| 0 comments ]

\---------------===IP TOOLS===---------------/

DL LINK:
http://rapidshare.com/files/290282402/ip-tools.exe


Operations:
---==LOCAL INFO---==
---==CONNECTION INFO---==
---==NET BIOS---==
---==NB SCANNER---==
---==SNMP SCANNER---==
---==NAME SCANNER---==
---==PORT SCANNER---==
---==UDP SCANNER---==
---==PING SCANNER---==
---==TRACE---==
---==WHOIS---==
---==FINGER USER ---==
---==NS LOOKUP---==
---==GET TIME---==
---==TELNET---==
---==HTTP---==
---==IP MONITOR---==
---==HOST MONITOR---==
---==TRAP WATCHER---==
Image:

Virus Scan:
http://scanner.novirusthanks.org/index.php?session=881531285031584770382055933321645007363201773


falsepositive......

| 0 comments ]

So... let's say that you donwloaded NMAP in one of its latest versions, if you didn't then go get it immediately! And come back only when you have it.

Code:
http://nmap.org/download.html
When you start/launch/whatever you call itNMAP you should see a screen like this one here:

You will quickly get used to this Interface, its really user friendly:

(1) IMPORTANT: This is the most important part of the interface, here youwill type the IP of the target, or a Web Page Adress, for you geeks out there it works both on IPv4 protocol and in IPv6 protocol.

(2) This is the type of scan you want to make, unless you are hacking
something really hardcore like government or big company shit then leave it as intensive, no one will notice. This also defines the speed and the agression it will use until it checks if a port is open or closed or if its using an specific OS

(3)This is where you'll set the commands to run in the process of scaning, leave it be, if you really want to change this use the wizard and create your own scan type so you can use later.

(4)Well, here you'll see displayed all the information you get. Well see that in just a second.

So lets go ahead and enter what we know, i'll be scanning a pretty crappy japanese page that i found 20 minutes ago when i wake up, i dont know what it is about because i dont read japanese, i only know it had its CGI-BIN wide open and withouth protection so i checked all their stuff... Its still default security, so its not really a challenge :)

(5) As you see i've entered the URL for that jap site

(6&7) This will remain the same, though you must know that you can change them if you want to

(8) With all set lets go ahead and click on SCAN

(9) You'll see the "Scanning..." text under host

(10) You should see and introductory text like this and some seconds later the scan per se will begin.

Now the scan is running, so just sit back and smoke a cigarrete (HEY ITS BAD FOR YOUR HEALTH DON'T DO IT) or listen to some music (BUT NOT TO LOUD, THATS BAD FOR YOUR HEALTH TOO)



Luckily for us this site has many ports wide open so you can see perfectly how the scan shows them AT FIRST. (11)

Now, since this could take a while specially if you are running it slowly to pass undetected every couple of minutes you'll see a percentage of the scan completed, just to let you know NMAP is still running. (12)

(13) VOILA! The ports that are open or filtered, their protocol (tipically TCP) and their main function and even the version of the software it is running, so you can search for your exploiting pleasure!

(14) And THIS is what i love about NMAP, it tells you the OS of the host! Well see this just now in depth...

Now, let see, oh yes, the OS! Look at this! its wonderful! The perfect tool for a hacker, to know your enemy! And knowledge is power!

(15) A nice image of the OS, in this case a relative of LINUX

(16) A graphic representing the average difficulty to hack into this, in this case a bomb, in safer systems you can see a Security Box, in the easiest of them a piece of cake (literally!)

(17) A brief report of the scan

(18) The EXACT version of the operative system (if found) an the accuracy (if found)

Now for you exploiter out there, click on the services (19) tab

(20) Look for the port you want to exploit (sendmail here)

(21)VOILA again! All the info on the sofware running on that port including the version its using (2010 here)
__________________

| 0 comments ]

