Tampilkan postingan dengan label Hacking and Phreaking. Tampilkan semua postingan
Tampilkan postingan dengan label Hacking and Phreaking. Tampilkan semua postingan

Rabu, 24 November 2010

Hacker Malaysia Jebol Jaringan Komputer The Fed

NEW YORK, KOMPAS.com - Setebal apapun lapisan teknologi yang dibalutkan otoritas AS di jaringan komputer Federal Reserve Bank atau The Fed, nyatanya jebol juga. Tahu, siapa yang berhasil menembus jaringan tersebut? Seorang warga negara Malaysia!
Namanya Lin Mun Poo. Ia menemukan cara untuk masuk ke jaringan komputer The Fed di Cleveland, AS. Ia mengantongi lebih dari 400.000 nomor kartu kredit curian saat agen Secret Service menangkapnya di John F. Kennedy Airport, bulan lalu. Saat itu, ia sedang dalam perjalanan menuju New York untuk menghadiri pertemuan dengan hacker lain.
Saat ini, otoritas yang berwenang di AS tengah mencari tahu bagaimana ia bisa masuk jaringan komputer The Fed dan juga sejumlah institusi finansial utama lain di Negeri Uwak Sam itu. Poo diduga menjual dan mengeruk untung dari informasi yang ia curi dari institusi finansial tersebut. 
Jaksa Loretta Lynch menjelaskan, kasus ini merupakan contoh bagaimana kriminal maya menggunakan kemampuan mereka sebagai hacker untuk menyerang sistem keamanan finansial maupun nasional. Bila kasus ini terbukti, Poo harus siap menghadapi kehidupan di balik jeruji besi hingga 10 tahun.
Poo adalah warga negara Malaysia; dan melalui pertanyaan yang dilontarkan oleh agen rahasia, Poo mengakui sejumlah tindakan kriminalnya. Investigator menjelaskan, Federal Reserve di Cleveland sempat di-hack pada bulan Juni lalu; dan Poo berencana untuk menghabiskan sejenak waktunya di New York untuk menjebol mesin ATM dengan kartu curian yang dikantonginya. 
Juru bicara The Fed di Cleveland Fed menjelaskan, belum ada uang kontan maupun data yang dicuri ditengah upaya hacking oleh Poo.(Kontan/Femi Adi Soempeno)

