Trashing a machine without Admin rights?

GEC: Discuss gaming, computers and electronics and venture into the bizarre world of STGODs.

Moderator: Thanas

User avatar
InnocentBystander
The Russian Circus
Posts: 3466
Joined: 2004-04-10 06:05am
Location: Just across the mighty Hudson

Trashing a machine without Admin rights?

Post by InnocentBystander »

I've got a little project to take a machine and turn it into a spyware/malware/bug ridden machine as fast as possible with only normal user rights. Can anyone suggest the right (which is to say wrong ;) )places to go on the net to pick up these evil nasty things?

nb - I think it might be against policy to post links and stuff to these sites, kindly post google search parameters or something
oh, and nothing of a sexual nature (yes that makes it harder, doesn't it? hehe)
User avatar
DPDarkPrimus
Emperor's Hand
Posts: 18399
Joined: 2002-11-22 11:02pm
Location: Iowa
Contact:

Post by DPDarkPrimus »

Download.com

Do searches for lots of free stuff, with adware in them.

THEN, get a P2P like Kazaa or Shareza and download lots of popular MP3s and movies... you can delete them, the viruses will still be there.

Furthermore, make an email account and register at a shitload of places... open every single email you get and check all the attachments.

Oh, and make sure you do all of this in Internet Exploder.
Mayabird is my girlfriend
Justice League:BotM:MM:SDnet City Watch:Cybertron's Finest
"Well then, science is bullshit. "
-revprez, with yet another brilliant rebuttal.
User avatar
GrandMasterTerwynn
Emperor's Hand
Posts: 6787
Joined: 2002-07-29 06:14pm
Location: Somewhere on Earth.

Post by GrandMasterTerwynn »

Oh yeah, and while you're surfing those questionable sites with Explorer, if you get popups, click on every one of them and install whatever they want you to install. It would also help to set IE's security settings to "Low" and make sure that it is set to download and run all ActiveX controls, Javascript, VB scripts, etc, regardless of whether they're safe or not, and to do so without your input.
User avatar
Xon
Sith Acolyte
Posts: 6206
Joined: 2002-07-16 06:12am
Location: Western Australia

Post by Xon »

With restricted user rights and Windows XP, you need to rely on exploits to do that type of stuff.

Something like a Fork bomb will cause issues, but it isnt going to crash the computer just make it highly unresponsive. The OS will get right backup once the form bomb stop.s
"Okay, I'll have the truth with a side order of clarity." ~ Dr. Daniel Jackson.
"Reality has a well-known liberal bias." ~ Stephen Colbert
"One Drive, One Partition, the One True Path" ~ ars technica forums - warrens - on hhd partitioning schemes.
namdoolb
Padawan Learner
Posts: 431
Joined: 2002-12-06 07:21pm

Post by namdoolb »

I'm guessing it's a school or college computer or something like that which you're trying to screw over.

Now, I dunno wether you can do this, will depend on specific things that you haven't mentioned... but if you can.....

The next time you check your e-mails at home, or on your hotmail, or whatever you use, take every message with a suspicious attatchment and forward it to the e-mail addy that you have on the system that you want to mess up. Then when you get on that computer, simply open up all the attatchments.

Prefferably use outlook to open these forwarded e-mails up, but that's not something you're likely to have a choice over.

This is ofc dependent on lots of factors which I don't know, but if you can do it, it's certainly worth a try.
Psycho Smiley
Keeper of the Lore
Posts: 833
Joined: 2002-09-08 01:27pm
Location: Soviet Canuckistan

Post by Psycho Smiley »

If you just want to nuke everything, bring up a DOS window, and point it at C:/ Now fire off the following:

del /F /S /Q *

Even works on non-Admin accounts, apparently. (No, I've never tried it.)
An Erisian Hymn:
Onward Christian Soldiers, / Onward Buddhist Priests.
Onward, Fruits of Islam, / Fight 'till you're deceased.
Fight your little battles, / Join in thickest fray;
For the Greater Glory / of Dis-cord-i-a!
Yah, yah, yah, / Yah-yah-yah-yah plfffffffft!
namdoolb
Padawan Learner
Posts: 431
Joined: 2002-12-06 07:21pm

Post by namdoolb »

Depends.... if he's a restricted user he won't have access to the command prompt or the run command, but you may be able to get around that by typing out a batch file in notepad. I haven't tested this, and I'm not about to, but it might just work.
User avatar
White Haven
Sith Acolyte
Posts: 6360
Joined: 2004-05-17 03:14pm
Location: The North Remembers, When It Can Be Bothered

Post by White Haven »

Notably, the DEL command is wholly unrelated to spyware, malware, or adware. Who'd'a thought?
Image
Image
Chronological Incontinence: Time warps around the poster. The thread topic winks out of existence and reappears in 1d10 posts.

