Pages

Friday, December 14, 2012

Dictionaries & Wordlists


In general, it's said that using a GOOD 'dictionary' or 'wordlist' (as far as I know, they're the same!) is 'key'. But what makes them GOOD? Most people will say 'the bigger, the better'; however, this isn't always the case... (for the record this isn't my opinion on the matter - more on this later). 


Other than a mass of download links it contains pretty pictures and confusing numbers which shows the break down of statistics regarding 17 wordlists. These wordlists, which the original source(s) can be found online, have been 'analysed', 'cleaned' and then 'sorted', for example:

  • Merged each 'collection' into one file (minus the 'readmes' files)
  • Removed leading & trailing spaces & tabs
  • Converted all 'new lines' to 'Unix' format
  • Removed non-printable characters
  • Removed HTML tags (Complete and common incomplete tags)
  • Removed (common domains) email addresses
  • Removed duplicate entries 
  • How much would be used if they were for 'cracking WPA(Between 8-63 characters)
It may not sound a lot - but after the process, the size of most wordlists are considerably smaller!


Before getting the the results, each wordlist has been sorted differently rather than 'case sensitive A-Z'.
Each wordlist was:

  • Split into two parts - 'Single or two words' and 'multiple spaces'.
  • Sorted by the amount of times the word was duplicated - Therefore higher up the list, the more common the word is.
  • Sorted again by 'in-case sensitive A-Z'.
  • Joined back together - Single or two words at the start.
The reason for splitting into two parts  was that  'most' passwords are either one or two words (containing one space in them). Words which have multiple spaces are mainly due to 'mistakes' with when/how the wordlists was created. So having them lower down, should increases the speed the password is discovered, without losing any possibility.

The justification of sorting by duplicated amount was the more common the word is, the higher the chance the word would be used! If you don't like this method, you can sort it yourself back to case sensitive A-Z, however it can't be sorted how it was - due to the lists not having (hopefully) any duplicates in them!

When removing HTML tags and/or email addresses, it doesn't mean that it wasn't effective. If the word has contained some HTML tags and it was still unique afterwords, it wouldn't change the line numbers, it would improve the wordlist & it still could be unique It is also worth mentioning, due to a general rule of 'search & replace', it COULD of removed a few false positives. It is believed that the amount removed to the predicted estimated amount is worth it. For example instead of having three passwords like below, it would be more worth while to have just the two passwords:

  •  user1@company.com:password1
  •  user2@company.com:password1
  •  user3@company.com:password2


Download links for each collection which has been 'cleaned' is in the table below along with the results found and graphs. '17-in-1' is the combination of the results produced from each of the 17 collections. The extra addition afterwords (18-in-1), is a mixture of random wordlists (Languages (AIO), Random & WPA) which I have accumulated. You can view & download them here (along with all the others!). '18-in-1 [WPA]', is a 'smaller' version of 18-in-1, with JUST words between 8-63 characters. 