Selasa, 17 Agustus 2010

71 Situs Indonesia Dikerjai "Hacker"

71 Situs Indonesia Dikerjai "Hacker"
KOMPAS.com — Menjelang peringatan kemerdekaan ke-65 Republik Indonesia, hacker atau peretas dari Indonesia justru bikin ulah di puluhan situs yang mayoritas milik lembaga resmi di Indonesia.
Mereka meninggalkan pesan begini, "DIRGAHAYU INDONESIA TANAH AIR PUSAKA JAYALAH BANGSAKU, JAYALAH NEGERIKU..MERDEKA!!"
Aksi itu dimotori peretas yang menyebut diri Aria Killnine a.k.a arianom, pendiri komunitas KiLL-9 CrEw dengan situsnya di Www.KiLL-9.Tk.
Daftar situs yang diretas terlihat di bawah nanti. Namun yang jadi pertanyaan, mengapa pula justru mereka menyerang situs milik anak bangsa sendiri?
Kompasianer Rakhjib Martapianur memberi tahu, "Mereka tidak melakukan perusakan terhadap site-site tersebut. Mereka hanya menitipkan file, sekaligus mengingatkan para admin site tersebut bahwa site yang mereka kelola rentan terhadap serangan oleh hacker-hacker luar Indonesia."
Rakhjib Martapianur mengakui, informasi itu dia ketahui dari temannya yang bergelut di dunia meretas. Dan, inilah daftar situs yang dititipkan pesan-pesan dari peretas itu:
1.    http://semestaberjaya.com/indonesiaku.php 2.    http://fs.uns.ac.id/indonesia.php 3.    http://unj.ac.id/indonesia.php 4.    http://www.unand.ac.id/foto/indonesia.htm 5.    http://el82itb.org/indonesia.htm 6.    http://unhalu.ac.id/staff/indonesia.htm 7.    http://www.adhiguna.ac.id/indonesia.htm 8.    http://www.stikes-insan-seagung.ac.id/indonesia.htm 9.    http://www.himsya.ac.id/indonesia.htm 10.    http://www.poltekpos.ac.id/indonesia.htm 11.    http://informatika.uin-malang.ac.id/COPYRIGHT.php 12.    http://www.mar-eng.its.ac.id/ina/akademik/admin/foto_berita/indonesia.htm 13.    http://kaltimprov.go.id/indonesia.php 14.    http://pengadilan.net/indonesia.php 15.    http://bkp.deptan.go.id/indonesia.htm 16.    http://kemenegpora.go.id/merdeka.html 17.    http://sifa.kemenegpora.go.id/merdeka.html 18.    http://www.lsf.go.id/merdeka.html 19.    http://pekalongankota.go.id/merdeka.html 20.    http://bpphp1.dephut.go.id/merdeka.html 21.    http://bpphp2.dephut.go.id/merdeka.html 22.    http://bpphp3.dephut.go.id/merdeka.html 23.    http://bpphp4.dephut.go.id/merdeka.html 24.    http://bpphp5.dephut.go.id/merdeka.html 25.    http://bpphp6.dephut.go.id/merdeka.html 26.    http://bpphp8.dephut.go.id/merdeka.html 27.    http://bpphp9.dephut.go.id/merdeka.html 28.    http://bpphp10.dephut.go.id/merdeka.html 29.    http://manmajenang.sch.id/files/indonesia.php 30.    http://spma-samarinda.sch.id/indonesia.htm 31.    http://smkn1kalasan.sch.id/merdeka.html 32.    http://smkn1madiun.sch.id/merdeka.html 33.    http://robbirodliyya.sch.id/merdeka.html 34.    http://smkypesampang.sch.id/merdeka.html 35.    http://www.smpn3kpj.sch.id/merdeka.html 36.    http://www.majesa.sch.id/merdeka.html 37.    http://smkypkpwk.sch.id/merdeka.html 38.    http://smpn5cirebon.sch.id/merdeka.html 39.    http://smpn2balen.sch.id/merdeka.html 40.    http://smpn1oku.sch.id/merdeka.html 41.    http://smkn6palembang.sch.id/merdeka.html 42.    http://smpn4gm.sch.id/merdeka.html 43.    http://smpn5lht.sch.id/merdeka.html 44.    http://manhokut.sch.id/merdeka.html 45.    http://mtsdarussalampkp.sch.id/merdeka.html 46.    http://smkn1barru.sch.id/merdeka.html 47.    http://sman3bantul.sch.id/merdeka.html 48.    http://sman1cepu.sch.id/merdeka.html 49.    http://smpn1piyungan-btl.sch.id/merdeka.html 50.    http://www.smansa-mjl.sch.id/merdeka.html 51.    http://smp1pra-bws.sch.id/merdeka.html 52.    http://smpn13bdg.sch.id/merdeka.html 53.    http://smpn1panumbangan.sch.id/merdeka.html 54.    http://smpmuh-ckn.sch.id/merdeka.html 55.    http://smkkpbe-bdg.sch.id/merdeka.html 56.    http://sditalamysubang.sch.id/merdeka.html 57.    http://sdnbjs2bdg.sch.id/merdeka.html 58.    http://www.smaplusbanyuasin.sch.id/merdeka.html 59.    http://www.smkn1samarinda.com/merdeka.html 60.    http://akademik.sma-alirsyad-clp.sch.id/merdeka.html 61.    http://sma-alirsyad-clp.sch.id/merdeka.html 62.    http://www.majesa.sch.id/merdeka.html 63.    http://www.bellarminus-bks.sch.id/merdeka.html 64.    http://sman2-wng.sch.id/merdeka.html 65.    http://www.sma1pekalongan.sch.id/merdeka.html 66.    http://kimomibutik.com/admin/foto_berita/indonesia.htm 67.    http://www.smart-v-indonesia.com/indonesia.php 68.    http://kabar-kini.com/indonesia.htm 69.    http://semestaberjaya.com/indonesia.php 70.    http://tikjo.my-php.net/indonesia.php 71.    http://www.pusatk3hiperkes.com/indonesia.htm

