Now you all can invite me on skype for any kind of help required as my username is krackoworld


30 May 2013

How to Hack PayPal Accounts to Steal User Private Info


paypal PayPal as you all knows one of the leading companies in today’s online transaction. Recently Nir Goldshlager, founder of Breaksec and Security Researcher reported critical flaws in Paypal Reporting system that allowed him to steal private data of any PayPal account. Exploiting the vulnerabilities he discovered, allowed him to access the financial information of any PayPal user including victim's shipping address, Email addresses, Phone Number, Item name, Item Amount, Full name, Transaction/Invoice ID,  Transaction, Subject, Account ID, Paypal Reference ID and many more.

He found that PayPal is actually using the Actuate Iportal Application (a third party app) to display customer reports, so Nir downloaded the trial version of this app for testing purpose from its official website.

After going deeply through the source code of trial version, Nir located a file named getfolderitems.do that allowed him to access user's data without credentials. For more information see the pictures below-

Critical Vulnerability allowed hacker to spy on PayPal accounts

paypal_reports_hacked 
Update- PayPal Security Team has fixed this bug now! Thanks…

Also read- How Hackers can Make Money with PayPal Bug Bounty Programs?



25 May 2013

What is Zero Day Attack or Exploit?- Know its Prevention


zero day attack A zero-day (or zero-hour or day zero) attack is an attack that exploits a previously unknown vulnerability in a computer application, i.e the attack occurs on "day zero" of awareness of the vulnerability. This means that the developers have had zero days to address and patch the vulnerability. Zero-day exploits (actual software that uses a security hole to carry out an attack) are used or shared by attackers before the developer of the target software knows about the vulnerability etc.

Ordinarily, when someone detects that a software program contains a potential security issue, that person or company will notify the software company (and sometimes the world at large) so that action can be taken. Given time, the software company can fix the code and distribute a patch or software update. Even if potential attackers hear about the vulnerability, it may take them some time to exploit it; meanwhile, the fix will hopefully become available first.

Sometimes, a hacker may be the first to discover the vulnerability. Since the vulnerability isn't known in advance, there is no way to guard against the exploit before it happens. Companies exposed to such exploits can, however, institute procedures for early detection:

  • Use virtual LANs (IPsec) to protect the contents of individual transmissions.
  • Deploy an intrusion detection system (firewall).
  • Introduce network access control to prevent rogue machines from gaining access to the wire.
  • Lock down wireless access points and use a security scheme like Wi-Fi Protected Accessor WPA2 for maximum protection against wireless-based attacks.

Zero Day Attack Prevention tips:

1. "Multiple layers" provides service-agnostic protection and is the first line of defense should an exploit in any one layer be discovered. An example of this for a particular service is implementing access control lists in the service itself, restricting network access to it via local server firewalling (i.e., IP tables), and then protecting the entire network with a hardware firewall. All three layers provide redundant protection in case a compromise in any one of them occurs.

2. The use of port knocking or single packet authorization daemons may provide effective protection against zero-day exploits in network services. However these techniques are not suitable for environments with a large number of users.

3. Whitelisting effectively protects against zero day threats. Whitelisting will only allow known good applications to access a system and so any new or unknown exploits are not allowed access. Although whitelisting is effective against zero-day attacks, an application "known" to be good can in fact have vulnerabilities that were missed in testing. To bolster its protection capability, it is often combined with other methods of protection such as host-based intrusion-prevention system or a blacklist of virus definitions, and it can sometimes be quite restrictive to the user.

4. Engineers and vendors such as Gama-Sec in Israel and DataClone Labs in Reno, Nevada are attempting to provide support with the Zeroday Project, which purports to provide information on upcoming attacks and provide support to vulnerable systems.

5. Keeping the computer’s software up-to-date is very important as well and it does help.

6. Users need to be careful when clicking on links or opening email attachments with images or PDF files, even if the sender is someone they know. This is how many cyber criminals deceive users, by pretending they are something they are not and gaining the user’s trust, as well as having a virus or other malware email copies of itself to the address lists of infected victims.

7. Utilize sites with Secure Socket Layer (SSL), which secures the information being passed between the user and the visited site.

That’s it!



09 May 2013

5 Tips to Prevent Online Account Hacking-Taking Hacking Efforts to the Base of Humiliation


online account hacking Hacking

Basically, with the changing face of technology, many online resources are increasingly falling victim due to many hacking due to attempts. Indeed, due to the failure of many online enterprises as well as persons to have a stable, highly integrative security systems on their accounts, hackers are taking advantage of weak access points leaving destruction beyond imaginations. But can that be curbed? A question is rattled by many. Well, with a particular focus on many online niches, certain efforts have proven worthwhile in preventing online account hacking. Let's take a look.

Preventing Hacking on Online Accounts


The first step of preventing hacking on online accounts is to keep vigil on the running accounts on your computing systems. This tip has seen many online accounts emerging as strong programs to bring rapid time to value in efforts to curb online accounts. This is because every single program in the internet launches a process that displays any information together with account access points in the windows task manager. Therefore, keeping vigil of the running processes can help identify any hacking attempts as well as increase operational performance to security systems.


