Showing posts with label HACKING. Show all posts
Showing posts with label HACKING. Show all posts

Wednesday, 6 November 2013

Hacking Online Casinos with Casino Hacking Software Kit by Hackingloops


Have you ever thought Online Casinos can be Hacked? If not, then start now because Hackingloops team has done it. Hackingloops team has made an Casino Hacking Software Kit which will hack the casinos and will generate profits of at least 60$ - 600$ per hour depending upon the Packages. Note: This is limited period offer only for Hackingloops readers. Casino Hacking Software Kit supports following games Roulette, Slot Machines, Blackjack, Scratch card games, KENO. Note: Current version of Hack does not support Poker but it will soon cover that too. Also Casino Hacking Kit can only be used at Online Casinos powered by Playtech. Don't worry there are 70+ Online Casinos which uses Playtech Casino Softwares and Games. So let me give you some idea about online casinos and Casino Hacking Kit. Don't miss this!

KNOW MORE ABOUT CASINO HACKING KIT

Casinos are basically the gambling houses, where users gamble to earn huge amount of money. But most of times they end with loosing handsome amount of money. This is what makes the casinos a multi billion dollar industry. As we all know everything is nowadays moving to online web world, so is the casinos. Now we can play almost all physical casino games(like Roulette, Slot Machines, Blackjack, Poker, Keno etc.) online on online casinos. Most casinos claims that they have payouts of 83% to 97% in their yearly audits but we all don't know what actually is this? This percentage payout is actually something like say 1000 players played 10$ each for year on particular gambling machine, means 1000X10=10000$ is in inside machine now 83% payout means 83% of 10000$ and that means only 8300$ as output which implies 8300$ will be distributed among player who are lucky to win that can be 1 in 1000 or 5 or 10 and Online casino companies profit is 1700$ no matter who wins or loose. So they are always at profit and 95% players are always at loss. From last few days our Hackingloops team was busy on targeting Online Casinos and after 40 days of rigorous analysis and hacking attempts we are able to perfect the Hack for online Casinos and make an average of 60$ to 600$ per hour(depending upon the package you choose i.e. Bronze Package makes 50-100$/hr, Silver Package makes 300-450$/hr and Diamond Package makes 500-600$+/hr). That sounds crazy but it does. Currently we are offering Casino Hacking Kit for Casino games namely Roulette, Slot Machines, Blackjack, Scratch Card games. Note: Poker is not currently a part of Hacking Kit because we are still in cracking phase of Poker RNG(Random number generation) algorithm but we will be adding it soon to Casino Hacking Software Kit. Let me give you brief what you will get inside the Casino Hacking Kit sponsored by Hackingloops.

online casino hacking software Kit
Online Casinos Hacking Software Kit


Some important features of Casino Hacking Kit by Hackingloops:
  • Autoplay Bot with Maximum Profit auto config settings.
  • Casino Hacking Kit makes 60$ - 600$ Profits per hour depending upon the Package you choose.
  • Anti - Cheat Detection Feature Inbuilt to protect players from getting caught.
  • RNG Patches for Slot Machines, Roulette, Blackjack and KENO games.
  • Play for Buddy feature where one of 9 members of Hackingloops will play on behalf of user to recover all the money lost by player and will make atleast 500$ profits for player.
  • Super Money Back Program : If you are not satisfied with the Casino Hacking Kit by Hackingloops you will get all you money back in 48 hours i.e. Package Cost + Deposited Amount + 50$ SMBP reward for customer satisfaction.
  • 70+ Casinos Supported by Hack be precise all Online Casinos who users Playtech Casino Softwares and games are supported.
  • Will make atleast 150$/hr with all the slot machines and KENO games.
  • Till date sold 40+ copies of Hack and till now 0 complaints at all. You can go through testimonials of user that purchased our Casino Hacking Kit.

KNOW MORE ABOUT CASINO HACKING KIT


Casino Hacking Software Kit Includes:

1. Roulette Auto Play Bot 
Roulette is one of the most popular game in Casinos world. We will provide you with Roulette auto play bot which will place bets automatically that means no user interference at all. This bot will place bets on your behalf. Note: There are lot of free roulette bots available online, but none will give you guarantee that it will make money for you, all comes with warning that Roulette bot will not provide any damages or guarantee if player loses. That sucks! But be cool, we are giving guarantee with Super Money Back Campaign which in explained down in article.

