Power By Dholu Production

Responsive Ads Here
Showing posts with label Hacking Tricks. Show all posts
Showing posts with label Hacking Tricks. Show all posts

Wednesday, March 21, 2018

How to Hack Someone's WhatsApp Without Their Mobile Phone | Tricks

How to Hack Someone's WhatsApp with Mac Address of the Target Devices Let's See This Artical



In which we will need the MAC address of the target mobile, BusyBox app and Terminal emulator app. You can download both the BusyBox and the Terminal emulator from the Google Play Store. With these three necessities at hand, we can now proceed.

Step 1: Using your smartphone, download, install, and run the BusyBox app. You will be required to create an account.

How to Hack Someone's WhatsApp Without Their Mobile Phone | Tricks
How to Hack Someone's WhatsApp Without Their Mobile Phone | Tricks




Step 2: Take the target mobile phone and obtain its MAC address. Follow these steps to you get the MAC address “Settings> About Phone> Status> MAC Address. Write this address down as you are going to need it.

How to Hack Someone's WhatsApp Without Their Mobile Phone | Tricks
How to Hack Someone's WhatsApp Without Their Mobile Phone | Tricks

Step 3: Launch the Terminal App and type $ su and press "Enter".

Step 4: In the next step, type "$ busybox iplink show eth0" and hit "Enter".
NOTE: If you get a "device not found" message, enter wlan0 instead of eth0 in the spaces provided.

Step 5: In the next step, type "$ busybox ifconfig eth0 hw ether" followed by your MAC address. type your victim's MAC Address XX:XX:XX:XX:XX:XX
NOTE: You have now successfully spoofed your MAC address. You can confirm this by entering the following command "$ busybox iplink show eth0".

Step 6: Launch your WhatsApp and enter the phone number of the target WhatsApp account.

Step 7: Before you can completely hack the victim's WhatsApp you will be required to confirm the hack. In this case, choose call verification.

Step 8: Write down the code that you will receive and enter it into the box provided on your smartphone.

It is simple as that. From this point henceforth, you will be receiving each and every message that leaves and enters the target phone WhatsApp account

Tuesday, December 26, 2017

HOW TO DECRYPT AND EXTRACT WHATSAPP DATABASE | Tricks

Nowadays , WhatsApp has become the best interoperable Instant Messaging and VoIP (Voice over Internet Protocol) and Multimedia platform for the end users that provides them an well-serviced environment for Instant Messaging , Voice/Video Calling , File Transfer such as Documents , Videos and Images easily at the scale with high-end encryption encapsulated into it globally .

Read Full Artical click here  <-- This Artical is easy to understand Decrypt Database. so i just suggest read this artical . 

WhatsApp basically uses a standardised protocol for Instant Messaging called Extensible Messaging and Presence Protocol (XMPP).  It basically uses one of it's most valuable service called Jabber for user account at the time of Installation using the phone no. as the username i.e. (Jabber ID: [phone number]@s.whatsapp.net) and then it estimates all smart phones from it's address book with the help of it's centralised database for adding contacts automatically to their contact list and then it also allows Multimedia Messaging to the end users with the help of HTTP server and generates a hyperlink to the content with Base64 encoded.


Whatsapp Database Decryption
Whatsapp Database Decryption


Before Demonstration , I'd like to write about the working principle of WhatsApp high-end Encryption

As you know that the Multimedia Messaging and other type of data are simply the decrypted data and need to be encapsulated in order to securely communicate with each other  through a communication channel.



So Firstly ,  the Plain Text is encrypted using Private Key for the Data Encapsulation

i.e. PlainText + Secret Key == Data Encapsulation (Encrypted Data)

Once the data has been received by the receiver needs to be decrypted i.e. plain text using the same Secret Key for it

i.e. Data Encapsulation (Encrypted Data) + Secret Key == PlainText (Original Data)

Read Full Artical click here

The Main Problem with the Technique is the usage of Same Key for both encryption and decryption
So , if the sender sends the data to the receiver , the third party is likely to be able to eavesdrop and forge and sniff the conversation , data etc between sender and receiver which could create a massive problem to both of them

In order to overcome the problem , WhatsApp basically uses Two Keys for both encryption and decryption. These two keys are mathematically so related to each other that one key can encrypt the PlainText to Encrypted Data which can be later on decrypted by receiver






Both of your public and private keys are generated on your smartphone at the time of installation , So what does that mean by high-end encryption

As your private key is generated on your mobile , The third party Attacker cannot decrypt your messages due to the implementation of private key.

