Tuesday, 22 October 2013

VirtualBox 3.2.8 Final Free Full Download




System virtualization to run and work on the same computer multiple virtual operating systems, similar to VMware Workstation and MS Virtual PC. Supports dynamic translation - to most of the instructions guest OS is on real hardware. As the host systems are supported 32 - and 64-bit versions of Linux, Windows, Mac OS, Solaris, as well as guest can serve Windows, GNU / Linux, BSD, Solaris and other operating systems. Pros: compact, proper support for VMware, high performance. Designed to create a virtual machine with the parameters of the real iron (your) computer, which can run any operating system. It is a handy feature, for example, for testing.

DOWNLOAD
Click Here TO Start VirtualBox 3.2.8 Download Part 1

Click Here TO Start VirtualBox 3.2.8 Download Part 2

Flash Decompiler GOLD 2.3.1.1300 free download






Flash Decompiler GOLD - a applicable tool for extracting resources from flash files. The program enables you to export images, sounds, fonts, texts, buttons, sprites, scripts, and frames from any SWF file. In addition, these resources can be exported in a format *. FLA. With one click you can easily convert file formats *. SWF or *. EXE.Vivid preview window makes Flash Decompiler GOLD easy to use. In tests, it works without a hitch and shows good speed.

top 3D Fiction ScreenSaver v64 Free Download


3dfiction Screensaver will develop your artistic sense and imagination. * 64 Unique 3dfiction Artworks * Ultimate Cross Fade Transition * Sequential or Random Item Order * 4:3 Full Screen Resolution (1600x1200, 1400x1050, 1152x864, 1024x768) * Wide Full Screen Resolution (1680x1050, 1440x900, 1280x800) * Sxga Full Screen Resolution (1280x1024) Default download mode is 4:3.

DOWNLOAD
Click Here TO Start top 3D Fiction ScreenSaver v64 Download

LimeWire Pro v5.5.13 Activated Version Free Download





LimeWire Pro - The Fastest P2P File Sharing Program on the Planet, running on the Gnutella Network. It is open standard software running on an open protocol, free for the public to use. LimeWire allows you to share any file such as.mp3s, .avis, jpgs, tiffs, etc., allows you to search for multiple files at the same time, available in several different languages, and is most famous for its ease-of-use and cross-platform compatibility.

Adobe Photoshop CS4 Extended Full Free Download





Adobe® Photoshop® CS4 software hasten your path from imagination to visual images. Ideal for photographers, graphic designers, and web designers, the professional standard delivers new emphasize such as automatic layer alignment and blending that enable advanced compositing. Live filters boost the comprehensive, nondestructive editing toolset for increased flexibility. And a streamlined interface and new timesaving tools make your work flow faster.

DOWNLOAD
Click Here TO Start Adobe Photoshop CS4 Download

USB Ultra Focus 1.1 acivated version free download




Welcome to Ultra Focus. Sounds from All the sizable Synthesizers: In the past, one would need to record sounds from a multiplicity of sources: modules, keyboards, even a good takes specimens. Today Ultra Focus take with you the best sounds from famous synths all in one virtual instrument.

DOWNLOAD


DOWNLOAD



USB.Ultra.Focus.v1.1.DVD.1.VSTi.DXi.RTAS.INCL.KEYGEN-TALiO (Disk1)

http://hotfile.com/dl/62455252/e4d14b6/USB.Ultra.Focus.v1.1.DVD.1.part01.rar.html
http://hotfile.com/dl/62455253/18032b7/USB.Ultra.Focus.v1.1.DVD.1.part02.rar.html
http://hotfile.com/dl/62455256/d252bc8/USB.Ultra.Focus.v1.1.DVD.1.part03.rar.html
http://hotfile.com/dl/62455265/56a51a7/USB.Ultra.Focus.v1.1.DVD.1.part04.rar.html
http://hotfile.com/dl/62455298/b020c23/USB.Ultra.Focus.v1.1.DVD.1.part05.rar.html
http://hotfile.com/dl/62455317/5b92474/USB.Ultra.Focus.v1.1.DVD.1.part06.rar.html
http://hotfile.com/dl/62455320/342f0d3/USB.Ultra.Focus.v1.1.DVD.1.part07.rar.html
http://hotfile.com/dl/62455355/f2795d5/USB.Ultra.Focus.v1.1.DVD.1.part08.rar.html
http://hotfile.com/dl/62455367/1a31189/USB.Ultra.Focus.v1.1.DVD.1.part09.rar.html

