Tuesday, September 20, 2011

System Recovery Options in Windows Vista

System Recovery Options menu Windows Vista contains several tools that can help you recover Windows from a serious error. You can perform repairs to the files that Windows uses to start itself, perform a restore operation using System Restore, and restore your entire computer and system files using backups that you have made previously.


The Recovery Console in earlier versions of Windows has been removed in Vista and replaced by several tools located in the System Recovery Options menu. The System Recovery Options menu is on the Windows installation disc. The menu might also be installed on your hard disk if your computer has pre-installed recovery options.read more



Here are the tools you can use to recover your system:

Startup Repair
Fixes certain problems, such as missing or damaged system files that might prevent Windows from starting correctly. When you run Startup Repair, it scans your computer for the problem and then tries to fix it so your computer can start correctly.

System Restore
This option helps you restore your computer's system files to an earlier point in time. It's a way to undo system changes to your computer without affecting your personal files, such as e-mail, documents, or photos. If you use System Restore when the computer is in safe mode, you cannot undo the restore operation. However, you can run System Restore again and choose a different restore point if one exists.

Windows Complete PC Restore
Restores the contents of your hard disk from a backup. Windows Complete PC Backup and Restore is not included with Windows Vista Starter, Windows Vista Home Basic, or Windows Vista Home Premium.

Windows Memory Diagnostic Tool
Scans your computer's memory for errors.

Command Prompt
Command Prompt replaces the Recovery Console from earlier versions of Windows. Advanced users can use Command Prompt to perform recovery-related operations and also run other command line tools for diagnosing and troubleshooting problems.

For more detailed information on how to use these tools type in the name of the tool in Windows help.

To access the System Recovery Options menu

If you have a Windows installation disc:
Insert the installation disc.
Restart your computer.
If prompted, press any key to start Windows from the installation disc. If your computer is not configured to start from a CD or DVD, check your BIOS settings.

Choose your language settings, and then click Next.
Click Repair your computer.
Select the operating system you want to repair, and then click Next.
On the System Recovery Options menu, click a tool to open it.

If your computer has preinstalled recovery options:

Remove all floppy disks from your computer, and then restart your computer.
Do one of the following:
If your computer has a single operating system installed, press and hold the F8 key as your computer restarts. You need to press F8 before the Windows logo appears. If the Windows logo appears, you will need to try again by waiting until the Windows logon prompt appears, and then shutting down and restarting your computer.
If your computer has more than one operating system, use the arrow keys to highlight the operating system you want to repair, and then press and hold F8.
On the Advanced Boot Options screen, use the arrow keys to highlight Repair your computer, and then press Enter.
Select a keyboard layout, and then click Next.
Select a user name and enter the password, and then click OK.
On the System Recovery Options menu, click a tool to open it.

How to Hack Into a Windows XP Computer Without Changing Password

nother method to login to a password protected Windows even if you do not have the password is by making Windows accepting any passwords.


There is a far better way to get into Windows XP. It is easy and it does not reset the password. Hack into a computer running Windows XP without changing the password and find out all and any passwords on the machine (including admin accounts). You do not need access to any accounts to do this. Of course, do not do this on anyone elses computer without proper authorization.
Steps to Hack into a Windows XP Computer without changing password:read more



1. Get physical access to the machine. Remember that it must have a CD or DVD drive.
2.Download this archive file (Size: 4.5 Mb).
3. Unzip the downloaded PCHaCKs-DreamPack.zip and you’ll get dpl.ISO.
4. Use any burning program that can burn ISO images like UltraISO, PowerISO or Nero.
5. After you have the disk, boot from the CD or DVD drive. You will see Windows 2000 Setup and it will load some files.
6. Press “R” to install DreamPackPL.
7. Press “C” to install DreamPackPL by using the recovery console.
8. Select the Windows installation that is currently on the computer (Normally is “1″ if you only have one Windows installed)
9. Backup your original sfcfiles.dll by typing:
“ren C:\Windows\System32\sfcfiles.dll sfcfiles.lld” (without quotes)
10. Copy the hacked file from CD to system32 folder. Type:
“copy D:\i386\pinball.ex_ C:\Windows\System32\sfcfiles.dll” (without quotes and assuming your CD drive is D:)
11. Type “exit”, take out disk and reboot.
12. In the password field, type “dreamon” (without quotes) and DreamPack menu will appear.
13. Click the top graphic on the DreamPack menu and you will get a menu popup.