2. Auto Config Roulette bot Maximum Win Settings 
This is what will make your roulette bot different from the others. We will provide you settings for our roulette bot which will provide you maximum profits with anti - cheat mechanism to fulfill the wagering requirements for payout. This will also protect you from getting caught online because there is no regular pattern.

3. Roulette RNG(Random number generation) Patch
We all know all Roulette Machines are based on RNG algorithm that means there is piece of code which generates random numbers between 0-36 counting 0 twice that means 38 numbers. All online casinos regularly updates(means updates usually on weekly basis or fortnight basis or in emergency) their random number generation algorithms and 99% Hacks fail after that. So in order to make continuous profits user need to update their RNG algorithm patch as per casino updates. Don't loose you cool and leave that to us, as we will update and send the regular patches to all our customers on regular basis i.e. as soon as its updated.

4. Slot Machines Random Generation Patch which maintains profits of 150$+/hr.
Slot machine RNG algorithms are little different from the roulette RNG's. Roulette RNG's are based on PRNG i.e. Pseudo RNG that means it repeats itself after sequence is over. Well sequence is generally 1 Million numbers (depends upon casino software provider to provider, also its not exact 1 Million its somewhere near around it) long on an average that means after 1 million numbers the sequence will repeat itself. While Slot Machines have different Mechanism, Considering a 5-reel Slot Machines with 25 lines and 8 different cards and 1 scatter card and 1 wild card that makes 9 unique and 1 wild card that can comprise of all. Normally people thinks that position of all cards is fixed in vertical lines but that's a myth because all 9 unique cards are randomly rotated for each slot i.e. in 5 reel (i.e. 15 different slots, 9 unique cards and 1 wild card) means 15XFactorial 9XFactorial 10 outcomes of 1 simple spin. So its quite hard to beat such Random Generation Patch but where there is hope there is way. Most casinos launch campaigns to attract new customers and for new customers usually Payout is high i.e. near 130%. But regularly new customers adds up to casino's and how they maintain this?? Answer is quite simple, they use multiple Data Servers and Gaming engines. With our through analysis we are able to identify the highest payout dataservers and hence we can maintain a profit of 150$+/hr.

5. All in one Casino Games Patch
This is similar to above concept. This patch will connect you to those dataservers in which Payout is high i.e. means win win situation.

6. Silver and Diamond Packages include Play for buddy feature where profits will be shared in 50:50 ratio.
Wow this is something unique, not all online casino players are that smart and sometimes there can be losses. To make every person earn who have invested in our Software Kit, we came with offer Play for buddy. In this one of 9 members of Hackingloops will play via Team viewer on your behalf and all profits will be shared in 50:50 ratio. Say our Player makes 1000$ profit then 500$ will be given to you and 500$ will be Hackingloops member share.

7. Super Money Back Campaign
That's the best part of our Package. Suppose any how you are not able to win with our Casino Hacking Software Kit. We will give you back all your money back + money invested in casino + 50$ bonus money. But that valid for first 15 days of purchase only. Don't worry if you play as guided you will make more that 5000$ with the hack in your first week. 


Last few words about Casino Hacking Software Kit, if you miss it you will miss best chances to make money from online casinos. 

Casino Hacking Kit Package costs 100$( Bronze Package), 200$ (Silver Package) and 250$ (Diamond Package). This might sounds little costly to new users but by you can recover that money in less than 2 hours by playing with our Casino Hacking Kit. Note: If you face problems with setup we will provide you Team viewer Support online and will setup it in your Machine. 

If you are not satisfied with the Casino Hacking Kit, then just send us a message that you are not satisfied with the Hack and snapshots of all deposits you make, you will be eligible for Super Money back Campaign and will get your money back withing 2 days.

Why Waiting? Go Ahead and Buy Casino Hacking Kit Now. Its now or never.