Computer protection through strong and impermeable security software might prevent advanced hackers from cracking into platforms with sensitive data and online accounts. An antimalware application as well as an antivirus (the latest version) provide a standardized, industry-leading practice delivery security mechanism that enables your account to offer fixed-scope security capabilities hence preventing any hacking practices. For instance, the child tax credit helpline has redefined value for customers as well as preventing hacking by having a strong bond of security system through malware applications and related security software.


As if this is not enough, the use of strong passwords that are well equipped by physical personal identifiers like voice and fingerprint identifier metrics has also shown continued ability to prevent spammer hacking efforts. In fact, such metrics strengthen the passwords hence preventing other computer crimes like cracking, industrial espionage, piracy and even fraud. Although strong passwords offer one of the best approaches in preventing hacking, it is true that serious and competent hackers will still find way to online accounts by using the key logger application. Therefore, weakening key logs by making use of unique passwords made up of a combination of letters, symbols, and numbers will be a technological initiative that will have an immediate impact on hacking.


Unprotected public networks, which have become the order of the day in the provision of free Wi-Fi and other web access protocols, are threat to online accounts. Through the special software, a hacker sitting in the same cyber café with you can gain access to all your password at a time when you are trying to access certain accounts. But how is it possible? Well, public networks are unprotected and attract a lot of people which make them prone to hacking therefore should never be used for online shopping, banking or even in many email forms.


Finally, it is no secret that many hackers are advancing towards freeware which occurs in many forms of downloads. This means that free downloads and other no-fee applications are being used by hackers to gain an internal metric in many accounts, both enterprise based and personal. Therefore, minimizing interactions with free downloads and applications will reduce the level of risk posed by online account hackers. With all these approaches, you can now redefine and expand your online account security by enabling industry-focused solutions to cut short and handicap any hacking efforts.



05 May 2013

Tips to Improve the security of your WordPress Blog and Make Bullet Proof


wordpress security tips Well Security is not really a massive issue until your blog starts becoming popular. If you start receiving a decent amount of traffic, your blog will become the target of online malcontents. Traffic may be turned into cash online via a large number of various (and sometimes nefarious) routes. It is good practice to start as you mean to go on and introduce blog security from the outset. Here are some tips that anyone can use, even if you are not technically/programmatically trained.


30 April 2013

How to Make Money with Google Chromium Bounty Programs


Google bug bounty for Chrome bugs Now a days its becoming trend to pay to those smart hackers who can find and fix vulnerability in their systems. Recently Google has also opened that type of program in which they already paid around $300,000 etc. Therefore, every person will get the bounty of $500 for each vulnerability they report in the Chrome browser and its underlying open-source code. This is known as Chromium Vulnerability Rewards Program.

The Purpose of The Program

This Vulnerability Rewards Program was created to help reward the contributions of security researchers who invest their time & effort in helping us to make Chromium more secure. Through this program we provide monetary awards and public recognition for vulnerabilities responsibly disclosed to the Chromium project and many more.

Some FAQ’s

What reward might I get?

Our base reward for eligible bugs is $500, but the typical payout is usually at least $1000. If the rewards panel finds the bug particularly severe, the value can be as much as $3133.70. Or if the rewards panel finds a report really impressive, the value can be as much as $10,000 or even beyond. To ensure the greatest chance at the maximum possible award please adhere to the guidelines provided in the Reporting Security Bugs.

What bugs are eligible?

Any security bug may be considered. We will typically focus on High and Critical impact bugs, but any clever vulnerability at any severity might get a reward. Obviously, your bug won't be eligible if you worked on the code or review in the area in question.

Who pays for the awards program?

As a consumer of the Chromium open source project, Google sponsors the rewards.

How do I find if out my bug was eligible?

You will see a provisional comment to that effect in the bug entry once we have triaged the bug etc.

What if someone else also found the same bug?

Only the first report of a given issue that we were previously unaware of is eligible. In the event of a duplicate submission, the earliest filed bug report in the bug tracker is considered the first report.

For more information, please Visit Here.

Also Read- How Hackers can Make Money with PayPal Bug Bounty Programs?



24 April 2013

Pirate Bay Co-founder Charged for Hacking Machines & Stealing Money


The Pirate Bay co-founder charged with hacking and stealing money Recently Pirate Bay co-founder Gottfrid Svartholm Warg was charged with hacking the IBM mainframe of Logica, a Swedish IT firm that provided tax services to Swedish government, and IBM mainframe of the Swedish Nordea bank, the Swedish public prosecutor. Also Besides Svartholm Warg, the prosecution charged three other Swedish citizens as well.

According to the prosecutors, IBM mainframes belonging to Logica and the bank were targeted in the attacks, which are said to have begun in 2010, and continued until April 2012. The Swedish authorities have claimed that it is the biggest investigation into a data intrusion ever conducted in the country.

Prosecutor Henrik Olin Says that,

"A large amount of data from companies and agencies was taken during this hack including a large amount of personal data, such as personal identity numbers of people with protected identities... I'd say that Svartholm Warg is the main person and brains behind the hacker attack."

