Thursday, August 4, 2011

Download Mac OS X 10.7 Lion Developer Preview 3 | 3.74 GB

Download Mac OS X 10.7 Lion Developer Preview 3

All the best ideas are implemented in the iPad, we make a new operating system, Mac OS X Lion for Mac, which is published in the summer of 2011. Here is a brief overview of some great features.App Store for Mac

The best way to search and download the applications for the Mac.
As App Store for the iPad, App Store for Mac offers endless possibilities of search and purchase applications. Install the application can be purchased with one click, and a second later it is displayed in a new Launchpad. App Store for Mac now available on any Mac running Mac OS X Snow Leopard. He also will be part of Mac OS X Lion.

Live here all your applications.
Launchpad provides instant access to all your applications - like the iPad. Just click the Launchpad in the Dock. Open windows will disappear, and in their place will be convenient full screen list of all applications on your Mac. You can navigate to other pages of the application gesture swipe, and you can organize applications convenient way, by dragging to new locations or integrating them in folders. When you download an application from the App Store for the Mac, it automatically appears in Launchpad and ready to go.

Once the application - and nothing more.
On the iPad each application is displayed in full screen mode - you have nothing distracting, but you can easily switch to other applications. With Mac OS X Lion's available on the computer. You can expand the window to full screen with one click, go to another full-screen application swipe gesture on the trackpad, and the same gesture back to the desktop and go to other applications. All these actions can be performed without leaving full screen mode. System support enables third-party developers to take advantage of a full-screen technology and make applications more attractive. Now there is nothing to distract you from work, and the game will become even more exciting Mission Control

Control Center Mac.
Mission Control - a powerful and useful new feature that lets you know what applications are running on a Mac. You can see them all, including Dashboard widgets and full-screen applications. A simple swipe gesture - and your screen appears Mission Control. Here you can view all open windows grouped by application, preview full-screen applications and Dashboard widgets in a single view. For any item in Mission Control can pass a single click. You will control your Mac entirely.

Convenient way to control your Mac.
Thanks to the Multi-Touch gestures any actions for the iPad simple and intuitive. Now an advanced Multi-Touch technology is available and on a Mac. You will appreciate the instant dynamic response by using gestures, such as smooth scrolling, zooming of images and pages, swipe in full screen mode. In Mac OS X Lion every gesture swipe, zoom and scroll looks and feels more realistic.
Auto Save

DOWNLOAD:

http://www.filesonic.com/file/1033510694/MAC1067Int.part01.rar
http://www.filesonic.com/file/1034239764/MAC1067Int.part02.rar
http://www.filesonic.com/file/1033531424/MAC1067Int.part03.rar
http://www.filesonic.com/file/1033531444/MAC1067Int.part04.rar
http://www.filesonic.com/file/1033531464/MAC1067Int.part05.rar
http://www.filesonic.com/file/1033531434/MAC1067Int.part06.rar
http://www.filesonic.com/file/1033538114/MAC1067Int.part07.rar
http://www.filesonic.com/file/1033538174/MAC1067Int.part08.rar
http://www.filesonic.com/file/1033538154/MAC1067Int.part09.rar

Wednesday, August 3, 2011

Search Google’s cache to look for vulnerabilities using SITEDIGGER V3.0 RELEASED 12/01/2009

SiteDigger 3.0 searches Google’s cache to look for vulnerabilities, errors, configuration issues, proprietary information, and interesting security nuggets on web sites.

What's New in SiteDigger 3.0
  • Improved user interface, signature update and results page.
  • No longer requires Google API License Key.
  • Support for Proxy and TOR.
  • Provides results in real time.
  • Configurable result set.
  • Updated signatures.
  • Ability to save signature selection and result set.

How To Use SiteDigger
  • Select the signatures from the tree
  • Provide the license key at the bottom-right box on the tool.
  • Enter the domain / sub-domain information.
  • Hit the Scan Button.
  • Save signatures and results for future analysis.


SOURCE: http://www.foundstone.com

Google SERPS - Mystery search algorithm gets Speed criteria

Google has announced that it will be adding the site speed or loading time of a website as a criteria for its Site speed as a new criteria ? - www.theprohack.comsearch rankings. this was indicated in Google’s last post in December and now its been formally announced by Amit Singhal, and Matt Cutts – Google's principal search quality team. Site speed as a new parameter reflects “how quickly a site responds to web requests" . This change is has been adopted to make this world a happier place

"Speeding up websites is important — not just to site owners, but to all Internet users. Faster sites create happy users and we've seen in our internal studies that when a site responds slowly, visitors spend less time there,"

Faster websites reduce operating costs, improve user experience and overall make internet a more habitable place. But as there are always two faces of a coin,some webmasters are just not finding site speed a solid idea. What about websites that have advertisements ? they will obviously load slower than websites with no advertisements and with plain html. What about websites with flash content ? Worse even,the Google Adsense and Google Adwords code is known to slow a website. Would that ultimately affect a website’s rankings ?

