Saturday, 22 December 2012

ႏွစ္သစ္ကူးကာလတြင္ အသစ္ထည္႔သြင္းလိုက္ေသာ Facebook privacy shortcuts မ်ားအေၾကာင္း

 
Facebook ဟာ သံုးစြဲသူမ်ားရဲ႕ မွ်ေ၀တဲ႔ ဓာတ္ပံုေတြ ႏွင္႔ update status လံုၿခံဳေရးကို အရိုးရွင္းဆံုးနဲ႔ အလြယ္ကူဆံုးအေထာက္အကူၿပဳႏိုင္မဲ႔ privacy shortcuts မ်ားကို ထည္႔သြင္းေပးထားတာေတြ႔ရမွာပါ။

ဒီလို privacy shortcuts မ်ားကို US က user မ်ားထံ စတင္ထည္႔သြင္းေပးခဲ႔ျပီး အခုအခ်ိန္မ...ွာေတာ႔ ကမၻာတစ္၀န္းလံုးမွာ ရိွတဲ႔ user ေတြအတြက္ပါ ထည္႔သြင္းေပးလိုက္ပါျပီ။

ဒါေၾကာင္႔ အသစ္ထည္႔သြင္းထားတဲ႔ Facebook privacy shortcuts ေတြရဲ႕ အသံုး၀င္မႈေတြကို NOM Fans ေတြအတြက္ ေဖာ္ျပေပးလိုက္ပါတယ္။

-Blocking

Facebook မွာ မိမိကို စိတ္အေႏွာက္အယွက္ၿဖစ္ေနတဲ႔ သူေတြ၊အဆက္အသြယ္မလုပ္လိုတဲ႔ သူေတြကို Block ခ်င္ရင္ အရင္လို setting ထဲကေန အရွည္ၾကီး ၀င္ေနစရာ မလိုေတာ႔ပါဘူး။

Facebook Privacy shortcuts pop-up box ကေလးကို ႏိွပ္ျပီး တတိယအေၾကာင္းမွာ မိမိ Block လိုတဲ႔ user ရဲ႕ နာမည္(သို႕)သူ႔ရဲ႕ email လိပ္စာကို ရိုက္ထည္႔လိုက္ရံုပါပဲ။

ဒါ႔အၿပင္ သင္ယခင္က block ထားတဲ႔ သူေတြရဲ႕ စာရင္းကိုၾကည္႔ႏို္င္ဖို႔ View All Blocked Users ဆိုတာကိုပါ ထည္႔သြင္းေပးထားတာေတြ႔ရပါတယ္။

-Privacy Shortcuts

Facebook Privacy shortcuts pop-up box ရဲ႕ ပထမအေၾကာင္းၿဖစ္တဲ႔ "who can see my stuff?" ဆိုတဲ႔ စာေၾကာင္းကို click ႏိွပ္လိုက္ပါ။

Who can see my future posts? ဆိုတဲ႔ ေနရာမွာ သင္႔ရဲ႕ post အသစ္အကုန္လံုးကို ဘယ္လို လံုၿခံဳေရးထားခ်င္သလဲဆိုတာကို မူတည္ျပီး လြယ္ကူစြာ ထိန္းခ်ဳပ္ႏိုင္ေအာင္ လုပ္ထားေပးတာၿဖစ္ပါတယ္။

ေနာက္ Facebook Privacy shortcuts pop-up box ရဲ႕ "who can see my stuff?" ဆိုတဲ႔ စာေၾကာင္းမွာရိွတဲ႔ ဒုတိယ အေၾကာင္းၿဖစ္တဲ႔ Where can I review all my posts and things I'm tagged in? ဆိုတဲ႔ေနရာမွာေတာ႔ သင္မတင္ခဲ႔ဘဲ Tag လုပ္ခံထားရတဲ႔ ပံုေတြ စာသားေတြကို ပါ ထိန္းခ်ဳပ္တာဖ်က္ပစ္လို႔ရမွာၿဖစ္ပါတယ္။

