In next tutorial I will Explain How to do it using port 443 of attacker machine instead of using port 80. So that even if victim type https://url instead of http then also he/she get attacked.
-=WELCOME IN MY BLOG=-
23/09/12
Tab-Nabbing With Dns Spoofing Using Backtrack
In next tutorial I will Explain How to do it using port 443 of attacker machine instead of using port 80. So that even if victim type https://url instead of http then also he/she get attacked.
29/09/11
Don't fight cybercrime on your own - do it with Synergy!
Project Synergy is the name of an ongoing annual series of conferences organised by the Queensland Police Service.Sophos has been sponsoring, attending and speaking at these events for several years; we've also written about them numerous times on Naked Security.
We've written about Romanian card-skimming gangs, recounted the pain suffered by the victims of hi-tech crime, presented talks on the risk posed by apparently-innocent file formats, and warned about the growing tendency of cybercriminals to target those who can least afford to get scammed.
The Project Synergy events aren't just for cops or law enforcement agents. Quite the opposite - the events are intended to bring together all of us who have an interest in helping to protect our economy from cybercrime.
If you're an anti-virus researcher, a computer security consultant, a penetration tester, a fraud investigator or an auditor; if you're from the financial sector, an ISP, a community group, a social media company, an online store (or, of course, from any branch of law enforcement), these events could be just the thing for you.
Both the size and scale of internet-enabled crime are vast, from the peddlers of fake anti-virus software who can suck in $72,000,000 by conducting nearly one million fraudulent transactions for just $75 each, to the financial scammers who spend months convincing targeted individuals to invest their entire retirement income in fraudulent schemes.
So, if you've got any interest in disrupting and preventing cybercriminality then you'll know how big a task it sometimes seems.
You probably keep asking yourself, "How can I possibly make a difference on my own?"
At the Project Synergy events, you get to meet a whole bunch of people - many of whom will become good contacts, probably even good friends - who will remind you that you aren't on your own.You become part of a virtual global team of people who share your goals. People who can help you, and whom you can help.
I'll be heading up to the Gold Coast in Queensland, Australia, on Monday next week (03 October 2011) for the final event in this year's Project Synergy series: the Identity and Hi-Tech Crime Symposium 2011.
I'm going to be giving a live demonstration of how Search Engine Poisoning works, and how to combat it.
By the way, there are still seats left at the event, rooms at the hotel where it's being held (I just checked!), and a special delegate rate at the hotel.
So, if you're in this part of the world, why not give some thought to a last-minute registration?It's at the Royal Pines Resort on Queensland's Gold Coast, and runs from Monday evening (03 Oct 2011) to Thursday early afternoon (06 Oct 2011). The fee is AU$1800, which includes a welcome party, a gala dinner, and luncheon plus morning/afternoon tea each day.
You also get an all-important Fiscal the Fraud Fighting Ferret laptop bag :-)
Hope to see you there!
22/09/11
Researchers claim to have broken SSL/TLS encryption
The researchers, Thai Duong and Juliano Rizzo, are due to demonstrate their Browser Exploit Against SSL/TLS (Beast) at the Ekoparty security conference on Friday 23 September.
News of the Beast ahead of the demonstration has created a stir in the security community, according to Help Net Security.
The latest two versions (1.1 and 1.2) of the TLS cryptographic protocol are reportedly invulnerable to the exploit, but the majority of websites, VPNs and instant messaging services in operation use the vulnerable version 1.0 because of its compatibility with the widest range of other web technologies.
Beast consists of JavaScript code that works with a network sniffer to decrypt the cookies that carry user credentials to access accounts.
Unlike most published attacks against https that focus on the authenticity property of SSL, Beast attacks the confidentiality of the protocol, Duong told The Register.
Duong and Rizzo claim that Beast implements the first attack that actually decrypts https requests.
The researchers claim they have been working with browser and SSL suppliers since May, but every fix proposed so far has proved to be incompatible with some existing SSL applications.
Philip Hoyer, director of Strategy Solutions at ActivIdentity, said if the claims are true, authentication should be done as an ever-changing and one-time password, so even if the attacker sees a password, it always changes and hence cannot be guessed for the next authentication.
