Showing posts with label android. Show all posts
Showing posts with label android. Show all posts

Friday, 18 December 2015

Hack Facebook Using Phishing 2016 - Bypassing Security Check (Responsive)

fb phishing 1016- picateshackz

This is a complete tutorial for creating a facebook phishing site in 2016, newbies can follow this tutorial very easily. there are many ways to hack facebook accounts but unfortunately Everything wont work properly in now a days because today's IT security system is developed so far especially facebook. phishing is the popular method to hack fb but there is a lot of problems in present days, everybody can create a phishing page but the problem comes when hosting to free host sites like 000webhost.com.., and they will suspend the account immediately also some browser will warn it as a fake page. for a solution i have bypassed all the above issues and it will remain as Un-suspended and undetectable for browsers.

Warning & Disclaimer: Making a phishing page is not illegal, but using a phishing page is illegal. This tutorial is just to show you, "How to create phishing page?". If you use this to hack anyone account, then I AM not responsible for it. Do anything on your own risk.

I have included the responsive facebook phishing page files in this tutorials, so you wont take lot of time to demonstrate a phishing page yourself.


Features 

  • No suspension (From free web host)
  • Undetectable (Browser security check bypassed)
  • Responsive (It will work with Mobile And Desktop)
  • Url Mask (Hiding or changing phisher url)


    I have sorted this tutorial as 4 steps:

  1. Download the Attachment file, size:2.16 mb (Click here to download) or Alternate download
  2. Sign up to Free web host and upload the files
  3. URL masking/hiding
  4. Responsive Demonstration 

Step 1: Download the Attachment file

First of all download the attachment file named 'responsive-facebook.zip' file from here.

Extract the zip file and you will see 10 files named (data.php, data1.php, index.php, Mobile_Detect.php, desktop.jpg, follow.jpg, follow.jpg, desktop_files.zip, login_files.zip, users.txt) see below screenshot.


fb-phishing-2016-mobile/desktop- picateshackz.com


If you want to know how can you create yourself a phishing page then i recommend you to read my previous article: Create Undetectable Facebook Phishing Site - Advanced


Step 2: Sign up to Free web host and upload the files

I prefer 000.webhost.com.

Go to: https://members.000webhost.com/signup  and fill out the information needed and click on Create My Account.

fb-phishing-2016-mobile/desktop- picateshackz.com


Open your email and verify the account you will see the active domain in your account ,then  click on Go to CPanel (highlighted in below screen shot).

fb-phishing-2016-mobile/desktop- picateshackz.com


Now open the first file manager icon under File managers section.

fb-phishing-2016-mobile/desktop- picateshackz.com


Open up  “public_html” folder and delete the 2 files inside it. then click on “upload.

fb-phishing-2016-mobile/desktop- picateshackz.com


  • Below “Archive” section on the right side click on “Choose file“, Select the 2 files from downloaded attachment in step 1 (login_files.zip, desktop_files.zip)
  • Below “Files” section Choose the remaining 8 file (data.php, data1.php, index.php, Mobile_Detect.php, desktop.jpg, follow.jpg, follow.jpg, users.txt) 
  • Click on the “green tick“.
fb-phishing-2016-mobile/desktop- picateshackz.com

Done!!!, Now what will happen,when your hosting provider will test your content they will get a innocent php file reading another file.and when they try will to access "login.jpg" file they will get an invalid/corrupted image.

Now Access your URL with this id at end (/?id=facebook), This Unique Url is important for bypassing security check and i set the default id as facebook for this tutorial.

Example: "www.autolikerfb.comxa.com/?id=facebook"(See the Screenshot below)

fb-phishing-2016-mobile/desktop- picateshackz.com


When victim enter the email and and password in above page will be stored in our 'users.txt' file, to see that click the view button next to users.txt file.

fb-phishing-2016-mobile/desktop- picateshackz.com

Inside users.txt file you can see the victim's email and password (highlighted part in below screen shot).

fb-phishing-2016-mobile/desktop- picateshackz.com

Finally you have your phisher link like this: www.autolikerfb.comxa.com/?id=facebook


Step 3: Url Masking/Hiding

Now you have to hide the URL. That way it can be less suspicious. so here we use Dot TK url Shortening. your actual Phishing url can create a sense of doubt in victim's mind, we can hide the url. Dot.tk is an online service which enables you to hide/mask the url.

