Showing posts with label Hacks And Anti-Hacks. Show all posts
Showing posts with label Hacks And Anti-Hacks. Show all posts

Wednesday, September 23, 2009

8 hacks to make Firefox ridiculously fast

Firefox has been outperforming IE in every department for years, and version 3 is speedier than ever.

But tweak the right settings and you could make it faster still, more than doubling your speed in some situations, all for about five minutes work and for the cost of precisely nothing at all. Here's what you need to do.

Hacking Windows XP: Speed Up Your Network and Internet Access

The speed of your network connection doesn't just depend on the speed of your hardware. Windows is an operating system that is designed to work on a variety of different hardware and network setups. Because of the abstract nature of the operating system, it cannot be optimized for user-specific hardware setups.

you will have to hack the System Registry and delete a reference to a key so that this feature will not be loaded. To do this, follow these steps:
read carefully...

Sunday, August 30, 2009

Know More About Secure Sockets Layer (SSL)

Know More About Secure Sockets Layer (SSL)

Secure Sockets Layer (SSL) is the most widely used technology for providing a secure communication between the web client and the web server. Most of us are familiar with many sites such as Gmail, Yahoo etc. using https protocol in their login pages. When we see this, we may wonder what’s the difference between http and https. In simple words HTTP protocol is used for standard communication between the Web server and the client. HTTPS is used for a SECURE communication.

What exactly is Secure Communication ?

Suppose there exists two communication parties A (client) and B (server).

Working of HTTP

When A sends a message to B, the message is sent as a plain text in an unencrypted manner. This is acceptable in normal situations where the messages exchanged are not confidential. But imagine a situation where A sends a PASSWORD to B. In this case, the password is also sent as a plain text. This has a serious security problem because, if an intruder (hacker) can gain unauthorised access to the ongoing communication between A and B , he can see the PASSWORDS since they remain unencrypted. This scenario is illustrated using the following figure

This image has been resized.Click to view original image



Now lets see the working of HTTPS

When A sends a PASSWORD (say "mypass") to B, the message is sent in an encrypted format. The encrypted message is decrypted on B’s side. So even if the Hacker gains an unauthorised access to the ongoing communication between A and B he gets only the encrypted password ("xz54p6kd") and not the original password. This is shown below


This image has been resized.Click to view original image




How is HTTPS implemented ?

HTTPS is implemented using Secure Sockets Layer (SSL).A website can implement HTTPS by purchasing an SSL Certificate. Secure Sockets Layer (SSL) technology protects a Web site and makes it easy for the Web site visitors to trust it. It has the following uses

1.An SSL Certificate enables encryption of sensitive information during online transactions.

2.Each SSL Certificate contains unique, authenticated information about the certificate owner.

3.A Certificate Authority verifies the identity of the certificate owner when it is issued.


How Encryption Works ?

Each SSL Certificate consists of a Public key and a Private key. The public key is used to encrypt the information and the private key is used to decrypt it. When your browser connects to a secure domain, the server sends a Public key to the browser to perform the encryption. The public key is made available to every one but the private key(used for decryption) is kept secret. So during a secure communication, the browser encrypts the message using the public key and sends it to the server. The message is decrypted on the server side using the Private key(Secret key).


How to identify a Secure Connection ?


In Internet Explorer, you will see a lock icon in the Security Status bar. The Security Status bar is located on the right side of the Address bar.You can click the lock to view the identity of the website.

In high-security browsers, the authenticated organization name is prominently displayed and the address bar turns GREEN when an Extended Validation SSL Certificate is detected. If the information does not match or the certificate has expired, the browser displays an error message or warning and the status bar may turn RED.


So the bottom line is, whenever you perform an online transaction such as Credit card payment, Bank login or Email login always ensure that you have a secure communication. A secure communication is a must in these situations.Otherwise there are chances of Phishing using a Fake login Page.

Learn What is Phishing and save your money from Hackers

What is Phishing ?




Phishing is an attempt to criminally and fraudulently acquire sensitive information, such as usernames, passwords and credit card details, by appearing as a trustworthy entity in an electronic communication. eBay, PayPal and other online banks are common targets. Phishing is typically carried out by email or instant messaging and often directs users to enter details at a website, although phone contact has also been used. Phishing is an example of social engineering techniques used to fool users.Attempts to deal with the growing number of reported phishing incidents include legislation, user training, public awareness, and technical measures.

Recent phishing attempts have targeted the customers of banks and online payment services.Social networking sites such as Orkut are also a target of phishing.

Spoofed/Fraudulent e-mails are the most widely used tools to carry out the phishing attack.In most cases we get a fake e-mail that appears to have come from a Trusted Website . Here the hacker may request us to verify username & password by replaying to a given email address.


TECHNIQUES BEHIND PHISHING ATTACK

1.Link Manipulation

Most methods of phishing use some form of technical deception designed to make a link in an email appear to belong to some trusted organization or spoofed organization. Misspelled URLs or the use of subdomains are common tricks used by phishers, such as this example URL

www.micosoft.com

www.mircosoft.com

www.verify-microsoft.com

Instead of http://www.microsoft.com/

2.Filter Evasion

Phishers have used images instead of text to make it harder for anti-phishing filters to detect text commonly used in phishing emails.This is the reason Gmail or Yahoo will disable the images by default for incoming mails.

How does a phishing attack/scam look like?

As scam artists become more sophisticated, so do their phishing e-mail messages and pop-up windows.They often include official-looking logos from real organizations and other identifying information taken directly from legitimate Web sites.Here is an example of how the phishing scam email looks like


Example of a phishing e-mail message, including a deceptive URL address linking to a scam Web site.
To make these phishing e-mail messages look even more legitimate, the scam artists may place a link in them that appears to go to the legitimate Web site (1), but it actually takes you to a phishing site (2) or possibly a pop-up window that looks exactly like the official site.
These copycat sites are also called “spoofed” Web sites. Once you’re at one of these spoofed sites, you may send personal information to the hackers.

How to identify a fraudulent e-mail?

Here are a few phrases to look for if you think an e-mail message is a phishing scam.

“Verify your account.”

Legitimate sites will never ask you to send passwords, login names, Social Security numbers, or any other personal information through e-mail.

