Thursday, January 24, 2013

Mantra Browser OWASP[browser to hack]



 
The Browser named “Mantra” is A Collection Of Open Source Tools Binded with a Browser To Make The Work Of Penetration Testers,Web Developers,Scurity Proffesional easier..
Its Loaded with Many Tools to Make the work Of Web Developers a lot easier..
Moreover its Portable ..just Download the browser and you can carry it in your pen drive and run it On Any Computer…
Mantra can be used for both offensive security and defensive security related tasks which makes it incredible.
Mantra is available on Backtrack 5, you can get it by click on Applications–>Backtrack–>Vulnerability assessment–>Vulnerability scanner–>Mantra
It is a user friendly,portable and GUI framework, you can carry it on flash drives and CD/DVD. It is a cross operating system framework that can be run on windows, Linux and MAC as well. It is a open source project so it is available on free of cost.
 Download URL:

http://www.getmantra.com/download/index.html

Download the required Version for required browser like Chrome or Firefox. You can also download Artworks (themes) for Mantra Browser.

LIST OF ALL TOOLS

Tools

The Mantra is a powerful set of tools to make the attacker’s task easier. The beta version of Mantra Security Toolkit contains following tools built onto it. You can also always suggest any tools/ scripts that you would like see in the next release.
  • Access Me
  • Add N Edit Cookies+
  • Chickenfoot
  • CookieSwap
  • DOM inspector
  • Domain Details
  • Firebug
  • Firebug Autocompleter
  • Firecookie
  • FireFTP
  • Firesheep
  • FormBug
  • FoxyProxy
  • Google Site Indexer
  • Greasemonkey
  • Groundspeed
  • HackBar
  • Host Spy
  • HttpFox
  • iMacros
  • JavaScript Deobfuscator
  • JSview
  • Key Manager
  • Library Detector
  • Live HTTP Headers
  • PassiveRecon
  • Poster
  • RefControl
  • Refspoof
  • RESTClient
  • RESTTest
  • Resurrect Pages
  • Selenium IDE
  • SQL Inject ME
  • Tamper Data
  • URL Flipper
  • User Agent Switcher
  • Vitzo WHOIS
  • Wappalyzer
  • Web Developer
  • XSS Me
Screenshot of the tools:-

Information Gathering


Flagfox
Flagfox
Displays a flag icon indicating the current webserver’s physical location with many additional features.


JSView
JSView
Get straight access to scripts and stylesheets included in the current web page.

PassiveRecon
PassiveRecon
Perform passive discovery of target resources utilizing publicly available information.


Wappalyzer
Wappalyzer
Uncovers underlying technologies used on websites like CMS, e-commerce systems, JavaScript frameworks, analytics tools etc..

View Dependencies
View Dependencies
Shows you all the files which were loaded to show the current page.


Link Sidebar
Link Sidebar
View, search and test hyperlinks in a web page.

Editors


JSView
JSView
Get straight access to scripts and stylesheets included in the current web page. View the source code external stylesheets and javascripts


Firebug
Firebug
Edit, debug, and monitor CSS, HTML, and JavaScript live in any web page.

Network Utilities


FireFTP
FireFTP
FTP/SFTP Client which provides intuitive access to FTP/SFTP servers.


DNS Cache
DNS Cache
Allows you to disable and enable the DNS Cache of Firefox

SQLite Manager
SQLite Manager
Manage any SQLite database on your computer.


HTTP Fox
HTTP Fox
Monitors and analyzes all incoming and outgoing HTTP traffic between the browser and the web servers.

FireSSH
FireSSH
SSH Client

Misc


Greasemonkey
Greasemonkey
Customize the way webpages look and function. A userscript manager for Firefox


Greasefire
Greasefire
Automatically finds Greasemonkey scripts on Userscripts.org.

CacheToggle
CacheToggle
Disable and optionally clear the browser cache with the flick of a switch.


