hacking contest

hacking exploits security forum
hacking
compliance articles
upgrade backup exec
information security consultant

Pages: 1, 2, 3, 4, 5
flashb4ck
thanx mate 4 your n!ce t00l i'll test it wink.gif


gr€€tz fl4Shb4Ck
extreme
Common Mods.. These "Thanks"es are really anoying.. I got 30 reply notifications per day in my email and 90% of these are "thank you" or "I will check it"... It's just so much waste of time to click on link every time just to see these same old messages.
Reaper527
QUOTE (extreme @ Jan 28 2004, 04:12 PM)
Common Mods.. These "Thanks"es are really anoying.. I got 30 reply notifications per day in my email and 90% of these are "thank you" or "I will check it"... It's just so much waste of time to click on link every time just to see these same old messages.

then turn email notification by default off in your user cp. i personally think thanking the author for an excellent tool is more important then you getting spammed out because you won't change your settings.
shiz
QUOTE

I got 30 reply notifications per day in my email and 90% of these are "thank you" or "I will check it".

turn off in your settings man, instead of bitchin..

and abouit the tool:
peep beenal's post....
:-(
MaNiakS
sad.gif
i run rAdMiN [nOpAsS] iP cHeCkEr bY_VIXVVXIV.exe
but the aplication say : Component "Msinet.ocx" or one of its dependicies not correctly registred : a file is mising or invalid
What means that? can anyone help me?

i have Windows 2000

thx you! blink.gif
Reaper527
do you have any plans to release the source? i would like to attempt to add in a dictionary attack option to guess some of the non-blank passwords.
LittleHacker
MaNiakS Posted on Jan 30 2004, 01:31 PM
QUOTE
 
i run rAdMiN [nOpAsS] iP cHeCkEr bY_VIXVVXIV.exe
but the aplication say : Component "Msinet.ocx" or one of its dependicies not correctly registred : a file is mising or invalid
What means that? can anyone help me?

i have Windows 2000

thx you! 


Download "Msinet.ocx" and put it in the same place of rAdMiN [nOpAsS] iP cHeCkEr bY_VIXVVXIV.exe or copy it to %Sys32dir% (for example c:\winnt\system32) and then register it using regsvr.exe
nuttieator
rAdMiN [nOpAsS] iP cHeCkEr bY_VIXVVXIV.exe



yep cool little app mate

use it myself
n0|_0g
VIXVVXIV sollten wir das nicht crew intern halten? rolleyes.gif
LittleHacker
Please Speak in English
nuttieator
does anyone know of a way of securing radmin after they are rooted. Cos it sux that some 1 can just steal them very easy..
Reaper527
well, you could always change the radmin password, it may catch the sysadmin's attention so it isn't necessarly a good way to secure it, but its the only way i know of.
MaNiakS
i think another way is to stop Radmin to run..
or maybe when you roted to instal another remote ..

..
mofo
To the author of the program,
Thank You SO much! This saves hours of time, If you need help with any coding for new versions PM me. I can also host any of the files on a nice 35mbit as well!
mofo
i cant login to the program anymore. what happened?
staticlycharged
WOW VIXVVXIV, nice program, i have to say i really love it, im not so fond of your newest version because i cant scan ranges sad.gif but its cool. Perhaps u can scan ranges and im just blind/dumb? eh, anyways, i was thinking, Perhaps you could code a RADMIN password scanner that will either give a Password/No password response? instead of "is this radmin" granted, i have no idea how your program works, or how it sends a request to connect ect, but i was just thinking that would be nice. As would a CMD line version that gave you password/no password smile.gif i would freaking love that. Keep me updated smile.gif you are welcome to PM me anytime
Thanks in advance VIXVVXIV smile.gif nice work
Reaper527
QUOTE (staticlycharged @ Feb 7 2004, 06:58 AM)
WOW VIXVVXIV, nice program, i have to say i really love it, im not so fond of your newest version because i cant scan ranges sad.gif but its cool. Perhaps u can scan ranges and im just blind/dumb? eh, anyways, i was thinking, Perhaps you could code a RADMIN password scanner that will either give a Password/No password response? instead of "is this radmin" granted, i have no idea how your program works, or how it sends a request to connect ect, but i was just thinking that would be nice. As would a CMD line version that gave you password/no password smile.gif i would freaking love that. Keep me updated smile.gif you are welcome to PM me anytime
Thanks in advance VIXVVXIV smile.gif nice work

well, as far as the password goes it does what your asking.

is this radmin.txt = port's listening but its not an Radmin server
radmin with password.txt = radmin server running, but has a password protecting
radmin with no password.txt = radmin server running, no password on it.
mehouse
Thanks VIXVVXIV

All working very fine biggrin.gif
Perhaps you can help me with some
Is there a possibility for dictonary possible with
AET2
I think i need to know the (RIGHT) variables (sequence and so on) huh.gif
Been busy with the request codes of radmin *iris* sad.gif
(you know already i asume) wink.gif

thanks in advance
Mehouse

)))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))
ExAmpLe from the netbus variable !!

