Search the web
Sign In
New User? Sign Up
F-13Labs · F-13 Labs
? Already a member? Sign in to Yahoo!

Yahoo! Groups Tips

Did you know...
Real people. Real stories. See how Yahoo! Groups impacts members worldwide.

Best of Y! Groups

   Check them out and nominate your group.
Having problems with message search? Fill out this form to ensure your group is one of the first to be migrated to the new message search system.

Messages

  Messages Help
Advanced
Messages 41 - 78 of 79   Newest  |  < Newer  |  Older >  |  Oldest
Messages: Show Message Summaries   (Group by Topic) Sort by Date v  
#78 From: "mohannadmya" <mohannadmya@...>
Date: Mon Oct 19, 2009 11:51 am
Subject: what is the password?
mohannadmya
Offline Offline
Send Email Send Email
 
what is the password of Cracking Password with only Physical Access?

#74 From: "lclee_vx" <lclee_vx@...>
Date: Thu Mar 19, 2009 5:34 am
Subject: Skype Room For F-13
lclee_vx
Offline Offline
Send Email Send Email
 
Get the skype software, install it and register one ID. i create the chatting
room. Search and add me lclee_vx. will add you in the chatting room list.

thanks

#73 From: "vvilp" <vvilp@...>
Date: Fri Nov 14, 2008 8:17 am
Subject: Hello from China£¡£¡
vvilp
Offline Offline
Send Email Send Email
 
Hello everyone

#71 From: "syngedflesh" <syngedflesh@...>
Date: Thu Aug 7, 2008 2:14 am
Subject: Check this article out. LOL
syngedflesh
Offline Offline
Send Email Send Email
 
#70 From: lclee_vx <lclee_vx@...>
Date: Mon Jul 14, 2008 12:59 am
Subject: Re: PEid full archive password...
lclee_vx
Offline Offline
Send Email Send Email
 
Hai,
 
For the PEid stuff, please download F-13 Live CD...i already include all the tools in that liveCD for virus development and analysis purpose.
 
from lclee_vx

----- Original Message ----
From: ashot.amian <ashot.amian@...>
To: F-13Labs@yahoogroups.com
Sent: Sunday, July 13, 2008 11:28:44 PM
Subject: [F-13Labs] PEid full archive password...

Please, help me with this tool - PEid full. Password needed... Have
Anybody got it?... )



#69 From: "ashot.amian" <ashot.amian@...>
Date: Sun Jul 13, 2008 3:28 pm
Subject: PEid full archive password...
ashot.amian
Offline Offline
Send Email Send Email
 
Please, help me with this tool - PEid full. Password needed... Have
Anybody got it?... )

#68 From: "serena_saylor2000" <serena_saylor2000@...>
Date: Sun Jul 13, 2008 2:41 pm
Subject: Online Degree Benefits
serena_saylo...
Offline Offline
Send Email Send Email
 
The fast paced advancements in education and technology require us to
keep up to date in the chosen field. We also need to improve our skill
sets or study a new discipline to meet ever growing competition in the
job market. Online degrees offer the best solution to all of us as we
don't have to attend regular classes leaving our present commitments.

Visit the website for some valuable tips on how to get online degrees
from world's renowned universities to improve our academics and
further our career interests: http://onlinedegrees.advisoronline.info

The More You Learn The More You Earn
* Don't quit your job
* Obtain your degree online on your schedule
* Earn more money

Average Salary Pattern:

High School Diploma - $34k
Associate Degree - $46k
Bachelor's Degree - $65k
Master's Degree - $83k
PG Degrees - $103k

Visit the website for some valuable tips on how to get online degrees:
http://onlinedegrees.advisoronline.info

#67 From: "arben.hendri" <arben.hendri@...>
Date: Wed Jul 2, 2008 2:36 am
Subject: request password peid full version
arben.hendri
Offline Offline
Send Email Send Email
 
dear friends
pls send me password for ollydbg and peid full version.