ျပီးေတာ႔ သင္မလိုေတာ႔တဲ႔ အတိတ္က ပိုစ္႔အကုန္လံုးကို တစ္ေနရာထဲကေန ဖ်က္ပစ္ႏိုင္မွာပါ။

Facebook Privacy shortcuts pop-up box ရဲ႕ "who can see my stuff?" ဆိုတဲ႔ စာေၾကာင္းမွာရိွတဲ႔ တတိယ အေၾကာင္းၿဖစ္တဲ႔What do other people see on my timeline? ဆိုတဲ႔ လံုၿခံဳေရးအတြက္ အသံုး၀င္ပံုအေၾကာင္းကို ရွင္းၿပသြားပါမယ္။

မိမိရဲ႕ Profile ကို မည္သူက ၀င္ၾကည္႔ရင္ ဘယ္လိုေပၚေနလဲ ဆိုတာ သိခ်င္ၾကပါတယ္။ ဒါေၾကာင္႔ "who can see my stuff?" ဆိုတဲ႔ စာေၾကာင္းမွာရိွတဲ႔ တတိယ အေၾကာင္းၿဖစ္တဲ႔What do other people see on my timeline? ကို၀င္ျပီး View As ကို ႏိွပ္လိုက္ပါ။

ဒါဆိုရင္ သင္႔ရဲ႕ profile ကို ေပၚလာျပီး This is what your timeline looks like to: ဆိုတဲ႔ေနရာမွာ မိမိသိလိုတဲ႔ သူငယ္ခ်င္းနာမည္ကို ရိုက္ထည္႔လိုက္ရံုပါပဲ။

အခုေျပာျပမွာကေတာ႔ ေနာက္ဆံုးအခ်က္ပါ။

Facebook Privacy shortcuts pop-up box ကေလးကို ႏိွပ္ျပီး ဒုတိယအေၾကာင္းၿဖစ္တဲ႔ "who can contact me" ကို click လိုက္ပါ။

ပထမဆံုးအေၾကာင္းၿဖစ္တဲ႔ Whose messages do I want filtered into my Inbox? ဆိုတာကေတာ႔ မိမိကို message ေပးပို႔ေနတဲ႔ သူေတြကို ထိန္းခ်ဳပ္ႏိုင္ဖို႔ ထည္႔သြင္းေပးထားတာပါ။

ဒုတိယအေၾကာင္းၿဖစ္တဲ႔ Who can send me friend requests? ဆိုတာကေတာ႔ ဘယ္သူေတြက သူငယ္ခ်င္းၿဖစ္ခြင္႔ ပို႔လို႔ရေအာင္ ထိန္းခ်ဳပ္မလဲဆိုတာပဲၿဖစ္ပါတယ္။

ဥပမာအေနနဲ႔ ေျပာရရင္ မိမိနဲ႔ သူငယ္ခ်င္းၿဖစ္လိုသူၾကားမွာ ၾကားခံသူငယ္ခ်င္း(Mutual) မရိွရင္ friend request ဆိုတဲ႔ button ကို ႏိွပ္ခြင္႔ေပးဖို႔ ေနေနသာသာ တဘက္လူက buttomကို ရွာလို႔ ရမွာေတာင္မဟုတ္ပါဘူး။
××××××××××××××××××××××××××××××××××××××

