Likes Likes:  0
Resultaten 1 tot 5 van de 5
Geen
  1. #1
    ViPeR
    MSN Messenger Password Decrypter for WinXP/2003
    Gast
    n/a Berichten
    Berichten zijn liked



    Thread Starter

    MSN Messenger Password Decrypter for WinXP/2003

    MSN Messenger uses Windows Credential UI [credui.dll]
    on WinXP/2003. Password-Storage mechanism differs in
    these OSes so, the code posted by tombkeeper
    [http://xfocus.net/articles/200408/726.html] doesn't
    seem to work anymore on my OS atleast. Also, a
    'entropy' value has been thrown, which is based on
    credui.dll GUID.

    So, here is the code that fullfils the same purpose -
    but surely works on my OS [WinXP SP2]

    /--- Start-Code --/

    /*
    * MSN Messenger Password Decrypter for Windows XP &
    2003
    * (Compiled-VC++ 7.0, tested on WinXP SP2, MSN
    Messenger 7.0)
    * - Gregory R. Panakkal
    * http://www.crapware.tk/
    * http://www.infogreg.com/
    */

    #include <windows.h>
    #include <wincrypt.h>
    #include <stdio.h>

    #pragma comment(lib, "Crypt32.lib")


    //Following definitions taken from wincred.h
    //[available only in Oct 2002 MS Platform SDK /
    LCC-Win32 Includes]

    typedef struct _CREDENTIAL_ATTRIBUTEA {
    LPSTR Keyword;
    DWORD Flags;
    DWORD ValueSize;
    LPBYTE Value;
    }
    CREDENTIAL_ATTRIBUTEA,*PCREDENTIAL_ATTRIBUTEA;

    typedef struct _CREDENTIALA {
    DWORD Flags;
    DWORD Type;
    LPSTR TargetName;
    LPSTR Comment;
    FILETIME LastWritten;
    DWORD CredentialBlobSize;
    LPBYTE CredentialBlob;
    DWORD Persist;
    DWORD AttributeCount;
    PCREDENTIAL_ATTRIBUTEA Attributes;
    LPSTR TargetAlias;
    LPSTR UserName;
    } CREDENTIALA,*PCREDENTIALA;

    typedef CREDENTIALA CREDENTIAL;
    typedef PCREDENTIALA PCREDENTIAL;

    ////////////////////////////////////////////////////////////////////

    typedef BOOL (WINAPI *typeCredEnumerateA)(LPCTSTR,
    DWORD, DWORD *, PCREDENTIALA **);
    typedef BOOL (WINAPI *typeCredReadA)(LPCTSTR, DWORD,
    DWORD, PCREDENTIALA *);
    typedef VOID (WINAPI *typeCredFree)(PVOID);

    typeCredEnumerateA pfCredEnumerateA;
    typeCredReadA pfCredReadA;
    typeCredFree pfCredFree;

    ////////////////////////////////////////////////////////////////////

    void showBanner()
    {
    printf("MSN Messenger Password Decrypter for
    Windows XP/2003\n");
    printf(" - Gregory R. Panakkal,
    http://www.infogreg.com \n\n");
    }

    ////////////////////////////////////////////////////////////////////
    int main()
    {
    PCREDENTIAL *CredentialCollection = NULL;
    DATA_BLOB blobCrypt, blobPlainText, blobEntropy;

    //used for filling up blobEntropy
    char szEntropyStringSeed[37] =
    "82BD0E67-9FEA-4748-8672-D5EFE5B779B0"; //credui.dll
    short int EntropyData[37];
    short int tmp;

    HMODULE hDLL;
    DWORD Count, i;

    showBanner();

    //Locate CredEnumerate, CredRead, CredFree from
    advapi32.dll
    if( hDLL = LoadLibrary("advapi32.dll") )
    {
    pfCredEnumerateA =
    (typeCredEnumerateA)GetProcAddress(hDLL,
    "CredEnumerateA");
    pfCredReadA =
    (typeCredReadA)GetProcAddress(hDLL, "CredReadA");
    pfCredFree =
    (typeCredFree)GetProcAddress(hDLL, "CredFree");

    if( pfCredEnumerateA == NULL||
    pfCredReadA == NULL ||
    pfCredFree == NULL )
    {
    printf("error!\n");
    return -1;
    }
    }


    //Get an array of 'credential', satisfying the
    filter
    pfCredEnumerateA("Passport.Net\\*", 0, &Count,
    &CredentialCollection);


    if( Count ) //usually this value is only 1
    {

    //Calculate Entropy Data
    for(i=0; i<37; i++) //
    strlen(szEntropyStringSeed) = 37
    {
    tmp = (short int)szEntropyStringSeed[i];
    tmp <<= 2;
    EntropyData[i] = tmp;
    }

    for(i=0; i<Count; i++)
    {
    blobEntropy.pbData = (BYTE *)&EntropyData;
    blobEntropy.cbData = 74;
    //sizeof(EntropyData)

    blobCrypt.pbData =
    CredentialCollection[i]->CredentialBlob;
    blobCrypt.cbData =
    CredentialCollection[i]->CredentialBlobSize;

    CryptUnprotectData(&blobCrypt, NULL,
    &blobEntropy, NULL, NULL, 1, &blobPlainText);

    printf("Username : %s\n",
    CredentialCollection[i]->UserName);
    printf("Password : %ls\n\n",
    blobPlainText.pbData);
    }
    }

    pfCredFree(CredentialCollection);
    }

    /--- End-Code --/

    URL :
    http://www.infogreg.com/source-code/...-and-2003.html

    rgds,
    Gregory R. Panakkal







    __________________________________________________ __
    Send a rakhi to your brother, buy gifts and win attractive prizes. Log on to http://in.promos.yahoo.com/rakhi/index.html

