Hôm rồi mình có tạo 1 site để get địa chỉ IP của người dùng yahoo... Trong quá trình tạo site và test mình thấy có khá nhiều lỗ hổng ở việc thiết lập các modem hiện nay. Thông qua các lỗ hổng này các hacker có thể :
Lấy được thông tin về mật khẩu Yahoo, Gmail, ... và hàng loạt trang khác.
Thay đổi DNS (Domain Name Server) mặc định (cực kì nguy hiểm - Có thể biến google.com thành site chứa mã độc).
Ăn cắp thẻ tín dụng, tài khoản game ... (thông qua thay đổi DNS server và dựng nên các site mạo danh ngân hàng, Ebank, hệ thống thanh toán trực tuyến).
Ngắt kết nối mạng của người dùng
Moi thông tin cá nhân của người dùng đó
Trong thời gian này mình khuyên các bạn nên kiểm tra lại thiết đặt modem... bằng cách sau
Thay đổi mật khẩu mặc định của modem (tốt nhất là mật khẩu trên 9 kí tự).
Đóng các port của modem nếu không thật sự cần thiết.
Modem đặc biệt dễ bị dính loại này là TD 8870 của VNPT. Viettel và FPT cũng không ngoại lệ.
Mong anh em cẩn thận.
Web chia sẻ thủ thuật máy tính, thủ thuật windows, thủ thuật internet, thủ thuật tin học, vi tính hay nhất, phần mềm miễn phí.
Showing posts with label Hacking and Security. Show all posts
Showing posts with label Hacking and Security. Show all posts
Monday, August 20, 2012
Thursday, July 12, 2012
Beginners guide to hacking
So first off I see a lot of people asking should I learn to program and what language to learn. So first off I would like to say that if you want to learn to hack, this would be a great skill to learn! All the hacking programs you see have been made with programming. If you know programming, than you will have a great start to hacking! So if you have decided that you want to learn programming, then a good language to start off on might be Python, I have heard that it is a bit choppy but personally it is the language I started off on, and the one that I found easy to learn. You can get python at its website:
http://python.org/
Some other languages that I know of but haven't really worked with are: C ,C++, C#, Java, Perl, Visual Basic, and PHP. Some tutorials that might be useful to you are:
Tutorial on C#
Tutorial on Python
Tutorial on Java
So I have been testing and messing around with ratting for a few weeks now. First off I'll let you know that RAT stands for "Remote Administrative Tool" Basically Rat is what it says it is, a tool to to let you remotely control a computer.
Some highlights of RAT'ing are:
- Screen Capture
- Sound Capture
- Webcam Capture
- Sending IM's to the slave
- Having all saved passwords
- Forceing the slave to go to a website
- Being able to see all the files on the slaves computer
- Remote scripting
- Hiding the desktop icons
- Hiding the taskbar
- Installing and deleting programs/files
- Playing piano noises on the slaves computer
Note: The 'slave' is the computer you are controlling.
I personally have decided not to RAT, because I would like to stay on the legal side of things, but this all personal preference I'm not going to tell you that you should or shouldn't. Some Tutorials that really go into depth on RAT'ing are:
Darkcomet R.A.T Tutorial
Cybergate R.A.T Tutorial
If you would like to read more about R.A.T's or just ask a question about a R.A.T than you should go to the following section.
R.A.T Section of HF
So this isn't exactly hacking but it is used for the same reason. Social Engineering (SE) is used to manipulate people or companies to get what you want. People use SE for all types of things, for example, you may want to manipulate a friend with the following e-mail to get their password.
"Hello Bob, we have received many notifications saying that someone is trying to log onto your account from a different location, and we will need the following questions answered to verify that this is your account:
Name-
Email-
Location-
Password-
Please reply with an email with those four questions answered. We are sorry for the inconvenience, but we would like to make sure that your account stays safe from malicious hackers.