thank's

#66 From: "lclee_vx" <lclee_vx@...>
Date: Thu May 22, 2008 2:07 am
Subject: F-13 LiveCD 0.1
lclee_vx
Offline Offline
Send Email Send Email
 
This is another version of F-13 LiveCD version 0.1. The tool include
as below:

1.Compiler:fasm, nasm, masm, tasm
2.Debugger: OllyICE[modified version OllyDebug include unpack
scripts], IDA Pro [Free Version]
3.Antivirus: Nod32 [Just for checking/scanning your new virus]
4.Assembly Editor: RadASM
5.Network:fport, sniffer, tcpview, wpe [check the network spreading
of your new virus]
6.PE Tool:APIscan, heapmemview[32bit], heapmemview-x64[64bit],
hexworkshop, lordPE, stud_PE, PEiD, Winhex...

Main for this LiveCD is to develop the virus and create the safety
environment for you to code the vx. Hmm...i am planning to include
the virus sample, utilities, virus library[the routine of retrieve
kernel32 address, api scanning etc] in next version.

Any idea and comment [good or bad] please let me know.

http://www.f13-labs.net/tool/F13-LiveCD/F13LiveCD.htm

Happy virus code!!

#64 From: lclee_vx <lclee_vx@...>
Date: Mon Mar 3, 2008 9:05 am
Subject: Re: password needed
lclee_vx
Offline Offline
Send Email Send Email
 
 

 
----- Original Message ----
From: Jay <silverspirit71@...>
To: F-13Labs@yahoogroups.com
Sent: Sunday, March 2, 2008 11:16:20 PM
Subject: [F-13Labs] password needed

for dezend.rar please




Looking for last minute shopping deals? Find them fast with Yahoo! Search.

#63 From: "Jay" <silverspirit71@...>
Date: Sun Mar 2, 2008 3:16 pm
Subject: password needed
silverspirit71
Offline Offline
Send Email Send Email
 
for dezend.rar please

#61 From: "itstime927" <itstime927@...>
Date: Thu Jan 17, 2008 6:57 am
Subject: Re: rar password needed.. plz help
itstime927
Offline Offline
Send Email Send Email
 
same here =) ..... hail the vx scene

#60 From: "sam_pi_1987" <sam_pi_1987@...>
Date: Tue Jan 8, 2008 7:40 pm
Subject: rar password needed.. plz help
sam_pi_1987
Offline Offline
Send Email Send Email
 
hey all,
i need password for passware kit &
PEID+plugins+tools
plz provide the same..

#59 From: "mr.mamtk" <mamtk@...>
Date: Mon Jan 7, 2008 2:04 pm
Subject: PEid + Plugins + Tools
mr.mamtk
Offline Offline
Send Email Send Email
 
hi Group
this group i was looking for
any 1 can help me in this

the site http://www.f13-labs.net
have this tool

PEid + Plugins + Tools [Download]

    Note: This PEid tool is famous in cracking stuff. The archive
include all the plugins and unpack/signature creator tool inside.
Complete.

             Anyhow, this tool is for member only, ask the password
in "Gathering" forum.


i need the pass for rar file plzzzzzzzzz

#58 From: "b00t_wizard" <b00t_wizard@...>
Date: Sat Dec 29, 2007 4:21 am
Subject: Re: New Ezine
b00t_wizard
Offline Offline
Send Email Send Email
 
sweet!

I'ma start a new code for this probably in visual basic...

when I have my ideas made I'll either write you my information/ideas
or post them here....either way

you'll here from me soon!