Actually waiting is just waste of Time and Money! This is initial sales campaign and we gonna increase our prices after first 200 sales. So Buy Casino Hacking Kit Now!
 
BUY CASINO HACKING KIT NOW 
or
KNOW MORE ABOUT CASINO HACKING KIT

Still scared! Another offer for first 50 buyers. First 50 buyers will get No deposit referral bonuses of at least 25$ as initial deposit at all Playtech Casinos and first 20 will get play with buddy feature and hidden bonuses.

Enjoy!

Read more: http://www.hackingloops.com/2013/10/hacking-online-casinos-with-casino-hacking-software-kit.html#ixzz2juAoQ9gE

11 Firefox Addons a Hacker Must Have and use


Firefox is one the most secured web browser in the world. Have you ever dreamed of that we can use Firefox to Hack like a pro? Firefox like other browsers has a feature called add-on. Add-ons adds an additional functionality to your Firefox browser. There are thousands of Firefox add-ons available for Mozilla but Hackingloops brings you the best and most effective Hacking add-ons ever on Firefox. In short, we are listing a most popular and interesting Firefox add-ons that are useful for Hackers. This list of 11 add-ons vary from information gathering tools to attacking tools. All these add-ons are available for free and you can download from the Mozilla add-on website. So friends lets see what Hackingloops has bring this time for you. I will list them in way from top( I like most) to bottom pattern but note that all of them are extremely good tools.

Firefox addons for Hackers
Firefox Add-ons for Hackers

11 Firefox Add-ons a Hacker Must Have and use


1. Tamper Data
Tamper data is an great tool to to view and modify HTTP/HTTPS headers and post parameters. We can alter each request going from our machine to destination host with this. Thus it helps in security testing web application by modifying POST parameters. It can be used in performing XSS and SQL Injection attacks by modifying header data.
Add Tamper data to Firefox:
https://addons.mozilla.org/en-us/firefox/addon/tamper-data/

2. Firebug
Firebug is a nice add-on that integrates a web development tool inside the browser. With this tool, you can edit and debug HTML, CSS and JavaScript live in any webpage to see the effect of changes. It helps in analyzing JS files to find XSS vulnerabilities. It’s an really helpful add-on in finding DOM based XSS for security testing professionals.
Add firebug to your browser :
https://addons.mozilla.org/en-US/firefox/addon/firebug/
 
3. Hackbar
Hackbar is a simple penetration tool for Firefox. It helps in testing simple SQL injection and XSS holes. You cannot execute standard exploits but you can easily use it to test whether vulnerability exists or not. You can also manually submit form data with GET or POST requests. It also has encryption and encoding tools. Most of the times, this tool helps in testing XSS vulnerability with encoded XSS payloads. It also supports keyboard shortcuts to perform various tasks.I am sure, most of the persons in the security field already know about this tool. This tool is mostly used in finding POST XSS vulnerabilities because it can send POST data manually to any page you like. With the ability of manually sending POST form data, you can easily bypass client side validations of the page. If your payload is being encoded at client side, you can use an encoding tool to encode your payload and then perform the attack. If the application is vulnerable to the XSS, I am sure you will find the vulnerability with the help of the Hackbar add-on on Firefox browser.
Add Hackbar to Firefox:
https://addons.mozilla.org/en-US/firefox/addon/hackbar/

4. Cookies Manager +
Cookie Manager is one of the greatest tool ever made. Using this tool you can actually play with cookies. You can alter almost all cookie using this tool. You can use Cookies manager to view, edit and create new cookies. It also shows extra information about cookies, allows edit multiple cookies at once and backup/restore them.
Add Cookies Manager to Firefox:
https://addons.mozilla.org/en-US/firefox/addon/cookies-manager-plus/

5. NoScript
No Script add-ons greatness is beyond imagination. With this tool you can monitor each an every script running on website, you can block any of scripts and see what actually that scripts does on website. But this add-on is for experts, newbies will face problems using this. Note: If you are testing XSS, HTTPS header modifications, Injection attacks on any website you need to disable this plugin because it will not allow you to do so. 
Add NoScript to Firefox:
https://addons.mozilla.org/en-us/firefox/addon/noscript/

