Facebook tricks, Windows trick, Google trick, Internet hacking, Ethical Hacking, gmail tricks, Technological news, Software Crack, Mobile Tricks, Blogging Trick, ebay Trick, Computer program, LAN hacking, WAN hacking, cookies stealing, Email Tracing
The Daily App Deals post is a round-up of the best app discounts of the day, as well as some notable mentions for ones that are on sale.
Splashtop Remote Desktop (Amazon Appstore) Previously $4.99, now $1.99. Splashtop Remote Desktop for Android allows you to take control of your home computer via your Android device. Want to listen to music stored on your computer on your Android device while you commute? Open the app and listen to your music via 3G/4G. Need to go over a Word document that is only stored on your computer? Just open the app and your good to go. Get it for $1.99. (via Apps-aholic)
In today's world, It becomes necessary for us to monitor our own computer or a remote computer to keep track of the activities going on. This may be for several reasons. Especially it is most necessary for the parents to monitor their computer to keep track of their children’s activities during their absence. Some people may also require to monitor their computer to keep an eye on the activities of their spouse or partner.
Today, with the advancement in the field of software technology, it is possible to easily monitor any given computer. For this all you have to do is, use a PC Monitoring Software.
But the job doesn’t end here. This is because, there exists tons of such monitoring softwares on the market and many times people often get confused which one to choose and how to use them. So I have decided to make this job simpler for you, by writing this post. In this post I’ll give a detailed information about computer monitoring softwares which include their features, advantages, usage and so on.
What exactly is a Monitoring Software and how can it help me ? A computer monitoring software is just like any other software (program) which when installed, secretly monitors each and every activity that takes place on the computer. The activities such as web browsing, chatting, gaming etc. are all recorded and saved. These monitoring softwares can record each and every keystroke. So it is possible to capture usernames and passwords very easily with minimum effort. Monitoring softwares are also commonly known as Keyloggers.
How can i install a spyware keylogger software? Installing a spyware keylogger software is very simple,even a person with basic knowledge of computer can use and monitor each and every activity that takes place on the computer.You need to setup a secret password and hotkey combination which is required later to see the recorded data ( logs). After the installation is complete the software goes invisible,once the software gets installed it will sent you recorded data(logs) and screen shots of the activities that takes place on your computer.
Which spyware keylogger software to choose? There exists different types of these software's, you have to choose the one that best match your needs. Here is a list of some of the best monitoring programs that I recommend.you to use
For monitoring your own PC (Local Pc) If you want to monitor your own PC, i recommend the following spyware software:
SpyAgent Editor rating Rating ( 9/10 ) SpyAgent is our award winning, powerful computer spy software that allows you to monitor EVERYTHING users do on your computer - in total stealth. SpyAgent provides a large array of essential computer monitoring features, as well as website, application, and chat client blocking, lockdown scheduling, and remote delivery of logs via email or FTP. SpyAgent will put your mind at ease with its innovative and unmatched, yet easy to use feature-set that provides the ultimate all-in-one computer monitoring software package.
For more information and download details please visit the following link
For monitoring a Remote PC (Also works on local PC) If you want to monitor a Remote PC then the following softwares are Recommended Editor rating Rating ( 9/10 )
Spy on a Remote PC and expose the truth behind the lies! Unlike the rest, SniperSpy allows you to remotely spy any PC like a television! Watch what happens on the screen LIVE! The only remote PC spy software with a SECURE control panel!
This Remote PC Spy software also saves screenshots along with text logs of chats, websites, keystrokes in any language and more. Remotely view everything your child, employee or anyone does while they use your distant PC. Includes LIVE admin and control commands!
Editor Rating ( 7/10 )
Winspy keylogger is a Complete Stealth Monitoring Package that can spy on both your Local PC and Remote PC. It includes Remote Install and Real time Remote PC Viewer. Win Spy Software will capture anything the user sees or types on the keyboard. A special hotkey is used to login and access the program. Users will not be able to terminate or uninstall Win-Spy. Win-Spy Software operates in stealth mode. It will not appear in Windows Start, System Tray, Desktop, Task Manager or Add/Remove Programs.
