I lost my broadband before some months and using a 2g phone as a modem which is (really) very slow, so i
thought to write an article about things you can do to make your experience a bit better even in slow connection.
1. Pale moon:
Basically its a windows optimized build of firefox with some tweaks in UI too, i found it a bit faster then official firefox build.
2. Fasterfox: This addone tweak your firefox or palemoon (in my case) for faster and better browsing, you don't need to mess with the settings it'll handle everything.
3. Adblock plus: Its a must have addone for everyone. block the adds so websites load faster and also block some known malware links.
4. Flashblock: Flash content takes a lot of bandwidth. This addone block all flash content and you can simply click on blocked flash if you wanna load it.
5. Fastun.com: Its a free proxy service with image compression, html compression with GZIP and code optimization. It can give a noticeable speed up to your browsing and also hide your ip address.
6. Use a download manager: If you have a slow connection, def use a download manager, it'll increase download speeds and also give you extra help to resume downloads. My favorite is IDM, but there are some free alternatives too just google it.
7. CloseTheDoor: Sometime there is a app in your pc which is connecting to internet and slowing down your work. Its a free utility to view which apps are connecting to internet. Close the apps you don't want.
8. Pidgin: Web based chat is really no go in slow connection. I use pidgin to chat with facebook friends and it works beautifully and much faster then browser based chat.
So thats it for now, have your own tips? or any comments, leave it below.
Hope it'll help you all, Thanks for reading.
Compression can be used to save the space and easily transfer the files. 7zip is the best compression utility, however it is USELESS when you are working with the media files.
There are two types of compression
1. Lossless: no lose of quality.
2. Lossy: lose of quality.
Today i am gonna tell you about best lossy compression tools available for compressing media files. In the below types of lossy compression you not gonna notice any difference until you gonna pay attention.
Video Now a days videos take a lot of space in our hds and with the recent increased prices of hard disks it become important to save the space.
Handbrake Its the best video compression utility with a lot of options for compressing the videos. Tune the RF value in video tab and bit rate in audio tab to get the desired quality in your video in small sizes.I have compressed a 4.7gb homemade video DVD to a 700 mb mp4 file using this.
Audio in my opinion there is no way to reduce the audio size without loosing a noticeable quality but using the AAC codec you can get almost same quality in half bit rates then MP3.however the only aac encoder i found working nicely is nero aac encoder but it comes with no gui.
Audiocoder Its a very nice utility to convert and compress the audio with support for all major audio formats. i found using the HE-AAC V2 you can get almost same quality in half bitrate then your mp3 source file.
Image HD wallpapers and pics from your HD camera can eat a lot of space too. Riot Its a truly amazing utility to compress images.You hardly gonna notice the difference between compressed and uncompressed image. As you can see in the image i compressed a pic i have taken with a 12 mp camera and there is no noticeable difference between these two.
If you wanna experiment with a new technology of image compression google developed WebP image format with a very good compression ratio. you can download it here. you can open webp files in chrome.To view WebP files in windows install WebP codec. Notice that its only available in cli version yet. i have written 2 simple script for encoding or decoding a folder of images at once,included in the zip file.
Please leave the comments/suggestions below. Thanx for reading.
Hello Security Explorers , Welcome to Security Explored
This is the next tutorial in Sql Injection Series.
WAF Bypassing Through Sql Injection.
WAF stands for Web Application Firewall.
A web application firewall (WAF) is an appliance, server plugin, or filter that applies a set of rules to an HTTP conversation. Generally, these rules cover common attacks such as Cross-site Scripting (XSS) and SQL Injection. By customizing the rules to your application, many attacks can be identified and blocked. The effort to perform this customization can be significant and needs to be maintained as the application is modified.
Now We are Moving A step Forward in Sql Injection , Advanced SQL injection.
In this Tutorial , I hope that u know basic sql injection .
If don’t then you should read my recent tutorial With a video demonstration.
“You have an error in your SQL syntax; check the manual that corresponds to your MySQL server version for the right syntax to use near '\' ORDER BY title ASC' at line 1”
You will get these columns - id,headline,offer,price,contact,id,headline,offer,price,contact,apr,updated,id,title,p1,p2,p3,p4,updated,id,email,name,surname,address,phone,curr_car,year,id,username,password,email
Again I need username and password ,So the columns I am going to dump are “username” , ”password”
Hello Security Explorers, Welcome to Security Explored.
Today I Am going to teach you basic sql injection with a live demo.
As you have already heard of sql injection ..
