Pages

Saturday, 7 December 2013

Remove Write Protection On USB Pen Drive or Memory Card

Write Protection on any portable USB Device can be applied by the physical lock provided on the card adjuster or some times provided on the pen drives, so make sure to make your drive not write protected by moving the lock in right direction.
But even after moving the physical lock for write protection the problem can happen due to some virus action. This happens when some virus or script which applies the registry hack to make any drive write protect when connected to the computer, In that case follow the procedure below to remove write protection from your pen drive.

First Method

1. Open Start Menu >> Run, type regedit and press Enter, this will open the registry editor.
2. Navigate to the following path:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\StorageDevicePolicies

Note: If the registry key StorageDevicePolicies key does not exist, you will need to create it
Download this batch file called add.bat from here, and double click after download the key will be automatically added to registry.
3. Double click the key WriteProtect in the right pane and set the value to 0 in the Value Data Box and press OK button
4. Exit Registry, restart your computer and then again re-connect your USB pen drive on your computer. That is it, done.
In case you still find an issue, please leave a comment below.

 Second Method

 Second method which you can follow to solve the �Pen Drive is Write Protected� problem.
If the above method does not work for you, follow the below steps:
1. Copy all the important data from this drive to your computer because this method will format the drive and erase all the data on the pen drive.
2. Now download the Apacer Formatting Utility, Unzip this utility to a folder on your hard disk, preferably on a folder on desktop screen for easy access (Do Not Try To Save it on pen drive). Keep your pen drive plugged in, and double click on the Start.bat file in the folder where you unzipped the above utility. This will start formatting your pen drive, wait till the formatting completes and the LED on your pen drive stops blinking. Remove your pen drive after than and plug it in again.
The above two steps will solve the problem. If you still face the problem, follow the below steps:
1. Goto Start > Run, type cmd and press enter, this will open command prompt.
2. Type the following command on the command prompt replacing X with the drive letter of your pen drive.
CHKDSK X: /F
The above two methods will help you fix the problem.

Make VLC run in Backtrack 5 - Fix for running VLC Under root

Was playing with some weird things under backtrack and when installed a good player named as VLC for playing some songs formatted as .flv , I got amused that it wasn't running and nothing happened also not a single error. Just a peaceful screen on clicking the VLC player under the application menu. Some entertainment was necessary so this made me feel angry that's why I started to search out for a fix to made it run. Then I came up to terminal and tried to run that without graphical interface and came with an error which had a theme like this:-

    "Unable to run VLC under the root, Try other way to run as unprivileged user."

Thus, I thought to tried to sort this problem. Lets go with step by step process. Don't panic there is not much tedious process to follow. As most of the common users find linux to be weird than Windows.
How to Install VLC under Linux:-

Go to terminal and type this command:-

sudo apt-get install vlc

If it asks for password then write and press enter. Under the same terminal it will start installing vlc media player. (You need to be connected to internet. If not then download the vlc media player and place that in that pc where there is no internet) when you type the password there will be no characters shown so don't worry just write and hit enter.
Fix to make vlc run under Bactrack - Making VLC run under the root:-

    Open the terminal.
    Write this command and hit enter

        hexedit /usr/bin/vlc

    Press tab and you will see that blinker has been shifted to the 2nd group.
    Find this geteuid._libc_start_man by scrolling the mouse wheel or else pushing the down button; and replace with this getppid.libc_start_man(i-e you just have to change the word take the pointer there and then just write; and you will see that alphabets different from the already there will start getting replaced by newly typed)
    After done press ctrl+s and type y (means yes). You are done.

    In the same terminal type vlc and hit enter. Woa! It runs now. Tune the speakers and let rocks

Friday, 6 December 2013

How do I use a Proxy Server?

Please be aware that the use of proxy servers without the express permission from the owner of the proxy server may be illegal in some states and/or countries. Use at your own risk.
Use your favorite search engine and search for 'proxy server list'. You'll find many sites with lists of proxy servers, their IP address, the port they listen on, and usually what country they are in. Write down a few of them.
You may see references to four different types of proxy servers:
Proxy server list 

Transparent Proxy

This type of proxy server identifies itself as a proxy server and also makes the original IP address available through the http headers. These are generally used for their ability to cache websites and do not effectively provide any anonymity to those who use them. However, the use of a transparent proxy will get you around simple IP bans. They are transparent in the terms that your IP address is exposed, not transparent in the terms that you do not know that you are using it (your system is not specifically configured to use it.)

