Windows Hacking

CH-6 WINDOWS HACKING

Agar aap ek computer user hai to aap sirf control panel ka use kar ke hi computer ki setting badle hoge.par agar aap ek hacker hai to aap control panel ke saath saath registry files ke jariye computer ki setting badalte hoge.Ek hacker control panel ke sivaay rajgistry file ke jariye hi setting badal sakta hai.
Control panel ke jariye aap sirf basic chije jaise ki program install uninstall , network card setting,file wall setting hi kar sakte hai.par ragisty file ke jariye aap cmd ko block karna,control panel ko block karna,koi bhi program me error ka messege dikhana,koi bhi program ko crash karana ,task bar ya start button ki jagah pe aap ka naam insert karna jaise kaam kar sakte hai.ragistry esi files hai jo Microsoft nahi chaahta ki vo aam logo koi ski jaankari ho.ragistry files se aap apne tarike se oprating system chala sakte hai.

Ragistry files ke jariye aap ye saari chije kar sakte hai.
·       Koi bhi drive ko access karne se rock sakte hai
·       CD\DVD drive ko lock kar sakte hai.
·       Control panel block kar sakte hai.
·       Program install hone ki defeault location change kr sakte hai
·       Shutdown disable kar sakte hai.
·       Keyboard or mouse diseble kar sakte hai.
·       start button name or refress name change kar sakte hai.
·       Internet access ,run search ko block kar sakte hai.
·       Program start hone par leagle notice bata sakte hai
·       Paasword policy ko change kar sakte hai.

Ragistry setting on kaise kare.
Is liye sabse pahle Run option me jaye is liye windows+R key press kare.
Fir  Regedit type kijiye. And than ok press kijiye.

On hone ke baad aapko left site pe jo 5 forder dikhai dete hai use hives kahte hai.


Jaise ki HKEY_CLASS_ROOT
HKEY_CURRUNT_USER
HKEY_LOCAL_MACHIN
HKEY_USERS
HKEY_CURRUNT_CONFING
In sab se hi aap ki oprating system control hoti hai.

·       HKEY_CLASS_ROOT -:
Agar aap ko file types,filename ke extensions ko change ya hack karne hai to aap is hives me enter hona padega
·       HKEY_CURRUNT_USER:-
Jo user abhi logged hai uski setting change karni hai to aap ko HKEY_CLASS_ROOT isme enter karna padega.
·       HKEY_LOCAL_MACHIN-:
is me aap ko computer ko saari setting milegi or oprating system ki keyboard ki hardware ki port ki setting milegi jise aap change kar sakte hai.
·       HKEY_USERS
Jistne user ki profile hai unki setting aap ko is hives me milegi.

·       HKEY_CURRUNT_CONFING
HEY_USERS OR HKEY_CURRUNT_CONFING SAME HOGI.
Hives ke andar ke sub forder ko subkeys or unke andar ke forder ko unke sub keys kahte hai.
Hives ka matlab hota hai madhumakkhi ka chhataa.jab aap ye open karege ko aap ko pata lag hi jaayega ki ise hives kyu kahte hai.isme hazaro ke number me setting hote hai.
Registry ko control karne ke liye data value or key hoti hai jise hume right panel me set kar ni hoti hai.ye sab is prakar hoti hai.


·       String value
·       Binary value
·       Dword 32-bit value
·       Qword 64-bit value
·       Multy string value
·       Expandeble string value

1.   REG_SZ(String value)-yaha par number or plane text ki value dali jati hai jisse ragisty ki setting change ho jati hai.
2.   REG_MULTY_SZ(String array value)
Yaha par string arrey value nakhi jati hai par aap ise khud creat nahi kar sakte hai.
3.   REG_EXPAND_SZ(Expandebld String value)
Ye partyculr koi location ke liye value hoti hai.
4.   REG_BINARY(Binary value)-:
Ye binary value 0 or 1 ke form me hoti hai
5.   REG_DWORD(DWORD Values)-:
Ye value number or binary done ke form me hoti hai jaise 564 eise bahut saare number

HOW CAN FIND SETTING IN REGEDIT

Sabse pahle ragisty setting on kariye fir aap ko jobhi setting dhundhni ho uske liye ctrl+F press kijiye fir aap ko setting dhundh ni ho use search bar me type kijiye.