Sincerely,
The Facebook Team"
If your lucky your slave would send you the E-mail and password to their account. SE is used for way more than just passwords though. Many people use SE to get free items from companies. If you would like to learn more on SE than you should go to the following section.
Social Engineering Section of HF
What key logging is, is a program that logs your (Or the person you send it to) key strokes on the keyboard. This is most commonly used to try and get passwords for facebook, gmail, xbox account, ect. If you would like to learn more about key logging, than you should head to the following section.
Key logging section
I don't really know much about this but I know that phreaking is phone hacking. To get more information on this type of hacking you should check out the following section.
Phreaking section
What this is to me is just URL hacking. Basically what you do is edit the URL of the page you are on until you can get to admin pages. The part of the site where you can learn more about SQLI injection is here.
SQL Injection section
Since this doesn't really tell you much I will link you to Wikipedia where the first paragraph pretty much says it all.
Wikipedia for SQL Injection
This is a kinda weird thing, and it's not really hacking. Since this does however have it's own section on the site, I thought I would tell you what it is, so at least you know. E-whoring is getting pictures of fairly hot women (Preferably naked) and selling them on sites such as Craigslist. When you sell the pictures you usually act like you are the girl, selling pictures of yourself. As you can see this is just a money making method, that I believe is illegal. I have talked to some people who have done this, and they have told me that you can make a lot of money doing this. One guy specifically made around $100 in a month! So there is a lot of money in this. The section for E-Whoring is here:
E-Whoring Section
There are plenty more types of hacking but these are just a few of the basic hacking types. I will post a more in depth guide later when I learn more about the different types of hacking myself, but I thought that this would help at least guide some of the newcomers on the site. I would also like to say that I am not responsible for any type of hacking that you do. This is just a a simple guide to help you decide where to start with hacking.
Thanks for reading this quick guide, if you have any questions feel free to PM me, and I'll try to get back to you as soon as possible. Finally the guide was made entirely by me, Blades. If you are going to share this with anyone please be sure to give the credit to the creator of the guide, me.
Thursday, July 5, 2012
32% máy chủ web .gov.vn mắc lỗ hổng nghiêm trọng
Có tới 32% máy chủ web của các cơ quan Nhà nước, Chính phủ đang tồn tại lỗ hổng nguy hiểm trong giao thức RDP (Remote Desktop Protocol), theo khảo sát mới nhất của Bkav.

Lỗi nghiêm trọng trong giao thức Remote Desktop của Windows đe dọa tới 32% máy chủ web của các cơ quan Nhà nước.Lỗ hổng RDP tồn tại trong giao thức kết nối Remote Desktop của Windows, dịch vụ thường được các quản trị mạng sử dụng để quản lý máy chủ từ xa. Lợi dụng lỗ hổng này, hacker có thể chiếm quyền Quản trị hệ thống và điều khiển máy chủ từ xa mà không cần mật khẩu.
Mặc dù Microsoft đã đưa ra bản vá vào trung tuần tháng 3 nhưng tại Việt Nam, vẫn có tới gần 1/3 các máy chủ web thuộc cơ quan Nhà nước, Chính phủ tồn tại lỗ hổng nguy hiểm này.
“Tình trạng lỏng lẻo trong công tác đảm bảo an ninh cho máy chủ web đã ở mức báo động đỏ. Việc kẻ xấu lợi dụng lỗ hổng để tấn công mạng máy tính bất kỳ lúc nào là nguy cơ sát sườn. Nếu tình trạng mất an toàn an ninh trong hệ thống mạng của các cơ quan Nhà nước, Chính phủ cứ tiếp tục như hiện nay sẽ đe dọa đến an ninh quốc gia”, ông Nguyễn Minh Đức, Giám đốc Bộ phận an ninh mạng Công ty Bkav cảnh báo.
