Ads 468x60px

Friday, 4 January 2013

100% FUD Crypter for Keyloggers and RATs

I have posted a number of FUD crypters on TRICKSLK.INFO in last few days. Today, I am adding one more to the list. No doubt, this crypter too, is FUD (Fully UnDetectable) and is found supporting large number of keyloggers. If our sent keylogger server is not FUD, the victim antivirus might detect and delete our server. Thus, hacking victim email passwords becomes almost a tedious task due to antivirus on victim computer. So, FUD crypter is necessary to bypass antivirus detection.
What are Crypters and what is FUD???

Well, I won’t extend this topic over here, as I have explained all things about crypters in my article FUD crypter basics. Once, you have gone through that article, move on to further steps. 
How to use FUD crypter???
I tried this FUD crypter with Decay Logger and found it working perfect with it. Below, I have demonstrated how to make Decay Logger server FUD using this crypter.
1. Download FUD Crypter software to bypass antivirus.
Password:- TRICKSLK.INFO
2. Run crypter on your computer to see:

3. Hit on Browse and select the Decay logger server you have created. Again, hit on second Browse button and select the msc2.exe stub file from downloaded folder. Select type of encryption like Xor, Rsa, etc. as you want. Now, hit on Crypt and select the path where you want to save the crypted FUD server.
4. You will find the crypted FUD server created at required destination. Now, bind this crypted keylogger server with any .exe file using Iexpress Binder software and send it to your victim to get the required email passwords from victim computer. You don’t have to worry about victim antivirus as the crypted server will not be detected by any antivirus. I have posted the scan results below:
Scan result before crypting:

Scan result after Crypting:

Note: Since this crypter is public, it will remain FUD for not more than 2-3 days. So, use this crypter the earliest. The best way is to get the best hacking software – Winspy Keylogger, which is FUD (Fully UnDetectable). This is personally recommended keylogger from TRICKS4INDYA.
So friends, try out this FUD crypter to bypass antivirus detection. This crypter supports many keyloggers and RATs. You can try out for your own server.
Enjoy FUD crypter to bypass antivirus detection…
Note: This is illegal and is for educational purpose only. Any loss/damage happening will not be in any way our responsibility.

How to Check if your Gmail Account Has Been Hacked or Not??

TRICKSLK.INFO always post some awareness article to protect you from hacker. Today I am going to share some information on “How to Check if your Gmail Account has been hacked or not??”
Gmail
If you’re worried about email security, here is a step by step guide to help you check and determine if your Gmail account has been hacked or watched/use in any way: -
1. Find the ‘Last Account Activity’ Section Your Inbox
At the bottom of your Gmail inbox there is a ‘Last Account Activity’ section. Click on ‘details’ to launch the full blown monitor.
Details
2. See who has accessed your Gmail account recently
Next, what you’ll see is a table of the most recent activity from your Gmail account. It shows you
· How it was accessed (Browser/mobile etc)
· Where exactly the IP address is (So you can do some further digging)
· When it was accessed

If you found some difference means at that date & time you not login to your gmail account as show in Activity Information window then change your passwords with security question immediately.
3. Understand the IP addresses – Has your Gmail really been hacked?
If you see IP addresses from different countries, don’t be too quick to panic. If you use any 3rd party services which hook-up to your Gmail account, they will almost certainly show up in your activity log. To do your own investigation, you can use DomainTools to identify the IP address. This will help you differentiate normal activity and your Gmail account being hacked.
DomainTools
DomainTools
4. Understand the alerts – Google’s way of highlighting suspicious activity
Google will also do its fair share of monitoring, and will also alert you if it sees suspicious activity both in your inbox, as well as your recent activity log. When this happens, and the IP addresses look suspicious, it is advisable to play it safe, assume your Gmail account has been hacked, and change your passwords immediately.
5. Sign Out All Other Sessions – If you forgot to sign out on a public computer
If you are worried you did not sign out of a public computer, you can use ‘sign out all other sessions’. sign out all other sessions tab found in Activity Information window. This won’t fix any hacked Gmail accounts, but it will resolve any careless mistakes. This is also useful if you happen to lose your mobile phone and you want to ensure your email is not read by others.
Sign Out
6. What to do if your Gmail account has really been hacked
The first thing you do is change both your password and security question right away. Then make sure your new choices are very secure. Google themselves have some really good tips . For example in the case of security questions:
· Choose a question only you know the answer to – make sure the question isn’t associated with your password.
· Pick a question that can’t be answered through research (for example, avoid your mother’s maiden name, your birth date, your first or last name, your social security number, your phone number, your pet’s name, etc.).
· Make sure your answer is memorable, but not easy to guess. Use an answer that is a complete sentence for even more security.
For more information you also read my article on “How To Create Strong Password? “.
7. Always Use Google Gmail’s 2-step Authentication/Verification
This is most important security tool add by Google recently to protect your Gmail account. If you want to save yourself then enable Gmail 2- step Authentication/Verification. For more detail how to use Gmail 2-step Authentication/Verification read my article “How to use Google Gmail’s 2-step Authentication/Verification
So, these are the step-by-step guide on fully understanding Gmail’s account activity log, and how to check if your Gmail account has been hacked or not??

