Affichage des articles dont le libellé est Twitter. Afficher tous les articles
Affichage des articles dont le libellé est Twitter. Afficher tous les articles

WikiLeaks Under Cyber Attack Due to Recent Failed Turkish Military Coup

On Monday July 18th, WikiLeaks tweeted about that they are going through a sustained attack on their infrastructure. All this start happening has after they announced to release a trove of documents detailing the Turkey’s political power structure.



WikiLeaks is best known for its release of classified government and military documents. Earlier on Monday it said that they are preparing to release 300,000 emails and 500,000 documents related to the failed coup operation in Turkey.


According to WikiLeaks, they suggest that the Turkish government is behind the attack on their organization. Furthermore, they said "We are unsure of the true origin of the attack. The timing suggests a Turkish state power faction or its allies”. In a subsequent tweet "We will prevail & publish”.


During the attempted coup in Turkey, it has been reported that Facebook, Twitter, YouTube was blocked. But many residents appear to have gotten around the blocks, posting messages and videos, likely using VPNs or other anonymizing services.

~ mardi 19 juillet 2016 0 commentaires

tinfoleak - Information gathering Over Twitter

Information gathering, the first and the most important step of penetration testing/ ethical hacking; the more you know about your target, more the chances of success you have. Social media specially Facebook and Twitter have loads on information about any person or business, and hackers also using these platform to get the information of the target; whatever the purpose is, you need information or simply you need to get information by using intelligence gathering techniques. There are many services and products are available in the market, but what if I tell you that there are many OSINT (open source intelligence tools) are available for free of cost, tinfoleak is one of them.

tinfoleak can gather information of any Twitter account, it is a simple Python script that allow to obtain:
  • basic information about a Twitter user (name, picture, location, followers, etc.)
  • devices and operating systems used by the Twitter user
  • applications and social networks used by the Twitter user
  • place and geolocation coordinates to generate a tracking map of locations visited
  • show user tweets in Google Earth!
  • download all pics from a Twitter user
  • hashtags used by the Twitter user and when are used (date and time)
  • user mentions by the the Twitter user and when are occurred (date and time)
  • topics used by the Twitter user

You can filter all the information by:
  • start date / time
  • end date / time
  • keywords
Download and learn more

~ jeudi 25 septembre 2014 0 commentaires

Twitter.com Hacked Via Text Load Injection by ./BL4CK E4GL3



I found this around 2 AM last night, and it's quite suprising that twitter.com is vulnerable for Text Load Injection . Text load injection is where you're are allowed to inject text from ixData that is an indextable data type. So it will displays message as follow,


{"request":"\/i\/promoted_content\/log.json?BL4CK_E4GL3_W4S_H3RE",
"error":"Invalid event parameter provided."}
 
We will get that message by visiting the following link:
 https://twitter.com/i/promoted_content/log.json?BL4CK_E4GL3_W4S_H3RE  
 
I tried to sumbit it on Defacement Mirror like Zone-H, but I can't 
because someone already sumbitted Twitter.com to that mirror, and it was 
a FAKE defacement. WTF?
 
 
 

~ samedi 8 mars 2014 0 commentaires

NodeXL Social Media Network Analysis Tool


Social networking website has changed the way of social life now a days everybody using Facebook, Twitter, Google plus and other social networking website, there are different pros and cons of social networking website but as a penetration tester and ethical hacker aspect we have to discuss about privacy and security issue of a person in social networking website. As discussed about the security of different social networking website this time I will let you know the importance of social networking website in a penetration testing.

Social networking are now a best source for penetration tester and even for hacker to get the information about a victim, social networking websites easily lead towards the social engineering attack.
There are different tools and techniques out there to get and analyze the data from different websites to make the plan of action like as discussed about Maltego. Maltego is also available on backtrack 5 but maltego is not the point of this article, in this I will discuss NodeXL.

What Is NodeXL ?

