1/16/2014

Certified Ethical Hacker (CEH) v.8 [PDF]

ebook ေတြမရွယ္ျဖစ္တာ ေတာ္ေတာ္ၾကာပါျပီ။ ကြ်န္ေတာ္ hackingsec ကေန RAR ဖုိင္တစ္ခုတည္း 100 MB ေက်ာ္တယ္။ ဆြဲတာ ျပီးလည္းျပီးေရာ ဖုိင္ကအယ္ရာတက္တာနဲ႔စိတ္ေလသြားတယ္။ အခု link က dropbox ကေန part အလုိက္ဆုိေတာ့ အဆင္ေျပမယ္ထင္ပါတယ္။ ကြ်န္ေတာ္လည္း ကြန္ေကာင္းရင္ျပန္ဆြဲရအုံးမယ္။ လူခ်င္သူမ်ားဆြဲလုိ႔ရေအာင္ ျပန္ရွယ္ေပးတဲ့သေဘာပါပဲ။
    CEH v8 Labs Module 00
    CEH v8 Labs Module 02 Footprinting and Reconnaissance
    CEH v8 Labs Module 03 Scanning Networks
    CEH v8 Labs Module 04 Enumeration
    CEH v8 Labs Module 05 System Hacking
    CEH v8 Labs Module 06 Trojans and Backdoors
    CEH v8 Labs Module 07 Viruses and Worms
    CEH v8 Labs Module 08 Sniffers
    CEH v8 Labs Module 09 Social Engineering
    CEH v8 Labs Module 10 Denial of Service
    CEH v8 Labs Module 11 Session Hijacking
    CEH v8 Labs Module 12 Hacking Webservers
    CEH v8 Labs Module 13 Hacking Web Applications
    CEH v8 Labs Module 14 SQL Injection
    CEH v8 Labs Module 15 Hacking Wireless Networks
    CEHv8 Module 16 Hacking Mobile Platforms
    CEHv8 Module 17 Evading IDS, Firewalls, and Honeypots
    CEHv8 Module 18 Buffer Overflow
    CEHv8 Module 19 Cryptography
    CEHv8 Module 20 Penetration Testing
    CEHv8 References
      Download All Parts
      password= http://www.hackingarticles.in
      All Credit to: http://techgator.org/download-link-of-certified-ethical-hackercehv8-slides/
      Special Thanks: http://www.itheinzin.blogspot.com/
      Read more »

      1/15/2014

      Kali Linux 1.0.6 with LUKS Released

      Kali ကခုဆုိ ဗားရွင္းအသစ္တစ္ခုကုိထပ္မံ Release လုပ္ခဲ့ျပန္ပါျပီ။ Kernel Version 3.12 နဲ႔အတူ Feature အသစ္ Emergency Self-Destruction LUKS ကုိလည္းေပါင္းထည့္ထားပါတယ္။ ေနာက္ထပ္ Tool အသစ္ေတြကုိေတာ့ ထပ္ေပါင္းထားျခင္းမရွိဘူးလုိ႔ဆုိပါတယ္။ အရင္ဗားရွင္း သြင္းထားျပီးသားသူေတြကေတာ့ ေနာက္ထပ္ေဒါင္းစရာမလုိေတာ့ပါဘူး။ ေျပာသာေျပာရတာ ကုိယ္ေတြကေတာ့ ျပန္ေဒါင္းရမယ့္ကိန္းပဲ။ :D အေသးစိတ္ကုိ Official Site မွာေလ့လာႏုိင္ပါတယ္။

      [Download]
      Read more »

      1/12/2014

      DAVOSET [DDoS attacks Perl Script]

      Windows သမားေတြကေတာ့ ထုံးစံအတုိင္း Perl ကုိသြင္းထားဖုိ႔လုိပါမယ့္။ BT/Kali မွာဆုိရင္ေတာ့ တန္းျပီး Run ရုံပါပဲ။ Usage ကုိလည္း readme.txt မွာဖတ္ၾကည့္ရင္ နားလည္သြားပါမယ္။ အေသးစိတ္ကုိေတာ့ မူရင္း link မွာပဲေသခ်ာဖတ္လုိ႔ရပါတယ္။

      [Download]
      Read more »

      1/09/2014

      Sandcat [The Pen Tester's Browser]

