english-inmind.com Hacked by aK47 and D4RK CRYST4L

Website english.inmind.com is hacked by Indian Hackers :- aK47 and D4RK

On Page SEO Optimization Techniques for Blogs/Beginners/Blogger

On Page SEO optimization is a technique to bring your site on to the top pages of search engines so If you want to do SEO for blogs then you can't be ignore on page seo optimization.

What is Denial of Service (DoS) Attacks

Denial Of Service (DoS) Attacks :- A denial of service (DoS) attack is an attack that clogs up so much memory on the target system that it can not serve it’s users, or it causes the target system to crash, reboot, or otherwise deny services to legitimate users.

26 Books on Hacking by Ankit Fadia: Free Downloads

Download various books on Hacking by Ankit Fadia for free Collection

Showing posts with label Tools. Show all posts
Showing posts with label Tools. Show all posts

Saturday, September 17

SSHtrix - Fastest Multithreaded SSHv1 and SSH1v2 login cracker




sshtrix is a very fast multithreaded SSH login cracker. It supports SSHv1 and SSHv2.sshtrix was designed to automate rapid bruteforce attacks against SSH authentification screens. Unlike other public tools, the aim is to keep it simple, stable, fast and modular. With its clean code design, it is easy to extend the code to a framework or to fork it against protocols of your choice. In fact, sshtrix is a fork of my own generic login cracker framework.
Download SSHtrix here

Friday, September 16

WAVSEP 1.0.3 – Web Application Vulnerability Scanner Evaluation Project

A vulnerable web application designed to help assessing the features, quality and accuracy of web application vulnerability scanners. This evaluation platform contains a collection of unique vulnerable web pages that can be used to test the various properties of web application scanners. Additional information can be found in the developer's blog.

Project WAVSEP currently includes the following test cases:
Vulnerabilities:


  • Reflected XSS: 66 test cases, implemented in 64 jsp pages (GET & POST)
  • Error Based SQL Injection: 80 test cases, implemented in 76 jsp pages (GET & POST )
  • Blind SQL Injection: 46 test cases, implemented in 44 jsp pages (GET & POST )
  • Time Based SQL Injection: 10 test cases, implemented in 10 jsp pages (GET & POST )

False Positives:

  • 7 different categories of false positive Reflected XSS vulnerabilities (GET & POST )
  • 10 different categories of false positive SQL Injection vulnerabilities (GET & POST)

Additional Features:

  • A simple web interface for accessing the vulnerable pages
  • Sample detection & exploitation payloads for each and every test case
  • Database connection pool support, ensuring the consistency of scanning results
Although some of the test cases are vulnerable to additional exposures, the purpose of each test case is to evaluate the detection accuracy of one type of exposure, and thus, “out of scope” exposures should be ignored when evaluating the accuracy of vulnerability scanners.

Balaji Plus Cloud Antivirus Released - Mix of 32 antivirus Engines for ultra Protection



Leo Impact Launch World first Antivirus scanning software which protects your PC from viruses, trojans, spyware, rootkits and other malicious programs (zero day exploits) by using 32+ antivirus on cloud. Most of time you can install and use only 2 to 3 antivirus in one system, not more so virus author bypass top antivirus but Balajiplus is Free service by Leo impact Security for Corporate Social Responsibility to protect your digital life using multiple antivirus scanners on cloud. Collective Intelligence, Balaji Antivirus Plus proprietary cloud-scanning technology that automatically collects and processes millions of malware samples, lies at the core of Balaji Cloud Antivirus. In recent comparative tests conducted by both AV-Test.org and AV-Comparatives.org, Balaji Antivirus Security's detection and protection scores rank consistently amongst the top security solutions.
Balajiplus Cloud scanner use following Latest 32+ antivirus engine
Ad-Adware
ArcaVir
Avast
AVG Anti-Virus
Avira AntiVir Personal
BitDefender Internet Security
BullGuard
VirusBuster Internet Security
ClamAV
COMODO Internet Security
Dr.Web
CA Internet Security
F-PROT Antivirus
F-Secure Internet Security
G Data InternetSecurity 2011
IKARUS Security Software
Kaspersky Internet Security
McAfee Total Protection
Microsoft Security Essentials
ESET NOD32 Antivirus
Norman Security Suite
Norton Internet Security
Panda Cloud Antivirus
Quick Heal
Rising AntiVirus 2011
SOLO ANTI-VIRUS
Sophos AutoUpdate
Trend Micro Internet Security
VirusBlokAda
Vexira Antivirus Scanner
Webroot Internet Security
Zoner AntiVirus client
Why Balaji plus is unique/Safe?

