Pages

Showing posts with label Phreaking. Show all posts
Showing posts with label Phreaking. Show all posts

Friday, April 5, 2013

How to Run Backtrack 5 on Android



Backtrack is a popular linux dsitrubiton known for...umm..well hacking WEP. Actually, as people like to say..used for testing out the security of their networks. So, there's an arm version available which means it can run an android devices, here's how.
Quick links:

Backtrack 5 for ARM:
http://www.backtrack-linux.org/downloads/

commands:
su
cd /sdcard/BT5
sh bootbt
export USER=root
vncpasswd
(make up any password)

Android VNC: download
Terminal Emulator: download
BusyBox: download
7Zipdownload

Link to full instructions: here

Thursday, April 4, 2013

Hack Computers and Other Network Devices using Android


Hey peeps, what's up! So, I'm here to show you another network penetration app.
This one goes beyond the capabilities that you've seen in my last network penetration video,
which you can see here:
http://www.youtube.com/watch?v=FR9vFmxNLKI 

 This one gives you features such as Cookie Hi-jack, and password sniffer, and a lot of other neat things. 

**Remember, this is for education purposes only!!! To strengthen the security of your own network**
 Link to Developer's page for App:
http://dsploit.net/

Saturday, February 2, 2013

Costly Android Malware Infects 600,000 Users in China, Firm Says

Researchers from mobile security firm NQ Mobile have uncovered what they are calling “a nasty piece of malware” that has already infected more than 600,000 users in China.

Named “Bill Shocker” by the China-based mobile security firm, the malware is potentially one of the most costly viruses yet discovered, the company said.
“Bill Shocker is an SDK-type virus (Software Development Kit). Our experts, using NQ’s RiskRanker system, found the virus attached to several of the most popular mobile apps in China, including Tencent QQ Messenger and Sohu News,” the company explained.

The malware is propagating via third-party online app stores and retail installation channels, something the company says is allowing it to “spread like wildfire”.
The Bill Shocker malware downloads itself in the background on a users’ Android device without their knowledge and takes remote control of the device, including accessing contact lists, Internet connections, dialing and texting functions.

“Once it’s turned your phone into a “zombie,” it sends text messages that create financial gains for advertisers. In many cases, the threat will overrun a user’s bundling quota, which subjects you to even more unwanted charges,” the company said.

While the malware may not steal data or cause other damage to the device, NQ Mobile still considers it a threat due to the fact that it can rack up a users’ phone bill by sending costly messages.
NQ says it has notified Chinese mobile carriers of the threat, and has provided its technology to China’s top mobile carriers including, China Mobile and China Unicom as well as Baidu Mobile Services, to help reduce the spread of mobile malware.

This past summer, researchers from TrustGo discovered a mobile threat targeting Android phones that was said to have infected roughly 500,000 devices, mainly in China. Called “SMSZombie”, the malware was little threat to users outside of China, as the prime function of the mobile malware was to exploit a vulnerability in the mobile payment system used by China Mobile, making it of little value to the fraudsters outside of China.

SecurityWeek contacted Lookout, a mobile security firm based in San Francisco, to see if they had any information on the "Bill Shocker" threat. A Lookout spokesperson toldSecurityWeek that it was hard to measure the threat’s significance without access to the sample. “As soon as NQ releases more details on the threat, we'll be able to determine if this is in fact a new threat, and who it is affecting,” the spokesperson said.

That big, scary call recording malware isn't in the Android Market

Here we go again, folks. Look -- malware, by definition, is bad and absolutely should be taken seriously. So when Total Defense (née CA Community -- it's a rebranding thing) points out that it's possible for some rogue code to record your phone calls and even send them off to some far-away land (China, of course), well, it's something that we all need to pay attention to. But things also need a little perspective. Total Defense tells us that it's received just four cases of this malware, from 13 unique sources, for 14 total incidents, and TD can't tell us with any specificity just how prevalent this piece of malware is. There are more than 550,000 Android devices being activated every day. Perspective, ya know. Now, as far as your likelihood of being affected by this piece of malware, Total Defense tells us: "there are very high chances as anybody can customize this to lure their victims to fall into the trap." Scary, ain't it? Only, here's the thing, and it's an important one for most of you: Not a single instance of this malware was reported from coming from an app in the Android Market. That's not to say malicious apps haven't made it into the Market before -- it's happened, and it'll happen again, and we suspect Google will act as swiftly as it has in the past. But unless you're wandering around app "stores" you probably shouldn't be wondering around in the first place, we wouldn't worry too much.

