Showing posts with label crack. Show all posts
Showing posts with label crack. Show all posts

How to Solve the Crackme Challenge (A Small Reverse Engineering Puzzle)

Welcome back my fellow hackers! Recently, I’ve been delving into the incredibly interesting world of reverse engineering! I hope to  write more about this topic some time in the future, but for now we’ll just start with something simple. I took a few days and made a small reverse engineering challenge. Today, we’re going to go through this challenge and solve it with all 3 intended solutions (if you can find more, leave them in the comments!).
We’ll start with downloading and compiling the challenge, then we’ll start solving it. Our first solution will be a buffer overflow vulnerability intentionally coded into the challenge, then we’ll hunt down and execute a secret function to solve the challenge, and finally we’ll execute the program instruction to instruction until we can read the solution straight out of the computers memory! Now that we know what we’ll be doing, let’s get started!

Downloading and Compiling the Challenge

First, we need to download and compile the code of our challenge. Let’s download the challenge code from pastebin using the curl command:
We’ve written the code to a file named crackme.c. Now that we have our code, we need to compile it. We’ll be using the GCC (GNU Compiler Collection) to compile our code. Pay close attention to the flags used when compiling our code, as they are important to the challenge functioning properly:
You may get a warning out of the compiler but don’t fret, the code will still work (this warning is related to the buffer overflow vulnerability, which is intentional). Let’s test our executable just to make sure it works:
Now that we have our code compiled and working, we can start cracking this challenge! We’ll start with the buffer overflow vulnerability.

Cracking the Challenge

Solution 1: Buffer Overflow

Buffer overflows are very common vulnerabilities. A “buffer” is simply an area of memory designated for storing data to be processed or used in processing. If we can fill a buffer with more data than it can handle, we “overflow” it, and can then store data in areas of memory where we shouldn’t be able to. This can lead to code execution, which is how a lot of buffer overflow exploits work. But, in our case, we’ll be overflowing a buffer simply to change the value of the data being held in another.
Let’s perform this attack, and then we’ll take a look at the code that makes this possible:
We can see here that by entering a large amount of text, we can successfully login even when this is obviously not the correct password. Now that we’ve exploited our buffer overflow, let’s take a look at the code that made this happen:
We can see here that we make a character array that holds 30 characters. So, if we input more than 30 characters, that will overflow this buffer, which will change the value of the “valid” integer. This integer is then evaluated later in the program and, since the overflow changed it to a non-zero number, it equates to true and logs in without a problem. Next up, we’ll be hunting for a hidden function in our program!

Solution 2: Using the Hidden Function

If you read the code of our challenge, you’ll that there is a function named “secret.” This function is never used, yet it still exists. If we can force this function to execute somehow, we could get the password we need. Well we have just the tools to do that! First, we need to use a tool called objdump (object dump) to disassemble our executable into assembly. Then we’ll be able to see where our secret function is:
Now that we have our new assembly code in a text file, we can sift through it until we find our secret function. It should be just above the main function, and looks something like this:
Now, don’t panic, this looks way more complicated than it is. The only part of this assembly we need to pay attention to is the string of characters next to the word “secret.” Specifically, we need to remember the last 7 characters, as this is the entry address for this function. Now that we have this 7 character string, let’s start our program in GDB and do some magic:
No need to pay attention to this large chunk of text, it’s mostly just information about GDB. But here’s the important part: when GDB starts up, we need to use the start command in order to start our program. Now, remember that 7 character string? This is where we’ll be using it. If we can change where the instruction pointer is pointing, we can force it to execute our secret function. Luckily for us, GDB allows us to do just that:
We need to precede our string with a “0x” as this specifies it as a memory address. Now that we’ve wrapped up this solution, on to the next, reading the password out of memory!

