20CN网络安全小组第一代论坛
发表新主题  发表回复

个人资料 | 社区目录 用户登录 | | 论坛搜索 | 常见问题 | 论坛主页
  下一个最老的主题   下一个最新的主题
» 20CN网络安全小组第一代论坛   » 安 全 基 地   » 安全漏洞   » 国外一黑客网站BBS的一篇文章。。。(作者:theRIDDLER)

   
作者 标题: 国外一黑客网站BBS的一篇文章。。。(作者:theRIDDLER)
绝地苍狼
未注册


图标 1  发表于         编辑/删除帖子   引用原文回复  
PROOF POSITIVE: Microsoft has tried to keep the files secret.
I made a mistake in the way I presented my "really hidden" file findings. I should have been more informative about the methods Microsoft used to keep these files hidden. I apologize for opening another sub, but it's important.

The following "Strange Occurrences" (in order in which I found them) are proof-positive that Microsoft does not want you finding these files:

STRANGE OCCURRENCE 1:
1) Drop to DOS
2) DIR C:\WINDOWS\TEM*.*
3) DIR C:\WINDOWS\TEM*.* /AH

The only directory listed was the "TEMP" directory wasn't it? But we already know for sure there is a "Temporary Internet Files" directory so what gives?

What gives is that DOS is either incapable of listing the directory or has straight out LIED to you. Just to be sure I'm not dreaming this up type this:

4) CD\WINDOWS\TEMPOR~1

According to DOS you are now in a directory that doesn't exist.

STRANGE OCCURRENCE 2:
1) Open up Windows Explorer
2) Make sure it is enabled it to view all files. (View / Folder Options / View Tab)
3) Double click on the WINDOWS folder
4) Notice you will be given a list of all the contents in the Windows folder, including all the subfolders. This is normal.
4) Double click on the TEMPORARY INTERNET FILES folder.
6) Now notice you are given a list of the files only. This does well to "fool" people into believing there are no subfolders here. Afterall, there is none listed.

Windows Explorer is indeed capable of listing the subfolder, but has straight out LIED to you as well. The trick is to pay attention to the tree (left-hand window). Double click on the TEMPORARY INTERNET FILES folder there. Now do you see it?

According to standard browsing methods with Windows Explorer, you are now viewing a subfolder that doesn't exist.

STRANGE OCCURRENCE 3:
Notice that with that last step the tree expanded to reveal a "Content.IE5" folder and four (or more?) alphanumeric folders that look something like this: 7Y9D3KY5, 0DXQY6H3, PK6QJL7J, 8AS4MHD9.

Why did they change their minds to go to alphanumeric when previous versions of MSIE called them cache1, cache2, cache3, cache4? What was wrong with that system?

Think about this one.

STRANGE OCCURRENCE 4:
Double click on any of the alphanumeric folders. Hmm, nothing appears to be here. Why would Microsoft try so hard to hide empty folders? Well as you might have guessed, Windows Explorer has LIED again and there are in fact files here. You just can't see them. Oddly enough, the only way to find them is through DOS now. Write down the 4 alphanumeric subfolders on a piece of paper. You'll need them for these next steps... (Note that their may be more than 4.)

1) Drop to DOS
2) CD\WINDOWS\TEMPOR~1\CONTENT.IE5
3) CD 7Y9D3KY5 (exchange the 7Y9D3KY5 with one of your alphanumerics.)
4) DIR/P

You are now viewing files that Windows Explorer claims do not exist.

STRANGE OCCURRENCE 5:
1) Drop to DOS
2) DIR C:\WINDOWS\HISTORY\*.*
3) DIR Cl\WINDOWS\HISTORY\*.* /AH

It seems that the only folder or file in this directory is the desktop.ini.

1) Open up Windows Explorer
2) Double click WINDOWS
3) Double click HISTORY

It seems that the only folders or files in this directory are "Wednesday," "Today." etc...
4) Double click on the left-hand side TREE.

DIDN'T WORK THIS TIME.

Here is a situation where both DOS and Windows Explorer are stating that there are no subfolders here. THEY LIED.

1) Drop to DOS
2) CD WINDOWS
3) DELTREE HISTORY
4) EXIT
5) Close and re-open windows explorer.
6) Double click WINDOWS
7) Double click HISTORY

Somebody please tell me where this HISTORY.IE5 folder came from!

STRANGE OCCURRENCE 6:
You will now notice a couple folders that look something like this: MSHist033010029230100210

Double click on one.

The index.dat file that you are now looking is a record of your browsing history. Not only does it record all the URLS you visited, but it records the words you clicked on in a link. If you take a closer look into index.dat (hex) then you will notice it is also quite capable of recording basic <HTML> tags within a webpage. Moreover, it also records every thing you've searched for in a search engine.

Is it a coincidence that Microsoft decided to cripple the "Find Files or Folders" program in a way that it would be incapable of searching through the History folder? (See for yourself.)

NOTE: I'm currently researching the index.dat files. If you have information about this file contact me.

STRANGE OCCURRENCE 7:
If I go into real DOS mode and deltree the HISTORY folder I will (sometimes but not always) get a corrupt directory structure there.

...this could be just my computer, but still strange.