--- In F-13Labs@yahoogroups.com, lclee_vx <lclee_vx@...> wrote:
>
> we are welcome any vx (virus) codes & ideas
>
>
> ----- Original Message ----
> From: b00t_wizard <b00t_wizard@...>
> To: F-13Labs@yahoogroups.com
> Sent: Saturday, December 29, 2007 11:59:37 AM
> Subject: [F-13Labs] Re: New Ezine
>
> any room for :
> visual basic/studio programming , net &/or software background
ethics
> let me know!
>
> --- In F-13Labs@yahoogroup s.com, "lclee_vx" <lclee_vx@ .> wrote:
> >
> > Dear F-13 members,
> >
> > I am planning to come out the new Ezine for 2008, what say you?
> >
> >
> > from lclee_vx
> >
>
>
>
>
>
>
______________________________________________________________________
______________
> Looking for last minute shopping deals?
> Find them fast with Yahoo! Search.
http://tools.search.yahoo.com/newsearch/category.php?category=shopping
>

#57 From: lclee_vx <lclee_vx@...>
Date: Sat Dec 29, 2007 4:06 am
Subject: Re: Re: New Ezine
lclee_vx
Offline Offline
Send Email Send Email
 
we are welcome any vx (virus) codes & ideas

----- Original Message ----
From: b00t_wizard <b00t_wizard@...>
To: F-13Labs@yahoogroups.com
Sent: Saturday, December 29, 2007 11:59:37 AM
Subject: [F-13Labs] Re: New Ezine

any room for :
visual basic/studio programming , net &/or software background ethics
let me know!

--- In F-13Labs@yahoogroup s.com, "lclee_vx" <lclee_vx@.. .> wrote:
>
> Dear F-13 members,
>
> I am planning to come out the new Ezine for 2008, what say you?
>
>
> from lclee_vx
>




Looking for last minute shopping deals? Find them fast with Yahoo! Search.

#56 From: "b00t_wizard" <b00t_wizard@...>
Date: Sat Dec 29, 2007 3:59 am
Subject: Re: New Ezine
b00t_wizard
Offline Offline
Send Email Send Email
 
any room for :
visual basic/studio programming , net &/or software background ethics
let me know!


--- In F-13Labs@yahoogroups.com, "lclee_vx" <lclee_vx@...> wrote:
>
> Dear F-13 members,
>
> I am planning to come out the new Ezine for 2008, what say you?
>
>
> from lclee_vx
>

#55 From: "b00t_wizard" <b00t_wizard@...>
Date: Sat Dec 29, 2007 3:58 am
Subject: Re: F-13 LiveCD
b00t_wizard
Offline Offline
Send Email Send Email
 
definitley useful & a great idea!

--- In F-13Labs@yahoogroups.com, "lclee_vx" <lclee_vx@...> wrote:
>
> This is the windows LiveCD, i include the famous asm compiler such as
> masm32, tasm32, nasm32 and fasm32, OllyDebug and ASM editor.
>
> Just download and burn into cd and boot the cd.
>
> I created this LiveCD for virus code development and virus analysist
> purpose.
>
> will add other tool and functions soon.
>
> any comment, good or bad please let me know.
>
> http://www.f13-labs.net/tool/F13-LiveCD/F13LiveCD.htm
>
>
> from lclee_vx/F-13 & lychan25/F-13
>

#53 From: Soravis Prommas <prommas_6@...>
Date: Wed Nov 14, 2007 11:20 am
Subject: RE: F-13 LiveCD
moaphie_z6
Offline Offline
Send Email Send Email
 

thx, lclee_vx its very useful!

To: F-13Labs@yahoogroups.com
From: lclee_vx@...
Date: Tue, 13 Nov 2007 20:14:01 +0000
Subject: [F-13Labs] F-13 LiveCD

This is the windows LiveCD, i include the famous asm compiler such as
masm32, tasm32, nasm32 and fasm32, OllyDebug and ASM editor.

Just download and burn into cd and boot the cd.

I created this LiveCD for virus code development and virus analysist
purpose.

will add other tool and functions soon.

any comment, good or bad please let me know.

http://www.f13-labs.net/tool/F13-LiveCD/F13LiveCD.htm

from lclee_vx/F-13 & lychan25/F-13




Windows Live Hotmail and Microsoft Office Outlook – together at last. Get it now!