AD Domains and Trusts domain.msc
Active Directory Management admgmt.msc
AD Sites and Serrvices dssite.msc
AD Users and Computers dsa.msc
ADSI Edit adsiedit.msc
Authorization manager azman.msc
Certification Authority Management certsrv.msc
Certificate Templates certtmpl.msc
Cluster Administrator cluadmin.exe
Computer Management compmgmt.msc
Component Services comexp.msc
Configure Your Server cys.exe
Device Manager devmgmt.msc
DHCP Managment dhcpmgmt.msc
Disk Defragmenter dfrg.msc
Disk Manager diskmgmt.msc
Distributed File System dfsgui.msc
DNS Managment dnsmgmt.msc
Event Viewer eventvwr.msc
Indexing Service Management ciadv.msc
IP Address Managerment ipaddrmgmt.msc
Licensing Manager llsmgr.exe
Local Certificates Management certmgr.msc
Local Group Policy Editor gpedit.msc
Local Security Settings Manager secpol.msc
Local Users and Groups Manager lusrmgr.msc
Network Load balancing nlbmgr.exe
Performance Montior perfmon.msc
PKI Viewer pkiview.msc
Public Key Managment pkmgmt.msc
QoS Control Management acssnap.msc
Remote Desktops tsmmc.msc
Remote Storage Administration rsadmin.msc
Removable Storage ntmsmgr.msc
Removalbe Storage Operator Requests ntmsoprq.msc
Routing and Remote Access Manager rrasmgmt.msc
Resultant Set of Policy rsop.msc
Schema management schmmgmt.msc
Services Management services.msc
Shared Folders fsmgmt.msc
SID Security Migration sidwalk.msc
Telephony Management tapimgmt.msc
Terminal Server Configuration tscc.msc
Terminal Server Licensing licmgr.exe
Terminal Server Manager tsadmin.exe
UDDI Services Managment uddi.msc
Windows Mangement Instumentation wmimgmt.msc
WINS Server manager winsmgmt.msc

| 0 comments ]

This is the same guide I posted at
Code:
unkn0wn.ws
under the nickname sendakalle. Since I didn't see a similar guide here on security-shell I thought it was a good idea to post it here aswell.
_____________________________

Hey guys!

In this tutorial I'm going to show you how to hack a server and then rooting it from a shell.

Let's begin by getting some form of a linux-server, if you dont have one install VirtualBox and install a linux OS.
When this have been completed then we need a scanner because hacking a server one by one takes alot more time.

So here's a scanner:
Code:
http://data.fuskbugg.se/skalman01/-----scan.tgz
Write this in the terminal.
tar zxvf -----scan.tgz
cd scan
Now we most give the files rights, so we do that by writing chmod +x *

Now start googling after VPS-hosting companys and check their IP range and scan the B-address.
Let's say this is the IP-range we found:
95.238

then we start the scan by writing ./start 95.238
Now it's scanning after ssh's on that IP-range when it's done searching it will bruteforce automaticly.
(you can change the wordlist in scan.conf)

Okay let's say we found a server now with the username: root and the password: root123
Login. And now we write uname -a and check what version it's running and it's running "Linux irc 2.6.26-2-686 #1 SMP Fri Aug 14 01:27:18 UTC 2009 i686"
Then we check if gcc is installed, we do that by writing gcc --help.
If it doesnt work it will complicate the rooting of the server.

If it says "gcc : command not found" then it's not installed.
Let's now google for 2.6.26 localrootexploits, and we found one on milworm
"2009-wunderbar_emporium.tgz"
Then let's get it in the server by wget and then pack up the files using tar zxvf and then cd wunderbar_emporium.

First we check the ID and it says:
uid=1002(admin) gid=1002(admin) groups:1002(admin)
Then we run the exploit sh run.sh
Now it will probably come up alot of text where it says # SSH.
Then we check the ID again then we're root!
Now we can change the root password, backdoor the server and much more.

Hope this taught you something and I apologize for my bad english.
Take care!

| 0 comments ]









Ảnh dưới đây đã được chỉnh sửa kích cỡ. Hãy click vào đây để xem toàn bộ ảnh. Ảnh gốc có kích thước 1149x832.




Ảnh dưới đây đã được chỉnh sửa kích cỡ. Hãy click vào đây để xem toàn bộ ảnh. Ảnh gốc có kích thước 1149x861.

Microsoft Office 2010 Blue Edition (Fully Activated)

Microsoft intends to release Microsoft Office 2010 Technical Preview to invited guests who register to sign up for Office 2010 CTP Program only by July 2009. Office 2010 was previously known by codename Office 14 (taken cue from its version), and wrongly assume to be Office 2009. The setup installer of both 32bit (x86) and 64bit (x64) Office 2010 Technical Preview 1 (TP 1) has been leaked to BT network. The leaked Office 2010 Technical Preview 1 has the version of 14.0.4006.1010, a pre-trial version provided to premium Microsoft partners.

