Next Gen Boards
 

Sponsored Links
Arcade YouTube vbBux / vbPlaza Calendar FAQ

Reply
 
Thread Tools Display Modes  
destroyka
Corporal Grade 1
 
destroyka's Avatar
 
Join Date: Feb 2008
Location: Ontario, CA
Posts: 58
Rep Power: 1 destroyka is on a distinguished road Reputation: 10
Points: 26,758.53
Bank: 1,148.69
Total Points: 27,907.22
destroyka is offline
 
Send a message via AIM to destroyka
 
#1
02-16-2008, 04:46 PM   #1
Reply With Quote
AIM Password Grabbing

When a user signs into AOL Instant Messenger and stores their password by enabling the 'Save password' option, their password is stored within the computers registry - however, the password itself within the password entry field on AIM is replaced with the whole 'Saved' message.

The password can be recovered, or stolen, even though security measures are taken to counter any attempt at unmasking/copying the * entry or stealing the password. To do this, you will either need to 'steal' certain parts of a computers registry remotely, or be physically at the computer.

To Steal A Password.....
1) Run the Registry Editor by searching for 'regedit' from Start>Run...
2) Look into the following directory path: HKEY_CURRENT_USER>Software>America Online>AOL Instant Messenger>Current Version>Users.
3) Find the user you are looking for with the stored password. In the following steps, I'll use 'destroyka' as an example.
4) Drop down the directory named 'destroyka', then click the subdirectory titled 'Login'.
5) The entry named 'Password1' is your ticket to the users password...heh, surprise surprise eh? Even though the password is encrypted, you can copy the entire entry. A password entry looks something like this: Z0hFdshg4QE+NFSh999ysgsd3g354gSDGfF06wVKsVY=. To copy the value data, right-click the value name 'Password1', then click Modify. Select the entire value data entry, and simply copy it...or go on and be ghetto and write it down, your choice.

To Use A Stolen Password.....
1) Add a new user to a different PC by the AIM sign in menu, making sure you enter the user name in correctly (by the way, its not case-sensitive). The password does not have to be correct, just enter something like NORTENO4LIFE. BE SURE TO SAVE THE PASSWORD!!!
2) Run the Registry Editor by searching for 'regedit' from Start>Run...
3) Look into the following directory path: HKEY_CURRENT_USER>Software>America Online>AOL Instant Messenger>Current Version>Users.
4) Find the user you just added. Like I said in the previous steps, the name was 'destroyka'.
5) Drop down the directory named 'destroyka', then click the subdirectory titled 'Login'.
6) To replace the incorrect password with the actual password of destroyka, right-click the value name 'Password1', then click Modify. Erase the entire entry, then paste or key in the stolen coded password (again, the example password was Z0hFdshg4QE+NFSh999ysgsd3g354gSDGfF06wVKsVY=).
7) Completely exit out of AIM if you haven't yet, then load AIM again. Now log into the account destroyka and voila!

***remember, if you log into someone elses AIM account while they are logged in, both you and the other person(s) will recieve a message saying that they are now logged into multiple locations. this is enough to raise an eye-brow or two...

This process not only works for stored AIM passwords, but pretty much any password that is saved on a PC, such as Outlook, Yahoo! Instant Messenger (as far as I know...Im not a big fan of yim). To do this remotely, you'd have to use a trojan program like S7..I'm not saying that if you actually get a working copy of the program you'll surely 100% recover the victims regs.

IF ANYONE KNOWS HOW THE AIM PASSWORDS ARE CODED, PLEASE LET ME KNOW! I know its not MD, its too complicated for that basic two plus two algorithm lol. If I can find out how it coded, I'll update you all and write a walkthrough on decrypting the password so you don't have to registry edit in the long coded pass.

PS: Don't post replies telling me that you can't log in destroyka with the password I posted. It was an example. Besides, my AIM is theaurasoulja.