The 60 digit number shown above is shorter form of addition of your and your contact's public key. Remember, you use your contact's public key to encrypt outgoing message and your contact uses their private key to decrypt and vice versa.

Scanning QR code or comparing those 60 digit number is a way to verify and ensure that you are using correct public key of your contact and no one (whatsapp server or others) is spoofing you with wrong public key.

Now let me cut to the chase and write about the mechanism of both decryption and extraction of WhatsApp Database

You got to be thinking that it's impossible to just decrypt and extract the WhatsApp Database so easily with such high-end security attached to it

But let me tell you straight that it's possible and very easy to decrypt and extract the Database easily with the help of built-in tools available today in this technology

After all , Nothing is Impossible in today's technology

If there exists the technology then obviously there exists security tools too

Read Full Artical click here

There are following prerequisites software and tools need to be downloaded and installed before it

1. Crypt Key Extractor (https://codeload.github.com/EliteAndroidApps/WhatsApp-Key-DB-Extractor/zip/master)
2. Operating System (Windows , Linux , Mac OS X)
3. Java (https://www.java.com/en/download/)
4. ADB i.e. Android Debug Bridge (https://developer.android.com/studio/releases/platform-tools.html#download)
5. Android Device (with Android 4.0 or Higher than it)
6. USB Debugging must be enabled on the target device
7. Web Browser
8. Internet
9. USB (Universal Serial Bus)

In order to enable USB Debugging , Please navigate to Settings --> Developer Options -->  Enable USB debugging. Please tap multiple times on Build Number  under About Phone unless and until you become the developer if you find no developer option under the Settings option

Note :

01. I apologise Linux and Mac OS X users for the following below demonstration
02. Windows end users must have minimum knowledge about Windows OS for it
03. This is to be advised that it's for the education purpose , any illegal activity against any                      other unauthorised devices could lead to jail

Are you finally ready to decrypt and extract WhatsApp Database

So , Let's Get Started

04. Download prerequisites software and tools
05. Extract it to your preferred drive
06. Open up your Command Prompt
07. Navigate to the directory where WhatsApp Key DB Extractor installed
08. Connect your device via USB and change the mode from charging to media
09. Unlock your screen and wait for Full Backup option
10. Enter your backup password or leave the blank (if none set)
11. Tap on Back up my data.

Read Full Artical click here

Note : Please wait as It could take few minutes depending upon your size of data

12. Confirm backup password on your Command Prompt and check for extracted folder.
13. You'll find many files there such as axolotl.db , chatsettings.db , msgstore.db, wa.db.
14. As all these files are in SQL format visible through SQLite Software
15. Visit https://sqliteonline.com for Online Viewing
16. Click on Open DB and select them all in order to view the files online through the website
17. Done
I hope you can now easily decrypt and extract WhatsApp Database.

How to Decrypt WhatsApp crypt12 Database Messages | Tricks

WhatsApp backup conversation files are now saved with the .crypt12 extension. From crypt9, they seem to be using a modified version of Spongy Castle – a cryptography API library for Android.

Decrypt Database
Decrypt Database

All the findings below are based on reverse engineering work done on WhatCrypt and Omni-Crypt. I would like to highlight that IGLogger proved to be a very useful tool when it came to smali code debugging.

Extract Key File

To decrypt the crypt12 files, you will first need the key file. The key file stores the encryption key, K. WhatsApp stores the key file in a secure location: /data/data/com.whatsapp/files/key.
If your phone is rooted, extracting this file is easy. If your phone is not rooted, refer to instructions from WhatCrypt and Omni-Crypt for details on extracting the key file. The idea is to install an older version of WhatsApp, where Android ADB backup was still working and extract the key file from the backup.

Extract crypt12 Backup File

Pull the encrypted WhatsApp messages file from your phone using ADB.
$ adb pull /sdcard/WhatsApp/Databases/msgstore.db.crypt12

Decryption Keys

This section is just for your information and you can skip this section.
The encryption method being used is AES with a key (K) length of 256 bits and an initialisation vector (IV) size of 128 bits. The 256-bit AES key is saved from offset 0x7E till 0x9D in the file. Offsets start from 0x00. You can extract the AES key with hexdump and assign the value to variable $k.
$ k=$(hexdump -ve '2/1 "%02x"' key | cut -b 253-316)
The $k variable will hold a 64-digit hexadecimal value in ASCII that is actually 256 bits in length.
The IV or the initialisation vector is saved from offset 0x33 till 0x42 in the crypt12 file. The IV value will be different for every crypt12 file.
$ iv=$(hexdump -n 67 -ve '2/1 "%02x"' msgstore.db.crypt12 | cut -b 103-134)
The K and IV extraction method is similar to what we have done for crypt8 files before.