Collection Name
(Original Source)
Lines & Size
(Extracted/ Compressed)
DownloadMD5
Collection of Wordlist v.2374806023
(3.9GB / 539MB)
Part 1Part 2Part 35510122c3c27c97b2243208ec580cc67
HuegelCDC53059218
(508MB / 64MB)
Part 152f42b3088fcb508ddbe4427e8015be6
Naxxatoe-Dict-Total-New4239459985
(25GB / 1.1GB)
Part 1Part 2Part 3
Part 4Part 5Part 6
e52d0651d742a7d8eafdb66283b75e12
Purehates Word list165824917
(1.7GB / 250MB)
Part 1Part 2c5dd37f2b3993df0b56a0d0eba5fd948
theargonlistver14865840
(52MB / 15MB)
Part 1b156e46eab541ee296d1be3206b0918d
theargonlistver246428068
(297MB / 32MB)
Part 141227b1698770ea95e96b15fd9b7fc6a
theargonlistver2-v2 (word.lst.s.u.john.s.u.200)244752784
(2.2GB / 219MB)
Part 1Part 236f47a35dd0d995c8703199a09513259
WordList Collection472603140
(4.9GB / 1.4GB)
Part 1Part 2Part 3,Part 4Part 5Part 6,Part 7a76e7b1d80ae47909b5a0baa4c414194
wordlist-final8287890
(80MB / 19MB)
Part 1db2de90185af33b017b00424aaf85f77
wordlists-sorted65581967
(687MB / 168MB)
Part 12537a72f729e660d87b4765621b8c4bc
wpalist37520637
(422MB / 66MB)
Part 19cb032c0efc41f2b377147bf53745fd5
WPA-PSK WORDLIST (40 MB)2829412
(32MB / 8.7MB)
Part 1de45bf21e85b7175cabb6e41c509a787
WPA-PSK WORDLIST 2 (107 MB)5062241
(55MB / 15MB)
Part 1684c5552b307b4c9e4f6eed86208c991
WPA-PSK WORDLIST 3 Final (13 GB)611419293
(6.8GB / 1.4GB)
Part 1Part 2Part 3,Part 4Part 5Part 6,Part 758747c6dea104a48016a1fbc97942c14
-=Xploitz=- Vol 1 - PASSWORD DVD100944487
(906MB / 109MB)
Part 138eae1054a07cb894ca5587b279e39e4
-=Xploitz=- Vol 2 - Master Password Collection87565344
(1.1GB / 158MB)
Part 153f0546151fc2c74c8f19a54f9c17099
-=Xploitz Pirates=- Masters Password Collection #1! -- Optimized79523622
(937MB / 134MB)
Part 16dd2c32321161739563d0e428f5362f4
17-in-15341231112
(37GB / 4.5GB)
Part 1 - Part 24d1f8abd4cb16d2280efb34998d41f604
18-in-15343814622
(37GB / 4.5GB)
Part 1 - Part 24aee6d1a230fdad3b514a02eb07a95226
18-in-1 [WPA Edition]1130701596
(12.6GB / 2.9GB)
Part 1 - Part 15425d47c549232b62dbb0e71b8394e9d9
Table 1 - raw data
Table 2 - Calculated Differences
Table 3 - Summary
Graph 1 - Number of lines in a collection
Graph 2 - Percentage of unique words in a collection
Graph 3 - Number of lines removed during claning
Graph 4 - Percentage of content removed
Graph 5 - Percentage of words between 8-63 characters (WPA) *Red means it is MEANT for WPA*
A few notes about the results:
  • In the tables - 'Purehates' wordlist is corrupt and towards the end, it contains 'rubbish' (non-printable characters). Which is why it is highlighted red, as it isn't complete. I was unable to find the original. 
  • Table 3 which summarizes the results - shows that 57% of the 17 collections are unique. Therefore 43% of it would be wasted due to duplication if it was tested - that's a large amount of extra un-needed attempts!
  • In graph 2 - Only one collection was 100% 'unique', which means most of the collections sizes have been reduced.
  • In graph 5 - which is for showing how effective it would be towards cracking WPA. The four wordlists which were 'meant' for WPA, are in red.
In a few of the 'readme' file (which wasn't included when merging), several of them claimed to of have duplicates removed. However, unless the list is sorted, the bash program 'uniq', wouldn't remove the duplicates. By piping the output of 'sort', uniq should then remove the duplicates. However, using sort takes time, and with a bit of 'awk fu', awk '!x[$0]++ [filename], removes the need to sort. For example:
Valueuniqsort | uniq
or awk '!x[$0]++'
word1,word2,word2,word3word1,word2,word3word1,word2,word3
word1,word2,word2,word3,word1word1,word2,word3,word1word1,word2,word3
word1,word2,word1,word1,word2,word3,word1word1,word2,word1,word2,word3,word1word1,word2,word3


