နည္းပညာဗဟုသုတ ျပည့္၀ၾကပါေစ

Showing posts with label Hacking. Show all posts
Showing posts with label Hacking. Show all posts

Friday, May 2, 2014

Hacking Ebooks ( 45 ) အုပ်စုစည်းမှု


 သည်စာအုပ်လေးတွေကတော့ Hacking စိတ်ဝင်စားသူများအတွက် စုစည်းထားခြင်းဖြစ်ပါတယ်.. စာအုပ်ပေါင်း 45 အုပ်ပါရှိပါတယ်..ကဲ လေ့လာမယ်ဆိုရင်တော့ အောက်မှာ ဒေါင်းယူလိုက်ပါနော်..
ညီလေး it helper ကနေစုစည်းပေးထားခြင်းဖြစ်ပါတယ်..နော်.. ကဲဆွဲလိုက်ကြဗျာ....

အဆင်ပြေပါစေ

<<<တာဝန်မလေးပါကတချက်လောက်ကလစ်ပေးခဲ့စေလို>>>

ခုလိုအားပေးတဲ့အတွက် အထူးကျေးဇူးတင်ပါကြောင်း ပြောကြားပါရစေ..ဘလော့ခရီးသည်မှ နည်းပညာများအား မည်သူမဆို လွတ်လပ်စွာ ကူးယူသုံးစွဲနိုင်ပါတယ်.. ကျွန်တော် ပိုင်ဆိုင်သောနေရာလေးများအား ဆက်လက် လည်ပါတ်လိုပါက ***************************************
ဘလော့ခရီးသည်သို့ { ဒီမှာ } သွားလိုက်ပါ
လယ်တီမြေသားသို့{ ဒီမှာ } သွားလိုက်ပါ
စာပေနန်းတော်သို့{ ဒီမှာ } သွားလိုက်ပါ
စွယ်စုံစာအုပ်စင်{ ဒီမှာ } သွားလိုက်ပါ
Rate this posting:
{[['']]}

Tuesday, April 29, 2014

မိမိ account အဟက်မခံရအောင် ကြိုတင်ကာကွယ်နည်း

ခုတလော facebook အကောင့်တွေ gmail တွေ အဟက်ခံရတာကို ခဏခဏ ကြားနေရပါတယ်။ နည်းပညာဗဟုသုတအားနည်းလို့ အဟက်ခံရသလို ပညာရှိသတိဖြစ်ခဲလို့လဲ အဟက်ခံနေကြရခြင်းပါ။ မမိုးသိသလောက် မမိုးအကောင့်ကို ဘယ်လိုကာကွယ်ထားလဲ ဆိုတာလေး နည်းပညာအားနည်းသူများအတွက် ပြန်လည်မျှဝေပေးပါတယ်။ နှစ်သစ်မှာ မိမိ account လေးများကို မိမိကိုယ်တိုင်ကာကွယ်နိုင်မယ်လို့ မျှော်လင့်ပါတယ်ရှင်။


Hacker တွေ account တွေကို ဘယ်လိုနည်းလမ်းတွေ သုံးပြီး hack နေကြလဲ ?  


လေ့လာမိသလောက်လေးပါ၊ Hacking နဲ့ ပတ်သက်တဲ့ Hack နည်းတွေ ဒါပဲရှိတာမဟုတ်ဘူးနော်။ လတ်တလော ကြုံနေရတဲ့ Hack နည်းတွေကို ရှောင်ရှားနို်င်ဖို့ပါ။ account များ ပေါပါတယ်၊ အလကားရနေတာပဲလို့ မမှတ်နဲ့နော်၊ ကိုယ့်အကောင့် ကိုယ်သုံးလာတဲ့ အချိန်ပေါ် မူတည်ပြီး ကိုယ့်ရဲ့ personal တွေ အများကြီးရှိနေတယ်ဆိုတာ မမေ့ပါနဲ့။ အဟက်ခံရပြီးမှ ပြန်လိုက်ရတာထက် ကြိုပြီး ကာကွယ်နိုင်တော့ မမှားဘူးပေါ့။

ခုတလော ဟက်ကာတွေ ဟက်နေတဲ့ နည်းလမ်းတွေကတော့

1. Phishing

2. Keylogger

3. Add ons စတာတွေကို အဓိကသုံးပြီး Hack နေကြတာပါ။ 

4. trusted contacts ဒါကတော့ ခုမှ စပြီးသုံးနေတယ်လို့ ထင်ပါတယ်။ အရင်ကသိပ်မကြားဖူးလို့ပါ။