NodeXL is a free, open-source template for Excel 2007 and 2010 that lets you enter a network edge list, click a button, and see the network graph, all in the Excel window. You can easily customize the graph’s appearance; zoom, scale and pan the graph; dynamically filter vertices and edges; alter the graph’s layout; find clusters of related vertices; and calculate graph metrics. Networks can be imported from and exported to a variety of file formats, and built-in connections for getting networks from Twitter, Flickr, YouTube, and your local email are provided. Additional importers for Exchange Email, Facebook, and Hyperlink networks are available.

Download








Note: If you want to learn more about Linux and Windows based Penetration testing, you might want to subscribe our RSS feed and Email Subscription  or become our Facebook fan! You will get all the latest updates at both the places.

~ dimanche 16 octobre 2011 0 commentaires

Which Social Networking Websites Are Secure- Infography

If you are not in any social networking website than I really don't whats your life in the Internet, social networking websites has changed the way of communication and social life, facebook is one of the best and common social networking website, but Facebook is not only a single player beside Facebook we have twitter, Google Plus, Hi5, Orkut, Myspace and many more. Security and privacy of a social networking website is very important because an attacker can gather enough information from a social networking websites to launch an attack against you.

As discussed before about the best facebook security tips and tricks and twitter security tips but the question same which social networking website is best according to security and privacy. To solve this question we have a wonderful inforgaphy.


Mobile Malware




Note: If you want to learn more about Linux and Windows based Penetration testing, you might want to subscribe our RSS feed and Email Subscription  or become our Facebook fan! You will get all the latest updates at both the places.

~ mardi 11 octobre 2011 0 commentaires

Celebrities Twitter Accounts Hacked [INFORGRAPHIC]

Twitter is one the best and popular social media networking website among different social networking web like Facebook and Google plus. Twitter is famous because it is easy to use and most of the celebrity and high profile person can easily find on twitter, twitter is on the hit list of the hackers and an attacker usually tries to hack famous accounts. There are many techniques can be use to hack any twitter account, but this is not our topic of this article.

You must have heard about Lady gaga, Justin bieber, Shakira and other people got hacked on twitter, you have also heard that twitter was hacked by Iranian cyber army . So below you can see a Info-graphic means a graphical representation of these account.
Twitter Infographic








Note: If you want to learn more about Linux and Windows based Penetration testing, you might want to subscribe our RSS feed and Email Subscription  or become our Facebook fan! You will get all the latest updates at both the places.

~ vendredi 30 septembre 2011 0 commentaires

Droidsheep-Android Application for Session Hijacking

Android is one of the best and most famous operating system for mobile devices, mobile devices is now a important part of our life and we are using it every where in any condition. There are a lot people that are using Wifi on their mobile devices. Look at the past when we had a Firefox ad ons that can hijack Facebook, Twitter and other social networking websites sessions and the tool is called Firesheep, after this we got FaceNiff the purpose is same means session hijacking while Faceniff is for android OS.

Now there is another best tool for Android OS that can hijack session and it called Droidsheep.

What Is DroidSheep ?

DroidSheep is a simple Android tool for web session hijacking (sidejacking). It listens for HTTP packets sent via a wireless (802.11) network connection and extracts the session id from these packets in order to reuse them.
DroidSheep can capture sessions using the libpcap library and supports: OPEN Networks WEP encrypted networks WPA and WPA2 encrypted networks (PSK only). This software uses libpcap and arpspoof. DroidSheep has been developed with support of the information security team of the University of Trier.

Requirement

    You need an android-powered device, running at least version 2.1 of Android  You need Root-Access on your phone (link)  You need DroidSheep

Download

DroidSheep Video Tutorial




Note: If you want to learn more about Linux and Windows based Penetration testing, you might want to subscribe our RSS feed and Email Subscription  or become our Facebook fan! You will get all the latest updates at both the places.

