Last year, I was talking about how to use NightHawk to do malicious things. The full article is here. Two years ago, I also talked about using pre-paid SIM card to do malicious things and the full article is here. However, you think that it would be a chance to be caught as TOR network exit nodes may be monitoring by law enforcements. Meanwhile, identity registration may be needed to purchase SIM card in your country. Okay, today I will introduce another method that you can use wired network to do malicious things untraceable.
In my country, there are many "Internet Cafe" which have a pool of computer systems that running Windows system to provide network gaming or internet services to their customers with a cheap price per hour. Those computer systems will be equipped "Reborn Card" which can reset to its default setting on every reboot. Normally, the "Internet Cafe" will reboot their computer systems every day.
You can hire a computer system in the "Internet Cafe", reboot it. Plug in your Kali Linux or BackBox Linux Live USB (or your custom made pentesting Linux Live USB). Personally, I will recommend BackBox as it will have some outstanding features, such as memory wiper.
After your malicious tasks, you can reboot your computer system and it will reset to its default setting. Normally, no data or activiities will be logged in the computer system.
When law enforcements trace your IP address which will direct them to the "Internet Cafe", they cannot obtain any evidence from the computer pool as those systems are reborned!
Finally, beware that CCTV will be installed in the "Internet Cafe" or nearby shops which will capture your present. You may need to do some "make up" when necessary.
That's all! See you.
See Also
Catch Me If You Can
Catch Me If You Can 2
Catch Me If You Can 4
Open Source is a great idea and it has changed the world!
Open Source forever ....
While you do not know attack, how can you know about defense? (未知攻,焉知防?)
Do BAD things .... for the RIGHT reasons -- OWASP ZAP
It is easier to port a shell than a shell script. -- Larry Wall
Most of you are familiar with the virtues of a programmer. There are three, of course: laziness, impatience, and hubris. -- Larry Wall
为天地立心, 为生民立命, 为往圣继绝学, 为万世开太平。 -- 王炜
Showing posts with label Malicious Hacker. Show all posts
Showing posts with label Malicious Hacker. Show all posts
Friday, August 28, 2015
Sunday, January 19, 2014
Catch Me If You Can 2
Last year, I was talking about how to use 3G/4G pre-paid SIM card to do malicious things. The full article is here. However, many countries required to register the buyer's personal particulars when they purchase 3G/4G pre-paid SIM card. Today, I will introduce another method that you can use wired or mobile network to do malicious things untraceable.
First of all, you need a virtual machine (VMWare, VirtualBox or Parallels, etc) or a standalone computer. A router when you are connecting to the internet in wire. Otherwise, a pocket 3G/4G WiFi router is a must for mobile connection.
I prefer virtual machine if you have a suitable hardware (for example, more than 4GB RAM and a large hard drive or SSD).
Secondary, you need to install Ubuntu Server 12.04 LTS (x86 or x86_64) with openssh installed on the virtual machine (or a standalone computer if your prefer).
Thirdly, after installed Ubuntu server 12.04 LTS, you need to install NightHawk. Make sure your MAC address of the network interface (NIC) is changed or customized by macchanger. I recommended not to use the default MAC address even you are using virtual machine.
Fourthly, you connect to the virtual machine (NightHawk) with PPTP VPN and then you can do everything (including maliciously) untraceable. Make sure you change the DNS to others (not your real ISP) in your host computer (PPTP setting).
Finally, if you are using Kali Linux, you can install the VPN client as the following :
For the setup of NightHawk, please refer to here.
Two things you should remember, one is to change the MAC address of the NIC at virtual machine; and the other is to change the DNS entries of PPTP configuration. By the way, do NOT use reverse connection or you need to use hidden services (I am not tried yet). Javascript and Flash should be disabled on browser too. Otherwise, you will be traced.
Final thought, after the successful and amazing malicious attack, you can securely and completely delete the virtual machine. In addition, you are recommended to fully encrypt your Kali Linux box and implement the self-destruction. Then, you can destroy your Kali Linux box with "nuke" passphrase in case you are being caught. Nice?
That's all! See you.
See Also
Catch Me If You Can
Catch Me If You Can 3
Catch Me If You Can 4
First of all, you need a virtual machine (VMWare, VirtualBox or Parallels, etc) or a standalone computer. A router when you are connecting to the internet in wire. Otherwise, a pocket 3G/4G WiFi router is a must for mobile connection.