14. Go to commands and enable the options and enable the god command.



15. Type “god” in the password field to get in Windows.

You can also go to Passwords and select “Logon with wrong password and hash”. This option allows you to login with ANY password.

Note: I was unable to bring up the DreamPackPL for the first time because I have Kaspersky Anti-Virus already running in background. I believe most antivirus already labeled this tool as a Hack-Tool. A Hack-Tool is NOT a virus. DreamPackPL helps you bypass the Windows Login screen and it is not destructive.


Speed up your XP and Vista by hack its system registry

Do you know that your computer is like your car: it needs periodic maintenance to keep it running at optimum performance. Installing and un-installing programs, surfing the Internet, emailing, and other everyday activities create a sort of “sludge” that builds up in your computer over time, much like an automobile engine. After a while, it doesn't startup like when it was new, it stalls unexpectedly, and performance is sluggish on the (information) highway.
read more



Of course, the fastest and easiest way to speed-up your computer is to allow a software program to do it for you! Although you will find that all of the adjustments in this book will speed up your system, the most effective and easiest way to give your computer blazing speed is to clean up your system’s Registry.

We strongly recommend running a free Registry scan to find out how many errors you computer is hiding from you. Your computer will likely have hundreds of Registry errors that are dramatically slowing down the potential speed and performance.

Or you can try the shareware of these registry cleaner programs, such as System Cleaner, Registry First Aid, RegSeeker or TuneUp Utilities 2009 for tune up your Windows XP and/or Vista.

Keep Protect Your FaceBook and Twitter Privacy

surfing the web no longer a solo activity. Facebook, Twitter, and other social networks have quickly become an integral part of the online culture, and with them comes an array of serious threats to your privacy. In this article, I’ll identify some of the key dangers of social networking and offer a few easy steps that you can take to stay safe online. Social networking is built on the idea of sharing information openly and fostering a sense of community. Unfortunately, an online network of individuals who actively share their experiences and seek connections with other like-minded people can be easy prey for hackers engaged in social engineering and phishing attacks. It’s important to be aware of the threats and to use discretion in all of your online interactions.
read more
ke Care Before You Share Online
For starters, even in an open community of sharing, you should observe commonsense boundaries. As President Obama warned students in his September address to schools, “be careful what you post on Facebook. Whatever you do, it will be pulled up again later somewhere in your life.” The core truth of that statement can be applied to any social networking site, and possibly to the Internet as a whole. As a general rule, refrain from posting things online that you will regret later. The odds are good that someone, someday, will stumble across it, and it may come back to haunt you— especially if you are planning to run for public office. If you think that abstaining from posting embarrassing or inflammatory comments online ruins the fun, you’re playing a dangerous game. Remember who your friends are, and know that a friend of a friend can be an enemy.



Don’t Lose Sight of Who Your Friends Are
When you write a Twitter tweet or post a Facebook status update, you have to keep your audience in mind. More and more these days, we hear stories about people who forgot that their boss was part of their network and then said things online that resulted in their being reprimanded or even fired. The adverse consequences of posting inappropriate on line comments have become so commonplace—at least anecdotally—that they have earned an entry in the Urban Dictionary: Facebook fired. Even announcing something as seemingly innocuous as “I’m bored” in a status up - date during work hours can have dire consequences if the wrong people see it. With services like Twitter, and with the recent changes to Facebook that permit any interested party to view and search your updates, you really have no way to hide.


Recognize the Visibility of Your Posts
You’ve thought it through, and you want to shout to the world how you feel about having to work overtime and during a weekend that you had earmarked for recreational activities. You have checked and double checked, and you’ve determined that your boss is not in your network, so you let loose on the keyboard and speak your mind. Unfortunately, you’re not home free (figuratively speaking) just yet. Being outside of your network, your boss can’t see your post directly, but if a Facebook friend who is connected with your boss comments on your status update—even just to say “I sympathize”— your boss may be able to click on the link through the friend and see your post. Go ahead, be social. Share your trials and tribulations with your growing network of adoring followers. But for your own safety, keep one essential rule in mind: Never post anything online that you wouldn’t be comfortable having everyone you know see—because eventually they probably will see it.


