News:

Holy shit, it's 2018 2019 2020 2021 2022 2023 2024, and the US isn't a fascist country! What a time to be alive.

Main Menu

[RCRS] EXEInfo

Started by Ryan Marcus, September 13, 2005, 08:00:47 PM

Previous topic - Next topic

0 Members and 1 Guest are viewing this topic.

Ryan Marcus

I am trying to get EXE info from RCRS... I send "STAR" or "D2DV", but I do not get a response...

What am I supposed to send to RCRS to get EXE info?
Thanks, Ryan Marcus

Quote
<OG-Trust> I BET YOU GOT A CAR!
<OG-Trust> A JAPANESE CAR!
Quote
deadly: Big blue fatass to the rescue!
496620796F75722072656164696E6720746869732C20796F75722061206E6572642E00

rabbit

It takes 15 minutes for my JavaOp to connect.  Please note that my JavaOp is run by iago, who also runs RCRS.  They are on the same network, and possibly the same computer.  That should give you some idea.

MyndFyre

Quote from: Ryan Marcus on September 13, 2005, 08:00:47 PM
What am I supposed to send to RCRS to get EXE info?

CDN$2,000,000,000 in small nonsequential bills.
Quote from: Joe on January 23, 2011, 11:47:54 PM
I have a programming folder, and I have nothing of value there

Running with Code has a new home!

Quote from: Rule on May 26, 2009, 02:02:12 PMOur species really annoys me.

Newby

Hmm.

Packet log a connection, and then search the forums for that document iago wrote telling you the format of what to send. :p
- Newby
http://www.x86labs.org

Quote[17:32:45] * xar sets mode: -oooooooooo algorithm ban chris cipher newby stdio TehUser tnarongi|away vursed warz
[17:32:54] * xar sets mode: +o newby
[17:32:58] <xar> new rule
[17:33:02] <xar> me and newby rule all

Quote from: Rule on June 30, 2008, 01:13:20 PM
Quote from: CrAz3D on June 30, 2008, 10:38:22 AM
I'd bet that you're currently bloated like a water ballon on a hot summer's day.

That analogy doesn't even make sense.  Why would a water balloon be especially bloated on a hot summer's day? For your sake, I hope there wasn't too much logic testing on your LSAT. 

Ryan Marcus

#4
I know the format, I just can't get the darn info back!

I will just have to use the... the... EVIL BNLS!

[edit]
Nevermind. I won't do it.

Here is my packet log. Whats wrong?



Send option management request (T_OPTMGMT_REQ = 108).

Receive option management ack (T_OPTMGMT_ACK = 131).

Send bind request (T_BIND_REQ = 101).
  Bind to «Any Address»
  Connection Indication Number = 0

Receive bind ack (T_BIND_ACK = 122).
  Bind to port 51648
  Connection Indication Number = 0

Send connection request (T_CONN_REQ = 102).
  Connect to 142.161.168.85:8321

Receive connection confirmation (T_CONN_CON = 123).
  Connect from 142.161.168.85:8321

Send data (9 bytes).
<00000000< 53 54 41 52  0D 0A 30 0D  0A                        STAR..0..

Send data (9 bytes).
<00000009< 53 54 41 52  0D 0A 31 0D  0A                        STAR..1..

Send data (9 bytes).
<00000012< 53 54 41 52  0D 0A 33 0D  0A                        STAR..3..

Receive data (4 bytes).
>00000000> 32 30 35 0A                                         205.

Receive data (49 bytes).
>00000004> 31 36 38 34  33 35 32 34  0A 73 74 61  72 63 72 61  16843524.starcra
>00000014> 66 74 2E 65  78 65 20 30  38 2F 30 37  2F 30 35 20  ft.exe 08/07/05
>00000024> 31 34 3A 30  36 3A 34 32  20 31 30 39  33 36 33 32  14:06:42 1093632
>00000034> 0A                                                  .


Somebody tell me why I only get 2 responses when I send 3 packets!

Thanks in advance!
Thanks, Ryan Marcus

Quote
<OG-Trust> I BET YOU GOT A CAR!
<OG-Trust> A JAPANESE CAR!
Quote
deadly: Big blue fatass to the rescue!
496620796F75722072656164696E6720746869732C20796F75722061206E6572642E00

Joe

If I were you, I'd request one, wait until the result is returned, request another one, and so on.
Quote from: Camel on June 09, 2009, 04:12:23 PMI'd personally do as Joe suggests

Quote from: AntiVirus on October 19, 2010, 02:36:52 PM
You might be right about that, Joe.


Ryan Marcus

#6
.... No ;)

I can't seem to figure out which BNLS packet gives me EXE info anyway, so I will have to packet log my 1000 convertered VB bots, of which half work, to figure it out lol.

[edit]
Ah HA! I need to buffer the data! It was sending the version hash and the EXE info in the same "break". I need to split incoming data into an array and then parse them! I bet I come off as a real moron, huh?
Thanks, Ryan Marcus

Quote
<OG-Trust> I BET YOU GOT A CAR!
<OG-Trust> A JAPANESE CAR!
Quote
deadly: Big blue fatass to the rescue!
496620796F75722072656164696E6720746869732C20796F75722061206E6572642E00

Hdx

Quote from: Ryan Marcus on September 14, 2005, 11:27:23 AM
I can't seem to figure out which BNLS packet gives me EXE info anyway, so I will have to packet log my 1000 convertered VB bots, of which half work, to figure it out lol.
POKE
~-~(HDX)~-~
http://img140.exs.cx/img140/6720/hdxnew6lb.gif
09/08/05 - Clan SBs @ USEast
[19:59:04.000] <DeadHelp> We don't like customers.
[19:59:05.922] <DeadHelp> They're assholes
[19:59:08.094] <DeadHelp> And they're never right.