6. Grease Monkey
Grease Monkey is an counter part of No Script, its actually behaves opposite of Noscript. We use Noscript to block the scripts and use GreaseMonkey to run the scripts. It allows you to customize the way a web page displays or behaves, by using small bits of JavaScript. 
Add Grease Monkey to Firefox :
https://addons.mozilla.org/en-US/firefox/addon/greasemonkey/

7. User Agent Switcher

User Agent Switcher add-on; adds a one click user agent switch to the browser. It adds a menu and tool bar button in the browser. Whenever you want to switch the user agent, use the browser button. User Agent add on helps in spoofing the browser while performing some attack.
Add user agent Switcher to Firefox:
https://addons.mozilla.org/en-US/firefox/addon/user-agent-switcher/

8. CryptoFox
CryptoFox is an encryption or decryption tool for Mozilla Firefox. It supports most of the available encryption algorithm. So, you can easily encrypt or decrypt data with supported encryption algorithm. This add-on comes with dictionary attack support, to crack MD5 cracking passwords. Although, it hasn’t have good reviews, it works satisfactorily.
Add CryptoFox to Firefox:
https://addons.mozilla.org/en-US/firefox/addon/cryptofox/

9. SQL Inject Me
SQL Inject Me is another nice Firefox add-on used to find SQL injection vulnerabilities in web applications. This tool does not exploit the vulnerability but display that it exists. SQL injection is one of the most harmful web application vulnerabilities, it can allow attackers to view, modify, edit, add or delete records in a database.The tool sends escape strings through form fields, and tries to search database error messages. If it finds a database error message, it marks the page as vulnerable. Hackers can use this tool for SQL injection testing.
Add SQL Inject Me to Firefox:
https://addons.mozilla.org/en-us/firefox/addon/sql-inject-me/ 

10.  XSS ME
Cross Site Scripting is the most found web application vulnerability. For detecting XSS vulnerabilities in web applications, this add-on can be a useful tool. XSS-Me is used to find reflected XSS vulnerabilities from a browser. It scans all forms of the page, and then performs an attack on the selected pages with pre-defined XSS payloads. After the scan is complete, it lists all the pages that renders a payload on the page, and may be vulnerable to XSS attack. Now, you can manually test the web page to find whether the vulnerability exists or not.
Add XSS ME to Firefox:
https://addons.mozilla.org/en-us/firefox/addon/xss-me/

11.  Passive Recon
Last but not the least. Passive recon is a good information gathering tool. 
PassiveRecon provides information security professionals with the ability to perform "packetless" discovery of target resources utilizing publicly available information. It gathers information like DnsStuff tool available on backtrack.

Add Passive Recon to Firefox:
https://addons.mozilla.org/en-US/firefox/addon/passiverecon/


That's all for today guys, i hope you all are enjoying your journey towards becoming a Professional Hacker. Have fun! Keep Learning

Read more: http://www.hackingloops.com/2013/08/11-firefox-addons-hacker-must-have-use.html#ixzz2ju5qkN6W

how-to-make-phisher-or-fake-pages

Phishers are fake pages which are intentionally made by hackers to steal the critical information like identity details, usernames, passwords, IP address and other such stuff. As i mentioned intentional, which clearly means its illegal and its a cyber crime. Phishing is basically a social engineering technique to hack username and passwords by deceiving the legitimate users. Phishers are sent normally using spam or forged mails.

Note: This article is for educational purposes only, any misuse is not covered by Hacking loops or CME.

What is Phishing?
Phishing is basically derived from the word called Fishing which is done by making a trap to catch the fishes. Similarly in case of hacking, hackers make Phish pages (traps) to deceive the normal or unaware user to hack his account details. Phishing technique is advancing day by day, its really tough to believe that on what extent this technique is reached but this is always remains far away from normal internet users and most of hackers.
Most of hackers and computer geeks still believe that Phishing attempt can be easily detected by seeing the URL in address bar. Below are some myths that hacking industry still have about Phishing. I will mention only few because then article will become sensitive and major security agencies will flag my website for posting sensitive data. So i will only explain the facts, if you need the same you need to fill the form and give us assurance that you will not misuse it.