Credit: NewsOfMyanmar

Friday, 21 December 2012

Brutus Password Cracker

ကဲ့ Brutus Password Cracker ေလးတင္ေပးလိုက္ပါျပီ.. .. သံုးပံုသံုးနည္းေလး သိေလာက္မွာပါ .. :D
Brute-force Attacks ဟာ Password အမွန္ကိုမေတြ ့မခ်င္း ျဖစ္ႏိုင္ေခ်ရွိတဲ့ letters ေတြ . number ေတြ Special Character ေတြရဲ ့ တြဲစပ္ျပီး ရွာေပးပါတယ္.. Brute force Attack ဟာ အခ်ိန္မ်ားစြာ ျကာႏိုင္ပါတယ္. ျကာျမင့္ခ်ိန္ဟာ pass ရဲ ့ ရွုပ္ေထြးမွဳ ၊ Cracking Program ကုိ Run ေနတဲ့ ကြန္ပ်ဴတာ ၇ဲ ့Speed ေတြေပၚမွာ မူတည္ပါတယ္.. သံုးပံုသံုးနည္းေတာ့ သိေလာက္မယ္ ထင္ပါတယ္.. DOwn link ေတြ Google မွာ ပလူကိုပ်ံေနတာဘဲ ... ဒီထဲက တခုေပးလိုက္ပါတယ္..  >
 bru Brutus Password Cracker
Download link > http://www.hoobie.net/brutus/brutus-download.html

Google Book Downloader

ဒီ Software ေလးက GoogleBook ဆိုတဲ့အတိုင္း. . Google က Book ေတြကိုေဒါင္းလို ့ရပါတယ္ :P 
တခုေျပာခ်င္တာ. ဒီ Software ေလးကိုVirusစစ္ျပီးမွ သံုးေစခ်င္တယ္.. ဒင္းတို ့ကသိတယ္မလား :P :D က်ြန္ေတာ္စစ္ေပးမလို ့လိုင္းကထင္သေလာက္မေကာင္းလို ့ပါ :D
google+book+downloader Google Book Downloader
Download

Site Restoration ( Security tips )

အေတာ္မ်ားမ်ား ဘေလာ့ေတြ/ဆိုက္ဒ္ေတြေထာင္လာၾကတယ္ ၿပီးေတာ့အနည္းနဲ ့အမ်ား အဟက္ခံရတယ္ဆိုပါေတာ့ဗ်ာ... အဲ့တာဆို malicious file/code ေတြကို ရွာမည့္ tips အနည္းငယ္ကို ေဖာ္ၿပမွာၿဖစ္ပါတယ္. အလံုးစံုေတာ့မဟုတ္ေပမယ့့္္ ဒါေလးေတြလည္း သိသင့္တယ္ထင္လို ့တင္ေပးလိုက္ပါတယ္. ဒါကိုသိမွ သူတို ့ဒီလိုလုပ္တတ္တယ္ဆိုပီး ကိုယ္က ထပ္လူလည္က် ဖို ့ စဥ္းစားေပါ့... .

1) မိမိ ဆိုက္ဒ္ အဟက္ခံရတယ္ဆိုပါေတာ့ deface တင္ခံရပီဆိုရင္ေတာ့ shell ပါတင္ခံလိုက္ရဒယ္ ေပါ့ ဒါဆို မ်ားေသာအားၿဖင့္ hacker ေတြ shell တင္တတ္တဲ့ေနရာေလးေတြ ကိုယ့္ဘာသာ manual လိုက္ရွာၾကည့္ၾကေပါ့ ဥပမာ.
/image /admin/ /themes/ /cgi/ etc... ဒီလိုေနရာေလးေတြေပါ့..

2) မိမိဆိုက္ဒ္ အဟက္ခံလိုက္ရတယ္ဆိုရင္ေတာ့ မိမိ blog / site ရဲ ့ application (cms level vul: ) ကို ရွာရေတာ့ပါမယ္. ခုဟက္ကင္း နယ္ပယ္ထဲကလူေတြ ေထာင္ထားတယ္ဆိုေတာ့ ဟက္ကာေတြရဲ ့နည္းလမ္းေတြကိုပိုၿပီး သိရွိၾကမယ္ထင္ပါတယ္. ဥပမာ. i.e XSS, RFI , LFI , SQLi --> most common
အဲ့လုိနည္းေတြ ၿဖစ္နိုင္လား စ႕ဥ္းစားရပါမယ္.

Still NOTHING?