“If you don’t respond within 48 hours, your account will be closed.”

These messages convey a sense of urgency so that you’ll respond immediately without thinking.

“Dear Valued Customer.”

Phishing e-mail messages are usually sent out in bulk and often do not contain your first or last name.

“Click the link below to gain access to your account.”

HTML-formatted messages can contain links or forms that you can fill out just as you’d fill out a form on a Web site. The links that you are urged to click may contain all or part of a real company’s name and are usually “masked,” meaning that the link you see does not take you to that address but somewhere different, usually a scam Web site.
Notice in the following example that resting the mouse pointer on the link reveals the real Web address, as shown in the box with the yellow background. The string of cryptic numbers looks nothing like the company’s Web address, which is a suspicious sign.




So the Bottom line to defend from phishing attack is-

1.Never assume that an email is valid based on the sender’s email address.
2.A trusted bank/organization such as paypal will never ask you for your full name and password in a PayPal email.
3.An email from trusted organization will never contain attachments or software.
4.Clicking on a link in an email is the most insecure way to get to your account.

How To Prevent Your Twitter Account from Being Hacked

Twitter, with its increased popularity have obviously been at the dark sight of crackers. They try phishing to manipulate your account and also hijack your twitter profile to irritate your followers too. That may seriously harm your reputation and credentials though you were never aware of such issues yourselves. The scammers put up websites that look exactly like Twitter. These websites prompt you to login with your Twitter username and password and then use your Twitter account to spam your followers. They send direct messages and @replies under your account with their phishing url. Your followers may then click on the link, give their credentials and have the exact same thing happen. And this cycle will grow bigger each day. So what can you do to prevent them?



1. Don't Trust any other Domain but Twitter
Whoever gives you a link or from whatever sources, do not log in with your twitter account anywhere excepting http://twitter.com. Check your browsers address bar before logging in and make sure its correct. look at this site for a change which has been a culprit in the recent past. Here is a screen-shot of that site:



[Do not click on that link unless you are too curious]

2. Do not Share Your Account Information with Anybody
Be very careful what outside Twitter applications you give your password to. If an outside application asks for your password, read their terms and do a little research on who is behind the application. If wary at all don’t give your password. There may be twitter tools which can harm you that way. Any third party twitter tool should not be trusted.

3. Do not Trust any Mail that Claims to Have Come from Twitter
If you receive an email notice saying you’ve received a Direct Message with a link that redirects to what seems like Twitter.com, be careful about entering your Twitter credentials. Instead, look closely at the URL to see if it’s not really Twitter but a sketchy phishing site. If you are not sure, then don't click on it.


These are the three main tips I have for now to share with you. If you have more suggestion, please write to us and we will publish it for the benefit of others (with your name as the contributor).

Latest Labs Feature in Gmail Adds Anti-Phishing Key For Ebay and PayPal





Recently Gmail labs team introduced a new security feature to completely stop spam and phishing emails. Last year they started a program for spam filtration from fake eBay and PayPal mails.


What does this feature do?



As most of the people were not aware of the spam filtration feature so Gmail team decided to create an actual icon for a verified account so people would recognize an email address that’s legitimate. After enabling this feature you will see a super-trustworthy icon next to verified emails so that you can know that they are not trustworthy but super-trustworthy.


According to the official blog super-trustworthy means :


1. The sender, usually a financial institution, is a target of phishers
2. All of the sender’s email is authenticated with DKIM
3. Gmail rejects any fake messages that claim to come from this sender, but actually don’t.
Currently this feature is limited to eBay and Paypal only but they hope to add more senders in the future.

How to enable it

Visit Gmail settings >> Labs and look for “Authentication icon for verified senders”, select Enable beside it and click on Save changes at the bottom.

How To Get Back Your Hacked Gmail/Orkut/Google Account!





This is my official reply to all mails/comments/scraps asking me how to get back hacked Gmail/Orkut/Google Account (Most of Mine orkuts friends A/cs are hacked in recent past)
Everyone should read this no matter how safe you think you are! ;-) As Google Account is a single account used across all Googles services like Gmail, Orkut, Blogger, Adsense, Checkout. etc, it can turn out to be our worst nightmare if it gets hacked! Like many other online services Google tries to protect your account with secret question as well as optional secondary email address. But there is one more official option which only Google Provides! Now lets go step-by-step?


#1. Trying "Forget Password" Option

I know this will not work in most cases, as options like forget password rely on secondary email address and security question, both of which can be easily changed once a account gets hacked. Still you should try atleast once as most password gets hacked by script kiddies and not by real hackers. So go to Forget Password form first!


#2. What if "Forget Password" Option Fails

You can submit a form to Google in which you can provide details about your Google Account usage. Details include information which most likely only real owner can provide. Here are few things for example?

* Last successful login date
* Account creation date
* Google products you used with this account and the date you started using each one
* Details about Orkut account (if you use Orkut)
* Details about Blogger account (if you use Blogger)

Now most important part is what they quoted on the form,

"Please answer each question as thoroughly and accurately as possible. If you?re not certain about some of the information, provide your closest estimate. Whether or not we can return your account depends on the strength and accuracy of your responses."

So I will suggest following things?

* Your goal should be to give Google maximum & accurate data! So take your time and submit form with maximum amount of information possible. You can consult your trusted friends if you are not sure. As an example it could be Vicky or Pankaj who invited you on orkut. If you are not sure call them up and ask it!
* Submit only one form! Yes this should be common sense. Do not submit multiple forms. A person who uses around 10-15 Google products asked me if he can submit multiple forms mentioning different Google products.
* Submit form from the place which you use most often to access your account like PC at home! Although they haven?t mentioned this explicitly, line above submit button says, "Please note that we need your IP address in order to resolve this issue. Your IP address will be captured automatically when you submit this form."


Finally Contact Form is here!


Code:
http://www.google.com/support/accounts/bin/request.py?contact_type=ara&ctx=accounts&hl=en
I advise everyone to have a look at this form and information it asks. You can prepare a document about secret info, may be in cell phone or pen down it on a paper. This will come handy if something goes wrong in future!

