Welcome Guest ( Log In | Register )

29 Pages V  < 1 2 3 4 > »   
Reply to this topicStart new topic
USB Switchblade Development
DLSS
post Wed, 06 Sep 2006 07:15:14 +0000
Post #21


Hak.5 Ninja
*******

Group: Members
Posts: 979
Joined: Tue, 07 Mar 2006 12:40:16 +0000
From: Belgium
Member No.: 275



avast dont like it :(
and wiggs out


--------------------
Go to the top of the page
 
+Quote Post
Darren Kitchen
post Wed, 06 Sep 2006 11:40:07 +0000
Post #22


Hak.5 Junkie
************

Group: Root Admin
Posts: 3,008
Joined: Tue, 26 Jul 2005 15:52:42 +0000
From: Williamsburg, VA
Member No.: 2



QUOTE ("aznrocket")
huh, just curious how difficult it would be to add a feature to this switchblade-- the capacity to copy files OFF of the computer you plug it into (e.g. documents, msn messenger logs, etc), while maintaining its stealthiness.


It wouldn't be hard to program in, but I rather like it the way it is since it's actually way more stealthy. As a systems administrator if I found that this happened on my network I could check traffic logs and possibly find the drop site that the cracker used.


--------------------
Go to the top of the page
 
+Quote Post
vehlewa1
post Wed, 06 Sep 2006 12:14:41 +0000
Post #23


Newbie


Group: Members
Posts: 2
Joined: Wed, 06 Sep 2006 09:05:00 +0000
Member No.: 2,044



Great tool, but I'm getting errors on the DUMP SAM portion:

Logon to 127.0.0.1ADMIN$ failed: code 53

Or

Logon to 127.0.0.1ADMIN$ failed: code 1231

Anyone else having similar problems?
Go to the top of the page
 
+Quote Post
Sparda
post Wed, 06 Sep 2006 12:20:17 +0000
Post #24


Also known as Boris
************

Group: Global Moderators
Posts: 6,722
Joined: Tue, 07 Mar 2006 17:32:49 +0000
From: The Great England
Member No.: 284



That could be casued by a firewall or windows file sharing been disabled, I'm not familier with the error coads and so can't say for sure.


--------------------
skype me: tehboris
PS3 ID: tehBoris
Twitter: https://twitter.com/tehboris
Steam: http://steamcommunity.com/id/tehboris
Go to the top of the page
 
+Quote Post
vehlewa1
post Wed, 06 Sep 2006 12:35:04 +0000
Post #25


Newbie


Group: Members
Posts: 2
Joined: Wed, 06 Sep 2006 09:05:00 +0000
Member No.: 2,044



File Sharing is enabled, and even with the firewall and anti-virus turned off I'm still getting the same errors. It seems to work great pulling all of my passwords from applications, but it wont even generate the hash to run against rainbow..
Go to the top of the page
 
+Quote Post
cypherhash
post Wed, 06 Sep 2006 12:48:00 +0000
Post #26


Newbie


Group: Members
Posts: 2
Joined: Wed, 06 Sep 2006 12:44:46 +0000
Member No.: 2,058



Something that would be really interesting is having this work even if autorun is enabled, by exploiting the USB to either enable temporarily or just run this code. A lot of places are now preventing the autorun feature for fear of things like this. I'd be interested to see / help with that solution.
Go to the top of the page
 
+Quote Post
Hug_It
post Wed, 06 Sep 2006 13:00:04 +0000
Post #27


Newbie


Group: Members
Posts: 3
Joined: Wed, 06 Sep 2006 12:53:37 +0000
Member No.: 2,059



I'd love to see it expanded so that it can email or somehow send the results to a user specified destination just for use in penetration testing. Leave a few USB sticks around a company and just wait for the users to pick them up and plug them in. Great example to convince companies to quit allowing their users administrative priviledges.

Either the U3 version or Amish's version would be satisfactory. Anyone know how to do that?
Go to the top of the page
 
+Quote Post
Sparda
post Wed, 06 Sep 2006 13:07:01 +0000
Post #28


Also known as Boris
************

Group: Global Moderators
Posts: 6,722
Joined: Tue, 07 Mar 2006 17:32:49 +0000
From: The Great England
Member No.: 284



QUOTE ("vehlewa1")
File Sharing is enabled, and even with the firewall and anti-virus turned off I'm still getting the same errors. It seems to work great pulling all of my passwords from applications, but it wont even generate the hash to run against rainbow..


Perhaps there is no password on the admin acount. In that instance windows would force remote users to logon using the guesst acount.


--------------------
skype me: tehboris
PS3 ID: tehBoris
Twitter: https://twitter.com/tehboris
Steam: http://steamcommunity.com/id/tehboris
Go to the top of the page
 
+Quote Post
cypherhash
post Wed, 06 Sep 2006 13:08:27 +0000
Post #29


Newbie


Group: Members
Posts: 2
Joined: Wed, 06 Sep 2006 12:44:46 +0000
Member No.: 2,058



Interesting article that sounds exactly like what you described, http://www.darkreading.com/document.asp?do...T.svl=column1_1. Now if only they'd release the source of their program. Though I doubt it would be hard to whip something together.
Go to the top of the page
 
+Quote Post
elitegoodguy
post Wed, 06 Sep 2006 13:33:11 +0000
Post #30


Newbie


Group: Members
Posts: 3
Joined: Wed, 06 Sep 2006 13:29:03 +0000
Member No.: 2,063



This works great. However 1 problem. I want to make it as stealthy as possible but it causes a popup box saying that it wan't to restart the computer to finish installing the hardware. Anyone know how to disable that or get around this?

