here's a tip for yall... on windows systems 2k/nt/xp i found this nice tip in an israeli security mag with no name:
add ".{0003000D-0000-0000-C000-000000000046}" to any dir name, example: temp.000.{0003000D-0000-0000-C000-000000000046}
and it will show the file to be "temp.000" thru explorer browsing... and the icon will be of windows media player and it if the person tried to open the file by double clicking it, it will open it with windows media player (with no success)... the big downside is that all you need to do is right click and "explore" it ... and thru DOS it is easily viewable... but for those lazy admins its a nice perfect little trick... tip #2: you can take an existing temporary file or something and delete it, then rename your directory to the name and extension of the file and add the special line to it to make it look like its that file...
-GhostCow
ducky
Oct 31 2003, 04:19 PM
Nice tips thanks mate...May come in handy (sorry about my eng)
RELiC
Oct 31 2003, 08:58 PM
Heres something else also..you can Create a new dir called:
Control Panel.{21EC2020-3AEA-1069-A2DD-08002B30309D}
Now if the sysops opens it in windows he will think it's the CONTROL PANEL and it will even pop up the CONTROL PANEL if he clicks on it..
Other system folder code-names: Recycle Bin.{645FF040-5081-101B-9F08-00AA002F954E} Internet Explorer.{FBF23B42-E3F0-101B-8488-00AA003E56F8} Fonts.{BD84B380-8CA2-1069-AB1D-08000948F534}
etc..theres alot more file/folder types to choose from.. nice tip indeed thanks -GhostCow very cool info.
../
vnet576
Oct 31 2003, 09:13 PM
Very nice tip, never knew about this feature of windows.
liquidSilver
Oct 31 2003, 10:34 PM
How.....Awesome! Wicked, Ha! I think I will fool our sysadmin at school
-=[MePhIsTo]=-
Nov 1 2003, 11:51 AM
Works great
Big thx
mrfloppy
Nov 1 2003, 03:46 AM
here another one hide stuff in recycled folder access it via dos only way you can see see hidden dir/files
UNDERTAKER
Nov 1 2003, 10:32 AM
Great post people!!! 10x a lot!!!
limbox
Nov 3 2003, 09:18 AM
This works in Windows XP. I can't access the folders with my explorer. But you always see the brackets as well and that too obvious. Anyway - great trick
hermel
Nov 3 2003, 12:35 PM
THX for the good info
ghost_c
Nov 3 2003, 07:32 PM
hehe.... cool isn't it..
kenshin_efx
Nov 4 2003, 05:31 AM
Thankz man, is very nice tip.
10x for that info
manu
Nov 4 2003, 06:28 AM
M8,
I dont think ADMIN's are that Lazy and to be fooled..!! He he, Atleast they are "ADMIN" naaa?..!!
Anyway Thanks M8, You can't make everybody fools everytime, but you came make somebody fools in everytime..!!
Manu
VamPs
Nov 4 2003, 08:17 AM
in the fxp scene, people just store in /Recycler/ folder, as its invisible
lol had 4 terabyte on 1 chinese uni once
always works..
back in pub scene they use to do / / n com1 n prn invalid folders etc... but think thats only for nt4
nice to see some new tricks tho, tnx dude
beardednose
Nov 4 2003, 02:11 PM
Ghostcow, When you do this on a PC that you share with others (that don't have admin rights), make sure you add security to the folder under which the "fake" folder resides, as I couldn't add security to the fake folder itself.
That way, other users won't delete your precious folder accidentally.
And of course, don't all you folks use temp.00---be more creative than the example.
Nice tip.
beardednose
Nov 4 2003, 02:41 PM
After playing with this a bit more, I noticed that the fake folder (temp.00) appears in the left side of Windows Explorer, and if you double click on it on the LEFT side, it does open and reveal the files inside.
If you double click it when it's on the RIGHT side, it opens media player.
So this isn't as good as it seems originally. Of course, I'm open to the possibility that I goofed somewhere, but it doesn't appear that way, at least yet. Comments?
