ITT: Epic wins using these Keyloggers or any others. [rss]

Anonymous >30d ago #p1503 >>quote

I'll start.

I ordered one of these things off the internet about a year ago mostly out of boredom. I had a slight understanding of spyware and have use keyloggers before mostly for fun. I've snagged a few passwords in the past, never for any real deviant reasons just to snoop around. Anyways. So I get one of these things in the mail. It was the kind that you just put in the back of a desktop computer where you plug the mouse in and basically in intercepts EVERYthing that's typed and has 2gigs of memory with an encrypted wordfile. Sounds juicy right? So I'm thinking and thinking, hmm where the hell could I use this thing? At home? Naw, that's small time shit. At work? School? Bingo. I started off slow and took it to a computer lab at my CC. Hopped on one of the computers dinked around for a minute then was like WTF the mouse isn't working. Did that stupid look around the room like is this happening to anyone else? Herp Derp. The stage was set. Hopped down there and pretended to fiddle with the connection when obviously I was just installing the keylogger. I was scared I was going to be caught somehow. I thought maybe some computer savvy asshole would be snooping around and see it and take it hell I don't know. Anyways, so I returned for it about a day and a half later. When I opened the file and snooped through it all I had easily over 100 different username/passwords to anything from facebook to paypal, amazon, you name it.

Cr0s5H34D_QA ## GOLD >30d ago #p1504 >>quote

You've caught my attention, where did you get this? I currently just reinstalled ""windows"" for extra credit in a class, installed mint linux instead, however I would love to fishout some information with this.

-QA

Anonymous >30d ago #p1527 >>quote

What's the name of that logger with 2 Gigs of ram? I'm curious

Anonymous >30d ago #p1681 >>quote

i'd love to keylog just for lols. imagine you have a roommate and you begin rambling on about their passwords while they're in bed. that, but also public keylogging can be fun too but it's unfunny and skiddy if you do it just to hijack people's shit. i think psychological terrorism is better