This can be achieved by many techniques, he said, both using one-time password (OTP) technology and public key infrastructure (PKI) using a challenge response.
"But this won't help to a level that is needed since the attacker can then simply read and hijack your session. So the only true defence from fraudulent transactions is to sign the transaction or part of the transaction data so that the attacker cannot inject bogus material," said Hoyer.
This means effectively using a token with a pin pad to enter transaction details or signing the transaction using a PKI certificate.
"This allows a cryptographic signature that the attacker can't forge and is intrinsically linked to the transaction data that is independent from the transport security and cannot be forged by the spying attacker," he said.
Hoyer believes this is the only way to stay secure until the infrastructure has been upgraded from TLS V1.0.
nb : computerweekly
20/09/11
NetworkMiner v1.1 Released – Windows Packet Analyzer & Sniffer Want to Learn Penetration Testing
NetworkMiner
NetworkMiner is a Network Forensic Analysis Tool (NFAT) for Windows. NetworkMiner can be used as a passive network sniffer/packet capturing tool in order to detect operating systems, sessions, hostnames, open ports etc.without putting any traffic on the network. NetworkMiner can also parse PCAP files for off-line analysis and to regenerate/reassemble transmitted files and certificates from PCAP files.
NetworkMiner collects data (such as forensic evidence) about hosts on the network rather than to collect data regarding the traffic on the network. The main user interface view is host centric (information grouped per host) rather than packet centric (information showed as a list of packets/frames).
NetworkMiner has, since the first release in 2007, become popular tool among incident response teams as well as law enforcement. NetworkMiner is today used by companies and organizations all over the world.
| NetworkMiner (free edition) | NetworkMiner Professional | |
|---|---|---|
| Live sniffing | | |
| Parse PCAP files | | |
| Receive Pcap-over-IP | | |
| OS Fingerprinting (*) | | |
| Port Independent Protocol Identification (PIPI) | | |
| Export results to CSV / Excel | | |
| Configurable file output directory | | |
| Geo IP localization (**) | | |
| Host coloring support | | |
| Command line scripting support | (through NetworkMinerCLI) | |
| PCAP parsing speed (***) | 0.581 MB/s | 0.457 MB/s (GUI version) 0.735 MB/s (command line version) |
| Price | Free | € 500 EUR |
| Download NetworkMiner (free edition) | Buy NetworkMiner Professional |
| * Fingerprinting of Operating Systems (OS) is performed by using databases from Satori and p0f ** This product includes GeoLite data created by MaxMind, available from http://maxmind.com/ *** Measured by loading dump.eth0.1059726000 from Defcon 11 (189MB) on a PC with Intel Core 2 Duo (2,66GHz) and 2GB RAM | ||
Another very useful feature is that the user can search sniffed or stored data for keywords.NetworkMiner allows the user to insert arbitrary string or byte-patterns that shall be searched for with the keyword search functionality.
NetworkMiner Professional comes installed on a specially designed USB flash drive. You can run NetworkMiner directly from the USB flash drive since NetworkMiner is a portable application that doesn't require any istallation. We at Netresec do, however, recommend that you copy NetworkMiner to the local hard drive of your computer in order to achieve maximum performance.
» Buy NetworkMiner Professional «
More Information
For more information about NetworkMiner, please see the NetworkMiner Wiki page on SourceForge.There are also several blog posts about NetworkMiner on the NETRESEC Network Security Blog:
- Pcap-over-IP in NetworkMiner
- Network Forensic Analysis of SSL MITM Attacks
- Command-line Network Forensics with NetworkMinerCLI
- NetworkMiner Video Tutorials on the Intertubes
- Webmail Information Leakage
- Analyzing the TCP/IP Weapons School Sample Lab
NetworkMiner_1-1.zip
nb : netresec
15/09/11
Google relents, offers "WiFi sniffing" opt-out
An article on Google's grandly-named European Public Policy Blog, which offers "Google's views on government, policy and politics in Europe", has gently announced what the search-and-advertising behemoth calls A new option for location-based services.Google's location-based services rely extensively on its controversial global database of WiFi access points.
The idea is simple. Google's many StreetView cars and bicycles spend their time driving around our suburbs, snapping a continuous stream of photographs of houses, gardens, offices, parks - whatever they pass on their
all-encompassing journeys.