Google's New Search algorithm - www.theprohack.com

Google has provided a list of free tools to measure speed of a website. Tools like Google Pagespeed,Yahoo’s Yslow are provided to measure website’s speed. Google might use Google toolbar to measure website speed, but is it a reliable measure ? Further, the Google duo commented

“While site speed is a new signal, it doesn't carry as much weight as the relevance of a page. Currently, fewer than 1% of search queries are affected by the site speed signal in our implementation and the signal for site speed only applies for visitors searching in English on Google.com at this point. We launched this change a few weeks back after rigorous testing. If you haven't seen much change to your site rankings, then this site speed change possibly did not impact your site.”

Ah well…if this is true, then the current web design as we know it;is dead. Whatever the bets, a new competition of speed is being heralded in coming days.

In the mean time, you can check out the pagespeed addon from here

Google

Google Search Engine most confusing Boolean operator is OR

The OR operator, represented by the pipe symbol ( | ) or simply the word OR in uppercase letters, instructs Google to locate either one term or another in a query. Although this seems fairly straightforward when considering a simple query such as hacker or “evil cybercriminal,” things can get terribly confusing when you string together a bunch of ANDs and ORs and NOTs.

Let’s take a look at a very complex example.

intext:password | passcode intext:username | userid | user filetype:csv

This example uses advanced operators combined with the OR Boolean to create a query that reads like a sentence written as a polite request.The request asked of Google would read, “Locate all pages that have either password or passcode in the text of the document. From those pages, show me only the pages that contain either the words username, userid, or user in the text of the document. From those pages, only show me documents that are CSV files.” Google doesn’t get confused by the fact that technically those OR symbols break up the query into all sorts of possible interpretations. Google isn’t bothered by the fact that from an algebraic standpoint, your query is syntactically wrong. For the purposes of learning how to create queries, all we need to remember is that Google read our query from left to right.

The previous query can also be submitted as

intext:(password | passcode) intext:(username | userid | user) filetype:csv

This query is infinitely more readable for us humans.

Google Street View goof up – Privacy Invasion, data theft and Apologies

You might have heard of Google street view, heck, some of you might be avid users of Google street view, which is aGoogle Street View goof up – Privacy, data theft and Apologies - theprohack.com service that allows you that provides panoramic views from various positions along many streets in the world. Google managed to pull up that by using its elite squadron of sophisticated technocars to capture both imagery and 3D geometrical data for Google Maps and data about Wi-Fi networks that it uses in its geolocation-enabled applications. The practice of mapping and gathering data has always been a controversial practice (giving too much of power in Google’s hand, or in any techno firm is a bad omen.). It was on April 27 when Google tried to clear up misconceptions in a blog post which can be easily summarized as -
  1. We are not invading anyone’s privacy &
  2. Take a look around folks, other people have been collecting data even longer then we have.
While the whole posts was quite edgy in nature, Google tripped and now has stated in an updated post that it was not only collecting SSID and MAC information from the wifi networks, but also “fragments” of payload data from open and insecure wifi networks they drove by. At the request of the German government, Google audited its data collection system more carefully & discovered that Street View cars have been accidentally using a piece of software that can collect data being transmitted over insecure wifi networks. But it was further clarified that since the cars were always moving and their networking monitoring devices changed channels five times a second, Google says they "typically" only picked up "fragments" of data.
Google Street View Cars - theprohack.com
Nevertheless, cars have been temporarily grounded and the data has been isolated till someone figures out what do do with it. Google intents to hire a third party to examine the software is "profoundly sorry for this error" and will try to learn from it. Quoting from the official blog post


The engineering team at Google works hard to earn your trust—and we are acutely aware that we failed badly here. We are profoundly sorry for this error and are determined to learn all the lessons we can from our mistake.


Inner thoughts -
I am glad German authorities are competent enough to sniff and dig facts and give an earful to Google.
Data collection is a scary thing anyways..we need to be paranoid of what data we are allowing to be public and private considering the vast attempts of world to catch us with our pants down :P Who knows that data might be jacked up with folks at CIA/FBI/NSA to track some sucker down (there's always a chance…remember FBI carnivore ? anyone ?).
Before the screw up, Google insisted what they were doing was nothing wrong. Frankly speaking, NO company ever admits to invading anyone's privacy. It's always "your privacy is important to us" blah blah blah…skepticism is the key to protect ourselves anyways.
In the end,


if privacy is outlawed, only outlaws will have privacy
(sorry if I sound corny.. but I couldn't think better)


Privacy Outlawed ? ah well.. - theprohack.com


From – PCWORLD

Advanced password hacking using Google – easy to learn, easy to apply

Google is your best friend when it comes to hacking. The search engine giant has crawled loads of data which was intended to be protected by webmasters, butAdvanced password hacking using Google – easy to learn, prompt to deploy - theprohack.com is being exploited and mined by smart users using Google dorks. Today I will be discussing some practical dorks which will help you gain passwords, databases and vulnerable directories. The basic methodology remains the same, query Google using specialized dorks with precise parameters and you are good to go. I assume you have basic working knowledge of google dorks.

