Showing posts with label hack. Show all posts
Showing posts with label hack. Show all posts

11/5/12

WILD LEAKY LEAK. FULL VMware ESX Server Kernel LEAKED




Anonymous group member "Stun" announce the leak of VMware ESX Server Kernel source code via twitter today. The tweet reads,  "WILD LEAKY LEAK. FULL VMware ESX Server Kernel LEAKED LINK #Anonymous #AntiSec". VMware ESX is an enterprise-level computer virtualization product offered by VMware. The reason behind this wild leak by anonymous is that, Vmware continue producing on same level again and again which is not a good practice for better Security.

"Bullshitting people and selling crap. But it's time for Anonymous finally to deliver. Ofc VMware will try to make like this Kernel is old and isn't used in its recent products. But thanks god, there is still such as thing as reverse engineering that will prove it's true destiny." Hacker said.
VMware+ESX+Server+Kernel

A 1.89 MB uploaded on torrent and titled "VMware ESX Server Kernel LEAKED". I have download the archive and file inside archive as shown above. Dump seems to be produced by reversing the product.

Before in Sep 2012 the Symantec Norton Utilities 2006 source code was also leaked by same member.

Update: We just have an  interview with STUN:
Q: Whether its a reversed engineered version or original dump ?
A: That's original version from 1998 / 2004 still used on several products. And as we are aware kernels don't change that often...

Q: Do you think,this leak will seriously create any impact on VMWARE users? Like crooks can use the source to to reproduce something malicious?
A: Leak aware the people about the drawback of products, they are paying for is shitless when it upto security.

Update: VMware blog post published earlier today confirmed that code is real but its part of an old hack. that ,"our security team became aware of the public posting of VMware ESX source code dating back to 2004. This source code is related to the source code posted publicly on April 23, 2012. It is possible that more related files will be posted in the future. We take customer security seriously and have engaged our VMware Security Response Center to thoroughly investigate."
- See more at: http://thehackernews.com/2012/11/anonymous-leaks-vmware-esx-server-kernel.html?utm_source=dlvr.it&utm_medium=twitter&utm_campaign=Feed%3A+TheHackersNews+(The+Hackers+News+-+Daily+Cyber+News+Updates)#sthash.75MpOezV.dpuf

10/24/12

avast! 7.0.1473 Final 24-10-2012


avast! 7.0.1473 Final




avast! Pro Antivirus is for people and companies that want a customized computer security package. Antivirus and internet protection components in avast! Pro Antivirus are built for easy integration with existing firewalls in users' home or work computers. Pro Antivirus has two major additions to the core protection elements in avast! Free Antivirus: the Script Engine and the Sandbox.

Changes in 7.0.1473

Full compatibility with Windows 8
Outlook plugin stability and performance
Browser plugins stability
General AV performance and stability







CRACK SERIALS here 

DOWNLOAD HERE

Size : 113 - 117 Mb





letitbit
Anti Virus Pro http://takemyfile.com/7469850
Internet Security http://takemyfile.com/7469874

Med1Fire
Anti Virus Pro http://takemyfile.com/7470432
Internet Security http://takemyfile.com/7470433

depositfiles
Anti Virus Pro http://takemyfile.com/7469865
Internet Security http://takemyfile.com/7469920

jumbofile
Anti Virus Pro http://takemyfile.com/7469853
Internet Security http://takemyfile.com/7469882

turbobit
Anti Virus Pro http://takemyfile.com/7469855
Internet Security http://takemyfile.com/7469876

restfile
Anti Virus Pro http://takemyfile.com/7469852
Internet Security http://takemyfile.com/7469886

ul
Anti Virus Pro http://takemyfile.com/7469857
Internet Security http://takemyfile.com/7469880

filerio
Anti Virus Pro http://takemyfile.com/7469858
Internet Security http://takemyfile.com/7469884

filecloud
Anti Virus Pro http://takemyfile.com/7469854
Internet Security http://takemyfile.com/7469890

sendspace
Anti Virus Pro http://takemyfile.com/7469866
Internet Security http://takemyfile.com/7469878

fileswap
Anti Virus Pro http://takemyfile.com/7469867
Internet Security http://takemyfile.com/7469895
 

rapidshare
Anti Virus Pro http://takemyfile.com/7469868
Internet Security http://takemyfile.com/7469893

FREE VERSION
Med1Fire
TurboBitUploaded LetitBit 
SendSpace EzzFileFileRio FileSwap

10/23/12

McDonald's Thailand Hacked, Around 2,000 Customer Details Leaked





The group of Turkish hackers that claimed responsibility forbreaching Pepsi Hungary a few weeks ago, Turkish Agent Hacker Group, now claims to have penetrated the website of McDonald’s Thailand (mcthai.co.th).