Agar aap ko ragitry setting ki puri jankari nahi hai to aap isme change na kare.issse aap ko computer formet krna pd sakta hai.

Agar aap ye nahi chate to aap ko registry files ka backup lena padega is liye aap ko jis hives ka back up lena hai us hives per right click kijiye or export par click kijiye or fir uska name insert kijiye is tarah aap ki registry setting ka beckup ho jayega.Or fir aap koi se fir se import karna ho to aap ko is par right click karke marge par click karna hoga jisse aap ki registry setting pahle jaisi ho jaayegi.

Agar aap registry me koi path dete hai to aap ko ye left panel ke bottme me dikhai dega.


Agar aap ko koi tutorial me dikhai diye hue path me jana hai aap us path par follow karte hai par aap ko vo value vaha par nahi dikhi deti hai to aap use kais eedit karege.
To aap ko us par right karna hoga fir aap ko new par click karna hoga fir key me click karna hoga uska naam aap ko insert karna hoga

To aap is tarah se new ragistry create kar sakte hai.

Ragistry Files Changing

1.   Remove OpenWith Option from right click
Sabse pahle Regedit Open kare
Fir ye path follow kijiye.

HKEY_CLASS_ROOT/*/Shellex/ContextMenuHandlers/Open With
Fir Us par right click kijiye or Modify Par ok kijiye.
Fir value data me text kea age – laga dijiye.
Jab hum c ya c++ coding karte hai to compiler se jo word compile nahi karana chahte us li aage // ka use hota hai isi tarah isme – ka use hota hai.is se pc ye value ko read nahi karega fir ok dijiye and than restart kijiye.fir aap koi bhi file par right click kijiye to aap ko open with ka option nahi dikhega.


Or fir use pahle jaisa karne ke liye – nikal dijiye to aap fir Open With option dikhai dega

2.   Print Leagal Notice
Aap ko ye path par jana hoga
HKEY_LOCAL_MACHIN/SOFTWARE/MICROSOFT/WINDOWS/CURRUNT VIRSION/POLICIES/SYSTEM

LEGALNOTICECAPTION PAR CLICK KARKE USE PODIFI PAR CLICK KIJIYE.FIR AAP KO USME NAME LIKHNA HOGA JAISE KI ME LIKHTA HU SHAILANDRA RAJPUT
Fir Leagalnoticetext ko modify kariye aap ko jo likhna ho vo likhiye jaise ki mai likhta hu YOUR PC HAS BEEN HACKED BY SHAILANDRA RAJPUT
Fir restart kijiye fir aap ko ek notice dikhai degi jo screenshot me batai gayi hai.


Fir jab aap koi se hatana ho o fir se vahi path me jaker aap ne jo bhi edit kiya hai use hata dijiye fir vo fir se pahle jaisa ho jaayega
3.   Remove control panel,run and find
Is liye is path ko follow kijiye.
HKEY_LOCAL_MACHIN/SOFTWARE/MICROSOFT/WINDOWS/CURRUNT VIRSION/POLICIE/explorer
Vaha par jake explorer par right click kigiye New par click kijiye or fir Dword value par click kijiye fir use naam dijiye
NoControlPanel isme pahle word capitel rakhna hoga.fir use modified kare us liye 0 ke badle 1 likh dijiye fir is tarah NoRun,NoFind subkey banaye or modified karke value 1 set kar dijiye.or restart kar dijiye.


To is tarah aap ko is prakar ki screen dikhi degi.agar aap ko pahle jaisa karna ho to aap ko regedit ke liye findi ki jarurat padegi par aap ko find dikhai nahi dega is liye aap my computer par jaye fir local disk C/windows me to aap ko regedit.exe milega use open kijiye or fir use pahle jaisa kar dijiye.


Aap dekh hi sakte na control panel hai na hi run hai or agar aap windows+R key press karte hai to aap ko ye messege dikhai deta hai.

To is tarah aap bhi registry setting kar sakte hai.

BOOKS FOR REGISTARY SETTING
1. REGISTARY Tips
Click here For Download


HOW CAN DO REGISTRY Setting Using Cmd
Sabse pahle cmd open kijiye.
Fir aapko cmd me C drive me aana hoga isliye cmd me typr kijiye cd/
Fir aap C drive me aa jayege fir aap reg/? type kijiye issse aap ko Regstry ki help windows dikhai degi kis opration ke kis keyword ka use hota hai ye aap dekh sakte hai.