ဒါဆိုရင္ေတာ့ ဆာဗာကို သံသယၿဖစ္ရပါေတာ့မယ္ မိမိဆိုက္ဒ္ကို support ေပးထားတဲ့ ဟို ့စ္ကိုက security weak မယ္ဆိုရင္ေတာ့ အတတ္နိုင္ဆံုး သိသမွ်မွတ္သမွ်ေတြရွာေဖြပီး မိမိအတြက္အေကာင္းဆံုးကာကြယ္မွဴေလးေတြလုပ္ရပါမယ္ .
တစ္ခုသိထားရမွာက
Don't forget that if the attacker found a way to get in YOU CAN TOO !!

3) တကယ္လို ့ ဟို ့စ္က terminal (ssh) support ေပးထားတယ္ဆိုရင္ေတာ့ terminal(ssh) ကေန ဒီလိုေလးရိုက္ပီး စစ္ၾကည့္ရပါမယ္.
Code:
grep -RPl --include=*.{php,txt,asp} "(passthru|shell_exec|system|phpinfo|base64_decode|chmod|mkdir|fopen|fclose|readfile) *\(" /var/www/
cmd code အလုပ္လုပ္ပံုေတြက
  • php,txt,asp extension ရွိတဲ့ဖိုင္ေတြကိုစစ္မယ္. (ထပ္ထည့္လို ့ရပါေသးတယ္)
  • pattern string ဆင္တူၿဖစ္တဲ့ "passthru", shell_exec etc အစရွိတာေတြကို ရွာပါမယ္
  • ေနာက္ဆံုးနားေလးက code ကေတာ့ /var/www/ directory ေအာက္က ဖိုင္ေတြကိုစစ္မယ္ဆိုတဲ့သေဘာပါ (မိမိဆိုက္ဒ္တစ္ခုလံုးပါပဲ)


4) တကယ္လို ့မိမိကသာ ဟို ့စ္ဆာဗာ တစ္ခုလံုးပိုင္တယ္ ၿပီးေတာ့ ဟက္ကာက လည္း root လုပ္သြားတယ္ဆိုရင္ေတာ့ မိမိ ဆာဗာရဲ ့ kernal version ကိုၿမွင့္ေပးရပါမယ္. root user/pass ခက္ခက္ေတြၿပန္ထားမယ္ ၿပီးေတာ့ account အသစ္ေတြသြင္းထားပါက အသစ္ေတြကိုဖ်က္မယ္ေပါ့ ... ၿပီးေတာ့ backdoor အေနနဲ ့ port အသစ္နဲ ့ ssh backdoor လုပ္ထားသလားဆိုပီး မိမိဆာဗာ port ေတြကိုၿပန္စစ္ရပါမယ္.

Trolling the hacker:

က်ေနာ္တို ့ ဆိုက္ဒ္ေတြရဲ ့ default homepage ေတြဟာ မ်ားေသာအားၿဖင့္ ဒီလိုေတြပါ.

IIS: default.asp/.aspx
Apache:Index.php/.html

> Apache မွာဆိုရင္ေတာ့ .htaccess ကိုကြန့္ပီး ဟက္ကာ index.php လုပ္ေတာင္ home page က သပ္သပ္တတ္မွာဖစ္ပါတယ္. (that's trolling ) နဲနဲေတာ့ လည္သြားမယ္ေပါ့ ဟက္ကာ
http://www.javascriptkit.com/howto/htaccess6.shtml

> နမူနာအေနနဲ ့ ဥပမာ မိမိဆိုက္ဒ္ရဲ ့ index page ကို 12d9au.html ထားလို္က္မယ္. ဒါဆို တကယ္လို ့ဟက္ကာက index.php/index.html ဆိုပီး homepage ကိုဒီေဖ့မယ္လုပ္လည္း homepage က 12d9au.html အၿဖစ္နဲ ့ .htaccess ထဲမွာေရးထားတဲ့အတြက္. deface home page အၿဖစ္ရွိမွာမဟုတ္ပါဖူး ... လာေဖာက္တဲ့ ဟက္ကာ အူေၾကာင္က်ား ဖစ္သြားပါလိမ့္မယ္. 99% of hackers ဆိုပဲ

credit: Suriya Team Indishell
 
 MYANMAR VERSION > BiG bOss(MHU-TEaM)

Thursday, 20 December 2012

How to Find who unfriends You in Facebook?

