Showing posts with label hacking. Show all posts
Showing posts with label hacking. Show all posts

Monday, November 29, 2010

The devil's workshop or the devil himself?

They say, an unoccupied mind is the devil's workshop. Well here's an unoccupied mind here. Where's the devil?

I've been spending the last few of months, practically doing nothing. I did some of the photography thing. Then, when it started getting boring, I did some gaming. Played some of the Ego Draconis, NFSMW, Splinter Cell and SC Pandora Tomorrow. When all the games were over, here I was unoccupied again. Then there was this advertisement in the paper about a photography competition (No, I still don't read the newspaper. Dad showed it to me). But their print aspect ratio was one of a kind. Not 16:9, not 16:10 and definitely not 4:3, which was the ratio of my photographs. They wanted huge prints for one to participate in it, and such a great place for photographers this place is, the best photo printers in town didn't have that big a paper. So I had to drop the plan. Then there came this lucid dreaming thing. I got inspired after watching Inception. Sinofemp used to talk about these lucid dream things when we lived together. He'd say that he was dreaming and found something unusual. And then he'd realize that he was dreaming and start doing whatever he wanted. Mostly he'd fly like Superman. I trained my ass to do that for a couple of weeks, but as they'd put it, it needs a lot of patience just for you to get the first lucid dream. Patience, as it turns out is my worst nightmare when I see no development at all. I did have one though, much after I stopped trying, but the moment I realized I was dreaming, I woke up panting heavily. But it did add to the patience thing after all. Then there came this urge to watch movies about lucid dreaming. So I watched A waking life. And the visuals of it amazed me so much, that I started researching into how they had the patience to make such lifelike animations. Turns out the animation was outsourced to another company, who use this Rotoshop thing to make the animations. But it was closed source and they didn't source it outside the company. So there went my endeavor to try the software. And as with every new kind of program I find, I started finding Open Source alternatives. I found just one (among the automated ones and not the ones in which you have to manually draw the outline of the subject, which was not possible for me, taking into consideration that I'd work with videos, which would be about 30 frames for one second. And then I found a script. Days later, I made a version of that script that gave me my lifelike animations. And after the Splinter Cell thing, I developed a thing for Espionage and as such. Started watching movies about espionage. Realistic ones. Not the gadgetry bullshit of movies like James Bond. Although with Daniel Craig, it is much more realistic nowadays. At the time of Brosnon, it was comedy more and espionage less. Now that I'm done with the Wikipedia list of spy films, I'm watching whatever I can lay my hands on. Mostly open source movies. Wikipedia has been a hell of a companion lately. I'd wake up night after night reading stuff which will probably never be of any use to me. But at least I like reading those. It's not like reading to pass in a goddamn exam. It's not like pretending that you're digesting the stuff well when you're hating every single bite of it.



And, yes I did come up with a small project with that script I made:




Time and again, I find me questioning myself - What's this life all about. The answer, as I well know is imprinted in my brain. But as I'd always put, when you see no developments, patience dies. But hope doesn't. And that's what keeps you at it, whether you consciously realize that or not.

At present, I'm thinking of taking up an open source movie project using the rotoscoping script I wrote two days ago. But again, you need other people to work with you to make a movie. Skouzer made the solo of our first song a few days ago. With the exams on and no time to record it all, we're still waiting for the recording and production. Ironically, there's still two more songs to be completed and it doesn't remotely seem to me that we'll meet the deadline. But again, there's noone above us to kick our asses if we don't. The question now remains, what do we do when we have released the songs. Will they get any attention in this world of corporations? Will an endeavor with zero capital be successful? Time has the answer and I'm willing to find out.

Oh, and I did make an antenna for my wifi card. After two years of waiting, I got the connectors and wires in eBay. Unfortunately that's used to wire just the antennas to PCI cards for desktops and not laptops. The guy's gonna get me the  laptop connectors tomorrow though. And I made a parabolic reflector out of paper recently, which I plan to use for the antenna. Ironically you don't get those pringles cans here (because you don't get pringles), which means I'd have to make that out of paper and aluminum foil as well. Once I get that connector, I'll be up and running to hack my way into all the wireless networks around. It's funny how people don't realize how insecure they are in this world. One password and they think it's all safe. Nothing really is. Two years ago I hacked into one of these networks, probably from a hotel nearby. The admins probably knew that encryption could be easily broken by novices using programs. S they used MAC (Media Access Control not the Apple's Mac) filtering. But your humble friend here isn't a novice now, is he? I did break into the network, but finding their gateways was a real pain in the ass. Never really got through that and the next chance I got, I was too late. The people I gave my laptop to, to fix my screen ripped off my wifi card and antenna cables and lost them and down it all went. I had to fight with those fuckers for a week to get them to give me a new card. They didn't attach the wires though. I've been searching for the connectors ever since.