Kamis, 06 Agustus 2009

Hack Windows XP Admin Passwords


the easy way by Estyle, Jaoibh
and Azrael.
This hack will only work if the person that owns the machine
has no intelligence. This is how it works:
When you or anyone installs Windows XP for the first time your
asked to put in your username and up to five others.
Now, unknownst to a lot of other people this is the only place in
Windows XP that you can password the default Administrator Diagnostic
Account. This means that to by pass most administrators accounts
on Windows XP all you have to do is boot to safe mode by pressing F8
during boot up and choosing it. Log into the Administrator Account
and create your own or change the password on the current Account.
This only works if the user on setup specified a password for the
Administrator Account.
This has worked for me on both Windows XP Home and Pro.
-----------------------------------------------------------------------------
Now this one seems to be machine dependant, it works randomly(don't know why)
If you log into a limited account on your target machine and open up a dos prompt
then enter this set of commands Exactly:
(this appeared on www.astalavista.com a few days ago but i found that it wouldn't work
on the welcome screen of a normal booted machine)
-----------------------------------------------------------------------------
cd\ *drops to root
cd\windows\system32 *directs to the system32 dir
mkdir temphack *creates the folder temphack
copy logon.scr temphack\logon.scr *backsup logon.scr
copy cmd.exe temphack\cmd.exe *backsup cmd.exe
del logon.scr *deletes original logon.scr
rename cmd.exe logon.scr *renames cmd.exe to logon.scr
exit *quits dos
-----------------------------------------------------------------------------
Now what you have just done is told the computer to backup the command program
and the screen saver file, then edits the settings so when the machine boots the
screen saver you will get an unprotected dos prompt with out logging into XP.
Once this happens if you enter this command minus the quotes
"net user password"
If the Administrator Account is called Frank and you want the password blah enter this
"net user Frank blah"
and this changes the password on franks machine to blah and your in.
Have fun
p.s: dont forget to copy the contents of temphack back into the system32 dir to cover tracks
Any updates, Errors, Suggestions or just general comments mail them to either



Jumat, 05 Juni 2009

TUTORIAL LAN Hacking (Buat Newbie yang mau belajar hack)