If money is not your concern and if your looking to buy the best SYPWARE then go with Sniperspy If your looking for a compact and cheaper one they i suggest you to go with Win spy, its very cheap when compared to Sniperspy,
For Monitoring a Network: The following program can be used to monitor an Entire Network of computers from one central location. This becomes handy to monitor the staff in a company or students in a school/college.
Netvizor NetVizor is network monitoring software that invisibly monitors your entire network from one central location! Track workstations and users that may use multiple PC's on your network. Deploy NetVizor from one location and record everything users do, including screenshots, keystrokes typed, program and internet usage, emails and chats, file/document usage, and much more. Generate detailed activity reports in seconds, view your entire network in real-time, and receive instant behavior alerts when
This software becomes handy if you want to monitor an entire network including your offices,school etc. You can test this product by downloding its trial version.
For more information and download details please visit the following link
For Monitoring a Mac OS I get lots of question regarding Spyware keylogger that, Do they work on Mac OS the answer is know,the above softwares wont wok on Mac os, For Mac OS We recommend the following software
Sniperspy-Mac (No physical access Required )
Editor Rating ( 9/10 )
Are you worried how others might use your Mac OS X computer? Expose the truth behind the lies! SniperSpy is the only software that allows you to secretly watch your Macintosh like a television! Login from ANYWHERE using another computer, smart phone or iPad.After you install this program to the Mac you wish to monitor, it begins silently recording everything they do online. The program then uploads user activities and sends the data to your online account. You login to your accountusing your own password securely to view logs and view their screen LIVE and see everything they do online in real time!
Features: Captures Actual Screenshots and Websites VisitedLogs Keystrokes and Full Chat ConversationsLocation Mapping and more ..
Keyloggers or Sypware are software's which captures keystrokes typed by the victim and thus commonly used for hacking victims email passwords Face book, paypal accounts.. etc Remotely, If your new to keyloggers kindly read my previous article What are Keyloggers
So far i've Reviewed and recommended various remote keyloggers and spy ware, but many of my blog readers still get confused on which remote keylogger they have to choose. I get a lot of emails and comments asking me which keylogger should i choose ? Which is the best keylogger ? etc..
So i decided write this article so as to help readers choose a key logger according to their needs , Before i start i want to say this to every reader who's reading this Every Keylogger has its own Pros and cons. So you have to keep three things in mind before you buy a keylogger Features and compatibility Performance and its stealth capabilities Money - cost of the keylogger Whats A Remote Keylogger /Spyware ? When it comes to Buying a Keylogger /Spyware most people get confused and Finally end up buying the wrong Sypware, There are plenty of Keyloggers in the market most of which are used for monitoring their Local PC and Not for spying remote computers, A very Handful of Key loggers have remote installation features in them and can be used to monitor remote PC, If Your looking to Monitor, hack email, Facebook accounts ..etc, remotely with out any physical access. Then you have to go with Remote Keyloggers
Following are some of the Best Remote Keyloggers that we recommend our readers to use
Keyloggers and Sypware For Windows Sniper Spy (No physical access Required )Editor rating Rating ( 9/10 )
Spy on a Remote PC and expose the truth behind the lies! Unlike the rest, SniperSpy allows you to remotely spy any PC like a television! Watch what happens on the screen LIVE! The only remote PC spy software with a SECURE control panel!
This Remote PC Spy software also saves screenshots along with text logs of chats, websites, keystrokes in any language and more. Remotely view everything your child, employee or anyone does while they use your distant PC. Includes LIVE admin and control commands!