Anonymous >30d ago [DE] [TOR] #p18598 >>quote
[AutoMod] action=keep R:8 E:8 N:9 C:9 | The post provides a detailed, technical anecdote about building a keylogger. It is engaging and relevant to the thread's theme.
This post caught my attention and stirred some youth emotions in me because I did something similar at school when I was younger. I'm gonna waste a bit of time on this telling my story. I coded a windows software keylogger that copied itself to the user's startup folder, that way every time that user logged in the keylogger would run. It was a crap simple C# "collect keylogs to memory and after 5 minutes send them through SMTP to this email". I bought a raspberry pi 0 for 15 bucks and downloaded from github a project that turns the data usb port of the rp0 into a function HID device (aka keyboard) and made it so that when connected to a usb it opens the cmd and types a command to download and execute my keylogger. All set, brought the pi to school the next day because we had class on the computer's room. I knew that the teachers' computers all ran windows and had only a single user that all teachers used. all classes we could choose our own seats so I chose to sit right the first row of computers that were right in front, front facing, the teacher's desk. during the class I pretended to have dropped a pen to the ground but looking back I didn't really had the need to pretend, the teacher we were having class with really didn't care about us so we always did whatever we wanted and he didn't ever flinch an eye. I had the pi inside my backpack connected to a long usb cable which I connected to the back of the teacher's computer while he was away. I sat back in my seat waiting for the pi to start up and execute my commands, it took about 40 seconds and those were some intense 40 seconds where I hoped that the teacher wouldn't be back. It finally started typing, i knew these because in front of the teacher's monitor there was a white board and I could see in the reflection that cmd had opened. I also made it so that it would close the cmd at the end. 5 minutes after this the keylogs start dropping in the email and I remember feeling like a real h4x0r. a week passed and everyday at the end of the day i would check the keylogs for lulz, some teachers spent the entire class just going through facebook, writing emails, whatever. I snatched some credentials from some teachers and logged in through their emails, to avoid being flagged as suspicious I would always do this with the school's computer. Going through the emails I found a school email from the IT guy which said the teacher's windows credentials. Next day at school I tried those credentials on my computer and got in successfully, and a special bonus, it had admin privileges unlike our student's account. I told a friend of mine that I could install counter strike on the computers at school, he didn't believe me so I got into his seat and logged in with the teacher's creds with the runas command and gave himself admin privs with the net user command. I then did this to all the cool kids in the class and in no time we were hosting counter strike tournaments in the school's network. That got me thinking, if we can connect to each other's computers with the counter strike's server then I may be able to pull something else too and I remembered that eternal blue exploit that exploited windows's smb via port 445 and could get access to any windows computer by just having that port open. that exploit was already patched but still the core functionality of smb was still a thing (and still is in windows 11). I pulled psexec from microsoft's website and try to to login with the teacher's account to random IPs inside the network and voila, I was in in all of fucking them, lol. I downloaded nmap and started crawling the entire internal network for port 445 and soon I found out that I could access not only the computers from my classroom but also the computers from other classrooms and even from other buildings and even from other schools (it was a big organization of different schools throughout the city). holy fucking lol. I remember the hit of dopamine I felt with the realization that I had full admin access to any computer anywhere. I worked on my C# keylogger, now that I had admin privs I could install it on the common startup folder which means it would run with any user that logged in into windows. I also made it take screenshots every 30 seconds and ditched the SMTP and coded my own webserver that would be running inside the network on a random computer that I got in and found out that the uptime was months, that computer was always on for some reason. I made it password protected but because I was a kid I didn't know how to work with HTTPS so I just left it unencrypted, figured no one would notice anyway so no problem, at least I XOR'ed the loot (keylogs and screenshots) and base64'ed it so in case someone for some reason played around with wireshark they wouldn't immediately sound an alarm. A month passed and I had amounted 50Gbs of screenshots and around 10Mbs of keylogs. I went through the screenshots divided them by the computer's hostname. I filtered out computers that were mainly used by the student account and was left with teacher's computers and more. I filtered out teachers computers and was left with internal office computers, the ones from departments like countability, treasury, human resources and sys administrators. Through those computers I got access to our teacher's salaries, home addresses, phone numbers, everything. Me and some friends started a prank calling campaign to all our teachers and recorded them for the lulz. We also got some of our teacher's passwords and sometimes would hint them subliminally to them, for example, one teacher had a password related to Alice In Chains and so we would randomly strike a conversation with the teacher about Alice In Chains and say stuff like "ah ye the teacher looks like someone who really likes Alice In Chains". One time with another teacher's class during truth or dare we dared a guy to randomly scream the teachers password that was his son or grandson's name followed by birthdate, he screamed it during a time that everyone was talking loud during some projects and we all had to hold our laughs so hard looking at the teacher's reaction of "did I just hear my own password?", the teacher looked so confused it was hilarious, we joked that she thought she was hallucinating. Later I found that that the computer that was 24 hours p/day turned on was the computer at the school's entrance, where we passed our cards to validate our presence, every time we passed our cards it played a little sound in the speakers, I realized that it was just a windows program reading RFID cards sending them to a SQL server, I got access to the SQL server and was able to see the entire logs for years, I also found out that the sounds was just something the program played directly with the windows sound drivers so really anything could be heard even from a youtube video or vlc or anything so I coded a quick program that would play a moaning from a porn video and would play it remotely from a building with windows access to there every time some kid passed. and they would always looked so confused it cracked us open LOL. Anyway I wasn't and still I'm not a malicious guy. I did all this in my spare time just for the lulz. I was never caught because I never really did something problematic like leaking stuff or ransomware the entire thing, I did it purely for the lulz and it was fun, I did got a hold of some exams before doing them but I really didn't need to cheat to pass so I was fine and didn't tell my friends I had them because I knew they would want them and teacher would eventually discover so I layed low on that. School ended and it was my last year, I didnt go through the trouble of wiping everything from the computers so it's possible that the keyloggers are still sitting on some computers that were never updated to a newer windows or on some backup disks in storage.
Replies: >>18599
Anonymous >30d ago [NL] [TOR] #p18599 >>quote
[AutoMod] action=keep R:9 E:8 N:7 C:9 | The post directly engages with the thread topic and adds a personal, relatable anecdote. It's engaging and relevant to the discussion.
a9cdfa5e5301255f00ac3af878d97ac41b42ab9e00f6f16b0ed96f9ea9268240.png
a9cdfa5e5301255f00ac3af878d97ac41b42ab9e00f6f16b0ed96f9ea9268240.png
>>18598
Paragraphs, man. You know what they are?
Replies: >>18600
Anonymous >30d ago [DE] [TOR] #p18600 >>quote
[AutoMod] action=keep R:8 E:5 N:4 C:8 | The user is engaging with the thread context by commenting on the formatting and the perceived necessity of paragraphs. It's relevant to the discussion.
>>18599
I only really care about my grammar and syntax when I'm being paid for it at my job.
Also, wasn't the consensus that paragraphs were "reddit spacing"?
I haven't been lurking much lately.
Replies: >>18620
Anonymous >30d ago [JP] [VPN] #p18616 >>quote
[AutoMod] action=keep R:8 E:7 N:6 C:8 | The post is a solid, engaging contribution to the thread. It provides a personal anecdote about using keyloggers and the messy cleanup process. It flows well and is relevant to the topic.
I can add my two cents here. I got a hardware device a few years ago. I almost pissed my pants when I installed it in a public place. I left it there for around two weeks to collect some data. In hindsight, it was a bad idea as it took me five different scripts to clean up all the gibberish that it logged. I can't say I got any useful information out of it. Most of the accounts at that time were from poorfags, but I had a good laugh reading through some emails. Luckily, MFA in gmail wasn't enforced as strictly as it is now. The trick was to access the account and delete the notification about the location directly. Personal opsec was shit at that time, did some stupid beginner mistakes, got scarred as fuck and decided to stop for some time. However remembering the shitty passwords people used for their mail or socials was hilarious. My fav: saltpepper123
Anonymous >30d ago [US-WA] #p18620 >>quote
[AutoMod] action=keep R:8 E:5 N:7 C:8 | The post engages with the thread context by addressing the 'Reddit spacing' debate. The argument is clear and relevant to the context, though the tone is slightly defensive.
AAAAAAAAA.png
AAAAAAAAA.png
>>18600
"Reddit spacing" is a 4chan debate about whether to use 1 or 2 newlines between each paragraph.
>Redditors have to press enter twice to make a new paragraph due to their bbcode. This carries over to 4chan with Redditors having an extra newline between each line
>Old 4chan users where also known to press enter twice between paragraphs, but at some point this shifted
I don't think it matters because anons on both side strongly claim theirs is correct.
Attachments:
AAAAAAAAA.png (163.49 KB)

[ reply ]