Cara hacking via LAN (untuk curi pass orang2 yang lagi browsing)
Pertama-tama sorry kalo repost karena teknik ini bukanlah teknik yang fresh di dunia hacking tapi teknik ini belum basi karena sampai saat ini masih dapat digunakan karena sebagian besar jaringan meggunakan jaringan hub & switch yang tidak terenkripsi.
Mengapa tidak terenkripsi?
* Network Admin sebagian besar adalah orang IT yang specialist dalam membuat program, bukan dalam Network Security
* Bila dienkripsi bandwidth yang dibuthkan akan meningkat dan tentu inet yang sudah lemot ini akan semakin lemot dan akhirnya page error
* Harganya tidak murah untuk memperoleh yang terenkripsi
Perbedaan antara jaringan Hub dan Switch:
* Pada jaringan hub semua data yang mengalir di jaringan dapat dilihat/diambil oleh komputer manapun yang ada di jaringan asalakan komputer tersebut merequest data tersebut, kalo tidak direquest ya tidak akan datang.
* Pada jaringan switch hanya komputer yang melakukan pertukaran data yang dapat melihat data tersebut, komputer2 lain tidak berhak merequest data tersebut.
Masalahnya adalah harga dari router hub dan switch tidak berbeda jauh sehingga kebanyakan tempat sekarang sudah menggunakan metode switch yang menyulitkan untuk network hacking.
Hacking ini menggunakan teknik:
* Sniffing
* ARP Poison Routing
Kedua Teknik di atas tidak akan bisa dicegah oleh firewall apapun di komputer korban, dijamin.
Important Note: ARP Poison Routing dapat meyebabkan denial of service (dos) pada salah satu / semua komputer pada network anda
Kelebihan:
* Tidak akan terdeteksi oleh firewall tipe dan seri apapun karena kelemahannya terletak pada sistem jaringan bukan pada komputernya
* Bisa mencuri semua jenis login password yang melalui server HTTP
* Bisa mencuri semua login password orang yang ada di jaringan Hub selama program diaktifkan
* Untuk ARP Poisoning bisa digunakan untuk mencuri password di HTTPS
* Semua programnya free
Kekurangan:
* Untuk jaringan Switch harus di ARP poisoning 1 persatu dan bandwidth anda akan termakan banyak untuk hal itu (kalo inet super cepat ga masalah)
* Ketahuan / tidak oleh admin jaringan di luar tanggung jawab saya
Mulai dari sini anggap bahwa di network dalam kisah ini ada 3 komputer, yaitu:
* Komputer Korban
* Komputer Hacker
* Server
Perbedaan-perbedaan antara jaringan switch dan jaringan hub:
Langkah-langkah pertama:
1. Cek tipe jaringan anda, anda ada di jaringan switch / hub. Jika anda berada di jaringan hub bersyukurlah karena proses hacking anda akan jauh lebih mudah.
2. Download program-program yang dibutuhkan yaitu Wireshark dan Cain&Abel.
Code:
http://www.wireshark.org/download.html
http://www.oxid.it/cain.html
Cara Menggunakan WireShark:
* Jalankan program wireshark
* Tekan tombol Ctrl+k (klik capture lalu option)
* Pastikan isi pada Interfacenya adalah Ethernet Card anda yang menuju ke jaringan, bila bukan ganti dan pastikan pula bahwa “Capture packets in promiscuous mode” on
* Klik tombol start
* Klik tombol stop setelah anda merasa yakin bahwa ada password yang masuk selama anda menekan tombol start
* Anda bisa melihat semua jenis packet yang masuk dan keluar di jaringan (atau pada komputer anda saja jika network anda menggunakan Swtich
* Untuk menganalisis datanya klik kanan pada data yang ingin di analisis lalu klik “Follow TCP Stream” dan selamat menganalisis paketnya (saya tidak akan menjelaskan caranya karena saya tidak bisa )
* Yang jelas dari data itu pasti di dalamnya terdapat informasi2 yang dimasukkan korban ke website dan sebaliknya
Cara di atas hanya berlaku apabila jaringan anda adalah Hub bukan switch
Dari cara di atas anda dapat mengetahui bahwa jaringan anda adalah hub/switch dengan melihat pada kolom IP Source dan IP Destination. Bila pada setiap baris salah satu dari keduanya merupakan ip anda maka dapat dipastikan jaringan anda adalah jaringan switch, bila tidak ya berarti sebaliknya.
Cara Menggunakan Cain&Abel:
* Penggunaan program ini jauh lebih mudah dan simple daripada menggunakan wireshark, tetapi bila anda menginginkan semua packet yang sudah keluar dan masuk disarankan anda menggunakan program wireshark
* Buka program Cain anda
* Klik pada bagian configure
* Pada bagian “Sniffer” pilih ethernet card yang akan anda gunakan
* Pada bagian “HTTP Fields” anda harus menambahkan username fields dan password fields nya apabila yang anda inginkan tidak ada di daftar.
Sebagai contoh saya akan beritahukan bahwa kalo anda mau hack password Friendster anda harus menambahkan di username fields dan passworsd fields kata name, untuk yang lain anda bisa mencarinya dengan menekan klik kanan view source dan anda harus mencari variabel input dari login dan password website tersebut. Yang sudah ada di defaultnya rasanyan sudah cukup lengkap, anda dapat mencuri pass yang ada di klubmentari tanpa menambah apapun.
* Setelah itu apply settingannya dan klik ok
* Di menu utama terdapat 8 tab, dan yang akan dibahas hanya 1 tab yaitu tab “Sniffer” karena itu pilih lah tab tersebut dan jangan pindah2 dari tab tersebut untuk mencegah kebingungan anda sendiri



