| Welcome, Guest |
You have to register before you can post on our site.
|
|
|
| HQ dork tuts e-book 2020 |
|
Posted by: Blackhatking - 02-10-2020, 06:43 AM - Forum: Free Ebook Hacking
- No Replies
|
 |
Code: The contents of this section are hidden for your group
Register or Login
Hq dork tuts leaked by Blackhatcarding.ru
Don't mess with me, you will get disturb during the career.
Thanks to dork to find that shit.
|
|
|
|
| ♕Hack someone's Instagram Account LEAKED♕ 2020 |
|
Posted by: Blackhatking - 02-10-2020, 06:36 AM - Forum: Hacking
- No Replies
|
 |
This are Ways people use to hack Instagram this are not methods!
With more than 1 billion active users, Instagram is the second most used social networking website next to Facebook. So it is not a wonder to know that “hack [To see content please register here] ” is a widely searched keyword across the internet. There are tons of online websites and Android / iPhone apps that claims to hack someone’s Instagram account but merely none of the password hackers do the job for you.
Do you know why?
Because Instagram (owned by Facebook) take security seriously. They don’t want their users to suffer of such hacks. But still we see some people get their insta account hacked, that is majorly because of social engineering attacks like phishing, definitely not because of Instagram password hackers available online. So don’t become a victim of those downloadable apps and websites.
What we are going to see is a list of all the techniques possible to hack someone’s Instagram account and their respective prevention techniques.
Please remember that this article is written with the aim of educating people about how Instagram hacking works and how should they prevent such hacks. Therefore don’t use these techniques for malicious purposes.
1. [To see content please register here]
Remote keylogger is a piece of software (also called as spyware) that records whatever you type on your mobile or computer and send it to the person who installed it. So the passwords, credit card details and other sensitive information you input on your mobile or computer can easily be spied.
Most operating systems (including android & iOS) require root access before any app could record sensitive information. That’s why rooting / jail-breaking your phone isn’t a great idea when security is concerned.
Mobile spyware is a very useful software for parents who want to monitor their kids mobile activity. There are hundreds of free and paid spyware mobile apps and remote keyloggers available on the internet. You can google it for more details.
All key loggers requires physical access to install unless the device is rooted.
How to protect yourself from mobile key loggers?
Never root your mobile device. Rooting makes your device vulnerable.
Install any anti spy app to detect malicious application that has power to access your inputs.
Don’t use third party keypad apps unless you really trust the publisher.
2. Phishing
Phishing is a very successful technique used by hackers to hack an account’s password. It involves creation of a duplicate copy of a website’s login page to steal a user’s password. When a common user lands on such page, he/she might enter their username & password thinking that is legitimate login page and so they get their account hacked.
Instagram web based phishing page sample
Look at the image placed above, you might not have noticed a discrepancy in the URL ([To see content please register here] ). Spelling of the domain name, .com and forward slash is a crucial piece information to note whenever you find a login page. A legitimate URL should be [To see content please register here] , there shouldn’t be any change. If you notice any change, it must be a phishing page.
Instagram is a mobile app, we hardly use its web based login and hence phishing is not an easy way to hack Instagram password.
Since everybody is aware that Facebook account is enough to get started with Instagram, hacking someones Facebook account’s password leads to Instagram hacking. Therefore phishing your Facebook account password gets your Instagram account hacked.
Creating a phishing page isn’t rocket science. Thousands of websites provide direct download of phishing pages. Basic programming knowledge like php / html is pretty enough for anyone to get a phishing page done. So be cautious of phishing pages. Learn more about phishing.
3. Plain password grabbing
This is one of the most common methods exploited by hackers to hack instagram accounts. We have this bad habit of using the same password for all the websites we use. I call this a bad habit because all the websites are not equally built and secured. Facebook.com might have more security mechanisms in place than a poor xyz.com. Therefore a hacker gains access to poor xyz.com’s database can hack your instagram account easily.
A password should always be hashed before storing in a database. But small and medium sized website owners store passwords in plain text and hence it is easy for a hacker to steal your all-in-all password from the vulnerable website.
How to protect yourself from hacking passwords?
Never use a common password for day-to-day websites such as Google, Facebook, Instagram etc.
Have two kinds of passwords.
A strong password for important websites.
A common easy password for other unimportant websites. Hence avoiding the need to remember multiple passwords.
4. Weak Passwords
Guessing the password through social engineering allows one to hack instagram account. It isn’t a simple task if you have a strong password.