How to Hack Protect your Orkut Account

Most of the people wants to know How to hack an Orkut accountwhich I am going to post later.But here I am giving you a detailed information about how to protect your Orkut accounts.As we all know most of the Google services are still in BETA.So,websites like Orkut, powered by Google is not totally secure!Several people feel proud in hacking other user’s account. You do a foolish thing, and next day your account is hacked. This is very sad indeed, but hackers are adding names to their victims list till now.

This image has been resized.Click to view original image


How can a hacker hack my Orkut account?

As I told the answer to this question is coming is my later posts.

But this post is meant for providing some safety measures to prevent your Orkut account from being hacked.There is not much you have to take care of. Just follow the simple steps and never get your orkut account hacked in your life.

1. Never try to login/access your Orkut account from sites other than Orkut.com.

2. Never click on any links from the sources you don’t trust while accessing your Orkut account.(or while accessing any other Google services like Gmail,Blogger etc.)

3. Delete any links on your scrapbook, no matter if a known or unknown person have sent it.

4. Never disclose your orkut login details with anyone.

5. Never ever use Javascripts on Orkut, no matter whatever it claims to do.Get satisfied with the services provided by default! Avoid using third party Scripts which might be malicious.

6. Never get excited to see a site claiming to have 1000 cool orkut tricks for which you have to just log in to your orkut account. Don’t trust that site. That’s a phishing site.

7. Never tick the box “REMEMBER ME” on the orkut homepage if you are surfing from a cafe or a public area.

8. Always remember to hit Sign out button, when you are done.

Top 10 reasons how websites get hacked

Experts say the people who actually build Web applications aren't paying much attention to security; a non-profit group is trying to solve that
By Jon Brodkin, Network World
October 05, 2007

Web security is at the top of customers' minds after many well-publicized personal data breaches, but the people who actually build Web applications aren't paying much attention to security, experts say.

"They're totally ignoring it," says IT consultant Joel Snyder. "When you go to your Web site design team, what you're looking for is people who are creative and able to build these interesting Web sites... That's No. 1, and No. 9 on the list would be that it's a secure Web site."

The biggest problem is designers aren't building walls within Web applications to partition and validate data moving between parts of the system, he says.

Security is usually something that's considered after a site is built rather than before it is designed, agrees Khalid Kark, senior analyst at Forrester.

"I'd say the majority of Web sites are hackable," Kark says. "The crux of the problem is security isn't thought of at the time of creating the application."

That's a big problem, and it's one the nonprofit Open Web Application Security Project (OWASP) is trying to solve. An OWASP report called "The Ten Most Critical Web Application Security Vulnerabilities" was issued this year to raise awareness about the biggest security challenges facing Web developers.

The first version of the list was released in 2004, but OWASP Chairman Jeff Williams says Web security has barely improved. New technologies such as AJAX and Rich Internet Applications that make Web sites look better also create more attack surfaces, he says. Convincing businesses their Web sites are insecure is no easy task, though.

"It's frustrating to me, because these flaws are so easy to find and so easy to exploit," says Williams, who is also CEO and co-founder of Aspect Security. "It's like missing a wall on a house."

Here is a summary of OWASP's top 10 Web vulnerabilities, including a description of each problem, real-world examples and how to fix the flaws.

1. Cross site scripting (XSS)

The problem: The "most prevalent and pernicious" Web application security vulnerability, XSS flaws happen when an application sends user data to a Web browser without first validating or encoding the content. This lets hackers execute malicious scripts in a browser, letting them hijack user sessions, deface Web sites, insert hostile content and conduct phishing and malware attacks.

Attacks are usually executed with JavaScript, letting hackers manipulate any aspect of a page. In a worst-case scenario, a hacker could steal information and impersonate a user on a bank's Web site, according to Snyder.

Real-world example: PayPal was targeted last year when attackers redirected PayPal visitors to a page warning users their accounts had been compromised. Victims were redirected to a phishing site and prompted to enter PayPal login information, Social Security numbers and credit card details. PayPal said it closed the vulnerability in June 2006.

How to protect users: Use a whitelist to validate all incoming data, which rejects any data that's not specified on the whitelist as being good. This approach is the opposite of blacklisting, which rejects only inputs known to be bad.

Additionally, use appropriate encoding of all output data. "Validation allows the detection of attacks, and encoding prevents any successful script injection from running in the browser," OWASP says.

2. Injection flaws

The problem: When user-supplied data is sent to interpreters as part of a command or query, hackers trick the interpreter -- which interprets text-based commands -- into executing unintended commands. "Injection flaws allow attackers to create, read, update, or delete any arbitrary data available to the application," OWASP writes. "In the worst-case scenario, these flaws allow an attacker to completely compromise the application and the underlying systems, even bypassing deeply nested firewalled environments."

Real-world example: Russian hackers broke into a Rhode Island government Web site to steal credit card data in January 2006. Hackers claimed the SQL injection attack stole 53,000 credit card numbers, while the hosting service provider claims it was only 4,113.

How to protect users: Avoid using interpreters if possible. "If you must invoke an interpreter, the key method to avoid injections is the use of safe APIs, such as strongly typed parameterized queries and object relational mapping libraries," OWASP writes.

3. Malicious file execution

The problem: Hackers can perform remote code execution, remote installation of rootkits, or completely compromise a system. Any type of Web application is vulnerable if it accepts filenames or files from users. The vulnerability may be most common with PHP, a widely used scripting language for Web development.

Real-world example: A teenage programmer discovered in 2002 that Guess.com was vulnerable to attacks that could steal more than 200,000 customer records from the Guess database, including names, credit card numbers and expiration dates. Guess agreed to upgrade its information security the next year after being investigated by the Federal Trade Commission.

How to protect users: Don't use input supplied by users in any filename for server-based resources, such as images and script inclusions. Set firewall rules to prevent new connections to external Web sites and internal systems.

4. Insecure direct object reference

The problem: Attackers manipulate direct object references to gain unauthorized access to other objects. It happens when URLs or form parameters contain references to objects such as files, directories, database records or keys.

Banking Web sites commonly use a customer account number as the primary key, and may expose account numbers in the Web interface.

"References to database keys are frequently exposed," OWASP writes. "An attacker can attack these parameters simply by guessing or searching for another valid key. Often, these are sequential in nature."