1. So, go to http://www.dot.tk/en/index.html?lang=en to hide a url.

2. Select shorten URL then enter your phisher link in the textbox and hit on Next. (our Phisher link: 
www.autolikerfb.comxa.com/?id=facebook )
3. Enter the link you want to rename your phisher link to dot.tk domain name.
(domain: autolikerfb )

Now we have the phishing url shortened like belove:

www.autolikerfb.comxa.com/?id=facebook  =  autolikerfb.tk

Now, you can send this masked phisher link to your victim.

The victim will now find our phisher link less suspicious as we have hidden the actual phisher link using .tk domain.


Step 4: Responsive Demonstration 

Here is the screenshot of autoliker.tk in mobile view and desktop version,it will automatically redirect to original facebook page when login. 


fb-phishing-2016-mobile/desktop- picateshackz.com
Mobile View
fb-phishing-2016-mobile/desktop- picateshackz.com
Desktop View

Wednesday, 16 December 2015

Deep Web Surfing On Android: Setup Tor And Stay Anonymous

Deep web-android-tor- picateshackz.com

It may be known to hackers and coders worldwide but for most internet users, the so-called 'Deep Web' remains shrouded in mystery, a supposed morass of drugs, deviancy and stolen credit card details. so in this post i will tell you more about deep web and a complete guide to setup Android Tor and get access to Deep Web from Android devices.

First i want to tell you little more about Deep Web, Interest in this massive part of the Internet - which is inaccessible by search engines and includes blocked sites, limited-access networks and private sites that require login credentials - has piqued in recent years, especially following the 2013 FBI investigation into online marketplace Silk Road that exposed the extent of online drug trafficking. The hit television series House of Cards also featured the phenomenon during its second season.

Now, security software firm Trend Micro has explored the anatomy of the Deep Web, investigating why people go there and the wide range of their transactions. Want to go deeper into the Deep Web? Trend Micro's report has the answers to your key questions.

How big is big when it comes to the Deep Web?

It's around 400 times larger than the visible Web, according to the report. The nature of the Deep Web makes an accurate estimation of size impossible but over the course of two years, Trend Micro collected more than 38 million pieces of content that account for 576,000 URLs.

English language sites make up the bulk of the Deep Web at 62 percent. Russian was second at nearly 7 percent, followed by French at 5.5 percent.

How do I access it?

Logging on to the Deep Web requires the use of specific software that allows users to communicate anonymously, such as TOR, Freenet, or the Invisible Internet Project, the report said. A brief Google search reveals that TOR is easily available and free, making access relatively simple.

Keeping your online data and identity private is an uphill battle, but with the anonymity network Tor, you have a pretty decent line of defense from prying eyes.

But while Tor is great for desktop users, since they can simply install a Tor browser or plugin, it's a bit more complicated on Android. The difficulty lies in getting all the data your device sends out pushed through the Tor network, which anonymizes by sending data through various servers around the world.

Now Let's Start setting up Tor on Android:

Requirements for Tor

Before installing the three apps needed to get Tor up and running on your Android device, you need to first make sure it's rooted. Additionally, because the required apps are not found on the Google Play Store, you'll need to make sure you enabled app installation from Unknown sources.

Read this tutorial to Root Android: Benefits Of Rooting Android Devices And How To Root Without Computer

Once you have root access, you'll be able to download and install OrWall, Orbot, and Orweb to get the full Tor experience on your phone.

Step 1: Install OrWall

Developed by Swiss privacy activist Cédric Jeanneret, OrWall is essentially a firewall for your Android that will force all of your apps (or just the ones you select) to use the Tor network to transmit all of their data. If an app is unable to use the Tor network to access the internet, then that data connection will be blocked.