1. Phishing 
     Phishing ဆိုတာ Facebook, Gmail စတာတွေရဲ့ Home Page အတုတွေပါ။ Phishing တွေကို ဘယ်ကနေ တွေ့နိုင်လဲ? လွယ်ပါတယ် Hack မယ့်သူက မျှားထားတဲ့ page အတုတွေပါ။ link လေး တခုချထားပေးမယ်၊ အဲဒီ link ကို click လိုက်တာနဲ့ Facebook Log in page, Gmail Log in page လေး ကျလာမှာပါ။ ဒါကို ကိုယ်က နည်းပညာပိုင်းဆိုင်ရာ အားနည်းတော့ မသိပဲ email နဲ့ password ကို ရိုက်ပြီး ဝင်လိုက်တာနဲ့ Hacker ရဲ့ ထောင်ချောက်ထဲရောက်ပြီး ကိုယ့်ရဲ့ gmail နဲ့ facebook account တွေ Hacker ရဲ့ Hosting လို့ခေါ်တဲ့ online ပေါ်က နေရာလေး တခုမှာ ရောက်သွားပါတယ်။ ဒါဆို ကိုယ့်ရဲ့ အကောင့်က Hacker ရဲ့ ပိုင်ဆိုင်မှုကို ခံရပြီပေါ့။ ဒီအကောင့်ကို ပြန်ပြီး လိုက်လို့မရနိုင်ဘူးလား ဆိုတော့ အချိန်ပေးပြီး နည်းပညာသုံးပြီး ပြန်လိုက်မယ်ဆိုရင် ရလဲ ရနိုင်သလို မိမိအကောင့်က Hacker ရဲ့ ကျွမ်းကျင်မှုပေါ်မူတည်ပြီး ချယ်လှယ်တာခံလိုက်ရရင်တော့ အခြေအနေတမျိုးဖြစ်သွားမှာပေါ့။ ဒါကြောင့် ဒီစာပိုဒ်လေးကို ဖတ်ပြီးရင် မိမိနဲ့ မရင်းနှီးတဲ့ သူ ပေးတဲ့ မည်သည့် link ကိုမှ Click မနှိပ်မိပါစေနဲ့။ Link ကို နှိပ်လိုက်ရင် Email and Password တောင်းပြီဆိုရင် ပိတ်လိုက်ပါ။ လုံးဝ မရိုက်ထည့်လိုက်ပါနဲ့။ ဒါဆို Phishing နဲ့ hack ခြင်းကို ကာကွယ်နိုင်ပြီပေါ့။

