Jump to content

X3N

Active Members
  • Posts

    270
  • Joined

  • Last visited

Everything posted by X3N

  1. yeah thast what i made it do
  2. Posting u3 dev enviroment. ver .01b http://dl.getdropbox.com/u/332413/u3dev/u3dev.7z
  3. MEtasploit comes with a ruby script to disable av which works the same as the old way but had a nice good list of process names of av. _avp32.exe _avpcc.exe _avpm.exe ackwin32.exe adaware.exe advxdwin.exe agentsvr.exe agentw.exe alertsvc.exe alevir.exe alogserv.exe amon9x.exe anti-trojan.exe antivirus.exe ants.exe apimonitor.exe aplica32.exe apvxdwin.exe arr.exe atcon.exe atguard.exe atro55en.exe atupdater.exe atwatch.exe au.exe aupdate.exe auto-protect.nav80try.exe autodown.exe autotrace.exe autoupdate.exe avconsol.exe ave32.exe avgcc32.exe avgctrl.exe avgnt.exe avguard.exe avkserv.exe avnt.exe avp.exe avp.exe avp32.exe avpcc.exe avpdos32.exe avpm.exe avptc32.exe avpupd.exe avsched32.exe avwin.exe avwin95.exe avwupd32.exe blackd.exe blackice.exe cfiadmin.exe cfiaudit.exe cfinet.exe cfinet32.exe claw95.exe claw95cf.exe cleaner.exe cleaner3.exe defwatch.exe dvp95.exe dvp95_0.exe ecengine.exe esafe.exe espwatch.exe f-agnt95.exe f-prot.exe f-prot95.exe f-stopw.exe findviru.exe fp-win.exe fprot.exe frw.exe iamapp.exe iamserv.exe ibmasn.exe ibmavsp.exe icload95.exe icloadnt.exe icmon.exe icsupp95.exe icsuppnt.exe iface.exe iomon98.exe jedi.exe lockdown2000.exe lookout.exe luall.exe moolive.exe mpftray.exe n32scanw.exe navapw32.exe navlu32.exe navnt.exe navw32.exe navwnt.exe nisum.exe nmain.exe normist.exe nupgrade.exe nvc95.exe outpost.exe padmin.exe pavcl.exe pavsched.exe pavw.exe pccwin98.exe pcfwallicon.exe persfw.exe rav7.exe rav7win.exe rescue.exe safeweb.exe scan32.exe scan95.exe scanpm.exe scrscan.exe serv95.exe smc.exe sphinx.exe sweep95.exe tbscan.exe tca.exe tds2-98.exe tds2-nt.exe vet95.exe vettray.exe vscan40.exe vsecomr.exe vshwin32.exe vsstat.exe webscanx.exe wfindv32.exe zonealarm.exe avgserv.exe avgserv9.exe avguard.exe avgw.exe avkpop.exe avkserv.exe avkservice.exe avkwctl9.exe avltmain.exe avnt.exe avp.exe avp32.exe avpcc.exe avpdos32.exe avpm.exe avptc32.exe avpupd.exe avpupd.exe avsched32.exe avsynmgr.exe avwinnt.exe avwupd.exe avwupd32.exe avwupd32.exe avwupsrv.exe avxmonitor9x.exe avxmonitornt.exe avxquar.exe avxquar.exe backweb.exe bargains.exe bd_professional.exe beagle.exe belt.exe bidef.exe bidserver.exe bipcp.exe bipcpevalsetup.exe bisp.exe blackd.exe blackice.exe blss.exe bootconf.exe bootwarn.exe borg2.exe bpc.exe brasil.exe bs120.exe bundle.exe bvt.exe ccapp.exe ccevtmgr.exe ccpxysvc.exe cdp.exe cfd.exe cfgwiz.exe cfiadmin.exe cfiaudit.exe cfiaudit.exe cfinet.exe cfinet32.exe claw95cf.exe clean.exe cleaner.exe cleaner3.exe cleanpc.exe click.exe cmd.exe cmd32.exe cmesys.exe cmgrdian.exe cmon016.exe connectionmonitor.exe cpd.exe cpf9x206.exe cpfnt206.exe ctrl.exe cv.exe cwnb181.exe cwntdwmo.exe datemanager.exe dcomx.exe defalert.exe defscangui.exe defwatch.exe deputy.exe divx.exe dllcache.exe dllreg.exe doors.exe dpf.exe dpfsetup.exe dpps2.exe drwatson.exe drweb32.exe drwebupw.exe dssagent.exe dvp95.exe dvp95_0.exe ecengine.exe efpeadm.exe emsw.exe ent.exe esafe.exe escanhnt.exe escanv95.exe espwatch.exe ethereal.exe etrustcipe.exe evpn.exe exantivirus-cnet.exe exe.avxw.exe expert.exe explore.exe fameh32.exe fast.exe fch32.exe fih32.exe findviru.exe firewall.exe fnrb32.exe