USB.Ultra.Focus.v1.1.DVD.1.VSTi.DXi.RTAS.INCL.KEYGEN-TALiO (Disk2)

http://hotfile.com/dl/62455425/d80f00b/USB.Ultra.Focus.v1.1.DVD.2.part01.rar.html
http://hotfile.com/dl/62455457/895bbe4/USB.Ultra.Focus.v1.1.DVD.2.part02.rar.html
http://hotfile.com/dl/62455491/eac7c27/USB.Ultra.Focus.v1.1.DVD.2.part03.rar.html
http://hotfile.com/dl/62455518/a0941d7/USB.Ultra.Focus.v1.1.DVD.2.part04.rar.html
http://hotfile.com/dl/62455534/7d6d45e/USB.Ultra.Focus.v1.1.DVD.2.part05.rar.html
http://hotfile.com/dl/62455587/865baea/USB.Ultra.Focus.v1.1.DVD.2.part06.rar.html
http://hotfile.com/dl/62455593/95b6a31/USB.Ultra.Focus.v1.1.DVD.2.part07.rar.html
http://hotfile.com/dl/62455605/33673c7/USB.Ultra.Focus.v1.1.DVD.2.part08.rar.html
http://hotfile.com/dl/62455645/6edf90a/USB.Ultra.Focus.v1.1.DVD.2.part09.rar.html

Opera 10.70 Snapshot Build 3486 Free Download





Opera 10.70 Snapshot Build 3486 l 12.18 MB Changes : Opera is advertised as “the fastest browser on earth” slogan, which was supported by many professional testing sound. Opera started out as a investigation project in Norway's big telecom company, Telenor, in 1994, and branched out into an independent evolution company named Opera Software ASA in 1995. Opera Software develops the Opera Web browser, a high-quality, multi-platform product for a wide range of platforms, operating systems and inserted Internet products.The successor of Opera 10.60 could very well be labeled Opera 10.70 still, but it could also end up sporting a different, superseding version.


DOWNLOAD

Click Here TO Start Opera 10.70 Snapshot Build 3486 Download

Google Earth Pro Final 4.2.0205.5730 Full Version Free Download





Google Earth Pro Final 4.2 Review

Google Earth Pro Review

Google Earth maps the Earth by the superimposition of images obtained from satellite imagery, aerial photography and GIS 3D globe. It is available under three different licenses: Google Earth,Google Earth Plus (discontinued), and Google Earth Pro which is intended for commercial use.Google Earth is available as a browser plugin for Firefox, Safari 3, IE6 and IE7.It is also available for use on personal computers running Microsoft Windows 2000, XP, Vista, Mac OS X 10.3.9 and above and Linux.

Cowon jetAudio / jet Audio 8.0.7.1000 Plus Full Version Free Download




jet Audio 7.5.1.2 Review


JetAudio is a highly advanced multimedia software that can play various music and video files, burn CD's and DVD's , record and convert to various popular formats. New jet Audio 8 is equipped with a feature called JetCast that enables it to create your own Internet broadcasting. Jetaudio supports all popular file formats and discs, including WAV, MP3, MP3Pro,OGG, WMA, MPG, AVI, WMV, MIDI, RM, and video, and audio CD Convert among audio file formats, and record analog audio to various formats.