Real-world example: An Australian Taxation Office site was hacked in 2000 by a user who changed a tax ID present in a URL to access details on 17,000 companies. The hacker e-mailed the 17,000 businesses to notify them of the security breach.

How to protect users: Use an index, indirect reference map or another indirect method to avoid exposure of direct object references. If you can't avoid direct references, authorize Web site visitors before using them.

5. Cross site request forgery

The problem: "Simple and devastating," this attack takes control of victim's browser when it is logged onto a Web site, and sends malicious requests to the Web application. Web sites are extremely vulnerable, partly because they tend to authorize requests based on session cookies or "remember me" functionality. Banks are potential targets.

"Ninety-nine percent of the applications on the Internet are susceptible to cross site request forgery," Williams says. "Has there been an actual exploit where someone's lost money? Probably the banks don't even know. To the bank, all it looks like is a legitimate transaction from a logged-in user."

Real-world example: A hacker known as Samy gained more than a million "friends" on MySpace.com with a worm in late 2005, automatically including the message "Samy is my hero" in thousands of MySpace pages. The attack itself may not have been that harmful, but it was said to demonstrate the power of combining cross site scripting with cross site request forgery. Another example that came to light one year ago exposed a Google vulnerability allowing outside sites to change a Google user's language preferences.

How to protect users: Don't rely on credentials or tokens automatically submitted by browsers. "The only solution is to use a custom token that the browser will not 'remember,'" OWASP writes.

6. Information leakage and improper error handling

The problem: Error messages that applications generate and display to users are useful to hackers when they violate privacy or unintentionally leak information about the program's configuration and internal workings.

"Web applications will often leak information about their internal state through detailed or debug error messages. Often, this information can be leveraged to launch or even automate more powerful attacks," OWASP says.

Real-world example: Information leakage goes well beyond error handling, applying also to breaches occurring when confidential data is left in plain sight. The ChoicePoint debacle in early 2005 thus falls somewhere in this category. The records of 163,000 consumers were compromised after criminals pretending to be legitimate ChoicePoint customers sought details about individuals listed in the company's database of personal information. ChoicePoint subsequently limited its sales of information products containing sensitive data.

How to protect users: Use a testing tool such as OWASP'S WebScarab Project to see what errors your application generates. "Applications that have not been tested in this way will almost certainly generate unexpected error output," OWASP writes.

Another tip: disable or limit detailed error handling, and don't display debug information to users.

7. Broken authentication and session management

The problem: User and administrative accounts can be hijacked when applications fail to protect credentials and session tokens from beginning to end. Watch out for privacy violations and the undermining of authorization and accountability controls.

"Flaws in the main authentication mechanism are not uncommon, but weaknesses are more often introduced through ancillary authentication functions such as logout, password management, timeouts, remember me, secret question and account update," OWASP writes.

Real-world example: Microsoft had to eliminate a vulnerability in Hotmail that could have let malicious JavaScript programmers steal user passwords in 2002. Revealed by a networking products reseller, the flaw was vulnerable to e-mails containing Trojans that altered the Hotmail user interface, forcing users to repeatedly reenter their passwords and unwittingly send them to hackers.

How to protect users: Communication and credential storage has to be secure. The SSL protocol for transmitting private documents should be the only option for authenticated parts of the application, and credentials should be stored in hashed or encrypted form.

Another tip: get rid of custom cookies used for authentication or session management.

8. Insecure cryptographic storage

The problem: Many Web developers fail to encrypt sensitive data in storage, even though cryptography is a key part of most Web applications. Even when encryption is present, it's often poorly designed, using inappropriate ciphers.

"These flaws can lead to disclosure of sensitive data and compliance violations," OWASP writes.

Real-world example: The TJX data breach that exposed 45.7 million credit and debit card numbers. A Canadian government investigation faulted TJX for failing to upgrade its data encryption system before it was targeted by electronic eavesdropping starting in July 2005.

Furthermore, generate keys offline, and never transmit private keys over insecure channels.

It's pretty common to store credit card numbers these days, but with a Payment Card Industry Data Security Standard https://www.pcisecuritystandards.org/ compliance deadline coming next year, OWASP says it's easier to stop storing the numbers altogether.

9. Insecure communications

The problem: Similar to No. 8, this is a failure to encrypt network traffic when it's necessary to protect sensitive communications. Attackers can access unprotected conversations, including transmissions of credentials and sensitive information. For this reason, PCI standards require encryption of credit card information transmitted over the Internet.

Real-world example: TJX again. Investigators believe hackers used a telescope-shaped antenna and laptop computer to steal data exchanged wirelessly between portable price-checking devices, cash registers and store computers, the Wall Street Journal reported.

"The $17.4-billion retailer's wireless network had less security than many people have on their home networks," the Journal wrote. TJX was using the WEP encoding system, rather than the more robust WPA.

How to protect users: Use SSL on any authenticated connection or during the transmission of sensitive data, such as user credentials, credit card details, health records and other private information. SSL or a similar encryption protocol should also be applied to client, partner, staff and administrative access to online systems. Use transport layer security or protocol level encryption to protect communications between parts of your infrastructure, such as Web servers and database systems.

10. Failure to restrict URL access

The problem: Some Web pages are supposed to be restricted to a small subset of privileged users, such as administrators. Yet often there's no real protection of these pages, and hackers can find the URLs by making educated guesses. Say a URL refers to an ID number such as "123456." A hacker might say 'I wonder what's in 123457?' Williams says.

The attacks targeting this vulnerability are called forced browsing, "which encompasses guessing links and brute force techniques to find unprotected pages," OWASP says.

Real-world example: A hole on the Macworld Conference & Expo Web site this year let users get "Platinum" passes worth nearly $1,700 and special access to a Steve Jobs keynote speech, all for free. The flaw was code that evaluated privileges on the client but not on the server, letting people grab free passes via JavaScript on the browser, rather than the server.

How to protect users: Don't assume users will be unaware of hidden URLs. All URLs and business functions should be protected by an effective access control mechanism that verifies the user's role and privileges. "Make sure this is done ... every step of the way, not just once towards the beginning of any multistep process,' OWASP advises.