  2. #2
    kuku@kuku.com
    MSN Messenger Password Decrypter for WinXP/2003
    Gast
    n/a Berichten
    Berichten zijn liked



    Thread Starter

    Re: MSN Messenger Password Decrypter for WinXP/2003

    Doesn't work anymore in 7.5. This tool works though:
    http://www.msn-password-recovery.com

  3. #3
    James_gmail-ij
    MSN Messenger Password Decrypter for WinXP/2003
    Gast
    n/a Berichten
    Berichten zijn liked



    Thread Starter

    Re: MSN Messenger Password Decrypter for WinXP/2003

    On 13 Jan 2006 00:51:37 -0000, kuku@kuku.com <kuku@kuku.com> wrote:
    > Doesn't work anymore in 7.5. This tool works though:
    > http://www.msn-password-recovery.com
    >

    File: =09 MSN-Password-Recovery.exe
    Status: =09
    MIGHT BE INFECTED/MALWARE (Sandbox emulation took a long time and/or
    runtime packers were found, this is suspicious. Normally programs
    aren't packed and don't force the sandbox into lengthy emulation. Do
    realize no scanner issued any warning, the file can very well be
    harmless. Caution is advised, however.) (Note: this file has been
    scanned before. Therefore, this file's scan results will not be stored
    in the database)
    MD5 =092784bee6f9bd768fb67dd5cb028345ad
    Packers detected: UPX

    The link on that site to the Skype recovery tool domain leads to a complete=
    ly
    unrelated ad for a website building software package

  4. #4
    frank boldewin
    MSN Messenger Password Decrypter for WinXP/2003
    Gast
    n/a Berichten
    Berichten zijn liked



    Thread Starter

    Re: MSN Messenger Password Decrypter for WinXP/2003

    This is a multi-part message in MIME format.

    ------=_NextPart_000_00A2_01C61BC3.46AA0CC0
    Content-Type: text/plain;
    format=flowed;
    charset="iso-8859-1";
    reply-type=original
    Content-Transfer-Encoding: 7bit

    the MSN-Password-Recovery.exe is a normal nullsoft installer.

    after installing the software there's one pe-file called:

    MSN Password Recovery.exe

    which is upx packed. after unpacking with upx -d

    i throwed it into IDA and had a short look for suspicious code snippets.

    funny is this one:

    ..text:004021AF call ebp ; SendDlgItemMessageA
    ..text:004021B1 push offset OutputString ; "Greetings to
    all reversers who reverse" ...
    ..text:004021B6 call OutputDebugStringA
    ..text:00401260 OutputString db 'Greetings to all reversers who reverse
    this program - it',27h
    ..text:00401260 db 's easier to make another program rather
    than brake ours!',0Ah




    basically it enums the creds and if it finds one, the tool looks eg. at:
    HKEY_CURRENT_USER\Software\Microsoft\IdentityCRL\C reds\username@blabla.com

    key psassword and it's values

    then decrypts with CryptUnprotectData() and shows you the password to the
    cred if you're a registered customer.

    but i really can't find malicious stuff in there, nor phone home stuff.

    with regards,

    frank





    > On 13 Jan 2006 00:51:37 -0000, kukukuku.com <kukukuku.com> wrote:
    > Doesn't work anymore in 7.5. This tool works though:
    > http://www.msn-password-recovery.com
    >
    > File: MSN-Password-Recovery.exe
    > Status:
    > MIGHT BE INFECTED/MALWARE (Sandbox emulation took a long time and/or
    > runtime packers were found, this is suspicious. Normally programs
    > aren't packed and don't force the sandbox into lengthy emulation. Do
    > realize no scanner issued any warning, the file can very well be
    > harmless. Caution is advised, however.) (Note: this file has been
    > scanned before. Therefore, this file's scan results will not be stored
    > in the database)
    > MD5 2784bee6f9bd768fb67dd5cb028345ad
    > Packers detected: UPX



    > The link on that site to the Skype recovery tool domain leads to a
    > completely
    > unrelated ad for a website building software package





    ------=_NextPart_000_00A2_01C61BC3.46AA0CC0
    Content-Type: image/gif;
    name="at.gif"
    Content-Transfer-Encoding: base64
    Content-Location: http://archives.neohapsis.com/imgs/at.gif

    R0lGODlhEgARAID/AMDAwAAAACH5BAEAAAAALAAAAAASABEAAAIrhI+pyxoPG3iOhX ariTkfD3aJ
    iJDfVp7ptHpqiGoctbjaaE95CdHSD1wUAAA7

    ------=_NextPart_000_00A2_01C61BC3.46AA0CC0--


  5. #5
    null@msn-pwd-recovery.com
    MSN Messenger Password Decrypter for WinXP/2003
    Gast
    n/a Berichten
    Berichten zijn liked



    Thread Starter

    Re: Re: MSN Messenger Password Decrypter for WinXP/2003

    Hi,
    This is the author of the MSN Messenger Password Recovery tool. Searched in google and found this post.
    I would like to assure you that this program is not dangerous and does not perform any illegal actions. All it does is read the registry values and decrypt them. What's wrong with using UPX?
    As far as the link at the bottom is concerned - we are in the process of making the Skype tool and will put a proper website in place once we are finished.
    Also, regarding you message that this program is malicious:

    http://www.softpedia.com/progClean/M...ean-32261.html

    MSN Messenger Password Recovery 1.1.100.2006 - SOFTPEDIA "100% CLEAN" AWARD
    This software product was tested in the Softpedia labs on: 18 January 2006

Webhostingtalk.nl

Contact

  • Rokin 113-115
  • 1012 KP, Amsterdam
  • Nederland
  • Contact
© Copyright 2001-2026 Webhostingtalk.nl.
Web Statistics