And soon, it will all be over. But I can't help but question myself - when?

Saturday, November 27, 2010

A rotoscope script

For those who don't know what a rotoscope is, it is a cartoon, created essentially from a non cartoon image. You take a photograph and turn it to a cartoon and it's a rotoscope.

I've been doing some of it since the past few days. I came across quite a few programs for both imagery and video. The greatest one (in my opinion), was a hack and not a program created by a youtube user about which I found out from a google search. Here's that original rotoscope hack.

The results were, however, not quite upto my needs. So I worked on it, and now I have a modified hack of that script, which I used to make this video.



You just get a video, get this script and a few packages and you're up and running. Bad news for my Windoze friends, as this only works on Linux. I don't know for sure at this point if the used programs are available for Windows, but if they are, I'll write a batch script to do the same on windows. Till then, use a live Ubuntu CD.

Here's the script:

Automatic rotoscope hack

Tuesday, December 1, 2009

What's this life for?

Not unlike many nights, I could not sleep last night. With this pressure kinda thing in your head, you think more. Your mind goes astray thinking about a hell lot of different kinds of things. I remember when I used to be this high tech hacker guy, whose mind wandered in the unexplored depths of the cyber world. With time, my explorations became slower. I started taking a slide towards this crazy guy, who just thinks a lot. I unraveled the mysteries about life and everything. But on the other hand, I sometimes find myself questioning, "Is this all worth it?" Ironically, I do not seem to be having the answer to that. Over and again, Jack's words click back in my head:

With insomnia, nothing is real. Everything is far away. Everything is a copy of a copy of a copy.

Looking in the mirror, I find my face sagging down. I begin to accept what they probably call "fate". Everything that begins must at some point, end.

I have, like most of us must have, tried to figure out the answer to why we all exist. My purpose however, was to find the reason for my existence. I never did though. But in the place where I am, it doesn't really matter any more. May be we really are here to just be "happy", but again, not everyone thinks like that.


We are the middle children of history. No purpose or place. We have no great war, no great depression. Our great war is a spiritual war. Our great depression is our lives.

 Tyler's words coming out of my mouth. And I used to be such a nice guy.

Friday, November 27, 2009

Hack your life

This blog has taken a sudden shift from ultra l33t hacker articles to articles relating to the life of a hacker. But that, I suppose is a good thing. Now it won't be boring for anyone.

Today, I will tell you the greatest hack that was ever discovered. The hack can and has changed several lives. But only for those that have known it and done it. If you know this, you can hack your life! But first, it requires you to hack your mind.

As with all of us, on a wide basis, we all have two kinds of philosophies:
  1. Everything happens for a reason
  2. There is no such thing as reason. Everything is an accident.
People going with the second philosophy never really do anything. And the people going with the first one, eventually come up to an inference that there is something which is known as "FATE". From what I see, both are mistaken. There is no such thing as fate. And nothing is an accident. Whatever we see happening in front of us, is in some way or the other invited by us. At some point of time, we have imagined that happening. And that is the sole reason why it is happening.

What I am trying to do here is share what I know. My motive here is not to change what you believe, but to show you the truth. It is however, upto your discretion  to do what you think is right.

You look back. Say, 20 years back from now. There was telephone, and there was this newly born Internet (newly born in the sense that the general public had just started using it). The world had already started seeing cases of cyber crimes. Those included a great deal of social engineering. Calling people up in organizations and then pretending to be a government official or maintenance staff or something and then extracting relevant information from them. People used to think that one day, in near future, there will be no prank calls. Everyone would know who is calling. Everyone will know the calling number, and after some time, they'd know the name. And after that, they might even know what the purpose of the call is!

Now fast forward to the present. We first had caller IDs coming to the market. We started getting numbers. But eventually, we figured it was hard to remember all the numbers. So, it became necessary now, to know the name as well. So, we started having phone books, which would tell the name of the person calling now.

What my point in telling all this is that when you think of something that isn't there (not just in the realm of technology), you fear it. Eventually when that does start happening, you slowly accept it, and at a certain point of time, it all becomes "normal".

Have you ever wondered why it is like, someone or some groups of people imagine a certain thing, which might turn into fear or absolute awe, becomes reality after some time?

Well, I gotta tell you, it's mostly because they communicate it with others. When many people start wondering about the same thing, it materializes faster. Now, guess what? Everyone's probably thinking about 2012. After the movie is out, the mayan controversy is back again. More people now know about this. As a result, more people think about this same thing. This is not the way it should be. Because if we think about it over and over again, it will definitely materialize. But when we do a little more research on the Internet, we come to know that it is what archaeologists and scientists "think". This may or may not be true that the Mayan saw the end of the world coming. It might have been some other cause. But, this very thought is taking us closer to the end. Now I cannot change how the world thinks, but I can suggest a better way of trying to make things better (favorable).