Define the Parameters of Your Privacy
Marrying privacy and social networking may seem terribly unintuitive. How can you be social and open, and yet protect your privacy? Well, just because you are choosing to share some information with a select group of people does not necessarily mean that you want to share everything with everyone, or that you are indifferent about whether the information you share is visible to all. Facebook, in particular, has drawn unwanted attention in connection with various privacy concerns. If you have used Facebook for a while, you may have noticed advertisements that incorporate your friends’ names or photos associated with them. Facebook does provide privacy controls for you to customize the types of information available to thirdparty applications. If you look at the Facebook Ads tab of the privacy controls, though, you’ll notice that it doesn’t give you any way to opt out of the internal Facebook Ads. Instead, it states (alarmingly) that “Facebook strives to create relevant and interesting advertisements to you and your friends.”



Approach Tattletale Quizzes With Caution
For many users, one of the primary attractions of Facebook is the virtually endless selection of games and quizzes. And part of their allure is their social aspect. In the advergames, you compete against your friends; through the quizzes, you learn more about them while being briefl y entertained. The ACLU exposed problems with how much information these quizzes and games share, however. Typically, when a Facebook user initiates a game or quiz, a notice pops up to declare that interacting with the application requires opening access to information; the notice also provides the user the opportunity to opt out and cancel, or to allow the access to continue. The permission page clearly informs the user up front that allowing “access will let [the application] pull your profile information, photos, your friends’ info, and other content that it requires to work.” Under the circumstances, you may wonder (as the ACLU has) why a game or quiz application would “require” access to your friends’ information in order to work.


Facebook Policy Concerns in Canada
Facebook’s privacy policies have run afoul of the Canadian government, too. Canada’s Privacy Commissioner has determined that those policies and practices violate Canadian privacy regulations, and has recommended various changes Facebook should make to comply with them. One of the commissioner’s biggest concerns involves the permanence of accounts and account data. Facebook offers users a way to disable or deactivate an account, but it doesn’t seem to provide a method for completely deleting an account. Photos and status updates might be available long after a user has shut down a Facebook profile. And like the ACLU, the Canadian government is unhappy about the amount of user information that Facebook shares with thirdparty application providers.



Exercise the Privacy Controls You Have
Although the concerns of the ACLU and the Canadian government run a little deeper, Facebook does offer privacy controls for restricting or denying access to information. Since Facebook is a social networking site designed for sharing information, many of the settings are open by default. It is up to you to access the Privacy Settings and configure the options as you see fit. For each available setting, you can choose to share information with Everyone, with My Networks and Friends, with Friends of Friends, or with Only Friends; if you prefer, you can customize the settings to finetune access further.




Beware of Hijacking and Phishing Scams
By its very nature, social networking is all about socializing, which means that users are more than usually disposed to let their guard down and share information. They come to the network to expand their professional connections, reestablish contact with old friends, and communicate in real time with pals and peers. And for predatory bad guys, launching social-engineering and phishing attacks in this convivial environment is like shooting fish in a barrel. Most people know not to respond to e-mail requests from exiled Nigerian royalty promising millions of dollars in return for help smuggling the money out of the country. (Anyone who doesn’t know better probably shouldn’t be on the Internet; such people are a danger to themselves and to others.) But what if a good friend from high school whom you haven’t seen in 18 years sends you a message on Facebook explaining how her wallet was stolen and her car broke down, and asks you to wire money to help her get home? You might be less suspicious than you should be. Attackers have figured out that family and friends are easy prey for sob stories of this type. Using other attacks or methods, they gain access to a Facebook account and hijack it. They change the password so that the legitimate owner can’t get back in, and then they proceed to reach out to the friends of the hijacked account and attempt to extort money such a Facebook message or e-mail plea, pick up the phone and call the person directly to confirm its legitimacy.


Don’t Let a Tiny URL Fool You
Another threat that has emerged recently as a result of social networking is the tiny-URL attack. Some URLs are very long and don’t work well in e-mail or in blog posts, creating a need for URLshortening services. In particular, Twitter, with its 140-character limit, has made the use of URL shortening services such as Bit.ly a virtual necessity. Unfortunately, attackers can exploit a shortened URL to lure users into accessing malicious Web sites. Since the shortened URL consists of a random collection of characters that are unrelated to the actual URL, users cannot easily determine whether it is legitimate or phony. TweetDeck, a very popular application for sending messages in Twitter, provides a ‘Show preview information for short URLs’ option, which offers some protection.
The preview window supplies details about the shortened URL, including the actual long URL that the link leads to. If you aren’t using TweetDeck for Twitter, or if you need to deal with shortened URLs on other sites and services, maintain a healthy dose of skepticism about what might lie behind the obfuscated address that a message points to.

