Saturday, April 2, 2011


If you are a business owner, then you must know how important it is for you to have your own website. You can use it to be able to reach as many target customers as possible. After all, they are located in almost many parts of the world. You can display all your products and services in your website. But do you know that they can be a great area for hackers to play on? So how can you protect your website against hacking?

1. Protect your files with passwords. Surely, your website will contain scripts, database, and files that are not meant to be shared publicly but for perhaps the search engine bots. To avoid having anyone getting hold of them, it may be ideal to protect them with password. However, you have to make sure that these are very hard to decipher. This is because they can simply make use of a password-deciphering software. You can combine alphanumeric characters and exhaust all the character limits as much as possible.

2. Secure your e-mail address. There may be times when you will be receiving an e-mail address courtesy of your online business form. There are even others who will send a message directly into your mailbox. This may mean that spammers have got hold of your contact information perhaps in the Web or from someone else. To prevent this, you can make use of software that will split your e-mail address. It will then very hard for spamming software to read. You can also just add an E-mail Us link into your website or an image which can be clicked and allow your customers to send an e-mail right away. There�s no need to reveal the e-mail address.

3. Don�t leave e-mail addresses anywhere. Perhaps you�re thinking of marketing your website in forums and other public online networks. This is okay; however, you have to be very cautious. Hackers and spammers are very much interested of your e-mail address. You can make use of a bogus one, and simply add a link of your website in the signature.

4. Secure your source code. There are hackers who are interested in getting your source code to either destroy it or to build a website clone. That�s why it is very important that you can protect it against such individuals. You can make use of scripts that will allow your source code to remain hidden to Internet users. Or you can simply make use of external CSS sheets as well as files for Javascript.

5. Check for software patches. If you have been using some software in building or maintaining your website, make sure that you constantly update all of your files. This may be because the older ones can no longer protect your website from hackers and spammers.

6. Sign up for updates. Majority of the product and software updates may only be announced in their respective websites. This is to encourage their customers to continuously be up-to-date too of any new products that they are currently introducing into the market. To avoid the hassle, sign up using one secure e-mail address in all of their newsletters. If you receive any updates, make sure you take time in reading them.

7. Add a robot.txt. This is a special instruction you will give to search engines who may be visiting your webpages. You can instruct them to only index those files that are meant for users. You can also direct them to not index any that are only meant for webmasters. These may include files and images.

8. Check the permissions you may have set for your uploaded files. This is to prevent any hacker from getting access into your important and confidential files. You can confirm it by selecting CHMOD for your files located in the web hosting server. Otherwise, if you aren�t sure, then you can simply verify it from your webmaster.

9. Take away old or unnecessary files. It�s normal for search engines to keep files from your website, especially if they are being indexed. However, if you remove them from the server, then no one can access them anymore. It will not be obtainable for hackers and spammers.

10. Know your server. Your server is very essential as you basically keep all of your files there, and it will cause your website to run smoothly. Intruders, on the other hand, can add virus or malware into your system, thereby causing damage into your website. If you are running it on your own, you must know your server properly. This way, you can set the right security and permission level for your site.


Now a days everybody uses Email accounts and social networking like Facebook , Twitter etc . . Lots of personal Information is associated with such social networking sites .. So this is important to protect such data from Hackers . . Because Hackers ( Black Hat Hackers ) always try to get others important data , information and use it for wrong purpose . . So please always try to be safe from hackers . .

Below i am telling u simple steps which you should follow :-


Never share your password to anyone.

1) Don't use password as your nick name, phone no. or pet names.
2) Use the combination of lower case, uper case, numbers and special characters for passwords.
3) Never click on any suspected link comes in a mail from unknown sender
4) Never give your passwords to any 3rd party websites for any service.
5) Use different passwords for different accounts.
6) Check the website url every time before login. EX: check url to be



before login to face account. Never login to website such as


( Most Important )
7) Use secondary email address and mobile phone numbers with secret questions for account recovery.
8) Never use any javascript code in url while login to any of your email or any other website account. It may be a cookie stealer script.
9) use latest antivirus and antimalware softwares with firewall on.