Whilst they're about it, the StreetView vehicles also make digital recordings in other parts of the electromagnetic spectrum - to wit, they sniff out WiFi access points and record their identification information and location.
Most access points spend long periods of time with the same MAC address and network name, and in the same place. So, a list of the access points currently within range of your laptop or mobile phone lets Google make a pretty good guess at your current location.
This obviates the need for GPS - which is slow to lock when you first power it up, drains your battery if you leave it running, and doesn't work well indoors.Google's outward-facing explanation of the benefit of its massive WiFi database is that it represents value to you - it helps you find out where you are. Sadly, most of the time you already know where you are. You're at home, or in the office, or stuck yet again in a traffic jam on Parramatta Road on your way to work. Or from it.
The inward-facing explanation, of course, is that it represents value to Google - it helps Google know where you are. And that's good for targeted advertising, and that's great for business.
Anyway, after pressure from various privacy-minded data protection authorities in Europe, Google has changed its stance on its WiFi location database. You will soon be able to opt out, Google says, from being a part of the access point service.
The details of how this will work have not yet been released. How you will opt out has not been explained. And calling it "opting out" when you didn't opt in in the first place is a little cheeky.
It doesn't even sound from the blog article as though Google intends to remove your access point data from its database if you opt out. The lawyerly prose in the article simply says that if you opt out, "[Google's] services will not use that access point to determine users' locations."
(Actually, this is a Catch-22. Google pretty much has to keep you on file, simply in order to know that you didn't want to be on file in the first place. Otherwise they'd just add you back in next time the StreetView WiFi scanner came round - and then you'd have to opt out again. Sadly, you can't opt out of the StreetView collection process proactively.)Nevertheless, this is an interesting change because it shows that, with enough pressure, even data-accumulation juggernauts like Google can be persuaded to change their ways.
In short: if big companies are doing things online with your data which you aren't happy with, don't just keep quiet. Write to your Privacy Commissioner. You can make a difference!
nb : nakedsecurity.sophos
30/08/11
Hackers acquire Google certificate, could hijack Gmail accounts
Hackers have obtained a digital certificate good for any Google website from a Dutch certificate provider, a security researcher said today.
Criminals could use the certificate to conduct "man-in-the-middle" attacks targeting users of Gmail, Google's search engine or any other service operated by the Mountain View, Calif. company.
[ Learn how to greatly reduce the threat of malicious attacks with InfoWorld's Insider Threat Deep Dive PDF special report. ]
"This is a wildcard for any of the Google domains," said Roel Schouwenberg, senior malware researcher with Kaspersky Lab, in an email interview Monday.
"[Attackers] could poison DNS, present their site with the fake cert and bingo, they have the user's credentials," said Andrew Storms, director of security operations at nCircle Security.
Man-in-the-middle attacks could also be launched via spam messages with links leading to a site posing as, say, the real Gmail. If recipients surfed to that link, their account login username and password could be hijacked.
Details of the certificate were posted on Pastebin.com last Saturday. Pastebin.com is a public site where developers -- including hackers -- often post source code samples.
According to Schouwenberg, the SSL (secure socket layer) certificate is valid, and was issued by DigiNotar, a Dutch certificate authority, or CA. DigiNotar was acquired earlier this year by Chicago-based Vasco, which bills itself on its site as "a world leader in strong authentication."
Vasco did not reply to a request for comment.
Security researcher and Tor developer Jacob Applebaum confirmed that the certificate was valid in an email answer to Computerworld questions, as did noted SSL researcher Moxie Marlinspike on Twitter. "Yep, just verified the signature, that pastebin *.google.com certificate is real," said Marlinspike .
Because the certificate is valid, a browser would not display a warning message if its user went to a website signed with the certificate.
It's unclear whether the certificate was obtained because of a lack of oversight by DigiNotar or through a breach of the company's certificate issuing website.
Schouwenberg urged the company to provide more information as soon as possible.
"Given their ties to the government and financial sectors it's extremely important we find out the scope of the breach as quickly as possible," Schouwenberg said. The situation was reminiscent of a breach last March, when a hacker obtained certificates for some of the Web's biggest sites, including Google and Gmail, Microsoft, Skype and Yahoo.