      ခုရက္ပုိင္း ကြ်န္ေတာ္ဆီမွာ Conection က်ေနတာမ်ားေတာ့ အျမန္ဆုံး Browser ဆုိျပီး Google မွာရွာၾကည့္တာ Chrome ကုိညြန္းတာေတြ႕ခဲ့တယ္။ ဟုတ္ခ်င္ဟုတ္မွာေပါ့ေလ။ ကြ်န္ေတာ္ကေတာ့ Firefox ကမွ ပုိအဆင္ေျပသလုိပဲ။ ဒါနဲ႔ ဒီ Browser ကုိပဲရွာေဒါင္းလုိက္တယ္။ ဟီး။ သူကေတာ့ pen-testing အတြက္ပါ။ XSS Attack အတြက္လည္းကူညီေပးပါလိမ့္မယ္။ www.faccebook.com ကုိေခၚလုိက္ရင္ တစ္ခါတည္း browser, source, resources, log ဆုိျပီးၾကည့္ႏုိင္တယ္။ ကြ်န္ေတာ္ကေတာ့ ကြန္ေလးေနရင္ အဆင္ေျပလုိေျပႏုိင္ေကာင္းပါရဲဆုိျပီး စမ္းၾကည့္တာပါ။ Windows ကုိသာ support လုပ္ပါတယ္။ BT/Kali သမားဆုိရင္ေတာ့ စိတ္ပ်က္စရာပါပဲ။

      [Screenshot]

      [Download]
      Read more »

      1/08/2014

      Basic Phishing Tutorial

      Phishing ဆုိတာလည္း ကေလးအထာလုိ႔ ဆုိႏုိင္ေပမယ့္ ဘာမွမသိမနားလည္တဲ့သူေတြအတြက္ေတာ့ ဟက္ကာေတြပစ္မွတ္ထားႏုိင္တဲ့နည္းတစ္ခုပါပဲ။ ဒီ Tutorial မွာ Phishing page တစ္ခုဘယ္လုိ လုပ္မလဲဆုိတာကုိ ေရးသြားပါမယ္။

      Requirement:
      နမူနာ Phishing page (Facebook login page, Gmail login page and so on)
      Free Hosting Site (Bytehost, 000webhost etc)

      Phishing Page အတြက္ ကုိယ္က Facebook အတြက္လုပ္ခ်င္တယ္ဆုိရင္ facebook.com ကုိသြားျပီး 
      view source ကေန နမူနာ code ေတြကုိ save ထားေပါ့။ .html နဲ႔သိမ္းပါ။ မိမိႏွစ္သက္ရာကုိ စိတ္ကူးရွိသေလာက္ အက်ယ္ခ်ဲျပီး သိေစသတည္း။ :D ကုိယ္က သူမ်ားေတြရုိက္ထည့္သမွ် pass ေတြကုိပါခုိးခ်င္တာဆုိရင္ေတာ့ အဲဒီ code ေတြထဲမွာ action=post ကုိ action=get ဘာညာျပင္ေပးဖုိ႔ လုိပါလိမ့္မယ္။ မသိမနားလည္တဲ့သူေတြကုိ မဟုတ္တဲ့ေနရာမွာ  ဒီနည္းနဲ႔မလုပ္ဖုိ႔ ေျပာခ်င္ပါတယ္။  ထားပါေတာ့။ ကြ်န္ေတာ္ကေတာ့ Basic ကုိပဲေျပာမွာဆုိေတာ့ အေသးစိတ္မေျပာျပေတာ့ဘူး။

      Hosting Site အတြက္ကေတာ့ ကြ်န္ေတာ္က bytehost မွာပဲလုပ္လုိက္ပါတယ္။ အေကာင့္တစ္ခု Sigup လုပ္ျပီး index.html ေနရာမွာ ကုိယ္လုိခ်င္တဲ့ index.html ကုိ upload တင္လုိက္ရုံပါပဲ။ 
      Account ရရင္ cpanel ကေန Online File Manager ကုိသြားပါ။ အဲဒီကေနမွ htdocs ဆုိတဲ့ Directory ကုိသြားပါ။ index2.html ဆုိတာရွိပါမယ္။ အဲဒီဖုိင္ကုိ edit လုပ္ရင္လုပ္၊ မဟုတ္ရင္လည္း အဲဒါကုိဖ်က္ျပီး ကုိယ္လုပ္ထားတဲ့ index.html ဖုိင္ကုိ တင္ရုံပါပဲ။ အျခား hosting site ေတြမွာပုံစံကြဲလြဲႏုိင္ပါတယ္။ File Manager တုိ႔၊ ဘာညာ ဒါေပမယ့္ သေဘာတရားကေတာ့ အတူတူပါပဲ။ စမ္းလုပ္ၾကည့္ရင္ လုပ္တတ္သြားမွာပါ။ ဒါေၾကာင့္ Detail မေျပာေတာ့ဘူး။
      ေအာက္ကပုံအတုိင္း upload တင္လုိက္ျပီ။ ဒါဆုိ ကုိယ္လုပ္ထားတဲ့ domain name ကေနၾကည့္လုိ႔ရပါျပီ။ In my case, http://lotusblack.byethost22.com/ ပါ။