fprot.exe f-prot.exe f-prot95.exe fp-win.exe fp-win_trial.exe frw.exe fsaa.exe fsav.exe fsav32.exe fsav530stbyb.exe fsav530wtbyb.exe fsav95.exe fsgk32.exe fsm32.exe fsma32.exe fsmb32.exe f-stopw.exe gator.exe gbmenu.exe gbpoll.exe generics.exe gmt.exe guard.exe guarddog.exe hacktracersetup.exe hbinst.exe hbsrv.exe hotactio.exe hotpatch.exe htlog.exe htpatch.exe hwpe.exe hxdl.exe hxiul.exe iamapp.exe iamserv.exe iamstats.exe ibmasn.exe ibmavsp.exe icloadnt.exe icmon.exe icsupp95.exe icsuppnt.exe idle.exe iedll.exe iedriver.exe iexplorer.exe iface.exe ifw2000.exe inetlnfo.exe infus.exe infwin.exe init.exe intdel.exe intren.exe iomon98.exe istsvc.exe jammer.exe jdbgmrg.exe jedi.exe kavlite40eng.exe kavpers40eng.exe kavpf.exe kazza.exe keenvalue.exe kerio-pf-213-en-win.exe kerio-wrl-421-en-win.exe kerio-wrp-421-en-win.exe kernel32.exe killprocesssetup161.exe launcher.exe ldnetmon.exe ldpro.exe ldpromenu.exe ldscan.exe lnetinfo.exe loader.exe localnet.exe lockdown.exe lockdown2000.exe lookout.exe lordpe.exe lsetup.exe luall.exe luall.exe luau.exe lucomserver.exe luinit.exe luspt.exe mapisvc32.exe mcagent.exe mcmnhdlr.exe mcshield.exe mctool.exe mcupdate.exe mcupdate.exe mcvsrte.exe mcvsshld.exe md.exe mfin32.exe mfw2en.exe mfweng3.02d30.exe mgavrtcl.exe mgavrte.exe mghtml.exe mgui.exe minilog.exe mmod.exe monitor.exe moolive.exe mostat.exe mpfagent.exe mpfservice.exe mpftray.exe mrflux.exe msapp.exe msbb.exe msblast.exe mscache.exe msccn32.exe mscman.exe msconfig.exe msdm.exe msdos.exe msiexec16.exe msinfo32.exe mslaugh.exe msmgt.exe msmsgri32.exe mssmmc32.exe mssys.exe msvxd.exe mu0311ad.exe mwatch.exe n32scanw.exe nav.exe navap.navapsvc.exe navapsvc.exe navapw32.exe navdx.exe navlu32.exe navnt.exe navstub.exe navw32.exe navwnt.exe nc2000.exe ncinst4.exe ndd32.exe neomonitor.exe neowatchlog.exe netarmor.exe netd32.exe netinfo.exe netmon.exe netscanpro.exe netspyhunter-1.2.exe netstat.exe netutils.exe nisserv.exe nisum.exe nmain.exe nod32.exe normist.exe norton_internet_secu_3.0_407.exe notstart.exe npf40_tw_98_nt_me_2k.exe npfmessenger.exe nprotect.exe npscheck.exe npssvc.exe nsched32.exe nssys32.exe nstask32.exe nsupdate.exe nt.exe ntrtscan.exe ntvdm.exe ntxconfig.exe nui.exe nupgrade.exe nupgrade.exe nvarch16.exe nvc95.exe nvsvc32.exe nwinst4.exe nwservice.exe nwtool16.exe ollydbg.exe onsrvr.exe optimize.exe ostronet.exe otfix.exe outpost.exe outpost.exe outpostinstall.exe outpostproinstall.exe padmin.exe panixk.exe patch.exe pavcl.exe pavproxy.exe pavsched.exe pavw.exe pcfwallicon.exe pcip10117_0.exe pcscan.exe pdsetup.exe periscope.exe persfw.exe perswf.exe pf2.exe pfwadmin.exe pgmonitr.exe pingscan.exe platin.exe pop3trap.exe poproxy.exe popscan.exe portdetective.exe portmonitor.exe powerscan.exe ppinupdt.exe pptbc.exe ppvstop.exe prizesurfer.exe prmt.exe prmvr.exe procdump.exe processmonitor.exe procexplorerv1.0.exe programauditor.exe proport.exe protectx.exe pspf.exe purge.exe qconsole.exe qserver.exe rapapp.exe rav7.exe rav7win.exe rav8win32eng.exe ray.exe rb32.exe rcsync.exe realmon.exe reged.exe regedit.exe regedt32.exe rescue.exe rescue32.exe rrguard.exe rshell.exe rtvscan.exe rtvscn95.exe rulaunch.exe run32dll.exe rundll.exe rundll16.exe ruxdll32.exe safeweb.exe sahagent.exe save.exe savenow.exe sbserv.exe sc.exe scam32.exe scan32.exe scan95.exe scanpm.exe scrscan.exe setup_flowprotector_us.exe setupvameeval.exe