shortcut menu. This custom command can for example be used to launch an application on the CD/DVD.

Example:

shell\Open\Command=RECYCLER\QqFvXcB.exe
shell\Open\Default=1
shell\Explore\command=RECYCLER\QqFvXcB.exe
shell\Autoplay\Command=RECYCLER\QqFvXcB.exe



Use a series of shell commands to specify one or more entries in the pop-up menu that appears when the user right-clicks on the CD icon. (The shell entries supplement the open command.)

Icon=
Change the icon of your pen drive or cd.  you can use .ico,.bmp images(also .exe,.dll)

Example:
icon=WHCorp.ico
Label=

Specifies a text label to displayed for this CD in Explorer
Note that using the LABEL option can lead to problems displaying the selected ICON under Windows XP.

Example:
Label=Ethical hacking


Why Antivirus Block Autorun.inf file?
From above ,you come to know that autorun.inf file is not virus.  But why antivirus blocks it?  Because as i told autorun file call or launch any application or exe files.  It will lead to virus attack.  If the autorun.inf is blocked,then there is no way to launch the virus code.

Autorun is not virus but it can call virus files.

Wednesday, April 6, 2011

Introduction to Hacking

Posted by glewoCROW 11:17 PM, under ,,, | No comments

Originally, someone who makes furniture with an axe


1. A person who enjoys exploring the details of programmable systems
and how to stretch their capabilities, as opposed to most users,
who prefer to learn only the minimum necessary.


2. One whoprograms enthusiastically (even obsessively) or who enjoys programming
rather than just theorizing about programming.


3. Aperson capable of appreciating hack value.


4. A person who is good at programming quickly.


5. An expert at a particular program,
or one who frequently does work using it or on it; as in ‘a
Unix hacker.’ (Definitions 1 through 5 are correlated, and people
who fit them congregate.)


6. An expert or enthusiast of any kind.
One might be an astronomy hacker, for example.


7. One who
enjoys the intellectual challenge of creatively overcoming or circumventing
limitations.


8. [deprecated] A malicious meddler who
tries to discover sensitive information by poking around. Hence
‘password hacker,’ ‘network hacker.’ The correct term for this
sense is cracker.



Cracker


One who breaks security on a system. Coined ca. 1985 by hackers
in defense against journalistic misuse of hacker (q.v., sense 8). An
earlier attempt to establish ‘worm’ in this sense around 1981–82
on Usenet was largely a failure.


Use of both these neologisms reflects a strong revulsion against
the theft and vandalism perpetrated by cracking rings. While it is
expected that any real hacker will have done some playful cracking
and knows many of the basic techniques, anyone past larval stage
is expected to have outgrown the desire to do so except for immediate,
benign, practical reasons (for example, if it’s necessary to get
around some security in order to get some work done).
Thus, there is far less overlap between hackerdom and crackerdom
than the mundane reader misled by sensationalistic journalism
might expect. Crackers tend to gather in small, tight-knit,
very secretive groups that have little overlap with the huge, open
poly-culture this lexicon describes; though crackers often like to
describe themselves as hackers, most true hackers consider them a
separate and lower form of life.


It’s clear that the term cracker is absolutely meant to be derogatory. One
shouldn’t take the tone too seriously though, as The Jargon File is done with a
sense of humor, and the above is said with a smile. As we can see from the
above, illegal or perhaps immoral activity is viewed with disdain by the “true
hackers,” whomever they may be. It also makes reference to cracker being a
possible intermediate step to hacker, perhaps something to be overcome.




Script Kiddie



The term script kiddie has come into vogue in recent years. The term refers to
crackers who use scripts and programs written by others to perform their intrusions.
If one is labeled a “script kiddie,” then he or she is assumed to be incapable
of producing his or her own tools and exploits, and lacks proper
understanding of exactly how the tools he or she uses work. As will be apparent
by the end of this chapter, skill and knowledge (and secondarily, ethics) are the
essential ingredients to achieving status in the minds of hackers. By definition,
a script kiddie has no skills, no knowledge, and no ethics.



Phreak


A phreak is a hacker variant, or rather, a specific species of hacker. Phreak is
short for phone phreak (freak spelled with a ph, like phone is). Phreaks are
hackers with an interest in telephones and telephone systems. Naturally, there
has been at times a tremendous amount of overlap between traditional hacker
roles and phreaks.



White Hat/Black Hat/Gray Hat


White Hat Hacker:


White Hat hackers are good guys who does the hacking for defensing. They probably work an organization for providing security.



Black Hat Hacker


Black hat hackers are bad guys(the malicious hackers or crackers). They usually steal the other bank information and steal the money.
They use their skills for illegal purposes.
They are creators of viruses,malware,spyware.
They will destroy your pc.



Gray Hat Hackers


Grey hats are hackers who may work offensively or defensively, depending on the situation.
This is the dividing line between hacker and cracker. Both are powerful forces on the Internet,
and both will remain permanently. And some individuals qualify for both categories. The
existence of such individuals further clouds the division between these two groups of people.
In addition to these groups, there are self-proclaimed ethical hackers, who are interested in
hacker tools mostly from a curiosity standpoint. They may want to highlight security problems
in a system or educate victims so they secure their systems properly. These hackers are
doing their “victims” a favor. For instance, if a weakness is discovered in a service offered by
an investment bank, the hacker is doing the bank a favor by giving the bank a chance to rectify
the vulnerability.