      သာမန္ Phishing Page တစ္ခုလုပ္ရတာ ဘာမွမခက္ပါဘူး။ ခက္တာက အဲဒါကုိ Victim ဆီကုိ ေအာင္ေအာင္ျမင္ျမင္ ဘယ္လုိ႔လုပ္ရမလဲဆုိတာပါပဲ။ဒီေနရာမွာေတာ့ သင့္ရဲ႕ ဖန္တီးႏုိင္စြမ္း၊ SE Skill ေတြေပၚမွာ မူတည္သြားပါလိမ့္မယ္။ ဒီပုိ႔စ္မွာဆုိ ကြ်န္ေတာ္က www.mail4u.com.mm ရဲ႕ page ကုိ copy ကူးျပီးလုပ္ထားတာပါ။ page ကလည္း မပီျပင္ပါဘူး။ ပုံေတြကလည္းမေသသပ္ဘူး။ ေနာက္ url ကလည္း သိသာၾကီး။ :D တကယ္ဆုိ ဒီထက္ ပုိျပီး ယုံစရာျဖစ္ေအာင္ အမ်ားၾကီးလုပ္သင့္တာေပါ့ေနာ္။

      ေနာက္ free hosting site ေတြမွာ Phishing page ေတြတင္ရင္ ဘန္းပါတယ္။ ေျပာရရင္ အမ်ားၾကီးပါပဲဗ်ာ။ ဒီေလာက္ဆုိရင္ Phishing Page တစ္ခုကုိ ဘယ္လုိလုပ္ရသလဲဆုိတာ သိသြားျပီလုိ႔ ယူဆလုိက္ပါမယ္။ :)





      Read more »

      1/01/2014

      Metasploit Penetration Testing Cookbook, Second Edition [PDF]


      Metasploit Penetration Testing Cookbook, Second Edition
      English | 320 pages | ISBN-10: 1782166785 | PDF | 6.88 MB

      Amazon တုိ႔မွာဆုိ ပုိက္ပုိက္ေပးရမယ္ဗ်။ madleets ကေန မ,လာတာ။ အခုက Second Edition ပါ။ ဘာေတြ အသစ္ပါလာသလဲသိခ်င္ရင္ ေဒါင္းေပေတာ့ဗ်ာ။ 

      [Download] [Mirror]
      Read more »

      Egyptian Team Shell Toolkit [Priv8]

      ေဒါင္းျပီး စမ္းၾကည့္ေပါ့ဗ်ာ။ အထဲမွာေတာ့ Tool ေတြေတာ္ေတာ္စုံတယ္။ Virustotal မွာ အေကာင္ 15 ေကာင္ထိေတြ႕ထားတယ္။ Use your own risk ေပါ့ဗ်ာ။ ဟီး ဘာေတြပါသလဲဆုိေတာ့က

      Tool Includes:
      Shells
      Sql Injection Tools
      Local Root Exploits
      Symlinks\Bypass
      Vulnerabily Scanners
      Script/Windows Tools
      Trojans
      Windows Scanners
      Encryptation
      Crypters
      Tutoriais
      Sistemas

      [Download]
      Virustotal:  https://www.virustotal.com/en/file/7647302da5e5064bac9e337d2dbdf5d4ec54b974859f3e283e220aaaa078f0ae/analysis/
      Read more »

      IP-Digger v4 by Freak Coderz

      IP-Digger version အသစ္မွာ အရင္ဗားရွင္းက Function ေတြအျပင္ ေနာက္ထပ္ function အသစ္ေတြထပ္ေပါင္းထားပါတယ္။ Usage ကုိ readme file မွာဖတ္ႏုိင္ပါတယ္။ Happy New Year!! All my blog readers.