Anonymous Proxy

This type of proxy server indentifies itself as a proxy server, but does not make the original IP address available. This type of proxy server is detectable, but provides reasonable anonymity for most users.

Distorting Proxy

This type of proxy server identifies itself as a proxy server, but make an incorrect original IP address available through the http headers.

High Anonymity Proxy

This type of proxy server does not identify itself as a proxy server and does not make available the original IP address.
Please make sure to read about anonymous proxy risks before using a proxy server.
If you need further assistance using proxy servers please post a question in the proxy server forum.

Browser Settings

How to Use?
Mozilla is the famous browser. So i will explain how to use the proxy servers in Mozilla.

Open Mozilla FireFox.
Select Tools from menu bar(or simply press ALT+T)
Click the Options
Small window Will Open.
Navigate to Advanced tab
Click Settings.
Now select the Manual Proxy Configuration Radio Button.

Paste the one of the Ip address of Proxy server and set the Port as defined in the list.
For Eg:
Let's take this proxy
058.056.108.114:80
Here ip address is 058.056.108.114
Port no is :80
That's all click ok.
Now to check the whether your ip address is changed or not, visit "www.whatismyipaddress.com".


All Saved Password Location


Google Chrome:

Chrome Passwords are stored in a SQLite file the sites name and sites username is in clear text but the password is seeded in a Triple DES algorithm. The file is called Web Data and is stored in the following location


XP � C:\Documents and Settings\Username\Local Settings\Application Data\Google\Chrome\User Data\Default

Vista � C:\Users\Username\Appdata\Local\Google\Chrome\User Data\Default


Trillian:

Note- I have just realised the new version of trillian the passwords made be stored/encrypted differently.

Trillian Passwords are stored in .ini files the first character of the password is encrypted with XOR with the key 243 then the password is converted into hex. The file is based on what the password is for so if it was icq it would be icq.ini (for new versions I think they are all stored in a file called accounts.ini or something similar if you open it up with notepad you will see all the data + the encrypted password). The files are stored in the following location:

XP (old version) � C:\Program Files\Trillian\users\

XP (new version) � C:\Documents and Settings\Username\Local Settings\Application Data\Trillian\user\global � I am not sure on exact but it is somewhere there.

Vista (old version)- C:\Program Files\Trillian\users\

Vista (new version)- C:\Users\Username\Appdata\Roaming\Trillian\user\gl obal



MSN /Windows Live Messenger:

MSN Messenger version 7.x: The passwords are stored under HKEY_CURRENT_USER\Software\Microsoft\IdentityCRL\C reds\[AccountName]

Windows Live Messenger version 8.x/9.x: The passwords are stored in the Credentials file, with entry name begins with �WindowsLive:name=�. They a set of Win API functions (Credential API�s) to store its� security data (Credentials). These functions store user information, such as names and passwords for the accounts (Windows Live ID credentials). Windows Live ID Credential records are controlled by the operating system for each user and for each session. They are attached to the �target name� and �type�. If you are familiar with SQL you can think of target name and type as the primary key. Table below lists most frequently used fields in Windows Live ID Credential records.



Paltalk:

Paltalk Passwords are using the same password encryption algorithm. Paltalk passwords are stored in the registry. To encrypt the new password Paltalk looks at the serial number of the disk C:\ and performs a mix with the Nickname. The resulting string is then mixed again with the password and some other constants. The final string is then encoded and written to the registry.

AIM, ICQ and Yahoo Messenger passwords that are stored by Paltalk are encoded by BASE64 algorithm.

The passwords are stored in the Registry, under HKEY_CURRENT_USER\Software\Paltalk\[Account Name]



Google Talk:

Google Talk passwords are encoded/decoded using Crypto API. Encrypted Gmail passwords are stored by Google Talk in the registry under HKEY_CURRENT_USER\Software\Google\Google
Talk\Accounts\[Account Name]



Firefox:

The passwords are stored in one of the following filenames: signons.txt, signons2.txt, and signons3.txt (depends on Firefox version)
These password files are located inside the profile folder of Firefox, in [Windows Profile]\Application Data\Mozilla\Firefox\Profiles\[Profile Name]
Also, key3.db, located in the same folder, is used for encryption/decription of the passwords.



