Cyber gate tutorial + no-ip setup

Tuesday 12 April 2011

 Download file..

1:Cybergate rat & no-ip pack : click here


Setting Up The No-IP & Client
1. Start Off By Going To; No-IP.com And Register. If You Have An Account There Already, Then Just Log In.

2. Once You've Logged In, Press "Add Host"
[Image: NOIP1.png]

3. Now It's Time To Choose Your Host Name!
[Image: NoIP2-1.png]

Hostname: Your Host Name, EG:

YourHostName.no-ip.biz

Host Type: DNS Host (A)

Dont Care About The Rest, Once You've Choosen Your Host Name, Press "Create Host" In The Lower Right Bottom.

The Host Is Now Finished! Lets Move On To The No-IP Client.

1. The No-IP Client You Downloaded In The Beginning (present in cyber mafia rat pack), Extract It To Your Desktop & Install It.

2. Now When You've Installed It, Open It Up & Log In With Your No-ip Username & Password.

3. When You're Logged In Press "Select Hosts" And Then Check That Little Box With Your Hostname.
[Image: No-ip3.png]

--// Note: Always Have No-IP Open When You Have Cybergate Open!

There! Your No-IP Host & Your No-IP Duc Is Now Sat Up!

Setting Up Cybergate 1.07.5

1. Extract The Cybergate File You Downloaded In The Beginning To Your Desktop! Once Extracted, Open It & Wait 20 Seconds For The Agreement To Pass! :)

2. When It's Open, Press: Control Center -> Start.

3. Press: Control Center -> Options -> Select Listening Ports
[Image: RAT4-1.png]
4. Once You've Pressed The "Select Listening Ports" This Window Should Appear:
[Image: RAT5-1.png]
5. --/

Firstly, Write "100" In That Little Box And Press The Blue Arrow. Then It Should Appear Under "Active Ports"

Active Ports: The Port You Will Forward Later!

Connections Limit: The Max Amount Of Victims You Can Have.

Connection PW: The Connection Password. Use "123456"

[V] Show Password: (Shows Password)

Once This Is Done, Press "Save"!

6. Now We'll Go To The: Control Center -> Build -> Create Server.

[Image: RAT6-1.png]
User: First, Press "New" And Name It To: "Plutonium". Once Done, Press "OK"

Now Just Double Click On "Plutonium" Or Press "Plutonium" And Then Press "Forward"

7. Now We're In The "Connection" Tab.

[Image: RAT7.png]

First, Press "127.0.0.1 - 999" And Then Press Delete.
Now Press "Add" And Write Your Hostname In It + :100.
Like This:

Quote:YourHostName.No-ip.biz:100


Change The Identification To: Cyber
Change The PW To: 123456

**Note, If You Want To Try The Server On Yourself, Then Delete Both:

- 127.0.0.1:999
- YourHostName.No-ip.biz

And Replace Them With; 127.0.0.1:100 Since 127.0.0.1 Means "Local Computer & LAN Internet"

Make The DNS/HostName Server First Though! :)

DNS: Your Host Name, EG:

Quote:YourHostName.no-ip.biz

Port: The Port You Will Forward Later.
Identification: The Victim Name
PW: The Password You Wrote In The Options, "123456"

8. Once You're Done With Theese, You'll Move On To The "Installation" Tab.

9. Have The Same Settings As I Do, And Follow The Instructions In The Image!

--//--//--//--//--//--//

Install Directory: Where The Server Installs,

%System%
%Windows%
%Root%
%Program Files%
%Other%

Use The "System"! :).

Boot: This Is The "Startup" Option. Have Everything Checked & Press "Random" 5 Times And It Will Startup On Your Victim Everytime They Start Their Computer!

Directory: Where The Virus Folder Installs
File Name: What The File Will Be Inside The Folder.

Inject Into. What Process It Injects into, Use Svchost.exe!

[V] Persistance: Keeps Trying To Inject Until Succed.
[V] Hide File: Hides The File, (Not FUD Though!)
[V] CCD: Changes The Creation Date From 16th July To 4 September 2005.

Mutex: Mutex Of The Server, Just Press Random A Couple Of Times!