In total, the four men allegedly attempted to transfer a little over 680,000 Euros to different bank accounts. Therefore Court proceedings against Svartholm Warg and the other three are expected to begin at the Nacka district court at the end of May, Olin said.

That’s it!



17 April 2013

WordPress Blogs Under Botnet Attack and Prevention


botnet attack All the world knows that WordPress is one of the best blogging platform ever, now due to it its Hacking is becoming common now a days. In a recent post, Matt Mullenweg posted about the recent attack on WordPress sites. This is a botnet attack, and is performing brute force attack using default WordPress login (admin). A large botnet with more than 90k servers is attempting to log in by cycling through several passwords and usernames. So lets learn more on it below-

What is Botnet Attack?

  • Bot master: Usually the hacker who operates all infected computer.
  • Zombies computer/Bot: System which are infected by the Bot master, and helps in spamming. Usually owner of computers are unaware of the fact, that they are compromised. It could be anyone computer, including yours etc.

    How to Prevent WordPress from brute force attack?

    1. Install Limit login attempt plugin, hence it blocks individual I.P., in this botnet attack, hackers are running the attack using 90,000+ I.P.

  • 2. Use .htaccess to protect your admin pages and rename the login pages.

    3. Change your WordPress default username also

    4. Enable two-step authentication and

    5. Always use a complex password etc.

    That’s it! Also don’t forgot to make a backup of your blog for some extra security. Peace!



    10 April 2013

    Download free Phrozen Keylogger to capture all Keystrokes


    keylogger 2013 Are you fed up with all paid keyloggers? if yes, then today I will provide you a absolutely free software named as Phrozen Keylogger which is 100% free and full version. It is actually developed by Dark comet RAT developer. Now Phrozen Keylogger Lite is also compatible with Windows 8. Phrozen Keylogger Lite has been especially created to capture all keystrokes from any type of keyboard (PS/2, USB and even Virtual Keyboards). The captured keystrokes are stored into a local database. There they are sorted by their process name and the active window into a log.

    How it works?

    This software is silently activated in background. When the program is successfully installed on a computer, it will capture all keystrokes fully stealthily & the program will remain hidden from every user. It will not slow down the computer it is installed on etc.

    Now if you want to consult the logs of the current/previous days just hit the so-called “Magic Shortcut” and enter your personal password and the logs will be made visible in a new window. With this, You can easily manage, export, delete, mark as important, mail, etc. these logs.

    Download Phrozen Keylogger Lite v1.0



    04 April 2013

    World's biggest DDoS Attack Ever in the World


    DDoS attack Do you know my friends that last week it has been seen probably the largest distributed denial-of-service (DDoS) attack ever on Internet. Around 300Gbps was thrown against Internet blacklist maintainer Spamhaus' website but the anti-spam organisation , CloudFlare was able to recover from this attack and get its core services back up and running etc.

    The Spamhaus Project is an international organization based in both London and Geneva, founded in 1998 by Steve Linford to track email spammers and spam-related activity. The name spamhaus, a pseudo-German expression was coined by Linford for an Internet service provider, or other firm, which spams or knowingly provides service to spammers.

    “In the Spamhaus case, the attacker was sending requests for the DNS zone file for ripe.net to open DNS resolvers. The attacker spoofed the CloudFlare IPs we'd issued for Spamhaus as the source in their DNS requests. The open resolvers responded with DNS zone file, generating collectively approximately 75Gbps of attack traffic. The requests were likely approximately 36 bytes long (e.g. dig ANY ripe.net @X.X.X.X +edns=0 +bufsize=4096, where X.X.X.X is replaced with the IP address of an open DNS resolver) and the response was approximately 3,000 bytes, translating to a 100x amplification factor."

    Read also- How to Flood a Website with Denial of Service Attack

    Thats it!



    29 March 2013

    Best Vodafone and Airtel 3G + 2G Hack 2013


    vodafone hack 2013 Hope that you all are satisfied with my older posts. Now I am back again with a very interesting hacking tricks. This article is very good for Airtel and Vodafone users because in this article you can learn free 3G/2G hack of Airtel and Vodafone. By using these hack tricks you can enjoy your internet both in 2G and 3G speed. You can also download any thing in just few minutes. These tricks are also used by me and my friends but I am not sure that these hacking tricks will work in your region also but you are a very lucky person if these tricks works well in your region. Hope you all will like this article too.

    Hack Trick for Vodafone:

    Access point - internet
    Proxy - 186.149.156.119
    Proxy type - Real Host
    Homepage - google.com
    By applying these settings you can enjoy the internet in lightning fast speed.Enjoy...

    Hack Trick for Airtel:

    APN - airtelgprs.com
    Proxy - whatiswindpower.org
    Port - 80
    Homepage - http://202.46.201.115 or if have your own other selected free homepage

    That's all...

    About the Author:

    This is Sumit Dadwal from www.techstories.in



     

    Recent Posts

    Review this blog on Bloggers.com

    Recent Comments

    | KrackoWorld (KoW) © 2014. All Rights Reserved | Style By All Web Designing | | Contact |