Android NFC 'hacking' is ingenious, but not yet dangerous

The Black Hat conference takes place in Las Vegas this week, where hackers, security experts and representatives from major companies meet to discuss all things relating to information security. If you're following the news out of the conference today, you may have come across reports of a new security vulnerability in Android (and NFC-enabled Meego phones) that could allow a malicious NFC (near-field communication) tag to beam malware directly onto your phone. Sounds terrifying, right? Now hackers can take over your smartphone without you even doing anything. But as is always the case with these kinds of security issues, it's not as simple as it seems. And this NFC 'hack,' sexy and technically impressive as it is, isn't really anything particularly scary to regular smartphone users. Read on to find out why. First off, we should quickly explain what NFC actually is. It stands for near-field communication, and it's a a very short-range wireless communication technology designed for sending small amounts of data instantly over very short distances. On smartphones, this can be used to transfer things like URLs from one handset to another, or alternatively to scan NFC "tags," which can themselves contain small quantities of data that the phone can then act upon. It can also be used for facilitate payments, for example via Google Wallet. (Read more in our Android A-Z) Multiple sources report that security researcher Charlie Miller demonstrated a variety of techniques for hacking into the Nexus S (on Gingerbread), the Galaxy Nexus (on Ice Cream Sandwich) and the Meego-powered Nokia N9 at Black Hat this week. Many of the scariest exploits were found on the N9, but we'll focus on Android here, 'cause that's what we do. (And that's also what many of today's headlines focus on.) Starting at the high end, on the Galaxy Nexus Miller demonstrated that NFC-enabled Android phones running Ice Cream Sandwich or later use Android Beam, a feature which some (but not all) have turned on by default. Amongst other things, Beam lets users load URLs from another phone or NFC tag directly into the device's web browser. That means it's possible, with a malicious NFC tag, to send an unassuming user directly to a malicious web page. For that to work, though, the tag needs to be within the very short range at which NFC radios can operate -- basically all but touching the back of the device. Android Beam opens tagged URLs automatically without any prompt, by design. It's a valid security concern, but not an exploit in the traditional sense, as in order to do anything you need to find a vulnerability in the user's web browser of choice. If you're using the built-in Android browser on Android 4.0.1, then such a bug exists, and that could allow a specially designed web page to run code on the device. Again, an entirely valid security issue, but using NFC as a delivery method for this kind of exploit is far from practical. Not to mention Android 4.0.1 was only released on the Galaxy Nexus, a phone which has since been updated to Android 4.0.4 or 4.1.1, depending on your carrier. Miller also demonstrated how he could exploit bugs in Android 2.3's memory management to cause a Gingerbread device with NFC support to execute code using a malicious tag. That potentially gives an attacker the ability to take complete control of the device using only an NFC tag, but we should point out a few factors that make this a less serious issue that you might think. Sure, Android 2.3 Gingerbread is still the most-used version of Android, and many new Android devices ship with NFC support, but there's little cross-over between the two. The Nexus S was the first Android handset to support NFC, but that's since been updated to Jelly Bean. Other NFC-supporting devices shipped on 2.3, but most of the mainstream Android phones with NFC run at least version 4.0.3, which isn't vulnerable to the exploits used in this demo. In fact, we can't think of a single Gingerbread phone with NFC that's yet to be updated to at least Android 4.0.3. So vulnerabilities certainly exist, but right now the only serious ones are limited to a very small subset of the Android population with NFC, and a very specific OS version. What's more, the phone needs to be powered on, the NFC radio needs to be enabled, and the user needs to be distracted enough so as not to notice the tell-tale NFC tone or vibration. Ultimately, any exploit involving physical access to the device being hacked is going to be of limited use to the real bad guys. Taking control of a smartphone over NFC in the real world is going to be dangerous and impractical to would-be perps, even after the methods shown at Black Hat are publicized. If I have access to your phone, powered on, for an extended period, with malicious intent, NFC isn't going to be my first port of call. The exploits demonstrated by Charlie Miller this week are ingenious and undeniably cool to read about. But it's easy to exaggerate the real danger they pose, especially when the mainstream reporting of these hacks is light on important technical details. Bottom line -- if you enjoy using NFC on your Android phone from time to time, you're safe to continue doing just that.