Myth's about Phishing among Computer Geeks and Hackers
1. Almost each and every Hacker or computer Geek, thinks that Phishing attempt can be detected by just having a look on the URL. Let me tell you friends it was old days when you recognize Phishers by seeing URL's. But nowadays recent development in Cross site scripting(XSS) and Cross site Script forgery has made it possible that we can embed our scripts in the URL of famous websites, and you must know scripting has no limitations. Below are some examples that you can do from scripting:
a. Embed a Ajax Keylogger into the main URL and user clicks on the URL, keylogger script will get executed and all the keystrokes of the user will get record.
b. Spoof the fake URL: If you are little bit good in scripting and web browser exploits recognition then this can be easily done. What you need to do you need to write a script which will tell web browser to open fake page URL whenever user opens some website like Facebook. Just you need to manipulate the host file and manipulate the IP address of that website from Host file(found in windows folder).
c. Simply retrieving the information saved in the web browser like saved passwords, and bookmarks etc. Just need to write a script which will explore the locations in Windows user profile (where actually the stored information of web browsers saved). 
2. One biggest myth, when you enter the data into the fake page, it will show either some warning message or show login information is incorrect. Rofl, new phishers are bit smart, now they don't show warning messages, when you login through fake page. They will actually login you into your account, and simultaneously at the back end they will steal your information using batch scripts.

So  friends i think this is enough back ground about new phishing technologies. Let's learn how to make a basic Phisher of any website in less than one or two minutes.

Steps to make your own Phisher:
1. Open the website Login or Sign in page whose phisher you want to make. Suppose you pick Gmail.
2. Right click to view the source and simultaneously open notepad.
3. Copy all the contents of the source into the notepad file.
4. Now you need to search for word action in the copied source code. You will find something like below:
How to make Phishers
Manipulate action and method

Now in this line you need to edit two things, first method and then action. Method Post is used for security purposes which encrypts the plain text, so we need to change it to GET.
Action field contains the link to next page, where it should go when you click on login or press enter. You need to change it to something.php (say lokesh.php).
5. Now save the above page.
6. Now open the Notepad again and paste the below code in that:
Make batch script for Phisher
Batch script for Phisher
7. Location contains the next page URL, where you wish to send to user and passwords.html will contains the passwords.
8. Now save this file as lokesh.php as told in step number 4.
9. Now create an empty file and name it as passwords.html, where the password get stored.
10. Upload all the three file to any web server and test it.
Note: In case of facebook, it will show error after user login, for that you need to use tabnabbing trick.
Note: Always keep the extension correct, otherwise it will not work. So always use save as trick rather than save otherwise it will save files as lokesh.php.txt.

Read more: http://www.hackingloops.com/2011/10/how-to-make-phisher-or-fake-pages.html#ixzz2ju47fVUf

That's all from my side today, I hope you all enjoyed this article..
If you have any issues ask me in form of comments..

Hacking hackers phishing pages to view hacked facebook and email accounts

Welcome friends, today i am going to teach you how to see the hackers illegal phish pages password file using Google, which all the passwords of victims are stored. As we all know 99 % hackers over internet are novice hackers or simply script kiddies. They don't know the concepts and they just follow or use the material available on internet to create Phishers to Hack Facebook, Gmail or simply passwords. Which always result in creating Phisher successfully but not a secure one because none tells the after phisher technique like how to make phishers undetectable, how to protect password files where all hacked passwords are stored etc. As most of us know that Phishing is the easiest method over internet to hack Facebook and Email account passwords, so most novice hackers opt this option to hack victims passwords. In fact some professional hackers uses Phishing technique too but they are bit advanced and prefer tabnabbing(click here to learn more) over Phishing. As Hackingloops concentrates on concepts and digging the root causes. We will learn something better that no body does or tells. What loophole we are digging today?? Any idea?? No ?? So go on.

