Support The Ethical Hacker !! - Click Here If You Like My Contents !!!

Showing posts with label Email. Show all posts
Showing posts with label Email. Show all posts

Monday, December 7, 2009

Catch Invisible Friends On An Instant Messenger !!


So now I will tell you about something which will be very fun to try out.
So why are we here?  What is the fun thing...?
Hey I am just there....Many of us stay invisible in Yahoo Messenger, Gtalk etc to avoid unnecessary chat requests and spam. Yeah, I know you have many more reasons to stay invisible. But being in the ETHICAL side let us not discuss it here!! .
Here we will learn how I used to detect the status of my friends in IM's.I will be concentrating mainly on detecting the status in Yahoo and Google IM's.

Yahoo Messenger

Here I will give you some links and their uses. Using this method you cannot find out the invisible mode of the person. But it is easy to know the ONLINE or OFFLINE status of your friends. The main advantage of this method is that you never have to login to your account to know the status of your target.


http://mail.opi.yahoo.com/online?u=[Target's username]&m=g&t=0 
You will get a yellow smiley if the person is online and gray if the person is offline or invisible

http://mail.opi.yahoo.com/online?u=[Target's username]&m=g&t=1
This will fetch you a button with “Online Now” or “Not Online”

http://mail.opi.yahoo.com/online?u=[Target's username]&m=g&t=2
We will get an image with “I am Online send me a message” or “Not Online right now”

http://mail.opi.yahoo.com/online?u=[Target's username]&m=g&t=[number from 0 to 24]

Similarly you can change the [number from 0 to 24] to any number from 0 to 24 to get different icons displaying the status of the target.

http://mail.opi.yahoo.com/online?u=[Target's username]&m=a&t=0
Shows a text with “[Target’s username] is ONLINE or NOT ONLINE”

http://mail.opi.yahoo.com/online?u=[Target's username]&m=a&t=1
This will show a value “00” if person is offline and value “01” if he is online

NB: You will have to change the [Target's username] in the above shown URL’s to the yahoo ID you want to detect.  

For Eg: If my Email ID is “hackingwithswar”
So http://mail.opi.yahoo.com/online?u=[Target's username]&m=a&t=1
Will have to be in the form

NB:
We can use these links discussed above to set or hide your status on your blog or site.Think How..?   


We cannot find out the real status of person who is in the “invisible “mode. It will be shown as  he is “Offline”. So in order to solve this problem we can use the method discussed below.

Yahoo Invisibility detection sites

While surfing the net I came across many sites which help us to get the real status of the person of our choice.

Feel free to click on the links to try it out yourself and have fun





Gtalk 
There is a simple trick to know if a Gtalk Friend is online or not
First login to the Gtalk application with your Gmail ID
Then activate the chat window of the profile you need to check the status in the Gtalk.

The Next step is to activate "off the record" function in the chat window of the Victim






Here you can see that you do not receive an  alert when you send your chat


Now we get two kind of responses depending on the status of the Victim.They are :
1) When the Victim is in invisible mode

  In the image displayed below ,you can see that no alerts are generated.So we can be sure that ,the Victim is Online,but in the Invisible Mode!!



2)When the Victim is really Offline






Wednesday, November 25, 2009

Bypassing Email Antivirus

Many of the Email domains available to us, say, Gmail,Yahoo mail etc, do not allow us to send .exe files or zip files as attachments.When you try to send an application setup the Gmail will notify that "something  .exe is an executable file. For security reasons, Gmail does not allow you to send this type of file." Sometimes it is found that we cannot send compressed files in .zip also via Gmail.



Gmail email account has a virus scanner that scans email attachments and block them appropriately. Gmail email account also blocks .exe files. So, you can't send exe files via Gmail. Yes of course I mean that you cannot sent them directly
So How can you Bypass Gmail security..?
 Mainly 3 ways can be employed to do this .Now let us discuss them here.


Rename The Extension of the compressed file.
For this method you will have to compress to .zip format if you do not have any other softwares like WinRar to do that.This method is found to work completely for the .zip files. All you have to do is to change the extension to something which cannot be recognized by Gmail. For Eg : you can change the setup.zip to setup.<your name>.Then you can attach it to your mail and send it to the target.

NB:
  • Make sure you tell the person you're mailing to rename it to .zip on the other end so that they can extract it.
  • Here Gmail is depending on the extension to recognize the file types.
  • A simple method by which Gmail can avoid this hack is by making use of the fact that  "All zip files start with the bytes 'PK' "
 Bingo now that is an idea to make a patch..


Use WinRar software for compressing
Download the WinRar application and compress the .exe file using this application.The file you get will be in the .rar format.This can be easily sent via Gmail.In some occasions this may not work well.So you will have to encrypt the file names also before sending. 


Use Online file storage services for sharing.

 There are many file storage services in the web which will allow you to store the files online.We can make use of these to share the files with our friends.All you have to do is to send the link to the file to the target.So when the target clicks on the link it will allow him to download the file.

You can avail the service of Ziddushare for such things.A simple registration process will allow us to upload files to our account.Also we are getting paid for the uploads.The main highlight of this service is that the registration is free.Ziddu.com has no wait times.


Tuesday, November 24, 2009

E-mail Forging- Sending spoofed mails

Email spoofing is the art of sending spoofed mails to the target in order to create chaos on the other end.Many criminals make use of this technology to send spoofed mails.This allows the attacker to send the E-mail from the victim's mail account without knowing his or her passwords.

Even these days we can find many vulnerable servers connected to the internet which allows unauthenticated access to its smtp ports.This allows the attacker to send spoofed mails.

