Getting Started With Kali Linux


Kali Linux is a Debian-based Linux distribution aimed at advanced Penetration Testing and Security Auditing. Kali contains several hundred tools which are geared towards various information security tasks, such as Penetration Testing, Security research, Computer Forensics and Reverse Engineering. Kali Linux is developed, funded and maintained by Offensive Security, a leading information security training company.
Kali Linux was released on the 13th March, 2013 as a complete, top-to-bottom rebuild of BackTrack Linux, adhering completely to Debian development standards.
Kali Linux can be installed in a machine as an Operating System, Virtual Machine and also we can create a bootable USB or CD. Here we are going to install Kali Linux in a Virtual Machine.
First of all we need to download Oracle Virtual Box and Kali Linux. Download links are given below.

Step 1: Download Kali Linux and VirtualBox from the above given link.



Step 2: Install VirtualBox.

Step 3: After installation we nee to install Kali Linux in VirtualBox.

Step 4: Open Virtualbox and click on Machine then click on New and select the downloaded Kali Linux file. Then click on create.

Step 5: Start Kali Linux. The default username is root and the password is toor.

That's All
Explore the next level of  hacking with Kali Linux








Simple Tips to Secure Your WordPress Website

WordPress is the most popular content management system(CMS) for businesses all over the world. That's why hackers often violate the security of Wordpress Web sites.

Although the most effective content marketing tool in creating widgets that make blogs, websites and other resources visually appealing, it is very likely that cyber attacks are likely due to open source web development on the web.

Hackers need to change the content, use the server, malware, redirect the website to unauthorized websites, and install malware. However, the good news is to follow the simple ideas and make it easy for WordPress to protect the Web site security.

Take a deep diving to safety insights to secure your blog's website.

Tips To Secure WordPress Website

1. Do not allow multiple password attempts

In most cases, cybercriminals try the correct username and try several usernames and passwords. Here it is that you will not take too much effort if you try to access your website. That's why you do not allow WordPress to allow multiple attempts. You can also use the Jetpack, iThemes security, and so on.

2. Don't Use any Gussing Usernames

Usernames like "admin" should not be easy to guess. If a user uses the username to login, there are WordPress plugins that give you the terms of banning that person. This simple idea can prevent many hacking attacks.

3. Passwords should be changed at fixed intervals

Your password needs enough power to prevent cyber crimes, and it should be changed regularly to make sure your blog is safe and secure.

4. Use an HTTPS secure connection

SSL (Secure Sockets Layer) Certificate allows data transfer via encryption, thereby preventing hackers from retrieving any confidential information from the website. It should be a safe HTTPS connection to increase your search engine rankings.

5. You must update WordPress and its Plugins when needed

Update your WordPress and WP plugins regularly to make sure that your website is free from hackers. The main reason is that you can easily find vulnerabilities in older versions.

To update your themes and plugins automatically, use the following code into the functions.php of your theme:

add_filter( 'auto_update_plugin', '__return_true' );
add_filter( 'auto_update_theme', '__return_true' );

6. Do not reveal your version of WordPress

Wordpress Recommended that keep your version as Hidden So that hacker cannot find vulnerabilities. This can be done with the help of a few plugins provided by WordPress. You can also use the security plugins that this feature offers.

7. Do not use third-party plugins

Third-party plugins are likely to be opened up to malware, so you should not use these plug-ins and depend on only authentic plug-ins from WP.

8. Ensure a double-factor authentication when logging in

When you ensure the security of your website, two attempts are to be authenticated and tested on login. This creates additional password protection on a website by redirecting you to the second authentication screen. You need to add your Security Information to log in.

9. Get admin Dashboard password protection

WordPress allows you to protect your admin category along with the central login page. You can also add another password in this part with plugins that WP provides.

10. Avoid indexing the admin section

Search Engine Experts are looking to index websites on the World Wide Web. These indexes will gain access to the appropriate results when searching for search engines

However, all pages of the website, including personal information in the admin category, are displayed on search engines with the indexing process. It is clear that the index pages can be easily hacked.

The X-Robots-Tag HTTP header is code that represents Google's spiders. Do not mention related pages that add it. If you are not technically sound, you can help web developers use this technology.

That's it! Share your experience in the discussion thread below.

WhatsApp Hacking One And Only Working Trick in Internet [Will Be Removed Shortly]

WhatsApp has been developed from the early days using open source software. WhatsApp engineers use, contribute to and release a lot of open source software
ok guys whatsApp become so popular now we find a method to Hack it..


For hacking Such a Social App you have to be Smart..

let's start

ok
[for users Outside India Add Binary of your number]
Indian Mobile numbers have 10 digits with AB-XYZ-OOOOO format where AB- the access code, XYZ- MSC Code and OOOOO is the subscriber number. First five digits are allotted time to time by DoT to all mobile operators. Generally a set of 10 MSC codes are allotted to a mobile operator hence first four digits of the mobile number become sufficient to identify the mobile operator and circle.Now we have to spoof our number with the Target Mobile Number.

Note down the simple code Coversion
if you know the Binary conversion it will be easy

0     0 0 0 0
1     0 0 0 1
2     0 0 1 0
3     0 0 1 1
4     0 1 0 0
5     0 1 0 1
6     0 1 1 0
7     0 1 1 1
8     1 0 0 0
9     1 0 0 1





You Must convert Your mobile number and targets mobile number to binary

Eg:

919999999999 = 1 0 0 10 0 0 11 0 0 11 0 0 11 0 0 11 0 0 11 0 0 11 0 0 11 0 0 11 0 0 11 0 0 11 0 0 1

Now the encription

Encryption is the transformation of data into a form unreadable by anyone without a secret decryption key. Its purpose is to ensure privacy by keeping the information hidden from anyone for whom it is not intended, even those who can see the encrypted data. For example, one may wish to encrypt files on a hard disk to prevent an intruder from reading them

whatsApp using cryptography
  A disadvantage of using public-key cryptography for encryption is speed: there are popular secret-key encryption methods which are significantly faster than any currently available public-key encryption method. But public-key cryptography can share the burden with secret-key cryptography to get the best of both worlds.

For encryption, the best solution is to combine public- and secret-key systems in order to get both the security advantages of public-key systems and the speed advantages of secret-key systems. The public-key system can be used to encrypt a secret key which is then used to encrypt the bulk of a file or message


We have to exploit this security hole in whatApp

things you need

[Android Phone]
WhatsApp Messenger 2.11.12 
Clean Master 


[Windows Phone]
WhatsApp Messenger [any version]


For Admin Hack Of a Group 

Send this Message to group

"cng=true?=[target mobile number in binary]![your mobile number]&findchache.mnc.id=[802]ste5%Set.content?/rfd=gv<rf@5%set+mnc=tag?"

after this Uninstall WhatsApp from Your phone And Reinstall it .

For android phones clean the chache using clean master.

You will be the admin of the new group

For Get Messages Sent To your target  in your Phone Also

Change your User Name to "testuserid#"

set a complete blue picture ass your pic 

delete all previous chat history

now send this message excatly to the target

"dip.g?=testuserid#?[target mobile number in binary]xps:biu.clone.8.22.14set=tpass=[your mobile  number]?include=true?/=1mtnl.loc=true.sh"

If you get this Replay

"testuserid#?[target mobile number in binary]=1?"

Replay "testuserid#?[your mobile  number]=1"

that's all You get a copy of each message send to your Target



Have fun..
// Tech powered by DXG SOFTS PRIVATE LIMITED Total site views: 0