One thing I have learned in all this time is, "Thoughts become Things". If you think something about some event or material, it will eventually materialize.

Pertaining to the last post, where I wrote about how pathetic the situation is. It is not because it is what it is. We have been witnessing some of it, and have been thinking the same since the last few decades. As a result, this has been exponentially increasing. The more we try to run from them, the more we go towards them. That's how things work. The only way out of this would be think about what you want, rather than what you don't want.

With these words, I make the last post or rather, this post, controversial. I am saying exactly the opposite of what I did. But, the only justification I'd give to that, is that if I didn't post that, there was no point in posting this article.

My point also, is that competition is not what takes us towards "the greater good". It is creation. This can be proven from day to day experience. And if you are in India, and have been a good student, as they call it, at some point of time, you'd understand this. If your aim is to top the class, you'd always think of beating the person in front of you. In all, you'd be left trying to be better than a set standard, but you can never understand what really is the "standard" that is supposed to be good. In fact, there is none. You define what you want and if you take the steps to get it, you definitely will.

A mass trend in thoughts is leading us all to what we are going to. If we have to change something which pertains to all of us, all of us, or at the very least, most of us should think that way.

Friday, August 28, 2009

WPA can now be broken in 60 seconds




The WPA, wireless encryption protocol is no more secure. In an earlier attack, WPA could be cracked in 12 to 15 minutes. But now, after some research from Japanese scientists, the WPA algorithm can be cracked in under a minute.

This has been a breakthrough in the field of the establishment of the fact that wireless encryption technology has not been given much thought in the beginning, and now it is growing up to be a huge problem.

Earlier WEP had been proved to have so many vulnerabilities. And we hackers were able to crack a network in under an hour, if near enough the source to get sufficient packets. It didn't seem to be any problem at all, but we had to get those handshake packets for WPA, and then use dictionary or brute-force attacks. But now with this revolution brought about by these scientists, we cannot anymore consider WPA as a secure algorithm.

However, this has been proven to work with TKIP (Temporal Key Integrity Protocol) only, and does not work with AES (Advanced Encryption System) or the WPA2 protocols.

This post has more information about this.

Wednesday, March 4, 2009

Download YouTube and other streaming videos in Linux without any program

Linux is a great Operating System, as I've always been seeing. This post is going to describe a technique that I've been using for quite some time now. Experienced users may be familiar to this. But this post is targeted towards that are unaware.

There have been times when most of us have wanted to download a particular YouTube or other streaming video. In Linux, this is possible without the use of any external program.

In Linux, the streaming video is stored in /tmp directory. So, all one needs to do is go to the /tmp directory. If thumbnails are shown, it is easy to spot the video. If not, then looking for files starting with Flash will do the job. These are the files that are being streamed. But only the amount that has been streamed is stored in this file. One can simply copy this to the Desktop and view it with any media player.

If it is not Linux that one is using, then AFAIK, options are limited. There is a website, that helps people to download YouTube and Google Videos. But it is only limited to these two. It is called videodl.org.

If you find this post useful, do leave a comment down there and encourage me to write more useful tricks and techniques like this.

Sunday, February 1, 2009

Making a mail list from all mailing addresses lying around

I was recently on a project of spreading words about my new magazine, for which I was not getting contributors. The best idea I could think of, was to mail people and let them know about it. So, I got out all mail addresses from my orkut account, my address book, and some mail list that used to email all recipients in one go, from which I got most of the addresses. Now, the problem was that, I could not make it typing 1070 email addresses in the To field of my email client. I had to get them in one csv (comma separated value) list. This article would rather be a how to on this topic. I wrote programs for that, whose source code is freely available here along with makefiles and a readme file.

  1. The first thing was to get the list in a file in some format. The mail list was the first target, which had many addresses. So, I had them in space (' ') separated format. So, I wrote a program eliminateduplication, which will also eliminate the duplication of email addresses, that is two addresses in the same list, and give the output in another file in csv format.
  2. The second source of addresses was Orkut. I pulled out all contacts in csv format. But, this time it had the names as well. So, I had to open it in a spreadsheet program. Although I used Open Office, Microsoft Excel will do fine. Then all I did, was copy the specific column containing the email addresses, and pasted in a file, where the addresses got separated by Enter. For this, I used the program crlf_to_space, which will take input from the file maillist.13 and put it in a space separated file maillist, which can be later put in maillist.csv.
  3. The last thing I did, was open the maillist.csv file in a text editor (kwrite, gedit and notepad are examples), and copied the whole list to the To field. The problem was solved.
The programs are made with standard C functions. So, the program should compile with any gnu compatible compiler, like gcc in Linux and mingw in Windows. Other compilers will also work, but one will have to compile the individual files, because the Makefile is GNU compatible.