The commands used were:
Step By Step 

# Merging
rm -vf CREADME CHANGELOG* readme* README* stage*
echo "Number of files:" `find . -type f | wc -l`cat * > /tmp/aio-"${PWD##*/}".lst && rm * && mv /tmp/aio-"${PWD##*/}".lst ./ && wc -l aio-"${PWD##*/}".lst
file -k aio-"${PWD##*/}".lst

# Uniq Lines
cat aio-"${PWD##*/}".lst | sort -b -f -i -T "$(pwd)/" | uniq > stage1 && wc -l stage1

# "Clean" Lines
tr '\r' '\n' < stage1 > stage2-tmp && rm stage1 && tr '\0' ' ' < stage2-tmp > stage2-tmp1 && rm stage2-tmp && tr -cd '\11\12\15\40-\176' < stage2-tmp1 > stage2-tmp && rm stage2-tmp1
cat stage2-tmp | sed "s/ */ /gI;s/^[ \t]*//;s/[ \t]*$//" | sort -b -f -i -T "$(pwd)/" | uniq > stage2 && rm stage2-* && wc -l stage2

# Remove HTML Tags
htmlTags="a|b|big|blockquote|body|br|center|code|del|div|em|font|h[1-9]|head|hr|html|i|img|ins|item|li|ol|option|p|pre|s|small|span|strong|sub|sup|table|td|th|title|tr|tt|u|ul"
cat stage2 | sed -r "s/<[^>]*>//g;s/^\w.*=\"\w.*\">//;s/^($htmlTags)>//I;s/<\/*($htmlTags)$//I;s/&*/&/gI;s/"/\"/gI;s/'/'/gI;s/'/'/gI;s/</ stage3 && wc -l stage3 && rm stage2

# Remove Email addresses
cat stage3 | sed -r "s/\w.*\@.*\.(ac|ag|as|at|au|be|bg|bill|bm|bs|c|ca|cc|ch|cm|co|com|cs|de|dk|edu|es|fi|fm|fr|gov|gr|hr|hu|ic|ie|il|info|it|jo|jp|kr|lk|lu|lv|me|mil|mu|net|nil|nl|no|nt|org|pk|pl|pt|ru|se|si|tc|tk|to|tv|tw|uk|us|ws|yu):*//gI" | sort -b -f -i -T "$(pwd)/" | uniq > stage4 && wc -l stage4 && rm stage3

# Misc
pw-inspector -i aio-"${PWD##*/}".lst -o aio-"${PWD##*/}"-wpa.lst -m 8 -M 63 ; wc -l aio-"${PWD##*/}"-wpa.lst && rm aio-"${PWD##*/}"-wpa.lst
pw-inspector -i stage4 -o stage5 -m 8 -M 63 ; wc -l stage5
7za a -t7z -mx9 -v200m stage4.7z stage4
du -sh *

AIO + Sort

cat * > /tmp/aio-"${PWD##*/}".lst && rm * && mv /tmp/aio-"${PWD##*/}".lst ./

tr '\r' '\n' < aio-"${PWD##*/}".lst > stage1-tmp && tr '\0' ' ' < stage1-tmp > stage1-tmp1 && tr -cd '\11\12\15\40-\176' < stage1-tmp1 > stage1-tmp && mv stage1-tmp stage1 && rm stage1-*

htmlTags="a|b|big|blockquote|body|br|center|code|del|div|em|font|h[1-9]|head|hr|html|i|img|ins|item|li|ol|option|p|pre|s|small|span|strong|sub|sup|table|td|th|title|tr|tt|u|ul"
cat stage1 | sed -r "s/ */ /gI;s/^[ \t]*//;s/[ \t]*$//;s/<[^>]*>//g;s/^\w.*=\"\w.*\">//;s/^($htmlTags)>//I;s/<\/*($htmlTags)$//I;s/&*/&/gI;s/"/\"/gI;s/'/'/gI;s/'/'/gI;s/</ stage2 && rm stage1

