Thursday, October 5, 2017

Use JPGFileBinder to Hide Files Inside JPEG Images Easily

We discussed how to hide files inside JPEG/GIF/PNG images in Windows PCs in a previous article. The method was not difficult but it involves some hassle. It includes making a new folder and copying files through the command line.
There is a tool known as JPGFileBinder which can be used for the same purpose. The software is portable and requires no installation. You can easily hide files inside JPEG images using this tool. All you need to do is download the zip file, extract the JPG+FileBinder.exe in your computer and hide files using a few steps.
Here’s a step by step guide to perform the process.
1. Collect the files which you want to hide in a single folder because you would need to compress it to .rar or .zip format using a file compression tool.
2. Double click on JPG+FileBinder.exe icon.
3. A small pop up box will appear. Click on the “Picture” button to add a picture in which you want to hide files. Click on “Compressed file” button to add files you compressed in step 1.
hide files in JPEG images
4. Click on “Output Picture File” button. Now you have to give a name to the output picture file. This output file will be your secret image file in which all the compressed files will stay hidden.
output picture file
Note: In the example, I’ve given a name “picture” to the image file. It will be saved as picture.jpg. You are free to choose any other name.
5. Now click on OK button.
jpgfileblinder1
6. A small notification box appears telling you that the files have been binded.
files binded

How to get our Files back from the image

In step 5, a name has been given to the output picture file. Rename the output image file picture.jpg to picture.zip. Now open it using any file compression software such as Zipgenius, 7Zip, Winrar or extract it online using Wobzip.
Download JPGFileBlinder [Softpedia via Makeuseof]

Wednesday, October 4, 2017

SQL Injection (SQLi)

SQL Injection (SQLi) refers to an injection attack wherein an attacker can execute malicious SQL statements (also commonly referred to as a malicious payload) that control a web application’s database server (also commonly referred to as a Relational Database Management System – RDBMS). Since an SQL Injection vulnerability could possibly affect any website or web application that makes use of an SQL-based database, the vulnerability is one of the oldest, most prevalent and most dangerous of web application vulnerabilities.
By leveraging an SQL Injection vulnerability, given the right circumstances, an attacker can use it to bypass a web application’s authentication and authorization mechanisms and retrieve the contents of an entire database. SQL Injection can also be used to add, modify and delete records in a database, affecting data integrity.
To such an extent, SQL Injection can provide an attacker with unauthorized access to sensitive data including, customer data, personally identifiable information (PII), trade secrets, intellectual property and other sensitive information.

How SQL Injection works

In order to run malicious SQL queries against a database server, an attacker must first find an input within the web application that is included inside of an SQL query.
In order for an SQL Injection attack to take place, the vulnerable website needs to directly include user input within an SQL statement. An attacker can then insert a payload that will be included as part of the SQL query and run against the database server.
The following server-side pseudo-code is used to authenticate users to the web application.
# Define POST variables
uname = request.POST['username']
passwd = request.POST['password']

# SQL query vulnerable to SQLi
sql = “SELECT id FROM users WHERE username=’” + uname + “’ AND password=’” + passwd + “’”

# Execute the SQL statement
database.execute(sql)
The above script is a simple example of authenticating a user with a username and a password against a database with a table named users, and a username and password column.
The above script is vulnerable to SQL Injection because an attacker could submit malicious input in such a way that would alter the SQL statement being executed by the database server.
A simple example of an SQL Injection payload could be something as simple as setting the password field to password’ OR 1=1.
This would result in the following SQL query being run against the database server.
SELECT id FROM users WHERE username=’username’ AND password=’password’ OR 1=1’
An attacker can also comment out the rest of the SQL statement to control the execution of the SQL query further.
-- MySQL, MSSQL, Oracle, PostgreSQL, SQLite
' OR '1'='1' --
' OR '1'='1' /*
-- MySQL
' OR '1'='1' #
-- Access (using null characters)
' OR '1'='1' 
' OR '1'='1' %16
Once the query executes, the result is returned to the application to be processed, resulting in an authentication bypass. In the event of authentication bypass being possible, the application will most likely log the attacker in with the first account from the query result — the first account in a database is usually of an administrative user.

What’s the worst an attacker can do with SQL?