AutoCAD 2010 Full Free Download


formulate and shape the round you with the powerful, pliable features found in 2010 AutoCAD conceive and documentation software, one of the world's leading 2D and 3D CAD tools. Speed documentation, share ideas inconspicuously , and investigate ideas more instinctively in 3D. With thousands of available add-ons, AutoCAD 2010 software provides the ultimate in flexibility, personalized for your specific needs. It's time to take design further. It's time for AutoCAD.Link

DOWNLOAD

Get FLV 8.9.231 full and activated version free download

Download Flash movies perfectly: On most sites, you can't download a Flash movie. With GetFLV, you can. It's easy to download Flash movies from Internet movie sites. Simply start the FLV browser, and visit your favorite video site. Select and play a video, and click "download" to save it to your hard drive.


GetFLV can reformat standard Flash movies in dozens of ways, specificlly:
FLV to WMA, FLV to AAC, FLV to DV, FLV to DVD, AVI to FLV, MPEG to FLV , MP4 to FLV, 3GP to FLV, MOV to FLV, WMV to FLV, DV to FLV, DVD to FL
FLV to AVI, FLV to MPEG, FLV to MP4, FLV to 3GP, FLV to MOV, FLV to WMV, FLV to MP3,


DOWNLOAD Click Here TO Start Get FLV 8.9.231 Download

Thursday, 3 October 2013

FPD aka Full Path Disclouser

Hey everybody.Today we are going to talk about a very common web vulnerbility "Full Path Disclosure".
Overview:=
Full Path Disclosure AKA, FPD vulnerabilities enable the attacker to see the internal path structure of an installation. Eg: /home/dir/htdocs/blahblah.

Severity:=Low to Medium

For FPD the severity level is said to be upto medium becoz usually, it's not a vulnerability. It's more of informational risk.
Most of the time it is not exploited itself.But it's a clue to exploitation of other web vulnerabilities like SQL injections loadfile() or LFI etc.


Reason:=
It may sometimes be due to web server application mis-configuration which reveals error messages to website 
visitors. Sometimes, an application itself generates debugging error messages.

How To Generate An FPD Error:=
As i said before that FPD can be very useful in cases like SQL injections loadfile() or LFI.So what if you got a site vulnerable to SQL injections loadfile() or LFI but you dont know the root path.There is nothing you can do to it.Once you get the root path you can continue your digging.
Below we are going to discuss some common well known and few less known methods of generating errors for FPD.


1-Empty Array
If we have a site that uses a method of requesting a page like this:
Quote:http://site.com/index.php?page=about

We can use a method of opening and closing braces that causes the page to output an error. This method would look like this:
Quote:http://site.com/index.php?page[]=about

This renders the page defunct thus spitting out an error:
Quote:Warning: opendir(Array): failed to open dir: No such file or directory in /home/omg/htdocs/index.php on line 84
Warning: pg_num_rows(): supplied argument ... in /usr/home/example/html/pie/index.php on line 131


2-Null Session Cookie

Another popular and very reliable method of producing errors containing a FPD is to give the page a nulled session using Javascript Injections. A simple injection using this method would look something like so:
PHP Code:
javascript:void(document.cookie="PHPSESSID="); 

By simply setting the PHPSESSID cookie to nothing (null) we get an error.
Quote:Warning: session_start() [function.session-start]: The session id contains illegal characters,
valid characters are a-z, A-Z, 0-9 and '-,' in /home/example/public_html/includes/functions.php on line 2

Errors can contain useful information for site owner so instead of disabling the error reporting at all, it is possible to only hide errors from output by display_errors.

3-Dorks:


We can also use dorks to find the errors on a specific site.
Warning: * [function.*]: site:yourtargeritehere.

I prefer using bing.com for this purpose especially when i have to search full server for an error message.
ip:xxx.xxx.xxx.xx sql error
ip:xxx.xxx.xxx.xx fatal error
ip:xxx.xxx.xxx.xx warning:* [function.*]

The creativity of your dorks is upto you.

