10 Techniques to Hack Passwords with Google

Posted by : Shitu on Sunday, June 21, 2009

Comments(1)

Categories: ,

Google is able to index almost everything now is more than satisfied, even this feature plays her very often to the benefit of those who have some pretty questionable purposes related all'hacking and infringement of Internet servers and websites. And 'Just a poorly configured web server to enable the' access to Google's crawlers, and directories containing sensitive information resources, configuration files and utilities password. And of course when Googlebot access to a resource accessible via HTTP provides "right" to index it and then making it available for research.

In this article we will see a list of interesting hacking techniques based on using Google to obtain credentials for access and use information to make intrusions and attacks. Try to just enter in the Google search box the search strings below in italics.

#1 Utilities and passwords stored on FTP and WS FlashFXP

WS FlashFXP and FTP are two popular FTP client, respectively, using a file called ws_ftp.ini and flashFXP.ini to save the information for access to FTP sites configured.
Search string for WAS FTP: intitle: index.of ws_ftp.ini or filetype: ini pwd WS_FTP or "index of /" "ws_ftp.ini" "parent directory"
Search string for FlashFXP: filetype: ini inurl: flashFXP.ini

#2 Utilities and passwords of sites created with Frontpage

Frontpage client is still widely used to create static web sites: the authentication system for automatic connection is based on the service.pwd file that contains the users and encrypted passwords that can be decoded with little effort by using John The Ripper.
Ricenca string: "#-FrontPage-" inurl: service.pwd


#3 Log files with users and passwords

It seems incredible but that happens very often the users and passwords for access to restricted areas or sites are stored in a file passwords.log. Try it yourself ...
Search string: filetype: log inurl: "password.log"


#4 Download complete database mdb Forums Web Wiz Forums

If a forum Web Wiz Forums is not properly configured, you can download the entire database in an instant!
String of ricenca: filetype: mdb wwforum


#5 VNC server interface exposed via Java Applet

VNC is a remote control software that can also be exposed via web through a Java applet that is normally listens on port 5800.
String of ricenca: intitle: vnc.desktop inurl: 5800 or "VNC Desktop" inurl: 5800


#6 Configuration file for proftpd

The configuration file for proftpd server contains a lot of information about installing, utilities and logs.
Search string: filetype: conf inurl: proftpd.conf-sample


#7 Create a user on the mail server pro Argosoft

If a mail server Argosoft is not properly configured, you can create your own mail user entering a URL ad hoc.
Search string: "adding new user" inurl: addnewuser - "there are no domains"


#8 Administration interface for Web Data Administrator Microsoft SQL Server

Web Data Administrator is a web utility written in ASP.NET and used to manage via a web database SQL Server.
Search string: intitle: "Web Data Administrator - Login"


#9 Files backup of passwords and configurations

Many managers are (rightly) used to make a backup copy before you edit a configuration file, and often change the extension. "Bak".
Search string: filetype: bak inurl: "htaccess | passwd | shadow | htusers"


#10 Archives of e-mail in Microsoft Outlook

Outlook stores the email on file with the extension. Pst: uploading a file of this type on Outlook you can access all the email that contains immediately.
Search string: outlook filetype: pst

Continue Reading~"10 Techniques to Hack Passwords with Google"

Watch ICC Twenty20(T20) 2009 World Cup Online For Free!

Posted by : Shitu on Sunday, May 31, 2009

Comments(4)

Categories:

The ICC World Twenty20 is the international championship of Twenty20 cricket. The event is organised by the sport's governing body, the International Cricket Council (ICC). The tournament consists of 12 teams and is contested by all Test-playing nations plus qualifiers.

Below is the grouping of teams for ICC World Cup Twenty20 2009.
Group A: India, Bangladesh, Ireland
Group B: Pakistan, England, Netherlands
Group C: Australia, Sri Lanka, West Indies
Group D: New Zealand, South Africa, Scotland
 The ICC World Twenty20 2009 event will take place in England and it starts from 5th June 2009.Here are the list of sites that let you watch World cup T20 2009 Online for FREE.

  1. Yahoo ICC World Twenty20 Website
  2. Cricinfo's 2009 ICC World Twenty20 coverage
  3. Twenty20 World Cup Coverage
  4. Watch ICC twenty-20 World Cup 2009 Live Streaming on OOXTV
  5. Watch T20 World Cup 2009 Online for FREE on CRICTIME
  6. Watch World T20 Cricket 2009 Live Streaming on WebCric
  7. Live-Cricket-Match - World Twenty20 2009
  8. ICC World cup T20 Watch Online for free on eCric.net
  9. Cricket World cup Live Streaming on WatchAnyTV
  10. Live World Cup 20-20 Cricket Streaming - CricketHeats.org
  11. p2pDesi Live Cricket Streaming
  12. Watch Star Cricket Channel Online for FREE on Fusefry
  13. Watch Twenty20 World cup 2009 online on LiveCricket Bollyfm


Thanks to Raju

Continue Reading~"Watch ICC Twenty20(T20) 2009 World Cup Online For Free!"

Download Licensed copy of TechSmith SnagIt 7.2.5 Free

Posted by : Shitu on Tuesday, May 26, 2009

Comments(0)

Categories: ,

TechSmith is now providing their most popular screen capturing software, SnagIt 7.2.5 Free. This offer is actually for CT readers but you can also avail it. SnagIt helps me a lot in my day to day blogging activities and I must say it simply awesome.


SnagIt is the screen capture and editing software that lets you add stunning effects - and helpful instructions - to anything you see on your PC screen. SnagIt’s powerful built-in Editor lets you crop, resize, adjust color, add text and apply custom effects to your screenshots and images.

Follow the steps below to get SnagIt 7.2.5 Free:

  1. Visit this promotional page.
  2. Fill up your details in the form at right side. Click on Send My Key!

  3. After submitting, you’ll receive an email with genuine license key of SnagIt 7.2.5.
  4. Download SnagIt 7.2.5 and activate it to full version using the license key. Enjoy!

Using this offer, you can also upgrade to the latest version of SnagIt 9.1 for 50% off the full purchase price!

Thanx to Mayur from Web Trickz

Continue Reading~"Download Licensed copy of TechSmith SnagIt 7.2.5 Free"