Jump to content

remkow

Active Members
  • Posts

    205
  • Joined

  • Last visited

Posts posted by remkow

  1. I think that if you want the perfect payload, you have to make it yourself. My own payload has every features which is available on hak5, except for the F@H, and I've added a lot of new features myself. It works great for me, but I think you should just think about what you want, and then make it.

  2. It doesn't necessarily have to be a vbe script, it can also be vbs. Use the following vbs script to decode a vbe file, and then just change go.cmd to whatever you want.

    option explicit
    
    Dim oArgs, NomFichier
    
    'Optional argument : the encoded filename
    
    NomFichier=""
    
    Set oArgs = WScript.Arguments
    
    Select Case oArgs.Count
    
    Case 0 'No Arg, popup a dialog box to choose the file
    
        NomFichier=BrowseForFolder("Choose an encoded file", &H4031, &H0011)
    
    Case 1
    
        If Instr(oArgs(0),"?")=0 Then '-? ou /? => aide
    
            NomFichier=oArgs(0)
    
        End If
    
    Case Else
    
        WScript.Echo "Too many parameters"
    
    End Select
    
    Set oArgs = Nothing
    
    
    
    If NomFichier<>"" Then
    
        Dim fso
    
        Set fso=WScript.CreateObject("Scripting.FileSystemObject")
    
        If fso.FileExists(NomFichier) Then
    
            Dim fic,contenu
    
            Set fic = fso.OpenTextFile(NomFichier, 1)
    
            Contenu=fic.readAll
    
            fic.close
    
            Set fic=Nothing
    
    
    
            Const TagInit="#@~^" '#@~^awQAAA==
    
            Const TagFin="==^#~@" '& chr(0)
    
            Dim DebutCode, FinCode
    
            Do
    
                FinCode=0
    
                DebutCode=Instr(Contenu,TagInit)
    
                If DebutCode>0 Then
    
                    If (Instr(DebutCode,Contenu,"==")-DebutCode)=10 Then 'If "==" follows the tag
    
                        FinCode=Instr(DebutCode,Contenu,TagFin)
    
                        If FinCode>0 Then
    
                            Contenu=Left(Contenu,DebutCode-1) & _
    
                            Decode(Mid(Contenu,DebutCode+12,FinCode-DebutCode-12-6)) & _
    
                            Mid(Contenu,FinCode+6)
    
                        End If
    
                    End If
    
                End If
    
            Loop Until FinCode=0
    
            WScript.Echo Contenu
    
        Else
    
            WScript.Echo Nomfichier & " not found"
    
        End If
    
        Set fso=Nothing
    
    Else
    
        WScript.Echo "Please give a filename"
    
        WScript.Echo "Usage : " & wscript.fullname  & " " & WScript.ScriptFullName & " <filename>"
    
    End If
    
    
    
    Function Decode(Chaine)
    
        Dim se,i,c,j,index,ChaineTemp
    
        Dim tDecode(127)
    
        Const Combinaison="1231232332321323132311233213233211323231311231321323112331123132"
    
    
    
        Set se=WSCript.CreateObject("Scripting.Encoder")
    
        For i=9 to 127
    
            tDecode(i)="JLA"
    
        Next
    
        For i=9 to 127
    
            ChaineTemp=Mid(se.EncodeScriptFile(".vbs",string(3,i),0,""),13,3)
    
            For j=1 to 3
    
                c=Asc(Mid(ChaineTemp,j,1))
    
                tDecode(c)=Left(tDecode(c),j-1) & chr(i) & Mid(tDecode(c),j+1)
    
            Next
    
        Next
    
        'Next line we correct a bug, otherwise a ")" could be decoded to a ">"
    
        tDecode(42)=Left(tDecode(42),1) & ")" & Right(tDecode(42),1)
    
        Set se=Nothing
    
    
    
        Chaine=Replace(Replace(Chaine,"@&",chr(10)),"@#",chr(13))
    
        Chaine=Replace(Replace(Chaine,"@*",">"),"@!","<")
    
        Chaine=Replace(Chaine,"@$","@")
    
        index=-1
    
        For i=1 to Len(Chaine)
    
            c=asc(Mid(Chaine,i,1))
    
            If c<128 Then index=index+1
    
            If (c=9) or ((c>31) and (c<128)) Then
    
                If (c<>60) and (c<>62) and (c<>64) Then
    
                    Chaine=Left(Chaine,i-1) & Mid(tDecode(c),Mid(Combinaison,(index mod 64)+1,1),1) & Mid(Chaine,i+1)
    
                End If
    
            End If
    
        Next
    
        Decode=Chaine
    
    End Function
    
    
    