It’s unclear whether it is the leaked Office 2010 TP1 build will be the version that is going to be released officially by Microsoft in July. And it’s still unclear yet whether Microsoft will make available publicly for Office 2010 Beta downloads, which is said to be will be having 2 betas - Beta 1 in July 2009 and another Beta 2 in November 2009. The betas is said to be different from Technical Preview, where TP is just meant as an engineering milestone for the development of Office 2010 and related products that leading to RTM that will reach in July 2009, according to Office 2010 IT Blog. Office 2010 is expected to RTM and released as final product in March 2010, with the exception of Exchange Server 2010, where Exchange Server 2010 beta already available from official download links.

The setup installer of the leaked download will install Microsoft Office Plus 2010 edition, with Access 2010, Excel 2010, InfoPath 2010, OneNote 2010, Outlook 2010, PowerPoint 2010, Publisher 2010, and Word 2010. Project Professional 2010, SharePoint Designer 2010 and Visio Professional 2010 are also included in the leaked RAR archive download. Office 2010 supports Windows XP SP3, Windows Vista, and Windows 7.

Important note is that Office2010 TP 1 is still in early stage of development, and may contain bugs, although most individual programs such as Word 2010 and Excel 2010 are usable in everyday life. It’s also interesting to know that Office 2007, the predecessor of Office 2010, is version 12. Office 2010 will be version 14, skipping version 13, the number that Microsoft assumes may be not so lucky.

Microsoft Office 2010 Blue Edition (Fully Activated) - 796 MB

Code:
http://rapidshare.com/files/280234241/M.O.10.Blue.Edition.part01.rar.html
http://rapidshare.com/files/280234451/M.O.10.Blue.Edition.part02.rar.html
http://rapidshare.com/files/280235354/M.O.10.Blue.Edition.part03.rar.html
http://rapidshare.com/files/280235150/M.O.10.Blue.Edition.part04.rar.html
http://rapidshare.com/files/280236044/M.O.10.Blue.Edition.part05.rar.html
http://rapidshare.com/files/280235904/M.O.10.Blue.Edition.part06.rar.html
http://rapidshare.com/files/280236904/M.O.10.Blue.Edition.part07.rar.html
http://rapidshare.com/files/280236658/M.O.10.Blue.Edition.part08.rar.html

http://www.megaupload.com/?d=Q9Z5N8K5
http://www.megaupload.com/?d=R6YIQFCH
http://www.megaupload.com/?d=HQVOODCP
http://www.megaupload.com/?d=4XTT4LXH
http://www.megaupload.com/?d=X10H2DZE
http://www.megaupload.com/?d=9QXB9F5S
http://www.megaupload.com/?d=FCTOKB84
http://www.megaupload.com/?d=8BYCE6NU


Link Mediafire

http://www.mediafire.com/?yjzkxmdwmjk
http://www.mediafire.com/?jzjhwjqdj2m
http://www.mediafire.com/?1gzdoizwcin
http://www.mediafire.com/?giwjnmjj3zt
http://www.mediafire.com/?5ezqo3ngdmt
http://www.mediafire.com/?jnynikvzvj1
http://www.mediafire.com/?z2mnwmmzlm5
http://www.mediafire.com/?zznj2mrnydy

| 0 comments ]

chuẩn bị
+ 2 tấm ảnh (ảnh 1: 201x306 ;ảnh 2: 142x366) định dạng bitmap( đuôi .bmp)
+ down mấy file này về

start menu gốc

sau khi download về giải nén file vinhxomdoi.exe trong đó có 1 file .exe và 1 shortcut
dùng rehacker mở file .exe đó lên ==> vào phần bitmap==> ORANGE_STARTPANELMFUBACKGROUND_BMP ==>1033 thực hiện replace bằng ảnh 1. tiếp đó suống ORANGE_STARTPANELPLACESBACKGROUND_BMP thực hiện replace bằng ảnh 2





hình ảnh trong start chỉ có 2 pic này là quan trọng nhất.bạn có thể dừng ở đây nếu muốn, hoặc làm tiếp .kệ bạn!
các ảnh trong start menu
ORANGE_STARTPANELMOREPROBACKGROUND_BMP
ORANGE_STARTUSERPANEL_BMP
ORANGE_STARTPANELLOGOFFBACKGROUND_BMP
thực hiện replace song là bạn có 1 start menu hoàn chỉnh rùi

replace song vào file ==> save as...==> tên mà bạn muốn.msstyles

mở file vừa làm lên xem có gì khác ko