This is only for education purpose.
So who ever try this is at his risk.
I am not sure that this will work 100 %.
But yes will work almost 70 percent of the times.
But before that you need to know some few things of yahoo chat protocol
leave a comment here after u see the post lemme know if it does works or not or u having a problem post here.
Following are the features : -
1) When we chat on yahoo every thing goes through the server.Only when we chat thats messages.
2 ) When we send files yahoo has 2 options
a) Either it uploads the file and then the other client has to down load it.
Either it connects to the client directly and gets the files
3) When we use video or audio:-
a) It either goes thru the server
Or it has client to client connection
And when we have client to client connection the opponents IP is revealed.On the 5051 port.So how do we exploit the Chat user when he gets a direct connection. And how do we go about it.Remember i am here to hack a system with out using a TOOL only by simple net commands and yahoo chat techniques.Thats what makes a difference between a real hacker and new bies.
So lets analyse
1) Its impossible to get a Attackers IP address when you only chat.
2 ) There are 50 % chances of getting a IP address when you send files
3 ) Again 50 % chances of getting IP when you use video or audio.
So why to wait lets exploit those 50 % chances.
I'll explain only for files here which lies same for Video or audio
1) Go to dos
type ->
netstat -n 3
You will get the following output.Just do not care and be cool
Active Connections
Proto Local Address Foreign Address State
TCP 194.30.209.15 : 1631 194.30.209.20 :5900 ESTABLISHED
TCP 194.30.209.15 : 2736 216.136.224.214 :5050 ESTABLISHED
TCP 194.30.209.15 : 2750 64.4.13.85 :1863 ESTABLISHED
TCP 194.30.209.15 : 2864 64.4.12.200 :1863 ESTABLISHED
Active Connections
Proto Local Address Foreign Address State
TCP 194.30.209.15 : 1631 194.30.209.20 :5900 ESTABLISHED
TCP 194.30.209.15 : 2736 216.136.224.214 :5050 ESTABLISHED
TCP 194.30.209.15 : 2750 64.4.13.85 :1863 ESTABLISHED
TCP 194.30.209.15 : 2864 64.4.12.200 :1863 ESTABLISHED
Just i will explain what the out put is in general.In left hand side is your IP address.And in right hand side is the IP address of the foreign machine.And the port to which is connected.Ok now so what next ->
2) Try sending a file to the Target.
if the files comes from server.Thats the file is uploaded leave itYou will not get the ip.But if a direct connection is established
HMMMM then the first attacker first phase is over
This is the output in your netstat.The 5101 number port is where the Attacker is connected.
Active Connections
Proto Local Address Foreign Address State
TCP 194.30.209.15 : 1631 194.30.209.20 :5900 ESTABLISHED
TCP 194.30.209.15 : 2736 216.136.224.214 :5050 ESTABLISHED
TCP 194.30.209.15 : 2750 64.4.13.85 :1863 ESTABLISHED
TCP 194.30.209.15 : 2864 64.4.12.200 :1863 ESTABLISHED
TCP 194.30.209.15 : 5101 194.30.209.14 :3290 ESTABLISHED
3) so what next???
Hmmm........ Ok so make a DOS attack now
Go to dos prompt and
Just do
nbtstat -A Attackers IPaddress.Can happen that if system is not protected then you can see the whole network.
C:\>nbtstat -A 194.30.209.14
Local Area Connection:
Node IpAddress: [ 194.30.209.15 ] Scope Id: []
NetBIOS Remote Machine Name Table
Name Type Status
-------------------------------- -------------
EDP12 <00> UNIQUE Registered
XYZ <00> GROUP Registered
XYZ <20> UNIQUE Registered
XYZCOMP1 <1E> GROUP Registered
MAC Address = 00 -C0 -W0 - D5 -EF-9A
Ok so you will ask now what next???
No you find what you can do with this network than me explaining everything.
so post ur comments and lemme know....
So the conclusion is never exchange files, video or audio till you know that the user with whom you are chatting is not going to harm you.
Friday, July 24, 2009
CRACK YAHOO,MSN,HOTMAIL,GOOGLE ACCOUNTS PASSWORD
We all use Hotmail.. well its one of my Favorites..
**Here m going to reveal n Alert About how the Unethical Hackers Can cheat us.
This Page is meant for Educational Purpose only.
I do not Endorse Hacking at all
but its Meant for knowing the Threats n Protect yourself also Curbing them**
Here we present:
1 :- How hotmail can be hacked with fake login screen (2 different ways)
2:- Fake e-mails threats
3:- Detect a fake message into hotmail
4:- How to get persons ip address through msn messenger
5:- curbing the way hackers get the passwords
6:- Easiest Way
7:- Change msn messenger title
8:- Protect yourself from Virus
9 :- Hoax Toolbox v1.1
1) Protect yourself from Phishing
Usually The Unethical Hackers Upload their hotmail's fake login screen on a web server and then send these codes
to the victim from yahoo or another mail sending program. The codes are
and the user will be automatically redirected to your fake hotmail screen from their e-mail
box & you r Hacked.