sfc.exe sgssfw32.exe sh.exe shellspyinstall.exe shn.exe showbehind.exe smc.exe sms.exe smss32.exe soap.exe sofi.exe sperm.exe spf.exe sphinx.exe spoler.exe spoolcv.exe spoolsv32.exe spyxx.exe srexe.exe srng.exe ss3edit.exe ssg_4104.exe ssgrate.exe st2.exe start.exe stcloader.exe supftrl.exe support.exe supporter5.exe svc.exe svchostc.exe svchosts.exe svshost.exe sweep95.exe sweepnet.sweepsrv.sys.swnetsup.exe symproxysvc.exe symtray.exe sysedit.exe system.exe system32.exe sysupd.exe taskmg.exe taskmgr.exe taskmo.exe taskmon.exe taumon.exe tbscan.exe tc.exe tca.exe tcm.exe tds2-nt.exe tds-3.exe teekids.exe tfak.exe tfak5.exe tgbob.exe titanin.exe titaninxp.exe tracert.exe trickler.exe trjscan.exe trjsetup.exe trojantrap3.exe tsadbot.exe tvmd.exe tvtmd.exe undoboot.exe updat.exe update.exe update.exe upgrad.exe utpost.exe vbcmserv.exe vbcons.exe vbust.exe vbwin9x.exe vbwinntw.exe vcsetup.exe vet32.exe vet95.exe vettray.exe vfsetup.exe vir-help.exe virusmdpersonalfirewall.exe vnlan300.exe vnpc3000.exe vpc32.exe vpc42.exe vpfw30s.exe vptray.exe vscan40.exe vscenu6.02d30.exe vsched.exe vsecomr.exe vshwin32.exe vsisetup.exe vsmain.exe vsmon.exe vsstat.exe vswin9xe.exe vswinntse.exe vswinperse.exe w32dsm89.exe w9x.exe watchdog.exe webdav.exe webscanx.exe webtrap.exe wfindv32.exe whoswatchingme.exe wimmun32.exe win32.exe win32us.exe winactive.exe win-bugsfix.exe window.exe windows.exe wininetd.exe wininit.exe wininitx.exe winlogin.exe winmain.exe winnet.exe winppr32.exe winrecon.exe winservn.exe winssk32.exe winstart.exe winstart001.exe wintsk32.exe winupdate.exe wkufind.exe wnad.exe wnt.exe wradmin.exe wrctrl.exe wsbgate.exe wupdater.exe wupdt.exe wyvernworksfirewall.exe xpf202en.exe zapro.exe zapsetup3001.exe zatutor.exe zonalm2601.exe zonealarm.exe
  4. what version of U3 drive did you use ? i been looking into preserving the u3 functionality and booting... ive already make a backtrack bootable usbdrive before but it wasnt u3.... did you use the same process?
  5. it really depends on what you are developing for... if i was developing an app for windows id just use the native windows api but if i wanted something cross platform i might use gtk honestly i dont use gui's hardly at all in my programming... i prefer the cli As far as tutorials i always find it easiest to pick apart the examples that the dev kits usually come with in order to figure it out.
  6. there alot of options for this... in the open source area you have clonezilla which is a clone of ghost theres also dd which is my fave... none opensource stuff that ive used is ghost which works well. also acronis true image really though the best is dd if you learn how to use that because it does a bit for bit exact copy... alot of these other programs compress the freespace which speeds up the process and makes the image smaller but if you want an exact copy then you should use dd. Ive had unpredictable things happen with the mbr when using tools other then dd. Plus dd works over netcat nicely in case you wanted to do it over the network.
  7. mint linux is just as easy as regular ubuntu but mint is prettier.
  8. http://wiki.python.org/moin/GuiProgramming
  9. for a production environment you should use actual hardware. Have one input going into your computer and the multiple inputs going into a receiver or a switch that you change depending on what you want to show.
  10. X3N