http://www.androidcentral.com/android-nfc-hack-cool-not-new-or-dangerous

Cyber Warrior's Nexus 10 hacking video tutorials


We know plenty of people who grabbed a Nexus 10 last week are aware of how to unlock and root it. But there's also a whole bunch of people, some even new to Android, who might need a starting point. For those folks, there's a real treat in the Nexus 10 forums.

You might know Cyber Warrior from the Galaxy S3 forums, or from his amazing Android wallpapers. Turns out, he's a man of many other hacking related talents as well, and has put together and awesome pair of video tutorials to show you how to unlock the bootloader, and then root the Samsung Nexus 10 tablet. A world of potential is inside there, and this is your first step if you want to try and unlock some more of it. The videos are clear and well done, but that's not even the best part. Cyber's also always quick to assist from the coaches box anytime you hit a snag. He'll be there to help if you have any questions, and between he and the rest of the hard-working crew in the forums you'll soon be unlocked, rooted, and back running again if there's a problem. Sharing is caring, and the mods and advisers in the forums are the sharing, caring type of Android nerds. And we love 'em all for it! 

http://www.androidcentral.com/forums-cyber-warrior-s-nexus-10-hacking-video-tutorials

Android malware predicted to have a big year in 2012, says Lookout Mobile Security


 Researchers from mobile security firm NQ Mobile have uncovered what they are calling “a nasty piece of malware” that has already infected more than 600,000 users in China.

Named “Bill Shocker” by the China-based mobile security firm, the malware is potentially one of the most costly viruses yet discovered, the company said.
“Bill Shocker is an SDK-type virus (Software Development Kit). Our experts, using NQ’s RiskRanker system, found the virus attached to several of the most popular mobile apps in China, including Tencent QQ Messenger and Sohu News,” the company explained.

The malware is propagating via third-party online app stores and retail installation channels, something the company says is allowing it to “spread like wildfire”.
The Bill Shocker malware downloads itself in the background on a users’ Android device without their knowledge and takes remote control of the device, including accessing contact lists, Internet connections, dialing and texting functions.

“Once it’s turned your phone into a “zombie,” it sends text messages that create financial gains for advertisers. In many cases, the threat will overrun a user’s bundling quota, which subjects you to even more unwanted charges,” the company said.

While the malware may not steal data or cause other damage to the device, NQ Mobile still considers it a threat due to the fact that it can rack up a users’ phone bill by sending costly messages.
NQ says it has notified Chinese mobile carriers of the threat, and has provided its technology to China’s top mobile carriers including, China Mobile and China Unicom as well as Baidu Mobile Services, to help reduce the spread of mobile malware.

This past summer, researchers from TrustGo discovered a mobile threat targeting Android phones that was said to have infected roughly 500,000 devices, mainly in China. Called “SMSZombie”, the malware was little threat to users outside of China, as the prime function of the mobile malware was to exploit a vulnerability in the mobile payment system used by China Mobile, making it of little value to the fraudsters outside of China.

SecurityWeek contacted Lookout, a mobile security firm based in San Francisco, to see if they had any information on the "Bill Shocker" threat. A Lookout spokesperson toldSecurityWeek that it was hard to measure the threat’s significance without access to the sample. “As soon as NQ releases more details on the threat, we'll be able to determine if this is in fact a new threat, and who it is affecting,” the spokesperson said.