Strip Header / Footer in crypt12 File

Again, this section is just for your information and you can skip this section.
Before we start the decryption process, we will need to strip the 67 byte header and 20 byte footer from the crypt12 file.
$ dd if=msgstore.db.crypt12 of=msgstore.db.crypt12.enc ibs=67 skip=1
$ truncate -s -20 msgstore.db.crypt12.enc
The above dd command will strip the the first 67 bytes from the crypt12 file and save it to a file with extension crypt12.enc. The truncate command will strip the last 20 bytes from the crypt12 file.

Decrypt crypt12 File

As the WhatsApp AES cryptography API library seems to be a modified version, we will no longer be able to use openssl to decrypt the crypt12 file. I have yet to determine what has been modified.
To decrypt crypt12 files, I have written a simple Java program that will use the modified cryptography API library instead. For the cryptography API library, I have extracted the modified Spongy Castle cryptography class files from the Omni-Crypt APK file using dex2jar. You can find the Java program and crypto library over here at GitLab.
The Java program will create 3 output files:
  • msgstore.db.crypt12.enc – encrypted file with header and footer stripped.
  • msgstore.db.zlib – decrypted file in zlib format.
  • msgstore.db – decrypted sqlite3 database file.
Below is how you can compile and run the Java program.
$ git clone https://gitlab.com/stackpointer/whatsapp-crypt12.git

$ cd whatsapp-crypt12/

$ javac -classpath "lib/whatsapp_spongycastle.jar:." crypt12.java

$ cp ../whatsapp.data/key .

$ cp ../whatsapp.data/msgstore.db.crypt12 .

$ java -cp "lib/whatsapp_spongycastle.jar:." crypt12

K:XXXXXXXXXX
IV:YYYY
creating encrypted file with header/footer stripped: msgstore.db.crypt12.enc
creating zlib output file: msgstore.db.zlib
creating sqlite3 output file: msgstore.db

$ ls -l
total 136724
-rw-r--r-- 1 ibrahim staff     4339 Oct  9 16:05 crypt12.class
-rw-r--r-- 1 ibrahim staff     5459 Oct  9 16:05 crypt12.java
-rw-r--r-- 1 ibrahim staff      158 Oct  9 16:05 key
drwxr-xr-x 2 ibrahim staff     4096 Oct  9 16:05 lib
-rw-r--r-- 1 ibrahim staff     1089 Oct  9 16:05 LICENSE
-rw-r--r-- 1 ibrahim staff 62692352 Oct  9 16:06 msgstore.db
-rw-r--r-- 1 ibrahim staff 25757610 Oct  9 16:05 msgstore.db.crypt12
-rw-r--r-- 1 ibrahim staff 25757523 Oct  9 16:05 msgstore.db.crypt12.enc
-rw-r--r-- 1 ibrahim staff 25757507 Oct  9 16:06 msgstore.db.zlib
-rw-r--r-- 1 ibrahim staff     1376 Oct  9 16:05 README.md

$ file *
crypt12.class:           compiled Java class data, version 52.0 (Java 1.8)
crypt12.java:            C source, ASCII text
key:                     Java serialization data, version 5
lib:                     directory
msgstore.db:             SQLite 3.x database, user version 1
msgstore.db.crypt12:     raw G3 data, byte-padded
msgstore.db.crypt12.enc: data
msgstore.db.zlib:        zlib compressed data

Final Words

To use the Java decryption tool, you will need to use OpenJDK. Oracle require JCE Provider libraries to be signed. OpenJDK does not have this requirement. If you try running the Java program on Oracle JDK, you will most likely get the following exception.
Exception in thread "main" java.lang.SecurityException: JCE cannot authenticate the provider SC

Tuesday, October 31, 2017

How to Find Any Website's IP Address Using CMD & Android & iPhone | Tricks

Checking the IP address of a particular website is not a difficult task. This @llsinfoHow teaches you how to find the IP address of a website. You can do this by using an online service, by using your computer's built-in "ping" And "nslookup" command, or by downloading and using a free app for your iPhone or Android. Keep in mind that if a website is "masking" its IP address, you won't be able to see the website's true IP address.