Lets start, shall we ?

FTP passwords

ws_ftp.ini is a configuration file for a popular win32 FTP client that stores usernames, (weakly) encoded passwords, sites and directories that the user can store for later reference.

intitle:index.of ws_ftp.ini

You can also this dork which uses "parent directory" to avoid results other than directory listings

filetype:ini ws_ftp pwd

Or

"index of/" "ws_ftp.ini" "parent directory"

even if the site or file has been taken offlline, you can still search the contents in the Google cache using the following dork

"cache:www.abc.com/ws_ftp.ini"

where

www.abc.com is the site you want to check the dork for.

The ws_ftp password uses quite weak encryption algorithm, hence once you get the password, you can break it using the decryptor provided here or from here.

PHP Hacking

Sites made in PHP have a file known as “config.php” which stores configuration and the username and password for the sql database the site is hosting. This password is required only once per transaction (i.e when ever admin logins or a transaction is committed at administrator level) and hence will be specified by the ‘require_once’ parameter in the config file or in index file.

intitle:index.of config.php

to view php file contents

intitle:"Index of" phpinfo.php

you can also try the directory traversal attack in php using the following dork

inurl:download.php?=filename

if you are lucky, substitute the filename with ‘index.php’, download it, read it and get the password (hint:if you are not able to find it, try looking for globals.php).

Since most websites today deny this trick, but you may get lucky with some :) You might also want to have a look at Hacking PHP 4.4 websites in 20 seconds

SQL Dumps

We will be hunting for SQL password dumps saved in database, here ext:sql specifies the type of password dump, e10adc3949ba59abbe56e057f20f883e is the md5 hash for 123456; one of the most common password people keep..and intext dork will allows to search inside the dump.

ext:sql intext:@gmail.com intext:e10adc3949ba59abbe56e057f20f883e

ext:sql intext:"INSERT INTO" intext:@somemail.com intext:password

Remember kids

  1. Use different email providers, substitute gmail/yahoomail instead of somemail ,or try custom domain mail providers.
  2. Use different file extensions.
  3. Use different type of hashes, some older ones might be using md4 and some others might be using other prominent encryption algorithms.
  4. just mix everything up and try different combinations :)

Its not over..Yet

A very flexible query can be used to hunt for WS_FTP.log which in turn can disclose valuable information about the server.

+htpasswd +WS_FTP.LOG filetype:log

You can substitute "+htpasswd" for "+FILENAME" & you may get several results not mentioned before using the normal search. You can further explore filenames by using keywords like

phpinfo, admin, MySQL, password, htdocs, root, Cisco, Oracle, IIS, resume, inc, sql, users, mdb, frontpage, CMS, backend, https, editor, intranet

The list goes on and on.. Also you cam try this dork to data mine information about the uploader

"allinurl: "some.host.com" WS_FTP.LOG filetype:log"

which tells you more about who's uploading files to a specific site, quite handy for some passive reconnaissance.

Also..if you are one hell of a lazy b**tard ,you can do it using some software like Google Hacks..but remember, manual way is the way to go. I may have included some software specific password mining, but that would cripple your imagination. My recco ? go postal by using your imagination and developing your own dorks and queries.

I guess that was enough for this time, will be coming with more tuts with time

Tuesday, August 2, 2011

Downright now - Monitoring if your favorite website is down

Last night when I was at Facebook, suddenly it stopped responding and the server requests just timed out.Downright now - Monitoring if your favorite website is down - theprohack.com I wondered if it was a problem with my ISP or the king of social networking was down at the moment. With nothing to do, I googled and stumbled across Downrightnow , a service that monitors your favorite websites. It compiles the status by combining
  • Reports from users who visit downrightnow
  • Public messages on Twitter from users who are having service trouble
  • Official company announcements and status reports
  • Other third-party web sites that monitor service status
Downright now - Monitoring if your favorite website is down - theprohack.com
As soon as I opened the website, I came to know that Facebook was having some problems at that time
Yep..Facebook was down - theprohack.com
Mission Successful :P I guess you will find it interesting.

Like This post ? You can buy me a Beer :)