Yahoo Messenger 6.x:

The password is stored in the Registry, under HKEY_CURRENT_USER\Software\Yahoo\Pager
(�EOptions string� value)



Yahoo Messenger 7.5 or later:

The password is stored in the Registry, under HKEY_CURRENT_USER\Software\Yahoo\Pager � �ETS� value.
The value stored in �ETS� value cannot be recovered back to the original password.



AIM:

AIM uses Blowfish and base64 algorithms to encrypt the AIM passwords.
448-bit keyword is used to encrypt the password with Blowfish. The encrypted string is then encoded using base64. The passwords are stored in the Registry, under HKEY_CURRENT_USER\Software\America Online\AIM6\Passwords



Filezilla:

Passwords are stored in a .xml file located in Filezilla on appdata their is sources for this



Internet Explorer 4.00 � 6.00:

The passwords are stored in a secret location in the Registry known as the �Protected Storage�.
The base key of the Protected Storage is located under the following key:
�HKEY_CURRENT_USER\Software\Microsoft\Protected Storage System Provider�.

You can browse the above key in the Registry Editor (RegEdit), but you won�t be able to watch the passwords, because they are encrypted.
Also, this key cannot easily moved from one computer to another, like you do with regular Registry keys.



Internet Explorer 7.00 � 8.00:

The new versions of Internet Explorer stores the passwords in 2 different locations.
AutoComplete passwords are stored in the Registry under HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\IntelliForms\Storage2.

HTTP Authentication passwords are stored in the Credentials file under Documents and Settings\Application Data\Microsoft\Credentials , together with login passwords of LAN computers and other passwords.



Opera:

The passwords are stored in wand.dat filename, located under [Windows Profile]\Application Data\Opera\Opera\profile



Outlook Express (All Versions):

The POP3/SMTP/IMAP passwords Outlook Express are also stored in the Protected Storage, like the passwords of old versions of Internet Explorer.



Outlook 98/2000:


Old versions of Outlook stored the POP3/SMTP/IMAP passwords in the Protected Storage, like the passwords of old versions of Internet Explorer.



Outlook 2002-2008:

All new versions of Outlook store the passwords in the same Registry key of the account settings.

The accounts are stored in the Registry under HKEY_CURRENT_USER\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\[ProfileName]\9375CFF0413111d3B88A00104B2A6676\[Account Index]

If you use Outlook to connect an account on Exchange server, the password is stored in the Credentials file, together with login passwords of LAN computers.



ThunderBird:

The password file is located under [Windows Profile]\Application Data\Thunderbird\Profiles\[Profile Name]
You should search a filename with .s extension.



Digsby:

The main password of Digsby is stored in [Windows Profile]\Application Data\Digsby\digsby.dat
All other passwords are stored in Digsby servers.

 

Tuesday, 3 December 2013

Hide multiple files into a single .jpg file

Hide multiple files into a single .jpg file

 

 What I am going to tell about hiding multiple files into a single .jpg file, tis process is known as Binding, which most of us get confused with Steganography.

I  am going to explain how to bind files to a single image file.
                                                                                                                                    Steps involved:

  1. Compress the files as a single rar file and name give an appropriate name (hide.rar in my case)
  2. Copy the Image file (Image.jpg) and the rar file to the same folder
  3. In the command prompt, use the following command: Copy /b Image.jpg + hide.rar HiddenImg.jpg
  4. Now if you double click on the HiddenImg.jpg you would see the image as of the Image.jpg
  5. Now open in WinRar and you would find all the files under the Hide.rar
I have two documents file and an Image file.
This technique is also used by hackers to attack a remote computer.

 

Monday, 2 December 2013

Bypass Phone and SMS verification of Any Website

Bypass Phone and SMS verification of Any Website

Virus to Format Hard Disk

Virus to Format Hard Disk !!!

 

 Today i will show you how to make a virus to format Hard disk. You can send this file to your friend or enemy to format their Hard disk. But please dont try this on your own computer or else you will end up formatting your own/other computer.

 


 Copy the below codes into Notepad

                        0100101100011111001001010101010101000001111110000      

   Save the file as Format.exe
          You have created your virus..............
Enjoy It.........