URL Flipper
URL Flipper
Easily increment or decrement a portion of a URL without having to manually edit the text in the Location Bar.

Event Spy
Event Spy
DOM Event spy addon. Lets you watch JavaScript events as they occur.


Stacked Inspector
Stacked Inspector
Switch DOM Inspector to an over/under vertical layout instead of the usual side-by-side panel layout.

Scriptish
Scriptish
The greatest user script engine on the Internet (a fork of Greasemonkey).


Session Manager
Session Manager
Session Manager saves and restores the state of all windows. It can also automatically save the state of open windows individually.

Scriptish
Fire Encrypter
Encrypt, decrypt and hashing functions utility.

Application Auditing


Hackbar<
Hackbar
Simple security audit / Penetration test tool.


RESTClient
RESTClient
Visit and test RESTful/WebDav services.

Tamper Data
Tamper Data
Use tamperdata to view and modify HTTP/HTTPS headers and post parameters.


Live HTTP Headers
Live HTTP Headers
View HTTP headers of a page and while browsing.

RefControl
RefControl
Control what gets sent as the HTTP Referer on a per-site basis.


User Agent Switcher
User Agent Switcher
Easily switch the user agent of a browser.

Web Developer
Web Developer
Various web developer tools on browser.


DOM Inspector
DOM Inspector 
Inspect and edit the live DOM of any web document or XUL application.

Inspect This
Inspect This
Inspect the current element with the DOM Inspector.


Form Fox
Form Fox
Displays the form action, the site to which the information you’ve entered is being sent.

SQL Inject Me
SQL Inject Me
Test for SQL injection vulnerabilities which can cause a lot of damage to a web application.


XSS Me
XSS Me
Test for XSS vulnerabilities which can cause a lot of damage to a web application.

Cookies Manager+
Cookies Manager+
View, edit and create cookies.


Firecookie
Firecookie
View and manage cookies

Autofill Forms
Autofill Forms
Autofill Forms enables you to fill out web forms with one click or a keyboard shortcut.


Cookie Monster
Cookie Monster
Cookie Monster provides proactive cookie management on a site or domain level basis, including 3rd party cookies.

Fireforce
Fireforce
Brute-force attacks on GET or POST forms


Groundspeed
Groundspeed
Groundspeed is an add-on that allows security testers to manipulate the application user interface to eliminate annoying limitations and client-side controls that interfere with the web application penetration tests.

Http Requester
Http Requester
A tool for easily making HTTP requests (GET/PUT/POST/DELETE), viewing the responses, and keeping a history of transactions.


Modify Headers
Modify Headers
Add, modify and filter the HTTP request headers sent to web servers. This addon is particularly useful for Mobile web development, HTTP testing and privacy.

Poster
Poster
A developer tool for interacting with web services and other web resources that lets you make HTTP requests, set the entity body, and content type.


Ref Spoof
Ref Spoof
Easy spoofing of the URL referer (referrer) featuring a toolbar

SeleniumExpertSeleniumIDE
SeleniumExpertSeleniumIDE
This plugin is my attempt to bring the wonderful world of inspections, tips, hints, fixes and refactoring to Selenese!


SeleniumIDE
SeleniumIDE
This plugin is my attempt to bring the wonderful world of inspections, tips, hints, fixes and refactoring to Selenese!

NoRedirect
NoRedirect
Take control of web page redirects for fun and profit.


Websecurify
Websecurify
Websecurify is a powerful, cross-platform web security testing technology designed from the ground up with simplicity in mind.

Ra.2
Ra.2
Blackbox DOM-based XSS Scanner


Proxy


HTTP Fox
Monitors and analyzes all incoming and outgoing HTTP traffic between the browser and the web servers.


FoxyProxy
Advanced proxy management tool.