4-Using SQL Injection Loadfile()
This is also a very good possiblity.I am going to discuss it later in another tutorial. Smile

How to Patch FPD:=
This vulnerability is prevented simply by turning error reporting off so your code does not spit out errors.
error_reporting(0);

php.ini
PHP Code:
display_errors = 'off' 

httpd.conf
PHP Code:
php_flag  display_errors  off 

Tools
https://code.google.com/p/inspathx/

Refrences:
http://yehg.net/l
https://www.owasp.org/index.php/Full_Path_Disclosure

How To Search For Exploits Using Exploit-DB search BackTrack - Terminal

In hacking we usually look for exploits to own the target, and today I'm going to show you how to look for exploits in Backtrack Inside your terminal!
What Many of us don't know, there is more than 15,000 exploits inside your backtrack written perl, ruby, python and more. But, today we'll learn how to search in those exploits easily, and faster than Googling!
When I use linux, I like to use the terminal for almost everything, and now, we will use it for exploit searching Wink
Lets start,


First of all open your terminal and type this command:



cd /pentest/exploits/exploitdb


[Image: Untitled.png]


as you can see, we have two files and a directory in that directory we entered. For now let's just focus on "searchsploit" file.
We will use this file to find the exploits on our PC, here is how to use it:



./searchsploit term1 term2 term3


what I mean in "term" is something that describes the exploit you're looking for, something that narrows down the search results to only the things you want.


For example, if you want an exploit for java inside windows, and we want the exploit to be DoS. Our command should look like this:



./searchsploit windows java dos


[Image: How+to+use+exploit+db+on+backtrack.png]
That .csv file contains all the names and paths of the exploits, and searchsploit try to find the right exploit for you
Easy, right?
Now you can change the terms and find the exploit you want.
Ok, so we get the exploit description, and a path...
As I mentioned before, there are two files, and one directory.. now we know what those two files do, it's the directory's turn now Tongue
that directory contains all of the exploits you need, and their paths.. so just enter, and copy the path to get it..
Let me show you an example.


We used the command:



./searchsploit windows java dos


and got some paths, here is how to get the exploits,


add "platforms" to the beginning of the path, for example
we got:



/windows/dos/11670.py


to read it use



cat platforms/windows/dos/11760.py


[Image: How+to+use+exploit+db+on+backtrack2.png]


That's it you guys =)
Have fun, and happy pentesting!

Threaded Mode | Linear Mode WHM/cPanel Access Hash Key - Adding Domains - Viewing Clients - RootkIt

Welcome To This Lesson ,, It's New And It was Private For Long Time =)

Our Focus is On cPanel/WHM

[Image: cpanel.jpg] 

We Often Hack Sites That Installed WHMCS As Hosting Manager

And We Don't See Password OF Root ,,, Or We See Unknown Password

Some OF These Problems Can Be Solved ,, But What About if we can't find password ?!!

may be we see Remote Access Hash Key

What Is Remote Access Hash Key ?!

It's Code That We Can Connect To Server And Manager Accounts 

Add Account - Suspend Account - Edit Password - Play Tongue

It's Not Normal MD5 Code In The Same Line 

I'm talking About Great Hash 

It Like This ..
Code:
767b2858b1a897b86ae1c3764937412b
59522de4e947c607022c223a76003518
2bd5beecffbf55f5c469a3eabed339ac
d9b6d6f97e04895d573be9f7864b5baa
547fd4bf3979f9b369855db746214904
6c47f85e76ed4efd330e1c2534fac7bb
101b83264ed58c129e9aa739aadc8bf9
bf4192e90cb6d035f0b5514efd23dcae
e98796a55082ea4f8329cc2bfa96a85e
a2233e3145f0033dd2dea96c10d88b1f
cea203d7fac890e59828e2a9f4b831dc
c5bfc593c18aa448117bfe590ae1618c
e47391302a073ea6cdd5e45b5fe386c6
23ec1fa296a4c3b0b20388c43ab19cd4
1e9b45b7795f15d599b89a1418c43019
d7b1554a9f89640c0a0ae3ac4b40045b
4f497ce4eb46f3a7b3c90f1a27ec9431
ca792e7992018f8a343326fe8e9fc2f3
315dd1272b5ee62269350c7bc75e35da
4851ec310e0dcb2c5644afb72f84aeb3
5239c8816a696435e8b4e7718e18fef6
a3a1041dc800cfa9abce8c830358762f
b0347197fe578ebabd75a9f9fa793852
f351cd781811bb55b86f8a8cfa796315
256cb3f59f6d8e6d3f61c37f4e848743
e9e7cc2dd8172dbe095cfb57b764d5fe
f0ca63276b708f3e42eca0f1d553ddef
9ceef46b40dd1c826ceb42fde190e9fb
00fbdd4d320d1a5bdb2747d67ef957f6


