Saturday, February 26, 2011


I made this TuT Because many free crypting services are going around in this section. So many new members may get infected by others binding their Rats on their Server.


The point of This thread is to show you how you can find out if someone that has crypted your server has binded his server too.
So in this TUT we will be using Sandboxie to find out
You can find sandboxie here:
Spoiler (Click to Hide)
http://www.sandboxie.com/index.php?DownloadSandboxie
What sandboxie does is that it shoes you what a file opens and drops on your computer.It is secure cause it opens the files on an isolated space of your disc.

Before all We need to secure Our data Incase that he binded any Stealer that can steal our data and send them imediately
Pictures Below will explain

Supose we made our server and is all working good and we need to crypt it(making it FUD so Antiviruses wont detect it as a malicious program)
Here is Our server We chose to Inject Our server in Default Browser
[Image: 68785899.png]

Uploaded with ImageShack.us

We will now Open it in Sandboxie to see What does it execute and what does it drop
Here we see that Our Server Is runing and tha tit injects its self in Default browser as we Selected Before

Lets say we sent Our server to the guy that its gona crypt our server and gave us this file as the crypted fileNow IF you get any error Here He probably Used Antis ANd its probably Infected by his server

Now if we didnt Got any error how do we know that he didnt bind his server on ours ? This is what we are going to find out next. We are going to open the crypted file in Sandboxie again.We should again see Sandboxie runing,Our server,And that its gonna be injected in default Browser
[Image: werethefckthese2apeared.png]

Uploaded with ImageShack.us
This Means that he binded his Server on our server cause we see that it opens another 2 files that it shouldnt.

This is the end of the TUT Hope i helpedBlack Hat

No comments:

Unleash the Power of AI: AMD Ryzen 8000 Pro Processors Take Productivity to the Next Level

Get ready to supercharge your professional workflow with the arrival of the all-new AMD Ryzen 8000 Pro processors! Building upon the foun...