• Trying to decrypt VB .Net keyloggers
    408 replies, posted
Just thought of a better way than using email. Pastebin + RSA + keyword. Have the keyloggers pastebin their logs with a keyword and the data encrypted with an RSA public key. Then have a tool which searches for the keyword and decrypts the data. There would be an issue of them blocking the keyword so instead you could just setup a crawler that looks for the data. Web history is so fun to look at. Found another person who used the keylogger account for more than keylogging. Searched for [email]ficky_nox@hotmail.com[/email] Searched for fonefinder.net Searched for <phone> I wonder whose number that is.
[QUOTE=supersnail11;34952584]OK guys quick ethical question. What if you were to: ... Ethically fine Y/N[/QUOTE] Enough people do it, why not.
So am I the only one Chaotic-neutral on this subject? You can make some good money by selling gold from various online games to goldsellers. Or use the hacked accounts to spam the keylogger to get even more views. After a while, decrypting phishers/keyloggers gets quite monotonous and loading massive amounts of various items/gold to your main is quite satisfying.
Am I the only one that does not care about key logging and thinks that you are all taking it a bit too far for Visual Basic Runescape keyloggers?
[QUOTE=The freeman;34958360]Am I the only one that does not care about key logging and thinks that you are all taking it a bit too far for Visual Basic Runescape keyloggers?[/QUOTE] it is a fun challenge, and depending on your current alignment, either helps people / helps yourself.
Do not post people's personal information or you will get banned for raiding.
lol, this thread owns, it's like programming section has finally come out and admitted it is just a hackforum-equivalent. good job being elite white hat hackers guys with your .net reflectors(i hope you are all arrested for illegally accessing those e-mails) supersnail -- what is the point of that blog? is it to put on a resume one day(this is the only legitimate purpose for blogs)?? if that's the case, why did you name yourself "communistpancake"? you don't think that'd reflect poorly? [QUOTE=The freeman;34958360]Am I the only one that does not care about key logging and thinks that you are all taking it a bit too far for Visual Basic Runescape keyloggers?[/QUOTE] no, see, the wonderful facepunch programming section members apparently unanimously think this is a great show of skill and have to show everyone what they've done
[QUOTE=Soda;34959066]lol, this thread owns, it's like programming section has finally come out and admitted it is just a hackforum-equivalent. good job being elite white hat hackers guys with your .net reflectors(i hope you are all arrested for illegally accessing those e-mails) supersnail -- what is the point of that blog? is it to put on a resume one day(this is the only legitimate purpose for blogs)?? if that's the case, why did you name yourself "communistpancake"? you don't think that'd reflect poorly? no, see, the wonderful facepunch programming section members apparently unanimously think this is a great show of skill and have to show everyone what they've done[/QUOTE] Who shit in your cereal this morning? Some of us find the concept of reverse engineering fun, even if it is at a basic level.
[QUOTE=Soda;34959066]lol, this thread owns, it's like programming section has finally come out and admitted it is just a hackforum-equivalent. good job being elite white hat hackers guys with your .net reflectors(i hope you are all arrested for illegally accessing those e-mails) supersnail -- what is the point of that blog? is it to put on a resume one day(this is the only legitimate purpose for blogs)?? if that's the case, why did you name yourself "communistpancake"? you don't think that'd reflect poorly? no, see, the wonderful facepunch programming section members apparently unanimously think this is a great show of skill and have to show everyone what they've done[/QUOTE] So what you're saying is that your keylogger just got trashed by one of these guys?
[QUOTE=Phreebird;34959304]Who shit in your cereal this morning? Some of us find the concept of reverse engineering fun, even if it is at a basic level.[/QUOTE] Apparently, in his mind, actually working out how to reverse stuff, = the same as copy paste skiddies. Never the mind the fact that some people here (me included) have acutally made new tools and utilities to do this stuff with.
[QUOTE=Lexic;34959491]So what you're saying is that your keylogger just got trashed by one of these guys?[/QUOTE] yeah totally I secretly run all the runescape keylogging networks, all those videos are made by me. I'd prob be more supportive of this if there was actual reverse engineering discussion instead of skiddie "guys I can't handle all this obfuscation :downs:" "just download this it'll set you up proper ;)"
[QUOTE=Soda;34959586]yeah totally I secretly run all the runescape keylogging networks, all those videos are made by me. I'd prob be more supportive of this if there was actual reverse engineering discussion instead of skiddie "guys I can't handle all this obfuscation :downs:" "just download this it'll set you up proper ;)"[/QUOTE] Because yeah, discussing how decrypting an assembly that is then dynamically loaded, without actually letting it run cant be reverse engineering discussion.
We need a new thread for reverse engineering.
[QUOTE=nekosune;34959615]Because yeah, discussing how decrypting an assembly that is then dynamically loaded, without actually letting it run cant be reverse engineering discussion.[/QUOTE] yeah don't lie actual technical posts on this are not the main feature of this thread(and I don't recall seeing anything related to that past "guys...this one had an exe in an exe in an exe...wowzers!")
35th post [url]http://www.facepunch.com/threads/1166226?p=34885094&viewfull=1#post34885094[/url] [editline]2nd March 2012[/editline] [url]http://www.facepunch.com/threads/1167605?p=34959792#post34959792[/url] made a new thread, for generic reverse engineering, including keylogger stuff.