Deep web-android-tor- picateshackz 3Deep web-android-tor- picateshackz 3

After installing the APK, complete the set up wizard and reboot your Android to activate the background process. When you're back up, you can open the Apps section of OrWall to begin selecting which apps you would like to have use the Tor network.

Step 2: Install Orbot

In its simplest form, Orbot, by the great people over at the Guardian Project, is the connector between your device and the Tor network. It facilitates the passage of data from your apps to the Tor network, but it can only do so with apps that support data being sent through a proxy. Because of that limitation, it's necessary to have both Orbot and OrWall installed on your device, since OrWall will help with apps which do not have proxy support.

Deep web-android-tor- picateshackz 3Deep web-android-tor- picateshackz 3

The first time you open the app, you'll have to complete the set-up wizard, but afterwards, all you have to do is long-press the Power button in the center to activate Orbot. If at any time you want to change your Tor Identity to a different IP address, you can swipe across the main screen, which will come in handy if you don't want to stray on the same IP address for too long.

Step 3: Install Orweb

Last up we have the companion browser the developers over at the the Guardian Project created for Orbot, called Orweb. While Orbot creates the connection to Tor, Orweb is what actually lets you use it to surf the web.

Since your data will be bouncing around through the vast labyrinth of international Tor servers, it will feel like your connection has slowed down, but that this the price you must pay for anonymity. As an added bonus, Orweb can also bypass most network restrictions so you can finally get in some quality Reddit browsing even through your office's firewall.

Deep web-android-tor- picateshackz.comDeep web-android-tor- picateshackz.com

There is no setup required to begin using Orweb—just open the app and wait for the homepage to display a "success" message letting you know that it has been connected to the Tor network.

The Guardian Project has also been working on an improved version of Orweb named Orfox, which adds features like tabbed browsing and a way to properly request mobile versions of websites. However, Orfox is still in its early stages and not supported on Lollipop devices, but if you're still on KitKat, be sure to give it a try.

Conclusion

With these three apps, you'll be able to Surf on Deep Web using Orweb Browser and it will keep most of your data secure, but if the dozens of security breaches and NSA scandals over the past few months have told us anything is that no one's data is ever 100% secure online.

During the Silk Road trial, several news reports conflicted on whether the site belonged to the Deep Web or the Dark Web, creating confusion on whether the terms 'dark' and 'deep' were interchangeable.

They are not, explains Trend Micro: "The Dark Web is only part of the Deep Web. It relies on darknets or networks where connections are made between trusted peers."

The Silk Road site was indeed part of the Dark Web, and the majority of public interest in the overall Deep Web lies in activities that happen inside these darknets as they are harder to access, the report added.

Friday, 11 December 2015

Stay Anonymous Online - Setup A VPN On Android Device

setup-vpn-on-android- www.picateshackz.com

Android is open-source software and as with all open-source material, there are a lot of options and customization that can be created because the code is open for anyone to manipulate as they see fit. This comes with, of course, a major flaw… that flaw being that it’s easier to find ways to add malicious code and find “zero-day” exploits to read/steal data from the device. One thing that can help as far as sending and receiving data is a VPN. A VPN app encrypts one’s data transfers to safeguard against malicious “eyes.”


Related:


One should seriously consider using a Virtual Private Network (VPN) service if they perform below activities often from their mobile devices:
  • Using (open) public Wi-Fi (i.e. – from coffee shops, cafes, restaurants, etc.)
  • Performs online transactions (i.e. – online banking, paying bills, online shopping, money transfer, etc.)
  • Using one’s phone for emails, consistently.
  • Using Messenger, Hangouts, Skype calls on a regular basis.

Based upon a new poll, people prefer downloading a VPN application on their Android devices versus manually setting it up, because it saves time and energy. The Virtual Private Network application encrypts and re-routes information that is being received and sent from a device to protect you against the dirty tricks of online criminals and eavesdroppers.

Although we appreciate the difficult works of entrepreneurs who are applying all of their energies to ensure that our information is secure, it is always suggested that one goes for a VPN service that is hosted on a large scale and has positive reviews from reputable security websites.