Instructions:
  • Do not delete the maillist file, because any later additions can be done to it, and eliminateduplications will just write those in csv format to maillist.csv, overwriting any existing addresses.
  • Download your gmail contacts in csv, and copy email addresses as instructed earlier. Then use crlf_to_space, to append those addresses to the maillist file. This will not overwrite the already existing addresses in that file.
  • After this, use the eliminateduplications program to save the space separated email addresses in maillist to maillist.csv in csv format.
Application:
  • These programs can be useful in gathering various email addresses from different locations, and using them all in one go, without having to type the individual messages.
Download The Mailing List Project:

Sunday, March 2, 2008

The ATM card



Written by
Xtreme Great
(for k0r0pt)
(no copying please)

Disclaimer

This document is for informational purposes only. I do not condone any form of fraud or deceit or any exploit carried out as a result of this document. So, I cannot be held responsible for any act carried out by you or the consequences thereof. Use this document to learn. To explore and not to exploit. And beware if you land doing any shit with this, you're gonna land your ass in trouble. And also remember, that it is the case with banks, so if you do something really stupid and serious, the cops will definitely ram your ass. Better look out.

Introduction

How often, in your life have you thought about cracking into someone's bank account? How much have you wondered about the infinite possibilities of doing so. How deep have you delved into the sea of "possibilities"?

I'm going to tell you one aspect of the securities of bank accounts in present day life. Remember, NOTHING is foolproof. Everything can be broken. In today's world of cyber banking, nothing is safe. There is no security. No privacy. Everything is publicized, without of course, the prior knowledge of the VICTIMS. We expose our information, every time we buy something from the Internet, or give our Credit card numbers. What is the guarantee that the credit card database won't be cracked? There is no guarantee. There is only HOPE, and trust me, HOPES never work out. So, the end users are the ultimate losers.

In this post, I'll shed some light on ATM card hacking.

ATM's are the most widely used cash money machines around. They'd handle thousands of transactions every single day. A single card holds the key to all of your money. And that card is protected by only one key - The PIN, and that too is only 4 digits long, and if we'd calculate the permutation, there are only 10^4 possible combinations, which can be cracked "very" easily, provided we have the card. Now, how the fuck would someone crack the PIN from a card, you may ask, and I say, why not? Broaden your point of view. The answer lies right in front of you. You're not noticing it though. Every magnetic card, in today's world, works on a single basis - Magnet. Magnets are all around - in your hard disk, your cassette tapes, your DATs, your Floppy disks, Your Debit card, your ATM card. Not only is it possible to read out and crack PINs from ATM cards, but also, it is possible to MAKE your own ATM card, with a card writer, which is of course quite costly. Now, we'd delve a bit more deeper into the world of magnetic cards.

But before I go any further, I'll assure you that there are thousands of other articles out there, that will tell you the same thing. I will only tell you what to do to do what they say, in addition.

Techstuff

All the magnetic cards have what "they" (the makers) call tracks. Tracks are nothing, but tracks (don't ask me again), of magnets that contain data. There are three standard tracks. Track one, track two and (you guessed it) track three. These tracks contain different kinds of information.
The information is stored in different formats. But first, I'd tell how to read all those 1's and 0's from the cards. After all, that's what we're upto. These 1's and 0's are our business... When we read a card with a card reader (when I say card, I mean magnetic card, so don't get confused again) we get voltages. High voltage obviously means a 1, and low means 0. These voltages would be produced due to electromagnetic induction. If you don't know what this is, try googling it. After this, you'd get some voltages. When you stripe your card against the read head (I used a tape player read head. Search for them, and you'd definitely get one around. If not, try going to some radio shack store), remember that in the ATMs, the card get read, when you pull the card outside, not when you push it inside. So, if your magstripe is facing upwards and away from you, you stripe it right to left. Here, you'd get two types of frequencies. Remember, when I mean frequency, I mean the width between two waves, that you'd get, not the height of the waves, which is the amplitude. The frequency for a one, will always be double the frequency for a 0. Thus, we can read either of the three tracks. But how do we know which track we've read? The positions of tracks is standardized, with respect to the edge of the card.

As you can see the positions of the three tracks, with respect to the edge of the card, you can easily construct a card reader, and start reading your card right away. Now, we get to the nitty gritty details of the hardware and software parts. This is where the Computer comes into play.

The Hardware

For the hardware part, as I already said, all you need to get is a card reader, lying around somewhere in your basement or something. Then solder that thing's end terminals to a copper wire and attach it to a mono jack, that can be inserted in your computer microphone slot.