2. Keylogger
     ပထမဆုံး Keylogger အကြောင်းပြောပြမယ်။ Keylogger ဆိုတာ ကိုယ့်ရဲ့စက်ထဲမှာ ကိုယ် မမြင်ရပဲ အနောက်မှာ run နေပြီး ကိုယ့်ရဲ့ အချက်အလက်တွေကို Keylogger ရဲ့ ပိုင်ရှင်ရဲ့ email ဆီသို့ အဆက်မပြတ် ပေးပို့နေသော ထောက်လှမ်း ဆော့ဝဲတမျိုးပါ။ Keylogger အမျိုးအစားတွေမှာ keylogger ဝင်နေတဲ့စက်မှာ အချိန်ကိုက် screen shoot ဓာတ်ပုံရိုက်သွားတဲ့ keylogger (ဒီ keylogger လေး ကို အသုံးပြုနေတဲ့ user မှ လုံးဝမသိနိုင်ဘဲ keylogger software သွင်းထားသူသာ ကိုယ်ပိုင် password ဖြင့် ဝင်ရောက် ကြည့်ရှုနိုင်ပြီး အကျိုးပြုတဲ့ keylogger ဆိုလဲ မမှားပါဘူး၊ ဘာကြောင့် အကျိုးပြုလဲဆိုတော့ မိဘတွေ ကိုယ့်သားသမီးတွေ Internet ကို ဘာတွေအတွက် သုံးနေကြလဲ? မကြည့်သင့်တာတွေ ကြည့်နေလား? မသုံးသင့်တာတွေ သုံးနေလား? စသည်ဖြင့် သိစေတဲ့အတွက် အကျိုးပြု keylogger လို့ မမိုးနာမည်ပေးထားတာပါ။ နောက်တခု အကျိုးမဲ့ keylogger။ ဒါကတော့ hacker တွေရဲ့ လက်စွဲပါ။ keylogger တခုကို software သုံးပြီး ကိုယ်တိုင်ဖန်တီးလို့ရနိုင်သလို online ပေါ်ကရနိုင်တဲ့ keylogger တွေ အများကြီးမို့ hacker တွေအတွက် အလွယ်တကူ အသုံးပြုနေတဲ့ နည်းတခုပါ။ ဒီထက် အဆင့်မြင့်တဲ့ programming language တွေနဲ့ အဆင့်မြင့်မြင့်ရေးလို့ ရပါသေးတယ်။ ကဲဒါတော့ ထားလိုက်ပါတော့။ Hacker တွေ user တွေရဲ့ စက်ထဲကို keylogger ကို ဘယ်လိုထည့်လဲဆိုတာ နည်းနည်းပြောပြမယ်နော်။ user တွေ စိတ်ဝင်စားတဲ့ photo, ebooks, video,... စတာတွေမှာ ကပ်ပြီး user တွေဆီ ချပေးပါတယ် ဒါကို မသိပဲ download လုပ်မိပြီး double click နှိပ်လိုက်တာနဲ့ ကိုယ့်ရဲ့စက်ထဲမှာ သကောင့်သားက မွှေတော့တာပဲ၊ ပြီးရင် သူ့သခင်ဆီကို အချက်အလက်တွေ အဆက်မပြတ် ပို့တော့တာပေါ့။ key ရိုက်သမျှ အားလုံး ချိတ်ဆက်ထားတဲ့ keylogger ပိုင်ရှင်ရဲ့ email ကို data တွေ ပို့ပါတယ်။ ဒီနည်းလမ်းနဲ့ user ရဲ့ အကောင့်၊ password ကို hacker တွေ ရရှိရတာပါ။ Keylogger ပိုင်ရှင်တွေ ဘယ်လို အရာတွေကို keylogger မြှုတ်တတ်သလဲ? အရိုးရှင်းဆုံးပါ၊ လူအများ စိတ်ဝင်စားနိုင်တဲ့ လတ်တလော ဖြစ်ပျက်နေတဲ့ photo, video တွေကို အသုံးချတတ်ပါတယ်၊ ဥပမာ - မလေးရှားလေယာဉ်နဲ့ ပတ်သက်တဲ့ video file လေးပါ၊ သတင်းကို စိတ်ချရတဲ့ သတင်းဌာနတွေကပဲ ဖတ်သင့်ပါတယ်၊ video ကိုလဲ သတင်းဌာနတွေကပဲ တိုက်ရိုက် ကြည့်သင့်ပါတယ်။ နောက်တခု sexy နဲ့ ပတ်သက်တဲ့ ဓာတ်ပုံတွေ video တွေကို ရှောင်သင့်ပါတယ်။ ဒါတွေက hacker တွေရဲ့ ထောင်ချောက်တွေဆိုတာ မမေ့ပါနဲ့။ မမိုးကြုံဖူးတာလေး တခုကို ဗဟုသုတအနေနဲ့ ပြောပြချင်ပါတယ်။ ebooks တအုပ်ကို ဒေါင်းဖို့ ဖွင့်လိုက်တာ လေးထောင့်တွေပဲ တွေ့ရတယ် ကိုယ့်ရဲ့ အကျင့်ကလဲ ကိုယ်ယုံကြည်တဲ့သူမဟုတ်ရင် အဲစာအုပ်ကို အရင် သေချာ စစ်တတ်တယ်။ လေးထောင့်တွေဆိုတော့ မသင်္ကာလို့ save လုပ်ပြီး notepad ထဲပြောင်းကူးတော့ script တွေနဲ့ ရေးထားတဲ့ keylogger တမျက်နှာ တိတိတွေ့ခဲ့ရပါတယ်။ ဒါကတော့ ဗဟုသုတအဖြစ်ပြောတာနော်။ 