Solution 3: Reading the Password out of Memory

SIDE NOTE: For this solution to work you may want to re-compile the program with the -m32 flag to compile a 32-bit version of it.
Our final solution is the most complicated. When we enter a password into the program, it needs to be stored in memory so it can be evaluated later. If we can catch it while it’s stored in memory, we can read it! We can also use GDB for this. So, let’s start up GDB again:
I’ve cut out the large chunk of text shown by GDB for the sake of organization. Now, we need to start the program with the start command. Once we do, we display current number of the EAX register. This is the register that our password will be in once we enter it. After we display the current contents of EAX, we use the ni command (next instruction) to move on to the next instruction in the program.
As you can see by the output above, once we used the ni command, it displayed the value of EAX again. We can use this to tell when the value in EAX changes, if the number changes, the contents changed. Now we just need to repeatedly press return to re-execute the ni command and step through our program. Once we reach the prompt for a password, enter something random:
We can see that a few instructions after we entered an incorrect password, the value of EAX changed. Now we can use x/s to read the contents of EAX as a string which, in this case, is the correct password to our program!

This concludes our small reverse engineering article. I’d like write more about this in the future, but since I’m still learning myself, we’ll have to save it for another time. Just know that this idea is on the back-burner for now!
Share:

Internet Download Manager [IDM] v6.11 Build 8 + Crack

Internet Download Manager (IDM) has a smart download logic accelerator that
features intelligent dynamic file segmentation and safe multipart downloading
technology to accelerate your downloads. IDM increases download speeds by up to
5 times, resumes and schedules downloads. Comprehensive error recovery and resume
capability will restart broken or interrupted downloads due to lost connections,
network problems, computer shutdowns, or unexpected power outages. Simple graphic
user interface makes IDM user friendly and easy to use. IDM has a smart download
logic accelerator that features intelligent dynamic file segmentation and safe
multipart downloading technology to accelerate your downloads. Unlike other
download managers and accelerators, IDM segments downloaded files dynamically
during download process and reuses available connections without additional
connect and login stages to achieve best acceleration performance.

https://rapidshare.com/files/954765364/IDM.6.11.8.rar http://ifile.it/sbek0mq

http://rapidgator.net/file/16884893/IDM.6.11.8.rar.html

http://www.filefactory.com/file/uplw9uadblt/n/IDM.6.11.8.rar

Share:

Remove Password Protect From WinRAR Files [Excluzive]

WinRAR

I tested this and works fine, If you want to test it - Process with below steps Grin


Step 01:

Go to OnlineConvert Website

Step 02:

Then you can upload form like below picture

[Image: 15pigsh.png]

Upload your password protected WinRAR file to it

Step 03:

Wait some seconds and You will redirect to new page there is message like this

[Image: vgmrt3.png]

Step 04:

Click on download link and Download your new RAR file

Enjoy Bye
Don't forget add your feedback
Share:

How to download from Sharecash without doing surveys

Downloading from Sharecash might be a nightmare due to their surveys. A new version of the bypasser is online to skip them all!

If you have ever searched on the web things like game cheats, hacks, useful tools, guides and similar, it is likely you faced a screen like the one showed above.
Essence is that you are required to complete a survey to unlock the download.
I hate to generalize, I have nothing against Sharecash uploaders, but issues are numbered:
  • many surveys are paid surveys, like mobile subscriptions etc...
  • free surveys are few and end up not locking the file
  • not all countries are covered with at least 1 survey, so file will never unlock for you if you connect from any of those unlucky Countries

Chances are that:
a. you purchase a Premium Account to download bypassing the surveys.
This is the "legal" way, if you like.
To do this, you just need to click on a random Sharecash file, close the survey window and proceed to the purchase of the relevant package.

b. you use a Sharecash Bypasser tool
I found many on the net so far. The latest that worked for me is available for download HERE.
Good thing with this is that there is no survey associated with this download, it's a mediafire link with an encrypted archive, but password is in clear in the enclosed PDF file and tool is usable for free.

Make sure you read the instructions on the PDF FULLY, or the tool won't work.

There is also a Virus Total Scan Report which shows how the tool is 100% safe.