Mouhahaha
Nov 4 2003, 02:42 PM
veryyyy nice, really helpfulll very good job, i just wanted to ask how to rename the folder to a normal folder ?
boshcash
Nov 9 2003, 10:31 PM
nice one m8 , i wouldnt ever have known that , and it would help me to hide some executable stuff at server thnx
maxxis
Nov 10 2003, 02:05 AM
Create is new dir:
My Computer.{20D04FE0-3AEA-1069-A2D8-08002B30309D} My Documents.{ECF03A32-103D-11d2-854D-006008059367}
^RB^
Nov 10 2003, 11:51 AM
aha... Just what I needed...
Thanks for the new hiding tricks!!!!
RB
Mr_X
Nov 12 2003, 02:14 AM
I tried to create a control panel dir. It worked. But now it makes my real Control panel crashing even if it is deleted. What to do? I neither want to reinstall my windows neither reformat my hard disk. Help me plz
no1
Dec 3 2003, 09:26 PM
thx 4 this nice infos
saendler
Dec 3 2003, 09:29 PM
very nice thx
UltraCool
Dec 4 2003, 01:22 PM
gonna remind that, nice tip indeed m8
But it's also easy deletable..?
Uc
SLiM577
Dec 6 2003, 09:23 PM
well when i usually hide a directory i just make a bat file as such.
NET START VGN CD %SYSTEMROOT%\system32\setup attrib +S +H service CD %SYSTEMROOT%\system32\setup del x.exe
i usually attrib +S +H the folder i need to hide.
Hope this helps someone
hidden
Dec 7 2003, 01:27 AM
same for me attrib +s +h it's well
inconu
Dec 7 2003, 10:14 AM
I use "Hyena" .... and I see all hiden dirs ....
hi hi hi ....
trinity
Dec 20 2003, 12:22 PM
QUOTE (RELiC @ Oct 31 2003, 08:58 PM)
Heres something else also..you can Create a new dir called:
Control Panel.{21EC2020-3AEA-1069-A2DD-08002B30309D}
Now if the sysops opens it in windows he will think it's the CONTROL PANEL and it will even pop up the CONTROL PANEL if he clicks on it..
Other system folder code-names: Recycle Bin.{645FF040-5081-101B-9F08-00AA002F954E} Internet Explorer.{FBF23B42-E3F0-101B-8488-00AA003E56F8} Fonts.{BD84B380-8CA2-1069-AB1D-08000948F534}
etc..theres alot more file/folder types to choose from.. nice tip indeed thanks -GhostCow very cool info.
../
Using this trick in Windows 2000 I can't go inside the directory. Clicking on Explore or Open it will open the Control Panel, or Recycle bin, etc... Trinity
rush
Dec 31 2003, 05:36 PM
Do: Attrib +s +h +r dirname And you can make rights on dir with cacls.exe! try it out!
headbanger
Jan 1 2004, 07:28 AM
thanks dude, very helpful
headbanger
Jan 1 2004, 06:27 PM
cool i just tried it and it works great!
FiNaLBeTa
Jan 1 2004, 06:32 PM
here you have two more :
CODE
Control Panel.{21EC2020-3AEA-1069-A2DD-08002B30309D} Internet Explorer.{FBF23B42-E3F0-101B-8488-00AA003E56F8} Recycle Bin.{645FF040-5081-101B-9F08-00AA002F954E} My Computer.{20D04FE0-3AEA-1069-A2D8-08002B30309D} My Documents.{ECF03A32-103D-11d2-854D-006008059367} Fonts.{BD84B380-8CA2-1069-AB1D-08000948F534}
zero-maitimax
Jan 2 2004, 12:37 AM
ppl have read all the posting on this forum..
the attrib mode isn't usefull... i use windowscommander www.wincmd.com i can see every folder that is hidden (it's a option in wincmd you have the klick on it)
could somebody explain this for me:
QUOTE
add ".{0003000D-0000-0000-C000-000000000046}" to any dir name, example: temp.000.{0003000D-0000-0000-C000-000000000046}
how should i use this??
question no2. why do you put this behind the files? BD84B380-8CA2-1069-AB1D-08000948F534 what is it?