  • Trusted by Trustwave and verisign
  • Online scanning module so no need to install any program in your system
  • Totally free and Anonymous (your exe and attachments auto deleted and never shared with antivirus companies)
  • Its better than install & use one antivirus instant Muliple 32+ antivirus scanning using our cloud technology.
  • This is ver 1.1 and we will launch ver 2.1 engine soon in next 2 months with patent patending technology so No virus /RAT./ Trojan infection's on your system

Visit us : http://balajiplus.com (3.26 MB Only)

Thursday, September 15

THC-HYDRA v7.0 new version released for Download




THC-HYDRA is a very fast network logon cracker which support many different services. This tool is a proof of concept code, to give researchers and security consultants the possibility to show how easy it would be to gain unauthorized access from remote to a system. It was tested to compile cleanly on Linux, Windows/Cygwin, Solaris, FreeBSD and OSX.

Official change log:

  • New main engine for hydra: better performance, flexibility and stability
  • New option -u – loop around users, not passwords
  • Option -e now also works with -x and -C
  • Added RDP module, domain can be passed as argument
  • Added other_domain option to smb module to test trusted domains
  • Small enhancement for http and http-proxy module for standard ignoring servers
  • Lots of bugfixes, especially with many tasks, multiple targets and restore file
  • Fixes for a few http-form issues
  • Fix smb module NTLM hash use
  • Fixed Firebird module deprecated API call
  • Fixed for dpl4hydra to work on old sed implementations (OS/X …)
  • Fixed makefile to install dpl4hydra (thx @sitecrea)
  • Fixed local buffer overflow in debug output function (required -d to be used)
  • Fixed xhydra running warnings and correct quit action event

Download THC-HYDRA v7.0

Backtrack 5 Wireless Penetration Testing by BOOK Vivek Ramachandran




This book will provide a highly technical and in-depth treatment of Wi-Fi security. The emphasis will be to provide the readers with a deep understanding of the principles behind various attacks and not just a quick how-to guide on publicly available tools. We will start our journey with the very basics by dissecting WLAN packet headers with Wireshark, then graduate to the next level by cracking WEP, WPA/WPA2 and then move on to real life challenges like orchestrating Man-in-the-Middle attacks, creating Wi-Fi Honeypots and compromise networks running WPA-Enterprise mechanisms such as PEAP and EAP-TTLS.

Even though touted as a Beginner's Guide, this book has something for everyone - from the kiddies to the Ninjas. You can purchase the book from:
Global:  http://www.amazon.com/BackTrack-Wireless-Penetration-Testing-Beginners/dp/1849515581/
India: http://www.packtpub.com/backtrack-5-wireless-penetration-testing-beginners-guide/book

Sample Chapter can be downloaded here: 
http://www.packtpub.com/sites/default/files/5580OS-Chapter-6-Attacking-the-Client_0.pdf

Author Bio:
Vivek Ramachandran, the author of the book has been into Wireless security research since 2003. He has spoken at conferences such as Blackhat, Defcon and Toorcon on Wireless Security and is the discoverer of the Caffe Latte attack. He also broke WEP Cloaking, a WEP protection schema in 2007 publically at Defcon. He was one of the programmers of the 802.1x protocol and Port Security in Cisco's 6500 Catalyst series of switches. He was one of the winners of Microsoft Security Shootout contest held in India among a reported 65,000 participants. He is best known in the hacker community as the founder of SecurityTube.net where he routinely posts videos on Wi-Fi Security, Assembly Language, Exploitation Techniques etc. Vivek's work on wireless security has been quoted in BBC online, InfoWorld, MacWorld, The Register, IT World Canada etc. places. This year he is either speaking or training at Blackhat, Defcon, Hacktivity, HITB-ML, Brucon, Derbycon, HashDays, SecurityByte etc.
For those who cannot afford to purchase the book, Vivek's Wireless Megaprimer Video series (12+ hours of HD videos on Wi-Fi Hacking) is the next best thing to it.
You can download the DVD here: http://www.securitytube.net/downloads