keylogger စစ်ဖို့ မမိုးကတော့ စက်ထဲမှာ MSE (Microsoft Security Essential) နဲ့ Malwarebytes ၂မျိုးနဲ့ အမြဲတမ်း စစ်ဖြစ်ပါတယ်။ ကိုယ့်ရဲ့ စက်ထဲမှာ keylogger ရှိပြီလို့ ထင်ရင် windows ချလိုက်တာ အကောင်းဆုံးပါပဲ။ တခုတော့ သတိပေးချင်တယ် ကိုယ်ကတော့ ဒါတွေကို ရှောင်ပေမယ့် ကိုယ့်စက်မှာ မျှယူသုံးစွဲသူက မရှောင်ရင်လဲ hacker ရဲ့ ထောင်ချောက်ထဲ သက်ဆင်းရမှာမို့ အကောင်းဆုံး အကြံပေးချင်တာကတော့ computer တလုံးကို ၁ယောက်ထဲ သုံးစေချင်တယ်။ ဒါမှမဟုတ် မျှဝေသုံးစွဲသူကို ဗဟုသုတလေးတွေ ပြောပြထားသင့်တယ်။ နောက်တနည်းက ကိုယ့်ရဲ့ password ကို keyboard ကနေ ရိုက်မဝင်ပဲ windows မှာ ပါတဲ့ on screen keyboard မှ ဝင်သည်ဖြစ်စေ၊ notepad တွင် password ကို save ထားပြီး အကောင့်ဖွင့်တိုင်း copy and paste နဲ့ ဝင်ပေါ့။ အချို့ အဆင့်မြင့် keylogger တွေ on screens keyboards ရော notepad ကိုရော ရှာနိုင်တယ်လို့ နိုင်ငံခြား ဆိုဒ်တခုမှာ ဖတ်ဖူးပါတယ်။ ဟုတ်မဟုတ် မမိုးလဲ မကြုံဖူးလို့ အတတ်မပြောနိုင်ပါဘူး။ အကောင်းဆုံး နည်းလမ်းကတော့ ကိုယ့်ရဲ့စက်ကို မှန်မှန်လေး စစ်ပေးသင့်ပါတယ်။ ဒီလောက်ဆို keylogger ကို ကာကွယ်နိုင်မယ်လို့ ထင်ပါတယ်။


3. Add ons

     Hacker တွေရဲ့ အဓိက ပစ်မှတ်တခုပေါ့။ လတ်တလော အသုံးအများဆုံး hack နည်းလေးပါ။ add ons တခု ဖန်တီးပြီး ဒီ add ons လေးကတော့ internet connection ကို ၂ဆတို့ ၄ဆတို့ ဆိုပြီး မက်လုံးပေးပြီး link ကို ချပေးတတ်တယ်။ ဒါကို ယုံကြည်တဲ့သူတွေက install လုပ်တော့ အကောင့်တွေ တန်းစီပြီး ပါပြန်ရောပေါ့။ အရင်က Mozilla Firefox တခုကိုပဲ target ထားလို့ firefox သုံးတဲ့သူတွေ တော်တော်များများ ခံလိုက်ကြရပါတယ်။ ခု Maxthon browser ဘက်ကို ဦးတည်နေကြပြီ။ ဘယ်အတွက်ပဲ ထုတ်ထား ထုတ်ထား အဓိက ကိုယ်မသုံးမိရင် အကောင့်ပါမှာ မဟုတ်ပါဘူး။ မမိုးဆို add ons ဘယ်တော့မှ သုံးလေ့မရှိပါဘူး။ add ons တောင်းတဲ့သူတွေကိုလဲ browser ရဲ့ official site မှာပဲ ရှာပြီး ပေးလေ့ရှိပါတယ်။ သေချာမသိရင် ဘာမှမသုံးတာ အကောင်းဆုံးပါ။ ကိုယ့်ရဲ့ account ကို ကိုယ်တိုင်ကလွဲပြီး ဘယ်သူမှ မကာကွယ်နိုင်ပါဘူး။


4. trusted contacts

     မိမိ account lock ကျရင် trusted contacts မှာ ထည့်ထားတဲ့ သူငယ်ချင်း အနည်းဆုံး (၃)ယောက်ဆီကို facebook မှ code ပို့ပေးခြင်းပါ။ ဒီနည်းနဲ့ ဘယ်လို hack မလဲ စဉ်းစားစရာနော်။ မမိုးသေချာတော့ မရေးပြတော့ဘူး မသမာသူလက်ထဲကို ရောက်မှာ ဆိုးလို့ပါ။ အဓိက အချက်ကိုပဲ ပြောတော့မယ်။ trusted contacts list မှာ မိမိ ကိုယ်ပိုင် account များကိုသာ ထည့်ထားသင့်ပါတယ်။ ဒီလောက်ပဲ အကြံပြုပါရစေ။ သူခိုးဓားရိုးမကမ်းချင်လို့ပါ။ 

