![]() |
|
Tutorial Cracking Serial Numbers With SentryMBA - Printable Version +- Sinisterly (https://sinister.li) +-- Forum: Hacking (https://sinister.li/Forum-Hacking) +--- Forum: Tutorials (https://sinister.li/Forum-Tutorials) +--- Thread: Tutorial Cracking Serial Numbers With SentryMBA (/Thread-Tutorial-Cracking-Serial-Numbers-With-SentryMBA) Pages:
1
2
|
Cracking Serial Numbers With SentryMBA - Darkbyte - 05-11-2017 I posted this on another forum but thought you guys might be intrested. SentryMba is usually used for cracking usernames/password on websites. But here we will use it for cracking serial numbers. Step one - Find a valid serial Before we can do anything we need a valid serial to work off. In this tutorial I will be doing evga for this card: http://www.evga.com/Products/Product.aspx?pn=08G-P4-6284-KR After viewing a few youtube videos I found this video and after sticking the video on the highest quality and zooming in using windows magnifier I got the serial number 1612536284001473 ![]() Because the video is so blurry we want to make sure the serial works using the evga warranty checker here http://www.evga.com/support/guestregister.asp ![]() Good , it worked. Lets continue.... Step Two - Create a wordlist As we seen previously our target uses only numbers in there serial numbers. Download python 2.7 from https://www.python.org/download/releases/2.7/ and install it. Now open idle Programs > python2.7>idle . Press file > new window. We are now going to make a simple python script to print wordlist based on our first serial 1612536284001473 we will create a wordlist using everyserial from 161253628400111 to 1612536284009999. In the python window we enter Code: startserial = "161253628400"This setsstartserial to our original serial number minus the last 4 numbers. below this we enter Code: currentnum = 1111This setscurrentnum to 1111 the serial we want to start from note that we do not add quotes to this as we want it to be treated as a number not a word so we can use math functions on it. Next we want to loop until currentnum = 9999 (our final serial number) so we enter Code: while currentnum < 9999:now we want to increase currentnum by 1 everytime our loop runs , so we enter this code Code: currentnum = currentnum+1Notice the whitespace before the text? We do this by pressing tab. It tells python that this code runs inside the while loop in the line before, Now we want to combine currentnum with the first digits of our serial number like so Code: serialnumber = startserial + str(currentnum)this sets serialnumber to be our starting serial from line 1 + the currentnum the str() function currentnum is wrapped in just converts current num back to a word instead of a number. Again we use whitespace before the code so this executes every loop. Finally we want to print out our new serialnumber each loop so we just use Code: print serialnumberNow we can run the script by pressing F5 or run > run module , you may be prompted to save first , do so. When the script runs we will see a bunch of serials spitting out ![]() just for reference this is the final python code: Code: startserial = "161253628400"
currentnum = 1111
while currentnum < 9999:
currentnum = currentnum+1
serialnumber = startserial + str(currentnum)
print serialnumberOk so highlight , copy (there is no copy when u right click in python so use edit > copy or ctrl+c then save all these serials to a text file in notepad. This will be our wordlist. Step Three - Creating a sentry config We will need a few tools for this , first the firefox browser. Why firefox? Because its tamper data addon runs better than chromes. I only use firefox for tamper data but it makes life alot easier get it from https://www.mozilla.org/firefox Once installed open it up and inside firefox goto https://addons.mozilla.org/en-GB/firefox/addon/tamper-data/ and install it. Finally right click the button in the top right of firefox with 3 lines and press the menu bar button ![]() We are ready . Lets head on over to the evga rma page we used earlier inside firefox http://www.evga.com/support/guestregister.asp and lets enter our valid serial number from step 1 but do not press continue yet. Before we do that we want to press tools> Tamper data > start tamper (in the top left hand side). Now we can press continue on the evga site. I see this![]() Untick continue tampering and press the tamper button a window will popup like so: ![]() The important info here is in the top left hand side (tells us what url the data is being sent to) in this case its the same url we already have but other sites it may not be. Secondly the data on the right hand side is the info being sent to the server. sn is our serialnumber and __ncforminfo is a key evga use to make sure u are human. This is just a random string of text we will make sentry auto grab that. Now we know what we need to send and where to send it lets fire up sentry in the site text box we will use the url that was being posted too in tamperdata