#52 From: "lclee_vx" <lclee_vx@...>
Date: Tue Nov 13, 2007 8:14 pm
Subject: F-13 LiveCD
lclee_vx
Offline Offline
Send Email Send Email
 
This is the windows LiveCD, i include the famous asm compiler such as
masm32, tasm32, nasm32 and fasm32, OllyDebug and ASM editor.

Just download and burn into cd and boot the cd.

I created this LiveCD for virus code development and virus analysist
purpose.

will add other tool and functions soon.

any comment, good or bad please let me know.

http://www.f13-labs.net/tool/F13-LiveCD/F13LiveCD.htm


from lclee_vx/F-13 & lychan25/F-13

#51 From: "b00t_wizard" <b00t_wizard@...>
Date: Sun Aug 26, 2007 5:19 pm
Subject: Re: New Ezine
b00t_wizard
Offline Offline
Send Email Send Email
 
count me in!
I've been working with some naughty codez...lol

#50 From: "lclee_vx" <lclee_vx@...>
Date: Tue Aug 21, 2007 9:12 am
Subject: Need 10 ID in undernet
lclee_vx
Offline Offline
Send Email Send Email
 
Hai,

I need 10 ID in undernet for apply the new channel

Please register in
http://cservice.undernet.org/live/

and revert the ID to me.

Thanks

#49 From: "lclee_vx" <lclee_vx@...>
Date: Tue Aug 21, 2007 9:12 am
Subject: Need 10 ID in undernet
lclee_vx
Offline Offline
Send Email Send Email
 
Hai,

I need 10 ID in undernet for apply the new channel

Please register in
http://cservice.undernet.org/live/

and revert the ID to me.

Thanks

#48 From: "syngedflesh" <syngedflesh@...>
Date: Fri Aug 10, 2007 10:33 pm
Subject: Re: New Ezine
syngedflesh
Offline Offline
Send Email Send Email
 
Let's do it :)



--- In F-13Labs@yahoogroups.com, "lclee_vx" <lclee_vx@...> wrote:
>
> Dear F-13 members,
>
> I am planning to come out the new Ezine for 2008, what say you?
>
>
> from lclee_vx
>

#46 From: "b00t_wizard" <b00t_wizard@...>
Date: Thu Jul 26, 2007 3:24 am
Subject: Re: do you know GO game
b00t_wizard
Offline Offline
Send Email Send Email
 
ive heard of it,havent looked into it,
I wouldnt mind knowing a little bit more about it

#45 From: ï¿ ³Â <silence_vx@...>
Date: Tue Jul 24, 2007 7:46 am
Subject: »Ø¸´£º Re: »Ø¸´£º iiHELP ME PLEASE HELP ME HELP ME ! MAN PLEASE HELP ME ! I WILL WORSHIP YOU !
silence_vx
Offline Offline
Send Email Send Email
 
yes  #eof-project or #vir #virus at irc.undernet.org

sandundhammikaperera <sandundhammikaperera@...> дµÀ£º
--- In F-13Labs@yahoogroups.com, ï¿ ³Â <silence_vx@...> wrote:
>
> hi sanzilla jackcat
> i had read your code and find some code is unuseful !!!
> i post code which is also to search APIS
> i hope it can help you ^-^
Thanks man i got the code . Man how to find other virus crues in the
IRC ? what are the servers and what are the usernames and passwords
man ? how to find out some real virus source code analysis with little
more comments man ? Are you on IRC ? chat ?



ÇÀ×¢ÑÅ»¢Ãâ·ÑÓÊÏä3.5GÈÝÁ¿£¬20M¸½¼þ£¡

#44 From: "sandundhammikaperera" <sandundhammikaperera@...>
Date: Mon Jul 23, 2007 2:55 pm
Subject: Re: »Ø¸´£º iiHELP ME PLEASE HELP ME HELP ME ! MAN PLEASE HELP ME ! I WILL WORSHIP YOU !
sandundhammi...
Offline Offline
Send Email Send Email
 
--- In F-13Labs@yahoogroups.com, ï¿ ³Â <silence_vx@...> wrote:
>
> hi sanzilla jackcat
>          i had read your code and find some code is unuseful !!!
>          i post code which is also to search APIS
>          i hope it can help you ^-^
Thanks man i got the code . Man how to find other virus crues in the
IRC ? what are the servers and what are the usernames and passwords
man ? how to find out some real virus source code analysis with little
more comments man ? Are you on IRC ? chat ?