Black Hat hacker lays waste to Android and Meego using NFC exploits

A security researcher at the Black Hat conference in Las Vegas has demonstrated some gaping holes in the implementation of NFC on the Samsung Nexus S, Samsung/Google Galaxy Nexus, and Nokia N9. These hacks were demonstrated by Charlie Miller, a security researcher renowned for cracking Safari, the MacBook Air, and the iPad and iPhone — and now, seemingly, he has turned his attention to Android. In all three cases, vulnerabilities in the near-field communication (NFC) implementation allowed Miller to execute arbitrary, malicious code on the smartphone — at which point, it is trivial to turn a phone into a botnet zombie, or to extract sensitive information.
In the Nexus S’s case, Android 2.3 Gingerbread contains memory corruption bugs, which allow Miller to gain control of the NFC daemon with a specially designed RFID tag (or another NFC-enabled smartphone). This tag could be tailored to contain malicious code that is executed upon scanning.
The Meego-powered Nokia N9, it turns out, will automatically accept any NFC request without confirmation by the user. Miller says he can force a Nokia N9 to make calls, send SMSes, or upload or download arbitrary files — including your address book. Apparently, even if you turn on notifications, the N9 will still accept and automatically open incoming file transfers. All you would have to do is send a specially crafted file — a Word DOC, a PDF — to gain root access to the phone.
And then we have the most important hack of all, the Galaxy Nexus. In Android 4.0 Ice Cream Sandwich, Android Beam and NFC are enabled by default — and according to Miller, Android Beam will automatically download and open any transmitted website links or files. Apparently, there is no way for users to approve/deny transfers that are initiated by another NFC handset or RFID tag. Again, when coupled with an OS or browser exploit, this functionality could be used to gain root access.
During the same presentation at Black Hat, Miller also brought up the dreaded “F” word — fragmentation. He says that older versions of Android contain lots of known vulnerabilities — and because it takes so long for carriers and OEMs to roll out patches, malicious hackers can make use of those holes for months. The Nexus S hack relied on a memory corruption exploit in Android 2.3, and the Galaxy Nexus hack exploited a bug in the Android 4.0.1 stock browser. ICS is now up to version 4.0.4, and so that browser bug is probably plugged — but even so, Miller says there are probably other WebKit holes that can be exploited in a similar way.
Ultimately, what we’re looking at here is the future of credit card skimming. NFC only has a range of a few centimeters, and so none of these hacks can be performed from a distance — but that’s the problem with smartphones: we’re constantly being encouraged to bring them very close to other gadgets. All it would take is an exploited point of sale, or even just an RFID tag affixed to the bottom of a wireless POS — and voila, your phone can be hacked.
The good news, unlike yesterday’s hack of four million hotel door locks, is that NFC can be secured quite easily. The actual transmission of NFC data can be encrypted, and strong authentication is definitely possible with the current NFC specs. In this case, though, it would seem that Google and Nokia have simply been a bit lazy with their software implementations — which, given that NFC is relatively new and untested, isn’t surprising… but it is a bit sad.

Friday, February 1, 2013

Opera Mini Handler Android All versions


Here is the Biggest collection opera mini handlers for Android Phones .
Now a days most of people have switched to Android phones .
So guys This is the Best collection of all .
Grab your handler and use free Gprs on mobile .