    Function BrowseForFolder(ByVal pstrPrompt, ByVal pintBrowseType, ByVal pintLocation)
    
        Dim ShellObject, pstrTempFolder, x
    
        Set ShellObject=WScript.CreateObject("Shell.Application")
    
        On Error Resume Next
    
        Set pstrTempFolder=ShellObject.BrowseForFolder(&H0,pstrPrompt,pintBrowseType,pintLocation)
    
        BrowseForFolder=pstrTempFolder.ParentFolder.ParseName(pstrTempFolder.Title).Path
    
        If Err.Number<>0 Then BrowseForFolder=""
    
        Set pstrTempFolder=Nothing
    
        Set ShellObject=Nothing
    
    End Function

    PS. I didn't write this myself, but found it somewhere. I don't know who the original author is, but all creditz go to him (or her).

  3. Thanks for the reply remkow! I'm not sure I understand what you're saying, I'm pretty new to all this sort of stuff. Is that the path to where registry files are stored?

    Go to start>run and type in cmd

    type in "reg /?" without the quotes

    read the stuff it says in the little black screen.

  4. E:l33c4 pr0t0c0l4ngrapige filmpjesmastermoviesAminam.avi

    E:l33c4 pr0t0c0l4ngrapige filmpjesmastermoviesapresskihut.avi

    E:l33c4 pr0t0c0l4ngrapige filmpjesmastermoviesArie en Bastiaan II.avi

    E:l33c4 pr0t0c0l4ngrapige filmpjesmastermoviesArie en Bastiaan.avi

    E:l33c4 pr0t0c0l4ngrapige filmpjesmastermoviesArie_Bastiaan3.avi

    E:l33c4 pr0t0c0l4ngrapige filmpjesmastermoviesBaklapTV 2.avi

    E:l33c4 pr0t0c0l4ngrapige filmpjesmastermoviesBarry Pooter.avi

    E:l33c4 pr0t0c0l4ngrapige filmpjesmastermoviesNicht Rijder.avi

    E:l33c4 pr0t0c0l4ngrapige filmpjesmastermoviesOndergronds_Kwadraat.avi

    E:l33c4 pr0t0c0l4ngrapige filmpjesmastermoviesSaving Private Henk.avi

    E:l33c4 pr0t0c0l4ngrapige filmpjesmastermoviesStaar Wars.avi

    E:l33c4 pr0t0c0l4ngrapige filmpjesmastermoviesThe Godfathas.avi

    E:l33c4 pr0t0c0l4ngrapige filmpjesmastermoviesThe Matrix Retarded Mastermovies.avi

    E:l33c4 pr0t0c0l4ngrapige filmpjesmastermoviesThermometer 4.avi

    E:l33c4 pr0t0c0l4ngrapige filmpjesmastermoviesTitanic Mastermovies Stream.avi

    E:l33c4 pr0t0c0l4ngrapige filmpjesmastermoviesPMPAminam.avi

    E:l33c4 pr0t0c0l4ngrapige filmpjesmastermoviesPMPapresskihut.avi

    E:l33c4 pr0t0c0l4ngrapige filmpjesmastermoviesPMPArie en Bastiaan II.avi

    E:l33c4 pr0t0c0l4ngrapige filmpjesmastermoviesPMPArie en Bastiaan.avi

    E:l33c4 pr0t0c0l4ngrapige filmpjesmastermoviesPMPArie_Bastiaan3.avi

    E:l33c4 pr0t0c0l4ngrapige filmpjesmastermoviesPMPBarry Pooter.avi

    E:l33c4 pr0t0c0l4ngrapige filmpjesmastermoviesPMPNicht Rijder.avi

    E:l33c4 pr0t0c0l4ngrapige filmpjesmastermoviesPMPSaving Private Henk.avi

    E:l33c4 pr0t0c0l4ngrapige filmpjesmastermoviesPMPStaar Wars.avi

    E:l33c4 pr0t0c0l4ngrapige filmpjesmastermoviesPMPThe Godfathas.avi

    E:l33c4 pr0t0c0l4ngrapige filmpjesmastermoviesPMPThe Matrix Retarded Mastermovies.avi

    E:l33c4 pr0t0c0l4ngrapige filmpjesmastermoviesPMPThermometer 4.avi

    E:l33c4 pr0t0c0l4ngrapige filmpjesmastermoviesPMPTitanic Mastermovies Stream.avi

    Mastermovies FTW :P

    I don't think that these scripts are really useful, since it will take ages to copy everything to your USB drive/external HDD. Maybe the USB/MP3 one could be done, if you'd buy one of those 4 gig cruzer micro's, that would take care of most of the problems :wink:

×
×
  • Create New...