Thursday, December 26, 2013

BurpSuite_Pro_V1.5.01

BurpSuite  ဆိုတာ ကေတာ.လူတိုင္း  သိမယ္ ထင္ပါတယ္
Security tools 125 ထဲမွာ နံပါတ္ ၁၃ အဆင္.၇ွိတဲ. 

web scanner tools ေလးတစ္ခု ေပါ.

အခု ဟာေလး ကေတာ.  BurpSuite_Pro_V1.5.01 အမ်ိဳးအစားေလးပါ


မသိေသးသူမ်ားက ဒီလင္.ေလး မွာ တစ္ခ်က္ေလာက္သြားဖတ္ျကည္.ျကပါ


http://xploitdigit.blogspot.com/2013/03/burp-suite-part-i_5.html




BurpSuite_Pro_V1.5.01 Download

BrupSuite_Pro_V1.5.01 Download

Sunday, November 17, 2013

OWASP TOP 10 2013

The OWASP Top Ten provides a powerful awareness document for web application security. The OWASP Top Ten represents a broad consensus about what the most critical web application security flaws are. Project members include a variety of security experts from around the world who have shared their expertise to produce this list.

Download PDF

+5000 dorks for SQL injection

SQL injection is a code injection technique, used to attack data driven applications, in which malicious SQL statements are inserted into an entry field for execution (e.g. to dump the database contents to the attacker).SQL injection must exploit a security vulnerability in an application's software, for example, when user input is either incorrectly filtered for string literal escape characters embedded in SQL statements or user input is not strongly typed and unexpectedly executed. SQL injection is mostly known as an attack vector for websites but can be used to attack any type of SQL database.

Link:

Hacking web site with DarkMySQLi.py on BackTrack 5 R2

Link:

Hacking web site with sqlmap on BackTrack 5 R3 

Link:

+5000 dorks for SQL injection


Sunday, November 10, 2013

The Art of Exploitation, 2nd Edition

Hacking is the art of creative problem solving, whether that means finding an unconventional solution to a difficult problem or exploiting holes in sloppy programming. Many people call themselves hackers, but few have the strong technical foundation needed to really push the envelope.
Rather than merely showing how to run existingexploits, author Jon Erickson explains how arcane hacking techniques actually work. To share the art and science of hacking in a way that is accessible to everyone, Hacking: The Art of Exploitation, 2nd Edition introduces the fundamentals of C programming from a hacker's perspective.

This book will teach you how to:

1. Program computers using C, assembly language, and shell scripts

2. Corrupt system memory to run arbitrary code using buffer overflows and format strings

3. Inspect processor registers and system memory with a debugger to gain a real understanding of what is happening

4. Outsmart common security measures like nonexecutable stacks and intrusion detection systems

5. Gain access to a remote server using port-binding or connect-back shellcode, and alter a server's logging behavior to hide your presence

6. Redirect network traffic, conceal open ports, and hijack TCP connections

7. Crack encrypted wireless traffic using the FMS attack, and speed up brute-force attacks using a password probability matrix

Hackers are always pushing the boundaries, investigating the unknown, and evolving their art. Even if you don't already know how to program, Hacking: The Art of Exploitation, 2nd Edition will give you a complete picture of programming, machine architecture, network communications, and existing hacking techniques. Combine this knowledge with the included Linux environment, and all you need is your own creativity.

Download PDF

Refer To :  http://www.backtrack-pages.com

Wednesday, November 6, 2013

Mission-Critical Network Planning

Whether a terrorist attack, fibre cut, security breach, natural disaster or traffic overload, today's networks must be designed to withstand adverse conditions and provide continuous service. This comprehensive, leading-edge book reveals the techniques and strategies to help you keep enterprise data and voice networks in service under critical circumstances. You learn numerous ways to minimize single points of failure through redundancy and backups, and discover how to select the right networking technologies to improve survivability and performance.

Download PDF

Refer To: http://www.backtrack-pages.com

Hacker Techniques, Tools, and Incident Handling (Jones & Bartlett Learning Information Systems Security & Assurance Series)

Hacker Techniques, Tools, and Incident Handling begins with an examination of the landscape, key terms, and concepts that a security professional needs to know about hackers and computer criminals who break into networks, steal information, and corrupt data. It goes on to review the technical overview of hacking: how attacks target networks and the methodology they follow. The final section studies those methods that are most effective when dealing with hacking attacks, especially in an age of increased reliance on the Web. Written by a subject matter expert with numerous real-world examples, Hacker Techniques, Tools, and Incident Handling provides readers with a clear, comprehensive introduction to the many threats on our Internet environment and security and what can be done to combat them.