* Aktifkan Sniffer dengan cara klik tombol sniffer yang ada di atas tab2 tersebut, carilah tombol yang tulisannya “Start/Stop Sniffer”
* Bila anda ada di jaringan hub saat ini anda sudah bisa mengetahui password yang masuk dengan cara klik tab (Kali ini tab yang ada di bawah bukan yang di tengah, yang ditengah sudah tidak usah diklik-klik lagi) “Passwords”
* Anda tinggal memilih password dari koneksi mana yang ingin anda lihat akan sudah terdaftar di sana
* Bila anda ternyata ada di jaringan switch, ini membutuhkan perjuangan lebih, anda harus mengaktifkan APR yang tombolonya ada di sebelah kanan Sniffer (Dan ini tidak dijamin berhasil karena manage dari switch jauh lebih lengkap&secure dari hub)
* Sebelum diaktifkan pada tab sniffer yang bagian bawah pilih APR
* Akan terlihat 2 buah list yang masih kosong, klik list kosong bagian atas kemudian klik tombol “+” (Bentuknya seperti itu) yang ada di jajaran tombol sniffer APR dll
* Akan ada 2 buah field yang berisi semua host yang ada di jaringan anda
* Hubungkan antara alamat ip korban dan alamat ip gateway server (untuk mengetahui alamat gateway server klik start pada komp anda pilih run ketik cmd lalu ketik ipconfig pada command prompt)
* Setelah itu baru aktifkan APR, dan semua data dari komp korban ke server dapat anda lihat dengan cara yang sama.
Anda dapat menjalankan kedua program di atas secara bersamaan (Cain untuk APR dan wireshark untuk packet sniffing) bila ingin hasil yang lebih maksimal.
Password yang bisa anda curi adalah password yang ada di server HTTP (server yang tidak terenkripsi), bila data tersebut ada di server yang terenkripsi maka anda harus mendekripsi data tersebut sebelum memperoleh passwordnya (dan itu akan membutuhkan langkah2 yang jauh lebih panjang dari cara hack ini)
Untuk istilah-istilah yang tidak ngerti bisa dicari di wikipedia (tapi yang inggris ya kalo yang indo jg belum tentu ada).