There We Go, You've Now Completed The "Installation" Tab!

--/ Skip The Message & Keylogger Since They Are Pre-Set Already!

10. You Should Now Have Trumbled Into The "Antis" Tab, Have Everything Checked! (Except SANDBOXIE If You Are Gonna TRY IT ON YOURSELF!)

[Image: RAT9-1.png]
Ok, The Final Tab.. "Creation Of The Server". Have Every Setting As Me!

[Image: RAT10-1.png]

V] Use Icon: Yes Buy i have notice some crypter corrupt the server if you use an icon
[V] Delayed Execution: (How Many Seconds It Takes Until Your Server Injects And They Pop Up In Your RAT)
[V] Google Chrome PW: Yes, Steals Their GC Passwords :)
[X] Bind Files: No, Get An Real Binder Instead! (Have Your Server Crypted Though First!)
[X] Compress With UPX: Makes The Server Smaller But More AV's Detects It!

There! Your RAT Is Now Fully Sat Up. You Do Only Need To PORT FORWARD First To Make It Work! Follow This Tutorial: Plutoniums Port Forward Tutorial! And Everything Should Work Out Well!

Quick Troubleshooting If Your RAT Doesent Work:

Non-Connecting RATs

Make Sure That....

1. ..You are properly port-forwarded if using a router.
2. ..You have the No-IP Client installed and running.
3. ..Your DNS entries are correctly spelled when building your server.
4. ..The password in Listening Ports and the password your server uses are identical.
5. ..You are Listening on the correct ports.
6. ..Your Firewall is letting connections through on the port you're listening on.
7. ..Your server is added to excluded files in your Antivirus and Firewall.

''By:Malik'' If You Have ANY Troubles With This, Feel Free To contact me & I'll Reply As Fast As I Can.

Armadax Key loger-remote installation

Wednesday 6 April 2011

Ardamax Keylogger 2.85 Tutorial
I. Get Ardamax 2.85:

Download: Click Here


1. Once you’ve downloaded and installed it, you’ll see a little notepad icon in your taskbar.
[Image: step1111.jpg]
2.Now right-hand click it and click ‘Enter registration key…’.
[Image: step210.jpg]
3.Copy/Paste Registration name and Registration key from Serial (your reg key is present in the download pack).
[Image: step310.jpg]
4.Once done click ‘Ok’ and you should get a pop-up saying ‘Registration code is accepted. Thank you for registration!’
[Image: step410.jpg]
II. Creating the Keylogger Engine:
1. Now your going to make the Keylogger Engine (The thing you give to your victim). Click ‘Remote Installation…’,
[Image: step514.jpg]
click ‘Next’
2.Now,you should see this.
[Image: step613.jpg]
3.If you want to bind Keylogger Engine with another application or file click the box that says ‘Append keylogger engine to file or another applitacion’ and browse file or applitacion that you want to bind it with.
[Image: step710.jpg]
4. Now click ‘Additional components’ and tick ‘Installation Package Bilder’ like done in the screenshot.
[Image: step810.jpg]
5.Now you should be at ‘Invisibility’, make sure all the boxes are ticked, then click ‘Next’.
[Image: step918.jpg]