An often used way to attack the security of an website is to input SQL statements in a web form to get a badly designed website to dump the database content to the attacker - an SQL injection. It's a code injection technique that exploits a security vulnerability in a website's software. The vulnerability happens when user input is either incorrectly filtered for string literal escape characters embedded in SQL statements or user input is not strongly typed and unexpectedly executed. SQL commands are thus injected from the web form into the database of an application (like queries) to change the database content or dump the database information like credit card or passwords to the attacker. SQL injection is mostly known as an attack vector for websites but can be used to attack any type of SQL database.
we go this error “Unknown column '12' in 'order clause' ”
This shows that there is no 12th column in the database or there are only 11 columns in the database .
Ok next Step
We got the number of columns in the database , now we need to find the vulnerable column, the column in which we will inject and extract data.
To do that we are going to use “Union all select”
The “order by” , “union all select “ and much more , all are Mysql commands .If you want to learn the real knowledge behind sql injection , you need to learn about MY-SQL.
The “0x3a” between these two columns just put “ : “ ,colon sign such that you can easily distinguish betwwen username and password.
Here we get admin information ,
Username : ishir
Password : ishir123
If you need to get data other than username and password , so you have to choose columns name and table name .
Like ,
http://www.leadacidbatteryinfo.org/newsdetail.php?id=-44+union+all+select+1,2,group_concat(COLUMNS NAME SEPARATED BY “,” SIGN),4,5,6,7,8,9,10,11+from+TABLE NAME--
Now you have username and passwords of the admin , so the next thing you need to find admin page where you can login with this data ,
As we are in this world influenced by information security, we as security professional have seen many kind of Dos and DDoS attacks happening around the world but what if any one DoS your daily communication Companion ? your mobile device ? and you are just unable to call or operate your phone in proper way ,not even listen to music or even videos ??
Some years back there was DoS possible on a Nokia Phone back in around 2003. but now there is a new way (at least i think so) for performing DoS attack on a Samsung Mobile Phone. Because of auto call reject functionality of the Samsung phones.
Auto call Reject functionality : this function of the Samsung phones is used to block any number to call u so when a person adds any number like xxxxxxxxxx to reject list and if xxxxxxxxxx calls that person ,so the call is automatically gets disconnected , and that number xxxxxxxxxx can not connect a call with you.
Example : if Bob has a Samsung mobile phone and if Bob adds Mak's mobile number to is auto reject list , so when Mak calls Bob it call gets disconnected in first call ring and Bob has just a missed call alert of Mak's call.
Its a nice function of Samsung mobile phones to block unwanted callers but as by the example the rejection function reject call but it shows a missed call alert of that blocked number. This is the main flow (Bug) which allow the DoS happening on the Samsung mobile phones.
Lets take the above example again , Mak's mobile number is in reject list of Bob's Samsung phone so when Mak calls Bob his call ends immediately and with a missed call alert on Bob's phone but if Mak calls Bob in a rate of just a few seconds then ?? - than it performs a DoS on Bob's Samsung mobile phone so if Mak calls Bob in seconds again and again by his phone's auto redial function than bob is unable to receive any on else calls because its going to show busy to that other caller calling Bob. even Bob can not do calls , can not listen to music ,videos or even capture photos because the phone continuously shows missed call alerts of Mak's calls.
It happens because of the missed call alert which takes long to go from the screen on the phone. so if Samsung adds a function like some Chinese phones - they just don't show any alert on the mobile screen and shows entries of blocked calls.
Anyone can just give missed calls to that mobile number for some time so when the user of that Samsung mobile phone adds the number to auto reject list than u can register on mobivox or similar service and just write a Autoit3 script or similar to give missed calls to the person to its a DoS on his Samsung Mobile.
The script for this purpose is under construction.
Author : Ashish Mistry
Founder of Hcon
Information Security Researcher, Penetration Tester, Malware Researcher, Trainer
Hello Friends ,today i am going to teach you about phishing . Phishing is a type of deception designed to steal your valuable personal data, such as credit card numbers, passwords, account data, or other information.
In the field of computer security, phishing is the criminally fraudulent process of attempting to acquire sensitive information such as usernames, passwords and credit card details by masquerading as a trustworthy entity in an electronic communication. Let i will tell you how to create fake web pages and steal your friends username and password
1. First of all download Super Phisher here. 2. Extract it and open super phisher it will look like this
3. In the field "URL of the login page" type the url of the login page of website of which u want to create fake web page e.g : For yahoo : http://mail.yahoo.com , for gmail: http://www.gmail.com
4." name of log file " is file where your enemy details would be saved .you can give any name.txt
5. .php file is the main file here is the source of phisher name .php 6. In the last field u have to type the url where u want to redirect the enemy after login ,i t can be anything 7. Click on build phisher .
8. This creates two output files in output folder included
Well i suggest these two but u can select any other free hosting websites 10. Upload those two files on your free hosting account. 11.Send the link of your phisher(file.html not .php) to your enemy
12 When he will login on this page a .txt file will be created on your free hosting account containing his login details And your are done happy hacking If any problem related to this article feel free to comment