Wednesday, September 14

The Security Onion LiveDVD - Download



The Security Onion LiveDVD is a bootable DVD that contains software used for installing, configuring, and testing Intrusion Detection Systems. It is based on Xubuntu 10.04 and contains Snort, Suricata, Sguil, Squert, Xplico, nmap, metasploit, Armitage, scapy, hping, netcat, tcpreplay, and many other security tools.Official change log for Security Onion 20110919:

  • The “IDS Rules” menu now has a new entry called “Add Local Rules” which will open /etc/nsm/rules/local.rules for editing using the “mousepad” GUI editor. You can then add any rules that you want to maintain locally (outside of the downloaded VRT or Emerging Threats rulesets).
  • A new menu called “IDS Config” was added with a new menu entry called “Configure IDS engine(s)”. This will list all of the IDS engines on your system and allow you to choose one to configure. It will then open the proper config file for whatever IDS engine you’re running. After you save and close the config file, it will offer to restart the IDS engine for you.

Hook Analyser Malware Tool Released



Hook analyser is a hook tool which can be potentially helpful in reversing applications and analysing malware. It can hook to an API in a process and search for a pattern in memory or dump the buffer. The tool can hook to an API in a process and can do following tasks.

  • 1. Hook to API in a process
  • 2. Hook to API and search for pattern in memory of a process
  • 3. Hook to API and dump buffer (memory).

Download Here

Sunday, September 11

Rootkit Hunter | Rootkit Scanning tool | Scan Rootkit Now



Rootkit scanner is scanning tool to ensure you for about 99.9%* you're clean of nasty tools. This tool scans for rootkits, backdoors and local exploits by running tests like:
- MD5 hash compare
- Look for default files used by rootkits
- Wrong file permissions for binaries
- Look for suspected strings in LKM and KLD modules
- Look for hidden files
- Optional scan within plaintext and binary files
Download Rootkit Hunter

Saturday, September 10

FBPwn : A Cross-Platform Facebook Profile Dumper tool



FBPwn is an open source, cross-platform, Java based Facebook profile dumper. It can send friend requests to a list of Facebook profiles, and poll for their acceptance notification. Once the victim accepts the invitation, it dumps all their information, photos and friend list to a local folder. It supports a lot of modules that can expand its current functionalities. It has a well documented Wiki page explaining the process of building a FBPwn module. Though it has a lot of available modules prebuilt for your use.
All modules work on a selected profile URL (we’ll call him Bob), using a valid authenticated account (we’ll call him Mallory).
AddVictimFriends: Request to add some or all friends of Bob to increase the chance of Bob accepting any future requests, after he finds that you have common friends.
ProfileCloner: A list of all Bob’s friends is displayed, you choose one of them (we’ll call him Andy). FBPwn will change Mallory’s display picture, and basic info to match Andy’s. This will generate more chance that Bob accepts requests from Mallory as he thinks he is accepting from Andy. Eventually Bob will realize this is not Andy’s account, but probably it would be too late as all his info are already saved for offline checking by Mallory.
CheckFriendRequest: Check if mallory is already friend of Bob, then just end execution. If not, the module tries to add bob as as a friend and poll waiting for him to accept. The module will not stop executing until the friend request is accepted.
DumpFriends: Accessable friends of Bob is saved for offline viewing. The output of the module depends on other modues, if mallory is not a friend of Bob yet, the data might not be accessable and nothing will be dumped.
DumpImages: Accessable images (tagged and albums) are saved for offline viewing. Same limitations of dump friends applies.
DumpInfo: Accessable basic info are saved for offline viewing. Same limitations of dump friends applies.

So you can see, you can do almost everything that you could do manually with Facebook. People might use it for malicious purposes too like cloning a Facebook profile. In addition to reading the Facebook official security guide, you need to avoid friend requests from un-known people.
Download FBpwn

Wireshark 1.4.9 & Wireshark 1.6.2 updated version released




Wireshark is the world’s most popular network protocol analyzer. It is used for troubleshooting, analysis, development, and education.
The following bugs have been fixed:

  • configure ignores (partially) LDFLAGS. (Bug 5607)
  • Build fails when it tries to #include , not present in Solaris 9. (Bug 5608)
  • Unable to configure zero length SNMP Engine ID. (Bug 5731)
  • BACnet who-is request device range values are not decoded correctly in the packet details window. (Bug 5769)
  • H.323 RAS packets missing from packet counts in “Telephony->VoIP Calls” and the “Flow Graph” for the call. (Bug 5848)
  • Wireshark crashes if sercosiii module isn’t installed. (Bug 6006)
  • Editcap could create invalid pcap files when converting from JPEG. (Bug 6010)
  • Timestamp is incorrectly decoded for ICMP Timestamp Response packets from MS Windows. (Bug 6114)
  • Malformed Packet in decode for BGP-AD update. (Bug 6122)
  • Wrong display of CSN_BIT in CSN.1. (Bug 6151)
  • Fix CSN_RECURSIVE_TARRAY last bit error in packet-csn1.c. (Bug 6166)
  • Wireshark cannot display Reachable time & Retrans timer in IPv6 RA messages. (Bug 6168)
  • ReadPropertyMultiple-ACK not correctly dissected. (Bug 6178)
  • GTPv2 dissectors should treat gtpv2_ccrsi as optional. (Bug 6183)
  • BGP : AS_PATH attribute was decode wrong. (Bug 6188)
  • Fixes for SCPS TCP option. (Bug 6194)
  • Offset calculated incorrectly for sFlow extended data. (Bug 6219)
  • [Enter] key behavior varies when manually typing display filters. (Bug 6228)
  • Contents of pcapng EnhancedPacketBlocks with comments aren’t displayed. (Bug 6229)
  • Misdecoding 3G Neighbour Cell Information Element in SI2quater message due to a coding typo. (Bug 6237)
  • Mis-spelled word “unknown” in assorted files. (Bug 6244)
  • tshark run with -Tpdml makes a seg fault. (Bug 6245)
  • btl2cap extended window shows wrong bit. (Bug 6257)
  • NDMP dissector incorrectly represents “ndmp.bytes_left_to_read” as signed. (Bug 6262)
  • TShark/dumpcap skips capture duration flag occasionally. (Bug 6280)
  • File types with no snaplen written out with a zero snaplen in pcap-ng files. (Bug 6289)
  • Wireshark improperly parsing 802.11 Beacon Country Information tag. (Bug 6264)
  • ERF records with extension headers not written out correctly to pcap or pcap-ng files. (Bug 6265)
  • RTPS2: MAX_BITMAP_SIZE is defined incorrectly. (Bug 6276)
  • Copying from RTP stream analysis copies 1st line many times. (Bug 6279)
  • Wrong display of CSN_BIT under CSN_UNION. (Bug 6287)
  • MEGACO context tracking fix – context id reuse. (Bug 6311)

Updated Protocol Support BACapp, Bluetooth L2CAP, CSN.1, DCERPC, GSM A RR, GTPv2, ICMP, ICMPv6, IKE, MEGACO, MSISDN, NDMP, OpenSafety, RTPS2, sFlow, SNMP, TCP


New and Updated Capture File Support
CommView, pcap-ng, JPEG.
Download Wireshark

Google Web History vulnerable to new Firesheep Addon

Two researchers have shown how a modded version of the Firesheep Wi-Fi sniffing tool can be used to access most of a victim’s Google Web History, a record of everything an individual has searched for.

The core weakness discovered by the proof-of-concept attack devised by Vincent Toubiana and Vincent Verdot lies with what is called a Session ID (SID) cookie, used to identify a user to each service they access while logged in to one of Google’s services.Fortunately, the latest exploit does not allow attackers to take over Google Accounts, but obviously, it can be used to expose private data. "While the direct access to users' data is subject to a strict security policy, using personalized services (which may leak this same personal information) is not," wrote Vincent Toubiana and Vincent Verdot, the creators of the modded Firesheep.

To be sure, the compromised cookies are deployed across more than 20 websites including Google Search, Google Maps, YouTube and Blogger. Every time the user accesses an application, the same SID cookie is sent in the clear, which the Firesheep captures from the data sent to and from a PC connected to a non-encrypted public Wi-Fi hotspot.A Google spokesman sent a statement :
We consider the concerns raised by these researchers to be fairly academic in nature and not a significant risk to users. Google Web History and our Web Search suggestion service are served over HTTPS, and we have encrypted the back-end server requests associated with the suggestion service as well. We look forward to providing more support for SSL technologies across our product offerings in the future, including changes that will specifically protect hijacked cookies from being used to access search data.
The researchers said users can protect themselves by logging out of their Google accounts while connecting over networks they don't trust. Another countermeasure is to disable Google's “visited” and “social” search filters.