Proxy Tool
Powerful, yet User-friendly proxy tool to manage your proxies and anonymity needs, including: 46M+ user agents (world’s largest), 10 different spoofed HTTP referrers, auto-proxy rotation, plus many more.
And Many Many More Tools……

.::ScreenShots ::.

mantra
mantra1
mantra2
mantra3
mantra4
mantra5
mantra6

Hack Websites Using Drupal IMCE mkdir Remote Exploit Easily

“Drupal IMCE Remote File Upload Vulnerability Mkdir”

Mkdir IMCE is a vulnerability that allows file uploads remotely (remote file upload) and is in the platform durpal.
generally you can upload files *. txt on websites, but some sites let you upload the files* . html . If you try to upload a shell try to upload files *. phtml .
Google Dork:
inurl: "/ IMCE? dir =" intitle: "File Browser"
-------------------- -------------------------------------------------- -------------
Domain : IMCE? dir =. 

Mkdir IMCE is a vulnerability that allows file uploads remotely (remote file upload) and is in the platform durpal.
generally you can upload files *. txt on websites, but some sites let you upload the files* . html . If you try to upload a shell try to upload files *. phtml .

Google Dork:
inurl: "/ IMCE? dir =" intitle: "File Browser"
-------------------- -------------------------------------------------- -------------
Domain : IMCE? dir =.


STEPS

[+] The first thing to do is find a vulnerable site for uploading files using Google Dork
[V]> = http://www.anfaco.es/webs/Museo2.0/imce?dir. 
[X]> = http://www.civic-forum.org/de/imce?dir.
————————————————————————————————————————————————————————–
[+] After finding the site with an upload, see if you can upload a file *. html or *. phtml
———— [Example:] ———— Click on image to enlarge
__ [+ +] First click on Upload ___ [+ +] then click on Select File ___ [+ +] select our file ___ [+ +] click to open then ___ [+ +] Upload And finally click again to file upload to our website.
[+] Once we got the file and we can go to him

Click on image to enlarge
> www.anfaco.es/webs/Museo2.0/sites/default/files/THC.html
————————————————————————————————————————————————————————–
Logically the file is uploaded in the folder that comes after the exploit. Example:
If you found a site that is vulnerable: www.ejemplo.com/hola/chau/ IMCE? dir =.
And in the lindex could see something like this: It means that your file will be uploaded from: www.ejemplo.com / hi / bye / sites / default / files / Here it is again: If you find yourself on page www.ejemplo.com/hola/chau/ IMCE? dir =. and upload a file called wasa.html , your file rise to www.ejemplo.com / hi / bye / sites / default / files / wasa.html But if you rather than upload it in “ / sites / default / files / ”you go and subis in the” languages ”, your file appear in www.ejemplo.com / hi / bye / sites / default / files / languages / wasa.html. , because languages / is inside the folder “ / sites / default / files / ”.


This can serve to:
[+] Save Image
[+] Save information
[+] Delete Data (Above all the delete option usually appears)
[+] Upload shell
[+] Get Data
Defacements made using this vulnerability:-
[1]= Domain
[2] = Domain + Exploit
————————————————————–
http://www.climateinvestmentfunds.org
…/cifnet/imce?dir=fivestar
http://www.climateinvestmentfunds.org/cifnet/sites/default/files/fivestar/basic/THC.html
—————————————————————
http://cycleandwalking.org/
…/imce?dir=gallery_assist/1/gallery_assist293
http://cycleandwalking.org/sites/default/files/gallery_assist/1/gallery_assist293/THC.html
————————————————————–
http://www.la-gerbille.net
http://www.la-gerbille.net/imce?dir=artykul
http://www.la-gerbille.net/sites/default/files/artykul/THC.html
————————————————————–
http://www.arcireal.com
…/imce?dir=imagecache/604
http://www.arcireal.com/sites/real.sitetest.it/files/imagecache/604/THC.html
————————————————————–
http://www.anfaco.es
…/webs/Museo2.0/imce?dir=.
http://www.anfaco.es/webs/Museo2.0/sites/default/files/THC.html
————————————————————–
http://www.travelagentcentral.com
…/imce?dir=.
http://www.travelagentcentral.com/files/travelagent/THC.html
————————————————————–
https://stp.abes.fr
…/imce?dir=.
https://stp.abes.fr/sites/stp.abes.fr/files/THC.html
————————————————————–
http://priora-wtcc.ru
…/imce?dir=u3
http://priora-wtcc.ru/sites/default/files/upload/u3/THC.html
————————————————————–
http://labourlakesandfurness.co.uk
…/imce?dir=.
http://labourlakesandfurness.co.uk/sites/labourlakesandfurness.co.uk/files/THC.html