Hacking Hackers online
Hacking Hackers Phish Pages to View Hacked Facebook and Email accounts using Google

Loophole

Most of us who are webmasters i.e. people who design websites knows the concept of Google indexing but others might not have that good idea. So let me explain first. How any website results appears in Google search results? You made the website and how does Google knows you website? All search engines uses spider and crawler software's over the web to index the new websites or latest changes in the existing websites in order to give users the best latest results. And indexing of website depends on a file located at root level of all web hosting websites, if its not present Google treats as full index. Most people think that robots.txt file is used to tell Google to index your website but actually robots.txt file used to tell Google that what you want to index from your website and what you don't want. By default, robot file allow full website indexing i.e. all files are indexed even password and database files. Woooo! Here the loophole lies. Most almost all hackers uses free web hosting websites to run the Phish pages and all free web hosting websites have default robot.txt file which means when hacker uploads its phish pages, its indexed by Google. And we all know what we use to extract smart information from Google? Off course its Google Dorks. Now we have to learn how to make our own dorks to extract hackers phish page information.

Hackers edits Form redirects of any login page and change the request mode from POST to GET in order to retrieve passwords in plain text and then they stores it in simple text and html files. Today we are going to learn how to extract those password files using Google. Well there is not much to learn in it because i have already made the DORK for you, what you have to do is just enter the same in Google and you will have access to all Hackers Phish pages password files containing all the hacked password they hacked till now. 

Learn how to make Phish page online in less than two minutes:

Dork to extract all Hackers Phish Pages Password file :

inurl:"passes" OR inurl:"pass" OR inurl:"passwords" OR inurl:"credentials" -search -download -techsupt -git -games -gz -bypass -exe filetype:txt @yahoo.com OR @gmail OR @hotmail OR @rediff
Just open the Google search and enter the above dork into it, you will get all Phish page password files. 

If you want to learn how to Search Google like Professional Hacker then its a must read:

Hope you all like the noobie way to view all the hacked passwords. There are several other ways to hack the hackers in smart way. We will learn that in future tutorials.

Learn 4 different ways that hacker uses to hack Facebook accounts:

Tuesday, 15 October 2013

Sam Spade: The Swiss Army Knife of network analysis


 For a variety of network analysis and management functions, consider putting Sam Spade to work. As Jason Hiner explains, this free, downloadable utility offers a versatile suite of TCP/IP and internetworking tools

Every administrator’s computer contains a toolbox full of useful utilities for network management. These can include performance and diagnostic counters, network packet analyzers, remote control programs, administration modules for server software, and a variety of other tools. If your organization’s connected to the Internet 24/7, I would recommend that you consider adding Sam Spade to your toolbox. Sam Spade for Windows offers a suite of tools for protecting against spam on mail servers, analyzing and troubleshooting Web servers, and gathering information on Internet hosts.

Many of these utilities were previously available only on UNIX machines. Most are aimed at stopping and tracking down spammers. Nevertheless, you can also use Sam Spade to gather some great general information about your network. This information will help you identify areas where hackers can gather too much information about your hosts, in addition to helping you keep your mail servers protected from spam.

One of my favorite features of Sam Spade is that it’s free. If you’re a Windows user, simply go to their Web site and download the latest version. On the main page, you’ll also find online versions of many of these networking tools. These are helpful when you are away from your main workstation or at a computer connected to the Internet behind a very restrictive firewall. Otherwise, the Windows version of Sam Spade is preferable because of its fast and easy access to a variety of tools and because you can run a number of different inquiries simultaneously.

Configuration
Once you download Sam Spade and install it on your workstation, you’ll want to configure a few settings. First, open Sam Spade and click Edit | Options, as shown in Figure A. In the Basics tab, enter your default DNS server (or use DHCP), your e-mail address, so that you can do SMTP relay checking, and your ISP’s Web server, so that you can use the Awake feature to have Sam Spade send out periodic packets to keep a dial-up connection from being dropped.

Figure A
Basics tab of the Options dialog box


Using the tools
Sam Spade has a nice user interface, as shown in Figure B. It combines many of the traditional TCP/IP tools with some unique tools that give an administrator a great look at a network. Best of all, these tools are combined in one package. You’ll find versions of ping, nslookup, and traceroute. And the Sam Spade versions are intuitive and flexible, especially when compared to the Windows versions of these TCP/IP tools. For example, with the ping feature, you can set the number of echo requests you prefer on the toolbar; then, every time you use ping, it will use that setting. At the command line, you have to use a switch such as “ping -n 2” each time you want to set the echo number.