#43 From: "lclee_vx" <lclee_vx@...>
Date: Mon Jul 23, 2007 1:07 pm
Subject: Re: iiHELP ME PLEASE HELP ME HELP ME ! MAN PLEASE HELP ME ! I WILL WORSHIP YOU !
lclee_vx
Offline Offline
Send Email Send Email
 
Hai,

I did not go through the detail of your code (busy on study
now)...anyhow..just my opinion, refer to the following code:

XPKernel32BaseAddress equ 77E60000h

as i know..you tried to fix the kernel32 base address...this may
cause the exception when the code not successful to look for the
right address..

try add another routine search for kernel32.dll base address
random..refer to my article the technic checksum...

cheer...

and nice code !!

i will study again your code and get back tto you :)

--- In F-13Labs@yahoogroups.com, "sandundhammikaperera"
<sandundhammikaperera@...> wrote:
>
> man I read the articles and find out the ways to get the kernel32
> base address on the hardcorded method and I done some
GetProcAddress
> search . But the problem in this is I got an exception . why was
> that ?
> my code is this .
> First I write the code but the variables in the code segment are
> read only thus I changet that segment attributes and try again
> already then in I debugging on the ollydebug it faills when it
scans
> the 2Dh element of the export table of the Kernel32.dll what a
fuck
> is this ? Please help me man please ... Please ... I'm very
curious
> now . I just cant breath without assembly now . Please man help me
> give me some drugs .
>
>
> This is my source code .
> ------------------------------------------------code begins ------
>
>     .586
>     .model flat , stdcall
>     option casemap : none
> include c:\masm32\include\kernel32.inc
> includelib c:\masm32\lib\kernel32.lib
> include c:\masm32\include\user32.inc
> includelib c:\masm32\lib\user32.lib
> ;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;
>
>
> .code
> start:
>     call GetDelta
>  GetDelta:
>     pop ebp
>     sub ebp , OFFSET GetDelta - OFFSET start
> XPKernel32BaseAddress equ 77E60000h
>     mov eax , XPKernel32BaseAddress
>     call CheckForK32
>     cmp eax , 0000000h
>     jne  ExitLoop
>     mov eax , XPKernel32BaseAddress
>     call GetApiAddress
>     ;; now we are going to print a messageBox
>     invoke ExitProcess , 0
>
>
>
>
>
> ExitLoop:
>     ;; return to the host code in our virus .
>
> ;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;
>
>
>
>
> ;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;
> CheckForK32 proc
>     cmp word ptr [ eax ] , 'ZM'
>     jne NotFound
>     add eax , 3ch
>     mov eax , [eax]
>     add eax , XPKernel32BaseAddress
>     cmp word ptr [ eax ] , 'EP'
>     jne NotFound
>     xor eax  , eax
>     ret
> NotFound:
>     ;; die
> CheckForK32 endp
> ;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;
>
>
> ;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;
> aPEHelder dd 0
> aimportDir dd 0
> aAddressTable dd 0
> aNameTable dd 0
> aOrdinalTable dd 0
> nOfExports dd 0
> sGetProcAddress db 'GetProcAddress' ,0
> aGetProcAddress dd 0
>
> GetApiAddress proc
>     ;; oky now we have to get the PE real address
>     mov eax , [eax+3ch]
>     mov [ebp + (OFFSET aPEHelder - OFFSET start) ] , eax
>     add eax , XPKernel32BaseAddress
