Hiển thị các bài đăng có nhãn Hacking Tutorials. Hiển thị tất cả bài đăng
Hiển thị các bài đăng có nhãn Hacking Tutorials. Hiển thị tất cả bài đăng
SQL Injection Tutorial: All common SQL injection problems and Solutions

SQL Injection Tutorial: All common SQL injection problems and Solutions





Hello readers of BTS,
    Today I'll write an tutorial for you what covers most problems while doing SQL injection and solutions to them. Probably every person who has looked at tutorials to hack a website have noticed that there are too much SQL tutorials. Almost every forum has 10 tutorials and blogs 5 tutorials about SQL injection, but actually those tutorials are stolen from somewhere
Demo: How to upload your PHP shell through Tamper Data an Firefox Add-on?

Demo: How to upload your PHP shell through Tamper Data an Firefox Add-on?


This is a guest post by s3v3n from Code104

Many times you get login of a website, but you are unable to upload your PHP shell !
Today i'll show you how to upload your PHP shell through Tamper Data an Firefox Add-on

Install Tamper Data firefox add-on:
Download Tamper Data here
Now Install it and Restart Firefox

Rename shell:
Note: You have to rename you .php shell to .jpg to bypass the
How to create Phishing site without Webhost using Data URI?

How to create Phishing site without Webhost using Data URI?



Hello, BTS readers, it has been long time since i posted article in this blog.  Today i come across interesting news update which shares new technique used in the Phishing attack.

Phishing is one of the popular social engineering attack used by Cybercriminals. In this method, hackers host a fake webpage which looks similar to the original page of the website.

Then, hackers lure users to visit
How to Use Ravan for Password Cracking?

How to Use Ravan for Password Cracking?

In my previous article, i explained about the Ravan Tool.  Now let us see how to use the Ravan for cracking passwords.


Requriments:Lot of Friends :Ravan is Distributed password cracking method. So you will need lot of friends who have Pc with Internet connection. The speed of cracking will increase based on the number of pc contribute in the cracking.

How to use Ravan?Step1:
Go to http://
Ravan , JavaScript based Distributed Password cracking

Ravan , JavaScript based Distributed Password cracking


You want to crack a hash but your system speed is low?! No need to worry..! Here is solution for you , "Distributed Password Cracking". Let me introduce a new tool called "Ravan" developed by LavaKumar.
About Ravan:Ravan is a JavaScript based Distributed Computing system that can perform brute force attacks on salted hashes by distributing the task across several browsers. It makes use of HTML5
The Art of Human Hacking -Social Engineering(SE) tutorial series

The Art of Human Hacking -Social Engineering(SE) tutorial series


Hello BTS readers, here we come with an interesting tutorial written by my friend Mr.Ashish Mistry who is the founder of Hcon and author of 'HconSTF ' project.


Hello all,

after a long time I am again started writing, In a hope that my believe in “sharing the spirit of learning” fulfills well. So from today I am going to write series of tutorials on my favorite topic, 'Social Engineering' (SE)
How to hack a websites using Symlink Bypassing?

How to hack a websites using Symlink Bypassing?


Symlink Bypassing:Symlink is a method to reference other files and folder on Linux, in order to make linux work faster.  Symlink Bypassing is a hacking technique used to gain unauthorized access to folders on a server. Using this technique an hackers are able to hack multiple sites on a shared web hosting service.

Here is Video tutorial that explain how to hack a website using Symlink Bypassing
Google dork "Index of /sh3llZ" allows you to find shell uploaded by hackers

Google dork "Index of /sh3llZ" allows you to find shell uploaded by hackers


Usually hackers upload shell to victim's site using the vulnerability in that website. Shell allows hackers to hack/deface the website. Sometimes hackers left the shell in the vulnerable sites.  Here is simple google search allows you to find a shell uploaded by hackers.

Use one of the following google dork to find the shell:
intitle:index of/sh3llZ
"Index of /sh3llZ"
"/sh3llZ/uploadshell/
How to deface website with Cross Site Scripting ? : Complete XSS Tutorial

How to deface website with Cross Site Scripting ? : Complete XSS Tutorial


This is my third article about Cross site Scripting Tutorial. Last time, i explained how to do vulnerability test for XSS and some filter bypassing technique. Now let us see how a hacker deface a website with XSS vulnerability?

Never implement this technique. I am just explaining it for educational purpose only.
Defacing is one of the most common thing when the hacker found the vulnerability
Bypassing the XSS Filters : Advanced XSS Tutorials for Web application Pen Testing

Bypassing the XSS Filters : Advanced XSS Tutorials for Web application Pen Testing




copyrights reserved © 2viet.blogspot.com
Hi friends, last time, i explained what is XSS and how an attacker can inject malicious script in your site. As i promised earlier, i am writing this advanced XSS tutorial for you(still more articles will come).

Sometimes, website owner use XSS filters(WAF) to protect against XSS vulnerability.
For eg: if you put the alert("hi") , the
"Simple Upload 53" Vulnerability allows Hacker to upload Shell

"Simple Upload 53" Vulnerability allows Hacker to upload Shell

Web Application vulnerability in "Simple Upload 53" PHP file allows an attacker to upload Backdoor shell code in your website.

"inurl:simple-upload-53.php"
using this google search , you can find the vulnerable Sites.

If you want to find the vulnerability in your web application, use this google dark:
"inurl:simple-upload-53.php site:Your-Site.com"

After you search in google; if you find any
Self-XSS (Cross Site Scripting) ~ Social Engineering Attack and Prevention

Self-XSS (Cross Site Scripting) ~ Social Engineering Attack and Prevention


Last time , I have explained about the Clickjacking attack and prevention.  Today,  i am going to explain about the Self-XSS(Cross Site Scripting) Attack





What is Self-XSS?
Self-XSS is one of the popular Social Engineering Attack used by Attackers to trick users into paste the malicious code in browser.  Results in attacker accessing to the whatever website you visit. Usually scammers use
Remotely spy on any computer using Win-Spy

Remotely spy on any computer using Win-Spy

Do you need to know what your child is doing on the computer? Is your spouse cheating on you? Do you need to monitor what your employees are doing during work hours? Is someone tampering with your computer while you are away?

With Win Spy Software you will know exactly what they are doing.

Win Spy Software is a Complete Stealth Monitoring Software that can both monitor your Local PC and Remote
DoS (denial of service) attack on Mobile phones

DoS (denial of service) attack on Mobile phones

As we are in this world influenced by information security, we as security professional have seen many kind of Dos and DDoS attacks happening around the world but what if any one DoS your daily communication Companion ? your mobile device ? and you are just unable to call or operate your phone in proper way ,not even listen to music or even videos ??

Some years back there was DoS possible on a
What is Clickjacking Attack? How to Prevent? | UI Redressing

What is Clickjacking Attack? How to Prevent? | UI Redressing

Will answering simple maths quiz delete your Social Network account?  If your answer is "No", then check this news Linkedin Clickjacking Vulnerability and come back.  Will visiting a website turn on your webcam? The answer is "Yes".  Check this Flash player clickjacking vulnerability.

If you read above news completely, It will be easy for you to understand  what is clickjacking.  Ok, lets