RE: Your program in the official HC Programs? 12-22-2012, 04:46 PM
#41
Hm ok but don't you think that it'll look strange?? cause it's just a little tool without many functions
| Your program in the official HC Programs? filter_list | |
![[Image: l7e9kgas.png]](http://s7.directupload.net/images/121226/l7e9kgas.png)
![[Image: 2YpkRjy.png]](http://i.imgur.com/2YpkRjy.png)
(12-26-2012, 04:13 PM)Deque Wrote: Requirements: Java 7
Programming Language: Java
Screenshot:
Description:
Once you start the program, it searches automatically for default locations of your key3.db in Firefox and, if not found, in the Thunderbird application directory. I prepared and tested this for Windows 7 and Linux. If it is not working for your OS, please tell me the default location for it. I just need the information to put that in. You can change the location by hand, of course.
key3.db is the file that is used to recover the master password. You can start a wordlist attack on that. The program ships with a default worldlist, but it is small (I didn't want to upload a wordlist file that adds several megabytes to the program). You can use your own list by changing the location.
Alternatively you can start a bruteforce attack by activating the "bruteforce" checkbox. Although I used threads, this is limited to a word length of five (a bruteforce attack with a wordlength of six would take several days, so I don't allow that) and the alphabet a-zA-Z by now. I got about 30000 password tests per second on my machine.
Once you got the master password, it is very easy to obtain saved login information from signons.sqlite, since both, Thunderbird and Firefox, will show usernames and passwords in plain text. (google if you don't know how)
Conclusion: Always set a master password if you save login information with Thunderbird or Firefox. Otherwise the login information can be obtained without any problems.
The only (non-standard) library I used is apache.log4j for logging purposes. You will see a properties file and a log folder. The standard logging level is WARN. If you change this level to INFO or DEBUG, the master passwords found with the program will be saved in there, so be careful with that option.
Lines of code without comments and empty lines: 914
Lines of code with everything else: 1141
The code was tested for: Firefox 9.01 Thunderbird 9.01, Windows XP, Vista, 7, Arch Linux
Problems?
Please make sure that you have Java 7.
If there are still problems, post the logging file that is in the logs folder.
Source: http://www.multiupload.nl/LVZ5N60W1F
Program: http://www.multiupload.nl/R7L1D4M3E5
![[Image: 3yxy3cv7.png]](http://s14.directupload.net/images/121228/3yxy3cv7.png)
![[Image: 2YpkRjy.png]](http://i.imgur.com/2YpkRjy.png)
(12-28-2012, 10:11 PM)Deque Wrote: Name: MinecraftLoginReader
Language: Java
Screenshot:
Description:
I already provided main source and explanation here: http://www.hackcommunity.com/Thread-Java...-lastlogin
I just made a GUI for it.
Usage is simple. MLR automatically searches for the lastlogin file in the default location of your OS. But you can also change the file by pressing the "..." button on the right.
Clicking "decrypt" will show password and username.
Works in Unix, Linux, Mac and Windows.
Requirements: Java Runtime 1.7
Source: http://www.multiupload.nl/9OR3NU5T6B
Program: http://www.multiupload.nl/C7RJQV7KZN
(12-28-2012, 10:41 PM)bluedog.tar.gz Wrote: You don't have to post in this thread anymore, you have my permission to make your own threads here http://www.hackcommunity.com/Forum-Official-HC-Programs
![[Image: 2YpkRjy.png]](http://i.imgur.com/2YpkRjy.png)