Skip to main content

www.kenahack.com/2013/04/tabnabbing-adalah-sejenis-serangan.html

Posted on 19 Apr by Sinchan KenaHackDoTCom "Tabnabbing" adalah sejenis serangan phishing yang baru. seperti namanya tabnabbing ia akan menukar tab yang telah di endahkan oleh mangsa menjadi log masuk phishing tanpa disedari mangsa. Kepada yang belum memahami bagaimana tabnabbing menyerang anda boleh layari video dibawah : https://www.facebook.com/photo.php?v=492488447466329 Sebelum kita teruskan tutorial ini pastikan ada sudah mempunyai pegalaman dalam membuat phishing ini kerana ia akan memudahkan lagi pembelajaran ini.. 4 perkara yang harus anda sediakan adalah: 1.youtube.html 2.Loginfb.html 3.login.php 4.tab.txt 5.tabnabb.js Semua ini boleh dimuat turun di : http://www.4shared.com/folder/2lR3G37S/KH_Tabnabbing.html Langkah 1 :Kita akan buat tab palsu dahulu, anda boleh salin sumber dari mana-mana laman muka yang anda suka. Sebagai contoh disini KH mengunakan sumber halaman muka youtube. Langkah 2 :Buka tab.txt salin script itu dan tampal ke sumber youtube.html dan simpan dengan nama yang sama. Script yang di tampal itu yang akan berfungsi mengubah muka halaman palsu youtube.html bila diendah oleh mangsa. Ini bermaksud anda boleh mengubah langkah 1 mengikut kehendak anda asalkan Langkah 2 dibuat. Langkah 3 : Buka tabnabb.js dan anda perlu cari (ctrl + F) perkataan "KenaHack". Gantikan perkataan KenaHack itu dengan pautan palsu log masuk (phishing) anda sebagai contoh disini pautan Loginfb.html dan simpan dengan nama yg sama. tabnabb.js ini akan berfungsi untuk menghalakan halaman muka palsu kepada log masuk phishing anda. Langkah 4 : KH sudah sediakan log masuk palsu facebook iaitu Loginfb.html untuk merekod log masuk mangsa kita dan login.php yang berfungsi sebagai header selepas mangsa kita log masuk. Anda boleh mengubah ia mengikut kreativiti anda. Langkah 5 : Setelah semua selesai langkah terakhir ialah memuat naik kesemua ini iaitu youtube.html , Loginfb.html dan login.php kedalam hosting anda, tabnabbing anda sudah siap dan selamat mencuba.. Ilmu di kongsi bersama-sama utk masa hadapan :)

Comments

Popular posts from this blog

Gangguan Elektrik..

1992 ~ muda remaja masa ni..sedang mengajar di kelas komputer di KL 1996 ~ sedang pulang dari menikmati buah durian dgn menumpang kereta kawan.. 2003 ~ tidak terlibat..sbb berada di KL...cuma teringat 2 pengalaman '92 & '96 2005 ~ sedang cuba mengecas bateri telefon bimbit.. ingatkan 'power trip' sbb tu.. hwa hwa hwa!!! ...The country's biggest power disruption was in 1992 when the entire Peninsular was in darkness for about 48 hours. It was caused by lightning which damaged the grid in eastern Malaysia, crippling power stations in the peninsula. The incident which occurred on Sept 29 that year, affected 18 million people and caused losses to businesses amounting to RM220 million. The second biggest power breakdown was on Aug 3, 1996 . Dubbed the "Black Friday" because it happened on Friday, it caused "massive chaos" in city centres as it occurred at 5.17pm when most people, especially office workers, were on their way home. Many were caugh...

How To Find Ebooks : One first trick

intitle:index.of intitle:ebooks|books|ebook|book intext:chm|pdf|zip|rar intext:nfo Add this on query to find files on file hosting server: Rapidshare: intext:rapidshare.de/*/*/* QFile: intext:qfile.de/*/*/* MegaUpload: intext:megaupload.com/?d= mytempdir intext:(sr1|sr2).mytempdir.com/* savefile.com intext:savefile.com/files/* Yousendit.com intext:yousendit.com/*.aspx?id= A variant of the Rapidshare query is the following: site:rapidshare.de OR intext:rapidshare.de/files/ On all the queries you have posted, the last asterisk or wildcard is being ignored by Google. Just put a '/' or forward slash on the end of these queries and Google will not ignore it (i.e. intext:rapidshare.de/*/*/*/). With Rapidshare, you don't need the wildcards because anything that comes after "rapidshare.de/files/" is going to be a number followed by the name of the actual file. QFile query is the same as the Rapidshare query. The following will work and return less noise than what you have...

Virus Tips..

Ten Commandments for Your Computer Sanity 1. Do not open e-mails coming from unknown or distrusted sources. 2. Do not open any e-mail message unless you know what is it about, even if it comes from a friend or partner. Most viruses spread via e-mail messages so please ask for a confirmation from the sender if you are in anny doubt. 3. Do not open the attachments of messages with a suspicious or unexpected subject. If you want to open them, first save them to your hard disk and scan them with an updated antivirus program. 4. Delete any chain e-mails or unwanted messages. Do not forward them or reply to their senders. This kind of messages is considered spam, because it is undesired and unsolicited and it overloads the Internet traffic. 5. Do not copy any file if you don't know or don't trust its source. 6. Be very careful when downloading files from the Internet. Check their source every time and make sure that an antivirus program already verified the files on the download site...