I prefer virtual machine if you have a suitable hardware (for example, more than 4GB RAM and a large hard drive or SSD).
Secondary, you need to install Ubuntu Server 12.04 LTS (x86 or x86_64) with openssh installed on the virtual machine (or a standalone computer if your prefer).
Thirdly, after installed Ubuntu server 12.04 LTS, you need to install NightHawk. Make sure your MAC address of the network interface (NIC) is changed or customized by macchanger. I recommended not to use the default MAC address even you are using virtual machine.
Fourthly, you connect to the virtual machine (NightHawk) with PPTP VPN and then you can do everything (including maliciously) untraceable. Make sure you change the DNS to others (not your real ISP) in your host computer (PPTP setting).
Finally, if you are using Kali Linux, you can install the VPN client as the following :
apt-get install network-manager-pptp-gnome network-manager-pptp
/etc/init.d/network-manager restartFor the setup of NightHawk, please refer to here.
Two things you should remember, one is to change the MAC address of the NIC at virtual machine; and the other is to change the DNS entries of PPTP configuration. By the way, do NOT use reverse connection or you need to use hidden services (I am not tried yet). Javascript and Flash should be disabled on browser too. Otherwise, you will be traced.
Final thought, after the successful and amazing malicious attack, you can securely and completely delete the virtual machine. In addition, you are recommended to fully encrypt your Kali Linux box and implement the self-destruction. Then, you can destroy your Kali Linux box with "nuke" passphrase in case you are being caught. Nice?
That's all! See you.
See Also
Catch Me If You Can
Catch Me If You Can 3
Catch Me If You Can 4
Labels:
hacker,
Malicious Hacker
Wednesday, July 31, 2013
Catch Me If You Can
As a malicious hacker, you are required to hide yourself before attack. If you failed to do so, you will be caught. Most malicious hackers will hide themselves by using botnets, Tor or proxies, or similar. However, I would like to introduce a new way to hide yourself when doing evil things in the internet.
In our country, you are not required to register your personal particulars to purchase 3G/4G pre-paid SIM card. In other countries, you may required to do so.
In the early morning, you can on board a public transportation, such as bus, and pay with non-traceable payment method, such as cash. Open your laptop and plugin your 3G/4G mobile dougle. You are using a pre-paid SIM card and you are on a moving public transportation as well as paid by non-traceable payment method. You fake your MAC address with macchanger.
You search for a target in the Google with dorks. Once you find a target, you can go ahead to attack it without worrying about to hide yourself. After several commands issued, you get a shell and compromised the target. You leave a backdoor for further access.
After that, you make sure to drop the pre-paid SIM card to the rubbish bin that out of your living area after your successful attack.
Next time, you take another route of the public transportation to access the compromised target or to seek another target with another pre-paid SIM card.
Now, you are fully untraceable.
That's all! See you.
See Also
Catch Me If You Can 2
Catch Me If You Can 3
Catch Me If You Can 4
Catch Me If You Can 2
Catch Me If You Can 3
Catch Me If You Can 4
Labels:
hacker,
Malicious Hacker
Friday, January 04, 2013
Why You Need To Learn Hacking Skills (2013)?
Male : I am managing a network and some servers. Ah, how to protect them from being compromised?
Female : In general speaking, you need to know how to hardening your network and servers.
Male : I followed all the advices and suggestions from the internet, such as security discussions or wiki. Some advices are asking me to read logs. However, I learnt from the internet that some exploit activities will not be logged. Any suggestion?
Female : Why not learn how malicious hackers thinking and doing in order to protect your network and servers?
Male : What that means?
Female : To be an Ethical Hacker in order to protect your network and servers. Then, you will be thinking like a criminal and act as a professional.
Male : It sounds good. However, when I ask for something about hacking skills in the forums, those guys in the forums always turn me down. Sometimes, they will misleading me.
Female : Why not take some formal training on hacking? Such as OSCP or CEH? Those courses will teach you about hacking skills or knowledge. When you know how malicious hackers thinking and doing, you will know how to protect your network and servers well. Ethical Hackers and Malicious Hackers are speaking the same language, using the same tools and playing the same game. Learn to hire a thief to try to steal something but don't hire a cop.
Male : Sure. Thanks for the suggestion.
Female : You're welcome.
That's all! See you.
Subscribe to:
Posts (Atom)
