Power By Dholu Production

Responsive Ads Here
Showing posts with label Hacking Tricks. Show all posts
Showing posts with label Hacking Tricks. Show all posts

Wednesday, March 21, 2018

How to Hack Someone's WhatsApp Without Their Mobile Phone | Tricks

How to Hack Someone's WhatsApp with Mac Address of the Target Devices Let's See This Artical



In which we will need the MAC address of the target mobile, BusyBox app and Terminal emulator app. You can download both the BusyBox and the Terminal emulator from the Google Play Store. With these three necessities at hand, we can now proceed.

Step 1: Using your smartphone, download, install, and run the BusyBox app. You will be required to create an account.

How to Hack Someone's WhatsApp Without Their Mobile Phone | Tricks
How to Hack Someone's WhatsApp Without Their Mobile Phone | Tricks




Step 2: Take the target mobile phone and obtain its MAC address. Follow these steps to you get the MAC address “Settings> About Phone> Status> MAC Address. Write this address down as you are going to need it.

How to Hack Someone's WhatsApp Without Their Mobile Phone | Tricks
How to Hack Someone's WhatsApp Without Their Mobile Phone | Tricks

Step 3: Launch the Terminal App and type $ su and press "Enter".

Step 4: In the next step, type "$ busybox iplink show eth0" and hit "Enter".
NOTE: If you get a "device not found" message, enter wlan0 instead of eth0 in the spaces provided.

Step 5: In the next step, type "$ busybox ifconfig eth0 hw ether" followed by your MAC address. type your victim's MAC Address XX:XX:XX:XX:XX:XX
NOTE: You have now successfully spoofed your MAC address. You can confirm this by entering the following command "$ busybox iplink show eth0".

Step 6: Launch your WhatsApp and enter the phone number of the target WhatsApp account.

Step 7: Before you can completely hack the victim's WhatsApp you will be required to confirm the hack. In this case, choose call verification.

Step 8: Write down the code that you will receive and enter it into the box provided on your smartphone.

It is simple as that. From this point henceforth, you will be receiving each and every message that leaves and enters the target phone WhatsApp account

Tuesday, December 26, 2017

HOW TO DECRYPT AND EXTRACT WHATSAPP DATABASE | Tricks

Nowadays , WhatsApp has become the best interoperable Instant Messaging and VoIP (Voice over Internet Protocol) and Multimedia platform for the end users that provides them an well-serviced environment for Instant Messaging , Voice/Video Calling , File Transfer such as Documents , Videos and Images easily at the scale with high-end encryption encapsulated into it globally .

Read Full Artical click here  <-- This Artical is easy to understand Decrypt Database. so i just suggest read this artical . 

WhatsApp basically uses a standardised protocol for Instant Messaging called Extensible Messaging and Presence Protocol (XMPP).  It basically uses one of it's most valuable service called Jabber for user account at the time of Installation using the phone no. as the username i.e. (Jabber ID: [phone number]@s.whatsapp.net) and then it estimates all smart phones from it's address book with the help of it's centralised database for adding contacts automatically to their contact list and then it also allows Multimedia Messaging to the end users with the help of HTTP server and generates a hyperlink to the content with Base64 encoded.


Whatsapp Database Decryption
Whatsapp Database Decryption


Before Demonstration , I'd like to write about the working principle of WhatsApp high-end Encryption

As you know that the Multimedia Messaging and other type of data are simply the decrypted data and need to be encapsulated in order to securely communicate with each other  through a communication channel.



So Firstly ,  the Plain Text is encrypted using Private Key for the Data Encapsulation

i.e. PlainText + Secret Key == Data Encapsulation (Encrypted Data)

Once the data has been received by the receiver needs to be decrypted i.e. plain text using the same Secret Key for it

i.e. Data Encapsulation (Encrypted Data) + Secret Key == PlainText (Original Data)

Read Full Artical click here

The Main Problem with the Technique is the usage of Same Key for both encryption and decryption
So , if the sender sends the data to the receiver , the third party is likely to be able to eavesdrop and forge and sniff the conversation , data etc between sender and receiver which could create a massive problem to both of them

In order to overcome the problem , WhatsApp basically uses Two Keys for both encryption and decryption. These two keys are mathematically so related to each other that one key can encrypt the PlainText to Encrypted Data which can be later on decrypted by receiver






Both of your public and private keys are generated on your smartphone at the time of installation , So what does that mean by high-end encryption

As your private key is generated on your mobile , The third party Attacker cannot decrypt your messages due to the implementation of private key.