      Tool Name :- IP-Digger v4.0 The WeB Xploit3r The Next Level
      Coded by :- Manoj Nath aka Silent Hacker and Gurender Singh aka Un_NoN

      Features of IP - Digger
      All features of V1 , 2 , 3 + Additional features :)
      New Features Added :)

      17 - FTP Brute Force                       [+] New Feature Added
      18 - Admin Panel Finder                    [+] New Feature Added

       Website Vulnerability Scanning To0ls
      --------------------------------------------
      19 - Joomla Vulnerability Scanner          [+] New Feature Added
      20 - Wordpress Vulnerability Scanner       [+] New Feature Added
      21 - UniScan -> Web Vulnerability Scanner  [+] New Feature Added
      --------------------------------------------
      22 - Uploaded Shell Finder ( Website )     [+] New Feature Added
      --------------------------------------------

       Web-Backd0or ( Weevely )
      --------------------------------------------
      23 - Web Backd0or Generator ( Weevely )
      24 - Web Backd0or Server Connect0r ( Weevely )

       Other Hacking To0lKit
      --------------------------------------------
      25 - W3bSploit T0olkit by 0x0ptim0us

      [Download] [Mirror]
      Vitustotal: https://www.virustotal.com/en/file/3589df3e59471da5baab55296f64ea50dd704c10350c6e2a2a7e327c3d0e8910/analysis/

      [Screenshot]


      Read more »

      12/31/2013

      myBB in Localhost

      myBB ကုိ localhost မွာ အင္စေတာ့လုပ္နည္းပါ။ ဘာမွမခက္ပါဘူး။ လုိအပ္တဲ့ Tool ေတြကုိအရင္သြင္းသြားရပါမယ္။ Read my previous post.  ေနာက္ myBB package ကုိ Official Site ကေနေဒါင္းထားဖုိ႔လုိပါလိမ့္မယ္။ က်န္တာကုိေတာ့ မရွင္းျပေတာ့ပါဘူး။ ပုံေလးေတြကုိၾကည့္ျပီး လုပ္တတ္သြားမယ္လုိ႔ ထင္ပါတယ္။















      Read more »

      Hash Code Cracker 1.2.1

      Breakthesecurity.com ကေန ထုတ္ထားတာ။ Ethical Hacking အတြက္ျဖစ္ပါသတဲ့။ md5 Password ေတြကုိ Crack ႏုိင္မယ္။ MD5 Hash ေတြကုိလည္း Generate လုပ္ေပးႏုိင္မယ္။ အျခား ဘာညာ function ေတြလည္းပါေသးတယ္။ ဟီး။

      [Download]
      Read more »

      12/30/2013

      Dork Searcher

      Dork ေတြ Google မွာ Typing လုပ္ျပီး ရွာမေနနဲ႕ေတာ့ လုိခ်င္တာကုိ select လုပ္ျပီး ရွာရုံပဲ။ အဓိက ရွာေပးမွာက SQLi Vul ျဖစ္ေနတဲ့ဆုိဒ္ေတြကုိ ရွာေပးမွာပါ။ ကုိယ့္ဆီမွာ Dork list ေတြရွိေနရင္လည္း ထပ္ေပါင္းလုိ႔ ရေသးတယ္။

      [Download]

      Read more »

      12/27/2013

      Node Zero [Pen-testing Distro]

      Ubuntu-based ျဖစ္တဲ့ pen-testing Distro တစ္ခုပါ။ Kernel 2.6 ဆုိေတာ့ ေတာ္ေတာ္ေလး ေဟာင္းေနပါျပီ။ GUI Interface ကေတာ့ မဆုိးဘူးေျပာရမယ္။ ထူးျခားတာဆုိလုိ႔ Vitual Machine ပါတာရယ္။ Wine ကုိတစ္ခါတည္းသြင္းထားတာရယ္၊ Windows Desktop လုိျပင္ဆင္ထားတာရယ္ ဒါပဲေတြ႕တယ္။ Pen-testing Distro ဆုိလုိ႔ ေဒါင္းျပီး စမ္းၾကည့္ရုံပါ။ ကြ်န္ေတာ္ကေတာ့ မၾကိဳက္ပါဘူး။ Pen-testing Tool ေတြကေတာ့ ေတာ္ေတာ္မ်ားမ်ားပါတယ္။ Tor လည္းပါတယ္။ က်န္တာကေတာ့ သိပ္ထူးျခားတာမေတြ႕ပါဘူး။ ပုိ႔စ္တစ္္ခုေရးမလုိ႔ ေဒါင္းတာ ၁ လေလာက္ေဒါင္းလုိက္ရတယ္။ ေအာက္မွာ Screenshot ေတြကုိသာၾကည့္ျပီး အားနာပါးနာနဲ႔ Comment ေလးတစ္ေၾကာင္းပဲ ေရးသြားခဲ့ဗ်ာ။ :)