Gmail Hacker: How to hack Gmail account password

In my previous article How to Hack Gmail account, I mentioned about use of Keylogger software to hack Gmail account password. Gmail Hacker is hacking software used to hack Gmail account password very easily. The article below illustrates the procedure of using Gmail Hacker software. I have even provided link for Gmail Hacker software download… just read on.
Gmail Hacker to hack Gmail account:-
While using Gmail Hacker, you have to create Gmail Hacker.exe file and then send this file to your victim. Tell your victim that this sent Gmail Hacker file is used to hack Gmail account password and that he only needs to fill all the details in Gmail Hacker file. Once, he enters all the details (which include his Gmail id and password) and hits on “Hack Them”, his entered Gmail account information is mailed to you and you can now hack his Gmail account easily.
Follow the procedure below: -
1. Free Download Gmail Hacker file to hack Gmail account password.
Password: TRICKSLK.INFO
2. Run Gmail Hacker Builder.exe file to see:-

3. Now, enter your Gmail id and password. Here, use the Gmail id where you want to receive the hacked password of the victim. Gmail Hacker will send hacked Gmail password to this mail id. Hit on Build.  4. Gmail Hacker.exe file will be created in current directory.

5. Send this file to your victim and make him believe that this Gmail Hacker is used to retrieve/hack anyone’s Gmail password and that he needs to fill all the fields (which includes his Gmail id and password) to get password.  Once he fills all the information in Gmail Hacker.exe file and hits on Hack Them, his entered Gmail id and password will be mailed to you at the email you’ve used in Step 3. The mail will look like this:-
 
Thus, you have now successfully got victim’s Gmail password and can hack Gmail account easily.  So friends, this was all about the method of using Gmail Hacker software to hack Gmail account password of the victim. You can also use Keylog software as an alternate way of hacking Gmail.
Enjoy Gmail Hacker to hack Gmail account password…
Note: This is illegal and is for educational purpose only. Any loss/damage happening will not be in any way our responsibility.

Hack the Hacker: How to hack Email Account Password using Bintext

Previously, I have posted Gmail Hacker software used to hack Gmail account password & today I m going to post article on “How to Hack Email Account of Hacker??”. Well, its somewhat difficult to hack the hacker. But, there are always chances of getting password of hacker. One of the best methods used to hack Email account password of hacker is using Bintext software. I have link for software download… just read on.



How to Hack Email Account password:-
Bintext is a powerful text extractor software that can extract text from almost any kind of file. It has the ability to find plain ASCII, Unicode and resource strings from the file. The hacker’s username and password, if not present in encrypted format, is easily seen in this Bintext interface.
Usually, whenever hacker has to create a keylogger server to hack email account password, he has to enter his Email id and password where he wants to receive the hacked account information. If this entered Email id and password is not encrypted, Bintext exposes the entered Email id and password in plain text format and you can easily hack email account password of the hacker. Simply proceed further to know more on how to hack the hacker.
How to hack the Hacker???
1. Free download Bintext software to hack Email account password of hacker.
Password: TRICKS4INDYA
2. Refer my article on Gmail Hacker and create one Gmail Hacker.exe file. Now, though Gmail Hacker is created by you, simply imagine that this is a Gmail hacker file sent to you by a hacker. And you want to hack his (actually yours in this case) Email account password.
3. Run Bintext software on your computer.
4. Hit on Browse and select the Gmail Hacker file created in Step 2. Hit on GO.

5. Now, Bintext will show you all the file information in text format. Move on to end part of the information. You will find Email id and password of the hacker as shown. You can also use Find box at bottom to simplify your search. Enter search terms related to Email domains like Gmail, Hotmail, Live, Rediffmail, Yahoo and so on.
Note: This method used to hack the hacker will not work if Email username and password are encrypted. But, I have checked out and found that many keyloggers and hacking software’s do not encrypt the login information, thus making them vulnerable to Bintext attack and we can easily hack Email account password of the hacker.
So friends, I hope now you will be able to hack Email account password of hacker using this Bintext software. As I have mentioned earlier, it is quite difficult to hack the hacker. But, we have to keep on trying various methods used to hack Email account password.
Enjoy Bintext software to hack Email account password of hacker…
Note: This is illegal and is for educational purpose only. Any loss/damage happening will not be in any way our responsibility.

Social Engineering – Art of Manipulation

What is Social Engineering?
·      Social Engineering is the use of influence and persuasion to deceive people for the purpose of obtaining information or persuading the victim to perform some action. This may include obtaining information, gaining access, or getting the target to take certain action.