Download PDF


Refer To: http://www.backtrack-pages.com

Hackers: Heroes of the Computer Revolution


 This 25th anniversary edition of Steven Levy's classic book traces the exploits of the computer revolution's original hackers -- those brilliant and eccentric nerds from the late 1950s through the early '80s who took risks, bent the rules, and pushed the world in a radical new direction. With updated material from noteworthy hackers such as Bill Gates, Mark Zukerberg, Richard Stallman, and Steve Wozniak, Hackers is a fascinating story that begins in early computer research labs and leads to the first home computers.

Levy profiles the imaginative brainiacs who found clever and unorthodox solutions to computer engineering problems. They had a shared sense of values, known as "the hacker ethic," that still thrives today. Hackers captures a seminal period in recent history when underground activities blazed a trail for today's digital world, from MIT students finagling access to clunky computer-card machines to the DIY culture that spawned the Altair and the Apple II.

Download PDF

 Refer To: http://www.backtrack-pages.com

The Shell-coder's Handbook: Discovering and Exploiting Security Holes second Edition


 This much-anticipated revision, written by the ultimate group of top security experts in the world, features 40 percent new content on how to find security holes in any operating system or application
New material addresses the many new exploitation techniques that have been discovered since the first edition, including attacking "unbreakable" software packages such as McAfee's Entercept, Mac OS X, XP, Office 2003, and Vista
Also features the first-ever published information on exploiting Cisco's IOS, with content that has never before been explored
The companion Web site features downloadable code files


Download PDF

Refer To:  http://www.backtrack-pages.com

Secrets of a Super Hacker



Once more, Loompanics publishes something other houses wouldn't: a guide to violating computer security. Covering hacking scenarios ranging from the merely mischievous to the criminal, the super hacker known as the Knightmare gives step-by-step instructions in meaningful hacking from a personal computer. Fortunately, he also includes a section on state and federal computer laws, allowing potential hackers to be cognizant of the sanctions they risk with any particular project. Appendixes offer an array of technical explanations and tips for understanding database and system structures; tips cover password divination and searching strategies; and a glossary, besides explaining terms likely to be encountered in any particular documentation being hacked, enhances the hacker's ability to share experiences and tips. As science outstrips society's control of information, systems of secretkeeping proliferate maddeningly. Yet with this book, the keyboard jockey can enter all sorts of "secure" systems, databases, and records; and a hacker-security chapter explains both why hacking is a valuable and useful activity and--equally important because entering and altering systems without clearance is generally illegal--how to avoid getting caught. Mike Tribby




 
 

Hacking Vim 7.2

This book is a tutorial packed with ready-to-use hacks that give solutions for common problems faced by Vim users in their everyday life. Every chapter covers a set of recipes, each of which follows a systematic approach with a self-contained description of the task it covers, how to use it, and what you gain by using it. The minimum version of Vim required for each hack is clearly indicated.
If you are a Vim user who wants to get more out of this legendary text editor, this book is for you. It focuses on making life easier for intermediate to experienced Vim users.

Download PDF

Refer To : http://www.backtrack-pages.com



Tuesday, November 5, 2013

iOS Hacker's Handbook


Discover all the security risks and exploits that can threaten iOS-based mobile devices

iOS is Apple's mobile operating system for the iPhone and iPad. With the introduction of iOS5, many security issues have come to light. This book explains and discusses them all. The award-winning author team, experts in Mac and iOS security, examines the vulnerabilities and the internals of iOS to show how attacks can be mitigated. The book explains how the operating system works, its overall security architecture, and the security risks associated with it, as well as exploits, rootkits, and other payloads developed for it.

Covers iOS security architecture, vulnerability hunting, exploit writing, and how iOS jailbreaks work
Explores iOS enterprise and encryption, code signing and memory protection, sandboxing, iPhone fuzzing, exploitation, ROP payloads, and baseband attacks
Also examines kernel debugging and exploitation
Companion website includes source code and tools to facilitate your efforts

iOS Hacker's Handbook arms you with the tools needed to identify, understand, and foil iOS attacks.

Download PDF

Refer to : http://www.backtrack-pages.com

The Web Application Hacker's Handbook: Finding and Exploiting Security Flaws 2nd Edition

The Web Application Hacker's Handbook: Finding and Exploiting Security Flaws 2nd Edition
The highly successful security book returns with a new edition, completely updatedWeb applications are the front door to most organizations, exposing them to attacks that may disclose personal information, execute fraudulent transactions, or compromise ordinary users. This practical book has been completely updated and revised to discuss the latest step-by-step techniques for attacking and defending the range of ever-evolving web applications. You'll explore the various new technologies employed in web applications that have appeared since the first edition and review the new attack techniques that have been developed, particularly in relation to the client side.

