Show Posts

This section allows you to view all posts made by this member. Note that you can only see posts made in areas you currently have access to.


Messages - Racheltjie de Beer

Pages: [1] 2
1
Found it on the Webs / Anonymous hacks SA government database
« on: February 14, 2016, 08:28:49 am »
So Anonymous hacks SA government database and Massive number of South African websites hacked by Anonymous

If they are going after corrupt politicians like Jacob Zuma, Robert Mugabe, et al., then they are going to be stuck on #OpAfrica for a very long time.  Mugabe, apparently got more money in his Swiss bank account than what Zimbabwe has.  Zuma is probably South Africa's most corrupt president ever!

The countries around the biggest lakes in Africa has the worst famine - thanks to corrupt African leaders!

So good luck with that  Anonymous ;)

2
Web Oriented Coding / Re: Best PHP resources
« on: February 02, 2016, 12:13:04 pm »
well man you should use search or something. There is a thing like this here https://evilzone.org/wiki/index.php/The_big_ebook_index#.40PHP with many favorite books

E-books and wiki is not available for under 20 post memebers

I agree with:

simply go to http://php.net/manual/en/

3
Game Hacking, Modding & Discussing / Re: Hacking a gambling website?
« on: February 02, 2016, 12:09:04 pm »
(and trying myself) about hacking gambling websites.

What methodology, technique, tool etc did you try?

Or, would someone do it for 100-150$?

Ask HTH, he takes money to deploy his mad skillz...

4
No to double post...

Just a note on using vi to view the file in Hex:
  • Open extracted file using vi
  • To switch to Hex, type:
    :%!xxd
  • To switch back, type:
    :%!xxd -r

This might be old news to seasoned *Nix users...

5
For our Ubuntu (and maybe other *Nix) listeners, the default unzip (or Archive Manager) will not work to unzip the sample.zip file:
Code: [Select]
Archive:  sample.zip
   skipping: 238bd6216c533984173a80c5675bd76f18100ec2c0cf462e24fe82d28305a674  need PK compat. v5.1 (can do v4.6)

I found this Ubuntu Forums thread

I did the following:
Code: [Select]
sudo apt-get install -y p7zip-full
7z x sample.zip

(Although I see one could just installed 7z)

Hope this help

6
General discussion / Re: Post your deskTOP
« on: January 29, 2016, 08:43:34 am »

7
General discussion / Re: Where are you from?
« on: January 28, 2016, 10:21:47 am »
I'm from Europe, Austria, Lower Austria :)

LOL, Lower Austria... Ha! Austria is as big as a stamp!
Texas vs Austria
 

8
In my opinion:

To start with; are you going to be a specialist or a generalist?  I.e. are you going to go in depth in one language / technology and master it or are you going to become knowledgeable in a few of them.

The inputs that influence your first decision are 1) what the market wants and will need (over the next 5 years) 2) your age 3) do you like tech more than ppl.

Best of luck

9
General discussion / Re: Where are you from?
« on: January 27, 2016, 12:38:17 pm »
Marie Byrd Land  :P

10
General discussion / Re: Dream Car?
« on: January 26, 2016, 01:35:42 pm »
Mine is the Ford Escort MK 2 Rally Style:

Very cool Rally cars!

11
Beginner's Corner / Re: Win.Exploit.CVE_2015_0005 FOUND
« on: January 25, 2016, 12:04:08 pm »
Hi Deque,

Thank you for your response and inputs.

On a sidenote: ClamAV produces lots of false positives, I do not recommend it.
What would you, personally, recommend for Linux?

If you need a proper checkup of your system, let me know.
Thank you.  I've followed the steps https://malwaretips.com/blogs/remove-popup-ads-windows-10/ on all my own PC's and they seems clean now.  Now just to get the Mother-in-law to stop clicking on banner add  ;)

12
Beginner's Corner / Win.Exploit.CVE_2015_0005 FOUND
« on: January 25, 2016, 08:02:35 am »
Problem
Not so much a problem as a learning experience.  I think I found malware on my Windows partition and would like to statically analysis it.