Minggu, 03 Mei 2009

The REAL way to hack Remote Access

"Saving the Brain Forest" Well dewdz, ya seen the file text about hacking RemoteAccess and you wanna crack that H/P or warez RA board for mega ratios? Get Real! RA *CAN* be hacked but only in the same way as any other BBS sox... no sysop reading that file was shat themselves .. here's why not: Basically the technique outlined involved you writing a trojan and disguising it as some program the sysop is really gagging for in the hope is he'll run it on his system. Wot it'll really do is copy his USER.BBS onto the filebase so you can call back later and d/l it... neat idea, and one that in *theory* will work with most BBS sox (most are EVEN easier coz they don't encrypt the users file like RA) but their execution of it sucks! Firstly, their compiled batch file relied on the sysop running RA off their C: drive from the directory \RA... Yeah, maybe some lame PD board they hang out on is like that but most sysops I know run multiple drives and many have more complex directory structures... Lame Hacker 0 - Sysop 1 Okay... letz assume they got on some lame fucking board and the users file *is* C:\RA\USERS.BBS - next step is to copy the file into the filebase and make it d/lable. How do they do that? (patronising Dez Lymon voice) . Their idea was to copy the file into D:\FILES\UPLOAD .. Yeah sure guyz... EVERY board uses the D: drive for the filebase and happen to have a file area in \FILES\UPLOAD - NOT!!!!!! Lame Hacker 0 - Sysop 2 Right, so they got better odds than winning the national fucking lottery and all the above worked (yeah man, we're dreamin' but let's give 'em a chance). What next? The file has to be d/lable... you found a sysop that makes UNCHECKED & UNSCANNED files available for download? Fuck off! Get a life! Lame Hacker 0 - Sysop 3 So... okay.... we got a sysop that's so fucking lame he doesn't deserve to to breath the same air as the rest of the human race and uses all the above paths and makes unchecked uploads d/lable. RA by default won't allow files to be d/led UNLESS they're in the file database. Unless the USERS.BBS destination ALREADY EXISTED in that area and was previously in the area database there's NO WAY you can d/l it. The way they "solved" this was to add an entry to FILES.BBS in the file directory. Nice one... EXCEPT RA DOESN'T USE FILES.BBS AS IT'S FILE DATABASE. Unless you happen to be lucky enough that the sysop does an import from FILES.BBS to the REAL file database before checking out your planted file (most RA sysops only import from FILES.BBS when adding CDROMs) the addition of this entry will do FUCK ALL! Lame Hacker 0 - Sysop 4 To quote from the author "This is a generic program and you will have to tailor it so it will meet your needs." - yeah man, fucking rethink, redesign and rewrite it more like! Oh yeah... EVEN IF YOU DO get a copy of the USER.BBS file downloaded THE PASSWORDS ARE ENCRYPTED!!! Lame Hacker :( - Sysop:-) So how can U hack RA? Well, the idea was okay but, like hacking any system, you gotta KNOW the system ya gonna hack b4 U stand a chance. Most sysops will use the DOS environment variable RA set to the RA system directory so that external doors can find the system files... that's very helpful of the sysop, to show us where we can find his config files. In the RA system directory should be the file CONFIG.RA. You might want to include a check for this file within your program and possibly do a disk and directory scan for the file if RA isn't defined or is set incorrectly. I'm not *entirely* sure about other versions of RA, but in the current release (2.02) the CONFIG.RA offset &h3E4 is where the name of the mail directory starts. This is the path where USERS.BBS will be found. Next you need to know for SURE the name of a directory which stores the files for a filearea from which you are able to download. I suggest you do this in one of three ways: 1) Interogate the file FILES.RA in the RA system directory which contains the filebase area configs. You *could* just search the directory for a valid path but you'd wouldn't know if you had d/l access to the area. 2) If you want to be a bit more clever you could interpret the file and find out the minimum security level required to d/l from each area and dump your copy of USERS.BBS in the area with the lowest access level, pretty much guaranteeing that you'll be able to get to the file. This doesn't take security flags into account so there's still a SLIM possiblity you won't be able to d/l the file unless you also write flag testing into your program. 3) My favourite technique is to have the program read a small config file which is uploaded with your archive. This file just contains the name of a file you KNOW you have d/l access from. You can then either do a global search for that filename or, preferably (coz it's faster) read FILES.RA for the paths used by the filebase and search those. So now you have the location of the USERS.BBS and the destination directory you simply need to copy the file. However, even though the file is sitting in a filebase directory it STILL isn't available for d/l... why? Because it's not in the filearea database. You could get clever and find amend filearea database files directly if you get the fileareas path from CONFIG.RA (offset &hC12) and write to the files HDR\FBD#####.HDR (header) IDX\FDB#####.IDX (index) and, if you want to add a description, TXT\FBD#####.TXT, where ##### is the RA file area number.