6. Now you should be at ‘Security’, click ‘Enable’ and put your password (it can be any password you like, make it something easy so you can remember). Once done, make sure all the boxes are ticked and click ‘Next’. [Image: step1010.jpg]
[Image: step1110.jpg]
7. Now you should be at ‘Web Update’, un-tick ‘Check for updates’ and Click ‘Next’.
[Image: step1210.jpg]
8. Ok, you should now be at ‘Options’, use setting like done in screenshots.
[Image: step1310.jpg]
Btw you can make your keylogger to self distruct any time you like.
[Image: step1410.jpg]
9. Ok, now you should be at ‘Control’, click the box that says ‘Send logs every’, now make it so it sends logs every 20 minutes, then where it says ‘Delivery’, un-tick ‘Email’ and tick ‘FTP’, then where it says ‘Include’ un-tick ‘Screenshots’, now un-tick the box where it says ‘Send only if log size exceeds’, once thats done, it should all look like it does in this screenshot:
[Image: step1510.jpg]
10. Now you should be at ‘FTP’, create a free account at http://www.drivehq.com/secure/FreeSignup…om=storage, then make sure your at ‘Online Storage’, then make a new folder called: Logs (this is where the logs are sent to when you keylogg someone), Now on your FTP on Ardamax Keylogger, where it says ‘FTP Host:’, put this:
Code:
FTP.DriveHQ.com
Now where it says ‘Remote Folder:’, put this: Logs
Now where it says ‘Userame:’ and ‘Password:’, put your DriveHQ username and password, then it should look something like this:
[Image: step1610.jpg]
Now Click ‘Test’ and it should pop up like this:
[Image: step1710.jpg]
Once done, do NOT change your DriveHQ password or rename/delete the folder called ‘Logs’, if you do, the logs will not come through.
11. You should now be at ‘Control’, un-tick ‘Enable Screenshots Capturing’ then click ‘Next’.
[Image: step1810.jpg]

12. Now you can change name and icon your Keylogger Engine as you want it to look like. [Image: step1910.jpg]
[Image: step2010.jpg]
and click ‘Next’.
13. Now you should see this.
[Image: step2110.jpg]
just click ‘Finish’.
14.After you click ‘Finish’ you should see this:
[Image: step2210.jpg]
Click ‘Ok’
15.Now your Keylogger engine is created.
[Image: step2310.jpg]

Note: All the content on this blog site is for educational purpose. We will not be responsible for any harm caused by it.

Tips For Securing yourself at facebook

Saturday 2 April 2011

  During last few years, Facebook has become very famous and they are also trying to make it more secure and safe with the passage of time, also user friendly. Facebook interface is totally changed now and it will keep changing since technology and progress doesn't stop. I received many emails asking me a question that :
"My Facebook profile has been hacked, please! help me to take it back!"
But personally its bit difficult to take a compromised profile back. All this is possible by some social engineering tricks. So, better is to be secure and more safe already rather than asking for help after after getting hacked. There are many drawbacks of getting hacked as your personal photos can be leaked and your private messaged too. Thats the reason i am posting here at hackersthirst on how to remain or make your online presence secure.The problem is this that even many users don't know how to use security features provided by Facebook. Lets, Take a review of them:
1) Linking your Facebook Account with gmail, hotmail or yahoo:
Infact this feature is quite good, Now assume that your profile has been hacked and the hacker changes email id as well as your password. But if he didn't take notice of the linked accounts then you can access your account. How? lets see, You have linked your google account with facebook, now when ever you log into your google account, cookies are stored in your browser, now you are logged in your facebook linked account i-e google, Navigate to www.facebook.com and thats it you will be logged in automatically after few seconds. Without entering Email ID and Password with the use of cookies.
Inorder to enable this feature, Login to your facebook account. And Navigate to >> Account (At top right corner) >> Account Setting >> Linked Accounts
And then add your any yahoo, hotmail or gmail account. As there are options given.

2) Specifying Your security Questions:
Sometimes accounts can also be compromised by guessing security questions of the victim social ID. But Specifying some good and powerful security questions for your Facebook profile is better. But keep in mind:
a) Security question must be about some personal thing which other don't know.
b) Don't use easy questions which can be guessed by others like, What is your father name? In which school did you read? What was your first gift? etc
c) This section is majorly up to your own mind that how much you make it strong, so better make strong personal questions. So that if your account is hacked you may get it back.

For security questions section,Login Facebook, go to Account (At top right corner) >> Account Setting >> Security Question.
3) Remain Safe from phishing Links:
Often new Facebook user who are not aware of phishing scams, They open the link given by facebook user and then Login using that page login fields and get hacked, since email id and password is sent to the hacker. Following may be form of phishing page link (If on opening such links you get a similar facebook login page then its a phishing page don't login form there) :
a) www.website.t35.com
b) www.website.100mb.com
c) www.website.0fees.net
b) www.website.co.cc
c) www.website.tk
d) www.website.free
e) www.website.co.nr
c) Bit.ly/facebooknewcredits
And much more smilar to them, If on opening them you get facebook login page, then close your window and don't login from there.
What to do if you have logged in from phishing page?
Answer is simple just change your password. Well, Also facebook will warn you after logging in from fake/phishing page that you have come from a phishing page change your password.