As a result of the hack, the names, physical addresses, phone numbers, email addresses, registration dates and other details of around 2,000 individuals have been dumped online.



The hackers have also published administrator usernames and passwords. As Cyber War News underscores, it’s no surprise that the site has been breached, considering that the admins are using passwords that can be easily guessed.

The information from the Pastebin paste is not sensitive, but it’s more than enough for a targeted attack. 

On the other hand, considering that the administrator’s credentials are contained in the leak in clear text, along with the URL of the admin panel, I will not be providing a link to it.

10/17/12

Fake PayPal and WebEx Notifications Lead to Malicious Flash Player Update






security experts are seeing more and more fake emails designed to lead users to malicious Adobe Flash Player update websites. The latest ones spotted leverage the names and reputations of PayPal and WebEx.
Researchers from GFI Labs have found phony notifications that claimed to be from SkypeADP andFacebook. Trend Micro, on the other hand, has identified messages allegedly originating from PayPal’s Bill Me Later service and WebEx to be involved in the same campaign.

“We had an issue this morning with our WebEx and therefore, please accept the new invitation. This invitation has the Conference ID #36189133. Sorry for any confusion,” read the emails entitled “Important – Please read regarding this afternoon’s Webex.”

The alerts that appear to be sent by Bill Me Later bear the subject “Thank you for scheduling a payment to Bill Me Later” and they inform recipients of a payment that’s been made of over $1,000 (800 EUR).

When users click on the links contained in these emails, they’re taken to a website that almost perfectly replicates the Adobe Flash Player download website. Experts highlight the fact that the attackers have gone to great lengths to make sure that the drop menu on the fake webpage imitates the one of the genuine site.

The so-called Flash Player update is actually a malicious element identified by Trend Micro as TSPY_FAREIT.SMC. When it’s executed, it drops a version of the ZeuS banking Trojan onto the infected computer.

“These variants are specifically crafted to steal online banking credentials such as usernames, passwords, and other important account details. These stolen information are then used to initiate transactions without users knowledge or are peddled in the underground market for the right price,” Trend Micro Threat Analyst Jocelyn Racoma explained.

Researchers underscore the fact that it’s probably not a coincidence that the name of WebEx – a popular technology for business conferences – is leveraged by cybercriminals. It’s believed that these particular attacks are aimed at businesses and their employees.

5/10/12

Adobe CS6 All Products Activator x32 & x64

Adobe CS6 All Products Activator x32 & x64
Adobe CS6 All Products Activator x32 & x64
Adobe CS6 All Products Activator x32 & x64 
 it is a crack for elements thanks to download it  soo free and easy



1 open the trial version and close it
2.after that open the crack and make sure that antivirus its desactivated 


and just put like image
يدعم منتجات جديدة 10/5] الكراك

AND THEN CLICK OK
يدعم منتجات جديدة 10/5] الكراك
NOW ITS ACTIVATED


 

8/11/11

How Anonymous Could Attack Facebook - If It Really Wants To



Should Facebook be afraid of Anonymous? A message purportedly from a member of the group has threatened an attack on the social networking site for Nov. 5. Tweets from another Anonymous channel claim attacking Facebook wouldn't be the group's style. But if someone really did want to wallop Facebook, could it be done? Possibly -- there are more ways to screw up a site than a DDoS blitz.



Could Facebook be the next target in hacker group Anonymous' crosshairs?
tweet from the Twitter handle "OP_Facebook" -- which is labeled "Anonymous" yet had only a single tweet in its history as of mid-day Wednesday -- urged readers to go to a Pirate Bay Web page or watch a YouTube video in which a threat is made to attack Facebook on Nov. 5.
It's perhaps worth noting that the tweet was originally posted nearly a month ago. News of the threat has only recently been widely circulated.
Whomever controls one of Anonymous' main public communication channels, however, doesn't seem to support the effort. The AnonOps Twitter feed later stated that the so-called OpFacebook plan to take down the social networking 6 Ways to Use Social Media for Business. Free Guide. site is being organized by some Anons, that not all of Anonymous agrees with it, and that attacking the messenger is not Anonymous' style.
Schisms aside, just out of curiosity, how might a group of hackers such as Anonymous attack Facebook?