STRANGE OCCURRENCE 8:
1) Open up Outlook if you have it. (Hopefully you don't.)
2) E-Mail yourself a message.
3) Erase the message.
4) Erase it again from your tashbin.

Gone? Nope. Outlook has LIED to you.

Outlook now has three records of this message.
One is in your INBOX.MBX file
One is in your OUTBOX.MBX file
One is in your DELETE~1.MBX file

To find where Outlook is hiding these files, drop to DOS and type dir *.mbx. You will likely find it under a "really hidden" directory.

STRANGE OCCURRENCE 9:
1) Open up Outlook.
2) E-mail yourself any .zip attachment.
3) Erase it.
4) Erase it again from your trashbin.

Now Outlook has four records of this message. Inbox, Outbox, Delete~1, and now Sentit~1.mbx. (Sent Items.mbx)

Hex the sentit~1.mbx file and you will find that not only did it store your e-mail to yourself, but it stored the attachment as well. Moreover, your .zip file is now in some strange encoded binary.

What corporation do you suspect is capable of uncoding this binary? What agencies do you think are capable of uncoding this binary?

STRANGE OCCURRENCE 10:
I've personally witnessed Both Outlook and MSIE "change their mind" and start saving their files to other directories once I've infiltrated their original hiding spots. (Application Data, and Temp.)

Wouldn't you find it strange if Microsoft Word saved all your documents to the MY DOCUMENTS folder one day, but then suddenly started storing them somewhere else?

Keep up the good work man.

Here are the index.dat files I know of. They all have listings in them of places you've been and links you've clicked and whatever.

-c:\windows\cookies\index.dat
-c:\windows\tempo~1\content.ie5\index.dat
-c:\windows\history\history.ie5\index.dat

I have placed a post in the previous thread about this (microsofts really hidden files). I have summed up every location you mentioned and added a few of my own, including a registry key.

I found that if you remove all of them, IE is braindead when you see what's in the adresbox.

------------------
天也空,地也空,人生浮沉在其中。日也空,月也空,东升西落为谁动。金也空,银也空,死后何曾在手中。情也空,爱也空,泪流人去剩愁容。

IP: 已记录
Sonyws
未注册


图标 1  发表于         编辑/删除帖子   引用原文回复  

[fly]还不如不译,虽然我不懂英文!![/fly]

------------------
任何事總係有人有不滿,無論你做得有幾好!

任何事做得好都未必會有美好結局,但只係憑良心無愧!

IP: 已记录
小小瓶子
未注册


图标 1  发表于         编辑/删除帖子   引用原文回复  
哈哈~拿那信箱翻译?亏你想的出来,呵呵~~~~

------------------
沧海一声笑
滔滔两岸潮
浮沉随浪
只记今朝
苍天笑
纷纷世上潮
谁负谁胜出
天知晓
江山笑
烟雨遥
涛浪汹尽红尘俗世几多娇

IP: 已记录
绝地苍狼
未注册


图标 1  发表于         编辑/删除帖子   引用原文回复  
如果实在看不懂的话,请找春之律帮忙。
IP: 已记录
苏樱
未注册


图标 1  发表于         编辑/删除帖子   引用原文回复  
谁翻译的??真是烂,以后这样的翻译不要放上来,还不如不翻译. 要把真正好文章放上来,包括翻译的

------------------
telnet your heart
connecting....
Red Hat Linux release 6.2 (Zoot)
Kernel 2.4.4-prel on an i686
welcome to my heart
login:iloveyou
password:
Last login: Mon Apr 22 14:20:02 from 52.0.13.14
[iloveyou@heart iloveyou]#ls
miss+love lovestory

IP: 已记录
langwo
未注册


图标 1  发表于         编辑/删除帖子   引用原文回复  
拿东方快车翻译不就可以了吗!
IP: 已记录
maomao417
未注册


图标 1  发表于         编辑/删除帖子   引用原文回复  
讲的什么呀?
DOS?
IP: 已记录
密码
未注册


图标 1  发表于         编辑/删除帖子   引用原文回复  
版主老大你帮忙翻译一下不就得了
IP: 已记录
DevilDragon
未注册


图标 1  发表于         编辑/删除帖子   引用原文回复  
不知道是谁翻译的,我真没有看懂
IP: 已记录
功放
未注册


图标 1  发表于         编辑/删除帖子   引用原文回复  
。。。。。。。。
i hate e文!!!!!:(

------------------
功放---一个生活在现实和虚拟中间的角色~!!别把我当做只是网络的虚幻~~也别把我当成现实的真人~~~~~~~~~~~~~`

IP: 已记录
密码
未注册


图标 1  发表于         编辑/删除帖子   引用原文回复  
莫名其妙
IP: 已记录
精灵
未注册


图标 1  发表于         编辑/删除帖子   引用原文回复  
看不懂的可以去
下面的网站

[url]http://ciba.kingsoft.net/[/url]

IP: 已记录

 
发表新主题  发表回复 关闭主题 突出主题 移动主题 删除主题 下一个最老的主题   下一个最新的主题
 - 适于打印的主题视图
转到:
联系我们 | 20CN网络安全小组

Powered by Infopop Corporation
UBB.classic™ 6.5.0
NetDemon修改版 1.5.0, 20CN网络安全小组 版权所有。