So ,, We'll Use It To Add Account Or To Suspend Tongue

But First ,, How To Generate This Code From cPanel ?!

It's Too Easy Just Go 2 WHM / 2086

[Image: dSk53260.png] 

Then Setup Remote Access Key

After This You'll Generate a Code From a Picture

[Image: bQk53359.png] 
Note : This Access Key For User "root"

Note 2 : If The root changed password of itself ,,, you would use the code normally

but if the root generated new key ,, the last key will be invalid Big Grin

==========

Okey Let's Return To WHMCS

I Hacked WHMCS But I Saw This

[Image: Fvk53694.png] 

You See No Password ,, Just Username And Access Hash Smile

For Example IP Address OF This Server is : 123.123.123.123

Now I Want To Play With Accounts Tongue

I'll Use CP_Creator Script OR Any Script Supports API/Access Key

Okay Let's Install it

[Image: 20b54480.png] 

Now Select Fresh Install For New Setup

[Image: YYO54609.png] 

Put The MysQL Settings 

HOST,USER,PASSWD,DATABASE

Now Put New Admin information

[Image: twn54650.png] 

I Put it admin:admin you can put it anything u want Big Grin

[Image: B3l54700.png] 

hehe Done Big Grin

Now We've To Go Administrator Panel

http://madleets.com/cp_/admincp.php

Then Go To Servers

[Image: jsU54779.png] 

And Select Add Server

[Image: Upb54831.png] 

Here We're ,, Put The Correct Information 

[Image: 8CS54943.png] 

Don't Forget Access Key Smile

Note : I Put Hostname As IP Address Of Server To Do No Problem With Connection Big Grin

Now We Save It Big GrinBig Grin Let's Play

Go To

[Image: qoD55022.png] 

And Now

[Image: 9FQ55143.png] 

Start Importing Accounts Tongue

[Image: Pw655186.png] 

hahaha 32 Accounts Big Grin In This Server Big Grin

Now To Play With These ACcounts Go TO

[Image: bEU55264.png] 

You'll See Accounts ..

[Image: cA955283.png] 

This is Picture That You Can Play With Accounts

[Image: B3c55386.png] 

No Make Domain Suspended Tongue Do That Big GrinBig Grin

 
lool ;P Suspended Big GrinBig Grin

Now We've To Add Accounts On cPanel Remotly 

Just Check Your Script's Settings

[Image: fpW55617.png] 
And Create New Package 

[Image: no555732.png] 

No Go to Index OF Script

[Image: 51U55793.png] 

Order Now Big GrinBig Grin

[Image: nea55826.png] 

Accept This And To Next Step

[Image: DDF55959.png] 

Check These Information ,,, I Want U to Put Script on Your localhost 

It's Better Than Any Server Smile

Now You've To Chose Domain or SubDomain

Then Type it

[Image: sga56134.png] 


Put Here The Password Of Your cPanel

[Image: wNE56277.png] 

hahaha

Now Your Account Has Added Successfully Tongue

For Checking

[Image: ISI56467.png] 



Another Photo

[Image: tBV56498.png]



===========

Root-Kit

I Named it Reseller-kit Tongue

if you want to be smart don't take Access Key For Root Big Grin

Take The Reseller's Key Wink

[Image: KxM56784.png] 

And Plaaaaay Tongue And Have Fuuuuun Tongue


To Download CP_CREATOR