The software

Assuming you've got the hardware, Let's leap to the software. There are two ways for all hackers, when it comes to softwares. Either fetch some software made by some other person, or make your own. Well, the former is the case with most of the people around. But believe me. The true hacker, will go to every nitty gritty detail of everything, spend night after night, reading out man pages, and make the software him/herself (in case there are female hackers around). With the details I've given and that I am about to give, anyone could build that program to read magnetic stripes and dig out information. There are two ways. Either you make a microphone reader program, or you can make a program, that will read out a wave file, that contains the information of the card recorded in it, and give out the information.

Getting back to the main discussion, the magnetic card does have three tracks, the tracks have information coded as 1's and 0's. Now we get to interpreting those information. There are two standard formats used to encode data on cards The ANSI/ISO BCD Data Format and ANSI/ISO Alpha Data Format.

You must find the information regarding these standards yourself. C'mon if I give you all the details, what would you do?

The last two tracks are encoded by the BCD format, and the First one, by the Alpha standard. The second track is generally used to store information regarding the account thing. The first track contains information about the owner's name. The densities and number of characters per track are:

1st track: 210 bpi 79 characters
2nd track: 75 bpi 40 characters
3rd track: 210 bpi 107 characters

The 3rd track is generally, rarely used in any type of card. These standards also apply to all sorts of Credit cards, Debit cards, Metro Cards and whatever cards you can imagine. The deviation from the standards can also be there in particular case, for example, in case of Hotel room cards, that give you access to hotel rooms.

Epilogue

Well then, that's all the information I could give you. It's not enough, but still more than enough. Happy exploring, and remember not to do anything stupid. Till next time...

Friday, December 7, 2007

Increasing the span of my vision


All of us hackers must have seen the movie: Die Hard 4, which demonstrates, among all other things, the breaking of the villains into CCTV cameras, during the whole movie. At first I thought it is not possible, but then, I leapt into the field of CCTV hacking, and what I eventually found out is what I am about to write in the next few paragraphs.

CCTV cameras are everywhere. In airports, in hospitals, in schools, in hostels, in offices, restaurants, government buildings, and where not!!!

CCTV cameras have a built in web server, which streams data on the World Wide Web. Yes, the WWW. And that's what we make use of. We can search for the vulnerable cams. If the web server is not set to avoid search engine crawls, then we can search it and access the cameras and see whatever is going on. Something I call - seeing the world.

So, all we have to do, is search for all those vulnerable CCTV cameras, and just access it. That's it - no passwords, no authentication. All you gotta know is the IP of the camera. The IP assigned to the camera. Every camera server has its IP. And the location of the file, that streams the contents of the camera. We can access multiple cameras through the same server, depending on whether or not the server gives us access to the camera argument. The server running is the Axis 2400 servers. That is, all we have to know is the vulnerability. I have to do more research on these stuffs, before I can tell how to do more advanced stuffs.

The main theory behind this type of surveillance is that, the file stored in these servers is located somewhere in the /axis-cgi/mjpg or the /axis-cgi/jpg directories. The files may be of the type swf (Flash movies) or it could be a cgi script. The root of this camera may also provide multi camera views and some administrative setups as well, which obviously is more fun.


This is coming in the search string, when we search for the vulnerable cams. In this demo, I'll give you the IP of the CCTV server in the Stuttgart airport in Germany. The IP is 195.243.185.195 and here's a screen shot of that airport's various cameras:

Just make sure you don't do anything stupid enough to drive the German cops to your home!!!
;)
Till then, happy surveillance!!!

Thursday, December 6, 2007

Yet another orkut trick.....



Well, yet another nasty javascript for the Orkut users. Write this to your scrap, and if the user is on the same page, as this scrap, then he/she will get logged out. As can be seen, there is an embedding of an object, which is used to log out the user
"http://www.orkut.com/GLogin.aspx?cmd=logout"
Here, it is the active server page we are exploiting, by calling the cmd argument with a value of logout. This works the trick...
Try it!!!
Comments and suggestions are most welcome...
:)

Tuesday, December 4, 2007

Tracking down an email



Email tracing has been one of the prime considerations of the authorities. It has been the most basic task of the authorities, in the tracing of a mail, down to the door. And not surprisingly, it is also, the most easy thing to do. Though the amount of information is very limited, but still, this can provide the IP of the sender at the time of the mail sending, and that's no less than an important achievement.

This is accomplished by studying the email headers. If the IP is from a registered network, then we can know the exact location of the sender, along with the street address, but is it a personal internet connection, we can only know the name of the company, which the sender is sending from, that is the ISP(Internet Service Provider).

Now, we get to the real thing. We consider an example email header, from which, we trace the mail back to the sender.