These are some things which you should follow for safe surfing on Internet

I hope you like it . . Any queries just contact me anytime !!

Thanks . .
 
Posted By Sumit Ojha....
 
follow this article and secure your wireless network! It is imperative for everyone who has their own wireless network in a home or small business setting to take the following steps to ensure the well being of the network.
  1. Give your router an admin password - Learn how to change the admin password for your router by reading the manual or checking the manufacturer's support website.
  2. Change your routers SSID - Your router's SSID is like its name. If you set this to default, your neighbour might be accidentally using your wireless connection or you might accidentally use your neighbour's connection (which is a crime). You want to be sure that you can distinctly identify your router and prevent others from accidentally connecting to it, which will make your Internet slower.
  3. Use at least WPA2 Encryption - Not using encryption is like yelling your credit card number out loud. Anyone paying attention and snooping in on your wireless network can intercept all data that goes between the wireless router and the computer. Make sure you use at least WPA2 encryption. If your router doesn't have a WPA2 option then you might want to upgrade to a newer router or check for a firmware update.
  4. Use a hard to break pre-shared key - Make sure it is 63 characters long and make up of random letters, number and characters. Since you don't have to remember anything (you only need to set this on your router and computer/console once) A great way to generate good passwords is to use the GRC Passwords Page. It generates a key for you automatically. I recommend you use WPA2 and use a 63 character random ASCII string. Remember, once you use the key on your router, you'll need it for your computer too, so making a text file of the key might be helpful.
  5. Disable SSID Broadcast - Once your set up your router and initiate the wireless network, it is a good idea to turn off the SSID so people might not get tempted to try and use your network.
  6. Enable MAC Address Filtering - MAC in this case means Media Access Control, not a Mac. It allows you to specify the machines (i.e. only your machine) that can connect to your network.
  7. Try to broadcast only in Wireless G - If possible try and broadcast only on a 802.11 G band so that people with 802.11 B hardware will not be able to connect. If you have a laptop or device that needs 802.11 B, then obviously this isn't an option.
  8. Make sure to turn off any extended range functionality if living in a small house. Extended range mode will only make your router send out more powerful signals and make your network susceptible to attacks.
  9. Change Miscellaneous settings - Disable features such as gaming mode, and enable features such as discard PING from WAN side. This will prevent an attacker from compromising your network by repeatedly pinging your router to death.
  10. Update Update Update - If you haven't ever updated your router's firmware, then it's high time you do so. Make sure you stay informed about the latest developments in the wireless world too.
Posted By Sumit Ojha.....



Every one wants to create a virus but virus creation is not a child's play. It needs a good skill in programming and knowledge about system resources. Today i am going to post about a virus creating tool. This tool is Virus Matic 2010 or in short V-Maker. You don't need to know any thing. Only select the option you want and it will create a virus for you.

Main Feature of V-Maker

You can create your own prank files/viruses with ease by V-Maker.
  1. Disable Mouse and Keyboard
  2. Disable Regedit
  3. Delete System32
  4. Block Site
  5. Disable Task Manager
  6. Take Screen Shot Of Victim  PC
  7. Message Box (When User Click on Virus)
  8. Automatically Download Start (When User click on virus download start automatic)
  9. USB Spread
Download Here:

Friday, April 1, 2011

First of all we need to know that what is ethical hacker?


An ethical hacker is a computer and network expert who attacks a security system on behalf of its owners, seeking vulnerabilities that a malicious hacker could exploit. To test a security system, ethical hackers use the same methods as their less principled counterparts, but report problems instead of taking advantage of them. Ethical hacking is also known as penetration testing, intrusion testing and red teaming. An ethical hacker is sometimes called a white hat, a term that comes from old Western movies, where the "good guy" wore a white hat and the "bad guy" wore a black hat. 
One of the first examples of ethical hackers at work was in the 1970s, when the United States government used groups of experts called red teams to hack its own computer systems. According to Ed Skoudis, Vice President of Security Strategy for Predictive Systems' Global Integrity consulting practice, ethical hacking has continued to grow in an otherwise lackluster IT industry, and is becoming increasingly common outside the government and technology sectors where it began. Many large companies, such as IBM, maintain employee teams of ethical hackers. 
In a similar but distinct category, a hacktivist is more of a vigilante: detecting, sometimes reporting (and sometimes exploiting) security vulnerabilities as a form of social activism. 