[QUOTE=nekosune;34959746]35th post [url]http://www.facepunch.com/threads/1166226?p=34885094&viewfull=1#post34885094[/url][/QUOTE] right, that's the awful post that went nowhere I was recalling. you stop just because something can't be easymode reflected? this is reverse engineering, truly, when something can't be represented in a programming language I am familiar with, it is time to quit.
[QUOTE=Soda;34959828]right, that's the awful post that went nowhere I was recalling. you stop just because something can't be easymode reflected? this is reverse engineering, truly, when something can't be represented in a programming language I am familiar with, it is time to quit.[/QUOTE] and yeah, I really stopped, thats why two below it shows I continued it. [editline]2nd March 2012[/editline] [url]http://www.facepunch.com/threads/1166226?p=34885560&viewfull=1#post34885560[/url] Turns out that way was to use non ascii characters as function names. [url]http://www.facepunch.com/threads/1166226?p=34885646&viewfull=1#post34885646[/url] and then I hit the true wall of instead of going to email, it was being sent as a GET to a website, I have since reported that site to the ISP.
[QUOTE=nekosune;34959871]and yeah, I really stopped, thats why two below it shows I continued it. [editline]2nd March 2012[/editline] [url]http://www.facepunch.com/threads/1166226?p=34885560&viewfull=1#post34885560[/url] Turns out that way was to use non ascii characters as function names. [url]http://www.facepunch.com/threads/1166226?p=34885646&viewfull=1#post34885646[/url] and then I hit the true wall of instead of going to email, it was being sent as a GET to a website, I have since reported that site to the ISP.[/QUOTE] ah. didn't know you were using the thread as your stream of conciousness. obviously those posts had to be about the same thing. they're still completely contentless, not mentioning how you fixed novice issues of getting reflector to work, or anything on how you "decrypted" "dynamically loaded executables." as I said before, this is hackforum-tier "look at what I did" garbage.
Well I am sincerely sorry this thread did not meet to your expectations of what everyone should be doing with their time, I am sure everyone feels horrible about that.
[QUOTE=Soda;34960004]ah. didn't know you were using the thread as your stream of conciousness. obviously those posts had to be about the same thing. they're still completely contentless, not mentioning how you fixed novice issues of getting reflector to work, or anything on how you "decrypted" "dynamically loaded executables." as I said before, this is hackforum-tier "look at what I did" garbage.[/QUOTE] Wow, how were you ever unbanned. I bet you're a real people person in real life.
[QUOTE=Soda;34960004]ah. didn't know you were using the thread as your stream of conciousness. obviously those posts had to be about the same thing. they're still completely contentless, not mentioning how you fixed novice issues of getting reflector to work, or anything on how you "decrypted" "dynamically loaded executables." as I said before, this is hackforum-tier "look at what I did" garbage.[/QUOTE] Your posts in this thread are full of content and not just a bunch of bullshit garbage, for sure.
[QUOTE=Soda;34959066]lol, this thread owns, it's like programming section has finally come out and admitted it is just a hackforum-equivalent. good job being elite white hat hackers guys with your .net reflectors(i hope you are all arrested for illegally accessing those e-mails) supersnail -- what is the point of that blog? is it to put on a resume one day(this is the only legitimate purpose for blogs)?? if that's the case, why did you name yourself "communistpancake"? you don't think that'd reflect poorly? no, see, the wonderful facepunch programming section members apparently unanimously think this is a great show of skill and have to show everyone what they've done[/QUOTE] You act like they don't deserve it.
snip
[QUOTE=Darwin226;34960285]I people you're a real people person in real life.[/QUOTE] people people.
[img]http://puu.sh/ja8H[/img] Got it frome a youtube video, it actually still is active (Got new mails this morning) although i'm probably going to delete all mails and leave a message for him :v:
[QUOTE=Chris220;34961562]people people.[/QUOTE] Yeah, I zone out sometimes.
[QUOTE=Soda;34959066] supersnail -- what is the point of that blog? is it to put on a resume one day(this is the only legitimate purpose for blogs)?? if that's the case, why did you name yourself "communistpancake"? you don't think that'd reflect poorly? [/QUOTE] The point of the blog is to have a personal blog to post thoughts and programming things. Who would put a blog on a resume anyways, unless they're applying for a writing job? And I've named myself CommunistPancake since 2009. No harm has come of it, the worst thing that has happened was when I got kicked from a CS:S server for having a "political username" [editline]2nd March 2012[/editline] Also, what about a C# from scratch SMTP server? Discreet, doesn't require login info.
[QUOTE=supersnail11;34962783]Also, what about a C# from scratch SMTP server? Discreet, doesn't require login info.[/QUOTE] Uh, why?
[QUOTE=dajoh;34962990]Uh, why?[/QUOTE] Like instead of contacting smtp.gmail.com and giving it login info, just write your own simple smtp server that only supports what you need it to support (no error checking, no verification). You can obfuscate it all you want and you don't have to put any login details in the application.
[QUOTE=supersnail11;34963050]Like instead of contacting smtp.gmail.com and giving it login info, just write your own simple smtp server that only supports what you need it to support (no error checking, no verification). You can obfuscate it all you want and you don't have to put any login details in the application.[/QUOTE] Or you could just not give it any login info? It's not required.
Sorry, you need to Log In to post a reply to this thread.