Monday, May 7, 2012

Now all keyloggers and RATs are sending data to the hacker in regular intervals (usually every 5 to 10 minutes) by using one of the two methods below:

1. Using the Emails: where hacker configures his email ID and password while creating the server. Keylogger records the key strokes in a temp file and sends it to the hacker in form of emails. But this has a limit as most free email servers like Gmail or Yahoo or Hotmail has limit of 500 composed and received mails. So most hackers use the second method.
2. FTP server: While creating the keylogger server, hackers configure their FTP server, where they receive the logs of key strokes in the form of text file(usally labeled on the basis of current system time stamp). Hackers keylogger server uploads the files to FTP server after every few minutes interval.

If we monitor all data packages we can easily scan for one of these and then we'll have the hackers email info or FTP info. What can we do with this, you might ask; highly skilled hackers obviously won't allow this as they create a completely seperate email or FTP site which leaves no traces of them, but novice skilled hackers (there's plenty of those) will just use their own email or leaving behind information about them. An example could be that you find the name of the person from the email you backtraced - this ain't his primary email, so there's nothing valuable. From there you can look up his name on Google, you'll probably find his real email on some site; then simply try to login to it using the password from the fake email (most novice skilled hackers will have the same password).

Wireshark is a very famous network scanning hack tool which is used by hackers or network forensic experts to monitor the packet flow of their network cards like Ethernet or WLAN. It records each and every packet coming and going out of your system's Network card. Packets is just a bunch of data.

Whenever you feel anything suspicious in your system like your system is compromised or you are infected follow the steps below prior to removing the keylogger or RAT from your system.


Steps to reverse engeneering the email or FTP servers password:

1. First of all download and install Wireshark. You can easily get this simply by Googling it.
Note: While Wireshark is getting installed, ensure that it installs the Winpcap with it otherwise it won't work properly.


2. Now go to the "Capture"-button in the top menu of the Wireshark and select the interface (means your network card which can be Ethernet or WLAN).

3. It will now start capturing the packets through that Network card. What you have to do is just keep capturing the records for atleast 30 minutes for getting the best results. After x time, stop capturing the packets.

4. Now you need to filter your results, for this go to the filter box and type FTP and SMTP one by one. Note: if you get records for FTP then hacker has used FTP server and if you didn't get FTP that means the hacker has used SMTP, so give SMTP in Filter box.

5. As you scroll down you will find the “FTP username” and “Password” for victims ftp account in case FTP server is used. And if hacker has used SMTP then you will find "email address" and its "password" that hacker has used to create the server.

NOTE: This won't work in all cases, but it's certainly worth trying. Who wouldn't want revenge if some skid infected your precious PC?

I spent a long time writing this.
Please take 5 seconds to say thanks.
It is much appreciated.
As a hacker you should know the penalties of unauthorized hacking into a system. You should be judi-cious with your hacking skills and recognize the consequences of misusing those skills. The most important U.S. laws regarding computer crimes are described in this thread. Make sure you familiarize your-self with these U.S. statutes and the punishment for hacking. Remember, intent doesn’t make a hacker above the law; even an ethical hacker can be prosecuted for breaking these laws.

Cyber Security Enhancement Act and SPY ACT


The Cyber Security Enhancement Act of 2002 mandates
life sentences for hackers who “recklessly” endanger the lives of others. Malicious hackers who create a life-threatening situation by attacking computer networks for transportation systems, power companies, or other public services or utilities can be prosecuted under this law.
The Securely Protect Yourself Against Cyber Trespass Act of 2007 (SPY ACT) deals with the use of spyware on computer systems and essentially prohibits the following:

Taking remote control of a computer when you have not been authorized to do so


Using a computer to send unsolicited information to people (commonly known as spamming)

Redirecting a web browser to another site that is not authorized by the user

Displaying advertisements that cause the user to have to close out of the web browser (pop-up windows)


Collecting personal information using keystroke logging


Changing the default web page of the browser


Misleading users so they click on a web page link or duplicating a similar web page to mislead a user (Pishing).


The SPY ACT is important in that it starts to recognize annoying pop-ups and spam as more than mere annoyances and as real hacking attempts.
The SPY ACT lays a foundation for prosecuting hackers that use RATs, spam, pop-ups, and links in emails.

18 USC §1029 and 1030


The U.S. Code categorizes and defines the laws of the United States by titles. Title 18 details “Crimes and Criminal Procedure.” Section 1029, “Fraud and related activity in connection with access devices,” states that if you produce, sell, or use counterfeit access devices or tele-communications instruments with intent to commit fraud and obtain services or products with a value over $1,000, you have broken the law. Section 1029 criminalizes the misuse of computer passwords and other access devices such as token cards.


Section 1030, “Fraud and related activity in connection with computers,” prohibits accessing protected computers without permission and causing damage. This statute criminalizes the spreading of viruses and worms and breaking into computer systems by unauthorized individuals.


USA PATRIOT Act

This act, with the official name Uniting and Strengthening America by Providing Appropriate Tools Required to Intercept and Obstruct Terrorism (USA PATRIOT) Act of 2001, gives the government the authority to intercept voice communications in computer hacking and other types of investigations. The Patriot Act was enacted primarily to deal with terrorist activity but can also be construed as a wiretap mechanism to discover and prevent hacking attempts.

U.S. State Laws

In addition to federal laws, many states have their own laws associated with hacking. The National Security Institute has a website listing all the state laws applicable to computer crimes. The URL is
http://www.law.cornell.edu/states/listing.html


Not a US citizen? But it still matters...


Other countries each have their own applicable laws regarding protection of information and hacking attacks.
With the use of the Internet and remote attacks, regional and international borders can be crossed very quickly. When you’re performing an outside remote attack, the data may be stored on servers in another country and the laws of that country may apply. It is better to be safe than sorry, so do the research prior to engaging in a attack aainst an international entity. In some countries, laws may be more lenient than in the United States, and this fact may work to your advantage.

*** I am not a lawyer and neither am I a US citizen. I do not get the credits for the information posted here. I read a book on ethical hacking and got the idea for this thread from it. I feel that everybody involved in hacking (ethical or not) should know the legal consiquences of what they are doing. I copy-pasted information from various sources and organised it into this thread. ***
A few months ago, I discovered a free, web-based virual PC. It takes about 5 seconds to load, and needs no registration(Guest Account). However, you can register and log into your Account in the Windows welcome screen of the VM.

So here's the site: http://www.silveos.com/

Pros:

  • It will be a great alternative to those who, like me, do not have hardware resources to run VMs smoothly.
  • You can execute files your local file-system or from the Internet by:
    Start Menu>Install Program.
  • Just go to the site and your OS starts loading.
  • Registration is optional, but recommended!
  • It's free!

Cons:
  • I am only half convinced on how secure it is.

    This is what the website tells about it's security arrangement:
    Quote:Application runs in Silverlight’s security sandbox. By default code is restricted from accessing user's file system or doing anything that could hurt user's machine.

    HF users who know about "Silverlight’s security sandbox", please leave your openions.
  • Internet browsing sucks...

It tool me 45 minutes to write this up. At-least spent 45 seconds to post your replies.

More coming soon!

adf popup

adf

MY SKYPE

Powered by Blogger.

Random Posts

Featured Post

Form Grabber Released Works With IE,CROME and FIREFOX ,Unicode support [ 14-02-2016]

Hello guys! here i am releasing My form grabber Today, i have been coding this for oven 6 months and finally its time for public sales.....

Followers

Recent in Culture

News

Lorem 1

Pages

Popular Posts

Popular Posts