မမိုးရေးတဲ့ ဒီစာပိုဒ်လေးက နည်းပညာနဲ့ပတ်သက်ပြီး ဗဟုသုတ အနည်းငယ် ရခဲ့မယ်ဆိုရင် ကျေနပ်ပါတယ်။ IT Family Magazine မှာ ရေးဖို့ စဉ်းစားထားပေမယ့် အချိန်မလုံလောက်လို့ မရေးဖြစ်ခဲ့ပါ။ ဘယ်အချိန်ရေးရေး ဘယ်နေရာရေးရေး စာဖတ်သူ ဗဟုသုတ အနည်းငယ် ရသွားတယ်ဆိုရင်ပဲ ဝမ်းသာပါတယ်။ Hacking က ဒါပဲလားလို့တော့ မပြောနဲ့နော်။ သိချင်ရင် Hacker တွေဆီသာ တိုက်ရိုက်သွားမေးကြပါ။ မမိုးဘာမှမသိပါဘူး။ ကိုယ့် account ကိုယ် ကာကွယ်ထားရုံလေးကို ပြန်လည်မျှဝေတာပါ။



လက်ရှိ တွေ့ကြုံနေရသည်များကိုသာ ရည်ညွှန်းသည်။
နည်းပညာဗဟုသုတပြည့်ဝကြပါစေ


Rate this posting:
{[['']]}

Sunday, April 6, 2014

ဘလော့ဂါများနှင့်ဆို်င်ဘာအတိုက်အခံသမားများအတွက်လက်စွဲ [3.3Mb]

နယ်စည်းမခြား သတင်းထောက်များအဖွဲ့
 မှရေးသားပြုစုထားပါတယ်...


<<<တာဝန်မလေးပါကတချက်လောက်ကလစ်ပေးခဲ့စေလို>>>

ခုလိုအားပေးတဲ့အတွက် အထူးကျေးဇူးတင်ပါကြောင်း ပြောကြားပါရစေ..ဘလော့ခရီးသည်မှ နည်းပညာများအား မည်သူမဆို လွတ်လပ်စွာ ကူးယူသုံးစွဲနိုင်ပါတယ်.. ကျွန်တော် ပိုင်ဆိုင်သောနေရာလေးများအား ဆက်လက် လည်ပါတ်လိုပါက ***************************************
ဘလော့ခရီးသည်သို့ { ဒီမှာ } သွားလိုက်ပါ
လယ်တီမြေသားသို့{ ဒီမှာ } သွားလိုက်ပါ
စာပေနန်းတော်သို့{ ဒီမှာ } သွားလိုက်ပါ
စွယ်စုံစာအုပ်စင်{ ဒီမှာ } သွားလိုက်ပါ
Rate this posting:
{[['']]}

Saturday, March 22, 2014

Best Hacking Operating System and Download

1. kali Linux http://www.kali.org/downloads/

2. BackTrack 5r3 http://www.backtrack-linux.org/downloads/

3. NodeZero. http://www.nodezero-linux.org/downloads

4. BackBox Linux http://www.backbox.org/downloads

5. Blackbuntu. http://www.pen-tests.com/blackbuntu-download.html

6. Samurai Web Testing Framework. http://sourceforge.net/projects/samurai/files/

7. Knoppix STD. http://s-t-d.org/download.html

8. Pentoo. http://www.pentoo.ch/download/

9. WEAKERTH4N. http://hr.weaknetlabs.com/

10. Matriux Krypton. http://www.ulozto.net/xC6VodE/linux-matriux-krypton-1-2-iso

11. DEFT. http://www.deftlinux.net/download/

12. CAINE http://www.caine-live.net/page5/page5.html


                                  Ebook ကို အောက်တွင် download လုပ်ယူနိုင်သည်။


Ebooks ယူရန် click နှိပ်ပြီး download လုပ်ပါ။




နည်းပညာဗဟုသုတပြည့်ဝကြပါစေ
Rate this posting:
{[['']]}

Friday, March 21, 2014

How to Become a Hacker (ဟက်ကာတယောက်ဖြစ်ဖို့ ဘာတွေလေ့လာသင့်လဲ)

