\

Featured

Browsing Category "Vulnerabilities"
Powered by Blogger.

Browsing "Older Posts"


So Are You Ready To Own Your Victim's Account With A Smart Hack ?

First Of All send a text message containing only "fb" , "FBOOK" or "F" (without quotes) to 32665

[ N.B : if you attache your account with your phone it won't work on you..so use unused mobile number]

Then You Will Get A Confirmation Message On Your Phone.
Note Down The Confirmation Code.
Now We Will Trick User To Click On The Link &quot

[url]https://m.facebook.com/a/?c=[/url][ConfirmationCode]&_rdr "

For This I Send A Fake Email To Many Users And Every Time I Succeed Big Grin

Sample Email To Make The Victim To Click On The Link ( Let The Confirmation Code Is 365kj56 In My Case ) :
------------------------------
-----------------------------------------------------------------
Hi,
Your Facebook account has been blocked because of spaming.
To regain acess follow the link
[url]https://m.facebook.com/a/?c=365kj56&_rdr[/url]

If your account is hacked, please review the information below to get help.
- If your account or a friend's account is sending out suspicious links:
[url]https://www.facebook.com/help/hacked[/url]
- To report abuse:
[url]https://www.facebook.com/help/reportlinks[/url]
- For any other questions or concerns, please visit our Help Center:
[url]https://www.facebook.com/help[/url]

Thanks,
The Facebook Team
-----------------------------------------------------------------------------------------------

As Soon As Your Victim Clicks On The Link And Clicks ACTIVATE
Thinking His ID Is Blocked You Will Get A Message On The Same Number.
Its Means Your Done Cool

Now Hurrily You Have To Do Is Goto
[url]Http://m.facebook.com/login/easy[/url]

And Enter The Phone Number.
Then You Will Get The Link From Which We Can Acess His Account Even Without His Username & Password Big Grin

By This We Will Backdoor His Account Tongue Like Leaving A Backdoor On The Server No Matter Even
He Get To Know That He Is Tricked And He Changes The Password We Can Get The Access. We Have The Link To His Account Big Grin

Use Before Fb Remove Easy Login Or Remove This Verification Method Smile

Thanks For reading The Exploit.Hope You Own All Your Targets Thumbs Up

#[+] With A Bit Social Eng. And A Smart Hack You Can Access Any User's Account.

Facebook Account Reset Hijack Trick

By admin → Friday, February 7, 2014

You need: 

1) Google Account
2) Android device
3) PC + browser

You can install infinity count of apps to remote device from browser on PC.

The key is:
1) if you entered your google account once on android device
2) If you manage to get hold of someone else account (gmail), you can install any apps from Google Play Market on this device.
3) without asking owner of device for agreement.

In such way you can install bad soft and also can install so many apps then memory of device will be filled 

Google Market bug for Android, Jelly Bean Remote Target Download

By admin → Thursday, January 16, 2014
Just two days back Apple has yet fixed a security flaw in iOS 7 that allows anyone to bypass the lock screen to access users’ personal data and the next one has already appeared.




















The new vulnerability was discovered by Karam Daoud, a 27 year old from the West Bank city of Ramallah in Palestine, that allows anyone to make calls from a locked iPhone, including international calls and calls to premium numbers.

In a video, Daoud showed that calls can be made to any number from a locked iPhone running iOS 7 by using a vulnerability in the device’s emergency calling function.

The person needs to dial a number and then rapidly tap the call button until an empty screen with an Apple logo appears and makes the call to the particular number.



The Forbes writer tested the flaw on two iPhone 5 devices on separate networks and it worked both times. This is the second malfunction found in the lock screen since iOS 7 was seeded to all iPhone owners this past Wednesday.

Daoud notified Apple about the bug and received a same response that the next software update will fix this bug as well.

Second iOS 7 Lockscreen vulnerability lets intruders to make calls from locked iPhone

By admin →
Adobe Coldfusion Hack

Vulnerability Name :- => "Adobe ColdFusion 9 Administrative Login Bypass"

Description :- Adobe ColdFusion 9.09.0.19.0.2and 10 allows remote attackers to bypass authentication using the RDS component. Its password can by default or by misconfiguration be set to an empty value. This allows you to create a session via the RDS login that can be carried over to the admin web interface even though the passwords might be different. Therefore bypassing authentication on the admin web interface which then could lead to arbitrary code execution. Tested on Windows and Linux with ColdFusion 9.


Report-Timeline:- 2013-12-11: Public Disclosure (metasploit)
Status:- Published
Product:- ColdFusion 9.09.0.19.0.2and 10
Platform :- Windows and Linux
Exploitation-Technique:- Remote
Exploit Code :- Download Here
Read More :: Click Here
Source :: http://www.exploit-db.com/

Adobe ColdFusion 9 Administrative Login Bypass

By admin → Saturday, January 4, 2014
Vulnerability of The Week is  
Adobe Flash Player Vulnerability
adobe flash player hacked
Adobe Flash Player before 11.7.700.252 and 11.8.x and 11.9.x before 11.9.900.152 on Windows and Mac OS X and before 11.2.202.327 on Linux, Adobe AIR before 3.9.0.1210, Adobe AIR SDK before 3.9.0.1210, and Adobe AIR SDK & Compiler before 3.9.0.1210 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2013-5330. Patch released of for all affected programs. Adobe Recommend to users to update their flash player as soon as possible.

Source :: http://www.cvedetails.com/

Adobe Flash Player Vulnerability

By admin →