hacking contest

hacking exploits security forum
hacking
compliance articles
upgrade backup exec
information security consultant

Full Version: Yahooligan
illwill
yahooligan 1.0
Coded by illwill in Assembly
1/17/04

====================================================================
description:
jacks saved Yahoo! user/password from the registry
and sends them to a php script... works on win9x/me/nt/2k/xp/2k3
will not work if they didnt checkmark the 'save password'
feature when they sign on
====================================================================
features:
*only 8kb smile.gif
*sends user:pass to php script
*self-deletes after sending
*Bypasses any firewall
(sets the victims homepage as the url to your php script
then executes iexplorer.exe and after its sent it resets
the homepage back to the original page)

First:
1. u need to get a website that supports php
2. upload log.php and log.html to your website
3. chmod log.html to 666

CHMOD666 | Owner | Group | Public
----------------------------------
Read | x | x | x
Write | x | x | x
Execute | | |

Editor Instructions:
1. extract the server.exe and Editor.exe to a folder
2. enter the URL to your php script
3. save the new exe
4. send the exe to your victims
5. check the log.html for the gathered info i.e. http://blah.com/log.html
(note: if the password looks garbled that means the password wasnt set)
Faceless Master
~Nice-For php support one can use jc-hosting.co.uk
Regards
~Faceless Master
illwill
guess nobody likes hacking yahoo as much as hotmail biggrin.gif
Yorn
Naw, it's a good tool, but I'd be interested in a tool that just ouput the username and the pass for Yahoo, AIM, MSN, etc. even if all it got was hashes that'd be cool. Right now I'm using my own utility that is about 82kb uncompressed made with FBSL and pulling crap out of the registry.

If there was program that I could just run:

"hooligan.exe > save.txt"

That would be something I could use. Just have it pop all sorts of registry keys and such in there. Like the following options:

hooligan.exe by illmob
Arguments list:
-g Pull CDkeys from known games (Half-Life, Quake3, Unreal)
-im Pull user/pass from known instant messangers (MSN, AIM, Yahoo)
-w Pull user/pass from web cache (Hotmail, Yahoo Mail, etc.)

That, IMHO, would be nice. Of course, I've already coded one for myself that pulls what I need, but I bet you can get it under 10kb you friggen ASM kook. smile.gif
KarachiKing555
Thx ILL for this usefull progie ! and thinking about your Cams2cam prog u made dono if this is right name i heard about it while ago i forgot but u got it wink.gif by now wats up about it is tthet project up.

man prog like holigan is reall good any progs out there like this one ! or source may be !!
boshcash
u must make one to solve the msn 6 messenger problem , we need to get the messenger 6 pass which is alot more common than the yahoo one , the only prog i got that deals with recovering msn 6 pass is AIMPR , plz illwill try to make a program to get the msn 6 pass , second thing , posting the pass to php file is not really a good idea like sending to mail , using hotmail mailserver , so everybody makes a hotmail account and recieves passes instead of putting a php page and opening the site to see recieved passwords (someone may be able to send a fake pass to abuse the script) ..
illwill
ill prolly work on a msn one soon... the problem with getting protective storage passwords ( mail , Internet Explorer pages ) is that in coding they use COM calls to the dlls... well COM in ASM is a (filtered) bitch.. thats why yahooligan uses a C++ dll as a resource to do the COM calls for me .. im currently working with someone making a program to get those IE passes from protective storage... i prolly could have it easily send the reg info to somewhere then use another app to decode that info... that would make the app very small in size since it doesnt need the code in the server to do all the work except doing the recon for the info
This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please click here.

 
Invision Power Board © 2001-2005 Invision Power Services, Inc.