Pages

Friday, May 4, 2012

Have your own Domain Name for your PC??

So how to get the public Domain name?
1. Go to no-ip.com, and create and account.
2. Login and Click on the button Add a Host inside members page.

3. Write the host name you like in text box. And Select DNS Host(a) option.
4. Enter your IP address. To know your IP address go to command prompt and type ipconfig, first field is your IP address.

5. Click the button create host. You can clearly see that that your Host name is listed.
note:- you can create maximum of three hosts.
6. Download there dynamic DNS update client for windows(or linux) and run it in your PC.
7. Open the "No-Ip Duc" from start menu and click on select host and select any host you created.
8. Now test, if its working open the browser and type in your host name example http://hostname.zapto.org.

Use Proxy Chaining to hide your IP

Proxy chaining is a method of connecting to multiple proxy servers before connecting to your intended server. This method can be very effective in hiding your IP address(for anonymity) or we can say it will be very difficult to trace the IP address when we use multiple proxies. We can use as many proxy we want but it will certainly decrease our internet speed too.
client(browser)-->server(website)
client(browser)-->proxy-->server(website)
client(browser)--->proxy1--->proxy2-->proxy3--->proxy3--->proxy(n)-->server(website)
In this post i will be sharing 2 methods to accomplish proxy chaining.
1. Using websites
2. Using tools

Method1- Using websites
In this method we will use different websites that provides anonymous surfing services( free proxy services) like:-
Likewise find other websites which provides similar services, to search for such websites just type:  related:zend2.com in Google search box.

Now go to any such website and type the URL of another proxy service website and inside that type another proxy website and finally type your required website. This way you can create proxy chain of any length.
your browser-->zend2.com-->proxify.com-->vectroproxy.com-->your website name


Method2- Using tools:
Proxy Chain Builder Click Here to download.
Install and run this tool.
Features:
1. you can connect to 30 different proxies in a single chain.


2. You can add any number of proxy list. The program will automatically rank as per your settings.



3. Check the status to see, which proxy server is used at that moment.

Proxy Server Agent: to download.
Install and open proxy server agent and click on proxy, inside that click on "add" button and add the proxies. For list of proxies, go to  freeproxylists.net.

Now click on "chains" and select the proxy chain type and create a new chain(click on add)  and inside that chain add proxy from the list.

Note: The type of proxy in the chain and the last proxy in the chain must be of same type.

Wednesday, April 25, 2012

Play famous 'Snake Game' on Youtube!





Today I'm going to tell you how to play the famous 'snake game' on Youtube.com.

All you have to do is press -

" left mouse button+left arrow+up arrow"

on the screen where video is there. Once you do this,your game starts.For better play i'll recommend you to type ''black screen'' on youtube and you'll get some videos with black screen, so that you can see the snake properly.If you get out, then refresh the page and start again! have fun!!




Tuesday, April 24, 2012

STEALING PASSWORD USING GOOGLE HACK


Google is a treasure trove full of important information, especially for the underground world. This Potential fact can also be utilized in the data for the username and password stored on a server.

If the administrator save important data not in the complete system authentication folder, then most likely be reached by the google search engine. If data is successfully steal in by the unauthorized person, then the will be in misuse.

Here, some google search syntax to crawl the password:

1. "Login: *" "password =*" filetype: xls (searching data command to the system files that are stored in Microsoft Excel)

2. allinurl: auth_user_file.txt (to find files auth_user_file.txt containing password on server).

3. filetype: xls inurl: "password.xls" (looking for username and password in ms excel format). This command can change with admin.xls)

4. intitle: login password (get link to the login page with the login words on the title and password words anywhere. If you want to the query index more pages, type allintitle)

5. intitle: "Index of" master.passwd (index the master password page)

6. index of / backup (will search the index backup file on server)

7. intitle: index.of people.lst (will find web pages that contain user list).

8. intitle: index.of passwd.bak ( will search the index backup password files)

9. intitle: "Index of" pwd.db (searching database password files).

10. intitle: "Index of .. etc" passwd (this command will index the password sequence page).

11. index.of passlist.txt (will load the page containing password list in the clear text format).

12. index.of.secret (google will bring on the page contains confidential document). This syntax also changed with government query site: gov to search for government secret files, including password data) or use syntax: index.of.private

13. filetype: xls username password email (will find spreadsheets filese containing a list of username and password).

