Saturday, April 4, 2009

Change Text On the Internet Explorer title bar

This hack allows you to change the text on the internet explore title bar. The default text or title is "Windows Internet Explorer". You can change This title Text to your own choice.

  • Goto Run ( Win+R )
  • Type "regedit" ( without quotes ) in the run diologue box.
  • In the registry editor navigate to
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main
  • Modify/Create the Value Name [Window Title] according to the Value Data listed below
Data type: REG_SZ [String Value] // Value Name: Windows Title
Value Data: [Enter The Text Desired In The Title Bar]

Exit Registry and reboot...

Hardware Keyloggers

Did you know that keyloggers are simplest way to hack an emal password?. Today I'll be you a detailed information on hardware keyloggers and their use. Here I'll give a brief description about keyloggers.

A software keylogger ( or simple keylogger ) is a stealth computer program that captures every keystroke entered through the keybord.

Now I'll tell you what is hardware keylogger and jow it can be used for hacking an email.

Hardware Keyloggers are used for keystroke logging, a method of capturing and recording computer user keystrokes. They plug in between a computer keybord and computer and log all keyboard avtivity to an internal memory. They are designed to work with PS/2 keyboard, and most recently with USB keyboards. A hardware keyloggers appears as simply as a USB pendrive ( thumb drive ) or any computer peripheralso that the victims can never doubt that it is keylogger. So by looking at it's appearence it is not possible to identify it as a keylogger. Here are some of the images of hardware keyloggers for your convenience.



So by looking at above images we can come to know that hardware keyloggers look just like any USB or PS/2 device. So it is hard to identify it as keylogger.

Installing a Hardware Keylogger to Hack the Email Password

The hardware keylogger must be installed between the keyboard plug and the USB or PS/2 port socket. That is you have to just plug in the keylogger to your keyboard's plug ( PS/2 or USB ) and then plug in it to the PC socket. The following Images shows how the keylogger is installed.




Once you install the hardware keylogger as shown in the above two images the keyloggers start recording each and every keystroke of the keyboard including email password and other confidential information. The hardware keylogger has an inbuilt memory in which the logs are stored.

Friday, April 3, 2009

How To Hide IP Address?

Here in this post I will try to give you every possible information to hide the IP address. If you seriously want to hide your IP address then this post is for you!

One of the most frequently asked question by internet users is How To Hide IP Address?. Many times it becomes necessary to hide the real IP address for the sake of privacy.

you can definitely hide your IP.

Now I'll come to the heart of the post, which contains the answer to ypur curious question How To Hide IP address?. The only solution to hide your IP address is by using a Proxy Server. But wait! The story doesn't end here. Even though proxy servers are the only way to hide your IP address, there are several ways of connecting your PC to the proxy server. Before setting up the connection with the proxy servers you must know some information about different types of proxy servers and their use.

1. Transparent Proxy Server
This type of proxy server identifies itself as a proxy server anf also makes the original IP address available through the http headers. These are generally used to speeedup the web browsing since they have a very good ability to cache websites. But they do not conceal the IP of it's user. It is widely known as transparent proxy because it will expose your real IP address to the web. This type of proxy server does not hide your IP address.

2. Anonymous Proxy Server
THhis type of proxy server identifies itself as a proxy server, but does not make the original IP address available. This type of proxy server is detectable, but provides reasonable anonymity for most users. This type of proxy server will hide your IP address.

3. Distorting Proxy Server
This type of proxy server identifies itself as a proxy server, but make an incorrect original IP address available through the http headers. This type of proxy server will hide your IP address.

4. High Anonymity Proxy Server ( Elite Proxy )
This type of proxy servers does not identifies itself as a proxy server and does not make available the original IP address. This type of proxy server will hide your IP address. So this is the best way to mask your IP.

Which Proxy Server is the best to Hide My Proxy???

Obviously High Anonymity Proxy or Elite Proxy is the best to hide your IP. But it's not easy to get a list of working elite proxies. If you search the Google, you will definitely get tons of proxy list. You'll get a list of proxies in the following format

IP:Port Number
Eg: 221.90.45.67:8080 ( 221.90.45.67 is the IP of the proxy server and 8080 is the port number )
But most of them don't work. Here are the some problem/risk associated with using free proxies that available on the internet.

  • Most of them do not work since the proxy servers frequently changes it's IP/Port number.
  • Even if you find a working proxy server it may be too slow.
  • Your privacy is not guaranteed since all your traffic is routed through the proxy server.
  • The administrator of the proxy server may steal your valuable information such as password. SSN ( Social Security Number ), Credit Card details etc.