And now what is ethical hacking?
Ethical hacking, often performed by white hats or skilled computer experts, is the use of programming skills to determine vulnerabilities in computer systems. While the non-ethical hacker or black hat exploits these vulnerabilities for mischief, personal gain or other reasons, the ethical hacker evaluates them, points them out, and may suggest changes to systems that make them less likely to be penetrated by black hats. White hats can work in a variety of ways. Many companies utilize ethical hacking services from consultants or full-time employees to keep their systems and information as secure as possible. 
The work of ethical hacking is still considered hacking because it uses knowledge of computer systems in an attempt to in some way penetrate them or crash them. This work is ethical because it is performed to increase the safety of the computer systems. It’s reasoned that if a white hat can somehow break the security protocols of a system, so can a black hat. Thus, the goal of ethical hacking is to determine how to break in or create mischief with the present programs running, but only at the request of the company that owns the system and specifically to prevent others from attacking it.
People enter the field of ethical hacking in a variety of ways. Many people are very computer savvy and many, but not all, have an educational background in computer science. In some instances, the white hat has gained his or her experience by first being a black hat.
If black hat hacking was at a sufficiently criminal level, the black hat turned white hat may have served jail time before resuming a career in a more productive and positive way as an ethical hacker. The computer world is peopled with former black hats, who now hold ethical hacking jobs. Conversely, some white hats, such as Steve Wozniak, never committed any illegal acts, but simply possess the know-how and skills to analyze problems with any computer system.
With increasing use of the Internet and concerns about its security, especially when it comes to things like consumer information or private medical details, there is considerable need for computer experts to work in ethical hacking. Even sites owned by organizations like the US government have been hacked in the past, and concern about information theft remains incredibly high. Designing impenetrable systems or identifying the current weaknesses of a system are vital parts of keeping the Internet safe and information private, and even with the present legion of ethical hackers that perform this work, there is still more work to do.



The above article posted by Mr. Sachin Chauhan Ics
Hi guys many of us want to hack our friend pc. so we need to get their IP adress in order to hack him.once if we got his IP adress we can easily hack his pc.so in this post i am telling how to get the IP adress of friend while chatting.




IP is an address used by a person to connect to the internet. An Internet Protocol address also mean the identity of the person in the World Wide Web. Internet Protocol also has the information of location where the person is stays and connects to internet. If the person who connects to internet doesn’t use proxy, we can track the location of her or his country by knowing his IP (Internet Protocol Address). Internet Protocol Address sometime can also track the city where the person location is. 

Sometime when we are chatting with a friend via Private Message or Instant Message (PM or IM), we curious where the place of our friend is. If you using official yahoo messenger it is an easiest way to find your friend Internet Protocol address. Please read my tutorial below carefully and I guarantee you will be able to track and find the Internet Protocol Address of your friend.

First step we must to do is get a PM or IM with your friend user name or id. Then try to send a file (picture, mp3, etc), then wait until your friend accepted your file and your file begin transferred to him. If your and your friend connection has a huge bandwidth, I suggest you, to send a bigger byte of file. You also don’t have to do this step if you have their web cam yahoo messenger. After you done this thing, do the next step below (you can do this step before send a file).

Go to the command prompt application. If you don’t understand just follow this step (windows XP):

Start >> Run >> cmd >> Enter

Or

Start >> Programs >> Accessories >> Command Prompt

You will see a windows command prompt appear. Then write a command “netstat –n” or netstat –a” and press enter. Please note that the symbol “ not included when you type that command. You will see information under Active Connections list of Proto, Local Address, Foreign Address and State.

Active Connections indicate the connections being connected to your computer. Proto show the protocol you use to. Local Address refers to Internet Protocol in you LAN connection. Foreign Address indicates the Internet Protocol connection that connect to you and the port they used.