Master Tutorial For Anti Hacking ( For Layman )



#Emails

  • [b]Never give your private email id while registering on sites which u dont think hav gud intentions.Coz most of them sell their databases to advertisers which results in a hell lot of Spamming in ur Inbox.
  • Always keep Multiple Email IDs for specific purposes like one for registrations on websites which ask for Confirmation.Second for Official Emails like Bank accounts, Paypals and other financial details (Use This As Less As Possible) and the Last one for Friends and Relatives (As if this ID gets hacked thers not much of a loss)



#Passwords

  • [b]First and the Foremost Rule Never Type Ur Bank / Webmaster Password Or Credit Card Details.Keep it in some file in Ur Computer and Then Just CTRLC-CTRLV Or the BEST Thing to use is ONSCREEN KEYBOARD :wave
  • Always Keep A Gud Strong Password with Minimum 10 Letters coz now many Crackers are available which can Brute Force your Password.Also, make sure that the password doesnt make any sense and if u want a real gud strong password u must combine Characters,Upper Case and Lower Case , then it will be nearly impossible (If the man has lots and lots and lots of patience then its possible) to brute force ur password.

    Online Strong Password Generator
Code:
www.strongpasswordgenerator.com/
  • Always Install KeyScramble along with ur windows itz a great software and is successful in blocking all KEYLOGGERS.

#Viruses,BackDoor Trojans and KeyLoggers..
  • I already mentioned above abt KeyScramble which is the best tool for protecting ur Passwords and personal Details from KeyLoggers.
  • An AntiVirus & A Firewall is absolutely necessary coz without it u are giving a Silver Platter to the hackers to feed on.I dont mean to say that u install a 2003 Edition of an AV.An Antivirus Software shuld be updated daily coz thousands of viruses/trojans are made every day.
    Recommended Antivirus Softwares:
    • Kaspersky Internet Security (It Includes Firewall)
    • ESET Smart Security (Commonly Known as NOD32)
    • Bitdefender Antivirus
    Recommended Firewall Softwares:
    • ZoneAlaram Firewall Pro (It Really Fortifies ur PC)
    • Comodo Firewall (Occupies less memory and blocks ur Computer frm all Internet Attacks)


Files Protection
  • Nothing much can be done about the our files , two major things to be feared incase of files are [u]Viruses and BackDoor Trojans.
  • For Viruses, thers not pretty much u can do except keep a gud antivirus and always keep a backup of ur IMP Files.I usually upload them on net on some web drive website like www.adrive.com
  • BackDoor Torjans can transfer ur files to some other computer without ur knowing or permission.







Thts all, Nothing More to be worried abt If u hav any Questions Feel Free To Ask and be Safe and One last thing , never get tempted by anything like Online Lottery,etc they are usually scams and hackerz are always behind such scandals.

Tuesday, August 18, 2009

Hack To Download Windows Vista Service Pack 2 From Windows Update Before Official Release

FOR EDUCATIONAL PURPOSE ONLY

Early beta build of Windows Vista SP2 being released to private beta testers, and as usual we now have a simple hack which allows users to get their hands on this pre-build of Windows Vista Service Pack 2 before everybody else directly from Windows Update servers.

To enable the early download access hack simply follow the procedure as described:

Copy the following batch file code to a text file and save as "Download-Vista-SP2.bat",

@echo off

reg delete HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\WindowsUpdate\VistaSp2 /f > NUL 2>&1
reg delete HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\ Windows\CurrentVersion\WindowsUpdate\VistaSP2 /f > NUL 2>&1

reg add HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\WindowsUpdate\VistaSp2 /v Beta1 /t REG_SZ /d C21A5C64-2530-CC19-042F-9ABDB4ED27F9 /f
IF NOT %errorlevel% == 0 ( goto ERROR)

UCCESS
@echo.
echo ================================================== =========
echo Windows Vista SP2 registry key has been set successfully.
echo Please check for updates in Windows Update.
echo ================================================== =========
@echo.
goto END

:ERROR
@echo.
echo ================================================== =========
echo FAILED to set Windows Vista SP2 registry keys.
echo Please run this script by right clicking and selecting
echo "Run as Administrator".
echo ================================================== =========
@echo.
goto END

:END
pause

Double-click and launch the batch file to apply the hack.
Now, start Windows Update and you should see the Vista Service Pack 2 there.

Monday, August 10, 2009

Download Multi-Part Download Links In One Click! [RS Premium Users]

Well, like many of you, I'm not a fan of seeing 40 or 50 Rapidshare links and having to click each one to download. So I came up with this guide. I don't use ANY third party programs, just Firefox, with two extremely handy Firefox extensions, and the Notepad application.

FOR MAC USERS(skip this if you don't own a Mac): I'm not positive, but I'm pretty sure this works for Macs as well. Go through the same motions. I'm not sure what text editor Macs have built in, but use that to save as html.

1. So, how do you do this? First off, make sure you've set your RapidShare account to download direct. Go into your settings through RapidShare.com and find it. This skips the "free or premium" download choice screen and directly downloads as Premium the moment you click a Rapidshare link.

2. Then, grab the following extensions for Firefox(links included):

DownThemAll: A download manager/accelerator that's integrates into Firefox. It's really useful and performs just like IDM and those third party downloaders. I get speeds of up to 800-1 MB/sec using it.

Code:
https://addons.mozilla.org/en-US/firefox/addon/201
Linkification: Well, this is probably the single most useful extension ever, especially for us forum users. Essentially, what this extension does is turn any text URL into an actual clickable link. Translation? This means you can now click on links EVEN IF IT'S CODED. It works very well and is a snap to install, with no configuration needed.

Code:
https://addons.mozilla.org/en-US/firefox/addon/190
Next, say we find a huge download, like for instance, the Adobe CS3 Master Collection. This is, I think, almost 41 parts? Anyways, the number of parts doesn't matter, my trick will always work.

3. So, when you see these links, highlight and copy all of them. ONLY the links, no other text. Next, open up a Notepad, and paste all the links into the Notepad. Click File>Save As..., and then save it as links.html (or *anything*.html, as long as the extension is .html)

4. Open up that html file in Firefox, and voila! All of them appear as clickable links, on a blank white page. But of course, it's not over yet. Right click anywhere on the page, and click DownThemAll. For the filter check boxes, just click All Files. Then, for the Save Files In option, click the Orange folder to the right of it and pick a location where you want to save all these files.