This Article is by
Share:

IDM PATCHER WORKING WITH ALL VERSIONS

Friends this is one of the best share i have done.Kindly download it from HERE.
Kindly use it for every version of IDM.Register with it and enjoy.
Share:

How To Crack Simple MD5


 How To Crack Simple MD5 | Ethical Hacking Tutorials

 In this tutorial, I will teach you how to crack simple MD5. MD5 is hash value which has been employed in a wide variety of security applications nowdays. In global net, we can simplify MD5 decrypter and generate MD5 Hash in online. What is MD5? You can find more information of MD5 in Wikipedia.



MD5 (Message-Digest algorithm 5) is a widely used cryptographic hash function with a 128-bit (16-byte) hash value. Specified in RFC 1321, MD5 has been employed in a wide variety of security applications, and is also commonly used to check the integrity of files. However, it has been shown that MD5 is not collision resistant as such, MD5 is not suitable for applications like SSL certificates or digital signatures that rely on this property. An MD5 hash is typically expressed as a 32-digit hexadecimal number. MD5 was designed by Ron Rivest in 1991 to replace an earlier hash function, MD4. In 1996, a flaw was found with the design of MD5. While it was not a clearly fatal weakness, cryptographers began recommending the use of other algorithms, such as SHA-1 (which has since been found also to be vulnerable). In 2004, more serious flaws were discovered, making further use of the algorithm for security purposes questionable; specifically, a group of researchers described how to create a pair of files that share the same MD5 checksum. Further advances were made in breaking MD5 in 2005, 2006, and 2007. In an attack on MD5 published in December 2008, a group of researchers used this technique to fake SSL certificate validity. US-CERT of the U. S. Department of Homeland Security said MD5 "should be considered cryptographically broken and unsuitable for further use,"and most U.S. government applications will be required to move to the SHA-2 family of hash functions after 2010.


Let's start our tutorial. How To Crack Simple MD5,

 #!/usr/bin/perl
$ver = "01";
$dbgtmr = "1"; #Intervall of showing the current speed + lastpassword in seconds.

if ($dbgtmr<=0){ die "Set dbgtmr to a value >=1 !\n";};
use Digest::MD5 qw(md5_hex);
use Time::HiRes qw(gettimeofday);

if ($ARGV[0]=~"a") {
$alpha = "abcdefghijklmnopqrstuvwxyz";}
if ($ARGV[0]=~"A") {
$alpha = $alpha. "ABCDEFGHIJKLMNOPQRSTUVWXYZ";}
if ($ARGV[0]=~"d") {
$alpha = $alpha."1234567890";}
if ($ARGV[0]=~"x") {
$alpha = $alpha. "!\"\$%&/()=?-.:\\*'-_:.;,";}

if ($alpha eq "" or $ARGV[3] eq "") {usage();};
if (length($ARGV[3]) != 32) { die "Sorry but it seems that the MD5 is not valid!\n";};

print "Selected charset for attack: '$alpha\'\n";
print "Going to Crack '$ARGV[3]'...\n";

for (my $t=$ARGV ;$t<=$ARGV[2];$t++){
crack ($t);
}

sub usage{
print "\n\nMD5 Hash Bruteforce Kit v_$ver\n";
print "by unix_chro alias backtrack (311733@yahoo.com)\n";
print "Member in staff leader:elite-members,ubuntu-
hackers\n\n";
print "USAGE\n";
print "./md5crack <charset> <mincount> <maxcount> <yourMD5>\n";
print " Charset can be: [aAdx]\n";
print " a = {'a','b','c',...}\n";
print " A = {'A','B','C',...}\n";
print " d = {'1','2','3',...}\n";
print " x = {'!','\"',' ',...}\n";
print "EXAMPLE FOR CRACKING A MD5 HASH\n";
print "./md5crack.pl ad 1 3 900150983cd24fb0d6963f7d28e17f72\n";
print " This example tries to crack the given MD5 with all lowercase Alphas and all digits.\n";
print " MD5 Kit only tries combinations with a length from 1 and 3 characters.\n-------\n";
print "./md5crack.pl aA 3 3 900150983cd24fb0d6963f7d28e17f72\n";
print " This example tries to crack the given MD5 with all lowercase Alphas and all uppercase Alphas.\n";
print " MD5 Kit only tries passwords which length is exactly 3 characters.\n-------\n";
print "./md5crack.pl aAdx 1 10 900150983cd24fb0d6963f7d28e17f72\n";
print " This example tries to crack the given MD5 with nearly every character.\n";
print " MD5 Kit only tries combinations with a length from 1 to 10 characters.\n";
die "Quitting...\n";
}

