top.png
[ news ] [ contact ] [ links ] [ proxy ] [ remailer ] [ downloads ] [ archives ]

www.swateam.org.uk - k-rad 31337 downloadz

All of the files here can also be found public on other sites, these files may not be the most up to date of there kind (i.e these are files there where leaked and may be superceeded by other un-leaked files) we did not leak any of these mearly hosting them here for download.

 

Exploit Packs
Descriptions
CrimePack 3.1.3 exploit pack to pwn your browser when you visit dodgy websites
Bleeding Life v2.0 another exploit pack
Blackhole 1.0.2
awesome exploit pack, might need decrypting and cracking
Eleonore v.1.4.4 mod modded version of the eleonore exploit pack v.1.4.4
Sava Exploit Pack Sava exploit pack
Phoenix 2.5 The Phoenix Exploit Pack v2.5

PHP/Web Shells
Descriptions - some from net some from audited hosts
100 shells list of them here
bypass.txt webshell
c99.txt "famous" c99 shell
c99ud.txt same as above more or less
cgitelnet.pl perl cgi telnet
cps.php.txt found on compromised host
echo.gif.php.txt found on compromised host
echo.jpg.php.txt found on compromised host, same as above i think
islamshell.php.txt found on compromised host
my.php.txt another php webshell
r57.php.txt "famous" r57 shell
safe0ver.txt another webshell, think this ones php


We have loads of these and will get more online at some point, if any of you find any on your travels, please send them in, we have asp shells too that i'll add over the next few days.

DDoS php scripts
Descriptions - if you don't know anything you'll think this is what a shell is
Slowlaris.pl consume all the connections on a web server
UDP Flooder batter servers offline with k-rad uber UDP random data!! muhahaha 2gb/s to knock xbawx luzers offline

 

Shell Booter Frontends
Descriptions
ATT Booter ATT Booter source - SQL database thats required - excellent source
Advanced PHP Booter Another booter.
DDoS Shell Booter
Another good shell booter

 

BotNets
Descriptions
Zeus 2.0.8.9 Source Source code for the infamous banking trojan
   
   

 

Windows password dumpers
Descriptions
This handy utility dumps the password database of an NT machine that is held in the NT registry (under HKEY_LOCAL_MACHINE\SECURITY\SAM\Domains\Account\Users) into a valid smbpasswd format file (which is understood by practically all Windows password security auditing tools). (Windows NT )
This is an application which dumps the password hashes from NT's SAM database, whether or not SYSKEY is enabled on the system. NT Administrators can now enjoy the additional protection of SYSKEY, while still being able to check for weak users' passwords. The output follows the same format as the original pwdump (by Jeremy Allison) and can be used as input to password crackers. You need the SeDebugPrivilege for it to work. By default, only Administrators have this right, so this program does not compromise NT security. (Windows NT / 2000)
pwdump3 enhances the existing pwdump and pwdump2 programs developed by Jeremy Allison and Todd Sabin, respectively. pwdump3 works across the network and whether or not SYSKEY is enabled. Like the previous pwdump utilities, pwdump3 does not represent a new exploit since administrative privileges are still required on the remote system. One of the largest improvements with pwdump3 over pwdump2 is that it allows network administrators to retrieve hashes from a remote NT system. (Windows NT / 2000)
pwdump3e provides enhanced protection of the password hash information by encrypting the data before it is passed across the network. It uses Diffie-Hellman key agreement to generate a shared key that is not passed across the network, and employs the Windows Crypto API to protect the hashes. (Windows NT / 2000)
pwdump4 is an attempt to improve upon pwdump3. It might work in cases when pwdump3 fails (and vice versa). (Windows NT / 2000)
pwdump5 is an application that dumps password hashes from the SAM database even if SYSKEY is enabled on the system. If SYSKEY is enabled, the program retrieves the 128-bit encryption key, which is used to encrypt/decrypt the password hashes. (Windows NT/2000/XP/2003)
pwdump6 is a significantly modified version of pwdump3e. This program is able to extract NTLM and LanMan hashes from a Windows target, regardless of whether SYSKEY is enabled. It is also capable of displaying password histories if they are available. Currently, data transfer between the client and target is NOT encrypted, so use this at your own risk if you feel eavesdropping may be a problem. (Windows 2000/XP/2003/Vista)
pwdump7 works with its own filesytem driver (from rkdetector.com technology) so users with administrative privileges are able to dump directly from disk both SYSTEM and SAM registry hives. Once dumped, the SYSKEY key will be retrieved from the SYSTEM hive and then used to decrypt both LanMan and NTLM hashes and dump them in pwdump like format. (Windows 2000/XP/2003/Vista)
A Tool For Mass Password Auditing of Windows Systems - inc source

 

Windows password crackers
Descriptions
Ophcrack is a free Windows password cracker based on rainbow tables. It is a very efficient implementation of rainbow tables done by the inventors of the method. It comes with a Graphical User Interface and runs on multiple platforms. - official site here where you can also download rainbow tables.
A very fast network logon cracker which support many different services official site here
John the Ripper is a fast password cracker. Its primary purpose is to detect weak Unix passwords. Besides several crypt(3) password hash types most commonly found on various Unix systems, supported out of the box are Windows LM hashes, plus many more with contributed patches. - Windows version offical site
John the Ripper is a fast password cracker. Its primary purpose is to detect weak Unix passwords. Besides several crypt(3) password hash types most commonly found on various Unix systems, supported out of the box are Windows LM hashes, plus many more with contributed patches. - DOS version official site
Offline NT Password and Registry editor, ISO image that uses a good old Linux Live CD top reset passwords on pretty much any version of windows, burn to disc then boot from the CD in order to be able to reset the required password(s). Official site here.


Windows port scanners
Descriptions
superscan4.zip SuperScan 4 is an update of the highly popular Windows port scanning tool, SuperScan. Windows NT/XP - maybe vista and beyond - official site here
nmap-5.00-win32.zip The hackers choice in port scanners - command line version for Windows official site here
nmap-5.00-setup.exe The hackers choice in port scanners -  Windows with GUI official site here


Windows network sniffers
Descriptions
ettercap-NG-0.7.3-win32.exe Ettercap is a suite for man in the middle attacks on LAN. It features sniffing of live connections, content filtering on the fly and many other interesting tricks. It supports active and passive dissection of many protocols (even ciphered ones) and includes many feature for network and host analysis. Offical site here 
setup_kismet_2008-05-R1.exe Kismet is an 802.11 layer2 wireless network detector, sniffer, and intrusion detection system. Kismet will work with any wireless card which supports raw monitoring (rfmon) mode, and (with appropriate hardware) can sniff 802.11b, 802.11a, 802.11g, and 802.11n traffic. Kismet also supports plugins which allow sniffing other media such as DECT.
Kismet identifies networks by passively collecting packets and detecting standard named networks, detecting (and given time, decloaking) hidden networks, and infering the presence of nonbeaconing networks via data traffic.  Offical site here
wireshark-win32-1.2.5.exe Wireshark is the world's foremost network protocol analyzer, and is the de facto (and often de jure) standard across many industries and educational institutions.
Wireshark development thrives thanks to the contributions of networking experts across the globe. It is the continuation of a project that started in 1998. 
official site here


Wordlists
Descriptions
theargonlistver1.zip Definative wordlist from the argon.com - local copy 
Misc Wordlists
Rip of the argon wordlist directory.