 OperaMini 6.1 handler for Android
http://jumbofiles.com/kppmsam8qi3j
File Size : 798Kb
File Type : apk

Operamini 6.5.2 Handler Android
http://jumbofiles.com/87ysq621r5rs
File Size : 851 Kb
File Type : apk

Operamini 5.1 Handler Android
http://jumbofiles.com/runmqgrfnhda
File Size : 898 Kb
File Type : .apk

OperaMini 7 Modded AIRTEL(INBUILT AIRTEL)
http://jumbofiles.com/gen5jb4fllec
File Size : 355 Kb
File Type : apk

Airtel Free Gprs For Android User

Guys, as we know many ANDROID users are facing problems in using free GPrs, coz ANDROID dont have direct JAVA support for installing j2me midlets, nd there r no modded apps for android like we have for SYMBIAN nd JAVA, so here im giving a 100% working OPERA MINI handler for android, tested in my NEXUS ONE, download it from below nd install it, in back query field enter ?0.facebook.com/?zout=1
(NOTE= Dont forget to edit socket servers, like from socket:// to http:// as in screen shots then only it will work) , thats it ur done.
one more thing OPERA MINI works much better in ANDROID than any other platforms.
plz hit thanx IF AND ONLY IT WORKS




WiFi Hack App for Andorid Platforms




This is a final version of Wifi Hack Software 2013. It can hack every WiFi Network and can crack every WiFi password.
This hack is not fake and it wotks 100%.

Guarantee it works! Watch the whole video for proof.
Subscribe, rate, and comment!

----------------------------------------------------------------------------

Download : http://goo.gl/1j0wa *(Bug Fixed 2013)*

or

Visit official Blog at: http://goo.gl/iYA57

Updated *November 2012

*Scaned with Avast antivirus,its 100% virus free.
(Check virus scan):
https://www.virustotal.com/file/411f4aeb2fa0fff17d8ef0c08f878c785fd42a60dc2692816f336c8ec251b323/analysis/

Wifi Kill for Android + Download




Ever wanted to kick someone off of your wifi connection?! With Wifi Kill you can do just that from your Android based device with the press of a button, Sit back & Enjoy! Drop a comment say hello! Don't forget to subscribe and check out my channel!(:
http://www.youtube.com/user/AndroidLifeStyle/featured

Link to Wifi Kill!
http://forum.ponury.net/viewtopic.php?f=12&t=10

Droid X Gingerbread Free Wireless Tether Hack



Want to use your built-in 3G Mobile Hotspot app on your Droid X 2.3 Gingerbread device? This hack gets around the account check and allows you to have free Wireless Tether of your Droid's internet to any other WiFi device.

--- REQUIRED

1. Droid X on Gingerbread .602
2. Get into ClockworkMod Recovery
3. Team Black Hat's Tether Patch.
http://goo.gl/pF2kj

OR

4. WugPacked - TBH_DX_Tether_Patch_1.0.zip
Thanks to WugPacked, download the WugPacked_GB_Tether_Patch from here:
http://www.droidxforums.com/forum/gingerbread-development-hacking/30948-wugpacked-gb-tether-patch-all-one-zips.html

Android Malware Injection into Custom application

Video for Toorcon - Android Hacking Workshop

This workshop will get you familiar with the various Android Exploitation methodologies, as well as performing live attacks on mobile applications, identifying the security holes, and finally fixing it. We will be talking about Android Framework for Exploitation ( a framework which we have developed), finding security holes with it, as well as developing plugins for the framework. We will also discuss about Android Botnets, how they spread and an in-depth analysis of how the Blackhats generate their income using malwares and botnets.
Download it from : http://github.com/xysec

Network Spoofer - Hacking networks from Android



Network Spoofer is a navite app for the Android platform that requires root access to perform a multitude of attacks against a router.

Project Page: http://hackedexistence.com/project-networkspoofer.html

Faceniff Demo - Hijacking Facebook Sessions from Android

Faceniff is a native android app that allows you hijack facebook sessions.

Faceniff monitors network traffic to extract the cookie from facebook web requests made by authenticated users. It then installs the cookie locally on the device and visits the facebook website successfully assuming the identity of the logged in facbeook user. Faceniff does not expose the user's facebook password, it only hijacks the session, and therefore expires when the session expires (which happens when the user clicks 'logout').

Faceniff does not defeat SSL so this attack can be prevented by enabling SSL encryption in your facebook settings and only viewing facebook over HTTPS.

http://faceniff.ponury.net/

Hacking An Android Phone To Steal Files


Hacking an android phone and stealing files using metasploit.