Cuộc khảo sát của Bkav đã tiến hành với 520 website .gov.vn. Công ty này cho biết đã gửi cảnh báo và hướng dẫn cách khắc phục tới quản trị các hệ thống mắc lỗi. Người quản trị cần cập nhật bản vá bằng cách truy cập vào website của Microsoft và tìm kiếm với từ khóa: “MS12-020”.
Lỗi nghiêm trọng trong giao thức Remote Desktop của Windows đe dọa tới 32% máy chủ web của các cơ quan Nhà nước.
Mặc dù Microsoft đã đưa ra bản vá vào trung tuần tháng 3 nhưng tại Việt Nam, vẫn có tới gần 1/3 các máy chủ web thuộc cơ quan Nhà nước, Chính phủ tồn tại lỗ hổng nguy hiểm này.
“Tình trạng lỏng lẻo trong công tác đảm bảo an ninh cho máy chủ web đã ở mức báo động đỏ. Việc kẻ xấu lợi dụng lỗ hổng để tấn công mạng máy tính bất kỳ lúc nào là nguy cơ sát sườn. Nếu tình trạng mất an toàn an ninh trong hệ thống mạng của các cơ quan Nhà nước, Chính phủ cứ tiếp tục như hiện nay sẽ đe dọa đến an ninh quốc gia”, ông Nguyễn Minh Đức, Giám đốc Bộ phận an ninh mạng Công ty Bkav cảnh báo.
Cuộc khảo sát của Bkav đã tiến hành với 520 website .gov.vn. Công ty này cho biết đã gửi cảnh báo và hướng dẫn cách khắc phục tới quản trị các hệ thống mắc lỗi. Người quản trị cần cập nhật bản vá bằng cách truy cập vào website của Microsoft và tìm kiếm với từ khóa: “MS12-020”.
Tham khảo DanTri
Subscribe to:
Posts (Atom)
Popular Posts
-
Áo tắm của thí sinh hoa hậu Hong Kong bị nhận xét quá thoáng, Phạm Băng Băng mặc váy trong suốt và Jessica C khoe vòng 1 nóng bỏng là tin tứ...
-
What Is SQL Injection? 1-Introduction 2-Understanding How Web Applications Work. 3-A Simple Application Architecture 4-A More Complex Archit...
-
Ông Zhang ở Trịnh Châu (Trung Quốc) đã vác 10 thùng tiền lẻ gồm nhiều mệnh giá, cả tiền cũ lẫn mới, đến cửa hàng để “tậu” một chiếc xe hơi m...
-
Cô gái Pakistan chia sẻ những hình ảnh của mình trên Facebook khiến cộng đồng mạng Việt xôn xao. Cô gái có gương mặt đẹp đến hoàn mĩ. Cô gá...
-
Họ không phải là những anh chàng lăng nhăng, cư xử tệ bạc nhưng những kiểu đàn ông này lại tồn tại nhiều dấu hiệu "có vấn đề" dự b...
-
Một nữ giáo viên dạy môn học về sức khỏe và giáo dục giới tính tại một trường trung học ở Massachusetts, Hoa Kỳ đang phải đối mặt với cáo bu...
-
Giá vàng thế giới quay đầu giảm khi giới đầu tư chốt lời sau khi giá vàng lên mức cao nhất trong vòng 3 tháng qua. Tuy nhiên, trong sáng n...
-
Nga đã tăng cường nhóm quân sự hải quân ở Địa Trung Hải. Theo Bộ Tổng tham mưu, trong thời gian sắp tới cụm sẽ được điều động bổ sung một ch...
-
Xông vào nhà hiếp dâm xong còn đe dọa chủ nhà lấy tiền mang đi tiêu xài... 2 lần 'yêu' bé gái 12 tuổi, 'đổi' lấy 9 năm tù! H...
-
Đó là bày tỏ của bạn Dương Văn Đạt - Lớp Văn B, ĐHSP Thái Nguyên trong lá thư gửi đến Báo Giáo dục Việt Nam khi đề cập đến nhiều bất cập hiệ...