sort -b -f -i -T "$(pwd)/" stage2 > stage3 && rm stage2
grep -v " * .* " stage3 > stage3.1
grep " * .* " stage3 > stage3.4
rm stage3
for fileIn in stage3.*; do
   cat "$fileIn" | uniq -c -d > stage3.0
   sort -b -f -i -T "$(pwd)/" -k1,1r -k2 stage3.0 > stage3 && rm stage3.0
   sed 's/^ *//;s/^[0-9]* //' stage3 >> "${PWD##*/}"-clean.lst && rm stage3
   cat "$fileIn" | uniq -u >> "${PWD##*/}"-clean.lst
   rm "$fileIn"
done
rm -f stage* #aio-"${PWD##*/}".lst

wc -l "${PWD##*/}"-clean.lst
md5sum "${PWD##*/}"-clean.lst


If you're wanting to try this all out for your self, you can find some more wordlists here:



As mentioned at the start, whilst having gigabytes worth of wordlists may be good and all... having a personalised/specific/targeted wordlist is great. PaulDotCom (great show by the way), did just that a while back.

As the password has to be in the wordlist, and if it doesn't have the correct password you could try crunch (orL517 for windows) to generate your own. For a few good tutorials on how to use crunch, check here and here (I highly recommend ADayWithTape's blog).

As waiting for a mass of words to be tried takes some time - it could be sped up by 'pre-hashing'. For example this WPA-PSK is vulnerable, however WPA-PSK is 'Salted' (By using the SSID as the salt). This means that eachpre-hashes table is only valid for THAT salt/SSID. This isn't going to turn into another 'How to crack WPA', as its already been done. It was just mentioned due to this and this could help speed up the process.


Instead of brute forcing your way in, by 'playing it smart', it could be possible to generate/discover the password instead. This works if the algorithm has a weakness, for example here, or if the system is poor, for example here.However, finding a weakness might take longer than trying a wordlist (or three!).


When compiling all of this, I came across this, Most 'professional password guessers' known:

  • There is a 50 percent chance that a user's password will contain one or more vowels
  • If it contains a number, it will usually be a 1 or 2, and it will be at the end
  • If it contains a capital letter, it will be at the beginningfollowed by a vowel
  • The average person has a working vocabulary of 50,000 to 150,000 words, and they are likely to be used in the password. 
  • Women are famous for using personal names in their passwords, and men opt for their hobbies
  • "Tigergolf" is not as unique as CEOs think. 
  • Even if you use a symbol, an attacker knows which are most likely to appear: ~!@#$%&, and ?.


When your password has to be 'least 8 characters long and include at least one capital' it doesn't mean: 'MickeyMinniePlutoHueyLouieDeweyDonaldGoofyLondon'. And for the people that made it this far down, here is a 'riddle' on the the subject of passwords.

I would like to thank 'connection' for a helping hand with the bash commands =).

credit to ~g0tmi1k (http://g0tmi1k.blogspot.com)