Beware of There Threats
2) Beware of Fake Login Screens
They Start chatting with your victim and send him the fake login screen through Their messenger and try to pish you.
there are many many of them available on the net.. which are usually small Visual Basic programs.. never reveal your password anywhere other than the latest Versions of msn Messengers.
2:- Fake e-mails threats
This is very easy go to http://www.boxfrog.com/ register( its blocked now) but there are many others.. google u ll find many
click on create message and in from filed type in any ones e-mail address and the message will
be sent.
there's also a simple way of doing this by Telnet ting from the dos Prompt..
Beware of this Threat.. make your spam protection Powerful
3) Detect a fake message into Hotmail inbox.
This is Simple Buddies.. open your e-mail box go to options select display setting or
message display setting or (some thing like this) now select full where it says message display
settings or something like this. Open the mail which u thought to be fake now in the last
where it says from u can see the address of that site from where the mail is sent but if
some one has sent it through some sort of program it will tell u his ip.
n once you know D ip m sure u know how to go between it there after
IMP: Read the ip address log from Backwards..
4)- Protect urself revealing your ip address through msn messenger.
When you Open your messenger start chatting with friend open ms dos and type netstat -n there
do not press enter and then minimize it after this send something to your victim and as soon as he accept it the hotmail messenger will say connecting this is the time when u re maximize your MS-DOS and
press enter the ip address next to time wait: will the friends ip. U may be Hacked The same way
Beware!!
HoaX Toolbox v1.1
This is a PHP script that creates a website with an admin area that allows the user to choose between fake login pages of MSN Messenger, Hotmail, Yahoo and Google Mail, once you set up the script on a server that has PHP and SQL you will be able to log in the administration page and choose the fake login page to display to the main site, when the victim tries to log-in their mail/messenger, the website keeps the user/pass information in a log file that you can view anytime from the admin area, if the victim is not stupid enough to add their real log-in because they read the URL of your server instead of reading hotmail.com or yahoo.com in the URL bar then remember you can pop-up the main page of the site and disable the URL bar on the explorer, so when the user clicks on your real site the link "Yahoo Mail" an explorer without URL bar pops up, if you don't know how to pop up customized browsers
**Here m going to reveal n Alert About how the Unethical Hackers Can cheat us.
This Page is meant for Educational Purpose only.
I do not Endorse Hacking at all
but its Meant for knowing the Threats n Protect yourself also Curbing them**
Here we present:
1 :- How hotmail can be hacked with fake login screen (2 different ways)
2:- Fake e-mails threats
3:- Detect a fake message into hotmail
4:- How to get persons ip address through msn messenger
5:- curbing the way hackers get the passwords
6:- Easiest Way
7:- Change msn messenger title
8:- Protect yourself from Virus
9 :- Hoax Toolbox v1.1
1) Protect yourself from Phishing
Usually The Unethical Hackers Upload their hotmail's fake login screen on a web server and then send these codes
to the victim from yahoo or another mail sending program. The codes are
and the user will be automatically redirected to your fake hotmail screen from their e-mail
box & you r Hacked.
Beware of There Threats
2) Beware of Fake Login Screens
They Start chatting with your victim and send him the fake login screen through Their messenger and try to pish you.
there are many many of them available on the net.. which are usually small Visual Basic programs.. never reveal your password anywhere other than the latest Versions of msn Messengers.
2:- Fake e-mails threats
This is very easy go to http://www.boxfrog.com/ register( its blocked now) but there are many others.. google u ll find many
click on create message and in from filed type in any ones e-mail address and the message will
be sent.
there's also a simple way of doing this by Telnet ting from the dos Prompt..
Beware of this Threat.. make your spam protection Powerful
3) Detect a fake message into Hotmail inbox.
This is Simple Buddies.. open your e-mail box go to options select display setting or
message display setting or (some thing like this) now select full where it says message display
settings or something like this. Open the mail which u thought to be fake now in the last
where it says from u can see the address of that site from where the mail is sent but if
some one has sent it through some sort of program it will tell u his ip.
n once you know D ip m sure u know how to go between it there after
IMP: Read the ip address log from Backwards..
4)- Protect urself revealing your ip address through msn messenger.
When you Open your messenger start chatting with friend open ms dos and type netstat -n there
do not press enter and then minimize it after this send something to your victim and as soon as he accept it the hotmail messenger will say connecting this is the time when u re maximize your MS-DOS and
press enter the ip address next to time wait: will the friends ip. U may be Hacked The same way
Beware!!
HoaX Toolbox v1.1
This is a PHP script that creates a website with an admin area that allows the user to choose between fake login pages of MSN Messenger, Hotmail, Yahoo and Google Mail, once you set up the script on a server that has PHP and SQL you will be able to log in the administration page and choose the fake login page to display to the main site, when the victim tries to log-in their mail/messenger, the website keeps the user/pass information in a log file that you can view anytime from the admin area, if the victim is not stupid enough to add their real log-in because they read the URL of your server instead of reading hotmail.com or yahoo.com in the URL bar then remember you can pop-up the main page of the site and disable the URL bar on the explorer, so when the user clicks on your real site the link "Yahoo Mail" an explorer without URL bar pops up, if you don't know how to pop up customized browsers
Labels:
Hack
Subscribe to:
Posts (Atom)
Follow Me... Stay Connected
MY STATS