How to Find Any Website's IP Address Using CMD | Tricks
How to Find Any Website's IP Address Using CMD | Tricks


1) For Windows (1st Method)

Step 1: Open Image titled Windowscmd1.png Command Prompt (Administrator)

Step 2: Type nslookup command and your website name (e.g., nslookup xyz.com)
Note : You don't need to include the www. part of the address.

Step 3: Press ENTER. wait it will take a several time

Step 4: Note the IP address. You'll see the IP address



1) For Windows (2nd Method)

Step 1: Open Image titled Windowscmd1.png Command Prompt (Administrator)

Step 2: Type ping command and your website name (e.g., ping xyz.com)
Note : You don't need to include the www. part of the address.

Step 3: Press ENTER. Doing so will search for the website's IP address.

Step 4: Note the IP address. You'll see the IP address' series of numbers next to the "Reply from" line of text. This is the website's closest server's IP address.

Step 5: Try alternative IP ping commands. If you can't find an IP address for your website, try one of the following commands where "website.com" is the address of the website:


  • ping ftp.website.com
  • ping cpanel.website.com
  • ping mail.website.com



2) For Mac

Step 1: Open  Image titled Macspotlight.png  Spotlight And Type network utility And search

Step 2: Click  Network Utility

Step 3: Click Ping  Tab.  It's at the top of the window.

Step 4: Enter the website's address.(e.g., xyz.com)
Note : You don't need to include the www. part of the address.

Step 5: Check the "Send only [number] pings" box. It's in the middle of the page. You can change the number in the text field to anything you want here, but setting it to "1" should be sufficient.

Step 6: Click Ping  It's a blue button on the far-right side of the window. Doing so will cause Network Utility to request the IP address of your entered website.

Step 7: Note the IP address. In the window at the bottom of Network Utility, look for the IP address' numbers to the right of the "bytes from" heading. This is the IP address of the website you pinged

Step 8: Try adding extensions before the website name. If you can't find an IP address for your website, try adding one of the following extensions before the address (e.g., "ftp.website.com"):


  • ftp.website,com
  • cpanel.website.com
  • mail.website.com


3) For Android

Step 1:  Download PingTools Network Utility. To do so

  • Open your Android Google Play Store.
  • Tap the search bar
  • Type in pingtools
  • Tap PingTools Network Utility
  • Tap INSTALL
  • Tap AGREE


Step 2: Open PingTools Network Utility. Tap OPEN in the Google Play Store, or tap the PingTools app icon.

Step 3: Tap  ☰ . It's in the upper-left corner of the screen. A pop-out menu will appear

Step 4: Tap Ping. This option is near the middle of the pop-out menu

Step 5: Enter an address. Tap the address bar at the top of the screen, then type in the address of a website that you want to ping for an IP address (e.g., website.com)
Note: You don't need to include the www. section of the address.

Step 6: Tap PING. It's in the top-right corner of the screen. Doing so will prompt your Android to request the IP address from your selected website

Step 7: Note the IP address. You'll find it below the "Ping [website]" heading that appears on the screen.

4) For iPhone

Step 1: Download Ping from your iPhone's App Store. To do so:

  • Open App Store app.
  • Tap Search
  • Tap the search bar
  • Type in ping
  • Tap Search
  • Tap GET next to "Ping - network utility"
  • Enter your password when prompted


Step 2: Open Ping. Tap the Ping app icon

Step 3: Tap the address bar. It's at the top of the screen

Step 4: Enter an address. Type in the address of the website for which you want to find the IP address (e.g., website.com)

Step 5: Tap Ping. It's in the top-right corner of the screen. Doing so will prompt your phone to begin requesting the website's address

Step 6: Note the IP address. You'll see it appearing once every second or so on the screen. The IP address will continue to appear in one-second intervals until you cancel the ping.

Monday, October 30, 2017

Download Crack IDM 2017 |Activate Internet Download Manager Crack

Do you all want to download IDM? Yes, Then here you’re at the right post. The demand of Internet Download Manager is very high as per as their latest updates and because of their high downloading speed, we all want the free IDM in our PC or laptop. This is the one and the only tool in this Internet that I seriously love the most because of its uniqueness and best downloading speed ever. and the Simple graphic user interface makes IDM user-friendly and easy to use.



The IDM (Internet Download Manager) is the one of the best Internet download manager ever I use. But the big issue in the Free IDM that, it gives you 30 days trial version after that one has to purchase its license. Therefore this post is for those people who don’t want to pay any bucks. So here I’m going to show ‘How To Download Free IDM in 2017. and from where to download and how to make its 30 days trail period to unlimited days.

Download IDM Free 2017 Crack + Working