Version=AET2
Target=
Port=12345
UseUserID=0
userprompt=
passprompt=
RespString=
HTTPRequestType=HEAD
HTTPFormFields1=login
HTTPFormFields2=password
HTTPFormFields3=
HTTPFormFields4=
HTTPFormFields5=
HTTPFormFields6=
HTTPFormFields7=
HTTPFormFields8=
HTTPFormFields9=
HTTPFormFields10=
HTTPFormFields11=
HTTPFormFields12=
HTTPFormFields13=
HTTPFormFields14=
HTTPFormFields15=
HTTPFormFields16=
useHTTPKeepAlive=1
posResponse=0
IsTelnet=0
IsHTTP=0
IsSMB=0
maPrimaryResponseIsPositive=1
maSecondaryResponseIsPositive=0
maPrimaryResponseAction=13
maSecondaryResponseAction=0
maUserPrefix=""
maUserPostfix=""
maPassPrefix="Password;0;"
maPassPostfix=""
maUsePreAuth=0
maMaxAuthsConx=0
maauthStageStrings1=""
maauthReadLength1=1
maauthSendPostfix1=None
maauthStageStrings2=""
maauthReadLength2=1
maauthSendPostfix2=None
maauthStageStrings3=""
maauthReadLength3=1
maauthSendPostfix3=None
maauthStageStrings4=""
maauthReadLength4=1
maauthSendPostfix4=None
maauthStageStrings5=""
maauthReadLength5=1
maauthSendPostfix5=None
maauthStageStrings6=""
maauthReadLength6=1
maauthSendPostfix6=None
maauthStageStrings7=""
maauthReadLength7=1
maauthSendPostfix7=None
maauthStageStrings8=""
maauthReadLength8=1
maauthSendPostfix8=None
maauthStageStrings9=""
maauthReadLength9=1
maauthSendPostfix9=None
maauthStageStrings10=""
maauthReadLength10=1
maauthSendPostfix10=None
maauthStageStrings11=""
maauthReadLength11=1
maauthSendPostfix11=None
maauthStageStrings12="netbus"
maauthReadLength12=1
maauthSendPostfix12=None
maauthStageStrings13=""
maauthReadLength13=1
maauthSendPostfix13=CR+LF
maauthStageStrings14="Access;1"
maauthReadLength14=1
maauthSendPostfix14=None
maauthStageStrings15=""
maauthReadLength15=1
maauthSendPostfix15=None
maauthStageStrings16=""
maauthReadLength16=1
maauthSendPostfix16=None

paskaluis
thx a lot
Mik3yZ
great tools you made here m8! gonna check if they still work smile.gif
schnulli
can somebody program a scanner, who check especially ips from a .txt file...

dsns cans scan open port 4899 very fast and you can it save as a txt file...its very faster then the "normal" scanner
Gangster*
I seem to get an '9 Error' using the ip checker. What have i done wrong?
PL3X59
what can i do whit this scanner ??

o i see, radmin is a tool like VNC smile.gif

GREAT smile.gif smile.gifsmile.gif

Thx Man smile.gif
tte
it really works good man..
but I got a little problem.
it reaches the 25 sockets and stops there.
sometimes maybe 30 but not anymore and its slow ;[
can someone help me with that?
tianzhen
a dict for week password scan will be nice biggrin.gif
g33k
Thanx a lot! gr8 work! cool.gif
TeleTobi
thx 4 this nice tool!
I´ll try it. I hope you will release a dic version soon...
netpirate
great work.. been using ur first one for some time.. but got kinda irritating that u had to copy/past 1 and 1 ip at the time to check.. so i REALLY like this new one:) mad props ! biggrin.gif
kNarpH
nmap -iR -p 4899 > radmin.txt

scans random ip´s and dumps to txt........scanning forever =]
using "-sL iplist" instead of -iR scans a given iplist....
inferno-gwc
Thanks for sharing this nice app VIXVVXIV
Chuckey
Great toolk man thanks for sharing

Natas ph34r.gif
iWeasel410
great tool! it's a rather interesting alternative to just scanning for the open radmin port. maybe you could implement weak pass scanning or dictionary scanning in the near future? excellent!
rvd
Great work on this one your first version was also good but the last 2 where even great smile.gif


I haven't found any bugs so fare... Great work again smile.gif
kNarpH
Nice Work........
with list scanning even nicer =]
Kralle
JEAAA!