How can we say the password is weak?
Any password that is easily guessable by a third person or someone you know is a weak password. Some common weak passwords are given below.
Mobile Number
Nickname / Name and Date of Birth Conjunction
Boy Friend’s Mobile Number / Girl Friend’s Mobile Number – Most of the lovers
Girl Friend’s / Boy Friend’s Name – Most of the lovers
Boy or Girl Friend Name Combination
Bike Number
Unused / Old Mobile Number
Pet Name
Closest Person Name (can be friends too)
So if you have any one of the passwords listed above, you should change it immediately. Weak passwords are not limited to the list. We should avoid any password that is guessable.
As I have said earlier, always have two passwords. A strong password for important websites / apps and a common weak passwords for insignificant websites / apps.
5. Mobile Operating System Vulnerabilities
Android and iOS rules the world of mobile operating system and therefore vulnerabilities affecting the android and iOS can ultimately hack your mobile itself, instagram is just a part of it. These vulnerabilities are often addressed as zero day exploits. You really can’t do anything to prevent these vulnerabilities since we don’t have control over it.
Few things you can do to protect yourself
Always upgrade your operating system once an update is available. System upgrades includes important security patches, so it is mandatory to do.
Don’t ignore minor security updates from the mobile vendors.
Never install apps from unknown sources.
Install apps only from trusted publishers of app store.
6. Instagram zero day vulnerabilities
Last but not the least is Instagram vulnerabilities. Zero days are vulnerabilities that are unknown to the software vendor i.e instagram. Black hat hackers find vulnerabilities affecting instagram in order to hack accounts.
Being a commoner we can’t do anything if the vendor itself is vulnerable. All we can do is enable some basic security measures like two factor authentication.
|
|
|
|
| The Ultimate Beginner’s Guide to Learn and Understand Hacking Effectively 2020 |
|
Posted by: Blackhatking - 02-10-2020, 06:35 AM - Forum: Hacking
- No Replies
|
 |
This is a pdf file that will teach beginners that want to learn Hacking you will need to download the file.
here is what it will teach you Download link is at the end.
Introduction
Chapter 1: The Basics of Hacking
Different types of hackers
What skills do I need to start hacking?
Different attack types
Chapter 2: Doing a Penetration Test
Why should I do a penetration test?
Writing these reports
Chapter 3: Gaining Physical Access to the System
What vulnerabilities am I dealing with?
Creating a plan
Adding some physical controls
Technical controls
Chapter 4: Getting the Passwords You Need
Vulnerabilities that come with passwords
How to complete a password hack
Chapter 5: Social Engineering
Strategies for social engineering
Gaining trust
Phishing
Spamming
How to avoid these attacks
Chapter 6: Completing a Wireless Network Attack
WLAN attacks
How to verify a wireless network
WEP
WAP
How to do a spoofing attack
How to secure your wireless network
Chapter 7: How a Keylogger Can Help You
Logging the keystrokes
Conclusion
HACKING
The Utmost Intermediate Course Guide in the Concepts and Fundamentals of Hacking Introduction to Hacking
Chapter 1: The Fundamentals of Hacking
Chapter 2: Internet versus Intranet
Chapter 3: Remote Access and the Extranet
Chapter 4: The Concepts of Hacking – White Hat Hacking vs Black Hat Hacking
Chapter 5: Pentesting, Footprinting, and Scanning
Chapter 6: Enumeration and System Hacking
Chapter 7: Sniffing Traffic – Programs to Use and Benefits Conclusion
Download Mega.nz: [To see content please register here]
|
|
|
|
| ☠☠【 HACK WIFI - 2020 】☠☠ |
|
Posted by: Blackhatking - 02-10-2020, 06:34 AM - Forum: Hacking
- No Replies
|
 |
BHC TEAM
This is my first contribution to this great Community
Well, as all know, almost everyone wishes hack or connect to wifi without asking for that person the password or without know the password of that wifi
(This is seen more when you are away from home and don't have internet and want to connect to a Wi-Fi network)
Well, I haven't nothing else to say so let's go to the point.
This application is called as WPSApp, some knows that application and some don't know that application and don't knows hows works.
Code:
Code: The contents of this section are hidden for your group
Register or Login
Important things to mention:
- To see the passwords of the networks you have connected, need your device is rooted.*
- Not all networks are vulnerable and the fact that the network appears as such does not ensure 100% that it is, several companies have updated the firmware of their routers to correct the fault.