Hack Websites Using XPath Injection



XPath Injection:
SQL is the most popular type of code injection attack, there are several others that can be just as dangerous to your applications and your data, including LDAP injection and XPath injection. An ‘XPath injection’ attack is similar to an SQL injection attack, but its target is an XML document rather than an SQL database. ‘XPath Injection’ is an attack technique used to exploit web sites that construct XPath queries from user-supplied input.
What is XML?
XML stands for Extensible Markup Language and was designed to describe data. It allows programmers to create their own customized tags to store data. In XML the data is stored in nodes in a tree form. XML Path or XPath language is used for querying information from the nodes of an XML document. Please refer to XML Tutorial for more details on XML.
What is XPath?
“XML Path” or “XPath” 1.0 is a language used to refer to parts of an XML document. Path expressions are used to access elements and attributes in an XML document, which return a node-set, a string, a Boolean or a number. It can be used directly to query an XML document by an application, or as part of a larger operation such as applying an XSLT transformation to an XML document, or applying an XQuery to an XML document. Please refer to XPath Tutorial for more details on XPath.
In Detail:
Code Injection is a technique to Inject code into a program or application code by taking advantage of the unchecked assumptions the application makes about its inputs to bypass or modify the originally intended functionality of the code. All code injection attacks work in a same way; an attacker injects malicious code into the application code through an input field of the application. So, to perform such attacks there must be entry points that are not performing adequate validation.
Consider a Web application that uses XPath to query an XML document to retrieve the social security number of a customer by passing name and password values that are supplied by the user of the application. If the application embeds these values directly in the XPath query then it is vulnerable to XPath Injection.
OK, so when to use it? Let us assume we have found a vulnerable site that appears to be vulnerable from our usual quick tests, but when we try to inject using ORDER BY we get no errors generated. We double check using String injection method to make sure that it is not the problem, but still no results. Time to give up? Never, let us now try to see if we might be able to use XPATH injection.
34392415.png (800×224)
We will start with a quick check to confirm versioning to ensure this method can be used, as it only works on MySQL version >=5.1 (best with errors present). The first check for version and user looks like this:
COMMAND: http://site.com/index.php?id=1 and extractvalue(rand(),concat(0x3a,version(),0x3a,user()))—
RESULT: ’Xpath syntax error: version info:user info’
63361066.png (800×190)
OK, so now we have confirmation that this method will work as clearly displayed in the errors seen. We now have the version and current user info. Now we will move to checking the table info, like this:
COMMAND: http://site.com/index.php?id=1 and extractvalue(rand(),concat(0x3a,(select concat(0x3a,table_name) from information_schema.tables limit 0,1)))–
RESULT: ’Xpath syntax error: <Table Name Found at address used in LIMIT statement>’
95976832.png (800×194)
This is the biggest problem with XPATH Injection, it gets tricky here. You will need to use the LIMIT statement to sort your results and keep traffic of all of the table names found. This can be very time consuming, but it is key that you use your brain to pick up on any relationships that become obvious as you are sorting through tables, while also keeping an eye out for juicy tables that may warrant further investigation in future steps. I suggest first sorting them to find the lower and upper limits so you know what type of range you are working with (some sites will be only a few and others will have thousands in total – see example below).
53807123.png (800×185)
24698245.png (790×800)
Once you have determined the table info, you will need to follow similar steps to pull the column details. It works very similar to tables and looks like this:
COMMAND: http://site.com/index.php?id=1 and extractvalue(rand(),concat(0x3a,(select concat(0x3a,column_name) from information_schema.columns limit 0,1)))–
RESULT: ‘Xpath syntax error: <column name found at address used in LIMIT statement>’
39102492.png (800×185)
This is just as time consuming as the pulling the table names and is a bit tricky as it becomes very hard to tell what columns link to what tables or database for that matter, for this reason it is key to use your brain power to make some logical determinations about what you find. This means you can use your brain to deduce that you have found a table named mysql_auth_users and columns idx, username, and password. It would not be a great stretch to assume these might go together. I tend to use a bit of trial and error on this last part but have found if you just think about it for a minute you can usually make the necessary connections to extract what you want. That being said, extraction of data works the exact same as it does for simple SQLi. You choose the columns you want and indicate what table to pull from and parse the results from the error given. It looks like this:
COMMAND: http://site.com/index.php?id=1 and extractvalue(rand(),concat(0x3a,(select concat(0x3a,idx,0x3a,username,0x3a,password) from mysql_auth_usr)))–
RESULT:  Xpath syntax error: ‘:1:admin:password1’
101ld.png (800×215)
Now you have successfully injected and extracted the data using XPATH injection! Now go pat yourself on the back for learning a new method and enjoy a well-deserved break ;) There are other XPATH queries that can be used but this is the one I have found the best results with. You can also use updatexml(). I will continue to add to this as I investigate this technique more, but this concludes my write up on XPATH injection using the EXTRACTVLAUE() method for now. I hope you have found this interesting and educational and as always until next time Enjoy!
 