The 60 digit number shown above is shorter form of addition of your and your contact's public key. Remember, you use your contact's public key to encrypt outgoing message and your contact uses their private key to decrypt and vice versa.

Scanning QR code or comparing those 60 digit number is a way to verify and ensure that you are using correct public key of your contact and no one (whatsapp server or others) is spoofing you with wrong public key.

Now let me cut to the chase and write about the mechanism of both decryption and extraction of WhatsApp Database

You got to be thinking that it's impossible to just decrypt and extract the WhatsApp Database so easily with such high-end security attached to it

But let me tell you straight that it's possible and very easy to decrypt and extract the Database easily with the help of built-in tools available today in this technology

After all , Nothing is Impossible in today's technology

If there exists the technology then obviously there exists security tools too

Read Full Artical click here

There are following prerequisites software and tools need to be downloaded and installed before it

1. Crypt Key Extractor (https://codeload.github.com/EliteAndroidApps/WhatsApp-Key-DB-Extractor/zip/master)
2. Operating System (Windows , Linux , Mac OS X)
3. Java (https://www.java.com/en/download/)
4. ADB i.e. Android Debug Bridge (https://developer.android.com/studio/releases/platform-tools.html#download)
5. Android Device (with Android 4.0 or Higher than it)
6. USB Debugging must be enabled on the target device
7. Web Browser
8. Internet
9. USB (Universal Serial Bus)

In order to enable USB Debugging , Please navigate to Settings --> Developer Options -->  Enable USB debugging. Please tap multiple times on Build Number  under About Phone unless and until you become the developer if you find no developer option under the Settings option

Note :

01. I apologise Linux and Mac OS X users for the following below demonstration
02. Windows end users must have minimum knowledge about Windows OS for it
03. This is to be advised that it's for the education purpose , any illegal activity against any                      other unauthorised devices could lead to jail

Are you finally ready to decrypt and extract WhatsApp Database

So , Let's Get Started

04. Download prerequisites software and tools
05. Extract it to your preferred drive
06. Open up your Command Prompt
07. Navigate to the directory where WhatsApp Key DB Extractor installed
08. Connect your device via USB and change the mode from charging to media
09. Unlock your screen and wait for Full Backup option
10. Enter your backup password or leave the blank (if none set)
11. Tap on Back up my data.

Read Full Artical click here

Note : Please wait as It could take few minutes depending upon your size of data

12. Confirm backup password on your Command Prompt and check for extracted folder.
13. You'll find many files there such as axolotl.db , chatsettings.db , msgstore.db, wa.db.
14. As all these files are in SQL format visible through SQLite Software
15. Visit https://sqliteonline.com for Online Viewing
16. Click on Open DB and select them all in order to view the files online through the website
17. Done
I hope you can now easily decrypt and extract WhatsApp Database.

How to Decrypt WhatsApp crypt12 Database Messages | Tricks

WhatsApp backup conversation files are now saved with the .crypt12 extension. From crypt9, they seem to be using a modified version of Spongy Castle – a cryptography API library for Android.

Decrypt Database
Decrypt Database

All the findings below are based on reverse engineering work done on WhatCrypt and Omni-Crypt. I would like to highlight that IGLogger proved to be a very useful tool when it came to smali code debugging.

Extract Key File

To decrypt the crypt12 files, you will first need the key file. The key file stores the encryption key, K. WhatsApp stores the key file in a secure location: /data/data/com.whatsapp/files/key.
If your phone is rooted, extracting this file is easy. If your phone is not rooted, refer to instructions from WhatCrypt and Omni-Crypt for details on extracting the key file. The idea is to install an older version of WhatsApp, where Android ADB backup was still working and extract the key file from the backup.

