Thursday, 4 December 2014

8 awesome tips for freelance programmers

 

A freelance programmer can enjoy a nice career. Not only that, he or she can avoid working at a large corporation where they will have to deal with company politics and an eventual ceiling. Of course, it is not all fun and games as a well-trained and hardworking programmer should follow some basic tips if he or she wants to enjoy success in this arena. With that in mind, here are eight tips for freelance programmers.

1. Constant communication:

 
 
When taking on a project, one should communicate with the business as often as possible. This means, when speaking to the client, one should mention any road blocks or any accomplishments. With an open door policy, the programmer will have an easier time keeping clients happy and informed.

2. Educating:

While most software developers possess a lot of skills and brains, it is wise to attend more computer classes. By continuing the education, a hardworking programmer can learn more and avoid getting left behind by the competition. In fact, this is extremely important as this field is ever-evolving and new coding ideas and techniques come up all the time.

3. Do not sell yourself short:

All-too-often, an independent contractor or business owner will ask for a low wage. When doing this, one will hurt their long-term chances for success. While it is not wise to ask for top dollar, it is beneficial to demand a livable wage. Believe it or not, when dealing with a confident programmer, a company is likely to give in to the financial demands.

4. Home office:

Whether a person works from home or at the office all the time, they should still have a home office. With this, a programmer can complete tasks without interruption from spouses, children or animals. Without a doubt, this is extremely important as a serious programmer will need to concentrate on the task at hand.

5. Have website and online presence: 

Now, more than ever, a company owner or contractor should have a website and online presence. With this, a reliable software developer can reach millions of potential clients. At the same time, while making a website, one should keep it simple, straightforward and easy to understand. With this, a programmer can showcase his or her talent for the world to see.

6. Outsource quality assurance: 

It is not easy for a programmer to check out his or her programs and code. To avoid turning in a bad product, a smart developer should hire a contractor who can check out the code. By taking a few hours to go over everything, a quality assurance analyst can find any issues and report back to the programmer. This is a great idea as one mistake can result in serious problems in the short and long run.

7. Speak up:

Often, a foolish client will want an unrealistic or impractical solution. While the customer is always right, it is still beneficial if a programmer voices his or her concerns. This should not cause a lot of problems as most business owners will willingly give in as they will, usually, trust the programmer. Either way, it is wise to remain assertive when talking about the product.

8. Set schedule:

It is often tempting for a business owner to set a weird schedule or work nights and weekends. While this is okay at first, a serious programmer who wants to succeed should opt to work a typical 9-5 schedule. This allows other business owners to stay in contact and communicate with the programmer. Since most other entrepreneurs love to work 9 to 5, this is a great way to go above and beyond and offer solid customer support.

It is not easy to work as an independent software programmer. With that in mind, with a few basic tips, a developer can take his or her ideas to the next level. Remember, when focused and ready, a programmer will please his or her clients and make a nice living in the process.

Deciphering password from WS_FTP.ini file



WS_FTP is a line of file transfer protocol client software produced by Ipswitch, Inc.for the Windows operating systems. WS_FTP stands for WinSock File Transfer Protocol. The graphical user interface of WS_FTP has two-panes: the left pane is the local computer that the software is installed on and the right pane is the server being connected to. Recent versions of WS_FTP include the ability to customize the panes and to connect to multiple servers at the same time.
The line includes a "Home" version (which lacks security features such as SSH andhttps support), a more powerful "Professional" version (also known as WS_FTP Pro), and an FTP server. WS_FTP Home used to be called WS_FTP LE, which was a Limited Edition version whose license permitted used by educational, government and non-profit home usrs (version 5.x and earlier). With version 6.0, WS_FTP LE's license was revised to allow for educational use only.
An initialization file, or INI file, is a configuration file that contains configuration data (i.e. idiom terms) for Microsoft Windows based applications.
Starting with Windows 95, the INI file format was superseded but not entirely replaced by a registry database in Microsoft operating systems. Recently, XMLbecame a popular choice for encoding configuration, as well as other kinds of data for many applications, but INI format is still in use.
Although made popular by Windows, INI files can be used on any system thanks to their flexibility. They allow a program to store configuration data, which can then be easily parsed and changed.
Use the 14th line of the google hacking query 5 to find an ini file (WS_FTP.ini file) and find the password
The password must be in that way:
PWD=V29BEA5A170EE544D8F2D7CEA802A182BA76A387266A14799AEA53D73B0AE

researcher get $10000 for hacking google server with malicious xml

This feature of Google search engine is vulnerable to XML External Entity (XXE). It is an XML injection that allows an attacker to force a badly configured XML parser to "include" or "load" unwanted functionality that can compromise the security of a web application.