ဒီနည္းေလးက  Facebook မွာ ကိုယ့္ကိုဘယ္သူ unfriend ဘယ္ႏွစ္ေယာက္လုပ္ထားလဲျကည့္လို ့ရပါတယ္.. http://www.outandin.info ထဲ ၀င္ျပီး login with facebook ကိုုႏိုပ္ျပီးအဆင့္ဆင့္လုပ္သြားလိုက္ပါ ... :D


က်န္းး ျကည့္ခ်မ္းး နာ့ကိုလူခ်စ္လူခင္မ်ားတာ.. တေယာက္ Unfriend မလုပ္ထားဘူး :D Have Fun :)

How to Hijack Domain ?

    How to Hijack Domain တဲ့.. စိတ္၀င္စားတာနဲ ့တင္ေပးလိုက္ပါတယ္ :D Have Fun ! :)

Hide your Video or Audio File Behind Image

ခုဟာက OmhiHide Pro ေလးနဲ ့မိတ္ဆက္လိုက္ပါျပီ.. သူကိုယ့္ powerful data-hiding လို ့ေခၚျကတယ္..ကိုယ့္အတင္းေရး (အဲ့) အတြင္းေ၇း ေတြ ကို Hide လုပ္၇ာမွ အလြန္အသံုး၀င္မွာပါ .. သူ ့လုပ္ပံုလုပ္နည္းေလးကို သူ ့၇ဲ ့Offlical Website မွာသြားျကည့္ျပီး ေဒါင္းႏိုင္ပါတယ္... :D
omni Hide your Video or Audio File Behind Image

How to Hack Admin Password from Guest Account?

ဒီနည္းက Internet ဆိုင္မွာသံုးတဲ့ သူငယ္ခ်င္းေတြအတြက္.. တခုေျပာခ်င္တာက
" မလိုအပ္ဘဲ သူမ်ားစီးပြားေ၇းကိုမထိခိုက္ပါနဲ ့ "

Command Prompt on Logon Screen .. .. ..

For XP User > C:/windows-system32 ထဲ၀င္ျပီး cmd.exe ကို COpy ယူျပီး Desktop ထဲ Paste လိုက္ပါ ။ ျပီး၇င္ sethc.exe လို ့နာမည္ ေျပာင္းလိုက္ပါ ။ ျပီး၇င္ system32 မွာ Paste Again လုပ္ပါ ။ အကယ္၍ windows က overwriting the file ေမးခဲ့မယ္ဆို၇င္ yes ႏိုပ္လိုက္ပါ .ျပီး၇င္ Guest Account ကို Log out လုပ္ပါ ျပီး၇င္ window ႏိုပ္ျပီး shift key ကို 5 ျကိမ္ (Or) Left (ALT+Shift+ Num Lock).... .... .... (windows 7 မွာလုပ္နည္းနဲ ့တခါထဲဆက္ေပါ့မယ္)

For Windows 7 User > sethc.exe ကိုရွာပါ . ရွာျပီး Right click ျပီး Run as administrator နဲ ့ေမာင္းပါ ။
1 How to Hack Admin Password from Guest Account
ျပီး၇င္ sethc.exe ကို Right Click ႏိုပ္ျပီး propertiesကို ႏိုပ္ပါ ။ ျပီး၇င္ Security Tab ကိုသြားျပီး ပံုမွာျပထားတဲ့ အတိုင္း Advanced ကိုႏိုပ္ပါ ... ... 
3 How to Hack Admin Password from Guest Account
 ျပီး၇င္ Current user ကုိယ္သံုးေနတဲ့ USer ေပါ့ .. အဲ့ဒါကို Select လုပ္ပါ ျပီးရင္ Change Permissions ကို ထပ္ႏိုပ္ပါ ။
4 How to Hack Admin Password from Guest Account