Sunday, December 9, 2012

Introduction to ARP – Poisoning


Man-In-The-Middle attack using ARP spoofing
ARP stands for Address Resolution Protocol. ARP acts as a layer over the Internet Protocol address (IP) and converts it into a Media Access Control address (MAC address) or Ethernet Hardware Address (EHA). Understanding the concept of ARP is very important for a hacker because, a potential hacker will be able to poison the network and steal the information running between two servers. Hence he can execute a ‘Man-In-The-Middle‘ attack using a simple ARP poisoning tool such as Cain & Abel. The function of Cain & Abel is similar to a packet sniffer.
MAC address is a unique identification address for network nodes, such as computers, printers, and other devices on a LAN.  MAC addresses are associated to network adapter that connects devices to networks.  The MAC address is critical to locating networked hardware devices because it ensures that data packets go to the correct place.  ARP tables, or cache, are used to correlate network device’s IP addresses to their MAC addresses.
How it works?
Consider you want the phone number of a person whose name is already known to you. In that case you will checkout your telephone book and if the number is not available the you will call the phone service and request him the number. Here the telephone directory act as ARP tables and the phone service as ARP. ARP tables give the list of addresses of computers which are connected to that system inside the network.
What is ARP poisoning?
If a system(say System 1) requests to connect to another system(System 2) inside the network, then System 2 checks the entry of the System 1 in its ARP tables and if the entry is not present then it is automatically added in System 2′s ARP tables. The weakness of the ARP is that, it cannot identify if a person request to connect with it showing a another address. Therefore a hacker can easily poison this network, that is, a potential hacker if sends a request to connect to System 2 showing the IP address of System 1 then he can access the network of System 1 associated with System 2! So he will be able to obtain the information passing between them. That is, there is another path executed between the System 1 and System 2.
Suppose, if a hacker has poisoned a path between social networking site and a victim’s system then he would be able to steal the information passing between them, like username and password etc.
So here, in this case the phone service is calling you and giving you the number, even though you haven’t requested it! (Scenario mentioned above)
The concept of ARP with a simple example:
The attacker: 10.0.0.1
MAC address: 00-AA-BB-CC-DD-00
The victims: 10.0.0.2
MAC address: 00-AA-BB-CC-DD-E1
Fake address:10.0.0.3
MAC address: 00-AA-BB-CC-DD-E2
A potential hacker sends a packet (request to connect) to 10.0.0.2 with spoofed IP of  10.0.0.3 and then it sends a crafted package to 10.0.0.3 with  spoofed IP of 10.0.0.2 with his own IP. This means that both victims think they can find each other at the MAC address of the attacker. This is known as Man-In-The-Middle attack
Now all the traffic between those 2 hosts will go through the attacker first. So this means that the attack will need to reroute the packets to the real destination else you get a DOS on the network and there will be no traffic possible. Also remember that the ARP tables get updated so if during a long period of time there is no ARP poisoning the entries will be deleted and you won’t be able to sniff until you start poisoning again.
http://basichackingskills.wordpress.com/ 

Saturday, December 8, 2012

RA1N DoSer v4 (lite)



Flooding

  • UDP
  • TCP
  • SYN




Features

  • Port Scanning (100+ times faster than RDv3)
  • History
  • Favorites
  • Awesome CPanel
  • Defualts for input fields for flooding
  • and more!




Tech Specs:

  • Over 25kbs a UDP Flood
  • Cusstomizable SYN Flooding (using exploitations)
  • Encrypted source (noobs piss me off)
  • TCP Flooding (very efficient)
  • program averages only 5,000 kbs of processing





[x] Download ->
Code:  http://dl.dropbox.com/u/32095117/RA1N/RDv4/RDv4.exe
[x] Virusscan ->
Code: https://www.virustotal.com/file/7fd5d9978a966827b74426a657c8b66abf9604a4742b2cf1718f87136e99fb23/analysis/1351546234/

credit : RA1N

Acunetix Web Vulnerability Scanner 8.x Enterprise Edition KeyGen


       This is a network vulnerability scanning tools. Web crawler to test your website security, testing the popular attacks such as cross-site scripting, sql injection. Been hacked before scanning cart, forms, security zones and other Web applications. 75% of Internet attacks target Web-based applications. Because they often access to confidential data and is placed before the firewall.

2012.05.11-original Enterprise Edition is not the most expensive, it is updated with the most expensive version of the key to do RI.

Official original download address: http://www.acunetix.com/download/fullver8
ID: acunetixwvsfullv8 PASSWORD: nFu834! 29bg_S2q

Found that does not support the directory listing, direct to a new version of the download path can also automatically install this upgrade:

Description: first official address to download the latest Enterprise Edition installation package [RI only supports the Enterprise Edition does not support the free version] to close the program after the installation is complete, open the crack, Point Patch registered the following registration information, registration then support normal upgrade!