Background
I scanned my laptop a while ago, from my Linux partition using Clamav.  Clamav picked up a few malware infected files on the windows partition.  So I boot up in Windows and ran a slew of malware removal tools (Malwarebytes, JTR, etc).  Avast never picked up any malware.

Things I have tried
Then I started reading the tutorials on EZ (not because of the above).  I started with Deque's tutorials and it made me wonder. So I ran the scan again and found:

Code: [Select]
/media/Data/Python35/Scripts/smbrelayx.py: Win.Exploit.CVE_2015_0005 FOUND

----------- SCAN SUMMARY -----------
Known viruses: 4238654
Engine version: 0.98.7
Scanned directories: 0
Scanned files: 1
Infected files: 1
Data scanned: 0.06 MB
Data read: 0.04 MB (ratio 1.78:1)
Time: 5.719 sec (0 m 5 s)

Ooh, I thought, lets use my mad skills (from reading only two tutorials) and crack open this puppy. But wait, I told myself, think first!  Lets see what we are dealing with here before I do anything.

So I DDG (Search) a bit and found SMB Relay Demystified and NTLMv2 Pwnage with Python. Which, after reading, I found that it was developed to do SMB Relay attacks.

I also search for info on Win.Exploit.CVE_2015_0005 and found a lot of sites reporting the same (as Vulnerability Center):
Quote
Microsoft Windows multiple versions in vulnerable to remote spoofing attack in NETLOGON due to improper establishment of a secure communications channel belonging to a different machine with a spoofed computer name.

Questions
  • Is my assumption correct; that it is an intentional exploiting script and clamav is over reacting?
  • Is there possibly malware embedded in this exploiting script?

Regardless, I'll first work though a few tutorials (to gain knowledge and confidence), read up more and then take a look at smbrelayx.py – if it is malware...

13
Found it on the Webs / New browser: Brave
« on: January 24, 2016, 02:26:47 pm »
Found this article on in my inbox...
Abstract
Quote
Former Mozilla CEO Brendan Eich has launched a new web browser called Brave, which promises to “block all the greed and ugliness on the Web that slows you down and invades your privacy”.

Eich said that at Brave, they are building a solution designed to avert the war between publishers, users, and ad blockers.

The browser aims to give users “the fair deal they deserve for coming to the Web to browse and contribute”.

“We are building a new browser and a connected private cloud service with anonymous ads,” said Eich.

Article about the new browser: Brave

Brave

14
Tutorials / Re: Try and Bring Back Privacy to Windows 10
« on: January 22, 2016, 02:40:23 pm »
Personally I'm an artist that uses primarily high level photoshop extensions that I can't get with Linux "equivalents". Also, gaming yo

Most artist I've came across uses Mac, but that might be out of a students budget?
Gaming, yip I've not seen the top end of games for *Nix.

15
High Quality Tutorials / Re: Malware Lab Setup for Static Analysis
« on: January 22, 2016, 01:44:16 pm »
...
 but I want to know in what way (where it going to comunicate, what info will going to be stolen, etc). Antivirus, Endpoints protecctions and similars I think are mitigation, not for prevention.
...

It was not curiosity that killed the cat, it was a little boy and a microwave...
In the 90, when you still could email exe, I made a simple "bomb" app to email to an idiot.  On load, kicked of a new thread to load the same app as a new process/program (each one needed to be killed separately).  On close did the same.  So I coded and compiled the thing and like a toad I pressed run on my PC (just to see what will happened). Guess I was the id10t

Win 95 crashed after loading 127 programs in 10 sec...

Any case, studying code will tell you almost all you need to know.  And I would try and do that first before testing the "unknown" interactions, like with Anti virus etc.

Pages: [1] 2