Thanks
Go to the top of the page
 
+Quote Post
Sparda
post Wed, 06 Sep 2006 13:39:53 +0000
Post #31


Also known as Boris
************

Group: Global Moderators
Posts: 6,722
Joined: Tue, 07 Mar 2006 17:32:49 +0000
From: The Great England
Member No.: 284



That sounds like it could be a computer (or windows rather) specific problem. Windows will do that on some computer for what ever reason, it's just egnorable.


--------------------
skype me: tehboris
PS3 ID: tehBoris
Twitter: https://twitter.com/tehboris
Steam: http://steamcommunity.com/id/tehboris
Go to the top of the page
 
+Quote Post
elitegoodguy
post Wed, 06 Sep 2006 13:42:57 +0000
Post #32


Newbie


Group: Members
Posts: 3
Joined: Wed, 06 Sep 2006 13:29:03 +0000
Member No.: 2,063



QUOTE ("Sparda")
That sounds like it could be a computer (or windows rather) specific problem. Windows will do that on some computer for what ever reason, it's just egnorable.


I tried it on 5 computers at work. mine, and 4 others. Mine did not do that, however all 4 others did
Go to the top of the page
 
+Quote Post
Hug_It
post Wed, 06 Sep 2006 13:47:10 +0000
Post #33


Newbie


Group: Members
Posts: 3
Joined: Wed, 06 Sep 2006 12:53:37 +0000
Member No.: 2,059



QUOTE ("cypherhash")
Interesting article that sounds exactly like what you described, http://www.darkreading.com/document.asp?do...T.svl=column1_1. Now if only they'd release the source of their program. Though I doubt it would be hard to whip something together.


Exactly what I was thinking.
Go to the top of the page
 
+Quote Post
Guest_MaxDamage_*
post Wed, 06 Sep 2006 14:05:09 +0000
Post #34





Guests






...
Go to the top of the page
 
+Quote Post
elitegoodguy
post Wed, 06 Sep 2006 14:07:53 +0000
Post #35


Newbie


Group: Members
Posts: 3
Joined: Wed, 06 Sep 2006 13:29:03 +0000
Member No.: 2,063



QUOTE ("MaxDamage")
Hey man I feel famous LOL. Seriously thanks for the credit Darren. 8)

When I developed the first payload it was just a proof of concept put together in half an hour as soon as I found out how to replace the U3 iso. Anywaz since then I have written some more, and refined it a bit. I have also got a bolt on, that silently finds the local smtp server (or builds its own if directly connected) and emails the results.

So If you guys want to help develop it further I’m up for it. And if you need help getting it running then just ask :).

I also have a nun U3 version somthing like Amesh'e that I could add if you need it.


That would be great... would this be something that copies all the required files to the HD then emails from there? I'm thinking that so I won't have to be at the local computer any longer than needs be.
Go to the top of the page
 
+Quote Post
Guest_MaxDamage_*
post Wed, 06 Sep 2006 14:26:36 +0000
Post #36





Guests






...
Go to the top of the page
 
+Quote Post
brainkill
post Wed, 06 Sep 2006 14:45:26 +0000
Post #37


Hak.5 Fan
**

Group: Members
Posts: 19
Joined: Sat, 22 Jul 2006 23:41:19 +0000
From: <banned>
Member No.: 1,488



QUOTE ("DLSS")
avast dont like it :(
and wiggs out



what files? pleas email me at admin@vertex-hosting.net with the files it flags. I will encrypt them. I have encrypted pwdump.exe lsaext.dll and pwservice and they are hosted at http://brainkill.net/hack. Consult page for direct links.


Thanks


--------------------
-----------------------------
Brandon G.
Lead Hosting Tech/Owner
------------------------------
<banned>
Go to the top of the page
 
+Quote Post
Guest_MaxDamage_*
post Wed, 06 Sep 2006 14:54:20 +0000
Post #38





Guests






...
Go to the top of the page
 
+Quote Post
brainkill
post Wed, 06 Sep 2006 14:57:50 +0000
Post #39


Hak.5 Fan
**

Group: Members
Posts: 19
Joined: Sat, 22 Jul 2006 23:41:19 +0000
From: <banned>
Member No.: 1,488



QUOTE ("MaxDamage")
nice, how do you ecrypt exe's ?


secret :X I dont give it out for fear of it becoming public and caught by avs. I WILL ENCRYPT THEM BUT I WONT GIVE OUT THE ENCRYPTER. Sorry. It would also allow any blackhat-wannabe to hack people. Im not going to let that happen.


--------------------
-----------------------------
Brandon G.
Lead Hosting Tech/Owner
------------------------------
<banned>
Go to the top of the page
 
+Quote Post
DLSS
post Wed, 06 Sep 2006 15:06:25 +0000
Post #40


Hak.5 Ninja
*******

Group: Members
Posts: 979
Joined: Tue, 07 Mar 2006 12:40:16 +0000
From: Belgium
Member No.: 275



QUOTE ("brainkill")
QUOTE ("DLSS")


avast dont like it :(
and wiggs out



what files? pleas email me at admin@vertex-hosting.net with the files it flags. I will encrypt them. I have encrypted pwdump.exe lsaext.dll and pwservice and they are hosted at http://brainkill.net/hack. Consult page for direct links.


Thanks


i think i can guess how :P
i'll do a quick check . that message was just emediately while dowloading (the on acces scanner)
but i'll disable it and maually test each file seperate and send u the results :wink:


--------------------
Go to the top of the page
 
+Quote Post

29 Pages V  < 1 2 3 4 > » 
Reply to this topicStart new topic
2 User(s) are reading this topic (2 Guests and 0 Anonymous Users)
0 Members:

 



RSS Lo-Fi Version Time is now: Sat, 21 Nov 2009 02:51:31 +0000