Extract crypt12 Backup File

Pull the encrypted WhatsApp messages file from your phone using ADB.
$ adb pull /sdcard/WhatsApp/Databases/msgstore.db.crypt12

Decryption Keys

This section is just for your information and you can skip this section.
The encryption method being used is AES with a key (K) length of 256 bits and an initialisation vector (IV) size of 128 bits. The 256-bit AES key is saved from offset 0x7E till 0x9D in the file. Offsets start from 0x00. You can extract the AES key with hexdump and assign the value to variable $k.
$ k=$(hexdump -ve '2/1 "%02x"' key | cut -b 253-316)
The $k variable will hold a 64-digit hexadecimal value in ASCII that is actually 256 bits in length.
The IV or the initialisation vector is saved from offset 0x33 till 0x42 in the crypt12 file. The IV value will be different for every crypt12 file.
$ iv=$(hexdump -n 67 -ve '2/1 "%02x"' msgstore.db.crypt12 | cut -b 103-134)
The K and IV extraction method is similar to what we have done for crypt8 files before.

Strip Header / Footer in crypt12 File

Again, this section is just for your information and you can skip this section.
Before we start the decryption process, we will need to strip the 67 byte header and 20 byte footer from the crypt12 file.
$ dd if=msgstore.db.crypt12 of=msgstore.db.crypt12.enc ibs=67 skip=1
$ truncate -s -20 msgstore.db.crypt12.enc
The above dd command will strip the the first 67 bytes from the crypt12 file and save it to a file with extension crypt12.enc. The truncate command will strip the last 20 bytes from the crypt12 file.

Decrypt crypt12 File

As the WhatsApp AES cryptography API library seems to be a modified version, we will no longer be able to use openssl to decrypt the crypt12 file. I have yet to determine what has been modified.
To decrypt crypt12 files, I have written a simple Java program that will use the modified cryptography API library instead. For the cryptography API library, I have extracted the modified Spongy Castle cryptography class files from the Omni-Crypt APK file using dex2jar. You can find the Java program and crypto library over here at GitLab.
The Java program will create 3 output files:
  • msgstore.db.crypt12.enc – encrypted file with header and footer stripped.
  • msgstore.db.zlib – decrypted file in zlib format.
  • msgstore.db – decrypted sqlite3 database file.
Below is how you can compile and run the Java program.
$ git clone https://gitlab.com/stackpointer/whatsapp-crypt12.git

$ cd whatsapp-crypt12/

$ javac -classpath "lib/whatsapp_spongycastle.jar:." crypt12.java

$ cp ../whatsapp.data/key .

$ cp ../whatsapp.data/msgstore.db.crypt12 .

$ java -cp "lib/whatsapp_spongycastle.jar:." crypt12

K:XXXXXXXXXX
IV:YYYY
creating encrypted file with header/footer stripped: msgstore.db.crypt12.enc
creating zlib output file: msgstore.db.zlib
creating sqlite3 output file: msgstore.db

$ ls -l
total 136724
-rw-r--r-- 1 ibrahim staff     4339 Oct  9 16:05 crypt12.class
-rw-r--r-- 1 ibrahim staff     5459 Oct  9 16:05 crypt12.java
-rw-r--r-- 1 ibrahim staff      158 Oct  9 16:05 key
drwxr-xr-x 2 ibrahim staff     4096 Oct  9 16:05 lib
-rw-r--r-- 1 ibrahim staff     1089 Oct  9 16:05 LICENSE
-rw-r--r-- 1 ibrahim staff 62692352 Oct  9 16:06 msgstore.db
-rw-r--r-- 1 ibrahim staff 25757610 Oct  9 16:05 msgstore.db.crypt12
-rw-r--r-- 1 ibrahim staff 25757523 Oct  9 16:05 msgstore.db.crypt12.enc
-rw-r--r-- 1 ibrahim staff 25757507 Oct  9 16:06 msgstore.db.zlib
-rw-r--r-- 1 ibrahim staff     1376 Oct  9 16:05 README.md

$ file *
crypt12.class:           compiled Java class data, version 52.0 (Java 1.8)
crypt12.java:            C source, ASCII text
key:                     Java serialization data, version 5
lib:                     directory
msgstore.db:             SQLite 3.x database, user version 1
msgstore.db.crypt12:     raw G3 data, byte-padded
msgstore.db.crypt12.enc: data
msgstore.db.zlib:        zlib compressed data