Features: SniperSpy is remotely-deployable spy softwareCompletely Bypasses any FirewallInvisibility Stealth Mode Option. Works in complete stealth mode Undetectable!Logs All Keystrokes and Records any Password (Email, Login, Instant Messenger etc.) and more ..Editor Rating ( 7/10 )
Winspy keylogger is a Complete Stealth Monitoring Package that can spy on both your Local PC and Remote PC. It includes Remote Install and Real time Remote PC Viewer. Win Spy Software will capture anything the user sees or types on the keyboard. A special hotkey is used to login and access the program. Users will not be able to terminate or uninstall Win-Spy. Win-Spy Software operates in stealth mode. It will not appear in Windows Start, System Tray, Desktop, Task Manager or Add/Remove Programs.
Win Spy Features: Remote Monitor any EmailRemote Monitor children’s activity and Cheating Spouse Records any Password and Monitor Remote PC WebcamIts Totally Stealth (i.e) Totally undetectable Editor Rating ( 8/10 )
Realtime Spy is the latest in cutting-edge remote spy software monitoring technology that allows you to monitor ANY PC you own from ANYWHERE. Realtime-Spy is remotely installable (no physical installation needed), and its activity logs are accessible from anywhere - regardless if the remote PC is online or not.All you have to do is point your browser to your own Realtime-Spy website address to view logs from any machines you deploy Realtime-Spy on! Real-time Activity and Keystrokes Viewing Captures Keystrokes Typed ,Desktop Screenshots and Chat ConversationsLogs E-mails typed ,Websites Visited and Passwords typed
As i said earlier you have to keep three things in mind cost , performance, features and stealth capabilities If money is not your concern and if your looking to buy the best keylogger then go with Sniperspy If your looking for a compact and cheaper one they i suggest you to go with either win spy or real time spy i always recommend Winspy since it has some extra features like remote webcam, and its also cheap and very easy to use
Are you worried how others might use your Mac OS X computer? Expose the truth behind the lies! SniperSpy is the only software that allows you to secretly watch your Macintosh like a television! Login from ANYWHERE using another computer, smart phone or iPad.After you install this program to the Mac you wish to monitor, it begins silently recording everything they do online. The program then uploads user activities and sends the data to your online account. You login to your accountusing your own password securely to view logs and view their screen LIVE and see everything they do online in real time!
Features: Captures Actual Screenshots and Websites VisitedLogs Keystrokes and Full Chat ConversationsLocation Mapping and more ..
Keyloggers and Spyware For Linux
THC-vlogger THC-vlogger, an advanced Linux kernel based keylogger, enables the capability to log keystrokes of all administrator/user's sessions via console, serial and remote sessions (Telnet, SSH), switching logging mode by using magic password, stealthily sending logged data to centralized remote server. Its smart mode can automatically detect password prompts to log only sensitive user and password information.
LKL Linux KeyLogger LKL is a user space keylogger that runs under Linux on the x86 arch. LKL sniffs and logs everything that passes through the hardware keyboard port (0x60). It translates key codes to ASCII with a key map file. Since both the Keylogger are free you can use both , Both have the same features ,So what are you waiting for download and use them, And see which is the best yourselves
Hardware Keyloggers Software Key loggers are not the only keyloggers that are used for hacking email or face book accounts, there's an other type of keyloggers and they are called Hardware keyloggers.Hardware Keyloggers are used for keystroke logging, a method of capturing and recording computer user keystrokes. They plug in between a computer keyboard and a computer and log all keyboard activity to an internal memory. They are designed to work with PS/2 keyboards, and more recently with USB keyboards
Why Hardware Keyloggers? If you have physical access to a computer then i would surely recommend you to use hardware keyloggers as there are countless number of reasons for it ,Since its attached with a keyboard most anti viruses don't pick them up, Hardware keyloggers are Compatible with all operating systems
KeyCobra Editor rating Rating ( 9/10 )
KeyCobra is the world's smallest and smartest USB hardware keylogger. The KeyCobraUSB keyboard logger comes in a standard version (4MB memory capacity which can capture 2,000,000 keystrokes - over 1,000 pages of text), and a Venom Version (2GB memory capacity -which can capture billion keystrokes - over 1 million pages of text), Its Completely invisible for computer operation, It is also compatible with Mac.Visit the official website of KeyCobra Hardware Keylogger for more details
Hope this info help you in selecting your Keylogger, If You have any Doubts Regarding the software's please Let us Know via comments
This paper demonstrates unique kind of communication technique between attacker machine and victim machine during the exploitation of any victim system. Usually, while an attacker exploits the remote system and gets the remote command prompt (remote shell), attacker is only able to execute commands till the session from the remote machine is opened (established). While exploiting the system in a normal way, attacker and the victim system both should be online, if attacker wants to execute some commands in remote machine (Victim Machine). This paper would demonstrate how an attacker can attack a remote victim without being online (attacker may or may be online AND victim may or may not be online).