Here's a sample mail header:

This one is the header of a mail from McAfee.
Example 1

From McAfee Fri Aug 24 04:11:46 2007
X-Apparently-To: xtreme_the_great1@yahoo.co.in via 202.43.219.101; Sat, 25 Aug 2007 21:45:41 +0530
X-Originating-IP: [216.49.92.103]
Return-Path:
Authentication-Results: mta125.mail.in.yahoo.com from=mcafee.com; domainkeys=neutral (no sig)
Received: from 216.49.92.103 (HELO mcafee.com) (216.49.92.103) by mta125.mail.in.yahoo.com with SMTP; Sat, 25 Aug 2007 21:45:40 +0530
X-Mailer: UnityMail
Errors-To:
Originator:
X-Mailer-Version: 5.1.182
X-UnityID: <20070823224146.hxfcjbysebaaa3aumail4.xtreme_the_great1@yahoo.co.in@unity4.mcafee.com>
X-UnityUser: McAfee
Reply-to: "McAfee"
From:"McAfee" Add to Address BookAdd to Address Book
To:"xtreme_the_great1@yahoo.co.in"
Subject: McAfee Security Brief 08.07: Microsoft Vulnerabilities
Date: Thu, 23 Aug 2007 15:41:46 -0700
MIME-Version: 1.0
Content-Type: multipart/alternative; boundary="----=_NextPart_000_0963_01C7E5D6.C90B46F0"
Thread-Index: AcfmEXVgCOCwhz8cS5K6y62QtMC7QQ==
Content-Class: urn:content-classes:message
X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2800.1807
Content-Length: 19546


The X-originating IP is the IP of the mail server, that is the smtp server used in the process. These servers, are the machines, that are used for sending mails in the Internet. In this case, it is 216.49.92.103. The sending machine's IP can also be figured out from the mail header itself. We can figure it out by examining the Received fields, which in this case reads:

Received: from 216.49.92.103 (HELO mcafee.com) (216.49.92.103) by mta125.mail.in.yahoo.com with SMTP; Sat, 25 Aug 2007 21:45:40 +0530

The sending IP here is thus, the same as that of the first mail server used in the process. That is: 216.49.92.103.

But, cases may not be like this.

We consider another case, where there are multiple mail servers used in the process.


Example 2

X-Apparently-To: xtreme_the_great1@yahoo.co.in via 202.43.219.149; Sun, 25 Mar 2007 18:02:32 +0530
X-Originating-IP: [202.43.219.31]
Return-Path:
Authentication-Results: mta135.mail.in.yahoo.com from=yahoo.co.in; domainkeys=pass (ok)
Received: from 202.43.219.31 (HELO web8316.mail.in.yahoo.com) (202.43.219.31) by mta135.mail.in.yahoo.com with SMTP; Sun, 25 Mar 2007 18:02:32 +0530
Received: (qmail 84649 invoked by uid 60001); 25 Mar 2007 12:32:32 -0000
DomainKey-Signature: a=rsa-sha1; q=dns; c=nofws; s=s1024; d=yahoo.co.in; h=X-YMail-OSG:Received:Date:From:Subject:To:MIME-Version:Content-Type:Content-Transfer-Encoding:Message-ID; b=0s8bAtp2vC7RFSCYSfLno7bSWfAP6ebccb/weUTLZiw/rWfNuCgFdZvZUc9iMyUkgYuxqjz7WX3LqbMS8L8Qpyg4sM+M+BR2YQt50I330raEEFk5kuAjjGCNOZBe8zFphRNtIeAsOFJ8keIEQ+0kzbPdJQ0xuon7g7mDTyJv0Tw=;
X-YMail-OSG: jC_yrKkVM1n7FtpNbkqEXJdYRgDvi3PDe0HUOmSPKTBwyHwm_1crZ.fBVw6xODaYBudsxpwFsOtmkF6_lYfGUTo.FBDkKgfTLsoHun6qK.irkJFE.QqhNsPs2JfHOpVQDVVdACQ4HUZ7A9SFDqR7KA6pTw--
Received: from [122.168.69.140] by web8316.mail.in.yahoo.com via HTTP; Sun, 25 Mar 2007 13:32:31 BST
Date: Sun, 25 Mar 2007 13:32:31 +0100 (BST)
From:Send an Instant Message "sooraj elamana" Add to Address BookAdd to Address Book
Yahoo! DomainKeys has confirmed that this message was sent by yahoo.co.in. Learn more
Subject: Proxy Lists by Sooraj E
To:xtreme_the_great1@yahoo.co.in
MIME-Version: 1.0
Content-Type: multipart/alternative; boundary="0-575879626-1174825951=:84636"
Content-Transfer-Encoding: 8bit
Message-ID: <34533.84636.qm@web8316.mail.in.yahoo.com>
Content-Length: 58637

Here, we see the Received fields, and deduce, what we are supposed to deduce.: The IP of the sender, at the time of sending the message. The X-Originating IP is 202.43.219.31, which is the IP of the first mail server in the path. Then we come to the point.