In addition, most larger VPN providers offer custom VPN clients for mobile devices. However, there are several providers that have failed to catch up with the pace of the trade, and need efforts from our end to establish their clients’ connections using our cell phones. If you select a VPN provider that has no pre-built client, then one can always utilize these instructions for manual setup on their Android device(s).

First, select the process or the protocol you wish to configure your VPN to use. Here are the protocols supported by the Android OS:

PPTP
L2TP/IPSec (PSK)
L2TP/IPSec (RSA)
IPSec Xauth (PSK)
IPSec Xauth (RSA)
IPSec Hybrid (RSA)

Based on the protocol you want to take advantage of, ask your VPN service provider to provide you with the preceding details:


PPTP

a) DNS Search Domains
b) DNS Servers
c) Forwarding Routes


L2TP/IPSec (PSK)

a) Server Address
b) L2TP Secret
c) IPSec Identifier
d) IPSec Pre-Shared Key
e) DNS Search Domains
f) DNS Servers
g) Forwarding Routes


L2TP/IPSec (RSA)

a) Server Address
b) L2TP Secret
c) IPSec User Certificate
d) IPSec CA Certificate
e) IPSec Server Certificate
f) DNS Search Domains
g) DNS Servers
h) Forwarding Routers


IPSec Xauth (PSK)

a) Server Address
b) IPSec Identifier
c) IPSec Pre-Shared Key
d) DNS Search Domains
e) DNS Servers
f) Forwarding Routes


IPSec Xauth (RSA)

a) Server Address
b) IPSec User Certificate
c) IPSec CA Certificate
d) IPSec Server Certificate
e) DNS Search Domains
f) DNS Servers
g) Forwarding Routes


IPSec Hybrid (RSA)

a) Server Address
b) IPSec CA Certificate
c) IPSec Server Certificate
d) DNS Search Domains
e) DNS Servers
f) Forwarding Routes


NOTE: Your VPN provider may not support ALL of these protocols, however make sure you request these components, so the VPN provider is aware that they are not dealing with some kid who used his father’s credit card to buy something he possess no knowledge about.


Step 1: From your home screen, go to the app drawer and choose ‘Settings.’ You should see something similar to the screenshot below:


setup-vpn-on-android- www.picateshackz.com


step 2: Choose ‘More…’

step 3:
Once inside ‘More,’ you will see ‘VPN’ as an option on the settings list. Touch it to take you to the profile page.

setup-vpn-on-android- www.picateshackz.com


step 4:
At this point, you should be presented with a blank screen (may vary for different devices as the picture is of stock Android) with a ‘+’ sign at the top. Next to it is the “Options” menu, the place where you can add, edit, activate and remove VPN profiles and configurations.

setup-vpn-on-android- www.picateshackz.com


step 5: Click on the plus sign on the top right corner of the touch screen. Once you touch it, it lets you add a manual Virtual Private Network profile. (You can add multiple configurations by tapping the plus sign again after configuring your first profile.)

step 6: Once there, all you need to do is select the protocol that you wish to use.

setup-vpn-on-android- www.picateshackz.com


step 7: Once you have selected your desired protocol, tap the ‘Save’ option and it will take you back to the main page of the VPN settings screen, and your profile will be available to you on main VPN screen – in our case it’s titled, “Test.”

setup-vpn-on-android- www.picateshackz.com


step 8: Once that is done, click on the profile to enter further details… once you touch it, a pop-up will appear asking for a username, password and any other pertinent details based upon the protocol you chose – the VPN service provider will provide all of that data – and once all of the information is entered correctly you are ready to use your VPN!

setup-vpn-on-android- www.picateshackz.com


Remember! You can always edit or remove the VPN profile by touching the profile you wish to modify or want removed.

Monday, 24 August 2015

New Android Vulnerable - Hackers To Take Over Your Phone

New Android Vulnerable  to Hackers- picateshackz.com

This time Everything is Affected!

Yet another potentially dangerous vulnerability has reportedly been disclosed in the Google's mobile operating system platform – Android.