A critical vulnerability has been uncovered in Google that could allow an attacker to access the internal files of Google’s production servers. Sounds ridiculous but has been proven by the security researchers from Detectify.

The vulnerability resides in the Toolbar Button Gallery (as shown). The team of researchers found a loophole after they noticed that Google Toolbar Button Gallery allows users to customize their toolbars with new buttons. So, for the developers, it is easy to create their own buttons by uploading XML files containing metadata for styling and other such properties.

The root cause of XXE vulnerabilities is naive XML parsers that blindly interpret the DTD of the user supplied XML documents. By doing so, you risk having your parser doing a bunch of nasty things. Some issues include: local file access, SSRF and remote file includes, Denial of Service and possible remote code execution. If you want to know how to patch these issues, check out the OWASP page on how to secure XML parsers in various languages and platforms," the researchers wrote on a blog post.
Using the same, the researchers crafted their own button containing fishy XML entities. By sending it, they gain access to internal files stored in one of Google's production servers and managed to read the “/etc/passwd” and the “/etc/hosts” files from the server.

By exploiting the same vulnerability the researchers said they could have access any other file on their server, or could have gain access to their internal systems through the SSRF exploitation.

The researchers straight away reported the vulnerability to the Google’s security team and rewarded with $10,000 (€7,200) bounty for identifying an XML External Entity (XXE) vulnerability in one of the search engine’s features.

Wednesday, 3 December 2014

How to Hack/Crack/Recover/Skip an iPhone/iPad/iPod’s Passcode?



Hello Apple lovers, today in this tutorial we are going to show you the simplest way to Hack, or Skip your iPhone’s passcode. Follow us after the break and do as shown to unlock any iPhone, iPad or iPod touch!

How To Hack, Skip an iPhone’s Password

 
If you are one of those “father” or “mother” who are caring so much about everything with their sons, or want to see your girl’s iPhone to be sure of anything in your mind Mr lover, or forget your passcode and looking for any way to restore your missed password/passcode!
The following tutorial guide will show you how simply you can access the iDevice without any risks or harms, just follow the step-by-step guide as shown…
First Method: 
  • The Temporary Method ( it will open the contacts app from which you can browse, edit, email any contact)
  • Tap the “Emergency call” button on the lock screen
  • Then, enter “####”.
  • As soon as you enter”####” tap the dial button
  • Immediately, press the lock button which is on top of the iPhone
  • That’s it


But this way you will only be able to call, edit and email any contact. That’s why it is a temporary method only enables you to make urgent calls or get any contact numbers from the contact list.
Second Method:
The Permanent Method That Always Works
The Permanent solution to the problem is to Restore your iPhone. It will most certainly remove the passcode or password you have forgotten, However it will wipe out all data and everything you have on your iPhone or iPad unless you have it backed up in you Computer. So, if you have decided to go with this option the Just follow these steps:
  • Sync it with your computer and iTunes and back up your iPhone. You will be able to backup your data even if your iPhone is stuck at Passcode.
  • Put your iPhone into DFU mode.
  • (To do this, reboot your iPhone by holding down the power and home buttons simultaneously for about 10 seconds. When you see the Apple logo, let go of the power button but continue holding down the home button. A message will come saying “Connect to iTunes.”
iTunes will detect your iPhone as in recovery mode and will ask you to restore it. Click the Restore button in iTunes and then wait.
Once Done restoring, Sync your iPhone with iTunes to get all your data back. [Via iTechBook
My dear reader, don’t forget to like and share this helpful post with your friends and to make sure that you are one of our Facebook fans by hitting here, or followers on Twitter over here and Google Plus for more news.