Final Words

To use the Java decryption tool, you will need to use OpenJDK. Oracle require JCE Provider libraries to be signed. OpenJDK does not have this requirement. If you try running the Java program on Oracle JDK, you will most likely get the following exception.
Exception in thread "main" java.lang.SecurityException: JCE cannot authenticate the provider SC

Tuesday, October 31, 2017

How to Find Any Website's IP Address Using CMD & Android & iPhone | Tricks

Checking the IP address of a particular website is not a difficult task. This @llsinfoHow teaches you how to find the IP address of a website. You can do this by using an online service, by using your computer's built-in "ping" And "nslookup" command, or by downloading and using a free app for your iPhone or Android. Keep in mind that if a website is "masking" its IP address, you won't be able to see the website's true IP address.

How to Find Any Website's IP Address Using CMD | Tricks
How to Find Any Website's IP Address Using CMD | Tricks


1) For Windows (1st Method)

Step 1: Open Image titled Windowscmd1.png Command Prompt (Administrator)

Step 2: Type nslookup command and your website name (e.g., nslookup xyz.com)
Note : You don't need to include the www. part of the address.

Step 3: Press ENTER. wait it will take a several time

Step 4: Note the IP address. You'll see the IP address



1) For Windows (2nd Method)

Step 1: Open Image titled Windowscmd1.png Command Prompt (Administrator)

Step 2: Type ping command and your website name (e.g., ping xyz.com)
Note : You don't need to include the www. part of the address.

Step 3: Press ENTER. Doing so will search for the website's IP address.

Step 4: Note the IP address. You'll see the IP address' series of numbers next to the "Reply from" line of text. This is the website's closest server's IP address.

Step 5: Try alternative IP ping commands. If you can't find an IP address for your website, try one of the following commands where "website.com" is the address of the website:


  • ping ftp.website.com
  • ping cpanel.website.com
  • ping mail.website.com



2) For Mac

Step 1: Open  Image titled Macspotlight.png  Spotlight And Type network utility And search

Step 2: Click  Network Utility

Step 3: Click Ping  Tab.  It's at the top of the window.

Step 4: Enter the website's address.(e.g., xyz.com)
Note : You don't need to include the www. part of the address.

Step 5: Check the "Send only [number] pings" box. It's in the middle of the page. You can change the number in the text field to anything you want here, but setting it to "1" should be sufficient.

Step 6: Click Ping  It's a blue button on the far-right side of the window. Doing so will cause Network Utility to request the IP address of your entered website.

Step 7: Note the IP address. In the window at the bottom of Network Utility, look for the IP address' numbers to the right of the "bytes from" heading. This is the IP address of the website you pinged

Step 8: Try adding extensions before the website name. If you can't find an IP address for your website, try adding one of the following extensions before the address (e.g., "ftp.website.com"):


  • ftp.website,com
  • cpanel.website.com
  • mail.website.com


3) For Android

Step 1:  Download PingTools Network Utility. To do so

  • Open your Android Google Play Store.
  • Tap the search bar
  • Type in pingtools
  • Tap PingTools Network Utility
  • Tap INSTALL
  • Tap AGREE


Step 2: Open PingTools Network Utility. Tap OPEN in the Google Play Store, or tap the PingTools app icon.

Step 3: Tap  ☰ . It's in the upper-left corner of the screen. A pop-out menu will appear

Step 4: Tap Ping. This option is near the middle of the pop-out menu

Step 5: Enter an address. Tap the address bar at the top of the screen, then type in the address of a website that you want to ping for an IP address (e.g., website.com)
Note: You don't need to include the www. section of the address.

Step 6: Tap PING. It's in the top-right corner of the screen. Doing so will prompt your Android to request the IP address from your selected website

Step 7: Note the IP address. You'll find it below the "Ping [website]" heading that appears on the screen.