5. Then click start, and BAM. They're all cued up and 4 of them will start downloading. By default, DownThemAll downloads 4 links at a time, but you can of coruse change this by going into the Preferences. I don't recommend that, because the more you have downloading from Rapidshare at once, the slower your speeds are. Play around with it, sometimes I download one at a time too.

At any rate, it will start downloading, and at some pretty good speeds too (usually around 500 at least depending on your connection). Leave it in the background, and before you know it, all your links are there.

NOTE: For VERY large files (200MB+) it takes time for it to grab all the batch downloading links. Because of this, Firefox will probably freeze for a coupla seconds upon each new download link. DON'T worry, Firefox has not crashed, this is just a technical issue that can't be solved.

I took a decent amount of time to write this, a thanks would be nice .

Hack Microsoft Window's Picture & Fax Viewer To Support More Than 200 Image Formats

Windows XP features embedded Picture & Fax Viewer for quick viewing of your images, However, the handy utility only supports common popular image formats like JPEG, GIF, and BMP making it necessary to install other multi-format image viewers like ACDSee or XnView, but not anymore free Windows Utility ImageXtender let you hack Windows XP standard Picture & Fax Viewer to support more then 200 known graphics extensions.

You just need to install ImageXtender and it patches the default viewer to support the new image formats, the process of viewing images would remain the same allowing you to view all image formats in three different viewing modes - Preview, Thumbnails and Filmstrip.

The utility works fine and is just a matter of install and forget, However, it fell short of its claim to support Photoshop .PSD files on Windows XP SP3.

Download ImageXtender [1.5 MB] >>

Thursday, August 6, 2009

Anti hacking tips for home based online business.

Anti hacking tips for home based online business.
In previous articles, we've looked at protecting your online business in relation to credit card fraud and web site hacking, but another very important aspect of online security focuses on your most important tool - the computer you use to run your business.

Many of us involved in ecommerce choose to work from home - it's a comfortable environment, we can dress the way we want, save time and money in travel and be close to our loved ones.

But if the computer you use to run your online business is the same one your children use for homework and general surfing, this is potentially a very dangerous situation.

A recent security survey reported that 20% of home PC's are infected with viruses and over 80% contained spyware and adware. Frightening figures.

The following are a few anti-hacking tips that will help in keeping your business systems secure :

Don't ignore operating system updates

Practically every day, some new security flaw is found in the most critical aspect of your business - the operating system on which all your other software runs. While it's a major pain in the butt to apply updates and patches so regularly, especially if you access the web via dialup, it's nonetheless of vital importance not to put off performing these tasks as part of regular maintenance.

Don't wait to be alerted via mainstream media of problems that have been discovered - more often than not, these notifications will be delayed. As a part of your daily routine, it's wise to visit the software vendors' site and keep abreast of any critical security updates. In the case of Microsoft, you'll need to go to the Windows Update site.

Anti-virus software used *properly*

Install anti-virus software and ensure that it's regularly updated - this is of the utmost importance. Many times I have come across people who believe that because an anti-virus program is installed, they are protected, yet the last time the virus data file was updated was months or even years ago. Even missing one update could bring down your computer and the business you have struggled so long to build.

Also remember to password protect the settings on the software so no-one else can alter protection levels.

Firewall software

Anti-virus software isn't enough - it's also a good idea to install firewall software which will help prevent unauthorized incoming and outgoing communications from your computer while connected to the Internet. In most instances you wouldn't even be aware that these illegitimate probes and scans of your systems are occurring. Port scanning is *very* common and is carried out with a view to finding weaknesses in your system that can then be exploited.

If you are using Windows XP, then you're in luck as there's already an effective firewall included - but it's not enabled by default.

To activate the firewall in Windows XP:

- Go to "Start"
- Go to "Settings", then "Network connections"
- Select your Internet connection
- Click on "Properties"
- Click on "Advanced"
- Check the box in the "Internet Connection Firewall" section

Email software preview windows

Some viruses, called worms, can infect your system without you clicking on attachments - they can execute in the message preview window. Many worms can cause your sensitive information and documents to be transmitted to millions of people. While the preview window is a handy feature, it's safest to turn it off.

To turn off the preview window in Outlook Express:

- Select "View" on the Menu Bar
- Select "Layout"
- Uncheck "Show Preview Pane"

To turn off the preview window in Outlook:

- Select "View" on the Menu Bar
- Select "Preview Pane" if it's not already greyed out
- You may need to repeat this for each top level mail folder

Consider email filtering services

More and more people are turning to 3rd party solutions for filtering email of spam and viruses as their inboxes become inundated with junk. Email filtering can be very effective in dramatically reducing security risks before the mail even has a chance to be collected by your email software. It not only reduces the risk, but also the amount of time and bandwidth used in retrieving your mail. Learn more about these services in our anti-spam & email filtering guide.

free trial email filtering service - stop spam today! Anti-spam - free trial offer!
Sick of spam/virus email clogging your inbox? You never have to look at these emails again. Simple to set up and use with your current email address!

Regularly remove spyware

If you and your familiar do a lot of surfing and downloading of shareware software, then it's likely you'll also accumulate your fair share of spyware. Spyware is a broad term applied to software applications that monitor your actions and report them to back to a company.

Some software companies use spyware that is incorporated into their software products to gather data about customers, which is often sold to other companies. An excellent free application for removing spyware can be downloaded from Spybot. Learn more about spyware

Not using it? - unplug it..

Disconnect your computer from the Internet when not in use. The longer you are connected to the Internet, the more opportunity you give for persons to gain unauthorized access. This is especially the case where your ISP provides you with a static IP, which usually occurs in broadband scenarios.

Audit your computer regularly

If your computer is used by others, carry out regular audits of the software on it and research any software that you discover that you haven't installed yourself. It's safest to make it a policy not to allow any software to be installed without your permission. Spybot again is a very effective tool for detecting and removing software that may be a security risk

Remember that your anti-virus software, firewalls and email filtering services should always be considered your last line of defense against software nasties - the first line of defense should be you.