Great work VIXVVXIV. Thx for this sweet Tool smile.gif
Killaloop
Well I don't know why you put your tool on a server we have to connect to use it ... and after we connected the connection to the server still IS established. Normally the connection should be closed after password validation.
could it be that you steal people scanresults?
it looks like that to me

sorry if I'm wrong, but If I'm wrong you should rewrite the prog that the connection to your server gets closed after validation....still something strange there
shite
hmm..
hes right about that ..

how very sad
EviL
10x VIXVVXIV!!!
BRNick15
someone has the radmin scanna mirc addon/bot?
shite
al versions are infected with the Pe.spaces virus
Wiz4rd
Every version I have seen kav picks up as a virus so I stay clear.
Killaloop
yep this tools opens up listening ports just take alook on your machine what happens when you start the program up
as a few posts earlier I have said that something here is strange, but people don't read.
Also looks like mods are busy since I have informed them a few days ago about that problem.
PLEASE take care people unless the autor of this stuff answers to this.
mods lock this topic or whatever 12000 views here and how many downloads?
DON'T use this app!
(/me thinks noone listens?)
Anarchiste
Great Tool i will test it smile.gif
wizy
I wrote a perl/bash solution. It doesnt check passwords, but it scans for radmin existing.

Ill post it here. Usage is pretty simple. Put radmin.pl and radmin.sh in the same directory. Then run ./radmin.sh FILE SAVEFILE PORT
file is a list of ips, SAVEFILE is the file to output the good ips (ones with radmin on PORT), and port is whatever port you think the radmin is on, like:
./radmin.sh ip-list good-list 4899

Again, this doesnt check passwords. But if anyone wants to add that, go right ahead.
wizy
radmin.pl
CODE

#!/usr/bin/perl
# wizy/kn

use IO::Socket;
use POSIX;

$|=1;

#configurable
my $connect_alarm_time = 2;
my $recv_alarm_time = 3;
my $laddr = "63.209.253.166";
my $rcv="01 00 00 00 25 08 00 01 10 08 01 00 08 08 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00";
my $send="01 00 00 00 01 00 00 00 08 08";

#nothing else configurable
my $raddr = $ARGV[0];
my $rport = $ARGV[1];

local $SIG{ALRM} = sub {exit();};

sub check_recv {
my ($data)=@_;
my $x=0;
foreach (split(/ /,$rcv)) {
 my $valid_c=$_;
 my $test_c=sprintf("%02x", ord(substr($data,$x,1)));
 $x++;
 if ($valid_c eq $test_c) { next; } else { exit(); }
}
return 1;
}

sub recv_len  {
my $x=0;
foreach (split(/ /,$rcv)) {
 $x++;
}
return($x);
}

sub send_str {
my $send_str="";
foreach (split(/ /,$send)) {
 $send_str.=chr(hex($_));
}
return($send_str);
}

if (!$raddr || !$rport) {
print "usage: $0 raddr rport\n";
exit();
}

alarm($connect_alarm_time);
my $sock = IO::Socket::INET->new(Proto=>"tcp", PeerAddr=>$raddr, LocalAddr=>$laddr, PeerPort=>$rport);
alarm(0);
if ($sock) {
my $data="";
send($sock,send_str(),0);
alarm($recv_alarm_time);
recv($sock,$data,recv_len(),0);
alarm(0);
if (check_recv($data)) {
 print "$raddr\n";
}
}
wizy
radmin.sh
CODE

#!/bin/sh
# -wizy

exec 2>/dev/null
s=$(date +%s)
READFILE=$1
SAVEFILE=$2
touch $SAVEFILE
THEPORT=$3
i=0
TOSCAN=`cat $READFILE |wc -l`
TEMP_FILE=/tmp/files.$$
cat $READFILE > $TEMP_FILE 2> /dev/null
while read feh; do
GOODSOFAR=`cat $SAVEFILE | sort -u | wc -l`
       i=`expr $i + 1`
       echo -en "\033[K"
       echo -en "\033;Radmin Scanning: $i/$TOSCAN  IP: $feh   Good: $GOODSOFAR"
       echo -en "\033[80D"
./radmin.pl "$feh" $THEPORT 2>/dev/null >>$SAVEFILE
done < $TEMP_FILE
rm $TEMP_FILE > /dev/null 2> /dev/null
TOTALGOOD=`cat $SAVEFILE | sort -u | wc -l`
echo ""
echo "GOOD: $TOTALGOOD"
echo "Took $(($(date +%s) - $s)) seconds to run."

L0rD
First THX THX for all tjis checker smile.gif

But, is there a PASSWORD checker ? Bcs, i have a lot of radmin with pass :s

If someone get one, i will be so happy lol smile.gif

+++ tongue.gif
JMP
Hello smile.gif I like this tool, nice job VIXVVXIV wink.gif

About getting the password. As someone said earlier, you can either brute force it, or use a wordlist. The password is very likely 8 characters long, and that will take really really long to crack. Maybe even years if you include the whole keyboard + uppercase. The only way is to be very lucky with a wordlist. I use one myself that is about 1000 word-pages long.
wizy
If anyone has knowledge of password checking in this (the method used to generate the md5 hash and the twofish keys), and possibly the actuall packet dumps to show what and when to send. It would be nice to see. I could possibly get it working in my scripts.

L0rD
Thx men, but where can i find a prog for brute forcing ? Or what one do you use ?

biggrin.gif
This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please click here.

 
Invision Power Board © 2001-2005 Invision Power Services, Inc.