      [Screenshot]






      [Download]
      Read more »

      12/26/2013

      InnoExtractor v4.4.3.135 [Unpacker and decompiler for Inno Setup installers]

      InnoExtractor ဆုိတာကေတာ့ Tool တစ္ခုရဲ႕အထဲကဖုိင္ေတြကုိ ၾကည့္ႏုိင္တဲ့ဟာပါပဲ။ ဒီေကာင္နဲ႔ Software တစ္ခုရဲ႕ အထဲမွာရွိတဲ့ဖုိင္ေတြကုိ ၾကည့္လုိ႔ရမွာပါ။ မိမိလုိခ်င္တဲ့ေနရာမွာ စိတ္ကူးေပါက္ရာသုံးႏုိင္ပါတယ္။ Use you Brain xD

      Features:
      - Simple and friendly GUI.
      - Open installers into the application with only drag and drop executables from Windows Explorer.
      - Explore the internal content (files and more) of the installer.
      - Extract the embedded files and script to a local folder, to a zip package or to a self-extracting module (portable).
      - Decompiles the "CompiledCode.bin" file of the Installer to get the assembly code, corresponding to the "Code" script section (for advanced users only).
      - Open internal files of the installer into the same application.
      - Perform file searches by keyword.
      - Input panel, that allows you to enter a valid password to extract encrypted installers.
      - Properties panel to see advanced information about the installer.
      - History for recently opened installer.
      - Other miscellaneous options.
      - Support older and latest versions of Inno Setup.
      - Support older and latest versions of InnoUnp.
      - Full Unicode support.
      - Application available in multiple languages.
      - Much more!


      Download: Mediafire Solidfiles
      Read more »

      iOS 7.x Jailbreak [evasi0n7]

        
      Blog ေတြထဲမွာ ပလူပ်ံေနတာပဲ။ iOS7 ကုိ Jailbreak လုပ္လုိ႔ရတဲ့အေၾကာင္း။ ကြ်န္ေတာ္ကေတာ့ iDevice မဟုတ္ေတာ့ သိပ္ဂရုမစုိက္မိပါဘူးဗ်ာ။ ဒါေပမယ့္ iDevice ပရိတ္သတ္ေတြမနည္းဘူးဗ်။ Hacking Tool ေတြခ်ည္းတင္ေနတဲ့ႏုိင္ငံျခား ဘေလာ့တစ္ခုမွာေတြ႕လုိ ျပန္ရွယ္လုိက္တာပါ။ evasi0n7 ဆုိတာက နာမည္ၾကီး Jailbreak လုပ္တဲ့အဖြဲ႕ျဖစ္ပါတယ္။ ဒါကေတာ့ ခရစ္စမစ္အမွီလက္ေဆာင္လုိ႔ဆုိပါတယ္။ ဒီ Tool ကုိသုံးဖုိ႔ ေအာက္က Requirement ရွိရပါမယ္။

      A computer, running Windows (XP minimum), Mac OS X (10.6 minimum) or Linux (x86 / x86_64)
      iTunes installed if you’re running Windows
      An iPhone, iPad or iPod running iOS 7.0 through 7.0.4 (you may check in Settings / General / About => Version)
      A USB cable to connect the device to the computer

      evasi0n7 အေနနဲ႔ iOS 7, iOS 7.0.1, iOS 7.0.2, iOS 7.0.3, iOS 7.0.4 စတဲ့ iOS ေတြကုိ Support လုပ္ပါမယ္။ သူနဲ႔ဆက္ႏြယ္တဲ့ ေအာက္ပါ Device ေတြအားလုံး အက်ဳံးဝင္ပါတယ္။

      • iPhone 5s, iPhone 5c, iPhone 5, iPhone 4S, iPhone 4, iPhone 3GS
      • iPad Air, iPad 4, iPad 3, iPad 2
      • Retina iPad mini, iPad mini
      • iPod touch 5G
       [Download]
       
      Read more »