  • Learn TCP/IP, Basic Information gathering,Proxies, Socks, SSL, VPN, VPS, RDP, FTP, POP3, SMTP, Telnet, SSH.
  • Learn Linux, Unix, Windows - You can do this using vmware or any virtual desktop utility.
  • Learn a programming language that's compatible with all OS - Perl, Python, C .
  • Learn HTML, PHP, Javascript, ASP, XML, SQL, XSS, SQLI, RFI,LFI
  • Learn Reverse engineering and crack some programs for serials easy ones like mirc, winzip, winrar or old games.
  • Code a fuzzer for common protocols - ftp, pop3, 80, 8080 - Pick some free software like ftp server, mail server, apache or iis webserver or a webserver all-in-one pack, or teamspeak, ventrilo, mumble.
  • Code a tool that uses grep to sort out unique code in source codes.
  • Make a custom IPtable, IPsec firewall that blocks all incoming traffic and out going traffic and add filters to accept certain ports that your software or scripts use.
  • Pick a kernel in linux or unix, also pick a Microsoft OS version lets say Winxp pro sp2 put them on the virtual desktops (vmware) and find and code a new local exploit in those versions, then install a Apache webserver on the Linux/Unix and a IIS webserver on the winxp pro and attempt to find and code a new local reverse_tcp_shell exploit.
  • Learn Cisco Router and Switch configuration and setup.
  • Learn Checkpoint Setup and Config.
  • Learn Wifi scanning,cracking, sniffing.
  • Pick a person in you phonebook for the area code you live in or city then ring the person on a anonymous line like skype or a payphone or a carded sim and attempt to social engineer the person forhis name, address, data of birth, city born, country born, ISP connected with, Phone company connected with, What bank he/she uses and anything else you can get. Then Attempt to ring using a spoof caller ID software with the person's phone number - call the ISP and try reset the password to his/her internet connection/ webmail, get access to bank account or ask them to send out a new *** to a new address (drop) with a new pin, reset of phone company passwords.
  • Use your information gathering skills to get all the information off a website like a shop then use the spoofcallerID software or hack your phone to show a new number of the Webserver's Tech Support number then ring the shop owner and try get the shop site password.
  • Do the same thing but attempt to use a web attack against a site or shop to gainadmin access.
  • Once got access upload a shell and attempt to exploit the server to gain root using aexploit you coded not someone else s exploit.
  • Make your own Linux Distro
  • Use your own Linux Distro or use a vanilla Linux gnome (not kde) keep it with not much graphics so you can learn how to depend on the terminal and start from scratch install applications that you will only need for a blackbox (Security test box), make folders for fuzzers, exploits, scanners..etc Then load them up with your own scripts and other tools (By this stage you shouldn't need to depend on other peoples scripts).
  • Learn macosx and attempt to gain access to a Macosx box whether it be your own or someones elses.
  • Create a secure home network and secure your own systems with your own Security policies and firewall settings. All this isn't a over night learning it will take a nice 3 - 4 years to learn a bit of this 5+ years to learn most of it and even then you may need time to keep learn as IT keeps changing everyday. This tutorial has been written By Ayubkhan And ahmed taker and is NOT for public distribution.All information in this tutorial is for educational purposes only. Any illegal activity relating to this tutorial is not my responsibility, although I would like to say I don't care how you use it, I do. So please do not use this for Black-hat activities. One day when you grow up you might realise that you have been a skid, by using mass-deface techniques and SQLi for your entire life. Do not just hack a site because it is there. I have a few sites of my own and its annoying, unproductive, and pointless.


Ayub Khan


Ebooks ကို အောက်တွင် download လုပ်ပါ။



Click နှိပ်ပြီး Download လုပ်ပါ။



နည်းပညာဗဟုသုတပြည့်ဝကြပါစေ
မိုး(နည်းပညာများ)

Rate this posting:
{[['']]}

Thursday, December 12, 2013

Hacker တယောက်ဖြစ်ဖို့ ဘာတွေလေ့လာရမလဲ ?




1. Learn TCP/IP, Basic Information gathering,Proxies, Socks, SSL, VPN, VPS, RDP, FTP, POP3,

SMTP, Telnet, SSH.