History During the exploitation of vulnerable remote system (victim system) by an attacker, after vulnerability injection, attacker sends payload and gets remote command prompt on his/her (attacker’s) machine. In this case of normal payload, the limitation for an attacker is that, once the session is expired or shell is terminated, attacker can’t execute commands in remote machine (victim computer).This white paper demonstrates new type of payload by using which attacker can execute command in remote machine (victim system) without actually directly connecting to victim machine and also fooling Antivirus, Firewalls etc.
My Method In general scenario, if attacker gets remote command prompt and execute command in the current session then there is direct communication (connection) between attacker and victim machine. But by using this paper’s mechanism we can prevent direct communication (connection) between attacker and victim. For this, we use an intermediate server (zombie) that should be up and running all the time (24x7). In our case, we use this zombie as an email service like Gmail, Yahoo, msn etc. So the whole system works as explained below.
Attacker infects remote system with an Executable, which can be infected by one of the below mentioned methods:
By autorun.infDuring Metasploit ExploitationPhysical access of victim system
Now once Executable is up and running in the remote machine (Victim Machine), when the victim connects to the internet then it first checks the instruction set in Gmail inbox by an attacker. Now let’s say if an attacker wants to execute command ‘ipconfig’ in remote machine (victim machine) then attacker has to send email with subject ‘ipconfig’ to his own email address . Because the username and password is already encrypted in the Executable file in the victim machine (remote machine ), and as victim comes online , that executable file automatically logs in your Gmail account and reads all command instructions which is loaded by attacker.
It executes the commands of attacker’s choice and attaches these results to the attacker’s Gmail account. Attackers simply have to download that attachment which contains command output from victim machine. So there is an email service (Gmail) between attacker and victim machine. That shows, attacker can execute command in victim system but there is no direct connection between attacker and victim machine, and if an attacker uses Tor (The Onion Router Browser) or Anonymizers for accessing the Gmail account then attacker never can be caught (no reverse traces). It is something like Attacker <->email service <->Victim <->. So life cycle will be as shown below:
Attacker <--> Proxy <--> Email Service <--> Victim
(Tor, Anonymizers) (Gmail, Yahoo, etc.) (Proxy Case Scenario)
Hands-on-Approach
Stage I
Let’s say you have infected remote system with this exe and you want account info, drive info and network info from the remote machine (victim machine) then you have to send email to your own account (note: which is also listened and shared by injected exe in remote victim machine) with subject containing account_info, driveinfo, networkinfo as shown in the figure on the next page.
Stage II
Now once the email with appropriate subject is sent to your account, now it’s time for remote machine (victim machine) to be online and fetch the instruction given by intruder (in this approach, “Attacker”). As the victim system comes online, it executes appropriate commands of attacker’s need, redirect command output to .data file and finally automatically attach this file to your email account. Hence, by simply downloading this file you will get all the cmd output in attached .data file as shown in below figure.
Here in the above figure you can clearly see that, all required outputs are attached in your email address!
Advantages
Advantages are that the attacker is never going to be caught if he/she is using the browser like TOR, Anononymizer, VPNs or Any PROXY…. For accessing the attacking Gmail account.No Antivirus can detect the Instruction data because all traffic would come from HTTPS And Antivirus Softwares and Network Intrusion Detection Software Detects simply an outbound connection with GMAIL...!Only a single Gmail account is required. Attacker and victim machine both would be connected to the same account but the attacker knows, and the victim doesn’t!!
