Monday, 12 November 2012

What is VOIP and How it helps in Caller ID Spoofing Attack?Detail


What is VOIP?


 Voice-over-Internet Protocol (VoIP) is a protocol optimized for the transmission of
Voice Through the Internet or other packet-switched networks . VoIP systems employ Session control protocols to control the set-up and tear-down of calls as well As audio codecs which encode speech allowing transmission over an IP network as Digital audio via an audio stream. Codec use is varied between different Implementations of VoIP (and often a range of codecs are used); some Implementations rely on narrow band and compressed speech, while others support High fidelity stereo codecs.






How VOIP works?


VoIP Converts the voice signal from your telephone into a digital signal that can Travel
Over The Internet. If you are calling a regular telephone number, the signal is then
Converted Back at the other end. Depending on the type of VoIP service, you can make a VoIP Call from a computer, a special VoIP phone, or a traditional phone. Wireless "Hot
Spots" In public locations such as airports, parks, and cafes allow you to connect to The
Internet, And may enable you to use VoIP service wirelessly. If your VoIP service
Provider Assigns you a regular telephone number, then you can receive calls from regular Telephones that don't need special equipment.

Advantages of Using VoIP

90% Cost Saving (cheap call rates)
Great voice quality
3 ways Call forwarding
Caller ID spoofing
Unlimited calling
Web calling
Free phone call services
Free Call Forwarding

Top Voip Companies:

www.callcentric.com

Free Calling sites:


Unlimited Calling Sites:



Call-ID Spoofing Attack

Caller ID Spoofing is the practice of causing the Telephone network to display a number
On The recipient's caller ID display which is not that of the actual originating Station; the
Term Is commonly used to describe situations in which the motivation is considered
Nefarious By the speaker. Just as e-mail spoofing can make it appear that a message came From any e-mail address the sender chooses, caller ID spoofing can make a call Appear to have come from any phone number the caller wishes.
The The above method is a bit complex; many Caller ID spoofing service providers also Allow
Customers to initiate spoofed calls from a web-based interface. Some providers allow
Entering The name to display along with the spoofed Caller ID number, but in most parts
Of The United States for example, whatever name the local phone company has associated with the spoofed Caller ID number is the name that shows up on the Caller ID display. Using a web-based spoofing service involves creating an An account with a provider, logging in to their website and completing a form. Most companies require the following basic fields:
1. Source number
2. Destination number
3. Caller ID number
When The user completes this form and clicks a button to initiate the call, the Source
Number Is first called. When the source number line is registered, the destination is Then
Called And bridged together.

Advantages:

Show any number on victim mobile number
Record Outgoing Calls
Listen to your calls online
Include recordings in the email
Download your recordings

Caller ID Spoofing sites:






Caller ID Spoofing Attack:

SignUp With 123spoof.com and purchase 60 minutes, after login with PIN number.




This A screen will appear. After that we put all details like our number, number two Call and
Show Caller id and click to place a call. Then call to access number of 123spoof.com
From your number....
.
.

Posted By: Anshuman Kak



 

Tuesday, 23 October 2012

Cracking C-Panel Passwords




Cpanel is a Unix based web hosting control panel that provides a graphical interface and automation tools designed to simplify the process of hosting a web site. CPanel utilizes a 3 tier structure that provides capabilities for administrators, resellers, and end-user website owners to control the various aspects of website and server administration through a standard web browser.













So,we need  a cpanel cracking shell on that server to crack the passwords of the websites that are hosted on that server!!


Step 1

First we have to upload

cp.php cpanel cracking shell on that server to start our journey...!!

Step 2
Second thing we need, is the mother of this method!! Yes...we need Usernames of the websites and a Extremely capable password dictionary to crack!!

Now lets start...

Grab all the usernames of websites hosted on the website with the help these commands

1- "ls /var/mail"
2- "/etc/passwd"

Now you will see all the usersnames of the websites and the password list you have provided! Just press the "Go" button and just wait and watch your success!


If you have supplied strong enough password list then you will the a good response from the server ;) like this "Cracking success with username "ABC" with password "XYZ"

it will show you negative response like this "Please put some good passwords to crack username "ABC" :( "




Posted By: Anshuman kak A Script Kiddie from India

HSBC Recovers from the DDoS Attack, Anonymous Claims to Have 20,000 Debit Card Details.

Many HSBC customers were unable to log in to their internet banking accounts on Thursday, 18th of October. It has been stated that the problem started a little before 20:00 BST and lasted for around seven hours.

Later, an Anonymous hacker group named 'FawkesSecurity' took the liberty to announce that they were responsible for the problem that halted many HSBC account holders from accessing their accounts. The problem was a DDoS attack on the website itself. Which enabled them to steal details of 20,000 debit cards.


We are taking appropriate action, working hard to restore service. We are pleased to say that some sites are now back up and running.
We are cooperating with the relevant authorities and will cooperate with other organisations that have been similarly affected by such criminal acts.
We apologise for any inconvenience caused to our customers throughout the world."
 







HSBC soon recovered from the attack and the security researchers came to the conclusion that the attack largely resulted from botnet networks of malware-infected PCs.

HSBC was quick to come out with an statement to reassure their clients that their sensitive data had not been exploited in the attack.


"On 18 October 2012 HSBC servers came under a denial of service attack which affected a number of HSBC websites around the world.This denial of service attack did not affect any customer data, but did prevent customers using HSBC online services, including internet banking.


In response to this statement, Anonymous tweeted that:

When HSBC said ''user data had not been compromised'' This isn't entirely correct. We also managed to log 20,000 debit card details.
It seems like Anonymous is bewildered on whether to prove to the world that they in fact do have the sensitive information that HSBC denies.

"Were debating whether to release them or not, HSBC knows debit details were intercepted, They probz won't admit it tho."



Darren Anstee, EMEA solutions architect team lead at Arbor Networks, said in reference to the attack:

�Recent attacks have used what we call multi-vector attacks, attacks which utilise a combination of volumetric, and application layer attack vectors. What we are seeing here are TCP, UDP and ICMP packet floods combined HTTP, HTTPS and DNS application layer attacks. Attackers are doing this because they know it makes the attacks more difficult to deal with, but not impossible if we have the right services and solutions in place." �

HSBC has fully recovered from the attack and its websites are working perfectly now after being restored, according to their statement on their official website,,,,,

------------------------------------------------------------------------------

On the other hand, there have been unconfirmed reports of a group known as Izz ad-Din Al Qassam being behind the attack. They have been responsible for over 9 attacks on various banks in the US of A as a part of their current campaign which is to have the Innocence of Muslims video removed from YouTube and the Web all over.

A part of Izz ad-Din Al Qassam's statement reads:

With a little searching, we still found the anti-Islamic offensive film on the Internet. Thus the chain of cyber attacks on U.S. banks will continue this week. These attacks will be done since Tuesday, 16 October until Thursday, 18 October 2012 in midday hours. We know that banks officials are concerned and waiting to see this time it is the turn of which banks. For making variation in operation, this time we give them the opportunity to understand whether they are listed or not.

We aren't sure who the real attackers are but according to the reports being received, RBS, Llyods TSB and Barclays banks are going to be next.


Regards: Anshuman Kak a Script Kiddie FRom India...

 Posted by: Sindhia Javed Junejo.