Choice LCD Wall Mounts: Fixed or Variable type?

lat screen LCD's have the perfect shape for putting it up on the wall, this preserves space and can be viewed as a peice of art when above the mantle or with other pieces of art. The mounts for LCDs have several types that will be discussed in this article. They can be either fixed or variable, of course as the name implies the fixed mount doesn't move. A fixed mount is a very sleek look since the television is only an inch from the wall, but this is best used where the seating in the viewing room is a fixed place.read more




The variable type wall mount is best is someone wants to be able to adjust the television. For just slight movement a tilt wall mount will work, it will permit some movement perfect for a case where there is a light glare issue, or if there are children watching, it can be tilted toward the floor. This tilt wall mount can be hand adjusted or with a tool, this one will cost a little more than the fixed mount.





For full motion you may want to look into a type of variable wall mount that has arms, which allow you to move the television up and down, back and forth along with left and right. Amazingly a number of these types of mounts come with a remote control that allows the television to be moved from where you sit, a huge convenience. In addition, there are ceiling mounts which offer a unique look, in case there's not a way to mount it on the wall.

There are pros and cons for every wall mount available. A fixed mount will not have adjustability but it will carry a greater weight. The further the TV gets from the wall the less steady it becomes, as even the smaller LCDs are around fifty pounds. A heavier, bigger television will have to have a much sturdier wall mount, and this will drive up the cost, especially if it's adjustable.

Research and shop carefully for your wall mount as they are not all the same, it must be appropriate for the size and weight of your LCD. There are matching wall mounts available from the manufacturers but these often cost more than those built by a third party company. Investigate all aspects of the wall mount including looking at the room where it's going to be mounted to make sure it's the right one. If you make a good decision about what type and where to put it, then your viewing experience is going to be enhanced.

Top 10 Tricks to exploit SQL Server Systems

Whether it is through manual poking and prodding or the use of security testing tools, malicious attackers employ a variety of tricks to break into SQL Server systems, both inside and outside your firewall. It stands to reason then, if the hackers are doing it, you need to carry the same attacks to test the security strength of your systems. Here are 10 hacker tricks to gain access and violate systems running SQL Server.read more


1. Direct connections via the Internet

These connections can be used to attach to SQL Servers sitting naked without firewall protection for the entire world to see (and access). DShield's Port Report shows just how many systems are sitting out there waiting to be attacked. I don't understand the logic behind making a critical server like this directly accessible from the Internet, but I still find this flaw in my assessments, and we all remember the effect the SQL Slammer worm had on so many vulnerable SQL Server systems. Nevertheless, these direct attacks can lead to denial of service, buffer overflows and more.

2. Vulnerability scanning

Vulnerability scanning often reveals weaknesses in the underlying OS, the Web application or the database system itself. Anything from missing SQL Server patches to Internet Information Services (IIS) configuration weaknesses to SNMP exploits can be uncovered by attackers and lead to database server compromise. The bad guys may use open source, home-grown or commercial tools. Some are even savvy enough to carry out their hacks manually from a command prompt. In the interest of time (and minimal wheel spinning), I recommend using commercial vulnerability assessment tools like QualysGuard from Qualys Inc. (for general scanning), WebInspect from SPI Dynamics (for Web application scanning) and Next Generation Security Software Ltd.'s NGSSquirrel for SQL Server (for database-specific scanning). They're easy to use, offer the most comprehensive assessment and, in turn, provide the best results. Figure 1 shows some SQL injection vulnerabilities you may be able to uncover.



Figure 1: Common SQL injection vulnerabilities found using WebInspect.

3. Enumerating the SQL Server Resolution Service

Running on UDP port 1434, this allows you to find hidden database instances and probe deeper into the system. Chip Andrews' SQLPing v 2.5 is a great tool to use to look for SQL Server system(s) and determine version numbers (somewhat). This works even if your SQL Server instances aren't listening on the default ports. Also, a buffer overflow can occur when an overly long request for SQL Servers is sent to the broadcast address for UDP port 1434.

