| welcome to social.hackers | posts are made by Clocwork and Shadowdrifter | added some new hack diaries + podcasts |

Friday, June 3, 2011

[EBOOK] Ye Old Social Engineering [$5]

We recently finished our ebook on Social Engineering techniques. This book consists of many ways to gain information through reconnaissance, make money through somewhat illicit means, and also we reveal some secrets that we found. We hope that you enjoy this book!



Thanks,
- Clocwork and Preistpower

Doxing Assistant V4 or AIO.

I have recently added the finishing touches to my doxing tool version 4.0. For those unfamiliar with the doxing assistant it is based on a simple tool Clocwork made over a year ago. Inspired by his design I started by learning his code, and then added some of my own. It has become one of my biggest projects, and one I am incredibly proud of. The program, and its needed module has been uploaded to Sourceforge. The program uses many Python functions to complete tasks ranging from, decrypting hashes,encrypting hashes,html extracting for sql, sql table bruteforcing,custom password generating, random password generating,dox assistance,and even console based doxing. If you do not understand any of the code please comment, and I will respond as soon as possible.

Thursday, June 2, 2011

Chat bot.

Hello, I have recently been working on a new project I call it Socrabot after the philosopher Socrates. The reason for this program is so I can enter the Chatterbox Challenge which is a contest to create the smartest chat bot you can. The contest for this will begin in March so I have until then to improve him. If you have any suggestions/questions you would like added to his database please let me know in the comments section, and I will.

Wednesday, May 11, 2011

CONGRATS TO SHADOWDRIFTER!

Congrats Shadowdrifter!

One of our writers, Shadowdrifter, has made an outstanding article about hacking Audix systems. His article was recently published on a hacking security website called mrcracker.

Here is just a little taste of the article

So as many of you know cell phone voicemails are incredibly insecure. Now for reconnaissance this isn’t useful when you are gathering information on big companies. Mostly due to the fact that employee cell phones are often private. When doing reconnaissance you should always be aware of the information you have already found, and how it can be used. Thats where an employee directory comes in handy. Many top businesses use the Audix voicemail system so knowledge of the system is invaluable.

So, head on over to mrcracker to view the article now. Again, congratulations Shadowdrifter!

Simple coin flip simulation.

By simple coin flip simulation I am meaning that I created a program with Python to "simulate" flipping a coin 100 hundred times which then returns the result. It is a simple program using list, and the random module built into Python.


import random
# Assigning the variables
i = 1
h = 1
t = 2
lit = []
lih = []
# Starting the loop
while 101 > i:
# Random function to select 1,2 to represent heads and tails.
data = random.randint(h,t)
print data
i = i + 1
data = int(data)

if data == 1:
lih.append("1")

if data == 2:

lit.append("2")

e = len(lit)
e = str(e)
f = len(lih)
f = str(f)
print 'You flipped tails ' + e + ' ' + 'times ' + 'and ' +  'You flipped heads ' + f + ' times'
raw_input()


This is just an example of what you can do with very simple functions, and just a few lines of code.

Sunday, May 8, 2011

PODCAST : Episode Four - Dead Drops


In this episode Clocwork briefly talks about Dead Drops.

Saturday, April 30, 2011

Router Hacking.

Todays post is on router hacking. I am not going very indepth on how
to hack routers. I will just be going over a few ways to find unsecure routers, and poorly configured routers
The simplest way is to just gain access to the network, and go commonly to
192.168.1.1 for the router page. You will encounter routers without passwords, but you should learn some of the most common
default passwords for routers just in case.

Common default passwords for any router username:password:


admin:admin.
admin:password.
admin: no password.
nothing in either username nor password.
admin:guest
guest:password

Those few password combinations will be the most commonly used. I personally used admin:admin just the other day.
Now we have logged into router so what can we do? Well the first thing we can do is enable remote management ( Remote management is the ability to control the router from a remote location); it is different
for each router, and some do not even have the option.  If you do happen to find the option; you will need to change the default
password, and make sure you allow your I.P address to connect. This is all very self explanatory when you are familiar with routers.
By the end of this post you will be well on your way to becoming an expert at router configuration.

Now its easy to find routers from just finding secure, and unsecure wireless networks to try and access. There are a lot of
routers that web interfaces are actually indexed in Google! So with a simple Google dork we can find dozens even hundreds of unsecured routers
just waiting for someone to experiment with.

Google dorks to find routers:

intitle:"SpeedStream * Management Interface"      ( Speed Stream routers )

intitle:"Setup Home" "You will need * log in before * * change * settings"  ( Belkin routers )

intitle: "actiontec" main setup status " Copyright 2001 Actiontec Electronics Inc"


Those three dorks should keep you busy for quite some time. Now there is one more method that is hit, and miss really.
If you happen to find a target. Port scan them, and look for port 23 which is by default Telnet. There are a lot of off the shelves routers with telnet
active with only the default passwords in place. Which are very similar to the default router passwords except for a select few.

Default Telnet router passwords:


guest:guest
guest:password
user:guest
admin:guest

That is all for now; may your blades stay sharp, your mind sharper! Shadowdrifter.