SQL is a programming language designed for managing data stored in an RDBMS, therefore SQL can be used to access, modify and delete data. Furthermore, in specific cases, an RDBMS could also run commands on the operating system from an SQL statement.
Keeping the above in mind, when considering the following, it’s easier to understand how lucrative a successful SQL Injection attack can be for an attacker.
  • An attacker can use SQL Injection to bypass authentication or even impersonate specific users.
  • One of SQL’s primary functions is to select data based on a query and output the result of that query. An SQL Injection vulnerability could allow the complete disclosure of data residing on a database server.
  • Since web applications use SQL to alter data within a database, an attacker could use SQL Injection to alter data stored in a database. Altering data affects data integrity and could cause repudiation issues, for instance, issues such as voiding transactions, altering balances and other records.
  • SQL is used to delete records from a database. An attacker could use an SQL Injection vulnerability to delete data from a database. Even if an appropriate backup strategy is employed, deletion of data could affect an application’s availability until the database is restored.
  • Some database servers are configured (intentional or otherwise) to allow arbitrary execution of operating system commands on the database server. Given the right conditions, an attacker could use SQL Injection as the initial vector in an attack of an internal network that sits behind a firewall.

The anatomy of an SQL Injection attack

An SQL Injection needs just two conditions to exist – a relational database that uses SQL, and a user controllable input which is directly used in an SQL query.
In the example below, it shall be assumed that the attacker’s goal is to exfiltrate data from a database by exploiting an SQL Injection vulnerability present in a web application.
Supplying an SQL statement with improper input, for example providing a string when the SQL query is expecting an integer, or purposely inserting a syntax error in an SQL statement cause the database server to throw an error.
Errors are very useful to developers during development, but if enabled on a live site, they can reveal a lot of information to an attacker. SQL errors tend to be descriptive to the point where it is possible for an attacker to obtain information about the structure of the database, and in some cases, even to enumerate an entire database just through extracting information from error messages – this technique is referred to as error-based SQL Injection. To such an extent, database errors should be disabled on a live site, or logged to a file with restricted access instead.
Another common technique for exfiltrating data is to leverage the UNION SQL operator, allowing an attacker to combine the results of two or more SELECT statements into a single result. This forces the application to return data within the HTTP response – this technique is referred to as union-based SQL Injection.
The following is an example of such a technique. This can be seen on testphp.vulnweb.com, an intentionally vulnerable website hosted by Acunetix.
The following HTTP request is a normal request that a legitimate user would send.
GET http://testphp.vulnweb.com/artists.php?artist=1 HTTP/1.1
Host: testphp.vulnweb.com

HTTP request a legitimate user would send
Although the above request looks normal, the artist parameter in the GET request’s query string is vulnerable to SQL Injection.
The SQL Injection payload below modifies the query to look for an inexistent record by setting the value in the URL’s query string to -1 (it could be any other value that does not exist in the database, however, an ID in a database is less likely to be a negative number).
In SQL Injection, the UNION operator is commonly used to allow an attacker to join a malicious SQL query to the original query intended to be run by the web application. The result of the injected query will be joined to the result of the original query, allowing an attacker to exfiltrate data out of a database by obtaining values of columns from other tables.
GET http://testphp.vulnweb.com/artists.php?artist=-1 UNION SELECT 1, 2, 3 HTTP/1.1
Host: testphp.vulnweb.com

SQL injection using the UNION operator
The above example proves that the query to the database can be modified to return data which an attacker may want to extract. The following example shows how an SQL Injection payload could be used to exfiltrate data from this intentionally vulnerable site.
GET http://testphp.vulnweb.com/artists.php?artist=-1 UNION SELECT 1,pass,cc FROM users WHERE uname='test' HTTP/1.1
Host: testphp.vulnweb.com


Tuesday, October 3, 2017

How To Send An Anonymous Email Bomber Online 2018

Working Email Bomber - Hi Guys These day everyone wants to make fool thier friends.Pranks are common in nowdays.Today we are coming with email bomber script.With the help of this script you can send multiple fake emails to your friends.This is a very fast working E-mail bomber. It can easily do 80 spams a minute then again it all depends on your speed.