14. "# PhpMyAdmin MySQL-Dump" filetype: txt (will index the page containing sensitive data administration that build with php)

15. inurl: ipsec.secrets-history-bugs (contains confidential data that have only by the super user). or order with inurl: ipsec.secrets "holds shared secrets"

16. inurl: ipsec.conf-intitle: manpage (useful to find files containing important data for hacking)

17. inurl: "wvdial.conf" intext: "password" (display the dialup connection that contain phone number, username and password)

18. inurl: "user.xls" intext: "password" (showing url that save username and passwords in spread sheet files)

19. filetype: ldb admin (web server will look for the store password in a database that dos not delete by googledork)

20.inurl: search / admin.php (will look for php web page for admin login). If you are lucky, you will find admin configuration page to create a new user.

21. inurl: password.log filetype:log (this keyword is to search for log files in a specific url)

22. filetype: reg HKEY_CURRENT_USER username (this keyword used to look for reg files (registyry) to the path HCU (Hkey_Current_User))

Here, some of the other syntax google that we need to look for confidential data :

"Http://username: password @ www ..." filetype: bak inurl: "htaccess | passwd | shadow | ht users"
(this command is to take the user names and passwords for backup files)

filetype:mdb inurl:”account|users|admin|administrators|passwd|password” mdb files (this command is to take the password information)

filetype:ini ws_ftp pwd (searching admin password with ws_ftp.ini file)

intitle: "Index of" pwd.db (searching the encrypted usernames and passwords)

inurl:admin inurl:backup intitle:index.of (searching directories whose names contain the words admin and backup)

“Index of/” “Parent Directory” “WS _ FTP.ini” filetype:ini WS _ FTP PWD (WS_FTP configuration files is to take FTP server access passwords)

ext:pwd inurl:(service|authors|administrators|users) “# -FrontPage-” (there is Microsoft FrontPage passwords)

filetype: sql ( "passwd values ****" |" password values ****" | "pass values ****") searching a SQL code and passwords stored in the database)

intitle:index.of trillian.ini (configuration files for the Trillian IM)

eggdrop filetype:user (user configuration files for the Eggdrop ircbot)

filetype:conf slapd.conf (configuration files for OpenLDAP)

inurl:”wvdial.conf” intext:”password” (configuration files for WV Dial)

ext:ini eudora.ini (configuration files for the Eudora mail client)

filetype: mdb inurl: users.mdb (potentially to take user account information with Microsoft Access files)

intext:”powered by Web Wiz Journal” (websites using Web Wiz Journal, which in its standard configuration allows access to the passwords file – just enter http:///journal/journal.mdb instead of the default http:///journal/)

“Powered by DUclassified” -site:duware.com "Powered by DUclassified"-site: duware.com
“Powered by DUcalendar” -site:duware.com "Powered by DUcalendar"-site: duware.com
“Powered by DUdirectory” -site:duware.com "Powered by DUdirectory"-site: duware.com
“Powered by DUclassmate” -site:duware.com "Powered by DUclassmate"-site: duware.com
“Powered by DUdownload” -site:duware.com "Powered by DUdownload"-site: duware.com
“Powered by DUpaypal” -site:duware.com "Powered by DUpaypal"-site: duware.com
“Powered by DUforum” -site:duware.com "Powered by DUforum"-site: duware.com

intitle:dupics inurl:(add.asp | default.asp |view.asp | voting.asp) -site:duware.com (websites that use DUclassified, DUcalendar, DUdirectory, DUclassmate, DUdownload, DUpaypal, DUforum or DUpics applications, by default allows us to retrieve passwords file)

To DUclassified, just visit http:///duClassified/ _private / duclassified.mdb
or http:///duClassified/ or http:///duClassified/


intext: "BiTBOARD v2.0" "BiTSHiFTERS Bulletin Board" (Bitboard2 use the website bulletin board, the default settings make it possible to retrieve the passwords files to be obtained with the ways http:///forum/admin/data _ passwd.dat
or http:///forum/forum.php) or http:///forum/forum.php)

Searching for specific documents :

filetype: xls inurl: "email.xls" (potentially to take the information contact)

“phone * * *” “address *” “e-mail” intitle:”curriculum vitae”
CVs "not for distribution" (confidential documents containing the confidential clause
buddylist.blt)

AIM contacts list AIM contacts list

intitle:index.of mystuff.xml intitle: index.of mystuff.xml

Trillian IM contacts list Trillian IM contacts list

filetype:ctt “msn” filetype: Note "msn"

MSN contacts list MSN contacts list

filetype:QDF
(QDF database files for the Quicken financial application)

intitle: index.of finances.xls (finances.xls files, potentially to take information on bank accounts, financial Summaries and credit card numbers)

intitle: "Index Of"-inurl: maillog (potentially to retrieve e-mail account)

download GOOGLE hack from  HERE

Hope you enjoy.....

Related Posts Plugin for WordPress, Blogger...