NOTE: ONLY FOR EDUCATIONAL PURPOSE. IT IS TOTALLY ILLEGAL AND YOU WILL BE PUNISHED. SO DONT TRY.

 

Monday, January 14, 2013

Firesheep:Trick to Hack Facebook and Twitter Password on Wifi



So, the trick I am telling you works only on websites like facebook,twiiter,flickr but not on secured websites like Gmail.So here is Trick to Hack Facebook and Twitter Password on Wifi
and also the method of protection from this hack.This trick doesnot require any programming knowlege and everyone can use this trick easily.

1.Download firesheep Firefox extension.This is a freeware extension for firefox browser.
2.  Once installed it will open a sidebar window into your firefox browser.
3.Now it will show all the people who are connected to unsecured wifi network.Once they login into your facebook or twitter account you will get a notification and with a single click you can login into their account.
This whole thing work on the technique of cookie hijacking.Once your session cookie is hacked then anybody can login into your account.These cookies can be easily caputered on unsecured wifi network.
The best way to protect yourself from such a hacking trick is to avoid using your facebook or twitter accounts on unsecured wifi networks as it is a security lapse from the websites not on your side.

Note:-This article is to inform you about how your password can be hacked and how to prevent it.This article is purely for educational purposes.

20 Facebook Tips/Tricks You Might Not Know

facebook tips & tricks
If you surf Facebook on daily basis or occasionally, chances are you’re already familiar with regular stuffs like add/delete friends, update statuses, walls and profile, add and explore pages & applications, etc, but there’s more..
This week we want to cover some interesting things you can do on (or with) Facebook; inclusive of tricks that are not documented or unknown to many, as well as tips to stay connected better with your friends. Without further ado, here’s 20 Facebook Tips/Tricks You Might Not Know. If you have interesting tips/tricks related to Facebook, please feel free to share in the comment box below.