Android has been hit by a number of security flaws this month, including:
  •  Stagefright vulnerability that affects 950 Million Android devices worldwide
  • A critical mediaserver vulnerability that threatened to crash more than 55 percent of Android devices
  • Another critical flaw (CVE-2015-3842) discovered last week, affected almost all the versions of Android devices
This time the issue resides in the multitasking capability of the Android phones, the ability to run more than one app at a time.

The security flaw gives hacker ability to spy on Android smartphone owners, steal login credentials, install malware, and many more, according to the latest research conducted by the researchers at thePennsylvania State University and FireEye.

How the Attack Works?


According to security researchers, the flaw could be exploited to lure the victim into unwittingly handing over their login details into a spoofed user interface, controlled by a hacker, when an Android user starts an app.

The device owner won't at all be aware that they are typing their sensitive details into a malicious software program masquerading as a legit Android app.

The researchers published their research in a paper titled, "Towards Discovering and Understanding Task Hijacking in Android" [PDF], which they presented at the USENIX Security 15 conference in Washington DC last week.

The study explained practical details of how multitasking within Android differs from multitasking within desktop operating systems that focused on what happens when an app or multiple apps run in one or multiple processes simultaneously creating Multi-Tasks.

Multitasking in Android allows us to gain advantage in a way:
  • By being able to switch between the apps
  • Apps being able to maintain their state in the background
  • Easy task or app switching

Task Hijacking Attacks on Large Scale


Android task management mechanism is threatened by severe security risks. When maltreated, these convenient multitasking features can backfire and initiate task hijacking attacks on a vast scale.

The researchers analyzed more than 6.8 Million apps from multiple Android app stores and found that the task hijacking flaw is prevalent in all apps. Since many Android apps depend on "the current multitasking design, defeating task hijacking is not easy."

The researchers also claimed that the vulnerability can impersonate the user interface of the app, which is controlled by the attacker on the other hand.

You can watch the video to find the quick overview of the vulnerability.


This is just one scenario where the attacker is deploying phishing attack on Android users, and gaining their privacy credentials.

Yet More to Come

There can be instances where the users can be the victims of RansomwareDistributed Denial of Service (DDoS) attacks and other cyber attacks.

The five security researchers – Peng Liu and Chuangang Ren from the Pennsylvania State University, and Yulong Zhang, Tao Wei and Hui Xue from FireEye – involved in the research reported the security hole to the Android team.
"We appreciate this theoretical research as it makes Android's security stronger," said a Google spokeswoman.
You are safe as; as Google said that customers are protected from hijacking and phishing attacks withAndroid's Verify Apps and Safety Net features.

Also, you can keep yourself safe by installing apps from trusted sources and keeping your safety completely with you.

Sunday, 5 July 2015

Stealing Android Browser Cookies Using Cross Scheme Data Exposure Attack

android-cookies-stealing-cross-scheme-attack- picateshackz.com

tl;dr This exploit is an issue present in Android browser < 4.4 and several other android browsers which allows an attacker to read sqlite cookie database file and hence exposing all cookies. Along with it we will talk about a Cross Scheme Data exposure and intent URL scheme attack in Android < 4.4.


Introduction

During our research on ASOP (Stock Browser) we found out that is is possible to open links to local files using file:// protocol by from a webpage by selecting "Open Link in New tab" from the context menu". This itself is does not represent a vulnerability unless there is a way to read local files and use be able to retrieve the files remotely. However, what caught my attention here is this by default is not permitted browsers such as Chrome, Firefox, Opera etc.

The following screenshot demonstrates the error which is obtained when trying to access a local file from context menu.

android-cookies-stealing- picateshackz.com


Attack Plan 

In order to exploit this issue, the following was the attack plan we came up with:

  1. User visits Attacker.com.
  2. Attacker.com forces a download (exploit.html) on the victim's browser using content disposition header. The purpose of the exploit.html would be read local files and send it back to the attacker.
  3. The victim opens up a link by selecting "Open Link in New tab" which opens the local file exploit.html which was forced as download.
  4. Our file exploit.html would then be reading other local files and sending it back to the attacker.