Android Forensics: How To Bypass The Android Phone Pattern Lock

Introduction

Android is an open source operating system based on the Linux kernel, initially developed by Android Inc., which Google bought in 2005. Initially, Android was developed to support touch screen devices like smartphones. These devices support different types of screen locks, like swipe lock, PIN lock, pattern lock, gesture lock, facial lock, etc.
Swipe lock unlocks the screen just by swiping a defined area on the screen with your fingertips. PIN lock is when you enter a correct pin, the screen will be unlocked. Pattern lock unlocks the screen when the user creates a pattern by joining nine circles on the screen, which is already saved on your system. This article is only based on the pattern locking system and does not cover biometric locking systems available on the phones.

Understanding Android Pattern Locks

Android Forensics: How To Bypass The Android Phone Pattern Lock - 1
Figure 1: Android Pattern lock with numbering
Patterns are nothing but the path traced by the fingers on the nine circles with the number starting from 1 to 9 from top-left corner to the right bottom corner as shown in the figure above. If we select a pattern 1478, the pattern would look as shown in Figure 2.
Android Forensics How To Bypass The Android Phone Pattern Lock -2
Figure 2: Pattern for 1478
This pattern is saved with a 20-byte SHA-1 Hash. So the SHA-1 hash for 1478 will be “06CF96F30A7283FF7258FCEF5CF587ED51156C37” which is stored in a file named gesture.key in /data/system folder in Android’s internal memory.

The Catch

The catch to change the pattern is replace this file with a known pattern gesture.key file.

Prerequisite

  1. Debugging mode should be enabled.
  2. Android adb (Android Debugger Bridge) tool.
  3. AVD (Android Virtual Device) Manager Tool.
  4. Device USB Cable
  5. Device whose password needed to be changed

Methodology

Step 1
Start an AVD (Android Virtual Device), and create a pattern in the AVD. Open a command prompt. Execute the following command to check whether the AVD has been connected to the debugger or not.
1. adb devices
The output of the command should look as shown in Figure 3. If you see the name of your emulator on the screen, then your device is perfectly connected.
Android Forensics How To Bypass The Android Phone Pattern Lock -3
Figure 3: Output of adb devices
Step 2
Now pull out the gesture.key file from the AVD. For this execute the command that is mentioned below. This file is located in /data/system.
1. adb pull /data/system/gesture.key gesture.key
The gesture.key file will be pulled to your current working directory. Here the syntax of command is adb pull . Here my current working directory is my home folder. So the gesture.key file will be pulled out in my local file system in my home directory.
The output of the command is as shown n Figure 4.
Android Forensics How To Bypass The Android Phone Pattern Lock -4
Figure 4: Pulling out gesture.key file
Step 3
Now connect the other device, whose password is to be changed and close the AVD. For my example I will be using the same AVD. So now my password in my AVD is 1478 according to the pattern cell numbers. Figure 5 illustrates the pattern.
Android Forensics How To Bypass The Android Phone Pattern Lock -5
Figure 5: Current pattern of the Device
In next step, it will be shown how to change the pattern of new device to a known pattern from the previous AVD which was 1236. Figure 6 illustrates the new pattern.
Android Forensics How To Bypass The Android Phone Pattern Lock -6
Figure 6: The new pattern which is not stored in the AVD
Step 4
Now to change the password with a known pattern, we will push our known pattern file to the new device. The command for pushing a file into an android system is shown below. This file has to be pushed into /data/system of the new device.
adb push gesture.key /data/system/gesture.key
The gesture.key file will be pushed into the Android’s file system replacing the previous file. So now android will be having a new gesture file which contains a known password, and when we use this pattern to unlock the screen, the screen will be unlocked. The syntax for pushing a file into an Android system is adb push .
The output of the command is shown in Figure 7.
Android Forensics How To Bypass The Android Phone Pattern Lock -7
Figure 7: Pushing the known pattern file into the android system
Now this changes the pattern of the new device with a known pattern. Figure 8 illustrates the known pattern unlock.
Android Forensics How To Bypass The Android Phone Pattern Lock -8
Figure 8: Pattern replaced with a known pattern

Limitations

  • The device should be rooted
  • The device should have USB debugging mode enabled

Tuesday, 2 December 2014

3 Best methods to Hack Wi-fi using Android Phones

The use of Wifi Network is common to all android users, and it's also avaliable on all android phones. Wifi network is actually a helpful tool for wireless connection to the internet with the use of radiowave of 2.4Ghz and 5GHz SHF. Wi-fi can also be known as any wireless local area network (WLAN) product which is actually based on the Institute of Electrical and Electronics Engineering (IEEE) that is of 802.11 standard.