 ျပီး၇င္ Edit လုုပ္ပါ ။











5 How to Hack Admin Password from Guest Account
ျပီးရင္ Permission Entry for sethc ဆိုတဲ့ BOX က်လာလိမ့္မယ္ .. ဒီလိုဆို ၇င္ Full Control ေဘးနားက Checkbox မွာ အမွန္ေလးျခစ္ျပီး Okey ေပါ့ :D

6 How to Hack Admin Password from Guest Account
ျပီး၇င္ New Sethc.exe ကို system32 မွာ Copy And Replace ေပါ့ :D
7 How to Hack Admin Password from Guest Account
ျပီး၇င္ ကိုယ့္ PC ကို Restart ခ်လိုက္ပါ ။

Resetting the Password !

Reset ခ်မွာေပါ့ .. the login screen ေပၚလာ၇င္ Shift key မွာ 5ျကိမ္ႏိုပ္ပါ .ဒီလိုႏိုပ္လိုက္ရင္ administrator mode command prompt ေပၚလာပါလိမ့္မယ္...
Now to reset the password—> ျပီး၇င္ ေအာက္မွာျပထားတဲ့ Command ကို အသံုးျပဳျပီး Change လိုက္ပါ ..

Command : net user account.name *
ဥပမာ : net user liT2ledR.beat * 
ကုိႏိုပ္ပါ .. ဒါဆို ကိုယ္ျကိုက္တဲ့ Password နဲ ့၀င္ေပေတာ့ :D
8 How to Hack Admin Password from Guest Account
Have Fun >> :)  Credit ; - hackingarticles.in 
     Myanmar Version ;- liT2le.blogspot.com 

Best SQL Injection Tools

Havij SQL Injection
 


Havij is an automated SQL Injection tool that helps penetration testers to find and exploit SQL Injection vulnerabilities on a web page.The power of Havij that makes it different from similar tools is its injection methods. The success rate is more than 95% at injectiong vulnerable targets using Havij.The user friendly GUI (Graphical User Interface) of Havij and automated settings and detections makes it easy to use for everyone even amateur users.



Download
unavailable - havij က ေၾကာက္ရဒယ္


Pangolin – Automated SQL Injection Test Tool


Pangolin is a penetration testing, SQL Injection test tool on database security. It finds SQL Injection vulnerabitlities.Its goal is to detect and take advantage of SQL injection

vulnerabilities on web applications.



Download


The Mole

The Mole is an automatic SQL Injection exploitation tool. Only by providing a vulnerable URL and a valid string on the site it can detect the injection and exploit it, either by using the union technique or a boolean query based technique.



Download



SQLNinja

Sqlninja’s goal is to exploit SQL injection vulnerabilities on web applications that use Microsoft SQL Server as back end. There are a lot of other SQL injection tools out there but sqlninja, instead of extracting the data, focuses on getting an interactive shell on the remote DB server and using it as a foothold in the target network.



Download


Safe3SI


Safe3SI is one of the most powerful and easy usage penetration tool that automates the process of detecting and exploiting SQL injection flaws and taking over of database servers. It comes with a kick-ass detection engine, many niche features for the ultimate penetration tester and a broad range of switches lasting from database fingerprinting, over data fetching from the database, to accessing the underlying file system and executing commands on the operating system via out-of-band connections.



Download



BSQL Hacker

BSQL (Blind SQL) Hacker is an automated SQL Injection Framework / Tool designed to exploit SQL injection vulnerabilities virtually in any database.



Download




source :
http://www.hackingarticles.in/best-o...jection-tools/