There *is* an easier way. Shell out to DOS and execute the RAFILE utility from the RA program path, passing the arguments "ADOPT filename #####". E.g. the BASIC command would be: SHELL "RAFILE ADOPT "+filename$+STR$(areanum) Where filename$ contains the name of your USERS.BBS copy and areanum is the RA filearea number. If your filename was USERTEST.ZIP and you'd copied it to the directory used for RA file area 10 you'd be executing: RAFILE ADOPT USERTEST.ZIP 10 This will "adopt" the file, adding it to the RA file database, making it available for d/l (assuming you have the appropriate rights to the area). All you need to do now is to package this trojan file to entice the sysop into running it... In the LAME method for hacking RA the author used DSZ as an example. That was about the most realistic part of the file and the only bit worth leaching! Your archive: DSZ.EXE (your program) DSZ.DAT (the *real* DSZ.EXE) DSZ.CFG (small file containing the name of a *known* d/lable file - preferabbly encrypted) + any other files that normally come with DSZ Flow diagram for DSZ.EXE trojan: _______ / \ | Start | \_______/ | | +--------+--------+ | Read enviroment | | variable RA | +--------+--------+ | | / \ / \ /CONFIG.RA\ +---------------------+ / exist in \___>____| Scan drives & paths | \ that path / No | search for the file | \ ? / +----------+----------+ \ / | \ / | Yes | | +------------<-------------+ | +--------+--------+ | Read CONFIG.RA | | to get location | | of USERS.BBS | +--------+--------+ | | +--------+--------+ | Read DSZ.CFG to | | get a filename | +--------+--------+ |_____________<____________ | | +--------+--------+ | | Read FILES.RA to| | | get name of the | | | next filearea | | +--------+--------+ | | | | | / \ | / \ | /does area\ | / contain the \________>__________| \ file / No \ ? / \ / \ / Yes | | +--------+--------+ | Copy USERS.BBS | | to the filearea | | directory | +--------+--------+ | | +--------+--------+ | Run RAFILE with | | ADOPT to update | | RA database | +--------+--------+ | | +--------+--------+ | Delete DSZ.EXE | | and DSZ.CFG | +--------+--------+ | | +--------+--------+ | Rename DSZ.DAT | | to DSZ.EXE | +--------+--------+ | ___|___ / \ | Stop! | \_______/ Once you've uploaded the file, preferably using a pseudonym, post the sysop a message telling him how c00l your upload is. Wait a day or so and dial back. Do a filename search using the name you decided to use for your copy of USERS.BBS and d/l it. The next step, now you have the USERS.BBS file is to crack the passwords. I only know of ONE crack program out there which has the RA password encryption algorythm, a program based on the popular Unix CRACKERJACK program called RA-CRACK. This simply takes a given word, encrypts it, and compares it to the USERS.BBS file to find a user with a matching password. RA-CRACK takes it's source words from a text file so it would be possible to either: a) Use a TXT dictionary file as the source. All passwords that are normal words will be found. This method will usually find about 90% of the user passwords. b) Write a "brute force" cracker using a small routine that "counts" through valid ASCII character combinations from "!" (ASCII 33) upto a string containing 25 (max length of a RA password) null characters (ASCII 255), passing these via a text file to RA-CRACK. This SHOULD be _100%_ successful, but SLOW! l8r! >ByTe<>RyDeR<

Kamis, 30 April 2009

HACKING TECHNIQUES

1) CALLBACK UNITS: Callback units are a good security device, But with most phone systems, it is quite possible for the hacker to use the following steps to get around a callback unit that uses the same phone line for both incomming and out going calls:First, he calls he callback unit and enters any authorized ID code (this is not hard to get,as you'll see in a moment). After he enters this ID, the hacker holds the phone line open - he does not hang up. When the callback unit picks up the phone to call the user back, the hacker is there, waiting to meet it. The ID code as I said, is simple for a hacker to obtain, because these codes are not meant to be security precautions.The callback unit itself provides security by keeping incomming calls from reaching the computer. The ID codes are no more private than most telephone numbers. Some callback units refer to the codes as "location identification numbers," and some locations are used by several different people,so their IDs are fairly well known.I've been told that, in some cases,callback ubits also have certain simple codes that are always defined by default. Once the hacker has entered an ID code and the callback unit has picked up the phone to re-call him,the hacker may or may not decide to provide a dial tone to allow the unit to "think" it is calling the correct number. In any event, the hacker will then turn on his computer, connect with the system - and away he goes.If the however, the hacker has trouble holding the line with method,he has an option: the intercept. The Intercept: Holding the line will only work with callback units that use the same phone lines to call in and to call out.Some callback units use different incoming and outgoing lines, numbers 555-3820 through 555-3830 are dedicated to users' incoming calls, and lines 555-2020 through 555-2030 are dedicated to the computers outgoing calls.The only thing a hacker needs in order to get through to these systems is a computer and a little time - he doesn't even need an ID code. First,the hacker calls any one of the outgoing phone lines, which, of course, will not answer.Sooner or later, though, while the hacker has his computer waiting there, listening to the ring, an authorized user will call one of the incomming lines and request to be called back. It will usually be less than an hours wait, but the hacker's computer is perfectly capable of waiting for days, if need be. The callback unit will take the code of the authorized user, hang up, verify the code, and pick up the phone line to call back.If the unit tries to call out on the line the hacker has dialed, the hacker has his computer play a tone that sounds just like a dial tone.The computer will then dial the number given that matches up with the user's authorized ID. After that,the hacker can just connect his computer as he would in any other case.If he is really serious,he will even decode the touch tones that the mainframe dialed,figure out the phone number of the user the system was calling, call the person, and make a few strange noises that sound as though the computer called back but didnt work for some reason. 2) TRAPDOORS AS A POSSIBLILITY I haven't heard of this happening, but i think it is possible that a callback modem could have a trapdoor built into it.Callback modems are run by software, which is written by programmers.An unscrupulous programmer could find it very easy to slip in an unpublicized routine, such as, "if code =*43*, then show all valid codes and phone numbers." And such a routine, of course, would leave security wide open to anyone who found the trapdoor.The obvious protection here, assuming the situation ever arises, is simply an ethical manufactorer that checks its software thoroughly before releasing it. A trapdoor is a set of special instructions embedded in the large program that is the operating system of a computer.A permanent, hopefully secret "doorway", these special instructions enabe anyone who knows about them to bypass normal security procedures and to gain access to the computer's files.Although they may sound sinister, trapdoors were not invented by hackers, although existing ones are certainly used by hackers who find out about them.