4) For iPhone

Step 1: Download Ping from your iPhone's App Store. To do so:

  • Open App Store app.
  • Tap Search
  • Tap the search bar
  • Type in ping
  • Tap Search
  • Tap GET next to "Ping - network utility"
  • Enter your password when prompted


Step 2: Open Ping. Tap the Ping app icon

Step 3: Tap the address bar. It's at the top of the screen

Step 4: Enter an address. Type in the address of the website for which you want to find the IP address (e.g., website.com)

Step 5: Tap Ping. It's in the top-right corner of the screen. Doing so will prompt your phone to begin requesting the website's address

Step 6: Note the IP address. You'll see it appearing once every second or so on the screen. The IP address will continue to appear in one-second intervals until you cancel the ping.

Monday, October 30, 2017

Download Crack IDM 2017 |Activate Internet Download Manager Crack

Do you all want to download IDM? Yes, Then here you’re at the right post. The demand of Internet Download Manager is very high as per as their latest updates and because of their high downloading speed, we all want the free IDM in our PC or laptop. This is the one and the only tool in this Internet that I seriously love the most because of its uniqueness and best downloading speed ever. and the Simple graphic user interface makes IDM user-friendly and easy to use.



The IDM (Internet Download Manager) is the one of the best Internet download manager ever I use. But the big issue in the Free IDM that, it gives you 30 days trial version after that one has to purchase its license. Therefore this post is for those people who don’t want to pay any bucks. So here I’m going to show ‘How To Download Free IDM in 2017. and from where to download and how to make its 30 days trail period to unlimited days.

Download IDM Free 2017 Crack + Working

Wednesday, September 27, 2017

Top 10 Best Operating Systems For Hackers 2017

In the cyber world, there are lots of hacking attacks that occur daily, and they are done by some of the professional hackers and by some of the newcomers who use someone’s else codes and concepts to hack. But the essential thing that every hacker needs is the hacking OS and for that Linux is one of the best choices for the hackers for a long time. So today we are here with some of the best-operating systems based on Linux that hackers can use to perform their hacking attacks flawlessly. So have a look at these OS discussed below.



1) Kali Linux: Download

Kali Linix

It was developed by Mati Aharoni and Devon Kearns of Offensive Security through the rewrite of BackTrack, their previous forensics Linux distribution based on Ubuntu. Kali Linux has a dedicated project set-aside for compatibility and porting to specific Android devices, called Kali Linux NetHunter. It is the first Open Source Android penetration testing platform for Nexus devices, created as a joint effort between the Kali community member “BinkyBear” and Offensive Security. It supports Wireless 802.11 frame injection, one-click MANA Evil Access Point setups, HID keyboard (Teensy like attacks), as well as Bad USB MITM attacks.

If you are new in hacking than you must have to know about kali linux because kali linux is one of best Operating system for hacking and penetration testing. Kali linus  is part of Debian-Linux distribution. It maintained and updated by  Offensive Security Ltd. There are more than 300 tools pre-install tools in kali linux. You can run kali linux as  a primary operating system on the hard disk, live CD/USB and can even run as a virtual machine.it support both 32bit and 64bit iso file for use with  x86 machines and also support many development boards like Raspberry Pi, BeagleBone, Odroid, CuBox, etc. You can do many attack by kali linux like  Password attacks , wireless attacks , Sniffing and spoofing and many more.

2) BackBox: Download

BackBox

BackBox is an Ubuntu-based Linux distribution penetration test and security assessment oriented providing a network and informatic systems analysis toolkit. BackBox desktop environment includes a complete set of tools required for ethical hacking and security testing.

Features Of Backbox:

  • BackBox has built one of the very first cloud platforms for penetration testing.
  • Designed to be fast, easy to use and provide a minimal yet complete desktop environment.
  • BackBox is fully automated and non-intrusive, with no agents required and no network configuration changes needed to accomplish regularly scheduled, automated configuration backups.
  • With the BackBox dashboard overview, you save time and eliminate the need to track individual network devices


3) Parrot Security Operating System: Download

Parrot Security

Parrot Security Operating System run on  Debian GNU/Linux combined and the Frozenbox OS. Parrot  work same as kali linux but parrot have strong  community support that gives great experience of penetration and security testing in real-world environments. parrot is famous for anonymous Web browsing and deal with vulnerability assessment and mitigation. it also have easy to use GUI enviroment. Parrot securtty operating syastem is great for hackers and  pentetration testers and it also come free of cost and run  as primary operating system on the hard disk, live CD/USB and can even run as a virtual machine same as kali.