Then, Comodo said that nine certificates had been fraudulently issued after attackers used an account assigned to a company partner in southern Europe.
Initially, Comodo argued that Iran's government may have been involved in the theft. Days later, however, a solo Iranian hacker claimed responsibility for stealing the SSL certificates.
Today, Kaspersky's Schouwenberg said "nation-state involvement is the most plausible explanation" for the acquisition of the DigiNotar-issued certificate.
"For one [thing], there's the type of information being looked for -- from Google users," said Schouwenberg. "This hints towards an intelligence operation rather than anything else. Secondly, this type of attack only works when the attacker has some control over the network, but not over the actual machine."
Others were more skeptical because of the claim that a single hacker pulled off the Comodo heist.
"I think it might still be a stretch to attribute this to the Iranian government," said Marlinspike on Twitter shortly before 4 p.m. ET. "We all know how that went last time."
The google.com certificate has not yet been revoked by DigiNotar -- the first step to blocking its use -- even though it was issued July 10.
Last March, browser makers, including Google, Microsoft and Mozilla, rushed out updates that added the stolen Comodo certificates to their applications' blacklists.
Today, Storms said he expected Google to quickly update Chrome, and that Microsoft, Mozilla and other would do the same some time later. "I suspect that if asked [Microsoft and Mozilla] will also issue updates, as there is already a precedent," said Storms.
Google did not reply to a request for comment on the rogue certificate.
Read More...
Hurricane Irene Scam Hits Facebook
Hurricane Irene surely turned New York City to “city that never sleeps” as it brought flood waters, knocked out power to more than 4 million people and was even responsible for at least 15 deaths in six states.
What’s worse is that cybercriminals are taking advantage of the incident by spamming a fake video on Facebook.
The page, which contains the alarming title “VIDEO SHOCK – Hurricane Irene New York kills All” displays a clickable image of a fake video player on the page.

The text displayed in the succeeding pages is in Italian, which suggests that the attack specifically targets Italian users. Clicking the image of the video displays a prompt that says “Per Vedere il video devi prima condividere” which translates to “To see the video you must first share”, as well as two options that say “Share” and “See the video”.

Clicking “Share” displays the link to the Facebook on the user’s wall.

On the other hand, clicking “See the video” displays a list of deals that the user must register to, in order to view the video.

The said deals only lead to advertisement and affiliate program websites.
Such schemes in Facebook have been rampant in the past weeks, as we’ve seen such scams that lead to spam pages or surveys. We’ve seen these attacks use various social engineering lures, such as false news about the death of of singer Lady Gaga, tickets for the Twilight movie, Breaking Dawn, and invites for Google+.
For more information on threats found in social networks such as Facebook, check our report: Spam, Scams and Other Social Media Threats, and our infograph, The Geography of Social Media Threats. Read More...
29/08/11
24 August 2011 | 2,803 views Stealing ATM Pin Numbers Using Thermal Imaging Cameras
Now this is a really neat bit of hardware hacking, it’s been a while since we’ve reported on any kind of ATM Skimming or ATM Hacking stories.
You may remember back in November 2010 – European Banks Seeing New Wave Of ATM Skimming or way back in 2008 when Pro ATM Hacker ‘Chao’ Gives Out ATM Hacking Tips.
The latest is this neat hack that came out of a method outlined by Michal Zalewski back in 2005:
Cracking safes with thermal imaging
Security researchers have found that thermal cameras can be combined with computer algorithms to automate the process of stealing payment card data processed by automatic teller machines.
At the Usenix Security Symposium in San Francisco last week, the researchers said the technique has advantages over more common ATM skimming methods that use traditional cameras to capture the PINs people enter during transactions. That’s because customers often obscure a camera’s view with their bodies, either inadvertently or on purpose. What’s more, it can take a considerable amount of time for crooks to view the captured footage and log the code entered during each session.Thermal imaging can vastly improve the process by recovering the code for some time after each PIN is entered. Their output can also be processed by an algorithm that automates the process of translating it into the secret code.
The hack works extremely efficiently on ATMs using plastic keypads, it will not work on metal keypads and this method works up to 60 seconds after you’ve used the ATM.