Reveals how to overcome the new technologies and techniques aimed at defending web applications against attacks that have appeared since the previous edition
Discusses new remoting frameworks, HTML5, cross-domain integration techniques, UI redress, framebusting, HTTP parameter pollution, hybrid file attacks, and more
Features a companion web site hosted by the authors that allows readers to try out the attacks described, gives answers to the questions that are posed at the end of each chapter, and provides a summarized methodology and checklist of tasks

Focusing on the areas of web application security where things have changed in recent years, this book is the most current resource on the critical topic of discovering, exploiting, and preventing web application security flaws..


Download PDF



Refer to:  http://www.backtrack-pages.com

Friday, October 18, 2013

java-in-60-minutes-day-book

Java in 60 Minutes Day Ebook

 Java is a programming language and computing platform first released by Sun Micro systems in 1995. There are lots of applications and websites that will not work unless you have Java installed, and more are created every day. Java is fast, secure, and reliable. From laptops to data centers, game consoles to scientific supercomputers, cell phones to the Internet, Java is everywhere!  Author: Rich Raposa Features: A revolutionary virtual classroom Book Name: Java in 60 minutes a day
Introduction:
 Chapter 1: Getting Started with Java.
 Chapter 2: Java Fundamentals. 
 Chapter 3: Control Structures.
 Chapter 4: Classes and Objects.
 Chapter 5: Methods.
 Chapter 6: Understanding Inheritance.
 Chapter 7: Advanced Java Language Concepts.
 Chapter 8: Polymorphism and Abstraction. 
 Chapter 9: Collections.  Chapter 10: Interfaces.
 Chapter 11: Exception Handling.
 Chapter 12: An Introduction to GUI Programming.
 Chapter 13: GUI Components and Event Handling.
 Chapter 14: Applets.
 Chapter 15: Threads.
 Chapter 16: Input and Output.
 Chapter 17: Network Programming.
 Chapter 18: Database Programming.
 Chapter 19: JavaBeans.
 Appendix:  About the 60 Minutes Web Site.

Download

Wednesday, October 16, 2013

Using Google.com to Find Usernames + Passwords

 ဒီနည္းေလး ေတြက   Google  Dorks  ေတြ သံုး တဲ. နညး္လမး္ေလး ေတြပါ
အေျခ ခံ နညး္နည္း ၇ွိတဲ. သူေတြ နားလည္ မွာပါ

 Prerequisites:
 1. A modern webbrowser and a internet.
2. Time  Method

1: Facebook We will be using a google dork to find usernames and passwords of many accounts including Facebook! 
The Dork: intext:charset_ test= email= default_persist ent= 

Enter that into Google, and you will be presented with several sites that have username and passwords lists!

 Method 2: WordPress! This will look for WordPress backup files Which do contain the passwords, and all data for the site!
 The Dork: filetype:sql inurl:wp-conten t/backup-*

 Method 3: WWWBoard! This will look for the user and passwords of WWWBoard users  The Dork: inurl:/ wwwboard/ passwd.txt 

Method 4: FrontPage! This will find all users and passwords, similar to above. 
The Dork: ext:pwd inurl:(service | authors | administrators | users)"# -FrontPage-"

 Method 5: Symfony This finds database information and logins 
The Dork: inurl:config/ databases.yml -trac -trunk -"Google Code"-source -repository 

Method 6: TeamSpeak This will search for the server.dbs file  (A Sqlite database file With the SuperAdmin username and password) 
The Dork: server-dbs"intitle:index of" 

Method 7: TeamSpeak 2 This will find the log file which has the Super Admin user and pass in the Top 100 lines. Look for"superadmin account info:" 
 The Dork: "inurl:Teamspea k2_RC2/ server.log" 

Method 8: Get Admin pass Simple dork which looks for all types of admin info
 The Dork: "admin account info"filetype:log

 Method 9: Private keys This will find any .pem files which contain private keys. 
The Dork: filetype:pem pem intext:private  And the Ultimate one, the regular directory full of passwords.

 Method 10: The Dir of Passwords! Simple one! 