2. Learn Linux, Unix, Windows - You can do this using vmware or any virtual desktop utility.

3. Learn a programming language that's compatible with all OS - Perl, Python, C .

4. Learn HTML, PHP, Javascript, ASP, XML, SQL, XSS, SQLI, RFI,LFI

5. Learn Reverse engineering and crack some programs for serials easy ones like mirc,

winzip, winrar or old games.

6. Code a fuzzer for common protocols - ftp, pop3, 80, 8080 - Pick some free software like

ftp server, mail server, apache or iis webserver or a webserver all-in-one pack, or

teamspeak, ventrilo, mumble.

7. Code a tool that uses grep to sort out unique code in source codes.

8. Make a custom IPtable, IPsec firewall that blocks all incoming traffic and out going

traffic and add filters to accept certain ports that your software or scripts use.

9. Pick a kernel in linux or unix, also pick a Microsoft OS version lets say Winxp pro sp2

put them on the virtual desktops (vmware) and find and code a new local exploit in those

versions, then install a Apache webserver on the Linux/Unix and a IIS webserver on the winxp

pro and attempt to find and code a new local reverse_tcp_shell exploit.

10. Learn Cisco Router and Switch configuration and setup.

11. Learn Checkpoint Setup and Config

12. Learn Wifi scanning,cracking, sniffing.

13. Pick a person in you phonebook for the area code you live in or city then ring the

person on a anonymous line like skype or a payphone or a carded sim and attempt to social

engineer the person forhis name, address, data of birth, city born, country born, ISP

connected with, Phone company connected with, What bank he/she uses and anything else you

can get.Then Attempt to ring using a spoof caller ID software with the person's phone number

- call the ISP and try reset the password to his/her internet connection/ webmail, get

access to bank account or ask them to send out a new *** to a new address (drop) with a new

pin, reset of phone company passwords.

14. Use your information gathering skills to get all the information off a website like a

shop then use the spoofcallerID software or hack your phone to show a new number of the

Webserver's Tech Support number then ring the shop owner and try get the shop site password.

15. Do the same thing but attempt to use a web attack against a site or shop to gainadmin

access.

16. Once got access upload a shell and attempt to exploit the server to gain root using

aexploit you coded not someone else s exploit.

17. Make your own Linux Distro

18. Use your own Linux Distro or use a vanilla Linux gnome (not kde) keep it with not much

graphics so you can learn how to depend on the terminal and start from scratch install

applications that you will only need for a blackbox (Security test box), make folders for

fuzzers, exploits, scanners..etc Then load them up with your own scripts and other tools (

By this stage you shouldn't need to depend on other peoples scripts).

19. Learn macosx and attempt to gain access to a Macosx box whether it be your own or

someones else s.

20. Create a secure home network and secure your own systems with your own Security policies and firewall settings. All this isn't a over night learning it will take a nice 3 - 4 years to learn a bit of this 5+ years to learn most of it and even then you may need time to keep learn as IT keeps changing everyday.

This tutorial has been written By Ayubkhan And ahmed taker and is NOT for public distribution.All information in this tutorial is for educational purposes only. Any illegal activity relating to this tutorial is not my responsibility, although I would like to say I don't care how you use it, I do. So please do not use this for Black-hat activities. One day when you grow up you might realise that you have been a skid, by using mass-deface techniques and SQLi for your entire life. Do not just hack a site because it is there. I have a few sites of my own and its annoying, unproductive, and pointless.

Ayub Khan
Rate this posting:
{[['']]}

Monday, October 28, 2013

Command Prompt Basics (Ethical Hacking)



Hacking ပိုင်းလေ့လာလိုသူများအတွက် အဓိက CMD Basic များကို ပြန်လည်မျှဝေပေးလိုက်ပါတယ်ရှင်... အားလုံးပဲ တနေ့ကို ၅ကြောင်းလောက်သာ မှတ်သွား၊ ၂၁ရက်ဆို အားလုံးကို အလွတ်ရပီ။ Hacking သမားများအတွက်သာမက Technician များအတွက်ပါ အကျိုးရှိပါတယ်။