I’m not sure about you guys but all the ATMs I’ve seen here are using metal keypads, so it wouldn’t work too well over here.
Either way it’s a fairly cool hack and I’m glad to see, so far there’s no proof of thieves using it in the wild.
The findings expand on 2005 research from Michal Zalewski, who is now a member of Google’s security team. The Usenix presenters tested the technique laid out by Zalewski on 21 subjects who used 27 randomly selected PINs and found the rate of success varied depending on variables including the types of keypads and the subjects’ body temperature.
“In summary, while we document that post-hoc thermal imaging attacks are feasible and automatable, we also find that the window of vulnerability is far more modest than some feared and that there are simple counter-measures (i.e., deploying keypads with high thermal conductivity) that can shrink this vulnerability further still,” the researchers wrote.I wonder if we’ll see a spate of real life attacks based around this technique now the paper has been published publicly.
You can grab the paper discussing the technique here: Heat of the Moment: Characterizing the Efficacy of Thermal Camera-Based Attacks [PDF].
nb : darknet Read More...
26/08/11
MIT researchers craft defense against wireless man-in-middle attacks
Protocol can detect message tampering essential to these exploits
[ Learn how to greatly reduce the threat of malicious attacks with InfoWorld's Insider Threat Deep Dive PDF special report. ]
MORE RESEARCH: With SSL, who can you really trust?
TEP was devised by a quartet of MIT researchers: Shyamnath Gollakota, Nabeel Ahmed, Nickolaik Zeldovich and Dina Katabi, all with the Department of Electrical Engineering and Computer Science. Their research paper, "Secure in-band wireless pairing," was presented at the recent Usenix Security Symposium and MIT has its own story about the research online.
The group says TEP can be used to protect communications between devices, or between devices and base stations or access points, for any type of wireless connection.
Today, two wireless devices create a secure channel by swapping cryptographic keys, typically using what's known as the Diffie-Hellman Exchange. DHE is a cryptographic protocol designed to let two parties who don't know each other agree on a shared secret cryptographic key over an unsecured channel. Then, they use the key to encrypt their exchanges. (More on recent recognitions for Whitfield Diffie and Martin Hellman)
But Diffie-Hellman suffers from a well-known problem: An attacker inserts himself between the two parties and, for each one, pretends to be the other, sending each one his own Diffie-Hellman message. Both parties end up sharing their secret key with the attacker, who then has full access to the communications between them.
Passwords can be used to block such attacks, but there are problems. On public networks, users often have the same password. Other networks are protected with very weak passwords, or with none at all. Some use such standards as the Wi-Fi Alliance's Wi-Fi Protected Setup or Bluetooth's simple wireless pairing, a kind of push-button approach to secure connections. But these, too, are based on the Diffie-Hellman Exchange and remain vulnerable to the man-in-the-middle attack.
Another solution is to use "non-wireless" or out-of-band channels, such as audio or infrared, to authenticate and secure the channel. But these, the researchers say, can be costly and hard to adapt to small, resource-constrained wireless devices.
TEP begins by analyzing how an attacker mounts a man-in-the-middle exploit: In every case, the researchers say, the attack involves tampering with wireless messages. The researchers say they've identified these tampering techniques and can detect when they're being used. "Since we can [now] detect tampering, we can [now] trust messages which are untampered with," according to the group's Usenix presentation.
An attacker can tamper with a wireless message in three ways: by altering a message sent by one party to match his own Diffie-Hellman key; by hiding the fact that Party A has sent a message at all; and by blocking a message from being sent. TEP is designed to defang each of these tampering techniques.
It does this by compelling Party A to follow its message transmission with another: a pattern of energy "pulses" and "silences." Party A's wireless radio computes a hash of the original message, creating a sequence of ones and zeros. For each one, the radio sends a random packet; for each zero, it sends nothing -- it's silent. This combined pattern is unique to the original message.
If the attacker alters the contents of Party A's message, he, too, has to follow up with a new "silence pattern" that corresponds to the altered contents. But the two silence patterns will be different: The attacker "cannot generate silence" from Party A's "one bits." Party B can detect that difference and in effect refuse the connection offered by the attacker.