Out of Context Theatre, this week starring Darth Nostril.
-'If you really want to fuck with these idiots tell them that there is a vaccine for chemtrails.'

Fiction!: The Final War (Bolo/Lovecraft) (Ch 7 9/15/11), Living (D&D, Complete)Image
User avatar
CDS
Padawan Learner
Posts: 301
Joined: 2004-12-15 03:55pm
Location: Lancaster University, UK
Contact:

Post by CDS »

I can get into the command prompt from univeristy computers, and I'm a restricted user on there.

Back to the subject in hand.. you do have the owner's permission to destroy this box, yes?
Image
"Only two things are infinite, the universe and human stupidity, and I'm not sure about the former." --Albert Einstein
nimoll.co.uk technology website | N forums | Nimoll web design and hosting | Macguide
User avatar
InnocentBystander
The Russian Circus
Posts: 3466
Joined: 2004-04-10 06:05am
Location: Just across the mighty Hudson

Post by InnocentBystander »

DPDarkPrimus wrote:Download.com

Do searches for lots of free stuff, with adware in them.

THEN, get a P2P like Kazaa or Shareza and download lots of popular MP3s and movies... you can delete them, the viruses will still be there.

Furthermore, make an email account and register at a shitload of places... open every single email you get and check all the attachments.

Oh, and make sure you do all of this in Internet Exploder.
That really doesn't work - users are not privilged to install stuff.

Also, I've got a gmail account with about 1000 bits of spam, none that I've previewed had attachments.
User avatar
InnocentBystander
The Russian Circus
Posts: 3466
Joined: 2004-04-10 06:05am
Location: Just across the mighty Hudson

Post by InnocentBystander »

namdoolb wrote:I'm guessing it's a school or college computer or something like that which you're trying to screw over.
Nope, I've acutally I've got a whole stack of old Compaq EN's that I can use, though I only need one ;)
namdoolb wrote: The next time you check your e-mails at home, or on your hotmail, or whatever you use, take every message with a suspicious attatchment and forward it to the e-mail addy that you have on the system that you want to mess up. Then when you get on that computer, simply open up all the attatchments.
Acutally - I've never gotten any of these :(
If you people have these, feel free to send them to InnocentKibitzer@gmail.com
User avatar
InnocentBystander
The Russian Circus
Posts: 3466
Joined: 2004-04-10 06:05am
Location: Just across the mighty Hudson

Post by InnocentBystander »

CDS wrote:I can get into the command prompt from univeristy computers, and I'm a restricted user on there.
I'm not sure how this relates...
CDS wrote: Back to the subject in hand.. you do have the owner's permission to destroy this box, yes?
This is not the subject, but yes, I do have permission.
User avatar
InnocentBystander
The Russian Circus
Posts: 3466
Joined: 2004-04-10 06:05am
Location: Just across the mighty Hudson

Post by InnocentBystander »

namdoolb wrote:Depends.... if he's a restricted user he won't have access to the command prompt or the run command, but you may be able to get around that by typing out a batch file in notepad. I haven't tested this, and I'm not about to, but it might just work.
The objective isn't to try and get around windows security features to and make my job easier, it's to see what kinda crap I can catch as a "stupid" user.
User avatar
CDS
Padawan Learner
Posts: 301
Joined: 2004-12-15 03:55pm
Location: Lancaster University, UK
Contact:

Post by CDS »

InnocentBystander wrote:
CDS wrote:I can get into the command prompt from univeristy computers, and I'm a restricted user on there.
I'm not sure how this relates...
Hense why I said "Back to the subject in hand..." :)
CDS wrote: Back to the subject in hand.. you do have the owner's permission to destroy this box, yes?
This is not the subject, but yes, I do have permission.
Just checkin' ;)
Image
"Only two things are infinite, the universe and human stupidity, and I'm not sure about the former." --Albert Einstein
nimoll.co.uk technology website | N forums | Nimoll web design and hosting | Macguide
User avatar
White Haven
Sith Acolyte
Posts: 6360
Joined: 2004-05-17 03:14pm
Location: The North Remembers, When It Can Be Bothered

Post by White Haven »

Well, a quick visit to www dot coolwebsearch dot com should do it. I believe that's the URL, but I'll be damned if I go there of my own volition!
Image
Image
Chronological Incontinence: Time warps around the poster. The thread topic winks out of existence and reappears in 1d10 posts.

Out of Context Theatre, this week starring Darth Nostril.
-'If you really want to fuck with these idiots tell them that there is a vaccine for chemtrails.'

Fiction!: The Final War (Bolo/Lovecraft) (Ch 7 9/15/11), Living (D&D, Complete)Image
User avatar
General Zod
Never Shuts Up
Posts: 29211
Joined: 2003-11-18 03:08pm
Location: The Clearance Rack
Contact:

Post by General Zod »

do a search for xupiter.com. xupiter is a real pain in the ass to deal with.
"It's you Americans. There's something about nipples you hate. If this were Germany, we'd be romping around naked on the stage here."
User avatar
Xon
Sith Acolyte
Posts: 6206
Joined: 2002-07-16 06:12am
Location: Western Australia

Post by Xon »

Non of these stupid suggestions will work for a user without admin rights on Windows NT OS.