FiNaLBeTa
Jan 2 2004, 12:59 PM
QUOTE
could somebody explain this for me:
QUOTE
add ".{0003000D-0000-0000-C000-000000000046}" to any dir name, example: temp.000.{0003000D-0000-0000-C000-000000000046}
how should i use this??
No idea how i could explain this even more... it's there black on white, try on youre pc dude, it's not gonna crash it.
QUOTE
question no2. why do you put this behind the files? BD84B380-8CA2-1069-AB1D-08000948F534 what is it?
read dude, it's not : BD84B380-8CA2-1069-AB1D-08000948F534 it's : {BD84B380-8CA2-1069-AB1D-08000948F534}
and the reason is that for the admin that folder will look like a special windows folder. in this case fonts. when he click on it, he wont go in the dir, but windows will redirect him to the fonts windir.
beardednose
Jan 2 2004, 02:30 PM
Final, be nice. You were a noob once too, and I'm sure you missed something simple a couple times here and there.
zero, what it means is to type the info after the name of your directory. For example, it you want a directory called "sys" to hide files in, when you create your directory, name your directory
sys.{0003000D-0000-0000-C000-000000000046}
In other words, type all the info above when you name your directory.
I think Final answered your second question.
GhostCow
Jan 2 2004, 02:31 PM
but you will still be able to access that dir through dos, flashfxp, etc...
x1`
Jan 2 2004, 03:37 PM
thanks for this new method works great
zero-maitimax
Jan 2 2004, 07:53 PM
now i understand..
yeah sorry i'm still using win98 so... i was wondering what you ppl mean..
i have seen it on the xp machiene..
Blade
Jan 2 2004, 11:49 PM
cool thx 4 info
Cyrus
Jan 3 2004, 12:26 AM
QUOTE (GhostCow @ Jan 2 2004, 02:31 PM)
but you will still be able to access that dir through dos, flashfxp, etc...
yes, but the admin cant acess it with his explorer
Neo2k
Jan 3 2004, 01:25 PM
good tips anyway, thx
zero-maitimax
Jan 5 2004, 07:31 AM
QUOTE (|Cyrus| @ Jan 3 2004, 12:26 AM)
QUOTE (GhostCow @ Jan 2 2004, 02:31 PM)
but you will still be able to access that dir through dos, flashfxp, etc...
yes, but the admin cant acess it with his explorer
i think that good
i mean if you have a keylogger that logs stuff you can put the txt in does dirs and you are the only one that can read it in does.
normale system user or admin they will not go check every dir in dos it's to much work
GhostCow
Jan 5 2004, 03:38 PM
hence the term: lazy admin!
beardednose
Jan 5 2004, 08:05 PM
cyrus
QUOTE
yes, but the admin cant acess it with his explorer
I disagree. see my second post on page 2 of this thread. I was using w2k to test this.
zero-maitimax
Jan 6 2004, 07:47 AM
QUOTE (beardednose @ Jan 5 2004, 08:05 PM)
cyrus
QUOTE
yes, but the admin cant acess it with his explorer
I disagree. see my second post on page 2 of this thread. I was using w2k to test this.
i agree..
i'm using windows command and i'm getting in and out if it's a normale dir....
cha0s
Jan 6 2004, 11:48 AM
big thx
GhostCow
Jan 6 2004, 08:28 PM
there really is no reason for a sysadmin to start browsing in dirs like c:\winnt\system32\ras\ unless he finds something suspicous... what im trying to say is: people, hide files there dont run files from there. and use rootkits
macca
Jan 6 2004, 10:34 PM
system volume infomation
folder is my favourite place to start creating folders to hide files.... just hide files there, like your directories ect, dont run anything from there, it will stand out like a soar thumb on a 2 fingered elephant
ako
Jan 7 2004, 12:36 AM
gonna try this out thanks for the info
This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please click here.