In other word Social engineering is defined as the process of obtaining others passwords, personal information, ideas…ect by the act of manipulating or to handle a people using technical cracking techniques (force victim to do something that is in your interest) realize that they have been scammed.
·      It can also be defined as the human side of breaking into a network. People with authentication process, firewalls, virtual private networks and network monitoring software are still wide open to attacks.
In Other word if there is some planning for a company it can be used in such a way that an employee may unwittingly give away key information in an email or by answering questions over the phone with someone they don’t know or even by talking about a project with co-workers at a local bar after hours.
It is said that security is only as strong as the weakest link. It does not matter if enterprises have invested in high end infrastructure and security solutions such as complex authentication processes, firewalls, VPNs and network monitoring software. None of these devices or security measures is effective if an employee unwittingly gives away key information in an email, by answering questions over the phone with a stranger or new acquaintance or even brag about a project with coworkers at a local pub after hours.
Attackers take special interest in developing social engineering skills and can be so proficient that their victims would not even realize that they have been scammed because social engineers exploit the natural tendency of a person to trust their word, rather than exploiting computer security holes. It’s generally agreed that users/people are the weak link in security; this principle is what makes social engineering possible.

Here I will show you an example on how social engineering works:-

Let’s look at Example 1: -  !!SAURAV!! (Hacker) calls(mail,chat,etc..) Ankit(victim) and pretends to be a Gmail employee, Here is the conversation:
!!SAURAV!!: Hi Michael I am Robert a Gmail employee
Ankit: Oh so, How are you doing?
!!SAURAV!!: I am fine. I am here to inform you that Gmail is performing a security update on all Gmail accounts and we therefore need to install those securities updates on your account.
Ankit: Yes kindly install those security updates.
!!SAURAV!!: Thanks for your interest in our security updates we will require your account
password for installing it..(You may also tell i will give u a tool install it which may be a sniffer)
Ankit(Victim) has become a victim of social engineering, he will give out his password thinking that the person whom he was conversing was a Gmail employee.
Art of Manipulation

· Social Engineering includes acquisition of sensitive information or inappropriate access privileges by an outsider, based upon building of inappropriate trust relationships with outsiders.
·      The goal of a social engineer is to trick someone into providing valuable information or access to that information.
·      It preys on qualities of human nature, such as the desire to be helpful, the tendency to trust people and the fear of getting in trouble.
Social engineering is the art and science of getting people to comply with an attacker’s wishes. It is not a way of mind control, and it does not allow the attacker to get people to perform tasks wildly outside of their normal behavior. Above all, it is not foolproof. Yet, this is one way most Attackers get a foot into the corporation.
Let’s look at Example 2: -
Attacker: “Good morning Ma’am, I am Bob; I would like to speak with Ms. Alice”
Alice: “Hello, I am Alice”
Attacker: “Good morning Ma’am, I am calling from the data center, I am sorry I am calling you so early…”
Alice: ” Uh, data center office, well, I was having breakfast, but it doesn’t matter”
Attacker: “I was able to call you because of the personal data form you filled when creating your account.”
Alice: “My pers.. oh, yes”
Attacker: “I have to inform you that we had a mail server crash tonight, and we are trying to restore all corporate users’ mail. Since you are a remote user, we are clearing your problems first.”
Alice: “A crash? Is my mail lost?”
Attacker: “Oh no, Ma’am, we can restore it. But, since we are data center employees, and we are not allowed to mess with the corporate office user’s mail, we need your password; otherwise we cannot take any action”(first try, probably unsuccessful)
Alice: “Er, my password? Well…”
Attacker: “Yes, I know, you have read on the license agreement that we will never ask for it, but it was written by the legal department, you know, all law stuff for compliance. (effort to gain victim’s trust)
Attacker: Your username is AliceDxb, isn’t it? Corporate sys dept gave us your username and telephone, but, as smart as they are, not the password. See, without your password nobody can access your mail, even we at the datacenter. But we have to restore your mail, and we need access. You can be sure we will not use your password for anything else, well, we will forget it.” (smiling )
Alice: “Well, it’s not so secret (also smiling! It’s amazing…), my password is xxxxxx”
Attacker: “Thank you very much, Ma’am. We will restore your mail in a few minutes” Alice: “But no mail is lost, is it?”
Attacker: “Absolutely, Ma’am. You should not experience any problems, but do not hesitate to contact us just in case. You will find contact numbers on the Intranet”
Alice: “Thanks”
Attacker: “Goodbye” 
You see above example in a few minutes a hacker is able to get information that might have taken him days to get by capturing traffic and cracking the password. So, Social engineering is hacker that depends for getting needed information from a person rather than breaking into a system. It is much easier to gain information by social engineering than by technical methods.

People are usually the weakest link in the security chain. A successful defense depends on having good policies in place and teaching employees to follow the policies. Social engineering is the hardest form of attack to defend against because a company can’t protect itself with hardware or software alone and social engineering concentrates on the weakest link of the computer security chain.

One of the essential tools used for social engineering is a good memory for gathered facts.
Social Engineering can be broken into two common types:
·      Human-based: Human-based social engineering refers to person-to-person interaction to retrieve the desired information. An example is calling the help desk and trying to find out a password.
·      Computer-based: Computer-based social engineering refers to having computer software that attempts to retrieve the desired information. An example is sending a user an e-mail and asking them to reenter a password in a web page to confirm it. This social-engineering attack is also known as phishing.

Many example of Social Engineering is share with you in my next coming article. So, continue reading TRICKSLK.INFO.
Note: This is illegal and is for educational purpose only. Any loss/damage happening will not be in any way our responsibility.