Do not be used for illegal purposes, or peril! 
License Key:   5s3b6136t52s56de60d1e76fgd4f7d5h
Name: Hmily / [LCG]
ComPany: Www.52PoJie.Cn
Email: Hmily@Acunetix.com
Telephone: 110

Acunetix_Web_Vulnerability_Scanner_8.x_Consultant _Edition_KeyGen.exe
MD5: 6EF77924A7D92E6FF168053E3B4A5814
Acunetix_Web_Vulnerability_Scanner_8.x_Consultant_Edition_KeyGen_Hmily [LCG]. Rar
MD5: 302C3EC2C7F726E253400CAB654C7AF5

Forum download:

Network disk download:

source :  http://hi.baidu.com

Wednesday, December 5, 2012

Games for Hackers


Hackthissite – http://www.hackthissite.org
A nice site (even though it has been having problems recently) including basic web challenges, “realistic” missions, basic cracking and encryption challenges.

ngsec – http://www.ngsec.com
A great website, with some tough final challenges. Including SQL Injection and some Buffer overflow challenges.

Try2Hack – http://www.try2hack.nl
One of the most well known hacking challenge sites, its levels are basic and ideal for those new to security.

Hackerslab – http://www.hackerslab.org
A great site with levels based around unix security, you’ll either want to use linux or have a copy of putty to complete any of these challenges.

SlyFX – http://www.slyfx.com
A great challenge site, starts off with some basic maths and moves onto solving application problems (starts with some basic debugging and moves onto solving stuff)

Mod-X – http://www.mod-x.co.uk
Never completed this site, got a little bored with it. But on the whole rather good, if you’ve played the game uplink it’s that sort of story (i think, as I said, never really played it 

I got bored at lvl3 )

HackMe @ Elderson – http://hackme.elderson.net
Only a few challenges, but they are interesting ones.

Mindlock Security Challene – http://mindlock.bestweb.net/join.php

Zebulun Challenge – http://www.cyberarmy.com/zebulun/

Root Hack – http://www.roothack.org/

Hack Test -   http://www.hackertest.net

DataFort – http://hack.datafort.net/

HackNull – http://hacknull.com/

Digital Evolution – http://wargames.unix.se/

Osix Challenges – http://www.osix.net/

H4cherx Challenges – http://www.h4ckerx.ne

The Black Sheep – http://www.bright-shadows.net/

0penhack – http://www.0penhack.com/

ISATCIS – http://scifi.pages.at/hackits/

“The Game” – http://lightning.prohosting.com/~thegame/
Real applets which have been used in the real world, all client side editing.

HackQuest – http://www.hackquest.de/

BigContent – http://bigcontest.securityhack.net/ – In French

hackerss.com – http://www.hackerss.com/ – Spanish

izhal – http://www.izhal.com/ – Spanish

Boinas Negras – http://www.boinasnegras.com/ – Spanish

Hack4u – http://www.hack4u.nl

credit to BigBoss 

Tuesday, December 4, 2012

B2 DoS Tool


[Image: fe459b3c1c57674ccc9c1298e22c0b52.png?1353101973]



B2 DoS Tool
Created By ๖ۣۜStealth
Features :
{~UDP Flood~}
{~Resolve Host~}
{~Ping Host / IP~}
{~Credits~}

Download :

MEDIAFIRE


source : freehacktools.com

Sunday, December 2, 2012

Money Making


---------->> Leak of the Day <<--------------- 
Category: Money Making.. 
Name: Earn by Daily 15 Minutes.. 
Sales Page: http://www.warriorforum.com 
Download: http://www.mediafire.com/?j1bqtkd1jywbr59 
Size: 94mb 



---------->> Leak of the Day <<---------------
Category: Money Making..
Name: Earn $75 a day (autopilot)
Download: http://fpk.im/gvtr
Passwd: dirtyrules

credit:DirTyMiNd