3) THE DECOY One of the more sophisticated hacking tools is known as the decoy, and it comes in three versions.The first version requires that the hacker have an account on the system in question. As in my case,the hacker has a low-security account,and he tries this method to get higher-security account.He will first use his low-security account to write a program that will emulate the log-on procedures of the systems in questions. This program will do the following: *- Clear the terminal screen and place text on it that makes everything look as if the system is in charge. *- Prompt for, and allow the user to enter, both an account name and a password. *- Save that information in a place the hacker can access. *- Tell the use the account/password entries are not acceptable. *- turn control of the terminal back over to the system. The user will now assume that the account name or password was mistyped and will try again...this time (scince the real operating system is in control) with more success.You can see a diagram of the way these steps are accomplished ___________________ | Clear Terminal | | screen | |____________________| || _________||_________ | Print Compuserve | | Computer | |_____ Network ______| || _________||_________ | Print "ENTER | | PASSWORD" |______ |____________________| | || | _________||_________ | | PASSWORD ENTERED? |__NO__| |____________________| ||_YES _________||_________ | SAVE PASSWORD | | INFORMATION | |____________________| || _________||_________ | PRINT "LOGIN | | INCORRECT | |____________________| || _________||_________ | LOG OFF/RETURN | | CONTROL TO | | OPERATING SYSTEM | |____________________| 4) CALL FORWARDING Many people use call forwarding by special arrangement with the phone company.When a customer requests call forwarding, the phone company uses its computer to forward all the customers incomeing calls to another number. Lets say, for example, that you want calls that come to your office phone to be forwarded to your home phone: A call from you to the phone company,some special settings in the phone companys computer, and all calls to your office will ring at your home instead.This little bit of help from the phone company is another tool used by hackers. Lets say you thought that the computer you were hacking into was being watched-because the sysop might have seen you and called the fed's and your sort of bugged by this nagging feeling that they will trace the next hacker that calls, just call the phone company and ask for call forwarding, pick a number, (ANY NUMBER) out of the phone book and have your calls forwarded to that number,Hea,Hea, the number you picked is the one that will be traced to, not yours, so you could be hacking away,they think that they have traced you, but actually the number you had your calls forwarded too. they enter chat mode and say (YOUR BUSTED!!!!, WE'VE TRACED YOUR PHONE NUMER THE FEDS ARE ON THE WAY!!), You could reply (Hea, SURE YA DID! I'D LIKE TO SEE YA TRY AND GET ME! GO AHEAD!) ,that wont seem very important to them at the time, but it will sure piss them off when they bust the wrong guy! 5) RAPID FIRE Memory-location manipulation can be helpful, but there is another, more powerful,possibility, in some cases: the Rapid-fire method.To understand how this methos works, you have to know something about the way operationg systems work.When a user enters a command, the operating system first places the command in a holding area, a buffer, where it will sit for a few millionths of a second.The system looks at the command and say's "Does this person really have authorization to do this, or not?" Then, the command sits there a few thousandths of a second while the system runs off to check the user's authorization.When the system comes back to the command, it will have one of two possible answers: "OK, GO AHEAD," or "SORRY, GET PERMISSION FIRST." Once you are on a system that handles things this way, you can