So with all these being the risk then how to find a working, fast Anonymous and secured Proxy Server?

Here is a list of working IP Hiding softwares that you can try.

1. Hide The IP

Let's you choose the country, Type and speed of the proxy. Not so popular but personally I recommand this to the user.

2. Hide My IP

3. Hide IP NG

you can get more informations about these product on their respective homepages.

How to ensure that the IP is hidden ?

Before you hide your IP you can check your real IP by visitting the following site.

WhatIsMyIPAddress.Com

Once you get your real IP, switch on your IP hiding software. Now Once again visit the above site and check your IP address. If you see a new IP then this means that your software is doing the right job. Also the above site ( WhatIsMyIPAddress ) is capable of detecting many proxies. If you see the words such as "Suspected proxy server or network sharing device" or similar words then it means that the proxy you are using is not an Elite Proxy.

One Final Word before you leave! Even though Elite proxies are almost undetectable this doesn't that you can escape frome online crimes by hiding your IP. There are many proxy detecting services available detect almost any proxy. So if you involve in any cyber crimes then you definitely be behind the bars. Using proxy will not help you in this case.

One more thing, It is unsafe to use proxy during e-commerce transaction such as online banking, Online Credit Card payment etc. So please avoid proxies during these circumstance. Please expresse your experience and opinion through comments.

Sunday, March 29, 2009

How Phishing Works

Phishing is an attempt to criminally acquire sensitive information, such as usernames, password and credit card details, by appearing as a trustworthy entity in an electronic communication. eBay, PayPal and other online banks are common targets. Phishing is typically carried out by email or instant messaging and often directs users to enter details at a website, although phon contact has also be used. Phishing is an example social engineering techniques used to fool users. Attempts ti deal with the growing number of reported phishing incident include legislation, user training, public awareness, and technical measures.

Recent phishing attempts have targeted the customer of bank and online payment services. Social networking sites such as Orkut are also a target of phishing.

Spoofed/Fraudulent e-mails are the most widely used tools to carry out the phishing attack. In most cases we get fake e-mail that appears to have come from a Trusted Website. Here the hacker may requests us to verify username & password by replaying to a given email address.

TECHNIQUES BEHIND PHISSHING ATTACK

1. Link Manipulation

Most methods of phishing use some from of technical deception design to make a link an email appear to belong to some trusted organization or spoofed organization. Misspelled URLs or the use of subdomain are common tricks used by phishers, such as this example URL

www.micosoft.com

www.mircosoft.com

www.verify-microsoft.com

instead of http://www.microsoft.com/


2. Filter Evasion

Phishers have used images instead of text to make it harder for anti-phishing filters to detect text commonly used in phishing emails. This is the reason Gmail or Yahoo will disable the images by default for incoming mails.

How does a phishing attack/scam look like?

As scam artist become sophisticated, so do their phishing e-mail messages and pop-up windows. They often include official-looking logos from other identifying information taken directly from real Web sites. Here is an example of how the phishing scam email looks like

Example of phishing e-mail message, including a deceptive URL address linking to a scam Web site. To make these phishing e-mail messages look even more ligitimate, the scam artist may place a link in them that to go to the legitimate Web site (1), but it actually takes you to a phishing site (2) or possibly a pop-up window that looks like the official site. These copycat sites are also called "spoofed" Web sites. Once you're at one of these spoofed sites, you may send personal information to the hackers.

How to identify a fraudulent e-mail?

here are a few phrases to look for it an e-mail message is a phishing scam.

"verify your account."

Legitimate sites will never ask you to send passwords, ligin names, Social Security numbers, or any other personal information through e-mail.

"IF you messages convey a sense of urgency so that you'll respond immediately without thinking.

"Dear Valued Customer."

Phishing e-mail messages are usually sent out in bulk and often do not contain your first or last name.

"Click the link below to gain access to your account."

HTML-formatted messages can contain links or forms that you can fill out just as you'd fill out a form on a Web site. The links that you are urged to click may contain all or part of a real company's name and are usually "masked," meaning that the link you see does not takee you to that address but somewhere different, usually a scam Web site.

Notice in the following example that resting the mouse pointer on the link reveal the real Wb address, as shown in the box with the yellow background. The string of cryptic numbers looks nothing like the company's Web address, which is a suspicious sign.

So the Bottom line to defend from phishing attack is
1. Never assume that an e-mail is valid based on the sender's email address.
2. A trusted bank/organization such as paypal will never ask you for your full name and password in a payPal email.
3. An email from trusted organization will never contain attachment or software.
4. Clicking on a link in an email is the most insecure way to get to your account.