Figure B
Example of Sam Spade user interface


The traceroute feature is one of my favorites. You can do a fast traceroute or a slow traceroute. The fast traceroute gives you the quick list of hops your packet makes from your machine to a designated host. The slow traceroute is more like the traditional traceroute utility. However, both traceroute options provide a nice graph to accompany the information, as shown in Figure C.

Figure C
Graph using the fast traceroute function


Sam Spade also includes some traditional UNIX tools, such as whois and finger. Whois is actually the default tool. If you simply enter a domain such as techrepublic.com in the Sam Spade toolbar hostname field and press [Enter], Sam Spade will return the whois information on who owns the domain name, as well as other registration information, such as the technical contact for the domain.

In addition to nslookup, Sam Spade offers a more advanced DNS querying tool called dig, which requests all the DNS records for an individual host and/or a domain. An advanced whois tool, called “IP block whois,” tries to find who owns a block of IP addresses.

Spam is its specialty
The core of Sam Spade is in its spam tools:
  • SMTP VRFY: Checks to see whether an e-mail address is a true address or if it is being forwarded.
  • SMTP relay check: Measures the security of a mail server. It attempts to relay mail externally. If it is successful, the mail server is vulnerable to being exploited by spammers looking for a third-party machine to relay their mail.
  • E-mail header analysis: Allows you to paste an e-mail address from your mail client into the Sam Spade toolbar and analyze it with all of the standard tools.
  • Blacklist lookups and Abuse.net query: Both allow you to interact with Web sites (and organizations) that track down and report known spammers.

In addition to these anti-spamming tools, Sam Spade’s help files contain some good tutorials on tracking down spammers. See Spam-tracking 101 through Spam-tracking 104 in the Manuals and Tutorials category of the help files.

Useful Web site tools
The Sam Spade suite also provides some useful Web site tools. The Crawl Web tool, shown in Figure D, allows you to search a Web site based on specific query parameters you set. It also enables you to download all the documents of an entire Web site. The program includes a Web browser that offers a raw source-code view of a Web site rather than a graphical view. The browser doesn’t send any identifying information to the host Web server. In addition, it doesn’t support any plug-ins, scripting languages, or other browser add-ons, and it doesn’t actually render the HTML into a graphical format. As a result, it allows you to see meta fields, hidden form fields, white-on-white text, and other developer tricks for disguising information.

Figure D
Crawl Web tool


Sam Spade also includes some security tools that could send up some red flags if you decide to use them to look at information on other companies, especially large multinational organizations. These tools include a port scanner, a DNS zone transfer tool, and the SMTP relay checker. The port scanner in Sam Spade is fairly basic, as you can see in Figure E, but it’s functional. For a better port scanner, go to the Eeye Web site, which offers a freeware port scanner for Windows NT and a commercial port scanner for serious hacker prevention. If you use the port scanner on another network, be aware that you can set off hacker detection programs.

Figure E
Port scanner


The SMTP relay checker we discussed above can also set off alerts for companies that carefully guard against spamming. In order to use port scanning, SMTP relay checking, and zone transfers, you have to go to Edit | Options and then click on the Advanced tab, shown in Figure F. Here, you can select any of these tools you want to use.

Figure F
Selecting security tools in the Advanced tab


Zone transfers are extremely useful for testing your own domain to make sure hackers can’t gather valuable information about your systems architecture. Once you have enabled zone transfers, go to the fields at the top of the Sam Spade toolbar and enter your fully qualified domain name in the hostname field (on the left side) and enter the IP address of one of your DNS servers in the name server field (on the right side). Then click Tools | Zone Transfer. If you see Query refused, you’re in good shape. However, if you discover that Zone Transfer has provided a list of your DNS entries, your network is vulnerable. You’ll need to disable zone transfers on your DNS servers if you are managing your own name servers, or you’ll need to call your ISP and request that it disable zone transfers if it’s doing DNS for your Internet servers.