  1. How to Place Facebook Chat On Firefox Sidebar

    If you are using Firefox, you can place the Facebook Chat at the sidebar.
    Facebook_Chat_Firefox_Sidebar
  2. How to Download Facebook Photo Albums

    FacePAD: Facebook Photo Album Downloader allows you to download your friends’ facebook albums, Events albums, and Group Albums, en masse, with the click of a button.
    facepad
  3. How to Share Flickr Photos to Facebook

    Flickr2Facebook is an unofficial Flickr to Facebook uploader(bookmarklet) which allows you upload photos to Facebook from Flickr.
    flickr2facebook
  4. How to Update Facebook without Using Facebook

    hellotxt and Ping.fm both introduced features that let Facebook administrators update Facebook Pages.
    hellotxt
  5. How to Schedule Facebook Messages

    Sendible lets you schedule Facebook messages ahead of time so you can send messages to your friends, customers or colleagues in the future.
    sendible
  6. How to "Friend" Someone on Facebook & Hide It From Your Status Updates

    A short tutorial on Makeuseof to guide you how to hide Facebook status updates and keep that fact confined to your closer friends.

  7. How to Create a Photo Collage Using Pictures of Your Facebook Friends

    Click on Friends tab. Proceed to More tab. From "Choose an option" dropdown, choose any of the dashes "" . Your Facebook friends collage is right on your computer screen.
    photo_collage
  8. How to Know When Facebook Friends Secretly Delete or Block You

    This service has been discontinued. X-Friends is a unique tool for tracking friends that disappear from Facebook.
    X-friends
  9. How to Display Selected Pictures Only on your Facebook Profile Page

    A little-known feature in Facebook that lets you decide who shows up in that Friends box. Click that "edit" pencil in your Friends box and type the names of your best friends in the box that says "Always show these friends"
    friend_photos
  10. How to Remove Facebook Advertisements

    This Greasemonkey script – Facebook: Cleaner removes many of the annoying ads and updates that unavoidably appear on your Facebook pages.
    ads
  11. How to Syncs Photos of Facebook Friends with Contacts in Microsoft Outlook

    OutSync is a free Windows application that syncs photos of your Facebook friends with matching contacts in Microsoft Outlook. It allows you to select which contacts are updated. So you can update all contacts at once or just a few at a time.
    outsync
  12. How to Display Facebook Statuses on WordPress Blog

    The following method make use of Facebook status feed and WordPress RSS widget to display Facebook Statuses on WordPress blog.. It will also work for self-host WordPress blogs.
    statuses
  13. How to Post Your Blog Posts to Your Facebook Wall Automatically

    Wordbook allows you to cross-post your blog posts to your Facebook Wall. Your Facebook “Boxes” tab will show your most recent blog posts.
    wordbook
  14. How to Access Facebook Chat on Desktop

    Gabtastik and digsby let you keep Facebook chat sessions open on your Windows desktop outside of your regular web browser, using minimal screen real estate and system memory.

  15. How to Create Quiz on Facebook Easily

    LOLapps provides quiz creator that can be employed to conjure up these popular personality quizzes that are so widespread in Facebook.
    lolapps
  16. How to Hide Your Online Status on Facebook Chat from Select Contacts

    Facebook has integrated friends list with Chat and you can also choose which of these list members get to see you online.
    hide
  17. How to Get Facebook Updates on Email

    NutshellMail consolidates your Facebook accounts through the inbox you use the most.
    nutshellmail
  18. How to Update Facebook Status from Firefox

    FireStatus is a status update utility for multiple social networks, including FaceBook.
    firestatus
  19. How to Get Facebook on Your Desktop

    Seesmic Desktop, Facebooker, Xobni, Facebook Sidebar Gadget, Scrapboy and Facebook AIR application are desktop applications that allows you interact with your stream just as you would on Facebook, but without the browser.

  20. How to Delete, Cancel and Terminate Facebook Account and Profile

    A simple guide to terminate, delete or cancel Facebook account, together with the Facebook profile easily.
    terminate