The second type of tampering is when a man-in-the-middle attacker hides Party A's transmission simply be sending its own packets and creating a collision with it. Party B sees this as a known and common event and ignores the attempted transmission by Party A.
TEP counters this by adding an unusually long, and random, synchronization packet to Party A's transmission. The packet length in effect causes it to "stand out" as not being a collision. Party B looks for these unusually long energy periods and treats them as an attempt by another party to pair with it. The attacker can't hide it by generating collisions, and if he sends his own long packet, Party B can detect it as an "unusual message."
The third tampering technique involves an attacker blocking transmissions by occupying continuously the radio channel, in effect, not giving Party A the chance to "talk" to Party B. TEP counters this by having Party A's radio time out after a known interval and transmit its message even if the channel is occupied.
"Thus we have a [transmit] message which can't be altered, hidden, or prevented without being detected at the receivers," say the MIT researchers.
But there's a potential flaw in this approach, as they note: TEP uses silent periods to authenticate communications. Other Wi-Fi devices listening on the channel would assume the silences mean the channel is open, and attempt their own transmission in keeping with the 802.11 protocol. To prevent this, TEP uses an optional mechanism in 802.11, called "clear to send" or CTS, which is a frame that reserves the channel for a given transmitter. Other Wi-Fi devices seeing the CTS frame would hold off on transmitting until Party A completes its hash transmission.
Having created this "tamper evident message," the MIT team created a protocol to implement it as part of setting up a secure wireless pairing between radios, riding on top of the push-button technique adopted via the Wi-Fi Alliance. Party A sends out a request message using the TEP primitive; Party B must reply using the same primitive within 120 seconds. If Party A receives only one reply in that time frame, and via TEP detects no tampering, the pairing goes forward.
But if an attacker tries to insert himself between the two parties, two things can happen to frustrate his attempt. First, Party A sees two replies to the original request, one from Party B and one from the attacker, and refuses to connect. Second, if the attacker tries to tamper with the Party B's reply message, TEP lets Party A detect the tampering and, again, refuse to connect.
The researchers streamlined this entire process of exchanging tamper-evident messages in order to set up a secure channel. They say that the hash and the longer synchronization packet add less than 23 milliseconds of overhead to the transmission.
nb : infoworld & John Cox
Read More...
29/07/11
Sniffjoke 0.4.1 Released – Anti-sniffing Framework & Tool For Session Scrambling
SniffJoke uses the network protocol in a permitted way, exploiting the implicit difference of network stack present in an operating system respect the sniffers dissector.
- concepts, goals, details intro
- is this "security by obscurity" (no, but, there are a long answer).
- why and how setup a location
- CODE you too: plugins specifications
- How does it works ? Hacks: how to fooling a dissector
- How does it works ? Scramble: make a sniffers desync
When you understand this, remember that the progressive acceptance of the control measure has been treated like a "necessary sacrifice". when you realize that this security method don't bring security, but only possibile abuses, you will be ready to stop accepting this useless sacrifice.
An Internet client running SniffJoke injects in the transmission flow some packets able to seriously disturb passive analysis like sniffing, interception and low level information theft. No server support is needed!
The internet protocols have been developed to allow two elements to communicate, not some third-parts to intercept their communication. This will happen, but the communication system has been not developed with this objective. SniffJoke uses the network protocol in a permitted way, exploiting the implicit difference of network stack present in an operating system respect the sniffers dissector.
How Does It Work?
It works only under Linux (at the moment), creates a fake default gateway in your OS (the client or a default gateway) using a TUN interface check every traffic passing thru it, tracks every session and applyies two concepts: the scramble and the hack.
The scramble is the technology to bring:
- A sniffer to accept as true a packet who will be discarded by the server, or
- A sniffer to drop a packet who will be accepted by the server.
The bogus packet accepted by the sniffer is generated by the “plugin” is a C++ simple class, which in a pseudo statefull tracking will forge the packet to be injected inside the flow. is pretty easy to develop
anew one, and if someone wants to make research on sniffers attack (or fuzzing the flow searching for bugs) need to make the hand inside its.
The configuration permits to define blacklist/whitelist ip address to scramble, a degree of aggressivity for each port, which plugin will be used.