The general methodology for sending spoofed mails, using telnet is described below. We can use the same method to send spoofed mails after knowing the vulnerable server.

start > run >cmd telnet 25
help
helo < domain name>
mail from : < sender's mail address>
rcpt to : < victim's mail address>

data
< message>


Countermeasures:
Always use a secure E-mail system like "Pretty Good Privacy"( PGP) for sending mails.
Digitally sign the E-mail's.
DO NOT do transactions blindly believing the E-mail service.
The most important aspect is the awareness of the user that nothing  can be done effectively against E-mail spoofing

Some Eg sites which will allow you to do Email Spoofing:

funmaza- funmailer
link 2

TIPS:
The links I provide is purely for educational purposes.

Even though you send spoofed emails it is easy to track the IP of the person sending the mails. Be Aware of that.

Create Disposable Email ID :To create a disposable email address to protect your privacy online. If you need to give someone your email address, or need to sign up to a website which requires an email address, but you don't wish to reveal your identity then use this free service for receiving emails. Simply signup instantly, give them the disposable email address and you'll be able to read every email they send in complete privacy. ( use it at your own risk) click here to get one.

Wednesday, November 18, 2009

Email Header Finger Printing

When we send an Email, the SMTP server creates a header.Study of the Mail server name reveals the OS of the server. For all this ,we have to analyze the Email Header first. The email header reveals a lot of other sensitive information about the sender including his IP.We will discuss more on this topic on other posts.
Countermeasures :
Change the mail daemon settings 

A sample Email header is shown below :


Delivered-To:XXX @gmail.com
Received: by 10.142.100.4 with SMTP id x4cs39161wfb;
        Tue, 17 Nov 2009 22:37:56 -0800 (PST)
Received: by 10.90.17.29 with SMTP id 29mr1540839agq.79.1258526174775;
        Tue, 17 Nov 2009 22:36:14 -0800 (PST)
Return-Path: 
Received: from mail15-a-ac.linkedin.com (mail15-a-ac.linkedin.com [208.111.169.137])
        by mx.google.com with ESMTP id 30si16545010iwn.121.2009.11.17.22.36.13;
        Tue, 17 Nov 2009 22:36:13 -0800 (PST)
Received-SPF: pass (google.com: domain of s-qKShvR1E_bKJbE3KpcihvgYpqS5pjeiVFRKjniEn-5Sp4jYEI5tJj_@bounce.linkedin.com designates 208.111.169.137 as permitted sender) client-ip=208.111.169.137;
Authentication-Results: mx.google.com; spf=pass (google.com: domain of s-qKShvR1E_bKJbE3KpcihvgYpqS5pjeiVFRKjniEn-5Sp4jYEI5tJj_@bounce.linkedin.com designates 208.111.169.137 as permitted sender) smtp.mail=s-qKShvR1E_bKJbE3KpcihvgYpqS5pjeiVFRKjniEn-5Sp4jYEI5tJj_@bounce.linkedin.com; dkim=pass header.i=communication@linkedin.com
DomainKey-Signature: s=prod; d=linkedin.com; c=nofws; q=dns;
  h=Sender:Date:From:To:Message-ID:Subject:MIME-Version:
   Content-Type:X-LinkedIn-fbl;
  b=LAlAw9S8qrGPLt6phtZNvQ37jeg3yvtYlApfNHApbwizFBIvNvk2D1H6
   r7PxLyDTGK5YmRBn84TgBPD5FB0gt90r9Khp4TnNFIHyM3Sy64uMytmRj
   N4agg6dfvT5H2mO;
DKIM-Signature: v=1; a=rsa-sha256; c=simple/simple;
  d=linkedin.com; i=communication@linkedin.com; q=dns/txt;
  s=proddkim; t=1258526173; x=1290062173;
  h=from:sender:reply-to:subject:date:message-id:to:cc:
   mime-version:content-transfer-encoding:content-id:
   content-description:resent-date:resent-from:resent-sender:
   resent-to:resent-cc:resent-message-id:in-reply-to:
   references:list-id:list-help:list-unsubscribe:
   list-subscribe:list-post:list-owner:list-archive;
  z=From:=20LinkedIn=20Communication=20
   in.com>|Sender:=20messages-noreply@bounce.linkedin.com
   |Subject:=20LinkedIn=20Messages,=2011/17/2009|Date:=20Tue
   ,=2017=20Nov=202009=2022:36:03=20-0800=20(PST)
   |Message-ID:=20<2138821644.368566.1258526163419.JavaMail.
   app@ech3-cdn09.prod>|To:=20"Mr.Swaroop=20Krishnan=20S"=20
   |MIME-Version:=201.0;
  bh=HFHniqCRWqBOKiU6PXUVuudYIJ3jsx+QLmyfTd3eFzU=;
  b=SDfsYwsz/HCedRw3aFZ2JkOkKrLzzK2R1gVWv2WDNXhKtr2kM0ioAlZi
   m230bpQm4ZzCi2fwM2yyYbY8GauwKPZav6r23wyGA4hTBwHKLheSmXFI5
   /+urlA2oJGJPlWR;
Sender: messages-noreply@bounce.linkedin.com
Date: Tue, 17 Nov 2009 22:36:03 -0800 (PST)
From: LinkedIn Communication 
To: "Mr.Swaroop Krishnan S" 
Message-ID: <2138821644.368566.1258526163419.JavaMail.app@ech3-cdn09.prod>
Subject: LinkedIn Messages, 11/17/2009
MIME-Version: 1.0
Content-Type: multipart/alternative; 
 boundary="----=_Part_368565_1338859.1258526163416"
X-LinkedIn-fbl: qKShvR1E_bKJbE3KpcihvgYpqS5pjeiVFRKjniEn-5Sp4jYEI5tJj_

------=_Part_368565_1338859.1258526163416
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: 7bit