Articles

Metasploit Framework Windows Tutorial
Remote Desktop Connection
Windows Processes That May Be Dangerous
How-To use NetCat a Tutorial
Common Linux Commands
Common Ports
Netcat Commands
HTTP Response Codes
War-Google Hack Terms
Wardriving
Avoiding Social Engineering and Phishing Attacks
Intrusion Detection on Linux
Linux Intrusion Detection
Penetration Testing Guide
Penetration Testing Tools
Social Engineering Fundamentals, Part I: Hacker Tactics
Social engineering (computer security)
The Psychology of Social Engineering

The Archives

General GSO
GovernmentSecurity.org News & Suggestions
In The News
Open Topic
General Security Information
Trash Can
Exploit & Vulnerability Mailing List Archives
Trial Member Forum
Product and Program Reviews GSO Tutorials
System Security
Windows Systems
Beginners Section
Linux & Unix Systems
File Downloads
Exploit Research & Discussion Trojan & Virus Errata
Networking Security / Firewall / IDS / VPN / Routers
System Hardening
E-Mail Security
Wifi Security
Trial Member Uploads
Upload discovered Trojans & Mal ware
GSO Programming Section
C , C++ , VC++
Visual Basic.NET
Perl /CGI
Java/Javascript
PHP/XML/ASP/HTML
Assembly + Other
The Cork Board
Network Security Consultant Directory
Network Security Jobs
The Archives
Encryption Information
General Network Security
Internet Anonymity
HTTP Protocol Security
Linux Security
MS IIS Information
Exploit Articles
Programming / Tool Design
GSO Software Projects
Public Downloads
Microsoft Security Questions and Papers

Full Version: Little Nice Tool
andi1983
usage:
[command] <parameter1> <parameter2> ...
commands:
sysinfo - shows system informations
cadmin - create an admin user
plist - shows running processes
pkill - kills a process
pmod - lists the loaded modules of a process
pexec - executes a command line
pexecp - executes a command line (setable parent by process id)
pexecp2 - executes a command line (setable parent by process name)
injmod - loads a dll into a process (by process id)
injmod2 - loads a dll into a process (by process name)
freemod - frees a dll in a process
sysmod - list the loaded system kernel modules
freesmod - frees a loaded system kernel module
hclose - closes a handle in a process
infect - modifies an exe file to load a specified dll file on start
slist - shows services
sstart - starts a service
sstop - stops a service
sdelete - removes a service
sstrcfg - sets a service startup config
sdspcfg - sets a service display name
sdesccfg - sets a service description
lads - lists the alternate data streams of files in a directory
dir - lists a directory content
mkdir - creates a directory
rmdir - removes a directory
tag - "tags" a directory
copy - copies a file into another (also ntfs streams)
copydriv - same as copy but in ring0/driver
filetime - sets a file creation and last write time
specdacl - forbids access to a filder except of one user (e.g. system)
eregval - enumerates values of a registry key
dregval - deletes a registry value
dregkey - deletes a registry key
autorun - adds a registry autorun
evtlog - clears the system event log (NOT logfiles!)
shutdown - shutdowns windows
fservu - finds the serv-u process
ports - shows LISTENING ports
wfp - terminates the Windows File Protection worker thread
wfp2 - disables the Windows File Protection of the system directory
wfpboot - disables the Windows File Protection boot scan
pwdcache - displays the cached passwords in winlogon (Win2k)
pwdump - displays the user password hashes of the SAM database
secdump - displays the lsa secrets
download - downloads a file from an url
cfg - change hackingtools config
dummyp - runs a dummy process and loads a dll
pmem - searches value(s) in virtual memory of a process
email - send a email with or without an attachment
scrcap - captures the screens
ownz - shows a penetrating screen for some time
rdaemon - register an daemon service
cdaemon - change a daemon config file (don't use with other services)
_sdaemon - <daemon service routine - don't use>
help - shows this help
--------------------------------------------------------------------------------
as you see it has alot of usefull functions

-plist shows all hidden processes by rootkits
-download u can download files from http
-sysinfo gives you a complete sysinfo

i never tried out all function

have fun ph34r.gif
Killaloop
I could be wrong, but if the autor of a tool would like to have it public he would most likely put it here on his own.
I'm almost sure scriptgod is the autor of this, could be wrong though
Pro21
yes sure but nice tool smile.gif
andi1983
QUOTE(Killaloop @ Aug 11 2005, 03:49 PM)
I could be wrong, but if the autor of a tool would like to have it public he would most likely put it here on his own.
I'm almost sure scriptgod is the autor of this, could be wrong though
*




as u see it is about 1 year old and u cant imaginge how many people this have, so i decided to offer it here.
MxMx
yeahh this tool can be used by ( pro-scriptkiddies ) to infect system processes like services.exe with their servu files to help them hide their files from the admin.. or ya can import a dll backdoor into a root processes.. after this being said, I really hope an admin is smart enough to delete this file from the board.

Greetings
tweakz20
QUOTE(MxMx @ Aug 11 2005, 06:12 PM)
yeahh this tool can be used by ( pro-scriptkiddies ) to infect system processes like services.exe with their servu files to help them hide their files from the admin.. or ya can import a dll backdoor into a root processes.. after this being said, I really hope an admin is smart enough to delete this file from the board.

Greetings
*



An admin should not have to delete the file from this board, hopefully everyone here will not become a "pro-scriptkiddie" and cause havoc across networks everywhere.
ttfella
hackin tool by script god
EzMe
QUOTE(ttfella @ Aug 12 2005, 01:38 AM)
hackin tool by script god
*



Well.. that wasn;t very hard to find out was it..?

CODE

+---------------------------+
| HackingTools by ScriptGod |
+---------------------------+
|        [17.11.04]         |
+---------------------------+
ttfella
indeed it wasnt
passi
Hey why are you all beeing that asslike? The guy postet a very good application that can come very handy, so stop it... mad.gif ffs

Thank you for this very handy tool smile.gif
FuzZyBeeR
yeh thanx for sharing this, either for the people who use it, or the people who want to know what the program does, so they can defend against it. thanx for sharing!
krazie
realy n1 tool, works fine for me on winxp, 2k.
infect option is very good, never seen bevor biggrin.gif
thanks 4 sharing
DumpZ
QUOTE(andi1983 @ Aug 11 2005, 05:17 PM)
QUOTE(Killaloop @ Aug 11 2005, 03:49 PM)
I could be wrong, but if the autor of a tool would like to have it public he would most likely put it here on his own.
I'm almost sure scriptgod is the autor of this, could be wrong though
*





as u see it is about 1 year old and u cant imaginge how many people this have, so i decided to offer it here.
*



QUOTE(passi @ Aug 14 2005, 06:10 PM)
Hey why are you all beeing that asslike? The guy postet a very good application that can come very handy, so stop it...  mad.gif  ffs

Thank you for this very handy tool smile.gif
*




Well thats besides the point how would you like it if you wrote something nice and someone else would spread it without giving credit.
Killaloop
exactly
and because of the fact that scriptgod is member of this board and he did NOT post his tool, what do you ever think about posting it here and don't give him credits or anything else?
I would not like it, if I give some unique tool to some friends and someone just posts it on a public place without asking me and without giving any credits.
the overall point is, that he is member here and did not post his tool, so who do you think you are if you post it without asking?
no respect left nowadays, its a shame
GSecur
This post is not following the rules and has been trashed.



Review the rules for the forum located here. Or you may run the risk of your account being deleted.
This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please click here.
Invision Power Board © 2001-2005 Invision Power Services, Inc.