Now you just to seek a remote port that used by foreign address. Usually remote port 80 or 81 is used to transfer a file. Remote Port 5050 used for private message. And 5100 used for web cam. And Remote Port 5000 or 5001 used for voice chat.
The IP address of PM not the real IP of your friend. It belongs to yahoo server IP. But if you send a file or receive a web cam you will be get a real IP of your friend address because yahoo use Peer to Peer connection to service this utility.

sharp ip getter

If you want a better way to get Internet Protocol of your friend, there are many software that designed and developed to get IP address. One of this software I ever tested and worked is Sharp IP Getter. We do not need to send a file or get a web cam to know the Internet Protocol of your friend. We only need have Private Message.

about sharp ip getter:

Sharp IP Getter is an application that has a purpose to find Internet Protocol of Yahoo Messenger through Instant Message Service. Whenever you chat with people in Yahoo Messenger Private Message or Instant Message, Sharp IP Getter will help you to find the real IP address of the current people or user that being chat with you. Sharp IP (Internet Protocol) Getter was developed and created by Www.Sharp-Soft.Net.

How to find IP address from Yahoo Messenger chat? How to find ip address of a person in yahoo messenger? how to get ip in yahoo messenger? how to find ip address from instant message in yahoo messenger?. Those all questions might be ask from people who wanna know how to get ip address from yahoo messenger.

Actually there is a simple steps using command prompt windows to find ip address from chat in yahoo messenger, but this is not the good time We give you that such ways, to get ip of Y!M, because without that steps, with Sharp IP Getter you already knew how to look for the IP address of a user or people in yahoo messenger.

How to use Sharp IP Getter:

Just run the software and instantly you will see a list of IP address in the software. That IP address should be the one / people who chat with you. If you are unable to see the IP, make sure you send a file or image aka photo to the target and the IP address of the target will rise at Sharp IP Getter.



The above article posted by Mr. Sachin Chauhan Ics
Yeah its true !!!! You can start recieving checks weekly . Simply join us and start your earnigs!!!! 
U CAN JOIN US:


* If u are student
* If u are graduate
* If u are jobless
* If u are profetional
* If u are web developer
* If u want to start your buissness.
 


No basic skill or knowledge is required..we will give u traning and certificate and many more stuffs..



Stop googling the ways of earnings..............Just call me and c how your life change.....You can earn upto 80000 per month + 6000 per week (fix).

Just pick you cellphone and make a call......


Mukesh Tiwari

9200966216 / 09247991493



Sachin Chauhan
9958489879

This is weekly income of Gurkirat singh ..he did'nt do anything then also earning!!!!!!


Tuesday, March 22, 2011


It is the most common type of Cyber crime being committed across the world. Hacking has been defined in section 66 of The Information Technology Act, 2000 as follows "whoever with the intent to cause or knowing that he is likely to cause wrongful loss or damage to the public or any person destroys or deletes or alters any information residing in a computer resource or
diminishes its value or utility or affects it injuriously by any means commits hacking".

Punishment for hacking under the above mentioned section is imprisonment for three years or fine which may extend Upto two lakh rupees or both. A Hacker is a person who breaks in or trespasses a computer system. Hackers are of different types ranging from code hackers to crackers to cyber punks to freaks. Some hackers just enjoy cracking systems and gaining access to them as an ordinary pastime; they do not desire to commit any further crime. Whether this itself would constitute a crime is a matter of fact. At most such a crime could be equated with criminal trespass.

Thursday, March 17, 2011

  You have high speed ADSL broadband at PC,but still facing low speed in IE (INTERNET EXPLORER )
so here are few steps that will help your to get better speed in IE
1. Click start > Run
2. Type regedit > Enter
3. Browse folder HKEY_CURRENT_USERSoftwarem*cro$oftWindowsCurrentVersion
InternetSettings
4. Right click @ windows right > New > DWORD
5. Type MaxConnectionsPerServer > you can set value (the more higher the no., the more good
speed you get, eg : 99)
6. Create another DWORD >type MaxConnectionsPer1_0Server
7. Then enter any higher values in that section
8. Then, restart IE … ur finished.
This Trick will increase your browsing speed as well as downloading speed.
Friends, all of us want to send fake mail with others mail id here i’m posting the method which is used to send the fake mail using the Simple Mail Transfer Protocol(SMTP)