In order to write an effective exploit for the attack, I coped up with Haru Sugiyama a Security researcher from Japan. He came up with the following POC:


Upon accessing the above page from android browser, it would first force the following file "exploit.html". Both FireFox and Android browser save files to '/sdcard/Download/exploit.html' in case sdcard is available. The exploit.html file would then try reading the other local files. However, this was not easy as it looked at first sight. Let's first talk about how the results from Android Gingerbread were different from Jellbeans.



Android Gingerbread:Observations 

In case of Android Gingerbread Emulator build 2.3 we are easily able to read other local files, this represents a vulnerability as in the browser, as it effectively allows a website to perform cross domains data theft and hence violating the same-origin-policy. The impact however is not large as roughly 11.4% of the users now use Android Gingerbread and they are dying slowly just like windows xp.

android-cookies-stealing- picateshackz.com



Android JellyBeans: Observations

In case jellybeans we found out that a local file was not able to read a local files, We then tried our old null byte trick and it worked like a charm.

The following is the POC:

<button onclick="exploit()">Read iframe</button>
<button onclick="window.open('\u0000javascript:alert(document.body.innerHTML)','test')">Try \u0000</button>
<iframe src="file:/default.prop" name="test" style='width:100%;height:200'></iframe>
<script>
function exploit() {
  var iframe = document.getElementsByTagName('iframe')[0];
  try{
    alert("Try to read local file.");
    alert("contentWindow:"+iframe.contentWindow);
    alert("document:"+iframe.contentWindow.document);
    alert("body:"+iframe.contentWindow.document.body);
    alert("innerHTML:"+iframe.contentWindow.document.body.innerHTML);
  } catch(e) {
    alert(e);
  }
}
</script>

However, due to the discovery of CVE-2014-6041 the nullbytes issue was already patched and the above exploit did not work on patched devices.


Intent URL Scheme Attack

Based upon our above findings it was concluded that in Android Jellybeans the access to local files was not an issue due to the fact that a local file could not read other local files. However Joe Vennix from metasploit team came up with a more strong way to exploit it by abusing the intent scheme. The following paper -> http://www.mbsd.jp/Whitepaper/IntentScheme.pdf describes a potential way of exploiting this issue. The following is the POC described in the paper:

android-cookies-stealing- picateshackz.com


The idea behind the attack vector is to saved a cookie containing javaScript code and trick the victim into opening the sqlite database file. Upon viewing the injected javascript would be executed in the context of a cookie file and would grab the rest of the cookies from the database file. Following is the basic POC, when when executed would read the entire webviewCookieChromium.db file.

<!doctype html> <html> <head><meta name="viewport" content="width=device-width, user-scalable=no" /></head> <body style='width:100%;font-size: 16px;'> <a href='file:///data/data/com.android.browser/databases/webviewCookiesChromium.db'> Redirecting... To continue, tap and hold here, then choose "Open in a new tab" </a> <script>

document.cookie='x=<img src=x onerror=prompt(document.body.innerHTML)>';


</script> </body> </html>

Joe has created a Metasploit module, which automates the process of stealing the cookies and sending it back to you , since the db file also contains httponly cookies as well this attack is quite dangerous.



Steps to Reproduce with Metasploit:

The following screenshots would walk you through the process of exploiting and retrieving the cookies:

If you don't know how to use metasploit then i suggest you to read this article: 
Introduction to using Metasploit in Kali Linux


Step 1 - Setting up the Module

android-cookies-stealing- picateshackz.com


Step 2 - Stealing The Cookies


All you need to sit back and watch the cookies coming to you.

android-cookies-stealing- picateshackz.com 3


Step 3 - Enjoy


android cookies stealing- picateshackz.com


Patch

The access to the data directory was tightened back in Feb 2014, however due to the android patch policies the patch did not make to most of the vendors.

Credits

I would like to thank Tod Beardsley and Joe Vennix from the metasploit team for their extensive support with analyzing and helping to co-ordinate with Google effectively. As well as Haru Sugiyama for his help and support.