Make Them Cry
Make Them Cry
The key to success is having a unique and sexy arrangement to post the information.
Here's a sample template that I just created:
~ DOX dropped by (Your username or way of contact, e.g. Skype or XXMP)
===============================================================
Target: (Name) / (IP) / (Alias)
===============================================================
Usernames:
*
*
===============================================================
Locations:
*
*
===============================================================
IP info:
*
*
===============================================================
Family:
*
*
===============================================================
Other information:
*
*
===============================================================
Along with the template you can decorate it with this text to art Website:
http://1lineart.kulaone.com/#/
PayPal Method
This used to give you tons of information like their address, phone number and such
but
now it only gives you the Name, the only way you'll get the address and stuff is if
they send you
money. The method is quite simple all you need to do is request or send money to
the email you
have. Once you do that there should be a notification in your Activity and it
should say their
name. Remember sometimes people put fake leads so don't always go for it.
Using their IP
Using the target's IP address is a very powerful way to dox, if you're quite
advanced an IP
is all you need to leak the user’s information.
Geolocating the IP
Basically head over to the website http://www.infosniper.net/ and input the IP
address
then click search. After doing that you should be granted a rough location on the
user, along with
their hostname, and other information. Remember that this information is pretty
inaccurate and
you should not think that it is their exact location.
ISP Doxing
Before doing this make sure you know what you are doing, never call from your home
or
mobile phone! Always use spoofed numbers!
ISP doxing is basically when you call up the users ISP (Internet Service Provider)
and SE
(Social Engineer) the support into giving you information on the IP address. You
can get basic
information such as full names, addresses, phone numbers, emails or you can go
further and get
SSN's and Credit cards. I will not be providing a guide on how to do this, there
are a ton out
there just search for some.
Searching the IP
In addition you may also search the IP address, as you can sometimes find another
Dox, a
leaked database or sometimes sites publicly post their IP ban list. Just go to
google and search for
their IP address with quotation marks. Ex: “127.0.0.1”
Using Databases
Database, a file or list of information something analyzes and gathers on users. In
short
words a database is more or less a text file in which information of users is
stored, like
passwords, emails, usernames, IPs, and much more. Liking this so far? Well,
unfortunately
databases are rather hard to find or easy but you need to pay a crazy sum of money,
at least the
more useful ones. But this does not mean that there aren’t any good ones for free,
no there are
plenty such as the MPGH forums database and 000webhost which have been leaked on
many
sites. So you don’t want to pay $100 for a database right? No problem, there are a
ton of
websites that have gathered hundreds of databases in which you can use for just $2
BTC a day.
One of those websites is known as http://leakedsource.com/, and just input one of
the following
registries: Usernames, emails, phone numbers, names, and IP addresses. In result
you will get a
password (Hashed or real), email, username, and more.
Here are a couple free databases and sites to get dbs from:
MPGH Database: http://www.filedropper.com/mpgh
Nulled.io Database: http://www.filedropper.com/nullediodatabasedump06052016
000webhost Database: http://www.filedropper.com/000webhostcom_1
http://siph0n.net/
https://leakforums.net/
https://citadel.sx/
Social Engineering the User
The amount of times I’ve done these techniques and succeeded. Many times when I end
up with a blank page I go to a last resort, faking a Skype account and messaging
the user and
SE’ing them to give me information. Here is a quick guide on how I SE through
Skype.
Let’s get a setting first, for example I will be faking a PayPal Support member.
Me: “Would like to add you as a contact…blah blah blah”
Target: “Accepts.”, “Hello who is this?”
Me: “Hello, this is Dan with the PayPal support team, we are currently having an
attack and
encourage all users to change their passwords. Unfortunately you may not manually
reset them,
we have to reset them for you because they will potentially get logged by the
attackers.”
Target: “How did you find my Skype?”
Me: “We are PayPal, a large organisation that surveys many users and connect much
of their
information, but in the act that this is the improper account I ask of your email
to confirm your
identity.”
Target: “Ok, it’s ……………@domain.com
Me: “Aaaaah, yes I found you. May I just ask for another method of access such as a
card linked,
phone number, address, or current password?”
Target: “Yeah, my password is *********.”
Me: “Alright let me just check here, yep everything looks fine. Now what do you
wish your new
password to be?”
Target: “I guess change it to **********.”
Me: “Very fell, the process will take up to 1 hour, please do not login to PayPal
until we send out
emails stating that you can. Thank you for your time and patience, Goodbye.”
Target: “Cya m9.”
And it can be done like this, or so this is how I usually do it. Although very
skeptical
people will usually either decline and block you, or just be notorious trolls. If
they get quite
curious though and say the PayPal site looks fine you can just say, “Our site is
currently being
controlled by hackers and they currently have stolen up to $1 million dollars. We
are currently
moving and changing our database and we need you to choose a new password.” Or
something
along those lines. Customize this however you want and have fun.
Picture to Account
Basically when someone posts a picture it sometimes can be taken from a photo
hosting
website, you can right click it and click it and open in a new tab and sometimes it
will lead to
imgur or something.
Or if you have a picture of the user in real life you could reverse the image to
find if there
is another profile that it is linked with. You can do this with the website known
as
https://www.tineye.com/
Pizza Bombing:
Basically, when you order many pizza’s to the address of the user, unfortunately
I’m not quite sure if this works anymore but I’ll implement it anyways. Simply head
over to
https://www.dominos.com/en/ and order whatever you want to the person’s house. If
you
intentionally order a large meal you will be prompted to confirm the order via a
call to a phone.