SMTP is the protocol which is used to send mail over the internet.
When we login to our account and send a mail the smtp protocol will send it to the smtp server which will send it to the pop3 server and then it gets to the receiver email account.
The main bug in this system is that the SMTP server access dosen’t need any authentication, means when u want to send data to any of the email account you need not to provide the your identification or the email id and password you can just login with any email id and send email.
But the receiver has to give his e mail id and password as the pop3 server needs a authentication.
thus, using this bug even a leyman can send a fake mail with any user id and fool the receiver.
This kind of java script are already available on net so u can get it from any where.
Now the main crux here is that the mail can be trace and the ip can be known to the tracer, now a days terrorist are using such bugs to send email and may be traced. So please dont use this method for any destructive or negative purpose.

As per the indian laws it may be punishable to send fake mail via internet bus there is no such juridiction in law for sending fake mail through GPRS and this the loop hole.

So once you got the site from web for fake mail use it to send fake mail via GPRS and enjoy.
Want to Spoof a identity of caller,we have brought some intresting trick.

Call Forging is the trick by which you can spoof the identity of the
caller and misguide the caller.

By call forging the caller identity is spoofed and can be easily done
by the folllowing way.

This post is written for educational purpose and dont misuse it.

Basics of Call Forging

Firstly the voip is used to call via internet PC to a telephone.
In the VOIP there is a loop hole which allow a intruder to spoof
a call.

There are many website on the net which provide the facility of the
internet calling.

This website work as follows, first the call the source phone no. then
the destiation number and then bridge them together.

Here there is no authentication done by the website and server are
normally located in US and so tracing of the intruder is not possible.

Thus, the intruder logs on to this server and gives a wrong source number
and then place a call over internet which is actually a spoofed call
which shows wrong identity.

Also there a no laws regarding the call spoofing in India and so a intruder
if gets traced is easily backed by the loophole of no laws for it.

Thus, if you get calls from other numbers dont trust it they may be spoofed
calls.

This post is written only for awareness and for educational purpose.
MySpace: Since this site relies on Web mail to solicit and accept friends and the blog moderating functions have been known to have XSS vulnerabilities in the past, it is recommended that to use this site for CDC communications, it be done so from specially designated hardware off the CDC network following guidelines developed in conjunction with OCISO.

Facebook: Since this site allows blog posts and there is limited or no control over which of your friends appear on your home page, it is recommended that to use this site for CDC communications, it be done so from specially designated hardware off the CDC network following guidelines developed in conjunction with OCISO.

Twitter: An interesting site in terms of social networking in that comments and posts are allowed, but are limited to 140 characters with no HTML or JS allowed. Hyperlinks are allowed and are automatically converted to the actual HTML code by the system. Eg – http://www.cdc.gov becomes http://www.cdc.gov automatically. Comments are designed to be sent by SMS messaging, which is text based. Requests for followers come through email and can be accepted without Web mail. Whereas it does seem to be secure against XSS exploits, the site does rely on AJAX technologies and can be used to post links to malicious sites. In order to vet these links, they must be followed, which would put the system at risk. It is recommended that to use this site for CDC communications, it be done so from specially designated hardware off the CDC network following guidelines developed in conjunction with OCISO.

DailyStrength: This site relies on Web mail to solicit and accept friends, allows blog comments and has limited to no control over which of your friends show up on your main profile page. It is recommended that to use this site for CDC communications, it be done so from specially designated hardware off the CDC network following guidelines developed in conjunction with OCISO.

YouTube: This site allows comments on videos and has limited to no control over which of your friends show up on your main profile page. It is recommended that to use this site for CDC communications, it be done so from specially designated hardware off the CDC network following guidelines developed in conjunction with OCISO.

Flickr: This site allows comments and has limited to no control over which of your friends show up on your main profile page. It is recommended that to use this site for CDC communications, it be done so from specially designated hardware off the CDC network following guidelines developed in conjunction with OCISO
 

Caller ID Forging the practice of causing the telephone network to display a number on the recipient's caller ID display which is not that of the actual originating station; the term is commonly used to describe situations in which the motivation is considered nefarious by the speaker. Just as e-mail spoofing can make it appear that a message came from any e-mail address the sender chooses, caller ID forging can make a call appear to have come from any phone number the caller wishes. Because people are prone to assume a call is coming from the number (and hence, the associated person, or persons), this can call the service's value into question.