- The pin connection doesn't work on LG models with Android 7 (Nougat). It's a problem of LG's own software.
- As of Android 6 (Marshmallow) it is necessary to grant location permissions.
- Networks that cannot be hacked are those that have the wps protocol disabled.
- For a better chance of connecting to that WIFI, it's recommended that your device be rooted.
LINK: [To see content please register here]
Virustotal: [To see content please register here]
If you have any questions, don't hesitate to reply here.
Cheers
|
|
|
|
| Hackers Hijack Any Phone Just By Sending SMS 2020 |
|
Posted by: Blackhatking - 02-10-2020, 06:31 AM - Forum: Hacking
- No Replies
|
 |
Hackers Hijack Any Phone Just By Sending SMS
New SIM Card Flaw Lets Hackers Hijack Any Phone Just By Sending SMS
Cybersecurity researchers today revealed the existence of a new and previously undetected critical vulnerability in SIM cards that could allow remote attackers to compromise targeted mobile phones and spy on victims just by sending an SMS.
Dubbed "SimJacker," the vulnerability resides in a particular piece of software, called the S@T Browser (a dynamic SIM toolkit), embedded on most SIM cards that is widely being used by mobile operators in at least 30 countries and can be exploited regardless of which handsets victims are using.
What's worrisome? A specific private company that works with governments is actively exploiting the SimJacker vulnerability from at least the last two years to conduct targeted surveillance on mobile phone users across several countries.
S@T Browser [To see content please register here]
S@T Browser, short for SIMalliance Toolbox Browser, is an application that comes installed on a variety of SIM cards, including eSIM, as part of SIM Tool Kit (STK) and has been designed to let mobile carriers provide some basic services, subscriptions, and value-added services over-the-air to their customers Since S@T Browser contains a series of STK instructions—such as send short message, setup call, launch browser, provide local data, run at command, and send data—that can be triggered just by sending an SMS to a device, the software offers an execution environment to run malicious commands on mobile phones as well.
How Does Simjacker Vulnerability Work?
Disclosed by researchers at AdaptiveMobile Security in new research published today, the vulnerability can be exploited using a $10 GSM modem to perform several tasks, listed below, on a targeted device just by sending an SMS containing a specific type of spyware-like code.Retrieving targeted device' location and IMEI information,
Spreading mis-information by sending fake messages on behalf of victims,
Performing premium-rate scams by dialing premium-rate numbers,
Spying on victims' surroundings by instructing the device to call the attacker's phone number,
Spreading malware by forcing victim's phone browser to open a malicious web page,
Performing denial of service attacks by disabling the SIM card, and
Retrieving other information like language, radio type, battery level, etc.
"During the attack, the user is completely unaware that they received the attack, that information was retrieved, and that it was successfully exfiltrated," researchers explain.
The location information of thousands of devices was obtained over time without the knowledge or consent of the targeted mobile phone users. However the Simjacker attack can, and has been extended further to perform additional types of attacks."
This attack is also unique, in that the Simjacker Attack Message could logically be classified as carrying a complete malware payload, specifically spyware. This is because it contains a list of instructions that the SIM card is to execute.
Though the technical details, detailed paper and proof-of-concept of the vulnerability are scheduled to be released publicly in October this year, the researchers said they had observed real-attacks against users with devices from nearly every manufacturer, including Apple, ZTE, Motorola, Samsung, Google, Huawei, and even IoT devices with SIM cards.According to the researchers, all manufacturers and mobile phone models are vulnerable to the SimJacker attack as the vulnerability exploits a legacy technology embedded on SIM cards, whose specification has not been updated since 2009, potentially putting over a billion people at risk.Researchers says, the Simjacker attack worked so well and was being successfully exploited for years "because it took advantage of a combination of complex interfaces and obscure technologies, showing that mobile operators cannot rely on standard established defences .
- Step 1 . Attackers send a malicious OTA SMS to the victim's phone number containing an S@T or WIB command such as SETUP CALL, SEND SMS, or PROVIDE LOCATION INFO.
- Step 2 . Once received, the victim's mobile operating system forwards this command to the S@T or WIB browser installed on the SIM card, without raising an alert or indicating the user about the incoming message.
- Step 3 . The targeted browser then instructs the victim's mobile operating system to follow the command.
- Step 4 . The victim's mobile OS then performs the corresponding actions.
Video
|
|
|
|
|