Attacks Against Facebook

Back in 2009, Facebook, along with other social media sites including Twitter and LiveJournal, were hit by massive distributed denial of service (DDoS) attacks. Facebook reportedly said the target was a pro-Georgian blogger with the username "Cyxym." However, Facebook services weren't too badly disrupted, and its engineers have publicly stated that a successful DDoS attack against their site would require a botnet so large that it might be traceable. The social networking site has other protections in place. "One would imagine Facebook would have incredible redundancy and capacity to resist a denial of service attack," Chris Harget, senior product manager at ActivIdentity, told TechNewsWorld. While a full assault on Facebook's front door may prove extremely difficult, there are other ways in which attackers could try to hurt the social network. Facebook is a favorite of cybercriminals whose attacks include setting up fake accounts or accounts with links to malicious sites, and spoofing or hijacking the accounts of legitimate users and sending out emails with either embedded malicious links or requests for financial help. "I don't consider DDoS or spoofing an account a 'hack,'" Randy Abrams, an independent security consultant told TechNewsWorld.

Taking Down Facebook's Walls

There are three primary means of attack, Abrams said. One consists of spear phishing and planting malicious code that gains access to victims' accounts or computers. This has worked against Google (Nasdaq: GOOG) and other large organizations, and "I doubt that Facebook is immune," Abrams stated. The second is exploiting a zero-day vulnerability. The third is guessing a weak password. "We know from research into past data breaches that even some security experts don't use good passwords," Abrams said. A good password, by the way, is one that has a combination of at least six to eight letters and numbers randomly mixed. A weak password would be something that's easily guessed, such as someone's date of birth or marriage or their car license plate number, for example.


8/5/11

Facebook launches security bug bounty program


Facebook has launched a security bug bounty program that rewards security researchers for privately and responsibly informing the company of website vulnerabilities.
Facebook has launched a program for compensating security researchers that discover vulnerabilities in the website’s code. To cash in, hackers must sign up at Facebook’s new whitehat hacking portal, called Information for Security Researchers, over at facebook.com/whitehat and report the issues directly to Facebook’s security team.
Facebook offers a base payment of $500 (one bounty per security bug) but says it is willing to pay more if the discovered flaw is a major one. The company says this new program is one of the ways it shows appreciation to the security researchers who help it keep the service safe and secure for everyone. It is allowing security researchers to create test accounts on Facebook in a way that doesn’t violate the website’s terms of use and doesn’t impact other Facebook users.
In order to qualify for a bounty, Facebook says that hackers must:
  • Adhere to its Responsible Disclosure Policy by giving the company a reasonable time to respond to a report before making any information public and make a good faith effort to avoid privacy violations, destruction of data, and interruption or degradation of the service during research
  • Be the first person to responsibly disclose the bug
  • Report a bug that could compromise the integrity or privacy of Facebook user data, such as Cross-Site Scripting (XSS), Cross-Site Request Forgery (CSRF/XSRF), and Remote Code Injection
  • Reside in a country not under any current US Sanctions (such as North Korea, Libya, Cuba, and so on)
Previously, Facebook has focused on simple recognition by putting the security researcher’s name on its security page under a list of White Hats (at the time of writing, there were 42 individuals listed). The company also often sent them Facebook merchandise, and even offered jobs based on their disclosures or their security work elsewhere (infamous hacker Geohot was hired three months ago). Now the portal has been upgraded so that security researchers can sign up, log in, and report bugs.
That being said, there are some exceptions that Facebook lists right off the bat:
  • Security bugs in third-party applications
  • Security bugs in third-party websites that integrate with Facebook
  • Security bugs in Facebook’s corporate infrastructure
  • Denial of Service Vulnerabilities
  • Spam or Social Engineering techniques
Since Facebook has more than 750 million users, vulnerabilities can potentially affect a huge number of people. As a result, this security bug bounty program, while not new (Mozilla and Google offer one as well), help hackers make a positive impact on the website.