To use a typical service, a customer pays in advance for a PIN allowing them to make a call for a certain amount of minutes. To begin, the customer dials from any phone the toll free number given to them by the company and enters their PIN. They are then asked to enter the number they wish to call and the number they wish to appear on the caller ID. Once the "customer" selects the options, the call is then bridged and the person on the other end assumes someone else is calling them.

Many Caller ID forging service providers also allow customers to initiate spoofed calls from a web-based interface in addition to calling a toll free number and entering the ten digit number you want to display followed by the ten digit number you want to call. Some providers allow you to enter the name you would like to display along with the spoofed Caller ID number but in most parts of the United States for example, whatever name the local phone company has associated with the spoofed Caller ID number is the name that shows up on the Caller ID display.

Using a web-based spoofing form involves creating an account with a provider, logging in to their website and completing a form. Most companies require the following basic fields:

1: Source number 2: Destination number 3: Caller ID number

Once the user completes this form and clicks a button to initiate the call, the source number is first called. Once the source number line is picked up, the destination is then called and bridged together.

Some providers also offer the ability to record calls, change your voice and send SMS text messages.

Methods:

Caller ID is forged through a variety of methods and different technology. The most popular ways of spoofing Caller ID are through the use of Voice over IP or PRI lines.

Another method of spoofing is that of emulating the Bell 202 FSK signal. This method, informally called orange boxing, uses software that generates the audio signal which is then coupled to the telephone line during the call. The object is to deceive the called party into thinking that there is an incoming call waiting call from the spoofed number, when in fact there is no new incoming call. This technique often also involves an accomplice who may provide a secondary voice to complete the illusion of a call waiting call. Because the orange box cannot truly spoof incoming caller ID prior to answer, and relies to a certain extent on the guile of the caller, it is considered as much a social engineering technique as a technical hack.

Other methods include switch access to the SS7 network, and social engineering telephone company operators into placing calls for you from the desired phone number. Another method that is not used as often is VXML which was gaining popularity before VoIP took over.

History:

Many people do not realize that Caller ID Forging has been around since Caller ID was created. For over a decade Caller ID forging was used mainly by businesses with access to expensive PRI (Primary Rate Interface) telephone lines provided by local telephone carriers. A single PRI line can provided businesses with up to 23 telephone lines and all of these lines are capable of having unique telephone numbers. Caller ID forging, in it’s most basic form, was typically used by businesses to display one main telephone number on all outgoing calls, even though those calls were not really originating from those numbers.

In the early 2000’s phone hackers, also known as “phone phreaks” or “phreaks”, began using Orange boxing to attempt to spoof Caller ID. Orange boxing is done by using a device, usually special computer software, to send a series of tones down the line during the first few seconds of a phone call, attempting to emulate the Caller ID signal sent from the telephone office. Orange boxing is very crude and unreliable, as it has to be done within a short timeframe at the beginning of a call. Phone phreaks, without access to PRI lines or blind line services at the time, thought the technique was clever.

In late 2003 and early 2004 the same phone phreaks began to explore a relatively new platform for developing voice applications, known as VoiceXML or VXML, which was offered by companies such as Voxeo.

In 2005 a handful of new sites allowing you to spoof your Caller ID were quietly launched. Some of the sites were PiPhone.com, CallNotes.net, SecretCalls.net, StayUnknown.com, SpoofTech.com, SpoofTel.com, and SpoofCard.com.

Towards the end of May, another site, TheZeroGroup.com, launched offering Caller ID spoofing, amongst it's other phone related services. TheZeroGroup's site claims they are hosted off-shore to avoid any legal issues that may arise.

On June 13th the U.S. House of Representatives passed the "Truth in Caller ID Act of 2007" which would make it "unlawful for any person within the United States, in connection with any telecommunications service or VOIP service, to cause any caller identification service to transmit misleading or inaccurate caller identification information with the intent to defraud or cause harm." A similiar bill was passed onto the Senate in April, but the Senate hasn't acted on either of the bills yet.