>     mov [ebp+( OFFSET aPEHelder- OFFSET start) ] , eax
>     ;; now there is PE helder address in the eax
>     ;; we shall play with it .
>     ;; Then we need is the place where VA of import dir is kept
>     ;; it is on the 78h
>     add  eax , 78h
>     mov eax,dword ptr [ eax ]
>     add eax , XPKernel32BaseAddress
>     push eax
>     mov [ebp + (OFFSET aimportDir- OFFSET start) ] , eax
>     ;;oky we are pointed to the import table in eax
>     ;; oky then get the addresstableRVA
>     add eax , 1ch
>     mov eax , [eax]
>     add eax , XPKernel32BaseAddress
>     mov dword ptr [ebp + (OFFSET aAddressTable-OFFSET start)] , eax
>     pop eax
>     ;; oky now we shoud have the Name PTR table
>     push eax
>     add eax , 20h
>     mov eax , dword ptr [eax]
>     add eax , XPKernel32BaseAddress
>     mov dword ptr [ebp + (OFFSET aNameTable - OFFSET start) ] , eax
>     pop eax
>     push eax
>     ;;Now we should get the Ordinal table
>     add eax , 24h
>     mov eax , dword ptr [eax]
>     add eax , XPKernel32BaseAddress
>     mov dword ptr [ ebp+ ( OFFSET aOrdinalTable - OFFSET start)] ,
> eax
>     pop eax
>     push eax
>     ;; now we have to get nunber of exports
>     add eax , 18h
>     mov eax , dword ptr [eax]
>     mov dword ptr [ebp + (OFFSET nOfExports- OFFSET start) ] , eax
>     mov ecx , eax
>     pop eax
>
>     ;; Now we have to search for the APIs , Lets go
>     ;; we shoud put the nOfExports to the ecx oky
>     ;; virus leavaman sanaseama laba! .
>     mov eax , dword ptr [ ebp + (OFFSET aNameTable - OFFSET start)]
>     ;; now the eax is pointed to the first address of the string
> name
>     mov edx , 0
>     lea esi , [ebp +(OFFSET sGetProcAddress- OFFSET start)]
>     mov ebx , esi
> CheckNext:
>     push edx
>     shl edx , 2
>     add eax , edx
>     pop edx
>     mov edi , dword ptr [ eax ]
>     add edi , XPKernel32BaseAddress
>     inc edx
>     mov esi , ebx
> CheckByte:
>     ;; we have to compare the bytes in EDI with ESI
>     cmpsb
>     jne CheckNext
>     cmp byte ptr [esi] , 0
>     je  GotIt
>     cmp edx , ecx
>     je  ExitLoop        ;; what a shitt this is not kernel32 what
a
> fuck .
>     jmp CheckByte
> GotIt:
>     ;; oky we now get that shitt . Oky now we have to store this
> shitt
>     ;; its on the count of edx +1
>     ;; but in the loop it was already incremented .This is where
> aAddressTable was need
>     mov eax , [ebp + (OFFSET aAddressTable - OFFSET start) ]
>     mov eax , [eax]
>     push edx
>     shl edx , 2
>     add eax , edx
>     pop edx
>     mov eax , [eax]
>     mov [ebp + (OFFSET aGetProcAddress-OFFSET start) ] , eax
>     xor eax , eax
>     xor edx , edx
>     ret
> GetApiAddress endp
> ;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;
;;
> ;;;
> end start
>
> -------------------------------------------------------------------
-
> please make sure to changet the attributes on the segments to full
> access in order to avoid memory access violations under ollydbg.
>
>
> oky man please help me man . I just a beaganner to the assembly
> langaueg and virus writing . I need to go to the hell .
>                                      by : sanzilla jackcat
>
> sandundhammikaperera@...
>