-destroyka

Last edited by destroyka; 02-16-2008 at 04:52 PM.. Reason: correcting a mistake
Report Post
LeGiT pRo
Major Grade 4
 
Join Date: Jan 2007
Location: Rochester, New York
Posts: 465
Rep Power: 2 LeGiT pRo is on a distinguished road Reputation: 10
Points: 3,511.51
Bank: 854,241.13
Total Points: 857,752.64
LeGiT pRo is offline
 
Send a message via AIM to LeGiT pRo
 
#2
02-16-2008, 10:34 PM   #2
Reply With Quote
You could also figure out the actually password if it isn't too complicated. There is a program that will change the AIM encrypted pw to a MD5 and from there you could brute force it or use a list of pws.
__________________
When you leave rep leave your name in the note, I'll return it.
Report Post
destroyka
Corporal Grade 1
 
destroyka's Avatar
 
Join Date: Feb 2008
Location: Ontario, CA
Posts: 58
Rep Power: 1 destroyka is on a distinguished road Reputation: 10
Points: 26,758.53
Bank: 1,148.69
Total Points: 27,907.22
destroyka is offline
 
Send a message via AIM to destroyka
 
#3
02-16-2008, 11:16 PM   #3
Reply With Quote
What program? I've been searching for a long time on anyway to either decrypt or translate that into a MD or SHA - no luck so far. So I figure to my knowledge such a program doesn't exist. That doesn't mean there isn't something out there though...
Report Post
LeGiT pRo
Major Grade 4
 
Join Date: Jan 2007
Location: Rochester, New York
Posts: 465
Rep Power: 2 LeGiT pRo is on a distinguished road Reputation: 10
Points: 3,511.51
Bank: 854,241.13
Total Points: 857,752.64
LeGiT pRo is offline
 
Send a message via AIM to LeGiT pRo
 
#4
02-16-2008, 11:28 PM   #4
Reply With Quote
Here is the program it converts it from registry hash to MD5.

http://tsourceweb.com/files/uaimpass.zip
__________________
When you leave rep leave your name in the note, I'll return it.
Report Post
destroyka
Corporal Grade 1
 
destroyka's Avatar
 
Join Date: Feb 2008
Location: Ontario, CA
Posts: 58
Rep Power: 1 destroyka is on a distinguished road Reputation: 10
Points: 26,758.53
Bank: 1,148.69
Total Points: 27,907.22
destroyka is offline
 
Send a message via AIM to destroyka
 
#5
02-16-2008, 11:44 PM   #5
Reply With Quote
I stand corrected lol. Good lookin out legit. And for those who need a MD5 cracker...

http://www.antsight.com/zsl/rainbowc...ck-1.2-win.zip

Now this changes everything, because instead of copying the registry hash, you could choose to sit through the hash cracking process.
Report Post
mameman2
Commander Grade 4
 
mameman2's Avatar
 
Join Date: Mar 2007
Location: in the shoutbox mostlikely
Posts: 554
Rep Power: 2 mameman2 is on a distinguished road Reputation: 17
Points: 301.00
Bank: 405,084.79
Total Points: 405,385.79
for giving me 60 bucks - cobrad for getting hacked - RezSide 
Boston Red Sox New England Patriots
mameman2 is offline
 
Send a message via AIM to mameman2Send a message via Yahoo to mameman2
 
#6
02-17-2008, 09:16 AM   #6
Reply With Quote
um yea...so wat is MD5...any ways thnx for the tut
__________________
DONT CLICK HERE

Quote:
[Today 08:54 PM] conrad127:we just abuse our powers and ban people
Quote:
[Today 09:04 PM] Tinsley85: no i'm a noob!!!
Quote:
[Today 10:22 PM] heavytech94: attack and brutally murder mamemam
Report Post
Beau
Moderatin' with style
 
Beau's Avatar
 
Join Date: Aug 2007
Location: Kent, UK
Posts: 6,125
Rep Power: 9 Beau will become famous soon enoughBeau will become famous soon enough Reputation: 127
Points: 3,827.74
Bank: 0.00
Total Points: 3,827.74
to blot up the piss on my pants... - Enzo thanks 4 lettin me no about net tools from crazydog090 - crazydog090 thanks for banning me! - ED__ thanx for being a greate sig maker give us some pointers from JABZ - JABZ13 thanx for the sig M8 - JABZ13 
Happy b-day Beau! stay active! - Oc LoG being my favorite mod xD - Oc LoG Happy Birthday - krizor <3 my favorite mod - mysteryentry beau is teh s3x - mysteryentry 
for being so cool whilste i av been on ngb - shamber I wont be a dick and leave you a horrible message. So here it is...Great jobs with the doubles! On our way to the top! xD - spankyx1x Dick face - spankyx1x hi - Versus No Message - Waelzleb 
Gay and Lesbian Pride - goldeneagle 
Manchester United
Beau is online now
 