~ mercredi 28 septembre 2011 0 commentaires

Fbpwn- A cross-platform Java based Facebook profile dumper

If you are popular than you are at risk, the same thing applies on Facebook one of the most popular social networking website. Social networking websites are good for social engineers because in the first step of hacking (Information gathering) social networking websites like Twitter, facebook linkedin plays an important role. Just like TheHarvester (a tool to gather information from search engine) there are different tools that can be useful to gather information from social networking websites.

So, for gather information from Facebook an attacker can use Fbpwn, now the question is, what is Fbpwn and how it gather information? Below is the answer.

What Is Fbpwn

Fbpwn is a cross-platform Java based Facebook profile dumper, sends friend requests to a list of Facebook profiles, and polls for the acceptance notification. Once the victim accepts the invitation, it dumps all their information,photos and friend list to a local folder.

In simple it can do all the stuffs automatically that you can do manually, it is an open source tool and available for free of cost so you don't need to worry about it.

Download

Fbpwn is best tool for the new users who don't know about programming because as discussed Facebook graph API information gathering, Fbpwn do all the stuffs automatically.

FBPwn modules

  • AddVictimFriends: Request to add some or all friends of bob to increase the chance of bob accepting any future requests, after he finds that you have common friends.
  • ProfileCloner: A list of all bob's friends is displayed, you choose one of them (we'll call him andy). FBPwn will change mallory's display picture, and basic info to match andy's. This will generate more chance that bob accepts requests from mallory as he thinks he is accepting from andy. Eventually bob will realize this is not andy's account, but probably it would be too late as all his info are already saved for offline checking by mallory.
  • CheckFriendRequest: Check if mallory is already friend of bob, then just end execution. If not, the module tries to add bob as as a friend and poll waiting for him to accept. The module will not stop executing until the friend request is accepted.
  • DumpFriends: Accessable friends of bob is saved for offline viewing. The output of the module depends on other modues, if mallory is not a friend of bob yet, the data might not be accessable and nothing will be dumped.
  • DumpImages: Accessable images (tagged and albums) are saved for offline viewing. Same limitations of dump friends applies.
  • DumpInfo: Accessable basic info are saved for offline viewing. Same limitations of dump friends applies.






Note: If you want to learn more about Linux and Windows based Penetration testing, you might want to subscribe our RSS feed and Email Subscription  or become our Facebook fan! You will get all the latest updates at both the places.

~ vendredi 9 septembre 2011 0 commentaires

Top Twitter Security Tips

Social networking websites has changed the way of user's to see the Internet, these websites provides a lot different features to interact with new peoples and make them connect via electronic link. Well there is so many benefit of social networking but you must consider security factor in it.

Twitter just like facebook is the most popular social networking website and just like facebook user faces different security issues, twitter user(s) also faces these security issues, phishing scam is the most famous one. There are so many user asking "How to secure twitter account"?  Well in this article we will cover some tips that would really help you to make your twitter account secure. 

If we talk about so general than the tips that are applicable on facebook it can easily be applicable on twitter too, so must know about 8-10 top facebook security tips.


  1. You must care about your passwords, make sure you have a strong password that contain capital letters,small letters,numbers and special characters. Use different password for different online accounts, your password must not related to some of your information, do not use such a words that are easily available on dictionary. To learn more about dictionary attack click here.
  2. Avoid phishing pages, try to secure yourself from fake websites, always look at the address bar before entering your ID and password it must be twitter.com
  3. Use secure session to secure your account from any sort of sniffing, it is more important if you are sign in from a public place use https://twitter.com instead of http://twitter.com
  4. Secure your computer use smart firewall and IDS to protect your computer in the jungle of web, it is very important to secure any account that your computer must not be infected by some sort of malware like keylogger, how to protect your computer from keyloggers? If you have a doubt that your computer is infected that follow the step to remove infected files click here to learn. 
  5. Smart phones are likely be use by so many people and they are used to login their accounts from smart phones so must be consider the factor, click here to learn about smart phone security.

Note: If you enjoyed this post, you might want to subscribe our RSS feed and Email Subscription  or become our Facebook fan! You will get all the latest updates at both the places.

~ jeudi 9 juin 2011 0 commentaires