sub crack{
$CharSet = shift;
@RawString = ();
for (my $i =0;$i<$CharSet;$i++){ $RawString = 0;}
$Start = gettimeofday();
do{
 for (my $i =0;$i<$CharSet;$i++){
  if ($RawString[$i] > length($alpha)-1){
   if ($i==$CharSet-1){
   print "Bruteforcing done with $CharSet Chars. No Results.\n";
   $cnt=0;
   return false;
  }
  $RawString[$i+1]++;
  $RawString[$i]=0;
  }
 }
##################################################  #
  $ret = "";
  for (my $i =0;$i<$CharSet;$i++){ $ret = $ret . substr($alpha,$RawString[$i],1);}
  $hash = md5_hex($ret);
  $cnt++;
  $Stop = gettimeofday();
  if ($Stop-$Start>$dbgtmr){
   $cnt = int($cnt/$dbgtmr);
   print "$cnt hashes\\second.\tLast Pass '$ret\'\n";
   $cnt=0;
   $Start = gettimeofday();
  }
           print "$ARGV[3] != $hash ($ret)\n";
  if ($ARGV[3] eq $hash){
   die "\n**** Password Cracked! => $ret\n";
  }
##################################################  #
 #checkhash($CharSet)."\n";

 $RawString[0]++;
}while($RawString[$CharSet-1]<length($alpha));
}

sub checkhash{
$CharSet = shift;
$ret = "";
for (my $i =0;$i<$CharSet;$i++){ $ret = $ret . substr($alpha,$RawString[$i],1);}
$hash = md5_hex($ret);
$cnt++;
$Stop = gettimeofday();
if ($Stop-$Start>$dbgtmr){
 $cnt = int($cnt/$dbgtmr);
 print "$cnt hashes\\second.\tLast Pass '$ret\'\n";
 $cnt=0;
 $Start = gettimeofday();
}

if ($ARGV[3] eq $hash){
 die "\n**** Password Cracked! => $ret\n";
}

}



save it as *.pl
How to use ? Easy.
-Install perl language console, then run.
- c:\> perl -script.pl
Share:

Widestep Elite Keylogger v4.8 [Full] [Free] [Crack]



A smart and powerful low-core (driver-mode) Keylogger engine!

Elite Keylogger is a small and powerful keylogger application.

Elite Keylogger is the best selling surveillance software for monitoring and recording every detail of PC and Internet activity everywhere: in your home or in your office.

Elite Keylogger includes several integrated stealth modules that record: chats, instant messages, emails, websites visited, absolutely all keystrokes, each and every program launched, all passwords and even Windows logon password, usernames and time they worked on your computer, desktop activity, clipboard and more.

Elite Keylogger is your only complete privacy fortress that will protect your PC and inform you about every keystroke made.Elite Keylogger provides the equivalent of a digital surveillance history so that you can see exactly what your family members, neighbours, employees or other users are doing on the computer.

Elite Keylogger works absolutely secretly saving all the recordings in a hidden location only you know about, all the logs are encrypted and cannot be viewed by anyone but you. 



KEY FEATURES:
==============

















DOWNLOAD


http://www.fileserve.com/file/Pth9fuq/ek_v4.8.210_plus_manual_and_serialwww.warez-town.info.rar 
Share:

DISCLAIMER

The information provided on hottechtips.blogspot.com is to be used for educational purposes only. The website creator is in no way responsible for any misuse of the information provided. All of the information in this website is meant to help the reader develop a hacker defense attitude in order to prevent the attacks discussed. In no way should you use the information to cause any kind of damage directly or indirectly. The word “Hack” or “Hacking” on hottechtips.blogspot.com should be regarded as “Ethical Hack” or “Ethical hacking” respectively. You implement the information given at your own risk.