Send a message via AIM to BeauSend a message via MSN to BeauSend a message via Skype™ to Beau
 
#7
02-17-2008, 10:04 AM   #7
Reply With Quote
This is pretty useless. You have to be on that person's PC to do that. Bruteforcing would be easier, even though that takes forever.
__________________


Report Post
destroyka
Corporal Grade 1
 
destroyka's Avatar
 
Join Date: Feb 2008
Location: Ontario, CA
Posts: 58
Rep Power: 1 destroyka is on a distinguished road Reputation: 10
Points: 26,758.53
Bank: 1,148.69
Total Points: 27,907.22
destroyka is offline
 
Send a message via AIM to destroyka
 
#8
02-17-2008, 10:38 AM   #8
Reply With Quote
Bruteforce does take forever - which is why I wrote this. And like I said before, simply use a program for remote access. And who knows, maybe someone reading this is able to get phsyical access to their victims PC.

MD5 hash is a hexidecimal-based algorithm used in many internet applications as a security measure. So it takes a word like 'rawries' and turns it into a series of hex characters

Last edited by destroyka; 02-17-2008 at 10:51 AM.. Reason: spelling
Report Post
GLoRY GuNz
-GFX Artist-
 
GLoRY GuNz's Avatar
 
Join Date: Aug 2007
Location: Pennsylvania
Posts: 1,404
Rep Power: 3 GLoRY GuNz will become famous soon enough Reputation: 52
Points: 23,225.12
Bank: 521,836.33
Total Points: 545,061.45
Pittsburgh Pittsburgh Steelers
GLoRY GuNz is offline
 
Send a message via Yahoo to GLoRY GuNz
 
#9
02-17-2008, 10:49 AM   #9
Reply With Quote
Maybe if you have a brother/sister, who you want to mess with:)
__________________
Founder of the Rainbow 6 Vegas Teleportation Glitch
The New James Bond Game is Made by ACTIVISION!!



Report Post
Beau
Moderatin' with style
 
Beau's Avatar
 
Join Date: Aug 2007
Location: Kent, UK
Posts: 6,125
Rep Power: 9 Beau will become famous soon enoughBeau will become famous soon enough Reputation: 127
Points: 3,827.74
Bank: 0.00
Total Points: 3,827.74
to blot up the piss on my pants... - Enzo thanks 4 lettin me no about net tools from crazydog090 - crazydog090 thanks for banning me! - ED__ thanx for being a greate sig maker give us some pointers from JABZ - JABZ13 thanx for the sig M8 - JABZ13 
Happy b-day Beau! stay active! - Oc LoG being my favorite mod xD - Oc LoG Happy Birthday - krizor <3 my favorite mod - mysteryentry beau is teh s3x - mysteryentry 
for being so cool whilste i av been on ngb - shamber I wont be a dick and leave you a horrible message. So here it is...Great jobs with the doubles! On our way to the top! xD - spankyx1x Dick face - spankyx1x hi - Versus No Message - Waelzleb 
Gay and Lesbian Pride - goldeneagle 
Manchester United
Beau is online now
 
Send a message via AIM to BeauSend a message via MSN to BeauSend a message via Skype™ to Beau
  02-17-2008, 11:02 AM   #10
Reply With Quote
Quote:
Originally Posted by destroyka View Post
Bruteforce does take forever - which is why I wrote this. And like I said before, simply use a program for remote access. And who knows, maybe someone reading this is able to get phsyical access to their victims PC.

MD5 hash is a hexidecimal-based algorithm used in many internet applications as a security measure. So it takes a word like 'rawries' and turns it into a series of hex characters
I think you'll find it's extremely difficult to gain remote access to someone's registry, that's why I think this pointless. Imo anyway.
__________________


Report Post
Reply

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off
Forum Jump