Starlight
Apr 14 2004, 08:19 AM
hello, I search for the best keylogger than I can launch as system because the others which I use, when I disconnect myself from the session, it is not active no more but it is at that moment that I need it most thank you I hope that you understood all, my English is really not perfect
terrortbd
Apr 14 2004, 09:45 AM
i have something called sysmangr32.exe which logs to startup.log. allthough its upx'ed/hacked exe my virusscanner, Bitdefender, still detecs it as Backdoor.SDBot.Gen but maybe you could hack the exe around some more so it isnt detected
i dont think im allowed to post it here tho since i cant attach any files nor post it in the public download section ;(
maybe you can google for it.
remember that if servu (or any other ftp server/backdoor you may use) is started as SYSTEM and you execute something from it (with site exec for example) it'll get the same rights
cougar
Apr 14 2004, 10:10 AM
BPK Keylogger is the best, It's invisable and it runs as system service  try google, you'll find it.
Metathron
Apr 14 2004, 11:03 AM
hehe but is there any keylogger which don't log only passwords in the session , logs the Password of a Winlogon too ?
enemc
Apr 14 2004, 11:55 AM
hi mate... i use perfekt keylogger v1.44 .. it works fine, but iam not sure wether it loggs at startup when somebody is logging in with username and password... but why dont you decrypt the sam file?
Metathron
Apr 14 2004, 01:03 PM
thanks for answer i try it but LC4 found only the last letters of the password  and i used PWDump and a lot of other tools but nothing can decrypt the administrator password
rush
Apr 14 2004, 01:51 PM
rainbow tables? try with lc4 if you got the time better preferences with cracking!
bah
Apr 14 2004, 04:11 PM
| QUOTE (Metathron @ Apr 14 2004, 01:03 PM) | thanks for answer
i try it but LC4 found only the last letters of the password 
and i used PWDump and a lot of other tools but nothing can decrypt the administrator password |
I found similar problems with LC4, and actually using a diff character set solved it try using combo of letters nos and special characters option 3 in brute force attack for the character set usually finds everything and doesnt take that long. If u want to crack it faster I would use PROACTIVE WINDOWS SECURITY EXPLORER http://www.elcomsoft.com/pwsex.htmlI have found it a lot faster then LC4 and if u have large dictionaries it checks them in minutes compared to hours for LC4.
Starlight
Apr 14 2004, 05:27 PM
i tested to crack the sam file wive lc4, pwsex, and all the other that are in the "windows section" but nothing works, i have only the last number of the password but i dont have the 8 other caracters so would have the password whive the keylogger, i think it is the last solution, therefor must it be as system service because my trojan optix is shutdown when the persons are delogged and start only when the person is logged but à that moment is it to late ...
Daume
Apr 14 2004, 10:28 PM
i have what you need :-) a key logger which logs only the password and username, when you are prompted at logon ctrl alt del --> type password and username this key logger does this =) i_xplogger works both XP and 2k enjoy ps google finds it
tweakz20
Apr 14 2004, 10:48 PM
| QUOTE (Metathron @ Apr 14 2004, 11:03 AM) | hehe but is there any keylogger which don't log only passwords in the session , logs the Password of a Winlogon too ? |
don't really see how it works... ms only loads other programs AFTER logon...?.. anyone know any other way around (besides embedding it in startup files or something?)
EDIT- just checked out that i_xp whatever.. that goes "low level" into the keyboard drivers... not all that bad of an idea
Starlight
Apr 15 2004, 08:59 AM
it is just wath i need in fakts but it is an instalation, is there any possibility to upload all the files and to lunch it wich site exec ??? because otherwise i can't do anything whive that
Metathron
Apr 15 2004, 09:18 AM
| QUOTE (tweakz20 @ Apr 14 2004, 10:48 PM) | | QUOTE (Metathron @ Apr 14 2004, 11:03 AM) | hehe but is there any keylogger which don't log only passwords in the session , logs the Password of a Winlogon too ? |
don't really see how it works... ms only loads other programs AFTER logon...?.. anyone know any other way around (besides embedding it in startup files or something?)
EDIT- just checked out that i_xp whatever.. that goes "low level" into the keyboard drivers... not all that bad of an idea
|
dude ... sure i understand it so i asked if there is a keylogger which logs the passwords in Winlogon
and i found one but dont know if it works
WinlogonHiJack
www.rootkit.com
enemc
Apr 15 2004, 04:32 PM
hi again.. m8, someone posted a good tutorial for cracking nt pass with cain... try this tool if your're having problems with rainbow tables.. it works fine.. (and thx for the tutorial btw  ; i didnt want to make an 1-line posting in the other thread) http://www.governmentsecurity.org/forum/in...?showtopic=6377
oblivion2004
Apr 15 2004, 10:59 PM
Just use your current favorite keylogger combined with INSTSRV.EXE and install it as a service without any extra hassle
jimmy
Apr 16 2004, 04:18 AM
short tut on how to get admin passes use pwdump4 command : pwdump4 %computername% /o:hashes.txt don't like to use /l for local, it misses passes sometimes and not alway able to dump them download the hashes.txt open LC4 , change character set to the 3rd one. from menu , chose :Import from pwdump file and open the hashes.txt start the shit and wait  In the end LC4 always found passes, sometimes option 4 is needed, but this takes ages
Starlight
Apr 16 2004, 12:26 PM
i allready have don this and lc4 didn't find the password ...
it's there for that i would like to have a kaylogger as system
Dalas
Apr 18 2004, 05:10 AM
hey mates ,, its my first time i write something here all what i think that the SC keylogger is cool .. i used it soo far . it send to the email .. and you dont have to install it on the pc by ur own .. you make small server and send it to whoever you want .. and that will do his job google will help you to get it
g33k
Apr 18 2004, 12:32 PM
hi all,
Okey! lemme explain!
As i've coded a keylogger that'll catch the password at ctrl+alt+del WinLogon dialog. First, the Sequence is called Secure Attention Sequence and cannot be caught or stopped by any of the redirection and hooking mechanisms. (But there are ways to do it though!! ;-)) Because it is handled by the NTKernel. In NT/2000/XP systems, the keys are handled by device drivers at the lowest level. So, write a keyboardclass driver load it, interface it with a application controlling. That's all. Have a buffer and write the captured keystorkes after identifying them. They will be coming to you a scan codes. One nice keylogger for temporary use, that i'll suggest is the keylogger from www.mikkotech.com. But be careful, the versions which i've used about 3-4 years back have resulted in beautiful bluescreens, (that's when i started my own version) though i managed to install on lot of machines and camoflouge it as a video driver. Try it! you too can do it! I didn't document any steps so please do not ask me for it. I'll give some more info later.
greets!!
-==.^.!Live and Let Live!.^.==-
JDog45
Apr 19 2004, 05:41 AM
ever try RedHand?
This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please click here.
|