8/2/11

How to find out who is using your wireless network


Do you suspect that someone is wrongfully using your wireless network connection? Maybe your wireless connection is slow these days and you suspect that someone has hacked into it. Well, there are several free tools available which can help you detect who is using your connection illegally. I am covering two tools here, but if you know of any more, please do share below in the comments.
network watcher 400x150 How to find out who is using your wireless network
Wireless Network Watcher is the 3rd new tool released by Nirsoft, this month. It is a small utility that scans your wireless network and displays the list of all computers and devices that are currently connected to your network.
It will display the following information for each connection:
  1. IP address
  2. MAC address
  3. Manufacturer of the network card
  4. Computer name
  5. Device Name.
The tool also allows you to export the list of connected devices and save it as an html,xml, csv or a text file.
Another utility for sniffing if someone else is using your wireless network is Zamzom.
wireless network tool 445x600 How to find out who is using your wireless network
Zamzom Wireless Network Tool lets you see all  the users that are using your wireless network. There are two scan options but only the Fast Scan is available in the free version, but that should be good enough for most, I suppose. Once the scan is completed, it displays the IP address and MAC address.

7/14/11

hacking Linux machine

hacking linux video

This is a Cool Collection of Top Ten Linux Hacking Tools.
1. nmap – Nmap (“Network Mapper”) is a free open source utility for network exploration or security auditing. It was designed to rapidly scan large networks, although it works fine against single hosts. Nmap uses raw IP packets in novel ways to determine what hosts are available on the network, what services (application name and version) those hosts are offering, what operating systems (and OS versions) they are running, what type of packet filters/firewalls are in use, and dozens of other characteristics. Nmap runs on most types of computers and both console and graphical versions are available.
2. Nikto – Nikto is an Open Source (GPL) web server scanner which performs comprehensive tests against web servers for multiple items, including over 3200 potentially dangerous files/CGIs, versions on over 625 servers, and version specific problems on over 230 servers. Scan items and plugins are frequently updated and can be automatically updated (if desired).
3. THC-Amap – Amap is a next-generation tool for assistingnetwork penetration testing. It performs fast and reliable application protocol detection, independant on the TCP/UDP port they are being bound to.
4. Ethereal – Ethereal is used by network professionals around the world for troubleshooting, analysis, software and protocol development, and education. It has all of the standard features you would expect in a protocol analyzer, and several features not seen in any other product.
5. THC-Hydra – Number one of the biggest security holes are passwords, as every password security study shows. Hydra is a parallized login cracker which supports numerous protocols to attack. New modules are easy to add, beside that, it is flexible and very fast.
6. Metasploit Framework – The Metasploit Framework is an advanced open-source platform for developing, testing, and using exploit code. This project initially started off as a portable network game and has evolved into a powerful tool for penetration testing, exploit development, and vulnerability research.
7. John the Ripper – John the Ripper is a fast password cracker, currently available for many flavors of Unix (11 are officially supported, not counting different architectures), DOS, Win32, BeOS, and OpenVMS. Its primary purpose is to detect weak Unix passwords. Besides several crypt(3) password hash types most commonly found on various Unix flavors, supported out of the box are Kerberos AFS and Windows NT/2000/XP/2003 LM hashes, plus several more with contributed patches.
8. Nessus – Nessus is the world’s most popular vulnerability scanner used in over 75,000 organisations world-wide. Many of the world’s largest organisations are realising significant cost savings by using Nessus to audit business-critical enterprise devices and applications.
9. IRPAS – Internetwork Routing Protocol Attack Suite – Routing protocols are by definition protocols, which are used by routers to communicate with each other about ways to deliver routed protocols, such as IP. While many improvements have been done to the host security since the early days of the Internet, the core of this network still uses unauthenticated services for critical communication.
10. Rainbowcrack – RainbowCrack is a general propose implementation of Philippe Oechslin’s faster time-memory trade-off technique. In short, the RainbowCrack tool is a hash cracker. A traditional brute force cracker try all possible plaintexts one by one in cracking time. It is time consuming to break complex password in this way. The idea of time-memory trade-off is to do all cracking time computation in advance and store the result in files so called “rainbow table”.



Related Posts Plugin for WordPress, Blogger...