Showing posts with label How to use. Show all posts
Showing posts with label How to use. Show all posts

Tuesday, 9 August 2016

How to Hack Locked Windows Laptop



Description:
Windows 8, windows 10, Windows 2012 servers comes with a default user logon screen and one of the feature in the logon screen is, the network selection user interface. This feature allows users to connect to the wireless network, turn on and off the network card etc without having to unlock the windows screen.



Risk:
This feature expose security risk, If the adversary has physical access to the machine even for few seconds, the adversary can open this network UI and connect the system to the attackers rouge wireless access point and can later perform MITM attack (as an example) and can potentially compromise the whole system.
 

Affected System:
Devices running Windows 8, windows 10, windows 2012 operating system with wireless card.



Recommendation:
To protect from this risk we need to disable this network UI on the log on screen and this can be achieved by doing it in the group policy or in the registry by going to
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\System
and add DontDisplayNetworkSelectionUI=dword:00000001


Saturday, 30 January 2016

Can I Hack Your Facebook ?

Facebook had a fantastic option for retrieving the account in a situation if you had  forgotten both your password & username and also if you don't have access to your registered email account.

All you need is a 3 good friends who is in your friends list. Yes, same old friends are back in frame for getting back your account, after all these years the best way Facebook came up to retrieve the account was by sending security codes to your 3 friends. Once you have the codes you can get back to your account.

This should be a great solution for someone who desperately want to get back his account back. This option is also good for hackers who can take over the accounts. How?

Just create 3 fake FB accounts (impersonate)  and get added into the victims trusted friends list, then simply follow the Facebook recovery option and your done, you hacked someones account.





Click "No longer have access to these?"







Enter the email ID that you can access and continue.




Click Continue and now comes the fantastic option. :)



 Select those 3 fake friends that you managed to add to the victims friends list and continue.

Your fake friends will receive security codes, complete the process and then reset the account with new password and now you hacked into the account.

This option was now removed by FB thank god for that, but hey belive me after 5 years they come up again with similar stupid options, so people who just accepts friends request from everyone please keep this in mind, you may have just added a hacker as your friend.....

Next time we will see how to deny any FB user from accessing the Facebook for few hours are even upto few days.... Sounds like fun ?

  Keep safe...

Conformio-Online Compliance Tool Multiple Vulnerabilities

# Exploit Title: Conformio-Online Compliance Tool Multiple Vulnerabilities. # Discovered Date: 16/11/2017 # Exploit Author: Ramikan # Websi...