This mail bomber has a maximum of 500 emails sent to the inbox of the popular email providers(Gmail/Yahoo/Hotmail)

Steps To Send Fake Emails To Your Friends

1.Go to Email bomber From Here - LINK

2.Now Fill in all details and Click on send

3.That’s it the person will start receiving unlimited mails

Note - This Trick is only for educational purpose we are not responsible for any harm by developer or friends.

Review By TricksAdda

I personally  used this email bomber.This works cool.You can make fool your friends with multiple emails. Guys i hope you like this post. We only recommended this email bomber only for fun purpose.

If You Like This Post Then Please Share It To Your Friends Because Sharing Is Caring


Monday, October 2, 2017

How to use Sqlmap (Sqlmap basics)

Sec-24-Hur-hackar-man-och-penetrationstest.-SQL-Injection-SQLi
Sqlmap is automated sql injection detection and exploitation tool written in python. It is very easy to use, straight forward tool to exploit sql injection in Relation Databases. Sqlmap supports variety of DBMS including the most popular ones: Mysql, Oracle, MSSql. The salient features of Sqlmap are:
  • Detecting sql injection
  • Dump data from databases
  • running arbitrary sql commands through it sql shell feature
  • running arbitrary OS commands through its OS shell feature
Requirements:
Sqlmap is simple to run. Before doing it practically lets see the most basic and important commands that are required for using sqlmap.
  • -r <REQUESTFILE>: Load HTTP request from a file(can be used for both GET and POST methods)
  • -u <URL>, –url=<URL>   Target URL (e.g. “http://www.site.com/vuln.php?id=1”) (For POST request, this needs to used in combination with –data option)
  • –level=<level>: Level of tests to perform (1-5, default 1)
  • –risk=<risk>: Risk of tests to perform (1-3, default 1) (for detection keep it 1 and for exploitation, keep it 3)
  • –dump: This option is used to dump data from a given database or table. (database is provided by -D <database> and table is provided by -T <table>
  • –dump-all: This option is used to dump data of everything (database and table) Sqlmap finds.
  • –dbs: To enumerate databases
  • –tables: To enumerate tables for a given database(provided using -D). If ‘-D’ option is not provided, current database is default.
For more options, you can refer the sqlmap help by typing:
python sqlmap.py –help

Lets start using Sqlmap. For this demo, I have used a freely available, intentionally vulnerable web app called mutillidae which can be run locally using apache for learning purpose. Its code can be found here.
The page shown below takes username and password as input and shows the user details if both, username and password, are correct.
The request going to the server hosted on the localhost is shown below using burp proxy. Here the parameters username and password within the query string are vulnerable to sql injection. We’ll use username parameter for sql injection detection and exploitation using sqlmap.
To run sqlmap, open command prompt or terminal, go to the folder where sqlmap code is extracted and the commands.
To check if username name parameter is vulnerable to sql injection, we need to specify the following things:
  • -u: Full url of the web app page to test
  • -p: Parameter in the query string or in the request body to be tested
  • –data: If POST method is used, specify the request body data here
Sqlmap has determined that the parameter username is vulnerable to sql injection and also enumerated the backend database among other information. Here, Mysql of version 5.0.12 is being used.
Once we have identified that the parameter username is vulnerable, lets specify additionally the dbms as Mysql using option “–dbms=Mysql” and tell sqlmap to enumerate all the databases using option “–dbs”. Specifying the dbms, if you know, speeds thing up by not trying payloads of other dbms.
Sqlmap has successfully enumerated the list of databases in the current dbms as shown below.
We’ll enumerate the nowasp database and specify the same to Sqlmap using option “-D <database-name>”. We’ll tell Sqlmap to enumerate tables in nowasp database using option “–tables”.
Below screenshot shows the tables from nowasp database.
Looking at the list of tables, it looks like the table accounts may contain sensitive data. We’ll try to dump all the data of that table. To tell sqlmap which table’s data to be extracted, use “-T <tablename>”. Use “–dump” to dump data of the specified table(-T) from the specified database(-D).
As you can see, sqlmap has successfully dumped the data of the table accounts which contains the user credentials.
For POST method, a more feasible way of running sqlmap is using the “-r” option. Store the whole request containing vulnerable parameter inside a file, example shown below, and call the file. The request can be taken from the burpsuite history.
Example command for the same attack shown above is:
python sqlmap.py -r <request-file-name> -p username
Note: The post is only for learning purpose only. Do not perform testing where you are not authorized to.