Don’t worry, I will teach you how to make a free number in the anonymity section.
Swatting:
Now claimed as an illegal act, swatting is when you ring up the police and claim
your
target has a bomb or is doing something worthy of a Swat team arriving and raiding
the home. I
do not condone anyone to swat.
Craigslist:
A godly website, known as craigslist is the horror point of doxing. One of my
favorite
things is faking a large party at the place. All you have to do is create a thread
on it exclaiming
that there will be free food, DJ, booze and many chicks and you will have a total
sausage fest. In
the thread include the address, your email just in case people have questions and
the date it is
occurring. (Best days of the week would have to be Friday – Sunday and the time
could be from
8:00pm till 12:00am.
DDoS:
Although this is quite pointless unless you have like a huge net and can boot for
days on
days.
Legal action:
If the user has done something illegal the best option is to inform the police, and
give them all the info you have (apart from the illegal stuff you gained, if you
did).
Anonymity Introduction (BONUS)
What is the point of performing and posting a Dox or simply searching the internet
if you
can’t cover up your tracks? Welcome to anonymity section, I will guide you on how
to conceal
the light and live in only the darkness. As dark as it sounds it’s actually
pleasant. Now, let us
begin!
Using an RDP
An RDP is the acronym for Remote Desktop Protocol, basically a Windows desktop that
you can connect through remotely. This can give you a large benefit when for
example you are
playing a game and want to Skype someone for contact but want to hide your IP. You
don’t want
to use a VPN as that will give you a slower connection in the game so your next
best option is an
RDP. There are plenty of them which you can buy or even get for free in the
Marketplace on HF.
Using a VPS
A VPS is basically the Linux based RDP. I honestly think that VPS’ are better
because
they have far more features. Like for instance setting up a private SOCKS5 proxy on
your VPS.
Here’s a tutorial on how to do that on CentOS 5, every line is a command:
yum update
yum upgrade
yum install make automake gcc gccc++ gccg77 nano wget
wget http://downloads.sourceforge.net/project/kingate/kingate/2.1/kingate2.1.tar.gz
tar xvf kingate2.1.tar.gz
cd kingate2.1
sh ./configure prefix=/usr/local/kingate
make
make install
nano /usr/local/kingate/etc/kingate.conf (find socks off and change it to on, find
socks_port
and change it to whatever you like or leave it default, then save by CTRL X)
wget http://soft.vpser.net/proxy/kingate/kingate.init.d
mv kingate.init.d /etc/init.d/kingate
chmod +x /etc/init.d/kingate
service iptables save
service iptables stop
chkconfig iptables off
Then to start it type in:
/etc/init.d/kingate start
The proxy IP will be your main VPS IP, and port is whatever you set it to.
Using Proxies
Basically just like Tor except you don’t need to install anything. All you have to
do is go
scraping for some good proxies, although most people in my opinion don’t use
proxies for a soul
purpose of staying anonymous over Google Chrome but rather while cracking. Anyways
it’s
quite simple, all you have to do is do some searches on “proxies” and you will be
bombed with
pages full of live proxies. Or if you’re quite the lazy gentleman you could pay $1-
$4 for a proxy
scraper from HF, which supplies you with Lifetime proxies, around 35k per day.
Report Abuse
As much of a meme it sounds it actually works on Pastebin. Basically, click the
“report
abuse” button and create a Pastebin account and file a complaint against it too and
it should
disappear in around 35 business days.
Removing Cache
This will delete all the information from deleted/removed pastes. To define that
basically
when you report a post it gets junked, although removed from Pastebin it is still
available when
people search for your dox on Google and such. All you have to do to remove the
information is
head over to this website: https://www.google.com/webmasters/tools/removals?pli=1
Now enter in the URL of the dox and then it’ll say some other stuff. Make sure the
page
has been removed, you will get denied if the page is a live page, like someone made
their own
website and posted the dox on there, it won’t work until the owner of the website
deletes the
content.
Using XXMP
Using XXMP over Skype is needed if you’re wanting to be anonymous. It offers
encrypted chats and connections so you are anonymous when chatting with people.
Using BTC
Another thing you want to add to your list is using BTC instead of PayPal and such.
My
pros are that it offers securable banking and money usage, it is very unlikely
someone will hack
into your account. Another point to add is that it doesn’t reveal info when you
send money,
unlike PayPal that hands your Address, Phone number, email and all that to someone
BTC does
not collect that info and sending money is secure. Also there are no worries about
someone
charging back because you can’t.
Deleting Accounts
A huge part of the information in doxes are gathered from Social Media that have
much
leaked info on them. Here I will show you how to delete your accounts.
Email:
Gmail: https://www.google.com/accounts/DeleteAccount
Yahoo: https://edit.yahoo.com/config/delete_user
Microsoft Emails: https://accounts.live.com/CloseAccount.aspx
Skype: Although you can’t actually delete your Skype account but you can remove it
from the
user search. All you have to do is contact Skype Support and tell them you would
like to delete
your account and they’ll do the rest for you.
Outro
Again I would like to thank you for reading Savage Doxing and I would love
feedback. If you have any questions feel free to private message me and I hope for
the best in
your further Private Investigations.
Another Bonus I thought I’d add: (LOOK BELOW)