Friday, September 9

New Twitter Tool Released by Anonymous : U.R.G.E


The Anonymous group of online activists released a new tool today designed to allow people to hijack trending topics on Twitter and tweet messages within them.
Dubbed URGE (for Universal Rapid Gamma Emitter), the beta software is available for download for Windows computers and requires .Net Framework 4 to work.
"This is not a hacking tool nor is it an exploit tool," the group said in a statement. "It was created to make it easier for us to tweet faster without copying and pasting constantly."
Anonymous members say they are annoyed with all the redundant and "pop culture" topics featured on Twitter Trends and want to draw more attention to topics that "actually serve a cause."
"We have taken note of why Twitter would not do so, they only trend topics which would 'appeal' to people and can get people to tweet more," the statement says. "This was pathetic in our eyes, and we could not stand by and take it anymore."
URGE will allow people to spread the message of Anonymous--including "bashing corrupt politicians," among other causes--by riding the coattails of trending topics. "This will help raise awareness of problems going on in this world and show people that real problems exist outside of 'Jersey Shore' and 'Sex,'" according to the statement.
So people interested in singer Jordan Sparks (never heard of her!), National Kiss Day, and the American Jobs Act--which were among the top 10 topics worldwide late today--would conceivably have seen more tweets about the latest San Francisco BART subway protest, civilian unrest in Syria, and President Obama's jobs plan.

You can Download this program HERE (Windows-Beta)
You will need .net framework four to run this program. You can get it: HERE

winAUTOPWN v2.7 – Windows Autohacking Tool




This version covers almost all remote exploits up-till mid-July 2011 and a few older ones as well. This version incorporates a few new commandline parameters: -perlrevshURL (for a PERL Reverse Shell URL), – mailFROM (smtpsender) and -mailTO (smtpreceiver). These are the commandline arguments required for a few exploits which require remote connect-back using a perl shell and email server exploits requiring authentication respectively. This version also tackles various internal bugs and fixes them.A complete list of all Exploits in winAUTOPWN is available in CHANGELOG.TXT
A complete list of User Interface changes is available in UI_CHANGES.txt
Also, in this version :

  • BSDAUTOPWN has been upgraded to version 1.5.
  • In this release you will also find pre-compiled binaries for :
  • FreeBSD x86
  • FreeBSD x64
  • DragonFly BSD x86
Download winAUTOPWN v2.7
Source==> THN

Offline Windows Analysis and Data Extraction (OWADE) - Forensics tool to expose all your online activity





Researchers "Elie Bursztein" from Stanford University in California have managed to bypass the encryption on a PC's hard drive to find out what websites a user has visited and whether they have any data stored in the cloud. "Commercial forensic software concentrates on extracting files from a disc, but that's not super-helpful in understanding online activity," says Elie Bursztein, whose team developed the software. "We've built a tool that can reconstruct where the user has been online, and what identity they used." The open-source software, Offline Windows Analysis and Data Extraction (OWADE), was launched at the Black Hat 2011 security conference and works with PCs running on the Windows operating system.

OWADE is in alpha version and is only available by checking out the code directly as we update it very frequently. Note that the current version has only been tested on ubuntu 10.10 against Windows XP drives. When we reach a stable version we will release a tgz.
Download Offline Windows Analysis and Data Extraction (OWADE)

Wednesday, September 7

How To Unlock Various 3G USB Modems 2011

Use any one of the method to unlock your 3G USB modem,
 Online Huawei Modem Unlock Code Calculator

Step 1: Goto site a-zgsm.com,


Step 2: Enter your modem’s IMEI, enter the CAPTCHA code and click on the “Calculator” button. Within seconds, it will return you with your modems unlock code and flash code.



Step 1: Free Download DC Modem Unlocker Software here.
             Password:  www.wildhacker.com

Step 2: After extraction of file, install the DC Unlocker Software on your computer to see:


Note : If there is a memory card stick on your datacard, please remove it. remove sim card and put sim card preferably from another another carrier that you want to unlock.(it will display invalid sim)

Step 3: Plug your 3G Usb modem stick device in to your computer Usb port or adpater, sometime connection manager will display,close it.