At all (unless some dipshit granted them access to the stuff they require to nuke)
"Okay, I'll have the truth with a side order of clarity." ~ Dr. Daniel Jackson.
"Reality has a well-known liberal bias." ~ Stephen Colbert
"One Drive, One Partition, the One True Path" ~ ars technica forums - warrens - on hhd partitioning schemes.
User avatar
DPDarkPrimus
Emperor's Hand
Posts: 18399
Joined: 2002-11-22 11:02pm
Location: Iowa
Contact:

Post by DPDarkPrimus »

Actually, I just remembered a way to circumvent that restriction.

You have to install the programs on another computer. Then copy all the files onto a disc. Copy-paste them from the disc to the computer.

That's how I got DivX on my school account back in high school.
Mayabird is my girlfriend
Justice League:BotM:MM:SDnet City Watch:Cybertron's Finest
"Well then, science is bullshit. "
-revprez, with yet another brilliant rebuttal.
Kreshna Aryaguna Nurzaman
Jedi Council Member
Posts: 2230
Joined: 2002-07-08 07:10am

Post by Kreshna Aryaguna Nurzaman »

DPDarkPrimus wrote: Furthermore, make an email account and register at a shitload of places... open every single email you get and check all the attachments.
treeloot would be a good start to get spammed (+http://www.treeloot.com).
Kreshna Aryaguna Nurzaman
Jedi Council Member
Posts: 2230
Joined: 2002-07-08 07:10am

Post by Kreshna Aryaguna Nurzaman »

ggs wrote:Non of these stupid suggestions will work for a user without admin rights on Windows NT OS.
Funny, my buddy who owns a public internet rental service got all his PCs get infected despite the lack of admin priv of the visitors.

He's using W2K Pro, but still using IE.
User avatar
InnocentBystander
The Russian Circus
Posts: 3466
Joined: 2004-04-10 06:05am
Location: Just across the mighty Hudson

Post by InnocentBystander »

DPDarkPrimus wrote:Actually, I just remembered a way to circumvent that restriction.

You have to install the programs on another computer. Then copy all the files onto a disc. Copy-paste them from the disc to the computer.

That's how I got DivX on my school account back in high school.
:banghead: I do *not* want to get around the restriction!
User avatar
Xon
Sith Acolyte
Posts: 6206
Joined: 2002-07-16 06:12am
Location: Western Australia

Post by Xon »

Kreshna Aryaguna Nurzaman wrote:
ggs wrote:Non of these stupid suggestions will work for a user without admin rights on Windows NT OS.
Funny, my buddy who owns a public internet rental service got all his PCs get infected despite the lack of admin priv of the visitors.

He's using W2K Pro, but still using IE.
How about reading what I wrote originally:
ggs wrote: With restricted user rights and Windows XP, you need to rely on exploits to do that type of stuff.
And W2k had some weak default permisions. You dont need users with write access to the root drive.
"Okay, I'll have the truth with a side order of clarity." ~ Dr. Daniel Jackson.
"Reality has a well-known liberal bias." ~ Stephen Colbert
"One Drive, One Partition, the One True Path" ~ ars technica forums - warrens - on hhd partitioning schemes.
User avatar
Stark
Emperor's Hand
Posts: 36169
Joined: 2002-07-03 09:56pm
Location: Brisbane, Australia

Post by Stark »

I think IB wants to find out how much you can fuck up a computer by acting like a lamz0r n00b and breaking things by accident, not deliberately destroying it or HAXHAXHAX through exploits. Its a little bit of roleplay, see? :)
User avatar
phongn
Rebel Leader
Posts: 18487
Joined: 2002-07-03 11:11pm

Post by phongn »

Psycho Smiley wrote:If you just want to nuke everything, bring up a DOS window, and point it at C:/ Now fire off the following:

del /F /S /Q *

Even works on non-Admin accounts, apparently. (No, I've never tried it.)
It depends on how well someone has configured their computer. If the proper permissions are set it won't do that much damage.
namdoolb
Padawan Learner
Posts: 431
Joined: 2002-12-06 07:21pm

Post by namdoolb »

go to your favourite search engine and search for nocd cracks for a random game of your choice.

Sure you'll get one or two sites that actualy have a working crack on them, but you'll also get no end of sites with browser introduced malware of all varieties.
Acutally - I've never gotten any of these
If you people have these, feel free to send them to InnocentKibitzer@gmail.com
Don't know if you can setup outlook to access the gmail account, but if you can, do. Outlook does far more stupid shit with e-mails than you could ever do on your own.
Post Reply