The first Received field says, that the message was obtained from 202.43.219.31 a.k.a. web8316.mail.in.yahoo.com, that is, the computer introduced itself to the mail server mta135.mail.in.yahoo.com as web8316.mail.in.yahoo.com.

The second one says, that the message was obtained from 122.168.69.140 by web8316.mail.in.yahoo.com via HTTP, that is, the sender used a web browser, to send the email.

Then, to find more information about the sender, we lookup the obtained IP 122.168.69.140 with the nslookup command, which returns the following:

Name: ABTS-MP-dynamic-140.69.168.122.airtelbroadband.in
Address: 122.168.69.140

That is the sender's ISP is Airtel broadband, and he is situated in India, in the state Madhya Pradesh (Deduced from the ABTS-MP) and the IP is a dynamic IP address, that is the next time the sender logs on to the ISP, he'll have a new IP.

In the next post, I'll demonstrate how I traced down a sender to his college, and got a phone number, so that I could talk to him! Keep checking. :)

Friday, November 30, 2007

The Conscience of a Hacker

\/\The Conscience of a Hacker/\/

by

+++The Mentor+++

Written on January 8, 1986
=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=

Another one got caught today,
it's all over the papers.
"Teenager Arrested in Computer Crime Scandal",
"Hacker Arrested after Bank Tampering"...
Damn kids. They're all alike.

But did you, in your three-piece psychology
and 1950's technobrain,
ever take a look behind the eyes of the hacker?
Did you ever wonder what
made him tick, what forces shaped him,
what may have molded him?
I am a hacker, enter my world...
Mine is a world that begins with school...
I'm smarter than most of
the other kids,
this crap they teach us bores me...
Damn underachiever. They're all alike.

I'm in junior high or high school.
I've listened to teachers explain
for the fifteenth time how to reduce a fraction.
I understand it.
"No, Ms. Smith, I didn't show my work.
I did it in my head..."
Damn kid. Probably copied it.
They're all alike.

I made a discovery today.
I found a computer.
Wait a second, this is cool.
It does what I want it to.
If it makes a mistake,
it's because I screwed it up.
Not because it doesn't like me...
Or feels threatened by me...
Or thinks I'm a smart ass...
Or doesn't like teaching
and shouldn't be here...
Damn kid. All he does is play games.
They're all alike.

And then it happened...
a door opened to a world...
rushing through the phone line
like heroin through an addict's veins,
an electronic pulse is sent out,
a refuge from
the day-to-day incompetencies is sought...
a board is found.
"This is it... this is where I belong..."
I know everyone here...
even if I've never met them,
never talked to them,
may never hear from them again...
I know you all...
Damn kid. Tying up the phone line again.
They're all alike...

You bet your ass we're all alike...
we've been spoon-fed baby food at
school when we hungered for steak...
the bits of meat that you did let slip
through were pre-chewed and tasteless.
We've been dominated by sadists, or
ignored by the apathetic.
The few that had something to teach
found us willing pupils,
but those few are like drops of water in the desert.

This is our world now...
the world of the electron and the switch,
the beauty of the baud.
We make use of a service
already existing without paying
for what could be dirt-cheap
if it wasn't run by profiteering gluttons,
and you call us criminals.
We explore... and you call us criminals.
We seek after knowledge... and you call us criminals.
We exist without skin color,
without nationality, without religious bias...
and you call us criminals.
You build atomic bombs, you wage wars,
you murder, cheat, and lie to us
and try to make us believe it's for our own good,
yet we're the criminals.

Yes, I am a criminal.
My crime is that of curiosity.
My crime is that of judging people
by what they say and think,
not what they look like.
My crime is that of outsmarting you,
something that you will never forgive me for.

I am a hacker,
and this is my manifesto.
You may stop this individual,
but you can't stop us all...
after all, we're all alike.

+++The Mentor+++
_______________________________________________________________________________

Original post

Thursday, November 29, 2007

The power of google


This post is being written after a long time since the previous one. Because of lack of time and mood. But this one is definitely one of the most important.

The most powerful search engine of the world- Google.com is indeed powerful. But, like every power, Google is also a double edged sword.

The search engine can be used to reveal password files of various sites, most of which are encrypted by the DES algorithm, and can be cracked right away. This will give access to various ftp servers, and who knows? may be even many telnet servers, or proxy servers of the corresponding sites.