Step 4: Select the manufacture then select the model as Auto detect (recommended). If you know the model and which com port you use.you can do that in same way also.

Step 5: Click the detect Modem button. after your modem model will display below box.

Step 6: When your modem has been detected, then click the Unlock Button at your right hand side top corner.

Thats it........

when you keep another network sim in the Modem , and then insert into computer, the computer will ask for the unlock code so you have to enter the unlock code which you got.
Hence your modem has been unlocked, and now you can use any 3g, 2g sim of any networks.

So friends, I hope this
article will help you to Unlock 3G Modem.
If you have any querries drop the comments below ....

Enjoy !!
Source--> Wild Hacker

Registry Decoder - Digital Forensics Tool




Digital forensics deals with the analysis of artifacts on all types of digital devices. One of the most prevalent analysis techniques performed is that of the registry hives contained in Microsoft Windows operating systems. Registry Decoder was developed with the purpose of providing a single tool for the acquisition, analysis, and reporting of registry contents.
Download Here

Tuesday, September 6

DDOs Tracer - 1.0 Released by MaxPainCode


At most any time of the day, there's a distributed denial-of-service (DDOS) attack underway somewhere on the Internet. Yes, it's still true, despite reports that some ISPs have experienced fewer DDOS attacks overall during the last six months. It's a matter of quality, not quantity: "When DDOSes do occur, they are done with much greater purpose than they used to be," says Rodney Joffe, senior vice president and senior technologist for Neustar, a directory services and clearinghouse provider for Internet industry. "They are usually to obscure what's [really] happening in the background."

So if you want to be safe and trace someone like a pro here is the tool that is being used by tracing the ms per second and then if the site goes down or just get lot of traffic it will report the time that the attacker started his web attack, that is really good as you can report the attack and give to police more information or just use the information for your host or home connection.
Video Demonstration :


Monday, September 5

BackBox Linux 2 Released





The BackBox team is proud to announce the release of BackBox. Linux 2.BackBox 2 features the following upstream components: Ubuntu 11.04, Linux Kernel 2.6.38 and Xfce 4.8. BackBox is an Ubuntu-based distribution developed to perform penetration tests and security assessments. It is designed to be fast and easy to use. It provides a minimal yet complete desktop environment, thanks to its own software repositories, which are always updated to the latest stable versions of the most often used and best-known ethical hacking tools.What's new
System upgrade
Performance boost
New look and feel
Improved start menu
Bug fixing
Hacking tools new or updated
Three new section: Vulnerabilty Assessment, Forensic Analysis and VoIP Analysis
Much, much more!

System requirements
32-bit or 64-bit processor
256 MB of system memory (RAM)
2 GB of disk space for installation
Graphics card capable of 800×600 resolution
DVD-ROM drive or USB port
Download BackBox2

Friday, September 2

SQLi | LFI | XSS | Shell UpLoad : Vulnerable site scanner

This is a great tool i find that scans for SQLi | LFI | XSS | ShEll UpLoad vulnerable websites.I used this software when i went to practice now i don't use it any more.


Then follow the procedure how to scan it .... Pic below



Hope you understand..   any queries Do Comment ;)

Download here - http://www.multiupload.com/87MMECTG0Y

Wednesday, August 31

Qubes OS : Operating System Designed For Security | Be Secure with Qubes OS



Qubes is an open source operating system designed to provide strong security for desktop computing. Qubes is based on Xen, X Window System, and Linux, and can run most Linux applications and utilize most of the Linux drivers. In the future it might also run Windows apps.
Key architecture features:

  • Based on a secure bare-metal hypervisor (Xen)

  • Networking code sand-boxed in an unprivileged VM (using IOMMU/VT-d)

  • No networking code in the privileged domain (dom0)

  • All user applications run in “AppVMs”, lightweight VMs based on Linux

  • Centralized updates of all AppVMs based on the same template

  • Qubes GUI virtualization presents applications like if they were running locally

  • Qubes GUI provides isolation between apps sharing the same desktop

  • Storage drivers and backends sand-boxed in an unprivileged virtual machine(*)

  • Secure system boot based on Intel TXT(*)

 
Source==> THN

Related Posts Plugin for WordPress, Blogger...