#42 From: ï¿ ³Â <silence_vx@...>
Date: Mon Jul 23, 2007 1:01 pm
Subject: »Ø¸´£º iiHELP ME PLEASE HELP ME HELP ME ! MAN PLEASE HELP ME ! I WILL WORSHIP YOU !
silence_vx
Offline Offline
Send Email Send Email
 
hi sanzilla jackcat
       i had read your code and find some code is unuseful !!!
       i post code which is also to search APIS
       i hope it can help you ^-^
code:
       ;esi point to the API string
    GetFunctionAddress PROC
        mov     eax, [ebp+Kernel32Address]          ;EAX = Kernel32 Address
        mov     ebx, [eax+3Ch]
        add     ebx, eax
        add     ebx, 120
        mov     ebx, [ebx]
        add     ebx, eax                            ;EBX = Export Address
 
        xor     edx, edx
        mov     ecx, [ebx+32]
        add     ecx, eax
        push    esi
        push    edx
CompareNext:
        pop     edx
        pop     esi
        inc     edx
        mov     edi, [ecx]
        add     edi, eax
        add     ecx, 4
        push    esi
        push    edx
CompareName:
        mov     dl, [edi]
        mov     dh, [esi]
        cmp     dl, dh
        jne     CompareNext
        inc     edi
        inc     esi
        cmp     byte ptr [esi], 0
        je      GetAddress
        jmp     CompareName
GetAddress:
        pop     edx
        pop     esi
        dec     edx
        shl     edx, 1       
        mov     ecx, [ebx+36]
        add     ecx, eax
        add     ecx, edx
  xor     edx, edx
        mov     dx, [ecx]
        shl     edx, 2
        mov     ecx, [ebx+28]
        add     ecx, eax
        add     ecx, edx
        add     eax, [ecx]
        ret
GetFunctionAddress ENDP


ÇÀ×¢ÑÅ»¢Ãâ·ÑÓÊÏä3.5GÈÝÁ¿£¬20M¸½¼þ£¡

#41 From: "sandundhammikaperera" <sandundhammikaperera@...>
Date: Mon Jul 23, 2007 12:08 pm
Subject: iiHELP ME PLEASE HELP ME HELP ME ! MAN PLEASE HELP ME ! I WILL WORSHIP YOU !
sandundhammi...
Offline Offline
Send Email Send Email
 
man I read the articles and find out the ways to get the kernel32
base address on the hardcorded method and I done some GetProcAddress
search . But the problem in this is I got an exception . why was
that ?
my code is this .
First I write the code but the variables in the code segment are
read only thus I changet that segment attributes and try again
already then in I debugging on the ollydebug it faills when it scans
the 2Dh element of the export table of the Kernel32.dll what a fuck
is this ? Please help me man please ... Please ... I'm very curious
now . I just cant breath without assembly now . Please man help me
give me some drugs .


This is my source code .
------------------------------------------------code begins ------

     .586
     .model flat , stdcall
     option casemap : none
include c:\masm32\include\kernel32.inc
includelib c:\masm32\lib\kernel32.lib
include c:\masm32\include\user32.inc
includelib c:\masm32\lib\user32.lib
;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;


.code
start:
     call GetDelta
  GetDelta:
     pop ebp
     sub ebp , OFFSET GetDelta - OFFSET start
XPKernel32BaseAddress equ 77E60000h
     mov eax , XPKernel32BaseAddress
     call CheckForK32
     cmp eax , 0000000h
     jne  ExitLoop
     mov eax , XPKernel32BaseAddress
     call GetApiAddress
     ;; now we are going to print a messageBox
     invoke ExitProcess , 0





ExitLoop:
     ;; return to the host code in our virus .

;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;




;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;
CheckForK32 proc
     cmp word ptr [ eax ] , 'ZM'
     jne NotFound
     add eax , 3ch
     mov eax , [eax]
     add eax , XPKernel32BaseAddress
     cmp word ptr [ eax ] , 'EP'
     jne NotFound
     xor eax  , eax
     ret
NotFound:
     ;; die
CheckForK32 endp
;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;


;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;
aPEHelder dd 0
aimportDir dd 0
aAddressTable dd 0
aNameTable dd 0
aOrdinalTable dd 0
nOfExports dd 0
sGetProcAddress db 'GetProcAddress' ,0
aGetProcAddress dd 0