4) Remain Safe from inserting obfuscated java script in browser address bar:
I have created a detailed post in past that how hackers make use of java script to hack your facebook unique email id or fan pages. Kindly Refer here for detailed information. Inshort, Don't paste any script in the browser address bar while browsing facebook. Since it will be harmful and will steal your id.

5) Browsing Facebook On Secure Connection:
This feature of Facebook will allow to browse in secure connection whenever it is possible. In such case your data sent to server is encrypted by using a scheme and so that it can't be Hijacked. To use this feature go to Account >> Account Setting >> Account Security And then tick the option given in pic below:
6) Receiving SMS and Email Alert when New device logs in your Facebook Account:
This is quite a good Facebook Security Measure, You can receive sms at your mobile ( If you have linked your mobile to Facebook) and an email when another computer logs into your facebook ID with another ip address. To activate this, Go to Account >> Account Setting >> Account Security
Now, After ticking and Saving settings you will see a prompt appearing when your log into your facebook account that name your device, i-e it may be home, office or etc. and whenever other device logs into the name will be sent to your activated mobile and also email. So that if any new or unknown device logs into your facebook ID then you may know that your account is compromised  and change the password at once.

7) Receiving Temporary password for loging into Facebook at Public place:
If you are at a public place and as a security measure you will like to make or get a temporary password for logging into facebook which will expire after sometime. So that your password may not be logged in any friend, official or public computer. To get one text "otp" to 32665 (Works If you are in US or some other countries too and also your mobile is activated for facebook texts) and you will get s temporary password which will expire after 20 to 15 minutes and can be used in this time interval to be logged into Facebook.

8) Tab-Napping Can be Used to Hack your Social Accounts:
We know a lot of users are using latest browsers in which there is option for tabbed browsing. Now hacker may give you a link in which the tabbed napping script is used and that page on becoming idle for some seconds will redirect you to a phishing page or cookies stealing page and you will not know that did you opened facebook or any other social network or not, you will just log in from there.
9) Using Trusted Facebook Applications:
Surely there are many fake and spammy application there at facebook. Personally, it depends on your experience that how you indentify scams. There are many application which may redirect you to there own server, also these applications may hack your personal unique facebook mobile id, and these applications can be used to send messages as well as posts updates to your friends wall automatically. Well, There is no application which may change your facebook profile theme, yes it is true also no application can use facebook logarithm to determine that who viewed your pofile. All such things are scams. Also, whenever clicking an image, copy link location by right clicking and then you will know whats behind like there may be:
www.website.etc.com/tools/gift.exe
So, you have come to know that an exe file is embedded in the image which can be trojan or keylogger server. Report to Facebook if you find such applications. And accidentally if you granted access to your account for such applications, then inorder to delete them follow these steps:
Go to Account >> Privacy Setting >> Apps and Websites
Now, take your mouse to the right corner of the application which you want to delete, and a pencil icon will apear like this click it:
After clicking it, you will see menu like this:
10) Remaining Safe from email social engineering:
Similary phishing pages and other cookies stealing pages links (Keylogger server also) can be sent by using email service. Or also by using fake emails. These emails may urge you to click the link provided. As these emails may say, Click link to claim your 10000 fans facebook page, Click link to claim free farmville gifts, and much more. Read my post on fake emails to clear your view that how a hacker may fool you.

For other security measures, Kindly tell me in your comments, Your view is always appreciated......!!
Note: All the content on this blog site is for educational purpose. We will not be responsible for any harm caused by it.

Usefull Sites

To check if a port is open:


To multiple scan a file for viruses:

The best online dork scanner out here:


To check if a site is down

A place to get newest exploits


Lets other people view your inserted text


The free online crypting + decrypting service


An online MD5 decrypter


The best online Admin Page Finder


Online WPA cracker


Online Fake Mailer


It gives you alternatives for program's


Upload and send files to friends etc. Very quick


Online LFI RFI PD Scanner


i will post more links soon inshAllah .....