Kid's *aren't* all computer whizzes

Monitor your children's computer usage carefully. They may seem to be "experts", but more often than not they will have very little idea of the ramifications of some of their actions whilst on the Internet. Close supervision is especially necessary in chat rooms as these are places where Script Kiddies and other undesirable elements of the online community are very active.

Password issues

If you must store usernames and passwords on your system, ensure they are contained in a document that is password protected. It is safest not to store any passwords on your computer. Don't let Windows "remember" passwords for you. Passwords should always be more than 8 characters long and contain a mixture of numbers and letters. Learn more about password security issues.

Logging out

Ensure that you log out of online services properly. Failure to do so can allow others who use your computer to gain access to those services and you can be blamed for their activities.

The fight against viruses, script kiddies and other online parasites isn't getting any easier for those of us involved with ecommerce; and as the years go by, more and more of our time and money will be spent on dealing with the darker side of the web.

We can only hope that in the future detection methods become so efficient and punishment becomes so harsh that these kinds of incidences stop occurring. But if the history of our species is any indicator - that's highly unlikely to happen.

Anti Hacking Basics

The only way to make a computer 100% hacker proof is to disconnect it from the internet or turn it off. Since this simply isn't feasible, the security-minded computer user attempts to make it 99% secure. There are a few common ways to accomplish this task.
They are:

* Firewalls
* Software
* Basic Computer Precautions

The only way to make a computer 100% hacker proof is to disconnect it from the internet or turn it off. Since this simply isn't feasible, the security-minded computer user attempts to make it 99% secure. There are a few common ways to accomplish this task.
They are:

* Firewalls
* Software
* Basic Computer Precautions

Some Basic Tips for Anti Hacking

Don't ignore operating system updates

Practically every day, some new security flaw is found in the most critical aspect of your business - the operating system on which all your other software runs. While it's a major pain in the butt to apply updates and patches so regularly, especially if you access the web via dialup, it's nonetheless of vital importance not to put off performing these tasks as part of regular maintenance.

Don't wait to be alerted via mainstream media of problems that have been discovered - more often than not, these notifications will be delayed. As a part of your daily routine, it's wise to visit the software vendors' site and keep abreast of any critical security updates. In the case of Microsoft, you'll need to go to the Windows Update site.

Anti-virus software used *properly*

Install anti-virus software and ensure that it's regularly updated - this is of the utmost importance. Many times I have come across people who believe that because an anti-virus program is installed, they are protected, yet the last time the virus data file was updated was months or even years ago. Even missing one update could bring down your computer and the business you have struggled so long to build.

Also remember to password protect the settings on the software so no-one else can alter protection levels.

Firewall software

Anti-virus software isn't enough - it's also a good idea to install firewall software which will help prevent unauthorized incoming and outgoing communications from your computer while connected to the Internet. In most instances you wouldn't even be aware that these illegitimate probes and scans of your systems are occurring. Port scanning is *very* common and is carried out with a view to finding weaknesses in your system that can then be exploited.

If you are using Windows XP, then you're in luck as there's already an effective firewall included - but it's not enabled by default.

To activate the firewall in Windows XP:

- Go to "Start"
- Go to "Settings", then "Network connections"
- Select your Internet connection
- Click on "Properties"
- Click on "Advanced"
- Check the box in the "Internet Connection Firewall" section

Email software preview windows

Some viruses, called worms, can infect your system without you clicking on attachments - they can execute in the message preview window. Many worms can cause your sensitive information and documents to be transmitted to millions of people. While the preview window is a handy feature, it's safest to turn it off.

To turn off the preview window in Outlook Express:

- Select "View" on the Menu Bar
- Select "Layout"
- Uncheck "Show Preview Pane"

To turn off the preview window in Outlook:

- Select "View" on the Menu Bar
- Select "Preview Pane" if it's not already greyed out
- You may need to repeat this for each top level mail folder

Consider email filtering services

More and more people are turning to 3rd party solutions for filtering email of spam and viruses as their inboxes become inundated with junk. Email filtering can be very effective in dramatically reducing security risks before the mail even has a chance to be collected by your email software. It not only reduces the risk, but also the amount of time and bandwidth used in retrieving your mail. Learn more about these services in our anti-spam & email filtering guide.

Regularly remove spyware

If you and your familiar do a lot of surfing and downloading of shareware software, then it's likely you'll also accumulate your fair share of spyware. Spyware is a broad term applied to software applications that monitor your actions and report them to back to a company.

Some software companies use spyware that is incorporated into their software products to gather data about customers, which is often sold to other companies. An excellent free application for removing spyware can be downloaded from Spybot. Learn more about spyware

Not using it? - unplug it..

Disconnect your computer from the Internet when not in use. The longer you are connected to the Internet, the more opportunity you give for persons to gain unauthorized access. This is especially the case where your ISP provides you with a static IP, which usually occurs in broadband scenarios.

Audit your computer regularly

If your computer is used by others, carry out regular audits of the software on it and research any software that you discover that you haven't installed yourself. It's safest to make it a policy not to allow any software to be installed without your permission. Spybot again is a very effective tool for detecting and removing software that may be a security risk

Remember that your anti-virus software, firewalls and email filtering services should always be considered your last line of defense against software nasties - the first line of defense should be you.

Kid's *aren't* all computer whizzes

Monitor your children's computer usage carefully. They may seem to be "experts", but more often than not they will have very little idea of the ramifications of some of their actions whilst on the Internet. Close supervision is especially necessary in chat rooms as these are places where Script Kiddies and other undesirable elements of the online community are very active.

Password issues

If you must store usernames and passwords on your system, ensure they are contained in a document that is password protected. It is safest not to store any passwords on your computer. Don't let Windows "remember" passwords for you. Passwords should always be more than 8 characters long and contain a mixture of numbers and letters. Learn more about password security issues.

Logging out

Ensure that you log out of online services properly. Failure to do so can allow others who use your computer to gain access to those services and you can be blamed for their activities.

The fight against viruses, script kiddies and other online parasites isn't getting any easier for those of us involved with ecommerce; and as the years go by, more and more of our time and money will be spent on dealing with the darker side of the web.

We can only hope that in the future detection methods become so efficient and punishment becomes so harsh that these kinds of incidences stop occurring. But if the history of our species is any indicator - that's highly unlikely to happen.

