1

(11 replies, posted in Thoughts)

Please read this post for the c# program I wrote for ms10-046 spreading.
By using the link I have mentioned the above post.

http://forum.vxheavens.com/viewtopic.php?id=1405.

2

(0 replies, posted in Thoughts)

Hi Guys,
Please check this program and give comments .
Original source is from :
[Register or log in to view the URL]

after compiling, you can use it as follows:
- ms10046spreader.exe <driver Letter>
eg: ms10046spreader.exe G

it will create links which is  pointed to the DLL in I-Z drivers. (15 ".lnk" files)


please read the comments in the program

3

(11 replies, posted in Thoughts)

Guys give me some comments about this.

regarding the MS10-046 and the drive letter thing.

what if I create links which points to the DLL with different paths that covers 10 drive letters in the usb drive .

eg:
if the usb driver letter is "I" ill create different links as below.

a.lnk => e:\ms10-046.dll
b.lnk => f:\ms10-046.dll
c.lnk => g:\ms10-046.dll .

then the probability of triggering the DLL will be high

4

(11 replies, posted in Thoughts)

here is the CPP I downloaded. You can use the MSF to create a dll and use it .

5

(11 replies, posted in Thoughts)

I have found this link.
May be this will help.

[Register or log in to view the URL]

this contains a C++ code for the MS10-046.

6

(11 replies, posted in Thoughts)

LNK (ms10-046) will not work properly because the dll path. (Driver letter)
eg: if I make the lnk link to the i:\ foo.dll, the particular driver's letter will be changed in another machine.

So LNK is not good I think.

7

(2 replies, posted in Thoughts)

I'm developing a worm.
I need to spread it through the LAN.
PC in the LAN are Windows XP SP2.
and password protected.
Please suggest me any Ideas you guys have..
Thank you.

8

(10 replies, posted in Newbie)

I'm developing a worm.

I need to spread it through the LAN.
PC in the LAN are Windows XP SP2.

and password protected.
Please suggest me any Ideas you guys have..

Thank you.

9

(0 replies, posted in Newbie)

I have successfully used the MS08-67 in metasploit with windows/adduser payload.

Now,

I need to create an exe which use the MS08-67,
which I can pass the target IP Address as a parameter.

eg:-  ms0867.exe 192.168.10.1

i need these to work in WINDOWS XP - sp2

Please Help thanks

10

(8 replies, posted in Newbie)

Thanks for the quick reply.
Can you please give me an example code ?
I need to execute a shell code which can download a file from a remote location and execute it.
thank you.

11

(8 replies, posted in Newbie)

Hi,
I need to spread my worm using Remote Code execution through the network.

I'm testing on Windows Xp sp2 machines.

How can I use Remote Code execution.

Thank you.

12

(28 replies, posted in Virus talks)

Hi Guys...
I have came across [Register or log in to view the URL]
Its free and open source..
Whats your opinion ?

Hi Guys..
I like to ask for a help..
Please can anyone post all the service names and registry entries created by the anti viruses which available in the market.
I have checked this link.
[Register or log in to view the URL]
but its not completed i guess. And its very old
Thanks a lot..

Hi Guys..
I like to ask for a help..
Please can anyone post all the service names and registry entries created by the anti viruses which available in the market.

I have checked this link.

[Register or log in to view the URL]

but its not completed i guess. And its very old

Thanks a lot..

15

(9 replies, posted in Virus talks)

[Register or log in to view the URL] is good page which gives details about rimecud.
I think its a variant of mariposa.

16

(9 replies, posted in Virus talks)

hey NExTliFE...,

Thanks for the reply...

#1. I like to study it. I want to learn from the best.
#2. I'm not a cop big_smile ( even I'm not usa guy.. I'm from Sri Lanka )
#3. I prefer any client or server. ( Server is most likely).

17

(3 replies, posted in Virus talks)

Thanks dude..
I was looking forward for these files.. smile

18

(9 replies, posted in Virus talks)

Hi Guys,
Anyone have a sample of "Mariposa" bot or ButterFly Bot sample?
Thanks.

19

(141 replies, posted in Virus eXchange)

zeus

20

(3 replies, posted in Virus talks)

koobface sample

21

(141 replies, posted in Virus eXchange)

koobFace

22

(1 replies, posted in Virus talks)

get well soon..

23

(3 replies, posted in Virus talks)

Hi guys,

I'm very much thankful If u guys can give me sample of Koob Face or the Source Code (desperately needed)...

smile
Thanks

24

(12 replies, posted in Virus talks)

Hi arc,

I dont want to race, because I want to learn from the best (like you,herm1t).
So, you take your time...

Thanks...

25

(12 replies, posted in Virus talks)

Thanks guys for the reply.
I have downloaded the collection from the offensive computing site.
I think the source code is not available in that. I need the source code for the Koob Face,Zues, Trojan.Fakeavalert. I want to study them. I'm a university student.

arc, I'm glad that ur are going to talk about them. If you can do it quickly, I'm more very much thank full.