Disadvantages Disadvantage is that, if the victim has a habit of checking the current connections using commands like ‘netstat –n’, then there is a possibility to detect Gmail connection when actually there is no browser activity. But still it is difficult to detect because process is running in Hidden mode.
Conclusion So by using above technique, attacker has to send commands as a subject to his/her own email address and then it is fetched and executed in victim machine by executable file running in victim machine. And results of that commands are sent back to the attacker’s email account as an attachment. So there is no need to be online for both attacker and victim. And Anti-viruses and Firewalls going to bypass using this technique because Av and Firewall notice that victim system connects to the Gmail (not actually connects to attacker machine for transferring data) and it uses HTTPS encryption of Gmail for transferring the data (no chance of signature based detection because of HTTPS), so they don’t find any threats for victim machine, so no security alarms!
Remote Thread Execution in System Process using NtCreateThreadEx for Vista & Windows 7 | ClubHACK Magazine Skip to Main Content Area ClubHACKAbout UsTeamPartnersContributorsAuthorsArchives Contact UsSubscribeRSSAdvertise HomeTech GyanLegal GyanTool GyanMom's GuideSpecial FeatureMatriux VibhagPosterDownloadsDownload PDF Home Remote Thread Execution in System Process using NtCreateThreadEx for Vista & Windows 7
Windows provides API function called, CreateRemoteThread Ref 2 which allows any process to execute thread in the context of remote process. This method has been mainly used to inject DLL into remote process, this technique is popularly known as 'DLL Injection'. Especially malware programs exploited this mechanism to evade their detection by injecting their DLL into legitimate processes such as Explorer.exe, Winlogon.exe etc.
Vista & Session Separation
This DLL Injection technique using CreateRemoteThread technique has worked flawlessly till Vista without any limitations. However since Vista onwards things have changed with the introduction of 'Session Separation'Ref 3. This was one of the many defenses introduced in Vista towards securing the system. 'Session Separation' ensured that core system processes including services always run in session 0 while all user process's run in different sessions. As a result any process running in user session failed to inject DLL into system process as CreateRemoteThread did not work across session boundaries.
This is clearly evident from the MSDN documentation of CreateRemoteThread Ref 2 function...
"Terminal Services isolates each terminal session by design. Therefore, CreateRemoteThread fails if the target process is in a different session than the calling process."
About NtCreateThreadEx Function
With the failure of CreateRemoteThread, there was a need for universal solution for remote thread execution on Vista and Windows 7 platform. Then comes the function, NtCreateThreadEx Ref 1, the undocumented function which provides complete solution for executing remote thread across session boundaries. It allows any process to inject DLL into any other process irrespective of the session in which it is running as long as it has sufficient privileges.
Here is the prototype of NtCreateThreadEx function [undocumented]
typedef NTSTATUS (WINAPI *LPFUN_NtCreateThreadEx) ( OUT PHANDLE hThread, IN ACCESS_MASK DesiredAccess, IN LPVOID ObjectAttributes, IN HANDLE ProcessHandle, IN LPTHREAD_START_ROUTINE lpStartAddress, IN LPVOID lpParameter, IN BOOL CreateSuspended, IN ULONG StackZeroBits, IN ULONG SizeOfStackCommit, IN ULONG SizeOfStackReserve, OUT LPVOID lpBytesBuffer);
This function is almost similar to CreateRemoteThread function except the last parameter which takes unknown buffer structure. Here is the definition of that buffer structure parameter...
This information is derived based on reverse engineering work. Hence meanings and importance of internal fields of this buffer structure is not clear.
Executing Remote Thread into System Process using NtCreateThreadEx
FunctionThe steps involved in the execution of the remote thread using NtCreateThreadEx is almost similar to that of CreateRemoteThread function. Hence the traditional steps such as allocating memory, copying the thread code into remote process are not repeated here. For detailed steps you can refer to article, "Three Ways to Inject Your Code into Another Process" Ref 4.