in this case its just http://www.evga.com/support/guestregister.asp . Open the httpheader tab tick MW then hit the wand next to the postdata textbox. A window will pop up so enter the Action Url (url in the top left hand side of tamper data http://www.evga.com/support/guestregister.asp ). We also need to fill in data from tamperdata right hand side we will input this into the additional data text box: sn=<PASS>&action=Continue &affiliatecode= this tells sentry to use the current item in the wordlist for the value of sn and to set a default for "action" and "continue". We skipped the __ncforminfo because it changes every refresh and we will need to extract this ourselves. To do this we tick enable custom parsing at the top of the window. Now press the wand next to the custom parsing textbox window. This pops up yet another window , open firefox it should still be loaded onto the rma page , right click it , press view source and copy/paste it into the large textbox in sentry mba. We are going to tell sentry where exactly in the html to extract the value for __ncforminfo from. In the find textbox enter __ncforminfo and hit find I am put here Code: <input type="hidden" name="__ncforminfo" value="_U4_gFtUQYUoim5rw9gXGKMHiqSdn5C20t4VmtJE9Ny6aivQbLDCK1mGZTSZymH6e3XvyiXqnNpjg9w8hLZLfFIAc8AEvzBT79evho9zuoH366yg6FGu4A=="/></form>We now know everything we need , in the fielname textbox put __ncforminfo in left string textbox we put __ncforminfo" value=" because this is to the left of the text we want to extract in the right string textbox we put "/></form> because this text is to the right of the text we want to extract hit update then test the code it worked for me so press use data and then usedata again on the mw wizard window. We are almost done but we need to tell sentry what to look for now in the html so it knows if a key is valid or not. Lets go over to sentrymba yet again and press keywords on the left hand side. Go over to firefox again and close tamper data if you have not already. Submit our valid key on the evga page and press continue. Quite a bit of text changed but I will use the text "08G-P4-6284-KR" this is the part number of the item we want so using this we can filter our any serials that work but are not for the device we want. Add this to the Success keys by right clicking > add and paste it in. Then tick define success keys. Now go back a page in firefox and this time lets enter a invalid serial by just bashing some numbers on our keyboard and seeing what happens when a key is invalid. We get the error "The serial number you entered, may be invalid or out of warranty already. Please contact customer service. (E9)" lets put the words "invalid or out of warranty already" into our failure keys and tick define failure keys. In sentry press List > wordlist and load our wordlist we made earlier up. Goto settings > proxy settings and press do not use proxys if you do not want to use them. Goto General > save snapshot to file. Whew we are done. Now press start a window will pop up. Change the user index to 0 as we did not use it. Change the password index to 1. Hit start.
RE: Cracking Serial Numbers With SentryMBA - Bish0pQ - 05-11-2017 Very nice tutorial! Will definitly look into this more later, but very good documented and easily understandable. Keep it up with those. Not sure, but I believe burp suite is also a very good and easy to use tool instead of SentryMBA for the checking of the keys. Great share! RE: Cracking Serial Numbers With SentryMBA - mothered - 05-12-2017 Without question, this Is a HQ tutorial that's very well formatted and documented. Just adding to the creation of a wordlist, alternatively, you can use "Crunch": https://sourceforge.net/projects/crunch-wordlist/?SetFreedomCookie Appreciate the contribution, thanks. RE: Cracking Serial Numbers With SentryMBA - AngehYT - 05-12-2017 string not found, i was trying with logitech :/ RE: Cracking Serial Numbers With SentryMBA - Darkbyte - 05-12-2017 String not found on what the python script? I have a logitech serial gen , not for sentry but im sure its possible ;-) RE: Cracking Serial Numbers With SentryMBA - AngehYT - 05-12-2017 (05-12-2017, 06:17 PM)Darkbyte Wrote: String not found on what the python script? when I try to find the __ncforminfo RE: Cracking Serial Numbers With SentryMBA - Darkbyte - 05-12-2017 Logitech does not use that in the html the url they use is https://support.logitech.com/en_us/contact-warranty They then set a random text string to the value "csrf". This is then posted to along with some other data to https://support.logitech.com/apexremote RE: Cracking Serial Numbers With SentryMBA - d0wngrade - 05-19-2017 Nice, a few lines of code could be improved but the idea is good. RE: Cracking Serial Numbers With SentryMBA - Guzzie - 11-05-2017 Great config. You might can add variables? RE: Cracking Serial Numbers With SentryMBA - Snapchat - 12-08-2017 Actually a really helpful and detailed post. Learnt a lot from this thank you
|