The Dork: intitle:"Index of..etc"passwd

 Refer to:
http://www.backtrack-pages.com

Thursday, October 3, 2013

ninja-hacking-unconventional

Ninja  Hacking Unconventional  Penetration Testing Tactics and Techniques

  About book  Ninja Hacking, the new book by Thomas Wilhelm and Jason Andress, is not a typical book about hacking andpenetration testing. Experienced penetration testers who want to learn cutting-edge penetration techniques will find few references to little-known penetration tools or techniques presented in bland technical format. The book doesn’t rely on pun-filled humor, either.  Ninja Hacking is targeted at individuals who have an interest in the warriors of feudal Japan and want a serious philosophical exploration on how those warrior’s techniques map into modern cyber-warfare. For penetration testers who want to know how to be Ninjas, Ninja Hacking creates a framework for becoming a feudal Japanesewarrior in cyberspace. Each chapter discusses a new piece of the puzzle, and, while you won’t achieve mastery from this book alone, the building blocks are laid that should allow an inspired reader to know what additional areas need to be researched.

Download

Sunday, September 8, 2013

vmware-workstation-1000-build-1295980

VMware Workstation 10.0.0 Build 1295980 Full Version + Keygen


နိုင္ငံျခား ဆိုက္ဒ္ တစ္ခုက ေတြလို. မလားတာ 


VM ware ဆိုတာေတာ. လူတိုင္းသိမွာ ပါ သူေပၚ မွာ OS  အမ်ိဳးစံု  run လို.၇တယ္  IOS ( Mac) ေတာင္  Virtual  hardware အစားထိုး ျပီး run လို. ၇တယ္လို. လည္း ေျပာျကတယ္ ဗ်  

တစ္ခု တစ္ခု ကို မသကၤာ လို. စမ္းမယ္ဆို၇င္လည္း အဲ ေပၚေတြမွာ တင္ထားတဲ. OS ေတြ နဲ. လည္း စမ္းလို.၇ပါတယ္ 

VMware Workstation 10.0.0 Build 1295980 Full Setup
link1
Download
link2
Download

VMware Workstation 10.0.0 Build 1295980 Full Keygen
Link1
Download
Link2
Download

Password:   www.saisoftwarecracks.com

Sunday, September 1, 2013

Ankit Fadia Hacking Book Collections

အဲထဲ က exe application ကို run ျပီးမွ စာအုပ္ေတြ ဖတ္လို. ၇တယ္ ဗ်


ကၽြန္ေတာ္လည္း အစ က  နည္းနည္း ေျကာင္ သြားတယ္   ေျပာေတာ. စာအုပ္ဆိုျပီး ျပီးမွာ exe  ျကီးနဲ.


ဒါေပမဲ. အထဲ မွာမွ  စာအုပ္ေတြ


လိုခ်င္၇င္ေတာ.

Download

exe ျဖစ္ေနတာနဲ. မသကၤာလုိ. စစ္ထားတယ္


VirusTotal:

Scan link


လုိခ်င္၇င္ေတာ. ယူမလုိခ်င္၇င္ေတာ.  As you like  ဘဲ

အေနာ္က ၇ွာေတြ.လုိ. ျပန္၇ွယ္ ယံုဘဲ


Wednesday, August 28, 2013

Hcon Security Testing Framework (HconSTF)

၇ွည္၇ွည္ေ၀း ေ၀း ေတာ. မေျပာခ်င္ေတာ. ပါ ၀ူး

အေနာ္ အခု လက္၇ွိ  သံုးျဖစ္ေနတဲ.    browser ေလးပါ add on ေပါငး္ 89 ခုပါတယ္ ေတာ္ေတာ္လည္း စံုတယ္   hacking နဲ. security ေလ.လာေနတာ သူေတြလညး္ သံုးသင္.တယ္လို .ထင္တယ္
သူက ထက္၀က္ေလာက္ ကို File size ခ်ဳပ္ေပးထား  ပါတယ္
Direct Download Links

For Window  Download  
For  Linux x86 
For Linux x64

(အေပၚ က ေဒါင္းေလာ. လင္. ထဲက ဟာေတြက error တက္ေနတယ္ ေျပာလုိ. အေနာ္ ဆီမွာ ၇ွိတဲ. ဟာေလး ျပန္ တင္ေပးလိုက္ပါတယ္)

Download

Sunday, August 18, 2013

How to install Armitage in Window

ကၽြန္ေတာ္. ၇ဲ .ပထမဆံုး စာအုပ္ေလးပါ အားေပးျကပါအံုး
h4ck3r ေတြ overflow ထိုး ၇င္သံုးေနျက MSF  tools ေလးကို GUI အျဖစ္ေျပာင္းထားတဲ. Armitage ေလးကို window မွာ တင္သံုးနည္းေလး ပါ  ဆက္လက္ေလ.လာ နိုင္ေအာင္လည္း  tut လမ္းညြန္း ေလးေတြလည္း ထည္.ေပးထားပါေသးတယ္

DropBox:
Download
UploadMb:
Download

TuT:  How to hacke window server 2003  with armitage