In this post, I'll tell about the various search techniques in Google, which also work in many other search engines.

inurl (also allinurl) - This keyword is used to search for a specific string in the url(Uniform Resource Locator) of the sites being searched. Those with a positive match are listed in the search results.
for example,

inurl:google.com

will list all results, which have google.com in the url.

site - This keyword is used to search for a specific kind of site. Type of site is specified by the extension of the site. It may be .edu(Educational institution), .com(Commercial organization), .org(non profit organization), .gov(Governmental organization), .net(Network), .mil(Millitary network) and the others are normally country abbreviations(e.g. .jp for Japan, .in for India, .br for Britain etc.)
for example,

site:mil

will list all sites, with mil extension. This one is actually a U.S. millitary network.

filetype - This keyword is used to access certain file extensions in sites. This one is particularly useful for accessing password files. The password files are normally in the pwd, pw, mdb, xls extensions. The pwd files will store maintenance or service passwords.
for example,

filetype:mpg

will search for mpeg video files in the sites being searched. Other extensions can be searched in this way.

index of - This keyword is used to search for directory listings. It is also useful for searching certain types of files. It is particularly useful, if it is known, which directory, a certain type of file is stored in a web server. For example, the _vti_pvt folder will store service.pwd, which happens to store the service passwords.
for example,

index of /

will search for the directory listing of vulnerable sites.

OR - An uppercase OR acts as logical OR
intitle (also allintitle) - The intitle keyword is used to search for pages, which have the specified string in the title tags.

link - This keyword will search for the sites, which have link to the specified site.
for example,

link:www.google.com

will search for sites, which have a link to the site www.google.com

related - This keyword will list all pages, which are similar to the specified web page.

info - This keyword will show information, that Google has about the specified website.

Well, that's all folks, I have included enough information in this post, that will be enough to search for password files, and break into servers, but always remember - Intelligence is a double edged sword. Which edge you end up using, is on to you.

Wednesday, November 14, 2007

Email forging




Email forging has always been one of the easiest forms of email hacking ever used. It has been well known in the hacking community for quite a long time.

All one needs to know while forging email, is the basic knowledge of how the SMTP works. SMTP stands for Simple Mail Transfer Protocol - The protocol(set of instructions and rules) used to send email in the Internetwork. The total set of the step by step instructions from client to server can easily be found in any rfc database. Click here for the rfc relating to the SMTP. This link is for those, who are real PUJARIES of ultimate knowledge. Not for dummies...

A tutorial on how to forge email through any command prompt, can be very easily found in the Internet. So, I will not reinvent the wheel by redescribing the whole process here. The following link will show the simple tutorial on how to forge a simple email. Advanced email forging including attaching files in the mail will be posted soon in this blog. Keep checking.

The tutorial
.

Sunday, November 11, 2007

So, what is hacking all about???

"Hackers!!!"- The very term would scare people.

It's use has become so very restricted, that people have started taking the term for cyber criminals and computer vandals. But believe me, the very term hacking means "to redefine something to do what it was not made to do...". So, if you configure your FM radio, so that it can receive TV signals as well, it is hacking. If you sneak into someone's privacy, then we term it to be "cracking" not hacking. The very term hacking is clean.

We shall take some examples. All of us must have heard about the famous Operating system Linux. I'll tell you a truth associated with it. It was invented by a fin computer science student, whose name was Linus Torvalds. He was a hacker. Yes, a hacker. Hackers are not evil people. They are people in search of something. That something is knowledge. It is only their thirst for knowledge that makes them do what they do. So, from a broader aspect, even the black hat hackers, whom we call "crackers" aren't really bad people. They help us, the white hats. We are like family. They teach us that we have faults in the programs we have created, and that fault can be misused, and can be potentially harmful to people using the program.

The term hacker was first coined in the MIT(the Massachusetts Institute of Technology), for someone who was a computer expert. But, later on the media has corrupted the term, to designate computer criminals.

I shall now tell about the two major devisions in the world of hackers. There are, basically two types of hackers in this planet. The ones who like to use their knowledge in the positive side, whom we call the The white hats and the others, who use it in the negative side, whom we call The black hats. Always remember - intelligence acts as a double edged sword. The choice, which side you want to take is on to you. I'd say that none is "bad". Because the basic motive in either case is the same - freeing the civilization of ours, from all sorts of threats. To give us a wider view of this place, we are all living in.

This is all I have to say in the intro to hacking section.

A brief intro of mine...

My name is Xtreme Great, and HCl is the name of my community.
I am not a white hat, and have been in the scene for above an year now...
I am a computer geek...
I am starting this blog to make people aware of all sorts of cyber threats in today's cyber world...
Basically, I am trying to form a basis of this "scene"

All I am trying to tell, is the truth...- The truth, about how safe we actually are...

Check out the official website : xtremehcl.googlepages.com to know more about my innovations and creations..