Today's stroll, I would brief you guys on the 3 Best methods to Hack Wi-fi using Android Phones.



wifi+hacking+tools


Weeks back ago, I got lots of mails from most of my blog readers requesting for apps that could make them hack into any vulnerable wi-fi network amongst their area through the use of their android phones. With the tips I would be breifing you on, bet me, there is a 99.9% chance for any password protected Wi-fi network to be hacked.



3 Best methods to Hack Wi-fi using Android Phones




Method 1: Hacking of WPA2 WPS Routers

Step 1: Firstly, if your android phone isn't rooted, try to root it, and also make sure that such android phone have a Broadcom bcm4329 or bcm 4330 chipest unlike the Nexus 7, Galaxy S1/S2, Nuxus 1, Htc Desire HD, etc. The presence of Cyanogen ROM on your device can be of use to make the bcmon app work through.


Recommended: Do you wish to root your android device? Root it here


Step 2: Then download and install bcmon, it's essential because it helps monitor mode on your broadcom chipest that helps in the PIN Cracking.


Step 3: After installation, run the app and tap "monitor mode" option.


Step 4: Download and Install Reaver app which helps to crack the WPS Pin to retrieve the WPA2 passphrase.


Step 5: After installation of reaver app, launch it and do an on-screen comfirmation, which is, comfirmint that you're not using it for illegal purpose, then tap the APN or access poin you'd wish to crack and continue. Most times, you might need to verify monitor mode to proceed, and this would cause the bcmon to open again. 


Step 6: Verify your settings and also make sure that you've checked the Automatic Advanced settings" box.


Step 7: Finally, start cracking process by tapping start attack, at this final stage, it can take 2-10hrs for the cracking of WPS to be successful.



Method 2: Hacking of WEP Routers


Step 1: Firstly, if your android phone isn't rooted, try to root it, and also make sure that such android phone have a Broadcom bcm4329 or bcm 4330 chipest unlike the Nexus 7, Galaxy S1/S2, Nuxus 1, Htc Desire HD, etc. The presence of Cyanogen ROM on your device can be of use to make the bcmon app work through.


Step 2: Then download and install bcmon, it's essential because it helps monitor mode on your broadcom chipest that helps in the PIN Cracking.


Step 3: After installation, run the app and tap "monitor mode" option.


Step 4: Then tap the "Run bcmon terminal" option and type "airodump-ng" and Enter. Once the airodump loads finish, you would be directed to the prompt command in which you're to type "airodump-ng wlan0" then tap the Enter button.


Step 5: In this stage, a Mac address would appear, in which you're to jot down.


Step 6: Start scanning the channel by collecting information from the access point before attempting to crack the password, then type, "airodump-ng -cchannel#--bssidMAC address-w output ath0" and tap enter, then it would start scanning, try scanning till it reaches 20,000 - 30,000 packets.


Data usage- 5 Best tips to reduce High data usage on Android Phones


Step 7: To finally crack the password, return to the terminal, but make sure you've reached the suitable number of packets, then type "aircrack-ng output*.cap" and tap enter at the terminal.


Step 8: Once the password is cracked successfully, you would recieve a message alerting, 'Key Found' and would display the key in hexidecimal form. So when entering the key, make sure you eliminate the dots '.' or double dots ':', i.e if it displays 12:34:56:78:90, then enter 1234567890 as the code.






Method 3: Through the use of Osmino Wi-fi

The use of osmino wifi app seems to be the best any easiest method when hacking into a wifi network. Actually, it doesn't do any hacking but it serve as help to retrieve the already hacked password by someone else. It also tracks down the location of such vulnerability and gets connected it's network.
To download osmino wifi app, click here.


Disclaimer: Please I won't be held responsible for any illegal activity this tips is used for, it's just for knowledge sake.



How to Hack an iPhone's Passcode

Ever wanted to unlock an iPhone when you did not know the passcode? This article tells you how to hack an iPhone's passcode. This will open the contacts app from which you will be able to browse, edit, email any contact.

Step 1:

Tap the "Emergency call" button on the lock screen.

Step 2:

Then, enter "####".

Step 3:

As soon as you enter"####" tap the dial button.

Step 4:

Immediately, press the lock button which is on top of the iPhone.

Step 5:

Ta-daa! you have unlocked the iPhone. However, you will only be able to call, edit and email any contact.