1. Accessibility Controls - access.cpl
2. Accessibility Wizard - accwiz
3. Add Hardware Wizard - hdwwiz.cpl
4. Add/Remove Programs - appwiz.cpl
5. Administrative Tools - control admintools
6. Automatic Updates - wuaucpl.cpl
7. Bluetooth Transfer Wizard - fsquirt
8. Calculator - calc
9. Certificate Manager - certmgr.msc
10. Character Map - charmap
11. Check Disk Utility - chkdsk
12. Clipboard Viewer - clipbrd
13. Command Prompt - cmd
14. Component Services - dcomcnfg
15. Computer Management - compmgmt.msc
16. Control Panel - control
17. Date and Time Properties - timedate.cpl
18. DDE Shares - ddeshare
19. Device Manager - devmgmt.msc
20. Direct X Troubleshooter - dxdiag
21. Disk Cleanup Utility - cleanmgr
22. Disk Defragment - dfrg.msc
23. Disk Management - diskmgmt.msc
24. Disk Partition Manager - diskpart
25. Display Properties - control desktop
26. Display Properties - desk.cpl
27. Dr. Watson System Troubleshooting Utility - drwtsn32
28. Driver Verifier Utility - verifier
29. Event Viewer - eventvwr.msc
30. Files and Settings Transfer Tool - migwiz
31. File Signature Verification Tool - sigverif
32. Findfast - findfast.cpl
33. Firefox - firefox
34. Folders Properties - control folders
35. Fonts - control fonts
36. Fonts Folder - fonts
37. Free Cell Card Game - freecell
38. Game Controllers - joy.cpl
39. Group Policy Editor (for xp professional) - gpedit.msc
40. Hearts Card Game - mshearts
41. Help and Support - helpctr
42. HyperTerminal - hypertrm
43. Iexpress Wizard - iexpress
44. Indexing Service - ciadv.msc
45. Internet Connection Wizard - icwconn1
46. Internet Explorer - iexplore
47. Internet Properties - inetcpl.cpl
48. Keyboard Properties - control keyboard
49. Local Security Settings - secpol.msc
50. Local Users and Groups - lusrmgr.msc
51. Logs You Out Of Windows - logoff
52. Malicious Software Removal Tool - mrt
53. Microsoft Chat - winchat
54. Microsoft Movie Maker - moviemk
55. Microsoft Paint - mspaint
56. Microsoft Syncronization Tool - mobsync
57. Minesweeper Game - winmine
58. Mouse Properties - control mouse
59. Mouse Properties - main.cpl
60. Netmeeting - conf
61. Network Connections - control netconnections
62. Network Connections - ncpa.cpl
63. Network Setup Wizard - netsetup.cpl
64. Notepad - notepad
65. Object Packager - packager
66. ODBC Data Source Administrator - odbccp32.cpl
67. On Screen Keyboard - osk
68. Outlook Express - msimn
69. Paint - pbrush
70. Password Properties - password.cpl
71. Performance Monitor - perfmon.msc
72. Performance Monitor - perfmon
73. Phone and Modem Options - telephon.cpl
74. Phone Dialer - dialer
75. Pinball Game - pinball
76. Power Configuration - powercfg.cpl
77. Printers and Faxes - control printers
78. Printers Folder - printers
79. Regional Settings - intl.cpl
80. Registry Editor - regedit
81. Registry Editor - regedit32
82. Remote Access Phonebook - rasphone
83. Remote Desktop - mstsc
84. Removable Storage - ntmsmgr.msc
85. Removable Storage Operator Requests - ntmsoprq.msc
86. Resultant Set of Policy (for xp professional) - rsop.msc
87. Scanners and Cameras - sticpl.cpl
88. Scheduled Tasks - control schedtasks
89. Security Center - wscui.cpl
90. Services - services.msc
91. Shared Folders - fsmgmt.msc
92. Shuts Down Windows - shutdown
93. Sounds and Audio - mmsys.cpl
94. Spider Solitare Card Game - spider
95. SQL Client Configuration - cliconfg
96. System Configuration Editor - sysedit
97. System Configuration Utility - msconfig
98. System Information - msinfo32
99. System Properties - sysdm.cpl
100. Task Manager - taskmgr
101. TCP Tester - tcptest
102. Telnet Client - telnet
103. User Account Management - nusrmgr.cpl
104. Utility Manager - utilman
105. Windows Address Book - wab
106. Windows Address Book Import Utility - wabmig
107. Windows Explorer - explorer ................................ By Shivam Panchal.
Rate this posting:
{[['']]}

Twitter Facebook More