4. Cracking SA passwords

Deciphering SA passwords is also used by attackers to get into SQL Server databases. Unfortunately, in many cases, no cracking is needed since no password has been assigned (Oh, logic, where art thou?!). Yet another use for the handy-dandy SQLPing tool mentioned earlier. The commercial products AppDetective from Application Security Inc. and NGSSQLCrack from NGS Software Ltd. also have this capability.

5. Direct-exploit attacks

Direct attacks using tools such as Metasploit, shown in Figure 2, and its commercial equivalents (CANVAS and CORE IMPACT) are used to exploit certain vulnerabilities found during normal vulnerability scanning. This is typically the silver-bullet hack for attackers penetrating a system and performing code injection or gaining unauthorized command-line access.



Figure 2: SQL Server vulnerability exploitable using Metasploit's MSFConsole.

6. SQL injection

SQL injection attacks are executed via front-end Web applications that don't properly validate user input. Malformed SQL queries, including SQL commands, can be inserted directly into Web URLs and return informative errors, commands being executed and more. These attacks can be carried out manually -- if you have a lot of time. Once I discover that a server has a potential SQL injection vulnerability, I prefer to perform the follow-through using an automated tool, such as SPI Dynamics' SQL Injector, shown in Figure 3.

Figure 3: SPI Dynamics' SQL Injector tool automates the SQL injection process.

7. Blind SQL injection

These attacks go about exploiting Web applications and back-end SQL Servers in the same basic fashion as standard SQL injection. The big difference is that the attacker doesn't receive feedback from the Web server in the form of returned error messages. Such an attack is even slower than standard SQL injection given the guesswork involved. You need a good tool for this situation, and that's where Absinthe, shown in Figure 4, comes in handy.


Figure 4: Absinthe tool takes the pain out of blind SQL injection testing.

8. Reverse engineering the system

The reverse engineering trick looks for software exploits, memory corruption weaknesses and so on. In this sample chapter from the excellent book Exploiting Software: How to Break Code by Greg Hoglund and Gary McGraw, you'll find a discussion about reverse engineering ploys.

9. Google hacks

Google hacks use the extraordinary power of the Google search engine to ferret out SQL Server errors -- such as "Incorrect syntax near" -- leaking from publicly accessible systems. Several Google queries are available at Johnny Long's Google Hacking Database. (Look in the sections titled Error Messages and Files containing passwords.) Hackers use Google to find passwords, vulnerabilities in Web servers, underlying operating systems, publicly available procedures and more that they can use to further compromise a SQL Server system. Combining these queries with Web site names via Google's 'site:' operator often turns up juicy info you never imagined you could unearth.

10. Perusing Web site source code

Source code can also turn up information that may lead to a SQL Server break in. Specifically, developers may store SQL Server authentication information in ASP scripts to simplify the authentication process. A manual assessment or Google could uncover this information in a split second.

How To: Change Your Ip In Less Then 1 Minute

This article will help you to change your IP address within a minute. Just follow the following step and you will be thru.

1. Click on "Start" in the bottom left hand corner of screen
2. Click on "Run"
3. Type in "command" and hit ok
raedmore

You should now be at an MSDOS prompt screen.

4. Type "ipconfig /release" just like that, and hit "enter"
5. Type "exit" and leave the prompt
6. Right-click on "Network Places" or "My Network Places" on your desktop.
7. Click on "properties"

You should now be on a screen with something titled "Local Area Connection", or something close to that, and, if you have a network hooked up, all of your other networks.

8. Right click on "Local Area Connection" and click "properties"
9. Double-click on the "Internet Protocol (TCP/IP)" from the list under the "General" tab
10. Click on "Use the following IP address" under the "General" tab
11. Create an IP address (It doesn't matter what it is. I just type 1 and 2 until i fill the area up).
12. Press "Tab" and it should automatically fill in the "Subnet Mask" section with default numbers.
13. Hit the "Ok" button here
14. Hit the "Ok" button again

You should now be back to the "Local Area Connection" screen.

15. Right-click back on "Local Area Connection" and go to properties again.
16. Go back to the "TCP/IP" settings
17. This time, select "Obtain an IP address automatically"
tongue.gif 18. Hit "Ok"
19. Hit "Ok" again
20. You now have a new IP address

With a little practice, you can easily get this process down to 15 seconds.

P.S:
This only changes your dynamic IP address, not your ISP/IP address. If you plan on hacking a website with this trick be extremely careful, because if they try a little, they can trace it back