4) BlackArch Linux: Download

BlackArch Linux

BlackArch Linux is based on  Arch Linux-based security and penetration testing distribution. There are 1600 tools pre-install in BlackArch linux . Thats why  hackers and cyber security  expert like it most. BlackArch is easy to use and it also also have regular based updated. BlackArch is best for who work in Web and applications based security testing. Arch Linux can be installed on 32-bit and 64-bit machines including ARM based development boards like Raspberry Pi, BeagleBone, etc. Latest verison of BlackArch is  2016.12.29.


5) NodeZero: Download

NodeZero

NodeZero is an open source Linux kernel-based operating system derived from the world’s most popular distribution of Linux, Ubuntu, and designed to be used for penetration testing operations. The distro is available for download as a dual-arch Live DVD ISO image, which will run well on computers that support both 32-bit (x86) and 64-bit (x86_64) instruction set architectures. Besides the fact that it allows you to start the live system, the boot menu contains various advanced options, such as the ability to perform a system memory diagnostic test, boot from a local drive, start the installer directly, as well as to boot in safe graphics mode, text mode or debug mode.

NodeZero’s default graphical desktop environment is powered by GNOME, which uses the GNOME Classic interface. It features a two-panel layout, and uses Ubuntu’s default software repositories. Keep in mind though, that you must first log into the live session with the username nodezero and without a password.With NodeZero you will have instant access to over 300 penetration testing tools, as well as a set of basic services that are needed in penetration testing operations. Default applications include the Mozilla Firefox web browser, F-Spot photo manager, Rhythmbox music player, PiTiVi video editor, Transmission torrent downloader, Empathy multi-protocol instant messenger, and OpenOffice.org office suite.

6) Live Hacking OS: Download

Live Hacking

Live Hacking OS is a Linux distribution packed with tools and utilities for ethical hacking, penetration testing and countermeasure verification. It includes the graphical user interface GNOME inbuilt. There is a second variation available which has command line only, and it requires very less hardware requirements.

7) Pentoo: Download
pentoo

This is one of the best OS for hackers that is just in the form of Live CD. In this, you just have to create a bootable USB of this OS and then simply boot on your PC, and there is no requirement to install it, you just have to run it on your PC and do hacking attacks.

Features Of Pentoo:

  • Available in 32-bit and 64-bit versions, the latter having a significant speed increase from 32bit
  • Includes the required environment to crack passwords using GPGPU with OpenCL and CUDA configured ‘out of the box'[5][6][7]
  • Built on hardened Linux, including a hardened kernel and toolchain
  • Hardened kernel with extra patches[8]
  • Uses a pentoo overlay, which allows tools to be built on top of a standard gentoo build.

8) Network Security Toolkit: Download

NST

The Network Security Toolkit (NST) is a Linux-based Live CD that provides a set of open source computer security and networking tools to perform routine security and networking diagnostic and monitoring tasks. The distribution can be used as a network security analysis, validation and monitoring tool on servers hosting virtual machines. The majority of tools published in the article “Top 125 security tools” by Insecure.org are available in the toolkit. NST has package management capabilities similar to Fedora and maintains its own repository of additional packages.

Features Of NST:

  • Many tasks that can be performed within NST are available through a web interface called NST WUI
  • Visualization of ntopng, ntop, Wireshark, traceroute, NetFlow and kismet data
  • JavaScript console with a built-in object library with functions that aid the development of dynamic web pages


9) GnackTrack: Download

GnackTrack

After the release of backtrack five this OS is being developed and is now one of the best OS used for pen testing and network cracking, and it is based on a Linux distribution. Must try out this OS.

10)  DEFT Linux: Download


DEFT stands for Digital Evidence and Forensic Toolkit and it’s an open source distribution of Linux built around the DART (Digital Advanced Response Toolkit) software and based on the Ubuntu operating system. It has been designed from the ground up to offer some of the best open source computer forensics and incident response tools that can be used by individuals, IT auditors, investigators, military, and police.