Before we begin, we need to load NtCreateThreadEx function from Ntdll.dll as shown below.
HMODULE modNtDll = GetModuleHandle("ntdll.dll"); if( !modNtDll ){ printf("\n failed to get module handle for ntdll.dll, Error=0x%.8x", GetLastError()); return;}LPFUN_NtCreateThreadEx funNtCreateThreadEx = (LPFUN_NtCreateThreadEx) GetProcAddress(modNtDll, "NtCreateThreadEx");if( !funNtCreateThreadEx ){ printf("\n failed to get funtion address from ntdll.dll, Error=0x%.8x", GetLastError()); return;}
Now setup the buffer structure which is passed as last parameter to NtCreateThreadEx function.
Finally execute remote thread 'pRemoteFunction' into remote process using NtCreateThreadEx function. Here one can use 'LoadLibrary' function address instead of 'pRemoteFunction' thread to implement 'DLL Injection' technique.
NTSTATUS status = funNtCreateThreadEx( &hThread, 0x1FFFFF, NULL, hProcess, (LPTHREAD_START_ROUTINE) pRemoteParameter, pRemoteParameter, FALSE, //start instantly NULL, NULL, NULL, &ntbuffer);Now check for the result of NtCreateThreadEx function and then wait for it to execute completely. if (hThread == NULL){ printf("\n NtCreateThreadEx failed, Error=0x%.8x", GetLastError()); return;}//Wait for thread to complete....WaitForSingleObject(hThread, INFINITE);
Finally retrieve the return value from the remote thread function, 'pRemoteFunction' to verify the result of function execution.
//Check the return code from remote thread function int dwExitCode;if( GetExitCodeThread(hThread, (DWORD*) &dwExitCode) ){ printf("\n Remote thread returned with status = %d", dwExitCode);} CloseHandle(hThread);
The steps illustrated above are almost similar except that here NtCreateThreadEx is used instead of CreateRemoteThread for creating thread in the context of remote process
Limitations of NtCreateThreadEx Method
Though NtCreateThreadEx provides universal solution on Vista/Win 7 platform for remote thread execution, it is risky to use in the production code as it is an undocumented function. As things may change with new version and suppor packs, enough testing is necessary before putting it into production especially when injecting code into system critical process such as LSASS.EXE, CSRSS.EXE.
Another limitation is that it cannot be used in earlier platforms before Vista, such as Windows XP because NtCreateThreadEx function is available only Vista onwards. However developers can easily tune their code to dynamically use CreateRemoteThread function on XP and NtCreateThreadEx for Vista/Windows 7.
Alternative Techniques
Another way to inject DLL into system process is to write the service process (which will run in session 0) and then issue the command from user process to that service to inject DLL into any system process using the CreateRemoteThread function.
This technique will work for any system process running in session 0. But it will fail to execute thread into any other process running in session other than 0.
Though it is a clumsy way of doing the work, it still holds good solution to inject thread into system process only.
Conclusion
This article provides practical implementation of using NtCreateThreadEx function to execute remote thread into any process on Vista/Windows 7 platform. Though it is undocumented function, it provides universal solution for executing code in any process across session boundaries imposed by Vista/Windows 7.
ReferencesNtCreateThreadEx FunctionMSDN Documentation of CreateRemoteThread FunctionImpact of Session 0 Isolation on ServicesThree ways to inject code into remote processAbout The AuthorNagareshwar is a security professional with the unbeaten passion towards Computer Security, mainly involved in Reverse Engineering, Security Research and developing Security Tools. He holds engineering degree in Computer Science from National Institute of Technology of Karnataka, Surathkal (KREC), India. He has professional experience of around 6+ years spanning across Novell & Citrix where he has worked on security and application virtualization technologies.
Microsoft VistaMicrosoft WindowstechGyanTerminal ServicesWindows 7 Add new comment Author CHMag Collector's Edition Vol II