You've been hacked: What to do first!

You've been hacked: What to do first!
What should you do in the first five minutes after you discover your system has been hacked?


Sitting at your desk, you notice some odd activity in a log while you're looking into a user problem. The more you step through it, the more you are convinced that something is just not right. Your heart skips a beat when you realise that the system has been hacked.

At this point, you enter a stage of shock as you ask yourself, "How could this happen?" and "What do I do now?"

Although you'll find plenty of advice on how to keep your systems from being hacked, there are relatively few articles that will help you sort things out in the aftermath of an attack. So for the next three weeks, I'll present a series of articles that will explain what you should do in the first five minutes, in the first hour, and in the first week after you've discovered that an interloper has compromised your systems. This article will focus on the most immediate actions you must take to secure your system: evaluate, communicate, and disconnect.

Evaluate
The first question that you must answer after an attack (or preferably before) is what your objectives are. In most cases, the objectives are simple: prevent further intrusion and resolve the problem. However, in some cases, you will want to be able to positively identify the intruder and, in others, you will be focused on figuring out which vulnerability the hacker exploited.

Identify the intruder
It may be necessary to positively identify the intruder so that you can refer the matter to the police for further investigation and possible prosecution. Of course, this is not the most expedient way to get the systems back online and prevent further infection. Identifying intruders can be difficult, particularly if they have covered their tracks well. Despite Hollywood's portrayal of hackers easily being traced, someone who is routing traffic through several systems is not only difficult to find, but might be -- in all practical terms -- impossible to track down.

Identify the vulnerability
Another approach that some organisations take is to try to identify the specific vulnerability exploited. The thinking is that you want to patch the specific hole that allowed this intruder to gain access. By and large, this approaches the problem from a suboptimal perspective. A far better strategy is to attempt to identify all vulnerabilities and prevent any intruder from gaining access to your systems, rather than focusing on the one vulnerability this particular hacker exploited.

Many of today's security assessment tools will allow you to quickly test and resolve all vulnerabilities.

Return systems to operation
If this is the first time you have been attacked, you may find it simpler to forgo trying to pinpoint the intruder or the specific vulnerability that was exploited. In general, it is unlikely that you will be able to easily generate the logs you might need to target the origin of the intrusion.

Patching the vulnerabilities and returning systems to operation as soon as possible is the most straightforward approach. It reduces your risk and allows you to fortify your defences without worrying about the intruder continuing to take advantage of your systems.

Plan ahead
In many cases, organisations determine their course of action prior to an attack. But in an equal number of cases, organisations must make this their first order of business after an attack. In addition to determining your specific goals after an attack, you should consider executing a disaster recovery plan, if one exists for your organisation. Depending on the severity of the situation, it may make sense to treat the situation as if the data centre had been destroyed.

The one unique complication to activating a disaster recovery plan for an organisation is that it is typically centred on a known event with a known time. But with an intrusion into your network, you may not know exactly when the system was first compromised. This can complicate the recovery process because it may not be clear what set of backups should be restored for each system. Further complicating matters is the fact that some systems may have been compromised before others, so it may be necessary to repeat the restoration process several times while trying to determine when the first intrusion occurred and on which system.

Communicate
Once you have decided on your approach, you need to communicate to upper management what is happening -- or what you suspect is happening. This is perhaps the most difficult step and, because of that, it is one that is often skipped or delayed. But despite the potential for internal political problems, it is important to let business leadership understand what is happening so that everyone can plan for the steps required to resolve the problem. It will also give business leadership an opportunity to reaffirm the goal for problem resolution, whether that goal is to go after the intruder, target the vulnerability, or simply solve the problem as quickly as possible.

You should also communicate with your IT peers about the problem. You need everyone on the team to look for suspicious activity to ensure that the network is not further compromised. To that end, the more professionals involved who are aware of the problem, the more likely it is that nothing will slip through the cracks and be missed.

Conversely, you should not communicate with your users that you have detected an intrusion. An employee may have caused the breach, either by providing a password to a friend with the intention of allowing a breach or through something more innocent. It is a good idea to hold off on notifying employees until the HR department can communicate the company policy along with the message.

Finally, if you have a security infrastructure partner, communicate with it immediately that you have a potential situation. Even if you have only engaged the organisation in the past to perform a security audit, you should call it to indicate that you suspect that you have a problem. The intent here is not at this point to ask for help but rather to inform the partner so that it can be prepared to assist if necessary.

Disconnect
If you are not planning on attempting to identify the intruder or the vulnerability, you should disconnect the system or the entire internal network from the Internet as soon as possible. This prevents the intruder from working against you as you try to clean up the mess and also prevents further infections or data loss while you work on the systems.

One of the downsides of disconnecting is that people who want to use the system internally and externally will be unable to do so until the problem is resolved. This can exert substantial internal pressure to take shortcuts to get the systems back up again. But the natural desire to reconnect systems before a thorough evaluation of their status has been conducted is ill advised and typically leads to repeated intrusions while the problems with each of the servers are identified and resolved one-by-one.

The decision to disconnect the entire organisation from the Internet or to disconnect just one system or a few systems is a difficult call, particularly in the first five minutes. You will not have had time to evaluate which, if any, other systems have been compromised, so it is possible that removing a single system from the Internet may not resolve the problem. On the other hand, you may want the organisation to continue to function with as little disruption as possible.

Ultimately, the decision comes down to one of risk tolerance. How much risk is the organisation willing to accept to avoid some downtime? In most organisations, the risk of potential intruders greatly outweighs the desire to maintain availability of all systems. In other words, most organisations agree that it is important to disconnect from the Internet immediately so that the systems can be checked for signs of intrusion without the possibility of intruders attempting to cover their tracks.

Conclusion
The first few minutes after you discover an attack are likely to be stressful and confused, so it's important to have a plan of action in place before it happens. When you realise you've been attacked, make sure you identify your objectives in resolving the situation, communicate the situation promptly to business leadership and peers, and determine whether the problem requires you to disconnect one or more systems from the Internet. Deciding how to react to an attack is tricky, at best. The actions you take (or don't take) can have a huge impact on your organisation -- and on your reputation. However, following a plan for controlling the situation can make things less chaotic and start you down the right path to get things back on track.