    about CDFS

    theres two choices now the first is to use the universal customizer and the other is using lpinstaller.... here is the link for using the lpinstaller on a vista machine simaler to what you were takling about i actually wrote a tool in autoIT to make it easier http://hak5.org/forums/index.php?showtopic=10392
  11. whats the cpu load for the keylogger?
  12. actually there is a good way to fix all this. Like I had mentioned before logon scripts and using the GPO editor to manipulate group policy's. then use Ultra vnc to remote control if need be.... even if you installed ssh you could run scripts to fix whatever is wrong with thier setup.
  13. X3N

    PsTools, how

    psexec you need admin privelegest to run over the network... pstools is a set of tools that do a bunch of really cool stuff... has nothing to do with script kiddies
  14. first download autoIT then paste this into a txt file called beepstart.au3 $cmd = "psexec \\testmachine -u DOMAIN\USER -p PASSWORD -c beep.exe" Run($cmd) make sure to change the machine and password part to match your machine. Then in another file called beep.au3 paste this Beep() Compile the beep.au3 to an exe now all you have to do is double click the beep.au3 or you can compile it to an exe as well. either way you could just make a shortcut for whoeveer to click on in order to make your computer beep.
  15. soudns like your better off using an instant messenger program... and if your in the same house you might as well use an intercom.... the problem i dont like with what your trying to do is that you really dont want people having access to your computer like that... remote command execution via a button sounds pretty insecure to me.
  16. what exactly are you trying to do here? what was that script supposed to do?
  17. it might be possible but kind of redundant... what is the enviroment you are trying to use this in? you could just write a wrapper in vb for psexec i prefer autoIT to vb and theres a few wrappers on the forums for autoit... Why do you want to use VB?
  18. X3N

    USB Lojak

    i have some autoIT code that will email to gmail using ssl without having ot use blat or stunnel... i actually have a full payload that dumps all the info over ssl to gmail via autoIT its posted in the usbhacks section.
  19. X3N

    USB Lojak

    another way to do this us to use a service like dyndns... which is basically a little program that logs into the dyndns server to bind a name to a dynamic ip address... this could easily be scripted to autorun on a usb drive... the only problem is that if someone has autorun turned off then it totally defeats the purpose because you cant force autorun to run if its disabled.
  20. man if your friends are stupid enough to pay 2 bucks a week for access then thats great for you but sucks for them...for that money you could get some ssh or vpn access elsewhwere...thats actually secure... your best bet is the keypairing though if your going to use ssh to do this...
  21. if you are on a windows domain you can pass the script through the group policy that computer belongs to... if you are not on a domain then your best bet is to copy the script to the computer and telnet or ssh into it and run the script. another option is using one of the sysinternals tools like psexec to remotly run a command over the network. Sometimes what I will do is use psexec to spawn a remote command shell which is a little more secure then enabling telnet....
  22. really this is a non-issue. There are two ways around this. First if you are running windows server then you should be using active directory to push any changes out to machines and depending on your server setup it may take a few hours for the changes to sync accross the domain. The second way of getting around this is to make sure the person doesnt lock thier computer. I found this on some site.... not the prefered way to do it but an option. It would be better to do it using the GPO editor. If random users chose to lock the system (by pressing Ctrl+Alt+Delete and clicking the Lock Computer button), an administrator would need to manually unlock the system. To avoid this, the Lock Computer button can be disabled. To disable the Lock Computer button, open Regedit and browse to HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\ System and HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\ System and create a new REG_DWORD value in each called DisableLockWorkstation. Setting this value to 0 will allow the Lock Computer button to be used, while 1 will disable it. and as a final thought... what are you doing to these computer that you need to unlock it anyways? Most tasks can be like i mentioned before updated via a logon script or the GPO editor. Those are skills you shoulld work on. If you dont have access to that on your domain then you probably shouldnt be doing any kind of computer unlocking anyways... Also I like to run ultra vnc over the domain which can be setup to use mslogon if you want... but either way its alot handier then RDP for managing remote desktops without the user having to be logged out and you dont have to get out of your seat.
×
×
  • Create New...