You can download SniffJoke here:
sniffjoke-0.4.1.tar.bz2
FaceNiff – Taking FireSheep Mobile – Sniff & Intercept Web Sessions With Android
It is possible to hijack sessions only when WiFi is not using EAP, but it should work over any private networks (Open/WEP/WPA-PSK/WPA2-PSK)
It's kind of like Firesheep for android. Maybe a bit easier to use (and it works on WPA2!).
*** ROOTED PHONE *** is required. Please note that if webuser uses SSL this application won't work.
This application due to its nature is very phone-dependant so please let me know if it won't work for You
Use with stock browser (might not work with other)
Legal notice: this application is for educational purposes only. Do not try to use it if it's not legal in your country.
I do not take any responsibility for anything you do using this application. Use at your own risk
This apk is limited to use only 3 hijacked profiles, if you want more - you will need activation code - contact me if you're interested.
DONATIONS/ACTIVATION CODES CAN BE BOUGHT USING BITCOIN - 1Lp9C3NXiR7tF28rTN8t31xmKLBPaThXLG
NEW 2.0 RELEASE: FaceNiff-2.0-alpha9.apk
OLD RELEASE: FaceNiff-1.9.4.apk
Any questions? - Look at forum here: http://faceniff.freeforums.org How to secure yourself: LINK
UPDATES
- 03-06-2011 (v1.9.4): fixed a bug when the app crashed network on some roms
- 03-06-2011 (v1.9.3): bugfix release if the app works for you - don't upgrade. If the app isn't working you should uninstall the old one and use this.
- 02-06-2011 (v1.9.2): *** UNINSTALL OLD APK ***
- Amazon.com support
- Sniffing all supported services at the same time!
- Added option to clear list of sniffed profiles
- fixed name resolving for Nasza-Klasa
- a lot of bugfixes
- 25-05-2011 (v1.9.1): way too many updates!, fixed a bug when unlocked app wasn't working, sorry for all that trouble...
- 25-05-2011 (v1.9): added stealth mode which tries to bypass router anti-arpspoof protection,
use it only when you don't see any profiles appearing in the profile list (stealth mode is much much slower) (thanks goto: karololszak) - 25-05-2011 (v1.8.2): fixed bug when some devices couldn't buy app, added Nasza-Klasa support
- 24-05-2011 (v1.8.1): fixed twitter support, redesigned ui, added YouTube support
- 24-05-2011 (v1.8): *** UNINSTALL OLD APP FIRST *** So much changed I skipped a number!
- total code rewrite! more reliable, more stable and most of all - new updates will be easier for me to code
- now app works as a service so only explicit poweroff will shut it down
- wakelock - phone won't go off when sniffing for profiles
- fixed a bug when profiles showed up as "Unknown"
- support for twitter! (unlocked version only) - please send me request for other services I'll add them ASAP
- browse profiles from PC! (unlocked version only) - you can now use your PC at home to log onto sniffed profiles
- 20-05-2011 (v1.6.1): fixed FC when switching screens (thanks Matt!)
- 20-05-2011 (v1.6): code cleanup + when wifi disconnects you will get a message about it (that was annoying)
- 07-05-2011 (v1.5b): during update somehow Permission Denied bug reappeared, this update fixes it (I hope)
- 02-05-2011 (v1.5): fixed a bug when some devices couldn't buy an app from PP, if you encounter any problems please uninstall, *re-download* and install again
- 30-04-2011 (v1.4): *** UNINSTALL OLD APP FIRST ***
- fixed arp bug now hijacking should be more continuous and reliable.
- fixed name resolving problem that occur if hijacked invalid session
- 19-04-2011 (v1.3): lowered cpu usage + few bug fixes. (you will need to reinstall)
- 18-04-2011 (v1.2): fixed Permission Denied bug (thanks G.)
Supported services: (new coming soon)
| Confirmed to work on:
|
If you want to contact me look here: http://ponury.net/contact
If you didn't get the Key for the app after buying please check spam, if it's not there then click "Buy" again - it will redirect you to a page with your key. In case everything fails - contact me we'll figure this out
video tutorial
nb : darknet Read More...
![[+]d'ZheNwaY's Blog[+]](http://feeds.feedburner.com/blogspot/YRtWp.1.gif)