In India,we do not have any law which is related to the crime made by hoaxters by spoofing caller id.







Orkut Server Side Session Handling Problems:

Overview:

1. Orkut fails to expire the orkut_state session cookie from the server side even when the
user logs off from Orkut upon clicking "Sign-Out" from the application. The cookie is
cleared from the client side (browser), but is not cleared from the server side. If reused,
it provides access to the user's Orkut account.

2. Upon logging in again, a new orkut_state session cookie is created, but the old session
cookies still stay active on the server side. Therefore, any session cookie can be reused
to gain access to the user's Orkut account.

Details:

When any user logs into “orkut.com” . data of cookie will be generated on server and it will be sent back to user after successful authentication process on server. If I come to know about cookie data of any victim remotely then I can access victim’s account without password ( and even user id).


After an access to victim's account, I can edit his/her social,personal,professional,contact profiles,i can also have an access to his/her albums,videos,testimonials.i can even stop victim to access his/her account by editing the contact email.

My aim is not to hack the orkut account and damaged any victim's data, but to create awareness among the people about the security risks over social networking websites.

Recently I had been interviewed by HEADLINES TODAY and I have proved live that any orkut account can be hacked. I am also going to do half an hour live show on AAJTAK.

More Details will be covered in LIVE demonstration.

Gmail Server Side Session Handling Problems:

Overview:

1. Gmail fails to expire the GX session cookie from the server side even when the user
logs off from Gmail upon clicking "Sign-Out" from the application. The cookie is
cleared from the client side (browser), but is not cleared from the server side. If reused,
it provides access to the user's Gmail account.

2. Upon logging in again, a new GX session cookie is created, but the old session cookies
still stay active on the server side. Therefore, any session cookie can be re-used to
gain access to the user's Gmail account.

The above article given by http://gprsinformation.blogspot.com/2010/08/call-forging-caller-id-forging-practice.html


SMS forging is a relatively new kind of high-tech felony, which uses the short message service (SMS), which is available on most mobile phones and personal digital assistants, to spoof or impersonate another user. The spoofing is often used to send viruses that can be carried from phone to phone and which can cause destructive behavior.

SMS spoofing became possible after many mobile/cellular operators had integrated their network communications with/in the Internet. So anybody could send SMS from the Internet using forms at the websites of mobile operators or even through e-mail. Unfortunately, the Internet forms designed to send SMS may have vulnerabilities that could lead hackers to be able to break the tunneling protocol that links the phones with the Internet.

Surprisingly, one can use legitimate SMS tools available on the market for spoofing. For instance, Clickatell, a provider of carrier-grade bulk SMS messaging solutions and applications that can be integrated and used immediately within a global environment, developed various software allowing users to send bulk and personalized SMS messaging to existing databases, Lotus Domino and other integrated SMS solutions. Therefore any person can purchase or even download evaluation software that would allow the individual to send a spoof SMS. Other providers such as FakeMyText and CloakText actually sell an anonymous texting service as their main service which can be used to spoof a SMS message from any international number.

There is also dedicated Open Source tool called SMS Spoof, which is a Palm OS application that allows individuals to send spoofed SMS messages. It uses a dialup connection to any EMI/UCP-compatible short message service center (SMSC) which supports the EMI/UCP protocol, as long as no authentication is required.

Details:
Every SMS sent from sender to receiver is in PDU format which is of 7bit .
07917283010010F5040BC87238880900F10000993092516195800AE8329BFD4697D9

Octet(s)Description:-

07Length of the SMSC information (in this case 7 octets)

91Type-of-address of the SMSC. (91 means international format of the phone number)

72 83 01 00 10 F5Service center number(in decimal semi-octets). The length of the phone number is odd (11), so a trailing F has been added to form proper octets. The phone number of this service center is "+27381000015".

04First octet of this SMS-DELIVER message .

0BAddress-Length. Length of the sender number (0B hex = 11 dec)

C8Type-of-address of the sender number

72 38 88 09 00 F1Sender number (decimal semi-octets), with a trailing F, By changing this format at the sender side,we can spoof sender ID of the SMS.