Jise ki agar aap ko koi quary ke baare me pata lagana ho to REG QUERY/? Aise hi keyword aap screen shot medekh sakte hai.
Jaise ki hume Shutdown ka option hatana hai to sabse pahle cmd open kijiye fir c drive me aayiye fir REG ADD ke bad vo path as it is copy kar ke past kijiye jaise ki
“REG ADD HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\policies\explorer /v NoClose /t REG_DWORD /d 1”
Yaha /v value ke liye hai /t data type ke liye hai value ko 0 karna hai ya one karna hai us liye /d ka use hota hai.
Ab agar aap ko ye command hatana hai to 1 ki jagah 0 kijiye.
Ab agar aap ko ye effect lana hai to pc restart karna hoga par aap ek command ka use karke isse bach sakte hai is liye cmd me type kijiye.

Taskkill /f /im explorer.exe fir aap ko type karna hoga explorer.exe is se aapka pc pahle jaisa ho jayega.

GPEDIT
Gpedit windows hacking me sabse easy hai isliye sabse pahle win+R key press kijiye fir gpedit.msc type kijiye.
Aap ke saamne gpedit khul gaya hai
Isme do category hai 1st computer or 2nd user setting
Computer setting me computer ki setting aati hai or user setting me users ki setting aati hai.to user setting me software ki setting windows ki setting administration setting jaisi setting kar sakte hai.
Aap niche ki screenshot mai dekh sakte hai ki konsi setting kar sakte hai.

Yaha hamne admistration setting on kari hai.agar aapko koi setting enble ya diseble karna ho to use aap kar sakte haiu jaise ki agar aap ko koi setting change karni ho to us par dubble click kariye or fir agar diseble karna ho to disable par click karke ok dijiye.or agar aap ko eneble karna ho use par ok dijiye.





Hide Forders
Agar aap ek simple windows user hai to agar aap ko koi file ya forder hide karna ho to aap kya karte hai.
Aap file ya forder par right click karke propatise me jaker hide par click karte hai.or agar aap ko use unhide karna hoto aap tools me jake forder option me jaker unhide par click krate hai.par agar aap ek hacker hai to aap apne file ya forder kaise hide karge aayiye sikhte hai.
US liye aapko forder ka naam or vo kis drive mai hai vo yaad rakhna hoga.
Is liye sabse pahle cmd open kijiye.
Fir aap ki file jis drive me aaye jaise ki meri file d drive me hai to liye cd/ type kijiye. Fir aap ke drive ka naam likhiye jaise ki agar d hai to D: type kijiye.
Fir type kijie Attrib Forder ka naam +h +s
Jaise ki

C:\Users\Rajput Shailandra>cd/
C:\>D:
D:\>Attrib video +h +s
D:\>
Ab agar aap is simple unhide karne ka try karege to aap ko ye nahi dikhai dega.
Ise unhide karne teliye bilkul vaisi hi coding kare par +ki jagah – likhiye.
Jaise ki

C:\Users\Rajput Shailandra>cd/
C:\>D:
D:\>Attrib video -h -s
D:\>
Ab agar aapko aapke victim ka computer mil gaya or aapko uski hide chije dekhni ho to agar vo normel user hai to aapko simple tarike se chije mil jayegi par agar usne dusare tarike se file hide ki hogi to aap kya karege aap ko file ki location to pata hi nahi hogi.isliye do tarike hai
1st WinRAR ka use karke WinRAR ka use karke aapko use simple hi browse karna hai or aapko hide file dikhai degi par agar aap ke victim ke computer me win rar nahi hai to is liye aapko registry setting karni hogi
Is liye registry setting on kiijiye fir ye path follow kijiye.
HKEY_CURRENT_USER\Software\microsoft\windows\current virsion\explorer\advanse

Fir usme superhide file me change karna hoga agar value 0 hai to 1 kar dijiye.or agar 1 hai to 0 kar dijiye fir restat ya uperwali process kariye.aap ki saari file unhide ho gayi hai. 
Previous
Next Post »