GetApiAddress proc
     ;; oky now we have to get the PE real address
     mov eax , [eax+3ch]
     mov [ebp + (OFFSET aPEHelder - OFFSET start) ] , eax
     add eax , XPKernel32BaseAddress
     mov [ebp+( OFFSET aPEHelder- OFFSET start) ] , eax
     ;; now there is PE helder address in the eax
     ;; we shall play with it .
     ;; Then we need is the place where VA of import dir is kept
     ;; it is on the 78h
     add  eax , 78h
     mov eax,dword ptr [ eax ]
     add eax , XPKernel32BaseAddress
     push eax
     mov [ebp + (OFFSET aimportDir- OFFSET start) ] , eax
     ;;oky we are pointed to the import table in eax
     ;; oky then get the addresstableRVA
     add eax , 1ch
     mov eax , [eax]
     add eax , XPKernel32BaseAddress
     mov dword ptr [ebp + (OFFSET aAddressTable-OFFSET start)] , eax
     pop eax
     ;; oky now we shoud have the Name PTR table
     push eax
     add eax , 20h
     mov eax , dword ptr [eax]
     add eax , XPKernel32BaseAddress
     mov dword ptr [ebp + (OFFSET aNameTable - OFFSET start) ] , eax
     pop eax
     push eax
     ;;Now we should get the Ordinal table
     add eax , 24h
     mov eax , dword ptr [eax]
     add eax , XPKernel32BaseAddress
     mov dword ptr [ ebp+ ( OFFSET aOrdinalTable - OFFSET start)] ,
eax
     pop eax
     push eax
     ;; now we have to get nunber of exports
     add eax , 18h
     mov eax , dword ptr [eax]
     mov dword ptr [ebp + (OFFSET nOfExports- OFFSET start) ] , eax
     mov ecx , eax
     pop eax

     ;; Now we have to search for the APIs , Lets go
     ;; we shoud put the nOfExports to the ecx oky
     ;; virus leavaman sanaseama laba! .
     mov eax , dword ptr [ ebp + (OFFSET aNameTable - OFFSET start)]
     ;; now the eax is pointed to the first address of the string
name
     mov edx , 0
     lea esi , [ebp +(OFFSET sGetProcAddress- OFFSET start)]
     mov ebx , esi
CheckNext:
     push edx
     shl edx , 2
     add eax , edx
     pop edx
     mov edi , dword ptr [ eax ]
     add edi , XPKernel32BaseAddress
     inc edx
     mov esi , ebx
CheckByte:
     ;; we have to compare the bytes in EDI with ESI
     cmpsb
     jne CheckNext
     cmp byte ptr [esi] , 0
     je  GotIt
     cmp edx , ecx
     je  ExitLoop        ;; what a shitt this is not kernel32 what a
fuck .
     jmp CheckByte
GotIt:
     ;; oky we now get that shitt . Oky now we have to store this
shitt
     ;; its on the count of edx +1
     ;; but in the loop it was already incremented .This is where
aAddressTable was need
     mov eax , [ebp + (OFFSET aAddressTable - OFFSET start) ]
     mov eax , [eax]
     push edx
     shl edx , 2
     add eax , edx
     pop edx
     mov eax , [eax]
     mov [ebp + (OFFSET aGetProcAddress-OFFSET start) ] , eax
     xor eax , eax
     xor edx , edx
     ret
GetApiAddress endp
;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;
;;;
end start

--------------------------------------------------------------------
please make sure to changet the attributes on the segments to full
access in order to avoid memory access violations under ollydbg.


oky man please help me man . I just a beaganner to the assembly
langaueg and virus writing . I need to go to the hell .
                                      by : sanzilla jackcat

sandundhammikaperera@...

Messages 41 - 78 of 79   Newest  |  < Newer  |  Older >  |  Oldest
Advanced
Add to My Yahoo!      XML What's This?

Copyright © 2009 Yahoo! Inc. All rights reserved.
Privacy Policy - Terms of Service - Guidelines - Help